# \#none

**URL:** https://discuss.elastic.co/tag/none.md?no_tags=true&page=420

[Latest](https://discuss.elastic.co/latest.md) · [Categories](https://discuss.elastic.co/categories.md) · [Tags](https://discuss.elastic.co/tags.md)

**Page:** 421

---

## [Dashboard filtering](https://discuss.elastic.co/t/dashboard-filtering/327437)

<div class="topic-metadata">

**Author:** [@Alice\_Ionescu](https://discuss.elastic.co/u/Alice_Ionescu)\
**Replies:** 2\
**Last updated:** [March 10, 2023, 4:17pm UTC](https://discuss.elastic.co/t/dashboard-filtering/327437 "2023-03-10T16:17:40Z")

</div>

Hello, I want to add a filter that eliminates the records with type Disconnect and have user admin. So only for user admin to eliminate the Disconnect events. I've tried this, but it is not ok { "query": { "boo…

---

## [Can i send message from logstash to pagerduty by http output plugin](https://discuss.elastic.co/t/can-i-send-message-from-logstash-to-pagerduty-by-http-output-plugin/326129)

<div class="topic-metadata">

**Author:** [@YasuhiroOkumura](https://discuss.elastic.co/u/YasuhiroOkumura)\
**Replies:** 1\
**Last updated:** [March 10, 2023, 3:22pm UTC](https://discuss.elastic.co/t/can-i-send-message-from-logstash-to-pagerduty-by-http-output-plugin/326129 "2023-03-10T15:22:25Z")

</div>

Are there any having sample code using http output plugin of logstash to send message to pagerduty. Can I see the code.

---

## [Error Loading data into ElasticSearch using Azure Data Factory - Zappysys connector](https://discuss.elastic.co/t/error-loading-data-into-elasticsearch-using-azure-data-factory-zappysys-connector/327442)

<div class="topic-metadata">

**Author:** [@gau\_prpce](https://discuss.elastic.co/u/gau_prpce)\
**Replies:** 0\
**Last updated:** [March 10, 2023, 10:58am UTC](https://discuss.elastic.co/t/error-loading-data-into-elasticsearch-using-azure-data-factory-zappysys-connector/327442 "2023-03-10T10:58:33Z")

</div>

I was trying to load data from azure postgresql to elasticsearch through ADF copy activity using Zappysys connector. Facing this issue. Failure happened on 'Sink' side. ErrorCode=UserErrorOdbcOperationFailed,'Type=Micr…

---

## [How can I delete unnassigned shards?](https://discuss.elastic.co/t/how-can-i-delete-unnassigned-shards/327433)

<div class="topic-metadata">

**Author:** [@frankmehlhop.com](https://discuss.elastic.co/u/frankmehlhop.com)\
**Replies:** 1\
**Last updated:** [March 10, 2023, 10:56am UTC](https://discuss.elastic.co/t/how-can-i-delete-unnassigned-shards/327433 "2023-03-10T10:56:03Z")

</div>

In my cluster there are unassigned shards which are not primary shards. I don't know why I have these secondary shards in my cluster. I didn't create them intentionally and I use the default configuration (elasticsearch…

---

## [How to remove the empty result set caused by bucket\_selector?](https://discuss.elastic.co/t/how-to-remove-the-empty-result-set-caused-by-bucket-selector/327430)

<div class="topic-metadata">

**Author:** [@Jinnrry](https://discuss.elastic.co/u/Jinnrry)\
**Replies:** 2\
**Last updated:** [March 10, 2023, 10:48am UTC](https://discuss.elastic.co/t/how-to-remove-the-empty-result-set-caused-by-bucket-selector/327430 "2023-03-10T10:48:13Z")

</div>

This operation will show you my problem. 1、Create Index PUT car { "mappings": { "properties": { "color": { "type": "keyword" }, "company": { "type": "keyword" }, "pri…

---

## [How to roll up RUM data](https://discuss.elastic.co/t/how-to-roll-up-rum-data/326927)

<div class="topic-metadata">

**Author:** [@Rick\_V](https://discuss.elastic.co/u/Rick_V)\
**Replies:** 5\
**Last updated:** [March 10, 2023, 10:07am UTC](https://discuss.elastic.co/t/how-to-roll-up-rum-data/326927 "2023-03-10T10:07:10Z")

</div>

Hi all, we are using an Elastic deployment for collecting apm & rum data of a website. It is used for a project where we are improving the user experience. The project will take a few weeks/months so we want to rollup t…

---

## [How to Add Another Host To Kibana On Different Device or Server](https://discuss.elastic.co/t/how-to-add-another-host-to-kibana-on-different-device-or-server/327250)

<div class="topic-metadata">

**Author:** [@Tw1cUser](https://discuss.elastic.co/u/Tw1cUser)\
**Replies:** 4\
**Last updated:** [March 10, 2023, 9:39am UTC](https://discuss.elastic.co/t/how-to-add-another-host-to-kibana-on-different-device-or-server/327250 "2023-03-10T09:39:40Z")

</div>

I want add more host to my kibana on windows server 2019, but i have no idea how to do it. Anyone can help me with that simple question?

---

## [Finding similar/related news articles process](https://discuss.elastic.co/t/finding-similar-related-news-articles-process/327427)

<div class="topic-metadata">

**Author:** [@cyril\_g](https://discuss.elastic.co/u/cyril_g)\
**Replies:** 0\
**Last updated:** [March 10, 2023, 9:12am UTC](https://discuss.elastic.co/t/finding-similar-related-news-articles-process/327427 "2023-03-10T09:12:15Z")

</div>

Hello, I am working on a news app in the gaming industry and I would like to be able to identify headlines/ articles with titles about the same subject. One thing to note is that games and platforms have many alternati…

---

## [Elastic Agent with custom log integration](https://discuss.elastic.co/t/elastic-agent-with-custom-log-integration/327341)

<div class="topic-metadata">

**Author:** [@eleong](https://discuss.elastic.co/u/eleong)\
**Replies:** 10\
**Last updated:** [March 10, 2023, 7:53am UTC](https://discuss.elastic.co/t/elastic-agent-with-custom-log-integration/327341 "2023-03-10T07:53:37Z")

</div>

Hi, Ran into issue which is quite puzzling. Referred to the official docs and some topics in this forum but it did not help. I am trying to ingest custom logs via integration within elastic agent. Everything is working…

---

## [ELK Vulnerability Detection](https://discuss.elastic.co/t/elk-vulnerability-detection/327261)

<div class="topic-metadata">

**Author:** [@cyberintellect](https://discuss.elastic.co/u/cyberintellect)\
**Replies:** 2\
**Last updated:** [March 10, 2023, 6:01am UTC](https://discuss.elastic.co/t/elk-vulnerability-detection/327261 "2023-03-10T06:01:03Z")

</div>

Hi guys, I was wondering if the function exists or is being looked at to implement vulnerability detections via the agent like with Wazuh Vulnerability Detection module. I searched the forum but I'm not seeing, might b…

---

## [Creating Endpoint Exception for one endpoint](https://discuss.elastic.co/t/creating-endpoint-exception-for-one-endpoint/326593)

<div class="topic-metadata">

**Author:** [@slash24](https://discuss.elastic.co/u/slash24)\
**Replies:** 1\
**Last updated:** [March 9, 2023, 11:41pm UTC](https://discuss.elastic.co/t/creating-endpoint-exception-for-one-endpoint/326593 "2023-03-09T23:41:43Z")

</div>

How do I create an Endpoint Exception that only apply to one specfic host? I have alot of servers in one Fleet policy and would like to excluse w3wp.exe. This however a dangerous blindspot so of course i want to limit th…

---

## [Importing rules with detection\_rules CLI](https://discuss.elastic.co/t/importing-rules-with-detection-rules-cli/327190)

<div class="topic-metadata">

**Author:** [@Fredrick](https://discuss.elastic.co/u/Fredrick)\
**Replies:** 1\
**Last updated:** [March 9, 2023, 10:35pm UTC](https://discuss.elastic.co/t/importing-rules-with-detection-rules-cli/327190 "2023-03-09T22:35:55Z")

</div>

Hello! I've been recently importing rules with detection\_rules - detection-rules/CLI.md at main · elastic/detection-rules · GitHub. My usecase is to convert our custom Kibana rules into toml files so we can manage our c…

---

## [Endpoint service not honoring proxy environment variables](https://discuss.elastic.co/t/endpoint-service-not-honoring-proxy-environment-variables/327234)

<div class="topic-metadata">

**Author:** [@indyg](https://discuss.elastic.co/u/indyg)\
**Replies:** 2\
**Last updated:** [March 9, 2023, 10:26pm UTC](https://discuss.elastic.co/t/endpoint-service-not-honoring-proxy-environment-variables/327234 "2023-03-09T22:26:13Z")

</div>

We're testing out deploying Defend to our fleet but are running into an issue where the endpoint service isn't honoring the HTTP\_PROXY or HTTPS\_PROXY environment variables, which for us is needed to push documents into E…

---

## [Custom Query detection Rule is not runnig on my elk](https://discuss.elastic.co/t/custom-query-detection-rule-is-not-runnig-on-my-elk/327256)

<div class="topic-metadata">

**Author:** [@Sajith](https://discuss.elastic.co/u/Sajith)\
**Replies:** 2\
**Last updated:** [March 9, 2023, 10:20pm UTC](https://discuss.elastic.co/t/custom-query-detection-rule-is-not-runnig-on-my-elk/327256 "2023-03-09T22:20:54Z")

</div>

I created a custom detection rule which is just a query for failed logins (event.code : "4625") I have pointed it to the index pattern and I can see the output on preview results as well. After enabling the rule there …

---

## [Does this mean my "\_id" field is taking up GB of RAM?](https://discuss.elastic.co/t/does-this-mean-my-id-field-is-taking-up-gb-of-ram/327128)

<div class="topic-metadata">

**Author:** [@linkerc](https://discuss.elastic.co/u/linkerc)\
**Replies:** 3\
**Last updated:** [March 9, 2023, 6:39pm UTC](https://discuss.elastic.co/t/does-this-mean-my-id-field-is-taking-up-gb-of-ram/327128 "2023-03-09T18:39:27Z")

</div>

\[fielddata\] New used memory 13315258923 \[12.4gb\] for data of \[\_id\] would be larger than configured breaker: 13314398617 \[12.3gb\], breaking I'm getting the above warning and wondering why. Does it mean my "\_id" field (t…

---

## [How to stop ECK Operator changes to elastic cluster at k8s](https://discuss.elastic.co/t/how-to-stop-eck-operator-changes-to-elastic-cluster-at-k8s/327358)

<div class="topic-metadata">

**Author:** [@prabhakar\_talari](https://discuss.elastic.co/u/prabhakar_talari)\
**Replies:** 0\
**Last updated:** [March 9, 2023, 12:31pm UTC](https://discuss.elastic.co/t/how-to-stop-eck-operator-changes-to-elastic-cluster-at-k8s/327358 "2023-03-09T12:31:58Z")

</div>

Hi Team, I am running ECK 1.4.1 & elastic 7.16.3 version at OnPrem K8s, Some times when i want to add more data nodes to cluster i will do the changes in elastic yam file and deployit then operator will push the changes…

---

## [Watches not writing to wacher history](https://discuss.elastic.co/t/watches-not-writing-to-wacher-history/327364)

<div class="topic-metadata">

**Author:** [@Sagi\_Bensimon](https://discuss.elastic.co/u/Sagi_Bensimon)\
**Replies:** 3\
**Last updated:** [March 9, 2023, 5:38pm UTC](https://discuss.elastic.co/t/watches-not-writing-to-wacher-history/327364 "2023-03-09T17:38:23Z")

</div>

.watcher-history indices aren't being created and are also missing. There aren't any errors and action.auto\_create\_index isn't set anywhere.

---

## [Elastic-agent updates](https://discuss.elastic.co/t/elastic-agent-updates/327382)

<div class="topic-metadata">

**Author:** [@stobbe](https://discuss.elastic.co/u/stobbe)\
**Replies:** 0\
**Last updated:** [March 9, 2023, 5:00pm UTC](https://discuss.elastic.co/t/elastic-agent-updates/327382 "2023-03-09T17:00:14Z")

</div>

Hello, If I understand correctly, if you update an agent to a new version, the software (binaries) have to be downloaded from a repository. The extra "plugins" are available from kibana Simple question, why not use Ki…

---

## [Statuscode-404-error-not-found-message-not-found](https://discuss.elastic.co/t/statuscode-404-error-not-found-message-not-found/327359)

<div class="topic-metadata">

**Author:** [@thomas4](https://discuss.elastic.co/u/thomas4)\
**Replies:** 1\
**Last updated:** [March 9, 2023, 4:13pm UTC](https://discuss.elastic.co/t/statuscode-404-error-not-found-message-not-found/327359 "2023-03-09T16:13:29Z")

</div>

Hi all, I created a space and when i try to login to it i get the message above, but if i sign in with the super user account and then sign out, and sign in with my new space account it works. Any help would be grateful. …

---

## [Static variables in Kibana discovery script](https://discuss.elastic.co/t/static-variables-in-kibana-discovery-script/327125)

<div class="topic-metadata">

**Author:** [@gyannea](https://discuss.elastic.co/u/gyannea)\
**Replies:** 6\
**Last updated:** [March 9, 2023, 3:41pm UTC](https://discuss.elastic.co/t/static-variables-in-kibana-discovery-script/327125 "2023-03-09T15:41:23Z")

</div>

What should be something very simple. I want to create a new field for a Kibana discovery and dashboard that simply counts the received document. So each document will have an index 0, 1, 2, ..., n. However, I do not se…

---

## [Not able to parse geojson data in logstash](https://discuss.elastic.co/t/not-able-to-parse-geojson-data-in-logstash/325247)

<div class="topic-metadata">

**Author:** [@aaryan](https://discuss.elastic.co/u/aaryan)\
**Replies:** 1\
**Last updated:** [March 9, 2023, 3:35pm UTC](https://discuss.elastic.co/t/not-able-to-parse-geojson-data-in-logstash/325247 "2023-03-09T15:35:45Z")

</div>

This is the config I am using. input { file { path =\> "D:/Softwares/ELK/data/geojson/features.geojson" start\_position =\> "beginning" sincedb\_path =\> "D:/Softwares/ELK/data/cache/geojsontry.txt" codec =\> mult…

---

## [\[ES 8.6.1 & 8.6.2\] Fleet's "Custom Logs" integration stops sending logs with "failed to publish events: temporary bulk send failure" message](https://discuss.elastic.co/t/es-8-6-1-8-6-2-fleets-custom-logs-integration-stops-sending-logs-with-failed-to-publish-events-temporary-bulk-send-failure-message/327293)

<div class="topic-metadata">

**Author:** [@BorisNaguet](https://discuss.elastic.co/u/BorisNaguet)\
**Replies:** 0\
**Last updated:** [March 8, 2023, 5:08pm UTC](https://discuss.elastic.co/t/es-8-6-1-8-6-2-fleets-custom-logs-integration-stops-sending-logs-with-failed-to-publish-events-temporary-bulk-send-failure-message/327293 "2023-03-08T17:08:35Z")

</div>

Hello, I'm new to Elastic, so it's possible that I configured something wrong... Also, please be precise on where/how to find things if you ask for more info. Base installationI installed a fresh Elastic recently: 8…

---

## [Logstash log file location](https://discuss.elastic.co/t/logstash-log-file-location/327307)

<div class="topic-metadata">

**Author:** [@elasticforme](https://discuss.elastic.co/u/elasticforme)\
**Replies:** 2\
**Last updated:** [March 9, 2023, 2:57pm UTC](https://discuss.elastic.co/t/logstash-log-file-location/327307 "2023-03-09T14:57:19Z")

</div>

I am running logstash as daemon via systemd I get my log in to my special log dir /log/logstash/logstash-plain.log but I also get that in /var/log/message. I want to stop them and I read that it is control by log4j2 fi…

---

## [Index sorting with two order values in the same field](https://discuss.elastic.co/t/index-sorting-with-two-order-values-in-the-same-field/327333)

<div class="topic-metadata">

**Author:** [@joaoantao](https://discuss.elastic.co/u/joaoantao)\
**Replies:** 0\
**Last updated:** [March 9, 2023, 8:33am UTC](https://discuss.elastic.co/t/index-sorting-with-two-order-values-in-the-same-field/327333 "2023-03-09T08:33:53Z")

</div>

I am trying to improve queries in one index with ~ 125 million documents and 3 shards. Most of the queries hitting this index have a sort order for a given field with values ascending and descending. Currently the index…

---

## [Stackoverflow error on logstash when using es\_bulk codec](https://discuss.elastic.co/t/stackoverflow-error-on-logstash-when-using-es-bulk-codec/327337)

<div class="topic-metadata">

**Author:** [@eeijlar](https://discuss.elastic.co/u/eeijlar)\
**Replies:** 1\
**Last updated:** [March 9, 2023, 2:17pm UTC](https://discuss.elastic.co/t/stackoverflow-error-on-logstash-when-using-es-bulk-codec/327337 "2023-03-09T14:17:45Z")

</div>

Using the following pipeline with logstash: - pipeline.id: export-process pipeline.workers: 4 config.string: | input { elasticsearch { hosts =\> "http://elastic:80/elasticsearch/…

---

## [Meta data not written to logstash output file](https://discuss.elastic.co/t/meta-data-not-written-to-logstash-output-file/327366)

<div class="topic-metadata">

**Author:** [@eeijlar](https://discuss.elastic.co/u/eeijlar)\
**Replies:** 0\
**Last updated:** [March 9, 2023, 2:02pm UTC](https://discuss.elastic.co/t/meta-data-not-written-to-logstash-output-file/327366 "2023-03-09T14:02:14Z")

</div>

I am using the following logstash pipeline: - pipeline.id: export-process pipeline.workers: 4 config.string: | input { elasticsearch { hosts =\> "http://elastic:80/elasticsearch/…

---

## [Issue with removing tag](https://discuss.elastic.co/t/issue-with-removing-tag/327193)

<div class="topic-metadata">

**Author:** [@Harika](https://discuss.elastic.co/u/Harika)\
**Replies:** 1\
**Last updated:** [March 9, 2023, 1:27pm UTC](https://discuss.elastic.co/t/issue-with-removing-tag/327193 "2023-03-09T13:27:03Z")

</div>

we are having the \<system-out\>\<!\[CDATA\[\]\]\>\</system-out\> tag in our XML File. Due to this tag it could not index and throwing the below Error: "error"=\>{"type"=\>"illegal\_argument\_exception", "reason"=\>"can't merge a non …

---

## [How to load CSV data to already created and existing Index in Kibana?](https://discuss.elastic.co/t/how-to-load-csv-data-to-already-created-and-existing-index-in-kibana/326979)

<div class="topic-metadata">

**Author:** [@hitnalli\_praveen](https://discuss.elastic.co/u/hitnalli_praveen)\
**Replies:** 8\
**Last updated:** [March 9, 2023, 11:55am UTC](https://discuss.elastic.co/t/how-to-load-csv-data-to-already-created-and-existing-index-in-kibana/326979 "2023-03-09T11:55:07Z")

</div>

I've a unique requirement and trying few new things. My main objective is to display scanned data from Tenable Nessus (showing total count of scanned vulnerabilities - Critical, High and Medium) on to Kibana Dashboard af…

---

## [Logstash stopped processing logs after enabling minimal security](https://discuss.elastic.co/t/logstash-stopped-processing-logs-after-enabling-minimal-security/327232)

<div class="topic-metadata">

**Author:** [@A.Hani](https://discuss.elastic.co/u/A.Hani)\
**Replies:** 4\
**Last updated:** [March 9, 2023, 11:02am UTC](https://discuss.elastic.co/t/logstash-stopped-processing-logs-after-enabling-minimal-security/327232 "2023-03-09T11:02:25Z")

</div>

I was wondering what should be configured on logstash side after enabling basic on Elasticsearch node? I set x.pack.security.enabled to true on elasticsearch.yml, generated passwords for the cluster users, added the ki…

---

## [Elasticsearch Setup Custom Index and Write Issue](https://discuss.elastic.co/t/elasticsearch-setup-custom-index-and-write-issue/327332)

<div class="topic-metadata">

**Author:** [@elk-siwm](https://discuss.elastic.co/u/elk-siwm)\
**Replies:** 0\
**Last updated:** [March 9, 2023, 8:28am UTC](https://discuss.elastic.co/t/elasticsearch-setup-custom-index-and-write-issue/327332 "2023-03-09T08:28:45Z")

</div>

Elasticsearch get logs via filebeats shipper default settings. All custom index settings were configured on /etc/filebeats/filebeats.yml file. This is my configuration file: output.elasticsearch: # Array of hosts to c…

[Previous page](https://discuss.elastic.co/tag/none.md?no_tags=true&page=419)

[Next page](https://discuss.elastic.co/tag/none.md?no_tags=true&page=421)
