# Elastic Stack

**URL:** https://discuss.elastic.co/c/elastic-stack/81.md?page=593

[Latest](https://discuss.elastic.co/latest.md) · [Categories](https://discuss.elastic.co/categories.md) · [Tags](https://discuss.elastic.co/tags.md)

**Page:** 594

---

## [2 Mongo DB collection how to merge in Logstash](https://discuss.elastic.co/t/2-mongo-db-collection-how-to-merge-in-logstash/328423)

<div class="topic-metadata">

**Author:** [@rachit](https://discuss.elastic.co/u/rachit)\
**Replies:** 0\
**Last updated:** [March 24, 2023, 6:29am UTC](https://discuss.elastic.co/t/2-mongo-db-collection-how-to-merge-in-logstash/328423 "2023-03-24T06:29:03Z")

</div>

Hi Team, Can anyone help me to merge 2 different collection of mongodb in single index in Elasticsearch with sync enable feature. Thanks

---

## [Unable to do cross cluster replication , Please help here](https://discuss.elastic.co/t/unable-to-do-cross-cluster-replication-please-help-here/328345)

<div class="topic-metadata">

**Author:** [@JayaPavani\_Pathakota](https://discuss.elastic.co/u/JayaPavani_Pathakota)\
**Replies:** 10\
**Last updated:** [March 24, 2023, 6:28am UTC](https://discuss.elastic.co/t/unable-to-do-cross-cluster-replication-please-help-here/328345 "2023-03-24T06:28:14Z")

</div>

I created two clusters in 2 data centers and I am trying to do cross cluster replication , in one of the cluster I configured leader index and in the other I did the remote configuration pointing to the cluster of leader…

---

## [Hide size parameter from URL](https://discuss.elastic.co/t/hide-size-parameter-from-url/328397)

<div class="topic-metadata">

**Author:** [@ach](https://discuss.elastic.co/u/ach)\
**Replies:** 3\
**Last updated:** [March 24, 2023, 6:18am UTC](https://discuss.elastic.co/t/hide-size-parameter-from-url/328397 "2023-03-24T06:18:14Z")

</div>

Hi all, I want to hide the size parameter from the search query URL, e.g., site.com/?q=phone&size=n\_10\_n and I want to hide '&size=n\_10\_n.' Is configuring the routing options the way to go? I would greatly appreciate i…

---

## [Visualize not works after reindex](https://discuss.elastic.co/t/visualize-not-works-after-reindex/328315)

<div class="topic-metadata">

**Author:** [@rachit](https://discuss.elastic.co/u/rachit)\
**Replies:** 11\
**Last updated:** [March 24, 2023, 5:53am UTC](https://discuss.elastic.co/t/visualize-not-works-after-reindex/328315 "2023-03-24T05:53:37Z")

</div>

Hi Team, i have merged 2 indexes with reindex Query. Billingdemo(index) filedemo(index) POST \_reindex { "source": { "index": "\*demo" }, "dest": { "index": "ReindexDemo" } } indexes merged, but now wh…

---

## [TypeError: no implicit conversion of nil into String](https://discuss.elastic.co/t/typeerror-no-implicit-conversion-of-nil-into-string/328416)

<div class="topic-metadata">

**Author:** [@kala\_y](https://discuss.elastic.co/u/kala_y)\
**Replies:** 0\
**Last updated:** [March 24, 2023, 3:38am UTC](https://discuss.elastic.co/t/typeerror-no-implicit-conversion-of-nil-into-string/328416 "2023-03-24T03:38:12Z")

</div>

2023-03-23T22:23:02.967-05:00 Copy \[2023-03-24T03:23:02,967\]\[WARN \]\[logstash.inputs.s3snssqs \]\[main\]\[97e0bbb90d3a28c08cdd88a484e0aa3737932f33f22b59839ba78170f15c7929\] Error in poller loop {:error=\>#\<TypeError: no impli…

---

## [In Metricbeat have provided the process monitoring list in system.yml but not getting process stats in the kibana dashboard](https://discuss.elastic.co/t/in-metricbeat-have-provided-the-process-monitoring-list-in-system-yml-but-not-getting-process-stats-in-the-kibana-dashboard/327183)

<div class="topic-metadata">

**Author:** [@sourabh\_rawat](https://discuss.elastic.co/u/sourabh_rawat)\
**Replies:** 2\
**Last updated:** [March 24, 2023, 3:53am UTC](https://discuss.elastic.co/t/in-metricbeat-have-provided-the-process-monitoring-list-in-system-yml-but-not-getting-process-stats-in-the-kibana-dashboard/327183 "2023-03-24T03:53:08Z")

</div>

Hi I have provided the list of processes to get monitored on my system but I am not getting stats for one of the processes for other listed processes I am getting data but. My system.yml is below # Module: system # Docs…

---

## [Hyperthreading effects on Elasticsearch performance](https://discuss.elastic.co/t/hyperthreading-effects-on-elasticsearch-performance/328402)

<div class="topic-metadata">

**Author:** [@Vadym](https://discuss.elastic.co/u/Vadym)\
**Replies:** 3\
**Last updated:** [March 24, 2023, 3:39am UTC](https://discuss.elastic.co/t/hyperthreading-effects-on-elasticsearch-performance/328402 "2023-03-24T03:39:48Z")

</div>

Hi team, What's the current recommendations regarding Hyper Threading with Elasticsearch, do we get any benefits and are there any downsides to keep HT enabled? I've seen multiple performance tests documents which clai…

---

## [Filebeat AWS CloudWatch input loss data](https://discuss.elastic.co/t/filebeat-aws-cloudwatch-input-loss-data/328409)

<div class="topic-metadata">

**Author:** [@jacksparrow414](https://discuss.elastic.co/u/jacksparrow414)\
**Replies:** 0\
**Last updated:** [March 24, 2023, 2:14am UTC](https://discuss.elastic.co/t/filebeat-aws-cloudwatch-input-loss-data/328409 "2023-03-24T02:14:07Z")

</div>

filebeat configuration filebeat.inputs: - type: aws-cloudwatch enabled: true log\_group\_arn: arn log\_stream\_prefix: my-logstream-prefix scan\_frequency: 10s start\_position: end access\_key\_id: omi…

---

## [Kubernetes deployment - Elastic Search](https://discuss.elastic.co/t/kubernetes-deployment-elastic-search/328384)

<div class="topic-metadata">

**Author:** [@aharo-lumificyber](https://discuss.elastic.co/u/aharo-lumificyber)\
**Replies:** 1\
**Last updated:** [March 24, 2023, 1:21am UTC](https://discuss.elastic.co/t/kubernetes-deployment-elastic-search/328384 "2023-03-24T01:21:57Z")

</div>

We currently use Elasticsearch through the Azure implementation but is getting too expensive, and I would like to know the procedure to host my own image of Elasticsearch and kibana through kubernetes. Do I need to pay f…

---

## [JSON Logstash](https://discuss.elastic.co/t/json-logstash/328403)

<div class="topic-metadata">

**Author:** [@Whazaza](https://discuss.elastic.co/u/Whazaza)\
**Replies:** 0\
**Last updated:** [March 24, 2023, 12:55am UTC](https://discuss.elastic.co/t/json-logstash/328403 "2023-03-24T00:55:06Z")

</div>

I have a problem when taking the data from my json suppose i need to take the data from this json { "header" : { "sendingApplicationNs" : "value", "sendingApplicationId" : "value", "sendingApplicationIdTy…

---

## [Multiple search criteria](https://discuss.elastic.co/t/multiple-search-criteria/328400)

<div class="topic-metadata">

**Author:** [@Sheng111](https://discuss.elastic.co/u/Sheng111)\
**Replies:** 0\
**Last updated:** [March 23, 2023, 10:52pm UTC](https://discuss.elastic.co/t/multiple-search-criteria/328400 "2023-03-23T22:52:49Z")

</div>

Hi there, one common question, how to do multiple criteria search using elasticsearch UI? for example I search for attribute A==5 and attribute B within recent 3 months; is this possible to combine above 2 filter criter…

---

## [How does document update work under the hood?](https://discuss.elastic.co/t/how-does-document-update-work-under-the-hood/328392)

<div class="topic-metadata">

**Author:** [@egalpin](https://discuss.elastic.co/u/egalpin)\
**Replies:** 2\
**Last updated:** [March 23, 2023, 9:10pm UTC](https://discuss.elastic.co/t/how-does-document-update-work-under-the-hood/328392 "2023-03-23T21:10:32Z")

</div>

Hi all! I’m curious to learn about how the process of document update (and upsert/partial upsert) works under the hood. I know that Lucene segments are immutable and that “deleting” a doc is a soft delete by way of tomb…

---

## [Vega tree graph in Kibana: How to filter the second level data node using Kibana filter control](https://discuss.elastic.co/t/vega-tree-graph-in-kibana-how-to-filter-the-second-level-data-node-using-kibana-filter-control/328362)

<div class="topic-metadata">

**Author:** [@Dimple.P](https://discuss.elastic.co/u/Dimple.P)\
**Replies:** 0\
**Last updated:** [March 23, 2023, 3:26pm UTC](https://discuss.elastic.co/t/vega-tree-graph-in-kibana-how-to-filter-the-second-level-data-node-using-kibana-filter-control/328362 "2023-03-23T15:26:21Z")

</div>

Hi Team, I wrote the following code to the Kibana custom visualizations widget; I want to filter only Student1 node and it's child nodes, but when I try, it expects its parent node to be filtered. This filtering can be …

---

## [Kibana custom visualizations widget (Vega) - to bind data using API](https://discuss.elastic.co/t/kibana-custom-visualizations-widget-vega-to-bind-data-using-api/328365)

<div class="topic-metadata">

**Author:** [@Dimple.P](https://discuss.elastic.co/u/Dimple.P)\
**Replies:** 0\
**Last updated:** [March 23, 2023, 3:41pm UTC](https://discuss.elastic.co/t/kibana-custom-visualizations-widget-vega-to-bind-data-using-api/328365 "2023-03-23T15:41:59Z")

</div>

Hi Team, Binding API response in Kibana Vega. Is it possible to bind API response in Kibana Vega to dynamically bind the data?

---

## [Search in Kibana with big amount of data](https://discuss.elastic.co/t/search-in-kibana-with-big-amount-of-data/328324)

<div class="topic-metadata">

**Author:** [@vladislav](https://discuss.elastic.co/u/vladislav)\
**Replies:** 3\
**Last updated:** [March 23, 2023, 8:55pm UTC](https://discuss.elastic.co/t/search-in-kibana-with-big-amount-of-data/328324 "2023-03-23T20:55:05Z")

</div>

Hello! Thanks for help in advance. I have a pretty big index about 80+ Gib of data containing multiple fields, such as ip addresses, time, requests, etc. And I need to make a search of around 1000 unique addresses in t…

---

## [Fscrawler - change the index mapping，reduce redundant field or object](https://discuss.elastic.co/t/fscrawler-change-the-index-mapping-reduce-redundant-field-or-object/328296)

<div class="topic-metadata">

**Author:** [@bolo](https://discuss.elastic.co/u/bolo)\
**Replies:** 4\
**Last updated:** [March 23, 2023, 8:04pm UTC](https://discuss.elastic.co/t/fscrawler-change-the-index-mapping-reduce-redundant-field-or-object/328296 "2023-03-23T20:04:04Z")

</div>

i am new to fscrawler and really appreciate it. i know, the mapping can be changed. But to which content？just the analyzer? or the field type ? or the whole structure(because i dont want too much inner object). thank you …

---

## [Strange authentication error](https://discuss.elastic.co/t/strange-authentication-error/328385)

<div class="topic-metadata">

**Author:** [@PTLyon](https://discuss.elastic.co/u/PTLyon)\
**Replies:** 2\
**Last updated:** [March 23, 2023, 7:59pm UTC](https://discuss.elastic.co/t/strange-authentication-error/328385 "2023-03-23T19:59:12Z")

</div>

Hello, I have been running the ELK stack 8.6.2 for a month now with no problems, but I had security disabled. Today I attempted to enable security following this documentation: https://www.elastic.co/guide/en/elasticse…

---

## [Error connecting to node kafka-broker:9092 (id: 1 rack: null) java.net.UnknownHostException: kafka-broker](https://discuss.elastic.co/t/error-connecting-to-node-kafka-broker-9092-id-1-rack-null-java-net-unknownhostexception-kafka-broker/327434)

<div class="topic-metadata">

**Author:** [@Rajesh\_R](https://discuss.elastic.co/u/Rajesh_R)\
**Replies:** 3\
**Last updated:** [March 23, 2023, 7:31pm UTC](https://discuss.elastic.co/t/error-connecting-to-node-kafka-broker-9092-id-1-rack-null-java-net-unknownhostexception-kafka-broker/327434 "2023-03-23T19:31:43Z")

</div>

When I use kafka plugin in logstash, I am getting the below error. \[2023-03-10T15:11:46,310\]\[WARN \]\[org.apache.kafka.clients.NetworkClient\]\[main\]\[289f84d5c44d64af9505535a5352178af25a608c83252a1c520ab39a4faa4855\] \[Consum…

---

## [Permission denied /usr/share/logstash/run](https://discuss.elastic.co/t/permission-denied-usr-share-logstash-run/327769)

<div class="topic-metadata">

**Author:** [@RJC](https://discuss.elastic.co/u/RJC)\
**Replies:** 3\
**Last updated:** [March 23, 2023, 7:29pm UTC](https://discuss.elastic.co/t/permission-denied-usr-share-logstash-run/327769 "2023-03-23T19:29:51Z")

</div>

I am getting the following error message when starting Logstash on a Linux server: \[ERROR\]\[logstash.java.pipeline \]\[main\] Pipeline worker error, the pipeline will be stopped (:pipeline\_id=\>"main", :error=\>" (EACCESS) Pe…

---

## [Strip array off of ndjson data set using elasticsearch pipeline](https://discuss.elastic.co/t/strip-array-off-of-ndjson-data-set-using-elasticsearch-pipeline/328118)

<div class="topic-metadata">

**Author:** [@nika](https://discuss.elastic.co/u/nika)\
**Replies:** 4\
**Last updated:** [March 23, 2023, 6:44pm UTC](https://discuss.elastic.co/t/strip-array-off-of-ndjson-data-set-using-elasticsearch-pipeline/328118 "2023-03-23T18:44:08Z")

</div>

Hello, I have data being ingested into elasticsearch (currently using version 7.3) sent to it from filebeat (7.3). The logs are in ndjson format. A section of the data is in the format {"tagset": {"username": { "domain…

---

## [Logstash S3 input not deleting files](https://discuss.elastic.co/t/logstash-s3-input-not-deleting-files/328386)

<div class="topic-metadata">

**Author:** [@true64gurus](https://discuss.elastic.co/u/true64gurus)\
**Replies:** 0\
**Last updated:** [March 23, 2023, 6:17pm UTC](https://discuss.elastic.co/t/logstash-s3-input-not-deleting-files/328386 "2023-03-23T18:17:41Z")

</div>

I am using logstash S3 input plugin. The plugin is not deleting logs post ingestion. I am running logstsash docker on VM and have "delete =\> true". I have job running to delete logs older than 7 days and this is how I …

---

## [Version\_conflict\_engine\_exception](https://discuss.elastic.co/t/version-conflict-engine-exception/326418)

<div class="topic-metadata">

**Author:** [@INS](https://discuss.elastic.co/u/INS)\
**Replies:** 1\
**Last updated:** [March 23, 2023, 5:38pm UTC](https://discuss.elastic.co/t/version-conflict-engine-exception/326418 "2023-03-23T17:38:35Z")

</div>

Hi Can You explain me what was happened on the kibana, it was crashed and this is the tail logs from the docker container. I'm using kibana 8.1.1 \[2023-02-23T19:59:28.069+00:00\]\[ERROR\]\[plugins.dataEnhanced.data\_enhanced…

---

## [Elastic-agent "Process another repeated request" in loop indefinitely](https://discuss.elastic.co/t/elastic-agent-process-another-repeated-request-in-loop-indefinitely/328251)

<div class="topic-metadata">

**Author:** [@Nicolas\_Pellletier](https://discuss.elastic.co/u/Nicolas_Pellletier)\
**Replies:** 5\
**Last updated:** [March 23, 2023, 4:45pm UTC](https://discuss.elastic.co/t/elastic-agent-process-another-repeated-request-in-loop-indefinitely/328251 "2023-03-23T16:45:41Z")

</div>

Hello, I've got an elastic-agent with no agent monitoring settings (meaning no Agent Logs/Mertrics collection) and only one integration policy. So my elastic-agent.yml is pretty small: id: 949c1a80-c8a9-11ed-8539-532f…

---

## [Kibana from charts to excel](https://discuss.elastic.co/t/kibana-from-charts-to-excel/328368)

<div class="topic-metadata">

**Author:** [@Fatiha](https://discuss.elastic.co/u/Fatiha)\
**Replies:** 1\
**Last updated:** [March 23, 2023, 4:41pm UTC](https://discuss.elastic.co/t/kibana-from-charts-to-excel/328368 "2023-03-23T16:41:41Z")

</div>

hi I want to developp a plugin that export from the chart in kibana to excel

---

## [Heartbeat in eks](https://discuss.elastic.co/t/heartbeat-in-eks/328360)

<div class="topic-metadata">

**Author:** [@amar12](https://discuss.elastic.co/u/amar12)\
**Replies:** 1\
**Last updated:** [March 23, 2023, 4:31pm UTC](https://discuss.elastic.co/t/heartbeat-in-eks/328360 "2023-03-23T16:31:18Z")

</div>

Hi , I want to provision the heart beat in eks , I have purchased the elastic apm account . i want to do the service uptime monitoring.

---

## [WARN message when trying to install on windows 10](https://discuss.elastic.co/t/warn-message-when-trying-to-install-on-windows-10/328348)

<div class="topic-metadata">

**Author:** [@Ene\_Dragos](https://discuss.elastic.co/u/Ene_Dragos)\
**Replies:** 10\
**Last updated:** [March 23, 2023, 4:08pm UTC](https://discuss.elastic.co/t/warn-message-when-trying-to-install-on-windows-10/328348 "2023-03-23T16:08:19Z")

</div>

Hi! I'm trying to install elasticsearch on windows and i've followed the guid on here: Install Elasticsearch with .zip on Windows | Elasticsearch Guide \[8.6\] | Elastic. The issue is, when I try to configure Elasticsearc…

---

## [Error in parsing some logs from firewall due to object being returned](https://discuss.elastic.co/t/error-in-parsing-some-logs-from-firewall-due-to-object-being-returned/328349)

<div class="topic-metadata">

**Author:** [@viera120](https://discuss.elastic.co/u/viera120)\
**Replies:** 1\
**Last updated:** [March 23, 2023, 3:57pm UTC](https://discuss.elastic.co/t/error-in-parsing-some-logs-from-firewall-due-to-object-being-returned/328349 "2023-03-23T15:57:57Z")

</div>

Hi all, The setup is: Firewall --\> Filebeat --\> Logstash --\> Elasticsearch The following error keeps appearing in /var/log/logstash/logstash-plain.log \[2023-03-23T18:03:53,651\]\[WARN \]\[logstash.outputs.elasticsearch\]\[…

---

## [Kafka sink Connector to Elasticsearch](https://discuss.elastic.co/t/kafka-sink-connector-to-elasticsearch/328361)

<div class="topic-metadata">

**Author:** [@searchwithme](https://discuss.elastic.co/u/searchwithme)\
**Replies:** 1\
**Last updated:** [March 23, 2023, 3:20pm UTC](https://discuss.elastic.co/t/kafka-sink-connector-to-elasticsearch/328361 "2023-03-23T15:20:15Z")

</div>

I am trying to set up ingestion pipeline to elasticsearch cluster via kafka sink connector. A question I have is if I have a doc that haas multiple json objects like this: \[ {"name":"abc", "company":"123","dept":"test"…

---

## [Wrong calculations - ruby code](https://discuss.elastic.co/t/wrong-calculations-ruby-code/328093)

<div class="topic-metadata">

**Author:** [@wedkarz014](https://discuss.elastic.co/u/wedkarz014)\
**Replies:** 1\
**Last updated:** [March 23, 2023, 3:13pm UTC](https://discuss.elastic.co/t/wrong-calculations-ruby-code/328093 "2023-03-23T15:13:40Z")

</div>

Hi all, logstash v.7.17.8 I have ~45 metrics to calculate, here is the example, code and results: ruby { code =\> " if !event.get('\[Package2VersionCreatesWithoutValidation\]\[Max\]').nil? and !e…

---

## [How to Install heartbeat in Openshift](https://discuss.elastic.co/t/how-to-install-heartbeat-in-openshift/328048)

<div class="topic-metadata">

**Author:** [@kiran7373](https://discuss.elastic.co/u/kiran7373)\
**Replies:** 1\
**Last updated:** [March 23, 2023, 3:06pm UTC](https://discuss.elastic.co/t/how-to-install-heartbeat-in-openshift/328048 "2023-03-23T15:06:57Z")

</div>

Our need is to install heartbeat service in Openshift . Unable to find good documentation . Can anyone please suggest.

[Previous page](https://discuss.elastic.co/c/elastic-stack/81.md?page=592)

[Next page](https://discuss.elastic.co/c/elastic-stack/81.md?page=594)
