# \#none

**URL:** https://discuss.elastic.co/tag/none.md?no_tags=true&page=337

[Latest](https://discuss.elastic.co/latest.md) · [Categories](https://discuss.elastic.co/categories.md) · [Tags](https://discuss.elastic.co/tags.md)

**Page:** 338

---

## [Role based Control](https://discuss.elastic.co/t/role-based-control/338825)

<div class="topic-metadata">

**Author:** [@Kumar\_Abhinav](https://discuss.elastic.co/u/Kumar_Abhinav)\
**Replies:** 2\
**Last updated:** [July 19, 2023, 10:50pm UTC](https://discuss.elastic.co/t/role-based-control/338825 "2023-07-19T22:50:11Z")

</div>

Hi, I am running a Basic version ELK. I am trying to make a role-based user profile in Kibana. I can see from the subscription page that it is available in the free version as well but when I try to navigate to "Stack M…

---

## [Configurar 3 master nodos sin datos solo maestros? en la version 8.8?](https://discuss.elastic.co/t/configurar-3-master-nodos-sin-datos-solo-maestros-en-la-version-8-8/338829)

<div class="topic-metadata">

**Author:** [@hlcxpl](https://discuss.elastic.co/u/hlcxpl)\
**Replies:** 0\
**Last updated:** [July 19, 2023, 9:36pm UTC](https://discuss.elastic.co/t/configurar-3-master-nodos-sin-datos-solo-maestros-en-la-version-8-8/338829 "2023-07-19T21:36:18Z")

</div>

estoy configurando un cluster con 3 nodos masestros la seguridad ya la tengo cubierta pero cuando inicializo me quedan 3 nodos master con data y 4 nodos de datos necesito que 3 sean dedicados master sin data y todos los…

---

## ["Watcher" is not showing in Kibana Version 8.6.2](https://discuss.elastic.co/t/watcher-is-not-showing-in-kibana-version-8-6-2/338725)

<div class="topic-metadata">

**Author:** [@Kumar\_Abhinav](https://discuss.elastic.co/u/Kumar_Abhinav)\
**Replies:** 2\
**Last updated:** [July 19, 2023, 6:32pm UTC](https://discuss.elastic.co/t/watcher-is-not-showing-in-kibana-version-8-6-2/338725 "2023-07-19T18:32:37Z")

</div>

Hi, I am using ELK 8.6.2. Till last week, I have the "Watcher" tab in the 'Alerts and Insights' inside the "Stack Management" menu. Can you guide me that how it can be restored back?

---

## [Segregating data sent from Elastic-Agents or Beats to a Specified Index](https://discuss.elastic.co/t/segregating-data-sent-from-elastic-agents-or-beats-to-a-specified-index/338811)

<div class="topic-metadata">

**Author:** [@pkward](https://discuss.elastic.co/u/pkward)\
**Replies:** 0\
**Last updated:** [July 19, 2023, 5:32pm UTC](https://discuss.elastic.co/t/segregating-data-sent-from-elastic-agents-or-beats-to-a-specified-index/338811 "2023-07-19T17:32:47Z")

</div>

Hello, I'm ingesting data from multiple systems and different system owners. I have multi-tenancy set up using Kibana spaces and roles, but all of the data is being sent to a single index. I would like to store my data …

---

## [Query indices on cold node?](https://discuss.elastic.co/t/query-indices-on-cold-node/338810)

<div class="topic-metadata">

**Author:** [@datencio](https://discuss.elastic.co/u/datencio)\
**Replies:** 0\
**Last updated:** [July 19, 2023, 4:49pm UTC](https://discuss.elastic.co/t/query-indices-on-cold-node/338810 "2023-07-19T16:49:06Z")

</div>

I am trying to see if there is a straight forward way to query indices that are located on the "cold" node and to get a list of those indices, is there a straight forward way to do that in Elasticsearch? I presume I can …

---

## [Group data By 5 minutes using sql query in elastic](https://discuss.elastic.co/t/group-data-by-5-minutes-using-sql-query-in-elastic/338754)

<div class="topic-metadata">

**Author:** [@leonid\_fayngold](https://discuss.elastic.co/u/leonid_fayngold)\
**Replies:** 1\
**Last updated:** [July 19, 2023, 4:03pm UTC](https://discuss.elastic.co/t/group-data-by-5-minutes-using-sql-query-in-elastic/338754 "2023-07-19T16:03:48Z")

</div>

how can I group data By 5 minutes using SQL query in elastic

---

## [Error while using ./elasticsearch-node repurpose tool](https://discuss.elastic.co/t/error-while-using-elasticsearch-node-repurpose-tool/338807)

<div class="topic-metadata">

**Author:** [@hlcxpl](https://discuss.elastic.co/u/hlcxpl)\
**Replies:** 0\
**Last updated:** [July 19, 2023, 3:43pm UTC](https://discuss.elastic.co/t/error-while-using-elasticsearch-node-repurpose-tool/338807 "2023-07-19T15:43:23Z")

</div>

i got this error while using /usr/share/elasticsearch/elasticsearch-node repurpose to set my master node only for master { "error" : { "root\_cause" : \[ { "type" : "security\_exception", "reas…

---

## [Unassigned shards - cannot allocate because all found copies of the shard are either stale or corrupt](https://discuss.elastic.co/t/unassigned-shards-cannot-allocate-because-all-found-copies-of-the-shard-are-either-stale-or-corrupt/338804)

<div class="topic-metadata">

**Author:** [@karsai1993](https://discuss.elastic.co/u/karsai1993)\
**Replies:** 0\
**Last updated:** [July 19, 2023, 3:11pm UTC](https://discuss.elastic.co/t/unassigned-shards-cannot-allocate-because-all-found-copies-of-the-shard-are-either-stale-or-corrupt/338804 "2023-07-19T15:11:55Z")

</div>

Hello there, We are facing a RED cluster. GET \_cluster/health { "cluster\_name": "my\_cluster", "status": "red", "timed\_out": false, "number\_of\_nodes": 20, "number\_of\_data\_nodes": 13, "active\_primary\_shards"…

---

## [Dynamically Link to external site in Kibana Visuals](https://discuss.elastic.co/t/dynamically-link-to-external-site-in-kibana-visuals/338797)

<div class="topic-metadata">

**Author:** [@breiter](https://discuss.elastic.co/u/breiter)\
**Replies:** 1\
**Last updated:** [July 19, 2023, 2:33pm UTC](https://discuss.elastic.co/t/dynamically-link-to-external-site-in-kibana-visuals/338797 "2023-07-19T14:33:17Z")

</div>

What is the standard for dynamically linking to external sites in dashboards? I have a table of data from my database. I'm displaying entity's IDs. These entities can be accessed through unique URLs, for example: https:…

---

## [Access is denied](https://discuss.elastic.co/t/access-is-denied/338304)

<div class="topic-metadata">

**Author:** [@Step-Creeper](https://discuss.elastic.co/u/Step-Creeper)\
**Replies:** 5\
**Last updated:** [July 19, 2023, 2:30pm UTC](https://discuss.elastic.co/t/access-is-denied/338304 "2023-07-19T14:30:25Z")

</div>

I have my Elasticsearch running on the default port and am able to login, so that is running fine. I downloaded the kibana.zip from official elasticsearch site, extracted it to desktop, and tried running kibana.bat Thi…

---

## [Pros and Cons of using Elastic as a vector database?](https://discuss.elastic.co/t/pros-and-cons-of-using-elastic-as-a-vector-database/338733)

<div class="topic-metadata">

**Author:** [@Ernest\_Dong](https://discuss.elastic.co/u/Ernest_Dong)\
**Replies:** 2\
**Last updated:** [July 19, 2023, 1:47pm UTC](https://discuss.elastic.co/t/pros-and-cons-of-using-elastic-as-a-vector-database/338733 "2023-07-19T13:47:28Z")

</div>

I'm comparing Elastic vs other pure vector databases vs Mongodb/redis offerings. Is anything wrong or supplemental? Thank you! Pros: It's an Elastic product, meaning high SLA and needless to buy other products when do…

---

## [Example Inputs logtash configuration](https://discuss.elastic.co/t/example-inputs-logtash-configuration/338792)

<div class="topic-metadata">

**Author:** [@willsy](https://discuss.elastic.co/u/willsy)\
**Replies:** 0\
**Last updated:** [July 19, 2023, 1:39pm UTC](https://discuss.elastic.co/t/example-inputs-logtash-configuration/338792 "2023-07-19T13:39:45Z")

</div>

Hello, Can i get help with an input configuration for logstash please? I currently am using this as a curl to get my information, but i need this in yaml if possible \</\> \</\>curl -X GET 'https://192.168.3.21:9200/\_cat…

---

## [How can I pass kibana authentication credentials from python application?](https://discuss.elastic.co/t/how-can-i-pass-kibana-authentication-credentials-from-python-application/338504)

<div class="topic-metadata">

**Author:** [@Rushi\_Bagul](https://discuss.elastic.co/u/Rushi_Bagul)\
**Replies:** 6\
**Last updated:** [July 19, 2023, 1:25pm UTC](https://discuss.elastic.co/t/how-can-i-pass-kibana-authentication-credentials-from-python-application/338504 "2023-07-19T13:25:21Z")

</div>

Hello,, I have python application, In which I have iframe kibana dashboard . If I am log in that python app at same time log in iframe kibana dashboard as well. User not again log in kibana dashboard. How can I manage t…

---

## [How to send logs from IBM DataPower to logstash](https://discuss.elastic.co/t/how-to-send-logs-from-ibm-datapower-to-logstash/338715)

<div class="topic-metadata">

**Author:** [@ram\_mq](https://discuss.elastic.co/u/ram_mq)\
**Replies:** 1\
**Last updated:** [July 19, 2023, 12:34pm UTC](https://discuss.elastic.co/t/how-to-send-logs-from-ibm-datapower-to-logstash/338715 "2023-07-19T12:34:08Z")

</div>

I would like to send logs from IBM DataPower to Logstash. Please advise how to send the logs?

---

## [How to fetch Ids from more than 10k records in single response](https://discuss.elastic.co/t/how-to-fetch-ids-from-more-than-10k-records-in-single-response/338749)

<div class="topic-metadata">

**Author:** [@Paras\_Rangani](https://discuss.elastic.co/u/Paras_Rangani)\
**Replies:** 2\
**Last updated:** [July 19, 2023, 11:21am UTC](https://discuss.elastic.co/t/how-to-fetch-ids-from-more-than-10k-records-in-single-response/338749 "2023-07-19T11:21:20Z")

</div>

I have around 1 million documents , after applying the filters I get more than 10k records, but I do not want whole documents , instead I want the IDS of that records in a single call.How can I do that ?

---

## [Not able to index array in logstash](https://discuss.elastic.co/t/not-able-to-index-array-in-logstash/338774)

<div class="topic-metadata">

**Author:** [@Mohit\_Gupta2](https://discuss.elastic.co/u/Mohit_Gupta2)\
**Replies:** 0\
**Last updated:** [July 19, 2023, 11:11am UTC](https://discuss.elastic.co/t/not-able-to-index-array-in-logstash/338774 "2023-07-19T11:11:40Z")

</div>

As it says, Logstash is not able to index array of strings or any kind of string for that matter. eg. - country :\["some\_name"\] is not mapped while country: '\["some\_name"\]' is indexed although it is showing the unmapped …

---

## [Failed to run a query](https://discuss.elastic.co/t/failed-to-run-a-query/338678)

<div class="topic-metadata">

**Author:** [@leonid\_fayngold](https://discuss.elastic.co/u/leonid_fayngold)\
**Replies:** 3\
**Last updated:** [July 19, 2023, 10:27am UTC](https://discuss.elastic.co/t/failed-to-run-a-query/338678 "2023-07-19T10:27:01Z")

</div>

Failed to run the following query: select (date\_trunc('hour', my\_date) + interval date\_part('minute', my\_date)::int minutes) as group\_by\_name from table\_name where my\_date\>= '2023-07-12' having the following excepti…

---

## [ELSER deployments crash kibana and fail deployment](https://discuss.elastic.co/t/elser-deployments-crash-kibana-and-fail-deployment/337344)

<div class="topic-metadata">

**Author:** [@cvarano](https://discuss.elastic.co/u/cvarano)\
**Replies:** 1\
**Last updated:** [July 19, 2023, 10:06am UTC](https://discuss.elastic.co/t/elser-deployments-crash-kibana-and-fail-deployment/337344 "2023-07-19T10:06:30Z")

</div>

Trying to test ELSER following this tutorial, but I cannot get past the very first step of deploying the ELSER model. I have a 4GB ML node, as specified. Every time I try to deploy the ELSER model, my Kibana node crashe…

---

## [Filter results by another query](https://discuss.elastic.co/t/filter-results-by-another-query/338763)

<div class="topic-metadata">

**Author:** [@ndtreviv](https://discuss.elastic.co/u/ndtreviv)\
**Replies:** 0\
**Last updated:** [July 19, 2023, 10:01am UTC](https://discuss.elastic.co/t/filter-results-by-another-query/338763 "2023-07-19T10:01:07Z")

</div>

I have a usecase where I want to search for documents that do not have counterparts in the index. For example, consider the following: I have a document format like this: { "file": "myfile.ext", "classificatio…

---

## [Is it recommended to disable sniffer and always direct the requests to the k8s HTTP SVC instead?](https://discuss.elastic.co/t/is-it-recommended-to-disable-sniffer-and-always-direct-the-requests-to-the-k8s-http-svc-instead/338762)

<div class="topic-metadata">

**Author:** [@GustavoSantos](https://discuss.elastic.co/u/GustavoSantos)\
**Replies:** 0\
**Last updated:** [July 19, 2023, 9:36am UTC](https://discuss.elastic.co/t/is-it-recommended-to-disable-sniffer-and-always-direct-the-requests-to-the-k8s-http-svc-instead/338762 "2023-07-19T09:36:04Z")

</div>

Hi all, Our ES clusters are deployed in k8s using the eck-operator and our application uses the Java client with sniffer enabled. We are currently struggling with an annoying issue when the cluster is restarted. By th…

---

## [Discect rule with a "+" sign in the message, can't escape it](https://discuss.elastic.co/t/discect-rule-with-a-sign-in-the-message-cant-escape-it/338661)

<div class="topic-metadata">

**Author:** [@UPPERCASE](https://discuss.elastic.co/u/UPPERCASE)\
**Replies:** 2\
**Last updated:** [July 19, 2023, 8:36am UTC](https://discuss.elastic.co/t/discect-rule-with-a-sign-in-the-message-cant-escape-it/338661 "2023-07-19T08:36:05Z")

</div>

I have the following disect rule: %{timestamp} queries: info: client @%{dns\_client} %{source\_ip}#%{source\_port} (%{query}): query: %{query\_2} IN %{class} + (%{dns\_server}), which is from a BIND DNS server (querylog). Wh…

---

## [The connection between Logstash and Elasticsearch is not working](https://discuss.elastic.co/t/the-connection-between-logstash-and-elasticsearch-is-not-working/338750)

<div class="topic-metadata">

**Author:** [@chldnjs8899](https://discuss.elastic.co/u/chldnjs8899)\
**Replies:** 1\
**Last updated:** [July 19, 2023, 8:14am UTC](https://discuss.elastic.co/t/the-connection-between-logstash-and-elasticsearch-is-not-working/338750 "2023-07-19T08:14:42Z")

</div>

The following content has been translated using ChatGPT. Thank you for your understanding. Hello, I'm currently learning Elasticsearch. I'm using Elasticsearch version 8.8.2. I have written the following pipeline in ord…

---

## [Visualize user journey on a website](https://discuss.elastic.co/t/visualize-user-journey-on-a-website/338060)

<div class="topic-metadata">

**Author:** [@Neelam\_Zanvar](https://discuss.elastic.co/u/Neelam_Zanvar)\
**Replies:** 4\
**Last updated:** [July 19, 2023, 7:52am UTC](https://discuss.elastic.co/t/visualize-user-journey-on-a-website/338060 "2023-07-19T07:52:59Z")

</div>

Hi , I want to visualize the various url visited by a spcific user along with the timestamp in a graph. i have the following data in es index, date: 11/Jul/2023:11:15:13.705 +0530 remote ip: 49.37.163.204 url: /3…

---

## [ES node handshake failed](https://discuss.elastic.co/t/es-node-handshake-failed/338743)

<div class="topic-metadata">

**Author:** [@emmning](https://discuss.elastic.co/u/emmning)\
**Replies:** 0\
**Last updated:** [July 19, 2023, 6:17am UTC](https://discuss.elastic.co/t/es-node-handshake-failed/338743 "2023-07-19T06:17:43Z")

</div>

Hi team, I am trying to start cluster on my MacBook. I got below error \[2023-07-19T14:16:03,014\]\[WARN \]\[o.e.d.HandshakingTransportAddressConnector\] \[node-2\] \[connectToRemoteMasterNode\[127.0.0.1:9301\]\] completed handsha…

---

## [How to connect Stand Alone Elastic Agent to SentinelOne and Logstash?](https://discuss.elastic.co/t/how-to-connect-stand-alone-elastic-agent-to-sentinelone-and-logstash/338726)

<div class="topic-metadata">

**Author:** [@toman](https://discuss.elastic.co/u/toman)\
**Replies:** 1\
**Last updated:** [July 19, 2023, 4:29am UTC](https://discuss.elastic.co/t/how-to-connect-stand-alone-elastic-agent-to-sentinelone-and-logstash/338726 "2023-07-19T04:29:30Z")

</div>

I am trying to make a connection from our SentinelOne environment to our existing Logstash server where we process data. We do not use Fleet or Elasticsearch. It seems that we could use Elastic Agent for this connection…

---

## [Set top\_hits size dynamically for each bucket based on its doc\_count with a script](https://discuss.elastic.co/t/set-top-hits-size-dynamically-for-each-bucket-based-on-its-doc-count-with-a-script/338728)

<div class="topic-metadata">

**Author:** [@DMinovski](https://discuss.elastic.co/u/DMinovski)\
**Replies:** 0\
**Last updated:** [July 18, 2023, 11:31pm UTC](https://discuss.elastic.co/t/set-top-hits-size-dynamically-for-each-bucket-based-on-its-doc-count-with-a-script/338728 "2023-07-18T23:31:51Z")

</div>

I use a query to find the duplicates in an index based on a field. Some documents have the same value in this field and they are duplicates. { "size": 0, "aggs": { "duplicate\_terms": { "terms…

---

## [Elasticsearch delete docs during the indexations](https://discuss.elastic.co/t/elasticsearch-delete-docs-during-the-indexations/338674)

<div class="topic-metadata">

**Author:** [@atombrownbear](https://discuss.elastic.co/u/atombrownbear)\
**Replies:** 1\
**Last updated:** [July 18, 2023, 9:53pm UTC](https://discuss.elastic.co/t/elasticsearch-delete-docs-during-the-indexations/338674 "2023-07-18T21:53:06Z")

</div>

Hi all! When im do indexation, my backend app sends 1234 pages (for example). if I call /stats? by curl I will see that 1234 pages have been indexed and 234 pages have been deleted, although they should not be deleted. w…

---

## [Custom analyser for numeric string](https://discuss.elastic.co/t/custom-analyser-for-numeric-string/338529)

<div class="topic-metadata">

**Author:** [@hmkhitaryan](https://discuss.elastic.co/u/hmkhitaryan)\
**Replies:** 3\
**Last updated:** [July 18, 2023, 8:32pm UTC](https://discuss.elastic.co/t/custom-analyser-for-numeric-string/338529 "2023-07-18T20:32:19Z")

</div>

Hi everyone. I have this kind of issue: I have a numeric string field, seperated with dots, like "1.1.2", "11.2.1", and the like. I have a requirement to do sorting by this field, and when I try to sort by that field, i…

---

## [Which configuration schemes are avaliable in 8.8 version of elastic clusterization?](https://discuss.elastic.co/t/which-configuration-schemes-are-avaliable-in-8-8-version-of-elastic-clusterization/338137)

<div class="topic-metadata">

**Author:** [@hlcxpl](https://discuss.elastic.co/u/hlcxpl)\
**Replies:** 20\
**Last updated:** [July 18, 2023, 7:57pm UTC](https://discuss.elastic.co/t/which-configuration-schemes-are-avaliable-in-8-8-version-of-elastic-clusterization/338137 "2023-07-18T19:57:03Z")

</div>

which configuration schemes are avaliable in 8.8 version of slatic clusterization?

---

## [Setup filebeat to send different logs to different indexes (to elasticsearch)](https://discuss.elastic.co/t/setup-filebeat-to-send-different-logs-to-different-indexes-to-elasticsearch/338709)

<div class="topic-metadata">

**Author:** [@perfecto25](https://discuss.elastic.co/u/perfecto25)\
**Replies:** 0\
**Last updated:** [July 18, 2023, 6:36pm UTC](https://discuss.elastic.co/t/setup-filebeat-to-send-different-logs-to-different-indexes-to-elasticsearch/338709 "2023-07-18T18:36:10Z")

</div>

Hello, I setup a filebeat 8.8.2 on redhat host and configured my filebeat.yml like this, Im sending all my log data to ES directly, filebeat.inputs: - type: filestream id: my\_id enabled: true paths: - /home/cu…

[Previous page](https://discuss.elastic.co/tag/none.md?no_tags=true&page=336)

[Next page](https://discuss.elastic.co/tag/none.md?no_tags=true&page=338)
