# \#none

**URL:** https://discuss.elastic.co/tag/none.md?no_tags=true&page=298

[Latest](https://discuss.elastic.co/latest.md) · [Categories](https://discuss.elastic.co/categories.md) · [Tags](https://discuss.elastic.co/tags.md)

**Page:** 299

---

## [Easy way to parse flattened data type?](https://discuss.elastic.co/t/easy-way-to-parse-flattened-data-type/343926)

<div class="topic-metadata">

**Author:** [@elasticnub](https://discuss.elastic.co/u/elasticnub)\
**Replies:** 0\
**Last updated:** [September 26, 2023, 7:59pm UTC](https://discuss.elastic.co/t/easy-way-to-parse-flattened-data-type/343926 "2023-09-26T19:59:21Z")

</div>

While I understand the reasoning behind the flattened data type, is there an easy way to split key value pairs out as their own field to use with dashboards / aggregations etc. IE - m365\_defender.event.activity.objects …

---

## [What field shows sign-in due to app or hardware token?](https://discuss.elastic.co/t/what-field-shows-sign-in-due-to-app-or-hardware-token/343925)

<div class="topic-metadata">

**Author:** [@BabyElkUser](https://discuss.elastic.co/u/BabyElkUser)\
**Replies:** 0\
**Last updated:** [September 26, 2023, 7:49pm UTC](https://discuss.elastic.co/t/what-field-shows-sign-in-due-to-app-or-hardware-token/343925 "2023-09-26T19:49:16Z")

</div>

I'm in Filebeat and am hoping that someone can please help me find the field that holds the information as to whether someone is signing in with an app, like the MFA app, or with a hardware token. This is getting me all…

---

## [Elasticsearch index has multiple document ids](https://discuss.elastic.co/t/elasticsearch-index-has-multiple-document-ids/343923)

<div class="topic-metadata">

**Author:** [@PodarcisMuralis](https://discuss.elastic.co/u/PodarcisMuralis)\
**Replies:** 1\
**Last updated:** [September 26, 2023, 7:36pm UTC](https://discuss.elastic.co/t/elasticsearch-index-has-multiple-document-ids/343923 "2023-09-26T19:36:59Z")

</div>

Hi. I am using Logstash / Elasticsearch (8.5.3) and am indexing json data. In logstash I use http input plugin, filter plugins and elasticsearch output. Currently the auto generated @version field in logstash filter i…

---

## [Downgrade from ES 8.10.1 TO 8.9.2](https://discuss.elastic.co/t/downgrade-from-es-8-10-1-to-8-9-2/343919)

<div class="topic-metadata">

**Author:** [@balakr](https://discuss.elastic.co/u/balakr)\
**Replies:** 3\
**Last updated:** [September 26, 2023, 6:22pm UTC](https://discuss.elastic.co/t/downgrade-from-es-8-10-1-to-8-9-2/343919 "2023-09-26T18:22:49Z")

</div>

I would like to upgrade my ES to 8.10.1, i want to have the option to downgrade if tests fails. i did my search and did not find any breaking change between 8.9 to 8.10, wanted to confirm is downgrade is possible. ex., …

---

## [Question for storage types for hot nodes on Elastic Cloud](https://discuss.elastic.co/t/question-for-storage-types-for-hot-nodes-on-elastic-cloud/343790)

<div class="topic-metadata">

**Author:** [@Ray\_Zhang](https://discuss.elastic.co/u/Ray_Zhang)\
**Replies:** 2\
**Last updated:** [September 26, 2023, 5:42pm UTC](https://discuss.elastic.co/t/question-for-storage-types-for-hot-nodes-on-elastic-cloud/343790 "2023-09-26T17:42:49Z")

</div>

I was checking the fact sheets for " Elasticsearch Service GCP default provider instance configurations" on elastic website and noticed that the storage type is "NVME" for the hot nodes instead of "Zonal SSD Persistent D…

---

## [Restrict nested data in result of search](https://discuss.elastic.co/t/restrict-nested-data-in-result-of-search/343918)

<div class="topic-metadata">

**Author:** [@TomTom](https://discuss.elastic.co/u/TomTom)\
**Replies:** 0\
**Last updated:** [September 26, 2023, 5:38pm UTC](https://discuss.elastic.co/t/restrict-nested-data-in-result-of-search/343918 "2023-09-26T17:38:21Z")

</div>

I have a index that stores tasks to do, in it there is a user id, task id and inside there is nested data that is used to store a timer that the user started and finished working on a task. I have a script that I used i…

---

## [Indexing Subtitles and Maintaining Timestamps](https://discuss.elastic.co/t/indexing-subtitles-and-maintaining-timestamps/343708)

<div class="topic-metadata">

**Author:** [@ADarkDividedGem](https://discuss.elastic.co/u/ADarkDividedGem)\
**Replies:** 7\
**Last updated:** [September 26, 2023, 5:32pm UTC](https://discuss.elastic.co/t/indexing-subtitles-and-maintaining-timestamps/343708 "2023-09-26T17:32:00Z")

</div>

I am wanting to index subtitles and also maintain the timestamp data. My initial thought was to make each line of text a document with the start and end timestamps stored as fields for that document. For example the fol…

---

## [Error when querying Elasticsearch from Logstash](https://discuss.elastic.co/t/error-when-querying-elasticsearch-from-logstash/343907)

<div class="topic-metadata">

**Author:** [@subash](https://discuss.elastic.co/u/subash)\
**Replies:** 0\
**Last updated:** [September 26, 2023, 3:19pm UTC](https://discuss.elastic.co/t/error-when-querying-elasticsearch-from-logstash/343907 "2023-09-26T15:19:17Z")

</div>

I'm using Elasticsearch input plugin in logstash to query the Elastic data. But I'm getting the below error Ignoring clear\_scroll exception {:message=\>"\[404\] {\\"succeeded\\":true,\\"num\_freed\\":0}", :exception=\>Elasticsea…

---

## [Email action message](https://discuss.elastic.co/t/email-action-message/343910)

<div class="topic-metadata">

**Author:** [@ramiwashere](https://discuss.elastic.co/u/ramiwashere)\
**Replies:** 0\
**Last updated:** [September 26, 2023, 3:55pm UTC](https://discuss.elastic.co/t/email-action-message/343910 "2023-09-26T15:55:52Z")

</div>

Hello, I have an alert using rule from security section. My aim is to gather some information into the mail alert from the alert: In my example, I would like to take the username & the ip: {{#context.hits}} Username:…

---

## [Trace Search](https://discuss.elastic.co/t/trace-search/343908)

<div class="topic-metadata">

**Author:** [@techtuga](https://discuss.elastic.co/u/techtuga)\
**Replies:** 0\
**Last updated:** [September 26, 2023, 3:26pm UTC](https://discuss.elastic.co/t/trace-search/343908 "2023-09-26T15:26:37Z")

</div>

Hi there, We are getting application feeds from an opentelemetry/java 1.23.1 agent, trough Otel Collector 0.82.0 to APM 8.9.1 Server, the feeds are arriving fine into the APM index: Anyway when trying to to filter u…

---

## [Importing / Exporting dashboards and agent policy's](https://discuss.elastic.co/t/importing-exporting-dashboards-and-agent-policys/343878)

<div class="topic-metadata">

**Author:** [@Maretti](https://discuss.elastic.co/u/Maretti)\
**Replies:** 2\
**Last updated:** [September 26, 2023, 2:24pm UTC](https://discuss.elastic.co/t/importing-exporting-dashboards-and-agent-policys/343878 "2023-09-26T14:24:39Z")

</div>

Hi, I would like to export my dashboards and agent policies to use in another Elastic cluster. Is this possible to do? If so, how can I do this? Thanks!

---

## [StatusCode:401, Unauthorized - Kibana - API request](https://discuss.elastic.co/t/statuscode-401-unauthorized-kibana-api-request/343899)

<div class="topic-metadata">

**Author:** [@tfournier](https://discuss.elastic.co/u/tfournier)\
**Replies:** 0\
**Last updated:** [September 26, 2023, 2:18pm UTC](https://discuss.elastic.co/t/statuscode-401-unauthorized-kibana-api-request/343899 "2023-09-26T14:18:06Z")

</div>

Hi there, I'm not able to find Kibana cases by API request. This is the error I get : {"statusCode":401,"error":"Unauthorized","message":"Unauthorized"} I'm trying to find cases with this curl : curl --user usern…

---

## [How to parse values as key value not array](https://discuss.elastic.co/t/how-to-parse-values-as-key-value-not-array/342896)

<div class="topic-metadata">

**Author:** [@dreambeam](https://discuss.elastic.co/u/dreambeam)\
**Replies:** 2\
**Last updated:** [September 26, 2023, 2:02pm UTC](https://discuss.elastic.co/t/how-to-parse-values-as-key-value-not-array/342896 "2023-09-26T14:02:17Z")

</div>

Hi there. I am trying parse a text file containing values below. 15, 3241 16, 800 17, 1 Below if my logstash configuration. When I checked in Kibana , I have the field document displayed as a array. "hcount": \[ 800 \] …

---

## [Configuring alerts on event](https://discuss.elastic.co/t/configuring-alerts-on-event/343892)

<div class="topic-metadata">

**Author:** [@oll](https://discuss.elastic.co/u/oll)\
**Replies:** 0\
**Last updated:** [September 26, 2023, 1:45pm UTC](https://discuss.elastic.co/t/configuring-alerts-on-event/343892 "2023-09-26T13:45:20Z")

</div>

Hello! Help me to find a way to notify about winlogbeat event c for example event.code 4625 - An account failed to log on. The idea is to notify the administrator if the number of failed logins from a user exceeds for…

---

## [Date math Incorrect HTTP method for uri](https://discuss.elastic.co/t/date-math-incorrect-http-method-for-uri/343843)

<div class="topic-metadata">

**Author:** [@INS](https://discuss.elastic.co/u/INS)\
**Replies:** 1\
**Last updated:** [September 26, 2023, 11:30am UTC](https://discuss.elastic.co/t/date-math-incorrect-http-method-for-uri/343843 "2023-09-26T11:30:53Z")

</div>

Hi I just want to create index with date math from dev tool console for rollover but I got below error: request PUT /%3Cindex\_test-%7Bnow%2Fd%7BYYYYMMDD%7D%7D%3E { "aliases": { "logs\_write": {} } } { "error…

---

## [Elastic apm instrumentation not working for my Flask application running in python 3.x](https://discuss.elastic.co/t/elastic-apm-instrumentation-not-working-for-my-flask-application-running-in-python-3-x/343693)

<div class="topic-metadata">

**Author:** [@Ankit\_kumar\_Srivasta](https://discuss.elastic.co/u/Ankit_kumar_Srivasta)\
**Replies:** 3\
**Last updated:** [September 26, 2023, 11:22am UTC](https://discuss.elastic.co/t/elastic-apm-instrumentation-not-working-for-my-flask-application-running-in-python-3-x/343693 "2023-09-26T11:22:04Z")

</div>

I am unable to find out transaction traces on kibana server after using the apm object like this. app = Flask(\_\_name\_\_) app.secret\_key = "ahugekey@netcore#2019" app.config\['ELASTIC\_APM'\] = { 'SERVICE\_NAME': 'o…

---

## [How to update ES node transport address](https://discuss.elastic.co/t/how-to-update-es-node-transport-address/343851)

<div class="topic-metadata">

**Author:** [@HadesC](https://discuss.elastic.co/u/HadesC)\
**Replies:** 1\
**Last updated:** [September 26, 2023, 10:59am UTC](https://discuss.elastic.co/t/how-to-update-es-node-transport-address/343851 "2023-09-26T10:59:32Z")

</div>

I have two Red Hat installed ES 7.9.1 nodes (build type: tar) in my environment, joined to same cluster. Suppose one of the Red Hat nodes should only have private IP 10.121.0.2, somehow there is another private IP 10.12…

---

## [Logstash google pubsub output plugin](https://discuss.elastic.co/t/logstash-google-pubsub-output-plugin/343791)

<div class="topic-metadata">

**Author:** [@Bala\_Joshi](https://discuss.elastic.co/u/Bala_Joshi)\
**Replies:** 1\
**Last updated:** [September 26, 2023, 10:21am UTC](https://discuss.elastic.co/t/logstash-google-pubsub-output-plugin/343791 "2023-09-26T10:21:32Z")

</div>

hello All, I am trying to injest to google pubsub topic from logstash server. Below are the configuration google\_pubsub { project\_id =\> "xx" topic =\> "xx" json\_key\_file =\> "xx" #Options for configuring the upload …

---

## [Need to create a graph for hourly committed frequency in pie chart](https://discuss.elastic.co/t/need-to-create-a-graph-for-hourly-committed-frequency-in-pie-chart/343842)

<div class="topic-metadata">

**Author:** [@Manjari](https://discuss.elastic.co/u/Manjari)\
**Replies:** 0\
**Last updated:** [September 26, 2023, 7:54am UTC](https://discuss.elastic.co/t/need-to-create-a-graph-for-hourly-committed-frequency-in-pie-chart/343842 "2023-09-26T07:54:00Z")

</div>

No of commits per hour for example 1 commit an hour 5% of the time 2 commit an hour 23% of the time.. and so on

---

## [Deploy a multi-replica Filebeat Deployment using PersistentVolumeClaims](https://discuss.elastic.co/t/deploy-a-multi-replica-filebeat-deployment-using-persistentvolumeclaims/343610)

<div class="topic-metadata">

**Author:** [@niaomingjian](https://discuss.elastic.co/u/niaomingjian)\
**Replies:** 1\
**Last updated:** [September 26, 2023, 1:24am UTC](https://discuss.elastic.co/t/deploy-a-multi-replica-filebeat-deployment-using-persistentvolumeclaims/343610 "2023-09-26T01:24:07Z")

</div>

I want to use Filebeat to import data from a Kafka topic into Elasticsearch. For high reliability (so other pods can still work if one pod fails), I would like to deploy Filebeat as a multi-replica Deployment. Deploy a …

---

## [Host in agent stuck in "Updating" status on Fleet-Server](https://discuss.elastic.co/t/host-in-agent-stuck-in-updating-status-on-fleet-server/343664)

<div class="topic-metadata">

**Author:** [@sheaces](https://discuss.elastic.co/u/sheaces)\
**Replies:** 3\
**Last updated:** [September 26, 2023, 1:16am UTC](https://discuss.elastic.co/t/host-in-agent-stuck-in-updating-status-on-fleet-server/343664 "2023-09-26T01:16:22Z")

</div>

Course: Elastic Observability Engineer On-Demand Version: ID: E-J0E990 Question: In lab 2.1, after installing and enrolling the elastic agent to the host, the fleet server reflects that the agent is stuck in "updating"…

---

## [Unable to Upload Winevt to Elastic Stack](https://discuss.elastic.co/t/unable-to-upload-winevt-to-elastic-stack/343809)

<div class="topic-metadata">

**Author:** [@scott\_securit360](https://discuss.elastic.co/u/scott_securit360)\
**Replies:** 0\
**Last updated:** [September 25, 2023, 9:20pm UTC](https://discuss.elastic.co/t/unable-to-upload-winevt-to-elastic-stack/343809 "2023-09-25T21:20:18Z")

</div>

Hello! I've recently enabled Security on my Elastic stack (7.17) using the documentation here. I've completed up until the "Configure Beats security" section, as that is not needed in my environment. I'm using the Bur…

---

## [Anomaly rules, select multiple services](https://discuss.elastic.co/t/anomaly-rules-select-multiple-services/343799)

<div class="topic-metadata">

**Author:** [@sguerrero](https://discuss.elastic.co/u/sguerrero)\
**Replies:** 0\
**Last updated:** [September 25, 2023, 6:41pm UTC](https://discuss.elastic.co/t/anomaly-rules-select-multiple-services/343799 "2023-09-25T18:41:30Z")

</div>

Hello, I'm currently utilizing the Anomaly rule under "Rules and Connectors" within the "Stack Management". I've encountered a situation where I need to select specific services to send emails to distinct addresses. Ho…

---

## [Encounter error "Saved field "timeStamp" of data view "index-name" is invalid for use with the "Date Histogram" aggregation. Please select a new field](https://discuss.elastic.co/t/encounter-error-saved-field-timestamp-of-data-view-index-name-is-invalid-for-use-with-the-date-histogram-aggregation-please-select-a-new-field/343798)

<div class="topic-metadata">

**Author:** [@Long\_Nguyen](https://discuss.elastic.co/u/Long_Nguyen)\
**Replies:** 0\
**Last updated:** [September 25, 2023, 6:20pm UTC](https://discuss.elastic.co/t/encounter-error-saved-field-timestamp-of-data-view-index-name-is-invalid-for-use-with-the-date-histogram-aggregation-please-select-a-new-field/343798 "2023-09-25T18:20:16Z")

</div>

Hello everyone, I'm running Elastic Stack 8.3.0. I encounter the following error in Kibana "Discover" with an index: The index is indexed from the following csv file (some fields have been redacted): timeStamp…

---

## [Is it possible to have the cluster use a node's hardware specs for allocation decisions?](https://discuss.elastic.co/t/is-it-possible-to-have-the-cluster-use-a-nodes-hardware-specs-for-allocation-decisions/343634)

<div class="topic-metadata">

**Author:** [@Mike\_Snare](https://discuss.elastic.co/u/Mike_Snare)\
**Replies:** 5\
**Last updated:** [September 25, 2023, 5:59pm UTC](https://discuss.elastic.co/t/is-it-possible-to-have-the-cluster-use-a-nodes-hardware-specs-for-allocation-decisions/343634 "2023-09-25T17:59:44Z")

</div>

I know that it's possible to use custom attributes in allocations for things like rack-awareness, but I'm more interested in whether or not elastic is capable of taking a node's hardware specs into consideration when dec…

---

## [High resource usage of query with large term filter](https://discuss.elastic.co/t/high-resource-usage-of-query-with-large-term-filter/343585)

<div class="topic-metadata">

**Author:** [@Ray\_Zhang](https://discuss.elastic.co/u/Ray_Zhang)\
**Replies:** 4\
**Last updated:** [September 25, 2023, 5:15pm UTC](https://discuss.elastic.co/t/high-resource-usage-of-query-with-large-term-filter/343585 "2023-09-25T17:15:32Z")

</div>

We are running some rather large queries with about 6 thousand of term values in the filter sections. The queries take 20 to 40 more seconds to run and much more CPU usage were observed when running with the large term …

---

## [.JSON Conf File for Logstash](https://discuss.elastic.co/t/json-conf-file-for-logstash/343638)

<div class="topic-metadata">

**Author:** [@Google-Cloud-DFIR](https://discuss.elastic.co/u/Google-Cloud-DFIR)\
**Replies:** 19\
**Last updated:** [September 25, 2023, 4:17pm UTC](https://discuss.elastic.co/t/json-conf-file-for-logstash/343638 "2023-09-25T16:17:01Z")

</div>

Hello, I've been trying to configure this .conf file to help parse out .json files correctly. This script is able to ingest Google Cloud Audit Logs (in .json), but fails to parse it correctly: input { # stdin {} …

---

## [Aggregate Logs based on Source IP](https://discuss.elastic.co/t/aggregate-logs-based-on-source-ip/343789)

<div class="topic-metadata">

**Author:** [@maof97](https://discuss.elastic.co/u/maof97)\
**Replies:** 0\
**Last updated:** [September 25, 2023, 4:16pm UTC](https://discuss.elastic.co/t/aggregate-logs-based-on-source-ip/343789 "2023-09-25T16:16:26Z")

</div>

Hello, I'm collecting firewall logs from a firewall (PfSense). On every log record, among other details, I have destination ip addresses and destination ports. Now, I need to have an aggregated list of all destination…

---

## [How to find polygons that contain a given point in Elasticsearch](https://discuss.elastic.co/t/how-to-find-polygons-that-contain-a-given-point-in-elasticsearch/343769)

<div class="topic-metadata">

**Author:** [@Pranav\_Kapur](https://discuss.elastic.co/u/Pranav_Kapur)\
**Replies:** 5\
**Last updated:** [September 25, 2023, 4:05pm UTC](https://discuss.elastic.co/t/how-to-find-polygons-that-contain-a-given-point-in-elasticsearch/343769 "2023-09-25T16:05:57Z")

</div>

I need to build a query on a database with around 50k terrain polygons (stored as geo\_shape polygons on ES) where I give a point and it returns every polygon that contains this point. I tried to create it, but getting i…

---

## [Error when clicking View Details for alert](https://discuss.elastic.co/t/error-when-clicking-view-details-for-alert/343773)

<div class="topic-metadata">

**Author:** [@val722](https://discuss.elastic.co/u/val722)\
**Replies:** 4\
**Last updated:** [September 25, 2023, 3:41pm UTC](https://discuss.elastic.co/t/error-when-clicking-view-details-for-alert/343773 "2023-09-25T15:41:58Z")

</div>

Hello I created a custom threshold detection rule and I get this error in Kibana when I click View details for the alert generated by that rule Error Error: Object.hasOwn is not a function o/\<@http://192.168.56.130:560…

[Previous page](https://discuss.elastic.co/tag/none.md?no_tags=true&page=297)

[Next page](https://discuss.elastic.co/tag/none.md?no_tags=true&page=299)
