# \#none

**URL:** https://discuss.elastic.co/tag/none.md?no_tags=true&page=317

[Latest](https://discuss.elastic.co/latest.md) · [Categories](https://discuss.elastic.co/categories.md) · [Tags](https://discuss.elastic.co/tags.md)

**Page:** 318

---

## [Elastic Uptime - Best Practices](https://discuss.elastic.co/t/elastic-uptime-best-practices/340907)

<div class="topic-metadata">

**Author:** [@serkol](https://discuss.elastic.co/u/serkol)\
**Replies:** 3\
**Last updated:** [August 23, 2023, 10:47am UTC](https://discuss.elastic.co/t/elastic-uptime-best-practices/340907 "2023-08-23T10:47:56Z")

</div>

Hello Dear Community, I'm planning to set up Elastic Uptime in three different locations to monitor the response times of services. The goal is to track how the response times of services in our data centers change ove…

---

## [Nested Aggregation not returning document count](https://discuss.elastic.co/t/nested-aggregation-not-returning-document-count/341454)

<div class="topic-metadata">

**Author:** [@Raju\_Yadav](https://discuss.elastic.co/u/Raju_Yadav)\
**Replies:** 0\
**Last updated:** [August 23, 2023, 9:49am UTC](https://discuss.elastic.co/t/nested-aggregation-not-returning-document-count/341454 "2023-08-23T09:49:56Z")

</div>

i have a product document and that product is published into various eCommerce website like amazon , flipkart as shown in location field. The product published is a nested field in Elasticsearch. now i want to aggregate …

---

## [Problem with accessing elastic from Hetzner](https://discuss.elastic.co/t/problem-with-accessing-elastic-from-hetzner/341446)

<div class="topic-metadata">

**Author:** [@scolak](https://discuss.elastic.co/u/scolak)\
**Replies:** 1\
**Last updated:** [August 23, 2023, 9:44am UTC](https://discuss.elastic.co/t/problem-with-accessing-elastic-from-hetzner/341446 "2023-08-23T09:44:30Z")

</div>

Hi, I have an issue with accessing elastic from Hetzner Finland servers. Whenever I try update or install I get 403 Forbidden. Can you check if the IP range si blocked (95.217.198.0/24)? Thank you

---

## [Why is fast bulk than single indexing in elasticsearch](https://discuss.elastic.co/t/why-is-fast-bulk-than-single-indexing-in-elasticsearch/341339)

<div class="topic-metadata">

**Author:** [@slowup](https://discuss.elastic.co/u/slowup)\
**Replies:** 11\
**Last updated:** [August 23, 2023, 9:42am UTC](https://discuss.elastic.co/t/why-is-fast-bulk-than-single-indexing-in-elasticsearch/341339 "2023-08-23T09:42:00Z")

</div>

I wonder why bulk indexing is faster than single indexing. I'm curious from the point of view of elasticsearch, other than being connected and closed and network communication problems. Based on the default refresh tim…

---

## [Logstash runs forever but no index got created](https://discuss.elastic.co/t/logstash-runs-forever-but-no-index-got-created/341428)

<div class="topic-metadata">

**Author:** [@uma\_parvathy](https://discuss.elastic.co/u/uma_parvathy)\
**Replies:** 0\
**Last updated:** [August 23, 2023, 6:13am UTC](https://discuss.elastic.co/t/logstash-runs-forever-but-no-index-got-created/341428 "2023-08-23T06:13:30Z")

</div>

Hi All, I'm using the below configuration in logstash to populate the data on Elasticsearch 7.17.11 from logstash 7.17.12. It shows pipeline started but no index got created . input { jdbc { jdbc\_driver\_li…

---

## [Huge Segments filling up heap](https://discuss.elastic.co/t/huge-segments-filling-up-heap/341317)

<div class="topic-metadata">

**Author:** [@sreekanth\_makam](https://discuss.elastic.co/u/sreekanth_makam)\
**Replies:** 3\
**Last updated:** [August 23, 2023, 5:25am UTC](https://discuss.elastic.co/t/huge-segments-filling-up-heap/341317 "2023-08-23T05:25:34Z")

</div>

In our cluster, We have 6 node each with 30GB heap. We have around 30 indices each with few Millions of docs. Index structure is very very small with just 10 fileds. Each index size is hardly 5GB. Issue: After ingestin…

---

## [Elasticsearch Interface not loading](https://discuss.elastic.co/t/elasticsearch-interface-not-loading/341399)

<div class="topic-metadata">

**Author:** [@Elk\_huh](https://discuss.elastic.co/u/Elk_huh)\
**Replies:** 1\
**Last updated:** [August 22, 2023, 9:02pm UTC](https://discuss.elastic.co/t/elasticsearch-interface-not-loading/341399 "2023-08-22T21:02:31Z")

</div>

Cluster is green, all nodes are green but yet i cannot open up the interface, it stays as a blank screen, anyone ever run into this ? if I go to the monitoring node, and view the main cluster it loads fine , looks fine

---

## [We couldn't log you in. Please try again - Elastc/Kibana](https://discuss.elastic.co/t/we-couldnt-log-you-in-please-try-again-elastc-kibana/341384)

<div class="topic-metadata">

**Author:** [@Giancarlo\_Huapaya\_Ra](https://discuss.elastic.co/u/Giancarlo_Huapaya_Ra)\
**Replies:** 1\
**Last updated:** [August 22, 2023, 8:39pm UTC](https://discuss.elastic.co/t/we-couldnt-log-you-in-please-try-again-elastc-kibana/341384 "2023-08-22T20:39:21Z")

</div>

Hi, I am trying to log in to my kibana but I get the following message: I have logged in to the server and I get the following error in the log: \[ERROR\]\[plugins.securitySolution.endpoint:user-artifact-packager:1.0.0…

---

## [Unable to start logstash - Tried to load a plugin's code, but failed. {:exception=\>#\<LoadError: no such file to load -- logstash/outputs/microsoft-logstash-output-azure-loganalytics](https://discuss.elastic.co/t/unable-to-start-logstash-tried-to-load-a-plugins-code-but-failed-exception-loaderror-no-such-file-to-load-logstash-outputs-microsoft-logstash-output-azure-loganalytics/341403)

<div class="topic-metadata">

**Author:** [@pavank](https://discuss.elastic.co/u/pavank)\
**Replies:** 2\
**Last updated:** [August 22, 2023, 7:15pm UTC](https://discuss.elastic.co/t/unable-to-start-logstash-tried-to-load-a-plugins-code-but-failed-exception-loaderror-no-such-file-to-load-logstash-outputs-microsoft-logstash-output-azure-loganalytics/341403 "2023-08-22T19:15:37Z")

</div>

Hi We are trying to install the microsoft-logstash-output-azure-loganalytics output plugin to send logs to Azure Log analytics, but getting the following error in Logstash start-up and the Logstash service keeps restart…

---

## [Heartbeat - monitor email domains](https://discuss.elastic.co/t/heartbeat-monitor-email-domains/341306)

<div class="topic-metadata">

**Author:** [@Robin020](https://discuss.elastic.co/u/Robin020)\
**Replies:** 4\
**Last updated:** [August 22, 2023, 6:50pm UTC](https://discuss.elastic.co/t/heartbeat-monitor-email-domains/341306 "2023-08-22T18:50:44Z")

</div>

Hello, I am trying to monitor email domains (with heartbeat) for example: - type: tcp name: TLS\_CHECK schedule: '@every 30s' hosts: \["tls://mx.example.com"\] ports: \[25\] Unfortantly this give me the following e…

---

## [Rsyslog and syslog-ng direct logging to Elasticsearch, viable replacement for elastic-agent?](https://discuss.elastic.co/t/rsyslog-and-syslog-ng-direct-logging-to-elasticsearch-viable-replacement-for-elastic-agent/341390)

<div class="topic-metadata">

**Author:** [@Craig\_Rodrigues](https://discuss.elastic.co/u/Craig_Rodrigues)\
**Replies:** 4\
**Last updated:** [August 22, 2023, 4:43pm UTC](https://discuss.elastic.co/t/rsyslog-and-syslog-ng-direct-logging-to-elasticsearch-viable-replacement-for-elastic-agent/341390 "2023-08-22T16:43:26Z")

</div>

rsyslog has a module to send directly to Elasticsearch: syslog-ng also has a module for logging directly to Elasticsearch: https://www.syslog-ng.com/technical-documents/doc/syslog-ng-open-source-edition/3.22/adminis…

---

## [Get most frequent combinations of nested docs](https://discuss.elastic.co/t/get-most-frequent-combinations-of-nested-docs/341397)

<div class="topic-metadata">

**Author:** [@JsRg](https://discuss.elastic.co/u/JsRg)\
**Replies:** 0\
**Last updated:** [August 22, 2023, 4:41pm UTC](https://discuss.elastic.co/t/get-most-frequent-combinations-of-nested-docs/341397 "2023-08-22T16:41:46Z")

</div>

I have a elasticsearch index with nested documents (colors). I would like to have a query with an aggregation, which shows the most frequent combinations of colors. An example: I have three documents \[ { "name": "D…

---

## [Using DataDog's vector to ship logs to ElasticSearch instead of elastic-agent?](https://discuss.elastic.co/t/using-datadogs-vector-to-ship-logs-to-elasticsearch-instead-of-elastic-agent/341388)

<div class="topic-metadata">

**Author:** [@Craig\_Rodrigues](https://discuss.elastic.co/u/Craig_Rodrigues)\
**Replies:** 3\
**Last updated:** [August 22, 2023, 4:29pm UTC](https://discuss.elastic.co/t/using-datadogs-vector-to-ship-logs-to-elasticsearch-instead-of-elastic-agent/341388 "2023-08-22T16:29:19Z")

</div>

DataDog's vector program has a feature which allows you to ship logs directly to Elasticsearch: This looks like this could be used as an alternative to elastic-agent. Does anyone have any experiences to share on usi…

---

## [Elastic agent upgrade 8.7.1 failed](https://discuss.elastic.co/t/elastic-agent-upgrade-8-7-1-failed/341169)

<div class="topic-metadata">

**Author:** [@xqaiviwjxzw](https://discuss.elastic.co/u/xqaiviwjxzw)\
**Replies:** 2\
**Last updated:** [August 22, 2023, 3:40pm UTC](https://discuss.elastic.co/t/elastic-agent-upgrade-8-7-1-failed/341169 "2023-08-22T15:40:04Z")

</div>

Hello ,When I upgraded the elastic agent from 8.5.2 to 8.7.1, the following error occurred, and I have been unable to upgrade to 8.7.1. What is the solution? message: "component gateway-8da30c24: failed to dispatch acti…

---

## [Elasticsearch 8.9.1 - How to extract the self-signed CA and server cert](https://discuss.elastic.co/t/elasticsearch-8-9-1-how-to-extract-the-self-signed-ca-and-server-cert/341304)

<div class="topic-metadata">

**Author:** [@saltspreader](https://discuss.elastic.co/u/saltspreader)\
**Replies:** 2\
**Last updated:** [August 22, 2023, 3:06pm UTC](https://discuss.elastic.co/t/elasticsearch-8-9-1-how-to-extract-the-self-signed-ca-and-server-cert/341304 "2023-08-22T15:06:46Z")

</div>

Hi there, Elasticsearch v 8.9.1 installed via ES apt repo on ubuntu 22.04. I need to extract the self-signed CA and https cert from my elasticsearch 8.9.1 setup to copy to a gitlab instance for https connections. I've …

---

## [Upgrading elastic to 8.8 has resulted in a master node sending out 5 megabytes a second](https://discuss.elastic.co/t/upgrading-elastic-to-8-8-has-resulted-in-a-master-node-sending-out-5-megabytes-a-second/341299)

<div class="topic-metadata">

**Author:** [@data\_smith](https://discuss.elastic.co/u/data_smith)\
**Replies:** 2\
**Last updated:** [August 22, 2023, 2:19pm UTC](https://discuss.elastic.co/t/upgrading-elastic-to-8-8-has-resulted-in-a-master-node-sending-out-5-megabytes-a-second/341299 "2023-08-22T14:19:08Z")

</div>

Usually elastic master nodes send out 100 kilobytes a second of data. But after upgrading the active master is sending out 5 megabytes. There's no known issue but this doesn't seem healthy. It's role is only master.

---

## [Trial License ECK Issues](https://discuss.elastic.co/t/trial-license-eck-issues/341381)

<div class="topic-metadata">

**Author:** [@walberss](https://discuss.elastic.co/u/walberss)\
**Replies:** 0\
**Last updated:** [August 22, 2023, 2:04pm UTC](https://discuss.elastic.co/t/trial-license-eck-issues/341381 "2023-08-22T14:04:16Z")

</div>

Hi guys I'm trying make tests with ldap integration on kubernetes eck and i can change de license from basic to trial, after few seconds the license come back to basic, Has anyone already caught this behavior? {"type":…

---

## [Training lab incorrectly built](https://discuss.elastic.co/t/training-lab-incorrectly-built/341364)

<div class="topic-metadata">

**Author:** [@Craig\_Anderson](https://discuss.elastic.co/u/Craig_Anderson)\
**Replies:** 2\
**Last updated:** [August 22, 2023, 2:06pm UTC](https://discuss.elastic.co/t/training-lab-incorrectly-built/341364 "2023-08-22T14:06:44Z")

</div>

Try to reach out to the training Labs team. I am attending to compile the practice analyst practice exam and it seems that the lab is incorrectly built as I am missing index’s Can any one help

---

## [Threshold detection rule - limitation of group by fields](https://discuss.elastic.co/t/threshold-detection-rule-limitation-of-group-by-fields/338383)

<div class="topic-metadata">

**Author:** [@Poukim0m](https://discuss.elastic.co/u/Poukim0m)\
**Replies:** 3\
**Last updated:** [August 22, 2023, 1:51pm UTC](https://discuss.elastic.co/t/threshold-detection-rule-limitation-of-group-by-fields/338383 "2023-08-22T13:51:54Z")

</div>

Hello, I want to implement a threshold detection rule that aggregates more than 3 fields in the "Group by" section of rule definition. But there seems to be a limitation of 3 fields as i get an error message "Number of …

---

## [High latency issue with inner\_hits](https://discuss.elastic.co/t/high-latency-issue-with-inner-hits/341375)

<div class="topic-metadata">

**Author:** [@Gilat\_Naveh](https://discuss.elastic.co/u/Gilat_Naveh)\
**Replies:** 0\
**Last updated:** [August 22, 2023, 1:46pm UTC](https://discuss.elastic.co/t/high-latency-issue-with-inner-hits/341375 "2023-08-22T13:46:56Z")

</div>

I’m trying to install a new cluster on ECK (version 8.8.1) and I’m having latency issues (~300ms). We already have a similar cluster working in version 6.5.3 (EC2) and for the same query timing is good (~20ms) The quer…

---

## [Microsoft-sentinel-log-analytics-logstash-output-plugin functionality](https://discuss.elastic.co/t/microsoft-sentinel-log-analytics-logstash-output-plugin-functionality/341374)

<div class="topic-metadata">

**Author:** [@shadu88](https://discuss.elastic.co/u/shadu88)\
**Replies:** 0\
**Last updated:** [August 22, 2023, 1:40pm UTC](https://discuss.elastic.co/t/microsoft-sentinel-log-analytics-logstash-output-plugin-functionality/341374 "2023-08-22T13:40:10Z")

</div>

Hello Dear ELKs i was using "microsoft-sentinel-log-analytics-logstash-output-plugin" to forward the logs to azure sentinel but we switched to AMA( azure native) recently but post this switch the amount of logs doubled/…

---

## [Elaticsearch SQL CLI is not working](https://discuss.elastic.co/t/elaticsearch-sql-cli-is-not-working/340615)

<div class="topic-metadata">

**Author:** [@ashishshukla](https://discuss.elastic.co/u/ashishshukla)\
**Replies:** 10\
**Last updated:** [August 22, 2023, 11:41am UTC](https://discuss.elastic.co/t/elaticsearch-sql-cli-is-not-working/340615 "2023-08-22T11:41:02Z")

</div>

Hi Team, I am trying to execute some sql commands from SQL CLI in elasticsearch -8.8.2 but while executing below commands to open SQL CLI ./bin/elasticsearch-sql-cli I am getting below error ERROR: Cannot communicat…

---

## [Geo-distance query to match geo\_point within a given distance of a geopoint](https://discuss.elastic.co/t/geo-distance-query-to-match-geo-point-within-a-given-distance-of-a-geopoint/341356)

<div class="topic-metadata">

**Author:** [@Allen\_Liang](https://discuss.elastic.co/u/Allen_Liang)\
**Replies:** 0\
**Last updated:** [August 22, 2023, 11:27am UTC](https://discuss.elastic.co/t/geo-distance-query-to-match-geo-point-within-a-given-distance-of-a-geopoint/341356 "2023-08-22T11:27:27Z")

</div>

Hello, I'm seeking clarification regarding the distance utilised for filtering documents using the geo-distance query (Geo-distance query | Elasticsearch Guide \[8.9\] | Elastic). In each of my documents, there exists a …

---

## [How to perform with condition divide math operation in elasticsearch](https://discuss.elastic.co/t/how-to-perform-with-condition-divide-math-operation-in-elasticsearch/341329)

<div class="topic-metadata">

**Author:** [@Huy\_Vu\_Quang](https://discuss.elastic.co/u/Huy_Vu_Quang)\
**Replies:** 0\
**Last updated:** [August 22, 2023, 6:54am UTC](https://discuss.elastic.co/t/how-to-perform-with-condition-divide-math-operation-in-elasticsearch/341329 "2023-08-22T06:54:06Z")

</div>

I have a query like this how I perform a query in Elasticsearch with this condition if wager == 0 : payout/1 \>= multiplier else: payout/wager \>= multiplier filter multiplier according to this condition I wrote this …

---

## [How to Optimize time start Logstash with than 100 condition in output](https://discuss.elastic.co/t/how-to-optimize-time-start-logstash-with-than-100-condition-in-output/341335)

<div class="topic-metadata">

**Author:** [@quoctuan2311](https://discuss.elastic.co/u/quoctuan2311)\
**Replies:** 0\
**Last updated:** [August 22, 2023, 7:37am UTC](https://discuss.elastic.co/t/how-to-optimize-time-start-logstash-with-than-100-condition-in-output/341335 "2023-08-22T07:37:58Z")

</div>

Hi, I have built an ES with architect such as picture. And deploy it on AWS EKS. My expected is filebeat will collect logs all pods on EKS. And send it to Logstash. And Logstash will send this to Elasticsearch. At…

---

## [Coerce seems not working](https://discuss.elastic.co/t/coerce-seems-not-working/341019)

<div class="topic-metadata">

**Author:** [@Jan\_Vavra](https://discuss.elastic.co/u/Jan_Vavra)\
**Replies:** 2\
**Last updated:** [August 22, 2023, 7:33am UTC](https://discuss.elastic.co/t/coerce-seems-not-working/341019 "2023-08-22T07:33:54Z")

</div>

I am constructing datetime from directory structure, eg. 2023\\08\\17\\15\\08 represent files stored at 2023-08-17 15:08. I have this logstash.conf that parses each directory name into variables and hours and minutes are opt…

---

## [Index creating through logstash and show on kibana index pattern](https://discuss.elastic.co/t/index-creating-through-logstash-and-show-on-kibana-index-pattern/340972)

<div class="topic-metadata">

**Author:** [@bharti](https://discuss.elastic.co/u/bharti)\
**Replies:** 5\
**Last updated:** [August 22, 2023, 7:05am UTC](https://discuss.elastic.co/t/index-creating-through-logstash-and-show-on-kibana-index-pattern/340972 "2023-08-22T07:05:35Z")

</div>

Hello , I need a help on configuration of logstash output section....i want to create an index and fetch some particular logs on that index...whenever am creating a new index it is not showing on kibana output { if "…

---

## [Failed to retrieve password hash for reserved user \[elastic\]](https://discuss.elastic.co/t/failed-to-retrieve-password-hash-for-reserved-user-elastic/341330)

<div class="topic-metadata">

**Author:** [@nairobi](https://discuss.elastic.co/u/nairobi)\
**Replies:** 0\
**Last updated:** [August 22, 2023, 7:03am UTC](https://discuss.elastic.co/t/failed-to-retrieve-password-hash-for-reserved-user-elastic/341330 "2023-08-22T07:03:20Z")

</div>

I upgraded elasticsearch cluster 7.17 to 8.9 version. I used "yum update elasticsearch" command to upgrade. It is upgraded successfully. But when i try to start elasticsearch, it couldn't start. How can i solve it? e…

---

## [Answers | Practice Exam: Elastic Certified Observability Engineer](https://discuss.elastic.co/t/answers-practice-exam-elastic-certified-observability-engineer/341265)

<div class="topic-metadata">

**Author:** [@AmitKakkad](https://discuss.elastic.co/u/AmitKakkad)\
**Replies:** 1\
**Last updated:** [August 22, 2023, 6:53am UTC](https://discuss.elastic.co/t/answers-practice-exam-elastic-certified-observability-engineer/341265 "2023-08-22T06:53:15Z")

</div>

Course: Elastic Certified Observability Engineer Version: 7.9 Question: Why are there no solutions to this Practice Exam? There were solutions for the "Elastic Certified Analyst Practice Exam". Some of the questions n…

---

## [UDP-input Receiving an encoding value �](https://discuss.elastic.co/t/udp-input-receiving-an-encoding-value/341199)

<div class="topic-metadata">

**Author:** [@aurangzeb99](https://discuss.elastic.co/u/aurangzeb99)\
**Replies:** 7\
**Last updated:** [August 22, 2023, 6:36am UTC](https://discuss.elastic.co/t/udp-input-receiving-an-encoding-value/341199 "2023-08-22T06:36:03Z")

</div>

Hi I am using logstash udp input and in elasticsearch field event.original have true values. but in a document field.DeviceCapabilities value is "�" and for field.PoleCapabilities is empty. fieldname: event.original Va…

[Previous page](https://discuss.elastic.co/tag/none.md?no_tags=true&page=316)

[Next page](https://discuss.elastic.co/tag/none.md?no_tags=true&page=318)
