# \#none

**URL:** https://discuss.elastic.co/tag/none.md?no_tags=true&page=559

[Latest](https://discuss.elastic.co/latest.md) · [Categories](https://discuss.elastic.co/categories.md) · [Tags](https://discuss.elastic.co/tags.md)

**Page:** 560

---

## [Elastic Observability Engineer training - Lab 6.1](https://discuss.elastic.co/t/elastic-observability-engineer-training-lab-6-1/312327)

<div class="topic-metadata">

**Author:** [@deccman](https://discuss.elastic.co/u/deccman)\
**Replies:** 2\
**Last updated:** [August 18, 2022, 12:55am UTC](https://discuss.elastic.co/t/elastic-observability-engineer-training-lab-6-1/312327 "2022-08-18T00:55:19Z")

</div>

I am currently doing the Elastic Observability Engineer training and starting on the Machine Learning lab. Lab 6.1 mentions that under the Anomaly Detection section that I should have two ML jobs for the logs-ui group f…

---

## [How to generate shingles before synonyms filter?](https://discuss.elastic.co/t/how-to-generate-shingles-before-synonyms-filter/312235)

<div class="topic-metadata">

**Author:** [@mattkallo](https://discuss.elastic.co/u/mattkallo)\
**Replies:** 2\
**Last updated:** [August 17, 2022, 10:56pm UTC](https://discuss.elastic.co/t/how-to-generate-shingles-before-synonyms-filter/312235 "2022-08-17T22:56:32Z")

</div>

Hi, I understand we can't have token filters that produce multiple tokens before a synonyms filter. (Ensure TokenFilters only produce single tokens when parsing synonyms by romseygeek · Pull Request #34331 · elastic/ela…

---

## [Disk usage exceeded flood-stage watermark](https://discuss.elastic.co/t/disk-usage-exceeded-flood-stage-watermark/312294)

<div class="topic-metadata">

**Author:** [@Khaled\_Saidi](https://discuss.elastic.co/u/Khaled_Saidi)\
**Replies:** 1\
**Last updated:** [August 17, 2022, 9:53pm UTC](https://discuss.elastic.co/t/disk-usage-exceeded-flood-stage-watermark/312294 "2022-08-17T21:53:10Z")

</div>

Hello everybody, I need some help on conception and settings. I have a cluster of 6 nodes running each one an elasticsearch server instance. An error was logged in logstash log file : TOO\_MANY\_REQUESTS/12/disk usage …

---

## [Error “S02000B61A1A001\>Service 'Elasticsearch 8.1.3 (elasticsearch-service-x64)' is not running. (No automatic restart is attempted)](https://discuss.elastic.co/t/error-s02000b61a1a001-service-elasticsearch-8-1-3-elasticsearch-service-x64-is-not-running-no-automatic-restart-is-attempted/312303)

<div class="topic-metadata">

**Author:** [@Coen](https://discuss.elastic.co/u/Coen)\
**Replies:** 1\
**Last updated:** [August 17, 2022, 9:42pm UTC](https://discuss.elastic.co/t/error-s02000b61a1a001-service-elasticsearch-8-1-3-elasticsearch-service-x64-is-not-running-no-automatic-restart-is-attempted/312303 "2022-08-17T21:42:40Z")

</div>

As the title says “S02000B61A1A001\>Service 'Elasticsearch 8.1.3 (elasticsearch-service-x64)' is not running. (No automatic restart is attempted). This event seems to happen daily, the services are being started by us an…

---

## [Developing Custom Parser for Logs](https://discuss.elastic.co/t/developing-custom-parser-for-logs/312021)

<div class="topic-metadata">

**Author:** [@sta02](https://discuss.elastic.co/u/sta02)\
**Replies:** 2\
**Last updated:** [August 17, 2022, 3:36pm UTC](https://discuss.elastic.co/t/developing-custom-parser-for-logs/312021 "2022-08-17T15:36:26Z")

</div>

Hello, In my installation, the output of Logstash is set to Azure Sentinel. The installation is working fine. However, the client prefers to send logs from inhouse applications to Sentinel via Syslog. Is it possible to…

---

## [How to read mongoDB logs from logstash jdbc plugin](https://discuss.elastic.co/t/how-to-read-mongodb-logs-from-logstash-jdbc-plugin/312301)

<div class="topic-metadata">

**Author:** [@sundar\_elk](https://discuss.elastic.co/u/sundar_elk)\
**Replies:** 0\
**Last updated:** [August 17, 2022, 3:00pm UTC](https://discuss.elastic.co/t/how-to-read-mongodb-logs-from-logstash-jdbc-plugin/312301 "2022-08-17T15:00:28Z")

</div>

Hi All, We are trying to get logs from MongoDB database using logstash jdbc plugin and below is the Logstash version :- 7.16.2 MongoDB version :- 4.2 MongoJDBC driver version :- mongojdbc4.1.jar (download jar from Dow…

---

## [Logstash parse json child element, format and insert into elasticsearch](https://discuss.elastic.co/t/logstash-parse-json-child-element-format-and-insert-into-elasticsearch/312230)

<div class="topic-metadata">

**Author:** [@babuzrb](https://discuss.elastic.co/u/babuzrb)\
**Replies:** 9\
**Last updated:** [August 17, 2022, 2:46pm UTC](https://discuss.elastic.co/t/logstash-parse-json-child-element-format-and-insert-into-elasticsearch/312230 "2022-08-17T14:46:50Z")

</div>

I have a json file like this: "fruits": { "fruit": \[ { "id": 1, "label": "test", "tag": "fine", "start": "4", "end": "9" }, { "id": 2, "lab…

---

## [Fscrawler only indexed 59 of a 2000 page pdf](https://discuss.elastic.co/t/fscrawler-only-indexed-59-of-a-2000-page-pdf/312262)

<div class="topic-metadata">

**Author:** [@defalt](https://discuss.elastic.co/u/defalt)\
**Replies:** 1\
**Last updated:** [August 17, 2022, 1:06pm UTC](https://discuss.elastic.co/t/fscrawler-only-indexed-59-of-a-2000-page-pdf/312262 "2022-08-17T13:06:10Z")

</div>

Hello :wave: i guess @dadoonet would know best about this but if someone else can answer this it would be great. I am currently trying to index pdfs into elasticsearch. I installed the 'Ingest Attachment Processor Plug…

---

## [Do Elastic Agent (integrations) and Logstash have best practices?a](https://discuss.elastic.co/t/do-elastic-agent-integrations-and-logstash-have-best-practices-a/312279)

<div class="topic-metadata">

**Author:** [@GustavoPires](https://discuss.elastic.co/u/GustavoPires)\
**Replies:** 1\
**Last updated:** [August 17, 2022, 12:16pm UTC](https://discuss.elastic.co/t/do-elastic-agent-integrations-and-logstash-have-best-practices-a/312279 "2022-08-17T12:16:21Z")

</div>

Hello, are there any good practices for using Logstash or Elastic Agent (integrations), for example, I have Pfsense Integration for Elastic Agent, at the same time I can send data via Syslog to Logstash. In what situatio…

---

## [Data Stream Backing Indice Count](https://discuss.elastic.co/t/data-stream-backing-indice-count/312271)

<div class="topic-metadata">

**Author:** [@Saeed\_Mozaffari](https://discuss.elastic.co/u/Saeed_Mozaffari)\
**Replies:** 1\
**Last updated:** [August 17, 2022, 11:28am UTC](https://discuss.elastic.co/t/data-stream-backing-indice-count/312271 "2022-08-17T11:28:00Z")

</div>

Dose the number of data stream backing indice have any effect on search time performance? for example if in one year i rollover every one month and in another scenario i rollover every one day, are these two scenarios d…

---

## [Is Elasticsearch guide available in PDF?](https://discuss.elastic.co/t/is-elasticsearch-guide-available-in-pdf/312043)

<div class="topic-metadata">

**Author:** [@Blason](https://discuss.elastic.co/u/Blason)\
**Replies:** 3\
**Last updated:** [August 17, 2022, 10:23am UTC](https://discuss.elastic.co/t/is-elasticsearch-guide-available-in-pdf/312043 "2022-08-17T10:23:09Z")

</div>

Hi Team, Wondering if elasticsearch guide is available in PDF format?

---

## [Custom list of keywords](https://discuss.elastic.co/t/custom-list-of-keywords/312264)

<div class="topic-metadata">

**Author:** [@seeminglee](https://discuss.elastic.co/u/seeminglee)\
**Replies:** 0\
**Last updated:** [August 17, 2022, 9:44am UTC](https://discuss.elastic.co/t/custom-list-of-keywords/312264 "2022-08-17T09:44:35Z")

</div>

I have setup an index with the following settings: { "settings": { "analysis": { "analyzer": { "html\_analyzer": { "type": "custom", "tokeni…

---

## [8 node setup , 2 nodes not joining the cluster](https://discuss.elastic.co/t/8-node-setup-2-nodes-not-joining-the-cluster/311806)

<div class="topic-metadata">

**Author:** [@jeevan\_hedge](https://discuss.elastic.co/u/jeevan_hedge)\
**Replies:** 15\
**Last updated:** [August 17, 2022, 9:08am UTC](https://discuss.elastic.co/t/8-node-setup-2-nodes-not-joining-the-cluster/311806 "2022-08-17T09:08:50Z")

</div>

we are running 2 instances of elasticsearch (6.6.1 version) in 4 nodes forming 8 nodes cluster setup. When we check the cluster health , the output showing only 6 nodes. 2 nodes are not joining the cluster . and we see …

---

## [Disable regex in Lucene search](https://discuss.elastic.co/t/disable-regex-in-lucene-search/311907)

<div class="topic-metadata">

**Author:** [@Leventi](https://discuss.elastic.co/u/Leventi)\
**Replies:** 2\
**Last updated:** [August 17, 2022, 9:03am UTC](https://discuss.elastic.co/t/disable-regex-in-lucene-search/311907 "2022-08-17T09:03:31Z")

</div>

Hi How I could disable regex in Lucene search? My problem is when I search something like that 32/22-ЕКТ I cant't find anything. It's working just when I write in quotes like this "32/22-ЕКТ" or 32/22-ЕКТ It's becaus…

---

## [How to upgrade node.js (from v10.23.1 to v16.13.2) in Kibana 7.10.2](https://discuss.elastic.co/t/how-to-upgrade-node-js-from-v10-23-1-to-v16-13-2-in-kibana-7-10-2/307409)

<div class="topic-metadata">

**Author:** [@mridul.tamuli](https://discuss.elastic.co/u/mridul.tamuli)\
**Replies:** 2\
**Last updated:** [August 17, 2022, 9:02am UTC](https://discuss.elastic.co/t/how-to-upgrade-node-js-from-v10-23-1-to-v16-13-2-in-kibana-7-10-2/307409 "2022-08-17T09:02:19Z")

</div>

Hi, We are using Kibana 7.10.2 with Elasticsearch of the same version. Currently we have a urgent need to upgrade the node.js version of Kibana to 16.13.2. We tried but unable to get the desired result. Is it possible t…

---

## [Moving applications logs to Elastic Observability](https://discuss.elastic.co/t/moving-applications-logs-to-elastic-observability/305409)

<div class="topic-metadata">

**Author:** [@michael\_kot](https://discuss.elastic.co/u/michael_kot)\
**Replies:** 15\
**Last updated:** [August 17, 2022, 9:00am UTC](https://discuss.elastic.co/t/moving-applications-logs-to-elastic-observability/305409 "2022-08-17T09:00:13Z")

</div>

Hello, Our team is developing a product - an application for e-commerce. This application has logs that are stored in the file system and displayed in the admin panel of this application. So any admin user can go to th…

---

## [Ratio visualization](https://discuss.elastic.co/t/ratio-visualization/312257)

<div class="topic-metadata">

**Author:** [@Mikhail\_M](https://discuss.elastic.co/u/Mikhail_M)\
**Replies:** 0\
**Last updated:** [August 17, 2022, 8:23am UTC](https://discuss.elastic.co/t/ratio-visualization/312257 "2022-08-17T08:23:57Z")

</div>

Hello! Can you pls give a hint how to create this kind of timeserial visualization. Let's say I've got documents like this: doc1:(term = 'term1', value = 1) doc2:(term = 'term2', value = 2) doc3:(term = 'term3', valu…

---

## [Unable to start elasticsearch service](https://discuss.elastic.co/t/unable-to-start-elasticsearch-service/312083)

<div class="topic-metadata">

**Author:** [@Alice\_Walker](https://discuss.elastic.co/u/Alice_Walker)\
**Replies:** 2\
**Last updated:** [August 17, 2022, 7:50am UTC](https://discuss.elastic.co/t/unable-to-start-elasticsearch-service/312083 "2022-08-17T07:50:03Z")

</div>

Unable to start elastisearch service on AWS EC2 instances. systemctl start elasticsearch Job for elasticsearch.service failed because a fatal signal was delivered to the control process. See "systemctl status elasticse…

---

## [Comparison of data between two time points](https://discuss.elastic.co/t/comparison-of-data-between-two-time-points/312172)

<div class="topic-metadata">

**Author:** [@RonGros](https://discuss.elastic.co/u/RonGros)\
**Replies:** 3\
**Last updated:** [August 17, 2022, 6:39am UTC](https://discuss.elastic.co/t/comparison-of-data-between-two-time-points/312172 "2022-08-17T06:39:24Z")

</div>

Hi, I think the answer is "no can do" but I will ask anyhow in case I am missing something (and if I'm right it's surprising that I'm the only one to need it) We are monitoring results of tests on a daily basis. we have…

---

## [Logstash DLQ dir empty, but all events end up duplicated in the Elasticsearch's dlq index](https://discuss.elastic.co/t/logstash-dlq-dir-empty-but-all-events-end-up-duplicated-in-the-elasticsearchs-dlq-index/312250)

<div class="topic-metadata">

**Author:** [@kudlatyjoe](https://discuss.elastic.co/u/kudlatyjoe)\
**Replies:** 0\
**Last updated:** [August 17, 2022, 6:22am UTC](https://discuss.elastic.co/t/logstash-dlq-dir-empty-but-all-events-end-up-duplicated-in-the-elasticsearchs-dlq-index/312250 "2022-08-17T06:22:41Z")

</div>

Hi all, I'm currently trying to introduce the dead-letter-plugin to the ELK stack that we use for collecting application logs. We've been having some issues with the logging functionality breaking down and losing some …

---

## [Elasticsearch snapshot for starting Kibana as a developer](https://discuss.elastic.co/t/elasticsearch-snapshot-for-starting-kibana-as-a-developer/312135)

<div class="topic-metadata">

**Author:** [@Sheereen](https://discuss.elastic.co/u/Sheereen)\
**Replies:** 3\
**Last updated:** [August 17, 2022, 5:56am UTC](https://discuss.elastic.co/t/elasticsearch-snapshot-for-starting-kibana-as-a-developer/312135 "2022-08-17T05:56:27Z")

</div>

To create a custom plugin, I 1. I cloned the kibana git hub repo 2. yarn kbn bootstrap ----\> was succesfull The next step as per the documentation, (Getting started | Kibana Guide \[master\] | Elastic) yarn es snapsh…

---

## [Unable to use OpenJDK distribution with Elasticsearch](https://discuss.elastic.co/t/unable-to-use-openjdk-distribution-with-elasticsearch/312239)

<div class="topic-metadata">

**Author:** [@Fasil](https://discuss.elastic.co/u/Fasil)\
**Replies:** 4\
**Last updated:** [August 17, 2022, 5:06am UTC](https://discuss.elastic.co/t/unable-to-use-openjdk-distribution-with-elasticsearch/312239 "2022-08-17T05:06:28Z")

</div>

Trying to run elasticsearch-8.3.3-windows-x86\_64 release with OpenJDK 19 Early Access Build 35. But my locally installed OpenJDK 19 is ignored and used bundled Oracle JDK version 18 while starting elasticsearch for the …

---

## [Documentation Error RE: elasticsearch multi-target syntax](https://discuss.elastic.co/t/documentation-error-re-elasticsearch-multi-target-syntax/312233)

<div class="topic-metadata">

**Author:** [@Andrew\_DS](https://discuss.elastic.co/u/Andrew_DS)\
**Replies:** 0\
**Last updated:** [August 17, 2022, 1:11am UTC](https://discuss.elastic.co/t/documentation-error-re-elasticsearch-multi-target-syntax/312233 "2022-08-17T01:11:14Z")

</div>

In the API Conventions Documentation, you state: Aliases are resolved after wildcard expressions. This can result in a request that targets an excluded alias. For example, if test3 is an index alias, the pattern test\*,…

---

## [Elasticsearch platinum license](https://discuss.elastic.co/t/elasticsearch-platinum-license/312187)

<div class="topic-metadata">

**Author:** [@vnaresh666666](https://discuss.elastic.co/u/vnaresh666666)\
**Replies:** 1\
**Last updated:** [August 16, 2022, 10:32pm UTC](https://discuss.elastic.co/t/elasticsearch-platinum-license/312187 "2022-08-16T22:32:15Z")

</div>

I am planning to buy elasticsearch platinum license. I have one question that if I buy one license, can I use the same license for dev, UAT, Prod or should I take three licenses for three environments. Please provide the…

---

## [Python and kibana](https://discuss.elastic.co/t/python-and-kibana/312212)

<div class="topic-metadata">

**Author:** [@5k\_pwc](https://discuss.elastic.co/u/5k_pwc)\
**Replies:** 1\
**Last updated:** [August 16, 2022, 10:27pm UTC](https://discuss.elastic.co/t/python-and-kibana/312212 "2022-08-16T22:27:27Z")

</div>

Hi all , as a beginner, I would like to know in what condition I use python and kibana together.

---

## [How to divide two doc\_count values in aggregations](https://discuss.elastic.co/t/how-to-divide-two-doc-count-values-in-aggregations/312035)

<div class="topic-metadata">

**Author:** [@Chandana\_P](https://discuss.elastic.co/u/Chandana_P)\
**Replies:** 5\
**Last updated:** [August 16, 2022, 10:26pm UTC](https://discuss.elastic.co/t/how-to-divide-two-doc-count-values-in-aggregations/312035 "2022-08-16T22:26:44Z")

</div>

I want to perform division between two doc\_count values of unique fields obtained through "terms" bucket aggregation. Is there a way to do that?

---

## [Found not working footnote in docs. Can't fix it](https://discuss.elastic.co/t/found-not-working-footnote-in-docs-cant-fix-it/312177)

<div class="topic-metadata">

**Author:** [@defalt](https://discuss.elastic.co/u/defalt)\
**Replies:** 1\
**Last updated:** [August 16, 2022, 10:13pm UTC](https://discuss.elastic.co/t/found-not-working-footnote-in-docs-cant-fix-it/312177 "2022-08-16T22:13:25Z")

</div>

Hey, hope this is the right forum to post this. The references in here Snapshot and restore | Elasticsearch Guide \[8.3\] | Elastic dont work. (You cant click the small '2') Tried to fix it via a pull request in git…

---

## [I want to write in another index with project monitor (synthetic monitor) It's possible?](https://discuss.elastic.co/t/i-want-to-write-in-another-index-with-project-monitor-synthetic-monitor-its-possible/311232)

<div class="topic-metadata">

**Author:** [@odelacruzc](https://discuss.elastic.co/u/odelacruzc)\
**Replies:** 7\
**Last updated:** [August 16, 2022, 10:09pm UTC](https://discuss.elastic.co/t/i-want-to-write-in-another-index-with-project-monitor-synthetic-monitor-its-possible/311232 "2022-08-16T22:09:50Z")

</div>

I want to write in another index with project monitor (synthetic monitor) It's possible?, I can to change the index synthetic-\* or write in other datastream?

---

## [Decorators: registry.register\_document vs INDEX.doc\_type](https://discuss.elastic.co/t/decorators-registry-register-document-vs-index-doc-type/312218)

<div class="topic-metadata">

**Author:** [@scheung38](https://discuss.elastic.co/u/scheung38)\
**Replies:** 0\
**Last updated:** [August 16, 2022, 8:17pm UTC](https://discuss.elastic.co/t/decorators-registry-register-document-vs-index-doc-type/312218 "2022-08-16T20:17:21Z")

</div>

Sometimes I see decorators: from django\_elasticsearch\_dsl import Index INDEX = Index(settings.ELASTICSEARCH\_INDEX\_NAMES\[\_\_name\_\_\]) @INDEX.doc\_type and from django\_elasticsearch\_dsl.registries import registry from art…

---

## [How to get first file and last file in data?](https://discuss.elastic.co/t/how-to-get-first-file-and-last-file-in-data/311945)

<div class="topic-metadata">

**Author:** [@MLsuper](https://discuss.elastic.co/u/MLsuper)\
**Replies:** 3\
**Last updated:** [August 16, 2022, 7:47pm UTC](https://discuss.elastic.co/t/how-to-get-first-file-and-last-file-in-data/311945 "2022-08-16T19:47:18Z")

</div>

I have a index pattern with data with files for every business day(i have a run time field named business time/day) which is the business day and time everyday. Now I want to show a visualization/dashboard to get the ba…

[Previous page](https://discuss.elastic.co/tag/none.md?no_tags=true&page=558)

[Next page](https://discuss.elastic.co/tag/none.md?no_tags=true&page=560)
