# \#none

**URL:** https://discuss.elastic.co/tag/none.md?no_tags=true&page=504

[Latest](https://discuss.elastic.co/latest.md) · [Categories](https://discuss.elastic.co/categories.md) · [Tags](https://discuss.elastic.co/tags.md)

**Page:** 505

---

## [No logs from Elastic Agent](https://discuss.elastic.co/t/no-logs-from-elastic-agent/318321)

<div class="topic-metadata">

**Author:** [@EExisT](https://discuss.elastic.co/u/EExisT)\
**Replies:** 1\
**Last updated:** [November 7, 2022, 1:49pm UTC](https://discuss.elastic.co/t/no-logs-from-elastic-agent/318321 "2022-11-07T13:49:42Z")

</div>

Hello, I'm trying to ingest datas from elastic agents but I have no logs. This is the situation: Thank u

---

## [At least one primary shard for the index \[.security-7\] is unavailable issue](https://discuss.elastic.co/t/at-least-one-primary-shard-for-the-index-security-7-is-unavailable-issue/316149)

<div class="topic-metadata">

**Author:** [@sahere37](https://discuss.elastic.co/u/sahere37)\
**Replies:** 8\
**Last updated:** [November 7, 2022, 12:31pm UTC](https://discuss.elastic.co/t/at-least-one-primary-shard-for-the-index-security-7-is-unavailable-issue/316149 "2022-11-07T12:31:23Z")

</div>

Hi I have a two-node cluster with IP "0.0.0.1" , "0.0.0.2". One of my VMs "0.0.0.2" suddenly stopped, and when I start it, the cluster health was RED. Then I restart both VMs again and below message has been found in th…

---

## [Can we tokenise emailid text along with split characters in elasticsearch and prefixes tokens?](https://discuss.elastic.co/t/can-we-tokenise-emailid-text-along-with-split-characters-in-elasticsearch-and-prefixes-tokens/318329)

<div class="topic-metadata">

**Author:** [@Karthik\_Amar](https://discuss.elastic.co/u/Karthik_Amar)\
**Replies:** 0\
**Last updated:** [November 7, 2022, 12:12pm UTC](https://discuss.elastic.co/t/can-we-tokenise-emailid-text-along-with-split-characters-in-elasticsearch-and-prefixes-tokens/318329 "2022-11-07T12:12:08Z")

</div>

I have a use case where i want to tokenise emailId with starts with filter along with punctuations. for example. email - ona.ki@gl.co I want to know whether the the following matches for the above is possible to achiev…

---

## [ElasticSearch deletes documents in an index automatically](https://discuss.elastic.co/t/elasticsearch-deletes-documents-in-an-index-automatically/318316)

<div class="topic-metadata">

**Author:** [@joanjanku2000](https://discuss.elastic.co/u/joanjanku2000)\
**Replies:** 19\
**Last updated:** [November 7, 2022, 11:51am UTC](https://discuss.elastic.co/t/elasticsearch-deletes-documents-in-an-index-automatically/318316 "2022-11-07T11:51:17Z")

</div>

I have configured an ELK Cluster with 5 nodes, one being master and the other slaves. I index logs in the cluster once a day using logstash. I use a CronJOB (script) to copy the log files to the configured logstash direc…

---

## [Partial word search with free text search string in multiple fields](https://discuss.elastic.co/t/partial-word-search-with-free-text-search-string-in-multiple-fields/318311)

<div class="topic-metadata">

**Author:** [@Sagar\_Viradiya](https://discuss.elastic.co/u/Sagar_Viradiya)\
**Replies:** 0\
**Last updated:** [November 7, 2022, 10:02am UTC](https://discuss.elastic.co/t/partial-word-search-with-free-text-search-string-in-multiple-fields/318311 "2022-11-07T10:02:13Z")

</div>

Currently I am using multi\_match as below to search partial text string { "query": { "multi\_match": { "fields": \[ "model", "make", "year.keyword" …

---

## [Need to display only row records that shows only MAX/MIN Value count among all the records.(Kibana table or Enhanced table)](https://discuss.elastic.co/t/need-to-display-only-row-records-that-shows-only-max-min-value-count-among-all-the-records-kibana-table-or-enhanced-table/318116)

<div class="topic-metadata">

**Author:** [@PRASHANT\_MEHTA](https://discuss.elastic.co/u/PRASHANT_MEHTA)\
**Replies:** 4\
**Last updated:** [November 7, 2022, 7:48am UTC](https://discuss.elastic.co/t/need-to-display-only-row-records-that-shows-only-max-min-value-count-among-all-the-records-kibana-table-or-enhanced-table/318116 "2022-11-07T07:48:46Z")

</div>

Hello All, I want to achieve this usecase where I just want to display only those records in kibana table whereI need to show only those row records with MAX/MIN count value. Kibana version 7.9.1,How can this be achiev…

---

## [Elasticsearch - Attempted to resurrect connection to dead ES instance, but got an error](https://discuss.elastic.co/t/elasticsearch-attempted-to-resurrect-connection-to-dead-es-instance-but-got-an-error/318291)

<div class="topic-metadata">

**Author:** [@Zay\_Lin\_Htun](https://discuss.elastic.co/u/Zay_Lin_Htun)\
**Replies:** 5\
**Last updated:** [November 7, 2022, 8:49am UTC](https://discuss.elastic.co/t/elasticsearch-attempted-to-resurrect-connection-to-dead-es-instance-but-got-an-error/318291 "2022-11-07T08:49:19Z")

</div>

My Logstash can not connect to Elastic Search. My Logstash beats.conf config input { beats { port =\> 5044 } } output { elasticsearch { hosts =\> \["18.00.00.00:9200"\] } stdout { codec =\> rubydebug } } My Fil…

---

## [Error 8.5.0 running as systemctl service](https://discuss.elastic.co/t/error-8-5-0-running-as-systemctl-service/318278)

<div class="topic-metadata">

**Author:** [@georgios.mpouras](https://discuss.elastic.co/u/georgios.mpouras)\
**Replies:** 2\
**Last updated:** [November 7, 2022, 8:37am UTC](https://discuss.elastic.co/t/error-8-5-0-running-as-systemctl-service/318278 "2022-11-07T08:37:28Z")

</div>

I have a new installation of logstash 8.5.0 at Alma 9 from the repo When I run logstash as user logstash from the command line everything works as expocted sudo -u logstash /usr/share/logstash/bin/logstash "--path.sett…

---

## [How to remove transferred logs with Logstash?](https://discuss.elastic.co/t/how-to-remove-transferred-logs-with-logstash/318249)

<div class="topic-metadata">

**Author:** [@Vladimir\_Routine](https://discuss.elastic.co/u/Vladimir_Routine)\
**Replies:** 1\
**Last updated:** [November 7, 2022, 5:58am UTC](https://discuss.elastic.co/t/how-to-remove-transferred-logs-with-logstash/318249 "2022-11-07T05:58:21Z")

</div>

I want to use Logstash to move my log files from Mongodb to Elasticsearch. Is there any option to remove transferred logs from mongo?

---

## [Logstash not working fine](https://discuss.elastic.co/t/logstash-not-working-fine/318284)

<div class="topic-metadata">

**Author:** [@greeklegend](https://discuss.elastic.co/u/greeklegend)\
**Replies:** 5\
**Last updated:** [November 7, 2022, 5:27am UTC](https://discuss.elastic.co/t/logstash-not-working-fine/318284 "2022-11-07T05:27:48Z")

</div>

When I am trying to run as I am transferring data from csv file to Elasticsearch using logstash. My logstash.conf as follows input { file { path =\> "C:/Users/user/Downloads/abc/abc.csv" start\_position =\> "be…

---

## [Logstash issues/ is not working](https://discuss.elastic.co/t/logstash-issues-is-not-working/318265)

<div class="topic-metadata">

**Author:** [@Zay\_Lin\_Htun](https://discuss.elastic.co/u/Zay_Lin_Htun)\
**Replies:** 4\
**Last updated:** [November 7, 2022, 2:19am UTC](https://discuss.elastic.co/t/logstash-issues-is-not-working/318265 "2022-11-07T02:19:21Z")

</div>

There are three AWS EC2 instances. First one is Elasticsearch+ Kibana, Second one is logstash and third one UbuntuOS which will send logs to logstash. I deployed Elasticsearch and Kibana together on AWS EC2 instancens a…

---

## [Splitting for Logstash working intermittently](https://discuss.elastic.co/t/splitting-for-logstash-working-intermittently/318280)

<div class="topic-metadata">

**Author:** [@eleong](https://discuss.elastic.co/u/eleong)\
**Replies:** 2\
**Last updated:** [November 7, 2022, 2:08am UTC](https://discuss.elastic.co/t/splitting-for-logstash-working-intermittently/318280 "2022-11-07T02:08:49Z")

</div>

Hi, Currently, I have Logstash configured for splitting. The issue is that, sometimes it works, sometimes it goes about 10-15 minutes without any output (it suppose to have an output every 5 minutes). At the backend, I…

---

## [Flattened Data Type Sorting](https://discuss.elastic.co/t/flattened-data-type-sorting/318262)

<div class="topic-metadata">

**Author:** [@kailash\_lambe](https://discuss.elastic.co/u/kailash_lambe)\
**Replies:** 0\
**Last updated:** [November 6, 2022, 2:41pm UTC](https://discuss.elastic.co/t/flattened-data-type-sorting/318262 "2022-11-06T14:41:22Z")

</div>

Hi Team, I need your input for one of the tasks, I am working on one of the project where I need the different multiple price combinations for each product and since we do not have control over the number of combination…

---

## [Relevance of results on multiple fields](https://discuss.elastic.co/t/relevance-of-results-on-multiple-fields/318245)

<div class="topic-metadata">

**Author:** [@ChristopherHS](https://discuss.elastic.co/u/ChristopherHS)\
**Replies:** 0\
**Last updated:** [November 5, 2022, 6:55pm UTC](https://discuss.elastic.co/t/relevance-of-results-on-multiple-fields/318245 "2022-11-05T18:55:20Z")

</div>

Hello, We are new to the use of Elasticsearch, we can't make a setting to display the results with the right relevance on the phrase in the search. To give an example, when we do a search with the phrase Facebook Data …

---

## [Inner\_hits in has parent giving error-"Couldn't find nested source for path currentCompany"](https://discuss.elastic.co/t/inner-hits-in-has-parent-giving-error-couldnt-find-nested-source-for-path-currentcompany/318232)

<div class="topic-metadata">

**Author:** [@Venkat\_Koushik](https://discuss.elastic.co/u/Venkat_Koushik)\
**Replies:** 0\
**Last updated:** [November 5, 2022, 10:18am UTC](https://discuss.elastic.co/t/inner-hits-in-has-parent-giving-error-couldnt-find-nested-source-for-path-currentcompany/318232 "2022-11-05T10:18:28Z")

</div>

Hello We are migrating to Elasticsearch 8 and when we are trying to fetch the data of parent document inner hits using has parent query it is returning exception but the reverse scenario is working good.Elasticsearch re…

---

## [Pretty option for kibana rest api?](https://discuss.elastic.co/t/pretty-option-for-kibana-rest-api/318213)

<div class="topic-metadata">

**Author:** [@learningelastic](https://discuss.elastic.co/u/learningelastic)\
**Replies:** 2\
**Last updated:** [November 5, 2022, 1:58am UTC](https://discuss.elastic.co/t/pretty-option-for-kibana-rest-api/318213 "2022-11-05T01:58:58Z")

</div>

I tried running this command: curl -X GET -u myuser:mypass "https://localhost:5601/api/alerting/rules/\_find?pretty=true" But I get the error {"statusCode":400,"error":"Bad Request","message":"\[request query.pretty\]: d…

---

## [Elasticsearch 7.17.3: \[parent\] Data too large, data for \[cluster:monitor/nodes/stats\[n\]\]](https://discuss.elastic.co/t/elasticsearch-7-17-3-parent-data-too-large-data-for-cluster-monitor-nodes-stats-n/317349)

<div class="topic-metadata">

**Author:** [@alecswan](https://discuss.elastic.co/u/alecswan)\
**Replies:** 12\
**Last updated:** [November 5, 2022, 12:22am UTC](https://discuss.elastic.co/t/elasticsearch-7-17-3-parent-data-too-large-data-for-cluster-monitor-nodes-stats-n/317349 "2022-11-05T00:22:43Z")

</div>

Hello, We recently upgraded from ES 7.9.2 to 7.17.3 (in preparation for the subsequent 8.x upgrade) and noticed that the cluster spends a lot more time in Yellow state than it used to. The root cause appears to be the "…

---

## [Unable to query for exact term](https://discuss.elastic.co/t/unable-to-query-for-exact-term/318215)

<div class="topic-metadata">

**Author:** [@learningelastic](https://discuss.elastic.co/u/learningelastic)\
**Replies:** 1\
**Last updated:** [November 4, 2022, 9:08pm UTC](https://discuss.elastic.co/t/unable-to-query-for-exact-term/318215 "2022-11-04T21:08:51Z")

</div>

I'm still new to working with elasticsearch queries. I find that my query is returning too many results despite my attempts to request specific results. For example, if I run this query: GET /test-index/\_search { "que…

---

## [Help extracting logs from message field with /t delimiter](https://discuss.elastic.co/t/help-extracting-logs-from-message-field-with-t-delimiter/318212)

<div class="topic-metadata">

**Author:** [@RaonyO](https://discuss.elastic.co/u/RaonyO)\
**Replies:** 3\
**Last updated:** [November 4, 2022, 7:50pm UTC](https://discuss.elastic.co/t/help-extracting-logs-from-message-field-with-t-delimiter/318212 "2022-11-04T19:50:03Z")

</div>

hello, I would like to know how I can extract the fields from this log, using grok or another way, I've tried with grok but I completely messed up, the question is how can i separate the fields with the /t delimiter? I …

---

## [Specific Encyption at Rest Algorithm?](https://discuss.elastic.co/t/specific-encyption-at-rest-algorithm/318210)

<div class="topic-metadata">

**Author:** [@tensor](https://discuss.elastic.co/u/tensor)\
**Replies:** 1\
**Last updated:** [November 4, 2022, 7:26pm UTC](https://discuss.elastic.co/t/specific-encyption-at-rest-algorithm/318210 "2022-11-04T19:26:01Z")

</div>

Hi One of our customers is insisting we provide evidence of encryption used by our third party processors (which includes Elastic). I can find published statements that data is encrypted at rest in the SOC-3 compliance…

---

## [Working with secrets and sensitive values with the Uptime App](https://discuss.elastic.co/t/working-with-secrets-and-sensitive-values-with-the-uptime-app/317126)

<div class="topic-metadata">

**Author:** [@Marchelune](https://discuss.elastic.co/u/Marchelune)\
**Replies:** 3\
**Last updated:** [November 4, 2022, 5:03pm UTC](https://discuss.elastic.co/t/working-with-secrets-and-sensitive-values-with-the-uptime-app/317126 "2022-11-04T17:03:55Z")

</div>

Hi there! I'm investigating the best way to monitor API uptime, and I have checked out the synthetics samples. A lot of APIs under test require authentication, thus some sort of credentials needs to be available during…

---

## [How to get a date\_range boundary on script](https://discuss.elastic.co/t/how-to-get-a-date-range-boundary-on-script/318148)

<div class="topic-metadata">

**Author:** [@Victor\_Garcia](https://discuss.elastic.co/u/Victor_Garcia)\
**Replies:** 0\
**Last updated:** [November 4, 2022, 2:22am UTC](https://discuss.elastic.co/t/how-to-get-a-date-range-boundary-on-script/318148 "2022-11-04T02:22:09Z")

</div>

Hi, How can I access to a date\_range field boundary on a script? I tried doc\['field.gte'\] Also, I debug the class of the field Debug.explain(doc\['status.dates'\]) and get org.elasticsearch.index.fielddata.ScriptDocVa…

---

## [Search all doc between 2 times each day](https://discuss.elastic.co/t/search-all-doc-between-2-times-each-day/318124)

<div class="topic-metadata">

**Author:** [@Soren\_vdc](https://discuss.elastic.co/u/Soren_vdc)\
**Replies:** 3\
**Last updated:** [November 4, 2022, 4:16pm UTC](https://discuss.elastic.co/t/search-all-doc-between-2-times-each-day/318124 "2022-11-04T16:16:24Z")

</div>

Hi, I have an ES query where i want to search the doc created between 06 AM and 23 PM. I have add this to my query: "range": { "timestamp": { "format": "strict\_hour", …

---

## [No runtime directory making kibana failed to start](https://discuss.elastic.co/t/no-runtime-directory-making-kibana-failed-to-start/318199)

<div class="topic-metadata">

**Author:** [@JimJ](https://discuss.elastic.co/u/JimJ)\
**Replies:** 0\
**Last updated:** [November 4, 2022, 2:29pm UTC](https://discuss.elastic.co/t/no-runtime-directory-making-kibana-failed-to-start/318199 "2022-11-04T14:29:40Z")

</div>

Hi, I installed kibana 8.4.1-1 on a RHEL server using Elastic RPM's. After the first reboot, kibana failed to start because of missing /run/kibana directory: FATAL Error: ENOENT: no such file or directory, open '/run…

---

## [Unassigned primary + replica shard, minimise data loss](https://discuss.elastic.co/t/unassigned-primary-replica-shard-minimise-data-loss/317393)

<div class="topic-metadata">

**Author:** [@tg295](https://discuss.elastic.co/u/tg295)\
**Replies:** 11\
**Last updated:** [November 4, 2022, 2:27pm UTC](https://discuss.elastic.co/t/unassigned-primary-replica-shard-minimise-data-loss/317393 "2022-11-04T14:27:53Z")

</div>

Hello, my cluster is currently in red state due to one of both the primary and replica shard of an index becoming unassigned. This happened after a number of large tasks were executed simultaneously by accident on the sa…

---

## [F5 VIP as syslog destination on network devices](https://discuss.elastic.co/t/f5-vip-as-syslog-destination-on-network-devices/318196)

<div class="topic-metadata">

**Author:** [@amitpal](https://discuss.elastic.co/u/amitpal)\
**Replies:** 1\
**Last updated:** [November 4, 2022, 2:27pm UTC](https://discuss.elastic.co/t/f5-vip-as-syslog-destination-on-network-devices/318196 "2022-11-04T14:27:13Z")

</div>

We have all the network devices pointing to F5 Virtual server and under that server we have elastic nodes . In elastic , we see logs but all of them have source as F5 Self IP, i have marked NAT as none on F5 VIP but sti…

---

## [Unassigned Replica Shards](https://discuss.elastic.co/t/unassigned-replica-shards/317923)

<div class="topic-metadata">

**Author:** [@James\_Stallings](https://discuss.elastic.co/u/James_Stallings)\
**Replies:** 7\
**Last updated:** [November 4, 2022, 12:47pm UTC](https://discuss.elastic.co/t/unassigned-replica-shards/317923 "2022-11-04T12:47:36Z")

</div>

How often does the control loop run that checks to attempt to re-assign an unassigned replica shard? Is there documentation to this effect? Is there source code I can look at?

---

## [Filebeat with customized config and ingest\_pipeline](https://discuss.elastic.co/t/filebeat-with-customized-config-and-ingest-pipeline/318111)

<div class="topic-metadata">

**Author:** [@Tanek21](https://discuss.elastic.co/u/Tanek21)\
**Replies:** 3\
**Last updated:** [November 4, 2022, 11:59am UTC](https://discuss.elastic.co/t/filebeat-with-customized-config-and-ingest-pipeline/318111 "2022-11-04T11:59:19Z")

</div>

I've deployed eck cluster (Kibana, elasticsearch, filebeat) and want to pass old logstash filters (logstash.conf) as ingest pipeline in elasticsearch. Fortunately, I am able to do the same with different processors. wh…

---

## [Best option for working with MySQL](https://discuss.elastic.co/t/best-option-for-working-with-mysql/318084)

<div class="topic-metadata">

**Author:** [@ChristopherHS](https://discuss.elastic.co/u/ChristopherHS)\
**Replies:** 2\
**Last updated:** [November 4, 2022, 11:10am UTC](https://discuss.elastic.co/t/best-option-for-working-with-mysql/318084 "2022-11-04T11:10:40Z")

</div>

Hello, We currently use Percona but to improve the search, we want to delegate this task to Elasticsearch. We have a videos table which contains over 4 million recordings. The search is done on all the fields below li…

---

## [Logstash-Twitter input error "undefined method \`filter' for nil:NilClass"](https://discuss.elastic.co/t/logstash-twitter-input-error-undefined-method-filter-for-nil-nilclass/317874)

<div class="topic-metadata">

**Author:** [@True](https://discuss.elastic.co/u/True)\
**Replies:** 5\
**Last updated:** [November 4, 2022, 9:44am UTC](https://discuss.elastic.co/t/logstash-twitter-input-error-undefined-method-filter-for-nil-nilclass/317874 "2022-11-04T09:44:42Z")

</div>

Hello. I have been facing issues using the 'Twitter input' in Logstash. LS version : 8.2.2 ES version : 8.2.2 When I run Logstash, Twit are not indexed and the error message below continues to appear. Did I write th…

[Previous page](https://discuss.elastic.co/tag/none.md?no_tags=true&page=503)

[Next page](https://discuss.elastic.co/tag/none.md?no_tags=true&page=505)
