# \#none

**URL:** https://discuss.elastic.co/tag/none.md?no_tags=true&page=277

[Latest](https://discuss.elastic.co/latest.md) · [Categories](https://discuss.elastic.co/categories.md) · [Tags](https://discuss.elastic.co/tags.md)

**Page:** 278

---

## [Creating JSON structure for sensor.community API](https://discuss.elastic.co/t/creating-json-structure-for-sensor-community-api/346470)

<div class="topic-metadata">

**Author:** [@CargoBikoMeter](https://discuss.elastic.co/u/CargoBikoMeter)\
**Replies:** 8\
**Last updated:** [November 7, 2023, 11:47am UTC](https://discuss.elastic.co/t/creating-json-structure-for-sensor-community-api/346470 "2023-11-07T11:47:54Z")

</div>

I will send data from my logstash pipeline to the sensor.community API. The API requires the following structure which works with my curl command: curl --location --request POST 'https://api.sensor.community/v1/push-sen…

---

## [Getting 401 first time and able to login in same session in second attempt](https://discuss.elastic.co/t/getting-401-first-time-and-able-to-login-in-same-session-in-second-attempt/346524)

<div class="topic-metadata">

**Author:** [@amitkumar.gupta](https://discuss.elastic.co/u/amitkumar.gupta)\
**Replies:** 3\
**Last updated:** [November 7, 2023, 11:42am UTC](https://discuss.elastic.co/t/getting-401-first-time-and-able-to-login-in-same-session-in-second-attempt/346524 "2023-11-07T11:42:53Z")

</div>

I am implementing SSO with elastic/Kibana. and using Wso2 credential to login. When i login first time, i see 401, below is the curl i can copy from browser. curl 'http://server1.local:5601/api/security/oidc/callback?c…

---

## [Supporting Exact Search while obeying punctuations using ES](https://discuss.elastic.co/t/supporting-exact-search-while-obeying-punctuations-using-es/346604)

<div class="topic-metadata">

**Author:** [@prakharchaube](https://discuss.elastic.co/u/prakharchaube)\
**Replies:** 0\
**Last updated:** [November 7, 2023, 9:22am UTC](https://discuss.elastic.co/t/supporting-exact-search-while-obeying-punctuations-using-es/346604 "2023-11-07T09:22:36Z")

</div>

Hi folks, I am new to ES and was stuck at something so seeking help! I have a search requirement where I need to get results for "Exact Matches". Consider it similar to Google's double quote search but only on content…

---

## [I'm working on new community beat](https://discuss.elastic.co/t/im-working-on-new-community-beat/346190)

<div class="topic-metadata">

**Author:** [@zeynepyz](https://discuss.elastic.co/u/zeynepyz)\
**Replies:** 7\
**Last updated:** [November 7, 2023, 8:12am UTC](https://discuss.elastic.co/t/im-working-on-new-community-beat/346190 "2023-11-07T08:12:35Z")

</div>

Hello, i'm working on new project that collecting metrics from k6 via restAPI and indexes them then sending them to elasticsearch by beats. I just wonder if anyone working on this?

---

## [Change path.data in elasticsearh cluster node](https://discuss.elastic.co/t/change-path-data-in-elasticsearh-cluster-node/346596)

<div class="topic-metadata">

**Author:** [@Frances\_Chu](https://discuss.elastic.co/u/Frances_Chu)\
**Replies:** 0\
**Last updated:** [November 7, 2023, 7:07am UTC](https://discuss.elastic.co/t/change-path-data-in-elasticsearh-cluster-node/346596 "2023-11-07T07:07:26Z")

</div>

May I got 3 node elasticsearch cluster. Is it possible to change the path.data If yes. What is the recommended procedure?

---

## [Extend the size of ElasticSearch path.data](https://discuss.elastic.co/t/extend-the-size-of-elasticsearch-path-data/346595)

<div class="topic-metadata">

**Author:** [@Frances\_Chu](https://discuss.elastic.co/u/Frances_Chu)\
**Replies:** 0\
**Last updated:** [November 7, 2023, 7:04am UTC](https://discuss.elastic.co/t/extend-the-size-of-elasticsearch-path-data/346595 "2023-11-07T07:04:00Z")

</div>

I got a elasticsearch cluster with 3 nodes. Each node got a path.data (size 5T) Which is a virtual harddisk. I would like to know is it possible to enlarge the disk storage by extend the virtual disk to 10T. If it is …

---

## [Kibana Timeseries or Area chart to split chart on two fileds value](https://discuss.elastic.co/t/kibana-timeseries-or-area-chart-to-split-chart-on-two-fileds-value/346497)

<div class="topic-metadata">

**Author:** [@PRASHANT\_MEHTA](https://discuss.elastic.co/u/PRASHANT_MEHTA)\
**Replies:** 1\
**Last updated:** [November 7, 2023, 3:43am UTC](https://discuss.elastic.co/t/kibana-timeseries-or-area-chart-to-split-chart-on-two-fileds-value/346497 "2023-11-07T03:43:07Z")

</div>

Hello All, I have a requirement for below data and not sure which visual could achieve the requirement properly.Ideal requirement is of Timeseries using TSVB or someother visual also fine.Plz let know if this is possibl…

---

## [Curl ssl error to elasticsearch server via filebeat](https://discuss.elastic.co/t/curl-ssl-error-to-elasticsearch-server-via-filebeat/346420)

<div class="topic-metadata">

**Author:** [@baber1223](https://discuss.elastic.co/u/baber1223)\
**Replies:** 2\
**Last updated:** [November 7, 2023, 4:52am UTC](https://discuss.elastic.co/t/curl-ssl-error-to-elasticsearch-server-via-filebeat/346420 "2023-11-07T04:52:57Z")

</div>

This is my filebeat output test : filebeat test output elasticsearch: https://172.10.110.29:9200... parse url... OK connection... parse host... OK dns lookup... OK addresses: 172.10.110.29 dial up..…

---

## [Elastic SQL CLI Error](https://discuss.elastic.co/t/elastic-sql-cli-error/345905)

<div class="topic-metadata">

**Author:** [@Debasis\_Mallick](https://discuss.elastic.co/u/Debasis_Mallick)\
**Replies:** 6\
**Last updated:** [November 7, 2023, 4:46am UTC](https://discuss.elastic.co/t/elastic-sql-cli-error/345905 "2023-11-07T04:46:29Z")

</div>

HI Team, I am able to connect to Elastic sql CLI but while querying the index data getting below error. Could you please help me on this. sql\> select \* from employee; Communication error \[Cannot POST address http://1…

---

## [Use search or scroll for large dataset which needs aggregations](https://discuss.elastic.co/t/use-search-or-scroll-for-large-dataset-which-needs-aggregations/346578)

<div class="topic-metadata">

**Author:** [@nboisnea1](https://discuss.elastic.co/u/nboisnea1)\
**Replies:** 0\
**Last updated:** [November 6, 2023, 10:45pm UTC](https://discuss.elastic.co/t/use-search-or-scroll-for-large-dataset-which-needs-aggregations/346578 "2023-11-06T22:45:38Z")

</div>

Hi! I'm new to Elasticsearch and I have a particular use case for which I don't know if I should use a basic search or a scroll search. I have an index in which I periodically save a copy of JSON documents. Each JSON do…

---

## [Configure Remote Clusters](https://discuss.elastic.co/t/configure-remote-clusters/346571)

<div class="topic-metadata">

**Author:** [@biancoda](https://discuss.elastic.co/u/biancoda)\
**Replies:** 0\
**Last updated:** [November 6, 2023, 9:18pm UTC](https://discuss.elastic.co/t/configure-remote-clusters/346571 "2023-11-06T21:18:17Z")

</div>

So, I'm trying to configure the remote cluster connections. But I believe I'm missing something. I'm following this instructions: Remote clusters | Elastic Cloud on Kubernetes \[2.9\] | Elastic I have 2 different ES cl…

---

## [Connection reset by peer](https://discuss.elastic.co/t/connection-reset-by-peer/346570)

<div class="topic-metadata">

**Author:** [@milindyedge](https://discuss.elastic.co/u/milindyedge)\
**Replies:** 0\
**Last updated:** [November 6, 2023, 8:58pm UTC](https://discuss.elastic.co/t/connection-reset-by-peer/346570 "2023-11-06T20:58:22Z")

</div>

We are using Elasticsearch cloud version. We are connecting to Elasticsearch cloud using Elasticsearch java api client. However, we are getting "IOException : connection reset by peer" error randomly. It seems this error…

---

## [My Elasticsearch experiences freezing 3 to 4 times a day](https://discuss.elastic.co/t/my-elasticsearch-experiences-freezing-3-to-4-times-a-day/346438)

<div class="topic-metadata">

**Author:** [@ihatecrypto](https://discuss.elastic.co/u/ihatecrypto)\
**Replies:** 9\
**Last updated:** [November 6, 2023, 8:39pm UTC](https://discuss.elastic.co/t/my-elasticsearch-experiences-freezing-3-to-4-times-a-day/346438 "2023-11-06T20:39:49Z")

</div>

Hello everyone, I'm currently facing an issue that's not well defined. . The freezing periods last approximately 30 to 60 seconds. During these periods, I'm unable to query it using Kibana or the Nodejs client. I've…

---

## [Variables and subfields](https://discuss.elastic.co/t/variables-and-subfields/346554)

<div class="topic-metadata">

**Author:** [@B-Rad](https://discuss.elastic.co/u/B-Rad)\
**Replies:** 0\
**Last updated:** [November 6, 2023, 7:01pm UTC](https://discuss.elastic.co/t/variables-and-subfields/346554 "2023-11-06T19:01:16Z")

</div>

When working with alerts and using variables in the connectors, is if possible to only use a subset of the data in my notifications? For example, the field name is details, but this field looks to contain its own json d…

---

## [Sorting when scoring documents with child function\_score](https://discuss.elastic.co/t/sorting-when-scoring-documents-with-child-function-score/346551)

<div class="topic-metadata">

**Author:** [@AngX](https://discuss.elastic.co/u/AngX)\
**Replies:** 0\
**Last updated:** [November 6, 2023, 6:28pm UTC](https://discuss.elastic.co/t/sorting-when-scoring-documents-with-child-function-score/346551 "2023-11-06T18:28:45Z")

</div>

Hi all, Running into a tricky requirement when it comes to sorting in search so would appreciate getting some thoughts or advice on the matter We have two collections of documents set with a join. The child documents h…

---

## [Plugin \[analysis-icu\] was built for Elasticsearch version 8.5.0 but version 8.9.1 is running](https://discuss.elastic.co/t/plugin-analysis-icu-was-built-for-elasticsearch-version-8-5-0-but-version-8-9-1-is-running/346062)

<div class="topic-metadata">

**Author:** [@lanz](https://discuss.elastic.co/u/lanz)\
**Replies:** 5\
**Last updated:** [November 6, 2023, 5:26pm UTC](https://discuss.elastic.co/t/plugin-analysis-icu-was-built-for-elasticsearch-version-8-5-0-but-version-8-9-1-is-running/346062 "2023-11-06T17:26:15Z")

</div>

Hello, I am trying to upgrade the ELK from 8.5.0 to 8.9.1 version, Once installed 8.9.1 version, I need to install the analysis-icu\] plug-in . Therefore I have followed the steps of this link ICU analysis plugin | Elas…

---

## [Server-client search architecture with PIT in ElasticSearch](https://discuss.elastic.co/t/server-client-search-architecture-with-pit-in-elasticsearch/346545)

<div class="topic-metadata">

**Author:** [@forceson](https://discuss.elastic.co/u/forceson)\
**Replies:** 0\
**Last updated:** [November 6, 2023, 4:41pm UTC](https://discuss.elastic.co/t/server-client-search-architecture-with-pit-in-elasticsearch/346545 "2023-11-06T16:41:58Z")

</div>

I want to use search\_after and PIT to provide consistent search results. The guide documentation suggests that PITs should be generated in the background and utilized after each search, rather than after every search. M…

---

## [SNMP with Logstash (Pipeline Error)](https://discuss.elastic.co/t/snmp-with-logstash-pipeline-error/346533)

<div class="topic-metadata">

**Author:** [@Funkster](https://discuss.elastic.co/u/Funkster)\
**Replies:** 2\
**Last updated:** [November 6, 2023, 4:03pm UTC](https://discuss.elastic.co/t/snmp-with-logstash-pipeline-error/346533 "2023-11-06T16:03:19Z")

</div>

Hello, I am trying to get SNMP-Loggin to work whithin ELK in Logstash and I get the following Error: root@vm-kibana:~# /usr/share/logstash/bin/logstash -f /etc/logstash/conf.d/logstash-snmp.conf --path.settings=/etc/lo…

---

## [Multiple Pipelines with condition](https://discuss.elastic.co/t/multiple-pipelines-with-condition/346405)

<div class="topic-metadata">

**Author:** [@Manasa4](https://discuss.elastic.co/u/Manasa4)\
**Replies:** 4\
**Last updated:** [November 6, 2023, 3:44pm UTC](https://discuss.elastic.co/t/multiple-pipelines-with-condition/346405 "2023-11-06T15:44:20Z")

</div>

Hi Team, I have been trying to add a condition on my multi processor pipeline. { "4modelprocessor\_peopleagg": { "processors": \[ { "pipeline": { "name": "ner\_pipeline\_peopleagg" } }, { "pipeline": { "name": "e…

---

## [Advance logic alter rules (if "A" happens look for "B"](https://discuss.elastic.co/t/advance-logic-alter-rules-if-a-happens-look-for-b/346529)

<div class="topic-metadata">

**Author:** [@B-Rad](https://discuss.elastic.co/u/B-Rad)\
**Replies:** 0\
**Last updated:** [November 6, 2023, 1:50pm UTC](https://discuss.elastic.co/t/advance-logic-alter-rules-if-a-happens-look-for-b/346529 "2023-11-06T13:50:31Z")

</div>

When creating an alert rule is it possible to add some more advanced logic or additional criteria if the first query is triggered? For example, I have authentication logs from our Idp I have an alert rule set for pot…

---

## [Clearing the search context manually after reindexing is done](https://discuss.elastic.co/t/clearing-the-search-context-manually-after-reindexing-is-done/346517)

<div class="topic-metadata">

**Author:** [@Achyut\_Muley](https://discuss.elastic.co/u/Achyut_Muley)\
**Replies:** 0\
**Last updated:** [November 6, 2023, 11:28am UTC](https://discuss.elastic.co/t/clearing-the-search-context-manually-after-reindexing-is-done/346517 "2023-11-06T11:28:36Z")

</div>

We have a shell script which takes the name of an index and then reindexes it. We are using ES 7.17.0 The reindex command- response=$(curl -u $CREDENTIALS -X POST "$PROTOCOL://$HOST:9200/\_reindex?slices=50&refresh&wai…

---

## [About ES8.10.4 pytorch\_inference](https://discuss.elastic.co/t/about-es8-10-4-pytorch-inference/346513)

<div class="topic-metadata">

**Author:** [@jaeho](https://discuss.elastic.co/u/jaeho)\
**Replies:** 0\
**Last updated:** [November 6, 2023, 10:37am UTC](https://discuss.elastic.co/t/about-es8-10-4-pytorch-inference/346513 "2023-11-06T10:37:31Z")

</div>

Hello, I'm using Elasticsearch 8.10.4. I'm aiming to perform vector searches using a custom model through eland. You can find more details on this at NLP를 배포하는 방법: 텍스트 임베딩 및 벡터 검색 | Elastic Blog. I'm facing a long inde…

---

## [Metricbeat readiness for production, and how to configure the MSI package?](https://discuss.elastic.co/t/metricbeat-readiness-for-production-and-how-to-configure-the-msi-package/346511)

<div class="topic-metadata">

**Author:** [@mshwf](https://discuss.elastic.co/u/mshwf)\
**Replies:** 0\
**Last updated:** [November 6, 2023, 10:15am UTC](https://discuss.elastic.co/t/metricbeat-readiness-for-production-and-how-to-configure-the-msi-package/346511 "2023-11-06T10:15:54Z")

</div>

I want to use Metricbeat to instrument one of our services. Firstly, I tried APM, but found we can't use it with custom metrics (our counters, gauges... etc.). So, I'm having a look at Metricbeat, it seems to offer what …

---

## [Sending cisco switch logs to elasticsearch](https://discuss.elastic.co/t/sending-cisco-switch-logs-to-elasticsearch/346458)

<div class="topic-metadata">

**Author:** [@laale1](https://discuss.elastic.co/u/laale1)\
**Replies:** 2\
**Last updated:** [November 6, 2023, 9:39am UTC](https://discuss.elastic.co/t/sending-cisco-switch-logs-to-elasticsearch/346458 "2023-11-06T09:39:36Z")

</div>

Hello community. I want to send my cisco switches logs to Elasticsearch, and we can't install elastic agent or beats to switches so what are the best ways we can send those logs to the elasticsearch.

---

## [Boolean should query wrong result](https://discuss.elastic.co/t/boolean-should-query-wrong-result/346381)

<div class="topic-metadata">

**Author:** [@Lukas\_Cern](https://discuss.elastic.co/u/Lukas_Cern)\
**Replies:** 1\
**Last updated:** [November 6, 2023, 9:14am UTC](https://discuss.elastic.co/t/boolean-should-query-wrong-result/346381 "2023-11-06T09:14:47Z")

</div>

Depending on order of queries, there is no match (wrong) or there is a match (correct). This wrong behavior is only the case of queryes containing one of synonyms. This is my index, data and explain queries: PUT /pokus…

---

## [Best practice for adding/complement additional data to existing documents](https://discuss.elastic.co/t/best-practice-for-adding-complement-additional-data-to-existing-documents/346498)

<div class="topic-metadata">

**Author:** [@daniel-san](https://discuss.elastic.co/u/daniel-san)\
**Replies:** 0\
**Last updated:** [November 6, 2023, 8:32am UTC](https://discuss.elastic.co/t/best-practice-for-adding-complement-additional-data-to-existing-documents/346498 "2023-11-06T08:32:12Z")

</div>

Hello there, we're only scratched the surface regarding the possibilities in Elasticsearch so the following question/example might be pretty basic: In our example we have multiple Hosts (VDI Workplaces) that are tied/o…

---

## [Could you please delete my account?](https://discuss.elastic.co/t/could-you-please-delete-my-account/346484)

<div class="topic-metadata">

**Author:** [@anon69830709](https://discuss.elastic.co/u/anon69830709)\
**Replies:** 2\
**Last updated:** [November 6, 2023, 8:07am UTC](https://discuss.elastic.co/t/could-you-please-delete-my-account/346484 "2023-11-06T08:07:49Z")

</div>

Could you please delete my account from the forum?

---

## [Queries regarding logsatsh configuration file](https://discuss.elastic.co/t/queries-regarding-logsatsh-configuration-file/346491)

<div class="topic-metadata">

**Author:** [@Ajay\_Kumar.S](https://discuss.elastic.co/u/Ajay_Kumar.S)\
**Replies:** 0\
**Last updated:** [November 6, 2023, 6:16am UTC](https://discuss.elastic.co/t/queries-regarding-logsatsh-configuration-file/346491 "2023-11-06T06:16:45Z")

</div>

input { beats { port =\> "9006" } } filter { mutate { add\_field =\> { "beat\_version" =\> "%{\[beat\]\[version\]}" } } mutate { add\_field =\> { "log\_file" =\> "%{\[log\]\[file\]\[path\]}" } } mutate { add\_field =\> { "beat\_…

---

## [How to list top 5 IPs with their total usage in Mega Byte](https://discuss.elastic.co/t/how-to-list-top-5-ips-with-their-total-usage-in-mega-byte/346490)

<div class="topic-metadata">

**Author:** [@Indunil75](https://discuss.elastic.co/u/Indunil75)\
**Replies:** 0\
**Last updated:** [November 6, 2023, 5:54am UTC](https://discuss.elastic.co/t/how-to-list-top-5-ips-with-their-total-usage-in-mega-byte/346490 "2023-11-06T05:54:32Z")

</div>

Hi Users, I have setup fortigate firewall with logstash, Elasticsearch and Kibana. It woks fine. In kibana, Dashboard, How to list top 5 IPs with their total usage in Mega Byte. How can I achieve it? Hope to hear from…

---

## [ELK v 7.6.0 Paloalto take certain types of logs](https://discuss.elastic.co/t/elk-v-7-6-0-paloalto-take-certain-types-of-logs/346479)

<div class="topic-metadata">

**Author:** [@juancamiloll](https://discuss.elastic.co/u/juancamiloll)\
**Replies:** 2\
**Last updated:** [November 6, 2023, 5:12am UTC](https://discuss.elastic.co/t/elk-v-7-6-0-paloalto-take-certain-types-of-logs/346479 "2023-11-06T05:12:42Z")

</div>

Hello I am working with ELK v 7.6.0 I have asked the paloalto firewall administrator to send me the logs via Syslog on port 514 to my server where I have ELK. In the linux operating system in the path /etc/ the file r…

[Previous page](https://discuss.elastic.co/tag/none.md?no_tags=true&page=276)

[Next page](https://discuss.elastic.co/tag/none.md?no_tags=true&page=278)
