# \#none

**URL:** https://discuss.elastic.co/tag/none.md?no_tags=true&page=261

[Latest](https://discuss.elastic.co/latest.md) · [Categories](https://discuss.elastic.co/categories.md) · [Tags](https://discuss.elastic.co/tags.md)

**Page:** 262

---

## [Elasticsearch curl output returning error](https://discuss.elastic.co/t/elasticsearch-curl-output-returning-error/348836)

<div class="topic-metadata">

**Author:** [@Kamesh\_Pratapa](https://discuss.elastic.co/u/Kamesh_Pratapa)\
**Replies:** 0\
**Last updated:** [December 7, 2023, 6:01pm UTC](https://discuss.elastic.co/t/elasticsearch-curl-output-returning-error/348836 "2023-12-07T18:01:13Z")

</div>

Hi all, I am trying to setup ELK cluster with 7.16 version with X-pack enabled and SSL certificates configured. I am doing it in ubuntu where we have ansible code to deploy the stack which was developed by a person ear…

---

## [How to input the evtx file in logstash](https://discuss.elastic.co/t/how-to-input-the-evtx-file-in-logstash/348834)

<div class="topic-metadata">

**Author:** [@musk\_elon](https://discuss.elastic.co/u/musk_elon)\
**Replies:** 0\
**Last updated:** [December 7, 2023, 5:15pm UTC](https://discuss.elastic.co/t/how-to-input-the-evtx-file-in-logstash/348834 "2023-12-07T17:15:14Z")

</div>

Hello, everyone. I want to know how to input the evtx file in logstash. output is json. help me. thanks

---

## [Create a metric out of the last values from multiple log files](https://discuss.elastic.co/t/create-a-metric-out-of-the-last-values-from-multiple-log-files/348748)

<div class="topic-metadata">

**Author:** [@Jospaul](https://discuss.elastic.co/u/Jospaul)\
**Replies:** 2\
**Last updated:** [December 7, 2023, 3:58pm UTC](https://discuss.elastic.co/t/create-a-metric-out-of-the-last-values-from-multiple-log-files/348748 "2023-12-07T15:58:47Z")

</div>

I need to find the current active threads in a system. The log files spit this information per log file, but as I am running multiple of them in parallel. There are multiple log files created each showing the active thre…

---

## [Ignore\_inactive does not work in filebeat with filestream config type](https://discuss.elastic.co/t/ignore-inactive-does-not-work-in-filebeat-with-filestream-config-type/348822)

<div class="topic-metadata">

**Author:** [@josepcorrea](https://discuss.elastic.co/u/josepcorrea)\
**Replies:** 0\
**Last updated:** [December 7, 2023, 3:13pm UTC](https://discuss.elastic.co/t/ignore-inactive-does-not-work-in-filebeat-with-filestream-config-type/348822 "2023-12-07T15:13:10Z")

</div>

When I use the filestream type instead of the log type, filebeat always reads the entire log file from the beginning. - type: filestream id: test\_id enable: true paths: - "/usr/share/filebeat/inputs.d/\*.log" …

---

## [What is the max id for rollover in index name](https://discuss.elastic.co/t/what-is-the-max-id-for-rollover-in-index-name/348802)

<div class="topic-metadata">

**Author:** [@avnere](https://discuss.elastic.co/u/avnere)\
**Replies:** 3\
**Last updated:** [December 7, 2023, 2:58pm UTC](https://discuss.elastic.co/t/what-is-the-max-id-for-rollover-in-index-name/348802 "2023-12-07T14:58:46Z")

</div>

Hi, I have created index with rollover policy (with 9 digits: 000000001) : PUT /\<my-index-{now/d}-000000001\> After rollover it create the new index with 6 digits: 000002 Is there a way to increase the number of digit…

---

## [Alerts Page Only Shows for Threat Intel rule](https://discuss.elastic.co/t/alerts-page-only-shows-for-threat-intel-rule/348751)

<div class="topic-metadata">

**Author:** [@sourcreamnormanbates](https://discuss.elastic.co/u/sourcreamnormanbates)\
**Replies:** 2\
**Last updated:** [December 7, 2023, 2:29pm UTC](https://discuss.elastic.co/t/alerts-page-only-shows-for-threat-intel-rule/348751 "2023-12-07T14:29:52Z")

</div>

When I'm on the Detection & Response page, I am seeing alerts for various SIEM rules. However; when I go to the Alerts page, I only see alerts from the Threat Intelligence alerts. No other alerts are displayed.

---

## [Links Panel Font SIze](https://discuss.elastic.co/t/links-panel-font-size/348811)

<div class="topic-metadata">

**Author:** [@willemdh](https://discuss.elastic.co/u/willemdh)\
**Replies:** 1\
**Last updated:** [December 7, 2023, 1:23pm UTC](https://discuss.elastic.co/t/links-panel-font-size/348811 "2023-12-07T13:23:28Z")

</div>

Hello, I love the new Links Panel, but the default font size is way too big imho. In the previous years we always made menus with the Markdown panel, which allows to resize the font size. Please please add this funct…

---

## [Logstash custom DATE fields (extracted by regex or custom patterns) how to convert it to DATE field](https://discuss.elastic.co/t/logstash-custom-date-fields-extracted-by-regex-or-custom-patterns-how-to-convert-it-to-date-field/348419)

<div class="topic-metadata">

**Author:** [@elk1985](https://discuss.elastic.co/u/elk1985)\
**Replies:** 7\
**Last updated:** [December 7, 2023, 12:45pm UTC](https://discuss.elastic.co/t/logstash-custom-date-fields-extracted-by-regex-or-custom-patterns-how-to-convert-it-to-date-field/348419 "2023-12-07T12:45:28Z")

</div>

Hello everyone. Currently, I'm in the stage of writing custom Grok filters in Logstash. I have many different logs - some of them have a date format that fits ISO8601 format. But unfortunately when I use this format in m…

---

## [Extract specific string from a field in ELK](https://discuss.elastic.co/t/extract-specific-string-from-a-field-in-elk/348799)

<div class="topic-metadata">

**Author:** [@Satheesh](https://discuss.elastic.co/u/Satheesh)\
**Replies:** 1\
**Last updated:** [December 7, 2023, 12:07pm UTC](https://discuss.elastic.co/t/extract-specific-string-from-a-field-in-elk/348799 "2023-12-07T12:07:43Z")

</div>

I am newbie in ELK. In my ELK, a single document has multiple fields (k8s.pod,k8s.ns,timestamp,logtag,stream and message etc.,). In the message field, I am getting the logs like below e\[36m15:25:47.508e\[0;39m e\[1;30m\[de…

---

## [Hide all panels, using control or filter](https://discuss.elastic.co/t/hide-all-panels-using-control-or-filter/348804)

<div class="topic-metadata">

**Author:** [@Arshukla](https://discuss.elastic.co/u/Arshukla)\
**Replies:** 1\
**Last updated:** [December 7, 2023, 12:03pm UTC](https://discuss.elastic.co/t/hide-all-panels-using-control-or-filter/348804 "2023-12-07T12:03:15Z")

</div>

Hello Team, Please help to tell how to hide all panels, of a dashboard using controls or filter

---

## [Not able to get file logs from otel collector to elasticsearch using APM server](https://discuss.elastic.co/t/not-able-to-get-file-logs-from-otel-collector-to-elasticsearch-using-apm-server/348214)

<div class="topic-metadata">

**Author:** [@Akshay\_Ranka](https://discuss.elastic.co/u/Akshay_Ranka)\
**Replies:** 5\
**Last updated:** [December 7, 2023, 11:56am UTC](https://discuss.elastic.co/t/not-able-to-get-file-logs-from-otel-collector-to-elasticsearch-using-apm-server/348214 "2023-12-07T11:56:08Z")

</div>

extensions: health\_check: pprof: endpoint: 0.0.0.0:1777 zpages: endpoint: 0.0.0.0:55679 receivers: filelog: include: \[/path/to log/.log\] operators: - type: regex\_parser regex: '^(?P\\d{4}-\\d{2}-\\d{2} \\d{2}:\\d{2…

---

## [Running Logstah in Windows](https://discuss.elastic.co/t/running-logstah-in-windows/348749)

<div class="topic-metadata">

**Author:** [@Alberto\_Jimenez1](https://discuss.elastic.co/u/Alberto_Jimenez1)\
**Replies:** 1\
**Last updated:** [December 7, 2023, 10:52am UTC](https://discuss.elastic.co/t/running-logstah-in-windows/348749 "2023-12-07T10:52:37Z")

</div>

Im running in Windows Logstah the basic Test Official website recommends: logstash.bat -e "input { stdin { } } output { stdout {} }" but I receive following error in the cmd: \`\`\` "\[FATAL\] 2023-12-06 14:24:21.428 \[ma…

---

## [ES create indexes\\reindex are slow when using a synonym file](https://discuss.elastic.co/t/es-create-indexes-reindex-are-slow-when-using-a-synonym-file/348718)

<div class="topic-metadata">

**Author:** [@ryzhovas](https://discuss.elastic.co/u/ryzhovas)\
**Replies:** 6\
**Last updated:** [December 7, 2023, 9:29am UTC](https://discuss.elastic.co/t/es-create-indexes-reindex-are-slow-when-using-a-synonym-file/348718 "2023-12-07T09:29:50Z")

</div>

We have synonym file 38M when we create index with filter "dictionary": { "expand": false, "lenient": true, "synonyms\_path": "linguistics/expert\_20231123/em\_dictionary.txt", …

---

## [Dec 7th, 2023: \[EN\] Find book about Christmas without searching for Christmas](https://discuss.elastic.co/t/dec-7th-2023-en-find-book-about-christmas-without-searching-for-christmas/348129)

<div class="topic-metadata">

**Author:** [@lio](https://discuss.elastic.co/u/lio)\
**Replies:** 0\
**Last updated:** [November 28, 2023, 11:12am UTC](https://discuss.elastic.co/t/dec-7th-2023-en-find-book-about-christmas-without-searching-for-christmas/348129 "2023-11-28T11:12:58Z")

</div>

As we’re getting closer to the holiday season, I’m looking forward to getting cozy, picking up a new book and having a relaxing time. But book discovery online using a search bar is not as easy as it seems.... Most reta…

---

## [Discuss: Security Vulnerabilities: ESA-2023-14 - CVE-2023-31419](https://discuss.elastic.co/t/discuss-security-vulnerabilities-esa-2023-14-cve-2023-31419/348769)

<div class="topic-metadata">

**Author:** [@devkgk](https://discuss.elastic.co/u/devkgk)\
**Replies:** 2\
**Last updated:** [December 7, 2023, 8:32am UTC](https://discuss.elastic.co/t/discuss-security-vulnerabilities-esa-2023-14-cve-2023-31419/348769 "2023-12-07T08:32:44Z")

</div>

Hello, everybody. According to the community's safety announcement: " Elasticsearch StackOverflow vulnerability (ESA-2023-14) A flaw was discovered in Elasticsearch, affecting the \_search API that allowed a specially …

---

## [Does date-format of ES7.5.2 not support YYYY?](https://discuss.elastic.co/t/does-date-format-of-es7-5-2-not-support-yyyy/348787)

<div class="topic-metadata">

**Author:** [@MiuNice](https://discuss.elastic.co/u/MiuNice)\
**Replies:** 2\
**Last updated:** [December 7, 2023, 7:54am UTC](https://discuss.elastic.co/t/does-date-format-of-es7-5-2-not-support-yyyy/348787 "2023-12-07T07:54:02Z")

</div>

I created a field named "created" in the index as shown below: "created": { "type": "date", "format": "YYYY-MM-dd'T'HH:mm:ss'Z'" } When I used the range method for querying, I got unexpected results. There is a…

---

## [Elastic Search Indices Migration from Version 5.6 to Version 8.11 (New ES cluster)](https://discuss.elastic.co/t/elastic-search-indices-migration-from-version-5-6-to-version-8-11-new-es-cluster/348784)

<div class="topic-metadata">

**Author:** [@chateesh](https://discuss.elastic.co/u/chateesh)\
**Replies:** 1\
**Last updated:** [December 7, 2023, 7:01am UTC](https://discuss.elastic.co/t/elastic-search-indices-migration-from-version-5-6-to-version-8-11-new-es-cluster/348784 "2023-12-07T07:01:39Z")

</div>

Hi Team, Indices in ES version 5.6 are compatible with ES version 8.11 (New ES Cluster) if we restore these indices by pointing snapshot repository of ES 5.6 cluster to new ES 8.11 cluster? Can you please share the ste…

---

## [Elasticsearch false mapping](https://discuss.elastic.co/t/elasticsearch-false-mapping/348722)

<div class="topic-metadata">

**Author:** [@vladislav](https://discuss.elastic.co/u/vladislav)\
**Replies:** 6\
**Last updated:** [December 7, 2023, 6:50am UTC](https://discuss.elastic.co/t/elasticsearch-false-mapping/348722 "2023-12-07T06:50:20Z")

</div>

Hello everyone and thanks for help. I've installed latest versions of elasticsearch, kibana and logstash (8.11.1) on test cluster. Next, created new simple logstash pipeline that listens tcp port, next send data to elas…

---

## [We are getting two different offset values for same message](https://discuss.elastic.co/t/we-are-getting-two-different-offset-values-for-same-message/348779)

<div class="topic-metadata">

**Author:** [@prashant1](https://discuss.elastic.co/u/prashant1)\
**Replies:** 0\
**Last updated:** [December 7, 2023, 5:44am UTC](https://discuss.elastic.co/t/we-are-getting-two-different-offset-values-for-same-message/348779 "2023-12-07T05:44:39Z")

</div>

Hi, We have two logstash pods which are reading the data from elasticsearch from one index for last 24 hr data and then sending data to Kafka server. We can see two different offset are created for similar log message. …

---

## [Can't Create Enrollment Token](https://discuss.elastic.co/t/cant-create-enrollment-token/348460)

<div class="topic-metadata">

**Author:** [@Bethanie\_Tipton](https://discuss.elastic.co/u/Bethanie_Tipton)\
**Replies:** 6\
**Last updated:** [December 6, 2023, 9:06pm UTC](https://discuss.elastic.co/t/cant-create-enrollment-token/348460 "2023-12-06T21:06:53Z")

</div>

When I try to open elasticsearch-create-enrollment-token, it crashes. I can't do anything with it; I click it, it pops up on my screen for half a second, and then closes.

---

## [Pagination Search - page 1 to page 5](https://discuss.elastic.co/t/pagination-search-page-1-to-page-5/348668)

<div class="topic-metadata">

**Author:** [@Jasonespo](https://discuss.elastic.co/u/Jasonespo)\
**Replies:** 1\
**Last updated:** [December 6, 2023, 9:30pm UTC](https://discuss.elastic.co/t/pagination-search-page-1-to-page-5/348668 "2023-12-06T21:30:06Z")

</div>

Hi, We're trying to implement pagination for our application. We are displaying a table with 10 results per page. And we're wondering if it's possible to go from page 1 (record 1-10) to page 5 (record 51-60) in one jump…

---

## [Dec 6th, 2023: \[EN\] "He's making a list 🎶" and now needs to sort it — with Elasticsearch](https://discuss.elastic.co/t/dec-6th-2023-en-hes-making-a-list-and-now-needs-to-sort-it-with-elasticsearch/348128)

<div class="topic-metadata">

**Author:** [@xeraa](https://discuss.elastic.co/u/xeraa)\
**Replies:** 0\
**Last updated:** [December 6, 2023, 8:00am UTC](https://discuss.elastic.co/t/dec-6th-2023-en-hes-making-a-list-and-now-needs-to-sort-it-with-elasticsearch/348128 "2023-12-06T08:00:49Z")

</div>

While you might be picturing Santa Claus when singing this song, European folklore, particularly in the Alpine regions, has the two legendary figures Saint Nicholas and Krampus. Saint Nicholas, symbolizing generosity …

---

## [Logstash service is active, enabled but netstat output shows port not listening](https://discuss.elastic.co/t/logstash-service-is-active-enabled-but-netstat-output-shows-port-not-listening/348695)

<div class="topic-metadata">

**Author:** [@jayadevp](https://discuss.elastic.co/u/jayadevp)\
**Replies:** 17\
**Last updated:** [December 6, 2023, 7:54pm UTC](https://discuss.elastic.co/t/logstash-service-is-active-enabled-but-netstat-output-shows-port-not-listening/348695 "2023-12-06T19:54:58Z")

</div>

If i run the command to manually run logstash " sudo /usr/share/logstash/bin/logstash -f "/etc/logstash/conf.d/fortigate.conf" --config.reload.automatic" im able to see the output and netstat also shows port listening …

---

## [Scroll inner\_hits in Elasticsearch](https://discuss.elastic.co/t/scroll-inner-hits-in-elasticsearch/348757)

<div class="topic-metadata">

**Author:** [@TomTom](https://discuss.elastic.co/u/TomTom)\
**Replies:** 0\
**Last updated:** [December 6, 2023, 7:38pm UTC](https://discuss.elastic.co/t/scroll-inner-hits-in-elasticsearch/348757 "2023-12-06T19:38:04Z")

</div>

I have a document that has nested items, and in some cases I need to query documents that have nested items that match the filter applied in the search and return all nested items that match. To do this, in the search q…

---

## [No d for data node anymore?](https://discuss.elastic.co/t/no-d-for-data-node-anymore/348736)

<div class="topic-metadata">

**Author:** [@Doc\_Kaos](https://discuss.elastic.co/u/Doc_Kaos)\
**Replies:** 1\
**Last updated:** [December 6, 2023, 7:20pm UTC](https://discuss.elastic.co/t/no-d-for-data-node-anymore/348736 "2023-12-06T19:20:53Z")

</div>

Looking at the documentation cat nodes API | Elasticsearch Guide \[8.11\] | Elastic It appears that a "Hot" node should have roles hd ... but that's not true in real life. Is a hot node not a "data" node? Are 'data\_content…

---

## [Use Logstash for access REST APIs and do complex queries or better Connector Clients](https://discuss.elastic.co/t/use-logstash-for-access-rest-apis-and-do-complex-queries-or-better-connector-clients/348725)

<div class="topic-metadata">

**Author:** [@sebastianboelling](https://discuss.elastic.co/u/sebastianboelling)\
**Replies:** 1\
**Last updated:** [December 6, 2023, 3:47pm UTC](https://discuss.elastic.co/t/use-logstash-for-access-rest-apis-and-do-complex-queries-or-better-connector-clients/348725 "2023-12-06T15:47:55Z")

</div>

Hi anybody, has anybody experiences in using Logstash to gather data from a complex REST/JSON API. The API delivers user specific data similar to OneDrive or SharePoint. That means I have to access the (1) users list a…

---

## [Use logstash to connect VMware vCenter API?](https://discuss.elastic.co/t/use-logstash-to-connect-vmware-vcenter-api/348517)

<div class="topic-metadata">

**Author:** [@pyk346](https://discuss.elastic.co/u/pyk346)\
**Replies:** 7\
**Last updated:** [December 6, 2023, 2:33pm UTC](https://discuss.elastic.co/t/use-logstash-to-connect-vmware-vcenter-api/348517 "2023-12-06T14:33:35Z")

</div>

I'm trying to utilize the elastic logstash to obtain VMware vcenter datacenter metrics via API but failed to connect them. The vCenter version is 8.0.1. I had successfully configured "syslog" as input and recieved logs…

---

## [Download Windows Agent from source artifacts.elastic.co](https://discuss.elastic.co/t/download-windows-agent-from-source-artifacts-elastic-co/348654)

<div class="topic-metadata">

**Author:** [@Tybe\_sacha](https://discuss.elastic.co/u/Tybe_sacha)\
**Replies:** 4\
**Last updated:** [December 6, 2023, 2:00pm UTC](https://discuss.elastic.co/t/download-windows-agent-from-source-artifacts-elastic-co/348654 "2023-12-06T14:00:04Z")

</div>

Hi, I'm trying to install the Fleet Server and Windows Agent. Here is text I paste : $ProgressPreference = 'SilentlyContinue' Invoke-WebRequest -Uri https://artifacts.elastic.co/downloads/beats/elastic-agent/elastic-ag…

---

## [JVM very greedy with memory. How do I get it to shrink when possible?](https://discuss.elastic.co/t/jvm-very-greedy-with-memory-how-do-i-get-it-to-shrink-when-possible/348657)

<div class="topic-metadata">

**Author:** [@Vulume](https://discuss.elastic.co/u/Vulume)\
**Replies:** 2\
**Last updated:** [December 6, 2023, 1:57pm UTC](https://discuss.elastic.co/t/jvm-very-greedy-with-memory-how-do-i-get-it-to-shrink-when-possible/348657 "2023-12-06T13:57:37Z")

</div>

I want my JVM to give back memory to the OS if it's not using it. I don't care about performance. When I set -Xms128m -Xmx4g, I see the JVM's memory usage grow while indexing and searching, but it never shrinks again af…

---

## [How to know if the result was due to a fuzzysearch?](https://discuss.elastic.co/t/how-to-know-if-the-result-was-due-to-a-fuzzysearch/348726)

<div class="topic-metadata">

**Author:** [@vidhaat](https://discuss.elastic.co/u/vidhaat)\
**Replies:** 0\
**Last updated:** [December 6, 2023, 1:50pm UTC](https://discuss.elastic.co/t/how-to-know-if-the-result-was-due-to-a-fuzzysearch/348726 "2023-12-06T13:50:34Z")

</div>

I have a query where I get results which may or may not have fuzzy search results. I want to get analytics on what results are the result of fuzzy search. How can this be achieved ? { "query": { "bool": { "f…

[Previous page](https://discuss.elastic.co/tag/none.md?no_tags=true&page=260)

[Next page](https://discuss.elastic.co/tag/none.md?no_tags=true&page=262)
