# \#none

**URL:** https://discuss.elastic.co/tag/none.md?no_tags=true&page=388

[Latest](https://discuss.elastic.co/latest.md) · [Categories](https://discuss.elastic.co/categories.md) · [Tags](https://discuss.elastic.co/tags.md)

**Page:** 389

---

## [Failed to Parse date](https://discuss.elastic.co/t/failed-to-parse-date/331445)

<div class="topic-metadata">

**Author:** [@valleram](https://discuss.elastic.co/u/valleram)\
**Replies:** 1\
**Last updated:** [May 1, 2023, 2:58am UTC](https://discuss.elastic.co/t/failed-to-parse-date/331445 "2023-05-01T02:58:25Z")

</div>

Hi All, I'm trying to parse dates with format 1/3/2022. I've tried to parse it using following mapping M/d/YYYY but Kibana is showing a completely different result. See example below. Ingested date: Date showed in …

---

## [Remote clusters for basic/platinum , onprem/cloud license](https://discuss.elastic.co/t/remote-clusters-for-basic-platinum-onprem-cloud-license/330668)

<div class="topic-metadata">

**Author:** [@Petr.Simik](https://discuss.elastic.co/u/Petr.Simik)\
**Replies:** 10\
**Last updated:** [May 1, 2023, 12:43am UTC](https://discuss.elastic.co/t/remote-clusters-for-basic-platinum-onprem-cloud-license/330668 "2023-05-01T00:43:55Z")

</div>

Hi, We have several Elastic clusters on-premises and we plan to create a few new ones on Azure cloud. All of them are self-managed version 8.6. The purpose of all Elasticsearch clusters is data analysis in Kibana, so I…

---

## [Elasticsearch G1GC over CMS in resolving the GC overhead](https://discuss.elastic.co/t/elasticsearch-g1gc-over-cms-in-resolving-the-gc-overhead/330744)

<div class="topic-metadata">

**Author:** [@navaneethan](https://discuss.elastic.co/u/navaneethan)\
**Replies:** 3\
**Last updated:** [April 30, 2023, 11:21pm UTC](https://discuss.elastic.co/t/elasticsearch-g1gc-over-cms-in-resolving-the-gc-overhead/330744 "2023-04-30T23:21:48Z")

</div>

We are using the ES 7.3 with CMS GC and we are preparing for the rolling upgrade to 7.17 which supports G1GC only We are getting the GC overhead curently, \[2023-04-25T02:00:41,085\]\[WARN \]\[o.e.m.j.JvmGcMonitorService\] \[…

---

## [Mappings Issue](https://discuss.elastic.co/t/mappings-issue/330797)

<div class="topic-metadata">

**Author:** [@Dasher](https://discuss.elastic.co/u/Dasher)\
**Replies:** 1\
**Last updated:** [April 30, 2023, 11:17pm UTC](https://discuss.elastic.co/t/mappings-issue/330797 "2023-04-30T23:17:15Z")

</div>

Hi, I have a field in my index with the mapping and custom analyzer has followed: Mapping: "BookingNo" : { "type" : "text", "fields" : { "lowercase\_keyword" : { "type" : "text", "analyzer" : "lowercase\_keyword\_an…

---

## [How to index audio/video files to kibana](https://discuss.elastic.co/t/how-to-index-audio-video-files-to-kibana/330834)

<div class="topic-metadata">

**Author:** [@AdityaKhajuria](https://discuss.elastic.co/u/AdityaKhajuria)\
**Replies:** 1\
**Last updated:** [April 30, 2023, 11:15pm UTC](https://discuss.elastic.co/t/how-to-index-audio-video-files-to-kibana/330834 "2023-04-30T23:15:08Z")

</div>

Hi, Im trying to index audio/video files to kibana. I am able to get audio in a field by setting Format-URL and type-Audio in index pattern. But i want my logstash to index my audio/video files to kibana.

---

## [Elasticsearch 8.7.0 Installation issue: elasticsearch.bat cmd automatic closes without installation](https://discuss.elastic.co/t/elasticsearch-8-7-0-installation-issue-elasticsearch-bat-cmd-automatic-closes-without-installation/331156)

<div class="topic-metadata">

**Author:** [@M4MURARI](https://discuss.elastic.co/u/M4MURARI)\
**Replies:** 1\
**Last updated:** [April 30, 2023, 10:58pm UTC](https://discuss.elastic.co/t/elasticsearch-8-7-0-installation-issue-elasticsearch-bat-cmd-automatic-closes-without-installation/331156 "2023-04-30T22:58:55Z")

</div>

After unzipping the elasticsearch-8.7.0-windows-x86\_64.zip when I click on elasticsearch.bat of bin folder, It automatically closes without full installation. One solution I tried was xpack.security.transport.ssl.enable…

---

## [Log stash behavior when output plug-in not reachable](https://discuss.elastic.co/t/log-stash-behavior-when-output-plug-in-not-reachable/331376)

<div class="topic-metadata">

**Author:** [@eth](https://discuss.elastic.co/u/eth)\
**Replies:** 0\
**Last updated:** [April 30, 2023, 6:14pm UTC](https://discuss.elastic.co/t/log-stash-behavior-when-output-plug-in-not-reachable/331376 "2023-04-30T18:14:03Z")

</div>

I am using logstash 7 with syslog as output plugin. The syslog server is not reachable for a quite a long time and persistent queue is growing as expected to the limit. But the persistent queue data size is growing bey…

---

## [Aggregate field with text type](https://discuss.elastic.co/t/aggregate-field-with-text-type/331119)

<div class="topic-metadata">

**Author:** [@Indeed2000](https://discuss.elastic.co/u/Indeed2000)\
**Replies:** 1\
**Last updated:** [April 30, 2023, 5:37pm UTC](https://discuss.elastic.co/t/aggregate-field-with-text-type/331119 "2023-04-30T17:37:31Z")

</div>

Hi i have two field in kibana "hostname" and "usage", when i add "usage" it will show area chart but when i add "hostname" as breakdown not show. FYI1: hostname type are text and not aggregatable! FYI2: these field cr…

---

## [Which index do elastic agents output too?](https://discuss.elastic.co/t/which-index-do-elastic-agents-output-too/331168)

<div class="topic-metadata">

**Author:** [@learningelastic](https://discuss.elastic.co/u/learningelastic)\
**Replies:** 1\
**Last updated:** [April 30, 2023, 5:11pm UTC](https://discuss.elastic.co/t/which-index-do-elastic-agents-output-too/331168 "2023-04-30T17:11:19Z")

</div>

I'm trying to configure a stand alone elastic agent. I get a success response during installation but i'm not sure which index in elasticsearch the data get sent to? This is my elastic-agent.yml file: outputs: defau…

---

## [View In context option is not available(EFK- Elasticsearch Fluentd kibana Stack)](https://discuss.elastic.co/t/view-in-context-option-is-not-available-efk-elasticsearch-fluentd-kibana-stack/331367)

<div class="topic-metadata">

**Author:** [@Srijitha](https://discuss.elastic.co/u/Srijitha)\
**Replies:** 0\
**Last updated:** [April 30, 2023, 4:03pm UTC](https://discuss.elastic.co/t/view-in-context-option-is-not-available-efk-elasticsearch-fluentd-kibana-stack/331367 "2023-04-30T16:03:45Z")

</div>

Hi Team, I am sending log from fluentd to elasticsearch, everything works fine. But I am not able to see "VIEW IN CONTEXT" option in log section of observability, Elasticsearch version: 8.7 and Kibana Version: 8.7. Below…

---

## [How to avoid duplicate values being copied while using copy\_to?](https://discuss.elastic.co/t/how-to-avoid-duplicate-values-being-copied-while-using-copy-to/330905)

<div class="topic-metadata">

**Author:** [@Srikrishna\_Raghupath](https://discuss.elastic.co/u/Srikrishna_Raghupath)\
**Replies:** 1\
**Last updated:** [April 30, 2023, 11:22am UTC](https://discuss.elastic.co/t/how-to-avoid-duplicate-values-being-copied-while-using-copy-to/330905 "2023-04-30T11:22:10Z")

</div>

My Index definition: PUT /test-index { "mappings": { "properties": { "category":{ "type": "text", "similarity": "boolean", "term\_vector": "with\_positions\_offsets", "fields":{…

---

## [Logstash gives OOM & CPU Usage too high when used with S3 Input plugin](https://discuss.elastic.co/t/logstash-gives-oom-cpu-usage-too-high-when-used-with-s3-input-plugin/331121)

<div class="topic-metadata">

**Author:** [@Utpal\_Brahma](https://discuss.elastic.co/u/Utpal_Brahma)\
**Replies:** 3\
**Last updated:** [April 29, 2023, 5:25pm UTC](https://discuss.elastic.co/t/logstash-gives-oom-cpu-usage-too-high-when-used-with-s3-input-plugin/331121 "2023-04-29T17:25:38Z")

</div>

Logstash gives out of Memory when S3 plugin is used for a bucket which has already existing tones of files.

---

## [Can't write data to elasticsearch (cannot be changed from type \[date\] to \[text)](https://discuss.elastic.co/t/cant-write-data-to-elasticsearch-cannot-be-changed-from-type-date-to-text/330062)

<div class="topic-metadata">

**Author:** [@Indeed2000](https://discuss.elastic.co/u/Indeed2000)\
**Replies:** 21\
**Last updated:** [April 29, 2023, 2:59pm UTC](https://discuss.elastic.co/t/cant-write-data-to-elasticsearch-cannot-be-changed-from-type-date-to-text/330062 "2023-04-29T14:59:19Z")

</div>

Hi can't write data to elasticsearch vi logstash(http\_poller) here is the scenario: influxdb \> logstash(http\_poller) \> elasticsearch error that I get: "status"=\>400, "error"=\>{"type"=\>"illegal\_argument\_exception", "…

---

## [Elastic defendで取得するログについて](https://discuss.elastic.co/t/elastic-defend/331118)

<div class="topic-metadata">

**Author:** [@e-se](https://discuss.elastic.co/u/e-se)\
**Replies:** 0\
**Last updated:** [April 29, 2023, 8:20am UTC](https://discuss.elastic.co/t/elastic-defend/331118 "2023-04-29T08:20:28Z")

</div>

linuxのサーバにelastic agentを導入し、にelastic defend integrationをあてて、logを収集することを検討しています。 そこで疑問です。 Linuxの場合、File、Network、Processのイベントを取得できるようですが、これらは何処で作成されたログになるのでしょうか。 System integrationや、Auditd log integrationなら、設定にファイルを指定する…

---

## [Limiting data integrity risks from compromised client](https://discuss.elastic.co/t/limiting-data-integrity-risks-from-compromised-client/331086)

<div class="topic-metadata">

**Author:** [@nf4ray](https://discuss.elastic.co/u/nf4ray)\
**Replies:** 3\
**Last updated:** [April 29, 2023, 7:49am UTC](https://discuss.elastic.co/t/limiting-data-integrity-risks-from-compromised-client/331086 "2023-04-29T07:49:16Z")

</div>

Let's say I want to monitor the system logs of a cluster of servers with filebeat. Because using one data stream per host doesn't scale well and the cluster is logically part of the same application, they all write to th…

---

## [Logstash filters for log file which is included some raw data and json data](https://discuss.elastic.co/t/logstash-filters-for-log-file-which-is-included-some-raw-data-and-json-data/330950)

<div class="topic-metadata">

**Author:** [@Harish1](https://discuss.elastic.co/u/Harish1)\
**Replies:** 3\
**Last updated:** [April 28, 2023, 5:24pm UTC](https://discuss.elastic.co/t/logstash-filters-for-log-file-which-is-included-some-raw-data-and-json-data/330950 "2023-04-28T17:24:50Z")

</div>

Hi Elastic team, I'm new to ELK, I'm trying to find out the filters for below log file but I'm not able to find the proper Logstash filter for below data 2023-01-19 15:38:31 INFO VCIPDownstreamController:138 - {"timest…

---

## [Not able to connect my apm-agent to my apm-server and data transfer from hosted on same server](https://discuss.elastic.co/t/not-able-to-connect-my-apm-agent-to-my-apm-server-and-data-transfer-from-hosted-on-same-server/330627)

<div class="topic-metadata">

**Author:** [@Tataelastic](https://discuss.elastic.co/u/Tataelastic)\
**Replies:** 1\
**Last updated:** [April 28, 2023, 4:39pm UTC](https://discuss.elastic.co/t/not-able-to-connect-my-apm-agent-to-my-apm-server-and-data-transfer-from-hosted-on-same-server/330627 "2023-04-28T16:39:35Z")

</div>

I have deployed elasticsearch, kibana, apm-server on same server ip: 10.8.30.220 output for http://10.8.30.220:8200 { "build\_date": "2023-01-31T04:33:06Z", "build\_sha": "71a8b4c241eb5b4609862c8354d2aa2270f6c568", "…

---

## [Migrate from ELK to ECK - roles, role\_mappings](https://discuss.elastic.co/t/migrate-from-elk-to-eck-roles-role-mappings/330505)

<div class="topic-metadata">

**Author:** [@charlot\_Attard](https://discuss.elastic.co/u/charlot_Attard)\
**Replies:** 4\
**Last updated:** [April 28, 2023, 4:14pm UTC](https://discuss.elastic.co/t/migrate-from-elk-to-eck-roles-role-mappings/330505 "2023-04-28T16:14:03Z")

</div>

Hello, We are migrating ELK Version 7.17.0 to ECK Version 7.17.0 and we want to automate as much as we can the setup of the cluster. Is there a way whilst provisioning the ECK in the yaml manifets or init scripts we cre…

---

## [Multisource index on elasticsearch passing by logstash](https://discuss.elastic.co/t/multisource-index-on-elasticsearch-passing-by-logstash/330844)

<div class="topic-metadata">

**Author:** [@Abdeljalil\_El\_Yousso](https://discuss.elastic.co/u/Abdeljalil_El_Yousso)\
**Replies:** 10\
**Last updated:** [April 28, 2023, 3:57pm UTC](https://discuss.elastic.co/t/multisource-index-on-elasticsearch-passing-by-logstash/330844 "2023-04-28T15:57:42Z")

</div>

hey , im trying to create multiple source input from Filebeat , than injecting them into logstash to apply filters , and finally transfer the sources to elasticsearch as indexes The problem i have , only one index is cr…

---

## [How to use SearchLookup getSource(LeafReaderContext ctx, int doc)](https://discuss.elastic.co/t/how-to-use-searchlookup-getsource-leafreadercontext-ctx-int-doc/331072)

<div class="topic-metadata">

**Author:** [@p4paul](https://discuss.elastic.co/u/p4paul)\
**Replies:** 0\
**Last updated:** [April 28, 2023, 3:57pm UTC](https://discuss.elastic.co/t/how-to-use-searchlookup-getsource-leafreadercontext-ctx-int-doc/331072 "2023-04-28T15:57:41Z")

</div>

In 8.7.0 the source() method was removed from SearchLookup: How do I use the new getSource method in SearchLookup for a FilterScript given the following use case... public class MyLeafFactory implements FilterScript.…

---

## [Remove random indexes](https://discuss.elastic.co/t/remove-random-indexes/331066)

<div class="topic-metadata">

**Author:** [@Marcelo\_Moro\_Brondan](https://discuss.elastic.co/u/Marcelo_Moro_Brondan)\
**Replies:** 2\
**Last updated:** [April 28, 2023, 2:59pm UTC](https://discuss.elastic.co/t/remove-random-indexes/331066 "2023-04-28T14:59:17Z")

</div>

remove random indexesremove random indexesHello! I have an elasticsearch 5.6 in centOS 7 and it is behaving unexpectedly. Random indexes are being created. I am not able to identify the origin and apply a configuration …

---

## [Rename nested field based on its data type](https://discuss.elastic.co/t/rename-nested-field-based-on-its-data-type/331044)

<div class="topic-metadata">

**Author:** [@aversecguy](https://discuss.elastic.co/u/aversecguy)\
**Replies:** 0\
**Last updated:** [April 28, 2023, 10:18am UTC](https://discuss.elastic.co/t/rename-nested-field-based-on-its-data-type/331044 "2023-04-28T10:18:21Z")

</div>

Hello, dear community, I am brand new to logstash, but have to fix a problem: We are gathering eks audit logs and have errors like illegal\_state\_exception error because of the field responseObject.status could be the t…

---

## [Failed to assign role via role mapping API ldap realm](https://discuss.elastic.co/t/failed-to-assign-role-via-role-mapping-api-ldap-realm/331039)

<div class="topic-metadata">

**Author:** [@GaetanCia](https://discuss.elastic.co/u/GaetanCia)\
**Replies:** 0\
**Last updated:** [April 28, 2023, 9:59am UTC](https://discuss.elastic.co/t/failed-to-assign-role-via-role-mapping-api-ldap-realm/331039 "2023-04-28T09:59:04Z")

</div>

Hi, I have issue to assign a role via the role-mapping setting. I tried to assign a role to a certain group of people who connect from the ldap realm. If i use the native role mapping file, it work fine My role\_mappi…

---

## [Elasticsearch how do I properly monitor performance? Is there a good tool? is there a free alternative to datadog?](https://discuss.elastic.co/t/elasticsearch-how-do-i-properly-monitor-performance-is-there-a-good-tool-is-there-a-free-alternative-to-datadog/331028)

<div class="topic-metadata">

**Author:** [@Eduard\_mart](https://discuss.elastic.co/u/Eduard_mart)\
**Replies:** 1\
**Last updated:** [April 28, 2023, 8:28am UTC](https://discuss.elastic.co/t/elasticsearch-how-do-i-properly-monitor-performance-is-there-a-good-tool-is-there-a-free-alternative-to-datadog/331028 "2023-04-28T08:28:14Z")

</div>

Elasticsearch how do I properly monitor performance? Is there a good tool? is there a free alternative to datadog?

---

## [How do I check why my search query takes too long? Is there something like Explain command in SQL databases?](https://discuss.elastic.co/t/how-do-i-check-why-my-search-query-takes-too-long-is-there-something-like-explain-command-in-sql-databases/331029)

<div class="topic-metadata">

**Author:** [@Eduard\_mart](https://discuss.elastic.co/u/Eduard_mart)\
**Replies:** 1\
**Last updated:** [April 28, 2023, 8:26am UTC](https://discuss.elastic.co/t/how-do-i-check-why-my-search-query-takes-too-long-is-there-something-like-explain-command-in-sql-databases/331029 "2023-04-28T08:26:05Z")

</div>

How do I check why my search query takes too long? Is there something like Explain command in SQL databases?

---

## [Error updating Security Data View](https://discuss.elastic.co/t/error-updating-security-data-view/331027)

<div class="topic-metadata">

**Author:** [@TheMadmax](https://discuss.elastic.co/u/TheMadmax)\
**Replies:** 0\
**Last updated:** [April 28, 2023, 8:17am UTC](https://discuss.elastic.co/t/error-updating-security-data-view/331027 "2023-04-28T08:17:08Z")

</div>

I am facing an error on my kibana: Error updating Security Data View { "name": "AbortError", "body": null, "message": "The operation was aborted. ", "stack": "o@https://kibana.xxxxxx:5403/59020/bundles/kbn-ui-sh…

---

## [Question around setting proper ds / index / ilm](https://discuss.elastic.co/t/question-around-setting-proper-ds-index-ilm/330709)

<div class="topic-metadata">

**Author:** [@alexsamad](https://discuss.elastic.co/u/alexsamad)\
**Replies:** 6\
**Last updated:** [April 28, 2023, 7:04am UTC](https://discuss.elastic.co/t/question-around-setting-proper-ds-index-ilm/330709 "2023-04-28T07:04:14Z")

</div>

Hi new to ES, i have 12 node cluster and its purpose is to capture all of the logs from apps in our 14 env - lets call them dev1-14. each env has 6 apps server and 2 rp and 2 geodes and jmp box - so 11 servers. on the a…

---

## [Logstash is not showing base64 encoded data for pdf's extracted from urls](https://discuss.elastic.co/t/logstash-is-not-showing-base64-encoded-data-for-pdfs-extracted-from-urls/330386)

<div class="topic-metadata">

**Author:** [@Disha\_Bodade](https://discuss.elastic.co/u/Disha_Bodade)\
**Replies:** 5\
**Last updated:** [April 28, 2023, 6:58am UTC](https://discuss.elastic.co/t/logstash-is-not-showing-base64-encoded-data-for-pdfs-extracted-from-urls/330386 "2023-04-28T06:58:36Z")

</div>

Hi Team, I am using logstash http filter to get pdf from url and extract it. http filter has downloaded pdf and extracted its content on target\_field. But the contents are not proper and also its not base64 encoded. Ho…

---

## [How to create new array by using existing list of strings field in logstash ruby filter](https://discuss.elastic.co/t/how-to-create-new-array-by-using-existing-list-of-strings-field-in-logstash-ruby-filter/330761)

<div class="topic-metadata">

**Author:** [@Disha\_Bodade](https://discuss.elastic.co/u/Disha_Bodade)\
**Replies:** 2\
**Last updated:** [April 28, 2023, 4:57am UTC](https://discuss.elastic.co/t/how-to-create-new-array-by-using-existing-list-of-strings-field-in-logstash-ruby-filter/330761 "2023-04-28T04:57:00Z")

</div>

Hi Team, I have three arrays created from xml in logstash content.REFERENCE: \[PXXXX, TECHNICAL\_SUPPORT\] content.ROOT: \[INTERNAL\_PRODUCT\_OR\_APPLICATION, TOPICS\] I have to create a result array from above inputs if roo…

---

## [Empty alerts in Palo Alto Cortex XDR Integration](https://discuss.elastic.co/t/empty-alerts-in-palo-alto-cortex-xdr-integration/330997)

<div class="topic-metadata">

**Author:** [@dhsmf](https://discuss.elastic.co/u/dhsmf)\
**Replies:** 0\
**Last updated:** [April 28, 2023, 2:05am UTC](https://discuss.elastic.co/t/empty-alerts-in-palo-alto-cortex-xdr-integration/330997 "2023-04-28T02:05:56Z")

</div>

I'm planning to use Palo Alto Cortex XDR Integration to ingest alerts for our analyses. It looks that the Integration often brings almost empty alerts (without file hash, process info and so on, showing reply: 0). Is it …

[Previous page](https://discuss.elastic.co/tag/none.md?no_tags=true&page=387)

[Next page](https://discuss.elastic.co/tag/none.md?no_tags=true&page=389)
