# \#none

**URL:** https://discuss.elastic.co/tag/none.md?no_tags=true&page=459

[Latest](https://discuss.elastic.co/latest.md) · [Categories](https://discuss.elastic.co/categories.md) · [Tags](https://discuss.elastic.co/tags.md)

**Page:** 460

---

## [How to Mask Card Number](https://discuss.elastic.co/t/how-to-mask-card-number/322914)

<div class="topic-metadata">

**Author:** [@Anil0110](https://discuss.elastic.co/u/Anil0110)\
**Replies:** 2\
**Last updated:** [January 11, 2023, 9:55pm UTC](https://discuss.elastic.co/t/how-to-mask-card-number/322914 "2023-01-11T21:55:35Z")

</div>

How to Mask Card Number OF XML MESSAGE

---

## [Kibana http to elasticsearch](https://discuss.elastic.co/t/kibana-http-to-elasticsearch/322896)

<div class="topic-metadata">

**Author:** [@Vojtech\_Vavra](https://discuss.elastic.co/u/Vojtech_Vavra)\
**Replies:** 0\
**Last updated:** [January 11, 2023, 9:26am UTC](https://discuss.elastic.co/t/kibana-http-to-elasticsearch/322896 "2023-01-11T09:26:19Z")

</div>

Hello I would like to ask how to configure kibana for connect to the elasticsearch on HTTP not HTTPS. i have installed ECK on kubernetes and turn off SSL on elasticsearch because I have treafik before ECK and don't nee…

---

## [Checksum failed (hardware problem?)](https://discuss.elastic.co/t/checksum-failed-hardware-problem/322500)

<div class="topic-metadata">

**Author:** [@yang\_peng](https://discuss.elastic.co/u/yang_peng)\
**Replies:** 2\
**Last updated:** [January 11, 2023, 9:11pm UTC](https://discuss.elastic.co/t/checksum-failed-hardware-problem/322500 "2023-01-11T21:11:03Z")

</div>

A two-node cluster was restarted. The shard of one index failed to merge. The error is as follows： failed shard on node \[VosGChW1QTudYo9Tcl5sqg\]: shard failure, reason \[merge failed\], failure NotSerializableExceptionWra…

---

## [\_dateparseerror for timestamp in this format: 2023-01-11T05:07:30.648881Z,](https://discuss.elastic.co/t/dateparseerror-for-timestamp-in-this-format-2023-01-11t0530-648881z/322959)

<div class="topic-metadata">

**Author:** [@rickfish](https://discuss.elastic.co/u/rickfish)\
**Replies:** 10\
**Last updated:** [January 11, 2023, 8:54pm UTC](https://discuss.elastic.co/t/dateparseerror-for-timestamp-in-this-format-2023-01-11t0530-648881z/322959 "2023-01-11T20:54:45Z")

</div>

I am trying to parse a field called create\_ts with a value of 2023-01-11T05:07:30.648881Z and then add fields for year, month and day. I have scoured everything to figure out the correct timestamp pattern and cannot see…

---

## [TEXT FIELDS NOT GETTING IMPORTED](https://discuss.elastic.co/t/text-fields-not-getting-imported/314052)

<div class="topic-metadata">

**Author:** [@Shashank02](https://discuss.elastic.co/u/Shashank02)\
**Replies:** 4\
**Last updated:** [October 20, 2022, 9:06am UTC](https://discuss.elastic.co/t/text-fields-not-getting-imported/314052 "2022-10-20T09:06:20Z")

</div>

Text fields are not optimized for operations that require per-document field data like aggregations and sorting, so these operations are disabled by default. Please use a keyword field instead. Alternatively, set fieldda…

---

## [Logstash Issue](https://discuss.elastic.co/t/logstash-issue/322960)

<div class="topic-metadata">

**Author:** [@amulya](https://discuss.elastic.co/u/amulya)\
**Replies:** 2\
**Last updated:** [January 11, 2023, 6:00pm UTC](https://discuss.elastic.co/t/logstash-issue/322960 "2023-01-11T18:00:53Z")

</div>

Starting Logstash for the first time in linux machine There was an error while loading \`logstash-core-plugin-api.gemspec\`: load error: psych -- java.lang.RuntimeException: BUG: we can not copy embedded jar to temp direc…

---

## [How to configure filebeat if we are getting log files from different Linux servers?](https://discuss.elastic.co/t/how-to-configure-filebeat-if-we-are-getting-log-files-from-different-linux-servers/322954)

<div class="topic-metadata">

**Author:** [@SP003](https://discuss.elastic.co/u/SP003)\
**Replies:** 0\
**Last updated:** [January 11, 2023, 4:03pm UTC](https://discuss.elastic.co/t/how-to-configure-filebeat-if-we-are-getting-log-files-from-different-linux-servers/322954 "2023-01-11T16:03:57Z")

</div>

Hi Experts, As of now, I am able configure filebeat , logstash and get the index created with logs successfully in Elastic Search in the same server where log files are available, now I want to access log files which is…

---

## [Logstash http output plugin times out](https://discuss.elastic.co/t/logstash-http-output-plugin-times-out/322953)

<div class="topic-metadata">

**Author:** [@sarabande](https://discuss.elastic.co/u/sarabande)\
**Replies:** 0\
**Last updated:** [January 11, 2023, 4:03pm UTC](https://discuss.elastic.co/t/logstash-http-output-plugin-times-out/322953 "2023-01-11T16:03:01Z")

</div>

I'm using logstash http output plugin to send log events to an URL. This is how my output section looks like: output { if \[logger\_name\] != 'xxx' and \[type\] != "xxx" and \[logger\_name\] != 'xxx' { elasticsearch {…

---

## [2 ECK stacks in the same GKE Cluster](https://discuss.elastic.co/t/2-eck-stacks-in-the-same-gke-cluster/322771)

<div class="topic-metadata">

**Author:** [@psyfox](https://discuss.elastic.co/u/psyfox)\
**Replies:** 3\
**Last updated:** [January 11, 2023, 3:58pm UTC](https://discuss.elastic.co/t/2-eck-stacks-in-the-same-gke-cluster/322771 "2023-01-11T15:58:57Z")

</div>

Hi ppl! I have an ECK at my GKE cluster. But I need to install another ECK to test some things before upgrade the first one. Is it possible to run 2 ECK, with differente version, in the same k8s cluster?

---

## [\[ERROR\]\[logstash.agent\] Failed to execute action {:action=\>LogStash::PipelineAction::Create/pipeline\_id:main, :exception=\>"LogStash::ConfigurationError", :message=\>"Expected one of \[ \\\\t\\\\r\\\\n\], \\"#\\", \\"and\\", \\"or\\", \\"xor\\", \\"nand\\",](https://discuss.elastic.co/t/error-logstash-agent-failed-to-execute-action-action-logstash-create-pipeline-id-main-exception-logstash-configurationerror-message-expected-one-of-t-r-n-and-or-xor-nand/322599)

<div class="topic-metadata">

**Author:** [@SP003](https://discuss.elastic.co/u/SP003)\
**Replies:** 6\
**Last updated:** [January 11, 2023, 3:50pm UTC](https://discuss.elastic.co/t/error-logstash-agent-failed-to-execute-action-action-logstash-create-pipeline-id-main-exception-logstash-configurationerror-message-expected-one-of-t-r-n-and-or-xor-nand/322599 "2023-01-11T15:50:28Z")

</div>

Hello experts, I am setting up filebeat, logstash for my log monitoring work. (Linux system) Getting below error on filebeat. --\> systemctl status filebeat - getting error --\> systemctl status logstash - Running fine…

---

## [How to stagger results by same source id but default sorted by date?](https://discuss.elastic.co/t/how-to-stagger-results-by-same-source-id-but-default-sorted-by-date/322275)

<div class="topic-metadata">

**Author:** [@Urban\_B](https://discuss.elastic.co/u/Urban_B)\
**Replies:** 3\
**Last updated:** [January 11, 2023, 3:37pm UTC](https://discuss.elastic.co/t/how-to-stagger-results-by-same-source-id-but-default-sorted-by-date/322275 "2023-01-11T15:37:54Z")

</div>

I have a situation where I have a set of documents that by default sorts by datetime so most resent documents are top listed. The dilemma is that a company can send us a feed of data so that companies results can take u…

---

## [Logstash - Converting input from JDBC to json for an HTTP request](https://discuss.elastic.co/t/logstash-converting-input-from-jdbc-to-json-for-an-http-request/322949)

<div class="topic-metadata">

**Author:** [@L\_C](https://discuss.elastic.co/u/L_C)\
**Replies:** 0\
**Last updated:** [January 11, 2023, 3:32pm UTC](https://discuss.elastic.co/t/logstash-converting-input-from-jdbc-to-json-for-an-http-request/322949 "2023-01-11T15:32:47Z")

</div>

Hello, I am looking for some pointers regarding how to convert input data from a JBDC plugin into json to send the content to an API. Here is the logstash.conf: input { jdbc { jdbc\_driver\_library =\> "/logstash-c…

---

## [Reference line - can it vary over time?](https://discuss.elastic.co/t/reference-line-can-it-vary-over-time/321226)

<div class="topic-metadata">

**Author:** [@tinrik](https://discuss.elastic.co/u/tinrik)\
**Replies:** 1\
**Last updated:** [December 14, 2022, 3:36pm UTC](https://discuss.elastic.co/t/reference-line-can-it-vary-over-time/321226 "2022-12-14T15:36:24Z")

</div>

Hi! I'm following the tutorial on how to add a reference line. It looks great and exactly what I'm looking for. However I need to have the reference line be different at different points in time. For example at t = 0 t…

---

## [KPI for data comparison in Kibana](https://discuss.elastic.co/t/kpi-for-data-comparison-in-kibana/322920)

<div class="topic-metadata">

**Author:** [@Vasili](https://discuss.elastic.co/u/Vasili)\
**Replies:** 3\
**Last updated:** [January 11, 2023, 3:25pm UTC](https://discuss.elastic.co/t/kpi-for-data-comparison-in-kibana/322920 "2023-01-11T15:25:17Z")

</div>

Hello, I'm using Kibana 6.8.21, I have created dashboard regarding users Mailbox usage and corresponding carbon emission over time (with following KPIs for instance: number of sent and received emails per day…). The go…

---

## [Pipeline: copy unique value to a new index](https://discuss.elastic.co/t/pipeline-copy-unique-value-to-a-new-index/322946)

<div class="topic-metadata">

**Author:** [@SalvoDM91](https://discuss.elastic.co/u/SalvoDM91)\
**Replies:** 0\
**Last updated:** [January 11, 2023, 3:19pm UTC](https://discuss.elastic.co/t/pipeline-copy-unique-value-to-a-new-index/322946 "2023-01-11T15:19:27Z")

</div>

I guys, I need an help! I have an index called s1v6\_new\_cleaninq2 with more then 1 million of documents. Inside each documents I have a field called "num\_pratica" and this field could be repeated for a couple of documen…

---

## [Optional match for a grok pattern](https://discuss.elastic.co/t/optional-match-for-a-grok-pattern/322904)

<div class="topic-metadata">

**Author:** [@moep](https://discuss.elastic.co/u/moep)\
**Replies:** 3\
**Last updated:** [January 11, 2023, 3:05pm UTC](https://discuss.elastic.co/t/optional-match-for-a-grok-pattern/322904 "2023-01-11T15:05:46Z")

</div>

Hey community, I would like to build an optional match for the following logline: 2023-01-11 00:00:11 1pEoP9-000LLu-Gz \<= noreply@domain.de H=fqdn.domain.de (FQDN) \[10.1.1.1\] P=esmtpa A=login\_virtual\_exim:mtaspooler@do…

---

## [Get elastic shards failure upon search query across multiple indices (while creating indices)](https://discuss.elastic.co/t/get-elastic-shards-failure-upon-search-query-across-multiple-indices-while-creating-indices/322935)

<div class="topic-metadata">

**Author:** [@fesiqueira](https://discuss.elastic.co/u/fesiqueira)\
**Replies:** 0\
**Last updated:** [January 11, 2023, 1:52pm UTC](https://discuss.elastic.co/t/get-elastic-shards-failure-upon-search-query-across-multiple-indices-while-creating-indices/322935 "2023-01-11T13:52:37Z")

</div>

I'm using Elastic 7.13.1. I create indices dynamically using a template based on the year of a timestamp field. So when I try to index a document with a timestamp for 2023-01-01 into index index-2023 the index will be cr…

---

## [Change logstash default @timestamp format](https://discuss.elastic.co/t/change-logstash-default-timestamp-format/322857)

<div class="topic-metadata">

**Author:** [@markedperf](https://discuss.elastic.co/u/markedperf)\
**Replies:** 2\
**Last updated:** [January 11, 2023, 1:41pm UTC](https://discuss.elastic.co/t/change-logstash-default-timestamp-format/322857 "2023-01-11T13:41:29Z")

</div>

I am looking to change the default @timestamp format from nano seconds ("@timestamp" : "2023-01-07T17:26:16.969990782Z") to just milliseconds ("@timestamp" : "2023-01-07T17:26:16.969" or "@timestamp" : "2023-01-07T17:26:…

---

## [TCP/UDP VS syslog](https://discuss.elastic.co/t/tcp-udp-vs-syslog/322927)

<div class="topic-metadata">

**Author:** [@m3bgwad](https://discuss.elastic.co/u/m3bgwad)\
**Replies:** 3\
**Last updated:** [January 11, 2023, 1:31pm UTC](https://discuss.elastic.co/t/tcp-udp-vs-syslog/322927 "2023-01-11T13:31:40Z")

</div>

What is differences between the below. input { tcp { port =\> 514 type =\> syslog } udp { port =\> 514 type =\> syslog } } VS input { syslog { port =\> 514 } } If I need to receive syslog m…

---

## [Logstash Input plugin for Elasticsearch to query once based on scedule instead of scrolling](https://discuss.elastic.co/t/logstash-input-plugin-for-elasticsearch-to-query-once-based-on-scedule-instead-of-scrolling/322931)

<div class="topic-metadata">

**Author:** [@sahil\_sawhney](https://discuss.elastic.co/u/sahil_sawhney)\
**Replies:** 0\
**Last updated:** [January 11, 2023, 1:21pm UTC](https://discuss.elastic.co/t/logstash-input-plugin-for-elasticsearch-to-query-once-based-on-scedule-instead-of-scrolling/322931 "2023-01-11T13:21:39Z")

</div>

As visible in the screenshot for 1-minute duration, the data is queried multiple times. I wish to disable this and for a schedule "\* \* \* \* \*" collect data only once in 1 minute. My current config for logstash input pl…

---

## [Can't add wildcard multifield to double type through Kibana in Component Template](https://discuss.elastic.co/t/cant-add-wildcard-multifield-to-double-type-through-kibana-in-component-template/322310)

<div class="topic-metadata">

**Author:** [@bkelastic](https://discuss.elastic.co/u/bkelastic)\
**Replies:** 2\
**Last updated:** [January 11, 2023, 1:12pm UTC](https://discuss.elastic.co/t/cant-add-wildcard-multifield-to-double-type-through-kibana-in-component-template/322310 "2023-01-11T13:12:09Z")

</div>

Stack v 7.17.3 It is not possible to add wildcard multifield to field with type Double through Kibana in Component Template -\> Mappings. Via REST API I am able to add this to mappings in existing index. Searching with …

---

## [Elasticsearch 7.7 , cpu usage is very high](https://discuss.elastic.co/t/elasticsearch-7-7-cpu-usage-is-very-high/322726)

<div class="topic-metadata">

**Author:** [@gilsagiv](https://discuss.elastic.co/u/gilsagiv)\
**Replies:** 10\
**Last updated:** [January 11, 2023, 1:00pm UTC](https://discuss.elastic.co/t/elasticsearch-7-7-cpu-usage-is-very-high/322726 "2023-01-11T13:00:36Z")

</div>

Hi, My server is working on Elasticsearch 7.7, Recently the CPU usage is reaching 100% when Kibana is running. Elasticsearch process CPU usage is very high. GET \_cat/nodes?v=true&s=cpu:desc GET /\_cluster/setti…

---

## [Logstash Elasticsearch output plugin fails to establish a connection](https://discuss.elastic.co/t/logstash-elasticsearch-output-plugin-fails-to-establish-a-connection/322922)

<div class="topic-metadata">

**Author:** [@Thijsvdp](https://discuss.elastic.co/u/Thijsvdp)\
**Replies:** 2\
**Last updated:** [January 11, 2023, 12:59pm UTC](https://discuss.elastic.co/t/logstash-elasticsearch-output-plugin-fails-to-establish-a-connection/322922 "2023-01-11T12:59:37Z")

</div>

Hi all, I am facing an error with Logstash which is not able to connect to Elasticsearch. I am getting the following error: \[2023-01-11T12:10:15,365\]\[WARN \]\[logstash.outputs.elasticsearch\]\[continuous\] Attempted to resu…

---

## [Syslog output plugin :number type input parametrization](https://discuss.elastic.co/t/syslog-output-plugin-number-type-input-parametrization/322905)

<div class="topic-metadata">

**Author:** [@arirajamaki](https://discuss.elastic.co/u/arirajamaki)\
**Replies:** 3\
**Last updated:** [January 11, 2023, 12:38pm UTC](https://discuss.elastic.co/t/syslog-output-plugin-number-type-input-parametrization/322905 "2023-01-11T12:38:49Z")

</div>

Hello Community, I'm in trouble with my logstash pipeline configuration. I'm trying to use syslog output plugin so that I can dynamically change the destination syslog server port. I'm trying do tcp/udp connection to d…

---

## [Number of fields displayed in drop down list Controls visualizations](https://discuss.elastic.co/t/number-of-fields-displayed-in-drop-down-list-controls-visualizations/322840)

<div class="topic-metadata">

**Author:** [@Alice\_Ionescu](https://discuss.elastic.co/u/Alice_Ionescu)\
**Replies:** 1\
**Last updated:** [January 11, 2023, 12:24pm UTC](https://discuss.elastic.co/t/number-of-fields-displayed-in-drop-down-list-controls-visualizations/322840 "2023-01-11T12:24:40Z")

</div>

Hello, Now when creating a Controls visualization the number of fields displayed in the drop down list is 10. Is there possible to change the number of fields displayed? Thank you!

---

## [Parse PDF catalogs to extract products informations](https://discuss.elastic.co/t/parse-pdf-catalogs-to-extract-products-informations/322145)

<div class="topic-metadata">

**Author:** [@Valentin\_Hirson](https://discuss.elastic.co/u/Valentin_Hirson)\
**Replies:** 3\
**Last updated:** [January 11, 2023, 11:22am UTC](https://discuss.elastic.co/t/parse-pdf-catalogs-to-extract-products-informations/322145 "2023-01-11T11:22:52Z")

</div>

Hello, I need to parse some PDF files to find the most relevant words and trying to find what PDF are talking about. Those PDF are vendors catalog, I need for example to extract products to propose them in a web search…

---

## [Cat Nodes API returning CPU usage as -1. Elasticsearch version:7.11.2 OS Deb 11](https://discuss.elastic.co/t/cat-nodes-api-returning-cpu-usage-as-1-elasticsearch-version-7-11-2-os-deb-11/322912)

<div class="topic-metadata">

**Author:** [@Sagar\_Shivani1](https://discuss.elastic.co/u/Sagar_Shivani1)\
**Replies:** 1\
**Last updated:** [January 11, 2023, 10:59am UTC](https://discuss.elastic.co/t/cat-nodes-api-returning-cpu-usage-as-1-elasticsearch-version-7-11-2-os-deb-11/322912 "2023-01-11T10:59:42Z")

</div>

Cat Nodes API returning CPU usage as -1. Elasticsearch version:7.11.2 OS Deb 11.. What can be the case?

---

## [How to create an array runtime field](https://discuss.elastic.co/t/how-to-create-an-array-runtime-field/322791)

<div class="topic-metadata">

**Author:** [@cr\_168328](https://discuss.elastic.co/u/cr_168328)\
**Replies:** 15\
**Last updated:** [January 11, 2023, 10:53am UTC](https://discuss.elastic.co/t/how-to-create-an-array-runtime-field/322791 "2023-01-11T10:53:23Z")

</div>

I have an index with a nested field 'roles': "roles": { "type": "nested", "properties": { "name": { "type": "text", "fields": { "raw": { "type"…

---

## [Saved Discover Visual Download csv option doesn't provide the result data](https://discuss.elastic.co/t/saved-discover-visual-download-csv-option-doesnt-provide-the-result-data/320555)

<div class="topic-metadata">

**Author:** [@Susendiran](https://discuss.elastic.co/u/Susendiran)\
**Replies:** 6\
**Last updated:** [December 14, 2022, 11:38am UTC](https://discuss.elastic.co/t/saved-discover-visual-download-csv-option-doesnt-provide-the-result-data/320555 "2022-12-14T11:38:34Z")

</div>

Hi All, I've done an discover visual which has nearly 6k data. I added that visual to a dashboard and tried to download the data as csv. When I clicked on the download csv button which is available in the saved discover…

---

## [SNMP Traps version 3](https://discuss.elastic.co/t/snmp-traps-version-3/322889)

<div class="topic-metadata">

**Author:** [@m3bgwad](https://discuss.elastic.co/u/m3bgwad)\
**Replies:** 4\
**Last updated:** [January 11, 2023, 10:06am UTC](https://discuss.elastic.co/t/snmp-traps-version-3/322889 "2023-01-11T10:06:39Z")

</div>

Hello Everyone, Can the snmptrap input plugin for logstash receive snmp version 3 traps ? If not, are there other solutions ? I would like to collect SNMP v3 traps. Thank You

[Previous page](https://discuss.elastic.co/tag/none.md?no_tags=true&page=458)

[Next page](https://discuss.elastic.co/tag/none.md?no_tags=true&page=460)
