# \#none

**URL:** https://discuss.elastic.co/tag/none.md?no_tags=true&page=364

[Latest](https://discuss.elastic.co/latest.md) · [Categories](https://discuss.elastic.co/categories.md) · [Tags](https://discuss.elastic.co/tags.md)

**Page:** 365

---

## [Disable \_source field](https://discuss.elastic.co/t/disable-source-field/335434)

<div class="topic-metadata">

**Author:** [@Mhag](https://discuss.elastic.co/u/Mhag)\
**Replies:** 4\
**Last updated:** [June 8, 2023, 5:39am UTC](https://discuss.elastic.co/t/disable-source-field/335434 "2023-06-08T05:39:53Z")

</div>

Hello, I'm currently working on optimizing the size of an index. After reviewing the documentation and analyzing the field sizes, I found that a significant portion of the document size is attributed to the \_source fiel…

---

## [Elastic agent 7.12 32-bit](https://discuss.elastic.co/t/elastic-agent-7-12-32-bit/335495)

<div class="topic-metadata">

**Author:** [@Pukar](https://discuss.elastic.co/u/Pukar)\
**Replies:** 0\
**Last updated:** [June 8, 2023, 5:15am UTC](https://discuss.elastic.co/t/elastic-agent-7-12-32-bit/335495 "2023-06-08T05:15:37Z")

</div>

Hi, i have elasticsearch environment with 7.12 version 64-bit operating system for logging elastic agents to windows 7, one of the w7 machines is 32-bit OS. is it possible to collect logs from elastic agent 32-bit into …

---

## [Unable to enrich document](https://discuss.elastic.co/t/unable-to-enrich-document/335492)

<div class="topic-metadata">

**Author:** [@Dasher](https://discuss.elastic.co/u/Dasher)\
**Replies:** 1\
**Last updated:** [June 8, 2023, 3:30am UTC](https://discuss.elastic.co/t/unable-to-enrich-document/335492 "2023-06-08T03:30:32Z")

</div>

Hi All, I have created an kibana alert which is ingesting the document to a index. I have set a default pipeline to that index but when i see the documents ingested from kibana alerts it doesn't have the enrich fields. …

---

## [Monitoring Microservice](https://discuss.elastic.co/t/monitoring-microservice/335491)

<div class="topic-metadata">

**Author:** [@Suhendra\_sitorus](https://discuss.elastic.co/u/Suhendra_sitorus)\
**Replies:** 0\
**Last updated:** [June 8, 2023, 2:55am UTC](https://discuss.elastic.co/t/monitoring-microservice/335491 "2023-06-08T02:55:18Z")

</div>

Hallo, I am used ELK version 8.5.0, i am want monitoring Microservice system, the microservice with base pyhton frame work Fast API and the microservice on docker and kubernetes ( OCP ), i have 100 more microservice so …

---

## [How to format the grok pattern parsed field value in a new line based on timestamp?](https://discuss.elastic.co/t/how-to-format-the-grok-pattern-parsed-field-value-in-a-new-line-based-on-timestamp/335460)

<div class="topic-metadata">

**Author:** [@abhisheksa](https://discuss.elastic.co/u/abhisheksa)\
**Replies:** 0\
**Last updated:** [June 7, 2023, 6:15pm UTC](https://discuss.elastic.co/t/how-to-format-the-grok-pattern-parsed-field-value-in-a-new-line-based-on-timestamp/335460 "2023-06-07T18:15:42Z")

</div>

I have this log message which is filtered using grok pattern. Entire message gets displayed in a single line in the filtered output. { "message": \[ "Calling com.portal.ws.service.GvpV2Service@2ad03f20 method cr…

---

## [Elasticsearch Circuit breaking exception](https://discuss.elastic.co/t/elasticsearch-circuit-breaking-exception/335305)

<div class="topic-metadata">

**Author:** [@RAM\_NATHAN](https://discuss.elastic.co/u/RAM_NATHAN)\
**Replies:** 2\
**Last updated:** [June 7, 2023, 10:57pm UTC](https://discuss.elastic.co/t/elasticsearch-circuit-breaking-exception/335305 "2023-06-07T22:57:00Z")

</div>

Hi Im using elasticsearch 7.10.2 single node. Im getting this Data too large, data for \[\<http\_request\>\] would be \[3985754120/3.7gb\], which is larger than the limit of \[3910375833/3.6gb\], real usage: \[3985754120/3.7gb\],…

---

## [How to create elastic Agent Policy and Toekns using Curl](https://discuss.elastic.co/t/how-to-create-elastic-agent-policy-and-toekns-using-curl/335482)

<div class="topic-metadata">

**Author:** [@kos](https://discuss.elastic.co/u/kos)\
**Replies:** 0\
**Last updated:** [June 7, 2023, 10:16pm UTC](https://discuss.elastic.co/t/how-to-create-elastic-agent-policy-and-toekns-using-curl/335482 "2023-06-07T22:16:34Z")

</div>

Trying to setup automatic sandbox environment that requires destroy and rebuild quiet often. Every time building the sandbox using the docker compose had to manually login to the GUI and add fleet host, create fleet pol…

---

## [Setting up Elastic Search, Kibana, Fleet and Elastic Agent](https://discuss.elastic.co/t/setting-up-elastic-search-kibana-fleet-and-elastic-agent/335481)

<div class="topic-metadata">

**Author:** [@kos](https://discuss.elastic.co/u/kos)\
**Replies:** 0\
**Last updated:** [June 7, 2023, 10:12pm UTC](https://discuss.elastic.co/t/setting-up-elastic-search-kibana-fleet-and-elastic-agent/335481 "2023-06-07T22:12:17Z")

</div>

When setting up Elastic Search, Kibana, Fleet Server and Elastic Agent using the docker compose file provided in the Elastic Search 8.8 documentation here we have to login to the GUI and modify the outputs settings Eg: m…

---

## [DSL Query does date math differently than KQL?](https://discuss.elastic.co/t/dsl-query-does-date-math-differently-than-kql/335468)

<div class="topic-metadata">

**Author:** [@pocketcolin](https://discuss.elastic.co/u/pocketcolin)\
**Replies:** 1\
**Last updated:** [June 7, 2023, 8:37pm UTC](https://discuss.elastic.co/t/dsl-query-does-date-math-differently-than-kql/335468 "2023-06-07T20:37:10Z")

</div>

I have a Kibana graph showing a number of records where a value is \>= the current date (specifically now/d). I just happened to be testing a similar query in dev tools when I discovered that the number shown in Kibana or…

---

## [Set Kibana Memory](https://discuss.elastic.co/t/set-kibana-memory/335472)

<div class="topic-metadata">

**Author:** [@kaismax](https://discuss.elastic.co/u/kaismax)\
**Replies:** 4\
**Last updated:** [June 7, 2023, 7:54pm UTC](https://discuss.elastic.co/t/set-kibana-memory/335472 "2023-06-07T19:54:57Z")

</div>

in kibana 7.17.7, How I can set the Memory for kibana, I edited node.options and set to --max-old-space-size=8192 but when i go "stack monitoring", i found that kibana still showing under "Memory Usage :1.9 GB / 4.0 GB"

---

## [I cannot search by telephone (part)](https://discuss.elastic.co/t/i-cannot-search-by-telephone-part/333353)

<div class="topic-metadata">

**Author:** [@mg85](https://discuss.elastic.co/u/mg85)\
**Replies:** 1\
**Last updated:** [June 7, 2023, 7:21pm UTC](https://discuss.elastic.co/t/i-cannot-search-by-telephone-part/333353 "2023-06-07T19:21:37Z")

</div>

Im trying to create an autocomplete, this is my index creation: curl -X PUT "localhost:9200/backoffice\_clients-com" -H 'Content-Type: application/json' -d' { "settings": { "analysis": { "analyzer": { …

---

## [QueryString vs multiple wildcards](https://discuss.elastic.co/t/querystring-vs-multiple-wildcards/335382)

<div class="topic-metadata">

**Author:** [@Ortiga\_Abdo](https://discuss.elastic.co/u/Ortiga_Abdo)\
**Replies:** 5\
**Last updated:** [June 7, 2023, 6:23pm UTC](https://discuss.elastic.co/t/querystring-vs-multiple-wildcards/335382 "2023-06-07T18:23:01Z")

</div>

I can't find any documentations that talks about queries and their performance/comparison I'm wondering which is better performance/faster multiple wildcard filter or a string\_query? "query": { "bool" : { "mu…

---

## [How are logstash grok definitions updated?](https://discuss.elastic.co/t/how-are-logstash-grok-definitions-updated/335452)

<div class="topic-metadata">

**Author:** [@lreger](https://discuss.elastic.co/u/lreger)\
**Replies:** 1\
**Last updated:** [June 7, 2023, 5:35pm UTC](https://discuss.elastic.co/t/how-are-logstash-grok-definitions-updated/335452 "2023-06-07T17:35:41Z")

</div>

How do I find out what my current version of logstash core patterns are running on my logstash cluster? I am running 7.17.1, but I suspect I am not running grok core patterns 4.34 ecsv1. I would like to have access to s…

---

## [Fetching all external IP address from firewall logs using logstash](https://discuss.elastic.co/t/fetching-all-external-ip-address-from-firewall-logs-using-logstash/334934)

<div class="topic-metadata">

**Author:** [@libinmath](https://discuss.elastic.co/u/libinmath)\
**Replies:** 5\
**Last updated:** [June 7, 2023, 4:27pm UTC](https://discuss.elastic.co/t/fetching-all-external-ip-address-from-firewall-logs-using-logstash/334934 "2023-06-07T16:27:27Z")

</div>

I am working with fortinet firewall logs, trying to get all external IP address from the fields srcip and dstip into a text file. I am new to writing filters for the logstash. The sample documents are as follow but I am…

---

## [Failed to start elastic search service after upgrade from version 8.2 to 8.8](https://discuss.elastic.co/t/failed-to-start-elastic-search-service-after-upgrade-from-version-8-2-to-8-8/335081)

<div class="topic-metadata">

**Author:** [@JonathanDSSOUZA](https://discuss.elastic.co/u/JonathanDSSOUZA)\
**Replies:** 5\
**Last updated:** [June 7, 2023, 4:17pm UTC](https://discuss.elastic.co/t/failed-to-start-elastic-search-service-after-upgrade-from-version-8-2-to-8-8/335081 "2023-06-07T16:17:49Z")

</div>

Hello community, after updating a cluster that contains 3 master nodes and 3 data nodes (ingest), the master nodes work normally, but the ingest nodes do not start the elasticsearch service, activating the DEBUG mode, re…

---

## [Https://discuss.elastic.co/t/possible-to-highlight-inner-hits-in-percolate-query/91926](https://discuss.elastic.co/t/https-discuss-elastic-co-t-possible-to-highlight-inner-hits-in-percolate-query-91926/335261)

<div class="topic-metadata">

**Author:** [@marufrahman](https://discuss.elastic.co/u/marufrahman)\
**Replies:** 4\
**Last updated:** [June 7, 2023, 3:35pm UTC](https://discuss.elastic.co/t/https-discuss-elastic-co-t-possible-to-highlight-inner-hits-in-percolate-query-91926/335261 "2023-06-07T15:35:48Z")

</div>

Is this currently supported?

---

## [How to set \`index.codec: best\_compression\` as the default for all future indices?](https://discuss.elastic.co/t/how-to-set-index-codec-best-compression-as-the-default-for-all-future-indices/335383)

<div class="topic-metadata">

**Author:** [@jerrac](https://discuss.elastic.co/u/jerrac)\
**Replies:** 2\
**Last updated:** [June 7, 2023, 3:22pm UTC](https://discuss.elastic.co/t/how-to-set-index-codec-best-compression-as-the-default-for-all-future-indices/335383 "2023-06-07T15:22:32Z")

</div>

Pretty much what the subject says. How to I turn on best\_compression as the default for all new indices? The docs explain how to do it per index. But I haven't found anything on setting it as the default. Nor has googl…

---

## [How can I delete documents 3 months older?](https://discuss.elastic.co/t/how-can-i-delete-documents-3-months-older/335351)

<div class="topic-metadata">

**Author:** [@Mary2022](https://discuss.elastic.co/u/Mary2022)\
**Replies:** 5\
**Last updated:** [June 7, 2023, 1:41pm UTC](https://discuss.elastic.co/t/how-can-i-delete-documents-3-months-older/335351 "2023-06-07T13:41:09Z")

</div>

I have Elasticsearch and Kibana 8.6 and I have an index with a size of 115GB. I would like to query by @timestamp and delete documents older than April 1, 2023. How can I do that? I am new to the query part and not sure …

---

## [Elastic Agent, Custom API Integration - GET Next URL from JSON response](https://discuss.elastic.co/t/elastic-agent-custom-api-integration-get-next-url-from-json-response/335104)

<div class="topic-metadata">

**Author:** [@Mark\_Campbell](https://discuss.elastic.co/u/Mark_Campbell)\
**Replies:** 1\
**Last updated:** [June 7, 2023, 1:24pm UTC](https://discuss.elastic.co/t/elastic-agent-custom-api-integration-get-next-url-from-json-response/335104 "2023-06-07T13:24:35Z")

</div>

I'm using ES, Kibana and Agent version 8.8.0. I can use the Custom API Integration to get the JSON response from the API. API URL: https://example.com/api/data/?page=1 JSON Response: { "data": \[ { "attri…

---

## [Compatibility rabbitmq 3.11.9 with metricbeat 7.17.6](https://discuss.elastic.co/t/compatibility-rabbitmq-3-11-9-with-metricbeat-7-17-6/334943)

<div class="topic-metadata">

**Author:** [@imaad](https://discuss.elastic.co/u/imaad)\
**Replies:** 1\
**Last updated:** [June 7, 2023, 1:17pm UTC](https://discuss.elastic.co/t/compatibility-rabbitmq-3-11-9-with-metricbeat-7-17-6/334943 "2023-06-07T13:17:50Z")

</div>

Hello, The metricbeat (v7.17.6) rabbitmq modules works fine with my rabbitMq 3.7.3. I plan to upgrade RabbitMQ to 3.11.9 version but I have faced a problem with the node module : ERROR module/wrapper.go:259 Error fetch…

---

## [Timeout on Kibana](https://discuss.elastic.co/t/timeout-on-kibana/334444)

<div class="topic-metadata">

**Author:** [@mihai.radulescu](https://discuss.elastic.co/u/mihai.radulescu)\
**Replies:** 8\
**Last updated:** [June 7, 2023, 12:01pm UTC](https://discuss.elastic.co/t/timeout-on-kibana/334444 "2023-06-07T12:01:00Z")

</div>

Hello, Getting this error on Kibana graph is I select the period higher than 5 days (probably too many datapoints): Tried increasing elasticsearch.requestTimeout: 900000 (and restarted kibana service) but this messa…

---

## [Schema Registry integration with Logstash kafka input plugin](https://discuss.elastic.co/t/schema-registry-integration-with-logstash-kafka-input-plugin/335431)

<div class="topic-metadata">

**Author:** [@Hemanth\_Gowda](https://discuss.elastic.co/u/Hemanth_Gowda)\
**Replies:** 0\
**Last updated:** [June 7, 2023, 10:41am UTC](https://discuss.elastic.co/t/schema-registry-integration-with-logstash-kafka-input-plugin/335431 "2023-06-07T10:41:34Z")

</div>

Hi All, We are trying to setup Kafka Schema registry integration with Logstash. However we have below questions to understand before we start with. Can someone please help with this. We have multiple dynamic schemas …

---

## [Auditbeat \>=8, logstash, and elasticsearch data stream](https://discuss.elastic.co/t/auditbeat-8-logstash-and-elasticsearch-data-stream/335357)

<div class="topic-metadata">

**Author:** [@Mike\_Williams](https://discuss.elastic.co/u/Mike_Williams)\
**Replies:** 2\
**Last updated:** [June 7, 2023, 9:37am UTC](https://discuss.elastic.co/t/auditbeat-8-logstash-and-elasticsearch-data-stream/335357 "2023-06-07T09:37:50Z")

</div>

Hey, I'm preparing to upgrade a set of auditbeat agents from 7.17 to 8.something. Clients are not allowed to talk directly to elasticsearch, all messages go through logstash. More than happy with the requirement to us…

---

## [Can't (yet) decode flowset id 256 from source id 0, because no template to decode it with has been received. This message will usually go away after 1 minute on logstash 7.17 and elasticsearch 7.17](https://discuss.elastic.co/t/cant-yet-decode-flowset-id-256-from-source-id-0-because-no-template-to-decode-it-with-has-been-received-this-message-will-usually-go-away-after-1-minute-on-logstash-7-17-and-elasticsearch-7-17/335421)

<div class="topic-metadata">

**Author:** [@Hanginium65](https://discuss.elastic.co/u/Hanginium65)\
**Replies:** 0\
**Last updated:** [June 7, 2023, 9:32am UTC](https://discuss.elastic.co/t/cant-yet-decode-flowset-id-256-from-source-id-0-because-no-template-to-decode-it-with-has-been-received-this-message-will-usually-go-away-after-1-minute-on-logstash-7-17-and-elasticsearch-7-17/335421 "2023-06-07T09:32:33Z")

</div>

Hi, my config file for logstash looks like this: input { snmp { hosts =\> \[{host =\> "udp:192.168.56.3/161" version =\> "3"}\] get =\> \["1.3.6.1.2.1.25.3.3.1.2.1", "1.3.6.1.2.1.25.2.3.1.5.65536", "1.3.6.1.2.1.25.2…

---

## [JDBC INPUT plugin not syncing all eligible records from postgres db to elasticsearch](https://discuss.elastic.co/t/jdbc-input-plugin-not-syncing-all-eligible-records-from-postgres-db-to-elasticsearch/335409)

<div class="topic-metadata">

**Author:** [@Gio\_Vanni](https://discuss.elastic.co/u/Gio_Vanni)\
**Replies:** 0\
**Last updated:** [June 7, 2023, 8:43am UTC](https://discuss.elastic.co/t/jdbc-input-plugin-not-syncing-all-eligible-records-from-postgres-db-to-elasticsearch/335409 "2023-06-07T08:43:00Z")

</div>

Hi I have an issue whereby logstash doesn't update all records that are returned by the jdbc-input query to Elasticsearch.As a result we always have to restart logstash to force through the updates. input plugin config: …

---

## [Can't get text on a START\_OBJECT at 1:34](https://discuss.elastic.co/t/cant-get-text-on-a-start-object-at-1-34/335399)

<div class="topic-metadata">

**Author:** [@hackercat](https://discuss.elastic.co/u/hackercat)\
**Replies:** 0\
**Last updated:** [June 7, 2023, 7:40am UTC](https://discuss.elastic.co/t/cant-get-text-on-a-start-object-at-1-34/335399 "2023-06-07T07:40:52Z")

</div>

Hi everyone, I recently upgraded ELK from 7 to 8 and it was working fine for v7, but since v8, it continuously gave me the below error. Jun 07 16:48:00 gitlab-logger logstash\[115245\]: \[2023-06-07T16:48:00,346\]\[WARN \]\[l…

---

## [How to run multiple geo\_distance filter to get result for each filter separately?](https://discuss.elastic.co/t/how-to-run-multiple-geo-distance-filter-to-get-result-for-each-filter-separately/335286)

<div class="topic-metadata">

**Author:** [@maulik\_trapasiya](https://discuss.elastic.co/u/maulik_trapasiya)\
**Replies:** 3\
**Last updated:** [June 7, 2023, 7:20am UTC](https://discuss.elastic.co/t/how-to-run-multiple-geo-distance-filter-to-get-result-for-each-filter-separately/335286 "2023-06-07T07:20:13Z")

</div>

I need result documents based on geo\_distance query for points A(lat=3,long=101) and B(lat=5,long=102) separately. one result docs I need corresponding to filter A(lat=3,long=101) and other result set I need correspondin…

---

## [Infrarelated query](https://discuss.elastic.co/t/infrarelated-query/335291)

<div class="topic-metadata">

**Author:** [@TECHY\_GEEK](https://discuss.elastic.co/u/TECHY_GEEK)\
**Replies:** 2\
**Last updated:** [June 7, 2023, 7:07am UTC](https://discuss.elastic.co/t/infrarelated-query/335291 "2023-06-07T07:07:58Z")

</div>

Hi there! Actually we want to apply SIEM and SOAR in our organization . we have 100+ servers and want to monitor each one of them. so could anyone tell me about how much specifications we required for that. and yes we d…

---

## [Apple M1 Ultra chip computer with elastic agent installed,.Approved Elastic Endpoint's web content filtering, resulting in network disconnection](https://discuss.elastic.co/t/apple-m1-ultra-chip-computer-with-elastic-agent-installed-approved-elastic-endpoints-web-content-filtering-resulting-in-network-disconnection/333739)

<div class="topic-metadata">

**Author:** [@xqaiviwjxzw](https://discuss.elastic.co/u/xqaiviwjxzw)\
**Replies:** 4\
**Last updated:** [June 7, 2023, 6:36am UTC](https://discuss.elastic.co/t/apple-m1-ultra-chip-computer-with-elastic-agent-installed-approved-elastic-endpoints-web-content-filtering-resulting-in-network-disconnection/333739 "2023-06-07T06:36:40Z")

</div>

I tried to install resilient agent 8.4.1 and 8.7.1 on a chip:Apple M1 Ultra mac, after approving the network content filtering of the resilient endpoint, the computer was disconnected and could not use the wifi networ…

---

## [How to create sequence rules?](https://discuss.elastic.co/t/how-to-create-sequence-rules/335390)

<div class="topic-metadata">

**Author:** [@VellayLoket](https://discuss.elastic.co/u/VellayLoket)\
**Replies:** 0\
**Last updated:** [June 7, 2023, 4:39am UTC](https://discuss.elastic.co/t/how-to-create-sequence-rules/335390 "2023-06-07T04:39:52Z")

</div>

So, i want to create the sequence rules to aggregate the same events to one alert. For example i have event from IDS system where i have fields like: client.ip cs1 - the category name ("malware activity" or smth like …

[Previous page](https://discuss.elastic.co/tag/none.md?no_tags=true&page=363)

[Next page](https://discuss.elastic.co/tag/none.md?no_tags=true&page=365)
