# \#none

**URL:** https://discuss.elastic.co/tag/none.md?no_tags=true&page=414

[Latest](https://discuss.elastic.co/latest.md) · [Categories](https://discuss.elastic.co/categories.md) · [Tags](https://discuss.elastic.co/tags.md)

**Page:** 415

---

## [Best approach to implement ILM on a large index and archive old data](https://discuss.elastic.co/t/best-approach-to-implement-ilm-on-a-large-index-and-archive-old-data/328045)

<div class="topic-metadata">

**Author:** [@Baygon](https://discuss.elastic.co/u/Baygon)\
**Replies:** 5\
**Last updated:** [March 21, 2023, 4:43pm UTC](https://discuss.elastic.co/t/best-approach-to-implement-ilm-on-a-large-index-and-archive-old-data/328045 "2023-03-21T16:43:16Z")

</div>

Hi, We have a single node cluster where one index unfortunately grew very big (261Gb) as we had no ILM on it. This is a production cluster. We understand that above 50Gb there is performance degradation and I think we …

---

## [Maximum allowed string Issue](https://discuss.elastic.co/t/maximum-allowed-string-issue/328076)

<div class="topic-metadata">

**Author:** [@alon\_carmelly](https://discuss.elastic.co/u/alon_carmelly)\
**Replies:** 5\
**Last updated:** [March 21, 2023, 4:21pm UTC](https://discuss.elastic.co/t/maximum-allowed-string-issue/328076 "2023-03-21T16:21:11Z")

</div>

I get this error: The content length (732630494) is bigger than the maximum allowed string (536870888) I added to kibana.yml: server.maxPayloadBytes: 888888888 savedObjects.maxImportPayloadBytes: 50485760 I added to…

---

## [Extract from ElasticSearch, into Kafka, continuously add any new ES updates using logstash](https://discuss.elastic.co/t/extract-from-elasticsearch-into-kafka-continuously-add-any-new-es-updates-using-logstash/328172)

<div class="topic-metadata">

**Author:** [@aniketdatir](https://discuss.elastic.co/u/aniketdatir)\
**Replies:** 0\
**Last updated:** [March 21, 2023, 2:21pm UTC](https://discuss.elastic.co/t/extract-from-elasticsearch-into-kafka-continuously-add-any-new-es-updates-using-logstash/328172 "2023-03-21T14:21:20Z")

</div>

Hi Team, My objective is to add latest ES index documents to kafka Below is my logstash conf -\> ''' input { elasticsearch { hosts =\> \["IP"\] index =\> "Index\_name" query =\> '{"query":{"range":{"@timestamp":{"gte": …

---

## [Logstash Parse stingyfied json to seperate json fieldsl](https://discuss.elastic.co/t/logstash-parse-stingyfied-json-to-seperate-json-fieldsl/327097)

<div class="topic-metadata">

**Author:** [@PRASHANT\_MEHTA](https://discuss.elastic.co/u/PRASHANT_MEHTA)\
**Replies:** 0\
**Last updated:** [March 6, 2023, 3:13pm UTC](https://discuss.elastic.co/t/logstash-parse-stingyfied-json-to-seperate-json-fieldsl/327097 "2023-03-06T15:13:24Z")

</div>

Hello All, I've a column in oracle table PACKAGE\_DATA and it has json like string in it and I would like to get every fileds and its value seperate: PACKAGE\_DATA Column data {"status":"READY\_FOR\_PROCESSING","errorData…

---

## [Logstash filter to process jason array fileds as seperate fileds in elastic indexl](https://discuss.elastic.co/t/logstash-filter-to-process-jason-array-fileds-as-seperate-fileds-in-elastic-indexl/326874)

<div class="topic-metadata">

**Author:** [@PRASHANT\_MEHTA](https://discuss.elastic.co/u/PRASHANT_MEHTA)\
**Replies:** 9\
**Last updated:** [March 15, 2023, 3:56pm UTC](https://discuss.elastic.co/t/logstash-filter-to-process-jason-array-fileds-as-seperate-fileds-in-elastic-indexl/326874 "2023-03-15T15:56:53Z")

</div>

Hello All, After trying several time,I'm unable to process one column in oracle table that contains json data and I would require every field in that as seperate filed created in elastic index.Could someone guide what a…

---

## [Updating an existing field using path data](https://discuss.elastic.co/t/updating-an-existing-field-using-path-data/328110)

<div class="topic-metadata">

**Author:** [@Jeferson\_Schiavinato](https://discuss.elastic.co/u/Jeferson_Schiavinato)\
**Replies:** 5\
**Last updated:** [March 21, 2023, 1:07pm UTC](https://discuss.elastic.co/t/updating-an-existing-field-using-path-data/328110 "2023-03-21T13:07:36Z")

</div>

Hello Guys, I am using a path which is formed by /dir/subdir/filename\_log.gz. I want to extract the filename and update an existent Field called Hostname with this information. I have tried to use this code, but I had…

---

## [Merge 2 Clusters with same name](https://discuss.elastic.co/t/merge-2-clusters-with-same-name/328065)

<div class="topic-metadata">

**Author:** [@devarajsit](https://discuss.elastic.co/u/devarajsit)\
**Replies:** 5\
**Last updated:** [March 21, 2023, 12:09pm UTC](https://discuss.elastic.co/t/merge-2-clusters-with-same-name/328065 "2023-03-21T12:09:20Z")

</div>

Hi Team, Is there any way where we can merge 2 clusters with same name to 1. Scenario is... will have an existing cluster with name xyz and have some data. Will create additional cluster in different nodes with same na…

---

## [Error: failed to perform any bulk index operations: 429 Too Many Requests](https://discuss.elastic.co/t/error-failed-to-perform-any-bulk-index-operations-429-too-many-requests/328074)

<div class="topic-metadata">

**Author:** [@Nicolas\_Pelletier](https://discuss.elastic.co/u/Nicolas_Pelletier)\
**Replies:** 10\
**Last updated:** [March 21, 2023, 10:07am UTC](https://discuss.elastic.co/t/error-failed-to-perform-any-bulk-index-operations-429-too-many-requests/328074 "2023-03-21T10:07:04Z")

</div>

Hello, I know that there is already a lot of post on (github | stackoverflow | here) about this error and how to fix it but despite the reading of all of these ones i was not able to get rid of this error: Here is a sn…

---

## [Ingest logs from S3 bucket](https://discuss.elastic.co/t/ingest-logs-from-s3-bucket/328155)

<div class="topic-metadata">

**Author:** [@rahul\_sirugudi](https://discuss.elastic.co/u/rahul_sirugudi)\
**Replies:** 0\
**Last updated:** [March 21, 2023, 10:25am UTC](https://discuss.elastic.co/t/ingest-logs-from-s3-bucket/328155 "2023-03-21T10:25:43Z")

</div>

Currently i am using elk stack to ingest only warning and errors logs to Elasticsearch server. Also i am using elastic beanstalk to rotate logs to S3 bucket. Now as i ingest only warning and error logs sometimes i need …

---

## [Overwrite data VS data duplication](https://discuss.elastic.co/t/overwrite-data-vs-data-duplication/328143)

<div class="topic-metadata">

**Author:** [@m3bgwad](https://discuss.elastic.co/u/m3bgwad)\
**Replies:** 0\
**Last updated:** [March 21, 2023, 8:53am UTC](https://discuss.elastic.co/t/overwrite-data-vs-data-duplication/328143 "2023-03-21T08:53:18Z")

</div>

Hello, every all, What is the goal of handling the data duplication using a fingerprint filter, In my opinion, this is overwritten data, not preventing the duplication. Let's say the overwrite is removing the oldest an…

---

## [My Kibana Dashboard shows 350 percentage or more for CPU utilization for Servers.. i wanted to have the vaules under 100 percentage](https://discuss.elastic.co/t/my-kibana-dashboard-shows-350-percentage-or-more-for-cpu-utilization-for-servers-i-wanted-to-have-the-vaules-under-100-percentage/328141)

<div class="topic-metadata">

**Author:** [@AKAM14](https://discuss.elastic.co/u/AKAM14)\
**Replies:** 0\
**Last updated:** [March 21, 2023, 8:40am UTC](https://discuss.elastic.co/t/my-kibana-dashboard-shows-350-percentage-or-more-for-cpu-utilization-for-servers-i-wanted-to-have-the-vaules-under-100-percentage/328141 "2023-03-21T08:40:55Z")

</div>

ELK 7.17.3 , KIBANA : 7.17.3 I have created Kibana Dashboards - there is a Average CPU Utilization dashboard for Application servers - the graph shows 350 or 250 percentage for cpu . which is quite confusing . I would…

---

## [What are logstash-plain-YYYY-MM-DD.log.gz and logstash-deprecation-YYYY-MM-DD.log.gz?](https://discuss.elastic.co/t/what-are-logstash-plain-yyyy-mm-dd-log-gz-and-logstash-deprecation-yyyy-mm-dd-log-gz/328125)

<div class="topic-metadata">

**Author:** [@ohaya](https://discuss.elastic.co/u/ohaya)\
**Replies:** 1\
**Last updated:** [March 21, 2023, 8:21am UTC](https://discuss.elastic.co/t/what-are-logstash-plain-yyyy-mm-dd-log-gz-and-logstash-deprecation-yyyy-mm-dd-log-gz/328125 "2023-03-21T08:21:37Z")

</div>

Hi, I'm fairly new working with logstash (and actually the entire ELK components), but am trying to determine why some logs are not being ingested and indexed. While I was investigating this, I noticed that on the mach…

---

## [Sending data from 2 logstash nodes to an elasticsearch cluster](https://discuss.elastic.co/t/sending-data-from-2-logstash-nodes-to-an-elasticsearch-cluster/328128)

<div class="topic-metadata">

**Author:** [@Shreesh\_Narayanan](https://discuss.elastic.co/u/Shreesh_Narayanan)\
**Replies:** 4\
**Last updated:** [March 21, 2023, 6:29am UTC](https://discuss.elastic.co/t/sending-data-from-2-logstash-nodes-to-an-elasticsearch-cluster/328128 "2023-03-21T06:29:34Z")

</div>

Hi Folks, I have 2 logstash nodes (version -8.6.2) that i want to send data to 2 elasticsearch nodes (version -8.6.2) ( a third node will be added soon to the cluster) . Do i just mention the elasticsearch nodes' in t…

---

## [Sort on multiple fields Not working](https://discuss.elastic.co/t/sort-on-multiple-fields-not-working/328131)

<div class="topic-metadata">

**Author:** [@\_baba](https://discuss.elastic.co/u/_baba)\
**Replies:** 2\
**Last updated:** [March 21, 2023, 6:27am UTC](https://discuss.elastic.co/t/sort-on-multiple-fields-not-working/328131 "2023-03-21T06:27:58Z")

</div>

Hi, I'm trying to sort on multiple fields like - sort on field1 first if there is a tie on field1, sort based on field 2. POST sort\_logic/\_doc { "field1" : 4, "field2" : "4" } POST sort\_logic/\_doc { "field1" : …

---

## [How to specify "bulk\_path" in elasticsearch output on logstash config](https://discuss.elastic.co/t/how-to-specify-bulk-path-in-elasticsearch-output-on-logstash-config/328130)

<div class="topic-metadata">

**Author:** [@Shreesh\_Narayanan](https://discuss.elastic.co/u/Shreesh_Narayanan)\
**Replies:** 0\
**Last updated:** [March 21, 2023, 5:49am UTC](https://discuss.elastic.co/t/how-to-specify-bulk-path-in-elasticsearch-output-on-logstash-config/328130 "2023-03-21T05:49:19Z")

</div>

Hello, how do i mention "bulk\_path" in the ES output in logstash ? this is how it's currently implemented (testing) , but i wanted to confirm if i'm doing is correct I have 2 elasticsearch nodes ( a 3rd one will be pr…

---

## [Cases API not working on ELK 8.1](https://discuss.elastic.co/t/cases-api-not-working-on-elk-8-1/328066)

<div class="topic-metadata">

**Author:** [@nitisha](https://discuss.elastic.co/u/nitisha)\
**Replies:** 4\
**Last updated:** [March 21, 2023, 5:52am UTC](https://discuss.elastic.co/t/cases-api-not-working-on-elk-8-1/328066 "2023-03-21T05:52:27Z")

</div>

Hi, I am running ELK stack 8.1 in our production environment and would like to create cases based on the log alerts we're filtering using grok pattern. As I understood correctly beginning 8.2 version, we have an option…

---

## [Sort based on absolute value](https://discuss.elastic.co/t/sort-based-on-absolute-value/328078)

<div class="topic-metadata">

**Author:** [@\_baba](https://discuss.elastic.co/u/_baba)\
**Replies:** 5\
**Last updated:** [March 21, 2023, 5:36am UTC](https://discuss.elastic.co/t/sort-based-on-absolute-value/328078 "2023-03-21T05:36:07Z")

</div>

Hi, I'm looking to sort documents based on a field of long type by their absolute value. So, the change field has both positive and negative numbers. "change" : { "type" : "long" } I want to sort it in such a way th…

---

## [Index\_failed number is increasing after adding a new node to elasticsearch cluster(previously single node)](https://discuss.elastic.co/t/index-failed-number-is-increasing-after-adding-a-new-node-to-elasticsearch-cluster-previously-single-node/328098)

<div class="topic-metadata">

**Author:** [@Shreesh\_Narayanan](https://discuss.elastic.co/u/Shreesh_Narayanan)\
**Replies:** 2\
**Last updated:** [March 21, 2023, 5:32am UTC](https://discuss.elastic.co/t/index-failed-number-is-increasing-after-adding-a-new-node-to-elasticsearch-cluster-previously-single-node/328098 "2023-03-21T05:32:45Z")

</div>

Hi Folks, Today i added a new node to a previously single -node elasticsearch cluster and the process was successful . however when i look at the node stats (via the node stats API) it shows the index\_failed numbers to …

---

## [What the better way, create 400 columns with types keyword, text, float, date and boolean in index or 5 nested fields?](https://discuss.elastic.co/t/what-the-better-way-create-400-columns-with-types-keyword-text-float-date-and-boolean-in-index-or-5-nested-fields/328123)

<div class="topic-metadata">

**Author:** [@Yuri\_Khmelevsky](https://discuss.elastic.co/u/Yuri_Khmelevsky)\
**Replies:** 0\
**Last updated:** [March 21, 2023, 4:02am UTC](https://discuss.elastic.co/t/what-the-better-way-create-400-columns-with-types-keyword-text-float-date-and-boolean-in-index-or-5-nested-fields/328123 "2023-03-21T04:02:18Z")

</div>

What is the better for read and write performance? And in general is this good idea to store 400 columns in index (I know that I can store 1000 columns per index by default). I expect that one documents will have 5-15 t…

---

## [How to join two indexes or use an index as a lookup](https://discuss.elastic.co/t/how-to-join-two-indexes-or-use-an-index-as-a-lookup/328073)

<div class="topic-metadata">

**Author:** [@alissan](https://discuss.elastic.co/u/alissan)\
**Replies:** 5\
**Last updated:** [March 21, 2023, 1:19am UTC](https://discuss.elastic.co/t/how-to-join-two-indexes-or-use-an-index-as-a-lookup/328073 "2023-03-21T01:19:15Z")

</div>

I have log indexes with 500 million records daily in one index (logs-20230320,logs-20230321,...) And i have malicious IP addresses list ( ~150.000 records) in another index (blacklist-202303) (rebuilt every day) I need…

---

## [Strigo says "course has ended" after restarting subscription](https://discuss.elastic.co/t/strigo-says-course-has-ended-after-restarting-subscription/328116)

<div class="topic-metadata">

**Author:** [@lkey4126](https://discuss.elastic.co/u/lkey4126)\
**Replies:** 1\
**Last updated:** [March 20, 2023, 11:41pm UTC](https://discuss.elastic.co/t/strigo-says-course-has-ended-after-restarting-subscription/328116 "2023-03-20T23:41:21Z")

</div>

Course:Elasticsearch Engineer Version: \<And which particular version?\> Question: I was working through the Elasticsearch Engineer course when my subscription expired. After procuring another subscription 4 months lat…

---

## [Issue with apache Tika Extraction for Tabular Column Data in PDF](https://discuss.elastic.co/t/issue-with-apache-tika-extraction-for-tabular-column-data-in-pdf/328080)

<div class="topic-metadata">

**Author:** [@Sai\_Kiran\_solix](https://discuss.elastic.co/u/Sai_Kiran_solix)\
**Replies:** 1\
**Last updated:** [March 20, 2023, 9:05pm UTC](https://discuss.elastic.co/t/issue-with-apache-tika-extraction-for-tabular-column-data-in-pdf/328080 "2023-03-20T21:05:04Z")

</div>

I extracted a PDF that has tabular column data using apache Tika, in the result the row data from different columns are getting merged Before Extracting | Column A | Column B | | -------- | -------- | | 1 | saikiran | |…

---

## [Changed password for metricbeat user, now I can't connect to Kibana](https://discuss.elastic.co/t/changed-password-for-metricbeat-user-now-i-cant-connect-to-kibana/327970)

<div class="topic-metadata">

**Author:** [@JacobBaynes](https://discuss.elastic.co/u/JacobBaynes)\
**Replies:** 4\
**Last updated:** [March 20, 2023, 7:41pm UTC](https://discuss.elastic.co/t/changed-password-for-metricbeat-user-now-i-cant-connect-to-kibana/327970 "2023-03-20T19:41:15Z")

</div>

Hello! The employee who set up our instance of elastic is no longer working here and he did not document how he set things up or the passwords that he created for the user that metricbeat uses to connect to the kibana/el…

---

## [RPM signing key is invalid on newer operating systems](https://discuss.elastic.co/t/rpm-signing-key-is-invalid-on-newer-operating-systems/327476)

<div class="topic-metadata">

**Author:** [@twilson](https://discuss.elastic.co/u/twilson)\
**Replies:** 1\
**Last updated:** [March 20, 2023, 7:04pm UTC](https://discuss.elastic.co/t/rpm-signing-key-is-invalid-on-newer-operating-systems/327476 "2023-03-20T19:04:59Z")

</div>

The signing key used for RPM packages (and I assume other package types) is no longer valid on newer operating systems since the key is SHA1 and these newer operating systems have deprecated SHA1. Specifically, I'm tryi…

---

## [My elasticsearch is not running with error code 128](https://discuss.elastic.co/t/my-elasticsearch-is-not-running-with-error-code-128/327892)

<div class="topic-metadata">

**Author:** [@Terry\_2018](https://discuss.elastic.co/u/Terry_2018)\
**Replies:** 9\
**Last updated:** [March 20, 2023, 6:54pm UTC](https://discuss.elastic.co/t/my-elasticsearch-is-not-running-with-error-code-128/327892 "2023-03-20T18:54:02Z")

</div>

Hi. I'm using Elasticsearch 8.6.2 on Ubuntu 22.04. Since a few days ago, my elastic is not running. Please help me. The system output is below. dev@logserver:~$ sudo systemctl status elasticsearch × elasticsearch.se…

---

## [Allocation Failed](https://discuss.elastic.co/t/allocation-failed/328097)

<div class="topic-metadata">

**Author:** [@fnitz](https://discuss.elastic.co/u/fnitz)\
**Replies:** 6\
**Last updated:** [March 20, 2023, 5:58pm UTC](https://discuss.elastic.co/t/allocation-failed/328097 "2023-03-20T17:58:03Z")

</div>

Hi, I've got many error messages like that: { "index" : "logstash-prod\_operations\_clear-001098", "shard" : 0, "primary" : false, "current\_state" : "unassigned", "unassigned\_info" : { "reason" : "ALLOCATIO…

---

## [Elastic Agent falling after first enrollment on fleet server](https://discuss.elastic.co/t/elastic-agent-falling-after-first-enrollment-on-fleet-server/327385)

<div class="topic-metadata">

**Author:** [@thiago8martins](https://discuss.elastic.co/u/thiago8martins)\
**Replies:** 2\
**Last updated:** [March 20, 2023, 4:45pm UTC](https://discuss.elastic.co/t/elastic-agent-falling-after-first-enrollment-on-fleet-server/327385 "2023-03-20T16:45:16Z")

</div>

Hello Folks, I'm deploying Elastic Agent and Fleet Server on K8s environment: The Fleet Server I have deployed at the same cluster as the Kibana and ES using ECK. The Elastic Agent i need to deploy in other K8s clust…

---

## [Json parsin](https://discuss.elastic.co/t/json-parsin/326849)

<div class="topic-metadata">

**Author:** [@chrispos](https://discuss.elastic.co/u/chrispos)\
**Replies:** 10\
**Last updated:** [March 20, 2023, 4:34pm UTC](https://discuss.elastic.co/t/json-parsin/326849 "2023-03-20T16:34:54Z")

</div>

Hello, I have a question. We are trying to set up a logging system for a java application running on Jboss. The goal is to be able to filter for certain errors. We've done the following Server.log converted to server.…

---

## [Please reset elastic engineer training and practice exam lab enviroments](https://discuss.elastic.co/t/please-reset-elastic-engineer-training-and-practice-exam-lab-enviroments/328031)

<div class="topic-metadata">

**Author:** [@cwilkey](https://discuss.elastic.co/u/cwilkey)\
**Replies:** 1\
**Last updated:** [March 20, 2023, 3:42pm UTC](https://discuss.elastic.co/t/please-reset-elastic-engineer-training-and-practice-exam-lab-enviroments/328031 "2023-03-20T15:42:13Z")

</div>

Hi, Please could someone reset my Strigo lab environment and training progress for the Elastic Engineer course and the Strigo Elastic Engineer practice exam environment , as I would like to a re-run of the course before…

---

## [Strigo lab expired even before I could use it](https://discuss.elastic.co/t/strigo-lab-expired-even-before-i-could-use-it/328016)

<div class="topic-metadata">

**Author:** [@AmolV](https://discuss.elastic.co/u/AmolV)\
**Replies:** 1\
**Last updated:** [March 20, 2023, 3:40pm UTC](https://discuss.elastic.co/t/strigo-lab-expired-even-before-i-could-use-it/328016 "2023-03-20T15:40:36Z")

</div>

Course: Elasticsearch Engineer (On-Demand) Version: \<And which particular version?\> Question: The very first step in this course is about setting up the lab and strigo account. The course is valid for 1 year. So when I…

[Previous page](https://discuss.elastic.co/tag/none.md?no_tags=true&page=413)

[Next page](https://discuss.elastic.co/tag/none.md?no_tags=true&page=415)
