# \#none

**URL:** https://discuss.elastic.co/tag/none.md?no_tags=true&page=293

[Latest](https://discuss.elastic.co/latest.md) · [Categories](https://discuss.elastic.co/categories.md) · [Tags](https://discuss.elastic.co/tags.md)

**Page:** 294

---

## [Using Date plugin to parse apache2 error log datetime](https://discuss.elastic.co/t/using-date-plugin-to-parse-apache2-error-log-datetime/344547)

<div class="topic-metadata">

**Author:** [@lobart78](https://discuss.elastic.co/u/lobart78)\
**Replies:** 2\
**Last updated:** [October 6, 2023, 11:00pm UTC](https://discuss.elastic.co/t/using-date-plugin-to-parse-apache2-error-log-datetime/344547 "2023-10-06T23:00:07Z")

</div>

Hi all ! I am trying to use Logstash to parse apache2 error logs. These logs contain a dattime in a format e.g. Fri Oct 03 09:07:41.570 2023. I have already successfully transfered this string into a field "eventfire" …

---

## [How to give specific disk threshold for specific node in a Elastic cluster](https://discuss.elastic.co/t/how-to-give-specific-disk-threshold-for-specific-node-in-a-elastic-cluster/344247)

<div class="topic-metadata">

**Author:** [@hiruni.insyncit.net](https://discuss.elastic.co/u/hiruni.insyncit.net)\
**Replies:** 5\
**Last updated:** [October 6, 2023, 7:00pm UTC](https://discuss.elastic.co/t/how-to-give-specific-disk-threshold-for-specific-node-in-a-elastic-cluster/344247 "2023-10-06T19:00:03Z")

</div>

Hi, I have a multi-node cluster. I want to allocate only 100 shards to a specific node in the elastic cluster. (But other nodes should be allocated more than 100 shards.) I have one node that has less disk space than …

---

## [How to calculate EPS-Events per second in Elastic cluster](https://discuss.elastic.co/t/how-to-calculate-eps-events-per-second-in-elastic-cluster/344548)

<div class="topic-metadata">

**Author:** [@hiruni.insyncit.net](https://discuss.elastic.co/u/hiruni.insyncit.net)\
**Replies:** 0\
**Last updated:** [October 6, 2023, 6:55pm UTC](https://discuss.elastic.co/t/how-to-calculate-eps-events-per-second-in-elastic-cluster/344548 "2023-10-06T18:55:27Z")

</div>

Hi, I want to calculate the average and maximum EPS in my cluster. I'm using the ELK 8.1.2 version. Thank you..! Hiruni

---

## [Documented options to disable xpack plugins in kibana not working as expected and cause container fail to start](https://discuss.elastic.co/t/documented-options-to-disable-xpack-plugins-in-kibana-not-working-as-expected-and-cause-container-fail-to-start/344529)

<div class="topic-metadata">

**Author:** [@hakakuma](https://discuss.elastic.co/u/hakakuma)\
**Replies:** 1\
**Last updated:** [October 6, 2023, 3:55pm UTC](https://discuss.elastic.co/t/documented-options-to-disable-xpack-plugins-in-kibana-not-working-as-expected-and-cause-container-fail-to-start/344529 "2023-10-06T15:55:24Z")

</div>

We are trying kibana 8.9.0 container as a standalone server for the first time and we are trying to disable certain xpack packages using kibana.yml We wanted to disable the below plugins and we are following elastic doc…

---

## [Collect all Prometheus Metrics 8.7 integration, also looking to target live\_msgs](https://discuss.elastic.co/t/collect-all-prometheus-metrics-8-7-integration-also-looking-to-target-live-msgs/344536)

<div class="topic-metadata">

**Author:** [@Ryan\_Downey](https://discuss.elastic.co/u/Ryan_Downey)\
**Replies:** 0\
**Last updated:** [October 6, 2023, 3:25pm UTC](https://discuss.elastic.co/t/collect-all-prometheus-metrics-8-7-integration-also-looking-to-target-live-msgs/344536 "2023-10-06T15:25:26Z")

</div>

Team, I'm having trouble understanding how to collect all of the Prometheus metrics available. We currently have Elastic Agent (EA) working and connected to the Prometheus server but its not pulling any data for one of…

---

## [Time\_zone in Lucence query](https://discuss.elastic.co/t/time-zone-in-lucence-query/344534)

<div class="topic-metadata">

**Author:** [@Michael7](https://discuss.elastic.co/u/Michael7)\
**Replies:** 0\
**Last updated:** [October 6, 2023, 2:17pm UTC](https://discuss.elastic.co/t/time-zone-in-lucence-query/344534 "2023-10-06T14:17:34Z")

</div>

Hi, Im trying to realize how to specify time\_zone in URI query for elastic. ...&q=Mobile AND delivered\_at:\["now-30d" TO "now"\] How I can add time\_zone +03:00 to delivered\_at field?

---

## [Deployment upgrade from 8.2.2 to 8.10.2 disk space error](https://discuss.elastic.co/t/deployment-upgrade-from-8-2-2-to-8-10-2-disk-space-error/344399)

<div class="topic-metadata">

**Author:** [@Ryan\_Downey](https://discuss.elastic.co/u/Ryan_Downey)\
**Replies:** 2\
**Last updated:** [October 6, 2023, 1:05pm UTC](https://discuss.elastic.co/t/deployment-upgrade-from-8-2-2-to-8-10-2-disk-space-error/344399 "2023-10-06T13:05:03Z")

</div>

I'm trying to upgrade a deployment from 8.2.2 to 8.10.2 and keep hitting the error below. The basics are pretty clear, there isn't enough disk space, but is this for just one of the nodes or the entire deployment? If …

---

## [Upload CSV File to Kibana Dashboard](https://discuss.elastic.co/t/upload-csv-file-to-kibana-dashboard/342821)

<div class="topic-metadata">

**Author:** [@Debasis\_Mallick](https://discuss.elastic.co/u/Debasis_Mallick)\
**Replies:** 25\
**Last updated:** [October 6, 2023, 10:53am UTC](https://discuss.elastic.co/t/upload-csv-file-to-kibana-dashboard/342821 "2023-10-06T10:53:19Z")

</div>

Hi Team, I need help on below two points while uploading csv file through kibana dashboard. How to upload a csv file size of more than 100MB through the kibana dashboard. How to upload multiple csv files to same indic…

---

## [Deserialising Avro data in losgstash](https://discuss.elastic.co/t/deserialising-avro-data-in-losgstash/344531)

<div class="topic-metadata">

**Author:** [@DivyaDileep](https://discuss.elastic.co/u/DivyaDileep)\
**Replies:** 0\
**Last updated:** [October 6, 2023, 10:22am UTC](https://discuss.elastic.co/t/deserialising-avro-data-in-losgstash/344531 "2023-10-06T10:22:07Z")

</div>

Continuing the discussion from Unable to Parse AVRO using Kafka Input and Avro Codec:

---

## [Elasticsearch License](https://discuss.elastic.co/t/elasticsearch-license/344471)

<div class="topic-metadata">

**Author:** [@Debasis\_Mallick](https://discuss.elastic.co/u/Debasis_Mallick)\
**Replies:** 7\
**Last updated:** [October 6, 2023, 10:10am UTC](https://discuss.elastic.co/t/elasticsearch-license/344471 "2023-10-06T10:10:36Z")

</div>

Hi Team, Could you please help me to understand the licensing part of Elasticsearch. Because I had installed Elasticsearch from below link and now while using Kibana dashboard today it is showing License related error.…

---

## [Elastic and kibana logs](https://discuss.elastic.co/t/elastic-and-kibana-logs/344448)

<div class="topic-metadata">

**Author:** [@MahithaSarala](https://discuss.elastic.co/u/MahithaSarala)\
**Replies:** 3\
**Last updated:** [October 6, 2023, 9:23am UTC](https://discuss.elastic.co/t/elastic-and-kibana-logs/344448 "2023-10-06T09:23:42Z")

</div>

Hi Team, I have deployed elasticsearch (v8.5.3) and kibana through eck , How to enable debugs for kibana, can you help on this . Thanks&Regards, SM

---

## [It's possible to encrypt Snapshots or ElasticSearch Snapshot repository?](https://discuss.elastic.co/t/its-possible-to-encrypt-snapshots-or-elasticsearch-snapshot-repository/344524)

<div class="topic-metadata">

**Author:** [@Alberto\_Roca](https://discuss.elastic.co/u/Alberto_Roca)\
**Replies:** 0\
**Last updated:** [October 6, 2023, 7:37am UTC](https://discuss.elastic.co/t/its-possible-to-encrypt-snapshots-or-elasticsearch-snapshot-repository/344524 "2023-10-06T07:37:05Z")

</div>

Currently the structure I have is made up of a cluster with Elasticsearch nodes, which take snapshots and are saved in their corresponding repository. This data is later sent to an already encrypted Ceph bucket. Is there…

---

## [How can we create synthetic light weight monitor for private URLs?](https://discuss.elastic.co/t/how-can-we-create-synthetic-light-weight-monitor-for-private-urls/344444)

<div class="topic-metadata">

**Author:** [@surya\_dadi\_dhamarake](https://discuss.elastic.co/u/surya_dadi_dhamarake)\
**Replies:** 3\
**Last updated:** [October 6, 2023, 7:37am UTC](https://discuss.elastic.co/t/how-can-we-create-synthetic-light-weight-monitor-for-private-urls/344444 "2023-10-06T07:37:06Z")

</div>

Hi , I am trying to reach the URLs which are hosted on private VPC which are only accessible through vpn. Is there any way to connect to the URLs using synthetic lightweight monitor?

---

## [Throughput tweaks for Elastic Agent Integrations? Agent integration not able to keep up with volume of events within an Eventhub](https://discuss.elastic.co/t/throughput-tweaks-for-elastic-agent-integrations-agent-integration-not-able-to-keep-up-with-volume-of-events-within-an-eventhub/344515)

<div class="topic-metadata">

**Author:** [@elasticnub](https://discuss.elastic.co/u/elasticnub)\
**Replies:** 0\
**Last updated:** [October 6, 2023, 3:17am UTC](https://discuss.elastic.co/t/throughput-tweaks-for-elastic-agent-integrations-agent-integration-not-able-to-keep-up-with-volume-of-events-within-an-eventhub/344515 "2023-10-06T03:17:32Z")

</div>

We are having issues with the agent being able to support roughly ~80GB a day of M365 event data ingestion being pulled from an EventHub. The aggregation server is by no means pegged on any resources so I am trying to fi…

---

## [Filebeat logging MSSQL ERROR log, but not able to search on Message field in Kibana](https://discuss.elastic.co/t/filebeat-logging-mssql-error-log-but-not-able-to-search-on-message-field-in-kibana/344428)

<div class="topic-metadata">

**Author:** [@dbaddorf](https://discuss.elastic.co/u/dbaddorf)\
**Replies:** 1\
**Last updated:** [October 5, 2023, 10:26pm UTC](https://discuss.elastic.co/t/filebeat-logging-mssql-error-log-but-not-able-to-search-on-message-field-in-kibana/344428 "2023-10-05T22:26:19Z")

</div>

I have Filebeat using the MSSQL module running on a Windows SQL Server exporting logs to an Elasticsearch server. I can view the Filebeat logs in Kibana. But I can't (seem) to search on the Message field. For example,…

---

## [How to display node hostname in Kibana stack monitoring?](https://discuss.elastic.co/t/how-to-display-node-hostname-in-kibana-stack-monitoring/344504)

<div class="topic-metadata">

**Author:** [@Jignesh\_Soni](https://discuss.elastic.co/u/Jignesh_Soni)\
**Replies:** 1\
**Last updated:** [October 5, 2023, 8:10pm UTC](https://discuss.elastic.co/t/how-to-display-node-hostname-in-kibana-stack-monitoring/344504 "2023-10-05T20:10:03Z")

</div>

Hi All, Hostname is set in Elasticsearch and Kibana configurations , but still Kibana stack monitoring is showing only IP address of nodes. Is there any way to show host name also of nodes in stack monitoring in Kibana…

---

## [@Timestamp is not matching event timestamp \_dateparsefailure](https://discuss.elastic.co/t/timestamp-is-not-matching-event-timestamp-dateparsefailure/344506)

<div class="topic-metadata">

**Author:** [@Cara410](https://discuss.elastic.co/u/Cara410)\
**Replies:** 2\
**Last updated:** [October 5, 2023, 8:01pm UTC](https://discuss.elastic.co/t/timestamp-is-not-matching-event-timestamp-dateparsefailure/344506 "2023-10-05T20:01:48Z")

</div>

Hello All, I am having filebeat send data through logstash and I have been unable to get the @timestamp to match the event time. I get a \_dateparsefailure tag in Kibana. Everything else is ingesting as intended. I have …

---

## [Using Elasticsearch Completion Suggester for large text search](https://discuss.elastic.co/t/using-elasticsearch-completion-suggester-for-large-text-search/344507)

<div class="topic-metadata">

**Author:** [@TomTom](https://discuss.elastic.co/u/TomTom)\
**Replies:** 0\
**Last updated:** [October 5, 2023, 7:55pm UTC](https://discuss.elastic.co/t/using-elasticsearch-completion-suggester-for-large-text-search/344507 "2023-10-05T19:55:52Z")

</div>

Is it possible to use the Completion Suggester feature for Elasticsearch to find content as text is typed, similar to Elasticsearch's Discuss? For example, I have articles in my knowledge base that have a title and cont…

---

## [Query an Elasticsearch index for one field, all documents in last 24 hours?](https://discuss.elastic.co/t/query-an-elasticsearch-index-for-one-field-all-documents-in-last-24-hours/344493)

<div class="topic-metadata">

**Author:** [@Meme-ento](https://discuss.elastic.co/u/Meme-ento)\
**Replies:** 1\
**Last updated:** [October 5, 2023, 7:40pm UTC](https://discuss.elastic.co/t/query-an-elasticsearch-index-for-one-field-all-documents-in-last-24-hours/344493 "2023-10-05T19:40:16Z")

</div>

Hi There. I'm trying to make a simple get request to my elk index. I have the right credentials, hostname, index name, etc. my ELK version is 6.8.6 But for what I'm trying to get I cannot figure out how to construct …

---

## [Kibana error: security\_exception: \[security\_exception\] Reason: unable to authenticate with provided credentials and anonymous access is not allowed for this request](https://discuss.elastic.co/t/kibana-error-security-exception-security-exception-reason-unable-to-authenticate-with-provided-credentials-and-anonymous-access-is-not-allowed-for-this-request/344243)

<div class="topic-metadata">

**Author:** [@PodarcisMuralis](https://discuss.elastic.co/u/PodarcisMuralis)\
**Replies:** 1\
**Last updated:** [October 5, 2023, 3:26pm UTC](https://discuss.elastic.co/t/kibana-error-security-exception-security-exception-reason-unable-to-authenticate-with-provided-credentials-and-anonymous-access-is-not-allowed-for-this-request/344243 "2023-10-05T15:26:00Z")

</div>

Hi. I upgraded the Kibana from 7.17 to 8.5.3 and got some corrupt indices. then I used these instructions and deleted .kibana and . monitoring indices. Resolve Migration Failures But I also deleted .security\_7. This …

---

## [Kibana Error - Error while updating search session x: Saved object x conflict](https://discuss.elastic.co/t/kibana-error-error-while-updating-search-session-x-saved-object-x-conflict/343783)

<div class="topic-metadata">

**Author:** [@PodarcisMuralis](https://discuss.elastic.co/u/PodarcisMuralis)\
**Replies:** 1\
**Last updated:** [October 5, 2023, 2:56pm UTC](https://discuss.elastic.co/t/kibana-error-error-while-updating-search-session-x-saved-object-x-conflict/343783 "2023-10-05T14:56:31Z")

</div>

Hello. I am using Kibana 8.5.3 and getting this error continuously. Error while updating search session b4100d1f-dfea-4ba9-8873-070219cbfe5f: Saved object \[search-session/b4100d1f-dfea-4ba9-8873-070219cbfe5f\] conflict…

---

## [Kibana fleet error - Failed to fetch latest version of synthetics from registry: Error connecting to package registry: request to URL failed, reason: connect ENETUNREACH xx.xxx.xxx.xxx:xxx - Local (0.0.0.0:0)](https://discuss.elastic.co/t/kibana-fleet-error-failed-to-fetch-latest-version-of-synthetics-from-registry-error-connecting-to-package-registry-request-to-url-failed-reason-connect-enetunreach-xx-xxx-xxx-xxx-xxx-local-0-0-0-0-0/344498)

<div class="topic-metadata">

**Author:** [@PodarcisMuralis](https://discuss.elastic.co/u/PodarcisMuralis)\
**Replies:** 0\
**Last updated:** [October 5, 2023, 2:43pm UTC](https://discuss.elastic.co/t/kibana-fleet-error-failed-to-fetch-latest-version-of-synthetics-from-registry-error-connecting-to-package-registry-request-to-url-failed-reason-connect-enetunreach-xx-xxx-xxx-xxx-xxx-local-0-0-0-0-0/344498 "2023-10-05T14:43:55Z")

</div>

Hi. I am using Kibana 8.5.3 and everytime I start Kibana with "sudo systemctl start kibana" or restart, I get this error once. Failed to fetch latest version of synthetics from registry: Error connecting to package reg…

---

## [bulkIndex() or saveAll()?](https://discuss.elastic.co/t/bulkindex-or-saveall/344487)

<div class="topic-metadata">

**Author:** [@Cemre\_Senyuva](https://discuss.elastic.co/u/Cemre_Senyuva)\
**Replies:** 0\
**Last updated:** [October 5, 2023, 1:24pm UTC](https://discuss.elastic.co/t/bulkindex-or-saveall/344487 "2023-10-05T13:24:19Z")

</div>

Which one is faster method to save/index in elasticsearch bulkIndex() or saveAll()?

---

## [Elasticsearch SCCM Windows deployment](https://discuss.elastic.co/t/elasticsearch-sccm-windows-deployment/344497)

<div class="topic-metadata">

**Author:** [@Waldfried](https://discuss.elastic.co/u/Waldfried)\
**Replies:** 0\
**Last updated:** [October 5, 2023, 2:24pm UTC](https://discuss.elastic.co/t/elasticsearch-sccm-windows-deployment/344497 "2023-10-05T14:24:20Z")

</div>

Hi everyone, i'm having problems deploying Elasticsearch via SCCM. During execution the setup tries to create a symlink which is working as long as i install it with a administrative user account. As soon as the setup …

---

## [Kibana errors after changing encryptionKey - Failed to decrypt "apiKey" attribute: Unsupported state or unable to authenticate data](https://discuss.elastic.co/t/kibana-errors-after-changing-encryptionkey-failed-to-decrypt-apikey-attribute-unsupported-state-or-unable-to-authenticate-data/344492)

<div class="topic-metadata">

**Author:** [@PodarcisMuralis](https://discuss.elastic.co/u/PodarcisMuralis)\
**Replies:** 1\
**Last updated:** [October 5, 2023, 2:21pm UTC](https://discuss.elastic.co/t/kibana-errors-after-changing-encryptionkey-failed-to-decrypt-apikey-attribute-unsupported-state-or-unable-to-authenticate-data/344492 "2023-10-05T14:21:07Z")

</div>

I use elasticstack 8.5.3 and have 2 Logstash, 5 ELS and 1 Kibana nodes. I was cleaning the older kibana system indices ( upgraded from 7.17.7) and deleted .security\_7 index also and had to create all built in users agai…

---

## [Elasticsearch jvm memory outbursts above settings causing oom-kill](https://discuss.elastic.co/t/elasticsearch-jvm-memory-outbursts-above-settings-causing-oom-kill/344490)

<div class="topic-metadata">

**Author:** [@Guillaume\_Soustrade](https://discuss.elastic.co/u/Guillaume_Soustrade)\
**Replies:** 0\
**Last updated:** [October 5, 2023, 1:49pm UTC](https://discuss.elastic.co/t/elasticsearch-jvm-memory-outbursts-above-settings-causing-oom-kill/344490 "2023-10-05T13:49:55Z")

</div>

Dear Elasticsearch connoisseurs, We have a repeating issue in our clusters of nodes suddenly exiting due to the java process being oom-killed. Let's take the example of this falling node : 94.3 Go of RAM 8 CPUs SWAP …

---

## [Elastic-Agent takes up too much disk space](https://discuss.elastic.co/t/elastic-agent-takes-up-too-much-disk-space/344429)

<div class="topic-metadata">

**Author:** [@swtrux](https://discuss.elastic.co/u/swtrux)\
**Replies:** 3\
**Last updated:** [October 5, 2023, 1:32pm UTC](https://discuss.elastic.co/t/elastic-agent-takes-up-too-much-disk-space/344429 "2023-10-05T13:32:50Z")

</div>

The size of elastic-agent continues to increase with every version: 8.8 1.7G 8.7 1.4G 8.6 1.2G 8.5 415M 1.7GB for this package size is way too big. We are looking at moving to elastic-agent but can't have over 2000 …

---

## [Does Elastic accept combined JSON with flatten keys](https://discuss.elastic.co/t/does-elastic-accept-combined-json-with-flatten-keys/344373)

<div class="topic-metadata">

**Author:** [@ddoroshenko](https://discuss.elastic.co/u/ddoroshenko)\
**Replies:** 1\
**Last updated:** [October 4, 2023, 12:06pm UTC](https://discuss.elastic.co/t/does-elastic-accept-combined-json-with-flatten-keys/344373 "2023-10-04T12:06:17Z")

</div>

Hi, is it possible to send to ES messages in combined JSON format { "a": { "b": { "c.d.e.f": "value" } } } or it ends with error like can't merge a non object mapping with an object mapping?

---

## [How to change an index mapping in Elastic search](https://discuss.elastic.co/t/how-to-change-an-index-mapping-in-elastic-search/344456)

<div class="topic-metadata">

**Author:** [@Francesco66](https://discuss.elastic.co/u/Francesco66)\
**Replies:** 4\
**Last updated:** [October 5, 2023, 11:47am UTC](https://discuss.elastic.co/t/how-to-change-an-index-mapping-in-elastic-search/344456 "2023-10-05T11:47:11Z")

</div>

Hello, I am ingesting the following document into Elasticsearch via Logstash: \[xxxx@yyyy ~\]# curl -k http://my\_es\_hostname:9200/cdp-zos-syslog-console-plex75-20231005/\_search?pretty { "took" : 564, "timed\_out" : fal…

---

## [Optimal way to handle log with multiple format?](https://discuss.elastic.co/t/optimal-way-to-handle-log-with-multiple-format/344470)

<div class="topic-metadata">

**Author:** [@Tanin\_Imanothai](https://discuss.elastic.co/u/Tanin_Imanothai)\
**Replies:** 0\
**Last updated:** [October 5, 2023, 10:33am UTC](https://discuss.elastic.co/t/optimal-way-to-handle-log-with-multiple-format/344470 "2023-10-05T10:33:57Z")

</div>

I try to parse this dataset: https://github.com/logpai/loghub/tree/master/Android using logstash. I have tried using grok filter but some parts of the log contains multiple templates. example of log: 03-17 16:13:38.81…

[Previous page](https://discuss.elastic.co/tag/none.md?no_tags=true&page=292)

[Next page](https://discuss.elastic.co/tag/none.md?no_tags=true&page=294)
