# \#none

**URL:** https://discuss.elastic.co/tag/none.md?no_tags=true&page=367

[Latest](https://discuss.elastic.co/latest.md) · [Categories](https://discuss.elastic.co/categories.md) · [Tags](https://discuss.elastic.co/tags.md)

**Page:** 368

---

## [Synonyms and semantic search](https://discuss.elastic.co/t/synonyms-and-semantic-search/334880)

<div class="topic-metadata">

**Author:** [@Rahul\_Agarwal1](https://discuss.elastic.co/u/Rahul_Agarwal1)\
**Replies:** 2\
**Last updated:** [June 3, 2023, 5:37pm UTC](https://discuss.elastic.co/t/synonyms-and-semantic-search/334880 "2023-06-03T17:37:02Z")

</div>

Need your help with one more thing. What is the best way to support synonyms (we have our own custom list) with semantic search?? Couldn't find anything related to this in the documentation.

---

## [Alerts not appearing after 8.5.2 \> 8.8.0 upgrade](https://discuss.elastic.co/t/alerts-not-appearing-after-8-5-2-8-8-0-upgrade/335136)

<div class="topic-metadata">

**Author:** [@bfarren240](https://discuss.elastic.co/u/bfarren240)\
**Replies:** 0\
**Last updated:** [June 3, 2023, 3:23pm UTC](https://discuss.elastic.co/t/alerts-not-appearing-after-8-5-2-8-8-0-upgrade/335136 "2023-06-03T15:23:42Z")

</div>

I noticed that alerts are no longer appearing in the Security \> Alerts view after a 8.5.2 \> 8.8.0 upgrade. The noisy 'Component Object Model Hijacking' rule is no longer appearing during the usual browser upgrades, and …

---

## [Highlighting and text\_expansion query](https://discuss.elastic.co/t/highlighting-and-text-expansion-query/334679)

<div class="topic-metadata">

**Author:** [@Mark\_Harwood1](https://discuss.elastic.co/u/Mark_Harwood1)\
**Replies:** 2\
**Last updated:** [June 3, 2023, 2:04pm UTC](https://discuss.elastic.co/t/highlighting-and-text-expansion-query/334679 "2023-06-03T14:04:54Z")

</div>

Playing with the new ELSER model and the text\_expansion query in 8.8 which looks to be matching OK. Now I want end users to understand why documents matched but can't get highlighting to work. Does it? I've tried settin…

---

## [Grouping And Ordering Log is Posible?](https://discuss.elastic.co/t/grouping-and-ordering-log-is-posible/335017)

<div class="topic-metadata">

**Author:** [@aidensV](https://discuss.elastic.co/u/aidensV)\
**Replies:** 2\
**Last updated:** [June 3, 2023, 1:11pm UTC](https://discuss.elastic.co/t/grouping-and-ordering-log-is-posible/335017 "2023-06-03T13:11:30Z")

</div>

I have Log with example : (Case 1) CHAN1 : 23:57:05:89 |Message Start CHAN1 : 23:57:05:89 |Lorem CHAN1 : 23:57:05:89 |Ipsum CHAN1 : 23:57:05:89 |Dolor CHAN99i : 23:57:05:89 |Message Start CHAN99i : 23:57:05:89 |Lo…

---

## [ No config files found in path {:path=\>"/etc/logstash/conf.d/\*.conf"}](https://discuss.elastic.co/t/no-config-files-found-in-path-path-etc-logstash-conf-d-conf/335106)

<div class="topic-metadata">

**Author:** [@karma\_services](https://discuss.elastic.co/u/karma_services)\
**Replies:** 1\
**Last updated:** [June 3, 2023, 5:28am UTC](https://discuss.elastic.co/t/no-config-files-found-in-path-path-etc-logstash-conf-d-conf/335106 "2023-06-03T05:28:55Z")

</div>

I have installed ELK stack via debian package on Ubuntu Server. I want to send pfsense logs to logstash. File Settings: 1- /etc/logstash/conf.d/syslog.conf input { tcp { port =\> 514 type =\> "pfsense" } udp { …

---

## [LDAP/AD Configuration - w/o GOLD License](https://discuss.elastic.co/t/ldap-ad-configuration-w-o-gold-license/335116)

<div class="topic-metadata">

**Author:** [@mreed](https://discuss.elastic.co/u/mreed)\
**Replies:** 0\
**Last updated:** [June 2, 2023, 6:40pm UTC](https://discuss.elastic.co/t/ldap-ad-configuration-w-o-gold-license/335116 "2023-06-02T18:40:15Z")

</div>

Hello all, My apologies if this is a long post. I'm looking for some advice around integrating LDAP (Active Directory) logins via Kibana using a basic license (unfortunately we can't afford to pay for the Gold license …

---

## [Bulk Indexing of signals failed: object mapping for \[host\] tried to parse field \[host\] as object, but found a concrete value name](https://discuss.elastic.co/t/bulk-indexing-of-signals-failed-object-mapping-for-host-tried-to-parse-field-host-as-object-but-found-a-concrete-value-name/334705)

<div class="topic-metadata">

**Author:** [@UP\_NEWS](https://discuss.elastic.co/u/UP_NEWS)\
**Replies:** 1\
**Last updated:** [June 2, 2023, 3:53pm UTC](https://discuss.elastic.co/t/bulk-indexing-of-signals-failed-object-mapping-for-host-tried-to-parse-field-host-as-object-but-found-a-concrete-value-name/334705 "2023-06-02T15:53:18Z")

</div>

Hi team, the parser used for Kaspersky, more precisely in the host field, does not allow the triggering of the rule relating to the detection of malicious files once the conditions are met.

---

## [Kibana8.8.0 error with 'guidedOnboarding'](https://discuss.elastic.co/t/kibana8-8-0-error-with-guidedonboarding/334700)

<div class="topic-metadata">

**Author:** [@jiwon](https://discuss.elastic.co/u/jiwon)\
**Replies:** 3\
**Last updated:** [June 2, 2023, 2:59pm UTC](https://discuss.elastic.co/t/kibana8-8-0-error-with-guidedonboarding/334700 "2023-06-02T14:59:46Z")

</div>

hello :slight\_smile: I just installed Elasticsearch and Kibana. but I have some problem. I opened Kibana web browser to get started. And I input my enrollment token, username and password. enrollment token, username …

---

## [Finding user\_message index pattern for Elastic Certified Analyst Exam](https://discuss.elastic.co/t/finding-user-message-index-pattern-for-elastic-certified-analyst-exam/333380)

<div class="topic-metadata">

**Author:** [@StratCharl](https://discuss.elastic.co/u/StratCharl)\
**Replies:** 0\
**Last updated:** [May 14, 2023, 12:50pm UTC](https://discuss.elastic.co/t/finding-user-message-index-pattern-for-elastic-certified-analyst-exam/333380 "2023-05-14T12:50:36Z")

</div>

Hello, I have started the Elastic Certified Analyst Exam and am required to use the user\_message index pattern. However I cannot find it / how to add it. Any help would be appreciated on how to continue.

---

## [Problem with login after upgrading to 8.8.0](https://discuss.elastic.co/t/problem-with-login-after-upgrading-to-8-8-0/335083)

<div class="topic-metadata">

**Author:** [@ccaillet](https://discuss.elastic.co/u/ccaillet)\
**Replies:** 1\
**Last updated:** [June 2, 2023, 2:40pm UTC](https://discuss.elastic.co/t/problem-with-login-after-upgrading-to-8-8-0/335083 "2023-06-02T14:40:30Z")

</div>

Hi all, I've upgrade a cluster from 8.7.1 to 8.8.0 it's a small cluster with 3 nodes and two kibana instances. All is working well until the upgrade to 8.8.0. Globally no error during upgrade BUT unable to log in throug…

---

## [How to size the ELK platform for on-premise setup / on-cloud setup](https://discuss.elastic.co/t/how-to-size-the-elk-platform-for-on-premise-setup-on-cloud-setup/335048)

<div class="topic-metadata">

**Author:** [@shpankaj](https://discuss.elastic.co/u/shpankaj)\
**Replies:** 1\
**Last updated:** [June 2, 2023, 1:45pm UTC](https://discuss.elastic.co/t/how-to-size-the-elk-platform-for-on-premise-setup-on-cloud-setup/335048 "2023-06-02T13:45:12Z")

</div>

We have to ingest logs and analyze as part of SOC services covering 100 windows 10 / 11 endpoints, 2 FortiGate F100 firewall, 20 Windows servers, 20 managed network switches of 24 ports, 120 EDR - sentinelOne. What shou…

---

## [Logstash unable to parse specific format of log](https://discuss.elastic.co/t/logstash-unable-to-parse-specific-format-of-log/334815)

<div class="topic-metadata">

**Author:** [@SmoZyNS](https://discuss.elastic.co/u/SmoZyNS)\
**Replies:** 11\
**Last updated:** [June 2, 2023, 1:35pm UTC](https://discuss.elastic.co/t/logstash-unable-to-parse-specific-format-of-log/334815 "2023-06-02T13:35:33Z")

</div>

Hello I am looking for some help since getting some headaches when trying to parse some logs Raw logs cs1Label=username cs1=/test@test.com cn1Label=actionSuccess cn1=1 deviceCustomDate1Label=userActionTime deviceCusto…

---

## [Help with creating a Logstash configuration file for Postfix log analysis](https://discuss.elastic.co/t/help-with-creating-a-logstash-configuration-file-for-postfix-log-analysis/335078)

<div class="topic-metadata">

**Author:** [@Aleksandr\_Terekhov](https://discuss.elastic.co/u/Aleksandr_Terekhov)\
**Replies:** 0\
**Last updated:** [June 2, 2023, 12:38pm UTC](https://discuss.elastic.co/t/help-with-creating-a-logstash-configuration-file-for-postfix-log-analysis/335078 "2023-06-02T12:38:59Z")

</div>

Hello everybody Can someone help to correctly create a configuration file that will display the fields from the postfix log that from status Message-id in Kiban in one line and not as in the screenshot I will be g…

---

## [LogStash::Json::ParserError: Unexpected end-of-input: expected close marker for Array](https://discuss.elastic.co/t/logstash-unexpected-end-of-input-expected-close-marker-for-array/335071)

<div class="topic-metadata">

**Author:** [@niveditakathal](https://discuss.elastic.co/u/niveditakathal)\
**Replies:** 0\
**Last updated:** [June 2, 2023, 10:54am UTC](https://discuss.elastic.co/t/logstash-unexpected-end-of-input-expected-close-marker-for-array/335071 "2023-06-02T10:54:46Z")

</div>

Hi Experts, I want to ingest data from a text file (refer data.txt) to elastic using logstash and in order to achieve it, I have created the logstash.conf file as mentioned below - logstash.conf - input { file { …

---

## [Query\_string search exact phrase causes performance issues](https://discuss.elastic.co/t/query-string-search-exact-phrase-causes-performance-issues/335055)

<div class="topic-metadata">

**Author:** [@Sandeep\_Raju](https://discuss.elastic.co/u/Sandeep_Raju)\
**Replies:** 3\
**Last updated:** [June 2, 2023, 10:44am UTC](https://discuss.elastic.co/t/query-string-search-exact-phrase-causes-performance-issues/335055 "2023-06-02T10:44:22Z")

</div>

Hi all, When I make query\_string search exact phrase in Elasticsearch, POST /myindex\_\*/\_search { "query": { "query\_string": { "query": "\\"Classe A\\"" } } The query is run and shows hits, but sho…

---

## [Elastic Stack 8.3.3 - config changes fails](https://discuss.elastic.co/t/elastic-stack-8-3-3-config-changes-fails/334969)

<div class="topic-metadata">

**Author:** [@afmin](https://discuss.elastic.co/u/afmin)\
**Replies:** 1\
**Last updated:** [June 2, 2023, 10:10am UTC](https://discuss.elastic.co/t/elastic-stack-8-3-3-config-changes-fails/334969 "2023-06-02T10:10:19Z")

</div>

Hi I am trying to increase my Master Nodes with more diskspace. The two nodes are used with 82 and 83% diskspace. When I try an config change from 1 to 2 availability zones it fails by the step "Calling Elasticsearch no…

---

## [Elasticsearch performance in HDD vs SSD and 32 GB vs 64 GB of RAM](https://discuss.elastic.co/t/elasticsearch-performance-in-hdd-vs-ssd-and-32-gb-vs-64-gb-of-ram/334622)

<div class="topic-metadata">

**Author:** [@Don\_Boscow](https://discuss.elastic.co/u/Don_Boscow)\
**Replies:** 24\
**Last updated:** [June 2, 2023, 9:47am UTC](https://discuss.elastic.co/t/elasticsearch-performance-in-hdd-vs-ssd-and-32-gb-vs-64-gb-of-ram/334622 "2023-06-02T09:47:22Z")

</div>

I understand from what I have read that ES works best in conjunction with a sweet spot of 64 GB RAM per node and a fair bit of SSD (3-4 TB per node, with multiple shards in each node to handle primary copies and replicas…

---

## [There is a problem with elastic agent pushing logstash](https://discuss.elastic.co/t/there-is-a-problem-with-elastic-agent-pushing-logstash/335063)

<div class="topic-metadata">

**Author:** [@xqaiviwjxzw](https://discuss.elastic.co/u/xqaiviwjxzw)\
**Replies:** 0\
**Last updated:** [June 2, 2023, 9:13am UTC](https://discuss.elastic.co/t/there-is-a-problem-with-elastic-agent-pushing-logstash/335063 "2023-06-02T09:13:29Z")

</div>

By changing the original strategy of the elastic agent to push the log to Elasticsearch to push to the new strategy to push to logstash, why the log is still in the original Elasticsearch, but not pushed to the new lo…

---

## [How to remove low correlation results?](https://discuss.elastic.co/t/how-to-remove-low-correlation-results/335056)

<div class="topic-metadata">

**Author:** [@Jinnrry](https://discuss.elastic.co/u/Jinnrry)\
**Replies:** 0\
**Last updated:** [June 2, 2023, 8:31am UTC](https://discuss.elastic.co/t/how-to-remove-low-correlation-results/335056 "2023-06-02T08:31:03Z")

</div>

I want to be able to filter my search results for less relevant results. So I use the min\_score for filtering. like this: GET xxx/\_search { "min\_score": 2.8, "query": { "match": { "xxx": "xxxx" } }…

---

## [Open source community](https://discuss.elastic.co/t/open-source-community/335051)

<div class="topic-metadata">

**Author:** [@Open\_source\_Advocate](https://discuss.elastic.co/u/Open_source_Advocate)\
**Replies:** 4\
**Last updated:** [June 2, 2023, 7:44am UTC](https://discuss.elastic.co/t/open-source-community/335051 "2023-06-02T07:44:07Z")

</div>

Where can I host a community survey to get input from community members?

---

## [Help with Grok (syntax issue as well as question regarding double quotes)](https://discuss.elastic.co/t/help-with-grok-syntax-issue-as-well-as-question-regarding-double-quotes/333891)

<div class="topic-metadata">

**Author:** [@roman-tasi](https://discuss.elastic.co/u/roman-tasi)\
**Replies:** 7\
**Last updated:** [June 2, 2023, 7:19am UTC](https://discuss.elastic.co/t/help-with-grok-syntax-issue-as-well-as-question-regarding-double-quotes/333891 "2023-06-02T07:19:40Z")

</div>

This is a sample log that I want to parse: type=EXECVE msg=audit(1684525987.999:148345): argc=2 a0="vim" a1="logstash-syslog.conf" This is the grok filter I am trying: type=%{WORD:type} msg=audit\\(%{NUMBER:audit}\\): a…

---

## [Exporting message fields from Elasticsearch for one years](https://discuss.elastic.co/t/exporting-message-fields-from-elasticsearch-for-one-years/335029)

<div class="topic-metadata">

**Author:** [@Brat\_Qaqa](https://discuss.elastic.co/u/Brat_Qaqa)\
**Replies:** 1\
**Last updated:** [June 2, 2023, 6:44am UTC](https://discuss.elastic.co/t/exporting-message-fields-from-elasticsearch-for-one-years/335029 "2023-06-02T06:44:35Z")

</div>

Hi, what is the best/easiest way of exporting message field from Elasticsearch to some text/json file?

---

## [How can I unwind array in elasticsearch](https://discuss.elastic.co/t/how-can-i-unwind-array-in-elasticsearch/335046)

<div class="topic-metadata">

**Author:** [@Anand\_Konagala](https://discuss.elastic.co/u/Anand_Konagala)\
**Replies:** 0\
**Last updated:** [June 2, 2023, 5:14am UTC](https://discuss.elastic.co/t/how-can-i-unwind-array-in-elasticsearch/335046 "2023-06-02T05:14:35Z")

</div>

Hii { "size": 0, "aggs": { "location\_buckets": { "composite": { "size": 1000, "sources": \[ { "city": { "terms": { "field": "location.city…

---

## [Multiple Out Of Memory Errors occurring, sometimes causing Cluster State Red Alerts](https://discuss.elastic.co/t/multiple-out-of-memory-errors-occurring-sometimes-causing-cluster-state-red-alerts/334985)

<div class="topic-metadata">

**Author:** [@Sarit\_Ghosh](https://discuss.elastic.co/u/Sarit_Ghosh)\
**Replies:** 2\
**Last updated:** [June 2, 2023, 4:03am UTC](https://discuss.elastic.co/t/multiple-out-of-memory-errors-occurring-sometimes-causing-cluster-state-red-alerts/334985 "2023-06-02T04:03:34Z")

</div>

We are getting many Out Of Memory errors on one cluster, but other clusters with similar size are not facing the issue. All the errors are of same type. \[2023-06-01T11:30:41,368\]\[ERROR\]\[o.e.b.ElasticsearchUncaughtExcept…

---

## [Output HTTP: Problem to send @metadata from one pipeline into another](https://discuss.elastic.co/t/output-http-problem-to-send-metadata-from-one-pipeline-into-another/335043)

<div class="topic-metadata">

**Author:** [@junchao](https://discuss.elastic.co/u/junchao)\
**Replies:** 0\
**Last updated:** [June 2, 2023, 3:38am UTC](https://discuss.elastic.co/t/output-http-problem-to-send-metadata-from-one-pipeline-into-another/335043 "2023-06-02T03:38:38Z")

</div>

I am trying to send the value of \[@metadata\]\[usertag\] from one pipeline 1 to pipeline 2. I tried to parse the value using "headers" setting but the value parsed is the string: "%{\[@metadata\]\[usertag\]}" and not the vari…

---

## [Embedding query to baseurl](https://discuss.elastic.co/t/embedding-query-to-baseurl/334984)

<div class="topic-metadata">

**Author:** [@waqar\_jamali](https://discuss.elastic.co/u/waqar_jamali)\
**Replies:** 1\
**Last updated:** [June 2, 2023, 1:03am UTC](https://discuss.elastic.co/t/embedding-query-to-baseurl/334984 "2023-06-02T01:03:44Z")

</div>

I have url to connect to elasticsearch forexample ip:9200 I have query suppose { "query": { "range": { "@timestamp": { "gte": "now-1d/d", "lt": "now/d" } } }, "aggs": { …

---

## [Can we use dense vector field in ES v7.10 for free?](https://discuss.elastic.co/t/can-we-use-dense-vector-field-in-es-v7-10-for-free/334994)

<div class="topic-metadata">

**Author:** [@Vivek\_Sagar](https://discuss.elastic.co/u/Vivek_Sagar)\
**Replies:** 2\
**Last updated:** [June 2, 2023, 1:02am UTC](https://discuss.elastic.co/t/can-we-use-dense-vector-field-in-es-v7-10-for-free/334994 "2023-06-02T01:02:56Z")

</div>

With my installation of elasticsearch v7.10. I see x-pack enabled is true. So I am assuming the free features in x-pack is available to use. When i create a mapping with data type dense vector, I am able to do so and al…

---

## [Uninstall plugin from the eck operator eck cluster](https://discuss.elastic.co/t/uninstall-plugin-from-the-eck-operator-eck-cluster/335033)

<div class="topic-metadata">

**Author:** [@elastic-db-user](https://discuss.elastic.co/u/elastic-db-user)\
**Replies:** 0\
**Last updated:** [June 1, 2023, 8:04pm UTC](https://discuss.elastic.co/t/uninstall-plugin-from-the-eck-operator-eck-cluster/335033 "2023-06-01T20:04:29Z")

</div>

Please share any insights on how to uninstall plugin from the eck operator managed es cluster. ex: in yaml - name: install-plugins command: - sh - -c - | bin/elasticsearch-plugin install --batch mapper-size

---

## [Fleet server managed elastic agent deployment in a azure managed kubernetes cluster running windows](https://discuss.elastic.co/t/fleet-server-managed-elastic-agent-deployment-in-a-azure-managed-kubernetes-cluster-running-windows/335038)

<div class="topic-metadata">

**Author:** [@rtalreja](https://discuss.elastic.co/u/rtalreja)\
**Replies:** 0\
**Last updated:** [June 1, 2023, 11:14pm UTC](https://discuss.elastic.co/t/fleet-server-managed-elastic-agent-deployment-in-a-azure-managed-kubernetes-cluster-running-windows/335038 "2023-06-01T23:14:47Z")

</div>

I want help with elastic-agent daemonset deployment on an Azure managed Kubernetes cluster. This agent is configured on fleet server via a policy. Searching online I found elastic-agent-managed-kubernetes.yaml file for …

---

## [Ingest EVTX file with Elastic Agent](https://discuss.elastic.co/t/ingest-evtx-file-with-elastic-agent/335031)

<div class="topic-metadata">

**Author:** [@DefensiveDepth](https://discuss.elastic.co/u/DefensiveDepth)\
**Replies:** 0\
**Last updated:** [June 1, 2023, 7:41pm UTC](https://discuss.elastic.co/t/ingest-evtx-file-with-elastic-agent/335031 "2023-06-01T19:41:59Z")

</div>

I know that it is possible to ingest evtx files with Winlogbeat (Not sure how to read from .evtx files | Winlogbeat Reference \[8.8\] | Elastic) Is there a way to do this with Elastic Agent?

[Previous page](https://discuss.elastic.co/tag/none.md?no_tags=true&page=366)

[Next page](https://discuss.elastic.co/tag/none.md?no_tags=true&page=368)
