# \#none

**URL:** https://discuss.elastic.co/tag/none.md?no_tags=true&page=481

[Latest](https://discuss.elastic.co/latest.md) · [Categories](https://discuss.elastic.co/categories.md) · [Tags](https://discuss.elastic.co/tags.md)

**Page:** 482

---

## [Error on uploading ML model to Elasticsearch](https://discuss.elastic.co/t/error-on-uploading-ml-model-to-elasticsearch/320803)

<div class="topic-metadata">

**Author:** [@Odd\_Erik\_Gronberg](https://discuss.elastic.co/u/Odd_Erik_Gronberg)\
**Replies:** 0\
**Last updated:** [December 8, 2022, 3:18pm UTC](https://discuss.elastic.co/t/error-on-uploading-ml-model-to-elasticsearch/320803 "2022-12-08T15:18:28Z")

</div>

I am trying to upload a ML model to Elasticsearch through the Eland client but there seems to be some issues. The model I am trying to upload is listed as a Compatible third party model in the documentation here: Mode…

---

## [How to use min\_score parameter in ES percolator query?](https://discuss.elastic.co/t/how-to-use-min-score-parameter-in-es-percolator-query/320845)

<div class="topic-metadata">

**Author:** [@aneeshkoya](https://discuss.elastic.co/u/aneeshkoya)\
**Replies:** 2\
**Last updated:** [December 9, 2022, 6:28am UTC](https://discuss.elastic.co/t/how-to-use-min-score-parameter-in-es-percolator-query/320845 "2022-12-09T06:28:20Z")

</div>

Hi all. My case scenario is such that when the documents are percolated against the stored queries, only those queries that have a score greater than a threshold give a hit for the respective document. I tried min\_score…

---

## [Can We move mapping and template without moving data with snapshot and restore?](https://discuss.elastic.co/t/can-we-move-mapping-and-template-without-moving-data-with-snapshot-and-restore/320857)

<div class="topic-metadata">

**Author:** [@Vijaykumar\_Deshmukh1](https://discuss.elastic.co/u/Vijaykumar_Deshmukh1)\
**Replies:** 2\
**Last updated:** [December 9, 2022, 6:16am UTC](https://discuss.elastic.co/t/can-we-move-mapping-and-template-without-moving-data-with-snapshot-and-restore/320857 "2022-12-09T06:16:56Z")

</div>

Is it Possible? like i dont want take snapshot of any index but just want to take snapshot of cluster state and restore it !

---

## [What exactly elasticsearch is? Is it database or search engine](https://discuss.elastic.co/t/what-exactly-elasticsearch-is-is-it-database-or-search-engine/320856)

<div class="topic-metadata">

**Author:** [@Vijaykumar\_Deshmukh1](https://discuss.elastic.co/u/Vijaykumar_Deshmukh1)\
**Replies:** 2\
**Last updated:** [December 9, 2022, 6:10am UTC](https://discuss.elastic.co/t/what-exactly-elasticsearch-is-is-it-database-or-search-engine/320856 "2022-12-09T06:10:15Z")

</div>

Just Want Clarity Please Help

---

## [Kibana equivalent to lookup table](https://discuss.elastic.co/t/kibana-equivalent-to-lookup-table/320839)

<div class="topic-metadata">

**Author:** [@Matt.Wash](https://discuss.elastic.co/u/Matt.Wash)\
**Replies:** 1\
**Last updated:** [December 9, 2022, 5:48am UTC](https://discuss.elastic.co/t/kibana-equivalent-to-lookup-table/320839 "2022-12-09T05:48:49Z")

</div>

I have a list of all user.names in a lens table and another list of user.names in another table. I want to perform lookup between the two tables to create a list of user.names are in the first table but not in the other …

---

## [A logstash to bigquery transmission problem](https://discuss.elastic.co/t/a-logstash-to-bigquery-transmission-problem/320771)

<div class="topic-metadata">

**Author:** [@dalaopo](https://discuss.elastic.co/u/dalaopo)\
**Replies:** 4\
**Last updated:** [December 9, 2022, 2:01am UTC](https://discuss.elastic.co/t/a-logstash-to-bigquery-transmission-problem/320771 "2022-12-09T02:01:50Z")

</div>

Hello！ I encountered an error when I used logstash to transfer kafka data to google bigquery \[ERROR\]\[logstash.outputs.googlebigquery\]\[main\]\[30729410306cb4d98635a59cbf171cea3b769fd734b29b17e925785d4edac5ba\] Error upload…

---

## [Fuzzy matching hashtag with Simple Query String Query](https://discuss.elastic.co/t/fuzzy-matching-hashtag-with-simple-query-string-query/320416)

<div class="topic-metadata">

**Author:** [@kabcampbell](https://discuss.elastic.co/u/kabcampbell)\
**Replies:** 2\
**Last updated:** [December 8, 2022, 10:44pm UTC](https://discuss.elastic.co/t/fuzzy-matching-hashtag-with-simple-query-string-query/320416 "2022-12-08T22:44:51Z")

</div>

I have an indexed field named "searchBucket" with the term "#revit" in it. Here is the analyzer applied to that field: "default" : { "filter" : \[ "lowercase", "asciifolding"…

---

## [Elasticsearch can't start service](https://discuss.elastic.co/t/elasticsearch-cant-start-service/320823)

<div class="topic-metadata">

**Author:** [@natthanon\_khr](https://discuss.elastic.co/u/natthanon_khr)\
**Replies:** 2\
**Last updated:** [December 8, 2022, 9:23pm UTC](https://discuss.elastic.co/t/elasticsearch-cant-start-service/320823 "2022-12-08T21:23:39Z")

</div>

I can't start and restart systemctl elasticsearch after reboot server, I want to know what is the reason please. this is log! \[2022-12-09T00:59:50,406\]\[WARN \]\[o.e.b.Natives \] \[vmcbmsudbu01\] unable to load JN…

---

## [Batch Upload with Enrich Policy Suddenly taking much longer](https://discuss.elastic.co/t/batch-upload-with-enrich-policy-suddenly-taking-much-longer/320493)

<div class="topic-metadata">

**Author:** [@cj\_hillbrand](https://discuss.elastic.co/u/cj_hillbrand)\
**Replies:** 2\
**Last updated:** [December 8, 2022, 9:13pm UTC](https://discuss.elastic.co/t/batch-upload-with-enrich-policy-suddenly-taking-much-longer/320493 "2022-12-08T21:13:27Z")

</div>

Hello all, My team has been running a single-vm elasticsearch instance for about a year and we are currently facing an issue when it comes to batch uploading documents, which is also assigned an enrichment policy. To h…

---

## [Error in logstash plain file](https://discuss.elastic.co/t/error-in-logstash-plain-file/320624)

<div class="topic-metadata">

**Author:** [@michaeljsamuel](https://discuss.elastic.co/u/michaeljsamuel)\
**Replies:** 18\
**Last updated:** [December 8, 2022, 8:39pm UTC](https://discuss.elastic.co/t/error-in-logstash-plain-file/320624 "2022-12-08T20:39:04Z")

</div>

Hi there, I am trying to use logstash on windows and believe I have downloaded it correctly however i am unable to forward any logs and this is what is in my plain file \[2022-12-07T10:41:03,853\]\[INFO \]\[logstash.runner …

---

## [Is there an easy way to manage custom ingest pipeline and custom fields for Elastic Agent Integrations?](https://discuss.elastic.co/t/is-there-an-easy-way-to-manage-custom-ingest-pipeline-and-custom-fields-for-elastic-agent-integrations/319682)

<div class="topic-metadata">

**Author:** [@leandrojmp](https://discuss.elastic.co/u/leandrojmp)\
**Replies:** 1\
**Last updated:** [December 8, 2022, 7:01pm UTC](https://discuss.elastic.co/t/is-there-an-easy-way-to-manage-custom-ingest-pipeline-and-custom-fields-for-elastic-agent-integrations/319682 "2022-12-08T19:01:37Z")

</div>

Hello, We are trying to find a way to manage custom ingest pipelines and fields/mappings for our integrations. As an example, we are using the Cisco Duo integration, this integration has the following ingest pipelines. …

---

## [Kibana not accessible in browser after allowing port in firewall-cmd](https://discuss.elastic.co/t/kibana-not-accessible-in-browser-after-allowing-port-in-firewall-cmd/316526)

<div class="topic-metadata">

**Author:** [@mikhatanu](https://discuss.elastic.co/u/mikhatanu)\
**Replies:** 1\
**Last updated:** [October 13, 2022, 10:46pm UTC](https://discuss.elastic.co/t/kibana-not-accessible-in-browser-after-allowing-port-in-firewall-cmd/316526 "2022-10-13T22:46:18Z")

</div>

Hello, i have installed kibana in remote host from ssh. I tried curl from the host and it succeed. I tried to access it from browser, but it said ERR\_CONNECTION\_TIMED\_OUT. here is my firewalld # firewall-cmd --list-…

---

## [How to expose "demo" ECK elastic/kibana services on Kubernetes? loadbalancer?](https://discuss.elastic.co/t/how-to-expose-demo-eck-elastic-kibana-services-on-kubernetes-loadbalancer/320492)

<div class="topic-metadata">

**Author:** [@timb33](https://discuss.elastic.co/u/timb33)\
**Replies:** 2\
**Last updated:** [December 8, 2022, 5:31pm UTC](https://discuss.elastic.co/t/how-to-expose-demo-eck-elastic-kibana-services-on-kubernetes-loadbalancer/320492 "2022-12-08T17:31:34Z")

</div>

Hi, I've following the quickstart demo (Quickstart | Elastic Cloud on Kubernetes \[2.5\] | Elastic) and have an ES I can port-forward to,but I want to be able to access my ES instance using e.g. a loadbalancer. Usually, I…

---

## [Self-hosting and license](https://discuss.elastic.co/t/self-hosting-and-license/320767)

<div class="topic-metadata">

**Author:** [@leo\_girault](https://discuss.elastic.co/u/leo_girault)\
**Replies:** 2\
**Last updated:** [December 8, 2022, 4:52pm UTC](https://discuss.elastic.co/t/self-hosting-and-license/320767 "2022-12-08T16:52:21Z")

</div>

Hi there, First I'm sorry if this question has already been answered but I've not been able to find this information neither on official Elasticsearch documentation nor on Discussion / Forums. So far we are using in my…

---

## [Using ElasticSearch(from ECK) storage with Azure remote storages](https://discuss.elastic.co/t/using-elasticsearch-from-eck-storage-with-azure-remote-storages/320797)

<div class="topic-metadata">

**Author:** [@OlLap](https://discuss.elastic.co/u/OlLap)\
**Replies:** 0\
**Last updated:** [December 8, 2022, 2:09pm UTC](https://discuss.elastic.co/t/using-elasticsearch-from-eck-storage-with-azure-remote-storages/320797 "2022-12-08T14:09:26Z")

</div>

Hello, is it possible to use any of the Azure storage types (Files share or Blob container) with Elasticsearch installed on Azure Kubernetes Cluster? I tried with Azure Disks and everything works, but building Hot-Warm-…

---

## [Logstash | pubsub |Consume the early message instead of the oldest?](https://discuss.elastic.co/t/logstash-pubsub-consume-the-early-message-instead-of-the-oldest/320802)

<div class="topic-metadata">

**Author:** [@dfraz](https://discuss.elastic.co/u/dfraz)\
**Replies:** 0\
**Last updated:** [December 8, 2022, 3:13pm UTC](https://discuss.elastic.co/t/logstash-pubsub-consume-the-early-message-instead-of-the-oldest/320802 "2022-12-08T15:13:50Z")

</div>

Hi Could it be possible to configure logstash to consume the early messages in Pubsub instead of the oldest ? thx for the help.

---

## [Push notification from Elasticsearch to Microsoft teams via Logstash pipeline](https://discuss.elastic.co/t/push-notification-from-elasticsearch-to-microsoft-teams-via-logstash-pipeline/320159)

<div class="topic-metadata">

**Author:** [@niveditakathal](https://discuss.elastic.co/u/niveditakathal)\
**Replies:** 2\
**Last updated:** [December 8, 2022, 1:40pm UTC](https://discuss.elastic.co/t/push-notification-from-elasticsearch-to-microsoft-teams-via-logstash-pipeline/320159 "2022-12-08T13:40:16Z")

</div>

Hi All, I want to send some notifications from Elasticsearch to Microsoft teams via logstash pipeline. Based on my knowledge, I should use http output plugin to connect to Microsoft teams and push notification under me…

---

## [Rollup jobs with distinct/unique count on metrics](https://discuss.elastic.co/t/rollup-jobs-with-distinct-unique-count-on-metrics/318606)

<div class="topic-metadata">

**Author:** [@mikhatanu](https://discuss.elastic.co/u/mikhatanu)\
**Replies:** 1\
**Last updated:** [November 10, 2022, 2:12pm UTC](https://discuss.elastic.co/t/rollup-jobs-with-distinct-unique-count-on-metrics/318606 "2022-11-10T14:12:03Z")

</div>

Hello, i was trying to set up a rollup job in kibana. Is it possible to aggregate using unique/distinct count in metric?

---

## [Is there a way to see the script's console log on observability uptime monitor](https://discuss.elastic.co/t/is-there-a-way-to-see-the-scripts-console-log-on-observability-uptime-monitor/320496)

<div class="topic-metadata">

**Author:** [@ZaidMomin1](https://discuss.elastic.co/u/ZaidMomin1)\
**Replies:** 6\
**Last updated:** [December 8, 2022, 1:19pm UTC](https://discuss.elastic.co/t/is-there-a-way-to-see-the-scripts-console-log-on-observability-uptime-monitor/320496 "2022-12-08T13:19:37Z")

</div>

Hi, Hope you're doing well! We have written the journey for monitoring the web app using playwright and Typescript. We are facing a difficulty to view the script's console.log written with the step, on the uptime monit…

---

## [Not able to delete Project monitor which is undefined](https://discuss.elastic.co/t/not-able-to-delete-project-monitor-which-is-undefined/320572)

<div class="topic-metadata">

**Author:** [@Deepak\_Vyas](https://discuss.elastic.co/u/Deepak_Vyas)\
**Replies:** 1\
**Last updated:** [December 8, 2022, 1:17pm UTC](https://discuss.elastic.co/t/not-able-to-delete-project-monitor-which-is-undefined/320572 "2022-12-08T13:17:30Z")

</div>

Under same project ID "Kingmakers" i see two monitors with same name one is default and one is undefined. I am not able to delete undefined one.

---

## [How to sync data from htttp\_poller](https://discuss.elastic.co/t/how-to-sync-data-from-htttp-poller/320787)

<div class="topic-metadata">

**Author:** [@Rakhshunda\_Noorein\_J](https://discuss.elastic.co/u/Rakhshunda_Noorein_J)\
**Replies:** 0\
**Last updated:** [December 8, 2022, 12:29pm UTC](https://discuss.elastic.co/t/how-to-sync-data-from-htttp-poller/320787 "2022-12-08T12:29:18Z")

</div>

Hello, I am having 1 Billion data coming from an http API. The Api has pagination so that I can fetch data in batches. How can I implement that pagination in logstash using http\_poller plugin... My config file structur…

---

## [Parsing key value pairs from 2 seperate fields into several fields in ingest pipeline](https://discuss.elastic.co/t/parsing-key-value-pairs-from-2-seperate-fields-into-several-fields-in-ingest-pipeline/320782)

<div class="topic-metadata">

**Author:** [@DennisLC](https://discuss.elastic.co/u/DennisLC)\
**Replies:** 0\
**Last updated:** [December 8, 2022, 12:11pm UTC](https://discuss.elastic.co/t/parsing-key-value-pairs-from-2-seperate-fields-into-several-fields-in-ingest-pipeline/320782 "2022-12-08T12:11:44Z")

</div>

I have just started ingesting 0365 audit logs, and I have come across the following field: o365.audit.ExtraProperties.value that I would like to parse out to several fields (as it contains comma seperated values) in my…

---

## [Manipulating Nested Fields](https://discuss.elastic.co/t/manipulating-nested-fields/320768)

<div class="topic-metadata">

**Author:** [@dawiro](https://discuss.elastic.co/u/dawiro)\
**Replies:** 1\
**Last updated:** [December 8, 2022, 10:44am UTC](https://discuss.elastic.co/t/manipulating-nested-fields/320768 "2022-12-08T10:44:45Z")

</div>

Hi, Given a field \[field\]\[sub-field\], how can I move the value from "sub-field" to field? That is, convert this from an object to a string? I've tried: mutate { covert =\> { "field" =\> "string" } } and: mutate {…

---

## [Delete index older than a week](https://discuss.elastic.co/t/delete-index-older-than-a-week/320737)

<div class="topic-metadata">

**Author:** [@Neelam\_Zanvar](https://discuss.elastic.co/u/Neelam_Zanvar)\
**Replies:** 23\
**Last updated:** [December 8, 2022, 10:26am UTC](https://discuss.elastic.co/t/delete-index-older-than-a-week/320737 "2022-12-08T10:26:15Z")

</div>

Currently i have logs from 5 to 6 servers coming to elk. I want to delete all indices older than a week. what is the best way to achieve this? i went through ILM but didn't get the exact way to do this

---

## [Upsert solution Logstash](https://discuss.elastic.co/t/upsert-solution-logstash/320764)

<div class="topic-metadata">

**Author:** [@Vincent001](https://discuss.elastic.co/u/Vincent001)\
**Replies:** 0\
**Last updated:** [December 8, 2022, 9:56am UTC](https://discuss.elastic.co/t/upsert-solution-logstash/320764 "2022-12-08T09:56:36Z")

</div>

Hello, I have a solution with filebeat(on server) -\> logstash(on server) -\> elasticsearch(as service) i have to ingest data from file.log in json format. each row have an "GUID" element wich is use for upsert. there i…

---

## [Upgrade Java for Elasticsearch and logstash](https://discuss.elastic.co/t/upgrade-java-for-elasticsearch-and-logstash/319644)

<div class="topic-metadata">

**Author:** [@Ravi\_Vishwakarma](https://discuss.elastic.co/u/Ravi_Vishwakarma)\
**Replies:** 8\
**Last updated:** [December 8, 2022, 9:19am UTC](https://discuss.elastic.co/t/upgrade-java-for-elasticsearch-and-logstash/319644 "2022-12-08T09:19:37Z")

</div>

Hi, Can anyone let me know how I can upgrade the java JDK on Elasticsearch and logstash. Path : /usr/share/logstash/jdk/ Installed version : 11.0.14.1 2022-02-08 Upgrade to a version greater than 11.0.16 Path : /…

---

## [Http request curl: (52) Empty reply from server](https://discuss.elastic.co/t/http-request-curl-52-empty-reply-from-server/320750)

<div class="topic-metadata">

**Author:** [@hello5346](https://discuss.elastic.co/u/hello5346)\
**Replies:** 6\
**Last updated:** [December 8, 2022, 8:48am UTC](https://discuss.elastic.co/t/http-request-curl-52-empty-reply-from-server/320750 "2022-12-08T08:48:09Z")

</div>

We started a new Elasticsearch instance of 8.4.3 and the ES is up and running but when i am trying to send an HTTP request to the server I get a reply of curl: (52) Empty reply from server but when I pass the certificate…

---

## [Dec 8th, 2022: \[EN\] What you need to know: Elastic Global Threat Report 2022](https://discuss.elastic.co/t/dec-8th-2022-en-what-you-need-to-know-elastic-global-threat-report-2022/320712)

<div class="topic-metadata">

**Author:** [@jakeking](https://discuss.elastic.co/u/jakeking)\
**Replies:** 0\
**Last updated:** [December 8, 2022, 8:00am UTC](https://discuss.elastic.co/t/dec-8th-2022-en-what-you-need-to-know-elastic-global-threat-report-2022/320712 "2022-12-08T08:00:24Z")

</div>

It's been a few weeks since we published the Global Threat Report here at Elastic Security Labs, and we’re immensely happy with the feedback, responses and commentary from the Security Community. Building reports such…

---

## [Logs dont have date in timestamp](https://discuss.elastic.co/t/logs-dont-have-date-in-timestamp/320544)

<div class="topic-metadata">

**Author:** [@kurdit](https://discuss.elastic.co/u/kurdit)\
**Replies:** 2\
**Last updated:** [December 8, 2022, 8:26am UTC](https://discuss.elastic.co/t/logs-dont-have-date-in-timestamp/320544 "2022-12-08T08:26:44Z")

</div>

hi! using logtash I collect logs from communigate, but they come with a timestamp without a date 15:32:37.159 SMTPI-875156(\[40.11.11.11\]) \[33221\] received encrypted, 9618 bytes 15:32:37.160 QUEUE(\[33221\]) from 9618 byt…

---

## [Wrong number of result using match\_phrase\_prefix](https://discuss.elastic.co/t/wrong-number-of-result-using-match-phrase-prefix/318838)

<div class="topic-metadata">

**Author:** [@Gorelldk](https://discuss.elastic.co/u/Gorelldk)\
**Replies:** 12\
**Last updated:** [December 8, 2022, 8:15am UTC](https://discuss.elastic.co/t/wrong-number-of-result-using-match-phrase-prefix/318838 "2022-12-08T08:15:22Z")

</div>

Hi all I have a on-premise ELK instance where i have an index with roughly 50.000 documents with 30 columns. One of the columns is name, indexed as a text. I have 4500 documents called VFCXXXX where the X is numbers, i…

[Previous page](https://discuss.elastic.co/tag/none.md?no_tags=true&page=480)

[Next page](https://discuss.elastic.co/tag/none.md?no_tags=true&page=482)
