# \#none

**URL:** https://discuss.elastic.co/tag/none.md?no_tags=true&page=514

[Latest](https://discuss.elastic.co/latest.md) · [Categories](https://discuss.elastic.co/categories.md) · [Tags](https://discuss.elastic.co/tags.md)

**Page:** 515

---

## [A node cannot be upgraded directly from version \[7.10.2\] to version \[8.4.3\], it must first be upgraded to version \[7.17.0\]](https://discuss.elastic.co/t/a-node-cannot-be-upgraded-directly-from-version-7-10-2-to-version-8-4-3-it-must-first-be-upgraded-to-version-7-17-0/317036)

<div class="topic-metadata">

**Author:** [@SUNA](https://discuss.elastic.co/u/SUNA)\
**Replies:** 6\
**Last updated:** [October 20, 2022, 3:27am UTC](https://discuss.elastic.co/t/a-node-cannot-be-upgraded-directly-from-version-7-10-2-to-version-8-4-3-it-must-first-be-upgraded-to-version-7-17-0/317036 "2022-10-20T03:27:11Z")

</div>

Hi Team, I'm not sure how elastic verion managed to upgrade the major version without tried anyone. Did the stack try to upgrade itself? Kindly help how can i fix this error. my kibana down due to this error

---

## [Zabbix와 elastic의 비교](https://discuss.elastic.co/t/zabbix-elastic/317059)

<div class="topic-metadata">

**Author:** [@sjh0207](https://discuss.elastic.co/u/sjh0207)\
**Replies:** 0\
**Last updated:** [October 20, 2022, 12:00am UTC](https://discuss.elastic.co/t/zabbix-elastic/317059 "2022-10-20T00:00:44Z")

</div>

네트워크 트래픽 모니터링을 중점적으로 기획하고 있습니다. zabbix와 비교 시 elastic에서의 이점은 무엇이 있을까요?

---

## [Alert for Elastic-Agent Offline](https://discuss.elastic.co/t/alert-for-elastic-agent-offline/317058)

<div class="topic-metadata">

**Author:** [@perea870724](https://discuss.elastic.co/u/perea870724)\
**Replies:** 0\
**Last updated:** [October 19, 2022, 11:34pm UTC](https://discuss.elastic.co/t/alert-for-elastic-agent-offline/317058 "2022-10-19T23:34:26Z")

</div>

Hello, Friends, does anyone know how it is possible to send an alert when an elastic-agent goes down?

---

## [How change pattern of data?](https://discuss.elastic.co/t/how-change-pattern-of-data/317045)

<div class="topic-metadata">

**Author:** [@Nikolas1306](https://discuss.elastic.co/u/Nikolas1306)\
**Replies:** 2\
**Last updated:** [October 19, 2022, 11:08pm UTC](https://discuss.elastic.co/t/how-change-pattern-of-data/317045 "2022-10-19T23:08:23Z")

</div>

i have this format in kibana Jul 27, 2022 @ 15:27:26.598 but is have a problem not order correctly with create a field datetime in logstash filter { grok { match =\> \["message", "%{TIMESTAMP\_ISO8601:log…

---

## [Extract datatime in log and convert in datatime field?](https://discuss.elastic.co/t/extract-datatime-in-log-and-convert-in-datatime-field/317021)

<div class="topic-metadata">

**Author:** [@Nikolas1306](https://discuss.elastic.co/u/Nikolas1306)\
**Replies:** 2\
**Last updated:** [October 19, 2022, 11:06pm UTC](https://discuss.elastic.co/t/extract-datatime-in-log-and-convert-in-datatime-field/317021 "2022-10-19T23:06:32Z")

</div>

i ve this config in logstash filter { grok { match =\> \["message", "%{TIMESTAMP\_ISO8601:timestamp\_message}"\] } date { match =\> \["timestamp\_message","YYYY-MM-dd HH:mm:ss"\] target =\> "@timesta…

---

## [Elastic Search Slow Response time range filter query](https://discuss.elastic.co/t/elastic-search-slow-response-time-range-filter-query/316936)

<div class="topic-metadata">

**Author:** [@prateek\_shekhar](https://discuss.elastic.co/u/prateek_shekhar)\
**Replies:** 2\
**Last updated:** [October 19, 2022, 10:35pm UTC](https://discuss.elastic.co/t/elastic-search-slow-response-time-range-filter-query/316936 "2022-10-19T22:35:25Z")

</div>

Hi Everyone, We a have a use case where we have added a new float field to our Elasticsearch index. The structure of the field is: class Foo { Float x Float y } This is our filter query which uses the above field: {…

---

## [Unable to create Threshold rule](https://discuss.elastic.co/t/unable-to-create-threshold-rule/316262)

<div class="topic-metadata">

**Author:** [@Blason](https://discuss.elastic.co/u/Blason)\
**Replies:** 1\
**Last updated:** [October 19, 2022, 10:35pm UTC](https://discuss.elastic.co/t/unable-to-create-threshold-rule/316262 "2022-10-19T22:35:12Z")

</div>

Hi Team, I am trying to write a threshold rule but failing to find the exact results. Can someone please help? I have nginx logs pouring in and wanted to setup the threshold alert so that if source.ip \>=750 from single …

---

## [Engineer Class Lab 4.1 - Missing data](https://discuss.elastic.co/t/engineer-class-lab-4-1-missing-data/315719)

<div class="topic-metadata">

**Author:** [@Kimberly](https://discuss.elastic.co/u/Kimberly)\
**Replies:** 1\
**Last updated:** [October 19, 2022, 10:34pm UTC](https://discuss.elastic.co/t/engineer-class-lab-4-1-missing-data/315719 "2022-10-19T22:34:45Z")

</div>

For Item 9-11, I ran load\_webtraffic.sh, created a dataview for web\_traffic index and used @timestamp as the time field. I only found 1456190 hits from Apr 1, 00:00:00 thru Apr 30, 23:30:00 instead of 1462658 hits in th…

---

## [How to compare 2 values in the only field using elasticsearch on grafana dashboard](https://discuss.elastic.co/t/how-to-compare-2-values-in-the-only-field-using-elasticsearch-on-grafana-dashboard/316932)

<div class="topic-metadata">

**Author:** [@Vitoria\_De\_Lara](https://discuss.elastic.co/u/Vitoria_De_Lara)\
**Replies:** 1\
**Last updated:** [October 19, 2022, 10:00pm UTC](https://discuss.elastic.co/t/how-to-compare-2-values-in-the-only-field-using-elasticsearch-on-grafana-dashboard/316932 "2022-10-19T22:00:11Z")

</div>

I need to create a dashboard that shows the two results of my boolean field.

---

## [Elasticsearch with nmap](https://discuss.elastic.co/t/elasticsearch-with-nmap/316998)

<div class="topic-metadata">

**Author:** [@VitorBarroso](https://discuss.elastic.co/u/VitorBarroso)\
**Replies:** 1\
**Last updated:** [October 19, 2022, 9:47pm UTC](https://discuss.elastic.co/t/elasticsearch-with-nmap/316998 "2022-10-19T21:47:51Z")

</div>

Hello, Can my elasticsearch works like nmap, for example, when i add a machine on elasticsearch, the elasticsearch detect the vulnerabilies(cve) for this machine and add on a dashboard?

---

## [How to enable Elastic Security](https://discuss.elastic.co/t/how-to-enable-elastic-security/316154)

<div class="topic-metadata">

**Author:** [@mruthyu](https://discuss.elastic.co/u/mruthyu)\
**Replies:** 1\
**Last updated:** [October 19, 2022, 9:28pm UTC](https://discuss.elastic.co/t/how-to-enable-elastic-security/316154 "2022-10-19T21:28:23Z")

</div>

How to enable the default elastic security solution for non default indices (metric\*, filebeat\*..etc), which follow the ECS. Should be able to add the required indices in the security solution.

---

## [Vulnerability (CVE-2022-42889) Apache Commons Text](https://discuss.elastic.co/t/vulnerability-cve-2022-42889-apache-commons-text/317009)

<div class="topic-metadata">

**Author:** [@mduijkers](https://discuss.elastic.co/u/mduijkers)\
**Replies:** 1\
**Last updated:** [October 19, 2022, 8:56pm UTC](https://discuss.elastic.co/t/vulnerability-cve-2022-42889-apache-commons-text/317009 "2022-10-19T20:56:55Z")

</div>

Vulnerability (CVE-2022-42889) Apache Commons Text. For this vulnerability ES needs to upgrade to Apache Commons Text 1.10.0 Source: https://lists.apache.org/thread/n2bd4vdsgkqh2tm14l1wyc3jyol7s1om Which version of ES…

---

## [Logstash plugin use @logger in new class](https://discuss.elastic.co/t/logstash-plugin-use-logger-in-new-class/317034)

<div class="topic-metadata">

**Author:** [@tylersiemers](https://discuss.elastic.co/u/tylersiemers)\
**Replies:** 1\
**Last updated:** [October 19, 2022, 8:42pm UTC](https://discuss.elastic.co/t/logstash-plugin-use-logger-in-new-class/317034 "2022-10-19T20:42:34Z")

</div>

New to logstash plugins here. How do you pass the @logger reference into another class within a plugin? The example below but trying to call another class outside and logging cause a failure. class SecondClass @logger.…

---

## [Why default index created logstash-2022.01.01-000001](https://discuss.elastic.co/t/why-default-index-created-logstash-2022-01-01-000001/316632)

<div class="topic-metadata">

**Author:** [@connectgeeks](https://discuss.elastic.co/u/connectgeeks)\
**Replies:** 7\
**Last updated:** [October 19, 2022, 6:35pm UTC](https://discuss.elastic.co/t/why-default-index-created-logstash-2022-01-01-000001/316632 "2022-10-19T18:35:27Z")

</div>

I'm using filebeat for forwarding logs to logstash and creating multiple datastreams in elasticsearch. I noticed one index created with name "logstash-2022.01.01-000001" and storing some of data from different datasteams…

---

## [Send json data with escape character](https://discuss.elastic.co/t/send-json-data-with-escape-character/317041)

<div class="topic-metadata">

**Author:** [@Pratik1](https://discuss.elastic.co/u/Pratik1)\
**Replies:** 0\
**Last updated:** [October 19, 2022, 5:50pm UTC](https://discuss.elastic.co/t/send-json-data-with-escape-character/317041 "2022-10-19T17:50:51Z")

</div>

I am using Kapacitor to send alerts via post method to elasticsearch. However, I was unable to do, so to debug further I was using a local django application to read the post response. By using alert template I am able t…

---

## [Elasticsearch proxy that can proxy searches to mask ES version?](https://discuss.elastic.co/t/elasticsearch-proxy-that-can-proxy-searches-to-mask-es-version/317028)

<div class="topic-metadata">

**Author:** [@Todd\_Lyons](https://discuss.elastic.co/u/Todd_Lyons)\
**Replies:** 0\
**Last updated:** [October 19, 2022, 4:07pm UTC](https://discuss.elastic.co/t/elasticsearch-proxy-that-can-proxy-searches-to-mask-es-version/317028 "2022-10-19T16:07:44Z")

</div>

Hi, all! We have used PMM 1.x for quite some time (Percona Monitoring & Management) to monitor our various mysql servers. Under the hood it's grafana and victoriametrics. It can use ES clusters as a data source and we…

---

## [Treating your Cluster like cattle instead of pets](https://discuss.elastic.co/t/treating-your-cluster-like-cattle-instead-of-pets/316930)

<div class="topic-metadata">

**Author:** [@pushshift](https://discuss.elastic.co/u/pushshift)\
**Replies:** 3\
**Last updated:** [October 19, 2022, 3:16pm UTC](https://discuss.elastic.co/t/treating-your-cluster-like-cattle-instead-of-pets/316930 "2022-10-19T15:16:01Z")

</div>

Anyone who has managed large server farms soon realizes that treating your servers like cattle instead of pets is the most efficient way to deploy, run, decommission nodes quickly and efficiently. If a server fails you, …

---

## [Kibana Elasticearch configuration](https://discuss.elastic.co/t/kibana-elasticearch-configuration/316915)

<div class="topic-metadata">

**Author:** [@not\_correct](https://discuss.elastic.co/u/not_correct)\
**Replies:** 8\
**Last updated:** [October 19, 2022, 2:45pm UTC](https://discuss.elastic.co/t/kibana-elasticearch-configuration/316915 "2022-10-19T14:45:01Z")

</div>

Hi, I am trying to configure the Kibana file to talk to ELasticsearch. It is deployed on single node EC2 instance on AWS. Here are my config files: kibana.yml # Kibana is served by a back end server. This setting spe…

---

## [Unable to connect to Elastic search with https from Logstash](https://discuss.elastic.co/t/unable-to-connect-to-elastic-search-with-https-from-logstash/316995)

<div class="topic-metadata">

**Author:** [@Pramod\_Kumar\_G](https://discuss.elastic.co/u/Pramod_Kumar_G)\
**Replies:** 1\
**Last updated:** [October 19, 2022, 2:40pm UTC](https://discuss.elastic.co/t/unable-to-connect-to-elastic-search-with-https-from-logstash/316995 "2022-10-19T14:40:38Z")

</div>

I am a new bie to ELK .I was able to start successfully elastic server and kibana.I was trying to start Logstash server but I am getting errors as below when run command logstash -f .\\config\\sample.conf my sample.conf …

---

## [Cannot use own java version in ES 8](https://discuss.elastic.co/t/cannot-use-own-java-version-in-es-8/317007)

<div class="topic-metadata">

**Author:** [@surkovoleg2010](https://discuss.elastic.co/u/surkovoleg2010)\
**Replies:** 0\
**Last updated:** [October 19, 2022, 1:16pm UTC](https://discuss.elastic.co/t/cannot-use-own-java-version-in-es-8/317007 "2022-10-19T13:16:19Z")

</div>

Hello, I have ES version 8.1.2 and have env var for ES\_JAVA\_HOME But anyway, when I start ES with systemctl start elasticsearch.service it uses bundled jdk. I found a way how to start it with my own, using override.…

---

## [Query "at least one not in given array"](https://discuss.elastic.co/t/query-at-least-one-not-in-given-array/316984)

<div class="topic-metadata">

**Author:** [@ltr31](https://discuss.elastic.co/u/ltr31)\
**Replies:** 1\
**Last updated:** [October 19, 2022, 11:20am UTC](https://discuss.elastic.co/t/query-at-least-one-not-in-given-array/316984 "2022-10-19T11:20:52Z")

</div>

Hello I have documents with let say positive terms and negative terms like { ... "mood" : \[ "happy", "excited", "furious" \], ... } Positive terms can be an infinite list of values, …

---

## [searchAsync is calling both OnResponse and onFailure](https://discuss.elastic.co/t/searchasync-is-calling-both-onresponse-and-onfailure/316981)

<div class="topic-metadata">

**Author:** [@jjc](https://discuss.elastic.co/u/jjc)\
**Replies:** 0\
**Last updated:** [October 19, 2022, 10:06am UTC](https://discuss.elastic.co/t/searchasync-is-calling-both-onresponse-and-onfailure/316981 "2022-10-19T10:06:15Z")

</div>

Hi, i've got a little problem. im running an async search that first returns calls OnResponse with the desired result then immediately calls onFailure. The index i'm querying contains exactly one single row. Please i…

---

## [Why logstash does not create field on Kibana](https://discuss.elastic.co/t/why-logstash-does-not-create-field-on-kibana/316978)

<div class="topic-metadata">

**Author:** [@glaucoperucchi](https://discuss.elastic.co/u/glaucoperucchi)\
**Replies:** 0\
**Last updated:** [October 19, 2022, 9:36am UTC](https://discuss.elastic.co/t/why-logstash-does-not-create-field-on-kibana/316978 "2022-10-19T09:36:50Z")

</div>

Hello guys, I need a your help. I did a filter with grok, but when I go to kibana I did not see the field of the filter. The log: type=USER\_ACCT msg=audit(1666101680.397:1224): pid=665272 uid=0 auid=525000037 ses=27 …

---

## [WAF logs Configuration from s3 bucket to Elasticsearch Using logstash s3 Plugin](https://discuss.elastic.co/t/waf-logs-configuration-from-s3-bucket-to-elasticsearch-using-logstash-s3-plugin/315243)

<div class="topic-metadata">

**Author:** [@dharminfadia](https://discuss.elastic.co/u/dharminfadia)\
**Replies:** 2\
**Last updated:** [October 19, 2022, 9:32am UTC](https://discuss.elastic.co/t/waf-logs-configuration-from-s3-bucket-to-elasticsearch-using-logstash-s3-plugin/315243 "2022-10-19T09:32:46Z")

</div>

Hello Everyone I am trying to Configuring WAF 2.0 logs from s3 Bucket to elasticsearch but I am facing some erroorm please Helpme for the same. My Current Logstash configuration input { s3 { access\_key\_id =\> "myid" …

---

## [Logstash to convert scientific notation to float](https://discuss.elastic.co/t/logstash-to-convert-scientific-notation-to-float/316231)

<div class="topic-metadata">

**Author:** [@the\_elkguy](https://discuss.elastic.co/u/the_elkguy)\
**Replies:** 7\
**Last updated:** [October 19, 2022, 9:25am UTC](https://discuss.elastic.co/t/logstash-to-convert-scientific-notation-to-float/316231 "2022-10-19T09:25:54Z")

</div>

Hello, I'm using logstash ruby filter to convert scientific notation from string to float which seem to be not working. I have used GROK to extract the scientific notation (1.989e-04) from the message and now converting…

---

## [How to rename a field with regex](https://discuss.elastic.co/t/how-to-rename-a-field-with-regex/316972)

<div class="topic-metadata">

**Author:** [@Saeedeh\_Moghimi](https://discuss.elastic.co/u/Saeedeh_Moghimi)\
**Replies:** 1\
**Last updated:** [October 19, 2022, 9:11am UTC](https://discuss.elastic.co/t/how-to-rename-a-field-with-regex/316972 "2022-10-19T09:11:05Z")

</div>

I have a log like this: {"A.amazon.aws.requestedParameters":{"testlabel1":"testvalue1"}} {"B.amazon.aws.requestedParameters":{"testlabel1":"testvalue1"}} ... and I want to change the field name to something like this: A…

---

## [Remove field with pattern using mutate](https://discuss.elastic.co/t/remove-field-with-pattern-using-mutate/316966)

<div class="topic-metadata">

**Author:** [@yuswanul](https://discuss.elastic.co/u/yuswanul)\
**Replies:** 1\
**Last updated:** [October 19, 2022, 9:08am UTC](https://discuss.elastic.co/t/remove-field-with-pattern-using-mutate/316966 "2022-10-19T09:08:00Z")

</div>

Hi there, i want to remove some field based on pattern. for example, i have some field like: iso.org.dod.internet.mgmt.mib-2.interfaces.ifTable.2 iso.org.dod.internet.mgmt.mib-2.interfaces.ifEntry.3 and i want to del…

---

## [ERROR: no\_shard\_available\_action\_exception](https://discuss.elastic.co/t/error-no-shard-available-action-exception/316950)

<div class="topic-metadata">

**Author:** [@hjsroldan](https://discuss.elastic.co/u/hjsroldan)\
**Replies:** 11\
**Last updated:** [October 19, 2022, 8:44am UTC](https://discuss.elastic.co/t/error-no-shard-available-action-exception/316950 "2022-10-19T08:44:42Z")

</div>

Hi, Does someone know how to fix this issue "no\_shard\_available\_action\_exception". Encountered this error after I restore my cluster, index was restored but the documents was not restored. Kindly see the error below: '…

---

## [Duplicated data in index](https://discuss.elastic.co/t/duplicated-data-in-index/316863)

<div class="topic-metadata">

**Author:** [@INS](https://discuss.elastic.co/u/INS)\
**Replies:** 2\
**Last updated:** [October 19, 2022, 8:26am UTC](https://discuss.elastic.co/t/duplicated-data-in-index/316863 "2022-10-19T08:26:43Z")

</div>

Hi I have a problem that sometime during uploading to elastic data with eventType number has a difrent date then it has in the file, This is suspicious that metadata has been changed somewhere, I guess that logstash are…

---

## [Problem in multi match search](https://discuss.elastic.co/t/problem-in-multi-match-search/316963)

<div class="topic-metadata">

**Author:** [@Fakeknox](https://discuss.elastic.co/u/Fakeknox)\
**Replies:** 0\
**Last updated:** [October 19, 2022, 7:47am UTC](https://discuss.elastic.co/t/problem-in-multi-match-search/316963 "2022-10-19T07:47:13Z")

</div>

hello i have 6 different field that i want to search in all of them . im using edge gram analyzer for search and using multi match query and text come from front. my sample code is : esClient.search({ index…

[Previous page](https://discuss.elastic.co/tag/none.md?no_tags=true&page=513)

[Next page](https://discuss.elastic.co/tag/none.md?no_tags=true&page=515)
