# \#none

**URL:** https://discuss.elastic.co/tag/none.md?no_tags=true&page=380

[Latest](https://discuss.elastic.co/latest.md) · [Categories](https://discuss.elastic.co/categories.md) · [Tags](https://discuss.elastic.co/tags.md)

**Page:** 381

---

## [Fleet server does not have a liveness probe, thus it cannot be auto-restarted even if it fails](https://discuss.elastic.co/t/fleet-server-does-not-have-a-liveness-probe-thus-it-cannot-be-auto-restarted-even-if-it-fails/333371)

<div class="topic-metadata">

**Author:** [@fzyzcjy](https://discuss.elastic.co/u/fzyzcjy)\
**Replies:** 0\
**Last updated:** [May 14, 2023, 5:21am UTC](https://discuss.elastic.co/t/fleet-server-does-not-have-a-liveness-probe-thus-it-cannot-be-auto-restarted-even-if-it-fails/333371 "2023-05-14T05:21:43Z")

</div>

Hi thanks for elastic stack! However, Fleet server does not have a liveness probe (when deployed via ECK), thus it cannot be auto-restarted even if it fails.

---

## [Difference duration calculation between start and end time to show in table](https://discuss.elastic.co/t/difference-duration-calculation-between-start-and-end-time-to-show-in-table/330137)

<div class="topic-metadata">

**Author:** [@PRASHANT\_MEHTA](https://discuss.elastic.co/u/PRASHANT_MEHTA)\
**Replies:** 1\
**Last updated:** [May 14, 2023, 4:34am UTC](https://discuss.elastic.co/t/difference-duration-calculation-between-start-and-end-time-to-show-in-table/330137 "2023-05-14T04:34:03Z")

</div>

Hello All, I'd like to know how can I calculate the duration difference between start execution-end execution(Date format) and only get the duration to show in third column. How can this be done?,backend only provides …

---

## [Could not able to install ELK in windows11](https://discuss.elastic.co/t/could-not-able-to-install-elk-in-windows11/333369)

<div class="topic-metadata">

**Author:** [@priyanka\_g](https://discuss.elastic.co/u/priyanka_g)\
**Replies:** 1\
**Last updated:** [May 14, 2023, 3:47am UTC](https://discuss.elastic.co/t/could-not-able-to-install-elk-in-windows11/333369 "2023-05-14T03:47:52Z")

</div>

Hi Team, As i need to do pattern analysis for log files. i had downloaded Elasticsearch, Kibana and Logstack. But when i gave "elasticsearch.bat" in the command prompt, it is not getting installed properly, instead i…

---

## [Integration Ingest pipeline not executed when logstash ouptut is activated for Agent Policy (Fleet)](https://discuss.elastic.co/t/integration-ingest-pipeline-not-executed-when-logstash-ouptut-is-activated-for-agent-policy-fleet/332936)

<div class="topic-metadata">

**Author:** [@mehdi-lamrani](https://discuss.elastic.co/u/mehdi-lamrani)\
**Replies:** 3\
**Last updated:** [May 13, 2023, 1:12pm UTC](https://discuss.elastic.co/t/integration-ingest-pipeline-not-executed-when-logstash-ouptut-is-activated-for-agent-policy-fleet/332936 "2023-05-13T13:12:27Z")

</div>

8.7 here For some obscure reason, when I add a pipeline to an integration via Custom configurations (lower red rectangle in first screen below), it is not triggered when the policy integration output is set to logstash…

---

## [Logstash Limits](https://discuss.elastic.co/t/logstash-limits/331353)

<div class="topic-metadata">

**Author:** [@shushuu](https://discuss.elastic.co/u/shushuu)\
**Replies:** 4\
**Last updated:** [May 13, 2023, 12:32pm UTC](https://discuss.elastic.co/t/logstash-limits/331353 "2023-05-13T12:32:13Z")

</div>

Hi, We would like to use Logstash to receive log messages from multiple services (nxlog) and send them further to Elastic. i.e. using this architecture - but with nxlog instead of Beats: What are the limits of a si…

---

## [Custom Sample data - same sata reoccuring every week](https://discuss.elastic.co/t/custom-sample-data-same-sata-reoccuring-every-week/333348)

<div class="topic-metadata">

**Author:** [@Rnx](https://discuss.elastic.co/u/Rnx)\
**Replies:** 0\
**Last updated:** [May 13, 2023, 12:27pm UTC](https://discuss.elastic.co/t/custom-sample-data-same-sata-reoccuring-every-week/333348 "2023-05-13T12:27:51Z")

</div>

How to achieve a configuration in an Elasticsearch/Kibana, which will handle my custom sample data to be shown as reoccurring for, lets say, every week? Just like the essential "Kibana Sample Data" - these are clearly li…

---

## [Unique Doc related to one \`field\`](https://discuss.elastic.co/t/unique-doc-related-to-one-field/333344)

<div class="topic-metadata">

**Author:** [@\_zogaj](https://discuss.elastic.co/u/_zogaj)\
**Replies:** 0\
**Last updated:** [May 13, 2023, 6:02am UTC](https://discuss.elastic.co/t/unique-doc-related-to-one-field/333344 "2023-05-13T06:02:38Z")

</div>

Hey, I am using pagination and i want to filter duplicated doc related to one field. For the moment i am trying it with Collapse functionality to filter duplicated and with Cardinality aggregation to get the total unique…

---

## [Increase heap size of Elastic Cluster in dev tools](https://discuss.elastic.co/t/increase-heap-size-of-elastic-cluster-in-dev-tools/333165)

<div class="topic-metadata">

**Author:** [@Sandeep\_Raju](https://discuss.elastic.co/u/Sandeep_Raju)\
**Replies:** 1\
**Last updated:** [May 13, 2023, 4:56am UTC](https://discuss.elastic.co/t/increase-heap-size-of-elastic-cluster-in-dev-tools/333165 "2023-05-13T04:56:25Z")

</div>

Hi all, I'm trying to increase Elastic RAM alloted to Elastic. I know i have to change -Xmx=1G -Xms=1G in jvm options file. But I have access only to elastic and kibana. Is there a way to increase in dev tools or a…

---

## [Automation adding the password for basic security step #2 in Elasticsearch 7](https://discuss.elastic.co/t/automation-adding-the-password-for-basic-security-step-2-in-elasticsearch-7/333335)

<div class="topic-metadata">

**Author:** [@Chuck\_Reynolds](https://discuss.elastic.co/u/Chuck_Reynolds)\
**Replies:** 5\
**Last updated:** [May 12, 2023, 8:05pm UTC](https://discuss.elastic.co/t/automation-adding-the-password-for-basic-security-step-2-in-elasticsearch-7/333335 "2023-05-12T20:05:31Z")

</div>

How can I automate step 2 and pass a password to the following 2 commands? ./bin/elasticsearch-keystore add xpack.security.transport.ssl.keystore.secure\_password. ./bin/elasticsearch-keystore add xpack.security.transpo…

---

## [Suricata Logs Not Received by Elastic Cloud](https://discuss.elastic.co/t/suricata-logs-not-received-by-elastic-cloud/333334)

<div class="topic-metadata">

**Author:** [@Tim\_Mobley](https://discuss.elastic.co/u/Tim_Mobley)\
**Replies:** 0\
**Last updated:** [May 12, 2023, 6:19pm UTC](https://discuss.elastic.co/t/suricata-logs-not-received-by-elastic-cloud/333334 "2023-05-12T18:19:11Z")

</div>

I have set up both the 'Windows' and 'Suricata' integrations, using the same Agent Policy. Both integrations are showing that my client machine is connected. On the client, I have installed the Elastic Agent, however onl…

---

## [Tema integration message formatting for alert](https://discuss.elastic.co/t/tema-integration-message-formatting-for-alert/333321)

<div class="topic-metadata">

**Author:** [@Gaston\_Beltramelli](https://discuss.elastic.co/u/Gaston_Beltramelli)\
**Replies:** 1\
**Last updated:** [May 12, 2023, 6:04pm UTC](https://discuss.elastic.co/t/tema-integration-message-formatting-for-alert/333321 "2023-05-12T18:04:06Z")

</div>

Hello everyone! I need help for formatting an alert to TEAMS integration, i've been trying to add a new line in the message but i couldn´t find much info about t in kibana i set up this Alerta para {{context.group}} {…

---

## [Aggregations count vs hits count](https://discuss.elastic.co/t/aggregations-count-vs-hits-count/332648)

<div class="topic-metadata">

**Author:** [@NNI](https://discuss.elastic.co/u/NNI)\
**Replies:** 3\
**Last updated:** [May 12, 2023, 5:01pm UTC](https://discuss.elastic.co/t/aggregations-count-vs-hits-count/332648 "2023-05-12T17:01:11Z")

</div>

Hi I would like to concern on aggregations count for explain in more details But for the sake of presenting the case a little background : I have cluster contains with 3 master nodes, 3 ingest nodes, 3 data nodes so t…

---

## [Show which tokens were not found in full text search](https://discuss.elastic.co/t/show-which-tokens-were-not-found-in-full-text-search/333331)

<div class="topic-metadata">

**Author:** [@kadermetov](https://discuss.elastic.co/u/kadermetov)\
**Replies:** 0\
**Last updated:** [May 12, 2023, 4:48pm UTC](https://discuss.elastic.co/t/show-which-tokens-were-not-found-in-full-text-search/333331 "2023-05-12T16:48:34Z")

</div>

Hello, beautiful community! Is there a way to determine which words (tokens) in a phrase was or wasn't found during full text search. I need it to make something like Google does: Under each query result it shows wh…

---

## [An error occurred during rule execution: message: "Parse Error: Header overflow"](https://discuss.elastic.co/t/an-error-occurred-during-rule-execution-message-parse-error-header-overflow/330017)

<div class="topic-metadata">

**Author:** [@kmz161](https://discuss.elastic.co/u/kmz161)\
**Replies:** 1\
**Last updated:** [May 12, 2023, 4:23pm UTC](https://discuss.elastic.co/t/an-error-occurred-during-rule-execution-message-parse-error-header-overflow/330017 "2023-05-12T16:23:03Z")

</div>

Hello! I have problem with Security Rules. This issue only affects the Threshold rules How can I fix issue? P.S. Elastic 7.17

---

## [Elastic prebuilt rules not executed](https://discuss.elastic.co/t/elastic-prebuilt-rules-not-executed/330816)

<div class="topic-metadata">

**Author:** [@amatol1515](https://discuss.elastic.co/u/amatol1515)\
**Replies:** 1\
**Last updated:** [May 12, 2023, 4:03pm UTC](https://discuss.elastic.co/t/elastic-prebuilt-rules-not-executed/330816 "2023-05-12T16:03:55Z")

</div>

Hi Some of prebuilt rules not executed e.q. Execution result screen But when I duplicate this rules it works Execution results of Duplicated rule

---

## [About ELK STack](https://discuss.elastic.co/t/about-elk-stack/333296)

<div class="topic-metadata">

**Author:** [@Anil\_Sai\_Pinnelli](https://discuss.elastic.co/u/Anil_Sai_Pinnelli)\
**Replies:** 1\
**Last updated:** [May 12, 2023, 3:54pm UTC](https://discuss.elastic.co/t/about-elk-stack/333296 "2023-05-12T15:54:55Z")

</div>

Commands to link Mysql DB to elasticsearch using logstash. I am having one configuration file but, it did'nt worked for me!! input { jdbc { jdbc\_driver\_library =\> "/root/mysql-connector-java-5.1.30-bin.jar" jdbc\_dri…

---

## [Verify internode communication is using TLS](https://discuss.elastic.co/t/verify-internode-communication-is-using-tls/332975)

<div class="topic-metadata">

**Author:** [@mikewillis](https://discuss.elastic.co/u/mikewillis)\
**Replies:** 5\
**Last updated:** [May 12, 2023, 2:51pm UTC](https://discuss.elastic.co/t/verify-internode-communication-is-using-tls/332975 "2023-05-12T14:51:18Z")

</div>

Having set up TLS for internode communication per is there a way to confirm that is is being used? E.g. is there something specific that gets written to the log during start up when it's in use, or is there something t…

---

## [How to determine the bottleneck between Filebeat and ES?](https://discuss.elastic.co/t/how-to-determine-the-bottleneck-between-filebeat-and-es/333272)

<div class="topic-metadata">

**Author:** [@hjazz6](https://discuss.elastic.co/u/hjazz6)\
**Replies:** 2\
**Last updated:** [May 12, 2023, 2:48pm UTC](https://discuss.elastic.co/t/how-to-determine-the-bottleneck-between-filebeat-and-es/333272 "2023-05-12T14:48:01Z")

</div>

Hi, I'm trying to determine the bottleneck for my Netflow setup, to see if I can further optimize the performance. I am ingesting Netflow traffic into a Linux server running both filebeat and elasticsearch 7.1.4. I'm u…

---

## [CSV Response Data Format from SQL Rest API](https://discuss.elastic.co/t/csv-response-data-format-from-sql-rest-api/333224)

<div class="topic-metadata">

**Author:** [@Akaash\_Mukherjee](https://discuss.elastic.co/u/Akaash_Mukherjee)\
**Replies:** 2\
**Last updated:** [May 12, 2023, 2:20pm UTC](https://discuss.elastic.co/t/csv-response-data-format-from-sql-rest-api/333224 "2023-05-12T14:20:12Z")

</div>

Hi, I was told in a previous post: that Elasticsearch cannot return csv as response data: Then I found this: I've been trying to play around with it, but must admit I'm a little lost. I have a Kibana query that lo…

---

## [3 Node Elasticsearch cluster is failing repeatedly with error: this node is unhealthy: health check failed due to broken node lock](https://discuss.elastic.co/t/3-node-elasticsearch-cluster-is-failing-repeatedly-with-error-this-node-is-unhealthy-health-check-failed-due-to-broken-node-lock/333234)

<div class="topic-metadata">

**Author:** [@akansha.agarwal1](https://discuss.elastic.co/u/akansha.agarwal1)\
**Replies:** 3\
**Last updated:** [May 12, 2023, 1:17pm UTC](https://discuss.elastic.co/t/3-node-elasticsearch-cluster-is-failing-repeatedly-with-error-this-node-is-unhealthy-health-check-failed-due-to-broken-node-lock/333234 "2023-05-12T13:17:16Z")

</div>

Hi All, I am stuck in a very weird situation. My 3-node ES cluster is failing after 8-10 days abruptly with error: \[WARN \]\[o.e.c.c.ClusterFormationFailureHelper\] \[elasticsearch-0.es-service\] this node is unhealthy: he…

---

## [Create a new index when document has a particular field?](https://discuss.elastic.co/t/create-a-new-index-when-document-has-a-particular-field/333307)

<div class="topic-metadata">

**Author:** [@searchwithme](https://discuss.elastic.co/u/searchwithme)\
**Replies:** 1\
**Last updated:** [May 12, 2023, 1:06pm UTC](https://discuss.elastic.co/t/create-a-new-index-when-document-has-a-particular-field/333307 "2023-05-12T13:06:15Z")

</div>

Is it possible to create a new index everytime my document has a particular field updated? say all docs with 'tenant':"100" are part of one index and if a document comes with a field "tenant":101, a new index is created…

---

## [Index Thread Pools](https://discuss.elastic.co/t/index-thread-pools/333302)

<div class="topic-metadata">

**Author:** [@Mohit\_Munjal](https://discuss.elastic.co/u/Mohit_Munjal)\
**Replies:** 1\
**Last updated:** [May 12, 2023, 12:54pm UTC](https://discuss.elastic.co/t/index-thread-pools/333302 "2023-05-12T12:54:34Z")

</div>

My objective is to calculate how many index requests can a elasticsearch cluster hold in it's queue before starting rejecting it. My elasticsearch cluster(v6.8) has 8 data nodes of r5.xlarge instance i.e. 4 vCPU's. In …

---

## [How many resources should I have per data?](https://discuss.elastic.co/t/how-many-resources-should-i-have-per-data/333305)

<div class="topic-metadata">

**Author:** [@SamuelSMendes](https://discuss.elastic.co/u/SamuelSMendes)\
**Replies:** 0\
**Last updated:** [May 12, 2023, 12:59pm UTC](https://discuss.elastic.co/t/how-many-resources-should-i-have-per-data/333305 "2023-05-12T12:59:47Z")

</div>

My team has changed from On Premisse into the Cloud and as we are now centralizing all of our content into the same place I would like to estimate the resource power we need to escalate per GB generated a day (or maybe t…

---

## [Using Contains string or "wildcard" in filter button](https://discuss.elastic.co/t/using-contains-string-or-wildcard-in-filter-button/333247)

<div class="topic-metadata">

**Author:** [@Sandeep\_Raju](https://discuss.elastic.co/u/Sandeep_Raju)\
**Replies:** 1\
**Last updated:** [May 12, 2023, 11:28am UTC](https://discuss.elastic.co/t/using-contains-string-or-wildcard-in-filter-button/333247 "2023-05-12T11:28:25Z")

</div>

Hi all, I'm trying to use "wildcard" option in filter as shown below i.e location.keyword : \*PASO\* show me any string that contains PASO string anywhere in the word. I know I can use in KQL in search bar or DSL quer…

---

## [How do I 'Update All Fields Where'](https://discuss.elastic.co/t/how-do-i-update-all-fields-where/333293)

<div class="topic-metadata">

**Author:** [@ste1](https://discuss.elastic.co/u/ste1)\
**Replies:** 0\
**Last updated:** [May 12, 2023, 11:21am UTC](https://discuss.elastic.co/t/how-do-i-update-all-fields-where/333293 "2023-05-12T11:21:05Z")

</div>

I have a few different indicies that have logs in them that were digested using Logstash. The filter in my config looks like this: filter { csv { autodetect\_column\_names =\> false columns =\> \["uid", "ip"\] …

---

## [Why does the performance difference occur when searching in the regular or keyword field?](https://discuss.elastic.co/t/why-does-the-performance-difference-occur-when-searching-in-the-regular-or-keyword-field/333289)

<div class="topic-metadata">

**Author:** [@Ruveyda\_Aksoy](https://discuss.elastic.co/u/Ruveyda_Aksoy)\
**Replies:** 0\
**Last updated:** [May 12, 2023, 11:13am UTC](https://discuss.elastic.co/t/why-does-the-performance-difference-occur-when-searching-in-the-regular-or-keyword-field/333289 "2023-05-12T11:13:39Z")

</div>

Hi, I have a question regarding query performance. The data types of the fields I am querying are as follows. "primaryIdentificationNumber" : { "type" : "keyword", "fields" : { …

---

## [Collapse feature and total\_hist after collapse](https://discuss.elastic.co/t/collapse-feature-and-total-hist-after-collapse/333288)

<div class="topic-metadata">

**Author:** [@\_zogaj](https://discuss.elastic.co/u/_zogaj)\
**Replies:** 0\
**Last updated:** [May 12, 2023, 11:12am UTC](https://discuss.elastic.co/t/collapse-feature-and-total-hist-after-collapse/333288 "2023-05-12T11:12:41Z")

</div>

As Elastisearch documantion said: The total number of hits in the response indicates the number of matching documents without collapsing. The total number of distinct group is unknown. I am using a search with paginatio…

---

## [Illegal\_argument\_exception: index.lifecycle.rollover\_alias \[nginx\_uat\_test-frontend\_mobile-test\] does not point to index \[nginx\_uat\_test-frontend\_mobile\_2023.05.12\]](https://discuss.elastic.co/t/illegal-argument-exception-index-lifecycle-rollover-alias-nginx-uat-test-frontend-mobile-test-does-not-point-to-index-nginx-uat-test-frontend-mobile-2023-05-12/333276)

<div class="topic-metadata">

**Author:** [@Alwyn\_Tiu](https://discuss.elastic.co/u/Alwyn_Tiu)\
**Replies:** 0\
**Last updated:** [May 12, 2023, 9:54am UTC](https://discuss.elastic.co/t/illegal-argument-exception-index-lifecycle-rollover-alias-nginx-uat-test-frontend-mobile-test-does-not-point-to-index-nginx-uat-test-frontend-mobile-2023-05-12/333276 "2023-05-12T09:54:03Z")

</div>

Rule： { "del-test" : { "version" : 1, "modified\_date" : "2023-05-11T09:30:54.350Z", "policy" : { "phases" : { "hot" : { "min\_age" : "0ms", "actions" : { "rollover" : { "max\_age" : "1d" }, "set\_priority" : { …

---

## [Timeline template change timefilter to @timestamp instead of event.ingested?](https://discuss.elastic.co/t/timeline-template-change-timefilter-to-timestamp-instead-of-event-ingested/333087)

<div class="topic-metadata">

**Author:** [@elk\_jh](https://discuss.elastic.co/u/elk_jh)\
**Replies:** 2\
**Last updated:** [May 12, 2023, 8:54am UTC](https://discuss.elastic.co/t/timeline-template-change-timefilter-to-timestamp-instead-of-event-ingested/333087 "2023-05-12T08:54:44Z")

</div>

Hello~ I'm having an issue where I use a timeline template in the investigate in timeline feature of a rule in elastic security. When we create the rule, we override the timestamp to event.ingested. Our logs has a lag du…

---

## [Parse Array of JSON object](https://discuss.elastic.co/t/parse-array-of-json-object/333034)

<div class="topic-metadata">

**Author:** [@Nurm](https://discuss.elastic.co/u/Nurm)\
**Replies:** 4\
**Last updated:** [May 12, 2023, 7:10am UTC](https://discuss.elastic.co/t/parse-array-of-json-object/333034 "2023-05-12T07:10:55Z")

</div>

input { jdbc { jdbc\_connection\_string =\> "jdbc:postgresql://localhost:5432/db" jdbc\_user =\> "user" jdbc\_password =\> "pass" jdbc\_driver\_library =\> "/usr/share/logstash/lib/postgresql-42…

[Previous page](https://discuss.elastic.co/tag/none.md?no_tags=true&page=379)

[Next page](https://discuss.elastic.co/tag/none.md?no_tags=true&page=381)
