# \#none

**URL:** https://discuss.elastic.co/tag/none.md?no_tags=true&page=383

[Latest](https://discuss.elastic.co/latest.md) · [Categories](https://discuss.elastic.co/categories.md) · [Tags](https://discuss.elastic.co/tags.md)

**Page:** 384

---

## [Can I do a sum on the fields that have 'keyword' type](https://discuss.elastic.co/t/can-i-do-a-sum-on-the-fields-that-have-keyword-type/333076)

<div class="topic-metadata">

**Author:** [@searchwithme](https://discuss.elastic.co/u/searchwithme)\
**Replies:** 1\
**Last updated:** [May 10, 2023, 11:06am UTC](https://discuss.elastic.co/t/can-i-do-a-sum-on-the-fields-that-have-keyword-type/333076 "2023-05-10T11:06:31Z")

</div>

I have a field that is keyword type. The index looks like this: { "key": 1 }, { "key": 2 }, { "key": 3 }, { "key":"abc" }, { "key":"zyx" } Some values are numeric and some are strings. Is there a way to …

---

## [Check performance of cluster](https://discuss.elastic.co/t/check-performance-of-cluster/332996)

<div class="topic-metadata">

**Author:** [@NNI](https://discuss.elastic.co/u/NNI)\
**Replies:** 11\
**Last updated:** [May 10, 2023, 9:56am UTC](https://discuss.elastic.co/t/check-performance-of-cluster/332996 "2023-05-10T09:56:45Z")

</div>

Hi We're facing some performance issue cluster build on 9 nodes 3x ingest 3x master 3x data (on NVMe disks) index\_with\_data 2 r STARTED 10590253 elk\_es\_data-1 index\_with\_data 2 p …

---

## [Install and run Logstash tar file](https://discuss.elastic.co/t/install-and-run-logstash-tar-file/332899)

<div class="topic-metadata">

**Author:** [@hjsroldan](https://discuss.elastic.co/u/hjsroldan)\
**Replies:** 4\
**Last updated:** [May 10, 2023, 9:56am UTC](https://discuss.elastic.co/t/install-and-run-logstash-tar-file/332899 "2023-05-10T09:56:13Z")

</div>

Hi, Good day! Does anyone know how to install and run logstash in a tar format binary? Thank you! Best regards, Hasmine Joyce Roldan

---

## [JDBC plugin - issue getting binary data](https://discuss.elastic.co/t/jdbc-plugin-issue-getting-binary-data/332537)

<div class="topic-metadata">

**Author:** [@vymk](https://discuss.elastic.co/u/vymk)\
**Replies:** 1\
**Last updated:** [May 10, 2023, 9:25am UTC](https://discuss.elastic.co/t/jdbc-plugin-issue-getting-binary-data/332537 "2023-05-10T09:25:26Z")

</div>

I use the JDBC plugin to get data from a MSSQL database. Generally this is working but my query output includes MD5 hashes saved as binary, and then the output looks something like this in stdout (and even more gibberish…

---

## [Grok debugger works, on logstash not](https://discuss.elastic.co/t/grok-debugger-works-on-logstash-not/332930)

<div class="topic-metadata">

**Author:** [@psyskeletor](https://discuss.elastic.co/u/psyskeletor)\
**Replies:** 2\
**Last updated:** [May 10, 2023, 8:23am UTC](https://discuss.elastic.co/t/grok-debugger-works-on-logstash-not/332930 "2023-05-10T08:23:54Z")

</div>

Hi there. Super new to logstash. I wanted to extract exit code from logs, so i came with this solution using grok debugger filter { grok { match =\> { "message" =\> "(?\<exit\_code\>\\b\[exit code \]\\d+ \\b)" } …

---

## [Aggregating unique (timestamp) values](https://discuss.elastic.co/t/aggregating-unique-timestamp-values/333043)

<div class="topic-metadata">

**Author:** [@idrv](https://discuss.elastic.co/u/idrv)\
**Replies:** 0\
**Last updated:** [May 10, 2023, 8:13am UTC](https://discuss.elastic.co/t/aggregating-unique-timestamp-values/333043 "2023-05-10T08:13:27Z")

</div>

Hello, community! I hope my question doesn't double something already asked and answered here. I'm searching for the best way to store aggregated data in a dedicated index. In the best-case scenario, it should include …

---

## [What are the best ways to find near phrases? How to combine them to find near to nearest near? ))](https://discuss.elastic.co/t/what-are-the-best-ways-to-find-near-phrases-how-to-combine-them-to-find-near-to-nearest-near/333042)

<div class="topic-metadata">

**Author:** [@Eduard\_mart](https://discuss.elastic.co/u/Eduard_mart)\
**Replies:** 0\
**Last updated:** [May 10, 2023, 8:11am UTC](https://discuss.elastic.co/t/what-are-the-best-ways-to-find-near-phrases-how-to-combine-them-to-find-near-to-nearest-near/333042 "2023-05-10T08:11:59Z")

</div>

How to find nearest near. Example: "query" : { "query\_string": { "query": "\\"field korean\\"~10", "fields" : \["message.stemmed"\], "default\_operator": "AND" } It finds all strings that contain …

---

## [Remove all backslash from fields in logstash](https://discuss.elastic.co/t/remove-all-backslash-from-fields-in-logstash/333041)

<div class="topic-metadata">

**Author:** [@SmoZyNS](https://discuss.elastic.co/u/SmoZyNS)\
**Replies:** 0\
**Last updated:** [May 10, 2023, 8:08am UTC](https://discuss.elastic.co/t/remove-all-backslash-from-fields-in-logstash/333041 "2023-05-10T08:08:08Z")

</div>

Hello, what I am trying to do is to remove backslash as well as double quotes from fields after parsing them with kv. Here is the original input sent to logstash: \<14\>1 2023-05-09T15:06:23+02:00 NAS WinFileService - -…

---

## [Npx @elastic/synthetic Command Line Options for Selectively Deploying 'lightweight' Synthetics](https://discuss.elastic.co/t/npx-elastic-synthetic-command-line-options-for-selectively-deploying-lightweight-synthetics/330747)

<div class="topic-metadata">

**Author:** [@ameindel](https://discuss.elastic.co/u/ameindel)\
**Replies:** 3\
**Last updated:** [May 10, 2023, 7:26am UTC](https://discuss.elastic.co/t/npx-elastic-synthetic-command-line-options-for-selectively-deploying-lightweight-synthetics/330747 "2023-05-10T07:26:21Z")

</div>

Hello there, I was wondering if there is any undocumented functionality that allows one to selectively deploy 'lightweight' synthetics, similar to how 'journeys' synthetics can be selectively run using --pattern, --matc…

---

## [Issue with logsatsh](https://discuss.elastic.co/t/issue-with-logsatsh/330227)

<div class="topic-metadata">

**Author:** [@Hanni](https://discuss.elastic.co/u/Hanni)\
**Replies:** 38\
**Last updated:** [May 10, 2023, 6:34am UTC](https://discuss.elastic.co/t/issue-with-logsatsh/330227 "2023-05-10T06:34:23Z")

</div>

Hello, I am currently working on a subject. I am trying to parse my data in JSON format to store it in Elasticsearch, but Logstash is unable to parse my data and is generating errors. Can you help me?

---

## [Mapping conflict between two indexes of different versions of metricbeat](https://discuss.elastic.co/t/mapping-conflict-between-two-indexes-of-different-versions-of-metricbeat/333010)

<div class="topic-metadata">

**Author:** [@ElasticLiver](https://discuss.elastic.co/u/ElasticLiver)\
**Replies:** 7\
**Last updated:** [May 10, 2023, 5:19am UTC](https://discuss.elastic.co/t/mapping-conflict-between-two-indexes-of-different-versions-of-metricbeat/333010 "2023-05-10T05:19:15Z")

</div>

Hi, I have two metricbeats with diferent versions pointing to the same elasticsearch, the difference between their mapping is causing me problems when I try to use the control visualization in kibana. if i choose to u…

---

## [Trace source of authentication failures from logs](https://discuss.elastic.co/t/trace-source-of-authentication-failures-from-logs/333005)

<div class="topic-metadata">

**Author:** [@Russell\_Fulton](https://discuss.elastic.co/u/Russell_Fulton)\
**Replies:** 1\
**Last updated:** [May 10, 2023, 12:40am UTC](https://discuss.elastic.co/t/trace-source-of-authentication-failures-from-logs/333005 "2023-05-10T00:40:13Z")

</div>

I am seeing this log repeated twice a minute on one of my ES servers: \[2023-05-10T00:11:33,186\]\[WARN \]\[o.e.x.s.a.RealmsAuthenticator\] \[secesprd02\] Authentication to realm default\_native failed - Password authentication …

---

## [Not Able To Install Elastic Agent Onto Windows 10](https://discuss.elastic.co/t/not-able-to-install-elastic-agent-onto-windows-10/332971)

<div class="topic-metadata">

**Author:** [@mx09](https://discuss.elastic.co/u/mx09)\
**Replies:** 2\
**Last updated:** [May 9, 2023, 8:29pm UTC](https://discuss.elastic.co/t/not-able-to-install-elastic-agent-onto-windows-10/332971 "2023-05-09T20:29:52Z")

</div>

Error: unable to perform install command, not executed with Administrator permissions I've tried to add an Agent onto what will be my "Victim Machine" I'm doing this with the Kali Purple instance in a virtual environmen…

---

## [Form data in body for Logstash HTTP filter](https://discuss.elastic.co/t/form-data-in-body-for-logstash-http-filter/332574)

<div class="topic-metadata">

**Author:** [@analog\_memories](https://discuss.elastic.co/u/analog_memories)\
**Replies:** 2\
**Last updated:** [May 9, 2023, 7:18pm UTC](https://discuss.elastic.co/t/form-data-in-body-for-logstash-http-filter/332574 "2023-05-09T19:18:37Z")

</div>

Hello, I was wondering if anyone has had the syntax for using form data in the body of HTTP filter. I have tried all manor of ways to make it work, and searched the forums, but have not found anything. This post is pr…

---

## [Support for multiple named computed scores in a single search](https://discuss.elastic.co/t/support-for-multiple-named-computed-scores-in-a-single-search/332995)

<div class="topic-metadata">

**Author:** [@Krum\_Bakalsky](https://discuss.elastic.co/u/Krum_Bakalsky)\
**Replies:** 0\
**Last updated:** [May 9, 2023, 7:05pm UTC](https://discuss.elastic.co/t/support-for-multiple-named-computed-scores-in-a-single-search/332995 "2023-05-09T19:05:38Z")

</div>

Hello Elasticsearch community, When serving a given search query, our service is computing and using proximity score for each document in our index relative to the given query. This we currently implement by invoking th…

---

## [Is it preferable to use publicly signed certificates for fleet server?](https://discuss.elastic.co/t/is-it-preferable-to-use-publicly-signed-certificates-for-fleet-server/332732)

<div class="topic-metadata">

**Author:** [@learningelastic](https://discuss.elastic.co/u/learningelastic)\
**Replies:** 2\
**Last updated:** [May 9, 2023, 7:02pm UTC](https://discuss.elastic.co/t/is-it-preferable-to-use-publicly-signed-certificates-for-fleet-server/332732 "2023-05-09T19:02:27Z")

</div>

I'm reading through the documentation for fleet servers in elastic 8.7. On the subject of configuring TLS/SSL for fleet servers, I see this: Is it preferable to create certificates for fleet servers with ./bin/elasti…

---

## [Using a modal to display Elastic Search-UI results, but there is a weird lag where only part of the original search term is searched](https://discuss.elastic.co/t/using-a-modal-to-display-elastic-search-ui-results-but-there-is-a-weird-lag-where-only-part-of-the-original-search-term-is-searched/332973)

<div class="topic-metadata">

**Author:** [@Jonah\_Cornish\_Packer](https://discuss.elastic.co/u/Jonah_Cornish_Packer)\
**Replies:** 1\
**Last updated:** [May 9, 2023, 5:33pm UTC](https://discuss.elastic.co/t/using-a-modal-to-display-elastic-search-ui-results-but-there-is-a-weird-lag-where-only-part-of-the-original-search-term-is-searched/332973 "2023-05-09T17:33:12Z")

</div>

I have implemented Elastic's Search-UI on my website, where the user can enter their search term on the parent page and when they submit their search the results show up in a modal. The modal displays the search results …

---

## [Use new metric like legacy with Last value function on keyword field](https://discuss.elastic.co/t/use-new-metric-like-legacy-with-last-value-function-on-keyword-field/332927)

<div class="topic-metadata">

**Author:** [@Jonas\_S](https://discuss.elastic.co/u/Jonas_S)\
**Replies:** 3\
**Last updated:** [May 9, 2023, 3:31pm UTC](https://discuss.elastic.co/t/use-new-metric-like-legacy-with-last-value-function-on-keyword-field/332927 "2023-05-09T15:31:48Z")

</div>

Hello, i create one index per month, which are grouped in a data view. There is a keyword field in the index which contains a string representation of the month that the index was created like 'May 2023'. Up until now …

---

## [List all runtime fields in index pattern?](https://discuss.elastic.co/t/list-all-runtime-fields-in-index-pattern/332908)

<div class="topic-metadata">

**Author:** [@nisow95612](https://discuss.elastic.co/u/nisow95612)\
**Replies:** 4\
**Last updated:** [May 9, 2023, 3:28pm UTC](https://discuss.elastic.co/t/list-all-runtime-fields-in-index-pattern/332908 "2023-05-09T15:28:57Z")

</div>

Hello, sadly it seems Are runtime multi-fields possible? is not possible, so my question for today is: Is it possible to list all runtime fields for an index pattern in Kibana? I know I can dump the mapping for each i…

---

## [Will the elasticsearch input plugin of logstash ensure no repeat reading after restart?](https://discuss.elastic.co/t/will-the-elasticsearch-input-plugin-of-logstash-ensure-no-repeat-reading-after-restart/332962)

<div class="topic-metadata">

**Author:** [@liusanyong](https://discuss.elastic.co/u/liusanyong)\
**Replies:** 0\
**Last updated:** [May 9, 2023, 3:14pm UTC](https://discuss.elastic.co/t/will-the-elasticsearch-input-plugin-of-logstash-ensure-no-repeat-reading-after-restart/332962 "2023-05-09T15:14:19Z")

</div>

Hello, If use elasticsearch input plugin of logstash to read data from a elasticsearch index and do some processing. How to ensure it will not read repeated data after the logstash restarted ?

---

## [CVEs present in the latest version](https://discuss.elastic.co/t/cves-present-in-the-latest-version/332950)

<div class="topic-metadata">

**Author:** [@beltran-rubo](https://discuss.elastic.co/u/beltran-rubo)\
**Replies:** 1\
**Last updated:** [May 9, 2023, 3:03pm UTC](https://discuss.elastic.co/t/cves-present-in-the-latest-version/332950 "2023-05-09T15:03:18Z")

</div>

In the latest release, at this moment 8.7.1, there are vulnerabilities in some jar files included. From Trivy scanner: CVE-2020-15522 CVE-2020-8908 CVE-2021-29425 CVE-2021-40690 CVE-2022-1471 CVE-2022-45146 CVE-20…

---

## [Logstash TCP and Syslog Plugin Error](https://discuss.elastic.co/t/logstash-tcp-and-syslog-plugin-error/330722)

<div class="topic-metadata">

**Author:** [@hanna](https://discuss.elastic.co/u/hanna)\
**Replies:** 4\
**Last updated:** [May 9, 2023, 1:26pm UTC](https://discuss.elastic.co/t/logstash-tcp-and-syslog-plugin-error/330722 "2023-05-09T13:26:55Z")

</div>

Hello, I'm experiencing a Logstash error with the syslog input plugin. The input plugin for my pipeline keeps crashing with the message Force-closing a channel whose registration task was not accepted by an event loop …

---

## [Logstash logging](https://discuss.elastic.co/t/logstash-logging/332887)

<div class="topic-metadata">

**Author:** [@Haytham\_Shammout](https://discuss.elastic.co/u/Haytham_Shammout)\
**Replies:** 2\
**Last updated:** [May 9, 2023, 12:53pm UTC](https://discuss.elastic.co/t/logstash-logging/332887 "2023-05-09T12:53:34Z")

</div>

Hi! I was wondering if there is any location that stores the logs in Logstash before sending it to any destination? and if there, where and how can I find it? Thanks.

---

## [Disable exists query in Kibana 8.7](https://discuss.elastic.co/t/disable-exists-query-in-kibana-8-7/329753)

<div class="topic-metadata">

**Author:** [@Jonas\_S](https://discuss.elastic.co/u/Jonas_S)\
**Replies:** 14\
**Last updated:** [May 9, 2023, 12:45pm UTC](https://discuss.elastic.co/t/disable-exists-query-in-kibana-8-7/329753 "2023-05-09T12:45:20Z")

</div>

Hello, after the new controls came out and replaced the beta controls, i started to add them to every dashboard i'm managing. There was no exists query possible at all back then. Then a new update came out, introducing…

---

## [Importing dashboards into multiple spaces through the kibana api](https://discuss.elastic.co/t/importing-dashboards-into-multiple-spaces-through-the-kibana-api/332599)

<div class="topic-metadata">

**Author:** [@CarolynR](https://discuss.elastic.co/u/CarolynR)\
**Replies:** 4\
**Last updated:** [May 9, 2023, 12:42pm UTC](https://discuss.elastic.co/t/importing-dashboards-into-multiple-spaces-through-the-kibana-api/332599 "2023-05-09T12:42:04Z")

</div>

I have saved objects that I am trying to import into 2 different spaces. This worked under kibana 7, but is broken under kibana 8. I use s/spacename in the url when working with the different spaces Importing into the…

---

## [Queue.drain: true not working for logstash as K8s setup](https://discuss.elastic.co/t/queue-drain-true-not-working-for-logstash-as-k8s-setup/329236)

<div class="topic-metadata">

**Author:** [@Karthik\_N](https://discuss.elastic.co/u/Karthik_N)\
**Replies:** 18\
**Last updated:** [May 9, 2023, 12:21pm UTC](https://discuss.elastic.co/t/queue-drain-true-not-working-for-logstash-as-k8s-setup/329236 "2023-05-09T12:21:47Z")

</div>

Hi Team, We have issues in draining the logstash queue, this config is queue.drain: true not working. Our Current logstash setup in K8s and persistence queue setup in EBS volume, after killing our one of the logstash po…

---

## [Logstash - Convert JSON array and delete whitespaces from key fields](https://discuss.elastic.co/t/logstash-convert-json-array-and-delete-whitespaces-from-key-fields/332419)

<div class="topic-metadata">

**Author:** [@h49nakxs](https://discuss.elastic.co/u/h49nakxs)\
**Replies:** 3\
**Last updated:** [May 9, 2023, 11:55am UTC](https://discuss.elastic.co/t/logstash-convert-json-array-and-delete-whitespaces-from-key-fields/332419 "2023-05-09T11:55:33Z")

</div>

Hi there, I'm using Logstash to receive events from winlogbeat and send them to Kafka which will ultimately send them further. To be able to correctly process those events at the end of the pipe, I need to : Convert t…

---

## [Elastic-agent ignores logging level setting](https://discuss.elastic.co/t/elastic-agent-ignores-logging-level-setting/332560)

<div class="topic-metadata">

**Author:** [@vitalyrychkov](https://discuss.elastic.co/u/vitalyrychkov)\
**Replies:** 1\
**Last updated:** [May 9, 2023, 10:07am UTC](https://discuss.elastic.co/t/elastic-agent-ignores-logging-level-setting/332560 "2023-05-09T10:07:38Z")

</div>

I am trying to reduce the output of the elastic-agent containers in Kubernetes. I have added the following parameter to the configmap: agent: logging: level: error and restarted agents. There is still…

---

## [Logstash long nested messgage field in json format not getting parsed](https://discuss.elastic.co/t/logstash-long-nested-messgage-field-in-json-format-not-getting-parsed/332893)

<div class="topic-metadata">

**Author:** [@Alok\_ojha](https://discuss.elastic.co/u/Alok_ojha)\
**Replies:** 0\
**Last updated:** [May 9, 2023, 8:57am UTC](https://discuss.elastic.co/t/logstash-long-nested-messgage-field-in-json-format-not-getting-parsed/332893 "2023-05-09T08:57:45Z")

</div>

Please Help!! I had data in kafka, I used logstash config file to upload it to elasticsearch, data is coming to elasticsearch but the message field is very long and logstash is unable to parse it in key value pair. Is t…

---

## [Elasticsearch and kibana access](https://discuss.elastic.co/t/elasticsearch-and-kibana-access/329806)

<div class="topic-metadata">

**Author:** [@roshan\_vikhar](https://discuss.elastic.co/u/roshan_vikhar)\
**Replies:** 2\
**Last updated:** [May 9, 2023, 8:27am UTC](https://discuss.elastic.co/t/elasticsearch-and-kibana-access/329806 "2023-05-09T08:27:09Z")

</div>

I am new in ELK am using elastic ip for connecting both elasticsearch and kibana but only kibana i can access. what should be the changes i have to make in elasticsearch.yml and kibana.yml to make it work.

[Previous page](https://discuss.elastic.co/tag/none.md?no_tags=true&page=382)

[Next page](https://discuss.elastic.co/tag/none.md?no_tags=true&page=384)
