# \#none

**URL:** https://discuss.elastic.co/tag/none.md?no_tags=true&page=532

[Latest](https://discuss.elastic.co/latest.md) · [Categories](https://discuss.elastic.co/categories.md) · [Tags](https://discuss.elastic.co/tags.md)

**Page:** 533

---

## [How to clone multiple indices at once within Kibana DevTools](https://discuss.elastic.co/t/how-to-clone-multiple-indices-at-once-within-kibana-devtools/314939)

<div class="topic-metadata">

**Author:** [@fim01](https://discuss.elastic.co/u/fim01)\
**Replies:** 4\
**Last updated:** [September 23, 2022, 12:29pm UTC](https://discuss.elastic.co/t/how-to-clone-multiple-indices-at-once-within-kibana-devtools/314939 "2022-09-23T12:29:22Z")

</div>

Hello Is it possible to clone multiple indices in one shot? I tried: POST /test-13,test-14,test-15/\_clone/test-clone Unfortunately I'll get an error: { "error" : { "root\_cause" : \[ { "type" : "…

---

## [Score is same for single value match vs multiple match for an array field using terms query](https://discuss.elastic.co/t/score-is-same-for-single-value-match-vs-multiple-match-for-an-array-field-using-terms-query/314976)

<div class="topic-metadata">

**Author:** [@Divit\_Sharma](https://discuss.elastic.co/u/Divit_Sharma)\
**Replies:** 3\
**Last updated:** [September 23, 2022, 11:42am UTC](https://discuss.elastic.co/t/score-is-same-for-single-value-match-vs-multiple-match-for-an-array-field-using-terms-query/314976 "2022-09-23T11:42:48Z")

</div>

PUT dvt\_test\_long/\_doc/1 { "items" : \[1\] } PUT dvt\_test\_long/\_doc/2 { "items" : \[1, 2\] } PUT dvt\_test\_long/\_doc/3 { "items" : \[1, 2, 3\] } PUT dvt\_test\_long/\_doc/4 { "items" : \[1, 2, 3, 4\] } Query: GET d…

---

## [Query on timeseries data very slow](https://discuss.elastic.co/t/query-on-timeseries-data-very-slow/314815)

<div class="topic-metadata">

**Author:** [@kk123](https://discuss.elastic.co/u/kk123)\
**Replies:** 6\
**Last updated:** [September 23, 2022, 9:37am UTC](https://discuss.elastic.co/t/query-on-timeseries-data-very-slow/314815 "2022-09-23T09:37:49Z")

</div>

Hi, this follows previous questions. I have merged all my indices into 1 ilm based index, with a added field that contains the previous "index" name... Generally this is fine, with some performance hit. Queries are gene…

---

## [Best approach to reuse an already existing ELK enviroment to monitor a new E-Commerce Env](https://discuss.elastic.co/t/best-approach-to-reuse-an-already-existing-elk-enviroment-to-monitor-a-new-e-commerce-env/315006)

<div class="topic-metadata">

**Author:** [@Carlos\_T](https://discuss.elastic.co/u/Carlos_T)\
**Replies:** 0\
**Last updated:** [September 23, 2022, 9:36am UTC](https://discuss.elastic.co/t/best-approach-to-reuse-an-already-existing-elk-enviroment-to-monitor-a-new-e-commerce-env/315006 "2022-09-23T09:36:20Z")

</div>

Good morning. I've been requested to use an already existing ELK environment that until now has been used to monitor a single E-Commerce App environment. The client is asking me now to reuse this ELK environment to mon…

---

## [SNMP Pipeline didn't work](https://discuss.elastic.co/t/snmp-pipeline-didnt-work/315003)

<div class="topic-metadata">

**Author:** [@yuswanul](https://discuss.elastic.co/u/yuswanul)\
**Replies:** 0\
**Last updated:** [September 23, 2022, 9:29am UTC](https://discuss.elastic.co/t/snmp-pipeline-didnt-work/315003 "2022-09-23T09:29:58Z")

</div>

Hello everyone, i'm struggling with snmp pipeline here. i have configured the pipeline like below picture. i used walk and define the tables too. when i run the logstash, there is no error log about this pipeline. it's …

---

## ["type"=\>"illegal\_argument\_exception", "reason"=\>"cannot parse empty date"} in logstash logs](https://discuss.elastic.co/t/type-illegal-argument-exception-reason-cannot-parse-empty-date-in-logstash-logs/314991)

<div class="topic-metadata">

**Author:** [@madurad](https://discuss.elastic.co/u/madurad)\
**Replies:** 2\
**Last updated:** [September 23, 2022, 7:36am UTC](https://discuss.elastic.co/t/type-illegal-argument-exception-reason-cannot-parse-empty-date-in-logstash-logs/314991 "2022-09-23T07:36:37Z")

</div>

Hello, Getting an error on pushing logs to logstash to elasticseacrch, "error"=\>{"type"=\>"mapper\_parsing\_exception", "reason"=\>"failed to parse field \[message\] of type \[date\] in document with id 'NVWQaIMBa0kW\_rfG7Lb1'…

---

## [Object mapping for \[data.value\] tried to parse field \[value\] as object, but found a concrete value](https://discuss.elastic.co/t/object-mapping-for-data-value-tried-to-parse-field-value-as-object-but-found-a-concrete-value/314867)

<div class="topic-metadata">

**Author:** [@shivendra95](https://discuss.elastic.co/u/shivendra95)\
**Replies:** 2\
**Last updated:** [September 23, 2022, 5:44am UTC](https://discuss.elastic.co/t/object-mapping-for-data-value-tried-to-parse-field-value-as-object-but-found-a-concrete-value/314867 "2022-09-23T05:44:03Z")

</div>

Hi, I'm trying to read log files from s3 bucket, but for some log lines I'm getting the below error \[WARN \] 2022-09-21 10:43:42.756 \[\[main\]\>worker0\] elasticsearch - Could not index event to Elasticsearch. {:status=\>4…

---

## [Elasticsearch::Transport::Transport::Errors::BadRequest](https://discuss.elastic.co/t/elasticsearch-badrequest/314860)

<div class="topic-metadata">

**Author:** [@Hunaid\_Nawaz](https://discuss.elastic.co/u/Hunaid_Nawaz)\
**Replies:** 1\
**Last updated:** [September 23, 2022, 3:27am UTC](https://discuss.elastic.co/t/elasticsearch-badrequest/314860 "2022-09-23T03:27:41Z")

</div>

Hi, I'm facing the error related to the Elasticsearch::Transport. I'm using searchkick gem in rails. elasticsearch version 7.17.4 When i'm doing reindex using searchkick gem it returned this error Elasticsearch::Tran…

---

## [Issue with output plugin type elasticsearch in logstash](https://discuss.elastic.co/t/issue-with-output-plugin-type-elasticsearch-in-logstash/314967)

<div class="topic-metadata">

**Author:** [@sbk-elk](https://discuss.elastic.co/u/sbk-elk)\
**Replies:** 4\
**Last updated:** [September 22, 2022, 8:39pm UTC](https://discuss.elastic.co/t/issue-with-output-plugin-type-elasticsearch-in-logstash/314967 "2022-09-22T20:39:39Z")

</div>

Hello All, Below is my logstash configuration. I have a few questions with respect to how i added the fields and how they carry over in the stages of my pipeline. Do the fields set in hash in my input plugin are added…

---

## [Is there anyway to use Logstash on Cloud?](https://discuss.elastic.co/t/is-there-anyway-to-use-logstash-on-cloud/314975)

<div class="topic-metadata">

**Author:** [@SamuelSMendes](https://discuss.elastic.co/u/SamuelSMendes)\
**Replies:** 1\
**Last updated:** [September 22, 2022, 9:37pm UTC](https://discuss.elastic.co/t/is-there-anyway-to-use-logstash-on-cloud/314975 "2022-09-22T21:37:02Z")

</div>

So far I'm aware of the Ingest Pipelines and they are really useful, but I've been using a lot of Logstash plugins (mostly JDBC and HTTP) plusm mutates in a daily basis and so I started wondering if there is also a solut…

---

## [Convert my doc.timestamp as date](https://discuss.elastic.co/t/convert-my-doc-timestamp-as-date/314973)

<div class="topic-metadata">

**Author:** [@erwin339](https://discuss.elastic.co/u/erwin339)\
**Replies:** 3\
**Last updated:** [September 22, 2022, 9:08pm UTC](https://discuss.elastic.co/t/convert-my-doc-timestamp-as-date/314973 "2022-09-22T21:08:07Z")

</div>

I am currently trying to get the date the logs were generated since I only have the date they were processed, I am receiving the logs in log4j xml format. I am unable to convert the UNIX date to this format Sep 22, 2022 …

---

## [Elasticsearch 7.10 durability permanent](https://discuss.elastic.co/t/elasticsearch-7-10-durability-permanent/314875)

<div class="topic-metadata">

**Author:** [@Michael\_Sanchez](https://discuss.elastic.co/u/Michael_Sanchez)\
**Replies:** 14\
**Last updated:** [September 22, 2022, 6:45pm UTC](https://discuss.elastic.co/t/elasticsearch-7-10-durability-permanent/314875 "2022-09-22T18:45:11Z")

</div>

Hello team, My Elasticsearch cluster v7.10 has the following error: reason" : "\[parent\] Data too large, data for \[\<http\_request\>\] would be \[17110531128/15.9gb\], which is larger than the limit of \[16320875724/15.1gb\], r…

---

## [\[ERROR\]\[elasticsearch-service\] Unable to retrieve version information from Elasticsearch nodes](https://discuss.elastic.co/t/error-elasticsearch-service-unable-to-retrieve-version-information-from-elasticsearch-nodes/306399)

<div class="topic-metadata">

**Author:** [@HKN\_MZ](https://discuss.elastic.co/u/HKN_MZ)\
**Replies:** 5\
**Last updated:** [September 22, 2022, 6:10pm UTC](https://discuss.elastic.co/t/error-elasticsearch-service-unable-to-retrieve-version-information-from-elasticsearch-nodes/306399 "2022-09-22T18:10:35Z")

</div>

Hi Everyone, I try to install Elasticsearch8.2.2 and Kibana8.2.2 on the one ubuntu20.04 virtual machine. I installed and configured Elasticsearch8.2.2 and get accessed from my local browser successfully. As below picture…

---

## [Search\_coordination thread queue filling up. Can we change the setting?](https://discuss.elastic.co/t/search-coordination-thread-queue-filling-up-can-we-change-the-setting/314813)

<div class="topic-metadata">

**Author:** [@elastic\_dude](https://discuss.elastic.co/u/elastic_dude)\
**Replies:** 6\
**Last updated:** [September 22, 2022, 4:38pm UTC](https://discuss.elastic.co/t/search-coordination-thread-queue-filling-up-can-we-change-the-setting/314813 "2022-09-22T16:38:35Z")

</div>

Hello, We are operating some Elasticsearch clusters and have noticed in the most queried cluster periodically the search\_coordination thread pool can't keep up, resulting in a queue that then translates to high latency …

---

## [New ECE Student](https://discuss.elastic.co/t/new-ece-student/314957)

<div class="topic-metadata">

**Author:** [@bertwaffles1](https://discuss.elastic.co/u/bertwaffles1)\
**Replies:** 1\
**Last updated:** [September 22, 2022, 4:22pm UTC](https://discuss.elastic.co/t/new-ece-student/314957 "2022-09-22T16:22:08Z")

</div>

I am going through the Elastic Certified Engineer course. The videos seem short and the pdf's while long really do not seem to go into details on several items. I do like the labs and I am on module 4 but I feel like I a…

---

## [Trying to upload a csv to an index fails](https://discuss.elastic.co/t/trying-to-upload-a-csv-to-an-index-fails/314954)

<div class="topic-metadata">

**Author:** [@alter1](https://discuss.elastic.co/u/alter1)\
**Replies:** 1\
**Last updated:** [September 22, 2022, 3:53pm UTC](https://discuss.elastic.co/t/trying-to-upload-a-csv-to-an-index-fails/314954 "2022-09-22T15:53:54Z")

</div>

I am trying to load a csv file to an index associated with ILM policies, the first time it was executed it was successful, then I have deleted and recreated the index and the load has not worked again. This is the pipel…

---

## [Dividing buckets values](https://discuss.elastic.co/t/dividing-buckets-values/314938)

<div class="topic-metadata">

**Author:** [@Aniket\_Pant](https://discuss.elastic.co/u/Aniket_Pant)\
**Replies:** 2\
**Last updated:** [September 22, 2022, 3:13pm UTC](https://discuss.elastic.co/t/dividing-buckets-values/314938 "2022-09-22T15:13:33Z")

</div>

Hi Community, Below is my query. It is performing count no. of response\_code and total no. of response\_code using filters aggregation. I want to divide response\_code by total no of response\_code For dividing i used bu…

---

## [Logstash filter for records of nested json messages from eventhub](https://discuss.elastic.co/t/logstash-filter-for-records-of-nested-json-messages-from-eventhub/314930)

<div class="topic-metadata">

**Author:** [@Sivaramakrishhna\_Amb](https://discuss.elastic.co/u/Sivaramakrishhna_Amb)\
**Replies:** 2\
**Last updated:** [September 22, 2022, 2:50pm UTC](https://discuss.elastic.co/t/logstash-filter-for-records-of-nested-json-messages-from-eventhub/314930 "2022-09-22T14:50:03Z")

</div>

Input message looks like below { "records": \[ { "level": "Informational", "properties": { "Keywords": 0, "ProviderName": "Core.LogRecord", "Message": "2022-09-08 08:17:02,935 \[23\] INFO {"Message":"9/8/2022 8:17:0…

---

## [Data Storage](https://discuss.elastic.co/t/data-storage/314846)

<div class="topic-metadata">

**Author:** [@ibtissem\_Ben\_lafi](https://discuss.elastic.co/u/ibtissem_Ben_lafi)\
**Replies:** 12\
**Last updated:** [September 22, 2022, 2:01pm UTC](https://discuss.elastic.co/t/data-storage/314846 "2022-09-22T14:01:19Z")

</div>

Hello eveyone, I have an issue: The size of the data is not the same in MySQL and Elasticsearch . What can I do for this problem? Someone help me, please

---

## [ECK Elasticsearch - Performing Full Restart of ES Nodes](https://discuss.elastic.co/t/eck-elasticsearch-performing-full-restart-of-es-nodes/312798)

<div class="topic-metadata">

**Author:** [@vasek](https://discuss.elastic.co/u/vasek)\
**Replies:** 8\
**Last updated:** [September 22, 2022, 1:25pm UTC](https://discuss.elastic.co/t/eck-elasticsearch-performing-full-restart-of-es-nodes/312798 "2022-09-22T13:25:08Z")

</div>

Hello hello, I would like to ask you whether is possible to perform full restart of ES nodes using ECK operator. Is it possible to do using this? updateStrategy: changeBudget: maxSurge: \<SOME VALUE\> …

---

## [Elasticsearch filter plugin for data enrichment](https://discuss.elastic.co/t/elasticsearch-filter-plugin-for-data-enrichment/314944)

<div class="topic-metadata">

**Author:** [@Hamza\_Khalid](https://discuss.elastic.co/u/Hamza_Khalid)\
**Replies:** 0\
**Last updated:** [September 22, 2022, 12:35pm UTC](https://discuss.elastic.co/t/elasticsearch-filter-plugin-for-data-enrichment/314944 "2022-09-22T12:35:27Z")

</div>

i have indexed 2 tables from mysql to elasticsearch: user\_index: { id : 1, name : user\_name, hobbies : 1,2 } hobbies\_index: { id : 1, name : hobby1 } id : 2, name : hobby2 } i want to enrich my document a…

---

## [Backup and Restore of the overall ECE (configuration)](https://discuss.elastic.co/t/backup-and-restore-of-the-overall-ece-configuration/314901)

<div class="topic-metadata">

**Author:** [@stobbe99](https://discuss.elastic.co/u/stobbe99)\
**Replies:** 3\
**Last updated:** [September 22, 2022, 10:46am UTC](https://discuss.elastic.co/t/backup-and-restore-of-the-overall-ece-configuration/314901 "2022-09-22T10:46:08Z")

</div>

Hello, Not found in the documentation, how to backup/restore the ECE environment. (think moving or migrating the full or part of an ECE) KR Henk

---

## [Elastic Search Not Reflecting Database Changes](https://discuss.elastic.co/t/elastic-search-not-reflecting-database-changes/314916)

<div class="topic-metadata">

**Author:** [@Binish\_Shams](https://discuss.elastic.co/u/Binish_Shams)\
**Replies:** 3\
**Last updated:** [September 22, 2022, 8:54am UTC](https://discuss.elastic.co/t/elastic-search-not-reflecting-database-changes/314916 "2022-09-22T08:54:12Z")

</div>

Hello we are using Elasticsearch version 7.16.2. We having synced our Elasticsearch with database using listeners. Usually the Elasticsearch reflects the database changes within no time but once it happened that it took …

---

## [Getting count using aggregation](https://discuss.elastic.co/t/getting-count-using-aggregation/314837)

<div class="topic-metadata">

**Author:** [@Aniket\_Pant](https://discuss.elastic.co/u/Aniket_Pant)\
**Replies:** 4\
**Last updated:** [September 22, 2022, 8:19am UTC](https://discuss.elastic.co/t/getting-count-using-aggregation/314837 "2022-09-22T08:19:59Z")

</div>

Hi Team, { "query": { "bool": { "filter": \[ { "bool": { "should":{ "range": { "@timestamp": { "gte": "now-15m" } } …

---

## [RDBMS Query transforms to Elasticsearch Query DSL](https://discuss.elastic.co/t/rdbms-query-transforms-to-elasticsearch-query-dsl/314907)

<div class="topic-metadata">

**Author:** [@Pranjal\_Sett](https://discuss.elastic.co/u/Pranjal_Sett)\
**Replies:** 1\
**Last updated:** [September 22, 2022, 7:26am UTC](https://discuss.elastic.co/t/rdbms-query-transforms-to-elasticsearch-query-dsl/314907 "2022-09-22T07:26:48Z")

</div>

Hi, I wanted to transform the RDBMS query into elasticsearch query DSL. So the RDBMS query is like below: sum(1) where \<art1\> = TODAY() and \<atr2\> = ’K’ and \<atr3\> \<\> 0 and \<atr4\> = 0 And I have transformed that abov…

---

## [How to use offset in DateHistogram.Builder from new java api client](https://discuss.elastic.co/t/how-to-use-offset-in-datehistogram-builder-from-new-java-api-client/314921)

<div class="topic-metadata">

**Author:** [@Raghunandan](https://discuss.elastic.co/u/Raghunandan)\
**Replies:** 0\
**Last updated:** [September 22, 2022, 7:25am UTC](https://discuss.elastic.co/t/how-to-use-offset-in-datehistogram-builder-from-new-java-api-client/314921 "2022-09-22T07:25:35Z")

</div>

in old implementation of DateHistogramAggregationBuilder we could pass offset as string, dateHistogramAggregationBuilder.offset(configurationManagementProxy.getStartDayOfWeek() - 1) + "d"); now it requires the offset v…

---

## [EQL rules are wrong, God help me](https://discuss.elastic.co/t/eql-rules-are-wrong-god-help-me/314606)

<div class="topic-metadata">

**Author:** [@zhixiang\_hao](https://discuss.elastic.co/u/zhixiang_hao)\
**Replies:** 6\
**Last updated:** [September 22, 2022, 2:19am UTC](https://discuss.elastic.co/t/eql-rules-are-wrong-god-help-me/314606 "2022-09-22T02:19:11Z")

</div>

sequence by process.entity\_id with maxspan = 30s \[process where event.type in ("start", "process\_started") and process.name:("powershell.exe", "pwsh.exe","cmd.exe","wmic.exe","excel.exe") and process.command\_line:("H…

---

## [Is it possible to format Logstash output in a way that it shows in Uptime?](https://discuss.elastic.co/t/is-it-possible-to-format-logstash-output-in-a-way-that-it-shows-in-uptime/314883)

<div class="topic-metadata">

**Author:** [@SamuelSMendes](https://discuss.elastic.co/u/SamuelSMendes)\
**Replies:** 3\
**Last updated:** [September 21, 2022, 8:50pm UTC](https://discuss.elastic.co/t/is-it-possible-to-format-logstash-output-in-a-way-that-it-shows-in-uptime/314883 "2022-09-21T20:50:25Z")

</div>

I was thinking if, by using mutate in the output of my pipeline on logstash in a way that "mimics" the heartbeat output, I could have an uptime application to see the return of my pseudo-heartbeat (generated by the logst…

---

## [Create custom transaction for jmeter transactions](https://discuss.elastic.co/t/create-custom-transaction-for-jmeter-transactions/314898)

<div class="topic-metadata">

**Author:** [@senyam08](https://discuss.elastic.co/u/senyam08)\
**Replies:** 0\
**Last updated:** [September 21, 2022, 8:16pm UTC](https://discuss.elastic.co/t/create-custom-transaction-for-jmeter-transactions/314898 "2022-09-21T20:16:24Z")

</div>

Trying to use elastic APM to track requests executed from jmeter load testing tool. Added trace method for http sampler by adding sampler.HTTPHC4Impl#sample. Works fine. Issue is elastic apm creating transaction with nam…

---

## [ElasticsearchStatusException\[Unable to parse response body\] \[HTTP/1.1 301 Moved Permanently\]](https://discuss.elastic.co/t/elasticsearchstatusexception-unable-to-parse-response-body-http-1-1-301-moved-permanently/314888)

<div class="topic-metadata">

**Author:** [@Jai\_Tripathi](https://discuss.elastic.co/u/Jai_Tripathi)\
**Replies:** 3\
**Last updated:** [September 21, 2022, 8:13pm UTC](https://discuss.elastic.co/t/elasticsearchstatusexception-unable-to-parse-response-body-http-1-1-301-moved-permanently/314888 "2022-09-21T20:13:59Z")

</div>

Hello Everyone, Key Points: I am able to get response from Elastic search (deployed on AWS) using postman at my machine. However when I am trying to use elasticsearch API to get the response, I am getting Elasticsearc…

[Previous page](https://discuss.elastic.co/tag/none.md?no_tags=true&page=531)

[Next page](https://discuss.elastic.co/tag/none.md?no_tags=true&page=533)
