# \#none

**URL:** https://discuss.elastic.co/tag/none.md?no_tags=true&page=434

[Latest](https://discuss.elastic.co/latest.md) · [Categories](https://discuss.elastic.co/categories.md) · [Tags](https://discuss.elastic.co/tags.md)

**Page:** 435

---

## [Migrating from self hosted to elastic service, how to change our ingest flow from kafka/logstash?](https://discuss.elastic.co/t/migrating-from-self-hosted-to-elastic-service-how-to-change-our-ingest-flow-from-kafka-logstash/325766)

<div class="topic-metadata">

**Author:** [@tymercer](https://discuss.elastic.co/u/tymercer)\
**Replies:** 7\
**Last updated:** [February 16, 2023, 7:14pm UTC](https://discuss.elastic.co/t/migrating-from-self-hosted-to-elastic-service-how-to-change-our-ingest-flow-from-kafka-logstash/325766 "2023-02-16T19:14:48Z")

</div>

We are in the process of migrating our self hosted ELK stack to the hosted Elastic Services in Azure. Currently we have our servers running filebeat configured to push their logs to Kafka/zookeeper which then pushes to …

---

## [Use of aggregations with multiple queries](https://discuss.elastic.co/t/use-of-aggregations-with-multiple-queries/325763)

<div class="topic-metadata">

**Author:** [@usergbgc](https://discuss.elastic.co/u/usergbgc)\
**Replies:** 0\
**Last updated:** [February 16, 2023, 4:31pm UTC](https://discuss.elastic.co/t/use-of-aggregations-with-multiple-queries/325763 "2023-02-16T16:31:24Z")

</div>

Hello, I've been having trouble getting some results for a while, and I'm starting to wonder if my query is even feasible. I have a set of documents collecting articles, with fields like date, title, and a nested autho…

---

## [Convert values from string to int](https://discuss.elastic.co/t/convert-values-from-string-to-int/325164)

<div class="topic-metadata">

**Author:** [@Law\_Rence](https://discuss.elastic.co/u/Law_Rence)\
**Replies:** 6\
**Last updated:** [February 16, 2023, 2:31pm UTC](https://discuss.elastic.co/t/convert-values-from-string-to-int/325164 "2023-02-16T14:31:23Z")

</div>

How can I convert all the keys that have numbers from strings to int using ruby? example: "x": "hello", "a": "1", "b": "2", "c": "3", "d": "bye" to: "x": "hello", "a": 1, "b": 2, "c": 3, e.t.c here's my ruby…

---

## [Migrate indices from elasticsearsh 6.8 to 7.17](https://discuss.elastic.co/t/migrate-indices-from-elasticsearsh-6-8-to-7-17/325745)

<div class="topic-metadata">

**Author:** [@Parvatayya\_Malimath](https://discuss.elastic.co/u/Parvatayya_Malimath)\
**Replies:** 2\
**Last updated:** [February 16, 2023, 2:02pm UTC](https://discuss.elastic.co/t/migrate-indices-from-elasticsearsh-6-8-to-7-17/325745 "2023-02-16T14:02:29Z")

</div>

We have Elasticsearch 6.8 running at the moment and want to migrate it to 7.17. I have created another cluster with 7.17 running and we would like migrate the indices from 6.8. what is the best way to do it, I would li…

---

## [Elasticsearch 5 vs 8 performance and index size](https://discuss.elastic.co/t/elasticsearch-5-vs-8-performance-and-index-size/325601)

<div class="topic-metadata">

**Author:** [@Idorasi\_Paul](https://discuss.elastic.co/u/Idorasi_Paul)\
**Replies:** 9\
**Last updated:** [February 16, 2023, 1:45pm UTC](https://discuss.elastic.co/t/elasticsearch-5-vs-8-performance-and-index-size/325601 "2023-02-16T13:45:18Z")

</div>

Hello. I've updated from elasticsearch 5.6 to 8.1 and following load tests I can see a decrease in performance, between 20-40%. I was expecting 8.1 to be faster 5.6, I'm assuming we're doing something wrong. Another weir…

---

## [Разное использование дисков на дата нодах](https://discuss.elastic.co/t/topic/324702)

<div class="topic-metadata">

**Author:** [@vsityz](https://discuss.elastic.co/u/vsityz)\
**Replies:** 1\
**Last updated:** [February 16, 2023, 1:01pm UTC](https://discuss.elastic.co/t/topic/324702 "2023-02-16T13:01:53Z")

</div>

Есть две дата ноды в кластере. Одна останавливалась по причине нехватки места. Дата ноду поднял, синхронизирвал, но... Если посмотреть занимаемое место индексов, на одной ноде оно составляет 205G На другой (восстанов…

---

## [Cant do case insensitive search in elastic search](https://discuss.elastic.co/t/cant-do-case-insensitive-search-in-elastic-search/325680)

<div class="topic-metadata">

**Author:** [@Dang\_Hai](https://discuss.elastic.co/u/Dang_Hai)\
**Replies:** 2\
**Last updated:** [February 16, 2023, 12:58pm UTC](https://discuss.elastic.co/t/cant-do-case-insensitive-search-in-elastic-search/325680 "2023-02-16T12:58:35Z")

</div>

I'm new to Elasticsearch and trying to do this query right. So I'm having a document like this: { "id": 1, "name": "Văn Hiến" } I want to get that document in 3 cases: 1/ User input is: "v" or "h" or "i",... …

---

## [Customize panel time range - Last week, and Next week](https://discuss.elastic.co/t/customize-panel-time-range-last-week-and-next-week/325734)

<div class="topic-metadata">

**Author:** [@fengen](https://discuss.elastic.co/u/fengen)\
**Replies:** 0\
**Last updated:** [February 16, 2023, 12:26pm UTC](https://discuss.elastic.co/t/customize-panel-time-range-last-week-and-next-week/325734 "2023-02-16T12:26:19Z")

</div>

Hi, Does anyone know how to set the Customize panel time range to "Last week", and "Next week". It is possible to set it to "This week" which i think means that it chooses the week that you are currently in and updates…

---

## [Elastic Search:Update of existing Record (which has custom routing param set) results in duplicate record, if custom routing is not set during update](https://discuss.elastic.co/t/elastic-search-update-of-existing-record-which-has-custom-routing-param-set-results-in-duplicate-record-if-custom-routing-is-not-set-during-update/325730)

<div class="topic-metadata">

**Author:** [@Bhushan\_Shelke](https://discuss.elastic.co/u/Bhushan_Shelke)\
**Replies:** 0\
**Last updated:** [February 16, 2023, 11:55am UTC](https://discuss.elastic.co/t/elastic-search-update-of-existing-record-which-has-custom-routing-param-set-results-in-duplicate-record-if-custom-routing-is-not-set-during-update/325730 "2023-02-16T11:55:51Z")

</div>

Env Details: Elastic Search version 7.8.1 routing param is an optional in Index settings. As per Elasticsearch docs - \_routing field | Elasticsearch Guide \[8.6\] | Elastic When indexing documents specifying a custom \_…

---

## [Elastic On-Premise license buy,contact sales](https://discuss.elastic.co/t/elastic-on-premise-license-buy-contact-sales/325704)

<div class="topic-metadata">

**Author:** [@PRASHANT\_MEHTA](https://discuss.elastic.co/u/PRASHANT_MEHTA)\
**Replies:** 1\
**Last updated:** [February 16, 2023, 10:33am UTC](https://discuss.elastic.co/t/elastic-on-premise-license-buy-contact-sales/325704 "2023-02-16T10:33:09Z")

</div>

Hello Elastic Team, I have a question regarding Elasticsearch on premise licensing,I would like to get in contact with Sales or any representative who could guide out how licensing works.Currently I'm using elk 7.9.1 …

---

## [Writing queries with Search UI](https://discuss.elastic.co/t/writing-queries-with-search-ui/325712)

<div class="topic-metadata">

**Author:** [@Pierre-Olivier\_BEAU](https://discuss.elastic.co/u/Pierre-Olivier_BEAU)\
**Replies:** 0\
**Last updated:** [February 16, 2023, 10:01am UTC](https://discuss.elastic.co/t/writing-queries-with-search-ui/325712 "2023-02-16T10:01:23Z")

</div>

Hello all, I am currently researching the best way to send complex queries from a front-end interface to a custom api which will then send the query to Elasticsearch (using search UI-ES-connector). Search UI seems the …

---

## [Unkown script compilations for template-context in script-cache](https://discuss.elastic.co/t/unkown-script-compilations-for-template-context-in-script-cache/325707)

<div class="topic-metadata">

**Author:** [@The\_Hans](https://discuss.elastic.co/u/The_Hans)\
**Replies:** 0\
**Last updated:** [February 16, 2023, 9:43am UTC](https://discuss.elastic.co/t/unkown-script-compilations-for-template-context-in-script-cache/325707 "2023-02-16T09:43:02Z")

</div>

Hi, from time to time we are facing a 'circuit\_breaking\_exception' caused by 'Too many dynamic script compilations within, max: \[75/5m\]' We only use 2 score\_scripts to re-rank the score of documents. These 2 scripts us…

---

## [Fail to add second fleet server with error missing enrollment api key](https://discuss.elastic.co/t/fail-to-add-second-fleet-server-with-error-missing-enrollment-api-key/325698)

<div class="topic-metadata">

**Author:** [@lusynda](https://discuss.elastic.co/u/lusynda)\
**Replies:** 0\
**Last updated:** [February 16, 2023, 7:41am UTC](https://discuss.elastic.co/t/fail-to-add-second-fleet-server-with-error-missing-enrollment-api-key/325698 "2023-02-16T07:41:15Z")

</div>

Hi all, I have a weird case that i dont know how to fix. I've already setup a fleet server successfully and already enrolling agent to that fleet. But now i want to add another fleet server to the cluster to ensure hig…

---

## [Elastic decay function not working on nested field](https://discuss.elastic.co/t/elastic-decay-function-not-working-on-nested-field/324517)

<div class="topic-metadata">

**Author:** [@AthanatiusC](https://discuss.elastic.co/u/AthanatiusC)\
**Replies:** 2\
**Last updated:** [February 16, 2023, 6:58am UTC](https://discuss.elastic.co/t/elastic-decay-function-not-working-on-nested-field/324517 "2023-02-16T06:58:19Z")

</div>

I have the following configuration: mapping put geo\_test { "mappings":{ "properties":{ "name":{ "type":"text" }, "location":{ "type":"nested", "properties":{ "n…

---

## [Elasticsearch cluster automatically adds transient settings...How do I remove this?](https://discuss.elastic.co/t/elasticsearch-cluster-automatically-adds-transient-settings-how-do-i-remove-this/325353)

<div class="topic-metadata">

**Author:** [@prabhash\_mohanty](https://discuss.elastic.co/u/prabhash_mohanty)\
**Replies:** 4\
**Last updated:** [February 16, 2023, 6:27am UTC](https://discuss.elastic.co/t/elasticsearch-cluster-automatically-adds-transient-settings-how-do-i-remove-this/325353 "2023-02-16T06:27:29Z")

</div>

I have 2 nodes in the cluster log-es-default-0 and log-es-default-1. log-es-default-0 - master node log-es-default-1 - data node I tried running the below command but it still adds it. PUT /\_cluster/settings?pretty {…

---

## [ELK for Jasper](https://discuss.elastic.co/t/elk-for-jasper/325579)

<div class="topic-metadata">

**Author:** [@ELK\_USR1](https://discuss.elastic.co/u/ELK_USR1)\
**Replies:** 2\
**Last updated:** [February 16, 2023, 6:18am UTC](https://discuss.elastic.co/t/elk-for-jasper/325579 "2023-02-16T06:18:11Z")

</div>

I need elk on Jasper application. Can someone guide me to configure.

---

## [When i use snmp . why value in key:value is missing](https://discuss.elastic.co/t/when-i-use-snmp-why-value-in-key-value-is-missing/325684)

<div class="topic-metadata">

**Author:** [@sirichai\_phungsuntho](https://discuss.elastic.co/u/sirichai_phungsuntho)\
**Replies:** 0\
**Last updated:** [February 16, 2023, 4:37am UTC](https://discuss.elastic.co/t/when-i-use-snmp-why-value-in-key-value-is-missing/325684 "2023-02-16T04:37:06Z")

</div>

When i use input snmp and selct more than 10 columns in function tables i will receive missing value like this how can i fix it?

---

## [Logstash Kafka consumer count](https://discuss.elastic.co/t/logstash-kafka-consumer-count/325671)

<div class="topic-metadata">

**Author:** [@rsk0](https://discuss.elastic.co/u/rsk0)\
**Replies:** 1\
**Last updated:** [February 16, 2023, 5:47am UTC](https://discuss.elastic.co/t/logstash-kafka-consumer-count/325671 "2023-02-16T05:47:58Z")

</div>

According to the Logstash guide: "How many partitions should I use per topic?" At least the number of Logstash nodes multiplied by consumer threads per node. Better yet, use a multiple of the above number. Increasing…

---

## [Restart elastic agent from fleet server in kibana](https://discuss.elastic.co/t/restart-elastic-agent-from-fleet-server-in-kibana/325097)

<div class="topic-metadata">

**Author:** [@bex](https://discuss.elastic.co/u/bex)\
**Replies:** 1\
**Last updated:** [February 16, 2023, 4:56am UTC](https://discuss.elastic.co/t/restart-elastic-agent-from-fleet-server-in-kibana/325097 "2023-02-16T04:56:11Z")

</div>

Is it possible to restart the elastic agent (which is on the fleet server) from kibana? There is only an option to update, is there a way to restart elastic agents remotely? In case you have so many elastic agents, it …

---

## [Missing setting option "response.include\_body\_max\_bytes" in "Add Elastic Synthetics integration" UI](https://discuss.elastic.co/t/missing-setting-option-response-include-body-max-bytes-in-add-elastic-synthetics-integration-ui/325444)

<div class="topic-metadata">

**Author:** [@billhong-just](https://discuss.elastic.co/u/billhong-just)\
**Replies:** 1\
**Last updated:** [February 16, 2023, 1:24am UTC](https://discuss.elastic.co/t/missing-setting-option-response-include-body-max-bytes-in-add-elastic-synthetics-integration-ui/325444 "2023-02-16T01:24:03Z")

</div>

Description In Kibana v8.5.3's dashboard, I can't find the setting option response.include\_body\_max\_bytes to control the maximum size of the stored body contents. Is this a bug or is it by design? :thinking: Refer…

---

## [Best practices for internal corporate site search](https://discuss.elastic.co/t/best-practices-for-internal-corporate-site-search/325532)

<div class="topic-metadata">

**Author:** [@Buntu\_Dev](https://discuss.elastic.co/u/Buntu_Dev)\
**Replies:** 1\
**Last updated:** [February 15, 2023, 9:44pm UTC](https://discuss.elastic.co/t/best-practices-for-internal-corporate-site-search/325532 "2023-02-15T21:44:48Z")

</div>

I'm looking for best practices to tag the existing webpages which consist internal web apps and employee resources (internal forms, static content, policy documents) to help index into ES and make them available for site…

---

## [Couldn't open localhost:9200 for elasticsearch version 8.2.3](https://discuss.elastic.co/t/couldnt-open-localhost-9200-for-elasticsearch-version-8-2-3/325534)

<div class="topic-metadata">

**Author:** [@Sivapriya-Sugumar](https://discuss.elastic.co/u/Sivapriya-Sugumar)\
**Replies:** 1\
**Last updated:** [February 15, 2023, 9:44pm UTC](https://discuss.elastic.co/t/couldnt-open-localhost-9200-for-elasticsearch-version-8-2-3/325534 "2023-02-15T21:44:15Z")

</div>

This page isn’t working localhost didn’t send any data. ERR\_EMPTY\_RESPONSE getting this batch file is running but couldn't open localhost:9200 in elasticsaerch 8.2.3

---

## [Kibana alerts](https://discuss.elastic.co/t/kibana-alerts/325570)

<div class="topic-metadata">

**Author:** [@MahithaSarala](https://discuss.elastic.co/u/MahithaSarala)\
**Replies:** 1\
**Last updated:** [February 15, 2023, 9:41pm UTC](https://discuss.elastic.co/t/kibana-alerts/325570 "2023-02-15T21:41:00Z")

</div>

Hi team, I have installed elastisearch and kibana 8.5.1 throgh helm on cluster, now i tried to configure the alerts on kibana. So inside kibana pod kibana.yaml, In the kibana.yml configuration file, add the xpack.encryp…

---

## [Why data save to master cluster?](https://discuss.elastic.co/t/why-data-save-to-master-cluster/325576)

<div class="topic-metadata">

**Author:** [@fered](https://discuss.elastic.co/u/fered)\
**Replies:** 1\
**Last updated:** [February 15, 2023, 9:33pm UTC](https://discuss.elastic.co/t/why-data-save-to-master-cluster/325576 "2023-02-15T21:33:24Z")

</div>

I have a cluster that it have 3 master and 4 data node(2 hot , 1 warm , 1 cold). so i configure ILM for this cluster , but I dont know why index(primery & replica) save in master node ?

---

## [Getting 403 code while connecting to elastic](https://discuss.elastic.co/t/getting-403-code-while-connecting-to-elastic/325615)

<div class="topic-metadata">

**Author:** [@fvtarnovskiy](https://discuss.elastic.co/u/fvtarnovskiy)\
**Replies:** 1\
**Last updated:** [February 15, 2023, 9:32pm UTC](https://discuss.elastic.co/t/getting-403-code-while-connecting-to-elastic/325615 "2023-02-15T21:32:05Z")

</div>

Hello! We are a cloud provider from Uzbekistan pro-data.tech (https://pro-data.tech/). Please help in solving the problem - when trying to access Elastic, we get an error code 403 from all our addresses (95.47.127.0/24…

---

## [Logstash pipeline index question](https://discuss.elastic.co/t/logstash-pipeline-index-question/325273)

<div class="topic-metadata">

**Author:** [@MKirby](https://discuss.elastic.co/u/MKirby)\
**Replies:** 12\
**Last updated:** [February 15, 2023, 9:28pm UTC](https://discuss.elastic.co/t/logstash-pipeline-index-question/325273 "2023-02-15T21:28:45Z")

</div>

AS many of you know and have been following, my syslog collectors keep stopping due to running out of shards. I have made some improvements and they now run for about 3 weeks before I have to "close" the index. Better …

---

## [Kibana does not recognize the @timestamp field as a time filter](https://discuss.elastic.co/t/kibana-does-not-recognize-the-timestamp-field-as-a-time-filter/325404)

<div class="topic-metadata">

**Author:** [@Alvik173](https://discuss.elastic.co/u/Alvik173)\
**Replies:** 4\
**Last updated:** [February 15, 2023, 9:27pm UTC](https://discuss.elastic.co/t/kibana-does-not-recognize-the-timestamp-field-as-a-time-filter/325404 "2023-02-15T21:27:07Z")

</div>

Kibana (7.17.8) does not seem to recognize the @timestamp field in my index as a time field. The symptoms are as follows. In Discover, the "Show dates" box on the top right is missing The time series chart above the D…

---

## [Logstash rename json fields](https://discuss.elastic.co/t/logstash-rename-json-fields/325399)

<div class="topic-metadata">

**Author:** [@yilmazbuhar](https://discuss.elastic.co/u/yilmazbuhar)\
**Replies:** 6\
**Last updated:** [February 15, 2023, 9:24pm UTC](https://discuss.elastic.co/t/logstash-rename-json-fields/325399 "2023-02-15T21:24:05Z")

</div>

Hi community, We have a json log as below { "Timestamp": "2023-02-09T17:41:54.5320239+03:00", "Level": "", "MessageTemplate": "", "Properties": { "responsetime": 4758, "SourceContext": "", "Username…

---

## [Kibana server is not ready yet](https://discuss.elastic.co/t/kibana-server-is-not-ready-yet/325665)

<div class="topic-metadata">

**Author:** [@tagba](https://discuss.elastic.co/u/tagba)\
**Replies:** 0\
**Last updated:** [February 15, 2023, 9:07pm UTC](https://discuss.elastic.co/t/kibana-server-is-not-ready-yet/325665 "2023-02-15T21:07:06Z")

</div>

Hi All, Please am new to Dsiem. I have just clone it from github and running it on ubuntu, below is the error am getting. "Kibana server is not ready yet" see the logs below, can I get help with this please {"type":"…

---

## [Simple aggregation counting distinct values that has turned out to be difficult](https://discuss.elastic.co/t/simple-aggregation-counting-distinct-values-that-has-turned-out-to-be-difficult/325659)

<div class="topic-metadata">

**Author:** [@Adam\_Burr](https://discuss.elastic.co/u/Adam_Burr)\
**Replies:** 0\
**Last updated:** [February 15, 2023, 8:26pm UTC](https://discuss.elastic.co/t/simple-aggregation-counting-distinct-values-that-has-turned-out-to-be-difficult/325659 "2023-02-15T20:26:30Z")

</div>

I have a very simple index and I am trying to produce what I thought would be a simple aggregation, but I am finding it difficult to get working. I would be very grateful for any help the community can give. My "sales"…

[Previous page](https://discuss.elastic.co/tag/none.md?no_tags=true&page=433)

[Next page](https://discuss.elastic.co/tag/none.md?no_tags=true&page=435)
