# \#none

**URL:** https://discuss.elastic.co/tag/none.md?no_tags=true&page=404

[Latest](https://discuss.elastic.co/latest.md) · [Categories](https://discuss.elastic.co/categories.md) · [Tags](https://discuss.elastic.co/tags.md)

**Page:** 405

---

## [Logstash consumes persistent queue size when no events stored](https://discuss.elastic.co/t/logstash-consumes-persistent-queue-size-when-no-events-stored/329311)

<div class="topic-metadata">

**Author:** [@ferdose\_shaik](https://discuss.elastic.co/u/ferdose_shaik)\
**Replies:** 0\
**Last updated:** [April 4, 2023, 11:03am UTC](https://discuss.elastic.co/t/logstash-consumes-persistent-queue-size-when-no-events-stored/329311 "2023-04-04T11:03:25Z")

</div>

Hi, We are using persistent queue in Logstash to store the events when output is blocked. Please refer to the following configuration. - pipeline.id: syslog queue.type: persisted queue.max\_bytes: 128mb path.confi…

---

## [During scale in of logstash through HPA data remains in the persistence queue](https://discuss.elastic.co/t/during-scale-in-of-logstash-through-hpa-data-remains-in-the-persistence-queue/329307)

<div class="topic-metadata">

**Author:** [@prashant1](https://discuss.elastic.co/u/prashant1)\
**Replies:** 0\
**Last updated:** [April 4, 2023, 10:42am UTC](https://discuss.elastic.co/t/during-scale-in-of-logstash-through-hpa-data-remains-in-the-persistence-queue/329307 "2023-04-04T10:42:31Z")

</div>

Problem Statement :- In our environment we are sending application logs from Fluentd to logstash where persistent queues are enabled. HPA is enabled on the logstash pod so when the load increases so logstash pods scale …

---

## [Mongodb/logstash connect error](https://discuss.elastic.co/t/mongodb-logstash-connect-error/328799)

<div class="topic-metadata">

**Author:** [@jskang](https://discuss.elastic.co/u/jskang)\
**Replies:** 18\
**Last updated:** [April 4, 2023, 9:57am UTC](https://discuss.elastic.co/t/mongodb-logstash-connect-error/328799 "2023-04-04T09:57:48Z")

</div>

This is an error message when running logstash. error message: Using bundled JDK: /home/admin/lg-862/jdk Sending Logstash logs to /home/admin/lg-862/logs which is now configured via log4j2.properties \[2023-03-29T18:2…

---

## [Need help to push pm2 logs into ELK server](https://discuss.elastic.co/t/need-help-to-push-pm2-logs-into-elk-server/329176)

<div class="topic-metadata">

**Author:** [@SUNA](https://discuss.elastic.co/u/SUNA)\
**Replies:** 7\
**Last updated:** [April 4, 2023, 9:16am UTC](https://discuss.elastic.co/t/need-help-to-push-pm2-logs-into-elk-server/329176 "2023-04-04T09:16:55Z")

</div>

Hi Team, Could you please help to push pm2 service logs for nodejs application into ELK server.

---

## [\[WARN \]\[o.e.c.c.ClusterFormationFailureHelper\] \[node1\] master not discovered yet, this node has not previously joined a bootstrapped cluster](https://discuss.elastic.co/t/warn-o-e-c-c-clusterformationfailurehelper-node1-master-not-discovered-yet-this-node-has-not-previously-joined-a-bootstrapped-cluster/329267)

<div class="topic-metadata">

**Author:** [@Raghulvishal](https://discuss.elastic.co/u/Raghulvishal)\
**Replies:** 9\
**Last updated:** [April 4, 2023, 7:56am UTC](https://discuss.elastic.co/t/warn-o-e-c-c-clusterformationfailurehelper-node1-master-not-discovered-yet-this-node-has-not-previously-joined-a-bootstrapped-cluster/329267 "2023-04-04T07:56:16Z")

</div>

Hi Team, I am using ES 8.6 version and configured 3 nodes,while starting the node i'am getting master not discovered yet exception. This is my elastic .yml given below. cluster.name: es-8\_6 node.name: node1 path.dat…

---

## [Failed to enable unit](https://discuss.elastic.co/t/failed-to-enable-unit/329289)

<div class="topic-metadata">

**Author:** [@bhargav.burugupalli](https://discuss.elastic.co/u/bhargav.burugupalli)\
**Replies:** 0\
**Last updated:** [April 4, 2023, 7:45am UTC](https://discuss.elastic.co/t/failed-to-enable-unit/329289 "2023-04-04T07:45:37Z")

</div>

Hello everyone, Good day ! I was trying to setup Elastic search on a RHEL machine in our office network. And following through this link.Install Elasticsearch with RPM | Elasticsearch Guide \[8.7\] | Elastic When I am t…

---

## [Shield Licensing in 2023](https://discuss.elastic.co/t/shield-licensing-in-2023/329272)

<div class="topic-metadata">

**Author:** [@ovidiutirsa-en](https://discuss.elastic.co/u/ovidiutirsa-en)\
**Replies:** 1\
**Last updated:** [April 4, 2023, 7:09am UTC](https://discuss.elastic.co/t/shield-licensing-in-2023/329272 "2023-04-04T07:09:41Z")

</div>

Hello, We are currently self hosting a very old version of Elasticsearch (2.0) and are in need of extending our Shield plugin license. Is there a way to contact someone from ES for pricing? Querying on emails did not h…

---

## [Elastic agent fails to install on Centos 7](https://discuss.elastic.co/t/elastic-agent-fails-to-install-on-centos-7/329260)

<div class="topic-metadata">

**Author:** [@sblack](https://discuss.elastic.co/u/sblack)\
**Replies:** 10\
**Last updated:** [April 4, 2023, 4:21am UTC](https://discuss.elastic.co/t/elastic-agent-fails-to-install-on-centos-7/329260 "2023-04-04T04:21:19Z")

</div>

Hi, I am getting the following error message when attempting to install Fleet agent: Installed as a system package, installation will not be altered. Error: failed to execute enroll command: fork/exec /usr/bin/elastic-…

---

## [Would be a good idea to turn all data nodes into non-eligible masters?](https://discuss.elastic.co/t/would-be-a-good-idea-to-turn-all-data-nodes-into-non-eligible-masters/329261)

<div class="topic-metadata">

**Author:** [@Bruno\_Arruda](https://discuss.elastic.co/u/Bruno_Arruda)\
**Replies:** 2\
**Last updated:** [April 4, 2023, 3:57am UTC](https://discuss.elastic.co/t/would-be-a-good-idea-to-turn-all-data-nodes-into-non-eligible-masters/329261 "2023-04-04T03:57:08Z")

</div>

Hi, Actually I have a cluster with 4 master nodes and 10 data nodes on a Kubernetes Cluster. Basically, each node causes my cluster to scale new hosts because of the anti-affinity default behavior, so my k8s got 14 node…

---

## [Determine a document's origin](https://discuss.elastic.co/t/determine-a-documents-origin/329253)

<div class="topic-metadata">

**Author:** [@etnachtman](https://discuss.elastic.co/u/etnachtman)\
**Replies:** 3\
**Last updated:** [April 4, 2023, 2:39am UTC](https://discuss.elastic.co/t/determine-a-documents-origin/329253 "2023-04-04T02:39:33Z")

</div>

Is there a way to glean additional information on what generated a document in elasticsearch? I'm working with an inherited reporting architecture and found some visualizations that are using an index pattern I'm not fa…

---

## [Kafka 0 partition metadata cannot be read in logstash6.8, other partitions can. Sample configuration:](https://discuss.elastic.co/t/kafka-0-partition-metadata-cannot-be-read-in-logstash6-8-other-partitions-can-sample-configuration/329055)

<div class="topic-metadata">

**Author:** [@angus](https://discuss.elastic.co/u/angus)\
**Replies:** 1\
**Last updated:** [April 4, 2023, 1:45am UTC](https://discuss.elastic.co/t/kafka-0-partition-metadata-cannot-be-read-in-logstash6-8-other-partitions-can-sample-configuration/329055 "2023-04-04T01:45:44Z")

</div>

kafka 0 partition metadata cannot be read in logstash6.8, other partitions can. Sample configuration: input { kafka { client\_id =\> "ycUsrRdNews" consumer\_threads =\> 4 bootstrap\_servers =\> "${KAFKA\_BOOTSTRAP\_SERVE…

---

## [Elasticsearch - getting Circuit breaker exception with sudden spike in Heap usage](https://discuss.elastic.co/t/elasticsearch-getting-circuit-breaker-exception-with-sudden-spike-in-heap-usage/329231)

<div class="topic-metadata">

**Author:** [@navaneethan](https://discuss.elastic.co/u/navaneethan)\
**Replies:** 1\
**Last updated:** [April 4, 2023, 1:33am UTC](https://discuss.elastic.co/t/elasticsearch-getting-circuit-breaker-exception-with-sudden-spike-in-heap-usage/329231 "2023-04-04T01:33:07Z")

</div>

We are having ES 7.3.2 in production and we are getting circuit breaker exception when the heap usage increases suddenly, we have also tested for the same in es 7.17 and 8.x in local but is there any improvement in lates…

---

## [Snowflake -Pyspark numPartitions support](https://discuss.elastic.co/t/snowflake-pyspark-numpartitions-support/329203)

<div class="topic-metadata">

**Author:** [@digitalspecz](https://discuss.elastic.co/u/digitalspecz)\
**Replies:** 2\
**Last updated:** [April 4, 2023, 1:30am UTC](https://discuss.elastic.co/t/snowflake-pyspark-numpartitions-support/329203 "2023-04-04T01:30:14Z")

</div>

We're attempting to run the snowflake query with Pyspark, and we've set numPartitions to 10 and submitted a spark query. However, when I checked the Snowflake History tab. As far as I can tell, only one query is being ex…

---

## [How do I enable data collection in the elastic agent of my fleet server?](https://discuss.elastic.co/t/how-do-i-enable-data-collection-in-the-elastic-agent-of-my-fleet-server/329251)

<div class="topic-metadata">

**Author:** [@WowSuchLogs](https://discuss.elastic.co/u/WowSuchLogs)\
**Replies:** 0\
**Last updated:** [April 3, 2023, 9:08pm UTC](https://discuss.elastic.co/t/how-do-i-enable-data-collection-in-the-elastic-agent-of-my-fleet-server/329251 "2023-04-03T21:08:43Z")

</div>

Hello, I'm learning ES in a home lab consisting in a server running a cluster of ES/Kibana docker nodes and I installed the fleet server on the docker host itself. I'd like to monitor Docker through the agent of the fl…

---

## [Issues with snapshots](https://discuss.elastic.co/t/issues-with-snapshots/329142)

<div class="topic-metadata">

**Author:** [@Russell\_Fulton](https://discuss.elastic.co/u/Russell_Fulton)\
**Replies:** 5\
**Last updated:** [April 3, 2023, 7:30pm UTC](https://discuss.elastic.co/t/issues-with-snapshots/329142 "2023-04-03T19:30:06Z")

</div>

I am struggling to understand how one is expected to use the snapshot system to provide a reliable back up. I understand that individual snapshots are incremental, but presumably only within repositories? I have set up…

---

## [Streaming API to local folder using logstash](https://discuss.elastic.co/t/streaming-api-to-local-folder-using-logstash/329248)

<div class="topic-metadata">

**Author:** [@Reloef\_Khoza](https://discuss.elastic.co/u/Reloef_Khoza)\
**Replies:** 0\
**Last updated:** [April 3, 2023, 7:26pm UTC](https://discuss.elastic.co/t/streaming-api-to-local-folder-using-logstash/329248 "2023-04-03T19:26:54Z")

</div>

Any example of how to stream multiple API from a website into a local folder

---

## [How to exclude attachment content and still searching inside it?](https://discuss.elastic.co/t/how-to-exclude-attachment-content-and-still-searching-inside-it/329191)

<div class="topic-metadata">

**Author:** [@aabdo](https://discuss.elastic.co/u/aabdo)\
**Replies:** 7\
**Last updated:** [April 3, 2023, 5:35pm UTC](https://discuss.elastic.co/t/how-to-exclude-attachment-content-and-still-searching-inside-it/329191 "2023-04-03T17:35:58Z")

</div>

hello, to optimize my disk space, i'm excluding my attachment content in the mapping of my index. but i can't no longer search inside it . i don't know what am i messing !! . is there any solution for this issue ??

---

## [Elasticsearch 7.17 with G1GC and Java 17](https://discuss.elastic.co/t/elasticsearch-7-17-with-g1gc-and-java-17/329230)

<div class="topic-metadata">

**Author:** [@navaneethan](https://discuss.elastic.co/u/navaneethan)\
**Replies:** 1\
**Last updated:** [April 3, 2023, 5:14pm UTC](https://discuss.elastic.co/t/elasticsearch-7-17-with-g1gc-and-java-17/329230 "2023-04-03T17:14:39Z")

</div>

Is it good to go with G1GC in Elasticsearch 7.17 With Java 17 and is there any drawback of having this config in production

---

## [If IP results in \_geoip\_lookup\_failure is it possible to fill geoip-related vields with a custom value?](https://discuss.elastic.co/t/if-ip-results-in-geoip-lookup-failure-is-it-possible-to-fill-geoip-related-vields-with-a-custom-value/329144)

<div class="topic-metadata">

**Author:** [@roman-tasi](https://discuss.elastic.co/u/roman-tasi)\
**Replies:** 3\
**Last updated:** [April 3, 2023, 4:57pm UTC](https://discuss.elastic.co/t/if-ip-results-in-geoip-lookup-failure-is-it-possible-to-fill-geoip-related-vields-with-a-custom-value/329144 "2023-04-03T16:57:54Z")

</div>

Basically if the IP cannot be found in the database, I want to fill the geoip.city\_name, geoip.region\_name, and geoip.country\_name with a custom value like "PRIVATE ADDRESS" or "IP NOT IN DATABASE" or something similar..…

---

## [Elasticsearch Engineer (On-Demand) 8.1](https://discuss.elastic.co/t/elasticsearch-engineer-on-demand-8-1/329235)

<div class="topic-metadata">

**Author:** [@Jordan\_Rylander](https://discuss.elastic.co/u/Jordan_Rylander)\
**Replies:** 2\
**Last updated:** [April 3, 2023, 4:56pm UTC](https://discuss.elastic.co/t/elasticsearch-engineer-on-demand-8-1/329235 "2023-04-03T16:56:37Z")

</div>

Course: Elasticsearch Engineer (On-Demand) 8.1 Version: 8.1 Question: I can't seem to find any password for the Kibana instance in the training materials. Creds don't seem to be available in the Strigo console like oth…

---

## [Median Forumla Question](https://discuss.elastic.co/t/median-forumla-question/329238)

<div class="topic-metadata">

**Author:** [@Joshua\_Boyd](https://discuss.elastic.co/u/Joshua_Boyd)\
**Replies:** 0\
**Last updated:** [April 3, 2023, 4:51pm UTC](https://discuss.elastic.co/t/median-forumla-question/329238 "2023-04-03T16:51:40Z")

</div>

Hello, wondering if anyone could give advice on the following: i have a table of incidents, with column of account name and the incident id incident1, account1 incident2, account1 incident3, account2 .... I want to…

---

## [Operations over indexed documents](https://discuss.elastic.co/t/operations-over-indexed-documents/329068)

<div class="topic-metadata">

**Author:** [@tmslara.a](https://discuss.elastic.co/u/tmslara.a)\
**Replies:** 4\
**Last updated:** [April 3, 2023, 4:27pm UTC](https://discuss.elastic.co/t/operations-over-indexed-documents/329068 "2023-04-03T16:27:41Z")

</div>

Hi, Is it possible to compute variables taking the documents from an index as input? I will describe my current situation and my objective. I have data indexed on an Elasticsearch cluster. My data contains a timestamp …

---

## [How to changes advance setting on my build for ELK setup](https://discuss.elastic.co/t/how-to-changes-advance-setting-on-my-build-for-elk-setup/327716)

<div class="topic-metadata">

**Author:** [@Arshukla](https://discuss.elastic.co/u/Arshukla)\
**Replies:** 1\
**Last updated:** [April 3, 2023, 3:52pm UTC](https://discuss.elastic.co/t/how-to-changes-advance-setting-on-my-build-for-elk-setup/327716 "2023-04-03T15:52:41Z")

</div>

Hello Team, Please help to change advance settings on my ELK setup for by build. I have tried with Kibana.yaml, but couldn't succeed. Below are parameters which require changes - Scaled Date Format storeinSessionStor…

---

## [Multiple index search](https://discuss.elastic.co/t/multiple-index-search/329180)

<div class="topic-metadata">

**Author:** [@Phoenix1](https://discuss.elastic.co/u/Phoenix1)\
**Replies:** 5\
**Last updated:** [April 3, 2023, 3:43pm UTC](https://discuss.elastic.co/t/multiple-index-search/329180 "2023-04-03T15:43:28Z")

</div>

How to search logs in multiple index, within discover it does not gives option to select multiple indexes in drop down option.

---

## [Logstash does not creates nor updates index on elasticsearch](https://discuss.elastic.co/t/logstash-does-not-creates-nor-updates-index-on-elasticsearch/329069)

<div class="topic-metadata">

**Author:** [@Quentin\_Moisy](https://discuss.elastic.co/u/Quentin_Moisy)\
**Replies:** 5\
**Last updated:** [April 3, 2023, 3:41pm UTC](https://discuss.elastic.co/t/logstash-does-not-creates-nor-updates-index-on-elasticsearch/329069 "2023-04-03T15:41:40Z")

</div>

Hello, I new to the ELK flow and I have some issues with Logstash. Sometime my index will be populated sometime not. Furthermore it seems that logstash does not create index on elasticsearch. Can you help on that My .c…

---

## [All AWS WAF event goes to message field even after using correct mapping](https://discuss.elastic.co/t/all-aws-waf-event-goes-to-message-field-even-after-using-correct-mapping/329227)

<div class="topic-metadata">

**Author:** [@SSP1](https://discuss.elastic.co/u/SSP1)\
**Replies:** 0\
**Last updated:** [April 3, 2023, 2:55pm UTC](https://discuss.elastic.co/t/all-aws-waf-event-goes-to-message-field-even-after-using-correct-mapping/329227 "2023-04-03T14:55:22Z")

</div>

HI, I'm using Logstash to ingest AWS WAF Logs from S3 using S3 Input login with SQS and logs are going through to elasticsearch. I can see those in Kibana but all the waf event goes to message filed. I have tried to use …

---

## [Databricks lakehouse delta tables as data source](https://discuss.elastic.co/t/databricks-lakehouse-delta-tables-as-data-source/328591)

<div class="topic-metadata">

**Author:** [@mruthyu](https://discuss.elastic.co/u/mruthyu)\
**Replies:** 2\
**Last updated:** [April 3, 2023, 2:44pm UTC](https://discuss.elastic.co/t/databricks-lakehouse-delta-tables-as-data-source/328591 "2023-04-03T14:44:47Z")

</div>

Is it possible to connect to the databricks lakehouse Delta tables to get the data to be indexed into elasticsearch?

---

## [Timeline displaying no data views](https://discuss.elastic.co/t/timeline-displaying-no-data-views/328841)

<div class="topic-metadata">

**Author:** [@AndyBox2](https://discuss.elastic.co/u/AndyBox2)\
**Replies:** 1\
**Last updated:** [April 3, 2023, 2:31pm UTC](https://discuss.elastic.co/t/timeline-displaying-no-data-views/328841 "2023-04-03T14:31:48Z")

</div>

I am all very new to the ELK stack. I am attempting to implement a risk based score into my test environment. I have successfully set up alerts into the SIEM. However, when I go into the timeline, the displayed data vie…

---

## [Kibana discover url link click naviagte to custom url](https://discuss.elastic.co/t/kibana-discover-url-link-click-naviagte-to-custom-url/329171)

<div class="topic-metadata">

**Author:** [@PRASHANT\_MEHTA](https://discuss.elastic.co/u/PRASHANT_MEHTA)\
**Replies:** 4\
**Last updated:** [April 3, 2023, 2:21pm UTC](https://discuss.elastic.co/t/kibana-discover-url-link-click-naviagte-to-custom-url/329171 "2023-04-03T14:21:46Z")

</div>

Hello All, Above is how my data looks like in old implementation.Now I'm using jdbc plugin in logstash to parse this data and send to elastic index.Now the data in table is simple value. Now I would like to click on …

---

## [Failed to obtain node locks on data dir mounted as volume in Kubernetes](https://discuss.elastic.co/t/failed-to-obtain-node-locks-on-data-dir-mounted-as-volume-in-kubernetes/329207)

<div class="topic-metadata">

**Author:** [@bade27](https://discuss.elastic.co/u/bade27)\
**Replies:** 0\
**Last updated:** [April 3, 2023, 12:44pm UTC](https://discuss.elastic.co/t/failed-to-obtain-node-locks-on-data-dir-mounted-as-volume-in-kubernetes/329207 "2023-04-03T12:44:44Z")

</div>

Hello everyone! I'm trying to deploy ES v 8.6.2 on a Kubernetes cluster in a single-node configuration, and having troubles with the data storage on bootstrap. I'm deploying ES as a StatefulSet (replicas: 1) with indexi…

[Previous page](https://discuss.elastic.co/tag/none.md?no_tags=true&page=403)

[Next page](https://discuss.elastic.co/tag/none.md?no_tags=true&page=405)
