# \#none

**URL:** https://discuss.elastic.co/tag/none.md?no_tags=true&page=245

[Latest](https://discuss.elastic.co/latest.md) · [Categories](https://discuss.elastic.co/categories.md) · [Tags](https://discuss.elastic.co/tags.md)

**Page:** 246

---

## [Plugin logstash.inputs.tcp debug logging showing many "initialized channel" messages](https://discuss.elastic.co/t/plugin-logstash-inputs-tcp-debug-logging-showing-many-initialized-channel-messages/350990)

<div class="topic-metadata">

**Author:** [@bbenne821](https://discuss.elastic.co/u/bbenne821)\
**Replies:** 0\
**Last updated:** [January 12, 2024, 9:30pm UTC](https://discuss.elastic.co/t/plugin-logstash-inputs-tcp-debug-logging-showing-many-initialized-channel-messages/350990 "2024-01-12T21:30:53Z")

</div>

Running OSS logstash 2.8.2, bundled JDK, on CentOS 7 Linux plugin tcp input specifying "tcp\_keep\_alive=true". Experiencing recurring "closing due: java.net.SocketException: Connection reset" errors for this pipeline (var…

---

## [Force new field to type "keyword" or "text"](https://discuss.elastic.co/t/force-new-field-to-type-keyword-or-text/349665)

<div class="topic-metadata">

**Author:** [@yquirion](https://discuss.elastic.co/u/yquirion)\
**Replies:** 3\
**Last updated:** [January 12, 2024, 8:49pm UTC](https://discuss.elastic.co/t/force-new-field-to-type-keyword-or-text/349665 "2024-01-12T20:49:30Z")

</div>

Hello, I'm currently struggling with an annoying problem who lead to many lost logs into my Elastic cluster. The problem happen when a field that hasn't been defined into the default filebeat template is created. When …

---

## [Errors: reason\\":\\"Unrecognized compile-time parameter(s)](https://discuss.elastic.co/t/errors-reason-unrecognized-compile-time-parameter-s/350988)

<div class="topic-metadata">

**Author:** [@ElasticDev1](https://discuss.elastic.co/u/ElasticDev1)\
**Replies:** 0\
**Last updated:** [January 12, 2024, 8:28pm UTC](https://discuss.elastic.co/t/errors-reason-unrecognized-compile-time-parameter-s/350988 "2024-01-12T20:28:40Z")

</div>

I have written a scriptquery that should work but I keep getting this error "Unrecognized compile-time parameter(s)". I have even super simplified my script where I just "return true", and continue to get the same error…

---

## [Unable to start Logstash as a service. Errors with: Unable to locate required config /etc/logstash/logstash.conf](https://discuss.elastic.co/t/unable-to-start-logstash-as-a-service-errors-with-unable-to-locate-required-config-etc-logstash-logstash-conf/350938)

<div class="topic-metadata">

**Author:** [@Maiky](https://discuss.elastic.co/u/Maiky)\
**Replies:** 3\
**Last updated:** [January 12, 2024, 6:33pm UTC](https://discuss.elastic.co/t/unable-to-start-logstash-as-a-service-errors-with-unable-to-locate-required-config-etc-logstash-logstash-conf/350938 "2024-01-12T18:33:40Z")

</div>

Hi, On RHEL7 I'm able to run logstash v 7.17 directly as root like so: logstash -f /home/maiky/first-pipeline.conf --config.reload.automatic However when trying to run it as a service, I get the following error: Job …

---

## [Native SOAR in Elastic](https://discuss.elastic.co/t/native-soar-in-elastic/350977)

<div class="topic-metadata">

**Author:** [@blueoreo](https://discuss.elastic.co/u/blueoreo)\
**Replies:** 1\
**Last updated:** [January 12, 2024, 5:39pm UTC](https://discuss.elastic.co/t/native-soar-in-elastic/350977 "2024-01-12T17:39:24Z")

</div>

Hi Team, I wanted some help in clarifying the capabilities of Elastic Products. For native SOAR Capabilities, is it provided by Elastic Security? Additionally, what are the features of the native SOAR Platform? Thank…

---

## [Group results in visualization](https://discuss.elastic.co/t/group-results-in-visualization/350735)

<div class="topic-metadata">

**Author:** [@KaBergmanis](https://discuss.elastic.co/u/KaBergmanis)\
**Replies:** 5\
**Last updated:** [January 12, 2024, 5:31pm UTC](https://discuss.elastic.co/t/group-results-in-visualization/350735 "2024-01-12T17:31:05Z")

</div>

Hello! I've set up search that pulls out OS versions from VPN data feed. All working as expected. Then I created pie chart showing count of OS versions, again, so far so good, please see attached. Issue: There are mul…

---

## [Invalid UTF-8](https://discuss.elastic.co/t/invalid-utf-8/350978)

<div class="topic-metadata">

**Author:** [@cyberzlo](https://discuss.elastic.co/u/cyberzlo)\
**Replies:** 7\
**Last updated:** [January 12, 2024, 5:10pm UTC](https://discuss.elastic.co/t/invalid-utf-8/350978 "2024-01-12T17:10:44Z")

</div>

I've been using ruby to decode hex to ascii if (\[field\]) { mutate { gsub =\> \[ "\[field\]", ":", "" \] } ruby { code =\> 'event.set("\[field\]", \[event.get("\[field\]")\].pack("H\*"))' } } but I'v…

---

## [Is there a way to access old documentation search system?](https://discuss.elastic.co/t/is-there-a-way-to-access-old-documentation-search-system/350869)

<div class="topic-metadata">

**Author:** [@Incauto](https://discuss.elastic.co/u/Incauto)\
**Replies:** 2\
**Last updated:** [January 12, 2024, 4:56pm UTC](https://discuss.elastic.co/t/is-there-a-way-to-access-old-documentation-search-system/350869 "2024-01-12T16:56:13Z")

</div>

Just yesterday I was studing for a certifcation, and I was able to reach anything I want with just a couple of words and some filtering (version, documentation, plataform) but now I reach page 10 (got bored) in the searc…

---

## [Sum average](https://discuss.elastic.co/t/sum-average/350945)

<div class="topic-metadata">

**Author:** [@francieliton\_araujo](https://discuss.elastic.co/u/francieliton_araujo)\
**Replies:** 1\
**Last updated:** [January 12, 2024, 4:51pm UTC](https://discuss.elastic.co/t/sum-average/350945 "2024-01-12T16:51:24Z")

</div>

could you help me create a dashboard and a canvas, which first adds up to a group and then makes an average, dividing

---

## [Setting default number of replicas for new indexes?](https://discuss.elastic.co/t/setting-default-number-of-replicas-for-new-indexes/350835)

<div class="topic-metadata">

**Author:** [@emoxam](https://discuss.elastic.co/u/emoxam)\
**Replies:** 4\
**Last updated:** [January 12, 2024, 4:49pm UTC](https://discuss.elastic.co/t/setting-default-number-of-replicas-for-new-indexes/350835 "2024-01-12T16:49:49Z")

</div>

addidng index.number\_of\_replicas: 0 to /etc/elasticsearch/elasticsearch.yml doesn't work. With this option elasticsearch doesn't start. at the log i see fatal exception while booting Elasticsearch java.lang.IllegalArgu…

---

## [Time range based on timestamp in DSL query](https://discuss.elastic.co/t/time-range-based-on-timestamp-in-dsl-query/350962)

<div class="topic-metadata">

**Author:** [@LeCalve](https://discuss.elastic.co/u/LeCalve)\
**Replies:** 3\
**Last updated:** [January 12, 2024, 2:57pm UTC](https://discuss.elastic.co/t/time-range-based-on-timestamp-in-dsl-query/350962 "2024-01-12T14:57:31Z")

</div>

Hello, I want to make a filter based on the time of a timestamp. I would like to extract all timestamps which have a time \< 8 or time \> 20. I don't know how to make the DSL query for that :slight\_smile: {

---

## [Utilize serilog sinks to elastic search](https://discuss.elastic.co/t/utilize-serilog-sinks-to-elastic-search/350969)

<div class="topic-metadata">

**Author:** [@minh.tran](https://discuss.elastic.co/u/minh.tran)\
**Replies:** 0\
**Last updated:** [January 12, 2024, 2:36pm UTC](https://discuss.elastic.co/t/utilize-serilog-sinks-to-elastic-search/350969 "2024-01-12T14:36:01Z")

</div>

Hi there, we are currently using seirlog elastic sink. Details can be found here GitHub - serilog-contrib/serilog-sinks-elasticsearch: A Serilog sink that writes events to Elasticsearch Is there a way we can make the si…

---

## [Analysis is not available for this field](https://discuss.elastic.co/t/analysis-is-not-available-for-this-field/350965)

<div class="topic-metadata">

**Author:** [@cyberzlo](https://discuss.elastic.co/u/cyberzlo)\
**Replies:** 1\
**Last updated:** [January 12, 2024, 2:25pm UTC](https://discuss.elastic.co/t/analysis-is-not-available-for-this-field/350965 "2024-01-12T14:25:19Z")

</div>

Kibana for some fields that used to work now returns me a Analysis is not available for this field. message and they do not show up in Discover tables etc. It is also impossible to search using these fields such as field…

---

## [Facing issue in elasticsearch - /usr/share/elasticsearch/config/elasticsearch.keystore: Device or resource busy](https://discuss.elastic.co/t/facing-issue-in-elasticsearch-usr-share-elasticsearch-config-elasticsearch-keystore-device-or-resource-busy/350905)

<div class="topic-metadata">

**Author:** [@Akshay04](https://discuss.elastic.co/u/Akshay04)\
**Replies:** 1\
**Last updated:** [January 12, 2024, 2:23pm UTC](https://discuss.elastic.co/t/facing-issue-in-elasticsearch-usr-share-elasticsearch-config-elasticsearch-keystore-device-or-resource-busy/350905 "2024-01-12T14:23:49Z")

</div>

Hello, I'm trying to enable Google OAuth with Elasticsearch using - Set up OpenID Connect with Azure, Google, or Okta | Elasticsearch Service Documentation | Elastic I'm deploying this to Kubernetes and using Elastic …

---

## [Jenkins logstash plugin don't send build log](https://discuss.elastic.co/t/jenkins-logstash-plugin-dont-send-build-log/350967)

<div class="topic-metadata">

**Author:** [@khergner](https://discuss.elastic.co/u/khergner)\
**Replies:** 0\
**Last updated:** [January 12, 2024, 2:09pm UTC](https://discuss.elastic.co/t/jenkins-logstash-plugin-dont-send-build-log/350967 "2024-01-12T14:09:22Z")

</div>

Hi everyone I have a problem. ı want to use logstash plugin with jenkins. İt isn't send build log elasticsearch but ı have bellow error. I don't upgrade logstash latest plugin because many plugin must upgrade from jenk…

---

## [Custom logs from Logstash to Cloudwatch](https://discuss.elastic.co/t/custom-logs-from-logstash-to-cloudwatch/350955)

<div class="topic-metadata">

**Author:** [@Vadsgator](https://discuss.elastic.co/u/Vadsgator)\
**Replies:** 1\
**Last updated:** [January 12, 2024, 1:55pm UTC](https://discuss.elastic.co/t/custom-logs-from-logstash-to-cloudwatch/350955 "2024-01-12T13:55:28Z")

</div>

Hiya, Currently there is no actual support to send custom logs from Logstash to Cloudwatch. (There is a way to send metrics data using the Cloudwatch Output Plugin) and there was some support for a plugin called logstas…

---

## [Transfer indices to new cluster](https://discuss.elastic.co/t/transfer-indices-to-new-cluster/350946)

<div class="topic-metadata">

**Author:** [@JimJ](https://discuss.elastic.co/u/JimJ)\
**Replies:** 0\
**Last updated:** [January 12, 2024, 12:40pm UTC](https://discuss.elastic.co/t/transfer-indices-to-new-cluster/350946 "2024-01-12T12:40:19Z")

</div>

I put in place a new Elastic cluster v8.7 to replace an old one in v7.12. In Elastic cluster v8.7, I started using Datastreams. My question: what is the best way to transfer indices' data from old cluster to datastream…

---

## [System indexes stuck initializing state](https://discuss.elastic.co/t/system-indexes-stuck-initializing-state/350937)

<div class="topic-metadata">

**Author:** [@joao-subtil](https://discuss.elastic.co/u/joao-subtil)\
**Replies:** 0\
**Last updated:** [January 12, 2024, 11:24am UTC](https://discuss.elastic.co/t/system-indexes-stuck-initializing-state/350937 "2024-01-12T11:24:58Z")

</div>

Hello, I am using Elastic 8.11 and was attempting to setup a cluster with ilm for hot/warm/cold. However after creating the instance and roles and users I get the system indices stuck in initializing state and cannot m…

---

## [Very slow queries always take 1s](https://discuss.elastic.co/t/very-slow-queries-always-take-1s/350933)

<div class="topic-metadata">

**Author:** [@matthijs1](https://discuss.elastic.co/u/matthijs1)\
**Replies:** 0\
**Last updated:** [January 12, 2024, 11:02am UTC](https://discuss.elastic.co/t/very-slow-queries-always-take-1s/350933 "2024-01-12T11:02:06Z")

</div>

Hi All, I'm not that experienced in Elastic Search, but I have a problem and I'm out of ideas to try. In a test setup, I have a 3-node cluster running ES6.8.22 on windows. Until a windows reboot (for updates) 2 days a…

---

## [Silent failures with delete-by-query](https://discuss.elastic.co/t/silent-failures-with-delete-by-query/350925)

<div class="topic-metadata">

**Author:** [@mrodent](https://discuss.elastic.co/u/mrodent)\
**Replies:** 0\
**Last updated:** [January 12, 2024, 9:38am UTC](https://discuss.elastic.co/t/silent-failures-with-delete-by-query/350925 "2024-01-12T09:38:27Z")

</div>

I've examined all the questions on this subject. None seems to address the problem I'm having. I need to loop through doing multiple delete\_by\_queries. As I've set things up for experimenting, just a handful. The proble…

---

## [Curl XPOST not working after upgrading from Elastic v7 to Elastic v8](https://discuss.elastic.co/t/curl-xpost-not-working-after-upgrading-from-elastic-v7-to-elastic-v8/350706)

<div class="topic-metadata">

**Author:** [@zeninuxx](https://discuss.elastic.co/u/zeninuxx)\
**Replies:** 3\
**Last updated:** [January 12, 2024, 8:51am UTC](https://discuss.elastic.co/t/curl-xpost-not-working-after-upgrading-from-elastic-v7-to-elastic-v8/350706 "2024-01-12T08:51:00Z")

</div>

This is an example of a json file I am trying to POST into elasticsearch: {"index": {}} {"topic": "example1", "size": 2192, "timestamp": "2024-01-10"} {"index": {}} {"topic": "example2", "size": 2052, "timestamp": "2024…

---

## [Logstash input with beats function is not work good by OCP platform in ingress](https://discuss.elastic.co/t/logstash-input-with-beats-function-is-not-work-good-by-ocp-platform-in-ingress/350915)

<div class="topic-metadata">

**Author:** [@bigwind123](https://discuss.elastic.co/u/bigwind123)\
**Replies:** 0\
**Last updated:** [January 12, 2024, 7:47am UTC](https://discuss.elastic.co/t/logstash-input-with-beats-function-is-not-work-good-by-ocp-platform-in-ingress/350915 "2024-01-12T07:47:36Z")

</div>

I am currently facing a problem. I'm planning to set up an ELK service on a redhat ocp platform and install metricbeat on the VM to send the data to a logstash pod in ocp, I'm currently doing the following. a pod -\> e…

---

## [How to pause the logstash output temporarily](https://discuss.elastic.co/t/how-to-pause-the-logstash-output-temporarily/350841)

<div class="topic-metadata">

**Author:** [@jevonsnotes](https://discuss.elastic.co/u/jevonsnotes)\
**Replies:** 3\
**Last updated:** [January 12, 2024, 5:36am UTC](https://discuss.elastic.co/t/how-to-pause-the-logstash-output-temporarily/350841 "2024-01-12T05:36:49Z")

</div>

how to keep the logstash accept the input data but pause the output temporarily?

---

## [Elastic Agent failing to parse valid condition functions](https://discuss.elastic.co/t/elastic-agent-failing-to-parse-valid-condition-functions/349579)

<div class="topic-metadata">

**Author:** [@BenB196](https://discuss.elastic.co/u/BenB196)\
**Replies:** 8\
**Last updated:** [January 12, 2024, 1:34am UTC](https://discuss.elastic.co/t/elastic-agent-failing-to-parse-valid-condition-functions/349579 "2024-01-12T01:34:46Z")

</div>

Hi, I'm having an issue where if I try to run elastic-agent inspect with a policy that defines a condition with a function, I get an error, even if the function is valid. Elastic Agent 8.11.3 Example: Use the Kuberne…

---

## [Logstash TCP Input Codecs](https://discuss.elastic.co/t/logstash-tcp-input-codecs/350517)

<div class="topic-metadata">

**Author:** [@mgotechlock](https://discuss.elastic.co/u/mgotechlock)\
**Replies:** 10\
**Last updated:** [January 11, 2024, 11:09pm UTC](https://discuss.elastic.co/t/logstash-tcp-input-codecs/350517 "2024-01-11T23:09:15Z")

</div>

Is there a place to undestand exactly what format each of the TCP input codecs are meant to cover? (line vs json vs plain vs cef). I have a situation of a new log source (Sophos firewall). Must use TLS so syslog input i…

---

## [Collect values from elasticsearch/kibana](https://discuss.elastic.co/t/collect-values-from-elasticsearch-kibana/350886)

<div class="topic-metadata">

**Author:** [@cyberphantom](https://discuss.elastic.co/u/cyberphantom)\
**Replies:** 1\
**Last updated:** [January 11, 2024, 8:54pm UTC](https://discuss.elastic.co/t/collect-values-from-elasticsearch-kibana/350886 "2024-01-11T20:54:08Z")

</div>

Hello! I'm trying to retrieve specific values from my Elasticsearch/Kibana graphs to manipulate them in another environment. Initially, I thought I could achieve this using the Elasticsearch API, but being relatively ne…

---

## [Normalization or denormalization structure(Notification to multiple recipients - business logic)](https://discuss.elastic.co/t/normalization-or-denormalization-structure-notification-to-multiple-recipients-business-logic/350877)

<div class="topic-metadata">

**Author:** [@Behemo1h](https://discuss.elastic.co/u/Behemo1h)\
**Replies:** 0\
**Last updated:** [January 11, 2024, 6:09pm UTC](https://discuss.elastic.co/t/normalization-or-denormalization-structure-notification-to-multiple-recipients-business-logic/350877 "2024-01-11T18:09:27Z")

</div>

Hello all. I can't decide whether to "normalize" the data or not. I have notification datas in my app. When notification can be triggered for whole complay, user, or user in company. My current data looks like: Its o…

---

## [Index\_not\_found\_exception](https://discuss.elastic.co/t/index-not-found-exception/350736)

<div class="topic-metadata">

**Author:** [@e-ferrari](https://discuss.elastic.co/u/e-ferrari)\
**Replies:** 2\
**Last updated:** [January 11, 2024, 4:57pm UTC](https://discuss.elastic.co/t/index-not-found-exception/350736 "2024-01-11T16:57:55Z")

</div>

Hi, i'm following Parsing Logs with Logstash | Logstash Reference \[8.11\] | Elastic. When i try, as mentioned in the text curl -k -u elastic:xxxxxxxxxxxxxxxxxxxxx -XGET 'https://localhost:9200/2024.01.10/\_search?pretty&q…

---

## [Getting crazy with nnotes.dll](https://discuss.elastic.co/t/getting-crazy-with-nnotes-dll/349544)

<div class="topic-metadata">

**Author:** [@GKre](https://discuss.elastic.co/u/GKre)\
**Replies:** 8\
**Last updated:** [January 11, 2024, 3:41pm UTC](https://discuss.elastic.co/t/getting-crazy-with-nnotes-dll/349544 "2024-01-11T15:41:53Z")

</div>

Yes - i am using HCL Notes / Domino in release 12 and 14 (the newest one). Elastic Endpoint Security is driving me crazy as it is putting the file "nnotes.dll" into quartantain. I tested rule exception and endpoint exc…

---

## [Error: can not write type \[class java.time.LocalDate\] - Elasticsearch v8.10](https://discuss.elastic.co/t/error-can-not-write-type-class-java-time-localdate-elasticsearch-v8-10/350868)

<div class="topic-metadata">

**Author:** [@Abhishek](https://discuss.elastic.co/u/Abhishek)\
**Replies:** 0\
**Last updated:** [January 11, 2024, 2:39pm UTC](https://discuss.elastic.co/t/error-can-not-write-type-class-java-time-localdate-elasticsearch-v8-10/350868 "2024-01-11T14:39:34Z")

</div>

Hi Everyone, I have recently upgraded from es 5.6 to es 8.10. Following script field is working fine in es5.6 "script\_fields": { "customDate": { "script": { "inline": "def i ; if(params.\_source.cu…

[Previous page](https://discuss.elastic.co/tag/none.md?no_tags=true&page=244)

[Next page](https://discuss.elastic.co/tag/none.md?no_tags=true&page=246)
