# \#none

**URL:** https://discuss.elastic.co/tag/none.md?no_tags=true&page=527

[Latest](https://discuss.elastic.co/latest.md) · [Categories](https://discuss.elastic.co/categories.md) · [Tags](https://discuss.elastic.co/tags.md)

**Page:** 528

---

## [Malformed action/metadata line \[1\], expected START\_OBJECT but found \[START\_ARRAY\]](https://discuss.elastic.co/t/malformed-action-metadata-line-1-expected-start-object-but-found-start-array/315528)

<div class="topic-metadata">

**Author:** [@Hemabh\_Ravee\_Fox](https://discuss.elastic.co/u/Hemabh_Ravee_Fox)\
**Replies:** 5\
**Last updated:** [September 30, 2022, 10:56am UTC](https://discuss.elastic.co/t/malformed-action-metadata-line-1-expected-start-object-but-found-start-array/315528 "2022-09-30T10:56:03Z")

</div>

I've been trying to use the bulk api to insert a large number of documents to an index. I followed the documentation and came up with the following API call - POST https://localhost:9200/index/\_bulk \[ {"create":{}}…

---

## [Requirement to build logstah core module to generate a custom logstah for a specific purpose](https://discuss.elastic.co/t/requirement-to-build-logstah-core-module-to-generate-a-custom-logstah-for-a-specific-purpose/315200)

<div class="topic-metadata">

**Author:** [@rravitech](https://discuss.elastic.co/u/rravitech)\
**Replies:** 3\
**Last updated:** [September 30, 2022, 9:01am UTC](https://discuss.elastic.co/t/requirement-to-build-logstah-core-module-to-generate-a-custom-logstah-for-a-specific-purpose/315200 "2022-09-30T09:01:01Z")

</div>

I have a requirement to edit the logstash core, and generate a kind of build out of it. Need to customize logstash code to resist over the below mechanism. Logstash has an at-least-once delivery model. Every event is s…

---

## [Collapse dense\_vector field in search results](https://discuss.elastic.co/t/collapse-dense-vector-field-in-search-results/315517)

<div class="topic-metadata">

**Author:** [@ruslaniv](https://discuss.elastic.co/u/ruslaniv)\
**Replies:** 1\
**Last updated:** [September 30, 2022, 8:00am UTC](https://discuss.elastic.co/t/collapse-dense-vector-field-in-search-results/315517 "2022-09-30T08:00:57Z")

</div>

Hi! Is it possible to collapse or hide a dense\_vector field in the results returned by ES? When developing, I have to send a lot of queries to ES and then inspect the results and it is getting really tiresome to scroll…

---

## [Help! How to aggs data by two or more fields, and get the max value of 'count' field?](https://discuss.elastic.co/t/help-how-to-aggs-data-by-two-or-more-fields-and-get-the-max-value-of-count-field/315345)

<div class="topic-metadata">

**Author:** [@Dosia96](https://discuss.elastic.co/u/Dosia96)\
**Replies:** 2\
**Last updated:** [September 30, 2022, 6:52am UTC](https://discuss.elastic.co/t/help-how-to-aggs-data-by-two-or-more-fields-and-get-the-max-value-of-count-field/315345 "2022-09-30T06:52:59Z")

</div>

How to aggs data by two or more fields, and get the max value of 'count' field? I have already config the kibana Y-Axis: Metrics sum('count'), X-Axis: Data Histogram @timestamp , interval : sec terms field(a) order b…

---

## [How to Remove old value and replace it with new value in Kibana](https://discuss.elastic.co/t/how-to-remove-old-value-and-replace-it-with-new-value-in-kibana/315522)

<div class="topic-metadata">

**Author:** [@SayliKibana](https://discuss.elastic.co/u/SayliKibana)\
**Replies:** 0\
**Last updated:** [September 30, 2022, 6:29am UTC](https://discuss.elastic.co/t/how-to-remove-old-value-and-replace-it-with-new-value-in-kibana/315522 "2022-09-30T06:29:51Z")

</div>

We have an Automation process wherein we process Transaction Input as "ECO Number" and as it get processed ,the output of the ECO Number with Status is displayed on the Kibana Dashboard. According to our process we upda…

---

## [When nod workers have disaster, they don't deploy the terminated pods](https://discuss.elastic.co/t/when-nod-workers-have-disaster-they-dont-deploy-the-terminated-pods/314703)

<div class="topic-metadata">

**Author:** [@farhad\_kh](https://discuss.elastic.co/u/farhad_kh)\
**Replies:** 2\
**Last updated:** [September 28, 2022, 6:08am UTC](https://discuss.elastic.co/t/when-nod-workers-have-disaster-they-dont-deploy-the-terminated-pods/314703 "2022-09-28T06:08:03Z")

</div>

I have a cluster with 6 workers I created 3 data nodes and 3 master nodes on them When cluster nodes fail The operator does not create termination pods in other nodes It also has trouble rebuilding Kibana pods Also,…

---

## [Find average aggregation of the top N buckets](https://discuss.elastic.co/t/find-average-aggregation-of-the-top-n-buckets/315515)

<div class="topic-metadata">

**Author:** [@bhavya](https://discuss.elastic.co/u/bhavya)\
**Replies:** 0\
**Last updated:** [September 30, 2022, 5:43am UTC](https://discuss.elastic.co/t/find-average-aggregation-of-the-top-n-buckets/315515 "2022-09-30T05:43:39Z")

</div>

I'm trying to determine the average value of the "count" column for the top 5 documents ordered by "timestamp" (in descending order). Sample Index data: {"index":{}} {"title": "foo", "count": 1, "timestamp":"2022-09-15…

---

## [I tried to upload a log file and a CSV file through the Kibana UI upload file option. But in both cases getting "File structure cannot be determined" error](https://discuss.elastic.co/t/i-tried-to-upload-a-log-file-and-a-csv-file-through-the-kibana-ui-upload-file-option-but-in-both-cases-getting-file-structure-cannot-be-determined-error/314878)

<div class="topic-metadata">

**Author:** [@cadrija](https://discuss.elastic.co/u/cadrija)\
**Replies:** 11\
**Last updated:** [September 30, 2022, 5:23am UTC](https://discuss.elastic.co/t/i-tried-to-upload-a-log-file-and-a-csv-file-through-the-kibana-ui-upload-file-option-but-in-both-cases-getting-file-structure-cannot-be-determined-error/314878 "2022-09-30T05:23:52Z")

</div>

I am new to Elastic. I have setup ELK in Ubuntu machine. I tried to upload a log file and a CSV file through the Kibana UI upload file option. But in both cases getting "File structure cannot be determined" error. I h…

---

## [Elasticsearch \[6.8\] small index query response time in seconds](https://discuss.elastic.co/t/elasticsearch-6-8-small-index-query-response-time-in-seconds/315512)

<div class="topic-metadata">

**Author:** [@srivatsa](https://discuss.elastic.co/u/srivatsa)\
**Replies:** 0\
**Last updated:** [September 30, 2022, 4:34am UTC](https://discuss.elastic.co/t/elasticsearch-6-8-small-index-query-response-time-in-seconds/315512 "2022-09-30T04:34:27Z")

</div>

Hi folks, Facing an issue involving a small index of the size 378kb taking around 10s for a read query. We had tried increasing the number of replicas assuming it would help with reads but did not see any noticeable dif…

---

## [Ingest Pipeline threads](https://discuss.elastic.co/t/ingest-pipeline-threads/315182)

<div class="topic-metadata">

**Author:** [@alah64](https://discuss.elastic.co/u/alah64)\
**Replies:** 1\
**Last updated:** [September 30, 2022, 3:57am UTC](https://discuss.elastic.co/t/ingest-pipeline-threads/315182 "2022-09-30T03:57:38Z")

</div>

In logstash, the pipeline.workers setting determines how many threads to run to process the filter and output. Do we have similar settings for elasticsearch ingest pipeline? It seems to work single-threaded and the more…

---

## [Is this ES config valid & how to address cluster](https://discuss.elastic.co/t/is-this-es-config-valid-how-to-address-cluster/315262)

<div class="topic-metadata">

**Author:** [@Bitdoctor](https://discuss.elastic.co/u/Bitdoctor)\
**Replies:** 1\
**Last updated:** [September 30, 2022, 3:52am UTC](https://discuss.elastic.co/t/is-this-es-config-valid-how-to-address-cluster/315262 "2022-09-30T03:52:21Z")

</div>

Even though there are amazing communities like this, it's still difficult to find good answers on some things. We have 1 x Kibana, 1 x LogStash, 3 x ES Cluster nodes. Is this a valid architecture; or do we have to have 1…

---

## [Banzai Cloud Fluentd filter is not working](https://discuss.elastic.co/t/banzai-cloud-fluentd-filter-is-not-working/315444)

<div class="topic-metadata">

**Author:** [@buulq90](https://discuss.elastic.co/u/buulq90)\
**Replies:** 1\
**Last updated:** [September 30, 2022, 3:41am UTC](https://discuss.elastic.co/t/banzai-cloud-fluentd-filter-is-not-working/315444 "2022-09-30T03:41:07Z")

</div>

Hi all, I'm trying to remove some field on Fluentd by using plugin record\_transformer but it does not works. I'm trying to delete 2 fields: "\_id" & "\_index". Below is my configuration file: apiVersion: logging.banzaic…

---

## [How to force mapper\_parsing\_exception? from ElasticSearch to prevent accepting different types for a specific field](https://discuss.elastic.co/t/how-to-force-mapper-parsing-exception-from-elasticsearch-to-prevent-accepting-different-types-for-a-specific-field/315485)

<div class="topic-metadata">

**Author:** [@Saeedeh\_Moghimi](https://discuss.elastic.co/u/Saeedeh_Moghimi)\
**Replies:** 1\
**Last updated:** [September 30, 2022, 3:38am UTC](https://discuss.elastic.co/t/how-to-force-mapper-parsing-exception-from-elasticsearch-to-prevent-accepting-different-types-for-a-specific-field/315485 "2022-09-30T03:38:52Z")

</div>

I have a production index with a date type field, which causes the error of Field \[tagSet.items.value\] of type \[text\] does not support custom formats in Kibana. I've created another index for test and whenever I want t…

---

## [JSON Plugin - Ignore Field](https://discuss.elastic.co/t/json-plugin-ignore-field/315510)

<div class="topic-metadata">

**Author:** [@QuestBevan](https://discuss.elastic.co/u/QuestBevan)\
**Replies:** 1\
**Last updated:** [September 30, 2022, 3:37am UTC](https://discuss.elastic.co/t/json-plugin-ignore-field/315510 "2022-09-30T03:37:20Z")

</div>

Hi All, Need some advise. I am currently using filebeat, to send logs to Elasticsearch via Logstash. Filebeat -\> Logstash -\> Elasticsearch Log files are in JSON, and these JSON documents are being expanded as expecte…

---

## [Seperate fleet management cluster - integrations, management,](https://discuss.elastic.co/t/seperate-fleet-management-cluster-integrations-management/315507)

<div class="topic-metadata">

**Author:** [@vbohata](https://discuss.elastic.co/u/vbohata)\
**Replies:** 0\
**Last updated:** [September 30, 2022, 12:41am UTC](https://discuss.elastic.co/t/seperate-fleet-management-cluster-integrations-management/315507 "2022-09-30T00:41:10Z")

</div>

I checked the documentation and using the logstash outputs it is not possible to use separate fleet managed agents with logstash output to different clusters. But what about the integrations? Lets imagine for big deplo…

---

## [Min\_score doesnt apply to aggregates](https://discuss.elastic.co/t/min-score-doesnt-apply-to-aggregates/315503)

<div class="topic-metadata">

**Author:** [@reisner](https://discuss.elastic.co/u/reisner)\
**Replies:** 0\
**Last updated:** [September 29, 2022, 9:37pm UTC](https://discuss.elastic.co/t/min-score-doesnt-apply-to-aggregates/315503 "2022-09-29T21:37:06Z")

</div>

Hi there, I'm seeing some weird behaviour trying to fix an issue with a query. I was originally running this query: GET /coe\_td\_council\_report\_files\_test/\_search { "size": 0, "min\_score": 2.9, "query": { "b…

---

## [Kibana is not coming up](https://discuss.elastic.co/t/kibana-is-not-coming-up/315263)

<div class="topic-metadata">

**Author:** [@DineshGarimella](https://discuss.elastic.co/u/DineshGarimella)\
**Replies:** 9\
**Last updated:** [September 29, 2022, 8:28pm UTC](https://discuss.elastic.co/t/kibana-is-not-coming-up/315263 "2022-09-29T20:28:57Z")

</div>

{"type":"log","@timestamp":"2022-09-27T11:07:06Z","tags":\["status","plugin:kibana@6.4.0","info"\],"pid":153778,"state":"green","message":"Status changed from uninitialized to green - Ready","prevState":"uninitialized","pr…

---

## [Create rules error](https://discuss.elastic.co/t/create-rules-error/314993)

<div class="topic-metadata">

**Author:** [@zhixiang\_hao](https://discuss.elastic.co/u/zhixiang_hao)\
**Replies:** 1\
**Last updated:** [September 29, 2022, 8:24pm UTC](https://discuss.elastic.co/t/create-rules-error/314993 "2022-09-29T20:24:44Z")

</div>

There is no problem in the test on the platform, and the alarm can be reported normally, but an error is reported when I create a rule

---

## [My Elasticsearch wont start after java update](https://discuss.elastic.co/t/my-elasticsearch-wont-start-after-java-update/315454)

<div class="topic-metadata">

**Author:** [@Joe\_Li](https://discuss.elastic.co/u/Joe_Li)\
**Replies:** 4\
**Last updated:** [September 29, 2022, 6:13pm UTC](https://discuss.elastic.co/t/my-elasticsearch-wont-start-after-java-update/315454 "2022-09-29T18:13:28Z")

</div>

getting the below error and not sure where to start... can anyone assist? \[root@bh3elklpv01 jli\]# sudo systemctl status elasticsearch.service ● elasticsearch.service - Elasticsearch Loaded: loaded (/usr/lib/systemd/sy…

---

## [\[logstash.filters.xml Error parsing xml with XmlSimple {:source=\>"message" , :exception=\>#\<REXML::ParseException: No close tag for /log4j:event/log4j:message and truncated](https://discuss.elastic.co/t/logstash-filters-xml-error-parsing-xml-with-xmlsimple-source-message-exception-rexml-no-close-tag-for-log4j-event-log4j-message-and-truncated/315472)

<div class="topic-metadata">

**Author:** [@erwin339](https://discuss.elastic.co/u/erwin339)\
**Replies:** 0\
**Last updated:** [September 29, 2022, 2:48pm UTC](https://discuss.elastic.co/t/logstash-filters-xml-error-parsing-xml-with-xmlsimple-source-message-exception-rexml-no-close-tag-for-log4j-event-log4j-message-and-truncated/315472 "2022-09-29T14:48:19Z")

</div>

This log is giving me problems: Note: my log is much longer but you exceed the character limit that allows me to upload here. Just delete things from the log that are repeated as messages. The message exceeds 1000 lines…

---

## [Hide Exit Full Screen button](https://discuss.elastic.co/t/hide-exit-full-screen-button/315435)

<div class="topic-metadata">

**Author:** [@S-elk](https://discuss.elastic.co/u/S-elk)\
**Replies:** 1\
**Last updated:** [September 29, 2022, 3:16pm UTC](https://discuss.elastic.co/t/hide-exit-full-screen-button/315435 "2022-09-29T15:16:48Z")

</div>

Hello! I want to put a dashboard on a room screen in fullscreen. i got this with: &\_a=(fullScreenMode:!t) But the exit button remains, I would like to know if this can be hidden somehow. Thanks in advance!

---

## [Integration with nginx stubstatus doesn't work](https://discuss.elastic.co/t/integration-with-nginx-stubstatus-doesnt-work/315402)

<div class="topic-metadata">

**Author:** [@odelacruzc](https://discuss.elastic.co/u/odelacruzc)\
**Replies:** 5\
**Last updated:** [September 29, 2022, 5:43pm UTC](https://discuss.elastic.co/t/integration-with-nginx-stubstatus-doesnt-work/315402 "2022-09-29T17:43:31Z")

</div>

I work with nginx integration and elastic agent so, I configured host by default http://127.0.0.1:80, but my instance nginx is https, so kibana observability logs give me the follow error: "Error fetching data for metri…

---

## [Engine Name is already Taken (second occurrence)](https://discuss.elastic.co/t/engine-name-is-already-taken-second-occurrence/313412)

<div class="topic-metadata">

**Author:** [@Rav\_Panchalingam](https://discuss.elastic.co/u/Rav_Panchalingam)\
**Replies:** 4\
**Last updated:** [September 29, 2022, 5:03pm UTC](https://discuss.elastic.co/t/engine-name-is-already-taken-second-occurrence/313412 "2022-09-29T17:03:31Z")

</div>

I previously posted about this in June Engine Name is already Taken - Elastic Enterprise Search - Discuss the Elastic Stack where @Artem\_Shelkovnikov was helpful in resolving the issue Everything has been working great…

---

## [Filtered Log messages show up as empty fields in Kibana](https://discuss.elastic.co/t/filtered-log-messages-show-up-as-empty-fields-in-kibana/315400)

<div class="topic-metadata">

**Author:** [@Chma](https://discuss.elastic.co/u/Chma)\
**Replies:** 7\
**Last updated:** [September 29, 2022, 5:01pm UTC](https://discuss.elastic.co/t/filtered-log-messages-show-up-as-empty-fields-in-kibana/315400 "2022-09-29T17:01:49Z")

</div>

I have filtered my log message using grok. But when I check Kibana, I find the new fields on the left side of the page, but they are empty. I am also getting the \_grokparsefailure tag. Here's an example of my log messag…

---

## [Cannot add more than 10 columns in kibana table](https://discuss.elastic.co/t/cannot-add-more-than-10-columns-in-kibana-table/315442)

<div class="topic-metadata">

**Author:** [@Pierre\_Abi\_Chedid](https://discuss.elastic.co/u/Pierre_Abi_Chedid)\
**Replies:** 1\
**Last updated:** [September 29, 2022, 3:04pm UTC](https://discuss.elastic.co/t/cannot-add-more-than-10-columns-in-kibana-table/315442 "2022-09-29T15:04:27Z")

</div>

Hello, I seem to have a problem when trying to add more than 10 columns in my kibana visualization I get the following error: Any idea on how to resolve the problem?

---

## [Document count by index name](https://discuss.elastic.co/t/document-count-by-index-name/315477)

<div class="topic-metadata">

**Author:** [@S-elk](https://discuss.elastic.co/u/S-elk)\
**Replies:** 1\
**Last updated:** [September 29, 2022, 4:57pm UTC](https://discuss.elastic.co/t/document-count-by-index-name/315477 "2022-09-29T16:57:49Z")

</div>

Hello! Im trying to get the document count by index but I have only been able to get a total count or the count per index of a few. attempts: GET \*/\_search { "size": 0, "aggs": { "indices": { "terms": { …

---

## [Logstash logs](https://discuss.elastic.co/t/logstash-logs/314911)

<div class="topic-metadata">

**Author:** [@irivas95](https://discuss.elastic.co/u/irivas95)\
**Replies:** 2\
**Last updated:** [September 29, 2022, 4:39pm UTC](https://discuss.elastic.co/t/logstash-logs/314911 "2022-09-29T16:39:23Z")

</div>

Hi, I have installed logstash 7.16.3 with default settings in logstash.yml and log4j2.properties. My understanding is that with this configuration each log type, for example, logstash-plain.log should not be able to ex…

---

## [How to view docs.deleted data](https://discuss.elastic.co/t/how-to-view-docs-deleted-data/315459)

<div class="topic-metadata">

**Author:** [@KrishnaCh](https://discuss.elastic.co/u/KrishnaCh)\
**Replies:** 2\
**Last updated:** [September 29, 2022, 2:29pm UTC](https://discuss.elastic.co/t/how-to-view-docs-deleted-data/315459 "2022-09-29T14:29:41Z")

</div>

Hi All, In my elastic cluster, I see there are some records in docs.deleted for some of the indices, and I am not sure how to find out who deleted the docs? My 3 node elastic cluster version is 7.16.1 and it is Not an …

---

## [How to set Max\_analyzed\_offset setting for all searches in Discover](https://discuss.elastic.co/t/how-to-set-max-analyzed-offset-setting-for-all-searches-in-discover/315466)

<div class="topic-metadata">

**Author:** [@Quentin\_vk](https://discuss.elastic.co/u/Quentin_vk)\
**Replies:** 0\
**Last updated:** [September 29, 2022, 2:14pm UTC](https://discuss.elastic.co/t/how-to-set-max-analyzed-offset-setting-for-all-searches-in-discover/315466 "2022-09-29T14:14:51Z")

</div>

Hi, we're having this very well known error "the length of field\[...\] index has exceed maximum allowed to be analyzed for highlighting". We're trying to use the max\_analyzed\_offset setting as a global search setting in …

---

## [I have a problem elasticsearch](https://discuss.elastic.co/t/i-have-a-problem-elasticsearch/315366)

<div class="topic-metadata">

**Author:** [@Marcelo\_F\_Costa](https://discuss.elastic.co/u/Marcelo_F_Costa)\
**Replies:** 2\
**Last updated:** [September 29, 2022, 2:03pm UTC](https://discuss.elastic.co/t/i-have-a-problem-elasticsearch/315366 "2022-09-29T14:03:04Z")

</div>

I have this problem and I have no idea what it is. Can someone help me? Follow the log. \[2022-09-28T02:21:14,224\]\[WARN \]\[o.e.m.j.JvmGcMonitorService\] \[VM-Elasticsearch\] \[gc\]\[young\]\[365947\]\[70063\] duration \[1.5s\], coll…

[Previous page](https://discuss.elastic.co/tag/none.md?no_tags=true&page=526)

[Next page](https://discuss.elastic.co/tag/none.md?no_tags=true&page=528)
