# \#none

**URL:** https://discuss.elastic.co/tag/none.md?no_tags=true&page=278

[Latest](https://discuss.elastic.co/latest.md) · [Categories](https://discuss.elastic.co/categories.md) · [Tags](https://discuss.elastic.co/tags.md)

**Page:** 279

---

## [How can I get Gigabyte instead of number of records?](https://discuss.elastic.co/t/how-can-i-get-gigabyte-instead-of-number-of-records/346272)

<div class="topic-metadata">

**Author:** [@Indunil75](https://discuss.elastic.co/u/Indunil75)\
**Replies:** 1\
**Last updated:** [November 6, 2023, 4:34am UTC](https://discuss.elastic.co/t/how-can-i-get-gigabyte-instead-of-number-of-records/346272 "2023-11-06T04:34:02Z")

</div>

I have configured elasticsearch, kibana and logstash. fortigate firewall sends logs. While creating dashboard, It gives count of records. How can I get Gigabyte instead of count of records?

---

## [Node Replacement Procedure](https://discuss.elastic.co/t/node-replacement-procedure/346478)

<div class="topic-metadata">

**Author:** [@digital-thought](https://discuss.elastic.co/u/digital-thought)\
**Replies:** 0\
**Last updated:** [November 5, 2023, 11:05pm UTC](https://discuss.elastic.co/t/node-replacement-procedure/346478 "2023-11-05T23:05:01Z")

</div>

Hi All, I have a multi-tier elastic cluster setup. My Hot tier is made up of 4 nodes. I need to replace one of these nodes with a completely new instance (machine). Can anyone recommend the best procedure to follow t…

---

## [Why there are not any index on elasticsearch after run filebeat](https://discuss.elastic.co/t/why-there-are-not-any-index-on-elasticsearch-after-run-filebeat/346422)

<div class="topic-metadata">

**Author:** [@baber1223](https://discuss.elastic.co/u/baber1223)\
**Replies:** 9\
**Last updated:** [November 5, 2023, 2:43pm UTC](https://discuss.elastic.co/t/why-there-are-not-any-index-on-elasticsearch-after-run-filebeat/346422 "2023-11-05T14:43:56Z")

</div>

My elasticsearch version = 8.10.4 My filebeat version : 8.7 Also these are outputs : filebeat test output elasticsearch: https://172.10.110.29:9200... parse url... OK connection... parse host... OK dns loo…

---

## [Where can we find those user tutorials mentioned on the badges?](https://discuss.elastic.co/t/where-can-we-find-those-user-tutorials-mentioned-on-the-badges/346432)

<div class="topic-metadata">

**Author:** [@bunste](https://discuss.elastic.co/u/bunste)\
**Replies:** 4\
**Last updated:** [November 5, 2023, 1:42pm UTC](https://discuss.elastic.co/t/where-can-we-find-those-user-tutorials-mentioned-on-the-badges/346432 "2023-11-05T13:42:56Z")

</div>

In the badge overview you can see that there seems to be a new user tutorial ("Certified" badge) and an advanced user tutorial ("Licensed" badge). But where can we find these tutorials? I have not been able to find them…

---

## [Edit static lookup with API](https://discuss.elastic.co/t/edit-static-lookup-with-api/346111)

<div class="topic-metadata">

**Author:** [@cyberzlo](https://discuss.elastic.co/u/cyberzlo)\
**Replies:** 1\
**Last updated:** [November 5, 2023, 10:24am UTC](https://discuss.elastic.co/t/edit-static-lookup-with-api/346111 "2023-11-05T10:24:11Z")

</div>

I have the following problem. I have an X field in every document, but not in every document I have a Y field. I would like the information from field Y to appear in place of field X. Specifically, it is about the occurr…

---

## [Import Pretrained Model to Elasticsearch Cluster](https://discuss.elastic.co/t/import-pretrained-model-to-elasticsearch-cluster/346440)

<div class="topic-metadata">

**Author:** [@Khanh\_Dao\_Minh](https://discuss.elastic.co/u/Khanh_Dao_Minh)\
**Replies:** 1\
**Last updated:** [November 5, 2023, 3:09am UTC](https://discuss.elastic.co/t/import-pretrained-model-to-elasticsearch-cluster/346440 "2023-11-05T03:09:09Z")

</div>

Hello everyone. I have a question about import sentence-transformer model to elasticsearch cluster. When I run the python script below, I see only 1 node has allocated my mode, but I want to allocate my model in 2 nodes …

---

## [This error seems to be related to mapping issues in Elasticsearch, below error found in logstash](https://discuss.elastic.co/t/this-error-seems-to-be-related-to-mapping-issues-in-elasticsearch-below-error-found-in-logstash/346414)

<div class="topic-metadata">

**Author:** [@Sreecharanhope](https://discuss.elastic.co/u/Sreecharanhope)\
**Replies:** 4\
**Last updated:** [November 5, 2023, 2:38am UTC](https://discuss.elastic.co/t/this-error-seems-to-be-related-to-mapping-issues-in-elasticsearch-below-error-found-in-logstash/346414 "2023-11-05T02:38:14Z")

</div>

2023-11-04T10:33:48,353\]\[WARN \]\[logstash.outputs.elasticsearch\]\[main\] Could not index event to Elasticsearch. {:status=\>400, :action=\>\["index", {:\_id=\>nil, :\_index=\>"staging-2023.11.04", :\_type=\>"\_doc", :routing=\>nil}, …

---

## [How to create a document where the \_id has spaces (Dev Tools)](https://discuss.elastic.co/t/how-to-create-a-document-where-the-id-has-spaces-dev-tools/346404)

<div class="topic-metadata">

**Author:** [@thadc](https://discuss.elastic.co/u/thadc)\
**Replies:** 9\
**Last updated:** [November 4, 2023, 10:08pm UTC](https://discuss.elastic.co/t/how-to-create-a-document-where-the-id-has-spaces-dev-tools/346404 "2023-11-04T22:08:45Z")

</div>

I am attempting to create a document in an index where \_id has spaces. I get a parsing exception in Dev Tools. Here is the start of POST statement: POST /label-expression/\_doc/(AB\_123 | CD\_123) I must have the spaces, …

---

## [Query for the fields which is non empty](https://discuss.elastic.co/t/query-for-the-fields-which-is-non-empty/345764)

<div class="topic-metadata">

**Author:** [@Manasa4](https://discuss.elastic.co/u/Manasa4)\
**Replies:** 5\
**Last updated:** [November 4, 2023, 6:27pm UTC](https://discuss.elastic.co/t/query-for-the-fields-which-is-non-empty/345764 "2023-11-04T18:27:32Z")

</div>

Hi Team, I'm reaching out query that I have, I want a query which returns the field with any random value inside it and filter out the empty records. For eg: In my case, I have a FileContent.content field and it has va…

---

## [This error seems to be related to mapping issues in Elasticsearch, ](https://discuss.elastic.co/t/this-error-seems-to-be-related-to-mapping-issues-in-elasticsearch/346427)

<div class="topic-metadata">

**Author:** [@jamesjames](https://discuss.elastic.co/u/jamesjames)\
**Replies:** 2\
**Last updated:** [November 4, 2023, 4:06pm UTC](https://discuss.elastic.co/t/this-error-seems-to-be-related-to-mapping-issues-in-elasticsearch/346427 "2023-11-04T16:06:29Z")

</div>

2023-11-04T10:33:48,353\]\[WARN \]\[logstash.outputs.elasticsearch\]\[main\] Could not index event to Elasticsearch. {:status=\>400, :action=\>\["index", {:\_id=\>nil, :\_index=\>"staging-2023.11.04", :\_type=\>"\_doc", :routing=\>nil}, …

---

## [Kibana Plugin](https://discuss.elastic.co/t/kibana-plugin/346245)

<div class="topic-metadata">

**Author:** [@Srini-99](https://discuss.elastic.co/u/Srini-99)\
**Replies:** 1\
**Last updated:** [November 4, 2023, 12:49pm UTC](https://discuss.elastic.co/t/kibana-plugin/346245 "2023-11-04T12:49:09Z")

</div>

Hi! I wanted to create a custom plugin to add on to kibana. since i had Elasticsearch and kibana already set up and running, i started my plugin development in the 'plugin' of kibana. (system - win11) when i start kib…

---

## [Extract JSON log from JSON](https://discuss.elastic.co/t/extract-json-log-from-json/346353)

<div class="topic-metadata">

**Author:** [@AlarleCKe](https://discuss.elastic.co/u/AlarleCKe)\
**Replies:** 2\
**Last updated:** [November 4, 2023, 11:33am UTC](https://discuss.elastic.co/t/extract-json-log-from-json/346353 "2023-11-04T11:33:26Z")

</div>

Hi everyone, I´m trying to create an index based on a script output. The script itself creates an NDJSON like: {"packages/current\_version":"3.7.3-2+deb10u5","packages/candidate\_version":"3.7.3-2+deb10u6","packages/prio…

---

## [Logstash http\_pollar Rest API push more than 1000 records](https://discuss.elastic.co/t/logstash-http-pollar-rest-api-push-more-than-1000-records/346374)

<div class="topic-metadata">

**Author:** [@puneetsharma2](https://discuss.elastic.co/u/puneetsharma2)\
**Replies:** 12\
**Last updated:** [November 3, 2023, 6:35pm UTC](https://discuss.elastic.co/t/logstash-http-pollar-rest-api-push-more-than-1000-records/346374 "2023-11-03T18:35:20Z")

</div>

Logstash http\_pollar Rest API push more than 1000 records As we are using HTTP\_POLLAR to execute the rest API and push the response in elastic index in one go. But default only 1000 records are pushing in elastic. How …

---

## [Show only time with out date](https://discuss.elastic.co/t/show-only-time-with-out-date/345059)

<div class="topic-metadata">

**Author:** [@naveed786.shaik](https://discuss.elastic.co/u/naveed786.shaik)\
**Replies:** 7\
**Last updated:** [November 3, 2023, 11:10pm UTC](https://discuss.elastic.co/t/show-only-time-with-out-date/345059 "2023-11-03T23:10:49Z")

</div>

Hi All, Need a help with Kibana dashboard , I could see the customization for date and time, in version 8.6.0 of the dashboard. I am trying to get indexed data with only time where need to exclude date. Please suggest …

---

## [High cpu for new data nodes for several days?](https://discuss.elastic.co/t/high-cpu-for-new-data-nodes-for-several-days/346400)

<div class="topic-metadata">

**Author:** [@linkerc](https://discuss.elastic.co/u/linkerc)\
**Replies:** 0\
**Last updated:** [November 3, 2023, 7:22pm UTC](https://discuss.elastic.co/t/high-cpu-for-new-data-nodes-for-several-days/346400 "2023-11-03T19:22:55Z")

</div>

Has anybody experienced this? Or is this normal? After adding 6 new data nodes, the high CPU (bouncing off 100%) often persisted for several days (around 5 days). The shards are balanced within a day of new node addit…

---

## [Accessing Aggregation buckets to get the \`key\` value and \`\_doc\` values](https://discuss.elastic.co/t/accessing-aggregation-buckets-to-get-the-key-value-and-doc-values/346391)

<div class="topic-metadata">

**Author:** [@Santosh\_mandyajayara](https://discuss.elastic.co/u/Santosh_mandyajayara)\
**Replies:** 0\
**Last updated:** [November 3, 2023, 5:12pm UTC](https://discuss.elastic.co/t/accessing-aggregation-buckets-to-get-the-key-value-and-doc-values/346391 "2023-11-03T17:12:50Z")

</div>

We were using the Rest High Level Client before and below was the usage to access the aggregation buckets from the SearchResponse ParsedStringTerms aggregation1 = searchResponse.getAggregations().get(AGGREGATION1.name…

---

## [Deleting indices older than 30 days with policy problem](https://discuss.elastic.co/t/deleting-indices-older-than-30-days-with-policy-problem/346388)

<div class="topic-metadata">

**Author:** [@Mark\_S](https://discuss.elastic.co/u/Mark_S)\
**Replies:** 0\
**Last updated:** [November 3, 2023, 4:51pm UTC](https://discuss.elastic.co/t/deleting-indices-older-than-30-days-with-policy-problem/346388 "2023-11-03T16:51:25Z")

</div>

I am using an application that creates daily indices, using legacy index template. Two types of indices are created: jaeger-spans-date and jaeger-services-date (where date is the date produced). Using the kibana UI, I c…

---

## [Elastic Agent Disk Queue](https://discuss.elastic.co/t/elastic-agent-disk-queue/346382)

<div class="topic-metadata">

**Author:** [@wwalker](https://discuss.elastic.co/u/wwalker)\
**Replies:** 0\
**Last updated:** [November 3, 2023, 3:42pm UTC](https://discuss.elastic.co/t/elastic-agent-disk-queue/346382 "2023-11-03T15:42:03Z")

</div>

Does Elastic Agent support disk queue? How do you configure it?

---

## [Logstash + S3 Input plugin with High Availability](https://discuss.elastic.co/t/logstash-s3-input-plugin-with-high-availability/346370)

<div class="topic-metadata">

**Author:** [@Pedro\_Baldanta](https://discuss.elastic.co/u/Pedro_Baldanta)\
**Replies:** 1\
**Last updated:** [November 3, 2023, 2:01pm UTC](https://discuss.elastic.co/t/logstash-s3-input-plugin-with-high-availability/346370 "2023-11-03T14:01:38Z")

</div>

Hi all: I need to implement high availability of Logstash reading log files from S3. Is there any way to implement HA via scaleout without duplicating the events? Each VM is going to store until which file has read, s…

---

## [Visualize logs from two Suricata filebeat modules in one dashboard](https://discuss.elastic.co/t/visualize-logs-from-two-suricata-filebeat-modules-in-one-dashboard/346306)

<div class="topic-metadata">

**Author:** [@edpuig97](https://discuss.elastic.co/u/edpuig97)\
**Replies:** 1\
**Last updated:** [November 3, 2023, 12:35pm UTC](https://discuss.elastic.co/t/visualize-logs-from-two-suricata-filebeat-modules-in-one-dashboard/346306 "2023-11-03T12:35:21Z")

</div>

Hi, I'm using Filebeat's suricata module from two suricata hosts, when I setup those, only the last of them is showed in the Kibana dashboards. Is any way to show both of them? Thanks in advance.

---

## [Additional Elastic Agent Integrations needed](https://discuss.elastic.co/t/additional-elastic-agent-integrations-needed/346308)

<div class="topic-metadata">

**Author:** [@dwortmann](https://discuss.elastic.co/u/dwortmann)\
**Replies:** 2\
**Last updated:** [November 3, 2023, 12:09pm UTC](https://discuss.elastic.co/t/additional-elastic-agent-integrations-needed/346308 "2023-11-03T12:09:51Z")

</div>

We are current users of Elastic stack and are using FileBeat modules to assist with parsing of data. We have begun to review the Elastic Agent and have found there are several additional integrations that are available …

---

## [How to search these kind of texts without Synonyms](https://discuss.elastic.co/t/how-to-search-these-kind-of-texts-without-synonyms/346362)

<div class="topic-metadata">

**Author:** [@Anand\_Konagala](https://discuss.elastic.co/u/Anand_Konagala)\
**Replies:** 0\
**Last updated:** [November 3, 2023, 11:55am UTC](https://discuss.elastic.co/t/how-to-search-these-kind-of-texts-without-synonyms/346362 "2023-11-03T11:55:42Z")

</div>

Hi, When I search with this query, { "match":{ "company":{ "query":"walmart" } } …

---

## [Elastic nodes started to give hardware error on esxi 8.01c servers](https://discuss.elastic.co/t/elastic-nodes-started-to-give-hardware-error-on-esxi-8-01c-servers/346208)

<div class="topic-metadata">

**Author:** [@cemkayar](https://discuss.elastic.co/u/cemkayar)\
**Replies:** 8\
**Last updated:** [November 3, 2023, 9:56am UTC](https://discuss.elastic.co/t/elastic-nodes-started-to-give-hardware-error-on-esxi-8-01c-servers/346208 "2023-11-03T09:56:09Z")

</div>

Hi, After upgrading ESXi servers from 7.0.3l to 8.0.1c some of the elastic clusters started to give hardware errors during index hash. If move the problematic elastics VMs to the old version of the esxi servers (7.0.3l …

---

## [After stopping elasticserver 8.x it is shown status deactivating](https://discuss.elastic.co/t/after-stopping-elasticserver-8-x-it-is-shown-status-deactivating/346329)

<div class="topic-metadata">

**Author:** [@subrahmanyam](https://discuss.elastic.co/u/subrahmanyam)\
**Replies:** 1\
**Last updated:** [November 3, 2023, 8:58am UTC](https://discuss.elastic.co/t/after-stopping-elasticserver-8-x-it-is-shown-status-deactivating/346329 "2023-11-03T08:58:01Z")

</div>

Loaded: loaded (/etc/systemd/system/Elasticsearch8.service; enabled; vendor preset: disabled) Active: deactivating (stop-sigterm) since Thu 2023-11-02 13:28:39 GMT; 16h ago Process: 2780103 ExecStop=/test/config/elasti…

---

## [Online monitoring log sending devices in logstash machine](https://discuss.elastic.co/t/online-monitoring-log-sending-devices-in-logstash-machine/346337)

<div class="topic-metadata">

**Author:** [@Mohsen\_R.Marandi](https://discuss.elastic.co/u/Mohsen_R.Marandi)\
**Replies:** 0\
**Last updated:** [November 3, 2023, 8:24am UTC](https://discuss.elastic.co/t/online-monitoring-log-sending-devices-in-logstash-machine/346337 "2023-11-03T08:24:36Z")

</div>

Hi every one I have set up logstash on a large scale network. Is there a way to online monitor log sending devices? Tanks

---

## [Logstash Stuck Indexing Pipeline and throwing Error - warning: already initialized constant Manticore::Client::HttpPost](https://discuss.elastic.co/t/logstash-stuck-indexing-pipeline-and-throwing-error-warning-already-initialized-constant-manticore-httppost/345948)

<div class="topic-metadata">

**Author:** [@mnasim1](https://discuss.elastic.co/u/mnasim1)\
**Replies:** 5\
**Last updated:** [November 3, 2023, 5:52am UTC](https://discuss.elastic.co/t/logstash-stuck-indexing-pipeline-and-throwing-error-warning-already-initialized-constant-manticore-httppost/345948 "2023-11-03T05:52:57Z")

</div>

Logstash was running fine and successfully reading data from the Postgres Database for indexing. However, it suddenly started throwing the following errors, causing the indexing pipeline to become stuck: logstash-8.6.2…

---

## [Logstash 8.10.4 breaking changes](https://discuss.elastic.co/t/logstash-8-10-4-breaking-changes/346312)

<div class="topic-metadata">

**Author:** [@ranjini](https://discuss.elastic.co/u/ranjini)\
**Replies:** 9\
**Last updated:** [November 3, 2023, 4:55am UTC](https://discuss.elastic.co/t/logstash-8-10-4-breaking-changes/346312 "2023-11-03T04:55:19Z")

</div>

"status"=\>400, "error"=\>{"type"=\>"mapper\_parsing\_exception", "reason"=\>"failed to parse field \[host\] of type \[text\] in document with id 'xxxxxxx'. added this to resolve the above mutate { rename =\> { "\[host\]" =\> …

---

## [Nested JSON in CSV](https://discuss.elastic.co/t/nested-json-in-csv/346310)

<div class="topic-metadata">

**Author:** [@Cal](https://discuss.elastic.co/u/Cal)\
**Replies:** 1\
**Last updated:** [November 3, 2023, 4:54am UTC](https://discuss.elastic.co/t/nested-json-in-csv/346310 "2023-11-03T04:54:39Z")

</div>

I have a CSV file with 1500 rows of data. I am wanting to optimize how I have certain data and nest it in Elastic. Here's an example: Name, Location, Age, Favorite Colors Bob, USA, 32, Orange, Pink Jane, USA, 28, Gr…

---

## [Coordinating Nodes High Circuit Breaker Tripped Counts](https://discuss.elastic.co/t/coordinating-nodes-high-circuit-breaker-tripped-counts/344161)

<div class="topic-metadata">

**Author:** [@BenB196](https://discuss.elastic.co/u/BenB196)\
**Replies:** 11\
**Last updated:** [November 3, 2023, 2:37am UTC](https://discuss.elastic.co/t/coordinating-nodes-high-circuit-breaker-tripped-counts/344161 "2023-11-03T02:37:24Z")

</div>

Hi All, I'm curious if anyone has any ideas on an issue I'm seeing. I have a cluster of 33 nodes, 3 of these nodes are coordinating only nodes that handle all requests. I've been noticing that these coordinating nodes…

---

## [Manually Add node to cluster Elasticsearch 8.6](https://discuss.elastic.co/t/manually-add-node-to-cluster-elasticsearch-8-6/346322)

<div class="topic-metadata">

**Author:** [@syifelastic](https://discuss.elastic.co/u/syifelastic)\
**Replies:** 4\
**Last updated:** [November 3, 2023, 1:52am UTC](https://discuss.elastic.co/t/manually-add-node-to-cluster-elasticsearch-8-6/346322 "2023-11-03T01:52:51Z")

</div>

Hello. I have a 3 node Elasticsearch cluster. I originally set up the 3 nodes with an enrollment token. However, I later changed from http keystore to a certificate/key configuration in the yml. This breaks the enrollme…

[Previous page](https://discuss.elastic.co/tag/none.md?no_tags=true&page=277)

[Next page](https://discuss.elastic.co/tag/none.md?no_tags=true&page=279)
