# \#none

**URL:** https://discuss.elastic.co/tag/none.md?no_tags=true&page=519

[Latest](https://discuss.elastic.co/latest.md) · [Categories](https://discuss.elastic.co/categories.md) · [Tags](https://discuss.elastic.co/tags.md)

**Page:** 520

---

## [Error Starting Kibana 8.4.3 Onpremise](https://discuss.elastic.co/t/error-starting-kibana-8-4-3-onpremise/316454)

<div class="topic-metadata">

**Author:** [@LeoCP](https://discuss.elastic.co/u/LeoCP)\
**Replies:** 2\
**Last updated:** [October 12, 2022, 9:26pm UTC](https://discuss.elastic.co/t/error-starting-kibana-8-4-3-onpremise/316454 "2022-10-12T21:26:50Z")

</div>

respectful greeting, I am evaluating the onpremise version of elasticsearch & Kibana 8.4.3 on windows 10, starting Elasticsearch, it works ok, I can see it http://localhost:9200/...... but when I try to run kibana. I ge…

---

## [Group regex while search](https://discuss.elastic.co/t/group-regex-while-search/316461)

<div class="topic-metadata">

**Author:** [@Indeed2000](https://discuss.elastic.co/u/Indeed2000)\
**Replies:** 0\
**Last updated:** [October 12, 2022, 6:09pm UTC](https://discuss.elastic.co/t/group-regex-while-search/316461 "2022-10-12T18:09:27Z")

</div>

Hi I have log file that contain lines like this: 08:00:00.032 user parameter: A\[0\]B\[0\]C: Action successful. How can i extract A value, B value while searching with regular expression. FYI:i don't want to change a…

---

## [Why logstash merge index of 3 different config?](https://discuss.elastic.co/t/why-logstash-merge-index-of-3-different-config/316450)

<div class="topic-metadata">

**Author:** [@Nikolas1306](https://discuss.elastic.co/u/Nikolas1306)\
**Replies:** 2\
**Last updated:** [October 12, 2022, 4:12pm UTC](https://discuss.elastic.co/t/why-logstash-merge-index-of-3-different-config/316450 "2022-10-12T16:12:07Z")

</div>

i ve 3 config but i see the 3 index is similar why ? all index contais info all 3 index this is my type config is different for path and name index in \*\* lines input { file { \*\*path =\> \[ "/logstash\_dir/fede…

---

## [Best solution for Aggregation SUM without losing precision](https://discuss.elastic.co/t/best-solution-for-aggregation-sum-without-losing-precision/316448)

<div class="topic-metadata">

**Author:** [@SooperTee](https://discuss.elastic.co/u/SooperTee)\
**Replies:** 0\
**Last updated:** [October 12, 2022, 3:35pm UTC](https://discuss.elastic.co/t/best-solution-for-aggregation-sum-without-losing-precision/316448 "2022-10-12T15:35:44Z")

</div>

Hi All, I think maybe similar subject was brought up here before, however, I was not able to find a satisfactory answer from the past posts in this forum. So I create a post of my own. I would like to state the constra…

---

## [Logstash cut line why?](https://discuss.elastic.co/t/logstash-cut-line-why/316440)

<div class="topic-metadata">

**Author:** [@Nikolas1306](https://discuss.elastic.co/u/Nikolas1306)\
**Replies:** 4\
**Last updated:** [October 12, 2022, 2:51pm UTC](https://discuss.elastic.co/t/logstash-cut-line-why/316440 "2022-10-12T14:51:06Z")

</div>

i have this secotion of logs 2022-09-28 16:19:49,383 ERROR \[it.unidoc.cdr.core.route.Iti41MllpSource\] (TcpSocketConsumerRunnable\[mllp://0.0.0.0:9010\] - /192.168.0.7:56372 =\> /192.168.0.32:9010) Conversion error: ca.uhn…

---

## [Enrich execution takes long time (about 3 min)](https://discuss.elastic.co/t/enrich-execution-takes-long-time-about-3-min/316390)

<div class="topic-metadata">

**Author:** [@hyungsun\_lim](https://discuss.elastic.co/u/hyungsun_lim)\
**Replies:** 2\
**Last updated:** [October 12, 2022, 2:15pm UTC](https://discuss.elastic.co/t/enrich-execution-takes-long-time-about-3-min/316390 "2022-10-12T14:15:02Z")

</div>

We use elasticsearch 7.5.0 version, and we use enrich pipelint to join two index every 15 min. However, enrich execution time takes about 3-5 min. It's so long time... I don't know the exact cause. What is the altern…

---

## [Kibana 8.4.2 dashboard date filter not working in firefox](https://discuss.elastic.co/t/kibana-8-4-2-dashboard-date-filter-not-working-in-firefox/316437)

<div class="topic-metadata">

**Author:** [@Jonas\_S](https://discuss.elastic.co/u/Jonas_S)\
**Replies:** 1\
**Last updated:** [October 12, 2022, 2:04pm UTC](https://discuss.elastic.co/t/kibana-8-4-2-dashboard-date-filter-not-working-in-firefox/316437 "2022-10-12T14:04:42Z")

</div>

Hello, when i try to add a filter for a date field with the add filter menu in firefox, the date given is not recognized. In chrome it works fine. I type for example 1.1.22, press tab and the date is there: Trying …

---

## [Can I convert a string column type to a timestamp?](https://discuss.elastic.co/t/can-i-convert-a-string-column-type-to-a-timestamp/316385)

<div class="topic-metadata">

**Author:** [@wpm](https://discuss.elastic.co/u/wpm)\
**Replies:** 1\
**Last updated:** [October 12, 2022, 1:38pm UTC](https://discuss.elastic.co/t/can-i-convert-a-string-column-type-to-a-timestamp/316385 "2022-10-12T13:38:06Z")

</div>

I ingested a bunch of documents. They have a property "time" containing strings of the form "2015-01-20 07:52:05.013047". I let Elastic automatically detect the data types and it treated "time" as a string. The schema ha…

---

## [Operator will not start](https://discuss.elastic.co/t/operator-will-not-start/316104)

<div class="topic-metadata">

**Author:** [@Jeff\_Rankin](https://discuss.elastic.co/u/Jeff_Rankin)\
**Replies:** 1\
**Last updated:** [October 12, 2022, 12:33pm UTC](https://discuss.elastic.co/t/operator-will-not-start/316104 "2022-10-12T12:33:03Z")

</div>

My operator which has worked just fine for a couple of years (with upgrades of course) is failing today. Logs are below. We had some kubernetes issues earlier but they are are all fixed now. This is the only issue we …

---

## [Warning : regular expression has redundant nested repeat operator](https://discuss.elastic.co/t/warning-regular-expression-has-redundant-nested-repeat-operator/316436)

<div class="topic-metadata">

**Author:** [@PM75](https://discuss.elastic.co/u/PM75)\
**Replies:** 0\
**Last updated:** [October 12, 2022, 12:26pm UTC](https://discuss.elastic.co/t/warning-regular-expression-has-redundant-nested-repeat-operator/316436 "2022-10-12T12:26:51Z")

</div>

Hello, After an update to version 8.4.3, I have this warning: regular expression has redundant nested repeat operator I took the time to search for it, but no post was found: \[ES 7.6\] regular expression has redundant…

---

## [Not able to view new features in Elastic security 8.4 i.e. (Respond Action0](https://discuss.elastic.co/t/not-able-to-view-new-features-in-elastic-security-8-4-i-e-respond-action0/316409)

<div class="topic-metadata">

**Author:** [@theacodes](https://discuss.elastic.co/u/theacodes)\
**Replies:** 2\
**Last updated:** [October 12, 2022, 12:19pm UTC](https://discuss.elastic.co/t/not-able-to-view-new-features-in-elastic-security-8-4-i-e-respond-action0/316409 "2022-10-12T12:19:31Z")

</div>

Hi! As shown in this video below section \[Purpose-built response automation interface \] Elastic Security 8.4: SOAR for modern security operations arms analysts to remediate threats faster | Elastic Blog where we go to …

---

## [I can't use the bulk function on my centos8](https://discuss.elastic.co/t/i-cant-use-the-bulk-function-on-my-centos8/316361)

<div class="topic-metadata">

**Author:** [@Vitoria\_De\_Lara](https://discuss.elastic.co/u/Vitoria_De_Lara)\
**Replies:** 1\
**Last updated:** [October 12, 2022, 12:17pm UTC](https://discuss.elastic.co/t/i-cant-use-the-bulk-function-on-my-centos8/316361 "2022-10-12T12:17:47Z")

</div>

{ "error" : { "root\_cause" : \[ { "type" : "illegal\_argument\_exception", "reason" : "Malformed action/metadata line \[3\], expected START\_OBJECT or END\_OBJECT but found \[VALUE\_STRING\]" } \], "type" : "illegal\_argumen…

---

## [Lucene query for string containing # (hash symbol)](https://discuss.elastic.co/t/lucene-query-for-string-containing-hash-symbol/316429)

<div class="topic-metadata">

**Author:** [@ykara84](https://discuss.elastic.co/u/ykara84)\
**Replies:** 0\
**Last updated:** [October 12, 2022, 11:28am UTC](https://discuss.elastic.co/t/lucene-query-for-string-containing-hash-symbol/316429 "2022-10-12T11:28:42Z")

</div>

How to query in Lucene for strings containing special characters such as @ and # for example #rescheduled i.e. it has to have the # in front of the word and not just the word itself, currently getting: Tried all sorts o…

---

## [Enrich processor time range](https://discuss.elastic.co/t/enrich-processor-time-range/316070)

<div class="topic-metadata">

**Author:** [@Marcin\_Frankiewicz](https://discuss.elastic.co/u/Marcin_Frankiewicz)\
**Replies:** 4\
**Last updated:** [October 12, 2022, 11:02am UTC](https://discuss.elastic.co/t/enrich-processor-time-range/316070 "2022-10-12T11:02:51Z")

</div>

Hi, i have a pipeline with enrich processor. When enriching is called.. what time range is used for enrich? All documents in index(defined in enrich policy) will be scanned? or maybe from last 15minutes? Elasticsearc…

---

## [What's the Lucene equivalent of KQL query: now/d](https://discuss.elastic.co/t/whats-the-lucene-equivalent-of-kql-query-now-d/316230)

<div class="topic-metadata">

**Author:** [@ykara84](https://discuss.elastic.co/u/ykara84)\
**Replies:** 3\
**Last updated:** [October 12, 2022, 10:58am UTC](https://discuss.elastic.co/t/whats-the-lucene-equivalent-of-kql-query-now-d/316230 "2022-10-12T10:58:21Z")

</div>

Hi I'm trying to filter my data based on a date field to show me everything for today, in Kibana I can use the KQL query using now/d but I need the equivalent for Lucene, any help? I wouldve thought it'd be the same but…

---

## [Debug slow search query](https://discuss.elastic.co/t/debug-slow-search-query/316265)

<div class="topic-metadata">

**Author:** [@Icy\_Goose](https://discuss.elastic.co/u/Icy_Goose)\
**Replies:** 1\
**Last updated:** [October 12, 2022, 10:45am UTC](https://discuss.elastic.co/t/debug-slow-search-query/316265 "2022-10-12T10:45:35Z")

</div>

Hi everyone, I'm trying to debug a slow search query in Elasticsearch. Per-shard activities seems healthy but total amount to complete the request is surprisingly high. As I understand, the profile API does not include t…

---

## [Elastic agent behind NAT](https://discuss.elastic.co/t/elastic-agent-behind-nat/316424)

<div class="topic-metadata">

**Author:** [@krzychohoho](https://discuss.elastic.co/u/krzychohoho)\
**Replies:** 1\
**Last updated:** [October 12, 2022, 10:05am UTC](https://discuss.elastic.co/t/elastic-agent-behind-nat/316424 "2022-10-12T10:05:45Z")

</div>

Hi, I came across some issues while trying to install elastic-agent. The case is I have a fleet server with elastic and kibana on local machine with local IP adres. The problem is that i need to deploy elastic agent on a…

---

## [Elastic-agent communication error](https://discuss.elastic.co/t/elastic-agent-communication-error/316418)

<div class="topic-metadata">

**Author:** [@Mohsin\_Ashraf](https://discuss.elastic.co/u/Mohsin_Ashraf)\
**Replies:** 0\
**Last updated:** [October 12, 2022, 8:18am UTC](https://discuss.elastic.co/t/elastic-agent-communication-error/316418 "2022-10-12T08:18:54Z")

</div>

hi, When I tried to enrol elastic-agent, it was successfully enrolled but after a few time, it give me this error I tried to resolve this but was not able to resolve this error. if anyone has a solution to this please h…

---

## [Logstash http\_poller "read time out" on http 200 response](https://discuss.elastic.co/t/logstash-http-poller-read-time-out-on-http-200-response/316416)

<div class="topic-metadata">

**Author:** [@Marc\_Hoog](https://discuss.elastic.co/u/Marc_Hoog)\
**Replies:** 0\
**Last updated:** [October 12, 2022, 8:11am UTC](https://discuss.elastic.co/t/logstash-http-poller-read-time-out-on-http-200-response/316416 "2022-10-12T08:11:33Z")

</div>

So I got this pipeline in logstash using http\_poller and it works when the client is responding with a 401, but It breaks when it responses with a 200 with a little bit of data. These request also do work with curl from…

---

## [Date histogram that doesn't look at the entire date bucket?](https://discuss.elastic.co/t/date-histogram-that-doesnt-look-at-the-entire-date-bucket/316415)

<div class="topic-metadata">

**Author:** [@netzer](https://discuss.elastic.co/u/netzer)\
**Replies:** 0\
**Last updated:** [October 12, 2022, 8:06am UTC](https://discuss.elastic.co/t/date-histogram-that-doesnt-look-at-the-entire-date-bucket/316415 "2022-10-12T08:06:33Z")

</div>

I'm wondering if the following is possible. I have events with metrics sent every 10 minutes, so when I create a dashboard looking at the past 15 minutes I can see the "latest status". I can also do a "SUM" of a field o…

---

## [Match and replace in logstash](https://discuss.elastic.co/t/match-and-replace-in-logstash/316406)

<div class="topic-metadata">

**Author:** [@tegerei](https://discuss.elastic.co/u/tegerei)\
**Replies:** 1\
**Last updated:** [October 12, 2022, 7:21am UTC](https://discuss.elastic.co/t/match-and-replace-in-logstash/316406 "2022-10-12T07:21:54Z")

</div>

Hello, I have a setup where I collect PfSense VPN logs and pass them through Logstash to extract some fields. My VPN logs have LDAP usernames such as doejo, which implies the full name of John Doe. Now I need the logs …

---

## [Is any Java client V7 working with ES V8?](https://discuss.elastic.co/t/is-any-java-client-v7-working-with-es-v8/316325)

<div class="topic-metadata">

**Author:** [@Eduardo\_Montes](https://discuss.elastic.co/u/Eduardo_Montes)\
**Replies:** 3\
**Last updated:** [October 12, 2022, 6:56am UTC](https://discuss.elastic.co/t/is-any-java-client-v7-working-with-es-v8/316325 "2022-10-12T06:56:26Z")

</div>

Hello, I'm trying to make upgrade from ES V6 to V8. Unfortunately I have to use Java 8 only (on client side). I found out that compatible (it means supported) Java 8 client (TransportClient) for ES V8 is also V7.17.6. …

---

## [Policy is not getting applied to the particular index in elastic](https://discuss.elastic.co/t/policy-is-not-getting-applied-to-the-particular-index-in-elastic/316399)

<div class="topic-metadata">

**Author:** [@AnandRajalingam](https://discuss.elastic.co/u/AnandRajalingam)\
**Replies:** 0\
**Last updated:** [October 12, 2022, 6:39am UTC](https://discuss.elastic.co/t/policy-is-not-getting-applied-to-the-particular-index-in-elastic/316399 "2022-10-12T06:39:08Z")

</div>

We have upgraded our elastic from 6.xxx to 7.17.15 version recently. Our elastic policy was working fine in the old instances but not working in the new server. Please find below steps which are performed while creating…

---

## [Logstash service discover\_files {:count=\>0}](https://discuss.elastic.co/t/logstash-service-discover-files-count-0/316376)

<div class="topic-metadata">

**Author:** [@fantastas](https://discuss.elastic.co/u/fantastas)\
**Replies:** 5\
**Last updated:** [October 12, 2022, 6:33am UTC](https://discuss.elastic.co/t/logstash-service-discover-files-count-0/316376 "2022-10-12T06:33:30Z")

</div>

hello, i have an issue i can't figure out. I am also not sure how logstash sincedb\_path works too so if someone could help me understand - I'd highly appreciate. I am running ELK on RedHat Linux virtual machine. If i …

---

## [Is Rolling restart documentation correct?](https://discuss.elastic.co/t/is-rolling-restart-documentation-correct/316338)

<div class="topic-metadata">

**Author:** [@landychev](https://discuss.elastic.co/u/landychev)\
**Replies:** 2\
**Last updated:** [October 12, 2022, 6:33am UTC](https://discuss.elastic.co/t/is-rolling-restart-documentation-correct/316338 "2022-10-12T06:33:05Z")

</div>

I have read the documentation for rolling restart at. and more about cluster.routing.allocation.enable What i am confused about is step 7, Re-enable shard allocation . Why would you set it to null when the default v…

---

## [Read data from postgres and calling external api in Logstash](https://discuss.elastic.co/t/read-data-from-postgres-and-calling-external-api-in-logstash/316398)

<div class="topic-metadata">

**Author:** [@mani7](https://discuss.elastic.co/u/mani7)\
**Replies:** 0\
**Last updated:** [October 12, 2022, 6:28am UTC](https://discuss.elastic.co/t/read-data-from-postgres-and-calling-external-api-in-logstash/316398 "2022-10-12T06:28:19Z")

</div>

I am looking forward to read data from Postgres using Logstash, taking one value as a input to call one external api. and taking the output results of that. And storing into elastic. Can anyone tell what all can be the …

---

## [Full Text Search Force Find All Tokens](https://discuss.elastic.co/t/full-text-search-force-find-all-tokens/316215)

<div class="topic-metadata">

**Author:** [@Saeed\_Mozaffari](https://discuss.elastic.co/u/Saeed_Mozaffari)\
**Replies:** 4\
**Last updated:** [October 12, 2022, 6:24am UTC](https://discuss.elastic.co/t/full-text-search-force-find-all-tokens/316215 "2022-10-12T06:24:22Z")

</div>

I try to implement full text search. I have a question related to this subject. I want to at search time, when i search a text, for example "Hello Saeed", return result only when all tokens of that text exist in a mess…

---

## [Condition filter not working after upgrading to logstash8](https://discuss.elastic.co/t/condition-filter-not-working-after-upgrading-to-logstash8/316300)

<div class="topic-metadata">

**Author:** [@PIYUSH\_MISHRA1](https://discuss.elastic.co/u/PIYUSH_MISHRA1)\
**Replies:** 5\
**Last updated:** [October 12, 2022, 5:35am UTC](https://discuss.elastic.co/t/condition-filter-not-working-after-upgrading-to-logstash8/316300 "2022-10-12T05:35:52Z")

</div>

Hi Team, I have following configuration in my logstash.conf file. irresepective of the value in ${ENV}, always else block is getting executed. Same piece of code used to work with logstash older versions (2.X and 6.x)…

---

## [Aggregation is not working occasionally](https://discuss.elastic.co/t/aggregation-is-not-working-occasionally/316392)

<div class="topic-metadata">

**Author:** [@Tomo\_M](https://discuss.elastic.co/u/Tomo_M)\
**Replies:** 0\
**Last updated:** [October 12, 2022, 2:01am UTC](https://discuss.elastic.co/t/aggregation-is-not-working-occasionally/316392 "2022-10-12T02:01:15Z")

</div>

Hi, I'm using Elasticsearch 7.16.2 and posting query by Dev Tools of Kibana 7.16.2. I got strange results from an aggregation query. When I repeat completely the same query: GET ss-mix2\_omp-01\_active/\_search { "siz…

---

## [Elasticsearch, Kibana, Apache-Nifi](https://discuss.elastic.co/t/elasticsearch-kibana-apache-nifi/316382)

<div class="topic-metadata">

**Author:** [@sytherin](https://discuss.elastic.co/u/sytherin)\
**Replies:** 0\
**Last updated:** [October 11, 2022, 8:49pm UTC](https://discuss.elastic.co/t/elasticsearch-kibana-apache-nifi/316382 "2022-10-11T20:49:35Z")

</div>

Hi! so I am trying to build a log with Apache Nifi and send it to Elasticsearch, and Kibana on ubuntu. After downloading the Apache Nifi, i ran the \<gpg --import KEYS\> to verify he integrity of the files, i got \<gpg: ca…

[Previous page](https://discuss.elastic.co/tag/none.md?no_tags=true&page=518)

[Next page](https://discuss.elastic.co/tag/none.md?no_tags=true&page=520)
