# \#none

**URL:** https://discuss.elastic.co/tag/none.md?no_tags=true&page=366

[Latest](https://discuss.elastic.co/latest.md) · [Categories](https://discuss.elastic.co/categories.md) · [Tags](https://discuss.elastic.co/tags.md)

**Page:** 367

---

## [How to calculate percentage of a field over all documents present in index](https://discuss.elastic.co/t/how-to-calculate-percentage-of-a-field-over-all-documents-present-in-index/334544)

<div class="topic-metadata">

**Author:** [@Amit\_Charkha](https://discuss.elastic.co/u/Amit_Charkha)\
**Replies:** 5\
**Last updated:** [June 6, 2023, 4:54am UTC](https://discuss.elastic.co/t/how-to-calculate-percentage-of-a-field-over-all-documents-present-in-index/334544 "2023-06-06T04:54:48Z")

</div>

how to calculate percentage of a field log\_count over all documents present in index.

---

## [There is a problem with elastic agent pushing logstash](https://discuss.elastic.co/t/there-is-a-problem-with-elastic-agent-pushing-logstash/335265)

<div class="topic-metadata">

**Author:** [@xqaiviwjxzw](https://discuss.elastic.co/u/xqaiviwjxzw)\
**Replies:** 0\
**Last updated:** [June 6, 2023, 4:49am UTC](https://discuss.elastic.co/t/there-is-a-problem-with-elastic-agent-pushing-logstash/335265 "2023-06-06T04:49:20Z")

</div>

By changing the original strategy of the elastic agent to push the log to Elasticsearch to push to the new strategy to push to logstash, why the log is still in the original Elasticsearch, but not pushed to the new lo…

---

## [Indexing requests and time goes high on 1 node in cluster](https://discuss.elastic.co/t/indexing-requests-and-time-goes-high-on-1-node-in-cluster/334491)

<div class="topic-metadata">

**Author:** [@tarund](https://discuss.elastic.co/u/tarund)\
**Replies:** 1\
**Last updated:** [June 6, 2023, 4:28am UTC](https://discuss.elastic.co/t/indexing-requests-and-time-goes-high-on-1-node-in-cluster/334491 "2023-06-06T04:28:49Z")

</div>

Hi Team I am using ES 7.17.1. Pushing logs from Fluent to 5 node cluster. Enabled xpack monitoring on ES. we observe that sometime during the day the indexing requests & indexing time goes very high on a single node. So…

---

## [TLS error after fresh install of elastic search](https://discuss.elastic.co/t/tls-error-after-fresh-install-of-elastic-search/335264)

<div class="topic-metadata">

**Author:** [@antarr](https://discuss.elastic.co/u/antarr)\
**Replies:** 3\
**Last updated:** [June 6, 2023, 2:36am UTC](https://discuss.elastic.co/t/tls-error-after-fresh-install-of-elastic-search/335264 "2023-06-06T02:36:34Z")

</div>

I'm trying to get Elasticsearch working on Ubuntu 22. I've uninstalled it a few times but keep getting an SSL error when testing using curl. I've tried 7.17, 7.10, and 8.8. uninstall sudo apt-get remove --purge elastic…

---

## [Push Logs from Elastic Search to Alien Vault USM Anywhere](https://discuss.elastic.co/t/push-logs-from-elastic-search-to-alien-vault-usm-anywhere/334781)

<div class="topic-metadata">

**Author:** [@Zu\_kun](https://discuss.elastic.co/u/Zu_kun)\
**Replies:** 4\
**Last updated:** [June 6, 2023, 2:16am UTC](https://discuss.elastic.co/t/push-logs-from-elastic-search-to-alien-vault-usm-anywhere/334781 "2023-06-06T02:16:58Z")

</div>

Hi, I'm a legit noob when it comes to ELK so my questions might not make sense or will probably have some obvious answers to it. Getting straight to the point, I want to pull the logs from my on premises Elasticsearch …

---

## [Dynamic data (no code) scenario strategy](https://discuss.elastic.co/t/dynamic-data-no-code-scenario-strategy/334870)

<div class="topic-metadata">

**Author:** [@Zak\_Sesti](https://discuss.elastic.co/u/Zak_Sesti)\
**Replies:** 1\
**Last updated:** [June 6, 2023, 1:38am UTC](https://discuss.elastic.co/t/dynamic-data-no-code-scenario-strategy/334870 "2023-06-06T01:38:52Z")

</div>

I use ES for searching of my basic CRUD constructs. But now we need to expand to help us search, sort, paginate our no-code constructs. These are json documents that have 100% dynamic fields. Some rough numbers: We …

---

## [Integration Elastic Security with Microsoft Sentinel available?](https://discuss.elastic.co/t/integration-elastic-security-with-microsoft-sentinel-available/335025)

<div class="topic-metadata">

**Author:** [@Jeronimodus](https://discuss.elastic.co/u/Jeronimodus)\
**Replies:** 6\
**Last updated:** [June 6, 2023, 1:20am UTC](https://discuss.elastic.co/t/integration-elastic-security-with-microsoft-sentinel-available/335025 "2023-06-06T01:20:39Z")

</div>

Hello all, I am looking for a way to import alerts and possibly more data from Sentinel into Elastic Security. I do not see an integration available for this. Is there someone who can confirm that this does not exist an…

---

## [Profile API](https://discuss.elastic.co/t/profile-api/335217)

<div class="topic-metadata">

**Author:** [@searchwithme](https://discuss.elastic.co/u/searchwithme)\
**Replies:** 1\
**Last updated:** [June 6, 2023, 1:06am UTC](https://discuss.elastic.co/t/profile-api/335217 "2023-06-06T01:06:58Z")

</div>

I ran the profile API for my query that took 15s to run. I have a very big json as output. I am unable to determine why it is taking 15s. Can someone help me read or what to look for in the output of \_profile?

---

## [Does it use more storage with "fields" mapping?](https://discuss.elastic.co/t/does-it-use-more-storage-with-fields-mapping/334883)

<div class="topic-metadata">

**Author:** [@linkerc](https://discuss.elastic.co/u/linkerc)\
**Replies:** 4\
**Last updated:** [June 5, 2023, 6:43pm UTC](https://discuss.elastic.co/t/does-it-use-more-storage-with-fields-mapping/334883 "2023-06-05T18:43:22Z")

</div>

"some\_label" : { "type" : "keyword", "fields" : { "keyword" : { "type" : "keyword", "ignore\_above" : 256 } } } Supposed I have a …

---

## [Help optimize my query](https://discuss.elastic.co/t/help-optimize-my-query/335250)

<div class="topic-metadata">

**Author:** [@searchwithme](https://discuss.elastic.co/u/searchwithme)\
**Replies:** 1\
**Last updated:** [June 5, 2023, 5:44pm UTC](https://discuss.elastic.co/t/help-optimize-my-query/335250 "2023-06-05T17:44:52Z")

</div>

I have this query: "query": { "bool": { "filter": { "bool": { "must": \[ { "range": { "movies-date": { "gt": "2018", "lt": "2022" } } }, given that this is a must query, does it make sense to move the range …

---

## [Log4j2 vulnerability mitigation](https://discuss.elastic.co/t/log4j2-vulnerability-mitigation/335213)

<div class="topic-metadata">

**Author:** [@mostafaelsayed](https://discuss.elastic.co/u/mostafaelsayed)\
**Replies:** 6\
**Last updated:** [June 5, 2023, 3:33pm UTC](https://discuss.elastic.co/t/log4j2-vulnerability-mitigation/335213 "2023-06-05T15:33:18Z")

</div>

Hello all, I was checking the actions needed from our side in the ELK cluster to mitigate the Log4j2 vulnerability found in Dec 2021. we are using 7.9.2 for all ELK components. After investigating and checking the below…

---

## [Considering using L4 or kafka](https://discuss.elastic.co/t/considering-using-l4-or-kafka/335238)

<div class="topic-metadata">

**Author:** [@a01066278824](https://discuss.elastic.co/u/a01066278824)\
**Replies:** 1\
**Last updated:** [June 5, 2023, 3:15pm UTC](https://discuss.elastic.co/t/considering-using-l4-or-kafka/335238 "2023-06-05T15:15:30Z")

</div>

im considering two ways. first, using L4 between Beats and logstash. second, using Kafka between beats and logstahs. which way is more effective one? and im wondering if is it possible Beats - Kafka - L4 - Logstash. …

---

## [iIhave problems Fleet daemonset collect kubernetes container logs](https://discuss.elastic.co/t/iihave-problems-fleet-daemonset-collect-kubernetes-container-logs/335239)

<div class="topic-metadata">

**Author:** [@hanhee](https://discuss.elastic.co/u/hanhee)\
**Replies:** 0\
**Last updated:** [June 5, 2023, 3:10pm UTC](https://discuss.elastic.co/t/iihave-problems-fleet-daemonset-collect-kubernetes-container-logs/335239 "2023-06-05T15:10:11Z")

</div>

hello i have some problems operating elastic-agent with fleet i did the settings elastic-agent usging kubernetes daemonset and kubernetes integration in fleet and that setting works normally without problems but sud…

---

## [Using Environment Variables in Elastic Synthetics](https://discuss.elastic.co/t/using-environment-variables-in-elastic-synthetics/334997)

<div class="topic-metadata">

**Author:** [@DougR](https://discuss.elastic.co/u/DougR)\
**Replies:** 8\
**Last updated:** [June 5, 2023, 1:40pm UTC](https://discuss.elastic.co/t/using-environment-variables-in-elastic-synthetics/334997 "2023-06-05T13:40:50Z")

</div>

TL;DR How do I force Elastic Synthetics to use environment variables defined in the pod environment? Use Case I am in the process of migrating our synthetic monitoring framework to Elastic Synthetics. I'm currently usin…

---

## [How to change Data type Runtime and change filter type range slider to dropdown list](https://discuss.elastic.co/t/how-to-change-data-type-runtime-and-change-filter-type-range-slider-to-dropdown-list/335179)

<div class="topic-metadata">

**Author:** [@PappuSingh](https://discuss.elastic.co/u/PappuSingh)\
**Replies:** 1\
**Last updated:** [June 5, 2023, 2:15pm UTC](https://discuss.elastic.co/t/how-to-change-data-type-runtime-and-change-filter-type-range-slider-to-dropdown-list/335179 "2023-06-05T14:15:55Z")

</div>

Hi, How to change data type long to String and Range slider to the dropdown list. Please find attached a snap for your reference.

---

## [What's the efficient way to filter and transfer data from Elastic](https://discuss.elastic.co/t/whats-the-efficient-way-to-filter-and-transfer-data-from-elastic/335006)

<div class="topic-metadata">

**Author:** [@Monkey\_D\_Luffy1](https://discuss.elastic.co/u/Monkey_D_Luffy1)\
**Replies:** 1\
**Last updated:** [June 5, 2023, 1:23pm UTC](https://discuss.elastic.co/t/whats-the-efficient-way-to-filter-and-transfer-data-from-elastic/335006 "2023-06-05T13:23:43Z")

</div>

I have an Elastic Index which has 100 million documents inside it and I want to understand whats the efficient way of writing a python script to filter values and then transfer the filtered values to a SQL storage ?

---

## [How to encode the aggregation response and get doc by id response values in Elasticsearch 7.17.x](https://discuss.elastic.co/t/how-to-encode-the-aggregation-response-and-get-doc-by-id-response-values-in-elasticsearch-7-17-x/335220)

<div class="topic-metadata">

**Author:** [@Karunakaran-ti](https://discuss.elastic.co/u/Karunakaran-ti)\
**Replies:** 0\
**Last updated:** [June 5, 2023, 1:05pm UTC](https://discuss.elastic.co/t/how-to-encode-the-aggregation-response-and-get-doc-by-id-response-values-in-elasticsearch-7-17-x/335220 "2023-06-05T13:05:27Z")

</div>

I am writing a custom Elasticsearch plugin. I want to do encode the response values from aggregation response and get doc by id. Using Elasticsearch v7.17.x I want to know what are interface/classes to be used from Ela…

---

## [Filtering with nested query inner\_hits count](https://discuss.elastic.co/t/filtering-with-nested-query-inner-hits-count/335202)

<div class="topic-metadata">

**Author:** [@LaySoft](https://discuss.elastic.co/u/LaySoft)\
**Replies:** 0\
**Last updated:** [June 5, 2023, 10:08am UTC](https://discuss.elastic.co/t/filtering-with-nested-query-inner-hits-count/335202 "2023-06-05T10:08:26Z")

</div>

I have the following query: "query": { "nested": { "path": "cuccok", "inner\_hits": {}, "query": { "bool": { "must": \[ …

---

## [Highlight in the field response](https://discuss.elastic.co/t/highlight-in-the-field-response/334955)

<div class="topic-metadata">

**Author:** [@Kirtash](https://discuss.elastic.co/u/Kirtash)\
**Replies:** 3\
**Last updated:** [June 5, 2023, 10:07am UTC](https://discuss.elastic.co/t/highlight-in-the-field-response/334955 "2023-06-05T10:07:24Z")

</div>

Good morning, I have an application that read the results from my query in elasticsearch and I take all the fields of the response and after it, I put it in a windows form for the user. Now I would like remark the part…

---

## [Enriching data with ProxyIP database](https://discuss.elastic.co/t/enriching-data-with-proxyip-database/335169)

<div class="topic-metadata">

**Author:** [@Hitz2403](https://discuss.elastic.co/u/Hitz2403)\
**Replies:** 5\
**Last updated:** [June 5, 2023, 8:50am UTC](https://discuss.elastic.co/t/enriching-data-with-proxyip-database/335169 "2023-06-05T08:50:40Z")

</div>

Hi everyone, I need help enriching data with IP Proxy database like geoip plugin, has anyone done this before? Docs or something can help?

---

## [ECK cachce issue](https://discuss.elastic.co/t/eck-cachce-issue/335189)

<div class="topic-metadata">

**Author:** [@Rick\_Vailer](https://discuss.elastic.co/u/Rick_Vailer)\
**Replies:** 0\
**Last updated:** [June 5, 2023, 7:41am UTC](https://discuss.elastic.co/t/eck-cachce-issue/335189 "2023-06-05T07:41:34Z")

</div>

Hello, We are experiencing these issues on our ECK instance running 5 concurrent pods, sporadically some pods stop and change to a crashloopbackoff state with the below errors. We are mounting the plugin cache folder a…

---

## [Is context.hits supported on 8.1](https://discuss.elastic.co/t/is-context-hits-supported-on-8-1/334105)

<div class="topic-metadata">

**Author:** [@nitisha](https://discuss.elastic.co/u/nitisha)\
**Replies:** 0\
**Last updated:** [May 23, 2023, 10:39am UTC](https://discuss.elastic.co/t/is-context-hits-supported-on-8-1/334105 "2023-05-23T10:39:20Z")

</div>

Hi Team, Is context.hits supported on kibana version 8.1? I am using "Rules and Connectors" type as "Inventory" to monitor CPU metric threshold. With the default action rule {{alertName}} - {{context.group}} is in a st…

---

## [How to use custom field as control filter with values](https://discuss.elastic.co/t/how-to-use-custom-field-as-control-filter-with-values/334077)

<div class="topic-metadata">

**Author:** [@PappuSingh](https://discuss.elastic.co/u/PappuSingh)\
**Replies:** 2\
**Last updated:** [June 5, 2023, 5:00am UTC](https://discuss.elastic.co/t/how-to-use-custom-field-as-control-filter-with-values/334077 "2023-06-05T05:00:20Z")

</div>

Hi, We have created a custom field and we want to use this field as a control filter but not fill the values under the Control filter, please see the attached snap for your reference.

---

## [Elasticsearch killed by oom-killer](https://discuss.elastic.co/t/elasticsearch-killed-by-oom-killer/334982)

<div class="topic-metadata">

**Author:** [@Andy\_Ni](https://discuss.elastic.co/u/Andy_Ni)\
**Replies:** 5\
**Last updated:** [June 5, 2023, 3:27am UTC](https://discuss.elastic.co/t/elasticsearch-killed-by-oom-killer/334982 "2023-06-05T03:27:33Z")

</div>

Elasticsearch version: 6.2.3 System: \[root@my-host-name\]# uname -s -r -v -m -p -i -o Linux 5.4.8-1.el7.elrepo.x86\_64 #1 SMP Sat Jan 4 15:29:03 EST 2020 x86\_64 x86\_64 x86\_64 GNU/Linux ErrorMessage in /var/log/message: …

---

## [Not able to create index patterns as kibana is not getting the indices](https://discuss.elastic.co/t/not-able-to-create-index-patterns-as-kibana-is-not-getting-the-indices/334565)

<div class="topic-metadata">

**Author:** [@kirankumarb](https://discuss.elastic.co/u/kirankumarb)\
**Replies:** 15\
**Last updated:** [June 5, 2023, 1:23am UTC](https://discuss.elastic.co/t/not-able-to-create-index-patterns-as-kibana-is-not-getting-the-indices/334565 "2023-06-05T01:23:30Z")

</div>

\-I am getting indices for most of services, but unable to get indices for few services. So I am unable to create index patterns. We are getting logs in servers but unable to see logs in Kibana dashboard. \_Filebeat is up…

---

## [how geo\_distance query works under the hood in Elasticsearch?](https://discuss.elastic.co/t/how-geo-distance-query-works-under-the-hood-in-elasticsearch/335154)

<div class="topic-metadata">

**Author:** [@maulik\_trapasiya](https://discuss.elastic.co/u/maulik_trapasiya)\
**Replies:** 1\
**Last updated:** [June 4, 2023, 8:38pm UTC](https://discuss.elastic.co/t/how-geo-distance-query-works-under-the-hood-in-elasticsearch/335154 "2023-06-04T20:38:32Z")

</div>

I need to use geo\_distance query on Elasticsearch. Need info about how it works under the hood and what is latency? I am not able to find any doc relevant to this. please help

---

## [Unable to restart the nginx service](https://discuss.elastic.co/t/unable-to-restart-the-nginx-service/335170)

<div class="topic-metadata">

**Author:** [@surajhekare](https://discuss.elastic.co/u/surajhekare)\
**Replies:** 1\
**Last updated:** [June 4, 2023, 7:48pm UTC](https://discuss.elastic.co/t/unable-to-restart-the-nginx-service/335170 "2023-06-04T19:48:02Z")

</div>

ubuntu@ip-172-31-37-106:~$ sudo service nginx restart Job for nginx.service failed because the control process exited with error code. See "systemctl status nginx.service" and "journalctl -xe" for details. systemctl s…

---

## [Elastic Cluster Architecture Best Practices](https://discuss.elastic.co/t/elastic-cluster-architecture-best-practices/335138)

<div class="topic-metadata">

**Author:** [@A.Hani](https://discuss.elastic.co/u/A.Hani)\
**Replies:** 5\
**Last updated:** [June 4, 2023, 4:57am UTC](https://discuss.elastic.co/t/elastic-cluster-architecture-best-practices/335138 "2023-06-04T04:57:20Z")

</div>

Hi all, I have an upcoming project to set up a small cluster and thought would use the community help to validate the design scenario that I have in mind. A little background about available resources for that project: …

---

## [Failed to start Elasticsearch](https://discuss.elastic.co/t/failed-to-start-elasticsearch/335146)

<div class="topic-metadata">

**Author:** [@surajhekare](https://discuss.elastic.co/u/surajhekare)\
**Replies:** 2\
**Last updated:** [June 4, 2023, 4:36am UTC](https://discuss.elastic.co/t/failed-to-start-elasticsearch/335146 "2023-06-04T04:36:10Z")

</div>

ubuntu@ip-172-31-37-106:~$ systemctl status elasticsearch.service ● elasticsearch.service - Elasticsearch Loaded: loaded (/lib/systemd/system/elasticsearch.service; disabled; vendor preset: enabled) Active: failed (Re…

---

## [Logstash giving error which is not clear](https://discuss.elastic.co/t/logstash-giving-error-which-is-not-clear/335126)

<div class="topic-metadata">

**Author:** [@Patr123](https://discuss.elastic.co/u/Patr123)\
**Replies:** 7\
**Last updated:** [June 3, 2023, 7:06pm UTC](https://discuss.elastic.co/t/logstash-giving-error-which-is-not-clear/335126 "2023-06-03T19:06:59Z")

</div>

I am getting the following error in logstash-plain.log: \[2023-06-03T01:33:34,256\]\[INFO \]\[logstash.runner \] Log4j configuration path used is: /etc/logstash/log4j2.properties \[2023-06-03T01:33:34,272\]\[INFO \]\[logs…

[Previous page](https://discuss.elastic.co/tag/none.md?no_tags=true&page=365)

[Next page](https://discuss.elastic.co/tag/none.md?no_tags=true&page=367)
