# \#none

**URL:** https://discuss.elastic.co/tag/none.md?no_tags=true&page=357

[Latest](https://discuss.elastic.co/latest.md) · [Categories](https://discuss.elastic.co/categories.md) · [Tags](https://discuss.elastic.co/tags.md)

**Page:** 358

---

## [Switching 'cluster.routing.allocation' between node-upgrades](https://discuss.elastic.co/t/switching-cluster-routing-allocation-between-node-upgrades/335843)

<div class="topic-metadata">

**Author:** [@slash24](https://discuss.elastic.co/u/slash24)\
**Replies:** 1\
**Last updated:** [June 20, 2023, 4:26am UTC](https://discuss.elastic.co/t/switching-cluster-routing-allocation-between-node-upgrades/335843 "2023-06-20T04:26:49Z")

</div>

We have a three-node cluster onprem, and during rolling upgrade of the individual Elastic-nodes, we tend to toggle 'cluster.routing.allocation.enable' between 'primaries' and null. Is this necessary to do between each i…

---

## [Multiple child inastances of a single client or multiple clients, which is better for bulk indexing in large rates?](https://discuss.elastic.co/t/multiple-child-inastances-of-a-single-client-or-multiple-clients-which-is-better-for-bulk-indexing-in-large-rates/336293)

<div class="topic-metadata">

**Author:** [@shameel](https://discuss.elastic.co/u/shameel)\
**Replies:** 6\
**Last updated:** [June 20, 2023, 4:23am UTC](https://discuss.elastic.co/t/multiple-child-inastances-of-a-single-client-or-multiple-clients-which-is-better-for-bulk-indexing-in-large-rates/336293 "2023-06-20T04:23:26Z")

</div>

Hi Im using Elasticsearch v7.5.0 and I have a huge number of documents being ingested per second, as per the documentation it is recommended to use multiple clients for bulk indexing to reduce load. Can I get the same re…

---

## [Elastic agent and port mirroring](https://discuss.elastic.co/t/elastic-agent-and-port-mirroring/336185)

<div class="topic-metadata">

**Author:** [@Ammar\_Mostafa](https://discuss.elastic.co/u/Ammar_Mostafa)\
**Replies:** 1\
**Last updated:** [June 20, 2023, 12:31am UTC](https://discuss.elastic.co/t/elastic-agent-and-port-mirroring/336185 "2023-06-20T00:31:36Z")

</div>

If i have a server that i make it as destination of port mirroring how can i use this mirrored traffic to ingest it in elastic agent to parse it and deliver it to Elasticsearch.

---

## [How Statsd output plugin work](https://discuss.elastic.co/t/how-statsd-output-plugin-work/336298)

<div class="topic-metadata">

**Author:** [@Indeed2000](https://discuss.elastic.co/u/Indeed2000)\
**Replies:** 3\
**Last updated:** [June 19, 2023, 10:55pm UTC](https://discuss.elastic.co/t/how-statsd-output-plugin-work/336298 "2023-06-19T22:55:12Z")

</div>

Hi I have logfile that need to count number of this string on it "connection failed" now question is log file created last day and continuously new log add to it. which of these Statsd output configuration options "co…

---

## [Elastic prebuilt rules error](https://discuss.elastic.co/t/elastic-prebuilt-rules-error/334086)

<div class="topic-metadata">

**Author:** [@hasan.idriss](https://discuss.elastic.co/u/hasan.idriss)\
**Replies:** 2\
**Last updated:** [June 19, 2023, 6:56pm UTC](https://discuss.elastic.co/t/elastic-prebuilt-rules-error/334086 "2023-06-19T18:56:32Z")

</div>

hi guys am facing an issue with all prebuilt rules in Elasticsearch, when I enable the rules it runs with the following error An error occurred during rule execution: message: "verification\_exception Root causes: veri…

---

## [Elasticsearch Master Not discovered](https://discuss.elastic.co/t/elasticsearch-master-not-discovered/336375)

<div class="topic-metadata">

**Author:** [@A.Hani](https://discuss.elastic.co/u/A.Hani)\
**Replies:** 2\
**Last updated:** [June 19, 2023, 3:16pm UTC](https://discuss.elastic.co/t/elasticsearch-master-not-discovered/336375 "2023-06-19T15:16:33Z")

</div>

Hi all, I'm trying to form a cluster of 3 Nodes using Elasticsearch V8.8. I'm testing how this should work on the first 2 nodes and this really driving me crazy. My initial attempt was to start the first node as a clust…

---

## [Club char\_filter for a regex pattern and synonyms in the same query](https://discuss.elastic.co/t/club-char-filter-for-a-regex-pattern-and-synonyms-in-the-same-query/336383)

<div class="topic-metadata">

**Author:** [@searchwithme](https://discuss.elastic.co/u/searchwithme)\
**Replies:** 0\
**Last updated:** [June 19, 2023, 2:53pm UTC](https://discuss.elastic.co/t/club-char-filter-for-a-regex-pattern-and-synonyms-in-the-same-query/336383 "2023-06-19T14:53:58Z")

</div>

I have an index that has candidate resumes. Resume has 2 fields: a) name b) resume Name has name of candidate and resume has a blob of text like "address:""chicago.st", "skill":"python", "email":"myemail@ymail.com". I …

---

## [FATAL Error: Unable to complete saved object migrations for the \[.kibana\] index: Migrations failed. Reason: 2 transformation errors were encountered](https://discuss.elastic.co/t/fatal-error-unable-to-complete-saved-object-migrations-for-the-kibana-index-migrations-failed-reason-2-transformation-errors-were-encountered/336382)

<div class="topic-metadata">

**Author:** [@Jasmine\_Blooms](https://discuss.elastic.co/u/Jasmine_Blooms)\
**Replies:** 0\
**Last updated:** [June 19, 2023, 2:49pm UTC](https://discuss.elastic.co/t/fatal-error-unable-to-complete-saved-object-migrations-for-the-kibana-index-migrations-failed-reason-2-transformation-errors-were-encountered/336382 "2023-06-19T14:49:30Z")

</div>

Hi All, While performing migration of kibana using eck-operator from 7.8.1 to 7.17.10, we are facing the following issue: FATAL Error: Unable to complete saved object migrations for the \[.kibana\] index: Migrations fa…

---

## [Specify an index in search query](https://discuss.elastic.co/t/specify-an-index-in-search-query/336221)

<div class="topic-metadata">

**Author:** [@stephane\_chan](https://discuss.elastic.co/u/stephane_chan)\
**Replies:** 3\
**Last updated:** [June 19, 2023, 2:41pm UTC](https://discuss.elastic.co/t/specify-an-index-in-search-query/336221 "2023-06-19T14:41:30Z")

</div>

I need to search multiple indexes on Elasticsearch, My problem is that on each index I have the same field name (is\_active), how do I specify that it's the field of the other index ? GET index-1,index-2/\_search { "que…

---

## [Character group tokenizer in ElasticSearch](https://discuss.elastic.co/t/character-group-tokenizer-in-elasticsearch/336212)

<div class="topic-metadata">

**Author:** [@Rakhshunda\_Noorein\_J](https://discuss.elastic.co/u/Rakhshunda_Noorein_J)\
**Replies:** 4\
**Last updated:** [June 19, 2023, 2:00pm UTC](https://discuss.elastic.co/t/character-group-tokenizer-in-elasticsearch/336212 "2023-06-19T14:00:53Z")

</div>

Hello, I want to implement Character group tokenizer in elasticsearch. How Do I implement an index with char\_group tokenizer. I am putting this setting in my index: { "index": { "analysis": { "number\_of\_sha…

---

## [Calculate and display failure rate based on a "keyword" field](https://discuss.elastic.co/t/calculate-and-display-failure-rate-based-on-a-keyword-field/336099)

<div class="topic-metadata">

**Author:** [@zebu14](https://discuss.elastic.co/u/zebu14)\
**Replies:** 3\
**Last updated:** [June 19, 2023, 1:53pm UTC](https://discuss.elastic.co/t/calculate-and-display-failure-rate-based-on-a-keyword-field/336099 "2023-06-19T13:53:32Z")

</div>

Hello, For a MFT platform, each transfer is tagged with a status\_code, based on letters "E" for Ended, "C" for Canceled. I have to find out the partners with high failure rates over time. Do you have an idea on how to…

---

## [Cannot initialize custom codec plugin](https://discuss.elastic.co/t/cannot-initialize-custom-codec-plugin/336371)

<div class="topic-metadata">

**Author:** [@ofekinger](https://discuss.elastic.co/u/ofekinger)\
**Replies:** 0\
**Last updated:** [June 19, 2023, 1:28pm UTC](https://discuss.elastic.co/t/cannot-initialize-custom-codec-plugin/336371 "2023-06-19T13:28:07Z")

</div>

Hello. I'm working on a new codec plugin that parses protobuf data in a unique way (meaning I can't use the existing protobuf plugin). Here's the plugin code: package com.ofekinger.logstash.plugins.mycodec; import co…

---

## [Differnce in results when the search query contains a hyphen](https://discuss.elastic.co/t/differnce-in-results-when-the-search-query-contains-a-hyphen/336324)

<div class="topic-metadata">

**Author:** [@zigoo0](https://discuss.elastic.co/u/zigoo0)\
**Replies:** 1\
**Last updated:** [June 19, 2023, 1:00pm UTC](https://discuss.elastic.co/t/differnce-in-results-when-the-search-query-contains-a-hyphen/336324 "2023-06-19T13:00:46Z")

</div>

Hello team, I have an elasticsearch index that contains hostnames and email addresses. When searching the index, my aim is to retrieve all hostnames and emails that contains certain domain Following examples will expla…

---

## [LogStash Configurations for Log4Net, Log4J etc](https://discuss.elastic.co/t/logstash-configurations-for-log4net-log4j-etc/336258)

<div class="topic-metadata">

**Author:** [@Tomahawk](https://discuss.elastic.co/u/Tomahawk)\
**Replies:** 2\
**Last updated:** [June 19, 2023, 11:55am UTC](https://discuss.elastic.co/t/logstash-configurations-for-log4net-log4j-etc/336258 "2023-06-19T11:55:34Z")

</div>

Bit of a left field question….. In a highly regulated space and restricted industry, log files coming from multiple apps (100-200) with Log4Net and Log4J, Python Native logging libraries. No real customisation done by t…

---

## [Logstash batch import nested objects](https://discuss.elastic.co/t/logstash-batch-import-nested-objects/336342)

<div class="topic-metadata">

**Author:** [@Joker\_Lu](https://discuss.elastic.co/u/Joker_Lu)\
**Replies:** 0\
**Last updated:** [June 19, 2023, 9:23am UTC](https://discuss.elastic.co/t/logstash-batch-import-nested-objects/336342 "2023-06-19T09:23:55Z")

</div>

Hi everyone, I want to batch import nested objects to ES, but when i paging my nested objects, it will cover my previous data. Can anyone have a solution for this.

---

## [Issue with ingesting data and disk size](https://discuss.elastic.co/t/issue-with-ingesting-data-and-disk-size/336087)

<div class="topic-metadata">

**Author:** [@ANUBHAV\_GUPTA](https://discuss.elastic.co/u/ANUBHAV_GUPTA)\
**Replies:** 3\
**Last updated:** [June 19, 2023, 9:23am UTC](https://discuss.elastic.co/t/issue-with-ingesting-data-and-disk-size/336087 "2023-06-19T09:23:29Z")

</div>

I am facing a very weird issue. I tried uploading 30 GB of csv data in Elasticsearch using python client. The below is the disk usage when I quit ingestion:- shards disk.indices disk.used disk.avail disk.total disk.pe…

---

## [Upgrading kibana and Elastic from 7.9 to 8.7](https://discuss.elastic.co/t/upgrading-kibana-and-elastic-from-7-9-to-8-7/335906)

<div class="topic-metadata">

**Author:** [@Kumar\_Abhinav](https://discuss.elastic.co/u/Kumar_Abhinav)\
**Replies:** 5\
**Last updated:** [June 19, 2023, 8:49am UTC](https://discuss.elastic.co/t/upgrading-kibana-and-elastic-from-7-9-to-8-7/335906 "2023-06-19T08:49:42Z")

</div>

Hi. I am in the process to upgrade my kibana and Elasticsearch from 7.9 to 8.7. I installed 7.17 but did not back up the data from version 7.9. What shall I do now? Someone, please guide.

---

## [Server public URL Warning](https://discuss.elastic.co/t/server-public-url-warning/336338)

<div class="topic-metadata">

**Author:** [@Ganesh2303](https://discuss.elastic.co/u/Ganesh2303)\
**Replies:** 0\
**Last updated:** [June 19, 2023, 8:39am UTC](https://discuss.elastic.co/t/server-public-url-warning/336338 "2023-06-19T08:39:54Z")

</div>

HI Team, I'm using Version 7.16 ELK and when i try to hit the kibana URL im getting below warning message "server.publicBaseUrl is missing and should be configured when running in a production environment" if i add th…

---

## [No Logs appearing in Kibana](https://discuss.elastic.co/t/no-logs-appearing-in-kibana/336208)

<div class="topic-metadata">

**Author:** [@Shabu](https://discuss.elastic.co/u/Shabu)\
**Replies:** 15\
**Last updated:** [June 19, 2023, 8:21am UTC](https://discuss.elastic.co/t/no-logs-appearing-in-kibana/336208 "2023-06-19T08:21:27Z")

</div>

Those are my statistics. When I tcpdump port 5044 I see traffic coming from the host where I have winlogbeat running and when I tcpdump port 9200 on the server I see a lot of traffic. So I suppose Data is reaching ela…

---

## [Fleet: This output type currently does not support connectivity to a remote Elasticsearch cluster](https://discuss.elastic.co/t/fleet-this-output-type-currently-does-not-support-connectivity-to-a-remote-elasticsearch-cluster/336336)

<div class="topic-metadata">

**Author:** [@tomx1](https://discuss.elastic.co/u/tomx1)\
**Replies:** 0\
**Last updated:** [June 19, 2023, 8:15am UTC](https://discuss.elastic.co/t/fleet-this-output-type-currently-does-not-support-connectivity-to-a-remote-elasticsearch-cluster/336336 "2023-06-19T08:15:22Z")

</div>

I'm currently testing Fleet and added a dedicated fleet server and a dedicated "collector server" VM with elastic agent installed. Everything is now managed via Kibana and my goal is to collect stuff via the collector VM…

---

## [Getting unrelated data while searching with -\* in simple\_query\_string](https://discuss.elastic.co/t/getting-unrelated-data-while-searching-with-in-simple-query-string/336192)

<div class="topic-metadata">

**Author:** [@ms.t](https://discuss.elastic.co/u/ms.t)\
**Replies:** 4\
**Last updated:** [June 19, 2023, 8:10am UTC](https://discuss.elastic.co/t/getting-unrelated-data-while-searching-with-in-simple-query-string/336192 "2023-06-19T08:10:50Z")

</div>

Hi I am using simple\_query\_string method with suffix \* (operator) for getting result But when i am searching with odd number of - getting unrelated data but with even number of - getting empty data.

---

## [Need help with Elasticsearch and Elastic agent](https://discuss.elastic.co/t/need-help-with-elasticsearch-and-elastic-agent/335502)

<div class="topic-metadata">

**Author:** [@SanketBaraiya](https://discuss.elastic.co/u/SanketBaraiya)\
**Replies:** 7\
**Last updated:** [June 19, 2023, 7:20am UTC](https://discuss.elastic.co/t/need-help-with-elasticsearch-and-elastic-agent/335502 "2023-06-19T07:20:21Z")

</div>

I am facing the problem in my elk server. Whenever I start the elasticsearch service the outgoing traffic increases to \>10 MBps. This is what is shown in the processes. I also have stopped both filebeat and metricbea…

---

## [Upgrde 7.8 to 7](https://discuss.elastic.co/t/upgrde-7-8-to-7/336264)

<div class="topic-metadata">

**Author:** [@Abhishek\_Tiwari1](https://discuss.elastic.co/u/Abhishek_Tiwari1)\
**Replies:** 3\
**Last updated:** [June 19, 2023, 6:39am UTC](https://discuss.elastic.co/t/upgrde-7-8-to-7/336264 "2023-06-19T06:39:42Z")

</div>

HI Team, Need help , we are facing issue after upgrade elasticseach from 7.8 to 7.17.10, Issue first it incresed respoonce time Chche value decresed drasticily from 7.8 to 7.17.10 on search . Please help Thanks Abh…

---

## [Index status red with reason failed engine (reason: \[merge failed\])](https://discuss.elastic.co/t/index-status-red-with-reason-failed-engine-reason-merge-failed/336249)

<div class="topic-metadata">

**Author:** [@Fajaruddin\_Shiddiq](https://discuss.elastic.co/u/Fajaruddin_Shiddiq)\
**Replies:** 7\
**Last updated:** [June 19, 2023, 1:55am UTC](https://discuss.elastic.co/t/index-status-red-with-reason-failed-engine-reason-merge-failed/336249 "2023-06-19T01:55:47Z")

</div>

Hi, one of my index seems corrupt because of failed during merge process as below org.apache.lucene.index.MergePolicy$MergeException: org.apache.lucene.index.CorruptIndexException: docs out of order (594 \<= 594 ) (reso…

---

## [Elastic Defend Integration with Airgapped Package Registry](https://discuss.elastic.co/t/elastic-defend-integration-with-airgapped-package-registry/336314)

<div class="topic-metadata">

**Author:** [@sgehman](https://discuss.elastic.co/u/sgehman)\
**Replies:** 0\
**Last updated:** [June 18, 2023, 9:17pm UTC](https://discuss.elastic.co/t/elastic-defend-integration-with-airgapped-package-registry/336314 "2023-06-18T21:17:12Z")

</div>

I am using Andrew Peases Elastic Container Project, and version 8.6.2 for Elasticsearch, Kibana, and the Elastic Agent which serves as my fleet server. This is in an Airgapped environment, and I have followed the Documen…

---

## [Recent ecommerce requirement change ballooned our hosting costs x7. Need help with data model](https://discuss.elastic.co/t/recent-ecommerce-requirement-change-ballooned-our-hosting-costs-x7-need-help-with-data-model/336308)

<div class="topic-metadata">

**Author:** [@sdata47](https://discuss.elastic.co/u/sdata47)\
**Replies:** 0\
**Last updated:** [June 18, 2023, 6:14pm UTC](https://discuss.elastic.co/t/recent-ecommerce-requirement-change-ballooned-our-hosting-costs-x7-need-help-with-data-model/336308 "2023-06-18T18:14:54Z")

</div>

We're having a serious issue using Elasticsearch at work without large hosting costs. A recent requirement change bumped us up from $120 to $700 a month. Essentially, this is the issue. We have a catalog of products, …

---

## [Little confuse about decay function source code](https://discuss.elastic.co/t/little-confuse-about-decay-function-source-code/336296)

<div class="topic-metadata">

**Author:** [@RandalTeng](https://discuss.elastic.co/u/RandalTeng)\
**Replies:** 2\
**Last updated:** [June 18, 2023, 8:36am UTC](https://discuss.elastic.co/t/little-confuse-about-decay-function-source-code/336296 "2023-06-18T08:36:15Z")

</div>

hi guys, I recently read some source code about the decay function. there is some code doc, I can't figure out why it should be. the code line is: https://github.com/elastic/elasticsearch/blob/13fb93511c23fe0d1a02de07…

---

## [Updating index is not working for existing data inside json object](https://discuss.elastic.co/t/updating-index-is-not-working-for-existing-data-inside-json-object/336291)

<div class="topic-metadata">

**Author:** [@J\_S](https://discuss.elastic.co/u/J_S)\
**Replies:** 1\
**Last updated:** [June 18, 2023, 7:15am UTC](https://discuss.elastic.co/t/updating-index-is-not-working-for-existing-data-inside-json-object/336291 "2023-06-18T07:15:53Z")

</div>

I am repeatedly fetching rows from a database. I insert them into elasticsearch using the unique key as the document\_id. For any fields not on the current document I want to add any missing columns to the exiting documen…

---

## [Event.remove method not working inside aggregate section in code block](https://discuss.elastic.co/t/event-remove-method-not-working-inside-aggregate-section-in-code-block/336201)

<div class="topic-metadata">

**Author:** [@J\_S](https://discuss.elastic.co/u/J_S)\
**Replies:** 20\
**Last updated:** [June 18, 2023, 3:37am UTC](https://discuss.elastic.co/t/event-remove-method-not-working-inside-aggregate-section-in-code-block/336201 "2023-06-18T03:37:16Z")

</div>

Hi All, I am newbie to ELK stack, I am trying to remove the field called "attributes" while aggregate the data inside code block. But it is not removing the already existing "attributes" in the corresponding "id" but on…

---

## [Can you forward logs going into elasticsearch to a third party?](https://discuss.elastic.co/t/can-you-forward-logs-going-into-elasticsearch-to-a-third-party/334800)

<div class="topic-metadata">

**Author:** [@willsy](https://discuss.elastic.co/u/willsy)\
**Replies:** 3\
**Last updated:** [June 17, 2023, 3:32pm UTC](https://discuss.elastic.co/t/can-you-forward-logs-going-into-elasticsearch-to-a-third-party/334800 "2023-06-17T15:32:43Z")

</div>

I have a single instance of elasticsearch, kibana and i am getting the data in this via agents and filebeats. is there a way to "forward" the data that is ingested into elasticsearch to another device or instance?

[Previous page](https://discuss.elastic.co/tag/none.md?no_tags=true&page=356)

[Next page](https://discuss.elastic.co/tag/none.md?no_tags=true&page=358)
