# \#none

**URL:** https://discuss.elastic.co/tag/none.md?no_tags=true&page=530

[Latest](https://discuss.elastic.co/latest.md) · [Categories](https://discuss.elastic.co/categories.md) · [Tags](https://discuss.elastic.co/tags.md)

**Page:** 531

---

## [Logstash circuit breaking](https://discuss.elastic.co/t/logstash-circuit-breaking/315049)

<div class="topic-metadata">

**Author:** [@Harper\_S1](https://discuss.elastic.co/u/Harper_S1)\
**Replies:** 2\
**Last updated:** [September 27, 2022, 3:24am UTC](https://discuss.elastic.co/t/logstash-circuit-breaking/315049 "2022-09-27T03:24:11Z")

</div>

Hi, Do anyone know how to solve this circuit breaking exception in logstash (7.10). \[2022-09-23T14:38:22,920\]\[INFO \]\[logstash.outputs.elasticsearch\]\[main\]\[299ec4f1e5994d0fe7b59d4e4d29f50e734f0d6401d909dc198ecbc402ca398…

---

## [Deleted Elasticsearch http\_ca.crt](https://discuss.elastic.co/t/deleted-elasticsearch-http-ca-crt/315225)

<div class="topic-metadata">

**Author:** [@ElasticLiver](https://discuss.elastic.co/u/ElasticLiver)\
**Replies:** 1\
**Last updated:** [September 27, 2022, 3:17am UTC](https://discuss.elastic.co/t/deleted-elasticsearch-http-ca-crt/315225 "2022-09-27T03:17:37Z")

</div>

A client, who has logstash and a elastic node in the same machine, was having problem indexing data with logstash, the cacert configuration in the logstash output was pointing to the elasticsearch directory where he h…

---

## [Duplicate data from filebeat (input type: log)](https://discuss.elastic.co/t/duplicate-data-from-filebeat-input-type-log/315221)

<div class="topic-metadata">

**Author:** [@sathishpal](https://discuss.elastic.co/u/sathishpal)\
**Replies:** 0\
**Last updated:** [September 26, 2022, 11:27pm UTC](https://discuss.elastic.co/t/duplicate-data-from-filebeat-input-type-log/315221 "2022-09-26T23:27:23Z")

</div>

Hi All, Duplicate data is sent from Filebeat. When I start the elastic agent, I can see two filebeat processes running. If I Kill the first one it auto restarts and the second one disappears when I kill it twice. Once …

---

## [Full space /var/lib/elasticsearch](https://discuss.elastic.co/t/full-space-var-lib-elasticsearch/315197)

<div class="topic-metadata">

**Author:** [@Diego\_Santos](https://discuss.elastic.co/u/Diego_Santos)\
**Replies:** 3\
**Last updated:** [September 26, 2022, 10:13pm UTC](https://discuss.elastic.co/t/full-space-var-lib-elasticsearch/315197 "2022-09-26T22:13:08Z")

</div>

Hi everyone, I have my /var/lib/elasticsearch filesystem reached 100%. Could you please tell me what I can do? health status index uuid pri rep docs.count docs.del…

---

## [Create a POST body for a search](https://discuss.elastic.co/t/create-a-post-body-for-a-search/315201)

<div class="topic-metadata">

**Author:** [@Sergio\_vrijk](https://discuss.elastic.co/u/Sergio_vrijk)\
**Replies:** 0\
**Last updated:** [September 26, 2022, 6:38pm UTC](https://discuss.elastic.co/t/create-a-post-body-for-a-search/315201 "2022-09-26T18:38:20Z")

</div>

I would like some help on a query that I am trying. I have three fields in my JSON. The field1.key, field2.key and field3 which has a nest of data1,data2,data3. What I am trying to do is. Get per unique combination of th…

---

## [Primary Shard Allocation\_Failed](https://discuss.elastic.co/t/primary-shard-allocation-failed/315033)

<div class="topic-metadata">

**Author:** [@ivandbarria](https://discuss.elastic.co/u/ivandbarria)\
**Replies:** 4\
**Last updated:** [September 26, 2022, 9:32pm UTC](https://discuss.elastic.co/t/primary-shard-allocation-failed/315033 "2022-09-26T21:32:23Z")

</div>

Hello, Hope everyone is doing great. We had a power outage and our ES server went down. When the server went back online I noticed ES status on red: "cluster\_name" : "elasticsearch", "status" : "red", "timed\_out" : …

---

## [Enterprise Search failed to start](https://discuss.elastic.co/t/enterprise-search-failed-to-start/314905)

<div class="topic-metadata">

**Author:** [@PublicName](https://discuss.elastic.co/u/PublicName)\
**Replies:** 9\
**Last updated:** [September 26, 2022, 7:35pm UTC](https://discuss.elastic.co/t/enterprise-search-failed-to-start/314905 "2022-09-26T19:35:35Z")

</div>

Fresh install of Enterprise search after not touching if for several months. Different machine different cluster. Java 11. Very basic setup. Kibana and Elasticsearch info only. No other settings changed even set as HTT…

---

## [Logstash + datastreams](https://discuss.elastic.co/t/logstash-datastreams/315210)

<div class="topic-metadata">

**Author:** [@Zdeno\_Liska](https://discuss.elastic.co/u/Zdeno_Liska)\
**Replies:** 0\
**Last updated:** [September 26, 2022, 7:33pm UTC](https://discuss.elastic.co/t/logstash-datastreams/315210 "2022-09-26T19:33:46Z")

</div>

Hi, I have issue with configuration of Logstash and Datastreams with already defined ILM,index template here are details: Logstash pipeline config: elasticsearch { hosts =\> \["host1"\] data\_stream =\> "true" …

---

## [Error multiples inputs - block in multifilter, block in start\_workers, ParseException: No close tag for /log4j:event/log4j:throwable](https://discuss.elastic.co/t/error-multiples-inputs-block-in-multifilter-block-in-start-workers-parseexception-no-close-tag-for-log4j-event-log4j-throwable/315106)

<div class="topic-metadata">

**Author:** [@erwin339](https://discuss.elastic.co/u/erwin339)\
**Replies:** 4\
**Last updated:** [September 26, 2022, 6:54pm UTC](https://discuss.elastic.co/t/error-multiples-inputs-block-in-multifilter-block-in-start-workers-parseexception-no-close-tag-for-log4j-event-log4j-throwable/315106 "2022-09-26T18:54:15Z")

</div>

Context: I have 4 folders, one contains logstash, the other 3 each contain filebeat, the first acts as if an application launched log, the second with 2 applications that send logs for which filebeat has 2 entries, and t…

---

## [Why is the error log being sent divided?](https://discuss.elastic.co/t/why-is-the-error-log-being-sent-divided/315192)

<div class="topic-metadata">

**Author:** [@erwin339](https://discuss.elastic.co/u/erwin339)\
**Replies:** 1\
**Last updated:** [September 26, 2022, 6:08pm UTC](https://discuss.elastic.co/t/why-is-the-error-log-being-sent-divided/315192 "2022-09-26T18:08:56Z")

</div>

I am sending error and fatal logs, these have multiple lines, so the multiline is configured like this: filebeat multiline: This is throwing me an error: my error and fatal log have this structure: \<log4j:even…

---

## [Cannot Find Answers to Prefix Queries and Max Expansion](https://discuss.elastic.co/t/cannot-find-answers-to-prefix-queries-and-max-expansion/315196)

<div class="topic-metadata">

**Author:** [@st11x](https://discuss.elastic.co/u/st11x)\
**Replies:** 0\
**Last updated:** [September 26, 2022, 5:49pm UTC](https://discuss.elastic.co/t/cannot-find-answers-to-prefix-queries-and-max-expansion/315196 "2022-09-26T17:49:10Z")

</div>

I have seen many posts asking the same question with elaborate examples and most never got answered and got closed by the bot. With a phrase query like "quick brown f" as in the example on Match phrase prefix query | El…

---

## [Error restoring state from URL Unable to completely restore the URL, be sure to use the share functionality](https://discuss.elastic.co/t/error-restoring-state-from-url-unable-to-completely-restore-the-url-be-sure-to-use-the-share-functionality/314925)

<div class="topic-metadata">

**Author:** [@Irwan\_Kurniawan](https://discuss.elastic.co/u/Irwan_Kurniawan)\
**Replies:** 1\
**Last updated:** [September 26, 2022, 5:46pm UTC](https://discuss.elastic.co/t/error-restoring-state-from-url-unable-to-completely-restore-the-url-be-sure-to-use-the-share-functionality/314925 "2022-09-26T17:46:13Z")

</div>

When I open Kibana, it show error like this. I search on discussion and nobody answer. How to fix it?

---

## [Kibana Canvas error: Invalid string. Length must be a multiple of 4](https://discuss.elastic.co/t/kibana-canvas-error-invalid-string-length-must-be-a-multiple-of-4/314286)

<div class="topic-metadata">

**Author:** [@bhavya](https://discuss.elastic.co/u/bhavya)\
**Replies:** 1\
**Last updated:** [September 26, 2022, 5:42pm UTC](https://discuss.elastic.co/t/kibana-canvas-error-invalid-string-length-must-be-a-multiple-of-4/314286 "2022-09-26T17:42:40Z")

</div>

I am using version 7.16.2 of Kibana. I am adding a dropdown filter in Canvas. Let's say the index pattern is \*-\*\_stage. This index pattern includes 100 data streams. When trying to add this index pattern in the Canva…

---

## [Remove\_fields doesn't remove field in json](https://discuss.elastic.co/t/remove-fields-doesnt-remove-field-in-json/315176)

<div class="topic-metadata">

**Author:** [@Kostyantyn\_Dobriohlo](https://discuss.elastic.co/u/Kostyantyn_Dobriohlo)\
**Replies:** 2\
**Last updated:** [September 26, 2022, 4:53pm UTC](https://discuss.elastic.co/t/remove-fields-doesnt-remove-field-in-json/315176 "2022-09-26T16:53:23Z")

</div>

Cannot remove fields in json, 'cause always have a json parsing error. Tried many different ways, but inside the json nothing changes. And there is a warning in logs: Error parsing json Config file: input { tcp { …

---

## [OutOfDirectMemoryError: failed in Logstash logs](https://discuss.elastic.co/t/outofdirectmemoryerror-failed-in-logstash-logs/315145)

<div class="topic-metadata">

**Author:** [@madurad](https://discuss.elastic.co/u/madurad)\
**Replies:** 2\
**Last updated:** [September 26, 2022, 4:45pm UTC](https://discuss.elastic.co/t/outofdirectmemoryerror-failed-in-logstash-logs/315145 "2022-09-26T16:45:13Z")

</div>

Hi, Continuously getting OutOfDirectMemoryError: failed error on Logstash, I chekced the host memory usage and CPU all good and memory is around 60% used, but no clear idea how this issue is being happened. In jvm.opt…

---

## [I can't access my elasticsearch , since it's already running in my terminal](https://discuss.elastic.co/t/i-cant-access-my-elasticsearch-since-its-already-running-in-my-terminal/315183)

<div class="topic-metadata">

**Author:** [@Vitoria\_De\_Lara](https://discuss.elastic.co/u/Vitoria_De_Lara)\
**Replies:** 0\
**Last updated:** [September 26, 2022, 3:04pm UTC](https://discuss.elastic.co/t/i-cant-access-my-elasticsearch-since-its-already-running-in-my-terminal/315183 "2022-09-26T15:04:50Z")

</div>

Good morning guys, I'm trying to access my elasticsearch but so far without success. I installed it on my centos8 virtual machine and it is already running. I gave a netstat -na to see and it says that I have to enable …

---

## [Elastic Observability Engineer Lab 5.4 - geoip database unavailable](https://discuss.elastic.co/t/elastic-observability-engineer-lab-5-4-geoip-database-unavailable/315188)

<div class="topic-metadata">

**Author:** [@AnitaL](https://discuss.elastic.co/u/AnitaL)\
**Replies:** 1\
**Last updated:** [September 26, 2022, 3:51pm UTC](https://discuss.elastic.co/t/elastic-observability-engineer-lab-5-4-geoip-database-unavailable/315188 "2022-09-26T15:51:49Z")

</div>

Hi, When I use the GeoIP processor as per step 11 and test the pipeline as per step 12 I see the following instead of the new geoip fields - full test result at bottom of this post. "tags": \[ "\_ge…

---

## [Does \_split actually splits data or just copies it across shards](https://discuss.elastic.co/t/does-split-actually-splits-data-or-just-copies-it-across-shards/315164)

<div class="topic-metadata">

**Author:** [@danskiyq](https://discuss.elastic.co/u/danskiyq)\
**Replies:** 4\
**Last updated:** [September 26, 2022, 3:50pm UTC](https://discuss.elastic.co/t/does-split-actually-splits-data-or-just-copies-it-across-shards/315164 "2022-09-26T15:50:13Z")

</div>

I want to create a new index with bigger amount of shards and copy my data across. \_reindex would probably be the best solution, but I expected split to do what I wanted. So I have 38gb 1shard index and I wanted to spli…

---

## [Watcher : parsing index to get values to be used in watchers](https://discuss.elastic.co/t/watcher-parsing-index-to-get-values-to-be-used-in-watchers/315041)

<div class="topic-metadata">

**Author:** [@JohnJ\_M](https://discuss.elastic.co/u/JohnJ_M)\
**Replies:** 2\
**Last updated:** [September 26, 2022, 3:49pm UTC](https://discuss.elastic.co/t/watcher-parsing-index-to-get-values-to-be-used-in-watchers/315041 "2022-09-26T15:49:50Z")

</div>

Hello the community, first post for me so please excuse my possible mistakes. Here is my issue: I am using the watcher in Elastic v7.13.4. I am using watcher to send mail to my customers to produce audit report on dif…

---

## [Unable to change JVM heap file in Elastic search 5.4.0](https://discuss.elastic.co/t/unable-to-change-jvm-heap-file-in-elastic-search-5-4-0/315186)

<div class="topic-metadata">

**Author:** [@TharinduK](https://discuss.elastic.co/u/TharinduK)\
**Replies:** 0\
**Last updated:** [September 26, 2022, 3:33pm UTC](https://discuss.elastic.co/t/unable-to-change-jvm-heap-file-in-elastic-search-5-4-0/315186 "2022-09-26T15:33:33Z")

</div>

5 Nodes 7 GB memory - 3.5 GB JVM heap file Indices - 62 Primary Shared 222 Replica Shared 157 We have been tried to change jvm.option file in /etc/elasticsearch but it is not reflecting in Kibana dashboard.

---

## [Using a must\_not filter on 'drone' returns a document containing 'drone'](https://discuss.elastic.co/t/using-a-must-not-filter-on-drone-returns-a-document-containing-drone/315150)

<div class="topic-metadata">

**Author:** [@cracanut](https://discuss.elastic.co/u/cracanut)\
**Replies:** 6\
**Last updated:** [September 26, 2022, 3:03pm UTC](https://discuss.elastic.co/t/using-a-must-not-filter-on-drone-returns-a-document-containing-drone/315150 "2022-09-26T15:03:26Z")

</div>

Using a must\_not filter on 'drone' returns a document containing 'drone': Cluster analyzer settings: "analysis": { "filter": { "english\_stemmer": { "type": "stemmer", "language": "engl…

---

## [💠 JSON format for Server log connector](https://discuss.elastic.co/t/json-format-for-server-log-connector/315178)

<div class="topic-metadata">

**Author:** [@Its\_Anton](https://discuss.elastic.co/u/Its_Anton)\
**Replies:** 0\
**Last updated:** [September 26, 2022, 2:34pm UTC](https://discuss.elastic.co/t/json-format-for-server-log-connector/315178 "2022-09-26T14:34:06Z")

</div>

Hi! I have switched all logs from Kibana to JSON format and that work awesome! But when I use the Server log connector in my alerting rules, it adds annoying ''Server log: " text that breaks the JSON being logged: …

---

## [Maintain confidentiality of agents and user in kibana](https://discuss.elastic.co/t/maintain-confidentiality-of-agents-and-user-in-kibana/315143)

<div class="topic-metadata">

**Author:** [@yahire](https://discuss.elastic.co/u/yahire)\
**Replies:** 2\
**Last updated:** [September 26, 2022, 2:02pm UTC](https://discuss.elastic.co/t/maintain-confidentiality-of-agents-and-user-in-kibana/315143 "2022-09-26T14:02:25Z")

</div>

Hi team, Please have a look at below screenshots. I wanted to implement Elasticsearch in such a way that we can have seperate users for seperate projects so that one user can not see the agent and traces of another …

---

## [Errors in Kibana: plugins.securitySolution.endpoint:metadata-check-transforms-task:0.0.1](https://discuss.elastic.co/t/errors-in-kibana-plugins-securitysolution-endpoint0-0-1/314134)

<div class="topic-metadata">

**Author:** [@kurdit](https://discuss.elastic.co/u/kurdit)\
**Replies:** 1\
**Last updated:** [September 26, 2022, 2:02pm UTC](https://discuss.elastic.co/t/errors-in-kibana-plugins-securitysolution-endpoint0-0-1/314134 "2022-09-26T14:02:46Z")

</div>

hi all! in kibana.log I see a lot of errors like \[2022-09-07T03:58:32.117+03:00\]\[WARN \]\[plugins.securitySolution.endpoint:metadata-check-transforms-task:0.0.1\] transform endpoint.metadata\_current-default-8.3.0 has fail…

---

## [Elastic reindex documents with new fields](https://discuss.elastic.co/t/elastic-reindex-documents-with-new-fields/315177)

<div class="topic-metadata">

**Author:** [@vee](https://discuss.elastic.co/u/vee)\
**Replies:** 0\
**Last updated:** [September 26, 2022, 2:00pm UTC](https://discuss.elastic.co/t/elastic-reindex-documents-with-new-fields/315177 "2022-09-26T14:00:57Z")

</div>

Hi - What's the best way to update an existing index with new field added to it? For eg: Current index has fields, firstName,lastName,streetNo,City,Zipcode. I would like to add one more field called FullAddress - which…

---

## [Data table with time shift](https://discuss.elastic.co/t/data-table-with-time-shift/315172)

<div class="topic-metadata">

**Author:** [@Samuele\_Mosci](https://discuss.elastic.co/u/Samuele_Mosci)\
**Replies:** 3\
**Last updated:** [September 26, 2022, 1:53pm UTC](https://discuss.elastic.co/t/data-table-with-time-shift/315172 "2022-09-26T13:53:52Z")

</div>

Hi, I'm using Kibana 8.4. I am trying to make a visualization (in particular a data table) where I can view documents that I do not have in a timestamp but which are present in the timestamp of the previous day. I tried …

---

## [\[Kibana 7.17.1\] Index patterns disappear after restoring VM snaphots of ES cluster machines](https://discuss.elastic.co/t/kibana-7-17-1-index-patterns-disappear-after-restoring-vm-snaphots-of-es-cluster-machines/313457)

<div class="topic-metadata">

**Author:** [@gerib](https://discuss.elastic.co/u/gerib)\
**Replies:** 1\
**Last updated:** [September 26, 2022, 1:52pm UTC](https://discuss.elastic.co/t/kibana-7-17-1-index-patterns-disappear-after-restoring-vm-snaphots-of-es-cluster-machines/313457 "2022-09-26T13:52:19Z")

</div>

We're running an ES test cluster of 3 machines with the following nodes: master, coordinating only, data master, coordinating only, data master, ingest, data We have three index types in this cluster: shop-\<YYYY.MM.…

---

## [Не совпадает время в логе на сервере и в Kibana](https://discuss.elastic.co/t/kibana/314760)

<div class="topic-metadata">

**Author:** [@dbushkov](https://discuss.elastic.co/u/dbushkov)\
**Replies:** 2\
**Last updated:** [September 26, 2022, 1:34pm UTC](https://discuss.elastic.co/t/kibana/314760 "2022-09-26T13:34:30Z")

</div>

Не совпадает время в логе на сервере и в Kibana На сервере в логе время такого вида: 2022-09-20T08:57:48+00:00,057840 В Kibana получаю такое время: Sep 20, 2022 @ 15:57:48.225000000 Если я правильно понимаю, Kibana …

---

## [Ordering results based on derivate aggregation](https://discuss.elastic.co/t/ordering-results-based-on-derivate-aggregation/313954)

<div class="topic-metadata">

**Author:** [@Toni\_Heinonen](https://discuss.elastic.co/u/Toni_Heinonen)\
**Replies:** 1\
**Last updated:** [September 26, 2022, 1:32pm UTC](https://discuss.elastic.co/t/ordering-results-based-on-derivate-aggregation/313954 "2022-09-26T13:32:39Z")

</div>

I'm working with a audit trail data and trying to make a graph (or even a table) that would list users that have a greatest drop on usage since last month. So far I have tried the following. TSVB: I can get a percenta…

---

## [General guidance on data replication - Google Cloud](https://discuss.elastic.co/t/general-guidance-on-data-replication-google-cloud/315161)

<div class="topic-metadata">

**Author:** [@Lucien\_Perouze](https://discuss.elastic.co/u/Lucien_Perouze)\
**Replies:** 0\
**Last updated:** [September 26, 2022, 10:09am UTC](https://discuss.elastic.co/t/general-guidance-on-data-replication-google-cloud/315161 "2022-09-26T10:09:34Z")

</div>

I'm building a search engine for my app. For that i'm trying Elasticsearch for the first time. My app uses a Postgre SQL. As I understood I need to replicate datas from my Postgre to Elastic Search in order to perform RE…

[Previous page](https://discuss.elastic.co/tag/none.md?no_tags=true&page=529)

[Next page](https://discuss.elastic.co/tag/none.md?no_tags=true&page=531)
