# \#none

**URL:** https://discuss.elastic.co/tag/none.md?no_tags=true&page=513

[Latest](https://discuss.elastic.co/latest.md) · [Categories](https://discuss.elastic.co/categories.md) · [Tags](https://discuss.elastic.co/tags.md)

**Page:** 514

---

## [Remove opening and closing parenthesis using gsub](https://discuss.elastic.co/t/remove-opening-and-closing-parenthesis-using-gsub/317100)

<div class="topic-metadata">

**Author:** [@ombit](https://discuss.elastic.co/u/ombit)\
**Replies:** 6\
**Last updated:** [October 21, 2022, 9:51am UTC](https://discuss.elastic.co/t/remove-opening-and-closing-parenthesis-using-gsub/317100 "2022-10-21T09:51:47Z")

</div>

Hi all, I am using Logstash to change the formatting of messages before forwarding them on to a QRadar reader. The syslogs are coming from various other servers, being collated onto one central 'master' server within …

---

## [Can't deploy fleet server : "Remote server is not ready to accept connections..."](https://discuss.elastic.co/t/cant-deploy-fleet-server-remote-server-is-not-ready-to-accept-connections/316912)

<div class="topic-metadata">

**Author:** [@Mouc](https://discuss.elastic.co/u/Mouc)\
**Replies:** 1\
**Last updated:** [October 21, 2022, 9:46am UTC](https://discuss.elastic.co/t/cant-deploy-fleet-server-remote-server-is-not-ready-to-accept-connections/316912 "2022-10-21T09:46:40Z")

</div>

Hello, I am currently trying to deploy a fleet server but I am having a problem at the enrollment step, the self signed certificate is generated for Fleet server, then enrollment is starting to the URL i specified for h…

---

## [Logstash Pipeline](https://discuss.elastic.co/t/logstash-pipeline/317155)

<div class="topic-metadata">

**Author:** [@QuestBevan](https://discuss.elastic.co/u/QuestBevan)\
**Replies:** 1\
**Last updated:** [October 21, 2022, 8:42am UTC](https://discuss.elastic.co/t/logstash-pipeline/317155 "2022-10-21T08:42:28Z")

</div>

Hi All, Urgent problem here. Have raised a support ticket but hoping to find a solution quicker! We have our logstash pipelines being managed by Kibana. A pipeline was accidently overwritten with an incorrect configura…

---

## [Slow sub-aggregation for low-cardinality field + high-cardinality field](https://discuss.elastic.co/t/slow-sub-aggregation-for-low-cardinality-field-high-cardinality-field/316992)

<div class="topic-metadata">

**Author:** [@astrodi](https://discuss.elastic.co/u/astrodi)\
**Replies:** 1\
**Last updated:** [October 21, 2022, 8:08am UTC](https://discuss.elastic.co/t/slow-sub-aggregation-for-low-cardinality-field-high-cardinality-field/316992 "2022-10-21T08:08:42Z")

</div>

Hi there, I'm having index having 14M documents, occupying 1.6TB of pri.storage with 50shards. There is query doing 22 aggregations (mainly simple terms aggs), took 0.3s. I needed to add one sub-aggregation to every o…

---

## [Strict execution ordering of Logstash output plugins](https://discuss.elastic.co/t/strict-execution-ordering-of-logstash-output-plugins/317048)

<div class="topic-metadata">

**Author:** [@gordonjlee](https://discuss.elastic.co/u/gordonjlee)\
**Replies:** 5\
**Last updated:** [October 20, 2022, 10:49pm UTC](https://discuss.elastic.co/t/strict-execution-ordering-of-logstash-output-plugins/317048 "2022-10-20T22:49:13Z")

</div>

I have 2 outputs from a Logstash instance, one output to Elasticsearch and one output to a Kafka topic that is consumed by a homegrown ms. In practice, I have seen instances where the ms consuming the Kafka topic receiv…

---

## [Is it possible to force document update despite a smaller version](https://discuss.elastic.co/t/is-it-possible-to-force-document-update-despite-a-smaller-version/317135)

<div class="topic-metadata">

**Author:** [@Achraf](https://discuss.elastic.co/u/Achraf)\
**Replies:** 1\
**Last updated:** [October 20, 2022, 9:24pm UTC](https://discuss.elastic.co/t/is-it-possible-to-force-document-update-despite-a-smaller-version/317135 "2022-10-20T21:24:06Z")

</div>

Our documents are indexed in ES with a version, this allows us to be sure that only new versions of the documents are indexed. In some special circumstances, we would like to baypass this mechanism, meaning updating a do…

---

## [Restored indices in red](https://discuss.elastic.co/t/restored-indices-in-red/317099)

<div class="topic-metadata">

**Author:** [@not\_correct](https://discuss.elastic.co/u/not_correct)\
**Replies:** 3\
**Last updated:** [October 20, 2022, 8:59pm UTC](https://discuss.elastic.co/t/restored-indices-in-red/317099 "2022-10-20T20:59:12Z")

</div>

Hi, I just restored the ES snapshot, but however I get all the restored indices in red status. When I call GET \_cluster/allocation/explain , I get the following: { "index" : "componentinformation", "shard" : 0, …

---

## [Logstash is disaster](https://discuss.elastic.co/t/logstash-is-disaster/317151)

<div class="topic-metadata">

**Author:** [@Nikolas1306](https://discuss.elastic.co/u/Nikolas1306)\
**Replies:** 1\
**Last updated:** [October 20, 2022, 8:49pm UTC](https://discuss.elastic.co/t/logstash-is-disaster/317151 "2022-10-20T20:49:33Z")

</div>

200% of cpu without pipelines and not produce log Who develops it is aware of its total unreliability? response: deny that Logstash has problems is not the solution in my opinion and better not to use it and try to …

---

## [How can I parse this date format into @timestamp?](https://discuss.elastic.co/t/how-can-i-parse-this-date-format-into-timestamp/316261)

<div class="topic-metadata">

**Author:** [@Roger\_Huang](https://discuss.elastic.co/u/Roger_Huang)\
**Replies:** 5\
**Last updated:** [October 20, 2022, 7:51pm UTC](https://discuss.elastic.co/t/how-can-i-parse-this-date-format-into-timestamp/316261 "2022-10-20T19:51:04Z")

</div>

Hi everyone, I am new to ELK and I cannot seems to get this right. Keep getting date parse error. I also wanted to put the \_time to @timestamp. For your kind advise please. 2022-06-30T13:14:40.558 Edgar.conf inpu…

---

## [Is there any way to do monitoring for Websockets?](https://discuss.elastic.co/t/is-there-any-way-to-do-monitoring-for-websockets/317124)

<div class="topic-metadata">

**Author:** [@Walter\_Hiranpat1](https://discuss.elastic.co/u/Walter_Hiranpat1)\
**Replies:** 1\
**Last updated:** [October 20, 2022, 7:28pm UTC](https://discuss.elastic.co/t/is-there-any-way-to-do-monitoring-for-websockets/317124 "2022-10-20T19:28:35Z")

</div>

Hi I was wondering if there is any way to monitor websockets for uptime? I have heartbeat 8.4 installed. I would like to see some documentation or example for how might one implement monitoring for this. Thank you.

---

## [Multiple Elastic Search Outputs for two different Azure event hubs as input in Logstash](https://discuss.elastic.co/t/multiple-elastic-search-outputs-for-two-different-azure-event-hubs-as-input-in-logstash/317129)

<div class="topic-metadata">

**Author:** [@Anudeep\_Konaboina](https://discuss.elastic.co/u/Anudeep_Konaboina)\
**Replies:** 3\
**Last updated:** [October 20, 2022, 6:09pm UTC](https://discuss.elastic.co/t/multiple-elastic-search-outputs-for-two-different-azure-event-hubs-as-input-in-logstash/317129 "2022-10-20T18:09:49Z")

</div>

I have to configure log stash to read from 2 different event hubs and write them to two different Elasticsearch index as shown below: input { azure\_event\_hubs { config\_mode =\> "advanced" threads =\> 8 d…

---

## [Can we restrict Dashboard view for Kibana](https://discuss.elastic.co/t/can-we-restrict-dashboard-view-for-kibana/316989)

<div class="topic-metadata">

**Author:** [@Anil\_Alapati](https://discuss.elastic.co/u/Anil_Alapati)\
**Replies:** 3\
**Last updated:** [October 20, 2022, 5:42pm UTC](https://discuss.elastic.co/t/can-we-restrict-dashboard-view-for-kibana/316989 "2022-10-20T17:42:37Z")

</div>

Hi , i have kibana access, but I can see multiple dashboards, can we restrict the access on specific dashbard

---

## [Index total\_fields \> limit](https://discuss.elastic.co/t/index-total-fields-limit/317139)

<div class="topic-metadata">

**Author:** [@nagrgk](https://discuss.elastic.co/u/nagrgk)\
**Replies:** 1\
**Last updated:** [October 20, 2022, 4:50pm UTC](https://discuss.elastic.co/t/index-total-fields-limit/317139 "2022-10-20T16:50:18Z")

</div>

Hello ElasticTeam, we have an issue with the total\_fields limit, which is defaulted to 1000 and we have increased it to more than 1000, problem is it gets changed back to 1000 after a few days and it is not preserved w…

---

## [How to get date parsing target as a date nor string](https://discuss.elastic.co/t/how-to-get-date-parsing-target-as-a-date-nor-string/317097)

<div class="topic-metadata">

**Author:** [@sh.user](https://discuss.elastic.co/u/sh.user)\
**Replies:** 3\
**Last updated:** [October 20, 2022, 4:03pm UTC](https://discuss.elastic.co/t/how-to-get-date-parsing-target-as-a-date-nor-string/317097 "2022-10-20T16:03:36Z")

</div>

Hello, I need to parse Field1 as date . I use date filter but when i specify target , i get target as string not date ( by default the timestamp is the target but this is not my need). date { match =\> \["Field1", "dd/M…

---

## [Uneven disk usage after removing a node set](https://discuss.elastic.co/t/uneven-disk-usage-after-removing-a-node-set/317107)

<div class="topic-metadata">

**Author:** [@Fares\_Oueslati](https://discuss.elastic.co/u/Fares_Oueslati)\
**Replies:** 1\
**Last updated:** [October 20, 2022, 1:19pm UTC](https://discuss.elastic.co/t/uneven-disk-usage-after-removing-a-node-set/317107 "2022-10-20T13:19:15Z")

</div>

Hello I'm using ECK 1.8.0 and ES 7.16.2. In order to increase the storage available for an ES cluster managed by the ECK operator, I proceeded through two steps, first I added a new node set with the new disk capacity …

---

## [Prometheus module remote\_write metricset](https://discuss.elastic.co/t/prometheus-module-remote-write-metricset/317114)

<div class="topic-metadata">

**Author:** [@ChristianOelsner](https://discuss.elastic.co/u/ChristianOelsner)\
**Replies:** 0\
**Last updated:** [October 20, 2022, 1:02pm UTC](https://discuss.elastic.co/t/prometheus-module-remote-write-metricset/317114 "2022-10-20T13:02:24Z")

</div>

Hello, We are scraping metrics from some 30+ Kafka clusters running in Confluent Cloud. We are scraping the metrics api using prometheus. Prometheus is configured to remote\_write to an elastic agent running among othe…

---

## [No Hosts Monitor Id or Url in Uptime](https://discuss.elastic.co/t/no-hosts-monitor-id-or-url-in-uptime/316913)

<div class="topic-metadata">

**Author:** [@lcsb-sysadmins](https://discuss.elastic.co/u/lcsb-sysadmins)\
**Replies:** 3\
**Last updated:** [October 20, 2022, 12:59pm UTC](https://discuss.elastic.co/t/no-hosts-monitor-id-or-url-in-uptime/316913 "2022-10-20T12:59:25Z")

</div>

Hello Team, We have successfully setup our Elastic Cluster - 7.17.5 with log-stash and search-guard. We have enrolled ~530 nodes in our elastic cluster. We tried to enable the HeartBeat to monitor/check the uptime of …

---

## [Run same script in multiple environments](https://discuss.elastic.co/t/run-same-script-in-multiple-environments/316937)

<div class="topic-metadata">

**Author:** [@Kris\_MacKay](https://discuss.elastic.co/u/Kris_MacKay)\
**Replies:** 1\
**Last updated:** [October 20, 2022, 12:34pm UTC](https://discuss.elastic.co/t/run-same-script-in-multiple-environments/316937 "2022-10-20T12:34:26Z")

</div>

I'd like to reuse the same script for different environments. The opening URL is dependent on passed in parameter. For each Fleet agent policy, I'd like the passed in parameter to apply to just that script, but not shar…

---

## [Can I use the values from the timepicker into aggregations?](https://discuss.elastic.co/t/can-i-use-the-values-from-the-timepicker-into-aggregations/317067)

<div class="topic-metadata">

**Author:** [@JimClark](https://discuss.elastic.co/u/JimClark)\
**Replies:** 2\
**Last updated:** [October 20, 2022, 12:19pm UTC](https://discuss.elastic.co/t/can-i-use-the-values-from-the-timepicker-into-aggregations/317067 "2022-10-20T12:19:47Z")

</div>

My usecase is as follows: I have a network resource that I need to track the usage of. Every usage of the resource is recorded into a separate document with the total usage @timestamp -\> End of usage @id -\> resour…

---

## [Export Kibana Dashboards from One server to another](https://discuss.elastic.co/t/export-kibana-dashboards-from-one-server-to-another/317101)

<div class="topic-metadata">

**Author:** [@stramzik](https://discuss.elastic.co/u/stramzik)\
**Replies:** 0\
**Last updated:** [October 20, 2022, 11:23am UTC](https://discuss.elastic.co/t/export-kibana-dashboards-from-one-server-to-another/317101 "2022-10-20T11:23:01Z")

</div>

Hello, I have a dashboard created on Kibana 7.8 version I am trying to export and import it onto a different server which is ruining Kibana 8.4 version based on this Saved Objects | Kibana Guide \[7.8\] | Elastic steps …

---

## [Exiting: couldn't connect to any of the configured Elasticsearch hosts. Errors: \[error connecting to Elasticsearch](https://discuss.elastic.co/t/exiting-couldnt-connect-to-any-of-the-configured-elasticsearch-hosts-errors-error-connecting-to-elasticsearch/317060)

<div class="topic-metadata">

**Author:** [@Joao\_Malebo](https://discuss.elastic.co/u/Joao_Malebo)\
**Replies:** 2\
**Last updated:** [October 20, 2022, 10:14am UTC](https://discuss.elastic.co/t/exiting-couldnt-connect-to-any-of-the-configured-elasticsearch-hosts-errors-error-connecting-to-elasticsearch/317060 "2022-10-20T10:14:29Z")

</div>

Hello dears, I'm getting errors when running filebeats on a remote server to test the Elasticsearch connection Below is the error image and description. sudo filebeat setup -E output.logstash.enabled=false -E output.e…

---

## [Logstash sometimes ignoring datastream configuration in elasticsearch output](https://discuss.elastic.co/t/logstash-sometimes-ignoring-datastream-configuration-in-elasticsearch-output/317089)

<div class="topic-metadata">

**Author:** [@hti](https://discuss.elastic.co/u/hti)\
**Replies:** 1\
**Last updated:** [October 20, 2022, 10:21am UTC](https://discuss.elastic.co/t/logstash-sometimes-ignoring-datastream-configuration-in-elasticsearch-output/317089 "2022-10-20T10:21:06Z")

</div>

Hello, we are running logstash 8.4.0 with multiple pipelines outputting to elasticsearch. Most of the time this works fine, but sometimes logstash will ignore the datastream configuration on startup and tries to write …

---

## [Kibana user profile with specific index?](https://discuss.elastic.co/t/kibana-user-profile-with-specific-index/317096)

<div class="topic-metadata">

**Author:** [@Nikolas1306](https://discuss.elastic.co/u/Nikolas1306)\
**Replies:** 1\
**Last updated:** [October 20, 2022, 10:14am UTC](https://discuss.elastic.co/t/kibana-user-profile-with-specific-index/317096 "2022-10-20T10:14:50Z")

</div>

hello is possible create multi user with same user have a group of index and other is not visible for all? example have 3 index index1 =\>user1 index2 =\>user2 index3 =\>user3 now all index is visible

---

## [Kibana not respect order by date why?](https://discuss.elastic.co/t/kibana-not-respect-order-by-date-why/317046)

<div class="topic-metadata">

**Author:** [@Nikolas1306](https://discuss.elastic.co/u/Nikolas1306)\
**Replies:** 2\
**Last updated:** [October 20, 2022, 9:47am UTC](https://discuss.elastic.co/t/kibana-not-respect-order-by-date-why/317046 "2022-10-20T09:47:48Z")

</div>

in my index have this "message": "2022-10-08 19:36:24,452 INFO \[org.springframework.web.servlet.DispatcherServlet\] (default task-1) Completed initialization in 15 ms", "@timestamp": "2022-10-19T19:07:49.010Z", …

---

## [Sum of last complete Bucket as a single metric](https://discuss.elastic.co/t/sum-of-last-complete-bucket-as-a-single-metric/314936)

<div class="topic-metadata">

**Author:** [@smueller](https://discuss.elastic.co/u/smueller)\
**Replies:** 3\
**Last updated:** [October 20, 2022, 9:41am UTC](https://discuss.elastic.co/t/sum-of-last-complete-bucket-as-a-single-metric/314936 "2022-10-20T09:41:16Z")

</div>

hi, im looking for a way to display the sum of all values from the last complete bucket of a timeseries. the idea is to display the current sum of all memory ,cores ,requests,disk space, etc. used for a server farm in …

---

## [Analysis (Pipeline)](https://discuss.elastic.co/t/analysis-pipeline/317073)

<div class="topic-metadata">

**Author:** [@linhz](https://discuss.elastic.co/u/linhz)\
**Replies:** 3\
**Last updated:** [October 20, 2022, 7:51am UTC](https://discuss.elastic.co/t/analysis-pipeline/317073 "2022-10-20T07:51:18Z")

</div>

Hi. Anyone can share with me where can i find Pipeline Formulas for Kibana. Thanks.

---

## [How to do mathematical operations on 2 variables in tsvb markdown](https://discuss.elastic.co/t/how-to-do-mathematical-operations-on-2-variables-in-tsvb-markdown/317062)

<div class="topic-metadata">

**Author:** [@eleven\_e](https://discuss.elastic.co/u/eleven_e)\
**Replies:** 2\
**Last updated:** [October 20, 2022, 6:29am UTC](https://discuss.elastic.co/t/how-to-do-mathematical-operations-on-2-variables-in-tsvb-markdown/317062 "2022-10-20T06:29:39Z")

</div>

I have 2 variables 'a' and 'b' where i need to perform (b-a)/b operation, how should i achieve it in the markdown? thanks.

---

## [Is there a library/API in Java to connect and fetch data from Elasticsearch](https://discuss.elastic.co/t/is-there-a-library-api-in-java-to-connect-and-fetch-data-from-elasticsearch/317069)

<div class="topic-metadata">

**Author:** [@pravu](https://discuss.elastic.co/u/pravu)\
**Replies:** 1\
**Last updated:** [October 20, 2022, 5:30am UTC](https://discuss.elastic.co/t/is-there-a-library-api-in-java-to-connect-and-fetch-data-from-elasticsearch/317069 "2022-10-20T05:30:58Z")

</div>

Is there a library/API in Java to connect and fetch data from Elasticsearch

---

## [Is it possible to add multiple outputs for elastic agents?](https://discuss.elastic.co/t/is-it-possible-to-add-multiple-outputs-for-elastic-agents/316891)

<div class="topic-metadata">

**Author:** [@shi](https://discuss.elastic.co/u/shi)\
**Replies:** 5\
**Last updated:** [October 20, 2022, 4:20am UTC](https://discuss.elastic.co/t/is-it-possible-to-add-multiple-outputs-for-elastic-agents/316891 "2022-10-20T04:20:29Z")

</div>

We have 3 elasticsearch nodes and a client node. node 1, node 2, node 3 The current output of elastic agent is node 1. If the node 1 goes down is there a way for elastic agent to automatically sent its output to node 2…

---

## [Can ELK configure Remote Syslog Forwarding to Third party syslog server?](https://discuss.elastic.co/t/can-elk-configure-remote-syslog-forwarding-to-third-party-syslog-server/316953)

<div class="topic-metadata">

**Author:** [@wcpoon](https://discuss.elastic.co/u/wcpoon)\
**Replies:** 5\
**Last updated:** [October 20, 2022, 3:30am UTC](https://discuss.elastic.co/t/can-elk-configure-remote-syslog-forwarding-to-third-party-syslog-server/316953 "2022-10-20T03:30:26Z")

</div>

Hi All, Can ELK Stack able to configure remote syslog forwarding to another syslog server? Kindly please advise. Thanks.

[Previous page](https://discuss.elastic.co/tag/none.md?no_tags=true&page=512)

[Next page](https://discuss.elastic.co/tag/none.md?no_tags=true&page=514)
