# \#none

**URL:** https://discuss.elastic.co/tag/none.md?no_tags=true&page=430

[Latest](https://discuss.elastic.co/latest.md) · [Categories](https://discuss.elastic.co/categories.md) · [Tags](https://discuss.elastic.co/tags.md)

**Page:** 431

---

## [Can you query AD with Elastic to see Last Logon time?](https://discuss.elastic.co/t/can-you-query-ad-with-elastic-to-see-last-logon-time/326230)

<div class="topic-metadata">

**Author:** [@Mahigs](https://discuss.elastic.co/u/Mahigs)\
**Replies:** 1\
**Last updated:** [February 22, 2023, 9:58pm UTC](https://discuss.elastic.co/t/can-you-query-ad-with-elastic-to-see-last-logon-time/326230 "2023-02-22T21:58:30Z")

</div>

Relatively new to Elastic and all that it can do. Our team is trying to query Active Directory with Elastic so that we can view user's last logon time. We're trying to satisfy DoD requirements relating to accounts needin…

---

## [Deploying elastic agent container in kubernetes: error retrieving resource lock](https://discuss.elastic.co/t/deploying-elastic-agent-container-in-kubernetes-error-retrieving-resource-lock/326227)

<div class="topic-metadata">

**Author:** [@jmyns](https://discuss.elastic.co/u/jmyns)\
**Replies:** 0\
**Last updated:** [February 22, 2023, 9:22pm UTC](https://discuss.elastic.co/t/deploying-elastic-agent-container-in-kubernetes-error-retrieving-resource-lock/326227 "2023-02-22T21:22:24Z")

</div>

When I deploy an elastic agent image I see this repeated error in the container logs. error retrieving resource lock default/elastic-agent-cluster-leader: leases.coordination.k8s.io "elastic-agent-cluster-leader" is for…

---

## [Load different formats of data under the same index name](https://discuss.elastic.co/t/load-different-formats-of-data-under-the-same-index-name/326131)

<div class="topic-metadata">

**Author:** [@Raj4](https://discuss.elastic.co/u/Raj4)\
**Replies:** 1\
**Last updated:** [February 22, 2023, 9:16pm UTC](https://discuss.elastic.co/t/load-different-formats-of-data-under-the-same-index-name/326131 "2023-02-22T21:16:08Z")

</div>

Hello All, Is it possible to load different formats of data (from different sources) under the same index name in Elasticsearch? If yes, how can we do and what are the pros and cons. Please advise

---

## [Create time series index from non-time series index](https://discuss.elastic.co/t/create-time-series-index-from-non-time-series-index/326221)

<div class="topic-metadata">

**Author:** [@butchkelley](https://discuss.elastic.co/u/butchkelley)\
**Replies:** 1\
**Last updated:** [February 22, 2023, 8:25pm UTC](https://discuss.elastic.co/t/create-time-series-index-from-non-time-series-index/326221 "2023-02-22T20:25:08Z")

</div>

Hello, I have a non-time series index that is updated on occasion however the data is typically very static. I would like to create a time series index from this data so I can track when it changes. I thought I could …

---

## [Unable to restart Kibana after configuring CSV max size](https://discuss.elastic.co/t/unable-to-restart-kibana-after-configuring-csv-max-size/325494)

<div class="topic-metadata">

**Author:** [@maskrider1111](https://discuss.elastic.co/u/maskrider1111)\
**Replies:** 1\
**Last updated:** [February 22, 2023, 5:49pm UTC](https://discuss.elastic.co/t/unable-to-restart-kibana-after-configuring-csv-max-size/325494 "2023-02-22T17:49:52Z")

</div>

Hey guys, My Kibana failed to restart after i changed the CSV setting "maxSizeBytes" in kibana.yml. Its working well if i reverted back the settings. Please advise

---

## [Logstash logs filling up disk. How to configure log4j?](https://discuss.elastic.co/t/logstash-logs-filling-up-disk-how-to-configure-log4j/326207)

<div class="topic-metadata">

**Author:** [@Thijsvdp](https://discuss.elastic.co/u/Thijsvdp)\
**Replies:** 0\
**Last updated:** [February 22, 2023, 5:29pm UTC](https://discuss.elastic.co/t/logstash-logs-filling-up-disk-how-to-configure-log4j/326207 "2023-02-22T17:29:13Z")

</div>

Hi all, We are currently facing an issue where Logstash fills up disk space on some of the nodes on our K8s cluster by outputting entire events to stdout. I am aware that I can change the loglevel of Logstash as a whole…

---

## [Very big time gap when use wildcard field on one word search](https://discuss.elastic.co/t/very-big-time-gap-when-use-wildcard-field-on-one-word-search/325947)

<div class="topic-metadata">

**Author:** [@913043599](https://discuss.elastic.co/u/913043599)\
**Replies:** 3\
**Last updated:** [February 22, 2023, 3:48pm UTC](https://discuss.elastic.co/t/very-big-time-gap-when-use-wildcard-field-on-one-word-search/325947 "2023-02-22T15:48:19Z")

</div>

Hi, When I used the new field type - wildcard field - for some queries, I found that different query inputs had a significant time difference, even though the input length was always one character: You can see ther…

---

## [Error Events with "\>"](https://discuss.elastic.co/t/error-events-with/326192)

<div class="topic-metadata">

**Author:** [@akrog79](https://discuss.elastic.co/u/akrog79)\
**Replies:** 1\
**Last updated:** [February 22, 2023, 3:43pm UTC](https://discuss.elastic.co/t/error-events-with/326192 "2023-02-22T15:43:21Z")

</div>

Hello people! I have a trouble with the ingestion of a anomaly events in fortigate. The raw event is: \<185\>logver=702032456 timestamp=1676305141 devname="FG200-E" devid="FG200ETK189243" vd="root" date=2023-02-13 time=…

---

## [Custom integration](https://discuss.elastic.co/t/custom-integration/324819)

<div class="topic-metadata">

**Author:** [@adrien\_moreau](https://discuss.elastic.co/u/adrien_moreau)\
**Replies:** 2\
**Last updated:** [February 22, 2023, 3:30pm UTC](https://discuss.elastic.co/t/custom-integration/324819 "2023-02-22T15:30:04Z")

</div>

Hi, I would like to build my own custom elastic integration for a self managed elk. I read documentation here: https://www.elastic.co/guide/en/integrations-developer I would like to know if the only way to use that in…

---

## [Question about KEMP LoadManager](https://discuss.elastic.co/t/question-about-kemp-loadmanager/326188)

<div class="topic-metadata">

**Author:** [@MKirby](https://discuss.elastic.co/u/MKirby)\
**Replies:** 1\
**Last updated:** [February 22, 2023, 3:02pm UTC](https://discuss.elastic.co/t/question-about-kemp-loadmanager/326188 "2023-02-22T15:02:27Z")

</div>

In my home lab i am testing the collection of syslog from a Kemp LoadManager. Has anyone every worked with this product to ingest or have the syslogs captured? I was able to find the folowing page and have gone throug…

---

## [Joins across heterogenous documents in an index](https://discuss.elastic.co/t/joins-across-heterogenous-documents-in-an-index/325536)

<div class="topic-metadata">

**Author:** [@kembhootha](https://discuss.elastic.co/u/kembhootha)\
**Replies:** 1\
**Last updated:** [February 22, 2023, 2:58pm UTC](https://discuss.elastic.co/t/joins-across-heterogenous-documents-in-an-index/325536 "2023-02-22T14:58:35Z")

</div>

Newbie to ES. I have heterogenous documents being thrown into the same index in ES . Some example documents ( 8 typical documents that would be in the index ) {"actor\_id":1, "actor\_name":"Adam Sandler"} {"actor\_id":2,…

---

## [Implement elastic agent to collect postgresql log](https://discuss.elastic.co/t/implement-elastic-agent-to-collect-postgresql-log/326189)

<div class="topic-metadata">

**Author:** [@bagafoot](https://discuss.elastic.co/u/bagafoot)\
**Replies:** 0\
**Last updated:** [February 22, 2023, 2:47pm UTC](https://discuss.elastic.co/t/implement-elastic-agent-to-collect-postgresql-log/326189 "2023-02-22T14:47:50Z")

</div>

Hello all, I recently install elastic agent in postgresql server, I follow steps that in integration scope "add postgresql" in kibana user interface, download the yaml file and copy to postgresql server agent home dir …

---

## [How to maintain the JSON sequence in the response from Elasctic, currently ordering is getting changed](https://discuss.elastic.co/t/how-to-maintain-the-json-sequence-in-the-response-from-elasctic-currently-ordering-is-getting-changed/326168)

<div class="topic-metadata">

**Author:** [@Shraddha29](https://discuss.elastic.co/u/Shraddha29)\
**Replies:** 1\
**Last updated:** [February 22, 2023, 2:08pm UTC](https://discuss.elastic.co/t/how-to-maintain-the-json-sequence-in-the-response-from-elasctic-currently-ordering-is-getting-changed/326168 "2023-02-22T14:08:33Z")

</div>

How to maintain the JSON sequence in the response from Elastic, currently ordering is getting changed to what was inserted.

---

## [Transporterror 429 for search & bulk operations](https://discuss.elastic.co/t/transporterror-429-for-search-bulk-operations/326180)

<div class="topic-metadata">

**Author:** [@abhaygc](https://discuss.elastic.co/u/abhaygc)\
**Replies:** 4\
**Last updated:** [February 22, 2023, 1:55pm UTC](https://discuss.elastic.co/t/transporterror-429-for-search-bulk-operations/326180 "2023-02-22T13:55:02Z")

</div>

I am getting elasticsearch.exceptions.TransportError: TransportError(429, '429 Too Many Requests for my "\_search" & "\_bulk" operations. My cluster health is green. I have monitored threadpool write & search queues. Nu…

---

## [App Search Fundamentals](https://discuss.elastic.co/t/app-search-fundamentals/325631)

<div class="topic-metadata">

**Author:** [@lonpm2](https://discuss.elastic.co/u/lonpm2)\
**Replies:** 1\
**Last updated:** [February 22, 2023, 1:30pm UTC](https://discuss.elastic.co/t/app-search-fundamentals/325631 "2023-02-22T13:30:33Z")

</div>

Course: Version: Question: In the App Search Fundamentals guidance, following the curation guidance it asks me to return to the engine menu and look at the resulting suggestion. Click on the eye to open it... Howev…

---

## [Stuck on Observability Lab 2.2](https://discuss.elastic.co/t/stuck-on-observability-lab-2-2/325767)

<div class="topic-metadata">

**Author:** [@katie.ainscough](https://discuss.elastic.co/u/katie.ainscough)\
**Replies:** 1\
**Last updated:** [February 22, 2023, 1:20pm UTC](https://discuss.elastic.co/t/stuck-on-observability-lab-2-2/325767 "2023-02-22T13:20:06Z")

</div>

Course: Elastic Observability Version: 7.9.2 Question: Petclinic-client isn't displaying on Kibana, Discover, Metricbeat-\* Index? Have repeated the lab multiple times to check for errors I made and I still cant get th…

---

## [Rabbitmq output plugin with 'x-delayed-message' exchange](https://discuss.elastic.co/t/rabbitmq-output-plugin-with-x-delayed-message-exchange/326182)

<div class="topic-metadata">

**Author:** [@yilmazbuhar](https://discuss.elastic.co/u/yilmazbuhar)\
**Replies:** 0\
**Last updated:** [February 22, 2023, 1:04pm UTC](https://discuss.elastic.co/t/rabbitmq-output-plugin-with-x-delayed-message-exchange/326182 "2023-02-22T13:04:07Z")

</div>

Hi all, Can i send a message to "x-delayed-message" exchange with logstash. When i try this, getting error like this output { rabbitmq { # This setting must be a \["fanout", "direct", "topic", "x-consistent-…

---

## [Synthetics push command issues](https://discuss.elastic.co/t/synthetics-push-command-issues/325650)

<div class="topic-metadata">

**Author:** [@BenB196](https://discuss.elastic.co/u/BenB196)\
**Replies:** 5\
**Last updated:** [February 22, 2023, 11:53am UTC](https://discuss.elastic.co/t/synthetics-push-command-issues/325650 "2023-02-22T11:53:21Z")

</div>

Hi All, I'm testing out the npx @elastic/synthetics push command, but I'm running into a few issues, and was wondering if anyone has any ideas on how to fix them. Push command doesn't respect NodeJS TLS settings. I h…

---

## [Logstash setup on Azure kubernetes services](https://discuss.elastic.co/t/logstash-setup-on-azure-kubernetes-services/326159)

<div class="topic-metadata">

**Author:** [@vijay78](https://discuss.elastic.co/u/vijay78)\
**Replies:** 0\
**Last updated:** [February 22, 2023, 10:38am UTC](https://discuss.elastic.co/t/logstash-setup-on-azure-kubernetes-services/326159 "2023-02-22T10:38:13Z")

</div>

i am running Elasticsearch and kibana as container on azure kubernetes services iam able to run as expected both Elasticsearch and kibana and load some sample logs from a file Now iam trying to load kubernetes sample lo…

---

## [Cant convert timestamp field from text to date](https://discuss.elastic.co/t/cant-convert-timestamp-field-from-text-to-date/326158)

<div class="topic-metadata">

**Author:** [@Dor\_Steinberg](https://discuss.elastic.co/u/Dor_Steinberg)\
**Replies:** 0\
**Last updated:** [February 22, 2023, 10:36am UTC](https://discuss.elastic.co/t/cant-convert-timestamp-field-from-text-to-date/326158 "2023-02-22T10:36:30Z")

</div>

hello everyone, i got problem converting log.timestamp field from text to date someone can help me understand what am i doing wrong? i also will appreciate if do you have an idea of getting the day of the week from th…

---

## [Index pattern not creating](https://discuss.elastic.co/t/index-pattern-not-creating/326126)

<div class="topic-metadata">

**Author:** [@akhilkv43](https://discuss.elastic.co/u/akhilkv43)\
**Replies:** 2\
**Last updated:** [February 22, 2023, 9:54am UTC](https://discuss.elastic.co/t/index-pattern-not-creating/326126 "2023-02-22T09:54:30Z")

</div>

In Elasticsearch yml i have provided the code to create index pattern named production When opening kibana its not reflecting. here is the code i ahve injected in elasticsearch action.auto\_create\_index: .monitoring\*,.…

---

## [Synthetic integration](https://discuss.elastic.co/t/synthetic-integration/325754)

<div class="topic-metadata">

**Author:** [@kumar\_v](https://discuss.elastic.co/u/kumar_v)\
**Replies:** 1\
**Last updated:** [February 22, 2023, 9:50am UTC](https://discuss.elastic.co/t/synthetic-integration/325754 "2023-02-22T09:50:16Z")

</div>

I have done synthetic integration with the elastic agent running in web servers. Set alerts about the ping response and tls certificates expiry dates. As the certs was approaching the expiry, updated the certs in the loa…

---

## [Weired behaviour of fuzziness in elasticsearch](https://discuss.elastic.co/t/weired-behaviour-of-fuzziness-in-elasticsearch/326058)

<div class="topic-metadata">

**Author:** [@alliswell](https://discuss.elastic.co/u/alliswell)\
**Replies:** 2\
**Last updated:** [February 22, 2023, 9:10am UTC](https://discuss.elastic.co/t/weired-behaviour-of-fuzziness-in-elasticsearch/326058 "2023-02-22T09:10:14Z")

</div>

I have following document in my\_index: { "title": "weiß", "id": 1 } Consider the following query: GET my\_index/\_search?explain=true { "\_source": \["title"\], "query": { "bool": { "must": \[ { …

---

## [Https communication not secured for elasticsearch](https://discuss.elastic.co/t/https-communication-not-secured-for-elasticsearch/326026)

<div class="topic-metadata">

**Author:** [@akhilkv43](https://discuss.elastic.co/u/akhilkv43)\
**Replies:** 3\
**Last updated:** [February 22, 2023, 5:59am UTC](https://discuss.elastic.co/t/https-communication-not-secured-for-elasticsearch/326026 "2023-02-22T05:59:21Z")

</div>

I am using single node version is 8.5.3 Getting" Your connection to this site is not secured". I used cert and key in yml file Attaching the yml file can anybody advise on installation ======================== Elas…

---

## [Need help for installing Elastic-search, filebeat, logstash, metricbeat and kibana via helm using 8.5.1](https://discuss.elastic.co/t/need-help-for-installing-elastic-search-filebeat-logstash-metricbeat-and-kibana-via-helm-using-8-5-1/325994)

<div class="topic-metadata">

**Author:** [@Ram\_M](https://discuss.elastic.co/u/Ram_M)\
**Replies:** 11\
**Last updated:** [February 22, 2023, 4:43am UTC](https://discuss.elastic.co/t/need-help-for-installing-elastic-search-filebeat-logstash-metricbeat-and-kibana-via-helm-using-8-5-1/325994 "2023-02-22T04:43:25Z")

</div>

Hi all... I've using the helm chart for Elastic -search, Filebeat, Logstash and Kibana. Version is 8.5.1 environment in kubernetes AKS. Issue is Logstash not recognize the elastic-search. I need proper installation gui…

---

## [Using synonym\_graph means non-synonyms are not found](https://discuss.elastic.co/t/using-synonym-graph-means-non-synonyms-are-not-found/326022)

<div class="topic-metadata">

**Author:** [@Jonathan\_Mugan](https://discuss.elastic.co/u/Jonathan_Mugan)\
**Replies:** 8\
**Last updated:** [February 22, 2023, 4:20am UTC](https://discuss.elastic.co/t/using-synonym-graph-means-non-synonyms-are-not-found/326022 "2023-02-22T04:20:43Z")

</div>

Hi, I have this analyzer settings = { "analysis": { "analyzer": { "gale\_analyzer": { "tokenizer": "standard", "filter": \[ "lowercase", …

---

## [Trying to bring up filebeat + logstash + Elasticsea + Kibana](https://discuss.elastic.co/t/trying-to-bring-up-filebeat-logstash-elasticsea-kibana/326095)

<div class="topic-metadata">

**Author:** [@vassiliy.vins](https://discuss.elastic.co/u/vassiliy.vins)\
**Replies:** 3\
**Last updated:** [February 22, 2023, 1:05am UTC](https://discuss.elastic.co/t/trying-to-bring-up-filebeat-logstash-elasticsea-kibana/326095 "2023-02-22T01:05:58Z")

</div>

Hi! Followed Elasticsearch docs while installing elasticsearch + kibana + logstash + filebeat default set up. For the moment filebeat configured to send events using logstash-tutorial.log.gz (extracted to logstash-tu…

---

## [No logstash output on windows](https://discuss.elastic.co/t/no-logstash-output-on-windows/326077)

<div class="topic-metadata">

**Author:** [@jeanette](https://discuss.elastic.co/u/jeanette)\
**Replies:** 6\
**Last updated:** [February 21, 2023, 11:50pm UTC](https://discuss.elastic.co/t/no-logstash-output-on-windows/326077 "2023-02-21T23:50:09Z")

</div>

Hello, I have been troubleshooting my logstash for some time now. I was following the "Parsing Logs with Logstash" tutorial for Windows and have not been able to see any output with the basic pipeline. Below is my first-…

---

## [Ruby script for auditd EXECVE logs](https://discuss.elastic.co/t/ruby-script-for-auditd-execve-logs/326098)

<div class="topic-metadata">

**Author:** [@JCW](https://discuss.elastic.co/u/JCW)\
**Replies:** 2\
**Last updated:** [February 21, 2023, 10:53pm UTC](https://discuss.elastic.co/t/ruby-script-for-auditd-execve-logs/326098 "2023-02-21T22:53:09Z")

</div>

I want to make a ruby script that makes an extra field for "command" that it parses out of the message that auditd creates, however it does not work and I am unable to figure out why. example log: type=EXECVE msg=audit…

---

## [Why does indexation load create query load?](https://discuss.elastic.co/t/why-does-indexation-load-create-query-load/326055)

<div class="topic-metadata">

**Author:** [@alsyia](https://discuss.elastic.co/u/alsyia)\
**Replies:** 1\
**Last updated:** [February 21, 2023, 9:36pm UTC](https://discuss.elastic.co/t/why-does-indexation-load-create-query-load/326055 "2023-02-21T21:36:32Z")

</div>

Hi everyone, I've noticed when my ES (5.6) cluster is indexing lots of documents the number of queries being answered also increases. I index using the op\_type "create" with predefined ids, so I guess this is just the c…

[Previous page](https://discuss.elastic.co/tag/none.md?no_tags=true&page=429)

[Next page](https://discuss.elastic.co/tag/none.md?no_tags=true&page=431)
