# \#none

**URL:** https://discuss.elastic.co/tag/none.md?no_tags=true&page=413

[Latest](https://discuss.elastic.co/latest.md) · [Categories](https://discuss.elastic.co/categories.md) · [Tags](https://discuss.elastic.co/tags.md)

**Page:** 414

---

## [Too much network data out in 8.4.3 elasticsearch](https://discuss.elastic.co/t/too-much-network-data-out-in-8-4-3-elasticsearch/328182)

<div class="topic-metadata">

**Author:** [@Dharampal\_Singh](https://discuss.elastic.co/u/Dharampal_Singh)\
**Replies:** 9\
**Last updated:** [March 23, 2023, 5:43am UTC](https://discuss.elastic.co/t/too-much-network-data-out-in-8-4-3-elasticsearch/328182 "2023-03-23T05:43:09Z")

</div>

HI We have migrated from elasticsearch 6.2.3 to 8.4.3 and seeing huge network data transfer cost.is anyone else also facing this issue or its suppose to be happen. in my configuration only 3 node cluster all are mater …

---

## [Why is the length of keyword array always 1?](https://discuss.elastic.co/t/why-is-the-length-of-keyword-array-always-1/328164)

<div class="topic-metadata">

**Author:** [@lyq2333](https://discuss.elastic.co/u/lyq2333)\
**Replies:** 6\
**Last updated:** [March 23, 2023, 12:56am UTC](https://discuss.elastic.co/t/why-is-the-length-of-keyword-array-always-1/328164 "2023-03-23T00:56:28Z")

</div>

I create an index by PUT my-index-000002 { "mappings": { "properties": { "content":{ "type": "keyword", "index\_options": "freqs" }, "id":{ "type": "integer" } } …

---

## [ORing a text field with a unique identifier keyword field leading to increased next\_doc count and poor performance](https://discuss.elastic.co/t/oring-a-text-field-with-a-unique-identifier-keyword-field-leading-to-increased-next-doc-count-and-poor-performance/328283)

<div class="topic-metadata">

**Author:** [@helderdias](https://discuss.elastic.co/u/helderdias)\
**Replies:** 8\
**Last updated:** [March 22, 2023, 11:24pm UTC](https://discuss.elastic.co/t/oring-a-text-field-with-a-unique-identifier-keyword-field-leading-to-increased-next-doc-count-and-poor-performance/328283 "2023-03-22T23:24:18Z")

</div>

TL;DR: I want to find documents that match a certain query (e.g. "my search") OR match the unique ID of a document. When I search for the text field alone, the search is super fast. However, when I or the text field wit…

---

## [K8s multiple replicas pq](https://discuss.elastic.co/t/k8s-multiple-replicas-pq/327887)

<div class="topic-metadata">

**Author:** [@liel\_bondy](https://discuss.elastic.co/u/liel_bondy)\
**Replies:** 3\
**Last updated:** [March 19, 2023, 1:10pm UTC](https://discuss.elastic.co/t/k8s-multiple-replicas-pq/327887 "2023-03-19T13:10:15Z")

</div>

Hey, quick question. If I want to scale my logstash (with PQ) horizontally in k8s, I would just increase the replica amount. Now that I have multiple nodes, I would like to understand how the PQ manages race conditions.…

---

## [Logstash TCP input pipeline performance issues](https://discuss.elastic.co/t/logstash-tcp-input-pipeline-performance-issues/328006)

<div class="topic-metadata">

**Author:** [@mread830](https://discuss.elastic.co/u/mread830)\
**Replies:** 9\
**Last updated:** [March 22, 2023, 9:44pm UTC](https://discuss.elastic.co/t/logstash-tcp-input-pipeline-performance-issues/328006 "2023-03-22T21:44:22Z")

</div>

I’m having an issue when a particular pipeline and i’m not sure how to track it down or trouble shoot it further.. First, I have multiple cloud environments, configured the same, sending to the same endpoints. 2 of the…

---

## [Threat intelligence](https://discuss.elastic.co/t/threat-intelligence/328211)

<div class="topic-metadata">

**Author:** [@ermilan2309](https://discuss.elastic.co/u/ermilan2309)\
**Replies:** 7\
**Last updated:** [March 22, 2023, 9:30pm UTC](https://discuss.elastic.co/t/threat-intelligence/328211 "2023-03-22T21:30:33Z")

</div>

Hello, I would like to integrate threat intelligence with wazuh. How can I do that. what are the ways to archive this ? I have deployed the hive , cortex and MISP for threat intelligence but do not know how to integra…

---

## [Remove Specific Field matching pattern](https://discuss.elastic.co/t/remove-specific-field-matching-pattern/328260)

<div class="topic-metadata">

**Author:** [@rubhamra](https://discuss.elastic.co/u/rubhamra)\
**Replies:** 4\
**Last updated:** [March 22, 2023, 8:55pm UTC](https://discuss.elastic.co/t/remove-specific-field-matching-pattern/328260 "2023-03-22T20:55:44Z")

</div>

Hello I am trying to remove specific fields in logstash before it goes to elasticssearch, I tried below config. with drop option. if "\[response\]\[body\]\[entries\]\[values\]" == '^n1D.\*' { drop { } } I have a…

---

## [It is not possible to install Multi-tenancy in kibana](https://discuss.elastic.co/t/it-is-not-possible-to-install-multi-tenancy-in-kibana/328274)

<div class="topic-metadata">

**Author:** [@Marco\_Batista\_12](https://discuss.elastic.co/u/Marco_Batista_12)\
**Replies:** 1\
**Last updated:** [March 22, 2023, 8:50pm UTC](https://discuss.elastic.co/t/it-is-not-possible-to-install-multi-tenancy-in-kibana/328274 "2023-03-22T20:50:21Z")

</div>

There is no possibility or plugin for the latest version to install Multi-tenancy.

---

## [Unable to PUT \_index\_template which was captured from GET \_index\_template](https://discuss.elastic.co/t/unable-to-put-index-template-which-was-captured-from-get-index-template/328221)

<div class="topic-metadata">

**Author:** [@eeijlar](https://discuss.elastic.co/u/eeijlar)\
**Replies:** 4\
**Last updated:** [March 22, 2023, 7:14pm UTC](https://discuss.elastic.co/t/unable-to-put-index-template-which-was-captured-from-get-index-template/328221 "2023-03-22T19:14:32Z")

</div>

I am getting an index template as follows: curl -X GET http://localhost:9200/\_index\_template/filebeat\* \> /var/tmp/filebeat-template.json Now I want to PUT the same template into another elastic instance: curl http://…

---

## [{"statusCode":503,"error":"Service Unavailable","message":"License is not available."}](https://discuss.elastic.co/t/statuscode-503-error-service-unavailable-message-license-is-not-available/326340)

<div class="topic-metadata">

**Author:** [@nvelumani](https://discuss.elastic.co/u/nvelumani)\
**Replies:** 5\
**Last updated:** [March 22, 2023, 6:43pm UTC](https://discuss.elastic.co/t/statuscode-503-error-service-unavailable-message-license-is-not-available/326340 "2023-03-22T18:43:59Z")

</div>

Hello Team, I have installed elastic version 8.5.2 on three node cluster, it runs good. when I take down down node 2 (master -2), cluster is up and running with other two nodes. when I take down down node 3 (master -3…

---

## [Elasticsearch endpoint giving http 504 error](https://discuss.elastic.co/t/elasticsearch-endpoint-giving-http-504-error/328276)

<div class="topic-metadata">

**Author:** [@Raman\_Sawhney](https://discuss.elastic.co/u/Raman_Sawhney)\
**Replies:** 1\
**Last updated:** [March 22, 2023, 4:58pm UTC](https://discuss.elastic.co/t/elasticsearch-endpoint-giving-http-504-error/328276 "2023-03-22T16:58:16Z")

</div>

Hello Team, I am trying to install Elasticsearch on Kubernetes (1.24) version using the Elasticsearch(8.5.1) helm charts. I was able to install the charts and pods are in running status but when i tried to access the e…

---

## [ES persistent outages](https://discuss.elastic.co/t/es-persistent-outages/327395)

<div class="topic-metadata">

**Author:** [@orthecreedence](https://discuss.elastic.co/u/orthecreedence)\
**Replies:** 5\
**Last updated:** [March 22, 2023, 4:22pm UTC](https://discuss.elastic.co/t/es-persistent-outages/327395 "2023-03-22T16:22:35Z")

</div>

Hello. We recently upgraded to ES 7.17.9 (8.x is on the radar, but we have a lot of reindexing to do before then) and are having a lot of problems. We're using a fairly stock configuration on EC2. Our setup consists of …

---

## [Why I get after Client.Indices.Create() a second and unassigned index?](https://discuss.elastic.co/t/why-i-get-after-client-indices-create-a-second-and-unassigned-index/328264)

<div class="topic-metadata">

**Author:** [@frankmehlhop.com](https://discuss.elastic.co/u/frankmehlhop.com)\
**Replies:** 2\
**Last updated:** [March 22, 2023, 3:34pm UTC](https://discuss.elastic.co/t/why-i-get-after-client-indices-create-a-second-and-unassigned-index/328264 "2023-03-22T15:34:12Z")

</div>

I create a index on Elasticsearch with the C# code below. But instead of creating one assigned index I find a second unassigned index with the same name. I don't want and need this second (unassigned) index. My elasticse…

---

## [Elastic-agent with Misp integration policy no data received while no errors comes up](https://discuss.elastic.co/t/elastic-agent-with-misp-integration-policy-no-data-received-while-no-errors-comes-up/328183)

<div class="topic-metadata">

**Author:** [@Nicolas\_Pellletier](https://discuss.elastic.co/u/Nicolas_Pellletier)\
**Replies:** 8\
**Last updated:** [March 22, 2023, 2:37pm UTC](https://discuss.elastic.co/t/elastic-agent-with-misp-integration-policy-no-data-received-while-no-errors-comes-up/328183 "2023-03-22T14:37:58Z")

</div>

Hello, I've got a standalone elastic-agent deployed on localhost where my MISP instance is running. I'm trying to integrate MISP IOC's to Elastic in order to use the dashboard. I don't understand why i don't receive a…

---

## [Increase doc\_count even if record is same in date\_histogram on Array field](https://discuss.elastic.co/t/increase-doc-count-even-if-record-is-same-in-date-histogram-on-array-field/328257)

<div class="topic-metadata">

**Author:** [@AbhimanyuSharma](https://discuss.elastic.co/u/AbhimanyuSharma)\
**Replies:** 0\
**Last updated:** [March 22, 2023, 2:16pm UTC](https://discuss.elastic.co/t/increase-doc-count-even-if-record-is-same-in-date-histogram-on-array-field/328257 "2023-03-22T14:16:41Z")

</div>

I have an object / array field which contains date-time. This field contains every second of the duration between start and end time of some event. I am doing this because I want to see the running events on each second.…

---

## [Elastic shards are not storing data equally](https://discuss.elastic.co/t/elastic-shards-are-not-storing-data-equally/328235)

<div class="topic-metadata">

**Author:** [@Chanaka\_Liyanarachch](https://discuss.elastic.co/u/Chanaka_Liyanarachch)\
**Replies:** 1\
**Last updated:** [March 22, 2023, 12:39pm UTC](https://discuss.elastic.co/t/elastic-shards-are-not-storing-data-equally/328235 "2023-03-22T12:39:54Z")

</div>

elastic shards are not storing data equally,

---

## [Too many properties: should we increase the property limit or use a nested approach and increase that limit?](https://discuss.elastic.co/t/too-many-properties-should-we-increase-the-property-limit-or-use-a-nested-approach-and-increase-that-limit/328179)

<div class="topic-metadata">

**Author:** [@obi-wan](https://discuss.elastic.co/u/obi-wan)\
**Replies:** 3\
**Last updated:** [March 22, 2023, 11:19am UTC](https://discuss.elastic.co/t/too-many-properties-should-we-increase-the-property-limit-or-use-a-nested-approach-and-increase-that-limit/328179 "2023-03-22T11:19:59Z")

</div>

Hi there, We have a situation with limits in the mapping, and I am not sure what is the way to go as there are multiple solutions. I will start by describing the use case: there are multiple tenants, which each have …

---

## [UPDATE existing index with reindex and pipeline](https://discuss.elastic.co/t/update-existing-index-with-reindex-and-pipeline/328227)

<div class="topic-metadata">

**Author:** [@hben](https://discuss.elastic.co/u/hben)\
**Replies:** 0\
**Last updated:** [March 22, 2023, 9:51am UTC](https://discuss.elastic.co/t/update-existing-index-with-reindex-and-pipeline/328227 "2023-03-22T09:51:54Z")

</div>

Hi, I have an index that our application is working with like a Relational table, so we insert and update documents in it. now we want to make a structure change and add 3 fields and add data to those fields from a ta…

---

## [How to use user-defined plugin](https://discuss.elastic.co/t/how-to-use-user-defined-plugin/328224)

<div class="topic-metadata">

**Author:** [@wendywong0020](https://discuss.elastic.co/u/wendywong0020)\
**Replies:** 0\
**Last updated:** [March 22, 2023, 9:24am UTC](https://discuss.elastic.co/t/how-to-use-user-defined-plugin/328224 "2023-03-22T09:24:06Z")

</div>

logstash.conf: input { file { type =\> "\_doc" path =\> "/data/mysql\_\*\_log/slow.log" codec =\> multiline { …

---

## [Edit Deployment Cloud without downtime](https://discuss.elastic.co/t/edit-deployment-cloud-without-downtime/328177)

<div class="topic-metadata">

**Author:** [@davide.lilliu](https://discuss.elastic.co/u/davide.lilliu)\
**Replies:** 2\
**Last updated:** [March 22, 2023, 9:15am UTC](https://discuss.elastic.co/t/edit-deployment-cloud-without-downtime/328177 "2023-03-22T09:15:19Z")

</div>

Hi, i want to edit my deployment cloud from 3 server elastic server hot data to 1 hot data and 2 warm data. I read this document ec-customize-deployment and it seems that the old servers are not turned off before the n…

---

## [Mailenable server smtp activity logs using filebeat to elasticsearch](https://discuss.elastic.co/t/mailenable-server-smtp-activity-logs-using-filebeat-to-elasticsearch/327852)

<div class="topic-metadata">

**Author:** [@dharminfadia](https://discuss.elastic.co/u/dharminfadia)\
**Replies:** 2\
**Last updated:** [March 22, 2023, 9:08am UTC](https://discuss.elastic.co/t/mailenable-server-smtp-activity-logs-using-filebeat-to-elasticsearch/327852 "2023-03-22T09:08:34Z")

</div>

Hello Every one I am using elasticsearch 7.10 and filebeat 7.10 I want to pars following logs using filebeat to direct elasticsearch I have no Idea how I can achive can you please suggest me from my sample logs. 03/15/…

---

## [Detected ambiguous Field Reference warning](https://discuss.elastic.co/t/detected-ambiguous-field-reference-warning/328218)

<div class="topic-metadata">

**Author:** [@parosio](https://discuss.elastic.co/u/parosio)\
**Replies:** 1\
**Last updated:** [March 22, 2023, 8:29am UTC](https://discuss.elastic.co/t/detected-ambiguous-field-reference-warning/328218 "2023-03-22T08:29:58Z")

</div>

Hello, I've got to ingest (logstash 6.7) documents which are stages of a workflow (queue\_in, start\_work, end\_work, queue\_out, etc.). I need to add various fields with elapsed times (looking for initial times in previou…

---

## [Extract logs from a file that start with a line and end with a known line do this for the whole file using logstash](https://discuss.elastic.co/t/extract-logs-from-a-file-that-start-with-a-line-and-end-with-a-known-line-do-this-for-the-whole-file-using-logstash/328216)

<div class="topic-metadata">

**Author:** [@chikugerson](https://discuss.elastic.co/u/chikugerson)\
**Replies:** 0\
**Last updated:** [March 22, 2023, 7:58am UTC](https://discuss.elastic.co/t/extract-logs-from-a-file-that-start-with-a-line-and-end-with-a-known-line-do-this-for-the-whole-file-using-logstash/328216 "2023-03-22T07:58:21Z")

</div>

input { file { path =\> "C:/Users/user/Documents/Logstash/mylogs/spa2.log" start\_position =\> "beginning" } } filter { if "SPAHGW:31 32 30 30 :004:: 1200" in \[message\] { …

---

## [Logstash ignores newly created template when importing index](https://discuss.elastic.co/t/logstash-ignores-newly-created-template-when-importing-index/328215)

<div class="topic-metadata">

**Author:** [@eeijlar](https://discuss.elastic.co/u/eeijlar)\
**Replies:** 0\
**Last updated:** [March 22, 2023, 7:40am UTC](https://discuss.elastic.co/t/logstash-ignores-newly-created-template-when-importing-index/328215 "2023-03-22T07:40:43Z")

</div>

I am using the following pipeline to do an import of an index exported from Elastic: - pipeline.id: import-process pipeline.workers: 4 config.string: | input { file { path =\>…

---

## [Docker Logs keep getting dropped with tried to parse field \[image\] as object, but found a concrete value error](https://discuss.elastic.co/t/docker-logs-keep-getting-dropped-with-tried-to-parse-field-image-as-object-but-found-a-concrete-value-error/326245)

<div class="topic-metadata">

**Author:** [@jerrac](https://discuss.elastic.co/u/jerrac)\
**Replies:** 49\
**Last updated:** [March 22, 2023, 1:15am UTC](https://discuss.elastic.co/t/docker-logs-keep-getting-dropped-with-tried-to-parse-field-image-as-object-but-found-a-concrete-value-error/326245 "2023-03-22T01:15:41Z")

</div>

When investigating why I couldn't find my docker logs in Elastic, I found that Elastic Agent has been dropping them. It keeps logging stuff like: {"log.level":"warn","@timestamp":"2023-02-22T18:48:50.007-0800","message"…

---

## [Semantic Search API](https://discuss.elastic.co/t/semantic-search-api/328113)

<div class="topic-metadata">

**Author:** [@rpmansion](https://discuss.elastic.co/u/rpmansion)\
**Replies:** 7\
**Last updated:** [March 21, 2023, 8:52pm UTC](https://discuss.elastic.co/t/semantic-search-api/328113 "2023-03-21T20:52:25Z")

</div>

There is a semantic search API endpoint (/index\_name/\_semantic-search) that was released in the documentation, what is the reason this was removed?

---

## [Conflict fluent bit and elasticsearch](https://discuss.elastic.co/t/conflict-fluent-bit-and-elasticsearch/328198)

<div class="topic-metadata">

**Author:** [@Verdugo\_Gonzalo](https://discuss.elastic.co/u/Verdugo_Gonzalo)\
**Replies:** 0\
**Last updated:** [March 21, 2023, 7:54pm UTC](https://discuss.elastic.co/t/conflict-fluent-bit-and-elasticsearch/328198 "2023-03-21T19:54:54Z")

</div>

Hello everyone, I just migrated my cluster from version 7.9 to 8.5 everything went well but I have problems with fluent. For some reason Fluent is not able to ingest on ELK. Here are some data. \[SERVICE\] Flush …

---

## [Handle space in a field](https://discuss.elastic.co/t/handle-space-in-a-field/328190)

<div class="topic-metadata">

**Author:** [@rubhamra](https://discuss.elastic.co/u/rubhamra)\
**Replies:** 2\
**Last updated:** [March 21, 2023, 7:43pm UTC](https://discuss.elastic.co/t/handle-space-in-a-field/328190 "2023-03-21T19:43:41Z")

</div>

I am trying to remove a space from a field in logstash but it's not working, because there is space in the field, I can't even rename the field or not able to do replacement is with gsub. Request ID to be renamed to Req…

---

## [Ingest RESTAPI response into Elasticsearch as separate document through Logstash](https://discuss.elastic.co/t/ingest-restapi-response-into-elasticsearch-as-separate-document-through-logstash/328117)

<div class="topic-metadata">

**Author:** [@rubhamra](https://discuss.elastic.co/u/rubhamra)\
**Replies:** 2\
**Last updated:** [March 21, 2023, 5:30pm UTC](https://discuss.elastic.co/t/ingest-restapi-response-into-elasticsearch-as-separate-document-through-logstash/328117 "2023-03-21T17:30:28Z")

</div>

I am working http\_poller and using http plugin to ingest RestApi Array response output into Elasticsearch. using Logstash , I need help to split the output and store each as a separate document in Elasticsearch. Below…

---

## [Creating Multiple Alert Documents when Alert is Triggered](https://discuss.elastic.co/t/creating-multiple-alert-documents-when-alert-is-triggered/327088)

<div class="topic-metadata">

**Author:** [@juliette.littlewood](https://discuss.elastic.co/u/juliette.littlewood)\
**Replies:** 3\
**Last updated:** [March 10, 2023, 11:46pm UTC](https://discuss.elastic.co/t/creating-multiple-alert-documents-when-alert-is-triggered/327088 "2023-03-10T23:46:47Z")

</div>

Hi all, I've got a bit of a unique issue. For the system I am developing, data records will be ingested and compared against thresholds to confirm if values are anomalous. To test out this functionality I've set up an …

[Previous page](https://discuss.elastic.co/tag/none.md?no_tags=true&page=412)

[Next page](https://discuss.elastic.co/tag/none.md?no_tags=true&page=414)
