# \#none

**URL:** https://discuss.elastic.co/tag/none.md?no_tags=true&page=400

[Latest](https://discuss.elastic.co/latest.md) · [Categories](https://discuss.elastic.co/categories.md) · [Tags](https://discuss.elastic.co/tags.md)

**Page:** 401

---

## [Search: Filter data after an aggregation](https://discuss.elastic.co/t/search-filter-data-after-an-aggregation/329760)

<div class="topic-metadata">

**Author:** [@gutierrezfj](https://discuss.elastic.co/u/gutierrezfj)\
**Replies:** 2\
**Last updated:** [April 12, 2023, 10:25am UTC](https://discuss.elastic.co/t/search-filter-data-after-an-aggregation/329760 "2023-04-12T10:25:17Z")

</div>

Hi community. I have made a query to obtain the average number of bytes per browser type, but I require that only the data that has an average less than 5000 be displayed or retrieved. I have read a lot but nothing con…

---

## [How to create new field after subtracting 2 date time field](https://discuss.elastic.co/t/how-to-create-new-field-after-subtracting-2-date-time-field/329822)

<div class="topic-metadata">

**Author:** [@rkidev](https://discuss.elastic.co/u/rkidev)\
**Replies:** 0\
**Last updated:** [April 12, 2023, 10:08am UTC](https://discuss.elastic.co/t/how-to-create-new-field-after-subtracting-2-date-time-field/329822 "2023-04-12T10:08:19Z")

</div>

I want to create one new field type String in existing index after subtracting two datetime (format - 2023-04-31 23:23:13). It should return 'Type-1' if seconds difference is more than or equal to 180 and should return '…

---

## [Multiple configuration or multiple codec](https://discuss.elastic.co/t/multiple-configuration-or-multiple-codec/329752)

<div class="topic-metadata">

**Author:** [@JackieLaFrite](https://discuss.elastic.co/u/JackieLaFrite)\
**Replies:** 2\
**Last updated:** [April 12, 2023, 9:44am UTC](https://discuss.elastic.co/t/multiple-configuration-or-multiple-codec/329752 "2023-04-12T09:44:11Z")

</div>

Here is my logstash.conf file input { file { path =\> "/var/log/appslogs/\*\*/\*.log" start\_position =\> "beginning" sincedb\_path =\> "/dev/null" codec =\> plain { charset =\> "UTF-8" } type =\> "…

---

## [Help with this grok](https://discuss.elastic.co/t/help-with-this-grok/329817)

<div class="topic-metadata">

**Author:** [@roman-tasi](https://discuss.elastic.co/u/roman-tasi)\
**Replies:** 1\
**Last updated:** [April 12, 2023, 9:28am UTC](https://discuss.elastic.co/t/help-with-this-grok/329817 "2023-04-12T09:28:39Z")

</div>

Need a grok filter that parses out the account (the peacesat) from these two types of logs Case 1: Apr 11 14:26:55 mail saslauthd\[15405\]: auth\_zimbra: peacesat@uhtasi.org auth failed: authentication failed for \[peacesa…

---

## [ELK on AWS](https://discuss.elastic.co/t/elk-on-aws/329819)

<div class="topic-metadata">

**Author:** [@Ankita\_Pachauri](https://discuss.elastic.co/u/Ankita_Pachauri)\
**Replies:** 0\
**Last updated:** [April 12, 2023, 9:25am UTC](https://discuss.elastic.co/t/elk-on-aws/329819 "2023-04-12T09:25:14Z")

</div>

Hi Team, We did install elk \[3 elastic nodes and 2 kibana nodes on us-east-1a,us-east-1b\] on AWS. We are trying to access Kibana dashboard via NLB with ACM\[AWS certificate Manager\] ,but somehow when I am starting kiba…

---

## [Elastic user password change in kubernetes secret](https://discuss.elastic.co/t/elastic-user-password-change-in-kubernetes-secret/329328)

<div class="topic-metadata">

**Author:** [@basavarajvn0513](https://discuss.elastic.co/u/basavarajvn0513)\
**Replies:** 2\
**Last updated:** [April 12, 2023, 9:18am UTC](https://discuss.elastic.co/t/elastic-user-password-change-in-kubernetes-secret/329328 "2023-04-12T09:18:19Z")

</div>

I have elasticsearch ,kiabana,logstash,filebeat in kuberentes. All use the same elasatic username and password as ENV variables from the secret .yaml. I want to change the password for the elastic user . After I change …

---

## [How elasticsearch distribute the requests from client](https://discuss.elastic.co/t/how-elasticsearch-distribute-the-requests-from-client/329815)

<div class="topic-metadata">

**Author:** [@qksjdhi1212](https://discuss.elastic.co/u/qksjdhi1212)\
**Replies:** 1\
**Last updated:** [April 12, 2023, 8:53am UTC](https://discuss.elastic.co/t/how-elasticsearch-distribute-the-requests-from-client/329815 "2023-04-12T08:53:27Z")

</div>

I want to know the whole process where elasticsearch distribute the request received from client server (logstash, application, fluentd etc.) does the master node in cluster just assign the request to the most stable no…

---

## [Kibana Uptime monitors broken after migrating to another cluster](https://discuss.elastic.co/t/kibana-uptime-monitors-broken-after-migrating-to-another-cluster/329727)

<div class="topic-metadata">

**Author:** [@George\_ML](https://discuss.elastic.co/u/George_ML)\
**Replies:** 3\
**Last updated:** [April 12, 2023, 8:15am UTC](https://discuss.elastic.co/t/kibana-uptime-monitors-broken-after-migrating-to-another-cluster/329727 "2023-04-12T08:15:29Z")

</div>

Hello, I have recently migrated to another cluster, but I have restored the snapshot after the cluster creation. Because of this, I think some encryption keys for the encrypted saved objects have been changed. This cau…

---

## [Logstash plugin install : Error socket closed](https://discuss.elastic.co/t/logstash-plugin-install-error-socket-closed/328243)

<div class="topic-metadata">

**Author:** [@Julien069](https://discuss.elastic.co/u/Julien069)\
**Replies:** 22\
**Last updated:** [April 12, 2023, 7:50am UTC](https://discuss.elastic.co/t/logstash-plugin-install-error-socket-closed/328243 "2023-04-12T07:50:09Z")

</div>

Hi , I want to install a Stormshield plugin for Logstash I tried bin/logstash-plugin install --no-verify logstash-filter-SNS I have "ERROR : Something went wrong when installalling bin/logstash-filter-SNS , message s…

---

## [Anonymous access is denied in kibana?](https://discuss.elastic.co/t/anonymous-access-is-denied-in-kibana/329799)

<div class="topic-metadata">

**Author:** [@Shreesh\_Narayanan](https://discuss.elastic.co/u/Shreesh_Narayanan)\
**Replies:** 1\
**Last updated:** [April 12, 2023, 6:29am UTC](https://discuss.elastic.co/t/anonymous-access-is-denied-in-kibana/329799 "2023-04-12T06:29:09Z")

</div>

Hi Folks, I have 3 node elasticsearch , 2 logstash nodes and 1 kibana node . Do i mention all three elasticsearch nodes in kibana.yml's "elasticsearch.hosts" config line ? . It was working when i had just the master el…

---

## [Cannt find dependency for CommonAnalysisPlugin](https://discuss.elastic.co/t/cannt-find-dependency-for-commonanalysisplugin/329798)

<div class="topic-metadata">

**Author:** [@yeziblo](https://discuss.elastic.co/u/yeziblo)\
**Replies:** 1\
**Last updated:** [April 12, 2023, 6:05am UTC](https://discuss.elastic.co/t/cannt-find-dependency-for-commonanalysisplugin/329798 "2023-04-12T06:05:08Z")

</div>

Hello everyone, I am currently trying to upgrade my Elasticsearch version from 7.8.1 to 7.17.4. However, after the upgrade, I encountered an error in my project: Cannot resolve symbol 'CommonAnalysisPlugin In Elastics…

---

## [Duration time between logs](https://discuss.elastic.co/t/duration-time-between-logs/329757)

<div class="topic-metadata">

**Author:** [@justme123](https://discuss.elastic.co/u/justme123)\
**Replies:** 2\
**Last updated:** [April 12, 2023, 5:54am UTC](https://discuss.elastic.co/t/duration-time-between-logs/329757 "2023-04-12T05:54:21Z")

</div>

Hi Everyone ! I'm new to elastic and kibana and I have some troubles with duration time between log event. I have 2 logs that i get via SNMP Trap : referenceNumber : 123456 alarmType: 2 @timestamp : 2023-04-11T09:…

---

## [Elasticsearch](https://discuss.elastic.co/t/elasticsearch/329426)

<div class="topic-metadata">

**Author:** [@MahithaSarala](https://discuss.elastic.co/u/MahithaSarala)\
**Replies:** 2\
**Last updated:** [April 12, 2023, 5:23am UTC](https://discuss.elastic.co/t/elasticsearch/329426 "2023-04-12T05:23:51Z")

</div>

Hi team, How to deploy metric beats for elasticsearch and kibana using ECK, Is there any document for this . because not able to see all logs for kibana and elasticsearch . Could you help on this

---

## [Waiting for the transport certificates](https://discuss.elastic.co/t/waiting-for-the-transport-certificates/329789)

<div class="topic-metadata">

**Author:** [@SeibertronSS](https://discuss.elastic.co/u/SeibertronSS)\
**Replies:** 2\
**Last updated:** [April 12, 2023, 5:21am UTC](https://discuss.elastic.co/t/waiting-for-the-transport-certificates/329789 "2023-04-12T05:21:35Z")

</div>

Hi, I followed ECK's documentation to install elasticsearch using Elastic Operator. My elasticsearch pod is stuck in Init state when I use the provided quick start, here is a snippet of its log Starting init script Link…

---

## [I am unable to run Kibana 8.6.1 from browser](https://discuss.elastic.co/t/i-am-unable-to-run-kibana-8-6-1-from-browser/329137)

<div class="topic-metadata">

**Author:** [@Aysh14](https://discuss.elastic.co/u/Aysh14)\
**Replies:** 8\
**Last updated:** [April 12, 2023, 5:10am UTC](https://discuss.elastic.co/t/i-am-unable-to-run-kibana-8-6-1-from-browser/329137 "2023-04-12T05:10:38Z")

</div>

Hi Team, I am unable to connect to kibana from browser. I have installed Kibana, 8.6.1 . I am getting HTTP/1.1 302 Found when I do a curl on the URL from the VM , but unable to get response when I try to access from br…

---

## [Kube State Metrics stop reporting / Potential Leader Election issue](https://discuss.elastic.co/t/kube-state-metrics-stop-reporting-potential-leader-election-issue/329794)

<div class="topic-metadata">

**Author:** [@RichardMatthews](https://discuss.elastic.co/u/RichardMatthews)\
**Replies:** 0\
**Last updated:** [April 12, 2023, 4:00am UTC](https://discuss.elastic.co/t/kube-state-metrics-stop-reporting-potential-leader-election-issue/329794 "2023-04-12T04:00:19Z")

</div>

Hey, I am having an issue with collecting data from kube state metrics where it will randomly stop coming through into Kibana and all that seems to help is restarting the elastic-agents until it starts to come back. I …

---

## [ElasticSearch delete model with force does not work](https://discuss.elastic.co/t/elasticsearch-delete-model-with-force-does-not-work/329781)

<div class="topic-metadata">

**Author:** [@Diogo\_Moura](https://discuss.elastic.co/u/Diogo_Moura)\
**Replies:** 0\
**Last updated:** [April 11, 2023, 10:23pm UTC](https://discuss.elastic.co/t/elasticsearch-delete-model-with-force-does-not-work/329781 "2023-04-11T22:23:17Z")

</div>

According to the documentation here https://www.elastic.co/guide/en/elasticsearch/reference/8.6/delete-trained-models.html#ml-delete-trained-models-query-parms it is possible to use the parameter "force" to force the de…

---

## [Bulk alerting configuration](https://discuss.elastic.co/t/bulk-alerting-configuration/327511)

<div class="topic-metadata">

**Author:** [@rossw](https://discuss.elastic.co/u/rossw)\
**Replies:** 5\
**Last updated:** [April 11, 2023, 9:13pm UTC](https://discuss.elastic.co/t/bulk-alerting-configuration/327511 "2023-04-11T21:13:48Z")

</div>

Afternoon, We are using the alerting functionality inside the Elastic Security toolset, and we have turned on about 100-odd rules. We have created email and webhook integrations and have started to tune the data being …

---

## [FortiMail logs are being combined in TCP input](https://discuss.elastic.co/t/fortimail-logs-are-being-combined-in-tcp-input/329768)

<div class="topic-metadata">

**Author:** [@6igwig](https://discuss.elastic.co/u/6igwig)\
**Replies:** 4\
**Last updated:** [April 11, 2023, 7:12pm UTC](https://discuss.elastic.co/t/fortimail-logs-are-being-combined-in-tcp-input/329768 "2023-04-11T19:12:53Z")

</div>

I have configured a tcp input in logstash to receive FortiMail logs. I believe the logs are losing their new line character in transit because all of the logs come in as a single document. (If I leave the pipeline runnin…

---

## [Is Elasticsearch paid?](https://discuss.elastic.co/t/is-elasticsearch-paid/329759)

<div class="topic-metadata">

**Author:** [@adzik](https://discuss.elastic.co/u/adzik)\
**Replies:** 6\
**Last updated:** [April 11, 2023, 5:52pm UTC](https://discuss.elastic.co/t/is-elasticsearch-paid/329759 "2023-04-11T17:52:54Z")

</div>

Hello, I have an ecommerce app and I would like to utilize Elasticsearch to search my products by customers. Do I need to buy a license in this case? I just want to make sure

---

## [Elasicsearch index error: org.elasticsearch.core.Tuple.v2()" is null](https://discuss.elastic.co/t/elasicsearch-index-error-org-elasticsearch-core-tuple-v2-is-null/329763)

<div class="topic-metadata">

**Author:** [@vanwoes](https://discuss.elastic.co/u/vanwoes)\
**Replies:** 0\
**Last updated:** [April 11, 2023, 4:06pm UTC](https://discuss.elastic.co/t/elasicsearch-index-error-org-elasticsearch-core-tuple-v2-is-null/329763 "2023-04-11T16:06:53Z")

</div>

Hi there, We have recently moved from a single node to multi node cluster and I have set up an ILM to move from hot, warm to cold. I keep seeing data moving from cold to warm despite it being marked as complete. I'm co…

---

## [Logstash error](https://discuss.elastic.co/t/logstash-error/329706)

<div class="topic-metadata">

**Author:** [@sks](https://discuss.elastic.co/u/sks)\
**Replies:** 1\
**Last updated:** [April 11, 2023, 3:16pm UTC](https://discuss.elastic.co/t/logstash-error/329706 "2023-04-11T15:16:08Z")

</div>

Dear sir ; i want to send a json log file from my local pc to Elasticsearch my sample json file is { "people" : \[ { "firstName": "Joe", "lastName": "Jackson", "gender": "male", "age": 28, "number": "7349282382" …

---

## [Grok filter isn't working but working in kibana grok debugger](https://discuss.elastic.co/t/grok-filter-isnt-working-but-working-in-kibana-grok-debugger/329755)

<div class="topic-metadata">

**Author:** [@ira-zaya](https://discuss.elastic.co/u/ira-zaya)\
**Replies:** 0\
**Last updated:** [April 11, 2023, 2:44pm UTC](https://discuss.elastic.co/t/grok-filter-isnt-working-but-working-in-kibana-grok-debugger/329755 "2023-04-11T14:44:21Z")

</div>

Hi. I have the following logstash configuration: filter { if "platform1" in \[tags\] { grok { match =\> { "message" =\> \['%{TIMESTAMP\_ISO8601:timestamp}? ?\\\[?L?:? ?%{LOGLEVEL:logLevel}?\\\]…

---

## [Parsing logfiles](https://discuss.elastic.co/t/parsing-logfiles/329505)

<div class="topic-metadata">

**Author:** [@SIRAJEDDINE-HAMZA](https://discuss.elastic.co/u/SIRAJEDDINE-HAMZA)\
**Replies:** 2\
**Last updated:** [April 11, 2023, 1:08pm UTC](https://discuss.elastic.co/t/parsing-logfiles/329505 "2023-04-11T13:08:16Z")

</div>

I'm new to using ElasticStack and I'm having trouble parsing a log file using Logstash. Specifically, I want to split the file using the timestamp as a separator and extract data from each block, but I'm not sure how to …

---

## [License in a cluster](https://discuss.elastic.co/t/license-in-a-cluster/329502)

<div class="topic-metadata">

**Author:** [@Joel\_Goncalves](https://discuss.elastic.co/u/Joel_Goncalves)\
**Replies:** 6\
**Last updated:** [April 11, 2023, 12:33pm UTC](https://discuss.elastic.co/t/license-in-a-cluster/329502 "2023-04-11T12:33:05Z")

</div>

Hello I have a cluster with 5 nodes, one of them (master) is installed on-premises and I have 4 nodes connected to it if I put a license on elasticsearch which is installed on-premises will this license be passed to the…

---

## [Active alert for terminated instance](https://discuss.elastic.co/t/active-alert-for-terminated-instance/329552)

<div class="topic-metadata">

**Author:** [@leandro.silva](https://discuss.elastic.co/u/leandro.silva)\
**Replies:** 1\
**Last updated:** [April 11, 2023, 12:27pm UTC](https://discuss.elastic.co/t/active-alert-for-terminated-instance/329552 "2023-04-11T12:27:52Z")

</div>

I've installed the elastic agent on some instances. On March 27 one instance generated an alert about hard disk available space. On March 31 the instance was terminated. The problem is that the alert is still active. Te…

---

## [Bulk ingester no close at the end](https://discuss.elastic.co/t/bulk-ingester-no-close-at-the-end/329633)

<div class="topic-metadata">

**Author:** [@ALX\_DM](https://discuss.elastic.co/u/ALX_DM)\
**Replies:** 3\
**Last updated:** [April 11, 2023, 12:11pm UTC](https://discuss.elastic.co/t/bulk-ingester-no-close-at-the-end/329633 "2023-04-11T12:11:49Z")

</div>

I read the documents but it is not clear to me. I have this code: public void indexProduct(Product product) { try (BulkIngester\<String\> bulkIngester = indexingService.createBulkIngester()) { indexingService.bulkI…

---

## [Run direct dsl query using high level client elasticsearch](https://discuss.elastic.co/t/run-direct-dsl-query-using-high-level-client-elasticsearch/329746)

<div class="topic-metadata">

**Author:** [@mangeshs](https://discuss.elastic.co/u/mangeshs)\
**Replies:** 0\
**Last updated:** [April 11, 2023, 11:56am UTC](https://discuss.elastic.co/t/run-direct-dsl-query-using-high-level-client-elasticsearch/329746 "2023-04-11T11:56:47Z")

</div>

I am trying run dsl query directly as we do from dev tools. I created java api for that but want provide formatted string. Is there any way to do this? in Elasticsearch

---

## [How to set default value for rank\_feature field type](https://discuss.elastic.co/t/how-to-set-default-value-for-rank-feature-field-type/329694)

<div class="topic-metadata">

**Author:** [@binoiii](https://discuss.elastic.co/u/binoiii)\
**Replies:** 0\
**Last updated:** [April 11, 2023, 1:09am UTC](https://discuss.elastic.co/t/how-to-set-default-value-for-rank-feature-field-type/329694 "2023-04-11T01:09:13Z")

</div>

I'm performing a rank\_feature query and there is a possibility that the fields that I will rank i.e bid field (please below) won't be available. I wonder if there is a way to set a default for bid if the field is not pr…

---

## [How to receive alerts in two elasticsearch](https://discuss.elastic.co/t/how-to-receive-alerts-in-two-elasticsearch/329743)

<div class="topic-metadata">

**Author:** [@Joel\_Goncalves](https://discuss.elastic.co/u/Joel_Goncalves)\
**Replies:** 0\
**Last updated:** [April 11, 2023, 11:40am UTC](https://discuss.elastic.co/t/how-to-receive-alerts-in-two-elasticsearch/329743 "2023-04-11T11:40:51Z")

</div>

Hello, I want to know how do I send alerts from one elasticsearch to another. Let's imagine that I have 2 elasticsearch servers in different networks and clusters and on one server I have the fleet installed and several …

[Previous page](https://discuss.elastic.co/tag/none.md?no_tags=true&page=399)

[Next page](https://discuss.elastic.co/tag/none.md?no_tags=true&page=401)
