# \#none

**URL:** https://discuss.elastic.co/tag/none.md?no_tags=true&page=305

[Latest](https://discuss.elastic.co/latest.md) · [Categories](https://discuss.elastic.co/categories.md) · [Tags](https://discuss.elastic.co/tags.md)

**Page:** 306

---

## [Filebeat processor not doing anything](https://discuss.elastic.co/t/filebeat-processor-not-doing-anything/342890)

<div class="topic-metadata">

**Author:** [@artschooldropout](https://discuss.elastic.co/u/artschooldropout)\
**Replies:** 4\
**Last updated:** [September 12, 2023, 11:11pm UTC](https://discuss.elastic.co/t/filebeat-processor-not-doing-anything/342890 "2023-09-12T23:11:49Z")

</div>

I'm trying to use a processor to split up syslog messages into separate fields (using the '=' character as a delimiter). Here's my processor: - type: syslog format: auto protocol.udp: host: "0.0.0.0:9002" tags…

---

## [Syslog to BigQuery help](https://discuss.elastic.co/t/syslog-to-bigquery-help/342816)

<div class="topic-metadata">

**Author:** [@Russ\_Starr](https://discuss.elastic.co/u/Russ_Starr)\
**Replies:** 1\
**Last updated:** [September 12, 2023, 8:53pm UTC](https://discuss.elastic.co/t/syslog-to-bigquery-help/342816 "2023-09-12T20:53:04Z")

</div>

Hi, I am new to logstash and I've been doing some reading and grok debugging. My goal is really simple. I have a Linux box with logstash and I want to receive syslog messages from all my systems and forward them to Googl…

---

## [Error: ElasticSearch won't start when downgraded from 8.9.2 to 8.4.1](https://discuss.elastic.co/t/error-elasticsearch-wont-start-when-downgraded-from-8-9-2-to-8-4-1/342879)

<div class="topic-metadata">

**Author:** [@ujosyula](https://discuss.elastic.co/u/ujosyula)\
**Replies:** 8\
**Last updated:** [September 12, 2023, 8:52pm UTC](https://discuss.elastic.co/t/error-elasticsearch-wont-start-when-downgraded-from-8-9-2-to-8-4-1/342879 "2023-09-12T20:52:35Z")

</div>

I see this error when I try to downgrade. The version of elasticsearch is 8.4.1, but the service won't start. \[2023-09-12T09:52:39,253\]\[ERROR\]\[o.e.b.Elasticsearch \] fatal exception while booting Elasticsearch j…

---

## [How extract a value from grock pattern in a new field](https://discuss.elastic.co/t/how-extract-a-value-from-grock-pattern-in-a-new-field/342855)

<div class="topic-metadata">

**Author:** [@Amani188](https://discuss.elastic.co/u/Amani188)\
**Replies:** 1\
**Last updated:** [September 12, 2023, 7:38pm UTC](https://discuss.elastic.co/t/how-extract-a-value-from-grock-pattern-in-a-new-field/342855 "2023-09-12T19:38:10Z")

</div>

Hi, I'm trying to create new field called Systeme from a grock pattern whitch match the value of Systeme but it's always empty does anyone have an idea about how to do that. I'm using ingest pipeline like this: "gro…

---

## [Elastic Defend - Credential Harderning](https://discuss.elastic.co/t/elastic-defend-credential-harderning/342858)

<div class="topic-metadata">

**Author:** [@slash24](https://discuss.elastic.co/u/slash24)\
**Replies:** 1\
**Last updated:** [September 12, 2023, 6:29pm UTC](https://discuss.elastic.co/t/elastic-defend-credential-harderning/342858 "2023-09-12T18:29:07Z")

</div>

What does the "Credential hardening"-setting in Elastic Defend-integration do for Windows-endpoints when active? Does it simply set the RunasPPL registry key? We have thirdparty components involved in authentication an…

---

## [Issue creating case from Dev Panel](https://discuss.elastic.co/t/issue-creating-case-from-dev-panel/341718)

<div class="topic-metadata">

**Author:** [@AceVla](https://discuss.elastic.co/u/AceVla)\
**Replies:** 16\
**Last updated:** [September 12, 2023, 6:19pm UTC](https://discuss.elastic.co/t/issue-creating-case-from-dev-panel/341718 "2023-09-12T18:19:08Z")

</div>

We are creating a case in the dev panel in Elastic, here is the code: POST api/cases { "description": "A case description.", "title": "Case title 1", "tags": \[ "tag 1" \], "connector": { "id": "none", "na…

---

## [Metricbeat unable to insert data after upgrade from 7 to 8](https://discuss.elastic.co/t/metricbeat-unable-to-insert-data-after-upgrade-from-7-to-8/342859)

<div class="topic-metadata">

**Author:** [@Claude\_Brassel](https://discuss.elastic.co/u/Claude_Brassel)\
**Replies:** 0\
**Last updated:** [September 12, 2023, 2:52pm UTC](https://discuss.elastic.co/t/metricbeat-unable-to-insert-data-after-upgrade-from-7-to-8/342859 "2023-09-12T14:52:24Z")

</div>

Hello, I have upgraded my elk cluster from 7.17 to 8.10, everything is fine but metricbeat seem's unable to insert new data : (status=403): {"type":"security\_exception","reason":"action \[indices:admin/mapping/auto\_put\]…

---

## [Calculate the size of logs in a specific time period](https://discuss.elastic.co/t/calculate-the-size-of-logs-in-a-specific-time-period/342845)

<div class="topic-metadata">

**Author:** [@nickmannouch](https://discuss.elastic.co/u/nickmannouch)\
**Replies:** 1\
**Last updated:** [September 12, 2023, 2:47pm UTC](https://discuss.elastic.co/t/calculate-the-size-of-logs-in-a-specific-time-period/342845 "2023-09-12T14:47:05Z")

</div>

Hi, We can see that in a specific 12 hour period, we have 1.3 million log entries. We want to see how much disk space was consumed by this. We thought we could just add 'bytes' as a metric to the graph. However, bytes …

---

## [Backup policy](https://discuss.elastic.co/t/backup-policy/342853)

<div class="topic-metadata">

**Author:** [@sravanth\_cabbu](https://discuss.elastic.co/u/sravanth_cabbu)\
**Replies:** 0\
**Last updated:** [September 12, 2023, 2:39pm UTC](https://discuss.elastic.co/t/backup-policy/342853 "2023-09-12T14:39:34Z")

</div>

Hi Team, We are upgrading RHEL7 to 8 and installed ES. We have NAS mount in place and restored all indices. So in the process of cutover from rhel 7 to 8, we have to add the backup policy to rhel 8 for snapshot. we have…

---

## [Reading new data from elastic using logstash to rabbitMQ](https://discuss.elastic.co/t/reading-new-data-from-elastic-using-logstash-to-rabbitmq/342844)

<div class="topic-metadata">

**Author:** [@Shay\_Hershko](https://discuss.elastic.co/u/Shay_Hershko)\
**Replies:** 0\
**Last updated:** [September 12, 2023, 1:51pm UTC](https://discuss.elastic.co/t/reading-new-data-from-elastic-using-logstash-to-rabbitmq/342844 "2023-09-12T13:51:59Z")

</div>

Hi, I want to send every new data entered to index in elastic to a RabbitMQ queue every second. I tried using logstash for it but for some reason it send all the data and not just the new one. I saw you can use time st…

---

## [Input jdbc error handling](https://discuss.elastic.co/t/input-jdbc-error-handling/342836)

<div class="topic-metadata">

**Author:** [@inbeom\_cho](https://discuss.elastic.co/u/inbeom_cho)\
**Replies:** 0\
**Last updated:** [September 12, 2023, 1:03pm UTC](https://discuss.elastic.co/t/input-jdbc-error-handling/342836 "2023-09-12T13:03:16Z")

</div>

hi all this is my input jdbc input { jdbc { jdbc\_driver\_library =\> "/usr/share/java/postgresql.jar" jdbc\_driver\_class =\> "org.postgresql.Driver" jdbc\_connection\_string =\> "jdbc:postgresql://\*.\*.\*.\*/databa…

---

## [Stack monitoring not visible in Kibana UI 8.8.2 version](https://discuss.elastic.co/t/stack-monitoring-not-visible-in-kibana-ui-8-8-2-version/342831)

<div class="topic-metadata">

**Author:** [@PRASHANT\_MEHTA](https://discuss.elastic.co/u/PRASHANT_MEHTA)\
**Replies:** 1\
**Last updated:** [September 12, 2023, 12:31pm UTC](https://discuss.elastic.co/t/stack-monitoring-not-visible-in-kibana-ui-8-8-2-version/342831 "2023-09-12T12:31:55Z")

</div>

Hello All, I am using Enterprise license of kibana and migrated from 7.9.1 to 8.8.2 version. Earlier it used to show STACK MONITORING OPTION in kibana now its not showing in 8.8.2 version. How to enable? , I tried belo…

---

## [After upgrading logstash to version 8.9.1, it disconnects from the DB2 database after a few days](https://discuss.elastic.co/t/after-upgrading-logstash-to-version-8-9-1-it-disconnects-from-the-db2-database-after-a-few-days/342830)

<div class="topic-metadata">

**Author:** [@Lukas\_Hrcka](https://discuss.elastic.co/u/Lukas_Hrcka)\
**Replies:** 0\
**Last updated:** [September 12, 2023, 12:20pm UTC](https://discuss.elastic.co/t/after-upgrading-logstash-to-version-8-9-1-it-disconnects-from-the-db2-database-after-a-few-days/342830 "2023-09-12T12:20:33Z")

</div>

Hello, after upgrading logstash to version 8.9.1 from 7.17.x, I have problems with the automatic loss of connection to the DB2 database (DB2 ver. 11.5 Mod 7). The previous version of ELK 7.17.x had no problem, the conne…

---

## [Comparison of data at a kibana dashboard](https://discuss.elastic.co/t/comparison-of-data-at-a-kibana-dashboard/342805)

<div class="topic-metadata">

**Author:** [@Voula\_Mikr](https://discuss.elastic.co/u/Voula_Mikr)\
**Replies:** 1\
**Last updated:** [September 12, 2023, 12:09pm UTC](https://discuss.elastic.co/t/comparison-of-data-at-a-kibana-dashboard/342805 "2023-09-12T12:09:37Z")

</div>

Hi , I have the below kind of data counter1: { "name":"name1", "vnf\_type":"ZTS", "counter":"cpu", "value":"10", "event\_time\_stamp":"2021-02-15T02:44:19Z" } I would like to compare the value "value" of t…

---

## [Rolling restart triggers primary-replica resync leading to write unavailability](https://discuss.elastic.co/t/rolling-restart-triggers-primary-replica-resync-leading-to-write-unavailability/339301)

<div class="topic-metadata">

**Author:** [@devoxel](https://discuss.elastic.co/u/devoxel)\
**Replies:** 10\
**Last updated:** [September 12, 2023, 10:54am UTC](https://discuss.elastic.co/t/rolling-restart-triggers-primary-replica-resync-leading-to-write-unavailability/339301 "2023-09-12T10:54:13Z")

</div>

When a node is shutdown during a normal rolling restart, we end up in a loss of write availability for a period of 10 mins. We're using ECK operator to manage the cluster. It's 7.17 and the operator is the latest versio…

---

## [Custom Machine Learning Model on Elastic Security](https://discuss.elastic.co/t/custom-machine-learning-model-on-elastic-security/341862)

<div class="topic-metadata">

**Author:** [@xynobob](https://discuss.elastic.co/u/xynobob)\
**Replies:** 3\
**Last updated:** [September 12, 2023, 10:38am UTC](https://discuss.elastic.co/t/custom-machine-learning-model-on-elastic-security/341862 "2023-09-12T10:38:52Z")

</div>

Hi, I am doing a small side project and this is my first time diving into Elastic Security. Read several documentations, however it doesn't clarify my doubt, so am asking here instead. So my question is - Is it possible…

---

## [Use new dataview in an existing dashboard](https://discuss.elastic.co/t/use-new-dataview-in-an-existing-dashboard/342656)

<div class="topic-metadata">

**Author:** [@javierelastic](https://discuss.elastic.co/u/javierelastic)\
**Replies:** 2\
**Last updated:** [September 12, 2023, 9:38am UTC](https://discuss.elastic.co/t/use-new-dataview-in-an-existing-dashboard/342656 "2023-09-12T09:38:25Z")

</div>

Hi. I have a dashboard created with a set of data that I passed through logstash to elasticsearch. But now I have created a new index and a new dataview with similar data. And I want to use the complete dashboard with t…

---

## [Failed to fetch https://artifacts.elastic.co/packages/7.x/apt/dists/stable/InRelease 403 Forbidden \[IP: 2600:1901:0:1d7:: 443\]](https://discuss.elastic.co/t/failed-to-fetch-https-artifacts-elastic-co-packages-7-x-apt-dists-stable-inrelease-403-forbidden-ip-26000-443/341442)

<div class="topic-metadata">

**Author:** [@Andi0r](https://discuss.elastic.co/u/Andi0r)\
**Replies:** 8\
**Last updated:** [September 12, 2023, 9:35am UTC](https://discuss.elastic.co/t/failed-to-fetch-https-artifacts-elastic-co-packages-7-x-apt-dists-stable-inrelease-403-forbidden-ip-26000-443/341442 "2023-09-12T09:35:06Z")

</div>

Hi, i am trying to install Elastic Search but i am getting the error: Failed to fetch https://artifacts.elastic.co/packages/7.x/apt/dists/stable/InRelease 403 Forbidden \[IP: 2600:1901:0:1d7:: 443\] Could it be that y…

---

## [Is Is watcher is free in elastic search? if paid than what is the cost?](https://discuss.elastic.co/t/is-is-watcher-is-free-in-elastic-search-if-paid-than-what-is-the-cost/342785)

<div class="topic-metadata">

**Author:** [@jaimika\_kosambia](https://discuss.elastic.co/u/jaimika_kosambia)\
**Replies:** 1\
**Last updated:** [September 12, 2023, 9:05am UTC](https://discuss.elastic.co/t/is-is-watcher-is-free-in-elastic-search-if-paid-than-what-is-the-cost/342785 "2023-09-12T09:05:03Z")

</div>

Is watcher is free in Elasticsearch? if paid than what is the cost?

---

## [I need to use search\_after sort by \_score and \_id in a rescore query](https://discuss.elastic.co/t/i-need-to-use-search-after-sort-by-score-and-id-in-a-rescore-query/342789)

<div class="topic-metadata">

**Author:** [@George\_Githinji](https://discuss.elastic.co/u/George_Githinji)\
**Replies:** 0\
**Last updated:** [September 12, 2023, 8:20am UTC](https://discuss.elastic.co/t/i-need-to-use-search-after-sort-by-score-and-id-in-a-rescore-query/342789 "2023-09-12T08:20:03Z")

</div>

I want to implement the search\_after pagination technique, I want to sort out the data using \_score and \_id. The problem I am facing is that I have built my query using rescore and you can't use the sort and rescore at t…

---

## [Which Rule Type is Better to Monitor the data streams and raise an alert](https://discuss.elastic.co/t/which-rule-type-is-better-to-monitor-the-data-streams-and-raise-an-alert/342561)

<div class="topic-metadata">

**Author:** [@vinay.bommarati](https://discuss.elastic.co/u/vinay.bommarati)\
**Replies:** 4\
**Last updated:** [September 12, 2023, 8:28am UTC](https://discuss.elastic.co/t/which-rule-type-is-better-to-monitor-the-data-streams-and-raise-an-alert/342561 "2023-09-12T08:28:12Z")

</div>

Hi Team , we are exploring elastic observability. At the moment , using logstash pipelines as intermediary , we are able to push our logs from different applications to central elastic. Every application logs go into…

---

## [Generating term vectors on the fly](https://discuss.elastic.co/t/generating-term-vectors-on-the-fly/342784)

<div class="topic-metadata">

**Author:** [@d\_u](https://discuss.elastic.co/u/d_u)\
**Replies:** 0\
**Last updated:** [September 12, 2023, 6:47am UTC](https://discuss.elastic.co/t/generating-term-vectors-on-the-fly/342784 "2023-09-12T06:47:54Z")

</div>

Suppose, I have more than 1mil documents where I have a text field lets say "Contents". We have not enabled termvector for the index. Now when we want to find count of occurrence of a word lets say "data" in "Contents" …

---

## [Change text mapping from text to integer](https://discuss.elastic.co/t/change-text-mapping-from-text-to-integer/342484)

<div class="topic-metadata">

**Author:** [@Geeboy](https://discuss.elastic.co/u/Geeboy)\
**Replies:** 4\
**Last updated:** [September 12, 2023, 3:21am UTC](https://discuss.elastic.co/t/change-text-mapping-from-text-to-integer/342484 "2023-09-12T03:21:08Z")

</div>

Good day! Im creating new index, when I add this to "data views", it was tagged as TEXT type. I need it to be integer. do you have step by step guide for this case? my temporary solution is this command -\> emit (Intege…

---

## [File /run/elastic-agent.sock no such file and directory when i finished installing the agent on linux](https://discuss.elastic.co/t/file-run-elastic-agent-sock-no-such-file-and-directory-when-i-finished-installing-the-agent-on-linux/342775)

<div class="topic-metadata">

**Author:** [@Yanuar\_Ahmad\_Adhari](https://discuss.elastic.co/u/Yanuar_Ahmad_Adhari)\
**Replies:** 0\
**Last updated:** [September 12, 2023, 3:15am UTC](https://discuss.elastic.co/t/file-run-elastic-agent-sock-no-such-file-and-directory-when-i-finished-installing-the-agent-on-linux/342775 "2023-09-12T03:15:48Z")

</div>

Error: failed to communicate with Elastic Agent daemon: rpc error: code = Unavailable desc = connection error: desc = "transport: Error while dialing dial unix /run/elastic-agent.sock: connect: no such file or directory"…

---

## [Grok patterns for nginx](https://discuss.elastic.co/t/grok-patterns-for-nginx/342692)

<div class="topic-metadata">

**Author:** [@vanhaiit90](https://discuss.elastic.co/u/vanhaiit90)\
**Replies:** 1\
**Last updated:** [September 11, 2023, 3:24am UTC](https://discuss.elastic.co/t/grok-patterns-for-nginx/342692 "2023-09-11T03:24:40Z")

</div>

Today I have text log format about nginx\_access {"timestamp": "2023-09-07T03:03:33+00:00", "remote\_addr": "10.0.x.x", "remote\_user": "-", "request\_time": "0.002 s", "status\_request": "200", "request\_Size": "510", "requ…

---

## [GET api by doc\_id returns different result whenever i try](https://discuss.elastic.co/t/get-api-by-doc-id-returns-different-result-whenever-i-try/342293)

<div class="topic-metadata">

**Author:** [@ycice](https://discuss.elastic.co/u/ycice)\
**Replies:** 7\
**Last updated:** [September 12, 2023, 1:53am UTC](https://discuss.elastic.co/t/get-api-by-doc-id-returns-different-result-whenever-i-try/342293 "2023-09-12T01:53:49Z")

</div>

Hi, i manage more than 100 ES clusters in my company for 3 years But at last week, I faced very strange issue. I think it is not possible... Could you carefully check this? ES version : 6.8.2 Cluster health : Green G…

---

## [Kind:Elasticsearch Kind:Kibana not creating any nodes in K8s why?](https://discuss.elastic.co/t/kind-elasticsearch-kind-kibana-not-creating-any-nodes-in-k8s-why/342758)

<div class="topic-metadata">

**Author:** [@Esakki](https://discuss.elastic.co/u/Esakki)\
**Replies:** 1\
**Last updated:** [September 11, 2023, 5:32pm UTC](https://discuss.elastic.co/t/kind-elasticsearch-kind-kibana-not-creating-any-nodes-in-k8s-why/342758 "2023-09-11T17:32:12Z")

</div>

Hi All, I had elasticsearch and kibana deployed in my on-prem K8s cluster, due to some config issue I deleted both deployments (I deployed, deployments, svc, and secrets) in my cluster and trying to re-deploy but it's n…

---

## [Netflow gigamon - Flowset id error](https://discuss.elastic.co/t/netflow-gigamon-flowset-id-error/342747)

<div class="topic-metadata">

**Author:** [@SilasMuniz1](https://discuss.elastic.co/u/SilasMuniz1)\
**Replies:** 0\
**Last updated:** [September 11, 2023, 2:40pm UTC](https://discuss.elastic.co/t/netflow-gigamon-flowset-id-error/342747 "2023-09-11T14:40:42Z")

</div>

Hi everybody. I still have a problem about neflow gigamon. I used netflow codec for parsing logs received from gigamon however I continuous received flowset error. My logstash is 8.4.3 version. Netflow codec versio…

---

## [Kibana :Invalid string. Length must be a multiple of 4](https://discuss.elastic.co/t/kibana-invalid-string-length-must-be-a-multiple-of-4/342685)

<div class="topic-metadata">

**Author:** [@Amani188](https://discuss.elastic.co/u/Amani188)\
**Replies:** 2\
**Last updated:** [September 11, 2023, 1:21pm UTC](https://discuss.elastic.co/t/kibana-invalid-string-length-must-be-a-multiple-of-4/342685 "2023-09-11T13:21:54Z")

</div>

Hi everyone, I'm trying to load data through kibana but i had this error message below : The response message shows internal server error

---

## [Aggregate - Output issues](https://discuss.elastic.co/t/aggregate-output-issues/342536)

<div class="topic-metadata">

**Author:** [@vymk](https://discuss.elastic.co/u/vymk)\
**Replies:** 1\
**Last updated:** [September 11, 2023, 11:34am UTC](https://discuss.elastic.co/t/aggregate-output-issues/342536 "2023-09-11T11:34:44Z")

</div>

I asked for some aggregation code a while ago (Help with aggregation code) and now finally had the time to get back at this (and changed the output concept a bit). So I want to aggregate data from multiple documents with…

[Previous page](https://discuss.elastic.co/tag/none.md?no_tags=true&page=304)

[Next page](https://discuss.elastic.co/tag/none.md?no_tags=true&page=306)
