# \#none

**URL:** https://discuss.elastic.co/tag/none.md?no_tags=true&page=517

[Latest](https://discuss.elastic.co/latest.md) · [Categories](https://discuss.elastic.co/categories.md) · [Tags](https://discuss.elastic.co/tags.md)

**Page:** 518

---

## [No Activity From Agent - Agent Renamed](https://discuss.elastic.co/t/no-activity-from-agent-agent-renamed/315492)

<div class="topic-metadata">

**Author:** [@Marko\_Todoric](https://discuss.elastic.co/u/Marko_Todoric)\
**Replies:** 1\
**Last updated:** [October 15, 2022, 9:58pm UTC](https://discuss.elastic.co/t/no-activity-from-agent-agent-renamed/315492 "2022-10-15T21:58:18Z")

</div>

Hello everyone, I have this glitch with Kibana where i added an agent to fleet , then figured i need to rename it so i renamed the host. Rename was successful, howerver I'm getting alerts " No Activity From Agent" whole…

---

## [Self-hosted deployment- licence question](https://discuss.elastic.co/t/self-hosted-deployment-licence-question/316698)

<div class="topic-metadata">

**Author:** [@misztol](https://discuss.elastic.co/u/misztol)\
**Replies:** 1\
**Last updated:** [October 15, 2022, 9:13pm UTC](https://discuss.elastic.co/t/self-hosted-deployment-licence-question/316698 "2022-10-15T21:13:25Z")

</div>

Dear Elastic I am attempting to build self-hosted deployment for SIEM purposes. I would like to use Platinum license features. I wonder how many licenses are required for following build: Hot tier (logs ingestion and …

---

## [Csv: map each field name to an array index](https://discuss.elastic.co/t/csv-map-each-field-name-to-an-array-index/316673)

<div class="topic-metadata">

**Author:** [@ktomu](https://discuss.elastic.co/u/ktomu)\
**Replies:** 3\
**Last updated:** [October 15, 2022, 8:41pm UTC](https://discuss.elastic.co/t/csv-map-each-field-name-to-an-array-index/316673 "2022-10-15T20:41:21Z")

</div>

Hi, I have a csv file with 2000 fields and I need only 5 from them and I know their position. It's easy to get that 5 fields using filebeat (decode\_csv\_fields and extract\_array) because everything that I need it just map…

---

## [This alert will apply to approximately 24 monitors](https://discuss.elastic.co/t/this-alert-will-apply-to-approximately-24-monitors/316637)

<div class="topic-metadata">

**Author:** [@Nitin08bisht](https://discuss.elastic.co/u/Nitin08bisht)\
**Replies:** 2\
**Last updated:** [October 15, 2022, 6:55pm UTC](https://discuss.elastic.co/t/this-alert-will-apply-to-approximately-24-monitors/316637 "2022-10-15T18:55:22Z")

</div>

I am trying to create alert to monitor server for specific process but it is showing a message "This alert will apply to approximately 24 monitors". I want to create server specific alert for each process. How can I do?…

---

## [ElasticSearch on-premise pricing](https://discuss.elastic.co/t/elasticsearch-on-premise-pricing/316683)

<div class="topic-metadata">

**Author:** [@dominique.bejean](https://discuss.elastic.co/u/dominique.bejean)\
**Replies:** 2\
**Last updated:** [October 15, 2022, 3:53pm UTC](https://discuss.elastic.co/t/elasticsearch-on-premise-pricing/316683 "2022-10-15T15:53:46Z")

</div>

Hi, For Elasticsearch on-premise pricing, according to this page (Tarifs officiels Elasticsearch : Elastic Cloud, offre Elasticsearch gérée | Elastic), I understand, the pricing is per month and per server for any serve…

---

## [Monitor Elasticsearch in Grafana](https://discuss.elastic.co/t/monitor-elasticsearch-in-grafana/316688)

<div class="topic-metadata">

**Author:** [@ZahraZare](https://discuss.elastic.co/u/ZahraZare)\
**Replies:** 2\
**Last updated:** [October 15, 2022, 2:06pm UTC](https://discuss.elastic.co/t/monitor-elasticsearch-in-grafana/316688 "2022-10-15T14:06:34Z")

</div>

I want to monitor Elasticsearch in Grafana,( not ٍELK stack). How can I do this without elastic exporter and prometheus? Can I monitor elasticsearch with X-pack? How? I have found this link(Elasticsearch Monitoring base…

---

## [Advice on indexing long form text](https://discuss.elastic.co/t/advice-on-indexing-long-form-text/316674)

<div class="topic-metadata">

**Author:** [@orweinberger](https://discuss.elastic.co/u/orweinberger)\
**Replies:** 1\
**Last updated:** [October 15, 2022, 2:02pm UTC](https://discuss.elastic.co/t/advice-on-indexing-long-form-text/316674 "2022-10-15T14:02:19Z")

</div>

I'm trying to find the best and most efficient way to index a transcript of long conversations, for example a 2-3 hour podcast between multiple members, or for another example a transcript of a large Zoom meeting with ma…

---

## [How to achieve same results as cutoff\_frequency with minimum\_should\_match with Elasticsearch 8.X after deprecation of common term queries](https://discuss.elastic.co/t/how-to-achieve-same-results-as-cutoff-frequency-with-minimum-should-match-with-elasticsearch-8-x-after-deprecation-of-common-term-queries/316679)

<div class="topic-metadata">

**Author:** [@jatinw21](https://discuss.elastic.co/u/jatinw21)\
**Replies:** 0\
**Last updated:** [October 15, 2022, 10:24am UTC](https://discuss.elastic.co/t/how-to-achieve-same-results-as-cutoff-frequency-with-minimum-should-match-with-elasticsearch-8-x-after-deprecation-of-common-term-queries/316679 "2022-10-15T10:24:29Z")

</div>

If I make a search for a term in the database of say movie titles, I want it to do an AND query for all the words in the search query that have higher than certain cutoff\_frequency and OR query for all the words in the s…

---

## [Let's encrypt issue with the CA Certificate after end of validation 3o September](https://discuss.elastic.co/t/lets-encrypt-issue-with-the-ca-certificate-after-end-of-validation-3o-september/316675)

<div class="topic-metadata">

**Author:** [@abkrim](https://discuss.elastic.co/u/abkrim)\
**Replies:** 0\
**Last updated:** [October 15, 2022, 8:25am UTC](https://discuss.elastic.co/t/lets-encrypt-issue-with-the-ca-certificate-after-end-of-validation-3o-september/316675 "2022-10-15T08:25:17Z")

</div>

I have tried various ways to install let's encrypt with my Elasticsearch cluster, but have been unable to do so. First method error displayed root@elk2:~# /usr/share/elasticsearch/bin/elasticsearch-create-enrollment-tok…

---

## [Ho validate filter expression?](https://discuss.elastic.co/t/ho-validate-filter-expression/316664)

<div class="topic-metadata">

**Author:** [@Nikolas1306](https://discuss.elastic.co/u/Nikolas1306)\
**Replies:** 1\
**Last updated:** [October 15, 2022, 3:07am UTC](https://discuss.elastic.co/t/ho-validate-filter-expression/316664 "2022-10-15T03:07:22Z")

</div>

example produce error filter { grok { match =\> { "message" =\> "%\[stderr\] (default task%" } } mutate { remove\_field =\> \['@timestamp'\] } } Failed to execute action {:action=\>L…

---

## [Error starting Elastic Search](https://discuss.elastic.co/t/error-starting-elastic-search/316659)

<div class="topic-metadata">

**Author:** [@ArrakisMiner](https://discuss.elastic.co/u/ArrakisMiner)\
**Replies:** 4\
**Last updated:** [October 14, 2022, 7:44pm UTC](https://discuss.elastic.co/t/error-starting-elastic-search/316659 "2022-10-14T19:44:57Z")

</div>

I'm having issues trying to start Elastic Search after installation, and I'm not sure how to get around it, nor can I find any similar topics with solutions online. When I run systemctl start elasticsearch, I get the er…

---

## [Kibana security password?](https://discuss.elastic.co/t/kibana-security-password/316234)

<div class="topic-metadata">

**Author:** [@Nikolas1306](https://discuss.elastic.co/u/Nikolas1306)\
**Replies:** 6\
**Last updated:** [October 14, 2022, 7:14pm UTC](https://discuss.elastic.co/t/kibana-security-password/316234 "2022-10-14T19:14:35Z")

</div>

ho enable password for kibana in simple mode?

---

## [Can I delete a older system index once a rollover has been made?](https://discuss.elastic.co/t/can-i-delete-a-older-system-index-once-a-rollover-has-been-made/316642)

<div class="topic-metadata">

**Author:** [@SamuelSMendes](https://discuss.elastic.co/u/SamuelSMendes)\
**Replies:** 1\
**Last updated:** [October 14, 2022, 7:03pm UTC](https://discuss.elastic.co/t/can-i-delete-a-older-system-index-once-a-rollover-has-been-made/316642 "2022-10-14T19:03:52Z")

</div>

So I got this index which got massive we were trying out the APM, now it has been made a rollover but the older one still have a huge impact on the cluster. Already talked to the team and decided to delete the 100GB …

---

## [How to query a nested array for an object with one matching field and one nonexistent field?](https://discuss.elastic.co/t/how-to-query-a-nested-array-for-an-object-with-one-matching-field-and-one-nonexistent-field/316663)

<div class="topic-metadata">

**Author:** [@A111](https://discuss.elastic.co/u/A111)\
**Replies:** 1\
**Last updated:** [October 14, 2022, 5:36pm UTC](https://discuss.elastic.co/t/how-to-query-a-nested-array-for-an-object-with-one-matching-field-and-one-nonexistent-field/316663 "2022-10-14T17:36:25Z")

</div>

Given this: { "mappings": { "document\_type": { "properties": { "id": { "type": "long" }, "resolutions": { "…

---

## [Logstash stalls processing and becomes unresponsitive after some runtime (filter issues?)](https://discuss.elastic.co/t/logstash-stalls-processing-and-becomes-unresponsitive-after-some-runtime-filter-issues/316640)

<div class="topic-metadata">

**Author:** [@gweiss76](https://discuss.elastic.co/u/gweiss76)\
**Replies:** 2\
**Last updated:** [October 14, 2022, 5:15pm UTC](https://discuss.elastic.co/t/logstash-stalls-processing-and-becomes-unresponsitive-after-some-runtime-filter-issues/316640 "2022-10-14T17:15:26Z")

</div>

Hi fellow log analysts. We are currently using Logstash for all syslog related logdata. Currently we have the issue, that logstash (almost) stops processing logdata after some time which results in backpressure to the …

---

## [Kibana index is not found](https://discuss.elastic.co/t/kibana-index-is-not-found/316612)

<div class="topic-metadata">

**Author:** [@not\_correct](https://discuss.elastic.co/u/not_correct)\
**Replies:** 2\
**Last updated:** [October 14, 2022, 5:07pm UTC](https://discuss.elastic.co/t/kibana-index-is-not-found/316612 "2022-10-14T17:07:41Z")

</div>

Hi, I have Elasticsearch cluster in production set by another person. I need to be able to find and store kibana index. However when I list all the indeces (xxx:9200/\_cat/indices) Kibana related is not there. Is there …

---

## [Dashboard - Convertir champ string en integer](https://discuss.elastic.co/t/dashboard-convertir-champ-string-en-integer/316551)

<div class="topic-metadata">

**Author:** [@the\_biker](https://discuss.elastic.co/u/the_biker)\
**Replies:** 3\
**Last updated:** [October 14, 2022, 4:53pm UTC](https://discuss.elastic.co/t/dashboard-convertir-champ-string-en-integer/316551 "2022-10-14T16:53:10Z")

</div>

Bonjour, je suis complètement novice sur Elasticsearch stack. J'arrive bien à récupérer les logs de mes serveurs windows avec winlogbeat. J'ai créé un dashboard à partir des logs de mon serveur d'impression Windows. I…

---

## [Remove timestamp where message have a string search?](https://discuss.elastic.co/t/remove-timestamp-where-message-have-a-string-search/316661)

<div class="topic-metadata">

**Author:** [@Nikolas1306](https://discuss.elastic.co/u/Nikolas1306)\
**Replies:** 0\
**Last updated:** [October 14, 2022, 4:22pm UTC](https://discuss.elastic.co/t/remove-timestamp-where-message-have-a-string-search/316661 "2022-10-14T16:22:42Z")

</div>

i have this |2022-09-30 15:10:15,151 ERROR \[stderr\] (default task-4) |at org.jboss.resteasy.resteasy-jaxrs@3.12.1.Final//org.jboss.resteasy.core.MethodInjectorImpl.invoke(MethodInjectorImpl.java:138)| |---|---| |2022-09…

---

## [Elasticsearch GeoIP and unknown error](https://discuss.elastic.co/t/elasticsearch-geoip-and-unknown-error/316541)

<div class="topic-metadata">

**Author:** [@ulysse31](https://discuss.elastic.co/u/ulysse31)\
**Replies:** 6\
**Last updated:** [October 14, 2022, 4:15pm UTC](https://discuss.elastic.co/t/elasticsearch-geoip-and-unknown-error/316541 "2022-10-14T16:15:50Z")

</div>

Hi, My elasticsearch DB suddently stopped making geoip resolve on entries, and on the elasticsearch DB logs the following message is logged: \[2022-10-13T15:06:21,875\]\[WARN \]\[o.e.i.g.GeoIpDownloader \] \[host\] could not …

---

## [Ho group specific pattern in 1 message?](https://discuss.elastic.co/t/ho-group-specific-pattern-in-1-message/316646)

<div class="topic-metadata">

**Author:** [@Nikolas1306](https://discuss.elastic.co/u/Nikolas1306)\
**Replies:** 0\
**Last updated:** [October 14, 2022, 2:38pm UTC](https://discuss.elastic.co/t/ho-group-specific-pattern-in-1-message/316646 "2022-10-14T14:38:32Z")

</div>

example 2022-09-28 16:48:11,016 INFO \[stdout\] (default task-2) RELOAD PKCS#11 CRYPTOKI 2022-09-28 16:48:11,027 ERROR \[stderr\] (default task-2) it.unidoc.cdr.core.exception.IdentityStoreException: it.unidoc.cdr.core.exc…

---

## [Unable to export csv](https://discuss.elastic.co/t/unable-to-export-csv/316362)

<div class="topic-metadata">

**Author:** [@rivermigue](https://discuss.elastic.co/u/rivermigue)\
**Replies:** 1\
**Last updated:** [October 14, 2022, 1:58pm UTC](https://discuss.elastic.co/t/unable-to-export-csv/316362 "2022-10-14T13:58:28Z")

</div>

I have recently enabled the xpack plugin for native basic authentication, once I did that, the export csv within kibana stopped working and displaying the following error message: Failed to create report Sorry, you don'…

---

## [Pull data from Elastic Enterprise Search to Kafka Topic](https://discuss.elastic.co/t/pull-data-from-elastic-enterprise-search-to-kafka-topic/316451)

<div class="topic-metadata">

**Author:** [@albertopneto](https://discuss.elastic.co/u/albertopneto)\
**Replies:** 7\
**Last updated:** [October 14, 2022, 12:43pm UTC](https://discuss.elastic.co/t/pull-data-from-elastic-enterprise-search-to-kafka-topic/316451 "2022-10-14T12:43:24Z")

</div>

Hi guys, I'm doing some experiments trying to pull data from Elasticsearch and pushing to Kafka. The source connector I'm using from Kafka Connect requires an index name and in this case with Elastic Enterprise Search …

---

## [Request elasticsearch to update geoip database](https://discuss.elastic.co/t/request-elasticsearch-to-update-geoip-database/315850)

<div class="topic-metadata">

**Author:** [@A\_Abdellah](https://discuss.elastic.co/u/A_Abdellah)\
**Replies:** 6\
**Last updated:** [October 14, 2022, 12:32pm UTC](https://discuss.elastic.co/t/request-elasticsearch-to-update-geoip-database/315850 "2022-10-14T12:32:30Z")

</div>

Hello I use elasticsearch on premises for security features, and I can't expose it all the time which made my geoip databases expire. I'm aware that elasticsearch use maxmind database and request using https://geoip.el…

---

## [Fuzzy search](https://discuss.elastic.co/t/fuzzy-search/316620)

<div class="topic-metadata">

**Author:** [@subodh\_dhukuchhu](https://discuss.elastic.co/u/subodh_dhukuchhu)\
**Replies:** 1\
**Last updated:** [October 14, 2022, 11:44am UTC](https://discuss.elastic.co/t/fuzzy-search/316620 "2022-10-14T11:44:07Z")

</div>

I have \[ {title:"This is title",desc:"This is desc"}, {title:"I am second title",desc:"I am second title"}, \] My requirement was To show result when I search "secott" ( from second object) To show result when I se…

---

## [Exact string match query on all fields](https://discuss.elastic.co/t/exact-string-match-query-on-all-fields/316623)

<div class="topic-metadata">

**Author:** [@melwinalmeida](https://discuss.elastic.co/u/melwinalmeida)\
**Replies:** 0\
**Last updated:** [October 14, 2022, 10:32am UTC](https://discuss.elastic.co/t/exact-string-match-query-on-all-fields/316623 "2022-10-14T10:32:09Z")

</div>

Our records contain lot of string fields. How do I perform an exact string match query without mentioning the field names in the query. For example, suppose I have following records: { "address": "google.com", "a…

---

## [Heartbeat monitoring not work](https://discuss.elastic.co/t/heartbeat-monitoring-not-work/316271)

<div class="topic-metadata">

**Author:** [@cheching](https://discuss.elastic.co/u/cheching)\
**Replies:** 3\
**Last updated:** [October 14, 2022, 9:44am UTC](https://discuss.elastic.co/t/heartbeat-monitoring-not-work/316271 "2022-10-14T09:44:44Z")

</div>

Hi All, I've encountered an issue when finished setup Uptime monitor under Observability. I'm not sure is that my configuration was incorrect or somewhere wrongly config, there're always show 0 monitors Please see b…

---

## [Shards for three node cluster](https://discuss.elastic.co/t/shards-for-three-node-cluster/316386)

<div class="topic-metadata">

**Author:** [@cool999](https://discuss.elastic.co/u/cool999)\
**Replies:** 6\
**Last updated:** [October 14, 2022, 6:50am UTC](https://discuss.elastic.co/t/shards-for-three-node-cluster/316386 "2022-10-14T06:50:35Z")

</div>

Hi Team, I have three node cluster and my current shard setting is 2 primary and 1 replica so in total, 4 shards for three node cluster. In this case, a single node is having one extra shard everytime? Can i have 1 pr…

---

## [Get the score for a document with String id](https://discuss.elastic.co/t/get-the-score-for-a-document-with-string-id/316596)

<div class="topic-metadata">

**Author:** [@karthik\_sagar](https://discuss.elastic.co/u/karthik_sagar)\
**Replies:** 1\
**Last updated:** [October 14, 2022, 6:47am UTC](https://discuss.elastic.co/t/get-the-score-for-a-document-with-string-id/316596 "2022-10-14T06:47:55Z")

</div>

Hi everyone, Here is a sample document I have with document id as string datatype. For one of my query I was expecting ~1000 records but the returned count is 10 documents less. I wanted to understand why some documents…

---

## [Pagination Logic in input of HTTP Poller plugin, if not how to do it in custom plugin](https://discuss.elastic.co/t/pagination-logic-in-input-of-http-poller-plugin-if-not-how-to-do-it-in-custom-plugin/316595)

<div class="topic-metadata">

**Author:** [@Sayontani\_Bose1](https://discuss.elastic.co/u/Sayontani_Bose1)\
**Replies:** 1\
**Last updated:** [October 14, 2022, 6:44am UTC](https://discuss.elastic.co/t/pagination-logic-in-input-of-http-poller-plugin-if-not-how-to-do-it-in-custom-plugin/316595 "2022-10-14T06:44:41Z")

</div>

I have to bulk import data via LogStash as below: Source: Restful Get APIs Destination : Elasticsearch My .conf file looks as below: input { http\_poller { urls =\> { ticket\_status =\> { method =\> get url =\> "https…

---

## [Installing Elasticsearch in Centos7 problem](https://discuss.elastic.co/t/installing-elasticsearch-in-centos7-problem/316497)

<div class="topic-metadata">

**Author:** [@MBekhit](https://discuss.elastic.co/u/MBekhit)\
**Replies:** 8\
**Last updated:** [October 14, 2022, 6:19am UTC](https://discuss.elastic.co/t/installing-elasticsearch-in-centos7-problem/316497 "2022-10-14T06:19:11Z")

</div>

Hi, I have this error when I want to install Elasticsearch in Centos 7 elasticsearch-7.17.6-x86\_64.rp FAILED https://artifacts.elastic.co/packages/7.x/yum/7.17.6/elasticsearch-…

[Previous page](https://discuss.elastic.co/tag/none.md?no_tags=true&page=516)

[Next page](https://discuss.elastic.co/tag/none.md?no_tags=true&page=518)
