# \#none

**URL:** https://discuss.elastic.co/tag/none.md?no_tags=true&page=304

[Latest](https://discuss.elastic.co/latest.md) · [Categories](https://discuss.elastic.co/categories.md) · [Tags](https://discuss.elastic.co/tags.md)

**Page:** 305

---

## [\[es 5.6.8\] How to tanslate this postgre sql to es ver -- order by count(id) over (partition by org\_name, visit\_datetime) desc](https://discuss.elastic.co/t/es-5-6-8-how-to-tanslate-this-postgre-sql-to-es-ver-order-by-count-id-over-partition-by-org-name-visit-datetime-desc/343042)

<div class="topic-metadata">

**Author:** [@vvneedspeed](https://discuss.elastic.co/u/vvneedspeed)\
**Replies:** 0\
**Last updated:** [September 14, 2023, 10:25am UTC](https://discuss.elastic.co/t/es-5-6-8-how-to-tanslate-this-postgre-sql-to-es-ver-order-by-count-id-over-partition-by-org-name-visit-datetime-desc/343042 "2023-09-14T10:25:57Z")

</div>

Hi there, I'm stuck. How to tanslate this postgre sql to Elasticsearch ver? The Elasticsearch is 5.6.8, but the solution with higher version is also welcome! select user\_name from tablea order by count(meid) over (p…

---

## [Get base events triggered by a threshold rule](https://discuss.elastic.co/t/get-base-events-triggered-by-a-threshold-rule/343034)

<div class="topic-metadata">

**Author:** [@c8n](https://discuss.elastic.co/u/c8n)\
**Replies:** 0\
**Last updated:** [September 14, 2023, 9:35am UTC](https://discuss.elastic.co/t/get-base-events-triggered-by-a-threshold-rule/343034 "2023-09-14T09:35:09Z")

</div>

I'm having a hard time trying to get the base events that triggered a threshold rule using a logstash pipeline. Right now I've built a KQL query that gives those documents, but still doesnt populate any field in the orig…

---

## [Index size and doc\_count of a customer or field filter](https://discuss.elastic.co/t/index-size-and-doc-count-of-a-customer-or-field-filter/343025)

<div class="topic-metadata">

**Author:** [@agonzalez](https://discuss.elastic.co/u/agonzalez)\
**Replies:** 0\
**Last updated:** [September 14, 2023, 8:05am UTC](https://discuss.elastic.co/t/index-size-and-doc-count-of-a-customer-or-field-filter/343025 "2023-09-14T08:05:24Z")

</div>

Hi, i have one index where i store documents from different customerid differentiated but a customerid field. I want to know how many documents and storage size each customer is consuming in my index, I can see this for…

---

## [Installing Elasticsearch Error](https://discuss.elastic.co/t/installing-elasticsearch-error/342976)

<div class="topic-metadata">

**Author:** [@heureux](https://discuss.elastic.co/u/heureux)\
**Replies:** 2\
**Last updated:** [September 14, 2023, 6:56am UTC](https://discuss.elastic.co/t/installing-elasticsearch-error/342976 "2023-09-14T06:56:38Z")

</div>

Hi, By executing the command: ./bin/elasticsearch I have this error: \< \[ERROR\]\[o.e.b.Elasticsearch \] \[wazuh-server\] fatal exception while booting Elasticsearchjava.lang.RuntimeException: can not run elasticsearc…

---

## [How to show only 2 numbers in vertical axis](https://discuss.elastic.co/t/how-to-show-only-2-numbers-in-vertical-axis/342897)

<div class="topic-metadata">

**Author:** [@rkidev](https://discuss.elastic.co/u/rkidev)\
**Replies:** 3\
**Last updated:** [September 14, 2023, 6:48am UTC](https://discuss.elastic.co/t/how-to-show-only-2-numbers-in-vertical-axis/342897 "2023-09-14T06:48:24Z")

</div>

Hi, I have only 2 servers and in the time series graph I want to show which server is online. Is there any way in Kibana to show only 2 numbers in X-axis ? I know Kibana dynamically set the ranges and display values but…

---

## [The Elasticsearch process is experiencing rapid memory growth in the older generation](https://discuss.elastic.co/t/the-elasticsearch-process-is-experiencing-rapid-memory-growth-in-the-older-generation/343013)

<div class="topic-metadata">

**Author:** [@liguifa](https://discuss.elastic.co/u/liguifa)\
**Replies:** 5\
**Last updated:** [September 14, 2023, 6:46am UTC](https://discuss.elastic.co/t/the-elasticsearch-process-is-experiencing-rapid-memory-growth-in-the-older-generation/343013 "2023-09-14T06:46:43Z")

</div>

As shown in the above figure, my Elasticsearch cluster has experienced rapid memory growth in its old age, and after a period of time, it will be reclaimed, which will also occupy a large amount of memory. How should …

---

## [What is the best way to detect inconsistency between elasticsearch with another authorized data store](https://discuss.elastic.co/t/what-is-the-best-way-to-detect-inconsistency-between-elasticsearch-with-another-authorized-data-store/343009)

<div class="topic-metadata">

**Author:** [@zouyang](https://discuss.elastic.co/u/zouyang)\
**Replies:** 0\
**Last updated:** [September 14, 2023, 5:11am UTC](https://discuss.elastic.co/t/what-is-the-best-way-to-detect-inconsistency-between-elasticsearch-with-another-authorized-data-store/343009 "2023-09-14T05:11:37Z")

</div>

Hi, Our system uses dynamoDB as the data store and sync the data to elasticsearch with kafka. In case there are any data loss due to the failure of any part of the system, we would have inconsistency between dynamo and…

---

## [Elasticsearch Security Statement regarding CVE-2022-1471](https://discuss.elastic.co/t/elasticsearch-security-statement-regarding-cve-2022-1471/343006)

<div class="topic-metadata">

**Author:** [@ikakavas](https://discuss.elastic.co/u/ikakavas)\
**Replies:** 0\
**Last updated:** [September 14, 2023, 4:53am UTC](https://discuss.elastic.co/t/elasticsearch-security-statement-regarding-cve-2022-1471/343006 "2023-09-14T04:53:14Z")

</div>

Elasticsearch is not affected by this issue. Elasticsearch is not affected by the issue described in CVE-2022-1471 as, in general, it does not use Snakeyaml to parse YAML. Summary Elasticsearch supports YAML as a format…

---

## [Kibana quits 1 second after launch](https://discuss.elastic.co/t/kibana-quits-1-second-after-launch/342997)

<div class="topic-metadata">

**Author:** [@ljk602308](https://discuss.elastic.co/u/ljk602308)\
**Replies:** 1\
**Last updated:** [September 14, 2023, 3:31am UTC](https://discuss.elastic.co/t/kibana-quits-1-second-after-launch/342997 "2023-09-14T03:31:29Z")

</div>

It was running a week ago, but when I ran it this time, Kibana did not run. The issue of the console window closing as soon as you run kibana.bat still occurs even if you reinstall Kibana. I'm using Windows 10, and Ela…

---

## [Discuss configuration connectors about mail exchange](https://discuss.elastic.co/t/discuss-configuration-connectors-about-mail-exchange/343000)

<div class="topic-metadata">

**Author:** [@vanhaiit90](https://discuss.elastic.co/u/vanhaiit90)\
**Replies:** 2\
**Last updated:** [September 14, 2023, 2:38am UTC](https://discuss.elastic.co/t/discuss-configuration-connectors-about-mail-exchange/343000 "2023-09-14T02:38:43Z")

</div>

Hi everyone! I getting issue when after completed configure connector mail exchange with Client ID and Tenant ID . So I have tried test send but it still shows error And this is a text configure connect mail exch…

---

## [Migration of ELK users](https://discuss.elastic.co/t/migration-of-elk-users/342647)

<div class="topic-metadata">

**Author:** [@mostafaelsayed](https://discuss.elastic.co/u/mostafaelsayed)\
**Replies:** 3\
**Last updated:** [September 13, 2023, 8:59pm UTC](https://discuss.elastic.co/t/migration-of-elk-users/342647 "2023-09-13T20:59:59Z")

</div>

Hello, Is there a secure way to migrate kibana users from one instance to another along with their passwords? Thanks

---

## [Logstash file plugin on windows](https://discuss.elastic.co/t/logstash-file-plugin-on-windows/342852)

<div class="topic-metadata">

**Author:** [@mahmoud.shsuite](https://discuss.elastic.co/u/mahmoud.shsuite)\
**Replies:** 7\
**Last updated:** [September 13, 2023, 8:03pm UTC](https://discuss.elastic.co/t/logstash-file-plugin-on-windows/342852 "2023-09-13T20:03:41Z")

</div>

I've just installed logstach version 8.9.2 on windows and tried to do first file sample but I am greeting message=\>"Unable to configure plugins: (PluginLoadingError) Couldn't find any input plugin named 'file' I insured…

---

## [Fleet Server shutdown after enroll](https://discuss.elastic.co/t/fleet-server-shutdown-after-enroll/342791)

<div class="topic-metadata">

**Author:** [@bixiyan](https://discuss.elastic.co/u/bixiyan)\
**Replies:** 0\
**Last updated:** [September 12, 2023, 8:47am UTC](https://discuss.elastic.co/t/fleet-server-shutdown-after-enroll/342791 "2023-09-12T08:47:39Z")

</div>

Hi Team: I want to set up fleet server but failed after executed enroll command. My es version is v 7.16.3 . Let me know any more infomation you needed. Here is my fleet enroll command. elastic-agent enroll --url=htt…

---

## [Logstash crashing](https://discuss.elastic.co/t/logstash-crashing/342972)

<div class="topic-metadata">

**Author:** [@sc5283](https://discuss.elastic.co/u/sc5283)\
**Replies:** 4\
**Last updated:** [September 13, 2023, 5:49pm UTC](https://discuss.elastic.co/t/logstash-crashing/342972 "2023-09-13T17:49:37Z")

</div>

Input is from S3 layout of S3 bucket is : s3 { .... bucket =\> "bucket" prefix =\> "YYYY/MM/DD/hh/" ..... } so every hour I have to create a new conf file with the corresponding prefix…

---

## [Top n over Max() aggregation with group by and then return all fields](https://discuss.elastic.co/t/top-n-over-max-aggregation-with-group-by-and-then-return-all-fields/342954)

<div class="topic-metadata">

**Author:** [@aakashagrawal](https://discuss.elastic.co/u/aakashagrawal)\
**Replies:** 1\
**Last updated:** [September 13, 2023, 4:24pm UTC](https://discuss.elastic.co/t/top-n-over-max-aggregation-with-group-by-and-then-return-all-fields/342954 "2023-09-13T16:24:56Z")

</div>

Hi, I'm a total newbie to Elasticsearch and hence please ignore if you think my question is very basic. I've already looked at this post which solves one part of my problem: What I want is only top n (say top 2) resu…

---

## [Elastic agent indices - ILM](https://discuss.elastic.co/t/elastic-agent-indices-ilm/342243)

<div class="topic-metadata">

**Author:** [@Tyty](https://discuss.elastic.co/u/Tyty)\
**Replies:** 5\
**Last updated:** [September 13, 2023, 3:30pm UTC](https://discuss.elastic.co/t/elastic-agent-indices-ilm/342243 "2023-09-13T15:30:02Z")

</div>

Hi All, Currently using ELK stack 8.91. Fleet enable. Elasticc-agent deployed on around 100 Servers/vm. I notice that indexes will never be cleared. Seems to be a default behavior. I need to know how to setup an Inde…

---

## [A query builder java library for parsing web query into an elastic client Query object](https://discuss.elastic.co/t/a-query-builder-java-library-for-parsing-web-query-into-an-elastic-client-query-object/342958)

<div class="topic-metadata">

**Author:** [@Jim\_Song](https://discuss.elastic.co/u/Jim_Song)\
**Replies:** 1\
**Last updated:** [September 13, 2023, 3:28pm UTC](https://discuss.elastic.co/t/a-query-builder-java-library-for-parsing-web-query-into-an-elastic-client-query-object/342958 "2023-09-13T15:28:32Z")

</div>

I am building an elastic client Java application that users will enter a search query from the browser. I am looking for an open source Java library that can take the user inputs and parse them into an elasticsearch clie…

---

## [How to delete the records older than certain time using elastic java rest client](https://discuss.elastic.co/t/how-to-delete-the-records-older-than-certain-time-using-elastic-java-rest-client/342960)

<div class="topic-metadata">

**Author:** [@Tukaram](https://discuss.elastic.co/u/Tukaram)\
**Replies:** 1\
**Last updated:** [September 13, 2023, 3:27pm UTC](https://discuss.elastic.co/t/how-to-delete-the-records-older-than-certain-time-using-elastic-java-rest-client/342960 "2023-09-13T15:27:18Z")

</div>

Hi, I am looking to delete all the records older than 1 month or so(in bulk). How to get this done using java restclient.

---

## [Global Filter Overrides the Hard coded Date Range](https://discuss.elastic.co/t/global-filter-overrides-the-hard-coded-date-range/342090)

<div class="topic-metadata">

**Author:** [@Kumar\_Abhinav](https://discuss.elastic.co/u/Kumar_Abhinav)\
**Replies:** 10\
**Last updated:** [September 13, 2023, 2:38pm UTC](https://discuss.elastic.co/t/global-filter-overrides-the-hard-coded-date-range/342090 "2023-09-13T14:38:08Z")

</div>

Hello everyone, I've been working on a Kibana dashboard to track item expirations over time. I created a Visualization table that displays the Date Range, Item Name, Item Location, Item Expiry Date, and Quantity. Specif…

---

## [How to aggregate conditionally logs](https://discuss.elastic.co/t/how-to-aggregate-conditionally-logs/342945)

<div class="topic-metadata">

**Author:** [@Marieta](https://discuss.elastic.co/u/Marieta)\
**Replies:** 1\
**Last updated:** [September 13, 2023, 2:30pm UTC](https://discuss.elastic.co/t/how-to-aggregate-conditionally-logs/342945 "2023-09-13T14:30:07Z")

</div>

Hi I am trying to aggregate the following logs: 2023-09-06 07:36:22,573 | INFO | Thread-934 | Config | ENTERORDER: identifier = 'Barbie', buy = false, quantity = 290000.0, price = 96.1, account = '123', reference = '',…

---

## [Please help kibana show server not ready yet](https://discuss.elastic.co/t/please-help-kibana-show-server-not-ready-yet/342943)

<div class="topic-metadata">

**Author:** [@Mbrezzy](https://discuss.elastic.co/u/Mbrezzy)\
**Replies:** 1\
**Last updated:** [September 13, 2023, 1:07pm UTC](https://discuss.elastic.co/t/please-help-kibana-show-server-not-ready-yet/342943 "2023-09-13T13:07:48Z")

</div>

I have active the trial version of security but when its ended i face this problem and kibana show me server is not ready yet

---

## [Want to figure that how the mapping of an index gets changed on one env](https://discuss.elastic.co/t/want-to-figure-that-how-the-mapping-of-an-index-gets-changed-on-one-env/342934)

<div class="topic-metadata">

**Author:** [@Mansi\_Ghule](https://discuss.elastic.co/u/Mansi_Ghule)\
**Replies:** 7\
**Last updated:** [September 13, 2023, 12:53pm UTC](https://discuss.elastic.co/t/want-to-figure-that-how-the-mapping-of-an-index-gets-changed-on-one-env/342934 "2023-09-13T12:53:29Z")

</div>

Hello, I want to figure out that is there any chances that the mapping of the index may change. As the ES queries n all was running fine on one env but sudden I'm getting error while searching. And I checked that and …

---

## [Substitute GROK by dissect: test of writing](https://discuss.elastic.co/t/substitute-grok-by-dissect-test-of-writing/342930)

<div class="topic-metadata">

**Author:** [@sam1975](https://discuss.elastic.co/u/sam1975)\
**Replies:** 2\
**Last updated:** [September 13, 2023, 12:07pm UTC](https://discuss.elastic.co/t/substitute-grok-by-dissect-test-of-writing/342930 "2023-09-13T12:07:54Z")

</div>

hello, I want to substitute a grok filter by a dissect In a few words, i want replace this grok filter grok { match =\> { "\[raw\_syslog\_result\]\[syslog\_message\]" =\> \[ "THREAT,%{WORD:threat\_type},%{DATA:generate\_time},%…

---

## [Elastic search queue choking](https://discuss.elastic.co/t/elastic-search-queue-choking/342904)

<div class="topic-metadata">

**Author:** [@cosmos\_roeba](https://discuss.elastic.co/u/cosmos_roeba)\
**Replies:** 5\
**Last updated:** [September 13, 2023, 9:52am UTC](https://discuss.elastic.co/t/elastic-search-queue-choking/342904 "2023-09-13T09:52:59Z")

</div>

I am running a 2 node cluster with 2 core cpus. I have 2 indices with about 1 million docs each. They are flat documents and I need to enable search on title key stored both as text and keyword. Search text is minimum 3…

---

## [I cannot search the file name from path in Elasticsearch](https://discuss.elastic.co/t/i-cannot-search-the-file-name-from-path-in-elasticsearch/342812)

<div class="topic-metadata">

**Author:** [@Enes\_Can\_ISIK](https://discuss.elastic.co/u/Enes_Can_ISIK)\
**Replies:** 3\
**Last updated:** [September 13, 2023, 9:48am UTC](https://discuss.elastic.co/t/i-cannot-search-the-file-name-from-path-in-elasticsearch/342812 "2023-09-13T09:48:05Z")

</div>

I want to search filename from a path in Elasticsearch, but I cannot do it. I have documents consisting of "name" fields with paths. Example: Name "folder/folder1/test/folder2/folder/" "folder/folder1/test/folder2/f…

---

## [Doubt about cacerts file of Elasticsearch](https://discuss.elastic.co/t/doubt-about-cacerts-file-of-elasticsearch/342925)

<div class="topic-metadata">

**Author:** [@RdrgPorto](https://discuss.elastic.co/u/RdrgPorto)\
**Replies:** 0\
**Last updated:** [September 13, 2023, 9:18am UTC](https://discuss.elastic.co/t/doubt-about-cacerts-file-of-elasticsearch/342925 "2023-09-13T09:18:34Z")

</div>

Hi, everyone I would like to know the purpose of cacerts file of Elasticsearch (/usr/share/elasticsearch/jdk/lib/security/cacerts). It has some certificates into, are they important? they could be removed? Thanks in a…

---

## [Logstash output to loki](https://discuss.elastic.co/t/logstash-output-to-loki/342910)

<div class="topic-metadata">

**Author:** [@Neelam\_Zanvar](https://discuss.elastic.co/u/Neelam_Zanvar)\
**Replies:** 0\
**Last updated:** [September 13, 2023, 7:04am UTC](https://discuss.elastic.co/t/logstash-output-to-loki/342910 "2023-09-13T07:04:39Z")

</div>

Hi is there any way to send data from logstash to loki or promtial or grafana?

---

## [Kibana status is Yellow due to plugins degraded (after upgrade to version 8.8.2)](https://discuss.elastic.co/t/kibana-status-is-yellow-due-to-plugins-degraded-after-upgrade-to-version-8-8-2/342901)

<div class="topic-metadata">

**Author:** [@chethan\_m](https://discuss.elastic.co/u/chethan_m)\
**Replies:** 1\
**Last updated:** [September 13, 2023, 5:33am UTC](https://discuss.elastic.co/t/kibana-status-is-yellow-due-to-plugins-degraded-after-upgrade-to-version-8-8-2/342901 "2023-09-13T05:33:18Z")

</div>

Hi, I just upgraded elasticseach/ kibana to 8.8.2. Cluster health is Green. But Kibana status is Yellow (when I navigate to http:///status ) What is see is there are lot of plugins in yellow status with the message de…

---

## [What happens if my Elasticsearch cluster has only two nodes with a significant difference in disk storage space?](https://discuss.elastic.co/t/what-happens-if-my-elasticsearch-cluster-has-only-two-nodes-with-a-significant-difference-in-disk-storage-space/342895)

<div class="topic-metadata">

**Author:** [@gaorui](https://discuss.elastic.co/u/gaorui)\
**Replies:** 1\
**Last updated:** [September 13, 2023, 4:06am UTC](https://discuss.elastic.co/t/what-happens-if-my-elasticsearch-cluster-has-only-two-nodes-with-a-significant-difference-in-disk-storage-space/342895 "2023-09-13T04:06:24Z")

</div>

According to the official documentation, when the disk space reaches 85%, replica allocation becomes challenging, at 90% replicas start getting relocated to other nodes (but since I have only two nodes and the principle …

---

## [File input not sending to Elasticsearch](https://discuss.elastic.co/t/file-input-not-sending-to-elasticsearch/342891)

<div class="topic-metadata">

**Author:** [@roman-tasi](https://discuss.elastic.co/u/roman-tasi)\
**Replies:** 0\
**Last updated:** [September 13, 2023, 12:55am UTC](https://discuss.elastic.co/t/file-input-not-sending-to-elasticsearch/342891 "2023-09-13T00:55:05Z")

</div>

Hi I am just wondering if someone could look over these relevant portions of my Logstash config to see if there is an issue: input { file { path =\> "/etc/elasticsearch/scripts/otherScripts/fortune.txt" codec =\>…

[Previous page](https://discuss.elastic.co/tag/none.md?no_tags=true&page=303)

[Next page](https://discuss.elastic.co/tag/none.md?no_tags=true&page=305)
