# \#none

**URL:** https://discuss.elastic.co/tag/none.md?no_tags=true&page=328

[Latest](https://discuss.elastic.co/latest.md) · [Categories](https://discuss.elastic.co/categories.md) · [Tags](https://discuss.elastic.co/tags.md)

**Page:** 329

---

## [Trying to delete documents in index older than XXX](https://discuss.elastic.co/t/trying-to-delete-documents-in-index-older-than-xxx/339852)

<div class="topic-metadata">

**Author:** [@guy\_guy](https://discuss.elastic.co/u/guy_guy)\
**Replies:** 0\
**Last updated:** [August 1, 2023, 7:45pm UTC](https://discuss.elastic.co/t/trying-to-delete-documents-in-index-older-than-xxx/339852 "2023-08-01T19:45:00Z")

</div>

I need to delete some documents from indexes older than XXX days, but delete\_by\_query doesn't seem to be working for me. Here is an example query I'm trying to run POST shipment-log/\_delete\_by\_query { "query": { …

---

## [Elastic Serverless Forwarder not able to send Cloudwatch Logs to Elastic](https://discuss.elastic.co/t/elastic-serverless-forwarder-not-able-to-send-cloudwatch-logs-to-elastic/339801)

<div class="topic-metadata">

**Author:** [@Vedant14](https://discuss.elastic.co/u/Vedant14)\
**Replies:** 0\
**Last updated:** [August 1, 2023, 1:28pm UTC](https://discuss.elastic.co/t/elastic-serverless-forwarder-not-able-to-send-cloudwatch-logs-to-elastic/339801 "2023-08-01T13:28:26Z")

</div>

We deployed elastic-serverless-forwarder application on AWS lambda and also configured the config.yaml for specifying the outputs to Elastic and Kibana. We are not able to get the Cloudwatch Logs in Elastic . I have shar…

---

## [Unknown reason of All Elastic indices deletion repeatedly](https://discuss.elastic.co/t/unknown-reason-of-all-elastic-indices-deletion-repeatedly/339934)

<div class="topic-metadata">

**Author:** [@usman1](https://discuss.elastic.co/u/usman1)\
**Replies:** 6\
**Last updated:** [August 2, 2023, 12:25pm UTC](https://discuss.elastic.co/t/unknown-reason-of-all-elastic-indices-deletion-repeatedly/339934 "2023-08-02T12:25:49Z")

</div>

My elasticsearch instance is deployed in an EC2 instance and due to some reason, all my indices got deleted on 20th of July. After recovering the data on 30th, they got deleted again on 31st and then on 1st of August aga…

---

## [Not able to see watcher option in kibana using entrerprise edition](https://discuss.elastic.co/t/not-able-to-see-watcher-option-in-kibana-using-entrerprise-edition/339541)

<div class="topic-metadata">

**Author:** [@PRASHANT\_MEHTA](https://discuss.elastic.co/u/PRASHANT_MEHTA)\
**Replies:** 2\
**Last updated:** [August 2, 2023, 11:09am UTC](https://discuss.elastic.co/t/not-able-to-see-watcher-option-in-kibana-using-entrerprise-edition/339541 "2023-08-02T11:09:50Z")

</div>

Hello All, I'm unable to see watcher option in kibana and using enterprise edition. I want to configure alerts based on some string or if certain condition meets.For this watcher is required, but unable to see that opt…

---

## [Fail to start Elasticsearch in Linux](https://discuss.elastic.co/t/fail-to-start-elasticsearch-in-linux/339920)

<div class="topic-metadata">

**Author:** [@Saeed\_Ramezani](https://discuss.elastic.co/u/Saeed_Ramezani)\
**Replies:** 0\
**Last updated:** [August 2, 2023, 10:11am UTC](https://discuss.elastic.co/t/fail-to-start-elasticsearch-in-linux/339920 "2023-08-02T10:11:49Z")

</div>

I'm just trying to install Elasticsearch on Linux(ubuntu 22) by this article All the following commands passed by but when I reach to command ./bin/elasticsearch this error accord: ERROR: Elasticsearch exited unexpecte…

---

## [How to wait for indexing to finish before closing bulkingester](https://discuss.elastic.co/t/how-to-wait-for-indexing-to-finish-before-closing-bulkingester/339875)

<div class="topic-metadata">

**Author:** [@ALX\_DM](https://discuss.elastic.co/u/ALX_DM)\
**Replies:** 1\
**Last updated:** [August 2, 2023, 8:15am UTC](https://discuss.elastic.co/t/how-to-wait-for-indexing-to-finish-before-closing-bulkingester/339875 "2023-08-02T08:15:08Z")

</div>

how to wait for indexing to finish before closing bulkingester. previously we have awaitClose() for bulkprocessor. is is same for bulkingester? there is no awaitClose, but there is wait() in bulkIngester. I am not sur…

---

## [Why are my indexes automatically removed?](https://discuss.elastic.co/t/why-are-my-indexes-automatically-removed/339857)

<div class="topic-metadata">

**Author:** [@Miguel3](https://discuss.elastic.co/u/Miguel3)\
**Replies:** 5\
**Last updated:** [August 2, 2023, 8:13am UTC](https://discuss.elastic.co/t/why-are-my-indexes-automatically-removed/339857 "2023-08-02T08:13:59Z")

</div>

I have a problem with my elastic instance, after a few days of creating and uploading data to my indexes they are automatically deleted, I don't understand why it's happening and I don't see any message in the logs that …

---

## [Wildcard in control](https://discuss.elastic.co/t/wildcard-in-control/339687)

<div class="topic-metadata">

**Author:** [@martinsbleu](https://discuss.elastic.co/u/martinsbleu)\
**Replies:** 2\
**Last updated:** [August 2, 2023, 7:45am UTC](https://discuss.elastic.co/t/wildcard-in-control/339687 "2023-08-02T07:45:12Z")

</div>

Hello Team, Is there a way for control in Dashboard to have wildcard search ? If not, how can I open a request for it ? Thanks in advance,

---

## [Too\_many\_clauses: maxClauseCount is set to 1337](https://discuss.elastic.co/t/too-many-clauses-maxclausecount-is-set-to-1337/339894)

<div class="topic-metadata">

**Author:** [@drorp\_korra](https://discuss.elastic.co/u/drorp_korra)\
**Replies:** 0\
**Last updated:** [August 2, 2023, 7:29am UTC](https://discuss.elastic.co/t/too-many-clauses-maxclausecount-is-set-to-1337/339894 "2023-08-02T07:29:16Z")

</div>

Hello, i'm getting the this error: ApiError(500, 'search\_phase\_execution\_exception', 'too\_many\_clauses: maxClauseCount is set to 1337') The query that is use is: { "bool": { "filter": \[ { "term": { "fi…

---

## [{“statusCode”:503,”error”:”Service Unavailable”,”message”:”License is not available.”}](https://discuss.elastic.co/t/statuscode-503-error-service-unavailable-message-license-is-not-available/339891)

<div class="topic-metadata">

**Author:** [@R1d3rBG](https://discuss.elastic.co/u/R1d3rBG)\
**Replies:** 0\
**Last updated:** [August 2, 2023, 7:15am UTC](https://discuss.elastic.co/t/statuscode-503-error-service-unavailable-message-license-is-not-available/339891 "2023-08-02T07:15:18Z")

</div>

Hello, Since a few days its starting again with the same error. Almost every morning when I check the machine its stopped with the following error when I open the URL. {"statusCode":503,"error":"Service Unavailable","m…

---

## [Field mapping \[field with constant name\]. --\> \[field with a changing/dynamic name\] --\> \[fields with constant names\]](https://discuss.elastic.co/t/field-mapping-field-with-constant-name-field-with-a-changing-dynamic-name-fields-with-constant-names/339886)

<div class="topic-metadata">

**Author:** [@stcdarrell](https://discuss.elastic.co/u/stcdarrell)\
**Replies:** 2\
**Last updated:** [August 2, 2023, 5:12am UTC](https://discuss.elastic.co/t/field-mapping-field-with-constant-name-field-with-a-changing-dynamic-name-fields-with-constant-names/339886 "2023-08-02T05:12:34Z")

</div>

hi.. i've run into a problem with elasticsearch mapping.. i'm sure there is a way to deal with it.. but i cant figure it out.. or even the terminology to use to search for a solution. i'm trying to import a json from sh…

---

## [Installing Elasticsearch 7.17](https://discuss.elastic.co/t/installing-elasticsearch-7-17/339887)

<div class="topic-metadata">

**Author:** [@Rahul\_Kumar\_Jaiswal](https://discuss.elastic.co/u/Rahul_Kumar_Jaiswal)\
**Replies:** 0\
**Last updated:** [August 2, 2023, 5:12am UTC](https://discuss.elastic.co/t/installing-elasticsearch-7-17/339887 "2023-08-02T05:12:10Z")

</div>

I am trying to reinstall the elasticsearch same version on ubuntu 20.04 but I am getting the below error again and again. I have tried almost all the solution given on google but the error was not resolved. Previously sa…

---

## [Using Maxmind databases without access to ES cluster](https://discuss.elastic.co/t/using-maxmind-databases-without-access-to-es-cluster/339736)

<div class="topic-metadata">

**Author:** [@hjazz6](https://discuss.elastic.co/u/hjazz6)\
**Replies:** 5\
**Last updated:** [August 2, 2023, 4:47am UTC](https://discuss.elastic.co/t/using-maxmind-databases-without-access-to-es-cluster/339736 "2023-08-02T04:47:38Z")

</div>

Hi, I'm using a ES cluster (v8.8.0) running on Kubenetes that is managed by someone else, and I was told by them that I would not be able to directly access the cluster. Previously, when I was managing my own cluster r…

---

## [ELK Update](https://discuss.elastic.co/t/elk-update/339880)

<div class="topic-metadata">

**Author:** [@juancamiloll](https://discuss.elastic.co/u/juancamiloll)\
**Replies:** 0\
**Last updated:** [August 2, 2023, 3:19am UTC](https://discuss.elastic.co/t/elk-update/339880 "2023-08-02T03:19:27Z")

</div>

Hello everyone, I currently have an ELK version 7.6.0 implementation which I use hand in hand with Splunk version 8.0.1. I realize they are old versions, but it is working for what I need. The plugin I use from Splunk…

---

## [Is elastic Near-Real-Time when we discussing Observability?](https://discuss.elastic.co/t/is-elastic-near-real-time-when-we-discussing-observability/339323)

<div class="topic-metadata">

**Author:** [@Ernest\_Dong](https://discuss.elastic.co/u/Ernest_Dong)\
**Replies:** 2\
**Last updated:** [August 2, 2023, 2:35am UTC](https://discuss.elastic.co/t/is-elastic-near-real-time-when-we-discussing-observability/339323 "2023-08-02T02:35:03Z")

</div>

Elasticsearch is Near real-time. I just wonder when it comes to observability(and security), does NRT means that I can't get insight instantly when my cluster is hacked very quickly? E.g. I got hacked and this event data…

---

## [Unable to create a new Field in Logstash ElasticSearch please help](https://discuss.elastic.co/t/unable-to-create-a-new-field-in-logstash-elasticsearch-please-help/339874)

<div class="topic-metadata">

**Author:** [@Jennifer\_Coley](https://discuss.elastic.co/u/Jennifer_Coley)\
**Replies:** 0\
**Last updated:** [August 2, 2023, 12:58am UTC](https://discuss.elastic.co/t/unable-to-create-a-new-field-in-logstash-elasticsearch-please-help/339874 "2023-08-02T00:58:14Z")

</div>

hello sir, I really need an help, I'm new to elasticsearch Kibana but learnt in recent days to understand terms used. I have a Index name "logstash-\*" which receives logs constantly, my task is to filter from all logs …

---

## [Multi-index query returning no results](https://discuss.elastic.co/t/multi-index-query-returning-no-results/339855)

<div class="topic-metadata">

**Author:** [@PedroD](https://discuss.elastic.co/u/PedroD)\
**Replies:** 4\
**Last updated:** [August 2, 2023, 12:01am UTC](https://discuss.elastic.co/t/multi-index-query-returning-no-results/339855 "2023-08-02T00:01:47Z")

</div>

Hey guys, I have 2 different indexes that store information about my users. Both use a hashed version of their id\_number as their doc\_id, I\`m trying to create a query that will look for different fields in both indexes …

---

## [Aggregate latest values of documents](https://discuss.elastic.co/t/aggregate-latest-values-of-documents/339868)

<div class="topic-metadata">

**Author:** [@MrFuxi](https://discuss.elastic.co/u/MrFuxi)\
**Replies:** 0\
**Last updated:** [August 1, 2023, 10:40pm UTC](https://discuss.elastic.co/t/aggregate-latest-values-of-documents/339868 "2023-08-01T22:40:42Z")

</div>

I have items that over the time can go from one category to the other. Each change results in a new document with current state of the item. I'm tying to get run basic analytics based on the latest state of the item li…

---

## [Logstash filtering](https://discuss.elastic.co/t/logstash-filtering/339864)

<div class="topic-metadata">

**Author:** [@Jennifer\_Coley](https://discuss.elastic.co/u/Jennifer_Coley)\
**Replies:** 0\
**Last updated:** [August 1, 2023, 9:45pm UTC](https://discuss.elastic.co/t/logstash-filtering/339864 "2023-08-01T21:45:00Z")

</div>

In my logstash every second logs will update, In a field name "message" consists group of data like '2023-08-01T21:11:54 \<local.info\> web.site.com IncomingMax1\[123\] 2023-08-01 11:10:54,123 INFO 987654321 Message.py 12 I…

---

## [CSV and XLS import to Elastic Cloud](https://discuss.elastic.co/t/csv-and-xls-import-to-elastic-cloud/339120)

<div class="topic-metadata">

**Author:** [@Vog93](https://discuss.elastic.co/u/Vog93)\
**Replies:** 14\
**Last updated:** [August 1, 2023, 9:36pm UTC](https://discuss.elastic.co/t/csv-and-xls-import-to-elastic-cloud/339120 "2023-08-01T21:36:08Z")

</div>

Hello, I would like to automatically integrate some CSV and XLS files into Elastic Cloud. How could I do this?

---

## [How to create a field that filters the data](https://discuss.elastic.co/t/how-to-create-a-field-that-filters-the-data/339861)

<div class="topic-metadata">

**Author:** [@Jennifer\_Coley](https://discuss.elastic.co/u/Jennifer_Coley)\
**Replies:** 0\
**Last updated:** [August 1, 2023, 9:01pm UTC](https://discuss.elastic.co/t/how-to-create-a-field-that-filters-the-data/339861 "2023-08-01T21:01:50Z")

</div>

I have a "message" field contains bulk of data(like customerName,number,address) in logstash, Now I want to create a new field that filter the data contains only word "Incoming Message:" I'm using ELK 8.6.0 I am tryin…

---

## [Can't set my log file timestamp as Time Filter in Kibana](https://discuss.elastic.co/t/cant-set-my-log-file-timestamp-as-time-filter-in-kibana/339628)

<div class="topic-metadata">

**Author:** [@younes-gr](https://discuss.elastic.co/u/younes-gr)\
**Replies:** 7\
**Last updated:** [August 1, 2023, 8:23pm UTC](https://discuss.elastic.co/t/cant-set-my-log-file-timestamp-as-time-filter-in-kibana/339628 "2023-08-01T20:23:52Z")

</div>

I am trying to process my log file in logstash using the following configuration: Example of log file content: 2023-07-15T07:32:01,645 ERROR \[00000003\] :01234567891011 - ERROR: Some error message 2023-07-15T07:32:01,64…

---

## [Indices.fielddata.cache.size will be allocated within heap or outside heap?](https://discuss.elastic.co/t/indices-fielddata-cache-size-will-be-allocated-within-heap-or-outside-heap/339846)

<div class="topic-metadata">

**Author:** [@mannoj87](https://discuss.elastic.co/u/mannoj87)\
**Replies:** 0\
**Last updated:** [August 1, 2023, 6:54pm UTC](https://discuss.elastic.co/t/indices-fielddata-cache-size-will-be-allocated-within-heap-or-outside-heap/339846 "2023-08-01T18:54:49Z")

</div>

Hi Team, Q1). indices.fielddata.cache.size is set as 10% of heap by default. Does it mean it will consider 10% of heap lets say 1.2GB and it will allocate within heap or will it go outside of heap and take from overall …

---

## [Can I update ES mappings to exclude copy\_to?](https://discuss.elastic.co/t/can-i-update-es-mappings-to-exclude-copy-to/339834)

<div class="topic-metadata">

**Author:** [@Vlado](https://discuss.elastic.co/u/Vlado)\
**Replies:** 1\
**Last updated:** [August 1, 2023, 6:34pm UTC](https://discuss.elastic.co/t/can-i-update-es-mappings-to-exclude-copy-to/339834 "2023-08-01T18:34:48Z")

</div>

Hi, What are ES back-compat rules around directives? Say, I have a copy\_to mapping on several fields with data already indexed and wanted to remove the "copy\_to" directive on some of those. Is this allowed? Or is it an…

---

## [How to filter a table based on another table's contents](https://discuss.elastic.co/t/how-to-filter-a-table-based-on-another-tables-contents/338965)

<div class="topic-metadata">

**Author:** [@Dillard\_Coffey](https://discuss.elastic.co/u/Dillard_Coffey)\
**Replies:** 3\
**Last updated:** [August 1, 2023, 6:32pm UTC](https://discuss.elastic.co/t/how-to-filter-a-table-based-on-another-tables-contents/338965 "2023-08-01T18:32:45Z")

</div>

Hello, I am using Kibana 7.10 and am trying to find a way to visualize the relationship that is between two tables of data I have. Table 1 is similar to: +-------------+-------------+------------+---------------+------…

---

## [Separate ELK pattern for log files](https://discuss.elastic.co/t/separate-elk-pattern-for-log-files/339817)

<div class="topic-metadata">

**Author:** [@sanjeev1895](https://discuss.elastic.co/u/sanjeev1895)\
**Replies:** 4\
**Last updated:** [August 1, 2023, 6:14pm UTC](https://discuss.elastic.co/t/separate-elk-pattern-for-log-files/339817 "2023-08-01T18:14:09Z")

</div>

Hi team, Can any one help me to find the solution for my below requirement. I have two apache server and I want to send the apache access and error logs to elk server via filebeat apache module to logstash. I configure…

---

## [Filebeat timestamp not working](https://discuss.elastic.co/t/filebeat-timestamp-not-working/339827)

<div class="topic-metadata">

**Author:** [@McJava1967](https://discuss.elastic.co/u/McJava1967)\
**Replies:** 1\
**Last updated:** [August 1, 2023, 6:05pm UTC](https://discuss.elastic.co/t/filebeat-timestamp-not-working/339827 "2023-08-01T18:05:53Z")

</div>

Hi all. I'm trying to tell Filebeat to use my timestamp, rather than creating one. I'm getting this error: "error": "failed parsing time field \_app.ACTUAL\_TIME='2023-08-01T11:49:09.386Z'", "errorCauses": \[{"error": "f…

---

## [Is new Geometry simplifier (ES 8.9.0) available for direct use?](https://discuss.elastic.co/t/is-new-geometry-simplifier-es-8-9-0-available-for-direct-use/339832)

<div class="topic-metadata">

**Author:** [@Tomas\_Bartek](https://discuss.elastic.co/u/Tomas_Bartek)\
**Replies:** 0\
**Last updated:** [August 1, 2023, 4:33pm UTC](https://discuss.elastic.co/t/is-new-geometry-simplifier-es-8-9-0-available-for-direct-use/339832 "2023-08-01T16:33:47Z")

</div>

Hello ES friends, Is the new Geometry simplifier in ES version 8.9.0. available for direct use or is it only an internally callable feature ? From What's new document, it seems to me that it can be used merely for int…

---

## [Naming convention for ingest pipelines etc](https://discuss.elastic.co/t/naming-convention-for-ingest-pipelines-etc/339480)

<div class="topic-metadata">

**Author:** [@rsk0](https://discuss.elastic.co/u/rsk0)\
**Replies:** 6\
**Last updated:** [August 1, 2023, 3:32pm UTC](https://discuss.elastic.co/t/naming-convention-for-ingest-pipelines-etc/339480 "2023-08-01T15:32:59Z")

</div>

Elastic-Provided Naming Convention :question: Is there a naming convention for ingest pipelines, index templates, component templates, or any other such configuration objects? I see in the docs \[1,2,3,4\] there are examp…

---

## [Elasticsearch for Data Science](https://discuss.elastic.co/t/elasticsearch-for-data-science/339818)

<div class="topic-metadata">

**Author:** [@tmslara.a](https://discuss.elastic.co/u/tmslara.a)\
**Replies:** 0\
**Last updated:** [August 1, 2023, 3:02pm UTC](https://discuss.elastic.co/t/elasticsearch-for-data-science/339818 "2023-08-01T15:02:14Z")

</div>

Hi, Some context. I'm using Elasticsearch and filebeat to store documents. I have 6 fields. One field represents the timestamp and the other 5 are keywords. Two fields correspond to IDs (id\_1 and id\_2). The IDs have man…

[Previous page](https://discuss.elastic.co/tag/none.md?no_tags=true&page=327)

[Next page](https://discuss.elastic.co/tag/none.md?no_tags=true&page=329)
