# \#none

**URL:** https://discuss.elastic.co/tag/none.md?no_tags=true&page=291

[Latest](https://discuss.elastic.co/latest.md) · [Categories](https://discuss.elastic.co/categories.md) · [Tags](https://discuss.elastic.co/tags.md)

**Page:** 292

---

## [Logstash exec input plugin issue](https://discuss.elastic.co/t/logstash-exec-input-plugin-issue/344834)

<div class="topic-metadata">

**Author:** [@Ankita\_Pachauri](https://discuss.elastic.co/u/Ankita_Pachauri)\
**Replies:** 0\
**Last updated:** [October 11, 2023, 3:32pm UTC](https://discuss.elastic.co/t/logstash-exec-input-plugin-issue/344834 "2023-10-11T15:32:13Z")

</div>

Hi All, I am using logstash's exec input plugin to pull data from ManageEngine via the REST API using a Python script. The script takes around 2 mins to run and return json lines. The pipeline runs fine for a few iterat…

---

## [Field type of message](https://discuss.elastic.co/t/field-type-of-message/344789)

<div class="topic-metadata">

**Author:** [@anon90868141](https://discuss.elastic.co/u/anon90868141)\
**Replies:** 1\
**Last updated:** [October 11, 2023, 3:20pm UTC](https://discuss.elastic.co/t/field-type-of-message/344789 "2023-10-11T15:20:06Z")

</div>

Hello, we're using the Elastic Stack to store server logs. Currently, the field message is mapped as text field. Today, I tried to search for "oom-kill", but I couldn't get a search to work that matched exacly that. It …

---

## [Without the write permission of the kibana directory, how to launch kibana properly](https://discuss.elastic.co/t/without-the-write-permission-of-the-kibana-directory-how-to-launch-kibana-properly/344543)

<div class="topic-metadata">

**Author:** [@Lingran\_Xiao](https://discuss.elastic.co/u/Lingran_Xiao)\
**Replies:** 1\
**Last updated:** [October 11, 2023, 3:17pm UTC](https://discuss.elastic.co/t/without-the-write-permission-of-the-kibana-directory-how-to-launch-kibana-properly/344543 "2023-10-11T15:17:25Z")

</div>

Hi, I don't have the write permission of the kibana-8.7.1 directory, but my group want me to finish the deployment of kibana. I specify the config directory by using the environment variable KBN\_PATH\_CONF. And when I tr…

---

## [ECK - coordinating nodes expose ingress](https://discuss.elastic.co/t/eck-coordinating-nodes-expose-ingress/344830)

<div class="topic-metadata">

**Author:** [@octav](https://discuss.elastic.co/u/octav)\
**Replies:** 0\
**Last updated:** [October 11, 2023, 2:15pm UTC](https://discuss.elastic.co/t/eck-coordinating-nodes-expose-ingress/344830 "2023-10-11T14:15:26Z")

</div>

Hello, We are using ECK for ELK clusters and we have a deployment for example with the following: - 3 master nodes - 3 data nodes - 2 coordinating nodes When we deploy this, a default service - \<cluster\>-es-http is cr…

---

## [Windows defender logs](https://discuss.elastic.co/t/windows-defender-logs/344532)

<div class="topic-metadata">

**Author:** [@cara\_es](https://discuss.elastic.co/u/cara_es)\
**Replies:** 3\
**Last updated:** [October 11, 2023, 1:59pm UTC](https://discuss.elastic.co/t/windows-defender-logs/344532 "2023-10-11T13:59:45Z")

</div>

Hi. How can i get logs from windows defender to Elasticsearch the log are in EventViewer -\> Applications and Services Logs Microsoft - Windows - Windows Defender - Operational Kind regards Carsten

---

## [Overwrite the value for String field](https://discuss.elastic.co/t/overwrite-the-value-for-string-field/344813)

<div class="topic-metadata">

**Author:** [@My\_Google\_Account](https://discuss.elastic.co/u/My_Google_Account)\
**Replies:** 5\
**Last updated:** [October 11, 2023, 1:43pm UTC](https://discuss.elastic.co/t/overwrite-the-value-for-string-field/344813 "2023-10-11T13:43:05Z")

</div>

Good day ! could you please help me with the following question: how can i overwrite or (what plugin should i use?) the following value to another one: from /server/oauth2/userinfo/slaves/\* to /server/oauth2/userinfo …

---

## [Visualization In Kibana after Merging/Mapping](https://discuss.elastic.co/t/visualization-in-kibana-after-merging-mapping/344801)

<div class="topic-metadata">

**Author:** [@Priyaansh\_Dwivedi](https://discuss.elastic.co/u/Priyaansh_Dwivedi)\
**Replies:** 1\
**Last updated:** [October 11, 2023, 11:29am UTC](https://discuss.elastic.co/t/visualization-in-kibana-after-merging-mapping/344801 "2023-10-11T11:29:32Z")

</div>

"Hello Community, I've always found great support here, and I'm hoping for the same assistance again. In my application, I'm dealing with three different types of logs. These logs are sent to Logstash via Filebeat, wher…

---

## [Where is logstash log](https://discuss.elastic.co/t/where-is-logstash-log/344800)

<div class="topic-metadata">

**Author:** [@ChiMu\_Yuan](https://discuss.elastic.co/u/ChiMu_Yuan)\
**Replies:** 2\
**Last updated:** [October 11, 2023, 11:10am UTC](https://discuss.elastic.co/t/where-is-logstash-log/344800 "2023-10-11T11:10:21Z")

</div>

Hello everyone, I installed logstash with yum. But I can't start it. And the log is empty. How can i find the error log Thank you.

---

## [I want to read key value kafka headers](https://discuss.elastic.co/t/i-want-to-read-key-value-kafka-headers/344711)

<div class="topic-metadata">

**Author:** [@Ayushi\_bhardwaj](https://discuss.elastic.co/u/Ayushi_bhardwaj)\
**Replies:** 3\
**Last updated:** [October 11, 2023, 11:00am UTC](https://discuss.elastic.co/t/i-want-to-read-key-value-kafka-headers/344711 "2023-10-11T11:00:47Z")

</div>

Hello I want to read key value kafka headers but it is not giving me any output Can anyone please help me with the configuration or piece of code to read key value from kafka headers. My old ticket reference -

---

## [XML Array parsing](https://discuss.elastic.co/t/xml-array-parsing/344795)

<div class="topic-metadata">

**Author:** [@Matthias\_Brauchle](https://discuss.elastic.co/u/Matthias_Brauchle)\
**Replies:** 0\
**Last updated:** [October 11, 2023, 8:04am UTC](https://discuss.elastic.co/t/xml-array-parsing/344795 "2023-10-11T08:04:45Z")

</div>

Hello, Setup: Elasticsearch Elastic Agent with the CEL Integration (Documentation) XML Processor Ingest Pipeline My goal is to store the output in Elasticsearch (of course). The URL is from Cisco CUCM and responds w…

---

## [A slow query problem in elasticsearch (aggregation)](https://discuss.elastic.co/t/a-slow-query-problem-in-elasticsearch-aggregation/344793)

<div class="topic-metadata">

**Author:** [@haipeng.zhao](https://discuss.elastic.co/u/haipeng.zhao)\
**Replies:** 0\
**Last updated:** [October 11, 2023, 7:59am UTC](https://discuss.elastic.co/t/a-slow-query-problem-in-elasticsearch-aggregation/344793 "2023-10-11T07:59:48Z")

</div>

Please help me optimize this query. The index is 800mb and the query time is about to exceed 1 second. { "from": 0, "size": 300, "explain": "true", "\_source": \[ "sku\_id", "upc", "…

---

## [Impact of CVE-2023-4863, CVE-2023-5129, & CVE-2023-5217 to Elasticsearch v7.17.10](https://discuss.elastic.co/t/impact-of-cve-2023-4863-cve-2023-5129-cve-2023-5217-to-elasticsearch-v7-17-10/344790)

<div class="topic-metadata">

**Author:** [@Ravi\_Rao](https://discuss.elastic.co/u/Ravi_Rao)\
**Replies:** 1\
**Last updated:** [October 11, 2023, 7:58am UTC](https://discuss.elastic.co/t/impact-of-cve-2023-4863-cve-2023-5129-cve-2023-5217-to-elasticsearch-v7-17-10/344790 "2023-10-11T07:58:32Z")

</div>

This is regarding CVE-2023-4863 , CVE-2023-5129 , CVE-2023-5217 new vulnerabilities identified and seeking confirmation on Elastic search v7.17.x is impacted with these new vulnerabilities or not ? Any updates availa…

---

## [Define Runtime Field as Clickable URL](https://discuss.elastic.co/t/define-runtime-field-as-clickable-url/344784)

<div class="topic-metadata">

**Author:** [@carollyl](https://discuss.elastic.co/u/carollyl)\
**Replies:** 1\
**Last updated:** [October 11, 2023, 6:07am UTC](https://discuss.elastic.co/t/define-runtime-field-as-clickable-url/344784 "2023-10-11T06:07:59Z")

</div>

Referring to the attached screenshot of Scripted Field, it was working using Kibana 7.17.0. Expected to see the label shows up on Kibana as 1234567 (es\_id) and the clickable URL being resolved using URL template, e.g. ht…

---

## [Kibana console 's message section show messy code only for elasticsearch server's messages, but ok for other servers forwarding messages by filebeat](https://discuss.elastic.co/t/kibana-console-s-message-section-show-messy-code-only-for-elasticsearch-servers-messages-but-ok-for-other-servers-forwarding-messages-by-filebeat/344775)

<div class="topic-metadata">

**Author:** [@huanghaiqing1](https://discuss.elastic.co/u/huanghaiqing1)\
**Replies:** 0\
**Last updated:** [October 11, 2023, 3:06am UTC](https://discuss.elastic.co/t/kibana-console-s-message-section-show-messy-code-only-for-elasticsearch-servers-messages-but-ok-for-other-servers-forwarding-messages-by-filebeat/344775 "2023-10-11T03:06:04Z")

</div>

Here I setup kibana/elasticsearch/filebeat in one server: autoyast1, and it also plays as syslog server by store all forwarding messages from managed servers. Today I found ONLY the server itself's message shows as messy…

---

## [ElasticSearch custom index and mapping | local json data visualization issue](https://discuss.elastic.co/t/elasticsearch-custom-index-and-mapping-local-json-data-visualization-issue/344571)

<div class="topic-metadata">

**Author:** [@Srini-99](https://discuss.elastic.co/u/Srini-99)\
**Replies:** 11\
**Last updated:** [October 11, 2023, 2:34am UTC](https://discuss.elastic.co/t/elasticsearch-custom-index-and-mapping-local-json-data-visualization-issue/344571 "2023-10-11T02:34:42Z")

</div>

Hi! I have setup elasticsearch, kibana, filebeat. With the other beats, i am able to collect logs and visualize them. But i want to be able to upload logs that are in json format and visualize them. The logs that i wa…

---

## [How to highlight the matching subtext in elasticsearch](https://discuss.elastic.co/t/how-to-highlight-the-matching-subtext-in-elasticsearch/344754)

<div class="topic-metadata">

**Author:** [@Karthikeyan\_Amaresan](https://discuss.elastic.co/u/Karthikeyan_Amaresan)\
**Replies:** 1\
**Last updated:** [October 11, 2023, 1:08am UTC](https://discuss.elastic.co/t/how-to-highlight-the-matching-subtext-in-elasticsearch/344754 "2023-10-11T01:08:52Z")

</div>

I am getting expected highlighting of substring matching user search keyword in companyName and country fields. However in emailId field instead of highlighting the substring the entire field is getting highlighted. Que…

---

## [A question around logstash S3 input plugin](https://discuss.elastic.co/t/a-question-around-logstash-s3-input-plugin/344769)

<div class="topic-metadata">

**Author:** [@pk.241011](https://discuss.elastic.co/u/pk.241011)\
**Replies:** 2\
**Last updated:** [October 11, 2023, 1:04am UTC](https://discuss.elastic.co/t/a-question-around-logstash-s3-input-plugin/344769 "2023-10-11T01:04:04Z")

</div>

Hi All, We run logstash on multiple EC2 instances behind a loadbalancer for reliability purposes. We are thinking of using the S3 input plugin. Since the servers are created by auto-scaling process of AWS, they are exac…

---

## [Split my json input in logstash and push to ES](https://discuss.elastic.co/t/split-my-json-input-in-logstash-and-push-to-es/344767)

<div class="topic-metadata">

**Author:** [@shdasgupta](https://discuss.elastic.co/u/shdasgupta)\
**Replies:** 1\
**Last updated:** [October 11, 2023, 12:17am UTC](https://discuss.elastic.co/t/split-my-json-input-in-logstash-and-push-to-es/344767 "2023-10-11T00:17:44Z")

</div>

Hi, I have a gzipped json coming from kafka and I need to push it to ES after some transformations. With the help of this forum, I was able solve some of my problem. Right now i need to split the decompressed json into s…

---

## [Single shard failing with snapshot](https://discuss.elastic.co/t/single-shard-failing-with-snapshot/344688)

<div class="topic-metadata">

**Author:** [@Russell\_Fulton](https://discuss.elastic.co/u/Russell_Fulton)\
**Replies:** 3\
**Last updated:** [October 10, 2023, 9:53pm UTC](https://discuss.elastic.co/t/single-shard-failing-with-snapshot/344688 "2023-10-10T21:53:15Z")

</div>

I wish I knew why my backup system is so brittle : ( I have a single shard failing for the last couple of days - from kibana: INTERNAL\_SERVER\_ERROR: UncategorizedExecutionException\[Failed execution\]; nested: Execution…

---

## [Sort the Elasticsearch results based on the matched nested object in search-ui](https://discuss.elastic.co/t/sort-the-elasticsearch-results-based-on-the-matched-nested-object-in-search-ui/344752)

<div class="topic-metadata">

**Author:** [@rommelcanoy](https://discuss.elastic.co/u/rommelcanoy)\
**Replies:** 0\
**Last updated:** [October 10, 2023, 3:14pm UTC](https://discuss.elastic.co/t/sort-the-elasticsearch-results-based-on-the-matched-nested-object-in-search-ui/344752 "2023-10-10T15:14:02Z")

</div>

I want to implement it in Search-UI. How should I do it? For instance, if users search for 'Mucopolysaccharidosis Type 1,' I want to sort the results based on the "score" of the matched nested condition inside this field…

---

## [Get documents based on other documents](https://discuss.elastic.co/t/get-documents-based-on-other-documents/344475)

<div class="topic-metadata">

**Author:** [@Jonas\_S](https://discuss.elastic.co/u/Jonas_S)\
**Replies:** 5\
**Last updated:** [October 10, 2023, 3:13pm UTC](https://discuss.elastic.co/t/get-documents-based-on-other-documents/344475 "2023-10-10T15:13:32Z")

</div>

Hello, i have multiple indexes with multiple documents grouped in a data view. For documents like {..., field1: value, field2: value, ...}, is there a way to get all documents for which at least one other document exis…

---

## [Which filter(s) to extract array of JSON values, then use array to look up nested JSON objects?](https://discuss.elastic.co/t/which-filter-s-to-extract-array-of-json-values-then-use-array-to-look-up-nested-json-objects/343814)

<div class="topic-metadata">

**Author:** [@paolovalladolid](https://discuss.elastic.co/u/paolovalladolid)\
**Replies:** 11\
**Last updated:** [October 10, 2023, 3:08pm UTC](https://discuss.elastic.co/t/which-filter-s-to-extract-array-of-json-values-then-use-array-to-look-up-nested-json-objects/343814 "2023-10-10T15:08:32Z")

</div>

I have a Logstash pipeline which is processing JSON data from a flat file. The data is somewhat structured like this: { "name": "job1", "tasks": { "75fc": { "name": "restAction", "variables": { "incoming"…

---

## [Broken documentation for Source maps](https://discuss.elastic.co/t/broken-documentation-for-source-maps/344716)

<div class="topic-metadata">

**Author:** [@Mattias\_Pantzare](https://discuss.elastic.co/u/Mattias_Pantzare)\
**Replies:** 1\
**Last updated:** [October 10, 2023, 2:55pm UTC](https://discuss.elastic.co/t/broken-documentation-for-source-maps/344716 "2023-10-10T14:55:00Z")

</div>

In the documentation for APM Real User Monitoring Javascript Agent 5.x (current) there is a chapter for "Source maps". Introduction | APM Real User Monitoring JavaScript Agent Reference \[5.x\] | Elastic No link on that …

---

## [Event Filters & Wildcards](https://discuss.elastic.co/t/event-filters-wildcards/343295)

<div class="topic-metadata">

**Author:** [@DefensiveDepth](https://discuss.elastic.co/u/DefensiveDepth)\
**Replies:** 6\
**Last updated:** [October 10, 2023, 2:09pm UTC](https://discuss.elastic.co/t/event-filters-wildcards/343295 "2023-10-10T14:09:03Z")

</div>

According to the docs, it sounds like the only way to use wildcards is with matches and file.path.text ? So using is with an asterisk at the beginning or end going to interpret that as a literal asterisk?

---

## [Pre-built Dashboards Not Loading for Users Except Superuser](https://discuss.elastic.co/t/pre-built-dashboards-not-loading-for-users-except-superuser/344642)

<div class="topic-metadata">

**Author:** [@Ankur\_Mahajan](https://discuss.elastic.co/u/Ankur_Mahajan)\
**Replies:** 10\
**Last updated:** [October 10, 2023, 1:26pm UTC](https://discuss.elastic.co/t/pre-built-dashboards-not-loading-for-users-except-superuser/344642 "2023-10-10T13:26:50Z")

</div>

I have encountered an issue with certain pre-built dashboards in our system. These dashboards are failing to load for any users except the superuser. I have verified that all the required permissions are correctly assign…

---

## [NoClassDefFoundError: org/bouncycastle/asn1/ASN1Encodable - Missing ASN.1 Utility Classes](https://discuss.elastic.co/t/noclassdeffounderror-org-bouncycastle-asn1-asn1encodable-missing-asn-1-utility-classes/344734)

<div class="topic-metadata">

**Author:** [@Franco901](https://discuss.elastic.co/u/Franco901)\
**Replies:** 0\
**Last updated:** [October 10, 2023, 12:32pm UTC](https://discuss.elastic.co/t/noclassdeffounderror-org-bouncycastle-asn1-asn1encodable-missing-asn-1-utility-classes/344734 "2023-10-10T12:32:41Z")

</div>

Hello there, I have a Nextcloud instance (V26) with an Elasticsearch V8.2.10 as full text search component. While indexing user data my ES node poorly died this morning with a missing class not found exception. It see…

---

## [Sliding Window Query in Elastic](https://discuss.elastic.co/t/sliding-window-query-in-elastic/344733)

<div class="topic-metadata">

**Author:** [@vignesh\_nayak](https://discuss.elastic.co/u/vignesh_nayak)\
**Replies:** 0\
**Last updated:** [October 10, 2023, 12:26pm UTC](https://discuss.elastic.co/t/sliding-window-query-in-elastic/344733 "2023-10-10T12:26:12Z")

</div>

Hello, I have a log message which has an id, and it will be same for repeating requests. So I need to find repetitive requests from same id in a certain interval(ex:15min) , What would be the easiest way to achieve this,…

---

## [How to set in Discovery max\_analyzed\_offset as a default value?](https://discuss.elastic.co/t/how-to-set-in-discovery-max-analyzed-offset-as-a-default-value/344731)

<div class="topic-metadata">

**Author:** [@elk1985](https://discuss.elastic.co/u/elk1985)\
**Replies:** 0\
**Last updated:** [October 10, 2023, 11:51am UTC](https://discuss.elastic.co/t/how-to-set-in-discovery-max-analyzed-offset-as-a-default-value/344731 "2023-10-10T11:51:51Z")

</div>

Hello. I have a problem with documents with over 10 mln characters. I'm getting max\_analyzed\_offset error. How can I set max\_analyzed\_offset as a default value so when I will be using Discovery i will not get any error…

---

## [Grok parser question (Invalid json string)](https://discuss.elastic.co/t/grok-parser-question-invalid-json-string/344730)

<div class="topic-metadata">

**Author:** [@superm0](https://discuss.elastic.co/u/superm0)\
**Replies:** 0\
**Last updated:** [October 10, 2023, 11:46am UTC](https://discuss.elastic.co/t/grok-parser-question-invalid-json-string/344730 "2023-10-10T11:46:22Z")

</div>

Hi,please assit me with creating custom grok pattern . I've created custom pattern, it works perfectly in Grok Debugger. But i cant add this expression for parsing data: Error: Invalid Json string. %{SYSLOGTIMESTAMP:…

---

## [Wildcard not working](https://discuss.elastic.co/t/wildcard-not-working/344370)

<div class="topic-metadata">

**Author:** [@yash\_gehi](https://discuss.elastic.co/u/yash_gehi)\
**Replies:** 2\
**Last updated:** [October 10, 2023, 11:24am UTC](https://discuss.elastic.co/t/wildcard-not-working/344370 "2023-10-10T11:24:22Z")

</div>

{ "query":{ "wildcard":{ "id": "C0\*" } } } I'm trying to run a get request through postman using this as a json body. there is around 44k entries with this id. But when I run it I cannot see any data in my resp…

[Previous page](https://discuss.elastic.co/tag/none.md?no_tags=true&page=290)

[Next page](https://discuss.elastic.co/tag/none.md?no_tags=true&page=292)
