# \#none

**URL:** https://discuss.elastic.co/tag/none.md?no_tags=true&page=407

[Latest](https://discuss.elastic.co/latest.md) · [Categories](https://discuss.elastic.co/categories.md) · [Tags](https://discuss.elastic.co/tags.md)

**Page:** 408

---

## [How to grok catalina log file](https://discuss.elastic.co/t/how-to-grok-catalina-log-file/328895)

<div class="topic-metadata">

**Author:** [@vanhaiit90](https://discuss.elastic.co/u/vanhaiit90)\
**Replies:** 0\
**Last updated:** [March 30, 2023, 7:24am UTC](https://discuss.elastic.co/t/how-to-grok-catalina-log-file/328895 "2023-03-30T07:24:33Z")

</div>

I have context my config logstash for tomcat filtertomcat filter { if \[fileset\]\[module\] == "tomcat" { if \[fileset\]\[name\] == "tomcatcatalina" { grok { match =\> \[ "message", "(?m)%{TOMCAT\_DATESTAMP:timestamp} %{LOG…

---

## [Is logstash necessarily](https://discuss.elastic.co/t/is-logstash-necessarily/328833)

<div class="topic-metadata">

**Author:** [@LilBaloche](https://discuss.elastic.co/u/LilBaloche)\
**Replies:** 8\
**Last updated:** [March 30, 2023, 8:30pm UTC](https://discuss.elastic.co/t/is-logstash-necessarily/328833 "2023-03-30T20:30:36Z")

</div>

Hi everyone I'm testing ELK in a virtual environment (WinServer AD + DNS, Ubuntu Server 22.04, Ubuntu Client 22.04 and Win 10 Client) I've installed ELK stack on an Ubuntu Server 22.04 (I've been helped by a youtube vi…

---

## [Joining instances to form cluster](https://discuss.elastic.co/t/joining-instances-to-form-cluster/328860)

<div class="topic-metadata">

**Author:** [@DRW-ATCA](https://discuss.elastic.co/u/DRW-ATCA)\
**Replies:** 5\
**Last updated:** [March 30, 2023, 6:23pm UTC](https://discuss.elastic.co/t/joining-instances-to-form-cluster/328860 "2023-03-30T18:23:46Z")

</div>

reference:ERROR: Failed to determine the health of the cluster - #7 by DRW-ATCA My goal is to create a 6-instance cluster in a private VPC (AWS), 1 master, 5 data nodes, with additional instances hosting Kibana and rela…

---

## [ERROR: Failed to determine the health of the cluster](https://discuss.elastic.co/t/error-failed-to-determine-the-health-of-the-cluster/328746)

<div class="topic-metadata">

**Author:** [@DRW-ATCA](https://discuss.elastic.co/u/DRW-ATCA)\
**Replies:** 11\
**Last updated:** [March 30, 2023, 5:20pm UTC](https://discuss.elastic.co/t/error-failed-to-determine-the-health-of-the-cluster/328746 "2023-03-30T17:20:52Z")

</div>

I am trying to add nodes to a cluster for ES 8.6.2 in an AWS EC2 environment. After creating a master node and the first of several data nodes, the two instances give healthy responses to the following commands but do n…

---

## [Logstash not reading my config](https://discuss.elastic.co/t/logstash-not-reading-my-config/328958)

<div class="topic-metadata">

**Author:** [@M\_D](https://discuss.elastic.co/u/M_D)\
**Replies:** 3\
**Last updated:** [March 30, 2023, 5:13pm UTC](https://discuss.elastic.co/t/logstash-not-reading-my-config/328958 "2023-03-30T17:13:32Z")

</div>

I have my config under /etc/logstash/conf.d/myconfig.conf. Below is my simple config input { file { path =\> "/home/foo/logs/\*.log" start\_position =\> "beginning" # stat\_interval =\> 1 # discover\_interval =\>…

---

## [Elastic document\_id](https://discuss.elastic.co/t/elastic-document-id/328738)

<div class="topic-metadata">

**Author:** [@bmagistro1](https://discuss.elastic.co/u/bmagistro1)\
**Replies:** 5\
**Last updated:** [March 30, 2023, 4:08pm UTC](https://discuss.elastic.co/t/elastic-document-id/328738 "2023-03-30T16:08:51Z")

</div>

Is there any defined behavior for document\_id (Elasticsearch output plugin | Logstash Reference \[8.6\] | Elastic) similar to pipeline (Elasticsearch output plugin | Logstash Reference \[8.6\] | Elastic)? We have at least o…

---

## [Dataview with some columns excluded](https://discuss.elastic.co/t/dataview-with-some-columns-excluded/328942)

<div class="topic-metadata">

**Author:** [@joerg55](https://discuss.elastic.co/u/joerg55)\
**Replies:** 9\
**Last updated:** [March 30, 2023, 3:16pm UTC](https://discuss.elastic.co/t/dataview-with-some-columns-excluded/328942 "2023-03-30T15:16:35Z")

</div>

Hi community, I want to create a data view of an index without some columns. The background is that these columns lead to the display of 'no results' with certain filters. I only have this one index and I don't have the…

---

## [How to distribute Primary & Replica shards equally across the nodes](https://discuss.elastic.co/t/how-to-distribute-primary-replica-shards-equally-across-the-nodes/328950)

<div class="topic-metadata">

**Author:** [@prabhakar\_talari](https://discuss.elastic.co/u/prabhakar_talari)\
**Replies:** 2\
**Last updated:** [March 30, 2023, 3:03pm UTC](https://discuss.elastic.co/t/how-to-distribute-primary-replica-shards-equally-across-the-nodes/328950 "2023-03-30T15:03:05Z")

</div>

Hi Team, I have Elastic cluster with 3 Master, 5 Data & 2 Client nodes. I have created index called my-index with 5 Primary and 1 Replica also i used setting called number of shards per node is 2. But i could see at f…

---

## [Match query with specific order of terms](https://discuss.elastic.co/t/match-query-with-specific-order-of-terms/328936)

<div class="topic-metadata">

**Author:** [@Rafael\_Kubina](https://discuss.elastic.co/u/Rafael_Kubina)\
**Replies:** 1\
**Last updated:** [March 30, 2023, 2:09pm UTC](https://discuss.elastic.co/t/match-query-with-specific-order-of-terms/328936 "2023-03-30T14:09:14Z")

</div>

We need to match a set of terms in a field while taking the order into account. Example: The document: { "my\_field": "foo bar" } It should match when the user search for foo bar, foo bar baz or baz foo bar but no…

---

## [Sharing Case ID value using Elastic Case Management webhook](https://discuss.elastic.co/t/sharing-case-id-value-using-elastic-case-management-webhook/328641)

<div class="topic-metadata">

**Author:** [@yzaritskyi](https://discuss.elastic.co/u/yzaritskyi)\
**Replies:** 2\
**Last updated:** [March 30, 2023, 2:05pm UTC](https://discuss.elastic.co/t/sharing-case-id-value-using-elastic-case-management-webhook/328641 "2023-03-30T14:05:45Z")

</div>

Greetings! I'm on the way to implementing the automation solution for our Elastic Security Cases. While working on some automation scripts, I got a problem with the response to Cases. For example, when the Case is crea…

---

## [Correct way to do tiebreaking with search\_after query without PIT](https://discuss.elastic.co/t/correct-way-to-do-tiebreaking-with-search-after-query-without-pit/328941)

<div class="topic-metadata">

**Author:** [@martsraits](https://discuss.elastic.co/u/martsraits)\
**Replies:** 0\
**Last updated:** [March 30, 2023, 1:05pm UTC](https://discuss.elastic.co/t/correct-way-to-do-tiebreaking-with-search-after-query-without-pit/328941 "2023-03-30T13:05:03Z")

</div>

Hi We use search\_after queries to support infinite scroll in the front end. Previously we used \_id field for sorting to keep consistent order. In newer versions of Elasticsearch it's not possible to use \_id field for so…

---

## [Collecting SHA256 checksum of container images using Metricbeat Kubernetes configuration](https://discuss.elastic.co/t/collecting-sha256-checksum-of-container-images-using-metricbeat-kubernetes-configuration/328940)

<div class="topic-metadata">

**Author:** [@kkushal0588](https://discuss.elastic.co/u/kkushal0588)\
**Replies:** 0\
**Last updated:** [March 30, 2023, 12:57pm UTC](https://discuss.elastic.co/t/collecting-sha256-checksum-of-container-images-using-metricbeat-kubernetes-configuration/328940 "2023-03-30T12:57:18Z")

</div>

Hi, I have gone through the documentation link below to understand the fields exported by metricbeat for Kubernetes, but I do not see any field to get the SHA256 checksum of the container image being used for a running …

---

## [Scripted field for date + 12 months](https://discuss.elastic.co/t/scripted-field-for-date-12-months/328715)

<div class="topic-metadata">

**Author:** [@redfox](https://discuss.elastic.co/u/redfox)\
**Replies:** 2\
**Last updated:** [March 30, 2023, 12:30pm UTC](https://discuss.elastic.co/t/scripted-field-for-date-12-months/328715 "2023-03-30T12:30:44Z")

</div>

How would I create a scripted field in Kibana that adds 12 months to the value in existing date field in the index?

---

## [Unable to communicate between 2 master nodes creating cluster issue](https://discuss.elastic.co/t/unable-to-communicate-between-2-master-nodes-creating-cluster-issue/328931)

<div class="topic-metadata">

**Author:** [@devarajsit](https://discuss.elastic.co/u/devarajsit)\
**Replies:** 4\
**Last updated:** [March 30, 2023, 12:31pm UTC](https://discuss.elastic.co/t/unable-to-communicate-between-2-master-nodes-creating-cluster-issue/328931 "2023-03-30T12:31:54Z")

</div>

I tried creating a new Elasticsearch cluster with 3 master nodes, 3 data nodes and 2 clients. All the 3 master nodes status is in Running but when i verified the logs of the third node, it says time out connecting to 1st…

---

## [I have created a Kibana dashboard for Top 10 Process by CPU Usage , the data is not coming up for 15 or 30 minutes or even for 1 hour](https://discuss.elastic.co/t/i-have-created-a-kibana-dashboard-for-top-10-process-by-cpu-usage-the-data-is-not-coming-up-for-15-or-30-minutes-or-even-for-1-hour/328760)

<div class="topic-metadata">

**Author:** [@AKAM14](https://discuss.elastic.co/u/AKAM14)\
**Replies:** 3\
**Last updated:** [March 30, 2023, 12:30pm UTC](https://discuss.elastic.co/t/i-have-created-a-kibana-dashboard-for-top-10-process-by-cpu-usage-the-data-is-not-coming-up-for-15-or-30-minutes-or-even-for-1-hour/328760 "2023-03-30T12:30:41Z")

</div>

Kibana version -7.17.3, elk version 7.17.3 I have used the field - system.process.cpu.total.pct and aggregation is average... i dont see data coming up for 15 or 30 mints or even 1 hour interval time . I only get it f…

---

## [Elasticsearch 7.3.2 witjh Java 17](https://discuss.elastic.co/t/elasticsearch-7-3-2-witjh-java-17/328932)

<div class="topic-metadata">

**Author:** [@Siva\_Karan](https://discuss.elastic.co/u/Siva_Karan)\
**Replies:** 1\
**Last updated:** [March 30, 2023, 12:29pm UTC](https://discuss.elastic.co/t/elasticsearch-7-3-2-witjh-java-17/328932 "2023-03-30T12:29:57Z")

</div>

Hi Team, We need run the elasticsearch 7.3.2 with java 17 version ,myself able to run the elasticsearch with java17 version, is this casue any issues in future.

---

## [Connect elastic search to external react plugin](https://discuss.elastic.co/t/connect-elastic-search-to-external-react-plugin/328929)

<div class="topic-metadata">

**Author:** [@anik-27](https://discuss.elastic.co/u/anik-27)\
**Replies:** 2\
**Last updated:** [March 30, 2023, 11:56am UTC](https://discuss.elastic.co/t/connect-elastic-search-to-external-react-plugin/328929 "2023-03-30T11:56:29Z")

</div>

Hello there ! Is it possible to connect Elasticsearch to the external plugin created in react and use the data stored in indices without using node.js ?

---

## [External plugin connectivity with Elastic search](https://discuss.elastic.co/t/external-plugin-connectivity-with-elastic-search/328552)

<div class="topic-metadata">

**Author:** [@anik-27](https://discuss.elastic.co/u/anik-27)\
**Replies:** 4\
**Last updated:** [March 30, 2023, 11:41am UTC](https://discuss.elastic.co/t/external-plugin-connectivity-with-elastic-search/328552 "2023-03-30T11:41:38Z")

</div>

Hello there ! I have created an external plugin using React in Kibana Now I want to connect that to the Elastic search and use the data stored in one of the index. What are the possible options to achieve this ?

---

## [Facing issue while inserting data into the index](https://discuss.elastic.co/t/facing-issue-while-inserting-data-into-the-index/328917)

<div class="topic-metadata">

**Author:** [@Balraj\_Periasamy](https://discuss.elastic.co/u/Balraj_Periasamy)\
**Replies:** 7\
**Last updated:** [March 30, 2023, 11:04am UTC](https://discuss.elastic.co/t/facing-issue-while-inserting-data-into-the-index/328917 "2023-03-30T11:04:08Z")

</div>

Hi, I am facing issue while inserting the data into Elasticsearch. All data is going to Elastic queue and its taking time to insert the data into index. I am using Elasticsearch docker image

---

## [Required Elastic Query with having Clause in Aggregation](https://discuss.elastic.co/t/required-elastic-query-with-having-clause-in-aggregation/328920)

<div class="topic-metadata">

**Author:** [@Sunny\_Gupta](https://discuss.elastic.co/u/Sunny_Gupta)\
**Replies:** 1\
**Last updated:** [March 30, 2023, 9:57am UTC](https://discuss.elastic.co/t/required-elastic-query-with-having-clause-in-aggregation/328920 "2023-03-30T09:57:46Z")

</div>

If Have One index having records with Properties Email and Event We have different Events like Submitted, Delivered,Bounce etc. I want to Get those record that available in Submitted only. Means If any Email has to de…

---

## [Kibana Dashboards giving 403 error in dashboards when more visualizations added in 8.6.2 version](https://discuss.elastic.co/t/kibana-dashboards-giving-403-error-in-dashboards-when-more-visualizations-added-in-8-6-2-version/328883)

<div class="topic-metadata">

**Author:** [@Sandeep\_Raju](https://discuss.elastic.co/u/Sandeep_Raju)\
**Replies:** 2\
**Last updated:** [March 30, 2023, 7:30am UTC](https://discuss.elastic.co/t/kibana-dashboards-giving-403-error-in-dashboards-when-more-visualizations-added-in-8-6-2-version/328883 "2023-03-30T07:30:28Z")

</div>

Hi all, I recently migrated my kibana dashboards from 7.9 to 7.17 and then to 8.6.2 However i'm getting an error in my dashboards as shown below. Apparently this error appears when there are approximately 20 visualiza…

---

## [Kibana not running as a service](https://discuss.elastic.co/t/kibana-not-running-as-a-service/328829)

<div class="topic-metadata">

**Author:** [@LilBaloche](https://discuss.elastic.co/u/LilBaloche)\
**Replies:** 12\
**Last updated:** [March 30, 2023, 8:35am UTC](https://discuss.elastic.co/t/kibana-not-running-as-a-service/328829 "2023-03-30T08:35:51Z")

</div>

Hello everyone, I've installed ELK stack on an Ubuntu Server 22.04. My problem is that I've start elasticsearch with "systemctl start elasticsearch.service" because bin/elasticsearch does not work, I always have an err…

---

## [Unresolved reference 'Aggregation, Size, TrackTotalHits, Pretty, Sort, and Do'](https://discuss.elastic.co/t/unresolved-reference-aggregation-size-tracktotalhits-pretty-sort-and-do/328884)

<div class="topic-metadata">

**Author:** [@golofetuk](https://discuss.elastic.co/u/golofetuk)\
**Replies:** 3\
**Last updated:** [March 30, 2023, 7:34am UTC](https://discuss.elastic.co/t/unresolved-reference-aggregation-size-tracktotalhits-pretty-sort-and-do/328884 "2023-03-30T07:34:24Z")

</div>

I am trying to execute a search on the Elasticsearch client in Go olivere/elastic, using the appropriate client library for Elasticsearch version 7.x. The expected behavior is to compile the code without errors and retur…

---

## [Elastic-agent does not restart automatically after machine reboot](https://discuss.elastic.co/t/elastic-agent-does-not-restart-automatically-after-machine-reboot/328894)

<div class="topic-metadata">

**Author:** [@irivas95](https://discuss.elastic.co/u/irivas95)\
**Replies:** 0\
**Last updated:** [March 30, 2023, 7:19am UTC](https://discuss.elastic.co/t/elastic-agent-does-not-restart-automatically-after-machine-reboot/328894 "2023-03-30T07:19:20Z")

</div>

Hi, I have an elastic-agent with a prometheus integration with and another elastic-agent acting as fleet with the service enabled and when the machines (both with Red Hat SO) are restarted neither the fleet nor the elas…

---

## [How does rescore query affect aggregation results?](https://discuss.elastic.co/t/how-does-rescore-query-affect-aggregation-results/328892)

<div class="topic-metadata">

**Author:** [@Abhishek3](https://discuss.elastic.co/u/Abhishek3)\
**Replies:** 0\
**Last updated:** [March 30, 2023, 7:00am UTC](https://discuss.elastic.co/t/how-does-rescore-query-affect-aggregation-results/328892 "2023-03-30T07:00:33Z")

</div>

I am running rescore\_query with ltr model with window\_size=5, I am seeing the recore\_query is being applied to top 5 docs in hits and top 5 docs of every aggregated bucket. Is the how rescore\_query designed to work? f…

---

## [Way for implementing proxy server goint to elastic cluster](https://discuss.elastic.co/t/way-for-implementing-proxy-server-goint-to-elastic-cluster/328889)

<div class="topic-metadata">

**Author:** [@minkiyo](https://discuss.elastic.co/u/minkiyo)\
**Replies:** 0\
**Last updated:** [March 30, 2023, 6:46am UTC](https://discuss.elastic.co/t/way-for-implementing-proxy-server-goint-to-elastic-cluster/328889 "2023-03-30T06:46:09Z")

</div>

Hello I am suffuring now. I am implementing Proxy Server going to Elastic Cluster . Broswer --\> Elastic Proxy Server (Nginx(prot:8081) --\> Express(port:7081)) --\> Elastic Cluster(http://10.150.25.119:5601) When I t…

---

## [Transport response handler not found of id](https://discuss.elastic.co/t/transport-response-handler-not-found-of-id/328879)

<div class="topic-metadata">

**Author:** [@KeithTt](https://discuss.elastic.co/u/KeithTt)\
**Replies:** 3\
**Last updated:** [March 30, 2023, 6:31am UTC](https://discuss.elastic.co/t/transport-response-handler-not-found-of-id/328879 "2023-03-30T06:31:21Z")

</div>

\[2023-03-30T09:20:19,277\]\[WARN \]\[o.e.t.TransportService \] \[m-21-63\] Transport response handler not found of id \[197374379\] \[2023-03-30T09:20:19,280\]\[WARN \]\[o.e.t.TransportService \] \[m-21-63\] Transport response handle…

---

## [Space privilege](https://discuss.elastic.co/t/space-privilege/328796)

<div class="topic-metadata">

**Author:** [@\_Thomas](https://discuss.elastic.co/u/_Thomas)\
**Replies:** 5\
**Last updated:** [March 30, 2023, 6:23am UTC](https://discuss.elastic.co/t/space-privilege/328796 "2023-03-30T06:23:43Z")

</div>

Hi Guys, I'm trying to limit the Space to particular Users - this however, doesn't seem to work the way I'd expect. The Problem is as following: I did create a new Space called "SoC", created a new Role called "TestUs…

---

## [Why the "exec" input in logstash does not work?](https://discuss.elastic.co/t/why-the-exec-input-in-logstash-does-not-work/328808)

<div class="topic-metadata">

**Author:** [@JohnnyLee](https://discuss.elastic.co/u/JohnnyLee)\
**Replies:** 0\
**Last updated:** [March 29, 2023, 10:02am UTC](https://discuss.elastic.co/t/why-the-exec-input-in-logstash-does-not-work/328808 "2023-03-29T10:02:24Z")

</div>

Hi, I failed to load shell script output to ELK with "exec" input plugin in logstash. Is there anything misconfigured in my configure file? Below is my logstash configuraitons. input { exec { command =\> "bash /r…

---

## [Logstash autorelaod even the config file not changed](https://discuss.elastic.co/t/logstash-autorelaod-even-the-config-file-not-changed/328881)

<div class="topic-metadata">

**Author:** [@kannan\_raj](https://discuss.elastic.co/u/kannan_raj)\
**Replies:** 0\
**Last updated:** [March 30, 2023, 4:35am UTC](https://discuss.elastic.co/t/logstash-autorelaod-even-the-config-file-not-changed/328881 "2023-03-30T04:35:16Z")

</div>

Hello Team, We use the logstash to consume the messages from Kafka and indexing into Elasticsearch and we use the vault to drop the cert and keys to connect to Kafka and Elasticsearch. vault rotates the cert and key dep…

[Previous page](https://discuss.elastic.co/tag/none.md?no_tags=true&page=406)

[Next page](https://discuss.elastic.co/tag/none.md?no_tags=true&page=408)
