# \#none

**URL:** https://discuss.elastic.co/tag/none.md?no_tags=true&page=375

[Latest](https://discuss.elastic.co/latest.md) · [Categories](https://discuss.elastic.co/categories.md) · [Tags](https://discuss.elastic.co/tags.md)

**Page:** 376

---

## [Issues regarding the installation of ElasticSearch on a remote server](https://discuss.elastic.co/t/issues-regarding-the-installation-of-elasticsearch-on-a-remote-server/333860)

<div class="topic-metadata">

**Author:** [@Gio\_27](https://discuss.elastic.co/u/Gio_27)\
**Replies:** 2\
**Last updated:** [May 22, 2023, 12:48pm UTC](https://discuss.elastic.co/t/issues-regarding-the-installation-of-elasticsearch-on-a-remote-server/333860 "2023-05-22T12:48:07Z")

</div>

Good morning everyone. First thing first: I am a newbie on topics like servers, unix systems and CLIs. I am working on a Logs monitoring & analysis tool project using the ELK stack. I need to install elasticsearch on …

---

## [Event.ingested huge time difference](https://discuss.elastic.co/t/event-ingested-huge-time-difference/333975)

<div class="topic-metadata">

**Author:** [@AnkurYogi](https://discuss.elastic.co/u/AnkurYogi)\
**Replies:** 6\
**Last updated:** [May 22, 2023, 11:06am UTC](https://discuss.elastic.co/t/event-ingested-huge-time-difference/333975 "2023-05-22T11:06:23Z")

</div>

Hello All, While investigating on an event I noticed there was a huge difference between event.created and event.ingested which created a confusion on the real event time. Later digging in docs resulted event.ingested…

---

## [Kibana url template scripted field](https://discuss.elastic.co/t/kibana-url-template-scripted-field/329050)

<div class="topic-metadata">

**Author:** [@PRASHANT\_MEHTA](https://discuss.elastic.co/u/PRASHANT_MEHTA)\
**Replies:** 3\
**Last updated:** [May 22, 2023, 10:29am UTC](https://discuss.elastic.co/t/kibana-url-template-scripted-field/329050 "2023-05-22T10:29:53Z")

</div>

Hello All, I've created a scripted field and would like know how can i configure the url host and port dynamically through some external config for 1 specific index pattern? intention is not to come in kibana and do…

---

## [Kuromoji\_number and kuromoji\_readingform filter issue](https://discuss.elastic.co/t/kuromoji-number-and-kuromoji-readingform-filter-issue/333999)

<div class="topic-metadata">

**Author:** [@kagnihotri](https://discuss.elastic.co/u/kagnihotri)\
**Replies:** 0\
**Last updated:** [May 22, 2023, 9:02am UTC](https://discuss.elastic.co/t/kuromoji-number-and-kuromoji-readingform-filter-issue/333999 "2023-05-22T09:02:49Z")

</div>

Hi, I have added these two filters - kuromoji\_number, kuromoji\_readingform kuromoji\_readingform is dominating and it is not generating expected tokens from kuromoji\_number filter. Example - { "text": "一〇〇〇", "tok…

---

## [Cluster is not established](https://discuss.elastic.co/t/cluster-is-not-established/333671)

<div class="topic-metadata">

**Author:** [@apopap](https://discuss.elastic.co/u/apopap)\
**Replies:** 14\
**Last updated:** [May 22, 2023, 8:16am UTC](https://discuss.elastic.co/t/cluster-is-not-established/333671 "2023-05-22T08:16:28Z")

</div>

I have 2 EC2 instances one on private network 1 AZ1 and other on private network 2 AZ 2 and try to establish a cluster. The configuration is similar on both nodes, node.name changes # Add your configuration lines here …

---

## [How i can convert the given SQl query to dsl query?](https://discuss.elastic.co/t/how-i-can-convert-the-given-sql-query-to-dsl-query/333878)

<div class="topic-metadata">

**Author:** [@babu\_dev](https://discuss.elastic.co/u/babu_dev)\
**Replies:** 2\
**Last updated:** [May 22, 2023, 7:58am UTC](https://discuss.elastic.co/t/how-i-can-convert-the-given-sql-query-to-dsl-query/333878 "2023-05-22T07:58:49Z")

</div>

Sql query SELECT \* FROM USER\_DB WHERE (NAME IN('BABU DEV', 'NIKHIL') OR AGE IN(23,45)) AND COUNTRY = 'INDIA' AND STATE ='DELHI';

---

## [ElasticSearch Version Upgrade in AWS EKS using Helm Charts \[7.17.3 -\> 8.5.1\]](https://discuss.elastic.co/t/elasticsearch-version-upgrade-in-aws-eks-using-helm-charts-7-17-3-8-5-1/333988)

<div class="topic-metadata">

**Author:** [@helloworld466](https://discuss.elastic.co/u/helloworld466)\
**Replies:** 0\
**Last updated:** [May 22, 2023, 7:54am UTC](https://discuss.elastic.co/t/elasticsearch-version-upgrade-in-aws-eks-using-helm-charts-7-17-3-8-5-1/333988 "2023-05-22T07:54:51Z")

</div>

Have deployed Elasticsearch version 7.17.3 in AWS EKS using helm chart GitHub - elastic/helm-charts: You know, for Kubernetes. My goal is to upgrade my ES to the latest version 8.5.1 using helm chart. I followed the ste…

---

## [Logstash config](https://discuss.elastic.co/t/logstash-config/333631)

<div class="topic-metadata">

**Author:** [@A1i](https://discuss.elastic.co/u/A1i)\
**Replies:** 9\
**Last updated:** [May 22, 2023, 4:28am UTC](https://discuss.elastic.co/t/logstash-config/333631 "2023-05-22T04:28:57Z")

</div>

how can I config logstash to read two log files from local then pass them into two indies

---

## [I have a ELK Cluster 7.17.3 and I have installed bundled JDK 18+36.. if i need to upgrade JDK to higher version is it compatible with my 7.17.3 version](https://discuss.elastic.co/t/i-have-a-elk-cluster-7-17-3-and-i-have-installed-bundled-jdk-18-36-if-i-need-to-upgrade-jdk-to-higher-version-is-it-compatible-with-my-7-17-3-version/333782)

<div class="topic-metadata">

**Author:** [@AKAM14](https://discuss.elastic.co/u/AKAM14)\
**Replies:** 2\
**Last updated:** [May 22, 2023, 1:49am UTC](https://discuss.elastic.co/t/i-have-a-elk-cluster-7-17-3-and-i-have-installed-bundled-jdk-18-36-if-i-need-to-upgrade-jdk-to-higher-version-is-it-compatible-with-my-7-17-3-version/333782 "2023-05-22T01:49:25Z")

</div>

Hi All, I have a ELK Stack 7.17.3 installed on a Windows 2019 server with bundled JDK 18 +36 . Since there is a vulnerability in JDK 18, can i upgrade the jdk to open jdk 18.0.1 will this impact my ELK Stack . Thanks, …

---

## [Converting timezones in Logstash - HOWTO](https://discuss.elastic.co/t/converting-timezones-in-logstash-howto/333821)

<div class="topic-metadata">

**Author:** [@nbertram](https://discuss.elastic.co/u/nbertram)\
**Replies:** 2\
**Last updated:** [May 21, 2023, 9:12pm UTC](https://discuss.elastic.co/t/converting-timezones-in-logstash-howto/333821 "2023-05-21T21:12:27Z")

</div>

Hi, After trawling a lot of the internet asking how to convert a timestamp from UTC to local time in Logstash I came up blank, and against a whole bunch of answers on here saying "don't - leave that to the presentation …

---

## [Index pattern link is not available at Kibana](https://discuss.elastic.co/t/index-pattern-link-is-not-available-at-kibana/333945)

<div class="topic-metadata">

**Author:** [@Yasser\_Alsawy](https://discuss.elastic.co/u/Yasser_Alsawy)\
**Replies:** 2\
**Last updated:** [May 21, 2023, 7:28pm UTC](https://discuss.elastic.co/t/index-pattern-link-is-not-available-at-kibana/333945 "2023-05-21T19:28:20Z")

</div>

I have installed kibana at my Windows 11 WSL. Index pattern is not coming under stack management --\> kibana --\> index pattern Accordingly, when creating an index using logstash or filebeat I cannot find any data at Disc…

---

## [Failed start elasticsearch after install](https://discuss.elastic.co/t/failed-start-elasticsearch-after-install/333959)

<div class="topic-metadata">

**Author:** [@Addr1](https://discuss.elastic.co/u/Addr1)\
**Replies:** 3\
**Last updated:** [May 21, 2023, 6:50pm UTC](https://discuss.elastic.co/t/failed-start-elasticsearch-after-install/333959 "2023-05-21T18:50:25Z")

</div>

Hi, I've an error message after "sudo systemctl start elasticsearch" : Job for elasticsearch.service failed because the control process exited with error code. See "systemctl status elasticsearch.service" and "journalc…

---

## [ELK Indexing Strategy](https://discuss.elastic.co/t/elk-indexing-strategy/333663)

<div class="topic-metadata">

**Author:** [@ARDA\_ASLAN](https://discuss.elastic.co/u/ARDA_ASLAN)\
**Replies:** 11\
**Last updated:** [May 21, 2023, 6:46pm UTC](https://discuss.elastic.co/t/elk-indexing-strategy/333663 "2023-05-21T18:46:30Z")

</div>

Hello Elastic Community, I am quite new in ELK environment so trying to understand the concept and the best practices for a new project that i am responsible. Needing some advices and overview about the indexing strate…

---

## [Elasticsearch cluster replication](https://discuss.elastic.co/t/elasticsearch-cluster-replication/333752)

<div class="topic-metadata">

**Author:** [@ahmed.emad](https://discuss.elastic.co/u/ahmed.emad)\
**Replies:** 4\
**Last updated:** [May 21, 2023, 10:56am UTC](https://discuss.elastic.co/t/elasticsearch-cluster-replication/333752 "2023-05-21T10:56:59Z")

</div>

hello, if i have 2 nodes standalone elasticsearch working with scenario: node-1 : have elasticsearch and logstash and logstash send logs let's called it "index-1" node-2 : have elasticsearch and logstash and logstash …

---

## [Indexing speed single vs multiple clusters](https://discuss.elastic.co/t/indexing-speed-single-vs-multiple-clusters/333910)

<div class="topic-metadata">

**Author:** [@sliu](https://discuss.elastic.co/u/sliu)\
**Replies:** 3\
**Last updated:** [May 21, 2023, 4:22am UTC](https://discuss.elastic.co/t/indexing-speed-single-vs-multiple-clusters/333910 "2023-05-21T04:22:14Z")

</div>

Here's my simplified use case: three indexes, each has 5 billion documents. No need to hit multiple indexes in search. The length of time to index the data is in concern here. With three server nodes, I can have: (1) si…

---

## [2 conf sending data to the same index](https://discuss.elastic.co/t/2-conf-sending-data-to-the-same-index/333888)

<div class="topic-metadata">

**Author:** [@jefin\_dark](https://discuss.elastic.co/u/jefin_dark)\
**Replies:** 7\
**Last updated:** [May 20, 2023, 10:41pm UTC](https://discuss.elastic.co/t/2-conf-sending-data-to-the-same-index/333888 "2023-05-20T22:41:47Z")

</div>

Hello, I have 2 conf files and they are sending data at the same time to the 2 index (when I would like each conf to send the information to the specific index) If you can help me, I can provide more information if nee…

---

## [Referencing a weight value from array of match under score function](https://discuss.elastic.co/t/referencing-a-weight-value-from-array-of-match-under-score-function/333909)

<div class="topic-metadata">

**Author:** [@Harinder\_Singh](https://discuss.elastic.co/u/Harinder_Singh)\
**Replies:** 3\
**Last updated:** [May 20, 2023, 5:31pm UTC](https://discuss.elastic.co/t/referencing-a-weight-value-from-array-of-match-under-score-function/333909 "2023-05-20T17:31:16Z")

</div>

We have a requirement to override default elastic score mechanism and score two documents equally if they have equal number of matches ignoring tf and idf. Below is my sample index data PUT my\_index/\_doc/5 { "affinit…

---

## [Weird Bug, Field name is blocked, cant use the same name of field it in other pipelines](https://discuss.elastic.co/t/weird-bug-field-name-is-blocked-cant-use-the-same-name-of-field-it-in-other-pipelines/333890)

<div class="topic-metadata">

**Author:** [@ElasticLiver](https://discuss.elastic.co/u/ElasticLiver)\
**Replies:** 5\
**Last updated:** [May 20, 2023, 2:25am UTC](https://discuss.elastic.co/t/weird-bug-field-name-is-blocked-cant-use-the-same-name-of-field-it-in-other-pipelines/333890 "2023-05-20T02:25:50Z")

</div>

Hi, I have a pipeline that stores the fields memory\_memused\_per and memory\_swapused\_per in an index , in another pipeline that stores data in another index I have tried to use the same name but nothing is indexed. after …

---

## [\_geoip\_lookup\_failure in Logstash pipeline using GeoLite2-City.mmdb](https://discuss.elastic.co/t/geoip-lookup-failure-in-logstash-pipeline-using-geolite2-city-mmdb/333802)

<div class="topic-metadata">

**Author:** [@Carlos\_T](https://discuss.elastic.co/u/Carlos_T)\
**Replies:** 4\
**Last updated:** [May 19, 2023, 11:51pm UTC](https://discuss.elastic.co/t/geoip-lookup-failure-in-logstash-pipeline-using-geolite2-city-mmdb/333802 "2023-05-19T23:51:35Z")

</div>

Hi all When trying to enrich the following pipeline of my Logstash 8.4.3 with GeoIP info: input { file { path =\> "/var/log/apache2/\*.log" start\_position =\> "beginning" } http { } } fi…

---

## ["Elasticsearch connection failure" on newly installed Elastic Security server](https://discuss.elastic.co/t/elasticsearch-connection-failure-on-newly-installed-elastic-security-server/333707)

<div class="topic-metadata">

**Author:** [@Timothy\_Dilbert](https://discuss.elastic.co/u/Timothy_Dilbert)\
**Replies:** 1\
**Last updated:** [May 19, 2023, 10:50pm UTC](https://discuss.elastic.co/t/elasticsearch-connection-failure-on-newly-installed-elastic-security-server/333707 "2023-05-19T22:50:55Z")

</div>

I recently installed Elastic Security following the belowlinked YouTube video: Under Management \> Fleet it is showing "Fleet Server is not Healthy. A healthy Fleet server is required before you can enroll …

---

## [When I am trying to open Dev\_tools in Kibana, Why I am getting Black page](https://discuss.elastic.co/t/when-i-am-trying-to-open-dev-tools-in-kibana-why-i-am-getting-black-page/333839)

<div class="topic-metadata">

**Author:** [@Anand\_Konagala](https://discuss.elastic.co/u/Anand_Konagala)\
**Replies:** 6\
**Last updated:** [May 19, 2023, 3:48pm UTC](https://discuss.elastic.co/t/when-i-am-trying-to-open-dev-tools-in-kibana-why-i-am-getting-black-page/333839 "2023-05-19T15:48:41Z")

</div>

This is how it will shows when I am opening elasticsearch devTools

---

## [Reindex error : "type":"mapper\_parsing\_exception","reason":"failed to parse field \[date\] of type \[date\]](https://discuss.elastic.co/t/reindex-error-type-mapper-parsing-exception-reason-failed-to-parse-field-date-of-type-date/333798)

<div class="topic-metadata">

**Author:** [@GenSSC](https://discuss.elastic.co/u/GenSSC)\
**Replies:** 5\
**Last updated:** [May 19, 2023, 3:25pm UTC](https://discuss.elastic.co/t/reindex-error-type-mapper-parsing-exception-reason-failed-to-parse-field-date-of-type-date/333798 "2023-05-19T15:25:12Z")

</div>

Hello, While using the reindexing API, I am running into 4 indices that are giving me errors. It seems like the date in the document matches the template but I guess it is not. I don't really know how to tackle this. …

---

## [Logstash ConfigurationError - Failed to execute action](https://discuss.elastic.co/t/logstash-configurationerror-failed-to-execute-action/333874)

<div class="topic-metadata">

**Author:** [@Yasser\_Alsawy](https://discuss.elastic.co/u/Yasser_Alsawy)\
**Replies:** 1\
**Last updated:** [May 19, 2023, 2:25pm UTC](https://discuss.elastic.co/t/logstash-configurationerror-failed-to-execute-action/333874 "2023-05-19T14:25:51Z")

</div>

I'm getting a configuration error when try to start logstash: at line 13, column 28 (byte 213) after filter {\\n grok {\\n match =\> { \\"message\\" =\> \\"%{COMBINEDAPACHELOG}\\" }\\n }\\n date {\\n match =\> \[ \\"times…

---

## [Kibana Import JSON : File structure cannot be determined](https://discuss.elastic.co/t/kibana-import-json-file-structure-cannot-be-determined/333275)

<div class="topic-metadata">

**Author:** [@Julien069](https://discuss.elastic.co/u/Julien069)\
**Replies:** 2\
**Last updated:** [May 19, 2023, 1:42pm UTC](https://discuss.elastic.co/t/kibana-import-json-file-structure-cannot-be-determined/333275 "2023-05-19T13:42:20Z")

</div>

Hi , I want to import this index-pattern : Kibana index-pattern When I import it , I have this error : I tried to override Timestamp with this option but it doesn't work : I tried to make timestamp\_format to n…

---

## [Elasticsearch 8.7 2-node cluster](https://discuss.elastic.co/t/elasticsearch-8-7-2-node-cluster/333772)

<div class="topic-metadata">

**Author:** [@zen.xen](https://discuss.elastic.co/u/zen.xen)\
**Replies:** 6\
**Last updated:** [May 19, 2023, 11:22am UTC](https://discuss.elastic.co/t/elasticsearch-8-7-2-node-cluster/333772 "2023-05-19T11:22:54Z")

</div>

Hello, I want to create 2-node cluster and it doesn't work node-01: path.data: /bitnami/elasticsearch/data cluster.name: zephyr node.name: node-01 node.roles: \[ master, data \] http.port: 9200 transport.port: 9300 boot…

---

## [Elasticsearch monitoring using telegraf](https://discuss.elastic.co/t/elasticsearch-monitoring-using-telegraf/333862)

<div class="topic-metadata">

**Author:** [@mhr](https://discuss.elastic.co/u/mhr)\
**Replies:** 0\
**Last updated:** [May 19, 2023, 10:58am UTC](https://discuss.elastic.co/t/elasticsearch-monitoring-using-telegraf/333862 "2023-05-19T10:58:07Z")

</div>

I am using telegraf to monitor elasticsearch. i am using below doc. i am not able to get the data elasticsearch\_network ' tcp\_in\_errs value=0 tcp\_passive\_opens value=16 tcp\_curr\_estab value=29 tcp\_in\_segs value=11…

---

## [Unassigned shards, with status "Elasticsearch can allocate the shard" for all of them](https://discuss.elastic.co/t/unassigned-shards-with-status-elasticsearch-can-allocate-the-shard-for-all-of-them/333806)

<div class="topic-metadata">

**Author:** [@Petr.Simik](https://discuss.elastic.co/u/Petr.Simik)\
**Replies:** 6\
**Last updated:** [May 19, 2023, 9:49am UTC](https://discuss.elastic.co/t/unassigned-shards-with-status-elasticsearch-can-allocate-the-shard-for-all-of-them/333806 "2023-05-19T09:49:27Z")

</div>

Can you help me to explain why I have for several days 25 unassigned replica shards wich can\_allocate status = yes and allocation\_explanation = Elasticsearch can allocate the shard. I supposed rebalancing job will alloc…

---

## [Logstash is not working properly. \_grokparsefailure](https://discuss.elastic.co/t/logstash-is-not-working-properly-grokparsefailure/333851)

<div class="topic-metadata">

**Author:** [@San9](https://discuss.elastic.co/u/San9)\
**Replies:** 0\
**Last updated:** [May 19, 2023, 9:07am UTC](https://discuss.elastic.co/t/logstash-is-not-working-properly-grokparsefailure/333851 "2023-05-19T09:07:16Z")

</div>

strange behavior of the logstash, everything is parsed in the debugger, but not in the config - gives an error - \_grokparsefailure my logs 10.10.10.10.1680263940261.385400.G\_B2C\_BETA,03/31/2023 15:02:05.465,sf\_sap\_put\_…

---

## [Logstash JDBC input plugin: Java::OrgPostgresqlUtil::PSQLException: An I/O error occurred while sending to the backend](https://discuss.elastic.co/t/logstash-jdbc-input-plugin-java-an-i-o-error-occurred-while-sending-to-the-backend/333848)

<div class="topic-metadata">

**Author:** [@Captain](https://discuss.elastic.co/u/Captain)\
**Replies:** 0\
**Last updated:** [May 19, 2023, 7:46am UTC](https://discuss.elastic.co/t/logstash-jdbc-input-plugin-java-an-i-o-error-occurred-while-sending-to-the-backend/333848 "2023-05-19T07:46:32Z")

</div>

I encountered this problem some time ago and have not been able to find a good solution. Finally, after I modified the configuration in the jvm.options file, the problem did not occur again. The original configuration "-…

---

## [Disk space is 100% after running a "delete by query" in devtool in kibana](https://discuss.elastic.co/t/disk-space-is-100-after-running-a-delete-by-query-in-devtool-in-kibana/333647)

<div class="topic-metadata">

**Author:** [@sanjeevtomar](https://discuss.elastic.co/u/sanjeevtomar)\
**Replies:** 5\
**Last updated:** [May 19, 2023, 5:24am UTC](https://discuss.elastic.co/t/disk-space-is-100-after-running-a-delete-by-query-in-devtool-in-kibana/333647 "2023-05-19T05:24:34Z")

</div>

After running the query below, server space is getting full in all data nodes ( ELK cluster: 3 masters, 3 data, 1 kibana node). POST /apic\_sandbox/\_delete\_by\_query?wait\_for\_completion=false //change index here accordi…

[Previous page](https://discuss.elastic.co/tag/none.md?no_tags=true&page=374)

[Next page](https://discuss.elastic.co/tag/none.md?no_tags=true&page=376)
