# \#none

**URL:** https://discuss.elastic.co/tag/none.md?no_tags=true&page=326

[Latest](https://discuss.elastic.co/latest.md) · [Categories](https://discuss.elastic.co/categories.md) · [Tags](https://discuss.elastic.co/tags.md)

**Page:** 327

---

## [Include logs with custom logs](https://discuss.elastic.co/t/include-logs-with-custom-logs/340231)

<div class="topic-metadata">

**Author:** [@shubham.s](https://discuss.elastic.co/u/shubham.s)\
**Replies:** 0\
**Last updated:** [August 7, 2023, 7:01am UTC](https://discuss.elastic.co/t/include-logs-with-custom-logs/340231 "2023-08-07T07:01:33Z")

</div>

Hi, I have successfully integrated logs with the help of elastic-agent and integrated custom logs. Now I want elastic agent to process only logs from the file which contains specific keyword. I want elastic agent to exc…

---

## [Failed to execute action {:id=\>:main, :action\_type=\>LogStash::ConvergeResult::FailedAction, :message=\>"Could not execute action: PipelineAction::Create\<main\>, action\_result: false", :backtrace=\>nil](https://discuss.elastic.co/t/failed-to-execute-action-id-main-action-type-logstash-failedaction-message-could-not-execute-action-pipelineaction-create-main-action-result-false-backtrace-nil/340116)

<div class="topic-metadata">

**Author:** [@ItsGautam](https://discuss.elastic.co/u/ItsGautam)\
**Replies:** 3\
**Last updated:** [August 7, 2023, 5:30am UTC](https://discuss.elastic.co/t/failed-to-execute-action-id-main-action-type-logstash-failedaction-message-could-not-execute-action-pipelineaction-create-main-action-result-false-backtrace-nil/340116 "2023-08-07T05:30:44Z")

</div>

Hi, I am new to the elasticsearch. i ve tried to find the solution but ...... \[2023-08-04T13:09:08,778\]\[INFO \]\[logstash.javapipeline \]\[main\] Pipeline terminated {"pipeline.id"=\>"main"} \[2023-08-04T13:09:08,806\]\[ERR…

---

## [Cumulative Sum String field](https://discuss.elastic.co/t/cumulative-sum-string-field/340216)

<div class="topic-metadata">

**Author:** [@dro](https://discuss.elastic.co/u/dro)\
**Replies:** 4\
**Last updated:** [August 7, 2023, 3:19am UTC](https://discuss.elastic.co/t/cumulative-sum-string-field/340216 "2023-08-07T03:19:18Z")

</div>

I've tried searching on the forum, but haven't really found something similar. Is there a method to show a cumulative sum of a field of type string using Lens or TVSB? For example a field of data with string types YES …

---

## [ECE Fundamentals Lab3, Step9 "failed to parse - Malformed content"](https://discuss.elastic.co/t/ece-fundamentals-lab3-step9-failed-to-parse-malformed-content/340215)

<div class="topic-metadata">

**Author:** [@David\_Cupitt](https://discuss.elastic.co/u/David_Cupitt)\
**Replies:** 0\
**Last updated:** [August 7, 2023, 2:36am UTC](https://discuss.elastic.co/t/ece-fundamentals-lab3-step9-failed-to-parse-malformed-content/340215 "2023-08-07T02:36:41Z")

</div>

I'm running through the ECE Fundamentals course and have an issue with Lab 3, Step 9. When bulk loading the dataset into the index blogs-00001 I get the following error: { "error":{ "root\_cause":\[{ "type":"mapper\_pa…

---

## [Noop Query](https://discuss.elastic.co/t/noop-query/340208)

<div class="topic-metadata">

**Author:** [@yonzmeer](https://discuss.elastic.co/u/yonzmeer)\
**Replies:** 0\
**Last updated:** [August 6, 2023, 8:03pm UTC](https://discuss.elastic.co/t/noop-query/340208 "2023-08-06T20:03:11Z")

</div>

Hello, I'm building a some-what generic converter from an object that contains lists of values, to a search requests for elasticsearch, for example: { names: \["john", "bob"\], cities: \["boston", "moscow"\] } tur…

---

## [Did anything change concerning dashboards from version 6.3 to version 7.5?](https://discuss.elastic.co/t/did-anything-change-concerning-dashboards-from-version-6-3-to-version-7-5/338584)

<div class="topic-metadata">

**Author:** [@mpniel](https://discuss.elastic.co/u/mpniel)\
**Replies:** 13\
**Last updated:** [August 6, 2023, 6:54pm UTC](https://discuss.elastic.co/t/did-anything-change-concerning-dashboards-from-version-6-3-to-version-7-5/338584 "2023-08-06T18:54:04Z")

</div>

Hello, Did anything change concerning dashboards from version 6.3 to version 7.5 ? I have a working dashboard in one environment with version 6.3, and the exactly same dashboard doesn't work from version 7.5. The dash…

---

## [Security\_exception: unable to authenticate user \[kibana\_system\] for REST request \[/\_nodes?filter\_path=nodes..version%2Cnodes..http.publish\_address%2Cnodes..ip\]](https://discuss.elastic.co/t/security-exception-unable-to-authenticate-user-kibana-system-for-rest-request-nodes-filter-path-nodes-version-2cnodes-http-publish-address-2cnodes-ip/340187)

<div class="topic-metadata">

**Author:** [@Joao\_Malebo](https://discuss.elastic.co/u/Joao_Malebo)\
**Replies:** 7\
**Last updated:** [August 6, 2023, 3:11pm UTC](https://discuss.elastic.co/t/security-exception-unable-to-authenticate-user-kibana-system-for-rest-request-nodes-filter-path-nodes-version-2cnodes-http-publish-address-2cnodes-ip/340187 "2023-08-06T15:11:02Z")

</div>

hello friends, I am getting this error when launching kibana in the browser... below is the cause of the error returned by kibana statuses. Please can you help overcome this situation md/system/kibana.service; enabled…

---

## [Stored fields getting deleted upon partial update of the document in elastic search](https://discuss.elastic.co/t/stored-fields-getting-deleted-upon-partial-update-of-the-document-in-elastic-search/340011)

<div class="topic-metadata">

**Author:** [@Jagadeesh12](https://discuss.elastic.co/u/Jagadeesh12)\
**Replies:** 4\
**Last updated:** [August 5, 2023, 1:12pm UTC](https://discuss.elastic.co/t/stored-fields-getting-deleted-upon-partial-update-of-the-document-in-elastic-search/340011 "2023-08-05T13:12:32Z")

</div>

Hi. I have an index which have stored fields in the documents. But, upon updating the document with new fields (partially update), the previously existing stored fields are getting deleted. Create the Index PUT itf\_t…

---

## [How to apply filter(s) to all the embedded iframe visuals](https://discuss.elastic.co/t/how-to-apply-filter-s-to-all-the-embedded-iframe-visuals/340071)

<div class="topic-metadata">

**Author:** [@Amphagory](https://discuss.elastic.co/u/Amphagory)\
**Replies:** 8\
**Last updated:** [August 5, 2023, 1:11am UTC](https://discuss.elastic.co/t/how-to-apply-filter-s-to-all-the-embedded-iframe-visuals/340071 "2023-08-05T01:11:26Z")

</div>

I would like to embed visuals into a webpage. I guess I can use a dashboard to have a filter applied to all the visuals, but I was wondering if I only had a bunch of visuals on a webpage, is it possible to have a filter…

---

## [Elasticsearch search based on term position and fuzzy](https://discuss.elastic.co/t/elasticsearch-search-based-on-term-position-and-fuzzy/340163)

<div class="topic-metadata">

**Author:** [@JohnsM](https://discuss.elastic.co/u/JohnsM)\
**Replies:** 0\
**Last updated:** [August 4, 2023, 10:39pm UTC](https://discuss.elastic.co/t/elasticsearch-search-based-on-term-position-and-fuzzy/340163 "2023-08-04T22:39:30Z")

</div>

I am a beginner in Elasticsearch and I try to combine a query with term position and fuzzy and the results are not what I expected. I tried this query { "query": { "bool": { "must": \[ …

---

## [How to use event.set to get the values of a variable?](https://discuss.elastic.co/t/how-to-use-event-set-to-get-the-values-of-a-variable/340155)

<div class="topic-metadata">

**Author:** [@mohsin106](https://discuss.elastic.co/u/mohsin106)\
**Replies:** 1\
**Last updated:** [August 4, 2023, 10:34pm UTC](https://discuss.elastic.co/t/how-to-use-event-set-to-get-the-values-of-a-variable/340155 "2023-08-04T22:34:59Z")

</div>

I'm using Kafka's input plugin within my logstash pipline and I have enabled decorated\_events =\> true If I want to get the kafka topic and partition names I can do this: mutate { add\_field =\> { "\[topic\_na…

---

## [Monitor users (requests, CPU usage, etc.)](https://discuss.elastic.co/t/monitor-users-requests-cpu-usage-etc/340018)

<div class="topic-metadata">

**Author:** [@GinkoLucas](https://discuss.elastic.co/u/GinkoLucas)\
**Replies:** 1\
**Last updated:** [August 4, 2023, 7:23pm UTC](https://discuss.elastic.co/t/monitor-users-requests-cpu-usage-etc/340018 "2023-08-04T19:23:28Z")

</div>

Hello, I'd like to be able to find out what my users are doing, and more specifically list the users who are consuming CPU, consult the list of "big" requests and the linked user. Basically, I'd like to know if someone…

---

## [ECK Autoscaler Object Race Condition](https://discuss.elastic.co/t/eck-autoscaler-object-race-condition/338718)

<div class="topic-metadata">

**Author:** [@Phillip\_Mabry](https://discuss.elastic.co/u/Phillip_Mabry)\
**Replies:** 1\
**Last updated:** [August 4, 2023, 5:23pm UTC](https://discuss.elastic.co/t/eck-autoscaler-object-race-condition/338718 "2023-08-04T17:23:23Z")

</div>

One of our customers uses helm charts to deploy elasticsearch on ECK which has been working correctly. They recently added autoscaler to the helm chart and they get inconsistent results. Sometimes the deployment works,…

---

## [I want create a kibana table, combining the 2 latest documents grouped by a common field](https://discuss.elastic.co/t/i-want-create-a-kibana-table-combining-the-2-latest-documents-grouped-by-a-common-field/339937)

<div class="topic-metadata">

**Author:** [@MJohansen](https://discuss.elastic.co/u/MJohansen)\
**Replies:** 1\
**Last updated:** [August 4, 2023, 5:05pm UTC](https://discuss.elastic.co/t/i-want-create-a-kibana-table-combining-the-2-latest-documents-grouped-by-a-common-field/339937 "2023-08-04T17:05:00Z")

</div>

Hey guys, I'm fairly new working with Kibana and the ELK stack. I currently have logs being sent roughly every 12 hours, containing packages and their versions. My goal, is to create a table that groups the data by the…

---

## [Wildcard query took 200 seconds with version 8.8 but only a few seconds with 6.3](https://discuss.elastic.co/t/wildcard-query-took-200-seconds-with-version-8-8-but-only-a-few-seconds-with-6-3/340152)

<div class="topic-metadata">

**Author:** [@xluan](https://discuss.elastic.co/u/xluan)\
**Replies:** 0\
**Last updated:** [August 4, 2023, 4:53pm UTC](https://discuss.elastic.co/t/wildcard-query-took-200-seconds-with-version-8-8-but-only-a-few-seconds-with-6-3/340152 "2023-08-04T16:53:49Z")

</div>

We are migrating Elastic from 6.3 to 8,8. But the wildcard queries (in query string) are excessively slow in 8,8 as compared with 6.3. For example, for query "abcddcba\*" that does not actually match anything, it takes 4 …

---

## [How we can remove deduplication event in logstash](https://discuss.elastic.co/t/how-we-can-remove-deduplication-event-in-logstash/340060)

<div class="topic-metadata">

**Author:** [@Sukhdeob\_95](https://discuss.elastic.co/u/Sukhdeob_95)\
**Replies:** 6\
**Last updated:** [August 4, 2023, 4:53pm UTC](https://discuss.elastic.co/t/how-we-can-remove-deduplication-event-in-logstash/340060 "2023-08-04T16:53:48Z")

</div>

I want to remove the duplicate event based on particular field of my input i wrote logic like following but i got an error aggregate { task\_id =\> "%{\[meta\]\[ingestionHash\]}" code =\> " map\['@metadata'\]\['keep'\] ||= ev…

---

## [Is there a way to have an aggregation bucket that delivery the sum of other values](https://discuss.elastic.co/t/is-there-a-way-to-have-an-aggregation-bucket-that-delivery-the-sum-of-other-values/340148)

<div class="topic-metadata">

**Author:** [@Fabio\_Batalha](https://discuss.elastic.co/u/Fabio_Batalha)\
**Replies:** 0\
**Last updated:** [August 4, 2023, 3:35pm UTC](https://discuss.elastic.co/t/is-there-a-way-to-have-an-aggregation-bucket-that-delivery-the-sum-of-other-values/340148 "2023-08-04T15:35:26Z")

</div>

I'm doing an aggregation, limiting the buckets size to 6, and I would have a bucket having the sum of the other values. I see Kibana deal with that in a hidden way. At Kibana we can configure an aggregation to delivery …

---

## [Becoming ECS Compliant](https://discuss.elastic.co/t/becoming-ecs-compliant/340080)

<div class="topic-metadata">

**Author:** [@wwalker](https://discuss.elastic.co/u/wwalker)\
**Replies:** 6\
**Last updated:** [August 4, 2023, 3:33pm UTC](https://discuss.elastic.co/t/becoming-ecs-compliant/340080 "2023-08-04T15:33:31Z")

</div>

I've been ingesting datasets from before ECS was a thing that now have an ECS mapping. What would be the most efficient means of ingesting data (moving forward) so that it is ECS compliant? Examples of datasets are For…

---

## [Getting an error while running the logstash email output plugin - Unknown Garbage collector name- "G1 -Concurrent GC"](https://discuss.elastic.co/t/getting-an-error-while-running-the-logstash-email-output-plugin-unknown-garbage-collector-name-g1-concurrent-gc/340133)

<div class="topic-metadata">

**Author:** [@AKCG23](https://discuss.elastic.co/u/AKCG23)\
**Replies:** 1\
**Last updated:** [August 4, 2023, 2:47pm UTC](https://discuss.elastic.co/t/getting-an-error-while-running-the-logstash-email-output-plugin-unknown-garbage-collector-name-g1-concurrent-gc/340133 "2023-08-04T14:47:18Z")

</div>

I Have configured Logstash 7.17.3 and Heart beats 7.17.3. I am trying to send an email alert , if the url returns a code 401 . I have configured the email output plugin. While running the logstash i get this error. \[20…

---

## [Kibana Input controls old v/s new](https://discuss.elastic.co/t/kibana-input-controls-old-v-s-new/339915)

<div class="topic-metadata">

**Author:** [@VVK](https://discuss.elastic.co/u/VVK)\
**Replies:** 4\
**Last updated:** [August 4, 2023, 1:56pm UTC](https://discuss.elastic.co/t/kibana-input-controls-old-v-s-new/339915 "2023-08-04T13:56:51Z")

</div>

Hi, We are using Kibana/Elasticsearch /eck managed for our dev/production (non customer facing UIs) to analyse many things. Sometime back kibana depricated beta version / non-guaranteed (non production ready) versions …

---

## [Logstash / Beats Encryption Error](https://discuss.elastic.co/t/logstash-beats-encryption-error/340140)

<div class="topic-metadata">

**Author:** [@WLhelp](https://discuss.elastic.co/u/WLhelp)\
**Replies:** 0\
**Last updated:** [August 4, 2023, 1:44pm UTC](https://discuss.elastic.co/t/logstash-beats-encryption-error/340140 "2023-08-04T13:44:09Z")

</div>

Hey folks, i have trouble setting up encryption for Beats send to logstash server. Test Config says "ok", test output on the client gives me: logstash: 10.1.7.27:5044... connection... parse host... OK dns lookup...…

---

## [Multipath in the pipeline not working](https://discuss.elastic.co/t/multipath-in-the-pipeline-not-working/339842)

<div class="topic-metadata">

**Author:** [@anupvtr](https://discuss.elastic.co/u/anupvtr)\
**Replies:** 2\
**Last updated:** [August 4, 2023, 1:09pm UTC](https://discuss.elastic.co/t/multipath-in-the-pipeline-not-working/339842 "2023-08-04T13:09:11Z")

</div>

Hello All, Thanks in advance. We have succesfully sending the data to the Logz.io console via custom application. There was a specific request to add one more path in addition to the existing path. The logs that are p…

---

## [Elastic Serverless Forwarder for AWS adding reserved \_id field when sending to logstash](https://discuss.elastic.co/t/elastic-serverless-forwarder-for-aws-adding-reserved-id-field-when-sending-to-logstash/340084)

<div class="topic-metadata">

**Author:** [@stabbotco1](https://discuss.elastic.co/u/stabbotco1)\
**Replies:** 3\
**Last updated:** [August 4, 2023, 12:55pm UTC](https://discuss.elastic.co/t/elastic-serverless-forwarder-for-aws-adding-reserved-id-field-when-sending-to-logstash/340084 "2023-08-04T12:55:27Z")

</div>

Hi All! I am new to ES, so apologies in advance if I mis-state some things. We are looking to use the ES Serverless Forwarder for AWS (Elastic Serverless Forwarder for AWS | Elastic Serverless Forwarder Guide | Elastic)…

---

## [Can Logstash be setup separately after deploying Elasticsearch using AzureRM template?](https://discuss.elastic.co/t/can-logstash-be-setup-separately-after-deploying-elasticsearch-using-azurerm-template/339152)

<div class="topic-metadata">

**Author:** [@Haralambie\_Lungu](https://discuss.elastic.co/u/Haralambie_Lungu)\
**Replies:** 1\
**Last updated:** [August 4, 2023, 11:59am UTC](https://discuss.elastic.co/t/can-logstash-be-setup-separately-after-deploying-elasticsearch-using-azurerm-template/339152 "2023-08-04T11:59:58Z")

</div>

Hi everyone, We have deployed Elasticsearch Self-Managed using the ARM template from Azure Marketplace. We haven't checked Logstash during the setup process, we only created the kibana, master-0,1 and 2 and also the da…

---

## [Sorting help with query](https://discuss.elastic.co/t/sorting-help-with-query/340128)

<div class="topic-metadata">

**Author:** [@lakhr034](https://discuss.elastic.co/u/lakhr034)\
**Replies:** 0\
**Last updated:** [August 4, 2023, 11:58am UTC](https://discuss.elastic.co/t/sorting-help-with-query/340128 "2023-08-04T11:58:40Z")

</div>

{ "query": { "bool": { "must": \[ { "term": { "status": { "value": 1 } } } \], "should": \[ { "wildcard": {…

---

## [Help me to query this document](https://discuss.elastic.co/t/help-me-to-query-this-document/340110)

<div class="topic-metadata">

**Author:** [@marcin\_cron](https://discuss.elastic.co/u/marcin_cron)\
**Replies:** 3\
**Last updated:** [August 4, 2023, 9:19am UTC](https://discuss.elastic.co/t/help-me-to-query-this-document/340110 "2023-08-04T09:19:02Z")

</div>

This is my documents: //document 1 { "place": "galaxy", "range": { "area": { "planet": "mars", "country": \[ -----------country 1------------------ …

---

## [Logstash:grok:Create a single structure from multiple pattern](https://discuss.elastic.co/t/logstashcreate-a-single-structure-from-multiple-pattern/340098)

<div class="topic-metadata">

**Author:** [@nehag](https://discuss.elastic.co/u/nehag)\
**Replies:** 0\
**Last updated:** [August 4, 2023, 6:15am UTC](https://discuss.elastic.co/t/logstashcreate-a-single-structure-from-multiple-pattern/340098 "2023-08-04T06:15:12Z")

</div>

I have logs coming in the following pattern: ================================================================================================== CHECK 1 : Below are the missing Components in the patch =================…

---

## [Grokparse failure even grok debugger fine](https://discuss.elastic.co/t/grokparse-failure-even-grok-debugger-fine/340023)

<div class="topic-metadata">

**Author:** [@shailendra1](https://discuss.elastic.co/u/shailendra1)\
**Replies:** 8\
**Last updated:** [August 4, 2023, 4:17am UTC](https://discuss.elastic.co/t/grokparse-failure-even-grok-debugger-fine/340023 "2023-08-04T04:17:25Z")

</div>

Hi All, i am facing the grokparsefailure for my logs even the grok debugger is showing all parsed data but logstash is failing for all fields. below is my filter of logstash filter { grok { …

---

## [Inserting Custom Logs Into Siem](https://discuss.elastic.co/t/inserting-custom-logs-into-siem/340092)

<div class="topic-metadata">

**Author:** [@Nishant\_Chauhan](https://discuss.elastic.co/u/Nishant_Chauhan)\
**Replies:** 0\
**Last updated:** [August 4, 2023, 3:35am UTC](https://discuss.elastic.co/t/inserting-custom-logs-into-siem/340092 "2023-08-04T03:35:16Z")

</div>

Hi @cwurm, Referring to this topic - Inserting Custom Logs Into Siem I am using Custom Log Integration, using everything as default , I only added custom pattern for below logs. 2023-07-25T08:05:25.661Z ERRO 1 --- \[…

---

## [Rename json nested fields using mutate](https://discuss.elastic.co/t/rename-json-nested-fields-using-mutate/340063)

<div class="topic-metadata">

**Author:** [@mario\_kazela](https://discuss.elastic.co/u/mario_kazela)\
**Replies:** 4\
**Last updated:** [August 4, 2023, 3:32am UTC](https://discuss.elastic.co/t/rename-json-nested-fields-using-mutate/340063 "2023-08-04T03:32:03Z")

</div>

Hi, I have an issue with mutating a nested JSON fields using Logstash. Example of my nested JSON: "test\_results\_result\_legacy\_entities\_hashtags": \[ { "indices": \[ 34, 43 \], "text"…

[Previous page](https://discuss.elastic.co/tag/none.md?no_tags=true&page=325)

[Next page](https://discuss.elastic.co/tag/none.md?no_tags=true&page=327)
