# \#none

**URL:** https://discuss.elastic.co/tag/none.md?no_tags=true&page=360

[Latest](https://discuss.elastic.co/latest.md) · [Categories](https://discuss.elastic.co/categories.md) · [Tags](https://discuss.elastic.co/tags.md)

**Page:** 361

---

## [Update elasticsearch from 7.15 to 7.17 version](https://discuss.elastic.co/t/update-elasticsearch-from-7-15-to-7-17-version/336006)

<div class="topic-metadata">

**Author:** [@Amani188](https://discuss.elastic.co/u/Amani188)\
**Replies:** 1\
**Last updated:** [June 14, 2023, 8:49pm UTC](https://discuss.elastic.co/t/update-elasticsearch-from-7-15-to-7-17-version/336006 "2023-06-14T20:49:09Z")

</div>

Hi, I'm migrating elasticsearch from 7.15 to 7.17 version and i want to ensure that the jvm options is it correct this way : the java version is: openjdk version "1.8.0\_372" pl\_elasticstack::params::jvm\_options: \[ '-…

---

## [Dev console suddenly just a blank canvas](https://discuss.elastic.co/t/dev-console-suddenly-just-a-blank-canvas/335981)

<div class="topic-metadata">

**Author:** [@supernat10](https://discuss.elastic.co/u/supernat10)\
**Replies:** 2\
**Last updated:** [June 14, 2023, 8:00pm UTC](https://discuss.elastic.co/t/dev-console-suddenly-just-a-blank-canvas/335981 "2023-06-14T20:00:07Z")

</div>

This is the same issue as was reported in March but closed: Dev console suddenly just a blank canvas We are using Kibana 8.7.0 and have been for a couple of weeks without issue as we migrate from version 6. I use Chrom…

---

## [Removing text qualifier double quotes from Logstash CSV output](https://discuss.elastic.co/t/removing-text-qualifier-double-quotes-from-logstash-csv-output/335990)

<div class="topic-metadata">

**Author:** [@mhoward](https://discuss.elastic.co/u/mhoward)\
**Replies:** 2\
**Last updated:** [June 14, 2023, 6:35pm UTC](https://discuss.elastic.co/t/removing-text-qualifier-double-quotes-from-logstash-csv-output/335990 "2023-06-14T18:35:18Z")

</div>

Not sure if possible but I'm creating a CSV using Logstash. When I open the CSV in Notepad++ it adds double quotations around one specific field. The field itself is a city state zip code field that is created using a …

---

## [I can't reopen a closed index](https://discuss.elastic.co/t/i-cant-reopen-a-closed-index/335895)

<div class="topic-metadata">

**Author:** [@Hatef](https://discuss.elastic.co/u/Hatef)\
**Replies:** 8\
**Last updated:** [June 14, 2023, 6:34pm UTC](https://discuss.elastic.co/t/i-cant-reopen-a-closed-index/335895 "2023-06-14T18:34:15Z")

</div>

Hi all, I'm pretty new to ES but have played around with ELK stack a bit and I'm more familiar now to run some API queries and modifying configs. I have closed an index called accelerate which is the main source of our…

---

## [Is there a way to convert a unicode escape sequence within the Logstash pipeline so that the actual emoji icon is show within Elastic?](https://discuss.elastic.co/t/is-there-a-way-to-convert-a-unicode-escape-sequence-within-the-logstash-pipeline-so-that-the-actual-emoji-icon-is-show-within-elastic/336002)

<div class="topic-metadata">

**Author:** [@farnazpatel](https://discuss.elastic.co/u/farnazpatel)\
**Replies:** 0\
**Last updated:** [June 14, 2023, 5:04pm UTC](https://discuss.elastic.co/t/is-there-a-way-to-convert-a-unicode-escape-sequence-within-the-logstash-pipeline-so-that-the-actual-emoji-icon-is-show-within-elastic/336002 "2023-06-14T17:04:38Z")

</div>

I am sending messages from Kafka in to Logstash and then through to Elastic, some of the messages contain emojis, these emojis are converted to Unicode escape characters when being stored in Kafka e.g. :blush: ---\> is c…

---

## [Logstash not applying correct system time to ingestion timestamp](https://discuss.elastic.co/t/logstash-not-applying-correct-system-time-to-ingestion-timestamp/335884)

<div class="topic-metadata">

**Author:** [@Anthony\_Zottola](https://discuss.elastic.co/u/Anthony_Zottola)\
**Replies:** 3\
**Last updated:** [June 14, 2023, 4:53pm UTC](https://discuss.elastic.co/t/logstash-not-applying-correct-system-time-to-ingestion-timestamp/335884 "2023-06-14T16:53:50Z")

</div>

Hello, I live in the NA East timezone so currently we are 4 hours behind UTC, I understand that logstash puts the @timestamp in UTC but it is putting in the wrong time. Logstash parsed a log at 10:30 am in my timezone …

---

## [Kafka plugin with every new group id it is pointing to old offset and not able to consume events](https://discuss.elastic.co/t/kafka-plugin-with-every-new-group-id-it-is-pointing-to-old-offset-and-not-able-to-consume-events/335994)

<div class="topic-metadata">

**Author:** [@Selim\_Hassan](https://discuss.elastic.co/u/Selim_Hassan)\
**Replies:** 0\
**Last updated:** [June 14, 2023, 3:36pm UTC](https://discuss.elastic.co/t/kafka-plugin-with-every-new-group-id-it-is-pointing-to-old-offset-and-not-able-to-consume-events/335994 "2023-06-14T15:36:18Z")

</div>

I have pipeline created as input { kafka { group\_id =\> "3fixed1" client\_id =\> "2fixed1" codec =\> avro{ schema\_uri =\> "C:\\LogStash\\KafkaClient\\topology.avsc" encoding =\> "binary" } bootstrap\_servers =\> "obootstap…

---

## [Expiration date password for kibana users](https://discuss.elastic.co/t/expiration-date-password-for-kibana-users/335989)

<div class="topic-metadata">

**Author:** [@valerio.vigliotta](https://discuss.elastic.co/u/valerio.vigliotta)\
**Replies:** 1\
**Last updated:** [June 14, 2023, 3:34pm UTC](https://discuss.elastic.co/t/expiration-date-password-for-kibana-users/335989 "2023-06-14T15:34:06Z")

</div>

Hi, We have an ELK stack on premise V. 8.5.3 with free licence. We need to be able to set the expiration date to users Kibana password every 6 months. The users that i am referred is those from "Menu"--\>"Stack Managamen…

---

## [Elastic Agent 8.8.0 disk space requirement](https://discuss.elastic.co/t/elastic-agent-8-8-0-disk-space-requirement/334723)

<div class="topic-metadata">

**Author:** [@schapman](https://discuss.elastic.co/u/schapman)\
**Replies:** 6\
**Last updated:** [June 14, 2023, 2:49pm UTC](https://discuss.elastic.co/t/elastic-agent-8-8-0-disk-space-requirement/334723 "2023-06-14T14:49:08Z")

</div>

Just a heads up if installing the latest elastic agent on Linux servers with relatively small free space... It looks like the elastic-agent's requirement for disk space has increased (almost doubled?) over the past year…

---

## [Create ElasticSearch cluster with 2 or 3 nodes](https://discuss.elastic.co/t/create-elasticsearch-cluster-with-2-or-3-nodes/335901)

<div class="topic-metadata">

**Author:** [@TomTom](https://discuss.elastic.co/u/TomTom)\
**Replies:** 4\
**Last updated:** [June 14, 2023, 1:45pm UTC](https://discuss.elastic.co/t/create-elasticsearch-cluster-with-2-or-3-nodes/335901 "2023-06-14T13:45:46Z")

</div>

I need to create an Elasticsearch cluster on Ubuntu machines, but to ensure high availability I would like to have more than one node in case I need to update or upgrade the server. Is there any material that teaches ho…

---

## [Spike on CPU usage relates to the increase of fielddata memory](https://discuss.elastic.co/t/spike-on-cpu-usage-relates-to-the-increase-of-fielddata-memory/335303)

<div class="topic-metadata">

**Author:** [@GustavoSantos](https://discuss.elastic.co/u/GustavoSantos)\
**Replies:** 5\
**Last updated:** [June 14, 2023, 1:43pm UTC](https://discuss.elastic.co/t/spike-on-cpu-usage-relates-to-the-increase-of-fielddata-memory/335303 "2023-06-14T13:43:41Z")

</div>

Hi team, We faced a very weird situation in one of our production clusters. Suddenly the CPU utilization of all nodes got 100% after being consistently under 30% for a long time. Looking at Kibana metrics, the only var…

---

## [How to highlight multifields? Iis there a way to highlight all results with the same multifield (same source, different analyzers) Multi-fields with multiple analyzers](https://discuss.elastic.co/t/how-to-highlight-multifields-iis-there-a-way-to-highlight-all-results-with-the-same-multifield-same-source-different-analyzers-multi-fields-with-multiple-analyzers/335985)

<div class="topic-metadata">

**Author:** [@Eduard\_mart](https://discuss.elastic.co/u/Eduard_mart)\
**Replies:** 0\
**Last updated:** [June 14, 2023, 1:41pm UTC](https://discuss.elastic.co/t/how-to-highlight-multifields-iis-there-a-way-to-highlight-all-results-with-the-same-multifield-same-source-different-analyzers-multi-fields-with-multiple-analyzers/335985 "2023-06-14T13:41:05Z")

</div>

How to highlight multifield? Is there a way to highlight all results with the same multifield (same source, different analyzers)? Multi-fields with multiple analyzers

---

## [Bool Filter doubt / Match\_all](https://discuss.elastic.co/t/bool-filter-doubt-match-all/335982)

<div class="topic-metadata">

**Author:** [@RabBit\_BR](https://discuss.elastic.co/u/RabBit_BR)\
**Replies:** 0\
**Last updated:** [June 14, 2023, 1:19pm UTC](https://discuss.elastic.co/t/bool-filter-doubt-match-all/335982 "2023-06-14T13:19:32Z")

</div>

Hi everybody. Maybe this is a silly doubt but if someone can answer. I have 3 docs, 1 with status:true field, 1 with status:false field and 1 doc without status field. POST idx\_test/\_bulk {"index":{}} {"name":"xpto 1"…

---

## [After restarting the master node, data and client nodes cannot discover the master](https://discuss.elastic.co/t/after-restarting-the-master-node-data-and-client-nodes-cannot-discover-the-master/334804)

<div class="topic-metadata">

**Author:** [@daniela09](https://discuss.elastic.co/u/daniela09)\
**Replies:** 10\
**Last updated:** [June 14, 2023, 1:11pm UTC](https://discuss.elastic.co/t/after-restarting-the-master-node-data-and-client-nodes-cannot-discover-the-master/334804 "2023-06-14T13:11:53Z")

</div>

Hi, I am using elasticsearch cluster (8.7.0) on Kubernetes, I have 1 master, 1 client and 3 data nodes. After the restart of my master node, the other nodes cannot discover the master again. This is in the log of the d…

---

## [Specify \`spec.policyID\` with standalone Elastic Agent deployed with ECK](https://discuss.elastic.co/t/specify-spec-policyid-with-standalone-elastic-agent-deployed-with-eck/335910)

<div class="topic-metadata">

**Author:** [@DougR](https://discuss.elastic.co/u/DougR)\
**Replies:** 2\
**Last updated:** [June 14, 2023, 12:39pm UTC](https://discuss.elastic.co/t/specify-spec-policyid-with-standalone-elastic-agent-deployed-with-eck/335910 "2023-06-14T12:39:54Z")

</div>

TL;DR ECK wants me to specify spec.policyID when deploying Elastic Agent, but I'm deploying a standalone Agent. Can I do this? Details I am using the Elastic Operator (ECK) to deploy standalone Elastic Agent to my clust…

---

## [Elastic Augeas Not Working](https://discuss.elastic.co/t/elastic-augeas-not-working/335718)

<div class="topic-metadata">

**Author:** [@ksaimohan2k](https://discuss.elastic.co/u/ksaimohan2k)\
**Replies:** 4\
**Last updated:** [June 14, 2023, 11:59am UTC](https://discuss.elastic.co/t/elastic-augeas-not-working/335718 "2023-06-14T11:59:40Z")

</div>

SELECT value FROM augeas WHERE path = '/etc/resolv.conf' AND label = 'nameserver'; SELECT \* FROM USERS When I am running this command, it's running successfully, but it's not retrieving the results.

---

## [Search by full name](https://discuss.elastic.co/t/search-by-full-name/335960)

<div class="topic-metadata">

**Author:** [@orlenkoda5](https://discuss.elastic.co/u/orlenkoda5)\
**Replies:** 1\
**Last updated:** [June 14, 2023, 11:57am UTC](https://discuss.elastic.co/t/search-by-full-name/335960 "2023-06-14T11:57:40Z")

</div>

Hi everyone. I have an index wich consists of 3 fields: sys\_name full\_name man\_id. I want to search by full name wich consists of 3 words: GET managers/\_search { "query": { "match": { "full\_name": "William Garvey J…

---

## [How can I show the value of a specific field from the most recent document in a time frame](https://discuss.elastic.co/t/how-can-i-show-the-value-of-a-specific-field-from-the-most-recent-document-in-a-time-frame/335964)

<div class="topic-metadata">

**Author:** [@Harold\_Van\_der\_Veken](https://discuss.elastic.co/u/Harold_Van_der_Veken)\
**Replies:** 2\
**Last updated:** [June 14, 2023, 11:22am UTC](https://discuss.elastic.co/t/how-can-i-show-the-value-of-a-specific-field-from-the-most-recent-document-in-a-time-frame/335964 "2023-06-14T11:22:40Z")

</div>

I have an ingest of logs where 1 field gets updated each time. Let say every minute I receive a logline and the count field holds certain value. In Kibana I can select for example the last hour as timeframe. Now I wo…

---

## [Getting HIgh s3 cost on LISTBUCKET OPERATION using logstash s3 pipeline](https://discuss.elastic.co/t/getting-high-s3-cost-on-listbucket-operation-using-logstash-s3-pipeline/335970)

<div class="topic-metadata">

**Author:** [@Dharampal\_Singh](https://discuss.elastic.co/u/Dharampal_Singh)\
**Replies:** 0\
**Last updated:** [June 14, 2023, 9:53am UTC](https://discuss.elastic.co/t/getting-high-s3-cost-on-listbucket-operation-using-logstash-s3-pipeline/335970 "2023-06-14T09:53:45Z")

</div>

Hi elastic Team, We have 3 logstash s3 pipeine from buckets(elb,cloudflare,cloudtrail) .Currently we are getting high s3 list bucket operation cost on these buckets.We want to know is there any way so we can minimize …

---

## [Replacing certificates on the server](https://discuss.elastic.co/t/replacing-certificates-on-the-server/335967)

<div class="topic-metadata">

**Author:** [@lolkerz](https://discuss.elastic.co/u/lolkerz)\
**Replies:** 0\
**Last updated:** [June 14, 2023, 9:42am UTC](https://discuss.elastic.co/t/replacing-certificates-on-the-server/335967 "2023-06-14T09:42:38Z")

</div>

Hello everyone. Previously, I had a certificate on the Logstash server. At the moment I have created a new certificate. Is it enough for me to simply replace it on the server, or does something need to be done beforehand…

---

## [Unable to execute commands in Logstash pipeline](https://discuss.elastic.co/t/unable-to-execute-commands-in-logstash-pipeline/335199)

<div class="topic-metadata">

**Author:** [@mr\_ph](https://discuss.elastic.co/u/mr_ph)\
**Replies:** 2\
**Last updated:** [June 14, 2023, 9:25am UTC](https://discuss.elastic.co/t/unable-to-execute-commands-in-logstash-pipeline/335199 "2023-06-14T09:25:28Z")

</div>

I have some pipelines in my logstash. In that pipelines i am executing some commands as per some conditions. After creating the pipeline i used the following command to test the pipeline /usr/share/logstash/bin/lo…

---

## [Question about elasticsearch index and logstash ingestion](https://discuss.elastic.co/t/question-about-elasticsearch-index-and-logstash-ingestion/335057)

<div class="topic-metadata">

**Author:** [@Hanni](https://discuss.elastic.co/u/Hanni)\
**Replies:** 20\
**Last updated:** [June 14, 2023, 9:10am UTC](https://discuss.elastic.co/t/question-about-elasticsearch-index-and-logstash-ingestion/335057 "2023-06-14T09:10:27Z")

</div>

Hello everyone I'd like to ask you 2 questions. I receive approximately 270 csv per month, 9 of them per day. Each csv is between 1kB and 3MG in size. All these csv are sent to the same index on elasticsearch with log…

---

## [Info about the free ELK tools](https://discuss.elastic.co/t/info-about-the-free-elk-tools/335044)

<div class="topic-metadata">

**Author:** [@sonujatav35](https://discuss.elastic.co/u/sonujatav35)\
**Replies:** 6\
**Last updated:** [June 14, 2023, 8:57am UTC](https://discuss.elastic.co/t/info-about-the-free-elk-tools/335044 "2023-06-14T08:57:36Z")

</div>

Hi Elasticsearch Community, I need some advice, I am creating a New ELK stack where i am going to store oracle log in ES and by using the logstash. I would like get the some information if i use the below the additional…

---

## [Fleet not working after update](https://discuss.elastic.co/t/fleet-not-working-after-update/335950)

<div class="topic-metadata">

**Author:** [@acosta353](https://discuss.elastic.co/u/acosta353)\
**Replies:** 0\
**Last updated:** [June 14, 2023, 8:33am UTC](https://discuss.elastic.co/t/fleet-not-working-after-update/335950 "2023-06-14T08:33:19Z")

</div>

Hello, Unfortunately, by mistake, one of my elasticsearch hosts updated from version 8.5.3 to 8.8.0, so this caused a lot of problems with my installation. I've already updated the other 2 elasticserver hosts, but now …

---

## [Shards are going to Intialized state againa and again, like in every 15 mins](https://discuss.elastic.co/t/shards-are-going-to-intialized-state-againa-and-again-like-in-every-15-mins/335902)

<div class="topic-metadata">

**Author:** [@priyankaMS](https://discuss.elastic.co/u/priyankaMS)\
**Replies:** 5\
**Last updated:** [June 14, 2023, 6:59am UTC](https://discuss.elastic.co/t/shards-are-going-to-intialized-state-againa-and-again-like-in-every-15-mins/335902 "2023-06-14T06:59:02Z")

</div>

My Elasticsearch cluster is going to yellow state in about every 15 min, becuase 2 replica shards are going to initialization state. After 5 mins or so, cluster is going back to green state. Error Logs: \[o.e.t.Outbou…

---

## [Index to red state cluster](https://discuss.elastic.co/t/index-to-red-state-cluster/335763)

<div class="topic-metadata">

**Author:** [@DJ\_Zhu](https://discuss.elastic.co/u/DJ_Zhu)\
**Replies:** 10\
**Last updated:** [June 14, 2023, 6:59am UTC](https://discuss.elastic.co/t/index-to-red-state-cluster/335763 "2023-06-14T06:59:46Z")

</div>

I have a question regarding shard selection during index/bulk operations in Elasticsearch version 6.8.6. In my cluster, I have three data nodes: A, B, and C. The shards (with no replicas) are evenly allocated across the…

---

## [How to synchronise data (PostgreSQL + MongoDB) in ES](https://discuss.elastic.co/t/how-to-synchronise-data-postgresql-mongodb-in-es/335876)

<div class="topic-metadata">

**Author:** [@stephane\_chan](https://discuss.elastic.co/u/stephane_chan)\
**Replies:** 3\
**Last updated:** [June 14, 2023, 6:32am UTC](https://discuss.elastic.co/t/how-to-synchronise-data-postgresql-mongodb-in-es/335876 "2023-06-14T06:32:37Z")

</div>

Hi, I'm new in Elasticsearch. I have Logstash configurations with postgresql and mongodb as data source (data.postgresql.conf, data.mongodb.conf), my problem is that I have to launch the logstash configuration of postg…

---

## [\[Agent-Netflow\] Anomaly Detect for spikes on coms between 2 IP](https://discuss.elastic.co/t/agent-netflow-anomaly-detect-for-spikes-on-coms-between-2-ip/335542)

<div class="topic-metadata">

**Author:** [@isaqueprofeta](https://discuss.elastic.co/u/isaqueprofeta)\
**Replies:** 5\
**Last updated:** [June 13, 2023, 9:49pm UTC](https://discuss.elastic.co/t/agent-netflow-anomaly-detect-for-spikes-on-coms-between-2-ip/335542 "2023-06-13T21:49:52Z")

</div>

Hey everyone, thanks for having me, I'm currently working with Elastic 8.3 using an Agent (Fleet managed) with Netflow Integration. My current goal is to create two ML Jobs for spikes on traffic between 2 IP's, but I …

---

## [Are mappings carried over when using daily indexes?](https://discuss.elastic.co/t/are-mappings-carried-over-when-using-daily-indexes/335807)

<div class="topic-metadata">

**Author:** [@dfinn](https://discuss.elastic.co/u/dfinn)\
**Replies:** 6\
**Last updated:** [June 13, 2023, 9:36pm UTC](https://discuss.elastic.co/t/are-mappings-carried-over-when-using-daily-indexes/335807 "2023-06-13T21:36:15Z")

</div>

We are looking into an issue where we continue to hit field limits. We have been bumping them but we know this is not a permanent solution and we need to find a long term solution. We are using daily indexes that we ar…

---

## [This output type currently does not support connectivity to a remote Elasticsearch cluster](https://discuss.elastic.co/t/this-output-type-currently-does-not-support-connectivity-to-a-remote-elasticsearch-cluster/335914)

<div class="topic-metadata">

**Author:** [@Verdugo\_Gonzalo](https://discuss.elastic.co/u/Verdugo_Gonzalo)\
**Replies:** 0\
**Last updated:** [June 13, 2023, 8:45pm UTC](https://discuss.elastic.co/t/this-output-type-currently-does-not-support-connectivity-to-a-remote-elasticsearch-cluster/335914 "2023-06-13T20:45:26Z")

</div>

Greetings, I have the following error in fleet that I can't fix. This output type currently does not support connectivity to a remote Elasticsearch cluster. I share the elasticsearch.yml, maybe some configuration is g…

[Previous page](https://discuss.elastic.co/tag/none.md?no_tags=true&page=359)

[Next page](https://discuss.elastic.co/tag/none.md?no_tags=true&page=361)
