# \#none

**URL:** https://discuss.elastic.co/tag/none.md?no_tags=true&page=246

[Latest](https://discuss.elastic.co/latest.md) · [Categories](https://discuss.elastic.co/categories.md) · [Tags](https://discuss.elastic.co/tags.md)

**Page:** 247

---

## [Think Like a Relevance Engineer for Elasticsearch with on-demand self-led training](https://discuss.elastic.co/t/think-like-a-relevance-engineer-for-elasticsearch-with-on-demand-self-led-training/350866)

<div class="topic-metadata">

**Author:** [@flaxsearch](https://discuss.elastic.co/u/flaxsearch)\
**Replies:** 0\
**Last updated:** [January 11, 2024, 2:09pm UTC](https://discuss.elastic.co/t/think-like-a-relevance-engineer-for-elasticsearch-with-on-demand-self-led-training/350866 "2024-01-11T14:09:54Z")

</div>

I'm very pleased to announce that OSC's flagship trainings, inspired by the book Relevant Search and which have been taken by hundreds of relevance engineers worldwide, are now available on demand as self-led courses. If…

---

## [What is the recommended memory:data ratio for a cold zone?](https://discuss.elastic.co/t/what-is-the-recommended-memory-data-ratio-for-a-cold-zone/349755)

<div class="topic-metadata">

**Author:** [@calin](https://discuss.elastic.co/u/calin)\
**Replies:** 8\
**Last updated:** [January 11, 2024, 1:31pm UTC](https://discuss.elastic.co/t/what-is-the-recommended-memory-data-ratio-for-a-cold-zone/349755 "2024-01-11T13:31:48Z")

</div>

I see for the hot zone it's 30. For a warm zone it's 160. I haven't seen a value for cold zone. And how exactly is that calculated ? Thank you.

---

## [Windows two Node Cluster stuck on tring to determine master](https://discuss.elastic.co/t/windows-two-node-cluster-stuck-on-tring-to-determine-master/350691)

<div class="topic-metadata">

**Author:** [@bytelink](https://discuss.elastic.co/u/bytelink)\
**Replies:** 11\
**Last updated:** [January 11, 2024, 1:28pm UTC](https://discuss.elastic.co/t/windows-two-node-cluster-stuck-on-tring-to-determine-master/350691 "2024-01-11T13:28:07Z")

</div>

I have been trying to install a new two node cluster on two windows servers and no matter what I have tried I get a situation where the two nodes do not seem to be able to determine which should be the master. I have tr…

---

## [How do I configure auditbeat to show on elastic all the users of the servers and what activities they did on the server](https://discuss.elastic.co/t/how-do-i-configure-auditbeat-to-show-on-elastic-all-the-users-of-the-servers-and-what-activities-they-did-on-the-server/350856)

<div class="topic-metadata">

**Author:** [@Emilia\_Kullutwe](https://discuss.elastic.co/u/Emilia_Kullutwe)\
**Replies:** 0\
**Last updated:** [January 11, 2024, 12:40pm UTC](https://discuss.elastic.co/t/how-do-i-configure-auditbeat-to-show-on-elastic-all-the-users-of-the-servers-and-what-activities-they-did-on-the-server/350856 "2024-01-11T12:40:00Z")

</div>

I want to know the usernames of all the users who have access to particular server, I also want to know what activities they did on the server. How do I configure auditbeat to show all this on elastic. I am using Elasti…

---

## [Update jsonString with UpdateRequest through new java client\[8+ version\]](https://discuss.elastic.co/t/update-jsonstring-with-updaterequest-through-new-java-client-8-version/350855)

<div class="topic-metadata">

**Author:** [@pankaj\_sen](https://discuss.elastic.co/u/pankaj_sen)\
**Replies:** 0\
**Last updated:** [January 11, 2024, 12:31pm UTC](https://discuss.elastic.co/t/update-jsonstring-with-updaterequest-through-new-java-client-8-version/350855 "2024-01-11T12:31:47Z")

</div>

Getting below error while trying to update json string through update request. \[x\_content\_parse\_exception\] \[1:8\] \[UpdateRequest\] doc doesn't support values of type: VALUE\_STRING Below is my code snnipt client.update(g…

---

## [Kibana server is not ready yet](https://discuss.elastic.co/t/kibana-server-is-not-ready-yet/350771)

<div class="topic-metadata">

**Author:** [@boubou](https://discuss.elastic.co/u/boubou)\
**Replies:** 1\
**Last updated:** [January 11, 2024, 11:50am UTC](https://discuss.elastic.co/t/kibana-server-is-not-ready-yet/350771 "2024-01-11T11:50:39Z")

</div>

I am trying to set up an ELK stack with communication between Kibana and Elasticsearch. I am new to ELK and I am having trouble. I will present my configurations and the results that I am getting. To start, I downloaded…

---

## [Kibana will not connect to elasticsearch](https://discuss.elastic.co/t/kibana-will-not-connect-to-elasticsearch/350773)

<div class="topic-metadata">

**Author:** [@Scott\_Barker](https://discuss.elastic.co/u/Scott_Barker)\
**Replies:** 1\
**Last updated:** [January 11, 2024, 11:34am UTC](https://discuss.elastic.co/t/kibana-will-not-connect-to-elasticsearch/350773 "2024-01-11T11:34:14Z")

</div>

When I connect via a web browser I get the error ‘Kibana server is not ready’ I’ve configured elastic with Windows certificates, I can connect to the elk cluster OK that looks OK. https://elkcluster9200/\_cluster/health …

---

## [Logstash date parse issue with date filter using csv file input plugin](https://discuss.elastic.co/t/logstash-date-parse-issue-with-date-filter-using-csv-file-input-plugin/350850)

<div class="topic-metadata">

**Author:** [@jgregory\_tc](https://discuss.elastic.co/u/jgregory_tc)\
**Replies:** 0\
**Last updated:** [January 11, 2024, 11:23am UTC](https://discuss.elastic.co/t/logstash-date-parse-issue-with-date-filter-using-csv-file-input-plugin/350850 "2024-01-11T11:23:30Z")

</div>

Hoping someone can assist me with my issue below: I have Logstash conf setup to use the csv input plugin. The data inputs a date field with value like follows… 2024-01-09 22:21:04 I then have this logic in the filter …

---

## [Elastic Unstable](https://discuss.elastic.co/t/elastic-unstable/350593)

<div class="topic-metadata">

**Author:** [@Dea\_Agra](https://discuss.elastic.co/u/Dea_Agra)\
**Replies:** 16\
**Last updated:** [January 11, 2024, 10:38am UTC](https://discuss.elastic.co/t/elastic-unstable/350593 "2024-01-11T10:38:34Z")

</div>

Hi Team Elastic, I have been stressful latelty because my logs are coming to Elasticsearch delay for about 10 hours. I have 3 nodes, Node 1: master, ingest, transform, resource: 16vCPU, 16GB, 500GB Node 2: data\_hot, …

---

## [Elasticsearch doesn't work!](https://discuss.elastic.co/t/elasticsearch-doesnt-work/350842)

<div class="topic-metadata">

**Author:** [@boubou](https://discuss.elastic.co/u/boubou)\
**Replies:** 1\
**Last updated:** [January 11, 2024, 10:28am UTC](https://discuss.elastic.co/t/elasticsearch-doesnt-work/350842 "2024-01-11T10:28:20Z")

</div>

I am having difficulties using Elasticsearch. I am on Linux and I have installed Elasticsearch 8.2. I have modified my elasticsearch.yml and here is what it contains: cluster.name: elasticsearch-prod node.name: myserve…

---

## [Need help deciding how to partition data](https://discuss.elastic.co/t/need-help-deciding-how-to-partition-data/350837)

<div class="topic-metadata">

**Author:** [@favoca](https://discuss.elastic.co/u/favoca)\
**Replies:** 1\
**Last updated:** [January 11, 2024, 8:44am UTC](https://discuss.elastic.co/t/need-help-deciding-how-to-partition-data/350837 "2024-01-11T08:44:05Z")

</div>

The document in my RDMS has a schema similar to this: { PatientId: "string", Date: "date", IsAvailable: "bool", \_hospitalId: "6-digit number which can be a number or a string" } The \_hospitalId acts like a partition ke…

---

## [Visualization - matching on a condition](https://discuss.elastic.co/t/visualization-matching-on-a-condition/350795)

<div class="topic-metadata">

**Author:** [@radio\_1](https://discuss.elastic.co/u/radio_1)\
**Replies:** 1\
**Last updated:** [January 11, 2024, 12:42am UTC](https://discuss.elastic.co/t/visualization-matching-on-a-condition/350795 "2024-01-11T00:42:24Z")

</div>

Hi - very new to Kibana and visualizations. I have a number of hosts reporting a bunch of objects, each containing a field with a "yes" or "no" value. I'm trying to create a visualization with timestamp on the H-axis a…

---

## [Kibana security roles access control](https://discuss.elastic.co/t/kibana-security-roles-access-control/350614)

<div class="topic-metadata">

**Author:** [@mst3r25](https://discuss.elastic.co/u/mst3r25)\
**Replies:** 3\
**Last updated:** [January 10, 2024, 10:05pm UTC](https://discuss.elastic.co/t/kibana-security-roles-access-control/350614 "2024-01-10T22:05:41Z")

</div>

My ELK stack stop respecting roles and role mapping. Anyone with a vaild cert can access any Space or index even if they don'tt have that role assigned to them. I upgrade to version 8.11.2 from 8.8.1 last month, but I a …

---

## [I have error in logstash](https://discuss.elastic.co/t/i-have-error-in-logstash/350790)

<div class="topic-metadata">

**Author:** [@ahmedtamawe](https://discuss.elastic.co/u/ahmedtamawe)\
**Replies:** 1\
**Last updated:** [January 10, 2024, 8:50pm UTC](https://discuss.elastic.co/t/i-have-error-in-logstash/350790 "2024-01-10T20:50:34Z")

</div>

i have this error and want to solve it

---

## [Logs received from panorama](https://discuss.elastic.co/t/logs-received-from-panorama/350785)

<div class="topic-metadata">

**Author:** [@juancamiloll](https://discuss.elastic.co/u/juancamiloll)\
**Replies:** 2\
**Last updated:** [January 10, 2024, 8:41pm UTC](https://discuss.elastic.co/t/logs-received-from-panorama/350785 "2024-01-10T20:41:25Z")

</div>

Hello everyone, Normally when I do the ELK installation I ask the firewall administrators to send the logs via port 514 TPC to the server I administer. In the server what I do is that I modify the rsyslog.com file to o…

---

## [Elastic search 8.7.1 cluster is not forming, Here is yml: and command to create a token run on CENTOS7](https://discuss.elastic.co/t/elastic-search-8-7-1-cluster-is-not-forming-here-is-yml-and-command-to-create-a-token-run-on-centos7/350613)

<div class="topic-metadata">

**Author:** [@Varinder](https://discuss.elastic.co/u/Varinder)\
**Replies:** 9\
**Last updated:** [January 10, 2024, 7:10pm UTC](https://discuss.elastic.co/t/elastic-search-8-7-1-cluster-is-not-forming-here-is-yml-and-command-to-create-a-token-run-on-centos7/350613 "2024-01-10T19:10:56Z")

</div>

path.data: /var/lib/elasticsearch path.logs: /var/log/elasticsearch xpack.security.enabled: false xpack.security.enrollment.enabled: true xpack.security.http.ssl: enabled: false keystore.path: certs/http.p12 xpack…

---

## [How to extract the time stamp from](https://discuss.elastic.co/t/how-to-extract-the-time-stamp-from/348741)

<div class="topic-metadata">

**Author:** [@pero](https://discuss.elastic.co/u/pero)\
**Replies:** 20\
**Last updated:** [January 10, 2024, 5:24pm UTC](https://discuss.elastic.co/t/how-to-extract-the-time-stamp-from/348741 "2024-01-10T17:24:43Z")

</div>

Hi All, Please I need help on how to extract the timestamp from "type=SYSCALL msg=audit(1701877882.123:5786893): " in the below code using grok filter { "\_index": "auditbeat-2023.12.06", "\_type": "\_doc", "\_id": "…

---

## [Creating Mappings for Index Interconnections in ElasticSearch: How to Establish Relationships Between Tables?](https://discuss.elastic.co/t/creating-mappings-for-index-interconnections-in-elasticsearch-how-to-establish-relationships-between-tables/350751)

<div class="topic-metadata">

**Author:** [@Neelesh\_Gupta](https://discuss.elastic.co/u/Neelesh_Gupta)\
**Replies:** 1\
**Last updated:** [January 10, 2024, 5:12pm UTC](https://discuss.elastic.co/t/creating-mappings-for-index-interconnections-in-elasticsearch-how-to-establish-relationships-between-tables/350751 "2024-01-10T17:12:53Z")

</div>

I've uploaded 10 CSV tables to Elasticsearch to create a Kibana dashboard. However, since these tables are interlinked with foreign keys, they have been transformed into JSON (NoSQL) format. I'm now looking for guidance …

---

## [Nagios Log Server: Cannot login](https://discuss.elastic.co/t/nagios-log-server-cannot-login/350780)

<div class="topic-metadata">

**Author:** [@riahc3](https://discuss.elastic.co/u/riahc3)\
**Replies:** 0\
**Last updated:** [January 10, 2024, 5:04pm UTC](https://discuss.elastic.co/t/nagios-log-server-cannot-login/350780 "2024-01-10T17:04:38Z")

</div>

Hello Im using Nagios Log Server (which is ELK) and the issue Im having is that when I point the data directory to a NFS share, it says invalid username or password. Doesnt matter if I even reset it, it says the same th…

---

## [Elastic Agents Sending Large Amounts of Data](https://discuss.elastic.co/t/elastic-agents-sending-large-amounts-of-data/350413)

<div class="topic-metadata">

**Author:** [@sourcreamnormanbates](https://discuss.elastic.co/u/sourcreamnormanbates)\
**Replies:** 5\
**Last updated:** [January 10, 2024, 3:37pm UTC](https://discuss.elastic.co/t/elastic-agents-sending-large-amounts-of-data/350413 "2024-01-10T15:37:34Z")

</div>

Some of my agents are sending 1GB of data every hour. They are all laptops and desktops with a basic setup. Would they do that if the elasticsearch destination they are sending data to is down?

---

## [Elastic for Aerospace Data](https://discuss.elastic.co/t/elastic-for-aerospace-data/350732)

<div class="topic-metadata">

**Author:** [@Samuele\_Lolli](https://discuss.elastic.co/u/Samuele_Lolli)\
**Replies:** 1\
**Last updated:** [January 10, 2024, 2:09pm UTC](https://discuss.elastic.co/t/elastic-for-aerospace-data/350732 "2024-01-10T14:09:27Z")

</div>

Hi everyone, im currently working in a project about aerospace and im considering ELK to store data and do some basic data visualization. The data are GPS coordinate, gyro data, speeds and stuff like that. Anyone have…

---

## [Enterprise-search.yml configuration](https://discuss.elastic.co/t/enterprise-search-yml-configuration/350757)

<div class="topic-metadata">

**Author:** [@awccu](https://discuss.elastic.co/u/awccu)\
**Replies:** 0\
**Last updated:** [January 10, 2024, 2:02pm UTC](https://discuss.elastic.co/t/enterprise-search-yml-configuration/350757 "2024-01-10T14:02:12Z")

</div>

I am having trouble configuring the enterprise-search.yml. Specifically, it is unclear to me how to proceed with configuring enterprise search when the ssl method of configuring the elasticsearch cluster and the kibana w…

---

## [Create a report showing the count of different services calling an end point:](https://discuss.elastic.co/t/create-a-report-showing-the-count-of-different-services-calling-an-end-point/350745)

<div class="topic-metadata">

**Author:** [@Laredo\_Tirnanic](https://discuss.elastic.co/u/Laredo_Tirnanic)\
**Replies:** 0\
**Last updated:** [January 10, 2024, 12:31pm UTC](https://discuss.elastic.co/t/create-a-report-showing-the-count-of-different-services-calling-an-end-point/350745 "2024-01-10T12:31:27Z")

</div>

Hi, I'd appreciate some help/guidance with the following scenario: Let's say I have a Login service with an endpoint called /login. This endpoint gets called by Service A and Service B. I'm suddenly noticing that /logi…

---

## [How Could I send my logs from One EC2 instance to Other EC2 instance](https://discuss.elastic.co/t/how-could-i-send-my-logs-from-one-ec2-instance-to-other-ec2-instance/350724)

<div class="topic-metadata">

**Author:** [@Subrato1](https://discuss.elastic.co/u/Subrato1)\
**Replies:** 0\
**Last updated:** [January 10, 2024, 9:59am UTC](https://discuss.elastic.co/t/how-could-i-send-my-logs-from-one-ec2-instance-to-other-ec2-instance/350724 "2024-01-10T09:59:55Z")

</div>

I configured two EC2 instance. In one instance I have Logstash and from other instance I want to send audit logs to Logstash. I am using SYSLOG input plugin to collect the events. input { syslog { port =\> 5…

---

## [Elasticsearch Cluster Disk Write Performance](https://discuss.elastic.co/t/elasticsearch-cluster-disk-write-performance/350711)

<div class="topic-metadata">

**Author:** [@sheng855174](https://discuss.elastic.co/u/sheng855174)\
**Replies:** 1\
**Last updated:** [January 10, 2024, 9:22am UTC](https://discuss.elastic.co/t/elasticsearch-cluster-disk-write-performance/350711 "2024-01-10T09:22:16Z")

</div>

Hello everyone, I have an ELK cluster and encountered performance problems, which caused most data to be written 10 minutes slower than the actual time. This problem occurs occasionally. I want to know the cause of thi…

---

## [Fuziness not working when querying in larger index](https://discuss.elastic.co/t/fuziness-not-working-when-querying-in-larger-index/350503)

<div class="topic-metadata">

**Author:** [@SriramOnGrid](https://discuss.elastic.co/u/SriramOnGrid)\
**Replies:** 5\
**Last updated:** [January 10, 2024, 8:49am UTC](https://discuss.elastic.co/t/fuziness-not-working-when-querying-in-larger-index/350503 "2024-01-10T08:49:44Z")

</div>

Hi team, I wanted to fuziness for the purpose of finding the words with minor spelling mistakes. The query I am using is { "query": { "bool": { "must": \[ { "match": { "respon…

---

## [Updating Elasticsearch Indices conditionally when referring to 2 database table](https://discuss.elastic.co/t/updating-elasticsearch-indices-conditionally-when-referring-to-2-database-table/350663)

<div class="topic-metadata">

**Author:** [@jainesh\_singh](https://discuss.elastic.co/u/jainesh_singh)\
**Replies:** 1\
**Last updated:** [January 10, 2024, 6:45am UTC](https://discuss.elastic.co/t/updating-elasticsearch-indices-conditionally-when-referring-to-2-database-table/350663 "2024-01-10T06:45:37Z")

</div>

Description: We have two SQL tables: FileDetail for storing file details and FileUserActivity for file activities. Using Logstash, we're indexing data into Elasticsearch with a flat index approach, combining file detail…

---

## [Remove Parent fields in logstash filter](https://discuss.elastic.co/t/remove-parent-fields-in-logstash-filter/350646)

<div class="topic-metadata">

**Author:** [@Priyanka\_chauhan](https://discuss.elastic.co/u/Priyanka_chauhan)\
**Replies:** 5\
**Last updated:** [January 10, 2024, 6:45am UTC](https://discuss.elastic.co/t/remove-parent-fields-in-logstash-filter/350646 "2024-01-10T06:45:26Z")

</div>

I have large log json message which I have to parse to visualize at kibana. I have used json filter first to parse message but there are generated lots of parent and dynamic fields. Due to dynamic fields in each log me…

---

## [Kibana : How to search a value in JSON field](https://discuss.elastic.co/t/kibana-how-to-search-a-value-in-json-field/350321)

<div class="topic-metadata">

**Author:** [@Aziza\_AJOUAOU](https://discuss.elastic.co/u/Aziza_AJOUAOU)\
**Replies:** 8\
**Last updated:** [January 9, 2024, 6:00pm UTC](https://discuss.elastic.co/t/kibana-how-to-search-a-value-in-json-field/350321 "2024-01-09T18:00:38Z")

</div>

Hello .I would like to searck in kibana all documents that contains this specific value Y100000005 . So , i tried in search bar : But Kibana dosen't return Any document! I have in kibana the document below (it con…

---

## [Load Balance Output to both hot nodes](https://discuss.elastic.co/t/load-balance-output-to-both-hot-nodes/350415)

<div class="topic-metadata">

**Author:** [@sourcreamnormanbates](https://discuss.elastic.co/u/sourcreamnormanbates)\
**Replies:** 13\
**Last updated:** [January 9, 2024, 5:53pm UTC](https://discuss.elastic.co/t/load-balance-output-to-both-hot-nodes/350415 "2024-01-09T17:53:30Z")

</div>

I have two hot nodes in my cluster. I currently just have on node in the Outputs. Can I just add the 2nd node to the list of outputs?

[Previous page](https://discuss.elastic.co/tag/none.md?no_tags=true&page=245)

[Next page](https://discuss.elastic.co/tag/none.md?no_tags=true&page=247)
