# \#none

**URL:** https://discuss.elastic.co/tag/none.md?no_tags=true&page=425

[Latest](https://discuss.elastic.co/latest.md) · [Categories](https://discuss.elastic.co/categories.md) · [Tags](https://discuss.elastic.co/tags.md)

**Page:** 426

---

## [Some questions on system.diskio latency metrics](https://discuss.elastic.co/t/some-questions-on-system-diskio-latency-metrics/326817)

<div class="topic-metadata">

**Author:** [@CatLoveFishma](https://discuss.elastic.co/u/CatLoveFishma)\
**Replies:** 3\
**Last updated:** [March 2, 2023, 7:00am UTC](https://discuss.elastic.co/t/some-questions-on-system-diskio-latency-metrics/326817 "2023-03-02T07:00:31Z")

</div>

Hello, I am trying to get a better understanding of the disk io metrics below. Included are the definitions for each per the Elastic documentation online. system.diskio.read.time - total number of milliseconds spent by…

---

## [Error when searching in a specific field](https://discuss.elastic.co/t/error-when-searching-in-a-specific-field/326734)

<div class="topic-metadata">

**Author:** [@Thoriqul\_Umar](https://discuss.elastic.co/u/Thoriqul_Umar)\
**Replies:** 4\
**Last updated:** [March 2, 2023, 4:14am UTC](https://discuss.elastic.co/t/error-when-searching-in-a-specific-field/326734 "2023-03-02T04:14:51Z")

</div>

hello, I got error "failed to connect to console's backed. please check the kibana server is up and running" when tried to search on field "file\_content". here is my query { "query": { "multi\_match": { "qu…

---

## [Elasticsearch Indexing Issues](https://discuss.elastic.co/t/elasticsearch-indexing-issues/326768)

<div class="topic-metadata">

**Author:** [@H-Soni](https://discuss.elastic.co/u/H-Soni)\
**Replies:** 1\
**Last updated:** [March 1, 2023, 11:54pm UTC](https://discuss.elastic.co/t/elasticsearch-indexing-issues/326768 "2023-03-01T23:54:56Z")

</div>

Hi, We have a 5-node cluster, currently running ES 5.6.11. When there's an increased load in indexing, heap usage reaches 90% in one of the nodes, while some have only 40-50% heap usage. Because of this, elasticsearch t…

---

## [Structured JSON logs via ElasticAgent Kubernetes Integration](https://discuss.elastic.co/t/structured-json-logs-via-elasticagent-kubernetes-integration/326809)

<div class="topic-metadata">

**Author:** [@metalp](https://discuss.elastic.co/u/metalp)\
**Replies:** 0\
**Last updated:** [March 1, 2023, 11:23pm UTC](https://discuss.elastic.co/t/structured-json-logs-via-elasticagent-kubernetes-integration/326809 "2023-03-01T23:23:59Z")

</div>

We're adopting Elastic stack to log our Kubernetes applications. We have installed ElasticAgent into our cluster via the Fleet managed manifest: https://raw.githubusercontent.com/elastic/elastic-agent/master/deploy/kub…

---

## [Get only the last record of an index in Kibana](https://discuss.elastic.co/t/get-only-the-last-record-of-an-index-in-kibana/326792)

<div class="topic-metadata">

**Author:** [@ismi2002](https://discuss.elastic.co/u/ismi2002)\
**Replies:** 2\
**Last updated:** [March 1, 2023, 10:06pm UTC](https://discuss.elastic.co/t/get-only-the-last-record-of-an-index-in-kibana/326792 "2023-03-01T22:06:28Z")

</div>

Hello everyone, I'm trying to do a visualization of "live events", therefore, I want to see only the last record inserted in an index in Kibana, can you help me with this? Thanks!

---

## [Problema al agregar certificado de empresa en kibana](https://discuss.elastic.co/t/problema-al-agregar-certificado-de-empresa-en-kibana/326807)

<div class="topic-metadata">

**Author:** [@DARWIN\_PEREZ](https://discuss.elastic.co/u/DARWIN_PEREZ)\
**Replies:** 0\
**Last updated:** [March 1, 2023, 9:46pm UTC](https://discuss.elastic.co/t/problema-al-agregar-certificado-de-empresa-en-kibana/326807 "2023-03-01T21:46:59Z")

</div>

Hola, me pueden apoyar, al momento de cambiar el certificado de confianza que entrega elastic, por una generado en una PKI , el servicio de kibana no arranca y sale el mensaje "El servidor Kibana aún no está listo."

---

## [Problema al agregar certificado de empresa en Elasticsearch Centos 7](https://discuss.elastic.co/t/problema-al-agregar-certificado-de-empresa-en-elasticsearch-centos-7/326806)

<div class="topic-metadata">

**Author:** [@DARWIN\_PEREZ](https://discuss.elastic.co/u/DARWIN_PEREZ)\
**Replies:** 1\
**Last updated:** [March 1, 2023, 9:40pm UTC](https://discuss.elastic.co/t/problema-al-agregar-certificado-de-empresa-en-elasticsearch-centos-7/326806 "2023-03-01T21:40:24Z")

</div>

kibana server is not ready yet

---

## [Logstash isn't sending data to elastic](https://discuss.elastic.co/t/logstash-isnt-sending-data-to-elastic/326686)

<div class="topic-metadata">

**Author:** [@Uzzi](https://discuss.elastic.co/u/Uzzi)\
**Replies:** 8\
**Last updated:** [March 1, 2023, 6:34pm UTC](https://discuss.elastic.co/t/logstash-isnt-sending-data-to-elastic/326686 "2023-03-01T18:34:18Z")

</div>

Hi, I've 1 vmq for Kibana+elasticsearch and 1 vm for Logstash. Logstash isn't sending data to elastic, this is log: \[DEBUG\]\[logstash.instrument.periodicpoller.cgroup\] One or more required cgroup files or directories no…

---

## [New Dark theme!](https://discuss.elastic.co/t/new-dark-theme/326634)

<div class="topic-metadata">

**Author:** [@warkolm](https://discuss.elastic.co/u/warkolm)\
**Replies:** 1\
**Last updated:** [March 1, 2023, 5:00pm UTC](https://discuss.elastic.co/t/new-dark-theme/326634 "2023-03-01T17:00:54Z")

</div>

We've enabled a new dark theme here thanks to the super awesome team at Discourse! Currently it is set to automatic, meaning the theme will change with your system settings, and you can change this; Click your profile…

---

## [I cannot update template](https://discuss.elastic.co/t/i-cannot-update-template/326775)

<div class="topic-metadata">

**Author:** [@rachelyang](https://discuss.elastic.co/u/rachelyang)\
**Replies:** 1\
**Last updated:** [March 1, 2023, 4:33pm UTC](https://discuss.elastic.co/t/i-cannot-update-template/326775 "2023-03-01T16:33:40Z")

</div>

I updated the template of filebeat in the elasticsearch node. It returned me an error: { "error": { "root\_cause": \[ { "type": "mapper\_parsing\_exception", "reason": "Root mapping definition has unsupported …

---

## [Groke parse failure on Haproxy logs while debugger is OK](https://discuss.elastic.co/t/groke-parse-failure-on-haproxy-logs-while-debugger-is-ok/326779)

<div class="topic-metadata">

**Author:** [@Bastien\_Bsc](https://discuss.elastic.co/u/Bastien_Bsc)\
**Replies:** 1\
**Last updated:** [March 1, 2023, 4:29pm UTC](https://discuss.elastic.co/t/groke-parse-failure-on-haproxy-logs-while-debugger-is-ok/326779 "2023-03-01T16:29:42Z")

</div>

Hello, I have a weird situation where the data is correctly parsed, grok debugger doesn't return errors. But logstash still adds a grokeparse\_failure tag. Here is an exemple log (in /var/log/haproxy.log) : Mar 1 15:4…

---

## [Rollover Errors](https://discuss.elastic.co/t/rollover-errors/325272)

<div class="topic-metadata">

**Author:** [@MKirby](https://discuss.elastic.co/u/MKirby)\
**Replies:** 2\
**Last updated:** [March 1, 2023, 4:23pm UTC](https://discuss.elastic.co/t/rollover-errors/325272 "2023-03-01T16:23:34Z")

</div>

Hello I have been working on some code to be able to rollover my syslogs so that it will continue to populate the Kibana. I am getting the following error in the Dev Tools Illegal argument exception rollover target is…

---

## [Elastic Crawler Debugging](https://discuss.elastic.co/t/elastic-crawler-debugging/326628)

<div class="topic-metadata">

**Author:** [@alongaks](https://discuss.elastic.co/u/alongaks)\
**Replies:** 7\
**Last updated:** [March 1, 2023, 1:01pm UTC](https://discuss.elastic.co/t/elastic-crawler-debugging/326628 "2023-03-01T13:01:58Z")

</div>

Hello, I am looking for info if it is possible for the Elastic Crawler ( cloud deployment ) to enable a debug log, just for a crawl job. I am hitting 599 timeout errors during a crawl, and once this occurs the crawl is…

---

## [Kibana generating false Recovery Monitor UP documents for offline monitors](https://discuss.elastic.co/t/kibana-generating-false-recovery-monitor-up-documents-for-offline-monitors/326566)

<div class="topic-metadata">

**Author:** [@Adriann](https://discuss.elastic.co/u/Adriann)\
**Replies:** 4\
**Last updated:** [March 1, 2023, 11:08am UTC](https://discuss.elastic.co/t/kibana-generating-false-recovery-monitor-up-documents-for-offline-monitors/326566 "2023-03-01T11:08:30Z")

</div>

Hi everyone, I'm experiencing an issue with Kibana generating false Recovery Monitor UP documents for monitors that have been offline for a long time. Specifically, when a host is monitored using heartbeat and is offlin…

---

## [Logstash how to mutate string of float array to denseVector](https://discuss.elastic.co/t/logstash-how-to-mutate-string-of-float-array-to-densevector/326750)

<div class="topic-metadata">

**Author:** [@wensi](https://discuss.elastic.co/u/wensi)\
**Replies:** 1\
**Last updated:** [March 1, 2023, 11:03am UTC](https://discuss.elastic.co/t/logstash-how-to-mutate-string-of-float-array-to-densevector/326750 "2023-03-01T11:03:50Z")

</div>

I am using Logstash to transfer data from MySQL to ES, one column in MySQL is \`vec\` text NOT NULL vec has value like \[0.1, 0.2, 0.3\] and is of string type. How to convert string of float array to ES dense\_vector? I tr…

---

## [Subtraction between current date and doc created date](https://discuss.elastic.co/t/subtraction-between-current-date-and-doc-created-date/326405)

<div class="topic-metadata">

**Author:** [@PappuSingh](https://discuss.elastic.co/u/PappuSingh)\
**Replies:** 4\
**Last updated:** [March 1, 2023, 10:54am UTC](https://discuss.elastic.co/t/subtraction-between-current-date-and-doc-created-date/326405 "2023-03-01T10:54:44Z")

</div>

Hi, Please see the below code sample. long l1=(new Date().getTime()); //emit(l1); long l= ChronoUnit.SECONDS.between(l1, doc\['timestamp'\].value); if(l\<=100000){ emit('New') } else{emit('Old')} I am getting the b…

---

## [Autodetect\_column\_names in condition](https://discuss.elastic.co/t/autodetect-column-names-in-condition/326439)

<div class="topic-metadata">

**Author:** [@INS](https://discuss.elastic.co/u/INS)\
**Replies:** 6\
**Last updated:** [March 1, 2023, 10:36am UTC](https://discuss.elastic.co/t/autodetect-column-names-in-condition/326439 "2023-03-01T10:36:45Z")

</div>

Hi Maybe You have idea why in this case autodetect\_column\_names doesn't work as independent. input: "CLLI","SWREL","RPTDATE","RPTIME","TZ","RPTTYPE","RPTPD","IVALDATE","IVALSTART","IVALEND","NUMENTIDS" "wifi06","EAGL…

---

## [Failure to parce query](https://discuss.elastic.co/t/failure-to-parce-query/326699)

<div class="topic-metadata">

**Author:** [@mikes1962](https://discuss.elastic.co/u/mikes1962)\
**Replies:** 1\
**Last updated:** [March 1, 2023, 10:27am UTC](https://discuss.elastic.co/t/failure-to-parce-query/326699 "2023-03-01T10:27:32Z")

</div>

I'm very new to elasticsearch so please forgive me if this is a stupid question. I'm writing python code to read data from the stack but from time to time I get a message like this: Exception: Invalid Query: \[erm/d-2Cll…

---

## [Output stdout does not print to shell when given info log level](https://discuss.elastic.co/t/output-stdout-does-not-print-to-shell-when-given-info-log-level/326392)

<div class="topic-metadata">

**Author:** [@wensi](https://discuss.elastic.co/u/wensi)\
**Replies:** 1\
**Last updated:** [March 1, 2023, 9:47am UTC](https://discuss.elastic.co/t/output-stdout-does-not-print-to-shell-when-given-info-log-level/326392 "2023-03-01T09:47:19Z")

</div>

The following script reads from mysql through jdbc plugin, and output every item through stdout. However, by running logstash -f mysql2es.conf， it does not print anything. Then I added --debug, I can see entities jdbc re…

---

## [Synthetics Playwright version](https://discuss.elastic.co/t/synthetics-playwright-version/324987)

<div class="topic-metadata">

**Author:** [@jasonwhetton](https://discuss.elastic.co/u/jasonwhetton)\
**Replies:** 12\
**Last updated:** [March 1, 2023, 6:54am UTC](https://discuss.elastic.co/t/synthetics-playwright-version/324987 "2023-03-01T06:54:09Z")

</div>

Hi, I'm trying to migrate some playwright tests to elastic synthetics and getting issues running the newer playwright methods e.g. getByRole. These are recognised when I run locally but not when I push to the server. Wha…

---

## [ELASTICSEARCH\_17 - Could not index '1' records: listener timeout after waiting for \[30000\] ms](https://discuss.elastic.co/t/elasticsearch-17-could-not-index-1-records-listener-timeout-after-waiting-for-30000-ms/326688)

<div class="topic-metadata">

**Author:** [@senix](https://discuss.elastic.co/u/senix)\
**Replies:** 5\
**Last updated:** [March 1, 2023, 6:32am UTC](https://discuss.elastic.co/t/elasticsearch-17-could-not-index-1-records-listener-timeout-after-waiting-for-30000-ms/326688 "2023-03-01T06:32:05Z")

</div>

We're using streamsets to send messages to Elasticsearch and are consistently getting the following error: ELASTICSEARCH\_17 - Could not index '1' records: listener timeout after waiting for \[30000\] ms We've tried vario…

---

## [Run Logstash manually without interrupting logstash service and logstash Scheduler](https://discuss.elastic.co/t/run-logstash-manually-without-interrupting-logstash-service-and-logstash-scheduler/326036)

<div class="topic-metadata">

**Author:** [@Rakhshunda\_Noorein\_J](https://discuss.elastic.co/u/Rakhshunda_Noorein_J)\
**Replies:** 8\
**Last updated:** [March 1, 2023, 6:25am UTC](https://discuss.elastic.co/t/run-logstash-manually-without-interrupting-logstash-service-and-logstash-scheduler/326036 "2023-03-01T06:25:43Z")

</div>

Hello, I have a configuration file with http\_poller plugins, where I have some scheduler which on the given schedule pull the data and enter it into my elastic db. But to manually run lagstash instantly, What I have to…

---

## [Improving resiliency or changing settings of system indices](https://discuss.elastic.co/t/improving-resiliency-or-changing-settings-of-system-indices/326108)

<div class="topic-metadata">

**Author:** [@garethhumphriesgkc](https://discuss.elastic.co/u/garethhumphriesgkc)\
**Replies:** 3\
**Last updated:** [March 1, 2023, 1:45am UTC](https://discuss.elastic.co/t/improving-resiliency-or-changing-settings-of-system-indices/326108 "2023-03-01T01:45:22Z")

</div>

Hi, I'm trying to improve the resiliency of my elastic stack. I want to make it tolerant to any two node failures, but I can't update system indices to have more than one replica. The setting in question is index.auto…

---

## [Search all indexes for document's parameter name or retrieve one document p/index](https://discuss.elastic.co/t/search-all-indexes-for-documents-parameter-name-or-retrieve-one-document-p-index/325175)

<div class="topic-metadata">

**Author:** [@brunofl](https://discuss.elastic.co/u/brunofl)\
**Replies:** 5\
**Last updated:** [February 28, 2023, 10:48pm UTC](https://discuss.elastic.co/t/search-all-indexes-for-documents-parameter-name-or-retrieve-one-document-p-index/325175 "2023-02-28T22:48:31Z")

</div>

Hi I am a bit new in elastic and started in a project that has more than 800 indexes and I need to rename some old names to the new ones requested. I already found some indexes that has parameters with values that need …

---

## [Logstash Netflow Codec Plugin - "unsupported enterprise" error with IPFIX template](https://discuss.elastic.co/t/logstash-netflow-codec-plugin-unsupported-enterprise-error-with-ipfix-template/326701)

<div class="topic-metadata">

**Author:** [@nosql\_injection](https://discuss.elastic.co/u/nosql_injection)\
**Replies:** 0\
**Last updated:** [February 28, 2023, 6:29pm UTC](https://discuss.elastic.co/t/logstash-netflow-codec-plugin-unsupported-enterprise-error-with-ipfix-template/326701 "2023-02-28T18:29:29Z")

</div>

Hi there, when trying to ingest IPFIX, we get the Can't (yet) decode flowset id 317 from observation domain id 6422528, because no template to decode it with has been received. This message will usually go away after …

---

## [Changing index settings when closed can corrupt an index](https://discuss.elastic.co/t/changing-index-settings-when-closed-can-corrupt-an-index/326705)

<div class="topic-metadata">

**Author:** [@dwilches](https://discuss.elastic.co/u/dwilches)\
**Replies:** 2\
**Last updated:** [February 28, 2023, 8:13pm UTC](https://discuss.elastic.co/t/changing-index-settings-when-closed-can-corrupt-an-index/326705 "2023-02-28T20:13:07Z")

</div>

I found a warning in this documentation page about updating index settings while they are closed: Changing static or dynamic index settings on a closed index could result in incorrect settings that are impossible to re…

---

## [Using aggregate to add modsecurity data to previous event](https://discuss.elastic.co/t/using-aggregate-to-add-modsecurity-data-to-previous-event/326423)

<div class="topic-metadata">

**Author:** [@admin\_berlin](https://discuss.elastic.co/u/admin_berlin)\
**Replies:** 3\
**Last updated:** [February 28, 2023, 7:33pm UTC](https://discuss.elastic.co/t/using-aggregate-to-add-modsecurity-data-to-previous-event/326423 "2023-02-28T19:33:13Z")

</div>

Hi, I have a modsec logfile that looks like this: --8afa774c-A-- \[24/Feb/2023:04:34:53 +0100\] Y-WoWiTsAtEsT123 12.139.152.111 14327 10.29.14.193 8080 --8afa774c-B-- POST /its/a/test/dude HTTP/1.1 Host: www.my-site.de Co…

---

## [Elastic agent transfer via logstahsh with incomplete logs](https://discuss.elastic.co/t/elastic-agent-transfer-via-logstahsh-with-incomplete-logs/326482)

<div class="topic-metadata">

**Author:** [@xqaiviwjxzw](https://discuss.elastic.co/u/xqaiviwjxzw)\
**Replies:** 3\
**Last updated:** [February 28, 2023, 4:08pm UTC](https://discuss.elastic.co/t/elastic-agent-transfer-via-logstahsh-with-incomplete-logs/326482 "2023-02-28T16:08:05Z")

</div>

1.elastic agent transfer via logstahsh, endpoint shows healthy but logs are not coming in, what is the reason? Is there any solution for this? The endpoint is viewed locally with the following result? 2.elastic agen…

---

## [Query not executing in Elasticsearch input plugin for logstash](https://discuss.elastic.co/t/query-not-executing-in-elasticsearch-input-plugin-for-logstash/326362)

<div class="topic-metadata">

**Author:** [@aelam](https://discuss.elastic.co/u/aelam)\
**Replies:** 6\
**Last updated:** [February 28, 2023, 3:55pm UTC](https://discuss.elastic.co/t/query-not-executing-in-elasticsearch-input-plugin-for-logstash/326362 "2023-02-28T15:55:15Z")

</div>

I'm new to the stack, and am trying to execute simple queries in logstash via the elasticsearch input plugin. I have worked through some initial errors and now have only a couple of notable warnings, but am not getting a…

---

## [Kibana is going slow](https://discuss.elastic.co/t/kibana-is-going-slow/326172)

<div class="topic-metadata">

**Author:** [@jdbcplusnet](https://discuss.elastic.co/u/jdbcplusnet)\
**Replies:** 11\
**Last updated:** [February 28, 2023, 3:27pm UTC](https://discuss.elastic.co/t/kibana-is-going-slow/326172 "2023-02-28T15:27:27Z")

</div>

Hi all We have some performance issues with Kibana and Elasticsearch. Both Elasticsearch and Kibana are 6.8.7 version. We have Elasticsearch Cluster with 3 nodes, one master and two slaves, 8GB for each node. We have …

[Previous page](https://discuss.elastic.co/tag/none.md?no_tags=true&page=424)

[Next page](https://discuss.elastic.co/tag/none.md?no_tags=true&page=426)
