# \#none

**URL:** https://discuss.elastic.co/tag/none.md?no_tags=true&page=356

[Latest](https://discuss.elastic.co/latest.md) · [Categories](https://discuss.elastic.co/categories.md) · [Tags](https://discuss.elastic.co/tags.md)

**Page:** 357

---

## [Elasticsearch/Kibana - Discover not showing traffic - but logs show no errors Elasticsearch 7.17.10](https://discuss.elastic.co/t/elasticsearch-kibana-discover-not-showing-traffic-but-logs-show-no-errors-elasticsearch-7-17-10/336508)

<div class="topic-metadata">

**Author:** [@Bruceclegg](https://discuss.elastic.co/u/Bruceclegg)\
**Replies:** 0\
**Last updated:** [June 20, 2023, 7:56pm UTC](https://discuss.elastic.co/t/elasticsearch-kibana-discover-not-showing-traffic-but-logs-show-no-errors-elasticsearch-7-17-10/336508 "2023-06-20T19:56:13Z")

</div>

We use nginx as the front end to move traffic from incoming port 9200 to 9400. This has been working more or less fine. We needed to make a change so port 9200 could accept both http and https traffic. So I made the ch…

---

## [Data View, Canvas, and ESQL](https://discuss.elastic.co/t/data-view-canvas-and-esql/336474)

<div class="topic-metadata">

**Author:** [@witwit](https://discuss.elastic.co/u/witwit)\
**Replies:** 1\
**Last updated:** [June 20, 2023, 5:35pm UTC](https://discuss.elastic.co/t/data-view-canvas-and-esql/336474 "2023-06-20T17:35:48Z")

</div>

Hi, So i have an index which is created from a transform with group by on a field and aggregation using terms. This means that my resulting field is a flattened field of terms. Through this I can create Data View term…

---

## [How can I index only new documents without updating the older ones?](https://discuss.elastic.co/t/how-can-i-index-only-new-documents-without-updating-the-older-ones/336501)

<div class="topic-metadata">

**Author:** [@SamuelSMendes](https://discuss.elastic.co/u/SamuelSMendes)\
**Replies:** 1\
**Last updated:** [June 20, 2023, 4:23pm UTC](https://discuss.elastic.co/t/how-can-i-index-only-new-documents-without-updating-the-older-ones/336501 "2023-06-20T16:23:15Z")

</div>

I am aware of the create action but when I use it a horrendous WARN log is printed in the logstash screen. The solution of create would fit perfect if it wasn't for it. So I've been wondering if there is another way to a…

---

## [Synthetics alert for redirects from https to http](https://discuss.elastic.co/t/synthetics-alert-for-redirects-from-https-to-http/336216)

<div class="topic-metadata">

**Author:** [@Alexander\_A](https://discuss.elastic.co/u/Alexander_A)\
**Replies:** 1\
**Last updated:** [June 20, 2023, 3:20pm UTC](https://discuss.elastic.co/t/synthetics-alert-for-redirects-from-https-to-http/336216 "2023-06-20T15:20:02Z")

</div>

Is it possible to configure alarm when site uses http instead of https or when we go to https and then redirected to http? This seems like a not good thing that can be detected by synthetics and created alert/inform mes…

---

## [Logstash output s3 prefix with date](https://discuss.elastic.co/t/logstash-output-s3-prefix-with-date/336498)

<div class="topic-metadata">

**Author:** [@kunalmohan](https://discuss.elastic.co/u/kunalmohan)\
**Replies:** 1\
**Last updated:** [June 20, 2023, 3:10pm UTC](https://discuss.elastic.co/t/logstash-output-s3-prefix-with-date/336498 "2023-06-20T15:10:27Z")

</div>

S3 output plugin | Logstash Reference \[8.8\] | Elastic mentions to use prefix = "%{+YYYY}/%{+MM}/%{+dd}" for creating folders based on event date. This doesn't work for my. It simply creates two nested folders with name /.…

---

## [Creating visualization with timestamp un y axis and not count](https://discuss.elastic.co/t/creating-visualization-with-timestamp-un-y-axis-and-not-count/336430)

<div class="topic-metadata">

**Author:** [@Anusha\_Kusanghi](https://discuss.elastic.co/u/Anusha_Kusanghi)\
**Replies:** 4\
**Last updated:** [June 20, 2023, 2:54pm UTC](https://discuss.elastic.co/t/creating-visualization-with-timestamp-un-y-axis-and-not-count/336430 "2023-06-20T14:54:27Z")

</div>

Hi All, We have a index which stores the status of job running in controlm platform , like job name ,id ,job start time end time and so on... We want to create a visualization: putting date in y axis (date on which da…

---

## [EQL - Alert when Follow up event doesn't occur](https://discuss.elastic.co/t/eql-alert-when-follow-up-event-doesnt-occur/329917)

<div class="topic-metadata">

**Author:** [@lilow](https://discuss.elastic.co/u/lilow)\
**Replies:** 2\
**Last updated:** [June 20, 2023, 2:38pm UTC](https://discuss.elastic.co/t/eql-alert-when-follow-up-event-doesnt-occur/329917 "2023-06-20T14:38:07Z")

</div>

Hey, I'm trying to implement a rule with eql where I only want to get an alert when a follow up event doesn't occur within a certain time frame. Unfortunately it's not really doing what I'm hoping. Is there any way how…

---

## [Percolate Query Issues after Upgrading to Elasticsearch 8.6.2 with REST High-Level Client 7.17.9](https://discuss.elastic.co/t/percolate-query-issues-after-upgrading-to-elasticsearch-8-6-2-with-rest-high-level-client-7-17-9/336359)

<div class="topic-metadata">

**Author:** [@ulysse42](https://discuss.elastic.co/u/ulysse42)\
**Replies:** 5\
**Last updated:** [June 20, 2023, 2:16pm UTC](https://discuss.elastic.co/t/percolate-query-issues-after-upgrading-to-elasticsearch-8-6-2-with-rest-high-level-client-7-17-9/336359 "2023-06-20T14:16:35Z")

</div>

Hello Elasticsearch community, I'm currently experiencing an issue with the Percolate Query after upgrading my Elasticsearch version to 8.6.2. I'm still using the REST High-Level Client 7.17.9. Here's the exception I'm…

---

## [Unassigned shards =\> How to set default replica number to 0?](https://discuss.elastic.co/t/unassigned-shards-how-to-set-default-replica-number-to-0/336458)

<div class="topic-metadata">

**Author:** [@sbocquet](https://discuss.elastic.co/u/sbocquet)\
**Replies:** 1\
**Last updated:** [June 20, 2023, 1:36pm UTC](https://discuss.elastic.co/t/unassigned-shards-how-to-set-default-replica-number-to-0/336458 "2023-06-20T13:36:37Z")

</div>

Hi, A few days ago, I've just installed a new node to my single node cluster, in order to manage datastreams lifecycle policies between 2 nodes : elk1 is configured in elasticsearch.yml with node.roles: master, data\_…

---

## [Seeking a developer to help extend Elasticsearch to connect with Web3 API](https://discuss.elastic.co/t/seeking-a-developer-to-help-extend-elasticsearch-to-connect-with-web3-api/336114)

<div class="topic-metadata">

**Author:** [@Jules\_Lai](https://discuss.elastic.co/u/Jules_Lai)\
**Replies:** 6\
**Last updated:** [June 19, 2023, 4:42pm UTC](https://discuss.elastic.co/t/seeking-a-developer-to-help-extend-elasticsearch-to-connect-with-web3-api/336114 "2023-06-19T16:42:34Z")

</div>

Hi, I am looking for a developer who is able to help integrate Web3 into Elasticsearch. I am one of the developers working on the Web3 interface for SIA decentralised storage. I will be mainly using Elasticsearch with…

---

## [Dynamically set s3 bucket name in logstash output](https://discuss.elastic.co/t/dynamically-set-s3-bucket-name-in-logstash-output/336484)

<div class="topic-metadata">

**Author:** [@kunalmohan](https://discuss.elastic.co/u/kunalmohan)\
**Replies:** 1\
**Last updated:** [June 20, 2023, 1:09pm UTC](https://discuss.elastic.co/t/dynamically-set-s3-bucket-name-in-logstash-output/336484 "2023-06-20T13:09:34Z")

</div>

Is there a way I can set s3 bucket name using a @metadata field?

---

## [Install/ create 6 node elasticsearch 8.7 cluster](https://discuss.elastic.co/t/install-create-6-node-elasticsearch-8-7-cluster/336148)

<div class="topic-metadata">

**Author:** [@zaeemmasood](https://discuss.elastic.co/u/zaeemmasood)\
**Replies:** 2\
**Last updated:** [June 20, 2023, 1:02pm UTC](https://discuss.elastic.co/t/install-create-6-node-elasticsearch-8-7-cluster/336148 "2023-06-20T13:02:24Z")

</div>

Hi All, I am looking for some info on how to install and create ES 8.7 cluster on RHEL 7 servers using tar.gz. I am not able to find the steps in the documentation. Need to know how to make nodes join a cluster. Need…

---

## [Logstash not listening for second input](https://discuss.elastic.co/t/logstash-not-listening-for-second-input/336480)

<div class="topic-metadata">

**Author:** [@Shabu](https://discuss.elastic.co/u/Shabu)\
**Replies:** 2\
**Last updated:** [June 20, 2023, 1:01pm UTC](https://discuss.elastic.co/t/logstash-not-listening-for-second-input/336480 "2023-06-20T13:01:21Z")

</div>

I have set up a working ELK stack with input from winlogbeat. Now I want to add a second input for ingesting syslog logs from a switch. I configured my logstash to do so, but it still only listens on port 5044 after rest…

---

## [Issue with mapping in elasticsearch](https://discuss.elastic.co/t/issue-with-mapping-in-elasticsearch/336461)

<div class="topic-metadata">

**Author:** [@Hanni](https://discuss.elastic.co/u/Hanni)\
**Replies:** 1\
**Last updated:** [June 20, 2023, 12:03pm UTC](https://discuss.elastic.co/t/issue-with-mapping-in-elasticsearch/336461 "2023-06-20T12:03:52Z")

</div>

Hi, I'm trying to index a field in elasticsearch with my index template. Except that my field can either be of type text (ex: No) or it can be of type float ( ex: 8.1). When I set the type to float in my mapping, I get e…

---

## [Can not have the same result](https://discuss.elastic.co/t/can-not-have-the-same-result/336460)

<div class="topic-metadata">

**Author:** [@stephane\_chan](https://discuss.elastic.co/u/stephane_chan)\
**Replies:** 3\
**Last updated:** [June 20, 2023, 11:54am UTC](https://discuss.elastic.co/t/can-not-have-the-same-result/336460 "2023-06-20T11:54:33Z")

</div>

Hi, I can't do a song search on an elasticsearch lyrics excerpt, The lyric: "... Na dia mbola zaza Na dia mbola kely ..." if I search for "mbola zaza" it gives me the result but if I type "ola zaza" it gives me no re…

---

## [Not working TCP input with TLS](https://discuss.elastic.co/t/not-working-tcp-input-with-tls/336473)

<div class="topic-metadata">

**Author:** [@wedkarz014](https://discuss.elastic.co/u/wedkarz014)\
**Replies:** 0\
**Last updated:** [June 20, 2023, 11:41am UTC](https://discuss.elastic.co/t/not-working-tcp-input-with-tls/336473 "2023-06-20T11:41:28Z")

</div>

Hi, I want to send syslog events but with tls, unfortunately i have a problem with that. Logstash receive first event and that's all, i don't have any error logs. Here is output config: output { tcp { host =\> …

---

## [TSVB Markdown visualization](https://discuss.elastic.co/t/tsvb-markdown-visualization/335319)

<div class="topic-metadata">

**Author:** [@Alice\_Ionescu](https://discuss.elastic.co/u/Alice_Ionescu)\
**Replies:** 1\
**Last updated:** [June 20, 2023, 11:11am UTC](https://discuss.elastic.co/t/tsvb-markdown-visualization/335319 "2023-06-20T11:11:26Z")

</div>

Hello, I am trying to create a table which is displayed like this: ||column\_name ||column\_value|| ||column\_name ||column\_value|| And display information only on a row from an index. in TSVB Markdown visualization. …

---

## [Logs related to database (postgres) pods are not moving to elastic](https://discuss.elastic.co/t/logs-related-to-database-postgres-pods-are-not-moving-to-elastic/336459)

<div class="topic-metadata">

**Author:** [@unais](https://discuss.elastic.co/u/unais)\
**Replies:** 0\
**Last updated:** [June 20, 2023, 9:29am UTC](https://discuss.elastic.co/t/logs-related-to-database-postgres-pods-are-not-moving-to-elastic/336459 "2023-06-20T09:29:37Z")

</div>

Hi community, I'm not able to see the logs related postgres even though I have mentioned the name of the pod in filebeat. postgres logs: (on running kubectl logs command) 2023-06-19 07:37:39.591 UTC \[73\] ERROR: "xyz" …

---

## [LogStash and parsing OPNSenser logs](https://discuss.elastic.co/t/logstash-and-parsing-opnsenser-logs/334234)

<div class="topic-metadata">

**Author:** [@LoggingJennfier](https://discuss.elastic.co/u/LoggingJennfier)\
**Replies:** 2\
**Last updated:** [June 20, 2023, 9:16am UTC](https://discuss.elastic.co/t/logstash-and-parsing-opnsenser-logs/334234 "2023-06-20T09:16:07Z")

</div>

My logs are coming in as follows: \<134\>May 24 14:39:32 edge.internal filterlog\[2535\]: 78,,,ffe6d10d1f27a42fc0edc3abb3a6d333,ovpnc1,match,pass,out,4,0x0,,63,61951,0,DF,6,tcp,60,10.8.0.2,20.44.17.5,44575,443,0,S,149708160…

---

## [Filebeat error for port ERROR: Address already in use](https://discuss.elastic.co/t/filebeat-error-for-port-error-address-already-in-use/336422)

<div class="topic-metadata">

**Author:** [@yogesh.gangwar](https://discuss.elastic.co/u/yogesh.gangwar)\
**Replies:** 1\
**Last updated:** [June 20, 2023, 8:54am UTC](https://discuss.elastic.co/t/filebeat-error-for-port-error-address-already-in-use/336422 "2023-06-20T08:54:33Z")

</div>

While running the logstash I'm getting an issue of "A plugin had an unrecoverable error. Will restart this plugin." \</ \[2023-06-20T10:37:52,046\]\[INFO \]\[org.logstash.beats.Server\]\[main\]\[f36c0056714d92177d9fb7e027196d5ceb…

---

## [Undefined class constant 'MAJOR\_VERSION](https://discuss.elastic.co/t/undefined-class-constant-major-version/336429)

<div class="topic-metadata">

**Author:** [@zaheer8](https://discuss.elastic.co/u/zaheer8)\
**Replies:** 4\
**Last updated:** [June 20, 2023, 8:46am UTC](https://discuss.elastic.co/t/undefined-class-constant-major-version/336429 "2023-06-20T08:46:53Z")

</div>

Hi Geek Elasticsearch component is showing the Undefined class constant 'MAJOR\_VERSION' error in Elasticsearch version 6.x . Can you help why it is showing this error?

---

## [Edit kibana login UI Title](https://discuss.elastic.co/t/edit-kibana-login-ui-title/335962)

<div class="topic-metadata">

**Author:** [@mr\_ph](https://discuss.elastic.co/u/mr_ph)\
**Replies:** 9\
**Last updated:** [June 20, 2023, 8:36am UTC](https://discuss.elastic.co/t/edit-kibana-login-ui-title/335962 "2023-06-20T08:36:23Z")

</div>

how can i edit the title seeing in the loging page of kibana, Where i can find the respective file. how can i add other logos and title texts in it. Change the welcome to elastic into any other title, for that wher…

---

## [Min and Max timestamp difference](https://discuss.elastic.co/t/min-and-max-timestamp-difference/334634)

<div class="topic-metadata">

**Author:** [@SUBIN\_B\_MATHEW](https://discuss.elastic.co/u/SUBIN_B_MATHEW)\
**Replies:** 1\
**Last updated:** [June 20, 2023, 8:04am UTC](https://discuss.elastic.co/t/min-and-max-timestamp-difference/334634 "2023-06-20T08:04:11Z")

</div>

Aggregated the Min and Max timestamp based on the message id. I wanted to calculate the time difference between min and Max time and show it in a data table on kibana dashboard , could you please help me on this?

---

## [How to get Distinct results using Search API](https://discuss.elastic.co/t/how-to-get-distinct-results-using-search-api/336217)

<div class="topic-metadata">

**Author:** [@asimelastic](https://discuss.elastic.co/u/asimelastic)\
**Replies:** 2\
**Last updated:** [June 20, 2023, 7:03am UTC](https://discuss.elastic.co/t/how-to-get-distinct-results-using-search-api/336217 "2023-06-20T07:03:08Z")

</div>

I have a "customer" index with fields "FirstName" and "LastName". My index contains data as follows: First Name | LastName Richard | Lockwood Richard | Lockwood 2 Richard | Lockwood 3 Richard | Lockwood 4 Richard …

---

## [Logstash config for transactions](https://discuss.elastic.co/t/logstash-config-for-transactions/336294)

<div class="topic-metadata">

**Author:** [@Indeed2000](https://discuss.elastic.co/u/Indeed2000)\
**Replies:** 5\
**Last updated:** [June 20, 2023, 6:25am UTC](https://discuss.elastic.co/t/logstash-config-for-transactions/336294 "2023-06-20T06:25:36Z")

</div>

Hi need to write logstash config that parse log file from this path: "/tmp/logs/\*" store in elastic. here is the log: 09:54:37:566 R\[SRV1\]L\[477\]T\[0300\]ID\[696119\] 09:54:37:566 S\[SRV2\]L\[477\]T\[0300\]ID\[696119\] 09:54:55:28…

---

## [Logstash update sql\_last\_value while using paging](https://discuss.elastic.co/t/logstash-update-sql-last-value-while-using-paging/336362)

<div class="topic-metadata">

**Author:** [@zalseryani](https://discuss.elastic.co/u/zalseryani)\
**Replies:** 3\
**Last updated:** [June 20, 2023, 6:00am UTC](https://discuss.elastic.co/t/logstash-update-sql-last-value-while-using-paging/336362 "2023-06-20T06:00:52Z")

</div>

sql\_last\_value update with Paging I am configuring logstash to use jdbc input knowing that I am using jdbc\_paging with the configuration. what I am facing now is that sql\_last\_value is being updated after all record…

---

## [Run a query after grouping and finding max](https://discuss.elastic.co/t/run-a-query-after-grouping-and-finding-max/336414)

<div class="topic-metadata">

**Author:** [@arvidh](https://discuss.elastic.co/u/arvidh)\
**Replies:** 2\
**Last updated:** [June 20, 2023, 5:33am UTC](https://discuss.elastic.co/t/run-a-query-after-grouping-and-finding-max/336414 "2023-06-20T05:33:12Z")

</div>

Here is some test data I have in an index: {"name" : "almara" , "version" : "1" , "groups" : "blueHouse", "data1" : " value1"} {"name" : "almara" , "version" : "2" , "groups" : "blueHouse", "data1" : " Something"} {"nam…

---

## [Elastic agent installation failed on windows](https://discuss.elastic.co/t/elastic-agent-installation-failed-on-windows/336424)

<div class="topic-metadata">

**Author:** [@esijati](https://discuss.elastic.co/u/esijati)\
**Replies:** 0\
**Last updated:** [June 20, 2023, 5:23am UTC](https://discuss.elastic.co/t/elastic-agent-installation-failed-on-windows/336424 "2023-06-20T05:23:40Z")

</div>

Fleet managed Elastic agent installation failed on windows With error Error: fail to enroll: fail to execute request to fleet-server: Proxy Authentication Required. Enroll command failed with exist code: 1 Event view…

---

## [Logstash filling up disk space beyond queue.max\_bytes](https://discuss.elastic.co/t/logstash-filling-up-disk-space-beyond-queue-max-bytes/336388)

<div class="topic-metadata">

**Author:** [@Sindhu\_Bandi](https://discuss.elastic.co/u/Sindhu_Bandi)\
**Replies:** 4\
**Last updated:** [June 20, 2023, 5:19am UTC](https://discuss.elastic.co/t/logstash-filling-up-disk-space-beyond-queue-max-bytes/336388 "2023-06-20T05:19:39Z")

</div>

Logstash persistent volume size is increasing beyond configured queue.max\_bytes Scenario: Logstash : 7.17.3 Env : On Kubernetes cluster Persistence: Enabled logstash.yml: ---- http.host: "0.0.0.0" path.config: /usr/…

---

## [Occasionally NoAliveNodesFound with HAProxy as Loadbalancer](https://discuss.elastic.co/t/occasionally-noalivenodesfound-with-haproxy-as-loadbalancer/335890)

<div class="topic-metadata">

**Author:** [@oliver.hart](https://discuss.elastic.co/u/oliver.hart)\
**Replies:** 2\
**Last updated:** [June 20, 2023, 4:30am UTC](https://discuss.elastic.co/t/occasionally-noalivenodesfound-with-haproxy-as-loadbalancer/335890 "2023-06-20T04:30:32Z")

</div>

Hello, we have kind of a special problem, so I try to explain everything in detail. Setup The above diagram shows our current setup (simplified). Our app runs within a Kubernetes / Openshift Cluster. The Deploymen…

[Previous page](https://discuss.elastic.co/tag/none.md?no_tags=true&page=355)

[Next page](https://discuss.elastic.co/tag/none.md?no_tags=true&page=357)
