# \#none

**URL:** https://discuss.elastic.co/tag/none.md?no_tags=true&page=421

[Latest](https://discuss.elastic.co/latest.md) · [Categories](https://discuss.elastic.co/categories.md) · [Tags](https://discuss.elastic.co/tags.md)

**Page:** 422

---

## [Request body is required Error encountered while performing reindexing task](https://discuss.elastic.co/t/request-body-is-required-error-encountered-while-performing-reindexing-task/327327)

<div class="topic-metadata">

**Author:** [@Chandan1](https://discuss.elastic.co/u/Chandan1)\
**Replies:** 4\
**Last updated:** [March 9, 2023, 7:58am UTC](https://discuss.elastic.co/t/request-body-is-required-error-encountered-while-performing-reindexing-task/327327 "2023-03-09T07:58:37Z")

</div>

Hello, I am trying to reindex the index with reindex api by providing a proper request body with the Source and Destination Index details and still iam receiving Request body is required Error. Please find below Reques…

---

## [Monitoring Metricbeat On Kibana](https://discuss.elastic.co/t/monitoring-metricbeat-on-kibana/327244)

<div class="topic-metadata">

**Author:** [@Tw1cUser](https://discuss.elastic.co/u/Tw1cUser)\
**Replies:** 5\
**Last updated:** [March 9, 2023, 6:15am UTC](https://discuss.elastic.co/t/monitoring-metricbeat-on-kibana/327244 "2023-03-09T06:15:15Z")

</div>

Hi all, I use windows server 2019 to monitor my laptop's data system, but after I do the .\\metricbeat setup, after Index setup finished. Loading dashboards (Kibana must be running and reachable) Loaded dashboards I chec…

---

## [\[plugin-development\] java.security.AccessControlException](https://discuss.elastic.co/t/plugin-development-java-security-accesscontrolexception/327326)

<div class="topic-metadata">

**Author:** [@Jinnrry](https://discuss.elastic.co/u/Jinnrry)\
**Replies:** 0\
**Last updated:** [March 9, 2023, 7:10am UTC](https://discuss.elastic.co/t/plugin-development-java-security-accesscontrolexception/327326 "2023-03-09T07:10:37Z")

</div>

Vesion: Elasticsearch 8.6.2 (My plugin is working on Elasticsearch7.6.0 ) I am developing a plugin to let ES filter through Redis data. So I import Jedis package in my code. But when ES starts, I get this error. Her…

---

## [Elastic Operator 2.6.1 Failing Reconciliation with "Invalid Settings" Error on ES 8.6.2 in AKS but not specifying what setting is invalid](https://discuss.elastic.co/t/elastic-operator-2-6-1-failing-reconciliation-with-invalid-settings-error-on-es-8-6-2-in-aks-but-not-specifying-what-setting-is-invalid/327285)

<div class="topic-metadata">

**Author:** [@Thomas\_Kuisel](https://discuss.elastic.co/u/Thomas_Kuisel)\
**Replies:** 1\
**Last updated:** [March 9, 2023, 5:44am UTC](https://discuss.elastic.co/t/elastic-operator-2-6-1-failing-reconciliation-with-invalid-settings-error-on-es-8-6-2-in-aks-but-not-specifying-what-setting-is-invalid/327285 "2023-03-09T05:44:19Z")

</div>

Hi - We are trying to upgrade our elastic operator to 2.6.1 from 1.9, and subsequently our elastic cluster deployed in K8s and managed by the operator from 7.17 to 8.6.2. Upgrading the operator to 2.6.1 intially posed n…

---

## [Logstash compliance with RFC5425 and RFC5426](https://discuss.elastic.co/t/logstash-compliance-with-rfc5425-and-rfc5426/327243)

<div class="topic-metadata">

**Author:** [@Nikhitha\_Karennagari](https://discuss.elastic.co/u/Nikhitha_Karennagari)\
**Replies:** 2\
**Last updated:** [March 9, 2023, 3:13am UTC](https://discuss.elastic.co/t/logstash-compliance-with-rfc5425-and-rfc5426/327243 "2023-03-09T03:13:49Z")

</div>

From the official logstash docs , the syslog output plugin of logstash supports any of RFC5424, RFC3164 formats only. Syslog output plugin | Logstash Reference \[8.6\] | Elastic Does logstash syslog output plugin comply w…

---

## [Shards Rebalancing Issue Version 7](https://discuss.elastic.co/t/shards-rebalancing-issue-version-7/327107)

<div class="topic-metadata">

**Author:** [@chateesh](https://discuss.elastic.co/u/chateesh)\
**Replies:** 3\
**Last updated:** [March 8, 2023, 10:57pm UTC](https://discuss.elastic.co/t/shards-rebalancing-issue-version-7/327107 "2023-03-08T22:57:05Z")

</div>

ES version 7, Shards are not equally distributing, one data node has more shards, rest of the two data nodes are less number of shards and low disk used. Replication set to "1" on all indices Please let me know if any …

---

## [Enrollment in Fleet works but agent don't receive its configuration](https://discuss.elastic.co/t/enrollment-in-fleet-works-but-agent-dont-receive-its-configuration/325636)

<div class="topic-metadata">

**Author:** [@litronics](https://discuss.elastic.co/u/litronics)\
**Replies:** 2\
**Last updated:** [March 8, 2023, 9:13pm UTC](https://discuss.elastic.co/t/enrollment-in-fleet-works-but-agent-dont-receive-its-configuration/325636 "2023-03-08T21:13:29Z")

</div>

:frowning: am running a fresh docker based instance of elasticsearch, kibana and fleet-server (all in separate containers). Now I am starting a fresh elastic-agent container which enrolls in fleet just fine but don't re…

---

## [Getting stuck on load geoip database file while installing Elasticsearch 8.6.2](https://discuss.elastic.co/t/getting-stuck-on-load-geoip-database-file-while-installing-elasticsearch-8-6-2/327289)

<div class="topic-metadata">

**Author:** [@Alfred\_C](https://discuss.elastic.co/u/Alfred_C)\
**Replies:** 2\
**Last updated:** [March 8, 2023, 6:21pm UTC](https://discuss.elastic.co/t/getting-stuck-on-load-geoip-database-file-while-installing-elasticsearch-8-6-2/327289 "2023-03-08T18:21:11Z")

</div>

Hi, I just tried to install Elasticsearch 8.6.2, however it was stuck when run elasticsearch.bat details as show at the screenshot

---

## [Is it possible to sort in a custom grouping manner with unicode collation algorithm in elasticsearch?](https://discuss.elastic.co/t/is-it-possible-to-sort-in-a-custom-grouping-manner-with-unicode-collation-algorithm-in-elasticsearch/327294)

<div class="topic-metadata">

**Author:** [@Karthik\_Amar](https://discuss.elastic.co/u/Karthik_Amar)\
**Replies:** 0\
**Last updated:** [March 8, 2023, 5:11pm UTC](https://discuss.elastic.co/t/is-it-possible-to-sort-in-a-custom-grouping-manner-with-unicode-collation-algorithm-in-elasticsearch/327294 "2023-03-08T17:11:35Z")

</div>

I am working on a phonebook, where if the user does not provide Name but fills only email, I will show the email value in phonebook (as in mac contacts). And the priority is as follows Name (if not present) -\> Email (if…

---

## [Null\_pointer\_exception: Cannot invoke "String.equals(Object)" because the return value of "org.apache.lucene.search.SortField.getField()" is null](https://discuss.elastic.co/t/null-pointer-exception-cannot-invoke-string-equals-object-because-the-return-value-of-org-apache-lucene-search-sortfield-getfield-is-null/327235)

<div class="topic-metadata">

**Author:** [@davidgAID](https://discuss.elastic.co/u/davidgAID)\
**Replies:** 1\
**Last updated:** [March 8, 2023, 4:35pm UTC](https://discuss.elastic.co/t/null-pointer-exception-cannot-invoke-string-equals-object-because-the-return-value-of-org-apache-lucene-search-sortfield-getfield-is-null/327235 "2023-03-08T16:35:29Z")

</div>

This is on Elasticsearch 8.6.2. I have a pretty mundane query that I want to paginate via search\_after. The initial query looks like this: { "\_source": true, "collapse": { "field": "collapse\_col" }, "query…

---

## [Data nodes separation (via attributes) vs. clusters separation](https://discuss.elastic.co/t/data-nodes-separation-via-attributes-vs-clusters-separation/327216)

<div class="topic-metadata">

**Author:** [@Itay\_Bittan](https://discuss.elastic.co/u/Itay_Bittan)\
**Replies:** 3\
**Last updated:** [March 8, 2023, 4:33pm UTC](https://discuss.elastic.co/t/data-nodes-separation-via-attributes-vs-clusters-separation/327216 "2023-03-08T16:33:45Z")

</div>

Hi, We are B2B that maintain one index per each one of our customers. Every index is being indexed every day from scratch and once it is ready, it replace the previous day index. Once the index is ready, it's in read-…

---

## [Question about must query](https://discuss.elastic.co/t/question-about-must-query/327282)

<div class="topic-metadata">

**Author:** [@tomizius](https://discuss.elastic.co/u/tomizius)\
**Replies:** 3\
**Last updated:** [March 8, 2023, 4:14pm UTC](https://discuss.elastic.co/t/question-about-must-query/327282 "2023-03-08T16:14:25Z")

</div>

Course: \< Elastic Certified Engineer Exam\> Version: \<8.1\> Question: What is the difference between following two queries? 1: { "query": { "bool": { "must": \[ { "multi\_match": { …

---

## [Is there a quicker way to import data to Elastic?](https://discuss.elastic.co/t/is-there-a-quicker-way-to-import-data-to-elastic/327275)

<div class="topic-metadata">

**Author:** [@eeijlar](https://discuss.elastic.co/u/eeijlar)\
**Replies:** 5\
**Last updated:** [March 8, 2023, 3:49pm UTC](https://discuss.elastic.co/t/is-there-a-quicker-way-to-import-data-to-elastic/327275 "2023-03-08T15:49:54Z")

</div>

I have exported elastic indices using logstash with the following logstash configuration: - pipeline.id: export-process pipeline.workers: 4 config.string: | input { elasticsearch { …

---

## [Logstash syslog message, doesn't choose right if statement](https://discuss.elastic.co/t/logstash-syslog-message-doesnt-choose-right-if-statement/327181)

<div class="topic-metadata">

**Author:** [@splitmessage88](https://discuss.elastic.co/u/splitmessage88)\
**Replies:** 2\
**Last updated:** [March 8, 2023, 2:36pm UTC](https://discuss.elastic.co/t/logstash-syslog-message-doesnt-choose-right-if-statement/327181 "2023-03-08T14:36:26Z")

</div>

Hi, I'm trying to create a logstash pipeline for cisco FMC audit log. I have create 3 if statements and would like for logstash to parse the syslog message according to the if statement. Here is two example syslog mes…

---

## [Example of testing cumstom plugins](https://discuss.elastic.co/t/example-of-testing-cumstom-plugins/327038)

<div class="topic-metadata">

**Author:** [@iljaskajrris](https://discuss.elastic.co/u/iljaskajrris)\
**Replies:** 1\
**Last updated:** [March 8, 2023, 2:33pm UTC](https://discuss.elastic.co/t/example-of-testing-cumstom-plugins/327038 "2023-03-08T14:33:34Z")

</div>

Hi team, i develop plugin for Kibana 7.10 and wonder if there any working example of functional tests for that. Can anybody help?

---

## [Logstash ignore\_older opposite](https://discuss.elastic.co/t/logstash-ignore-older-opposite/327279)

<div class="topic-metadata">

**Author:** [@GinkoLucas](https://discuss.elastic.co/u/GinkoLucas)\
**Replies:** 1\
**Last updated:** [March 8, 2023, 2:13pm UTC](https://discuss.elastic.co/t/logstash-ignore-older-opposite/327279 "2023-03-08T14:13:47Z")

</div>

Hello, I would like Logstash to read only files older than one day. How can I do that? It would be sort of the opposite of "ignore\_older". Thx

---

## [Query index from within an AnalysisProvider?](https://discuss.elastic.co/t/query-index-from-within-an-analysisprovider/327191)

<div class="topic-metadata">

**Author:** [@jnioche](https://discuss.elastic.co/u/jnioche)\
**Replies:** 2\
**Last updated:** [March 8, 2023, 12:38pm UTC](https://discuss.elastic.co/t/query-index-from-within-an-analysisprovider/327191 "2023-03-08T12:38:38Z")

</div>

Hi, Here is the context of my question: Synonym graph token filter backed by Elastic index I am writing a custom AnalysisPlugin to generate a list of synonyms from an Elastic index instead of using a static file. A na…

---

## [Performance implications of \`index.max\_result\_window\` vs \`track\_total\_hits\`](https://discuss.elastic.co/t/performance-implications-of-index-max-result-window-vs-track-total-hits/327270)

<div class="topic-metadata">

**Author:** [@Cristian\_Calara](https://discuss.elastic.co/u/Cristian_Calara)\
**Replies:** 1\
**Last updated:** [March 8, 2023, 12:21pm UTC](https://discuss.elastic.co/t/performance-implications-of-index-max-result-window-vs-track-total-hits/327270 "2023-03-08T12:21:15Z")

</div>

Hello, For example, if we would have 50.000 results for a search query. If we really need to return an exact total number of matches and we enabled track\_total\_hits to get it. Should we just as well increase the max\_res…

---

## [What is the best method to backup Fleet policies](https://discuss.elastic.co/t/what-is-the-best-method-to-backup-fleet-policies/327265)

<div class="topic-metadata">

**Author:** [@Patryk\_Ostrowski](https://discuss.elastic.co/u/Patryk_Ostrowski)\
**Replies:** 0\
**Last updated:** [March 8, 2023, 10:55am UTC](https://discuss.elastic.co/t/what-is-the-best-method-to-backup-fleet-policies/327265 "2023-03-08T10:55:51Z")

</div>

Hello, In the event of server failures, I have snapshots to recover data. But how can I recover fleet server integration configurations, installed agents and their policies?

---

## [How to filter date with optional keyword search](https://discuss.elastic.co/t/how-to-filter-date-with-optional-keyword-search/327260)

<div class="topic-metadata">

**Author:** [@gopikrish](https://discuss.elastic.co/u/gopikrish)\
**Replies:** 0\
**Last updated:** [March 8, 2023, 10:08am UTC](https://discuss.elastic.co/t/how-to-filter-date-with-optional-keyword-search/327260 "2023-03-08T10:08:48Z")

</div>

Hi All , while retrieving data from ELK, I need to filter records between two date(mandatory) with keyword (optional) parameter. The searching keyword is only present in value format not in key value pair. For eg ; { …

---

## [Index.mapping.depth.limit not persistent after an index rollover](https://discuss.elastic.co/t/index-mapping-depth-limit-not-persistent-after-an-index-rollover/327182)

<div class="topic-metadata">

**Author:** [@Khaled\_Saidi](https://discuss.elastic.co/u/Khaled_Saidi)\
**Replies:** 2\
**Last updated:** [March 8, 2023, 8:58am UTC](https://discuss.elastic.co/t/index-mapping-depth-limit-not-persistent-after-an-index-rollover/327182 "2023-03-08T08:58:52Z")

</div>

Hi everyone, I notice that when the current index is rollovered, the index.mapping.depth.limit is not take into account for the new created index. We are running an elasticsearch cluster and after we have created the f…

---

## [Not able to remove tag from xml](https://discuss.elastic.co/t/not-able-to-remove-tag-from-xml/326771)

<div class="topic-metadata">

**Author:** [@Navya\_04](https://discuss.elastic.co/u/Navya_04)\
**Replies:** 14\
**Last updated:** [March 8, 2023, 8:32am UTC](https://discuss.elastic.co/t/not-able-to-remove-tag-from-xml/326771 "2023-03-08T08:32:22Z")

</div>

I am trying to load xml through logstash. I have an unwnated tag which needs to be removed from xml while parsing. Used remove\_tag but not able to remove the tag while indexing to Elasticsearch xml File \<?xml version="…

---

## [TLS Certificate Roll - Enterprise Search Readiness probe failed - Failed to connect to Elasticsearch backend. (HTTPS/TLS)](https://discuss.elastic.co/t/tls-certificate-roll-enterprise-search-readiness-probe-failed-failed-to-connect-to-elasticsearch-backend-https-tls/327026)

<div class="topic-metadata">

**Author:** [@Glenn\_Sampson](https://discuss.elastic.co/u/Glenn_Sampson)\
**Replies:** 0\
**Last updated:** [March 6, 2023, 5:05am UTC](https://discuss.elastic.co/t/tls-certificate-roll-enterprise-search-readiness-probe-failed-failed-to-connect-to-elasticsearch-backend-https-tls/327026 "2023-03-06T05:05:43Z")

</div>

When rolling our CA certificates on our azure k8s clusters I noticed that our Elasticsearch is not using HTTPS/TLS. So I have attempted to updated the yamls and apply however my enterprise search is no longer working an…

---

## [What is the deciding factor for the number of coordinating only node in a cluster and how to route the requests?](https://discuss.elastic.co/t/what-is-the-deciding-factor-for-the-number-of-coordinating-only-node-in-a-cluster-and-how-to-route-the-requests/326842)

<div class="topic-metadata">

**Author:** [@pruthvi](https://discuss.elastic.co/u/pruthvi)\
**Replies:** 1\
**Last updated:** [March 8, 2023, 12:54am UTC](https://discuss.elastic.co/t/what-is-the-deciding-factor-for-the-number-of-coordinating-only-node-in-a-cluster-and-how-to-route-the-requests/326842 "2023-03-08T00:54:28Z")

</div>

Hi, I have a requirement to index 100TB of data per month in ES with ILM. No. dedicated master nodes – 3 nodes. Total no. of hot nodes - 66 nodes. Total no. of warm nodes - 216 nodes. Above calculations are based on…

---

## [Create new field value is incorrect](https://discuss.elastic.co/t/create-new-field-value-is-incorrect/326912)

<div class="topic-metadata">

**Author:** [@ikonrao](https://discuss.elastic.co/u/ikonrao)\
**Replies:** 1\
**Last updated:** [March 7, 2023, 10:54pm UTC](https://discuss.elastic.co/t/create-new-field-value-is-incorrect/326912 "2023-03-07T22:54:34Z")

</div>

Hi, I have a field which has value in seconds. I need to view it in hours. I used create new field and used script to convert it into hours. What i have observed is it is not able to take decimal values. For example, …

---

## [Logstash writer permissions](https://discuss.elastic.co/t/logstash-writer-permissions/327099)

<div class="topic-metadata">

**Author:** [@jfs1](https://discuss.elastic.co/u/jfs1)\
**Replies:** 0\
**Last updated:** [March 6, 2023, 3:45pm UTC](https://discuss.elastic.co/t/logstash-writer-permissions/327099 "2023-03-06T15:45:03Z")

</div>

On a new on-premises 8.6 logstash+elasticsearch deployment, I have the following error when configuring my "logstash\_writer" role as explained in Secure your connection to Elasticsearch | Logstash Reference \[8.6\] | Elast…

---

## [ElasticSearch and Kibana Migration](https://discuss.elastic.co/t/elasticsearch-and-kibana-migration/327146)

<div class="topic-metadata">

**Author:** [@Ramesh\_Ramachandran](https://discuss.elastic.co/u/Ramesh_Ramachandran)\
**Replies:** 1\
**Last updated:** [March 7, 2023, 10:25pm UTC](https://discuss.elastic.co/t/elasticsearch-and-kibana-migration/327146 "2023-03-07T22:25:37Z")

</div>

Hi Team, We are in the process of migrating Elasticsearch and Kibana from 8.2.2 to 8.5.3. We have deployed ES and Kibana in AKS with helm chart deployment. On migrating we are facing the below issue. \[2023-03-07T05:17…

---

## [Error in installing kibana](https://discuss.elastic.co/t/error-in-installing-kibana/327092)

<div class="topic-metadata">

**Author:** [@Ahmed\_Khaled](https://discuss.elastic.co/u/Ahmed_Khaled)\
**Replies:** 3\
**Last updated:** [March 7, 2023, 10:23pm UTC](https://discuss.elastic.co/t/error-in-installing-kibana/327092 "2023-03-07T22:23:51Z")

</div>

hello team, I am a beginner in using elastic stack and I have a problem (Kibana server is not ready) how I can fix it please????

---

## [Number of Zones for Zone awared Shard allocation](https://discuss.elastic.co/t/number-of-zones-for-zone-awared-shard-allocation/327169)

<div class="topic-metadata">

**Author:** [@Mani2](https://discuss.elastic.co/u/Mani2)\
**Replies:** 1\
**Last updated:** [March 7, 2023, 10:20pm UTC](https://discuss.elastic.co/t/number-of-zones-for-zone-awared-shard-allocation/327169 "2023-03-07T22:20:37Z")

</div>

Hello, What can be the criteria of deciding the maximum number of zones within a data centre. For ex, If I have 30 Racks in a Data Centre, and if I have Primary and Secondary shards are 1,2 so minimum zones require will…

---

## [Getting authentication failure when logging into kibana](https://discuss.elastic.co/t/getting-authentication-failure-when-logging-into-kibana/327222)

<div class="topic-metadata">

**Author:** [@Russell\_Fulton](https://discuss.elastic.co/u/Russell_Fulton)\
**Replies:** 1\
**Last updated:** [March 7, 2023, 10:06pm UTC](https://discuss.elastic.co/t/getting-authentication-failure-when-logging-into-kibana/327222 "2023-03-07T22:06:42Z")

</div>

I am trying to log into kibana as the elastic user to do some maintenance but the login fails -- server shows: Authentication of \[elastic\] was terminated by realm \[reserved\] - failed to authenticate user \[elastic\] I ca…

[Previous page](https://discuss.elastic.co/tag/none.md?no_tags=true&page=420)

[Next page](https://discuss.elastic.co/tag/none.md?no_tags=true&page=422)
