# \#none

**URL:** https://discuss.elastic.co/tag/none.md?no_tags=true&page=286

[Latest](https://discuss.elastic.co/latest.md) · [Categories](https://discuss.elastic.co/categories.md) · [Tags](https://discuss.elastic.co/tags.md)

**Page:** 287

---

## [Please delete my account](https://discuss.elastic.co/t/please-delete-my-account/345501)

<div class="topic-metadata">

**Author:** [@anon45970649](https://discuss.elastic.co/u/anon45970649)\
**Replies:** 2\
**Last updated:** [October 21, 2023, 2:13pm UTC](https://discuss.elastic.co/t/please-delete-my-account/345501 "2023-10-21T14:13:57Z")

</div>

Please delete my account.

---

## [Unable to segregate messages from two Input files](https://discuss.elastic.co/t/unable-to-segregate-messages-from-two-input-files/345492)

<div class="topic-metadata">

**Author:** [@Blason](https://discuss.elastic.co/u/Blason)\
**Replies:** 3\
**Last updated:** [October 21, 2023, 1:26pm UTC](https://discuss.elastic.co/t/unable-to-segregate-messages-from-two-input-files/345492 "2023-10-21T13:26:44Z")

</div>

Hi Team, I posted this message on stack but not getting any replies. Can someone please help? I need help in seggregrating messages from my two different conf files. I am bit confused about ingestion Here is my first f…

---

## [How do I stringify entire event object in logstash and put it in one field](https://discuss.elastic.co/t/how-do-i-stringify-entire-event-object-in-logstash-and-put-it-in-one-field/345496)

<div class="topic-metadata">

**Author:** [@ghanshyam\_baviskar](https://discuss.elastic.co/u/ghanshyam_baviskar)\
**Replies:** 4\
**Last updated:** [October 21, 2023, 1:24pm UTC](https://discuss.elastic.co/t/how-do-i-stringify-entire-event-object-in-logstash-and-put-it-in-one-field/345496 "2023-10-21T13:24:30Z")

</div>

I am trying to implement a dead letter queue pipeline, I want to take entire event , stringify it and put it into a field "strigified\_event". so that it can be monitored for elasticsearch mapper errors input { dead\_le…

---

## [Logstash failing to starting due to the error related to the "i18n" gem](https://discuss.elastic.co/t/logstash-failing-to-starting-due-to-the-error-related-to-the-i18n-gem/345341)

<div class="topic-metadata">

**Author:** [@akhilatham](https://discuss.elastic.co/u/akhilatham)\
**Replies:** 3\
**Last updated:** [October 21, 2023, 12:41am UTC](https://discuss.elastic.co/t/logstash-failing-to-starting-due-to-the-error-related-to-the-i18n-gem/345341 "2023-10-21T00:41:35Z")

</div>

I am getting the below error: \[2023-10-18T17:37:02,573\]\[FATAL\]\[logstash.runner\] An unexpected error occurred! {:error=\>#\<ArgumentError: wrong number of arguments (given 2, expected 0..1)\>, :backtrace=\>\["/usr/share/logst…

---

## [Splitting query returns](https://discuss.elastic.co/t/splitting-query-returns/345416)

<div class="topic-metadata">

**Author:** [@ken.s](https://discuss.elastic.co/u/ken.s)\
**Replies:** 0\
**Last updated:** [October 19, 2023, 7:09pm UTC](https://discuss.elastic.co/t/splitting-query-returns/345416 "2023-10-19T19:09:36Z")

</div>

Hi there. I'm working on returning multple query results based on an inner array. For instance, I have an object that looks like this: { "customer\_order\_number": "T391704031545", "aggregation\_date\_time": "2023-…

---

## [Web crawler and semantic search](https://discuss.elastic.co/t/web-crawler-and-semantic-search/345485)

<div class="topic-metadata">

**Author:** [@Michal\_Stoklasa](https://discuss.elastic.co/u/Michal_Stoklasa)\
**Replies:** 0\
**Last updated:** [October 20, 2023, 8:13pm UTC](https://discuss.elastic.co/t/web-crawler-and-semantic-search/345485 "2023-10-20T20:13:18Z")

</div>

Hi, im looking for web crawler connected to similarity search for my chatbot product. I have to be able to crawl website and then search similar parts based on query. Something like classic vector search with embedding…

---

## [Output syslog plugin \[Unable to load plugin\]](https://discuss.elastic.co/t/output-syslog-plugin-unable-to-load-plugin/344676)

<div class="topic-metadata">

**Author:** [@ans\_k](https://discuss.elastic.co/u/ans_k)\
**Replies:** 5\
**Last updated:** [October 20, 2023, 6:17pm UTC](https://discuss.elastic.co/t/output-syslog-plugin-unable-to-load-plugin/344676 "2023-10-20T18:17:05Z")

</div>

Hello, I followed this documentation : to install offline output syslog plugin in my machine, the plugin is successfully installed, but when i try to call syslog as output in my config file (logstash), i got "Unable …

---

## [DELETE index command returns varying JSON objects](https://discuss.elastic.co/t/delete-index-command-returns-varying-json-objects/345410)

<div class="topic-metadata">

**Author:** [@mrodent](https://discuss.elastic.co/u/mrodent)\
**Replies:** 1\
**Last updated:** [October 20, 2023, 6:03pm UTC](https://discuss.elastic.co/t/delete-index-command-returns-varying-json-objects/345410 "2023-10-20T18:03:02Z")

</div>

(ES 8.6.2, W10) In Insomnia, when I try to delete an non-existent index, using command DELETE and url https://localhost:9500/my\_test\_index, I always seem to get a JSON object like this: { "error": { "root\_cause": \[ …

---

## [Background Count (bg\_count) Remains Zero in Nested and Filtered significant\_terms Aggregation](https://discuss.elastic.co/t/background-count-bg-count-remains-zero-in-nested-and-filtered-significant-terms-aggregation/345413)

<div class="topic-metadata">

**Author:** [@Emporea](https://discuss.elastic.co/u/Emporea)\
**Replies:** 2\
**Last updated:** [October 20, 2023, 3:38pm UTC](https://discuss.elastic.co/t/background-count-bg-count-remains-zero-in-nested-and-filtered-significant-terms-aggregation/345413 "2023-10-20T15:38:20Z")

</div>

Hi everyone, I've recently started using the significant\_terms aggregation with a nested field in my index, and I've noticed that the results are very similar to those of a standard terms aggregation. This leads me to b…

---

## [Recuperer puis indexer des donnees via une api via logstash](https://discuss.elastic.co/t/recuperer-puis-indexer-des-donnees-via-une-api-via-logstash/345474)

<div class="topic-metadata">

**Author:** [@Phildefer](https://discuss.elastic.co/u/Phildefer)\
**Replies:** 0\
**Last updated:** [October 20, 2023, 3:37pm UTC](https://discuss.elastic.co/t/recuperer-puis-indexer-des-donnees-via-une-api-via-logstash/345474 "2023-10-20T15:37:42Z")

</div>

Bonjour, Je cherche à automatiser la récupération régulière (toutes les semaines) de données via une API. Les requêtes se présentent sous cette forme : V https://api.acleddata.com/{data}/{command}.csv Elles permetten…

---

## [Installing Logstash plugin while service is running](https://discuss.elastic.co/t/installing-logstash-plugin-while-service-is-running/345469)

<div class="topic-metadata">

**Author:** [@Samuele\_Lolli](https://discuss.elastic.co/u/Samuele_Lolli)\
**Replies:** 2\
**Last updated:** [October 20, 2023, 2:34pm UTC](https://discuss.elastic.co/t/installing-logstash-plugin-while-service-is-running/345469 "2023-10-20T14:34:14Z")

</div>

Hi everyone, just one quick question. I have on a linux server logstash running with systemctl. I need to try some new pipelines but i need to add a plugin. I can add a new plugin while the service is running? The plug…

---

## [Java API for terms](https://discuss.elastic.co/t/java-api-for-terms/345461)

<div class="topic-metadata">

**Author:** [@mfrob](https://discuss.elastic.co/u/mfrob)\
**Replies:** 2\
**Last updated:** [October 20, 2023, 1:34pm UTC](https://discuss.elastic.co/t/java-api-for-terms/345461 "2023-10-20T13:34:02Z")

</div>

Hi, I hope someone finds this. I am very new to elasticsearch. Currently I have this code snippet in my java file to search based on customer identification card (IC) number. I am able to fetch and search based off just…

---

## [Managing Real-time and Batch Processing in Elasticsearch to Prevent Document Resurrection](https://discuss.elastic.co/t/managing-real-time-and-batch-processing-in-elasticsearch-to-prevent-document-resurrection/345452)

<div class="topic-metadata">

**Author:** [@taichi](https://discuss.elastic.co/u/taichi)\
**Replies:** 0\
**Last updated:** [October 20, 2023, 10:17am UTC](https://discuss.elastic.co/t/managing-real-time-and-batch-processing-in-elasticsearch-to-prevent-document-resurrection/345452 "2023-10-20T10:17:41Z")

</div>

Hello, I'm facing a challenge and need your expertise. In our system, we have a real-time process that adds or removes documents in an Elasticsearch index based on changes in an RDBMS. Alongside, we also have a batch pr…

---

## [Cloudflare logpush to http elastic agent](https://discuss.elastic.co/t/cloudflare-logpush-to-http-elastic-agent/344383)

<div class="topic-metadata">

**Author:** [@gyterpena](https://discuss.elastic.co/u/gyterpena)\
**Replies:** 1\
**Last updated:** [October 20, 2023, 9:44am UTC](https://discuss.elastic.co/t/cloudflare-logpush-to-http-elastic-agent/344383 "2023-10-20T09:44:03Z")

</div>

Hello I'm trying to set up logpush integration with CF. I have set up elastic agent per documentation and I'm trying to enable logpush on CF by API but I'm getting {"errors":\[{"code":1002,"message":"error validatin…

---

## [Are comments supported in the synonyms file?](https://discuss.elastic.co/t/are-comments-supported-in-the-synonyms-file/345442)

<div class="topic-metadata">

**Author:** [@peterge1998](https://discuss.elastic.co/u/peterge1998)\
**Replies:** 1\
**Last updated:** [October 20, 2023, 8:08am UTC](https://discuss.elastic.co/t/are-comments-supported-in-the-synonyms-file/345442 "2023-10-20T08:08:32Z")

</div>

We set up a new way to deploy the synonyms file to our elasticsearch hosts in our company using gitlab ci cd and ansible. Now we would like to include a comment into the synonyms file, some this like "Ansible managed, ed…

---

## [Is Elastic	Winlogbeat MSI still beta version?](https://discuss.elastic.co/t/is-elastic-winlogbeat-msi-still-beta-version/345437)

<div class="topic-metadata">

**Author:** [@Metaad](https://discuss.elastic.co/u/Metaad)\
**Replies:** 1\
**Last updated:** [October 20, 2023, 7:01am UTC](https://discuss.elastic.co/t/is-elastic-winlogbeat-msi-still-beta-version/345437 "2023-10-20T07:01:15Z")

</div>

Am downloading ElasticWinlogbeat from Download Winlogbeat | Ship Windows Event Logs | Elastic | Elastic The name of the .msi shows beta. Can anyone please confirm if its still version or just the name itself is beta. A…

---

## [Deleting Events From Frozen Data Tier](https://discuss.elastic.co/t/deleting-events-from-frozen-data-tier/345395)

<div class="topic-metadata">

**Author:** [@wwalker](https://discuss.elastic.co/u/wwalker)\
**Replies:** 3\
**Last updated:** [October 20, 2023, 6:50am UTC](https://discuss.elastic.co/t/deleting-events-from-frozen-data-tier/345395 "2023-10-20T06:50:17Z")

</div>

Attempting to delete by query events in a frozen data tier index belonging to a data stream. I've tried targeting the specific index the events are in as well as the datastream name, but I get the following error: { …

---

## [Elasticsearch is processing incoming events/messages from Logstash in a non-sequential order](https://discuss.elastic.co/t/elasticsearch-is-processing-incoming-events-messages-from-logstash-in-a-non-sequential-order/345295)

<div class="topic-metadata">

**Author:** [@Aman\_Yadav1](https://discuss.elastic.co/u/Aman_Yadav1)\
**Replies:** 3\
**Last updated:** [October 20, 2023, 6:44am UTC](https://discuss.elastic.co/t/elasticsearch-is-processing-incoming-events-messages-from-logstash-in-a-non-sequential-order/345295 "2023-10-20T06:44:27Z")

</div>

We have a system that synchronises data from MongoDB to Elasticsearch . Here are the key components: MongoDB Source Connector: This component reads events from the MongoDB oplog and produces messages on a Kafka topic. L…

---

## [What happens if index.store.type set as niofs when create index and change to default](https://discuss.elastic.co/t/what-happens-if-index-store-type-set-as-niofs-when-create-index-and-change-to-default/345427)

<div class="topic-metadata">

**Author:** [@jonathanjxsq](https://discuss.elastic.co/u/jonathanjxsq)\
**Replies:** 0\
**Last updated:** [October 20, 2023, 3:23am UTC](https://discuss.elastic.co/t/what-happens-if-index-store-type-set-as-niofs-when-create-index-and-change-to-default/345427 "2023-10-20T03:23:07Z")

</div>

I created index with index.store type as niofs. if I change the config to default, which type the system is really running with? Based on my test, it seems the system changed from niofs to default. I saw performance ben…

---

## [Shard numbers no longer equal (not even close) among cluster nodes](https://discuss.elastic.co/t/shard-numbers-no-longer-equal-not-even-close-among-cluster-nodes/345342)

<div class="topic-metadata">

**Author:** [@Hao\_Yellow](https://discuss.elastic.co/u/Hao_Yellow)\
**Replies:** 6\
**Last updated:** [October 20, 2023, 1:58am UTC](https://discuss.elastic.co/t/shard-numbers-no-longer-equal-not-even-close-among-cluster-nodes/345342 "2023-10-20T01:58:34Z")

</div>

Hello, I've been recently upgraded an Elasticsearch cluster, with 5 nodes, from version 7.3 to 7.17 then 8.9. As always, I've never disabled shard allocation and rebalancing, so until 7.17 it's observed, and as I unders…

---

## [Elasticsearch process ended by code 137](https://discuss.elastic.co/t/elasticsearch-process-ended-by-code-137/345399)

<div class="topic-metadata">

**Author:** [@gustavoluza](https://discuss.elastic.co/u/gustavoluza)\
**Replies:** 7\
**Last updated:** [October 19, 2023, 7:09pm UTC](https://discuss.elastic.co/t/elasticsearch-process-ended-by-code-137/345399 "2023-10-19T19:09:10Z")

</div>

Hi, When checking the error message for the termination of the Elasticsearch process, it was indicating that the process was terminated due to error 137, when consulting I saw that it indicates excessive memory consumpt…

---

## [Cluster to ingest 7TB of data daily](https://discuss.elastic.co/t/cluster-to-ingest-7tb-of-data-daily/345412)

<div class="topic-metadata">

**Author:** [@kaismax](https://discuss.elastic.co/u/kaismax)\
**Replies:** 1\
**Last updated:** [October 19, 2023, 6:41pm UTC](https://discuss.elastic.co/t/cluster-to-ingest-7tb-of-data-daily/345412 "2023-10-19T18:41:19Z")

</div>

The task at hand is to build a cluster that can ingest 7 terabytes daily, and Hold the data for 7 days in Hot phase, and 83 days in Cold phase, What is the best recommendation in a huge elasticsearch cluster? How many…

---

## [Question about how to proceed with the development of a metrics module for an integration](https://discuss.elastic.co/t/question-about-how-to-proceed-with-the-development-of-a-metrics-module-for-an-integration/345409)

<div class="topic-metadata">

**Author:** [@Sebastian\_Huettersen](https://discuss.elastic.co/u/Sebastian_Huettersen)\
**Replies:** 0\
**Last updated:** [October 19, 2023, 5:40pm UTC](https://discuss.elastic.co/t/question-about-how-to-proceed-with-the-development-of-a-metrics-module-for-an-integration/345409 "2023-10-19T17:40:48Z")

</div>

Hey everyone currently I am developing an Elastic Integration for openVPN. The normalization of the logs is no problem for me. But now I would like to have metrics as well and of course they should be nicely visualized i…

---

## [Elastic Agent - Multiple inputs/output through Fleet](https://discuss.elastic.co/t/elastic-agent-multiple-inputs-output-through-fleet/345336)

<div class="topic-metadata">

**Author:** [@vee](https://discuss.elastic.co/u/vee)\
**Replies:** 2\
**Last updated:** [October 19, 2023, 2:58pm UTC](https://discuss.elastic.co/t/elastic-agent-multiple-inputs-output-through-fleet/345336 "2023-10-19T14:58:52Z")

</div>

Hello, here's our current setup: Multiple filebeats on a single VM (hundreds of VMs - Linux & windows based) Each filebeat scrapes from a unique path, sends to unique output (logstash endpoints) Metricbeat on ea…

---

## [Daily incoming data size calculation](https://discuss.elastic.co/t/daily-incoming-data-size-calculation/345105)

<div class="topic-metadata">

**Author:** [@nonameo](https://discuss.elastic.co/u/nonameo)\
**Replies:** 3\
**Last updated:** [October 19, 2023, 2:09pm UTC](https://discuss.elastic.co/t/daily-incoming-data-size-calculation/345105 "2023-10-19T14:09:14Z")

</div>

Hi everyone, I need to know the daily incoming data size in GB. How can I calculate it? Could you please help with that?

---

## [In pie chart kibana is this possible to set customize colour?](https://discuss.elastic.co/t/in-pie-chart-kibana-is-this-possible-to-set-customize-colour/344917)

<div class="topic-metadata">

**Author:** [@jaimika\_kosambia](https://discuss.elastic.co/u/jaimika_kosambia)\
**Replies:** 2\
**Last updated:** [October 19, 2023, 1:01pm UTC](https://discuss.elastic.co/t/in-pie-chart-kibana-is-this-possible-to-set-customize-colour/344917 "2023-10-19T13:01:46Z")

</div>

In pie chart kibana, is this possible to set customize colour ?

---

## [EQL sequence detection on windows and cloudtrail](https://discuss.elastic.co/t/eql-sequence-detection-on-windows-and-cloudtrail/345383)

<div class="topic-metadata">

**Author:** [@sholzhauer](https://discuss.elastic.co/u/sholzhauer)\
**Replies:** 0\
**Last updated:** [October 19, 2023, 11:36am UTC](https://discuss.elastic.co/t/eql-sequence-detection-on-windows-and-cloudtrail/345383 "2023-10-19T11:36:33Z")

</div>

Hi all,I have a bit of a challenge in building a detection, hoping someone has a good idea. scenario We have a couple of windows hosts in a dedicated aws account which should only be turned on temporary. I am looking t…

---

## [Many open alarms (building blocks) due to Correlation rules](https://discuss.elastic.co/t/many-open-alarms-building-blocks-due-to-correlation-rules/345014)

<div class="topic-metadata">

**Author:** [@siiman](https://discuss.elastic.co/u/siiman)\
**Replies:** 1\
**Last updated:** [October 19, 2023, 9:55am UTC](https://discuss.elastic.co/t/many-open-alarms-building-blocks-due-to-correlation-rules/345014 "2023-10-19T09:55:46Z")

</div>

Hello all, TL;DR When an alert is triggered by a correlation rule, the linked alerts (building blocks) are not automatically closed with the "main alert". This results in a large number of unnoticed open alerts. Probl…

---

## [Wrong format for duration in milliseconds](https://discuss.elastic.co/t/wrong-format-for-duration-in-milliseconds/344414)

<div class="topic-metadata">

**Author:** [@desna](https://discuss.elastic.co/u/desna)\
**Replies:** 1\
**Last updated:** [October 19, 2023, 9:48am UTC](https://discuss.elastic.co/t/wrong-format-for-duration-in-milliseconds/344414 "2023-10-19T09:48:08Z")

</div>

I have a property that represents duration in milliseconds (type Long), for example 1204172350 is 1,99 weeks (or 13,94 days). From Kibana index patterns I've configured my field with a format duration, input format: mill…

---

## [Elasticsearch REST API Commands](https://discuss.elastic.co/t/elasticsearch-rest-api-commands/345168)

<div class="topic-metadata">

**Author:** [@Debasis\_Mallick](https://discuss.elastic.co/u/Debasis_Mallick)\
**Replies:** 4\
**Last updated:** [October 19, 2023, 9:24am UTC](https://discuss.elastic.co/t/elasticsearch-rest-api-commands/345168 "2023-10-19T09:24:24Z")

</div>

Hi Team, I need a help for understanding the O/P of REST API commands while running through Dev Console in Kibana Dashboard. While doing search of an item, apart from result the O/P shows so many other details. Is th…

[Previous page](https://discuss.elastic.co/tag/none.md?no_tags=true&page=285)

[Next page](https://discuss.elastic.co/tag/none.md?no_tags=true&page=287)
