# \#none

**URL:** https://discuss.elastic.co/tag/none.md?no_tags=true&page=297

[Latest](https://discuss.elastic.co/latest.md) · [Categories](https://discuss.elastic.co/categories.md) · [Tags](https://discuss.elastic.co/tags.md)

**Page:** 298

---

## [Is RHEL9 supported on Elasticsearch 7.10.x or lower version](https://discuss.elastic.co/t/is-rhel9-supported-on-elasticsearch-7-10-x-or-lower-version/344031)

<div class="topic-metadata">

**Author:** [@ajay.bansal123](https://discuss.elastic.co/u/ajay.bansal123)\
**Replies:** 4\
**Last updated:** [September 28, 2023, 8:47am UTC](https://discuss.elastic.co/t/is-rhel9-supported-on-elasticsearch-7-10-x-or-lower-version/344031 "2023-09-28T08:47:56Z")

</div>

Hi Folks, Does Elasticsearch 7.10.x OR lower version supports RHEL 9.x OR Rocky Linux 9.x I did not find this info on support-matrix page BR, ajay

---

## [Retention policy characteristics](https://discuss.elastic.co/t/retention-policy-characteristics/343879)

<div class="topic-metadata">

**Author:** [@Tostis](https://discuss.elastic.co/u/Tostis)\
**Replies:** 6\
**Last updated:** [September 28, 2023, 8:23am UTC](https://discuss.elastic.co/t/retention-policy-characteristics/343879 "2023-09-28T08:23:30Z")

</div>

Hello, I am pretty new to Elasticsearch, but got some questions about retention policies. If I am implementing a retention policy for example to delete old data from a index if it is older then 5 days. How is this hand…

---

## [Suggestion in terms of RAM for 3 master nodes and 3 coordinating nodes with 9 data nodes](https://discuss.elastic.co/t/suggestion-in-terms-of-ram-for-3-master-nodes-and-3-coordinating-nodes-with-9-data-nodes/344040)

<div class="topic-metadata">

**Author:** [@Manal\_A](https://discuss.elastic.co/u/Manal_A)\
**Replies:** 0\
**Last updated:** [September 28, 2023, 7:28am UTC](https://discuss.elastic.co/t/suggestion-in-terms-of-ram-for-3-master-nodes-and-3-coordinating-nodes-with-9-data-nodes/344040 "2023-09-28T07:28:40Z")

</div>

Hello, Give me pls an optimal suggestion in terms of RAM for 3 master nodes and 3 coordinating nodes with 9 data nodes each having 64GB. I m using Elastic version 8.8.1

---

## [High CPU usage periodically](https://discuss.elastic.co/t/high-cpu-usage-periodically/343250)

<div class="topic-metadata">

**Author:** [@xCeLfr](https://discuss.elastic.co/u/xCeLfr)\
**Replies:** 8\
**Last updated:** [September 28, 2023, 7:47am UTC](https://discuss.elastic.co/t/high-cpu-usage-periodically/343250 "2023-09-28T07:47:33Z")

</div>

Hi, there are many topics about CPU load but I can't find an answer. Our standalone Elasticsearch 7.12.0 node runs on a 16 GB RAM Linux server. Every 10 minutes or so elasticsearch consumes 100% CPU and queries are ver…

---

## [How to show two value percentages on one gauge?](https://discuss.elastic.co/t/how-to-show-two-value-percentages-on-one-gauge/343844)

<div class="topic-metadata">

**Author:** [@andrewarnier](https://discuss.elastic.co/u/andrewarnier)\
**Replies:** 3\
**Last updated:** [September 28, 2023, 7:24am UTC](https://discuss.elastic.co/t/how-to-show-two-value-percentages-on-one-gauge/343844 "2023-09-28T07:24:33Z")

</div>

hi all , I have a column in data which two values are Human and Bot, how i can calculate percentage and show in one gauge. for example 7 documents are Human and total documents are 1000 from 1/1 to 2/15 ,then Human …

---

## [What is the best aproach to add self-sign certificate to Elasticsearch Kubernetes](https://discuss.elastic.co/t/what-is-the-best-aproach-to-add-self-sign-certificate-to-elasticsearch-kubernetes/343760)

<div class="topic-metadata">

**Author:** [@astingengo](https://discuss.elastic.co/u/astingengo)\
**Replies:** 0\
**Last updated:** [September 25, 2023, 12:59pm UTC](https://discuss.elastic.co/t/what-is-the-best-aproach-to-add-self-sign-certificate-to-elasticsearch-kubernetes/343760 "2023-09-25T12:59:32Z")

</div>

I deployed Elasticsearch in Kubernetes and I'm trying to backup it to an S3 Instance that has a self sign certificate. What would be the best approach to do so \[having Elasticsearch in Kubernetes\]? I tried to import th…

---

## [Logstash not pushing logs to loki](https://discuss.elastic.co/t/logstash-not-pushing-logs-to-loki/344007)

<div class="topic-metadata">

**Author:** [@sheldor](https://discuss.elastic.co/u/sheldor)\
**Replies:** 2\
**Last updated:** [September 28, 2023, 6:45am UTC](https://discuss.elastic.co/t/logstash-not-pushing-logs-to-loki/344007 "2023-09-28T06:45:00Z")

</div>

Below is my logstash config input { file { ecs\_compatibility =\> disabled path =\> \[ "/a/logs/project\_apps/\*\*/\*.log" \] start\_position =\> beginning exclude =\> \[ …

---

## [Error The given configuration is invalid. Reason: Unable to configure plugins](https://discuss.elastic.co/t/error-the-given-configuration-is-invalid-reason-unable-to-configure-plugins/344018)

<div class="topic-metadata">

**Author:** [@HectorCy10](https://discuss.elastic.co/u/HectorCy10)\
**Replies:** 0\
**Last updated:** [September 27, 2023, 10:32pm UTC](https://discuss.elastic.co/t/error-the-given-configuration-is-invalid-reason-unable-to-configure-plugins/344018 "2023-09-27T22:32:18Z")

</div>

Hi everyone, i have the next error but i can not find any topic to solve this issue

---

## [Parse rabbitmq json log](https://discuss.elastic.co/t/parse-rabbitmq-json-log/344009)

<div class="topic-metadata">

**Author:** [@ansamHox](https://discuss.elastic.co/u/ansamHox)\
**Replies:** 5\
**Last updated:** [September 27, 2023, 9:32pm UTC](https://discuss.elastic.co/t/parse-rabbitmq-json-log/344009 "2023-09-27T21:32:20Z")

</div>

Hi, got json log message from rabbit as {"timestamp":"2022-12-21 03:14:59.977922+02:00","level":"error","msg":"Error on AMQP connection \<0.32551.1583\>: enotconn (socket is not connected)","domain":"rabbitmq.connection",…

---

## [What is the default source of the @timestamp field in Filebeat?](https://discuss.elastic.co/t/what-is-the-default-source-of-the-timestamp-field-in-filebeat/343640)

<div class="topic-metadata">

**Author:** [@artschooldropout](https://discuss.elastic.co/u/artschooldropout)\
**Replies:** 3\
**Last updated:** [September 27, 2023, 8:59pm UTC](https://discuss.elastic.co/t/what-is-the-default-source-of-the-timestamp-field-in-filebeat/343640 "2023-09-27T20:59:01Z")

</div>

I'm ingesting Syslog input with Filebeat, and I'd like to use the timestamp processor to adjust the timezone of the logs (my source is sending them in local time and Kibana is expecting UTC). According to the documentati…

---

## [Field \[field\] not present as part of path \[field.query\]](https://discuss.elastic.co/t/field-field-not-present-as-part-of-path-field-query/344008)

<div class="topic-metadata">

**Author:** [@emi\_rose](https://discuss.elastic.co/u/emi_rose)\
**Replies:** 0\
**Last updated:** [September 27, 2023, 6:45pm UTC](https://discuss.elastic.co/t/field-field-not-present-as-part-of-path-field-query/344008 "2023-09-27T18:45:20Z")

</div>

I'm creating a pipeline with a gsub processor and I keep getting this error when testing the pipeline on a document. I had to add a unique delimiter before ingesting to deal with a whitespace issue. I'm now trying to rep…

---

## [Parse AWS EC2 logs Error](https://discuss.elastic.co/t/parse-aws-ec2-logs-error/344005)

<div class="topic-metadata">

**Author:** [@rachelyang](https://discuss.elastic.co/u/rachelyang)\
**Replies:** 0\
**Last updated:** [September 27, 2023, 6:07pm UTC](https://discuss.elastic.co/t/parse-aws-ec2-logs-error/344005 "2023-09-27T18:07:51Z")

</div>

Hi Engineers, I set up Observability Logs Stream in Kibana for AWS EC2 logs. I have received the aws.ec2\_logs, but Message showed "Fail to find message". When I clicked the "View Details" button, the log contents have b…

---

## [Delete .reporting index](https://discuss.elastic.co/t/delete-reporting-index/343482)

<div class="topic-metadata">

**Author:** [@johnashish](https://discuss.elastic.co/u/johnashish)\
**Replies:** 2\
**Last updated:** [September 27, 2023, 6:05pm UTC](https://discuss.elastic.co/t/delete-reporting-index/343482 "2023-09-27T18:05:05Z")

</div>

This is regarding my last raised topic - Kibana 7.17.3 So i have multiple csv reports generated and i want to delete them now those reports comes under .reportinf-\* index. So when i am trying to delete those i am gett…

---

## [Connecting to ELK from databricks](https://discuss.elastic.co/t/connecting-to-elk-from-databricks/343998)

<div class="topic-metadata">

**Author:** [@ksasidhar1103](https://discuss.elastic.co/u/ksasidhar1103)\
**Replies:** 0\
**Last updated:** [September 27, 2023, 2:35pm UTC](https://discuss.elastic.co/t/connecting-to-elk-from-databricks/343998 "2023-09-27T14:35:10Z")

</div>

Hi, I'm trying to load data into databrciks from ELK with the help of API using python script. Can you suggest me the best option that I can read the huge data like 200 million in single shot. The method now I'm using i…

---

## ["logs threshold rule" adding comparator: "MATCHES"](https://discuss.elastic.co/t/logs-threshold-rule-adding-comparator-matches/343986)

<div class="topic-metadata">

**Author:** [@BRINDAH\_B](https://discuss.elastic.co/u/BRINDAH_B)\
**Replies:** 0\
**Last updated:** [September 27, 2023, 12:51pm UTC](https://discuss.elastic.co/t/logs-threshold-rule-adding-comparator-matches/343986 "2023-09-27T12:51:22Z")

</div>

Missing "comparator": "MATCHES" or "MATCHES PHRASE" in "logs threshold rule". I want end-user to be able to search text fields in that rule. Is this possible? At this stage we are not able to grant "all" privilege for e…

---

## [Shipping access logs logstash to logstash using http plugins](https://discuss.elastic.co/t/shipping-access-logs-logstash-to-logstash-using-http-plugins/343980)

<div class="topic-metadata">

**Author:** [@Casper\_Thrane](https://discuss.elastic.co/u/Casper_Thrane)\
**Replies:** 1\
**Last updated:** [September 27, 2023, 12:42pm UTC](https://discuss.elastic.co/t/shipping-access-logs-logstash-to-logstash-using-http-plugins/343980 "2023-09-27T12:42:38Z")

</div>

Hi We have a setup where we ship logs between systems via logstash to logstash using http plugins. The access logs are in ecs format. The problem is, logstash overwrites http, url and others fields, with it's own transp…

---

## [Breaklines character](https://discuss.elastic.co/t/breaklines-character/343840)

<div class="topic-metadata">

**Author:** [@Kirtash](https://discuss.elastic.co/u/Kirtash)\
**Replies:** 3\
**Last updated:** [September 27, 2023, 11:50am UTC](https://discuss.elastic.co/t/breaklines-character/343840 "2023-09-27T11:50:31Z")

</div>

Good morning, I have an easy question about the text field when in the string I have breaklines. I have seen that in this moment when I read the index field I something like this: "enEN" : """- Characteristics of the g…

---

## [Elastic-Agent is not getting installed](https://discuss.elastic.co/t/elastic-agent-is-not-getting-installed/343976)

<div class="topic-metadata">

**Author:** [@syedsyed](https://discuss.elastic.co/u/syedsyed)\
**Replies:** 0\
**Last updated:** [September 27, 2023, 11:07am UTC](https://discuss.elastic.co/t/elastic-agent-is-not-getting-installed/343976 "2023-09-27T11:07:29Z")

</div>

Hello, I have 2 Problems, i have installed the integration of sonicwall in Elasticsearch and enrolled the elastic agent in fleet server by using the debian package, but the service is not getting started and iam getting …

---

## [Report data from Splunk to Elastic](https://discuss.elastic.co/t/report-data-from-splunk-to-elastic/343975)

<div class="topic-metadata">

**Author:** [@lehu](https://discuss.elastic.co/u/lehu)\
**Replies:** 0\
**Last updated:** [September 27, 2023, 10:47am UTC](https://discuss.elastic.co/t/report-data-from-splunk-to-elastic/343975 "2023-09-27T10:47:47Z")

</div>

So, I have been sending log data to Splunk. And I want to "catch" the data that is sent to Splunk and forward it to Elastic. I tried with Integrations but that did not work. Does anybody have any ideas on how to solve th…

---

## [Json multiline codec is not working and messages are not getting parsed](https://discuss.elastic.co/t/json-multiline-codec-is-not-working-and-messages-are-not-getting-parsed/343172)

<div class="topic-metadata">

**Author:** [@Blason](https://discuss.elastic.co/u/Blason)\
**Replies:** 16\
**Last updated:** [September 27, 2023, 10:44am UTC](https://discuss.elastic.co/t/json-multiline-codec-is-not-working-and-messages-are-not-getting-parsed/343172 "2023-09-27T10:44:41Z")

</div>

Hi Team, I an working on logstash json parser and messages are not getting parsed; any clue what could be wrong? Here are original messages \[ { "time": "12/Aug/2023:13:20:52 +0000", "source\_ip": "117.193.217.44",…

---

## [Threat Intelligence Integration won't show any data](https://discuss.elastic.co/t/threat-intelligence-integration-wont-show-any-data/343541)

<div class="topic-metadata">

**Author:** [@Gio\_27](https://discuss.elastic.co/u/Gio_27)\
**Replies:** 7\
**Last updated:** [September 27, 2023, 9:47am UTC](https://discuss.elastic.co/t/threat-intelligence-integration-wont-show-any-data/343541 "2023-09-27T09:47:23Z")

</div>

Good morning, I have installed the Threat Intelligence Integration, I also have a fleet managed server and I am currently tracking different hosts with different integrations and i am managing all of that through 2 agen…

---

## [Solution for monitoring](https://discuss.elastic.co/t/solution-for-monitoring/343916)

<div class="topic-metadata">

**Author:** [@sossoulokoariel](https://discuss.elastic.co/u/sossoulokoariel)\
**Replies:** 1\
**Last updated:** [September 27, 2023, 9:37am UTC](https://discuss.elastic.co/t/solution-for-monitoring/343916 "2023-09-27T09:37:20Z")

</div>

Hello community I hope you are well. After unpacking the ELK stack I'd like to do some tests to track my local logs and metrics but I don't really know how to go about it. I'm using the latest version of the stack.

---

## [CircuitBreakingException when load huge data by bulk write](https://discuss.elastic.co/t/circuitbreakingexception-when-load-huge-data-by-bulk-write/343410)

<div class="topic-metadata">

**Author:** [@ericsoul](https://discuss.elastic.co/u/ericsoul)\
**Replies:** 1\
**Last updated:** [September 27, 2023, 9:24am UTC](https://discuss.elastic.co/t/circuitbreakingexception-when-load-huge-data-by-bulk-write/343410 "2023-09-27T09:24:18Z")

</div>

I got many errors like Caused by: org.elasticsearch.common.breaker.CircuitBreakingException: \[parent\] Data too large, data for \[indices:data/write/bulk\[s\]\] would be \[30897445494/28.7gb\], which is larger than the limit…

---

## [How to create finger print ingest pipeline for nested field?](https://discuss.elastic.co/t/how-to-create-finger-print-ingest-pipeline-for-nested-field/343845)

<div class="topic-metadata">

**Author:** [@mhsankar](https://discuss.elastic.co/u/mhsankar)\
**Replies:** 2\
**Last updated:** [September 27, 2023, 9:23am UTC](https://discuss.elastic.co/t/how-to-create-finger-print-ingest-pipeline-for-nested-field/343845 "2023-09-27T09:23:58Z")

</div>

Hi every body. I have a mapping with nested field. I want to identify a finger print for every rows in nested field . how can create this ingest pipeline? I\`m using Elasticsearch v 7.17.7 my mapping: PUT test-neste…

---

## [ElasticSearch Cluster with two Nodes](https://discuss.elastic.co/t/elasticsearch-cluster-with-two-nodes/343874)

<div class="topic-metadata">

**Author:** [@Priyaansh\_Dwivedi](https://discuss.elastic.co/u/Priyaansh_Dwivedi)\
**Replies:** 2\
**Last updated:** [September 27, 2023, 8:37am UTC](https://discuss.elastic.co/t/elasticsearch-cluster-with-two-nodes/343874 "2023-09-27T08:37:15Z")

</div>

I've always appreciated the support of this community, and I hope it can assist me once more. Here's the situation: I currently have Elasticsearch installed on my VM1, but I've encountered disk space issues, and the clus…

---

## [Getting one of index in red and did rolling restart of elastic cluster but still in red](https://discuss.elastic.co/t/getting-one-of-index-in-red-and-did-rolling-restart-of-elastic-cluster-but-still-in-red/343957)

<div class="topic-metadata">

**Author:** [@Jeet\_Lal\_Bhatrai](https://discuss.elastic.co/u/Jeet_Lal_Bhatrai)\
**Replies:** 0\
**Last updated:** [September 27, 2023, 8:27am UTC](https://discuss.elastic.co/t/getting-one-of-index-in-red-and-did-rolling-restart-of-elastic-cluster-but-still-in-red/343957 "2023-09-27T08:27:54Z")

</div>

Getting one of index in red and did rolling restart of elastic cluster but still in red

---

## [How can I fix this to suggest phrases after say, three characters have been entered?](https://discuss.elastic.co/t/how-can-i-fix-this-to-suggest-phrases-after-say-three-characters-have-been-entered/343755)

<div class="topic-metadata">

**Author:** [@Bhavyagc](https://discuss.elastic.co/u/Bhavyagc)\
**Replies:** 7\
**Last updated:** [September 27, 2023, 4:34am UTC](https://discuss.elastic.co/t/how-can-i-fix-this-to-suggest-phrases-after-say-three-characters-have-been-entered/343755 "2023-09-27T04:34:30Z")

</div>

My query { "suggest": { "text" : "Tes", "simple\_phrase" : { "phrase" : { "field" : "Active\_Substance\_mstr.trigram", "size" : 1, "max\_errors" : 6, "direct\_generator" : \[ { "field" : "Active\_Substan…

---

## [Please suggest best mechanism to sync from Mongo db to elastic search in kubernetes (on prem)?](https://discuss.elastic.co/t/please-suggest-best-mechanism-to-sync-from-mongo-db-to-elastic-search-in-kubernetes-on-prem/343937)

<div class="topic-metadata">

**Author:** [@siva\_k](https://discuss.elastic.co/u/siva_k)\
**Replies:** 1\
**Last updated:** [September 27, 2023, 4:22am UTC](https://discuss.elastic.co/t/please-suggest-best-mechanism-to-sync-from-mongo-db-to-elastic-search-in-kubernetes-on-prem/343937 "2023-09-27T04:22:33Z")

</div>

Please suggest best mechanism to sync from Mongo db to Elasticsearch in kubernetes (on prem)? Thank you

---

## [Mysql slow log](https://discuss.elastic.co/t/mysql-slow-log/343917)

<div class="topic-metadata">

**Author:** [@danmed](https://discuss.elastic.co/u/danmed)\
**Replies:** 1\
**Last updated:** [September 26, 2023, 8:28pm UTC](https://discuss.elastic.co/t/mysql-slow-log/343917 "2023-09-26T20:28:54Z")

</div>

Hi all, I am not able to successfully parse Mysql's slow log using logstash. The log file: # Time: 2018-02-27T09:20:14.122543Z # User@Host: user\[user\] @ \[nnn.nnn.nnn.nn\] Id: 148 # Query\_time: 10.275441 Lock\_time: …

---

## [Term query by \_id very slow (30s+) occasionally](https://discuss.elastic.co/t/term-query-by-id-very-slow-30s-occasionally/343305)

<div class="topic-metadata">

**Author:** [@May\_Zeng](https://discuss.elastic.co/u/May_Zeng)\
**Replies:** 20\
**Last updated:** [September 26, 2023, 8:10pm UTC](https://discuss.elastic.co/t/term-query-by-id-very-slow-30s-occasionally/343305 "2023-09-26T20:10:48Z")

</div>

Mapping: { "dynamic": "strict", "\_source": { "enabled": false }, "properties": { "data": { "type": "binary", "doc\_values": false, "store": true } } } Query: {"query":{ "bool" …

[Previous page](https://discuss.elastic.co/tag/none.md?no_tags=true&page=296)

[Next page](https://discuss.elastic.co/tag/none.md?no_tags=true&page=298)
