# \#none

**URL:** https://discuss.elastic.co/tag/none.md?no_tags=true&page=506

[Latest](https://discuss.elastic.co/latest.md) · [Categories](https://discuss.elastic.co/categories.md) · [Tags](https://discuss.elastic.co/tags.md)

**Page:** 507

---

## [Elastic Agent installation error on Azure Windows VM](https://discuss.elastic.co/t/elastic-agent-installation-error-on-azure-windows-vm/318067)

<div class="topic-metadata">

**Author:** [@mitchelldemol](https://discuss.elastic.co/u/mitchelldemol)\
**Replies:** 0\
**Last updated:** [November 3, 2022, 6:28am UTC](https://discuss.elastic.co/t/elastic-agent-installation-error-on-azure-windows-vm/318067 "2022-11-03T06:28:30Z")

</div>

I have come across a bug when trying to install the elastic agent (8.4.0) on Windows Server 2019 VMs on Azure via the instructions provided in the fleet documentation. The startup script on the VM runs the following co…

---

## [Index RED with Error This version of Lucene only supports indexes created with release 6.0 and later](https://discuss.elastic.co/t/index-red-with-error-this-version-of-lucene-only-supports-indexes-created-with-release-6-0-and-later/317975)

<div class="topic-metadata">

**Author:** [@vishalbhandari](https://discuss.elastic.co/u/vishalbhandari)\
**Replies:** 3\
**Last updated:** [November 3, 2022, 5:31am UTC](https://discuss.elastic.co/t/index-red-with-error-this-version-of-lucene-only-supports-indexes-created-with-release-6-0-and-later/317975 "2022-11-03T05:31:21Z")

</div>

Hi I have Elastic search version 7.16.3, in this one index is showing RED and when i tried recover it using CheckIndex command "java -cp lucene-core-8.10.1.jar -ea:org.apache.lucene… org.apache.lucene.index.CheckIndex C…

---

## [How to get sum of some last values correctly in KIBANA](https://discuss.elastic.co/t/how-to-get-sum-of-some-last-values-correctly-in-kibana/317878)

<div class="topic-metadata">

**Author:** [@Joko\_Eliyanto](https://discuss.elastic.co/u/Joko_Eliyanto)\
**Replies:** 4\
**Last updated:** [November 3, 2022, 4:37am UTC](https://discuss.elastic.co/t/how-to-get-sum-of-some-last-values-correctly-in-kibana/317878 "2022-11-03T04:37:25Z")

</div>

I am a new user in KIBANA dashboard, I just want to create a card that contain sum of certain days last value(for example 1day, 2day, 3day or so on). I think I can get the result I need by change the last value interval …

---

## [Not able to connect Kafka server in output kafka plugin using SASL\_SSL](https://discuss.elastic.co/t/not-able-to-connect-kafka-server-in-output-kafka-plugin-using-sasl-ssl/318062)

<div class="topic-metadata">

**Author:** [@danishbit09](https://discuss.elastic.co/u/danishbit09)\
**Replies:** 0\
**Last updated:** [November 3, 2022, 3:53am UTC](https://discuss.elastic.co/t/not-able-to-connect-kafka-server-in-output-kafka-plugin-using-sasl-ssl/318062 "2022-11-03T03:53:23Z")

</div>

I am not able to publish log into Kafka topic. Below error is showing. Kindly suggest for the below error log. be removed in future version. Please use 'use\_all\_dns\_ips' or another non-deprecated value. \[2022-11-03T11:…

---

## [Pulsar connectivity](https://discuss.elastic.co/t/pulsar-connectivity/317939)

<div class="topic-metadata">

**Author:** [@omicronian8](https://discuss.elastic.co/u/omicronian8)\
**Replies:** 2\
**Last updated:** [November 2, 2022, 11:40pm UTC](https://discuss.elastic.co/t/pulsar-connectivity/317939 "2022-11-02T23:40:43Z")

</div>

I need to store the output of logstash onto a pulsar topic. Looking at the documentation and other threads here, I couldn't find any leads on it. I could only get a git repo where we can use pulsar topic as an input to l…

---

## [Unable to create pipeline when using drop processor](https://discuss.elastic.co/t/unable-to-create-pipeline-when-using-drop-processor/317897)

<div class="topic-metadata">

**Author:** [@matttjones60](https://discuss.elastic.co/u/matttjones60)\
**Replies:** 1\
**Last updated:** [November 2, 2022, 11:51pm UTC](https://discuss.elastic.co/t/unable-to-create-pipeline-when-using-drop-processor/317897 "2022-11-02T23:51:28Z")

</div>

Hi Fairly new to Elastic so apologies if this is an obvious issue! I'm trying to create a new processor to drop any entries containing: user\_agent.original =="GoogleHC/1.0" But when I add a processor containing that…

---

## [ICU and upgrading from 7.17.1 to 8.5](https://discuss.elastic.co/t/icu-and-upgrading-from-7-17-1-to-8-5/317929)

<div class="topic-metadata">

**Author:** [@elasticism](https://discuss.elastic.co/u/elasticism)\
**Replies:** 1\
**Last updated:** [November 2, 2022, 11:19pm UTC](https://discuss.elastic.co/t/icu-and-upgrading-from-7-17-1-to-8-5/317929 "2022-11-02T23:19:24Z")

</div>

On the page for ICU (ICU Analysis Plugin | Elasticsearch Plugins and Integrations \[8.5\] | Elastic), there's a callout that says ICU analysis and backwards compatibility From time to time, the ICU library receives updat…

---

## [Export Kibana dashboards into PDF](https://discuss.elastic.co/t/export-kibana-dashboards-into-pdf/24497)

<div class="topic-metadata">

**Author:** [@frank\_van](https://discuss.elastic.co/u/frank_van)\
**Replies:** 3\
**Last updated:** [June 6, 2017, 2:48pm UTC](https://discuss.elastic.co/t/export-kibana-dashboards-into-pdf/24497 "2017-06-06T14:48:30Z")

</div>

Hi, It appears Kibana 4 doesn't have a way to export dashboards into PDF, which is a key feature for many enterprise customers. Does anyone know if there's any work around solutions (preferably open source)? Also is th…

---

## [Input needed for Elastic's Cloud Security offerings!](https://discuss.elastic.co/t/input-needed-for-elastics-cloud-security-offerings/318056)

<div class="topic-metadata">

**Author:** [@danr](https://discuss.elastic.co/u/danr)\
**Replies:** 0\
**Last updated:** [November 2, 2022, 10:17pm UTC](https://discuss.elastic.co/t/input-needed-for-elastics-cloud-security-offerings/318056 "2022-11-02T22:17:57Z")

</div>

Hi Elastic community! I'm Dan-- I help out with our new cloud security capabilities where I focus on cloud threat detection, prevention & response. I'm looking to meet up with any Elastic users that might be: Thinking…

---

## [Searching for image changes](https://discuss.elastic.co/t/searching-for-image-changes/318047)

<div class="topic-metadata">

**Author:** [@cheshirecat](https://discuss.elastic.co/u/cheshirecat)\
**Replies:** 4\
**Last updated:** [November 2, 2022, 9:55pm UTC](https://discuss.elastic.co/t/searching-for-image-changes/318047 "2022-11-02T21:55:01Z")

</div>

Hello There! With my Friend we would like to know if there is a possibility to use Elastic as a tool to find that images were changed. We would like to upload an image and check if it is an original picture or not. For…

---

## [Why My Elastic Agent status showing unhealthy? Assuming Elastic agent restarting itself](https://discuss.elastic.co/t/why-my-elastic-agent-status-showing-unhealthy-assuming-elastic-agent-restarting-itself/317950)

<div class="topic-metadata">

**Author:** [@Vijaykumar\_Deshmukh1](https://discuss.elastic.co/u/Vijaykumar_Deshmukh1)\
**Replies:** 0\
**Last updated:** [November 2, 2022, 6:50am UTC](https://discuss.elastic.co/t/why-my-elastic-agent-status-showing-unhealthy-assuming-elastic-agent-restarting-itself/317950 "2022-11-02T06:50:10Z")

</div>

here are the logs \[elastic\_agent\]\[info\] operation 'operation-install' skipped for metricbeat.8.4.3 12:17:56.513 elastic\_agent \[elastic\_agent\]\[info\] operation 'operation-start' skipped for metricbeat.8.4.3 12:17:56.7…

---

## [Does logstash 8.4 supports Elastic Search 7.8 later?](https://discuss.elastic.co/t/does-logstash-8-4-supports-elastic-search-7-8-later/317960)

<div class="topic-metadata">

**Author:** [@djrshn2346](https://discuss.elastic.co/u/djrshn2346)\
**Replies:** 1\
**Last updated:** [November 2, 2022, 9:47pm UTC](https://discuss.elastic.co/t/does-logstash-8-4-supports-elastic-search-7-8-later/317960 "2022-11-02T21:47:13Z")

</div>

I am using logstash 8.4.3, along with Elasticsearch versions 7.8.1 and 7.10.2. Does logstash will support this version of ES?

---

## [Please fix your website @elastic =\> A lot of stuff is throwing 404's](https://discuss.elastic.co/t/please-fix-your-website-elastic-a-lot-of-stuff-is-throwing-404s/318053)

<div class="topic-metadata">

**Author:** [@willemdh](https://discuss.elastic.co/u/willemdh)\
**Replies:** 2\
**Last updated:** [November 2, 2022, 9:37pm UTC](https://discuss.elastic.co/t/please-fix-your-website-elastic-a-lot-of-stuff-is-throwing-404s/318053 "2022-11-02T21:37:42Z")

</div>

Such as https://www.elastic.co/blog/whats-new-elastic-enterprise-search-8-5-0 (has been going on for a few hours already afaik)

---

## [Show aggregations of same category after filter](https://discuss.elastic.co/t/show-aggregations-of-same-category-after-filter/318055)

<div class="topic-metadata">

**Author:** [@Peter\_Valek](https://discuss.elastic.co/u/Peter_Valek)\
**Replies:** 0\
**Last updated:** [November 2, 2022, 9:21pm UTC](https://discuss.elastic.co/t/show-aggregations-of-same-category-after-filter/318055 "2022-11-02T21:21:35Z")

</div>

Hello everyone ! I would like to create filter and aggregations after filter for procuts in Elasticsearch. I am having base aggregations for all products: "size": { "doc\_count\_error\_upper\_bound": 0, "su…

---

## [Elastic Security Statement for OpenSSL CVE-2022-3786 and CVE-2022-3602, OpenSSL version 3.0.7](https://discuss.elastic.co/t/elastic-security-statement-for-openssl-cve-2022-3786-and-cve-2022-3602-openssl-version-3-0-7/318039)

<div class="topic-metadata">

**Author:** [@Levine](https://discuss.elastic.co/u/Levine)\
**Replies:** 0\
**Last updated:** [November 2, 2022, 6:41pm UTC](https://discuss.elastic.co/t/elastic-security-statement-for-openssl-cve-2022-3786-and-cve-2022-3602-openssl-version-3-0-7/318039 "2022-11-02T18:41:01Z")

</div>

Elastic Products are not affected by this issue. On Oct 25, 2022, Elastic became aware of the Forthcoming OpenSSL 3.0.7 Release announcement, which was made available on Nov 1, 2022. The security issues addressed in thi…

---

## [Default alert action?](https://discuss.elastic.co/t/default-alert-action/258805)

<div class="topic-metadata">

**Author:** [@hilt86](https://discuss.elastic.co/u/hilt86)\
**Replies:** 3\
**Last updated:** [November 2, 2022, 6:13pm UTC](https://discuss.elastic.co/t/default-alert-action/258805 "2022-11-02T18:13:27Z")

</div>

Is there a way to set a default action in Elastic Siem? Manually setting up an action on 300+ rules is pretty raw!

---

## [Logstash does not take all the logs from eventhub](https://discuss.elastic.co/t/logstash-does-not-take-all-the-logs-from-eventhub/318024)

<div class="topic-metadata">

**Author:** [@Pavelm](https://discuss.elastic.co/u/Pavelm)\
**Replies:** 0\
**Last updated:** [November 2, 2022, 4:19pm UTC](https://discuss.elastic.co/t/logstash-does-not-take-all-the-logs-from-eventhub/318024 "2022-11-02T16:19:22Z")

</div>

Hi, I am using Logstash to connect to Eventhub in Azure and then push logs to ELK. For some reason, the Outgoing queue is much smaller than the Incoming as you may see in the screenshot: What can be the reason?

---

## [8.3 Memory calculations and nested fields](https://discuss.elastic.co/t/8-3-memory-calculations-and-nested-fields/317988)

<div class="topic-metadata">

**Author:** [@ewolfman](https://discuss.elastic.co/u/ewolfman)\
**Replies:** 6\
**Last updated:** [November 2, 2022, 4:10pm UTC](https://discuss.elastic.co/t/8-3-memory-calculations-and-nested-fields/317988 "2022-11-02T16:10:04Z")

</div>

Hi, Trying to better understanding the new memory planning for 8.3. Do nested fields count just like other fields? My indices have nested fields. So a single index including its nested fields has 100 fields. Accordin…

---

## [Parsing big xml files in logstash](https://discuss.elastic.co/t/parsing-big-xml-files-in-logstash/318018)

<div class="topic-metadata">

**Author:** [@mhoro](https://discuss.elastic.co/u/mhoro)\
**Replies:** 0\
**Last updated:** [November 2, 2022, 3:57pm UTC](https://discuss.elastic.co/t/parsing-big-xml-files-in-logstash/318018 "2022-11-02T15:57:31Z")

</div>

I would like to load data from multiple big xml files to elasticsearch using logstash. Files are up to 3gb with many lines, all with the same structure. They contain a list of elements and I would like one element to bec…

---

## [Logstash Arcsight Module Implementation Issues](https://discuss.elastic.co/t/logstash-arcsight-module-implementation-issues/317977)

<div class="topic-metadata">

**Author:** [@jakinmayowa](https://discuss.elastic.co/u/jakinmayowa)\
**Replies:** 2\
**Last updated:** [November 2, 2022, 2:44pm UTC](https://discuss.elastic.co/t/logstash-arcsight-module-implementation-issues/317977 "2022-11-02T14:44:42Z")

</div>

Completed installation of the ELK stack version 8.4 - single node installation Used a test pipeline to confirm comms between Elasticsearch and Logstash on local machine on the commandline interface. So, I tried impleme…

---

## [Elasticserach cannot show indices](https://discuss.elastic.co/t/elasticserach-cannot-show-indices/318004)

<div class="topic-metadata">

**Author:** [@toughLuck](https://discuss.elastic.co/u/toughLuck)\
**Replies:** 0\
**Last updated:** [November 2, 2022, 2:43pm UTC](https://discuss.elastic.co/t/elasticserach-cannot-show-indices/318004 "2022-11-02T14:43:51Z")

</div>

I am new to ELK, trying to set up a basic ELK following a youtube video, but cannot load the index to elasticsearch/ The logstash log \[2022-11-02T10:38:08,489\]\[ERROR\]\[logstash.outputs.elasticsearch\]\[main\]\[bef0a8230c929…

---

## [Issue with Elastic agent installation](https://discuss.elastic.co/t/issue-with-elastic-agent-installation/317830)

<div class="topic-metadata">

**Author:** [@subash](https://discuss.elastic.co/u/subash)\
**Replies:** 3\
**Last updated:** [November 2, 2022, 2:03pm UTC](https://discuss.elastic.co/t/issue-with-elastic-agent-installation/317830 "2022-11-02T14:03:47Z")

</div>

We are using Elastic Cloud Enterprise 2.13. When installing the Elastic agents in windows PC, getting the below warnings. Info: Starting enrollment to URL: https://hostname:9243 Warn: Remote server is not ready to acc…

---

## [Logstash webhdfs output plugin AlreadyBeingCreatedException](https://discuss.elastic.co/t/logstash-webhdfs-output-plugin-alreadybeingcreatedexception/317887)

<div class="topic-metadata">

**Author:** [@Rakhshunda\_Noorein\_J](https://discuss.elastic.co/u/Rakhshunda_Noorein_J)\
**Replies:** 10\
**Last updated:** [November 2, 2022, 1:20pm UTC](https://discuss.elastic.co/t/logstash-webhdfs-output-plugin-alreadybeingcreatedexception/317887 "2022-11-02T13:20:54Z")

</div>

Hello, I have created a webhdfc logstash configuaration file which will take file input and insert the data in hdfs through webhdfs output. sharing you the config file below. input { file { path =\> "C:/Users/user/…

---

## [Metricbeat and Elastic agent configuration?](https://discuss.elastic.co/t/metricbeat-and-elastic-agent-configuration/317987)

<div class="topic-metadata">

**Author:** [@subash](https://discuss.elastic.co/u/subash)\
**Replies:** 0\
**Last updated:** [November 2, 2022, 1:19pm UTC](https://discuss.elastic.co/t/metricbeat-and-elastic-agent-configuration/317987 "2022-11-02T13:19:55Z")

</div>

We are using Fleet managed Elastic agents version 7.17.4 in ECE. Is it possible to edit the metricbeat.yml which is inside the elastic agent? I tried editing it but got "metricbeat corrupted" during the Elastic agent in…

---

## [Free search event in Paris on Nov 21st](https://discuss.elastic.co/t/free-search-event-in-paris-on-nov-21st/317978)

<div class="topic-metadata">

**Author:** [@flaxsearch](https://discuss.elastic.co/u/flaxsearch)\
**Replies:** 0\
**Last updated:** [November 2, 2022, 11:39am UTC](https://discuss.elastic.co/t/free-search-event-in-paris-on-nov-21st/317978 "2022-11-02T11:39:25Z")

</div>

Join OpenSource Connections, founders of the Haystack search relevance conference, and Paris-based search engine tech experts Adelean for an afternoon of search enlightenment – learn how to build great data-driven search…

---

## [Elasticsearch dis\_max with PHP](https://discuss.elastic.co/t/elasticsearch-dis-max-with-php/317976)

<div class="topic-metadata">

**Author:** [@Makaveli1O](https://discuss.elastic.co/u/Makaveli1O)\
**Replies:** 0\
**Last updated:** [November 2, 2022, 11:01am UTC](https://discuss.elastic.co/t/elasticsearch-dis-max-with-php/317976 "2022-11-02T11:01:12Z")

</div>

My console query looks like this: { "query": { "dis\_max": { "tie\_breaker": 0.7, "boost": 1.2, "queries": \[ { "multi\_match": { "query": "this exact phrase", …

---

## [Failed to fetch X-pack information from ES - Failure to reach live ES Cluster](https://discuss.elastic.co/t/failed-to-fetch-x-pack-information-from-es-failure-to-reach-live-es-cluster/317306)

<div class="topic-metadata">

**Author:** [@jakinmayowa](https://discuss.elastic.co/u/jakinmayowa)\
**Replies:** 2\
**Last updated:** [November 2, 2022, 10:49am UTC](https://discuss.elastic.co/t/failed-to-fetch-x-pack-information-from-es-failure-to-reach-live-es-cluster/317306 "2022-11-02T10:49:12Z")

</div>

I'm currently configuring Logstash ArcSight Module, however I've reached a road-block, error message below: Sending Logstash logs to /usr/share/logstash/logs which is now configured via log4j2.properties \[2022-10-24T10:…

---

## [Logstash profile](https://discuss.elastic.co/t/logstash-profile/317934)

<div class="topic-metadata">

**Author:** [@GEHsu](https://discuss.elastic.co/u/GEHsu)\
**Replies:** 1\
**Last updated:** [November 2, 2022, 8:59am UTC](https://discuss.elastic.co/t/logstash-profile/317934 "2022-11-02T08:59:46Z")

</div>

System is Ubuntu Logstash version 7.17 The current idea is to collect logs (via syslog-514Port) from different servers or network devices Logstash will then send the log cut to Elasticsearch I have successfully recei…

---

## [Logstash stuck when lumberjack server is down](https://discuss.elastic.co/t/logstash-stuck-when-lumberjack-server-is-down/317955)

<div class="topic-metadata">

**Author:** [@ferdose\_shaik](https://discuss.elastic.co/u/ferdose_shaik)\
**Replies:** 0\
**Last updated:** [November 2, 2022, 8:44am UTC](https://discuss.elastic.co/t/logstash-stuck-when-lumberjack-server-is-down/317955 "2022-11-02T08:44:07Z")

</div>

We are using Logstash 7.15.2 with following lumberjack output configured. output { lumberjack { id =\> "dcae5gcprod" hosts =\> \["dcae-5gc-prod.ecomp.idns.cci.att.com"\] codec =\> json port =\> 31135 ssl\_cert…

---

## [Steps to configure and use memcached in logstash. Can you please share with me the steps](https://discuss.elastic.co/t/steps-to-configure-and-use-memcached-in-logstash-can-you-please-share-with-me-the-steps/317727)

<div class="topic-metadata">

**Author:** [@danishbit09](https://discuss.elastic.co/u/danishbit09)\
**Replies:** 4\
**Last updated:** [November 2, 2022, 8:32am UTC](https://discuss.elastic.co/t/steps-to-configure-and-use-memcached-in-logstash-can-you-please-share-with-me-the-steps/317727 "2022-11-02T08:32:42Z")

</div>

Can you please share with me the steps to configure and run memcached in filter plugin. Is memcached server configured in logstash internally or I have to install and start memcached externally? Please guide me.

[Previous page](https://discuss.elastic.co/tag/none.md?no_tags=true&page=505)

[Next page](https://discuss.elastic.co/tag/none.md?no_tags=true&page=507)
