# \#none

**URL:** https://discuss.elastic.co/tag/none.md?no_tags=true&page=462

[Latest](https://discuss.elastic.co/latest.md) · [Categories](https://discuss.elastic.co/categories.md) · [Tags](https://discuss.elastic.co/tags.md)

**Page:** 463

---

## [Error: \[config validation of \[elasticsearch\].serviceAccountToken\]: serviceAccountToken cannot be specified when "username" is also set](https://discuss.elastic.co/t/error-config-validation-of-elasticsearch-serviceaccounttoken-serviceaccounttoken-cannot-be-specified-when-username-is-also-set/321020)

<div class="topic-metadata">

**Author:** [@iLucas.Bechlte.exe](https://discuss.elastic.co/u/iLucas.Bechlte.exe)\
**Replies:** 0\
**Last updated:** [December 12, 2022, 11:04am UTC](https://discuss.elastic.co/t/error-config-validation-of-elasticsearch-serviceaccounttoken-serviceaccounttoken-cannot-be-specified-when-username-is-also-set/321020 "2022-12-12T11:04:39Z")

</div>

Hello, when I try to follow this instruction to secure my Elastic Stack, I will get this error: Error: \[config validation of \[elasticsearch\].serviceAccountToken\]: serviceAccountToken cannot be specified when "username"…

---

## [Moving license from old cluster nodes to new ones](https://discuss.elastic.co/t/moving-license-from-old-cluster-nodes-to-new-ones/322592)

<div class="topic-metadata">

**Author:** [@Nick.Evans](https://discuss.elastic.co/u/Nick.Evans)\
**Replies:** 7\
**Last updated:** [January 9, 2023, 6:27am UTC](https://discuss.elastic.co/t/moving-license-from-old-cluster-nodes-to-new-ones/322592 "2023-01-09T06:27:48Z")

</div>

We have a 3 node elasticsearch cluster. (node-1, node-2, node-3) We have a need to introduce 3 new nodes and fail out the original 3. I have built nodes 4, 5 and 6 and successfully added them to cluster. Once the clus…

---

## [Why translog\_ops still greater than 0 after flush](https://discuss.elastic.co/t/why-translog-ops-still-greater-than-0-after-flush/322095)

<div class="topic-metadata">

**Author:** [@DJ\_Zhu](https://discuss.elastic.co/u/DJ_Zhu)\
**Replies:** 1\
**Last updated:** [January 9, 2023, 6:26am UTC](https://discuss.elastic.co/t/why-translog-ops-still-greater-than-0-after-flush/322095 "2023-01-09T06:26:53Z")

</div>

I want to move shards between different kind of nodes in my cluster. First, I stop write any docs into index and invoked POST my\_idx/\_flush to commit translog to lucene. Then change the index.routing.allocation.require …

---

## [Wildcard Queries Vs Query\_string Queries](https://discuss.elastic.co/t/wildcard-queries-vs-query-string-queries/322692)

<div class="topic-metadata">

**Author:** [@Sheharyar\_Khalid](https://discuss.elastic.co/u/Sheharyar_Khalid)\
**Replies:** 1\
**Last updated:** [January 9, 2023, 5:21am UTC](https://discuss.elastic.co/t/wildcard-queries-vs-query-string-queries/322692 "2023-01-09T05:21:39Z")

</div>

Hello, I am looking for wildcard matching of events on log data in elasticsearch. For example i want to match IP addresses in my data but I only know the ending address (i want to match to 192.100.1.1 but i search for \*…

---

## [Elastic won't send data to Kibana](https://discuss.elastic.co/t/elastic-wont-send-data-to-kibana/318833)

<div class="topic-metadata">

**Author:** [@zerratriani](https://discuss.elastic.co/u/zerratriani)\
**Replies:** 3\
**Last updated:** [November 14, 2022, 7:19am UTC](https://discuss.elastic.co/t/elastic-wont-send-data-to-kibana/318833 "2022-11-14T07:19:38Z")

</div>

Hallo, I have a configuration like the following, but elastic can't retrieve the logs. And the plain-log .log also doesn't show the activation log. How else can I confirm that logstash and filebeat are connected and tran…

---

## [Wildcard search on all fields](https://discuss.elastic.co/t/wildcard-search-on-all-fields/322693)

<div class="topic-metadata">

**Author:** [@Sheharyar\_Khalid](https://discuss.elastic.co/u/Sheharyar_Khalid)\
**Replies:** 2\
**Last updated:** [January 9, 2023, 2:55am UTC](https://discuss.elastic.co/t/wildcard-search-on-all-fields/322693 "2023-01-09T02:55:08Z")

</div>

Hello, I want to search a wildcard string on all fields of a document. Is there any way to do it? I was able to write this query but for some reason it always returns empty. {"bool": {"must" : \[{"wildcard": {"\_all": "…

---

## [Logstash pkg update results log prasing stopped](https://discuss.elastic.co/t/logstash-pkg-update-results-log-prasing-stopped/322542)

<div class="topic-metadata">

**Author:** [@Dilipssn](https://discuss.elastic.co/u/Dilipssn)\
**Replies:** 7\
**Last updated:** [January 9, 2023, 1:57am UTC](https://discuss.elastic.co/t/logstash-pkg-update-results-log-prasing-stopped/322542 "2023-01-09T01:57:50Z")

</div>

Hello Team, We have logstash to push the logs from one server to other, where all the traps are collected. Through which we plot graphs in "Grafana". The port number in which logs parsing is "7546". until "logstash-7…

---

## [Date histogram aggregation seems incorrect with calendar\_interval and when offset \>= 30 days](https://discuss.elastic.co/t/date-histogram-aggregation-seems-incorrect-with-calendar-interval-and-when-offset-30-days/322492)

<div class="topic-metadata">

**Author:** [@xiaofei](https://discuss.elastic.co/u/xiaofei)\
**Replies:** 3\
**Last updated:** [January 9, 2023, 1:26am UTC](https://discuss.elastic.co/t/date-histogram-aggregation-seems-incorrect-with-calendar-interval-and-when-offset-30-days/322492 "2023-01-09T01:26:23Z")

</div>

Based on this doc, elasticsearch supports Calendar-aware interval on data histogram aggregation. Specially for a "quarter" interval: "One quarter is the interval between the start day of the month and time of day and t…

---

## [How to get average of items in an array of a nested field?](https://discuss.elastic.co/t/how-to-get-average-of-items-in-an-array-of-a-nested-field/322690)

<div class="topic-metadata">

**Author:** [@learningelastic](https://discuss.elastic.co/u/learningelastic)\
**Replies:** 4\
**Last updated:** [January 9, 2023, 12:32am UTC](https://discuss.elastic.co/t/how-to-get-average-of-items-in-an-array-of-a-nested-field/322690 "2023-01-09T00:32:28Z")

</div>

I'm trying to get the average price of products that are in stock across my different physical warehouses. I made this index: PUT warehouse POST warehouse/\_mapping { "properties": { "inventory": { "prope…

---

## [PHP Client 8.5 Not Response Data](https://discuss.elastic.co/t/php-client-8-5-not-response-data/322670)

<div class="topic-metadata">

**Author:** [@vcamargo](https://discuss.elastic.co/u/vcamargo)\
**Replies:** 1\
**Last updated:** [January 9, 2023, 12:07am UTC](https://discuss.elastic.co/t/php-client-8-5-not-response-data/322670 "2023-01-09T00:07:05Z")

</div>

When try request do elastic using php client response it's returning always null, I've try using "search", "get" methodos and not working, when a try use postman request it's working, sample code below Request Status Co…

---

## [Using NDJSON for Logstash HTTP Output Plugin](https://discuss.elastic.co/t/using-ndjson-for-logstash-http-output-plugin/322683)

<div class="topic-metadata">

**Author:** [@gs04](https://discuss.elastic.co/u/gs04)\
**Replies:** 0\
**Last updated:** [January 8, 2023, 3:29pm UTC](https://discuss.elastic.co/t/using-ndjson-for-logstash-http-output-plugin/322683 "2023-01-08T15:29:00Z")

</div>

I'm looking to use a Logstash http output plugin to send a batch of JSON events where all the events are stored in the HTTP message as new-line delimited JSON events. For example, we'd need the data of the HTTP transmis…

---

## [Kubernetes Logstash statefulset under a Service of type Load Balancer (Amazon EKS) uneven distribution of events between pods](https://discuss.elastic.co/t/kubernetes-logstash-statefulset-under-a-service-of-type-load-balancer-amazon-eks-uneven-distribution-of-events-between-pods/322578)

<div class="topic-metadata">

**Author:** [@vikasp](https://discuss.elastic.co/u/vikasp)\
**Replies:** 3\
**Last updated:** [January 8, 2023, 3:08pm UTC](https://discuss.elastic.co/t/kubernetes-logstash-statefulset-under-a-service-of-type-load-balancer-amazon-eks-uneven-distribution-of-events-between-pods/322578 "2023-01-08T15:08:20Z")

</div>

I am working with a self managed elasticsearch cluster hosted in Amazon EKS. The pipeline flow is: filebeat agent is deployed in all ec2 servers seding data to logstash. https://logstash.company.com:5046. Logstash is …

---

## [Json data from Filebeat to Logstash](https://discuss.elastic.co/t/json-data-from-filebeat-to-logstash/322672)

<div class="topic-metadata">

**Author:** [@Hamburglar](https://discuss.elastic.co/u/Hamburglar)\
**Replies:** 4\
**Last updated:** [January 8, 2023, 1:54pm UTC](https://discuss.elastic.co/t/json-data-from-filebeat-to-logstash/322672 "2023-01-08T13:54:35Z")

</div>

Json data to be ingested: /var/log/file.json {"event\_type":"temp","time":"2023-01-07 23:30:12","temp":64.0,"fan":2291} {"event\_type":"temp","time":"2023-01-07 23:30:22","temp":63.0,"fan":2308} {"event\_type":"temp","time…

---

## [Illegal\_argument\_exception](https://discuss.elastic.co/t/illegal-argument-exception/320962)

<div class="topic-metadata">

**Author:** [@Jinhyuck\_Cha](https://discuss.elastic.co/u/Jinhyuck_Cha)\
**Replies:** 1\
**Last updated:** [December 11, 2022, 4:38pm UTC](https://discuss.elastic.co/t/illegal-argument-exception/320962 "2022-12-11T16:38:55Z")

</div>

Hi i'm try to query to Elasticsearch in kibana But I got some error in there How can I solve it? this is my query POST dingo-dev-images-enriched-index-v1/\_search { "query": { "bool": { "filter": \[ …

---

## [Jdbc mongo plugin](https://discuss.elastic.co/t/jdbc-mongo-plugin/322282)

<div class="topic-metadata">

**Author:** [@reza\_sabz](https://discuss.elastic.co/u/reza_sabz)\
**Replies:** 2\
**Last updated:** [January 8, 2023, 8:58am UTC](https://discuss.elastic.co/t/jdbc-mongo-plugin/322282 "2023-01-08T08:58:46Z")

</div>

Hello every one I want to connect mongodb to elastic via logstash. I did a lot of research on this. I checked and tested many methods. Finally, I reached jdbc. I have a problem in configuring this plugin and somehow I i…

---

## [How to encrypt Elasticsearch data path](https://discuss.elastic.co/t/how-to-encrypt-elasticsearch-data-path/322562)

<div class="topic-metadata">

**Author:** [@Naga\_Prudhvi](https://discuss.elastic.co/u/Naga_Prudhvi)\
**Replies:** 3\
**Last updated:** [January 8, 2023, 6:21am UTC](https://discuss.elastic.co/t/how-to-encrypt-elasticsearch-data-path/322562 "2023-01-08T06:21:55Z")

</div>

I want to perform dm-crypt encryption at rest for all data path for Elasticsearch but it should be searchable if I try to access data from hadoop/spark/kibana. Any ideas on this would be very appreciated.

---

## [Visualize data by two fields](https://discuss.elastic.co/t/visualize-data-by-two-fields/316819)

<div class="topic-metadata">

**Author:** [@Kohlman](https://discuss.elastic.co/u/Kohlman)\
**Replies:** 1\
**Last updated:** [October 18, 2022, 6:54am UTC](https://discuss.elastic.co/t/visualize-data-by-two-fields/316819 "2022-10-18T06:54:56Z")

</div>

We have multiple clients. Each client has there own instance of our database. While there may be subtle differences in schema as we continue to make enhancements. For purposes of this question we can assume they are the …

---

## [Can ES single node use index lifecycle management(ILM)?](https://discuss.elastic.co/t/can-es-single-node-use-index-lifecycle-management-ilm/322664)

<div class="topic-metadata">

**Author:** [@jacksparrow414](https://discuss.elastic.co/u/jacksparrow414)\
**Replies:** 2\
**Last updated:** [January 8, 2023, 2:06am UTC](https://discuss.elastic.co/t/can-es-single-node-use-index-lifecycle-management-ilm/322664 "2023-01-08T02:06:56Z")

</div>

I checked the official documentation, which only mentioned clusters, I wonder if a single node supports ILM? According to my understanding, a single-node ES has all node roles and all data tiers, so it should support IL…

---

## [Status of hosts with ELK](https://discuss.elastic.co/t/status-of-hosts-with-elk/318738)

<div class="topic-metadata">

**Author:** [@kurdit](https://discuss.elastic.co/u/kurdit)\
**Replies:** 3\
**Last updated:** [November 13, 2022, 11:08am UTC](https://discuss.elastic.co/t/status-of-hosts-with-elk/318738 "2022-11-13T11:08:03Z")

</div>

hello friends! I have the following task: it is necessary to monitor hundreds of hosts (virtual machines). now they are monitored using Nagios, but I want to get a clear visualization of the availability of hosts. ther…

---

## [S3 output: Is there a way to have every event in its own file?](https://discuss.elastic.co/t/s3-output-is-there-a-way-to-have-every-event-in-its-own-file/322663)

<div class="topic-metadata">

**Author:** [@rickfish](https://discuss.elastic.co/u/rickfish)\
**Replies:** 4\
**Last updated:** [January 7, 2023, 6:57pm UTC](https://discuss.elastic.co/t/s3-output-is-there-a-way-to-have-every-event-in-its-own-file/322663 "2023-01-07T18:57:43Z")

</div>

I have an unusual requirement to put every event in a separate file in an s3 bucket. I have tried to use this: rotation\_strategy =\> "size" size\_file =\> 1 but that is just an estimate and it still puts multiple events i…

---

## [After 6.8 -\> 7.17 upgrade, logstash not sending data to logstash-\* indexes](https://discuss.elastic.co/t/after-6-8-7-17-upgrade-logstash-not-sending-data-to-logstash-indexes/322479)

<div class="topic-metadata">

**Author:** [@willdennis](https://discuss.elastic.co/u/willdennis)\
**Replies:** 7\
**Last updated:** [January 7, 2023, 4:45pm UTC](https://discuss.elastic.co/t/after-6-8-7-17-upgrade-logstash-not-sending-data-to-logstash-indexes/322479 "2023-01-07T16:45:48Z")

</div>

Hi all, Did an upgrade to my single-node cluster yesterday evening, now up on 7.17.8 and everything's basically working, except that it seems that Logstash is no longer creating logstash-\<YYYY.MM.DD\> indexes... I see th…

---

## [Kibana time filter change dynamically API](https://discuss.elastic.co/t/kibana-time-filter-change-dynamically-api/316732)

<div class="topic-metadata">

**Author:** [@PabloCuestaGarcia](https://discuss.elastic.co/u/PabloCuestaGarcia)\
**Replies:** 1\
**Last updated:** [October 17, 2022, 11:48pm UTC](https://discuss.elastic.co/t/kibana-time-filter-change-dynamically-api/316732 "2022-10-17T23:48:21Z")

</div>

Hi all. I would like to know if it is possible to dynamically change the time range in Kibana according to the last load data. I mean, I have an ETL loading data every day, but some days the data comes empty, the proce…

---

## [Kibana error when enabling xpack security](https://discuss.elastic.co/t/kibana-error-when-enabling-xpack-security/322666)

<div class="topic-metadata">

**Author:** [@francis009](https://discuss.elastic.co/u/francis009)\
**Replies:** 7\
**Last updated:** [January 7, 2023, 4:23pm UTC](https://discuss.elastic.co/t/kibana-error-when-enabling-xpack-security/322666 "2023-01-07T16:23:49Z")

</div>

Hi, i've look through the forums and found many people having errors when enabling xpack, but not exactly my error, if i enable xpack on elasticsearch it pops up the log in when i access the website, but when i enable it…

---

## [Query on Elastic Observability Engineer Exam](https://discuss.elastic.co/t/query-on-elastic-observability-engineer-exam/322489)

<div class="topic-metadata">

**Author:** [@chris3](https://discuss.elastic.co/u/chris3)\
**Replies:** 3\
**Last updated:** [January 7, 2023, 4:05pm UTC](https://discuss.elastic.co/t/query-on-elastic-observability-engineer-exam/322489 "2023-01-07T16:05:15Z")

</div>

Hi, I think I have the correct forum to post this in. I can setup an Elastic cluster no problem, the main query I have is surrounding APM server and the agents. I recently took the virtual instructor course for Elastic…

---

## [Elasticsearch not starting, with no errors in the logs](https://discuss.elastic.co/t/elasticsearch-not-starting-with-no-errors-in-the-logs/322660)

<div class="topic-metadata">

**Author:** [@sphawk](https://discuss.elastic.co/u/sphawk)\
**Replies:** 3\
**Last updated:** [January 7, 2023, 11:29am UTC](https://discuss.elastic.co/t/elasticsearch-not-starting-with-no-errors-in-the-logs/322660 "2023-01-07T11:29:34Z")

</div>

I've updated debian to buster version without no problem and today I've tried to update ES to 8.5 version. Bad idea (some Java problem) so I've reinstalled previous version (6.x) but ES still not starting. service elas…

---

## [Upgraded first node from 7.17.5 to 8.4. Won't start, claiming there is a 6.4.5 index, but I can't find it](https://discuss.elastic.co/t/upgraded-first-node-from-7-17-5-to-8-4-wont-start-claiming-there-is-a-6-4-5-index-but-i-cant-find-it/317811)

<div class="topic-metadata">

**Author:** [@Brett\_C](https://discuss.elastic.co/u/Brett_C)\
**Replies:** 11\
**Last updated:** [January 7, 2023, 10:57am UTC](https://discuss.elastic.co/t/upgraded-first-node-from-7-17-5-to-8-4-wont-start-claiming-there-is-a-6-4-5-index-but-i-cant-find-it/317811 "2023-01-07T10:57:10Z")

</div>

Hi Everyone, I have just started upgrading my cluster from 7.17.5 to 8.4. I completed the first node, but when I went to start the service, it complained that: \[2022-10-31T17:08:08,683\]\[ERROR\]\[o.e.b.Elasticsearch \]…

---

## [Divide Number in Y axis by 10 in TSVB Vizualization](https://discuss.elastic.co/t/divide-number-in-y-axis-by-10-in-tsvb-vizualization/320584)

<div class="topic-metadata">

**Author:** [@Divyank\_Mahalle](https://discuss.elastic.co/u/Divyank_Mahalle)\
**Replies:** 2\
**Last updated:** [December 10, 2022, 9:38am UTC](https://discuss.elastic.co/t/divide-number-in-y-axis-by-10-in-tsvb-vizualization/320584 "2022-12-10T09:38:24Z")

</div>

Hi, I am trying to Build Viz in Kibana Version 7.6. I want to divide number present in Y axis by 10. I tried filtering options but it did not worked out, may be I am missing something. Current viz Snap: Pls let me…

---

## [How can display horizontal bar on the Timelion? (or another chart)](https://discuss.elastic.co/t/how-can-display-horizontal-bar-on-the-timelion-or-another-chart/320661)

<div class="topic-metadata">

**Author:** [@Cusis\_Eel](https://discuss.elastic.co/u/Cusis_Eel)\
**Replies:** 4\
**Last updated:** [December 10, 2022, 3:28am UTC](https://discuss.elastic.co/t/how-can-display-horizontal-bar-on-the-timelion-or-another-chart/320661 "2022-12-10T03:28:11Z")

</div>

Help this please. (sample json too) Thanks.

---

## [Kibana Security Analyst Lab Issue](https://discuss.elastic.co/t/kibana-security-analyst-lab-issue/322650)

<div class="topic-metadata">

**Author:** [@david.mew](https://discuss.elastic.co/u/david.mew)\
**Replies:** 0\
**Last updated:** [January 7, 2023, 1:26am UTC](https://discuss.elastic.co/t/kibana-security-analyst-lab-issue/322650 "2023-01-07T01:26:10Z")

</div>

I am taking the training and I have several questions about the labs... Lab 6.2 is where I am having issues... #6, where is the all types drop down menu? I clicked on ML but don't see anomaly chart. #7 where is the .m…

---

## [Agent stuck on updating after install](https://discuss.elastic.co/t/agent-stuck-on-updating-after-install/322641)

<div class="topic-metadata">

**Author:** [@legoguy1000](https://discuss.elastic.co/u/legoguy1000)\
**Replies:** 0\
**Last updated:** [January 6, 2023, 9:37pm UTC](https://discuss.elastic.co/t/agent-stuck-on-updating-after-install/322641 "2023-01-06T21:37:45Z")

</div>

Continuing the discussion from Agent stuck on updating but still send index: We are also seeing this. We have Fleet deployed in ECK. We have 2 fleet servers listed in Kibana, one url is the k8s internal Cluster DNS FQ…

[Previous page](https://discuss.elastic.co/tag/none.md?no_tags=true&page=461)

[Next page](https://discuss.elastic.co/tag/none.md?no_tags=true&page=463)
