# \#none

**URL:** https://discuss.elastic.co/tag/none.md?no_tags=true&page=240

[Latest](https://discuss.elastic.co/latest.md) · [Categories](https://discuss.elastic.co/categories.md) · [Tags](https://discuss.elastic.co/tags.md)

**Page:** 241

---

## [Elastic Cluster Balancing](https://discuss.elastic.co/t/elastic-cluster-balancing/351456)

<div class="topic-metadata">

**Author:** [@Elk\_huh](https://discuss.elastic.co/u/Elk_huh)\
**Replies:** 3\
**Last updated:** [January 23, 2024, 5:18pm UTC](https://discuss.elastic.co/t/elastic-cluster-balancing/351456 "2024-01-23T17:18:02Z")

</div>

ELK stack 8.11, How do i get my cluster to balance by available disk space, 1 node keeps hitting the watermark while the other 3 nodes have 2TB available Here are the Cluster settings { "persistent": { "cluster"…

---

## [\`null\` is returned for sort instead of field value](https://discuss.elastic.co/t/null-is-returned-for-sort-instead-of-field-value/351642)

<div class="topic-metadata">

**Author:** [@sashatrn](https://discuss.elastic.co/u/sashatrn)\
**Replies:** 0\
**Last updated:** [January 23, 2024, 3:33pm UTC](https://discuss.elastic.co/t/null-is-returned-for-sort-instead-of-field-value/351642 "2024-01-23T15:33:19Z")

</div>

We have a strange behavior with sorting. The value returned for sorting is null. We decided to add a sub-field lowercase for all fields to support case-insensitive sorting. We did the following: Added custom lowercase…

---

## [Forcing a Logstash pipeline to restart](https://discuss.elastic.co/t/forcing-a-logstash-pipeline-to-restart/351639)

<div class="topic-metadata">

**Author:** [@intrepid1](https://discuss.elastic.co/u/intrepid1)\
**Replies:** 0\
**Last updated:** [January 23, 2024, 3:11pm UTC](https://discuss.elastic.co/t/forcing-a-logstash-pipeline-to-restart/351639 "2024-01-23T15:11:10Z")

</div>

Hi there, I have a pipeline that extracts documents from Elasticsearch and sends them to S3. I want to do some reconciliation on the process to prove that the number of documents extracted from Elasticsearch and the num…

---

## [Speeding up deep pagination for large ids query](https://discuss.elastic.co/t/speeding-up-deep-pagination-for-large-ids-query/351636)

<div class="topic-metadata">

**Author:** [@dsc](https://discuss.elastic.co/u/dsc)\
**Replies:** 0\
**Last updated:** [January 23, 2024, 2:45pm UTC](https://discuss.elastic.co/t/speeding-up-deep-pagination-for-large-ids-query/351636 "2024-01-23T14:45:08Z")

</div>

I've got an Elasticsearch index with ~100M documents, and typically need to search within a subset of them using an IDs query combined with other search terms/filters. These subsets of IDs are dynamic and come from an e…

---

## [Create independent indices](https://discuss.elastic.co/t/create-independent-indices/351603)

<div class="topic-metadata">

**Author:** [@marotaal](https://discuss.elastic.co/u/marotaal)\
**Replies:** 3\
**Last updated:** [January 23, 2024, 2:00pm UTC](https://discuss.elastic.co/t/create-independent-indices/351603 "2024-01-23T14:00:40Z")

</div>

Hello, I am setting up a lab for log collection (Apache, Sophos, ...) I want to create different indices for each device (Apache, Sophos, Windows, Linux, ...) Is it possible to create independent indices? How can thi…

---

## [Data nodes not ingesting new documents for over 10 min](https://discuss.elastic.co/t/data-nodes-not-ingesting-new-documents-for-over-10-min/351462)

<div class="topic-metadata">

**Author:** [@luana](https://discuss.elastic.co/u/luana)\
**Replies:** 4\
**Last updated:** [January 23, 2024, 12:10pm UTC](https://discuss.elastic.co/t/data-nodes-not-ingesting-new-documents-for-over-10-min/351462 "2024-01-23T12:10:00Z")

</div>

Hi, I've got about 10 data nodes (this value fluctuates throughout the day) that are triggering my "no new documents" alert, that'll trigger if a node doesn't ingest documents for over 10 minutes. When checking the logs…

---

## [I am trying to Use Webhook connector from ELK- Need Help](https://discuss.elastic.co/t/i-am-trying-to-use-webhook-connector-from-elk-need-help/350901)

<div class="topic-metadata">

**Author:** [@MOHAMMED\_ASIF\_Z](https://discuss.elastic.co/u/MOHAMMED_ASIF_Z)\
**Replies:** 6\
**Last updated:** [January 23, 2024, 11:45am UTC](https://discuss.elastic.co/t/i-am-trying-to-use-webhook-connector-from-elk-need-help/350901 "2024-01-23T11:45:14Z")

</div>

I am capturing IBM Tivoli Schedular logs using Elastic stach - so my idea is to retrigger a failed job based on the reasoning, so using query on the specify field i could get only the failure , but i want to try reach ou…

---

## [Indices con diferentes nombres](https://discuss.elastic.co/t/indices-con-diferentes-nombres/351554)

<div class="topic-metadata">

**Author:** [@marotaal](https://discuss.elastic.co/u/marotaal)\
**Replies:** 1\
**Last updated:** [January 23, 2024, 11:34am UTC](https://discuss.elastic.co/t/indices-con-diferentes-nombres/351554 "2024-01-23T11:34:27Z")

</div>

Hola Estoy generando un laboratorio para la recogida de logs (Apache, Sophos,.....) Es posible poner logs en diferentes indices? Como se puede hacer? Solo consigo hacer que el filebeat funcione si el índice es el por…

---

## [Retrieving or saving matching document ID when using percolate](https://discuss.elastic.co/t/retrieving-or-saving-matching-document-id-when-using-percolate/351555)

<div class="topic-metadata">

**Author:** [@Krikkits](https://discuss.elastic.co/u/Krikkits)\
**Replies:** 1\
**Last updated:** [January 23, 2024, 10:32am UTC](https://discuss.elastic.co/t/retrieving-or-saving-matching-document-id-when-using-percolate/351555 "2024-01-23T10:32:59Z")

</div>

I am unfamiliar with percolate and honestly a bit confused. My idea is to use percolate on an existing index and not only getting how many match the query, but also which exact ones. The field "\_percolator\_document\_slot"…

---

## ["master\_not\_discovered\_exception"](https://discuss.elastic.co/t/master-not-discovered-exception/351548)

<div class="topic-metadata">

**Author:** [@Chulter](https://discuss.elastic.co/u/Chulter)\
**Replies:** 1\
**Last updated:** [January 23, 2024, 10:20am UTC](https://discuss.elastic.co/t/master-not-discovered-exception/351548 "2024-01-23T10:20:35Z")

</div>

Hello everyone, My english is not well so i use google trad. have encountered this error from the start knowing that I work on a Debian 11.5 VM with suricata installed as well as elasticsearch, kibana, filebeat so I on…

---

## [Kibana7.17](https://discuss.elastic.co/t/kibana7-17/351484)

<div class="topic-metadata">

**Author:** [@Youssef\_Shehadeh](https://discuss.elastic.co/u/Youssef_Shehadeh)\
**Replies:** 5\
**Last updated:** [January 23, 2024, 9:33am UTC](https://discuss.elastic.co/t/kibana7-17/351484 "2024-01-23T09:33:17Z")

</div>

Hello, I'm working on a uni project where I need to use the curator tool. However, it is not compatible with ES8.11, so I configured a three-node cluster (data\_frozen, data\_hot, data\_cold). The cluster health is green, a…

---

## [Failed to flush the buffer](https://discuss.elastic.co/t/failed-to-flush-the-buffer/351538)

<div class="topic-metadata">

**Author:** [@Music\_World](https://discuss.elastic.co/u/Music_World)\
**Replies:** 1\
**Last updated:** [January 23, 2024, 9:15am UTC](https://discuss.elastic.co/t/failed-to-flush-the-buffer/351538 "2024-01-23T09:15:24Z")

</div>

Hi @all I am using elasticsearch version: 7.16.2 and fluentd version: 1.14.4 on aws eks cluster and it's throwing bufferoverflow error like failed to flush the buffer. retry\_times=0 next\_retry\_time=2024-01-19 07:43:43 …

---

## [Cound not run org.elasticsearch.bootstrap.Elasticsearch(v8.12.0) directly in Intellij Idea](https://discuss.elastic.co/t/cound-not-run-org-elasticsearch-bootstrap-elasticsearch-v8-12-0-directly-in-intellij-idea/351594)

<div class="topic-metadata">

**Author:** [@Henkel](https://discuss.elastic.co/u/Henkel)\
**Replies:** 2\
**Last updated:** [January 23, 2024, 9:10am UTC](https://discuss.elastic.co/t/cound-not-run-org-elasticsearch-bootstrap-elasticsearch-v8-12-0-directly-in-intellij-idea/351594 "2024-01-23T09:10:11Z")

</div>

Hi guys: with elasticsearch version 7.16.0, I can run org.elasticsearch.bootstrap.Elasticsearch directly in Intellij Idea.The configuration of Intellij Idea is as follows： However, with elasticsearch version 8.12.0,…

---

## [I am trying to deduplicate my events one the basis of timestamp and operation field. But it did not work?](https://discuss.elastic.co/t/i-am-trying-to-deduplicate-my-events-one-the-basis-of-timestamp-and-operation-field-but-it-did-not-work/351599)

<div class="topic-metadata">

**Author:** [@Subrato1](https://discuss.elastic.co/u/Subrato1)\
**Replies:** 0\
**Last updated:** [January 23, 2024, 8:18am UTC](https://discuss.elastic.co/t/i-am-trying-to-deduplicate-my-events-one-the-basis-of-timestamp-and-operation-field-but-it-did-not-work/351599 "2024-01-23T08:18:42Z")

</div>

My Log event: { "priority" =\> 13, "host" =\> "172.31.63.35", "consistency" =\> "\\"ONE\\"", "source" =\> "\\"127.0.0.1", "type" =\> "scylladb", "severity" =\> 5…

---

## [Sub aggregating top\_hits](https://discuss.elastic.co/t/sub-aggregating-top-hits/351163)

<div class="topic-metadata">

**Author:** [@Vivek\_Burman](https://discuss.elastic.co/u/Vivek_Burman)\
**Replies:** 6\
**Last updated:** [January 23, 2024, 7:51am UTC](https://discuss.elastic.co/t/sub-aggregating-top-hits/351163 "2024-01-23T07:51:19Z")

</div>

Hi, I've the below Query { "query": { "bool": { "filter": \[ { "term": { "is\_deleted": 0 } }, …

---

## [./elastic-agent: 2: Syntax error: word unexpected (expecting ")")](https://discuss.elastic.co/t/elastic-agent-2-syntax-error-word-unexpected-expecting/351589)

<div class="topic-metadata">

**Author:** [@axiescholar](https://discuss.elastic.co/u/axiescholar)\
**Replies:** 1\
**Last updated:** [January 23, 2024, 4:44am UTC](https://discuss.elastic.co/t/elastic-agent-2-syntax-error-word-unexpected-expecting/351589 "2024-01-23T04:44:31Z")

</div>

i am getting this error when i am installing agent on kali linux. ./elastic-agent: 1: ./elastic-agent: 1: ELF: not found O@8: not found ./elastic-agent: 2: Syntax error: word unexpected (expecting ")") i am using a V…

---

## [Regarding parsing of data in logstash](https://discuss.elastic.co/t/regarding-parsing-of-data-in-logstash/351400)

<div class="topic-metadata">

**Author:** [@Ajay\_Kumar.S](https://discuss.elastic.co/u/Ajay_Kumar.S)\
**Replies:** 2\
**Last updated:** [January 23, 2024, 1:59am UTC](https://discuss.elastic.co/t/regarding-parsing-of-data-in-logstash/351400 "2024-01-23T01:59:48Z")

</div>

"message" =\> "{\\"namespace\\":\\"oci\_computeagent\\",\\"resourceGroup\\":null,\\"compartmentId\\":\\"ocid1.compartment.oc1..aaaaaaaacu54zo4clgrmfs3faxqqgfxyu2mjlufgslcem3venf2kon2ktmsq\\",\\"name\\":\\"DiskIopsWritten\\",\\"dimensions…

---

## [When does compression\_level change?](https://discuss.elastic.co/t/when-does-compression-level-change/350659)

<div class="topic-metadata">

**Author:** [@slash24](https://discuss.elastic.co/u/slash24)\
**Replies:** 1\
**Last updated:** [January 23, 2024, 1:04am UTC](https://discuss.elastic.co/t/when-does-compression-level-change/350659 "2024-01-23T01:04:39Z")

</div>

We're on Elastic 8.8.1 and about to upgrade to 8.11.3. Since we have alot of issues with Elastic Agents on our Windows-boxes, esp. when endpoint or agent is being reloaded but also with high cpuutilization (mostly due t…

---

## [Which crptographic hash algo does elasticsearch 8.7.0 use?](https://discuss.elastic.co/t/which-crptographic-hash-algo-does-elasticsearch-8-7-0-use/351361)

<div class="topic-metadata">

**Author:** [@sahadev\_d](https://discuss.elastic.co/u/sahadev_d)\
**Replies:** 1\
**Last updated:** [January 23, 2024, 12:28am UTC](https://discuss.elastic.co/t/which-crptographic-hash-algo-does-elasticsearch-8-7-0-use/351361 "2024-01-23T00:28:01Z")

</div>

Hi community, just wanted to know which hashing algo does elasticsearch 8.7.0 uses for internal hashing. also does it by any chance use sha1 or sha0 Please let me know how can i check the version

---

## [Adding an array of events even if there is only one](https://discuss.elastic.co/t/adding-an-array-of-events-even-if-there-is-only-one/351567)

<div class="topic-metadata">

**Author:** [@ylevaill](https://discuss.elastic.co/u/ylevaill)\
**Replies:** 1\
**Last updated:** [January 23, 2024, 12:07am UTC](https://discuss.elastic.co/t/adding-an-array-of-events-even-if-there-is-only-one/351567 "2024-01-23T00:07:38Z")

</div>

Hello, I use this filter : json { source =\> "message" add\_field =\> { "\[events\]\[id\]" =\> "%{\_id}" } add\_field =\> { "\[events\]\[nom\]" =\> "%{eventName}" } add\_field =\> { "\[events\]\[timestamp\]" =\> "%{ti…

---

## [Modsecurity log (split on audit\_data\[messages\]) Only String and Array types are splittable](https://discuss.elastic.co/t/modsecurity-log-split-on-audit-data-messages-only-string-and-array-types-are-splittable/351507)

<div class="topic-metadata">

**Author:** [@sunnysigara](https://discuss.elastic.co/u/sunnysigara)\
**Replies:** 4\
**Last updated:** [January 22, 2024, 8:50pm UTC](https://discuss.elastic.co/t/modsecurity-log-split-on-audit-data-messages-only-string-and-array-types-are-splittable/351507 "2024-01-22T20:50:57Z")

</div>

{ "transaction": { "time": "20/Jan/2024:00:10:51 +0530", "transaction\_id": "16717361827536742843", "remote\_address": "20.1.198.110", "remote\_port": 80, "local\_address": "127.0.…

---

## [Kibana Discover / Dashboards Read Only](https://discuss.elastic.co/t/kibana-discover-dashboards-read-only/351286)

<div class="topic-metadata">

**Author:** [@randomnamegenerator](https://discuss.elastic.co/u/randomnamegenerator)\
**Replies:** 6\
**Last updated:** [January 22, 2024, 8:35pm UTC](https://discuss.elastic.co/t/kibana-discover-dashboards-read-only/351286 "2024-01-22T20:35:20Z")

</div>

Hello All, We wish to lock down access on a customer sites ELK in a way that they can view the Analytics/Discover & Dashboards but not edit. The indices already exist. I have created a space,role and user with this aim…

---

## [In pipeline: translate causes logstash to crash](https://discuss.elastic.co/t/in-pipeline-translate-causes-logstash-to-crash/351386)

<div class="topic-metadata">

**Author:** [@michael\_c\_michael](https://discuss.elastic.co/u/michael_c_michael)\
**Replies:** 4\
**Last updated:** [January 22, 2024, 7:22pm UTC](https://discuss.elastic.co/t/in-pipeline-translate-causes-logstash-to-crash/351386 "2024-01-22T19:22:22Z")

</div>

I'm using a JSON dictionary to convert values to strings, it looks like this: { "1.1.0.80.1.\*.\*": "Motorcycle -\> Generic Scooter (Small)", "1.1.0.80.2.\*.\*": "Motorcycle -\> Generic Sport/Street (Mid-Size)", …

---

## [Use watcher index action with multiple documents](https://discuss.elastic.co/t/use-watcher-index-action-with-multiple-documents/351503)

<div class="topic-metadata">

**Author:** [@lizozom](https://discuss.elastic.co/u/lizozom)\
**Replies:** 3\
**Last updated:** [January 22, 2024, 6:35pm UTC](https://discuss.elastic.co/t/use-watcher-index-action-with-multiple-documents/351503 "2024-01-22T18:35:54Z")

</div>

I have an index and I am using a watcher to monitor it. When a condition is met, I want to copy each document to a different index. I'm following the example here: "index\_payload": { "transform": { "script…

---

## [FSCrawler - Tika Configuration for escape quotes in TextandCSVParser](https://discuss.elastic.co/t/fscrawler-tika-configuration-for-escape-quotes-in-textandcsvparser/351273)

<div class="topic-metadata">

**Author:** [@kamalsharma](https://discuss.elastic.co/u/kamalsharma)\
**Replies:** 4\
**Last updated:** [January 22, 2024, 1:39pm UTC](https://discuss.elastic.co/t/fscrawler-tika-configuration-for-escape-quotes-in-textandcsvparser/351273 "2024-01-22T13:39:25Z")

</div>

When I am ingesting a csv file using FSCrawler, I am getting the error "IOException reading next record: java.io.IOException: (line 131664) invalid char between encapsulated token and delimiter -\> (line 131664) invalid c…

---

## [A user who can create, delete their indexes but restricted to deleting others'](https://discuss.elastic.co/t/a-user-who-can-create-delete-their-indexes-but-restricted-to-deleting-others/351296)

<div class="topic-metadata">

**Author:** [@jeannshuti](https://discuss.elastic.co/u/jeannshuti)\
**Replies:** 3\
**Last updated:** [January 22, 2024, 1:40pm UTC](https://discuss.elastic.co/t/a-user-who-can-create-delete-their-indexes-but-restricted-to-deleting-others/351296 "2024-01-22T13:40:54Z")

</div>

I am new to the ELK stack and I am trying to find a built-in role that could allow a user to create and delete their own indexes but restricted to deleting others' indexes (read-only). Is there any specific role that has…

---

## [How to take backup of specific time range of data from elastic search using Curator](https://discuss.elastic.co/t/how-to-take-backup-of-specific-time-range-of-data-from-elastic-search-using-curator/351542)

<div class="topic-metadata">

**Author:** [@shobana](https://discuss.elastic.co/u/shobana)\
**Replies:** 0\
**Last updated:** [January 22, 2024, 1:39pm UTC](https://discuss.elastic.co/t/how-to-take-backup-of-specific-time-range-of-data-from-elastic-search-using-curator/351542 "2024-01-22T13:39:23Z")

</div>

Hello All, I need to take specific time period of data as a backup. in index range what i need to give while taking doing ae elastic backup.

---

## [Building Kibana code in WSL giving error](https://discuss.elastic.co/t/building-kibana-code-in-wsl-giving-error/349790)

<div class="topic-metadata">

**Author:** [@vikas.shirke](https://discuss.elastic.co/u/vikas.shirke)\
**Replies:** 7\
**Last updated:** [January 22, 2024, 1:24pm UTC](https://discuss.elastic.co/t/building-kibana-code-in-wsl-giving-error/349790 "2024-01-22T13:24:28Z")

</div>

I am trying to build Kibana code locally in wsl enviroment. I am using version 8.11.3 I have ran below commands: git checkout 8.11.3 nvm use yarn kbn clean yarn cache clean rm yarn.lock yarn kbn bootstrap --force-…

---

## [S3 repository snapshot](https://discuss.elastic.co/t/s3-repository-snapshot/351486)

<div class="topic-metadata">

**Author:** [@Haytham\_Shammout](https://discuss.elastic.co/u/Haytham_Shammout)\
**Replies:** 5\
**Last updated:** [January 22, 2024, 1:04pm UTC](https://discuss.elastic.co/t/s3-repository-snapshot/351486 "2024-01-22T13:04:10Z")

</div>

Hello, I am trying to create a s3 repository snapshot that will take 1 exact day which is the day before 7 days, noting that all the indices I have is daily based, and this needs to be done every day at a specific time. …

---

## [Logstash filters not working as expected](https://discuss.elastic.co/t/logstash-filters-not-working-as-expected/351536)

<div class="topic-metadata">

**Author:** [@Mansi\_Kamthane](https://discuss.elastic.co/u/Mansi_Kamthane)\
**Replies:** 0\
**Last updated:** [January 22, 2024, 11:58am UTC](https://discuss.elastic.co/t/logstash-filters-not-working-as-expected/351536 "2024-01-22T11:58:03Z")

</div>

I am working with logstash filter no filter works here here is the config file of logstash \` input { tcp { id =\> "\*\*\*" port =\> \*\*\* codec =\> json\_lines } } filter { cipher { algorithm =\> "aes-128-cbc" key =\> …

[Previous page](https://discuss.elastic.co/tag/none.md?no_tags=true&page=239)

[Next page](https://discuss.elastic.co/tag/none.md?no_tags=true&page=241)
