# \#none

**URL:** https://discuss.elastic.co/tag/none.md?no_tags=true&page=262

[Latest](https://discuss.elastic.co/latest.md) · [Categories](https://discuss.elastic.co/categories.md) · [Tags](https://discuss.elastic.co/tags.md)

**Page:** 263

---

## [Grok-Debugger API-Endpoint](https://discuss.elastic.co/t/grok-debugger-api-endpoint/348317)

<div class="topic-metadata">

**Author:** [@justin\_sch](https://discuss.elastic.co/u/justin_sch)\
**Replies:** 5\
**Last updated:** [December 6, 2023, 1:01pm UTC](https://discuss.elastic.co/t/grok-debugger-api-endpoint/348317 "2023-12-06T13:01:52Z")

</div>

Hey, I'd like to use the grokdebuggerof the devtools via an api-endpoint. Unfortunally I can't find any documentation of this, is this tool even available via the rest-api?

---

## [Logstash stdout output text as in file](https://discuss.elastic.co/t/logstash-stdout-output-text-as-in-file/348675)

<div class="topic-metadata">

**Author:** [@carter.kovrov](https://discuss.elastic.co/u/carter.kovrov)\
**Replies:** 6\
**Last updated:** [December 6, 2023, 11:48am UTC](https://discuss.elastic.co/t/logstash-stdout-output-text-as-in-file/348675 "2023-12-06T11:48:31Z")

</div>

Hi all Tell me how to display information as in a file without additional fields? For example, there is a file app.log with the contents 12-15-2023 app running... 12-15-2023 app login user test necessary information …

---

## [JDBC Static Filter Plugin - Error handling, how to skip enrichment when Database is down](https://discuss.elastic.co/t/jdbc-static-filter-plugin-error-handling-how-to-skip-enrichment-when-database-is-down/347204)

<div class="topic-metadata">

**Author:** [@tori](https://discuss.elastic.co/u/tori)\
**Replies:** 2\
**Last updated:** [December 6, 2023, 10:40am UTC](https://discuss.elastic.co/t/jdbc-static-filter-plugin-error-handling-how-to-skip-enrichment-when-database-is-down/347204 "2023-12-06T10:40:58Z")

</div>

Hi, We've got logstash fetching some information from a MySQL database for log enrichment via JDBC Static Filter Plugin. The settings work just fine when things are working as expected: ... jdbc\_static { l…

---

## [SWEET32 Vulnerability Remediation for Elastic Fleet](https://discuss.elastic.co/t/sweet32-vulnerability-remediation-for-elastic-fleet/348598)

<div class="topic-metadata">

**Author:** [@jakechoi](https://discuss.elastic.co/u/jakechoi)\
**Replies:** 1\
**Last updated:** [December 6, 2023, 10:28am UTC](https://discuss.elastic.co/t/sweet32-vulnerability-remediation-for-elastic-fleet/348598 "2023-12-06T10:28:39Z")

</div>

Apologies if this is the wrong location to post this topic. I've been troubleshooting a vulnerability found by our Nessus scanner on our Kibana instance. Nessus shows that the port used by our fleet on our Kibana instan…

---

## [ECE frc-\* Container Descriptions](https://discuss.elastic.co/t/ece-frc-container-descriptions/306366)

<div class="topic-metadata">

**Author:** [@rahst12](https://discuss.elastic.co/u/rahst12)\
**Replies:** 1\
**Last updated:** [December 6, 2023, 8:51am UTC](https://discuss.elastic.co/t/ece-frc-container-descriptions/306366 "2023-12-06T08:51:05Z")

</div>

I'm looking for a description of what each of these ECE "default" containers are supposed to be doing on an allocator: frc-container-task-services-container-task-service frc-allocator-metricbeats-allocator-metricbeat f…

---

## [Kibana Azure AD SSO Authentication](https://discuss.elastic.co/t/kibana-azure-ad-sso-authentication/348692)

<div class="topic-metadata">

**Author:** [@Ilter\_Sag](https://discuss.elastic.co/u/Ilter_Sag)\
**Replies:** 1\
**Last updated:** [December 6, 2023, 8:37am UTC](https://discuss.elastic.co/t/kibana-azure-ad-sso-authentication/348692 "2023-12-06T08:37:34Z")

</div>

Hello, I am trying to setup Kibana Authentication with Azure AD SSO and getting this error. What will be the cause of that error? My server has connection to login.microsoftonline.com and can fetch federation xml. Ela…

---

## [Stack Monitoring with Fleet/elastic-agent](https://discuss.elastic.co/t/stack-monitoring-with-fleet-elastic-agent/347244)

<div class="topic-metadata">

**Author:** [@rastro](https://discuss.elastic.co/u/rastro)\
**Replies:** 36\
**Last updated:** [December 6, 2023, 8:25am UTC](https://discuss.elastic.co/t/stack-monitoring-with-fleet-elastic-agent/347244 "2023-12-06T08:25:21Z")

</div>

In Kibana, when you go to Stack Monitoring, it says "No monitoring data found" and suggests using Metricbeat. Except, shouldn't we be using Elastic Agent? So, how can I get the Stack Monitoring page working with Agent?…

---

## [Custom analyzer for search and indexing](https://discuss.elastic.co/t/custom-analyzer-for-search-and-indexing/348661)

<div class="topic-metadata">

**Author:** [@ssanja](https://discuss.elastic.co/u/ssanja)\
**Replies:** 1\
**Last updated:** [December 6, 2023, 6:33am UTC](https://discuss.elastic.co/t/custom-analyzer-for-search-and-indexing/348661 "2023-12-06T06:33:34Z")

</div>

Hello, when creating an index I specifically created a custom analyzer which should be used for indexing and searching (see the example code below) "settings": { "analysis": { "analyzer": { "custom\_…

---

## [Azure AD SSO setting behind a proxy not working](https://discuss.elastic.co/t/azure-ad-sso-setting-behind-a-proxy-not-working/346654)

<div class="topic-metadata">

**Author:** [@Ilter\_Sag](https://discuss.elastic.co/u/Ilter_Sag)\
**Replies:** 5\
**Last updated:** [December 6, 2023, 5:28am UTC](https://discuss.elastic.co/t/azure-ad-sso-setting-behind-a-proxy-not-working/346654 "2023-12-06T05:28:36Z")

</div>

Hello, I am trying to integrate Azure AD to Elasticsearch cluster behind a proxy. I tried the proxy parameter settings below but could not succeeded. You can find the log behind that post. It say it cannot access to mic…

---

## [Fields are not populating from logstash to elastic](https://discuss.elastic.co/t/fields-are-not-populating-from-logstash-to-elastic/348593)

<div class="topic-metadata">

**Author:** [@mmercaldi](https://discuss.elastic.co/u/mmercaldi)\
**Replies:** 10\
**Last updated:** [December 5, 2023, 10:44pm UTC](https://discuss.elastic.co/t/fields-are-not-populating-from-logstash-to-elastic/348593 "2023-12-05T22:44:34Z")

</div>

I am using logstash to populate elastic I have it set so this filter: filter { json { source =\> "message" target =\> "jsoncontent" remove\_field =\> \["message"\] } } and jsoncontent: {"switchname": "swi…

---

## [Accuracy of date histogram sub-aggregation doc count under terms aggregation](https://discuss.elastic.co/t/accuracy-of-date-histogram-sub-aggregation-doc-count-under-terms-aggregation/348685)

<div class="topic-metadata">

**Author:** [@myronmarston](https://discuss.elastic.co/u/myronmarston)\
**Replies:** 0\
**Last updated:** [December 5, 2023, 10:26pm UTC](https://discuss.elastic.co/t/accuracy-of-date-histogram-sub-aggregation-doc-count-under-terms-aggregation/348685 "2023-12-05T22:26:57Z")

</div>

Hello, I am working on query that combines a terms aggregation with a date histogram sub-aggregation. I would like to get the doc count of each sub-aggregation bucket, determine if it is accurate, and, if it is not acc…

---

## [Kibana Password User Interface](https://discuss.elastic.co/t/kibana-password-user-interface/348669)

<div class="topic-metadata">

**Author:** [@juancamiloll](https://discuss.elastic.co/u/juancamiloll)\
**Replies:** 1\
**Last updated:** [December 5, 2023, 10:15pm UTC](https://discuss.elastic.co/t/kibana-password-user-interface/348669 "2023-12-05T22:15:49Z")

</div>

Hello, Again I ejjeje, I can't get past this point, what should I do? And if I don't want to be prompted for a password, what can I do?

---

## [Connection reset when ingesting data from Filebeat to Logstash](https://discuss.elastic.co/t/connection-reset-when-ingesting-data-from-filebeat-to-logstash/348681)

<div class="topic-metadata">

**Author:** [@epronetlc](https://discuss.elastic.co/u/epronetlc)\
**Replies:** 0\
**Last updated:** [December 5, 2023, 8:55pm UTC](https://discuss.elastic.co/t/connection-reset-when-ingesting-data-from-filebeat-to-logstash/348681 "2023-12-05T20:55:06Z")

</div>

I have Filebeat 8.11.1 configured on a server running Windows Server 2019 with an output to Logstash. I have Logstash 8.11.1 configured on a server running Windows Server 2022 with an input from beats and an output to JD…

---

## [Default ingest pipeline overwritten](https://discuss.elastic.co/t/default-ingest-pipeline-overwritten/348640)

<div class="topic-metadata">

**Author:** [@Jasonespo](https://discuss.elastic.co/u/Jasonespo)\
**Replies:** 5\
**Last updated:** [December 5, 2023, 6:05pm UTC](https://discuss.elastic.co/t/default-ingest-pipeline-overwritten/348640 "2023-12-05T18:05:17Z")

</div>

Hi, I created an index template \`logs-{dataset\_name}-default' as well as setting up a data stream. I also setup a default ingest pipeline for this index. However after a number of days (and maybe coincidentally an Elas…

---

## [Grok\_timeout coming in logstash logs](https://discuss.elastic.co/t/grok-timeout-coming-in-logstash-logs/348623)

<div class="topic-metadata">

**Author:** [@Biswajit\_naik](https://discuss.elastic.co/u/Biswajit_naik)\
**Replies:** 2\
**Last updated:** [December 5, 2023, 5:25pm UTC](https://discuss.elastic.co/t/grok-timeout-coming-in-logstash-logs/348623 "2023-12-05T17:25:00Z")

</div>

when i process multiple type of logs by grok parser ,if the one of logline is not matched with the filter parser ,then i am excepting that it should be come grok parser faliure ,but it comes grok timeout warning in Logst…

---

## [Drop logstash logs not containing certain field](https://discuss.elastic.co/t/drop-logstash-logs-not-containing-certain-field/348626)

<div class="topic-metadata">

**Author:** [@e.vedelaar](https://discuss.elastic.co/u/e.vedelaar)\
**Replies:** 1\
**Last updated:** [December 5, 2023, 5:23pm UTC](https://discuss.elastic.co/t/drop-logstash-logs-not-containing-certain-field/348626 "2023-12-05T17:23:13Z")

</div>

I want to drop all logs who don't contain the dns.question.name field (or if the field is empty) how would i do this?

---

## [Take the Elasticsearch developer survey](https://discuss.elastic.co/t/take-the-elasticsearch-developer-survey/348664)

<div class="topic-metadata">

**Author:** [@carly.richmond](https://discuss.elastic.co/u/carly.richmond)\
**Replies:** 0\
**Last updated:** [December 5, 2023, 4:28pm UTC](https://discuss.elastic.co/t/take-the-elasticsearch-developer-survey/348664 "2023-12-05T16:28:35Z")

</div>

Our developer community is a big part of why Elasticsearch is so popular. To make sure Elastic continues to be a great choice for speed, scale, and relevance, we’d like your help. This survey on your developer experienc…

---

## [Elasticsearch-hadoop 7.17.11 / 8.9.0 Security Update (ESA-2023-28)](https://discuss.elastic.co/t/elasticsearch-hadoop-7-17-11-8-9-0-security-update-esa-2023-28/348663)

<div class="topic-metadata">

**Author:** [@Bryan\_Garcia](https://discuss.elastic.co/u/Bryan_Garcia)\
**Replies:** 0\
**Last updated:** [December 5, 2023, 4:27pm UTC](https://discuss.elastic.co/t/elasticsearch-hadoop-7-17-11-8-9-0-security-update-esa-2023-28/348663 "2023-12-05T16:27:11Z")

</div>

Elasticsearch-hadoop Unsafe Deserialization (ESA-2023-28) An issue was identified that allowed the unsafe deserialization of java objects from hadoop or spark configuration properties that could have been modified by au…

---

## [ELK Stack Events Per Second and Flow Per Minute](https://discuss.elastic.co/t/elk-stack-events-per-second-and-flow-per-minute/348660)

<div class="topic-metadata">

**Author:** [@Guestaba](https://discuss.elastic.co/u/Guestaba)\
**Replies:** 1\
**Last updated:** [December 5, 2023, 3:57pm UTC](https://discuss.elastic.co/t/elk-stack-events-per-second-and-flow-per-minute/348660 "2023-12-05T15:57:39Z")

</div>

Hi everyone, I have and ELK Stack as a SIEM and I am trying to know what are the Events Per Second and the Flow Per Minute of my SIEM. Can someone help me figure this out Thanks in advance

---

## [A question about Logstash S3 output plugin behaviour](https://discuss.elastic.co/t/a-question-about-logstash-s3-output-plugin-behaviour/348651)

<div class="topic-metadata">

**Author:** [@milon.james](https://discuss.elastic.co/u/milon.james)\
**Replies:** 0\
**Last updated:** [December 5, 2023, 2:33pm UTC](https://discuss.elastic.co/t/a-question-about-logstash-s3-output-plugin-behaviour/348651 "2023-12-05T14:33:35Z")

</div>

Hello, Would like to know what is the default behaviour of Logstash S3 output plugin if we stop the process. Can we configure the plugin to close all the open temporary files and push them to S3 before the process shuts…

---

## [Remove N leading bytes from TCP input](https://discuss.elastic.co/t/remove-n-leading-bytes-from-tcp-input/348650)

<div class="topic-metadata">

**Author:** [@rcz](https://discuss.elastic.co/u/rcz)\
**Replies:** 0\
**Last updated:** [December 5, 2023, 2:29pm UTC](https://discuss.elastic.co/t/remove-n-leading-bytes-from-tcp-input/348650 "2023-12-05T14:29:03Z")

</div>

Hi, We are receiving some dubious Protobuf-encoded messages on our TCP input. The sender is leading with a custom length-header of 4 bytes. If we manually dissect the messages, remove the first 4 bytes, and then give …

---

## [One Kibana for multiple Elastic Clusters](https://discuss.elastic.co/t/one-kibana-for-multiple-elastic-clusters/348539)

<div class="topic-metadata">

**Author:** [@Jose\_E](https://discuss.elastic.co/u/Jose_E)\
**Replies:** 2\
**Last updated:** [December 5, 2023, 1:18pm UTC](https://discuss.elastic.co/t/one-kibana-for-multiple-elastic-clusters/348539 "2023-12-05T13:18:56Z")

</div>

Hi everyone, I have a technical doubt regarding the capabilities of Kibana. I currently run an Elasticsearch Cluster with some storage issues and we cannot increase the storage size due to some limitations. However, we …

---

## [Logstash config](https://discuss.elastic.co/t/logstash-config/348644)

<div class="topic-metadata">

**Author:** [@kibanauser4](https://discuss.elastic.co/u/kibanauser4)\
**Replies:** 0\
**Last updated:** [December 5, 2023, 1:16pm UTC](https://discuss.elastic.co/t/logstash-config/348644 "2023-12-05T13:16:17Z")

</div>

I have installed 7.15.0 version of Logstash. I have the following config file: input { file { path =\> "C:/Users/ELK Stack/data/sample.csv" start\_position =\> "beginning" sincedb\_path =\> "NUL" } } filter { csv {…

---

## [Multiselect values in Kibana Visualizations](https://discuss.elastic.co/t/multiselect-values-in-kibana-visualizations/346659)

<div class="topic-metadata">

**Author:** [@fniwes](https://discuss.elastic.co/u/fniwes)\
**Replies:** 3\
**Last updated:** [December 5, 2023, 9:50am UTC](https://discuss.elastic.co/t/multiselect-values-in-kibana-visualizations/346659 "2023-12-05T09:50:40Z")

</div>

Hi! I have several visualizations, some as pie chart with multiple values. I want to select multiple values from the visualization to filter and also to explore in detail using discovery. But I am only able to select on…

---

## [ILM not working node does not match index setting \[index.routing.allocation.require\] filters \[data:\\"warm\\"\]](https://discuss.elastic.co/t/ilm-not-working-node-does-not-match-index-setting-index-routing-allocation-require-filters-data-warm/348617)

<div class="topic-metadata">

**Author:** [@esseti](https://discuss.elastic.co/u/esseti)\
**Replies:** 0\
**Last updated:** [December 5, 2023, 8:42am UTC](https://discuss.elastic.co/t/ilm-not-working-node-does-not-match-index-setting-index-routing-allocation-require-filters-data-warm/348617 "2023-12-05T08:42:41Z")

</div>

Hello i've setup an ILM but i noticed that indeces never leave the warm state, by checking \_cluster/allocation/ i get this message node does not match index setting \[index.routing.allocation.require\] filters \[data:\\"…

---

## [Clone api Bad Gateway error](https://discuss.elastic.co/t/clone-api-bad-gateway-error/348604)

<div class="topic-metadata">

**Author:** [@Krishna94](https://discuss.elastic.co/u/Krishna94)\
**Replies:** 0\
**Last updated:** [December 5, 2023, 2:27am UTC](https://discuss.elastic.co/t/clone-api-bad-gateway-error/348604 "2023-12-05T02:27:54Z")

</div>

Hi team, I tried to do a reindexing of my data but its taking more than 10 days so I tried to clone my index which is of 816GB and when I run clone api I am getting the following error, {"statusCode":502,"error":"Bad G…

---

## [Accessing nested aggregations in a watcher's action](https://discuss.elastic.co/t/accessing-nested-aggregations-in-a-watchers-action/348592)

<div class="topic-metadata">

**Author:** [@Wave](https://discuss.elastic.co/u/Wave)\
**Replies:** 0\
**Last updated:** [December 4, 2023, 7:17pm UTC](https://discuss.elastic.co/t/accessing-nested-aggregations-in-a-watchers-action/348592 "2023-12-04T19:17:59Z")

</div>

This isn't a question, but just wanted to share something I've learned. There are similar posts that talk about nested aggregations, but nothing that quite explained what I was looking for. Creating advanced watchers in…

---

## [Change Index Ingestion method](https://discuss.elastic.co/t/change-index-ingestion-method/348242)

<div class="topic-metadata">

**Author:** [@RodAndTom](https://discuss.elastic.co/u/RodAndTom)\
**Replies:** 2\
**Last updated:** [December 4, 2023, 4:49pm UTC](https://discuss.elastic.co/t/change-index-ingestion-method/348242 "2023-12-04T16:49:01Z")

</div>

Hi, I finally managed to setup a MongoDB connector integration with Elastic through Kibana, but it create a index and I can't change the settings and mappings for this Index (Ingestion method is shown as "Connector". S…

---

## [Anomaly Job - implications of low cardinality in population analysis](https://discuss.elastic.co/t/anomaly-job-implications-of-low-cardinality-in-population-analysis/348584)

<div class="topic-metadata">

**Author:** [@marmai16](https://discuss.elastic.co/u/marmai16)\
**Replies:** 0\
**Last updated:** [December 4, 2023, 4:41pm UTC](https://discuss.elastic.co/t/anomaly-job-implications-of-low-cardinality-in-population-analysis/348584 "2023-12-04T16:41:06Z")

</div>

Hello everybody, i'am testing an anomaly job. At creation, it warned me that the cardinality is below 10 and it might not be suitable for population analysis. I was asking myself, under which circumstances it might be …

---

## [The highlight is not returned when using prefixing query](https://discuss.elastic.co/t/the-highlight-is-not-returned-when-using-prefixing-query/348581)

<div class="topic-metadata">

**Author:** [@eric\_liu2007](https://discuss.elastic.co/u/eric_liu2007)\
**Replies:** 0\
**Last updated:** [December 4, 2023, 4:05pm UTC](https://discuss.elastic.co/t/the-highlight-is-not-returned-when-using-prefixing-query/348581 "2023-12-04T16:05:01Z")

</div>

hi all i am searching by using prefix query, the highlight was return on old version (tested 7.6.2, 7.10.3), but not in latest versions (tested 7.11.0, 7.17.5, 8.10.2, 8.10.4, 8.11.1). if ""index\_prefixes" sub-field …

[Previous page](https://discuss.elastic.co/tag/none.md?no_tags=true&page=261)

[Next page](https://discuss.elastic.co/tag/none.md?no_tags=true&page=263)
