# \#none

**URL:** https://discuss.elastic.co/tag/none.md?no_tags=true&page=418

[Latest](https://discuss.elastic.co/latest.md) · [Categories](https://discuss.elastic.co/categories.md) · [Tags](https://discuss.elastic.co/tags.md)

**Page:** 419

---

## [Logstash ruby filter hash class exception](https://discuss.elastic.co/t/logstash-ruby-filter-hash-class-exception/327747)

<div class="topic-metadata">

**Author:** [@onuruzun](https://discuss.elastic.co/u/onuruzun)\
**Replies:** 0\
**Last updated:** [March 15, 2023, 11:47am UTC](https://discuss.elastic.co/t/logstash-ruby-filter-hash-class-exception/327747 "2023-03-15T11:47:29Z")

</div>

I tried to get the difference between these two JSON objects coming from JDBC in Logstash. example JDBC JSON: before = '{"heroes":\[{"id":1,"name":"pudge"},{"id":2,"name":"slark"},{"id":3,"name":"techies"}\]}' after = '…

---

## [Upgrade from 7.x to 8.x requires multi upgrades?](https://discuss.elastic.co/t/upgrade-from-7-x-to-8-x-requires-multi-upgrades/327408)

<div class="topic-metadata">

**Author:** [@atdc12](https://discuss.elastic.co/u/atdc12)\
**Replies:** 5\
**Last updated:** [March 15, 2023, 9:36am UTC](https://discuss.elastic.co/t/upgrade-from-7-x-to-8-x-requires-multi-upgrades/327408 "2023-03-15T09:36:38Z")

</div>

We have a few production sites running ES 7.16 and would like to upgrade to 8.6: upgrade will be done with full cluster restart all indices were created under ES 7.x we have checked Upgrade Assistant on ES 7.16 and con…

---

## [Elasticsearch continuously on yellow Status - Unassigned Shards](https://discuss.elastic.co/t/elasticsearch-continuously-on-yellow-status-unassigned-shards/327742)

<div class="topic-metadata">

**Author:** [@Apostolos\_Koutoulas](https://discuss.elastic.co/u/Apostolos_Koutoulas)\
**Replies:** 1\
**Last updated:** [March 15, 2023, 9:34am UTC](https://discuss.elastic.co/t/elasticsearch-continuously-on-yellow-status-unassigned-shards/327742 "2023-03-15T09:34:13Z")

</div>

Hello all! Hope you are doing well Cluster status in yellow with unassigned replica shards Elasticsearch version 6.8.23 Cluster status: \[root@d38-pan020 ~\]# es\_cluster.sh health { "cluster\_name" : "\_\_pan\_cluster\_\_…

---

## [How can I mark root object as null](https://discuss.elastic.co/t/how-can-i-mark-root-object-as-null/327719)

<div class="topic-metadata">

**Author:** [@Vivek\_Burman](https://discuss.elastic.co/u/Vivek_Burman)\
**Replies:** 11\
**Last updated:** [March 15, 2023, 9:02am UTC](https://discuss.elastic.co/t/how-can-i-mark-root-object-as-null/327719 "2023-03-15T09:02:34Z")

</div>

So my mapping looks like this. My query is I would like to mark the custom\_field property as null as a root \[NULL\_VALUES IN ELASTIC SEARCH\] (null\_value | Elasticsearch Guide \[8.6\] | Elastic) "custom\_field":{ …

---

## [Data not ingested into master node](https://discuss.elastic.co/t/data-not-ingested-into-master-node/327649)

<div class="topic-metadata">

**Author:** [@truekonrads](https://discuss.elastic.co/u/truekonrads)\
**Replies:** 6\
**Last updated:** [March 15, 2023, 7:57am UTC](https://discuss.elastic.co/t/data-not-ingested-into-master-node/327649 "2023-03-15T07:57:19Z")

</div>

Hello, I have a three node cluster set up with no explicitly defined roles for each nodes. I can see by disk usage and index document count that no data was ingested into master node - only non-master nodes have data on…

---

## [Kibana Audit Log - Alerting Rule Deletion](https://discuss.elastic.co/t/kibana-audit-log-alerting-rule-deletion/327645)

<div class="topic-metadata">

**Author:** [@wanch](https://discuss.elastic.co/u/wanch)\
**Replies:** 0\
**Last updated:** [March 14, 2023, 9:59am UTC](https://discuss.elastic.co/t/kibana-audit-log-alerting-rule-deletion/327645 "2023-03-14T09:59:51Z")

</div>

Hi, I have a question regarding Kibana's audit logging and the deletion of alerting rules. Below is the audit logs I got for deleting an alerting rule in Kibana UI: { "event": { "action": "http\_request", "ca…

---

## [How to pass multiple indies to ElasticSearch UI ElasticsearchAPIConnector](https://discuss.elastic.co/t/how-to-pass-multiple-indies-to-elasticsearch-ui-elasticsearchapiconnector/327707)

<div class="topic-metadata">

**Author:** [@Sheng111](https://discuss.elastic.co/u/Sheng111)\
**Replies:** 0\
**Last updated:** [March 15, 2023, 12:08am UTC](https://discuss.elastic.co/t/how-to-pass-multiple-indies-to-elasticsearch-ui-elasticsearchapiconnector/327707 "2023-03-15T00:08:35Z")

</div>

Hi there, I am using Search UI with Elasticsearch, wondering how to pass multiple indies to config? I got requirement is build a global search box, so users can search multiple indies data based on different attribute …

---

## [How to integrate my logs to Elastic Observability](https://discuss.elastic.co/t/how-to-integrate-my-logs-to-elastic-observability/326233)

<div class="topic-metadata">

**Author:** [@schavaku](https://discuss.elastic.co/u/schavaku)\
**Replies:** 2\
**Last updated:** [March 14, 2023, 10:01pm UTC](https://discuss.elastic.co/t/how-to-integrate-my-logs-to-elastic-observability/326233 "2023-03-14T22:01:05Z")

</div>

How can I configure my logs from SQL Server on Elastic Search server( is already exists). How can I integrate the logs? Pleas let me know the steps.

---

## [Useragent filter not working as expected after enabling ECS](https://discuss.elastic.co/t/useragent-filter-not-working-as-expected-after-enabling-ecs/327662)

<div class="topic-metadata">

**Author:** [@flalar](https://discuss.elastic.co/u/flalar)\
**Replies:** 2\
**Last updated:** [March 14, 2023, 8:13pm UTC](https://discuss.elastic.co/t/useragent-filter-not-working-as-expected-after-enabling-ecs/327662 "2023-03-14T20:13:13Z")

</div>

We're having trouble with the useragent filter not adding the data to the document sent to Elasticsearch or stdout. Seems this happend after enabling support for ECS. Upgrading from Logstash 7.17.9 to 8.6.2 did not solv…

---

## [Sinker: a new tool to synchronize Postgres to Elasticsearch](https://discuss.elastic.co/t/sinker-a-new-tool-to-synchronize-postgres-to-elasticsearch/327691)

<div class="topic-metadata">

**Author:** [@loren](https://discuss.elastic.co/u/loren)\
**Replies:** 0\
**Last updated:** [March 14, 2023, 4:53pm UTC](https://discuss.elastic.co/t/sinker-a-new-tool-to-synchronize-postgres-to-elasticsearch/327691 "2023-03-14T16:53:41Z")

</div>

I built a change data capture tool to synchronize normalized Postgres data into denormalized Elasticsearch documents, and my employer let me open-source it yesterday. We tried some existing solutions but they weren't a…

---

## [Problems upgrading Elasticsearch from version 7.17 to 8.6.2 in ECE](https://discuss.elastic.co/t/problems-upgrading-elasticsearch-from-version-7-17-to-8-6-2-in-ece/327680)

<div class="topic-metadata">

**Author:** [@JRM](https://discuss.elastic.co/u/JRM)\
**Replies:** 0\
**Last updated:** [March 14, 2023, 2:42pm UTC](https://discuss.elastic.co/t/problems-upgrading-elasticsearch-from-version-7-17-to-8-6-2-in-ece/327680 "2023-03-14T14:42:37Z")

</div>

I am upgrading Elasticsearch from version 7.17 to 8.6.2 in ECE , and it gives this error: plan change failed: some instances were not running. I have used the upgrade wizard and everything was correct to perform the upg…

---

## [Missing headers even with include\_headers (Csv codec plugin) set to true](https://discuss.elastic.co/t/missing-headers-even-with-include-headers-csv-codec-plugin-set-to-true/327555)

<div class="topic-metadata">

**Author:** [@alexus](https://discuss.elastic.co/u/alexus)\
**Replies:** 5\
**Last updated:** [March 14, 2023, 4:34pm UTC](https://discuss.elastic.co/t/missing-headers-even-with-include-headers-csv-codec-plugin-set-to-true/327555 "2023-03-14T16:34:56Z")

</div>

Hello World! per Csv codec plugin | Logstash Reference \[7.17\] | Elastic I'm set include\_headers flag to value true, yet even though headers gets included into output on first run, at later time on re-run schedule of ve…

---

## [Thousands of services, means thousands of shards?](https://discuss.elastic.co/t/thousands-of-services-means-thousands-of-shards/327683)

<div class="topic-metadata">

**Author:** [@jtocher](https://discuss.elastic.co/u/jtocher)\
**Replies:** 0\
**Last updated:** [March 14, 2023, 3:07pm UTC](https://discuss.elastic.co/t/thousands-of-services-means-thousands-of-shards/327683 "2023-03-14T15:07:10Z")

</div>

At our organization, we have a system that has north of 1000 microservices, deployed across multiple environments. These are all instrumented with telemetry, communicating to our Elastic Stack. This past year we've migra…

---

## [Dev console suddenly just a blank canvas](https://discuss.elastic.co/t/dev-console-suddenly-just-a-blank-canvas/327596)

<div class="topic-metadata">

**Author:** [@stefws](https://discuss.elastic.co/u/stefws)\
**Replies:** 4\
**Last updated:** [March 14, 2023, 2:17pm UTC](https://discuss.elastic.co/t/dev-console-suddenly-just-a-blank-canvas/327596 "2023-03-14T14:17:15Z")

</div>

Suddenly one day my Dev Tools Console v.8.6.1 on top of a v.8.6.1 cluster is just a blank canvas, don't why, hints appreciated, TIA! Was a while ago playing with ldap/AD authentication but reverted it again as basic lic…

---

## [Building an index for faster search](https://discuss.elastic.co/t/building-an-index-for-faster-search/326301)

<div class="topic-metadata">

**Author:** [@orlenkoda5](https://discuss.elastic.co/u/orlenkoda5)\
**Replies:** 2\
**Last updated:** [March 14, 2023, 1:49pm UTC](https://discuss.elastic.co/t/building-an-index-for-faster-search/326301 "2023-03-14T13:49:35Z")

</div>

Hi everyone, I have one question. How should I build my index to reduce the time of searching? In my case, using aggregations for distinct search really increases the time of searching.

---

## [X509: certificate signed by unknown authority](https://discuss.elastic.co/t/x509-certificate-signed-by-unknown-authority/327572)

<div class="topic-metadata">

**Author:** [@AbbysS](https://discuss.elastic.co/u/AbbysS)\
**Replies:** 8\
**Last updated:** [March 14, 2023, 1:48pm UTC](https://discuss.elastic.co/t/x509-certificate-signed-by-unknown-authority/327572 "2023-03-14T13:48:51Z")

</div>

Hi everyone, I'm new on the forum. I'm little confuse, i try to learn many tutorials on fleet server / agent but i don't know how i can create my own certificate to deploy in production. I try to learn the ELK tutoria…

---

## [Indexing script with parameters into percolation field breaks in 8.5](https://discuss.elastic.co/t/indexing-script-with-parameters-into-percolation-field-breaks-in-8-5/327667)

<div class="topic-metadata">

**Author:** [@cehj](https://discuss.elastic.co/u/cehj)\
**Replies:** 0\
**Last updated:** [March 14, 2023, 1:07pm UTC](https://discuss.elastic.co/t/indexing-script-with-parameters-into-percolation-field-breaks-in-8-5/327667 "2023-03-14T13:07:26Z")

</div>

When indexing into a percolation field on a document, we submit something like: { "bool": { "filter": \[ { "script": { "script": { "sour…

---

## [First search Request on Elasticsearch is slow](https://discuss.elastic.co/t/first-search-request-on-elasticsearch-is-slow/327560)

<div class="topic-metadata">

**Author:** [@Rakhshunda\_Noorein\_J](https://discuss.elastic.co/u/Rakhshunda_Noorein_J)\
**Replies:** 3\
**Last updated:** [March 14, 2023, 11:41am UTC](https://discuss.elastic.co/t/first-search-request-on-elasticsearch-is-slow/327560 "2023-03-14T11:41:33Z")

</div>

Hello, Having an issue on elasticsearch, my first request to search in elastic is slow. Once any term gets searched then it becomes fast. I have researched about this and get to know the solution is to change the index …

---

## [System integration : specifying the interfaces needed](https://discuss.elastic.co/t/system-integration-specifying-the-interfaces-needed/326783)

<div class="topic-metadata">

**Author:** [@fabien9402](https://discuss.elastic.co/u/fabien9402)\
**Replies:** 1\
**Last updated:** [March 14, 2023, 10:38am UTC](https://discuss.elastic.co/t/system-integration-specifying-the-interfaces-needed/326783 "2023-03-14T10:38:30Z")

</div>

Hi, In the "System" integration of our policies we want to have the metrics of specific network interfaces. In the configuration menu, there is indeed the possibility of specifying the interfaces needed. It is specifie…

---

## [Sorting in Lens pies](https://discuss.elastic.co/t/sorting-in-lens-pies/327436)

<div class="topic-metadata">

**Author:** [@InesCM](https://discuss.elastic.co/u/InesCM)\
**Replies:** 2\
**Last updated:** [March 14, 2023, 9:48am UTC](https://discuss.elastic.co/t/sorting-in-lens-pies/327436 "2023-03-14T09:48:50Z")

</div>

Hi there! I thought that this was an issue with Legacy (aggregation based) visualizations, but I'm seeing this in Lens too... Am I missing something, or this makes no sense? When I slice a donut chart by ranges, the co…

---

## [How to set auto-reloading conf files in logstash.yml or pipeline.yml](https://discuss.elastic.co/t/how-to-set-auto-reloading-conf-files-in-logstash-yml-or-pipeline-yml/327425)

<div class="topic-metadata">

**Author:** [@terrymu](https://discuss.elastic.co/u/terrymu)\
**Replies:** 2\
**Last updated:** [March 14, 2023, 9:39am UTC](https://discuss.elastic.co/t/how-to-set-auto-reloading-conf-files-in-logstash-yml-or-pipeline-yml/327425 "2023-03-14T09:39:51Z")

</div>

Hi All, I know here is a feature that can auto-reloading conf files without logstash restart action. So my question is easy, how to turn on auto-reloading function in logstash.yml or pipeline.yml ? I need an workin…

---

## [Spike in failed logon events ML rule alerting](https://discuss.elastic.co/t/spike-in-failed-logon-events-ml-rule-alerting/327642)

<div class="topic-metadata">

**Author:** [@Maretti](https://discuss.elastic.co/u/Maretti)\
**Replies:** 0\
**Last updated:** [March 14, 2023, 9:31am UTC](https://discuss.elastic.co/t/spike-in-failed-logon-events-ml-rule-alerting/327642 "2023-03-14T09:31:53Z")

</div>

Hi everyone I am experimenting with the ML learning rule that alerts when a spike happens in failed logon events. I did a RDP bruteforce from kali to windows in the bruteforce the password did get guessed so the host is…

---

## [Upgrade to 7.x aggregation performance degradation](https://discuss.elastic.co/t/upgrade-to-7-x-aggregation-performance-degradation/327449)

<div class="topic-metadata">

**Author:** [@dbajra94](https://discuss.elastic.co/u/dbajra94)\
**Replies:** 1\
**Last updated:** [March 14, 2023, 8:51am UTC](https://discuss.elastic.co/t/upgrade-to-7-x-aggregation-performance-degradation/327449 "2023-03-14T08:51:39Z")

</div>

We are currently in process of migrating our Cloud tenants to 7.16.3 in preparation for an internal 8.6 Elasticsearch upgrade of our software. However, we have noticed that our aggregation queries have suffered a hard un…

---

## [Metricbeat kept connecting to http://localhost:9200 while using AWS privatelink](https://discuss.elastic.co/t/metricbeat-kept-connecting-to-http-localhost-9200-while-using-aws-privatelink/327634)

<div class="topic-metadata">

**Author:** [@tanwk2](https://discuss.elastic.co/u/tanwk2)\
**Replies:** 0\
**Last updated:** [March 14, 2023, 8:30am UTC](https://discuss.elastic.co/t/metricbeat-kept-connecting-to-http-localhost-9200-while-using-aws-privatelink/327634 "2023-03-14T08:30:21Z")

</div>

Anyone has the same problem where the Metricbeats keep trying to connect to Elasticsearch Url: http://localhost:9200 until around 1h 30 mins later and it finds the correct Elasticsearch Url that was identified in the fle…

---

## [Event Filter \* field](https://discuss.elastic.co/t/event-filter-field/325674)

<div class="topic-metadata">

**Author:** [@NathanLau](https://discuss.elastic.co/u/NathanLau)\
**Replies:** 4\
**Last updated:** [March 14, 2023, 1:12am UTC](https://discuss.elastic.co/t/event-filter-field/325674 "2023-03-14T01:12:04Z")

</div>

Hi all , The purpose is refuse receive some logs. (Endpoint) there are a lot of event on everyday , don't want to receive not meaningful logs to occupied the space , how could filter all value of \* or filter the field…

---

## [Disabling an integration in fleet](https://discuss.elastic.co/t/disabling-an-integration-in-fleet/327600)

<div class="topic-metadata">

**Author:** [@marcoderama](https://discuss.elastic.co/u/marcoderama)\
**Replies:** 0\
**Last updated:** [March 13, 2023, 10:00pm UTC](https://discuss.elastic.co/t/disabling-an-integration-in-fleet/327600 "2023-03-13T22:00:58Z")

</div>

I'm testing various agent policy incantations within fleet so I have a bunch of them now. As such, I have more going on at once than I'd like. It would be useful if I could mark an agent policy as "disabled" within fle…

---

## [Upgrade 7 -\> 8. depreciation messages -- ruby api](https://discuss.elastic.co/t/upgrade-7-8-depreciation-messages-ruby-api/327590)

<div class="topic-metadata">

**Author:** [@Russell\_Fulton](https://discuss.elastic.co/u/Russell_Fulton)\
**Replies:** 1\
**Last updated:** [March 13, 2023, 9:04pm UTC](https://discuss.elastic.co/t/upgrade-7-8-depreciation-messages-ruby-api/327590 "2023-03-13T21:04:54Z")

</div>

I am about to attempt to upgrade my test system from 7.17 to the latest 8.x... I have custom written ingestion processes which uses the ruby elasticsearch gem. Migration assistant says all is good but when I look at th…

---

## [Piece\_id.keyword vs piece\_id](https://discuss.elastic.co/t/piece-id-keyword-vs-piece-id/327584)

<div class="topic-metadata">

**Author:** [@Rafa\_H](https://discuss.elastic.co/u/Rafa_H)\
**Replies:** 1\
**Last updated:** [March 13, 2023, 6:11pm UTC](https://discuss.elastic.co/t/piece-id-keyword-vs-piece-id/327584 "2023-03-13T18:11:28Z")

</div>

Hello everyone. I am new to the community. I have a question related to elasticsearch and would appreciate your support. In the platform we are developing, in the local env and staging env elasticsearch works only if k…

---

## [Logstash error failed to install template](https://discuss.elastic.co/t/logstash-error-failed-to-install-template/327521)

<div class="topic-metadata">

**Author:** [@supraja\_inamadugu](https://discuss.elastic.co/u/supraja_inamadugu)\
**Replies:** 2\
**Last updated:** [March 13, 2023, 6:06pm UTC](https://discuss.elastic.co/t/logstash-error-failed-to-install-template/327521 "2023-03-13T18:06:17Z")

</div>

\[ERROR\] 2023-03-12 22:42:30.743 \[Ruby-0-Thread-10: /opt/homebrew/Cellar/logstash/8.6.1/libexec/vendor/bundle/jruby/2.6.0/gems/logstash-output-elasticsearch-11.12.1-java/lib/logstash/plugin\_mixins/elasticsearch/common.rb:…

---

## [User only with access to content they have created](https://discuss.elastic.co/t/user-only-with-access-to-content-they-have-created/327574)

<div class="topic-metadata">

**Author:** [@abrooky](https://discuss.elastic.co/u/abrooky)\
**Replies:** 2\
**Last updated:** [March 13, 2023, 4:36pm UTC](https://discuss.elastic.co/t/user-only-with-access-to-content-they-have-created/327574 "2023-03-13T16:36:53Z")

</div>

Can someone point me the in the right direction. I've built a simple search as you type tool for a website catalogue which will be used by multiple websites. I need to make sure that each tenant have a unique user/pass …

[Previous page](https://discuss.elastic.co/tag/none.md?no_tags=true&page=417)

[Next page](https://discuss.elastic.co/tag/none.md?no_tags=true&page=419)
