# \#none

**URL:** https://discuss.elastic.co/tag/none.md?no_tags=true&page=301

[Latest](https://discuss.elastic.co/latest.md) · [Categories](https://discuss.elastic.co/categories.md) · [Tags](https://discuss.elastic.co/tags.md)

**Page:** 302

---

## [AWS logging integration error](https://discuss.elastic.co/t/aws-logging-integration-error/343469)

<div class="topic-metadata">

**Author:** [@rachelyang](https://discuss.elastic.co/u/rachelyang)\
**Replies:** 4\
**Last updated:** [September 20, 2023, 4:27pm UTC](https://discuss.elastic.co/t/aws-logging-integration-error/343469 "2023-09-20T16:27:30Z")

</div>

Hi, I want to integrate the AWS logs into my Kibana Observability log stream. Here is the access policy of SQS queue: { "Version": "2012-10-17", "Id": "arn:aws:sqs:us-east-1:334811116626:ingest-ec2-logs-sqs/SQSDef…

---

## [CA Certificate for Elasticsearch and Kibana in K8s](https://discuss.elastic.co/t/ca-certificate-for-elasticsearch-and-kibana-in-k8s/342733)

<div class="topic-metadata">

**Author:** [@Esakki](https://discuss.elastic.co/u/Esakki)\
**Replies:** 4\
**Last updated:** [September 20, 2023, 2:21pm UTC](https://discuss.elastic.co/t/ca-certificate-for-elasticsearch-and-kibana-in-k8s/342733 "2023-09-20T14:21:26Z")

</div>

Hi All, Can someone share the steps how to configure certificate for Elasticsearch and Kiabana which is deployed on-prem K8s cluster. Thanks in advance. Kind Regards, Esakki

---

## [The issue in a detection rule](https://discuss.elastic.co/t/the-issue-in-a-detection-rule/343448)

<div class="topic-metadata">

**Author:** [@saudmajed99](https://discuss.elastic.co/u/saudmajed99)\
**Replies:** 2\
**Last updated:** [September 20, 2023, 2:14pm UTC](https://discuss.elastic.co/t/the-issue-in-a-detection-rule/343448 "2023-09-20T14:14:08Z")

</div>

Hi there, We would like your support, we face an issue if we create a detection rule where no result appears but results appears when we do the same search in the discover side , please assist me the solving an issue wi…

---

## [Issue on db query](https://discuss.elastic.co/t/issue-on-db-query/343369)

<div class="topic-metadata">

**Author:** [@girolamo](https://discuss.elastic.co/u/girolamo)\
**Replies:** 5\
**Last updated:** [September 20, 2023, 1:49pm UTC](https://discuss.elastic.co/t/issue-on-db-query/343369 "2023-09-20T13:49:57Z")

</div>

Hello there, I'm having issues making a query on a Elasticsearch db. Indeed, if I make this request: POST my-index/\_search I get almost all documents in the index. In this way: { "took" : 15, "timed\_out" : fals…

---

## [Use variable with logstash](https://discuss.elastic.co/t/use-variable-with-logstash/343462)

<div class="topic-metadata">

**Author:** [@sam1975](https://discuss.elastic.co/u/sam1975)\
**Replies:** 1\
**Last updated:** [September 20, 2023, 1:48pm UTC](https://discuss.elastic.co/t/use-variable-with-logstash/343462 "2023-09-20T13:48:41Z")

</div>

Hello I have a long list like this if \[monitoring\_data\_name\] == "componentFault" { pipeline { send\_to =\> "componentFault" } } else if \[monitoring\_data\_name\] == "localAccountPasswordModification" { pipeline { send\_t…

---

## [Logstash json input file only required fields to output](https://discuss.elastic.co/t/logstash-json-input-file-only-required-fields-to-output/342400)

<div class="topic-metadata">

**Author:** [@Narayan\_Rao](https://discuss.elastic.co/u/Narayan_Rao)\
**Replies:** 11\
**Last updated:** [September 20, 2023, 12:53pm UTC](https://discuss.elastic.co/t/logstash-json-input-file-only-required-fields-to-output/342400 "2023-09-20T12:53:37Z")

</div>

I'm new in ELK & I have logs in JSON format. Below is the json sample log file. I want only item level array, others fields not required. Sample logs { "source": "mdm/pim", "topic": "pim-record-globalfields", "subj…

---

## [Validation error on Kibana8 upgrade from Kibana7.17](https://discuss.elastic.co/t/validation-error-on-kibana8-upgrade-from-kibana7-17/343449)

<div class="topic-metadata">

**Author:** [@Vikrant\_Dewangan](https://discuss.elastic.co/u/Vikrant_Dewangan)\
**Replies:** 0\
**Last updated:** [September 20, 2023, 11:15am UTC](https://discuss.elastic.co/t/validation-error-on-kibana8-upgrade-from-kibana7-17/343449 "2023-09-20T11:15:07Z")

</div>

Hi, I am upgrading installing kibana8 from kibana7.17, and receiving the following error. Are there any leads for the validation type error? Configuring logger failed: ValidationError: \[config validation of \[logging\].a…

---

## [Logstash JDBC plugin](https://discuss.elastic.co/t/logstash-jdbc-plugin/343456)

<div class="topic-metadata">

**Author:** [@Akulainelastic](https://discuss.elastic.co/u/Akulainelastic)\
**Replies:** 0\
**Last updated:** [September 20, 2023, 12:04pm UTC](https://discuss.elastic.co/t/logstash-jdbc-plugin/343456 "2023-09-20T12:04:15Z")

</div>

Hello All , so I have a requirement where I need to use JDBC plugin to fetch the database data and reflect it in kibana , although I have successfully ingested data and pipelined it in logstash , the pipelines are runnin…

---

## [Error while starting elasticsearch v8.9.1](https://discuss.elastic.co/t/error-while-starting-elasticsearch-v8-9-1/343335)

<div class="topic-metadata">

**Author:** [@sanyam](https://discuss.elastic.co/u/sanyam)\
**Replies:** 3\
**Last updated:** [September 20, 2023, 10:32am UTC](https://discuss.elastic.co/t/error-while-starting-elasticsearch-v8-9-1/343335 "2023-09-20T10:32:21Z")

</div>

Whenever I start up ES by running ES .bat file on Windows, I receive this error: \[ERROR\]\[o.e.b.Elasticsearch \] \[node-1\] fatal exception while booting Elasticsearchorg.elasticsearch.ElasticsearchSecurityException: i…

---

## [Some entries is not coming in the field](https://discuss.elastic.co/t/some-entries-is-not-coming-in-the-field/343442)

<div class="topic-metadata">

**Author:** [@Rutuja\_More](https://discuss.elastic.co/u/Rutuja_More)\
**Replies:** 0\
**Last updated:** [September 20, 2023, 10:26am UTC](https://discuss.elastic.co/t/some-entries-is-not-coming-in-the-field/343442 "2023-09-20T10:26:14Z")

</div>

In my kibana field im putting one by one log but some entries is coming properly and some is not? @timestamp timestamp log\_type log\_level log\_message message Sep 20, 2023 @ 13:32:44.312 - - - - 023-09-01 14:07:0…

---

## [Kiaban generated url for index pattern](https://discuss.elastic.co/t/kiaban-generated-url-for-index-pattern/343438)

<div class="topic-metadata">

**Author:** [@O\_K](https://discuss.elastic.co/u/O_K)\
**Replies:** 0\
**Last updated:** [September 20, 2023, 9:50am UTC](https://discuss.elastic.co/t/kiaban-generated-url-for-index-pattern/343438 "2023-09-20T09:50:13Z")

</div>

I'm writing some app which will be generating kibana URLs with particular logs. The problem I faced that I can discover indexes in kibana UI using data view or get data view id from kibana API /api/data\_views and then ma…

---

## ["Failed to decode response" error from Java Client 8.8.0](https://discuss.elastic.co/t/failed-to-decode-response-error-from-java-client-8-8-0/343309)

<div class="topic-metadata">

**Author:** [@Roman\_Kagan](https://discuss.elastic.co/u/Roman_Kagan)\
**Replies:** 10\
**Last updated:** [September 20, 2023, 9:12am UTC](https://discuss.elastic.co/t/failed-to-decode-response-error-from-java-client-8-8-0/343309 "2023-09-20T09:12:14Z")

</div>

Hello: I am trying to use Elastic Java Client 8.8.0 (also known low-level rest client) and getting the error: status: 200, \[es/search\] Failed to decode response I used the same library to create a new index and insert …

---

## [Document to setup on-prem single node ECK on Kubernetes with elastic agent](https://discuss.elastic.co/t/document-to-setup-on-prem-single-node-eck-on-kubernetes-with-elastic-agent/343428)

<div class="topic-metadata">

**Author:** [@sankumar](https://discuss.elastic.co/u/sankumar)\
**Replies:** 0\
**Last updated:** [September 20, 2023, 8:19am UTC](https://discuss.elastic.co/t/document-to-setup-on-prem-single-node-eck-on-kubernetes-with-elastic-agent/343428 "2023-09-20T08:19:00Z")

</div>

Want to setup single node ECK on Kubernetes with elastic agent. So looking for the document to setup.

---

## [What is the max throughput of the stdout?](https://discuss.elastic.co/t/what-is-the-max-throughput-of-the-stdout/343416)

<div class="topic-metadata">

**Author:** [@Daniel9](https://discuss.elastic.co/u/Daniel9)\
**Replies:** 0\
**Last updated:** [September 20, 2023, 5:00am UTC](https://discuss.elastic.co/t/what-is-the-max-throughput-of-the-stdout/343416 "2023-09-20T05:00:14Z")

</div>

Here is my out output configration below: output { stdout { codec =\> json\_lines } } Here is my verification result: |Logs/s(In)|Logs/s (out)|Bytes/log (out)|Queue increase size (m)| |1500|200|580|700m| |780|200|5…

---

## [Cancel after time interval clarification](https://discuss.elastic.co/t/cancel-after-time-interval-clarification/343401)

<div class="topic-metadata">

**Author:** [@maxfriz](https://discuss.elastic.co/u/maxfriz)\
**Replies:** 0\
**Last updated:** [September 19, 2023, 8:48pm UTC](https://discuss.elastic.co/t/cancel-after-time-interval-clarification/343401 "2023-09-19T20:48:29Z")

</div>

To ensure a clear understanding of our global search configuration for a given cluster, I would like to clarify the following as written: The search.cancel\_after\_time\_interval configures (at the data node level) the t…

---

## [What's the secret to fast recovery when adding a new node?](https://discuss.elastic.co/t/whats-the-secret-to-fast-recovery-when-adding-a-new-node/343397)

<div class="topic-metadata">

**Author:** [@linkerc](https://discuss.elastic.co/u/linkerc)\
**Replies:** 0\
**Last updated:** [September 19, 2023, 8:08pm UTC](https://discuss.elastic.co/t/whats-the-secret-to-fast-recovery-when-adding-a-new-node/343397 "2023-09-19T20:08:45Z")

</div>

We are on on version 7.15. Still experiencing issues during recovery. The cluster will often (very likely) move shards from new node back to old nodes even though the new node(s) are still have way fewer shards (and lo…

---

## [Pfelk logstash data parsing](https://discuss.elastic.co/t/pfelk-logstash-data-parsing/343284)

<div class="topic-metadata">

**Author:** [@kozistan](https://discuss.elastic.co/u/kozistan)\
**Replies:** 8\
**Last updated:** [September 19, 2023, 7:54pm UTC](https://discuss.elastic.co/t/pfelk-logstash-data-parsing/343284 "2023-09-19T19:54:03Z")

</div>

Hello would appreciate help with logstash parsing data into elastisearch. Please check my log output. Using opnsense syslog to logstash's pfelk addon and can not figure out whe right mutate filter to get this done. Thank…

---

## [Beats, Elastic Agent, APM Server, and Fleet Server 8.10.1 Security Update - Improper Certificate Validation issue (ESA-2023-16)](https://discuss.elastic.co/t/beats-elastic-agent-apm-server-and-fleet-server-8-10-1-security-update-improper-certificate-validation-issue-esa-2023-16/343385)

<div class="topic-metadata">

**Author:** [@rodrigo\_silva](https://discuss.elastic.co/u/rodrigo_silva)\
**Replies:** 0\
**Last updated:** [September 19, 2023, 3:32pm UTC](https://discuss.elastic.co/t/beats-elastic-agent-apm-server-and-fleet-server-8-10-1-security-update-improper-certificate-validation-issue-esa-2023-16/343385 "2023-09-19T15:32:21Z")

</div>

Beats, Elastic Agent, APM Server, and Fleet Server Improper Certificate Validation issue (ESA-2023-16) It was discovered that when acting as TLS clients, Beats, Elastic Agent, APM Server, and Fleet Server did not verify …

---

## [Calculate percentage based on status of max per group in Elasticsearch](https://discuss.elastic.co/t/calculate-percentage-based-on-status-of-max-per-group-in-elasticsearch/343171)

<div class="topic-metadata">

**Author:** [@carollyl](https://discuss.elastic.co/u/carollyl)\
**Replies:** 5\
**Last updated:** [September 19, 2023, 4:27pm UTC](https://discuss.elastic.co/t/calculate-percentage-based-on-status-of-max-per-group-in-elasticsearch/343171 "2023-09-19T16:27:48Z")

</div>

Given the dataset below, I'd like to calculate percentage of status over unique count of workflow. id,workflow,status 1,A,FAILURE 2,A,ABORTED 3,A,SUCCESS 4,A,SUCCESS 1,B,FAILURE 2,B,SUCCESS 3,B,FAILURE 1,C,FAILURE 2,C,F…

---

## [Cardinality problem](https://discuss.elastic.co/t/cardinality-problem/343387)

<div class="topic-metadata">

**Author:** [@YvorL](https://discuss.elastic.co/u/YvorL)\
**Replies:** 0\
**Last updated:** [September 19, 2023, 4:27pm UTC](https://discuss.elastic.co/t/cardinality-problem/343387 "2023-09-19T16:27:18Z")

</div>

Hi, I'm not sure if this can be done, but it's worth asking :slight\_smile: I would like to see a specific metric, but it'd need a lot of conditions and cardinality. Let's say I have an index where I have documents fro…

---

## [Enrolling agent on Graviton ARM processor](https://discuss.elastic.co/t/enrolling-agent-on-graviton-arm-processor/342351)

<div class="topic-metadata">

**Author:** [@Jasonespo](https://discuss.elastic.co/u/Jasonespo)\
**Replies:** 4\
**Last updated:** [September 19, 2023, 3:26pm UTC](https://discuss.elastic.co/t/enrolling-agent-on-graviton-arm-processor/342351 "2023-09-19T15:26:59Z")

</div>

Hi, I was wondering if it is possible to run the agent on aarm64 architecture? We're potentially aiming to migrate all of our hosts from x86\_64 to aarm64. However when I try to run the agent install command on a host r…

---

## [Transaction\_sample\_rate post 8 release versions](https://discuss.elastic.co/t/transaction-sample-rate-post-8-release-versions/343290)

<div class="topic-metadata">

**Author:** [@senyam08](https://discuss.elastic.co/u/senyam08)\
**Replies:** 4\
**Last updated:** [September 19, 2023, 3:10pm UTC](https://discuss.elastic.co/t/transaction-sample-rate-post-8-release-versions/343290 "2023-09-19T15:10:40Z")

</div>

We haev java agent 1.42 and Elasticsearch/APM servers are in 8.10 version. I haev tried with sampling rate of .2 and .5. Both values and 1 are getting response time/throughput for all samples. But document has change in…

---

## [How to map ambiguous data](https://discuss.elastic.co/t/how-to-map-ambiguous-data/343271)

<div class="topic-metadata">

**Author:** [@francieliton\_araujo](https://discuss.elastic.co/u/francieliton_araujo)\
**Replies:** 3\
**Last updated:** [September 19, 2023, 1:56pm UTC](https://discuss.elastic.co/t/how-to-map-ambiguous-data/343271 "2023-09-19T13:56:36Z")

</div>

There is a more practical way to map ambiguous data other than deleting and creating index, I need to make a query to the canvas but try to show a column with an error because the data cannot be ambiguous

---

## [Substituting Match Phrase Prefix Query with a MUST combination of Match Phrase and Prefix](https://discuss.elastic.co/t/substituting-match-phrase-prefix-query-with-a-must-combination-of-match-phrase-and-prefix/343218)

<div class="topic-metadata">

**Author:** [@aliyanamu](https://discuss.elastic.co/u/aliyanamu)\
**Replies:** 1\
**Last updated:** [September 19, 2023, 12:24pm UTC](https://discuss.elastic.co/t/substituting-match-phrase-prefix-query-with-a-must-combination-of-match-phrase-and-prefix/343218 "2023-09-19T12:24:55Z")

</div>

Hi, I am using match phrase prefix for suggestion and querying search result. I'm using this for searching employee name, skill name, etc... basically name / title field which is not long. When I'm searching name like …

---

## [Send emails with PDF Dashboard](https://discuss.elastic.co/t/send-emails-with-pdf-dashboard/341105)

<div class="topic-metadata">

**Author:** [@hofrichterovak](https://discuss.elastic.co/u/hofrichterovak)\
**Replies:** 2\
**Last updated:** [September 19, 2023, 12:01pm UTC](https://discuss.elastic.co/t/send-emails-with-pdf-dashboard/341105 "2023-09-19T12:01:36Z")

</div>

Hello, I read the documentation about sending email with PDF dashboard in the attachment \>\>\> Automatically generate reports | Kibana Guide \[8.9\] | Elastic I wanted to create my own watcher. My Kibana version is 7.17.8 …

---

## [Error when converting Eland Dataframe to Pandas Dataframe using Eland on Jupyter](https://discuss.elastic.co/t/error-when-converting-eland-dataframe-to-pandas-dataframe-using-eland-on-jupyter/343331)

<div class="topic-metadata">

**Author:** [@xynobob](https://discuss.elastic.co/u/xynobob)\
**Replies:** 0\
**Last updated:** [September 19, 2023, 8:46am UTC](https://discuss.elastic.co/t/error-when-converting-eland-dataframe-to-pandas-dataframe-using-eland-on-jupyter/343331 "2023-09-19T08:46:50Z")

</div>

I currently have setup Eland to pull data from Elasticsearch and I am trying to rename some of the columns. However, I realised that to use the .rename() function, I would have to convert the data to Pandas Dataframe as …

---

## [Is it possible to generate or export a csv from Kibana dev tool](https://discuss.elastic.co/t/is-it-possible-to-generate-or-export-a-csv-from-kibana-dev-tool/343027)

<div class="topic-metadata">

**Author:** [@JasonREC](https://discuss.elastic.co/u/JasonREC)\
**Replies:** 2\
**Last updated:** [September 19, 2023, 8:38am UTC](https://discuss.elastic.co/t/is-it-possible-to-generate-or-export-a-csv-from-kibana-dev-tool/343027 "2023-09-19T08:38:11Z")

</div>

Hi, I wonder if it is possible to generate a CSV report from dev tool ? The following is my query run on Kibana dev tool, it composed of query and aggregation. I want to generate the query response to a csv. if it is …

---

## [Kibana server is not ready yet](https://discuss.elastic.co/t/kibana-server-is-not-ready-yet/343270)

<div class="topic-metadata">

**Author:** [@emoxam](https://discuss.elastic.co/u/emoxam)\
**Replies:** 4\
**Last updated:** [September 19, 2023, 6:38am UTC](https://discuss.elastic.co/t/kibana-server-is-not-ready-yet/343270 "2023-09-19T06:38:25Z")

</div>

I got one host with elasticsearch and kibana, i don't want to use any ssl/tls. That's an error i got in logs now. How can i fix kibana ? It's web page shows me "Kibana server is not ready yet" journalctl -efu kibana.se…

---

## [Some Questions About Security Vulnerabilities: ESA-2023-14](https://discuss.elastic.co/t/some-questions-about-security-vulnerabilities-esa-2023-14/343317)

<div class="topic-metadata">

**Author:** [@zekaifeng](https://discuss.elastic.co/u/zekaifeng)\
**Replies:** 0\
**Last updated:** [September 19, 2023, 6:33am UTC](https://discuss.elastic.co/t/some-questions-about-security-vulnerabilities-esa-2023-14/343317 "2023-09-19T06:33:09Z")

</div>

Hello, everybody. According to the community's safety announcement: I don't know which issue is associated with this security update or which pr fixed the issue.

---

## [Elastic-agent and Veeam man plugin](https://discuss.elastic.co/t/elastic-agent-and-veeam-man-plugin/343316)

<div class="topic-metadata">

**Author:** [@thiesens](https://discuss.elastic.co/u/thiesens)\
**Replies:** 0\
**Last updated:** [September 19, 2023, 6:16am UTC](https://discuss.elastic.co/t/elastic-agent-and-veeam-man-plugin/343316 "2023-09-19T06:16:36Z")

</div>

Hi all.. I have a few Oracle servers, where I want to install elastic-agent. The problem for me is that I have Veeam RMAN plugin installed, and it seems that both are using port 6791. Is it possible to change the elas…

[Previous page](https://discuss.elastic.co/tag/none.md?no_tags=true&page=300)

[Next page](https://discuss.elastic.co/tag/none.md?no_tags=true&page=302)
