# \#none

**URL:** https://discuss.elastic.co/tag/none.md?no_tags=true&page=344

[Latest](https://discuss.elastic.co/latest.md) · [Categories](https://discuss.elastic.co/categories.md) · [Tags](https://discuss.elastic.co/tags.md)

**Page:** 345

---

## [ElasticSearch cluster down due to high memory usage](https://discuss.elastic.co/t/elasticsearch-cluster-down-due-to-high-memory-usage/337975)

<div class="topic-metadata">

**Author:** [@maulik\_trapasiya](https://discuss.elastic.co/u/maulik_trapasiya)\
**Replies:** 1\
**Last updated:** [July 10, 2023, 12:32pm UTC](https://discuss.elastic.co/t/elasticsearch-cluster-down-due-to-high-memory-usage/337975 "2023-07-10T12:32:26Z")

</div>

I have ran some queries on ES, which fetched huge amount of data and due to that Memory utilization reached high and ES cluster went down. Below is the error that ES-java client has thrown {"error":{"root\_cause":\[{"typ…

---

## [Transaction is not logging in elastic](https://discuss.elastic.co/t/transaction-is-not-logging-in-elastic/337985)

<div class="topic-metadata">

**Author:** [@sapna\_jain](https://discuss.elastic.co/u/sapna_jain)\
**Replies:** 1\
**Last updated:** [July 10, 2023, 12:18pm UTC](https://discuss.elastic.co/t/transaction-is-not-logging-in-elastic/337985 "2023-07-10T12:18:55Z")

</div>

Hi all, I am using elastic apm version 1.18.0 in dot net core application. In my application ,I am starting transaction, setting labels to transactions and ending the transaction. This I am doing multiple times. I am f…

---

## [What is the function of CPU and Memory for elastic](https://discuss.elastic.co/t/what-is-the-function-of-cpu-and-memory-for-elastic/338017)

<div class="topic-metadata">

**Author:** [@yuswanul](https://discuss.elastic.co/u/yuswanul)\
**Replies:** 0\
**Last updated:** [July 10, 2023, 11:19am UTC](https://discuss.elastic.co/t/what-is-the-function-of-cpu-and-memory-for-elastic/338017 "2023-07-10T11:19:10Z")

</div>

Hi there, just want to confirm, as far as i know. memory is used by elastic for JVM, shard. is it correct? or anything else? and for cpu, what actually elastic does with cpu other than to run the service? your explana…

---

## [The es service on all nodes stops unexpectedly](https://discuss.elastic.co/t/the-es-service-on-all-nodes-stops-unexpectedly/337979)

<div class="topic-metadata">

**Author:** [@alanzc](https://discuss.elastic.co/u/alanzc)\
**Replies:** 1\
**Last updated:** [July 10, 2023, 10:41am UTC](https://discuss.elastic.co/t/the-es-service-on-all-nodes-stops-unexpectedly/337979 "2023-07-10T10:41:58Z")

</div>

When I update openjdk from 1.8-u312 to 1.8-u372, then 12 hours later I got this error from all nodes. Does anyone know the reason? \[2023-07-07T08:47:54,794\]\[ERROR\]\[o.e.b.ElasticsearchUncaughtExceptionHandler\] \[rcvaes01\]…

---

## [How to take the backup of 3months data of elasticsearch?](https://discuss.elastic.co/t/how-to-take-the-backup-of-3months-data-of-elasticsearch/337653)

<div class="topic-metadata">

**Author:** [@merson](https://discuss.elastic.co/u/merson)\
**Replies:** 10\
**Last updated:** [July 10, 2023, 9:28am UTC](https://discuss.elastic.co/t/how-to-take-the-backup-of-3months-data-of-elasticsearch/337653 "2023-07-10T09:28:41Z")

</div>

In elasticsearch, it is runned three months and the size of elk is 40gb then I want to backup the elasticsearch datas. so what to do the backup of elasticsearch for 3months without using snapshot and restore.

---

## [\[APM Logs\] - How to Specify the API Data Field based on User Perspectives](https://discuss.elastic.co/t/apm-logs-how-to-specify-the-api-data-field-based-on-user-perspectives/337981)

<div class="topic-metadata">

**Author:** [@aisyaharifin](https://discuss.elastic.co/u/aisyaharifin)\
**Replies:** 0\
**Last updated:** [July 10, 2023, 3:40am UTC](https://discuss.elastic.co/t/apm-logs-how-to-specify-the-api-data-field-based-on-user-perspectives/337981 "2023-07-10T03:40:22Z")

</div>

Hello Elastic, I want to ask, I have a situation where my user would like to access the APM Error Logs to pull the data to display in their dashboard. I already give them the API Key and URL for them to access to the l…

---

## [How to provide source Field in \_msearch query in ElasticSearch java client version 8](https://discuss.elastic.co/t/how-to-provide-source-field-in-msearch-query-in-elasticsearch-java-client-version-8/337924)

<div class="topic-metadata">

**Author:** [@maulik\_trapasiya](https://discuss.elastic.co/u/maulik_trapasiya)\
**Replies:** 2\
**Last updated:** [July 10, 2023, 3:19am UTC](https://discuss.elastic.co/t/how-to-provide-source-field-in-msearch-query-in-elasticsearch-java-client-version-8/337924 "2023-07-10T03:19:14Z")

</div>

My Elasticsearch's documents are of high size. My service is Java application and its using Elasticsearch java client version 8. Need to run \_msearch query on ES. MultisearchBody don't have field of \_source. in ES native…

---

## [Restriction for API Key](https://discuss.elastic.co/t/restriction-for-api-key/337973)

<div class="topic-metadata">

**Author:** [@aisyaharifin](https://discuss.elastic.co/u/aisyaharifin)\
**Replies:** 0\
**Last updated:** [July 10, 2023, 1:32am UTC](https://discuss.elastic.co/t/restriction-for-api-key/337973 "2023-07-10T01:32:36Z")

</div>

Hello, I would like to ask, how do I restrict the privileges roles for API Key, to pin point to specific "service.name" field in APM data? Thank you.

---

## [Ingest Pipeline for parsing multiline fields giving provided Grok expressions do not match field value error error](https://discuss.elastic.co/t/ingest-pipeline-for-parsing-multiline-fields-giving-provided-grok-expressions-do-not-match-field-value-error-error/337699)

<div class="topic-metadata">

**Author:** [@SecretAsianMan](https://discuss.elastic.co/u/SecretAsianMan)\
**Replies:** 1\
**Last updated:** [July 9, 2023, 9:40pm UTC](https://discuss.elastic.co/t/ingest-pipeline-for-parsing-multiline-fields-giving-provided-grok-expressions-do-not-match-field-value-error-error/337699 "2023-07-09T21:40:24Z")

</div>

I am trying to parse a multiline log file as shown below. This is the processor that I have currently configured for the multiline log file. \[ { "grok": { "field": "message", "patterns": \[ "…

---

## [Reindexing an index which had document added by ingest pipeline](https://discuss.elastic.co/t/reindexing-an-index-which-had-document-added-by-ingest-pipeline/337951)

<div class="topic-metadata">

**Author:** [@Aditya\_Teltia](https://discuss.elastic.co/u/Aditya_Teltia)\
**Replies:** 12\
**Last updated:** [July 9, 2023, 8:02pm UTC](https://discuss.elastic.co/t/reindexing-an-index-which-had-document-added-by-ingest-pipeline/337951 "2023-07-09T20:02:52Z")

</div>

I have an index my-idx-09-2022. I made a ingest pipeline so that all the updates from now of my-idx-09-2022 will go to a new index i.e my-idx-new-09-2023. Python code: def create\_write\_redirect\_pipeline(source\_client, …

---

## [Gork regex](https://discuss.elastic.co/t/gork-regex/337623)

<div class="topic-metadata">

**Author:** [@Indeed2000](https://discuss.elastic.co/u/Indeed2000)\
**Replies:** 8\
**Last updated:** [July 9, 2023, 6:29pm UTC](https://discuss.elastic.co/t/gork-regex/337623 "2023-07-09T18:29:28Z")

</div>

Hi I use this logstash gork: %{TIMESTAMP\_ISO8601:timestamp} %{LOGLEVEL:loglevel} %{DATA:id} \[%{DATA}\] %{DATA:jboss\_errors}(?=:|$) here is the log: 2023-06-30 09:09:55,941 ERROR CUS.InEP-AAAA-123194144 \[invocation\] WF…

---

## [How does Allocation of shards happens, when a node leaves cluster?](https://discuss.elastic.co/t/how-does-allocation-of-shards-happens-when-a-node-leaves-cluster/337960)

<div class="topic-metadata">

**Author:** [@Shashank\_Agrawal](https://discuss.elastic.co/u/Shashank_Agrawal)\
**Replies:** 3\
**Last updated:** [July 9, 2023, 5:09pm UTC](https://discuss.elastic.co/t/how-does-allocation-of-shards-happens-when-a-node-leaves-cluster/337960 "2023-07-09T17:09:33Z")

</div>

I want to know the exact procedure followed, for the allocation of shards on a node when the node leaves the cluster. Facts I know - 1.) ES waits for sometime before the reassigning the shards. 2.) For primary shards, …

---

## [Elasticsearch service not starting](https://discuss.elastic.co/t/elasticsearch-service-not-starting/337954)

<div class="topic-metadata">

**Author:** [@Jefferson\_Lourthusam](https://discuss.elastic.co/u/Jefferson_Lourthusam)\
**Replies:** 5\
**Last updated:** [July 9, 2023, 3:17pm UTC](https://discuss.elastic.co/t/elasticsearch-service-not-starting/337954 "2023-07-09T15:17:49Z")

</div>

Elasticsearch service not starting , we can see below in Elasticsearch-STG logs low disk watermark \[85%\] exceeded on free: 37.4gb\[14.9%\], replicas will not be assigned to this node

---

## [Filtering logic in elastic search output](https://discuss.elastic.co/t/filtering-logic-in-elastic-search-output/337922)

<div class="topic-metadata">

**Author:** [@Minika](https://discuss.elastic.co/u/Minika)\
**Replies:** 0\
**Last updated:** [July 8, 2023, 12:29am UTC](https://discuss.elastic.co/t/filtering-logic-in-elastic-search-output/337922 "2023-07-08T00:29:07Z")

</div>

Hi, I am trying to apply a filter logic in OCP Logstash pipeline. My pipeline receive logs from filebeat which contain a fields tag named logtype(that states the type of log) My motive is to use the logtype value and sen…

---

## [Mocking Search Results in new Java API](https://discuss.elastic.co/t/mocking-search-results-in-new-java-api/337012)

<div class="topic-metadata">

**Author:** [@silentfilm](https://discuss.elastic.co/u/silentfilm)\
**Replies:** 3\
**Last updated:** [July 7, 2023, 9:30pm UTC](https://discuss.elastic.co/t/mocking-search-results-in-new-java-api/337012 "2023-07-07T21:30:45Z")

</div>

Are there any examples of how to mock an Elasticsearch search result for the Java API for unit tests with Mockito? Do you mock the entire search result or individual hits? If I search the Internet for examples I only see…

---

## [Logstash using codec line is not working](https://discuss.elastic.co/t/logstash-using-codec-line-is-not-working/337816)

<div class="topic-metadata">

**Author:** [@cressprm](https://discuss.elastic.co/u/cressprm)\
**Replies:** 1\
**Last updated:** [July 7, 2023, 9:29pm UTC](https://discuss.elastic.co/t/logstash-using-codec-line-is-not-working/337816 "2023-07-07T21:29:17Z")

</div>

I am new to ELK and having trouble configuring a simple Logstash pipeline. Despite enabling debug logging(--log.level=debug), I can only find a message that says 'Received line' in the logs, and nothing else. Not sure wh…

---

## [Elasticsearch.service: Main process exited, code=killed, status=9/KILL](https://discuss.elastic.co/t/elasticsearch-service-main-process-exited-code-killed-status-9-kill/337796)

<div class="topic-metadata">

**Author:** [@bbkunbi](https://discuss.elastic.co/u/bbkunbi)\
**Replies:** 3\
**Last updated:** [July 7, 2023, 9:23pm UTC](https://discuss.elastic.co/t/elasticsearch-service-main-process-exited-code-killed-status-9-kill/337796 "2023-07-07T21:23:04Z")

</div>

Errror: elasticsearch.service: Main process exited, code=killed, status=9/KILL ul 06 17:32:05 linux systemd\[1\]: elasticsearch.service: Main process exited, code=killed, status=9/KILL Jul 06 17:32:05 linux systemd\[1\]: e…

---

## [Add new field to index based on maths calculation from other fields in the same index](https://discuss.elastic.co/t/add-new-field-to-index-based-on-maths-calculation-from-other-fields-in-the-same-index/337571)

<div class="topic-metadata">

**Author:** [@patcan](https://discuss.elastic.co/u/patcan)\
**Replies:** 12\
**Last updated:** [July 7, 2023, 9:15pm UTC](https://discuss.elastic.co/t/add-new-field-to-index-based-on-maths-calculation-from-other-fields-in-the-same-index/337571 "2023-07-07T21:15:07Z")

</div>

Hi, I use elastic-agent on EKS with kubernetes integration. One of the field such as kubernetes.volume.fs.used.pct in the index provides incorrect values I was able to get the correct value using the following formula…

---

## [Filter by Date in URL](https://discuss.elastic.co/t/filter-by-date-in-url/337083)

<div class="topic-metadata">

**Author:** [@Lehmer](https://discuss.elastic.co/u/Lehmer)\
**Replies:** 1\
**Last updated:** [July 7, 2023, 7:40pm UTC](https://discuss.elastic.co/t/filter-by-date-in-url/337083 "2023-07-07T19:40:13Z")

</div>

Hi, I need to access a kibana web filtering by date, but I need to put the filter in the URL. I know how to filter Namespaces and Jobs with the URL using queries: https:// kibana-host/s/desa/app/dashboards#/view/9908…

---

## [Codec Avro Plugin Forward Compatibility](https://discuss.elastic.co/t/codec-avro-plugin-forward-compatibility/337911)

<div class="topic-metadata">

**Author:** [@fine\_porcupine](https://discuss.elastic.co/u/fine_porcupine)\
**Replies:** 0\
**Last updated:** [July 7, 2023, 5:59pm UTC](https://discuss.elastic.co/t/codec-avro-plugin-forward-compatibility/337911 "2023-07-07T17:59:55Z")

</div>

I am processing serialized messages from SQS using Logstash. The messages have been serialized using a FORWARD TRANSITIVE schema. The schema may change in the future. To deserialize these messages, I'd like to use the Co…

---

## [Passing Filters to Kibana Dashboard Rendered In iFrame](https://discuss.elastic.co/t/passing-filters-to-kibana-dashboard-rendered-in-iframe/337710)

<div class="topic-metadata">

**Author:** [@kevfar](https://discuss.elastic.co/u/kevfar)\
**Replies:** 1\
**Last updated:** [July 7, 2023, 5:18pm UTC](https://discuss.elastic.co/t/passing-filters-to-kibana-dashboard-rendered-in-iframe/337710 "2023-07-07T17:18:54Z")

</div>

Hello! I am working with a variety of Kibana dashboards in a React application that renders the user's selected dashboard inside an iFrame. When the dashboard page opens, context from the user is passed in through the da…

---

## [Enhanced table plugin-8.7.1 availability](https://discuss.elastic.co/t/enhanced-table-plugin-8-7-1-availability/335248)

<div class="topic-metadata">

**Author:** [@PRASHANT\_MEHTA](https://discuss.elastic.co/u/PRASHANT_MEHTA)\
**Replies:** 12\
**Last updated:** [July 7, 2023, 5:14pm UTC](https://discuss.elastic.co/t/enhanced-table-plugin-8-7-1-availability/335248 "2023-07-07T17:14:09Z")

</div>

Hello @fbaligand , Can you please provide any info about how long will it take to get latest version of enhanced data table version-8.7.1.Checked github Not available yet. If this is not available then ,will it be fine…

---

## [Dotted Lines not working for formula in LENS](https://discuss.elastic.co/t/dotted-lines-not-working-for-formula-in-lens/337613)

<div class="topic-metadata">

**Author:** [@Arshukla](https://discuss.elastic.co/u/Arshukla)\
**Replies:** 1\
**Last updated:** [July 7, 2023, 5:05pm UTC](https://discuss.elastic.co/t/dotted-lines-not-working-for-formula-in-lens/337613 "2023-07-07T17:05:15Z")

</div>

Hello Team, When I am trying to put dotted lines for missing hour, LENS is not showing it for some of the Graphs. While for some of the graphs its working pretty fine. Not showing here Working here fine Can you …

---

## [Where to change auto\_expand\_replicas for enrich indices?](https://discuss.elastic.co/t/where-to-change-auto-expand-replicas-for-enrich-indices/337907)

<div class="topic-metadata">

**Author:** [@leandrojmp](https://discuss.elastic.co/u/leandrojmp)\
**Replies:** 0\
**Last updated:** [July 7, 2023, 4:51pm UTC](https://discuss.elastic.co/t/where-to-change-auto-expand-replicas-for-enrich-indices/337907 "2023-07-07T16:51:51Z")

</div>

Hello, I need to change the auto\_expand\_replicas for the indices created by enrich policies, the .enrich-\* indices, but I could not find any system template with this mapping, so it seems to be hard-coded elsewhere. Cu…

---

## [Java heap space](https://discuss.elastic.co/t/java-heap-space/337902)

<div class="topic-metadata">

**Author:** [@UP\_NEWS](https://discuss.elastic.co/u/UP_NEWS)\
**Replies:** 2\
**Last updated:** [July 7, 2023, 3:44pm UTC](https://discuss.elastic.co/t/java-heap-space/337902 "2023-07-07T15:44:25Z")

</div>

Hello, how to resolve this problem my jvm is 16g Thanks

---

## [How to setup logstash workers or batch size](https://discuss.elastic.co/t/how-to-setup-logstash-workers-or-batch-size/337903)

<div class="topic-metadata">

**Author:** [@lz840408](https://discuss.elastic.co/u/lz840408)\
**Replies:** 0\
**Last updated:** [July 7, 2023, 3:22pm UTC](https://discuss.elastic.co/t/how-to-setup-logstash-workers-or-batch-size/337903 "2023-07-07T15:22:50Z")

</div>

i have es cluster 6.1.3 i want migrate data to es 7.17.9 i used logstash 7.17.9 to make it my index count has only 1200 doc my logstash config file: input { elasticsearch { hosts =\> \["10.251.0.11:39202","10.25…

---

## [Move index to data warm manually](https://discuss.elastic.co/t/move-index-to-data-warm-manually/337885)

<div class="topic-metadata">

**Author:** [@UP\_NEWS](https://discuss.elastic.co/u/UP_NEWS)\
**Replies:** 7\
**Last updated:** [July 7, 2023, 2:53pm UTC](https://discuss.elastic.co/t/move-index-to-data-warm-manually/337885 "2023-07-07T14:53:06Z")

</div>

Hi, i can move a index from data hot to datawarm manullay with command rsync in linux from /var/lib/elasticsearch/nodes/uid(index) if the api ilm/\_move cant' work ? Thanks

---

## [Time Period for Individuals Visualization in Dash Board](https://discuss.elastic.co/t/time-period-for-individuals-visualization-in-dash-board/337845)

<div class="topic-metadata">

**Author:** [@Kumar\_Abhinav](https://discuss.elastic.co/u/Kumar_Abhinav)\
**Replies:** 4\
**Last updated:** [July 7, 2023, 2:49pm UTC](https://discuss.elastic.co/t/time-period-for-individuals-visualization-in-dash-board/337845 "2023-07-07T14:49:44Z")

</div>

Hi, I have applied a separate time span filter in one of my visualizations in the dashboard, but when I change the dashboard time period, this custom-based visualization also gets changed. I don't want this to happen. H…

---

## [Is it possible to parse NLP query on specific field?](https://discuss.elastic.co/t/is-it-possible-to-parse-nlp-query-on-specific-field/337900)

<div class="topic-metadata">

**Author:** [@learntech004](https://discuss.elastic.co/u/learntech004)\
**Replies:** 0\
**Last updated:** [July 7, 2023, 2:34pm UTC](https://discuss.elastic.co/t/is-it-possible-to-parse-nlp-query-on-specific-field/337900 "2023-07-07T14:34:57Z")

</div>

Hi I am trying to use ELSR model. One of my requirement is - I have a view column and if user searches using a NLP query like " Give me all documents viewed more than 10 times", will the model return only those documen…

---

## [Force merge optimise in background process](https://discuss.elastic.co/t/force-merge-optimise-in-background-process/337768)

<div class="topic-metadata">

**Author:** [@INS](https://discuss.elastic.co/u/INS)\
**Replies:** 8\
**Last updated:** [July 7, 2023, 2:33pm UTC](https://discuss.elastic.co/t/force-merge-optimise-in-background-process/337768 "2023-07-07T14:33:19Z")

</div>

Hi I need to change the force merge process in the background for count of segments. Also how I can steering/manipulating force merge. In my case I have the index which is really updating by data. So If this index is s…

[Previous page](https://discuss.elastic.co/tag/none.md?no_tags=true&page=343)

[Next page](https://discuss.elastic.co/tag/none.md?no_tags=true&page=345)
