# \#none

**URL:** https://discuss.elastic.co/tag/none.md?no_tags=true&page=593

[Latest](https://discuss.elastic.co/latest.md) · [Categories](https://discuss.elastic.co/categories.md) · [Tags](https://discuss.elastic.co/tags.md)

**Page:** 594

---

## [Shrink and split APIs](https://discuss.elastic.co/t/shrink-and-split-apis/308752)

<div class="topic-metadata">

**Author:** [@ewolfman](https://discuss.elastic.co/u/ewolfman)\
**Replies:** 4\
**Last updated:** [July 4, 2022, 9:42pm UTC](https://discuss.elastic.co/t/shrink-and-split-apis/308752 "2022-07-04T21:42:57Z")

</div>

Hi, I tried the shrink API on a 30GB index and shrinked from 15 shards to 5 shards. What I am not sure about is that this seemed to have happened instantaneously. I checked the \_cat/recovery endpoint and saw that ther…

---

## [Editing a managed policy can break Kibana](https://discuss.elastic.co/t/editing-a-managed-policy-can-break-kibana/308836)

<div class="topic-metadata">

**Author:** [@kmp](https://discuss.elastic.co/u/kmp)\
**Replies:** 0\
**Last updated:** [July 4, 2022, 9:12pm UTC](https://discuss.elastic.co/t/editing-a-managed-policy-can-break-kibana/308836 "2022-07-04T21:12:41Z")

</div>

Just upgraded a Cloud deployment to 8.3.1 ... I'm still working on tuning usage, to try to figure out how to ensure that we're using resources efficiently. I've been looking at storage usage, and using lifecycle polici…

---

## [Logstash MySQL pakcet too large exception](https://discuss.elastic.co/t/logstash-mysql-pakcet-too-large-exception/308541)

<div class="topic-metadata">

**Author:** [@Simone1](https://discuss.elastic.co/u/Simone1)\
**Replies:** 3\
**Last updated:** [July 4, 2022, 7:41pm UTC](https://discuss.elastic.co/t/logstash-mysql-pakcet-too-large-exception/308541 "2022-07-04T19:41:50Z")

</div>

I'm trying to retreive data from a remote MySQL Server through the 22 port and i receive this error: \[ERROR\] 2022-06-29 15:21:37.081 \[\[main\]\<jdbc\] jdbc - Unable to connect to database. Tried 0 times {:error\_message=\>"Ja…

---

## [Curl -X GET http://localhost:9200 returns Access Denied](https://discuss.elastic.co/t/curl-x-get-http-localhost-9200-returns-access-denied/308687)

<div class="topic-metadata">

**Author:** [@Alaa\_Omar](https://discuss.elastic.co/u/Alaa_Omar)\
**Replies:** 2\
**Last updated:** [July 4, 2022, 6:35pm UTC](https://discuss.elastic.co/t/curl-x-get-http-localhost-9200-returns-access-denied/308687 "2022-07-04T18:35:03Z")

</div>

am trying to install and setup Elasticsearch 8 on Centos 7 server, the service started but when I do curl -x GET HTTP://localhost:9200 , or curl -x GET HTTP://127.0.0.1:9200 or curl -x GET HTTP://(local IP of the host):9…

---

## [Get all spaces dev tools](https://discuss.elastic.co/t/get-all-spaces-dev-tools/308827)

<div class="topic-metadata">

**Author:** [@Gabriel\_Vasconcelos](https://discuss.elastic.co/u/Gabriel_Vasconcelos)\
**Replies:** 0\
**Last updated:** [July 4, 2022, 4:18pm UTC](https://discuss.elastic.co/t/get-all-spaces-dev-tools/308827 "2022-07-04T16:18:12Z")

</div>

Hello everyone, I would like to know how to return all my spaces through dev tools. The documentation says it would be GET api/spaces/apace, but when I use this path, it only returns the spaces I created with index api. …

---

## [Enrichment policy based on multiple fields / complex query?](https://discuss.elastic.co/t/enrichment-policy-based-on-multiple-fields-complex-query/308826)

<div class="topic-metadata">

**Author:** [@akb](https://discuss.elastic.co/u/akb)\
**Replies:** 0\
**Last updated:** [July 4, 2022, 4:09pm UTC](https://discuss.elastic.co/t/enrichment-policy-based-on-multiple-fields-complex-query/308826 "2022-07-04T16:09:58Z")

</div>

I am investigating a way to normalize / prettify geo data during ingestion. I realize there is a way to normalize by lat / lon, however we don't always have these properties availble. Master geo data: { "country": "…

---

## [Regarding grok Date Time](https://discuss.elastic.co/t/regarding-grok-date-time/308636)

<div class="topic-metadata">

**Author:** [@suresh\_u](https://discuss.elastic.co/u/suresh_u)\
**Replies:** 2\
**Last updated:** [July 4, 2022, 3:54pm UTC](https://discuss.elastic.co/t/regarding-grok-date-time/308636 "2022-07-04T15:54:30Z")

</div>

In my oracle DB, I have with timestamp like this: "createdDate" =\> 2022-04-02T17:00:44.339Z But in my elasticsearch index, having createdDate as "createdDate": "2022-04-02T17:00:44Z" How can we change the format in Log…

---

## [Average search latency increase 900% from 7.4 to 7.10](https://discuss.elastic.co/t/average-search-latency-increase-900-from-7-4-to-7-10/308760)

<div class="topic-metadata">

**Author:** [@fgarsombke](https://discuss.elastic.co/u/fgarsombke)\
**Replies:** 2\
**Last updated:** [July 4, 2022, 2:07pm UTC](https://discuss.elastic.co/t/average-search-latency-increase-900-from-7-4-to-7-10/308760 "2022-07-04T14:07:47Z")

</div>

We recently did an upgrade from 7.4 to 7.10 and have seen over a 900% increase in search latency. Before the upgrade our average search latency was about 0.5ms and after the upgrade our average search latency is now at …

---

## [Rally 2.6.0](https://discuss.elastic.co/t/rally-2-6-0/308819)

<div class="topic-metadata">

**Author:** [@Quentin\_Pradet](https://discuss.elastic.co/u/Quentin_Pradet)\
**Replies:** 0\
**Last updated:** [July 4, 2022, 2:06pm UTC](https://discuss.elastic.co/t/rally-2-6-0/308819 "2022-07-04T14:06:37Z")

</div>

Shortly after Rally 2.5.0, we have just released Rally 2.6.0. Highlights: Rally can now create and use unique ES API keys for each simulated client (#1520) Rally can now paginate through composite aggregations results …

---

## [Could not index event to Elasticsearch - no write index is defined for alias](https://discuss.elastic.co/t/could-not-index-event-to-elasticsearch-no-write-index-is-defined-for-alias/308783)

<div class="topic-metadata">

**Author:** [@teesr5](https://discuss.elastic.co/u/teesr5)\
**Replies:** 1\
**Last updated:** [July 4, 2022, 1:15pm UTC](https://discuss.elastic.co/t/could-not-index-event-to-elasticsearch-no-write-index-is-defined-for-alias/308783 "2022-07-04T13:15:31Z")

</div>

Hi guys, we are facing an issue on our ELK infrastructure: \[WARN \]\[logstash.outputs.elasticsearch\]\[main\] Could not index event to Elasticsearch. {:status=\>400, :action=\>\["index", {:\_id=\>nil, :\_index=\>"logstash-rollover…

---

## [Upgrade storage space for elasticsearch](https://discuss.elastic.co/t/upgrade-storage-space-for-elasticsearch/218630)

<div class="topic-metadata">

**Author:** [@atotheb](https://discuss.elastic.co/u/atotheb)\
**Replies:** 5\
**Last updated:** [July 4, 2022, 12:59pm UTC](https://discuss.elastic.co/t/upgrade-storage-space-for-elasticsearch/218630 "2022-07-04T12:59:49Z")

</div>

I try to increase the capacity of my persistant volume for elasticsearch. However this seems to be not so straightforward, as explained in this article: https://www.elastic.co/guide/en/cloud-on-k8s/current/k8s-orchestr…

---

## [How to set TimeStamp from java?](https://discuss.elastic.co/t/how-to-set-timestamp-from-java/308812)

<div class="topic-metadata">

**Author:** [@Enomine](https://discuss.elastic.co/u/Enomine)\
**Replies:** 1\
**Last updated:** [July 4, 2022, 12:01pm UTC](https://discuss.elastic.co/t/how-to-set-timestamp-from-java/308812 "2022-07-04T12:01:37Z")

</div>

Hi, i am using the elasticsearch-java-Client: \<dependency\> \<groupId\>co.elastic.clients\</groupId\> \<artifactId\>elasticsearch-java\</artifactId\> \<version\>8.2.0\</version\> \</dependency\> and connecte…

---

## [Hi I need to remove legends from vertical graphs in kibana plots how do i do that?](https://discuss.elastic.co/t/hi-i-need-to-remove-legends-from-vertical-graphs-in-kibana-plots-how-do-i-do-that/308799)

<div class="topic-metadata">

**Author:** [@damodar\_kv](https://discuss.elastic.co/u/damodar_kv)\
**Replies:** 1\
**Last updated:** [July 4, 2022, 10:58am UTC](https://discuss.elastic.co/t/hi-i-need-to-remove-legends-from-vertical-graphs-in-kibana-plots-how-do-i-do-that/308799 "2022-07-04T10:58:17Z")

</div>

Continuing the discussion from Can I hide legend from visualization?:

---

## [Migrating java application to Elasticsearch 8.x from ES 7.17.5](https://discuss.elastic.co/t/migrating-java-application-to-elasticsearch-8-x-from-es-7-17-5/308809)

<div class="topic-metadata">

**Author:** [@Swati\_Jain1](https://discuss.elastic.co/u/Swati_Jain1)\
**Replies:** 0\
**Last updated:** [July 4, 2022, 10:46am UTC](https://discuss.elastic.co/t/migrating-java-application-to-elasticsearch-8-x-from-es-7-17-5/308809 "2022-07-04T10:46:51Z")

</div>

We are using Elasticsearch 7.17.5 which is used by a Java 8 application. We are planning to upgrade to Elasticsearch 8.x. Since High-level Rest Client is now deprecated I am unable to resolve dependencies in order to us…

---

## [Unable to connect to Elastic-Search Server](https://discuss.elastic.co/t/unable-to-connect-to-elastic-search-server/308804)

<div class="topic-metadata">

**Author:** [@Shobhit\_Jain1](https://discuss.elastic.co/u/Shobhit_Jain1)\
**Replies:** 0\
**Last updated:** [July 4, 2022, 9:52am UTC](https://discuss.elastic.co/t/unable-to-connect-to-elastic-search-server/308804 "2022-07-04T09:52:38Z")

</div>

A few months back, I deployed the Elastic-Search(version - 8.0.1) on Kubernetes as a service as External load balancer using this guide. Now, I am unable to perform any read or write operation on ES. I checked the logs,…

---

## [Elasticsearch, Multiple Filebeat, Logstash](https://discuss.elastic.co/t/elasticsearch-multiple-filebeat-logstash/308791)

<div class="topic-metadata">

**Author:** [@balasani\_sri](https://discuss.elastic.co/u/balasani_sri)\
**Replies:** 0\
**Last updated:** [July 4, 2022, 8:24am UTC](https://discuss.elastic.co/t/elasticsearch-multiple-filebeat-logstash/308791 "2022-07-04T08:24:32Z")

</div>

Hello does anyone knows if is it possible to have multiple beats pointing to the same input port and then having single index output. Basically I need to identify which beat arrives and then how to find if any beat went …

---

## [Run aggregation on collapsed result](https://discuss.elastic.co/t/run-aggregation-on-collapsed-result/308171)

<div class="topic-metadata">

**Author:** [@Nowrin\_Hossain](https://discuss.elastic.co/u/Nowrin_Hossain)\
**Replies:** 8\
**Last updated:** [July 4, 2022, 8:08am UTC](https://discuss.elastic.co/t/run-aggregation-on-collapsed-result/308171 "2022-07-04T08:08:42Z")

</div>

Hello, I have an issue that, first I need to collapse data by a field after sorting by another field then I need to perform some complex aggregation on that output. How to do that ? can anyone help ?

---

## [Elasticsearch recovery tools](https://discuss.elastic.co/t/elasticsearch-recovery-tools/308739)

<div class="topic-metadata">

**Author:** [@pushshift](https://discuss.elastic.co/u/pushshift)\
**Replies:** 2\
**Last updated:** [July 4, 2022, 8:05am UTC](https://discuss.elastic.co/t/elasticsearch-recovery-tools/308739 "2022-07-04T08:05:16Z")

</div>

One issue that seem to be problematic (and reoccurring) is that there isn't much information in the error messages when things like "NODE\_LEFT" / "no\_valid\_shard\_copy" populate error messages when performing things like …

---

## [ES rolling upgrade from 6.3.2 to 6.8.22, ES plug-in version should be upgraded to 6.8.22?](https://discuss.elastic.co/t/es-rolling-upgrade-from-6-3-2-to-6-8-22-es-plug-in-version-should-be-upgraded-to-6-8-22/308325)

<div class="topic-metadata">

**Author:** [@qiuxb](https://discuss.elastic.co/u/qiuxb)\
**Replies:** 7\
**Last updated:** [July 4, 2022, 7:51am UTC](https://discuss.elastic.co/t/es-rolling-upgrade-from-6-3-2-to-6-8-22-es-plug-in-version-should-be-upgraded-to-6-8-22/308325 "2022-07-04T07:51:11Z")

</div>

In order to fix the log4j2 vulnerability, we plan to upgrade the ES version from 6.3.2 to 6.8.22, and 7.x to 7.16.2. When reading the rolling upgrade document, the rolling upgrade document for 7.16.2 mentioned that the p…

---

## [Metricbeat not show volume mount under dev filesystem](https://discuss.elastic.co/t/metricbeat-not-show-volume-mount-under-dev-filesystem/308380)

<div class="topic-metadata">

**Author:** [@Felipe\_Illanes](https://discuss.elastic.co/u/Felipe_Illanes)\
**Replies:** 1\
**Last updated:** [July 4, 2022, 7:00am UTC](https://discuss.elastic.co/t/metricbeat-not-show-volume-mount-under-dev-filesystem/308380 "2022-07-04T07:00:56Z")

</div>

Let me explain the problem. Im searching for a specific mount in a server (actually is a volume added), and when in terminal type df -aTh | grep "/dev" for show filesystem, its show this image: Then in metricbeat.yam…

---

## [Drop of some of the Prometheus based metrics at metric beat end](https://discuss.elastic.co/t/drop-of-some-of-the-prometheus-based-metrics-at-metric-beat-end/306846)

<div class="topic-metadata">

**Author:** [@Sagar\_Parmar](https://discuss.elastic.co/u/Sagar_Parmar)\
**Replies:** 1\
**Last updated:** [July 4, 2022, 6:51am UTC](https://discuss.elastic.co/t/drop-of-some-of-the-prometheus-based-metrics-at-metric-beat-end/306846 "2022-07-04T06:51:29Z")

</div>

Hi Team, I followed your document to get prometheus metrics in elasticsearch using metricbeat. But metricbeat is not showing all metrics on kibana dashboard. Below is Prometheus metrics On a metricbeat side It is …

---

## [Help with "\_grokparsefailure" and "\_geoip\_lookup\_failure"](https://discuss.elastic.co/t/help-with-grokparsefailure-and-geoip-lookup-failure/308702)

<div class="topic-metadata">

**Author:** [@roman-tasi](https://discuss.elastic.co/u/roman-tasi)\
**Replies:** 5\
**Last updated:** [July 4, 2022, 3:22am UTC](https://discuss.elastic.co/t/help-with-grokparsefailure-and-geoip-lookup-failure/308702 "2022-07-04T03:22:31Z")

</div>

I am getting those error tags. Here is my filter section from my logstash section (Note that I started to get the \_grokparsefailure after adding the second grok with the src match, it was working fine with just the top g…

---

## [Index From Excel (Workplace?)](https://discuss.elastic.co/t/index-from-excel-workplace/308618)

<div class="topic-metadata">

**Author:** [@Cal](https://discuss.elastic.co/u/Cal)\
**Replies:** 3\
**Last updated:** [July 3, 2022, 11:18pm UTC](https://discuss.elastic.co/t/index-from-excel-workplace/308618 "2022-07-03T23:18:32Z")

</div>

My team and I have an Excel database that constantly has new entries we need to put in. We want to avoid removing and reuploading the CSV file (replacing the index) each day we make an update. We are wondering if there…

---

## [CVE's in Elasticsearch](https://discuss.elastic.co/t/cves-in-elasticsearch/308669)

<div class="topic-metadata">

**Author:** [@6igwig](https://discuss.elastic.co/u/6igwig)\
**Replies:** 1\
**Last updated:** [July 3, 2022, 11:12pm UTC](https://discuss.elastic.co/t/cves-in-elasticsearch/308669 "2022-07-03T23:12:04Z")

</div>

Are there any prebuilt data pipelines / APIs for getting CVE's into elasticsearch? I would like to have a watcher alert me when CVE's of a certain priority are released, and enrich the alert with data from my cluster. Is…

---

## [Does auto reload cause Logstash to restart ingestion from beginning](https://discuss.elastic.co/t/does-auto-reload-cause-logstash-to-restart-ingestion-from-beginning/308756)

<div class="topic-metadata">

**Author:** [@kossde](https://discuss.elastic.co/u/kossde)\
**Replies:** 1\
**Last updated:** [July 3, 2022, 6:19pm UTC](https://discuss.elastic.co/t/does-auto-reload-cause-logstash-to-restart-ingestion-from-beginning/308756 "2022-07-03T18:19:33Z")

</div>

I am using the Elasticsearch input plugin to move a very large number of logs from one cluster to another. Logstash has been running for about 72 hours now and is pretty sluggish. I was thinking of adding a 2nd Elasti…

---

## ["Your settings are invalid. Setting "" doesnt exist" error during setup](https://discuss.elastic.co/t/your-settings-are-invalid-setting-doesnt-exist-error-during-setup/308751)

<div class="topic-metadata">

**Author:** [@dsilvera](https://discuss.elastic.co/u/dsilvera)\
**Replies:** 2\
**Last updated:** [July 3, 2022, 6:04pm UTC](https://discuss.elastic.co/t/your-settings-are-invalid-setting-doesnt-exist-error-during-setup/308751 "2022-07-03T18:04:00Z")

</div>

Setting up ELK 8.3.1 on Windows 10 PC and got Elastic Search and Kabana up and running. Reached to setting up logstash, entered the following command: .\\bin\\logstash.bat -e "input { stdin { } } output { stdout {} }" f…

---

## [Kibana - Per-date function](https://discuss.elastic.co/t/kibana-per-date-function/308598)

<div class="topic-metadata">

**Author:** [@RonGros](https://discuss.elastic.co/u/RonGros)\
**Replies:** 5\
**Last updated:** [July 3, 2022, 3:15pm UTC](https://discuss.elastic.co/t/kibana-per-date-function/308598 "2022-07-03T15:15:47Z")

</div>

Hi, I have an interesting situation and I would like to know if there is anything I can do about it. We are trying to build a dashboard that will visualize our open issues in our issue-handling system (JIRA etc...) Now…

---

## [Elasticsearch exception \[type=search\_phase\_execution\_exception, reason=all shards failed\]](https://discuss.elastic.co/t/elasticsearch-exception-type-search-phase-execution-exception-reason-all-shards-failed/308737)

<div class="topic-metadata">

**Author:** [@Pamal\_Jayawickrama](https://discuss.elastic.co/u/Pamal_Jayawickrama)\
**Replies:** 1\
**Last updated:** [July 3, 2022, 2:36pm UTC](https://discuss.elastic.co/t/elasticsearch-exception-type-search-phase-execution-exception-reason-all-shards-failed/308737 "2022-07-03T14:36:16Z")

</div>

when I searching this query using simpleQueryStringQuery, GET books/\_search { "query":{ "bool":{ "must":\[ {"bool":{ "should":\[{ "wildcard":{"vault-bpa-ui-url":{"wildcard":"http\*…

---

## [How can I use aggregation value in trigger condition](https://discuss.elastic.co/t/how-can-i-use-aggregation-value-in-trigger-condition/308743)

<div class="topic-metadata">

**Author:** [@puks\_apple](https://discuss.elastic.co/u/puks_apple)\
**Replies:** 0\
**Last updated:** [July 3, 2022, 10:43am UTC](https://discuss.elastic.co/t/how-can-i-use-aggregation-value-in-trigger-condition/308743 "2022-07-03T10:43:09Z")

</div>

{ "\_shards": { "total": 1, "failed": 0, "successful": 1, "skipped": 0 }, "hits": { "hits": \[\], "total": { "value": 7, "relation": "eq…

---

## [Logstash XML xpath function like PHP $father-\>children()](https://discuss.elastic.co/t/logstash-xml-xpath-function-like-php-father-children/308719)

<div class="topic-metadata">

**Author:** [@Samuele\_Lolli](https://discuss.elastic.co/u/Samuele_Lolli)\
**Replies:** 3\
**Last updated:** [July 3, 2022, 7:28am UTC](https://discuss.elastic.co/t/logstash-xml-xpath-function-like-php-father-children/308719 "2022-07-03T07:28:08Z")

</div>

I'm searching if in logstash exist a xpath function like the one in PHP to get the child of a node without knowing the name. Thanks to everyone

[Previous page](https://discuss.elastic.co/tag/none.md?no_tags=true&page=592)

[Next page](https://discuss.elastic.co/tag/none.md?no_tags=true&page=594)
