# \#none

**URL:** https://discuss.elastic.co/tag/none.md?no_tags=true&page=497

[Latest](https://discuss.elastic.co/latest.md) · [Categories](https://discuss.elastic.co/categories.md) · [Tags](https://discuss.elastic.co/tags.md)

**Page:** 498

---

## [Problem with aggregation returning most popular array entry among all documents](https://discuss.elastic.co/t/problem-with-aggregation-returning-most-popular-array-entry-among-all-documents/319127)

<div class="topic-metadata">

**Author:** [@Karol\_Radomski](https://discuss.elastic.co/u/Karol_Radomski)\
**Replies:** 0\
**Last updated:** [November 16, 2022, 8:52pm UTC](https://discuss.elastic.co/t/problem-with-aggregation-returning-most-popular-array-entry-among-all-documents/319127 "2022-11-16T20:52:20Z")

</div>

Please help me solve aggregation issue: Lets say I have mapping (...) "properties": { "kidName": { "type": "keyword", "fields": { "txt": { "type": "text", } …

---

## [Gather AWS tags for host running Elastic Agent](https://discuss.elastic.co/t/gather-aws-tags-for-host-running-elastic-agent/319125)

<div class="topic-metadata">

**Author:** [@keiransteele](https://discuss.elastic.co/u/keiransteele)\
**Replies:** 0\
**Last updated:** [November 16, 2022, 7:37pm UTC](https://discuss.elastic.co/t/gather-aws-tags-for-host-running-elastic-agent/319125 "2022-11-16T19:37:24Z")

</div>

Currently the only identifiable information when viewing a host in the fleet UI is the hostname and OS, there is some metadata available in the Observability UI (I think metrics needs to be enabled for this?) but there a…

---

## [Aggregation only over the search results](https://discuss.elastic.co/t/aggregation-only-over-the-search-results/319012)

<div class="topic-metadata">

**Author:** [@namespace-Pt](https://discuss.elastic.co/u/namespace-Pt)\
**Replies:** 1\
**Last updated:** [November 16, 2022, 6:32pm UTC](https://discuss.elastic.co/t/aggregation-only-over-the-search-results/319012 "2022-11-16T18:32:57Z")

</div>

I found that the terms aggregations always inspect the entire collection, for example I use { "query": { "match": { "text field": "some text" } }, "aggs": { "agg-terms": {…

---

## [I see the following message in logstash after enabling security on elaticsearch side](https://discuss.elastic.co/t/i-see-the-following-message-in-logstash-after-enabling-security-on-elaticsearch-side/319120)

<div class="topic-metadata">

**Author:** [@zozo6015](https://discuss.elastic.co/u/zozo6015)\
**Replies:** 0\
**Last updated:** [November 16, 2022, 5:19pm UTC](https://discuss.elastic.co/t/i-see-the-following-message-in-logstash-after-enabling-security-on-elaticsearch-side/319120 "2022-11-16T17:19:45Z")

</div>

Hello, I am running elasticsearch cluster 7.9 with logstash to parse logfiles and ingest. After enabling security on elasticsearch I am seeing the following error messages into the logstash logs. \[ERROR\]\[logstash.licen…

---

## [Use Kibana on my local machine to monitor Metricbeat on a remote VM?](https://discuss.elastic.co/t/use-kibana-on-my-local-machine-to-monitor-metricbeat-on-a-remote-vm/317054)

<div class="topic-metadata">

**Author:** [@nola](https://discuss.elastic.co/u/nola)\
**Replies:** 2\
**Last updated:** [October 19, 2022, 10:25pm UTC](https://discuss.elastic.co/t/use-kibana-on-my-local-machine-to-monitor-metricbeat-on-a-remote-vm/317054 "2022-10-19T22:25:14Z")

</div>

I have Metricbeat and Elasticsearch installed and running on an AWS EC2 instance. I have Kibana on my local machine. In kibana.yml, I have the server address for the elastic.hosts parameter, and am able to run queries …

---

## [How to drop DNS event if they are present into top 1 million file](https://discuss.elastic.co/t/how-to-drop-dns-event-if-they-are-present-into-top-1-million-file/318981)

<div class="topic-metadata">

**Author:** [@yquirion](https://discuss.elastic.co/u/yquirion)\
**Replies:** 5\
**Last updated:** [November 16, 2022, 4:55pm UTC](https://discuss.elastic.co/t/how-to-drop-dns-event-if-they-are-present-into-top-1-million-file/318981 "2022-11-16T16:55:32Z")

</div>

Dear all, I'm wonderion how to configure a logstash pipeline that will handle my DNS logs. From that logs, there are lots of logs I don't want to see because I know they are legitimate. So I would like to have logstash…

---

## [Unable to edit settings for agent policy](https://discuss.elastic.co/t/unable-to-edit-settings-for-agent-policy/319096)

<div class="topic-metadata">

**Author:** [@mammodde](https://discuss.elastic.co/u/mammodde)\
**Replies:** 0\
**Last updated:** [November 16, 2022, 3:32pm UTC](https://discuss.elastic.co/t/unable-to-edit-settings-for-agent-policy/319096 "2022-11-16T15:32:03Z")

</div>

Hi, I am trying to install an elastic agent on an apache web server. The problem is that the server is outside my system's network. In order to make it work, I added an output in the fleet settings which should send da…

---

## [Elastic support STIX and/or TAXII](https://discuss.elastic.co/t/elastic-support-stix-and-or-taxii/319076)

<div class="topic-metadata">

**Author:** [@oyuskeseliev](https://discuss.elastic.co/u/oyuskeseliev)\
**Replies:** 2\
**Last updated:** [November 16, 2022, 3:01pm UTC](https://discuss.elastic.co/t/elastic-support-stix-and-or-taxii/319076 "2022-11-16T15:01:40Z")

</div>

Hi all, i’m trying to find out if Elastic has support for STIX/TAXII. I do not see any info about this in the documentation, does anyone know? regards Ognyan

---

## [Deprecated Log](https://discuss.elastic.co/t/deprecated-log/319091)

<div class="topic-metadata">

**Author:** [@EExisT](https://discuss.elastic.co/u/EExisT)\
**Replies:** 0\
**Last updated:** [November 16, 2022, 2:49pm UTC](https://discuss.elastic.co/t/deprecated-log/319091 "2022-11-16T14:49:52Z")

</div>

Hello, i'm trying to patch the deprecated settings in my ES cluster v.7.13.x. I runned into these 2 deprecated settings: \[2022-11-16T15:03:23,504\]\[DEPRECATION\]\[o.e.d.c.s.Settings \] \[es-md-01\] \[xpack.security.htt…

---

## [Map의 키가 도큐먼트마다 다른 경우 인덱스 패턴 작성 방법을 알고 싶습니다](https://discuss.elastic.co/t/map/319041)

<div class="topic-metadata">

**Author:** [@ChangJoo\_Park](https://discuss.elastic.co/u/ChangJoo_Park)\
**Replies:** 2\
**Last updated:** [November 16, 2022, 1:54pm UTC](https://discuss.elastic.co/t/map/319041 "2022-11-16T13:54:14Z")

</div>

제가 다루는 도큐먼트 규격은 아래와 같습니다. { // ... 기타 데이터들 photos: { "\<해시된 아이디 1\>": { // "\<해시된 아이디 1\>" 과 연관된 데이터 }, "\<해시된 아이디 1\>": { // "\<해시된 아이디 1\>" 과 연관된 데이터 }, } } 제가 원하는 결과는 키바나 -\> Stack Management -\> 인…

---

## [Elasticsearch 8.05.00.00 ODBC connection error](https://discuss.elastic.co/t/elasticsearch-8-05-00-00-odbc-connection-error/318341)

<div class="topic-metadata">

**Author:** [@Gianluca\_De\_Pasquale](https://discuss.elastic.co/u/Gianluca_De_Pasquale)\
**Replies:** 2\
**Last updated:** [November 16, 2022, 1:35pm UTC](https://discuss.elastic.co/t/elasticsearch-8-05-00-00-odbc-connection-error/318341 "2022-11-16T13:35:17Z")

</div>

Hi, I want to try out the Elasticsearch ODBC driver for importing data from Microsoft Power Bi . After installation, I created a system DSN configuration, but when I tested the connection, I got the following error : Un…

---

## [Elasticsearch 7.7](https://discuss.elastic.co/t/elasticsearch-7-7/319079)

<div class="topic-metadata">

**Author:** [@Tiger1](https://discuss.elastic.co/u/Tiger1)\
**Replies:** 2\
**Last updated:** [November 16, 2022, 1:12pm UTC](https://discuss.elastic.co/t/elasticsearch-7-7/319079 "2022-11-16T13:12:26Z")

</div>

I'm trying to deploy elasticsearch 7.7 cluster, there's problem: \[es2\] master not discovered yet, this node has not previously joined a bootstrapped (v7+) cluster, and this node must discover master-eligible nodes \[es1,…

---

## [Put a rule that will allow me to detect brute force](https://discuss.elastic.co/t/put-a-rule-that-will-allow-me-to-detect-brute-force/319080)

<div class="topic-metadata">

**Author:** [@buhu698](https://discuss.elastic.co/u/buhu698)\
**Replies:** 0\
**Last updated:** [November 16, 2022, 12:40pm UTC](https://discuss.elastic.co/t/put-a-rule-that-will-allow-me-to-detect-brute-force/319080 "2022-11-16T12:40:52Z")

</div>

Hello, can you help me to put a rule that will allow me to detect brute force. type of rule ( event correlation or indicator match ). From the Kali machine, I run the following command: Hydra –L /usr/share/wordlists/…

---

## [Extract multiple substrings from a field using grok](https://discuss.elastic.co/t/extract-multiple-substrings-from-a-field-using-grok/319071)

<div class="topic-metadata">

**Author:** [@Matan\_Malka](https://discuss.elastic.co/u/Matan_Malka)\
**Replies:** 2\
**Last updated:** [November 16, 2022, 12:26pm UTC](https://discuss.elastic.co/t/extract-multiple-substrings-from-a-field-using-grok/319071 "2022-11-16T12:26:13Z")

</div>

Hi, I'm trying to extract the job name ("create-machine") and the build number ("\*\*") from the file path but it is not possible to use duplicate keys. Do you have any other suggestions? input{ file{ path =\> \[ "/bi…

---

## [Kubernetes elastic search and kibana communication issue](https://discuss.elastic.co/t/kubernetes-elastic-search-and-kibana-communication-issue/317023)

<div class="topic-metadata">

**Author:** [@Siva\_Priya](https://discuss.elastic.co/u/Siva_Priya)\
**Replies:** 1\
**Last updated:** [October 19, 2022, 9:47pm UTC](https://discuss.elastic.co/t/kubernetes-elastic-search-and-kibana-communication-issue/317023 "2022-10-19T21:47:11Z")

</div>

Am trying to set up the Elasticsearch and kibana in Kubernetes cluster as per the instructions mentioned in How to run Elastic Cloud on Kubernetes from Azure Kubernetes Service | Elastic Blog. Everything is fine But I am…

---

## [Timezone issue](https://discuss.elastic.co/t/timezone-issue/318620)

<div class="topic-metadata">

**Author:** [@MahithaSarala](https://discuss.elastic.co/u/MahithaSarala)\
**Replies:** 10\
**Last updated:** [November 16, 2022, 12:12pm UTC](https://discuss.elastic.co/t/timezone-issue/318620 "2022-11-16T12:12:32Z")

</div>

In our current kibana setup , the timezone has been set to browser timezone. This dashboard is live for users in India as well as users in Ireland . The kibana setup is live and linked to spinnaker to monitor the pipelin…

---

## [Update Elasticsearch and Kibana](https://discuss.elastic.co/t/update-elasticsearch-and-kibana/319027)

<div class="topic-metadata">

**Author:** [@Clonky](https://discuss.elastic.co/u/Clonky)\
**Replies:** 6\
**Last updated:** [November 16, 2022, 11:55am UTC](https://discuss.elastic.co/t/update-elasticsearch-and-kibana/319027 "2022-11-16T11:55:48Z")

</div>

Hello, I am running on a local server Elasticsearch in version 7.16 and Kibana in version 7.17 I want both to be updated to version 8.5. I have read, that I should use the Update Assistance in the wiki However, when I…

---

## [Search for documents containing words with and without dots (e.g. “ceo”, “c.e.o”, “c.e.o.”)](https://discuss.elastic.co/t/search-for-documents-containing-words-with-and-without-dots-e-g-ceo-c-e-o-c-e-o/319035)

<div class="topic-metadata">

**Author:** [@revencu](https://discuss.elastic.co/u/revencu)\
**Replies:** 11\
**Last updated:** [November 16, 2022, 11:43am UTC](https://discuss.elastic.co/t/search-for-documents-containing-words-with-and-without-dots-e-g-ceo-c-e-o-c-e-o/319035 "2022-11-16T11:43:04Z")

</div>

{ "query":{ "match":{ "title": "ceo" } } } this query returns docs that only contain "ceo", "Ceo", "CEO". But the index has values like "c.e.o.", "C.E.O.", "c.e.o" How to set up a query so th…

---

## [Node stats API fails with a Null Pointer exception for data nodes](https://discuss.elastic.co/t/node-stats-api-fails-with-a-null-pointer-exception-for-data-nodes/319016)

<div class="topic-metadata">

**Author:** [@Dheeraj\_Gupta](https://discuss.elastic.co/u/Dheeraj_Gupta)\
**Replies:** 1\
**Last updated:** [November 16, 2022, 11:15am UTC](https://discuss.elastic.co/t/node-stats-api-fails-with-a-null-pointer-exception-for-data-nodes/319016 "2022-11-16T11:15:32Z")

</div>

Hi, We have recently upgraded to 8.5.0 from 8.4.1. We use the node stats API (\_nodes/stats) to pull stats about various nodes for storage into graphite. Since the update all data nodes are showing the following failure …

---

## [Iam trying to parse fortigate syslog to logstash](https://discuss.elastic.co/t/iam-trying-to-parse-fortigate-syslog-to-logstash/319059)

<div class="topic-metadata">

**Author:** [@hasan.idriss](https://discuss.elastic.co/u/hasan.idriss)\
**Replies:** 0\
**Last updated:** [November 16, 2022, 10:55am UTC](https://discuss.elastic.co/t/iam-trying-to-parse-fortigate-syslog-to-logstash/319059 "2022-11-16T10:55:04Z")

</div>

when i run the command: /usr/share/logstash/bin/logstash -f /etc/logstash/conf.d/fortigate.conf I get the error : udp - UDP listener died {:exception=\>#\<Errno::EADDRINUSE: Address already in use - bind(2) for "192.168…

---

## [How can I clear "keyword" entries that have no documents?](https://discuss.elastic.co/t/how-can-i-clear-keyword-entries-that-have-no-documents/318537)

<div class="topic-metadata">

**Author:** [@wrobitza\_aveq](https://discuss.elastic.co/u/wrobitza_aveq)\
**Replies:** 7\
**Last updated:** [November 16, 2022, 10:45am UTC](https://discuss.elastic.co/t/how-can-i-clear-keyword-entries-that-have-no-documents/318537 "2022-11-16T10:45:21Z")

</div>

I accidentally indexed a document with a wrong text/keyword field. I later removed the document, but the keyword is still there. For instance, when I run the query: GET \_search { "size": 0, "aggs": { "group\_by\_…

---

## [Elastic DSL Query](https://discuss.elastic.co/t/elastic-dsl-query/319040)

<div class="topic-metadata">

**Author:** [@Nikhil\_Sharma2](https://discuss.elastic.co/u/Nikhil_Sharma2)\
**Replies:** 0\
**Last updated:** [November 16, 2022, 9:05am UTC](https://discuss.elastic.co/t/elastic-dsl-query/319040 "2022-11-16T09:05:38Z")

</div>

I have a query in sql which I want to transform in ES. Select \* from items where ( (State=== Open AND (userId=== '123' OR contributers.include('123'))) OR ( (State=== Review) AND ( AntherState=== Submitted AND A…

---

## [Grok Pattern For Java stack traces](https://discuss.elastic.co/t/grok-pattern-for-java-stack-traces/319036)

<div class="topic-metadata">

**Author:** [@Nessy](https://discuss.elastic.co/u/Nessy)\
**Replies:** 0\
**Last updated:** [November 16, 2022, 8:56am UTC](https://discuss.elastic.co/t/grok-pattern-for-java-stack-traces/319036 "2022-11-16T08:56:34Z")

</div>

Hello, I have been workin on this topic for a long time. Here my logstash conf : filter { if \[fields\]\[application\_name\] =~ "APPNAME" { grok { match =\> { "message" =\> "(?\<timestamp\>%{TIMESTAMP\_ISO8601})…

---

## [Kibana Observability dashboard custom field](https://discuss.elastic.co/t/kibana-observability-dashboard-custom-field/318991)

<div class="topic-metadata">

**Author:** [@Mario\_Fimiani](https://discuss.elastic.co/u/Mario_Fimiani)\
**Replies:** 2\
**Last updated:** [November 16, 2022, 8:52am UTC](https://discuss.elastic.co/t/kibana-observability-dashboard-custom-field/318991 "2022-11-16T08:52:14Z")

</div>

Ciao can anyone know if the Observability Dashboard can be customized in term of fields shows ? We are able to change the field but when we refresh the page we miss the customization. Stack v. 7.17.3

---

## [Поиск документов содержащие слова с точками и без (например "ceo", "c.e.o", "c.e.o.")](https://discuss.elastic.co/t/ceo-c-e-o-c-e-o/319033)

<div class="topic-metadata">

**Author:** [@revencu](https://discuss.elastic.co/u/revencu)\
**Replies:** 0\
**Last updated:** [November 16, 2022, 8:42am UTC](https://discuss.elastic.co/t/ceo-c-e-o-c-e-o/319033 "2022-11-16T08:42:25Z")

</div>

Как сделать поиск документов которые содержат также и укороченные слова { "query":{ "match":{ "title": "ceo" } } } этот запрос возвращает доки которые содержат только "ceo", "Ceo", "CEO". Но…

---

## [Elasticsearch picking wrong port](https://discuss.elastic.co/t/elasticsearch-picking-wrong-port/318978)

<div class="topic-metadata">

**Author:** [@harijld](https://discuss.elastic.co/u/harijld)\
**Replies:** 8\
**Last updated:** [November 16, 2022, 7:57am UTC](https://discuss.elastic.co/t/elasticsearch-picking-wrong-port/318978 "2022-11-16T07:57:37Z")

</div>

Hi Team, I am facing strange behavior in prod environment. I used same configuration in prod and DR servers but in prod its working fine, in DR elasticserch is not connecting to different node when I am configuring clu…

---

## [Mustache double quotes problem in search templates](https://discuss.elastic.co/t/mustache-double-quotes-problem-in-search-templates/318736)

<div class="topic-metadata">

**Author:** [@D1sturbance](https://discuss.elastic.co/u/D1sturbance)\
**Replies:** 7\
**Last updated:** [November 16, 2022, 7:52am UTC](https://discuss.elastic.co/t/mustache-double-quotes-problem-in-search-templates/318736 "2022-11-16T07:52:23Z")

</div>

What is the best way to use mustache False values feature in Elasticsearch template? At the moment I am trying to select function based on boolean value. Rendering seems to be working according to the logic, but it pri…

---

## [OUTDATED\_DOCUMENTS\_SEARCH\_OPEN\_PIT. Action failed with 'search\_phase\_execution\_exception'](https://discuss.elastic.co/t/outdated-documents-search-open-pit-action-failed-with-search-phase-execution-exception/317044)

<div class="topic-metadata">

**Author:** [@Shep](https://discuss.elastic.co/u/Shep)\
**Replies:** 0\
**Last updated:** [October 19, 2022, 6:41pm UTC](https://discuss.elastic.co/t/outdated-documents-search-open-pit-action-failed-with-search-phase-execution-exception/317044 "2022-10-19T18:41:36Z")

</div>

I'm having an issue with our Elastic Search / Kibana deployment. Kibana keeps failing to open with an error. Kibana 7.14.0\_001 Windows I was getting this fatal error: log \[12:18;05.466\] \[fatal\]\[root\] Error: Unable to c…

---

## [Logstash sql pipeline stops working](https://discuss.elastic.co/t/logstash-sql-pipeline-stops-working/318945)

<div class="topic-metadata">

**Author:** [@knakul853](https://discuss.elastic.co/u/knakul853)\
**Replies:** 0\
**Last updated:** [November 15, 2022, 9:34am UTC](https://discuss.elastic.co/t/logstash-sql-pipeline-stops-working/318945 "2022-11-15T09:34:37Z")

</div>

Hi all! I have a sync job for logstash which continuously picked data that have these config setups use\_column\_value =\> true tracking\_column =\> "last\_update\_time" tracking\_column\_type =\> "timestamp" my question is …

---

## [Does update and query document in diff cache?](https://discuss.elastic.co/t/does-update-and-query-document-in-diff-cache/319014)

<div class="topic-metadata">

**Author:** [@GithubRyze](https://discuss.elastic.co/u/GithubRyze)\
**Replies:** 2\
**Last updated:** [November 16, 2022, 6:17am UTC](https://discuss.elastic.co/t/does-update-and-query-document-in-diff-cache/319014 "2022-11-16T06:17:16Z")

</div>

step: updated document query the document immediately expected: return latest of the document but retunr the old docment Does update and query document in diff cache? update in RAM CACHE and QUERY IN DISK ?

[Previous page](https://discuss.elastic.co/tag/none.md?no_tags=true&page=496)

[Next page](https://discuss.elastic.co/tag/none.md?no_tags=true&page=498)
