# \#none

**URL:** https://discuss.elastic.co/tag/none.md?no_tags=true&page=486

[Latest](https://discuss.elastic.co/latest.md) · [Categories](https://discuss.elastic.co/categories.md) · [Tags](https://discuss.elastic.co/tags.md)

**Page:** 487

---

## [Custom TCP server to receive incoming binary data to Elastic?](https://discuss.elastic.co/t/custom-tcp-server-to-receive-incoming-binary-data-to-elastic/320322)

<div class="topic-metadata">

**Author:** [@kumaresanr](https://discuss.elastic.co/u/kumaresanr)\
**Replies:** 1\
**Last updated:** [December 2, 2022, 5:47am UTC](https://discuss.elastic.co/t/custom-tcp-server-to-receive-incoming-binary-data-to-elastic/320322 "2022-12-02T05:47:58Z")

</div>

I have the following requirement. I run a traffic proxy and the traffic proxy bundle some stats into a custom binary format and can send them to an endpoint via TCP socket. I cannot install a filebeat or such sort in th…

---

## [Pipeline queue is getting filled and never able to control, using below drop filter plugin](https://discuss.elastic.co/t/pipeline-queue-is-getting-filled-and-never-able-to-control-using-below-drop-filter-plugin/320287)

<div class="topic-metadata">

**Author:** [@rravitech](https://discuss.elastic.co/u/rravitech)\
**Replies:** 2\
**Last updated:** [December 2, 2022, 5:01am UTC](https://discuss.elastic.co/t/pipeline-queue-is-getting-filled-and-never-able-to-control-using-below-drop-filter-plugin/320287 "2022-12-02T05:01:19Z")

</div>

I am trying to implement 2 pipelines, when one is about to get blocked, i am trying to drop events form that pipeline. So that the other one, which is half filled or healthy will keep receiving the events. Here in th…

---

## [【Kibana】The line graph problem](https://discuss.elastic.co/t/kibana-the-line-graph-problem/320245)

<div class="topic-metadata">

**Author:** [@ydbdyds](https://discuss.elastic.co/u/ydbdyds)\
**Replies:** 2\
**Last updated:** [December 2, 2022, 2:36am UTC](https://discuss.elastic.co/t/kibana-the-line-graph-problem/320245 "2022-12-02T02:36:11Z")

</div>

I had a problem drawing with Kibana ，Every day I generate a document that looks like the following data structure { "reports":\[ { "url":"test1", "method":"get", "val1":40…

---

## [App search Analytics in Kibana (logs-app\_search.analytics-default)](https://discuss.elastic.co/t/app-search-analytics-in-kibana-logs-app-search-analytics-default/317657)

<div class="topic-metadata">

**Author:** [@moassafiri](https://discuss.elastic.co/u/moassafiri)\
**Replies:** 1\
**Last updated:** [November 4, 2022, 3:17am UTC](https://discuss.elastic.co/t/app-search-analytics-in-kibana-logs-app-search-analytics-default/317657 "2022-11-04T03:17:14Z")

</div>

Is there a way to Filter based on the Engine name from the logs-app\_search.analytics-default Data stream? I can see labels.engine\_id; but this returns a UUID which is not user-friendly. Especially when doing Drill-downs …

---

## [Connect Render.com Log Stream to Elastic Cloud](https://discuss.elastic.co/t/connect-render-com-log-stream-to-elastic-cloud/319704)

<div class="topic-metadata">

**Author:** [@Mike\_Cann](https://discuss.elastic.co/u/Mike_Cann)\
**Replies:** 5\
**Last updated:** [December 1, 2022, 11:59pm UTC](https://discuss.elastic.co/t/connect-render-com-log-stream-to-elastic-cloud/319704 "2022-12-01T23:59:26Z")

</div>

Hi I would like to push my logs from Render.com so that they are viewable / tailable etc in Elastic Cloud. Render.com sends to a syslog drain (Log Streams | Render · Cloud Hosting for Developers) in a standard (RFC5424)…

---

## [Syntax for Pipeline Processor Condition in Kibana](https://discuss.elastic.co/t/syntax-for-pipeline-processor-condition-in-kibana/320303)

<div class="topic-metadata">

**Author:** [@wpm](https://discuss.elastic.co/u/wpm)\
**Replies:** 1\
**Last updated:** [December 1, 2022, 10:50pm UTC](https://discuss.elastic.co/t/syntax-for-pipeline-processor-condition-in-kibana/320303 "2022-12-01T22:50:52Z")

</div>

I would like to write a pipeline that drops the field "A" from a document when its value is the string "None". I want to do this in the Kibana UI. I figure I need a Remove processor when runs on the condition that A == …

---

## [Where is JSON data file located in Strigo LAB environemtn?](https://discuss.elastic.co/t/where-is-json-data-file-located-in-strigo-lab-environemtn/319960)

<div class="topic-metadata">

**Author:** [@Kimberly](https://discuss.elastic.co/u/Kimberly)\
**Replies:** 2\
**Last updated:** [December 1, 2022, 9:36pm UTC](https://discuss.elastic.co/t/where-is-json-data-file-located-in-strigo-lab-environemtn/319960 "2022-12-01T21:36:41Z")

</div>

Due to VPN issue, I could not with Elasticsearch Engineer LAB anymore since Nov 16. In order to continue my LAB, I successfully downloaded Elasticsearch & Kibana 8.5.2. into my personal laptop. Unfortunately, I can neve…

---

## [Re-configure kibana to new cluster](https://discuss.elastic.co/t/re-configure-kibana-to-new-cluster/318068)

<div class="topic-metadata">

**Author:** [@mikhatanu](https://discuss.elastic.co/u/mikhatanu)\
**Replies:** 3\
**Last updated:** [November 3, 2022, 10:04pm UTC](https://discuss.elastic.co/t/re-configure-kibana-to-new-cluster/318068 "2022-11-03T22:04:35Z")

</div>

My kibana is already enrolled on a cluster, but the cluster failed to boot (the PC failed to boot and will be reinstalled). Can I reconfigure kibana to a new cluster? I don't care about losing existing data in kibana as …

---

## [Date Format](https://discuss.elastic.co/t/date-format/320296)

<div class="topic-metadata">

**Author:** [@valleram](https://discuss.elastic.co/u/valleram)\
**Replies:** 0\
**Last updated:** [December 1, 2022, 9:13pm UTC](https://discuss.elastic.co/t/date-format/320296 "2022-12-01T21:13:28Z")

</div>

Hi All, I'm trying to create a mapping for a date field with following format Sun, 06 Nov 2022 05:30:03 +0060 Can you help me with the correct custom date format I need to use, please. I tried with the following for…

---

## [What can be the query for this statement in Elasticsearch DSL](https://discuss.elastic.co/t/what-can-be-the-query-for-this-statement-in-elasticsearch-dsl/320275)

<div class="topic-metadata">

**Author:** [@Aniket\_Pant](https://discuss.elastic.co/u/Aniket_Pant)\
**Replies:** 2\
**Last updated:** [December 1, 2022, 5:51pm UTC](https://discuss.elastic.co/t/what-can-be-the-query-for-this-statement-in-elasticsearch-dsl/320275 "2022-12-01T17:51:41Z")

</div>

I am trying to have this query in elasticsearch statement: (ip=xx.xx.xx.xx and status="running") or (ip=xx.xx.xx.xx and status="running") can anyone tell me how can i write this in elasticsearch.

---

## [Dell iDrac Syslog Grok Logstash](https://discuss.elastic.co/t/dell-idrac-syslog-grok-logstash/320198)

<div class="topic-metadata">

**Author:** [@rcraigncs](https://discuss.elastic.co/u/rcraigncs)\
**Replies:** 2\
**Last updated:** [December 1, 2022, 5:32pm UTC](https://discuss.elastic.co/t/dell-idrac-syslog-grok-logstash/320198 "2022-12-01T17:32:24Z")

</div>

I am looking for help to grok Syslog from Dell idrac I am having problems taking the grok below and making it work with a Logstash. Your help is deeply appreciated! Extracting additional fields from iDRAC logs I found o…

---

## [Distance query with grouping and sorting](https://discuss.elastic.co/t/distance-query-with-grouping-and-sorting/320272)

<div class="topic-metadata">

**Author:** [@dthomas](https://discuss.elastic.co/u/dthomas)\
**Replies:** 0\
**Last updated:** [December 1, 2022, 4:44pm UTC](https://discuss.elastic.co/t/distance-query-with-grouping-and-sorting/320272 "2022-12-01T16:44:33Z")

</div>

I have a single index that represents the locations of buildings in the United States. Each buildings is owned by a company (hence the CompanyId property). The index looks something like this: (fake geo-coordinates). { …

---

## [Difference of aggregated value that grouped by two fields across time](https://discuss.elastic.co/t/difference-of-aggregated-value-that-grouped-by-two-fields-across-time/317906)

<div class="topic-metadata">

**Author:** [@amylyu](https://discuss.elastic.co/u/amylyu)\
**Replies:** 7\
**Last updated:** [November 3, 2022, 5:50pm UTC](https://discuss.elastic.co/t/difference-of-aggregated-value-that-grouped-by-two-fields-across-time/317906 "2022-11-03T17:50:25Z")

</div>

Hi, we are getting data into elastic through Kafka Prometheus endpoint and trying to create a visualization which would help us show latest ingestion rate in each kafka topics. In order to achieve this, we need to group …

---

## [Kiabana completing setup blocked](https://discuss.elastic.co/t/kiabana-completing-setup-blocked/319497)

<div class="topic-metadata">

**Author:** [@ardue](https://discuss.elastic.co/u/ardue)\
**Replies:** 2\
**Last updated:** [December 1, 2022, 3:33pm UTC](https://discuss.elastic.co/t/kiabana-completing-setup-blocked/319497 "2022-12-01T15:33:44Z")

</div>

Hello, I have a problem with kibana, when connecting elasticsearch on kibana, it remains blocked on "completing setup" Here is the error in the log Action failed with '\[index\_not\_green\_timeout\] Timeout waiting for t…

---

## [Upgrade elasticsearch to 8.x](https://discuss.elastic.co/t/upgrade-elasticsearch-to-8-x/320250)

<div class="topic-metadata">

**Author:** [@tegerei](https://discuss.elastic.co/u/tegerei)\
**Replies:** 1\
**Last updated:** [December 1, 2022, 2:45pm UTC](https://discuss.elastic.co/t/upgrade-elasticsearch-to-8-x/320250 "2022-12-01T14:45:22Z")

</div>

Hi, I am planning to upgrade Elasticsearch from 7.10 to 8.x. However I am not sure what will happen to multiple endpoints sending logs to ES using filebeat 7.10. Will I also need to upgrade the filebeat instances? Than…

---

## [Logstash(6.5.4) elasticsearch output](https://discuss.elastic.co/t/logstash-6-5-4-elasticsearch-output/320219)

<div class="topic-metadata">

**Author:** [@gyrao\_72](https://discuss.elastic.co/u/gyrao_72)\
**Replies:** 5\
**Last updated:** [December 1, 2022, 1:10pm UTC](https://discuss.elastic.co/t/logstash-6-5-4-elasticsearch-output/320219 "2022-12-01T13:10:10Z")

</div>

My filebeat is on two servers. let's say app1 and app2 My logs are in the format jobID status data Example: app1 log 5hgsxyt3838 SCHEDULED data app2 log 5hgsxyt3838 COMPLETE data Here both these logs have the sam…

---

## [Trying to send logs to AWS CloudWatch via logstash output plugin](https://discuss.elastic.co/t/trying-to-send-logs-to-aws-cloudwatch-via-logstash-output-plugin/320238)

<div class="topic-metadata">

**Author:** [@Randika\_Madhushan](https://discuss.elastic.co/u/Randika_Madhushan)\
**Replies:** 0\
**Last updated:** [December 1, 2022, 12:25pm UTC](https://discuss.elastic.co/t/trying-to-send-logs-to-aws-cloudwatch-via-logstash-output-plugin/320238 "2022-12-01T12:25:54Z")

</div>

Hello there, Currently, I'm trying to send the applications logs to AWS CloudWatch via logstash agent output plugin. So I tried the below configuration. But that did not work. Could you please help with this? input { …

---

## [Kibana starting with fatal error no such file](https://discuss.elastic.co/t/kibana-starting-with-fatal-error-no-such-file/319983)

<div class="topic-metadata">

**Author:** [@steves](https://discuss.elastic.co/u/steves)\
**Replies:** 10\
**Last updated:** [December 1, 2022, 10:33am UTC](https://discuss.elastic.co/t/kibana-starting-with-fatal-error-no-such-file/319983 "2022-12-01T10:33:11Z")

</div>

I just installed Kibana after getting Elasticsearch running (secure), both installed with apt, on an Ubuntu 22.04 Server. I start Kibana with systemctl start kibana.service or for debugging ./bin/kibana which results …

---

## [Prevent thai tokenizer from tokenizing hashtag](https://discuss.elastic.co/t/prevent-thai-tokenizer-from-tokenizing-hashtag/320225)

<div class="topic-metadata">

**Author:** [@TFP](https://discuss.elastic.co/u/TFP)\
**Replies:** 0\
**Last updated:** [December 1, 2022, 8:19am UTC](https://discuss.elastic.co/t/prevent-thai-tokenizer-from-tokenizing-hashtag/320225 "2022-12-01T08:19:03Z")

</div>

I'm currently using the thai tokenizer and wanted to preserve hashtag words but the tokenizer keeps on removing the hashtag symbol. ES version: 7.16.2 GET /\_analyze { "tokenizer": "thai", "text": "#รายการพ #hashtag" …

---

## [Dec 1st, 2022: \[PT\] Elastic Agent 101](https://discuss.elastic.co/t/dec-1st-2022-pt-elastic-agent-101/319992)

<div class="topic-metadata">

**Author:** [@AndersonQ](https://discuss.elastic.co/u/AndersonQ)\
**Replies:** 0\
**Last updated:** [December 1, 2022, 8:00am UTC](https://discuss.elastic.co/t/dec-1st-2022-pt-elastic-agent-101/319992 "2022-12-01T08:00:30Z")

</div>

Este artigo também está disponível em inglês. Primeiro, o que é o Elastic Agent? Elatic Agent é uma forma única e unificada de adicionar monitoramento para logs, métricas e outros tipos de dados em um host. Ele tam…

---

## [Dec 1st, 2022: \[EN\] Elastic Agent 101](https://discuss.elastic.co/t/dec-1st-2022-en-elastic-agent-101/316879)

<div class="topic-metadata">

**Author:** [@AndersonQ](https://discuss.elastic.co/u/AndersonQ)\
**Replies:** 0\
**Last updated:** [December 1, 2022, 8:00am UTC](https://discuss.elastic.co/t/dec-1st-2022-en-elastic-agent-101/316879 "2022-12-01T08:00:30Z")

</div>

This article is also available in portuguese. First things first, what is the Elastic Agent? Elastic Agent is a single, unified way to add monitoring for logs, metrics, and other types of data to a host. It can als…

---

## [Query\_string search within nested types](https://discuss.elastic.co/t/query-string-search-within-nested-types/320218)

<div class="topic-metadata">

**Author:** [@vlasami](https://discuss.elastic.co/u/vlasami)\
**Replies:** 0\
**Last updated:** [December 1, 2022, 7:26am UTC](https://discuss.elastic.co/t/query-string-search-within-nested-types/320218 "2022-12-01T07:26:47Z")

</div>

Hi, We recently introduced nested type to our document structure and found that it has some restriction with the query\_string search type, which we use extensively. The search documentation says that: "Avoid using th…

---

## [Bootstrap check failed max file descriptors \[16384\] for elasticsearch process is too low, increase to at least \[65535\]](https://discuss.elastic.co/t/bootstrap-check-failed-max-file-descriptors-16384-for-elasticsearch-process-is-too-low-increase-to-at-least-65535/320140)

<div class="topic-metadata">

**Author:** [@Dhakarlabh](https://discuss.elastic.co/u/Dhakarlabh)\
**Replies:** 2\
**Last updated:** [December 1, 2022, 6:12am UTC](https://discuss.elastic.co/t/bootstrap-check-failed-max-file-descriptors-16384-for-elasticsearch-process-is-too-low-increase-to-at-least-65535/320140 "2022-12-01T06:12:59Z")

</div>

While deploying from the helm chart on the dual stack cluster. I am facing this bootstrap check failed issue. It is working fine for single stack IPv4 cluster. I tried to configure the network.host="global:ipv6" but it i…

---

## [Would like to arrange data histogram COUNT values in descending order,Vertical bar](https://discuss.elastic.co/t/would-like-to-arrange-data-histogram-count-values-in-descending-order-vertical-bar/318072)

<div class="topic-metadata">

**Author:** [@PRASHANT\_MEHTA](https://discuss.elastic.co/u/PRASHANT_MEHTA)\
**Replies:** 1\
**Last updated:** [November 3, 2022, 12:06pm UTC](https://discuss.elastic.co/t/would-like-to-arrange-data-histogram-count-values-in-descending-order-vertical-bar/318072 "2022-11-03T12:06:15Z")

</div>

Hello All, Is it possible to arrange data histogram COUNT values in descending order(big to small). Simply need to display highestest count first for given product type on given date. I dont see any option available t…

---

## [Does nodequerycache need to be configured to be created?](https://discuss.elastic.co/t/does-nodequerycache-need-to-be-configured-to-be-created/320201)

<div class="topic-metadata">

**Author:** [@winteriscomming](https://discuss.elastic.co/u/winteriscomming)\
**Replies:** 1\
**Last updated:** [December 1, 2022, 1:30am UTC](https://discuss.elastic.co/t/does-nodequerycache-need-to-be-configured-to-be-created/320201 "2022-12-01T01:30:57Z")

</div>

A 404 not found error occurs when querying the nodequerycache index with cat api. According to the docs, it is said that node query cache can be set in elasticsearch.yml, but since the default value is enabled, I am con…

---

## [Elasticsearch keeps crashing and won't restart often](https://discuss.elastic.co/t/elasticsearch-keeps-crashing-and-wont-restart-often/320199)

<div class="topic-metadata">

**Author:** [@vesnindev](https://discuss.elastic.co/u/vesnindev)\
**Replies:** 1\
**Last updated:** [December 1, 2022, 1:02am UTC](https://discuss.elastic.co/t/elasticsearch-keeps-crashing-and-wont-restart-often/320199 "2022-12-01T01:02:36Z")

</div>

Hello. Tell me why Elasticsearch keeps crashing and often doesn't restart? \[2022-12-01T00:50:12.915+0000\]\[16713\]\[safepoint \] Safepoint "ICBufferFull", Time since last: 1183469 ns, Reaching safepoint: 22369 ns, At saf…

---

## [Rate limiter](https://discuss.elastic.co/t/rate-limiter/320177)

<div class="topic-metadata">

**Author:** [@srobison62](https://discuss.elastic.co/u/srobison62)\
**Replies:** 1\
**Last updated:** [November 30, 2022, 10:27pm UTC](https://discuss.elastic.co/t/rate-limiter/320177 "2022-11-30T22:27:01Z")

</div>

I understand that Elastic search has a built in functionality to control merges of data so if there is a huge increasing logs it doesn't overload the system. I am wondering where I could actually view these settings or i…

---

## [Silent error on date parsing](https://discuss.elastic.co/t/silent-error-on-date-parsing/320187)

<div class="topic-metadata">

**Author:** [@rfirpo](https://discuss.elastic.co/u/rfirpo)\
**Replies:** 3\
**Last updated:** [November 30, 2022, 9:19pm UTC](https://discuss.elastic.co/t/silent-error-on-date-parsing/320187 "2022-11-30T21:19:16Z")

</div>

Logstash is silently dropping my logs after implementing a small modification in my grok filter. The original filter looks like: filter { if \[internal\]\[logtype\] == "mycustomtype" { grok { match =\> { …

---

## [Architecture Question](https://discuss.elastic.co/t/architecture-question/320191)

<div class="topic-metadata">

**Author:** [@bsherman](https://discuss.elastic.co/u/bsherman)\
**Replies:** 1\
**Last updated:** [November 30, 2022, 9:18pm UTC](https://discuss.elastic.co/t/architecture-question/320191 "2022-11-30T21:18:32Z")

</div>

We have a 10 node cluster running 7.6 on s390x. I'm aware s390x is not supported but we've been able to make it work. We want to upgrade to 7.17. With the 7.17 upgrade we want to have at least one node to use machine l…

---

## [Elasticsearch how to subtract field number value with specific number](https://discuss.elastic.co/t/elasticsearch-how-to-subtract-field-number-value-with-specific-number/318090)

<div class="topic-metadata">

**Author:** [@pratikshatiwari](https://discuss.elastic.co/u/pratikshatiwari)\
**Replies:** 3\
**Last updated:** [November 3, 2022, 11:44am UTC](https://discuss.elastic.co/t/elasticsearch-how-to-subtract-field-number-value-with-specific-number/318090 "2022-11-03T11:44:36Z")

</div>

Hello I am looking for solution to prepare dashboard in which i need to prepare a visualization with difference value e.g. site performance field mentioned as 500ms but as per threshold it should be 200ms Field name "…

[Previous page](https://discuss.elastic.co/tag/none.md?no_tags=true&page=485)

[Next page](https://discuss.elastic.co/tag/none.md?no_tags=true&page=487)
