# \#none

**URL:** https://discuss.elastic.co/tag/none.md?no_tags=true&page=492

[Latest](https://discuss.elastic.co/latest.md) · [Categories](https://discuss.elastic.co/categories.md) · [Tags](https://discuss.elastic.co/tags.md)

**Page:** 493

---

## [Split filepath to a new field](https://discuss.elastic.co/t/split-filepath-to-a-new-field/319657)

<div class="topic-metadata">

**Author:** [@nestro](https://discuss.elastic.co/u/nestro)\
**Replies:** 2\
**Last updated:** [November 23, 2022, 2:51pm UTC](https://discuss.elastic.co/t/split-filepath-to-a-new-field/319657 "2022-11-23T14:51:56Z")

</div>

Hi! I use Filebeat on a central Syslog server which collects logs from all network devices. Filebeat is configured to collect the logs (which are arrenged by days in the month) from this server and sends them to Logstash…

---

## [Forward logs from rsyslog to Elasticsearch](https://discuss.elastic.co/t/forward-logs-from-rsyslog-to-elasticsearch/319597)

<div class="topic-metadata">

**Author:** [@vassiliy.vins](https://discuss.elastic.co/u/vassiliy.vins)\
**Replies:** 2\
**Last updated:** [November 23, 2022, 1:18pm UTC](https://discuss.elastic.co/t/forward-logs-from-rsyslog-to-elasticsearch/319597 "2022-11-23T13:18:52Z")

</div>

Hi! Need to use rsyslog to send data to Elasticsearh. Could you provide link to documentation? Manual? Thank you, Regards, Vassiliy

---

## [Field data type for multi\_match query with type phrase](https://discuss.elastic.co/t/field-data-type-for-multi-match-query-with-type-phrase/319652)

<div class="topic-metadata">

**Author:** [@ChristopherHS](https://discuss.elastic.co/u/ChristopherHS)\
**Replies:** 0\
**Last updated:** [November 23, 2022, 11:44am UTC](https://discuss.elastic.co/t/field-data-type-for-multi-match-query-with-type-phrase/319652 "2022-11-23T11:44:45Z")

</div>

Hello, I have the following query: { "size": 40, "from": 0, "query": { "bool": { "must": \[ { "multi\_match": { "query": "my sea…

---

## [Mixed line types JSON and Plain Text in the same file with multiline](https://discuss.elastic.co/t/mixed-line-types-json-and-plain-text-in-the-same-file-with-multiline/319648)

<div class="topic-metadata">

**Author:** [@sirReeall](https://discuss.elastic.co/u/sirReeall)\
**Replies:** 0\
**Last updated:** [November 23, 2022, 10:53am UTC](https://discuss.elastic.co/t/mixed-line-types-json-and-plain-text-in-the-same-file-with-multiline/319648 "2022-11-23T10:53:45Z")

</div>

Hello, I've got log files that can contain plain text lines from a Java application and JSON lines. To complicate matters the plain text lines can be multiline , for example a Java stack trace, so I'm using the multili…

---

## [Logstash Not sending data to Elasticsearch](https://discuss.elastic.co/t/logstash-not-sending-data-to-elasticsearch/319643)

<div class="topic-metadata">

**Author:** [@abkonred](https://discuss.elastic.co/u/abkonred)\
**Replies:** 0\
**Last updated:** [November 23, 2022, 10:37am UTC](https://discuss.elastic.co/t/logstash-not-sending-data-to-elasticsearch/319643 "2022-11-23T10:37:41Z")

</div>

Hi Team, I have created a pipeline and sending data from filebeat to logstash and to Elasticsearch. and I have created one custom field from filebeat to filter the data. Not sue why it is not sending data to "apa" index…

---

## [And of array items in terms query](https://discuss.elastic.co/t/and-of-array-items-in-terms-query/319633)

<div class="topic-metadata">

**Author:** [@chirag\_bansal](https://discuss.elastic.co/u/chirag_bansal)\
**Replies:** 0\
**Last updated:** [November 23, 2022, 9:07am UTC](https://discuss.elastic.co/t/and-of-array-items-in-terms-query/319633 "2022-11-23T09:07:17Z")

</div>

Hi, I need to know that whether an AND functionality of terms query exists or not? For example - { "terms": { "color": \[ blue, red, black \] } } The above query will return all t…

---

## [Deleted docs could be still retrieved although refreshed](https://discuss.elastic.co/t/deleted-docs-could-be-still-retrieved-although-refreshed/319609)

<div class="topic-metadata">

**Author:** [@fanqiaoqing](https://discuss.elastic.co/u/fanqiaoqing)\
**Replies:** 14\
**Last updated:** [November 23, 2022, 6:44am UTC](https://discuss.elastic.co/t/deleted-docs-could-be-still-retrieved-although-refreshed/319609 "2022-11-23T06:44:52Z")

</div>

Hi Elasticsearch, I have an index with about 2.5 billion documents. The primary has a total of 10 shards, and each shard is about 10G. We have a problem like this: A query will find out the number of documents for som…

---

## [Logstash 7.3.1 with Elasticsearch 7.17.1](https://discuss.elastic.co/t/logstash-7-3-1-with-elasticsearch-7-17-1/319617)

<div class="topic-metadata">

**Author:** [@Wan\_Nur\_Athirah\_Wan](https://discuss.elastic.co/u/Wan_Nur_Athirah_Wan)\
**Replies:** 0\
**Last updated:** [November 23, 2022, 6:30am UTC](https://discuss.elastic.co/t/logstash-7-3-1-with-elasticsearch-7-17-1/319617 "2022-11-23T06:30:02Z")

</div>

Hai. one quick question since i already upgrade my Elasticsearch version from 7.3.1 to 7.17.1. Is it compatible to use logstash 7.3.1 with Elasticsearch 7.17.1 and do i also must upgrade logstash? since there still no er…

---

## [Automatically create shards](https://discuss.elastic.co/t/automatically-create-shards/319613)

<div class="topic-metadata">

**Author:** [@dms6978](https://discuss.elastic.co/u/dms6978)\
**Replies:** 2\
**Last updated:** [November 23, 2022, 5:54am UTC](https://discuss.elastic.co/t/automatically-create-shards/319613 "2022-11-23T05:54:09Z")

</div>

Is there a way to automatically create a shard in one index when the specified shard capacity is full like index rollover?

---

## [Elastic search doesnot bootstrap with 8.5.0](https://discuss.elastic.co/t/elastic-search-doesnot-bootstrap-with-8-5-0/318993)

<div class="topic-metadata">

**Author:** [@smiley\_tamy](https://discuss.elastic.co/u/smiley_tamy)\
**Replies:** 6\
**Last updated:** [November 23, 2022, 3:07am UTC](https://discuss.elastic.co/t/elastic-search-doesnot-bootstrap-with-8-5-0/318993 "2022-11-23T03:07:08Z")

</div>

I have Elasticsearch service with version 8.5.0 When I try to invoke Elasticsearch.main from Java class, the following exception is thrown Can you please help me to resolve that Invoked call - Elasticsearch.main(args…

---

## [Access child aggregations from parent](https://discuss.elastic.co/t/access-child-aggregations-from-parent/319607)

<div class="topic-metadata">

**Author:** [@HasiAmarasena](https://discuss.elastic.co/u/HasiAmarasena)\
**Replies:** 0\
**Last updated:** [November 23, 2022, 3:04am UTC](https://discuss.elastic.co/t/access-child-aggregations-from-parent/319607 "2022-11-23T03:04:01Z")

</div>

I have below search POST /MY\_ID/\_search?typed\_keys=true { "aggs": { "terms\_agg": { "terms": { "field": "\[RefNumber\]" }, "aggs": { "max\_agg\_startdate": { "max": { …

---

## [Elasticsearch multi-match query using a fuzziness criteria behaves in a strange way](https://discuss.elastic.co/t/elasticsearch-multi-match-query-using-a-fuzziness-criteria-behaves-in-a-strange-way/319498)

<div class="topic-metadata">

**Author:** [@Ivo\_Tavares](https://discuss.elastic.co/u/Ivo_Tavares)\
**Replies:** 2\
**Last updated:** [November 23, 2022, 12:40am UTC](https://discuss.elastic.co/t/elasticsearch-multi-match-query-using-a-fuzziness-criteria-behaves-in-a-strange-way/319498 "2022-11-23T00:40:37Z")

</div>

I'm trying to search for some files using the function fetch\_document to fetch a document by its name in the data.name subfield. This function is being used in the following way: fetch\_document( client=server, …

---

## [Elasticsearch not returning larger results (not total result size/length, but size of individual hit](https://discuss.elastic.co/t/elasticsearch-not-returning-larger-results-not-total-result-size-length-but-size-of-individual-hit/319242)

<div class="topic-metadata">

**Author:** [@NickIsWorking](https://discuss.elastic.co/u/NickIsWorking)\
**Replies:** 5\
**Last updated:** [November 22, 2022, 10:59pm UTC](https://discuss.elastic.co/t/elasticsearch-not-returning-larger-results-not-total-result-size-length-but-size-of-individual-hit/319242 "2022-11-22T22:59:25Z")

</div>

Hello. I have an Elasticsearch instance, storing objects that contain really large strings. I am trying to make a request to retrieve those objects from elasticsearch, but for whatever reason, elasticsearch will not retu…

---

## [Rsyslog + Elasticsearch + Kibana](https://discuss.elastic.co/t/rsyslog-elasticsearch-kibana/319594)

<div class="topic-metadata">

**Author:** [@vassiliy.vins](https://discuss.elastic.co/u/vassiliy.vins)\
**Replies:** 0\
**Last updated:** [November 22, 2022, 10:41pm UTC](https://discuss.elastic.co/t/rsyslog-elasticsearch-kibana/319594 "2022-11-22T22:41:56Z")

</div>

Hello! Could you give link to rsyslog configuration to work with Elasticsearch and Kibana? Thank you, Vassiliy

---

## [How to Reference field value(s) in Logstash](https://discuss.elastic.co/t/how-to-reference-field-value-s-in-logstash/319593)

<div class="topic-metadata">

**Author:** [@RCooper56](https://discuss.elastic.co/u/RCooper56)\
**Replies:** 2\
**Last updated:** [November 22, 2022, 10:41pm UTC](https://discuss.elastic.co/t/how-to-reference-field-value-s-in-logstash/319593 "2022-11-22T22:41:06Z")

</div>

Hey Elastic Team, First time post here so please let me know if you need more detail, I'll try to provide as much context as possible. I am trying to create a visualisation based on snmp data coming from our firewall. …

---

## [Email - Something happen while delivering an email {:exception=\>#\<Net::OpenTimeout: execution expired\>}](https://discuss.elastic.co/t/email-something-happen-while-delivering-an-email-exception-net-execution-expired/319590)

<div class="topic-metadata">

**Author:** [@David\_Graciano](https://discuss.elastic.co/u/David_Graciano)\
**Replies:** 0\
**Last updated:** [November 22, 2022, 9:49pm UTC](https://discuss.elastic.co/t/email-something-happen-while-delivering-an-email-exception-net-execution-expired/319590 "2022-11-22T21:49:03Z")

</div>

Attempting to send an email from the logstash output produces the following error in the output. email - Something happen while delivering an email {:exception=\>#\<Net::OpenTimeout: execution expired\>} this is my curren…

---

## [MaxTimeoutReached occurring after failing to connect via sniffing connection pool](https://discuss.elastic.co/t/maxtimeoutreached-occurring-after-failing-to-connect-via-sniffing-connection-pool/318973)

<div class="topic-metadata">

**Author:** [@Hoppities](https://discuss.elastic.co/u/Hoppities)\
**Replies:** 1\
**Last updated:** [November 22, 2022, 7:53pm UTC](https://discuss.elastic.co/t/maxtimeoutreached-occurring-after-failing-to-connect-via-sniffing-connection-pool/318973 "2022-11-22T19:53:45Z")

</div>

Whenever we run into this scenario where a sniff happened and elastic was unable to connect, we then see this timeout with a massive negative number. I'm not even sure where to start with this. Any help would be appreci…

---

## [Filebeat.yml and logstash.conf are not getting loaded automatically](https://discuss.elastic.co/t/filebeat-yml-and-logstash-conf-are-not-getting-loaded-automatically/319573)

<div class="topic-metadata">

**Author:** [@Manjiri](https://discuss.elastic.co/u/Manjiri)\
**Replies:** 1\
**Last updated:** [November 22, 2022, 6:53pm UTC](https://discuss.elastic.co/t/filebeat-yml-and-logstash-conf-are-not-getting-loaded-automatically/319573 "2022-11-22T18:53:18Z")

</div>

When we starting the filebeat and logstash services through services.msc , filebeat.yml and logstash.conf is not getting loaded automatically. Everytime we need to load 2 files manually through command prompt using below…

---

## [Defender for Endpoint to Azure Event Hub to Elasticsearch?](https://discuss.elastic.co/t/defender-for-endpoint-to-azure-event-hub-to-elasticsearch/319578)

<div class="topic-metadata">

**Author:** [@mathurin68](https://discuss.elastic.co/u/mathurin68)\
**Replies:** 0\
**Last updated:** [November 22, 2022, 5:53pm UTC](https://discuss.elastic.co/t/defender-for-endpoint-to-azure-event-hub-to-elasticsearch/319578 "2022-11-22T17:53:31Z")

</div>

Our Defender for Endpoint Device tables are around 1TB a day, I'll never get the money to use Sentinel so I'm looking for an alternative. Is there no way to use Azure Event Hubs with Elasticsearch? Stream the events fr…

---

## [I want to have a button kind of visualization in the KIBANA dashboard, Can anyone please provide any information on this?](https://discuss.elastic.co/t/i-want-to-have-a-button-kind-of-visualization-in-the-kibana-dashboard-can-anyone-please-provide-any-information-on-this/316733)

<div class="topic-metadata">

**Author:** [@abhinay\_nalla](https://discuss.elastic.co/u/abhinay_nalla)\
**Replies:** 6\
**Last updated:** [October 26, 2022, 6:56am UTC](https://discuss.elastic.co/t/i-want-to-have-a-button-kind-of-visualization-in-the-kibana-dashboard-can-anyone-please-provide-any-information-on-this/316733 "2022-10-26T06:56:13Z")

</div>

I want to create one button which shows this kind of information in it. If anyone has this kind of solution or information please do help me. Thank you Regards Abhi

---

## [Discover gives error from Kibana](https://discuss.elastic.co/t/discover-gives-error-from-kibana/319371)

<div class="topic-metadata">

**Author:** [@mpniel](https://discuss.elastic.co/u/mpniel)\
**Replies:** 4\
**Last updated:** [November 22, 2022, 5:25pm UTC](https://discuss.elastic.co/t/discover-gives-error-from-kibana/319371 "2022-11-22T17:25:36Z")

</div>

Hi, Click on discover icon from kibana gives the following error: Error: Request to Elasticsearch failed: ("error": {"root\_cause": \[{"reason': 'forbidden' due to \["OPERATION NOT ALLOWED"\]}\], "reason": "forbidden", "du…

---

## [mTLS only setup for Elasticsearch](https://discuss.elastic.co/t/mtls-only-setup-for-elasticsearch/319576)

<div class="topic-metadata">

**Author:** [@Rohit\_Shrivastava](https://discuss.elastic.co/u/Rohit_Shrivastava)\
**Replies:** 0\
**Last updated:** [November 22, 2022, 4:59pm UTC](https://discuss.elastic.co/t/mtls-only-setup-for-elasticsearch/319576 "2022-11-22T16:59:20Z")

</div>

Is it possible to only use mTLS i.e. only authentication via PKI realm. I almost have the cluster working (using open source helm charts and 7.1.7 images). One issue I have is the pod readiness doesn't succeed as the \_c…

---

## [Unable to output container password details when using ansible with podman](https://discuss.elastic.co/t/unable-to-output-container-password-details-when-using-ansible-with-podman/319563)

<div class="topic-metadata">

**Author:** [@millerthegorilla](https://discuss.elastic.co/u/millerthegorilla)\
**Replies:** 0\
**Last updated:** [November 22, 2022, 3:21pm UTC](https://discuss.elastic.co/t/unable-to-output-container-password-details-when-using-ansible-with-podman/319563 "2022-11-22T15:21:28Z")

</div>

Hi, when using ansible-podman, I am unable to output the std-out of the container run command as I might do when using the command line. This means that I don't get to see the automatically generated password and keysto…

---

## [Elasticsearch PHP Client implementation for a webshop](https://discuss.elastic.co/t/elasticsearch-php-client-implementation-for-a-webshop/319557)

<div class="topic-metadata">

**Author:** [@Thymen](https://discuss.elastic.co/u/Thymen)\
**Replies:** 0\
**Last updated:** [November 22, 2022, 2:26pm UTC](https://discuss.elastic.co/t/elasticsearch-php-client-implementation-for-a-webshop/319557 "2022-11-22T14:26:03Z")

</div>

Hello there, I am using the Elasticsearch PHP client (8.3), as can be found on: github I've used several types of queries to find and filter through results on several indices to find relevant/popular. Some more comple…

---

## [Elasticsearch-certutil parameters](https://discuss.elastic.co/t/elasticsearch-certutil-parameters/319529)

<div class="topic-metadata">

**Author:** [@adrien\_moreau](https://discuss.elastic.co/u/adrien_moreau)\
**Replies:** 1\
**Last updated:** [November 22, 2022, 1:47pm UTC](https://discuss.elastic.co/t/elasticsearch-certutil-parameters/319529 "2022-11-22T13:47:45Z")

</div>

Hello, I am using Elasticsearch on a self managed cluster and I had to use the "elasticsearch-certutil" tool to manage my cluster certificates. The help menu from the tool only lists the following options Simplifies c…

---

## [Not breaking down Embeded json field and instead keep it in a single field](https://discuss.elastic.co/t/not-breaking-down-embeded-json-field-and-instead-keep-it-in-a-single-field/319505)

<div class="topic-metadata">

**Author:** [@stillfreem](https://discuss.elastic.co/u/stillfreem)\
**Replies:** 2\
**Last updated:** [November 22, 2022, 1:42pm UTC](https://discuss.elastic.co/t/not-breaking-down-embeded-json-field-and-instead-keep-it-in-a-single-field/319505 "2022-11-22T13:42:34Z")

</div>

Hi All, I use json filter plugin to parse log entries in json format such as the below {"actor\_ip":"xxx","from":"Api::ActionsRunnerRegistration#POST","actor":"xxx","actor\_id":2480,"org":"xxx","org\_id":13,"action":"org.…

---

## [Dumping requests](https://discuss.elastic.co/t/dumping-requests/319462)

<div class="topic-metadata">

**Author:** [@Georgi\_Danov](https://discuss.elastic.co/u/Georgi_Danov)\
**Replies:** 4\
**Last updated:** [November 22, 2022, 1:39pm UTC](https://discuss.elastic.co/t/dumping-requests/319462 "2022-11-22T13:39:03Z")

</div>

I'm reverse engineering and optimizing ES instance. One of the things that would help me enormously is to understand what operations (updates and queries) are coming in. What's the best way do dump & analyze the operat…

---

## [The content length (938946807) is bigger than the maximum allowed string (536870888) sending logstash-plain.log to elasticsearch](https://discuss.elastic.co/t/the-content-length-938946807-is-bigger-than-the-maximum-allowed-string-536870888-sending-logstash-plain-log-to-elasticsearch/319533)

<div class="topic-metadata">

**Author:** [@Neelam\_Zanvar](https://discuss.elastic.co/u/Neelam_Zanvar)\
**Replies:** 8\
**Last updated:** [November 22, 2022, 1:00pm UTC](https://discuss.elastic.co/t/the-content-length-938946807-is-bigger-than-the-maximum-allowed-string-536870888-sending-logstash-plain-log-to-elasticsearch/319533 "2022-11-22T13:00:00Z")

</div>

Hi I have setup filebeat to send logstash logs to logstah then elasticsearch. Getting this error when trying to access it on discover page Search Error The content length (938946807) is bigger than the maximum allowed s…

---

## [How to join/combine data from 2 indices using a common/join field in Elastic?](https://discuss.elastic.co/t/how-to-join-combine-data-from-2-indices-using-a-common-join-field-in-elastic/317195)

<div class="topic-metadata">

**Author:** [@AshwiniPrabhu](https://discuss.elastic.co/u/AshwiniPrabhu)\
**Replies:** 6\
**Last updated:** [October 26, 2022, 6:10am UTC](https://discuss.elastic.co/t/how-to-join-combine-data-from-2-indices-using-a-common-join-field-in-elastic/317195 "2022-10-26T06:10:10Z")

</div>

Hi, Thank you for your time for reading the question. I have 2 indices: Index 1 (Activation) - Order Id, Activation Date Index 2 (Identity) - Order Id, Identity Date. The join field/common field is Order id. I have t…

---

## [Match queries and ASCII folding](https://discuss.elastic.co/t/match-queries-and-ascii-folding/319544)

<div class="topic-metadata">

**Author:** [@babolivier](https://discuss.elastic.co/u/babolivier)\
**Replies:** 1\
**Last updated:** [November 22, 2022, 11:44am UTC](https://discuss.elastic.co/t/match-queries-and-ascii-folding/319544 "2022-11-22T11:44:25Z")

</div>

Hi all, I have an index that was created with the following configuration: { "settings": { "analysis": { "analyzer": { "std\_asciifolding": { "tokenizer": "standard", "filter": \[ …

[Previous page](https://discuss.elastic.co/tag/none.md?no_tags=true&page=491)

[Next page](https://discuss.elastic.co/tag/none.md?no_tags=true&page=493)
