# \#none

**URL:** https://discuss.elastic.co/tag/none.md?no_tags=true&page=460

[Latest](https://discuss.elastic.co/latest.md) · [Categories](https://discuss.elastic.co/categories.md) · [Tags](https://discuss.elastic.co/tags.md)

**Page:** 461

---

## [How to calculate disk space if 1tb of data ingested every day and log reteyis 180 days](https://discuss.elastic.co/t/how-to-calculate-disk-space-if-1tb-of-data-ingested-every-day-and-log-reteyis-180-days/322893)

<div class="topic-metadata">

**Author:** [@happylearning](https://discuss.elastic.co/u/happylearning)\
**Replies:** 1\
**Last updated:** [January 11, 2023, 9:06am UTC](https://discuss.elastic.co/t/how-to-calculate-disk-space-if-1tb-of-data-ingested-every-day-and-log-reteyis-180-days/322893 "2023-01-11T09:06:15Z")

</div>

How to calculate disk space if 1tb of data ingested every day and log reteyis 180 days

---

## [Combining phonetic filter with synonym\_graph filter](https://discuss.elastic.co/t/combining-phonetic-filter-with-synonym-graph-filter/322838)

<div class="topic-metadata">

**Author:** [@rune](https://discuss.elastic.co/u/rune)\
**Replies:** 0\
**Last updated:** [January 10, 2023, 1:12pm UTC](https://discuss.elastic.co/t/combining-phonetic-filter-with-synonym-graph-filter/322838 "2023-01-10T13:12:25Z")

</div>

So - I want to use the phonetic filter to transform the user query into phonetic hashes as it's supposed to do. F.ex. with "refined\_soundex" i get: pacemaker -\> P103080309 Then I want to take this hash value to my syno…

---

## [Kbn\_network plugin for Kibana 8.5+?](https://discuss.elastic.co/t/kbn-network-plugin-for-kibana-8-5/322891)

<div class="topic-metadata">

**Author:** [@Sheereen](https://discuss.elastic.co/u/Sheereen)\
**Replies:** 1\
**Last updated:** [January 11, 2023, 8:24am UTC](https://discuss.elastic.co/t/kbn-network-plugin-for-kibana-8-5/322891 "2023-01-11T08:24:47Z")

</div>

Hi, Is the kbn\_network plugin available for Kibana version 8.5+? Thanks

---

## [Different Doc count after reindexing](https://discuss.elastic.co/t/different-doc-count-after-reindexing/322826)

<div class="topic-metadata">

**Author:** [@cr\_168328](https://discuss.elastic.co/u/cr_168328)\
**Replies:** 5\
**Last updated:** [January 11, 2023, 8:10am UTC](https://discuss.elastic.co/t/different-doc-count-after-reindexing/322826 "2023-01-11T08:10:11Z")

</div>

I have an index user1. To add some fields, I created a new index and did reindexing using the query: POST /\_reindex?scroll=30m { "source": { "index": "user1" }, "dest": { "index": "user2" } } After rei…

---

## [Need Some Help Understanding Match Query Behavior](https://discuss.elastic.co/t/need-some-help-understanding-match-query-behavior/322870)

<div class="topic-metadata">

**Author:** [@denvaar](https://discuss.elastic.co/u/denvaar)\
**Replies:** 2\
**Last updated:** [January 11, 2023, 7:10am UTC](https://discuss.elastic.co/t/need-some-help-understanding-match-query-behavior/322870 "2023-01-11T07:10:43Z")

</div>

I'm confused why the match query seen below is matching two documents rather than just one. I thought using the "and" operator would require all terms to be present in order for it to match. When I hit the explain endpo…

---

## [Exclude log messages in logstash](https://discuss.elastic.co/t/exclude-log-messages-in-logstash/322829)

<div class="topic-metadata">

**Author:** [@tejal\_kubde](https://discuss.elastic.co/u/tejal_kubde)\
**Replies:** 7\
**Last updated:** [January 11, 2023, 6:31am UTC](https://discuss.elastic.co/t/exclude-log-messages-in-logstash/322829 "2023-01-11T06:31:50Z")

</div>

I'm picking up data from log files using filebeat and sending it to Elasticsearch via Logstash. I wanted to exclude few log lines. So can I use an if condition in Logstash. If yes, please share me the format and guide me…

---

## [Logstash configuration to delete input files once processed](https://discuss.elastic.co/t/logstash-configuration-to-delete-input-files-once-processed/322029)

<div class="topic-metadata">

**Author:** [@BhawanaSharma](https://discuss.elastic.co/u/BhawanaSharma)\
**Replies:** 11\
**Last updated:** [January 11, 2023, 6:27am UTC](https://discuss.elastic.co/t/logstash-configuration-to-delete-input-files-once-processed/322029 "2023-01-11T06:27:43Z")

</div>

I am trying to delete input files from directory once it was processed by Filebeat. Also wanted to confirm from filebeat that particular file is already processed so it is safe to delete. For that I tried few things on m…

---

## [Search is not working properly on cluster 2 node setup](https://discuss.elastic.co/t/search-is-not-working-properly-on-cluster-2-node-setup/322851)

<div class="topic-metadata">

**Author:** [@arjunmalu](https://discuss.elastic.co/u/arjunmalu)\
**Replies:** 2\
**Last updated:** [January 11, 2023, 5:39am UTC](https://discuss.elastic.co/t/search-is-not-working-properly-on-cluster-2-node-setup/322851 "2023-01-11T05:39:36Z")

</div>

Hi Elastic team, I am using Elasticsearch service on 2 node setup. Both the nodes have default configuration (elasticsearch.yml). Case : Suppose there are 50 entries in a list to search from. A new entry ("newentry51")…

---

## [Kibana 8.x Controls search don't find items](https://discuss.elastic.co/t/kibana-8-x-controls-search-dont-find-items/318667)

<div class="topic-metadata">

**Author:** [@ntkclara](https://discuss.elastic.co/u/ntkclara)\
**Replies:** 3\
**Last updated:** [November 16, 2022, 11:22am UTC](https://discuss.elastic.co/t/kibana-8-x-controls-search-dont-find-items/318667 "2022-11-16T11:22:33Z")

</div>

I was using ELK stack 7.x but i had issues with input controls. (For example case sensitivity or Data might be incomplete pop up) I saw that in ELK Stack 8.x, problems was solved. So I upgrade my stack to 8.5 But now,…

---

## [Regex on filtered data on Kibana](https://discuss.elastic.co/t/regex-on-filtered-data-on-kibana/318916)

<div class="topic-metadata">

**Author:** [@Anil\_Alapati](https://discuss.elastic.co/u/Anil_Alapati)\
**Replies:** 6\
**Last updated:** [December 14, 2022, 6:13am UTC](https://discuss.elastic.co/t/regex-on-filtered-data-on-kibana/318916 "2022-12-14T06:13:44Z")

</div>

Hi, is there any feature that can add regex and show the data on visualization? Like Name is 123@bc.com. it should show only 123

---

## [EuiCombobox is not working properly](https://discuss.elastic.co/t/euicombobox-is-not-working-properly/322544)

<div class="topic-metadata">

**Author:** [@Frlopezc](https://discuss.elastic.co/u/Frlopezc)\
**Replies:** 3\
**Last updated:** [January 10, 2023, 6:03pm UTC](https://discuss.elastic.co/t/euicombobox-is-not-working-properly/322544 "2023-01-10T18:03:33Z")

</div>

Hi everyone. Im using elastic and i'm trying to use the component Combobox but they options appear further from the element that it should be. (Shown in the following image) the combobox used is: \<EuiComboBox …

---

## [Three node cluster failes completely when one node shuts down](https://discuss.elastic.co/t/three-node-cluster-failes-completely-when-one-node-shuts-down/322638)

<div class="topic-metadata">

**Author:** [@cdy5159](https://discuss.elastic.co/u/cdy5159)\
**Replies:** 9\
**Last updated:** [January 10, 2023, 4:36pm UTC](https://discuss.elastic.co/t/three-node-cluster-failes-completely-when-one-node-shuts-down/322638 "2023-01-10T16:36:01Z")

</div>

I have a three node cluster with Elastic 8.4.2. When all three nodes are up, it all appears fine. I built the cluster with a single node (audit1), but later added the other two nodes (audit2 & audit3). If I shutdown e…

---

## [Searching special characters !, $, #, @](https://discuss.elastic.co/t/searching-special-characters/322727)

<div class="topic-metadata">

**Author:** [@oktaykalfa](https://discuss.elastic.co/u/oktaykalfa)\
**Replies:** 2\
**Last updated:** [January 10, 2023, 1:43pm UTC](https://discuss.elastic.co/t/searching-special-characters/322727 "2023-01-10T13:43:37Z")

</div>

Hello, My config is be like in the following and i want to search special characters like !, $, @, # too. class ConversationIndexConfigurator extends IndexConfigurator { use Migratable; protected $name = 'conv…

---

## [How does logstash use pipeline.batch.size to execute pipeline?](https://discuss.elastic.co/t/how-does-logstash-use-pipeline-batch-size-to-execute-pipeline/322772)

<div class="topic-metadata">

**Author:** [@rickfish](https://discuss.elastic.co/u/rickfish)\
**Replies:** 7\
**Last updated:** [January 10, 2023, 2:00pm UTC](https://discuss.elastic.co/t/how-does-logstash-use-pipeline-batch-size-to-execute-pipeline/322772 "2023-01-10T14:00:03Z")

</div>

I am looking for documentation on how Logstash processes a pipeline when pipeline.batch.size is more than 1. This is my assumption: The input plugin generates several events, not dictated by batch size While there are…

---

## [Elasticsearch autocomplete suggestion on array object](https://discuss.elastic.co/t/elasticsearch-autocomplete-suggestion-on-array-object/322375)

<div class="topic-metadata">

**Author:** [@ysunil702](https://discuss.elastic.co/u/ysunil702)\
**Replies:** 14\
**Last updated:** [January 10, 2023, 10:12am UTC](https://discuss.elastic.co/t/elasticsearch-autocomplete-suggestion-on-array-object/322375 "2023-01-10T10:12:52Z")

</div>

my mapping as follow : \`"skills": { "properties": { "id": { "type": "long" }, "skillName": { …

---

## [Exclude user access using regular expressions in kibana](https://discuss.elastic.co/t/exclude-user-access-using-regular-expressions-in-kibana/322833)

<div class="topic-metadata">

**Author:** [@Shivani\_Hadke](https://discuss.elastic.co/u/Shivani_Hadke)\
**Replies:** 4\
**Last updated:** [January 10, 2023, 12:45pm UTC](https://discuss.elastic.co/t/exclude-user-access-using-regular-expressions-in-kibana/322833 "2023-01-10T12:45:45Z")

</div>

I would like to exclude only a particular index and have access to rest of all indexes in a cluster. Right now, I'm adding every index by clicking on it and in roles and it is a hectic task to do just to exclude one ind…

---

## [Autoscaling by CPU usage](https://discuss.elastic.co/t/autoscaling-by-cpu-usage/322834)

<div class="topic-metadata">

**Author:** [@joao.mil](https://discuss.elastic.co/u/joao.mil)\
**Replies:** 0\
**Last updated:** [January 10, 2023, 12:40pm UTC](https://discuss.elastic.co/t/autoscaling-by-cpu-usage/322834 "2023-01-10T12:40:38Z")

</div>

Hi! In our use case, we use knn vector search which our tests show is very CPU intensive. We expect the load to vary significantly throughout the day and for that reason we would like to have some kind of CPU based autos…

---

## [Data duplication happening when using multiple configuration for logstash with different input ports](https://discuss.elastic.co/t/data-duplication-happening-when-using-multiple-configuration-for-logstash-with-different-input-ports/322799)

<div class="topic-metadata">

**Author:** [@asambasivan](https://discuss.elastic.co/u/asambasivan)\
**Replies:** 2\
**Last updated:** [January 10, 2023, 11:05am UTC](https://discuss.elastic.co/t/data-duplication-happening-when-using-multiple-configuration-for-logstash-with-different-input-ports/322799 "2023-01-10T11:05:32Z")

</div>

Hello, We have two logstash configurations with two different input ports 5044 and 5045 for accepting connections, but while the filebeat is sending logs to logstash via port 5045 the data is getting duplicated and we a…

---

## [Kibana Visualization of bucket aggregation data](https://discuss.elastic.co/t/kibana-visualization-of-bucket-aggregation-data/320554)

<div class="topic-metadata">

**Author:** [@jos\_nubel007](https://discuss.elastic.co/u/jos_nubel007)\
**Replies:** 3\
**Last updated:** [December 13, 2022, 9:33am UTC](https://discuss.elastic.co/t/kibana-visualization-of-bucket-aggregation-data/320554 "2022-12-13T09:33:05Z")

</div>

I created an index that collects metrics for different applications and I visualize these metrics in Kibana. However, there is a field that contains bucket aggregation datas (something like that: Variable width histogram…

---

## [Kibana Data view "fieldAttrs"](https://discuss.elastic.co/t/kibana-data-view-fieldattrs/322629)

<div class="topic-metadata">

**Author:** [@cotarbe](https://discuss.elastic.co/u/cotarbe)\
**Replies:** 2\
**Last updated:** [January 10, 2023, 9:28am UTC](https://discuss.elastic.co/t/kibana-data-view-fieldattrs/322629 "2023-01-10T09:28:03Z")

</div>

Hello, I used Kibana API to get info about a data view GET kbn:/api/data\_views/data\_view/\<data\_view\_id\> and I got an object as the following: { "data\_view": { "id": "...", "version": "...", "tit…

---

## [Keyword Stuffing](https://discuss.elastic.co/t/keyword-stuffing/322786)

<div class="topic-metadata">

**Author:** [@Kharad](https://discuss.elastic.co/u/Kharad)\
**Replies:** 1\
**Last updated:** [January 10, 2023, 8:04am UTC](https://discuss.elastic.co/t/keyword-stuffing/322786 "2023-01-10T08:04:09Z")

</div>

Need Help with Keyword Stuffing. Scenario: I have 2 Presentations, with the titles as follows: Example 1: Presentation #1: "Bake Cake Bake bake cake cake cake bake" Presentation #2: "Bake Cake" Now, when I search wi…

---

## [Can I use pattern in Logstash output plugin](https://discuss.elastic.co/t/can-i-use-pattern-in-logstash-output-plugin/322600)

<div class="topic-metadata">

**Author:** [@Rakhshunda\_Noorein\_J](https://discuss.elastic.co/u/Rakhshunda_Noorein_J)\
**Replies:** 12\
**Last updated:** [January 10, 2023, 7:30am UTC](https://discuss.elastic.co/t/can-i-use-pattern-in-logstash-output-plugin/322600 "2023-01-10T07:30:27Z")

</div>

Hello, I want to track all the failures log in a file. For Example, if "\_jsonparsefailure" in \[tags\] { file { path =\> "\_jsonparsefailure.txt" } } Can I use pattern like - if "\*failure\*" in \[tags\] so that I…

---

## [GUID is not a configured index pattern ID Showing the default index pattern:](https://discuss.elastic.co/t/guid-is-not-a-configured-index-pattern-id-showing-the-default-index-pattern/322352)

<div class="topic-metadata">

**Author:** [@hagite](https://discuss.elastic.co/u/hagite)\
**Replies:** 2\
**Last updated:** [January 10, 2023, 7:11am UTC](https://discuss.elastic.co/t/guid-is-not-a-configured-index-pattern-id-showing-the-default-index-pattern/322352 "2023-01-10T07:11:50Z")

</div>

Hello, My Kibana is working well always, yesterday, in Discovery page I got the message 99792e00-1552-11ec-929c-81cfc96dcc03" is not a configured index pattern ID Showing the default index pattern: "file\*" (5c1d0020…

---

## [Logstash regex pattern for a windows path](https://discuss.elastic.co/t/logstash-regex-pattern-for-a-windows-path/322790)

<div class="topic-metadata">

**Author:** [@ShubhamKumarJena](https://discuss.elastic.co/u/ShubhamKumarJena)\
**Replies:** 0\
**Last updated:** [January 10, 2023, 6:22am UTC](https://discuss.elastic.co/t/logstash-regex-pattern-for-a-windows-path/322790 "2023-01-10T06:22:33Z")

</div>

Hello Elastic community, I am trying to use a if condition for my logstash filter for a windows path but not sure about the delimiter and correct syntax. Here is my complete windows directory " R:\\I3\\IC\\Logs\\Sabio\_Elk\_…

---

## [I want to show that's ip which is triggered](https://discuss.elastic.co/t/i-want-to-show-thats-ip-which-is-triggered/322788)

<div class="topic-metadata">

**Author:** [@Tayyab\_Ilyas](https://discuss.elastic.co/u/Tayyab_Ilyas)\
**Replies:** 0\
**Last updated:** [January 10, 2023, 6:14am UTC](https://discuss.elastic.co/t/i-want-to-show-thats-ip-which-is-triggered/322788 "2023-01-10T06:14:52Z")

</div>

I want the detected anomaly's IP to show in the alert, I am attaching the picture for reference.

---

## [Log Deletion on Elasticsearch nodes based on lastModified](https://discuss.elastic.co/t/log-deletion-on-elasticsearch-nodes-based-on-lastmodified/322785)

<div class="topic-metadata">

**Author:** [@mahesh\_tangella](https://discuss.elastic.co/u/mahesh_tangella)\
**Replies:** 0\
**Last updated:** [January 10, 2023, 5:30am UTC](https://discuss.elastic.co/t/log-deletion-on-elasticsearch-nodes-based-on-lastmodified/322785 "2023-01-10T05:30:46Z")

</div>

Hello Team, We are facing an issue with log deletion policy defined in log4j2.properties based on ifLastModified age. We want to delete all the log files which are larger than 2GB in size and older than 15 days. So, we…

---

## [Mismatch between dotted lines and the default dark lines in Time Series of TSVB visualization](https://discuss.elastic.co/t/mismatch-between-dotted-lines-and-the-default-dark-lines-in-time-series-of-tsvb-visualization/319540)

<div class="topic-metadata">

**Author:** [@Abj\_Ins](https://discuss.elastic.co/u/Abj_Ins)\
**Replies:** 12\
**Last updated:** [December 13, 2022, 5:20am UTC](https://discuss.elastic.co/t/mismatch-between-dotted-lines-and-the-default-dark-lines-in-time-series-of-tsvb-visualization/319540 "2022-12-13T05:20:34Z")

</div>

Hi Team, In the Timeseries visualization, we can see dotted lines in the middle of the visualization which is matching exactly on top of the default dark lines. However, when we hover the mouse either on the left or …

---

## [Kibana Server is not ready yet](https://discuss.elastic.co/t/kibana-server-is-not-ready-yet/322780)

<div class="topic-metadata">

**Author:** [@Rishvana](https://discuss.elastic.co/u/Rishvana)\
**Replies:** 8\
**Last updated:** [January 10, 2023, 4:04am UTC](https://discuss.elastic.co/t/kibana-server-is-not-ready-yet/322780 "2023-01-10T04:04:10Z")

</div>

Hi Team, We are not able to login to kibana application as it throws an error "Kibana server is not ready yet. we recently renewed ssl certificate for kibana and we done sanity check at that time it works fine. can let…

---

## [Force kibana into connecting to preferred ES node](https://discuss.elastic.co/t/force-kibana-into-connecting-to-preferred-es-node/322779)

<div class="topic-metadata">

**Author:** [@blueren](https://discuss.elastic.co/u/blueren)\
**Replies:** 2\
**Last updated:** [January 10, 2023, 2:55am UTC](https://discuss.elastic.co/t/force-kibana-into-connecting-to-preferred-es-node/322779 "2023-01-10T02:55:10Z")

</div>

Hi, I've installed two instances of ES (co-ordinator only) running on a couple of machines, with a kibana instance. For kibana, I've set both of them as elasticsearch.hosts=\[es1, es2\] However, I'd always like it to talk…

---

## [How do I get find which parts of an Elasticsearch query match](https://discuss.elastic.co/t/how-do-i-get-find-which-parts-of-an-elasticsearch-query-match/322761)

<div class="topic-metadata">

**Author:** [@amirs5](https://discuss.elastic.co/u/amirs5)\
**Replies:** 7\
**Last updated:** [January 10, 2023, 2:37am UTC](https://discuss.elastic.co/t/how-do-i-get-find-which-parts-of-an-elasticsearch-query-match/322761 "2023-01-10T02:37:33Z")

</div>

I have a list of Key-word-sets, for example: set\_1: \["movie", "cinema", "theater"\], set\_2: \["beach", "ocean", "dock"\], set\_3: \["office", "downtown", "center"\] and I want to build up a single query that tells us which o…

[Previous page](https://discuss.elastic.co/tag/none.md?no_tags=true&page=459)

[Next page](https://discuss.elastic.co/tag/none.md?no_tags=true&page=461)
