# \#none

**URL:** https://discuss.elastic.co/tag/none.md?no_tags=true&page=391

[Latest](https://discuss.elastic.co/latest.md) · [Categories](https://discuss.elastic.co/categories.md) · [Tags](https://discuss.elastic.co/tags.md)

**Page:** 392

---

## [Issue with logstash](https://discuss.elastic.co/t/issue-with-logstash/330741)

<div class="topic-metadata">

**Author:** [@Hanni](https://discuss.elastic.co/u/Hanni)\
**Replies:** 0\
**Last updated:** [April 25, 2023, 12:57pm UTC](https://discuss.elastic.co/t/issue-with-logstash/330741 "2023-04-25T12:57:52Z")

</div>

Hello, I am trying to parse this JSON with Logstash. {"creation\_date": "2023/01/04", "vulnerabilities": \[{"count": 1, "score": null, "vuln\_index": 414, "plugin\_name": "WordPad History", "severity": 0, "vpr\_score": null,…

---

## [How to apply ilm policy to index patter tenat-\*](https://discuss.elastic.co/t/how-to-apply-ilm-policy-to-index-patter-tenat/328428)

<div class="topic-metadata">

**Author:** [@elasticlog](https://discuss.elastic.co/u/elasticlog)\
**Replies:** 2\
**Last updated:** [April 25, 2023, 10:42am UTC](https://discuss.elastic.co/t/how-to-apply-ilm-policy-to-index-patter-tenat/328428 "2023-04-25T10:42:28Z")

</div>

Hello Expert, I have to apply an ilm policy to my index patter so that the space full issue should not occur. Im able to create the policy but not able to apply to index patter as i need to add manually for index patte…

---

## [Sampling aggregation with a fixed seed producing unstable results](https://discuss.elastic.co/t/sampling-aggregation-with-a-fixed-seed-producing-unstable-results/329849)

<div class="topic-metadata">

**Author:** [@geoffballinger](https://discuss.elastic.co/u/geoffballinger)\
**Replies:** 1\
**Last updated:** [April 25, 2023, 10:10am UTC](https://discuss.elastic.co/t/sampling-aggregation-with-a-fixed-seed-producing-unstable-results/329849 "2023-04-25T10:10:31Z")

</div>

We would like to use sampling aggregations to improve aggregation performance in some dashboards, but the results must be the same each time to avoid confusing customers. We are thus setting the seed since if we do that …

---

## [Kibana failed to log in to the es cluster deployed by ECK, and the login timed out](https://discuss.elastic.co/t/kibana-failed-to-log-in-to-the-es-cluster-deployed-by-eck-and-the-login-timed-out/330597)

<div class="topic-metadata">

**Author:** [@Teresajw](https://discuss.elastic.co/u/Teresajw)\
**Replies:** 4\
**Last updated:** [April 25, 2023, 9:06am UTC](https://discuss.elastic.co/t/kibana-failed-to-log-in-to-the-es-cluster-deployed-by-eck-and-the-login-timed-out/330597 "2023-04-25T09:06:27Z")

</div>

Bug Report What did you do? I have installed ECK via CRD 2.7 in my Kubernetes cluster (v1.24.9) . After I have deployed Elasticsearch and Kibana via the manifests shown below. After a few minutes I can access to Kibana…

---

## [Elasticsearchversion 7.17.9 is not starting - Exception in thread "main" java.lang.RuntimeException: starting java](https://discuss.elastic.co/t/elasticsearchversion-7-17-9-is-not-starting-exception-in-thread-main-java-lang-runtimeexception-starting-java/330658)

<div class="topic-metadata">

**Author:** [@kirankumarb](https://discuss.elastic.co/u/kirankumarb)\
**Replies:** 5\
**Last updated:** [April 25, 2023, 5:48am UTC](https://discuss.elastic.co/t/elasticsearchversion-7-17-9-is-not-starting-exception-in-thread-main-java-lang-runtimeexception-starting-java/330658 "2023-04-25T05:48:42Z")

</div>

Elasticsearch 7.8 is upgraded to version 7.17.9, then unable to start the service. And in logs getting following Error: Exception in thread "main" java.lang.RuntimeException: starting java.

---

## [None of the configured nodes are available](https://discuss.elastic.co/t/none-of-the-configured-nodes-are-available/330340)

<div class="topic-metadata">

**Author:** [@zz-GuoYF](https://discuss.elastic.co/u/zz-GuoYF)\
**Replies:** 3\
**Last updated:** [April 25, 2023, 8:35am UTC](https://discuss.elastic.co/t/none-of-the-configured-nodes-are-available/330340 "2023-04-25T08:35:58Z")

</div>

The version of Elasticsearch I used is 2.4.6 and the deployment mode is single-node es. When I was running a query with a data volume of 7 million, the following error occurred in es： In addition, by adding GC log p…

---

## [How to send subject field data from logstash to syslog server](https://discuss.elastic.co/t/how-to-send-subject-field-data-from-logstash-to-syslog-server/330642)

<div class="topic-metadata">

**Author:** [@Thumati](https://discuss.elastic.co/u/Thumati)\
**Replies:** 2\
**Last updated:** [April 25, 2023, 6:25am UTC](https://discuss.elastic.co/t/how-to-send-subject-field-data-from-logstash-to-syslog-server/330642 "2023-04-25T06:25:52Z")

</div>

I would like to know if is it possible to send subject field to rsyslog server. Eg: subject : " username " should be sent.

---

## [Is Elasticsearch 7.17.9 is compatible withOpenJDK 1.8?](https://discuss.elastic.co/t/is-elasticsearch-7-17-9-is-compatible-withopenjdk-1-8/330654)

<div class="topic-metadata">

**Author:** [@kirankumarb](https://discuss.elastic.co/u/kirankumarb)\
**Replies:** 7\
**Last updated:** [April 25, 2023, 5:59am UTC](https://discuss.elastic.co/t/is-elasticsearch-7-17-9-is-compatible-withopenjdk-1-8/330654 "2023-04-25T05:59:59Z")

</div>

Is OpenJDK 1.8 version is compatible with elasticsearch 7.17.9 version? If not Which version of OpenJDK is compatible with elasticsearch 7.17.9?

---

## [Send logs from filebeat to elasticsearch](https://discuss.elastic.co/t/send-logs-from-filebeat-to-elasticsearch/330628)

<div class="topic-metadata">

**Author:** [@Neelam\_Zanvar](https://discuss.elastic.co/u/Neelam_Zanvar)\
**Replies:** 7\
**Last updated:** [April 25, 2023, 5:39am UTC](https://discuss.elastic.co/t/send-logs-from-filebeat-to-elasticsearch/330628 "2023-04-25T05:39:27Z")

</div>

I am trying to send logs from filebeat to elasticsearch. Here is the filbeat.yml filebeat.inputs: - type: filestream id: my-filestream-id enabled: true paths: - C:\\ProgramData\\sample\_logs\\sample.log - type: lo…

---

## [Analyzer \[full\_chinese\] contains filters \[my\_synonym\] that are not allowed to run in index time mode](https://discuss.elastic.co/t/analyzer-full-chinese-contains-filters-my-synonym-that-are-not-allowed-to-run-in-index-time-mode/330626)

<div class="topic-metadata">

**Author:** [@YKX-Can](https://discuss.elastic.co/u/YKX-Can)\
**Replies:** 1\
**Last updated:** [April 25, 2023, 2:59am UTC](https://discuss.elastic.co/t/analyzer-full-chinese-contains-filters-my-synonym-that-are-not-allowed-to-run-in-index-time-mode/330626 "2023-04-25T02:59:38Z")

</div>

this my setting PUT test { "settings": { "analysis": { "char\_filter": { "my\_tsconvert": { "convert\_type": "t2s", "type": "stconvert" } }, "filter": { "my\_synonym": { "type": "synon…

---

## [Average of sum(value)](https://discuss.elastic.co/t/average-of-sum-value/330685)

<div class="topic-metadata">

**Author:** [@elasticforme](https://discuss.elastic.co/u/elasticforme)\
**Replies:** 2\
**Last updated:** [April 24, 2023, 9:09pm UTC](https://discuss.elastic.co/t/average-of-sum-value/330685 "2023-04-24T21:09:50Z")

</div>

I am running a ingestion and records comes every 15 min one of the field is integer #user value might be 1, 2,3 or what ever. what I am trying to do is average of sum ( users) per hour for example rec1 - 10:00am { …

---

## [Send Logs from Filebeat on my local machine to Logstash having a private ip](https://discuss.elastic.co/t/send-logs-from-filebeat-on-my-local-machine-to-logstash-having-a-private-ip/330352)

<div class="topic-metadata">

**Author:** [@Neelam\_Zanvar](https://discuss.elastic.co/u/Neelam_Zanvar)\
**Replies:** 2\
**Last updated:** [April 24, 2023, 7:13pm UTC](https://discuss.elastic.co/t/send-logs-from-filebeat-on-my-local-machine-to-logstash-having-a-private-ip/330352 "2023-04-24T19:13:10Z")

</div>

Hi i have installed filebeat on my local windows machine. I want to send logs to Logstash which has a private IP only and is in a different VPC. How can i set a connection between these two machines? Is it possible?

---

## [Elastic search on windows](https://discuss.elastic.co/t/elastic-search-on-windows/330409)

<div class="topic-metadata">

**Author:** [@Preethi\_Manu](https://discuss.elastic.co/u/Preethi_Manu)\
**Replies:** 8\
**Last updated:** [April 24, 2023, 6:34pm UTC](https://discuss.elastic.co/t/elastic-search-on-windows/330409 "2023-04-24T18:34:34Z")

</div>

While installing Elastic search on windows , getting below error like plugin db2jcc4.jar is missing a descriptor properties file. Please help to resolve this

---

## [Kibana Authentification](https://discuss.elastic.co/t/kibana-authentification/330243)

<div class="topic-metadata">

**Author:** [@Julien069](https://discuss.elastic.co/u/Julien069)\
**Replies:** 7\
**Last updated:** [April 24, 2023, 6:27pm UTC](https://discuss.elastic.co/t/kibana-authentification/330243 "2023-04-24T18:27:00Z")

</div>

Hi, I'have a problem to authentificating Kibana on Elastic . After generating a token on Elastic, Kibana is block on "Server is not ready yet" I have two different IP on each server and they ping each other Changes i…

---

## [Logging and metrics to on prem or outside the ECE](https://discuss.elastic.co/t/logging-and-metrics-to-on-prem-or-outside-the-ece/330680)

<div class="topic-metadata">

**Author:** [@shani\_angarkadu](https://discuss.elastic.co/u/shani_angarkadu)\
**Replies:** 1\
**Last updated:** [April 24, 2023, 6:07pm UTC](https://discuss.elastic.co/t/logging-and-metrics-to-on-prem-or-outside-the-ece/330680 "2023-04-24T18:07:11Z")

</div>

We have ECE setup and few deployments/clusters running. But we would like to send the logging and metrics data for each deployment to outside ECE on premises Elastic cluster. But we didn’t see an option to add Elastic c…

---

## [Geo\_Point field for mapping](https://discuss.elastic.co/t/geo-point-field-for-mapping/330363)

<div class="topic-metadata">

**Author:** [@Abdeljalil\_El\_Yousso](https://discuss.elastic.co/u/Abdeljalil_El_Yousso)\
**Replies:** 1\
**Last updated:** [April 24, 2023, 5:53pm UTC](https://discuss.elastic.co/t/geo-point-field-for-mapping/330363 "2023-04-24T17:53:27Z")

</div>

hey , im tryin g to create and have and geo\_point field to create a map visualisation , but im finding difficulties , my Lat and Long fields that i extracted previously from Geoip filter on My configuration file are flo…

---

## [100% disk, single node cluster how to fix?](https://discuss.elastic.co/t/100-disk-single-node-cluster-how-to-fix/330588)

<div class="topic-metadata">

**Author:** [@elasticforme](https://discuss.elastic.co/u/elasticforme)\
**Replies:** 8\
**Last updated:** [April 24, 2023, 5:12pm UTC](https://discuss.elastic.co/t/100-disk-single-node-cluster-how-to-fix/330588 "2023-04-24T17:12:47Z")

</div>

I have a test single node cluster. I know what the problem is but can't seems to figure out how to get out of it and fix without removing everything and star over this node has all index without replica because I exe…

---

## [ELastic Defend agent high latency on DCs](https://discuss.elastic.co/t/elastic-defend-agent-high-latency-on-dcs/328766)

<div class="topic-metadata">

**Author:** [@Kelly\_Slavens](https://discuss.elastic.co/u/Kelly_Slavens)\
**Replies:** 2\
**Last updated:** [April 24, 2023, 4:44pm UTC](https://discuss.elastic.co/t/elastic-defend-agent-high-latency-on-dcs/328766 "2023-04-24T16:44:41Z")

</div>

We're seeing extreme latency on 2022 Domain controllers when Elastic Defend 8.6.2 Malicious Behavior rules are enabled. The server becomes very sluggish but performance metrics don't appear to show any sign of excesses l…

---

## [\[NEWBIE\] Increase speed of indexation huge logs](https://discuss.elastic.co/t/newbie-increase-speed-of-indexation-huge-logs/330069)

<div class="topic-metadata">

**Author:** [@pepite](https://discuss.elastic.co/u/pepite)\
**Replies:** 25\
**Last updated:** [April 24, 2023, 9:21am UTC](https://discuss.elastic.co/t/newbie-increase-speed-of-indexation-huge-logs/330069 "2023-04-24T09:21:27Z")

</div>

Hi everybody, I'm french and i m a very newbie with elasticsearch. Elasticsearch version imposed by security team : 7.10.2 I create a cluster like this with dedicate nodes: 2 master node 1 master only eligible node 1…

---

## [SlowLogs Info Missing in 8.6 - "event.duration"](https://discuss.elastic.co/t/slowlogs-info-missing-in-8-6-event-duration/329040)

<div class="topic-metadata">

**Author:** [@moni15moni](https://discuss.elastic.co/u/moni15moni)\
**Replies:** 5\
**Last updated:** [April 24, 2023, 2:52pm UTC](https://discuss.elastic.co/t/slowlogs-info-missing-in-8-6-event-duration/329040 "2023-04-24T14:52:08Z")

</div>

Hi Team, Previously we used elasticcloud 7.17 , where we configured the observability in the different es cluster (7.17), When the slow logs are triggered the following events are captured in the slowllog. "event": { …

---

## [Adding syslog priority fields to System integration](https://discuss.elastic.co/t/adding-syslog-priority-fields-to-system-integration/330519)

<div class="topic-metadata">

**Author:** [@sebek](https://discuss.elastic.co/u/sebek)\
**Replies:** 2\
**Last updated:** [April 24, 2023, 2:28pm UTC](https://discuss.elastic.co/t/adding-syslog-priority-fields-to-system-integration/330519 "2023-04-24T14:28:32Z")

</div>

Hi, i'm trying to work out how to add information about syslog priority to my logdata in elasticsearch. I'm testing out a self managed ELK stack, for collecting syslog data from linux(ubuntu) servers and workstations. …

---

## ['npx @elastic/synthetic journeys' Command to run on specific \*journey.ts files](https://discuss.elastic.co/t/npx-elastic-synthetic-journeys-command-to-run-on-specific-journey-ts-files/330473)

<div class="topic-metadata">

**Author:** [@ameindel](https://discuss.elastic.co/u/ameindel)\
**Replies:** 4\
**Last updated:** [April 24, 2023, 2:02pm UTC](https://discuss.elastic.co/t/npx-elastic-synthetic-journeys-command-to-run-on-specific-journey-ts-files/330473 "2023-04-24T14:02:54Z")

</div>

Hello there, I've been playing with the --pattern, --match and --tags CLI parameters to get just a specific .journey.ts synthetic to execute locally (which will eventually be used in a push command). In my project/jour…

---

## [Logstash show error "undefined method \`length' for nil:NilClass"](https://discuss.elastic.co/t/logstash-show-error-undefined-method-length-for-nil-nilclass/330373)

<div class="topic-metadata">

**Author:** [@C\_Wesley](https://discuss.elastic.co/u/C_Wesley)\
**Replies:** 7\
**Last updated:** [April 24, 2023, 1:20pm UTC](https://discuss.elastic.co/t/logstash-show-error-undefined-method-length-for-nil-nilclass/330373 "2023-04-24T13:20:09Z")

</div>

Hi there, I have an issue with the title. When I send the JSON log to Filebeat and send it ti my logstash, sometimes it passes the filter, but sometimes it fails. Would you please help me check my configuration to see w…

---

## [Different filters for different visualizations inside the same dashboard](https://discuss.elastic.co/t/different-filters-for-different-visualizations-inside-the-same-dashboard/330208)

<div class="topic-metadata">

**Author:** [@InesCM](https://discuss.elastic.co/u/InesCM)\
**Replies:** 6\
**Last updated:** [April 24, 2023, 11:21am UTC](https://discuss.elastic.co/t/different-filters-for-different-visualizations-inside-the-same-dashboard/330208 "2023-04-24T11:21:13Z")

</div>

Hi! I'm building a dashboard that has two visualizations, each of them taking data from different indexes. I want to apply a filter (that can be edited on the dashboard to show different data), but as the data comes fro…

---

## [Unable to configure elastic search apt repository as a remote repository in Artifactory](https://discuss.elastic.co/t/unable-to-configure-elastic-search-apt-repository-as-a-remote-repository-in-artifactory/330286)

<div class="topic-metadata">

**Author:** [@joaobaptista](https://discuss.elastic.co/u/joaobaptista)\
**Replies:** 4\
**Last updated:** [April 24, 2023, 9:00am UTC](https://discuss.elastic.co/t/unable-to-configure-elastic-search-apt-repository-as-a-remote-repository-in-artifactory/330286 "2023-04-24T09:00:57Z")

</div>

Hi all, We are trying to configure Elasticsearch apt repository in Artifactory, but it always fails due to a error: "HTTP ERROR 404" We are using the following URL: https://artifacts.elastic.co/packages/8.x/apt The sa…

---

## [What diffirent about nested and bool composite query](https://discuss.elastic.co/t/what-diffirent-about-nested-and-bool-composite-query/330063)

<div class="topic-metadata">

**Author:** [@sslhj](https://discuss.elastic.co/u/sslhj)\
**Replies:** 2\
**Last updated:** [April 24, 2023, 7:55am UTC](https://discuss.elastic.co/t/what-diffirent-about-nested-and-bool-composite-query/330063 "2023-04-24T07:55:36Z")

</div>

I have devloped a component that translate expression to esdel, now i have an exp like that "((extras.key== ‘k1’ and extras.value==100 ) or (extras.key== “k2” and extras.value==”v2”))", in that, ”extras“ is a nested fie…

---

## [In Elastic search, can we change the names of retrieved fields of searched response dynamically, like mongoDB projection?](https://discuss.elastic.co/t/in-elastic-search-can-we-change-the-names-of-retrieved-fields-of-searched-response-dynamically-like-mongodb-projection/330599)

<div class="topic-metadata">

**Author:** [@cvam199](https://discuss.elastic.co/u/cvam199)\
**Replies:** 3\
**Last updated:** [April 24, 2023, 6:42am UTC](https://discuss.elastic.co/t/in-elastic-search-can-we-change-the-names-of-retrieved-fields-of-searched-response-dynamically-like-mongodb-projection/330599 "2023-04-24T06:42:21Z")

</div>

When I query on Elasticsearch (ES) to get some data, I get it in following format: Response: "hits" : \[ { "\_index" : "testpoc", "\_type" : "\_doc", "\_id" : "1", "\_score" : 1.0, …

---

## [Elasticsearch template not working](https://discuss.elastic.co/t/elasticsearch-template-not-working/330574)

<div class="topic-metadata">

**Author:** [@jiankunking](https://discuss.elastic.co/u/jiankunking)\
**Replies:** 7\
**Last updated:** [April 24, 2023, 6:13am UTC](https://discuss.elastic.co/t/elasticsearch-template-not-working/330574 "2023-04-24T06:13:59Z")

</div>

I first write data directly to the specified index, and then create an index template, After the index template is created, I continue to write data into the specified index. At this time, I write the new properties of …

---

## [Question about DNS in a "regular" network](https://discuss.elastic.co/t/question-about-dns-in-a-regular-network/330596)

<div class="topic-metadata">

**Author:** [@GKre](https://discuss.elastic.co/u/GKre)\
**Replies:** 0\
**Last updated:** [April 24, 2023, 4:49am UTC](https://discuss.elastic.co/t/question-about-dns-in-a-regular-network/330596 "2023-04-24T04:49:58Z")

</div>

Hello, after collecting a lot of data from my firewall i wonder about the "structure" of the data in my network. What i found out in the past - there's more than 50 % of the overall traffic caused by DNS. My sonicwall…

---

## [Filter message log in logstash](https://discuss.elastic.co/t/filter-message-log-in-logstash/330524)

<div class="topic-metadata">

**Author:** [@kibana\_dev\_iko](https://discuss.elastic.co/u/kibana_dev_iko)\
**Replies:** 1\
**Last updated:** [April 24, 2023, 2:37am UTC](https://discuss.elastic.co/t/filter-message-log-in-logstash/330524 "2023-04-24T02:37:04Z")

</div>

i want to add filter to logstash to convert message to json format this is my example API response \< HTTP 200 - body: {"result": \[{"status": {"code": -18, "message": "No permission for the resource"}, "url": "/os/hi"}\]…

[Previous page](https://discuss.elastic.co/tag/none.md?no_tags=true&page=390)

[Next page](https://discuss.elastic.co/tag/none.md?no_tags=true&page=392)
