# \#none

**URL:** https://discuss.elastic.co/tag/none.md?no_tags=true&page=256

[Latest](https://discuss.elastic.co/latest.md) · [Categories](https://discuss.elastic.co/categories.md) · [Tags](https://discuss.elastic.co/tags.md)

**Page:** 257

---

## [One logstash instance per kubernetes cluster](https://discuss.elastic.co/t/one-logstash-instance-per-kubernetes-cluster/349546)

<div class="topic-metadata">

**Author:** [@codedoings](https://discuss.elastic.co/u/codedoings)\
**Replies:** 0\
**Last updated:** [December 18, 2023, 10:11am UTC](https://discuss.elastic.co/t/one-logstash-instance-per-kubernetes-cluster/349546 "2023-12-18T10:11:01Z")

</div>

Hi, What would be the best approach for configuring logstash in an environment where: Elasticsearch and Kibana are running in their own kubernetes cluster (deployed with ECK). Elasticsearch and Kibana instance is shar…

---

## [Fleet server configurations for elk-apm setup in AKS cluster](https://discuss.elastic.co/t/fleet-server-configurations-for-elk-apm-setup-in-aks-cluster/349542)

<div class="topic-metadata">

**Author:** [@mahimakha](https://discuss.elastic.co/u/mahimakha)\
**Replies:** 2\
**Last updated:** [December 18, 2023, 9:49am UTC](https://discuss.elastic.co/t/fleet-server-configurations-for-elk-apm-setup-in-aks-cluster/349542 "2023-12-18T09:49:35Z")

</div>

Hi I am trying to configure the ELK-APM on AKS cluster. I have been following the documentation as per the given link Run Elastic Agent on Kubernetes managed by Fleet | Fleet and Elastic Agent Guide \[8.5\] | Elastic I a…

---

## [Upgrade from 7.17.14 to 8.11.3 failes](https://discuss.elastic.co/t/upgrade-from-7-17-14-to-8-11-3-failes/349538)

<div class="topic-metadata">

**Author:** [@Ingo\_Voland](https://discuss.elastic.co/u/Ingo_Voland)\
**Replies:** 1\
**Last updated:** [December 18, 2023, 9:39am UTC](https://discuss.elastic.co/t/upgrade-from-7-17-14-to-8-11-3-failes/349538 "2023-12-18T09:39:22Z")

</div>

We have a 1 node elastic installation (7.17.14), upgrading to 8.11.3 failes wiith the error message Caused by: org.elasticsearch.gateway.CorruptStateException: Format version is not supported. Upgrading to \[8.11.3\] is o…

---

## [Dec 18th, 2023: \[EN\] The most magical time of the year: Using semantic search to find the most festive Harry Potter moments](https://discuss.elastic.co/t/dec-18th-2023-en-the-most-magical-time-of-the-year-using-semantic-search-to-find-the-most-festive-harry-potter-moments/347615)

<div class="topic-metadata">

**Author:** [@iulia](https://discuss.elastic.co/u/iulia)\
**Replies:** 0\
**Last updated:** [December 18, 2023, 8:00am UTC](https://discuss.elastic.co/t/dec-18th-2023-en-the-most-magical-time-of-the-year-using-semantic-search-to-find-the-most-festive-harry-potter-moments/347615 "2023-12-18T08:00:30Z")

</div>

Christmas at Hogwarts, anyone? I don't know about you, but for me, Christmas usually means starting (yet another) Harry Potter marathon. While I'm a fan of the Wizarding World year-round, there is something extra fest…

---

## [Date time with time multifield](https://discuss.elastic.co/t/date-time-with-time-multifield/349513)

<div class="topic-metadata">

**Author:** [@RRGTHWAR1](https://discuss.elastic.co/u/RRGTHWAR1)\
**Replies:** 1\
**Last updated:** [December 18, 2023, 1:18am UTC](https://discuss.elastic.co/t/date-time-with-time-multifield/349513 "2023-12-18T01:18:58Z")

</div>

This has come up from time to time, but I haven’t seen any definitive answers. Is it possible to have a time-only multi-field in a date time field? For example, created\_date would be the full datetime, and created\_date.t…

---

## [Circuit breaker in Elasticsearch](https://discuss.elastic.co/t/circuit-breaker-in-elasticsearch/349508)

<div class="topic-metadata">

**Author:** [@pksinghal](https://discuss.elastic.co/u/pksinghal)\
**Replies:** 9\
**Last updated:** [December 17, 2023, 5:01pm UTC](https://discuss.elastic.co/t/circuit-breaker-in-elasticsearch/349508 "2023-12-17T17:01:15Z")

</div>

we are running an Elasticsearch cluster with 3 nodes. sometimes a heavy agg query comes(run manually from Kibana dev tools) and one of the nodes becomes inaccessible. So full cluster becomes inaccessible as ES takes so…

---

## [Best data structure for sensor data](https://discuss.elastic.co/t/best-data-structure-for-sensor-data/349497)

<div class="topic-metadata">

**Author:** [@allatrue](https://discuss.elastic.co/u/allatrue)\
**Replies:** 1\
**Last updated:** [December 17, 2023, 5:10pm UTC](https://discuss.elastic.co/t/best-data-structure-for-sensor-data/349497 "2023-12-17T17:10:18Z")

</div>

Hello everyone, We are setting up a cluster for collecting of IoT/sensor data. And I'm not sure what is the best structure for this kind of data. The simplest way would be to use single index for all similar (numeric) d…

---

## [Dec 17th, 2023: \[EN\] Elasticsearch geospatial; go beyond OpenSearch](https://discuss.elastic.co/t/dec-17th-2023-en-elasticsearch-geospatial-go-beyond-opensearch/345512)

<div class="topic-metadata">

**Author:** [@Nathan\_Reese](https://discuss.elastic.co/u/Nathan_Reese)\
**Replies:** 0\
**Last updated:** [December 17, 2023, 8:00am UTC](https://discuss.elastic.co/t/dec-17th-2023-en-elasticsearch-geospatial-go-beyond-opensearch/345512 "2023-12-17T08:00:10Z")

</div>

In 2021, OpenSearch and OpenSearch Dashboards began as a fork from Elasticsearch and Kibana. Although they share similar lineage, OpenSearch and OpenSearch Dashboards do not provide the same functionality. At the time…

---

## [Logstash ran as service won't read logs only when ran through the command line](https://discuss.elastic.co/t/logstash-ran-as-service-wont-read-logs-only-when-ran-through-the-command-line/349403)

<div class="topic-metadata">

**Author:** [@ELI\_MA](https://discuss.elastic.co/u/ELI_MA)\
**Replies:** 14\
**Last updated:** [December 17, 2023, 5:10am UTC](https://discuss.elastic.co/t/logstash-ran-as-service-wont-read-logs-only-when-ran-through-the-command-line/349403 "2023-12-17T05:10:27Z")

</div>

Hi, I’m running Logstash on SUSE Linux where I’ve installed the RPM package for compatibility. Currently, When I start logstash as a service sudo systemctl stop logstash.service and check service status it seems to be r…

---

## [Not able to search a specific log file in Kibana UI](https://discuss.elastic.co/t/not-able-to-search-a-specific-log-file-in-kibana-ui/347428)

<div class="topic-metadata">

**Author:** [@kaushalshriyan](https://discuss.elastic.co/u/kaushalshriyan)\
**Replies:** 3\
**Last updated:** [December 17, 2023, 5:02am UTC](https://discuss.elastic.co/t/not-able-to-search-a-specific-log-file-in-kibana-ui/347428 "2023-12-17T05:02:03Z")

</div>

Hi, I am running the Elastic Stack on Red Hat Enterprise Linux release 8.8 (Ootpa) and the versions are as below. # rpm -qa | grep logstash logstash-8.11.0-1.x86\_64 # rpm -qa | grep elasticsearch elasticsearch-8.11.0-1…

---

## [Elasticsearch upgrade assistant](https://discuss.elastic.co/t/elasticsearch-upgrade-assistant/349447)

<div class="topic-metadata">

**Author:** [@jaykb77](https://discuss.elastic.co/u/jaykb77)\
**Replies:** 2\
**Last updated:** [December 16, 2023, 11:26pm UTC](https://discuss.elastic.co/t/elasticsearch-upgrade-assistant/349447 "2023-12-16T23:26:59Z")

</div>

Hi all, We are trying to upgrade our Elasticsearch cluster from 7.17 to 8.X and found that its recommended to use Upgrade assistant for this. But we do not use Kibana in our cluster. The ES is acting as a search backend…

---

## [Dec 16th, 2023: \[PT\] Sinfonia da Eficiência: AIOps Orquestrando a Excelência Operacional](https://discuss.elastic.co/t/dec-16th-2023-pt-sinfonia-da-eficiencia-aiops-orquestrando-a-excelencia-operacional/347297)

<div class="topic-metadata">

**Author:** [@Priscilla\_Parodi](https://discuss.elastic.co/u/Priscilla_Parodi)\
**Replies:** 0\
**Last updated:** [December 16, 2023, 8:00am UTC](https://discuss.elastic.co/t/dec-16th-2023-pt-sinfonia-da-eficiencia-aiops-orquestrando-a-excelencia-operacional/347297 "2023-12-16T08:00:54Z")

</div>

This post is also available in english. Antes de explorarmos o AIOps, vamos esclarecer alguns conceitos-chave relacionados a alguns (não todos :sweat\_smile:) dos diferentes "Ops": DevOps: DEV + OPS Você provavelme…

---

## [Dec 16th, 2023: \[EN\] Symphony of Efficiency: AIOps Orchestrating Operational Excellence](https://discuss.elastic.co/t/dec-16th-2023-en-symphony-of-efficiency-aiops-orchestrating-operational-excellence/347295)

<div class="topic-metadata">

**Author:** [@Priscilla\_Parodi](https://discuss.elastic.co/u/Priscilla_Parodi)\
**Replies:** 0\
**Last updated:** [December 16, 2023, 8:00am UTC](https://discuss.elastic.co/t/dec-16th-2023-en-symphony-of-efficiency-aiops-orchestrating-operational-excellence/347295 "2023-12-16T08:00:54Z")

</div>

This post is also available in portuguese. Before we explore AIOps, let’s clarify some key concepts related to some \[not all :sweat\_smile:\] of the different Ops: DevOps: DEV + OPS You've probably already heard of …

---

## [Some fields are missing after rename.](https://discuss.elastic.co/t/some-fields-are-missing-after-rename/349459)

<div class="topic-metadata">

**Author:** [@JHub-Wei](https://discuss.elastic.co/u/JHub-Wei)\
**Replies:** 11\
**Last updated:** [December 16, 2023, 2:22am UTC](https://discuss.elastic.co/t/some-fields-are-missing-after-rename/349459 "2023-12-16T02:22:57Z")

</div>

After logstash-oss is upgraded from 7.6.0 to 7.12.1, some fields are lost after parsing the nested JSON data of Kafka. Kafka JSON example data: {"timestamp":1702630468791,"region":"cn-north-3","eventId":"QER\_INFO","args…

---

## [Plugin installation issue, probably related to YAML](https://discuss.elastic.co/t/plugin-installation-issue-probably-related-to-yaml/349404)

<div class="topic-metadata">

**Author:** [@jediD83](https://discuss.elastic.co/u/jediD83)\
**Replies:** 4\
**Last updated:** [December 15, 2023, 10:38pm UTC](https://discuss.elastic.co/t/plugin-installation-issue-probably-related-to-yaml/349404 "2023-12-15T22:38:05Z")

</div>

Good day. The installation of the Elasticsearch's plugin for Zammad should be straightforward. After apt install elasticsearch using Set up Elasticsearch guide, its just sudo /usr/share/elasticsearch/bin/elasticsearch-p…

---

## [What could be the cause of error ""](https://discuss.elastic.co/t/what-could-be-the-cause-of-error/349436)

<div class="topic-metadata">

**Author:** [@Chen\_Wei](https://discuss.elastic.co/u/Chen_Wei)\
**Replies:** 1\
**Last updated:** [December 15, 2023, 7:07pm UTC](https://discuss.elastic.co/t/what-could-be-the-cause-of-error/349436 "2023-12-15T19:07:29Z")

</div>

I recently met a error about timestamp, the error appears after the logstash pipeline start and work for a while. I could not reproduce it. But I wonder where the error could happen. Does it happen in the input plugin?…

---

## [Kibana / Remplacement d'une valeur en fonction de deux autres pour une variable](https://discuss.elastic.co/t/kibana-remplacement-dune-valeur-en-fonction-de-deux-autres-pour-une-variable/349471)

<div class="topic-metadata">

**Author:** [@Phildefer](https://discuss.elastic.co/u/Phildefer)\
**Replies:** 4\
**Last updated:** [December 15, 2023, 7:19pm UTC](https://discuss.elastic.co/t/kibana-remplacement-dune-valeur-en-fonction-de-deux-autres-pour-une-variable/349471 "2023-12-15T19:19:38Z")

</div>

Bonjour, J'ai dans un index deux variables X et Y qui contiennent des valeurs textuelles (A ou B ou C ou D). Je souhaiterais faire en sorte que lorsqu'un document a pour valeur A ou B dans les variables X ou Y, cette va…

---

## [Drop complete row or message](https://discuss.elastic.co/t/drop-complete-row-or-message/349415)

<div class="topic-metadata">

**Author:** [@kundan](https://discuss.elastic.co/u/kundan)\
**Replies:** 1\
**Last updated:** [December 15, 2023, 7:08pm UTC](https://discuss.elastic.co/t/drop-complete-row-or-message/349415 "2023-12-15T19:08:38Z")

</div>

Hi, I want to drop full row based on one of the field. I am using following in filter. filter { grok { match =\> {"message" =\> \["%{IP:ip} %{SPACE}\\{user:%{USERNAME:UserId}\\}"\]} } date…

---

## [Logstash 8.10.3 ERROR Badly formatted index, after interpolation still contains placeholder](https://discuss.elastic.co/t/logstash-8-10-3-error-badly-formatted-index-after-interpolation-still-contains-placeholder/349377)

<div class="topic-metadata">

**Author:** [@efrainMZ](https://discuss.elastic.co/u/efrainMZ)\
**Replies:** 5\
**Last updated:** [December 15, 2023, 4:33pm UTC](https://discuss.elastic.co/t/logstash-8-10-3-error-badly-formatted-index-after-interpolation-still-contains-placeholder/349377 "2023-12-15T16:33:43Z")

</div>

good day! I am trying to extract data from redis using logstash, the data comes from an apm version 8.10.3 but I receive a warining that does not allow me to see the data in kibana. The log I receive is the following: …

---

## [Implementing Custom BERT-Based Text Embedding Model for Semantic Search in Elasticsearch](https://discuss.elastic.co/t/implementing-custom-bert-based-text-embedding-model-for-semantic-search-in-elasticsearch/349434)

<div class="topic-metadata">

**Author:** [@Ali\_Zare](https://discuss.elastic.co/u/Ali_Zare)\
**Replies:** 1\
**Last updated:** [December 15, 2023, 4:10pm UTC](https://discuss.elastic.co/t/implementing-custom-bert-based-text-embedding-model-for-semantic-search-in-elasticsearch/349434 "2023-12-15T16:10:22Z")

</div>

Hello everyone, I'm exploring the possibility of setting up a custom text embedding model using the BERT architecture for semantic search within Elasticsearch. I'm curious if it's feasible to integrate a personalized te…

---

## [File sharing between multiple logstash instance](https://discuss.elastic.co/t/file-sharing-between-multiple-logstash-instance/349445)

<div class="topic-metadata">

**Author:** [@kishan\_vadalia](https://discuss.elastic.co/u/kishan_vadalia)\
**Replies:** 1\
**Last updated:** [December 15, 2023, 2:49pm UTC](https://discuss.elastic.co/t/file-sharing-between-multiple-logstash-instance/349445 "2023-12-15T14:49:47Z")

</div>

I have 3 logstash instance running on same machine and putting data to same ES index. all 3 are reading file input from same location (/etc/logstash/conf.d). If there are 500 files in that location than on ES index numbe…

---

## [Issue with Date Formatting in Transform Script on Elasticsearch 8.6.1](https://discuss.elastic.co/t/issue-with-date-formatting-in-transform-script-on-elasticsearch-8-6-1/349463)

<div class="topic-metadata">

**Author:** [@Behnam.R](https://discuss.elastic.co/u/Behnam.R)\
**Replies:** 0\
**Last updated:** [December 15, 2023, 2:49pm UTC](https://discuss.elastic.co/t/issue-with-date-formatting-in-transform-script-on-elasticsearch-8-6-1/349463 "2023-12-15T14:49:39Z")

</div>

Hello, I'm encountering an issue with date formatting in a transform script on Elasticsearch 8.6.1 (licensed version). My goal is to pivot existing index and store the date as it is. However, the output in the transform…

---

## [Kibana doesn't work due to change ip](https://discuss.elastic.co/t/kibana-doesnt-work-due-to-change-ip/349282)

<div class="topic-metadata">

**Author:** [@Gabin\_17](https://discuss.elastic.co/u/Gabin_17)\
**Replies:** 13\
**Last updated:** [December 15, 2023, 2:47pm UTC](https://discuss.elastic.co/t/kibana-doesnt-work-due-to-change-ip/349282 "2023-12-15T14:47:39Z")

</div>

Hi Guys, I need your help ! I installed ELK few days ago, however, my Ip has changed and now i canno't reach the Kibana page. It's write " Kibana server is not ready yet". What's the process to fix it ? I guess, I have…

---

## [Metricbeat hostPath alternative](https://discuss.elastic.co/t/metricbeat-hostpath-alternative/349457)

<div class="topic-metadata">

**Author:** [@Jame\_M](https://discuss.elastic.co/u/Jame_M)\
**Replies:** 0\
**Last updated:** [December 15, 2023, 1:56pm UTC](https://discuss.elastic.co/t/metricbeat-hostpath-alternative/349457 "2023-12-15T13:56:53Z")

</div>

Hello all, I have a quick question. I am installing Metricbeat into a K8s cluster. I do not have rights to it, and we are simply adding a feature for monitering the cluster. And this is on a remote intranet sever so I c…

---

## [License is not available](https://discuss.elastic.co/t/license-is-not-available/349449)

<div class="topic-metadata">

**Author:** [@secsec](https://discuss.elastic.co/u/secsec)\
**Replies:** 2\
**Last updated:** [December 15, 2023, 1:55pm UTC](https://discuss.elastic.co/t/license-is-not-available/349449 "2023-12-15T13:55:28Z")

</div>

Hello im using ELK 8.11 version, only one node and under tail -f /var/log/syslog | grep license i can see this so many problems with licence (im using basic): Dec 15 12:37:03 SPTWS-ELK-NODE01 metricbeat\[607\]: {"log.l…

---

## [I Want to remove the duplicate events inside Logstash filter how could I do that? I mention the events below please have a look and suggest](https://discuss.elastic.co/t/i-want-to-remove-the-duplicate-events-inside-logstash-filter-how-could-i-do-that-i-mention-the-events-below-please-have-a-look-and-suggest/349175)

<div class="topic-metadata">

**Author:** [@Subrato1](https://discuss.elastic.co/u/Subrato1)\
**Replies:** 6\
**Last updated:** [December 15, 2023, 1:35pm UTC](https://discuss.elastic.co/t/i-want-to-remove-the-duplicate-events-inside-logstash-filter-how-could-i-do-that-i-mention-the-events-below-please-have-a-look-and-suggest/349175 "2023-12-15T13:35:00Z")

</div>

{ "date" =\> 2023-12-12T00:00:00.000Z, "category" =\> "AUTH", "username" =\> "cassandra", "event\_time" =\> "ab390a7b-98e7-11ee-af20-4b75abbb029d", "node" =\> "172.31.57.239",…

---

## [Fatal exception while booting Elasticsearchorg.elasticsearch.ElasticsearchSecurityException: failed to load SSL configuration \[xpack.security.transport.ssl\] - cannot read configured \[PKCS12\] keystore](https://discuss.elastic.co/t/fatal-exception-while-booting-elasticsearchorg-elasticsearch-elasticsearchsecurityexception-failed-to-load-ssl-configuration-xpack-security-transport-ssl-cannot-read-configured-pkcs12-keystore/349427)

<div class="topic-metadata">

**Author:** [@9631](https://discuss.elastic.co/u/9631)\
**Replies:** 7\
**Last updated:** [December 15, 2023, 10:58am UTC](https://discuss.elastic.co/t/fatal-exception-while-booting-elasticsearchorg-elasticsearch-elasticsearchsecurityexception-failed-to-load-ssl-configuration-xpack-security-transport-ssl-cannot-read-configured-pkcs12-keystore/349427 "2023-12-15T10:58:50Z")

</div>

\[2023-12-15T12:36:37,084\]\[ERROR\]\[o.e.b.Elasticsearch \] \[LAPTOP-ECGDD83N\] fatal exception while booting Elasticsearchorg.elasticsearch.ElasticsearchSecurityException: failed to load SSL configuration \[xpack.security.…

---

## [How bad is it for Elasticsearch peformance to use external disk storage?](https://discuss.elastic.co/t/how-bad-is-it-for-elasticsearch-peformance-to-use-external-disk-storage/349442)

<div class="topic-metadata">

**Author:** [@mtovmassian](https://discuss.elastic.co/u/mtovmassian)\
**Replies:** 0\
**Last updated:** [December 15, 2023, 9:36am UTC](https://discuss.elastic.co/t/how-bad-is-it-for-elasticsearch-peformance-to-use-external-disk-storage/349442 "2023-12-15T09:36:45Z")

</div>

I am currently running a small cluster of 3 nodes with a size (shards considered) of =~ 200GB. But disk usage keeps increasing and hard drives are about to reach saturation. I know that Elasticsearch need to be as clo…

---

## [Dec 15th, 2023: \[EN\] Mapping Christmas places with Elasticsearch and MapLibre](https://discuss.elastic.co/t/dec-15th-2023-en-mapping-christmas-places-with-elasticsearch-and-maplibre/346727)

<div class="topic-metadata">

**Author:** [@jsanz](https://discuss.elastic.co/u/jsanz)\
**Replies:** 0\
**Last updated:** [December 15, 2023, 8:00am UTC](https://discuss.elastic.co/t/dec-15th-2023-en-mapping-christmas-places-with-elasticsearch-and-maplibre/346727 "2023-12-15T08:00:37Z")

</div>

This post is also available in Spanish Introduction One of the most well-known security practices is to never expose your Elasticsearch cluster to the Internet. But we are in the Christmas season, and we like to be f…

---

## [How to specify a default value for my field in grok pattern match](https://discuss.elastic.co/t/how-to-specify-a-default-value-for-my-field-in-grok-pattern-match/349310)

<div class="topic-metadata">

**Author:** [@ameeto17](https://discuss.elastic.co/u/ameeto17)\
**Replies:** 9\
**Last updated:** [December 15, 2023, 5:53am UTC](https://discuss.elastic.co/t/how-to-specify-a-default-value-for-my-field-in-grok-pattern-match/349310 "2023-12-15T05:53:26Z")

</div>

I have a pattern to match using GROK Dec 14 03:13:01 ppddc1kfep302 my-checker: Context SHA of VSP Logger Software da39a3ee5e6b4b0d3255bfef95601890afd80709 I have the format below for the match %{SYSLOGTIMESTAMP}%{SPAC…

[Previous page](https://discuss.elastic.co/tag/none.md?no_tags=true&page=255)

[Next page](https://discuss.elastic.co/tag/none.md?no_tags=true&page=257)
