# \#none

**URL:** https://discuss.elastic.co/tag/none.md?no_tags=true&page=342

[Latest](https://discuss.elastic.co/latest.md) · [Categories](https://discuss.elastic.co/categories.md) · [Tags](https://discuss.elastic.co/tags.md)

**Page:** 343

---

## [How do I get unique keys counts, not unique values per key?](https://discuss.elastic.co/t/how-do-i-get-unique-keys-counts-not-unique-values-per-key/338044)

<div class="topic-metadata">

**Author:** [@ecc256](https://discuss.elastic.co/u/ecc256)\
**Replies:** 1\
**Last updated:** [July 12, 2023, 10:48pm UTC](https://discuss.elastic.co/t/how-do-i-get-unique-keys-counts-not-unique-values-per-key/338044 "2023-07-12T22:48:00Z")

</div>

I have a collections of documents. What query can produce unique keys counts (for a time interval), not unique values per key? It might be too simple to do and not mentioned anywhere... thus I cannot find it?

---

## [Elastic Search / ILM / Snapshots S3/Minio](https://discuss.elastic.co/t/elastic-search-ilm-snapshots-s3-minio/338263)

<div class="topic-metadata">

**Author:** [@datencio](https://discuss.elastic.co/u/datencio)\
**Replies:** 1\
**Last updated:** [July 12, 2023, 10:42pm UTC](https://discuss.elastic.co/t/elastic-search-ilm-snapshots-s3-minio/338263 "2023-07-12T22:42:59Z")

</div>

I have been asked to do a POC to see how to properly configure our systems so that ILM will before it deletes an indice will take a snapshot of the indice and store it into S3/Minio. I have successfully updated the clust…

---

## [Dashboard which automatically selects today's index](https://discuss.elastic.co/t/dashboard-which-automatically-selects-todays-index/338142)

<div class="topic-metadata">

**Author:** [@Sam\_Estes](https://discuss.elastic.co/u/Sam_Estes)\
**Replies:** 2\
**Last updated:** [July 12, 2023, 10:35pm UTC](https://discuss.elastic.co/t/dashboard-which-automatically-selects-todays-index/338142 "2023-07-12T22:35:39Z")

</div>

Hello, I have a database with an index for each day. I would like to create a dashboard with visualizations using data from today's index. Each day, we create a new index so I would like the dashboard to automatically u…

---

## [Sometimes I fail to start up and the error message is as follows.](https://discuss.elastic.co/t/sometimes-i-fail-to-start-up-and-the-error-message-is-as-follows/338174)

<div class="topic-metadata">

**Author:** [@pl02206984](https://discuss.elastic.co/u/pl02206984)\
**Replies:** 2\
**Last updated:** [July 12, 2023, 9:46pm UTC](https://discuss.elastic.co/t/sometimes-i-fail-to-start-up-and-the-error-message-is-as-follows/338174 "2023-07-12T21:46:54Z")

</div>

Sometimes I fail to start up and the error message is as follows. \[2023-07-12T10:50:36,815\]\[ERROR\]\[logstash.config.sourceloader\] No configuration found in the configured sources. \[2023-07-12T10:50:36,932\]\[INFO \]\[logstas…

---

## [In ElasticSearch8.5.1, sorted by longitude and latitude](https://discuss.elastic.co/t/in-elasticsearch8-5-1-sorted-by-longitude-and-latitude/338187)

<div class="topic-metadata">

**Author:** [@maoqingjue](https://discuss.elastic.co/u/maoqingjue)\
**Replies:** 1\
**Last updated:** [July 12, 2023, 8:44pm UTC](https://discuss.elastic.co/t/in-elasticsearch8-5-1-sorted-by-longitude-and-latitude/338187 "2023-07-12T20:44:08Z")

</div>

In Elasticsearch8.5.1, sorted by longitude and latitude, my data format is: Post\_info\_address\_index:\[ { LatALng:{ Lat: 37.520804, Lon: 121.219555 } }, { LatALng:{ Lat: 37.520496, Lon: 121.220644 } } \] I us…

---

## [Node repurpose from data to master made primary shard unavailable. How to reset the cluster as API not working](https://discuss.elastic.co/t/node-repurpose-from-data-to-master-made-primary-shard-unavailable-how-to-reset-the-cluster-as-api-not-working/338258)

<div class="topic-metadata">

**Author:** [@vaibhav.ubale](https://discuss.elastic.co/u/vaibhav.ubale)\
**Replies:** 0\
**Last updated:** [July 12, 2023, 8:12pm UTC](https://discuss.elastic.co/t/node-repurpose-from-data-to-master-made-primary-shard-unavailable-how-to-reset-the-cluster-as-api-not-working/338258 "2023-07-12T20:12:31Z")

</div>

node repurpose from data to master made primary shard unavailable. How to reset the cluster as API not working. I am ok to loose the data but not able to start the cluster a fresh. Please suggest.

---

## [Sending request to one index, writing to multiple indices](https://discuss.elastic.co/t/sending-request-to-one-index-writing-to-multiple-indices/338079)

<div class="topic-metadata">

**Author:** [@Aditya\_Teltia](https://discuss.elastic.co/u/Aditya_Teltia)\
**Replies:** 23\
**Last updated:** [July 12, 2023, 7:19pm UTC](https://discuss.elastic.co/t/sending-request-to-one-index-writing-to-multiple-indices/338079 "2023-07-12T19:19:13Z")

</div>

I have a index named index1. I want to configure it such that any write/update request that comes to index1 gets written to both index1 and index2 but any search request still uses index1. Is this possible with some exis…

---

## [Elasticsearch 7.17 suddenly prevents login](https://discuss.elastic.co/t/elasticsearch-7-17-suddenly-prevents-login/338249)

<div class="topic-metadata">

**Author:** [@eastdrive](https://discuss.elastic.co/u/eastdrive)\
**Replies:** 4\
**Last updated:** [July 12, 2023, 6:35pm UTC](https://discuss.elastic.co/t/elasticsearch-7-17-suddenly-prevents-login/338249 "2023-07-12T18:35:38Z")

</div>

I installed elasticsearch 7.17.11 from the artifacts.elastic.co repo with security, on a fresh Ubuntu 20.04.6 node a couple of days ago, for a Magento 2.4.5-p3 store. It worked fine, certainly allowed me to connect remot…

---

## [Rule Actions Sometimes Don't Fire](https://discuss.elastic.co/t/rule-actions-sometimes-dont-fire/338245)

<div class="topic-metadata">

**Author:** [@SomeRobot](https://discuss.elastic.co/u/SomeRobot)\
**Replies:** 2\
**Last updated:** [July 12, 2023, 5:49pm UTC](https://discuss.elastic.co/t/rule-actions-sometimes-dont-fire/338245 "2023-07-12T17:49:06Z")

</div>

We have hundreds of rules created in Elastic Security which we are leveraging as our SIEM, many Elastic created, some are ours. These rules are all configured to perform the same action, which is to send some details to …

---

## [Cannot increase buffer: current=512000 requested=544768 max=512000](https://discuss.elastic.co/t/cannot-increase-buffer-current-512000-requested-544768-max-512000/338020)

<div class="topic-metadata">

**Author:** [@premkumarmuddeneni](https://discuss.elastic.co/u/premkumarmuddeneni)\
**Replies:** 1\
**Last updated:** [July 12, 2023, 5:06pm UTC](https://discuss.elastic.co/t/cannot-increase-buffer-current-512000-requested-544768-max-512000/338020 "2023-07-12T17:06:36Z")

</div>

We are using Elastic search of V8.7.0 and fluent bit v2.0.10 and kubernetes is v1.24. We had deployed the Fluent bit as a daemon set in kubernetes and collecting the logs from pods and pushing to Elasticsearch We are f…

---

## [Kibana Dashboards for inventory tracking with deleted indexes](https://discuss.elastic.co/t/kibana-dashboards-for-inventory-tracking-with-deleted-indexes/337693)

<div class="topic-metadata">

**Author:** [@Sam\_Estes](https://discuss.elastic.co/u/Sam_Estes)\
**Replies:** 5\
**Last updated:** [July 12, 2023, 4:46pm UTC](https://discuss.elastic.co/t/kibana-dashboards-for-inventory-tracking-with-deleted-indexes/337693 "2023-07-12T16:46:43Z")

</div>

Hi, I have an ES database which is updated daily. We maintain two indexes (one for each day's worth of data). During the update, the older of the two indexes is deleted and a new one is created for the new day. We want t…

---

## [Does kibana will restart if it can't connect to elasticsearh?](https://discuss.elastic.co/t/does-kibana-will-restart-if-it-cant-connect-to-elasticsearh/337545)

<div class="topic-metadata">

**Author:** [@yuswanul](https://discuss.elastic.co/u/yuswanul)\
**Replies:** 1\
**Last updated:** [July 12, 2023, 4:36pm UTC](https://discuss.elastic.co/t/does-kibana-will-restart-if-it-cant-connect-to-elasticsearh/337545 "2023-07-12T16:36:21Z")

</div>

Hi there, i have a question about kibana. so i have a VM that installed kibana and elastic there. then at some point, my elastic is experience OOM, so it produce hprof file. but bufore i knew that my elastic was OOM, i …

---

## [Version mismatch message even though versions match](https://discuss.elastic.co/t/version-mismatch-message-even-though-versions-match/337819)

<div class="topic-metadata">

**Author:** [@McJava1967](https://discuss.elastic.co/u/McJava1967)\
**Replies:** 15\
**Last updated:** [July 12, 2023, 3:49pm UTC](https://discuss.elastic.co/t/version-mismatch-message-even-though-versions-match/337819 "2023-07-12T15:49:08Z")

</div>

Hi all. I'm trying out ELK 8.8.2, and getting this message: Job creation error The client noticed that the server is not Elasticsearch and we do not support this unknown product. All explanations in various posts s…

---

## [Periodic disconnection of same data nodes](https://discuss.elastic.co/t/periodic-disconnection-of-same-data-nodes/338197)

<div class="topic-metadata">

**Author:** [@alissan](https://discuss.elastic.co/u/alissan)\
**Replies:** 5\
**Last updated:** [July 12, 2023, 3:01pm UTC](https://discuss.elastic.co/t/periodic-disconnection-of-same-data-nodes/338197 "2023-07-12T15:01:53Z")

</div>

Hello, I have a cluster with 3 master, 40 data nodes (d1,d2,...,d40). First 5 data nodes have voting only master role. Only the following data nodes have periodic abnormal behavior: d11,d12,d13,d14,d15,d16,d17,d21,d2…

---

## [Select Timeout parameter for python helper async\_bulk](https://discuss.elastic.co/t/select-timeout-parameter-for-python-helper-async-bulk/338037)

<div class="topic-metadata">

**Author:** [@ionFreeman](https://discuss.elastic.co/u/ionFreeman)\
**Replies:** 1\
**Last updated:** [July 12, 2023, 2:53pm UTC](https://discuss.elastic.co/t/select-timeout-parameter-for-python-helper-async-bulk/338037 "2023-07-12T14:53:22Z")

</div>

Hello! Every so often, my async\_bulk load fails with a Connection Timeout. I have my timeout parameter set to 60; I had set it arbitrarily high, but it didn't pass code review. I can't just wrap the call in tenacity as I…

---

## [Another mysterious work logstash with errors \_grokparsefailure](https://discuss.elastic.co/t/another-mysterious-work-logstash-with-errors-grokparsefailure/337327)

<div class="topic-metadata">

**Author:** [@San9](https://discuss.elastic.co/u/San9)\
**Replies:** 18\
**Last updated:** [July 12, 2023, 2:51pm UTC](https://discuss.elastic.co/t/another-mysterious-work-logstash-with-errors-grokparsefailure/337327 "2023-07-12T14:51:43Z")

</div>

again I encounter a problem in the work of logstash, and specifically with grock. Everything is fine in the debugger, the messages are parsed, but as soon as I apply this configuration to the production, then these messa…

---

## [Log Stash Sql Server](https://discuss.elastic.co/t/log-stash-sql-server/338233)

<div class="topic-metadata">

**Author:** [@balupad14](https://discuss.elastic.co/u/balupad14)\
**Replies:** 1\
**Last updated:** [July 12, 2023, 2:49pm UTC](https://discuss.elastic.co/t/log-stash-sql-server/338233 "2023-07-12T14:49:07Z")

</div>

Hi all, I am trying to insert the data into the Elasticsearch from SQL Server. When I run the logstash, I am getting this error. Not eligible for data streams because config contains one or more settings that are not c…

---

## [Multiple instance of kibana sometime error status 404](https://discuss.elastic.co/t/multiple-instance-of-kibana-sometime-error-status-404/337980)

<div class="topic-metadata">

**Author:** [@lusynda](https://discuss.elastic.co/u/lusynda)\
**Replies:** 1\
**Last updated:** [July 12, 2023, 2:33pm UTC](https://discuss.elastic.co/t/multiple-instance-of-kibana-sometime-error-status-404/337980 "2023-07-12T14:33:10Z")

</div>

Hi all, I've tried to use multiple instance of kibana to HA. but then sometime i encounter error like this after refresh the page for a few times i was able to load the page but the problems persists very often for …

---

## [Exiting: Error reading config file: required 'object', but found 'string' in field 'filebeat.inputs.0' (source:'filebeat.yml')](https://discuss.elastic.co/t/exiting-error-reading-config-file-required-object-but-found-string-in-field-filebeat-inputs-0-source-filebeat-yml/337940)

<div class="topic-metadata">

**Author:** [@Bhakti\_Bhabal](https://discuss.elastic.co/u/Bhakti_Bhabal)\
**Replies:** 5\
**Last updated:** [July 12, 2023, 2:07pm UTC](https://discuss.elastic.co/t/exiting-error-reading-config-file-required-object-but-found-string-in-field-filebeat-inputs-0-source-filebeat-yml/337940 "2023-07-12T14:07:37Z")

</div>

HI Guys i have created the below sample filebeat.yml and verified through yamalint still i am getting the same error . I am trying to setup filebeat to work with elastic and the filebeat itself wont start up giving the e…

---

## [Creating graph in kibana](https://discuss.elastic.co/t/creating-graph-in-kibana/338208)

<div class="topic-metadata">

**Author:** [@Neelam\_Zanvar](https://discuss.elastic.co/u/Neelam_Zanvar)\
**Replies:** 1\
**Last updated:** [July 12, 2023, 12:58pm UTC](https://discuss.elastic.co/t/creating-graph-in-kibana/338208 "2023-07-12T12:58:19Z")

</div>

Hi i want to try out kibana graphs. How can i get started? i am referring this document But i don't find the graphs option in the menu in kibana. I am using kibana 8.7

---

## [To get message field for json filter](https://discuss.elastic.co/t/to-get-message-field-for-json-filter/337968)

<div class="topic-metadata">

**Author:** [@a.emrekaraman](https://discuss.elastic.co/u/a.emrekaraman)\
**Replies:** 5\
**Last updated:** [July 12, 2023, 12:44pm UTC](https://discuss.elastic.co/t/to-get-message-field-for-json-filter/337968 "2023-07-12T12:44:48Z")

</div>

Hi Team, I use json filter to parse my json data but my json data has "message" value. that's why ı'm not able to get standard message field which have all parsed log. I just have "message" field which come from json l…

---

## [Problem with new script](https://discuss.elastic.co/t/problem-with-new-script/337800)

<div class="topic-metadata">

**Author:** [@Valerija](https://discuss.elastic.co/u/Valerija)\
**Replies:** 33\
**Last updated:** [July 12, 2023, 11:49am UTC](https://discuss.elastic.co/t/problem-with-new-script/337800 "2023-07-12T11:49:08Z")

</div>

Hi there, I created a simple new script and it works w/o problems: def totalGood = doc\['actualQuantity'\].value - doc\['failureQuantity'\].value; return totalGood; Then I tried to create another one and this one does not…

---

## [Issues with pushing packages to my own package registry](https://discuss.elastic.co/t/issues-with-pushing-packages-to-my-own-package-registry/338209)

<div class="topic-metadata">

**Author:** [@hari\_ibm](https://discuss.elastic.co/u/hari_ibm)\
**Replies:** 0\
**Last updated:** [July 12, 2023, 11:40am UTC](https://discuss.elastic.co/t/issues-with-pushing-packages-to-my-own-package-registry/338209 "2023-07-12T11:40:24Z")

</div>

I have created new package and i want to push it to my custom hosted package registry? How to update the packages list in my custom hosted package registry?

---

## [How to upgrade metricbeat from 7.17.11 to 7.17.xx or 8.1.xx?](https://discuss.elastic.co/t/how-to-upgrade-metricbeat-from-7-17-11-to-7-17-xx-or-8-1-xx/338183)

<div class="topic-metadata">

**Author:** [@Swathi12](https://discuss.elastic.co/u/Swathi12)\
**Replies:** 2\
**Last updated:** [July 12, 2023, 11:13am UTC](https://discuss.elastic.co/t/how-to-upgrade-metricbeat-from-7-17-11-to-7-17-xx-or-8-1-xx/338183 "2023-07-12T11:13:59Z")

</div>

How do i upgrade next time from 7.17.11 to 7.17.xx ? or 8.x.x Is there any command which i can use in the Kibana DEV Tool ? Or how is the possible and easy way to do it ?

---

## [Start logstash error](https://discuss.elastic.co/t/start-logstash-error/338146)

<div class="topic-metadata">

**Author:** [@liqiu](https://discuss.elastic.co/u/liqiu)\
**Replies:** 2\
**Last updated:** [July 11, 2023, 8:05pm UTC](https://discuss.elastic.co/t/start-logstash-error/338146 "2023-07-11T20:05:01Z")

</div>

I have configured the logstash.yml configuration file logstash.yml： input {stdin{}} output {stdout{}} But when I enter ./logstash to start, the following error occurs \[2023-07-12T01:16:59,926\]\[INFO \]\[logstash.runner …

---

## [Help with query please](https://discuss.elastic.co/t/help-with-query-please/338191)

<div class="topic-metadata">

**Author:** [@lakhr034](https://discuss.elastic.co/u/lakhr034)\
**Replies:** 0\
**Last updated:** [July 12, 2023, 8:59am UTC](https://discuss.elastic.co/t/help-with-query-please/338191 "2023-07-12T08:59:04Z")

</div>

POST user\_info,user\_auth\_cards\_info/\_search { "size": 0, "query": { "bool": { "filter": \[ { "multi\_match": { "query": "test", "fields": \[ "e\_name.auto…

---

## [Each log line is split into a different document in Elastic](https://discuss.elastic.co/t/each-log-line-is-split-into-a-different-document-in-elastic/338144)

<div class="topic-metadata">

**Author:** [@Merav\_Yaacov](https://discuss.elastic.co/u/Merav_Yaacov)\
**Replies:** 3\
**Last updated:** [July 12, 2023, 5:37am UTC](https://discuss.elastic.co/t/each-log-line-is-split-into-a-different-document-in-elastic/338144 "2023-07-12T05:37:53Z")

</div>

Hi, What can be the reason that each line of log file is split into single document in Elastic? That's how Logstash is configured: input { file { type =\> "log" path =\> \["/etc/logstash/conf.d/files/\*.…

---

## [Parsing the message field in security event.code 4624](https://discuss.elastic.co/t/parsing-the-message-field-in-security-event-code-4624/338046)

<div class="topic-metadata">

**Author:** [@Cruz](https://discuss.elastic.co/u/Cruz)\
**Replies:** 2\
**Last updated:** [July 11, 2023, 11:19pm UTC](https://discuss.elastic.co/t/parsing-the-message-field-in-security-event-code-4624/338046 "2023-07-11T23:19:14Z")

</div>

The information that I want is located under the first sub-header "Subject" and "Network Information". My basic question is this, how do I pull this information out of the Message field and display it along with the Time…

---

## [How to convert the Logstash message to fileds](https://discuss.elastic.co/t/how-to-convert-the-logstash-message-to-fileds/337910)

<div class="topic-metadata">

**Author:** [@Harper\_S1](https://discuss.elastic.co/u/Harper_S1)\
**Replies:** 15\
**Last updated:** [July 11, 2023, 9:17pm UTC](https://discuss.elastic.co/t/how-to-convert-the-logstash-message-to-fileds/337910 "2023-07-11T21:17:00Z")

</div>

Hi, I am using Logstash as a syslog server which sends data to elastic. here is the output. @timestampJul 7, 2023 @ 11:30:12.520@version1 hostname10.11.12.13 message {"proxyname":"test-123-abc","revision":"8","latency…

---

## [Forwarding logs from Sun Solaris to ELK](https://discuss.elastic.co/t/forwarding-logs-from-sun-solaris-to-elk/338147)

<div class="topic-metadata">

**Author:** [@DKalin0789e](https://discuss.elastic.co/u/DKalin0789e)\
**Replies:** 6\
**Last updated:** [July 11, 2023, 9:04pm UTC](https://discuss.elastic.co/t/forwarding-logs-from-sun-solaris-to-elk/338147 "2023-07-11T21:04:29Z")

</div>

We need to find a workaround for forwarding logs from Sun Solaris to ELK. Any ideas - very welcome! No any vendors like Logstash, Filebeat, Vector officially support Log Forwarders on Sun Solaris. Any help? Thank you.

[Previous page](https://discuss.elastic.co/tag/none.md?no_tags=true&page=341)

[Next page](https://discuss.elastic.co/tag/none.md?no_tags=true&page=343)
