# \#none

**URL:** https://discuss.elastic.co/tag/none.md?no_tags=true&page=255

[Latest](https://discuss.elastic.co/latest.md) · [Categories](https://discuss.elastic.co/categories.md) · [Tags](https://discuss.elastic.co/tags.md)

**Page:** 256

---

## [Allowing long query to complete even if indexes are shriking](https://discuss.elastic.co/t/allowing-long-query-to-complete-even-if-indexes-are-shriking/349273)

<div class="topic-metadata">

**Author:** [@DidierB](https://discuss.elastic.co/u/DidierB)\
**Replies:** 4\
**Last updated:** [December 19, 2023, 5:14pm UTC](https://discuss.elastic.co/t/allowing-long-query-to-complete-even-if-indexes-are-shriking/349273 "2023-12-19T17:14:40Z")

</div>

Hello, I have a use case with up to two billions events a day that are injected into an Elasticsearch. I opimized by making one index per hour (4 primary shards with 1 replica per shard) and setting a index lifecycle po…

---

## [Elastic Agent Cisco ASA integration - timestamp issue](https://discuss.elastic.co/t/elastic-agent-cisco-asa-integration-timestamp-issue/349646)

<div class="topic-metadata">

**Author:** [@vuylstekeb](https://discuss.elastic.co/u/vuylstekeb)\
**Replies:** 5\
**Last updated:** [December 19, 2023, 5:01pm UTC](https://discuss.elastic.co/t/elastic-agent-cisco-asa-integration-timestamp-issue/349646 "2023-12-19T17:01:35Z")

</div>

Hi I've recently started experimenting with Elastic Agent integrations. I've added one for Cisco ASA logs. The problem I'm facing is that my data is coming in with wrong timestamps. The data gets added into the indice wi…

---

## [Failed to submit a listener notification task. Event loop shut down? java.util.concurrent.RejectedExecutionException: event executor terminated](https://discuss.elastic.co/t/failed-to-submit-a-listener-notification-task-event-loop-shut-down-java-util-concurrent-rejectedexecutionexception-event-executor-terminated/349623)

<div class="topic-metadata">

**Author:** [@Kelvin\_A\_Escobar\_Mor](https://discuss.elastic.co/u/Kelvin_A_Escobar_Mor)\
**Replies:** 2\
**Last updated:** [December 19, 2023, 4:28pm UTC](https://discuss.elastic.co/t/failed-to-submit-a-listener-notification-task-event-loop-shut-down-java-util-concurrent-rejectedexecutionexception-event-executor-terminated/349623 "2023-12-19T16:28:51Z")

</div>

Failed to submit a listener notification task. Event loop shut down? java.util.concurrent.RejectedExecutionException: event executor terminated at io.netty.util.concurrent.SingleThreadEventExecutor.reject(SingleThreadE…

---

## [Unstable operation of elasticsearch](https://discuss.elastic.co/t/unstable-operation-of-elasticsearch/345931)

<div class="topic-metadata">

**Author:** [@San9](https://discuss.elastic.co/u/San9)\
**Replies:** 19\
**Last updated:** [December 19, 2023, 2:14pm UTC](https://discuss.elastic.co/t/unstable-operation-of-elasticsearch/345931 "2023-12-19T14:14:15Z")

</div>

Hi Team! Recently I began to notice unstable operation of Logstash, I started looking at the logs (I have two Logstash nodes). Here is an example of logs: Oct 27 07:01:17 v-elk-lst01.my logstash\[42023\]: \[2023-10-27T07:…

---

## [Dec 19th, 2023: \[EN\] Kibana Lens Color Mapping & Color Palettes](https://discuss.elastic.co/t/dec-19th-2023-en-kibana-lens-color-mapping-color-palettes/347298)

<div class="topic-metadata">

**Author:** [@markov00](https://discuss.elastic.co/u/markov00)\
**Replies:** 0\
**Last updated:** [December 19, 2023, 8:00am UTC](https://discuss.elastic.co/t/dec-19th-2023-en-kibana-lens-color-mapping-color-palettes/347298 "2023-12-19T08:00:07Z")

</div>

Written by @Giovanni\_Magni and @markov00 The possibility to customize colors in charts simply and intuitively has been a feature requested for a long time. Given its complexity, it required some time to fully underst…

---

## [Create an alert set at specific time of the day](https://discuss.elastic.co/t/create-an-alert-set-at-specific-time-of-the-day/337280)

<div class="topic-metadata">

**Author:** [@Gio\_27](https://discuss.elastic.co/u/Gio_27)\
**Replies:** 1\
**Last updated:** [December 19, 2023, 1:06pm UTC](https://discuss.elastic.co/t/create-an-alert-set-at-specific-time-of-the-day/337280 "2023-12-19T13:06:25Z")

</div>

Goodmorning y'all! I'm finding myself in front of a issue which regards the timestamp field. The idea is to create an alert which would trigger whenever an admin user (or a user with particular access privileges) log o…

---

## [I configure rsyslog for my linux server now I want to send logs to LOGSTASH. How could I achieve that](https://discuss.elastic.co/t/i-configure-rsyslog-for-my-linux-server-now-i-want-to-send-logs-to-logstash-how-could-i-achieve-that/349566)

<div class="topic-metadata">

**Author:** [@Subrato1](https://discuss.elastic.co/u/Subrato1)\
**Replies:** 4\
**Last updated:** [December 19, 2023, 12:52pm UTC](https://discuss.elastic.co/t/i-configure-rsyslog-for-my-linux-server-now-i-want-to-send-logs-to-logstash-how-could-i-achieve-that/349566 "2023-12-19T12:52:08Z")

</div>

Below is my rsyslog conf. My audit logs are generating in syslogs only.

---

## [Logstash split log base on space and =](https://discuss.elastic.co/t/logstash-split-log-base-on-space-and/348526)

<div class="topic-metadata">

**Author:** [@sahere37](https://discuss.elastic.co/u/sahere37)\
**Replies:** 2\
**Last updated:** [December 19, 2023, 11:51am UTC](https://discuss.elastic.co/t/logstash-split-log-base-on-space-and/348526 "2023-12-19T11:51:39Z")

</div>

I want to separate below log in Logstash, I know that we can do it by grok filter, but is there any way to do it without grok? Log: date=2023-12-04 time=11:26:01 my\_id=5646875 dir="D" type=ML severety=info mtype="my lo…

---

## [Discovery-EC2 - master not discovered yet, this node has not previously joined a bootstrapped cluster, and \[cluster.initial\_master\_nodes\] is empty on this node: have discovered](https://discuss.elastic.co/t/discovery-ec2-master-not-discovered-yet-this-node-has-not-previously-joined-a-bootstrapped-cluster-and-cluster-initial-master-nodes-is-empty-on-this-node-have-discovered/349493)

<div class="topic-metadata">

**Author:** [@lakshmikandan](https://discuss.elastic.co/u/lakshmikandan)\
**Replies:** 4\
**Last updated:** [December 19, 2023, 10:15am UTC](https://discuss.elastic.co/t/discovery-ec2-master-not-discovered-yet-this-node-has-not-previously-joined-a-bootstrapped-cluster-and-cluster-initial-master-nodes-is-empty-on-this-node-have-discovered/349493 "2023-12-19T10:15:30Z")

</div>

Version: 8.11.0, Build: rpm/d9ec3fa628c7b0ba3d25692e277ba26814820b20/2023-11-04T10:04:57.184859352Z, JVM: 21.0.1 \[WARN \]\[o.e.c.c.ClusterFormationFailureHelper\] \[ip-10-10-10-1.us-west-2.compute.internal\] master not disco…

---

## [Elasticsearch deployment with 5 nodes](https://discuss.elastic.co/t/elasticsearch-deployment-with-5-nodes/349639)

<div class="topic-metadata">

**Author:** [@vapetri](https://discuss.elastic.co/u/vapetri)\
**Replies:** 0\
**Last updated:** [December 19, 2023, 9:39am UTC](https://discuss.elastic.co/t/elasticsearch-deployment-with-5-nodes/349639 "2023-12-19T09:39:19Z")

</div>

Hi, i am trying to deploy a test elasticsearch cluster on a 5 worker nodes kubernetes cluster. I am using 2 storage classes, one for data and for snapshot repositories as below. --- apiVersion: elasticsearch.k8s.elasti…

---

## [Can I use PHP Elasitcsearch client version 8 for Elasticsearch cluster version 7](https://discuss.elastic.co/t/can-i-use-php-elasitcsearch-client-version-8-for-elasticsearch-cluster-version-7/349631)

<div class="topic-metadata">

**Author:** [@yoss\_fazwaz](https://discuss.elastic.co/u/yoss_fazwaz)\
**Replies:** 0\
**Last updated:** [December 19, 2023, 8:04am UTC](https://discuss.elastic.co/t/can-i-use-php-elasitcsearch-client-version-8-for-elasticsearch-cluster-version-7/349631 "2023-12-19T08:04:43Z")

</div>

I am currently using Elasticsearch cluster version 7.17.7 and Elasticsearch client version 7.17.1. However, I want to upgrade the Elasticsearch client to version 8.11. Will Elasticsearch client version 8.11 function pro…

---

## [\[2023-12-19T02:08:38,809\]\[ERROR\]\[i.n.u.c.D.rejectedExecution\] \[data\_node4\] Failed to submit a listener notification task. Event loop shut down? java.util.concurrent.RejectedExecutionException: event executor terminated](https://discuss.elastic.co/t/2023-12-19t0238-809-error-i-n-u-c-d-rejectedexecution-data-node4-failed-to-submit-a-listener-notification-task-event-loop-shut-down-java-util-concurrent-rejectedexecutionexception-event-executor-terminated/349620)

<div class="topic-metadata">

**Author:** [@Kelvin\_A\_Escobar\_Mor](https://discuss.elastic.co/u/Kelvin_A_Escobar_Mor)\
**Replies:** 0\
**Last updated:** [December 19, 2023, 6:15am UTC](https://discuss.elastic.co/t/2023-12-19t0238-809-error-i-n-u-c-d-rejectedexecution-data-node4-failed-to-submit-a-listener-notification-task-event-loop-shut-down-java-util-concurrent-rejectedexecutionexception-event-executor-terminated/349620 "2023-12-19T06:15:39Z")

</div>

\[2023-12-19T02:08:38,809\]\[ERROR\]\[i.n.u.c.D.rejectedExecution\] \[data\_node4\] Failed to submit a listener notification task. Event loop shut down? java.util.concurrent.RejectedExecutionException: event executor terminated …

---

## [How to mock handlers for elastic search client v8.11.0](https://discuss.elastic.co/t/how-to-mock-handlers-for-elastic-search-client-v8-11-0/349614)

<div class="topic-metadata">

**Author:** [@yoss\_fazwaz](https://discuss.elastic.co/u/yoss_fazwaz)\
**Replies:** 1\
**Last updated:** [December 19, 2023, 5:30am UTC](https://discuss.elastic.co/t/how-to-mock-handlers-for-elastic-search-client-v8-11-0/349614 "2023-12-19T05:30:56Z")

</div>

Hi, guys, I have updated my Elasticsearch client from V7 to V8, and it seems that the setHandler is removed. I have no idea how to set it in version 8.

---

## [Dissect in logstash and tabs](https://discuss.elastic.co/t/dissect-in-logstash-and-tabs/349595)

<div class="topic-metadata">

**Author:** [@astateofmind](https://discuss.elastic.co/u/astateofmind)\
**Replies:** 3\
**Last updated:** [December 19, 2023, 2:29am UTC](https://discuss.elastic.co/t/dissect-in-logstash-and-tabs/349595 "2023-12-19T02:29:56Z")

</div>

Trying to use dissect to add log.level field to some beats. Using filebeat to send the data and some logs have their fields separated by tabs instead of spaces. The logs with space work ok with this filter: "%{} %{log…

---

## [Elasticsearch Input on Logstash](https://discuss.elastic.co/t/elasticsearch-input-on-logstash/349609)

<div class="topic-metadata">

**Author:** [@Leonadius](https://discuss.elastic.co/u/Leonadius)\
**Replies:** 0\
**Last updated:** [December 19, 2023, 3:04am UTC](https://discuss.elastic.co/t/elasticsearch-input-on-logstash/349609 "2023-12-19T03:04:23Z")

</div>

Dear Elastic Team, I have a case where i need to sync all of the documents from 1 index to another elastic cluster with near real-time. I'm thinking using logstash elasticsearch input to read all of the documents conti…

---

## [Validation Failed: 1: this action would add \[8\] total shards, but this cluster currently has \[3997\]/\[4000\] maximum shards open](https://discuss.elastic.co/t/validation-failed-1-this-action-would-add-8-total-shards-but-this-cluster-currently-has-3997-4000-maximum-shards-open/349527)

<div class="topic-metadata">

**Author:** [@HyebinHong](https://discuss.elastic.co/u/HyebinHong)\
**Replies:** 5\
**Last updated:** [December 18, 2023, 11:12pm UTC](https://discuss.elastic.co/t/validation-failed-1-this-action-would-add-8-total-shards-but-this-cluster-currently-has-3997-4000-maximum-shards-open/349527 "2023-12-18T23:12:26Z")

</div>

Hello, Elastic! I'm facing the trouble while indexing data. I run both ES 8.11 and OpenSearch 2.11 but both have same issues. Please help me. I found out my shards had reached the maximum(1000 shards per nodes). My da…

---

## [Secure ELK Stack with cloudflare wildcard SSL Failing on an ubuntu setup](https://discuss.elastic.co/t/secure-elk-stack-with-cloudflare-wildcard-ssl-failing-on-an-ubuntu-setup/349597)

<div class="topic-metadata">

**Author:** [@gurungo\_lovemore](https://discuss.elastic.co/u/gurungo_lovemore)\
**Replies:** 0\
**Last updated:** [December 18, 2023, 8:58pm UTC](https://discuss.elastic.co/t/secure-elk-stack-with-cloudflare-wildcard-ssl-failing-on-an-ubuntu-setup/349597 "2023-12-18T20:58:57Z")

</div>

I have a cloudflare wildcard ssl for my organization that i have configured on my elasticsearch and Kibana as follows: ''''''''' Elasticsearch # Enable security features xpack.security.enabled: true xpack.security.en…

---

## [Keystore for secrets in elastic-agent.yml](https://discuss.elastic.co/t/keystore-for-secrets-in-elastic-agent-yml/349525)

<div class="topic-metadata">

**Author:** [@learningelastic](https://discuss.elastic.co/u/learningelastic)\
**Replies:** 9\
**Last updated:** [December 18, 2023, 10:59pm UTC](https://discuss.elastic.co/t/keystore-for-secrets-in-elastic-agent-yml/349525 "2023-12-18T22:59:58Z")

</div>

I have some secret values in my ./elastic-agent.yml file. I was hoping to use a keystore to help manage those secrets. I tried this command ./elastic-agent keystore add outputs.default.password, but it gave the error E…

---

## [ES 8.8.2 high query latency](https://discuss.elastic.co/t/es-8-8-2-high-query-latency/349191)

<div class="topic-metadata">

**Author:** [@darshanypatel](https://discuss.elastic.co/u/darshanypatel)\
**Replies:** 3\
**Last updated:** [December 18, 2023, 10:19pm UTC](https://discuss.elastic.co/t/es-8-8-2-high-query-latency/349191 "2023-12-18T22:19:42Z")

</div>

I am encountering degraded query latency in v8. We are upgrading our cluster from 7.16.2 to 8.8.2 by standing up a new duplicate cluster with the new version and reindexing the data to it. The latency is 500ms to several…

---

## [Elasticsearch Query Multiple Must Nots](https://discuss.elastic.co/t/elasticsearch-query-multiple-must-nots/349570)

<div class="topic-metadata">

**Author:** [@Elk\_huh](https://discuss.elastic.co/u/Elk_huh)\
**Replies:** 7\
**Last updated:** [December 18, 2023, 7:28pm UTC](https://discuss.elastic.co/t/elasticsearch-query-multiple-must-nots/349570 "2023-12-18T19:28:37Z")

</div>

Is it possible to have 2 different must not query strings across two different fields I have this but it doesnt let me have 2 query strings GET winevents/\_search { "query": { "bool": { "must": \[ { …

---

## [Rules failing](https://discuss.elastic.co/t/rules-failing/349470)

<div class="topic-metadata">

**Author:** [@bbreer](https://discuss.elastic.co/u/bbreer)\
**Replies:** 2\
**Last updated:** [December 18, 2023, 7:25pm UTC](https://discuss.elastic.co/t/rules-failing/349470 "2023-12-18T19:25:17Z")

</div>

Hi, I have several rules that come back as Failed after running. I'm getting the following error for many rules. The field names for the unknown column message varies among the different rules. An error occurred during…

---

## [OIDC without TLS](https://discuss.elastic.co/t/oidc-without-tls/349580)

<div class="topic-metadata">

**Author:** [@Jo\_han](https://discuss.elastic.co/u/Jo_han)\
**Replies:** 0\
**Last updated:** [December 18, 2023, 4:39pm UTC](https://discuss.elastic.co/t/oidc-without-tls/349580 "2023-12-18T16:39:01Z")

</div>

Hello, I am deploying ECK in an on-premise Kubernetes cluster with Istio installed. We drew a security perimeter at our gateway. Meaning all the services are only reachable through the gateway, where TLS and authentica…

---

## [Massive performance degradation when terms filter has over 16 values?](https://discuss.elastic.co/t/massive-performance-degradation-when-terms-filter-has-over-16-values/349106)

<div class="topic-metadata">

**Author:** [@elastic\_dude](https://discuss.elastic.co/u/elastic_dude)\
**Replies:** 9\
**Last updated:** [December 18, 2023, 4:19pm UTC](https://discuss.elastic.co/t/massive-performance-degradation-when-terms-filter-has-over-16-values/349106 "2023-12-18T16:19:50Z")

</div>

Came across some odd behavior. We have a query that performs in the tens of milliseconds until we go over 16 values in our terms filter. When 17 or more are included the performance degrades by 15-20 multiples. Here is …

---

## [Index template - settings](https://discuss.elastic.co/t/index-template-settings/349568)

<div class="topic-metadata">

**Author:** [@zaeemmasood](https://discuss.elastic.co/u/zaeemmasood)\
**Replies:** 0\
**Last updated:** [December 18, 2023, 2:56pm UTC](https://discuss.elastic.co/t/index-template-settings/349568 "2023-12-18T14:56:12Z")

</div>

Hi All, I set up ILM for a particular index pattern. After applying this when I check index settings I see the following output: GET abc-90010-2023.12.18/\_settings { "abc-90010-2023.12.18": { "settings": { …

---

## [Help needed for certificate configuration](https://discuss.elastic.co/t/help-needed-for-certificate-configuration/349194)

<div class="topic-metadata">

**Author:** [@litronics](https://discuss.elastic.co/u/litronics)\
**Replies:** 13\
**Last updated:** [December 18, 2023, 2:14pm UTC](https://discuss.elastic.co/t/help-needed-for-certificate-configuration/349194 "2023-12-18T14:14:11Z")

</div>

Elasticsearch drives me nuts when it comes to certificates and how they are used / configured. This is my current configuration: ## Cluster Settings cluster.name: "elk-tls-cluster" node.name: node-1 network.host: "0.0.…

---

## [Manually execute ILM policy](https://discuss.elastic.co/t/manually-execute-ilm-policy/349560)

<div class="topic-metadata">

**Author:** [@rschirin](https://discuss.elastic.co/u/rschirin)\
**Replies:** 1\
**Last updated:** [December 18, 2023, 1:44pm UTC](https://discuss.elastic.co/t/manually-execute-ilm-policy/349560 "2023-12-18T13:44:59Z")

</div>

Hey there, is there a way to manually execute an ILMm policy? If I modify the mapping template for example, I would like to immediately create and use a new updated index, avoiding to wait for example date threshold or …

---

## [Elastic service stops unexpectedly](https://discuss.elastic.co/t/elastic-service-stops-unexpectedly/349555)

<div class="topic-metadata">

**Author:** [@mreddy9](https://discuss.elastic.co/u/mreddy9)\
**Replies:** 0\
**Last updated:** [December 18, 2023, 12:35pm UTC](https://discuss.elastic.co/t/elastic-service-stops-unexpectedly/349555 "2023-12-18T12:35:51Z")

</div>

Hi all, Sometime Elasticsearch service stops unexpectedly in the weekend and there are no details in logs to identify the exact issue. Please suggest any solution if you already come across this issue in past. log deta…

---

## [Kibana discover show wrong result when filter by date type field](https://discuss.elastic.co/t/kibana-discover-show-wrong-result-when-filter-by-date-type-field/349316)

<div class="topic-metadata">

**Author:** [@bbhhhh](https://discuss.elastic.co/u/bbhhhh)\
**Replies:** 3\
**Last updated:** [December 18, 2023, 12:08pm UTC](https://discuss.elastic.co/t/kibana-discover-show-wrong-result-when-filter-by-date-type-field/349316 "2023-12-18T12:08:01Z")

</div>

I created an index template 'order-index-template' which defined a date type mapping: ... "index\_patterns": \[ "order-index" \], "mappings": { "properties": { "orderTime": { "type": "date" …

---

## [Logstash error Cpu.cfs\_period\_us cannot be found](https://discuss.elastic.co/t/logstash-error-cpu-cfs-period-us-cannot-be-found/349515)

<div class="topic-metadata">

**Author:** [@Lena\_Yoon](https://discuss.elastic.co/u/Lena_Yoon)\
**Replies:** 9\
**Last updated:** [December 18, 2023, 11:43am UTC](https://discuss.elastic.co/t/logstash-error-cpu-cfs-period-us-cannot-be-found/349515 "2023-12-18T11:43:11Z")

</div>

Hello, I have been working with Logstash this week but stuck with below error. The error occurs when retrieving data from Oracle DB using the JDBC input plugin, filtering it in the pipeline, and despite the index being…

---

## [Merge two buckets muli\_level inside buckets](https://discuss.elastic.co/t/merge-two-buckets-muli-level-inside-buckets/349547)

<div class="topic-metadata">

**Author:** [@Azizi\_BESSEM](https://discuss.elastic.co/u/Azizi_BESSEM)\
**Replies:** 0\
**Last updated:** [December 18, 2023, 10:14am UTC](https://discuss.elastic.co/t/merge-two-buckets-muli-level-inside-buckets/349547 "2023-12-18T10:14:55Z")

</div>

{ "aggregations" : { "alert\_types" : { "doc\_count\_error\_upper\_bound" : 0, "sum\_other\_doc\_count" : 0, "buckets" : \[ { "key" : "1", "doc\_count" : 3, "device\_ref…

[Previous page](https://discuss.elastic.co/tag/none.md?no_tags=true&page=254)

[Next page](https://discuss.elastic.co/tag/none.md?no_tags=true&page=256)
