# \#none

**URL:** https://discuss.elastic.co/tag/none.md?no_tags=true&page=343

[Latest](https://discuss.elastic.co/latest.md) · [Categories](https://discuss.elastic.co/categories.md) · [Tags](https://discuss.elastic.co/tags.md)

**Page:** 344

---

## [Elastic Certified Observaibility Trainning Course - Lab 8.2 & 8.3](https://discuss.elastic.co/t/elastic-certified-observaibility-trainning-course-lab-8-2-8-3/337334)

<div class="topic-metadata">

**Author:** [@Sara\_YB](https://discuss.elastic.co/u/Sara_YB)\
**Replies:** 5\
**Last updated:** [July 11, 2023, 6:55pm UTC](https://discuss.elastic.co/t/elastic-certified-observaibility-trainning-course-lab-8-2-8-3/337334 "2023-07-11T18:55:28Z")

</div>

Course: \<Which course are you asking about?\> Elastic Certified Observaibility Trainning Course Version: \<And which particular version?\> 7.9 Question: \<Please add details here!\> I have a question about stack monitoring…

---

## [Elastic Certified Observaibility Trainning Course - Lab 7.3](https://discuss.elastic.co/t/elastic-certified-observaibility-trainning-course-lab-7-3/337228)

<div class="topic-metadata">

**Author:** [@Sara\_YB](https://discuss.elastic.co/u/Sara_YB)\
**Replies:** 5\
**Last updated:** [July 11, 2023, 6:52pm UTC](https://discuss.elastic.co/t/elastic-certified-observaibility-trainning-course-lab-7-3/337228 "2023-07-11T18:52:17Z")

</div>

Course: \<Which course are you asking about?\> Elastic Certified Observaibility Trainning Course Version: \<And which particular version?\> 7.9 Question: \<Please add details here!\> I am trying to create a snapshot as per …

---

## [What if difference between setting node.roles: \["data\_hot"\] vs node.attr.box\_type: hot?](https://discuss.elastic.co/t/what-if-difference-between-setting-node-roles-data-hot-vs-node-attr-box-type-hot/337766)

<div class="topic-metadata">

**Author:** [@kuldeep\_gupta](https://discuss.elastic.co/u/kuldeep_gupta)\
**Replies:** 3\
**Last updated:** [July 11, 2023, 4:27pm UTC](https://discuss.elastic.co/t/what-if-difference-between-setting-node-roles-data-hot-vs-node-attr-box-type-hot/337766 "2023-07-11T16:27:15Z")

</div>

What is the difference between node.roles:\["data\_hot"\] vs node.attr.box\_type: hot.

---

## [Invalid FieldReference: \`\_Domain\_Labels\[0\]\_ULabel\`](https://discuss.elastic.co/t/invalid-fieldreference-domain-labels-0-ulabel/337016)

<div class="topic-metadata">

**Author:** [@tcapp24](https://discuss.elastic.co/u/tcapp24)\
**Replies:** 5\
**Last updated:** [July 11, 2023, 3:50pm UTC](https://discuss.elastic.co/t/invalid-fieldreference-domain-labels-0-ulabel/337016 "2023-07-11T15:50:13Z")

</div>

Logstash version - 7.17.8 Currently we are seeing invalid FieldReference errors on our Logstash nodes dealing with \_Domain\_Labels\[0\]\_ULabel onf.d/mulesoft/get\_cloudhub\_app\_logs.conf"\], :thread=\>"#\<Thread:0x1475cac0 run\>…

---

## [Starting Elasticsearch failed](https://discuss.elastic.co/t/starting-elasticsearch-failed/337616)

<div class="topic-metadata">

**Author:** [@stephane\_chan](https://discuss.elastic.co/u/stephane_chan)\
**Replies:** 4\
**Last updated:** [July 11, 2023, 2:43pm UTC](https://discuss.elastic.co/t/starting-elasticsearch-failed/337616 "2023-07-11T14:43:07Z")

</div>

Hi, Why does the elasticsearch.service status always give me this every time I start/restart my server? . ● elasticsearch.service - Elasticsearch Loaded: loaded (/lib/systemd/system/elasticsearch.service; enabled;…

---

## [Using the transform feature for summarizing APM indexes](https://discuss.elastic.co/t/using-the-transform-feature-for-summarizing-apm-indexes/338118)

<div class="topic-metadata">

**Author:** [@Mohammad\_Mousavi](https://discuss.elastic.co/u/Mohammad_Mousavi)\
**Replies:** 0\
**Last updated:** [July 11, 2023, 2:27pm UTC](https://discuss.elastic.co/t/using-the-transform-feature-for-summarizing-apm-indexes/338118 "2023-07-11T14:27:23Z")

</div>

I have elasticsearch version 7.17.1 and our applications are integrated with APM server to send metrics. The problem that we have is it generates heavy indexes, and we want to have old data as well. I thought maybe I ca…

---

## [What mapping or structure should I use for an index that will have very varying fields per document?](https://discuss.elastic.co/t/what-mapping-or-structure-should-i-use-for-an-index-that-will-have-very-varying-fields-per-document/338114)

<div class="topic-metadata">

**Author:** [@Bart\_de\_Man](https://discuss.elastic.co/u/Bart_de_Man)\
**Replies:** 0\
**Last updated:** [July 11, 2023, 2:03pm UTC](https://discuss.elastic.co/t/what-mapping-or-structure-should-i-use-for-an-index-that-will-have-very-varying-fields-per-document/338114 "2023-07-11T14:03:04Z")

</div>

Hi there! As per title; i'd like to have an index which will have very different fields per document. How should I approach this task? What does the mapping look like, if any. Short example of what i'd like to acchieve…

---

## [Documentation on pushing a custom agent to Elastic packages artifactory](https://discuss.elastic.co/t/documentation-on-pushing-a-custom-agent-to-elastic-packages-artifactory/338000)

<div class="topic-metadata">

**Author:** [@hari\_ibm](https://discuss.elastic.co/u/hari_ibm)\
**Replies:** 6\
**Last updated:** [July 11, 2023, 1:45pm UTC](https://discuss.elastic.co/t/documentation-on-pushing-a-custom-agent-to-elastic-packages-artifactory/338000 "2023-07-11T13:45:21Z")

</div>

I would like to develop an custom agent and push to our own Elastic packages artifactory

---

## [Suggestion based on a real use case:](https://discuss.elastic.co/t/suggestion-based-on-a-real-use-case/338109)

<div class="topic-metadata">

**Author:** [@btsinfo](https://discuss.elastic.co/u/btsinfo)\
**Replies:** 0\
**Last updated:** [July 11, 2023, 1:29pm UTC](https://discuss.elastic.co/t/suggestion-based-on-a-real-use-case/338109 "2023-07-11T13:29:52Z")

</div>

We have observed that the APM application uses the datastream "metrics-apm.\*" to display metrics with transaction names in the application. However, one of the strengths of Elastic is the ability to customize transaction…

---

## [Transferring a writable index from one cluster to another](https://discuss.elastic.co/t/transferring-a-writable-index-from-one-cluster-to-another/337934)

<div class="topic-metadata">

**Author:** [@Aditya\_Teltia](https://discuss.elastic.co/u/Aditya_Teltia)\
**Replies:** 15\
**Last updated:** [July 11, 2023, 11:35am UTC](https://discuss.elastic.co/t/transferring-a-writable-index-from-one-cluster-to-another/337934 "2023-07-11T11:35:10Z")

</div>

I am trying to migrate writable indices from one cluster to another. I wanted to know what could possibly the best approach for doing this. Currently I am doing it as follows : Phase1 -\> Before taking snapshot of init…

---

## [Adjusting timezone in Fields in index pattern](https://discuss.elastic.co/t/adjusting-timezone-in-fields-in-index-pattern/337995)

<div class="topic-metadata">

**Author:** [@Sandeep\_Raju](https://discuss.elastic.co/u/Sandeep_Raju)\
**Replies:** 1\
**Last updated:** [July 11, 2023, 9:07am UTC](https://discuss.elastic.co/t/adjusting-timezone-in-fields-in-index-pattern/337995 "2023-07-11T09:07:07Z")

</div>

Hi , I'm using Kibana 7.10 One of the time fields i'm using is showing a +5.30 hrs time. i.e showing a future time. I think its a timezone error & I want to clear this error in Kibana index pattern field settings. So …

---

## [Sysdig integration with ELK](https://discuss.elastic.co/t/sysdig-integration-with-elk/338057)

<div class="topic-metadata">

**Author:** [@pennywise01](https://discuss.elastic.co/u/pennywise01)\
**Replies:** 2\
**Last updated:** [July 11, 2023, 6:47am UTC](https://discuss.elastic.co/t/sysdig-integration-with-elk/338057 "2023-07-11T06:47:35Z")

</div>

Hi all, i am trying to intergrate sysdig with ELK stack. I am following a tutorial from a blog. I already configured logstash to put the log into elasticsearch but i got an error. \> Blockquote \[ERROR\] 2023-07-11 05:45:…

---

## [Why isElectionQuorum need lastCommitedConfiguration and lastAcceptedConfiguration all pass?](https://discuss.elastic.co/t/why-iselectionquorum-need-lastcommitedconfiguration-and-lastacceptedconfiguration-all-pass/338048)

<div class="topic-metadata">

**Author:** [@cm\_z](https://discuss.elastic.co/u/cm_z)\
**Replies:** 1\
**Last updated:** [July 11, 2023, 6:43am UTC](https://discuss.elastic.co/t/why-iselectionquorum-need-lastcommitedconfiguration-and-lastacceptedconfiguration-all-pass/338048 "2023-07-11T06:43:01Z")

</div>

Why does Elasticsearch need to check if both lastAcceptedConfiguration and lastCommitedConfiguration are over the majority threshold when deciding whether to start an election? What is the reasoning behind this, and are …

---

## [Logstash automatic shutdown normal](https://discuss.elastic.co/t/logstash-automatic-shutdown-normal/337946)

<div class="topic-metadata">

**Author:** [@lz840408](https://discuss.elastic.co/u/lz840408)\
**Replies:** 2\
**Last updated:** [July 11, 2023, 2:44am UTC](https://discuss.elastic.co/t/logstash-automatic-shutdown-normal/337946 "2023-07-11T02:44:48Z")

</div>

logstash: 7.17.9 cfg file: input { elasticsearch { hosts =\> \["10.251.0.11:39202"\] index =\> "new\_index\_001" docinfo =\> true scroll =\> "30s" size =\> 500 } } filter { mutate { remove\_field =\> \["…

---

## [Overwriting a whole index without downtime best practices](https://discuss.elastic.co/t/overwriting-a-whole-index-without-downtime-best-practices/338039)

<div class="topic-metadata">

**Author:** [@krezno](https://discuss.elastic.co/u/krezno)\
**Replies:** 1\
**Last updated:** [July 10, 2023, 9:15pm UTC](https://discuss.elastic.co/t/overwriting-a-whole-index-without-downtime-best-practices/338039 "2023-07-10T21:15:46Z")

</div>

I have several batch pipelines that produce a new version of the result each time. The data can't have any downtime so I can't just delete the index before writing. The current solution is to create a new index with the …

---

## [UNASSIGNED state after REPLICA\_ADDED](https://discuss.elastic.co/t/unassigned-state-after-replica-added/336326)

<div class="topic-metadata">

**Author:** [@Itay\_Bittan](https://discuss.elastic.co/u/Itay_Bittan)\
**Replies:** 24\
**Last updated:** [July 10, 2023, 8:31pm UTC](https://discuss.elastic.co/t/unassigned-state-after-replica-added/336326 "2023-07-10T20:31:54Z")

</div>

We are indexing around 7TB on a daily basis. All the indices are being replaced once a day with a new ones (fresh data). Each index represent one customer (business). The variety of indices is big, from a few kilobyte…

---

## [Kibana filtering issue](https://discuss.elastic.co/t/kibana-filtering-issue/336880)

<div class="topic-metadata">

**Author:** [@VirusProtect](https://discuss.elastic.co/u/VirusProtect)\
**Replies:** 1\
**Last updated:** [July 10, 2023, 5:37pm UTC](https://discuss.elastic.co/t/kibana-filtering-issue/336880 "2023-07-10T17:37:22Z")

</div>

When I search for a value, it is only able to find it in the message field. If I specify the field name using the format 'field\_name: value', it works fine. How can I solve this issue so that I can simply type the value …

---

## [403 in Discover View](https://discuss.elastic.co/t/403-in-discover-view/336981)

<div class="topic-metadata">

**Author:** [@lenn\_rt](https://discuss.elastic.co/u/lenn_rt)\
**Replies:** 1\
**Last updated:** [July 10, 2023, 5:35pm UTC](https://discuss.elastic.co/t/403-in-discover-view/336981 "2023-07-10T17:35:14Z")

</div>

Hey, we trying to implement the ELK Stack (8.7.1) in an AKS via Helm Charts. We are using an NGINX controller to reverse proxy our request and are loadbalancing the requests with an application gateway. We are able to r…

---

## [Search\_phase\_execution\_exception: \[no\_shard\_available\_action\_exception\] Reason: null; \[no\_shard\_available\_action\_exception\] Reason: null (500)](https://discuss.elastic.co/t/search-phase-execution-exception-no-shard-available-action-exception-reason-null-no-shard-available-action-exception-reason-null-500/338003)

<div class="topic-metadata">

**Author:** [@Indeed2000](https://discuss.elastic.co/u/Indeed2000)\
**Replies:** 2\
**Last updated:** [July 10, 2023, 5:28pm UTC](https://discuss.elastic.co/t/search-phase-execution-exception-no-shard-available-action-exception-reason-null-no-shard-available-action-exception-reason-null-500/338003 "2023-07-10T17:28:56Z")

</div>

Hi after i've receive disk full i try to remove some indices from this path: /opt/elasticsearch/var/lib/elasticsearch/indices/ after that APM dashboard not load and give below errors. seems some indices that related t…

---

## [Elastic Observability Lab 2.2 Error](https://discuss.elastic.co/t/elastic-observability-lab-2-2-error/338035)

<div class="topic-metadata">

**Author:** [@AmitKakkad](https://discuss.elastic.co/u/AmitKakkad)\
**Replies:** 1\
**Last updated:** [July 10, 2023, 4:36pm UTC](https://discuss.elastic.co/t/elastic-observability-lab-2-2-error/338035 "2023-07-10T16:36:46Z")

</div>

Course: Elastic Observability Engineer 7.9 (On-Demand) Version: \<And which particular version?\> Question: Elastic Observability Lab 2.2 Error Hello. I have this in the myql yaml: Module: mysql Docs: MySQL module | M…

---

## [Unable to see console logs in Elastic Synthetics](https://discuss.elastic.co/t/unable-to-see-console-logs-in-elastic-synthetics/337195)

<div class="topic-metadata">

**Author:** [@Dmitriy.SDET](https://discuss.elastic.co/u/Dmitriy.SDET)\
**Replies:** 3\
**Last updated:** [July 10, 2023, 3:43pm UTC](https://discuss.elastic.co/t/unable-to-see-console-logs-in-elastic-synthetics/337195 "2023-07-10T15:43:36Z")

</div>

Hello. We are moving our monitors from New Relic to Elastic (as inline journeys). Why can't we see console logs in the "Console" tab? What is this tab for? Should we use something else instead of console.log()? For exam…

---

## [Issue on Lab 2.2](https://discuss.elastic.co/t/issue-on-lab-2-2/338032)

<div class="topic-metadata">

**Author:** [@AmitKakkad](https://discuss.elastic.co/u/AmitKakkad)\
**Replies:** 1\
**Last updated:** [July 10, 2023, 3:04pm UTC](https://discuss.elastic.co/t/issue-on-lab-2-2/338032 "2023-07-10T15:04:19Z")

</div>

Hello. I have this in the myql yaml: Module: mysql Docs: MySQL module | Metricbeat Reference \[7.9\] | Elastic module: mysql metricsets: status - galera\_status - performance - query period: 10s Host DSN should be d…

---

## [Running Logstash on multiple servers, avoiding double processing](https://discuss.elastic.co/t/running-logstash-on-multiple-servers-avoiding-double-processing/337780)

<div class="topic-metadata">

**Author:** [@BenSeb](https://discuss.elastic.co/u/BenSeb)\
**Replies:** 1\
**Last updated:** [July 10, 2023, 3:00pm UTC](https://discuss.elastic.co/t/running-logstash-on-multiple-servers-avoiding-double-processing/337780 "2023-07-10T15:00:20Z")

</div>

Hi We have logstash running on our worker servers, and they run with an identical config, to ensure if one hosts goes down, we are still processing events. The source data is Mysql, then logstash pushes the latest reco…

---

## [When Search goes to Replica shard?](https://discuss.elastic.co/t/when-search-goes-to-replica-shard/338021)

<div class="topic-metadata">

**Author:** [@siddhartha\_c](https://discuss.elastic.co/u/siddhartha_c)\
**Replies:** 4\
**Last updated:** [July 10, 2023, 2:52pm UTC](https://discuss.elastic.co/t/when-search-goes-to-replica-shard/338021 "2023-07-10T14:52:01Z")

</div>

I have a scenario , wherein I would need to perform searches in Elastic , but the number of "concurrent searches" are very less. In this case , can I assume that the searches will go to Primary shards? My understanding …

---

## [Recognition of similar words in a search?](https://discuss.elastic.co/t/recognition-of-similar-words-in-a-search/337311)

<div class="topic-metadata">

**Author:** [@Paul-III](https://discuss.elastic.co/u/Paul-III)\
**Replies:** 1\
**Last updated:** [July 10, 2023, 2:32pm UTC](https://discuss.elastic.co/t/recognition-of-similar-words-in-a-search/337311 "2023-07-10T14:32:46Z")

</div>

Is Elastic Search able to recognize that search for housedoor is the same as search for house door and so delivering results for both?

---

## [Nodes orchestration with ECK while upgrading to newer versions of Elasticsearch, Kibana etc](https://discuss.elastic.co/t/nodes-orchestration-with-eck-while-upgrading-to-newer-versions-of-elasticsearch-kibana-etc/337898)

<div class="topic-metadata">

**Author:** [@sebastianboelling](https://discuss.elastic.co/u/sebastianboelling)\
**Replies:** 2\
**Last updated:** [July 10, 2023, 2:26pm UTC](https://discuss.elastic.co/t/nodes-orchestration-with-eck-while-upgrading-to-newer-versions-of-elasticsearch-kibana-etc/337898 "2023-07-10T14:26:23Z")

</div>

Hi Community, I have an experimantal Elastic environment deployed on a Kubernetes cluster and I am working with ECK 2.8.0 and the orchestrator. My stack consists of Elasticsearch 2 master nodes and 2 data nodes and 2 ml…

---

## [Reindexed Documents are not showing up, Response says it has created but it does not show up in destination index](https://discuss.elastic.co/t/reindexed-documents-are-not-showing-up-response-says-it-has-created-but-it-does-not-show-up-in-destination-index/337987)

<div class="topic-metadata">

**Author:** [@Aditya\_Teltia](https://discuss.elastic.co/u/Aditya_Teltia)\
**Replies:** 9\
**Last updated:** [July 10, 2023, 2:15pm UTC](https://discuss.elastic.co/t/reindexed-documents-are-not-showing-up-response-says-it-has-created-but-it-does-not-show-up-in-destination-index/337987 "2023-07-10T14:15:13Z")

</div>

http://localhost:9201/restored\_index/\_search Response: { "took": 2, "timed\_out": false, "\_shards": { "total": 1, "successful": 1, "skipped": 0, "failed": 0 }, "hits":…

---

## [Creating Alerts for rollup jobs](https://discuss.elastic.co/t/creating-alerts-for-rollup-jobs/338030)

<div class="topic-metadata">

**Author:** [@akhil\_reddy](https://discuss.elastic.co/u/akhil_reddy)\
**Replies:** 0\
**Last updated:** [July 10, 2023, 1:47pm UTC](https://discuss.elastic.co/t/creating-alerts-for-rollup-jobs/338030 "2023-07-10T13:47:16Z")

</div>

Hi, Is it possible to get alerts for rollup jobs. If I schedule my rollup job to trigger for every hour, can I get alerts for the stats in rollup jobs. Ex: an alert for number of documents processed and number of rollup…

---

## [Logstash issues when writing from s3 to elastic](https://discuss.elastic.co/t/logstash-issues-when-writing-from-s3-to-elastic/338014)

<div class="topic-metadata">

**Author:** [@Keren\_Cohen](https://discuss.elastic.co/u/Keren_Cohen)\
**Replies:** 2\
**Last updated:** [July 10, 2023, 1:09pm UTC](https://discuss.elastic.co/t/logstash-issues-when-writing-from-s3-to-elastic/338014 "2023-07-10T13:09:53Z")

</div>

Hi, I am trying to write logs from AWS s3 bucket and write them to elastic. I'm using logstash 7.17 and get the following error: /usr/share/logstash/vendor/bundle/jruby/2.5.0/gems/aws-sdk-core-2.11.632/lib/seahorse/cl…

---

## [System.auth.ssh.event field not created](https://discuss.elastic.co/t/system-auth-ssh-event-field-not-created/338027)

<div class="topic-metadata">

**Author:** [@Nishant\_Chauhan](https://discuss.elastic.co/u/Nishant_Chauhan)\
**Replies:** 0\
**Last updated:** [July 10, 2023, 12:41pm UTC](https://discuss.elastic.co/t/system-auth-ssh-event-field-not-created/338027 "2023-07-10T12:41:59Z")

</div>

I installed "System" Integration into a policy. however ssh dashboard is not working. \[root@elastic-agent-8-nis elastic-agent-8.7.1-linux-x86\_64\]# sudo elastic-agent status State: HEALTHY Message: Running Fleet St…

[Previous page](https://discuss.elastic.co/tag/none.md?no_tags=true&page=342)

[Next page](https://discuss.elastic.co/tag/none.md?no_tags=true&page=344)
