# \#none

**URL:** https://discuss.elastic.co/tag/none.md?no_tags=true&page=313

[Latest](https://discuss.elastic.co/latest.md) · [Categories](https://discuss.elastic.co/categories.md) · [Tags](https://discuss.elastic.co/tags.md)

**Page:** 314

---

## [Logstash Output to Kibana with SSL?](https://discuss.elastic.co/t/logstash-output-to-kibana-with-ssl/341905)

<div class="topic-metadata">

**Author:** [@paolovalladolid](https://discuss.elastic.co/u/paolovalladolid)\
**Replies:** 12\
**Last updated:** [August 29, 2023, 9:45pm UTC](https://discuss.elastic.co/t/logstash-output-to-kibana-with-ssl/341905 "2023-08-29T21:45:43Z")

</div>

I am new to Logstash, having previous experience with Filebeat and Winlogbeat. In the Filebeat/Winlogbeat configuration we have separate output sections for Elasticsearch and Kibana. We configure the Kibana output sect…

---

## [Cisco ISE - associate with this object no longer exists in the index pattern. please use another field](https://discuss.elastic.co/t/cisco-ise-associate-with-this-object-no-longer-exists-in-the-index-pattern-please-use-another-field/341924)

<div class="topic-metadata">

**Author:** [@sebast.ssoto](https://discuss.elastic.co/u/sebast.ssoto)\
**Replies:** 0\
**Last updated:** [August 29, 2023, 8:57pm UTC](https://discuss.elastic.co/t/cisco-ise-associate-with-this-object-no-longer-exists-in-the-index-pattern-please-use-another-field/341924 "2023-08-29T20:57:02Z")

</div>

was found in a Cisco ISE dashboard which leaves the following error Someone knows why the complete syntax of the error detected is:

---

## [URL shortening services monitoring via ELK](https://discuss.elastic.co/t/url-shortening-services-monitoring-via-elk/341911)

<div class="topic-metadata">

**Author:** [@Ragul\_venkatasubban](https://discuss.elastic.co/u/Ragul_venkatasubban)\
**Replies:** 0\
**Last updated:** [August 29, 2023, 4:05pm UTC](https://discuss.elastic.co/t/url-shortening-services-monitoring-via-elk/341911 "2023-08-29T16:05:42Z")

</div>

Hey, I have integrated firewall logs in ELK. I came across some logs which are of URL shorteners eg., bit\[.\]ly, etc.. the interesting part is when a user clicks on these kinds of URLs we won't know the original URL and …

---

## [Building a Basic Query That Orders Results](https://discuss.elastic.co/t/building-a-basic-query-that-orders-results/341906)

<div class="topic-metadata">

**Author:** [@kocakserdar](https://discuss.elastic.co/u/kocakserdar)\
**Replies:** 0\
**Last updated:** [August 29, 2023, 3:37pm UTC](https://discuss.elastic.co/t/building-a-basic-query-that-orders-results/341906 "2023-08-29T15:37:50Z")

</div>

Hello, As a newbie, I'm trying to build a compound query for my NodeJS/Express web app. All I need is to give priority to phrases first in the search results if they exist... For example let's search for "customers are"…

---

## [Elastic search order of the highlighted fields not matching with the ranking](https://discuss.elastic.co/t/elastic-search-order-of-the-highlighted-fields-not-matching-with-the-ranking/341889)

<div class="topic-metadata">

**Author:** [@Vikram\_Jadhav](https://discuss.elastic.co/u/Vikram_Jadhav)\
**Replies:** 0\
**Last updated:** [August 29, 2023, 2:19pm UTC](https://discuss.elastic.co/t/elastic-search-order-of-the-highlighted-fields-not-matching-with-the-ranking/341889 "2023-08-29T14:19:23Z")

</div>

Hello, In the below document, I am trying to match multiple fields and I also want to know what fields are getting matched from the document that's why used the highlighted fields. sample doc: { "therapeutic\_area": "…

---

## [How to compare document fields in a elasticsearch query](https://discuss.elastic.co/t/how-to-compare-document-fields-in-a-elasticsearch-query/341814)

<div class="topic-metadata">

**Author:** [@juanmgarciaf](https://discuss.elastic.co/u/juanmgarciaf)\
**Replies:** 1\
**Last updated:** [August 29, 2023, 2:17pm UTC](https://discuss.elastic.co/t/how-to-compare-document-fields-in-a-elasticsearch-query/341814 "2023-08-29T14:17:06Z")

</div>

Hello! I have an index with a lot of documents and I need to group these documents by an specific field and after this I need to compare if the two last documents (with the most recent timestamp) from each group have a s…

---

## [No\_shard\_available\_action\_exception](https://discuss.elastic.co/t/no-shard-available-action-exception/341883)

<div class="topic-metadata">

**Author:** [@Nibort](https://discuss.elastic.co/u/Nibort)\
**Replies:** 0\
**Last updated:** [August 29, 2023, 1:25pm UTC](https://discuss.elastic.co/t/no-shard-available-action-exception/341883 "2023-08-29T13:25:32Z")

</div>

Hello, I'm trying to send rsyslog with filebeat to my Elasticsearch cluster I've added the global path where logs are stored (/var/log/\*.log) filebeat.yml filebeat.inputs: - type: log id: rsyslog paths: - /va…

---

## [How to do float comparison](https://discuss.elastic.co/t/how-to-do-float-comparison/341881)

<div class="topic-metadata">

**Author:** [@lostsoul352](https://discuss.elastic.co/u/lostsoul352)\
**Replies:** 3\
**Last updated:** [August 29, 2023, 1:16pm UTC](https://discuss.elastic.co/t/how-to-do-float-comparison/341881 "2023-08-29T13:16:29Z")

</div>

I'm trying to drop events if the value of a float field is less than -90000 Here is a code snippet: if \[type\] == "node\_perf" { mutate { convert =\> { "nodeperf\_value" =\> "float"} …

---

## [Aggregate filter plugin - final event contains empty message](https://discuss.elastic.co/t/aggregate-filter-plugin-final-event-contains-empty-message/339702)

<div class="topic-metadata">

**Author:** [@Anca\_Linca](https://discuss.elastic.co/u/Anca_Linca)\
**Replies:** 8\
**Last updated:** [August 29, 2023, 1:02pm UTC](https://discuss.elastic.co/t/aggregate-filter-plugin-final-event-contains-empty-message/339702 "2023-08-29T13:02:03Z")

</div>

Hello, Logstash version: 7.17 Aggregate filter plugin: v2.10.0 Contents for /var/log/logstash/input.log: {"timestamp": "2023-07-31T15:10:45.141Z", "parentOnly": 1, "logger\_name": "activity\_stream", "job": 102693, "ty…

---

## [Querying on large docs](https://discuss.elastic.co/t/querying-on-large-docs/341759)

<div class="topic-metadata">

**Author:** [@m4kkur0](https://discuss.elastic.co/u/m4kkur0)\
**Replies:** 4\
**Last updated:** [August 29, 2023, 12:53pm UTC](https://discuss.elastic.co/t/querying-on-large-docs/341759 "2023-08-29T12:53:15Z")

</div>

Hello all, I would like to know what are some good options to query an index that each doc in it structured like: field1, keyword field2, long field3, object, enabled: false (mostly below 1 mb but sometimes goes up t…

---

## [When to use SLO and when normal alerts in kibana?](https://discuss.elastic.co/t/when-to-use-slo-and-when-normal-alerts-in-kibana/341772)

<div class="topic-metadata">

**Author:** [@Navya1](https://discuss.elastic.co/u/Navya1)\
**Replies:** 1\
**Last updated:** [August 29, 2023, 11:02am UTC](https://discuss.elastic.co/t/when-to-use-slo-and-when-normal-alerts-in-kibana/341772 "2023-08-29T11:02:33Z")

</div>

Hello All, I have a questions on SLO when compared to normal alert setup in kibana. What is the difference ? Which option has to choose ? When to choose SLO and when to use normal alerts ? Please advise. Thanks, Navy…

---

## [Logstash index is not having the autosuggestions](https://discuss.elastic.co/t/logstash-index-is-not-having-the-autosuggestions/341866)

<div class="topic-metadata">

**Author:** [@uma\_parvathy](https://discuss.elastic.co/u/uma_parvathy)\
**Replies:** 0\
**Last updated:** [August 29, 2023, 8:26am UTC](https://discuss.elastic.co/t/logstash-index-is-not-having-the-autosuggestions/341866 "2023-08-29T08:26:45Z")

</div>

i've been trying to populate the data from postgresql db to elasticsearch7.17 using logstash. The data is imported but it's missing the autosuggestions and fuzzy logic suggestions which is needed to query from django ap…

---

## [Aggregate filter の timeout\_timestamp\_field設定時の動作について （続き）](https://discuss.elastic.co/t/aggregate-filter-timeout-timestamp-field/341858)

<div class="topic-metadata">

**Author:** [@e-se](https://discuss.elastic.co/u/e-se)\
**Replies:** 0\
**Last updated:** [August 29, 2023, 7:18am UTC](https://discuss.elastic.co/t/aggregate-filter-timeout-timestamp-field/341858 "2023-08-29T07:18:38Z")

</div>

Continuing the discussion from Aggregate filter の timeout\_timestamp\_field設定時の動作について: 2 行目は 2 番目の集計フィルターを通過しますが、タイムアウト オプションが設定されていないため、タイムアウト処理は行われません。 とありますが、システム時間でタイムアウトを計測する場合、フィルターを通過するかどうかに関係なく、timeoutオプションに設定し…

---

## [Remove old 7.x Kibana indices after upgrade to 8.9](https://discuss.elastic.co/t/remove-old-7-x-kibana-indices-after-upgrade-to-8-9/341212)

<div class="topic-metadata">

**Author:** [@chouben](https://discuss.elastic.co/u/chouben)\
**Replies:** 2\
**Last updated:** [August 29, 2023, 6:36am UTC](https://discuss.elastic.co/t/remove-old-7-x-kibana-indices-after-upgrade-to-8-9/341212 "2023-08-29T06:36:27Z")

</div>

Hi I posted my question in "elasticsearch" channel first. I didn't get a response yet, nor did I find a way to move it over here: Original post: https://discuss.elastic.co/t/remove-7-x-indices-after-upgrade-to-8-x I w…

---

## [Can I configure elastic agent to have logs indexed by elastic search?](https://discuss.elastic.co/t/can-i-configure-elastic-agent-to-have-logs-indexed-by-elastic-search/341856)

<div class="topic-metadata">

**Author:** [@Ong\_Yi\_Chong](https://discuss.elastic.co/u/Ong_Yi_Chong)\
**Replies:** 0\
**Last updated:** [August 29, 2023, 6:35am UTC](https://discuss.elastic.co/t/can-i-configure-elastic-agent-to-have-logs-indexed-by-elastic-search/341856 "2023-08-29T06:35:24Z")

</div>

Hi, I have just started learning about elastic stack one day ago. I have managed to add an elastic agent apm integration to a sample node JS server and I am able to view the log outputs on Observability \> Logs section. …

---

## [Remove 7.x indices after upgrade to 8.x](https://discuss.elastic.co/t/remove-7-x-indices-after-upgrade-to-8-x/341000)

<div class="topic-metadata">

**Author:** [@chouben](https://discuss.elastic.co/u/chouben)\
**Replies:** 6\
**Last updated:** [August 29, 2023, 6:34am UTC](https://discuss.elastic.co/t/remove-7-x-indices-after-upgrade-to-8-x/341000 "2023-08-29T06:34:57Z")

</div>

Hi I was wondering if we could remove the old 7.x indices from our Elastic Stack, since we upgraded to 8.x? E.g. Kibana: Remark: I found out about the allow\_restricted\_indices setting, which would probably allow me…

---

## [How to store/compress large string field in index (V6.8)](https://discuss.elastic.co/t/how-to-store-compress-large-string-field-in-index-v6-8/341777)

<div class="topic-metadata">

**Author:** [@elron](https://discuss.elastic.co/u/elron)\
**Replies:** 1\
**Last updated:** [August 29, 2023, 6:08am UTC](https://discuss.elastic.co/t/how-to-store-compress-large-string-field-in-index-v6-8/341777 "2023-08-29T06:08:04Z")

</div>

We are planning to store in the index a large string(error log) with a classifier for future use in a machine learning project. The error log can get to the size of tens of megabytes and we are planning to store tens of …

---

## [Elastic-agent metricbeat no verification mode](https://discuss.elastic.co/t/elastic-agent-metricbeat-no-verification-mode/341851)

<div class="topic-metadata">

**Author:** [@Daniel\_Lopez](https://discuss.elastic.co/u/Daniel_Lopez)\
**Replies:** 0\
**Last updated:** [August 29, 2023, 5:46am UTC](https://discuss.elastic.co/t/elastic-agent-metricbeat-no-verification-mode/341851 "2023-08-29T05:46:02Z")

</div>

Hi guys! I think i found a bug on elastic-agent. I configured the whole fleet server with --insecure and ssl.verification\_mode: none options and i'm getting logs to elastic but not metricbeat metrics as i show in the se…

---

## [Data getting SWAPPED in Elasticsearch with pipeline](https://discuss.elastic.co/t/data-getting-swapped-in-elasticsearch-with-pipeline/341796)

<div class="topic-metadata">

**Author:** [@tusharnemade](https://discuss.elastic.co/u/tusharnemade)\
**Replies:** 2\
**Last updated:** [August 29, 2023, 5:33am UTC](https://discuss.elastic.co/t/data-getting-swapped-in-elasticsearch-with-pipeline/341796 "2023-08-29T05:33:36Z")

</div>

Hello Team We are using Elasticsearch version 7.8.0 We are having Index with Pipeline Defined .. Our Problem is data is getting SWAPPED between two fields of Elasticsearch. Data of "OBJ\_NAM\_FILDT" is getting posted i…

---

## [Need confirmation for few Elasticsearch queries](https://discuss.elastic.co/t/need-confirmation-for-few-elasticsearch-queries/341849)

<div class="topic-metadata">

**Author:** [@ashishshukla](https://discuss.elastic.co/u/ashishshukla)\
**Replies:** 1\
**Last updated:** [August 29, 2023, 5:15am UTC](https://discuss.elastic.co/t/need-confirmation-for-few-elasticsearch-queries/341849 "2023-08-29T05:15:30Z")

</div>

Hi Team, Can you please confirm below query comes under SQL query or DSL query ? curl -X POST "https://localhost:9200/\_sql?format=txt&pretty" -H 'Content-Type: application/json' -d' { "query": "SELECT \* FROM custo…

---

## [Elasticsearch snapshot google.cloud.storage.StorageException](https://discuss.elastic.co/t/elasticsearch-snapshot-google-cloud-storage-storageexception/341848)

<div class="topic-metadata">

**Author:** [@navaneethan](https://discuss.elastic.co/u/navaneethan)\
**Replies:** 0\
**Last updated:** [August 29, 2023, 4:45am UTC](https://discuss.elastic.co/t/elasticsearch-snapshot-google-cloud-storage-storageexception/341848 "2023-08-29T04:45:52Z")

</div>

Elastic GCS bucket snapshot failed and we cannot able to retrive the old inremental backup in that bucket, Is there any possibility to recover the back FYI, we can able to view the data storage inside that bucket in th…

---

## [MY SQL database to Kibana directly](https://discuss.elastic.co/t/my-sql-database-to-kibana-directly/341831)

<div class="topic-metadata">

**Author:** [@Kumar\_Abhinav](https://discuss.elastic.co/u/Kumar_Abhinav)\
**Replies:** 6\
**Last updated:** [August 29, 2023, 3:12am UTC](https://discuss.elastic.co/t/my-sql-database-to-kibana-directly/341831 "2023-08-29T03:12:34Z")

</div>

Hello Elastic Community, I'm exploring the use of JDBC to connect Kibana(bypassing Elastic) directly to MySQL. This would help us overcome the challenge of joining data from different indices in Elasticsearch. I'd appre…

---

## [Metricbeat - Limit of total fields \[1000\] has been exceeded-urgent](https://discuss.elastic.co/t/metricbeat-limit-of-total-fields-1000-has-been-exceeded-urgent/341824)

<div class="topic-metadata">

**Author:** [@EL\_MALKI\_MOHAMED](https://discuss.elastic.co/u/EL_MALKI_MOHAMED)\
**Replies:** 5\
**Last updated:** [August 29, 2023, 12:50am UTC](https://discuss.elastic.co/t/metricbeat-limit-of-total-fields-1000-has-been-exceeded-urgent/341824 "2023-08-29T00:50:03Z")

</div>

Hello, Can u help me I have problem. I am having errors trying to ingest system metrics (system module) .The logs are ingested via a common beats pipeline running having the following configuration: logstashPipeline: …

---

## [Term negation and fuzziness](https://discuss.elastic.co/t/term-negation-and-fuzziness/341645)

<div class="topic-metadata">

**Author:** [@cvarano](https://discuss.elastic.co/u/cvarano)\
**Replies:** 1\
**Last updated:** [August 28, 2023, 9:47pm UTC](https://discuss.elastic.co/t/term-negation-and-fuzziness/341645 "2023-08-28T21:47:49Z")

</div>

The use case is a search engine over text documents for the general public. We were previously using a simple match query, but recently switched to simple\_query\_string in order to easily support phrase matching. I'm fi…

---

## [Is it safe to delete logs-deprecation indices, where can we disable creation of these indices?](https://discuss.elastic.co/t/is-it-safe-to-delete-logs-deprecation-indices-where-can-we-disable-creation-of-these-indices/341714)

<div class="topic-metadata">

**Author:** [@Vadym](https://discuss.elastic.co/u/Vadym)\
**Replies:** 2\
**Last updated:** [August 28, 2023, 9:34pm UTC](https://discuss.elastic.co/t/is-it-safe-to-delete-logs-deprecation-indices-where-can-we-disable-creation-of-these-indices/341714 "2023-08-28T21:34:44Z")

</div>

We have some system indices generated by ES, can we turn off generation of these indices and is it safe to delete them? health status index green open .ds-ilm-history-5-2023.06.02-000012 green open .ds-.logs-dep…

---

## [Logstash Logs output for jdbc](https://discuss.elastic.co/t/logstash-logs-output-for-jdbc/341826)

<div class="topic-metadata">

**Author:** [@nbrenke](https://discuss.elastic.co/u/nbrenke)\
**Replies:** 4\
**Last updated:** [August 28, 2023, 8:12pm UTC](https://discuss.elastic.co/t/logstash-logs-output-for-jdbc/341826 "2023-08-28T20:12:08Z")

</div>

I have a silly question:: I have several jdbc pipelines setup that pull data directly from a sql database. Short of the following that shows up in my logs \[2022-10-28T18:40:00,344\]\[INFO \]\[logstash.inputs.jdbc \] (0…

---

## [Investigate high GC time when indexing](https://discuss.elastic.co/t/investigate-high-gc-time-when-indexing/341154)

<div class="topic-metadata">

**Author:** [@ktech007](https://discuss.elastic.co/u/ktech007)\
**Replies:** 17\
**Last updated:** [August 28, 2023, 7:42pm UTC](https://discuss.elastic.co/t/investigate-high-gc-time-when-indexing/341154 "2023-08-28T19:42:54Z")

</div>

Hello, I am looking for some advice as to why we are seeing a high GC time on our Elasticsearch cluster. On average, we see 5 - 8% of GC time across all the nodes. This is the setup we have: 150 data nodes 1000 primar…

---

## [Retrieving millions of large documents](https://discuss.elastic.co/t/retrieving-millions-of-large-documents/341803)

<div class="topic-metadata">

**Author:** [@Tomer\_Avira](https://discuss.elastic.co/u/Tomer_Avira)\
**Replies:** 6\
**Last updated:** [August 28, 2023, 6:06pm UTC](https://discuss.elastic.co/t/retrieving-millions-of-large-documents/341803 "2023-08-28T18:06:58Z")

</div>

Hello everyone, first time i am requesting your help. I am working with elastic version 8.5.3 with java client 7.17.1, let me represent you with the problem I'm having. I have daily indices with the largest of them hol…

---

## [Elastic to logs management](https://discuss.elastic.co/t/elastic-to-logs-management/341716)

<div class="topic-metadata">

**Author:** [@Flavio\_Alves](https://discuss.elastic.co/u/Flavio_Alves)\
**Replies:** 2\
**Last updated:** [August 28, 2023, 4:44pm UTC](https://discuss.elastic.co/t/elastic-to-logs-management/341716 "2023-08-28T16:44:52Z")

</div>

Hey, guys! I'm new to using elastic What is the best way to build this structure? and what features should i use? at the moment I will only use the stack to centralize the logs

---

## [How do parse log format apache access](https://discuss.elastic.co/t/how-do-parse-log-format-apache-access/341790)

<div class="topic-metadata">

**Author:** [@vanhaiit90](https://discuss.elastic.co/u/vanhaiit90)\
**Replies:** 1\
**Last updated:** [August 28, 2023, 3:19pm UTC](https://discuss.elastic.co/t/how-do-parse-log-format-apache-access/341790 "2023-08-28T15:19:04Z")

</div>

Good afternoon I have a log with the format of the apache access log service (access\_log) 10.0.xx.xx - - \[28/Aug/2023:15:25:18 +0700\] "GET /xxx/en/neoclassic/cases/main HTTP/1.0" 200 2007 133793 "-" "Mozilla/5.0 (Wind…

[Previous page](https://discuss.elastic.co/tag/none.md?no_tags=true&page=312)

[Next page](https://discuss.elastic.co/tag/none.md?no_tags=true&page=314)
