# \#none

**URL:** https://discuss.elastic.co/tag/none.md?no_tags=true&page=330

[Latest](https://discuss.elastic.co/latest.md) · [Categories](https://discuss.elastic.co/categories.md) · [Tags](https://discuss.elastic.co/tags.md)

**Page:** 331

---

## [Create a kibana dashboard for user account lockouts](https://discuss.elastic.co/t/create-a-kibana-dashboard-for-user-account-lockouts/339463)

<div class="topic-metadata">

**Author:** [@kibana\_user17](https://discuss.elastic.co/u/kibana_user17)\
**Replies:** 9\
**Last updated:** [July 31, 2023, 11:07am UTC](https://discuss.elastic.co/t/create-a-kibana-dashboard-for-user-account-lockouts/339463 "2023-07-31T11:07:15Z")

</div>

Hi everyone. i'm very new to elasticsearch. Is it possible to create a dashboard in Kibana showing user account lockouts? If so, how? We used winlogbeat and elasticsearch. Appreciate the help..

---

## [Too many fields in an index](https://discuss.elastic.co/t/too-many-fields-in-an-index/339679)

<div class="topic-metadata">

**Author:** [@Jurrien](https://discuss.elastic.co/u/Jurrien)\
**Replies:** 0\
**Last updated:** [July 31, 2023, 10:55am UTC](https://discuss.elastic.co/t/too-many-fields-in-an-index/339679 "2023-07-31T10:55:28Z")

</div>

We have an index with the following structure (see below) So basically, we have our index business\_objects with a link and no. We add objects to this index (doc\_type1, doc\_type2, ....). These objects are linked via no …

---

## [Word count using Logstash Pipeline](https://discuss.elastic.co/t/word-count-using-logstash-pipeline/339678)

<div class="topic-metadata">

**Author:** [@rvadiga](https://discuss.elastic.co/u/rvadiga)\
**Replies:** 0\
**Last updated:** [July 31, 2023, 10:53am UTC](https://discuss.elastic.co/t/word-count-using-logstash-pipeline/339678 "2023-07-31T10:53:13Z")

</div>

Hi Team, I am trying to build and design a logstash pipeline where the count of different words tracked against the timestamp. I need to classify every word based on length of texts in three segments, say words with …

---

## [Support hieroglyphs and symbols](https://discuss.elastic.co/t/support-hieroglyphs-and-symbols/339677)

<div class="topic-metadata">

**Author:** [@viachaslau](https://discuss.elastic.co/u/viachaslau)\
**Replies:** 0\
**Last updated:** [July 31, 2023, 10:45am UTC](https://discuss.elastic.co/t/support-hieroglyphs-and-symbols/339677 "2023-07-31T10:45:39Z")

</div>

What analyzer I should use for support hieroglyphs and symbols. I cant use ICU because It remove symbols.

---

## [Getting user id from logstash](https://discuss.elastic.co/t/getting-user-id-from-logstash/339504)

<div class="topic-metadata">

**Author:** [@frh](https://discuss.elastic.co/u/frh)\
**Replies:** 1\
**Last updated:** [July 31, 2023, 10:01am UTC](https://discuss.elastic.co/t/getting-user-id-from-logstash/339504 "2023-07-31T10:01:29Z")

</div>

Hi, I've been trying to get this output in kibana by modifying my logstash, but to no avail. I'm not sure what went wrong. Input: User 'xxxxxx' logged in with concurrent ALM My logstash looks something like this: matc…

---

## [Maximum normal shards open achived](https://discuss.elastic.co/t/maximum-normal-shards-open-achived/339529)

<div class="topic-metadata">

**Author:** [@Patryk\_Ostrowski](https://discuss.elastic.co/u/Patryk_Ostrowski)\
**Replies:** 6\
**Last updated:** [July 31, 2023, 9:10am UTC](https://discuss.elastic.co/t/maximum-normal-shards-open-achived/339529 "2023-07-31T09:10:58Z")

</div>

Hello, I have one node ELK, I know that is not the best solution, but I cannot change that. I put logs to ELK, and every day I have new index for example: alerts-2023-07-23. But after few months of working filebeat showe…

---

## [Getting error when trying to run a filebeat](https://discuss.elastic.co/t/getting-error-when-trying-to-run-a-filebeat/339651)

<div class="topic-metadata">

**Author:** [@rkannan](https://discuss.elastic.co/u/rkannan)\
**Replies:** 3\
**Last updated:** [July 31, 2023, 9:00am UTC](https://discuss.elastic.co/t/getting-error-when-trying-to-run-a-filebeat/339651 "2023-07-31T09:00:36Z")

</div>

Exiting: fileset tomcat/error is configured but doesn't exist

---

## [How to add thousand of objects](https://discuss.elastic.co/t/how-to-add-thousand-of-objects/339124)

<div class="topic-metadata">

**Author:** [@senadk](https://discuss.elastic.co/u/senadk)\
**Replies:** 2\
**Last updated:** [July 31, 2023, 8:46am UTC](https://discuss.elastic.co/t/how-to-add-thousand-of-objects/339124 "2023-07-31T08:46:08Z")

</div>

Hi everyone, Im new to Elastic and i can't find a way to add big data (read 150k SQL rows) at once to my index. Im using postman to execute the endpoints like \_bulk. What i would like is to copy my 150k rows from my S…

---

## [Multiple JDBC input for different tables and output into separate indexes](https://discuss.elastic.co/t/multiple-jdbc-input-for-different-tables-and-output-into-separate-indexes/339596)

<div class="topic-metadata">

**Author:** [@Youdeep](https://discuss.elastic.co/u/Youdeep)\
**Replies:** 1\
**Last updated:** [July 31, 2023, 7:58am UTC](https://discuss.elastic.co/t/multiple-jdbc-input-for-different-tables-and-output-into-separate-indexes/339596 "2023-07-31T07:58:29Z")

</div>

Hello I'm new to ELK. Question - How do I use different index when importing tables from DB using logstash. I have used multiple JDBC input for different tables and separate output for each table in logstash. Logstash s…

---

## [\[o.e.t.TransportService\] Received response for a request that has timed out](https://discuss.elastic.co/t/o-e-t-transportservice-received-response-for-a-request-that-has-timed-out/339056)

<div class="topic-metadata">

**Author:** [@EVINDX](https://discuss.elastic.co/u/EVINDX)\
**Replies:** 16\
**Last updated:** [July 31, 2023, 7:54am UTC](https://discuss.elastic.co/t/o-e-t-transportservice-received-response-for-a-request-that-has-timed-out/339056 "2023-07-31T07:54:54Z")

</div>

We are receiving the following error {ElasticsearchLogger} \[o.e.t.TransportService\] Received response for a request that has timed out, sent \[21.3s/21361ms\] ago, timed out \[5.6s/5682ms\] ago, action \[indices:monitor/stat…

---

## [How to visualize user login](https://discuss.elastic.co/t/how-to-visualize-user-login/339280)

<div class="topic-metadata">

**Author:** [@frh](https://discuss.elastic.co/u/frh)\
**Replies:** 3\
**Last updated:** [July 31, 2023, 7:50am UTC](https://discuss.elastic.co/t/how-to-visualize-user-login/339280 "2023-07-31T07:50:38Z")

</div>

Hi, I'm trying to figure out the number of user logins in certain instance. The reason being is I want to see how many users have logged in to instance ABC and who are the users logged in to instance ABC. Thank you.

---

## [How to forward ALL logs](https://discuss.elastic.co/t/how-to-forward-all-logs/339653)

<div class="topic-metadata">

**Author:** [@willsy](https://discuss.elastic.co/u/willsy)\
**Replies:** 0\
**Last updated:** [July 31, 2023, 7:20am UTC](https://discuss.elastic.co/t/how-to-forward-all-logs/339653 "2023-07-31T07:20:41Z")

</div>

I have the following logstash configuration file that successfully sends information to a third party location. Effectively what i am asking is, how do i constantly send ALL the data going into elastic to this third par…

---

## [Logstash querying elasticsearch timeout error](https://discuss.elastic.co/t/logstash-querying-elasticsearch-timeout-error/339085)

<div class="topic-metadata">

**Author:** [@willsy](https://discuss.elastic.co/u/willsy)\
**Replies:** 4\
**Last updated:** [July 31, 2023, 7:09am UTC](https://discuss.elastic.co/t/logstash-querying-elasticsearch-timeout-error/339085 "2023-07-31T07:09:33Z")

</div>

Hello, I have the following error; just seeing if anyone knows where i am setting this? i originally put the timeout setting in the testpipeline.conf for logstash. Any help is greatly appreciated \[2023-07-24T11:59:41,3…

---

## [Auto authentication of user in python application](https://discuss.elastic.co/t/auto-authentication-of-user-in-python-application/339648)

<div class="topic-metadata">

**Author:** [@Rushi\_Bagul](https://discuss.elastic.co/u/Rushi_Bagul)\
**Replies:** 0\
**Last updated:** [July 31, 2023, 6:50am UTC](https://discuss.elastic.co/t/auto-authentication-of-user-in-python-application/339648 "2023-07-31T06:50:59Z")

</div>

Hi team, I have my django application in which I am rendering iframed Kibana dashboard. If am log in django application at same time log in iframed Kibana dashboard as well, it won't log in again in Kibana dashboard. S…

---

## [Elasticsearch Memory Utilization](https://discuss.elastic.co/t/elasticsearch-memory-utilization/338928)

<div class="topic-metadata">

**Author:** [@Debasis\_Mallick](https://discuss.elastic.co/u/Debasis_Mallick)\
**Replies:** 8\
**Last updated:** [July 31, 2023, 6:31am UTC](https://discuss.elastic.co/t/elasticsearch-memory-utilization/338928 "2023-07-31T06:31:44Z")

</div>

Hi Team, I am new to the Elasticsearch world. I had installed the Elasticsearch in one of my lab VM, where it is showing memory utilization is 8.3 GB when I check "systemctl status elasticsearch" and VM gets hang. Is t…

---

## [Group By Datetime fields While querying](https://discuss.elastic.co/t/group-by-datetime-fields-while-querying/339639)

<div class="topic-metadata">

**Author:** [@cybercom](https://discuss.elastic.co/u/cybercom)\
**Replies:** 0\
**Last updated:** [July 31, 2023, 4:03am UTC](https://discuss.elastic.co/t/group-by-datetime-fields-while-querying/339639 "2023-07-31T04:03:12Z")

</div>

I need to group by day in my query, so i'm trying to apply group by with datetime field as below: { "\_source": "false", "query": { "match\_all": {} }, "aggs": { "group\_by\_weekday": { …

---

## [Rename nested field in Logstash using Ruby filter](https://discuss.elastic.co/t/rename-nested-field-in-logstash-using-ruby-filter/339637)

<div class="topic-metadata">

**Author:** [@mario\_kazela](https://discuss.elastic.co/u/mario_kazela)\
**Replies:** 1\
**Last updated:** [July 31, 2023, 3:57am UTC](https://discuss.elastic.co/t/rename-nested-field-in-logstash-using-ruby-filter/339637 "2023-07-31T03:57:52Z")

</div>

Hi, I have some issues with rename a nested field in json. Example of nested field: test\_results.result.legacy.entities.user\_mentions.name then i want to rename it to displayname I have try this method, but unfortuna…

---

## [Pipeline Fail, failed to load pipeline. Error: Expected one of \[ \\\\t\\\\r\\\\n\], \\"#\\", \\"input\\", \\"filter\\", \\"output\\" at line 21](https://discuss.elastic.co/t/pipeline-fail-failed-to-load-pipeline-error-expected-one-of-t-r-n-input-filter-output-at-line-21/339615)

<div class="topic-metadata">

**Author:** [@Youdeep](https://discuss.elastic.co/u/Youdeep)\
**Replies:** 3\
**Last updated:** [July 31, 2023, 12:05am UTC](https://discuss.elastic.co/t/pipeline-fail-failed-to-load-pipeline-error-expected-one-of-t-r-n-input-filter-output-at-line-21/339615 "2023-07-31T00:05:17Z")

</div>

Running a pipeline with two config file: Error after running: logstash -f .\\config\\pipelines.yml Error: \[ERROR\]\[logstash.agent \] Failed to execute action {:action=\>LogStash::PipelineAction::Create/pipeline\_i…

---

## [Issues configuring SSL TCP Syslog Collection - Palo Alto Integration](https://discuss.elastic.co/t/issues-configuring-ssl-tcp-syslog-collection-palo-alto-integration/339572)

<div class="topic-metadata">

**Author:** [@elasticnub](https://discuss.elastic.co/u/elasticnub)\
**Replies:** 8\
**Last updated:** [July 30, 2023, 6:01pm UTC](https://discuss.elastic.co/t/issues-configuring-ssl-tcp-syslog-collection-palo-alto-integration/339572 "2023-07-30T18:01:35Z")

</div>

I am new to the Elastic ecosystem and looking for assistance...trying to configure tcp SSL collection for palo logs from cortex datalake... this cert worked fine with our previous solution so I know nothing is wrong with…

---

## [Split type failure Logstash](https://discuss.elastic.co/t/split-type-failure-logstash/339594)

<div class="topic-metadata">

**Author:** [@Bharat\_Lahori](https://discuss.elastic.co/u/Bharat_Lahori)\
**Replies:** 2\
**Last updated:** [July 29, 2023, 5:58pm UTC](https://discuss.elastic.co/t/split-type-failure-logstash/339594 "2023-07-29T17:58:16Z")

</div>

Dear Team, I have configured below logstash conf file . Trying to give stdin input and getting an error as split type failure. PFB details. We need to create two events based on metricValues. Conf file input { stdi…

---

## [Logstash Json Parsing Error](https://discuss.elastic.co/t/logstash-json-parsing-error/339515)

<div class="topic-metadata">

**Author:** [@fizem](https://discuss.elastic.co/u/fizem)\
**Replies:** 1\
**Last updated:** [July 28, 2023, 9:03pm UTC](https://discuss.elastic.co/t/logstash-json-parsing-error/339515 "2023-07-28T21:03:46Z")

</div>

Hi, I have setup the following pipeline to consolidate my logs in Elastic Search Cluster : filebeat to gather nginx logs ==\> logstash to parse the log and mutate them if needed ==\> Elasticsearch cluster. I'm facing an…

---

## [How to validate a json value is numeric](https://discuss.elastic.co/t/how-to-validate-a-json-value-is-numeric/339562)

<div class="topic-metadata">

**Author:** [@sc5283](https://discuss.elastic.co/u/sc5283)\
**Replies:** 4\
**Last updated:** [July 28, 2023, 9:01pm UTC](https://discuss.elastic.co/t/how-to-validate-a-json-value-is-numeric/339562 "2023-07-28T21:01:27Z")

</div>

noob question I have a JSON as follows: {"attr1":"One", "attr2":"300"} {"attr1":"Two","attr2":45.0} {"attr1":"Three","attr2":"Not Set"} attr2 is a numeric value How do I check if attr2 is numeric, not a string befo…

---

## [Phrase suggester giving suggestion on correct terms containing number values](https://discuss.elastic.co/t/phrase-suggester-giving-suggestion-on-correct-terms-containing-number-values/339579)

<div class="topic-metadata">

**Author:** [@Pavithra2014](https://discuss.elastic.co/u/Pavithra2014)\
**Replies:** 0\
**Last updated:** [July 28, 2023, 6:14pm UTC](https://discuss.elastic.co/t/phrase-suggester-giving-suggestion-on-correct-terms-containing-number-values/339579 "2023-07-28T18:14:33Z")

</div>

Team, We are using Phrase suggestion with below configuration. but this is returning suggestion on correct speeled words having numeric values on it. eg: Product 2023 is giving the suggestion Product 2022 . I'm expect…

---

## [Validate document before sending to elasticsearch](https://discuss.elastic.co/t/validate-document-before-sending-to-elasticsearch/337859)

<div class="topic-metadata">

**Author:** [@A\_Mightiev](https://discuss.elastic.co/u/A_Mightiev)\
**Replies:** 2\
**Last updated:** [July 28, 2023, 3:19pm UTC](https://discuss.elastic.co/t/validate-document-before-sending-to-elasticsearch/337859 "2023-07-28T15:19:00Z")

</div>

Hi, I have a strict mapping in my ES cluster and send documents via Logstash, sometimes the documents get dropped because they don't conform the strict mapping, is there a way to check if the document conforms or not to…

---

## [Translation does not work in Logged Out Page and Apply Filters in Unified Search](https://discuss.elastic.co/t/translation-does-not-work-in-logged-out-page-and-apply-filters-in-unified-search/338341)

<div class="topic-metadata">

**Author:** [@wsbr](https://discuss.elastic.co/u/wsbr)\
**Replies:** 8\
**Last updated:** [July 28, 2023, 3:12pm UTC](https://discuss.elastic.co/t/translation-does-not-work-in-logged-out-page-and-apply-filters-in-unified-search/338341 "2023-07-28T15:12:11Z")

</div>

Hi, We are using Elasticsearch 8.7.1 and some actions does not be translated. How to solve this problem?

---

## [How to use the JSON filter correctly?](https://discuss.elastic.co/t/how-to-use-the-json-filter-correctly/339372)

<div class="topic-metadata">

**Author:** [@Chel\_Db](https://discuss.elastic.co/u/Chel_Db)\
**Replies:** 13\
**Last updated:** [July 28, 2023, 2:27pm UTC](https://discuss.elastic.co/t/how-to-use-the-json-filter-correctly/339372 "2023-07-28T14:27:51Z")

</div>

Application logs is of below JSON format and I'm unsure what should be the source field incase I'm using the JSON filter ? I would like to have all the fields appear on the Kibana output, particularly the message field,…

---

## [Kibana login problem](https://discuss.elastic.co/t/kibana-login-problem/339538)

<div class="topic-metadata">

**Author:** [@Ibrahim\_Z\_HIDIR](https://discuss.elastic.co/u/Ibrahim_Z_HIDIR)\
**Replies:** 3\
**Last updated:** [July 28, 2023, 2:20pm UTC](https://discuss.elastic.co/t/kibana-login-problem/339538 "2023-07-28T14:20:36Z")

</div>

Hi all We are experiencing a problem when trying to login kibana 8.8.2, I could't find anythink, does anybody has an idea? thanks

---

## [Pass min\_score to shoudl close](https://discuss.elastic.co/t/pass-min-score-to-shoudl-close/339561)

<div class="topic-metadata">

**Author:** [@john\_nicolas](https://discuss.elastic.co/u/john_nicolas)\
**Replies:** 0\
**Last updated:** [July 28, 2023, 2:16pm UTC](https://discuss.elastic.co/t/pass-min-score-to-shoudl-close/339561 "2023-07-28T14:16:43Z")

</div>

i want to pass a min\_score but for only should clauses, i want filter should clause by min\_score to eliminate docs which have cosinesimilarity poor {'bool': {'filter': {'term': {'hidden': 'false'}}, 'must': \[{'bool': {'…

---

## [Could not push logs to Elasticsearch cluster](https://discuss.elastic.co/t/could-not-push-logs-to-elasticsearch-cluster/339488)

<div class="topic-metadata">

**Author:** [@Vikas1633](https://discuss.elastic.co/u/Vikas1633)\
**Replies:** 1\
**Last updated:** [July 28, 2023, 1:16pm UTC](https://discuss.elastic.co/t/could-not-push-logs-to-elasticsearch-cluster/339488 "2023-07-28T13:16:04Z")

</div>

I am facing issue could not push logs to Elasticsearch cluster but when i change the buffer path and restart elastic it gets solved and every odd day I have to do this, looking for some permanent solution over this. :El…

---

## [\_mget vs \_search for large amount of documents](https://discuss.elastic.co/t/mget-vs-search-for-large-amount-of-documents/339521)

<div class="topic-metadata">

**Author:** [@hattorihanzo](https://discuss.elastic.co/u/hattorihanzo)\
**Replies:** 4\
**Last updated:** [July 28, 2023, 12:40pm UTC](https://discuss.elastic.co/t/mget-vs-search-for-large-amount-of-documents/339521 "2023-07-28T12:40:39Z")

</div>

Hi there! I'm looking for some guidance around what's the most fit way to retrieve a large amount of documents (\>=1000) when you know their ID. I'd like it to be fast, yet efficient and not put unnecessary strain on ES s…

[Previous page](https://discuss.elastic.co/tag/none.md?no_tags=true&page=329)

[Next page](https://discuss.elastic.co/tag/none.md?no_tags=true&page=331)
