# \#none

**URL:** https://discuss.elastic.co/tag/none.md?no_tags=true&page=390

[Latest](https://discuss.elastic.co/latest.md) · [Categories](https://discuss.elastic.co/categories.md) · [Tags](https://discuss.elastic.co/tags.md)

**Page:** 391

---

## [Logstash Output](https://discuss.elastic.co/t/logstash-output/330786)

<div class="topic-metadata">

**Author:** [@Dasher](https://discuss.elastic.co/u/Dasher)\
**Replies:** 1\
**Last updated:** [April 26, 2023, 3:15pm UTC](https://discuss.elastic.co/t/logstash-output/330786 "2023-04-26T15:15:22Z")

</div>

I have a logstash conf file with multiple output configured In both the outputs i'm using multiple if else statements.Is it possible for the data to get entered in the else statement of both output?

---

## [Index external files](https://discuss.elastic.co/t/index-external-files/330771)

<div class="topic-metadata">

**Author:** [@fabian\_barnich](https://discuss.elastic.co/u/fabian_barnich)\
**Replies:** 5\
**Last updated:** [April 26, 2023, 3:11pm UTC](https://discuss.elastic.co/t/index-external-files/330771 "2023-04-26T15:11:21Z")

</div>

Good morning, I installed elasticsearch and kibana on a VM in debian, my documents that I want to index are on another VM. How can I tell Elasticsearch to index them? Thanks in advance

---

## [Markdown only clickable in a small region at the bottom of the image](https://discuss.elastic.co/t/markdown-only-clickable-in-a-small-region-at-the-bottom-of-the-image/330684)

<div class="topic-metadata">

**Author:** [@Buddha](https://discuss.elastic.co/u/Buddha)\
**Replies:** 1\
**Last updated:** [April 26, 2023, 2:54pm UTC](https://discuss.elastic.co/t/markdown-only-clickable-in-a-small-region-at-the-bottom-of-the-image/330684 "2023-04-26T14:54:00Z")

</div>

I have upgraded to version 8.7, but still experience an issue that should have been fix as follows: \[Dashboard\] Add styling to allow clickable TSVB markdown images by Heenawter · Pull Request #147802 · elastic/kibana · G…

---

## [After migration from Elasticsearch 6.3 to 7.17 the index size on disk doubled](https://discuss.elastic.co/t/after-migration-from-elasticsearch-6-3-to-7-17-the-index-size-on-disk-doubled/330678)

<div class="topic-metadata">

**Author:** [@igor\_sokolov](https://discuss.elastic.co/u/igor_sokolov)\
**Replies:** 3\
**Last updated:** [April 26, 2023, 2:39pm UTC](https://discuss.elastic.co/t/after-migration-from-elasticsearch-6-3-to-7-17-the-index-size-on-disk-doubled/330678 "2023-04-26T14:39:52Z")

</div>

Hello everyone, I've migrated an Elasticsearch 6.3 cluster to the version of 7.17 (by creating a new cluster with the same index mapping/shard structure and reindexing) and the index size on the disk almost doubled. The…

---

## [Fuzzy Search Query using KQL or Lucene](https://discuss.elastic.co/t/fuzzy-search-query-using-kql-or-lucene/330575)

<div class="topic-metadata">

**Author:** [@Tiharqa](https://discuss.elastic.co/u/Tiharqa)\
**Replies:** 1\
**Last updated:** [April 26, 2023, 2:14pm UTC](https://discuss.elastic.co/t/fuzzy-search-query-using-kql-or-lucene/330575 "2023-04-26T14:14:22Z")

</div>

I'm trying to find documents where the host.os.platform field has some words similar to host.os.name for example I want to use Kibana discover either Lucene or KQL for that. This is what I came up with : host.os.plat…

---

## [Elastic agent Does not receive traffic, but it reaches the Linux server](https://discuss.elastic.co/t/elastic-agent-does-not-receive-traffic-but-it-reaches-the-linux-server/330100)

<div class="topic-metadata">

**Author:** [@Razovnyik](https://discuss.elastic.co/u/Razovnyik)\
**Replies:** 7\
**Last updated:** [April 26, 2023, 2:09pm UTC](https://discuss.elastic.co/t/elastic-agent-does-not-receive-traffic-but-it-reaches-the-linux-server/330100 "2023-04-26T14:09:40Z")

</div>

Elasticsearch is configured with a Palo Alto Integration a corresponding Agent Policy and Agent. The Agent itself is installed on an Ubuntu Linux machine: The Ubuntu machine itself receives the traffic: But the …

---

## [Elasticsearch upgrade from 2.4.6 to 7.x](https://discuss.elastic.co/t/elasticsearch-upgrade-from-2-4-6-to-7-x/330620)

<div class="topic-metadata">

**Author:** [@iarunava](https://discuss.elastic.co/u/iarunava)\
**Replies:** 7\
**Last updated:** [April 26, 2023, 1:12pm UTC](https://discuss.elastic.co/t/elasticsearch-upgrade-from-2-4-6-to-7-x/330620 "2023-04-26T13:12:14Z")

</div>

Hi. Arunava here. Im trying to upgrade elasticsearch 2.4.6 to 7.17.x Im new to elasticsearch. I would appreciate some pointers. The 7.17 stack is ready. and there is a task defined which tries to bulk insert the data …

---

## [ELK stack in windows 11](https://discuss.elastic.co/t/elk-stack-in-windows-11/330832)

<div class="topic-metadata">

**Author:** [@Sardor](https://discuss.elastic.co/u/Sardor)\
**Replies:** 15\
**Last updated:** [April 26, 2023, 1:11pm UTC](https://discuss.elastic.co/t/elk-stack-in-windows-11/330832 "2023-04-26T13:11:08Z")

</div>

I tried to install ELK stack, Elasticsearch, Logstash, Kibana. Elasticsearch and Kibana run succesfully, but logstash returned some exceptions. How can I fix it? This is last logs from logstash : \[2023-04-26T16:45:34,3…

---

## [Ha in two node elasticsearch](https://discuss.elastic.co/t/ha-in-two-node-elasticsearch/330819)

<div class="topic-metadata">

**Author:** [@Monish22](https://discuss.elastic.co/u/Monish22)\
**Replies:** 9\
**Last updated:** [April 26, 2023, 12:58pm UTC](https://discuss.elastic.co/t/ha-in-two-node-elasticsearch/330819 "2023-04-26T12:58:07Z")

</div>

Hi, Currently, we setup two node elasticsearch cluster in my lab and configured ha. We set the both the nodes are master and data. but when the elk01 master node is down, the elk02 doesnt take the leader process. ELK02…

---

## [Monitoring data streams](https://discuss.elastic.co/t/monitoring-data-streams/330759)

<div class="topic-metadata">

**Author:** [@YvorL](https://discuss.elastic.co/u/YvorL)\
**Replies:** 4\
**Last updated:** [April 26, 2023, 12:57pm UTC](https://discuss.elastic.co/t/monitoring-data-streams/330759 "2023-04-26T12:57:18Z")

</div>

Hi, I started to use data streams in my ELK stack. However, I can't see proper data regarding to the indexing rate. "Elasticsearch overview" shows a 20/s indexing rate, and I can't see the backing indices in the "Indice…

---

## [Search query builder and mapping](https://discuss.elastic.co/t/search-query-builder-and-mapping/330715)

<div class="topic-metadata">

**Author:** [@SIMONE2](https://discuss.elastic.co/u/SIMONE2)\
**Replies:** 3\
**Last updated:** [April 26, 2023, 11:55am UTC](https://discuss.elastic.co/t/search-query-builder-and-mapping/330715 "2023-04-26T11:55:11Z")

</div>

Hello everyone, I inherited the mapping of a service (JAVA SPRING BOOT)with Elasticsearch and I'm going crazy for the search. my field is so mapped: "organizationNames":{ "type":"text", "fields":{ …

---

## [Elasticsearch 6.8.23 happen OOM](https://discuss.elastic.co/t/elasticsearch-6-8-23-happen-oom/330802)

<div class="topic-metadata">

**Author:** [@yunpeng.jiangyp](https://discuss.elastic.co/u/yunpeng.jiangyp)\
**Replies:** 3\
**Last updated:** [April 26, 2023, 11:37am UTC](https://discuss.elastic.co/t/elasticsearch-6-8-23-happen-oom/330802 "2023-04-26T11:37:05Z")

</div>

Hi, We have a 8core/16GB ( 4 nodes cluster ) for the Elasticsearch and the Elasticsearch process is getting killed. JDK settings -Xms8g -Xmx8g -XX:+UseConcMarkSweepGC -XX:CMSInitiatingOccupancyFraction=75 -XX:+UseCMSI…

---

## [Search templates with nested query](https://discuss.elastic.co/t/search-templates-with-nested-query/330745)

<div class="topic-metadata">

**Author:** [@orlenkoda5](https://discuss.elastic.co/u/orlenkoda5)\
**Replies:** 2\
**Last updated:** [April 26, 2023, 11:25am UTC](https://discuss.elastic.co/t/search-templates-with-nested-query/330745 "2023-04-26T11:25:41Z")

</div>

Hi everyone. I'm trying to make a search template with bool query. This bool query uses 'should' operator, which searches data throgh 4 fields of index. These results than must be filtered by two fields, so I try to use…

---

## [Help on using stored filed in side a query](https://discuss.elastic.co/t/help-on-using-stored-filed-in-side-a-query/330825)

<div class="topic-metadata">

**Author:** [@sreekanth\_makam](https://discuss.elastic.co/u/sreekanth_makam)\
**Replies:** 1\
**Last updated:** [April 26, 2023, 11:08am UTC](https://discuss.elastic.co/t/help-on-using-stored-filed-in-side-a-query/330825 "2023-04-26T11:08:44Z")

</div>

I have index1 and index2. Running below query against Index1 where i point to index2. In indexs those fields created with stored option. Please help on this query. POST /Index1/\_search { "query": { "bool": {…

---

## [Logstash : Codec multiline problem](https://discuss.elastic.co/t/logstash-codec-multiline-problem/330812)

<div class="topic-metadata">

**Author:** [@JackieLaFrite](https://discuss.elastic.co/u/JackieLaFrite)\
**Replies:** 0\
**Last updated:** [April 26, 2023, 9:20am UTC](https://discuss.elastic.co/t/logstash-codec-multiline-problem/330812 "2023-04-26T09:20:11Z")

</div>

Each time logstash try to parse a log like this : 09-Mar-2023 16:45:40.861 SEVERE \[main\] org.apache.catalina.core.StandardContext.listenerStart Exception sending context initialized event to listener instance of class \[…

---

## [Elasticsearch 8.7.0 High Heap Usage](https://discuss.elastic.co/t/elasticsearch-8-7-0-high-heap-usage/330730)

<div class="topic-metadata">

**Author:** [@esi](https://discuss.elastic.co/u/esi)\
**Replies:** 6\
**Last updated:** [April 26, 2023, 9:00am UTC](https://discuss.elastic.co/t/elasticsearch-8-7-0-high-heap-usage/330730 "2023-04-26T09:00:28Z")

</div>

Hello, we have a 3 node cluster one loadbalancer node, one slave node and one master node running with latest Ubuntu 22.04.2 and Elasticsearch with Kibana on version 8.7.0. The master and slave system has 4 CPUs and 64 G…

---

## [Module s3 input does not work error](https://discuss.elastic.co/t/module-s3-input-does-not-work-error/329522)

<div class="topic-metadata">

**Author:** [@San9](https://discuss.elastic.co/u/San9)\
**Replies:** 3\
**Last updated:** [April 26, 2023, 8:11am UTC](https://discuss.elastic.co/t/module-s3-input-does-not-work-error/329522 "2023-04-26T08:11:58Z")

</div>

Hi all, ran into this problem. At some point after upgrading from version 7 to 8, my S3 input module stopped working correctly. I see in the logs that the module connects to S3 and that it tries to deduct the content, …

---

## [Kibana stuck with association errors on K8S](https://discuss.elastic.co/t/kibana-stuck-with-association-errors-on-k8s/329254)

<div class="topic-metadata">

**Author:** [@Jennifer\_Klemisch](https://discuss.elastic.co/u/Jennifer_Klemisch)\
**Replies:** 8\
**Last updated:** [April 26, 2023, 8:10am UTC](https://discuss.elastic.co/t/kibana-stuck-with-association-errors-on-k8s/329254 "2023-04-26T08:10:32Z")

</div>

While attempting to troubleshoot why my enterprise search wouldn't deploy I ended up running into another error. The guide says after running the yaml for deploying enterprise search, to restart kibana. Which from what…

---

## [Failed to update mapping for index, failure org.elasticsearch.index.mapper.MapperParsingException: Failed to parse mapping: analyzer \[jobtitle\_synonym\_analyzer\] contains filters \[jobtitle\_synonym\_filter\] that are not allowed to run in index time mode](https://discuss.elastic.co/t/failed-to-update-mapping-for-index-failure-org-elasticsearch-index-mapper-mapperparsingexception-failed-to-parse-mapping-analyzer-jobtitle-synonym-analyzer-contains-filters-jobtitle-synonym-filter-that-are-not-allowed-to-run-in-index-time-mode/330785)

<div class="topic-metadata">

**Author:** [@Anand\_Konagala](https://discuss.elastic.co/u/Anand_Konagala)\
**Replies:** 6\
**Last updated:** [April 26, 2023, 5:51am UTC](https://discuss.elastic.co/t/failed-to-update-mapping-for-index-failure-org-elasticsearch-index-mapper-mapperparsingexception-failed-to-parse-mapping-analyzer-jobtitle-synonym-analyzer-contains-filters-jobtitle-synonym-filter-that-are-not-allowed-to-run-in-index-time-mode/330785 "2023-04-26T05:51:19Z")

</div>

When I restore the Index with the use of snapshot, It restored successfully but, I am getting an error called all shards are failed. When I search for an Explaination It shows that failed to update mapping for index, fai…

---

## [Kibana dashboard filter doesn't work](https://discuss.elastic.co/t/kibana-dashboard-filter-doesnt-work/330675)

<div class="topic-metadata">

**Author:** [@tonyaw](https://discuss.elastic.co/u/tonyaw)\
**Replies:** 10\
**Last updated:** [April 26, 2023, 5:44am UTC](https://discuss.elastic.co/t/kibana-dashboard-filter-doesnt-work/330675 "2023-04-26T05:44:25Z")

</div>

I created a Kibana dashboard contains a Lens visualization. I'm trying to use filter to get data for "cluster\_id == 77" OR "cluster\_id==80", But what Lens shows is cluster\_id == from 77 to 80. Could you please help to …

---

## [Change 4000 fields in my index](https://discuss.elastic.co/t/change-4000-fields-in-my-index/330504)

<div class="topic-metadata">

**Author:** [@searchwithme](https://discuss.elastic.co/u/searchwithme)\
**Replies:** 2\
**Last updated:** [April 25, 2023, 11:22pm UTC](https://discuss.elastic.co/t/change-4000-fields-in-my-index/330504 "2023-04-25T23:22:03Z")

</div>

I have nested json documents with about 4000 fields. To change the field type, I understand I have to reindex with a new index and updated mapping. But what if i want to change like 2500 fields? is there an alternative w…

---

## [Elasticsearch slow at the beginning of searching , and segment memory is 0](https://discuss.elastic.co/t/elasticsearch-slow-at-the-beginning-of-searching-and-segment-memory-is-0/330638)

<div class="topic-metadata">

**Author:** [@yuhan\_zhang2](https://discuss.elastic.co/u/yuhan_zhang2)\
**Replies:** 1\
**Last updated:** [April 25, 2023, 11:08pm UTC](https://discuss.elastic.co/t/elasticsearch-slow-at-the-beginning-of-searching-and-segment-memory-is-0/330638 "2023-04-25T23:08:14Z")

</div>

When I was testing the performance on 10 millions of docs, I found the performance was really bad at the beginning (~20s) but fast after thousands of search. Then I use \_cat/segments?v=true to check my segments and t…

---

## [Want to use shorten URL functionality of Kibana to generate id of dashboard](https://discuss.elastic.co/t/want-to-use-shorten-url-functionality-of-kibana-to-generate-id-of-dashboard/330648)

<div class="topic-metadata">

**Author:** [@aman\_giri](https://discuss.elastic.co/u/aman_giri)\
**Replies:** 1\
**Last updated:** [April 25, 2023, 11:02pm UTC](https://discuss.elastic.co/t/want-to-use-shorten-url-functionality-of-kibana-to-generate-id-of-dashboard/330648 "2023-04-25T23:02:33Z")

</div>

Hello, everyone I have this public URL that I want to show publicly but it has multiple parameters that can be seen in the URL so I wanted to be short . I was going through Shorten URL | Kibana User Guide \[6.7\] | Elast…

---

## [Changing IP on a running cluster](https://discuss.elastic.co/t/changing-ip-on-a-running-cluster/330673)

<div class="topic-metadata">

**Author:** [@zaeemmasood](https://discuss.elastic.co/u/zaeemmasood)\
**Replies:** 1\
**Last updated:** [April 25, 2023, 10:58pm UTC](https://discuss.elastic.co/t/changing-ip-on-a-running-cluster/330673 "2023-04-25T22:58:14Z")

</div>

Hello, We have a ELK 7.6.2 stack cluster (3 Master and 5 Data nodes) running in our Production environment. We need to migrate the servers (Cloud VMs) to a more robust ones. This process would result in changing the I…

---

## [Delete indices by date (Elasticsearch 8.7)](https://discuss.elastic.co/t/delete-indices-by-date-elasticsearch-8-7/330750)

<div class="topic-metadata">

**Author:** [@Suren\_Baboyan](https://discuss.elastic.co/u/Suren_Baboyan)\
**Replies:** 2\
**Last updated:** [April 25, 2023, 10:46pm UTC](https://discuss.elastic.co/t/delete-indices-by-date-elasticsearch-8-7/330750 "2023-04-25T22:46:49Z")

</div>

Hello. I created index from logstash (%{\[project\]\[name\]}-%{\[project\]\[service\]}-%{+YYYY.MM.dd}), and I want to keep only last 10 days logs. How can I delete automatically older data?

---

## [Filter specific information](https://discuss.elastic.co/t/filter-specific-information/329695)

<div class="topic-metadata">

**Author:** [@SilasMuniz1](https://discuss.elastic.co/u/SilasMuniz1)\
**Replies:** 11\
**Last updated:** [April 25, 2023, 6:58pm UTC](https://discuss.elastic.co/t/filter-specific-information/329695 "2023-04-25T18:58:19Z")

</div>

Hello, I am trying filter a specific information inside of determite field. I used kv for split my log. It's work well. After that I need get apelido information inside request field. But It didn't work. This …

---

## [Use logstash as a central logging server for log files exported from various devices](https://discuss.elastic.co/t/use-logstash-as-a-central-logging-server-for-log-files-exported-from-various-devices/330689)

<div class="topic-metadata">

**Author:** [@Arinjay\_Jain](https://discuss.elastic.co/u/Arinjay_Jain)\
**Replies:** 2\
**Last updated:** [April 25, 2023, 6:21pm UTC](https://discuss.elastic.co/t/use-logstash-as-a-central-logging-server-for-log-files-exported-from-various-devices/330689 "2023-04-25T18:21:55Z")

</div>

Hi All, I want to use logstash as a central logging server for storing log files exported from various devices. The log files can contain structured as well as un-structured data. Also I would like to store binary files…

---

## [Bulk upload in Elasticsearch 6.8.19 using python](https://discuss.elastic.co/t/bulk-upload-in-elasticsearch-6-8-19-using-python/330752)

<div class="topic-metadata">

**Author:** [@ANUBHAV\_GUPTA](https://discuss.elastic.co/u/ANUBHAV_GUPTA)\
**Replies:** 2\
**Last updated:** [April 25, 2023, 3:25pm UTC](https://discuss.elastic.co/t/bulk-upload-in-elasticsearch-6-8-19-using-python/330752 "2023-04-25T15:25:47Z")

</div>

Due to some reasons, I need to upload bulk csv data in Elasticsearch 6.8.19. Can someone provide me a piece of code for that. The latest version python code is not working for obvious reasons.

---

## [Kibana connection without enrollment token](https://discuss.elastic.co/t/kibana-connection-without-enrollment-token/330728)

<div class="topic-metadata">

**Author:** [@ANUBHAV\_GUPTA](https://discuss.elastic.co/u/ANUBHAV_GUPTA)\
**Replies:** 3\
**Last updated:** [April 25, 2023, 2:58pm UTC](https://discuss.elastic.co/t/kibana-connection-without-enrollment-token/330728 "2023-04-25T14:58:07Z")

</div>

Can we connect to elasticsearch using Kibana without the enrollment token and username-password? I tried sometime back, then it was not mandatory to provide enrollment token. Even tried setting xpack.security.enrollmen…

---

## [Upgrading ECK Operator on Openshift](https://discuss.elastic.co/t/upgrading-eck-operator-on-openshift/330742)

<div class="topic-metadata">

**Author:** [@gbschenkel](https://discuss.elastic.co/u/gbschenkel)\
**Replies:** 0\
**Last updated:** [April 25, 2023, 1:03pm UTC](https://discuss.elastic.co/t/upgrading-eck-operator-on-openshift/330742 "2023-04-25T13:03:26Z")

</div>

Hi, we have an instance of ELK on version 7.17.9, orchestrated on Openshift 4.11 using ECK Operator 1.9.0. For some reason the Certified ECK Operator for Openshift stopped upgrading itself. When Operator 2.0.0 came out …

[Previous page](https://discuss.elastic.co/tag/none.md?no_tags=true&page=389)

[Next page](https://discuss.elastic.co/tag/none.md?no_tags=true&page=391)
