# \#none

**URL:** https://discuss.elastic.co/tag/none.md?no_tags=true&page=275

[Latest](https://discuss.elastic.co/latest.md) · [Categories](https://discuss.elastic.co/categories.md) · [Tags](https://discuss.elastic.co/tags.md)

**Page:** 276

---

## [Where are Security Rules run?](https://discuss.elastic.co/t/where-are-security-rules-run/346753)

<div class="topic-metadata">

**Author:** [@digital-thought](https://discuss.elastic.co/u/digital-thought)\
**Replies:** 4\
**Last updated:** [November 10, 2023, 12:43pm UTC](https://discuss.elastic.co/t/where-are-security-rules-run/346753 "2023-11-10T12:43:39Z")

</div>

The security rules and alerts are fantastic in ELK. Am curious to know, where are the Rules (which dont require Machine Learning) run from? Is it the instance running Kibana or one of the Elastic instances with a speci…

---

## [Kibana 8.5.3, Aggregation Based Visualization Error](https://discuss.elastic.co/t/kibana-8-5-3-aggregation-based-visualization-error/346868)

<div class="topic-metadata">

**Author:** [@Kavikrishnan\_P](https://discuss.elastic.co/u/Kavikrishnan_P)\
**Replies:** 0\
**Last updated:** [November 10, 2023, 11:57am UTC](https://discuss.elastic.co/t/kibana-8-5-3-aggregation-based-visualization-error/346868 "2023-11-10T11:57:55Z")

</div>

In kibana 8.5.3 version, using Aggregation based Visualization, I created 3 'split slices' sub-buckets and in 1st level, one filter type sub aggregation and in 2nd level, two filter type sub aggregation and in 3rd lev…

---

## [Watcher - find difference between 2 buckets keys](https://discuss.elastic.co/t/watcher-find-difference-between-2-buckets-keys/346863)

<div class="topic-metadata">

**Author:** [@hofrichterovak](https://discuss.elastic.co/u/hofrichterovak)\
**Replies:** 0\
**Last updated:** [November 10, 2023, 11:05am UTC](https://discuss.elastic.co/t/watcher-find-difference-between-2-buckets-keys/346863 "2023-11-10T11:05:49Z")

</div>

Hello, I would like to ask for help. I would like to have a watcher that would find the difference between 2 buckets keys. The goal is to find out if there is a difference in the values of the HOST field now and some t…

---

## [Extend the expiry of the certificates](https://discuss.elastic.co/t/extend-the-expiry-of-the-certificates/346548)

<div class="topic-metadata">

**Author:** [@smiley\_tamy](https://discuss.elastic.co/u/smiley_tamy)\
**Replies:** 5\
**Last updated:** [November 10, 2023, 10:37am UTC](https://discuss.elastic.co/t/extend-the-expiry-of-the-certificates/346548 "2023-11-10T10:37:45Z")

</div>

Hi, we have enabled security for Elasticsearch. We extended the expiry of certificates. But still instance certificate does not get changed and retains the default expiry of 3 years Is there a way to make it work

---

## [ Logstash stopped processing because of an error: (SystemExit) exit Logstash stopped processing because of an error: (SystemExit) exit](https://discuss.elastic.co/t/logstash-stopped-processing-because-of-an-error-systemexit-exit-logstash-stopped-processing-because-of-an-error-systemexit-exit/346805)

<div class="topic-metadata">

**Author:** [@17\_Chinmay\_Shelke](https://discuss.elastic.co/u/17_Chinmay_Shelke)\
**Replies:** 3\
**Last updated:** [November 10, 2023, 10:34am UTC](https://discuss.elastic.co/t/logstash-stopped-processing-because-of-an-error-systemexit-exit-logstash-stopped-processing-because-of-an-error-systemexit-exit/346805 "2023-11-10T10:34:33Z")

</div>

Successfully started Logstash API endpoint {:port=\>9600, :ssl\_enabled=\>false} \[2023-11-09T11:25:11,753\]\[INFO \]\[logstash.runner \] Logstash shut down. \[2023-11-09T11:25:11,758\]\[FATAL\]\[org.logstash.Logstash \] …

---

## [Understanding why only one agent policy can be assigned to an agent](https://discuss.elastic.co/t/understanding-why-only-one-agent-policy-can-be-assigned-to-an-agent/346828)

<div class="topic-metadata">

**Author:** [@HHobeck](https://discuss.elastic.co/u/HHobeck)\
**Replies:** 2\
**Last updated:** [November 10, 2023, 8:23am UTC](https://discuss.elastic.co/t/understanding-why-only-one-agent-policy-can-be-assigned-to-an-agent/346828 "2023-11-10T08:23:59Z")

</div>

Dear community. I'm in the situation to setup an elastic agent to retrieve logs with custom integration from a directory e.g. d:\\Logs\\MyApp\_Staging\\\*.log on machine A and on machine B. So I have created an agent policy…

---

## [Can I change http client used for @elastic/elasticsearch in node js?](https://discuss.elastic.co/t/can-i-change-http-client-used-for-elastic-elasticsearch-in-node-js/346843)

<div class="topic-metadata">

**Author:** [@ghanshyam1](https://discuss.elastic.co/u/ghanshyam1)\
**Replies:** 0\
**Last updated:** [November 10, 2023, 7:39am UTC](https://discuss.elastic.co/t/can-i-change-http-client-used-for-elastic-elasticsearch-in-node-js/346843 "2023-11-10T07:39:42Z")

</div>

I want to use axios as http client underneath @elastic/elasticsearch.... I am trying using following code, const { Client } = require('@elastic/elasticsearch'); const axios = require('axios'); // Create a custom trans…

---

## [How can I fix a query dsl so that ALL documents are boosted in the function\_score?](https://discuss.elastic.co/t/how-can-i-fix-a-query-dsl-so-that-all-documents-are-boosted-in-the-function-score/346839)

<div class="topic-metadata">

**Author:** [@Kirill\_Cyber](https://discuss.elastic.co/u/Kirill_Cyber)\
**Replies:** 0\
**Last updated:** [November 10, 2023, 7:05am UTC](https://discuss.elastic.co/t/how-can-i-fix-a-query-dsl-so-that-all-documents-are-boosted-in-the-function-score/346839 "2023-11-10T07:05:45Z")

</div>

I have dsl query with structure { "query": { "function\_score": { "query": { "bool": { "must": { "multi\_match": { …

---

## [Ingest kafka syslog to elasticsearch or kibana](https://discuss.elastic.co/t/ingest-kafka-syslog-to-elasticsearch-or-kibana/346834)

<div class="topic-metadata">

**Author:** [@manasi](https://discuss.elastic.co/u/manasi)\
**Replies:** 0\
**Last updated:** [November 10, 2023, 6:08am UTC](https://discuss.elastic.co/t/ingest-kafka-syslog-to-elasticsearch-or-kibana/346834 "2023-11-10T06:08:37Z")

</div>

Hi all, How to ingest kafka syslog to elasticsearch or kibana? I'm using elasticsearch and Kibana of 8.10.4 version. I want to visualize kafka syslogs on kibana dashboards. But I don't know how to push or integrate the…

---

## [Set "index.mapping.dimension\_fields.limit" does not work](https://discuss.elastic.co/t/set-index-mapping-dimension-fields-limit-does-not-work/346330)

<div class="topic-metadata">

**Author:** [@VietDuc](https://discuss.elastic.co/u/VietDuc)\
**Replies:** 1\
**Last updated:** [November 10, 2023, 3:39am UTC](https://discuss.elastic.co/t/set-index-mapping-dimension-fields-limit-does-not-work/346330 "2023-11-10T03:39:59Z")

</div>

Hi everyone, We would like to extend the number of dimension\_fields of our TSDS by POST \_index\_template/ds-micrometer-metrics-prod { "index\_patterns": \[ "micrometer" \], "data\_stream": {}, "template": { …

---

## [Kibana bouncing degraded - available](https://discuss.elastic.co/t/kibana-bouncing-degraded-available/346685)

<div class="topic-metadata">

**Author:** [@wrsnrno](https://discuss.elastic.co/u/wrsnrno)\
**Replies:** 4\
**Last updated:** [November 10, 2023, 1:06am UTC](https://discuss.elastic.co/t/kibana-bouncing-degraded-available/346685 "2023-11-10T01:06:28Z")

</div>

Would appreciate some points in the right direction here. I have a new stack up and running but Kibana is bouncing availalbe - degraded, frequently but not at regular intervals. The environment is new, (so am I to Elas…

---

## [Sorting results not working properly](https://discuss.elastic.co/t/sorting-results-not-working-properly/346816)

<div class="topic-metadata">

**Author:** [@Mubolio](https://discuss.elastic.co/u/Mubolio)\
**Replies:** 1\
**Last updated:** [November 9, 2023, 11:27pm UTC](https://discuss.elastic.co/t/sorting-results-not-working-properly/346816 "2023-11-09T23:27:38Z")

</div>

Hello, I have a datastream that is updated often, I want to get unique results for the field @timestamp, I use this query: GET datastream\_name/\_search { "sort" : \[ { "@timestamp" : { "order":"desc…

---

## [Prune filter does not work with whitelist but it does with blacklist](https://discuss.elastic.co/t/prune-filter-does-not-work-with-whitelist-but-it-does-with-blacklist/346549)

<div class="topic-metadata">

**Author:** [@elk-user-0001](https://discuss.elastic.co/u/elk-user-0001)\
**Replies:** 1\
**Last updated:** [November 9, 2023, 8:11pm UTC](https://discuss.elastic.co/t/prune-filter-does-not-work-with-whitelist-but-it-does-with-blacklist/346549 "2023-11-09T20:11:15Z")

</div>

Hello colleagues! I am trying to use the prune filter with first level fields ( I know the problem with nested fields ) but I can't get it to work. I have a json of 900 fields and I am interested in keeping only a few,…

---

## [Using Key-value(KV) with multiple Value splits](https://discuss.elastic.co/t/using-key-value-kv-with-multiple-value-splits/346527)

<div class="topic-metadata">

**Author:** [@robnew](https://discuss.elastic.co/u/robnew)\
**Replies:** 6\
**Last updated:** [November 9, 2023, 7:53pm UTC](https://discuss.elastic.co/t/using-key-value-kv-with-multiple-value-splits/346527 "2023-11-09T19:53:20Z")

</div>

I have a wineventlog-application log which has (ie) 'EventCode=33210 EventRecordID=12345' then changes to session\_id:69,server\_principal\_id:226,etc etc so from = to : with , instead of spaces. Is there a way I can use th…

---

## [Mapping Geospatial Time Events](https://discuss.elastic.co/t/mapping-geospatial-time-events/345958)

<div class="topic-metadata">

**Author:** [@Cal](https://discuss.elastic.co/u/Cal)\
**Replies:** 5\
**Last updated:** [November 9, 2023, 6:20pm UTC](https://discuss.elastic.co/t/mapping-geospatial-time-events/345958 "2023-11-09T18:20:25Z")

</div>

I have an index wherein one of the pieces of data is the date a last even occurred as well as location. Using geospatial I want to map the events occurring based on the dates assigned to each document. I want to use th…

---

## [Search for any error exceptions or any specific string in a log file which is pushed from client machine using filebeat agent to Elastic stack server](https://discuss.elastic.co/t/search-for-any-error-exceptions-or-any-specific-string-in-a-log-file-which-is-pushed-from-client-machine-using-filebeat-agent-to-elastic-stack-server/346534)

<div class="topic-metadata">

**Author:** [@kaushalshriyan](https://discuss.elastic.co/u/kaushalshriyan)\
**Replies:** 7\
**Last updated:** [November 9, 2023, 6:09pm UTC](https://discuss.elastic.co/t/search-for-any-error-exceptions-or-any-specific-string-in-a-log-file-which-is-pushed-from-client-machine-using-filebeat-agent-to-elastic-stack-server/346534 "2023-11-09T18:09:12Z")

</div>

Hi, I have this log file /opt/apigee/var/log/edge-message-processor/messagelogging/apigee-dac-training/test/sf-response-parameters/6/log-api/elk.log which is seen in the kibana dashboard. I am searching for a specific s…

---

## [Fingerprint for json does not get resolved](https://discuss.elastic.co/t/fingerprint-for-json-does-not-get-resolved/346772)

<div class="topic-metadata">

**Author:** [@ranjini](https://discuss.elastic.co/u/ranjini)\
**Replies:** 9\
**Last updated:** [November 9, 2023, 5:12pm UTC](https://discuss.elastic.co/t/fingerprint-for-json-does-not-get-resolved/346772 "2023-11-09T17:12:08Z")

</div>

fingerprint for json is not working input { file { path =\> "/shared/logs/logi2/stats.\*" start\_position =\> "beginning" sincedb\_path =\> "/shared/logs/.sincedb" type =\> "logi2-stats" …

---

## [Showing query parameters in DSL query results](https://discuss.elastic.co/t/showing-query-parameters-in-dsl-query-results/345758)

<div class="topic-metadata">

**Author:** [@bgyomorei\_c](https://discuss.elastic.co/u/bgyomorei_c)\
**Replies:** 1\
**Last updated:** [November 9, 2023, 5:00pm UTC](https://discuss.elastic.co/t/showing-query-parameters-in-dsl-query-results/345758 "2023-11-09T17:00:10Z")

</div>

Let's take the DSL query example below. I'd like to see the value of fixed\_interval in date\_histogram in the generated response. Is it possible to tell in the DSL query to display this or any parameter value in the resul…

---

## [Understanding search-as-you-type Fields](https://discuss.elastic.co/t/understanding-search-as-you-type-fields/346661)

<div class="topic-metadata">

**Author:** [@safakkbilici](https://discuss.elastic.co/u/safakkbilici)\
**Replies:** 2\
**Last updated:** [November 9, 2023, 4:36pm UTC](https://discuss.elastic.co/t/understanding-search-as-you-type-fields/346661 "2023-11-09T16:36:43Z")

</div>

Hello community, I am using ES on my local machine with version of 8.10.4 I was experimenting with search-as-you-type lately and I am confused by ".\_2gram" and ".\_3gram" fields. I created a basic index as PUT autosugg…

---

## [Same shards on different physicals servers](https://discuss.elastic.co/t/same-shards-on-different-physicals-servers/346768)

<div class="topic-metadata">

**Author:** [@daniela09](https://discuss.elastic.co/u/daniela09)\
**Replies:** 7\
**Last updated:** [November 9, 2023, 4:01pm UTC](https://discuss.elastic.co/t/same-shards-on-different-physicals-servers/346768 "2023-11-09T16:01:04Z")

</div>

Hi I have deployed EFK stack on Kubernetes cluster, I have 3 nodes that have both roles data and master, the 3 Elasticsearch nodes are on 3 different Kubernetes nodes, but the Kubernetes nodes are on 2 different physical…

---

## [How to know wich grok is failing?](https://discuss.elastic.co/t/how-to-know-wich-grok-is-failing/346535)

<div class="topic-metadata">

**Author:** [@ElasticLiver](https://discuss.elastic.co/u/ElasticLiver)\
**Replies:** 2\
**Last updated:** [November 9, 2023, 3:46pm UTC](https://discuss.elastic.co/t/how-to-know-wich-grok-is-failing/346535 "2023-11-09T15:46:11Z")

</div>

Hi, Im reviewing the pipeline of an ex colleague, and there is almos 30 grok filters, wich will be the best way to identify wich grok is failing? Im using stdout in the output. Thanks!

---

## [Metric Threshold Alert reporting incorrect document count](https://discuss.elastic.co/t/metric-threshold-alert-reporting-incorrect-document-count/346553)

<div class="topic-metadata">

**Author:** [@vsabado](https://discuss.elastic.co/u/vsabado)\
**Replies:** 32\
**Last updated:** [November 9, 2023, 3:34pm UTC](https://discuss.elastic.co/t/metric-threshold-alert-reporting-incorrect-document-count/346553 "2023-11-09T15:34:20Z")

</div>

I have a metric threshold alert that will trigger when document count is above 30. This alert seems to trigger just fine. For the body I'm setting this: And this is the data that I get back when the alert fires up: {…

---

## [Azure EventHub Plugin for Logstash Errors](https://discuss.elastic.co/t/azure-eventhub-plugin-for-logstash-errors/346811)

<div class="topic-metadata">

**Author:** [@Kris\_Felscher](https://discuss.elastic.co/u/Kris_Felscher)\
**Replies:** 0\
**Last updated:** [November 9, 2023, 2:42pm UTC](https://discuss.elastic.co/t/azure-eventhub-plugin-for-logstash-errors/346811 "2023-11-09T14:42:49Z")

</div>

We have Logstash installed on Kubernetes running on 2 pods. My main pipeline is configured to receive events from 2 separate EventHub instances. Here's my Pipeline Input: input { azure\_event\_hubs { config\_m…

---

## [Why should we not use Metricbeat with scope: node for clusters with dedicated master nodes](https://discuss.elastic.co/t/why-should-we-not-use-metricbeat-with-scope-node-for-clusters-with-dedicated-master-nodes/346715)

<div class="topic-metadata">

**Author:** [@bunste](https://discuss.elastic.co/u/bunste)\
**Replies:** 9\
**Last updated:** [November 9, 2023, 1:35pm UTC](https://discuss.elastic.co/t/why-should-we-not-use-metricbeat-with-scope-node-for-clusters-with-dedicated-master-nodes/346715 "2023-11-09T13:35:36Z")

</div>

I am currently reading the documentation on collecting Elasticsearch monitoring data with Metricbeat. I had already posted something about this here in the forum, which led to this issue. The documentation has improved s…

---

## [How to improve fuzzy match performance](https://discuss.elastic.co/t/how-to-improve-fuzzy-match-performance/346794)

<div class="topic-metadata">

**Author:** [@chengyang.backend](https://discuss.elastic.co/u/chengyang.backend)\
**Replies:** 1\
**Last updated:** [November 9, 2023, 1:19pm UTC](https://discuss.elastic.co/t/how-to-improve-fuzzy-match-performance/346794 "2023-11-09T13:19:22Z")

</div>

---

## [Watcher log history not available for some watchers scripts](https://discuss.elastic.co/t/watcher-log-history-not-available-for-some-watchers-scripts/346795)

<div class="topic-metadata">

**Author:** [@Seemant\_Bind](https://discuss.elastic.co/u/Seemant_Bind)\
**Replies:** 0\
**Last updated:** [November 9, 2023, 12:48pm UTC](https://discuss.elastic.co/t/watcher-log-history-not-available-for-some-watchers-scripts/346795 "2023-11-09T12:48:29Z")

</div>

Hi, I am currently facing issue with the watcher logs, currently I am using ELK version 7.11 and when I check Execution history of some watcher for last 1 hour, 1 day or even last week , no logs are available. For few w…

---

## [Cloudflare integration not working](https://discuss.elastic.co/t/cloudflare-integration-not-working/346024)

<div class="topic-metadata">

**Author:** [@theacodes](https://discuss.elastic.co/u/theacodes)\
**Replies:** 7\
**Last updated:** [November 9, 2023, 12:28pm UTC](https://discuss.elastic.co/t/cloudflare-integration-not-working/346024 "2023-11-09T12:28:41Z")

</div>

I added this integration and entered all the required key and creds needed. still I am not getting any logs from cloudflare and the dashboard and saved search both are empty. what am I missing?

---

## [Unable to scale down ECK-managed cluster](https://discuss.elastic.co/t/unable-to-scale-down-eck-managed-cluster/346790)

<div class="topic-metadata">

**Author:** [@Philipp\_B](https://discuss.elastic.co/u/Philipp_B)\
**Replies:** 0\
**Last updated:** [November 9, 2023, 12:21pm UTC](https://discuss.elastic.co/t/unable-to-scale-down-eck-managed-cluster/346790 "2023-11-09T12:21:03Z")

</div>

Hi, we're running an ECK 1.7.1, Elastic 7.14.1 cluster with 3 nodes on an Azure Kubernetes cluster (v 1.26.6). The cluster is generally running fine. Now, in order to test scaling scenarios, we expanded the cluster to 6…

---

## [Single file indexing with multiple docs in es](https://discuss.elastic.co/t/single-file-indexing-with-multiple-docs-in-es/346785)

<div class="topic-metadata">

**Author:** [@ravikiran\_gunda](https://discuss.elastic.co/u/ravikiran_gunda)\
**Replies:** 0\
**Last updated:** [November 9, 2023, 11:56am UTC](https://discuss.elastic.co/t/single-file-indexing-with-multiple-docs-in-es/346785 "2023-11-09T11:56:44Z")

</div>

Hi Everyone, I have one large file and I indexed but that large file created multiple docs in Elasticsearch with myid+sequence no. so is there anyway to create multiple docs under single id, why i am asking is while sear…

---

## [Kibana visualisation requirement to get failed count of documents uploaded](https://discuss.elastic.co/t/kibana-visualisation-requirement-to-get-failed-count-of-documents-uploaded/346777)

<div class="topic-metadata">

**Author:** [@Sanjana\_Nalam](https://discuss.elastic.co/u/Sanjana_Nalam)\
**Replies:** 0\
**Last updated:** [November 9, 2023, 10:54am UTC](https://discuss.elastic.co/t/kibana-visualisation-requirement-to-get-failed-count-of-documents-uploaded/346777 "2023-11-09T10:54:38Z")

</div>

Dear community, We have a requirement where we will determine if the file is successfully uploaded or not based on the doc id, if doc id =-1 then the document is not uploaded and if doc id is other than that document is…

[Previous page](https://discuss.elastic.co/tag/none.md?no_tags=true&page=274)

[Next page](https://discuss.elastic.co/tag/none.md?no_tags=true&page=276)
