# \#none

**URL:** https://discuss.elastic.co/tag/none.md?no_tags=true&page=521

[Latest](https://discuss.elastic.co/latest.md) · [Categories](https://discuss.elastic.co/categories.md) · [Tags](https://discuss.elastic.co/tags.md)

**Page:** 522

---

## [Set variable in configuration file](https://discuss.elastic.co/t/set-variable-in-configuration-file/316096)

<div class="topic-metadata">

**Author:** [@RickT](https://discuss.elastic.co/u/RickT)\
**Replies:** 5\
**Last updated:** [October 10, 2022, 3:41pm UTC](https://discuss.elastic.co/t/set-variable-in-configuration-file/316096 "2022-10-10T15:41:30Z")

</div>

Hi all ! Simply, is there some method in Logstash news versions to code a variable which can be used in input, filter and output sections ? if so, how to code it ? Thanks.

---

## [Updating elastic search document by id is not working](https://discuss.elastic.co/t/updating-elastic-search-document-by-id-is-not-working/316240)

<div class="topic-metadata">

**Author:** [@Atul\_Joshi1](https://discuss.elastic.co/u/Atul_Joshi1)\
**Replies:** 1\
**Last updated:** [October 10, 2022, 3:26pm UTC](https://discuss.elastic.co/t/updating-elastic-search-document-by-id-is-not-working/316240 "2022-10-10T15:26:05Z")

</div>

I have document structure as below stored in Elasticsearch - { "\_index" : "testIndex", "\_type" : "\_doc", "\_id" : "6ZR6soMBLkXUqNwMnccZ", "\_score" : 3.4454321, "\_source" : { …

---

## [No Host events Endpoint Security](https://discuss.elastic.co/t/no-host-events-endpoint-security/316046)

<div class="topic-metadata">

**Author:** [@shellcode](https://discuss.elastic.co/u/shellcode)\
**Replies:** 1\
**Last updated:** [October 10, 2022, 2:35pm UTC](https://discuss.elastic.co/t/no-host-events-endpoint-security/316046 "2022-10-10T14:35:09Z")

</div>

Hi all, I have installed Elastic Agent (enrolled with fleet and healthy) and Endpoint Security on a couple of hosts. All seems to work, except I am missing host events in the overview. There are events, but the messages…

---

## [Script field is automatically deleted from the index pattern](https://discuss.elastic.co/t/script-field-is-automatically-deleted-from-the-index-pattern/316175)

<div class="topic-metadata">

**Author:** [@Aniket\_Pant](https://discuss.elastic.co/u/Aniket_Pant)\
**Replies:** 1\
**Last updated:** [October 10, 2022, 12:23pm UTC](https://discuss.elastic.co/t/script-field-is-automatically-deleted-from-the-index-pattern/316175 "2022-10-10T12:23:50Z")

</div>

Hi Community, recently we add a custom field that parse the string field to integer field that time it was showing and after 7 days it is deleted. We have added the field by clicking on Add Field.

---

## [Kibana field filter suggester settings](https://discuss.elastic.co/t/kibana-field-filter-suggester-settings/315665)

<div class="topic-metadata">

**Author:** [@gribna](https://discuss.elastic.co/u/gribna)\
**Replies:** 2\
**Last updated:** [October 10, 2022, 10:39am UTC](https://discuss.elastic.co/t/kibana-field-filter-suggester-settings/315665 "2022-10-10T10:39:18Z")

</div>

Which setting affects the appearance of value suggestion list in filters and in queries? We have several environments and it doesn't work for one of them. The difference between environments is that the one that doesn't…

---

## [Kibana cannot startup - always tried to migrate](https://discuss.elastic.co/t/kibana-cannot-startup-always-tried-to-migrate/316200)

<div class="topic-metadata">

**Author:** [@misterking7](https://discuss.elastic.co/u/misterking7)\
**Replies:** 0\
**Last updated:** [October 10, 2022, 9:47am UTC](https://discuss.elastic.co/t/kibana-cannot-startup-always-tried-to-migrate/316200 "2022-10-10T09:47:42Z")

</div>

Hello team, I have issue with Kibana that cannot start up . before it was deployed into Openshift3 , Kibana version showed as 7.9.3 - Elasticsearch is 7.9.2 now, I tried to shutdown old cluster instance on Openshift3 …

---

## [Roadmap for "Stateless" Elasticsearch](https://discuss.elastic.co/t/roadmap-for-stateless-elasticsearch/316107)

<div class="topic-metadata">

**Author:** [@benjismith](https://discuss.elastic.co/u/benjismith)\
**Replies:** 8\
**Last updated:** [October 10, 2022, 9:28am UTC](https://discuss.elastic.co/t/roadmap-for-stateless-elasticsearch/316107 "2022-10-10T09:28:46Z")

</div>

I read yesterday's blog post about the future of a "stateless" Elasticsearch architecture, where one of the big benefits is the ability to scale indexing workloads separately from search workloads... I have a 30+ node…

---

## [Disable default secret creating in kubernetes](https://discuss.elastic.co/t/disable-default-secret-creating-in-kubernetes/316196)

<div class="topic-metadata">

**Author:** [@Norsu296](https://discuss.elastic.co/u/Norsu296)\
**Replies:** 0\
**Last updated:** [October 10, 2022, 8:46am UTC](https://discuss.elastic.co/t/disable-default-secret-creating-in-kubernetes/316196 "2022-10-10T08:46:03Z")

</div>

Hi, how can I disable secret creating for elasticsearch? I'm using deployment with Kind: Elasticsearch and I want to use my own password but elastic is still recreating k8s password like elastic: password with name xyz-e…

---

## [Linking Dashboard and Discover tab to view documents based on filter](https://discuss.elastic.co/t/linking-dashboard-and-discover-tab-to-view-documents-based-on-filter/315687)

<div class="topic-metadata">

**Author:** [@ashit\_pupu](https://discuss.elastic.co/u/ashit_pupu)\
**Replies:** 3\
**Last updated:** [October 10, 2022, 7:13am UTC](https://discuss.elastic.co/t/linking-dashboard-and-discover-tab-to-view-documents-based-on-filter/315687 "2022-10-10T07:13:05Z")

</div>

Hi Team, I am looking for any feature availability in Kibana which would enable me to link my dashboard to the discover tab to view the documents. So the idea is I have a dashboard created based on field aggregation I …

---

## [Case Insensitive search in kibana dahboard](https://discuss.elastic.co/t/case-insensitive-search-in-kibana-dahboard/315653)

<div class="topic-metadata">

**Author:** [@vikram\_singh](https://discuss.elastic.co/u/vikram_singh)\
**Replies:** 1\
**Last updated:** [October 10, 2022, 7:11am UTC](https://discuss.elastic.co/t/case-insensitive-search-in-kibana-dahboard/315653 "2022-10-10T07:11:12Z")

</div>

Hi, I created dashboard with some visualization and add filters on it. But these are case sensitive. Is it possible to search with lower or upper case. For exam Adam name searchable from Adam or adam or aDaM. Thanks

---

## [Same index pattern in multiple namespaces](https://discuss.elastic.co/t/same-index-pattern-in-multiple-namespaces/316085)

<div class="topic-metadata">

**Author:** [@umesh2020](https://discuss.elastic.co/u/umesh2020)\
**Replies:** 1\
**Last updated:** [October 10, 2022, 7:07am UTC](https://discuss.elastic.co/t/same-index-pattern-in-multiple-namespaces/316085 "2022-10-10T07:07:26Z")

</div>

Hi I am using Kibana/Elasticsearch version 7.16.3. I have trouble creating the same index pattern within multiple namespaces. I am using bulk create API to create multiple index patterns and for one of the patterns …

---

## [New to Elastic - Netflow Data Analysis](https://discuss.elastic.co/t/new-to-elastic-netflow-data-analysis/316073)

<div class="topic-metadata">

**Author:** [@bigverm23](https://discuss.elastic.co/u/bigverm23)\
**Replies:** 1\
**Last updated:** [October 10, 2022, 7:03am UTC](https://discuss.elastic.co/t/new-to-elastic-netflow-data-analysis/316073 "2022-10-10T07:03:28Z")

</div>

good morning all. I am very new to Elastic and am looking for resources/insight on ingesting netflow from firewall logs and help with analysis. We are ingesting a few million events per day and I'd like to get to a poi…

---

## [Not Able to see Indexes in Kibana, nor in logs of Elastic Search](https://discuss.elastic.co/t/not-able-to-see-indexes-in-kibana-nor-in-logs-of-elastic-search/316178)

<div class="topic-metadata">

**Author:** [@shivamec92](https://discuss.elastic.co/u/shivamec92)\
**Replies:** 0\
**Last updated:** [October 10, 2022, 6:48am UTC](https://discuss.elastic.co/t/not-able-to-see-indexes-in-kibana-nor-in-logs-of-elastic-search/316178 "2022-10-10T06:48:05Z")

</div>

This is the logs that i am getting from Debug mode of Elastic Search Authentication of \[elastic\] using realm \[reserved/reserved\] with token \[UsernamePasswordToken\] was \[AuthenticationResult{status=SUCCESS, value=User\[us…

---

## [Doubts about building a relationship master detail](https://discuss.elastic.co/t/doubts-about-building-a-relationship-master-detail/316170)

<div class="topic-metadata">

**Author:** [@abkrim](https://discuss.elastic.co/u/abkrim)\
**Replies:** 2\
**Last updated:** [October 10, 2022, 6:27am UTC](https://discuss.elastic.co/t/doubts-about-building-a-relationship-master-detail/316170 "2022-10-10T06:27:09Z")

</div>

Currently, I have an index that collects the logs of a series of control centers, and obtain from them the technical data of their electrical consumption, on and off status, and other kinds of data that allow me to know …

---

## [System.AggregateException: One or more errors occurred. ---\> Elasticsearch.Net.ElasticsearchClientException: The client is unable to verify that the server is Elasticsearch due to an unsuccessful product check call](https://discuss.elastic.co/t/system-aggregateexception-one-or-more-errors-occurred-elasticsearch-net-elasticsearchclientexception-the-client-is-unable-to-verify-that-the-server-is-elasticsearch-due-to-an-unsuccessful-product-check-call/315970)

<div class="topic-metadata">

**Author:** [@arulmani](https://discuss.elastic.co/u/arulmani)\
**Replies:** 2\
**Last updated:** [October 10, 2022, 6:00am UTC](https://discuss.elastic.co/t/system-aggregateexception-one-or-more-errors-occurred-elasticsearch-net-elasticsearchclientexception-the-client-is-unable-to-verify-that-the-server-is-elasticsearch-due-to-an-unsuccessful-product-check-call/315970 "2022-10-10T06:00:25Z")

</div>

The below specified two different errors are logged intermittently during the bulk delete operation on a 3 million data. The cron job to delete the records in bulk runs from 8 seconds to 15 seconds on every 2 minutes in…

---

## [Combine Metricbeat events into one with Logstash](https://discuss.elastic.co/t/combine-metricbeat-events-into-one-with-logstash/315896)

<div class="topic-metadata">

**Author:** [@bg4erem](https://discuss.elastic.co/u/bg4erem)\
**Replies:** 5\
**Last updated:** [October 10, 2022, 3:21am UTC](https://discuss.elastic.co/t/combine-metricbeat-events-into-one-with-logstash/315896 "2022-10-10T03:21:15Z")

</div>

Dear community I have spent several days trying to combine Metricbeat events into one with Logstash. I understand it should be done with the aggregate filter of Logstash. Still, I haven't figured it out. I use Logstas…

---

## [Apmsql is not tracking my sql queries](https://discuss.elastic.co/t/apmsql-is-not-tracking-my-sql-queries/316158)

<div class="topic-metadata">

**Author:** [@Leonardo\_Henrique](https://discuss.elastic.co/u/Leonardo_Henrique)\
**Replies:** 2\
**Last updated:** [October 10, 2022, 2:03am UTC](https://discuss.elastic.co/t/apmsql-is-not-tracking-my-sql-queries/316158 "2022-10-10T02:03:15Z")

</div>

Hello Everyone. I am trying to configure the APM to track as well the SQL transactions. I am looking to Built-in instrumentation modules | APM Go Agent Reference \[2.x\] | Elastic and this is my current test code dsn :=…

---

## [Dead letter queue not working with logtash output mongo](https://discuss.elastic.co/t/dead-letter-queue-not-working-with-logtash-output-mongo/316030)

<div class="topic-metadata">

**Author:** [@van\_le1](https://discuss.elastic.co/u/van_le1)\
**Replies:** 2\
**Last updated:** [October 10, 2022, 1:04am UTC](https://discuss.elastic.co/t/dead-letter-queue-not-working-with-logtash-output-mongo/316030 "2022-10-10T01:04:20Z")

</div>

Hi everyone, I intend to use dead letter queue on log event failure from sending log into mongodb use logtash. My config includes: logtash.yml http.host: "0.0.0.0" pipeline.batch.delay: 10 pipeline.batch.size: 10…

---

## [Openshift problem with logstash in other server](https://discuss.elastic.co/t/openshift-problem-with-logstash-in-other-server/316157)

<div class="topic-metadata">

**Author:** [@Nikolas1306](https://discuss.elastic.co/u/Nikolas1306)\
**Replies:** 4\
**Last updated:** [October 9, 2022, 10:21pm UTC](https://discuss.elastic.co/t/openshift-problem-with-logstash-in-other-server/316157 "2022-10-09T22:21:44Z")

</div>

2022-10-09T19:03:48,320\]\[WARN \]\[logstash.outputs.elasticsearch\]\[openshift1\] Attempted to resurrect connection to dead ES instance, but got an error {:url=\>"http://elastichttp2-n-turri-dev.apps.sandbox-m2.ll9k.p1.openshif…

---

## [Force index rollover with a new index name](https://discuss.elastic.co/t/force-index-rollover-with-a-new-index-name/315983)

<div class="topic-metadata">

**Author:** [@frank\_rib](https://discuss.elastic.co/u/frank_rib)\
**Replies:** 2\
**Last updated:** [October 9, 2022, 8:35pm UTC](https://discuss.elastic.co/t/force-index-rollover-with-a-new-index-name/315983 "2022-10-09T20:35:05Z")

</div>

Hello, I was configured filebeat agent to send data directly to elasticsearch from multiples agent. afterwards I added the index to a have a problem with the rollover I added the index to the retention policy test0. T…

---

## [Scripted Field Help](https://discuss.elastic.co/t/scripted-field-help/316156)

<div class="topic-metadata">

**Author:** [@snkhan](https://discuss.elastic.co/u/snkhan)\
**Replies:** 11\
**Last updated:** [October 9, 2022, 6:44pm UTC](https://discuss.elastic.co/t/scripted-field-help/316156 "2022-10-09T18:44:40Z")

</div>

Hello, I am trying to use a scripted field to compare the value of one field against another. A sample document extract is below: Field1 C2\_Host: \["check.example.workers.dev"\] Field2 HostHeader: "Host: check.example.w…

---

## [Upgrade from 7.x to 8.4.1](https://discuss.elastic.co/t/upgrade-from-7-x-to-8-4-1/316027)

<div class="topic-metadata">

**Author:** [@Ravi\_S1](https://discuss.elastic.co/u/Ravi_S1)\
**Replies:** 3\
**Last updated:** [October 9, 2022, 2:36pm UTC](https://discuss.elastic.co/t/upgrade-from-7-x-to-8-4-1/316027 "2022-10-09T14:36:47Z")

</div>

After upgrade from 7.7.1 to 8.4.1, Kibana 8.4.1 is showing down.. "{"statusCode":503,"error":"Service Unavailable","message":"\[No shard available for \[get \[.kibana\_8.4.1\]\[space:default\]: routing \[null\]\]: no\_shard\_availab…

---

## [Elasticsearch Highlight the result of script fields](https://discuss.elastic.co/t/elasticsearch-highlight-the-result-of-script-fields/316121)

<div class="topic-metadata">

**Author:** [@AmirMohammad\_Safari](https://discuss.elastic.co/u/AmirMohammad_Safari)\
**Replies:** 2\
**Last updated:** [October 9, 2022, 2:11pm UTC](https://discuss.elastic.co/t/elasticsearch-highlight-the-result-of-script-fields/316121 "2022-10-09T14:11:19Z")

</div>

I write out an analyzer to remove the HTML tags in my search results, After that I thought I could highlight the results with a common query, But in the highlighting field I got other html contents that you removed with …

---

## [Merging two indexes by a column](https://discuss.elastic.co/t/merging-two-indexes-by-a-column/315163)

<div class="topic-metadata">

**Author:** [@Juanfer](https://discuss.elastic.co/u/Juanfer)\
**Replies:** 2\
**Last updated:** [October 9, 2022, 10:38am UTC](https://discuss.elastic.co/t/merging-two-indexes-by-a-column/315163 "2022-10-09T10:38:41Z")

</div>

Hello there, I am a beginner in Elasticsearch and I have been reading about how to merge 2 indexes based on two different names columns with the same values. I understand the NoSQL performance of elastic but still havin…

---

## [JSON with comma separated string to multiple tags](https://discuss.elastic.co/t/json-with-comma-separated-string-to-multiple-tags/315111)

<div class="topic-metadata">

**Author:** [@Ranger\_Rick](https://discuss.elastic.co/u/Ranger_Rick)\
**Replies:** 2\
**Last updated:** [October 9, 2022, 1:38am UTC](https://discuss.elastic.co/t/json-with-comma-separated-string-to-multiple-tags/315111 "2022-10-09T01:38:22Z")

</div>

Good evening! I really think this should be easy and straightforward but I am having a heck of a time with it so decided to ask the community. My pipeline accepts daily json files and splits it out and further enriches …

---

## [List of Query DSL keywords and additional instructions](https://discuss.elastic.co/t/list-of-query-dsl-keywords-and-additional-instructions/316132)

<div class="topic-metadata">

**Author:** [@Michael\_Gattinger](https://discuss.elastic.co/u/Michael_Gattinger)\
**Replies:** 4\
**Last updated:** [October 8, 2022, 5:49pm UTC](https://discuss.elastic.co/t/list-of-query-dsl-keywords-and-additional-instructions/316132 "2022-10-08T17:49:22Z")

</div>

Hello, as i understood Query DSL has in line 1 of the Query spezial keywords that are not part of the JSON. JSON starts at line 2 of the Query and is only one JSON-Object accept BULK-Requests, where multiple JSON Object…

---

## [Unable to Parse AVRO using Kafka Input and Avro Codec](https://discuss.elastic.co/t/unable-to-parse-avro-using-kafka-input-and-avro-codec/316133)

<div class="topic-metadata">

**Author:** [@mastersmit](https://discuss.elastic.co/u/mastersmit)\
**Replies:** 0\
**Last updated:** [October 8, 2022, 4:23pm UTC](https://discuss.elastic.co/t/unable-to-parse-avro-using-kafka-input-and-avro-codec/316133 "2022-10-08T16:23:09Z")

</div>

Hi, I am trying to use Kafka Input and Codec Avro, to read the messages but unable to do so. In Kafka, { "id": 5839355690199358000, "name": "VOH\*a|\[RF6y?" } In Logstash Output: "@timestamp" =\> 2022-10-08T14:…

---

## [Is Elastic Java Client actually communicating with Query DSL?](https://discuss.elastic.co/t/is-elastic-java-client-actually-communicating-with-query-dsl/316128)

<div class="topic-metadata">

**Author:** [@Michael\_Gattinger](https://discuss.elastic.co/u/Michael_Gattinger)\
**Replies:** 2\
**Last updated:** [October 8, 2022, 3:31pm UTC](https://discuss.elastic.co/t/is-elastic-java-client-actually-communicating-with-query-dsl/316128 "2022-10-08T15:31:55Z")

</div>

Hello, writing my master thesis. So a) if we are in Kibana we can open the dev console and type Query DSL (formatted in JSON) to send it to Elasticsearch. b) additionally we can send Query DSL (formatted in JSON) fro…

---

## [Elk on openshift server have limit?](https://discuss.elastic.co/t/elk-on-openshift-server-have-limit/316124)

<div class="topic-metadata">

**Author:** [@Nikolas1306](https://discuss.elastic.co/u/Nikolas1306)\
**Replies:** 6\
**Last updated:** [October 8, 2022, 3:00pm UTC](https://discuss.elastic.co/t/elk-on-openshift-server-have-limit/316124 "2022-10-08T15:00:09Z")

</div>

hello i' ve mounted elk vers 7.16.2 but in console i see this logs \[2022-10-08T11:59:14,859\]\[ERROR\]\[logstash.licensechecker.licensereader\] Unable to retrieve license information from license server {:message=\>"No Avail…

---

## [Remove / using logstash filter](https://discuss.elastic.co/t/remove-using-logstash-filter/316106)

<div class="topic-metadata">

**Author:** [@Giridharan\_C](https://discuss.elastic.co/u/Giridharan_C)\
**Replies:** 3\
**Last updated:** [October 8, 2022, 1:52pm UTC](https://discuss.elastic.co/t/remove-using-logstash-filter/316106 "2022-10-08T13:52:32Z")

</div>

I used multiple mutate filters to remove the / in the message field, which is not working. Also, I want to parse these message fields into valid JSON. Please suggest and help. { "host" =\> "mylocalhost.mydomain.com", …

[Previous page](https://discuss.elastic.co/tag/none.md?no_tags=true&page=520)

[Next page](https://discuss.elastic.co/tag/none.md?no_tags=true&page=522)
