# \#none

**URL:** https://discuss.elastic.co/tag/none.md?no_tags=true&page=309

[Latest](https://discuss.elastic.co/latest.md) · [Categories](https://discuss.elastic.co/categories.md) · [Tags](https://discuss.elastic.co/tags.md)

**Page:** 310

---

## [Filebeat to analyze xml logs](https://discuss.elastic.co/t/filebeat-to-analyze-xml-logs/342305)

<div class="topic-metadata">

**Author:** [@Ted0011](https://discuss.elastic.co/u/Ted0011)\
**Replies:** 8\
**Last updated:** [September 6, 2023, 3:53am UTC](https://discuss.elastic.co/t/filebeat-to-analyze-xml-logs/342305 "2023-09-06T03:53:56Z")

</div>

Hello Its Suman Ghorashine I am new to wazuh and ELK stack. And I wanted to know some certain things. I have a xml log format set to wazuh server for analysis from agent configuration file. But when filtering the logs …

---

## [Advanced Watch](https://discuss.elastic.co/t/advanced-watch/338906)

<div class="topic-metadata">

**Author:** [@Kumar\_Abhinav](https://discuss.elastic.co/u/Kumar_Abhinav)\
**Replies:** 7\
**Last updated:** [September 5, 2023, 9:30pm UTC](https://discuss.elastic.co/t/advanced-watch/338906 "2023-09-05T21:30:01Z")

</div>

Hi, I am using ELK in Supply Chain Traceability Company. 1 -- I wanted to create a Watcher to send "Alerts" from Kibana for the inventory items and it should be continuous alerts through email notification. Suppose a…

---

## [Cisco filebeat module not listening on port as configured](https://discuss.elastic.co/t/cisco-filebeat-module-not-listening-on-port-as-configured/341988)

<div class="topic-metadata">

**Author:** [@artschooldropout](https://discuss.elastic.co/u/artschooldropout)\
**Replies:** 18\
**Last updated:** [September 5, 2023, 7:26pm UTC](https://discuss.elastic.co/t/cisco-filebeat-module-not-listening-on-port-as-configured/341988 "2023-09-05T19:26:40Z")

</div>

We have an existing functional Elastic instance running with Filebeat 8.9, running on Ubuntu 22.04. We're attempting to add Cisco logs using the Cisco filebeat module. However, we're not seeing any logs coming in. We hav…

---

## [Windows server 2012 and 2008](https://discuss.elastic.co/t/windows-server-2012-and-2008/342371)

<div class="topic-metadata">

**Author:** [@Waseem.M](https://discuss.elastic.co/u/Waseem.M)\
**Replies:** 1\
**Last updated:** [September 5, 2023, 7:11pm UTC](https://discuss.elastic.co/t/windows-server-2012-and-2008/342371 "2023-09-05T19:11:21Z")

</div>

Hi Everyone, Recently start working on Kibana. I have created the dashboard and working on windows server 2008 and 2012 looking for advice. which file do I need to install winlogbeat is there any compatible version of w…

---

## [I don't understand why my bill is more than the cents per hour stated on the dashboard](https://discuss.elastic.co/t/i-dont-understand-why-my-bill-is-more-than-the-cents-per-hour-stated-on-the-dashboard/342079)

<div class="topic-metadata">

**Author:** [@tonyfam](https://discuss.elastic.co/u/tonyfam)\
**Replies:** 5\
**Last updated:** [September 5, 2023, 6:05pm UTC](https://discuss.elastic.co/t/i-dont-understand-why-my-bill-is-more-than-the-cents-per-hour-stated-on-the-dashboard/342079 "2023-09-05T18:05:29Z")

</div>

Hello, can someone please help me understand our bill? Budget crunch. On the dashboard, it says our one deployment is supposed to cost .0957 cents per hour. We have 2 x 45 GB. Enterprise search and Kibana is suppose…

---

## [Logstash SSL/TLS error](https://discuss.elastic.co/t/logstash-ssl-tls-error/342368)

<div class="topic-metadata">

**Author:** [@Kvoyce2023](https://discuss.elastic.co/u/Kvoyce2023)\
**Replies:** 0\
**Last updated:** [September 5, 2023, 5:56pm UTC](https://discuss.elastic.co/t/logstash-ssl-tls-error/342368 "2023-09-05T17:56:55Z")

</div>

My ELK stack got 3 ES nodes and 2 logstash nodes. Kibana is installed on one of the Logstash nodes. I was able to generate CA and all certificates. Distributed the certificates to all nodes.Confirmed Elasticsearch nodes …

---

## [Doubts about any field of wildcard](https://discuss.elastic.co/t/doubts-about-any-field-of-wildcard/342365)

<div class="topic-metadata">

**Author:** [@caixukun](https://discuss.elastic.co/u/caixukun)\
**Replies:** 0\
**Last updated:** [September 5, 2023, 5:21pm UTC](https://discuss.elastic.co/t/doubts-about-any-field-of-wildcard/342365 "2023-09-05T17:21:34Z")

</div>

hello everyone I currently have a problem. I want to search exactly for field a and match the search for field b. this is my code GET /\_search { "query": { "bool": { "must": \[ { "multi\_match": { "q…

---

## [Extract specific log set from others indexed togheter](https://discuss.elastic.co/t/extract-specific-log-set-from-others-indexed-togheter/341262)

<div class="topic-metadata">

**Author:** [@necromancer](https://discuss.elastic.co/u/necromancer)\
**Replies:** 1\
**Last updated:** [September 5, 2023, 4:33pm UTC](https://discuss.elastic.co/t/extract-specific-log-set-from-others-indexed-togheter/341262 "2023-09-05T16:33:44Z")

</div>

I want to know ihow can I extract/separate my nginx logs from an index where they are saved along with systemd logs and others (cron, fail2ban, etc)? I have it indexed with the ident "nginx". My point with it is be abl…

---

## [Aggregation with max field value](https://discuss.elastic.co/t/aggregation-with-max-field-value/341723)

<div class="topic-metadata">

**Author:** [@Mauricio\_Castrillon](https://discuss.elastic.co/u/Mauricio_Castrillon)\
**Replies:** 2\
**Last updated:** [September 5, 2023, 4:24pm UTC](https://discuss.elastic.co/t/aggregation-with-max-field-value/341723 "2023-09-05T16:24:57Z")

</div>

Hello, I'm trying to create a metric in Kibana for a dashboard with some information from servers. The main idea is to have the total amount of objects by location. The challenge is, in each location, I have a certain …

---

## [Sort results by inner hits (min/max)](https://discuss.elastic.co/t/sort-results-by-inner-hits-min-max/342359)

<div class="topic-metadata">

**Author:** [@LeoAdamek](https://discuss.elastic.co/u/LeoAdamek)\
**Replies:** 0\
**Last updated:** [September 5, 2023, 4:11pm UTC](https://discuss.elastic.co/t/sort-results-by-inner-hits-min-max/342359 "2023-09-05T16:11:18Z")

</div>

I'm using a join field and an has\_child filter in my search to join products with their various configuration permutations. There's a single level join from a product to a configuration. When a user searches for somethi…

---

## [Import trained model to ElastichSearch](https://discuss.elastic.co/t/import-trained-model-to-elastichsearch/342197)

<div class="topic-metadata">

**Author:** [@Khanh\_Dao\_Minh](https://discuss.elastic.co/u/Khanh_Dao_Minh)\
**Replies:** 2\
**Last updated:** [September 5, 2023, 3:43pm UTC](https://discuss.elastic.co/t/import-trained-model-to-elastichsearch/342197 "2023-09-05T15:43:23Z")

</div>

hello everyone. I have a question about importing my model to Elasticsearch. When i imported the model for task text embedding and started deployment mode on Kibana web, i got an error message " Couldn't start trained …

---

## [Query cache is getting cleared under heavy query load](https://discuss.elastic.co/t/query-cache-is-getting-cleared-under-heavy-query-load/341704)

<div class="topic-metadata">

**Author:** [@mahesh44](https://discuss.elastic.co/u/mahesh44)\
**Replies:** 2\
**Last updated:** [September 5, 2023, 2:38pm UTC](https://discuss.elastic.co/t/query-cache-is-getting-cleared-under-heavy-query-load/341704 "2023-09-05T14:38:15Z")

</div>

We are seeing exact same issue mentioned in the below post after upgrading to ES 7.17.8. This issue still exists even in the ES 8.8.0. Can someone please help with the solution for this. ES 7.17 | Exponentially growing …

---

## [Filtered alias not working](https://discuss.elastic.co/t/filtered-alias-not-working/342139)

<div class="topic-metadata">

**Author:** [@Amani188](https://discuss.elastic.co/u/Amani188)\
**Replies:** 2\
**Last updated:** [September 5, 2023, 2:01pm UTC](https://discuss.elastic.co/t/filtered-alias-not-working/342139 "2023-09-05T14:01:27Z")

</div>

Hi , I'm trying to create an alias filtered based on existing field but it seems not working Does anyone have any idea about this issue? POST /\_aliases { "actions" : \[ { "add" : { "index" : "myIndex", "alias" : …

---

## [How to filtering the data in api level while offloading in eastic search](https://discuss.elastic.co/t/how-to-filtering-the-data-in-api-level-while-offloading-in-eastic-search/342315)

<div class="topic-metadata">

**Author:** [@sahithi](https://discuss.elastic.co/u/sahithi)\
**Replies:** 6\
**Last updated:** [September 5, 2023, 2:00pm UTC](https://discuss.elastic.co/t/how-to-filtering-the-data-in-api-level-while-offloading-in-eastic-search/342315 "2023-09-05T14:00:39Z")

</div>

How to filtering the data in api level while offloading the data in eastic search ? Can any one help me here plz?

---

## [Problems with Number of replicas and UNASSIGNED errors](https://discuss.elastic.co/t/problems-with-number-of-replicas-and-unassigned-errors/342138)

<div class="topic-metadata">

**Author:** [@Ednei\_Rodrigues](https://discuss.elastic.co/u/Ednei_Rodrigues)\
**Replies:** 9\
**Last updated:** [September 5, 2023, 1:32pm UTC](https://discuss.elastic.co/t/problems-with-number-of-replicas-and-unassigned-errors/342138 "2023-09-05T13:32:54Z")

</div>

Hello, how are you doing ? So, I have a standalone ELK Stack and I am suffering with the error messages "UNASSIGNED" replicas. I know, to not use replica, I need to set 'number\_of\_replicas': 0 to the index. As I am usin…

---

## [Offload apic analytics to elastic search, while offloading exclude one of the api](https://discuss.elastic.co/t/offload-apic-analytics-to-elastic-search-while-offloading-exclude-one-of-the-api/342339)

<div class="topic-metadata">

**Author:** [@sahithi](https://discuss.elastic.co/u/sahithi)\
**Replies:** 0\
**Last updated:** [September 5, 2023, 12:38pm UTC](https://discuss.elastic.co/t/offload-apic-analytics-to-elastic-search-while-offloading-exclude-one-of-the-api/342339 "2023-09-05T12:38:53Z")

</div>

we implemented the Elasticsearch and kibana, and we are able to see analytics data and all for all APIs which are running . But now i want to exclude ( remove) one api analytics from the index . How can we achieve this t…

---

## [Enabling null values on expanded document in Kibana Discover](https://discuss.elastic.co/t/enabling-null-values-on-expanded-document-in-kibana-discover/341052)

<div class="topic-metadata">

**Author:** [@PodarcisMuralis](https://discuss.elastic.co/u/PodarcisMuralis)\
**Replies:** 1\
**Last updated:** [September 5, 2023, 10:54am UTC](https://discuss.elastic.co/t/enabling-null-values-on-expanded-document-in-kibana-discover/341052 "2023-09-05T10:54:40Z")

</div>

Hi. I am using version 8.5.3. I created a Data View under Stack Management. Displayed an index with multiple fields successfully If we filter results and click the diagonal button on document, expanded document comes …

---

## [Query latency spike when a node joins the cluster](https://discuss.elastic.co/t/query-latency-spike-when-a-node-joins-the-cluster/342213)

<div class="topic-metadata">

**Author:** [@marinko](https://discuss.elastic.co/u/marinko)\
**Replies:** 6\
**Last updated:** [September 5, 2023, 10:30am UTC](https://discuss.elastic.co/t/query-latency-spike-when-a-node-joins-the-cluster/342213 "2023-09-05T10:30:11Z")

</div>

Hi, We have Elasticsearch 8.6.0 with ltr plugin running on AWS EC2. Each time a new instance (data node) joins the cluster, we see a short (\< 1 min) spike in latency. The maximum latency can rise to 4-5 seconds. This h…

---

## [Does synonym\_graph work on Percolator Query?](https://discuss.elastic.co/t/does-synonym-graph-work-on-percolator-query/342331)

<div class="topic-metadata">

**Author:** [@jspark9812](https://discuss.elastic.co/u/jspark9812)\
**Replies:** 0\
**Last updated:** [September 5, 2023, 10:16am UTC](https://discuss.elastic.co/t/does-synonym-graph-work-on-percolator-query/342331 "2023-09-05T10:16:15Z")

</div>

Hello. There was a question from the percolator query, so I wrote it like this. The link below is a description of token-graphs. The description states that the positionLength of synonym\_graph is ignored in index time. …

---

## [Authentication failed for an OpenID integration(oidc)](https://discuss.elastic.co/t/authentication-failed-for-an-openid-integration-oidc/342330)

<div class="topic-metadata">

**Author:** [@EdricStrongshield](https://discuss.elastic.co/u/EdricStrongshield)\
**Replies:** 0\
**Last updated:** [September 5, 2023, 10:15am UTC](https://discuss.elastic.co/t/authentication-failed-for-an-openid-integration-oidc/342330 "2023-09-05T10:15:28Z")

</div>

Hello,I have a question about authentication that I need your help with. My software version is 8.5 Error: \[o.e.x.s.a.RealmsAuthenticator\] \[node-1\] Authentication to realm oidc1 failed - Failed to authenticate user wit…

---

## [Namespaced Synthetic monitors are missing after upgrade](https://discuss.elastic.co/t/namespaced-synthetic-monitors-are-missing-after-upgrade/342286)

<div class="topic-metadata">

**Author:** [@Marko\_Todoric](https://discuss.elastic.co/u/Marko_Todoric)\
**Replies:** 2\
**Last updated:** [September 5, 2023, 10:04am UTC](https://discuss.elastic.co/t/namespaced-synthetic-monitors-are-missing-after-upgrade/342286 "2023-09-05T10:04:51Z")

</div>

Hello everyone, after upgrading from 8.7.1 to 8.9.1 - I'm no longer able to see any of my monitored hosts but one from heartbeat in Kibana. I can confirm the data is there by looking at the discover but no hosts are sho…

---

## [logstash can no longer write to elasticsearch](https://discuss.elastic.co/t/logstash-can-no-longer-write-to-elasticsearch/342260)

<div class="topic-metadata">

**Author:** [@TaF](https://discuss.elastic.co/u/TaF)\
**Replies:** 2\
**Last updated:** [September 5, 2023, 9:51am UTC](https://discuss.elastic.co/t/logstash-can-no-longer-write-to-elasticsearch/342260 "2023-09-05T09:51:40Z")

</div>

Hello, I'm new to this platform and I need your help for my ELK stack Indeed logstash has not been able to write to elasticsearch for a while below is my logstash/conf.d flow management configuration \< input { tcp …

---

## [Configuring LDAP](https://discuss.elastic.co/t/configuring-ldap/342312)

<div class="topic-metadata">

**Author:** [@elk\_beginner](https://discuss.elastic.co/u/elk_beginner)\
**Replies:** 1\
**Last updated:** [September 5, 2023, 9:06am UTC](https://discuss.elastic.co/t/configuring-ldap/342312 "2023-09-05T09:06:06Z")

</div>

Hi, I am trying to configure LDAP authentication, but I have some trouble. I have this logs. P.S. I just begin to work with ELK, so I don’t know much \[node-1\] license \[...\] mode \[basic\] - valid \[node-1\] license mode i…

---

## [How trigger page with asking for built-in rules and conncectors?](https://discuss.elastic.co/t/how-trigger-page-with-asking-for-built-in-rules-and-conncectors/342304)

<div class="topic-metadata">

**Author:** [@smm](https://discuss.elastic.co/u/smm)\
**Replies:** 2\
**Last updated:** [September 5, 2023, 7:47am UTC](https://discuss.elastic.co/t/how-trigger-page-with-asking-for-built-in-rules-and-conncectors/342304 "2023-09-05T07:47:12Z")

</div>

Hi there, I am running 7.17.4 and would like to see the pop-up coming up in monitoring asking me if I want to install the the standard rules & connectors for Kibana alerting. No such page is showing up in the standard …

---

## [Aggregate filter plugin - aggregation exception](https://discuss.elastic.co/t/aggregate-filter-plugin-aggregation-exception/342314)

<div class="topic-metadata">

**Author:** [@Anca\_Linca](https://discuss.elastic.co/u/Anca_Linca)\
**Replies:** 0\
**Last updated:** [September 5, 2023, 8:15am UTC](https://discuss.elastic.co/t/aggregate-filter-plugin-aggregation-exception/342314 "2023-09-05T08:15:44Z")

</div>

Hello, Logstash version: 7.17 Aggregate filter plugin: v2.10.0 I have the following input of logs: {"@timestamp": "2023-07-27T08:40:27.849Z", "message": "Activity Stream update entry for job", "host": "tower-host", "…

---

## [Elastic Agent fleet-managed advanced filebeat configuration](https://discuss.elastic.co/t/elastic-agent-fleet-managed-advanced-filebeat-configuration/342310)

<div class="topic-metadata">

**Author:** [@martcus](https://discuss.elastic.co/u/martcus)\
**Replies:** 0\
**Last updated:** [September 5, 2023, 7:23am UTC](https://discuss.elastic.co/t/elastic-agent-fleet-managed-advanced-filebeat-configuration/342310 "2023-09-05T07:23:54Z")

</div>

Hi! We use the elastic agent fleet-managed solution extensively, especially with the custom logs integration for monitoring application logs. We need to set the filebeat close\_\*, scan\_frequency and ignore\_older paramet…

---

## [Logstash in k8s - parsing nested json from MongoDB and get every nested json as separated field](https://discuss.elastic.co/t/logstash-in-k8s-parsing-nested-json-from-mongodb-and-get-every-nested-json-as-separated-field/341755)

<div class="topic-metadata">

**Author:** [@Denis\_Lezgin](https://discuss.elastic.co/u/Denis_Lezgin)\
**Replies:** 2\
**Last updated:** [September 5, 2023, 7:11am UTC](https://discuss.elastic.co/t/logstash-in-k8s-parsing-nested-json-from-mongodb-and-get-every-nested-json-as-separated-field/341755 "2023-09-05T07:11:15Z")

</div>

Hi there, I'm using Logstash to take documents from specific MongoDB collection, and save it to Elasticsearch. Nested fields are being saved to "log\_entry" as one JSON, starting with "BSON" or "ID", depends on manipul…

---

## [Bulk inserts more documents than given](https://discuss.elastic.co/t/bulk-inserts-more-documents-than-given/342280)

<div class="topic-metadata">

**Author:** [@Kostyantyn\_Dobriohlo](https://discuss.elastic.co/u/Kostyantyn_Dobriohlo)\
**Replies:** 3\
**Last updated:** [September 5, 2023, 6:30am UTC](https://discuss.elastic.co/t/bulk-inserts-more-documents-than-given/342280 "2023-09-05T06:30:29Z")

</div>

Elasticsearched configured in single-node mode, I have ~1 million elements, but after bulk insert operation I see 10 million elements. I use this python code: def generate\_docs(data): for item in data: doc =…

---

## [Bulk API hangs forever python cloud function](https://discuss.elastic.co/t/bulk-api-hangs-forever-python-cloud-function/342221)

<div class="topic-metadata">

**Author:** [@Thani\_Ath\_Nain\_Khurs](https://discuss.elastic.co/u/Thani_Ath_Nain_Khurs)\
**Replies:** 1\
**Last updated:** [September 5, 2023, 6:25am UTC](https://discuss.elastic.co/t/bulk-api-hangs-forever-python-cloud-function/342221 "2023-09-05T06:25:50Z")

</div>

I am new to Elasticsearch and this issue is driving me crazy. My use case involves getting all documents in elastic-search, min-max normalising some fields and then updating documents in bulk but my bulk call just hangs …

---

## [What does it mean a shard executing a search locally?](https://discuss.elastic.co/t/what-does-it-mean-a-shard-executing-a-search-locally/342298)

<div class="topic-metadata">

**Author:** [@Dhineshkumar\_R](https://discuss.elastic.co/u/Dhineshkumar_R)\
**Replies:** 1\
**Last updated:** [September 5, 2023, 4:31am UTC](https://discuss.elastic.co/t/what-does-it-mean-a-shard-executing-a-search-locally/342298 "2023-09-05T04:31:17Z")

</div>

Hi Folks, I need some help understanding Query phase of distributed search in ES better, step 2 specifically. Node 3 forwards the search request to a primary or replica copy of every shard in the index. Each shard ex…

[Previous page](https://discuss.elastic.co/tag/none.md?no_tags=true&page=308)

[Next page](https://discuss.elastic.co/tag/none.md?no_tags=true&page=310)
