# \#none

**URL:** https://discuss.elastic.co/tag/none.md?no_tags=true&page=323

[Latest](https://discuss.elastic.co/latest.md) · [Categories](https://discuss.elastic.co/categories.md) · [Tags](https://discuss.elastic.co/tags.md)

**Page:** 324

---

## [Query for an event that happens X times within a given timerange](https://discuss.elastic.co/t/query-for-an-event-that-happens-x-times-within-a-given-timerange/340550)

<div class="topic-metadata">

**Author:** [@blacklistme](https://discuss.elastic.co/u/blacklistme)\
**Replies:** 3\
**Last updated:** [August 10, 2023, 3:17pm UTC](https://discuss.elastic.co/t/query-for-an-event-that-happens-x-times-within-a-given-timerange/340550 "2023-08-10T15:17:51Z")

</div>

Hi, as the title already suggests, I am looking for a way in Kibana to generate an Seucurity-Alert, if one event ouccures x times within a given timespan. Example: Five Failed logins on a system within 5 Minutes I´ve …

---

## [Urgent Query: Upgrading Kibana from version 7.9.0 to 8.9.0](https://discuss.elastic.co/t/urgent-query-upgrading-kibana-from-version-7-9-0-to-8-9-0/340561)

<div class="topic-metadata">

**Author:** [@Prathamesh\_S\_Pai](https://discuss.elastic.co/u/Prathamesh_S_Pai)\
**Replies:** 1\
**Last updated:** [August 10, 2023, 2:57pm UTC](https://discuss.elastic.co/t/urgent-query-upgrading-kibana-from-version-7-9-0-to-8-9-0/340561 "2023-08-10T14:57:57Z")

</div>

I have been using Kibana version 7.9.0 for my tasks. I would like to upgrade it to the latest version, 8.9.0, as some features supported by the latest version are urgently required. Could you please let me know if upgra…

---

## [Logstash JSON Filter Error](https://discuss.elastic.co/t/logstash-json-filter-error/340496)

<div class="topic-metadata">

**Author:** [@wwalker](https://discuss.elastic.co/u/wwalker)\
**Replies:** 2\
**Last updated:** [August 10, 2023, 2:25pm UTC](https://discuss.elastic.co/t/logstash-json-filter-error/340496 "2023-08-10T14:25:22Z")

</div>

I've pulled data from a SQL database that gets put into a field like below. "assignment": \[ { "assignedto": "1234", "assignedtoname": "John Doe", "assignedgroupid": 1 } \] I'm…

---

## [ElasticsearchException connection refused](https://discuss.elastic.co/t/elasticsearchexception-connection-refused/340567)

<div class="topic-metadata">

**Author:** [@Hanane1](https://discuss.elastic.co/u/Hanane1)\
**Replies:** 0\
**Last updated:** [August 10, 2023, 1:42pm UTC](https://discuss.elastic.co/t/elasticsearchexception-connection-refused/340567 "2023-08-10T13:42:10Z")

</div>

Hello, I have this error when I try to search for something using elasticsearch Caused by: org.springframework.data.elasticsearch.UncategorizedElasticsearchException: java.util.concurrent.ExecutionException: java.net.C…

---

## [ES performance improvement after restarting ES instance?](https://discuss.elastic.co/t/es-performance-improvement-after-restarting-es-instance/340564)

<div class="topic-metadata">

**Author:** [@hyt](https://discuss.elastic.co/u/hyt)\
**Replies:** 0\
**Last updated:** [August 10, 2023, 1:29pm UTC](https://discuss.elastic.co/t/es-performance-improvement-after-restarting-es-instance/340564 "2023-08-10T13:29:12Z")

</div>

I encountered a strange phenomenon where the Elasticsearch instance performed better after restarting it during performance testing with esrally. i don't know why? esrally ：v2.6.0 （official http\_logs track） es : v7.17.…

---

## [Job fails injecting dataframe with variables in index name](https://discuss.elastic.co/t/job-fails-injecting-dataframe-with-variables-in-index-name/340370)

<div class="topic-metadata">

**Author:** [@Joachim\_Rodrigues](https://discuss.elastic.co/u/Joachim_Rodrigues)\
**Replies:** 1\
**Last updated:** [August 10, 2023, 1:08pm UTC](https://discuss.elastic.co/t/job-fails-injecting-dataframe-with-variables-in-index-name/340370 "2023-08-10T13:08:57Z")

</div>

Hello I have this code that injects a dataframe to an elastic cluster 7.9.3 myDataframe.saveToEs("customer-{year}.{month}") But i'm getting this error : User class threw exception: java.lang.Exception: Error(s) durin…

---

## [Please share your wisdom: Passing Elastic key/value pairs instead of log statements?](https://discuss.elastic.co/t/please-share-your-wisdom-passing-elastic-key-value-pairs-instead-of-log-statements/340489)

<div class="topic-metadata">

**Author:** [@McJava1967](https://discuss.elastic.co/u/McJava1967)\
**Replies:** 2\
**Last updated:** [August 10, 2023, 12:57pm UTC](https://discuss.elastic.co/t/please-share-your-wisdom-passing-elastic-key-value-pairs-instead-of-log-statements/340489 "2023-08-10T12:57:38Z")

</div>

Hi all. I'm looking for some very general advice. I know ELK started as a way to make sense of log statements, like: "We shipped 12 yellow rubber duckies to France". It will pick out "yellow", "rubber" and "duckies",…

---

## [Open Search Contexts Not Closed After Expiration](https://discuss.elastic.co/t/open-search-contexts-not-closed-after-expiration/340557)

<div class="topic-metadata">

**Author:** [@Jaeger\_Jochimsen](https://discuss.elastic.co/u/Jaeger_Jochimsen)\
**Replies:** 0\
**Last updated:** [August 10, 2023, 12:25pm UTC](https://discuss.elastic.co/t/open-search-contexts-not-closed-after-expiration/340557 "2023-08-10T12:25:54Z")

</div>

We recently had a sudden surge in open search contexts as a result of initiating many scrolls without iterating on them or closing them explicitly. Even though scroll time to live was set to 2 min we continued to have to…

---

## [WARN messages in elsasticsearch.log CFF/OTF](https://discuss.elastic.co/t/warn-messages-in-elsasticsearch-log-cff-otf/340547)

<div class="topic-metadata">

**Author:** [@shayshy](https://discuss.elastic.co/u/shayshy)\
**Replies:** 3\
**Last updated:** [August 10, 2023, 12:22pm UTC](https://discuss.elastic.co/t/warn-messages-in-elsasticsearch-log-cff-otf/340547 "2023-08-10T12:22:21Z")

</div>

I have lots of WARN Messages in elasticsearch.log org.apache.pdfbox.pdmodel.font.PDCIDFontType2 WARNING: Found CFF/OTF but expected embedded TTF fount Generic3-Regular and also POI does not currently support template…

---

## [AWS target group health check configuration for application load balancer](https://discuss.elastic.co/t/aws-target-group-health-check-configuration-for-application-load-balancer/340553)

<div class="topic-metadata">

**Author:** [@akansha](https://discuss.elastic.co/u/akansha)\
**Replies:** 0\
**Last updated:** [August 10, 2023, 11:35am UTC](https://discuss.elastic.co/t/aws-target-group-health-check-configuration-for-application-load-balancer/340553 "2023-08-10T11:35:34Z")

</div>

I need to expose kibana through application load balancer , i have created one but the problem is health check for target group is failing , what should I do to resolve this?

---

## [Discovery service as endpoint provider not recognised](https://discuss.elastic.co/t/discovery-service-as-endpoint-provider-not-recognised/340512)

<div class="topic-metadata">

**Author:** [@nealder](https://discuss.elastic.co/u/nealder)\
**Replies:** 3\
**Last updated:** [August 10, 2023, 10:14am UTC](https://discuss.elastic.co/t/discovery-service-as-endpoint-provider-not-recognised/340512 "2023-08-10T10:14:52Z")

</div>

Hi Everyone, I have submitted a bug ticket on github, but I got redirected here. Here is the ticket. In short I found that the 'discovery.zen.ping.unicast.host' could resolve IP addresses of nodes in my cluster via dis…

---

## [The commercial usage of ELK stack in Russia today](https://discuss.elastic.co/t/the-commercial-usage-of-elk-stack-in-russia-today/340545)

<div class="topic-metadata">

**Author:** [@Abbey\_Monk](https://discuss.elastic.co/u/Abbey_Monk)\
**Replies:** 0\
**Last updated:** [August 10, 2023, 10:12am UTC](https://discuss.elastic.co/t/the-commercial-usage-of-elk-stack-in-russia-today/340545 "2023-08-10T10:12:39Z")

</div>

Hi, guys! Could we use ELK for free in Russia for the commercial purposes today? Thank you for your assistance.

---

## [The issue of data corruption in Logstash's Netflow plugin under high data concurrency](https://discuss.elastic.co/t/the-issue-of-data-corruption-in-logstashs-netflow-plugin-under-high-data-concurrency/340541)

<div class="topic-metadata">

**Author:** [@chenlx594](https://discuss.elastic.co/u/chenlx594)\
**Replies:** 0\
**Last updated:** [August 10, 2023, 10:02am UTC](https://discuss.elastic.co/t/the-issue-of-data-corruption-in-logstashs-netflow-plugin-under-high-data-concurrency/340541 "2023-08-10T10:02:38Z")

</div>

The Logstash Netflow plugin encounters a problem of misinterpreted fields like first\_switched , last\_switched , and bytes under a netflow data copy rate of 0.4 Gbps. How can this issue be resolved?

---

## [Getting 403 denied to elastic.co](https://discuss.elastic.co/t/getting-403-denied-to-elastic-co/339534)

<div class="topic-metadata">

**Author:** [@AlexandrK](https://discuss.elastic.co/u/AlexandrK)\
**Replies:** 3\
**Last updated:** [August 10, 2023, 9:58am UTC](https://discuss.elastic.co/t/getting-403-denied-to-elastic-co/339534 "2023-08-10T09:58:32Z")

</div>

Hello! My company's IP address was blocked by mistake. I wrote in a topic that deals with this problem, but the last unlock activity there was on May 1st. I don't know where to write to get my address unblocked Please …

---

## [Isolate a node](https://discuss.elastic.co/t/isolate-a-node/340528)

<div class="topic-metadata">

**Author:** [@Manal\_A](https://discuss.elastic.co/u/Manal_A)\
**Replies:** 1\
**Last updated:** [August 10, 2023, 9:01am UTC](https://discuss.elastic.co/t/isolate-a-node/340528 "2023-08-10T09:01:53Z")

</div>

How can we isolate a node that serves both as a master and data node from a cluster?

---

## [Curl: (77) Problem with the SSL CA cert (path? access rights?)](https://discuss.elastic.co/t/curl-77-problem-with-the-ssl-ca-cert-path-access-rights/338761)

<div class="topic-metadata">

**Author:** [@PodarcisMuralis](https://discuss.elastic.co/u/PodarcisMuralis)\
**Replies:** 4\
**Last updated:** [August 10, 2023, 7:39am UTC](https://discuss.elastic.co/t/curl-77-problem-with-the-ssl-ca-cert-path-access-rights/338761 "2023-08-10T07:39:34Z")

</div>

Hi, I use a shell script to send curl to elasticsearch. But I got this error: curl: (77) Problem with the SSL CA cert (path? access rights?) My curl is like: RESPONSE=$(curl -v -s -w "%{http\_code}" -o /dev/null -XDEL…

---

## [Failed to pull data from Salesforce into logstash](https://discuss.elastic.co/t/failed-to-pull-data-from-salesforce-into-logstash/340503)

<div class="topic-metadata">

**Author:** [@Lazaro\_O\_Farrill](https://discuss.elastic.co/u/Lazaro_O_Farrill)\
**Replies:** 0\
**Last updated:** [August 10, 2023, 3:44am UTC](https://discuss.elastic.co/t/failed-to-pull-data-from-salesforce-into-logstash/340503 "2023-08-10T03:44:35Z")

</div>

I am trying to pull my data from my Salesforce sandbox into logstash, and I am getting the following error. Does anyone have any idea what it might mean? I have tested the credentials directly through the API endpoints a…

---

## [Elasticdump is getting failed for uploading the index into elastic](https://discuss.elastic.co/t/elasticdump-is-getting-failed-for-uploading-the-index-into-elastic/340501)

<div class="topic-metadata">

**Author:** [@shailendra1](https://discuss.elastic.co/u/shailendra1)\
**Replies:** 0\
**Last updated:** [August 10, 2023, 1:38am UTC](https://discuss.elastic.co/t/elasticdump-is-getting-failed-for-uploading-the-index-into-elastic/340501 "2023-08-10T01:38:09Z")

</div>

hello all, i am trying to upload the index dump which i have taken using the elasticdump while uploading i am facing issue, as below - Tue, 08 Aug 2023 10:21:37 GMT | sent 10000 objects to destination elasticsearch, wr…

---

## [Fortigate alerts](https://discuss.elastic.co/t/fortigate-alerts/340499)

<div class="topic-metadata">

**Author:** [@Mbrezzy](https://discuss.elastic.co/u/Mbrezzy)\
**Replies:** 0\
**Last updated:** [August 10, 2023, 12:34am UTC](https://discuss.elastic.co/t/fortigate-alerts/340499 "2023-08-10T00:34:08Z")

</div>

Hello , i would like to set up alerts on fortinet field for example alert if a host sent or receive a large data . Hope you understand what im trying to say thanks

---

## [Documentation - get index api- why there is no info about what api is returning](https://discuss.elastic.co/t/documentation-get-index-api-why-there-is-no-info-about-what-api-is-returning/340495)

<div class="topic-metadata">

**Author:** [@Krzysztof\_Lempicki](https://discuss.elastic.co/u/Krzysztof_Lempicki)\
**Replies:** 0\
**Last updated:** [August 9, 2023, 9:16pm UTC](https://discuss.elastic.co/t/documentation-get-index-api-why-there-is-no-info-about-what-api-is-returning/340495 "2023-08-09T21:16:42Z")

</div>

In doc: Get index information | Elasticsearch API documentation there is no info about what is returned. Is this in purpose? If yes why? For example: From console I see that keys of returned map are index names. With…

---

## [Petclinic Lab Metrics Internal Server Error 500](https://discuss.elastic.co/t/petclinic-lab-metrics-internal-server-error-500/340487)

<div class="topic-metadata">

**Author:** [@lucasyuki](https://discuss.elastic.co/u/lucasyuki)\
**Replies:** 2\
**Last updated:** [August 9, 2023, 8:35pm UTC](https://discuss.elastic.co/t/petclinic-lab-metrics-internal-server-error-500/340487 "2023-08-09T20:35:49Z")

</div>

Course: \<Petclinic Lab 4t?\> I had done the lab until I arrived at the 4th module but as soon as I realized I went to Metrics and I was giving this error (Internal Server Error 500, before it was working

---

## [Kibana RAM usage allocation | ELK running too slow](https://discuss.elastic.co/t/kibana-ram-usage-allocation-elk-running-too-slow/340445)

<div class="topic-metadata">

**Author:** [@theacodes](https://discuss.elastic.co/u/theacodes)\
**Replies:** 1\
**Last updated:** [August 9, 2023, 8:08pm UTC](https://discuss.elastic.co/t/kibana-ram-usage-allocation-elk-running-too-slow/340445 "2023-08-09T20:08:54Z")

</div>

ELK running too slow and in kibana stack monitoring section this is what kibana memory shows my doubt is why it shows 4 gb for kibana when server ram is 64 gb

---

## [Custom integration for a KVM](https://discuss.elastic.co/t/custom-integration-for-a-kvm/340483)

<div class="topic-metadata">

**Author:** [@divygobi](https://discuss.elastic.co/u/divygobi)\
**Replies:** 0\
**Last updated:** [August 9, 2023, 5:30pm UTC](https://discuss.elastic.co/t/custom-integration-for-a-kvm/340483 "2023-08-09T17:30:14Z")

</div>

If I want to monitor user info(through ecs and kibana) from a KVM instance without installing anything on the KVM, would making a custom integration be the right way to do it? If so, how would we get started on that?

---

## [Separate result by category](https://discuss.elastic.co/t/separate-result-by-category/340479)

<div class="topic-metadata">

**Author:** [@Murilo\_Livorato](https://discuss.elastic.co/u/Murilo_Livorato)\
**Replies:** 0\
**Last updated:** [August 9, 2023, 5:05pm UTC](https://discuss.elastic.co/t/separate-result-by-category/340479 "2023-08-09T17:05:07Z")

</div>

Hello , I have nested filed . And I want to bring the result separated by broker , something like this - \[ "broker\_one" =\> \[ result \], "broker\_two" =\> \[ result \] I know that I can aggregate the result , and co…

---

## [Filter and search through python](https://discuss.elastic.co/t/filter-and-search-through-python/340386)

<div class="topic-metadata">

**Author:** [@IamExperimenting\_Now](https://discuss.elastic.co/u/IamExperimenting_Now)\
**Replies:** 3\
**Last updated:** [August 9, 2023, 2:51pm UTC](https://discuss.elastic.co/t/filter-and-search-through-python/340386 "2023-08-09T14:51:49Z")

</div>

Hi, I'm new to elasticsearch, I'm using elasticsearch for semantic search. I have pushed 5pdf files after converting into vector. when I do search i'm not getting right index value. so, I thought I would do the filter …

---

## [Synthetics Agent Options - Playwright Configuration](https://discuss.elastic.co/t/synthetics-agent-options-playwright-configuration/340428)

<div class="topic-metadata">

**Author:** [@aisyaharifin](https://discuss.elastic.co/u/aisyaharifin)\
**Replies:** 1\
**Last updated:** [August 9, 2023, 2:40pm UTC](https://discuss.elastic.co/t/synthetics-agent-options-playwright-configuration/340428 "2023-08-09T14:40:31Z")

</div>

Hello Elastic, I would like to set the timeout to 2 minutes = 120000 ms and do the word checking for Synthetic. This is for a Single Page Browser Test, I would like to do checking if there is a word 'DOWN' appeared in …

---

## [Which version of Kibana do we find "Formula" tab for Metrics visualization?](https://discuss.elastic.co/t/which-version-of-kibana-do-we-find-formula-tab-for-metrics-visualization/340355)

<div class="topic-metadata">

**Author:** [@Prathamesh\_S\_Pai](https://discuss.elastic.co/u/Prathamesh_S_Pai)\
**Replies:** 1\
**Last updated:** [August 9, 2023, 2:09pm UTC](https://discuss.elastic.co/t/which-version-of-kibana-do-we-find-formula-tab-for-metrics-visualization/340355 "2023-08-09T14:09:33Z")

</div>

---

## [Elasticsearch failed Search rejected due to missing shards \[\[.kibana\_task\_manager\_7.17.7\_001\]\[0\]\]](https://discuss.elastic.co/t/elasticsearch-failed-search-rejected-due-to-missing-shards-kibana-task-manager-7-17-7-001-0/340192)

<div class="topic-metadata">

**Author:** [@johnashish](https://discuss.elastic.co/u/johnashish)\
**Replies:** 7\
**Last updated:** [August 9, 2023, 1:42pm UTC](https://discuss.elastic.co/t/elasticsearch-failed-search-rejected-due-to-missing-shards-kibana-task-manager-7-17-7-001-0/340192 "2023-08-09T13:42:03Z")

</div>

Hello, Current Conf - Version - Elasticsearch| Kibana - 7.17.3 2 Node Cluster Recently i am facing lot of trouble to keep the cluster in healthy state. The error which i am facing is - Caused by: org.elasticsearch…

---

## [How can i update the data in index when i have multiple docementId](https://discuss.elastic.co/t/how-can-i-update-the-data-in-index-when-i-have-multiple-docementid/340167)

<div class="topic-metadata">

**Author:** [@Mohit\_Rajput](https://discuss.elastic.co/u/Mohit_Rajput)\
**Replies:** 1\
**Last updated:** [August 9, 2023, 1:06pm UTC](https://discuss.elastic.co/t/how-can-i-update-the-data-in-index-when-i-have-multiple-docementid/340167 "2023-08-09T13:06:34Z")

</div>

How can i update the data in index when i have multiple docementtId?

---

## [Upgrade Elastic Stack 7.15.1 to 7.17.10](https://discuss.elastic.co/t/upgrade-elastic-stack-7-15-1-to-7-17-10/339706)

<div class="topic-metadata">

**Author:** [@SAMY-ELK](https://discuss.elastic.co/u/SAMY-ELK)\
**Replies:** 24\
**Last updated:** [August 9, 2023, 12:50pm UTC](https://discuss.elastic.co/t/upgrade-elastic-stack-7-15-1-to-7-17-10/339706 "2023-08-09T12:50:14Z")

</div>

Hello Team, After Upgrade ELK from 7.15.1 to 7.17.10 : logstash-kibana-filebeat-Elastic search , i can't receive log IIS in KIBANA. when i check log logstash i get this error : " LogStash::PipelineAction::Create/pipel…

[Previous page](https://discuss.elastic.co/tag/none.md?no_tags=true&page=322)

[Next page](https://discuss.elastic.co/tag/none.md?no_tags=true&page=324)
