# \#none

**URL:** https://discuss.elastic.co/tag/none.md?no_tags=true&page=318

[Latest](https://discuss.elastic.co/latest.md) · [Categories](https://discuss.elastic.co/categories.md) · [Tags](https://discuss.elastic.co/tags.md)

**Page:** 319

---

## [AFTER changed DATA STREAM INDEX template, index stay 225b,](https://discuss.elastic.co/t/after-changed-data-stream-index-template-index-stay-225b/341293)

<div class="topic-metadata">

**Author:** [@cLaYYs](https://discuss.elastic.co/u/cLaYYs)\
**Replies:** 1\
**Last updated:** [August 22, 2023, 4:54am UTC](https://discuss.elastic.co/t/after-changed-data-stream-index-template-index-stay-225b/341293 "2023-08-22T04:54:20Z")

</div>

Hi All, We use custom UDP integration(fleet managed integration) to collect Linux auth logs. We set the default pipeline for auth logs which is \[logs-system.auth-default\]. We did parse the data as we expected. This dat…

---

## [Update indices replica set in Elasticsearch cluster](https://discuss.elastic.co/t/update-indices-replica-set-in-elasticsearch-cluster/341149)

<div class="topic-metadata">

**Author:** [@ahmed.emad](https://discuss.elastic.co/u/ahmed.emad)\
**Replies:** 1\
**Last updated:** [August 21, 2023, 10:32pm UTC](https://discuss.elastic.co/t/update-indices-replica-set-in-elasticsearch-cluster/341149 "2023-08-21T22:32:59Z")

</div>

Hello, I would like to update the number of replicas for newly creating indices to be 5 automatically, so i used the below curl curl -XPUT -k -u elastic:password 'https://192.168.x.x:9200/\_index\_template/my\_template' -…

---

## [Pinned Filters Passed Through Dashboard URL Are Not Applied](https://discuss.elastic.co/t/pinned-filters-passed-through-dashboard-url-are-not-applied/340162)

<div class="topic-metadata">

**Author:** [@kevfar](https://discuss.elastic.co/u/kevfar)\
**Replies:** 3\
**Last updated:** [August 21, 2023, 8:41pm UTC](https://discuss.elastic.co/t/pinned-filters-passed-through-dashboard-url-are-not-applied/340162 "2023-08-21T20:41:20Z")

</div>

Hello! I recently posted a question regarding this issue, but unfortunately the topic was closed before I got around to responding to the first reply. I am working for a company that utilizes Kibana dashboards to view cl…

---

## [Replica count 3 for .security-7](https://discuss.elastic.co/t/replica-count-3-for-security-7/341274)

<div class="topic-metadata">

**Author:** [@data\_smith](https://discuss.elastic.co/u/data_smith)\
**Replies:** 1\
**Last updated:** [August 21, 2023, 7:27pm UTC](https://discuss.elastic.co/t/replica-count-3-for-security-7/341274 "2023-08-21T19:27:06Z")

</div>

I'm trying to set the replica count for .security-7 to 3 so that if 2 nodes go down it's still ok. But it seems superuser can't update it. What's the best path forward for this situation. The docs don't really answer …

---

## [Changing to Service type of LoadBalancer from ClusterIP on ECK Operator Breaks](https://discuss.elastic.co/t/changing-to-service-type-of-loadbalancer-from-clusterip-on-eck-operator-breaks/341276)

<div class="topic-metadata">

**Author:** [@bigjoe21](https://discuss.elastic.co/u/bigjoe21)\
**Replies:** 1\
**Last updated:** [August 21, 2023, 6:04pm UTC](https://discuss.elastic.co/t/changing-to-service-type-of-loadbalancer-from-clusterip-on-eck-operator-breaks/341276 "2023-08-21T18:04:29Z")

</div>

I went through the quickstart and successfully deployed elasticsearch and kibana on EKS using the ECK operator. I then followed the directions in the docs to allow public access. However, the ECK Operator keeps throwing…

---

## [Create a rule or alert to monitor when its not receiving logs by 24 hours?](https://discuss.elastic.co/t/create-a-rule-or-alert-to-monitor-when-its-not-receiving-logs-by-24-hours/340932)

<div class="topic-metadata">

**Author:** [@lucasyuki](https://discuss.elastic.co/u/lucasyuki)\
**Replies:** 1\
**Last updated:** [August 21, 2023, 5:00pm UTC](https://discuss.elastic.co/t/create-a-rule-or-alert-to-monitor-when-its-not-receiving-logs-by-24-hours/340932 "2023-08-21T17:00:37Z")

</div>

Hi, I've been trying to check how to create this type of rule in the forum and I saw that other people have the same problem

---

## [Null value in field type with nested](https://discuss.elastic.co/t/null-value-in-field-type-with-nested/341278)

<div class="topic-metadata">

**Author:** [@Murilo\_Livorato](https://discuss.elastic.co/u/Murilo_Livorato)\
**Replies:** 0\
**Last updated:** [August 21, 2023, 4:18pm UTC](https://discuss.elastic.co/t/null-value-in-field-type-with-nested/341278 "2023-08-21T16:18:24Z")

</div>

I have a filed , that if has value , it has ID and TITLE . so , wold be like this - category: { id: 2, title: 'monitor' } but can be like this as well category: NULL So I did like this the mapping - "category":…

---

## [Cannot change log format with pipeline config file, pipeline config file is not getting read](https://discuss.elastic.co/t/cannot-change-log-format-with-pipeline-config-file-pipeline-config-file-is-not-getting-read/340081)

<div class="topic-metadata">

**Author:** [@Jenkins-Jobs](https://discuss.elastic.co/u/Jenkins-Jobs)\
**Replies:** 7\
**Last updated:** [August 21, 2023, 4:04pm UTC](https://discuss.elastic.co/t/cannot-change-log-format-with-pipeline-config-file-pipeline-config-file-is-not-getting-read/340081 "2023-08-21T16:04:30Z")

</div>

Greetings, First time posting here, elasticsearch 8.9 rhel 7 I am getting logs from jenkins jobs using logstash plugin with no issues the only mime type that seems to work is "application/json" If i try any other t…

---

## [RSS feed for new Elasticsearch versions](https://discuss.elastic.co/t/rss-feed-for-new-elasticsearch-versions/341272)

<div class="topic-metadata">

**Author:** [@jaketw47](https://discuss.elastic.co/u/jaketw47)\
**Replies:** 0\
**Last updated:** [August 21, 2023, 3:13pm UTC](https://discuss.elastic.co/t/rss-feed-for-new-elasticsearch-versions/341272 "2023-08-21T15:13:25Z")

</div>

Our company watches a small number of release-only RSS feeds so that we can be quickly notified when new versions of software we depend on are released (at least ones that still require manual upgrades). The Elastic Blog…

---

## [Should I disable scroll time if I don't explicitly use scroll in any search or index operation?](https://discuss.elastic.co/t/should-i-disable-scroll-time-if-i-dont-explicitly-use-scroll-in-any-search-or-index-operation/341158)

<div class="topic-metadata">

**Author:** [@arifd](https://discuss.elastic.co/u/arifd)\
**Replies:** 1\
**Last updated:** [August 21, 2023, 2:39pm UTC](https://discuss.elastic.co/t/should-i-disable-scroll-time-if-i-dont-explicitly-use-scroll-in-any-search-or-index-operation/341158 "2023-08-21T14:39:40Z")

</div>

Hello! So I am not (as far as I am aware) using the Scroll API, and yet I was able to get the "Trying to create too many scroll contexts. Must be less than or equal to: \[500\]" error. From searching around, I am under t…

---

## [Two custom analyzers with the same synonym filter - why no match](https://discuss.elastic.co/t/two-custom-analyzers-with-the-same-synonym-filter-why-no-match/341264)

<div class="topic-metadata">

**Author:** [@Lukas\_Cern](https://discuss.elastic.co/u/Lukas_Cern)\
**Replies:** 0\
**Last updated:** [August 21, 2023, 2:17pm UTC](https://discuss.elastic.co/t/two-custom-analyzers-with-the-same-synonym-filter-why-no-match/341264 "2023-08-21T14:17:23Z")

</div>

I have index with two fields. Each field uses different custom analyzer. Each of those analyzers use the same synonym filter. When querying with bool + should + match on both fields, it matches no document. I dont under…

---

## [ERROR : "Authentication to realm file1 failed - Password authentication failed for elastic" after updgrading my kubernetes cluster](https://discuss.elastic.co/t/error-authentication-to-realm-file1-failed-password-authentication-failed-for-elastic-after-updgrading-my-kubernetes-cluster/341260)

<div class="topic-metadata">

**Author:** [@khaled\_belgacem](https://discuss.elastic.co/u/khaled_belgacem)\
**Replies:** 0\
**Last updated:** [August 21, 2023, 2:08pm UTC](https://discuss.elastic.co/t/error-authentication-to-realm-file1-failed-password-authentication-failed-for-elastic-after-updgrading-my-kubernetes-cluster/341260 "2023-08-21T14:08:49Z")

</div>

hello everyone, a few days ago my kubernetes cluster certificates expired (on prem) so i upgraded my kubernetes version to get them renewed, before the upgrade i was using ECK for about a year, had multiple elastic clus…

---

## [High Index Count impacting Elasticsearch Performance](https://discuss.elastic.co/t/high-index-count-impacting-elasticsearch-performance/341259)

<div class="topic-metadata">

**Author:** [@Nitish\_Goyal](https://discuss.elastic.co/u/Nitish_Goyal)\
**Replies:** 0\
**Last updated:** [August 21, 2023, 2:07pm UTC](https://discuss.elastic.co/t/high-index-count-impacting-elasticsearch-performance/341259 "2023-08-21T14:07:43Z")

</div>

Problem Statement : Decrease in cluster throughput as we increase the number of indices in the cluster Cluster Set up Nodes = 8 Cores per node = 18 Memory = 90 GB Heap = 28 GB Version = 8.9.0 We are seeing decrease…

---

## [Render Json strings from Elastic API client objects](https://discuss.elastic.co/t/render-json-strings-from-elastic-api-client-objects/341238)

<div class="topic-metadata">

**Author:** [@Zer0](https://discuss.elastic.co/u/Zer0)\
**Replies:** 2\
**Last updated:** [August 21, 2023, 1:59pm UTC](https://discuss.elastic.co/t/render-json-strings-from-elastic-api-client-objects/341238 "2023-08-21T13:59:53Z")

</div>

Hi, I am using the Elasticsearch API client (8.9) for java and wondering how to render those Queries and Responses as json strings. For example I can do a simple query like so: val query = Query.of { q -\> q.matchAll {…

---

## [Is it possible to disable or remove log4j-core-2.17.1.jar from Logstash?](https://discuss.elastic.co/t/is-it-possible-to-disable-or-remove-log4j-core-2-17-1-jar-from-logstash/341221)

<div class="topic-metadata">

**Author:** [@kam89](https://discuss.elastic.co/u/kam89)\
**Replies:** 1\
**Last updated:** [August 21, 2023, 1:20pm UTC](https://discuss.elastic.co/t/is-it-possible-to-disable-or-remove-log4j-core-2-17-1-jar-from-logstash/341221 "2023-08-21T13:20:59Z")

</div>

Hi, We are running on Logstash 8.8.0 and our IT security team has concern about the log4j-core-2.17.1.jar in the logstash-core\\lib\\jars. Can we disable log4j totally in Logstash and remove the log4j-core-2.17.1.jar fro…

---

## [Spring + elastic 8.9.0 How to create index template](https://discuss.elastic.co/t/spring-elastic-8-9-0-how-to-create-index-template/340033)

<div class="topic-metadata">

**Author:** [@Prasanth\_Gutlapalli](https://discuss.elastic.co/u/Prasanth_Gutlapalli)\
**Replies:** 3\
**Last updated:** [August 21, 2023, 1:09pm UTC](https://discuss.elastic.co/t/spring-elastic-8-9-0-how-to-create-index-template/340033 "2023-08-21T13:09:26Z")

</div>

How to create index template give java example

---

## [Best way to load an elastic query and manipulate it](https://discuss.elastic.co/t/best-way-to-load-an-elastic-query-and-manipulate-it/341099)

<div class="topic-metadata">

**Author:** [@Zer0](https://discuss.elastic.co/u/Zer0)\
**Replies:** 1\
**Last updated:** [August 21, 2023, 12:10pm UTC](https://discuss.elastic.co/t/best-way-to-load-an-elastic-query-and-manipulate-it/341099 "2023-08-21T12:10:06Z")

</div>

Hi, I am using the Elasticsearch Java client and what I basically want to achieve is the following: Our backend is basically a ES Proxy, so there is an endpoint that takes an ES query as input, adds a clause (to scope t…

---

## [Problem between elasticsearch and logstash](https://discuss.elastic.co/t/problem-between-elasticsearch-and-logstash/341206)

<div class="topic-metadata">

**Author:** [@adimi\_worou](https://discuss.elastic.co/u/adimi_worou)\
**Replies:** 0\
**Last updated:** [August 21, 2023, 7:59am UTC](https://discuss.elastic.co/t/problem-between-elasticsearch-and-logstash/341206 "2023-08-21T07:59:49Z")

</div>

Good evening, Elasticsearch via logstash loads data from mysql. The problem is that logstash only retrieves a small part of the documents. Example: logstash retrieves 8 out of 510. What do you think could be the cause …

---

## [Single click option in drilldown](https://discuss.elastic.co/t/single-click-option-in-drilldown/341200)

<div class="topic-metadata">

**Author:** [@Rushi\_Bagul](https://discuss.elastic.co/u/Rushi_Bagul)\
**Replies:** 1\
**Last updated:** [August 21, 2023, 7:36am UTC](https://discuss.elastic.co/t/single-click-option-in-drilldown/341200 "2023-08-21T07:36:08Z")

</div>

I am used self deploy kibana application with basic licence and I want Single click option in drilldown for dashboard visualizations . Can anyone suggest me to approach for this?

---

## [Error activating rule](https://discuss.elastic.co/t/error-activating-rule/340742)

<div class="topic-metadata">

**Author:** [@saudmajed99](https://discuss.elastic.co/u/saudmajed99)\
**Replies:** 5\
**Last updated:** [August 21, 2023, 6:42am UTC](https://discuss.elastic.co/t/error-activating-rule/340742 "2023-08-21T06:42:13Z")

</div>

Hi there, We have faced the issue when activated the rule and the appear this Error Alert type siem.signals is disabled because your basic license has expired My version ELK: 7.17.8 Basic license can you hlep me ?

---

## [Not able to completely delete a deployment](https://discuss.elastic.co/t/not-able-to-completely-delete-a-deployment/341201)

<div class="topic-metadata">

**Author:** [@steman-provinzial](https://discuss.elastic.co/u/steman-provinzial)\
**Replies:** 0\
**Last updated:** [August 21, 2023, 6:30am UTC](https://discuss.elastic.co/t/not-able-to-completely-delete-a-deployment/341201 "2023-08-21T06:30:43Z")

</div>

Hi there, I am trying to delete a deployment, but there is always a piece that does not get deleted. In logging and metrics I find this error message that could be related: "Elasticsearch version is not determined for…

---

## [Need critical user journey logs on Kibana to find out the errors what users get](https://discuss.elastic.co/t/need-critical-user-journey-logs-on-kibana-to-find-out-the-errors-what-users-get/341072)

<div class="topic-metadata">

**Author:** [@Rajeev3](https://discuss.elastic.co/u/Rajeev3)\
**Replies:** 1\
**Last updated:** [August 21, 2023, 5:56am UTC](https://discuss.elastic.co/t/need-critical-user-journey-logs-on-kibana-to-find-out-the-errors-what-users-get/341072 "2023-08-21T05:56:26Z")

</div>

Hi There, I just wanted to tell you that i have deployed ELK stack on an EC2 instance and have routed the logs with the help of side car container deployment with application container. And it really worked and i can ab…

---

## [How to configure Logstash pipeline to not OOM-Kill ElasticSearch](https://discuss.elastic.co/t/how-to-configure-logstash-pipeline-to-not-oom-kill-elasticsearch/340949)

<div class="topic-metadata">

**Author:** [@amattice](https://discuss.elastic.co/u/amattice)\
**Replies:** 7\
**Last updated:** [August 21, 2023, 5:18am UTC](https://discuss.elastic.co/t/how-to-configure-logstash-pipeline-to-not-oom-kill-elasticsearch/340949 "2023-08-21T05:18:59Z")

</div>

I'm very new here and to the ELK stack in general. I setup an Ubuntu VM in my Azure resource group and installed the latest Elasticsearch,LogStash, and Kibana. I have basic user authentication setup for kibana, and no SS…

---

## [Using jdbc\_static to build connectionstring that are used in later step](https://discuss.elastic.co/t/using-jdbc-static-to-build-connectionstring-that-are-used-in-later-step/341189)

<div class="topic-metadata">

**Author:** [@johanwallenborg](https://discuss.elastic.co/u/johanwallenborg)\
**Replies:** 2\
**Last updated:** [August 20, 2023, 7:17pm UTC](https://discuss.elastic.co/t/using-jdbc-static-to-build-connectionstring-that-are-used-in-later-step/341189 "2023-08-20T19:17:02Z")

</div>

I found and read about jdbc\_static and trying to get my head around. But I have some questions before i dive deeper into this one. Say that I have a database with a table with rows that contains i.e a identifier, datab…

---

## [KIBANA 8.7.1 kibana\_system password update](https://discuss.elastic.co/t/kibana-8-7-1-kibana-system-password-update/341137)

<div class="topic-metadata">

**Author:** [@sealove23](https://discuss.elastic.co/u/sealove23)\
**Replies:** 1\
**Last updated:** [August 20, 2023, 6:08pm UTC](https://discuss.elastic.co/t/kibana-8-7-1-kibana-system-password-update/341137 "2023-08-20T18:08:00Z")

</div>

Happy Friday, need help with KIBANA start using xxxxxxx:5601

---

## [Search related documents in kibana in single query](https://discuss.elastic.co/t/search-related-documents-in-kibana-in-single-query/341115)

<div class="topic-metadata">

**Author:** [@vignesh\_nayak](https://discuss.elastic.co/u/vignesh_nayak)\
**Replies:** 4\
**Last updated:** [August 20, 2023, 4:32pm UTC](https://discuss.elastic.co/t/search-related-documents-in-kibana-in-single-query/341115 "2023-08-20T16:32:38Z")

</div>

Hi, I have one scenario. I am pushing certain ID in thread context from application for each transaction along with individual log messages, which means all docs in kibana for that transaction will have same ID, Ex: Tra…

---

## [As part of elastic upgrade prerequisite deleted .reindexed-v6-watches-6 all watchers are gone](https://discuss.elastic.co/t/as-part-of-elastic-upgrade-prerequisite-deleted-reindexed-v6-watches-6-all-watchers-are-gone/341139)

<div class="topic-metadata">

**Author:** [@Anusha\_Kusanghi](https://discuss.elastic.co/u/Anusha_Kusanghi)\
**Replies:** 1\
**Last updated:** [August 20, 2023, 4:01pm UTC](https://discuss.elastic.co/t/as-part-of-elastic-upgrade-prerequisite-deleted-reindexed-v6-watches-6-all-watchers-are-gone/341139 "2023-08-20T16:01:06Z")

</div>

Hi All, We're currently on Elastic 7.17 and are preparing to upgrade to version 8.6. As part of the upgrade process, we were reviewing the breaking changes, specifically in relation to the indices created in version 6. …

---

## [Aggregation Path](https://discuss.elastic.co/t/aggregation-path/341172)

<div class="topic-metadata">

**Author:** [@noman13bd](https://discuss.elastic.co/u/noman13bd)\
**Replies:** 0\
**Last updated:** [August 20, 2023, 6:05am UTC](https://discuss.elastic.co/t/aggregation-path/341172 "2023-08-20T06:05:05Z")

</div>

I want to use global number of total docs in bucket script. But getting the error No aggregation found for path \[global\_total\_docs\>total\_docs\] can you please help me to identify the right aggregation path? GET bl\_log\_d…

---

## [How to Check which service/application is generating more logs?](https://discuss.elastic.co/t/how-to-check-which-service-application-is-generating-more-logs/340827)

<div class="topic-metadata">

**Author:** [@johnashish](https://discuss.elastic.co/u/johnashish)\
**Replies:** 3\
**Last updated:** [August 20, 2023, 3:42am UTC](https://discuss.elastic.co/t/how-to-check-which-service-application-is-generating-more-logs/340827 "2023-08-20T03:42:08Z")

</div>

Is there a way to check which service/application is generating more logs? Kubernetes Cluster Centralised Elasticsearch and Kibana Fluentbit - different Kubernetes clusters which will send logs to centralised Elastics…

---

## [Logstash doesn't reads JSON file on Windows](https://discuss.elastic.co/t/logstash-doesnt-reads-json-file-on-windows/341156)

<div class="topic-metadata">

**Author:** [@VSKMurali](https://discuss.elastic.co/u/VSKMurali)\
**Replies:** 10\
**Last updated:** [August 19, 2023, 11:35pm UTC](https://discuss.elastic.co/t/logstash-doesnt-reads-json-file-on-windows/341156 "2023-08-19T23:35:17Z")

</div>

Hello, I am trying to configure a following setup on Windows machine. JSON file (creates every 5 mins with the same file name) and Elasticsearch should read the file and push to Index and this is my Logstash config fil…

[Previous page](https://discuss.elastic.co/tag/none.md?no_tags=true&page=317)

[Next page](https://discuss.elastic.co/tag/none.md?no_tags=true&page=319)
