# \#none

**URL:** https://discuss.elastic.co/tag/none.md?no_tags=true&page=416

[Latest](https://discuss.elastic.co/latest.md) · [Categories](https://discuss.elastic.co/categories.md) · [Tags](https://discuss.elastic.co/tags.md)

**Page:** 417

---

## [Elastic and Kibana](https://discuss.elastic.co/t/elastic-and-kibana/327548)

<div class="topic-metadata">

**Author:** [@MahithaSarala](https://discuss.elastic.co/u/MahithaSarala)\
**Replies:** 5\
**Last updated:** [March 19, 2023, 8:45pm UTC](https://discuss.elastic.co/t/elastic-and-kibana/327548 "2023-03-19T20:45:59Z")

</div>

Hi Team, I have installed the elasticsearch(8.5.3) and kibana throgh eck , its working I can able to login If we login first time i'm getting issue like \< elastic did not load properly check the server output for infor…

---

## [Kibana becomes unavailable](https://discuss.elastic.co/t/kibana-becomes-unavailable/327868)

<div class="topic-metadata">

**Author:** [@selvaraj-sembulingam](https://discuss.elastic.co/u/selvaraj-sembulingam)\
**Replies:** 1\
**Last updated:** [March 19, 2023, 8:44pm UTC](https://discuss.elastic.co/t/kibana-becomes-unavailable/327868 "2023-03-19T20:44:29Z")

</div>

Hi Team, My Kibana Web UI becomes unavailable quite often. From the logs I could see it as, \[INFO\] \[status\] Kibana is now degraded (was unavailable) \[INFO\] \[status\] Kibana is now available (was degraded) Elasticsearc…

---

## [Elastic Agent Kubernetes Integration Logs Moniotring](https://discuss.elastic.co/t/elastic-agent-kubernetes-integration-logs-moniotring/327881)

<div class="topic-metadata">

**Author:** [@Savva\_Morozov](https://discuss.elastic.co/u/Savva_Morozov)\
**Replies:** 0\
**Last updated:** [March 16, 2023, 8:40pm UTC](https://discuss.elastic.co/t/elastic-agent-kubernetes-integration-logs-moniotring/327881 "2023-03-16T20:40:19Z")

</div>

Hello! I am using Elastic Agent on Kubernetes and I am using Kubernetes integration to capture the logs, but I would like to capture logs only from our applications and filter out the logs of Kubernetes components. I sa…

---

## [Error Add New Node Elasticsearch](https://discuss.elastic.co/t/error-add-new-node-elasticsearch/327814)

<div class="topic-metadata">

**Author:** [@ilham\_bahrul](https://discuss.elastic.co/u/ilham_bahrul)\
**Replies:** 1\
**Last updated:** [March 19, 2023, 8:40pm UTC](https://discuss.elastic.co/t/error-add-new-node-elasticsearch/327814 "2023-03-19T20:40:39Z")

</div>

I want to add new nodes in my cluster from 3 nodes to 4 nodes. The condition of port 9300 and 9200 is already open on each node. However, I encountered a problem when adding a new node. the following is the error that oc…

---

## [How big should the disk of each node usually be configured reasonably?](https://discuss.elastic.co/t/how-big-should-the-disk-of-each-node-usually-be-configured-reasonably/327897)

<div class="topic-metadata">

**Author:** [@jaryzhong](https://discuss.elastic.co/u/jaryzhong)\
**Replies:** 1\
**Last updated:** [March 19, 2023, 8:40pm UTC](https://discuss.elastic.co/t/how-big-should-the-disk-of-each-node-usually-be-configured-reasonably/327897 "2023-03-19T20:40:06Z")

</div>

We have 10TB of data and this 10TB of data already contains all replicas, we have 5 data nodes, each node will store 2TB of data, how big should the disk of each node usually be configured reasonably?

---

## [How to address json objects in a json array in jdbc-output-plugin logstash conf?](https://discuss.elastic.co/t/how-to-address-json-objects-in-a-json-array-in-jdbc-output-plugin-logstash-conf/327980)

<div class="topic-metadata">

**Author:** [@alex\_petrov](https://discuss.elastic.co/u/alex_petrov)\
**Replies:** 0\
**Last updated:** [March 18, 2023, 6:56am UTC](https://discuss.elastic.co/t/how-to-address-json-objects-in-a-json-array-in-jdbc-output-plugin-logstash-conf/327980 "2023-03-18T06:56:16Z")

</div>

for example you have this json array : { "accounting" : \[ { "firstName" : "John", "lastName" : "Doe", "age" : 23 }, …

---

## [Solr to Elasticsearch Migration](https://discuss.elastic.co/t/solr-to-elasticsearch-migration/327981)

<div class="topic-metadata">

**Author:** [@mruthyu](https://discuss.elastic.co/u/mruthyu)\
**Replies:** 3\
**Last updated:** [March 19, 2023, 5:51pm UTC](https://discuss.elastic.co/t/solr-to-elasticsearch-migration/327981 "2023-03-19T17:51:49Z")

</div>

Is there any migration guidelines for migration from Apache Solr to Elasticsearch?

---

## [Question about the logstash plugin version](https://discuss.elastic.co/t/question-about-the-logstash-plugin-version/328022)

<div class="topic-metadata">

**Author:** [@wensionblao](https://discuss.elastic.co/u/wensionblao)\
**Replies:** 1\
**Last updated:** [March 19, 2023, 2:28pm UTC](https://discuss.elastic.co/t/question-about-the-logstash-plugin-version/328022 "2023-03-19T14:28:31Z")

</div>

When I use logstash-integration-kafka at version 10.4.0, I find that the corresponding kafka-clients version is 2.4 but logstash-input-kafka and logstash-output-kafka of version 10.4.0 have kafka-clients of version 2…

---

## [Logging from script within Ruby Filter](https://discuss.elastic.co/t/logging-from-script-within-ruby-filter/328012)

<div class="topic-metadata">

**Author:** [@16318a22907f3cbfa04b](https://discuss.elastic.co/u/16318a22907f3cbfa04b)\
**Replies:** 1\
**Last updated:** [March 19, 2023, 9:48am UTC](https://discuss.elastic.co/t/logging-from-script-within-ruby-filter/328012 "2023-03-19T09:48:42Z")

</div>

Hello, I can write to the logfile of Logstash from code within ruby filter. https://discuss.elastic.co/t/logging-from-within-ruby-filter/127983/2 Is it possible to do the same from script (not code)? And when yes how? …

---

## [SSL certificate - x509: certificate signed by unknown authority (Solved)](https://discuss.elastic.co/t/ssl-certificate-x509-certificate-signed-by-unknown-authority-solved/328011)

<div class="topic-metadata">

**Author:** [@Nicolas\_Pelletier](https://discuss.elastic.co/u/Nicolas_Pelletier)\
**Replies:** 0\
**Last updated:** [March 19, 2023, 8:15am UTC](https://discuss.elastic.co/t/ssl-certificate-x509-certificate-signed-by-unknown-authority-solved/328011 "2023-03-19T08:15:24Z")

</div>

I've deployed a standalone elastic-agent on my host machine where ELK is running. I've add the MISP integration policy to this standalone agent with https://localhost as MISP url variable. It's self signed certificate. …

---

## [No config files found in path](https://discuss.elastic.co/t/no-config-files-found-in-path/327879)

<div class="topic-metadata">

**Author:** [@Mxnita](https://discuss.elastic.co/u/Mxnita)\
**Replies:** 16\
**Last updated:** [March 18, 2023, 6:56pm UTC](https://discuss.elastic.co/t/no-config-files-found-in-path/327879 "2023-03-18T18:56:27Z")

</div>

Hello everyone I am new with Logstash and i trying to start Logstash 8.6.2 on a Windows Server 2019 Server to forward syslogs from a Firewall to Wazuh. When I try to run as administrator in PS the command C:\\logstash-8…

---

## [Error when creating Index Template: composable template \[ \] template after composition is invalid](https://discuss.elastic.co/t/error-when-creating-index-template-composable-template-template-after-composition-is-invalid/327948)

<div class="topic-metadata">

**Author:** [@Mark\_S](https://discuss.elastic.co/u/Mark_S)\
**Replies:** 4\
**Last updated:** [March 18, 2023, 5:59pm UTC](https://discuss.elastic.co/t/error-when-creating-index-template-composable-template-template-after-composition-is-invalid/327948 "2023-03-18T17:59:31Z")

</div>

When creating an Index Template, I get this error: Error when creating Template: composable template template after composition is invalid I observe that: This error occurs only when I use the normal index template.…

---

## [Elastic agent install error: already installed at: /opt/Elastic/Agent](https://discuss.elastic.co/t/elastic-agent-install-error-already-installed-at-opt-elastic-agent/327926)

<div class="topic-metadata">

**Author:** [@Nicolas\_Pelletier](https://discuss.elastic.co/u/Nicolas_Pelletier)\
**Replies:** 4\
**Last updated:** [March 18, 2023, 4:32pm UTC](https://discuss.elastic.co/t/elastic-agent-install-error-already-installed-at-opt-elastic-agent/327926 "2023-03-18T16:32:36Z")

</div>

Hello, I'm trying to enroll an agent on a healthy fleet server which is also an agent (what i've understood). I'm following the step by step guide from kibana interface in integration panel (see the image below) I'…

---

## [Field\_value\_factor use max of score](https://discuss.elastic.co/t/field-value-factor-use-max-of-score/327971)

<div class="topic-metadata">

**Author:** [@Alexander\_Engel](https://discuss.elastic.co/u/Alexander_Engel)\
**Replies:** 3\
**Last updated:** [March 18, 2023, 3:31pm UTC](https://discuss.elastic.co/t/field-value-factor-use-max-of-score/327971 "2023-03-18T15:31:09Z")

</div>

I have the following query: { "query": { "function\_score": { "boost\_mode": "multiply", "functions": \[ { "field\_value\_factor": { "factor": 0.5, "field": "albums…

---

## [Logstash filter: a field pointing to many format of the same field](https://discuss.elastic.co/t/logstash-filter-a-field-pointing-to-many-format-of-the-same-field/327918)

<div class="topic-metadata">

**Author:** [@Farah\_Bhr](https://discuss.elastic.co/u/Farah_Bhr)\
**Replies:** 3\
**Last updated:** [March 18, 2023, 10:51am UTC](https://discuss.elastic.co/t/logstash-filter-a-field-pointing-to-many-format-of-the-same-field/327918 "2023-03-18T10:51:33Z")

</div>

I have a lot of logs and I want to search through these log lines a callID flow and visualize everything related to that callID into kibana with logstash I made a filter that detects an hexadecimal format for that CallI…

---

## [Logtrail: problem using via reverse proxy](https://discuss.elastic.co/t/logtrail-problem-using-via-reverse-proxy/327951)

<div class="topic-metadata">

**Author:** [@freeman999](https://discuss.elastic.co/u/freeman999)\
**Replies:** 1\
**Last updated:** [March 18, 2023, 9:48am UTC](https://discuss.elastic.co/t/logtrail-problem-using-via-reverse-proxy/327951 "2023-03-18T09:48:21Z")

</div>

Hello everyone: my logtrail plugin doesn't work via reverse proxy nginx. I have the following picture when I try to get logtrail page using domain name https://kibana.domain.com/app/logtrail and I have a working log…

---

## [Elasticsearch 7.16.2 not getting started after upgrading Log4j to 2.20 version](https://discuss.elastic.co/t/elasticsearch-7-16-2-not-getting-started-after-upgrading-log4j-to-2-20-version/327799)

<div class="topic-metadata">

**Author:** [@kgpbharathi](https://discuss.elastic.co/u/kgpbharathi)\
**Replies:** 5\
**Last updated:** [March 17, 2023, 11:50pm UTC](https://discuss.elastic.co/t/elasticsearch-7-16-2-not-getting-started-after-upgrading-log4j-to-2-20-version/327799 "2023-03-17T23:50:25Z")

</div>

We are using elasticsearch with version": { "number": "7.16.2","build\_type": "rpm","lucene\_version": "8.10.1" } We have upgraded elasticsearch log4j files from 2.17 to 2.20 and elasticsearch is failing to start . Once…

---

## [Simple example for using curl to log a message to Logstash using the HTTP input plugin?](https://discuss.elastic.co/t/simple-example-for-using-curl-to-log-a-message-to-logstash-using-the-http-input-plugin/327964)

<div class="topic-metadata">

**Author:** [@jba](https://discuss.elastic.co/u/jba)\
**Replies:** 1\
**Last updated:** [March 17, 2023, 11:03pm UTC](https://discuss.elastic.co/t/simple-example-for-using-curl-to-log-a-message-to-logstash-using-the-http-input-plugin/327964 "2023-03-17T23:03:39Z")

</div>

I am trying to use curl to to log something, just something, to an index, any index, on a ELK 8.4.1 cluster. On my Logstash node I have the following as part of the configuration in the conf.d directory: input { beat…

---

## [Question about Opaque ID in index requests and Opaque ID restrictions/limitations](https://discuss.elastic.co/t/question-about-opaque-id-in-index-requests-and-opaque-id-restrictions-limitations/327963)

<div class="topic-metadata">

**Author:** [@Tomas\_Bartek](https://discuss.elastic.co/u/Tomas_Bartek)\
**Replies:** 0\
**Last updated:** [March 17, 2023, 6:22pm UTC](https://discuss.elastic.co/t/question-about-opaque-id-in-index-requests-and-opaque-id-restrictions-limitations/327963 "2023-03-17T18:22:07Z")

</div>

Hello Team, We are currently adding Opaque ID to our Elasticsearch calls to improve traceability in our system. We have also enabled slow logs for both indexing and searching, where Opaque ID is very helpful. So far, I…

---

## [Version\_conflict when trying to delete documents using \_delete\_by\_query API](https://discuss.elastic.co/t/version-conflict-when-trying-to-delete-documents-using-delete-by-query-api/327954)

<div class="topic-metadata">

**Author:** [@tmslara.a](https://discuss.elastic.co/u/tmslara.a)\
**Replies:** 0\
**Last updated:** [March 17, 2023, 3:58pm UTC](https://discuss.elastic.co/t/version-conflict-when-trying-to-delete-documents-using-delete-by-query-api/327954 "2023-03-17T15:58:41Z")

</div>

Hello, I'm using Elasticsearch 8.6. I loaded many documents to an index day by day. I made a mistake when uploading the data for one day, so I want to delete all data from that specific day and load the correct informat…

---

## [Logstash on Windows](https://discuss.elastic.co/t/logstash-on-windows/327906)

<div class="topic-metadata">

**Author:** [@Rakesh\_Mukherjee](https://discuss.elastic.co/u/Rakesh_Mukherjee)\
**Replies:** 1\
**Last updated:** [March 17, 2023, 4:49pm UTC](https://discuss.elastic.co/t/logstash-on-windows/327906 "2023-03-17T16:49:15Z")

</div>

I installed Logstash on Windows and find that my output plugin showing error, please help, the error message is here, Unable to configure plugins: (pluginloading error) couldn't find any output plugin named 'microsoft-se…

---

## [Elasticsearch search response pick(latency) occurs when \_refresh with G1GC](https://discuss.elastic.co/t/elasticsearch-search-response-pick-latency-occurs-when-refresh-with-g1gc/327612)

<div class="topic-metadata">

**Author:** [@doyle.min](https://discuss.elastic.co/u/doyle.min)\
**Replies:** 3\
**Last updated:** [March 17, 2023, 3:18pm UTC](https://discuss.elastic.co/t/elasticsearch-search-response-pick-latency-occurs-when-refresh-with-g1gc/327612 "2023-03-17T15:18:03Z")

</div>

hello. Our elasticsearch cluster has 3 master nodes and 12 data nodes installed on 2 IDCs. In front of elasticsearch, there is search api server that multisearches three indexes. It shows an average response time of le…

---

## [Do we have any chance to do the custom changes in individual visuals in Kibana except CSS](https://discuss.elastic.co/t/do-we-have-any-chance-to-do-the-custom-changes-in-individual-visuals-in-kibana-except-css/326845)

<div class="topic-metadata">

**Author:** [@Abj\_Ins](https://discuss.elastic.co/u/Abj_Ins)\
**Replies:** 5\
**Last updated:** [March 17, 2023, 12:34pm UTC](https://discuss.elastic.co/t/do-we-have-any-chance-to-do-the-custom-changes-in-individual-visuals-in-kibana-except-css/326845 "2023-03-17T12:34:57Z")

</div>

Hi Team, Please help us to do the custom changes in individual visuals in Kibana except CSS. Thanks.

---

## [Rebalancing data between disks](https://discuss.elastic.co/t/rebalancing-data-between-disks/327927)

<div class="topic-metadata">

**Author:** [@INS](https://discuss.elastic.co/u/INS)\
**Replies:** 3\
**Last updated:** [March 17, 2023, 12:13pm UTC](https://discuss.elastic.co/t/rebalancing-data-between-disks/327927 "2023-03-17T12:13:49Z")

</div>

Hi Can You give some tips how I can trigger rebalance for equal distribution of data depending on the size of the disk node shards disk.indices disk.used disk.avail disk.total disk.percent es\_data\_hdd\_1\_2 …

---

## [Logstash filter help pleas](https://discuss.elastic.co/t/logstash-filter-help-pleas/327718)

<div class="topic-metadata">

**Author:** [@alexsamad](https://discuss.elastic.co/u/alexsamad)\
**Replies:** 2\
**Last updated:** [March 17, 2023, 12:10pm UTC](https://discuss.elastic.co/t/logstash-filter-help-pleas/327718 "2023-03-17T12:10:27Z")

</div>

Hi I'm in the process of trying to migrate my config from 6.7 to 8.x I have found I have to rewrite my logstash rules - okay probably a good time to do that. On that note - my filebeat 6.7 client worked fine, when i u…

---

## [Kibana Connector - Unrecgonized Authentication tyoe](https://discuss.elastic.co/t/kibana-connector-unrecgonized-authentication-tyoe/327916)

<div class="topic-metadata">

**Author:** [@Tiharqa](https://discuss.elastic.co/u/Tiharqa)\
**Replies:** 0\
**Last updated:** [March 17, 2023, 9:50am UTC](https://discuss.elastic.co/t/kibana-connector-unrecgonized-authentication-tyoe/327916 "2023-03-17T09:50:02Z")

</div>

Receiving this message when attempt to test my elastic connector 504 5 .7 .4 unrecognized authentication type xpack.actions.preconfigured: my-email: name: somename actiontypeId : .email config: …

---

## [Unable to index into elasticsearch due to Byte range being out of range](https://discuss.elastic.co/t/unable-to-index-into-elasticsearch-due-to-byte-range-being-out-of-range/327857)

<div class="topic-metadata">

**Author:** [@Shreesh\_Narayanan](https://discuss.elastic.co/u/Shreesh_Narayanan)\
**Replies:** 3\
**Last updated:** [March 17, 2023, 9:44am UTC](https://discuss.elastic.co/t/unable-to-index-into-elasticsearch-due-to-byte-range-being-out-of-range/327857 "2023-03-17T09:44:05Z")

</div>

Hi, I have a log that shows the interface usage (eth0/eth1) at a particular time , it logs in bytes and while logstash is able to parse it , elasticsearch seems to be rejecting it . Any workaround for this ? , in the co…

---

## [Creating visualization with the single logline message](https://discuss.elastic.co/t/creating-visualization-with-the-single-logline-message/327417)

<div class="topic-metadata">

**Author:** [@prashant1](https://discuss.elastic.co/u/prashant1)\
**Replies:** 6\
**Last updated:** [March 17, 2023, 9:21am UTC](https://discuss.elastic.co/t/creating-visualization-with-the-single-logline-message/327417 "2023-03-17T09:21:55Z")

</div>

We have one usecase to create the visualization We have below fields in one log message :- requestedMsgCount 2500 allowedMsgCount 2400 startedMsgCount 2400 lostMsgCount 10 terminatedMsgC…

---

## [Allocation temporarily throttled issue](https://discuss.elastic.co/t/allocation-temporarily-throttled-issue/327629)

<div class="topic-metadata">

**Author:** [@nairobi](https://discuss.elastic.co/u/nairobi)\
**Replies:** 1\
**Last updated:** [March 14, 2023, 6:52am UTC](https://discuss.elastic.co/t/allocation-temporarily-throttled-issue/327629 "2023-03-14T06:52:59Z")

</div>

One of my node down accidently, and it joined cluster few minutes later. After that To allocate shard faster, I changed 'cluster.routing.allocation.node\_concurrent\_incoming\_recoveries' 10 to 50 And below issue happene…

---

## [Multi-Level Monitoring with Synthetic Monitoring](https://discuss.elastic.co/t/multi-level-monitoring-with-synthetic-monitoring/327734)

<div class="topic-metadata">

**Author:** [@aisyaharifin](https://discuss.elastic.co/u/aisyaharifin)\
**Replies:** 4\
**Last updated:** [March 17, 2023, 12:59am UTC](https://discuss.elastic.co/t/multi-level-monitoring-with-synthetic-monitoring/327734 "2023-03-17T00:59:43Z")

</div>

Hello Elastic, I would like to ask, can Synthetic Monitoring features in Elastic did a multi-level monitoring? In my situation, if the monitor is down for more than 5 times, the application will automatically restart o…

[Previous page](https://discuss.elastic.co/tag/none.md?no_tags=true&page=415)

[Next page](https://discuss.elastic.co/tag/none.md?no_tags=true&page=417)
