# \#none

**URL:** https://discuss.elastic.co/tag/none.md?no_tags=true&page=411

[Latest](https://discuss.elastic.co/latest.md) · [Categories](https://discuss.elastic.co/categories.md) · [Tags](https://discuss.elastic.co/tags.md)

**Page:** 412

---

## [Tasks are stuck for hours for index creation & setting update](https://discuss.elastic.co/t/tasks-are-stuck-for-hours-for-index-creation-setting-update/328523)

<div class="topic-metadata">

**Author:** [@sanders\_2345](https://discuss.elastic.co/u/sanders_2345)\
**Replies:** 8\
**Last updated:** [March 26, 2023, 3:28pm UTC](https://discuss.elastic.co/t/tasks-are-stuck-for-hours-for-index-creation-setting-update/328523 "2023-03-26T15:28:51Z")

</div>

Our cluster has 4k+ indices, 36 data nodes(8c & 32g). ,3 mn (4c & 16g) Write is on 10k+ & read is very less No of primary shards - 4k+, replica 1 Es version: 5.x All tasks are running for hrs. Logs throwing RemoteTr…

---

## [Why when i build data back to es config max\_buckets it back to default](https://discuss.elastic.co/t/why-when-i-build-data-back-to-es-config-max-buckets-it-back-to-default/328545)

<div class="topic-metadata">

**Author:** [@xuan\_do](https://discuss.elastic.co/u/xuan_do)\
**Replies:** 0\
**Last updated:** [March 26, 2023, 8:41am UTC](https://discuss.elastic.co/t/why-when-i-build-data-back-to-es-config-max-buckets-it-back-to-default/328545 "2023-03-26T08:41:28Z")

</div>

when I upload data to es, config max\_buckets sometimes resets its value default. Why is that

---

## [Kibana Security Analyst Course - Access lab](https://discuss.elastic.co/t/kibana-security-analyst-course-access-lab/328540)

<div class="topic-metadata">

**Author:** [@Gal\_Baron](https://discuss.elastic.co/u/Gal_Baron)\
**Replies:** 0\
**Last updated:** [March 26, 2023, 7:28am UTC](https://discuss.elastic.co/t/kibana-security-analyst-course-access-lab/328540 "2023-03-26T07:28:05Z")

</div>

Course: Kibana Security Analyst Version: Image version: 3.2.4, CTFd version: 3.3.0 Question: I'm currently learning the Kibana Security Analyst course. For some reason I can't setting up my lab. The URL from the CTF…

---

## [Dashboards and index patterns lost after upgrade from 7 to 8](https://discuss.elastic.co/t/dashboards-and-index-patterns-lost-after-upgrade-from-7-to-8/328531)

<div class="topic-metadata">

**Author:** [@SANDEEP\_SOMAPANGU](https://discuss.elastic.co/u/SANDEEP_SOMAPANGU)\
**Replies:** 2\
**Last updated:** [March 26, 2023, 3:40am UTC](https://discuss.elastic.co/t/dashboards-and-index-patterns-lost-after-upgrade-from-7-to-8/328531 "2023-03-26T03:40:53Z")

</div>

Hello, we recently upgraded from kibana version 7 to 8. In the previous version, we stored our configuration in the index named .kibana-abc\_7.17.9\_001. However, it appears that version 8 no longer supports this kind of i…

---

## [Logstash - rabbitmq config to get multiple queues data to multiple elastic indeces](https://discuss.elastic.co/t/logstash-rabbitmq-config-to-get-multiple-queues-data-to-multiple-elastic-indeces/328520)

<div class="topic-metadata">

**Author:** [@qrshat](https://discuss.elastic.co/u/qrshat)\
**Replies:** 5\
**Last updated:** [March 25, 2023, 10:20pm UTC](https://discuss.elastic.co/t/logstash-rabbitmq-config-to-get-multiple-queues-data-to-multiple-elastic-indeces/328520 "2023-03-25T22:20:13Z")

</div>

scenario: rabbitmq have different queues more than three. I want to make logstash configuration to get data from the rabbitmq queue and index this data to Elasticsearch. In order to that I have created logstash conf fi…

---

## [Elastic Search was not loaded](https://discuss.elastic.co/t/elastic-search-was-not-loaded/328504)

<div class="topic-metadata">

**Author:** [@Alex\_David\_Hurtado\_Y](https://discuss.elastic.co/u/Alex_David_Hurtado_Y)\
**Replies:** 1\
**Last updated:** [March 25, 2023, 11:23am UTC](https://discuss.elastic.co/t/elastic-search-was-not-loaded/328504 "2023-03-25T11:23:08Z")

</div>

HI, i´m using laradock with laravel, on the laravel project is integrte elasticsearch and inatalled the imgae the elasticsearch. The project get a command to fill a table using elasticsearch, buy trow the error: Elastic…

---

## [ECK operator](https://discuss.elastic.co/t/eck-operator/328516)

<div class="topic-metadata">

**Author:** [@abdul90082](https://discuss.elastic.co/u/abdul90082)\
**Replies:** 0\
**Last updated:** [March 25, 2023, 10:20am UTC](https://discuss.elastic.co/t/eck-operator/328516 "2023-03-25T10:20:56Z")

</div>

Hi everyone! we would like to use ES operator in all our cluster to monitor kubernetes logs. We have tried to get fleet and the agents working based on our scenario that looks the following: We are trying to send the l…

---

## [Is it normal for my ElasticSearch process to consume 10% of the CPU even when there are no read or write requests?](https://discuss.elastic.co/t/is-it-normal-for-my-elasticsearch-process-to-consume-10-of-the-cpu-even-when-there-are-no-read-or-write-requests/328507)

<div class="topic-metadata">

**Author:** [@zzzzer91](https://discuss.elastic.co/u/zzzzer91)\
**Replies:** 2\
**Last updated:** [March 25, 2023, 6:50am UTC](https://discuss.elastic.co/t/is-it-normal-for-my-elasticsearch-process-to-consume-10-of-the-cpu-even-when-there-are-no-read-or-write-requests/328507 "2023-03-25T06:50:33Z")

</div>

Elasticsearch Version elasticsearch-8.5.3 Installed Plugins No response Java Version bundled OS Version 4.19.188-10.el7 Problem Description Is it normal for Elasticsearch to consume 10% CPU even without requests afte…

---

## [Condicional if with Regex](https://discuss.elastic.co/t/condicional-if-with-regex/328417)

<div class="topic-metadata">

**Author:** [@Claudio\_Ract\_Costa](https://discuss.elastic.co/u/Claudio_Ract_Costa)\
**Replies:** 4\
**Last updated:** [March 25, 2023, 1:21am UTC](https://discuss.elastic.co/t/condicional-if-with-regex/328417 "2023-03-25T01:21:46Z")

</div>

Hi everybody, Does anyone know how can I build a "if" condicional that logstash change de number "1" to string "Worked" ? As example, the input are lines like: hello,ola,1hi,1 1,red1,1,green 1 ... and the output…

---

## [Parsing JSON Array In Event](https://discuss.elastic.co/t/parsing-json-array-in-event/328393)

<div class="topic-metadata">

**Author:** [@wwalker](https://discuss.elastic.co/u/wwalker)\
**Replies:** 9\
**Last updated:** [March 24, 2023, 9:54pm UTC](https://discuss.elastic.co/t/parsing-json-array-in-event/328393 "2023-03-24T21:54:24Z")

</div>

I am using the jdbc\_streaming filter to pull additional data for an event from a database, the result looks like below. Any ideas on how I could have this parsed out so that I don't lose any of the data and keep it all …

---

## [Browse and Navigate functionality](https://discuss.elastic.co/t/browse-and-navigate-functionality/328427)

<div class="topic-metadata">

**Author:** [@mruthyu](https://discuss.elastic.co/u/mruthyu)\
**Replies:** 1\
**Last updated:** [March 24, 2023, 8:46pm UTC](https://discuss.elastic.co/t/browse-and-navigate-functionality/328427 "2023-03-24T20:46:16Z")

</div>

Checking if any of the elastisearch features supports browse and navigate functionality.

---

## [Change Nil values to set default value](https://discuss.elastic.co/t/change-nil-values-to-set-default-value/328369)

<div class="topic-metadata">

**Author:** [@rubhamra](https://discuss.elastic.co/u/rubhamra)\
**Replies:** 3\
**Last updated:** [March 24, 2023, 7:29pm UTC](https://discuss.elastic.co/t/change-nil-values-to-set-default-value/328369 "2023-03-24T19:29:14Z")

</div>

Logstash is dropping fields which has "nil" values, but I don't want those fields to be drop, but at least we can set it to default values if the field is nil, else it has it's original value. I tried with this code fou…

---

## [Elasticsearch combining Filter with Bool by a Must](https://discuss.elastic.co/t/elasticsearch-combining-filter-with-bool-by-a-must/327863)

<div class="topic-metadata">

**Author:** [@MonikaJ](https://discuss.elastic.co/u/MonikaJ)\
**Replies:** 1\
**Last updated:** [March 24, 2023, 4:45pm UTC](https://discuss.elastic.co/t/elasticsearch-combining-filter-with-bool-by-a-must/327863 "2023-03-24T16:45:15Z")

</div>

I am trying to combine a "filter" with a "bool"/"should" inside a "must". The following query is automatically generated by an application (hence the nesting). How must the query look like to have an AND condition betwee…

---

## [Haystack US 2023 - The Search Relevance Conference](https://discuss.elastic.co/t/haystack-us-2023-the-search-relevance-conference/328479)

<div class="topic-metadata">

**Author:** [@flaxsearch](https://discuss.elastic.co/u/flaxsearch)\
**Replies:** 0\
**Last updated:** [March 24, 2023, 4:36pm UTC](https://discuss.elastic.co/t/haystack-us-2023-the-search-relevance-conference/328479 "2023-03-24T16:36:07Z")

</div>

We've published the talk schedule for Haystack US 2023, The Search Relevance Conference - and I don't think we've ever had such an amazing list of speakers from organisations like Amazon, Reddit, Elsevier; from authors o…

---

## [Logstash Kafka input - converting date to string format](https://discuss.elastic.co/t/logstash-kafka-input-converting-date-to-string-format/327967)

<div class="topic-metadata">

**Author:** [@zaeemmasood](https://discuss.elastic.co/u/zaeemmasood)\
**Replies:** 6\
**Last updated:** [March 24, 2023, 4:20pm UTC](https://discuss.elastic.co/t/logstash-kafka-input-converting-date-to-string-format/327967 "2023-03-24T16:20:27Z")

</div>

Hello, We are using Kafka plugin to get feed into Logstash. One of the fields that come with the message is in date format. I need to convert that date into string format. Please guide. My config file looks as follo…

---

## [What is the ratio between raw data and ingested data that is stored in Elastic cluster](https://discuss.elastic.co/t/what-is-the-ratio-between-raw-data-and-ingested-data-that-is-stored-in-elastic-cluster/327945)

<div class="topic-metadata">

**Author:** [@hiruni.insyncit.net](https://discuss.elastic.co/u/hiruni.insyncit.net)\
**Replies:** 3\
**Last updated:** [March 24, 2023, 4:20pm UTC](https://discuss.elastic.co/t/what-is-the-ratio-between-raw-data-and-ingested-data-that-is-stored-in-elastic-cluster/327945 "2023-03-24T16:20:41Z")

</div>

Hi, I want to know what the ratio is between raw data and ingested data that is stored in Elastic cluster. I know raw logs and ingested logs are not same in size. Also is there any way to find the incoming raw log vol…

---

## [High availability with two servers](https://discuss.elastic.co/t/high-availability-with-two-servers/328467)

<div class="topic-metadata">

**Author:** [@amiraliw](https://discuss.elastic.co/u/amiraliw)\
**Replies:** 3\
**Last updated:** [March 24, 2023, 2:43pm UTC](https://discuss.elastic.co/t/high-availability-with-two-servers/328467 "2023-03-24T14:43:53Z")

</div>

I have only two servers, how I should configure elasticsearch nodes to get high availability and avoid split-brain? should I only have one node on each server?

---

## [How variable width histogram with nested aggregations works](https://discuss.elastic.co/t/how-variable-width-histogram-with-nested-aggregations-works/328219)

<div class="topic-metadata">

**Author:** [@rym](https://discuss.elastic.co/u/rym)\
**Replies:** 2\
**Last updated:** [March 24, 2023, 1:24pm UTC](https://discuss.elastic.co/t/how-variable-width-histogram-with-nested-aggregations-works/328219 "2023-03-24T13:24:56Z")

</div>

Hi, I want to use the variable\_width\_histogram combined with other aggregations, such as min or max Here is an example of combinated aggregations on a numeric field: "aggs": { "aggregated-items": { …

---

## [Context suggester with search api](https://discuss.elastic.co/t/context-suggester-with-search-api/328245)

<div class="topic-metadata">

**Author:** [@mangeshs](https://discuss.elastic.co/u/mangeshs)\
**Replies:** 2\
**Last updated:** [March 24, 2023, 12:13pm UTC](https://discuss.elastic.co/t/context-suggester-with-search-api/328245 "2023-03-24T12:13:09Z")

</div>

I am using Elasticsearch 7.4 and java client api. I want to use context suggester with search api given in this document Suggesters | Elasticsearch Guide \[8.6\] | Elastic can any one give me any sample documents which e…

---

## [Network Policy, elastic-operator eck k8s Openshift](https://discuss.elastic.co/t/network-policy-elastic-operator-eck-k8s-openshift/328457)

<div class="topic-metadata">

**Author:** [@splitmessage88](https://discuss.elastic.co/u/splitmessage88)\
**Replies:** 0\
**Last updated:** [March 24, 2023, 12:07pm UTC](https://discuss.elastic.co/t/network-policy-elastic-operator-eck-k8s-openshift/328457 "2023-03-24T12:07:59Z")

</div>

Hi team, We are stuck with the networkPolicy between elastic-operator and to our respective namespace for elastic stack. The communication between elastic-operator and elastic-agent and kibana works fine but elasticsea…

---

## [Logstash nested json parsing,getting every nested json as seperate field](https://discuss.elastic.co/t/logstash-nested-json-parsing-getting-every-nested-json-as-seperate-field/327956)

<div class="topic-metadata">

**Author:** [@PRASHANT\_MEHTA](https://discuss.elastic.co/u/PRASHANT_MEHTA)\
**Replies:** 12\
**Last updated:** [March 24, 2023, 11:51am UTC](https://discuss.elastic.co/t/logstash-nested-json-parsing-getting-every-nested-json-as-seperate-field/327956 "2023-03-24T11:51:44Z")

</div>

Hello, After trying several times I'm unable to parse below json string data coming from oracle column called: package\_data.Kindly assist how to get data in elastic to show data like below from given data. {"status":"R…

---

## [Elasticsearch Cluster](https://discuss.elastic.co/t/elasticsearch-cluster/328443)

<div class="topic-metadata">

**Author:** [@Marco\_Batista\_12](https://discuss.elastic.co/u/Marco_Batista_12)\
**Replies:** 2\
**Last updated:** [March 24, 2023, 10:03am UTC](https://discuss.elastic.co/t/elasticsearch-cluster/328443 "2023-03-24T10:03:07Z")

</div>

Could someone help me to have a cluster with a main machine that has elasticsearch and kibana and other 9 machines with only elasticsearch that are slaves.

---

## [Rule Preview not Working](https://discuss.elastic.co/t/rule-preview-not-working/327737)

<div class="topic-metadata">

**Author:** [@j91321](https://discuss.elastic.co/u/j91321)\
**Replies:** 3\
**Last updated:** [March 24, 2023, 9:55am UTC](https://discuss.elastic.co/t/rule-preview-not-working/327737 "2023-03-24T09:55:36Z")

</div>

I have this weird problem where detection engine rules preview is not working for users. Now the users have roles that grant them read access to .preview.alerts-security.alerts-\<space-id\> and All Kibana pirvileges on Ki…

---

## [License Banned Nexus IQ Vulnerability in 7.16.2](https://discuss.elastic.co/t/license-banned-nexus-iq-vulnerability-in-7-16-2/328419)

<div class="topic-metadata">

**Author:** [@PAVK\_PRASAD](https://discuss.elastic.co/u/PAVK_PRASAD)\
**Replies:** 3\
**Last updated:** [March 24, 2023, 6:31am UTC](https://discuss.elastic.co/t/license-banned-nexus-iq-vulnerability-in-7-16-2/328419 "2023-03-24T06:31:39Z")

</div>

Hi Team, We are using 7.16.2 Version of ES and we Observed "License Banned" Nexus IQ Scan issue in 7.16.2 with Elastic Search where as ES 7.10.0 doesn't have this issue. If We want go back to 7.10.0, In that version we…

---

## [2 Mongo DB collection how to merge in Logstash](https://discuss.elastic.co/t/2-mongo-db-collection-how-to-merge-in-logstash/328423)

<div class="topic-metadata">

**Author:** [@rachit](https://discuss.elastic.co/u/rachit)\
**Replies:** 0\
**Last updated:** [March 24, 2023, 6:29am UTC](https://discuss.elastic.co/t/2-mongo-db-collection-how-to-merge-in-logstash/328423 "2023-03-24T06:29:03Z")

</div>

Hi Team, Can anyone help me to merge 2 different collection of mongodb in single index in Elasticsearch with sync enable feature. Thanks

---

## [Hide size parameter from URL](https://discuss.elastic.co/t/hide-size-parameter-from-url/328397)

<div class="topic-metadata">

**Author:** [@ach](https://discuss.elastic.co/u/ach)\
**Replies:** 3\
**Last updated:** [March 24, 2023, 6:18am UTC](https://discuss.elastic.co/t/hide-size-parameter-from-url/328397 "2023-03-24T06:18:14Z")

</div>

Hi all, I want to hide the size parameter from the search query URL, e.g., site.com/?q=phone&size=n\_10\_n and I want to hide '&size=n\_10\_n.' Is configuring the routing options the way to go? I would greatly appreciate i…

---

## [TypeError: no implicit conversion of nil into String](https://discuss.elastic.co/t/typeerror-no-implicit-conversion-of-nil-into-string/328416)

<div class="topic-metadata">

**Author:** [@kala\_y](https://discuss.elastic.co/u/kala_y)\
**Replies:** 0\
**Last updated:** [March 24, 2023, 3:38am UTC](https://discuss.elastic.co/t/typeerror-no-implicit-conversion-of-nil-into-string/328416 "2023-03-24T03:38:12Z")

</div>

2023-03-23T22:23:02.967-05:00 Copy \[2023-03-24T03:23:02,967\]\[WARN \]\[logstash.inputs.s3snssqs \]\[main\]\[97e0bbb90d3a28c08cdd88a484e0aa3737932f33f22b59839ba78170f15c7929\] Error in poller loop {:error=\>#\<TypeError: no impli…

---

## [Hyperthreading effects on Elasticsearch performance](https://discuss.elastic.co/t/hyperthreading-effects-on-elasticsearch-performance/328402)

<div class="topic-metadata">

**Author:** [@Vadym](https://discuss.elastic.co/u/Vadym)\
**Replies:** 3\
**Last updated:** [March 24, 2023, 3:39am UTC](https://discuss.elastic.co/t/hyperthreading-effects-on-elasticsearch-performance/328402 "2023-03-24T03:39:48Z")

</div>

Hi team, What's the current recommendations regarding Hyper Threading with Elasticsearch, do we get any benefits and are there any downsides to keep HT enabled? I've seen multiple performance tests documents which clai…

---

## [Byte size in is bigger than real traffic packages in Network Explore](https://discuss.elastic.co/t/byte-size-in-is-bigger-than-real-traffic-packages-in-network-explore/328145)

<div class="topic-metadata">

**Author:** [@wishes9](https://discuss.elastic.co/u/wishes9)\
**Replies:** 2\
**Last updated:** [March 24, 2023, 3:38am UTC](https://discuss.elastic.co/t/byte-size-in-is-bigger-than-real-traffic-packages-in-network-explore/328145 "2023-03-24T03:38:22Z")

</div>

elasticsearch-8.6.1 kibana-8.6.1 logstash-8.6.1 I install packetbeat in the VM which install elastic stack. When I try to use Security - Explore - Network in Kibana, I find that the traffice Bytes account is much more…

---

## [JSON Logstash](https://discuss.elastic.co/t/json-logstash/328403)

<div class="topic-metadata">

**Author:** [@Whazaza](https://discuss.elastic.co/u/Whazaza)\
**Replies:** 0\
**Last updated:** [March 24, 2023, 12:55am UTC](https://discuss.elastic.co/t/json-logstash/328403 "2023-03-24T00:55:06Z")

</div>

I have a problem when taking the data from my json suppose i need to take the data from this json { "header" : { "sendingApplicationNs" : "value", "sendingApplicationId" : "value", "sendingApplicationIdTy…

[Previous page](https://discuss.elastic.co/tag/none.md?no_tags=true&page=410)

[Next page](https://discuss.elastic.co/tag/none.md?no_tags=true&page=412)
