# \#none

**URL:** https://discuss.elastic.co/tag/none.md?no_tags=true&page=307

[Latest](https://discuss.elastic.co/latest.md) · [Categories](https://discuss.elastic.co/categories.md) · [Tags](https://discuss.elastic.co/tags.md)

**Page:** 308

---

## [Elastic Agent Standalone: Does agent reload when items in inputs.d/ are updated?](https://discuss.elastic.co/t/elastic-agent-standalone-does-agent-reload-when-items-in-inputs-d-are-updated/342621)

<div class="topic-metadata">

**Author:** [@DougR](https://discuss.elastic.co/u/DougR)\
**Replies:** 0\
**Last updated:** [September 8, 2023, 3:08pm UTC](https://discuss.elastic.co/t/elastic-agent-standalone-does-agent-reload-when-items-in-inputs-d-are-updated/342621 "2023-09-08T15:08:42Z")

</div>

A quick question. I'm deploying Elastic Agent standalone to our Kubernetes environment. I am saving the inputs as individual files in input.d/ and would like to mount that directory from a secret, since secrets automatic…

---

## [How to pass NodeSelector in the elasticsearch helm chart?](https://discuss.elastic.co/t/how-to-pass-nodeselector-in-the-elasticsearch-helm-chart/342619)

<div class="topic-metadata">

**Author:** [@Rajat\_Agrawal](https://discuss.elastic.co/u/Rajat_Agrawal)\
**Replies:** 0\
**Last updated:** [September 8, 2023, 3:05pm UTC](https://discuss.elastic.co/t/how-to-pass-nodeselector-in-the-elasticsearch-helm-chart/342619 "2023-09-08T15:05:47Z")

</div>

I am trying to install elasticsearch in Kubernetes and I want to deploy the elasticsearch pod inside a particular node. I am passing below config in yaml file - elasticsearch: enabled: true replicas: 1 minimumMas…

---

## [Granular access to diferent queries in the index](https://discuss.elastic.co/t/granular-access-to-diferent-queries-in-the-index/342615)

<div class="topic-metadata">

**Author:** [@Mihai-CMM](https://discuss.elastic.co/u/Mihai-CMM)\
**Replies:** 2\
**Last updated:** [September 8, 2023, 2:18pm UTC](https://discuss.elastic.co/t/granular-access-to-diferent-queries-in-the-index/342615 "2023-09-08T14:18:14Z")

</div>

Hello all, Can you please help with this question (saw some variants Setup access dashboard per user) but not quite what i want or maybe google did not liked my question enough: I have a VectorDev that sends all k8s l…

---

## [Kibanan 8.9.2. Not loading after upgrade from 8.9.1. because its MIME type ('text/html') is not executable, and strict MIME type checking is enabled](https://discuss.elastic.co/t/kibanan-8-9-2-not-loading-after-upgrade-from-8-9-1-because-its-mime-type-text-html-is-not-executable-and-strict-mime-type-checking-is-enabled/342607)

<div class="topic-metadata">

**Author:** [@deepfusion](https://discuss.elastic.co/u/deepfusion)\
**Replies:** 0\
**Last updated:** [September 8, 2023, 12:23pm UTC](https://discuss.elastic.co/t/kibanan-8-9-2-not-loading-after-upgrade-from-8-9-1-because-its-mime-type-text-html-is-not-executable-and-strict-mime-type-checking-is-enabled/342607 "2023-09-08T12:23:23Z")

</div>

Hi, I have just upgraded on my ubuntu 22.04 server all elastic stack to 8.9.2 from 8.9.1 and now I can no longer log-in because I get these errors: Refused to execute script from 'https://kibana.\*\*\*\*\*\*\*/login?next=%2F6…

---

## [Removing fields from logstash](https://discuss.elastic.co/t/removing-fields-from-logstash/341782)

<div class="topic-metadata">

**Author:** [@bharti](https://discuss.elastic.co/u/bharti)\
**Replies:** 66\
**Last updated:** [September 8, 2023, 11:06am UTC](https://discuss.elastic.co/t/removing-fields-from-logstash/341782 "2023-09-08T11:06:15Z")

</div>

input { file { path =\> "/var/log/abc.log" } beats { port =\> 5044 } } filter { mutate { remove\_field =\> \[ "agent.version.keyword" \] } }

---

## [Logstash output Elastic upsert](https://discuss.elastic.co/t/logstash-output-elastic-upsert/341549)

<div class="topic-metadata">

**Author:** [@mathur7vidit](https://discuss.elastic.co/u/mathur7vidit)\
**Replies:** 6\
**Last updated:** [September 8, 2023, 11:08am UTC](https://discuss.elastic.co/t/logstash-output-elastic-upsert/341549 "2023-09-08T11:08:55Z")

</div>

Hi Team, i am looking for clarity on logstash's Elasticsearch output attribute docs\_as\_upsert and action =\> update. Now for this action to work properly and update the existing document, does the document should be on …

---

## [Is there anyway to run async code before the SyntheticsConfig object in synthetics.config.ts is created?](https://discuss.elastic.co/t/is-there-anyway-to-run-async-code-before-the-syntheticsconfig-object-in-synthetics-config-ts-is-created/341815)

<div class="topic-metadata">

**Author:** [@ameindel](https://discuss.elastic.co/u/ameindel)\
**Replies:** 6\
**Last updated:** [September 8, 2023, 9:19am UTC](https://discuss.elastic.co/t/is-there-anyway-to-run-async-code-before-the-syntheticsconfig-object-in-synthetics-config-ts-is-created/341815 "2023-09-08T09:19:40Z")

</div>

Hello, Elastic! Our company has a home-rolled module that makes calls to AWS Parameter Store to retrieve secrets. I'd like to utilize this module in our Elastic Synthetics project. The usage would be making a call to t…

---

## [Colors on different threshold values](https://discuss.elastic.co/t/colors-on-different-threshold-values/342502)

<div class="topic-metadata">

**Author:** [@Rushi\_Bagul](https://discuss.elastic.co/u/Rushi_Bagul)\
**Replies:** 4\
**Last updated:** [September 8, 2023, 8:50am UTC](https://discuss.elastic.co/t/colors-on-different-threshold-values/342502 "2023-09-08T08:50:09Z")

</div>

We are having one index called resources, which consist of timeseries data i.e. each and every document is having value with timestamp. I want to show this timeseries data in table view with following column: name times…

---

## [ELK index being deleted for a certain period without index lifecycle](https://discuss.elastic.co/t/elk-index-being-deleted-for-a-certain-period-without-index-lifecycle/342189)

<div class="topic-metadata">

**Author:** [@Juan\_Paulo\_Serrano1](https://discuss.elastic.co/u/Juan_Paulo_Serrano1)\
**Replies:** 8\
**Last updated:** [September 8, 2023, 8:38am UTC](https://discuss.elastic.co/t/elk-index-being-deleted-for-a-certain-period-without-index-lifecycle/342189 "2023-09-08T08:38:18Z")

</div>

Hi, I'm having an issue where certain index is being deleted after 28 days, I already removed the lifecycle policy which has 60 days delete phase and it is still being deleted after 28 days. Does anyone has experience on…

---

## [Multi-value lists for elk rule](https://discuss.elastic.co/t/multi-value-lists-for-elk-rule/342579)

<div class="topic-metadata">

**Author:** [@Poukim0m](https://discuss.elastic.co/u/Poukim0m)\
**Replies:** 0\
**Last updated:** [September 8, 2023, 7:16am UTC](https://discuss.elastic.co/t/multi-value-lists-for-elk-rule/342579 "2023-09-08T07:16:27Z")

</div>

Do you know how to implement the functionality of lists (for the purpose of exclusion/whitelisting) that contain multiple (two or more) fields (values) in each entry? For example i need to have a list with the combinati…

---

## [Can synonym analyzer or Fuzzy queries return the token that it got matched to from document?](https://discuss.elastic.co/t/can-synonym-analyzer-or-fuzzy-queries-return-the-token-that-it-got-matched-to-from-document/342575)

<div class="topic-metadata">

**Author:** [@aashini](https://discuss.elastic.co/u/aashini)\
**Replies:** 0\
**Last updated:** [September 8, 2023, 6:22am UTC](https://discuss.elastic.co/t/can-synonym-analyzer-or-fuzzy-queries-return-the-token-that-it-got-matched-to-from-document/342575 "2023-09-08T06:22:38Z")

</div>

I am using search-time synonyms in my Index. I am also using fuzzy queries to correct the spelling mistakes of user input in making search. For example, My Index has a field named Trade which can have value "Plumbing". …

---

## [Outputing Logstash logs to Elastic Index fails](https://discuss.elastic.co/t/outputing-logstash-logs-to-elastic-index-fails/341774)

<div class="topic-metadata">

**Author:** [@aashini](https://discuss.elastic.co/u/aashini)\
**Replies:** 4\
**Last updated:** [September 8, 2023, 5:41am UTC](https://discuss.elastic.co/t/outputing-logstash-logs-to-elastic-index-fails/341774 "2023-09-08T05:41:55Z")

</div>

I am using Logstash version 7.11 and and trying to output logs from logstash pipeline to Elastic version 8.\*. I am using hosts, index, api\_key, ssl and action params with ssl =\> true and action =\> "create" . output { …

---

## [Receiving messages from remote syslog using logstash](https://discuss.elastic.co/t/receiving-messages-from-remote-syslog-using-logstash/342559)

<div class="topic-metadata">

**Author:** [@d14](https://discuss.elastic.co/u/d14)\
**Replies:** 0\
**Last updated:** [September 8, 2023, 1:47am UTC](https://discuss.elastic.co/t/receiving-messages-from-remote-syslog-using-logstash/342559 "2023-09-08T01:47:47Z")

</div>

I am trying to receive data from a remote syslog server using logstash and the syslog input plugin but unsure how it works. I have a custom domain I want to use for this communication, do I use the custom IP/domain in t…

---

## [Has anyone come up with a maintainable way to set index.number\_of\_replicas cluster wide?](https://discuss.elastic.co/t/has-anyone-come-up-with-a-maintainable-way-to-set-index-number-of-replicas-cluster-wide/341288)

<div class="topic-metadata">

**Author:** [@jerrac](https://discuss.elastic.co/u/jerrac)\
**Replies:** 7\
**Last updated:** [September 7, 2023, 11:09pm UTC](https://discuss.elastic.co/t/has-anyone-come-up-with-a-maintainable-way-to-set-index-number-of-replicas-cluster-wide/341288 "2023-09-07T23:09:03Z")

</div>

Thanks to budget issues, I'm trying to slim down the footprint of my Elastic stack. While not ideal, running in single-node mode would make things easier to manage. But, as far as I can tell, Elastic Agent creates ever…

---

## [Disable geo lookup in logstash](https://discuss.elastic.co/t/disable-geo-lookup-in-logstash/342557)

<div class="topic-metadata">

**Author:** [@trwillis](https://discuss.elastic.co/u/trwillis)\
**Replies:** 1\
**Last updated:** [September 7, 2023, 10:57pm UTC](https://discuss.elastic.co/t/disable-geo-lookup-in-logstash/342557 "2023-09-07T22:57:39Z")

</div>

I am parsing firewall logs and I don't want logstash to try and do geo parsing. My firewall logs already have the geo information. How can I disable geo parsing so I stop getting \_geoip\_lookup\_failure?

---

## [Ingest dns queries into elk from dozens of bind9 server](https://discuss.elastic.co/t/ingest-dns-queries-into-elk-from-dozens-of-bind9-server/342546)

<div class="topic-metadata">

**Author:** [@Poubelle\_Dirty](https://discuss.elastic.co/u/Poubelle_Dirty)\
**Replies:** 0\
**Last updated:** [September 7, 2023, 7:20pm UTC](https://discuss.elastic.co/t/ingest-dns-queries-into-elk-from-dozens-of-bind9-server/342546 "2023-09-07T19:20:09Z")

</div>

Hello everyone. I'm looking for the best way (if there is !) for ingesting dns queries from bind9 servers. The environment is composed of about 15 "cluster" of dns servers (1 master and 3 slaves per cluster) that are a…

---

## [Delete old back indexes from alias](https://discuss.elastic.co/t/delete-old-back-indexes-from-alias/342439)

<div class="topic-metadata">

**Author:** [@kmz161](https://discuss.elastic.co/u/kmz161)\
**Replies:** 11\
**Last updated:** [September 7, 2023, 5:32pm UTC](https://discuss.elastic.co/t/delete-old-back-indexes-from-alias/342439 "2023-09-07T17:32:45Z")

</div>

Hello! I use data streams for store data. And I have data stream alias. How I can automatically delete back indexes older 7 days from alias?

---

## [Alert Rule Not showing on Secuirty Dashboard but is rule is active and creating alerts](https://discuss.elastic.co/t/alert-rule-not-showing-on-secuirty-dashboard-but-is-rule-is-active-and-creating-alerts/342504)

<div class="topic-metadata">

**Author:** [@geekzy](https://discuss.elastic.co/u/geekzy)\
**Replies:** 1\
**Last updated:** [September 7, 2023, 3:13pm UTC](https://discuss.elastic.co/t/alert-rule-not-showing-on-secuirty-dashboard-but-is-rule-is-active-and-creating-alerts/342504 "2023-09-07T15:13:10Z")

</div>

We have been experiencing some on going issues since we have upgraded to 8.9.1 from 7.17.11. Primarily all our issues have been with Kibana's Security SIEM. There are two main issues that we have been experiencing: Ce…

---

## [Limited score precision for a big score hierarchy](https://discuss.elastic.co/t/limited-score-precision-for-a-big-score-hierarchy/340759)

<div class="topic-metadata">

**Author:** [@Grisha](https://discuss.elastic.co/u/Grisha)\
**Replies:** 14\
**Last updated:** [September 7, 2023, 3:02pm UTC](https://discuss.elastic.co/t/limited-score-precision-for-a-big-score-hierarchy/340759 "2023-09-07T15:02:20Z")

</div>

Hi, I'm trying to implement a kind of score hierarchy using different boosts for different fields (there are multiple fields and type of search (full match, fuzzy, etc.)). Simplified example of boosts: field\_1 fuzzy b…

---

## [JSON Parsing issue with elasticsearch ingest pipeline](https://discuss.elastic.co/t/json-parsing-issue-with-elasticsearch-ingest-pipeline/342519)

<div class="topic-metadata">

**Author:** [@Jobin\_James](https://discuss.elastic.co/u/Jobin_James)\
**Replies:** 4\
**Last updated:** [September 7, 2023, 1:51pm UTC](https://discuss.elastic.co/t/json-parsing-issue-with-elasticsearch-ingest-pipeline/342519 "2023-09-07T13:51:55Z")

</div>

Hello, I am building an Elasticsearch cluster to aggregate and monitor application logs. I am using ECK for deploying and managing the cluster in k8s and fleet-managed elastic agent deployed across multiple clusters to …

---

## [Question elk](https://discuss.elastic.co/t/question-elk/342529)

<div class="topic-metadata">

**Author:** [@Farah\_Bannour](https://discuss.elastic.co/u/Farah_Bannour)\
**Replies:** 0\
**Last updated:** [September 7, 2023, 1:49pm UTC](https://discuss.elastic.co/t/question-elk/342529 "2023-09-07T13:49:46Z")

</div>

Bonjour ,je voulais dans cette cas supprimer seulement la premier numero comme par exemple ici "create\_uid" : \[ 1, "Support" \], je voudrais supprimer 1 dans le champs create\_uid comment je peux faire ca

---

## [Watcher to send email alerts when Windows Defender detects malware](https://discuss.elastic.co/t/watcher-to-send-email-alerts-when-windows-defender-detects-malware/342528)

<div class="topic-metadata">

**Author:** [@RJC](https://discuss.elastic.co/u/RJC)\
**Replies:** 0\
**Last updated:** [September 7, 2023, 1:28pm UTC](https://discuss.elastic.co/t/watcher-to-send-email-alerts-when-windows-defender-detects-malware/342528 "2023-09-07T13:28:47Z")

</div>

I created a Watcher in Kibana to send email notification when malware is detected on one of the monitored hosts. Maleware detection event has a Windows Event Log ID 1116 and it is generated by Winlog channel "Microsoft-…

---

## [LABs logs not coming through](https://discuss.elastic.co/t/labs-logs-not-coming-through/342524)

<div class="topic-metadata">

**Author:** [@Renata](https://discuss.elastic.co/u/Renata)\
**Replies:** 0\
**Last updated:** [September 7, 2023, 12:39pm UTC](https://discuss.elastic.co/t/labs-logs-not-coming-through/342524 "2023-09-07T12:39:01Z")

</div>

Course: Elastic Observability Engineer (On-Demand) Version: 8.2 Question: Something not working properly with Logs for mysql (either sporadic, or not generated at all) Generally I am in 5.4. LABs section to test out a…

---

## [How does cluster.auto\_shrink\_voting\_configuration prevent split brain?](https://discuss.elastic.co/t/how-does-cluster-auto-shrink-voting-configuration-prevent-split-brain/342418)

<div class="topic-metadata">

**Author:** [@etki](https://discuss.elastic.co/u/etki)\
**Replies:** 9\
**Last updated:** [September 7, 2023, 11:31am UTC](https://discuss.elastic.co/t/how-does-cluster-auto-shrink-voting-configuration-prevent-split-brain/342418 "2023-09-07T11:31:15Z")

</div>

We have some docs telling that it's not possible, but they don't explain much, just stating some things. How is the following situation avoided? A cluster has voting configuration of 5 nodes. A network partition occurs…

---

## [Install Elastic Search](https://discuss.elastic.co/t/install-elastic-search/342320)

<div class="topic-metadata">

**Author:** [@Debasis\_Mallick](https://discuss.elastic.co/u/Debasis_Mallick)\
**Replies:** 14\
**Last updated:** [September 7, 2023, 11:39am UTC](https://discuss.elastic.co/t/install-elastic-search/342320 "2023-09-07T11:39:54Z")

</div>

Hi Team, I had a requirement to create elasticsearch cluster with three nodes . I had install the elasticsearch binaries on these three nodes individually and updated the elasticsearch.yml file with node information bu…

---

## [IP match failed](https://discuss.elastic.co/t/ip-match-failed/342475)

<div class="topic-metadata">

**Author:** [@javierelastic](https://discuss.elastic.co/u/javierelastic)\
**Replies:** 4\
**Last updated:** [September 7, 2023, 11:27am UTC](https://discuss.elastic.co/t/ip-match-failed/342475 "2023-09-07T11:27:38Z")

</div>

Hi everyone! Something strange happens to me. I'm trying to see if a source ip matches a pattern I indicate. The ip is 100.44.1.128 and it tells me that it matches "^10.\*" How is it possible? if \[IPorigen\] =~ "^10.\*"…

---

## [Where are memories go?](https://discuss.elastic.co/t/where-are-memories-go/342338)

<div class="topic-metadata">

**Author:** [@huajun\_qi](https://discuss.elastic.co/u/huajun_qi)\
**Replies:** 3\
**Last updated:** [September 7, 2023, 9:42am UTC](https://discuss.elastic.co/t/where-are-memories-go/342338 "2023-09-07T09:42:44Z")

</div>

Our clients encountered errors below recently when performing index and query requests: org.elasticsearch.client.ResponseException: org.elasticsearch.client.ResponseException: method \[POST\], host \[http://192.168.12.171:…

---

## [Alternative grok with API](https://discuss.elastic.co/t/alternative-grok-with-api/342265)

<div class="topic-metadata">

**Author:** [@sam1975](https://discuss.elastic.co/u/sam1975)\
**Replies:** 3\
**Last updated:** [September 7, 2023, 9:11am UTC](https://discuss.elastic.co/t/alternative-grok-with-api/342265 "2023-09-07T09:11:30Z")

</div>

Hello, I've some pipeline which use grok to parse logs and apply some modifications. As i collect in input data from Elastic index, make some modifications and send it directly data transformed in an Elastic index, is …

---

## [Logstash 8.9.0](https://discuss.elastic.co/t/logstash-8-9-0/342362)

<div class="topic-metadata">

**Author:** [@ranjini](https://discuss.elastic.co/u/ranjini)\
**Replies:** 2\
**Last updated:** [September 7, 2023, 8:53am UTC](https://discuss.elastic.co/t/logstash-8-9-0/342362 "2023-09-07T08:53:59Z")

</div>

Please help me. I m running logstash 8.9.0. I recieve the below error in the pod logs. \[2023-09-05T16:25:32,904\]\[ERROR\]\[logstash.javapipeline \]\[main\]\[d9383b2c5e755b975c5f06446fd24ec66c0265c309ed53bd78ed6e05939579ec\] …

---

## [Count only sum value of ID on their last date](https://discuss.elastic.co/t/count-only-sum-value-of-id-on-their-last-date/342227)

<div class="topic-metadata">

**Author:** [@Guillaume\_V](https://discuss.elastic.co/u/Guillaume_V)\
**Replies:** 6\
**Last updated:** [September 7, 2023, 8:23am UTC](https://discuss.elastic.co/t/count-only-sum-value-of-id-on-their-last-date/342227 "2023-09-07T08:23:27Z")

</div>

Hi, I have a problem i would like to share you. This is my data And my table in Dashboard look like this : Level descending | Count 1 | 4 0 …

[Previous page](https://discuss.elastic.co/tag/none.md?no_tags=true&page=306)

[Next page](https://discuss.elastic.co/tag/none.md?no_tags=true&page=308)
