# \#none

**URL:** https://discuss.elastic.co/tag/none.md?no_tags=true&page=399

[Latest](https://discuss.elastic.co/latest.md) · [Categories](https://discuss.elastic.co/categories.md) · [Tags](https://discuss.elastic.co/tags.md)

**Page:** 400

---

## [Indices in red state. "cannot allocate because all found copies of the shard are either stale or corrupt"](https://discuss.elastic.co/t/indices-in-red-state-cannot-allocate-because-all-found-copies-of-the-shard-are-either-stale-or-corrupt/328871)

<div class="topic-metadata">

**Author:** [@Bhuvesh\_Seth](https://discuss.elastic.co/u/Bhuvesh_Seth)\
**Replies:** 10\
**Last updated:** [April 13, 2023, 6:20am UTC](https://discuss.elastic.co/t/indices-in-red-state-cannot-allocate-because-all-found-copies-of-the-shard-are-either-stale-or-corrupt/328871 "2023-04-13T06:20:08Z")

</div>

Hi, we are facing one issue where some of indices health not getting updated to yellow or green due to this error "cannot allocate because all found copies of the shard are either stale or corrupt". Can someone please gu…

---

## [Limit storage needs by automatically remove data after 28 days](https://discuss.elastic.co/t/limit-storage-needs-by-automatically-remove-data-after-28-days/329865)

<div class="topic-metadata">

**Author:** [@GKre](https://discuss.elastic.co/u/GKre)\
**Replies:** 3\
**Last updated:** [April 13, 2023, 5:39am UTC](https://discuss.elastic.co/t/limit-storage-needs-by-automatically-remove-data-after-28-days/329865 "2023-04-13T05:39:23Z")

</div>

I have my small test environment up and running. It is collecting data from different sources. Now i wonder how i can handle the effective file storage. Only 1 node in the cluster - non productive. Is it possible to co…

---

## [MAX\_LOCKED\_MEMORY=unlimited setting in Elasticsearch 8.x](https://discuss.elastic.co/t/max-locked-memory-unlimited-setting-in-elasticsearch-8-x/329884)

<div class="topic-metadata">

**Author:** [@Tomas\_Bartek](https://discuss.elastic.co/u/Tomas_Bartek)\
**Replies:** 0\
**Last updated:** [April 13, 2023, 5:34am UTC](https://discuss.elastic.co/t/max-locked-memory-unlimited-setting-in-elasticsearch-8-x/329884 "2023-04-13T05:34:29Z")

</div>

Is MAX\_LOCKED\_MEMORY=unlimited settings in /etc/default/elasticsearch (on Ubuntu) still necessary in Elasticsearch 8.x? It looks like settings in /etc/default/elasticsearch system configuration file is quite simplified …

---

## [Mongodb logstash data input](https://discuss.elastic.co/t/mongodb-logstash-data-input/329830)

<div class="topic-metadata">

**Author:** [@jskang](https://discuss.elastic.co/u/jskang)\
**Replies:** 2\
**Last updated:** [April 13, 2023, 5:34am UTC](https://discuss.elastic.co/t/mongodb-logstash-data-input/329830 "2023-04-13T05:34:09Z")

</div>

hello. After struggling for days, I finally connected mongodb and logstash. But another problem arose. I want to send only newly entered logs to the index using sql\_last\_value, but it doesn't work. Is this impossible…

---

## [Unable to send bunyan logs in kibana using elastic apm node module (node js code)](https://discuss.elastic.co/t/unable-to-send-bunyan-logs-in-kibana-using-elastic-apm-node-module-node-js-code/329652)

<div class="topic-metadata">

**Author:** [@sandboxpd123](https://discuss.elastic.co/u/sandboxpd123)\
**Replies:** 3\
**Last updated:** [April 13, 2023, 4:52am UTC](https://discuss.elastic.co/t/unable-to-send-bunyan-logs-in-kibana-using-elastic-apm-node-module-node-js-code/329652 "2023-04-13T04:52:32Z")

</div>

Hi Team, I have created a node js code where I created a bunyan logger class consist of a constructor that returns the logger in below format - public logger: any constructor (serviceName: string) { this.logger = bun…

---

## [Browser error: Your browser does not meet the security requirements for Kibana](https://discuss.elastic.co/t/browser-error-your-browser-does-not-meet-the-security-requirements-for-kibana/329499)

<div class="topic-metadata">

**Author:** [@Sandeep\_Raju](https://discuss.elastic.co/u/Sandeep_Raju)\
**Replies:** 1\
**Last updated:** [April 12, 2023, 10:39pm UTC](https://discuss.elastic.co/t/browser-error-your-browser-does-not-meet-the-security-requirements-for-kibana/329499 "2023-04-12T22:39:27Z")

</div>

Hi all, When my dashboards get loaded in browser, the below error pops up everytime & it gets frustrating to show this pop up to others. Dashboards get loaded , but this error pops up too. I'm using ES version 8.6.2 …

---

## [Date parse error](https://discuss.elastic.co/t/date-parse-error/329871)

<div class="topic-metadata">

**Author:** [@Kostyantyn\_Dobriohlo](https://discuss.elastic.co/u/Kostyantyn_Dobriohlo)\
**Replies:** 0\
**Last updated:** [April 12, 2023, 9:23pm UTC](https://discuss.elastic.co/t/date-parse-error/329871 "2023-04-12T21:23:30Z")

</div>

Hello, I have recently got this problem with parsing date of this format '2022-08-02T9:00:00 AMZ'. failed to parse field \[Date\] of type \[date\] in document with id 'uVxVd4cB4mQncJVwtSB8'. Preview of field's value: '2022-…

---

## [Disabling Hostname Verification on Elasticsearch 7.16 Outbound Connections](https://discuss.elastic.co/t/disabling-hostname-verification-on-elasticsearch-7-16-outbound-connections/329816)

<div class="topic-metadata">

**Author:** [@icey7z](https://discuss.elastic.co/u/icey7z)\
**Replies:** 4\
**Last updated:** [April 12, 2023, 8:01pm UTC](https://discuss.elastic.co/t/disabling-hostname-verification-on-elasticsearch-7-16-outbound-connections/329816 "2023-04-12T20:01:16Z")

</div>

I'm trying to do a remote reindexing from a 5.3 cluster to a 7.16 cluster, and need a way to disable hostname verification when communicating between them. The 5.3 cluster's certificate doesn't match the hostname, and I…

---

## [Error during plugin bundling , while running gradlew gem command](https://discuss.elastic.co/t/error-during-plugin-bundling-while-running-gradlew-gem-command/329864)

<div class="topic-metadata">

**Author:** [@Theophila\_Vaiz\_R](https://discuss.elastic.co/u/Theophila_Vaiz_R)\
**Replies:** 0\
**Last updated:** [April 12, 2023, 6:08pm UTC](https://discuss.elastic.co/t/error-during-plugin-bundling-while-running-gradlew-gem-command/329864 "2023-04-12T18:08:47Z")

</div>

I created a logstash output plugin and tried building using ./gradlew gem command but locally its fine I changed it as a automated jenkins pipeline there I'm facing this error TypeError: Could not initialize copy of dig…

---

## [I want to get all the spaces in my kibana using python API](https://discuss.elastic.co/t/i-want-to-get-all-the-spaces-in-my-kibana-using-python-api/327859)

<div class="topic-metadata">

**Author:** [@Bhrugu\_Sharma](https://discuss.elastic.co/u/Bhrugu_Sharma)\
**Replies:** 3\
**Last updated:** [April 12, 2023, 5:14pm UTC](https://discuss.elastic.co/t/i-want-to-get-all-the-spaces-in-my-kibana-using-python-api/327859 "2023-04-12T17:14:49Z")

</div>

I am trying to write a python script to get all the spaces in my Kibana spaces I tried all the different combos but there seems to be no proper way for it. Here are the few examples that i tired resp = client.api.space…

---

## [Script access to nested field](https://discuss.elastic.co/t/script-access-to-nested-field/329860)

<div class="topic-metadata">

**Author:** [@GR8](https://discuss.elastic.co/u/GR8)\
**Replies:** 0\
**Last updated:** [April 12, 2023, 4:42pm UTC](https://discuss.elastic.co/t/script-access-to-nested-field/329860 "2023-04-12T16:42:02Z")

</div>

Hello Elastic folks, I need to run a script that gets data from index\_a to index\_b with some basic ETL. This works well except I can't figure out the syntax for accessing a nested field like: "transitions": { "prope…

---

## [Log files getting accumulated in temporary\_directory path while reading logs from s3 buckets](https://discuss.elastic.co/t/log-files-getting-accumulated-in-temporary-directory-path-while-reading-logs-from-s3-buckets/329838)

<div class="topic-metadata">

**Author:** [@Anusha\_Kusanghi](https://discuss.elastic.co/u/Anusha_Kusanghi)\
**Replies:** 1\
**Last updated:** [April 12, 2023, 4:23pm UTC](https://discuss.elastic.co/t/log-files-getting-accumulated-in-temporary-directory-path-while-reading-logs-from-s3-buckets/329838 "2023-04-12T16:23:58Z")

</div>

Hi All, We have a logstash configuration to read logs from s3 bucket. Here is the configuration: input { s3 { access\_key\_id =\> "\*\*\*\*\*\*\*\*\*\*\*\*\*\*" secret\_access\_key =\> "hjiufaaaa" bucket =\> "test…

---

## [Elastic phrase suggester](https://discuss.elastic.co/t/elastic-phrase-suggester/329858)

<div class="topic-metadata">

**Author:** [@sujata1993](https://discuss.elastic.co/u/sujata1993)\
**Replies:** 0\
**Last updated:** [April 12, 2023, 4:16pm UTC](https://discuss.elastic.co/t/elastic-phrase-suggester/329858 "2023-04-12T16:16:49Z")

</div>

Query: POST merchants\_phrase\_suggester\_29032023/\_search { "suggest": { "text" : "amazn,walmart", "simple\_phrase" : { "phrase" : { "field" : "mrch\_nm.trigram", "size" : 1, "confidence":0, "gram\_size":3, "max…

---

## [What triggers regular merges?](https://discuss.elastic.co/t/what-triggers-regular-merges/329773)

<div class="topic-metadata">

**Author:** [@Emma\_Vaiserfirov](https://discuss.elastic.co/u/Emma_Vaiserfirov)\
**Replies:** 3\
**Last updated:** [April 12, 2023, 3:58pm UTC](https://discuss.elastic.co/t/what-triggers-regular-merges/329773 "2023-04-12T15:58:46Z")

</div>

Hi there, we're trying to decide if we need to trigger force merges on a regular basis. To do that, I was trying to understand how (and how often) merges are triggered by default. The piece of public documentation on mer…

---

## [Parse XML sub tags as a separate log](https://discuss.elastic.co/t/parse-xml-sub-tags-as-a-separate-log/329832)

<div class="topic-metadata">

**Author:** [@Disha\_Bodade](https://discuss.elastic.co/u/Disha_Bodade)\
**Replies:** 1\
**Last updated:** [April 12, 2023, 3:43pm UTC](https://discuss.elastic.co/t/parse-xml-sub-tags-as-a-separate-log/329832 "2023-04-12T15:43:17Z")

</div>

Hi Team, I have a XML formatted as below \<?xml version="1.0" encoding="UTF-8"?\> \<documents\> \<Document\>\<docID\>101074476\</docID\>\<Title\>End of Sale 1403 and 1416\</Title\>\<Author\>clark13\</Author\>\</Document\> \<Document\>\<docI…

---

## [Apply filters](https://discuss.elastic.co/t/apply-filters/329510)

<div class="topic-metadata">

**Author:** [@serjio](https://discuss.elastic.co/u/serjio)\
**Replies:** 2\
**Last updated:** [April 12, 2023, 3:29pm UTC](https://discuss.elastic.co/t/apply-filters/329510 "2023-04-12T15:29:23Z")

</div>

good afternoon. Recently I started to get acquainted with ELK and aot what is my problem: I use such a filter filter { if \[type\] == "syslog" { grok { match =\> { "message" =\> "\<%{POSINT:syslog\_pri}\>%{SYSLO…

---

## [Data view - number of Index timeout issue](https://discuss.elastic.co/t/data-view-number-of-index-timeout-issue/329769)

<div class="topic-metadata">

**Author:** [@elasticforme](https://discuss.elastic.co/u/elasticforme)\
**Replies:** 1\
**Last updated:** [April 12, 2023, 2:58pm UTC](https://discuss.elastic.co/t/data-view-number-of-index-timeout-issue/329769 "2023-04-12T14:58:34Z")

</div>

I have large index with high volume of data. one shard is 20gig, Lets say two index per day from six month = 360 index with billions of record combine. when I run following it timesout select x,y,z from myidex-\* wh…

---

## [The documents JSON is not valid](https://discuss.elastic.co/t/the-documents-json-is-not-valid/329114)

<div class="topic-metadata">

**Author:** [@Hajar\_Lachhab](https://discuss.elastic.co/u/Hajar_Lachhab)\
**Replies:** 6\
**Last updated:** [April 12, 2023, 2:38pm UTC](https://discuss.elastic.co/t/the-documents-json-is-not-valid/329114 "2023-04-12T14:38:12Z")

</div>

Hi everyone, I just wanna ask for a solution of my problem when i try to test my pipeline i got an error "The documents JSON is not valid." That's the document that i try to test my pipeline with it \[ { "\_source…

---

## [Elastic Aggregations query](https://discuss.elastic.co/t/elastic-aggregations-query/329807)

<div class="topic-metadata">

**Author:** [@math1](https://discuss.elastic.co/u/math1)\
**Replies:** 3\
**Last updated:** [April 12, 2023, 2:33pm UTC](https://discuss.elastic.co/t/elastic-aggregations-query/329807 "2023-04-12T14:33:39Z")

</div>

POST test/\_doc/ { "food": \[ { "food1": { "type": "Western food", "name": "hamburger" }, "food2": { "type": "Japanese food", "name": "sushi" } } \] } POS…

---

## [Bonnes pratiques concernant l'indexation de documents](https://discuss.elastic.co/t/bonnes-pratiques-concernant-lindexation-de-documents/329847)

<div class="topic-metadata">

**Author:** [@jarod51](https://discuss.elastic.co/u/jarod51)\
**Replies:** 1\
**Last updated:** [April 12, 2023, 2:31pm UTC](https://discuss.elastic.co/t/bonnes-pratiques-concernant-lindexation-de-documents/329847 "2023-04-12T14:31:51Z")

</div>

Bonjour J'ai un petit projet de stockage de documents sous le coude. Dans mon idée je voulais séparer la problématique de stockage (multi drives; potentiellement gros fichiers) de la problématique d'indexation (beaucoup…

---

## [Licence: install Elastic 7.16.2 Free or Platinum on Kubernetes](https://discuss.elastic.co/t/licence-install-elastic-7-16-2-free-or-platinum-on-kubernetes/329576)

<div class="topic-metadata">

**Author:** [@SalvoDM91](https://discuss.elastic.co/u/SalvoDM91)\
**Replies:** 10\
**Last updated:** [April 12, 2023, 2:21pm UTC](https://discuss.elastic.co/t/licence-install-elastic-7-16-2-free-or-platinum-on-kubernetes/329576 "2023-04-12T14:21:31Z")

</div>

HI Guys, I would like to install all ELK stack (Elasticsearch, Logstash and Kibana) on Kubernets. I'm undecided if using the Free or Platinum version but before proceeding I would like to know if there are any limits on…

---

## [Search: Removing full stop if part of acronym / abbreviation with pattern\_replace character filter](https://discuss.elastic.co/t/search-removing-full-stop-if-part-of-acronym-abbreviation-with-pattern-replace-character-filter/329810)

<div class="topic-metadata">

**Author:** [@Marzipan](https://discuss.elastic.co/u/Marzipan)\
**Replies:** 0\
**Last updated:** [April 12, 2023, 8:24am UTC](https://discuss.elastic.co/t/search-removing-full-stop-if-part-of-acronym-abbreviation-with-pattern-replace-character-filter/329810 "2023-04-12T08:24:05Z")

</div>

Hi! My input are author names and book titles. I try to delete full stops if they appear in acronyms and abbreviations. For example: S.O.S. should be replaced with SOS H.P. Lovecraft should be replaced with HP Lovec…

---

## [Can't create a cluster if node's domain points to the localhost in /etc/hosts](https://discuss.elastic.co/t/cant-create-a-cluster-if-nodes-domain-points-to-the-localhost-in-etc-hosts/329738)

<div class="topic-metadata">

**Author:** [@panrobot](https://discuss.elastic.co/u/panrobot)\
**Replies:** 8\
**Last updated:** [April 12, 2023, 2:06pm UTC](https://discuss.elastic.co/t/cant-create-a-cluster-if-nodes-domain-points-to-the-localhost-in-etc-hosts/329738 "2023-04-12T14:06:37Z")

</div>

Hi, if /etc/hosts/ is configured as follows: 127.0.0.1 node01.com 127.0.0.1 localhost and if you set elasticsearch.yml to: network.host: \["\_enp1s0\_", "\_local\_"\] …

---

## [Unable to create dead letter queue writer](https://discuss.elastic.co/t/unable-to-create-dead-letter-queue-writer/329688)

<div class="topic-metadata">

**Author:** [@tcapp24](https://discuss.elastic.co/u/tcapp24)\
**Replies:** 1\
**Last updated:** [April 12, 2023, 2:01pm UTC](https://discuss.elastic.co/t/unable-to-create-dead-letter-queue-writer/329688 "2023-04-12T14:01:10Z")

</div>

Logstash Version - 7.9.1 Currently we are unable to start Logstash properly without receiving error below: \[2023-04-10T20:18:52,978\]\[ERROR\]\[org.logstash.common.DeadLetterQueueFactory\] unable to create dead letter queue…

---

## [Kibana web page does not open when virtual machine interface is host-only](https://discuss.elastic.co/t/kibana-web-page-does-not-open-when-virtual-machine-interface-is-host-only/329684)

<div class="topic-metadata">

**Author:** [@kh1971](https://discuss.elastic.co/u/kh1971)\
**Replies:** 2\
**Last updated:** [April 12, 2023, 1:28pm UTC](https://discuss.elastic.co/t/kibana-web-page-does-not-open-when-virtual-machine-interface-is-host-only/329684 "2023-04-12T13:28:10Z")

</div>

I have recently installed elasticsearch on my Kali purple virtual machine with my VM interface setting set as network enabled. I used a vmnet which allowed me access to the internet via my regualr host machine. After in…

---

## [Aggregate secure/sshd syslog event based on selected events](https://discuss.elastic.co/t/aggregate-secure-sshd-syslog-event-based-on-selected-events/328249)

<div class="topic-metadata">

**Author:** [@jun.7.6](https://discuss.elastic.co/u/jun.7.6)\
**Replies:** 24\
**Last updated:** [April 12, 2023, 1:19pm UTC](https://discuss.elastic.co/t/aggregate-secure-sshd-syslog-event-based-on-selected-events/328249 "2023-04-12T13:19:55Z")

</div>

Hi I'm trying to filter out the login & logout events from linux ssh events send as syslog to Logstash and forward it to my firewall via syslog again. This setup is to allow my firewall to map the user-id to IP address i…

---

## [Multiple bulk actions on the same document](https://discuss.elastic.co/t/multiple-bulk-actions-on-the-same-document/329650)

<div class="topic-metadata">

**Author:** [@Tudor\_Plugaru](https://discuss.elastic.co/u/Tudor_Plugaru)\
**Replies:** 6\
**Last updated:** [April 12, 2023, 12:44pm UTC](https://discuss.elastic.co/t/multiple-bulk-actions-on-the-same-document/329650 "2023-04-12T12:44:52Z")

</div>

Hi, To index data into Elasticsearch, we are using an Apache Flink pipeline that is consuming from Kafka topics. The index mapping looks something like below, a document with nested documents: { "name": "email documen…

---

## [Query to Select Document based on only one object to be present under Node](https://discuss.elastic.co/t/query-to-select-document-based-on-only-one-object-to-be-present-under-node/329824)

<div class="topic-metadata">

**Author:** [@Harinder\_Singh](https://discuss.elastic.co/u/Harinder_Singh)\
**Replies:** 1\
**Last updated:** [April 12, 2023, 12:14pm UTC](https://discuss.elastic.co/t/query-to-select-document-based-on-only-one-object-to-be-present-under-node/329824 "2023-04-12T12:14:43Z")

</div>

Hi, We have data indexed as below { "tags": { "firstlevel": { "events": \[\], "promotions": \[\] } } } Data can be something like which has both events and promotions, just events or just promotion…

---

## [Controls in ES 8.6.2](https://discuss.elastic.co/t/controls-in-es-8-6-2/329828)

<div class="topic-metadata">

**Author:** [@rvadiga](https://discuss.elastic.co/u/rvadiga)\
**Replies:** 0\
**Last updated:** [April 12, 2023, 11:38am UTC](https://discuss.elastic.co/t/controls-in-es-8-6-2/329828 "2023-04-12T11:38:27Z")

</div>

Hi I am migrating from ES 7.17 to ES 8.6.2 with predefined set of Kibana dashboards. Each dashboard has definition of user input panel with few Elasticsearch index fields. Now, with 8.6.2 introduced 'Controls' as repl…

---

## [\[Elastic search\] wildcard (ignore case) query is not working](https://discuss.elastic.co/t/elastic-search-wildcard-ignore-case-query-is-not-working/329701)

<div class="topic-metadata">

**Author:** [@K\_Nam](https://discuss.elastic.co/u/K_Nam)\
**Replies:** 2\
**Last updated:** [April 12, 2023, 11:37am UTC](https://discuss.elastic.co/t/elastic-search-wildcard-ignore-case-query-is-not-working/329701 "2023-04-12T11:37:01Z")

</div>

I have a problem when using wildcard (ignore case) query. I am using v7.10.2 Uppercase Lower case I have 2 query, the first is uppercase, the other is not. My expected output is both query will return the same r…

[Previous page](https://discuss.elastic.co/tag/none.md?no_tags=true&page=398)

[Next page](https://discuss.elastic.co/tag/none.md?no_tags=true&page=400)
