# \#none

**URL:** https://discuss.elastic.co/tag/none.md?no_tags=true&page=412

[Latest](https://discuss.elastic.co/latest.md) · [Categories](https://discuss.elastic.co/categories.md) · [Tags](https://discuss.elastic.co/tags.md)

**Page:** 413

---

## [Multiple search criteria](https://discuss.elastic.co/t/multiple-search-criteria/328400)

<div class="topic-metadata">

**Author:** [@Sheng111](https://discuss.elastic.co/u/Sheng111)\
**Replies:** 0\
**Last updated:** [March 23, 2023, 10:52pm UTC](https://discuss.elastic.co/t/multiple-search-criteria/328400 "2023-03-23T22:52:49Z")

</div>

Hi there, one common question, how to do multiple criteria search using elasticsearch UI? for example I search for attribute A==5 and attribute B within recent 3 months; is this possible to combine above 2 filter criter…

---

## [How does document update work under the hood?](https://discuss.elastic.co/t/how-does-document-update-work-under-the-hood/328392)

<div class="topic-metadata">

**Author:** [@egalpin](https://discuss.elastic.co/u/egalpin)\
**Replies:** 2\
**Last updated:** [March 23, 2023, 9:10pm UTC](https://discuss.elastic.co/t/how-does-document-update-work-under-the-hood/328392 "2023-03-23T21:10:32Z")

</div>

Hi all! I’m curious to learn about how the process of document update (and upsert/partial upsert) works under the hood. I know that Lucene segments are immutable and that “deleting” a doc is a soft delete by way of tomb…

---

## [How to add yml files to a forum post reply](https://discuss.elastic.co/t/how-to-add-yml-files-to-a-forum-post-reply/328396)

<div class="topic-metadata">

**Author:** [@iqworks](https://discuss.elastic.co/u/iqworks)\
**Replies:** 1\
**Last updated:** [March 23, 2023, 8:55pm UTC](https://discuss.elastic.co/t/how-to-add-yml-files-to-a-forum-post-reply/328396 "2023-03-23T20:55:35Z")

</div>

In a forum post i created, i got a reply that requested my ymls for them to see how they were configured. But I dont see how to add ymls, only cut and paste, and some of these ymls are big. thanks for any suggestions or…

---

## [Options for log collection from client applications](https://discuss.elastic.co/t/options-for-log-collection-from-client-applications/328288)

<div class="topic-metadata">

**Author:** [@malliaridis](https://discuss.elastic.co/u/malliaridis)\
**Replies:** 2\
**Last updated:** [March 23, 2023, 8:10pm UTC](https://discuss.elastic.co/t/options-for-log-collection-from-client-applications/328288 "2023-03-23T20:10:14Z")

</div>

tl;dr If I have generated logs on mobile applications / mobile devices and desktop PCs (owned by users) and stored them in files or embedded databases, what options are available and recommended to collect these logs in…

---

## [Fscrawler - change the index mapping，reduce redundant field or object](https://discuss.elastic.co/t/fscrawler-change-the-index-mapping-reduce-redundant-field-or-object/328296)

<div class="topic-metadata">

**Author:** [@bolo](https://discuss.elastic.co/u/bolo)\
**Replies:** 4\
**Last updated:** [March 23, 2023, 8:04pm UTC](https://discuss.elastic.co/t/fscrawler-change-the-index-mapping-reduce-redundant-field-or-object/328296 "2023-03-23T20:04:04Z")

</div>

i am new to fscrawler and really appreciate it. i know, the mapping can be changed. But to which content？just the analyzer? or the field type ? or the whole structure(because i dont want too much inner object). thank you …

---

## [Error connecting to node kafka-broker:9092 (id: 1 rack: null) java.net.UnknownHostException: kafka-broker](https://discuss.elastic.co/t/error-connecting-to-node-kafka-broker-9092-id-1-rack-null-java-net-unknownhostexception-kafka-broker/327434)

<div class="topic-metadata">

**Author:** [@Rajesh\_R](https://discuss.elastic.co/u/Rajesh_R)\
**Replies:** 3\
**Last updated:** [March 23, 2023, 7:31pm UTC](https://discuss.elastic.co/t/error-connecting-to-node-kafka-broker-9092-id-1-rack-null-java-net-unknownhostexception-kafka-broker/327434 "2023-03-23T19:31:43Z")

</div>

When I use kafka plugin in logstash, I am getting the below error. \[2023-03-10T15:11:46,310\]\[WARN \]\[org.apache.kafka.clients.NetworkClient\]\[main\]\[289f84d5c44d64af9505535a5352178af25a608c83252a1c520ab39a4faa4855\] \[Consum…

---

## [Permission denied /usr/share/logstash/run](https://discuss.elastic.co/t/permission-denied-usr-share-logstash-run/327769)

<div class="topic-metadata">

**Author:** [@RJC](https://discuss.elastic.co/u/RJC)\
**Replies:** 3\
**Last updated:** [March 23, 2023, 7:29pm UTC](https://discuss.elastic.co/t/permission-denied-usr-share-logstash-run/327769 "2023-03-23T19:29:51Z")

</div>

I am getting the following error message when starting Logstash on a Linux server: \[ERROR\]\[logstash.java.pipeline \]\[main\] Pipeline worker error, the pipeline will be stopped (:pipeline\_id=\>"main", :error=\>" (EACCESS) Pe…

---

## [Elastic-agent "Process another repeated request" in loop indefinitely](https://discuss.elastic.co/t/elastic-agent-process-another-repeated-request-in-loop-indefinitely/328251)

<div class="topic-metadata">

**Author:** [@Nicolas\_Pellletier](https://discuss.elastic.co/u/Nicolas_Pellletier)\
**Replies:** 5\
**Last updated:** [March 23, 2023, 4:45pm UTC](https://discuss.elastic.co/t/elastic-agent-process-another-repeated-request-in-loop-indefinitely/328251 "2023-03-23T16:45:41Z")

</div>

Hello, I've got an elastic-agent with no agent monitoring settings (meaning no Agent Logs/Mertrics collection) and only one integration policy. So my elastic-agent.yml is pretty small: id: 949c1a80-c8a9-11ed-8539-532f…

---

## [Uptime monitor status rule when all monitors down](https://discuss.elastic.co/t/uptime-monitor-status-rule-when-all-monitors-down/328094)

<div class="topic-metadata">

**Author:** [@Alexander\_A](https://discuss.elastic.co/u/Alexander_A)\
**Replies:** 3\
**Last updated:** [March 23, 2023, 4:11pm UTC](https://discuss.elastic.co/t/uptime-monitor-status-rule-when-all-monitors-down/328094 "2023-03-23T16:11:07Z")

</div>

Creating "Uptime monitor status" rule there is an option to create "Status check" when "ANY MONITOR IS DOWN" but how I can create a rule when ALL MONITORS ARE DOWN (from all locations) ANY X MONITORS ARE DOWN (from X l…

---

## [WARN message when trying to install on windows 10](https://discuss.elastic.co/t/warn-message-when-trying-to-install-on-windows-10/328348)

<div class="topic-metadata">

**Author:** [@Ene\_Dragos](https://discuss.elastic.co/u/Ene_Dragos)\
**Replies:** 10\
**Last updated:** [March 23, 2023, 4:08pm UTC](https://discuss.elastic.co/t/warn-message-when-trying-to-install-on-windows-10/328348 "2023-03-23T16:08:19Z")

</div>

Hi! I'm trying to install elasticsearch on windows and i've followed the guid on here: Install Elasticsearch with .zip on Windows | Elasticsearch Guide \[8.6\] | Elastic. The issue is, when I try to configure Elasticsearc…

---

## [Error in parsing some logs from firewall due to object being returned](https://discuss.elastic.co/t/error-in-parsing-some-logs-from-firewall-due-to-object-being-returned/328349)

<div class="topic-metadata">

**Author:** [@viera120](https://discuss.elastic.co/u/viera120)\
**Replies:** 1\
**Last updated:** [March 23, 2023, 3:57pm UTC](https://discuss.elastic.co/t/error-in-parsing-some-logs-from-firewall-due-to-object-being-returned/328349 "2023-03-23T15:57:57Z")

</div>

Hi all, The setup is: Firewall --\> Filebeat --\> Logstash --\> Elasticsearch The following error keeps appearing in /var/log/logstash/logstash-plain.log \[2023-03-23T18:03:53,651\]\[WARN \]\[logstash.outputs.elasticsearch\]\[…

---

## [Kafka sink Connector to Elasticsearch](https://discuss.elastic.co/t/kafka-sink-connector-to-elasticsearch/328361)

<div class="topic-metadata">

**Author:** [@searchwithme](https://discuss.elastic.co/u/searchwithme)\
**Replies:** 1\
**Last updated:** [March 23, 2023, 3:20pm UTC](https://discuss.elastic.co/t/kafka-sink-connector-to-elasticsearch/328361 "2023-03-23T15:20:15Z")

</div>

I am trying to set up ingestion pipeline to elasticsearch cluster via kafka sink connector. A question I have is if I have a doc that haas multiple json objects like this: \[ {"name":"abc", "company":"123","dept":"test"…

---

## [RAR file download from the internet](https://discuss.elastic.co/t/rar-file-download-from-the-internet/327072)

<div class="topic-metadata">

**Author:** [@Maretti](https://discuss.elastic.co/u/Maretti)\
**Replies:** 3\
**Last updated:** [March 23, 2023, 3:17pm UTC](https://discuss.elastic.co/t/rar-file-download-from-the-internet/327072 "2023-03-23T15:17:31Z")

</div>

I tried this rule since a lot of malware is spread using password protected RAR files Roshal Archive (RAR) or PowerShell File Downloaded from the Internet | Elastic Security Solution \[7.17\] | Elastic The Query the rule…

---

## [Wrong calculations - ruby code](https://discuss.elastic.co/t/wrong-calculations-ruby-code/328093)

<div class="topic-metadata">

**Author:** [@wedkarz014](https://discuss.elastic.co/u/wedkarz014)\
**Replies:** 1\
**Last updated:** [March 23, 2023, 3:13pm UTC](https://discuss.elastic.co/t/wrong-calculations-ruby-code/328093 "2023-03-23T15:13:40Z")

</div>

Hi all, logstash v.7.17.8 I have ~45 metrics to calculate, here is the example, code and results: ruby { code =\> " if !event.get('\[Package2VersionCreatesWithoutValidation\]\[Max\]').nil? and !e…

---

## [\[Logstash\] SSL TCP input certificate issue](https://discuss.elastic.co/t/logstash-ssl-tcp-input-certificate-issue/328220)

<div class="topic-metadata">

**Author:** [@perezdev](https://discuss.elastic.co/u/perezdev)\
**Replies:** 1\
**Last updated:** [March 23, 2023, 3:00pm UTC](https://discuss.elastic.co/t/logstash-ssl-tcp-input-certificate-issue/328220 "2023-03-23T15:00:44Z")

</div>

Hello, I'm trying to setup an SSL TCP input config file in Logstash to receive logs from other syslog server over TLS 1.2. For the certificates I have created the following files using openssl: openssl req -x509 -nodes…

---

## [Feature Request for more robust vector graphics (Vega not enough) so I can generate good looking network maps (non-geographic)](https://discuss.elastic.co/t/feature-request-for-more-robust-vector-graphics-vega-not-enough-so-i-can-generate-good-looking-network-maps-non-geographic/328286)

<div class="topic-metadata">

**Author:** [@J\_Todd](https://discuss.elastic.co/u/J_Todd)\
**Replies:** 2\
**Last updated:** [March 23, 2023, 2:15pm UTC](https://discuss.elastic.co/t/feature-request-for-more-robust-vector-graphics-vega-not-enough-so-i-can-generate-good-looking-network-maps-non-geographic/328286 "2023-03-23T14:15:15Z")

</div>

I want to be able to generate, within Kibana and / or Elastic Security, non-geographic, good looking network maps like these: Currently there doesn't seem to be any way to do this in any Elastic product no matter…

---

## [Logstash MultiPipeline](https://discuss.elastic.co/t/logstash-multipipeline/328341)

<div class="topic-metadata">

**Author:** [@Julien069](https://discuss.elastic.co/u/Julien069)\
**Replies:** 2\
**Last updated:** [March 23, 2023, 1:39pm UTC](https://discuss.elastic.co/t/logstash-multipipeline/328341 "2023-03-23T13:39:59Z")

</div>

Hello , I want to use several pipeline . I had put them in the logstash directory conf.d . I named the files like this 01\_Input 02\_Filter 03\_Output Must I do anything else for work with the pipelines ? Does it wo…

---

## [Elasticsearch NoShardAvailableActionException](https://discuss.elastic.co/t/elasticsearch-noshardavailableactionexception/328279)

<div class="topic-metadata">

**Author:** [@Lohanna\_Sarah](https://discuss.elastic.co/u/Lohanna_Sarah)\
**Replies:** 4\
**Last updated:** [March 23, 2023, 1:35pm UTC](https://discuss.elastic.co/t/elasticsearch-noshardavailableactionexception/328279 "2023-03-23T13:35:51Z")

</div>

Suppose a cluster is composed of three data nodes. If one of the nodes throws the exception "NoShardAvailableActionException", what is the impact on the cluster and how is the request handled? Specifically, is the reques…

---

## [How do I use Elastic Agent to send log data to Logstash?](https://discuss.elastic.co/t/how-do-i-use-elastic-agent-to-send-log-data-to-logstash/328269)

<div class="topic-metadata">

**Author:** [@Matt\_Johnston](https://discuss.elastic.co/u/Matt_Johnston)\
**Replies:** 7\
**Last updated:** [March 23, 2023, 12:57pm UTC](https://discuss.elastic.co/t/how-do-i-use-elastic-agent-to-send-log-data-to-logstash/328269 "2023-03-23T12:57:14Z")

</div>

Hello. Based on the documentation (Beats and Elastic Agent capabilities | Fleet and Elastic Agent Guide \[8.6\] | Elastic) I am under the impression that the Elastic Agent can send log data to Logstash. However, the only b…

---

## [How to search a piece of URI](https://discuss.elastic.co/t/how-to-search-a-piece-of-uri/328342)

<div class="topic-metadata">

**Author:** [@searchwithme](https://discuss.elastic.co/u/searchwithme)\
**Replies:** 8\
**Last updated:** [March 23, 2023, 12:36pm UTC](https://discuss.elastic.co/t/how-to-search-a-piece-of-uri/328342 "2023-03-23T12:36:28Z")

</div>

I want to search a piece of URL. I am using the sample weblogs in elasticsearch. If I analyze the field: GET /\_analyze { "analyzer" : "standard", "text" : \["http://nytimes.com/success/kevin-Kregel"\] } I get: { "…

---

## [Kibana login Issue due to space full](https://discuss.elastic.co/t/kibana-login-issue-due-to-space-full/328153)

<div class="topic-metadata">

**Author:** [@elasticlog](https://discuss.elastic.co/u/elasticlog)\
**Replies:** 11\
**Last updated:** [March 23, 2023, 12:15pm UTC](https://discuss.elastic.co/t/kibana-login-issue-due-to-space-full/328153 "2023-03-23T12:15:27Z")

</div>

Hello Expert, We have created the Kibana and Elasticsearch with filebeat. Below are the details. Kibana version: 7.14.1. running in Kubernetes. Issue: Not able to login to Kibana as Elasticsearch space is full. but …

---

## [Kibana dashboard issue - i have created a disk usage dashboard , it doesnot show up a straight line --but with dotted lines](https://discuss.elastic.co/t/kibana-dashboard-issue-i-have-created-a-disk-usage-dashboard-it-doesnot-show-up-a-straight-line-but-with-dotted-lines/328346)

<div class="topic-metadata">

**Author:** [@AKAM14](https://discuss.elastic.co/u/AKAM14)\
**Replies:** 1\
**Last updated:** [March 23, 2023, 12:05pm UTC](https://discuss.elastic.co/t/kibana-dashboard-issue-i-have-created-a-disk-usage-dashboard-it-doesnot-show-up-a-straight-line-but-with-dotted-lines/328346 "2023-03-23T12:05:25Z")

</div>

ELK - 7.17.3 , KIBANA 7.17.3 I have a 3 node cluster and two logstash server and one kibana server I have created disk usage dashboard , but it shows the data in dotted line for 15 minutes or 30 minutes.. while for 1 h…

---

## [Cluster en elastic search; error: main process exited, failed with result 'exit-code'](https://discuss.elastic.co/t/cluster-en-elastic-search-error-main-process-exited-failed-with-result-exit-code/328337)

<div class="topic-metadata">

**Author:** [@Marco\_Batista\_12](https://discuss.elastic.co/u/Marco_Batista_12)\
**Replies:** 3\
**Last updated:** [March 23, 2023, 11:37am UTC](https://discuss.elastic.co/t/cluster-en-elastic-search-error-main-process-exited-failed-with-result-exit-code/328337 "2023-03-23T11:37:24Z")

</div>

I am trying to create a cluster with two machines and I am trying to configure the /etc/elasticsearch/elasticsearch.yml file but I get an error. I am attaching code captures. The attached screenshot is from the ma…

---

## [Kibana Server is not ready yet](https://discuss.elastic.co/t/kibana-server-is-not-ready-yet/328232)

<div class="topic-metadata">

**Author:** [@Marco\_Batista\_12](https://discuss.elastic.co/u/Marco_Batista_12)\
**Replies:** 3\
**Last updated:** [March 23, 2023, 9:17am UTC](https://discuss.elastic.co/t/kibana-server-is-not-ready-yet/328232 "2023-03-23T09:17:18Z")

</div>

Hi, I am not able to connect kibana with elasticsearch, if someone could offer me some help. Thank you.

---

## [Building Kibana from source code got "operation not permitted, rename" ERROR](https://discuss.elastic.co/t/building-kibana-from-source-code-got-operation-not-permitted-rename-error/328317)

<div class="topic-metadata">

**Author:** [@gnehcnij](https://discuss.elastic.co/u/gnehcnij)\
**Replies:** 1\
**Last updated:** [March 23, 2023, 9:28am UTC](https://discuss.elastic.co/t/building-kibana-from-source-code-got-operation-not-permitted-rename-error/328317 "2023-03-23T09:28:50Z")

</div>

When I run yarn build --skip-os-packages, it got error below: ERROR Error: EPERM: operation not permitted, rename........

---

## [Dashboard performance help](https://discuss.elastic.co/t/dashboard-performance-help/327582)

<div class="topic-metadata">

**Author:** [@tommycahir](https://discuss.elastic.co/u/tommycahir)\
**Replies:** 9\
**Last updated:** [March 23, 2023, 8:56am UTC](https://discuss.elastic.co/t/dashboard-performance-help/327582 "2023-03-23T08:56:57Z")

</div>

Hi All I am looking for some help in understanding how I can debug/find slow performance issues and then resolve them. We have a dashboard that is presenting some visualisations on an index with 29,369,877 documents an…

---

## [APM-Server /intake/v2/events http 404 page not found](https://discuss.elastic.co/t/apm-server-intake-v2-events-http-404-page-not-found/328244)

<div class="topic-metadata">

**Author:** [@niemimik](https://discuss.elastic.co/u/niemimik)\
**Replies:** 2\
**Last updated:** [March 23, 2023, 8:40am UTC](https://discuss.elastic.co/t/apm-server-intake-v2-events-http-404-page-not-found/328244 "2023-03-23T08:40:13Z")

</div>

I'm running 7.17 APM server with Fleet and APM agent installed. APM server is responsing healthy status but intake/v2/events not found. I cannot see any errors in log files. Please, could you give some ideas how can I d…

---

## [Logstash error -"Could not load '.aprc' from ENV\['HOME'\]: couldn't find HOME environment -- expanding \`~"](https://discuss.elastic.co/t/logstash-error-could-not-load-aprc-from-env-home-couldnt-find-home-environment-expanding/328318)

<div class="topic-metadata">

**Author:** [@Shreesh\_Narayanan](https://discuss.elastic.co/u/Shreesh_Narayanan)\
**Replies:** 0\
**Last updated:** [March 23, 2023, 7:36am UTC](https://discuss.elastic.co/t/logstash-error-could-not-load-aprc-from-env-home-couldnt-find-home-environment-expanding/328318 "2023-03-23T07:36:38Z")

</div>

Hi Folks, I have a log file that logstash(8.6.2) is successfully parse, but has this error . i'm not sure whats causing it ? Could have a look ? , the data doesnt appear in kibana either Could not load '.aprc' from EN…

---

## [Split nested docs into a separate docs](https://discuss.elastic.co/t/split-nested-docs-into-a-separate-docs/328265)

<div class="topic-metadata">

**Author:** [@silverjoe](https://discuss.elastic.co/u/silverjoe)\
**Replies:** 0\
**Last updated:** [March 22, 2023, 3:02pm UTC](https://discuss.elastic.co/t/split-nested-docs-into-a-separate-docs/328265 "2023-03-22T15:02:21Z")

</div>

Hi, I have a simple Logstash pipeline that reads all docs from an ES index using an ES input plugin, then I have a filter that splits one doc into several, and finally the output plugin to index docs in the ES. My probl…

---

## [Fleet Server Agent with Public URL can't be enrolled](https://discuss.elastic.co/t/fleet-server-agent-with-public-url-cant-be-enrolled/328306)

<div class="topic-metadata">

**Author:** [@johnkim](https://discuss.elastic.co/u/johnkim)\
**Replies:** 0\
**Last updated:** [March 23, 2023, 5:51am UTC](https://discuss.elastic.co/t/fleet-server-agent-with-public-url-cant-be-enrolled/328306 "2023-03-23T05:51:04Z")

</div>

I essentially have the same issue as the person in this thread : The OP of that thread didn't really resolve the question for other people reading it. Similarly to that thread, I am trying to set up fleet-agent and ag…

[Previous page](https://discuss.elastic.co/tag/none.md?no_tags=true&page=411)

[Next page](https://discuss.elastic.co/tag/none.md?no_tags=true&page=413)
