# Elastic Stack

**URL:** https://discuss.elastic.co/c/elastic-stack/81.md?page=608

[Latest](https://discuss.elastic.co/latest.md) · [Categories](https://discuss.elastic.co/categories.md) · [Tags](https://discuss.elastic.co/tags.md)

**Page:** 609

---

## [Finding similar/related news articles process](https://discuss.elastic.co/t/finding-similar-related-news-articles-process/327427)

<div class="topic-metadata">

**Author:** [@cyril\_g](https://discuss.elastic.co/u/cyril_g)\
**Replies:** 0\
**Last updated:** [March 10, 2023, 9:12am UTC](https://discuss.elastic.co/t/finding-similar-related-news-articles-process/327427 "2023-03-10T09:12:15Z")

</div>

Hello, I am working on a news app in the gaming industry and I would like to be able to identify headlines/ articles with titles about the same subject. One thing to note is that games and platforms have many alternati…

---

## [Cannot race. too many values to unpack (expected 2) error while benchmarking](https://discuss.elastic.co/t/cannot-race-too-many-values-to-unpack-expected-2-error-while-benchmarking/327214)

<div class="topic-metadata">

**Author:** [@amitsa](https://discuss.elastic.co/u/amitsa)\
**Replies:** 8\
**Last updated:** [March 10, 2023, 9:02am UTC](https://discuss.elastic.co/t/cannot-race-too-many-values-to-unpack-expected-2-error-while-benchmarking/327214 "2023-03-10T09:02:08Z")

</div>

/ /\_/ / \_\_ \`/ / / / / / \[pod/benchmark-rb8nf/benchmark\] / \_, \_/ /\_/ / / / /\_/ / \[pod/benchmark-rb8nf/benchmark\] /\_/ |\_|\\\_\_,\_/\_/\_/\\\_\_, / \[pod/benchmark-rb8nf/benchmark\] /\_\_\_\_/ \[pod/benchmark-rb8nf/benchma…

---

## [How Exclude option in kibana tag cloud works?](https://discuss.elastic.co/t/how-exclude-option-in-kibana-tag-cloud-works/327365)

<div class="topic-metadata">

**Author:** [@Mehran\_Goodarzi](https://discuss.elastic.co/u/Mehran_Goodarzi)\
**Replies:** 0\
**Last updated:** [March 9, 2023, 1:40pm UTC](https://discuss.elastic.co/t/how-exclude-option-in-kibana-tag-cloud-works/327365 "2023-03-09T13:40:04Z")

</div>

Hi there, I have a field called "Ticket Text" that has fielddata enabled, the field contains paragraphs of text, when I use Exclude option to exclude words like : "at","in", "the" does it exclude only the word or the w…

---

## [How much user can login at same time for basic license ELK version 8.0.0](https://discuss.elastic.co/t/how-much-user-can-login-at-same-time-for-basic-license-elk-version-8-0-0/327383)

<div class="topic-metadata">

**Author:** [@Gaurav\_kr](https://discuss.elastic.co/u/Gaurav_kr)\
**Replies:** 3\
**Last updated:** [March 10, 2023, 8:21am UTC](https://discuss.elastic.co/t/how-much-user-can-login-at-same-time-for-basic-license-elk-version-8-0-0/327383 "2023-03-10T08:21:59Z")

</div>

Hi Team, I am using basic license of ELK version 8.0.0 , wanted to know how many user can login at same time we are using a docker image for setting it up.

---

## [Elastic Agent with custom log integration](https://discuss.elastic.co/t/elastic-agent-with-custom-log-integration/327341)

<div class="topic-metadata">

**Author:** [@eleong](https://discuss.elastic.co/u/eleong)\
**Replies:** 10\
**Last updated:** [March 10, 2023, 7:53am UTC](https://discuss.elastic.co/t/elastic-agent-with-custom-log-integration/327341 "2023-03-10T07:53:37Z")

</div>

Hi, Ran into issue which is quite puzzling. Referred to the official docs and some topics in this forum but it did not help. I am trying to ingest custom logs via integration within elastic agent. Everything is working…

---

## [How to filter the buckets that have more than N documents using ElasticSearch DSL in python?](https://discuss.elastic.co/t/how-to-filter-the-buckets-that-have-more-than-n-documents-using-elasticsearch-dsl-in-python/327412)

<div class="topic-metadata">

**Author:** [@Ashar\_Ahmad](https://discuss.elastic.co/u/Ashar_Ahmad)\
**Replies:** 0\
**Last updated:** [March 10, 2023, 4:41am UTC](https://discuss.elastic.co/t/how-to-filter-the-buckets-that-have-more-than-n-documents-using-elasticsearch-dsl-in-python/327412 "2023-03-10T04:41:09Z")

</div>

I have an index in Elasticsearch that contains information of a user in each document, along with the facebook posts they have made (in a denormalized manner). Each document contains: User\_ID | User\_Name | Post\_Text | P…

---

## [Cannot add new CA to keystore](https://discuss.elastic.co/t/cannot-add-new-ca-to-keystore/326767)

<div class="topic-metadata">

**Author:** [@alrubaa](https://discuss.elastic.co/u/alrubaa)\
**Replies:** 3\
**Last updated:** [March 10, 2023, 12:37am UTC](https://discuss.elastic.co/t/cannot-add-new-ca-to-keystore/326767 "2023-03-10T00:37:10Z")

</div>

Hi All, I have an ELasticsearch cluster of 12 nodes running 8.2 and the certificates have expired, just crossed 3 years which I did not realise. I have been trying to follow the instructions on Update security certifica…

---

## [Prometheus collector query defined once, applied everywhere](https://discuss.elastic.co/t/prometheus-collector-query-defined-once-applied-everywhere/327400)

<div class="topic-metadata">

**Author:** [@jeanfabrice](https://discuss.elastic.co/u/jeanfabrice)\
**Replies:** 0\
**Last updated:** [March 9, 2023, 10:33pm UTC](https://discuss.elastic.co/t/prometheus-collector-query-defined-once-applied-everywhere/327400 "2023-03-09T22:33:31Z")

</div>

Hi, I'm using Metricbeat 8.6.2 and I'm trying to collect Prometheus metrics using the official Prom snmp exporter. This particular exporter requires passing a URL query string to configure the snmp endpoint to collect t…

---

## [Unassigned.reason CLUSTER\_RECOVERED](https://discuss.elastic.co/t/unassigned-reason-cluster-recovered/327370)

<div class="topic-metadata">

**Author:** [@frankmehlhop.com](https://discuss.elastic.co/u/frankmehlhop.com)\
**Replies:** 1\
**Last updated:** [March 9, 2023, 8:05pm UTC](https://discuss.elastic.co/t/unassigned-reason-cluster-recovered/327370 "2023-03-09T20:05:34Z")

</div>

My health status is only yellow instead of green. { "cluster\_name" : "elasticsearch", "status" : "yellow", "timed\_out" : false, "number\_of\_nodes" : 1, "number\_of\_data\_nodes" : 1, "active\_primary\_shards" : 22…

---

## [Does this mean my "\_id" field is taking up GB of RAM?](https://discuss.elastic.co/t/does-this-mean-my-id-field-is-taking-up-gb-of-ram/327128)

<div class="topic-metadata">

**Author:** [@linkerc](https://discuss.elastic.co/u/linkerc)\
**Replies:** 3\
**Last updated:** [March 9, 2023, 6:39pm UTC](https://discuss.elastic.co/t/does-this-mean-my-id-field-is-taking-up-gb-of-ram/327128 "2023-03-09T18:39:27Z")

</div>

\[fielddata\] New used memory 13315258923 \[12.4gb\] for data of \[\_id\] would be larger than configured breaker: 13314398617 \[12.3gb\], breaking I'm getting the above warning and wondering why. Does it mean my "\_id" field (t…

---

## [\[HELP! ! \] About ILM (IndexLifecycleManagement) of ElasticSearch](https://discuss.elastic.co/t/help-about-ilm-indexlifecyclemanagement-of-elasticsearch/326813)

<div class="topic-metadata">

**Author:** [@YUUTA.INOUE-JPN](https://discuss.elastic.co/u/YUUTA.INOUE-JPN)\
**Replies:** 10\
**Last updated:** [March 9, 2023, 4:38pm UTC](https://discuss.elastic.co/t/help-about-ilm-indexlifecyclemanagement-of-elasticsearch/326813 "2023-03-09T16:38:56Z")

</div>

Hello from Japan I have a question for you dear engineers I'm using Elasticsearch 7.6.2 and want to remove the accumulated indexes The created ILM policy rolls over at 50GB/30 days, and I created an ILM policy that de…

---

## [Watches not writing to wacher history](https://discuss.elastic.co/t/watches-not-writing-to-wacher-history/327364)

<div class="topic-metadata">

**Author:** [@Sagi\_Bensimon](https://discuss.elastic.co/u/Sagi_Bensimon)\
**Replies:** 3\
**Last updated:** [March 9, 2023, 5:38pm UTC](https://discuss.elastic.co/t/watches-not-writing-to-wacher-history/327364 "2023-03-09T17:38:23Z")

</div>

.watcher-history indices aren't being created and are also missing. There aren't any errors and action.auto\_create\_index isn't set anywhere.

---

## [Elastic-agent updates](https://discuss.elastic.co/t/elastic-agent-updates/327382)

<div class="topic-metadata">

**Author:** [@stobbe](https://discuss.elastic.co/u/stobbe)\
**Replies:** 0\
**Last updated:** [March 9, 2023, 5:00pm UTC](https://discuss.elastic.co/t/elastic-agent-updates/327382 "2023-03-09T17:00:14Z")

</div>

Hello, If I understand correctly, if you update an agent to a new version, the software (binaries) have to be downloaded from a repository. The extra "plugins" are available from kibana Simple question, why not use Ki…

---

## [Statuscode-404-error-not-found-message-not-found](https://discuss.elastic.co/t/statuscode-404-error-not-found-message-not-found/327359)

<div class="topic-metadata">

**Author:** [@thomas4](https://discuss.elastic.co/u/thomas4)\
**Replies:** 1\
**Last updated:** [March 9, 2023, 4:13pm UTC](https://discuss.elastic.co/t/statuscode-404-error-not-found-message-not-found/327359 "2023-03-09T16:13:29Z")

</div>

Hi all, I created a space and when i try to login to it i get the message above, but if i sign in with the super user account and then sign out, and sign in with my new space account it works. Any help would be grateful. …

---

## [Disappearing Documents on Batch Upload with Enrich Policy](https://discuss.elastic.co/t/disappearing-documents-on-batch-upload-with-enrich-policy/327377)

<div class="topic-metadata">

**Author:** [@cj\_hillbrand](https://discuss.elastic.co/u/cj_hillbrand)\
**Replies:** 0\
**Last updated:** [March 9, 2023, 4:12pm UTC](https://discuss.elastic.co/t/disappearing-documents-on-batch-upload-with-enrich-policy/327377 "2023-03-09T16:12:39Z")

</div>

Hey folks, My team and I are evaluating some interesting behavior when our system attempts to batch upload documents to our Elasticsearch store. We are noticing that occasionally a collection of documents that we expect…

---

## [Static variables in Kibana discovery script](https://discuss.elastic.co/t/static-variables-in-kibana-discovery-script/327125)

<div class="topic-metadata">

**Author:** [@gyannea](https://discuss.elastic.co/u/gyannea)\
**Replies:** 6\
**Last updated:** [March 9, 2023, 3:41pm UTC](https://discuss.elastic.co/t/static-variables-in-kibana-discovery-script/327125 "2023-03-09T15:41:23Z")

</div>

What should be something very simple. I want to create a new field for a Kibana discovery and dashboard that simply counts the received document. So each document will have an index 0, 1, 2, ..., n. However, I do not se…

---

## [Not able to parse geojson data in logstash](https://discuss.elastic.co/t/not-able-to-parse-geojson-data-in-logstash/325247)

<div class="topic-metadata">

**Author:** [@aaryan](https://discuss.elastic.co/u/aaryan)\
**Replies:** 1\
**Last updated:** [March 9, 2023, 3:35pm UTC](https://discuss.elastic.co/t/not-able-to-parse-geojson-data-in-logstash/325247 "2023-03-09T15:35:45Z")

</div>

This is the config I am using. input { file { path =\> "D:/Softwares/ELK/data/geojson/features.geojson" start\_position =\> "beginning" sincedb\_path =\> "D:/Softwares/ELK/data/cache/geojsontry.txt" codec =\> mult…

---

## [Integration Elastic Dashboard to Power BI Visualization](https://discuss.elastic.co/t/integration-elastic-dashboard-to-power-bi-visualization/327018)

<div class="topic-metadata">

**Author:** [@aisyaharifin](https://discuss.elastic.co/u/aisyaharifin)\
**Replies:** 6\
**Last updated:** [March 9, 2023, 3:29pm UTC](https://discuss.elastic.co/t/integration-elastic-dashboard-to-power-bi-visualization/327018 "2023-03-09T15:29:07Z")

</div>

Hi, I would like to ask is there any way I could integrate my Elastic Dashboard to Power BI? I have a situation to export my Elastic Uptime Availability Dashboard to Power BI. Is there any way I could just drop the…

---

## [\[ES 8.6.1 & 8.6.2\] Fleet's "Custom Logs" integration stops sending logs with "failed to publish events: temporary bulk send failure" message](https://discuss.elastic.co/t/es-8-6-1-8-6-2-fleets-custom-logs-integration-stops-sending-logs-with-failed-to-publish-events-temporary-bulk-send-failure-message/327293)

<div class="topic-metadata">

**Author:** [@BorisNaguet](https://discuss.elastic.co/u/BorisNaguet)\
**Replies:** 0\
**Last updated:** [March 8, 2023, 5:08pm UTC](https://discuss.elastic.co/t/es-8-6-1-8-6-2-fleets-custom-logs-integration-stops-sending-logs-with-failed-to-publish-events-temporary-bulk-send-failure-message/327293 "2023-03-08T17:08:35Z")

</div>

Hello, I'm new to Elastic, so it's possible that I configured something wrong... Also, please be precise on where/how to find things if you ask for more info. Base installationI installed a fresh Elastic recently: 8…

---

## ["Unable to completely restore the URL" when viewing results from osquery in discover](https://discuss.elastic.co/t/unable-to-completely-restore-the-url-when-viewing-results-from-osquery-in-discover/327231)

<div class="topic-metadata">

**Author:** [@nemhods](https://discuss.elastic.co/u/nemhods)\
**Replies:** 1\
**Last updated:** [March 9, 2023, 3:07pm UTC](https://discuss.elastic.co/t/unable-to-completely-restore-the-url-when-viewing-results-from-osquery-in-discover/327231 "2023-03-09T15:07:37Z")

</div>

Hey, When investigating the results from osquery, I want to use the "View in Discover" button: It leads me to discover, but applies no filters and shows an error popup with the message "Unable to completely restore …

---

## [Logstash log file location](https://discuss.elastic.co/t/logstash-log-file-location/327307)

<div class="topic-metadata">

**Author:** [@elasticforme](https://discuss.elastic.co/u/elasticforme)\
**Replies:** 2\
**Last updated:** [March 9, 2023, 2:57pm UTC](https://discuss.elastic.co/t/logstash-log-file-location/327307 "2023-03-09T14:57:19Z")

</div>

I am running logstash as daemon via systemd I get my log in to my special log dir /log/logstash/logstash-plain.log but I also get that in /var/log/message. I want to stop them and I read that it is control by log4j2 fi…

---

## [Format a Scripted Date Field](https://discuss.elastic.co/t/format-a-scripted-date-field/327309)

<div class="topic-metadata">

**Author:** [@ashryver1995](https://discuss.elastic.co/u/ashryver1995)\
**Replies:** 1\
**Last updated:** [March 9, 2023, 2:55pm UTC](https://discuss.elastic.co/t/format-a-scripted-date-field/327309 "2023-03-09T14:55:54Z")

</div>

Hi, I have a scripted field using painless that is referencing from an existing field in my index. Below is the code snippet: if(doc\['market'\].value == 'SAMPLE'){ if (doc\['date field\].size()==0){ return ''…

---

## [Index sorting with two order values in the same field](https://discuss.elastic.co/t/index-sorting-with-two-order-values-in-the-same-field/327333)

<div class="topic-metadata">

**Author:** [@joaoantao](https://discuss.elastic.co/u/joaoantao)\
**Replies:** 0\
**Last updated:** [March 9, 2023, 8:33am UTC](https://discuss.elastic.co/t/index-sorting-with-two-order-values-in-the-same-field/327333 "2023-03-09T08:33:53Z")

</div>

I am trying to improve queries in one index with ~ 125 million documents and 3 shards. Most of the queries hitting this index have a sort order for a given field with values ascending and descending. Currently the index…

---

## [Adding watcher condition](https://discuss.elastic.co/t/adding-watcher-condition/326763)

<div class="topic-metadata">

**Author:** [@alextg](https://discuss.elastic.co/u/alextg)\
**Replies:** 6\
**Last updated:** [March 9, 2023, 2:23pm UTC](https://discuss.elastic.co/t/adding-watcher-condition/326763 "2023-03-09T14:23:10Z")

</div>

Hello, I'm looking to add a new condition to my working watcher. Currently, it alerts when the index doesn't received logs in the last 10 minutes (see below). The functionality I'm trying to add is to alert when the ind…

---

## [Group input values in Bar Chart Aggregation](https://discuss.elastic.co/t/group-input-values-in-bar-chart-aggregation/327306)

<div class="topic-metadata">

**Author:** [@Miriam99](https://discuss.elastic.co/u/Miriam99)\
**Replies:** 1\
**Last updated:** [March 9, 2023, 2:22pm UTC](https://discuss.elastic.co/t/group-input-values-in-bar-chart-aggregation/327306 "2023-03-09T14:22:37Z")

</div>

If I have documents where value.keyword = A1, value.keyword = A2 ... A3, B1, B2, B3 How would I get all of the A values to group together and B values to group together instead of having 6 separate bars on my graph? Th…

---

## [Stackoverflow error on logstash when using es\_bulk codec](https://discuss.elastic.co/t/stackoverflow-error-on-logstash-when-using-es-bulk-codec/327337)

<div class="topic-metadata">

**Author:** [@eeijlar](https://discuss.elastic.co/u/eeijlar)\
**Replies:** 1\
**Last updated:** [March 9, 2023, 2:17pm UTC](https://discuss.elastic.co/t/stackoverflow-error-on-logstash-when-using-es-bulk-codec/327337 "2023-03-09T14:17:45Z")

</div>

Using the following pipeline with logstash: - pipeline.id: export-process pipeline.workers: 4 config.string: | input { elasticsearch { hosts =\> "http://elastic:80/elasticsearch/…

---

## [Meta data not written to logstash output file](https://discuss.elastic.co/t/meta-data-not-written-to-logstash-output-file/327366)

<div class="topic-metadata">

**Author:** [@eeijlar](https://discuss.elastic.co/u/eeijlar)\
**Replies:** 0\
**Last updated:** [March 9, 2023, 2:02pm UTC](https://discuss.elastic.co/t/meta-data-not-written-to-logstash-output-file/327366 "2023-03-09T14:02:14Z")

</div>

I am using the following logstash pipeline: - pipeline.id: export-process pipeline.workers: 4 config.string: | input { elasticsearch { hosts =\> "http://elastic:80/elasticsearch/…

---

## [The chart shows a time beyond what's actually in data](https://discuss.elastic.co/t/the-chart-shows-a-time-beyond-whats-actually-in-data/327292)

<div class="topic-metadata">

**Author:** [@SamuelSMendes](https://discuss.elastic.co/u/SamuelSMendes)\
**Replies:** 1\
**Last updated:** [March 9, 2023, 1:57pm UTC](https://discuss.elastic.co/t/the-chart-shows-a-time-beyond-whats-actually-in-data/327292 "2023-03-09T13:57:54Z")

</div>

So I'm making this chart to pick up some data cross time but the chart shows data that doesn't exist yet. In a time that is yet to come: Latest timestamp in preview: The chart: How can I make so the chart will fol…

---

## [Kibana Lens - Cannot cutomize timestamp on several months, weeks or years](https://discuss.elastic.co/t/kibana-lens-cannot-cutomize-timestamp-on-several-months-weeks-or-years/327156)

<div class="topic-metadata">

**Author:** [@xchess64](https://discuss.elastic.co/u/xchess64)\
**Replies:** 1\
**Last updated:** [March 9, 2023, 1:31pm UTC](https://discuss.elastic.co/t/kibana-lens-cannot-cutomize-timestamp-on-several-months-weeks-or-years/327156 "2023-03-09T13:31:15Z")

</div>

I am creating a Lens Visualization on Kibana 7.17 When I try to customize my timestamp to aggregate data on several days, I can do it easily However, when I try to aggregate my data on several weeks, months or years…

---

## [Issue with removing tag](https://discuss.elastic.co/t/issue-with-removing-tag/327193)

<div class="topic-metadata">

**Author:** [@Harika](https://discuss.elastic.co/u/Harika)\
**Replies:** 1\
**Last updated:** [March 9, 2023, 1:27pm UTC](https://discuss.elastic.co/t/issue-with-removing-tag/327193 "2023-03-09T13:27:03Z")

</div>

we are having the \<system-out\>\<!\[CDATA\[\]\]\>\</system-out\> tag in our XML File. Due to this tag it could not index and throwing the below Error: "error"=\>{"type"=\>"illegal\_argument\_exception", "reason"=\>"can't merge a non …

[Previous page](https://discuss.elastic.co/c/elastic-stack/81.md?page=607)

[Next page](https://discuss.elastic.co/c/elastic-stack/81.md?page=609)
