# \#none

**URL:** https://discuss.elastic.co/tag/none.md?no_tags=true&page=381

[Latest](https://discuss.elastic.co/latest.md) · [Categories](https://discuss.elastic.co/categories.md) · [Tags](https://discuss.elastic.co/tags.md)

**Page:** 382

---

## [Index deletion error due to change from Gold to Basic license](https://discuss.elastic.co/t/index-deletion-error-due-to-change-from-gold-to-basic-license/329974)

<div class="topic-metadata">

**Author:** [@kazuo](https://discuss.elastic.co/u/kazuo)\
**Replies:** 4\
**Last updated:** [May 12, 2023, 6:36am UTC](https://discuss.elastic.co/t/index-deletion-error-due-to-change-from-gold-to-basic-license/329974 "2023-05-12T06:36:32Z")

</div>

Hello, I was using a GOLD license, but did not renew my contract and I did not renew the contract and switched to the free version. One week after the switchover I received the following message ERROR Failed to compl…

---

## [I want to split from filed value using logstash](https://discuss.elastic.co/t/i-want-to-split-from-filed-value-using-logstash/333059)

<div class="topic-metadata">

**Author:** [@dharminfadia](https://discuss.elastic.co/u/dharminfadia)\
**Replies:** 7\
**Last updated:** [May 12, 2023, 6:12am UTC](https://discuss.elastic.co/t/i-want-to-split-from-filed-value-using-logstash/333059 "2023-05-12T06:12:50Z")

</div>

@warkolm @Badger help me.... Hello Everyone I am trying to split recipient-status feild first 3 digit and want to add in to new feild I tried mutate split and add filed but no luck can any one suggest how I can achiv…

---

## [Bug of /\_nlpcn/sql with subqueries](https://discuss.elastic.co/t/bug-of-nlpcn-sql-with-subqueries/333243)

<div class="topic-metadata">

**Author:** [@liuchsh01](https://discuss.elastic.co/u/liuchsh01)\
**Replies:** 1\
**Last updated:** [May 12, 2023, 3:51am UTC](https://discuss.elastic.co/t/bug-of-nlpcn-sql-with-subqueries/333243 "2023-05-12T03:51:44Z")

</div>

After using the /\_nlpcn/sql interface to query the sql with subqueries, some subsequent queries will time out. sql sample: SELECT count(\*) FROM a\_index where someCode in (SELECT code FROM b\_index where someType ='ttt') …

---

## [Need input for ideal master and data node cluster for elastic search](https://discuss.elastic.co/t/need-input-for-ideal-master-and-data-node-cluster-for-elastic-search/333231)

<div class="topic-metadata">

**Author:** [@susmithabadam1609](https://discuss.elastic.co/u/susmithabadam1609)\
**Replies:** 2\
**Last updated:** [May 12, 2023, 3:16am UTC](https://discuss.elastic.co/t/need-input-for-ideal-master-and-data-node-cluster-for-elastic-search/333231 "2023-05-12T03:16:38Z")

</div>

Hi Team, I am trying to deploy Elasticsearch version "8.7.0" and I am currently using "2.7.0" eck operator. I need to deploy Elasticsearch in master-data architecture. Could you please share the ideal(recommended) num…

---

## [Trouble with installing ECK on my RKE2 Kubernetes cluster](https://discuss.elastic.co/t/trouble-with-installing-eck-on-my-rke2-kubernetes-cluster/330773)

<div class="topic-metadata">

**Author:** [@Michael\_Anthony](https://discuss.elastic.co/u/Michael_Anthony)\
**Replies:** 11\
**Last updated:** [May 12, 2023, 12:51am UTC](https://discuss.elastic.co/t/trouble-with-installing-eck-on-my-rke2-kubernetes-cluster/330773 "2023-05-12T00:51:33Z")

</div>

I'm just trying to follow the instructions on the elastic docs for their quick start guide to deploy ECK on my cluster and I can't get the "quickstart-es-default-0" pod to spin up. I'm following all the instructions. Do…

---

## [Logstash error connecting to ElasticSearch](https://discuss.elastic.co/t/logstash-error-connecting-to-elasticsearch/333168)

<div class="topic-metadata">

**Author:** [@audric\_w](https://discuss.elastic.co/u/audric_w)\
**Replies:** 3\
**Last updated:** [May 11, 2023, 10:29pm UTC](https://discuss.elastic.co/t/logstash-error-connecting-to-elasticsearch/333168 "2023-05-11T22:29:15Z")

</div>

I've tried to created sidecar using beats and logstash on OpenShift. However the logstash always attempted to resurrect connection to dead ES instance (to http://elastisearch:9200), despite configs that I've done. Logst…

---

## [Filter Windows Device Scanning from Direct Outbound SMB Connection rule](https://discuss.elastic.co/t/filter-windows-device-scanning-from-direct-outbound-smb-connection-rule/332248)

<div class="topic-metadata">

**Author:** [@Thyrum](https://discuss.elastic.co/u/Thyrum)\
**Replies:** 1\
**Last updated:** [May 11, 2023, 10:11pm UTC](https://discuss.elastic.co/t/filter-windows-device-scanning-from-direct-outbound-smb-connection-rule/332248 "2023-05-11T22:11:06Z")

</div>

Hi, We have been trying to filter out windows device scanning from our Direct Outbound SMB Connection rule logs. As is mentioned in the first note of Configure device discovery | Microsoft Learn, these SMB connections a…

---

## [Version conflict, document already exists (current version \[1\])](https://discuss.elastic.co/t/version-conflict-document-already-exists-current-version-1/333107)

<div class="topic-metadata">

**Author:** [@elasticforme](https://discuss.elastic.co/u/elasticforme)\
**Replies:** 11\
**Last updated:** [May 11, 2023, 8:46pm UTC](https://discuss.elastic.co/t/version-conflict-document-already-exists-current-version-1/333107 "2023-05-11T20:46:01Z")

</div>

I am running metricbeat on few system. sending that data to proxy server. proxy then sends data to two logstash servers logstash then parse this and stores records in Elasticsearch. I am creating my own \_id for each …

---

## [Index Pattern might be treated as substring of other Index Pattern](https://discuss.elastic.co/t/index-pattern-might-be-treated-as-substring-of-other-index-pattern/333220)

<div class="topic-metadata">

**Author:** [@paolovalladolid](https://discuss.elastic.co/u/paolovalladolid)\
**Replies:** 1\
**Last updated:** [May 11, 2023, 7:51pm UTC](https://discuss.elastic.co/t/index-pattern-might-be-treated-as-substring-of-other-index-pattern/333220 "2023-05-11T19:51:51Z")

</div>

We have 2 servers running Winlogbeat. Server 1 Winlogbeat has this index pattern configured: developer-portal-%{+yyyyMMdd} Server 2 Winlogbeat has this index pattern configured: developer-portal-hydrator-%{+yyyyMMdd} …

---

## [Change IP of single node instance](https://discuss.elastic.co/t/change-ip-of-single-node-instance/333133)

<div class="topic-metadata">

**Author:** [@Dusty\_Boley](https://discuss.elastic.co/u/Dusty_Boley)\
**Replies:** 2\
**Last updated:** [May 11, 2023, 7:12pm UTC](https://discuss.elastic.co/t/change-ip-of-single-node-instance/333133 "2023-05-11T19:12:05Z")

</div>

Hello all, if this info is somewhere and my search missed it I apologize. Also, I am an Elasticsearch noob so my apologies if I mix up terminology. I have a simple single node setup running version 8.7 to service a sma…

---

## [Deprecation Log Spam](https://discuss.elastic.co/t/deprecation-log-spam/332851)

<div class="topic-metadata">

**Author:** [@wwalker](https://discuss.elastic.co/u/wwalker)\
**Replies:** 2\
**Last updated:** [May 11, 2023, 3:43pm UTC](https://discuss.elastic.co/t/deprecation-log-spam/332851 "2023-05-11T15:43:02Z")

</div>

The below line is blowing up my log files. What is it and what do I need to do to get it to stop? \[2023-05-03T22:10:15,259\]\[WARN \]\[o.e.d.c.m.IndexNameExpressionResolver\] \[elastic.contoso.net\] data\_stream.dataset="depre…

---

## [UpdateByQueryRequest.setMaxRetries does not seems available in ElasticSearch version 8 Java Client](https://discuss.elastic.co/t/updatebyqueryrequest-setmaxretries-does-not-seems-available-in-elasticsearch-version-8-java-client/333222)

<div class="topic-metadata">

**Author:** [@csplrj](https://discuss.elastic.co/u/csplrj)\
**Replies:** 0\
**Last updated:** [May 11, 2023, 3:41pm UTC](https://discuss.elastic.co/t/updatebyqueryrequest-setmaxretries-does-not-seems-available-in-elasticsearch-version-8-java-client/333222 "2023-05-11T15:41:42Z")

</div>

Below code is for Elasticsearch Client version 7.17. Can't find equivalent code in Elasticsearch Client version 8.7 Script storedScript = new Script(ScriptType.STORED, null, script.getScriptId(), (Map\<String, Object\>) s…

---

## [Question logstash | Events received vs Event emitted](https://discuss.elastic.co/t/question-logstash-events-received-vs-event-emitted/333219)

<div class="topic-metadata">

**Author:** [@ahmed\_charafouddine](https://discuss.elastic.co/u/ahmed_charafouddine)\
**Replies:** 0\
**Last updated:** [May 11, 2023, 3:20pm UTC](https://discuss.elastic.co/t/question-logstash-events-received-vs-event-emitted/333219 "2023-05-11T15:20:04Z")

</div>

Hello, On the monitoring part of my logstash instance, I see that I have 1.3b of events received against 784.7m events emitted. can the fact that I drop certain messages in my pipeline explain this phenomenon or is it r…

---

## [Fastest way to ingest CSV's with logstash to elasticsearch](https://discuss.elastic.co/t/fastest-way-to-ingest-csvs-with-logstash-to-elasticsearch/333118)

<div class="topic-metadata">

**Author:** [@Security\_Check](https://discuss.elastic.co/u/Security_Check)\
**Replies:** 8\
**Last updated:** [May 11, 2023, 3:19pm UTC](https://discuss.elastic.co/t/fastest-way-to-ingest-csvs-with-logstash-to-elasticsearch/333118 "2023-05-11T15:19:24Z")

</div>

I'm currently trying to ingest 100gb of csv files into elasticsearch through logstash. The issue is it's taking forever. I have narrowed down the columns I'm trying to filter for to 8 out of 71 but it still takes a long …

---

## [Multiple matches required](https://discuss.elastic.co/t/multiple-matches-required/333192)

<div class="topic-metadata">

**Author:** [@Jason\_Hall](https://discuss.elastic.co/u/Jason_Hall)\
**Replies:** 1\
**Last updated:** [May 11, 2023, 3:10pm UTC](https://discuss.elastic.co/t/multiple-matches-required/333192 "2023-05-11T15:10:31Z")

</div>

I am currently setting up some filters for my incoming Watchguard Firewall logs. The logs come in various different formats so i have to setup multiple match rules. My current filter is filter { #Watchguard logs filter…

---

## [Need to split in form of key & value](https://discuss.elastic.co/t/need-to-split-in-form-of-key-value/333218)

<div class="topic-metadata">

**Author:** [@ZERO\_COOL](https://discuss.elastic.co/u/ZERO_COOL)\
**Replies:** 0\
**Last updated:** [May 11, 2023, 2:40pm UTC](https://discuss.elastic.co/t/need-to-split-in-form-of-key-value/333218 "2023-05-11T14:40:09Z")

</div>

I am getting event as below. "rusage" =\> \[ \[0\] "", \[1\] "\[mem=10000,mem=5000,VCS-BASE-RUNTIME=1\]" \], I want the value of mem as res\_mem higher one among two keys with "mem" as new field. output: { res\_mem = 10000 …

---

## [Joining Two Indexes with common field values](https://discuss.elastic.co/t/joining-two-indexes-with-common-field-values/332861)

<div class="topic-metadata">

**Author:** [@sai\_ravi\_shankar](https://discuss.elastic.co/u/sai_ravi_shankar)\
**Replies:** 8\
**Last updated:** [May 11, 2023, 2:22pm UTC](https://discuss.elastic.co/t/joining-two-indexes-with-common-field-values/332861 "2023-05-11T14:22:30Z")

</div>

Hi, I am trying to join two indexes with common field values. Can someone please help me. Here is the example: Index\_1 =\> A column\_1 =\> value\_1 Index\_2 =\> B column\_2 =\> value\_1 How can i join both indexes on the…

---

## [Kibana showing windows\_eventlog but not sysmon](https://discuss.elastic.co/t/kibana-showing-windows-eventlog-but-not-sysmon/333104)

<div class="topic-metadata">

**Author:** [@iqworks](https://discuss.elastic.co/u/iqworks)\
**Replies:** 2\
**Last updated:** [May 11, 2023, 1:57pm UTC](https://discuss.elastic.co/t/kibana-showing-windows-eventlog-but-not-sysmon/333104 "2023-05-11T13:57:01Z")

</div>

Hi, I finally got windows data into security onion. But I dont see sysmon categories? But I do show windows\_events? are windows\_eventlogs the same as sysmon maybe? not sure. thanks for any suggestions or advice

---

## [If statement performance question](https://discuss.elastic.co/t/if-statement-performance-question/333210)

<div class="topic-metadata">

**Author:** [@mgotechlock](https://discuss.elastic.co/u/mgotechlock)\
**Replies:** 0\
**Last updated:** [May 11, 2023, 12:43pm UTC](https://discuss.elastic.co/t/if-statement-performance-question/333210 "2023-05-11T12:43:59Z")

</div>

Question If I use this IF statement, if ("FTNTFGTpolicyname" in \[message\]) or ("FTNTFGTlogid" in \[message\]) {, the CPU of the logstash server spikes to very high, pretty much forever. If I change it to this, CPU is …

---

## [Configuración formato metric count](https://discuss.elastic.co/t/configuracion-formato-metric-count/333031)

<div class="topic-metadata">

**Author:** [@Javier\_Garcia\_Alvare](https://discuss.elastic.co/u/Javier_Garcia_Alvare)\
**Replies:** 3\
**Last updated:** [May 11, 2023, 12:42pm UTC](https://discuss.elastic.co/t/configuracion-formato-metric-count/333031 "2023-05-11T12:42:23Z")

</div>

Buenos días, Es posible dar formato a una metrica en una visualización tipo tabla? Es decir, cuando creas una tabla y la metrica la configuras como "Sum Bucket" o "count" el número se alinea en la parte de la izquierda…

---

## [Grok regex match after CSV filter: unable to add a new field from grok match in logstash](https://discuss.elastic.co/t/grok-regex-match-after-csv-filter-unable-to-add-a-new-field-from-grok-match-in-logstash/333206)

<div class="topic-metadata">

**Author:** [@rj.elkadmin](https://discuss.elastic.co/u/rj.elkadmin)\
**Replies:** 0\
**Last updated:** [May 11, 2023, 12:24pm UTC](https://discuss.elastic.co/t/grok-regex-match-after-csv-filter-unable-to-add-a-new-field-from-grok-match-in-logstash/333206 "2023-05-11T12:24:26Z")

</div>

Hi team, I am new to here, i apologize for any inconvenient. I am looking for some help on my issue here, kindly assist. My requirement is to process data from csv files located in s3 bucket using Logstash and ingest i…

---

## [How to combine two records into one with logstash and call a filter script before save into Elasticsearch](https://discuss.elastic.co/t/how-to-combine-two-records-into-one-with-logstash-and-call-a-filter-script-before-save-into-elasticsearch/332957)

<div class="topic-metadata">

**Author:** [@liusanyong](https://discuss.elastic.co/u/liusanyong)\
**Replies:** 3\
**Last updated:** [May 11, 2023, 12:23pm UTC](https://discuss.elastic.co/t/how-to-combine-two-records-into-one-with-logstash-and-call-a-filter-script-before-save-into-elasticsearch/332957 "2023-05-11T12:23:38Z")

</div>

Hi, I want to do some aggregation and transformation with logstash for input data stream as following steps: Combine two input metric events for a single transaction coming from transaction server and database into o…

---

## [Adding Processors / Pipelines to an integration attached to a policy breaks running agent (Error creating runner from config: Can only start an input when all related states are finished)](https://discuss.elastic.co/t/adding-processors-pipelines-to-an-integration-attached-to-a-policy-breaks-running-agent-error-creating-runner-from-config-can-only-start-an-input-when-all-related-states-are-finished/332909)

<div class="topic-metadata">

**Author:** [@mehdi-lamrani](https://discuss.elastic.co/u/mehdi-lamrani)\
**Replies:** 1\
**Last updated:** [May 11, 2023, 12:14pm UTC](https://discuss.elastic.co/t/adding-processors-pipelines-to-an-integration-attached-to-a-policy-breaks-running-agent-error-creating-runner-from-config-can-only-start-an-input-when-all-related-states-are-finished/332909 "2023-05-11T12:14:52Z")

</div>

8.7 here, Pretty self explanatory. Steps in the screenshots. Error creating runner from config: Can only start an input when all related states are finished What does related states mean ? there is only that single in…

---

## [Getting error "Could not index event to Elasticsearch" in logstash?](https://discuss.elastic.co/t/getting-error-could-not-index-event-to-elasticsearch-in-logstash/333198)

<div class="topic-metadata">

**Author:** [@talbehat](https://discuss.elastic.co/u/talbehat)\
**Replies:** 1\
**Last updated:** [May 11, 2023, 11:47am UTC](https://discuss.elastic.co/t/getting-error-could-not-index-event-to-elasticsearch-in-logstash/333198 "2023-05-11T11:47:25Z")

</div>

Using Logstash version 7.4.3 logstash-filter-json plugin. filter { json { source =\> "message" } } logs are:- {"Event":"SparkListenerJobStart","Job ID":1,"Submission Time":1640751467318,"Stage Infos":\[{"Stage ID":…

---

## [I want to get a status based on the date difference ersult](https://discuss.elastic.co/t/i-want-to-get-a-status-based-on-the-date-difference-ersult/333054)

<div class="topic-metadata">

**Author:** [@alig](https://discuss.elastic.co/u/alig)\
**Replies:** 1\
**Last updated:** [May 11, 2023, 11:41am UTC](https://discuss.elastic.co/t/i-want-to-get-a-status-based-on-the-date-difference-ersult/333054 "2023-05-11T11:41:32Z")

</div>

Hi there, This is what I am using in scripted fields def sorDate = new Date().getTime() - doc\['sor\_idate'\].value; if (sorDate \> 5){ return "crtical" }; The field is defined as below and I have an error and cannot f…

---

## [Unable to create new index \[.watches-6-reindexed-for-8\] because it would match composable template \[.watches\]](https://discuss.elastic.co/t/unable-to-create-new-index-watches-6-reindexed-for-8-because-it-would-match-composable-template-watches/333202)

<div class="topic-metadata">

**Author:** [@fmkaiser](https://discuss.elastic.co/u/fmkaiser)\
**Replies:** 0\
**Last updated:** [May 11, 2023, 11:35am UTC](https://discuss.elastic.co/t/unable-to-create-new-index-watches-6-reindexed-for-8-because-it-would-match-composable-template-watches/333202 "2023-05-11T11:35:23Z")

</div>

Hello, when trying to migrate system indices to ES 8.x, I get the following error: unable to create new index \[.watches-6-reindexed-for-8\] because it would match composable template \[.watches\] full output We are cu…

---

## [How to disable a plugin in Logstash Configuration file](https://discuss.elastic.co/t/how-to-disable-a-plugin-in-logstash-configuration-file/333197)

<div class="topic-metadata">

**Author:** [@Rakhshunda\_Noorein\_J](https://discuss.elastic.co/u/Rakhshunda_Noorein_J)\
**Replies:** 0\
**Last updated:** [May 11, 2023, 11:00am UTC](https://discuss.elastic.co/t/how-to-disable-a-plugin-in-logstash-configuration-file/333197 "2023-05-11T11:00:52Z")

</div>

Hello, I have a configuration file with multiple plugins. I want to disable all plugin and run 1 plugin for some use cases...How can I do that. My config example- input { http\_poller { urls =\> { api1=\> { …

---

## ["\_cat/nodes" API reports "transport" IP instead of "http" IP](https://discuss.elastic.co/t/cat-nodes-api-reports-transport-ip-instead-of-http-ip/333166)

<div class="topic-metadata">

**Author:** [@Jeremy\_Lecour](https://discuss.elastic.co/u/Jeremy_Lecour)\
**Replies:** 2\
**Last updated:** [May 11, 2023, 10:40am UTC](https://discuss.elastic.co/t/cat-nodes-api-reports-transport-ip-instead-of-http-ip/333166 "2023-05-11T10:40:38Z")

</div>

Hi, I have a 2-nodes cluster with this setup for the networking configuration : http.host: \[\_local\_,\_ens192\_\] http.port: 9200 transport.host: \[\_ens161\_\] transport.port: 9300 And here is my network setup : # ip -br a…

---

## [Multiple Elasticsearch instances architecture](https://discuss.elastic.co/t/multiple-elasticsearch-instances-architecture/333187)

<div class="topic-metadata">

**Author:** [@jabulon](https://discuss.elastic.co/u/jabulon)\
**Replies:** 0\
**Last updated:** [May 11, 2023, 10:18am UTC](https://discuss.elastic.co/t/multiple-elasticsearch-instances-architecture/333187 "2023-05-11T10:18:53Z")

</div>

I am designing a solution based on many smaller Elasticsearch engines scattered around the world, and a single instance containing all of the data from all of the instances combined. I do not need the data to be up to da…

---

## [Elasticsearch - get logs from DMZ](https://discuss.elastic.co/t/elasticsearch-get-logs-from-dmz/332901)

<div class="topic-metadata">

**Author:** [@Sharon\_Hacham](https://discuss.elastic.co/u/Sharon_Hacham)\
**Replies:** 4\
**Last updated:** [May 11, 2023, 9:28am UTC](https://discuss.elastic.co/t/elasticsearch-get-logs-from-dmz/332901 "2023-05-11T09:28:48Z")

</div>

Hi , we have Elasticsearch cluster and now we want to stream logs from DMZ environment to there which isn't allowed by InfoSec purpose. Only allowed method of pull from the DMZ. What's the preferred option in such cas…

[Previous page](https://discuss.elastic.co/tag/none.md?no_tags=true&page=380)

[Next page](https://discuss.elastic.co/tag/none.md?no_tags=true&page=382)
