# \#none

**URL:** https://discuss.elastic.co/tag/none.md?no_tags=true&page=603

[Latest](https://discuss.elastic.co/latest.md) · [Categories](https://discuss.elastic.co/categories.md) · [Tags](https://discuss.elastic.co/tags.md)

**Page:** 604

---

## [ElasticSearch as primary DB for document library](https://discuss.elastic.co/t/elasticsearch-as-primary-db-for-document-library/307852)

<div class="topic-metadata">

**Author:** [@Gresmir](https://discuss.elastic.co/u/Gresmir)\
**Replies:** 2\
**Last updated:** [June 22, 2022, 12:05pm UTC](https://discuss.elastic.co/t/elasticsearch-as-primary-db-for-document-library/307852 "2022-06-22T12:05:47Z")

</div>

My task is a full-text search system for a really large amount of documents (tens of millions). Now I have documents as RTF file and their metadata, so all this will be indexed in Elasticsearch. These documents are uncha…

---

## [The CPU load increases, the CPU utilization decreases, and the Version Map continues to decrease for 30 hours](https://discuss.elastic.co/t/the-cpu-load-increases-the-cpu-utilization-decreases-and-the-version-map-continues-to-decrease-for-30-hours/307618)

<div class="topic-metadata">

**Author:** [@yanha186036](https://discuss.elastic.co/u/yanha186036)\
**Replies:** 1\
**Last updated:** [June 22, 2022, 12:03pm UTC](https://discuss.elastic.co/t/the-cpu-load-increases-the-cpu-utilization-decreases-and-the-version-map-continues-to-decrease-for-30-hours/307618 "2022-06-22T12:03:57Z")

</div>

question1：Why are indicators suddenly like this？ java code ex：Exception message failed to refresh index: user\_rank\_total question2：Why is the sharding uneven? node3 is not sharded

---

## [Increase row count in search table in kibana dashboard](https://discuss.elastic.co/t/increase-row-count-in-search-table-in-kibana-dashboard/307864)

<div class="topic-metadata">

**Author:** [@mangeshs](https://discuss.elastic.co/u/mangeshs)\
**Replies:** 3\
**Last updated:** [June 22, 2022, 12:02pm UTC](https://discuss.elastic.co/t/increase-row-count-in-search-table-in-kibana-dashboard/307864 "2022-06-22T12:02:16Z")

</div>

I have added discover search results in dashboard and changed row count limit to 500 default but it is not reflecting to search table. Row count in search table is limited to 50. How to increase that.

---

## [Return multiple parent documents for each nested object match](https://discuss.elastic.co/t/return-multiple-parent-documents-for-each-nested-object-match/307873)

<div class="topic-metadata">

**Author:** [@dgurusam](https://discuss.elastic.co/u/dgurusam)\
**Replies:** 0\
**Last updated:** [June 22, 2022, 11:59am UTC](https://discuss.elastic.co/t/return-multiple-parent-documents-for-each-nested-object-match/307873 "2022-06-22T11:59:52Z")

</div>

Hi All, I have an index which contains a nested object. I would like to return multiple parent documents for each object matched in the nested object. For example: Index Details: "settings": { "number\_of\_sha…

---

## [Filebeat made my disk full in less than one day](https://discuss.elastic.co/t/filebeat-made-my-disk-full-in-less-than-one-day/307856)

<div class="topic-metadata">

**Author:** [@Khalifa\_Khalifi](https://discuss.elastic.co/u/Khalifa_Khalifi)\
**Replies:** 1\
**Last updated:** [June 22, 2022, 11:58am UTC](https://discuss.elastic.co/t/filebeat-made-my-disk-full-in-less-than-one-day/307856 "2022-06-22T11:58:21Z")

</div>

Using filebeat made my disk full in less than one day!!! Is there any config I could apply to filebeat.yml to avoid this please? Using this tool is really dangerous. Prod servers are suddenly full for no reason.

---

## [How to make a table like Excel sheet with Kibana?](https://discuss.elastic.co/t/how-to-make-a-table-like-excel-sheet-with-kibana/25687)

<div class="topic-metadata">

**Author:** [@cherah30](https://discuss.elastic.co/u/cherah30)\
**Replies:** 18\
**Last updated:** [June 22, 2022, 11:47am UTC](https://discuss.elastic.co/t/how-to-make-a-table-like-excel-sheet-with-kibana/25687 "2022-06-22T11:47:44Z")

</div>

I apologize for my beginner question. starting from "Discover" part of kibana, I could select some fields, filtering, ...etc, then I recorded the resultat of my research. Now, I would like to show the result of my se…

---

## [Elasticsearch SQL query with date and timestamp](https://discuss.elastic.co/t/elasticsearch-sql-query-with-date-and-timestamp/307753)

<div class="topic-metadata">

**Author:** [@Pranjal\_Sett](https://discuss.elastic.co/u/Pranjal_Sett)\
**Replies:** 3\
**Last updated:** [June 22, 2022, 11:47am UTC](https://discuss.elastic.co/t/elasticsearch-sql-query-with-date-and-timestamp/307753 "2022-06-22T11:47:26Z")

</div>

Hi, As per specification I want to get the data as per logic given. Here is the logic below: sum(QUANTITY) where FILE\_CREATION\_DATE = TODAY() and INDEX\_NUMBER in (2, 4) and SUBINVENTORY = \[x,y,z\] I have transferred t…

---

## [@elastic/elasticsearch](https://discuss.elastic.co/t/elastic-elasticsearch/307829)

<div class="topic-metadata">

**Author:** [@Rajan\_Devkota](https://discuss.elastic.co/u/Rajan_Devkota)\
**Replies:** 2\
**Last updated:** [June 22, 2022, 10:16am UTC](https://discuss.elastic.co/t/elastic-elasticsearch/307829 "2022-06-22T10:16:30Z")

</div>

Hello everyone. I am using elasticsearch client(@elastic/elasticsearch) version 7.13.0 and my elasticsearch server version is 7.10.0. And I am using typescript and node js in my backend. While using the elasticsearch c…

---

## [How to identify and remove duplicates in Elasticsearch index](https://discuss.elastic.co/t/how-to-identify-and-remove-duplicates-in-elasticsearch-index/307842)

<div class="topic-metadata">

**Author:** [@Komal\_42](https://discuss.elastic.co/u/Komal_42)\
**Replies:** 2\
**Last updated:** [June 22, 2022, 9:38am UTC](https://discuss.elastic.co/t/how-to-identify-and-remove-duplicates-in-elasticsearch-index/307842 "2022-06-22T09:38:51Z")

</div>

we are using elasticsearch 7.11.1 recently we observed an issue and below are the points for it. we store data for every 15 mins interval and we get time stamp from our input file (ex: 05:00, 23:15, 20:30, 11:45 ) rece…

---

## [Grok error filter json](https://discuss.elastic.co/t/grok-error-filter-json/307352)

<div class="topic-metadata">

**Author:** [@Roshan1](https://discuss.elastic.co/u/Roshan1)\
**Replies:** 7\
**Last updated:** [June 22, 2022, 8:16am UTC](https://discuss.elastic.co/t/grok-error-filter-json/307352 "2022-06-22T08:16:58Z")

</div>

Hello Team, can you please help me with error below? Error: \[WARN \] 2022-06-16 11:02:33.814 \[\[main\]-pipeline-manager\] grok - ECS v8 support is a preview of the unreleased ECS v8, and uses the v1 patterns. When Version…

---

## [Exception in thread "main" java.lang.NoClassDefFoundError](https://discuss.elastic.co/t/exception-in-thread-main-java-lang-noclassdeffounderror/307246)

<div class="topic-metadata">

**Author:** [@Ashutosh](https://discuss.elastic.co/u/Ashutosh)\
**Replies:** 2\
**Last updated:** [June 22, 2022, 8:08am UTC](https://discuss.elastic.co/t/exception-in-thread-main-java-lang-noclassdeffounderror/307246 "2022-06-22T08:08:44Z")

</div>

Hi Team, I am a beginner in Elasticsearch. We have a wazuh cluster running which use Elasticsearch for storing alerts. Since few days, the Elasticsearch is not starting at al. Whenever we try to use "systemctl start ela…

---

## [Calculate Error Budget Metric](https://discuss.elastic.co/t/calculate-error-budget-metric/307507)

<div class="topic-metadata">

**Author:** [@EllBil](https://discuss.elastic.co/u/EllBil)\
**Replies:** 3\
**Last updated:** [June 22, 2022, 8:07am UTC](https://discuss.elastic.co/t/calculate-error-budget-metric/307507 "2022-06-22T08:07:57Z")

</div>

Hello Elastic team, I'm actually working on SLI/SLO visualization on Kibana. My request is a bit complexe : I need to visualize the remaining error budget using this formula : EB = 436 minutes IF (not status = "500"…

---

## [Remove\_field not working](https://discuss.elastic.co/t/remove-field-not-working/307716)

<div class="topic-metadata">

**Author:** [@Naman1](https://discuss.elastic.co/u/Naman1)\
**Replies:** 2\
**Last updated:** [June 22, 2022, 7:59am UTC](https://discuss.elastic.co/t/remove-field-not-working/307716 "2022-06-22T07:59:01Z")

</div>

I am using remove\_field , but it is still showing that field in kibana. For eg- tags

---

## [Date time issue while sync up using Logstash from Oracle DB to Elasticsearch](https://discuss.elastic.co/t/date-time-issue-while-sync-up-using-logstash-from-oracle-db-to-elasticsearch/307824)

<div class="topic-metadata">

**Author:** [@suresh\_u](https://discuss.elastic.co/u/suresh_u)\
**Replies:** 0\
**Last updated:** [June 22, 2022, 4:05am UTC](https://discuss.elastic.co/t/date-time-issue-while-sync-up-using-logstash-from-oracle-db-to-elasticsearch/307824 "2022-06-22T04:05:41Z")

</div>

Hi team, I am using logstash for sync up data from Oracle Db to ElasticSearch index. I am able to sync data but the issue is : In Oracle db, I have 3 date fields. while syncing in ES index, they are storing as UTC. I…

---

## [Memcached not working](https://discuss.elastic.co/t/memcached-not-working/307822)

<div class="topic-metadata">

**Author:** [@paulohperes](https://discuss.elastic.co/u/paulohperes)\
**Replies:** 0\
**Last updated:** [June 22, 2022, 3:57am UTC](https://discuss.elastic.co/t/memcached-not-working/307822 "2022-06-22T03:57:26Z")

</div>

I am trying to create a pipeline using the memcached plugin, however it is not working when I create a key in the cache in dictionary format. Here's my pipeline: input { udp { port =\> 514 type =\> sy…

---

## [While connecting elasticSearch Getting this Exception through java api](https://discuss.elastic.co/t/while-connecting-elasticsearch-getting-this-exception-through-java-api/307764)

<div class="topic-metadata">

**Author:** [@Udayaprakash\_S\_10d](https://discuss.elastic.co/u/Udayaprakash_S_10d)\
**Replies:** 5\
**Last updated:** [June 22, 2022, 2:24am UTC](https://discuss.elastic.co/t/while-connecting-elasticsearch-getting-this-exception-through-java-api/307764 "2022-06-22T02:24:12Z")

</div>

SLF4J: Failed toString() invocation on an object of type \[org.elasticsearch.search.builder.SearchSourceBuilder\] Reported exception: java.lang.NullPointerException at org.elasticsearch.index.query.BoolQueryBuilder.doXArr…

---

## [Regarding count lookup of newly defined fields with log stash](https://discuss.elastic.co/t/regarding-count-lookup-of-newly-defined-fields-with-log-stash/307814)

<div class="topic-metadata">

**Author:** [@inwoo1](https://discuss.elastic.co/u/inwoo1)\
**Replies:** 3\
**Last updated:** [June 22, 2022, 2:32am UTC](https://discuss.elastic.co/t/regarding-count-lookup-of-newly-defined-fields-with-log-stash/307814 "2022-06-22T02:32:04Z")

</div>

I am collecting SNMP through logstash and creating a new field forti\_fw\_sessioncount through mutate-rename function. Looking at the log, 791 cases of forti\_fw\_sessioncount came in, but only 29 cases were shown when I ch…

---

## [Middleware Logic Layer](https://discuss.elastic.co/t/middleware-logic-layer/307817)

<div class="topic-metadata">

**Author:** [@randomusername001](https://discuss.elastic.co/u/randomusername001)\
**Replies:** 0\
**Last updated:** [June 22, 2022, 1:15am UTC](https://discuss.elastic.co/t/middleware-logic-layer/307817 "2022-06-22T01:15:45Z")

</div>

Hi All, Apologies if this is the wrong section to be posting in. Hoping to get some advice / insights if there is anything available in market to use for our use case. We have an ELK cluster that is running our site se…

---

## [Null results from search](https://discuss.elastic.co/t/null-results-from-search/307800)

<div class="topic-metadata">

**Author:** [@EnJay](https://discuss.elastic.co/u/EnJay)\
**Replies:** 2\
**Last updated:** [June 22, 2022, 12:49am UTC](https://discuss.elastic.co/t/null-results-from-search/307800 "2022-06-22T00:49:29Z")

</div>

Hello dear community :hugs: I record the price of bitcoin in ElasticSearch every 5 minutes. Today there was a problem, the server was down for a while, because of which the price was not recorded. Because of this, I sta…

---

## [How do I host an Elasticsearch server on a local machine and allow other machines to access that data?](https://discuss.elastic.co/t/how-do-i-host-an-elasticsearch-server-on-a-local-machine-and-allow-other-machines-to-access-that-data/307766)

<div class="topic-metadata">

**Author:** [@DataStorageMuse](https://discuss.elastic.co/u/DataStorageMuse)\
**Replies:** 18\
**Last updated:** [June 21, 2022, 11:42pm UTC](https://discuss.elastic.co/t/how-do-i-host-an-elasticsearch-server-on-a-local-machine-and-allow-other-machines-to-access-that-data/307766 "2022-06-21T23:42:59Z")

</div>

I have an Elasticsearch server running on a local machine with an ip address: {local\_machine\_ip}. I have another computer that has an ip {client\_ip}. How do I allow the client computer to access the Elasticsearch server …

---

## [Unable to download getting a 403](https://discuss.elastic.co/t/unable-to-download-getting-a-403/307139)

<div class="topic-metadata">

**Author:** [@abas](https://discuss.elastic.co/u/abas)\
**Replies:** 5\
**Last updated:** [June 21, 2022, 10:43pm UTC](https://discuss.elastic.co/t/unable-to-download-getting-a-403/307139 "2022-06-21T22:43:32Z")

</div>

Hello, We are using Chocolatay to install some packages on our Windows Server. I tried to install winlogbeat, which downloads the file from https://artifacts.elastic.co/downloads/beats/winlogbeat/winlogbeat-7.15.1-windo…

---

## [Export huge amount of data converted to csv format](https://discuss.elastic.co/t/export-huge-amount-of-data-converted-to-csv-format/307779)

<div class="topic-metadata">

**Author:** [@Tony79](https://discuss.elastic.co/u/Tony79)\
**Replies:** 1\
**Last updated:** [June 21, 2022, 10:28pm UTC](https://discuss.elastic.co/t/export-huge-amount-of-data-converted-to-csv-format/307779 "2022-06-21T22:28:04Z")

</div>

Hi, I want to export a huge amount of structured data to a csv formatted file. What is the most "production friendly" way to do this? I'm thinking of running elasticdump from a system with enough disk but I'm not sure…

---

## [How do I publish Elasticsearch cluster run on a remote machine (via its public IP address) and access it from another machine with Python Client?](https://discuss.elastic.co/t/how-do-i-publish-elasticsearch-cluster-run-on-a-remote-machine-via-its-public-ip-address-and-access-it-from-another-machine-with-python-client/307798)

<div class="topic-metadata">

**Author:** [@DataStorageMuse](https://discuss.elastic.co/u/DataStorageMuse)\
**Replies:** 1\
**Last updated:** [June 21, 2022, 10:18pm UTC](https://discuss.elastic.co/t/how-do-i-publish-elasticsearch-cluster-run-on-a-remote-machine-via-its-public-ip-address-and-access-it-from-another-machine-with-python-client/307798 "2022-06-21T22:18:21Z")

</div>

Hi, I was wondering if anyone could give me concrete instructions (or point me to where in the documentation there are specific instructions) for publishing an Elasticsearch cluster on the host machine (via the public IP…

---

## [Logstash Startup 401 error on Windows 10](https://discuss.elastic.co/t/logstash-startup-401-error-on-windows-10/307806)

<div class="topic-metadata">

**Author:** [@AE2000](https://discuss.elastic.co/u/AE2000)\
**Replies:** 0\
**Last updated:** [June 21, 2022, 9:55pm UTC](https://discuss.elastic.co/t/logstash-startup-401-error-on-windows-10/307806 "2022-06-21T21:55:32Z")

</div>

I'm installing ELK on my windows 10 workstation and I've gone through the steps to install all three; although there was a few issues with authorization during the process, Elasticsearch and Kibana are working perfectly …

---

## [Is there a way to efficiently get three layer aggrigations result in elasticsearch, where each layer is conditioned by above one](https://discuss.elastic.co/t/is-there-a-way-to-efficiently-get-three-layer-aggrigations-result-in-elasticsearch-where-each-layer-is-conditioned-by-above-one/307788)

<div class="topic-metadata">

**Author:** [@Robin\_Rawat](https://discuss.elastic.co/u/Robin_Rawat)\
**Replies:** 0\
**Last updated:** [June 21, 2022, 5:35pm UTC](https://discuss.elastic.co/t/is-there-a-way-to-efficiently-get-three-layer-aggrigations-result-in-elasticsearch-where-each-layer-is-conditioned-by-above-one/307788 "2022-06-21T17:35:41Z")

</div>

I am trying to get composite aggregation for certain feilds which are present in each document. These documents are stored in elastic. Format of each document is a json with below mentioned keys. {"id","name","topic","bu…

---

## [Challenges with date/time range selection when combining snapshot and timeseries data](https://discuss.elastic.co/t/challenges-with-date-time-range-selection-when-combining-snapshot-and-timeseries-data/304997)

<div class="topic-metadata">

**Author:** [@Sadia\_Mukhtar](https://discuss.elastic.co/u/Sadia_Mukhtar)\
**Replies:** 17\
**Last updated:** [June 21, 2022, 9:17pm UTC](https://discuss.elastic.co/t/challenges-with-date-time-range-selection-when-combining-snapshot-and-timeseries-data/304997 "2022-06-21T21:17:48Z")

</div>

Hi there, My organization is very new to Elasticsearch and Kibana. Historically we were using sql server for our analytics. We are doing a PoC to determine if Elastic and Kibana will with our scenario. We have 12 months…

---

## [Unnasigned shards for replica](https://discuss.elastic.co/t/unnasigned-shards-for-replica/307792)

<div class="topic-metadata">

**Author:** [@INS](https://discuss.elastic.co/u/INS)\
**Replies:** 1\
**Last updated:** [June 21, 2022, 7:43pm UTC](https://discuss.elastic.co/t/unnasigned-shards-for-replica/307792 "2022-06-21T19:43:15Z")

</div>

Hi How can I reassign (UNASSIGNED) shards for replica ? logstash-prod1-2022.06.21 3 p STARTED 2833524 es\_data\_ssd\_5\_1 logstash-prod1-2022.06.21 3 r UNASSIGNED I have tried through below req: POS…

---

## [Getting 403 denied to https://artifacts.elastic.co/packages/8.x/apt](https://discuss.elastic.co/t/getting-403-denied-to-https-artifacts-elastic-co-packages-8-x-apt/306956)

<div class="topic-metadata">

**Author:** [@dramis](https://discuss.elastic.co/u/dramis)\
**Replies:** 2\
**Last updated:** [June 21, 2022, 7:27pm UTC](https://discuss.elastic.co/t/getting-403-denied-to-https-artifacts-elastic-co-packages-8-x-apt/306956 "2022-06-21T19:27:52Z")

</div>

Since a few day I got error when trying to update elastic on one of my server: apt update Hit:1 Index of /debian-security bullseye-security InRelease Hit:2 Index of /debian bullseye InRelease Hit:3 Index of /debian b…

---

## [Parse JSON array with nested objects](https://discuss.elastic.co/t/parse-json-array-with-nested-objects/307770)

<div class="topic-metadata">

**Author:** [@eliz](https://discuss.elastic.co/u/eliz)\
**Replies:** 2\
**Last updated:** [June 21, 2022, 6:37pm UTC](https://discuss.elastic.co/t/parse-json-array-with-nested-objects/307770 "2022-06-21T18:37:09Z")

</div>

Hi there! I am receiving an array of nested JSON elements and I would like to build a logic capable of transforming the following input { "devices": \[ { "device": { "device\_name": "printer\_1", …

---

## [Getting slow logs on kibana with an hour delay time](https://discuss.elastic.co/t/getting-slow-logs-on-kibana-with-an-hour-delay-time/307645)

<div class="topic-metadata">

**Author:** [@Milad\_Akhlaghi](https://discuss.elastic.co/u/Milad_Akhlaghi)\
**Replies:** 6\
**Last updated:** [June 21, 2022, 6:06pm UTC](https://discuss.elastic.co/t/getting-slow-logs-on-kibana-with-an-hour-delay-time/307645 "2022-06-21T18:06:34Z")

</div>

Hi friends, i have elk cluster that includes: 20 filebeats , 6 logstash, 9 elasticsearches and 2 kibanas Elasticsearch node roles are : 3 x \[ data\_hot, data\_content \] 3 x \[ data\_warm, ingest, master \] 1x \[ master \] …

[Previous page](https://discuss.elastic.co/tag/none.md?no_tags=true&page=602)

[Next page](https://discuss.elastic.co/tag/none.md?no_tags=true&page=604)
