# \#none

**URL:** https://discuss.elastic.co/tag/none.md?no_tags=true&page=302

[Latest](https://discuss.elastic.co/latest.md) · [Categories](https://discuss.elastic.co/categories.md) · [Tags](https://discuss.elastic.co/tags.md)

**Page:** 303

---

## [Query\_string does not perform consistently in versions 6 and 7](https://discuss.elastic.co/t/query-string-does-not-perform-consistently-in-versions-6-and-7/343228)

<div class="topic-metadata">

**Author:** [@casterQ](https://discuss.elastic.co/u/casterQ)\
**Replies:** 2\
**Last updated:** [September 19, 2023, 6:04am UTC](https://discuss.elastic.co/t/query-string-does-not-perform-consistently-in-versions-6-and-7/343228 "2023-09-19T06:04:55Z")

</div>

version: 6.7.0 and 7.17.6 mapping: { "t1": { "type": "text", "analyzer": "ik\_max\_word" }, "t2": { "type": "text", "analyzer": "ik\_max\_word" } } DSL: POST test1/\_search { "query": { "boo…

---

## [Logstash - How to Dynamic Parse Log's value](https://discuss.elastic.co/t/logstash-how-to-dynamic-parse-logs-value/343125)

<div class="topic-metadata">

**Author:** [@Huy\_Hoang\_Le](https://discuss.elastic.co/u/Huy_Hoang_Le)\
**Replies:** 8\
**Last updated:** [September 19, 2023, 3:36am UTC](https://discuss.elastic.co/t/logstash-how-to-dynamic-parse-logs-value/343125 "2023-09-19T03:36:25Z")

</div>

Hi I have this sample Document \[Thread-13\]\[2023-09-15 09:32:35\]\[INFO\]:{'\[Sub\]0-BaseTransformer\]': '0.0004', '\[Sub\]1-NGINX Feature Extractor Service\]': '0.0135', '\[Dataloader\]\[#0.-PutToQueue\]': '0.0005', '\[Sub\]\[#1.EMA\_FP…

---

## [Elasticsearch 8.9.1 / 7.17.13 Security Update](https://discuss.elastic.co/t/elasticsearch-8-9-1-7-17-13-security-update/343297)

<div class="topic-metadata">

**Author:** [@rodrigo\_silva](https://discuss.elastic.co/u/rodrigo_silva)\
**Replies:** 0\
**Last updated:** [September 18, 2023, 8:40pm UTC](https://discuss.elastic.co/t/elasticsearch-8-9-1-7-17-13-security-update/343297 "2023-09-18T20:40:51Z")

</div>

Elasticsearch StackOverflow vulnerability (ESA-2023-14) A flaw was discovered in Elasticsearch, affecting the \_search API that allowed a specially crafted query string to cause a Stack Overflow and ultimately a Denial of…

---

## [Elastic Search on Rocky LInux 9](https://discuss.elastic.co/t/elastic-search-on-rocky-linux-9/343293)

<div class="topic-metadata">

**Author:** [@mcarifio](https://discuss.elastic.co/u/mcarifio)\
**Replies:** 1\
**Last updated:** [September 18, 2023, 8:27pm UTC](https://discuss.elastic.co/t/elastic-search-on-rocky-linux-9/343293 "2023-09-18T20:27:06Z")

</div>

Does anyone have experience running Elastic Search on Rocky Linux 9? The Elastic Search support matrix indicates that RHEL 9 is a supported platform. What's the best way to add a Rocky Linux 9 column? Thanks.

---

## [Logstash vulnerabilities around ruby-maven-libs](https://discuss.elastic.co/t/logstash-vulnerabilities-around-ruby-maven-libs/343278)

<div class="topic-metadata">

**Author:** [@balakr](https://discuss.elastic.co/u/balakr)\
**Replies:** 2\
**Last updated:** [September 18, 2023, 4:23pm UTC](https://discuss.elastic.co/t/logstash-vulnerabilities-around-ruby-maven-libs/343278 "2023-09-18T16:23:12Z")

</div>

my company is pushing me for fixing vulnerablities in logstash, at this point i am in learning mode. when i looking at the below vulnerablity, does this need ruby-maven-libs upgrade or just guava upgrade Required\_Versi…

---

## [Error installing gems (\> invalid source release: 11)](https://discuss.elastic.co/t/error-installing-gems-invalid-source-release-11/343201)

<div class="topic-metadata">

**Author:** [@balakr](https://discuss.elastic.co/u/balakr)\
**Replies:** 2\
**Last updated:** [September 18, 2023, 3:31pm UTC](https://discuss.elastic.co/t/error-installing-gems-invalid-source-release-11/343201 "2023-09-18T15:31:23Z")

</div>

Task :downloadPreviousJRuby UP-TO-DATE Task :downloadJRuby UP-TO-DATE Download jruby-dist-9.3.10.0-bin.tar.gz Task :benchmark-cli:compileJava FAILED FAILURE: Build failed with an exception. What went wrong: …

---

## [Unable to show span attributes of OTEL span in kibana](https://discuss.elastic.co/t/unable-to-show-span-attributes-of-otel-span-in-kibana/343223)

<div class="topic-metadata">

**Author:** [@Hamad](https://discuss.elastic.co/u/Hamad)\
**Replies:** 6\
**Last updated:** [September 18, 2023, 3:07pm UTC](https://discuss.elastic.co/t/unable-to-show-span-attributes-of-otel-span-in-kibana/343223 "2023-09-18T15:07:11Z")

</div>

I have a nestjs project and i need to trace graphql calls. i am usnig opentelemetry to collect traces and apm server to show them on kibana. The problem i am facing is that all graphql calls are being grouped under same …

---

## [Ingest Github Audit logs with Logstash](https://discuss.elastic.co/t/ingest-github-audit-logs-with-logstash/343266)

<div class="topic-metadata">

**Author:** [@trwillis](https://discuss.elastic.co/u/trwillis)\
**Replies:** 1\
**Last updated:** [September 18, 2023, 1:57pm UTC](https://discuss.elastic.co/t/ingest-github-audit-logs-with-logstash/343266 "2023-09-18T13:57:45Z")

</div>

Has anyone created a successful grok pattern to ingest Github audit logs into ELK? Or does the Github plugin support formatting those logs into ELK?

---

## [Failed to retrieve shard stats from node \[cRf-MJ\_dTDGEeR-NRfKvAg\]](https://discuss.elastic.co/t/failed-to-retrieve-shard-stats-from-node-crf-mj-dtdgeer-nrfkvag/343269)

<div class="topic-metadata">

**Author:** [@Jobin\_James](https://discuss.elastic.co/u/Jobin_James)\
**Replies:** 0\
**Last updated:** [September 18, 2023, 1:47pm UTC](https://discuss.elastic.co/t/failed-to-retrieve-shard-stats-from-node-crf-mj-dtdgeer-nrfkvag/343269 "2023-09-18T13:47:53Z")

</div>

Can someone help me with this? I have no idea how to fix this. ECK version 2.9 Elasicsearch version 8.9 { "@timestamp":"2023-09-18T13:43:13.838Z", "log.level":"WARN", "message":"failed to retrieve shard stats…

---

## [Elasticsearch alias issue with filtering](https://discuss.elastic.co/t/elasticsearch-alias-issue-with-filtering/343268)

<div class="topic-metadata">

**Author:** [@ricadao](https://discuss.elastic.co/u/ricadao)\
**Replies:** 0\
**Last updated:** [September 18, 2023, 1:44pm UTC](https://discuss.elastic.co/t/elasticsearch-alias-issue-with-filtering/343268 "2023-09-18T13:44:47Z")

</div>

Hi. I have on Index fullData where I store documents from various sources, having one field as docSource. After that, created an alias over this fullData to have a view over source='phone' with the following code: POST …

---

## [Send logs Citrix to logstash/elasticsearch](https://discuss.elastic.co/t/send-logs-citrix-to-logstash-elasticsearch/343263)

<div class="topic-metadata">

**Author:** [@mulbzh](https://discuss.elastic.co/u/mulbzh)\
**Replies:** 0\
**Last updated:** [September 18, 2023, 1:01pm UTC](https://discuss.elastic.co/t/send-logs-citrix-to-logstash-elasticsearch/343263 "2023-09-18T13:01:52Z")

</div>

Hello and sorry for my bad english :slight\_smile: , I am new in logstash/elasticsearch. I have a server installed by older technician. So, i understand globally how it works but i have one trouble. I send logs from my…

---

## [Delete Older csv reports from Kibana](https://discuss.elastic.co/t/delete-older-csv-reports-from-kibana/343219)

<div class="topic-metadata">

**Author:** [@johnashish](https://discuss.elastic.co/u/johnashish)\
**Replies:** 1\
**Last updated:** [September 18, 2023, 12:53pm UTC](https://discuss.elastic.co/t/delete-older-csv-reports-from-kibana/343219 "2023-09-18T12:53:17Z")

</div>

I want to delete older csv files automatically from reporting section from Kibana. Kibana - 7.17.3 Attached screenshot. The problem is now we have so many older reports if i run any automated script or any query wi…

---

## [Query not working as expected](https://discuss.elastic.co/t/query-not-working-as-expected/343186)

<div class="topic-metadata">

**Author:** [@DWAIPAYAN\_SOM](https://discuss.elastic.co/u/DWAIPAYAN_SOM)\
**Replies:** 4\
**Last updated:** [September 18, 2023, 12:07pm UTC](https://discuss.elastic.co/t/query-not-working-as-expected/343186 "2023-09-18T12:07:48Z")

</div>

The below are my query for selection and rejection. Selection : { "nested": { "path": "somethingnew", "query": { "bool": { "must": \[ { …

---

## [Anomaly detection Population Job](https://discuss.elastic.co/t/anomaly-detection-population-job/342451)

<div class="topic-metadata">

**Author:** [@NamithaJ97](https://discuss.elastic.co/u/NamithaJ97)\
**Replies:** 6\
**Last updated:** [September 18, 2023, 12:07pm UTC](https://discuss.elastic.co/t/anomaly-detection-population-job/342451 "2023-09-18T12:07:39Z")

</div>

country state child\_count a a\_s1 302 a a\_s2 310 a a\_s3 308 a a\_s4 21 b b\_s1 14 b b\_s2 16 b b\_s3 17 b b\_s4 218 I have a population anomaly detecti…

---

## [Is this library subject to US EAR (Encryption and Export administration regulations)?](https://discuss.elastic.co/t/is-this-library-subject-to-us-ear-encryption-and-export-administration-regulations/343211)

<div class="topic-metadata">

**Author:** [@ztest-dev](https://discuss.elastic.co/u/ztest-dev)\
**Replies:** 2\
**Last updated:** [September 18, 2023, 11:00am UTC](https://discuss.elastic.co/t/is-this-library-subject-to-us-ear-encryption-and-export-administration-regulations/343211 "2023-09-18T11:00:02Z")

</div>

Hello everyone, First, thank you so much for developing this open-source software which is powerful and feature-rich but also simple and easy to use. I prepare to use it in my projects. However, I wonder whether this so…

---

## [Enhanced Table Computed Columns can handle null values](https://discuss.elastic.co/t/enhanced-table-computed-columns-can-handle-null-values/343131)

<div class="topic-metadata">

**Author:** [@PRASHANT\_MEHTA](https://discuss.elastic.co/u/PRASHANT_MEHTA)\
**Replies:** 2\
**Last updated:** [September 18, 2023, 10:41am UTC](https://discuss.elastic.co/t/enhanced-table-computed-columns-can-handle-null-values/343131 "2023-09-18T10:41:03Z")

</div>

Hello @fbaligand , I am using computed columns to show Hyperlink values. The issue I'm facing is that this columns not always contains the value and somethimes the data from backend itself is not available, hence comput…

---

## [Node validation exception \[1\] bootstrap checks failed](https://discuss.elastic.co/t/node-validation-exception-1-bootstrap-checks-failed/343239)

<div class="topic-metadata">

**Author:** [@dev008](https://discuss.elastic.co/u/dev008)\
**Replies:** 3\
**Last updated:** [September 18, 2023, 10:30am UTC](https://discuss.elastic.co/t/node-validation-exception-1-bootstrap-checks-failed/343239 "2023-09-18T10:30:01Z")

</div>

Hi Team, I am getting the below error while configuring Elastic clustering on master node. I have gone through documentation still the error persist . Can someone please guide me where am i going wrong. Here are the lo…

---

## [Isolating and restoring the Data node](https://discuss.elastic.co/t/isolating-and-restoring-the-data-node/343244)

<div class="topic-metadata">

**Author:** [@Manal\_A](https://discuss.elastic.co/u/Manal_A)\
**Replies:** 0\
**Last updated:** [September 18, 2023, 9:50am UTC](https://discuss.elastic.co/t/isolating-and-restoring-the-data-node/343244 "2023-09-18T09:50:15Z")

</div>

What is the procedure for isolating and restoring the Data node for version 8.8.1?

---

## [Grok not parsing](https://discuss.elastic.co/t/grok-not-parsing/343098)

<div class="topic-metadata">

**Author:** [@pshas](https://discuss.elastic.co/u/pshas)\
**Replies:** 1\
**Last updated:** [September 18, 2023, 9:24am UTC](https://discuss.elastic.co/t/grok-not-parsing/343098 "2023-09-18T09:24:33Z")

</div>

logstash.conf # Sample Logstash configuration for creating a simple # Beats -\> Logstash -\> Elasticsearch pipeline. input { beats { port =\> 5044 type = "test" } } filter { if \[type\] == "log" { grok { …

---

## [Monitoring filebeat, heartbeat, metricbeat, logstash, kibana stats in kibana dashboards](https://discuss.elastic.co/t/monitoring-filebeat-heartbeat-metricbeat-logstash-kibana-stats-in-kibana-dashboards/342937)

<div class="topic-metadata">

**Author:** [@PRASHANT\_MEHTA](https://discuss.elastic.co/u/PRASHANT_MEHTA)\
**Replies:** 4\
**Last updated:** [September 18, 2023, 8:12am UTC](https://discuss.elastic.co/t/monitoring-filebeat-heartbeat-metricbeat-logstash-kibana-stats-in-kibana-dashboards/342937 "2023-09-18T08:12:14Z")

</div>

Hello All, Currently all the beats and logstash sends data directly to Elasticsearch. I have multiple servers installed with heartbeat,metricbeat,logstash and filebeat and now I've requirement to monitor all these comp…

---

## [FsCrawler 2.10 Rest Service upload returns error for file more than 20 MB](https://discuss.elastic.co/t/fscrawler-2-10-rest-service-upload-returns-error-for-file-more-than-20-mb/342706)

<div class="topic-metadata">

**Author:** [@Nilesh\_Pegasus](https://discuss.elastic.co/u/Nilesh_Pegasus)\
**Replies:** 12\
**Last updated:** [September 18, 2023, 6:00am UTC](https://discuss.elastic.co/t/fscrawler-2-10-rest-service-upload-returns-error-for-file-more-than-20-mb/342706 "2023-09-18T06:00:00Z")

</div>

Hi, I am using FsCrawler 2.10 with elasticsearch 8.9, I am trying to upload a 20Mb .msg file using rest service of FsCrawler, but it gives error. Please note that I am able to upload smaller files without any issues. F…

---

## [Logstash stop working due to FFI not available: null](https://discuss.elastic.co/t/logstash-stop-working-due-to-ffi-not-available-null/343174)

<div class="topic-metadata">

**Author:** [@lalchand\_rajak](https://discuss.elastic.co/u/lalchand_rajak)\
**Replies:** 2\
**Last updated:** [September 18, 2023, 5:37am UTC](https://discuss.elastic.co/t/logstash-stop-working-due-to-ffi-not-available-null/343174 "2023-09-18T05:37:38Z")

</div>

Logstash stopped working due to FFI not available: null . I have already provided the tmp path in Jvm.options # set the I/O temp directory #-Djava.io.tmpdir=$HOME -Djava.io.tmpdir=/home/apmuser/tmp drwxrwxr-x. 2 logsta…

---

## [ELK to monitor job](https://discuss.elastic.co/t/elk-to-monitor-job/342422)

<div class="topic-metadata">

**Author:** [@murran\_rais](https://discuss.elastic.co/u/murran_rais)\
**Replies:** 6\
**Last updated:** [September 18, 2023, 5:00am UTC](https://discuss.elastic.co/t/elk-to-monitor-job/342422 "2023-09-18T05:00:33Z")

</div>

hi, im new with ELK, wanna ask, can ELK monitor job from Apache airflow, SQL or other applications? and can elk monitor comprehensivly like give information about history of the job, last run time of the job, condition o…

---

## [How to do header control in Kibana?](https://discuss.elastic.co/t/how-to-do-header-control-in-kibana/343216)

<div class="topic-metadata">

**Author:** [@dudqlssky96](https://discuss.elastic.co/u/dudqlssky96)\
**Replies:** 1\
**Last updated:** [September 18, 2023, 4:22am UTC](https://discuss.elastic.co/t/how-to-do-header-control-in-kibana/343216 "2023-09-18T04:22:19Z")

</div>

I'd like to change the logo part from Kibana version 8.9. Please help me if you know how

---

## [Infer model Text embedding in Java](https://discuss.elastic.co/t/infer-model-text-embedding-in-java/343192)

<div class="topic-metadata">

**Author:** [@Khanh\_Dao\_Minh](https://discuss.elastic.co/u/Khanh_Dao_Minh)\
**Replies:** 1\
**Last updated:** [September 17, 2023, 12:37pm UTC](https://discuss.elastic.co/t/infer-model-text-embedding-in-java/343192 "2023-09-17T12:37:52Z")

</div>

Hi there, Is there any document or instruction on how to use the machine learning api in java? For example, how can I convert this query into java POST /\_ml/trained\_models/My\_model/\_infer { "docs": { "text\_field…

---

## [Get analytics with potential alerts if anomalies detected](https://discuss.elastic.co/t/get-analytics-with-potential-alerts-if-anomalies-detected/343177)

<div class="topic-metadata">

**Author:** [@O\_K](https://discuss.elastic.co/u/O_K)\
**Replies:** 5\
**Last updated:** [September 17, 2023, 11:20am UTC](https://discuss.elastic.co/t/get-analytics-with-potential-alerts-if-anomalies-detected/343177 "2023-09-17T11:20:31Z")

</div>

I'm researching options how to get some analytics, for instance, I want to look into ERRORs in log\_level column, and if its amount increases drastically, I want to receive an alert. There should be many such cases and it…

---

## [ElasticSearch on giant compute nodes](https://discuss.elastic.co/t/elasticsearch-on-giant-compute-nodes/343183)

<div class="topic-metadata">

**Author:** [@Don\_Boscow](https://discuss.elastic.co/u/Don_Boscow)\
**Replies:** 0\
**Last updated:** [September 16, 2023, 9:10pm UTC](https://discuss.elastic.co/t/elasticsearch-on-giant-compute-nodes/343183 "2023-09-16T21:10:30Z")

</div>

The standard paradigm which I see is usually recommended for ES (mainly for query purpose) is a collection or cluster of nodes - the nodes being typically SSD, the RAM usually recommended as 64 GB, with shard size not ex…

---

## [ELK SSL config problem](https://discuss.elastic.co/t/elk-ssl-config-problem/342668)

<div class="topic-metadata">

**Author:** [@p81061473525](https://discuss.elastic.co/u/p81061473525)\
**Replies:** 3\
**Last updated:** [September 16, 2023, 11:26am UTC](https://discuss.elastic.co/t/elk-ssl-config-problem/342668 "2023-09-16T11:26:22Z")

</div>

Hello, recently I've been practicing setting up ELK 8.9. My target architecture looks like this: Filebeat -\> Logstash -\> ES \<- Kibana. I encountered difficulties when configuring encryption. Currently, my architecture …

---

## [Sum of duration field of max per group in Elasticsearch](https://discuss.elastic.co/t/sum-of-duration-field-of-max-per-group-in-elasticsearch/342285)

<div class="topic-metadata">

**Author:** [@carollyl](https://discuss.elastic.co/u/carollyl)\
**Replies:** 22\
**Last updated:** [September 16, 2023, 6:31am UTC](https://discuss.elastic.co/t/sum-of-duration-field-of-max-per-group-in-elasticsearch/342285 "2023-09-16T06:31:01Z")

</div>

I would like to create a visualizer by summing up duration field after retrieving max id per group in Elasticsearch. For example: Data is: id workflow sid duration 1 A x1 1m 1 A x2 2m 2 A x1 2m 2 A x2 3m …

---

## [Fixing vulnerablities in logstash code](https://discuss.elastic.co/t/fixing-vulnerablities-in-logstash-code/343168)

<div class="topic-metadata">

**Author:** [@balakr](https://discuss.elastic.co/u/balakr)\
**Replies:** 1\
**Last updated:** [September 16, 2023, 5:05am UTC](https://discuss.elastic.co/t/fixing-vulnerablities-in-logstash-code/343168 "2023-09-16T05:05:34Z")

</div>

my company check for vulnerablities and i see bunch of vulnerablities in logstash. an example is below to fix this vulnerablity, should i upgrade guava or does jruby needs to be upgraded. if jruby needs to be upgraded …

[Previous page](https://discuss.elastic.co/tag/none.md?no_tags=true&page=301)

[Next page](https://discuss.elastic.co/tag/none.md?no_tags=true&page=303)
