# \#none

**URL:** https://discuss.elastic.co/tag/none.md?no_tags=true&page=280

[Latest](https://discuss.elastic.co/latest.md) · [Categories](https://discuss.elastic.co/categories.md) · [Tags](https://discuss.elastic.co/tags.md)

**Page:** 281

---

## [Timestamp from log files to @timestamp](https://discuss.elastic.co/t/timestamp-from-log-files-to-timestamp/346199)

<div class="topic-metadata">

**Author:** [@libertey](https://discuss.elastic.co/u/libertey)\
**Replies:** 4\
**Last updated:** [November 1, 2023, 2:39pm UTC](https://discuss.elastic.co/t/timestamp-from-log-files-to-timestamp/346199 "2023-11-01T14:39:12Z")

</div>

Hey, !NOTE! i'm new to the elk stack in all its facettes. I have some Problems with displaying my logfiles from an laravel application. I'm running laravel on one server and my elk stack on another i installed logstas…

---

## [Elastic Agent upgrade through Fleet and using Custom Agent Binary Source](https://discuss.elastic.co/t/elastic-agent-upgrade-through-fleet-and-using-custom-agent-binary-source/346206)

<div class="topic-metadata">

**Author:** [@hamidallaoui](https://discuss.elastic.co/u/hamidallaoui)\
**Replies:** 0\
**Last updated:** [November 1, 2023, 2:16pm UTC](https://discuss.elastic.co/t/elastic-agent-upgrade-through-fleet-and-using-custom-agent-binary-source/346206 "2023-11-01T14:16:32Z")

</div>

Hi All, Did someone already test to upgrade Elastic Agent through Fleet and using Custom Agent Binary Source ? We tried from our side by giving url of reverse proxy (Nginx) but it did not work. Thank you for your feed…

---

## [Kibana search fails to find string](https://discuss.elastic.co/t/kibana-search-fails-to-find-string/346163)

<div class="topic-metadata">

**Author:** [@ChazJaz](https://discuss.elastic.co/u/ChazJaz)\
**Replies:** 2\
**Last updated:** [November 1, 2023, 2:02pm UTC](https://discuss.elastic.co/t/kibana-search-fails-to-find-string/346163 "2023-11-01T14:02:51Z")

</div>

When I try a simple KQL search for the character pattern: message: "}\]}}}" it finds no results even though I can see that string pattern in some entries of an unfiltered query of my data stream. According to the KQL do…

---

## [Log4j2 Rolling File Strategy Only Rolls Once](https://discuss.elastic.co/t/log4j2-rolling-file-strategy-only-rolls-once/345320)

<div class="topic-metadata">

**Author:** [@Kris\_Felscher](https://discuss.elastic.co/u/Kris_Felscher)\
**Replies:** 4\
**Last updated:** [November 1, 2023, 1:48pm UTC](https://discuss.elastic.co/t/log4j2-rolling-file-strategy-only-rolls-once/345320 "2023-11-01T13:48:40Z")

</div>

I'm having issues with the log4j2 rolling file appender. It only writes the first rollover file. Here's my config: status = error name = LogstashPropertiesConfig appender.console.type = Console appender.console.name =…

---

## [Configure Fleet SSL Cert Port 8220](https://discuss.elastic.co/t/configure-fleet-ssl-cert-port-8220/346157)

<div class="topic-metadata">

**Author:** [@sourcreamnormanbates](https://discuss.elastic.co/u/sourcreamnormanbates)\
**Replies:** 2\
**Last updated:** [November 1, 2023, 12:49pm UTC](https://discuss.elastic.co/t/configure-fleet-ssl-cert-port-8220/346157 "2023-11-01T12:49:36Z")

</div>

I have deployed a Fleet server and I want to change the SSL cert that is being used. Is there a config file somewhere that I can modify to use the certificates that I generated? I want to avoid having to use the --inse…

---

## [Create an Observability alert with a watch](https://discuss.elastic.co/t/create-an-observability-alert-with-a-watch/346195)

<div class="topic-metadata">

**Author:** [@willemdh](https://discuss.elastic.co/u/willemdh)\
**Replies:** 0\
**Last updated:** [November 1, 2023, 11:47am UTC](https://discuss.elastic.co/t/create-an-observability-alert-with-a-watch/346195 "2023-11-01T11:47:43Z")

</div>

Hello, What would be the best way to create Observability alerts with a watch? Is it possible to create a watch action which creates the alert? Willem

---

## [Get records from index based on result from another search](https://discuss.elastic.co/t/get-records-from-index-based-on-result-from-another-search/346074)

<div class="topic-metadata">

**Author:** [@Mhag](https://discuss.elastic.co/u/Mhag)\
**Replies:** 5\
**Last updated:** [November 1, 2023, 10:41am UTC](https://discuss.elastic.co/t/get-records-from-index-based-on-result-from-another-search/346074 "2023-11-01T10:41:01Z")

</div>

Hi, I have an index where we collect the requests to our api somthing like this : myindex: url: /some/path service: someservice uuid: xxx-yyy-zzz-uuu And I have a requirement to get or correlate all urls that…

---

## [Fleet-server installation error](https://discuss.elastic.co/t/fleet-server-installation-error/346179)

<div class="topic-metadata">

**Author:** [@sudhir\_singh](https://discuss.elastic.co/u/sudhir_singh)\
**Replies:** 0\
**Last updated:** [November 1, 2023, 8:06am UTC](https://discuss.elastic.co/t/fleet-server-installation-error/346179 "2023-11-01T08:06:19Z")

</div>

Hi I'm trying to run fleet I tried with self generated fleet-server certificate and with basic one without generating certificate but ended up having an error.

---

## [Performance degrade after using Elastic 8](https://discuss.elastic.co/t/performance-degrade-after-using-elastic-8/345703)

<div class="topic-metadata">

**Author:** [@smiley\_tamy](https://discuss.elastic.co/u/smiley_tamy)\
**Replies:** 3\
**Last updated:** [November 1, 2023, 8:00am UTC](https://discuss.elastic.co/t/performance-degrade-after-using-elastic-8/345703 "2023-11-01T08:00:08Z")

</div>

We have been using elastic 7.17 Our application has load tests and we generally measure the performance After upgrading to elastic 8, we see lot of difference in the results we had when compared to elastic 7 We also n…

---

## [Best approach to combine two different ES instances in one instance](https://discuss.elastic.co/t/best-approach-to-combine-two-different-es-instances-in-one-instance/346177)

<div class="topic-metadata">

**Author:** [@Prashant\_Rana](https://discuss.elastic.co/u/Prashant_Rana)\
**Replies:** 1\
**Last updated:** [November 1, 2023, 7:34am UTC](https://discuss.elastic.co/t/best-approach-to-combine-two-different-es-instances-in-one-instance/346177 "2023-11-01T07:34:05Z")

</div>

I have two instances running from two different drives. I would like to combine both. I have two approaches. Shutdown second node and use the data path of the second node in the first node as a multi-data path option c…

---

## [Consider comma separated values in a field as separate values while aggregating](https://discuss.elastic.co/t/consider-comma-separated-values-in-a-field-as-separate-values-while-aggregating/345804)

<div class="topic-metadata">

**Author:** [@Gagan\_Saluja](https://discuss.elastic.co/u/Gagan_Saluja)\
**Replies:** 2\
**Last updated:** [November 1, 2023, 4:26am UTC](https://discuss.elastic.co/t/consider-comma-separated-values-in-a-field-as-separate-values-while-aggregating/345804 "2023-11-01T04:26:34Z")

</div>

Hi, i want to do aggregation on a field which has values like doc1\_field: "A" doc2\_field: "A, B" doc3\_field: "A, B, C" What mappings / settings I can use so that when I aggregate on this field I should get results l…

---

## [Elastic Defend: Unexpected error occurred during diagnostic memory scan: Success](https://discuss.elastic.co/t/elastic-defend-unexpected-error-occurred-during-diagnostic-memory-scan-success/346100)

<div class="topic-metadata">

**Author:** [@aqiank](https://discuss.elastic.co/u/aqiank)\
**Replies:** 2\
**Last updated:** [November 1, 2023, 1:50am UTC](https://discuss.elastic.co/t/elastic-defend-unexpected-error-occurred-during-diagnostic-memory-scan-success/346100 "2023-11-01T01:50:37Z")

</div>

Hi, I added Elastic Defend integration to an active policy and I noticed messages like the one below on the host's logs. \[elastic\_agent.endpoint\_security\]\[warning\] MemoryScan.cpp:677 Unexpected error occurred during dia…

---

## [Elastic Sharepoint Online Python Connector v8.10.3.0 Security Update](https://discuss.elastic.co/t/elastic-sharepoint-online-python-connector-v8-10-3-0-security-update/344732)

<div class="topic-metadata">

**Author:** [@ismisepaul](https://discuss.elastic.co/u/ismisepaul)\
**Replies:** 0\
**Last updated:** [October 10, 2023, 12:18pm UTC](https://discuss.elastic.co/t/elastic-sharepoint-online-python-connector-v8-10-3-0-security-update/344732 "2023-10-10T12:18:57Z")

</div>

Elastic Sharepoint Online Python Connector Improper Access Control (ESA-2023-18) An issue was discovered when using Document Level Security and the SPO "Limited Access" functionality in Elastic Sharepoint Online Python …

---

## [Endpoint v8.10.4 Security Update](https://discuss.elastic.co/t/endpoint-v8-10-4-security-update/345203)

<div class="topic-metadata">

**Author:** [@ismisepaul](https://discuss.elastic.co/u/ismisepaul)\
**Replies:** 0\
**Last updated:** [October 17, 2023, 12:07pm UTC](https://discuss.elastic.co/t/endpoint-v8-10-4-security-update/345203 "2023-10-17T12:07:38Z")

</div>

Elastic Endpoint Insertion of Sensitive Information into Log File (ESA-2023-21) If Elastic Endpoint (v7.9.0 - v8.10.3) is configured to use a non-default option in which the logging level is explicitly set to debug, and…

---

## [Hardware Requirements - Self hosted in Cloud](https://discuss.elastic.co/t/hardware-requirements-self-hosted-in-cloud/346067)

<div class="topic-metadata">

**Author:** [@bEngineer](https://discuss.elastic.co/u/bEngineer)\
**Replies:** 2\
**Last updated:** [October 31, 2023, 10:27pm UTC](https://discuss.elastic.co/t/hardware-requirements-self-hosted-in-cloud/346067 "2023-10-31T22:27:27Z")

</div>

Hi everyone, I'm researching scalability costs for an elasticsearch search engine project. I understand some hardware requirements on a small scale, large scale I'm having a hard time wrapping my head around it. I have…

---

## [Find transactions flow](https://discuss.elastic.co/t/find-transactions-flow/346059)

<div class="topic-metadata">

**Author:** [@Indeed2000](https://discuss.elastic.co/u/Indeed2000)\
**Replies:** 1\
**Last updated:** [October 31, 2023, 5:39pm UTC](https://discuss.elastic.co/t/find-transactions-flow/346059 "2023-10-31T17:39:29Z")

</div>

Hi Is there anyway to find transaction flow like this i have log file contain 50 million transactions like this 16:30:53:002 moduleA:\[C1\]L\[143\]F\[10\]ID\[123456\] 16:30:54:002 moduleA:\[C2\]L\[143\]F\[20\]ID\[123456\] 16:30:55:00…

---

## [Elasticsearch Export Import](https://discuss.elastic.co/t/elasticsearch-export-import/346143)

<div class="topic-metadata">

**Author:** [@Debasis\_Mallick](https://discuss.elastic.co/u/Debasis_Mallick)\
**Replies:** 1\
**Last updated:** [October 31, 2023, 4:11pm UTC](https://discuss.elastic.co/t/elasticsearch-export-import/346143 "2023-10-31T16:11:44Z")

</div>

Hi Team, I had a requirement where I need export/ import one of the index data to a separate cluster. Is there any such tool which help me to achieve the same. Thanks, Debasis

---

## [Offline maps in kibana 8.8](https://discuss.elastic.co/t/offline-maps-in-kibana-8-8/346137)

<div class="topic-metadata">

**Author:** [@Manal\_A](https://discuss.elastic.co/u/Manal_A)\
**Replies:** 5\
**Last updated:** [October 31, 2023, 3:49pm UTC](https://discuss.elastic.co/t/offline-maps-in-kibana-8-8/346137 "2023-10-31T15:49:20Z")

</div>

Hello, I want to create a map in Kibana 8.8, but I am in an environment that does not have internet access. Is there a method to create maps offline in Kibana? Thank you

---

## [Define second pattern for the remaining logs](https://discuss.elastic.co/t/define-second-pattern-for-the-remaining-logs/346010)

<div class="topic-metadata">

**Author:** [@hta](https://discuss.elastic.co/u/hta)\
**Replies:** 1\
**Last updated:** [October 31, 2023, 3:27pm UTC](https://discuss.elastic.co/t/define-second-pattern-for-the-remaining-logs/346010 "2023-10-31T15:27:00Z")

</div>

Hello, I have now set up a pipeline and defined a GROK pattern. It is working. However, the logs that do not match the pattern are not displayed. How could I define a simple second pattern to catch the remaining logs?

---

## [KIbana CSP error](https://discuss.elastic.co/t/kibana-csp-error/344888)

<div class="topic-metadata">

**Author:** [@Priyaansh\_Dwivedi](https://discuss.elastic.co/u/Priyaansh_Dwivedi)\
**Replies:** 1\
**Last updated:** [October 12, 2023, 4:14pm UTC](https://discuss.elastic.co/t/kibana-csp-error/344888 "2023-10-12T16:14:04Z")

</div>

"Hello Community, I'm facing an issue with my Elasticsearch cluster. It's up and running smoothly, but when I try to access Kibana on my browser, I see a message saying 'Kibana server not ready yet' in the console. I've…

---

## [Logstash - Parsing fields with duplicate names](https://discuss.elastic.co/t/logstash-parsing-fields-with-duplicate-names/346131)

<div class="topic-metadata">

**Author:** [@mgotechlock](https://discuss.elastic.co/u/mgotechlock)\
**Replies:** 5\
**Last updated:** [October 31, 2023, 1:19pm UTC](https://discuss.elastic.co/t/logstash-parsing-fields-with-duplicate-names/346131 "2023-10-31T13:19:42Z")

</div>

If I receive a log in that looks like this, how do I deal with the fact that the subfields under "records" are identical? Is there a concept of \[records\]\[operationName\]\[0\] and \[1\], for example? { "records": \[ { …

---

## [How to create index pattern(data view) for all indices](https://discuss.elastic.co/t/how-to-create-index-pattern-data-view-for-all-indices/346134)

<div class="topic-metadata">

**Author:** [@Sandeep\_Raju](https://discuss.elastic.co/u/Sandeep_Raju)\
**Replies:** 2\
**Last updated:** [October 31, 2023, 1:11pm UTC](https://discuss.elastic.co/t/how-to-create-index-pattern-data-view-for-all-indices/346134 "2023-10-31T13:11:39Z")

</div>

Hi all, I'm using Kibana 8.6.2. I had added indices some time back and don't want to delete or modify them. I have about 70 indices with different names: eg: locations roles tasks stats tickets stats These were cre…

---

## [2 agents on a machine?](https://discuss.elastic.co/t/2-agents-on-a-machine/346114)

<div class="topic-metadata">

**Author:** [@Nightingale\_John](https://discuss.elastic.co/u/Nightingale_John)\
**Replies:** 1\
**Last updated:** [October 31, 2023, 12:36pm UTC](https://discuss.elastic.co/t/2-agents-on-a-machine/346114 "2023-10-31T12:36:41Z")

</div>

Hi All, I'm wondering if anyone has any experience of putting 2 elastic agents on a machine? We've got a client who is using elastic for monitoring, and we need to have the elastic agent on for security.. this is on Mi…

---

## [Elasticsearch cluster configuration for intensive write](https://discuss.elastic.co/t/elasticsearch-cluster-configuration-for-intensive-write/346107)

<div class="topic-metadata">

**Author:** [@avnere](https://discuss.elastic.co/u/avnere)\
**Replies:** 5\
**Last updated:** [October 31, 2023, 11:31am UTC](https://discuss.elastic.co/t/elasticsearch-cluster-configuration-for-intensive-write/346107 "2023-10-31T11:31:25Z")

</div>

Hi, I need to index ~1TB data per day. I have the required HW and want to know which cluster should I raise, means How many nodes, How many shards, etc. Is there any formula for that? Thanks.

---

## [Kibana is extremely slow (Loading graphs)](https://discuss.elastic.co/t/kibana-is-extremely-slow-loading-graphs/345694)

<div class="topic-metadata">

**Author:** [@Saili\_Bakalkar](https://discuss.elastic.co/u/Saili_Bakalkar)\
**Replies:** 3\
**Last updated:** [October 31, 2023, 11:18am UTC](https://discuss.elastic.co/t/kibana-is-extremely-slow-loading-graphs/345694 "2023-10-31T11:18:57Z")

</div>

Hello everyone, I'm encountering significant performance issues with my Kibana setup, and I'm seeking guidance to improve its responsiveness. I've attached images to provide insights into the current state of our cluste…

---

## [Kibana Join two dasets into one visualization](https://discuss.elastic.co/t/kibana-join-two-dasets-into-one-visualization/346124)

<div class="topic-metadata">

**Author:** [@Mhag](https://discuss.elastic.co/u/Mhag)\
**Replies:** 0\
**Last updated:** [October 31, 2023, 11:15am UTC](https://discuss.elastic.co/t/kibana-join-two-dasets-into-one-visualization/346124 "2023-10-31T11:15:43Z")

</div>

Hi all, I have an index wit fields like this : Myindex: url: "/some/url1", service: "someservice1", uuid: "ccc-xxx-yyy-zzz1" url: "/some/url2", service: "someservice1", uuid: "ccc-xxx-yyy-zzz2" url: "…

---

## [Elastic APM - Angular-1.3.17 integration](https://discuss.elastic.co/t/elastic-apm-angular-1-3-17-integration/345362)

<div class="topic-metadata">

**Author:** [@Dixit](https://discuss.elastic.co/u/Dixit)\
**Replies:** 10\
**Last updated:** [October 31, 2023, 11:14am UTC](https://discuss.elastic.co/t/elastic-apm-angular-1-3-17-integration/345362 "2023-10-31T11:14:52Z")

</div>

hi Team, Am working on to integrate RUM service to angular-1.3.17, please can you help me with the steps. Facing issues with integration and other artifacts regarding calling the libraries/modules used. Getting error …

---

## [Object mapping for \[protoPayload.response.status\] tried to parse field \[status\] as object, but found a concrete value (document\_parsing\_exception)](https://discuss.elastic.co/t/object-mapping-for-protopayload-response-status-tried-to-parse-field-status-as-object-but-found-a-concrete-value-document-parsing-exception/346117)

<div class="topic-metadata">

**Author:** [@narrayana\_swamy](https://discuss.elastic.co/u/narrayana_swamy)\
**Replies:** 1\
**Last updated:** [October 31, 2023, 10:38am UTC](https://discuss.elastic.co/t/object-mapping-for-protopayload-response-status-tried-to-parse-field-status-as-object-but-found-a-concrete-value-document-parsing-exception/346117 "2023-10-31T10:38:55Z")

</div>

Hi, I am trying to load the data via GCP dataflow to elasticsearch, but i am getting the below error. i am not using any agents. i have installed the GCP integrations. "Error message from worker: java.io.IOException: Er…

---

## [How to join two stream data sources and find matches](https://discuss.elastic.co/t/how-to-join-two-stream-data-sources-and-find-matches/346097)

<div class="topic-metadata">

**Author:** [@fim01](https://discuss.elastic.co/u/fim01)\
**Replies:** 0\
**Last updated:** [October 31, 2023, 8:22am UTC](https://discuss.elastic.co/t/how-to-join-two-stream-data-sources-and-find-matches/346097 "2023-10-31T08:22:08Z")

</div>

I'm asking for an idea or approach to solve the following business problem: Two stream data sources (A and B) continuously ingesting events into two separate indices (A and B) in Elasticsearch. Each of them has a unique…

---

## [How do i change the hyper reference of header logo in production mode?](https://discuss.elastic.co/t/how-do-i-change-the-hyper-reference-of-header-logo-in-production-mode/346094)

<div class="topic-metadata">

**Author:** [@didar2016](https://discuss.elastic.co/u/didar2016)\
**Replies:** 0\
**Last updated:** [October 31, 2023, 7:28am UTC](https://discuss.elastic.co/t/how-do-i-change-the-hyper-reference-of-header-logo-in-production-mode/346094 "2023-10-31T07:28:43Z")

</div>

In dev mode it is possible to change the link but not in production mode. I don't find the header\_logo.tsx file in production mode.

[Previous page](https://discuss.elastic.co/tag/none.md?no_tags=true&page=279)

[Next page](https://discuss.elastic.co/tag/none.md?no_tags=true&page=281)
