# \#none

**URL:** https://discuss.elastic.co/tag/none.md?no_tags=true&page=419

[Latest](https://discuss.elastic.co/latest.md) · [Categories](https://discuss.elastic.co/categories.md) · [Tags](https://discuss.elastic.co/tags.md)

**Page:** 420

---

## [Grok parser and nested brackets](https://discuss.elastic.co/t/grok-parser-and-nested-brackets/327454)

<div class="topic-metadata">

**Author:** [@ddoroshenko](https://discuss.elastic.co/u/ddoroshenko)\
**Replies:** 5\
**Last updated:** [March 13, 2023, 4:03pm UTC](https://discuss.elastic.co/t/grok-parser-and-nested-brackets/327454 "2023-03-13T16:03:57Z")

</div>

Hi, I have log event like this 2023-03-03T11:11:11.000Z INFO (foo (bar) bla bla \[bla\]) 2023-03-03T11:11:11.000Z \[foo (bar) bla bla \[bla\]\] I want to parse it with grok filter like timestamp: 2023-03-03T11:11:11.000Z l…

---

## [Is it possible to "conditionaly" analyze same field differently? \[synonyms\]](https://discuss.elastic.co/t/is-it-possible-to-conditionaly-analyze-same-field-differently-synonyms/326441)

<div class="topic-metadata">

**Author:** [@astrodi](https://discuss.elastic.co/u/astrodi)\
**Replies:** 3\
**Last updated:** [March 13, 2023, 3:16pm UTC](https://discuss.elastic.co/t/is-it-possible-to-conditionaly-analyze-same-field-differently-synonyms/326441 "2023-03-13T15:16:46Z")

</div>

Hi there, The index contains 3 business units, the goal is to provide different set of synonyms for each BU. The field is unstructured text (PDF rendition), occupying 95% of overall index storage, currently analyzed t…

---

## [Does every index have its own shard?](https://discuss.elastic.co/t/does-every-index-have-its-own-shard/327526)

<div class="topic-metadata">

**Author:** [@emrethedev](https://discuss.elastic.co/u/emrethedev)\
**Replies:** 10\
**Last updated:** [March 13, 2023, 3:02pm UTC](https://discuss.elastic.co/t/does-every-index-have-its-own-shard/327526 "2023-03-13T15:02:47Z")

</div>

Hi, (Sorry if this is a double post but i could not find answer.) Does every index have its own shard or may they have common shards? We know that when we create an index, it has 5 shards by default. So when we create a…

---

## [Aggregation on specific object in an array](https://discuss.elastic.co/t/aggregation-on-specific-object-in-an-array/327533)

<div class="topic-metadata">

**Author:** [@Vivek\_Burman](https://discuss.elastic.co/u/Vivek_Burman)\
**Replies:** 3\
**Last updated:** [March 13, 2023, 1:27pm UTC](https://discuss.elastic.co/t/aggregation-on-specific-object-in-an-array/327533 "2023-03-13T13:27:33Z")

</div>

Hi, So my document has a structure as below. I would like to aggregate based on \*\*value\*\*, but only on the object with {"label": "Business Priority"}. Can you help how I can achieve this?

---

## [Questions regarding working with pie charts](https://discuss.elastic.co/t/questions-regarding-working-with-pie-charts/327554)

<div class="topic-metadata">

**Author:** [@marcober](https://discuss.elastic.co/u/marcober)\
**Replies:** 0\
**Last updated:** [March 13, 2023, 1:20pm UTC](https://discuss.elastic.co/t/questions-regarding-working-with-pie-charts/327554 "2023-03-13T13:20:45Z")

</div>

Hi, I'm new using Kibana and I have some questions regarding working with pie charts. There are two things that I've been trying to do but I have not been able to: With a KQL query I was able to handle my data and ge…

---

## [Asa integration in elastic agent](https://discuss.elastic.co/t/asa-integration-in-elastic-agent/327163)

<div class="topic-metadata">

**Author:** [@bex](https://discuss.elastic.co/u/bex)\
**Replies:** 7\
**Last updated:** [March 13, 2023, 12:54pm UTC](https://discuss.elastic.co/t/asa-integration-in-elastic-agent/327163 "2023-03-13T12:54:33Z")

</div>

Can anyone please advise with "Asa" integration in elastic agent? As we know, there are 2 ways: I am sending logs of ASA(192.168.110.1) by syslog udp to logstash(192.168.110.243). When checking by tcpdump, I see that…

---

## [Posting logs of underlying plugin libraries to Logstash log stream](https://discuss.elastic.co/t/posting-logs-of-underlying-plugin-libraries-to-logstash-log-stream/327105)

<div class="topic-metadata">

**Author:** [@alromos](https://discuss.elastic.co/u/alromos)\
**Replies:** 1\
**Last updated:** [March 13, 2023, 11:15am UTC](https://discuss.elastic.co/t/posting-logs-of-underlying-plugin-libraries-to-logstash-log-stream/327105 "2023-03-13T11:15:16Z")

</div>

Is it possible to post logs of underlying libraries to Logstash log stream? For instance, I use input JDBC plugin with MSSQL JDBC driver and I would like to see logs of the driver library for debug purposes. Is it poss…

---

## [Transport error 429](https://discuss.elastic.co/t/transport-error-429/327528)

<div class="topic-metadata">

**Author:** [@Susendiran](https://discuss.elastic.co/u/Susendiran)\
**Replies:** 5\
**Last updated:** [March 13, 2023, 10:48am UTC](https://discuss.elastic.co/t/transport-error-429/327528 "2023-03-13T10:48:31Z")

</div>

Hi Team, We are getting elasticsearch exceptions - transport error 429 while providing es.search command using python pandas for some large set of data(upto 13-15k records). It's showing the limit is more than the thres…

---

## [Adding extra field in filebeat](https://discuss.elastic.co/t/adding-extra-field-in-filebeat/327534)

<div class="topic-metadata">

**Author:** [@gyrao\_72](https://discuss.elastic.co/u/gyrao_72)\
**Replies:** 0\
**Last updated:** [March 13, 2023, 9:08am UTC](https://discuss.elastic.co/t/adding-extra-field-in-filebeat/327534 "2023-03-13T09:08:29Z")

</div>

filebeat.inputs: # Each - is an input. Most options can be set at the input level, so # you can use different inputs for various configurations. # Below are the input specific configurations. - type: log # Change to t…

---

## [NOT STRING IN ARRAY IN WATCHER](https://discuss.elastic.co/t/not-string-in-array-in-watcher/327421)

<div class="topic-metadata">

**Author:** [@Daniel\_Lopez](https://discuss.elastic.co/u/Daniel_Lopez)\
**Replies:** 1\
**Last updated:** [March 13, 2023, 10:18am UTC](https://discuss.elastic.co/t/not-string-in-array-in-watcher/327421 "2023-03-13T10:18:19Z")

</div>

Hi team! I'm trying to setup a watcher for finding a way to check if an array has not a string value, but i getting stuck, could someone have an idea?

---

## [Adding only the appended part of a file to elastic using logstash](https://discuss.elastic.co/t/adding-only-the-appended-part-of-a-file-to-elastic-using-logstash/327520)

<div class="topic-metadata">

**Author:** [@aks03](https://discuss.elastic.co/u/aks03)\
**Replies:** 1\
**Last updated:** [March 13, 2023, 4:37am UTC](https://discuss.elastic.co/t/adding-only-the-appended-part-of-a-file-to-elastic-using-logstash/327520 "2023-03-13T04:37:35Z")

</div>

Hey everyone, I am new to Elk stack but currently I want to add only the appended part of a file i.e, any extra content added to the file to elastic using logstash 6.3. The files are unstructured so even that has left …

---

## [Kibana 8.6.1 \`yarn kbn bootstrap\` Error](https://discuss.elastic.co/t/kibana-8-6-1-yarn-kbn-bootstrap-error/327519)

<div class="topic-metadata">

**Author:** [@suran\_choi](https://discuss.elastic.co/u/suran_choi)\
**Replies:** 0\
**Last updated:** [March 13, 2023, 4:35am UTC](https://discuss.elastic.co/t/kibana-8-6-1-yarn-kbn-bootstrap-error/327519 "2023-03-13T04:35:38Z")

</div>

I just wanna run Kibana 8.6.1. But I got this error. Node version : 16.18.1 yarn version : 1.22.19 ubuntu@raspberrypi:/usr/local/kibana$ bin/kibana node:internal/modules/cjs/loader:988 throw err; ^ Error: Cannot …

---

## [Convert a string field to number, but only brand new indices recognized](https://discuss.elastic.co/t/convert-a-string-field-to-number-but-only-brand-new-indices-recognized/327512)

<div class="topic-metadata">

**Author:** [@KeithTt](https://discuss.elastic.co/u/KeithTt)\
**Replies:** 0\
**Last updated:** [March 13, 2023, 3:39am UTC](https://discuss.elastic.co/t/convert-a-string-field-to-number-but-only-brand-new-indices-recognized/327512 "2023-03-13T03:39:55Z")

</div>

Logstash version: 6.3.0 Here is my config: mutate { convert =\> { "bytes\_sent" =\> "integer" } } I find that a indice which first created can recognized the config, but the others ones can not, even they created erv…

---

## [Visualizations not working in dashboard](https://discuss.elastic.co/t/visualizations-not-working-in-dashboard/327505)

<div class="topic-metadata">

**Author:** [@Sara\_YB](https://discuss.elastic.co/u/Sara_YB)\
**Replies:** 0\
**Last updated:** [March 12, 2023, 5:12pm UTC](https://discuss.elastic.co/t/visualizations-not-working-in-dashboard/327505 "2023-03-12T17:12:27Z")

</div>

I already upgraded to Elastic 8.6, and repalced beats by Elastic Agent. The problem is that because of some visualizations built in using filebeat, they stopped showing data after the replacement. So, is there any work…

---

## [False alert about certificate expiry](https://discuss.elastic.co/t/false-alert-about-certificate-expiry/327504)

<div class="topic-metadata">

**Author:** [@Sara\_YB](https://discuss.elastic.co/u/Sara_YB)\
**Replies:** 0\
**Last updated:** [March 12, 2023, 5:05pm UTC](https://discuss.elastic.co/t/false-alert-about-certificate-expiry/327504 "2023-03-12T17:05:05Z")

</div>

The certificate is up to date; however, it is not updated in Kibana as indicated in the below screenshot: This caused sending fslse alerts. I need your help to solve this issue as it is happening with this certifica…

---

## [Simple question about timestamp in logs](https://discuss.elastic.co/t/simple-question-about-timestamp-in-logs/327485)

<div class="topic-metadata">

**Author:** [@Mark\_S](https://discuss.elastic.co/u/Mark_S)\
**Replies:** 3\
**Last updated:** [March 12, 2023, 4:31pm UTC](https://discuss.elastic.co/t/simple-question-about-timestamp-in-logs/327485 "2023-03-12T16:31:42Z")

</div>

When I create an index and use Logstash to send logfiles, I use the option start\_position =\> "beginning". However when viewing "discover" mode in kibana, I only see the logs after the index was created. Shouldn't there …

---

## [Generate image out of kibana](https://discuss.elastic.co/t/generate-image-out-of-kibana/326914)

<div class="topic-metadata">

**Author:** [@mayer](https://discuss.elastic.co/u/mayer)\
**Replies:** 4\
**Last updated:** [March 12, 2023, 3:29pm UTC](https://discuss.elastic.co/t/generate-image-out-of-kibana/326914 "2023-03-12T15:29:22Z")

</div>

Dear All, We are running ELK latest version with authentication available on Intranet but not accessible from Internet. We want to make some images public available but we do not want to give access to ELK directly for …

---

## [Grok (or any alternative) to search for keywords in logs](https://discuss.elastic.co/t/grok-or-any-alternative-to-search-for-keywords-in-logs/327351)

<div class="topic-metadata">

**Author:** [@Mark\_S](https://discuss.elastic.co/u/Mark_S)\
**Replies:** 14\
**Last updated:** [March 12, 2023, 12:34pm UTC](https://discuss.elastic.co/t/grok-or-any-alternative-to-search-for-keywords-in-logs/327351 "2023-03-12T12:34:26Z")

</div>

Hello, Is it possible to create keywords in logstash, by searching for them in the message? The logs are formatted in the following way, however they are not always in the same place - they could be embedded in other m…

---

## [How to filter buckets based on the comparison of two sub-aggregation metrics in ElasticSearch (python)?](https://discuss.elastic.co/t/how-to-filter-buckets-based-on-the-comparison-of-two-sub-aggregation-metrics-in-elasticsearch-python/327498)

<div class="topic-metadata">

**Author:** [@Ashar\_Ahmad](https://discuss.elastic.co/u/Ashar_Ahmad)\
**Replies:** 0\
**Last updated:** [March 12, 2023, 8:59am UTC](https://discuss.elastic.co/t/how-to-filter-buckets-based-on-the-comparison-of-two-sub-aggregation-metrics-in-elasticsearch-python/327498 "2023-03-12T08:59:20Z")

</div>

My index has documents with the following fields: user\_id, user\_name, post\_text, post\_sentiment where post\_sentiment is of type double, and represents the sentiment of the post. A post\_sentiment greater than 0 indicates …

---

## [Unbale to view logs but indices available](https://discuss.elastic.co/t/unbale-to-view-logs-but-indices-available/327496)

<div class="topic-metadata">

**Author:** [@Prabhakar\_D](https://discuss.elastic.co/u/Prabhakar_D)\
**Replies:** 6\
**Last updated:** [March 12, 2023, 8:20am UTC](https://discuss.elastic.co/t/unbale-to-view-logs-but-indices-available/327496 "2023-03-12T08:20:08Z")

</div>

Hi, ELK uable to view logs for specific period but indices available. Someone please suggest how to recover the indices which is already rolledup as per lifecycle

---

## [Logstash Keeps Restarting](https://discuss.elastic.co/t/logstash-keeps-restarting/327494)

<div class="topic-metadata">

**Author:** [@kirkofthefleet](https://discuss.elastic.co/u/kirkofthefleet)\
**Replies:** 1\
**Last updated:** [March 12, 2023, 3:06am UTC](https://discuss.elastic.co/t/logstash-keeps-restarting/327494 "2023-03-12T03:06:51Z")

</div>

Hello! Please forgive any "syntax errors" as I am a complete newb to all of the elastic stack. I am working on getting elasticstack working for my small IT business. I have a few servers that I am interested in monitor…

---

## [What AWS config file settings are honored?](https://discuss.elastic.co/t/what-aws-config-file-settings-are-honored/327490)

<div class="topic-metadata">

**Author:** [@marcoderama](https://discuss.elastic.co/u/marcoderama)\
**Replies:** 0\
**Last updated:** [March 11, 2023, 9:39pm UTC](https://discuss.elastic.co/t/what-aws-config-file-settings-are-honored/327490 "2023-03-11T21:39:24Z")

</div>

\[Elastic noob warning!\] Fundamentally, I'm trying to figure out how to automatically update temporary credentials for the Elastic AWS integration. I'm trying to configure my AWS Elastic Agent integration to use a shar…

---

## [How Translog Work on elastic](https://discuss.elastic.co/t/how-translog-work-on-elastic/325880)

<div class="topic-metadata">

**Author:** [@yuswanul](https://discuss.elastic.co/u/yuswanul)\
**Replies:** 6\
**Last updated:** [March 11, 2023, 10:35am UTC](https://discuss.elastic.co/t/how-translog-work-on-elastic/325880 "2023-03-11T10:35:29Z")

</div>

Hi everyone, I have a question about translog. So here is the situation: I have one index with 1 primary and 1 replica shard and continuously ingesting data. If i read documentation, it says that primary and replica sh…

---

## [Insert multiple fields in nested array](https://discuss.elastic.co/t/insert-multiple-fields-in-nested-array/327415)

<div class="topic-metadata">

**Author:** [@Claudio\_Ract\_Costa](https://discuss.elastic.co/u/Claudio_Ract_Costa)\
**Replies:** 2\
**Last updated:** [March 11, 2023, 1:21am UTC](https://discuss.elastic.co/t/insert-multiple-fields-in-nested-array/327415 "2023-03-11T01:21:59Z")

</div>

Hi Guys I have the following input as example: generator { count =\> 1 lines =\> \[ '{ "RATING\_GROUP": "7,843,13", "CONSUMO": "328994,29715,13948" }' \] codec =\> json } Which filter can I use in Logstash to obtain a outp…

---

## [Elastic Agent USB Locking Feature](https://discuss.elastic.co/t/elastic-agent-usb-locking-feature/327323)

<div class="topic-metadata">

**Author:** [@ali.sharjeel](https://discuss.elastic.co/u/ali.sharjeel)\
**Replies:** 3\
**Last updated:** [March 10, 2023, 11:43pm UTC](https://discuss.elastic.co/t/elastic-agent-usb-locking-feature/327323 "2023-03-10T23:43:53Z")

</div>

Is there any feature like we have in antivirus to lock usb devices from plugging in Elastic Agent?

---

## [Elastic Security Rules Analytics](https://discuss.elastic.co/t/elastic-security-rules-analytics/326890)

<div class="topic-metadata">

**Author:** [@Alexander\_A](https://discuss.elastic.co/u/Alexander_A)\
**Replies:** 2\
**Last updated:** [March 10, 2023, 9:38pm UTC](https://discuss.elastic.co/t/elastic-security-rules-analytics/326890 "2023-03-10T21:38:13Z")

</div>

Is there a way to get how much time it gets to execute all security rules. In "Stack Management" -\> "Rules and Connectors" analytics available per each rule but summary analytics seems to be missing. For example all rule…

---

## [How to make a time series of discrete events](https://discuss.elastic.co/t/how-to-make-a-time-series-of-discrete-events/327367)

<div class="topic-metadata">

**Author:** [@gyannea](https://discuss.elastic.co/u/gyannea)\
**Replies:** 4\
**Last updated:** [March 10, 2023, 9:15pm UTC](https://discuss.elastic.co/t/how-to-make-a-time-series-of-discrete-events/327367 "2023-03-10T21:15:44Z")

</div>

It seems I can only make time series (including with TSBV) of numerical values. What I have are gateways that send a finite set of event types. What I would like to do is plot in a time series which type event was sent.…

---

## [Going from data nodes to hot and warm nodes](https://discuss.elastic.co/t/going-from-data-nodes-to-hot-and-warm-nodes/327311)

<div class="topic-metadata">

**Author:** [@reswob](https://discuss.elastic.co/u/reswob)\
**Replies:** 1\
**Last updated:** [March 10, 2023, 8:36pm UTC](https://discuss.elastic.co/t/going-from-data-nodes-to-hot-and-warm-nodes/327311 "2023-03-10T20:36:01Z")

</div>

Lab Environment: 3 Master and 2 Data nodes. Just sent some data to cluster without building custom templates or ILM policies or mappings. I added 2 more Data nodes and made the first two Hot and the new 2 Warm nodes p…

---

## [Search functionality in Elastic Stack fails with a proxy error](https://discuss.elastic.co/t/search-functionality-in-elastic-stack-fails-with-a-proxy-error/327372)

<div class="topic-metadata">

**Author:** [@Bhanuji\_paluri](https://discuss.elastic.co/u/Bhanuji_paluri)\
**Replies:** 1\
**Last updated:** [March 10, 2023, 4:24pm UTC](https://discuss.elastic.co/t/search-functionality-in-elastic-stack-fails-with-a-proxy-error/327372 "2023-03-10T16:24:07Z")

</div>

when the search is filtered with indices of large size and with more no of days ex: more than 7 days. Steps to reproduce: Login to Kibana service: https://docklin-efk-ks.sel .rnd.internal.com/ select index pattern d…

---

## [Connect sql server database to elasticsearch](https://discuss.elastic.co/t/connect-sql-server-database-to-elasticsearch/327465)

<div class="topic-metadata">

**Author:** [@Farah\_Bhr](https://discuss.elastic.co/u/Farah_Bhr)\
**Replies:** 1\
**Last updated:** [March 10, 2023, 4:23pm UTC](https://discuss.elastic.co/t/connect-sql-server-database-to-elasticsearch/327465 "2023-03-10T16:23:56Z")

</div>

I want to connect sql server database to elasticsearch without copying the sql data to elasticsearch, with a simple call of the sql data or simple connection , without loading the data from sql server to elasticsearch I…

[Previous page](https://discuss.elastic.co/tag/none.md?no_tags=true&page=418)

[Next page](https://discuss.elastic.co/tag/none.md?no_tags=true&page=420)
