# \#none

**URL:** https://discuss.elastic.co/tag/none.md?no_tags=true&page=284

[Latest](https://discuss.elastic.co/latest.md) · [Categories](https://discuss.elastic.co/categories.md) · [Tags](https://discuss.elastic.co/tags.md)

**Page:** 285

---

## [Remove HTTP encondings](https://discuss.elastic.co/t/remove-http-encondings/345720)

<div class="topic-metadata">

**Author:** [@lemospt](https://discuss.elastic.co/u/lemospt)\
**Replies:** 3\
**Last updated:** [October 25, 2023, 5:03pm UTC](https://discuss.elastic.co/t/remove-http-encondings/345720 "2023-10-25T17:03:12Z")

</div>

Hi guys, i'm integrating log from proxy squid, there is a field called 'Original Received Request Header' that has data like below, User-Agent:%20git/2.30.2%0D%0AProxy-Connection:%20Keep-Alive%0D%0AHost:%20github.priva…

---

## [Logstash fails with "FFI not available" message when starting logstash on Centos 7.9](https://discuss.elastic.co/t/logstash-fails-with-ffi-not-available-message-when-starting-logstash-on-centos-7-9/345387)

<div class="topic-metadata">

**Author:** [@shaigbdb](https://discuss.elastic.co/u/shaigbdb)\
**Replies:** 2\
**Last updated:** [October 25, 2023, 3:37pm UTC](https://discuss.elastic.co/t/logstash-fails-with-ffi-not-available-message-when-starting-logstash-on-centos-7-9/345387 "2023-10-25T15:37:59Z")

</div>

1. Logstash version (e.g. bin/logstash --version) - 8.10.2 \*\*2. Logstash installation source \*\* - RPM \*\*3. How is Logstash being run \*\* - systemd JVM - tried both the bundled JVM (openjdk version "17.0.8" 2023-07-18) …

---

## [Wtacher or Ingest pipeline avoiding duplicates](https://discuss.elastic.co/t/wtacher-or-ingest-pipeline-avoiding-duplicates/345747)

<div class="topic-metadata">

**Author:** [@elk-user-0001](https://discuss.elastic.co/u/elk-user-0001)\
**Replies:** 0\
**Last updated:** [October 25, 2023, 3:36pm UTC](https://discuss.elastic.co/t/wtacher-or-ingest-pipeline-avoiding-duplicates/345747 "2023-10-25T15:36:35Z")

</div>

Hello colleagues! I have a question. Is there a way to put in watcher or ingest pipelines an update based on a document\_id ( field, fields, fingerprint... ) to avoid duplicates as in the logstash output ? I have a wat…

---

## [Unassigned shards](https://discuss.elastic.co/t/unassigned-shards/344125)

<div class="topic-metadata">

**Author:** [@abisinio](https://discuss.elastic.co/u/abisinio)\
**Replies:** 0\
**Last updated:** [September 29, 2023, 10:21am UTC](https://discuss.elastic.co/t/unassigned-shards/344125 "2023-09-29T10:21:41Z")

</div>

Hi mates, I've made a mistake in my ELK deployment. I was trying to install a new elastic agent and I put the wrong token and used the one used to configure a new server. Now I've got a lot of unassigned shards and I d…

---

## [Logstash 8.6 low performance](https://discuss.elastic.co/t/logstash-8-6-low-performance/344661)

<div class="topic-metadata">

**Author:** [@RobertC1](https://discuss.elastic.co/u/RobertC1)\
**Replies:** 8\
**Last updated:** [October 25, 2023, 2:24pm UTC](https://discuss.elastic.co/t/logstash-8-6-low-performance/344661 "2023-10-25T14:24:09Z")

</div>

Hi there I ha a server with Linux Ubuntu 20.04 and ELK 8.6 I noticed that the ingestion proccess became slow and I have not change any parameters. This is the conf file for theindex. input { file { …

---

## [Start of Kibana fails](https://discuss.elastic.co/t/start-of-kibana-fails/345627)

<div class="topic-metadata">

**Author:** [@JohannesKjellberg](https://discuss.elastic.co/u/JohannesKjellberg)\
**Replies:** 4\
**Last updated:** [October 25, 2023, 12:55pm UTC](https://discuss.elastic.co/t/start-of-kibana-fails/345627 "2023-10-25T12:55:22Z")

</div>

Hello! I have installed Kibana 8.8.1 on Windows Server 2012 from the downloaded .zip file. I want to access Kibana via a reverse-proxy site in IIS. Therefore, I have created a scheduled task that runs kibana.bat. That t…

---

## [System Logs visiualizations is not showing in kibana dashboards](https://discuss.elastic.co/t/system-logs-visiualizations-is-not-showing-in-kibana-dashboards/345728)

<div class="topic-metadata">

**Author:** [@huzaifa224](https://discuss.elastic.co/u/huzaifa224)\
**Replies:** 0\
**Last updated:** [October 25, 2023, 12:53pm UTC](https://discuss.elastic.co/t/system-logs-visiualizations-is-not-showing-in-kibana-dashboards/345728 "2023-10-25T12:53:14Z")

</div>

I have installed filebeat 8.10.2 and follow the doc to install, i have enabled nginx Apache and system modules. The nginx and apache data is showing in kibana discovery tab and also showing visualizations of these module…

---

## [Not able to send logs to elastic search via Nlog.config](https://discuss.elastic.co/t/not-able-to-send-logs-to-elastic-search-via-nlog-config/345702)

<div class="topic-metadata">

**Author:** [@prakshi91](https://discuss.elastic.co/u/prakshi91)\
**Replies:** 1\
**Last updated:** [October 25, 2023, 12:11pm UTC](https://discuss.elastic.co/t/not-able-to-send-logs-to-elastic-search-via-nlog-config/345702 "2023-10-25T12:11:24Z")

</div>

Hi Everyone, Our aim is to send logs to Elasticsearch and we have made changes to the NLog.config file as per the documentation - Home · markmcdowell/NLog.Targets.ElasticSearch Wiki · GitHub NLog File However, we a…

---

## [Kibana Dashboards constantly showing 408 errors](https://discuss.elastic.co/t/kibana-dashboards-constantly-showing-408-errors/345645)

<div class="topic-metadata">

**Author:** [@leandrojmp](https://discuss.elastic.co/u/leandrojmp)\
**Replies:** 1\
**Last updated:** [October 25, 2023, 9:48am UTC](https://discuss.elastic.co/t/kibana-dashboards-constantly-showing-408-errors/345645 "2023-10-25T09:48:59Z")

</div>

Hello, We have a couple of dashboards with multiple visualizations, some of them have a automatic refresh of 5 or 10 minutes and we are stating to get the following error: \[layeredXyVis\] \> \[esaggs\] \> Check your networ…

---

## [Issue while upgrade kibana 7.16.2 to 7.17.0](https://discuss.elastic.co/t/issue-while-upgrade-kibana-7-16-2-to-7-17-0/345715)

<div class="topic-metadata">

**Author:** [@Dheerendra\_Singh\_Na1](https://discuss.elastic.co/u/Dheerendra_Singh_Na1)\
**Replies:** 0\
**Last updated:** [October 25, 2023, 9:45am UTC](https://discuss.elastic.co/t/issue-while-upgrade-kibana-7-16-2-to-7-17-0/345715 "2023-10-25T09:45:52Z")

</div>

Getting error " \[info\]\[savedobjects-service\] \[.kibana\] WAIT\_FOR\_YELLOW\_SOURCE -\> WAIT\_FOR\_YELLOW\_SOURCE. took: 124084ms. " while upgrade kibana from 7.16.2 to 7.17.0

---

## [Is there any api or plugin for alarming/popup when an attack is detected?](https://discuss.elastic.co/t/is-there-any-api-or-plugin-for-alarming-popup-when-an-attack-is-detected/344517)

<div class="topic-metadata">

**Author:** [@lilyyy](https://discuss.elastic.co/u/lilyyy)\
**Replies:** 1\
**Last updated:** [October 25, 2023, 9:17am UTC](https://discuss.elastic.co/t/is-there-any-api-or-plugin-for-alarming-popup-when-an-attack-is-detected/344517 "2023-10-25T09:17:42Z")

</div>

Hello all, When an attack is detected, I want to show someone in a glance we detect the attack likes popup or sounds on kibana. Is there any api or plugin related with it? Thanks

---

## [Fleet server status offline](https://discuss.elastic.co/t/fleet-server-status-offline/345444)

<div class="topic-metadata">

**Author:** [@candyli](https://discuss.elastic.co/u/candyli)\
**Replies:** 5\
**Last updated:** [October 25, 2023, 7:58am UTC](https://discuss.elastic.co/t/fleet-server-status-offline/345444 "2023-10-25T07:58:29Z")

</div>

I install fleet server on my centos7 Successfully. But status always display offline. I also check integration status: commandline status shows as follow: ''' \[root@fleet02 elastic-agent-8.10.4-linux-x86\_64\]# cd …

---

## [Add a new Elasticsearch to TLS/SSL cluster](https://discuss.elastic.co/t/add-a-new-elasticsearch-to-tls-ssl-cluster/345500)

<div class="topic-metadata">

**Author:** [@Farid\_Niasti](https://discuss.elastic.co/u/Farid_Niasti)\
**Replies:** 3\
**Last updated:** [October 25, 2023, 5:56am UTC](https://discuss.elastic.co/t/add-a-new-elasticsearch-to-tls-ssl-cluster/345500 "2023-10-25T05:56:41Z")

</div>

Hi I have a cluster with 2 nodes of Elasticsearch. TLS/SSL is enables according to the bellow blog: Everything is OK and monitor-node-01 with IP 192.168.11.142 and monitor-node-02 with IP 192.168.11.143 works correct…

---

## [Is possible to create multiple Stored Scripts in 1 single operation using the API?](https://discuss.elastic.co/t/is-possible-to-create-multiple-stored-scripts-in-1-single-operation-using-the-api/345680)

<div class="topic-metadata">

**Author:** [@iTiago](https://discuss.elastic.co/u/iTiago)\
**Replies:** 1\
**Last updated:** [October 25, 2023, 5:31am UTC](https://discuss.elastic.co/t/is-possible-to-create-multiple-stored-scripts-in-1-single-operation-using-the-api/345680 "2023-10-25T05:31:16Z")

</div>

I have more than 2.5K lines in StoredScripts in my old Cloud 5.6 cluster. I want to transfer them to my new Cloud 8.10.4 Cluster. For this, is there a way to automate the creation of these a little using the API? I crea…

---

## [Duplicate logs issue with elastic integration with Atlassian Jira](https://discuss.elastic.co/t/duplicate-logs-issue-with-elastic-integration-with-atlassian-jira/345676)

<div class="topic-metadata">

**Author:** [@TirathS](https://discuss.elastic.co/u/TirathS)\
**Replies:** 0\
**Last updated:** [October 24, 2023, 10:58pm UTC](https://discuss.elastic.co/t/duplicate-logs-issue-with-elastic-integration-with-atlassian-jira/345676 "2023-10-24T22:58:06Z")

</div>

Hello Everyone, Hope everyone is good. I am facing an issue, i am doing Elastic OOTB integration with Atlassian Jira using API. the integration is working fine, but i am seeing duplicate logs. Is there a way to get r…

---

## [ES superuser cannot Create & Delete Kibana index patterns](https://discuss.elastic.co/t/es-superuser-cannot-create-delete-kibana-index-patterns/345665)

<div class="topic-metadata">

**Author:** [@fuwei1234](https://discuss.elastic.co/u/fuwei1234)\
**Replies:** 2\
**Last updated:** [October 24, 2023, 8:37pm UTC](https://discuss.elastic.co/t/es-superuser-cannot-create-delete-kibana-index-patterns/345665 "2023-10-24T20:37:34Z")

</div>

I have an ES770, I am superuser and just found that I cannot create Kibana index pattern. When I create an index pattern, the page shows that successfully find ES index, but Next button does not go to the next page, no r…

---

## [Elasticsearch using lots of CPU and disk, flipping to read-only during heavy use](https://discuss.elastic.co/t/elasticsearch-using-lots-of-cpu-and-disk-flipping-to-read-only-during-heavy-use/345660)

<div class="topic-metadata">

**Author:** [@dpitchford](https://discuss.elastic.co/u/dpitchford)\
**Replies:** 1\
**Last updated:** [October 24, 2023, 8:37pm UTC](https://discuss.elastic.co/t/elasticsearch-using-lots-of-cpu-and-disk-flipping-to-read-only-during-heavy-use/345660 "2023-10-24T20:37:28Z")

</div>

I am trying to understand behavior I am seeing from Elasticsearch 6.8 on a production site. During a period of heavy use (indexing large numbers of documents), Prometheus metrics are showing me that ES is using large amo…

---

## [\[WATCHER\] Failed to Transform payload - Keyword field](https://discuss.elastic.co/t/watcher-failed-to-transform-payload-keyword-field/345666)

<div class="topic-metadata">

**Author:** [@Rossana](https://discuss.elastic.co/u/Rossana)\
**Replies:** 0\
**Last updated:** [October 24, 2023, 8:30pm UTC](https://discuss.elastic.co/t/watcher-failed-to-transform-payload-keyword-field/345666 "2023-10-24T20:30:53Z")

</div>

Hi, I am trying to configure a Watcher of a machine learning job. The ML job is a population job that works with keyword fields. A cause of using the keyword field, watcher gives me this error: This is the search o…

---

## [Clean Install 8.10 Security Configuration](https://discuss.elastic.co/t/clean-install-8-10-security-configuration/345510)

<div class="topic-metadata">

**Author:** [@mgriffith](https://discuss.elastic.co/u/mgriffith)\
**Replies:** 16\
**Last updated:** [October 24, 2023, 6:29pm UTC](https://discuss.elastic.co/t/clean-install-8-10-security-configuration/345510 "2023-10-24T18:29:16Z")

</div>

I've been testing Elastic 7.17 in single-node configuration and have successfully configured minimal and basic security. Now I'd like to setup a new 3-node cluster on the latest version (8.10), but can't for the life of…

---

## [Inline script not firing due to content security policy - dashboard URL link no longer loading](https://discuss.elastic.co/t/inline-script-not-firing-due-to-content-security-policy-dashboard-url-link-no-longer-loading/344092)

<div class="topic-metadata">

**Author:** [@smchamberlin](https://discuss.elastic.co/u/smchamberlin)\
**Replies:** 2\
**Last updated:** [October 24, 2023, 5:31pm UTC](https://discuss.elastic.co/t/inline-script-not-firing-due-to-content-security-policy-dashboard-url-link-no-longer-loading/344092 "2023-10-24T17:31:14Z")

</div>

After upgrading my version of kibana, I can no longer load a clickable hyperlink URL with parameters from my dashboard - it just loads indefinitely and throws exceptions. This is the URL I want to load: http://testserv…

---

## [Confusing about dashboard showing of AKS node memory](https://discuss.elastic.co/t/confusing-about-dashboard-showing-of-aks-node-memory/345150)

<div class="topic-metadata">

**Author:** [@John\_Vo](https://discuss.elastic.co/u/John_Vo)\
**Replies:** 0\
**Last updated:** [October 17, 2023, 3:23am UTC](https://discuss.elastic.co/t/confusing-about-dashboard-showing-of-aks-node-memory/345150 "2023-10-17T03:23:36Z")

</div>

Hi everyone, Currently, I have a bit confuse about dashboard of Memory of AKS node. The Memory usage by Node \[Metrics Kubernetes\] is about 80% The Memory Usage in Infrastructure/Inventory is about 25% Host Ove…

---

## [Kibana logstash pipelines editing multi line](https://discuss.elastic.co/t/kibana-logstash-pipelines-editing-multi-line/345103)

<div class="topic-metadata">

**Author:** [@PeterDK](https://discuss.elastic.co/u/PeterDK)\
**Replies:** 1\
**Last updated:** [October 24, 2023, 4:42pm UTC](https://discuss.elastic.co/t/kibana-logstash-pipelines-editing-multi-line/345103 "2023-10-24T16:42:53Z")

</div>

Hi, anyone noticed the UI change when editing logstash pipelines? Not only the font (size) has changed (way too large in my opinion), but also the behavior. You can duplicate lines with shift+alt+arrow key, moving lin…

---

## [Problem with security timelines for alias](https://discuss.elastic.co/t/problem-with-security-timelines-for-alias/343966)

<div class="topic-metadata">

**Author:** [@kmz161](https://discuss.elastic.co/u/kmz161)\
**Replies:** 0\
**Last updated:** [September 27, 2023, 9:34am UTC](https://discuss.elastic.co/t/problem-with-security-timelines-for-alias/343966 "2023-09-27T09:34:04Z")

</div>

Hello! I use alias for aggregate and display log log from different sources and I often use alias for SIEM rules and it is work great. But I can't use alias for timeline. When I choose alias in timeline I can't choos…

---

## [Kibana's "average" aggregation display time is showing the time wrong](https://discuss.elastic.co/t/kibanas-average-aggregation-display-time-is-showing-the-time-wrong/344333)

<div class="topic-metadata">

**Author:** [@Skimifil](https://discuss.elastic.co/u/Skimifil)\
**Replies:** 1\
**Last updated:** [October 24, 2023, 4:19pm UTC](https://discuss.elastic.co/t/kibanas-average-aggregation-display-time-is-showing-the-time-wrong/344333 "2023-10-24T16:19:46Z")

</div>

I have a pipeline that processes a field, whose value comes in the format "HH:MM:SS", and transforms it into seconds: ruby { code =\> " duration\_parts = event.get('format\_hh\_mm\_ss').split(':').map{|str| str…

---

## [Splitting Logstash message](https://discuss.elastic.co/t/splitting-logstash-message/345597)

<div class="topic-metadata">

**Author:** [@joecarter](https://discuss.elastic.co/u/joecarter)\
**Replies:** 5\
**Last updated:** [October 24, 2023, 3:37pm UTC](https://discuss.elastic.co/t/splitting-logstash-message/345597 "2023-10-24T15:37:38Z")

</div>

I am pulling events from an Azure Event Hub, but some of the events are being grouped into a single message containing an array of "records", which I want to be processed as individual messages. The format is: { timest…

---

## [How to collect the Infra logs using ELK bitnami Image](https://discuss.elastic.co/t/how-to-collect-the-infra-logs-using-elk-bitnami-image/345096)

<div class="topic-metadata">

**Author:** [@Saidi\_Reddy\_Morthala](https://discuss.elastic.co/u/Saidi_Reddy_Morthala)\
**Replies:** 1\
**Last updated:** [October 24, 2023, 2:53pm UTC](https://discuss.elastic.co/t/how-to-collect-the-infra-logs-using-elk-bitnami-image/345096 "2023-10-24T14:53:23Z")

</div>

Hi. I have installed the ELK VM using bitnami image from Azure Market place and I can able to connect to the ELK home page but unable to find the right article to integrate the Azure VM for logging purpose. Kindly help m…

---

## [My search term has reserved characters, and I need to perform a wildcard search](https://discuss.elastic.co/t/my-search-term-has-reserved-characters-and-i-need-to-perform-a-wildcard-search/344943)

<div class="topic-metadata">

**Author:** [@NandhiniD](https://discuss.elastic.co/u/NandhiniD)\
**Replies:** 1\
**Last updated:** [October 24, 2023, 2:51pm UTC](https://discuss.elastic.co/t/my-search-term-has-reserved-characters-and-i-need-to-perform-a-wildcard-search/344943 "2023-10-24T14:51:20Z")

</div>

Hi, I'm trying to search for multiple terms containing special characters using wildcards. To do this, I've employed the query string with the AND operator and multiple terms. When I exclusively use the code below, wil…

---

## [Auth kibana through jwt](https://discuss.elastic.co/t/auth-kibana-through-jwt/345384)

<div class="topic-metadata">

**Author:** [@kmz161](https://discuss.elastic.co/u/kmz161)\
**Replies:** 1\
**Last updated:** [October 24, 2023, 2:14pm UTC](https://discuss.elastic.co/t/auth-kibana-through-jwt/345384 "2023-10-24T14:14:07Z")

</div>

Hello! I need auth in kibana through jwt. I find documenation for elastic settings. I use id\_token, current config xpack.security.authc.realms.jwt.jwt1: order: 3 token\_type: id\_token client\_authentication.type: s…

---

## [Pass filters dynamic](https://discuss.elastic.co/t/pass-filters-dynamic/344651)

<div class="topic-metadata">

**Author:** [@fenixon](https://discuss.elastic.co/u/fenixon)\
**Replies:** 1\
**Last updated:** [October 24, 2023, 2:01pm UTC](https://discuss.elastic.co/t/pass-filters-dynamic/344651 "2023-10-24T14:01:08Z")

</div>

I have marked Hostip in the above screenshot. Here I have hardcoded the hostip and I want to change this hostip from filter to dynamic. I have attached the filter screenshot below

---

## [Doubt about Coordinating Node Resources](https://discuss.elastic.co/t/doubt-about-coordinating-node-resources/345394)

<div class="topic-metadata">

**Author:** [@RdrgPorto](https://discuss.elastic.co/u/RdrgPorto)\
**Replies:** 8\
**Last updated:** [October 24, 2023, 1:22pm UTC](https://discuss.elastic.co/t/doubt-about-coordinating-node-resources/345394 "2023-10-24T13:22:03Z")

</div>

Hi, everyone I have a couple of questions about coordinating nodes: What are the minimum resources (RAM, CPU, disk) for a coordinating node? What do I need to do in order to estimate the resources for this kind of nod…

[Previous page](https://discuss.elastic.co/tag/none.md?no_tags=true&page=283)

[Next page](https://discuss.elastic.co/tag/none.md?no_tags=true&page=285)
