# \#none

**URL:** https://discuss.elastic.co/tag/none.md?no_tags=true&page=258

[Latest](https://discuss.elastic.co/latest.md) · [Categories](https://discuss.elastic.co/categories.md) · [Tags](https://discuss.elastic.co/tags.md)

**Page:** 259

---

## [Dec 13th, 2023: \[FR\] 10 raisons pour demander elasticsearch-py 8.x au père Noël](https://discuss.elastic.co/t/dec-13th-2023-fr-10-raisons-pour-demander-elasticsearch-py-8-x-au-pere-noel/347293)

<div class="topic-metadata">

**Author:** [@Quentin\_Pradet](https://discuss.elastic.co/u/Quentin_Pradet)\
**Replies:** 0\
**Last updated:** [December 13, 2023, 8:00am UTC](https://discuss.elastic.co/t/dec-13th-2023-fr-10-raisons-pour-demander-elasticsearch-py-8-x-au-pere-noel/347293 "2023-12-13T08:00:29Z")

</div>

This post is available in english. En février 2022, lors de la sortie d'Elasticsearch 8.0, le client Python a également été mis à jour en version 8.0. Il s'agissait d'une réécriture partielle du client 7.x, accompagn…

---

## [Dec 13th, 2023: \[EN\] 10 reasons to upgrade to elasticsearch-py 8.x](https://discuss.elastic.co/t/dec-13th-2023-en-10-reasons-to-upgrade-to-elasticsearch-py-8-x/347292)

<div class="topic-metadata">

**Author:** [@Quentin\_Pradet](https://discuss.elastic.co/u/Quentin_Pradet)\
**Replies:** 0\
**Last updated:** [December 13, 2023, 8:00am UTC](https://discuss.elastic.co/t/dec-13th-2023-en-10-reasons-to-upgrade-to-elasticsearch-py-8-x/347292 "2023-12-13T08:00:29Z")

</div>

Cet article est disponible en français. Back in February 2022, when Elasticsearch 8.0 was released, the Python client also got an 8.0 release. It was a partial rewrite of the 7.x client, and came with a bunch of nice…

---

## [Could not add the UUID fingerprint in producer on logstash](https://discuss.elastic.co/t/could-not-add-the-uuid-fingerprint-in-producer-on-logstash/349227)

<div class="topic-metadata">

**Author:** [@pradeep.kumar](https://discuss.elastic.co/u/pradeep.kumar)\
**Replies:** 1\
**Last updated:** [December 13, 2023, 5:40pm UTC](https://discuss.elastic.co/t/could-not-add-the-uuid-fingerprint-in-producer-on-logstash/349227 "2023-12-13T17:40:34Z")

</div>

Hi Team, Im adding the fingerprint of method UUID to avoid the duplication of the data. Im using kafka as producer and Elasticsearch as consumer. Example pipeline conf looks like this input { kafka {…

---

## [Correlating/Matching data from 2 sources with diferent field types](https://discuss.elastic.co/t/correlating-matching-data-from-2-sources-with-diferent-field-types/349218)

<div class="topic-metadata">

**Author:** [@erni23](https://discuss.elastic.co/u/erni23)\
**Replies:** 2\
**Last updated:** [December 13, 2023, 5:17pm UTC](https://discuss.elastic.co/t/correlating-matching-data-from-2-sources-with-diferent-field-types/349218 "2023-12-13T17:17:55Z")

</div>

This is the scenario and I am using elastic 7.17; •Data source 1: VPN Network traffic data ingested with the usual fields (event.outcome: "success" and event.action: "login” etc (JSON) And •Data source 2: Logs from do…

---

## [Elastic SNMP - Best Practices?](https://discuss.elastic.co/t/elastic-snmp-best-practices/349285)

<div class="topic-metadata">

**Author:** [@erikg](https://discuss.elastic.co/u/erikg)\
**Replies:** 0\
**Last updated:** [December 13, 2023, 5:07pm UTC](https://discuss.elastic.co/t/elastic-snmp-best-practices/349285 "2023-12-13T17:07:47Z")

</div>

Continuing the discussion from Possability to use ELK-Stack for SNMP Monitoring like PRTG, CheckMK: Hello, It would be nice to hear how more people are using Elastic's SNMP (Logstash Input plugin) with a large number o…

---

## [Would dividing the same resources over more nodes improve performance?](https://discuss.elastic.co/t/would-dividing-the-same-resources-over-more-nodes-improve-performance/349264)

<div class="topic-metadata">

**Author:** [@calin](https://discuss.elastic.co/u/calin)\
**Replies:** 5\
**Last updated:** [December 13, 2023, 4:40pm UTC](https://discuss.elastic.co/t/would-dividing-the-same-resources-over-more-nodes-improve-performance/349264 "2023-12-13T16:40:46Z")

</div>

A load test seems to show that resources (CPU, RAM) on the data nodes aren't fully used. Would spreading the same resources over more data nodes help performance ?

---

## [Security not allowing me to install integration app](https://discuss.elastic.co/t/security-not-allowing-me-to-install-integration-app/349280)

<div class="topic-metadata">

**Author:** [@droidus](https://discuss.elastic.co/u/droidus)\
**Replies:** 0\
**Last updated:** [December 13, 2023, 3:12pm UTC](https://discuss.elastic.co/t/security-not-allowing-me-to-install-integration-app/349280 "2023-12-13T15:12:07Z")

</div>

I have a new install, and I went to add this app, and got this message. I followed the instructions in the listed guide, and even restarted the stack, to no avail. I get this same message.

---

## [Kibana drilldown on lens metrics doesn't work](https://discuss.elastic.co/t/kibana-drilldown-on-lens-metrics-doesnt-work/348698)

<div class="topic-metadata">

**Author:** [@Prakash\_Gupta](https://discuss.elastic.co/u/Prakash_Gupta)\
**Replies:** 5\
**Last updated:** [December 13, 2023, 3:10pm UTC](https://discuss.elastic.co/t/kibana-drilldown-on-lens-metrics-doesnt-work/348698 "2023-12-13T15:10:52Z")

</div>

I am trying to add a dashboard drill for a lens metrics. It let's me add the dashboard link but the visualization is not clickable. I am using Kibana 8.10 version. Could someone tell me if I am missing some setting or th…

---

## [\[eck-stack\] Unable to gather kubernetes logs via agent while passing ELASTICSEARCH\_CA to agent](https://discuss.elastic.co/t/eck-stack-unable-to-gather-kubernetes-logs-via-agent-while-passing-elasticsearch-ca-to-agent/349198)

<div class="topic-metadata">

**Author:** [@sevaho](https://discuss.elastic.co/u/sevaho)\
**Replies:** 1\
**Last updated:** [December 13, 2023, 2:59pm UTC](https://discuss.elastic.co/t/eck-stack-unable-to-gather-kubernetes-logs-via-agent-while-passing-elasticsearch-ca-to-agent/349198 "2023-12-13T14:59:53Z")

</div>

Hello everyone, Hope you're all doing well! I've been diving into setting up Elasticsearch on Kubernetes, and it's been quite the journey. I've been at it for the past two weeks, with my main goal being to seamlessly fe…

---

## [KIbana having (filtering groups)](https://discuss.elastic.co/t/kibana-having-filtering-groups/349142)

<div class="topic-metadata">

**Author:** [@chenchen40](https://discuss.elastic.co/u/chenchen40)\
**Replies:** 1\
**Last updated:** [December 13, 2023, 1:25pm UTC](https://discuss.elastic.co/t/kibana-having-filtering-groups/349142 "2023-12-13T13:25:44Z")

</div>

Hi guys, using 8.6, i can't find option to filter out groups with values i don't want to show. What do i miss?

---

## [Is the precision of cardinality aggregation decided by total unique value count or filtered unique value count?](https://discuss.elastic.co/t/is-the-precision-of-cardinality-aggregation-decided-by-total-unique-value-count-or-filtered-unique-value-count/349073)

<div class="topic-metadata">

**Author:** [@henrhoi](https://discuss.elastic.co/u/henrhoi)\
**Replies:** 4\
**Last updated:** [December 13, 2023, 1:07pm UTC](https://discuss.elastic.co/t/is-the-precision-of-cardinality-aggregation-decided-by-total-unique-value-count-or-filtered-unique-value-count/349073 "2023-12-13T13:07:14Z")

</div>

Hi, We have an index with a field containing ~30,000 unique values. When doing a filtered cardinality aggregation on this field, which should return ~650 unique values, we experience non-deterministic results (±25). W…

---

## [Aggregations Migration ES7 to ES8.11.1](https://discuss.elastic.co/t/aggregations-migration-es7-to-es8-11-1/349255)

<div class="topic-metadata">

**Author:** [@Dev1234](https://discuss.elastic.co/u/Dev1234)\
**Replies:** 0\
**Last updated:** [December 13, 2023, 12:03pm UTC](https://discuss.elastic.co/t/aggregations-migration-es7-to-es8-11-1/349255 "2023-12-13T12:03:42Z")

</div>

Hello dear community, I am currently migrating our ES7 to ES8 and am now encountering the problem that I cannot find a solution as to how I can migrate SearchHits or the .get(String) method. public static Set\<Integer\> …

---

## [Changing from Elasticsearch 7.10.2 OSS to Basic version](https://discuss.elastic.co/t/changing-from-elasticsearch-7-10-2-oss-to-basic-version/347523)

<div class="topic-metadata">

**Author:** [@Talha1](https://discuss.elastic.co/u/Talha1)\
**Replies:** 3\
**Last updated:** [December 13, 2023, 11:55am UTC](https://discuss.elastic.co/t/changing-from-elasticsearch-7-10-2-oss-to-basic-version/347523 "2023-12-13T11:55:24Z")

</div>

Hi, I'm currently using Elasticsearch version 7.10. OSS version but when trying to implement security ran into challenges which turns out is because I am not on the basic version of Elasticsearch. Is there a way I can ch…

---

## [How to maintain product availability in Elasticsearch?](https://discuss.elastic.co/t/how-to-maintain-product-availability-in-elasticsearch/349226)

<div class="topic-metadata">

**Author:** [@Aadhar\_Bhatt](https://discuss.elastic.co/u/Aadhar_Bhatt)\
**Replies:** 0\
**Last updated:** [December 13, 2023, 7:27am UTC](https://discuss.elastic.co/t/how-to-maintain-product-availability-in-elasticsearch/349226 "2023-12-13T07:27:52Z")

</div>

Hey everyone, I'm setting up an eCommerce search system on Elasticsearch with about 6 million product listings across 3000 stores. I need advice on storing availability data efficiently within ES. This data updates freq…

---

## [How to add day of month field but with certain timezone](https://discuss.elastic.co/t/how-to-add-day-of-month-field-but-with-certain-timezone/349207)

<div class="topic-metadata">

**Author:** [@yuswanul](https://discuss.elastic.co/u/yuswanul)\
**Replies:** 5\
**Last updated:** [December 13, 2023, 4:42am UTC](https://discuss.elastic.co/t/how-to-add-day-of-month-field-but-with-certain-timezone/349207 "2023-12-13T04:42:18Z")

</div>

i want to create a "day of month" field for my visualization. I already did this using a scripted field before. but since I chose Grafana to visualize my data, I can't use that scripted field there. so I want to generate…

---

## [Multiple hosts in one Java Rest Client with different API Keys](https://discuss.elastic.co/t/multiple-hosts-in-one-java-rest-client-with-different-api-keys/349069)

<div class="topic-metadata">

**Author:** [@aliaksei\_dev](https://discuss.elastic.co/u/aliaksei_dev)\
**Replies:** 1\
**Last updated:** [December 12, 2023, 1:33pm UTC](https://discuss.elastic.co/t/multiple-hosts-in-one-java-rest-client-with-different-api-keys/349069 "2023-12-12T13:33:04Z")

</div>

Hi, having trouble with implementing Java Rest Client v.7.17 - the requirement is to use multiple hosts with one client. At the same time our elastic uses Api Keys with header "Authorization" to authorize. So my question…

---

## [Need help to create a grok patter for my syslog pattern](https://discuss.elastic.co/t/need-help-to-create-a-grok-patter-for-my-syslog-pattern/349103)

<div class="topic-metadata">

**Author:** [@ameeto17](https://discuss.elastic.co/u/ameeto17)\
**Replies:** 2\
**Last updated:** [December 12, 2023, 10:17pm UTC](https://discuss.elastic.co/t/need-help-to-create-a-grok-patter-for-my-syslog-pattern/349103 "2023-12-12T22:17:28Z")

</div>

my log message looks like this message Dec 12 12:01:27 ppdtest302 test-checker: Context SHA of TEST Software Version 3.0.1\_RC5 0b1f71223180bf0df9330b13e17f8d7c62dfdaad16b97a80b8a25c99409c1109 How do i use a grok patte…

---

## [Fielddata is disabled on \[host.name\] in \[metricbeat-8.10.3\]](https://discuss.elastic.co/t/fielddata-is-disabled-on-host-name-in-metricbeat-8-10-3/348261)

<div class="topic-metadata">

**Author:** [@efrainMZ](https://discuss.elastic.co/u/efrainMZ)\
**Replies:** 8\
**Last updated:** [December 12, 2023, 9:03pm UTC](https://discuss.elastic.co/t/fielddata-is-disabled-on-host-name-in-metricbeat-8-10-3/348261 "2023-12-12T21:03:10Z")

</div>

Hello good morning! I am ingesting data from metricbeat to elasticsearch and loading the dashboards of version metricbeat 8.10.3 with the command "./metricbeat setup --dashboard" but when viewing the dashboards it shows…

---

## [Date\_histogram: Unknown time-zone ID: Europe/Kyiv](https://discuss.elastic.co/t/date-histogram-unknown-time-zone-id-europe-kyiv/349188)

<div class="topic-metadata">

**Author:** [@Inbal](https://discuss.elastic.co/u/Inbal)\
**Replies:** 9\
**Last updated:** [December 12, 2023, 8:15pm UTC](https://discuss.elastic.co/t/date-histogram-unknown-time-zone-id-europe-kyiv/349188 "2023-12-12T20:15:57Z")

</div>

Hey, I have a es search with aggregations which contains date\_histogram with time\_zone parameter. When I'm choosing "Europe/Kyiv" as time\_zone I'm getting the following error reason: "Unknown time-zone ID: Europe/Kyiv"…

---

## [Need help about starting logstash-8.11.2](https://discuss.elastic.co/t/need-help-about-starting-logstash-8-11-2/349125)

<div class="topic-metadata">

**Author:** [@AlexLWei](https://discuss.elastic.co/u/AlexLWei)\
**Replies:** 13\
**Last updated:** [December 12, 2023, 8:12pm UTC](https://discuss.elastic.co/t/need-help-about-starting-logstash-8-11-2/349125 "2023-12-12T20:12:08Z")

</div>

I installed Logstash by downloading and unzipping the zip file from the official website and it occurs an error about JDK , Using bundled JDK: /opt/logstash-8.11.2/jdk Unrecognized VM option 'UseConcMarkSweepGC' Erro…

---

## [Beats and Elastic Agent 8.11.3 / 7.17.16 Security Update (ESA-2023-30)](https://discuss.elastic.co/t/beats-and-elastic-agent-8-11-3-7-17-16-security-update-esa-2023-30/349180)

<div class="topic-metadata">

**Author:** [@ismisepaul](https://discuss.elastic.co/u/ismisepaul)\
**Replies:** 0\
**Last updated:** [December 12, 2023, 5:00pm UTC](https://discuss.elastic.co/t/beats-and-elastic-agent-8-11-3-7-17-16-security-update-esa-2023-30/349180 "2023-12-12T17:00:31Z")

</div>

Beats and Elastic Agent Insertion of Sensitive Information into Log File An issue was discovered by Elastic whereby Beats and Elastic Agent would log a raw event in its own logs at the WARN or ERROR level if ingesting th…

---

## [MatchAllQuery is slow once segment size exceeds 1](https://discuss.elastic.co/t/matchallquery-is-slow-once-segment-size-exceeds-1/349095)

<div class="topic-metadata">

**Author:** [@jwSmith1](https://discuss.elastic.co/u/jwSmith1)\
**Replies:** 5\
**Last updated:** [December 12, 2023, 6:04pm UTC](https://discuss.elastic.co/t/matchallquery-is-slow-once-segment-size-exceeds-1/349095 "2023-12-12T18:04:14Z")

</div>

Hi, I'm managing an extra-small index and had some issues with the latency. The index has ~4000 documents (25mb in total) 1 shard low index and search traffic I need to periodically fetch all of the documents from th…

---

## [Cannot read properties of undefined (reading 'split')](https://discuss.elastic.co/t/cannot-read-properties-of-undefined-reading-split/349034)

<div class="topic-metadata">

**Author:** [@Huzefa](https://discuss.elastic.co/u/Huzefa)\
**Replies:** 0\
**Last updated:** [December 11, 2023, 11:16am UTC](https://discuss.elastic.co/t/cannot-read-properties-of-undefined-reading-split/349034 "2023-12-11T11:16:17Z")

</div>

I am currently encountering an issue in Kibana related to "Cannot read properties of undefined (reading 'split')" when attempting to upgrade agent policies or view agent policies. The occurrence of this error was noted a…

---

## [Create visualization for sum of system.cpu.cores per host](https://discuss.elastic.co/t/create-visualization-for-sum-of-system-cpu-cores-per-host/348595)

<div class="topic-metadata">

**Author:** [@lpowers](https://discuss.elastic.co/u/lpowers)\
**Replies:** 7\
**Last updated:** [December 12, 2023, 5:23pm UTC](https://discuss.elastic.co/t/create-visualization-for-sum-of-system-cpu-cores-per-host/348595 "2023-12-12T17:23:46Z")

</div>

I'm trying to create a visualization for the total cores for each host and then sum them all up to get a count for each of our clusters. Is it possible?

---

## [Winlogbeat cannot sent a spécific event windows (level information) to kibana for provider .net runtime](https://discuss.elastic.co/t/winlogbeat-cannot-sent-a-specific-event-windows-level-information-to-kibana-for-provider-net-runtime/348922)

<div class="topic-metadata">

**Author:** [@SAMY-ELK](https://discuss.elastic.co/u/SAMY-ELK)\
**Replies:** 0\
**Last updated:** [December 8, 2023, 4:11pm UTC](https://discuss.elastic.co/t/winlogbeat-cannot-sent-a-specific-event-windows-level-information-to-kibana-for-provider-net-runtime/348922 "2023-12-08T16:11:00Z")

</div>

Hello Team, I noticed that we cannot sent all windows evenement with below description about "information level" with winlogbeat to kibana : " The description of event ID 0 in the .NET Runtime source cannot be found.…

---

## [Elasticsearch 8.11.2, 7.17.16 Security Update (ESA-2023-29)](https://discuss.elastic.co/t/elasticsearch-8-11-2-7-17-16-security-update-esa-2023-29/349179)

<div class="topic-metadata">

**Author:** [@Levine](https://discuss.elastic.co/u/Levine)\
**Replies:** 0\
**Last updated:** [December 12, 2023, 4:57pm UTC](https://discuss.elastic.co/t/elasticsearch-8-11-2-7-17-16-security-update-esa-2023-29/349179 "2023-12-12T16:57:56Z")

</div>

Elasticsearch Insertion of Sensitive Information into Log File (ESA-2023-29) An issue was discovered by Elastic whereby Watcher search input logged the search query results on DEBUG log level. This could lead to raw cont…

---

## [Palo Alto Next-Gen Firewall compatibility with Global Protect VPN Client](https://discuss.elastic.co/t/palo-alto-next-gen-firewall-compatibility-with-global-protect-vpn-client/349084)

<div class="topic-metadata">

**Author:** [@CodeMonky](https://discuss.elastic.co/u/CodeMonky)\
**Replies:** 5\
**Last updated:** [December 12, 2023, 2:52pm UTC](https://discuss.elastic.co/t/palo-alto-next-gen-firewall-compatibility-with-global-protect-vpn-client/349084 "2023-12-12T14:52:15Z")

</div>

Good day all! I'm looking for confirmation on the features of the Palo Alto Next-Gen Firewall integration with elastic. On the overview page of the integration, it details support of the Global Protect type of message. …

---

## [License Platinum Subscription 64 GB only for node?](https://discuss.elastic.co/t/license-platinum-subscription-64-gb-only-for-node/348422)

<div class="topic-metadata">

**Author:** [@Rossella\_Palmisano](https://discuss.elastic.co/u/Rossella_Palmisano)\
**Replies:** 7\
**Last updated:** [December 12, 2023, 2:28pm UTC](https://discuss.elastic.co/t/license-platinum-subscription-64-gb-only-for-node/348422 "2023-12-12T14:28:09Z")

</div>

For the calculation of elastic platinum licenses should only nodes count or should I also consider the GB RAM per node? Which nodes need to be licensed? I have both master nodes and worker nodes.

---

## [Possible bug with sorting dynamically mapped fields](https://discuss.elastic.co/t/possible-bug-with-sorting-dynamically-mapped-fields/349149)

<div class="topic-metadata">

**Author:** [@Evgeni\_Dzhelyov](https://discuss.elastic.co/u/Evgeni_Dzhelyov)\
**Replies:** 0\
**Last updated:** [December 12, 2023, 1:05pm UTC](https://discuss.elastic.co/t/possible-bug-with-sorting-dynamically-mapped-fields/349149 "2023-12-12T13:05:01Z")

</div>

We ingest a lot of custom logs in Elasticsearch. For the application logs we use a custom schema with dynamic mappings, but when sorting for some of the fields we hit a strange bug: Sort by a dext.duration#double field…

---

## [Can not create a document has mutlipolygon having hole](https://discuss.elastic.co/t/can-not-create-a-document-has-mutlipolygon-having-hole/349133)

<div class="topic-metadata">

**Author:** [@Sai\_Suvam\_Patnaik](https://discuss.elastic.co/u/Sai_Suvam_Patnaik)\
**Replies:** 1\
**Last updated:** [December 12, 2023, 11:47am UTC](https://discuss.elastic.co/t/can-not-create-a-document-has-mutlipolygon-having-hole/349133 "2023-12-12T11:47:05Z")

</div>

Hi all , can anyone help me I am facing a following issue . Summary Can not create a document has multipolygon having hole. This is the screenshot of the shp file in qgis: Expected behavior The document is succe…

[Previous page](https://discuss.elastic.co/tag/none.md?no_tags=true&page=257)

[Next page](https://discuss.elastic.co/tag/none.md?no_tags=true&page=259)
