# \#none

**URL:** https://discuss.elastic.co/tag/none.md?no_tags=true&page=288

[Latest](https://discuss.elastic.co/latest.md) · [Categories](https://discuss.elastic.co/categories.md) · [Tags](https://discuss.elastic.co/tags.md)

**Page:** 289

---

## [Elastic Daily Byte(s) Season 5: Search](https://discuss.elastic.co/t/elastic-daily-byte-s-season-5-search/344453)

<div class="topic-metadata">

**Author:** [@dadoonet](https://discuss.elastic.co/u/dadoonet)\
**Replies:** 3\
**Last updated:** [October 17, 2023, 5:03pm UTC](https://discuss.elastic.co/t/elastic-daily-byte-s-season-5-search/344453 "2023-10-17T17:03:56Z")

</div>

:mega: Everyday at 11:45AM (CET - European) during 3 weeks and for only 8 minutes, we are live on YouTube, explaining many things related to text search. It started on Monday with the basics of the Search API, then we c…

---

## [Could not find similarity in KnnQuery in Java Client?](https://discuss.elastic.co/t/could-not-find-similarity-in-knnquery-in-java-client/343002)

<div class="topic-metadata">

**Author:** [@csplrj](https://discuss.elastic.co/u/csplrj)\
**Replies:** 3\
**Last updated:** [October 17, 2023, 4:59pm UTC](https://discuss.elastic.co/t/could-not-find-similarity-in-knnquery-in-java-client/343002 "2023-10-17T16:59:35Z")

</div>

Could not find similarity in KnnQuery in Java Client?

---

## [Logstash jdbc plugin with MSSQL](https://discuss.elastic.co/t/logstash-jdbc-plugin-with-mssql/344912)

<div class="topic-metadata">

**Author:** [@catalin.bulancea](https://discuss.elastic.co/u/catalin.bulancea)\
**Replies:** 11\
**Last updated:** [October 17, 2023, 3:58pm UTC](https://discuss.elastic.co/t/logstash-jdbc-plugin-with-mssql/344912 "2023-10-17T15:58:05Z")

</div>

Hi Logstash gurus, I am trying to fetch data from MSSQL using the Logstash jdbc plugin. I am on logstash 7.17.4. I am using the below config for the input: input { jdbc { jdbc\_connection\_string =\> "jdbc:sqlserve…

---

## [Metric background change based on last week value](https://discuss.elastic.co/t/metric-background-change-based-on-last-week-value/345082)

<div class="topic-metadata">

**Author:** [@gnorillo](https://discuss.elastic.co/u/gnorillo)\
**Replies:** 3\
**Last updated:** [October 17, 2023, 2:24pm UTC](https://discuss.elastic.co/t/metric-background-change-based-on-last-week-value/345082 "2023-10-17T14:24:29Z")

</div>

Hi everyone, i would add a metric visualization to my dashboard with background colors based on a another metric (for example to compare same hour last week) some example to explain: if metric last hour is \>= metric l…

---

## [Plati­num license](https://discuss.elastic.co/t/plati-num-license/345213)

<div class="topic-metadata">

**Author:** [@Manal\_A](https://discuss.elastic.co/u/Manal_A)\
**Replies:** 4\
**Last updated:** [October 17, 2023, 3:46pm UTC](https://discuss.elastic.co/t/plati-num-license/345213 "2023-10-17T15:46:15Z")

</div>

Hello , I want to know if the Plati­num license is based on the number of nodes or on capacity, and whether it applies to coordinator nodes. Thank you.

---

## [Limit number of mapping fields](https://discuss.elastic.co/t/limit-number-of-mapping-fields/345226)

<div class="topic-metadata">

**Author:** [@MathieuINTIA](https://discuss.elastic.co/u/MathieuINTIA)\
**Replies:** 0\
**Last updated:** [October 17, 2023, 2:34pm UTC](https://discuss.elastic.co/t/limit-number-of-mapping-fields/345226 "2023-10-17T14:34:24Z")

</div>

Hello everyone, I have a mapping with well defined fields and fields that I don't want to see either indexed or in the mapping. Here's my mapping definition: mappings: { dynamic: false, properties: { '@t…

---

## [Detect previous password change in bruteforce detection rule](https://discuss.elastic.co/t/detect-previous-password-change-in-bruteforce-detection-rule/344881)

<div class="topic-metadata">

**Author:** [@e.vedelaar](https://discuss.elastic.co/u/e.vedelaar)\
**Replies:** 2\
**Last updated:** [October 17, 2023, 2:25pm UTC](https://discuss.elastic.co/t/detect-previous-password-change-in-bruteforce-detection-rule/344881 "2023-10-17T14:25:33Z")

</div>

Hi, we built a bruteforce use case which detects winlog bruteforces. The query is as follows: event.category : "authentication" and event.outcome : "failure" and (winlog.event\_data.Status: "0x18" or winlog.event\_data.St…

---

## [Query to check field is exist or not](https://discuss.elastic.co/t/query-to-check-field-is-exist-or-not/345206)

<div class="topic-metadata">

**Author:** [@Aniket\_Pant](https://discuss.elastic.co/u/Aniket_Pant)\
**Replies:** 1\
**Last updated:** [October 17, 2023, 1:03pm UTC](https://discuss.elastic.co/t/query-to-check-field-is-exist-or-not/345206 "2023-10-17T13:03:37Z")

</div>

Is there any query we can run to check a fieldname is exist or not

---

## [ElasticSearch User Profile/Personalization](https://discuss.elastic.co/t/elasticsearch-user-profile-personalization/345127)

<div class="topic-metadata">

**Author:** [@RodAndTom](https://discuss.elastic.co/u/RodAndTom)\
**Replies:** 1\
**Last updated:** [October 17, 2023, 12:58pm UTC](https://discuss.elastic.co/t/elasticsearch-user-profile-personalization/345127 "2023-10-17T12:58:13Z")

</div>

Hi, I work with IDOL (Intelligent Data Operating Layer) more for more than 13 years and right now, we are evaluating which IDOL functionalities Elasticsearch can perform OOTB. One of these features is the user profile /…

---

## [Custom UDP with PANW integration](https://discuss.elastic.co/t/custom-udp-with-panw-integration/344214)

<div class="topic-metadata">

**Author:** [@Patryk\_Ostrowski](https://discuss.elastic.co/u/Patryk_Ostrowski)\
**Replies:** 4\
**Last updated:** [October 17, 2023, 12:19pm UTC](https://discuss.elastic.co/t/custom-udp-with-panw-integration/344214 "2023-10-17T12:19:41Z")

</div>

Hello, I used PANOS integration that work great for me. Now I want to change my configuration and use Custom UDP Logs integration. In advanced options I changed Ingest pipelines "logs-udp.generic@custom". I also te…

---

## [Sample code to find similar HTML Documents](https://discuss.elastic.co/t/sample-code-to-find-similar-html-documents/345140)

<div class="topic-metadata">

**Author:** [@Ata\_Zangene](https://discuss.elastic.co/u/Ata_Zangene)\
**Replies:** 1\
**Last updated:** [October 17, 2023, 9:55am UTC](https://discuss.elastic.co/t/sample-code-to-find-similar-html-documents/345140 "2023-10-17T09:55:12Z")

</div>

Hi, I want to index around 10 million of web pages HTML code in elasticsearch, now, I want to give the HTML content as a search query and get the most similar documents related to the search query ( which is an HTML ) s…

---

## [How to auto delete data older than 2 month or 30 days from elastcisearch index?](https://discuss.elastic.co/t/how-to-auto-delete-data-older-than-2-month-or-30-days-from-elastcisearch-index/345161)

<div class="topic-metadata">

**Author:** [@bbkunbi](https://discuss.elastic.co/u/bbkunbi)\
**Replies:** 5\
**Last updated:** [October 17, 2023, 7:40am UTC](https://discuss.elastic.co/t/how-to-auto-delete-data-older-than-2-month-or-30-days-from-elastcisearch-index/345161 "2023-10-17T07:40:02Z")

</div>

Note: I am not using date in index name like index -yyyy-mm . any method to do this i am using python Elasticsearch client to store data in es database.

---

## [Relp error: Relp::InappropriateCommand open expecting syslog](https://discuss.elastic.co/t/relp-error-relp-inappropriatecommand-open-expecting-syslog/345125)

<div class="topic-metadata">

**Author:** [@MarcoV](https://discuss.elastic.co/u/MarcoV)\
**Replies:** 2\
**Last updated:** [October 17, 2023, 7:52am UTC](https://discuss.elastic.co/t/relp-error-relp-inappropriatecommand-open-expecting-syslog/345125 "2023-10-17T07:52:35Z")

</div>

Hello everyone. I have this warning in my logstash log: Relp error: Relp::InappropriateCommand open expecting syslog My logstash configuration filter has input relp as input but with this error the log from syslog are…

---

## [Elasticsearch](https://discuss.elastic.co/t/elasticsearch/345162)

<div class="topic-metadata">

**Author:** [@merson](https://discuss.elastic.co/u/merson)\
**Replies:** 1\
**Last updated:** [October 17, 2023, 7:31am UTC](https://discuss.elastic.co/t/elasticsearch/345162 "2023-10-17T07:31:01Z")

</div>

Suddenly am getting this Error in Elasticsearch: org.elasticsearch.ElasticsearchException: Trying to create too many scroll contexts. Must be less than or equal to: \[500\]. This limit can be set by changing the \[search.m…

---

## [Snapshot restore](https://discuss.elastic.co/t/snapshot-restore/345160)

<div class="topic-metadata">

**Author:** [@Sandeepa\_Kariyawasam](https://discuss.elastic.co/u/Sandeepa_Kariyawasam)\
**Replies:** 0\
**Last updated:** [October 17, 2023, 5:36am UTC](https://discuss.elastic.co/t/snapshot-restore/345160 "2023-10-17T05:36:28Z")

</div>

I have been restoring snapshots which caused some missing errors for some time but I only could find it possible one by one. Is there any way that I can restore all missing or erroneous snapshot all at once?

---

## [Kibana giving unauthenticated first time but allowing to login second time in same session](https://discuss.elastic.co/t/kibana-giving-unauthenticated-first-time-but-allowing-to-login-second-time-in-same-session/344984)

<div class="topic-metadata">

**Author:** [@amitkumar.gupta](https://discuss.elastic.co/u/amitkumar.gupta)\
**Replies:** 1\
**Last updated:** [October 17, 2023, 5:18am UTC](https://discuss.elastic.co/t/kibana-giving-unauthenticated-first-time-but-allowing-to-login-second-time-in-same-session/344984 "2023-10-17T05:18:04Z")

</div>

I have enabled Kibana login from wso2 API manager. below I have provided Elastic configuration file. I am following instruction to configure wso2 and kibana- https://shanchathusanda.medium.com/log-in-to-elastic-stack-w…

---

## [Signals to consider the nature of operation](https://discuss.elastic.co/t/signals-to-consider-the-nature-of-operation/343681)

<div class="topic-metadata">

**Author:** [@Dhineshkumar\_R](https://discuss.elastic.co/u/Dhineshkumar_R)\
**Replies:** 3\
**Last updated:** [October 17, 2023, 3:11am UTC](https://discuss.elastic.co/t/signals-to-consider-the-nature-of-operation/343681 "2023-10-17T03:11:36Z")

</div>

Hello folks, I recently came across this post Elasticsearch memory-bound tasks. Basis which I am trying to understand the nature of a search request to my cluster. Following are some questions I have What are the sig…

---

## [How can i setup alerts in kibana for a dashboard?](https://discuss.elastic.co/t/how-can-i-setup-alerts-in-kibana-for-a-dashboard/344538)

<div class="topic-metadata">

**Author:** [@Abhiyash\_Agrawal](https://discuss.elastic.co/u/Abhiyash_Agrawal)\
**Replies:** 1\
**Last updated:** [October 17, 2023, 3:01am UTC](https://discuss.elastic.co/t/how-can-i-setup-alerts-in-kibana-for-a-dashboard/344538 "2023-10-17T03:01:26Z")

</div>

I hope this message finds you well. I am reaching out to inquire about the possibilities of setting up alerts in Kibana for specific dashboard charts within defined durations. Our team has been utilizing Kibana for dat…

---

## [How to properly use Publicly signed Certifiate in kibana to communicate witih elastic?](https://discuss.elastic.co/t/how-to-properly-use-publicly-signed-certifiate-in-kibana-to-communicate-witih-elastic/345034)

<div class="topic-metadata">

**Author:** [@Fosiul\_Alam](https://discuss.elastic.co/u/Fosiul_Alam)\
**Replies:** 19\
**Last updated:** [October 17, 2023, 12:17am UTC](https://discuss.elastic.co/t/how-to-properly-use-publicly-signed-certifiate-in-kibana-to-communicate-witih-elastic/345034 "2023-10-17T00:17:01Z")

</div>

My elasticsearch.yml configuration xpack.security.http.ssl: enabled: true keystore.path: certs/certificates.p12 Bellow procedure has been followed to create certificate.p12 \> cat private-key.key certificate.crt \> …

---

## [Exam Put vs POST](https://discuss.elastic.co/t/exam-put-vs-post/344954)

<div class="topic-metadata">

**Author:** [@Matt\_Clairmont](https://discuss.elastic.co/u/Matt_Clairmont)\
**Replies:** 2\
**Last updated:** [October 16, 2023, 11:36pm UTC](https://discuss.elastic.co/t/exam-put-vs-post/344954 "2023-10-16T23:36:13Z")

</div>

Hi, I've found myself getting a bit confused as to when the appropriate time to use a PUT vs POST when going about the labs. I'm noticing very subtle differences, primarily around server config state, but it seems that m…

---

## [How to login to Kibana embedded in an iframe using API](https://discuss.elastic.co/t/how-to-login-to-kibana-embedded-in-an-iframe-using-api/344895)

<div class="topic-metadata">

**Author:** [@Sanchet\_Nagarnaik](https://discuss.elastic.co/u/Sanchet_Nagarnaik)\
**Replies:** 1\
**Last updated:** [October 16, 2023, 10:29pm UTC](https://discuss.elastic.co/t/how-to-login-to-kibana-embedded-in-an-iframe-using-api/344895 "2023-10-16T22:29:50Z")

</div>

I have a ReactJS and Go based web application. I have a Kibana dashboard embedded in an iframe. Now when a user logs into the application, then that user must be automatically logged into Kibana as well. And the Kibana d…

---

## [Display sum of difference of a field between two day](https://discuss.elastic.co/t/display-sum-of-difference-of-a-field-between-two-day/345129)

<div class="topic-metadata">

**Author:** [@elasticforme](https://discuss.elastic.co/u/elasticforme)\
**Replies:** 1\
**Last updated:** [October 16, 2023, 5:54pm UTC](https://discuss.elastic.co/t/display-sum-of-difference-of-a-field-between-two-day/345129 "2023-10-16T17:54:55Z")

</div>

I have daily data I would like to display difference of sum(total\_size) - sum(total\_size) basically difference of today - yesterday.

---

## [Kibana rule - raise alert when CPU is over 90% for the last 5 min](https://discuss.elastic.co/t/kibana-rule-raise-alert-when-cpu-is-over-90-for-the-last-5-min/344404)

<div class="topic-metadata">

**Author:** [@catalin.bulancea](https://discuss.elastic.co/u/catalin.bulancea)\
**Replies:** 6\
**Last updated:** [October 16, 2023, 5:02pm UTC](https://discuss.elastic.co/t/kibana-rule-raise-alert-when-cpu-is-over-90-for-the-last-5-min/344404 "2023-10-16T17:02:22Z")

</div>

Hi gurus, I'm new to Rules in Kibana so I need your help. I need to raise an email alert when the CPU is constantly exceeding 90% for the past 5 minutes. The way I configured the rule is the following: The alert i…

---

## [Entreprise Resource Unit](https://discuss.elastic.co/t/entreprise-resource-unit/345104)

<div class="topic-metadata">

**Author:** [@Manal\_A](https://discuss.elastic.co/u/Manal_A)\
**Replies:** 1\
**Last updated:** [October 16, 2023, 12:58pm UTC](https://discuss.elastic.co/t/entreprise-resource-unit/345104 "2023-10-16T12:58:25Z")

</div>

I have a qst about how to calculate Elastic's Enterprise Resource Unit (ERU) licenses. Is it based on system resources or JVM resources? Thank you

---

## [Unable to Display Visualization in custom plugin](https://discuss.elastic.co/t/unable-to-display-visualization-in-custom-plugin/345106)

<div class="topic-metadata">

**Author:** [@Amit\_Dhiman](https://discuss.elastic.co/u/Amit_Dhiman)\
**Replies:** 0\
**Last updated:** [October 16, 2023, 12:52pm UTC](https://discuss.elastic.co/t/unable-to-display-visualization-in-custom-plugin/345106 "2023-10-16T12:52:41Z")

</div>

I am successful to create and display Dashbaords and Lens in my custom plugin. I have some visualizations created in Kibana Admin. I want these visualizations to be rendered into my custom plugin screen. I tried many s…

---

## [Not able to search with date range filter](https://discuss.elastic.co/t/not-able-to-search-with-date-range-filter/345088)

<div class="topic-metadata">

**Author:** [@bhumika](https://discuss.elastic.co/u/bhumika)\
**Replies:** 22\
**Last updated:** [October 16, 2023, 11:35am UTC](https://discuss.elastic.co/t/not-able-to-search-with-date-range-filter/345088 "2023-10-16T11:35:07Z")

</div>

I had integrated Elasticsearch in my ruby on rails project with chewy gem. All the searches are working fine except date range filter I tried every approach but not getting any error or response is always blank array th…

---

## [Observed kernel bug for Elasticsearch 7.17.5 on Debian 12](https://discuss.elastic.co/t/observed-kernel-bug-for-elasticsearch-7-17-5-on-debian-12/345083)

<div class="topic-metadata">

**Author:** [@bunste](https://discuss.elastic.co/u/bunste)\
**Replies:** 2\
**Last updated:** [October 16, 2023, 10:35am UTC](https://discuss.elastic.co/t/observed-kernel-bug-for-elasticsearch-7-17-5-on-debian-12/345083 "2023-10-16T10:35:34Z")

</div>

Hi all, we are running an ES cluster in version 7.17.5 and some of our data nodes are already running on Debian 12. Now recently one data node failed. Elasticsearch itself did not log anything about the incident. Also s…

---

## [Grok issues / Fingerprint issues: Value not imported into ES after 6.x - 7-x update](https://discuss.elastic.co/t/grok-issues-fingerprint-issues-value-not-imported-into-es-after-6-x-7-x-update/344357)

<div class="topic-metadata">

**Author:** [@randomnamegenerator](https://discuss.elastic.co/u/randomnamegenerator)\
**Replies:** 9\
**Last updated:** [October 16, 2023, 8:48am UTC](https://discuss.elastic.co/t/grok-issues-fingerprint-issues-value-not-imported-into-es-after-6-x-7-x-update/344357 "2023-10-16T08:48:05Z")

</div>

Hello, I am new to ELK stack especially the filtering / Grok in Logstash, We are having issues importing DATA:servicename value into ES after moving from 6.3.X to a 7.14 version. The grok below is part of our applica…

---

## [Best approach to update huge # of documents (millions) single query](https://discuss.elastic.co/t/best-approach-to-update-huge-of-documents-millions-single-query/345080)

<div class="topic-metadata">

**Author:** [@vtadmin](https://discuss.elastic.co/u/vtadmin)\
**Replies:** 0\
**Last updated:** [October 16, 2023, 8:59am UTC](https://discuss.elastic.co/t/best-approach-to-update-huge-of-documents-millions-single-query/345080 "2023-10-16T08:59:47Z")

</div>

I'm using elastic for storing documents with multiple attributes that can go on and off (like active or inactive). They can go up to 1-2 million per index. On a daily basis I need to synchronize those documents who can…

---

## [Duplicate Data](https://discuss.elastic.co/t/duplicate-data/345053)

<div class="topic-metadata">

**Author:** [@Ruwi](https://discuss.elastic.co/u/Ruwi)\
**Replies:** 0\
**Last updated:** [October 15, 2023, 3:05pm UTC](https://discuss.elastic.co/t/duplicate-data/345053 "2023-10-15T15:05:10Z")

</div>

Hello, We have time series indexes created daily in Elasticsearch. We upgraded from version 7.10.2 to 8.10.2. While running our tests, we observed that the data coming with the creation of the first index is duplicate. …

[Previous page](https://discuss.elastic.co/tag/none.md?no_tags=true&page=287)

[Next page](https://discuss.elastic.co/tag/none.md?no_tags=true&page=289)
