# \#none

**URL:** https://discuss.elastic.co/tag/none.md?no_tags=true&page=322

[Latest](https://discuss.elastic.co/latest.md) · [Categories](https://discuss.elastic.co/categories.md) · [Tags](https://discuss.elastic.co/tags.md)

**Page:** 323

---

## [Handle retries for bulk api](https://discuss.elastic.co/t/handle-retries-for-bulk-api/340640)

<div class="topic-metadata">

**Author:** [@akhil\_reddy](https://discuss.elastic.co/u/akhil_reddy)\
**Replies:** 1\
**Last updated:** [August 12, 2023, 9:20am UTC](https://discuss.elastic.co/t/handle-retries-for-bulk-api/340640 "2023-08-12T09:20:51Z")

</div>

Hi, I am trying to make a bulk request using BulkRequest in java. I am not finding any documentation to retry the failed requests. Is there any inbuilt functionality in the java client api to handle retries or do I need…

---

## [Why query result cannot be generated all data (csv) of specific days in Elastic Search](https://discuss.elastic.co/t/why-query-result-cannot-be-generated-all-data-csv-of-specific-days-in-elastic-search/340674)

<div class="topic-metadata">

**Author:** [@jt2023](https://discuss.elastic.co/u/jt2023)\
**Replies:** 9\
**Last updated:** [August 12, 2023, 9:14am UTC](https://discuss.elastic.co/t/why-query-result-cannot-be-generated-all-data-csv-of-specific-days-in-elastic-search/340674 "2023-08-12T09:14:11Z")

</div>

why query result cannot be generated all data (csv) of specific days in Elastic Search. For example, i searched for 15,16,17 July data, but only 17July can be generated and displayed in csv file

---

## [Query Precision/Recall vs Sort](https://discuss.elastic.co/t/query-precision-recall-vs-sort/340667)

<div class="topic-metadata">

**Author:** [@RabBit\_BR](https://discuss.elastic.co/u/RabBit_BR)\
**Replies:** 1\
**Last updated:** [August 12, 2023, 7:59am UTC](https://discuss.elastic.co/t/query-precision-recall-vs-sort/340667 "2023-08-12T07:59:55Z")

</div>

I have a catalog of products and I'm facing some problems when I try to sort the results by other criteria than by relevance. Today I can sort the results in order: most recent and most rated. My query has the characte…

---

## [Log.file.path with grok condition issue with multiple log files](https://discuss.elastic.co/t/log-file-path-with-grok-condition-issue-with-multiple-log-files/339600)

<div class="topic-metadata">

**Author:** [@sanjeev1895](https://discuss.elastic.co/u/sanjeev1895)\
**Replies:** 2\
**Last updated:** [August 12, 2023, 6:45am UTC](https://discuss.elastic.co/t/log-file-path-with-grok-condition-issue-with-multiple-log-files/339600 "2023-08-12T06:45:48Z")

</div>

Hi Team, Am I trying to create the index using log.file.path field in the grok if condition. Actually am I including the multiple file path. so while doing this the index was not creating. but if I include only one, the…

---

## [Is is possible to have elasticsearch status return "running" but to get "no alive nodes found in cluster" for the same app?](https://discuss.elastic.co/t/is-is-possible-to-have-elasticsearch-status-return-running-but-to-get-no-alive-nodes-found-in-cluster-for-the-same-app/340670)

<div class="topic-metadata">

**Author:** [@nfanh](https://discuss.elastic.co/u/nfanh)\
**Replies:** 0\
**Last updated:** [August 11, 2023, 11:01pm UTC](https://discuss.elastic.co/t/is-is-possible-to-have-elasticsearch-status-return-running-but-to-get-no-alive-nodes-found-in-cluster-for-the-same-app/340670 "2023-08-11T23:01:39Z")

</div>

is is possible to have elasticsearch status return "running" but to get "no alive nodes found in cluster" for the same app?

---

## [Elastic Engineer Observality LAB 1.2 Heartbeat](https://discuss.elastic.co/t/elastic-engineer-observality-lab-1-2-heartbeat/339973)

<div class="topic-metadata">

**Author:** [@lucasyuki](https://discuss.elastic.co/u/lucasyuki)\
**Replies:** 2\
**Last updated:** [August 11, 2023, 8:11pm UTC](https://discuss.elastic.co/t/elastic-engineer-observality-lab-1-2-heartbeat/339973 "2023-08-11T20:11:13Z")

</div>

Problems with this code, could not create the monitor: job err can not convert object to string heartbeat.monitors: type: http ID used to uniquely identify this monitor in elasticsearch even if the config changes i…

---

## [Access Elasticsearch with HTTPs and HTTP](https://discuss.elastic.co/t/access-elasticsearch-with-https-and-http/340661)

<div class="topic-metadata">

**Author:** [@TomTom](https://discuss.elastic.co/u/TomTom)\
**Replies:** 1\
**Last updated:** [August 11, 2023, 7:53pm UTC](https://discuss.elastic.co/t/access-elasticsearch-with-https-and-http/340661 "2023-08-11T19:53:03Z")

</div>

I configured my Elasticsearch server to be secure, using a proprietary certificate. Similar to the configuration below: # security settings xpack.security.enabled: true xpack.security.autoconfiguration.enabled: false #…

---

## [In Kibana dashboard graph, what is unit of value format being selected as default? I have attached the snapshot below](https://discuss.elastic.co/t/in-kibana-dashboard-graph-what-is-unit-of-value-format-being-selected-as-default-i-have-attached-the-snapshot-below/340242)

<div class="topic-metadata">

**Author:** [@Abhinav\_Sharma](https://discuss.elastic.co/u/Abhinav_Sharma)\
**Replies:** 1\
**Last updated:** [August 11, 2023, 6:38pm UTC](https://discuss.elastic.co/t/in-kibana-dashboard-graph-what-is-unit-of-value-format-being-selected-as-default-i-have-attached-the-snapshot-below/340242 "2023-08-11T18:38:12Z")

</div>

---

## [Split One Lined "Message" field information](https://discuss.elastic.co/t/split-one-lined-message-field-information/340281)

<div class="topic-metadata">

**Author:** [@Jennifer\_Coley](https://discuss.elastic.co/u/Jennifer_Coley)\
**Replies:** 1\
**Last updated:** [August 11, 2023, 6:32pm UTC](https://discuss.elastic.co/t/split-one-lined-message-field-information/340281 "2023-08-11T18:32:58Z")

</div>

Hi, In my dynamic syslogs in eleasticsearch, A fields called "messages" has over 7 lines of data, I need to split that single line into different field. I have a special character "\\r\\n" before required split informatio…

---

## [Elasticsearch cluster search performance is bad after upgrade from 7.17 to 8.8](https://discuss.elastic.co/t/elasticsearch-cluster-search-performance-is-bad-after-upgrade-from-7-17-to-8-8/340592)

<div class="topic-metadata">

**Author:** [@chandra123](https://discuss.elastic.co/u/chandra123)\
**Replies:** 3\
**Last updated:** [August 11, 2023, 5:12pm UTC](https://discuss.elastic.co/t/elasticsearch-cluster-search-performance-is-bad-after-upgrade-from-7-17-to-8-8/340592 "2023-08-11T17:12:56Z")

</div>

Hello Elasticsearch Community, We recently did in-place upgrade from 7.17 to 8.8 and after which we started to see degraded search performance/latency. We have 150 data nodes and we observed that at most 10 data nodes a…

---

## [How to filter the particular timestamp in KQL field](https://discuss.elastic.co/t/how-to-filter-the-particular-timestamp-in-kql-field/340655)

<div class="topic-metadata">

**Author:** [@sanjeev1895](https://discuss.elastic.co/u/sanjeev1895)\
**Replies:** 1\
**Last updated:** [August 11, 2023, 4:58pm UTC](https://discuss.elastic.co/t/how-to-filter-the-particular-timestamp-in-kql-field/340655 "2023-08-11T16:58:34Z")

</div>

Hi Can anyone tell me the how to search the particular timestamp in KQL. Am I using the below format in logstash filter. time\_stamp 11/Aug/2023:16:31:44 +0000 So how to use this time\_stamp field and grep the log…

---

## [ELK Stack into AKS](https://discuss.elastic.co/t/elk-stack-into-aks/339086)

<div class="topic-metadata">

**Author:** [@izbant](https://discuss.elastic.co/u/izbant)\
**Replies:** 6\
**Last updated:** [August 11, 2023, 2:30pm UTC](https://discuss.elastic.co/t/elk-stack-into-aks/339086 "2023-08-11T14:30:11Z")

</div>

Hello, I am trying to deploy ELK Stack with basic license into my AKS cluster, but i am unable to secure connection between logstash and elasticsearch. Is there any documentation for deploying ELK Stack into an AKS clu…

---

## [SAML - Migrate to new IDP](https://discuss.elastic.co/t/saml-migrate-to-new-idp/340534)

<div class="topic-metadata">

**Author:** [@heric](https://discuss.elastic.co/u/heric)\
**Replies:** 2\
**Last updated:** [August 11, 2023, 2:29pm UTC](https://discuss.elastic.co/t/saml-migrate-to-new-idp/340534 "2023-08-11T14:29:14Z")

</div>

Hi All, I have 5 nodes cluster of elasticsearch integrated to SAML IDP. i want to migrate to new SAML IDP but i don't have working test environment to integrate to this new IDP. Below scenario that i can think of, do …

---

## [Msearch with PHP](https://discuss.elastic.co/t/msearch-with-php/340585)

<div class="topic-metadata">

**Author:** [@Murilo\_Livorato](https://discuss.elastic.co/u/Murilo_Livorato)\
**Replies:** 1\
**Last updated:** [August 11, 2023, 1:56pm UTC](https://discuss.elastic.co/t/msearch-with-php/340585 "2023-08-11T13:56:44Z")

</div>

Hello , I am using msearch like this doc - well it is working in kibana . but when I try to do it , in php . does not work . this is my test code - $this-\>elasticSeacrh-\>msearch(\[ …

---

## [If condition for null in json field](https://discuss.elastic.co/t/if-condition-for-null-in-json-field/340475)

<div class="topic-metadata">

**Author:** [@wwalker](https://discuss.elastic.co/u/wwalker)\
**Replies:** 1\
**Last updated:** [August 11, 2023, 12:59pm UTC](https://discuss.elastic.co/t/if-condition-for-null-in-json-field/340475 "2023-08-11T12:59:42Z")

</div>

I'm using the JDBC filter to pull info from a SQL database. If the field is blank, it generates the below: "example": \[ { "contoso": "" } \] I've tried the below to remove the empty field, but i…

---

## [Node roles impact on nodes](https://discuss.elastic.co/t/node-roles-impact-on-nodes/340625)

<div class="topic-metadata">

**Author:** [@Josselin](https://discuss.elastic.co/u/Josselin)\
**Replies:** 2\
**Last updated:** [August 11, 2023, 12:13pm UTC](https://discuss.elastic.co/t/node-roles-impact-on-nodes/340625 "2023-08-11T12:13:10Z")

</div>

Hi, We currently have a really big cluster with 150+ nodes. We are using node attributes to manage the data tiers and our ILM is based on it (node.attr.data). We are currently investigating the impact of migrating to …

---

## [I have a older version of Logstash 7.16.2 , is there a output plugin for email. i dont see it for 7.16.2 version](https://discuss.elastic.co/t/i-have-a-older-version-of-logstash-7-16-2-is-there-a-output-plugin-for-email-i-dont-see-it-for-7-16-2-version/339705)

<div class="topic-metadata">

**Author:** [@AKAM14](https://discuss.elastic.co/u/AKAM14)\
**Replies:** 3\
**Last updated:** [August 11, 2023, 11:06am UTC](https://discuss.elastic.co/t/i-have-a-older-version-of-logstash-7-16-2-is-there-a-output-plugin-for-email-i-dont-see-it-for-7-16-2-version/339705 "2023-08-11T11:06:40Z")

</div>

Hi Team, I have an older version of logstash 7.16.2 and i need install an Email output plugin for it . Is there a plugin available for this version . I see the 7.17.x versions have the output plugins. while i cannot f…

---

## [Obtener datos de una cadena](https://discuss.elastic.co/t/obtener-datos-de-una-cadena/340634)

<div class="topic-metadata">

**Author:** [@JorgeGV](https://discuss.elastic.co/u/JorgeGV)\
**Replies:** 0\
**Last updated:** [August 11, 2023, 10:36am UTC](https://discuss.elastic.co/t/obtener-datos-de-una-cadena/340634 "2023-08-11T10:36:59Z")

</div>

Hola, Tengo un código dentro del modelo de datos que en función de su posición dentro de la cadena indica diferentes conceptos, como puedo separarlo dentro del logstash para diferenciarlos y poder tratarlos como nuevas …

---

## [Poll data ingestion to an index should trigger data ingestion to another index](https://discuss.elastic.co/t/poll-data-ingestion-to-an-index-should-trigger-data-ingestion-to-another-index/340617)

<div class="topic-metadata">

**Author:** [@Sheereen](https://discuss.elastic.co/u/Sheereen)\
**Replies:** 6\
**Last updated:** [August 11, 2023, 10:25am UTC](https://discuss.elastic.co/t/poll-data-ingestion-to-an-index-should-trigger-data-ingestion-to-another-index/340617 "2023-08-11T10:25:00Z")

</div>

Hi, Let's say I have to indices, index\_poll and index\_latest. Index\_poll gets metrics data from devices using logstash and beats. When data is ingested into index\_poll, I want this to trigger the data ingestion/updatio…

---

## [Assign users to APM Agents](https://discuss.elastic.co/t/assign-users-to-apm-agents/340623)

<div class="topic-metadata">

**Author:** [@Namita\_Jaokar](https://discuss.elastic.co/u/Namita_Jaokar)\
**Replies:** 0\
**Last updated:** [August 11, 2023, 8:00am UTC](https://discuss.elastic.co/t/assign-users-to-apm-agents/340623 "2023-08-11T08:00:09Z")

</div>

Hi All, I am using ELK Version 8.6.2 and trying to create separate users for different Java APM Agents. For Example If I have 2 APM Agents namely 1\_agent & 2\_agent and 2 Users User1 and User2. My requirement is such…

---

## [How to create dynamic title in Markdown with Handlebars(mustache)?](https://discuss.elastic.co/t/how-to-create-dynamic-title-in-markdown-with-handlebars-mustache/339173)

<div class="topic-metadata">

**Author:** [@Aigerim\_Kubanychbeko](https://discuss.elastic.co/u/Aigerim_Kubanychbeko)\
**Replies:** 2\
**Last updated:** [August 11, 2023, 7:50am UTC](https://discuss.elastic.co/t/how-to-create-dynamic-title-in-markdown-with-handlebars-mustache/339173 "2023-08-11T07:50:37Z")

</div>

I wonder if there any way to create dynamic title in the TVSB visualization using Markdown and Handlebars. This visualization is a part of the dashboard. Whenever I filter particular field: title.keyword is ... this tit…

---

## [Auditbeat failed to load rules on aarch64/ARM 64 bits](https://discuss.elastic.co/t/auditbeat-failed-to-load-rules-on-aarch64-arm-64-bits/340612)

<div class="topic-metadata">

**Author:** [@albertchen](https://discuss.elastic.co/u/albertchen)\
**Replies:** 0\
**Last updated:** [August 11, 2023, 5:47am UTC](https://discuss.elastic.co/t/auditbeat-failed-to-load-rules-on-aarch64-arm-64-bits/340612 "2023-08-11T05:47:56Z")

</div>

Hi sir, When I try to load the following rules on aarch64 platform (ARM 64 bits) -a always,exit -F arch=b64 -S open,creat,truncate,ftruncate,openat,open\_by\_handle\_at -F exit=-EACCES -k access -a always,exit -F arch=b64…

---

## [Ruby code include?](https://discuss.elastic.co/t/ruby-code-include/340336)

<div class="topic-metadata">

**Author:** [@michaelv](https://discuss.elastic.co/u/michaelv)\
**Replies:** 6\
**Last updated:** [August 11, 2023, 5:48am UTC](https://discuss.elastic.co/t/ruby-code-include/340336 "2023-08-11T05:48:03Z")

</div>

Hi All, I have this code that used to be working in ELK 7.12 now that I've upgrade to 8.7.1 it gives a weird error in logstash code =\> " ip\_src = Array.new ip\_…

---

## [Metricbeat](https://discuss.elastic.co/t/metricbeat/340611)

<div class="topic-metadata">

**Author:** [@Rahul\_Kumar\_Jaiswal](https://discuss.elastic.co/u/Rahul_Kumar_Jaiswal)\
**Replies:** 0\
**Last updated:** [August 11, 2023, 5:30am UTC](https://discuss.elastic.co/t/metricbeat/340611 "2023-08-11T05:30:23Z")

</div>

How to get the cpu and memory usage of each users in "CPU Usage \[Metricbeat System\] ECS in ELK" and "Memory Usage \[Metricbeat System\] ECS in ELK". Right now it is showing the metric of 'user' fields which contains all th…

---

## [Upgrading component template logs-settings failed after update to 8.9](https://discuss.elastic.co/t/upgrading-component-template-logs-settings-failed-after-update-to-8-9/340606)

<div class="topic-metadata">

**Author:** [@jordan](https://discuss.elastic.co/u/jordan)\
**Replies:** 0\
**Last updated:** [August 11, 2023, 4:15am UTC](https://discuss.elastic.co/t/upgrading-component-template-logs-settings-failed-after-update-to-8-9/340606 "2023-08-11T04:15:42Z")

</div>

After updating elasticsearch cloud service from version 8.6 to 8.9.0 I want to share the following issue, that's showing up in logs every 30 minutes: \[instance-0000000005\] upgrading component template \[logs-settings\] fo…

---

## [Kibana 8.9.0 Something went wrong :e.replaceAll is not a function](https://discuss.elastic.co/t/kibana-8-9-0-something-went-wrong-e-replaceall-is-not-a-function/340601)

<div class="topic-metadata">

**Author:** [@ss\_s](https://discuss.elastic.co/u/ss_s)\
**Replies:** 1\
**Last updated:** [August 11, 2023, 2:53am UTC](https://discuss.elastic.co/t/kibana-8-9-0-something-went-wrong-e-replaceall-is-not-a-function/340601 "2023-08-11T02:53:27Z")

</div>

Hey Elastic Community team, When I open Kibana on the web after login.This error occurred i try to refreshing the page,but the error continued； Microsoft Edge 84.0.522.52

---

## [Decentralised architecture with elastic SIEM](https://discuss.elastic.co/t/decentralised-architecture-with-elastic-siem/340598)

<div class="topic-metadata">

**Author:** [@kafikone](https://discuss.elastic.co/u/kafikone)\
**Replies:** 1\
**Last updated:** [August 11, 2023, 2:15am UTC](https://discuss.elastic.co/t/decentralised-architecture-with-elastic-siem/340598 "2023-08-11T02:15:07Z")

</div>

Hi all I have a concern and I would like to have some leads if possible. I'd like to know if it's possible for elastic agents installed on machines at a company site in town A, for example, to be able to send logs to t…

---

## [Fuzzy search](https://discuss.elastic.co/t/fuzzy-search/340584)

<div class="topic-metadata">

**Author:** [@moep](https://discuss.elastic.co/u/moep)\
**Replies:** 0\
**Last updated:** [August 10, 2023, 6:17pm UTC](https://discuss.elastic.co/t/fuzzy-search/340584 "2023-08-10T18:17:37Z")

</div>

Hey there, I take in to a project into elasticsearch. The task is a webshop. Right now the problem is, that its possible to search for foo 40 Liter but its not possible for search for foo 40L. My next step is, to use lo…

---

## [How to calculate number of licenses count for my Elastic cluster](https://discuss.elastic.co/t/how-to-calculate-number-of-licenses-count-for-my-elastic-cluster/340583)

<div class="topic-metadata">

**Author:** [@hiruni.insyncit.net](https://discuss.elastic.co/u/hiruni.insyncit.net)\
**Replies:** 1\
**Last updated:** [August 10, 2023, 6:14pm UTC](https://discuss.elastic.co/t/how-to-calculate-number-of-licenses-count-for-my-elastic-cluster/340583 "2023-08-10T18:14:33Z")

</div>

Hi, I want to know what criteria are going to apply, when calculating the number of licenses for my Elastic cluster. Thank you..! Hiruni

---

## [SIEM LAB02 Zeek instalation error](https://discuss.elastic.co/t/siem-lab02-zeek-instalation-error/340194)

<div class="topic-metadata">

**Author:** [@Renato\_Arraes](https://discuss.elastic.co/u/Renato_Arraes)\
**Replies:** 1\
**Last updated:** [August 10, 2023, 4:49pm UTC](https://discuss.elastic.co/t/siem-lab02-zeek-instalation-error/340194 "2023-08-10T16:49:09Z")

</div>

Course: Elastic Security Fundamentals: SIEM Version: current Question: On lab 2 during the installation of zeek, there's a point in wich is requested to run a zeek.sh file, but when i try to run it, i receive the error…

[Previous page](https://discuss.elastic.co/tag/none.md?no_tags=true&page=321)

[Next page](https://discuss.elastic.co/tag/none.md?no_tags=true&page=323)
