# \#none

**URL:** https://discuss.elastic.co/tag/none.md?no_tags=true&page=520

[Latest](https://discuss.elastic.co/latest.md) · [Categories](https://discuss.elastic.co/categories.md) · [Tags](https://discuss.elastic.co/tags.md)

**Page:** 521

---

## [Elasticsearch Search Query](https://discuss.elastic.co/t/elasticsearch-search-query/316372)

<div class="topic-metadata">

**Author:** [@Ankita\_Pachauri](https://discuss.elastic.co/u/Ankita_Pachauri)\
**Replies:** 0\
**Last updated:** [October 11, 2022, 7:09pm UTC](https://discuss.elastic.co/t/elasticsearch-search-query/316372 "2022-10-11T19:09:49Z")

</div>

Hi Team, I have written a DSL Query as shown below: GET metricbeat\*/\_search { "size": 0, "aggs": { "hosts": { "terms": { "field": "agent.hostname", "size": "100", "order": { "memory": "desc" } }, "aggs": { …

---

## [How to set the max file size to unlimited in windows 10?](https://discuss.elastic.co/t/how-to-set-the-max-file-size-to-unlimited-in-windows-10/316366)

<div class="topic-metadata">

**Author:** [@JamesD\_7](https://discuss.elastic.co/u/JamesD_7)\
**Replies:** 0\
**Last updated:** [October 11, 2022, 6:30pm UTC](https://discuss.elastic.co/t/how-to-set-the-max-file-size-to-unlimited-in-windows-10/316366 "2022-10-11T18:30:03Z")

</div>

I'm ingesting a single CSV file in ES 8.4 using Kibana, but I found I hit the maximum size limit of 100k rows and had to split the file in two. I saw in the docs that you can set this file: /etc/security/limits.conf usi…

---

## [Multiple syslog input into logstash](https://discuss.elastic.co/t/multiple-syslog-input-into-logstash/316360)

<div class="topic-metadata">

**Author:** [@kazishafiullah](https://discuss.elastic.co/u/kazishafiullah)\
**Replies:** 2\
**Last updated:** [October 11, 2022, 5:24pm UTC](https://discuss.elastic.co/t/multiple-syslog-input-into-logstash/316360 "2022-10-11T17:24:27Z")

</div>

Hello, I wanted to parse logs of network devices into logstash. I have configured individual pipeline for cisco and paloalto. I have configured the input as syslog with different ports and output to different index name…

---

## [Why "View single document" is "button" tag in HTML and not a "a" tag with URL?](https://discuss.elastic.co/t/why-view-single-document-is-button-tag-in-html-and-not-a-a-tag-with-url/315583)

<div class="topic-metadata">

**Author:** [@bryancev](https://discuss.elastic.co/u/bryancev)\
**Replies:** 2\
**Last updated:** [October 11, 2022, 5:04pm UTC](https://discuss.elastic.co/t/why-view-single-document-is-button-tag-in-html-and-not-a-a-tag-with-url/315583 "2022-10-11T17:04:14Z")

</div>

Hi all! Why in Kibana version 8.1.2 the "View single document" document view is implemented via the button tag? This is extremely inconvenient, since I would like to open documents in a new tab by clicking the mouse wh…

---

## [Trying to implement CDC transfer from MongoDB to Elasticsearch 8.4](https://discuss.elastic.co/t/trying-to-implement-cdc-transfer-from-mongodb-to-elasticsearch-8-4/316007)

<div class="topic-metadata">

**Author:** [@Venkatesh\_Guruprasad](https://discuss.elastic.co/u/Venkatesh_Guruprasad)\
**Replies:** 7\
**Last updated:** [October 11, 2022, 4:55pm UTC](https://discuss.elastic.co/t/trying-to-implement-cdc-transfer-from-mongodb-to-elasticsearch-8-4/316007 "2022-10-11T16:55:25Z")

</div>

We are trying to implement CDC transfer from MongoDB to Elasticsearch 8.4. Do we have to manually create index mappings for each Mongo collection or can we enable dynamic mappings on create within Elasticsearch

---

## [Spring + ElasticSearch - How to bulk create or update document with autogenerated string \_id/id](https://discuss.elastic.co/t/spring-elasticsearch-how-to-bulk-create-or-update-document-with-autogenerated-string-id-id/316352)

<div class="topic-metadata">

**Author:** [@Java2avaj](https://discuss.elastic.co/u/Java2avaj)\
**Replies:** 1\
**Last updated:** [October 11, 2022, 4:49pm UTC](https://discuss.elastic.co/t/spring-elasticsearch-how-to-bulk-create-or-update-document-with-autogenerated-string-id-id/316352 "2022-10-11T16:49:00Z")

</div>

currently, we are forcing the \_id of the Elasticsearch documents by setting the id field. This simplifies the design, as it allows to perform updates and/or creation of new documents without previously knowing whether a …

---

## [Getting the same values multiple times while integrating Mysql with Logstash](https://discuss.elastic.co/t/getting-the-same-values-multiple-times-while-integrating-mysql-with-logstash/316277)

<div class="topic-metadata">

**Author:** [@Ritikapawar](https://discuss.elastic.co/u/Ritikapawar)\
**Replies:** 1\
**Last updated:** [October 11, 2022, 2:37pm UTC](https://discuss.elastic.co/t/getting-the-same-values-multiple-times-while-integrating-mysql-with-logstash/316277 "2022-10-11T14:37:22Z")

</div>

I've created a pipeline to get data directly from Mysql to kibana using logstash and Jdbc input plugin But when I do the actual execution on .conf file I'm getting the same values multiple time in the elastic index. he…

---

## [Deploy Logstash pipeline through Gitlab CI/CD](https://discuss.elastic.co/t/deploy-logstash-pipeline-through-gitlab-ci-cd/316257)

<div class="topic-metadata">

**Author:** [@kmz161](https://discuss.elastic.co/u/kmz161)\
**Replies:** 3\
**Last updated:** [October 11, 2022, 12:56pm UTC](https://discuss.elastic.co/t/deploy-logstash-pipeline-through-gitlab-ci-cd/316257 "2022-10-11T12:56:22Z")

</div>

Hi! I use Centralized Pipeline Management for creation and management pipeline. But I can’t saved changing of pipeline settings . Because of it I started use Gitlab to store pipelines config. And now I need perform tw…

---

## [Kibana (8.4.2) visualization does not show metadata fields](https://discuss.elastic.co/t/kibana-8-4-2-visualization-does-not-show-metadata-fields/316279)

<div class="topic-metadata">

**Author:** [@amirfarsi](https://discuss.elastic.co/u/amirfarsi)\
**Replies:** 3\
**Last updated:** [October 11, 2022, 12:32pm UTC](https://discuss.elastic.co/t/kibana-8-4-2-visualization-does-not-show-metadata-fields/316279 "2022-10-11T12:32:07Z")

</div>

Hello friends. We updated our ELK from 7.\* to 8.4.2, and we used from our backups to restoring visualization, dashboards, data views (index pattern) and ... We had problems that were fixed, except for the following : …

---

## [Issue in parsing JSON data](https://discuss.elastic.co/t/issue-in-parsing-json-data/316210)

<div class="topic-metadata">

**Author:** [@Aniket\_Pant](https://discuss.elastic.co/u/Aniket_Pant)\
**Replies:** 1\
**Last updated:** [October 11, 2022, 12:06pm UTC](https://discuss.elastic.co/t/issue-in-parsing-json-data/316210 "2022-10-11T12:06:10Z")

</div>

Sample Logs \[{ "Name":"abc", "Phone\_no":"9877231", "Gender":"M" } \] I am getting data from filebeat - paths: - /root/test.log fields: {log\_type: json-multiline} multiline.type: pattern multiline.pattern: '^\\…

---

## [LDAP User Authentication Multiple Users](https://discuss.elastic.co/t/ldap-user-authentication-multiple-users/316319)

<div class="topic-metadata">

**Author:** [@Tarah](https://discuss.elastic.co/u/Tarah)\
**Replies:** 0\
**Last updated:** [October 11, 2022, 10:47am UTC](https://discuss.elastic.co/t/ldap-user-authentication-multiple-users/316319 "2022-10-11T10:47:29Z")

</div>

Hi Elastic Team, I'm still new on configuring LDAP User Auth. Just wanted to ask if it's possible to use the password value in LDAP directly as the bind password? Because what I have done today was only 1 user and just …

---

## [Salesforce integration with ELK](https://discuss.elastic.co/t/salesforce-integration-with-elk/316317)

<div class="topic-metadata">

**Author:** [@Ayaan\_Shaik](https://discuss.elastic.co/u/Ayaan_Shaik)\
**Replies:** 0\
**Last updated:** [October 11, 2022, 10:40am UTC](https://discuss.elastic.co/t/salesforce-integration-with-elk/316317 "2022-10-11T10:40:45Z")

</div>

Hi team, I'm Using ELK version : 8.3.3 I am trying to ingest Salesforce data with the help of file beat module Salesforce through logstash , But I'm unable to get the data into kibana and elasticsearch . Suppose if I …

---

## [Field mapping: "ignore\_above" and "index" settings](https://discuss.elastic.co/t/field-mapping-ignore-above-and-index-settings/316235)

<div class="topic-metadata">

**Author:** [@gdd](https://discuss.elastic.co/u/gdd)\
**Replies:** 0\
**Last updated:** [October 10, 2022, 2:24pm UTC](https://discuss.elastic.co/t/field-mapping-ignore-above-and-index-settings/316235 "2022-10-10T14:24:36Z")

</div>

I experienced bulks by logstash returning some errors, The template contained this mapping for event.original field: {"index": false, "type": "keyword", "doc\_values": false } The unexpected solution has been the intro…

---

## [ES upgrade from 6 to 8 - How to?](https://discuss.elastic.co/t/es-upgrade-from-6-to-8-how-to/316290)

<div class="topic-metadata">

**Author:** [@Eduardo\_Montes](https://discuss.elastic.co/u/Eduardo_Montes)\
**Replies:** 0\
**Last updated:** [October 11, 2022, 8:40am UTC](https://discuss.elastic.co/t/es-upgrade-from-6-to-8-how-to/316290 "2022-10-11T08:40:35Z")

</div>

Hi, I tried to make the ES upgrade from 6.2.4 to 8.4. I found out that there are many not supported features in 8 version. E.g. missing tree a precision attributes in geo\_shape data type, not supported possibility to d…

---

## [Logstash input configuration](https://discuss.elastic.co/t/logstash-input-configuration/316296)

<div class="topic-metadata">

**Author:** [@ttyser](https://discuss.elastic.co/u/ttyser)\
**Replies:** 2\
**Last updated:** [October 11, 2022, 10:09am UTC](https://discuss.elastic.co/t/logstash-input-configuration/316296 "2022-10-11T10:09:00Z")

</div>

Hello, I have a question how should Logstash input config look like in case I have Fleet server, multiple agents/endpoints, checkpoint firewall etc logging to Logstash. What I am trying to ask is, should every agent have…

---

## [Retreive slowlog on ECE](https://discuss.elastic.co/t/retreive-slowlog-on-ece/316308)

<div class="topic-metadata">

**Author:** [@zanga](https://discuss.elastic.co/u/zanga)\
**Replies:** 0\
**Last updated:** [October 11, 2022, 9:58am UTC](https://discuss.elastic.co/t/retreive-slowlog-on-ece/316308 "2022-10-11T09:58:41Z")

</div>

Hello everyone, I am trying to investigate one of my cluster, thus I am trying to setup the slowlogs so that I can monitor queries. I modified my cluster settings as so : "index.search.slowlog.threshold.query.trace": …

---

## [Polygon storage failed](https://discuss.elastic.co/t/polygon-storage-failed/316162)

<div class="topic-metadata">

**Author:** [@baiwenbo1997](https://discuss.elastic.co/u/baiwenbo1997)\
**Replies:** 12\
**Last updated:** [October 11, 2022, 8:42am UTC](https://discuss.elastic.co/t/polygon-storage-failed/316162 "2022-10-11T08:42:40Z")

</div>

POLYGON((38591455.29279993 3341853.182999084,38591450.89579993 3341845.826799084,38591447.82339992 3341841.763499084,38591444.25549993 3341839.186599084,38591438.30899993 3341835.420499084,38591431.17329992 3341830.66319…

---

## [Logstash Pipeline getting Terminated due to avro format of kakfka topic](https://discuss.elastic.co/t/logstash-pipeline-getting-terminated-due-to-avro-format-of-kakfka-topic/316276)

<div class="topic-metadata">

**Author:** [@Akumar22](https://discuss.elastic.co/u/Akumar22)\
**Replies:** 0\
**Last updated:** [October 11, 2022, 6:45am UTC](https://discuss.elastic.co/t/logstash-pipeline-getting-terminated-due-to-avro-format-of-kakfka-topic/316276 "2022-10-11T06:45:24Z")

</div>

Hi, I have a topic in kafka which has messages in avro format, pasting a part of message below .. We are using this avro schema format, pasting a part of schema { "type" : "record", "name" : "ProductDetailsSc…

---

## [Reset lab environment and training](https://discuss.elastic.co/t/reset-lab-environment-and-training/316259)

<div class="topic-metadata">

**Author:** [@deccman](https://discuss.elastic.co/u/deccman)\
**Replies:** 1\
**Last updated:** [October 11, 2022, 8:26am UTC](https://discuss.elastic.co/t/reset-lab-environment-and-training/316259 "2022-10-11T08:26:13Z")

</div>

Hi, Please could someone reset my Strigo lab environment and training progress for the Observability Engineer course, as I would like to a re-run of the course before doing the exam. This is the same/similar request as…

---

## [Cannot connect to Elasticsearch cluster using cloud\_id](https://discuss.elastic.co/t/cannot-connect-to-elasticsearch-cluster-using-cloud-id/316203)

<div class="topic-metadata">

**Author:** [@h.allaoui](https://discuss.elastic.co/u/h.allaoui)\
**Replies:** 8\
**Last updated:** [October 11, 2022, 7:57am UTC](https://discuss.elastic.co/t/cannot-connect-to-elasticsearch-cluster-using-cloud-id/316203 "2022-10-11T07:57:00Z")

</div>

Hi All, I have an issue, I cannot to connect to my Elasticsearch cluster from python client using its cloud\_id. I am getting following error: File "D:\\Data\\Hamid\\Workspace\\Python\\MyTools\\venv\\lib\\site-packages\\elast…

---

## [Trying to build index template from dynamicly generated template](https://discuss.elastic.co/t/trying-to-build-index-template-from-dynamicly-generated-template/315943)

<div class="topic-metadata">

**Author:** [@fribse](https://discuss.elastic.co/u/fribse)\
**Replies:** 2\
**Last updated:** [October 11, 2022, 7:52am UTC](https://discuss.elastic.co/t/trying-to-build-index-template-from-dynamicly-generated-template/315943 "2022-10-11T07:52:15Z")

</div>

I want to apply lifecycle policy on some of the indexes. So I think I need to create an index template, otherwise I will have to contiunally apply the policy to newly created indexes. I pulled an index template from a …

---

## [Aggregate + sort + paginate on nested documents](https://discuss.elastic.co/t/aggregate-sort-paginate-on-nested-documents/314715)

<div class="topic-metadata">

**Author:** [@t0mer](https://discuss.elastic.co/u/t0mer)\
**Replies:** 1\
**Last updated:** [October 11, 2022, 7:44am UTC](https://discuss.elastic.co/t/aggregate-sort-paginate-on-nested-documents/314715 "2022-10-11T07:44:19Z")

</div>

Hi, I'm managing a product index, with product sales and other KPIs under a nested field. Trying to sort based on nested aggregation, and paginate - with no success. Below is a simplified version of my mapping, for th…

---

## [Elasticsearch 7.17.4 crashes without an error message, while indexing large chunks of data on Windows](https://discuss.elastic.co/t/elasticsearch-7-17-4-crashes-without-an-error-message-while-indexing-large-chunks-of-data-on-windows/314690)

<div class="topic-metadata">

**Author:** [@simon137](https://discuss.elastic.co/u/simon137)\
**Replies:** 7\
**Last updated:** [October 11, 2022, 7:38am UTC](https://discuss.elastic.co/t/elasticsearch-7-17-4-crashes-without-an-error-message-while-indexing-large-chunks-of-data-on-windows/314690 "2022-10-11T07:38:34Z")

</div>

Hello, I tried multiple java heap configurations for both logstash and elasticsearch, and also using a persisted queue (with space up to 40gb) instead of a memory queue, but it's always the same: If I take a large chun…

---

## [Logstash was having pipeline error: event executor terminated. What would possibly be the problem?](https://discuss.elastic.co/t/logstash-was-having-pipeline-error-event-executor-terminated-what-would-possibly-be-the-problem/316212)

<div class="topic-metadata">

**Author:** [@prashanthk](https://discuss.elastic.co/u/prashanthk)\
**Replies:** 5\
**Last updated:** [October 11, 2022, 3:52am UTC](https://discuss.elastic.co/t/logstash-was-having-pipeline-error-event-executor-terminated-what-would-possibly-be-the-problem/316212 "2022-10-11T03:52:28Z")

</div>

input { http { host =\> "0.0.0.0" port =\> 8443 user =\> provider password =\> "c6N65uxZ$M5@" # ssl =\> true # keystore =\> "/etc/logstash/keystore.jks" # keystore\_password =\> "password" } } filter { mutate { add\_f…

---

## [Bootstrap check failure](https://discuss.elastic.co/t/bootstrap-check-failure/316025)

<div class="topic-metadata">

**Author:** [@rt\_888](https://discuss.elastic.co/u/rt_888)\
**Replies:** 4\
**Last updated:** [October 11, 2022, 3:46am UTC](https://discuss.elastic.co/t/bootstrap-check-failure/316025 "2022-10-11T03:46:54Z")

</div>

I tried using ES on AWS server of ubutu image, and modify the elasticsearch.yml file of node, discovery.seed\_hosts, master node . But got error with bootstrap node validation exception and it shows "at least one of \[dis…

---

## [Logstash auto reload the pipeline?](https://discuss.elastic.co/t/logstash-auto-reload-the-pipeline/316152)

<div class="topic-metadata">

**Author:** [@Nikolas1306](https://discuss.elastic.co/u/Nikolas1306)\
**Replies:** 1\
**Last updated:** [October 11, 2022, 1:38am UTC](https://discuss.elastic.co/t/logstash-auto-reload-the-pipeline/316152 "2022-10-11T01:38:02Z")

</div>

hello i've installed elk on cloud but the image have the original configuration pipeline if change the config and reload the image all file is reset with originals exist a method with modify pipeline and reload logstas…

---

## [How to search for username that logged in to install a specific app](https://discuss.elastic.co/t/how-to-search-for-username-that-logged-in-to-install-a-specific-app/316249)

<div class="topic-metadata">

**Author:** [@BabyElkUser](https://discuss.elastic.co/u/BabyElkUser)\
**Replies:** 1\
**Last updated:** [October 11, 2022, 12:20am UTC](https://discuss.elastic.co/t/how-to-search-for-username-that-logged-in-to-install-a-specific-app/316249 "2022-10-11T00:20:51Z")

</div>

Hi folks, I'm very new to Elk and am attempting to help our Information Security office with a few tasks. Per our Information Security Office, applications must be approved prior to being installed on a computer. Unfort…

---

## [Best security pratice for elastich search?](https://discuss.elastic.co/t/best-security-pratice-for-elastich-search/316251)

<div class="topic-metadata">

**Author:** [@Nikolas1306](https://discuss.elastic.co/u/Nikolas1306)\
**Replies:** 1\
**Last updated:** [October 10, 2022, 11:47pm UTC](https://discuss.elastic.co/t/best-security-pratice-for-elastich-search/316251 "2022-10-10T23:47:16Z")

</div>

hello what is best security pratice for elk?

---

## [Elasticsearch Upgrade 7.9.1 to 8.4](https://discuss.elastic.co/t/elasticsearch-upgrade-7-9-1-to-8-4/316229)

<div class="topic-metadata">

**Author:** [@jacknino](https://discuss.elastic.co/u/jacknino)\
**Replies:** 2\
**Last updated:** [October 10, 2022, 8:10pm UTC](https://discuss.elastic.co/t/elasticsearch-upgrade-7-9-1-to-8-4/316229 "2022-10-10T20:10:47Z")

</div>

Hi Channel, We are planning to upgrade Elasticsearch opensource 7.9.1 to 8.4. while upgrading we noticed multiple data disk path deprecation warning . Could anyone help us how we can proceed further. FYI, Elasticsearc…

---

## [Logstash not starting](https://discuss.elastic.co/t/logstash-not-starting/316188)

<div class="topic-metadata">

**Author:** [@sandeep\_singh3](https://discuss.elastic.co/u/sandeep_singh3)\
**Replies:** 2\
**Last updated:** [October 10, 2022, 5:44pm UTC](https://discuss.elastic.co/t/logstash-not-starting/316188 "2022-10-10T17:44:57Z")

</div>

I am trying to run Logstash on my window machine but unable to do so due below error \\Eclipse was unexpected at this time. Command used to run the logstash logstash.bat -f logstash.conf Version of Logstash - 7.16.3 l…

[Previous page](https://discuss.elastic.co/tag/none.md?no_tags=true&page=519)

[Next page](https://discuss.elastic.co/tag/none.md?no_tags=true&page=521)
