# \#none

**URL:** https://discuss.elastic.co/tag/none.md?no_tags=true&page=368

[Latest](https://discuss.elastic.co/latest.md) · [Categories](https://discuss.elastic.co/categories.md) · [Tags](https://discuss.elastic.co/tags.md)

**Page:** 369

---

## [Create Apache Response Code Field](https://discuss.elastic.co/t/create-apache-response-code-field/334913)

<div class="topic-metadata">

**Author:** [@sanjeev1895](https://discuss.elastic.co/u/sanjeev1895)\
**Replies:** 1\
**Last updated:** [June 1, 2023, 6:08pm UTC](https://discuss.elastic.co/t/create-apache-response-code-field/334913 "2023-06-01T18:08:14Z")

</div>

Hi Guys, Can anyone help me to do the following configuration to work as expected. I'm trying to create the separate field for apache response code status using grok filter but it print IP address first two octect. Gr…

---

## [Can we have multiple destinations in one jms plugin in logstash cofiguration?](https://discuss.elastic.co/t/can-we-have-multiple-destinations-in-one-jms-plugin-in-logstash-cofiguration/334910)

<div class="topic-metadata">

**Author:** [@Pranjal\_Sett](https://discuss.elastic.co/u/Pranjal_Sett)\
**Replies:** 1\
**Last updated:** [June 1, 2023, 6:02pm UTC](https://discuss.elastic.co/t/can-we-have-multiple-destinations-in-one-jms-plugin-in-logstash-cofiguration/334910 "2023-06-01T18:02:47Z")

</div>

So my requirement is want to insert multiple destination name in one JMS plugin. Writing multiple JMS input plugin for more than 1 destination is bit hectic. So, how can we achieve this with one single jms input plugin. …

---

## [How to Setting single table or specific table output to BigQuery?](https://discuss.elastic.co/t/how-to-setting-single-table-or-specific-table-output-to-bigquery/335022)

<div class="topic-metadata">

**Author:** [@aidensV](https://discuss.elastic.co/u/aidensV)\
**Replies:** 0\
**Last updated:** [June 1, 2023, 5:08pm UTC](https://discuss.elastic.co/t/how-to-setting-single-table-or-specific-table-output-to-bigquery/335022 "2023-06-01T17:08:40Z")

</div>

BigQuery table ID prefix to be used when creating new tables for log data. Table name will be \<table\_prefix\>\<table\_separator\>\<date\>

---

## [Mutual tls between fluentd(act as client) and elasticsearch(act as server)](https://discuss.elastic.co/t/mutual-tls-between-fluentd-act-as-client-and-elasticsearch-act-as-server/334816)

<div class="topic-metadata">

**Author:** [@Voula\_Mikr](https://discuss.elastic.co/u/Voula_Mikr)\
**Replies:** 2\
**Last updated:** [June 1, 2023, 3:05pm UTC](https://discuss.elastic.co/t/mutual-tls-between-fluentd-act-as-client-and-elasticsearch-act-as-server/334816 "2023-06-01T15:05:33Z")

</div>

Hi I am trying to establish mutual tls between fluentd and elasticsearch. I have followed steps described in https://www.elastic.co/guide/en/elasticsearch/reference/8.7/security-basic-setup.html#generate-certificates …

---

## [My logstash conf file doesn't show me the output I don't what's the problem with that](https://discuss.elastic.co/t/my-logstash-conf-file-doesnt-show-me-the-output-i-dont-whats-the-problem-with-that/334999)

<div class="topic-metadata">

**Author:** [@Viknesh.S](https://discuss.elastic.co/u/Viknesh.S)\
**Replies:** 2\
**Last updated:** [June 1, 2023, 3:19pm UTC](https://discuss.elastic.co/t/my-logstash-conf-file-doesnt-show-me-the-output-i-dont-whats-the-problem-with-that/334999 "2023-06-01T15:19:26Z")

</div>

---

## [Connecting elastic search with microsoft fabric](https://discuss.elastic.co/t/connecting-elastic-search-with-microsoft-fabric/335000)

<div class="topic-metadata">

**Author:** [@waqar\_jamali](https://discuss.elastic.co/u/waqar_jamali)\
**Replies:** 3\
**Last updated:** [June 1, 2023, 3:04pm UTC](https://discuss.elastic.co/t/connecting-elastic-search-with-microsoft-fabric/335000 "2023-06-01T15:04:19Z")

</div>

Microsoft has released fabric for data analysis. It can connect to many types and sources of data How to connect elasticsearch data to microsoft fabric?

---

## [Check the conflict fields](https://discuss.elastic.co/t/check-the-conflict-fields/334754)

<div class="topic-metadata">

**Author:** [@therus000](https://discuss.elastic.co/u/therus000)\
**Replies:** 3\
**Last updated:** [June 1, 2023, 2:00pm UTC](https://discuss.elastic.co/t/check-the-conflict-fields/334754 "2023-06-01T14:00:07Z")

</div>

Good day i wonder if there is another way to check the mapping conflict othere that view data views i see in data view 9 fields conflicted. when i sort the field by type. i found only 3 fields that conflicted how can …

---

## [Single Sing On](https://discuss.elastic.co/t/single-sing-on/334970)

<div class="topic-metadata">

**Author:** [@fenixon](https://discuss.elastic.co/u/fenixon)\
**Replies:** 3\
**Last updated:** [June 1, 2023, 1:29pm UTC](https://discuss.elastic.co/t/single-sing-on/334970 "2023-06-01T13:29:39Z")

</div>

I'm loading a Kibana dashboard in an iframe. It asks for username and password to login. How do I bypass this login?

---

## [Error running filebeat](https://discuss.elastic.co/t/error-running-filebeat/334116)

<div class="topic-metadata">

**Author:** [@okasha](https://discuss.elastic.co/u/okasha)\
**Replies:** 0\
**Last updated:** [May 23, 2023, 12:15pm UTC](https://discuss.elastic.co/t/error-running-filebeat/334116 "2023-05-23T12:15:55Z")

</div>

hello guys, I'm getting this error when running this the filebeat 8.7.1 on my local machine (both Elasticsearch and kibana are running) when running .\\filebeat.exe setup -e on power shell i couldn't paste the whole …

---

## [Can not restart Elasticsearch service](https://discuss.elastic.co/t/can-not-restart-elasticsearch-service/334688)

<div class="topic-metadata">

**Author:** [@lcsb-sysadmins](https://discuss.elastic.co/u/lcsb-sysadmins)\
**Replies:** 18\
**Last updated:** [June 1, 2023, 12:57pm UTC](https://discuss.elastic.co/t/can-not-restart-elasticsearch-service/334688 "2023-06-01T12:57:02Z")

</div>

Hi, Elastic Stack Version - 7.17.5 We had an issue with our server (iDRAC is unable to successfully communicate with the device RAID Controller) which caused disruption for our elastic stack. However we solved that is…

---

## [Whole elasticsearh cluster become unresponsive if only one node is saturating](https://discuss.elastic.co/t/whole-elasticsearh-cluster-become-unresponsive-if-only-one-node-is-saturating/334960)

<div class="topic-metadata">

**Author:** [@shahzadkhan](https://discuss.elastic.co/u/shahzadkhan)\
**Replies:** 2\
**Last updated:** [June 1, 2023, 12:14pm UTC](https://discuss.elastic.co/t/whole-elasticsearh-cluster-become-unresponsive-if-only-one-node-is-saturating/334960 "2023-06-01T12:14:53Z")

</div>

Hello All, we have elasticsearch cluster with 12 nodes and all the nodes are configured as master/data. these days we encountring an issue that all the queries are automatically forwarded to a only one node and the thr…

---

## [Why Kibana Dashboard values are different from index query](https://discuss.elastic.co/t/why-kibana-dashboard-values-are-different-from-index-query/334813)

<div class="topic-metadata">

**Author:** [@Vitor\_Nilson](https://discuss.elastic.co/u/Vitor_Nilson)\
**Replies:** 3\
**Last updated:** [June 1, 2023, 11:27am UTC](https://discuss.elastic.co/t/why-kibana-dashboard-values-are-different-from-index-query/334813 "2023-06-01T11:27:14Z")

</div>

Hello, I have a index called kong (the main index), and a Rollup job in this index grouping every 24h which has a index calld rollup\_job\_kong\_gateway. If we take a look directely in the index Kong and run the following…

---

## [How to give multiple kibana FQDN in rp.redirect\_uri](https://discuss.elastic.co/t/how-to-give-multiple-kibana-fqdn-in-rp-redirect-uri/334961)

<div class="topic-metadata">

**Author:** [@Aniket\_Pant](https://discuss.elastic.co/u/Aniket_Pant)\
**Replies:** 0\
**Last updated:** [June 1, 2023, 11:12am UTC](https://discuss.elastic.co/t/how-to-give-multiple-kibana-fqdn-in-rp-redirect-uri/334961 "2023-06-01T11:12:25Z")

</div>

Hi Team, We are running two instance of kibana and we have seperate fqdn for this two kibana instance. We have successfully integrated Azure AD OIDC with Elasticsearch and kibana. During the testing we were testing only…

---

## [Query with Text field](https://discuss.elastic.co/t/query-with-text-field/334687)

<div class="topic-metadata">

**Author:** [@Kunjal\_Patel](https://discuss.elastic.co/u/Kunjal_Patel)\
**Replies:** 1\
**Last updated:** [June 1, 2023, 9:44am UTC](https://discuss.elastic.co/t/query-with-text-field/334687 "2023-06-01T09:44:56Z")

</div>

I have index settings and mappings are as below "settings": { "number\_of\_shards": 1, "number\_of\_replicas": 1, "index": {"max\_result\_window": 10000000, "max\_inner\_result\_window": 1000}, "analysis": { "analyzer": { …

---

## [Reverse nested problem](https://discuss.elastic.co/t/reverse-nested-problem/334783)

<div class="topic-metadata">

**Author:** [@Kenan\_Seyidov](https://discuss.elastic.co/u/Kenan_Seyidov)\
**Replies:** 1\
**Last updated:** [June 1, 2023, 8:46am UTC](https://discuss.elastic.co/t/reverse-nested-problem/334783 "2023-06-01T08:46:05Z")

</div>

In Elasticsearch we use a nested query, when we use the reverse nesting it does not remember the previous aggregation, it only returns the topmost eligible documents. For example : In the following query, rate\_option, s…

---

## [Issue with multiple pipelines of Logstash](https://discuss.elastic.co/t/issue-with-multiple-pipelines-of-logstash/334908)

<div class="topic-metadata">

**Author:** [@Wang\_Yin](https://discuss.elastic.co/u/Wang_Yin)\
**Replies:** 0\
**Last updated:** [June 1, 2023, 6:58am UTC](https://discuss.elastic.co/t/issue-with-multiple-pipelines-of-logstash/334908 "2023-06-01T06:58:04Z")

</div>

I'm using Logstash version 8.8.0. I have two Logstash conf files under /etc/logstash/conf.d folder, one is called "syslog\_cisco.conf", another one is called "test.conf" as below: syslog\_cisco.conf input { udp { …

---

## [Shards allocation method](https://discuss.elastic.co/t/shards-allocation-method/334900)

<div class="topic-metadata">

**Author:** [@saifulshihab](https://discuss.elastic.co/u/saifulshihab)\
**Replies:** 1\
**Last updated:** [June 1, 2023, 6:43am UTC](https://discuss.elastic.co/t/shards-allocation-method/334900 "2023-06-01T06:43:27Z")

</div>

Hello how shards are allocated in cluster nodes? for the below scenario could anyone explain ? for 3node cluster 3primary shards and 2 replica shards configured. i have to configure my nodes with same storage ? how …

---

## [Query taking longer times than expected, possible ways of optimization at query level](https://discuss.elastic.co/t/query-taking-longer-times-than-expected-possible-ways-of-optimization-at-query-level/334221)

<div class="topic-metadata">

**Author:** [@nadeem.akhter](https://discuss.elastic.co/u/nadeem.akhter)\
**Replies:** 2\
**Last updated:** [June 1, 2023, 4:14am UTC](https://discuss.elastic.co/t/query-taking-longer-times-than-expected-possible-ways-of-optimization-at-query-level/334221 "2023-06-01T04:14:47Z")

</div>

I have an Elasticsearch 8.6.0 instance with some data in it. I have been querying data off it using query string with 130 keywords in the following format: { "query": { "bool": { "should": \[ …

---

## [plugins.encryptedSavedObjects\] Failed to decrypt "apiKey" attribute: Unsupported state or unable to authenticate data](https://discuss.elastic.co/t/plugins-encryptedsavedobjects-failed-to-decrypt-apikey-attribute-unsupported-state-or-unable-to-authenticate-data/333402)

<div class="topic-metadata">

**Author:** [@vantrung](https://discuss.elastic.co/u/vantrung)\
**Replies:** 3\
**Last updated:** [June 1, 2023, 3:17am UTC](https://discuss.elastic.co/t/plugins-encryptedsavedobjects-failed-to-decrypt-apikey-attribute-unsupported-state-or-unable-to-authenticate-data/333402 "2023-06-01T03:17:37Z")

</div>

Hi I installed kibana by ECK on EKS cluster

---

## [Log Forwarding Capabilities](https://discuss.elastic.co/t/log-forwarding-capabilities/334627)

<div class="topic-metadata">

**Author:** [@ddawil](https://discuss.elastic.co/u/ddawil)\
**Replies:** 4\
**Last updated:** [June 1, 2023, 2:20am UTC](https://discuss.elastic.co/t/log-forwarding-capabilities/334627 "2023-06-01T02:20:32Z")

</div>

Network devices logs, system logs and Cloud services logs are sent to Elastic for log storage. Logs are processed are stored JSON format. Does Elastic able to do forwarding of logs simultaneously to a SIEM with its orig…

---

## [How to hide controls like Saved Filter Menu and Add Filter Menu, Options Menu when embedding Kibana IFrame URL in the web application](https://discuss.elastic.co/t/how-to-hide-controls-like-saved-filter-menu-and-add-filter-menu-options-menu-when-embedding-kibana-iframe-url-in-the-web-application/332640)

<div class="topic-metadata">

**Author:** [@ramanm](https://discuss.elastic.co/u/ramanm)\
**Replies:** 1\
**Last updated:** [June 1, 2023, 12:22am UTC](https://discuss.elastic.co/t/how-to-hide-controls-like-saved-filter-menu-and-add-filter-menu-options-menu-when-embedding-kibana-iframe-url-in-the-web-application/332640 "2023-06-01T00:22:33Z")

</div>

We are embedding kibana iframe url in our web application. We wanted to hide controls like Saved Filter Menu Add Filter Menu Options Menu Some of the above filters exposes the index names under Data View that are ava…

---

## [Event.start value minus Event.start last value code](https://discuss.elastic.co/t/event-start-value-minus-event-start-last-value-code/333374)

<div class="topic-metadata">

**Author:** [@patterno](https://discuss.elastic.co/u/patterno)\
**Replies:** 1\
**Last updated:** [May 31, 2023, 11:44pm UTC](https://discuss.elastic.co/t/event-start-value-minus-event-start-last-value-code/333374 "2023-05-31T23:44:31Z")

</div>

Good day! I am new to elastic and I'm wondering if any other users can help me with my problem. I am having a trouble computing the event.start and event.start (last value) of a certain process on my logs. I am planning…

---

## [@timestamp in .watcher.history-\*](https://discuss.elastic.co/t/timestamp-in-watcher-history/333322)

<div class="topic-metadata">

**Author:** [@rorii](https://discuss.elastic.co/u/rorii)\
**Replies:** 1\
**Last updated:** [May 31, 2023, 11:38pm UTC](https://discuss.elastic.co/t/timestamp-in-watcher-history/333322 "2023-05-31T23:38:13Z")

</div>

I am trying to visualise alerts metrics in Kibana. Since the results.actions are stored in an array, I am trying to query the watcher history and with watcher index action to create my own index where I can aggregate the…

---

## [Elastic Agent Integration for Cloudflare account scoped data sets](https://discuss.elastic.co/t/elastic-agent-integration-for-cloudflare-account-scoped-data-sets/334885)

<div class="topic-metadata">

**Author:** [@dflo16](https://discuss.elastic.co/u/dflo16)\
**Replies:** 0\
**Last updated:** [May 31, 2023, 10:55pm UTC](https://discuss.elastic.co/t/elastic-agent-integration-for-cloudflare-account-scoped-data-sets/334885 "2023-05-31T22:55:32Z")

</div>

I am using cloud hosted elastic stack (8.7) and would like to ingest Cloudflare account scoped data sets. These are different data sets than the ones supported by the default Cloudflare integration. The account scoped da…

---

## [Cluster.initial\_master\_nodes and discovery.seed\_hosts](https://discuss.elastic.co/t/cluster-initial-master-nodes-and-discovery-seed-hosts/334588)

<div class="topic-metadata">

**Author:** [@daniela09](https://discuss.elastic.co/u/daniela09)\
**Replies:** 2\
**Last updated:** [May 31, 2023, 10:49pm UTC](https://discuss.elastic.co/t/cluster-initial-master-nodes-and-discovery-seed-hosts/334588 "2023-05-31T22:49:21Z")

</div>

Hi, I have elasticsearch cluster (8.7.0) on Kubernetes. In the configmaps of the nodes (master,data,client) I had: ... discovery.seed\_hosts: ${NODE\_LIST} cluster.initial\_master\_nodes: ${MASTER\_NODES} ... In my deploym…

---

## [How to link kibana with elastic search?](https://discuss.elastic.co/t/how-to-link-kibana-with-elastic-search/333183)

<div class="topic-metadata">

**Author:** [@satvika\_maram](https://discuss.elastic.co/u/satvika_maram)\
**Replies:** 1\
**Last updated:** [May 31, 2023, 10:32pm UTC](https://discuss.elastic.co/t/how-to-link-kibana-with-elastic-search/333183 "2023-05-31T22:32:37Z")

</div>

I have a company server and I am using CentOS. With a lot of hardwork, I installed it into my server . Can someone help me out here??

---

## [Migration to 8.7 kibana](https://discuss.elastic.co/t/migration-to-8-7-kibana/332872)

<div class="topic-metadata">

**Author:** [@Lilia](https://discuss.elastic.co/u/Lilia)\
**Replies:** 4\
**Last updated:** [May 31, 2023, 10:00pm UTC](https://discuss.elastic.co/t/migration-to-8-7-kibana/332872 "2023-05-31T22:00:55Z")

</div>

Hi I'm trying to migrate custom plugin to version 8.7 of kibana, but i receive a Server error and the kibana is not loading, in the logs i have several warnings, could you please help fix it or advice how to clear the wa…

---

## [Ingest Pipeline Failure Processor Shard Failures](https://discuss.elastic.co/t/ingest-pipeline-failure-processor-shard-failures/330541)

<div class="topic-metadata">

**Author:** [@paolovalladolid](https://discuss.elastic.co/u/paolovalladolid)\
**Replies:** 4\
**Last updated:** [May 31, 2023, 9:25pm UTC](https://discuss.elastic.co/t/ingest-pipeline-failure-processor-shard-failures/330541 "2023-05-31T21:25:18Z")

</div>

I set up an ingest pipeline in Dev Tools console with this command PUT \_ingest/pipeline/ams-log-pipeline { "processors": \[ { "dissect": { "field": "message", "pattern": "%{@timestamp} %{logLe…

---

## [Log files to Logstash](https://discuss.elastic.co/t/log-files-to-logstash/333063)

<div class="topic-metadata">

**Author:** [@hjsroldan](https://discuss.elastic.co/u/hjsroldan)\
**Replies:** 1\
**Last updated:** [May 31, 2023, 8:43pm UTC](https://discuss.elastic.co/t/log-files-to-logstash/333063 "2023-05-31T20:43:19Z")

</div>

Hi, Good day! I have this scenario where I’m trying to collect log files and ship or ingest it to Logstash. Below is my logstash.conf Below is my input file (my-topics-1.txt) which contains 1-25 as shown below. …

---

## [Can I still jump from 7.17 to the new 8.8?](https://discuss.elastic.co/t/can-i-still-jump-from-7-17-to-the-new-8-8/334616)

<div class="topic-metadata">

**Author:** [@GenSSC](https://discuss.elastic.co/u/GenSSC)\
**Replies:** 8\
**Last updated:** [May 31, 2023, 7:16pm UTC](https://discuss.elastic.co/t/can-i-still-jump-from-7-17-to-the-new-8-8/334616 "2023-05-31T19:16:57Z")

</div>

I'm at 7.16 right now. I know I need to update to 7.17 first, but I am wondering if right after that I can go directly to 8.8? I know I could jump to 8.7 from 7.17. Just wondering if it's still the case.

[Previous page](https://discuss.elastic.co/tag/none.md?no_tags=true&page=367)

[Next page](https://discuss.elastic.co/tag/none.md?no_tags=true&page=369)
