# \#none

**URL:** https://discuss.elastic.co/tag/none.md?no_tags=true&page=316

[Latest](https://discuss.elastic.co/latest.md) · [Categories](https://discuss.elastic.co/categories.md) · [Tags](https://discuss.elastic.co/tags.md)

**Page:** 317

---

## [Need to setup API Logging tool for our project](https://discuss.elastic.co/t/need-to-setup-api-logging-tool-for-our-project/341573)

<div class="topic-metadata">

**Author:** [@Uttam\_Jagwani](https://discuss.elastic.co/u/Uttam_Jagwani)\
**Replies:** 0\
**Last updated:** [August 24, 2023, 12:05pm UTC](https://discuss.elastic.co/t/need-to-setup-api-logging-tool-for-our-project/341573 "2023-08-24T12:05:40Z")

</div>

Need to set up an API Logging tool for our project on the prod environment. Would like to know the details on the product stack, cluster setup, hardware & software specifications, storage requirements for logging, and a…

---

## [Decode Base64](https://discuss.elastic.co/t/decode-base64/341359)

<div class="topic-metadata">

**Author:** [@Khaled\_Aldughili](https://discuss.elastic.co/u/Khaled_Aldughili)\
**Replies:** 3\
**Last updated:** [August 24, 2023, 11:23am UTC](https://discuss.elastic.co/t/decode-base64/341359 "2023-08-24T11:23:00Z")

</div>

hello , I am a bit new to ELK, I am trying to decode a base64 field to show as a string. I read through some articles that suggest using ingest pipeline, how would i do that exactly? PS: I tried runtime fields, bu…

---

## [Rally 2.9.0](https://discuss.elastic.co/t/rally-2-9-0/341563)

<div class="topic-metadata">

**Author:** [@Quentin\_Pradet](https://discuss.elastic.co/u/Quentin_Pradet)\
**Replies:** 0\
**Last updated:** [August 24, 2023, 10:12am UTC](https://discuss.elastic.co/t/rally-2-9-0/341563 "2023-08-24T10:12:50Z")

</div>

Rally 2.9.0 has just been released. The new release brings improved support for the upcoming Elasticsearch Serverless offering. Highlights #1760: Exclude tasks based on serverless status #1750 (Breaking): Inject build\_…

---

## [Security Privileges - Auto Expand Replicas](https://discuss.elastic.co/t/security-privileges-auto-expand-replicas/341555)

<div class="topic-metadata">

**Author:** [@tneto](https://discuss.elastic.co/u/tneto)\
**Replies:** 0\
**Last updated:** [August 24, 2023, 9:09am UTC](https://discuss.elastic.co/t/security-privileges-auto-expand-replicas/341555 "2023-08-24T09:09:46Z")

</div>

Hello. I'm running ES version 8.1.3 and I'm facing some issues regarding "auto\_expand\_replicas" This is my command on the console over Dev Tools. PUT /.kibana/\_settings { "index" : { "number\_of\_replicas":0, "aut…

---

## [How can I change an existing node with both "master" and "data" roles to be a "master" role only, without any downtime?](https://discuss.elastic.co/t/how-can-i-change-an-existing-node-with-both-master-and-data-roles-to-be-a-master-role-only-without-any-downtime/340526)

<div class="topic-metadata">

**Author:** [@Manal\_A](https://discuss.elastic.co/u/Manal_A)\
**Replies:** 2\
**Last updated:** [August 24, 2023, 8:53am UTC](https://discuss.elastic.co/t/how-can-i-change-an-existing-node-with-both-master-and-data-roles-to-be-a-master-role-only-without-any-downtime/340526 "2023-08-24T08:53:16Z")

</div>

I have a cluster with multiple nodes. I intend to dynamically change an existing node that currently serves both the "master" and "data" roles to exclusively perform the "data" role, all without causing any downtime. Wha…

---

## [Extracting texts from Flatten/ Scanned PDF Documents in Kibana](https://discuss.elastic.co/t/extracting-texts-from-flatten-scanned-pdf-documents-in-kibana/341351)

<div class="topic-metadata">

**Author:** [@Anant\_Patankar](https://discuss.elastic.co/u/Anant_Patankar)\
**Replies:** 1\
**Last updated:** [August 24, 2023, 8:50am UTC](https://discuss.elastic.co/t/extracting-texts-from-flatten-scanned-pdf-documents-in-kibana/341351 "2023-08-24T08:50:10Z")

</div>

Hello Everyone, I am trying to read texts from scanned/flattened pdf which are made up of images and texts that are not readable with a pdf reader. How can I read and index texts from flattened or scanned pdf files in …

---

## [How can I pass filters to a dashboard through url](https://discuss.elastic.co/t/how-can-i-pass-filters-to-a-dashboard-through-url/341455)

<div class="topic-metadata">

**Author:** [@kanna](https://discuss.elastic.co/u/kanna)\
**Replies:** 1\
**Last updated:** [August 24, 2023, 8:45am UTC](https://discuss.elastic.co/t/how-can-i-pass-filters-to-a-dashboard-through-url/341455 "2023-08-24T08:45:14Z")

</div>

Hi, I have been trying to pass filters as part of url without success. I followed examples in other threads I would like to add following filters created manually on dashboard as part of url { "query": { "match…

---

## [Audit log issue for Elasticsearch 7.15.2 with trail license](https://discuss.elastic.co/t/audit-log-issue-for-elasticsearch-7-15-2-with-trail-license/341551)

<div class="topic-metadata">

**Author:** [@ashishshukla](https://discuss.elastic.co/u/ashishshukla)\
**Replies:** 0\
**Last updated:** [August 24, 2023, 8:30am UTC](https://discuss.elastic.co/t/audit-log-issue-for-elasticsearch-7-15-2-with-trail-license/341551 "2023-08-24T08:30:24Z")

</div>

Hi Team, I am using Elasticsearch 7.15.2 version with trail license on rpm machine(Red HAT). After enabling the audit log in elasticsearch.yml file , I am not getting audit log for the queries which I had executed. I…

---

## [Help for elk stack](https://discuss.elastic.co/t/help-for-elk-stack/341447)

<div class="topic-metadata">

**Author:** [@Farah\_Bannour](https://discuss.elastic.co/u/Farah_Bannour)\
**Replies:** 5\
**Last updated:** [August 24, 2023, 8:27am UTC](https://discuss.elastic.co/t/help-for-elk-stack/341447 "2023-08-24T08:27:13Z")

</div>

Can I make the datamart from elk stack . and How do I combine 2 index data in elasticsearch do-i-combine-2-index-data-in-elasticsearch/199044 .

---

## [I am using Multiline codec input plugin but the events which are not matching with my PATTERN it also processing those Events](https://discuss.elastic.co/t/i-am-using-multiline-codec-input-plugin-but-the-events-which-are-not-matching-with-my-pattern-it-also-processing-those-events/341425)

<div class="topic-metadata">

**Author:** [@Subrato1](https://discuss.elastic.co/u/Subrato1)\
**Replies:** 1\
**Last updated:** [August 24, 2023, 8:13am UTC](https://discuss.elastic.co/t/i-am-using-multiline-codec-input-plugin-but-the-events-which-are-not-matching-with-my-pattern-it-also-processing-those-events/341425 "2023-08-24T08:13:59Z")

</div>

Below is the codec which am using for multiline events. codec =\> multiline { pattern =\> "%{TIMESTAMP\_ISO8601:syslogtime}\\s%{WORD:str}\\s%{WORD:s}\\s%{YEAR:yeaa}-%{MONTHNUM:ooo}-%{MONTHDAY:ppp}\\s%{TIME:trrrs}" #patte…

---

## [Install via fleet from a local agent repository instead downloading each time?](https://discuss.elastic.co/t/install-via-fleet-from-a-local-agent-repository-instead-downloading-each-time/341544)

<div class="topic-metadata">

**Author:** [@GKre](https://discuss.elastic.co/u/GKre)\
**Replies:** 1\
**Last updated:** [August 24, 2023, 8:02am UTC](https://discuss.elastic.co/t/install-via-fleet-from-a-local-agent-repository-instead-downloading-each-time/341544 "2023-08-24T08:02:35Z")

</div>

well - unfortunately i do not have the best internet connection an installing the updating the agents via fleet takes a lot of time. Is it possible to use a local repository instead so that the agent does not have to be…

---

## [How do parse log format apache tomcat](https://discuss.elastic.co/t/how-do-parse-log-format-apache-tomcat/341529)

<div class="topic-metadata">

**Author:** [@vanhaiit90](https://discuss.elastic.co/u/vanhaiit90)\
**Replies:** 2\
**Last updated:** [August 24, 2023, 7:36am UTC](https://discuss.elastic.co/t/how-do-parse-log-format-apache-tomcat/341529 "2023-08-24T07:36:39Z")

</div>

Good moring everyone! I have a log with the format of the tomcat access log service (localaccesslog.txt) 10.0.xx.xx \[22/Aug/2023:00:00:30 +0700\] "GET /zkau?dtid=z\_qe0&cmd\_0=rmDesktop&opt\_0=i HTTP/1.0" 200 17 0 Now I…

---

## [Random function in Painless?](https://discuss.elastic.co/t/random-function-in-painless/70280)

<div class="topic-metadata">

**Author:** [@Dom-nik](https://discuss.elastic.co/u/Dom-nik)\
**Replies:** 3\
**Last updated:** [August 24, 2023, 6:25am UTC](https://discuss.elastic.co/t/random-function-in-painless/70280 "2023-08-24T06:25:09Z")

</div>

Hello, What is the way to genereate a random value in Painless? Being able to draw one value from a set would be particularly great - I want to use it to add a new field to my mock data and I need a possibility to add…

---

## [How can I store the average of CPU,Memory,Disk data of one day in some logs](https://discuss.elastic.co/t/how-can-i-store-the-average-of-cpu-memory-disk-data-of-one-day-in-some-logs/340112)

<div class="topic-metadata">

**Author:** [@AkshayP21296](https://discuss.elastic.co/u/AkshayP21296)\
**Replies:** 4\
**Last updated:** [August 24, 2023, 6:04am UTC](https://discuss.elastic.co/t/how-can-i-store-the-average-of-cpu-memory-disk-data-of-one-day-in-some-logs/340112 "2023-08-24T06:04:25Z")

</div>

Hello Sir, I am using metricbeat for infra monitoring but as it is consuming so much data do we have the option to store the average of a complete day in only few logs .

---

## [ElasticSearch Service Startup Issue](https://discuss.elastic.co/t/elasticsearch-service-startup-issue/341532)

<div class="topic-metadata">

**Author:** [@Jeevagan](https://discuss.elastic.co/u/Jeevagan)\
**Replies:** 0\
**Last updated:** [August 24, 2023, 4:40am UTC](https://discuss.elastic.co/t/elasticsearch-service-startup-issue/341532 "2023-08-24T04:40:06Z")

</div>

Hey everyone, I hope you're doing well. I've been working on setting up an Elasticsearch service using a systemd service file, but I'm encountering an issue when trying to start the application. I'm hoping someone here …

---

## [Logstash-7.17.12 file input not working](https://discuss.elastic.co/t/logstash-7-17-12-file-input-not-working/341527)

<div class="topic-metadata">

**Author:** [@Jongwook\_Seong](https://discuss.elastic.co/u/Jongwook_Seong)\
**Replies:** 2\
**Last updated:** [August 24, 2023, 4:44am UTC](https://discuss.elastic.co/t/logstash-7-17-12-file-input-not-working/341527 "2023-08-24T04:44:44Z")

</div>

I am using logstash-7.17.12 to input the contents of logstash-test.conf file. The contents of logstash-test.conf are as follows. input { file { path =\> "C:/Users/user/logstash-7.17.12/config/filter-example.log" …

---

## [Elasticsearch Aggregate Search Impact on Performance](https://discuss.elastic.co/t/elasticsearch-aggregate-search-impact-on-performance/340740)

<div class="topic-metadata">

**Author:** [@fangyan](https://discuss.elastic.co/u/fangyan)\
**Replies:** 2\
**Last updated:** [August 24, 2023, 3:45am UTC](https://discuss.elastic.co/t/elasticsearch-aggregate-search-impact-on-performance/340740 "2023-08-24T03:45:04Z")

</div>

Is there a leader in ES? For general product comprehensive search and display lists, it is recommended to use direct query or AGG aggregation form, as AGG has little impact on performance

---

## [When the number of documents exceeds 2 billion, the index status becomes RED](https://discuss.elastic.co/t/when-the-number-of-documents-exceeds-2-billion-the-index-status-becomes-red/341461)

<div class="topic-metadata">

**Author:** [@im.jinxinwang](https://discuss.elastic.co/u/im.jinxinwang)\
**Replies:** 5\
**Last updated:** [August 24, 2023, 3:24am UTC](https://discuss.elastic.co/t/when-the-number-of-documents-exceeds-2-billion-the-index-status-becomes-red/341461 "2023-08-24T03:24:29Z")

</div>

Version: 7.8.1 Cause of failure: The number of important index documents in the 7.8.1 open source version of ES has reached the limit of 2147483519 in Lucene. The index status is red, and read and write operations canno…

---

## [Blocklist not working as expected](https://discuss.elastic.co/t/blocklist-not-working-as-expected/341465)

<div class="topic-metadata">

**Author:** [@Krishna\_Teja](https://discuss.elastic.co/u/Krishna_Teja)\
**Replies:** 2\
**Last updated:** [August 24, 2023, 2:10am UTC](https://discuss.elastic.co/t/blocklist-not-working-as-expected/341465 "2023-08-24T02:10:47Z")

</div>

I added an application to blocklist. Ensured malware protections and blocklist are enabled for the policy. Even after hours of adding, I'm still able to run the application.

---

## [Connectors-python mysql - selfsigned SSL can not verify](https://discuss.elastic.co/t/connectors-python-mysql-selfsigned-ssl-can-not-verify/341512)

<div class="topic-metadata">

**Author:** [@lenny1](https://discuss.elastic.co/u/lenny1)\
**Replies:** 1\
**Last updated:** [August 24, 2023, 12:08am UTC](https://discuss.elastic.co/t/connectors-python-mysql-selfsigned-ssl-can-not-verify/341512 "2023-08-24T00:08:55Z")

</div>

Hello, when I try to connect to our mysql / mariadb database instance using SSL and providing the CA-cert.pem file of the selfsigned certificate, the connectors-python connector outputs an error that the selfsigned SSL …

---

## [Optimizing ElasticSearch startup time for CI](https://discuss.elastic.co/t/optimizing-elasticsearch-startup-time-for-ci/341516)

<div class="topic-metadata">

**Author:** [@blindsnowmobile](https://discuss.elastic.co/u/blindsnowmobile)\
**Replies:** 0\
**Last updated:** [August 23, 2023, 9:11pm UTC](https://discuss.elastic.co/t/optimizing-elasticsearch-startup-time-for-ci/341516 "2023-08-23T21:11:20Z")

</div>

We use Elasticsearch in our integration tests, which run many times every day. Running ES in this way has a different set of requirements than in our production environment. We need ES to start as fast as possible with…

---

## [Elastic Agent stopped sending ssh failed logs](https://discuss.elastic.co/t/elastic-agent-stopped-sending-ssh-failed-logs/341369)

<div class="topic-metadata">

**Author:** [@hoomant](https://discuss.elastic.co/u/hoomant)\
**Replies:** 1\
**Last updated:** [August 23, 2023, 6:04pm UTC](https://discuss.elastic.co/t/elastic-agent-stopped-sending-ssh-failed-logs/341369 "2023-08-23T18:04:32Z")

</div>

Hi I have setup elastic agent in an elasticsearch 8.7 environment and up to a few days ago everything was working fine but now it is not sending the ssh failed events to the elasticsearch which was a no problem in previo…

---

## [Data parse from multiple rsyslog to logstash to elasticsearch](https://discuss.elastic.co/t/data-parse-from-multiple-rsyslog-to-logstash-to-elasticsearch/341506)

<div class="topic-metadata">

**Author:** [@ermilan2309](https://discuss.elastic.co/u/ermilan2309)\
**Replies:** 0\
**Last updated:** [August 23, 2023, 5:38pm UTC](https://discuss.elastic.co/t/data-parse-from-multiple-rsyslog-to-logstash-to-elasticsearch/341506 "2023-08-23T17:38:28Z")

</div>

Hello, I am new to ELK. I have deployed my ELK with this article. https://www.digitalocean.com/community/tutorials/how-to-install-elasticsearch-logstash-and-kibana-elastic-stack-on-ubuntu-22-04 I skipped the nginx par…

---

## [Kibana not opening up in elastic on demand](https://discuss.elastic.co/t/kibana-not-opening-up-in-elastic-on-demand/341281)

<div class="topic-metadata">

**Author:** [@regepiyu](https://discuss.elastic.co/u/regepiyu)\
**Replies:** 3\
**Last updated:** [August 23, 2023, 4:53pm UTC](https://discuss.elastic.co/t/kibana-not-opening-up-in-elastic-on-demand/341281 "2023-08-23T16:53:37Z")

</div>

Course: Elasticsearch Engineer (On Demand) Version: \<And which particular version?\> Question: I was using Kibana 1 and Kibana2 terminals in the on demand course. Suddenly it stopped working and getting DNS error. se…

---

## [Lab material accessibility issues](https://discuss.elastic.co/t/lab-material-accessibility-issues/341484)

<div class="topic-metadata">

**Author:** [@halamrii](https://discuss.elastic.co/u/halamrii)\
**Replies:** 1\
**Last updated:** [August 23, 2023, 4:43pm UTC](https://discuss.elastic.co/t/lab-material-accessibility-issues/341484 "2023-08-23T16:43:00Z")

</div>

Course: Elasticsearch engineer Question: My strigo account has expired, and i am currently looking for the Lab material for the Elasticsearch engineer (on-demand) course. Note that i have access to the course material …

---

## [Logstash stops processing AWS WAF logs when fields exceed 1000 (or any number)](https://discuss.elastic.co/t/logstash-stops-processing-aws-waf-logs-when-fields-exceed-1000-or-any-number/341497)

<div class="topic-metadata">

**Author:** [@feo13](https://discuss.elastic.co/u/feo13)\
**Replies:** 4\
**Last updated:** [August 23, 2023, 4:41pm UTC](https://discuss.elastic.co/t/logstash-stops-processing-aws-waf-logs-when-fields-exceed-1000-or-any-number/341497 "2023-08-23T16:41:41Z")

</div>

Hi there, I'm ingesting AWS WAF logs and it works fine for a few minutes but then stops with the following error: response=\>{"index"=\>{"\_index"=\>"waf-logs-2023.08.01", "\_id"=\>"rjCKGYoBsxYs-jwL007l", "status"=\>400, "err…

---

## [About Kibana UI](https://discuss.elastic.co/t/about-kibana-ui/340993)

<div class="topic-metadata">

**Author:** [@Vamsi\_Ramisetti](https://discuss.elastic.co/u/Vamsi_Ramisetti)\
**Replies:** 2\
**Last updated:** [August 23, 2023, 2:55pm UTC](https://discuss.elastic.co/t/about-kibana-ui/340993 "2023-08-23T14:55:58Z")

</div>

In Kibana UI in the above uploaded image the document filed is showing empty but the timestamp is displaying. The logs is coming but not displaying in the document field

---

## [Is reading elastic logs from a node directly possible?](https://discuss.elastic.co/t/is-reading-elastic-logs-from-a-node-directly-possible/341473)

<div class="topic-metadata">

**Author:** [@mscch](https://discuss.elastic.co/u/mscch)\
**Replies:** 2\
**Last updated:** [August 23, 2023, 1:41pm UTC](https://discuss.elastic.co/t/is-reading-elastic-logs-from-a-node-directly-possible/341473 "2023-08-23T13:41:19Z")

</div>

Hi all Is there a way to read logs (sent to elastic by Logstash) directly from an Elasticsearch node? Our Elasticsearch version is 8.30. Because of a Ransomware attack, we currently do not have access to the Kibana VM.…

---

## [Security exception for remote cluster calls](https://discuss.elastic.co/t/security-exception-for-remote-cluster-calls/341395)

<div class="topic-metadata">

**Author:** [@darshanypatel](https://discuss.elastic.co/u/darshanypatel)\
**Replies:** 2\
**Last updated:** [August 23, 2023, 12:07pm UTC](https://discuss.elastic.co/t/security-exception-for-remote-cluster-calls/341395 "2023-08-23T12:07:41Z")

</div>

I have a local & a remote cluster running on the same host (localhost) to be used by the integration tests. It is basically a sidecar container running ES. These tests were passing for ES version 7.16.2, but when I tried…

---

## [Insert data into a field where data contains some text between dollar and flower brackets](https://discuss.elastic.co/t/insert-data-into-a-field-where-data-contains-some-text-between-dollar-and-flower-brackets/341444)

<div class="topic-metadata">

**Author:** [@Madhuri\_Desai](https://discuss.elastic.co/u/Madhuri_Desai)\
**Replies:** 1\
**Last updated:** [August 23, 2023, 10:57am UTC](https://discuss.elastic.co/t/insert-data-into-a-field-where-data-contains-some-text-between-dollar-and-flower-brackets/341444 "2023-08-23T10:57:11Z")

</div>

I need help with an issue that I am facing while inserting data into one of elastic index. Im trying to insert data from a log file into elastic and that file contains some text within dollar and flower brackets. Examp…

[Previous page](https://discuss.elastic.co/tag/none.md?no_tags=true&page=315)

[Next page](https://discuss.elastic.co/tag/none.md?no_tags=true&page=317)
