# \#none

**URL:** https://discuss.elastic.co/tag/none.md?no_tags=true&page=500

[Latest](https://discuss.elastic.co/latest.md) · [Categories](https://discuss.elastic.co/categories.md) · [Tags](https://discuss.elastic.co/tags.md)

**Page:** 501

---

## [Calculate elapsed time in Kibana?](https://discuss.elastic.co/t/calculate-elapsed-time-in-kibana/316575)

<div class="topic-metadata">

**Author:** [@TXBigDawg1836](https://discuss.elastic.co/u/TXBigDawg1836)\
**Replies:** 2\
**Last updated:** [November 13, 2022, 10:18am UTC](https://discuss.elastic.co/t/calculate-elapsed-time-in-kibana/316575 "2022-11-13T10:18:15Z")

</div>

ELK newbie here. Is it possible in Kibana visualization (ie. Table) to calculate the elapsed time from the timestamp and current time? Looking to populate a field in the table to show the elapsed time since the last ti…

---

## [Attempted to resurrect connection to dead ES instance](https://discuss.elastic.co/t/attempted-to-resurrect-connection-to-dead-es-instance/318562)

<div class="topic-metadata">

**Author:** [@Zay\_Lin\_Htun](https://discuss.elastic.co/u/Zay_Lin_Htun)\
**Replies:** 2\
**Last updated:** [November 13, 2022, 4:52am UTC](https://discuss.elastic.co/t/attempted-to-resurrect-connection-to-dead-es-instance/318562 "2022-11-13T04:52:10Z")

</div>

Hello folks, \[INFO \] 2022-11-09 16:05:14.964 \[Ruby-0-Thread-9: :1\] elasticsearch - Failed to perform request {:message=\>"PKIX path building failed: sun.security.provider.certpath.SunCertPathBuilderException: unable to f…

---

## [Elasticsearch node fails after multiple G1GC triggers](https://discuss.elastic.co/t/elasticsearch-node-fails-after-multiple-g1gc-triggers/318779)

<div class="topic-metadata">

**Author:** [@BradVido](https://discuss.elastic.co/u/BradVido)\
**Replies:** 0\
**Last updated:** [November 12, 2022, 9:16pm UTC](https://discuss.elastic.co/t/elasticsearch-node-fails-after-multiple-g1gc-triggers/318779 "2022-11-12T21:16:09Z")

</div>

We have a 6 node cluster on ES 7.17.7, which is very stable except for our single coordinating node (which also is master eligible, so not a "true" coordinating node). After 4-6 hours of uptime, we always get the below …

---

## [How many Public IP need for my cluster](https://discuss.elastic.co/t/how-many-public-ip-need-for-my-cluster/318766)

<div class="topic-metadata">

**Author:** [@Zay\_Lin\_Htun](https://discuss.elastic.co/u/Zay_Lin_Htun)\
**Replies:** 1\
**Last updated:** [November 12, 2022, 11:06pm UTC](https://discuss.elastic.co/t/how-many-public-ip-need-for-my-cluster/318766 "2022-11-12T23:06:33Z")

</div>

I would like to know the how many Public IP addresses need to deploy my cluster in AWS. In my cluster, there are 2 data nodes for Hot data 2 data nodes for warm data 3 Master Nodes 2 Logstash Feel free to suggest me …

---

## [Fleet Managed Elastic Agent - add parameter to filebeat.yml](https://discuss.elastic.co/t/fleet-managed-elastic-agent-add-parameter-to-filebeat-yml/317521)

<div class="topic-metadata">

**Author:** [@lnx](https://discuss.elastic.co/u/lnx)\
**Replies:** 3\
**Last updated:** [November 12, 2022, 7:31pm UTC](https://discuss.elastic.co/t/fleet-managed-elastic-agent-add-parameter-to-filebeat-yml/317521 "2022-11-12T19:31:12Z")

</div>

I need to set the scan\_frequency config parameter for the Filebeat subprocess of Elastic Agent running on Windows managed by Fleet. I'm using the IIS integration. I would like to try to reduce CPU usage. How do I do th…

---

## [Eecute python code from Kibana](https://discuss.elastic.co/t/eecute-python-code-from-kibana/316748)

<div class="topic-metadata">

**Author:** [@Rajesh\_Sharma](https://discuss.elastic.co/u/Rajesh_Sharma)\
**Replies:** 1\
**Last updated:** [October 17, 2022, 8:45am UTC](https://discuss.elastic.co/t/eecute-python-code-from-kibana/316748 "2022-10-17T08:45:39Z")

</div>

Hi, I need to execute a python script from kibana dashboard, is it something feasible? I have requirement where I need to build a dynamic image via the python and display in the kibana dashboard in a popup/overlay. On…

---

## [File "vendor/bundle/jruby/2.5.0/gems/pleaserun-0.0.31/bin/pleaserun" with access permission 777, who knows why?](https://discuss.elastic.co/t/file-vendor-bundle-jruby-2-5-0-gems-pleaserun-0-0-31-bin-pleaserun-with-access-permission-777-who-knows-why/317933)

<div class="topic-metadata">

**Author:** [@weng77](https://discuss.elastic.co/u/weng77)\
**Replies:** 1\
**Last updated:** [November 12, 2022, 6:15am UTC](https://discuss.elastic.co/t/file-vendor-bundle-jruby-2-5-0-gems-pleaserun-0-0-31-bin-pleaserun-with-access-permission-777-who-knows-why/317933 "2022-11-12T06:15:14Z")

</div>

File access permission with 777 will make things world writeable, it's an awful idea. But in logstash 7.7.0~logstash 7.12.0 pkg(from https://www.elastic.co/cn/downloads/past-releases/), we find out two files in vendor/b…

---

## [LogStash - Add fields between two unique events (start and stop)](https://discuss.elastic.co/t/logstash-add-fields-between-two-unique-events-start-and-stop/317586)

<div class="topic-metadata">

**Author:** [@Frankie\_Braybon](https://discuss.elastic.co/u/Frankie_Braybon)\
**Replies:** 1\
**Last updated:** [November 12, 2022, 3:18am UTC](https://discuss.elastic.co/t/logstash-add-fields-between-two-unique-events-start-and-stop/317586 "2022-11-12T03:18:24Z")

</div>

Hi, I have logs shipping to Logstash via FileBeat, which I'm doing log enrichment on before passing on to Elasticsearch. One of the enrichments I would like to do is add a field to each event which is between two uniqu…

---

## [Logtash CSV Parser Fail Muline Value is counting next raw](https://discuss.elastic.co/t/logtash-csv-parser-fail-muline-value-is-counting-next-raw/318617)

<div class="topic-metadata">

**Author:** [@dharminfadia](https://discuss.elastic.co/u/dharminfadia)\
**Replies:** 10\
**Last updated:** [November 11, 2022, 6:33pm UTC](https://discuss.elastic.co/t/logtash-csv-parser-fail-muline-value-is-counting-next-raw/318617 "2022-11-11T18:33:14Z")

</div>

see in my First raw last coulumn have multiline and second raw haveing signle line

---

## [Multilingual search and retrieval of a translated field](https://discuss.elastic.co/t/multilingual-search-and-retrieval-of-a-translated-field/318683)

<div class="topic-metadata">

**Author:** [@ChristopherHS](https://discuss.elastic.co/u/ChristopherHS)\
**Replies:** 2\
**Last updated:** [November 11, 2022, 6:05pm UTC](https://discuss.elastic.co/t/multilingual-search-and-retrieval-of-a-translated-field/318683 "2022-11-11T18:05:55Z")

</div>

Hello, I have the following mapping: { "settings": { "analysis": { "analyzer": { "en\_stopwords": { "type": "standard", "stopwords": "\_english\_" }, "de\_stopwords":…

---

## [Logstash Not Starting On Reboot - Ubuntu](https://discuss.elastic.co/t/logstash-not-starting-on-reboot-ubuntu/318406)

<div class="topic-metadata">

**Author:** [@AlP9923](https://discuss.elastic.co/u/AlP9923)\
**Replies:** 5\
**Last updated:** [November 11, 2022, 5:19pm UTC](https://discuss.elastic.co/t/logstash-not-starting-on-reboot-ubuntu/318406 "2022-11-11T17:19:51Z")

</div>

Hi My single node setup works fine except on reboot of the Ubuntu server when Logstash usually does not auto start up. But using the systemctl start logstash works ok. It looks like the issue is that Logstash is trying…

---

## [Sorting identical timestamp of logs in kibana](https://discuss.elastic.co/t/sorting-identical-timestamp-of-logs-in-kibana/318746)

<div class="topic-metadata">

**Author:** [@Bikash\_Swain](https://discuss.elastic.co/u/Bikash_Swain)\
**Replies:** 0\
**Last updated:** [November 11, 2022, 1:57pm UTC](https://discuss.elastic.co/t/sorting-identical-timestamp-of-logs-in-kibana/318746 "2022-11-11T13:57:36Z")

</div>

Hi , I have filebeat-logstash-ES-kibana setup for index abc\* for one of the application log. In log file we have many occurrences of identical timestamp for messages/logs. sample log file below. when we are searching …

---

## [Logstash Syslog output plugin streaming adds additional headers](https://discuss.elastic.co/t/logstash-syslog-output-plugin-streaming-adds-additional-headers/318719)

<div class="topic-metadata">

**Author:** [@Anandh\_Kumar](https://discuss.elastic.co/u/Anandh_Kumar)\
**Replies:** 1\
**Last updated:** [November 11, 2022, 1:45pm UTC](https://discuss.elastic.co/t/logstash-syslog-output-plugin-streaming-adds-additional-headers/318719 "2022-11-11T13:45:43Z")

</div>

Hi We are using Logstash syslog output plugin v3.0.5 to stream audit log to a external SIEM server using TCP with SSL. It is observed that there are additional headers automatically appended by the plugin to the origina…

---

## [CEF message parsing](https://discuss.elastic.co/t/cef-message-parsing/318743)

<div class="topic-metadata">

**Author:** [@d\_c](https://discuss.elastic.co/u/d_c)\
**Replies:** 0\
**Last updated:** [November 11, 2022, 1:14pm UTC](https://discuss.elastic.co/t/cef-message-parsing/318743 "2022-11-11T13:14:15Z")

</div>

Hello, I'm using TCP Input plugin with CEF codec to receive CEF messages. Problem is, that some messages are not parsed parsed correctly. Message isn't processed as whole, but it's split at blankspace character within m…

---

## [Import saved objects through API](https://discuss.elastic.co/t/import-saved-objects-through-api/315481)

<div class="topic-metadata">

**Author:** [@hemmerlin](https://discuss.elastic.co/u/hemmerlin)\
**Replies:** 2\
**Last updated:** [October 14, 2022, 4:00pm UTC](https://discuss.elastic.co/t/import-saved-objects-through-api/315481 "2022-10-14T16:00:32Z")

</div>

Hello, To summarize this post, I'm able to import Kibana saved objects using the web UI, but I face some issues importing them using the API. We use a dashboard.ndjson file which is the result of a saved object export …

---

## [I wanted to have the top 10 API's with more latency in elastic dashboard](https://discuss.elastic.co/t/i-wanted-to-have-the-top-10-apis-with-more-latency-in-elastic-dashboard/318734)

<div class="topic-metadata">

**Author:** [@gatewaymaster](https://discuss.elastic.co/u/gatewaymaster)\
**Replies:** 0\
**Last updated:** [November 11, 2022, 11:24am UTC](https://discuss.elastic.co/t/i-wanted-to-have-the-top-10-apis-with-more-latency-in-elastic-dashboard/318734 "2022-11-11T11:24:25Z")

</div>

Hi Guyz, I am completely new to elastic, our application is hosted in kubernetes and all the logs are sending to elastic, we wanted to create a dashboard an done of the requirement is that in our gateway, we do get lots…

---

## [Any performance difference between "must\_not" clause and "query\_string" with NOT operator?](https://discuss.elastic.co/t/any-performance-difference-between-must-not-clause-and-query-string-with-not-operator/318729)

<div class="topic-metadata">

**Author:** [@astrodi](https://discuss.elastic.co/u/astrodi)\
**Replies:** 0\
**Last updated:** [November 11, 2022, 11:09am UTC](https://discuss.elastic.co/t/any-performance-difference-between-must-not-clause-and-query-string-with-not-operator/318729 "2022-11-11T11:09:39Z")

</div>

Hi there, I'm wondering, if there is any performance gain using must\_not clause over to query\_string using NOT operator (will be used inside filter and should clause). query\_string has obviously shorter scripture, no r…

---

## [Pipeline getting terminated with OrgJrubyExceptions::ThreadKill](https://discuss.elastic.co/t/pipeline-getting-terminated-with-orgjrubyexceptions-threadkill/318724)

<div class="topic-metadata">

**Author:** [@Hafis](https://discuss.elastic.co/u/Hafis)\
**Replies:** 0\
**Last updated:** [November 11, 2022, 10:25am UTC](https://discuss.elastic.co/t/pipeline-getting-terminated-with-orgjrubyexceptions-threadkill/318724 "2022-11-11T10:25:45Z")

</div>

Hi Am using logstash 8.4.0 with csv filter. Am facing an issue that logstash is getting killed itself. From the logs I can see that the pipeline is getting terminated. Below I have pasted sample logs. \[2022-11-11T06:40…

---

## [Master not discovered or elected yet](https://discuss.elastic.co/t/master-not-discovered-or-elected-yet/318706)

<div class="topic-metadata">

**Author:** [@usilva](https://discuss.elastic.co/u/usilva)\
**Replies:** 3\
**Last updated:** [November 11, 2022, 9:12am UTC](https://discuss.elastic.co/t/master-not-discovered-or-elected-yet/318706 "2022-11-11T09:12:46Z")

</div>

{"type": "server", "timestamp": "2022-11-11T05:46:01,375Z", "level": "WARN", "component": "o.e.c.c.ClusterFormationFailureHelper", "cluster.name": "elasticsearch", "node.name": "elasticsearch-master-0", "message": "mas…

---

## [Extract data from elasticsearch and store into mongodb](https://discuss.elastic.co/t/extract-data-from-elasticsearch-and-store-into-mongodb/318337)

<div class="topic-metadata">

**Author:** [@chinmoy\_padhi](https://discuss.elastic.co/u/chinmoy_padhi)\
**Replies:** 4\
**Last updated:** [November 11, 2022, 7:44am UTC](https://discuss.elastic.co/t/extract-data-from-elasticsearch-and-store-into-mongodb/318337 "2022-11-11T07:44:32Z")

</div>

Hi, I'm looking for an option to extract data from Elasticsearch and store into the mongodb using some python script. Please help me with that.

---

## [Winlogbeat events not parsed](https://discuss.elastic.co/t/winlogbeat-events-not-parsed/318518)

<div class="topic-metadata">

**Author:** [@vitkon](https://discuss.elastic.co/u/vitkon)\
**Replies:** 1\
**Last updated:** [November 11, 2022, 9:08am UTC](https://discuss.elastic.co/t/winlogbeat-events-not-parsed/318518 "2022-11-11T09:08:50Z")

</div>

Hello, I am using elasticstack v8. The messages are sent from winlogbeat -\> logstash -\> elastic. The message is arrived unparsed. Logstash config: input { beats { port =\> "5044" …

---

## [Elastic Dashboard code of Elastic.co](https://discuss.elastic.co/t/elastic-dashboard-code-of-elastic-co/318688)

<div class="topic-metadata">

**Author:** [@kelk](https://discuss.elastic.co/u/kelk)\
**Replies:** 2\
**Last updated:** [November 11, 2022, 7:13am UTC](https://discuss.elastic.co/t/elastic-dashboard-code-of-elastic-co/318688 "2022-11-11T07:13:25Z")

</div>

Just checking the stock ticker of Elastic https://ir.elastic.co/stock/stock-quote/default.aspx Any chance to get the code of the above ? Looks nice and clean and blazing fast. cheers

---

## [Network devices like switch and firewall logs not visible in ELk](https://discuss.elastic.co/t/network-devices-like-switch-and-firewall-logs-not-visible-in-elk/318711)

<div class="topic-metadata">

**Author:** [@vrkumar79](https://discuss.elastic.co/u/vrkumar79)\
**Replies:** 0\
**Last updated:** [November 11, 2022, 6:48am UTC](https://discuss.elastic.co/t/network-devices-like-switch-and-firewall-logs-not-visible-in-elk/318711 "2022-11-11T06:48:25Z")

</div>

network devices like switches and firewall logs are not visible in Elk. we are using customized UDP ports for each location,

---

## [Kibana unavailable](https://discuss.elastic.co/t/kibana-unavailable/316552)

<div class="topic-metadata">

**Author:** [@not\_correct](https://discuss.elastic.co/u/not_correct)\
**Replies:** 8\
**Last updated:** [October 14, 2022, 1:26pm UTC](https://discuss.elastic.co/t/kibana-unavailable/316552 "2022-10-14T13:26:45Z")

</div>

Hi, I am running into an issue: the kibana is not available. When I check the log it gives me the error that kibana version is not compliant with the version of elasticsearch. It looks like I have to downgrade it in ord…

---

## [Elasticsearch8.5.0 jar hell problem](https://discuss.elastic.co/t/elasticsearch8-5-0-jar-hell-problem/318619)

<div class="topic-metadata">

**Author:** [@asasas234](https://discuss.elastic.co/u/asasas234)\
**Replies:** 1\
**Last updated:** [November 11, 2022, 1:10am UTC](https://discuss.elastic.co/t/elasticsearch8-5-0-jar-hell-problem/318619 "2022-11-11T01:10:51Z")

</div>

warning: ignoring JAVA\_HOME=/home/lizhibo/.sdkman/candidates/java/current; using bundled JDK java=/home/lizhibo/elasticsearch-8.5.0/jdk/bin/java \[2022-11-10T15:23:01,353\]\[ERROR\]\[o.e.b.Elasticsearch \] \[node-1\] fatal …

---

## [Filebeat Apache module not showing data on Dashboards when using Logstash](https://discuss.elastic.co/t/filebeat-apache-module-not-showing-data-on-dashboards-when-using-logstash/318594)

<div class="topic-metadata">

**Author:** [@Carlos\_T](https://discuss.elastic.co/u/Carlos_T)\
**Replies:** 12\
**Last updated:** [November 10, 2022, 11:08pm UTC](https://discuss.elastic.co/t/filebeat-apache-module-not-showing-data-on-dashboards-when-using-logstash/318594 "2022-11-10T23:08:08Z")

</div>

Good afternoon all. I've recently installed a filebeat and enabled the system and apache modules. After that I set the filebeat.yml to point to ES and Kibana and run the 'filebeat setup -e' Everything went as expecte…

---

## [Three Node Elastic Cluster balance issue](https://discuss.elastic.co/t/three-node-elastic-cluster-balance-issue/318680)

<div class="topic-metadata">

**Author:** [@alex\_sws](https://discuss.elastic.co/u/alex_sws)\
**Replies:** 6\
**Last updated:** [November 10, 2022, 10:08pm UTC](https://discuss.elastic.co/t/three-node-elastic-cluster-balance-issue/318680 "2022-11-10T22:08:58Z")

</div>

I have a 3 node elastic cluster with each node having equal disk space (250 Gb) but for some reason two of the nodes have significant more data usage then the others. When reviewing the servers, all the data usage is tie…

---

## [Unable to get rule triggered](https://discuss.elastic.co/t/unable-to-get-rule-triggered/317448)

<div class="topic-metadata">

**Author:** [@GUruisaDog](https://discuss.elastic.co/u/GUruisaDog)\
**Replies:** 6\
**Last updated:** [November 10, 2022, 8:53pm UTC](https://discuss.elastic.co/t/unable-to-get-rule-triggered/317448 "2022-11-10T20:53:34Z")

</div>

My current version of ES Security is on 7.16.1. I was trying to setup a threshold rule, and everything goes well. I could see the result from the preview and such. However, after created the rule and activate the rule, n…

---

## [How to enable authentication with logstash email output](https://discuss.elastic.co/t/how-to-enable-authentication-with-logstash-email-output/318473)

<div class="topic-metadata">

**Author:** [@learningelastic](https://discuss.elastic.co/u/learningelastic)\
**Replies:** 11\
**Last updated:** [November 10, 2022, 5:28pm UTC](https://discuss.elastic.co/t/how-to-enable-authentication-with-logstash-email-output/318473 "2022-11-10T17:28:44Z")

</div>

I want to learn how to use logstash with mailtrap smtp for development purposes. I installed logstash then ran this command: /usr/share/logstash/bin/logstash -e 'input { stdin { } } output { email { to =\> "user@examp…

---

## [What is boost in similarity score function?](https://discuss.elastic.co/t/what-is-boost-in-similarity-score-function/318091)

<div class="topic-metadata">

**Author:** [@fsanzestevez](https://discuss.elastic.co/u/fsanzestevez)\
**Replies:** 1\
**Last updated:** [November 10, 2022, 4:36pm UTC](https://discuss.elastic.co/t/what-is-boost-in-similarity-score-function/318091 "2022-11-10T16:36:26Z")

</div>

Hi, I have a question regarding the similarity function with BM25. I understand tf and idf. However it's not clear for me what the boost variable is and what it depends on. When I get the explanation of the score for …

[Previous page](https://discuss.elastic.co/tag/none.md?no_tags=true&page=499)

[Next page](https://discuss.elastic.co/tag/none.md?no_tags=true&page=501)
