# Elastic Stack

**URL:** https://discuss.elastic.co/c/elastic-stack/81.md?page=365

[Latest](https://discuss.elastic.co/latest.md) · [Categories](https://discuss.elastic.co/categories.md) · [Tags](https://discuss.elastic.co/tags.md)

**Page:** 366

---

## [/etc/default/logstash](https://discuss.elastic.co/t/etc-default-logstash/347994)

<div class="topic-metadata">

**Author:** [@Tal\_Blat](https://discuss.elastic.co/u/Tal_Blat)\
**Replies:** 1\
**Last updated:** [November 26, 2023, 1:57pm UTC](https://discuss.elastic.co/t/etc-default-logstash/347994 "2023-11-26T13:57:46Z")

</div>

Hi How do i add to logstash env file "/etc/default/logstash" a line with the following format: ELK\_SERVERS="host1:9200","host2:9200","host3:9200","host4:9200" Thanks

---

## [An internal error while attempting to create policy](https://discuss.elastic.co/t/an-internal-error-while-attempting-to-create-policy/347991)

<div class="topic-metadata">

**Author:** [@amarnath](https://discuss.elastic.co/u/amarnath)\
**Replies:** 0\
**Last updated:** [November 26, 2023, 11:42am UTC](https://discuss.elastic.co/t/an-internal-error-while-attempting-to-create-policy/347991 "2023-11-26T11:42:08Z")

</div>

{"service":{"node":{"roles":\["background\_tasks","ui"\]}},"ecs":{"version":"8.6.1"},"@timestamp":"2023-11-26T11:27:03.939+00:00","message":"Cannot read properties of undefined (reading 'split')","error":{"message":"Cannot …

---

## [How to calculate how much data a single data node in an elasticsearch cluster can store?](https://discuss.elastic.co/t/how-to-calculate-how-much-data-a-single-data-node-in-an-elasticsearch-cluster-can-store/347916)

<div class="topic-metadata">

**Author:** [@qq\_123456](https://discuss.elastic.co/u/qq_123456)\
**Replies:** 1\
**Last updated:** [November 26, 2023, 10:05am UTC](https://discuss.elastic.co/t/how-to-calculate-how-much-data-a-single-data-node-in-an-elasticsearch-cluster-can-store/347916 "2023-11-26T10:05:52Z")

</div>

I now want to install an elasticsearch cluster. How to evaluate the cluster size and resources? How to calculate how much data a single data node in an elasticsearch cluster can store? How to determine the ratio of memor…

---

## [Increase in shard count vs increase in shard size - Performance comparison](https://discuss.elastic.co/t/increase-in-shard-count-vs-increase-in-shard-size-performance-comparison/347984)

<div class="topic-metadata">

**Author:** [@sriapr98](https://discuss.elastic.co/u/sriapr98)\
**Replies:** 1\
**Last updated:** [November 26, 2023, 7:34am UTC](https://discuss.elastic.co/t/increase-in-shard-count-vs-increase-in-shard-size-performance-comparison/347984 "2023-11-26T07:34:08Z")

</div>

Currently we are creating an index which will take space of around 900GB. We are not able to use ILM because there are updates possible to any older data as well. So the only option left to us is sharding optimization w…

---

## [Hostname not extracted when i run logstash as a service on rhel](https://discuss.elastic.co/t/hostname-not-extracted-when-i-run-logstash-as-a-service-on-rhel/347977)

<div class="topic-metadata">

**Author:** [@Indeed2000](https://discuss.elastic.co/u/Indeed2000)\
**Replies:** 6\
**Last updated:** [November 26, 2023, 2:30am UTC](https://discuss.elastic.co/t/hostname-not-extracted-when-i-run-logstash-as-a-service-on-rhel/347977 "2023-11-26T02:30:37Z")

</div>

Hi When i run logstash normally like this: ./logstash -f logstash.cfg It extract hostname. But when i run as service not extract hostname. Any idea? Thanks

---

## [Dealing with high number of deleted documents](https://discuss.elastic.co/t/dealing-with-high-number-of-deleted-documents/347973)

<div class="topic-metadata">

**Author:** [@Dishant\_18](https://discuss.elastic.co/u/Dishant_18)\
**Replies:** 8\
**Last updated:** [November 25, 2023, 6:15pm UTC](https://discuss.elastic.co/t/dealing-with-high-number-of-deleted-documents/347973 "2023-11-25T18:15:55Z")

</div>

Hello everyone! We have an elasticsearch index with 40 shards and 1 replica. We index live email data in this ES index - so the volume of deletes is also high! We have 2 data nodes and 3 master nodes in our cluster. For…

---

## [Disable auto configuring Kibana](https://discuss.elastic.co/t/disable-auto-configuring-kibana/347972)

<div class="topic-metadata">

**Author:** [@habajol675](https://discuss.elastic.co/u/habajol675)\
**Replies:** 2\
**Last updated:** [November 25, 2023, 4:04pm UTC](https://discuss.elastic.co/t/disable-auto-configuring-kibana/347972 "2023-11-25T16:04:38Z")

</div>

I want to just launch services in docker compos but without automatic configuration from the Kibana side. Can you please tell me if I can turn this off? I see that initially it started correctly and waited for me to con…

---

## [No verify ssl input elasticsearch](https://discuss.elastic.co/t/no-verify-ssl-input-elasticsearch/347860)

<div class="topic-metadata">

**Author:** [@lstoneir](https://discuss.elastic.co/u/lstoneir)\
**Replies:** 3\
**Last updated:** [November 25, 2023, 1:11pm UTC](https://discuss.elastic.co/t/no-verify-ssl-input-elasticsearch/347860 "2023-11-25T13:11:46Z")

</div>

Hi Dears Is there any way to not verify ssl in input elasticsearch plugin? logstash 7.17 I can not do this! please help

---

## [Search template in elastic 8.10](https://discuss.elastic.co/t/search-template-in-elastic-8-10/347969)

<div class="topic-metadata">

**Author:** [@ashish9333](https://discuss.elastic.co/u/ashish9333)\
**Replies:** 0\
**Last updated:** [November 25, 2023, 9:13am UTC](https://discuss.elastic.co/t/search-template-in-elastic-8-10/347969 "2023-11-25T09:13:41Z")

</div>

Greetings to all I have an issue with my search template in ES 8.11, It appears that there is data on the docName parameter, but there is no data when I search using the fulltext parameter and the docName parameter. I…

---

## [Aws managed elastic search](https://discuss.elastic.co/t/aws-managed-elastic-search/347812)

<div class="topic-metadata">

**Author:** [@Hariharan\_Raj](https://discuss.elastic.co/u/Hariharan_Raj)\
**Replies:** 8\
**Last updated:** [November 25, 2023, 6:31am UTC](https://discuss.elastic.co/t/aws-managed-elastic-search/347812 "2023-11-25T06:31:28Z")

</div>

Hi, I am trying to create a 2 node aws managed elasticsearch. I am having trouble creating it. I am running my backend services inside a VPC. the filter service has all the elasticsearch codes and resides in a private …

---

## [Synonym Graph giving incorrect results](https://discuss.elastic.co/t/synonym-graph-giving-incorrect-results/347966)

<div class="topic-metadata">

**Author:** [@bhavya](https://discuss.elastic.co/u/bhavya)\
**Replies:** 0\
**Last updated:** [November 25, 2023, 6:10am UTC](https://discuss.elastic.co/t/synonym-graph-giving-incorrect-results/347966 "2023-11-25T06:10:45Z")

</div>

I am trying to implement Multi-Word Synonyms This is the index setting { "settings": { "analysis": { "filter": { "synonym\_filter": { "type": "synonym\_graph", "synonyms": \[ …

---

## [Acces to Elastic error "Username or password is incorrect. Please try again."](https://discuss.elastic.co/t/acces-to-elastic-error-username-or-password-is-incorrect-please-try-again/347963)

<div class="topic-metadata">

**Author:** [@Antonio\_Sanchez](https://discuss.elastic.co/u/Antonio_Sanchez)\
**Replies:** 1\
**Last updated:** [November 25, 2023, 1:44am UTC](https://discuss.elastic.co/t/acces-to-elastic-error-username-or-password-is-incorrect-please-try-again/347963 "2023-11-25T01:44:11Z")

</div>

Hello everyone I start in this app(elasticsearch,logstash and kibana) on Ubuntu 20.04, I finish all the process to intaller I add a other user but when I put my new user and my password I recibet the error "Username or…

---

## [Kibana with elastic form docker compose setup problem](https://discuss.elastic.co/t/kibana-with-elastic-form-docker-compose-setup-problem/347951)

<div class="topic-metadata">

**Author:** [@habajol675](https://discuss.elastic.co/u/habajol675)\
**Replies:** 5\
**Last updated:** [November 24, 2023, 7:51pm UTC](https://discuss.elastic.co/t/kibana-with-elastic-form-docker-compose-setup-problem/347951 "2023-11-24T19:51:30Z")

</div>

Hello everyone, I have been trying to deploy elasticsearch and kibana for several days now. I'm using docker compos and having a lot of problems. I have provided an example of the file below, but there is this error with…

---

## [Docker Plesk - ERROR: Elasticsearch exited unexpectedly](https://discuss.elastic.co/t/docker-plesk-error-elasticsearch-exited-unexpectedly/347954)

<div class="topic-metadata">

**Author:** [@appuni](https://discuss.elastic.co/u/appuni)\
**Replies:** 0\
**Last updated:** [November 24, 2023, 7:00pm UTC](https://discuss.elastic.co/t/docker-plesk-error-elasticsearch-exited-unexpectedly/347954 "2023-11-24T19:00:53Z")

</div>

Good afternoon Community, When launching the Elasticsearch image I am receiving the error message: ERROR: Elasticsearch exited unexpectedly I configured it in Docker Plesk for unlimited memory usage, but it didn't sol…

---

## [Use specific subsets of data for visualization layers](https://discuss.elastic.co/t/use-specific-subsets-of-data-for-visualization-layers/347945)

<div class="topic-metadata">

**Author:** [@greendrake](https://discuss.elastic.co/u/greendrake)\
**Replies:** 1\
**Last updated:** [November 24, 2023, 5:56pm UTC](https://discuss.elastic.co/t/use-specific-subsets-of-data-for-visualization-layers/347945 "2023-11-24T17:56:22Z")

</div>

There is a nice feature in Kibana (I am using v 8.6.2) which allows to add multiple layers to visualizations: I have the following kind of data in the index: { utc: "\<datetime\>", source: "foo", value: 5 }…

---

## [How to access an index created by APM in Kibana's custom visualization?](https://discuss.elastic.co/t/how-to-access-an-index-created-by-apm-in-kibanas-custom-visualization/347949)

<div class="topic-metadata">

**Author:** [@thiagobr](https://discuss.elastic.co/u/thiagobr)\
**Replies:** 0\
**Last updated:** [November 24, 2023, 5:33pm UTC](https://discuss.elastic.co/t/how-to-access-an-index-created-by-apm-in-kibanas-custom-visualization/347949 "2023-11-24T17:33:53Z")

</div>

I need to access some custom labels sent from the front in the Dashboard --\> Custom Visualization area, I'm trying to do the following code but I don't seem to get anything. In addition, I am getting a specific index fro…

---

## [Logstash 8.1 multiple patterns](https://discuss.elastic.co/t/logstash-8-1-multiple-patterns/347943)

<div class="topic-metadata">

**Author:** [@Dokh\_Ahmed](https://discuss.elastic.co/u/Dokh_Ahmed)\
**Replies:** 1\
**Last updated:** [November 24, 2023, 4:33pm UTC](https://discuss.elastic.co/t/logstash-8-1-multiple-patterns/347943 "2023-11-24T16:33:36Z")

</div>

According to the doc of logstash " \`\`\` filter { grok { match =\> \[ "message", "PATTERN1", "PATTERN2" \] } } I wrote my filter as : filter { grok { match =\> { "message" =\> \[ "%{TIMESTAMP\_ISO860…

---

## [Mustache toJSON tag issue](https://discuss.elastic.co/t/mustache-tojson-tag-issue/347944)

<div class="topic-metadata">

**Author:** [@pszemesy](https://discuss.elastic.co/u/pszemesy)\
**Replies:** 0\
**Last updated:** [November 24, 2023, 4:27pm UTC](https://discuss.elastic.co/t/mustache-tojson-tag-issue/347944 "2023-11-24T16:27:54Z")

</div>

Hi All, I'm trying to create a search template: { "script": { "lang": "mustache", "source": """{ "query": { "bool": { "must": \[ {{#docyear}}{ "terms": { …

---

## [Grouping logs into sessions](https://discuss.elastic.co/t/grouping-logs-into-sessions/347934)

<div class="topic-metadata">

**Author:** [@Dor-Alter](https://discuss.elastic.co/u/Dor-Alter)\
**Replies:** 7\
**Last updated:** [November 24, 2023, 3:35pm UTC](https://discuss.elastic.co/t/grouping-logs-into-sessions/347934 "2023-11-24T15:35:24Z")

</div>

My entries in Elasticsearch are logs of different event. I am trying to group the logs into sessions of users based on an attribute of the logs. Each log has action attribute, everytime there is the action "session\_start…

---

## [Backup Of Index In Elasticsearch](https://discuss.elastic.co/t/backup-of-index-in-elasticsearch/347834)

<div class="topic-metadata">

**Author:** [@Debasis\_Mallick](https://discuss.elastic.co/u/Debasis_Mallick)\
**Replies:** 4\
**Last updated:** [November 24, 2023, 3:27pm UTC](https://discuss.elastic.co/t/backup-of-index-in-elasticsearch/347834 "2023-11-24T15:27:27Z")

</div>

Hi Team, I had a requirement where Elasticsearch is running as a container. I need to take backup of the one of the index and need to restore in Elasticsearch cluster which is running on VM. There is no Kibana configure…

---

## [Add value to a previously indexed field with logstash](https://discuss.elastic.co/t/add-value-to-a-previously-indexed-field-with-logstash/347940)

<div class="topic-metadata">

**Author:** [@elk-user-0001](https://discuss.elastic.co/u/elk-user-0001)\
**Replies:** 0\
**Last updated:** [November 24, 2023, 3:25pm UTC](https://discuss.elastic.co/t/add-value-to-a-previously-indexed-field-with-logstash/347940 "2023-11-24T15:25:21Z")

</div>

Hello! I have a pipeline that has many inputs ( 19 ) and I use the update on the output using a document\_id to avoid duplicates and the elasticsearch filter and update the values. Is it possible to add the value of a f…

---

## [Max suggested index sizes / document amount etc](https://discuss.elastic.co/t/max-suggested-index-sizes-document-amount-etc/347937)

<div class="topic-metadata">

**Author:** [@elk1985](https://discuss.elastic.co/u/elk1985)\
**Replies:** 2\
**Last updated:** [November 24, 2023, 2:56pm UTC](https://discuss.elastic.co/t/max-suggested-index-sizes-document-amount-etc/347937 "2023-11-24T14:56:57Z")

</div>

Hello. My cluster is reaching 2000 opened shards. I have two data nodes now. I don't want to add another data node and scale up the cluster. I'm thinking more like changing indexing strategy. Currently logstash is cre…

---

## [logstash-output-elasticsearch fails with Permission denied](https://discuss.elastic.co/t/logstash-output-elasticsearch-fails-with-permission-denied/347787)

<div class="topic-metadata">

**Author:** [@mirceastoian](https://discuss.elastic.co/u/mirceastoian)\
**Replies:** 18\
**Last updated:** [November 24, 2023, 2:46pm UTC](https://discuss.elastic.co/t/logstash-output-elasticsearch-fails-with-permission-denied/347787 "2023-11-24T14:46:15Z")

</div>

Logstash information: Logstash version: 7.17.9 Logstash installation source: deb How is Logstash being run: systemd How was the Logstash Plugin installed: sudo /usr/share/logstash/bin/logstash-plugin install logstash-o…

---

## [Datafeed has been retrieving no data for a while](https://discuss.elastic.co/t/datafeed-has-been-retrieving-no-data-for-a-while/347924)

<div class="topic-metadata">

**Author:** [@marmai16](https://discuss.elastic.co/u/marmai16)\
**Replies:** 2\
**Last updated:** [November 24, 2023, 12:30pm UTC](https://discuss.elastic.co/t/datafeed-has-been-retrieving-no-data-for-a-while/347924 "2023-11-24T12:30:53Z")

</div>

Hello everybody, i just created some anomaly detection jobs, however new records are not processed after the lookback was performed. New data is available in the source index the jobs are working on. If i reset the jo…

---

## [Cannot upgrade APM integration after setting "traces-apm.traces-default\_policy" in stackConfigPolicy](https://discuss.elastic.co/t/cannot-upgrade-apm-integration-after-setting-traces-apm-traces-default-policy-in-stackconfigpolicy/347913)

<div class="topic-metadata">

**Author:** [@GeorgeGkinis](https://discuss.elastic.co/u/GeorgeGkinis)\
**Replies:** 1\
**Last updated:** [November 24, 2023, 11:42am UTC](https://discuss.elastic.co/t/cannot-upgrade-apm-integration-after-setting-traces-apm-traces-default-policy-in-stackconfigpolicy/347913 "2023-11-24T11:42:44Z")

</div>

We had disk running full because the "traces-apm.traces-default\_policy" did not specify a delete fase. To make sure the delete fase will be there in the future we defined the traces-apm.traces-default\_policy in our stac…

---

## [How best to Denormalize a SQL schema](https://discuss.elastic.co/t/how-best-to-denormalize-a-sql-schema/347922)

<div class="topic-metadata">

**Author:** [@cylon86](https://discuss.elastic.co/u/cylon86)\
**Replies:** 0\
**Last updated:** [November 24, 2023, 11:21am UTC](https://discuss.elastic.co/t/how-best-to-denormalize-a-sql-schema/347922 "2023-11-24T11:21:41Z")

</div>

Hi all, I'm building a new Index for a use case and I'm wondering what would be the best mapping to structure this index. I have no problem building this with SQL tables, links and joins; but I struggle finding the goo…

---

## [Json parse error](https://discuss.elastic.co/t/json-parse-error/347919)

<div class="topic-metadata">

**Author:** [@Belbo\_belbo](https://discuss.elastic.co/u/Belbo_belbo)\
**Replies:** 0\
**Last updated:** [November 24, 2023, 10:51am UTC](https://discuss.elastic.co/t/json-parse-error/347919 "2023-11-24T10:51:31Z")

</div>

I'm trying, via a busybox pod, to generate a json that sends it to filebeat which in turn sends it to logstash but I have this problem: at \[Source: (byte\[\])"Hello, World!"; line: 1, column: 7\]\>} \[2023-11-24T10:41:27,44…

---

## [Problem with Search-time Synonyms](https://discuss.elastic.co/t/problem-with-search-time-synonyms/347654)

<div class="topic-metadata">

**Author:** [@elleWajexi](https://discuss.elastic.co/u/elleWajexi)\
**Replies:** 7\
**Last updated:** [November 24, 2023, 10:38am UTC](https://discuss.elastic.co/t/problem-with-search-time-synonyms/347654 "2023-11-24T10:38:07Z")

</div>

I have an index with synonyms : "index": { "analysis": { "analyzer": { "index\_analyzer": { "tokenizer": "standard", "filter": \[ "lowercase", "my\_stemmer" \] }…

---

## [Elasticsearch .Net v8.x client use for bulk indexing raw JSON data](https://discuss.elastic.co/t/elasticsearch-net-v8-x-client-use-for-bulk-indexing-raw-json-data/347914)

<div class="topic-metadata">

**Author:** [@askids](https://discuss.elastic.co/u/askids)\
**Replies:** 0\
**Last updated:** [November 24, 2023, 10:19am UTC](https://discuss.elastic.co/t/elasticsearch-net-v8-x-client-use-for-bulk-indexing-raw-json-data/347914 "2023-11-24T10:19:58Z")

</div>

hi, I am using .Net 6.0, running Elastic.Client 8.x connecting to 7.17 ES, which will be shortly upgraded to 8.4. I want to know how do I perform bulk indexing of raw json data? I could see some example under Java clien…

---

## [Elasticsearch Classic Plugin Development Documents](https://discuss.elastic.co/t/elasticsearch-classic-plugin-development-documents/347912)

<div class="topic-metadata">

**Author:** [@Zeus101](https://discuss.elastic.co/u/Zeus101)\
**Replies:** 0\
**Last updated:** [November 24, 2023, 9:17am UTC](https://discuss.elastic.co/t/elasticsearch-classic-plugin-development-documents/347912 "2023-11-24T09:17:57Z")

</div>

I have been trying to develop plugins for Elasticsearch, but was unable to as I couldn't find a proper documentation for the same. I have been using to cookiecutters' sample template to play around this but a proper docu…

[Previous page](https://discuss.elastic.co/c/elastic-stack/81.md?page=364)

[Next page](https://discuss.elastic.co/c/elastic-stack/81.md?page=366)
