# \#none

**URL:** https://discuss.elastic.co/tag/none.md?no_tags=true&page=398

[Latest](https://discuss.elastic.co/latest.md) · [Categories](https://discuss.elastic.co/categories.md) · [Tags](https://discuss.elastic.co/tags.md)

**Page:** 399

---

## [Search with cluster wildcard returns data from non-matching indices](https://discuss.elastic.co/t/search-with-cluster-wildcard-returns-data-from-non-matching-indices/329990)

<div class="topic-metadata">

**Author:** [@VincentR](https://discuss.elastic.co/u/VincentR)\
**Replies:** 0\
**Last updated:** [April 14, 2023, 9:41am UTC](https://discuss.elastic.co/t/search-with-cluster-wildcard-returns-data-from-non-matching-indices/329990 "2023-04-14T09:41:24Z")

</div>

Hello, I am currently migrating from Elastic Search 7.17.8 to 8.6.2 and I am observing a very strange change of behaviour in the search API. Using the search REST api, when the index pattern (target) contains both a …

---

## [Is it possible to change the logging path for Elastic Agent?](https://discuss.elastic.co/t/is-it-possible-to-change-the-logging-path-for-elastic-agent/329983)

<div class="topic-metadata">

**Author:** [@lengoyvaerts](https://discuss.elastic.co/u/lengoyvaerts)\
**Replies:** 0\
**Last updated:** [April 14, 2023, 8:59am UTC](https://discuss.elastic.co/t/is-it-possible-to-change-the-logging-path-for-elastic-agent/329983 "2023-04-14T08:59:43Z")

</div>

Hi community As per the topic's title, I'm trying to configure the logging path when installing the Elastic Agent. I'm using central fleet management and following the installation guidelines from the Kibana UI as descr…

---

## [How long does it take to clone an index with 2TB of data?](https://discuss.elastic.co/t/how-long-does-it-take-to-clone-an-index-with-2tb-of-data/329969)

<div class="topic-metadata">

**Author:** [@dilshadpaleri](https://discuss.elastic.co/u/dilshadpaleri)\
**Replies:** 2\
**Last updated:** [April 14, 2023, 7:45am UTC](https://discuss.elastic.co/t/how-long-does-it-take-to-clone-an-index-with-2tb-of-data/329969 "2023-04-14T07:45:41Z")

</div>

Hi, I want to create an identical copy of an existing index with about 2 TB of data, Clone API seems to be the best option here. To clone an index, the index must be marked as read-only, so it will block my application …

---

## [How to use elastic in wiki js](https://discuss.elastic.co/t/how-to-use-elastic-in-wiki-js/329978)

<div class="topic-metadata">

**Author:** [@Kwa](https://discuss.elastic.co/u/Kwa)\
**Replies:** 0\
**Last updated:** [April 14, 2023, 7:13am UTC](https://discuss.elastic.co/t/how-to-use-elastic-in-wiki-js/329978 "2023-04-14T07:13:00Z")

</div>

Hi everyone, i have elasticsearch installed locally in a VM with version 7.17.8. By calling http://localhost:9200 in the browser i get the information like cluster\_name, cluster\_uuid etc. In elasticsearch.yml i have en…

---

## [Elastic 8 not search with hyphen](https://discuss.elastic.co/t/elastic-8-not-search-with-hyphen/327824)

<div class="topic-metadata">

**Author:** [@suresh\_chaudhari](https://discuss.elastic.co/u/suresh_chaudhari)\
**Replies:** 6\
**Last updated:** [April 14, 2023, 6:50am UTC](https://discuss.elastic.co/t/elastic-8-not-search-with-hyphen/327824 "2023-04-14T06:50:40Z")

</div>

I have documents with id fields {id:domain-837}{id:domain-838} these are automatically stored using mapping with data type keyword. "id": { "type": "text", "fields": { "keyword": { "ignore\_above": 256, "type": "keywor…

---

## [APM agent setup issue](https://discuss.elastic.co/t/apm-agent-setup-issue/329975)

<div class="topic-metadata">

**Author:** [@hairmemez](https://discuss.elastic.co/u/hairmemez)\
**Replies:** 0\
**Last updated:** [April 14, 2023, 6:41am UTC](https://discuss.elastic.co/t/apm-agent-setup-issue/329975 "2023-04-14T06:41:05Z")

</div>

Hi Team, I have successfully configured APM-server and Agent status says "Data successfully received from 1 or more agents" but when I launch APM there are no records. I have tried running query in dev tools {scre…

---

## [Filebeat Input X kafka topics](https://discuss.elastic.co/t/filebeat-input-x-kafka-topics/329950)

<div class="topic-metadata">

**Author:** [@luizsouzagarcia](https://discuss.elastic.co/u/luizsouzagarcia)\
**Replies:** 1\
**Last updated:** [April 13, 2023, 9:49pm UTC](https://discuss.elastic.co/t/filebeat-input-x-kafka-topics/329950 "2023-04-13T21:49:21Z")

</div>

Is it possible to consume all topics of a kafka cluster through filebeat input? ex: type: kafka hosts: - ${KAFKA\_BROKERCONNECT} topics: \["\*"\]. --------\> It doesn't work, I've tried several regex =/ group\_id: "kaf…

---

## [We're looking for community members to test Elastic Serverless!](https://discuss.elastic.co/t/were-looking-for-community-members-to-test-elastic-serverless/329952)

<div class="topic-metadata">

**Author:** [@Scotty\_Saunders](https://discuss.elastic.co/u/Scotty_Saunders)\
**Replies:** 0\
**Last updated:** [April 13, 2023, 9:42pm UTC](https://discuss.elastic.co/t/were-looking-for-community-members-to-test-elastic-serverless/329952 "2023-04-13T21:42:50Z")

</div>

Hey everyone :wave:, my name is Scotty Saunders - I’m a UX Researcher here at Elastic. I’m also part of a larger team helping design and build out a serverless/fully managed offering for Elastic solutions. Our UX researc…

---

## [From the time to time Elastic's docs.count value is updated by logstash. Is it normal?](https://discuss.elastic.co/t/from-the-time-to-time-elastics-docs-count-value-is-updated-by-logstash-is-it-normal/329875)

<div class="topic-metadata">

**Author:** [@german](https://discuss.elastic.co/u/german)\
**Replies:** 4\
**Last updated:** [April 13, 2023, 7:42pm UTC](https://discuss.elastic.co/t/from-the-time-to-time-elastics-docs-count-value-is-updated-by-logstash-is-it-normal/329875 "2023-04-13T19:42:41Z")

</div>

Hi everybody, I have a little question about elastic's docs.count as I have noticed that it's not updated constantly. For example: (Don't pay attention to credentials. It's only a lab test). The 3487 docs.count val…

---

## [Same synonyms in different synonym files](https://discuss.elastic.co/t/same-synonyms-in-different-synonym-files/329358)

<div class="topic-metadata">

**Author:** [@antoinelefloch](https://discuss.elastic.co/u/antoinelefloch)\
**Replies:** 4\
**Last updated:** [April 13, 2023, 6:26pm UTC](https://discuss.elastic.co/t/same-synonyms-in-different-synonym-files/329358 "2023-04-13T18:26:19Z")

</div>

Hello, it seems synonyms in 2nd file are not taken into account if already used in 1st file. In 1st file, I have: aaa,bbb In second file, I have: aaa,synaaa bbb,synbbb ccc,synccc When I do the \_analyze { "expl…

---

## [Logstash add subfield to elasticsearch index](https://discuss.elastic.co/t/logstash-add-subfield-to-elasticsearch-index/329870)

<div class="topic-metadata">

**Author:** [@Utibeabasi\_Umanah](https://discuss.elastic.co/u/Utibeabasi_Umanah)\
**Replies:** 3\
**Last updated:** [April 13, 2023, 5:59pm UTC](https://discuss.elastic.co/t/logstash-add-subfield-to-elasticsearch-index/329870 "2023-04-13T17:59:00Z")

</div>

Hi, i want to add a sub field called prefix to a text field called title using a logstash filter plugin. how do i go about this? i need this because the sub fields are required in app search. here is my logstash config s…

---

## [How can I check the avaiability of a Heartbeat monitor in Elasticsearch?](https://discuss.elastic.co/t/how-can-i-check-the-avaiability-of-a-heartbeat-monitor-in-elasticsearch/329942)

<div class="topic-metadata">

**Author:** [@SamuelSMendes](https://discuss.elastic.co/u/SamuelSMendes)\
**Replies:** 2\
**Last updated:** [April 13, 2023, 4:59pm UTC](https://discuss.elastic.co/t/how-can-i-check-the-avaiability-of-a-heartbeat-monitor-in-elasticsearch/329942 "2023-04-13T16:59:47Z")

</div>

I have a few monitors in heartbeat which I am going to plan a few alerts. One of the alerts should be aiming for the avaiability of a monitor in the uptime in a range of a whole period of time (could be a day or a month)…

---

## [Getting started with Logstash JDBC Integration on Windows](https://discuss.elastic.co/t/getting-started-with-logstash-jdbc-integration-on-windows/329784)

<div class="topic-metadata">

**Author:** [@Dale\_ander](https://discuss.elastic.co/u/Dale_ander)\
**Replies:** 3\
**Last updated:** [April 13, 2023, 4:20pm UTC](https://discuss.elastic.co/t/getting-started-with-logstash-jdbc-integration-on-windows/329784 "2023-04-13T16:20:15Z")

</div>

I'm just beginning my learning process on ELK but from what I've seen, I'd like to learn how to index data from an RDB table, I presume using the Logstash JDBC Integration plugin, so I can start trying to create differen…

---

## [Programmatically trigger the search action (React UI)](https://discuss.elastic.co/t/programmatically-trigger-the-search-action-react-ui/329943)

<div class="topic-metadata">

**Author:** [@Olivia\_Xu](https://discuss.elastic.co/u/Olivia_Xu)\
**Replies:** 0\
**Last updated:** [April 13, 2023, 3:52pm UTC](https://discuss.elastic.co/t/programmatically-trigger-the-search-action-react-ui/329943 "2023-04-13T15:52:34Z")

</div>

We hope to programmatically trigger the search action in some cases without the user having to type and click the search button from the front end. We are using React UI components. Is this possible to achieve? We have t…

---

## [Can I make two input and output in the logstash config file?](https://discuss.elastic.co/t/can-i-make-two-input-and-output-in-the-logstash-config-file/329933)

<div class="topic-metadata">

**Author:** [@lilyyy](https://discuss.elastic.co/u/lilyyy)\
**Replies:** 3\
**Last updated:** [April 13, 2023, 3:26pm UTC](https://discuss.elastic.co/t/can-i-make-two-input-and-output-in-the-logstash-config-file/329933 "2023-04-13T15:26:19Z")

</div>

Hello all. I want to get the two indexes from two input data in the one logstash config file. (One is from tshark file and the other one is filebeat so each data are different.) tshark data is changed to json file for …

---

## [Getting updated documents](https://discuss.elastic.co/t/getting-updated-documents/329910)

<div class="topic-metadata">

**Author:** [@Ismet](https://discuss.elastic.co/u/Ismet)\
**Replies:** 5\
**Last updated:** [April 13, 2023, 3:21pm UTC](https://discuss.elastic.co/t/getting-updated-documents/329910 "2023-04-13T15:21:11Z")

</div>

How to get all documents that have been edited in the last 24 hours and return only the id and attributes that have been changed? Is it possible to do this automatically via Elasticsearch without tracking each attribute?…

---

## [Versioning in Update API](https://discuss.elastic.co/t/versioning-in-update-api/329934)

<div class="topic-metadata">

**Author:** [@Mykyta\_Piddubskiy](https://discuss.elastic.co/u/Mykyta_Piddubskiy)\
**Replies:** 0\
**Last updated:** [April 13, 2023, 1:53pm UTC](https://discuss.elastic.co/t/versioning-in-update-api/329934 "2023-04-13T13:53:41Z")

</div>

Hello, I need to do version checks when I do some operations in Elastic. Example: I want to use date instance in milliseconds as a version to reject any old doc updates. So I chose \_version as a suitable mechanism fo…

---

## [Find users (IP adresses) which only access one group of servers](https://discuss.elastic.co/t/find-users-ip-adresses-which-only-access-one-group-of-servers/328714)

<div class="topic-metadata">

**Author:** [@zebu14](https://discuss.elastic.co/u/zebu14)\
**Replies:** 1\
**Last updated:** [April 13, 2023, 1:53pm UTC](https://discuss.elastic.co/t/find-users-ip-adresses-which-only-access-one-group-of-servers/328714 "2023-04-13T13:53:41Z")

</div>

Hello, I have two groups of forward proxies running Squid (2x 4 servers) Many users are using these proxies. A load balancer sends each new connection on a group or another. Some users are not using the load balancer…

---

## [Restarting logstash cloudwatch plugin](https://discuss.elastic.co/t/restarting-logstash-cloudwatch-plugin/329681)

<div class="topic-metadata">

**Author:** [@mphilip9](https://discuss.elastic.co/u/mphilip9)\
**Replies:** 15\
**Last updated:** [April 13, 2023, 1:42pm UTC](https://discuss.elastic.co/t/restarting-logstash-cloudwatch-plugin/329681 "2023-04-13T13:42:41Z")

</div>

We have an ELK stack app that has been down for over a month due to a credentials issue in the logstash cloudwatch plugin. The plugin is digesting data again now, but what is strange is that it is digesting logs from the…

---

## [Can I save the fields that I only want?](https://discuss.elastic.co/t/can-i-save-the-fields-that-i-only-want/329736)

<div class="topic-metadata">

**Author:** [@lilyyy](https://discuss.elastic.co/u/lilyyy)\
**Replies:** 2\
**Last updated:** [April 13, 2023, 1:29pm UTC](https://discuss.elastic.co/t/can-i-save-the-fields-that-i-only-want/329736 "2023-04-13T13:29:34Z")

</div>

Hello all. I collect the network packet data through the 'tshark' and then the packet is filtered through logstash. But there are a lot of fields in packet data so when I see data in the elasticsearch, there are a lot …

---

## [Unable to start logstash on FreeBSD](https://discuss.elastic.co/t/unable-to-start-logstash-on-freebsd/329874)

<div class="topic-metadata">

**Author:** [@odhiambo](https://discuss.elastic.co/u/odhiambo)\
**Replies:** 4\
**Last updated:** [April 13, 2023, 1:05pm UTC](https://discuss.elastic.co/t/unable-to-start-logstash-on-freebsd/329874 "2023-04-13T13:05:45Z")

</div>

I have installed logstash on FreeBSD. For some reason, starting or stopping it prompts for Kerberos authentication. I am not sure where it is getting this from, although it does seem there is some kerberos config somewhe…

---

## [Search using special characters in standard analyzer](https://discuss.elastic.co/t/search-using-special-characters-in-standard-analyzer/329920)

<div class="topic-metadata">

**Author:** [@Umang\_Pachaury](https://discuss.elastic.co/u/Umang_Pachaury)\
**Replies:** 0\
**Last updated:** [April 13, 2023, 10:36am UTC](https://discuss.elastic.co/t/search-using-special-characters-in-standard-analyzer/329920 "2023-04-13T10:36:23Z")

</div>

Hi guys, I have a cluster running and I have run into a problem involving including special characters in my search query. Now I did not setup the mapping for the index the mapping is dynamic and the analyzer is also st…

---

## [Error in Logstash - failed to parse date field with format strict\_date\_optional\_time||epoch\_millis date-time-parse-exception](https://discuss.elastic.co/t/error-in-logstash-failed-to-parse-date-field-with-format-strict-date-optional-time-epoch-millis-date-time-parse-exception/329797)

<div class="topic-metadata">

**Author:** [@sarath.sarepaka](https://discuss.elastic.co/u/sarath.sarepaka)\
**Replies:** 3\
**Last updated:** [April 13, 2023, 12:30pm UTC](https://discuss.elastic.co/t/error-in-logstash-failed-to-parse-date-field-with-format-strict-date-optional-time-epoch-millis-date-time-parse-exception/329797 "2023-04-13T12:30:34Z")

</div>

Hi, We are getting the below error in the logstash. We are using a field called "destination" for both time and string. We observed below issue when the destination field value is a string . ELasticsearch and Logstash …

---

## [How to use pipelines](https://discuss.elastic.co/t/how-to-use-pipelines/329919)

<div class="topic-metadata">

**Author:** [@Hajar\_Lachhab](https://discuss.elastic.co/u/Hajar_Lachhab)\
**Replies:** 1\
**Last updated:** [April 13, 2023, 11:00am UTC](https://discuss.elastic.co/t/how-to-use-pipelines/329919 "2023-04-13T11:00:29Z")

</div>

Hello evryone, I have created a pipeline that parse web logs but I don't know how to apply it on my data view. My data view is filebeat-8.6.2 and my pipeline is this:

---

## [Kibana 8.6 I dont see in fiscovery my data](https://discuss.elastic.co/t/kibana-8-6-i-dont-see-in-fiscovery-my-data/328280)

<div class="topic-metadata">

**Author:** [@Mary2022](https://discuss.elastic.co/u/Mary2022)\
**Replies:** 2\
**Last updated:** [April 13, 2023, 10:56am UTC](https://discuss.elastic.co/t/kibana-8-6-i-dont-see-in-fiscovery-my-data/328280 "2023-04-13T10:56:43Z")

</div>

I copied the pipeline from our old stack (7.17) and pasted it to our new ELK stack (8.6). I copied the mapping of one of my indices in the old stack and created a new index in my new kibana with that mapping. In my new…

---

## [Elastic search and kibana elastic didnot load properly](https://discuss.elastic.co/t/elastic-search-and-kibana-elastic-didnot-load-properly/329274)

<div class="topic-metadata">

**Author:** [@Moksha2](https://discuss.elastic.co/u/Moksha2)\
**Replies:** 3\
**Last updated:** [April 13, 2023, 10:52am UTC](https://discuss.elastic.co/t/elastic-search-and-kibana-elastic-didnot-load-properly/329274 "2023-04-13T10:52:46Z")

</div>

Hi Team, Elastic search(8.5.3) and kibana deployed through ECK , while accessing the kibana Most of the time facing issue like Elastic did not load properly check the logs . Is it cover security in the free version of …

---

## [How to enable/hide not necessary k8s pod metrics with metricbeat?](https://discuss.elastic.co/t/how-to-enable-hide-not-necessary-k8s-pod-metrics-with-metricbeat/329437)

<div class="topic-metadata">

**Author:** [@Swathi12](https://discuss.elastic.co/u/Swathi12)\
**Replies:** 11\
**Last updated:** [April 13, 2023, 9:26am UTC](https://discuss.elastic.co/t/how-to-enable-hide-not-necessary-k8s-pod-metrics-with-metricbeat/329437 "2023-04-13T09:26:36Z")

</div>

Hi team, i successfully getting from my multiple cluster the metrics in Kibana. But now i see that i don't want ALL metrics from a cluster the pods.. Example: one Cluster has 15 Pods but i need total 8 Pod of them. I…

---

## [What are fees for cross cluster replication and cross region replication and search](https://discuss.elastic.co/t/what-are-fees-for-cross-cluster-replication-and-cross-region-replication-and-search/329886)

<div class="topic-metadata">

**Author:** [@suresh\_chaudhari](https://discuss.elastic.co/u/suresh_chaudhari)\
**Replies:** 1\
**Last updated:** [April 13, 2023, 7:21am UTC](https://discuss.elastic.co/t/what-are-fees-for-cross-cluster-replication-and-cross-region-replication-and-search/329886 "2023-04-13T07:21:34Z")

</div>

As per this link for platinum it is 125 dollars per month. How much it is for onprem will it increase if we use 100GB RAM 2 tb storage for each node.

---

## [Elasticsearch index heavy reads](https://discuss.elastic.co/t/elasticsearch-index-heavy-reads/327739)

<div class="topic-metadata">

**Author:** [@hopa56](https://discuss.elastic.co/u/hopa56)\
**Replies:** 12\
**Last updated:** [April 13, 2023, 6:55am UTC](https://discuss.elastic.co/t/elasticsearch-index-heavy-reads/327739 "2023-04-13T06:55:56Z")

</div>

i have 3 indices in the cluster that are read-heavy and the load on the nodes on which the shards of these indices are located is very high (the indexes are small, the largest index weighs 5 gigabytes) we are thinking …

---

## [Elasticsearch local computer, use it on a dreamiest website](https://discuss.elastic.co/t/elasticsearch-local-computer-use-it-on-a-dreamiest-website/329879)

<div class="topic-metadata">

**Author:** [@Francisco\_Martell](https://discuss.elastic.co/u/Francisco_Martell)\
**Replies:** 1\
**Last updated:** [April 13, 2023, 6:24am UTC](https://discuss.elastic.co/t/elasticsearch-local-computer-use-it-on-a-dreamiest-website/329879 "2023-04-13T06:24:30Z")

</div>

if I have Elasticsearch on my local computer running, can I make a search bar and query data to display on a website I host with dream host? Sorry for anybody questions, all these topics are new to me and I haven't foun…

[Previous page](https://discuss.elastic.co/tag/none.md?no_tags=true&page=397)

[Next page](https://discuss.elastic.co/tag/none.md?no_tags=true&page=399)
