# \#none

**URL:** https://discuss.elastic.co/tag/none.md?no_tags=true&page=325

[Latest](https://discuss.elastic.co/latest.md) · [Categories](https://discuss.elastic.co/categories.md) · [Tags](https://discuss.elastic.co/tags.md)

**Page:** 326

---

## [See duplicate transaction with same date and time](https://discuss.elastic.co/t/see-duplicate-transaction-with-same-date-and-time/340340)

<div class="topic-metadata">

**Author:** [@younus](https://discuss.elastic.co/u/younus)\
**Replies:** 3\
**Last updated:** [August 8, 2023, 10:04am UTC](https://discuss.elastic.co/t/see-duplicate-transaction-with-same-date-and-time/340340 "2023-08-08T10:04:24Z")

</div>

See duplicate transaction with same date and time .

---

## [Perform CRUD Operation on Elasticsearch With REST API](https://discuss.elastic.co/t/perform-crud-operation-on-elasticsearch-with-rest-api/340329)

<div class="topic-metadata">

**Author:** [@Debasis\_Mallick](https://discuss.elastic.co/u/Debasis_Mallick)\
**Replies:** 5\
**Last updated:** [August 8, 2023, 9:48am UTC](https://discuss.elastic.co/t/perform-crud-operation-on-elasticsearch-with-rest-api/340329 "2023-08-08T09:48:37Z")

</div>

Hi Team, Could anyone share how to perform CRUD operation in Elastic search with REST API. I had tried the below one with the curl command but getting error as "curl: (52) Empty reply from server" . Could you please gui…

---

## [Possible Feature Request: Redis Authentication with Username/Password](https://discuss.elastic.co/t/possible-feature-request-redis-authentication-with-username-password/340349)

<div class="topic-metadata">

**Author:** [@alces](https://discuss.elastic.co/u/alces)\
**Replies:** 0\
**Last updated:** [August 8, 2023, 9:25am UTC](https://discuss.elastic.co/t/possible-feature-request-redis-authentication-with-username-password/340349 "2023-08-08T09:25:01Z")

</div>

Hi everyone. We are planing to use redis between beats and logstash as a buffer for high utilization timespots. In this setup currently there is only a "password" option for the redis output/input plugin, so every part…

---

## [// "reason": "Arrays (returned by \[ss\]) are not supported"](https://discuss.elastic.co/t/reason-arrays-returned-by-ss-are-not-supported/340136)

<div class="topic-metadata">

**Author:** [@fangyan](https://discuss.elastic.co/u/fangyan)\
**Replies:** 2\
**Last updated:** [August 8, 2023, 9:21am UTC](https://discuss.elastic.co/t/reason-arrays-returned-by-ss-are-not-supported/340136 "2023-08-08T09:21:00Z")

</div>

Elasticsearch updated version to 8.9, using SQL function, found abnormal collection data reports. Has anyone encountered them?

---

## [Purge index](https://discuss.elastic.co/t/purge-index/340265)

<div class="topic-metadata">

**Author:** [@Hanni](https://discuss.elastic.co/u/Hanni)\
**Replies:** 13\
**Last updated:** [August 8, 2023, 9:14am UTC](https://discuss.elastic.co/t/purge-index/340265 "2023-08-08T09:14:40Z")

</div>

hello, I would like to purge my data from my indexes in elasticsearch. I'd like to know how to do this without having to delete my index. How can I achieve that?

---

## [Elasticsearch upgrade from 7.17 to 8.x](https://discuss.elastic.co/t/elasticsearch-upgrade-from-7-17-to-8-x/340338)

<div class="topic-metadata">

**Author:** [@jaykb77](https://discuss.elastic.co/u/jaykb77)\
**Replies:** 1\
**Last updated:** [August 8, 2023, 8:16am UTC](https://discuss.elastic.co/t/elasticsearch-upgrade-from-7-17-to-8-x/340338 "2023-08-08T08:16:39Z")

</div>

Hi all, We are planning to upgrade our elasticsearch cluster from 7.17.x to 8.X. Apart from general upgrade recommendations from elastic, is there a specific 8.X version that we should be upgrading to?

---

## [Error on lifecycle policy alias](https://discuss.elastic.co/t/error-on-lifecycle-policy-alias/340337)

<div class="topic-metadata">

**Author:** [@fribse](https://discuss.elastic.co/u/fribse)\
**Replies:** 0\
**Last updated:** [August 8, 2023, 8:09am UTC](https://discuss.elastic.co/t/error-on-lifecycle-policy-alias/340337 "2023-08-08T08:09:00Z")

</div>

I wasn't aware of the alias requirement on lifecycle management, so now I have a ton of data imported, on indexes with this pattern based on an index template: dmarc-7.17.4-2023.08 Where the version, year and month var…

---

## [Unable to create Synthetics projects using the API key](https://discuss.elastic.co/t/unable-to-create-synthetics-projects-using-the-api-key/340335)

<div class="topic-metadata">

**Author:** [@opensourcengineer](https://discuss.elastic.co/u/opensourcengineer)\
**Replies:** 0\
**Last updated:** [August 8, 2023, 7:37am UTC](https://discuss.elastic.co/t/unable-to-create-synthetics-projects-using-the-api-key/340335 "2023-08-08T07:37:00Z")

</div>

I am trying to create project in the monitors using the API key and getting the below error: TypeError: unusable command i used is: npx @elastic/synthetics init projects-itops version 8.4 containerisation deployment

---

## [\[.kibana\_task\_manager\] Action failed with 'Request timed out'](https://discuss.elastic.co/t/kibana-task-manager-action-failed-with-request-timed-out/340325)

<div class="topic-metadata">

**Author:** [@tegerei](https://discuss.elastic.co/u/tegerei)\
**Replies:** 2\
**Last updated:** [August 8, 2023, 7:26am UTC](https://discuss.elastic.co/t/kibana-task-manager-action-failed-with-request-timed-out/340325 "2023-08-08T07:26:44Z")

</div>

Hello, I upgraded an Elasticsearch cluster from 7.10 to 7.17.9. ES upgrade is fine, with all the nodes up. However, when upgrading Kibana, I got the error when it attempts to re-index. {"type":"log","@timestamp":"2023-…

---

## [\[version 8.9\] Kibana server is not ready yet](https://discuss.elastic.co/t/version-8-9-kibana-server-is-not-ready-yet/340316)

<div class="topic-metadata">

**Author:** [@SageJustus](https://discuss.elastic.co/u/SageJustus)\
**Replies:** 1\
**Last updated:** [August 8, 2023, 7:21am UTC](https://discuss.elastic.co/t/version-8-9-kibana-server-is-not-ready-yet/340316 "2023-08-08T07:21:31Z")

</div>

Kibana version: 8.9 Elasticsearch version: 8.9 Server OS version: Windows10 Describe the bug: Unable to start kibana. Steps to reproduce: start Elasticsearch, browser access http://localhost:9200/, get the followi…

---

## [Migration from ES V6.8 to V7.17 with an additional node](https://discuss.elastic.co/t/migration-from-es-v6-8-to-v7-17-with-an-additional-node/340252)

<div class="topic-metadata">

**Author:** [@Franco901](https://discuss.elastic.co/u/Franco901)\
**Replies:** 2\
**Last updated:** [August 8, 2023, 6:47am UTC](https://discuss.elastic.co/t/migration-from-es-v6-8-to-v7-17-with-an-additional-node/340252 "2023-08-08T06:47:43Z")

</div>

Hi there, I have a V6.8 instance with a ~350 GB index and plan to migrate to ES V7.17. I read that ES can migrate between major versions, so my idea was to setup a new V7.17 node and let him join to the existing V6.8 n…

---

## [Unique count function](https://discuss.elastic.co/t/unique-count-function/340320)

<div class="topic-metadata">

**Author:** [@MeghanaReddy](https://discuss.elastic.co/u/MeghanaReddy)\
**Replies:** 0\
**Last updated:** [August 8, 2023, 4:26am UTC](https://discuss.elastic.co/t/unique-count-function/340320 "2023-08-08T04:26:02Z")

</div>

I have created a table visualisation so on x-axis I have entity data and on y-axis I am having unique count of traceids function but I am getting unique count of traceids for each entity value is more than the count of …

---

## [How to do to show field values in Kibana alert?](https://discuss.elastic.co/t/how-to-do-to-show-field-values-in-kibana-alert/340319)

<div class="topic-metadata">

**Author:** [@aungsoemin](https://discuss.elastic.co/u/aungsoemin)\
**Replies:** 0\
**Last updated:** [August 8, 2023, 4:12am UTC](https://discuss.elastic.co/t/how-to-do-to-show-field-values-in-kibana-alert/340319 "2023-08-08T04:12:38Z")

</div>

Hi Everyone, I created the custom rule to get the alert when there is successful login from public IP for Windows host. The lucene query is as per below. (winlog.channel:Security AND winlog.event\_id:4624 AND (NOT ((win…

---

## [Is there any performance comparison between the default index codec and best\_compression?](https://discuss.elastic.co/t/is-there-any-performance-comparison-between-the-default-index-codec-and-best-compression/340312)

<div class="topic-metadata">

**Author:** [@leandrojmp](https://discuss.elastic.co/u/leandrojmp)\
**Replies:** 0\
**Last updated:** [August 8, 2023, 3:17am UTC](https://discuss.elastic.co/t/is-there-any-performance-comparison-between-the-default-index-codec-and-best-compression/340312 "2023-08-08T03:17:18Z")

</div>

Hello, I'm looking into ways to optimize the disk usage of my indices on my cluster and before go on the route to remove the \_source field I've decided to try and change the index codec to best\_compression. The documen…

---

## [Combined grok pattern for customized logs](https://discuss.elastic.co/t/combined-grok-pattern-for-customized-logs/338535)

<div class="topic-metadata">

**Author:** [@shailendra1](https://discuss.elastic.co/u/shailendra1)\
**Replies:** 20\
**Last updated:** [August 8, 2023, 3:09am UTC](https://discuss.elastic.co/t/combined-grok-pattern-for-customized-logs/338535 "2023-08-08T03:09:23Z")

</div>

i am looking some help and guidenace for parsing the customized logs in one file. i have httpd access logs which have two format and i need to prepare the logstash config/filtering the data. so i tried two different pat…

---

## [What's the difference between consumption-based and resource-based pricing?](https://discuss.elastic.co/t/whats-the-difference-between-consumption-based-and-resource-based-pricing/340308)

<div class="topic-metadata">

**Author:** [@Ernest\_Dong](https://discuss.elastic.co/u/Ernest_Dong)\
**Replies:** 1\
**Last updated:** [August 8, 2023, 2:44am UTC](https://discuss.elastic.co/t/whats-the-difference-between-consumption-based-and-resource-based-pricing/340308 "2023-08-08T02:44:12Z")

</div>

I see two billing models on this page and wondering: does the resource-based model mean I have to pay for ECU of kibana node even if I'm not doing analytics? does the consumption-based model mean I wouldn't need to pay…

---

## [Lucene Regex issues](https://discuss.elastic.co/t/lucene-regex-issues/339869)

<div class="topic-metadata">

**Author:** [@turboz](https://discuss.elastic.co/u/turboz)\
**Replies:** 2\
**Last updated:** [August 7, 2023, 10:21pm UTC](https://discuss.elastic.co/t/lucene-regex-issues/339869 "2023-08-07T22:21:06Z")

</div>

I'm trying to use some regex and its becoming frustrating. It appears the syntax is not respected around the Kibana interface. For example, I can exclude via regex with visualizations. However I noticed if you choose to…

---

## [Fetch substring from a string in logstash filter](https://discuss.elastic.co/t/fetch-substring-from-a-string-in-logstash-filter/340223)

<div class="topic-metadata">

**Author:** [@Neelam\_Zanvar](https://discuss.elastic.co/u/Neelam_Zanvar)\
**Replies:** 1\
**Last updated:** [August 7, 2023, 5:36pm UTC](https://discuss.elastic.co/t/fetch-substring-from-a-string-in-logstash-filter/340223 "2023-08-07T17:36:04Z")

</div>

Hi, I have a field called url in elasticsearch document. The sample value for the field is /3dpassport/login I want to extract only the first string before / that is 3dpassport and store it in a field. Tried this copy…

---

## [Logstash Twitter error - no address for stream.twitter.com](https://discuss.elastic.co/t/logstash-twitter-error-no-address-for-stream-twitter-com/340238)

<div class="topic-metadata">

**Author:** [@Yochai\_Ben-Chaim](https://discuss.elastic.co/u/Yochai_Ben-Chaim)\
**Replies:** 1\
**Last updated:** [August 7, 2023, 5:27pm UTC](https://discuss.elastic.co/t/logstash-twitter-error-no-address-for-stream-twitter-com/340238 "2023-08-07T17:27:56Z")

</div>

I am trying to use the twitter plugin with the latest ELK stack (8.9.0). When I activate logstash -f myconf\_file.conf I am getting error messages messages : "no address for stream.twitter.com" My conf file is very bas…

---

## [Search for docs from last 24h on data field not timestamp](https://discuss.elastic.co/t/search-for-docs-from-last-24h-on-data-field-not-timestamp/338199)

<div class="topic-metadata">

**Author:** [@lemospt](https://discuss.elastic.co/u/lemospt)\
**Replies:** 1\
**Last updated:** [August 7, 2023, 4:47pm UTC](https://discuss.elastic.co/t/search-for-docs-from-last-24h-on-data-field-not-timestamp/338199 "2023-08-07T16:47:39Z")

</div>

Hi, in my documents i have the field report\_last\_request, in kibana i need a query that get all documents that has the report\_last\_request date from last 24h. Hope is clear. Thanks in advance.

---

## [Slow query concerns, how to optimize?](https://discuss.elastic.co/t/slow-query-concerns-how-to-optimize/339902)

<div class="topic-metadata">

**Author:** [@chenlx594](https://discuss.elastic.co/u/chenlx594)\
**Replies:** 6\
**Last updated:** [August 7, 2023, 4:34pm UTC](https://discuss.elastic.co/t/slow-query-concerns-how-to-optimize/339902 "2023-08-07T16:34:44Z")

</div>

Originally, there was an index a1. Now, it's modified to have index a1 with alias A, and index a2 with alias A. When querying using alias A, the query speed increases from 7ms to 60ms compared to directly querying using …

---

## [Get \`Error: s is undefined\` when browsing to "Management-\>Data-\>Transforms"](https://discuss.elastic.co/t/get-error-s-is-undefined-when-browsing-to-management-data-transforms/340276)

<div class="topic-metadata">

**Author:** [@tolland](https://discuss.elastic.co/u/tolland)\
**Replies:** 1\
**Last updated:** [August 7, 2023, 3:13pm UTC](https://discuss.elastic.co/t/get-error-s-is-undefined-when-browsing-to-management-data-transforms/340276 "2023-08-07T15:13:47Z")

</div>

I have a kibana / elasticsearch installed from rpms version 8.9.0 on rocky-8 linux. Security is disabled. When I browse to the Transforms menu: http://elasticsearch.lan:5601/app/management/data/transform I get the foll…

---

## [Delete data stream and all it's index](https://discuss.elastic.co/t/delete-data-stream-and-all-its-index/340085)

<div class="topic-metadata">

**Author:** [@elasticforme](https://discuss.elastic.co/u/elasticforme)\
**Replies:** 3\
**Last updated:** [August 7, 2023, 3:03pm UTC](https://discuss.elastic.co/t/delete-data-stream-and-all-its-index/340085 "2023-08-07T15:03:12Z")

</div>

I have a test data stream. it works fine. But now I am trying to delete it and I can't When I do delete via command or via GUI it recreates it self DELETE /\_data\_stream/msyos1-log I can't delete index template as wel…

---

## [Auto download Chromium in kibana](https://discuss.elastic.co/t/auto-download-chromium-in-kibana/336708)

<div class="topic-metadata">

**Author:** [@Suresh\_Ghatuwa](https://discuss.elastic.co/u/Suresh_Ghatuwa)\
**Replies:** 4\
**Last updated:** [August 7, 2023, 2:20pm UTC](https://discuss.elastic.co/t/auto-download-chromium-in-kibana/336708 "2023-08-07T14:20:30Z")

</div>

On starting Kibana 8.6.2, chromium browser was downloaded automatically internally for reporting purpose (i guess). Path: \<kibana\_path\>/x-pack/plugins/screenshotting/chromium/\* Can we disable auto download the chromium…

---

## [In MySQL to create a database we execute a query: CREATE DATABASE DEMODB, so can we create a DATABASE in Elasticsearch also?](https://discuss.elastic.co/t/in-mysql-to-create-a-database-we-execute-a-query-create-database-demodb-so-can-we-create-a-database-in-elasticsearch-also/340279)

<div class="topic-metadata">

**Author:** [@Subrato1](https://discuss.elastic.co/u/Subrato1)\
**Replies:** 2\
**Last updated:** [August 7, 2023, 1:41pm UTC](https://discuss.elastic.co/t/in-mysql-to-create-a-database-we-execute-a-query-create-database-demodb-so-can-we-create-a-database-in-elasticsearch-also/340279 "2023-08-07T13:41:58Z")

</div>

If possible, give me reference link or Command here.

---

## [Security autoconfiguration information](https://discuss.elastic.co/t/security-autoconfiguration-information/340100)

<div class="topic-metadata">

**Author:** [@usman1](https://discuss.elastic.co/u/usman1)\
**Replies:** 6\
**Last updated:** [August 7, 2023, 1:33pm UTC](https://discuss.elastic.co/t/security-autoconfiguration-information/340100 "2023-08-07T13:33:15Z")

</div>

I have just installed the newest version of Elasticsearch using the official guide but did not come across 'Security autoconfiguration information' screen. Now when I try to start Elasticsearch using the following comman…

---

## [Unexpected HTTP Error (503) when running Elasticsearch tools](https://discuss.elastic.co/t/unexpected-http-error-503-when-running-elasticsearch-tools/340263)

<div class="topic-metadata">

**Author:** [@General-Trident](https://discuss.elastic.co/u/General-Trident)\
**Replies:** 0\
**Last updated:** [August 7, 2023, 11:09am UTC](https://discuss.elastic.co/t/unexpected-http-error-503-when-running-elasticsearch-tools/340263 "2023-08-07T11:09:09Z")

</div>

Need help on how to resolve issue at Elasticsearch tools not working All permissions on $ES\_HOME using command ls -ltr : \[root@localhost bin\]# ls -ltr total 3204 -rwxr-xr-x. 1 root root 353 Jul 19 21:46 elasticsear…

---

## [Hide Some Filters](https://discuss.elastic.co/t/hide-some-filters/340235)

<div class="topic-metadata">

**Author:** [@fenixon](https://discuss.elastic.co/u/fenixon)\
**Replies:** 2\
**Last updated:** [August 7, 2023, 10:36am UTC](https://discuss.elastic.co/t/hide-some-filters/340235 "2023-08-07T10:36:58Z")

</div>

I want to hide some particular filters in kibana dashboard. Is it possible?

---

## [AWS S3 bucket logs through SQS](https://discuss.elastic.co/t/aws-s3-bucket-logs-through-sqs/340240)

<div class="topic-metadata">

**Author:** [@Yevheniy\_Moyko](https://discuss.elastic.co/u/Yevheniy_Moyko)\
**Replies:** 0\
**Last updated:** [August 7, 2023, 8:24am UTC](https://discuss.elastic.co/t/aws-s3-bucket-logs-through-sqs/340240 "2023-08-07T08:24:10Z")

</div>

Hello, can you please advise on how to ingest logs from AWS s3 bucket (CloudWatch) through SQS queue? I see that in AWS addon this method is deprecated Collect logs from S3 (Deprecated) and I can't find Custom AWS Logs…

---

## [What is status of the logs in case of agents unavailability](https://discuss.elastic.co/t/what-is-status-of-the-logs-in-case-of-agents-unavailability/340111)

<div class="topic-metadata">

**Author:** [@ankitha\_sn](https://discuss.elastic.co/u/ankitha_sn)\
**Replies:** 1\
**Last updated:** [August 7, 2023, 7:29am UTC](https://discuss.elastic.co/t/what-is-status-of-the-logs-in-case-of-agents-unavailability/340111 "2023-08-07T07:29:59Z")

</div>

Hi Team, I have some queries. If the agent is down, what is the status of the logs? Will it send the logs to Elastic DB once it is up? Here logs mean agent downtime logs. Thanks, Ankitha

[Previous page](https://discuss.elastic.co/tag/none.md?no_tags=true&page=324)

[Next page](https://discuss.elastic.co/tag/none.md?no_tags=true&page=326)
