# \#none

**URL:** https://discuss.elastic.co/tag/none.md?no_tags=true&page=461

[Latest](https://discuss.elastic.co/latest.md) · [Categories](https://discuss.elastic.co/categories.md) · [Tags](https://discuss.elastic.co/tags.md)

**Page:** 462

---

## [Elasticsearch-java dependency on httpclient](https://discuss.elastic.co/t/elasticsearch-java-dependency-on-httpclient/322770)

<div class="topic-metadata">

**Author:** [@bbunton](https://discuss.elastic.co/u/bbunton)\
**Replies:** 2\
**Last updated:** [January 9, 2023, 10:33pm UTC](https://discuss.elastic.co/t/elasticsearch-java-dependency-on-httpclient/322770 "2023-01-09T22:33:45Z")

</div>

I have been working with Elasticsearch as a developer for a couple of years now and have successfully written some NiFi services that use the now deprecated Java API that uses port 9300 to query/retrieve/delete records t…

---

## [Indexing multiple csv files into one index with nested fields](https://discuss.elastic.co/t/indexing-multiple-csv-files-into-one-index-with-nested-fields/322687)

<div class="topic-metadata">

**Author:** [@ivandreev1618](https://discuss.elastic.co/u/ivandreev1618)\
**Replies:** 1\
**Last updated:** [January 9, 2023, 10:25pm UTC](https://discuss.elastic.co/t/indexing-multiple-csv-files-into-one-index-with-nested-fields/322687 "2023-01-09T22:25:10Z")

</div>

I want to load data from multiple CSV files(Users, Scores, Messages) into one index via logstash. All CSV files have the same "userId" field that connects data in it. My goal is to have User-Index as a result, that has…

---

## [Understanding metrics filters](https://discuss.elastic.co/t/understanding-metrics-filters/322648)

<div class="topic-metadata">

**Author:** [@Dustin527](https://discuss.elastic.co/u/Dustin527)\
**Replies:** 11\
**Last updated:** [January 9, 2023, 10:15pm UTC](https://discuss.elastic.co/t/understanding-metrics-filters/322648 "2023-01-09T22:15:23Z")

</div>

Hi I am having trouble understanding the proper way to use metrics filter plugin to count the number of fields of a particular type. Say I have a file formatted with a name and age separated by a space e.g.: dustin 40 e…

---

## [Script\_score query with cosineSimularity on alias](https://discuss.elastic.co/t/script-score-query-with-cosinesimularity-on-alias/321700)

<div class="topic-metadata">

**Author:** [@KentLee](https://discuss.elastic.co/u/KentLee)\
**Replies:** 0\
**Last updated:** [December 20, 2022, 10:19pm UTC](https://discuss.elastic.co/t/script-score-query-with-cosinesimularity-on-alias/321700 "2022-12-20T22:19:45Z")

</div>

I have an alias created with several different indices and each index has multiple dense\_vector fields. I want to perform a script\_score search on all the dense\_vector field with the cosineSimularity function. For examp…

---

## [Logstash syntax error](https://discuss.elastic.co/t/logstash-syntax-error/322754)

<div class="topic-metadata">

**Author:** [@cool999](https://discuss.elastic.co/u/cool999)\
**Replies:** 5\
**Last updated:** [January 9, 2023, 8:28pm UTC](https://discuss.elastic.co/t/logstash-syntax-error/322754 "2023-01-09T20:28:20Z")

</div>

Hi Team, I have logstash on two servers. It seems its working as index are getting created and logstash service is running from few days but whenever i checked logstash syntax, it shows below error. Is there anything wr…

---

## [Showing Enterprise Search menu in multiple spaces](https://discuss.elastic.co/t/showing-enterprise-search-menu-in-multiple-spaces/321387)

<div class="topic-metadata">

**Author:** [@Steven29](https://discuss.elastic.co/u/Steven29)\
**Replies:** 1\
**Last updated:** [January 9, 2023, 8:12pm UTC](https://discuss.elastic.co/t/showing-enterprise-search-menu-in-multiple-spaces/321387 "2023-01-09T20:12:23Z")

</div>

I want to know how to adjust about 'Enterprise Search' menu, When I make a another new spaces. I'm sorry for that I can't bring some captured image. Elasticsearch version is 8.5.0, I make a new spaces and when I chec…

---

## [Unexpected exception while running Enterprise Search: Error: Read timed out at](https://discuss.elastic.co/t/unexpected-exception-while-running-enterprise-search-error-read-timed-out-at/307102)

<div class="topic-metadata">

**Author:** [@Nids\_Rai](https://discuss.elastic.co/u/Nids_Rai)\
**Replies:** 20\
**Last updated:** [January 9, 2023, 7:40pm UTC](https://discuss.elastic.co/t/unexpected-exception-while-running-enterprise-search-error-read-timed-out-at/307102 "2023-01-09T19:40:54Z")

</div>

Getting read timeout error while setting up, Appsearch in ECK cluster. Elastic is up and running fine. The LOG : \[2022-06-14T06:10:00.351+00:00\]\[7\]\[2000\]\[app-server\]\[INFO\]: \[db\_lock\] \[installation\] Status: \[Failed\] Cr…

---

## [Dutation field type - days to weeks error](https://discuss.elastic.co/t/dutation-field-type-days-to-weeks-error/320996)

<div class="topic-metadata">

**Author:** [@Matt.Wash](https://discuss.elastic.co/u/Matt.Wash)\
**Replies:** 4\
**Last updated:** [December 12, 2022, 9:11pm UTC](https://discuss.elastic.co/t/dutation-field-type-days-to-weeks-error/320996 "2022-12-12T21:11:15Z")

</div>

using a horizontal lens vis and a duration metric to human readable duration metrics, there appears to be a conversion miscalculation between days to weeks. the attached except shows the x axis increasing by 2.3 days un…

---

## [Can i increase performance on one host?](https://discuss.elastic.co/t/can-i-increase-performance-on-one-host/322748)

<div class="topic-metadata">

**Author:** [@Ostr1969](https://discuss.elastic.co/u/Ostr1969)\
**Replies:** 1\
**Last updated:** [January 9, 2023, 5:50pm UTC](https://discuss.elastic.co/t/can-i-increase-performance-on-one-host/322748 "2023-01-09T17:50:16Z")

</div>

I have one host with a lot of memory, cpus and disk. and I have static database of 700gb and 217M records, with only one client querying. can I increase the search speed?. now I get connection timeout sometimes.

---

## [Syslog client doesn't send to Logstash](https://discuss.elastic.co/t/syslog-client-doesnt-send-to-logstash/322618)

<div class="topic-metadata">

**Author:** [@diegz](https://discuss.elastic.co/u/diegz)\
**Replies:** 6\
**Last updated:** [January 9, 2023, 4:52pm UTC](https://discuss.elastic.co/t/syslog-client-doesnt-send-to-logstash/322618 "2023-01-09T16:52:03Z")

</div>

Hello, Hello, I would like to get some advice for this configuration: Send rsyslog to my logstash. I tested both configurations without success. One moment it worked after restarting the pipeline nothing. $ModLoad i…

---

## [ML Unsupervised question](https://discuss.elastic.co/t/ml-unsupervised-question/322437)

<div class="topic-metadata">

**Author:** [@alex\_su](https://discuss.elastic.co/u/alex_su)\
**Replies:** 2\
**Last updated:** [January 9, 2023, 4:40pm UTC](https://discuss.elastic.co/t/ml-unsupervised-question/322437 "2023-01-09T16:40:45Z")

</div>

Hi, as i know es provide ml to detect unusual event, like "Unusual Windows Username" and another exapmle is " Unusual Hour for a User to Logon". I have question about unusual meaning as belows. how to build this ml ? …

---

## [Unable to run Endpoint 8.4 on a Ubuntu 20.04 host hardened with CIS Level 2](https://discuss.elastic.co/t/unable-to-run-endpoint-8-4-on-a-ubuntu-20-04-host-hardened-with-cis-level-2/318559)

<div class="topic-metadata">

**Author:** [@dapster](https://discuss.elastic.co/u/dapster)\
**Replies:** 16\
**Last updated:** [January 9, 2023, 3:57pm UTC](https://discuss.elastic.co/t/unable-to-run-endpoint-8-4-on-a-ubuntu-20-04-host-hardened-with-cis-level-2/318559 "2023-01-09T15:57:38Z")

</div>

Hi, I am encountering difficulties to properly run Endpoint (deployed thanks to Fleet Server) on a Ubuntu 20.04 host (hardened with CIS Level 2 and I suspect the issue to be related to system hardening). When I run ela…

---

## [Will synthetic tests be added to other languages?](https://discuss.elastic.co/t/will-synthetic-tests-be-added-to-other-languages/322739)

<div class="topic-metadata">

**Author:** [@ntmxglrtayl03](https://discuss.elastic.co/u/ntmxglrtayl03)\
**Replies:** 2\
**Last updated:** [January 9, 2023, 3:25pm UTC](https://discuss.elastic.co/t/will-synthetic-tests-be-added-to-other-languages/322739 "2023-01-09T15:25:07Z")

</div>

I have checked in the documentation that the current syntax only includes js and ts, and whether I will consider adding other language versions, such as python, in the future

---

## [Best Practices for Adding New Logs?](https://discuss.elastic.co/t/best-practices-for-adding-new-logs/322743)

<div class="topic-metadata">

**Author:** [@BionicSecurityMgr](https://discuss.elastic.co/u/BionicSecurityMgr)\
**Replies:** 0\
**Last updated:** [January 9, 2023, 3:01pm UTC](https://discuss.elastic.co/t/best-practices-for-adding-new-logs/322743 "2023-01-09T15:01:22Z")

</div>

Does anyone have a good process for adding a new system to monitor into Elastic? We're deploying the Elastic Agent to the servers now, so now I've got to come up with a standard process to discover data and determine be…

---

## [Best Optimization for wildcard queries](https://discuss.elastic.co/t/best-optimization-for-wildcard-queries/322738)

<div class="topic-metadata">

**Author:** [@Sheharyar\_Khalid](https://discuss.elastic.co/u/Sheharyar_Khalid)\
**Replies:** 4\
**Last updated:** [January 9, 2023, 2:30pm UTC](https://discuss.elastic.co/t/best-optimization-for-wildcard-queries/322738 "2023-01-09T14:30:09Z")

</div>

Hello, I am working with elasticsearch on audit log data. I wanted to know what are the best optimizations and tokenizer/analyzer/term usages for optimizing elastic for wildcard queries. I have looked at n-grams and the…

---

## [CORS error while adding ServiceNow ITSM connector](https://discuss.elastic.co/t/cors-error-while-adding-servicenow-itsm-connector/321042)

<div class="topic-metadata">

**Author:** [@rakeshl](https://discuss.elastic.co/u/rakeshl)\
**Replies:** 0\
**Last updated:** [December 12, 2022, 2:40pm UTC](https://discuss.elastic.co/t/cors-error-while-adding-servicenow-itsm-connector/321042 "2022-12-12T14:40:12Z")

</div>

I have installed ECK with kibana 8.5.3. I have used logstash to forward the logs to ELK stack. I am able to see the logs in kibana. Now, I am trying to integrate elastic to ServiceNow ITSM for creating incidents for the …

---

## [Replicating data between an Elastic Cluster Nodes](https://discuss.elastic.co/t/replicating-data-between-an-elastic-cluster-nodes/322737)

<div class="topic-metadata">

**Author:** [@A.Hani](https://discuss.elastic.co/u/A.Hani)\
**Replies:** 2\
**Last updated:** [January 9, 2023, 1:08pm UTC](https://discuss.elastic.co/t/replicating-data-between-an-elastic-cluster-nodes/322737 "2023-01-09T13:08:53Z")

</div>

Hi New to Elastic here and would like to get help with some inquiries. Scenario: 1- Let's assume that I have a cluster of (2) master nodes, is it possible to configure each node to hold its own data? In other words, N…

---

## [Kibana and Azure Application Gateway](https://discuss.elastic.co/t/kibana-and-azure-application-gateway/322731)

<div class="topic-metadata">

**Author:** [@bruun963](https://discuss.elastic.co/u/bruun963)\
**Replies:** 0\
**Last updated:** [January 9, 2023, 12:05pm UTC](https://discuss.elastic.co/t/kibana-and-azure-application-gateway/322731 "2023-01-09T12:05:10Z")

</div>

Hi, First time testing a ECK deployment on Azure Kubernetes Service with the Application Gateway as an ingress controller. But somehow the health probes are unable to connect to the Kibana pod. There's no response. If …

---

## [Lens Table - "wrong" selection of top N elements](https://discuss.elastic.co/t/lens-table-wrong-selection-of-top-n-elements/321784)

<div class="topic-metadata">

**Author:** [@tinrik](https://discuss.elastic.co/u/tinrik)\
**Replies:** 8\
**Last updated:** [January 9, 2023, 11:12am UTC](https://discuss.elastic.co/t/lens-table-wrong-selection-of-top-n-elements/321784 "2023-01-09T11:12:53Z")

</div>

Hi! I want to display a table like this: | File Name | Number of warnings | | path/to/foo.cpp | 123 | | path/to/bar.cpp | 30 …

---

## [Unable to find Upgrade Assistant option in 8.3.3 version](https://discuss.elastic.co/t/unable-to-find-upgrade-assistant-option-in-8-3-3-version/322458)

<div class="topic-metadata">

**Author:** [@Abj\_Ins](https://discuss.elastic.co/u/Abj_Ins)\
**Replies:** 3\
**Last updated:** [January 9, 2023, 11:46am UTC](https://discuss.elastic.co/t/unable-to-find-upgrade-assistant-option-in-8-3-3-version/322458 "2023-01-09T11:46:56Z")

</div>

Hi Team, we are trying to upgrade from version 8.2.3 to 8.5 but, unable to find Upgrade Assistant option. Kindly help us and let us know the process, how to upgrade to the latest version. Thanks.

---

## [Error fields script in the Index Pattern](https://discuss.elastic.co/t/error-fields-script-in-the-index-pattern/321314)

<div class="topic-metadata">

**Author:** [@rpc29y](https://discuss.elastic.co/u/rpc29y)\
**Replies:** 4\
**Last updated:** [January 9, 2023, 11:21am UTC](https://discuss.elastic.co/t/error-fields-script-in-the-index-pattern/321314 "2023-01-09T11:21:41Z")

</div>

Hello. I have an elastic version 7.10 and in the Index Pattern of one of the indexes I have created a simple fields script: "doc\['temperature'\]\* 10" Apparently the creation is correct, but I can't get to display the v…

---

## [Translation does not work in EUI Core components](https://discuss.elastic.co/t/translation-does-not-work-in-eui-core-components/322636)

<div class="topic-metadata">

**Author:** [@wsbr](https://discuss.elastic.co/u/wsbr)\
**Replies:** 1\
**Last updated:** [January 9, 2023, 11:10am UTC](https://discuss.elastic.co/t/translation-does-not-work-in-eui-core-components/322636 "2023-01-09T11:10:05Z")

</div>

Hi, We are using Elasticsearch 8.4.1 and some actions does not be translated. How to solve this problem? In the packages/core/i18n/core-i18n-browser-internal/src/i18n\_eui\_mapping.tsx file we find at line 1161 'euiQu…

---

## [Function score query with decay function on huge dataset](https://discuss.elastic.co/t/function-score-query-with-decay-function-on-huge-dataset/322724)

<div class="topic-metadata">

**Author:** [@minhdao](https://discuss.elastic.co/u/minhdao)\
**Replies:** 0\
**Last updated:** [January 9, 2023, 11:09am UTC](https://discuss.elastic.co/t/function-score-query-with-decay-function-on-huge-dataset/322724 "2023-01-09T11:09:40Z")

</div>

Good day everyone. Background I'm building a search engine for a marketplace. Our market has products, sellers, and customers. Each product has many sellers with their locations. The number of sellers might be around 10…

---

## [Elasticsearch on Kubernetes - Auto scale](https://discuss.elastic.co/t/elasticsearch-on-kubernetes-auto-scale/322539)

<div class="topic-metadata">

**Author:** [@Itay\_Bittan](https://discuss.elastic.co/u/Itay_Bittan)\
**Replies:** 1\
**Last updated:** [January 9, 2023, 11:02am UTC](https://discuss.elastic.co/t/elasticsearch-on-kubernetes-auto-scale/322539 "2023-01-09T11:02:42Z")

</div>

Hi, We are upgrading our Elasticsearch clusters to work on top of EKS and we want to use autoscaling. We wonder if/when you'll support the autoscaling based on memory or CPU, and if there's a plan to dynamically add/re…

---

## [Download csv file option directly on visualization/dashboard](https://discuss.elastic.co/t/download-csv-file-option-directly-on-visualization-dashboard/322658)

<div class="topic-metadata">

**Author:** [@amarkoli](https://discuss.elastic.co/u/amarkoli)\
**Replies:** 1\
**Last updated:** [January 9, 2023, 11:02am UTC](https://discuss.elastic.co/t/download-csv-file-option-directly-on-visualization-dashboard/322658 "2023-01-09T11:02:27Z")

</div>

the Download CSV option in visible when clicked on the "Inspect" which is open when clicked on the 3 dots icons. But can we have the Download CSV option directly on the visualization/dashboard or somewhere else. if ther…

---

## [Data Pipeline Design Considerations](https://discuss.elastic.co/t/data-pipeline-design-considerations/322717)

<div class="topic-metadata">

**Author:** [@Tiharqa](https://discuss.elastic.co/u/Tiharqa)\
**Replies:** 0\
**Last updated:** [January 9, 2023, 9:47am UTC](https://discuss.elastic.co/t/data-pipeline-design-considerations/322717 "2023-01-09T09:47:21Z")

</div>

So I have a confluent kafka with multiple topics per network divided as follows NET1: Data NET1-SYSLG NET1-WIN ====== NET2 : Data NET2-SYSLG NET2-WIN I have 2 logstash servers reading from those topics on Kafka …

---

## [Brand new master doesn't join cluster bootstrap error](https://discuss.elastic.co/t/brand-new-master-doesnt-join-cluster-bootstrap-error/322567)

<div class="topic-metadata">

**Author:** [@faxm0dem](https://discuss.elastic.co/u/faxm0dem)\
**Replies:** 10\
**Last updated:** [January 9, 2023, 9:48am UTC](https://discuss.elastic.co/t/brand-new-master-doesnt-join-cluster-bootstrap-error/322567 "2023-01-09T09:48:36Z")

</div>

Hi, We have a 7.10.2 cluster with multiple data-only nodes and 3 master-only nodes. We wiped one of the 3 masters clean (reinstall), and now it refuses to join the cluster: master not discovered yet, this node has not…

---

## [About Fleet Agents categority](https://discuss.elastic.co/t/about-fleet-agents-categority/321844)

<div class="topic-metadata">

**Author:** [@cybersirp](https://discuss.elastic.co/u/cybersirp)\
**Replies:** 1\
**Last updated:** [January 9, 2023, 9:38am UTC](https://discuss.elastic.co/t/about-fleet-agents-categority/321844 "2023-01-09T09:38:33Z")

</div>

How is the consumption of resources related to the number of agents that we deploy in our organizations calculated? Is there a formula to be able to have an approximate amount of resources needed for each agent that wil…

---

## [Yearly reset of cumulative sum with monthly buckets](https://discuss.elastic.co/t/yearly-reset-of-cumulative-sum-with-monthly-buckets/321315)

<div class="topic-metadata">

**Author:** [@Jonas\_S](https://discuss.elastic.co/u/Jonas_S)\
**Replies:** 2\
**Last updated:** [January 9, 2023, 9:36am UTC](https://discuss.elastic.co/t/yearly-reset-of-cumulative-sum-with-monthly-buckets/321315 "2023-01-09T09:36:49Z")

</div>

Hello, i have a table lens with a monthly date histogram and a cumulative sum column. Is there a way to "reset" the cumulative sum to 0 at the start of a year? So 1.1.2007 would start with 0 instead of 3867 from the…

---

## [Webhdfs Output plugin does not working with use\_kerberos\_auth](https://discuss.elastic.co/t/webhdfs-output-plugin-does-not-working-with-use-kerberos-auth/322714)

<div class="topic-metadata">

**Author:** [@vincent.ea3](https://discuss.elastic.co/u/vincent.ea3)\
**Replies:** 0\
**Last updated:** [January 9, 2023, 9:20am UTC](https://discuss.elastic.co/t/webhdfs-output-plugin-does-not-working-with-use-kerberos-auth/322714 "2023-01-09T09:20:05Z")

</div>

Hello, I am working to deploy logstash in k8s container to output message to hadoop. https://github.com/elastic/helm-charts According to the documentation, webHDFS and Kerberos authentication are supported. https://w…

[Previous page](https://discuss.elastic.co/tag/none.md?no_tags=true&page=460)

[Next page](https://discuss.elastic.co/tag/none.md?no_tags=true&page=462)
