# \#none

**URL:** https://discuss.elastic.co/tag/none.md?no_tags=true&page=336

[Latest](https://discuss.elastic.co/latest.md) · [Categories](https://discuss.elastic.co/categories.md) · [Tags](https://discuss.elastic.co/tags.md)

**Page:** 337

---

## [Monitor indexes from ELK with monitoring feature enabled](https://discuss.elastic.co/t/monitor-indexes-from-elk-with-monitoring-feature-enabled/338724)

<div class="topic-metadata">

**Author:** [@dominbdg](https://discuss.elastic.co/u/dominbdg)\
**Replies:** 2\
**Last updated:** [July 20, 2023, 11:17pm UTC](https://discuss.elastic.co/t/monitor-indexes-from-elk-with-monitoring-feature-enabled/338724 "2023-07-20T23:17:57Z")

</div>

Hello I deployed ELK Monitoring Cluster (ELK with feature of monitoring enabled ) and I have couple of other clusters with metricbeat connecting to elasticsearch on it. I would like to implement rule that when in index…

---

## [Mocking an Aggregation](https://discuss.elastic.co/t/mocking-an-aggregation/338363)

<div class="topic-metadata">

**Author:** [@silentfilm](https://discuss.elastic.co/u/silentfilm)\
**Replies:** 1\
**Last updated:** [July 20, 2023, 8:14pm UTC](https://discuss.elastic.co/t/mocking-an-aggregation/338363 "2023-07-20T20:14:29Z")

</div>

I'm trying to mock an Aggregation result for a Unit Test. var mockedSearchResponse = SearchResponse.of(r -\> r .took(10) .timedOut(false) .hits(h -\> h …

---

## [String\_query doesn't respond to some characters](https://discuss.elastic.co/t/string-query-doesnt-respond-to-some-characters/338567)

<div class="topic-metadata">

**Author:** [@y34rz3r0](https://discuss.elastic.co/u/y34rz3r0)\
**Replies:** 2\
**Last updated:** [July 20, 2023, 7:40pm UTC](https://discuss.elastic.co/t/string-query-doesnt-respond-to-some-characters/338567 "2023-07-20T19:40:03Z")

</div>

Hello! I have a misunderstanding of how string\_query works. Index creating: PUT \_index\_template/test { "priority": 500, "template": { "settings": { "index.default\_pipeline": "set-timestamp" }, "ma…

---

## [Help with aggregation code](https://discuss.elastic.co/t/help-with-aggregation-code/338794)

<div class="topic-metadata">

**Author:** [@vymk](https://discuss.elastic.co/u/vymk)\
**Replies:** 3\
**Last updated:** [July 20, 2023, 4:22pm UTC](https://discuss.elastic.co/t/help-with-aggregation-code/338794 "2023-07-20T16:22:21Z")

</div>

We process mails through multiple modules resulting in logs with the same mail\_id, kinda like this: mail\_id\_X module1: key1 key2 mail\_id\_X module2: key3 key4 mail\_id\_X module3: key5 key6 key7 What I would like to do …

---

## [Elastic Agent to OpenTelemetry Collector](https://discuss.elastic.co/t/elastic-agent-to-opentelemetry-collector/338789)

<div class="topic-metadata">

**Author:** [@chadr](https://discuss.elastic.co/u/chadr)\
**Replies:** 3\
**Last updated:** [July 20, 2023, 4:15pm UTC](https://discuss.elastic.co/t/elastic-agent-to-opentelemetry-collector/338789 "2023-07-20T16:15:34Z")

</div>

Hi all, I am researching the capabilities of the current and future roadmap for the Elastic Agent. We have a very diverse infra/app/coding language environment. Specifically, I looking to understand if the Elastic Age…

---

## [Best disk modes for data nodes (VMVare ESX)](https://discuss.elastic.co/t/best-disk-modes-for-data-nodes-vmvare-esx/338898)

<div class="topic-metadata">

**Author:** [@alissan](https://discuss.elastic.co/u/alissan)\
**Replies:** 0\
**Last updated:** [July 20, 2023, 3:57pm UTC](https://discuss.elastic.co/t/best-disk-modes-for-data-nodes-vmvare-esx/338898 "2023-07-20T15:57:44Z")

</div>

I need to create a cluster on vmware esx with 60 data nodes. Every node have 100GB disk for OS and 10TB disk (SSD) with for data fiber channel. I'm looking for best vmware disk mode option for data nodes. There are 3 o…

---

## [Streamingbulk vs parallel bulk](https://discuss.elastic.co/t/streamingbulk-vs-parallel-bulk/338895)

<div class="topic-metadata">

**Author:** [@Vivek\_Burman](https://discuss.elastic.co/u/Vivek_Burman)\
**Replies:** 0\
**Last updated:** [July 20, 2023, 3:02pm UTC](https://discuss.elastic.co/t/streamingbulk-vs-parallel-bulk/338895 "2023-07-20T15:02:44Z")

</div>

Hi, I've stumbled upon a case where I see one of my index goes to RED state and taking ES down with it. Here are the JVM options I've set it to. -Xms10g -Xmx10g In my case I need to migrate around 6lakh of data from …

---

## [Unable to login to kibana with valid elastic user credentials after few days](https://discuss.elastic.co/t/unable-to-login-to-kibana-with-valid-elastic-user-credentials-after-few-days/338785)

<div class="topic-metadata">

**Author:** [@shiva\_ratnavarapu](https://discuss.elastic.co/u/shiva_ratnavarapu)\
**Replies:** 1\
**Last updated:** [July 20, 2023, 2:50pm UTC](https://discuss.elastic.co/t/unable-to-login-to-kibana-with-valid-elastic-user-credentials-after-few-days/338785 "2023-07-20T14:50:50Z")

</div>

Kibana version: kibana:8.5.1 Elasticsearch version: elasticsearch:8.5.1 We have installed the elasticsearch and kibana using helm chart. Post installation able to access kibana with elasticsearch credentials user/pass…

---

## [Re-indexing ElasticSearch](https://discuss.elastic.co/t/re-indexing-elasticsearch/338816)

<div class="topic-metadata">

**Author:** [@randallkiddsr](https://discuss.elastic.co/u/randallkiddsr)\
**Replies:** 4\
**Last updated:** [July 20, 2023, 2:38pm UTC](https://discuss.elastic.co/t/re-indexing-elasticsearch/338816 "2023-07-20T14:38:40Z")

</div>

I am trying to get clarity on the necessity and steps to re indexing Elasticsearch. After performing a search on one account, that account is coming up blank.

---

## [Kibana - Sending email from Microsoft Exchange with Certificate Auth](https://discuss.elastic.co/t/kibana-sending-email-from-microsoft-exchange-with-certificate-auth/338892)

<div class="topic-metadata">

**Author:** [@jsoule6](https://discuss.elastic.co/u/jsoule6)\
**Replies:** 0\
**Last updated:** [July 20, 2023, 2:19pm UTC](https://discuss.elastic.co/t/kibana-sending-email-from-microsoft-exchange-with-certificate-auth/338892 "2023-07-20T14:19:05Z")

</div>

Hello, We are trying to use the Kibana integration with Microsoft Exchange. We are being told that the requirement is to use certificate based authentication instead of the clientSecret string. Is there a supported way …

---

## [Couldn't configure Elastic Retry or update the kibana.yml file manually](https://discuss.elastic.co/t/couldnt-configure-elastic-retry-or-update-the-kibana-yml-file-manually/338624)

<div class="topic-metadata">

**Author:** [@Aditya\_Bollam](https://discuss.elastic.co/u/Aditya_Bollam)\
**Replies:** 31\
**Last updated:** [July 20, 2023, 2:00pm UTC](https://discuss.elastic.co/t/couldnt-configure-elastic-retry-or-update-the-kibana-yml-file-manually/338624 "2023-07-20T14:00:09Z")

</div>

even after editing manually same problem is persisiting.

---

## ["\[my\_s3\_repo\] path is not accessible on master node](https://discuss.elastic.co/t/my-s3-repo-path-is-not-accessible-on-master-node/338885)

<div class="topic-metadata">

**Author:** [@Samuel\_Emmanuel](https://discuss.elastic.co/u/Samuel_Emmanuel)\
**Replies:** 0\
**Last updated:** [July 20, 2023, 1:32pm UTC](https://discuss.elastic.co/t/my-s3-repo-path-is-not-accessible-on-master-node/338885 "2023-07-20T13:32:08Z")

</div>

I am trying to setup a repository using minIO s3 bucket to implement a snapshot for my Elasticsearch running in a kubernetes cluster, but I encountered the error as seen below on kibana dev too. { "error" : { "roo…

---

## [ILM rollover](https://discuss.elastic.co/t/ilm-rollover/338771)

<div class="topic-metadata">

**Author:** [@kruzadmn](https://discuss.elastic.co/u/kruzadmn)\
**Replies:** 12\
**Last updated:** [July 20, 2023, 1:20pm UTC](https://discuss.elastic.co/t/ilm-rollover/338771 "2023-07-20T13:20:51Z")

</div>

Hi! Please help me. I have configured ILM to rollover the index when it reaches 120GB or 7 days. I have a problem that ILM does not rollover the index because it thinks that the index size is for example 117GB, when in …

---

## [Kibana Alerts](https://discuss.elastic.co/t/kibana-alerts/338844)

<div class="topic-metadata">

**Author:** [@schandup](https://discuss.elastic.co/u/schandup)\
**Replies:** 1\
**Last updated:** [July 20, 2023, 1:16pm UTC](https://discuss.elastic.co/t/kibana-alerts/338844 "2023-07-20T13:16:30Z")

</div>

Hi, Can you help how to setup an alert in Kibana. We could see "Transaction not found" exception response in Kibana logs for one particular transaction. So, I would like to set up an in alert in Kibana if this exception…

---

## [ElasticsearchClient GetRecordsRequest examples?](https://discuss.elastic.co/t/elasticsearchclient-getrecordsrequest-examples/338820)

<div class="topic-metadata">

**Author:** [@McJava1967](https://discuss.elastic.co/u/McJava1967)\
**Replies:** 1\
**Last updated:** [July 20, 2023, 12:57pm UTC](https://discuss.elastic.co/t/elasticsearchclient-getrecordsrequest-examples/338820 "2023-07-20T12:57:05Z")

</div>

Hi all. Could anyone point me to examples of using the Java ElasticsearchClient GetRecordsRequest to return results from \_ml/anomaly\_detectors? Thanks!

---

## [Requirement for designing elastic search in aws](https://discuss.elastic.co/t/requirement-for-designing-elastic-search-in-aws/338879)

<div class="topic-metadata">

**Author:** [@uma\_parvathy](https://discuss.elastic.co/u/uma_parvathy)\
**Replies:** 0\
**Last updated:** [July 20, 2023, 12:35pm UTC](https://discuss.elastic.co/t/requirement-for-designing-elastic-search-in-aws/338879 "2023-07-20T12:35:23Z")

</div>

Hi All, I've asked to design a Elasticsearch for my project . I'm a new joiner to my project and new to Elasticsearch. I saw minimum requirement as such 8 GM Ram,4 CPU core, and 50 Gb disk space with 1 GBps network …

---

## [ElasticSearch Index Storage Optimization - Firewall Logs](https://discuss.elastic.co/t/elasticsearch-index-storage-optimization-firewall-logs/338410)

<div class="topic-metadata">

**Author:** [@viera120](https://discuss.elastic.co/u/viera120)\
**Replies:** 9\
**Last updated:** [July 20, 2023, 11:51am UTC](https://discuss.elastic.co/t/elasticsearch-index-storage-optimization-firewall-logs/338410 "2023-07-20T11:51:59Z")

</div>

We are running a 3 node cluster to index logs from a firewall. The nodes are physical machines (20 Core CPUs, 16GB RAM, SSD Storage). Each days logs are stored in an individual index. The storage utilized per index wor…

---

## [Show documents with a last value greater than a number and drop all other documents from the selection](https://discuss.elastic.co/t/show-documents-with-a-last-value-greater-than-a-number-and-drop-all-other-documents-from-the-selection/338783)

<div class="topic-metadata">

**Author:** [@zafire](https://discuss.elastic.co/u/zafire)\
**Replies:** 3\
**Last updated:** [July 20, 2023, 10:42am UTC](https://discuss.elastic.co/t/show-documents-with-a-last-value-greater-than-a-number-and-drop-all-other-documents-from-the-selection/338783 "2023-07-20T10:42:03Z")

</div>

Hi all. First post here, so hope I am doing it right. I have an index of servers and mounted disks (from metricbeat) that has a percent used value, system.filesystem.used.pct and system.filesystem.mount\_point. I want …

---

## [Multi-cluster installation, cluster loss and recovery](https://discuss.elastic.co/t/multi-cluster-installation-cluster-loss-and-recovery/338858)

<div class="topic-metadata">

**Author:** [@Christophe\_DAME](https://discuss.elastic.co/u/Christophe_DAME)\
**Replies:** 4\
**Last updated:** [July 20, 2023, 10:00am UTC](https://discuss.elastic.co/t/multi-cluster-installation-cluster-loss-and-recovery/338858 "2023-07-20T10:00:13Z")

</div>

Hi there, As I'm new, I'll introduce myself quickly : I'm Christophe Dame and I'm working for Camunda. Our solution embarks an Elasticsearch 7.17 and I'm currently experimenting a dual cluster setup. Ideally, my goal w…

---

## [How to check if the index was merged or not](https://discuss.elastic.co/t/how-to-check-if-the-index-was-merged-or-not/338866)

<div class="topic-metadata">

**Author:** [@yuswanul](https://discuss.elastic.co/u/yuswanul)\
**Replies:** 0\
**Last updated:** [July 20, 2023, 9:33am UTC](https://discuss.elastic.co/t/how-to-check-if-the-index-was-merged-or-not/338866 "2023-07-20T09:33:27Z")

</div>

Hi there, from this discuss, i know that elastic will check continuously to see if the index needs merging or not. but what parameter i can check, so i can makesure that the index was merged. is that by using this API? …

---

## [Elastics Syntherics Push 800KB limit](https://discuss.elastic.co/t/elastics-syntherics-push-800kb-limit/338796)

<div class="topic-metadata">

**Author:** [@Bill\_Voudouris](https://discuss.elastic.co/u/Bill_Voudouris)\
**Replies:** 3\
**Last updated:** [July 20, 2023, 8:13am UTC](https://discuss.elastic.co/t/elastics-syntherics-push-800kb-limit/338796 "2023-07-20T08:13:48Z")

</div>

Hello, I've setup an elastics synthetics project but when I import Then there is an error while pushing it using the cmd: npx @elastic/synthetics push Error Message: Error: You have monitors whose size exceeds th…

---

## ["cluster.routing.allocation.enable": "primaries"](https://discuss.elastic.co/t/cluster-routing-allocation-enable-primaries/338855)

<div class="topic-metadata">

**Author:** [@mannoj87](https://discuss.elastic.co/u/mannoj87)\
**Replies:** 0\
**Last updated:** [July 20, 2023, 7:58am UTC](https://discuss.elastic.co/t/cluster-routing-allocation-enable-primaries/338855 "2023-07-20T07:58:33Z")

</div>

Hi Team, "cluster.routing.allocation.enable": "primaries" In reality does it mean which ever primaries Node is unavailable the cluster will turn its related replica to become primary in that same replica node. There is…

---

## [Kibana Control With Static options](https://discuss.elastic.co/t/kibana-control-with-static-options/338824)

<div class="topic-metadata">

**Author:** [@OscarFilho](https://discuss.elastic.co/u/OscarFilho)\
**Replies:** 1\
**Last updated:** [July 20, 2023, 6:45am UTC](https://discuss.elastic.co/t/kibana-control-with-static-options/338824 "2023-07-20T06:45:35Z")

</div>

Hello! I have a dashboard and would like to add a dropdown field with static options (to make it easier for users to select only what they need). It's possible? If yes, how can I do it? Tks in advance.

---

## [Bypass Login Page](https://discuss.elastic.co/t/bypass-login-page/337047)

<div class="topic-metadata">

**Author:** [@fenixon](https://discuss.elastic.co/u/fenixon)\
**Replies:** 2\
**Last updated:** [July 20, 2023, 6:39am UTC](https://discuss.elastic.co/t/bypass-login-page/337047 "2023-07-20T06:39:26Z")

</div>

I want to bypass this login page Can i pass username and password through URL

---

## [Fluentd doesnt send log to elasticsearch](https://discuss.elastic.co/t/fluentd-doesnt-send-log-to-elasticsearch/337619)

<div class="topic-metadata">

**Author:** [@gurban.suleyman](https://discuss.elastic.co/u/gurban.suleyman)\
**Replies:** 6\
**Last updated:** [July 20, 2023, 5:30am UTC](https://discuss.elastic.co/t/fluentd-doesnt-send-log-to-elasticsearch/337619 "2023-07-20T05:30:48Z")

</div>

Hi I have a problem it is about to send logs to elasticsearch. I had configure the conf file ind the server but in elastic i couldnt see any log even in the Discover menu

---

## [Combining 3 logs into one](https://discuss.elastic.co/t/combining-3-logs-into-one/338832)

<div class="topic-metadata">

**Author:** [@Cruz](https://discuss.elastic.co/u/Cruz)\
**Replies:** 1\
**Last updated:** [July 20, 2023, 2:18am UTC](https://discuss.elastic.co/t/combining-3-logs-into-one/338832 "2023-07-20T02:18:15Z")

</div>

I have this 3 events logs that are almost the same. I want to combine the 3 events logs into one log but somehow it won't work. this is my filter aggregate { task\_id =\> "%{\_id}" code =\> " …

---

## [Kibana server is not ready yet kibana.service: Main process exited, code=exited, status=1/FAILURE](https://discuss.elastic.co/t/kibana-server-is-not-ready-yet-kibana-service-main-process-exited-code-exited-status-1-failure/338835)

<div class="topic-metadata">

**Author:** [@Tom\_Ferguson](https://discuss.elastic.co/u/Tom_Ferguson)\
**Replies:** 4\
**Last updated:** [July 20, 2023, 1:44am UTC](https://discuss.elastic.co/t/kibana-server-is-not-ready-yet-kibana-service-main-process-exited-code-exited-status-1-failure/338835 "2023-07-20T01:44:17Z")

</div>

Sorry if this post is repetitive, I did look for this issue and did not see an answer that worked for me. I realize this could turn out to be something fairly simple or even an OSI level 8 error. I can't imaging that I …

---

## [Regarding disk expansion for Elasticsearch Cluster](https://discuss.elastic.co/t/regarding-disk-expansion-for-elasticsearch-cluster/338838)

<div class="topic-metadata">

**Author:** [@klose.foot.baller](https://discuss.elastic.co/u/klose.foot.baller)\
**Replies:** 0\
**Last updated:** [July 20, 2023, 1:30am UTC](https://discuss.elastic.co/t/regarding-disk-expansion-for-elasticsearch-cluster/338838 "2023-07-20T01:30:25Z")

</div>

Hi, We currently have an Elasticsearch (version 6.5) cluster with 3 Azure Virtual Machines. Disk space is getting tight and we would like to improve the situation, but we are wondering what is the best approach to take…

---

## [Output set by field](https://discuss.elastic.co/t/output-set-by-field/338748)

<div class="topic-metadata">

**Author:** [@tbs575](https://discuss.elastic.co/u/tbs575)\
**Replies:** 4\
**Last updated:** [July 20, 2023, 1:29am UTC](https://discuss.elastic.co/t/output-set-by-field/338748 "2023-07-20T01:29:02Z")

</div>

Hi Guys, set logstash output influxdb, as title can out by field. output part like output { influxdb\_v2 { host =\> "10.200.101.18" port =\> "8086" org =\> "icep" token =\> "SIRq-QX3d7ddOI33Z9XfmZETHHGAFj…

---

## [Size reduction after re-indexing from v7 to v8](https://discuss.elastic.co/t/size-reduction-after-re-indexing-from-v7-to-v8/338833)

<div class="topic-metadata">

**Author:** [@Ian\_Simpson](https://discuss.elastic.co/u/Ian_Simpson)\
**Replies:** 0\
**Last updated:** [July 20, 2023, 12:24am UTC](https://discuss.elastic.co/t/size-reduction-after-re-indexing-from-v7-to-v8/338833 "2023-07-20T00:24:27Z")

</div>

I'm migrating from a v7.17.10 cluster to v8.8.2 using the reindex API. I'm seeing that some indices with data from ingested files (docx, pdf mostly) only take up 5% of the space that they used to. I've done a little spot…

[Previous page](https://discuss.elastic.co/tag/none.md?no_tags=true&page=335)

[Next page](https://discuss.elastic.co/tag/none.md?no_tags=true&page=337)
