# \#none

**URL:** https://discuss.elastic.co/tag/none.md?no_tags=true&page=333

[Latest](https://discuss.elastic.co/latest.md) · [Categories](https://discuss.elastic.co/categories.md) · [Tags](https://discuss.elastic.co/tags.md)

**Page:** 334

---

## [Logstash stops processing syslog messages when DNS server not available](https://discuss.elastic.co/t/logstash-stops-processing-syslog-messages-when-dns-server-not-available/339334)

<div class="topic-metadata">

**Author:** [@RJC](https://discuss.elastic.co/u/RJC)\
**Replies:** 0\
**Last updated:** [July 26, 2023, 5:07pm UTC](https://discuss.elastic.co/t/logstash-stops-processing-syslog-messages-when-dns-server-not-available/339334 "2023-07-26T17:07:09Z")

</div>

Running Logstash 8.5.2 on RHEL. I implemented DNS filter plugin to resolve IP addresses to hostnames for all syslog nodes reporting to this logstash server. I am using our local DNS server. It all worked perfectly unti…

---

## [How to create a Security Rule (SIEM) for Custom Logs Integration](https://discuss.elastic.co/t/how-to-create-a-security-rule-siem-for-custom-logs-integration/339327)

<div class="topic-metadata">

**Author:** [@Nishant\_Chauhan](https://discuss.elastic.co/u/Nishant_Chauhan)\
**Replies:** 0\
**Last updated:** [July 26, 2023, 3:51pm UTC](https://discuss.elastic.co/t/how-to-create-a-security-rule-siem-for-custom-logs-integration/339327 "2023-07-26T15:51:29Z")

</div>

Hi Team, I have setup Custom Logs Integration and able to create rules for observability. but rules are not working for Security dashboard. sample log 2023-07-26T08:05:25.661Z ERRO 1 --- \[nio-8080-exec-3\] c.i.c.b.c.H…

---

## [Pagination + Sorted Aggregations: Efficiently Retrieve Sorted List of Values?](https://discuss.elastic.co/t/pagination-sorted-aggregations-efficiently-retrieve-sorted-list-of-values/339325)

<div class="topic-metadata">

**Author:** [@openelasticsearch](https://discuss.elastic.co/u/openelasticsearch)\
**Replies:** 1\
**Last updated:** [July 26, 2023, 3:15pm UTC](https://discuss.elastic.co/t/pagination-sorted-aggregations-efficiently-retrieve-sorted-list-of-values/339325 "2023-07-26T15:15:05Z")

</div>

Hi, I'm looking for some advice on the best way to implement an aggregation query that supports pagination and sorting. Quick Overview of My Documents & Desired Use Case: I have indexes that contain documents with a nu…

---

## [Error logstash \[logstash.outputs.elasticsearch\] Encountered a retryable error code=\>503](https://discuss.elastic.co/t/error-logstash-logstash-outputs-elasticsearch-encountered-a-retryable-error-code-503/328331)

<div class="topic-metadata">

**Author:** [@San9](https://discuss.elastic.co/u/San9)\
**Replies:** 13\
**Last updated:** [July 26, 2023, 2:56pm UTC](https://discuss.elastic.co/t/error-logstash-logstash-outputs-elasticsearch-encountered-a-retryable-error-code-503/328331 "2023-07-26T14:56:45Z")

</div>

Hi all. I'm a beginner at this. When setting up another pipelayer, after starting it, the following errors started to appear in the log for all other pipelines: logstash\[363391\]: \[2023-03-23T08:05:49,424\]\[ERROR\]\[logsta…

---

## [Installing Elasticsearch as an external service at OpenShift](https://discuss.elastic.co/t/installing-elasticsearch-as-an-external-service-at-openshift/338845)

<div class="topic-metadata">

**Author:** [@Yasser\_Alsawy](https://discuss.elastic.co/u/Yasser_Alsawy)\
**Replies:** 1\
**Last updated:** [July 26, 2023, 2:38pm UTC](https://discuss.elastic.co/t/installing-elasticsearch-as-an-external-service-at-openshift/338845 "2023-07-26T14:38:21Z")

</div>

We have OpenShift cluster and we want to install elasticsearch at ocp to serve both internal and external audit shipment. our design should be something like this: FileBeat (outside ocp) --\> Logstash (inside ocp) --\> El…

---

## [Which is the most stable version of elastic search in 8.x?](https://discuss.elastic.co/t/which-is-the-most-stable-version-of-elastic-search-in-8-x/339314)

<div class="topic-metadata">

**Author:** [@Pankaj\_Goyal](https://discuss.elastic.co/u/Pankaj_Goyal)\
**Replies:** 1\
**Last updated:** [July 26, 2023, 1:57pm UTC](https://discuss.elastic.co/t/which-is-the-most-stable-version-of-elastic-search-in-8-x/339314 "2023-07-26T13:57:34Z")

</div>

We are working on a use case where we have to most rely on vector matching searched. Please suggest most stable version for elastic 8.x.

---

## [Multiline Filter : How to group error logs with stacktrace to elastic search using logstash?](https://discuss.elastic.co/t/multiline-filter-how-to-group-error-logs-with-stacktrace-to-elastic-search-using-logstash/338952)

<div class="topic-metadata">

**Author:** [@karthi.charles](https://discuss.elastic.co/u/karthi.charles)\
**Replies:** 2\
**Last updated:** [July 26, 2023, 11:57am UTC](https://discuss.elastic.co/t/multiline-filter-how-to-group-error-logs-with-stacktrace-to-elastic-search-using-logstash/338952 "2023-07-26T11:57:45Z")

</div>

I am trying to group Error logs which having stacktrace information using multiline filter. Not sure how to set pattern correctly. Kindly help me to config the correct pattern. This is my logging pattern, INFO | 2023-…

---

## [Install elasticsearch 8.8](https://discuss.elastic.co/t/install-elasticsearch-8-8/339304)

<div class="topic-metadata">

**Author:** [@abntkpi](https://discuss.elastic.co/u/abntkpi)\
**Replies:** 0\
**Last updated:** [July 26, 2023, 11:54am UTC](https://discuss.elastic.co/t/install-elasticsearch-8-8/339304 "2023-07-26T11:54:44Z")

</div>

Hello, I intend to install Elasticsearch 8.8 on an Ubuntu 22.04 server following the link below: Install Elasticsearch with Debian Package | Elasticsearch Guide \[8.9\] | Elastic The server has internet access, and the a…

---

## [Why comments field not being displayed](https://discuss.elastic.co/t/why-comments-field-not-being-displayed/338228)

<div class="topic-metadata">

**Author:** [@Dana\_Pavaday](https://discuss.elastic.co/u/Dana_Pavaday)\
**Replies:** 8\
**Last updated:** [July 26, 2023, 11:16am UTC](https://discuss.elastic.co/t/why-comments-field-not-being-displayed/338228 "2023-07-26T11:16:40Z")

</div>

Why is the comment field not being displayed for some Affected Services field values (Memory, CPU) in the Dashboard when they are already being displayed in Discover? Is this an issue with the logstash? What should be d…

---

## [Incorrect links in Kibana plugin documentation](https://discuss.elastic.co/t/incorrect-links-in-kibana-plugin-documentation/339097)

<div class="topic-metadata">

**Author:** [@Sheereen](https://discuss.elastic.co/u/Sheereen)\
**Replies:** 3\
**Last updated:** [July 26, 2023, 10:28am UTC](https://discuss.elastic.co/t/incorrect-links-in-kibana-plugin-documentation/339097 "2023-07-26T10:28:02Z")

</div>

Hi, Please update documentation for plugin development. There is very little/vague documentation, out of which most of them contains incorrect links to examples and github. This is just an example(Elasticsearch servic…

---

## [Date Filter](https://discuss.elastic.co/t/date-filter/337023)

<div class="topic-metadata">

**Author:** [@Kumar\_Abhinav](https://discuss.elastic.co/u/Kumar_Abhinav)\
**Replies:** 3\
**Last updated:** [July 26, 2023, 7:11am UTC](https://discuss.elastic.co/t/date-filter/337023 "2023-07-26T07:11:23Z")

</div>

I am trying to see how many count of items named from the data index has expiry date less than 30 days from now and also the count of items having expiry date till the next 30 days. I have tried a lot in TSVB with three …

---

## [Process logs of different formats to JSON](https://discuss.elastic.co/t/process-logs-of-different-formats-to-json/339258)

<div class="topic-metadata">

**Author:** [@Chel\_Db](https://discuss.elastic.co/u/Chel_Db)\
**Replies:** 0\
**Last updated:** [July 26, 2023, 6:45am UTC](https://discuss.elastic.co/t/process-logs-of-different-formats-to-json/339258 "2023-07-26T06:45:43Z")

</div>

I'm pretty new to ELK and I'm trying to push few of our service's logs to ES. Log funneling flow is --\> \` Fluentd --\> Logstash --\> ES --\> Kibana. \` A thing to note is that, each service has its own log format. Attach…

---

## [When using the index settings with auto\_expand\_replicas set to "0-all," an issue arises where primary shards are concentrated on specific nodes](https://discuss.elastic.co/t/when-using-the-index-settings-with-auto-expand-replicas-set-to-0-all-an-issue-arises-where-primary-shards-are-concentrated-on-specific-nodes/339185)

<div class="topic-metadata">

**Author:** [@wedul\_chul](https://discuss.elastic.co/u/wedul_chul)\
**Replies:** 2\
**Last updated:** [July 26, 2023, 4:31am UTC](https://discuss.elastic.co/t/when-using-the-index-settings-with-auto-expand-replicas-set-to-0-all-an-issue-arises-where-primary-shards-are-concentrated-on-specific-nodes/339185 "2023-07-26T04:31:01Z")

</div>

Due to the service requirements, the setting "auto\_expand\_replicas" is configured as "0-all," enabling replica shards to be present on all nodes. However, there is an issue where primary shards are concentrated on a spec…

---

## [Need advice on using Elasticsearch in a transaction processing application](https://discuss.elastic.co/t/need-advice-on-using-elasticsearch-in-a-transaction-processing-application/338265)

<div class="topic-metadata">

**Author:** [@Mike\_Z](https://discuss.elastic.co/u/Mike_Z)\
**Replies:** 2\
**Last updated:** [July 25, 2023, 11:13pm UTC](https://discuss.elastic.co/t/need-advice-on-using-elasticsearch-in-a-transaction-processing-application/338265 "2023-07-25T23:13:04Z")

</div>

We develop and maintain an ecommerce back-office fulfillment system. So, it has the transaction processing function to capture fulfillment requests from an ecommerce website, and the reporting, listing, and business fu…

---

## [How to overcome the two-billion limitation on the number of Elasticsearch records?](https://discuss.elastic.co/t/how-to-overcome-the-two-billion-limitation-on-the-number-of-elasticsearch-records/339232)

<div class="topic-metadata">

**Author:** [@Mike\_Z](https://discuss.elastic.co/u/Mike_Z)\
**Replies:** 1\
**Last updated:** [July 25, 2023, 11:01pm UTC](https://discuss.elastic.co/t/how-to-overcome-the-two-billion-limitation-on-the-number-of-elasticsearch-records/339232 "2023-07-25T23:01:55Z")

</div>

As explained in the below quoted post on StackOverflow, Elasticsearch has a limit of two billion documents. Yes there is limit to the number of docs per shard of 2 billion, which is a hard lucene limit. There is a max…

---

## [Getting started - Kibana - ElasticSearch - logstash](https://discuss.elastic.co/t/getting-started-kibana-elasticsearch-logstash/339204)

<div class="topic-metadata">

**Author:** [@rajdevworks](https://discuss.elastic.co/u/rajdevworks)\
**Replies:** 3\
**Last updated:** [July 25, 2023, 10:09pm UTC](https://discuss.elastic.co/t/getting-started-kibana-elasticsearch-logstash/339204 "2023-07-25T22:09:08Z")

</div>

Hello, I have different json files which I would like to visualize into Kibana after ingesting them to Elasticsearch. Where can I get started and do I need to define input/output filters?

---

## [We are seeing the issue on SonarQube with elasticsearch. Elastic search is not coming up preventing the sonarqube to be up and running](https://discuss.elastic.co/t/we-are-seeing-the-issue-on-sonarqube-with-elasticsearch-elastic-search-is-not-coming-up-preventing-the-sonarqube-to-be-up-and-running/339229)

<div class="topic-metadata">

**Author:** [@bipin23](https://discuss.elastic.co/u/bipin23)\
**Replies:** 1\
**Last updated:** [July 25, 2023, 9:56pm UTC](https://discuss.elastic.co/t/we-are-seeing-the-issue-on-sonarqube-with-elasticsearch-elastic-search-is-not-coming-up-preventing-the-sonarqube-to-be-up-and-running/339229 "2023-07-25T21:56:47Z")

</div>

Sonarqube version - 10.0.0 OS : RHEL 8 Java - opendfk 17 Here are the logs: 2023.07.25 21:03:47 ERROR es\[o.e.b.Elasticsearch\] fatal exception while booting Elasticsearch java.lang.ExceptionInInitializerError: null …

---

## [AlmaLinux OS 9](https://discuss.elastic.co/t/almalinux-os-9/338910)

<div class="topic-metadata">

**Author:** [@Nirjonadda](https://discuss.elastic.co/u/Nirjonadda)\
**Replies:** 4\
**Last updated:** [July 25, 2023, 8:27pm UTC](https://discuss.elastic.co/t/almalinux-os-9/338910 "2023-07-25T20:27:12Z")

</div>

Do you have any plan add support for AlmaLinux OS 9? Can not install Elasticsearch in AlmaLinux OS 9 because RPM signing key is invalid. rpm --import https://artifacts.elastic.co/GPG-KEY-elasticsearch warning: Signature…

---

## [Combine term and bucket range query](https://discuss.elastic.co/t/combine-term-and-bucket-range-query/339215)

<div class="topic-metadata">

**Author:** [@aelam](https://discuss.elastic.co/u/aelam)\
**Replies:** 2\
**Last updated:** [July 25, 2023, 8:09pm UTC](https://discuss.elastic.co/t/combine-term-and-bucket-range-query/339215 "2023-07-25T20:09:43Z")

</div>

I'm attempting to extract records of http success/failure data per user using an elasticsearch aggregation. I'm looking at two fields, "user.name" and "http.response.status\_code". My goal is to use a keyed range bucket …

---

## [How to set up 3 dedicate master + 4 data nodes also master elegible](https://discuss.elastic.co/t/how-to-set-up-3-dedicate-master-4-data-nodes-also-master-elegible/338887)

<div class="topic-metadata">

**Author:** [@hlcxpl](https://discuss.elastic.co/u/hlcxpl)\
**Replies:** 15\
**Last updated:** [July 25, 2023, 7:05pm UTC](https://discuss.elastic.co/t/how-to-set-up-3-dedicate-master-4-data-nodes-also-master-elegible/338887 "2023-07-25T19:05:02Z")

</div>

i need to set up 3 master node dedicate and 4 data node and master elegibles this is my yml configuration path.data: /var/lib/elasticsearch path.logs: /var/log/elasticsearch bootstrap.memory\_lock: true cluster.name: C…

---

## [Aligning array elements with parent in table visualization](https://discuss.elastic.co/t/aligning-array-elements-with-parent-in-table-visualization/338962)

<div class="topic-metadata">

**Author:** [@Thomas.c](https://discuss.elastic.co/u/Thomas.c)\
**Replies:** 3\
**Last updated:** [July 25, 2023, 7:16pm UTC](https://discuss.elastic.co/t/aligning-array-elements-with-parent-in-table-visualization/338962 "2023-07-25T19:16:53Z")

</div>

I'm trying to create a table visualization in Kibana. My data structure is like this: Vehicle{ Vehicle Number Vehicle make Vehicle model Vehicle year} Each record can have multiple vehicles in it, so the parent Veh…

---

## [Completely remove mapping check](https://discuss.elastic.co/t/completely-remove-mapping-check/339198)

<div class="topic-metadata">

**Author:** [@dastial](https://discuss.elastic.co/u/dastial)\
**Replies:** 2\
**Last updated:** [July 25, 2023, 6:15pm UTC](https://discuss.elastic.co/t/completely-remove-mapping-check/339198 "2023-07-25T18:15:23Z")

</div>

I'm using ES8+ to store a lot of different document, but I've encountered some problems with property mapping. I am working with documents, each of which has hundreds of different fields, many of them with the same name.…

---

## [Join two searches with nested field](https://discuss.elastic.co/t/join-two-searches-with-nested-field/339213)

<div class="topic-metadata">

**Author:** [@Murilo\_Livorato](https://discuss.elastic.co/u/Murilo_Livorato)\
**Replies:** 2\
**Last updated:** [July 25, 2023, 5:23pm UTC](https://discuss.elastic.co/t/join-two-searches-with-nested-field/339213 "2023-07-25T17:23:05Z")

</div>

hello , I have been trying to join those two searches , but I didnt managed . I want to do this - SELECT user-data WHERE company.id = 1 AND timestamp BETWEEEN 2023-05-04 - 2023-06-05 // RESULT 100 GET /user-data/\_se…

---

## [Kibana server is not ready yet](https://discuss.elastic.co/t/kibana-server-is-not-ready-yet/339009)

<div class="topic-metadata">

**Author:** [@SUNA](https://discuss.elastic.co/u/SUNA)\
**Replies:** 9\
**Last updated:** [July 25, 2023, 4:27pm UTC](https://discuss.elastic.co/t/kibana-server-is-not-ready-yet/339009 "2023-07-25T16:27:43Z")

</div>

Hi Team, My ELK cluster running in one node. while clearing Queue, I had restarted kibana and elk services. from now my URL is stuck with below error. Kibana server is not ready yet In order to fix this i have restar…

---

## [Following the quickstart guide: getting "Kibana server is not ready yet."](https://discuss.elastic.co/t/following-the-quickstart-guide-getting-kibana-server-is-not-ready-yet/338938)

<div class="topic-metadata">

**Author:** [@chadleywilson](https://discuss.elastic.co/u/chadleywilson)\
**Replies:** 6\
**Last updated:** [July 25, 2023, 3:58pm UTC](https://discuss.elastic.co/t/following-the-quickstart-guide-getting-kibana-server-is-not-ready-yet/338938 "2023-07-25T15:58:32Z")

</div>

Hi I have followed the 2.8.0 quickstart guide to the letter I have used the own certificate method and the sites are secure, I am happy with that. I have configured DNS and load balancing, and the pods and services lo…

---

## [Multiple pipelines bug with pipe-to-pipe config and CEF codec](https://discuss.elastic.co/t/multiple-pipelines-bug-with-pipe-to-pipe-config-and-cef-codec/338889)

<div class="topic-metadata">

**Author:** [@Markenstein](https://discuss.elastic.co/u/Markenstein)\
**Replies:** 23\
**Last updated:** [July 25, 2023, 3:52pm UTC](https://discuss.elastic.co/t/multiple-pipelines-bug-with-pipe-to-pipe-config-and-cef-codec/338889 "2023-07-25T15:52:09Z")

</div>

Hi, everyone! I have faced with such problem: several CEF strings pushed into the following pipelines configuration causing \_cefparseerror in result cause to incorrect string in the input. It's break original message in…

---

## [Kibana cuts HH:mm:ss off date in Table visualization](https://discuss.elastic.co/t/kibana-cuts-hhss-off-date-in-table-visualization/339195)

<div class="topic-metadata">

**Author:** [@OrangeBanana](https://discuss.elastic.co/u/OrangeBanana)\
**Replies:** 2\
**Last updated:** [July 25, 2023, 3:23pm UTC](https://discuss.elastic.co/t/kibana-cuts-hhss-off-date-in-table-visualization/339195 "2023-07-25T15:23:50Z")

</div>

In Elasticsearch I have dates saved in the yyyy-MM-ddTHH:mm:ssZ format. However in my Kibana Table visualization only the yyyy-MM-dd part is shown. When I click on the data field in Kibana the date format is also shown a…

---

## [Filtering messages from Logstash codec rubydebug output](https://discuss.elastic.co/t/filtering-messages-from-logstash-codec-rubydebug-output/339212)

<div class="topic-metadata">

**Author:** [@zaeemmasood](https://discuss.elastic.co/u/zaeemmasood)\
**Replies:** 0\
**Last updated:** [July 25, 2023, 3:15pm UTC](https://discuss.elastic.co/t/filtering-messages-from-logstash-codec-rubydebug-output/339212 "2023-07-25T15:15:06Z")

</div>

Our logtsash conf file is using tcp input plugin to ingest messages from different ports. The output part is as follows: output { if \[@metadata\]\[indexPrefix\] { file { path =\> "/opt/total/l…

---

## [Alert when winlogbeat host stop sending events](https://discuss.elastic.co/t/alert-when-winlogbeat-host-stop-sending-events/339141)

<div class="topic-metadata">

**Author:** [@vladislav](https://discuss.elastic.co/u/vladislav)\
**Replies:** 3\
**Last updated:** [July 25, 2023, 2:47pm UTC](https://discuss.elastic.co/t/alert-when-winlogbeat-host-stop-sending-events/339141 "2023-07-25T14:47:04Z")

</div>

Hello and thanks in advance. I have a group of 100+ hosts with winlogbeat installed and sending events to elasticsearch cluster. Is there any options to generate an alert (on security or any other page) when one or gro…

---

## [Is it possible modify query results before aggregations](https://discuss.elastic.co/t/is-it-possible-modify-query-results-before-aggregations/339136)

<div class="topic-metadata">

**Author:** [@Dalin](https://discuss.elastic.co/u/Dalin)\
**Replies:** 2\
**Last updated:** [July 25, 2023, 1:57pm UTC](https://discuss.elastic.co/t/is-it-possible-modify-query-results-before-aggregations/339136 "2023-07-25T13:57:46Z")

</div>

I need to modify Elasticsearch query results based on user permissions determined by an external authorizer, before the results are used for aggregations. Anyone know if it's possible to intercept the query results, modi…

[Previous page](https://discuss.elastic.co/tag/none.md?no_tags=true&page=332)

[Next page](https://discuss.elastic.co/tag/none.md?no_tags=true&page=334)
