# \#none

**URL:** https://discuss.elastic.co/tag/none.md?no_tags=true&page=522

[Latest](https://discuss.elastic.co/latest.md) · [Categories](https://discuss.elastic.co/categories.md) · [Tags](https://discuss.elastic.co/tags.md)

**Page:** 523

---

## [Store multiple values using ruby in multivalue field](https://discuss.elastic.co/t/store-multiple-values-using-ruby-in-multivalue-field/316059)

<div class="topic-metadata">

**Author:** [@bertr](https://discuss.elastic.co/u/bertr)\
**Replies:** 2\
**Last updated:** [October 8, 2022, 1:40pm UTC](https://discuss.elastic.co/t/store-multiple-values-using-ruby-in-multivalue-field/316059 "2022-10-08T13:40:57Z")

</div>

By nature all fields in elasticsearch are multivalue-enabled, i.e. they can have multiple values in one document. Using mutate filter it is easy to add multiple values, but I need to use ruby. I am trying to add multiple…

---

## [Handling changes between Kibana instances](https://discuss.elastic.co/t/handling-changes-between-kibana-instances/315640)

<div class="topic-metadata">

**Author:** [@cyberzlo](https://discuss.elastic.co/u/cyberzlo)\
**Replies:** 2\
**Last updated:** [October 8, 2022, 11:25am UTC](https://discuss.elastic.co/t/handling-changes-between-kibana-instances/315640 "2022-10-08T11:25:14Z")

</div>

I have a dozen or so Kibans with the same basic configuration, but they differ slightly from one another (e.g. the selected queries are slightly altered). Is there a good option for handling this? What I have in mind, fo…

---

## [Elastic Search and Python pushing error](https://discuss.elastic.co/t/elastic-search-and-python-pushing-error/316105)

<div class="topic-metadata">

**Author:** [@Shashank02](https://discuss.elastic.co/u/Shashank02)\
**Replies:** 1\
**Last updated:** [October 8, 2022, 9:07am UTC](https://discuss.elastic.co/t/elastic-search-and-python-pushing-error/316105 "2022-10-08T09:07:33Z")

</div>

elasticsearch.BadRequestError: BadRequestError(400, 'illegal\_argument\_exception', 'Action/metadata line \[1\] contains an unknown parameter \[\_type\]') How do you resolve this error? I'm trying to push the data through my p…

---

## [Unable to Tessellate shape. Possible malformed shape detected](https://discuss.elastic.co/t/unable-to-tessellate-shape-possible-malformed-shape-detected/316122)

<div class="topic-metadata">

**Author:** [@baiwenbo1997](https://discuss.elastic.co/u/baiwenbo1997)\
**Replies:** 0\
**Last updated:** [October 8, 2022, 8:58am UTC](https://discuss.elastic.co/t/unable-to-tessellate-shape-possible-malformed-shape-detected/316122 "2022-10-08T08:58:21Z")

</div>

Why is this polygon judged to be a self-intersecting figure? If it is the accuracy problem that causes the judgment to be self-intersecting, how can I make the judgment during storage, or please tell me what is the accu…

---

## [Action \[cluster:monitor/nodes/stats\[n\]\] timed out](https://discuss.elastic.co/t/action-cluster-monitor-nodes-stats-n-timed-out/312818)

<div class="topic-metadata">

**Author:** [@dukewrz](https://discuss.elastic.co/u/dukewrz)\
**Replies:** 8\
**Last updated:** [October 8, 2022, 6:56am UTC](https://discuss.elastic.co/t/action-cluster-monitor-nodes-stats-n-timed-out/312818 "2022-10-08T06:56:41Z")

</div>

I can't take the log file out. Logs says: Received response for a request that as timed out, sent \[xxx/xxx\] ago..... tells that a timeout occurred when the master tries to collecting node stats info from one particu…

---

## [Certificate issue while installing Elastic cluster using Helm Kubernetes](https://discuss.elastic.co/t/certificate-issue-while-installing-elastic-cluster-using-helm-kubernetes/315335)

<div class="topic-metadata">

**Author:** [@RoshRagh](https://discuss.elastic.co/u/RoshRagh)\
**Replies:** 0\
**Last updated:** [September 28, 2022, 8:35am UTC](https://discuss.elastic.co/t/certificate-issue-while-installing-elastic-cluster-using-helm-kubernetes/315335 "2022-09-28T08:35:06Z")

</div>

Hi, I am doing a helm-Kubernetes deployment of Elastic cluster and I am using company signed CA certificates. Elasticsearch is coming up with the certificate, however Kibana gives this error. Looking for help on underst…

---

## [Is it possible for Elasticsearch to integration with sophos and watchguard firewall?](https://discuss.elastic.co/t/is-it-possible-for-elasticsearch-to-integration-with-sophos-and-watchguard-firewall/315518)

<div class="topic-metadata">

**Author:** [@vyom](https://discuss.elastic.co/u/vyom)\
**Replies:** 0\
**Last updated:** [September 30, 2022, 6:00am UTC](https://discuss.elastic.co/t/is-it-possible-for-elasticsearch-to-integration-with-sophos-and-watchguard-firewall/315518 "2022-09-30T06:00:06Z")

</div>

Hello everyone, I am working on a project "Elastic integration with sophis and watchguard firewall". And i am very confuse about how the logs will come to the elastic. Can someone guide me to this???

---

## [Unable to retrieve version information from Elasticsearch nodes. unable to get issuer certificate Unable to retrieve version information from Elasticsearch nodes. unable to get issuer certificate](https://discuss.elastic.co/t/unable-to-retrieve-version-information-from-elasticsearch-nodes-unable-to-get-issuer-certificate-unable-to-retrieve-version-information-from-elasticsearch-nodes-unable-to-get-issuer-certificate/316000)

<div class="topic-metadata">

**Author:** [@learningelastic](https://discuss.elastic.co/u/learningelastic)\
**Replies:** 8\
**Last updated:** [October 7, 2022, 8:41pm UTC](https://discuss.elastic.co/t/unable-to-retrieve-version-information-from-elasticsearch-nodes-unable-to-get-issuer-certificate-unable-to-retrieve-version-information-from-elasticsearch-nodes-unable-to-get-issuer-certificate/316000 "2022-10-07T20:41:43Z")

</div>

I'm trying to use ssl certificates created by Let's Encrypt for elasticsearch and kibana version 8.4. Kibana fails at start up with this error message: Unable to retrieve version information from Elasticsearch nodes. u…

---

## [How to create table by month grouped by year](https://discuss.elastic.co/t/how-to-create-table-by-month-grouped-by-year/316044)

<div class="topic-metadata">

**Author:** [@LucasTavernier](https://discuss.elastic.co/u/LucasTavernier)\
**Replies:** 1\
**Last updated:** [October 7, 2022, 7:39pm UTC](https://discuss.elastic.co/t/how-to-create-table-by-month-grouped-by-year/316044 "2022-10-07T19:39:44Z")

</div>

Hello everyone, i'm new in the ELK stack. I have to to make a table but it's really hard can you please help me. To help you understand what i have to do, i will explain my datas. I got bugs tickets with the id/name o…

---

## [After SAML Configuration, when we try to access we seeing below mentioned error We hit an authentication error. Please check your credentials and try again. If you still can't log in, contact your system administrator](https://discuss.elastic.co/t/after-saml-configuration-when-we-try-to-access-we-seeing-below-mentioned-error-we-hit-an-authentication-error-please-check-your-credentials-and-try-again-if-you-still-cant-log-in-contact-your-system-administrator/316090)

<div class="topic-metadata">

**Author:** [@Elastic\_User3](https://discuss.elastic.co/u/Elastic_User3)\
**Replies:** 1\
**Last updated:** [October 7, 2022, 4:30pm UTC](https://discuss.elastic.co/t/after-saml-configuration-when-we-try-to-access-we-seeing-below-mentioned-error-we-hit-an-authentication-error-please-check-your-credentials-and-try-again-if-you-still-cant-log-in-contact-your-system-administrator/316090 "2022-10-07T16:30:14Z")

</div>

Observed error : We hit an authentication error. Please check your credentials and try again. If you still can't log in, contact your system administrator.

---

## [Problem with geoip plugin and IP whitelist filtering](https://discuss.elastic.co/t/problem-with-geoip-plugin-and-ip-whitelist-filtering/316051)

<div class="topic-metadata">

**Author:** [@Lynow](https://discuss.elastic.co/u/Lynow)\
**Replies:** 2\
**Last updated:** [October 7, 2022, 4:46pm UTC](https://discuss.elastic.co/t/problem-with-geoip-plugin-and-ip-whitelist-filtering/316051 "2022-10-07T16:46:45Z")

</div>

Good morning ! I am using Logstash to fetch data by Wazuh (HIDS) and Suricata (NIDS). So I use the Geoip plugin to geolocate the IPs that connect to my server. My first problem is this: When I do a test by connecting …

---

## [Logstash pipeline.workers](https://discuss.elastic.co/t/logstash-pipeline-workers/316053)

<div class="topic-metadata">

**Author:** [@S-elk](https://discuss.elastic.co/u/S-elk)\
**Replies:** 1\
**Last updated:** [October 7, 2022, 4:31pm UTC](https://discuss.elastic.co/t/logstash-pipeline-workers/316053 "2022-10-07T16:31:47Z")

</div>

Hello! Currently we have our pipeline.yml without defined workers. We understand that we take by default the number of cpu cores of the machine. Should we define all in pipeline.worker: 1 ? How do we decide which work…

---

## [Remote\_addr showing 127.0.01](https://discuss.elastic.co/t/remote-addr-showing-127-0-01/315738)

<div class="topic-metadata">

**Author:** [@AkankshaSS](https://discuss.elastic.co/u/AkankshaSS)\
**Replies:** 21\
**Last updated:** [October 7, 2022, 4:20pm UTC](https://discuss.elastic.co/t/remote-addr-showing-127-0-01/315738 "2022-10-07T16:20:46Z")

</div>

Hi,I am able to see only 127.0.01 in http-x\_forwarded\_for.Can someone please help me what's the changes required.

---

## [Switch from Watchers to Rules and Connectors](https://discuss.elastic.co/t/switch-from-watchers-to-rules-and-connectors/316088)

<div class="topic-metadata">

**Author:** [@federica.forti](https://discuss.elastic.co/u/federica.forti)\
**Replies:** 0\
**Last updated:** [October 7, 2022, 2:05pm UTC](https://discuss.elastic.co/t/switch-from-watchers-to-rules-and-connectors/316088 "2022-10-07T14:05:40Z")

</div>

Hi, we would like to move from watchers to rules (Rule and connectors section). In particular, in the past, we have defined a watcher that performs the following queries / aggregations: { "query": { "bool": { …

---

## [Failed to create query: maxClauseCount is set to 1024](https://discuss.elastic.co/t/failed-to-create-query-maxclausecount-is-set-to-1024/316089)

<div class="topic-metadata">

**Author:** [@GuillermoDelaGala](https://discuss.elastic.co/u/GuillermoDelaGala)\
**Replies:** 1\
**Last updated:** [October 7, 2022, 2:51pm UTC](https://discuss.elastic.co/t/failed-to-create-query-maxclausecount-is-set-to-1024/316089 "2022-10-07T14:51:32Z")

</div>

Hi everyone, first of all, saying that I'm quite new with Elasticsearch. I was diving into other similar issues related with my problem, but none of the solutions worked for me. My code has a query which says: failed…

---

## [Aggregate whole groups when search machtes only a few items of that group](https://discuss.elastic.co/t/aggregate-whole-groups-when-search-machtes-only-a-few-items-of-that-group/316082)

<div class="topic-metadata">

**Author:** [@lanwin](https://discuss.elastic.co/u/lanwin)\
**Replies:** 0\
**Last updated:** [October 7, 2022, 1:30pm UTC](https://discuss.elastic.co/t/aggregate-whole-groups-when-search-machtes-only-a-few-items-of-that-group/316082 "2022-10-07T13:30:02Z")

</div>

Hi, i am looking for a solution of the following problem. I have 20 million "Item" objects. Each Item Object have a GroupId property where 1-5000 Items a grouped together. Each Item has some other properties we can use …

---

## [Cluster state has not been recovered yet, cannot write to the \[null\] index](https://discuss.elastic.co/t/cluster-state-has-not-been-recovered-yet-cannot-write-to-the-null-index/315945)

<div class="topic-metadata">

**Author:** [@iLucas.Bechlte.exe](https://discuss.elastic.co/u/iLucas.Bechlte.exe)\
**Replies:** 1\
**Last updated:** [October 7, 2022, 1:00pm UTC](https://discuss.elastic.co/t/cluster-state-has-not-been-recovered-yet-cannot-write-to-the-null-index/315945 "2022-10-07T13:00:24Z")

</div>

Hi, i try to run an elastic stack with the localhost as the only node. I followed the official installation guide, but when I get to the running check it shows me this error after entering the password: {"error":{"root…

---

## [Multi-node backup and restore to GCS bucket](https://discuss.elastic.co/t/multi-node-backup-and-restore-to-gcs-bucket/316064)

<div class="topic-metadata">

**Author:** [@mohan\_s\_b](https://discuss.elastic.co/u/mohan_s_b)\
**Replies:** 0\
**Last updated:** [October 7, 2022, 11:06am UTC](https://discuss.elastic.co/t/multi-node-backup-and-restore-to-gcs-bucket/316064 "2022-10-07T11:06:19Z")

</div>

Hi All, I have deployed multi-node elasticsearch cluster in kubernetes and i wanted to take backup and restore. Since i have multi nodes i am not sure where to install google plugins and to upload service account.

---

## [Rollup job date histogram bucket starts at 00.00 for day interval instead of current time](https://discuss.elastic.co/t/rollup-job-date-histogram-bucket-starts-at-00-00-for-day-interval-instead-of-current-time/316063)

<div class="topic-metadata">

**Author:** [@mikhatanu](https://discuss.elastic.co/u/mikhatanu)\
**Replies:** 0\
**Last updated:** [October 7, 2022, 11:05am UTC](https://discuss.elastic.co/t/rollup-job-date-histogram-bucket-starts-at-00-00-for-day-interval-instead-of-current-time/316063 "2022-10-07T11:05:45Z")

</div>

Hello, i tried using rollup job and set date histogram bucket to interval of 24h. After starting the job, creating data view, and viewing it in kibana, the interval starts at 24h from 7 october at 00.00 until yesterday a…

---

## [Вопрос по xml filter plugin](https://discuss.elastic.co/t/xml-filter-plugin/316058)

<div class="topic-metadata">

**Author:** [@Serhio](https://discuss.elastic.co/u/Serhio)\
**Replies:** 0\
**Last updated:** [October 7, 2022, 9:47am UTC](https://discuss.elastic.co/t/xml-filter-plugin/316058 "2022-10-07T09:47:56Z")

</div>

Добрый день, Использую plugins-filters-xml для придания данным красивого и удобочитаемого вида, но столкнулся с проблемой что при парсинге содержимое xml разбирается в эластике на огромную кучу полей (один xml тэг - одн…

---

## [Unable to create token getting below error as Failed to determine the health of the cluster](https://discuss.elastic.co/t/unable-to-create-token-getting-below-error-as-failed-to-determine-the-health-of-the-cluster/316039)

<div class="topic-metadata">

**Author:** [@RChan](https://discuss.elastic.co/u/RChan)\
**Replies:** 0\
**Last updated:** [October 7, 2022, 7:10am UTC](https://discuss.elastic.co/t/unable-to-create-token-getting-below-error-as-failed-to-determine-the-health-of-the-cluster/316039 "2022-10-07T07:10:53Z")

</div>

WARN org.elasticsearch.common.ssl.DiagnosticTrustManager - failed to establish trust with server at \[x.x.x.x\]; the server provided a certificate with subject name, fingerprint \[629616647bf0e539b0ca8f616b516df4a356f5af…

---

## [How to get value of API call for Elasticsearch keystore](https://discuss.elastic.co/t/how-to-get-value-of-api-call-for-elasticsearch-keystore/316032)

<div class="topic-metadata">

**Author:** [@Ronak\_Darji](https://discuss.elastic.co/u/Ronak_Darji)\
**Replies:** 0\
**Last updated:** [October 7, 2022, 5:48am UTC](https://discuss.elastic.co/t/how-to-get-value-of-api-call-for-elasticsearch-keystore/316032 "2022-10-07T05:48:33Z")

</div>

Curl -XPATCH {{hostname}}/api/v1/clusters/elasticsearch/{cluster\_id}/keystore -H "Authorization: ApiKey $ECE\_API\_KEY" In above Api call what is the hostname, cluster\_id and ECE\_API\_KEY value and from where can i get tho…

---

## [Geography failed](https://discuss.elastic.co/t/geography-failed/315944)

<div class="topic-metadata">

**Author:** [@Jimmy\_Escrich](https://discuss.elastic.co/u/Jimmy_Escrich)\
**Replies:** 7\
**Last updated:** [October 7, 2022, 5:46am UTC](https://discuss.elastic.co/t/geography-failed/315944 "2022-10-07T05:46:01Z")

</div>

Hi there, I have an issue with GeometricCollection. I have a field location\_geography configured at geo\_shape. I want to update my document and I have this error : failed to parse field \[location\_geography\] of type \[geo…

---

## [String comparison inside a update\_by\_query api script](https://discuss.elastic.co/t/string-comparison-inside-a-update-by-query-api-script/316024)

<div class="topic-metadata">

**Author:** [@djoobbani](https://discuss.elastic.co/u/djoobbani)\
**Replies:** 0\
**Last updated:** [October 7, 2022, 12:51am UTC](https://discuss.elastic.co/t/string-comparison-inside-a-update-by-query-api-script/316024 "2022-10-07T00:51:35Z")

</div>

I am performing a Update\_by\_query api and inside its script i need to do string comparison of two different parameteres, similar to how u would do it with intgers: So, i need to do something like this with string: str…

---

## [COMPOSITE NESTED AGGREGATIONS](https://discuss.elastic.co/t/composite-nested-aggregations/316013)

<div class="topic-metadata">

**Author:** [@Vinicius\_Serafim](https://discuss.elastic.co/u/Vinicius_Serafim)\
**Replies:** 0\
**Last updated:** [October 6, 2022, 9:42pm UTC](https://discuss.elastic.co/t/composite-nested-aggregations/316013 "2022-10-06T21:42:12Z")

</div>

Hi, i hope that someone can help me. Supose that i have the following mapping to my index: PUT test-index { "mappings": { "properties": { "nestedOBJField": { "type": "nested", "index": true…

---

## [Grok pattern for suricata/barnyard alert in COMPLETE mode](https://discuss.elastic.co/t/grok-pattern-for-suricata-barnyard-alert-in-complete-mode/316009)

<div class="topic-metadata">

**Author:** [@mvrk](https://discuss.elastic.co/u/mvrk)\
**Replies:** 2\
**Last updated:** [October 6, 2022, 9:12pm UTC](https://discuss.elastic.co/t/grok-pattern-for-suricata-barnyard-alert-in-complete-mode/316009 "2022-10-06T21:12:37Z")

</div>

Hi, I have my suricata in pfsense sending the alerts using barnyard in COMPLETE mode to my greylog server. Example message: | \[SNORTIDS\[ALERT\]: \[pfsense.local\] \] || 2022-10-06 19:13:55.186+001 2 \[1:2403344:77870\] ET C…

---

## [Make Single output call with multiple events](https://discuss.elastic.co/t/make-single-output-call-with-multiple-events/315808)

<div class="topic-metadata">

**Author:** [@LJ\_LongWing](https://discuss.elastic.co/u/LJ_LongWing)\
**Replies:** 7\
**Last updated:** [October 6, 2022, 9:11pm UTC](https://discuss.elastic.co/t/make-single-output-call-with-multiple-events/315808 "2022-10-06T21:11:42Z")

</div>

I've done a few days of searching but can't find what I'm looking for....the closest I've found is this topic (How to aggregate multiple events into single output) I'll state that I'm starting with a functional pipeline…

---

## [Uptades to template not being applied](https://discuss.elastic.co/t/uptades-to-template-not-being-applied/315606)

<div class="topic-metadata">

**Author:** [@somatusjn](https://discuss.elastic.co/u/somatusjn)\
**Replies:** 9\
**Last updated:** [October 6, 2022, 6:25pm UTC](https://discuss.elastic.co/t/uptades-to-template-not-being-applied/315606 "2022-10-06T18:25:41Z")

</div>

I'm getting an error when trying to post a document. The error I think is that the format I used for a date property is incorrect. I initially used YYYY-MM-DD'T'hh:mm:ssZ, but since then I have made like 10 calls to upda…

---

## [Invalid version of beats protocol integration with spring boot](https://discuss.elastic.co/t/invalid-version-of-beats-protocol-integration-with-spring-boot/315997)

<div class="topic-metadata">

**Author:** [@Nikolas1306](https://discuss.elastic.co/u/Nikolas1306)\
**Replies:** 0\
**Last updated:** [October 6, 2022, 5:31pm UTC](https://discuss.elastic.co/t/invalid-version-of-beats-protocol-integration-with-spring-boot/315997 "2022-10-06T17:31:09Z")

</div>

i used a test with integrated log with spring-boot and logstash this is xml configuration \<?xml version="1.0" encoding="UTF-8"?\> \<configuration debug="true"\> \<include resource="org/springframework/boot/logging/logb…

---

## [Structure of document affect speed?](https://discuss.elastic.co/t/structure-of-document-affect-speed/315897)

<div class="topic-metadata">

**Author:** [@MaVa](https://discuss.elastic.co/u/MaVa)\
**Replies:** 1\
**Last updated:** [October 6, 2022, 4:23pm UTC](https://discuss.elastic.co/t/structure-of-document-affect-speed/315897 "2022-10-06T16:23:10Z")

</div>

I have a question out of curiosity. Does the structure of the document have any effect on the indexing and searching speed in an index? Would e.g. "user": { "id":"123", "first\_name":"John", "last\_n…

[Previous page](https://discuss.elastic.co/tag/none.md?no_tags=true&page=521)

[Next page](https://discuss.elastic.co/tag/none.md?no_tags=true&page=523)
