# \#none

**URL:** https://discuss.elastic.co/tag/none.md?no_tags=true&page=423

[Latest](https://discuss.elastic.co/latest.md) · [Categories](https://discuss.elastic.co/categories.md) · [Tags](https://discuss.elastic.co/tags.md)

**Page:** 424

---

## [Elastic Docker Integration - not collecting logs](https://discuss.elastic.co/t/elastic-docker-integration-not-collecting-logs/326947)

<div class="topic-metadata">

**Author:** [@sc1215](https://discuss.elastic.co/u/sc1215)\
**Replies:** 4\
**Last updated:** [March 6, 2023, 3:01pm UTC](https://discuss.elastic.co/t/elastic-docker-integration-not-collecting-logs/326947 "2023-03-06T15:01:20Z")

</div>

I had been using the 'System' integration agent to consume my docker logs which are saved in the path: /var/lib/docker/containers/\*/\*-json.log This has been working, but unfortunately, it was splitting up log lines whic…

---

## [Logstash Config File not running getting error: contains non-ascii characters but are not UTF-8 encoded](https://discuss.elastic.co/t/logstash-config-file-not-running-getting-error-contains-non-ascii-characters-but-are-not-utf-8-encoded/327080)

<div class="topic-metadata">

**Author:** [@PRASHANT\_MEHTA](https://discuss.elastic.co/u/PRASHANT_MEHTA)\
**Replies:** 2\
**Last updated:** [March 6, 2023, 2:24pm UTC](https://discuss.elastic.co/t/logstash-config-file-not-running-getting-error-contains-non-ascii-characters-but-are-not-utf-8-encoded/327080 "2023-03-06T14:24:27Z")

</div>

Hello All, I'm getting below error while running the logstash config,Unable to understand how it can be resolved.Eearlier it worked by now giving error. input { jdbc { jdbc\_connection\_string =\> "jdbc:oracle:thin…

---

## [Clone a space via API](https://discuss.elastic.co/t/clone-a-space-via-api/327041)

<div class="topic-metadata">

**Author:** [@oliverj](https://discuss.elastic.co/u/oliverj)\
**Replies:** 1\
**Last updated:** [March 6, 2023, 2:23pm UTC](https://discuss.elastic.co/t/clone-a-space-via-api/327041 "2023-03-06T14:23:18Z")

</div>

We are standing up our first Cluster, and one of the things we have run into is that people have no "user context" for the artifcats they create. Everything is shared by space. So, our plan is to have 2 spaces for our us…

---

## [High CPU Utilization in Elasticsearch Nodes](https://discuss.elastic.co/t/high-cpu-utilization-in-elasticsearch-nodes/327078)

<div class="topic-metadata">

**Author:** [@Souvik\_Das](https://discuss.elastic.co/u/Souvik_Das)\
**Replies:** 0\
**Last updated:** [March 6, 2023, 1:12pm UTC](https://discuss.elastic.co/t/high-cpu-utilization-in-elasticsearch-nodes/327078 "2023-03-06T13:12:26Z")

</div>

Hi, We have been experiencing HIGH CPU USAGE in elasticsearch nodes for the last couple of days causing timeout exceptions for most of the search queries. We have dedicated nodes for ES, however, there is no defined mas…

---

## [Gauge ordering by value calculated in bucket script aggregation](https://discuss.elastic.co/t/gauge-ordering-by-value-calculated-in-bucket-script-aggregation/327077)

<div class="topic-metadata">

**Author:** [@tumbl3w33d](https://discuss.elastic.co/u/tumbl3w33d)\
**Replies:** 0\
**Last updated:** [March 6, 2023, 1:07pm UTC](https://discuss.elastic.co/t/gauge-ordering-by-value-calculated-in-bucket-script-aggregation/327077 "2023-03-06T13:07:50Z")

</div>

Hello, I'm using elastic agent with its system integration to collect metrics and I want to display the disk use per host as gauges. It's achieved by calculating the percentual use in a bucket script: The ordering d…

---

## [All the shards are being assigned to a single node](https://discuss.elastic.co/t/all-the-shards-are-being-assigned-to-a-single-node/326857)

<div class="topic-metadata">

**Author:** [@sanju1323](https://discuss.elastic.co/u/sanju1323)\
**Replies:** 4\
**Last updated:** [March 6, 2023, 11:27am UTC](https://discuss.elastic.co/t/all-the-shards-are-being-assigned-to-a-single-node/326857 "2023-03-06T11:27:41Z")

</div>

Hi.. We have a 6 data node cluster and we have around 2000 indices with 9500 shards. We have the below cluster settings and have enabled all the shards to be re-balanced to distribute the shards across the cluster. { …

---

## [Elasticsearch deprecation issues](https://discuss.elastic.co/t/elasticsearch-deprecation-issues/325543)

<div class="topic-metadata">

**Author:** [@hermlam](https://discuss.elastic.co/u/hermlam)\
**Replies:** 5\
**Last updated:** [March 6, 2023, 11:20am UTC](https://discuss.elastic.co/t/elasticsearch-deprecation-issues/325543 "2023-03-06T11:20:40Z")

</div>

I can't upgrade to 8.6.1 due to a deprecation issue. I can't update the elasticsearch.yml, because I have a cloud solution. Problem: setting \[cluster.routing.allocation.disk.watermark.enable\_for\_single\_data\_node\] is dep…

---

## [Make a grok pattern for a field that might be missing](https://discuss.elastic.co/t/make-a-grok-pattern-for-a-field-that-might-be-missing/327014)

<div class="topic-metadata">

**Author:** [@ira-zaya](https://discuss.elastic.co/u/ira-zaya)\
**Replies:** 3\
**Last updated:** [March 6, 2023, 11:12am UTC](https://discuss.elastic.co/t/make-a-grok-pattern-for-a-field-that-might-be-missing/327014 "2023-03-06T11:12:38Z")

</div>

Hi! There are logs in the following format: 2023-03-05 17:07:01.586+0000 \[L: WARN\] \[O: A.b.c.d.e.FGScript\] \[I: \] \[U: email@example.com\] \[S: \] \[P: \] \[T: ABCProcessor-23 \] @@@ aboba=5 beboba=1 ceboba=4 So I have a correc…

---

## [Problem with PowerShell security rules that use process.args](https://discuss.elastic.co/t/problem-with-powershell-security-rules-that-use-process-args/326861)

<div class="topic-metadata">

**Author:** [@Maretti](https://discuss.elastic.co/u/Maretti)\
**Replies:** 2\
**Last updated:** [March 6, 2023, 9:58am UTC](https://discuss.elastic.co/t/problem-with-powershell-security-rules-that-use-process-args/326861 "2023-03-06T09:58:32Z")

</div>

The Problem Rules that are based off powershell like Disabling Windows Defender Security Settings via PowerShell and Windows Firewall Disabled via PowerShell are not giving alerts back. Windows Firewall Disabled via Pow…

---

## [Searching non-indexed fields](https://discuss.elastic.co/t/searching-non-indexed-fields/327033)

<div class="topic-metadata">

**Author:** [@kpachar](https://discuss.elastic.co/u/kpachar)\
**Replies:** 1\
**Last updated:** [March 6, 2023, 8:40am UTC](https://discuss.elastic.co/t/searching-non-indexed-fields/327033 "2023-03-06T08:40:00Z")

</div>

Hi everyone, Contrary to popular opinion, I'm able to search non-indexed fields in Elasticsearch. I'm wondering if this is is a bug or a newly introduced feature. I'm on Elasticsearch 8.6.2. The documentation says "Fie…

---

## [File Descriptors count](https://discuss.elastic.co/t/file-descriptors-count/327043)

<div class="topic-metadata">

**Author:** [@avnere](https://discuss.elastic.co/u/avnere)\
**Replies:** 0\
**Last updated:** [March 6, 2023, 8:15am UTC](https://discuss.elastic.co/t/file-descriptors-count/327043 "2023-03-06T08:15:17Z")

</div>

Hi, According to docs it is recommended to set File Descriptors to 65535 (ulimit -n). How it effect my node? What will be the behavior if I will set higher value? for instance: 500000 Thanks

---

## [How to measure time it takes from elasticsearch pod to elasticsearch?](https://discuss.elastic.co/t/how-to-measure-time-it-takes-from-elasticsearch-pod-to-elasticsearch/327035)

<div class="topic-metadata">

**Author:** [@Java2avaj](https://discuss.elastic.co/u/Java2avaj)\
**Replies:** 1\
**Last updated:** [March 6, 2023, 6:42am UTC](https://discuss.elastic.co/t/how-to-measure-time-it-takes-from-elasticsearch-pod-to-elasticsearch/327035 "2023-03-06T06:42:02Z")

</div>

We have a global search functionality that takes time to fetch data from Elasticsearch so we need to measure time it would take from elasticsearch pod to elasticsearch itself. Our technology uses java spring Elasticsearc…

---

## [Customization in line lens](https://discuss.elastic.co/t/customization-in-line-lens/327034)

<div class="topic-metadata">

**Author:** [@PappuSingh](https://discuss.elastic.co/u/PappuSingh)\
**Replies:** 0\
**Last updated:** [March 6, 2023, 6:22am UTC](https://discuss.elastic.co/t/customization-in-line-lens/327034 "2023-03-06T06:22:15Z")

</div>

Hi, Can we create Line lens as per the attached snap with color?

---

## [Deleting \_recovery\_source](https://discuss.elastic.co/t/deleting-recovery-source/327028)

<div class="topic-metadata">

**Author:** [@kpachar](https://discuss.elastic.co/u/kpachar)\
**Replies:** 0\
**Last updated:** [March 6, 2023, 5:32am UTC](https://discuss.elastic.co/t/deleting-recovery-source/327028 "2023-03-06T05:32:45Z")

</div>

Hi everyone, I'm on Elasticsearch 8.6.2. I wanted to reduce disk usage of my indices, and noticed that the \_recovery\_source takes up quite some space. I tried setting index.soft\_deletes.enabled to false, but index cr…

---

## [Rally 2.7.1](https://discuss.elastic.co/t/rally-2-7-1/326852)

<div class="topic-metadata">

**Author:** [@Quentin\_Pradet](https://discuss.elastic.co/u/Quentin_Pradet)\
**Replies:** 0\
**Last updated:** [March 2, 2023, 1:15pm UTC](https://discuss.elastic.co/t/rally-2-7-1/326852 "2023-03-02T13:15:50Z")

</div>

We have just released Rally 2.7.1. Highlights #1674: Allow reading metrics password from environment #1624: Skip building plugins moved to modules Enhancements #1654: Add role metadata to node-stats telemetry device #…

---

## [Endpoint Security 8.4.0/7.17.7 and Endgame 3.62.3 Security Update](https://discuss.elastic.co/t/endpoint-security-8-4-0-7-17-7-and-endgame-3-62-3-security-update/323754)

<div class="topic-metadata">

**Author:** [@ikakavas](https://discuss.elastic.co/u/ikakavas)\
**Replies:** 0\
**Last updated:** [January 23, 2023, 5:34pm UTC](https://discuss.elastic.co/t/endpoint-security-8-4-0-7-17-7-and-endgame-3-62-3-security-update/323754 "2023-01-23T17:34:10Z")

</div>

Elastic Endpoint Security Local Privilege Escalation issue (ESA-2022-13) An issue was discovered in the quarantine feature of Elastic Endpoint Security and Elastic Endgame for Windows, which could allow unprivileged use…

---

## [Endpoint Security 8.4.1 Security Update](https://discuss.elastic.co/t/endpoint-security-8-4-1-security-update/323753)

<div class="topic-metadata">

**Author:** [@ikakavas](https://discuss.elastic.co/u/ikakavas)\
**Replies:** 0\
**Last updated:** [January 23, 2023, 5:30pm UTC](https://discuss.elastic.co/t/endpoint-security-8-4-1-security-update/323753 "2023-01-23T17:30:33Z")

</div>

Elastic Endpoint Security Local Privilege Escalation issue (ESA-2022-14) An issue was discovered in the rollback feature of Elastic Endpoint Security for Windows, which could allow unprivileged users to elevate their pr…

---

## [Oportunidades abertas - NTT DATA Europe & LATAM](https://discuss.elastic.co/t/oportunidades-abertas-ntt-data-europe-latam/326868)

<div class="topic-metadata">

**Author:** [@ernandesjr](https://discuss.elastic.co/u/ernandesjr)\
**Replies:** 0\
**Last updated:** [March 2, 2023, 2:54pm UTC](https://discuss.elastic.co/t/oportunidades-abertas-ntt-data-europe-latam/326868 "2023-03-02T14:54:52Z")

</div>

Olá Elastic Community! Muito prazer a todos da comunidade, meu nome é Ernandes Franco Silveira, atualmente atuo como Gerente de Projetos na NTT DATA Europe & Latam e estou a procura de profissionais qualificados para im…

---

## [I need to create an elastic search cluster with one master and two data nodes](https://discuss.elastic.co/t/i-need-to-create-an-elastic-search-cluster-with-one-master-and-two-data-nodes/326929)

<div class="topic-metadata">

**Author:** [@Ram\_M](https://discuss.elastic.co/u/Ram_M)\
**Replies:** 0\
**Last updated:** [March 3, 2023, 10:53am UTC](https://discuss.elastic.co/t/i-need-to-create-an-elastic-search-cluster-with-one-master-and-two-data-nodes/326929 "2023-03-03T10:53:36Z")

</div>

So how can I deploy in one statefulset? or I need to deploy in separate statefulset for master and data plane and connect to it?

---

## [How to install Elastic stack (ELK) 8.6.2 in windows machine?](https://discuss.elastic.co/t/how-to-install-elastic-stack-elk-8-6-2-in-windows-machine/326933)

<div class="topic-metadata">

**Author:** [@sonu\_singh](https://discuss.elastic.co/u/sonu_singh)\
**Replies:** 1\
**Last updated:** [March 5, 2023, 10:58pm UTC](https://discuss.elastic.co/t/how-to-install-elastic-stack-elk-8-6-2-in-windows-machine/326933 "2023-03-05T22:58:16Z")

</div>

Hi there, I am trying to install Elastic stack (ELK 8.6.2) in windows machine and Elasticsearch is not getting up. No luck on finding the Installation steps/tutorials/blogs online for Elastic stack 8.6.2. Any suggesti…

---

## [Logstash: HTTP Poller Formatting Issue](https://discuss.elastic.co/t/logstash-http-poller-formatting-issue/326844)

<div class="topic-metadata">

**Author:** [@alaine](https://discuss.elastic.co/u/alaine)\
**Replies:** 4\
**Last updated:** [March 5, 2023, 10:53pm UTC](https://discuss.elastic.co/t/logstash-http-poller-formatting-issue/326844 "2023-03-05T22:53:08Z")

</div>

I am trying to use the HTTP poller to automate a curl command that I am able to run successfully in my environment. I am trying to run a query, put the results through a pipeline and then send the output to elasticsearch…

---

## [TLS Error in Logstash](https://discuss.elastic.co/t/tls-error-in-logstash/326962)

<div class="topic-metadata">

**Author:** [@sta02](https://discuss.elastic.co/u/sta02)\
**Replies:** 0\
**Last updated:** [March 3, 2023, 5:25pm UTC](https://discuss.elastic.co/t/tls-error-in-logstash/326962 "2023-03-03T17:25:53Z")

</div>

Hello, We are trying to send logs from an application hosted in kubernetes cluster to logstash via fluentd. The logs are sent in syslog over TCP on an encrypted channel with TLS configuration. At the logstash end we ar…

---

## [ELK Searches from Splunk](https://discuss.elastic.co/t/elk-searches-from-splunk/326887)

<div class="topic-metadata">

**Author:** [@juancamiloll](https://discuss.elastic.co/u/juancamiloll)\
**Replies:** 3\
**Last updated:** [March 5, 2023, 10:38pm UTC](https://discuss.elastic.co/t/elk-searches-from-splunk/326887 "2023-03-05T22:38:03Z")

</div>

Hello On a single server I have ELK(v 7.6.0) and Splunk. All sources that support syslog protocol are being ingested to ELK Taking advantage of some Splunk functionalities a query is made to ELK with this kind of code…

---

## [What's Python "best practice" for security certificates with ES8?](https://discuss.elastic.co/t/whats-python-best-practice-for-security-certificates-with-es8/327009)

<div class="topic-metadata">

**Author:** [@mrodent](https://discuss.elastic.co/u/mrodent)\
**Replies:** 1\
**Last updated:** [March 5, 2023, 4:17pm UTC](https://discuss.elastic.co/t/whats-python-best-practice-for-security-certificates-with-es8/327009 "2023-03-05T16:17:08Z")

</div>

I just set up ES 8.6.2 on my machine. This is a single-machine setup. In fact I'm upgrading from 7.10.2, see previous question. I've managed to obtain a password for user "elastic"... this means I can get the "You know,…

---

## [How to customise ICU Collation Keyword Field for sorting digits, symbols at last after the alphabets?](https://discuss.elastic.co/t/how-to-customise-icu-collation-keyword-field-for-sorting-digits-symbols-at-last-after-the-alphabets/327000)

<div class="topic-metadata">

**Author:** [@Karthik\_Amar](https://discuss.elastic.co/u/Karthik_Amar)\
**Replies:** 0\
**Last updated:** [March 5, 2023, 11:32am UTC](https://discuss.elastic.co/t/how-to-customise-icu-collation-keyword-field-for-sorting-digits-symbols-at-last-after-the-alphabets/327000 "2023-03-05T11:32:01Z")

</div>

The phonebook fields sort the symbols, currency and digits at the top grouped. Instead i want to give the alphabets (a-z) the most precedence and appears first in the sorting and all the above 3 below it. for example In…

---

## [Fleet Cloud Integrations on multiple agents](https://discuss.elastic.co/t/fleet-cloud-integrations-on-multiple-agents/326940)

<div class="topic-metadata">

**Author:** [@Derick\_Jansen](https://discuss.elastic.co/u/Derick_Jansen)\
**Replies:** 2\
**Last updated:** [March 5, 2023, 10:33am UTC](https://discuss.elastic.co/t/fleet-cloud-integrations-on-multiple-agents/326940 "2023-03-05T10:33:25Z")

</div>

Hi all. How does cloud integration work if you apply them to multiples agents. For example if I have two servers (for redundancy) dedicated to collecting logs from let's say Cloudflare (log pull) If I have both serve…

---

## [Run two versions of ES on machine](https://discuss.elastic.co/t/run-two-versions-of-es-on-machine/326985)

<div class="topic-metadata">

**Author:** [@mrodent](https://discuss.elastic.co/u/mrodent)\
**Replies:** 5\
**Last updated:** [March 5, 2023, 9:49am UTC](https://discuss.elastic.co/t/run-two-versions-of-es-on-machine/326985 "2023-03-05T09:49:51Z")

</div>

This is on a W10 box. ES (7.10.2) is currently running on localhost:9200. I need to upgrade. When I attempted to upgrade to 7.16.3 some time ago a regression occurred, reported by me and acknowledged by Elasticsearch HQ,…

---

## [Executing update by query for a array of arrays](https://discuss.elastic.co/t/executing-update-by-query-for-a-array-of-arrays/326993)

<div class="topic-metadata">

**Author:** [@otaviom\_30](https://discuss.elastic.co/u/otaviom_30)\
**Replies:** 0\
**Last updated:** [March 5, 2023, 4:30am UTC](https://discuss.elastic.co/t/executing-update-by-query-for-a-array-of-arrays/326993 "2023-03-05T04:30:27Z")

</div>

Hello! So, one of the metadata I have indexed is a array of arrays. But, I'm having problems when I try to execute a update by query on it. Here is the sintax I'm using: "source":"ctx.\_source.Exemple ='\[\['foobar','10',…

---

## [Kibana tag cloud does not count frequency of words in a text field](https://discuss.elastic.co/t/kibana-tag-cloud-does-not-count-frequency-of-words-in-a-text-field/326982)

<div class="topic-metadata">

**Author:** [@Mehran\_Goodarzi](https://discuss.elastic.co/u/Mehran_Goodarzi)\
**Replies:** 1\
**Last updated:** [March 5, 2023, 2:38am UTC](https://discuss.elastic.co/t/kibana-tag-cloud-does-not-count-frequency-of-words-in-a-text-field/326982 "2023-03-05T02:38:54Z")

</div>

Hi There, Kibana tag cloud does not count frequency of words in my text field let's say i have a field named : Ticket\_text.keyword and here are some examples: hello world here I am hello everybody this is blah in th…

---

## [Date/time field formatting from csv input](https://discuss.elastic.co/t/date-time-field-formatting-from-csv-input/326984)

<div class="topic-metadata">

**Author:** [@karlkras](https://discuss.elastic.co/u/karlkras)\
**Replies:** 2\
**Last updated:** [March 4, 2023, 9:19pm UTC](https://discuss.elastic.co/t/date-time-field-formatting-from-csv-input/326984 "2023-03-04T21:19:27Z")

</div>

Please excuse the ignorance of my question, I'm still trying get my arms around working with elk, not my forte. I'm generating a csv for a report that contains a few columns that refer to date/time stamps. During gener…

[Previous page](https://discuss.elastic.co/tag/none.md?no_tags=true&page=422)

[Next page](https://discuss.elastic.co/tag/none.md?no_tags=true&page=424)
