# \#none

**URL:** https://discuss.elastic.co/tag/none.md?no_tags=true&page=401

[Latest](https://discuss.elastic.co/latest.md) · [Categories](https://discuss.elastic.co/categories.md) · [Tags](https://discuss.elastic.co/tags.md)

**Page:** 402

---

## [Search logs for sensitive data](https://discuss.elastic.co/t/search-logs-for-sensitive-data/329734)

<div class="topic-metadata">

**Author:** [@Cejs](https://discuss.elastic.co/u/Cejs)\
**Replies:** 0\
**Last updated:** [April 11, 2023, 10:43am UTC](https://discuss.elastic.co/t/search-logs-for-sensitive-data/329734 "2023-04-11T10:43:22Z")

</div>

Hi, I am working on finding logs with potentially sensitive content like personal data and I would like to ask for your experience. Do you guys have some source I can use to define patterns for regexes? I have only som…

---

## [How to view documents by lucene segment?](https://discuss.elastic.co/t/how-to-view-documents-by-lucene-segment/329512)

<div class="topic-metadata">

**Author:** [@nisow95612](https://discuss.elastic.co/u/nisow95612)\
**Replies:** 2\
**Last updated:** [April 11, 2023, 10:16am UTC](https://discuss.elastic.co/t/how-to-view-documents-by-lucene-segment/329512 "2023-04-11T10:16:03Z")

</div>

Hello elasticsearch, I have a tricky question. I accidentally reindexed a bunch of documents into a wrong index. This original index was previously forcemerged to one big segment per shard. Indexing new documents creat…

---

## [What the different between ClusterStateTaskListener and AckedClusterStateTaskListener](https://discuss.elastic.co/t/what-the-different-between-clusterstatetasklistener-and-ackedclusterstatetasklistener/329719)

<div class="topic-metadata">

**Author:** [@cm\_z](https://discuss.elastic.co/u/cm_z)\
**Replies:** 2\
**Last updated:** [April 11, 2023, 10:05am UTC](https://discuss.elastic.co/t/what-the-different-between-clusterstatetasklistener-and-ackedclusterstatetasklistener/329719 "2023-04-11T10:05:25Z")

</div>

what the different between ClusterStateTaskListener.clusterStateProcessed and AckedClusterStateTaskListener.onAllNodesAcked , they all call after elasticsearch publish finish.

---

## [Elasticsearch Cluster Sizing](https://discuss.elastic.co/t/elasticsearch-cluster-sizing/329703)

<div class="topic-metadata">

**Author:** [@Darshan\_J](https://discuss.elastic.co/u/Darshan_J)\
**Replies:** 4\
**Last updated:** [April 11, 2023, 9:57am UTC](https://discuss.elastic.co/t/elasticsearch-cluster-sizing/329703 "2023-04-11T09:57:00Z")

</div>

The webinar above showcases bunch of formulas for Elasticsearch cluster sizing. There are discussions where responses show unfamiliarity with the formulas or techniques given in the webinar. The discussion also follows…

---

## [How to exploit rules](https://discuss.elastic.co/t/how-to-exploit-rules/328174)

<div class="topic-metadata">

**Author:** [@Iroshu](https://discuss.elastic.co/u/Iroshu)\
**Replies:** 10\
**Last updated:** [April 11, 2023, 8:58am UTC](https://discuss.elastic.co/t/how-to-exploit-rules/328174 "2023-04-11T08:58:30Z")

</div>

Dear team, We are actually playing with the detection of elastic and something seems weird for us. We have created a Rule and we add an action in order to populate an index using our collector : We choose all fied…

---

## [Logstash input pipelines are slow after restart](https://discuss.elastic.co/t/logstash-input-pipelines-are-slow-after-restart/329715)

<div class="topic-metadata">

**Author:** [@Amit\_Gupta2](https://discuss.elastic.co/u/Amit_Gupta2)\
**Replies:** 1\
**Last updated:** [April 11, 2023, 8:03am UTC](https://discuss.elastic.co/t/logstash-input-pipelines-are-slow-after-restart/329715 "2023-04-11T08:03:56Z")

</div>

Hi Team, I am facing slowness issue in data sync after every restart of logstash. My observation is that input pipeline are taking time to start in parallel. I am using Logstash 6.8 which is deployed on an EC2 instance…

---

## [Logs getting Merged/clubbed with each other in some cases](https://discuss.elastic.co/t/logs-getting-merged-clubbed-with-each-other-in-some-cases/329588)

<div class="topic-metadata">

**Author:** [@shadu88](https://discuss.elastic.co/u/shadu88)\
**Replies:** 10\
**Last updated:** [April 11, 2023, 7:52am UTC](https://discuss.elastic.co/t/logs-getting-merged-clubbed-with-each-other-in-some-cases/329588 "2023-04-11T07:52:05Z")

</div>

Hello Dear ELKs, I'm using logstash7.10 for forward the logs to Qradar and Azure sentinel. Have noticed some irregularities with some log source type. Log flow : heterogenous logs -\> file --\> logstash( file input) --\> …

---

## [Storage Configuration Question](https://discuss.elastic.co/t/storage-configuration-question/329675)

<div class="topic-metadata">

**Author:** [@Safty](https://discuss.elastic.co/u/Safty)\
**Replies:** 1\
**Last updated:** [April 10, 2023, 8:00pm UTC](https://discuss.elastic.co/t/storage-configuration-question/329675 "2023-04-10T20:00:21Z")

</div>

Hello, In the storage documentation link There is a reference in the path.data section that states the following: "Elasticsearch requires the filesystem to act as if it were backed by a local disk, but this means that…

---

## [Pod container logs stop randomly](https://discuss.elastic.co/t/pod-container-logs-stop-randomly/325632)

<div class="topic-metadata">

**Author:** [@woodywoodsta](https://discuss.elastic.co/u/woodywoodsta)\
**Replies:** 5\
**Last updated:** [April 10, 2023, 5:20pm UTC](https://discuss.elastic.co/t/pod-container-logs-stop-randomly/325632 "2023-04-10T17:20:23Z")

</div>

Since upgrading to 8.6.1 (from 8.5.x), I'm finding that logs that are supposed to be collected via the Kubernetes Integration for an elastic agent in Fleet mode are stopping completely and randomly (as far as I can see). …

---

## [Help - Display correct document from multiple aggregation](https://discuss.elastic.co/t/help-display-correct-document-from-multiple-aggregation/329669)

<div class="topic-metadata">

**Author:** [@Santiago\_Lovera](https://discuss.elastic.co/u/Santiago_Lovera)\
**Replies:** 0\
**Last updated:** [April 10, 2023, 3:18pm UTC](https://discuss.elastic.co/t/help-display-correct-document-from-multiple-aggregation/329669 "2023-04-10T15:18:35Z")

</div>

I need help please. I want to display a label in vega with information returned by one aggregation operation. I'm only looking for just 2 documents the minimum and the maximum for the log.json.sequence field. When I …

---

## [Treemap aggregation is not right](https://discuss.elastic.co/t/treemap-aggregation-is-not-right/329539)

<div class="topic-metadata">

**Author:** [@stramzik](https://discuss.elastic.co/u/stramzik)\
**Replies:** 4\
**Last updated:** [April 10, 2023, 12:27pm UTC](https://discuss.elastic.co/t/treemap-aggregation-is-not-right/329539 "2023-04-10T12:27:58Z")

</div>

Hi, When showing a 2 level tree map if the bottom level is averaged why does the top level sum the averages? {"Country": "India", "sample":1 , "State":"Karnataka" } {"Country": "India", "sample": 2, "State":"Delhi" }…

---

## [How to created multi field parsh message from snort](https://discuss.elastic.co/t/how-to-created-multi-field-parsh-message-from-snort/329637)

<div class="topic-metadata">

**Author:** [@wisnu\_adiputra](https://discuss.elastic.co/u/wisnu_adiputra)\
**Replies:** 1\
**Last updated:** [April 10, 2023, 12:15pm UTC](https://discuss.elastic.co/t/how-to-created-multi-field-parsh-message-from-snort/329637 "2023-04-10T12:15:06Z")

</div>

Continuing the discussion from Grok pattern for snort alerts: 1/03-21:37:12.106096 \[\] \[1:249:8\] DDOS mstream client to handler \[\] \[Classification: Attempted Denial of Service\] \[Priority: 2\] {TCP} 172.16.0.5:61301 -\> 19…

---

## [How can I make logstash automatically send my information to elasticsearch?](https://discuss.elastic.co/t/how-can-i-make-logstash-automatically-send-my-information-to-elasticsearch/329447)

<div class="topic-metadata">

**Author:** [@Raul\_dum](https://discuss.elastic.co/u/Raul_dum)\
**Replies:** 5\
**Last updated:** [April 10, 2023, 7:38am UTC](https://discuss.elastic.co/t/how-can-i-make-logstash-automatically-send-my-information-to-elasticsearch/329447 "2023-04-10T07:38:20Z")

</div>

Hi I was wondering if there is a method on how I could make logstash automatically send information to my elasticsearch.I have my config file : input { stdin {} } filter { grok { match =\> { "message" =\> "time=…

---

## [Self Managed ElasticSearch Cluster on AWS](https://discuss.elastic.co/t/self-managed-elasticsearch-cluster-on-aws/329645)

<div class="topic-metadata">

**Author:** [@shreyansh](https://discuss.elastic.co/u/shreyansh)\
**Replies:** 0\
**Last updated:** [April 10, 2023, 7:48am UTC](https://discuss.elastic.co/t/self-managed-elasticsearch-cluster-on-aws/329645 "2023-04-10T07:48:35Z")

</div>

I am trying to setup a production ready self managed Elasticsearch cluster on AWS. The main reason for going self managed is that we want: Latest ES version (8.6+) Deploy in a specific VPC Install custom plugins We ar…

---

## [Elastic search update document , Java client-8.7](https://discuss.elastic.co/t/elastic-search-update-document-java-client-8-7/329644)

<div class="topic-metadata">

**Author:** [@Adarsh\_R\_K](https://discuss.elastic.co/u/Adarsh_R_K)\
**Replies:** 0\
**Last updated:** [April 10, 2023, 7:25am UTC](https://discuss.elastic.co/t/elastic-search-update-document-java-client-8-7/329644 "2023-04-10T07:25:10Z")

</div>

How to update a document using elasticsearch Java client-8.7 , I could not find any documentation,All the avalilable ones are deprecated.

---

## [Clarification on cold/frozen state](https://discuss.elastic.co/t/clarification-on-cold-frozen-state/329575)

<div class="topic-metadata">

**Author:** [@QwerFact](https://discuss.elastic.co/u/QwerFact)\
**Replies:** 2\
**Last updated:** [April 10, 2023, 6:58am UTC](https://discuss.elastic.co/t/clarification-on-cold-frozen-state/329575 "2023-04-10T06:58:33Z")

</div>

Hiya, with the changes in version 8, the frozen tier has evolved. I was wondering about the differences between cold, cold fully-mounted and frozen and especially between open source and enterprise/platinum versions. M…

---

## [Difference between KIBANA\_CA and KIBANA\_FLEET\_CA](https://discuss.elastic.co/t/difference-between-kibana-ca-and-kibana-fleet-ca/329634)

<div class="topic-metadata">

**Author:** [@OmFJ](https://discuss.elastic.co/u/OmFJ)\
**Replies:** 0\
**Last updated:** [April 10, 2023, 4:06am UTC](https://discuss.elastic.co/t/difference-between-kibana-ca-and-kibana-fleet-ca/329634 "2023-04-10T04:06:15Z")

</div>

Hello everyone. Currently i'm having trouble with applying elastic agent(managed by fleet) to my kubernetes environment. i think one of the related parameter is KIBANA\_CA and KIBANA\_FLEET\_CA. so far, i followed steps …

---

## [Unable to perform airthmetic operations in ruby using logstash pipeline](https://discuss.elastic.co/t/unable-to-perform-airthmetic-operations-in-ruby-using-logstash-pipeline/329587)

<div class="topic-metadata">

**Author:** [@Sujith\_Nair](https://discuss.elastic.co/u/Sujith_Nair)\
**Replies:** 10\
**Last updated:** [April 9, 2023, 1:54pm UTC](https://discuss.elastic.co/t/unable-to-perform-airthmetic-operations-in-ruby-using-logstash-pipeline/329587 "2023-04-09T13:54:45Z")

</div>

Hi guys, I am facing an issue where i am trying to perform an airthmetic operation using ruby but in at the field section i am getting the same value not the subtracted value. event.set('\[d\]', (event.get('\[b\]').to\_f) -…

---

## [Integration sophos Firewall with elastic](https://discuss.elastic.co/t/integration-sophos-firewall-with-elastic/329454)

<div class="topic-metadata">

**Author:** [@Ahmad\_Shrateh](https://discuss.elastic.co/u/Ahmad_Shrateh)\
**Replies:** 10\
**Last updated:** [April 9, 2023, 1:17pm UTC](https://discuss.elastic.co/t/integration-sophos-firewall-with-elastic/329454 "2023-04-09T13:17:26Z")

</div>

Dear there. Im trying to connect sophos firewall with elastic but i don't receive any logs. Im deployed an agent with sophos integration, and i followed the instructions on the elastic, i add my firewall ip instead …

---

## [ERROR: Failed to reset password for the \[elastic\] user](https://discuss.elastic.co/t/error-failed-to-reset-password-for-the-elastic-user/329618)

<div class="topic-metadata">

**Author:** [@hadi\_farzipour](https://discuss.elastic.co/u/hadi_farzipour)\
**Replies:** 1\
**Last updated:** [April 9, 2023, 7:44am UTC](https://discuss.elastic.co/t/error-failed-to-reset-password-for-the-elastic-user/329618 "2023-04-09T07:44:55Z")

</div>

Hi, I installed elasticsearch 8.7 on my windows server but on installing screen I did not get any prompt for my elasticsearch or kibana password, also when I tried to change the password I faced following error: ERROR:…

---

## [Logstash running code](https://discuss.elastic.co/t/logstash-running-code/329408)

<div class="topic-metadata">

**Author:** [@sks](https://discuss.elastic.co/u/sks)\
**Replies:** 1\
**Last updated:** [April 5, 2023, 12:22pm UTC](https://discuss.elastic.co/t/logstash-running-code/329408 "2023-04-05T12:22:26Z")

</div>

Hyy, I am new to Elasticsearch . I am trying to send logfile from logstash to elasticsearch . for checking purspose i am running this config file as below vi logstash-simple.conf input { stdin { } } output { elasti…

---

## [Installing elasticsearch 8.6.2 on a windows server with ealsticserach 7.6.1](https://discuss.elastic.co/t/installing-elasticsearch-8-6-2-on-a-windows-server-with-ealsticserach-7-6-1/329281)

<div class="topic-metadata">

**Author:** [@hadi\_farzipour](https://discuss.elastic.co/u/hadi_farzipour)\
**Replies:** 7\
**Last updated:** [April 9, 2023, 5:01am UTC](https://discuss.elastic.co/t/installing-elasticsearch-8-6-2-on-a-windows-server-with-ealsticserach-7-6-1/329281 "2023-04-09T05:01:58Z")

</div>

In our company we have been using Elasticsearch 7.6.1 for two years, right now we need to update it to version 8.6.2, however, we can not move to version 8.6.2 immediately, we need first run Elasticsearch 8.6.2 beside th…

---

## [Geo\_shape query point in polygon runtime field for pre-indexed docs](https://discuss.elastic.co/t/geo-shape-query-point-in-polygon-runtime-field-for-pre-indexed-docs/329550)

<div class="topic-metadata">

**Author:** [@bchranko](https://discuss.elastic.co/u/bchranko)\
**Replies:** 3\
**Last updated:** [April 9, 2023, 12:48am UTC](https://discuss.elastic.co/t/geo-shape-query-point-in-polygon-runtime-field-for-pre-indexed-docs/329550 "2023-04-09T00:48:35Z")

</div>

I'm trying to create a geo\_shape query that will be used in a runtime field to tag a polygon 'id/name' to a point that it contains. I have two pre-indexed indexes: one for neighborhoods (polygon) and one for car crashe…

---

## [Search for a keyword in the field in the title, which can occur simultaneously several matching words from the query](https://discuss.elastic.co/t/search-for-a-keyword-in-the-field-in-the-title-which-can-occur-simultaneously-several-matching-words-from-the-query/329608)

<div class="topic-metadata">

**Author:** [@oleksiiorel](https://discuss.elastic.co/u/oleksiiorel)\
**Replies:** 0\
**Last updated:** [April 8, 2023, 10:25am UTC](https://discuss.elastic.co/t/search-for-a-keyword-in-the-field-in-the-title-which-can-occur-simultaneously-several-matching-words-from-the-query/329608 "2023-04-08T10:25:38Z")

</div>

I want to find blenders in elastic of a certain name & color and brand. To do this, specify 3 fields for the search, specifying in which field elastic should start the search. Elastic returns products that I have not sea…

---

## [Schedule , scroll , size Elasticsearch input plugin Plugin more explanation](https://discuss.elastic.co/t/schedule-scroll-size-elasticsearch-input-plugin-plugin-more-explanation/329606)

<div class="topic-metadata">

**Author:** [@alex\_petrov](https://discuss.elastic.co/u/alex_petrov)\
**Replies:** 0\
**Last updated:** [April 8, 2023, 6:11am UTC](https://discuss.elastic.co/t/schedule-scroll-size-elasticsearch-input-plugin-plugin-more-explanation/329606 "2023-04-08T06:11:51Z")

</div>

I am using elasticsearch index as my input in logstash.I read the documentation and don't understand the usage of schedule , scroll , size option.I need more explanation to understand these featues. Thanks

---

## [Design Index & Document](https://discuss.elastic.co/t/design-index-document/329596)

<div class="topic-metadata">

**Author:** [@YB\_Coding](https://discuss.elastic.co/u/YB_Coding)\
**Replies:** 0\
**Last updated:** [April 7, 2023, 6:47pm UTC](https://discuss.elastic.co/t/design-index-document/329596 "2023-04-07T18:47:45Z")

</div>

Hello everyone I have a hard time designing my documents. I do not know if I need to create multiple indexes, use nested fieds or index multiple times my documents with a field with a "versionning filter". Below my analo…

---

## [Updating @elastic/elasticsearch version on npm](https://discuss.elastic.co/t/updating-elastic-elasticsearch-version-on-npm/329595)

<div class="topic-metadata">

**Author:** [@Chukwuma\_Nwaugha](https://discuss.elastic.co/u/Chukwuma_Nwaugha)\
**Replies:** 0\
**Last updated:** [April 7, 2023, 6:01pm UTC](https://discuss.elastic.co/t/updating-elastic-elasticsearch-version-on-npm/329595 "2023-04-07T18:01:27Z")

</div>

The latest version of @elastic/elasticsearch is 8.7.0 but the version on npm is still at 8.6.0. When should an update be expected? Thanks and best regards, Chukwuma.

---

## [Creating an indicator match Watcher Alert](https://discuss.elastic.co/t/creating-an-indicator-match-watcher-alert/329590)

<div class="topic-metadata">

**Author:** [@Banderson02](https://discuss.elastic.co/u/Banderson02)\
**Replies:** 0\
**Last updated:** [April 7, 2023, 5:26pm UTC](https://discuss.elastic.co/t/creating-an-indicator-match-watcher-alert/329590 "2023-04-07T17:26:25Z")

</div>

Hello, Has anyone been able to replicate an indicator match alert like what is provided in Kibana security as an Elasticsearch Watcher alert? I have a deployment where we do not have access to Kibana Security, so I nee…

---

## [Can we create dependent inputs in logstash pipeline?](https://discuss.elastic.co/t/can-we-create-dependent-inputs-in-logstash-pipeline/329436)

<div class="topic-metadata">

**Author:** [@Disha\_Bodade](https://discuss.elastic.co/u/Disha_Bodade)\
**Replies:** 2\
**Last updated:** [April 7, 2023, 4:51pm UTC](https://discuss.elastic.co/t/can-we-create-dependent-inputs-in-logstash-pipeline/329436 "2023-04-07T16:51:15Z")

</div>

Hi Team, I have requirement to get the links from rss feed and extract each link and store its XML page source as a document in ES. I am trying to use rss and http\_poller input plugin together, something like below con…

---

## [Enforce Double quotes using csv codec plugin](https://discuss.elastic.co/t/enforce-double-quotes-using-csv-codec-plugin/329585)

<div class="topic-metadata">

**Author:** [@uzair13151](https://discuss.elastic.co/u/uzair13151)\
**Replies:** 1\
**Last updated:** [April 7, 2023, 4:30pm UTC](https://discuss.elastic.co/t/enforce-double-quotes-using-csv-codec-plugin/329585 "2023-04-07T16:30:09Z")

</div>

Hi All, Is it possible to wrap the data in the rows to be encapsulated by double quotes using csv codec plugin. Currently I am getting: Column1|Column2|Column3 Data1|Data2|"" Expectation: "Column1"|"Column2"|"Colum…

[Previous page](https://discuss.elastic.co/tag/none.md?no_tags=true&page=400)

[Next page](https://discuss.elastic.co/tag/none.md?no_tags=true&page=402)
