# \#none

**URL:** https://discuss.elastic.co/tag/none.md?no_tags=true&page=276

[Latest](https://discuss.elastic.co/latest.md) · [Categories](https://discuss.elastic.co/categories.md) · [Tags](https://discuss.elastic.co/tags.md)

**Page:** 277

---

## [Data nodes removed from cluster one by one after indexing activity peak](https://discuss.elastic.co/t/data-nodes-removed-from-cluster-one-by-one-after-indexing-activity-peak/346764)

<div class="topic-metadata">

**Author:** [@jalker](https://discuss.elastic.co/u/jalker)\
**Replies:** 0\
**Last updated:** [November 9, 2023, 8:35am UTC](https://discuss.elastic.co/t/data-nodes-removed-from-cluster-one-by-one-after-indexing-activity-peak/346764 "2023-11-09T08:35:12Z")

</div>

Elasticsearch 7.17, Debian, 12 data nodes, 5.5 Bi primary docs, 11.0 TB primary doc size. We have seen the following behavior twice now and we are clueless as to its root cause. We see an sudden increase of indexing a…

---

## [Multiple replicas of Kibana deployment](https://discuss.elastic.co/t/multiple-replicas-of-kibana-deployment/346763)

<div class="topic-metadata">

**Author:** [@daniela09](https://discuss.elastic.co/u/daniela09)\
**Replies:** 0\
**Last updated:** [November 9, 2023, 8:27am UTC](https://discuss.elastic.co/t/multiple-replicas-of-kibana-deployment/346763 "2023-11-09T08:27:37Z")

</div>

I have deployed EFK stack on Kubernetes, but Kibana is running as a single instance (pod) and there is no redundancy, so I wanted to change it to 2 replicas, in the Kibana deployment yaml, I only need to change replicas…

---

## [Threat intel rule stopped working when added exceptions](https://discuss.elastic.co/t/threat-intel-rule-stopped-working-when-added-exceptions/346617)

<div class="topic-metadata">

**Author:** [@theacodes](https://discuss.elastic.co/u/theacodes)\
**Replies:** 4\
**Last updated:** [November 9, 2023, 6:41am UTC](https://discuss.elastic.co/t/threat-intel-rule-stopped-working-when-added-exceptions/346617 "2023-11-09T06:41:56Z")

</div>

The threat intel rule stopped working when added some exceptions. any solution?

---

## [Custom fields creation in jira using elasticsearch](https://discuss.elastic.co/t/custom-fields-creation-in-jira-using-elasticsearch/346759)

<div class="topic-metadata">

**Author:** [@Kumar\_6](https://discuss.elastic.co/u/Kumar_6)\
**Replies:** 0\
**Last updated:** [November 9, 2023, 6:27am UTC](https://discuss.elastic.co/t/custom-fields-creation-in-jira-using-elasticsearch/346759 "2023-11-09T06:27:51Z")

</div>

Hi, Can some one help to fix this issue. I want to create custom fields in jira by passing data from jira connecter in kibana.

---

## [Update by query (async / task) - No failure info - Handling Conflicts](https://discuss.elastic.co/t/update-by-query-async-task-no-failure-info-handling-conflicts/346755)

<div class="topic-metadata">

**Author:** [@Irfanulla](https://discuss.elastic.co/u/Irfanulla)\
**Replies:** 0\
**Last updated:** [November 9, 2023, 6:08am UTC](https://discuss.elastic.co/t/update-by-query-async-task-no-failure-info-handling-conflicts/346755 "2023-11-09T06:08:55Z")

</div>

I am running an update by query as a task (wait\_for\_completion=false), with 'conflicts=proceed'. I do expect version conflicts to happen sometimes and can see that info in get task response (/task/task-id). I plan to rep…

---

## [A timeout (30000 milliseconds) was reached while waiting for a transaction response from the Elastic Agent service](https://discuss.elastic.co/t/a-timeout-30000-milliseconds-was-reached-while-waiting-for-a-transaction-response-from-the-elastic-agent-service/346751)

<div class="topic-metadata">

**Author:** [@digital-thought](https://discuss.elastic.co/u/digital-thought)\
**Replies:** 0\
**Last updated:** [November 9, 2023, 3:16am UTC](https://discuss.elastic.co/t/a-timeout-30000-milliseconds-was-reached-while-waiting-for-a-transaction-response-from-the-elastic-agent-service/346751 "2023-11-09T03:16:59Z")

</div>

We have installed the Elastic Agent onto a Windows system for monitoring. Since we have installed the agent, we are seeing an Error Event (ID 7011) in the System logs of the OS that is reporting: "A timeout (30000 mill…

---

## [Why is a wildcard query string matching on stemmed terms?](https://discuss.elastic.co/t/why-is-a-wildcard-query-string-matching-on-stemmed-terms/346576)

<div class="topic-metadata">

**Author:** [@cphramington](https://discuss.elastic.co/u/cphramington)\
**Replies:** 4\
**Last updated:** [November 8, 2023, 10:54pm UTC](https://discuss.elastic.co/t/why-is-a-wildcard-query-string-matching-on-stemmed-terms/346576 "2023-11-08T22:54:52Z")

</div>

First, some background. I understand that the algorithmic stemmer is not perfect, e.g. "focused" is stemmed to "focus," while "focus" is stemmed to "focu," which I've validated by looking through the term vectors. Howev…

---

## [Elastic Synthetics: Error executing step: $(...).popover is not a function](https://discuss.elastic.co/t/elastic-synthetics-error-executing-step-popover-is-not-a-function/346625)

<div class="topic-metadata">

**Author:** [@DougR](https://discuss.elastic.co/u/DougR)\
**Replies:** 7\
**Last updated:** [November 8, 2023, 8:19pm UTC](https://discuss.elastic.co/t/elastic-synthetics-error-executing-step-popover-is-not-a-function/346625 "2023-11-08T20:19:04Z")

</div>

I am using @elastic/synthetics-1.5.0 to write and deploy user journeys as project monitors. They run as expected when I test them on my local workstation, however when I push them to Elastic Synthetics, they fail with th…

---

## [RHEL8 Upgrade](https://discuss.elastic.co/t/rhel8-upgrade/346738)

<div class="topic-metadata">

**Author:** [@Brian-cf1](https://discuss.elastic.co/u/Brian-cf1)\
**Replies:** 0\
**Last updated:** [November 8, 2023, 7:14pm UTC](https://discuss.elastic.co/t/rhel8-upgrade/346738 "2023-11-08T19:14:43Z")

</div>

Is there anything special i need to do to upgrade from rhel7 to rhel8 running ELK8?

---

## [Loss of Elasticsearch Replicas/Shards After Node Failures](https://discuss.elastic.co/t/loss-of-elasticsearch-replicas-shards-after-node-failures/346664)

<div class="topic-metadata">

**Author:** [@Jeankininho](https://discuss.elastic.co/u/Jeankininho)\
**Replies:** 3\
**Last updated:** [November 8, 2023, 6:00pm UTC](https://discuss.elastic.co/t/loss-of-elasticsearch-replicas-shards-after-node-failures/346664 "2023-11-08T18:00:09Z")

</div>

Hello, I'm facing an issue with my Elasticsearch cluster and I'm looking for some guidance or suggestions on what might be happening. I have an Elasticsearch cluster running version 6.5.1 with JVM 11.0.11. Recently, I'…

---

## [Unexpected tCONSTANT in Ruby Script](https://discuss.elastic.co/t/unexpected-tconstant-in-ruby-script/346709)

<div class="topic-metadata">

**Author:** [@Kris\_Felscher](https://discuss.elastic.co/u/Kris_Felscher)\
**Replies:** 2\
**Last updated:** [November 8, 2023, 5:42pm UTC](https://discuss.elastic.co/t/unexpected-tconstant-in-ruby-script/346709 "2023-11-08T17:42:01Z")

</div>

We have a ton (200+) of applications that are all logging to the same index. Because of this, we are seeing a few field type collisions that cause messages to get bounced (to the tune of approximately 26 million bounced …

---

## [\[Logstash\] Use variables with ilm in Elasticsearch output](https://discuss.elastic.co/t/logstash-use-variables-with-ilm-in-elasticsearch-output/346697)

<div class="topic-metadata">

**Author:** [@quoctuan2311](https://discuss.elastic.co/u/quoctuan2311)\
**Replies:** 1\
**Last updated:** [November 8, 2023, 4:16pm UTC](https://discuss.elastic.co/t/logstash-use-variables-with-ilm-in-elasticsearch-output/346697 "2023-11-08T16:16:32Z")

</div>

Can you variables with ilm\_rollover\_alias and ilm\_policy. Current I use if else but if conditions increase with each log\_type by created. Logstash will be increase time start it. Pls support me with this case. elastic…

---

## [Getting error when using variable\_width\_histogram aggregation 'Too many buckets'](https://discuss.elastic.co/t/getting-error-when-using-variable-width-histogram-aggregation-too-many-buckets/346695)

<div class="topic-metadata">

**Author:** [@Chandra\_Shekhar](https://discuss.elastic.co/u/Chandra_Shekhar)\
**Replies:** 0\
**Last updated:** [November 8, 2023, 10:34am UTC](https://discuss.elastic.co/t/getting-error-when-using-variable-width-histogram-aggregation-too-many-buckets/346695 "2023-11-08T10:34:22Z")

</div>

We are trying to execute a query to get variable\_width\_histogram aggregation results but getting an error 'Trying to create too many buckets'. However bucket size in query is 10. When trying to get bucket size 8, I am ab…

---

## [Failed to start Elasticsearch](https://discuss.elastic.co/t/failed-to-start-elasticsearch/345232)

<div class="topic-metadata">

**Author:** [@Tybe\_sacha](https://discuss.elastic.co/u/Tybe_sacha)\
**Replies:** 27\
**Last updated:** [November 8, 2023, 2:23pm UTC](https://discuss.elastic.co/t/failed-to-start-elasticsearch/345232 "2023-11-08T14:23:01Z")

</div>

Hi everyone, I'm new here ! :ok\_woman: I just finished set up basic security on my server (1VM with : Elasticsearch, 1 node, Kibana). I ran those commands : ./bin/elasticsearch-keystore add xpack.security.transport.ss…

---

## [{\\"error\\":{\\"root\_cause\\":\[{\\"type\\":\\"x\_content\_parse\_exception\\",\\"reason\\":\\"\[1:2\] Unexpected character ('\<' (code 60)):](https://discuss.elastic.co/t/error-root-cause-type-x-content-parse-exception-reason-1-2-unexpected-character-code-60/346704)

<div class="topic-metadata">

**Author:** [@sichuanmcl](https://discuss.elastic.co/u/sichuanmcl)\
**Replies:** 0\
**Last updated:** [November 8, 2023, 12:21pm UTC](https://discuss.elastic.co/t/error-root-cause-type-x-content-parse-exception-reason-1-2-unexpected-character-code-60/346704 "2023-11-08T12:21:41Z")

</div>

Hi, I'm trying to send json string data using bulk update but the json string contain html component Is that possible? Because sometimes it's just okay, and sometimes it's error parsing. This is one of the body that …

---

## [Aggregate alerts by a specific field and send a summary through an action for each field value encountered](https://discuss.elastic.co/t/aggregate-alerts-by-a-specific-field-and-send-a-summary-through-an-action-for-each-field-value-encountered/346698)

<div class="topic-metadata">

**Author:** [@Arty](https://discuss.elastic.co/u/Arty)\
**Replies:** 0\
**Last updated:** [November 8, 2023, 10:52am UTC](https://discuss.elastic.co/t/aggregate-alerts-by-a-specific-field-and-send-a-summary-through-an-action-for-each-field-value-encountered/346698 "2023-11-08T10:52:37Z")

</div>

Hi everyone, I have set up a Kibana alert security detection rule which creates an alert for all my incoming third-party system alerts (Suricata) and send each one of them to my SIRP using webhook. I have many alerts w…

---

## [Indices got deleted anonymously](https://discuss.elastic.co/t/indices-got-deleted-anonymously/346641)

<div class="topic-metadata">

**Author:** [@aneesh](https://discuss.elastic.co/u/aneesh)\
**Replies:** 3\
**Last updated:** [November 8, 2023, 10:15am UTC](https://discuss.elastic.co/t/indices-got-deleted-anonymously/346641 "2023-11-08T10:15:22Z")

</div>

Hi, some of the indices are deleted. Following is the log we have. Can you please let us know for the possibilities for same. \[2023-11-07T00:52:00,000\]\[INFO \]\[o.e.x.m.MlDailyMaintenanceService\] \[ServerName1\] triggerin…

---

## [Elasticsearch installation issues](https://discuss.elastic.co/t/elasticsearch-installation-issues/346584)

<div class="topic-metadata">

**Author:** [@bosimaosh](https://discuss.elastic.co/u/bosimaosh)\
**Replies:** 2\
**Last updated:** [November 8, 2023, 10:10am UTC](https://discuss.elastic.co/t/elasticsearch-installation-issues/346584 "2023-11-08T10:10:57Z")

</div>

After installing Elasticsearch, when I try to start the elasticsearch.service service, it fails to start and I receive the following error. system is Ubuntu 20.04. Elasticsearch version is 7.17.14 sudo systemctl stat…

---

## [Risks of Fleet and endpoint agents](https://discuss.elastic.co/t/risks-of-fleet-and-endpoint-agents/346521)

<div class="topic-metadata">

**Author:** [@ivahbo](https://discuss.elastic.co/u/ivahbo)\
**Replies:** 4\
**Last updated:** [November 8, 2023, 9:57am UTC](https://discuss.elastic.co/t/risks-of-fleet-and-endpoint-agents/346521 "2023-11-08T09:57:00Z")

</div>

If the Elastic/Fleet server is compromised, can the compromise be leveraged to gain access to the systems running endpoint agents? For example, can you push a malicious update to endpoint agents?

---

## [Understanding query difference](https://discuss.elastic.co/t/understanding-query-difference/346690)

<div class="topic-metadata">

**Author:** [@Vivek\_Burman](https://discuss.elastic.co/u/Vivek_Burman)\
**Replies:** 0\
**Last updated:** [November 8, 2023, 9:44am UTC](https://discuss.elastic.co/t/understanding-query-difference/346690 "2023-11-08T09:44:42Z")

</div>

Below are two queries with their respective responses. I would like to understand the difference between the below queries from the point of aggregation. In Request 1 I filter docs based on "unique\_name" and then group t…

---

## [How can I filter certain information from the logs?](https://discuss.elastic.co/t/how-can-i-filter-certain-information-from-the-logs/344293)

<div class="topic-metadata">

**Author:** [@hta](https://discuss.elastic.co/u/hta)\
**Replies:** 7\
**Last updated:** [November 8, 2023, 7:41am UTC](https://discuss.elastic.co/t/how-can-i-filter-certain-information-from-the-logs/344293 "2023-11-08T07:41:48Z")

</div>

We work with ELK Stack and I have the task of creating meaningful visualizations from the log entries. I have logs in the following format: { "@timestamp": \[ "2023-08-08T00:00:11.2123" \], "xxxxx": \[ "yyyyy…

---

## [Error "String length exceeds the maximum length (5000000)" when transferring a large document to the attachment pipeline](https://discuss.elastic.co/t/error-string-length-exceeds-the-maximum-length-5000000-when-transferring-a-large-document-to-the-attachment-pipeline/345687)

<div class="topic-metadata">

**Author:** [@Vlad\_I](https://discuss.elastic.co/u/Vlad_I)\
**Replies:** 5\
**Last updated:** [November 8, 2023, 3:25am UTC](https://discuss.elastic.co/t/error-string-length-exceeds-the-maximum-length-5000000-when-transferring-a-large-document-to-the-attachment-pipeline/345687 "2023-11-08T03:25:44Z")

</div>

I'm using Elasticsearch 8.9.1 Using python, I send an 8MB xlsx document to the Elasticsearch index via attachment pipeline. But the error "String length (5046272) exceeds the maximum length (5000000)" appears. For exam…

---

## [Logstash export not working correctly, only a part of data exported](https://discuss.elastic.co/t/logstash-export-not-working-correctly-only-a-part-of-data-exported/346657)

<div class="topic-metadata">

**Author:** [@andre22](https://discuss.elastic.co/u/andre22)\
**Replies:** 1\
**Last updated:** [November 7, 2023, 10:27pm UTC](https://discuss.elastic.co/t/logstash-export-not-working-correctly-only-a-part-of-data-exported/346657 "2023-11-07T22:27:33Z")

</div>

Hi, i want to export some data from old indexes and write them into a text file. When I restart logstash, it exports some data (a part of one day, the index has a complete month) and goes back to do nothing. I am using …

---

## [How to solve \_geoip\_expired\_database](https://discuss.elastic.co/t/how-to-solve-geoip-expired-database/346583)

<div class="topic-metadata">

**Author:** [@yuswanul](https://discuss.elastic.co/u/yuswanul)\
**Replies:** 6\
**Last updated:** [November 7, 2023, 5:53pm UTC](https://discuss.elastic.co/t/how-to-solve-geoip-expired-database/346583 "2023-11-07T17:53:15Z")

</div>

Hi, I've been experiencing an issue with the GeoIP filter here. So, at the beginning of my logstash deployment, the GeoIP filter was working well but recently I saw a tag on all my documents that said \_geoip\_expired\_dat…

---

## [Failure to install package \[checkpoint\]](https://discuss.elastic.co/t/failure-to-install-package-checkpoint/346646)

<div class="topic-metadata">

**Author:** [@shaam1](https://discuss.elastic.co/u/shaam1)\
**Replies:** 0\
**Last updated:** [November 7, 2023, 5:44pm UTC](https://discuss.elastic.co/t/failure-to-install-package-checkpoint/346646 "2023-11-07T17:44:03Z")

</div>

Hi, I am not new to ELK, but I have an issue which I hope to solve with your help. I installed the Checkpoint integration using the button, but I get the error below: I am not able to \[WARN \]\[plugins.fleet\] Failure to…

---

## [Rally 2.10.0](https://discuss.elastic.co/t/rally-2-10-0/346632)

<div class="topic-metadata">

**Author:** [@gbanasiak](https://discuss.elastic.co/u/gbanasiak)\
**Replies:** 0\
**Last updated:** [November 7, 2023, 3:12pm UTC](https://discuss.elastic.co/t/rally-2-10-0/346632 "2023-11-07T15:12:32Z")

</div>

Rally 2.10.0 has just been released. This version brings support for Elastic Serverless. Highlights #1797: Document Rally use with Elastic Serverless Enhancements #1791: Add ESQL operator #1789: Add serverless-aware …

---

## [Logstash log containing huge nested JSON-objects](https://discuss.elastic.co/t/logstash-log-containing-huge-nested-json-objects/346623)

<div class="topic-metadata">

**Author:** [@apt-get\_install\_skil](https://discuss.elastic.co/u/apt-get_install_skil)\
**Replies:** 0\
**Last updated:** [November 7, 2023, 2:08pm UTC](https://discuss.elastic.co/t/logstash-log-containing-huge-nested-json-objects/346623 "2023-11-07T14:08:46Z")

</div>

Hey guys, since we upgraded our stack components to version 8.10.2, Logstash's internal logging behaviour has changed. For example, after all pipelines were startet, Logstash logs the following message: { "level": "…

---

## [How I can obtain an average from a normalization formula](https://discuss.elastic.co/t/how-i-can-obtain-an-average-from-a-normalization-formula/345644)

<div class="topic-metadata">

**Author:** [@Silvy20](https://discuss.elastic.co/u/Silvy20)\
**Replies:** 3\
**Last updated:** [November 7, 2023, 2:15pm UTC](https://discuss.elastic.co/t/how-i-can-obtain-an-average-from-a-normalization-formula/345644 "2023-11-07T14:15:04Z")

</div>

Hello, I've created a data histogram chart based in a formula where I'm expecting to analyze the amount of requests per device. However. I'd like to plot in the same chart a static line with the average around that day. …

---

## [Aggregation of aggregation](https://discuss.elastic.co/t/aggregation-of-aggregation/346472)

<div class="topic-metadata">

**Author:** [@Hakan\_Kucuk](https://discuss.elastic.co/u/Hakan_Kucuk)\
**Replies:** 1\
**Last updated:** [November 7, 2023, 1:37pm UTC](https://discuss.elastic.co/t/aggregation-of-aggregation/346472 "2023-11-07T13:37:39Z")

</div>

Hello, I’m struggling to create a query and dashboard for my specific scenario. I have a dataset of orders with the following structure: order\_id order\_status timestamp 1 started 01.01.2023 1 in\_progress 02.0…

---

## [Kibana custom labels missing from CSV export](https://discuss.elastic.co/t/kibana-custom-labels-missing-from-csv-export/346616)

<div class="topic-metadata">

**Author:** [@jonnyo](https://discuss.elastic.co/u/jonnyo)\
**Replies:** 0\
**Last updated:** [November 7, 2023, 12:00pm UTC](https://discuss.elastic.co/t/kibana-custom-labels-missing-from-csv-export/346616 "2023-11-07T12:00:52Z")

</div>

Hi. I have a Kibana report that utilises Custom Labels, but these labels do not get exported when using the Share option to CSV. Is it possible to export my report to CSV and retain the custom labels that I have set? Th…

[Previous page](https://discuss.elastic.co/tag/none.md?no_tags=true&page=275)

[Next page](https://discuss.elastic.co/tag/none.md?no_tags=true&page=277)
