# \#none

**URL:** https://discuss.elastic.co/tag/none.md?no_tags=true&page=442

[Latest](https://discuss.elastic.co/latest.md) · [Categories](https://discuss.elastic.co/categories.md) · [Tags](https://discuss.elastic.co/tags.md)

**Page:** 443

---

## [Convert string field to geo\_point field for map visualisation](https://discuss.elastic.co/t/convert-string-field-to-geo-point-field-for-map-visualisation/324397)

<div class="topic-metadata">

**Author:** [@cf4455](https://discuss.elastic.co/u/cf4455)\
**Replies:** 4\
**Last updated:** [February 6, 2023, 2:42pm UTC](https://discuss.elastic.co/t/convert-string-field-to-geo-point-field-for-map-visualisation/324397 "2023-02-06T14:42:59Z")

</div>

Hello, We collect in our logs, among other things, geo-coordinates and their accuracy in 2 "string" fields. Currently there are over 3,200,000 logs since the beginning of 2021. Now we want to display these coordinates o…

---

## [Elasticsearch boolean term query latency increases with zero match terms](https://discuss.elastic.co/t/elasticsearch-boolean-term-query-latency-increases-with-zero-match-terms/324619)

<div class="topic-metadata">

**Author:** [@vikcher123](https://discuss.elastic.co/u/vikcher123)\
**Replies:** 3\
**Last updated:** [February 6, 2023, 10:41am UTC](https://discuss.elastic.co/t/elasticsearch-boolean-term-query-latency-increases-with-zero-match-terms/324619 "2023-02-06T10:41:56Z")

</div>

I'm observing some interesting behavior with boolean term queries on Elasticsearch that I'd like to understand further. Each document in the index has several terms under the section ev\_tags. I'm issuing queries like b…

---

## [Macos install elastic agent 8.6.1 unhealthy](https://discuss.elastic.co/t/macos-install-elastic-agent-8-6-1-unhealthy/324782)

<div class="topic-metadata">

**Author:** [@xqaiviwjxzw](https://discuss.elastic.co/u/xqaiviwjxzw)\
**Replies:** 0\
**Last updated:** [February 6, 2023, 10:10am UTC](https://discuss.elastic.co/t/macos-install-elastic-agent-8-6-1-unhealthy/324782 "2023-02-06T10:10:44Z")

</div>

I'm installing elastic agent 8.6.1 and the backend says unhealthy，What can be done about it? Checking the status shows the following error： elastic-agent-8.6.1-darwin-x86\_64 % sudo /Library/Elastic/Agent/elastic-age…

---

## [Logstash and delete of gz files](https://discuss.elastic.co/t/logstash-and-delete-of-gz-files/324514)

<div class="topic-metadata">

**Author:** [@Rhh](https://discuss.elastic.co/u/Rhh)\
**Replies:** 2\
**Last updated:** [February 6, 2023, 10:07am UTC](https://discuss.elastic.co/t/logstash-and-delete-of-gz-files/324514 "2023-02-06T10:07:58Z")

</div>

Hi I have the following my conf file ... input { file { path =\> "C:/TDS.Extra/ConsoleApp13/ConsoleApp13/bin/Debug/test.gz" sincedb\_path =\> "nul" mode =\> "read" file\_completed\_action =\> "delete" codec =\> "json" } …

---

## [【Macos】elastic agent 8.5.2 and 8.5.3 install unhealthy](https://discuss.elastic.co/t/macos-elastic-agent-8-5-2-and-8-5-3-install-unhealthy/324596)

<div class="topic-metadata">

**Author:** [@xqaiviwjxzw](https://discuss.elastic.co/u/xqaiviwjxzw)\
**Replies:** 2\
**Last updated:** [February 6, 2023, 10:02am UTC](https://discuss.elastic.co/t/macos-elastic-agent-8-5-2-and-8-5-3-install-unhealthy/324596 "2023-02-06T10:02:11Z")

</div>

hello, I am trying to install elastic agent 8.5.2 and 8.5.3 in macos and I get the following error, what can I do to solve it? Status: FAILED Message: app endpoint-security--8.5.3-03e0f317: failed to start connection cr…

---

## [How to go from JSON-based aggregation to UI visualization?](https://discuss.elastic.co/t/how-to-go-from-json-based-aggregation-to-ui-visualization/324774)

<div class="topic-metadata">

**Author:** [@tinrik](https://discuss.elastic.co/u/tinrik)\
**Replies:** 1\
**Last updated:** [February 6, 2023, 9:56am UTC](https://discuss.elastic.co/t/how-to-go-from-json-based-aggregation-to-ui-visualization/324774 "2023-02-06T09:56:08Z")

</div>

Hi, In the Kibana documentation about aggregations, there is only information about how to write a JSON query and get an aggregated result. However I cannot find any documentation on how to go from there to a UI visual…

---

## [How to Differentiate Elastic Agent with same hostname](https://discuss.elastic.co/t/how-to-differentiate-elastic-agent-with-same-hostname/324763)

<div class="topic-metadata">

**Author:** [@OmFJ](https://discuss.elastic.co/u/OmFJ)\
**Replies:** 0\
**Last updated:** [February 6, 2023, 8:01am UTC](https://discuss.elastic.co/t/how-to-differentiate-elastic-agent-with-same-hostname/324763 "2023-02-06T08:01:15Z")

</div>

Hi Everyone, I have multiple CentOS 7 running on VM. What i am trying to do is to monitor processes or services within each host. the problem is that all my host has default hostname. i already placed tags in fleet menu…

---

## [Copy only Index Mapping from one cluster to another without the data](https://discuss.elastic.co/t/copy-only-index-mapping-from-one-cluster-to-another-without-the-data/324411)

<div class="topic-metadata">

**Author:** [@dadiasish](https://discuss.elastic.co/u/dadiasish)\
**Replies:** 2\
**Last updated:** [February 6, 2023, 6:37am UTC](https://discuss.elastic.co/t/copy-only-index-mapping-from-one-cluster-to-another-without-the-data/324411 "2023-02-06T06:37:11Z")

</div>

Hi, I have a cluster which has index mappings and data in it. I'm currently creating a new cluster where I have different set of data which need to be ingested with the same mappings like in the previous cluster. So, …

---

## [Filebeat stopped working after an hour after the install](https://discuss.elastic.co/t/filebeat-stopped-working-after-an-hour-after-the-install/324538)

<div class="topic-metadata">

**Author:** [@Joshua\_John\_Consulta](https://discuss.elastic.co/u/Joshua_John_Consulta)\
**Replies:** 1\
**Last updated:** [February 6, 2023, 3:08am UTC](https://discuss.elastic.co/t/filebeat-stopped-working-after-an-hour-after-the-install/324538 "2023-02-06T03:08:44Z")

</div>

Here's the error from the terminal: × filebeat.service - Filebeat sends log files to Logstash or directly to Elasticsearch. Loaded: loaded (/lib/systemd/system/filebeat.service; enabled; preset: enabled) Activ…

---

## [Content archival and retrieval app built on ELK](https://discuss.elastic.co/t/content-archival-and-retrieval-app-built-on-elk/324695)

<div class="topic-metadata">

**Author:** [@ryendluri](https://discuss.elastic.co/u/ryendluri)\
**Replies:** 1\
**Last updated:** [February 5, 2023, 11:11pm UTC](https://discuss.elastic.co/t/content-archival-and-retrieval-app-built-on-elk/324695 "2023-02-05T23:11:58Z")

</div>

is there an existing application that supports archiving data and retrieving data in a non-profit context? Thanks

---

## [Elasticsearch-reconfigure-node errors and aborts](https://discuss.elastic.co/t/elasticsearch-reconfigure-node-errors-and-aborts/324724)

<div class="topic-metadata">

**Author:** [@H\_K7](https://discuss.elastic.co/u/H_K7)\
**Replies:** 1\
**Last updated:** [February 5, 2023, 10:20pm UTC](https://discuss.elastic.co/t/elasticsearch-reconfigure-node-errors-and-aborts/324724 "2023-02-05T22:20:06Z")

</div>

it errored on the 4th node I ran, previous 3 nodes when I ran reconfigure node with the token it didn't error out. error message ERROR: Aborting enrolling to cluster. Could not communicate with the node on any of the a…

---

## [DEV TOOLS - Group indexes into 1](https://discuss.elastic.co/t/dev-tools-group-indexes-into-1/324666)

<div class="topic-metadata">

**Author:** [@vfeydel](https://discuss.elastic.co/u/vfeydel)\
**Replies:** 2\
**Last updated:** [February 5, 2023, 10:15pm UTC](https://discuss.elastic.co/t/dev-tools-group-indexes-into-1/324666 "2023-02-05T22:15:22Z")

</div>

Hi, I have 66 index with a similar structure ike for example : abc\_1, abc\_2, abc\_3 .... abc\_n. They have a commun field name "identifiant". The id 1 may be in 1 or 2 or n index or only one and the same for the other id.…

---

## [Can't find my index](https://discuss.elastic.co/t/cant-find-my-index/324686)

<div class="topic-metadata">

**Author:** [@Martin\_Sander](https://discuss.elastic.co/u/Martin_Sander)\
**Replies:** 1\
**Last updated:** [February 5, 2023, 10:11pm UTC](https://discuss.elastic.co/t/cant-find-my-index/324686 "2023-02-05T22:11:22Z")

</div>

I have a problem finding my created intex in Kibana/Search App engine. I have an API with a bunch of articles and already created an index with a python script. When I browse 127.0.0.1:9200/articles I do get a response …

---

## [Backward Pagination with Elasticsearch Aggregation with Spring data Elasticsearch](https://discuss.elastic.co/t/backward-pagination-with-elasticsearch-aggregation-with-spring-data-elasticsearch/324607)

<div class="topic-metadata">

**Author:** [@Anuja\_Brahmankar](https://discuss.elastic.co/u/Anuja_Brahmankar)\
**Replies:** 1\
**Last updated:** [February 5, 2023, 4:36pm UTC](https://discuss.elastic.co/t/backward-pagination-with-elasticsearch-aggregation-with-spring-data-elasticsearch/324607 "2023-02-05T16:36:47Z")

</div>

Hi , I have aggregation Query with Composite Aggregation builder with spring data elasticsearch which provides after\_key value,which return last aggregated count with That I am able do forward pagination. Sample Query: …

---

## [Can you get different results from replica and primary if queried at the same time?](https://discuss.elastic.co/t/can-you-get-different-results-from-replica-and-primary-if-queried-at-the-same-time/324732)

<div class="topic-metadata">

**Author:** [@Diya\_Al\_Mahameed](https://discuss.elastic.co/u/Diya_Al_Mahameed)\
**Replies:** 6\
**Last updated:** [February 5, 2023, 4:20pm UTC](https://discuss.elastic.co/t/can-you-get-different-results-from-replica-and-primary-if-queried-at-the-same-time/324732 "2023-02-05T16:20:14Z")

</div>

in our system we get different responses and I speculate it caused by "Adaptive Replica Selection". the two queries are different but they should fetch the same document . The first query check if the document have bee…

---

## [Query nested array having n matching elements](https://discuss.elastic.co/t/query-nested-array-having-n-matching-elements/324744)

<div class="topic-metadata">

**Author:** [@Frankk](https://discuss.elastic.co/u/Frankk)\
**Replies:** 0\
**Last updated:** [February 5, 2023, 4:00pm UTC](https://discuss.elastic.co/t/query-nested-array-having-n-matching-elements/324744 "2023-02-05T16:00:24Z")

</div>

Is this possible? I am indexing web site user activity focusing on user comments across multiple web sites and databases. I am "fairly" new to ES and am addressing quite a large problem. So basic question... Along wi…

---

## [Invalid FieldReference](https://discuss.elastic.co/t/invalid-fieldreference/324365)

<div class="topic-metadata">

**Author:** [@ztony](https://discuss.elastic.co/u/ztony)\
**Replies:** 2\
**Last updated:** [February 5, 2023, 3:14pm UTC](https://discuss.elastic.co/t/invalid-fieldreference/324365 "2023-02-05T15:14:19Z")

</div>

Does anyone see this "Invalid FieldReference" error? we added some mutations to the pipeline, but new field with the same error came out. see the error log below: An unexpected error occurred! {:error=\>org.logstash.Fiel…

---

## [Http filter Vs elasticsearch ouput](https://discuss.elastic.co/t/http-filter-vs-elasticsearch-ouput/324718)

<div class="topic-metadata">

**Author:** [@mostafaelsayed](https://discuss.elastic.co/u/mostafaelsayed)\
**Replies:** 8\
**Last updated:** [February 5, 2023, 10:41am UTC](https://discuss.elastic.co/t/http-filter-vs-elasticsearch-ouput/324718 "2023-02-05T10:41:10Z")

</div>

Hello, I want to capture and process failures related to Elasticsearch being down and Elasticsearch output does not offer a way to handle this so, I want to do a POC and experiment with indexing events into Elasticsearc…

---

## [Blocked by: \[TOO\_MANY\_REQUESTS/12/disk usage exceeded flood-stage watermark, index has read-only-allow-delete block\]](https://discuss.elastic.co/t/blocked-by-too-many-requests-12-disk-usage-exceeded-flood-stage-watermark-index-has-read-only-allow-delete-block/324725)

<div class="topic-metadata">

**Author:** [@Baygon](https://discuss.elastic.co/u/Baygon)\
**Replies:** 2\
**Last updated:** [February 5, 2023, 5:31am UTC](https://discuss.elastic.co/t/blocked-by-too-many-requests-12-disk-usage-exceeded-flood-stage-watermark-index-has-read-only-allow-delete-block/324725 "2023-02-05T05:31:13Z")

</div>

Hi, I reached disk usage of 90%. I increased the disk space and now have 80% usage: /dev/root 562G 445G 118G 80% / I've tried to run the commands to remove the read only blocker: PUT \_cluster/settings { "…

---

## [Logstash crash when starting after messing the queue files](https://discuss.elastic.co/t/logstash-crash-when-starting-after-messing-the-queue-files/324708)

<div class="topic-metadata">

**Author:** [@Baygon](https://discuss.elastic.co/u/Baygon)\
**Replies:** 2\
**Last updated:** [February 5, 2023, 3:34am UTC](https://discuss.elastic.co/t/logstash-crash-when-starting-after-messing-the-queue-files/324708 "2023-02-05T03:34:10Z")

</div>

I've just upgraded Logstash minor version from 7.13 to 7.17.9, but it doesn't restart, erroring about inability to create queues (there was a forced stop of Logstash, so I assume the files are corrupted). I tried to del…

---

## [SSL certificate embedding in winlogbeat or auditbeat - Need example](https://discuss.elastic.co/t/ssl-certificate-embedding-in-winlogbeat-or-auditbeat-need-example/324720)

<div class="topic-metadata">

**Author:** [@mgotechlock](https://discuss.elastic.co/u/mgotechlock)\
**Replies:** 0\
**Last updated:** [February 4, 2023, 11:18pm UTC](https://discuss.elastic.co/t/ssl-certificate-embedding-in-winlogbeat-or-auditbeat-need-example/324720 "2023-02-04T23:18:33Z")

</div>

I'd like to know if someone can present a working example of their Beats config for Beats to Logstash with SSL, but using the embedding the certificate in the beats config as described in Configure SSL | Winlogbeat Refer…

---

## [ILM: empty indices didn't age-out](https://discuss.elastic.co/t/ilm-empty-indices-didnt-age-out/322980)

<div class="topic-metadata">

**Author:** [@Adam\_Lin](https://discuss.elastic.co/u/Adam_Lin)\
**Replies:** 7\
**Last updated:** [February 4, 2023, 2:40pm UTC](https://discuss.elastic.co/t/ilm-empty-indices-didnt-age-out/322980 "2023-02-04T14:40:29Z")

</div>

Hi, I create an ILM policy and apply it to my index template, everything works fine at first until after a day, there will be an empty index left Here is my ILM policy { "test-policy" : { "version" : 4, "mod…

---

## [Can eland (python) filter on datetime64 fields?](https://discuss.elastic.co/t/can-eland-python-filter-on-datetime64-fields/324698)

<div class="topic-metadata">

**Author:** [@mike\_haberman](https://discuss.elastic.co/u/mike_haberman)\
**Replies:** 0\
**Last updated:** [February 4, 2023, 2:07am UTC](https://discuss.elastic.co/t/can-eland-python-filter-on-datetime64-fields/324698 "2023-02-04T02:07:32Z")

</div>

I get a NotImplementedError error for when I try to mask a field that's a datetime field: s\_t = pd.to\_datetime("2023-02-03T23:28:00", utc=True) # UTC t\_m = (df\['start'\] \>= s\_t) File /opt/conda/lib/python3.9/site-packag…

---

## [Write base64 decoded field from JSON message to a file](https://discuss.elastic.co/t/write-base64-decoded-field-from-json-message-to-a-file/324505)

<div class="topic-metadata">

**Author:** [@Arinjay\_Jain](https://discuss.elastic.co/u/Arinjay_Jain)\
**Replies:** 5\
**Last updated:** [February 3, 2023, 10:28pm UTC](https://discuss.elastic.co/t/write-base64-decoded-field-from-json-message-to-a-file/324505 "2023-02-03T22:28:19Z")

</div>

Hi Team, I have the following logstash pipeline configuration. input { tcp { port =\> 5102 codec =\> json } } filter { json { source =\> "message" remove\_field =\> \[ "message" \] } …

---

## [Elastic 7.17.9, 8.5.0 and 8.6.1 Security Update](https://discuss.elastic.co/t/elastic-7-17-9-8-5-0-and-8-6-1-security-update/324661)

<div class="topic-metadata">

**Author:** [@ikakavas](https://discuss.elastic.co/u/ikakavas)\
**Replies:** 0\
**Last updated:** [February 3, 2023, 2:30pm UTC](https://discuss.elastic.co/t/elastic-7-17-9-8-5-0-and-8-6-1-security-update/324661 "2023-02-03T14:30:50Z")

</div>

Kibana authenticated Denial of Service issue (ESA-2023-02) A flaw(CVE-2022-38900) was discovered in one of Kibana’s third party dependencies, that could allow an authenticated user to to perform a request that crashes th…

---

## [Grokparsefailure in processing a log file](https://discuss.elastic.co/t/grokparsefailure-in-processing-a-log-file/324682)

<div class="topic-metadata">

**Author:** [@Indrajit](https://discuss.elastic.co/u/Indrajit)\
**Replies:** 5\
**Last updated:** [February 3, 2023, 7:54pm UTC](https://discuss.elastic.co/t/grokparsefailure-in-processing-a-log-file/324682 "2023-02-03T19:54:15Z")

</div>

While processing a large log file with logstash, we are getting grokparsefailure & dateparsefailure. We would like to know which line in the log file is causing the failure so that we can look into more details with gro…

---

## [One index by dataset?](https://discuss.elastic.co/t/one-index-by-dataset/324684)

<div class="topic-metadata">

**Author:** [@m4rk](https://discuss.elastic.co/u/m4rk)\
**Replies:** 4\
**Last updated:** [February 3, 2023, 7:31pm UTC](https://discuss.elastic.co/t/one-index-by-dataset/324684 "2023-02-03T19:31:22Z")

</div>

I need to store multiple datasets in Elasticsearch, each containing a high number of documents (something between 100,000 and 1,000,000). They have essentially the same structure. Since I use /analyze only one dataset at…

---

## [How make a master node in a 3 node cluster?](https://discuss.elastic.co/t/how-make-a-master-node-in-a-3-node-cluster/324656)

<div class="topic-metadata">

**Author:** [@H\_K7](https://discuss.elastic.co/u/H_K7)\
**Replies:** 5\
**Last updated:** [February 3, 2023, 7:26pm UTC](https://discuss.elastic.co/t/how-make-a-master-node-in-a-3-node-cluster/324656 "2023-02-03T19:26:52Z")

</div>

Current 3 node cluster setup I have setup 3 node cluster { "cluster\_name" : "DEMOCLUSTER", "status" : "green", "timed\_out" : false, "number\_of\_nodes" : 3, "number\_of\_data\_nodes" : 3, "active\_primary\_shards"…

---

## [Python Search on Data Stream](https://discuss.elastic.co/t/python-search-on-data-stream/324680)

<div class="topic-metadata">

**Author:** [@yeppazu](https://discuss.elastic.co/u/yeppazu)\
**Replies:** 0\
**Last updated:** [February 3, 2023, 5:33pm UTC](https://discuss.elastic.co/t/python-search-on-data-stream/324680 "2023-02-03T17:33:49Z")

</div>

Hello, we migrate from an Elasticsearch 7.17 with indeces to Elasticsearch 8.6.0 with data stream. In the past we had develop a python script to search inside indices with pattern "myname-\*". Because now beats use dat…

---

## [Processing a TAXII feed?](https://discuss.elastic.co/t/processing-a-taxii-feed/324678)

<div class="topic-metadata">

**Author:** [@yak990](https://discuss.elastic.co/u/yak990)\
**Replies:** 0\
**Last updated:** [February 3, 2023, 5:02pm UTC](https://discuss.elastic.co/t/processing-a-taxii-feed/324678 "2023-02-03T17:02:48Z")

</div>

I have a data feed that needs to support TAXII 2.1 but also needs to handle certificate based authentication. Does elastic have support for this? Thanks!

[Previous page](https://discuss.elastic.co/tag/none.md?no_tags=true&page=441)

[Next page](https://discuss.elastic.co/tag/none.md?no_tags=true&page=443)
