# \#none

**URL:** https://discuss.elastic.co/tag/none.md?no_tags=true&page=324

[Latest](https://discuss.elastic.co/latest.md) · [Categories](https://discuss.elastic.co/categories.md) · [Tags](https://discuss.elastic.co/tags.md)

**Page:** 325

---

## [JVM for logstash](https://discuss.elastic.co/t/jvm-for-logstash/340424)

<div class="topic-metadata">

**Author:** [@yuswanul](https://discuss.elastic.co/u/yuswanul)\
**Replies:** 5\
**Last updated:** [August 9, 2023, 12:48pm UTC](https://discuss.elastic.co/t/jvm-for-logstash/340424 "2023-08-09T12:48:48Z")

</div>

Hi there, just want to confirm, is there any limit for JVM for logstash? if the JVM limit for elastic is 30 - 32 GB, does it also apply for logstash? Thanks

---

## [Elasticsearch v2.3 disk throughput Throttle](https://discuss.elastic.co/t/elasticsearch-v2-3-disk-throughput-throttle/340453)

<div class="topic-metadata">

**Author:** [@ram\_222](https://discuss.elastic.co/u/ram_222)\
**Replies:** 3\
**Last updated:** [August 9, 2023, 11:58am UTC](https://discuss.elastic.co/t/elasticsearch-v2-3-disk-throughput-throttle/340453 "2023-08-09T11:58:02Z")

</div>

we are currently using Elasticsearch v2.3 Cluster configuration Details: 3 master Nodes ( t2.medium.search ) and 9 Data Nodes ( r4.xlarge.search ) EBS changed from gp2 to Provision IOPS Storage is 250 Gib/Node CPU Ut…

---

## [Trace Apache Webserver to Python application](https://discuss.elastic.co/t/trace-apache-webserver-to-python-application/337757)

<div class="topic-metadata">

**Author:** [@Dixit](https://discuss.elastic.co/u/Dixit)\
**Replies:** 7\
**Last updated:** [August 9, 2023, 9:41am UTC](https://discuss.elastic.co/t/trace-apache-webserver-to-python-application/337757 "2023-08-09T09:41:17Z")

</div>

hi Team, There is a need to trace the Request from Apache WebServer to Python Backend (Zope). How can we utilize Elastic APM to trace the request from Apache Webserver (entry point), already ZOPE (python backend) we ha…

---

## [How Elasticsearch works with OIDC realm](https://discuss.elastic.co/t/how-elasticsearch-works-with-oidc-realm/340442)

<div class="topic-metadata">

**Author:** [@Aniket\_Pant](https://discuss.elastic.co/u/Aniket_Pant)\
**Replies:** 0\
**Last updated:** [August 9, 2023, 9:10am UTC](https://discuss.elastic.co/t/how-elasticsearch-works-with-oidc-realm/340442 "2023-08-09T09:10:51Z")

</div>

Hi Team, Recently we have integrated Azure AD OIDC with Elasticsearch and kibana. The OP will provide the token to users of kibana User of kibana will present the token to elasticsearch for accessing the resources Ela…

---

## [PHP APM Agent](https://discuss.elastic.co/t/php-apm-agent/340436)

<div class="topic-metadata">

**Author:** [@gnom92](https://discuss.elastic.co/u/gnom92)\
**Replies:** 4\
**Last updated:** [August 9, 2023, 9:06am UTC](https://discuss.elastic.co/t/php-apm-agent/340436 "2023-08-09T09:06:57Z")

</div>

Hello, I see the PHP APM Agent is available on Linux OS only: Is there really no way to get it working on Windows server ? Or is there something equivalent for Windows OS ? Thanks,

---

## [Logstash date filter](https://discuss.elastic.co/t/logstash-date-filter/340427)

<div class="topic-metadata">

**Author:** [@Neelam\_Zanvar](https://discuss.elastic.co/u/Neelam_Zanvar)\
**Replies:** 10\
**Last updated:** [August 9, 2023, 8:29am UTC](https://discuss.elastic.co/t/logstash-date-filter/340427 "2023-08-09T08:29:42Z")

</div>

Hi i have a short\_date field in the following format 09/Aug/2023:12:44:15 +0530 This field is created as text. To convert it to date i am doing the following date { match =\> \[ "short\_date", "dd/MMM/yyyy…

---

## [Logstash @timestamp in the input file](https://discuss.elastic.co/t/logstash-timestamp-in-the-input-file/340426)

<div class="topic-metadata">

**Author:** [@Tal\_Blat](https://discuss.elastic.co/u/Tal_Blat)\
**Replies:** 0\
**Last updated:** [August 9, 2023, 7:18am UTC](https://discuss.elastic.co/t/logstash-timestamp-in-the-input-file/340426 "2023-08-09T07:18:37Z")

</div>

Hello What will happen if my input file contain a field called @timestamp ? will it replace the logstash @timestamp automatically ? thanks

---

## [How to make a text field aggregate-able in Kibana](https://discuss.elastic.co/t/how-to-make-a-text-field-aggregate-able-in-kibana/340107)

<div class="topic-metadata">

**Author:** [@Pratishruti](https://discuss.elastic.co/u/Pratishruti)\
**Replies:** 4\
**Last updated:** [August 9, 2023, 6:25am UTC](https://discuss.elastic.co/t/how-to-make-a-text-field-aggregate-able-in-kibana/340107 "2023-08-09T06:25:24Z")

</div>

Hi, I am using Kibana 6.8.1 version. We are using EFK. There is a text field name Message, I want to make visualization by using this field. However the field is not showing in option. I have tried to do it by assignin…

---

## [Synchronize distributed term frequencies on READ ONLY shards?](https://discuss.elastic.co/t/synchronize-distributed-term-frequencies-on-read-only-shards/340420)

<div class="topic-metadata">

**Author:** [@Yukha\_Dharmeswara](https://discuss.elastic.co/u/Yukha_Dharmeswara)\
**Replies:** 0\
**Last updated:** [August 9, 2023, 6:06am UTC](https://discuss.elastic.co/t/synchronize-distributed-term-frequencies-on-read-only-shards/340420 "2023-08-09T06:06:32Z")

</div>

Hello, I wonder if it is possible to synchronize shard's distributed term frequencies so we are able to reliably sort data by relevancenes when using search\_type=query\_then\_fetch? query\_then\_fetch vs dfs\_query\_then\_fet…

---

## [ php client 7.17](https://discuss.elastic.co/t/php-client-7-17/340413)

<div class="topic-metadata">

**Author:** [@gihaka](https://discuss.elastic.co/u/gihaka)\
**Replies:** 0\
**Last updated:** [August 9, 2023, 2:55am UTC](https://discuss.elastic.co/t/php-client-7-17/340413 "2023-08-09T02:55:54Z")

</div>

Здравствуйте! Кто знает, может ли работать php client 7.17 с elastic 8.9? Сайт работает на пхп 7.2, больше поднять не возможно

---

## [Rejected execution of primary operation](https://discuss.elastic.co/t/rejected-execution-of-primary-operation/340391)

<div class="topic-metadata">

**Author:** [@yuswanul](https://discuss.elastic.co/u/yuswanul)\
**Replies:** 4\
**Last updated:** [August 9, 2023, 2:27am UTC](https://discuss.elastic.co/t/rejected-execution-of-primary-operation/340391 "2023-08-09T02:27:23Z")

</div>

Hi there, sometimes my logstash had printed the log that said "rejected execution of primary operation" with the error type "es\_rejected\_execution\_exception" can anyone explain to me what's going on actually? Thanks

---

## [Php client 7.17 for elastic 8.9 (client for php 7.2)](https://discuss.elastic.co/t/php-client-7-17-for-elastic-8-9-client-for-php-7-2/340406)

<div class="topic-metadata">

**Author:** [@vt\_g](https://discuss.elastic.co/u/vt_g)\
**Replies:** 0\
**Last updated:** [August 8, 2023, 9:08pm UTC](https://discuss.elastic.co/t/php-client-7-17-for-elastic-8-9-client-for-php-7-2/340406 "2023-08-08T21:08:09Z")

</div>

Hello! Who knows if php client 7.17 can work with elastic 8.9? The site works on PHP 7.2, it is not possible to upload more Thank you!

---

## [Why IDs query expands to terms query?](https://discuss.elastic.co/t/why-ids-query-expands-to-terms-query/340410)

<div class="topic-metadata">

**Author:** [@etki](https://discuss.elastic.co/u/etki)\
**Replies:** 0\
**Last updated:** [August 9, 2023, 12:53am UTC](https://discuss.elastic.co/t/why-ids-query-expands-to-terms-query/340410 "2023-08-09T00:53:25Z")

</div>

So i was poking around sources and looks like ids query doesn't do much by itself: protected Query doToQuery(SearchExecutionContext context) throws IOException { MappedFieldType idField = context.getFieldTyp…

---

## [Curator 7.0](https://discuss.elastic.co/t/curator-7-0/340407)

<div class="topic-metadata">

**Author:** [@Leandro\_Nieva](https://discuss.elastic.co/u/Leandro_Nieva)\
**Replies:** 0\
**Last updated:** [August 8, 2023, 9:11pm UTC](https://discuss.elastic.co/t/curator-7-0/340407 "2023-08-08T21:11:51Z")

</div>

Estoy arrancando con Curator y tengo un inconveniente, deseo realizar un snapshot de cada índice de wazuh dia a dia, el cual me esta tomando 36 indices al generar la tarea. Dejo el detalle de mi accion y de lo que realiz…

---

## [Elasticsearch Java API client 8.7.1, No Option available to generate the correct format for source ordering for composition aggregation](https://discuss.elastic.co/t/elasticsearch-java-api-client-8-7-1-no-option-available-to-generate-the-correct-format-for-source-ordering-for-composition-aggregation/337477)

<div class="topic-metadata">

**Author:** [@ramyogi](https://discuss.elastic.co/u/ramyogi)\
**Replies:** 12\
**Last updated:** [August 8, 2023, 8:39pm UTC](https://discuss.elastic.co/t/elasticsearch-java-api-client-8-7-1-no-option-available-to-generate-the-correct-format-for-source-ordering-for-composition-aggregation/337477 "2023-08-08T20:39:45Z")

</div>

Elasticsearch Java API client 8.7.1 does not have option to supply order for the composite term aggregation but it was available server lib. Query runs fine in KIBANA but cannot build same in Java client library {"from…

---

## [Logstash: MalformedCSVError](https://discuss.elastic.co/t/logstash-malformedcsverror/340330)

<div class="topic-metadata">

**Author:** [@benhartwich](https://discuss.elastic.co/u/benhartwich)\
**Replies:** 9\
**Last updated:** [August 8, 2023, 8:20pm UTC](https://discuss.elastic.co/t/logstash-malformedcsverror/340330 "2023-08-08T20:20:56Z")

</div>

Hi, can anybody help me to find the right mutate =\> gsub definition to avoid these warnings / errors: \[WARN \] 2023-08-08 07:05:15.003 \[\[main\]\>worker20\] csv - Error parsing csv {:field=\>"message", :source=\>"16600,26200,…

---

## [Create empty field in report / upload comments from excel](https://discuss.elastic.co/t/create-empty-field-in-report-upload-comments-from-excel/340006)

<div class="topic-metadata">

**Author:** [@Valerija](https://discuss.elastic.co/u/Valerija)\
**Replies:** 6\
**Last updated:** [August 8, 2023, 8:00pm UTC](https://discuss.elastic.co/t/create-empty-field-in-report-upload-comments-from-excel/340006 "2023-08-08T20:00:04Z")

</div>

Hello, I am supposed to create three empty columns in existing report and give possibility to users to upload comments in those columns from excel. I would appreciate if someone could tell me if this is feasible and…

---

## [Search where inside array ( like , search where in ) inside nested](https://discuss.elastic.co/t/search-where-inside-array-like-search-where-in-inside-nested/340307)

<div class="topic-metadata">

**Author:** [@Murilo\_Livorato](https://discuss.elastic.co/u/Murilo_Livorato)\
**Replies:** 2\
**Last updated:** [August 8, 2023, 7:10pm UTC](https://discuss.elastic.co/t/search-where-inside-array-like-search-where-in-inside-nested/340307 "2023-08-08T19:10:59Z")

</div>

hello , I have a nested search . It is working like this - GET /products/\_search { "size": 100, "query": { "bool": { "must": \[ { "nested": { "path": "owner", "query": { …

---

## [Backfill old data for integration in elastic-agent integration](https://discuss.elastic.co/t/backfill-old-data-for-integration-in-elastic-agent-integration/340387)

<div class="topic-metadata">

**Author:** [@liquidkite](https://discuss.elastic.co/u/liquidkite)\
**Replies:** 1\
**Last updated:** [August 8, 2023, 5:16pm UTC](https://discuss.elastic.co/t/backfill-old-data-for-integration-in-elastic-agent-integration/340387 "2023-08-08T17:16:13Z")

</div>

Hello all, I've been using elastic agent to fetch logs from a variety of data sources. We ran into an issue where there was a misconfiguration with the pipeline and that caused to drop logs for that timeframe. Once the …

---

## [NameError with Cloudwatch plugin in logstash](https://discuss.elastic.co/t/nameerror-with-cloudwatch-plugin-in-logstash/340388)

<div class="topic-metadata">

**Author:** [@rmunjuluri](https://discuss.elastic.co/u/rmunjuluri)\
**Replies:** 0\
**Last updated:** [August 8, 2023, 4:13pm UTC](https://discuss.elastic.co/t/nameerror-with-cloudwatch-plugin-in-logstash/340388 "2023-08-08T16:13:33Z")

</div>

Hi, I am trying to pull Cloudwatch logs (specifically EC2 status) into Logstash. I can retrieve the status using AWS\_CLI, but the CloudWatch plugin throws the following error: Pipeline\_id:main Plugin: \<LogStash::Input…

---

## [Need help creating advanced watcher](https://discuss.elastic.co/t/need-help-creating-advanced-watcher/340384)

<div class="topic-metadata">

**Author:** [@RJC](https://discuss.elastic.co/u/RJC)\
**Replies:** 1\
**Last updated:** [August 8, 2023, 3:45pm UTC](https://discuss.elastic.co/t/need-help-creating-advanced-watcher/340384 "2023-08-08T15:45:15Z")

</div>

I am new to Watchers and Elasticsearch API. I need to create an email alert that will notify me if someone inserts an unauthorized mass storage device into a USB slot of Windows machines. The watcher needs to query even…

---

## [I am trying to execute bulk query using Postman but getting an Error](https://discuss.elastic.co/t/i-am-trying-to-execute-bulk-query-using-postman-but-getting-an-error/340332)

<div class="topic-metadata">

**Author:** [@Subrato1](https://discuss.elastic.co/u/Subrato1)\
**Replies:** 3\
**Last updated:** [August 8, 2023, 2:33pm UTC](https://discuss.elastic.co/t/i-am-trying-to-execute-bulk-query-using-postman-but-getting-an-error/340332 "2023-08-08T14:33:05Z")

</div>

PUT /library/\_bulk?refresh {"index":{"\_id": "Leviathan Wakes"}} {"name": "Leviathan Wakes", "author": "James S.A. Corey", "release\_date": "2011-06-02", "page\_count": 561} {"index":{"\_id": "Hyperion"}} {"name": "Hyperion"…

---

## [LABs 5.4. petclinic-react does not show up, CORS policy error on PetClinic page](https://discuss.elastic.co/t/labs-5-4-petclinic-react-does-not-show-up-cors-policy-error-on-petclinic-page/339907)

<div class="topic-metadata">

**Author:** [@Renata](https://discuss.elastic.co/u/Renata)\
**Replies:** 7\
**Last updated:** [August 8, 2023, 2:31pm UTC](https://discuss.elastic.co/t/labs-5-4-petclinic-react-does-not-show-up-cors-policy-error-on-petclinic-page/339907 "2023-08-08T14:31:37Z")

</div>

Course: Elastic Observability Engineer Version: 7.9 Hello, I cannot figure out how to solve this. I all the steps in 5.4. seem to be successful but at the end petclinic-react does not show up on Elastic APM. Chrome D…

---

## [Upgrading to a patch version resulting in replication failure?](https://discuss.elastic.co/t/upgrading-to-a-patch-version-resulting-in-replication-failure/340374)

<div class="topic-metadata">

**Author:** [@jaykb77](https://discuss.elastic.co/u/jaykb77)\
**Replies:** 2\
**Last updated:** [August 8, 2023, 1:30pm UTC](https://discuss.elastic.co/t/upgrading-to-a-patch-version-resulting-in-replication-failure/340374 "2023-08-08T13:30:41Z")

</div>

Hi all, We recently tried to upgrade from 7.17.0 -\> 7.17.8 in a rolling way, but in the middle of the upgrade we found replication error. explanation" : "cannot allocate replica shard to a node with version \[7.17.0\] si…

---

## [EQL query to alert 1 alert per each user](https://discuss.elastic.co/t/eql-query-to-alert-1-alert-per-each-user/339539)

<div class="topic-metadata">

**Author:** [@yzaritskyi](https://discuss.elastic.co/u/yzaritskyi)\
**Replies:** 2\
**Last updated:** [August 8, 2023, 1:15pm UTC](https://discuss.elastic.co/t/eql-query-to-alert-1-alert-per-each-user/339539 "2023-08-08T13:15:08Z")

</div>

Hello all! I'd like to create a Rule based on the EQL query that will trigger an alert only once per user. For example: The input list of logs is user1 ip1 user1 ip1 user2 ip2 user5 ip5 user4 ip4 user4 ip4 user…

---

## [Different Dashboard views for different entities](https://discuss.elastic.co/t/different-dashboard-views-for-different-entities/340375)

<div class="topic-metadata">

**Author:** [@Marian\_Abou\_fares](https://discuss.elastic.co/u/Marian_Abou_fares)\
**Replies:** 0\
**Last updated:** [August 8, 2023, 1:13pm UTC](https://discuss.elastic.co/t/different-dashboard-views-for-different-entities/340375 "2023-08-08T13:13:21Z")

</div>

I have different stores that can access only certain parts of a dashboard. for instance each department can view only performance of its employees. How can I implement this authentication on Kibana? I dont have the " cre…

---

## [Logstash troubleshooting](https://discuss.elastic.co/t/logstash-troubleshooting/340115)

<div class="topic-metadata">

**Author:** [@sta02](https://discuss.elastic.co/u/sta02)\
**Replies:** 1\
**Last updated:** [August 8, 2023, 12:33pm UTC](https://discuss.elastic.co/t/logstash-troubleshooting/340115 "2023-08-08T12:33:35Z")

</div>

Hello, We have logstash performing dual feed. The first output writes to Elastic and the second output writes to Azure Sentinel. There is a clear delta in number of logs sent to Azure Sentinel and Elastic. Elastic rece…

---

## [Lucene query](https://discuss.elastic.co/t/lucene-query/340367)

<div class="topic-metadata">

**Author:** [@ZahraZare](https://discuss.elastic.co/u/ZahraZare)\
**Replies:** 0\
**Last updated:** [August 8, 2023, 12:18pm UTC](https://discuss.elastic.co/t/lucene-query/340367 "2023-08-08T12:18:41Z")

</div>

The following document is from the "mart-index" index in Elasticsearch. I want to use this index as a data source in Grafana 9. I want to have only "IS\_AVAILABLE" and "GPRS\_CNT" values from "DTLS\_MA" object as table colu…

---

## [99.9 / Custom percentiles?](https://discuss.elastic.co/t/99-9-custom-percentiles/340346)

<div class="topic-metadata">

**Author:** [@georgms](https://discuss.elastic.co/u/georgms)\
**Replies:** 1\
**Last updated:** [August 8, 2023, 12:04pm UTC](https://discuss.elastic.co/t/99-9-custom-percentiles/340346 "2023-08-08T12:04:17Z")

</div>

In the Elastic APM dashboard latencies can be displayed as average, 95 percentile or 99 percentile: Additionally, we would like to be able to display the 99.9 percentile and use that in SLOs / alerts as well. Can thi…

---

## [Change field name instead of requirement field](https://discuss.elastic.co/t/change-field-name-instead-of-requirement-field/340353)

<div class="topic-metadata">

**Author:** [@younus](https://discuss.elastic.co/u/younus)\
**Replies:** 0\
**Last updated:** [August 8, 2023, 10:16am UTC](https://discuss.elastic.co/t/change-field-name-instead-of-requirement-field/340353 "2023-08-08T10:16:23Z")

</div>

i want to change the field name agent.ephemeral\_id instead of ELK\_Id.

[Previous page](https://discuss.elastic.co/tag/none.md?no_tags=true&page=323)

[Next page](https://discuss.elastic.co/tag/none.md?no_tags=true&page=325)
