# \#none

**URL:** https://discuss.elastic.co/tag/none.md?no_tags=true&page=289

[Latest](https://discuss.elastic.co/latest.md) · [Categories](https://discuss.elastic.co/categories.md) · [Tags](https://discuss.elastic.co/tags.md)

**Page:** 290

---

## [Getting many more results than expected](https://discuss.elastic.co/t/getting-many-more-results-than-expected/345045)

<div class="topic-metadata">

**Author:** [@Shlomo\_Koppel](https://discuss.elastic.co/u/Shlomo_Koppel)\
**Replies:** 3\
**Last updated:** [October 15, 2023, 2:04pm UTC](https://discuss.elastic.co/t/getting-many-more-results-than-expected/345045 "2023-10-15T14:04:12Z")

</div>

Hi, I am making the following query: {'bool': {'must': \[{'terms': {'doc.attributes.type.keyword': \['Attachment', 'Document'\]}}, {'terms': {'doc.internal\_id': \['xxxx83a1c00f7004b52dxxxx'\]}}\], 'filter': \[{'range': {'doc.…

---

## [Reindexing a big index without down time](https://discuss.elastic.co/t/reindexing-a-big-index-without-down-time/345050)

<div class="topic-metadata">

**Author:** [@PodarcisMuralis](https://discuss.elastic.co/u/PodarcisMuralis)\
**Replies:** 0\
**Last updated:** [October 15, 2023, 12:59pm UTC](https://discuss.elastic.co/t/reindexing-a-big-index-without-down-time/345050 "2023-10-15T12:59:19Z")

</div>

Hi. I have a really big index with 100 millions of documents. I want to add some new fields, change existing ones and delete the redundant ones by applying explicit index. I will also use alias to switch the indiced. …

---

## [Is it bug? Disk Space Available in Hosts is calcualted average disk free](https://discuss.elastic.co/t/is-it-bug-disk-space-available-in-hosts-is-calcualted-average-disk-free/345031)

<div class="topic-metadata">

**Author:** [@oofbird](https://discuss.elastic.co/u/oofbird)\
**Replies:** 0\
**Last updated:** [October 14, 2023, 4:09pm UTC](https://discuss.elastic.co/t/is-it-bug-disk-space-available-in-hosts-is-calcualted-average-disk-free/345031 "2023-10-14T16:09:52Z")

</div>

I work with Elasitc 8.10.2. And I found Hosts feature in Observability. But Disk Space Available score is not correct. so there are inspect method, i checked it. Request for Disk Space Available is .... "aggs": {…

---

## [Wanted to have alerts in my email when a process goes down. Thanks](https://discuss.elastic.co/t/wanted-to-have-alerts-in-my-email-when-a-process-goes-down-thanks/345030)

<div class="topic-metadata">

**Author:** [@Abhiyash\_Agrawal](https://discuss.elastic.co/u/Abhiyash_Agrawal)\
**Replies:** 0\
**Last updated:** [October 14, 2023, 3:06pm UTC](https://discuss.elastic.co/t/wanted-to-have-alerts-in-my-email-when-a-process-goes-down-thanks/345030 "2023-10-14T15:06:42Z")

</div>

Wants to have an alert in my email when data of pipelines goes down and is it possible to get screen shot of kibana dashboards in the same email. Thanks

---

## [Kafka should include ip](https://discuss.elastic.co/t/kafka-should-include-ip/345029)

<div class="topic-metadata">

**Author:** [@Keremcan\_Seker](https://discuss.elastic.co/u/Keremcan_Seker)\
**Replies:** 0\
**Last updated:** [October 14, 2023, 2:42pm UTC](https://discuss.elastic.co/t/kafka-should-include-ip/345029 "2023-10-14T14:42:38Z")

</div>

my logstash has 2 pipelines one is listening for http request and other one is listening kafka The data coming from http pipeline includes host:{ip} and url in \_source section however the data from kafka does not have …

---

## [Logstash - systemd-journald suppressed mensagens](https://discuss.elastic.co/t/logstash-systemd-journald-suppressed-mensagens/344080)

<div class="topic-metadata">

**Author:** [@SilasMuniz1](https://discuss.elastic.co/u/SilasMuniz1)\
**Replies:** 8\
**Last updated:** [October 14, 2023, 2:10pm UTC](https://discuss.elastic.co/t/logstash-systemd-journald-suppressed-mensagens/344080 "2023-10-14T14:10:38Z")

</div>

Hi, Always when I restarting my logstash I see this message below: Nowadays I have CPU problem and I am trying fix it. I saw a person in the forum talk about change RateLimitBurst parameter into /etc/systemd/journa…

---

## [2GB enough RAM for a 300MB dataset?](https://discuss.elastic.co/t/2gb-enough-ram-for-a-300mb-dataset/345021)

<div class="topic-metadata">

**Author:** [@kiko](https://discuss.elastic.co/u/kiko)\
**Replies:** 1\
**Last updated:** [October 14, 2023, 6:44am UTC](https://discuss.elastic.co/t/2gb-enough-ram-for-a-300mb-dataset/345021 "2023-10-14T06:44:56Z")

</div>

Hi, I'm having a hard time finding the required RAM for a dataset like mine: it's 300 MB in size, and has around 300 products and 250 product categories. Each product's JSON is around 10-15 KB in size.

---

## [Elastic Agent not sending Data to Elastic search From KVM but works for VMWare](https://discuss.elastic.co/t/elastic-agent-not-sending-data-to-elastic-search-from-kvm-but-works-for-vmware/345012)

<div class="topic-metadata">

**Author:** [@AnyThink\_A](https://discuss.elastic.co/u/AnyThink_A)\
**Replies:** 4\
**Last updated:** [October 14, 2023, 3:12am UTC](https://discuss.elastic.co/t/elastic-agent-not-sending-data-to-elastic-search-from-kvm-but-works-for-vmware/345012 "2023-10-14T03:12:04Z")

</div>

Hello Team, In further lab setup. I am facing a strange issue. I have two setups LAB Windows -\> VMware (UBUNTU) Windows -\> VMware (Windows) Both guests are connected through host-only adapter. SANDBOX Windows -\> …

---

## [Remove my account](https://discuss.elastic.co/t/remove-my-account/345013)

<div class="topic-metadata">

**Author:** [@anon44344346](https://discuss.elastic.co/u/anon44344346)\
**Replies:** 3\
**Last updated:** [October 13, 2023, 10:54pm UTC](https://discuss.elastic.co/t/remove-my-account/345013 "2023-10-13T22:54:28Z")

</div>

how do I remove my account

---

## [Failed to close alert(s)](https://discuss.elastic.co/t/failed-to-close-alert-s/343832)

<div class="topic-metadata">

**Author:** [@IsItPossible](https://discuss.elastic.co/u/IsItPossible)\
**Replies:** 4\
**Last updated:** [October 13, 2023, 10:42pm UTC](https://discuss.elastic.co/t/failed-to-close-alert-s/343832 "2023-10-13T22:42:16Z")

</div>

Hello, Im using version 8.5.1 and since 25.09 around 12pm European time, im not able to close alerts or mark it as acknowledge. It returns an empty error message: The upload feature doesn't work so I cannot put a scree…

---

## [Unhealthy - (DEGRADED) Applied policy - Failure enabling network events; current state is disabled](https://discuss.elastic.co/t/unhealthy-degraded-applied-policy-failure-enabling-network-events-current-state-is-disabled/344477)

<div class="topic-metadata">

**Author:** [@dmgeurts](https://discuss.elastic.co/u/dmgeurts)\
**Replies:** 13\
**Last updated:** [October 13, 2023, 9:41pm UTC](https://discuss.elastic.co/t/unhealthy-degraded-applied-policy-failure-enabling-network-events-current-state-is-disabled/344477 "2023-10-13T21:41:26Z")

</div>

Elastic-agent v8.10.2 deployed on Fedora 37, has been running for months without issue. Noticed today that it's flagged as unhealthy. The same agent version and policy have been and are working fine on CentOS, Ubuntu etc…

---

## [Mounting disk at home/kafka\_data which has 20Gb already and data as well](https://discuss.elastic.co/t/mounting-disk-at-home-kafka-data-which-has-20gb-already-and-data-as-well/344991)

<div class="topic-metadata">

**Author:** [@kriti\_dabas](https://discuss.elastic.co/u/kriti_dabas)\
**Replies:** 5\
**Last updated:** [October 13, 2023, 5:33pm UTC](https://discuss.elastic.co/t/mounting-disk-at-home-kafka-data-which-has-20gb-already-and-data-as-well/344991 "2023-10-13T17:33:57Z")

</div>

typ\*\* command lsblk for checking the space added NAME MAJ:MIN RM SIZE RO TYPE MOUNTPOINT sda 8:0 0 40G 0 disk ├─sda1 8:1 0 …

---

## [CloudFlare Logpull Integration Recovering Log Gaps](https://discuss.elastic.co/t/cloudflare-logpull-integration-recovering-log-gaps/345011)

<div class="topic-metadata">

**Author:** [@wwalker](https://discuss.elastic.co/u/wwalker)\
**Replies:** 0\
**Last updated:** [October 13, 2023, 4:14pm UTC](https://discuss.elastic.co/t/cloudflare-logpull-integration-recovering-log-gaps/345011 "2023-10-13T16:14:24Z")

</div>

I ran into an issue where the Elastic Agent stopped pulling logs. I resolved that issue by reinstalling the CloudFlare integration. However, I now have a gap in my logs from when it failed to when I got it back online.…

---

## [Data for browser, location is not populating](https://discuss.elastic.co/t/data-for-browser-location-is-not-populating/344751)

<div class="topic-metadata">

**Author:** [@sameer7](https://discuss.elastic.co/u/sameer7)\
**Replies:** 5\
**Last updated:** [October 13, 2023, 2:47pm UTC](https://discuss.elastic.co/t/data-for-browser-location-is-not-populating/344751 "2023-10-13T14:47:41Z")

</div>

Hi, we've an integration with apm rum js agent and are tracking metrics with User Experience dashboard. But it seems the data for browser, location, is not getting populated. Not sure what we're missing here. We do s…

---

## [Slack Messages Stopped - error posting slack message](https://discuss.elastic.co/t/slack-messages-stopped-error-posting-slack-message/344400)

<div class="topic-metadata">

**Author:** [@zx8086](https://discuss.elastic.co/u/zx8086)\
**Replies:** 1\
**Last updated:** [October 13, 2023, 2:29pm UTC](https://discuss.elastic.co/t/slack-messages-stopped-error-posting-slack-message/344400 "2023-10-13T14:29:01Z")

</div>

Getting the following... The following error was found: error posting slack message Details: A request error occurred: self-signed certificate in certificate chain

---

## [Facing Issues while Installing Elastic-Search](https://discuss.elastic.co/t/facing-issues-while-installing-elastic-search/345006)

<div class="topic-metadata">

**Author:** [@Sadhwik\_Reddy](https://discuss.elastic.co/u/Sadhwik_Reddy)\
**Replies:** 0\
**Last updated:** [October 13, 2023, 1:07pm UTC](https://discuss.elastic.co/t/facing-issues-while-installing-elastic-search/345006 "2023-10-13T13:07:52Z")

</div>

:white\_check\_mark: Elasticsearch security features have been automatically configured! :white\_check\_mark: Authentication is enabled and cluster connections are encrypted. :x: Unable to auto-generate the password for th…

---

## [Filter data into kibana dashboard using post method](https://discuss.elastic.co/t/filter-data-into-kibana-dashboard-using-post-method/345001)

<div class="topic-metadata">

**Author:** [@Sujith\_Nair](https://discuss.elastic.co/u/Sujith_Nair)\
**Replies:** 0\
**Last updated:** [October 13, 2023, 12:33pm UTC](https://discuss.elastic.co/t/filter-data-into-kibana-dashboard-using-post-method/345001 "2023-10-13T12:33:17Z")

</div>

Hi Team, I would like to filter out data dynamically using javascript with the help of post method. I have used the a script but getting error in the post method. Attaching the script for your reference. const kibanaDa…

---

## [Getting doc\_count for each type under each index in a cluster](https://discuss.elastic.co/t/getting-doc-count-for-each-type-under-each-index-in-a-cluster/344987)

<div class="topic-metadata">

**Author:** [@Darshan\_J](https://discuss.elastic.co/u/Darshan_J)\
**Replies:** 0\
**Last updated:** [October 13, 2023, 10:39am UTC](https://discuss.elastic.co/t/getting-doc-count-for-each-type-under-each-index-in-a-cluster/344987 "2023-10-13T10:39:19Z")

</div>

Im using ES 5.6. Is there a way to get doc\_count of each type in each indices in a ES cluster.

---

## [No alias for PEM certificate when using elasticsearch-certutil cert](https://discuss.elastic.co/t/no-alias-for-pem-certificate-when-using-elasticsearch-certutil-cert/344977)

<div class="topic-metadata">

**Author:** [@Francesco66](https://discuss.elastic.co/u/Francesco66)\
**Replies:** 0\
**Last updated:** [October 13, 2023, 9:44am UTC](https://discuss.elastic.co/t/no-alias-for-pem-certificate-when-using-elasticsearch-certutil-cert/344977 "2023-10-13T09:44:12Z")

</div>

Hello, I have an application that needs to communicate to Logstash in TLS (one way) secure mode. More specifically these are the requirements to setup such secured connection: \*\*Supported certificate format …

---

## [Join Id and Name](https://discuss.elastic.co/t/join-id-and-name/344898)

<div class="topic-metadata">

**Author:** [@Samuele\_Lolli](https://discuss.elastic.co/u/Samuele_Lolli)\
**Replies:** 2\
**Last updated:** [October 13, 2023, 8:24am UTC](https://discuss.elastic.co/t/join-id-and-name/344898 "2023-10-13T08:24:04Z")

</div>

Hi everyone, im parsing with logstash some message containing an ID refering to an user, i need to add the name of the user with the specific ID. I have all the User and ID in a CSV file. Which one is the best way to a…

---

## [Facing issuse while running logstash of ELK version 8.10](https://discuss.elastic.co/t/facing-issuse-while-running-logstash-of-elk-version-8-10/344968)

<div class="topic-metadata">

**Author:** [@sandraimmaculate](https://discuss.elastic.co/u/sandraimmaculate)\
**Replies:** 0\
**Last updated:** [October 13, 2023, 6:55am UTC](https://discuss.elastic.co/t/facing-issuse-while-running-logstash-of-elk-version-8-10/344968 "2023-10-13T06:55:40Z")

</div>

Hi, i have installed elk in AWS instance with AMI Ubuntu 20.04 and hardware requirement 2vpcu, 4gb ram. i have created a Logstash configuration file like and created a log file in which contain the access logs when …

---

## [Search error and escaping characters](https://discuss.elastic.co/t/search-error-and-escaping-characters/344935)

<div class="topic-metadata">

**Author:** [@Lewis030](https://discuss.elastic.co/u/Lewis030)\
**Replies:** 1\
**Last updated:** [October 13, 2023, 5:59am UTC](https://discuss.elastic.co/t/search-error-and-escaping-characters/344935 "2023-10-13T05:59:07Z")

</div>

Hello there, i'm trying to play around with a rule to search for instances of the Sticky Key being abused in Windows. The output below has been created from converting a SIGMA rule: process where (event.category : "pro…

---

## [Change the Account which is used to run the elastic stack (Windows Server)](https://discuss.elastic.co/t/change-the-account-which-is-used-to-run-the-elastic-stack-windows-server/344741)

<div class="topic-metadata">

**Author:** [@Shaakxuur](https://discuss.elastic.co/u/Shaakxuur)\
**Replies:** 2\
**Last updated:** [October 13, 2023, 5:39am UTC](https://discuss.elastic.co/t/change-the-account-which-is-used-to-run-the-elastic-stack-windows-server/344741 "2023-10-13T05:39:17Z")

</div>

Hi! I´m running the Elastic Stack onPrem with the latest version 8.10.2 (Elasticsearch - Kibana - WinlogBeat + Metricbeat). The Elastic stack was installed with my normal Windows account on a Windows Server 2016. Now …

---

## [Elasticsearch data directory in S3 bucket](https://discuss.elastic.co/t/elasticsearch-data-directory-in-s3-bucket/344945)

<div class="topic-metadata">

**Author:** [@zaeemmasood](https://discuss.elastic.co/u/zaeemmasood)\
**Replies:** 5\
**Last updated:** [October 12, 2023, 8:04pm UTC](https://discuss.elastic.co/t/elasticsearch-data-directory-in-s3-bucket/344945 "2023-10-12T20:04:55Z")

</div>

Hi All, Is it possible to have the data directory of a newly built ES 8 cluster hosted on a S3 bucket. Idea is for the data nodes to use S3 instead of local disk or NAS. Thanks

---

## [Elastic Defend - Folder- Extensions and Process-exceptions](https://discuss.elastic.co/t/elastic-defend-folder-extensions-and-process-exceptions/344810)

<div class="topic-metadata">

**Author:** [@slash24](https://discuss.elastic.co/u/slash24)\
**Replies:** 1\
**Last updated:** [October 12, 2023, 7:37pm UTC](https://discuss.elastic.co/t/elastic-defend-folder-extensions-and-process-exceptions/344810 "2023-10-12T19:37:35Z")

</div>

When using elastic defend on enterprise workloads (Windows Servers), I want to adhere and follow official list of AV exclusions. These guidelines often includes Processes, folders, specific file-extensions (again, window…

---

## [Visualizing certain elements in an Array field](https://discuss.elastic.co/t/visualizing-certain-elements-in-an-array-field/344849)

<div class="topic-metadata">

**Author:** [@hs121](https://discuss.elastic.co/u/hs121)\
**Replies:** 2\
**Last updated:** [October 12, 2023, 3:21pm UTC](https://discuss.elastic.co/t/visualizing-certain-elements-in-an-array-field/344849 "2023-10-12T15:21:18Z")

</div>

Hi there, This is a naive question but I have a field called "tools\_usage" that holds some Array data: e.g tools\_record = \[ "toolname:banana", "toolcategory:fruit", "success:true", \] self.es.index(index="my\_i…

---

## [Elasticsearch api returning empty response (python)](https://discuss.elastic.co/t/elasticsearch-api-returning-empty-response-python/344238)

<div class="topic-metadata">

**Author:** [@Aidan\_Campbell](https://discuss.elastic.co/u/Aidan_Campbell)\
**Replies:** 3\
**Last updated:** [October 12, 2023, 3:10pm UTC](https://discuss.elastic.co/t/elasticsearch-api-returning-empty-response-python/344238 "2023-10-12T15:10:46Z")

</div>

I am trying to retrieve elasticsearch data in python using the elasticsearch rest api. When I attempt to call the search api using the requests python library, the elasticsearch python client, or directly from the comma…

---

## [Unable to connect one elasticsearch master pod to another pod to setup two node cluster](https://discuss.elastic.co/t/unable-to-connect-one-elasticsearch-master-pod-to-another-pod-to-setup-two-node-cluster/344915)

<div class="topic-metadata">

**Author:** [@Santhosh\_Sekar](https://discuss.elastic.co/u/Santhosh_Sekar)\
**Replies:** 2\
**Last updated:** [October 12, 2023, 2:23pm UTC](https://discuss.elastic.co/t/unable-to-connect-one-elasticsearch-master-pod-to-another-pod-to-setup-two-node-cluster/344915 "2023-10-12T14:23:18Z")

</div>

Hello Team, I am trying to setup two node es cluster in k8s. Issue that i am facing is that es-1 could not elect that as master and could not connect to another pod es-2.yml file cluster.name: "elastic.cluster" …

---

## [Is reindex from remote included in Python client](https://discuss.elastic.co/t/is-reindex-from-remote-included-in-python-client/344814)

<div class="topic-metadata">

**Author:** [@Shahab\_Malekzadeh](https://discuss.elastic.co/u/Shahab_Malekzadeh)\
**Replies:** 7\
**Last updated:** [October 12, 2023, 1:46pm UTC](https://discuss.elastic.co/t/is-reindex-from-remote-included-in-python-client/344814 "2023-10-12T13:46:04Z")

</div>

The Elasticsearch documentation specify the ability to reindex from remote. Can this be done through Python client? I can't find any example. This is what I got which returns error: host = 'https://XXXXXXXXX' indexna…

---

## [Name resolution in hierarchical facets. How to do it better?](https://discuss.elastic.co/t/name-resolution-in-hierarchical-facets-how-to-do-it-better/344719)

<div class="topic-metadata">

**Author:** [@Zer0](https://discuss.elastic.co/u/Zer0)\
**Replies:** 2\
**Last updated:** [October 12, 2023, 1:33pm UTC](https://discuss.elastic.co/t/name-resolution-in-hierarchical-facets-how-to-do-it-better/344719 "2023-10-12T13:33:52Z")

</div>

Hi, I have a question about how to model the following scenario in ES and if there is a better way for it than we already have. In our system there are documents and categories for these documents. The categories can be…

[Previous page](https://discuss.elastic.co/tag/none.md?no_tags=true&page=288)

[Next page](https://discuss.elastic.co/tag/none.md?no_tags=true&page=290)
