# \#none

**URL:** https://discuss.elastic.co/tag/none.md?no_tags=true&page=451

[Latest](https://discuss.elastic.co/latest.md) · [Categories](https://discuss.elastic.co/categories.md) · [Tags](https://discuss.elastic.co/tags.md)

**Page:** 452

---

## [Illegal reflective access errors](https://discuss.elastic.co/t/illegal-reflective-access-errors/323020)

<div class="topic-metadata">

**Author:** [@djrshn2346](https://discuss.elastic.co/u/djrshn2346)\
**Replies:** 6\
**Last updated:** [January 23, 2023, 9:58am UTC](https://discuss.elastic.co/t/illegal-reflective-access-errors/323020 "2023-01-23T09:58:24Z")

</div>

Getting Illegal reflective access errors along with these warnings: WARNING: An illegal reflective access operation has occurred WARNING: Illegal reflective access by org.jruby.ext.openssl.SecurityHelper (file:/{...}…

---

## [ElasticSearch - logstash ( 8.2.0 )](https://discuss.elastic.co/t/elasticsearch-logstash-8-2-0/323710)

<div class="topic-metadata">

**Author:** [@Nalin\_Kumar](https://discuss.elastic.co/u/Nalin_Kumar)\
**Replies:** 0\
**Last updated:** [January 23, 2023, 8:56am UTC](https://discuss.elastic.co/t/elasticsearch-logstash-8-2-0/323710 "2023-01-23T08:56:49Z")

</div>

Hi, all. I'am new to Elasticsearch and finding the best way to store data in elastic-search engine using log stash. Reading tables from input JDBC and output to elastic-search. Currently i have create single index but…

---

## [Help to create new field from message](https://discuss.elastic.co/t/help-to-create-new-field-from-message/323698)

<div class="topic-metadata">

**Author:** [@Sam\_1995](https://discuss.elastic.co/u/Sam_1995)\
**Replies:** 1\
**Last updated:** [January 23, 2023, 8:27am UTC](https://discuss.elastic.co/t/help-to-create-new-field-from-message/323698 "2023-01-23T08:27:50Z")

</div>

Hello, I m looking for a way (maybe with grok), to create new field by extracting some specified pattern but with keeping the field message without modification after operation Example Pattern 2023-01-23 10:33:25 \[ALB…

---

## [Run multi-vectors kNN search](https://discuss.elastic.co/t/run-multi-vectors-knn-search/299958)

<div class="topic-metadata">

**Author:** [@rporcu](https://discuss.elastic.co/u/rporcu)\
**Replies:** 2\
**Last updated:** [January 23, 2023, 7:48am UTC](https://discuss.elastic.co/t/run-multi-vectors-knn-search/299958 "2023-01-23T07:48:05Z")

</div>

Hello everyone! I’m really interested by the new kNN search functionality of Elasticsearch v8. Is there any way to run an approximate kNN search on multiple dense\_vectors? I checked the docs but, as of version 8.1.0, …

---

## [Paginantion in logstash](https://discuss.elastic.co/t/paginantion-in-logstash/323385)

<div class="topic-metadata">

**Author:** [@anik-27](https://discuss.elastic.co/u/anik-27)\
**Replies:** 3\
**Last updated:** [January 23, 2023, 6:34am UTC](https://discuss.elastic.co/t/paginantion-in-logstash/323385 "2023-01-23T06:34:07Z")

</div>

Hello there ! I am fetching data from vRops api using http\_poller. Is there any way to achieve pagination in logstash ?

---

## [Filter data based on dates and days](https://discuss.elastic.co/t/filter-data-based-on-dates-and-days/323681)

<div class="topic-metadata">

**Author:** [@stella\_raj](https://discuss.elastic.co/u/stella_raj)\
**Replies:** 2\
**Last updated:** [January 23, 2023, 3:50am UTC](https://discuss.elastic.co/t/filter-data-based-on-dates-and-days/323681 "2023-01-23T03:50:31Z")

</div>

Hi, Need to filter data based on specific dates and days. Suggest any filter plugin that will fulfil my requirement. Thanks

---

## [Execute policy synchronously without a \`sleep\` in my bash scripts](https://discuss.elastic.co/t/execute-policy-synchronously-without-a-sleep-in-my-bash-scripts/323695)

<div class="topic-metadata">

**Author:** [@learningelastic](https://discuss.elastic.co/u/learningelastic)\
**Replies:** 0\
**Last updated:** [January 23, 2023, 2:44am UTC](https://discuss.elastic.co/t/execute-policy-synchronously-without-a-sleep-in-my-bash-scripts/323695 "2023-01-23T02:44:41Z")

</div>

I've been following this guide to learn how to use enrich processor and ingestion pipelines: I've got most things working so I tried a more realistic workflow that goes something like this: #!/bin/bash /usr/share/l…

---

## [Shard Allocation](https://discuss.elastic.co/t/shard-allocation/323683)

<div class="topic-metadata">

**Author:** [@kajal\_sri](https://discuss.elastic.co/u/kajal_sri)\
**Replies:** 2\
**Last updated:** [January 22, 2023, 7:18pm UTC](https://discuss.elastic.co/t/shard-allocation/323683 "2023-01-22T19:18:11Z")

</div>

Getting Shard allocation issues. Able to see some partial indices as well and those are reported under UNASSIGNED shards. Any specific reason why am getting this issue and how to fix this?

---

## [As a result of my queries, only one result should be returned, but irrelevant results are coming](https://discuss.elastic.co/t/as-a-result-of-my-queries-only-one-result-should-be-returned-but-irrelevant-results-are-coming/323669)

<div class="topic-metadata">

**Author:** [@yasmin1991](https://discuss.elastic.co/u/yasmin1991)\
**Replies:** 8\
**Last updated:** [January 22, 2023, 6:54pm UTC](https://discuss.elastic.co/t/as-a-result-of-my-queries-only-one-result-should-be-returned-but-irrelevant-results-are-coming/323669 "2023-01-22T18:54:08Z")

</div>

Hello I have a question that I expect to return only one result. GET /cvlist/\_search { "query": { "match": { "cvID": "17411189" } } } As a result of the query, another result with a similar cvID is r…

---

## [403 on Discover Tab](https://discuss.elastic.co/t/403-on-discover-tab/323690)

<div class="topic-metadata">

**Author:** [@Akash\_Sethiya](https://discuss.elastic.co/u/Akash_Sethiya)\
**Replies:** 0\
**Last updated:** [January 22, 2023, 6:31pm UTC](https://discuss.elastic.co/t/403-on-discover-tab/323690 "2023-01-22T18:31:45Z")

</div>

Kibana version - 8.5.3 on k8s Elasticsearch version - 8.5.3 on VM On opening discover tab I keep getting Error: Batch request failed with status 403 at search\_interceptor\_SearchInterceptor.handleSearchError Look…

---

## [Remove monitoring for some specific URL in on application - Elastic APM](https://discuss.elastic.co/t/remove-monitoring-for-some-specific-url-in-on-application-elastic-apm/323685)

<div class="topic-metadata">

**Author:** [@Harhsa\_vardhan](https://discuss.elastic.co/u/Harhsa_vardhan)\
**Replies:** 1\
**Last updated:** [January 22, 2023, 4:48pm UTC](https://discuss.elastic.co/t/remove-monitoring-for-some-specific-url-in-on-application-elastic-apm/323685 "2023-01-22T16:48:33Z")

</div>

Trying to implement APM newly in one of my test cluster. My test application has some 6+ URL's which starts with same domain, I need to remove monitoring for some specific URL in on application. Is there any option to …

---

## [Use persian calendar in date\_histogram](https://discuss.elastic.co/t/use-persian-calendar-in-date-histogram/323678)

<div class="topic-metadata">

**Author:** [@masoud\_darvishi](https://discuss.elastic.co/u/masoud_darvishi)\
**Replies:** 0\
**Last updated:** [January 22, 2023, 2:08pm UTC](https://discuss.elastic.co/t/use-persian-calendar-in-date-histogram/323678 "2023-01-22T14:08:49Z")

</div>

hi i'm using date histogram with monthly interval aggregation "date\_histogram": { "field": "events.create", "calendar\_interval": "month", "format": "yyyy-MM-dd" } and this is the result { "key\_as\_…

---

## [Designing elasticsearch cluster for a SOC](https://discuss.elastic.co/t/designing-elasticsearch-cluster-for-a-soc/323647)

<div class="topic-metadata">

**Author:** [@TomSLV](https://discuss.elastic.co/u/TomSLV)\
**Replies:** 4\
**Last updated:** [January 22, 2023, 1:09pm UTC](https://discuss.elastic.co/t/designing-elasticsearch-cluster-for-a-soc/323647 "2023-01-22T13:09:13Z")

</div>

Hi everyone, I'm Tom, i'm a soc analyst since 4 years and i'm actually working for a company who want to put a SIEM. I've read many blog post on how to designing/sizing an elasticsearch cluster but i want to have your f…

---

## [Ruby Filter : difference between init option and path option in terms of performance](https://discuss.elastic.co/t/ruby-filter-difference-between-init-option-and-path-option-in-terms-of-performance/323677)

<div class="topic-metadata">

**Author:** [@mostafaelsayed](https://discuss.elastic.co/u/mostafaelsayed)\
**Replies:** 0\
**Last updated:** [January 22, 2023, 1:27pm UTC](https://discuss.elastic.co/t/ruby-filter-difference-between-init-option-and-path-option-in-terms-of-performance/323677 "2023-01-22T13:27:07Z")

</div>

Hello All, while I am reading on Ruby filter plugin, I found that the "init" option is used to execute any code at startup time. so, is there any 'performance' difference between path option and init option used like t…

---

## [Replacing @timestamp with logs having custom timestamp](https://discuss.elastic.co/t/replacing-timestamp-with-logs-having-custom-timestamp/323656)

<div class="topic-metadata">

**Author:** [@sahoo35](https://discuss.elastic.co/u/sahoo35)\
**Replies:** 7\
**Last updated:** [January 22, 2023, 10:22am UTC](https://discuss.elastic.co/t/replacing-timestamp-with-logs-having-custom-timestamp/323656 "2023-01-22T10:22:39Z")

</div>

Hello Everyone, I am newbie in ELK stack and i am still learning the logstash, kibana and its further uses . Currently i am stuck at a point where i want to extract the time stamp from my logs and replace it with @times…

---

## [Does NFS Server (remote source) exported in ELK?](https://discuss.elastic.co/t/does-nfs-server-remote-source-exported-in-elk/323667)

<div class="topic-metadata">

**Author:** [@m3bgwad](https://discuss.elastic.co/u/m3bgwad)\
**Replies:** 0\
**Last updated:** [January 22, 2023, 8:43am UTC](https://discuss.elastic.co/t/does-nfs-server-remote-source-exported-in-elk/323667 "2023-01-22T08:43:52Z")

</div>

I have a remote source (NFS server) and I want to use the file systems to visualize the row data in elastic and use the search engine (kibana). is there supporting in elastic with NFS?

---

## [Logstash unable to write records to existing elasticsearch index](https://discuss.elastic.co/t/logstash-unable-to-write-records-to-existing-elasticsearch-index/323659)

<div class="topic-metadata">

**Author:** [@learningelastic](https://discuss.elastic.co/u/learningelastic)\
**Replies:** 2\
**Last updated:** [January 21, 2023, 9:46pm UTC](https://discuss.elastic.co/t/logstash-unable-to-write-records-to-existing-elasticsearch-index/323659 "2023-01-21T21:46:13Z")

</div>

I can successfully get logstash to write records to an elasticsearch index if the index doesn't exist in the first place. But I can't seem to get logstash to write records to an index if it already exists. For example,…

---

## [ELK Active Active Setup with Failure Recovery](https://discuss.elastic.co/t/elk-active-active-setup-with-failure-recovery/323621)

<div class="topic-metadata">

**Author:** [@mostafaelsayed](https://discuss.elastic.co/u/mostafaelsayed)\
**Replies:** 2\
**Last updated:** [January 21, 2023, 6:34pm UTC](https://discuss.elastic.co/t/elk-active-active-setup-with-failure-recovery/323621 "2023-01-21T18:34:31Z")

</div>

Hello All The use case is that we want to setup Active Active architecture in ELK using two clusters in two different regions. We will index the event to both the local elasticsearch cluster and remote elasticsearch clu…

---

## [Unassigned missng shards after node failure](https://discuss.elastic.co/t/unassigned-missng-shards-after-node-failure/323649)

<div class="topic-metadata">

**Author:** [@EthanJ1999](https://discuss.elastic.co/u/EthanJ1999)\
**Replies:** 0\
**Last updated:** [January 21, 2023, 1:59pm UTC](https://discuss.elastic.co/t/unassigned-missng-shards-after-node-failure/323649 "2023-01-21T13:59:43Z")

</div>

Hi how's going every body. the proble is one of the shards of an specific index on a cluster is unassigned. the problem occures when a cluster node left, after rejoining to the cluster the shard reamain unassigned so we …

---

## [Divide two counts of the same index with different filters](https://discuss.elastic.co/t/divide-two-counts-of-the-same-index-with-different-filters/323631)

<div class="topic-metadata">

**Author:** [@TheFish](https://discuss.elastic.co/u/TheFish)\
**Replies:** 3\
**Last updated:** [January 21, 2023, 12:00pm UTC](https://discuss.elastic.co/t/divide-two-counts-of-the-same-index-with-different-filters/323631 "2023-01-21T12:00:32Z")

</div>

Hi, I'm trying to divide two counts in TSVB, and I've read the related answer at Divides two sum fields in kibana? but I have a twist, and I can't get it to work: I have one index with "death" events in a game. Each eve…

---

## [Segment size/ merge policy for large indices](https://discuss.elastic.co/t/segment-size-merge-policy-for-large-indices/323623)

<div class="topic-metadata">

**Author:** [@GregoryJC](https://discuss.elastic.co/u/GregoryJC)\
**Replies:** 7\
**Last updated:** [January 21, 2023, 6:44am UTC](https://discuss.elastic.co/t/segment-size-merge-policy-for-large-indices/323623 "2023-01-21T06:44:19Z")

</div>

I am new to Elastic, I started learning about it in depth a month ago as I moved into a position to take over the more or less unmanaged cloud install we had. We have quite a few indices with segment counts ranging from…

---

## [151209 (4) - OpenJDK 7 \<= 7u281 / 8 \<= 8u272 / 11.0.0 \<= 11.0.9 / 13.0.0 \<= 13.0.5 / 15.0.0 \<= 15.0.1 Vulnerability (2021-01-19)](https://discuss.elastic.co/t/151209-4-openjdk-7-7u281-8-8u272-11-0-0-11-0-9-13-0-0-13-0-5-15-0-0-15-0-1-vulnerability-2021-01-19/323620)

<div class="topic-metadata">

**Author:** [@khadija70](https://discuss.elastic.co/u/khadija70)\
**Replies:** 7\
**Last updated:** [January 20, 2023, 10:04pm UTC](https://discuss.elastic.co/t/151209-4-openjdk-7-7u281-8-8u272-11-0-0-11-0-9-13-0-0-13-0-5-15-0-0-15-0-1-vulnerability-2021-01-19/323620 "2023-01-20T22:04:22Z")

</div>

Hi , We have receive vulnerabilities affecting elasticksearch servers : 151209 (4) - OpenJDK 7 \<= 7u281 / 8 \<= 8u272 / 11.0.0 \<= 11.0.9 / 13.0.0 \<= 13.0.5 / 15.0.0 \<= 15.0.1 Vulnerability (2021-01-19) The solution pr…

---

## [Java.io.tmpdir](https://discuss.elastic.co/t/java-io-tmpdir/323534)

<div class="topic-metadata">

**Author:** [@chuck1](https://discuss.elastic.co/u/chuck1)\
**Replies:** 10\
**Last updated:** [January 20, 2023, 9:35pm UTC](https://discuss.elastic.co/t/java-io-tmpdir/323534 "2023-01-20T21:35:27Z")

</div>

Hello, My elasticsearch version is 8.5.3-1 I have a hardened RHEL 8 system which requires that /tmp be mounted with the "noexec" option. I have tried to adjust my jvm.options file in /etc/elasticsearch/jvm.options to s…

---

## [Loading large table from Mysql to ES via Logstash](https://discuss.elastic.co/t/loading-large-table-from-mysql-to-es-via-logstash/323442)

<div class="topic-metadata">

**Author:** [@Het\_Desai](https://discuss.elastic.co/u/Het_Desai)\
**Replies:** 7\
**Last updated:** [January 20, 2023, 7:07pm UTC](https://discuss.elastic.co/t/loading-large-table-from-mysql-to-es-via-logstash/323442 "2023-01-20T19:07:53Z")

</div>

Hello, I have multiple large tables (each table contains ~15M records and consumes ~70GB of data). My logstash configuration is as given below. input { jdbc { jdbc\_connection\_string =\> "jdbc:mysql:…

---

## [VSS errors with endpoint](https://discuss.elastic.co/t/vss-errors-with-endpoint/323533)

<div class="topic-metadata">

**Author:** [@yak990](https://discuss.elastic.co/u/yak990)\
**Replies:** 2\
**Last updated:** [January 20, 2023, 6:55pm UTC](https://discuss.elastic.co/t/vss-errors-with-endpoint/323533 "2023-01-20T18:55:18Z")

</div>

I get the error below in my application event log several times a minute at times if the endpoint features are enabled. It's a conflict with macrium reflect. To reproduce: Install free trial of macrium: Macrium Softwa…

---

## [Apache Log4j 2.0 \< 2.3.2 / 2.4 \< 2.12.4 / 2.13 \< 2.17.1 RCE](https://discuss.elastic.co/t/apache-log4j-2-0-2-3-2-2-4-2-12-4-2-13-2-17-1-rce/323614)

<div class="topic-metadata">

**Author:** [@khadija70](https://discuss.elastic.co/u/khadija70)\
**Replies:** 6\
**Last updated:** [January 20, 2023, 6:51pm UTC](https://discuss.elastic.co/t/apache-log4j-2-0-2-3-2-2-4-2-12-4-2-13-2-17-1-rce/323614 "2023-01-20T18:51:19Z")

</div>

Hi , We have recently receive security vulnerabilities related to Log4j , as solution proposed is to Upgrade to Apache Log4j version 2.17.1, 2.12.4, or 2.3.2 or later. Could you please confirm if there is a patch to …

---

## [Clean old indexes automatically in elasticsearch](https://discuss.elastic.co/t/clean-old-indexes-automatically-in-elasticsearch/323551)

<div class="topic-metadata">

**Author:** [@Joao\_Malebo](https://discuss.elastic.co/u/Joao_Malebo)\
**Replies:** 5\
**Last updated:** [January 20, 2023, 4:38pm UTC](https://discuss.elastic.co/t/clean-old-indexes-automatically-in-elasticsearch/323551 "2023-01-20T16:38:05Z")

</div>

Hello friends, I'm having problems with the storage where elasticsearch is installed... I'm constantly having a full disk. What can I do to delete or clean up old indexes?

---

## [Elastic cluster is getting overloaded by incorrect shard allocation](https://discuss.elastic.co/t/elastic-cluster-is-getting-overloaded-by-incorrect-shard-allocation/323595)

<div class="topic-metadata">

**Author:** [@Petr.Simik](https://discuss.elastic.co/u/Petr.Simik)\
**Replies:** 2\
**Last updated:** [January 20, 2023, 2:12pm UTC](https://discuss.elastic.co/t/elastic-cluster-is-getting-overloaded-by-incorrect-shard-allocation/323595 "2023-01-20T14:12:55Z")

</div>

Hi Community, May I ask for help: We have elastic v7.17.0 with 43 nodes. Sizing 2TB SSD, 8cores, 32GB RAM, 16GB Heap. Currently about 2400 indices and 6400shards. some nodes have less shards but have disk full which …

---

## [Can not create index pattern Uncaught TypeError: Cannot read properties of null](https://discuss.elastic.co/t/can-not-create-index-pattern-uncaught-typeerror-cannot-read-properties-of-null/323592)

<div class="topic-metadata">

**Author:** [@pi314](https://discuss.elastic.co/u/pi314)\
**Replies:** 0\
**Last updated:** [January 20, 2023, 12:54pm UTC](https://discuss.elastic.co/t/can-not-create-index-pattern-uncaught-typeerror-cannot-read-properties-of-null/323592 "2023-01-20T12:54:41Z")

</div>

Hi everyone, i use Version: 6.3.2, when i try to create a new index pattern i see this error: Any ideas?

---

## [Read-Only User With Save Query Priviieges](https://discuss.elastic.co/t/read-only-user-with-save-query-priviieges/323591)

<div class="topic-metadata">

**Author:** [@bigverm23](https://discuss.elastic.co/u/bigverm23)\
**Replies:** 0\
**Last updated:** [January 20, 2023, 12:53pm UTC](https://discuss.elastic.co/t/read-only-user-with-save-query-priviieges/323591 "2023-01-20T12:53:39Z")

</div>

I would like a read-only Dashboard user to be able to save a query, how can enable that? I cant seem to make it work but it's essential to our processes internally.

[Previous page](https://discuss.elastic.co/tag/none.md?no_tags=true&page=450)

[Next page](https://discuss.elastic.co/tag/none.md?no_tags=true&page=452)
