# \#none

**URL:** https://discuss.elastic.co/tag/none.md?no_tags=true&page=438

[Latest](https://discuss.elastic.co/latest.md) · [Categories](https://discuss.elastic.co/categories.md) · [Tags](https://discuss.elastic.co/tags.md)

**Page:** 439

---

## [Is there a way to get a nested field in not flattened format?](https://discuss.elastic.co/t/is-there-a-way-to-get-a-nested-field-in-not-flattened-format/325276)

<div class="topic-metadata">

**Author:** [@MohammedZia](https://discuss.elastic.co/u/MohammedZia)\
**Replies:** 1\
**Last updated:** [February 10, 2023, 3:00pm UTC](https://discuss.elastic.co/t/is-there-a-way-to-get-a-nested-field-in-not-flattened-format/325276 "2023-02-10T15:00:54Z")

</div>

I've a document that contains a field called json\_field. This field contains nested object (a dictionary as complex as it can get, as I can't fix the shape at the moment). When I search for this field using json\_field, I…

---

## [Migration path from embedded 2.x to current](https://discuss.elastic.co/t/migration-path-from-embedded-2-x-to-current/325080)

<div class="topic-metadata">

**Author:** [@Cyntech](https://discuss.elastic.co/u/Cyntech)\
**Replies:** 5\
**Last updated:** [February 10, 2023, 1:41pm UTC](https://discuss.elastic.co/t/migration-path-from-embedded-2-x-to-current/325080 "2023-02-10T13:41:35Z")

</div>

I'm the developer of a Grails web application that had embedded Elastic Search 1.x implemented more around 10 years ago (not by me, I've only been the developer for the last 2 yrs). In the process of upgrading to Grails…

---

## [Uptime Alerts False Alarms on All Monitors](https://discuss.elastic.co/t/uptime-alerts-false-alarms-on-all-monitors/324822)

<div class="topic-metadata">

**Author:** [@WilAlcantara](https://discuss.elastic.co/u/WilAlcantara)\
**Replies:** 2\
**Last updated:** [February 10, 2023, 1:28pm UTC](https://discuss.elastic.co/t/uptime-alerts-false-alarms-on-all-monitors/324822 "2023-02-10T13:28:35Z")

</div>

Recently we experienced having a slew of alarms/notifications going to our slack channel without our instances actually going down. Uptime monitors also show they were up in the time we received the notifications. Is thi…

---

## [Heap memory full? new documents just disappeared!](https://discuss.elastic.co/t/heap-memory-full-new-documents-just-disappeared/325037)

<div class="topic-metadata">

**Author:** [@Pete\_Watcharawit1](https://discuss.elastic.co/u/Pete_Watcharawit1)\
**Replies:** 5\
**Last updated:** [February 10, 2023, 6:07am UTC](https://discuss.elastic.co/t/heap-memory-full-new-documents-just-disappeared/325037 "2023-02-10T06:07:59Z")

</div>

Hello, some of our new batch of documents disappeared lately and I tried checking the heap memory usage of the cluster of 2 nodes by running: curl -XGET 'http://\<address\>:9200/\_nodes/stats/jvm?pretty' Our cluster is usi…

---

## [Logstash + Fortinet + Kibana](https://discuss.elastic.co/t/logstash-fortinet-kibana/323508)

<div class="topic-metadata">

**Author:** [@Cezary](https://discuss.elastic.co/u/Cezary)\
**Replies:** 10\
**Last updated:** [February 10, 2023, 12:57pm UTC](https://discuss.elastic.co/t/logstash-fortinet-kibana/323508 "2023-02-10T12:57:21Z")

</div>

Hello to All, I'm trying to create Kibana map using data from Fortinet syslog and Logstash. I was able to load geoip data to kibana, however geo.location field had to be created from Logstash because it was not created…

---

## [Elasticsearch, kibana y logstash y filebeat](https://discuss.elastic.co/t/elasticsearch-kibana-y-logstash-y-filebeat/325228)

<div class="topic-metadata">

**Author:** [@jomaguca](https://discuss.elastic.co/u/jomaguca)\
**Replies:** 1\
**Last updated:** [February 10, 2023, 12:46pm UTC](https://discuss.elastic.co/t/elasticsearch-kibana-y-logstash-y-filebeat/325228 "2023-02-10T12:46:06Z")

</div>

Hello everybody My name is José Manuel and I am testing this solution to be use in logs managment so I hope you can help to work with this. My idea is install this in a debian 11 and elasticsearch 8.6.1 with kibana 8.6…

---

## [Gelf Input plugin dropping messages](https://discuss.elastic.co/t/gelf-input-plugin-dropping-messages/325260)

<div class="topic-metadata">

**Author:** [@karlo95](https://discuss.elastic.co/u/karlo95)\
**Replies:** 0\
**Last updated:** [February 10, 2023, 12:08pm UTC](https://discuss.elastic.co/t/gelf-input-plugin-dropping-messages/325260 "2023-02-10T12:08:36Z")

</div>

Hello, I'm having problems with Gelf Input plugin dropping messages when listening on UDP. When a lot of messagess comes in same time, it seems like logstash plugin is dropping them randomly. E.g. when I restart quark…

---

## [Elastic-agent error ResourceExhausted desc = grpc: received message larger than max](https://discuss.elastic.co/t/elastic-agent-error-resourceexhausted-desc-grpc-received-message-larger-than-max/325256)

<div class="topic-metadata">

**Author:** [@fabien9402](https://discuss.elastic.co/u/fabien9402)\
**Replies:** 0\
**Last updated:** [February 10, 2023, 11:46am UTC](https://discuss.elastic.co/t/elastic-agent-error-resourceexhausted-desc-grpc-received-message-larger-than-max/325256 "2023-02-10T11:46:58Z")

</div>

We have an error in one of our elastic-agent. This returns the error below: 12:17:47.199 elastic\_agent.filebeat \[elastic\_agent.filebeat\]\[error\] elastic-agent-client got error: rpc error: code = ResourceExhausted desc =…

---

## [Adding Memcached integration turns agent unhealthy](https://discuss.elastic.co/t/adding-memcached-integration-turns-agent-unhealthy/325254)

<div class="topic-metadata">

**Author:** [@rrodrigues](https://discuss.elastic.co/u/rrodrigues)\
**Replies:** 0\
**Last updated:** [February 10, 2023, 11:39am UTC](https://discuss.elastic.co/t/adding-memcached-integration-turns-agent-unhealthy/325254 "2023-02-10T11:39:29Z")

</div>

When I add the Memcached Elastic Agent integration to a Fleet-managed agent it goes unhealthy. I believe this issue is similar to this one reported on Nginx/Kafka integration. Elastic Cloud/Elastic Agent: 8.6.1 Memcach…

---

## [GCSToElasticsearch Template](https://discuss.elastic.co/t/gcstoelasticsearch-template/323834)

<div class="topic-metadata">

**Author:** [@Roque\_Moyano](https://discuss.elastic.co/u/Roque_Moyano)\
**Replies:** 1\
**Last updated:** [February 10, 2023, 11:31am UTC](https://discuss.elastic.co/t/gcstoelasticsearch-template/323834 "2023-02-10T11:31:12Z")

</div>

Hi, I'm following this tutorial: Ingest data directly from Google Cloud Storage into Elastic using Google Dataflow | Elastic Blog but when the dataflow job is running I got this error: {"severity":"INFO","time":"2023/0…

---

## [Pass Multiple Fields in span term query](https://discuss.elastic.co/t/pass-multiple-fields-in-span-term-query/325213)

<div class="topic-metadata">

**Author:** [@Sahil5](https://discuss.elastic.co/u/Sahil5)\
**Replies:** 1\
**Last updated:** [February 10, 2023, 11:26am UTC](https://discuss.elastic.co/t/pass-multiple-fields-in-span-term-query/325213 "2023-02-10T11:26:25Z")

</div>

Hi Team, Can anyone please help how to pass multiple fields for searching in span\_term query? Example for span\_term query { "span\_term": { "field1": "value1" } } I want to pass something like this { "span\_term": { \[…

---

## [UNABLE TO CREATE THE VISUAL FOR MULTIPLE LOGS](https://discuss.elastic.co/t/unable-to-create-the-visual-for-multiple-logs/325245)

<div class="topic-metadata">

**Author:** [@Naveen3](https://discuss.elastic.co/u/Naveen3)\
**Replies:** 0\
**Last updated:** [February 10, 2023, 11:09am UTC](https://discuss.elastic.co/t/unable-to-create-the-visual-for-multiple-logs/325245 "2023-02-10T11:09:10Z")

</div>

How do I create the visual for the one value in two different logs? For the Example A is passed through L1. B is passed through L1. A is inducted from M1 L1 and M1 were in different logs for the same value. How do …

---

## [Change StorageClass of an already running cluster](https://discuss.elastic.co/t/change-storageclass-of-an-already-running-cluster/325238)

<div class="topic-metadata">

**Author:** [@Maksym\_Postument](https://discuss.elastic.co/u/Maksym_Postument)\
**Replies:** 0\
**Last updated:** [February 10, 2023, 10:33am UTC](https://discuss.elastic.co/t/change-storageclass-of-an-already-running-cluster/325238 "2023-02-10T10:33:38Z")

</div>

Hello, i am trying to use suggested method here Change StorageClass of an already running cluster I changed nodeset name and storage class. And i see next elasticsearch-data-common-cluster-es-data-0 Bound …

---

## [Unable to install Kibana Development Enviroment](https://discuss.elastic.co/t/unable-to-install-kibana-development-enviroment/325214)

<div class="topic-metadata">

**Author:** [@Mufasa](https://discuss.elastic.co/u/Mufasa)\
**Replies:** 2\
**Last updated:** [February 10, 2023, 10:01am UTC](https://discuss.elastic.co/t/unable-to-install-kibana-development-enviroment/325214 "2023-02-10T10:01:38Z")

</div>

Hello Team, I am a beginner and almost tried all tutorials, blogs and gits to build my kibana development environment but unable to sort this mystery out. Can someone please help me out. Best

---

## [Installed ElasticSearch on linux, service is running but curl to elasticsearch url is failing](https://discuss.elastic.co/t/installed-elasticsearch-on-linux-service-is-running-but-curl-to-elasticsearch-url-is-failing/324937)

<div class="topic-metadata">

**Author:** [@Devanshu](https://discuss.elastic.co/u/Devanshu)\
**Replies:** 3\
**Last updated:** [February 10, 2023, 9:37am UTC](https://discuss.elastic.co/t/installed-elasticsearch-on-linux-service-is-running-but-curl-to-elasticsearch-url-is-failing/324937 "2023-02-10T09:37:55Z")

</div>

Installed Elasticsearch on linux, service is running but curl to elasticsearch url is failing. Getting below error curl: (52) Empty reply from server

---

## [Kibana cannot connect to the Elastic Package Registry, which provides Elastic Agent integrations](https://discuss.elastic.co/t/kibana-cannot-connect-to-the-elastic-package-registry-which-provides-elastic-agent-integrations/325233)

<div class="topic-metadata">

**Author:** [@zyaza](https://discuss.elastic.co/u/zyaza)\
**Replies:** 0\
**Last updated:** [February 10, 2023, 9:27am UTC](https://discuss.elastic.co/t/kibana-cannot-connect-to-the-elastic-package-registry-which-provides-elastic-agent-integrations/325233 "2023-02-10T09:27:28Z")

</div>

After installing elasticsearch, kibana and auditbeat i went to http://127.0.0.1:5601. I clicked on Discorver and this what the image I saw

---

## [I use the SLM policy, and the start time of the snapshot is inconsistent with the scheduled time](https://discuss.elastic.co/t/i-use-the-slm-policy-and-the-start-time-of-the-snapshot-is-inconsistent-with-the-scheduled-time/325082)

<div class="topic-metadata">

**Author:** [@lijianzhi](https://discuss.elastic.co/u/lijianzhi)\
**Replies:** 8\
**Last updated:** [February 10, 2023, 8:59am UTC](https://discuss.elastic.co/t/i-use-the-slm-policy-and-the-start-time-of-the-snapshot-is-inconsistent-with-the-scheduled-time/325082 "2023-02-10T08:59:49Z")

</div>

I use slm policy to create a snapshot policy plan 0 0 \* \* \*?, The next plan is 12:00, but the actual start time of the snapshot is 11:59:59, one second ahead of schedule. Or 12:00:01, delay 1 second. There are three repl…

---

## [Kibana patches from 8.5.3 to 8.6.1](https://discuss.elastic.co/t/kibana-patches-from-8-5-3-to-8-6-1/324202)

<div class="topic-metadata">

**Author:** [@ArpitChoudhary](https://discuss.elastic.co/u/ArpitChoudhary)\
**Replies:** 26\
**Last updated:** [February 10, 2023, 7:15am UTC](https://discuss.elastic.co/t/kibana-patches-from-8-5-3-to-8-6-1/324202 "2023-02-10T07:15:12Z")

</div>

Hello guys, Need help while upgrading kibana patches from 8.5.3 to 8.6.1. not able to connect a node on browser. I update a node by apt update -y & apy upgrade -y, reboot it, try to make it out from the cluster but go…

---

## [Elasticsearch, Logstash, Kibana Scale-out Architecture](https://discuss.elastic.co/t/elasticsearch-logstash-kibana-scale-out-architecture/325206)

<div class="topic-metadata">

**Author:** [@haikal.azaim](https://discuss.elastic.co/u/haikal.azaim)\
**Replies:** 1\
**Last updated:** [February 10, 2023, 7:04am UTC](https://discuss.elastic.co/t/elasticsearch-logstash-kibana-scale-out-architecture/325206 "2023-02-10T07:04:54Z")

</div>

Hi Elastic Community, please need your advice. I have 2 logstash, 3 elasticsearch nodes, and 1 kibana for one office. I want to scale out the architecture, because there is new office with 300GB/day. My goal is to stick…

---

## [Grok filter request for json/custom pattern](https://discuss.elastic.co/t/grok-filter-request-for-json-custom-pattern/325135)

<div class="topic-metadata">

**Author:** [@a.emrekaraman](https://discuss.elastic.co/u/a.emrekaraman)\
**Replies:** 0\
**Last updated:** [February 9, 2023, 11:39am UTC](https://discuss.elastic.co/t/grok-filter-request-for-json-custom-pattern/325135 "2023-02-09T11:39:16Z")

</div>

Hi Team, I installed logstash and try to create right grok filter for my logs to parse it. How can I parse below logs ? ( timestamp seems as custom.%{TIMESTAMP\_ISO8601:timestamp}" doesnt work) 09-Feb-2023 09:52:49 tmp…

---

## [GROK Pattern creation](https://discuss.elastic.co/t/grok-pattern-creation/324605)

<div class="topic-metadata">

**Author:** [@anushka1203](https://discuss.elastic.co/u/anushka1203)\
**Replies:** 7\
**Last updated:** [February 10, 2023, 6:25am UTC](https://discuss.elastic.co/t/grok-pattern-creation/324605 "2023-02-10T06:25:33Z")

</div>

Hi all, Need help in creating grok pattern that works for both the following type of logs 01/25-05:17:51.314622 192.168.1.1:138 -\> 192.168.1.255:138 UDP TTL:64 TOS:0x0 ID:50222 IpLen:20 DgmLen:229 DF Len: 201 =+=+=+=+=…

---

## [Create an index with 0 replicas using terraform](https://discuss.elastic.co/t/create-an-index-with-0-replicas-using-terraform/324707)

<div class="topic-metadata">

**Author:** [@james-world](https://discuss.elastic.co/u/james-world)\
**Replies:** 2\
**Last updated:** [February 9, 2023, 11:42pm UTC](https://discuss.elastic.co/t/create-an-index-with-0-replicas-using-terraform/324707 "2023-02-09T23:42:26Z")

</div>

I am trying to use the latest terraform provider, currently 0.5.0 to create an index with no replicas into an existing Azure managed deployment. I can successfully create the index, but I always get 1 replica, even thou…

---

## ["missing authentication credentials for REST request \[/\]"](https://discuss.elastic.co/t/missing-authentication-credentials-for-rest-request/325177)

<div class="topic-metadata">

**Author:** [@vijaybala](https://discuss.elastic.co/u/vijaybala)\
**Replies:** 1\
**Last updated:** [February 9, 2023, 10:48pm UTC](https://discuss.elastic.co/t/missing-authentication-credentials-for-rest-request/325177 "2023-02-09T22:48:36Z")

</div>

Hi, I'm new to ELK Stack .I'm using 8.6.1 I have configured elasticsearch and kibana, and failed to configure logstash. After shutting down the system and running elasticsearch.bat, and connection to the local port it is…

---

## [Elasticsearch service does not start on Windows](https://discuss.elastic.co/t/elasticsearch-service-does-not-start-on-windows/325165)

<div class="topic-metadata">

**Author:** [@ludovic.denee](https://discuss.elastic.co/u/ludovic.denee)\
**Replies:** 1\
**Last updated:** [February 9, 2023, 9:42pm UTC](https://discuss.elastic.co/t/elasticsearch-service-does-not-start-on-windows/325165 "2023-02-09T21:42:28Z")

</div>

Hi all, In the context of an upgrade of Azure DevOps Server from 2020 to 2022, I needed to upgrade the ES service. from 6 to 7. Update is ok but impossible to start the service. I tried to uninstall and reinstall the …

---

## [Logstash to Elasticsearch connection](https://discuss.elastic.co/t/logstash-to-elasticsearch-connection/325198)

<div class="topic-metadata">

**Author:** [@vassiliy.vins](https://discuss.elastic.co/u/vassiliy.vins)\
**Replies:** 0\
**Last updated:** [February 9, 2023, 9:39pm UTC](https://discuss.elastic.co/t/logstash-to-elasticsearch-connection/325198 "2023-02-09T21:39:17Z")

</div>

Hello! I have filebeat running on 192.168.035 and ELK on 192.168.0.36 (name of the remote server is not good - " logstash" which can be confusing) I'm runnnig filebeat -e -c filebeat.yml -d "publish" using logstash…

---

## [Changing date format through Logstash](https://discuss.elastic.co/t/changing-date-format-through-logstash/325061)

<div class="topic-metadata">

**Author:** [@zaeemmasood](https://discuss.elastic.co/u/zaeemmasood)\
**Replies:** 4\
**Last updated:** [February 9, 2023, 9:39pm UTC](https://discuss.elastic.co/t/changing-date-format-through-logstash/325061 "2023-02-09T21:39:16Z")

</div>

Hello. We are getting feed from Kafka topic. One of the fields rdt appears in the following format: I need to change the date format to YYYY-MM-dd This was added in the logstash conf file: if "KafkCollect" in …

---

## [Http filter in Logstash](https://discuss.elastic.co/t/http-filter-in-logstash/325146)

<div class="topic-metadata">

**Author:** [@manikanta](https://discuss.elastic.co/u/manikanta)\
**Replies:** 2\
**Last updated:** [February 9, 2023, 8:28pm UTC](https://discuss.elastic.co/t/http-filter-in-logstash/325146 "2023-02-09T20:28:42Z")

</div>

hey I want to know how to pass a filters output as request body to http filter I am trying to pass output of mutate filter as body to http filter. mutate { remove\_field =\> \[ "@timestamp", "@version"\] } …

---

## [Need to know ways of controlling the write to storage account for event hub access](https://discuss.elastic.co/t/need-to-know-ways-of-controlling-the-write-to-storage-account-for-event-hub-access/325179)

<div class="topic-metadata">

**Author:** [@karthik\_Ravichandran](https://discuss.elastic.co/u/karthik_Ravichandran)\
**Replies:** 2\
**Last updated:** [February 9, 2023, 6:27pm UTC](https://discuss.elastic.co/t/need-to-know-ways-of-controlling-the-write-to-storage-account-for-event-hub-access/325179 "2023-02-09T18:27:56Z")

</div>

since its writing every 5 seconds from azure event hub to storage , its causing more cost utilization , instead we want to make it delay so that we can reduce the cost of ingesting the events , we are not having any iss…

---

## [Unable to connect logstash 8.6.1 to elastic 6.8.23 with SSL](https://discuss.elastic.co/t/unable-to-connect-logstash-8-6-1-to-elastic-6-8-23-with-ssl/324932)

<div class="topic-metadata">

**Author:** [@Patrick\_Lacson](https://discuss.elastic.co/u/Patrick_Lacson)\
**Replies:** 7\
**Last updated:** [February 9, 2023, 6:21pm UTC](https://discuss.elastic.co/t/unable-to-connect-logstash-8-6-1-to-elastic-6-8-23-with-ssl/324932 "2023-02-09T18:21:06Z")

</div>

I'm able to connect to elasticsearch 6.8.23 with logstash 8.6.1 but when I connect to an SSL enabled elasticsearch (using signed CERTS), I get the 503 error unable to connect. My output config looks like this: It works…

---

## [Prefer matching search text in beginning of result using elasticsearch in ElasticSearch Match Query](https://discuss.elastic.co/t/prefer-matching-search-text-in-beginning-of-result-using-elasticsearch-in-elasticsearch-match-query/325178)

<div class="topic-metadata">

**Author:** [@pavel4008](https://discuss.elastic.co/u/pavel4008)\
**Replies:** 0\
**Last updated:** [February 9, 2023, 4:44pm UTC](https://discuss.elastic.co/t/prefer-matching-search-text-in-beginning-of-result-using-elasticsearch-in-elasticsearch-match-query/325178 "2023-02-09T16:44:22Z")

</div>

I have a query and sometimes I can't get to return the most relevant answer: GET /items2/\_search { "query": { "match": { "description": { "query": "query\_value", "fuzzines…

[Previous page](https://discuss.elastic.co/tag/none.md?no_tags=true&page=437)

[Next page](https://discuss.elastic.co/tag/none.md?no_tags=true&page=439)
