# \#none

**URL:** https://discuss.elastic.co/tag/none.md?no_tags=true&page=294

[Latest](https://discuss.elastic.co/latest.md) · [Categories](https://discuss.elastic.co/categories.md) · [Tags](https://discuss.elastic.co/tags.md)

**Page:** 295

---

## [View SAML Users](https://discuss.elastic.co/t/view-saml-users/344462)

<div class="topic-metadata">

**Author:** [@lehu](https://discuss.elastic.co/u/lehu)\
**Replies:** 0\
**Last updated:** [October 5, 2023, 9:20am UTC](https://discuss.elastic.co/t/view-saml-users/344462 "2023-10-05T09:20:13Z")

</div>

Hi, does anybody know why I can't see users that login with SAML even though I am an admin? It is necessary to view all users to change their roles otherwise all SAML users have the same role, which I dont want... Any su…

---

## [Watcher filter Latency\_info](https://discuss.elastic.co/t/watcher-filter-latency-info/344458)

<div class="topic-metadata">

**Author:** [@Aitor\_MtzAm](https://discuss.elastic.co/u/Aitor_MtzAm)\
**Replies:** 0\
**Last updated:** [October 5, 2023, 8:52am UTC](https://discuss.elastic.co/t/watcher-filter-latency-info/344458 "2023-10-05T08:52:34Z")

</div>

I need the watcher to differentiate between 2 values of the same field: Within the latency\_info field in the task "Integration" I need to differentiate whether the result field is "-" or "200". "latency\_info": \[ { "t…

---

## [Salesforce input logstash - add filter](https://discuss.elastic.co/t/salesforce-input-logstash-add-filter/344217)

<div class="topic-metadata">

**Author:** [@Samuele\_Lolli](https://discuss.elastic.co/u/Samuele_Lolli)\
**Replies:** 4\
**Last updated:** [October 5, 2023, 8:17am UTC](https://discuss.elastic.co/t/salesforce-input-logstash-add-filter/344217 "2023-10-05T08:17:50Z")

</div>

I have a input configuration like that and i wonder if is possible to filter document like with a query or something like that. salesforce{ use\_test\_sandbox =\> true client\_id =\> '' client…

---

## [Why does cluster.routing.allocation.exclude.\_ip only work as a transient, not persistent setting?](https://discuss.elastic.co/t/why-does-cluster-routing-allocation-exclude-ip-only-work-as-a-transient-not-persistent-setting/344419)

<div class="topic-metadata">

**Author:** [@Jamshid](https://discuss.elastic.co/u/Jamshid)\
**Replies:** 3\
**Last updated:** [October 5, 2023, 7:12am UTC](https://discuss.elastic.co/t/why-does-cluster-routing-allocation-exclude-ip-only-work-as-a-transient-not-persistent-setting/344419 "2023-10-05T07:12:47Z")

</div>

Just a sanity check... trying to remove a node by setting cluster.routing.allocation.exclude.\_ip does not seem to have any effect if it's a persistent setting. Tested with elasticesarch 7.17.13 on a 3-node cluster. When …

---

## [Lot of delay in logs parsing at kibana GUI](https://discuss.elastic.co/t/lot-of-delay-in-logs-parsing-at-kibana-gui/344449)

<div class="topic-metadata">

**Author:** [@syedsyed](https://discuss.elastic.co/u/syedsyed)\
**Replies:** 0\
**Last updated:** [October 5, 2023, 7:01am UTC](https://discuss.elastic.co/t/lot-of-delay-in-logs-parsing-at-kibana-gui/344449 "2023-10-05T07:01:33Z")

</div>

I have Elasticsearch and kibana installed and i have integrated the fleet server into it, enrolled the elastic agent with sonicwall integration into it, but i am facing lot of delay of about one and half day, mostly the …

---

## [Elastic system indices migration issue while upgrade](https://discuss.elastic.co/t/elastic-system-indices-migration-issue-while-upgrade/344434)

<div class="topic-metadata">

**Author:** [@Harper\_S1](https://discuss.elastic.co/u/Harper_S1)\
**Replies:** 1\
**Last updated:** [October 5, 2023, 6:10am UTC](https://discuss.elastic.co/t/elastic-system-indices-migration-issue-while-upgrade/344434 "2023-10-05T06:10:48Z")

</div>

Hi, I am upgrading elastic from 6.8 to 7.17.0 and then 8.x.x. From version 6.8 to 7.17 migration was fine but while preparing to migrate from version 7.17 to 8.x.x upgrade assistant is not able to migrate this one(Task…

---

## [Master node in ECK with differente IP between pod and elasticsearch](https://discuss.elastic.co/t/master-node-in-eck-with-differente-ip-between-pod-and-elasticsearch/344431)

<div class="topic-metadata">

**Author:** [@dudds22](https://discuss.elastic.co/u/dudds22)\
**Replies:** 0\
**Last updated:** [October 4, 2023, 8:34pm UTC](https://discuss.elastic.co/t/master-node-in-eck-with-differente-ip-between-pod-and-elasticsearch/344431 "2023-10-04T20:34:06Z")

</div>

Hi, Today we faced a strange situation and really want to share with you in order to try to obtain more infos about what can be happened. Context: We have a elasticsearch cluster and we need to send slowlogs to Datado…

---

## [Elastic query takes over 1 minute due to time spent in "HighlightPhase"](https://discuss.elastic.co/t/elastic-query-takes-over-1-minute-due-to-time-spent-in-highlightphase/344344)

<div class="topic-metadata">

**Author:** [@David\_Avant](https://discuss.elastic.co/u/David_Avant)\
**Replies:** 5\
**Last updated:** [October 4, 2023, 7:26pm UTC](https://discuss.elastic.co/t/elastic-query-takes-over-1-minute-due-to-time-spent-in-highlightphase/344344 "2023-10-04T19:26:59Z")

</div>

Some elastic queries are slow, taking more than a minute to execute. The query input is simple: just a single, numeric account identifier (i.e. "123456789"). The query takes 68 seconds to execute and returns 6 hits. T…

---

## [File not found when attempting to index](https://discuss.elastic.co/t/file-not-found-when-attempting-to-index/344353)

<div class="topic-metadata">

**Author:** [@Ahriss](https://discuss.elastic.co/u/Ahriss)\
**Replies:** 2\
**Last updated:** [October 4, 2023, 7:23pm UTC](https://discuss.elastic.co/t/file-not-found-when-attempting-to-index/344353 "2023-10-04T19:23:12Z")

</div>

Hello. I'm building a simple elasticsearch/PHP application, and I got a very weird error. I can search on it just fine, though I need to build pagination for it still, but when I attempt to index something, I simply get …

---

## [ERROR: Skipping security auto configuration because it appears that the node is not starting up for the first time. The node might already be part of a cluster and this auto setup utility is designed to configure Security for new clusters only., with exit](https://discuss.elastic.co/t/error-skipping-security-auto-configuration-because-it-appears-that-the-node-is-not-starting-up-for-the-first-time-the-node-might-already-be-part-of-a-cluster-and-this-auto-setup-utility-is-designed-to-configure-security-for-new-clusters-only-with-exit/344422)

<div class="topic-metadata">

**Author:** [@nav\_11](https://discuss.elastic.co/u/nav_11)\
**Replies:** 0\
**Last updated:** [October 4, 2023, 6:29pm UTC](https://discuss.elastic.co/t/error-skipping-security-auto-configuration-because-it-appears-that-the-node-is-not-starting-up-for-the-first-time-the-node-might-already-be-part-of-a-cluster-and-this-auto-setup-utility-is-designed-to-configure-security-for-new-clusters-only-with-exit/344422 "2023-10-04T18:29:24Z")

</div>

Getting below error while adding the node. I am following the MACOS setup guide below. Command: bin/elasticsearch --enrollment-token ERROR: Skipping security auto configuration because it appears that the node is no…

---

## [Import Objects API for Rules/Connectors](https://discuss.elastic.co/t/import-objects-api-for-rules-connectors/344409)

<div class="topic-metadata">

**Author:** [@ameindel](https://discuss.elastic.co/u/ameindel)\
**Replies:** 1\
**Last updated:** [October 4, 2023, 5:38pm UTC](https://discuss.elastic.co/t/import-objects-api-for-rules-connectors/344409 "2023-10-04T17:38:36Z")

</div>

Hello, Elastic! I'm currently using a curl command to push an Alert Rule. Currently the rule gets created but is created in a 'disabled' state (see warnings.message): { "successCount": 1, "success": true, "warnin…

---

## [Getting index rate](https://discuss.elastic.co/t/getting-index-rate/344381)

<div class="topic-metadata">

**Author:** [@avnere](https://discuss.elastic.co/u/avnere)\
**Replies:** 1\
**Last updated:** [October 4, 2023, 3:56pm UTC](https://discuss.elastic.co/t/getting-index-rate/344381 "2023-10-04T15:56:49Z")

</div>

Hi, I am looking a way to monitor index rate not through Kibana. Is there any RestAPI command that provide the current index rate? Is there alternative way? Thanks...

---

## [Elasticsearch on K8s VS Vm](https://discuss.elastic.co/t/elasticsearch-on-k8s-vs-vm/344384)

<div class="topic-metadata">

**Author:** [@avnere](https://discuss.elastic.co/u/avnere)\
**Replies:** 0\
**Last updated:** [October 4, 2023, 12:09pm UTC](https://discuss.elastic.co/t/elasticsearch-on-k8s-vs-vm/344384 "2023-10-04T12:09:15Z")

</div>

Hi, On production which approach is preferred? Installing elastic on K8s or Vm? Is there any difference\\limitation? Thanks...

---

## [elasticsearch.UnsupportedProductError: The client noticed that the server is not Elasticsearch and we do not support this unknown product](https://discuss.elastic.co/t/elasticsearch-unsupportedproducterror-the-client-noticed-that-the-server-is-not-elasticsearch-and-we-do-not-support-this-unknown-product/344379)

<div class="topic-metadata">

**Author:** [@Arshdeep\_Singh](https://discuss.elastic.co/u/Arshdeep_Singh)\
**Replies:** 2\
**Last updated:** [October 4, 2023, 11:15am UTC](https://discuss.elastic.co/t/elasticsearch-unsupportedproducterror-the-client-noticed-that-the-server-is-not-elasticsearch-and-we-do-not-support-this-unknown-product/344379 "2023-10-04T11:15:22Z")

</div>

Here I'm trying to create a full sync between Django's database and Elastic Search. While running the command "python manage.py search\_index --create -f", I'm getting the error: ERROR: Traceback (most recent call last)…

---

## [Optimizing Elasticsearch Cluster Setup: Merging Logs Across Two Node](https://discuss.elastic.co/t/optimizing-elasticsearch-cluster-setup-merging-logs-across-two-node/344371)

<div class="topic-metadata">

**Author:** [@Priyaansh\_Dwivedi](https://discuss.elastic.co/u/Priyaansh_Dwivedi)\
**Replies:** 0\
**Last updated:** [October 4, 2023, 9:57am UTC](https://discuss.elastic.co/t/optimizing-elasticsearch-cluster-setup-merging-logs-across-two-node/344371 "2023-10-04T09:57:08Z")

</div>

"I have always valued the support of this community, and I find myself in need of assistance once again. Here's the situation: I currently have Elasticsearch installed on VM1, but I'm facing disk space issues, and the cl…

---

## [Unexpected Behavior of OR Match Query With Synonym Graph](https://discuss.elastic.co/t/unexpected-behavior-of-or-match-query-with-synonym-graph/344320)

<div class="topic-metadata">

**Author:** [@MilanGatyas](https://discuss.elastic.co/u/MilanGatyas)\
**Replies:** 3\
**Last updated:** [October 4, 2023, 9:45am UTC](https://discuss.elastic.co/t/unexpected-behavior-of-or-match-query-with-synonym-graph/344320 "2023-10-04T09:45:03Z")

</div>

I don't know if the following behavior is intended or not. See the following example of index definition and documents: PUT /test { "settings": { "analysis": { "filter": { "syn": { "syn…

---

## [Wildcard-like search on synonym authorizer](https://discuss.elastic.co/t/wildcard-like-search-on-synonym-authorizer/344363)

<div class="topic-metadata">

**Author:** [@mkalaaji](https://discuss.elastic.co/u/mkalaaji)\
**Replies:** 0\
**Last updated:** [October 4, 2023, 7:44am UTC](https://discuss.elastic.co/t/wildcard-like-search-on-synonym-authorizer/344363 "2023-10-04T07:44:44Z")

</div>

Currently facing an issue with synonyms and using Elasticsearch managed service not self hosted elasticsearch I have created a synonym file and created an authorizer that utilizes this synonym file in a filter PUT /sto…

---

## [From Python to Rust](https://discuss.elastic.co/t/from-python-to-rust/344329)

<div class="topic-metadata">

**Author:** [@FrederickFrance](https://discuss.elastic.co/u/FrederickFrance)\
**Replies:** 2\
**Last updated:** [October 4, 2023, 7:34am UTC](https://discuss.elastic.co/t/from-python-to-rust/344329 "2023-10-04T07:34:56Z")

</div>

Hi all, I'm a newbie with Python and Elasticsearch. I'm trying to create a client from host, username and password. With Python, the original code is: Elasticsearch( hosts=hosts, http\_auth=(es…

---

## [Fuzziness on multiple fields and match a particular field elastic search query](https://discuss.elastic.co/t/fuzziness-on-multiple-fields-and-match-a-particular-field-elastic-search-query/344361)

<div class="topic-metadata">

**Author:** [@uma\_parvathy](https://discuss.elastic.co/u/uma_parvathy)\
**Replies:** 0\
**Last updated:** [October 4, 2023, 7:32am UTC](https://discuss.elastic.co/t/fuzziness-on-multiple-fields-and-match-a-particular-field-elastic-search-query/344361 "2023-10-04T07:32:12Z")

</div>

Hi All, My requirement is to get the response for a specific word which can be appear anywhere in the document and it should belongs the user's account id. i've to use date range query like last 3 hours or 24 hours doc…

---

## [Is BulkIngester (replacement of 'Bulk Processor') in elasticsearch java api thread safe?](https://discuss.elastic.co/t/is-bulkingester-replacement-of-bulk-processor-in-elasticsearch-java-api-thread-safe/344285)

<div class="topic-metadata">

**Author:** [@Irfanulla](https://discuss.elastic.co/u/Irfanulla)\
**Replies:** 2\
**Last updated:** [October 4, 2023, 7:12am UTC](https://discuss.elastic.co/t/is-bulkingester-replacement-of-bulk-processor-in-elasticsearch-java-api-thread-safe/344285 "2023-10-04T07:12:35Z")

</div>

Use case: I have multiple kafka listeners for various topics. Each topic Listener will run in multiple threads (using spring's 'ConcurrentKafkaListenerContainer'). Listeners will be performing Update/Insert operations on…

---

## [Logs are not ingesting to elasticsearch](https://discuss.elastic.co/t/logs-are-not-ingesting-to-elasticsearch/344355)

<div class="topic-metadata">

**Author:** [@rahul\_sirugudi](https://discuss.elastic.co/u/rahul_sirugudi)\
**Replies:** 0\
**Last updated:** [October 4, 2023, 4:40am UTC](https://discuss.elastic.co/t/logs-are-not-ingesting-to-elasticsearch/344355 "2023-10-04T04:40:27Z")

</div>

This was my set up earlier. filebeat =\> logstash (SQS-PUSH) =\> logstash (SQS-PULL) =\> elasticsearch. The above approach seems very costlier to us because of (SQS API) calls. Hence we replaced kafka (standalone). fileb…

---

## [Elastic dev tool has different total hits number than discover query search](https://discuss.elastic.co/t/elastic-dev-tool-has-different-total-hits-number-than-discover-query-search/344275)

<div class="topic-metadata">

**Author:** [@JasonREC](https://discuss.elastic.co/u/JasonREC)\
**Replies:** 9\
**Last updated:** [October 4, 2023, 2:22am UTC](https://discuss.elastic.co/t/elastic-dev-tool-has-different-total-hits-number-than-discover-query-search/344275 "2023-10-04T02:22:53Z")

</div>

Hi, I have the same query and with the same filter. But the dev tool and discover give me different total hit counts ..I wonder what is the reason to that? and which is the accurate one

---

## [Restoring indexes that have missing shards from snapshot](https://discuss.elastic.co/t/restoring-indexes-that-have-missing-shards-from-snapshot/344265)

<div class="topic-metadata">

**Author:** [@Russell\_Fulton](https://discuss.elastic.co/u/Russell_Fulton)\
**Replies:** 3\
**Last updated:** [October 4, 2023, 2:11am UTC](https://discuss.elastic.co/t/restoring-indexes-that-have-missing-shards-from-snapshot/344265 "2023-10-04T02:11:43Z")

</div>

I had a cluster node restart while another the cluster was still recovering from another node crashing which resulted in some indexes with missing shards. None of the affected indexes are currently being written and I h…

---

## [Elastic Defend Degraded - Configure Network Events](https://discuss.elastic.co/t/elastic-defend-degraded-configure-network-events/344297)

<div class="topic-metadata">

**Author:** [@GKre](https://discuss.elastic.co/u/GKre)\
**Replies:** 3\
**Last updated:** [October 4, 2023, 12:39am UTC](https://discuss.elastic.co/t/elastic-defend-degraded-configure-network-events/344297 "2023-10-04T00:39:24Z")

</div>

Hi there, i rolled out elastic defend to my kali linux vm. On this machine the Agend is degraded with Elastic Defend showing a problem "configure network events". {"@timestamp":"2023-09-30T10:41:44.190134275Z","agent"…

---

## [How to enable "Continue as Guest" on Kibana?](https://discuss.elastic.co/t/how-to-enable-continue-as-guest-on-kibana/343713)

<div class="topic-metadata">

**Author:** [@Ong](https://discuss.elastic.co/u/Ong)\
**Replies:** 4\
**Last updated:** [October 4, 2023, 12:05am UTC](https://discuss.elastic.co/t/how-to-enable-continue-as-guest-on-kibana/343713 "2023-10-04T00:05:37Z")

</div>

I would like to enable "Continue as Guest" on Kibana and have followed the elastic docs but it did not work. My setup is a Kibana container running on Kubernetes that connects to a backend Elasticsearch. Kibana can star…

---

## [Do Time series data streams (TSDS) store non-numeric/non-dimension logs efficiently?](https://discuss.elastic.co/t/do-time-series-data-streams-tsds-store-non-numeric-non-dimension-logs-efficiently/344352)

<div class="topic-metadata">

**Author:** [@micheal\_riff](https://discuss.elastic.co/u/micheal_riff)\
**Replies:** 0\
**Last updated:** [October 3, 2023, 10:40pm UTC](https://discuss.elastic.co/t/do-time-series-data-streams-tsds-store-non-numeric-non-dimension-logs-efficiently/344352 "2023-10-03T22:40:07Z")

</div>

Hi, I have a few questions about time series data streams (TSDS). I've tried looking through the documentation but am still confused on a few small things :slightly\_smiling\_face: I was wondering if fields that are not …

---

## [Elasticsearch performance testing](https://discuss.elastic.co/t/elasticsearch-performance-testing/344335)

<div class="topic-metadata">

**Author:** [@jaykb77](https://discuss.elastic.co/u/jaykb77)\
**Replies:** 0\
**Last updated:** [October 3, 2023, 6:10pm UTC](https://discuss.elastic.co/t/elasticsearch-performance-testing/344335 "2023-10-03T18:10:58Z")

</div>

Hi all, We are trying to come up with performance tests, stress tests etc to calculate throughput and identify bottlenecks in our elasticsearch cluster. We are using elasticsearch exporter to export metrics from the clu…

---

## [Problem updating field via SDK GO](https://discuss.elastic.co/t/problem-updating-field-via-sdk-go/344326)

<div class="topic-metadata">

**Author:** [@Wiliam\_Joaquim](https://discuss.elastic.co/u/Wiliam_Joaquim)\
**Replies:** 0\
**Last updated:** [October 3, 2023, 3:48pm UTC](https://discuss.elastic.co/t/problem-updating-field-via-sdk-go/344326 "2023-10-03T15:48:02Z")

</div>

I'm using the Go SDK to update data in Elasticsearch, but strangely, via the SDK it doesn't update a specific field, via the http client it works correctly sometimes: POST test/type1/123/\_update { "doc": { "asset…

---

## [Using script processor in elastic-agent integration](https://discuss.elastic.co/t/using-script-processor-in-elastic-agent-integration/342632)

<div class="topic-metadata">

**Author:** [@aaszxc](https://discuss.elastic.co/u/aaszxc)\
**Replies:** 1\
**Last updated:** [October 3, 2023, 3:44pm UTC](https://discuss.elastic.co/t/using-script-processor-in-elastic-agent-integration/342632 "2023-10-03T15:44:52Z")

</div>

Need your help. I don't like that using kubernetes integration in elastic-agents we have one event\_dataset for all logs: kubernetes.container\_logs I would like to split it into several. In filebeat this can be done with…

---

## [Unknown certifications?](https://discuss.elastic.co/t/unknown-certifications/344325)

<div class="topic-metadata">

**Author:** [@Daniel\_Calisto](https://discuss.elastic.co/u/Daniel_Calisto)\
**Replies:** 1\
**Last updated:** [October 3, 2023, 3:35pm UTC](https://discuss.elastic.co/t/unknown-certifications/344325 "2023-10-03T15:35:30Z")

</div>

Hi, a client is asking for this certifications, but it seems that they are not part of yours certifications: -Elasticsearch advanced data modeling. -Elasticsearch Developer. Googling I found this document that seems l…

[Previous page](https://discuss.elastic.co/tag/none.md?no_tags=true&page=293)

[Next page](https://discuss.elastic.co/tag/none.md?no_tags=true&page=295)
