# \#none

**URL:** https://discuss.elastic.co/tag/none.md?no_tags=true&page=488

[Latest](https://discuss.elastic.co/latest.md) · [Categories](https://discuss.elastic.co/categories.md) · [Tags](https://discuss.elastic.co/tags.md)

**Page:** 489

---

## [Is it safe to modify system index template settings?](https://discuss.elastic.co/t/is-it-safe-to-modify-system-index-template-settings/319894)

<div class="topic-metadata">

**Author:** [@windows95](https://discuss.elastic.co/u/windows95)\
**Replies:** 1\
**Last updated:** [November 30, 2022, 1:03am UTC](https://discuss.elastic.co/t/is-it-safe-to-modify-system-index-template-settings/319894 "2022-11-30T01:03:56Z")

</div>

I have a single node installation. This leads to an yellow/unhealthy status when indices have replication configured. In my case there are these system indices which cause problems: .internal.alerts-observability.logs.a…

---

## [How to Stop Deletion of a Specific Index?](https://discuss.elastic.co/t/how-to-stop-deletion-of-a-specific-index/320032)

<div class="topic-metadata">

**Author:** [@Jdman647](https://discuss.elastic.co/u/Jdman647)\
**Replies:** 1\
**Last updated:** [November 30, 2022, 12:58am UTC](https://discuss.elastic.co/t/how-to-stop-deletion-of-a-specific-index/320032 "2022-11-30T00:58:45Z")

</div>

Hello, Using Securityonion's 'advanced clustering' which means us managing it's cluster. Our delete time is set to 15 days for our so-\* indices. If I want to stop specific index: so-zeek-11232022 from being deleted af…

---

## [cURL command to create the snapshot (cURL PUT) is showing empty response](https://discuss.elastic.co/t/curl-command-to-create-the-snapshot-curl-put-is-showing-empty-response/320041)

<div class="topic-metadata">

**Author:** [@thulsidosskrishnan](https://discuss.elastic.co/u/thulsidosskrishnan)\
**Replies:** 1\
**Last updated:** [November 30, 2022, 12:58am UTC](https://discuss.elastic.co/t/curl-command-to-create-the-snapshot-curl-put-is-showing-empty-response/320041 "2022-11-30T00:58:07Z")

</div>

Hello All, Greetings. I have a script that does the process for creating a repo on S3 AWS . I get all the indices and use the ES PUT CURL command to create the snapshot . For some time now the process is not completin…

---

## [Generating a periodic(i.e. timeslot based, say 2min duration) aggregation on an existing ELK index](https://discuss.elastic.co/t/generating-a-periodic-i-e-timeslot-based-say-2min-duration-aggregation-on-an-existing-elk-index/319858)

<div class="topic-metadata">

**Author:** [@rvadiga](https://discuss.elastic.co/u/rvadiga)\
**Replies:** 1\
**Last updated:** [November 30, 2022, 12:50am UTC](https://discuss.elastic.co/t/generating-a-periodic-i-e-timeslot-based-say-2min-duration-aggregation-on-an-existing-elk-index/319858 "2022-11-30T00:50:59Z")

</div>

Hi Team, I need to design or derive a ELK index (configurable time-window/time-slot) populated based on a highly loaded (i.e say 300 million data points generated per day and indexed) ELK index and define a dashboard ba…

---

## [Postman PUT GET](https://discuss.elastic.co/t/postman-put-get/319861)

<div class="topic-metadata">

**Author:** [@codeRed123](https://discuss.elastic.co/u/codeRed123)\
**Replies:** 1\
**Last updated:** [November 30, 2022, 12:50am UTC](https://discuss.elastic.co/t/postman-put-get/319861 "2022-11-30T00:50:20Z")

</div>

How to get POSTMAN to create index and all when im doing localhost:9200/ it says "type": "security\_exception", Can some one tell how to resolve this error, when i try it via console of kibana it is fine but I want it in …

---

## [How to change the number of replicas of the indices .internal.preview.alerts-security.alerts-default](https://discuss.elastic.co/t/how-to-change-the-number-of-replicas-of-the-indices-internal-preview-alerts-security-alerts-default/319713)

<div class="topic-metadata">

**Author:** [@Mor123460](https://discuss.elastic.co/u/Mor123460)\
**Replies:** 1\
**Last updated:** [November 30, 2022, 12:49am UTC](https://discuss.elastic.co/t/how-to-change-the-number-of-replicas-of-the-indices-internal-preview-alerts-security-alerts-default/319713 "2022-11-30T00:49:47Z")

</div>

Hey :slight\_smile: I have a kibana and elasticsearch installed on the same server, meaning only one data node, without the need for any replicas. I successfully changed all the index templates to: "index.number\_of\_rep…

---

## [How to manage data retention time in ElasticSearch](https://discuss.elastic.co/t/how-to-manage-data-retention-time-in-elasticsearch/319729)

<div class="topic-metadata">

**Author:** [@m3bgwad](https://discuss.elastic.co/u/m3bgwad)\
**Replies:** 1\
**Last updated:** [November 30, 2022, 12:49am UTC](https://discuss.elastic.co/t/how-to-manage-data-retention-time-in-elasticsearch/319729 "2022-11-30T00:49:10Z")

</div>

Hello, What is default of index data retention? If I want to change and edit this retentions for customize the time, if the data after I specifically time I want to remove this data. Thanks in advance for your help.

---

## [Elasticsearch upgrade](https://discuss.elastic.co/t/elasticsearch-upgrade/319837)

<div class="topic-metadata">

**Author:** [@Suraj\_Jannu](https://discuss.elastic.co/u/Suraj_Jannu)\
**Replies:** 1\
**Last updated:** [November 30, 2022, 12:47am UTC](https://discuss.elastic.co/t/elasticsearch-upgrade/319837 "2022-11-30T00:47:44Z")

</div>

Hello, We are planning to upgrade the ELK stack of the below versions to 8.4.3. Elasticsearch: 7.5.1 Kibana : 6.7.2 Logstash : 6.8.12 Questions: What should be the order of Upgrade? (Should I up…

---

## [Data/master node offline for extended period](https://discuss.elastic.co/t/data-master-node-offline-for-extended-period/319566)

<div class="topic-metadata">

**Author:** [@eh2021-elastic](https://discuss.elastic.co/u/eh2021-elastic)\
**Replies:** 1\
**Last updated:** [November 30, 2022, 12:43am UTC](https://discuss.elastic.co/t/data-master-node-offline-for-extended-period/319566 "2022-11-30T00:43:48Z")

</div>

I have a 3-node cluster that is used for monitoring. Each node runs the master and data roles. I just noticed that one of the nodes had been offline for a couple of months and after finding out why, the config had been …

---

## [Rollover alias vs index alias](https://discuss.elastic.co/t/rollover-alias-vs-index-alias/319698)

<div class="topic-metadata">

**Author:** [@mikhatanu](https://discuss.elastic.co/u/mikhatanu)\
**Replies:** 1\
**Last updated:** [November 30, 2022, 12:42am UTC](https://discuss.elastic.co/t/rollover-alias-vs-index-alias/319698 "2022-11-30T00:42:01Z")

</div>

Hello, I am going to apply ILM to an index template from Kibana. When applying to index template, there's a field of "alias for rollover index", but i have set and alias already in index template. What is the difference …

---

## [How robust is an Elastic cluster for planned single host outages?](https://discuss.elastic.co/t/how-robust-is-an-elastic-cluster-for-planned-single-host-outages/319794)

<div class="topic-metadata">

**Author:** [@ankh](https://discuss.elastic.co/u/ankh)\
**Replies:** 8\
**Last updated:** [November 29, 2022, 9:33pm UTC](https://discuss.elastic.co/t/how-robust-is-an-elastic-cluster-for-planned-single-host-outages/319794 "2022-11-29T21:33:37Z")

</div>

We are doing some network changes on about a dozen or so Elastic hosts, necessitating taking each host off the network briefly (up to a few minutes). We have at least 2 replicas for every index (ie 1 primary + 2 replica…

---

## [\[Integrations\] F5 Integration, Radware Integration Out Of Date](https://discuss.elastic.co/t/integrations-f5-integration-radware-integration-out-of-date/319241)

<div class="topic-metadata">

**Author:** [@cmendez92](https://discuss.elastic.co/u/cmendez92)\
**Replies:** 2\
**Last updated:** [November 29, 2022, 5:53pm UTC](https://discuss.elastic.co/t/integrations-f5-integration-radware-integration-out-of-date/319241 "2022-11-29T17:53:09Z")

</div>

F5 and Radware integrations are deprecated. Let me explain, it is not normal that they have an intermediate parser in JS (without posibility of change fron integration), it is practically better to let the message throug…

---

## [Prevent collision of field types of structured logs](https://discuss.elastic.co/t/prevent-collision-of-field-types-of-structured-logs/319806)

<div class="topic-metadata">

**Author:** [@katexochen](https://discuss.elastic.co/u/katexochen)\
**Replies:** 3\
**Last updated:** [November 29, 2022, 5:01pm UTC](https://discuss.elastic.co/t/prevent-collision-of-field-types-of-structured-logs/319806 "2022-11-29T17:01:09Z")

</div>

I'm collecting logs to filebeat, sending them to logstash and from there to elastic. As the logs are structured, I'm using the json filter in logstash to parse the message. Let's say I'm having two messages/logs in json…

---

## [Ignore-above](https://discuss.elastic.co/t/ignore-above/320064)

<div class="topic-metadata">

**Author:** [@Anil\_Alapati](https://discuss.elastic.co/u/Anil_Alapati)\
**Replies:** 1\
**Last updated:** [November 29, 2022, 4:15pm UTC](https://discuss.elastic.co/t/ignore-above/320064 "2022-11-29T16:15:29Z")

</div>

Hi, i could see ignore-above variable in index settings. What does this mean and does this applicable to both ELASTIC SEARCH Discovery and Kibana Lens view?

---

## [\[again\] Endpoint security immediately degraded](https://discuss.elastic.co/t/again-endpoint-security-immediately-degraded/318765)

<div class="topic-metadata">

**Author:** [@CrazyDumpling](https://discuss.elastic.co/u/CrazyDumpling)\
**Replies:** 8\
**Last updated:** [November 29, 2022, 3:35pm UTC](https://discuss.elastic.co/t/again-endpoint-security-immediately-degraded/318765 "2022-11-29T15:35:46Z")

</div>

Hello. I know this has been asked a million times here, but i've tried everything i know and i still can't get it to work. I have an Agent Policies with Network Packet Capture, Elastic Defend, and System integrations. …

---

## [Unable to delete datastream using delete datastream api](https://discuss.elastic.co/t/unable-to-delete-datastream-using-delete-datastream-api/320053)

<div class="topic-metadata">

**Author:** [@chinmoy\_padhi](https://discuss.elastic.co/u/chinmoy_padhi)\
**Replies:** 1\
**Last updated:** [November 29, 2022, 3:22pm UTC](https://discuss.elastic.co/t/unable-to-delete-datastream-using-delete-datastream-api/320053 "2022-11-29T15:22:54Z")

</div>

Hi I have referred the following link Delete data stream API | Elasticsearch Guide \[7.17\] | Elastic to delete Data stream. Unfortunately, not able to succeed Whenever I tried from console curl -X DELETE localhost:9200/…

---

## [One of the nodes disk usage is almost full](https://discuss.elastic.co/t/one-of-the-nodes-disk-usage-is-almost-full/318977)

<div class="topic-metadata">

**Author:** [@catadetest](https://discuss.elastic.co/u/catadetest)\
**Replies:** 8\
**Last updated:** [November 29, 2022, 2:44pm UTC](https://discuss.elastic.co/t/one-of-the-nodes-disk-usage-is-almost-full/318977 "2022-11-29T14:44:39Z")

</div>

We have 3 nodes in an elasticsearch cluster on version: 6.8.21 All of them are master and data nodes. Today, we observed that one node disk usage is almost full (88%), while the others are only 13%, 25% used. curl -s …

---

## [Wildcard queries slow since ES 5.x](https://discuss.elastic.co/t/wildcard-queries-slow-since-es-5-x/320054)

<div class="topic-metadata">

**Author:** [@nesretep](https://discuss.elastic.co/u/nesretep)\
**Replies:** 1\
**Last updated:** [November 29, 2022, 2:33pm UTC](https://discuss.elastic.co/t/wildcard-queries-slow-since-es-5-x/320054 "2022-11-29T14:33:18Z")

</div>

Hi there In the past, to my knowledge untill ES 6, queries - especially wildcard queries - were in general blisteringly fast. Since then, performance has degraded dramatically, with small improvements up through ES 7 an…

---

## ["TypeError: You provided 'undefined' where a stream was expected. You can provide an Observable](https://discuss.elastic.co/t/typeerror-you-provided-undefined-where-a-stream-was-expected-you-can-provide-an-observable/320056)

<div class="topic-metadata">

**Author:** [@Rajitha\_Bizz](https://discuss.elastic.co/u/Rajitha_Bizz)\
**Replies:** 0\
**Last updated:** [November 29, 2022, 2:12pm UTC](https://discuss.elastic.co/t/typeerror-you-provided-undefined-where-a-stream-was-expected-you-can-provide-an-observable/320056 "2022-11-29T14:12:38Z")

</div>

I facing this issue when we update kibana from 7.10.2 to 7.17.7. It is kind of strange behavior, there is a nginx proxy in between. {"type":"log","@timestamp":"2022-11-29T13:32:08+00:00","tags":\["error","http"\],"pid":2…

---

## [Custom Ingest Pipeline](https://discuss.elastic.co/t/custom-ingest-pipeline/319316)

<div class="topic-metadata">

**Author:** [@acosta353](https://discuss.elastic.co/u/acosta353)\
**Replies:** 2\
**Last updated:** [November 29, 2022, 1:22pm UTC](https://discuss.elastic.co/t/custom-ingest-pipeline/319316 "2022-11-29T13:22:27Z")

</div>

Hello, I'm new to Elastic, and I'm trying to search how to configure properly a custom ingest pipeline to Apache integration. In fact, I need to add some different groks and time formats so that some logs can be parsed…

---

## [Elasticsearch search querry](https://discuss.elastic.co/t/elasticsearch-search-querry/320021)

<div class="topic-metadata">

**Author:** [@Ali5](https://discuss.elastic.co/u/Ali5)\
**Replies:** 4\
**Last updated:** [November 29, 2022, 11:56am UTC](https://discuss.elastic.co/t/elasticsearch-search-querry/320021 "2022-11-29T11:56:35Z")

</div>

GET products/\_search { "query": { "multi\_match" : { "query": "novel", "fields": \[ "description", "name","id" ,"price"\] } } } this is the querry which get my results done i want to convert it into java api in …

---

## [Filebeat logs not sent on a server for which chocolatey installed](https://discuss.elastic.co/t/filebeat-logs-not-sent-on-a-server-for-which-chocolatey-installed/318569)

<div class="topic-metadata">

**Author:** [@khadija70](https://discuss.elastic.co/u/khadija70)\
**Replies:** 1\
**Last updated:** [November 29, 2022, 11:43am UTC](https://discuss.elastic.co/t/filebeat-logs-not-sent-on-a-server-for-which-chocolatey-installed/318569 "2022-11-29T11:43:55Z")

</div>

Hi , We are configuring a server whith filebeat agent to send costum logs , however no logs are received on Kibana . Just to mention that the server for which we don't receive logs , we have chocolatey installed but it …

---

## [Mirror Kibanas on separate clusters](https://discuss.elastic.co/t/mirror-kibanas-on-separate-clusters/319814)

<div class="topic-metadata">

**Author:** [@lduvnjak](https://discuss.elastic.co/u/lduvnjak)\
**Replies:** 9\
**Last updated:** [November 29, 2022, 9:50am UTC](https://discuss.elastic.co/t/mirror-kibanas-on-separate-clusters/319814 "2022-11-29T09:50:59Z")

</div>

Hey Everyone, Is there any way to sync Kibanas across multiple clusters? Essentially, a way to sync all visualizations, dashboards, queries, etc. from one Kibana to another. I'm aware that you can use remote reindex, an…

---

## [Install Elasticsearch as a service - Windows](https://discuss.elastic.co/t/install-elasticsearch-as-a-service-windows/319463)

<div class="topic-metadata">

**Author:** [@Clonky](https://discuss.elastic.co/u/Clonky)\
**Replies:** 4\
**Last updated:** [November 29, 2022, 9:41am UTC](https://discuss.elastic.co/t/install-elasticsearch-as-a-service-windows/319463 "2022-11-29T09:41:19Z")

</div>

HI all, I have a fresh installation of Elasticsearch 8.5 and Kibana 8.5 on my Windows Server. I would like to install Elasticsearch as a Service that it gets started as soon as the Server starts and Kibana as well. Ho…

---

## [How to convert this ES querry into java?](https://discuss.elastic.co/t/how-to-convert-this-es-querry-into-java/320019)

<div class="topic-metadata">

**Author:** [@Ali5](https://discuss.elastic.co/u/Ali5)\
**Replies:** 0\
**Last updated:** [November 29, 2022, 9:37am UTC](https://discuss.elastic.co/t/how-to-convert-this-es-querry-into-java/320019 "2022-11-29T09:37:33Z")

</div>

GET products/\_search { "query": { "multi\_match" : { "query": "novel", "fields": \[ "description", "name","id" ,"price"\] } } } \`\`\`\`\`\`\`\`\`\`\`\`\`\`\`\`\`

---

## [Multiple URL links in one field](https://discuss.elastic.co/t/multiple-url-links-in-one-field/319965)

<div class="topic-metadata">

**Author:** [@Harold\_Van\_der\_Veken](https://discuss.elastic.co/u/Harold_Van_der_Veken)\
**Replies:** 3\
**Last updated:** [November 29, 2022, 9:15am UTC](https://discuss.elastic.co/t/multiple-url-links-in-one-field/319965 "2022-11-29T09:15:00Z")

</div>

Is there a way to create a field that has more than 1 link to another resource. Can I create (and format) a string that holds 2 urls. E.g. "Goto \<this url\> or \<another url\>" \<this url\> can be selected to open the url. \<…

---

## [Collector \[cluster\_stats\] timed out when collecting data: node](https://discuss.elastic.co/t/collector-cluster-stats-timed-out-when-collecting-data-node/319955)

<div class="topic-metadata">

**Author:** [@rh05](https://discuss.elastic.co/u/rh05)\
**Replies:** 3\
**Last updated:** [November 29, 2022, 9:12am UTC](https://discuss.elastic.co/t/collector-cluster-stats-timed-out-when-collecting-data-node/319955 "2022-11-29T09:12:54Z")

</div>

Hello everyone, I have a problem if someone can help me it would be very appreciated. For several weeks I have noticed that my elastic cluster is unavailable for about 1 hour almost all the time at the same time on Sun…

---

## [Adding html\_strip filter](https://discuss.elastic.co/t/adding-html-strip-filter/319768)

<div class="topic-metadata">

**Author:** [@Srikanth\_V](https://discuss.elastic.co/u/Srikanth_V)\
**Replies:** 5\
**Last updated:** [November 29, 2022, 8:39am UTC](https://discuss.elastic.co/t/adding-html-strip-filter/319768 "2022-11-29T08:39:57Z")

</div>

Hello all, I would like to eliminate html tags when I am performing search on certain fields in elastic. Can this be achieved using html\_strip filter? If yes, can I have an example on how to add the analyzer and the fil…

---

## [Change timestamp in logstash input](https://discuss.elastic.co/t/change-timestamp-in-logstash-input/319506)

<div class="topic-metadata">

**Author:** [@zerratriani](https://discuss.elastic.co/u/zerratriani)\
**Replies:** 8\
**Last updated:** [November 29, 2022, 8:21am UTC](https://discuss.elastic.co/t/change-timestamp-in-logstash-input/319506 "2022-11-29T08:21:49Z")

</div>

Hi, I have a log like this and want to change the timestamp to the time in the log. Example Log event1: aaaaaaa | event2: xxxxxxx | event3: ccccccc | date : 2022-11-07T21:03:48.9110; The logstash input { file { …

---

## [Delete old document automatically (version 6.5.4)](https://discuss.elastic.co/t/delete-old-document-automatically-version-6-5-4/320007)

<div class="topic-metadata">

**Author:** [@gyrao\_72](https://discuss.elastic.co/u/gyrao_72)\
**Replies:** 1\
**Last updated:** [November 29, 2022, 8:06am UTC](https://discuss.elastic.co/t/delete-old-document-automatically-version-6-5-4/320007 "2022-11-29T08:06:09Z")

</div>

I want to delete old documents from elastic whenever a new record is inserted with the same request\_id through logstash Example: Suppose my first log to be inserted in elastic is 6b06a196-0f9e-4bec-9c2c-17f4f6cdd652 t…

[Previous page](https://discuss.elastic.co/tag/none.md?no_tags=true&page=487)

[Next page](https://discuss.elastic.co/tag/none.md?no_tags=true&page=489)
