# Latest

**URL:** https://discuss.elastic.co/latest.md?page=681

[Latest](https://discuss.elastic.co/latest.md) · [Categories](https://discuss.elastic.co/categories.md) · [Tags](https://discuss.elastic.co/tags.md)

**Page:** 682

---

## [Deprecation Log Spam](https://discuss.elastic.co/t/deprecation-log-spam/332851)

<div class="topic-metadata">

**Author:** [@wwalker](https://discuss.elastic.co/u/wwalker)\
**Replies:** 2\
**Last updated:** [May 11, 2023, 3:43pm UTC](https://discuss.elastic.co/t/deprecation-log-spam/332851 "2023-05-11T15:43:02Z")

</div>

The below line is blowing up my log files. What is it and what do I need to do to get it to stop? \[2023-05-03T22:10:15,259\]\[WARN \]\[o.e.d.c.m.IndexNameExpressionResolver\] \[elastic.contoso.net\] data\_stream.dataset="depre…

---

## [UpdateByQueryRequest.setMaxRetries does not seems available in ElasticSearch version 8 Java Client](https://discuss.elastic.co/t/updatebyqueryrequest-setmaxretries-does-not-seems-available-in-elasticsearch-version-8-java-client/333222)

<div class="topic-metadata">

**Author:** [@csplrj](https://discuss.elastic.co/u/csplrj)\
**Replies:** 0\
**Last updated:** [May 11, 2023, 3:41pm UTC](https://discuss.elastic.co/t/updatebyqueryrequest-setmaxretries-does-not-seems-available-in-elasticsearch-version-8-java-client/333222 "2023-05-11T15:41:42Z")

</div>

Below code is for Elasticsearch Client version 7.17. Can't find equivalent code in Elasticsearch Client version 8.7 Script storedScript = new Script(ScriptType.STORED, null, script.getScriptId(), (Map\<String, Object\>) s…

---

## [How to interpret CPU and memory stats?](https://discuss.elastic.co/t/how-to-interpret-cpu-and-memory-stats/332976)

<div class="topic-metadata">

**Author:** [@Ankita\_Pachauri](https://discuss.elastic.co/u/Ankita_Pachauri)\
**Replies:** 2\
**Last updated:** [May 11, 2023, 3:29pm UTC](https://discuss.elastic.co/t/how-to-interpret-cpu-and-memory-stats/332976 "2023-05-11T15:29:38Z")

</div>

Hi! Filebeat logs metric stats in its log file, I am wondering what CPU and memstat mean. Do these show CPU and memory utilization of the beat on the server? Adding a sample for reference. 2023-05-05T10:26:56.954Z …

---

## [Question logstash | Events received vs Event emitted](https://discuss.elastic.co/t/question-logstash-events-received-vs-event-emitted/333219)

<div class="topic-metadata">

**Author:** [@ahmed\_charafouddine](https://discuss.elastic.co/u/ahmed_charafouddine)\
**Replies:** 0\
**Last updated:** [May 11, 2023, 3:20pm UTC](https://discuss.elastic.co/t/question-logstash-events-received-vs-event-emitted/333219 "2023-05-11T15:20:04Z")

</div>

Hello, On the monitoring part of my logstash instance, I see that I have 1.3b of events received against 784.7m events emitted. can the fact that I drop certain messages in my pipeline explain this phenomenon or is it r…

---

## [Fastest way to ingest CSV's with logstash to elasticsearch](https://discuss.elastic.co/t/fastest-way-to-ingest-csvs-with-logstash-to-elasticsearch/333118)

<div class="topic-metadata">

**Author:** [@Security\_Check](https://discuss.elastic.co/u/Security_Check)\
**Replies:** 8\
**Last updated:** [May 11, 2023, 3:19pm UTC](https://discuss.elastic.co/t/fastest-way-to-ingest-csvs-with-logstash-to-elasticsearch/333118 "2023-05-11T15:19:24Z")

</div>

I'm currently trying to ingest 100gb of csv files into elasticsearch through logstash. The issue is it's taking forever. I have narrowed down the columns I'm trying to filter for to 8 out of 71 but it still takes a long …

---

## [Multiple matches required](https://discuss.elastic.co/t/multiple-matches-required/333192)

<div class="topic-metadata">

**Author:** [@Jason\_Hall](https://discuss.elastic.co/u/Jason_Hall)\
**Replies:** 1\
**Last updated:** [May 11, 2023, 3:10pm UTC](https://discuss.elastic.co/t/multiple-matches-required/333192 "2023-05-11T15:10:31Z")

</div>

I am currently setting up some filters for my incoming Watchguard Firewall logs. The logs come in various different formats so i have to setup multiple match rules. My current filter is filter { #Watchguard logs filter…

---

## [Ingest data with Node.js on Elastic Search service](https://discuss.elastic.co/t/ingest-data-with-node-js-on-elastic-search-service/333082)

<div class="topic-metadata">

**Author:** [@newbie\_coder](https://discuss.elastic.co/u/newbie_coder)\
**Replies:** 1\
**Last updated:** [May 11, 2023, 2:58pm UTC](https://discuss.elastic.co/t/ingest-data-with-node-js-on-elastic-search-service/333082 "2023-05-11T14:58:03Z")

</div>

I have a simple app and I want to ingest data from my app to Elastic Search sevice. I followed the steps from this tutorial which seem pretty straightforward - get a free trial, create a deployment, then install with np…

---

## [Need to split in form of key & value](https://discuss.elastic.co/t/need-to-split-in-form-of-key-value/333218)

<div class="topic-metadata">

**Author:** [@ZERO\_COOL](https://discuss.elastic.co/u/ZERO_COOL)\
**Replies:** 0\
**Last updated:** [May 11, 2023, 2:40pm UTC](https://discuss.elastic.co/t/need-to-split-in-form-of-key-value/333218 "2023-05-11T14:40:09Z")

</div>

I am getting event as below. "rusage" =\> \[ \[0\] "", \[1\] "\[mem=10000,mem=5000,VCS-BASE-RUNTIME=1\]" \], I want the value of mem as res\_mem higher one among two keys with "mem" as new field. output: { res\_mem = 10000 …

---

## [Joining Two Indexes with common field values](https://discuss.elastic.co/t/joining-two-indexes-with-common-field-values/332861)

<div class="topic-metadata">

**Author:** [@sai\_ravi\_shankar](https://discuss.elastic.co/u/sai_ravi_shankar)\
**Replies:** 8\
**Last updated:** [May 11, 2023, 2:22pm UTC](https://discuss.elastic.co/t/joining-two-indexes-with-common-field-values/332861 "2023-05-11T14:22:30Z")

</div>

Hi, I am trying to join two indexes with common field values. Can someone please help me. Here is the example: Index\_1 =\> A column\_1 =\> value\_1 Index\_2 =\> B column\_2 =\> value\_1 How can i join both indexes on the…

---

## [Elasticsearch too\_many\_requests disk usage exceeded flood-stage watermark](https://discuss.elastic.co/t/elasticsearch-too-many-requests-disk-usage-exceeded-flood-stage-watermark/333111)

<div class="topic-metadata">

**Author:** [@LilBaloche](https://discuss.elastic.co/u/LilBaloche)\
**Replies:** 4\
**Last updated:** [May 11, 2023, 2:20pm UTC](https://discuss.elastic.co/t/elasticsearch-too-many-requests-disk-usage-exceeded-flood-stage-watermark/333111 "2023-05-11T14:20:49Z")

</div>

Hello, I've installed elasticsearch and kibana on a virtual Ubuntu Server and I'm pretty sure I do not have enough space on my virtual disk. I'm running on VSphere and I tried to add disk space but it doesn't extend el…

---

## [Using a Terms Query via Elastic.Clients.Elasticsearch 8.1.1 .NET](https://discuss.elastic.co/t/using-a-terms-query-via-elastic-clients-elasticsearch-8-1-1-net/332817)

<div class="topic-metadata">

**Author:** [@felix-stnr](https://discuss.elastic.co/u/felix-stnr)\
**Replies:** 2\
**Last updated:** [May 11, 2023, 2:20pm UTC](https://discuss.elastic.co/t/using-a-terms-query-via-elastic-clients-elasticsearch-8-1-1-net/332817 "2023-05-11T14:20:16Z")

</div>

I am currently trying to write a Terms Query via the Elastic.Clients.Elasticsearch 8.1.1 .NET client. To be more precise, I want to write following query in C#: GET persons/\_search { "query": { "bool": { "mu…

---

## [Kibana showing windows\_eventlog but not sysmon](https://discuss.elastic.co/t/kibana-showing-windows-eventlog-but-not-sysmon/333104)

<div class="topic-metadata">

**Author:** [@iqworks](https://discuss.elastic.co/u/iqworks)\
**Replies:** 2\
**Last updated:** [May 11, 2023, 1:57pm UTC](https://discuss.elastic.co/t/kibana-showing-windows-eventlog-but-not-sysmon/333104 "2023-05-11T13:57:01Z")

</div>

Hi, I finally got windows data into security onion. But I dont see sysmon categories? But I do show windows\_events? are windows\_eventlogs the same as sysmon maybe? not sure. thanks for any suggestions or advice

---

## [Filestream id](https://discuss.elastic.co/t/filestream-id/333075)

<div class="topic-metadata">

**Author:** [@haralambop](https://discuss.elastic.co/u/haralambop)\
**Replies:** 1\
**Last updated:** [May 11, 2023, 1:51pm UTC](https://discuss.elastic.co/t/filestream-id/333075 "2023-05-11T13:51:19Z")

</div>

I have several filestream inputs type: filestream id: filestream1 type: filestream id: filestream2 type: filestream id: filestream3 How can I inserts the Ids ( filestream1,filestream2,filestream3) in the e…

---

## [Elasticsearch in Docker : WARN "this node is locked into cluster UUID" on container restart](https://discuss.elastic.co/t/elasticsearch-in-docker-warn-this-node-is-locked-into-cluster-uuid-on-container-restart/333105)

<div class="topic-metadata">

**Author:** [@Bruno44](https://discuss.elastic.co/u/Bruno44)\
**Replies:** 3\
**Last updated:** [May 11, 2023, 1:41pm UTC](https://discuss.elastic.co/t/elasticsearch-in-docker-warn-this-node-is-locked-into-cluster-uuid-on-container-restart/333105 "2023-05-11T13:41:05Z")

</div>

Hello, I use Elasticsearch 8.7.1 in an official Docker container. I export the data (/usr/share/elasticsearch/data/) to the host to keep indexing data. If I delete the container (for update for example), when I recrea…

---

## [NEST equivalent code for an ML infer query](https://discuss.elastic.co/t/nest-equivalent-code-for-an-ml-infer-query/333007)

<div class="topic-metadata">

**Author:** [@virtualaidev](https://discuss.elastic.co/u/virtualaidev)\
**Replies:** 2\
**Last updated:** [May 11, 2023, 1:21pm UTC](https://discuss.elastic.co/t/nest-equivalent-code-for-an-ml-infer-query/333007 "2023-05-11T13:21:55Z")

</div>

Hi there, any NEST library documentation on how to infer query in ML? For instance I want to do the below: POST /\_ml/trained\_models/sentence-transformers\_\_all-minilm-l12-v2/\_infer { "docs": { "text\_field": "simil…

---

## [Filebeat.yml config file permissions owner](https://discuss.elastic.co/t/filebeat-yml-config-file-permissions-owner/333190)

<div class="topic-metadata">

**Author:** [@lmrc](https://discuss.elastic.co/u/lmrc)\
**Replies:** 2\
**Last updated:** [May 11, 2023, 1:17pm UTC](https://discuss.elastic.co/t/filebeat-yml-config-file-permissions-owner/333190 "2023-05-11T13:17:23Z")

</div>

Hello, I get an error when I start Filebeat about the permissions of the filebeat.yml file error loading config file: config file ("/etc/filebeat/filebeat.yml") can only be writable by the owner but the permissions are…

---

## [If statement performance question](https://discuss.elastic.co/t/if-statement-performance-question/333210)

<div class="topic-metadata">

**Author:** [@mgotechlock](https://discuss.elastic.co/u/mgotechlock)\
**Replies:** 0\
**Last updated:** [May 11, 2023, 12:43pm UTC](https://discuss.elastic.co/t/if-statement-performance-question/333210 "2023-05-11T12:43:59Z")

</div>

Question If I use this IF statement, if ("FTNTFGTpolicyname" in \[message\]) or ("FTNTFGTlogid" in \[message\]) {, the CPU of the logstash server spikes to very high, pretty much forever. If I change it to this, CPU is …

---

## [Configuración formato metric count](https://discuss.elastic.co/t/configuracion-formato-metric-count/333031)

<div class="topic-metadata">

**Author:** [@Javier\_Garcia\_Alvare](https://discuss.elastic.co/u/Javier_Garcia_Alvare)\
**Replies:** 3\
**Last updated:** [May 11, 2023, 12:42pm UTC](https://discuss.elastic.co/t/configuracion-formato-metric-count/333031 "2023-05-11T12:42:23Z")

</div>

Buenos días, Es posible dar formato a una metrica en una visualización tipo tabla? Es decir, cuando creas una tabla y la metrica la configuras como "Sum Bucket" o "count" el número se alinea en la parte de la izquierda…

---

## [Grok regex match after CSV filter: unable to add a new field from grok match in logstash](https://discuss.elastic.co/t/grok-regex-match-after-csv-filter-unable-to-add-a-new-field-from-grok-match-in-logstash/333206)

<div class="topic-metadata">

**Author:** [@rj.elkadmin](https://discuss.elastic.co/u/rj.elkadmin)\
**Replies:** 0\
**Last updated:** [May 11, 2023, 12:24pm UTC](https://discuss.elastic.co/t/grok-regex-match-after-csv-filter-unable-to-add-a-new-field-from-grok-match-in-logstash/333206 "2023-05-11T12:24:26Z")

</div>

Hi team, I am new to here, i apologize for any inconvenient. I am looking for some help on my issue here, kindly assist. My requirement is to process data from csv files located in s3 bucket using Logstash and ingest i…

---

## [How to combine two records into one with logstash and call a filter script before save into Elasticsearch](https://discuss.elastic.co/t/how-to-combine-two-records-into-one-with-logstash-and-call-a-filter-script-before-save-into-elasticsearch/332957)

<div class="topic-metadata">

**Author:** [@liusanyong](https://discuss.elastic.co/u/liusanyong)\
**Replies:** 3\
**Last updated:** [May 11, 2023, 12:23pm UTC](https://discuss.elastic.co/t/how-to-combine-two-records-into-one-with-logstash-and-call-a-filter-script-before-save-into-elasticsearch/332957 "2023-05-11T12:23:38Z")

</div>

Hi, I want to do some aggregation and transformation with logstash for input data stream as following steps: Combine two input metric events for a single transaction coming from transaction server and database into o…

---

## [Adding Processors / Pipelines to an integration attached to a policy breaks running agent (Error creating runner from config: Can only start an input when all related states are finished)](https://discuss.elastic.co/t/adding-processors-pipelines-to-an-integration-attached-to-a-policy-breaks-running-agent-error-creating-runner-from-config-can-only-start-an-input-when-all-related-states-are-finished/332909)

<div class="topic-metadata">

**Author:** [@mehdi-lamrani](https://discuss.elastic.co/u/mehdi-lamrani)\
**Replies:** 1\
**Last updated:** [May 11, 2023, 12:14pm UTC](https://discuss.elastic.co/t/adding-processors-pipelines-to-an-integration-attached-to-a-policy-breaks-running-agent-error-creating-runner-from-config-can-only-start-an-input-when-all-related-states-are-finished/332909 "2023-05-11T12:14:52Z")

</div>

8.7 here, Pretty self explanatory. Steps in the screenshots. Error creating runner from config: Can only start an input when all related states are finished What does related states mean ? there is only that single in…

---

## [Getting error "Could not index event to Elasticsearch" in logstash?](https://discuss.elastic.co/t/getting-error-could-not-index-event-to-elasticsearch-in-logstash/333198)

<div class="topic-metadata">

**Author:** [@talbehat](https://discuss.elastic.co/u/talbehat)\
**Replies:** 1\
**Last updated:** [May 11, 2023, 11:47am UTC](https://discuss.elastic.co/t/getting-error-could-not-index-event-to-elasticsearch-in-logstash/333198 "2023-05-11T11:47:25Z")

</div>

Using Logstash version 7.4.3 logstash-filter-json plugin. filter { json { source =\> "message" } } logs are:- {"Event":"SparkListenerJobStart","Job ID":1,"Submission Time":1640751467318,"Stage Infos":\[{"Stage ID":…

---

## [I want to get a status based on the date difference ersult](https://discuss.elastic.co/t/i-want-to-get-a-status-based-on-the-date-difference-ersult/333054)

<div class="topic-metadata">

**Author:** [@alig](https://discuss.elastic.co/u/alig)\
**Replies:** 1\
**Last updated:** [May 11, 2023, 11:41am UTC](https://discuss.elastic.co/t/i-want-to-get-a-status-based-on-the-date-difference-ersult/333054 "2023-05-11T11:41:32Z")

</div>

Hi there, This is what I am using in scripted fields def sorDate = new Date().getTime() - doc\['sor\_idate'\].value; if (sorDate \> 5){ return "crtical" }; The field is defined as below and I have an error and cannot f…

---

## [Unable to create new index \[.watches-6-reindexed-for-8\] because it would match composable template \[.watches\]](https://discuss.elastic.co/t/unable-to-create-new-index-watches-6-reindexed-for-8-because-it-would-match-composable-template-watches/333202)

<div class="topic-metadata">

**Author:** [@fmkaiser](https://discuss.elastic.co/u/fmkaiser)\
**Replies:** 0\
**Last updated:** [May 11, 2023, 11:35am UTC](https://discuss.elastic.co/t/unable-to-create-new-index-watches-6-reindexed-for-8-because-it-would-match-composable-template-watches/333202 "2023-05-11T11:35:23Z")

</div>

Hello, when trying to migrate system indices to ES 8.x, I get the following error: unable to create new index \[.watches-6-reindexed-for-8\] because it would match composable template \[.watches\] full output We are cu…

---

## [ Index not moving to delete phase](https://discuss.elastic.co/t/index-not-moving-to-delete-phase/333026)

<div class="topic-metadata">

**Author:** [@tirelibirefe](https://discuss.elastic.co/u/tirelibirefe)\
**Replies:** 3\
**Last updated:** [May 11, 2023, 11:06am UTC](https://discuss.elastic.co/t/index-not-moving-to-delete-phase/333026 "2023-05-11T11:06:21Z")

</div>

Hello, I have Elasticsearch 8 on K8s. Fluentbit sends logs to ES8. Everyday new indexes are created based on date; likes this: backend-app-2023.05.09 backend-app-2023.05.10 backend-app-2023.05.11 ... I would like e…

---

## [How to disable a plugin in Logstash Configuration file](https://discuss.elastic.co/t/how-to-disable-a-plugin-in-logstash-configuration-file/333197)

<div class="topic-metadata">

**Author:** [@Rakhshunda\_Noorein\_J](https://discuss.elastic.co/u/Rakhshunda_Noorein_J)\
**Replies:** 0\
**Last updated:** [May 11, 2023, 11:00am UTC](https://discuss.elastic.co/t/how-to-disable-a-plugin-in-logstash-configuration-file/333197 "2023-05-11T11:00:52Z")

</div>

Hello, I have a configuration file with multiple plugins. I want to disable all plugin and run 1 plugin for some use cases...How can I do that. My config example- input { http\_poller { urls =\> { api1=\> { …

---

## ["\_cat/nodes" API reports "transport" IP instead of "http" IP](https://discuss.elastic.co/t/cat-nodes-api-reports-transport-ip-instead-of-http-ip/333166)

<div class="topic-metadata">

**Author:** [@Jeremy\_Lecour](https://discuss.elastic.co/u/Jeremy_Lecour)\
**Replies:** 2\
**Last updated:** [May 11, 2023, 10:40am UTC](https://discuss.elastic.co/t/cat-nodes-api-reports-transport-ip-instead-of-http-ip/333166 "2023-05-11T10:40:38Z")

</div>

Hi, I have a 2-nodes cluster with this setup for the networking configuration : http.host: \[\_local\_,\_ens192\_\] http.port: 9200 transport.host: \[\_ens161\_\] transport.port: 9300 And here is my network setup : # ip -br a…

---

## [Multiple Elasticsearch instances architecture](https://discuss.elastic.co/t/multiple-elasticsearch-instances-architecture/333187)

<div class="topic-metadata">

**Author:** [@jabulon](https://discuss.elastic.co/u/jabulon)\
**Replies:** 0\
**Last updated:** [May 11, 2023, 10:18am UTC](https://discuss.elastic.co/t/multiple-elasticsearch-instances-architecture/333187 "2023-05-11T10:18:53Z")

</div>

I am designing a solution based on many smaller Elasticsearch engines scattered around the world, and a single instance containing all of the data from all of the instances combined. I do not need the data to be up to da…

---

## [Elasticsearch - get logs from DMZ](https://discuss.elastic.co/t/elasticsearch-get-logs-from-dmz/332901)

<div class="topic-metadata">

**Author:** [@Sharon\_Hacham](https://discuss.elastic.co/u/Sharon_Hacham)\
**Replies:** 4\
**Last updated:** [May 11, 2023, 9:28am UTC](https://discuss.elastic.co/t/elasticsearch-get-logs-from-dmz/332901 "2023-05-11T09:28:48Z")

</div>

Hi , we have Elasticsearch cluster and now we want to stream logs from DMZ environment to there which isn't allowed by InfoSec purpose. Only allowed method of pull from the DMZ. What's the preferred option in such cas…

---

## [ElasticSearch does not see indices](https://discuss.elastic.co/t/elasticsearch-does-not-see-indices/332960)

<div class="topic-metadata">

**Author:** [@not\_correct](https://discuss.elastic.co/u/not_correct)\
**Replies:** 6\
**Last updated:** [May 11, 2023, 9:23am UTC](https://discuss.elastic.co/t/elasticsearch-does-not-see-indices/332960 "2023-05-11T09:23:11Z")

</div>

Hi, I had to reboot EC2 instances that hosts 5-node cluster. The data stored on corresponding EBS volumes. Once I have rebooted the instance and started the Elasticsearch my cluster got into status red. \_cat/indices m…

[Previous page](https://discuss.elastic.co/latest.md?page=680)

[Next page](https://discuss.elastic.co/latest.md?page=682)
