# Elastic Stack

**URL:** https://discuss.elastic.co/c/elastic-stack/81.md?page=378

[Latest](https://discuss.elastic.co/latest.md) · [Categories](https://discuss.elastic.co/categories.md) · [Tags](https://discuss.elastic.co/tags.md)

**Page:** 379

---

## [Azure EventHub Plugin for Logstash Errors](https://discuss.elastic.co/t/azure-eventhub-plugin-for-logstash-errors/346811)

<div class="topic-metadata">

**Author:** [@Kris\_Felscher](https://discuss.elastic.co/u/Kris_Felscher)\
**Replies:** 0\
**Last updated:** [November 9, 2023, 2:42pm UTC](https://discuss.elastic.co/t/azure-eventhub-plugin-for-logstash-errors/346811 "2023-11-09T14:42:49Z")

</div>

We have Logstash installed on Kubernetes running on 2 pods. My main pipeline is configured to receive events from 2 separate EventHub instances. Here's my Pipeline Input: input { azure\_event\_hubs { config\_m…

---

## [How to create an histogram with many aggregations on X axis and a formula on Y axis](https://discuss.elastic.co/t/how-to-create-an-histogram-with-many-aggregations-on-x-axis-and-a-formula-on-y-axis/346518)

<div class="topic-metadata">

**Author:** [@FIFI](https://discuss.elastic.co/u/FIFI)\
**Replies:** 3\
**Last updated:** [November 9, 2023, 2:35pm UTC](https://discuss.elastic.co/t/how-to-create-an-histogram-with-many-aggregations-on-x-axis-and-a-formula-on-y-axis/346518 "2023-11-09T14:35:03Z")

</div>

Hi, Goal: I would like to create a histogram With two aggregations on X axis. One over terms. One over time. With one aggregation on Y axis. One over terms With a formula to compute value (using lens formula : sum(v…

---

## [Wrong dynamic mapping in Elasticsearch 8.11 prevents indexation of arrays of more than 127 strings](https://discuss.elastic.co/t/wrong-dynamic-mapping-in-elasticsearch-8-11-prevents-indexation-of-arrays-of-more-than-127-strings/346803)

<div class="topic-metadata">

**Author:** [@JulienCarnec](https://discuss.elastic.co/u/JulienCarnec)\
**Replies:** 4\
**Last updated:** [November 9, 2023, 2:24pm UTC](https://discuss.elastic.co/t/wrong-dynamic-mapping-in-elasticsearch-8-11-prevents-indexation-of-arrays-of-more-than-127-strings/346803 "2023-11-09T14:24:54Z")

</div>

Since 8.11.0, when using dynamic mapping, there is a defect preventing the indexation of documents with an array field containing more than 127 strings. Here is how to reproduce: 1- start Elasticsearch 8.11.0: docker …

---

## [Why should we not use Metricbeat with scope: node for clusters with dedicated master nodes](https://discuss.elastic.co/t/why-should-we-not-use-metricbeat-with-scope-node-for-clusters-with-dedicated-master-nodes/346715)

<div class="topic-metadata">

**Author:** [@bunste](https://discuss.elastic.co/u/bunste)\
**Replies:** 9\
**Last updated:** [November 9, 2023, 1:35pm UTC](https://discuss.elastic.co/t/why-should-we-not-use-metricbeat-with-scope-node-for-clusters-with-dedicated-master-nodes/346715 "2023-11-09T13:35:36Z")

</div>

I am currently reading the documentation on collecting Elasticsearch monitoring data with Metricbeat. I had already posted something about this here in the forum, which led to this issue. The documentation has improved s…

---

## [How to improve fuzzy match performance](https://discuss.elastic.co/t/how-to-improve-fuzzy-match-performance/346794)

<div class="topic-metadata">

**Author:** [@chengyang.backend](https://discuss.elastic.co/u/chengyang.backend)\
**Replies:** 1\
**Last updated:** [November 9, 2023, 1:19pm UTC](https://discuss.elastic.co/t/how-to-improve-fuzzy-match-performance/346794 "2023-11-09T13:19:22Z")

</div>

---

## [Watcher log history not available for some watchers scripts](https://discuss.elastic.co/t/watcher-log-history-not-available-for-some-watchers-scripts/346795)

<div class="topic-metadata">

**Author:** [@Seemant\_Bind](https://discuss.elastic.co/u/Seemant_Bind)\
**Replies:** 0\
**Last updated:** [November 9, 2023, 12:48pm UTC](https://discuss.elastic.co/t/watcher-log-history-not-available-for-some-watchers-scripts/346795 "2023-11-09T12:48:29Z")

</div>

Hi, I am currently facing issue with the watcher logs, currently I am using ELK version 7.11 and when I check Execution history of some watcher for last 1 hour, 1 day or even last week , no logs are available. For few w…

---

## [Extract substring from the path](https://discuss.elastic.co/t/extract-substring-from-the-path/346787)

<div class="topic-metadata">

**Author:** [@Xhar](https://discuss.elastic.co/u/Xhar)\
**Replies:** 2\
**Last updated:** [November 9, 2023, 12:43pm UTC](https://discuss.elastic.co/t/extract-substring-from-the-path/346787 "2023-11-09T12:43:16Z")

</div>

in this config input { file { mode =\> "read" path =\> "/opt/stromReciever/parsed\_data/changedRights/csv/\*.json" start\_position =\> "beginning" sincedb\_path =\> "/dev/null" codec =\> "json" type =\> …

---

## [Cloudflare integration not working](https://discuss.elastic.co/t/cloudflare-integration-not-working/346024)

<div class="topic-metadata">

**Author:** [@theacodes](https://discuss.elastic.co/u/theacodes)\
**Replies:** 7\
**Last updated:** [November 9, 2023, 12:28pm UTC](https://discuss.elastic.co/t/cloudflare-integration-not-working/346024 "2023-11-09T12:28:41Z")

</div>

I added this integration and entered all the required key and creds needed. still I am not getting any logs from cloudflare and the dashboard and saved search both are empty. what am I missing?

---

## [Single file indexing with multiple docs in es](https://discuss.elastic.co/t/single-file-indexing-with-multiple-docs-in-es/346785)

<div class="topic-metadata">

**Author:** [@ravikiran\_gunda](https://discuss.elastic.co/u/ravikiran_gunda)\
**Replies:** 0\
**Last updated:** [November 9, 2023, 11:56am UTC](https://discuss.elastic.co/t/single-file-indexing-with-multiple-docs-in-es/346785 "2023-11-09T11:56:44Z")

</div>

Hi Everyone, I have one large file and I indexed but that large file created multiple docs in Elasticsearch with myid+sequence no. so is there anyway to create multiple docs under single id, why i am asking is while sear…

---

## [Kibana visualisation requirement to get failed count of documents uploaded](https://discuss.elastic.co/t/kibana-visualisation-requirement-to-get-failed-count-of-documents-uploaded/346777)

<div class="topic-metadata">

**Author:** [@Sanjana\_Nalam](https://discuss.elastic.co/u/Sanjana_Nalam)\
**Replies:** 0\
**Last updated:** [November 9, 2023, 10:54am UTC](https://discuss.elastic.co/t/kibana-visualisation-requirement-to-get-failed-count-of-documents-uploaded/346777 "2023-11-09T10:54:38Z")

</div>

Dear community, We have a requirement where we will determine if the file is successfully uploaded or not based on the doc id, if doc id =-1 then the document is not uploaded and if doc id is other than that document is…

---

## [CANVAS QUERY DEFAULT IS MANUALLY REFRESH?](https://discuss.elastic.co/t/canvas-query-default-is-manually-refresh/346493)

<div class="topic-metadata">

**Author:** [@Anh\_Nguyen](https://discuss.elastic.co/u/Anh_Nguyen)\
**Replies:** 6\
**Last updated:** [November 9, 2023, 10:21am UTC](https://discuss.elastic.co/t/canvas-query-default-is-manually-refresh/346493 "2023-11-09T10:21:30Z")

</div>

Hi, I have built some canvas with much of CSS and heavy element inside (query, gif,...). I wonder when the canvas do some query to Elasticsearch and if it default is manually refresh (It will not refresh or do any query …

---

## [Data nodes removed from cluster one by one after indexing activity peak](https://discuss.elastic.co/t/data-nodes-removed-from-cluster-one-by-one-after-indexing-activity-peak/346764)

<div class="topic-metadata">

**Author:** [@jalker](https://discuss.elastic.co/u/jalker)\
**Replies:** 0\
**Last updated:** [November 9, 2023, 8:35am UTC](https://discuss.elastic.co/t/data-nodes-removed-from-cluster-one-by-one-after-indexing-activity-peak/346764 "2023-11-09T08:35:12Z")

</div>

Elasticsearch 7.17, Debian, 12 data nodes, 5.5 Bi primary docs, 11.0 TB primary doc size. We have seen the following behavior twice now and we are clueless as to its root cause. We see an sudden increase of indexing a…

---

## [Multiple replicas of Kibana deployment](https://discuss.elastic.co/t/multiple-replicas-of-kibana-deployment/346763)

<div class="topic-metadata">

**Author:** [@daniela09](https://discuss.elastic.co/u/daniela09)\
**Replies:** 0\
**Last updated:** [November 9, 2023, 8:27am UTC](https://discuss.elastic.co/t/multiple-replicas-of-kibana-deployment/346763 "2023-11-09T08:27:37Z")

</div>

I have deployed EFK stack on Kubernetes, but Kibana is running as a single instance (pod) and there is no redundancy, so I wanted to change it to 2 replicas, in the Kibana deployment yaml, I only need to change replicas…

---

## [Custom fields creation in jira using elasticsearch](https://discuss.elastic.co/t/custom-fields-creation-in-jira-using-elasticsearch/346759)

<div class="topic-metadata">

**Author:** [@Kumar\_6](https://discuss.elastic.co/u/Kumar_6)\
**Replies:** 0\
**Last updated:** [November 9, 2023, 6:27am UTC](https://discuss.elastic.co/t/custom-fields-creation-in-jira-using-elasticsearch/346759 "2023-11-09T06:27:51Z")

</div>

Hi, Can some one help to fix this issue. I want to create custom fields in jira by passing data from jira connecter in kibana.

---

## [Update by query (async / task) - No failure info - Handling Conflicts](https://discuss.elastic.co/t/update-by-query-async-task-no-failure-info-handling-conflicts/346755)

<div class="topic-metadata">

**Author:** [@Irfanulla](https://discuss.elastic.co/u/Irfanulla)\
**Replies:** 0\
**Last updated:** [November 9, 2023, 6:08am UTC](https://discuss.elastic.co/t/update-by-query-async-task-no-failure-info-handling-conflicts/346755 "2023-11-09T06:08:55Z")

</div>

I am running an update by query as a task (wait\_for\_completion=false), with 'conflicts=proceed'. I do expect version conflicts to happen sometimes and can see that info in get task response (/task/task-id). I plan to rep…

---

## [Error creating runner from config: failed to create input: Can only start an input when all related states are finished](https://discuss.elastic.co/t/error-creating-runner-from-config-failed-to-create-input-can-only-start-an-input-when-all-related-states-are-finished/346749)

<div class="topic-metadata">

**Author:** [@alexus](https://discuss.elastic.co/u/alexus)\
**Replies:** 1\
**Last updated:** [November 9, 2023, 4:28am UTC](https://discuss.elastic.co/t/error-creating-runner-from-config-failed-to-create-input-can-only-start-an-input-when-all-related-states-are-finished/346749 "2023-11-09T04:28:52Z")

</div>

Hello World :wink: I'm tying to follow: yet, I'm running into this error: {"log.level":"error","@timestamp":"2023-11-09T01:40:40.122Z","log.logger":"autodiscover.cfgfile","log.origin":{"file.name":"cfgfile/list.go",…

---

## [A timeout (30000 milliseconds) was reached while waiting for a transaction response from the Elastic Agent service](https://discuss.elastic.co/t/a-timeout-30000-milliseconds-was-reached-while-waiting-for-a-transaction-response-from-the-elastic-agent-service/346751)

<div class="topic-metadata">

**Author:** [@digital-thought](https://discuss.elastic.co/u/digital-thought)\
**Replies:** 0\
**Last updated:** [November 9, 2023, 3:16am UTC](https://discuss.elastic.co/t/a-timeout-30000-milliseconds-was-reached-while-waiting-for-a-transaction-response-from-the-elastic-agent-service/346751 "2023-11-09T03:16:59Z")

</div>

We have installed the Elastic Agent onto a Windows system for monitoring. Since we have installed the agent, we are seeing an Error Event (ID 7011) in the System logs of the OS that is reporting: "A timeout (30000 mill…

---

## [Logstash is not up & running on MacOS](https://discuss.elastic.co/t/logstash-is-not-up-running-on-macos/346741)

<div class="topic-metadata">

**Author:** [@inandi](https://discuss.elastic.co/u/inandi)\
**Replies:** 1\
**Last updated:** [November 9, 2023, 1:11am UTC](https://discuss.elastic.co/t/logstash-is-not-up-running-on-macos/346741 "2023-11-09T01:11:32Z")

</div>

(in Docker) Logstash is not running on MAC, but the same thing is working on Windows getting below error 2023-11-09 01:12:57 runtime: failed to create new OS thread (have 2 already; errno=22) 2023-11-09 01:12:57 fatal …

---

## [Why is a wildcard query string matching on stemmed terms?](https://discuss.elastic.co/t/why-is-a-wildcard-query-string-matching-on-stemmed-terms/346576)

<div class="topic-metadata">

**Author:** [@cphramington](https://discuss.elastic.co/u/cphramington)\
**Replies:** 4\
**Last updated:** [November 8, 2023, 10:54pm UTC](https://discuss.elastic.co/t/why-is-a-wildcard-query-string-matching-on-stemmed-terms/346576 "2023-11-08T22:54:52Z")

</div>

First, some background. I understand that the algorithmic stemmer is not perfect, e.g. "focused" is stemmed to "focus," while "focus" is stemmed to "focu," which I've validated by looking through the term vectors. Howev…

---

## [Warn nfs/rpc.go - multifragment rpc message in logs](https://discuss.elastic.co/t/warn-nfs-rpc-go-multifragment-rpc-message-in-logs/346743)

<div class="topic-metadata">

**Author:** [@tomaskcz](https://discuss.elastic.co/u/tomaskcz)\
**Replies:** 0\
**Last updated:** [November 8, 2023, 8:38pm UTC](https://discuss.elastic.co/t/warn-nfs-rpc-go-multifragment-rpc-message-in-logs/346743 "2023-11-08T20:38:17Z")

</div>

I am getting lots of logs messages for packebeat with {"log.level":"warn","@timestamp":"2023-11-08T20:27:29.998Z","log.origin":{"file.name":"nfs/rpc.go","file.line":227},"message":"multifragment rpc message","service.na…

---

## [RHEL8 Upgrade](https://discuss.elastic.co/t/rhel8-upgrade/346738)

<div class="topic-metadata">

**Author:** [@Brian-cf1](https://discuss.elastic.co/u/Brian-cf1)\
**Replies:** 0\
**Last updated:** [November 8, 2023, 7:14pm UTC](https://discuss.elastic.co/t/rhel8-upgrade/346738 "2023-11-08T19:14:43Z")

</div>

Is there anything special i need to do to upgrade from rhel7 to rhel8 running ELK8?

---

## [Loss of Elasticsearch Replicas/Shards After Node Failures](https://discuss.elastic.co/t/loss-of-elasticsearch-replicas-shards-after-node-failures/346664)

<div class="topic-metadata">

**Author:** [@Jeankininho](https://discuss.elastic.co/u/Jeankininho)\
**Replies:** 3\
**Last updated:** [November 8, 2023, 6:00pm UTC](https://discuss.elastic.co/t/loss-of-elasticsearch-replicas-shards-after-node-failures/346664 "2023-11-08T18:00:09Z")

</div>

Hello, I'm facing an issue with my Elasticsearch cluster and I'm looking for some guidance or suggestions on what might be happening. I have an Elasticsearch cluster running version 6.5.1 with JVM 11.0.11. Recently, I'…

---

## [Failed after reindexing](https://discuss.elastic.co/t/failed-after-reindexing/346714)

<div class="topic-metadata">

**Author:** [@1337](https://discuss.elastic.co/u/1337)\
**Replies:** 4\
**Last updated:** [November 8, 2023, 6:00pm UTC](https://discuss.elastic.co/t/failed-after-reindexing/346714 "2023-11-08T18:00:22Z")

</div>

Got this error after reindexing \[INIT\] Fail initialize schema, index already exists, previous initialization fail because you kill the platform before the end of the initialization. Please remove your elastic/opensearch…

---

## [Unexpected tCONSTANT in Ruby Script](https://discuss.elastic.co/t/unexpected-tconstant-in-ruby-script/346709)

<div class="topic-metadata">

**Author:** [@Kris\_Felscher](https://discuss.elastic.co/u/Kris_Felscher)\
**Replies:** 2\
**Last updated:** [November 8, 2023, 5:42pm UTC](https://discuss.elastic.co/t/unexpected-tconstant-in-ruby-script/346709 "2023-11-08T17:42:01Z")

</div>

We have a ton (200+) of applications that are all logging to the same index. Because of this, we are seeing a few field type collisions that cause messages to get bounced (to the tune of approximately 26 million bounced …

---

## [Calling Elasticsearch API from Kibana plugin](https://discuss.elastic.co/t/calling-elasticsearch-api-from-kibana-plugin/343620)

<div class="topic-metadata">

**Author:** [@trosagnant](https://discuss.elastic.co/u/trosagnant)\
**Replies:** 2\
**Last updated:** [November 8, 2023, 5:41pm UTC](https://discuss.elastic.co/t/calling-elasticsearch-api-from-kibana-plugin/343620 "2023-11-08T17:41:04Z")

</div>

Follow-up for #337003 Similar to #268179 Hello, The main idea for the plugin I develop is to call elastic to alter some already existing index (just like using SQL UPDATE method). I'm trying to call elastic API throu…

---

## [\[Logstash\] Use variables with ilm in Elasticsearch output](https://discuss.elastic.co/t/logstash-use-variables-with-ilm-in-elasticsearch-output/346697)

<div class="topic-metadata">

**Author:** [@quoctuan2311](https://discuss.elastic.co/u/quoctuan2311)\
**Replies:** 1\
**Last updated:** [November 8, 2023, 4:16pm UTC](https://discuss.elastic.co/t/logstash-use-variables-with-ilm-in-elasticsearch-output/346697 "2023-11-08T16:16:32Z")

</div>

Can you variables with ilm\_rollover\_alias and ilm\_policy. Current I use if else but if conditions increase with each log\_type by created. Logstash will be increase time start it. Pls support me with this case. elastic…

---

## [Using bucket\_selector in anomaly detection datafeed](https://discuss.elastic.co/t/using-bucket-selector-in-anomaly-detection-datafeed/346720)

<div class="topic-metadata">

**Author:** [@jakn](https://discuss.elastic.co/u/jakn)\
**Replies:** 0\
**Last updated:** [November 8, 2023, 3:02pm UTC](https://discuss.elastic.co/t/using-bucket-selector-in-anomaly-detection-datafeed/346720 "2023-11-08T15:02:31Z")

</div>

Is the use of bucket\_selector supported i datafeed for an anomaly detection job? The problem If I set up a job having a bucket\_selector in the datafeed, then the job only processes a few initial buckets and then does n…

---

## [Getting error when using variable\_width\_histogram aggregation 'Too many buckets'](https://discuss.elastic.co/t/getting-error-when-using-variable-width-histogram-aggregation-too-many-buckets/346695)

<div class="topic-metadata">

**Author:** [@Chandra\_Shekhar](https://discuss.elastic.co/u/Chandra_Shekhar)\
**Replies:** 0\
**Last updated:** [November 8, 2023, 10:34am UTC](https://discuss.elastic.co/t/getting-error-when-using-variable-width-histogram-aggregation-too-many-buckets/346695 "2023-11-08T10:34:22Z")

</div>

We are trying to execute a query to get variable\_width\_histogram aggregation results but getting an error 'Trying to create too many buckets'. However bucket size in query is 10. When trying to get bucket size 8, I am ab…

---

## [Failed to start Elasticsearch](https://discuss.elastic.co/t/failed-to-start-elasticsearch/345232)

<div class="topic-metadata">

**Author:** [@Tybe\_sacha](https://discuss.elastic.co/u/Tybe_sacha)\
**Replies:** 27\
**Last updated:** [November 8, 2023, 2:23pm UTC](https://discuss.elastic.co/t/failed-to-start-elasticsearch/345232 "2023-11-08T14:23:01Z")

</div>

Hi everyone, I'm new here ! :ok\_woman: I just finished set up basic security on my server (1VM with : Elasticsearch, 1 node, Kibana). I ran those commands : ./bin/elasticsearch-keystore add xpack.security.transport.ss…

---

## [Winlogbeat - Deletion of specific event IDs which are older than 3 months](https://discuss.elastic.co/t/winlogbeat-deletion-of-specific-event-ids-which-are-older-than-3-months/345159)

<div class="topic-metadata">

**Author:** [@Shaakxuur](https://discuss.elastic.co/u/Shaakxuur)\
**Replies:** 3\
**Last updated:** [November 8, 2023, 12:57pm UTC](https://discuss.elastic.co/t/winlogbeat-deletion-of-specific-event-ids-which-are-older-than-3-months/345159 "2023-11-08T12:57:38Z")

</div>

I would like to delete old event ID's which have been recorded with Winlogbeat. These are the Event ID's 4768, 4769 and 4770. These are Kerberos authentications. The entries are very numerous. Only records older than 3…

[Previous page](https://discuss.elastic.co/c/elastic-stack/81.md?page=377)

[Next page](https://discuss.elastic.co/c/elastic-stack/81.md?page=379)
