# \#none

**URL:** https://discuss.elastic.co/tag/none.md?no_tags=true&page=369

[Latest](https://discuss.elastic.co/latest.md) · [Categories](https://discuss.elastic.co/categories.md) · [Tags](https://discuss.elastic.co/tags.md)

**Page:** 370

---

## [MISP + Alerts](https://discuss.elastic.co/t/misp-alerts/334280)

<div class="topic-metadata">

**Author:** [@VellayLoket](https://discuss.elastic.co/u/VellayLoket)\
**Replies:** 7\
**Last updated:** [May 31, 2023, 6:37pm UTC](https://discuss.elastic.co/t/misp-alerts/334280 "2023-05-31T18:37:03Z")

</div>

I had connect MISP to ELK with filebeat. So now i have index named filebeat, there are many IOCs. Next i have index with network activity from workstations. So i want to match IP from winlog index with IOCs from MISP …

---

## [Span\_Near and Span\_or query for two multiword match is not giving expected result](https://discuss.elastic.co/t/span-near-and-span-or-query-for-two-multiword-match-is-not-giving-expected-result/334862)

<div class="topic-metadata">

**Author:** [@chetab](https://discuss.elastic.co/u/chetab)\
**Replies:** 0\
**Last updated:** [May 31, 2023, 5:27pm UTC](https://discuss.elastic.co/t/span-near-and-span-or-query-for-two-multiword-match-is-not-giving-expected-result/334862 "2023-05-31T17:27:55Z")

</div>

I need to write the query for below scenario: Ex: The car will be getting close to me but I am unable to stop it. or The car is too close to me but I am unable to stop it. like: Span\_near(span\_or("getting close", "is t…

---

## [Split Value into different document](https://discuss.elastic.co/t/split-value-into-different-document/332799)

<div class="topic-metadata">

**Author:** [@yuswanul](https://discuss.elastic.co/u/yuswanul)\
**Replies:** 1\
**Last updated:** [May 31, 2023, 5:12pm UTC](https://discuss.elastic.co/t/split-value-into-different-document/332799 "2023-05-31T17:12:51Z")

</div>

Hi there, if i have data like this \[{...},{...},{...}\] how can i split them into different documents like document 1 =\> {...} document 2 =\> {...} document 3 =\> {...} so in that way, I can use the json filter to spre…

---

## [Upgrade Elastic Stack 7.15.1 to 7.17.10](https://discuss.elastic.co/t/upgrade-elastic-stack-7-15-1-to-7-17-10/334717)

<div class="topic-metadata">

**Author:** [@SAMY-ELK](https://discuss.elastic.co/u/SAMY-ELK)\
**Replies:** 6\
**Last updated:** [May 31, 2023, 4:36pm UTC](https://discuss.elastic.co/t/upgrade-elastic-stack-7-15-1-to-7-17-10/334717 "2023-05-31T16:36:33Z")

</div>

Hello Team, I need to perform a backup Data KIBANA : tenants-spaces-Index pattern-alias-dashboard -visualisation before upgrade to Elastic version 7.17.10. when i getting issue on upgrade i can restore DATA. how to do…

---

## [Logstash Enrich and translate plugin use](https://discuss.elastic.co/t/logstash-enrich-and-translate-plugin-use/332897)

<div class="topic-metadata">

**Author:** [@gbandasha](https://discuss.elastic.co/u/gbandasha)\
**Replies:** 6\
**Last updated:** [May 31, 2023, 4:08pm UTC](https://discuss.elastic.co/t/logstash-enrich-and-translate-plugin-use/332897 "2023-05-31T16:08:27Z")

</div>

Hello Team, I am trying to enrich the data before it makes its way too elastic, I have tried the below methods but both are currently not working Using the elasticsearch plugin in filter input { kafka { …

---

## [Match query with operator "and", doesn't work when using synonyms analyzer](https://discuss.elastic.co/t/match-query-with-operator-and-doesnt-work-when-using-synonyms-analyzer/334821)

<div class="topic-metadata">

**Author:** [@Bage\_Atanasovska](https://discuss.elastic.co/u/Bage_Atanasovska)\
**Replies:** 0\
**Last updated:** [May 31, 2023, 3:40pm UTC](https://discuss.elastic.co/t/match-query-with-operator-and-doesnt-work-when-using-synonyms-analyzer/334821 "2023-05-31T15:40:02Z")

</div>

I am creating an index using as a search analyzer, an alayzer that has a synonym filter. The query that creates the index is the following: { "settings": { "index": { "analysis": { …

---

## [Pipeline client receives callback 'onFilteredOut'](https://discuss.elastic.co/t/pipeline-client-receives-callback-onfilteredout/334818)

<div class="topic-metadata">

**Author:** [@TheMadmax](https://discuss.elastic.co/u/TheMadmax)\
**Replies:** 0\
**Last updated:** [May 31, 2023, 2:55pm UTC](https://discuss.elastic.co/t/pipeline-client-receives-callback-onfilteredout/334818 "2023-05-31T14:55:43Z")

</div>

Hello, I'm facing an error with my f5\_bigip pipeline. I use the elastic integration module for that, but ,the agent does receive data, but they don't process it : "Pipeline client receives callback 'onFilteredOut' for…

---

## [Logstash SWAP OOM](https://discuss.elastic.co/t/logstash-swap-oom/334675)

<div class="topic-metadata">

**Author:** [@nilsen](https://discuss.elastic.co/u/nilsen)\
**Replies:** 2\
**Last updated:** [May 31, 2023, 2:27pm UTC](https://discuss.elastic.co/t/logstash-swap-oom/334675 "2023-05-31T14:27:39Z")

</div>

We have the past months installed the ELK stack trying to follow the elastic documentation. Currently using logstash to push approx. 15 logs into our elastic indexes. Hoping to push all of our approx. 100 logs into diffe…

---

## [ECK in azure](https://discuss.elastic.co/t/eck-in-azure/334814)

<div class="topic-metadata">

**Author:** [@macdadi112](https://discuss.elastic.co/u/macdadi112)\
**Replies:** 0\
**Last updated:** [May 31, 2023, 2:15pm UTC](https://discuss.elastic.co/t/eck-in-azure/334814 "2023-05-31T14:15:47Z")

</div>

Hi, I have managed to install the ECK as explained in the quikcstart guides (Quickstart | Elastic Cloud on Kubernetes \[2.8\] | Elastic) but now I am trying to install with integration to Azure AD. I changed my elasticse…

---

## [Issue while running FSCrawler on WSL](https://discuss.elastic.co/t/issue-while-running-fscrawler-on-wsl/334620)

<div class="topic-metadata">

**Author:** [@chloesun](https://discuss.elastic.co/u/chloesun)\
**Replies:** 6\
**Last updated:** [May 31, 2023, 2:05pm UTC](https://discuss.elastic.co/t/issue-while-running-fscrawler-on-wsl/334620 "2023-05-31T14:05:48Z")

</div>

I installed JAVA 11, Elastic Search 7, and Fscrawler2.8 on WSL on my Windows machine. Elastic search has no issue starting, and I already configured JAVA\_HOME in .bashrc export JAVA\_HOME="/usr/lib/jvm/java-11-openjdk-am…

---

## [Mapper\_parsing\_exception error](https://discuss.elastic.co/t/mapper-parsing-exception-error/334447)

<div class="topic-metadata">

**Author:** [@Ruwi](https://discuss.elastic.co/u/Ruwi)\
**Replies:** 6\
**Last updated:** [May 31, 2023, 2:01pm UTC](https://discuss.elastic.co/t/mapper-parsing-exception-error/334447 "2023-05-31T14:01:26Z")

</div>

Hi all, I create indexes on a daily basis using fluentd in Elasticsearch. I don't do any mapping on elasticsearch side. After a while, the related index could not be created in Elasticsearch and I got the following erro…

---

## [How to change the date structure to YYYY:MM:DD](https://discuss.elastic.co/t/how-to-change-the-date-structure-to-yyyydd/334789)

<div class="topic-metadata">

**Author:** [@subash\_k](https://discuss.elastic.co/u/subash_k)\
**Replies:** 5\
**Last updated:** [May 31, 2023, 1:18pm UTC](https://discuss.elastic.co/t/how-to-change-the-date-structure-to-yyyydd/334789 "2023-05-31T13:18:44Z")

</div>

Hi, I tried multiple way to change the date event into YYYY:MMM:DD as log\_date. below format is actual date event (2023-05-31 10:30:50,244). I tried manual string concatenation even though am getting type as timestamp …

---

## [Range queries with should clause not working](https://discuss.elastic.co/t/range-queries-with-should-clause-not-working/334764)

<div class="topic-metadata">

**Author:** [@\_baba](https://discuss.elastic.co/u/_baba)\
**Replies:** 3\
**Last updated:** [May 31, 2023, 12:58pm UTC](https://discuss.elastic.co/t/range-queries-with-should-clause-not-working/334764 "2023-05-31T12:58:54Z")

</div>

Hi, I'm trying below range query with must and should clause: Product id can range from 1 to 1000. I'm using below query to fetch product\_id between 1 to 99 or product\_id = 100. However I can only see the must clause…

---

## ["The incoming YAML document exceeds the limit: 3145728 code points" in Logstash/ElastiFLOW](https://discuss.elastic.co/t/the-incoming-yaml-document-exceeds-the-limit-3145728-code-points-in-logstash-elastiflow/334803)

<div class="topic-metadata">

**Author:** [@numpty-boy](https://discuss.elastic.co/u/numpty-boy)\
**Replies:** 0\
**Last updated:** [May 31, 2023, 12:48pm UTC](https://discuss.elastic.co/t/the-incoming-yaml-document-exceeds-the-limit-3145728-code-points-in-logstash-elastiflow/334803 "2023-05-31T12:48:41Z")

</div>

Since upgrading to logstash 7.17.10 on Centos 7, I've been seeing the above error when starting. I see some other folks have had similar problems 8.7, and there are similar problems reported in RUBY forums. I had no su…

---

## [Faceting, sorting, paginating within buckets](https://discuss.elastic.co/t/faceting-sorting-paginating-within-buckets/334801)

<div class="topic-metadata">

**Author:** [@milindyedge](https://discuss.elastic.co/u/milindyedge)\
**Replies:** 0\
**Last updated:** [May 31, 2023, 12:30pm UTC](https://discuss.elastic.co/t/faceting-sorting-paginating-within-buckets/334801 "2023-05-31T12:30:56Z")

</div>

Hi there, I have a question around Elasticsearch's aggregation functionality. We have a use case where we need to do search with a "search term" and then group results by a field in the document and read documents within…

---

## [Dev-Tools gone](https://discuss.elastic.co/t/dev-tools-gone/334720)

<div class="topic-metadata">

**Author:** [@DavidGreensfelder](https://discuss.elastic.co/u/DavidGreensfelder)\
**Replies:** 2\
**Last updated:** [May 31, 2023, 12:14pm UTC](https://discuss.elastic.co/t/dev-tools-gone/334720 "2023-05-31T12:14:07Z")

</div>

Could someone tell me why my Dev-Tool are gone? What makes them get removed? Are they stored in the cache of my local machine?

---

## [Add query parameter "level" to the IndicesStatsRequest using the 7.17 transport client](https://discuss.elastic.co/t/add-query-parameter-level-to-the-indicesstatsrequest-using-the-7-17-transport-client/334782)

<div class="topic-metadata">

**Author:** [@kley](https://discuss.elastic.co/u/kley)\
**Replies:** 2\
**Last updated:** [May 31, 2023, 11:23am UTC](https://discuss.elastic.co/t/add-query-parameter-level-to-the-indicesstatsrequest-using-the-7-17-transport-client/334782 "2023-05-31T11:23:38Z")

</div>

Hey! We are using Elasticsearch 7.17 + the corresponding transport client. I try to calculate the consumed disk space from Elasticsearch without the cat API and came up with this solution (documentation): curl -H 'Con…

---

## [NameError, missing class name com.ibm.mq.jms.MQQueueConnectionFactory](https://discuss.elastic.co/t/nameerror-missing-class-name-com-ibm-mq-jms-mqqueueconnectionfactory/334784)

<div class="topic-metadata">

**Author:** [@paulov](https://discuss.elastic.co/u/paulov)\
**Replies:** 0\
**Last updated:** [May 31, 2023, 10:17am UTC](https://discuss.elastic.co/t/nameerror-missing-class-name-com-ibm-mq-jms-mqqueueconnectionfactory/334784 "2023-05-31T10:17:52Z")

</div>

Hello, I have a JMS plugin configuration with purpose of connecting to IBM MQ. After starting the pipeline I get: \> \> \[WARN \] 2023-05-31 10:38:14.348 \[\[main\]\<jms\] jms - JMS Consumer Died {:exception=\>"NameError", \> :…

---

## [Kibana visualisation-](https://discuss.elastic.co/t/kibana-visualisation/333176)

<div class="topic-metadata">

**Author:** [@Neelam\_Zanvar](https://discuss.elastic.co/u/Neelam_Zanvar)\
**Replies:** 12\
**Last updated:** [May 31, 2023, 9:15am UTC](https://discuss.elastic.co/t/kibana-visualisation/333176 "2023-05-31T09:15:18Z")

</div>

Hi I am creating a Kibana visualization. Using table in kibana lens I want to fetch the time a token is first created in the log file. I am able to view the last value of it. but how can i see the timestamp when the tok…

---

## [ECK continuous log spamming](https://discuss.elastic.co/t/eck-continuous-log-spamming/334569)

<div class="topic-metadata">

**Author:** [@anastazya](https://discuss.elastic.co/u/anastazya)\
**Replies:** 1\
**Last updated:** [May 31, 2023, 9:08am UTC](https://discuss.elastic.co/t/eck-continuous-log-spamming/334569 "2023-05-31T09:08:21Z")

</div>

I have a K8s ECK deployed as this : apiVersion: elasticsearch.k8s.elastic.co/v1 kind: Elasticsearch metadata: name: dev namespace: monitoring spec: version: 8.8.0 nodeSets: name: dev count: 3 podTemplate: sp…

---

## [Attempted to resurrect connection to dead ES instance, but got an error](https://discuss.elastic.co/t/attempted-to-resurrect-connection-to-dead-es-instance-but-got-an-error/333650)

<div class="topic-metadata">

**Author:** [@snalaband](https://discuss.elastic.co/u/snalaband)\
**Replies:** 4\
**Last updated:** [May 31, 2023, 9:03am UTC](https://discuss.elastic.co/t/attempted-to-resurrect-connection-to-dead-es-instance-but-got-an-error/333650 "2023-05-31T09:03:02Z")

</div>

Attempted to resurrect connection to dead ES instance, but got an error. {:error\_type=\>LogStash::Outputs::Elasticsearch::HttpClient::Pool::BadResponseCodeError, :error=\>"Got response code '401' contacting Elasticsearch a…

---

## [Dashboard with kibana](https://discuss.elastic.co/t/dashboard-with-kibana/334016)

<div class="topic-metadata">

**Author:** [@Hanni](https://discuss.elastic.co/u/Hanni)\
**Replies:** 13\
**Last updated:** [May 31, 2023, 8:52am UTC](https://discuss.elastic.co/t/dashboard-with-kibana/334016 "2023-05-31T08:52:28Z")

</div>

Hello, I have two CSV files. One file contains the names of applications, and the other file contains information about a specific application. Both files have the "Host" column in common. I have imported these two files…

---

## [Access Elasticsearch with public IP](https://discuss.elastic.co/t/access-elasticsearch-with-public-ip/334743)

<div class="topic-metadata">

**Author:** [@Rakhshunda\_Noorein\_J](https://discuss.elastic.co/u/Rakhshunda_Noorein_J)\
**Replies:** 2\
**Last updated:** [May 31, 2023, 8:48am UTC](https://discuss.elastic.co/t/access-elasticsearch-with-public-ip/334743 "2023-05-31T08:48:26Z")

</div>

Hello, I have my Elasticsearch running on my windows 10 server. I want to access it with \< my static public ip address \>:9200 I can access my elasticsearch from the server with: localhost:9200 \<my ipv4 address from …

---

## [How to get CPU, Memory and Storage from VCenter not VM's using Logstash](https://discuss.elastic.co/t/how-to-get-cpu-memory-and-storage-from-vcenter-not-vms-using-logstash/334747)

<div class="topic-metadata">

**Author:** [@gaetano](https://discuss.elastic.co/u/gaetano)\
**Replies:** 0\
**Last updated:** [May 31, 2023, 6:32am UTC](https://discuss.elastic.co/t/how-to-get-cpu-memory-and-storage-from-vcenter-not-vms-using-logstash/334747 "2023-05-31T06:32:05Z")

</div>

I'm trying to send CPU, Memory and Storage parameters of VCenter Server (VMWare) to Elasticsearch node (8.6.1 verson) passing by Logstash 8.6.1. What MIB file should I use to get those specific parameters? This is my Lo…

---

## [엘라스틱서치 shrink와 forcemerge 를 진행하는 node 선출 algorithm이나 문서](https://discuss.elastic.co/t/shrink-forcemerge-node-algorithm/334752)

<div class="topic-metadata">

**Author:** [@bxl0107](https://discuss.elastic.co/u/bxl0107)\
**Replies:** 0\
**Last updated:** [May 31, 2023, 6:46am UTC](https://discuss.elastic.co/t/shrink-forcemerge-node-algorithm/334752 "2023-05-31T06:46:05Z")

</div>

안녕하세요. elasticsearch 7.17.8을 사용 중입니다. ilm으로 hot-warm-cold index pahse도 함께 운영 중인데, forcemerge와 shink를 할 때, 용량이 부족한 node에서 진행하는 경우가 종종 있습니다. 용량은 wartermark로 설정해두었는데, shrink와 forcemerge를 진행하는 node를 선출하는 algorithm이나 문서가 있…

---

## [Access Kibana Remotely](https://discuss.elastic.co/t/access-kibana-remotely/334678)

<div class="topic-metadata">

**Author:** [@Rakhshunda\_Noorein\_J](https://discuss.elastic.co/u/Rakhshunda_Noorein_J)\
**Replies:** 3\
**Last updated:** [May 31, 2023, 6:26am UTC](https://discuss.elastic.co/t/access-kibana-remotely/334678 "2023-05-31T06:26:25Z")

</div>

Hello, I want to access kibana remotely. I have changed my Network.Host to my private ip in elasticsearch.yml file then I have changed server.host: 0.0.0.0 in kibana.yml file. I am able to access elasticsearch port 920…

---

## [Unable to see the index patterns and Indices in kibana dashboard](https://discuss.elastic.co/t/unable-to-see-the-index-patterns-and-indices-in-kibana-dashboard/334685)

<div class="topic-metadata">

**Author:** [@SalmaShaik](https://discuss.elastic.co/u/SalmaShaik)\
**Replies:** 2\
**Last updated:** [May 31, 2023, 3:14am UTC](https://discuss.elastic.co/t/unable-to-see-the-index-patterns-and-indices-in-kibana-dashboard/334685 "2023-05-31T03:14:12Z")

</div>

Hi Team, I am unable to see the indices and index patterns in kibana dashboard before upgrading to the Elasticsearch version to 7.17.9. Now I am using 7.8 version. Kindly help me on this.

---

## [Split json array into multiple documents](https://discuss.elastic.co/t/split-json-array-into-multiple-documents/332789)

<div class="topic-metadata">

**Author:** [@manramu22](https://discuss.elastic.co/u/manramu22)\
**Replies:** 1\
**Last updated:** [May 31, 2023, 12:35am UTC](https://discuss.elastic.co/t/split-json-array-into-multiple-documents/332789 "2023-05-31T00:35:04Z")

</div>

Hi Logstash community, I have the following json coming from http\_poller. I want to split that into multiple json documents and feed into Elasticsearch. Pls suggest json filter or split. Thanks in advance Input JSON {…

---

## [Gigamon Integration in Elasticsearch](https://discuss.elastic.co/t/gigamon-integration-in-elasticsearch/334494)

<div class="topic-metadata">

**Author:** [@fenixon](https://discuss.elastic.co/u/fenixon)\
**Replies:** 0\
**Last updated:** [May 27, 2023, 10:18am UTC](https://discuss.elastic.co/t/gigamon-integration-in-elasticsearch/334494 "2023-05-27T10:18:57Z")

</div>

How to integrate Gigamon in Elasticsearch

---

## [Alert linux nfs disks](https://discuss.elastic.co/t/alert-linux-nfs-disks/334719)

<div class="topic-metadata">

**Author:** [@Gaston\_Beltramelli](https://discuss.elastic.co/u/Gaston_Beltramelli)\
**Replies:** 0\
**Last updated:** [May 30, 2023, 7:40pm UTC](https://discuss.elastic.co/t/alert-linux-nfs-disks/334719 "2023-05-30T19:40:45Z")

</div>

Hello everyone, I hope everyone are doing well. I am reaching out to this forum because I'm looking for a solution to monitor NFS disks that are both mounted and accessible. I would like to know if there's any way to s…

[Previous page](https://discuss.elastic.co/tag/none.md?no_tags=true&page=368)

[Next page](https://discuss.elastic.co/tag/none.md?no_tags=true&page=370)
