# \#none

**URL:** https://discuss.elastic.co/tag/none.md?no_tags=true&page=238

[Latest](https://discuss.elastic.co/latest.md) · [Categories](https://discuss.elastic.co/categories.md) · [Tags](https://discuss.elastic.co/tags.md)

**Page:** 239

---

## [401 Unauthorized](https://discuss.elastic.co/t/401-unauthorized/351806)

<div class="topic-metadata">

**Author:** [@Lukasz\_Skrzat](https://discuss.elastic.co/u/Lukasz_Skrzat)\
**Replies:** 1\
**Last updated:** [January 27, 2024, 2:50pm UTC](https://discuss.elastic.co/t/401-unauthorized/351806 "2024-01-27T14:50:49Z")

</div>

Hi i trying connect my kubernetes agent to elastic-stack using fleet token but after deployment have error "Failed to connect to backoff(elasticsearch(https://elasticsearch.logging-stack.svc.cluster.local:9200)): 401 U…

---

## [Using one index and constantly removing from it would lead to a problem?](https://discuss.elastic.co/t/using-one-index-and-constantly-removing-from-it-would-lead-to-a-problem/351907)

<div class="topic-metadata">

**Author:** [@m4kkur0](https://discuss.elastic.co/u/m4kkur0)\
**Replies:** 0\
**Last updated:** [January 27, 2024, 6:20am UTC](https://discuss.elastic.co/t/using-one-index-and-constantly-removing-from-it-would-lead-to-a-problem/351907 "2024-01-27T06:20:46Z")

</div>

Hello, I wonder if using an index and constantly removing documents from it leads to problems? I upsert, daily, around 10 millions of documents so, there is a chance of removing 10 millions of documents. Why I am doing…

---

## [Generating same token for related words](https://discuss.elastic.co/t/generating-same-token-for-related-words/351902)

<div class="topic-metadata">

**Author:** [@RabBit\_BR](https://discuss.elastic.co/u/RabBit_BR)\
**Replies:** 0\
**Last updated:** [January 26, 2024, 9:15pm UTC](https://discuss.elastic.co/t/generating-same-token-for-related-words/351902 "2024-01-26T21:15:51Z")

</div>

Hello everybody. I would like to know if it is possible using analyzer to generate the same token for the following words: "bronzeadora", "bronze", "bronzeado". The token I need for the three words would be "bronz". I …

---

## [Input Varnish Logs to Logstash](https://discuss.elastic.co/t/input-varnish-logs-to-logstash/351898)

<div class="topic-metadata">

**Author:** [@ugola](https://discuss.elastic.co/u/ugola)\
**Replies:** 1\
**Last updated:** [January 26, 2024, 8:54pm UTC](https://discuss.elastic.co/t/input-varnish-logs-to-logstash/351898 "2024-01-26T20:54:23Z")

</div>

My goal is to send varnish logs to Logstash, both are running on different servers. Currently I am able to perform this using rsyslog (I also saw examples of FileBeat being used) on the machine where varnish logs are sto…

---

## [Would like to search text and try to identify strings that could be a persons name](https://discuss.elastic.co/t/would-like-to-search-text-and-try-to-identify-strings-that-could-be-a-persons-name/351745)

<div class="topic-metadata">

**Author:** [@warrengoldman](https://discuss.elastic.co/u/warrengoldman)\
**Replies:** 3\
**Last updated:** [January 26, 2024, 8:03pm UTC](https://discuss.elastic.co/t/would-like-to-search-text-and-try-to-identify-strings-that-could-be-a-persons-name/351745 "2024-01-26T20:03:52Z")

</div>

Example I have text like the following: Jeremy went to the ice cream shop with David and they met Sharee there. of the above Jeremy, David and Sharee are names. Is there a query I might be able to run that can identify…

---

## [Getting \_grokparsefailure for grok pattern on \[audit\_data\]\[messages\] field for modsecurity json log?](https://discuss.elastic.co/t/getting-grokparsefailure-for-grok-pattern-on-audit-data-messages-field-for-modsecurity-json-log/351831)

<div class="topic-metadata">

**Author:** [@sunnysigara](https://discuss.elastic.co/u/sunnysigara)\
**Replies:** 4\
**Last updated:** [January 26, 2024, 5:52pm UTC](https://discuss.elastic.co/t/getting-grokparsefailure-for-grok-pattern-on-audit-data-messages-field-for-modsecurity-json-log/351831 "2024-01-26T17:52:51Z")

</div>

Input Json {"transaction":{"time":"26/Jan/2024:00:54:31 +0530","transaction\_id":"16645304250678661185","remote\_address":"141.98.7.28","remote\_port":80,"local\_address":"127.0.0.1","local\_port":80},"request":{"request\_lin…

---

## [Set up remote cluster CA certificate in Elasticsearch 8.8.1](https://discuss.elastic.co/t/set-up-remote-cluster-ca-certificate-in-elasticsearch-8-8-1/351889)

<div class="topic-metadata">

**Author:** [@rachelyang](https://discuss.elastic.co/u/rachelyang)\
**Replies:** 0\
**Last updated:** [January 26, 2024, 2:53pm UTC](https://discuss.elastic.co/t/set-up-remote-cluster-ca-certificate-in-elasticsearch-8-8-1/351889 "2024-01-26T14:53:03Z")

</div>

I have a local cluster. Now I would like to set up a remote cluster to connect to the local cluster. How do I set up the CA certificate on the remote cluster node to make these two cluster to trust each other? Here is …

---

## [Detections API cant work with Unicode characters](https://discuss.elastic.co/t/detections-api-cant-work-with-unicode-characters/351781)

<div class="topic-metadata">

**Author:** [@gbL2k](https://discuss.elastic.co/u/gbL2k)\
**Replies:** 24\
**Last updated:** [January 26, 2024, 2:29pm UTC](https://discuss.elastic.co/t/detections-api-cant-work-with-unicode-characters/351781 "2024-01-26T14:29:10Z")

</div>

Hello everyone! I would like to to create detections with unicode characters in the description but I cant seem to find a way to make the API work with unicode characters. Anyone had the same problem? Thanks in advanc…

---

## [My Agent not send Logs, Kibana Healthy Green](https://discuss.elastic.co/t/my-agent-not-send-logs-kibana-healthy-green/351600)

<div class="topic-metadata">

**Author:** [@aguskhohar](https://discuss.elastic.co/u/aguskhohar)\
**Replies:** 3\
**Last updated:** [January 26, 2024, 1:10pm UTC](https://discuss.elastic.co/t/my-agent-not-send-logs-kibana-healthy-green/351600 "2024-01-26T13:10:40Z")

</div>

Hi Guys, Could you please to help me, my kibana is green but my agent not send log. fyi, my elastic : http://localhost:9200 my kibana : http://10.xxx.xxx.xxx:5601 my fleet server : http://10.xxx.xxx.xxx:8220

---

## [Why \_grokparsefailure?](https://discuss.elastic.co/t/why-grokparsefailure/351859)

<div class="topic-metadata">

**Author:** [@emoxam](https://discuss.elastic.co/u/emoxam)\
**Replies:** 5\
**Last updated:** [January 26, 2024, 12:38pm UTC](https://discuss.elastic.co/t/why-grokparsefailure/351859 "2024-01-26T12:38:14Z")

</div>

Part of a config filter { if \[message\] =~ /actions/ or \[message\] =~ /172\\.16\\.10\\.78/ or \[message\] =~ /172\\.16\\.10\\.77/ { grok { match =\> \[ "message", "%{GREEDYDATA:timestamp}%{LOGLEVEL:level}%{GR…

---

## [FSCrawler - Folder index is not getting created in the latest version](https://discuss.elastic.co/t/fscrawler-folder-index-is-not-getting-created-in-the-latest-version/351544)

<div class="topic-metadata">

**Author:** [@kamalsharma](https://discuss.elastic.co/u/kamalsharma)\
**Replies:** 8\
**Last updated:** [January 26, 2024, 9:46am UTC](https://discuss.elastic.co/t/fscrawler-folder-index-is-not-getting-created-in-the-latest-version/351544 "2024-01-26T09:46:28Z")

</div>

The index name is fs-test-001 (Example) in the \_settings.json file. After running the FsCrawler, Template is automatically added in the Elastic. I am able to see the Templates for the index as well as for the folders alo…

---

## [How to invoke custom rescorer plugin using elasticsearch-java 8 client](https://discuss.elastic.co/t/how-to-invoke-custom-rescorer-plugin-using-elasticsearch-java-8-client/351868)

<div class="topic-metadata">

**Author:** [@baji](https://discuss.elastic.co/u/baji)\
**Replies:** 0\
**Last updated:** [January 26, 2024, 9:27am UTC](https://discuss.elastic.co/t/how-to-invoke-custom-rescorer-plugin-using-elasticsearch-java-8-client/351868 "2024-01-26T09:27:49Z")

</div>

Hi, I have migrated a custom rescorer plugin from Elasticsearch version 7 to 8. I can invoke the plugin using the following request. However, I am unable to generate a similar request using elasticsearch-java 8.10.4. I …

---

## [Failed to install template {:message=\>"Got response code '400' contacting Elasticsearch at URL 'http://x.x.x.x:9200/\_template/ecs-logstash'",](https://discuss.elastic.co/t/failed-to-install-template-message-got-response-code-400-contacting-elasticsearch-at-url-http-x-x-x-x-9200-template-ecs-logstash/351578)

<div class="topic-metadata">

**Author:** [@sunnysigara](https://discuss.elastic.co/u/sunnysigara)\
**Replies:** 5\
**Last updated:** [January 26, 2024, 7:13am UTC](https://discuss.elastic.co/t/failed-to-install-template-message-got-response-code-400-contacting-elasticsearch-at-url-http-x-x-x-x-9200-template-ecs-logstash/351578 "2024-01-26T07:13:27Z")

</div>

Using a default mapping template {:es\_version=\>7, :ecs\_compatibility=\>:v8} gives me this error, \[2024-01-23T02:24:07,381\]\[INFO \]\[logstash.outputs.elasticsearch\]\[main\] Elasticsearch version determined (7.13.3) {:es\_versi…

---

## [I have installed Elasticsearch 7.17.17 version. i am doing semantic search, but at final search it give me the error which is give below:BadRequestError(400, 'illegal\_argument\_exception', 'Invalid type: expecting \[\_doc\] but got \[\_knn\_search\]')](https://discuss.elastic.co/t/i-have-installed-elasticsearch-7-17-17-version-i-am-doing-semantic-search-but-at-final-search-it-give-me-the-error-which-is-give-below-badrequesterror-400-illegal-argument-exception-invalid-type-expecting-doc-but-got-knn-search/351853)

<div class="topic-metadata">

**Author:** [@Muhammad\_Adnan1](https://discuss.elastic.co/u/Muhammad_Adnan1)\
**Replies:** 2\
**Last updated:** [January 26, 2024, 6:46am UTC](https://discuss.elastic.co/t/i-have-installed-elasticsearch-7-17-17-version-i-am-doing-semantic-search-but-at-final-search-it-give-me-the-error-which-is-give-below-badrequesterror-400-illegal-argument-exception-invalid-type-expecting-doc-but-got-knn-search/351853 "2024-01-26T06:46:07Z")

</div>

BadRequestError(400, 'illegal\_argument\_exception', 'Invalid type: expecting \[\_doc\] but got \[\_knn\_search\]')

---

## [Not able to use profiling on fargate enviroment](https://discuss.elastic.co/t/not-able-to-use-profiling-on-fargate-enviroment/350688)

<div class="topic-metadata">

**Author:** [@julianep](https://discuss.elastic.co/u/julianep)\
**Replies:** 3\
**Last updated:** [January 26, 2024, 6:40am UTC](https://discuss.elastic.co/t/not-able-to-use-profiling-on-fargate-enviroment/350688 "2024-01-26T06:40:00Z")

</div>

I'm using the elastic agent to implement the Universal Profiling feature in our AWS ECS Fargate clusters, but I'm facing strange errors and we got stuck trying to get this working properly, i know this is related to ebpf…

---

## [Looking for advice on a use case for NetFlow](https://discuss.elastic.co/t/looking-for-advice-on-a-use-case-for-netflow/351422)

<div class="topic-metadata">

**Author:** [@tonitones](https://discuss.elastic.co/u/tonitones)\
**Replies:** 3\
**Last updated:** [January 26, 2024, 2:47am UTC](https://discuss.elastic.co/t/looking-for-advice-on-a-use-case-for-netflow/351422 "2024-01-26T02:47:10Z")

</div>

Hello everyone from the elastic community! This will be my first topic here. Hoping to get some insights from everyone. I am very new to elastic. I was able to install and run elk stack on docker, thanks to the official…

---

## [Unable to Set UP TLS for Kibana](https://discuss.elastic.co/t/unable-to-set-up-tls-for-kibana/351380)

<div class="topic-metadata">

**Author:** [@audric\_w](https://discuss.elastic.co/u/audric_w)\
**Replies:** 2\
**Last updated:** [January 26, 2024, 2:19am UTC](https://discuss.elastic.co/t/unable-to-set-up-tls-for-kibana/351380 "2024-01-26T02:19:27Z")

</div>

Hi, I've encountered a problem when trying to disable TLSv1.1 for Kibana using the command below: server.ssl.supportedProtocols: "TLSv1.2" However, after adding that command, the Kibana cannot be started: Jan 19 03:3…

---

## [Maintaining @timestamp order of docs when using the reindex api](https://discuss.elastic.co/t/maintaining-timestamp-order-of-docs-when-using-the-reindex-api/351318)

<div class="topic-metadata">

**Author:** [@petlit2049](https://discuss.elastic.co/u/petlit2049)\
**Replies:** 1\
**Last updated:** [January 26, 2024, 1:36am UTC](https://discuss.elastic.co/t/maintaining-timestamp-order-of-docs-when-using-the-reindex-api/351318 "2024-01-26T01:36:06Z")

</div>

There's a deprecated feature in the reindex api which makes (made?) it possible to maintain the timestamp order between docs being reindexed using the reindex api. However, the documentation states that this is a depreca…

---

## [Basic Setup failures joining an existing cluster](https://discuss.elastic.co/t/basic-setup-failures-joining-an-existing-cluster/351830)

<div class="topic-metadata">

**Author:** [@bryanrood](https://discuss.elastic.co/u/bryanrood)\
**Replies:** 0\
**Last updated:** [January 25, 2024, 7:53pm UTC](https://discuss.elastic.co/t/basic-setup-failures-joining-an-existing-cluster/351830 "2024-01-25T19:53:41Z")

</div>

Hi there, I have been beating my head against a tree trying to get nodes added to my new ES cluster. I'm trying to build a 6 node ES cluster. I got the first node working and I'm trying to add the second node. I can ge…

---

## [How to loop the jdbc streaming filter by pass the index of array of object?](https://discuss.elastic.co/t/how-to-loop-the-jdbc-streaming-filter-by-pass-the-index-of-array-of-object/351784)

<div class="topic-metadata">

**Author:** [@kishorkumar](https://discuss.elastic.co/u/kishorkumar)\
**Replies:** 1\
**Last updated:** [January 25, 2024, 5:59pm UTC](https://discuss.elastic.co/t/how-to-loop-the-jdbc-streaming-filter-by-pass-the-index-of-array-of-object/351784 "2024-01-25T17:59:31Z")

</div>

So here is the usecase i have the "mainSKU": \[ { "id": 102, }, { "id": 101, }, { "id": 100, } \] like this and i am using jdb\_streaming and every mainSKU has 3 to 4 SKU in order to that i need to loop get …

---

## [Sql escape character in logstash](https://discuss.elastic.co/t/sql-escape-character-in-logstash/351800)

<div class="topic-metadata">

**Author:** [@Rakesh\_Verma](https://discuss.elastic.co/u/Rakesh_Verma)\
**Replies:** 2\
**Last updated:** [January 25, 2024, 5:51pm UTC](https://discuss.elastic.co/t/sql-escape-character-in-logstash/351800 "2024-01-25T17:51:31Z")

</div>

I am getting below error in following sql . SELECT HA.HotelID AS HotelCode,'\[' + STUFF((SELECT ',' + '{"AmenityId": ' + CAST(HA\_inner.AmenityId AS VARCHAR(10)) + ', "AmenityName": ' + QUOTENAME(HAT\_inner.AmenityName, '"…

---

## [Anonymous Viewer unable to see links panel](https://discuss.elastic.co/t/anonymous-viewer-unable-to-see-links-panel/351650)

<div class="topic-metadata">

**Author:** [@A\_Sto](https://discuss.elastic.co/u/A_Sto)\
**Replies:** 3\
**Last updated:** [January 25, 2024, 5:18pm UTC](https://discuss.elastic.co/t/anonymous-viewer-unable-to-see-links-panel/351650 "2024-01-25T17:18:16Z")

</div>

I recently updated my dashboards with a links panel. I have anonymous viewing set up with read permissions on a subset of dashboards to enable users without explicit logins to view some basic dashboards. The links panels…

---

## [Elastic artifacts repository missing last release](https://discuss.elastic.co/t/elastic-artifacts-repository-missing-last-release/350367)

<div class="topic-metadata">

**Author:** [@nisow95612](https://discuss.elastic.co/u/nisow95612)\
**Replies:** 3\
**Last updated:** [January 25, 2024, 4:05pm UTC](https://discuss.elastic.co/t/elastic-artifacts-repository-missing-last-release/350367 "2024-01-25T16:05:49Z")

</div>

Hello, I again notice new elastic version is released - Release notes | Elasticsearch Guide \[7.17\] | Elastic, now also with security fixes (Elasticsearch 8.11.2, 7.17.16 Security Update (ESA-2023-29)), but it is not ava…

---

## [How often a shard is actually refreshing](https://discuss.elastic.co/t/how-often-a-shard-is-actually-refreshing/351801)

<div class="topic-metadata">

**Author:** [@ktech007](https://discuss.elastic.co/u/ktech007)\
**Replies:** 3\
**Last updated:** [January 25, 2024, 2:31pm UTC](https://discuss.elastic.co/t/how-often-a-shard-is-actually-refreshing/351801 "2024-01-25T14:31:31Z")

</div>

Hi, I am trying to better understand how often a shard is refreshed in comparison to the refresh interval. For some context: We are trying to calculate the indexing lag in our indexing pipeline and refresh interval is …

---

## [Import Emails into Elasticsearch using Logstash IMAP Input](https://discuss.elastic.co/t/import-emails-into-elasticsearch-using-logstash-imap-input/351798)

<div class="topic-metadata">

**Author:** [@frank\_esg](https://discuss.elastic.co/u/frank_esg)\
**Replies:** 0\
**Last updated:** [January 25, 2024, 12:38pm UTC](https://discuss.elastic.co/t/import-emails-into-elasticsearch-using-logstash-imap-input/351798 "2024-01-25T12:38:01Z")

</div>

Hi, we would like to import Emails into Elasticsearch to have a kind of Email Archive. We started with Logstash and the IMAP Input plugin. But it turned out that this plugin was not updated in the last years and has se…

---

## [Failing to match "53...\\n" with "\[0-9\]\[0-9\]\\\\.\\\\.\\\\.\\n?" in Discover filter. Help?](https://discuss.elastic.co/t/failing-to-match-53-n-with-0-9-0-9-n-in-discover-filter-help/351104)

<div class="topic-metadata">

**Author:** [@timbav](https://discuss.elastic.co/u/timbav)\
**Replies:** 7\
**Last updated:** [January 25, 2024, 12:02pm UTC](https://discuss.elastic.co/t/failing-to-match-53-n-with-0-9-0-9-n-in-discover-filter-help/351104 "2024-01-25T12:02:35Z")

</div>

I'm on v 7.10.0 of Kibana. My logs are line-based Json, and the JSON looks like this: {"dlog":{ ..., "line":"53...\\n", ...}, ...} Those dots are three . characters, not a unicode ellipsis: 0000000 , " l i…

---

## [Elk 7.5 How to show all indexes having storage\_term as cold](https://discuss.elastic.co/t/elk-7-5-how-to-show-all-indexes-having-storage-term-as-cold/351377)

<div class="topic-metadata">

**Author:** [@mpniel](https://discuss.elastic.co/u/mpniel)\
**Replies:** 5\
**Last updated:** [January 25, 2024, 11:16am UTC](https://discuss.elastic.co/t/elk-7-5-how-to-show-all-indexes-having-storage-term-as-cold/351377 "2024-01-25T11:16:38Z")

</div>

How to show all indexes having storage\_term as cold? Why are there indexes with this cold parameter?

---

## [How to convert HEXA field into ASCII field through logstash pipeline](https://discuss.elastic.co/t/how-to-convert-hexa-field-into-ascii-field-through-logstash-pipeline/351771)

<div class="topic-metadata">

**Author:** [@upreddy](https://discuss.elastic.co/u/upreddy)\
**Replies:** 1\
**Last updated:** [January 25, 2024, 9:44am UTC](https://discuss.elastic.co/t/how-to-convert-hexa-field-into-ascii-field-through-logstash-pipeline/351771 "2024-01-25T09:44:11Z")

</div>

Hi All, we are getting one filed in the form of hexa i need to convert that filed into ASCII through logstash pipeline. Could you please guide me on this? eg:- "abc": "8a64756c656173654368616e" I need to convert "abc"…

---

## [Kibana is not connecting to Elasticsearch when providing own Certificate](https://discuss.elastic.co/t/kibana-is-not-connecting-to-elasticsearch-when-providing-own-certificate/351763)

<div class="topic-metadata">

**Author:** [@avrix121](https://discuss.elastic.co/u/avrix121)\
**Replies:** 1\
**Last updated:** [January 25, 2024, 7:32am UTC](https://discuss.elastic.co/t/kibana-is-not-connecting-to-elasticsearch-when-providing-own-certificate/351763 "2024-01-25T07:32:23Z")

</div>

Hi Team, I have deployed ECK 2.11 on AWS EKS. I have used elastic and kibana resource files as given in official quickstart documentation. I am exposing Kibana and elasticsearch externally using domain names and have c…

---

## [Rule preview is slow](https://discuss.elastic.co/t/rule-preview-is-slow/351732)

<div class="topic-metadata">

**Author:** [@elasticexpert](https://discuss.elastic.co/u/elasticexpert)\
**Replies:** 2\
**Last updated:** [January 25, 2024, 5:07am UTC](https://discuss.elastic.co/t/rule-preview-is-slow/351732 "2024-01-25T05:07:57Z")

</div>

Rule preview is very slow, but when I take the search and search it in kibana dev tools it is very fast. In the rule preview it says that the query time is fast (3ms), so I opened chrome dev tools at network and saw tha…

[Previous page](https://discuss.elastic.co/tag/none.md?no_tags=true&page=237)

[Next page](https://discuss.elastic.co/tag/none.md?no_tags=true&page=239)
