# \#none

**URL:** https://discuss.elastic.co/tag/none.md?no_tags=true&page=548

[Latest](https://discuss.elastic.co/latest.md) · [Categories](https://discuss.elastic.co/categories.md) · [Tags](https://discuss.elastic.co/tags.md)

**Page:** 549

---

## [Should I merge my many indices into 1 and use ILM?](https://discuss.elastic.co/t/should-i-merge-my-many-indices-into-1-and-use-ilm/313421)

<div class="topic-metadata">

**Author:** [@kk123](https://discuss.elastic.co/u/kk123)\
**Replies:** 2\
**Last updated:** [September 1, 2022, 11:18am UTC](https://discuss.elastic.co/t/should-i-merge-my-many-indices-into-1-and-use-ilm/313421 "2022-09-01T11:18:18Z")

</div>

Hi, this question follows on from previous issues I've had Shards per node, Heap, 100% CPU....help please I have since updated to 7.15 and have reduced the number of shard per index to 2 (from 5) with 1 replica. The clu…

---

## [Template priority explanation](https://discuss.elastic.co/t/template-priority-explanation/311443)

<div class="topic-metadata">

**Author:** [@pestevao](https://discuss.elastic.co/u/pestevao)\
**Replies:** 3\
**Last updated:** [September 1, 2022, 11:11am UTC](https://discuss.elastic.co/t/template-priority-explanation/311443 "2022-09-01T11:11:10Z")

</div>

Hi all, I'm trying to change the number\_of\_replicas of some indexes, applying a loosely index\_patterns but... I'm struggling with priority. If I make a change on number\_of\_replicas and define a priority 1 on my new tem…

---

## [APM Event Logger does not read Flask parameters](https://discuss.elastic.co/t/apm-event-logger-does-not-read-flask-parameters/313433)

<div class="topic-metadata">

**Author:** [@papers\_hive](https://discuss.elastic.co/u/papers_hive)\
**Replies:** 0\
**Last updated:** [September 1, 2022, 10:49am UTC](https://discuss.elastic.co/t/apm-event-logger-does-not-read-flask-parameters/313433 "2022-09-01T10:49:07Z")

</div>

I am running a flask application with apm as an agent. I have configured my app as the following initially: app = Flask(\_\_name\_\_) APM\_DICTIONARY = { 'SERVICE\_NAME': 'MY\_SERVICE\_NAME' , 'SERVER\_U…

---

## [Logstash Error : S3 input plugins](https://discuss.elastic.co/t/logstash-error-s3-input-plugins/313432)

<div class="topic-metadata">

**Author:** [@priyankamondalhcl](https://discuss.elastic.co/u/priyankamondalhcl)\
**Replies:** 0\
**Last updated:** [September 1, 2022, 10:48am UTC](https://discuss.elastic.co/t/logstash-error-s3-input-plugins/313432 "2022-09-01T10:48:40Z")

</div>

Hi Team, I am using us3 input plugins which was connecting with S3 bucket and provided data to elasticsearch. but suddenly, It stopped working. My configuration input { s3 { "access\_key\_id" =\> "" "secret\_access\_key…

---

## [Failed to create query: Score function should not be null](https://discuss.elastic.co/t/failed-to-create-query-score-function-should-not-be-null/313268)

<div class="topic-metadata">

**Author:** [@Sarit\_Ghosh](https://discuss.elastic.co/u/Sarit_Ghosh)\
**Replies:** 1\
**Last updated:** [September 1, 2022, 9:09am UTC](https://discuss.elastic.co/t/failed-to-create-query-score-function-should-not-be-null/313268 "2022-09-01T09:09:59Z")

</div>

We are trying to move from ES 6.8 to ES 7.17. On an ES query we are getting the following error (the same query was working fine in ES 6.8): When I try Kibana also, I get the same error: "root\_cause": \[ { "type": "qu…

---

## [Autodetect\_column\_name with 2 different CSV](https://discuss.elastic.co/t/autodetect-column-name-with-2-different-csv/313310)

<div class="topic-metadata">

**Author:** [@EliottB](https://discuss.elastic.co/u/EliottB)\
**Replies:** 4\
**Last updated:** [September 1, 2022, 8:37am UTC](https://discuss.elastic.co/t/autodetect-column-name-with-2-different-csv/313310 "2022-09-01T08:37:16Z")

</div>

Hello all, I have an issue with the autodetect\_column\_name of my pipeline below: filter { csv { separator =\>"," autodetect\_column\_names =\> true } When I process the first CSV message country,city,name…

---

## [Bug: Drilldowns do not take over values from Controls](https://discuss.elastic.co/t/bug-drilldowns-do-not-take-over-values-from-controls/313349)

<div class="topic-metadata">

**Author:** [@Martin\_Braendle](https://discuss.elastic.co/u/Martin_Braendle)\
**Replies:** 2\
**Last updated:** [September 1, 2022, 8:10am UTC](https://discuss.elastic.co/t/bug-drilldowns-do-not-take-over-values-from-controls/313349 "2022-09-01T08:10:18Z")

</div>

Elasticsearch / Kibana 8.3.3 I've replaced the Input Control Visualisations (that were outlined as deprecated) with the new controls. However, a drilldown does not take over the values that have been set by a control,…

---

## [Elasticsearch error after upgrade "can not run elasticsearch as root"](https://discuss.elastic.co/t/elasticsearch-error-after-upgrade-can-not-run-elasticsearch-as-root/312632)

<div class="topic-metadata">

**Author:** [@mangeshmj1992](https://discuss.elastic.co/u/mangeshmj1992)\
**Replies:** 3\
**Last updated:** [September 1, 2022, 7:48am UTC](https://discuss.elastic.co/t/elasticsearch-error-after-upgrade-can-not-run-elasticsearch-as-root/312632 "2022-09-01T07:48:43Z")

</div>

Hello team, I have update my elasticsearch data node from 7,16,3 to 7.17.5. But it is through below error. Can you please help on same.. All files running as root.elasticsearch \[2022-08-22T18:26:40,213\]\[ERROR\]\[o.e.b…

---

## [Multiple Nested JSON Formats parsing with Logstash](https://discuss.elastic.co/t/multiple-nested-json-formats-parsing-with-logstash/313414)

<div class="topic-metadata">

**Author:** [@Prateek\_Kumar\_Saini](https://discuss.elastic.co/u/Prateek_Kumar_Saini)\
**Replies:** 0\
**Last updated:** [September 1, 2022, 6:59am UTC](https://discuss.elastic.co/t/multiple-nested-json-formats-parsing-with-logstash/313414 "2022-09-01T06:59:14Z")

</div>

Hello everyone, I am trying to ingest multiple logs into my logstash. The input type is a JSON (Nested Jsons), but the formats are varying. For example, JSON 1) 1|2|3|4|{"event-ts":"07-07-2022 17:42:55.294","event-na…

---

## [Preloading all documents to filesystem cache](https://discuss.elastic.co/t/preloading-all-documents-to-filesystem-cache/313381)

<div class="topic-metadata">

**Author:** [@9guar1](https://discuss.elastic.co/u/9guar1)\
**Replies:** 2\
**Last updated:** [September 1, 2022, 6:51am UTC](https://discuss.elastic.co/t/preloading-all-documents-to-filesystem-cache/313381 "2022-09-01T06:51:12Z")

</div>

Hi community, Is there any possibility to preload all documents to the filesystem cache using 'index.store.preload' to increase search perfomance of the fetch phase? Search query is below: POST /structure/\_search?type…

---

## [Fetch values from excel sheet in Logstash](https://discuss.elastic.co/t/fetch-values-from-excel-sheet-in-logstash/313406)

<div class="topic-metadata">

**Author:** [@ImranArif](https://discuss.elastic.co/u/ImranArif)\
**Replies:** 0\
**Last updated:** [September 1, 2022, 3:46am UTC](https://discuss.elastic.co/t/fetch-values-from-excel-sheet-in-logstash/313406 "2022-09-01T03:46:05Z")

</div>

Hi all, I am parsing CDN logs, which contains a web url that serves images to users, and push these logs to Elasticsearch using Logstash. I want to add a field 'site region' in the logs which contains the region that we…

---

## [Parse Nested Airflow Logs with Logstash](https://discuss.elastic.co/t/parse-nested-airflow-logs-with-logstash/313401)

<div class="topic-metadata">

**Author:** [@Chma](https://discuss.elastic.co/u/Chma)\
**Replies:** 0\
**Last updated:** [August 31, 2022, 10:58pm UTC](https://discuss.elastic.co/t/parse-nested-airflow-logs-with-logstash/313401 "2022-08-31T22:58:08Z")

</div>

I am new to Logstash and ELK as a whole. I am trying to send my airflow logs to Logstash. I am confused on how to configure my configuration file, especially because I have several (nested) log files. My airflow is depl…

---

## [Can I push logs to logstash via an API endpoint?](https://discuss.elastic.co/t/can-i-push-logs-to-logstash-via-an-api-endpoint/313399)

<div class="topic-metadata">

**Author:** [@clarkmcc](https://discuss.elastic.co/u/clarkmcc)\
**Replies:** 1\
**Last updated:** [August 31, 2022, 10:43pm UTC](https://discuss.elastic.co/t/can-i-push-logs-to-logstash-via-an-api-endpoint/313399 "2022-08-31T22:43:33Z")

</div>

We have ~30 services that run on customer-premise (not our premise) and we'd like to push logs from our service on their machine to an Elasticsearch instance for debugging and analysis. We'd like to avoid having to insta…

---

## [Azure Resource Metrics Integration. elastic\_agent.metricbeat\]\[warn\] Charges amounted](https://discuss.elastic.co/t/azure-resource-metrics-integration-elastic-agent-metricbeat-warn-charges-amounted/311790)

<div class="topic-metadata">

**Author:** [@vithal\_wadje](https://discuss.elastic.co/u/vithal_wadje)\
**Replies:** 1\
**Last updated:** [August 31, 2022, 10:31pm UTC](https://discuss.elastic.co/t/azure-resource-metrics-integration-elastic-agent-metricbeat-warn-charges-amounted/311790 "2022-08-31T22:31:13Z")

</div>

We are retrieving the Azure resource metrics data to the elastic cloud, but in the log I see some messages. \[elastic\_agent.metricbeat\]\[warn\] Charges amounted to 27 are being applied while retrieving the metric values fro…

---

## [Azure Service Bus, Event hub, event grid metrics not collected](https://discuss.elastic.co/t/azure-service-bus-event-hub-event-grid-metrics-not-collected/311836)

<div class="topic-metadata">

**Author:** [@vithal\_wadje](https://discuss.elastic.co/u/vithal_wadje)\
**Replies:** 1\
**Last updated:** [August 31, 2022, 10:04pm UTC](https://discuss.elastic.co/t/azure-service-bus-event-hub-event-grid-metrics-not-collected/311836 "2022-08-31T22:04:00Z")

</div>

Hi , We are using the Azure Resource Metrics collector integration and we were expecting to get the integration services metrics such as service bus, event hub, and event grid, but it seems it is not collecting. Are se…

---

## [Empty array getting dropped from output, how do I keep it?](https://discuss.elastic.co/t/empty-array-getting-dropped-from-output-how-do-i-keep-it/313392)

<div class="topic-metadata">

**Author:** [@Ben-G](https://discuss.elastic.co/u/Ben-G)\
**Replies:** 2\
**Last updated:** [August 31, 2022, 10:02pm UTC](https://discuss.elastic.co/t/empty-array-getting-dropped-from-output-how-do-i-keep-it/313392 "2022-08-31T22:02:12Z")

</div>

The input to my logstash is is populating \[Current\]\[Alarms\] from the input ...\\"Alarms\\":null... when there are no alarms, and when there are alarms then it is a list. When there are no alarms, I still want to see "Ala…

---

## [Strigo Lab Credentials](https://discuss.elastic.co/t/strigo-lab-credentials/313351)

<div class="topic-metadata">

**Author:** [@rossg](https://discuss.elastic.co/u/rossg)\
**Replies:** 0\
**Last updated:** [August 31, 2022, 11:27am UTC](https://discuss.elastic.co/t/strigo-lab-credentials/313351 "2022-08-31T11:27:13Z")

</div>

Hello, I am unable to log into the mysql db with username elastic for the labs, the provided password does not seem to work.

---

## [Get the latest index of a certain form in elasticsearch](https://discuss.elastic.co/t/get-the-latest-index-of-a-certain-form-in-elasticsearch/313379)

<div class="topic-metadata">

**Author:** [@kosmylo](https://discuss.elastic.co/u/kosmylo)\
**Replies:** 1\
**Last updated:** [August 31, 2022, 9:22pm UTC](https://discuss.elastic.co/t/get-the-latest-index-of-a-certain-form-in-elasticsearch/313379 "2022-08-31T21:22:15Z")

</div>

I am periodically training an anomaly detection model and I am saving it in elasticsearch index of the form 'anomaly\_detection\_model-' + date\_model\_trained. This means that I am ending up with indices of the form: anomal…

---

## [The new version of the official documentation is too bad to use！](https://discuss.elastic.co/t/the-new-version-of-the-official-documentation-is-too-bad-to-use/313312)

<div class="topic-metadata">

**Author:** [@laoyang360](https://discuss.elastic.co/u/laoyang360)\
**Replies:** 6\
**Last updated:** [August 31, 2022, 5:31pm UTC](https://discuss.elastic.co/t/the-new-version-of-the-official-documentation-is-too-bad-to-use/313312 "2022-08-31T17:31:04Z")

</div>

After the revision of the official Elasticstack documentation, the new drop-down menu bar has become extremely difficult to use. I would like to ask if it is possible to go back to the previous version which is easy to …

---

## [Best way to implement a daily based time series, where current day data is being refreshed](https://discuss.elastic.co/t/best-way-to-implement-a-daily-based-time-series-where-current-day-data-is-being-refreshed/313377)

<div class="topic-metadata">

**Author:** [@dashiad](https://discuss.elastic.co/u/dashiad)\
**Replies:** 0\
**Last updated:** [August 31, 2022, 4:11pm UTC](https://discuss.elastic.co/t/best-way-to-implement-a-daily-based-time-series-where-current-day-data-is-being-refreshed/313377 "2022-08-31T16:11:00Z")

</div>

We're trying to find which would be the best way to handle this case: We are storing daily data from a remote source. This remote source updates the data several times per day, so we'd need to refresh the index too, for…

---

## [Kibana Generate CSV - Could Not Load Plugin](https://discuss.elastic.co/t/kibana-generate-csv-could-not-load-plugin/313298)

<div class="topic-metadata">

**Author:** [@JulieB](https://discuss.elastic.co/u/JulieB)\
**Replies:** 3\
**Last updated:** [August 31, 2022, 3:44pm UTC](https://discuss.elastic.co/t/kibana-generate-csv-could-not-load-plugin/313298 "2022-08-31T15:44:54Z")

</div>

Hi there, I am trying to export some data using Share \> CSV Reports \> Generate CSV feature (see picture). Once the file is ready to download, a new tab would normally open and trigger the download of the CSV file. Howeve…

---

## [How to create users for file based auth and deploy using Helm Chart](https://discuss.elastic.co/t/how-to-create-users-for-file-based-auth-and-deploy-using-helm-chart/313374)

<div class="topic-metadata">

**Author:** [@Rohit\_Shrivastava](https://discuss.elastic.co/u/Rohit_Shrivastava)\
**Replies:** 0\
**Last updated:** [August 31, 2022, 3:38pm UTC](https://discuss.elastic.co/t/how-to-create-users-for-file-based-auth-and-deploy-using-helm-chart/313374 "2022-08-31T15:38:24Z")

</div>

Hi I wanted to know how should I automate the users file creation (file based authentication) with helm chart. Docs suggests to use elasticsearch-users cli, should I run an init container and run the script? Should I g…

---

## [Large number of entries in \`host.ip\` of almost all logs from Elastic Agent](https://discuss.elastic.co/t/large-number-of-entries-in-host-ip-of-almost-all-logs-from-elastic-agent/313359)

<div class="topic-metadata">

**Author:** [@woodywoodsta](https://discuss.elastic.co/u/woodywoodsta)\
**Replies:** 0\
**Last updated:** [August 31, 2022, 12:39pm UTC](https://discuss.elastic.co/t/large-number-of-entries-in-host-ip-of-almost-all-logs-from-elastic-agent/313359 "2022-08-31T12:39:30Z")

</div>

I have an ECK managed Elastic Agent shipping logs to ES. In logs and metrics documents, the host.ip field has a large list of duplicate IPV6 addresses. An example: \[\<Redacted actual IP addresses (which are correct)\>, …

---

## [Keyword field type keep getting Mapped as a Multifield](https://discuss.elastic.co/t/keyword-field-type-keep-getting-mapped-as-a-multifield/313267)

<div class="topic-metadata">

**Author:** [@xef](https://discuss.elastic.co/u/xef)\
**Replies:** 2\
**Last updated:** [August 31, 2022, 2:47pm UTC](https://discuss.elastic.co/t/keyword-field-type-keep-getting-mapped-as-a-multifield/313267 "2022-08-31T14:47:51Z")

</div>

Hi We are tryoing to create an index with a field of type Keyowrd, but elasticsearch keeps creating a mapping for a multifield even though we have specified the field as a keyowrd. i..e 2 fields one with field and one w…

---

## [Disable geoip](https://discuss.elastic.co/t/disable-geoip/313366)

<div class="topic-metadata">

**Author:** [@Jonas\_S](https://discuss.elastic.co/u/Jonas_S)\
**Replies:** 1\
**Last updated:** [August 31, 2022, 2:40pm UTC](https://discuss.elastic.co/t/disable-geoip/313366 "2022-08-31T14:40:51Z")

</div>

Hello, i have a logstash pipeline creating elasticsearch indices. Everytime a new index is created, geoip fields are already in the mappings. I do not use them and they never get filled with data. How do i stop them fro…

---

## [XML or Json into elasticasearch](https://discuss.elastic.co/t/xml-or-json-into-elasticasearch/311931)

<div class="topic-metadata">

**Author:** [@kim\_frederiksen](https://discuss.elastic.co/u/kim_frederiksen)\
**Replies:** 3\
**Last updated:** [August 31, 2022, 2:01pm UTC](https://discuss.elastic.co/t/xml-or-json-into-elasticasearch/311931 "2022-08-31T14:01:39Z")

</div>

Hi everybody, I think we are doing something wrong here and I really need your help because we are stuck. We have several systems where we pass documents(xml/json) through. We want pass these document on to ELK so we c…

---

## [=\>"Expected one of \[ \\\\t\\\\r\\\\n\], \\"#\\", \\"{\\", \\"}\\"](https://discuss.elastic.co/t/expected-one-of-t-r-n/313258)

<div class="topic-metadata">

**Author:** [@syedabdullah](https://discuss.elastic.co/u/syedabdullah)\
**Replies:** 2\
**Last updated:** [August 31, 2022, 1:59pm UTC](https://discuss.elastic.co/t/expected-one-of-t-r-n/313258 "2022-08-31T13:59:17Z")

</div>

I am getting the following error and is resulting in a ingestion issue and cant seem to figure this out: \[2022-08-29T14:23:39,615\]\[ERROR\]\[logstash.agent \] Failed to execute action {:action=\>LogStash::PipelineA…

---

## [Highlighting not working after upgrade](https://discuss.elastic.co/t/highlighting-not-working-after-upgrade/312095)

<div class="topic-metadata">

**Author:** [@henke71](https://discuss.elastic.co/u/henke71)\
**Replies:** 1\
**Last updated:** [August 31, 2022, 1:17pm UTC](https://discuss.elastic.co/t/highlighting-not-working-after-upgrade/312095 "2022-08-31T13:17:35Z")

</div>

Highlighting has stopped working after upgrade from 7.16 to 8.3.3 This is when using must\_not. Steps to reproduce Create index PUT /test { "mappings": { "properties": { "Name": { "type": "text" }, "…

---

## [Field \[content\] not present as part of path \[content\] when update\_by\_query](https://discuss.elastic.co/t/field-content-not-present-as-part-of-path-content-when-update-by-query/313336)

<div class="topic-metadata">

**Author:** [@sherry\_cs](https://discuss.elastic.co/u/sherry_cs)\
**Replies:** 0\
**Last updated:** [August 31, 2022, 9:01am UTC](https://discuss.elastic.co/t/field-content-not-present-as-part-of-path-content-when-update-by-query/313336 "2022-08-31T09:01:00Z")

</div>

Hi, guys. I created an index with a pipeline which extracted field from the file attachments. It works well except the partial update. I tried the request : POST test\_know/\_update/G3LH2oIBXGHwpDNidXe9 { "doc": { …

---

## [Query\_string search on Date type returns incorrect results](https://discuss.elastic.co/t/query-string-search-on-date-type-returns-incorrect-results/313204)

<div class="topic-metadata">

**Author:** [@Miguel\_Rios](https://discuss.elastic.co/u/Miguel_Rios)\
**Replies:** 3\
**Last updated:** [August 31, 2022, 1:12pm UTC](https://discuss.elastic.co/t/query-string-search-on-date-type-returns-incorrect-results/313204 "2022-08-31T13:12:20Z")

</div>

We made a pretty big leap recently in elasticsearch versions and one issue we've run into is that when using query\_string's on Date fields we get items which are outside the range of the deadline date. I have the follow…

[Previous page](https://discuss.elastic.co/tag/none.md?no_tags=true&page=547)

[Next page](https://discuss.elastic.co/tag/none.md?no_tags=true&page=549)
