# \#none

**URL:** https://discuss.elastic.co/tag/none.md?no_tags=true&page=267

[Latest](https://discuss.elastic.co/latest.md) · [Categories](https://discuss.elastic.co/categories.md) · [Tags](https://discuss.elastic.co/tags.md)

**Page:** 268

---

## [An internal error while attempting to create policy](https://discuss.elastic.co/t/an-internal-error-while-attempting-to-create-policy/347991)

<div class="topic-metadata">

**Author:** [@amarnath](https://discuss.elastic.co/u/amarnath)\
**Replies:** 0\
**Last updated:** [November 26, 2023, 11:42am UTC](https://discuss.elastic.co/t/an-internal-error-while-attempting-to-create-policy/347991 "2023-11-26T11:42:08Z")

</div>

{"service":{"node":{"roles":\["background\_tasks","ui"\]}},"ecs":{"version":"8.6.1"},"@timestamp":"2023-11-26T11:27:03.939+00:00","message":"Cannot read properties of undefined (reading 'split')","error":{"message":"Cannot …

---

## [How to calculate how much data a single data node in an elasticsearch cluster can store?](https://discuss.elastic.co/t/how-to-calculate-how-much-data-a-single-data-node-in-an-elasticsearch-cluster-can-store/347916)

<div class="topic-metadata">

**Author:** [@qq\_123456](https://discuss.elastic.co/u/qq_123456)\
**Replies:** 1\
**Last updated:** [November 26, 2023, 10:05am UTC](https://discuss.elastic.co/t/how-to-calculate-how-much-data-a-single-data-node-in-an-elasticsearch-cluster-can-store/347916 "2023-11-26T10:05:52Z")

</div>

I now want to install an elasticsearch cluster. How to evaluate the cluster size and resources? How to calculate how much data a single data node in an elasticsearch cluster can store? How to determine the ratio of memor…

---

## [Best practis for agents enrollment with fleet on ECK](https://discuss.elastic.co/t/best-practis-for-agents-enrollment-with-fleet-on-eck/347986)

<div class="topic-metadata">

**Author:** [@khaled\_belgacem](https://discuss.elastic.co/u/khaled_belgacem)\
**Replies:** 0\
**Last updated:** [November 26, 2023, 8:33am UTC](https://discuss.elastic.co/t/best-practis-for-agents-enrollment-with-fleet-on-eck/347986 "2023-11-26T08:33:58Z")

</div>

Hello everyone, i'm currently using ECK for my elastic stack, i installed agents on some laptops and they enrolled successfully with fleet ( they go by the public network, both elasticsearch and fleet are exposed ), but…

---

## [Increase in shard count vs increase in shard size - Performance comparison](https://discuss.elastic.co/t/increase-in-shard-count-vs-increase-in-shard-size-performance-comparison/347984)

<div class="topic-metadata">

**Author:** [@sriapr98](https://discuss.elastic.co/u/sriapr98)\
**Replies:** 1\
**Last updated:** [November 26, 2023, 7:34am UTC](https://discuss.elastic.co/t/increase-in-shard-count-vs-increase-in-shard-size-performance-comparison/347984 "2023-11-26T07:34:08Z")

</div>

Currently we are creating an index which will take space of around 900GB. We are not able to use ILM because there are updates possible to any older data as well. So the only option left to us is sharding optimization w…

---

## [Hostname not extracted when i run logstash as a service on rhel](https://discuss.elastic.co/t/hostname-not-extracted-when-i-run-logstash-as-a-service-on-rhel/347977)

<div class="topic-metadata">

**Author:** [@Indeed2000](https://discuss.elastic.co/u/Indeed2000)\
**Replies:** 6\
**Last updated:** [November 26, 2023, 2:30am UTC](https://discuss.elastic.co/t/hostname-not-extracted-when-i-run-logstash-as-a-service-on-rhel/347977 "2023-11-26T02:30:37Z")

</div>

Hi When i run logstash normally like this: ./logstash -f logstash.cfg It extract hostname. But when i run as service not extract hostname. Any idea? Thanks

---

## [Dealing with high number of deleted documents](https://discuss.elastic.co/t/dealing-with-high-number-of-deleted-documents/347973)

<div class="topic-metadata">

**Author:** [@Dishant\_18](https://discuss.elastic.co/u/Dishant_18)\
**Replies:** 8\
**Last updated:** [November 25, 2023, 6:15pm UTC](https://discuss.elastic.co/t/dealing-with-high-number-of-deleted-documents/347973 "2023-11-25T18:15:55Z")

</div>

Hello everyone! We have an elasticsearch index with 40 shards and 1 replica. We index live email data in this ES index - so the volume of deletes is also high! We have 2 data nodes and 3 master nodes in our cluster. For…

---

## [No verify ssl input elasticsearch](https://discuss.elastic.co/t/no-verify-ssl-input-elasticsearch/347860)

<div class="topic-metadata">

**Author:** [@lstoneir](https://discuss.elastic.co/u/lstoneir)\
**Replies:** 3\
**Last updated:** [November 25, 2023, 1:11pm UTC](https://discuss.elastic.co/t/no-verify-ssl-input-elasticsearch/347860 "2023-11-25T13:11:46Z")

</div>

Hi Dears Is there any way to not verify ssl in input elasticsearch plugin? logstash 7.17 I can not do this! please help

---

## [Aws managed elastic search](https://discuss.elastic.co/t/aws-managed-elastic-search/347812)

<div class="topic-metadata">

**Author:** [@Hariharan\_Raj](https://discuss.elastic.co/u/Hariharan_Raj)\
**Replies:** 8\
**Last updated:** [November 25, 2023, 6:31am UTC](https://discuss.elastic.co/t/aws-managed-elastic-search/347812 "2023-11-25T06:31:28Z")

</div>

Hi, I am trying to create a 2 node aws managed elasticsearch. I am having trouble creating it. I am running my backend services inside a VPC. the filter service has all the elasticsearch codes and resides in a private …

---

## [Synonym Graph giving incorrect results](https://discuss.elastic.co/t/synonym-graph-giving-incorrect-results/347966)

<div class="topic-metadata">

**Author:** [@bhavya](https://discuss.elastic.co/u/bhavya)\
**Replies:** 0\
**Last updated:** [November 25, 2023, 6:10am UTC](https://discuss.elastic.co/t/synonym-graph-giving-incorrect-results/347966 "2023-11-25T06:10:45Z")

</div>

I am trying to implement Multi-Word Synonyms This is the index setting { "settings": { "analysis": { "filter": { "synonym\_filter": { "type": "synonym\_graph", "synonyms": \[ …

---

## [Use specific subsets of data for visualization layers](https://discuss.elastic.co/t/use-specific-subsets-of-data-for-visualization-layers/347945)

<div class="topic-metadata">

**Author:** [@greendrake](https://discuss.elastic.co/u/greendrake)\
**Replies:** 1\
**Last updated:** [November 24, 2023, 5:56pm UTC](https://discuss.elastic.co/t/use-specific-subsets-of-data-for-visualization-layers/347945 "2023-11-24T17:56:22Z")

</div>

There is a nice feature in Kibana (I am using v 8.6.2) which allows to add multiple layers to visualizations: I have the following kind of data in the index: { utc: "\<datetime\>", source: "foo", value: 5 }…

---

## [Logstash 8.1 multiple patterns](https://discuss.elastic.co/t/logstash-8-1-multiple-patterns/347943)

<div class="topic-metadata">

**Author:** [@Dokh\_Ahmed](https://discuss.elastic.co/u/Dokh_Ahmed)\
**Replies:** 1\
**Last updated:** [November 24, 2023, 4:33pm UTC](https://discuss.elastic.co/t/logstash-8-1-multiple-patterns/347943 "2023-11-24T16:33:36Z")

</div>

According to the doc of logstash " \`\`\` filter { grok { match =\> \[ "message", "PATTERN1", "PATTERN2" \] } } I wrote my filter as : filter { grok { match =\> { "message" =\> \[ "%{TIMESTAMP\_ISO860…

---

## [Mustache toJSON tag issue](https://discuss.elastic.co/t/mustache-tojson-tag-issue/347944)

<div class="topic-metadata">

**Author:** [@pszemesy](https://discuss.elastic.co/u/pszemesy)\
**Replies:** 0\
**Last updated:** [November 24, 2023, 4:27pm UTC](https://discuss.elastic.co/t/mustache-tojson-tag-issue/347944 "2023-11-24T16:27:54Z")

</div>

Hi All, I'm trying to create a search template: { "script": { "lang": "mustache", "source": """{ "query": { "bool": { "must": \[ {{#docyear}}{ "terms": { …

---

## [Backup Of Index In Elasticsearch](https://discuss.elastic.co/t/backup-of-index-in-elasticsearch/347834)

<div class="topic-metadata">

**Author:** [@Debasis\_Mallick](https://discuss.elastic.co/u/Debasis_Mallick)\
**Replies:** 4\
**Last updated:** [November 24, 2023, 3:27pm UTC](https://discuss.elastic.co/t/backup-of-index-in-elasticsearch/347834 "2023-11-24T15:27:27Z")

</div>

Hi Team, I had a requirement where Elasticsearch is running as a container. I need to take backup of the one of the index and need to restore in Elasticsearch cluster which is running on VM. There is no Kibana configure…

---

## [Add value to a previously indexed field with logstash](https://discuss.elastic.co/t/add-value-to-a-previously-indexed-field-with-logstash/347940)

<div class="topic-metadata">

**Author:** [@elk-user-0001](https://discuss.elastic.co/u/elk-user-0001)\
**Replies:** 0\
**Last updated:** [November 24, 2023, 3:25pm UTC](https://discuss.elastic.co/t/add-value-to-a-previously-indexed-field-with-logstash/347940 "2023-11-24T15:25:21Z")

</div>

Hello! I have a pipeline that has many inputs ( 19 ) and I use the update on the output using a document\_id to avoid duplicates and the elasticsearch filter and update the values. Is it possible to add the value of a f…

---

## [Max suggested index sizes / document amount etc](https://discuss.elastic.co/t/max-suggested-index-sizes-document-amount-etc/347937)

<div class="topic-metadata">

**Author:** [@elk1985](https://discuss.elastic.co/u/elk1985)\
**Replies:** 2\
**Last updated:** [November 24, 2023, 2:56pm UTC](https://discuss.elastic.co/t/max-suggested-index-sizes-document-amount-etc/347937 "2023-11-24T14:56:57Z")

</div>

Hello. My cluster is reaching 2000 opened shards. I have two data nodes now. I don't want to add another data node and scale up the cluster. I'm thinking more like changing indexing strategy. Currently logstash is cre…

---

## [logstash-output-elasticsearch fails with Permission denied](https://discuss.elastic.co/t/logstash-output-elasticsearch-fails-with-permission-denied/347787)

<div class="topic-metadata">

**Author:** [@mirceastoian](https://discuss.elastic.co/u/mirceastoian)\
**Replies:** 18\
**Last updated:** [November 24, 2023, 2:46pm UTC](https://discuss.elastic.co/t/logstash-output-elasticsearch-fails-with-permission-denied/347787 "2023-11-24T14:46:15Z")

</div>

Logstash information: Logstash version: 7.17.9 Logstash installation source: deb How is Logstash being run: systemd How was the Logstash Plugin installed: sudo /usr/share/logstash/bin/logstash-plugin install logstash-o…

---

## [How best to Denormalize a SQL schema](https://discuss.elastic.co/t/how-best-to-denormalize-a-sql-schema/347922)

<div class="topic-metadata">

**Author:** [@cylon86](https://discuss.elastic.co/u/cylon86)\
**Replies:** 0\
**Last updated:** [November 24, 2023, 11:21am UTC](https://discuss.elastic.co/t/how-best-to-denormalize-a-sql-schema/347922 "2023-11-24T11:21:41Z")

</div>

Hi all, I'm building a new Index for a use case and I'm wondering what would be the best mapping to structure this index. I have no problem building this with SQL tables, links and joins; but I struggle finding the goo…

---

## [Problem with Search-time Synonyms](https://discuss.elastic.co/t/problem-with-search-time-synonyms/347654)

<div class="topic-metadata">

**Author:** [@elleWajexi](https://discuss.elastic.co/u/elleWajexi)\
**Replies:** 7\
**Last updated:** [November 24, 2023, 10:38am UTC](https://discuss.elastic.co/t/problem-with-search-time-synonyms/347654 "2023-11-24T10:38:07Z")

</div>

I have an index with synonyms : "index": { "analysis": { "analyzer": { "index\_analyzer": { "tokenizer": "standard", "filter": \[ "lowercase", "my\_stemmer" \] }…

---

## [Elasticsearch .Net v8.x client use for bulk indexing raw JSON data](https://discuss.elastic.co/t/elasticsearch-net-v8-x-client-use-for-bulk-indexing-raw-json-data/347914)

<div class="topic-metadata">

**Author:** [@askids](https://discuss.elastic.co/u/askids)\
**Replies:** 0\
**Last updated:** [November 24, 2023, 10:19am UTC](https://discuss.elastic.co/t/elasticsearch-net-v8-x-client-use-for-bulk-indexing-raw-json-data/347914 "2023-11-24T10:19:58Z")

</div>

hi, I am using .Net 6.0, running Elastic.Client 8.x connecting to 7.17 ES, which will be shortly upgraded to 8.4. I want to know how do I perform bulk indexing of raw json data? I could see some example under Java clien…

---

## [Logstash is processing old documents](https://discuss.elastic.co/t/logstash-is-processing-old-documents/347678)

<div class="topic-metadata">

**Author:** [@Cruz](https://discuss.elastic.co/u/Cruz)\
**Replies:** 3\
**Last updated:** [November 24, 2023, 9:12am UTC](https://discuss.elastic.co/t/logstash-is-processing-old-documents/347678 "2023-11-24T09:12:38Z")

</div>

When I restart the logstash service, the old documents are coming out. I tried to stopping the filebeat service where the logs are coming from and I deleted the old documents. But when I restart the logstash service the…

---

## [What does "\_ignored" tag mean in hits](https://discuss.elastic.co/t/what-does-ignored-tag-mean-in-hits/344300)

<div class="topic-metadata">

**Author:** [@Aiswarya\_S](https://discuss.elastic.co/u/Aiswarya_S)\
**Replies:** 2\
**Last updated:** [November 24, 2023, 7:19am UTC](https://discuss.elastic.co/t/what-does-ignored-tag-mean-in-hits/344300 "2023-11-24T07:19:49Z")

</div>

In my Elastic search pulled data, I am getting an ignored tag in the hits but yet the data is coming correctly... so what does that ignored tag mean? { "took": 9, "timed\_out": false, "\_shards": { "total": 1, …

---

## [How to use LruRedux cache in ruby filter](https://discuss.elastic.co/t/how-to-use-lruredux-cache-in-ruby-filter/347893)

<div class="topic-metadata">

**Author:** [@Chen\_Wei](https://discuss.elastic.co/u/Chen_Wei)\
**Replies:** 0\
**Last updated:** [November 24, 2023, 2:44am UTC](https://discuss.elastic.co/t/how-to-use-lruredux-cache-in-ruby-filter/347893 "2023-11-24T02:44:03Z")

</div>

Somehow we have some logs having duplicated events, we want to dedup the events using fingerprint and LRU cache in the logstash pipeline, So I write a ruby file require "lru\_redux" def register(params) limit = para…

---

## [Encryption of saved logs](https://discuss.elastic.co/t/encryption-of-saved-logs/347612)

<div class="topic-metadata">

**Author:** [@Hamada](https://discuss.elastic.co/u/Hamada)\
**Replies:** 5\
**Last updated:** [November 24, 2023, 1:08am UTC](https://discuss.elastic.co/t/encryption-of-saved-logs/347612 "2023-11-24T01:08:57Z")

</div>

I am using Elastic 8.1 in a Windows environment, How do you implement encryption of saved logs?

---

## [Index has disappeared](https://discuss.elastic.co/t/index-has-disappeared/347889)

<div class="topic-metadata">

**Author:** [@juancamiloll](https://discuss.elastic.co/u/juancamiloll)\
**Replies:** 5\
**Last updated:** [November 23, 2023, 10:47pm UTC](https://discuss.elastic.co/t/index-has-disappeared/347889 "2023-11-23T22:47:53Z")

</div>

Hello I have several sources that ELK processes, as you know from /etc/logstash/conf.d a .conf file is created for each of the sources to be processed either by GROK or CSV, I don't know if there is another way. One of…

---

## [Time fields show different time](https://discuss.elastic.co/t/time-fields-show-different-time/346651)

<div class="topic-metadata">

**Author:** [@juancamiloll](https://discuss.elastic.co/u/juancamiloll)\
**Replies:** 8\
**Last updated:** [November 23, 2023, 10:25pm UTC](https://discuss.elastic.co/t/time-fields-show-different-time/346651 "2023-11-23T22:25:01Z")

</div>

Hello again, I find a new problem where in the logs of a Paloalto I see that the "ReceivedTime" field and the "column103" field show a different time. I would appreciate your help input { file { path =\> "…

---

## [Logstash Multiline and line codec differences](https://discuss.elastic.co/t/logstash-multiline-and-line-codec-differences/347466)

<div class="topic-metadata">

**Author:** [@randomnamegenerator](https://discuss.elastic.co/u/randomnamegenerator)\
**Replies:** 6\
**Last updated:** [November 23, 2023, 7:42pm UTC](https://discuss.elastic.co/t/logstash-multiline-and-line-codec-differences/347466 "2023-11-23T19:42:09Z")

</div>

Hello All, We have application logs coming in from a number of different hosts (shipped with filebeat) and have obvserved a mixing of datastreams for one of the log types. We changed the logstash input.config from vers…

---

## [How to namespace indexes - Automatic not Manual](https://discuss.elastic.co/t/how-to-namespace-indexes-automatic-not-manual/347886)

<div class="topic-metadata">

**Author:** [@Alexander\_Mills](https://discuss.elastic.co/u/Alexander_Mills)\
**Replies:** 1\
**Last updated:** [November 23, 2023, 7:33pm UTC](https://discuss.elastic.co/t/how-to-namespace-indexes-automatic-not-manual/347886 "2023-11-23T19:33:31Z")

</div>

Mongo has namespacing via different databases on the same db server RabbitMQ has namespacing via different exhanges How can I automatically namespace indices with Elastic without manually namespacing keys with prod-x…

---

## [Duplicate logs in Logstash](https://discuss.elastic.co/t/duplicate-logs-in-logstash/347630)

<div class="topic-metadata">

**Author:** [@marcowiskhy](https://discuss.elastic.co/u/marcowiskhy)\
**Replies:** 8\
**Last updated:** [November 23, 2023, 6:15pm UTC](https://discuss.elastic.co/t/duplicate-logs-in-logstash/347630 "2023-11-23T18:15:47Z")

</div>

I collect VPN logs through Logstash and index them in Elasticsearch, but I'm having the following problem: For each unique VPN connection (represented by TunnelID), there should be only one tunnel-up event and one tunne…

---

## [The Output Isolator Pattern: Inquiry regarding downstream pipeline failures](https://discuss.elastic.co/t/the-output-isolator-pattern-inquiry-regarding-downstream-pipeline-failures/347878)

<div class="topic-metadata">

**Author:** [@Kihyun\_Hwang](https://discuss.elastic.co/u/Kihyun_Hwang)\
**Replies:** 2\
**Last updated:** [November 23, 2023, 5:14pm UTC](https://discuss.elastic.co/t/the-output-isolator-pattern-inquiry-regarding-downstream-pipeline-failures/347878 "2023-11-23T17:14:12Z")

</div>

I have applied the Output Isolator pattern to send logs to two ES clusters. However, as mentioned in the reference: "If any of the persistent queues of the downstream pipelines (in the example above, buffered-es and bu…

---

## [Translate kibana bar chart to TSVB](https://discuss.elastic.co/t/translate-kibana-bar-chart-to-tsvb/347421)

<div class="topic-metadata">

**Author:** [@PRASHANT\_MEHTA](https://discuss.elastic.co/u/PRASHANT_MEHTA)\
**Replies:** 3\
**Last updated:** [November 23, 2023, 2:12pm UTC](https://discuss.elastic.co/t/translate-kibana-bar-chart-to-tsvb/347421 "2023-11-23T14:12:26Z")

</div>

Hello All, I have visual made using Vertical Bar chart and over there I can't split x axis twice .I need to show max of duration for given startTime (x-axis),but same time x-axis also show release to compare. Given rel…

[Previous page](https://discuss.elastic.co/tag/none.md?no_tags=true&page=266)

[Next page](https://discuss.elastic.co/tag/none.md?no_tags=true&page=268)
