# \#none

**URL:** https://discuss.elastic.co/tag/none.md?no_tags=true&page=503

[Latest](https://discuss.elastic.co/latest.md) · [Categories](https://discuss.elastic.co/categories.md) · [Tags](https://discuss.elastic.co/tags.md)

**Page:** 504

---

## [Use Elastic for Kubernetes monitoring](https://discuss.elastic.co/t/use-elastic-for-kubernetes-monitoring/318353)

<div class="topic-metadata">

**Author:** [@EDzhelyov](https://discuss.elastic.co/u/EDzhelyov)\
**Replies:** 1\
**Last updated:** [November 8, 2022, 12:35pm UTC](https://discuss.elastic.co/t/use-elastic-for-kubernetes-monitoring/318353 "2022-11-08T12:35:57Z")

</div>

We are trying to replace our Prometheus metrics and alarms with the Elastic stack and run into some issues. For example, with Prometheus, we use the up metric to create an alarm that will tell us if a given service, lik…

---

## [Threshold rule can't group by with source.ip but only with source.ip.keyword](https://discuss.elastic.co/t/threshold-rule-cant-group-by-with-source-ip-but-only-with-source-ip-keyword/317761)

<div class="topic-metadata">

**Author:** [@Simone\_Calo](https://discuss.elastic.co/u/Simone_Calo)\
**Replies:** 10\
**Last updated:** [November 8, 2022, 11:35am UTC](https://discuss.elastic.co/t/threshold-rule-cant-group-by-with-source-ip-but-only-with-source-ip-keyword/317761 "2022-11-08T11:35:36Z")

</div>

My problem consists in defining a threshold rule in the group by field. I can only enter source.ip.keyword and not source.ip. The consequence of this is that the rule fails every time with the following error: Bu…

---

## [KQL query for fields with a value which is not \`-\`](https://discuss.elastic.co/t/kql-query-for-fields-with-a-value-which-is-not/318098)

<div class="topic-metadata">

**Author:** [@mikewillis](https://discuss.elastic.co/u/mikewillis)\
**Replies:** 7\
**Last updated:** [November 8, 2022, 11:12am UTC](https://discuss.elastic.co/t/kql-query-for-fields-with-a-value-which-is-not/318098 "2022-11-08T11:12:08Z")

</div>

Kibana 7.17. I've got some indices where documents contain a field called username . Sometimes the value is a username, like bob or alice and often the value is -. What's a KQL query that will return documents where …

---

## [Logstash 7.17 update OpenJDK to 11.0.17](https://discuss.elastic.co/t/logstash-7-17-update-openjdk-to-11-0-17/317350)

<div class="topic-metadata">

**Author:** [@brilong](https://discuss.elastic.co/u/brilong)\
**Replies:** 2\
**Last updated:** [November 8, 2022, 10:56am UTC](https://discuss.elastic.co/t/logstash-7-17-update-openjdk-to-11-0-17/317350 "2022-11-08T10:56:29Z")

</div>

Is Logstash 7.17 still maintained and is there a plan to upgrade the built-in JDK to 11.0.17? This fixes various CVEs for those of us unable to upgrade to logstash 8.4 at this time. https://openjdk.org/groups/vulnerabi…

---

## [Elastic Certified Analyst Exam](https://discuss.elastic.co/t/elastic-certified-analyst-exam/318360)

<div class="topic-metadata">

**Author:** [@linhz](https://discuss.elastic.co/u/linhz)\
**Replies:** 4\
**Last updated:** [November 8, 2022, 10:47am UTC](https://discuss.elastic.co/t/elastic-certified-analyst-exam/318360 "2022-11-08T10:47:20Z")

</div>

Hi, Im super disappointed that this is the 2nd time i failed the Elastic Certified Analyst Exam. Understand the concept by go through all exam objectives, attended all the training materials and make lots of practice ye…

---

## [Cloudflare Integration problem with delayed ingestion](https://discuss.elastic.co/t/cloudflare-integration-problem-with-delayed-ingestion/317381)

<div class="topic-metadata">

**Author:** [@yago82](https://discuss.elastic.co/u/yago82)\
**Replies:** 3\
**Last updated:** [November 8, 2022, 10:01am UTC](https://discuss.elastic.co/t/cloudflare-integration-problem-with-delayed-ingestion/317381 "2022-11-08T10:01:32Z")

</div>

Hi everybody, using Cloduflare integration I noticed that if the machine where the elastic agent is installed falls for a certain period, Elastic is not able to recover the accumulated ingestion delay. I'm talking abou…

---

## [Hide/Disable runtime fields from Kibana available fields](https://discuss.elastic.co/t/hide-disable-runtime-fields-from-kibana-available-fields/301848)

<div class="topic-metadata">

**Author:** [@Ofir\_Edi](https://discuss.elastic.co/u/Ofir_Edi)\
**Replies:** 11\
**Last updated:** [November 8, 2022, 9:34am UTC](https://discuss.elastic.co/t/hide-disable-runtime-fields-from-kibana-available-fields/301848 "2022-11-08T09:34:09Z")

</div>

Hi, Is there a way to hide/disable/pick certain runtime fields from available fields in Discover? When applying many runtime fields, Discover page takes forever to load due to the number of available fields, While Elast…

---

## [8.4.2: "incompatible encodings: CP850 and UTF-8" - Issue sending DB records to Elastic after upgrade to Elastic 8.4.2 from 8.3.2](https://discuss.elastic.co/t/8-4-2-incompatible-encodings-cp850-and-utf-8-issue-sending-db-records-to-elastic-after-upgrade-to-elastic-8-4-2-from-8-3-2/315697)

<div class="topic-metadata">

**Author:** [@stevedearl](https://discuss.elastic.co/u/stevedearl)\
**Replies:** 4\
**Last updated:** [November 8, 2022, 8:59am UTC](https://discuss.elastic.co/t/8-4-2-incompatible-encodings-cp850-and-utf-8-issue-sending-db-records-to-elastic-after-upgrade-to-elastic-8-4-2-from-8-3-2/315697 "2022-11-08T08:59:40Z")

</div>

Hi All, I've been running the 8.3.2 Elastic products for some months (ELK), using logstash to poll an MSSQL DB regularly and pull the data into Elasticsearch. This has been working without any significant problems. I …

---

## [What's the correct ILM setup for .monitoring-\*-7 indices?](https://discuss.elastic.co/t/whats-the-correct-ilm-setup-for-monitoring-7-indices/318398)

<div class="topic-metadata">

**Author:** [@alytkowski](https://discuss.elastic.co/u/alytkowski)\
**Replies:** 0\
**Last updated:** [November 8, 2022, 8:38am UTC](https://discuss.elastic.co/t/whats-the-correct-ilm-setup-for-monitoring-7-indices/318398 "2022-11-08T08:38:15Z")

</div>

As per title, what's the correct ILM setup for the .monitoring-\*-7 indices? By default, they rollover every day and delete after 7 days. However, I need them to delete much faster, because in my small ELK setup, these in…

---

## [ES cannot search for special characters when using wildcard search](https://discuss.elastic.co/t/es-cannot-search-for-special-characters-when-using-wildcard-search/318332)

<div class="topic-metadata">

**Author:** [@surkovoleg2010](https://discuss.elastic.co/u/surkovoleg2010)\
**Replies:** 3\
**Last updated:** [November 8, 2022, 8:15am UTC](https://discuss.elastic.co/t/es-cannot-search-for-special-characters-when-using-wildcard-search/318332 "2022-11-08T08:15:51Z")

</div>

Hello, We are using query\_string for a quick search but looks like does not correctly work. For instance I can find results using: { "query": { "query\_string": { "query": "oleg$qwerty.com", …

---

## [Elasticsearch curl error](https://discuss.elastic.co/t/elasticsearch-curl-error/318391)

<div class="topic-metadata">

**Author:** [@thepawankumar](https://discuss.elastic.co/u/thepawankumar)\
**Replies:** 1\
**Last updated:** [November 8, 2022, 7:14am UTC](https://discuss.elastic.co/t/elasticsearch-curl-error/318391 "2022-11-08T07:14:04Z")

</div>

curl -X GET -u something:PASSWD https://20.197.3.229:5500 curl: (60) SSL certificate problem: self signed certificate in certificate chain More details here: curl - SSL CA Certificates curl failed to verify the legiti…

---

## [Unrecognized character escape ':'](https://discuss.elastic.co/t/unrecognized-character-escape/318393)

<div class="topic-metadata">

**Author:** [@MStrauch](https://discuss.elastic.co/u/MStrauch)\
**Replies:** 0\
**Last updated:** [November 8, 2022, 7:10am UTC](https://discuss.elastic.co/t/unrecognized-character-escape/318393 "2022-11-08T07:10:29Z")

</div>

Hi, I'm executing follow fulltext query string: "query": { "bool": { "filter": \[ { "nested": { "path": "@payload.identifier", "query": { "query\_string":…

---

## [Monitoring AIX metrics to ELK](https://discuss.elastic.co/t/monitoring-aix-metrics-to-elk/318390)

<div class="topic-metadata">

**Author:** [@Aniket\_Pant](https://discuss.elastic.co/u/Aniket_Pant)\
**Replies:** 0\
**Last updated:** [November 8, 2022, 6:54am UTC](https://discuss.elastic.co/t/monitoring-aix-metrics-to-elk/318390 "2022-11-08T06:54:14Z")

</div>

Hi Community, We want infra metrics data to ELK. The problem is that elastic beats does not support IBM AIX servers. Is there any other way we can ship metric data to ELK.

---

## [Node Uptime Bar Graph](https://discuss.elastic.co/t/node-uptime-bar-graph/318385)

<div class="topic-metadata">

**Author:** [@Aniket\_Pant](https://discuss.elastic.co/u/Aniket_Pant)\
**Replies:** 1\
**Last updated:** [November 8, 2022, 6:52am UTC](https://discuss.elastic.co/t/node-uptime-bar-graph/318385 "2022-11-08T06:52:20Z")

</div>

Hi Community, ELK version 7.17.5. We want to monitor Node/System availability using metricbeat. We want to create a bar graph of this. I created a dashboard for this The issue i am facing here is for one node i am…

---

## [Elastic Search cannot login after disk full (\>90%)](https://discuss.elastic.co/t/elastic-search-cannot-login-after-disk-full-90/317511)

<div class="topic-metadata">

**Author:** [@zahir](https://discuss.elastic.co/u/zahir)\
**Replies:** 5\
**Last updated:** [November 8, 2022, 6:42am UTC](https://discuss.elastic.co/t/elastic-search-cannot-login-after-disk-full-90/317511 "2022-11-08T06:42:01Z")

</div>

I suddenly unable to login Elastic Search after my snapshot backup is failed. I perform the snapshot backup after disk usage is more than 90%. Now my snapshot failed and my disk is 100% usage. Appreciate if anyone f…

---

## [High Availability of Kibana running on k8s](https://discuss.elastic.co/t/high-availability-of-kibana-running-on-k8s/317147)

<div class="topic-metadata">

**Author:** [@Nikita\_Ivankov](https://discuss.elastic.co/u/Nikita_Ivankov)\
**Replies:** 3\
**Last updated:** [November 8, 2022, 6:40am UTC](https://discuss.elastic.co/t/high-availability-of-kibana-running-on-k8s/317147 "2022-11-08T06:40:10Z")

</div>

Hi, we are running an EFK stack on top of k8s clusters in AWS. To deploy both elastic and kibana we use Kubernetes operator The installation contains several elasticsearch pods, but one kibana pod. The kibana is expos…

---

## [Elastic Search安装完成后无法启动](https://discuss.elastic.co/t/elastic-search/317941)

<div class="topic-metadata">

**Author:** [@Shadow\_CHN](https://discuss.elastic.co/u/Shadow_CHN)\
**Replies:** 10\
**Last updated:** [November 8, 2022, 5:47am UTC](https://discuss.elastic.co/t/elastic-search/317941 "2022-11-08T05:47:13Z")

</div>

在CentOS7.8上安装配置完成后初次启动会在输出以下日志后卡住，请问有什么解决办法吗？ \[2022-11-01T22:48:44,788\]\[INFO \]\[o.e.n.Node \] \[node-1\] started {node-1}{G9dqjNsoRKKiW16C2kJYRQ}{09N\_x9F9Tjuqd3OeeYchEg}{node-1}{10.11.0.2}{10.11.0.2:9300}{cdfh…

---

## [Data Indices are recovery](https://discuss.elastic.co/t/data-indices-are-recovery/316887)

<div class="topic-metadata">

**Author:** [@Ravi\_S1](https://discuss.elastic.co/u/Ravi_S1)\
**Replies:** 5\
**Last updated:** [November 8, 2022, 5:19am UTC](https://discuss.elastic.co/t/data-indices-are-recovery/316887 "2022-11-08T05:19:52Z")

</div>

I would like to check with community on recovery state of indices... after upgrading the ELK stack to 8.4.1, i could see that data indices are recovering very often.. Is there any reason for this behavior. GET \_cat/reco…

---

## [No results in Kibana search](https://discuss.elastic.co/t/no-results-in-kibana-search/318378)

<div class="topic-metadata">

**Author:** [@azamf](https://discuss.elastic.co/u/azamf)\
**Replies:** 5\
**Last updated:** [November 8, 2022, 3:09am UTC](https://discuss.elastic.co/t/no-results-in-kibana-search/318378 "2022-11-08T03:09:24Z")

</div>

I'm trying to search against an existing index but the request yields no results. I know there is data since other users can see the index and view data in the same time frame. I am able to view data in most indices in …

---

## [KNN search things in ES V8.4.0](https://discuss.elastic.co/t/knn-search-things-in-es-v8-4-0/313748)

<div class="topic-metadata">

**Author:** [@CGM397](https://discuss.elastic.co/u/CGM397)\
**Replies:** 5\
**Last updated:** [November 7, 2022, 11:54pm UTC](https://discuss.elastic.co/t/knn-search-things-in-es-v8-4-0/313748 "2022-11-07T23:54:00Z")

</div>

Hi there, I am facing some issues with knn search in es v8, hope someone can help: env: five es v8.4.0 nodes in a cluster each node in a linux server(Ubuntu 16.04, 48 Logic Cores, 180GB Memory) index mapping:(five sh…

---

## [Looking for a way to grab named stats from DNS servers and output them to Elastic for better visibility](https://discuss.elastic.co/t/looking-for-a-way-to-grab-named-stats-from-dns-servers-and-output-them-to-elastic-for-better-visibility/318364)

<div class="topic-metadata">

**Author:** [@hardeepsingh3](https://discuss.elastic.co/u/hardeepsingh3)\
**Replies:** 1\
**Last updated:** [November 7, 2022, 8:28pm UTC](https://discuss.elastic.co/t/looking-for-a-way-to-grab-named-stats-from-dns-servers-and-output-them-to-elastic-for-better-visibility/318364 "2022-11-07T20:28:33Z")

</div>

What is the best way to grab the named stats such as Resolver Statistics (IPv4 queries sent, IPv4 responses received etc) and Cache Statistics (cache hits, cache misses etc) and parse them to be able to visualize them on…

---

## [ElasticSearch Instance is going down periodically with no errors in logs](https://discuss.elastic.co/t/elasticsearch-instance-is-going-down-periodically-with-no-errors-in-logs/317133)

<div class="topic-metadata">

**Author:** [@nandeeswara](https://discuss.elastic.co/u/nandeeswara)\
**Replies:** 7\
**Last updated:** [November 7, 2022, 5:24pm UTC](https://discuss.elastic.co/t/elasticsearch-instance-is-going-down-periodically-with-no-errors-in-logs/317133 "2022-11-07T17:24:31Z")

</div>

We have an application in Liferay portal and it is using Elasticsearch service as remote server. Elasticsearch on a remote server is going down periodically even though the memory , CPU are highly available. Currently …

---

## [Fuzziness parameter in a query](https://discuss.elastic.co/t/fuzziness-parameter-in-a-query/318344)

<div class="topic-metadata">

**Author:** [@Ivo\_Tavares](https://discuss.elastic.co/u/Ivo_Tavares)\
**Replies:** 1\
**Last updated:** [November 7, 2022, 3:23pm UTC](https://discuss.elastic.co/t/fuzziness-parameter-in-a-query/318344 "2022-11-07T15:23:14Z")

</div>

I'm trying to understand the documentation of the fuzziness parameter. I'm not sure what the low and high values for AUTO mean. Why is it that when I do a query with "AUTO:0,2" I get a result(supposedly an exact match)…

---

## [Visualize Custom Time from a Scripted Field](https://discuss.elastic.co/t/visualize-custom-time-from-a-scripted-field/318272)

<div class="topic-metadata">

**Author:** [@g.bas](https://discuss.elastic.co/u/g.bas)\
**Replies:** 1\
**Last updated:** [November 7, 2022, 4:42pm UTC](https://discuss.elastic.co/t/visualize-custom-time-from-a-scripted-field/318272 "2022-11-07T16:42:51Z")

</div>

Hello I am new to Kibana and would like to create my own visual representation where the horizontal axis represents time which is derived from one of my runtime fields. The field is called Duration and is in milliseconds…

---

## [Need Help to extract custom log data using gork](https://discuss.elastic.co/t/need-help-to-extract-custom-log-data-using-gork/318350)

<div class="topic-metadata">

**Author:** [@ipasa](https://discuss.elastic.co/u/ipasa)\
**Replies:** 1\
**Last updated:** [November 7, 2022, 4:20pm UTC](https://discuss.elastic.co/t/need-help-to-extract-custom-log-data-using-gork/318350 "2022-11-07T16:20:43Z")

</div>

We want to extract some custom logs like this, \[2022-10-19 07:45:21\] test\_site.INFO: REQUEST: \[{"username":"6HANT","password":"u5469!230","grant\_type":"password"},{"Content-Type":"application/json"},"https://abc.SD.com:…

---

## [Interval query with filters to include in max gap?](https://discuss.elastic.co/t/interval-query-with-filters-to-include-in-max-gap/318346)

<div class="topic-metadata">

**Author:** [@Broccolimon](https://discuss.elastic.co/u/Broccolimon)\
**Replies:** 0\
**Last updated:** [November 7, 2022, 3:26pm UTC](https://discuss.elastic.co/t/interval-query-with-filters-to-include-in-max-gap/318346 "2022-11-07T15:26:42Z")

</div>

Hey! I have a query that is looking for the terms "fox" and "brown" in an interval of 10 positions and i would like to filter any result with the word "quick" which is 5 position before interval start and 5 position aft…

---

## [Phrase\_slop does not affect query\_string](https://discuss.elastic.co/t/phrase-slop-does-not-affect-query-string/318345)

<div class="topic-metadata">

**Author:** [@MultiheadAttention](https://discuss.elastic.co/u/MultiheadAttention)\
**Replies:** 2\
**Last updated:** [November 7, 2022, 3:21pm UTC](https://discuss.elastic.co/t/phrase-slop-does-not-affect-query-string/318345 "2022-11-07T15:21:51Z")

</div>

My search query { "query\_string": {"query": 'foo bar', "phrase\_slop": 1, "default\_operator": "AND"} } returns the following results: 'foo bar' 'fo…

---

## [Every log line sent to ES create new index](https://discuss.elastic.co/t/every-log-line-sent-to-es-create-new-index/318340)

<div class="topic-metadata">

**Author:** [@florind](https://discuss.elastic.co/u/florind)\
**Replies:** 3\
**Last updated:** [November 7, 2022, 2:59pm UTC](https://discuss.elastic.co/t/every-log-line-sent-to-es-create-new-index/318340 "2022-11-07T14:59:58Z")

</div>

Hello, I'm using fluentd to send pod logs to ES 8.5 My problem is that each log sent is creating a new index, so i end up having a very large number of indices. What I'd like to have is one index per day, and keep the…

---

## [Agrégation - Demande aide](https://discuss.elastic.co/t/agregation-demande-aide/318307)

<div class="topic-metadata">

**Author:** [@Artefact](https://discuss.elastic.co/u/Artefact)\
**Replies:** 5\
**Last updated:** [November 7, 2022, 2:38pm UTC](https://discuss.elastic.co/t/agregation-demande-aide/318307 "2022-11-07T14:38:18Z")

</div>

Bonjour, Pour un projet, mes requêtes d'agrégation ne me renvoient pas toutes les valeurs attendues et je n'arrive pas à comprendre pourquoi, si quelqu'un a une idée ou une piste à me communiquer :wink: L'index et les …

---

## ["best\_compression" not compressing the data](https://discuss.elastic.co/t/best-compression-not-compressing-the-data/318320)

<div class="topic-metadata">

**Author:** [@ashika](https://discuss.elastic.co/u/ashika)\
**Replies:** 2\
**Last updated:** [November 7, 2022, 2:27pm UTC](https://discuss.elastic.co/t/best-compression-not-compressing-the-data/318320 "2022-11-07T14:27:25Z")

</div>

Hello team, I was applying "best\_compression" compressing type to my existing elasticsearch indices, but I don't see any significant reduction happening in the indices size. The steps followed were : Close the indices …

[Previous page](https://discuss.elastic.co/tag/none.md?no_tags=true&page=502)

[Next page](https://discuss.elastic.co/tag/none.md?no_tags=true&page=504)
