# \#none

**URL:** https://discuss.elastic.co/tag/none.md?no_tags=true&page=435

[Latest](https://discuss.elastic.co/latest.md) · [Categories](https://discuss.elastic.co/categories.md) · [Tags](https://discuss.elastic.co/tags.md)

**Page:** 436

---

## [Computation of total in Reindex API status response](https://discuss.elastic.co/t/computation-of-total-in-reindex-api-status-response/325658)

<div class="topic-metadata">

**Author:** [@fifthist](https://discuss.elastic.co/u/fifthist)\
**Replies:** 0\
**Last updated:** [February 15, 2023, 8:23pm UTC](https://discuss.elastic.co/t/computation-of-total-in-reindex-api-status-response/325658 "2023-02-15T20:23:53Z")

</div>

I call Reindex API by creating a Task (wait\_for\_completion=false). I then use \_tasks API to get the details of the task once it is completed. Part of the task response is the response of the Reindex API with created, upd…

---

## [Metric to count number of queries per day/month](https://discuss.elastic.co/t/metric-to-count-number-of-queries-per-day-month/325076)

<div class="topic-metadata">

**Author:** [@Milad\_Heydariaan](https://discuss.elastic.co/u/Milad_Heydariaan)\
**Replies:** 4\
**Last updated:** [February 15, 2023, 6:23pm UTC](https://discuss.elastic.co/t/metric-to-count-number-of-queries-per-day-month/325076 "2023-02-15T18:23:00Z")

</div>

Hi, I'm trying to collect the number of queries that users send to Elasticsearch to understand how many queries per day/month are submitted to our clusters. I've tried using the following metrics mentioned in Nodes sta…

---

## [Filebeat : field \[event\] not present as part of path \[event.start\]](https://discuss.elastic.co/t/filebeat-field-event-not-present-as-part-of-path-event-start/325634)

<div class="topic-metadata">

**Author:** [@Youssef\_Mouadden](https://discuss.elastic.co/u/Youssef_Mouadden)\
**Replies:** 1\
**Last updated:** [February 15, 2023, 6:20pm UTC](https://discuss.elastic.co/t/filebeat-field-event-not-present-as-part-of-path-event-start/325634 "2023-02-15T18:20:51Z")

</div>

hello, I'm facing a problem with filebeat pipeline. when I execute the pipeline with a console output, I have no error and I have the right execution, except that when I put an elasticsearch output I receive the followi…

---

## [Elastic Agent conditions-based autodiscover doesn't pick up newly-scheduled pods/containers](https://discuss.elastic.co/t/elastic-agent-conditions-based-autodiscover-doesnt-pick-up-newly-scheduled-pods-containers/325271)

<div class="topic-metadata">

**Author:** [@DougR](https://discuss.elastic.co/u/DougR)\
**Replies:** 5\
**Last updated:** [February 15, 2023, 5:18pm UTC](https://discuss.elastic.co/t/elastic-agent-conditions-based-autodiscover-doesnt-pick-up-newly-scheduled-pods-containers/325271 "2023-02-15T17:18:39Z")

</div>

I am currently using Elastic Cloud, v8.6.1, with Elastic Agent Standalone v8.6.0 deployed to EKS, running Kubernetes v1.22.16 in our non-production cluster and v1.21.14 in our production cluster (to be updated this weeke…

---

## [High search\_fetch\_time for elasticsearch cluster](https://discuss.elastic.co/t/high-search-fetch-time-for-elasticsearch-cluster/325625)

<div class="topic-metadata">

**Author:** [@jaykb77](https://discuss.elastic.co/u/jaykb77)\
**Replies:** 1\
**Last updated:** [February 15, 2023, 5:13pm UTC](https://discuss.elastic.co/t/high-search-fetch-time-for-elasticsearch-cluster/325625 "2023-02-15T17:13:03Z")

</div>

We started seeing some high latency with the applications querying elasticsearch(7.17.0) and found that search\_fetch\_time is significantly increasing whenever there is some significant increase in incoming search traffic…

---

## [Send metricbeat via logstash as datastream](https://discuss.elastic.co/t/send-metricbeat-via-logstash-as-datastream/325628)

<div class="topic-metadata">

**Author:** [@A\_Mightiev](https://discuss.elastic.co/u/A_Mightiev)\
**Replies:** 4\
**Last updated:** [February 15, 2023, 4:41pm UTC](https://discuss.elastic.co/t/send-metricbeat-via-logstash-as-datastream/325628 "2023-02-15T16:41:24Z")

</div>

Hi I'm trying to send metricbeat data to logstash then store it as datastream into elasticsearch. I already have an datastream in elasticsearch "metricbeat-8.6.1", in my dashboards I'm using "metricbeat\*" index pattern …

---

## [Connect kibana to Elasticsearch after changes made](https://discuss.elastic.co/t/connect-kibana-to-elasticsearch-after-changes-made/325518)

<div class="topic-metadata">

**Author:** [@vassiliy.vins](https://discuss.elastic.co/u/vassiliy.vins)\
**Replies:** 16\
**Last updated:** [February 15, 2023, 4:00pm UTC](https://discuss.elastic.co/t/connect-kibana-to-elasticsearch-after-changes-made/325518 "2023-02-15T16:00:15Z")

</div>

Hello! My kibana doesnt talk to Elasticsearch after changes are made in elasticsearch config Some history: installed ELK on one host and filebeat on another one. Started elasticsearch, started kibana, started logsta…

---

## [Elasticsearch sort returns incorrect results?](https://discuss.elastic.co/t/elasticsearch-sort-returns-incorrect-results/325512)

<div class="topic-metadata">

**Author:** [@Fatih\_Erol1](https://discuss.elastic.co/u/Fatih_Erol1)\
**Replies:** 1\
**Last updated:** [February 15, 2023, 3:40pm UTC](https://discuss.elastic.co/t/elasticsearch-sort-returns-incorrect-results/325512 "2023-02-15T15:40:18Z")

</div>

Why elasticsearch sort returns incorrect results? Mappings { "mappings": { "\_doc": { "properties": { "name": { "type": "keyword", "fields": { "sort": { …

---

## [Limit of total fields \[1000\] in index has been exceeded after changing case classes to maps](https://discuss.elastic.co/t/limit-of-total-fields-1000-in-index-has-been-exceeded-after-changing-case-classes-to-maps/325635)

<div class="topic-metadata">

**Author:** [@markcitizen](https://discuss.elastic.co/u/markcitizen)\
**Replies:** 0\
**Last updated:** [February 15, 2023, 3:19pm UTC](https://discuss.elastic.co/t/limit-of-total-fields-1000-in-index-has-been-exceeded-after-changing-case-classes-to-maps/325635 "2023-02-15T15:19:34Z")

</div>

Hello, I have a Scala Spark job that's writing output data to ES index. I modified my code to recursively convert Scala classes into Maps before writing those to the index. Before (when using case classes) index write w…

---

## [When to clear es cache?](https://discuss.elastic.co/t/when-to-clear-es-cache/325428)

<div class="topic-metadata">

**Author:** [@elastic-db-user](https://discuss.elastic.co/u/elastic-db-user)\
**Replies:** 8\
**Last updated:** [February 15, 2023, 2:59pm UTC](https://discuss.elastic.co/t/when-to-clear-es-cache/325428 "2023-02-15T14:59:45Z")

</div>

Is it a good idea to proactively clear all cache with a daily cron job to avoid any circuit breaker or any other memory related issues? Api calls from app to Elasticsearch are the same query e.g. count, histogram, get, …

---

## [Kibana does not log all lines as json](https://discuss.elastic.co/t/kibana-does-not-log-all-lines-as-json/325627)

<div class="topic-metadata">

**Author:** [@woodywoodsta](https://discuss.elastic.co/u/woodywoodsta)\
**Replies:** 0\
**Last updated:** [February 15, 2023, 2:36pm UTC](https://discuss.elastic.co/t/kibana-does-not-log-all-lines-as-json/325627 "2023-02-15T14:36:24Z")

</div>

I have Kibana deployed as an ECK resource. Despite the following config: config: logging: appenders: json-layout: type: console layout: type: json root: appenders: \[json-…

---

## [Some indexes stopped to rollover and are now created without alias](https://discuss.elastic.co/t/some-indexes-stopped-to-rollover-and-are-now-created-without-alias/325623)

<div class="topic-metadata">

**Author:** [@zebu14](https://discuss.elastic.co/u/zebu14)\
**Replies:** 0\
**Last updated:** [February 15, 2023, 2:08pm UTC](https://discuss.elastic.co/t/some-indexes-stopped-to-rollover-and-are-now-created-without-alias/325623 "2023-02-15T14:08:59Z")

</div>

Hello, Some weeks ago, I had a full disk problem on my dev cluster. I made some space, reactivated index writing with PUT /\_all/\_settings { "index.blocks.read\_only\_allow\_delete": null } Most of the indexes are doin…

---

## [Elastic agent on eks](https://discuss.elastic.co/t/elastic-agent-on-eks/324903)

<div class="topic-metadata">

**Author:** [@oded\_rafi](https://discuss.elastic.co/u/oded_rafi)\
**Replies:** 1\
**Last updated:** [February 15, 2023, 1:48pm UTC](https://discuss.elastic.co/t/elastic-agent-on-eks/324903 "2023-02-15T13:48:27Z")

</div>

hey all i am trying to run an agent on my eks cluster and the pods wont run i am using the code from elastic as is. could anyone help? --- # For more information refer to https://www.elastic.co/guide/en/fleet/current…

---

## [Elastic Agent not shipping all logs from Kubernetes Cluster. Errors in logs](https://discuss.elastic.co/t/elastic-agent-not-shipping-all-logs-from-kubernetes-cluster-errors-in-logs/325620)

<div class="topic-metadata">

**Author:** [@slogger](https://discuss.elastic.co/u/slogger)\
**Replies:** 0\
**Last updated:** [February 15, 2023, 1:44pm UTC](https://discuss.elastic.co/t/elastic-agent-not-shipping-all-logs-from-kubernetes-cluster-errors-in-logs/325620 "2023-02-15T13:44:55Z")

</div>

Hello I have Elastic Agent installed on 5 EKS clusters for logging and monitoring. Recently the agents have stopped shipping all logs to the cluster (Hosted with elastic.cloud). Im seeing some logs, but not all (usual…

---

## [Elasticsearch.service craches (Active: failed) every 1,2 days](https://discuss.elastic.co/t/elasticsearch-service-craches-active-failed-every-1-2-days/325373)

<div class="topic-metadata">

**Author:** [@Ziad\_Khater](https://discuss.elastic.co/u/Ziad_Khater)\
**Replies:** 12\
**Last updated:** [February 15, 2023, 12:42pm UTC](https://discuss.elastic.co/t/elasticsearch-service-craches-active-failed-every-1-2-days/325373 "2023-02-15T12:42:09Z")

</div>

Hi Team, every 1,2 days elasticsearch.service failed on my ubunto machine. It has all memory/disk resources it needs. I'll attach logs here and below is the failed status of elasticsearch. ===========================…

---

## [Change time zone using date filter](https://discuss.elastic.co/t/change-time-zone-using-date-filter/325461)

<div class="topic-metadata">

**Author:** [@yuswanul](https://discuss.elastic.co/u/yuswanul)\
**Replies:** 5\
**Last updated:** [February 15, 2023, 12:37pm UTC](https://discuss.elastic.co/t/change-time-zone-using-date-filter/325461 "2023-02-15T12:37:36Z")

</div>

Hi there, i have a problem with timezone in date filter. so this is the situation: i have a field contain an epoch timestamp like this i try to convert it using date filter like this but it didn't work mutate{ …

---

## [Problems using search\_fields and weighting in queries](https://discuss.elastic.co/t/problems-using-search-fields-and-weighting-in-queries/325610)

<div class="topic-metadata">

**Author:** [@bar8s](https://discuss.elastic.co/u/bar8s)\
**Replies:** 0\
**Last updated:** [February 15, 2023, 12:35pm UTC](https://discuss.elastic.co/t/problems-using-search-fields-and-weighting-in-queries/325610 "2023-02-15T12:35:34Z")

</div>

I am trying to query an Elasticsearch index with some dynamic weighting on specific fields, but the query parser is rejecting the query I am basing this on the documentation at Relevance Tuning Guide, Weights and Boosts…

---

## [Synonyms Exact match Multiword Search](https://discuss.elastic.co/t/synonyms-exact-match-multiword-search/325439)

<div class="topic-metadata">

**Author:** [@Sahil5](https://discuss.elastic.co/u/Sahil5)\
**Replies:** 3\
**Last updated:** [February 15, 2023, 12:34pm UTC](https://discuss.elastic.co/t/synonyms-exact-match-multiword-search/325439 "2023-02-15T12:34:42Z")

</div>

Hi Team, We are looking for solution to search synonyms with exact match. For Example User is searching string - abc xyz abc has synonyms - abc1 abc2 xyz has synonyms - xyz1 xyz2 Data in Index Article1 - test abc1 …

---

## [Column count doesn't match after doing alias](https://discuss.elastic.co/t/column-count-doesnt-match-after-doing-alias/325454)

<div class="topic-metadata">

**Author:** [@Rushikesh\_Dikey](https://discuss.elastic.co/u/Rushikesh_Dikey)\
**Replies:** 1\
**Last updated:** [February 15, 2023, 10:37am UTC](https://discuss.elastic.co/t/column-count-doesnt-match-after-doing-alias/325454 "2023-02-15T10:37:23Z")

</div>

Hi Team, I am trying to merge two different index, so i used // POST /\_aliases { "actions": \[ { "add": { "index": "abc", "alias": "poc" } }, { "add": { "index": "xyz", …

---

## [Logs, metrics and APM on Solaris, HPUX - I know it's not supported - but related question anyway](https://discuss.elastic.co/t/logs-metrics-and-apm-on-solaris-hpux-i-know-its-not-supported-but-related-question-anyway/325598)

<div class="topic-metadata">

**Author:** [@Melee](https://discuss.elastic.co/u/Melee)\
**Replies:** 0\
**Last updated:** [February 15, 2023, 10:30am UTC](https://discuss.elastic.co/t/logs-metrics-and-apm-on-solaris-hpux-i-know-its-not-supported-but-related-question-anyway/325598 "2023-02-15T10:30:29Z")

</div>

Hello together, we are using the elastic stack (elastic agent, APM agent, heartbeat, logstash, kibana). So far so fine. Now, we have some legacy systems esp. Solaris, HPUX and also RHEL 6. There were already multiple …

---

## [Security Alert ：How to suppress repeat alarms](https://discuss.elastic.co/t/security-alert-how-to-suppress-repeat-alarms/325565)

<div class="topic-metadata">

**Author:** [@xqaiviwjxzw](https://discuss.elastic.co/u/xqaiviwjxzw)\
**Replies:** 1\
**Last updated:** [February 15, 2023, 10:29am UTC](https://discuss.elastic.co/t/security-alert-how-to-suppress-repeat-alarms/325565 "2023-02-15T10:29:32Z")

</div>

More than 100 duplicate alarms are generated in 1 minute, what can be done to suppress duplicate alarms and display only one of the duplicate alarms?

---

## [Remote Linux logs](https://discuss.elastic.co/t/remote-linux-logs/325578)

<div class="topic-metadata">

**Author:** [@Derick\_Jansen](https://discuss.elastic.co/u/Derick_Jansen)\
**Replies:** 0\
**Last updated:** [February 15, 2023, 9:48am UTC](https://discuss.elastic.co/t/remote-linux-logs/325578 "2023-02-15T09:48:42Z")

</div>

Is there no way to use Elastic Agent or Filebeat to accept TCP Syslog messages forwarded from Linux hosts? Will I need to use something like rsyslog or Logstash to write the files to disk first, then use the system inte…

---

## [Log4j add more fields](https://discuss.elastic.co/t/log4j-add-more-fields/325546)

<div class="topic-metadata">

**Author:** [@manusha\_karunathilak](https://discuss.elastic.co/u/manusha_karunathilak)\
**Replies:** 0\
**Last updated:** [February 15, 2023, 6:18am UTC](https://discuss.elastic.co/t/log4j-add-more-fields/325546 "2023-02-15T06:18:53Z")

</div>

I have setup to write log4j logs to elasticsearch. However it only maps log4j default fields such as level, message and etc. Full log message contains session id in the console log but that part is not mapped by default…

---

## [Elastic Upgrade Issue](https://discuss.elastic.co/t/elastic-upgrade-issue/325470)

<div class="topic-metadata">

**Author:** [@cobdeng](https://discuss.elastic.co/u/cobdeng)\
**Replies:** 3\
**Last updated:** [February 15, 2023, 7:30am UTC](https://discuss.elastic.co/t/elastic-upgrade-issue/325470 "2023-02-15T07:30:44Z")

</div>

Hi We are currently using Elasticsearch 7.16.2 and are now looking at the upgrade process to 7.16.3 and upwards. When we initially installed Elasticsearch, we used the msi installers that were then available as we are …

---

## [Custom plugin and custom entries in /etc/default/logstash gets deleted after each update on ubuntu](https://discuss.elastic.co/t/custom-plugin-and-custom-entries-in-etc-default-logstash-gets-deleted-after-each-update-on-ubuntu/325549)

<div class="topic-metadata">

**Author:** [@stillfreem](https://discuss.elastic.co/u/stillfreem)\
**Replies:** 0\
**Last updated:** [February 15, 2023, 6:44am UTC](https://discuss.elastic.co/t/custom-plugin-and-custom-entries-in-etc-default-logstash-gets-deleted-after-each-update-on-ubuntu/325549 "2023-02-15T06:44:03Z")

</div>

Hello All, I wanted a to ask if anybody knows why after almost each apt-get update/upgrate on my server two output plugins always gets deleted and I need to reinstall them along with all custom Logstash entries in /etc/…

---

## [Update\_by\_query - empty failures list in response when conflicts=proceed](https://discuss.elastic.co/t/update-by-query-empty-failures-list-in-response-when-conflicts-proceed/325100)

<div class="topic-metadata">

**Author:** [@Przemyslaw\_Mantaj](https://discuss.elastic.co/u/Przemyslaw_Mantaj)\
**Replies:** 1\
**Last updated:** [February 15, 2023, 5:51am UTC](https://discuss.elastic.co/t/update-by-query-empty-failures-list-in-response-when-conflicts-proceed/325100 "2023-02-15T05:51:30Z")

</div>

Continuing the discussion from Update\_by\_query with proceed does not return failure: I repeat @Paul\_Le\_Tilly question. Is it possible to return the failures list when the conflicts option has been set to proceed? Than…

---

## [Error importing Kibana dashboards: fail to import the dashboards in Kibana:](https://discuss.elastic.co/t/error-importing-kibana-dashboards-fail-to-import-the-dashboards-in-kibana/316015)

<div class="topic-metadata">

**Author:** [@Joao\_Malebo](https://discuss.elastic.co/u/Joao_Malebo)\
**Replies:** 6\
**Last updated:** [February 15, 2023, 4:16am UTC](https://discuss.elastic.co/t/error-importing-kibana-dashboards-fail-to-import-the-dashboards-in-kibana/316015 "2023-02-15T04:16:07Z")

</div>

I'm having errors when running the command to check the version information. To load dashboards when Logstash is enabled, you need to disable Logstash output and enable Elasticsearch output: Follow the command and error…

---

## [Elasticsearch + Java - Inconsistent Search/Query time](https://discuss.elastic.co/t/elasticsearch-java-inconsistent-search-query-time/325527)

<div class="topic-metadata">

**Author:** [@Java2avaj](https://discuss.elastic.co/u/Java2avaj)\
**Replies:** 0\
**Last updated:** [February 15, 2023, 3:38am UTC](https://discuss.elastic.co/t/elasticsearch-java-inconsistent-search-query-time/325527 "2023-02-15T03:38:35Z")

</div>

We are searching over 10million documents with a simple query that contains bool and multiple shoulds. But query time is inconsistent- taking sometimes 100ms sometimes 4 seconds. How can we tune this so that query time …

---

## [Elastic Security Manage - EndPoint not work](https://discuss.elastic.co/t/elastic-security-manage-endpoint-not-work/325367)

<div class="topic-metadata">

**Author:** [@NathanLau](https://discuss.elastic.co/u/NathanLau)\
**Replies:** 8\
**Last updated:** [February 15, 2023, 2:51am UTC](https://discuss.elastic.co/t/elastic-security-manage-endpoint-not-work/325367 "2023-02-15T02:51:03Z")

</div>

Hi , When I deleted agents for endpoint , I want to re-add agent to endpoint but not work , even I reinstall fleet server or any hosts to security --\> manage --\> Endpoint. references: Keep showing this to inst…

---

## [How to dynamically specify a url formatter](https://discuss.elastic.co/t/how-to-dynamically-specify-a-url-formatter/325520)

<div class="topic-metadata">

**Author:** [@kohkaw](https://discuss.elastic.co/u/kohkaw)\
**Replies:** 0\
**Last updated:** [February 15, 2023, 1:58am UTC](https://discuss.elastic.co/t/how-to-dynamically-specify-a-url-formatter/325520 "2023-02-15T01:58:25Z")

</div>

I want to dynamically specify a url formatter for a document that contains an ever-increasing number of URL strings. Is there any other way than manually setting Set format=url from Index pattern?

[Previous page](https://discuss.elastic.co/tag/none.md?no_tags=true&page=434)

[Next page](https://discuss.elastic.co/tag/none.md?no_tags=true&page=436)
