# \#none

**URL:** https://discuss.elastic.co/tag/none.md?no_tags=true&page=523

[Latest](https://discuss.elastic.co/latest.md) · [Categories](https://discuss.elastic.co/categories.md) · [Tags](https://discuss.elastic.co/tags.md)

**Page:** 524

---

## [How to grok first line from an XML format](https://discuss.elastic.co/t/how-to-grok-first-line-from-an-xml-format/315877)

<div class="topic-metadata">

**Author:** [@anupvtr](https://discuss.elastic.co/u/anupvtr)\
**Replies:** 1\
**Last updated:** [October 6, 2022, 4:19pm UTC](https://discuss.elastic.co/t/how-to-grok-first-line-from-an-xml-format/315877 "2022-10-06T16:19:04Z")

</div>

Hi All, I am quite new to the magic world of Grok. Any help will be thankful. I need to apply filter for the following file. 2022-08-22 22:18:59 , 666 INFO @ (blockurcolumn-11) \[rbbit\_MQ\_Versa.appache 75\] start col…

---

## [Kibana data table representaion](https://discuss.elastic.co/t/kibana-data-table-representaion/315988)

<div class="topic-metadata">

**Author:** [@PRASHANT\_MEHTA](https://discuss.elastic.co/u/PRASHANT_MEHTA)\
**Replies:** 1\
**Last updated:** [October 6, 2022, 3:22pm UTC](https://discuss.elastic.co/t/kibana-data-table-representaion/315988 "2022-10-06T15:22:40Z")

</div>

Hello All, I would like to dispaly the data as its shown below table. How can this be achieved best in kibana using enhanced/data table ? Here the challenge is the date fields are dynamice.Would have been only date fi…

---

## [Document enrichment via ingest pipeline or Indicator Match rule - which is preferable?](https://discuss.elastic.co/t/document-enrichment-via-ingest-pipeline-or-indicator-match-rule-which-is-preferable/315830)

<div class="topic-metadata">

**Author:** [@kossde](https://discuss.elastic.co/u/kossde)\
**Replies:** 1\
**Last updated:** [October 6, 2022, 3:15pm UTC](https://discuss.elastic.co/t/document-enrichment-via-ingest-pipeline-or-indicator-match-rule-which-is-preferable/315830 "2022-10-06T15:15:29Z")

</div>

Our elastic cluster is being used as a SIEM and is currently ingesting approximately 3x the data than originally scoped to ingest. It's working pretty hard. We have recently begun ingesting a MISP for enrichment and al…

---

## [Sending alerts via email](https://discuss.elastic.co/t/sending-alerts-via-email/315870)

<div class="topic-metadata">

**Author:** [@domw](https://discuss.elastic.co/u/domw)\
**Replies:** 1\
**Last updated:** [October 6, 2022, 3:06pm UTC](https://discuss.elastic.co/t/sending-alerts-via-email/315870 "2022-10-06T15:06:22Z")

</div>

Hello, I am hoping there is a way via email to notify on how many alerts we are receiving. And is there a way to have a report sent out periodically on how many alerts were received within a time frame? Thank you!

---

## [Remove backslash from xml log](https://discuss.elastic.co/t/remove-backslash-from-xml-log/315891)

<div class="topic-metadata">

**Author:** [@Jathurshan\_Sumandira](https://discuss.elastic.co/u/Jathurshan_Sumandira)\
**Replies:** 4\
**Last updated:** [October 6, 2022, 12:32pm UTC](https://discuss.elastic.co/t/remove-backslash-from-xml-log/315891 "2022-10-06T12:32:39Z")

</div>

\<soap-env:envelope xmlns:soap-env=\\"........ \\" xmlns:m2=\\".... \\".........................\</soap-env:envelope\> I wanted to remove the backslashs ("\\") in above xml log-line and I have tried ruby { code =\> ' d= event.…

---

## [Can't connect to Elasticsearch at \<Publicip\>:9200 - Logs don't show any errors](https://discuss.elastic.co/t/cant-connect-to-elasticsearch-at-publicip-9200-logs-dont-show-any-errors/315920)

<div class="topic-metadata">

**Author:** [@Chma](https://discuss.elastic.co/u/Chma)\
**Replies:** 12\
**Last updated:** [October 6, 2022, 1:53pm UTC](https://discuss.elastic.co/t/cant-connect-to-elasticsearch-at-publicip-9200-logs-dont-show-any-errors/315920 "2022-10-06T13:53:02Z")

</div>

This worked, thanks. I am running into a different issue. Elasticsearch status says it's active, but I can't connect at http://:9200. My elasticsearch logs doesn't show any issue. This is the yaml file which was working…

---

## [Elasticsearch Upgrade JVM Error](https://discuss.elastic.co/t/elasticsearch-upgrade-jvm-error/315928)

<div class="topic-metadata">

**Author:** [@wwalker](https://discuss.elastic.co/u/wwalker)\
**Replies:** 0\
**Last updated:** [October 6, 2022, 3:31am UTC](https://discuss.elastic.co/t/elasticsearch-upgrade-jvm-error/315928 "2022-10-06T03:31:38Z")

</div>

Trying to upgrade Elasticsearch from 8.2 to 8.4.3 running on Windows. I copied the config folder from the old version to the new one, adjusted file paths in elasticsearch.yml, deleted the old service, then ran elasticse…

---

## [Kibana Visualization: need a solution to get range(average(utilization), min, max)](https://discuss.elastic.co/t/kibana-visualization-need-a-solution-to-get-range-average-utilization-min-max/315955)

<div class="topic-metadata">

**Author:** [@Lakshmi\_Narayana\_Red](https://discuss.elastic.co/u/Lakshmi_Narayana_Red)\
**Replies:** 3\
**Last updated:** [October 6, 2022, 2:00pm UTC](https://discuss.elastic.co/t/kibana-visualization-need-a-solution-to-get-range-average-utilization-min-max/315955 "2022-10-06T14:00:34Z")

</div>

Hi Friends, We have a list of machines with and it's data like date, names, and utilization as mentioned below: date machine\_name utilization 01-10-2022 machine\_a 10 01-10-2022 machine\_b 5 01-10-2022 mach…

---

## [Azure Vnet / NSG Flow Logs](https://discuss.elastic.co/t/azure-vnet-nsg-flow-logs/315957)

<div class="topic-metadata">

**Author:** [@Chandrapaul](https://discuss.elastic.co/u/Chandrapaul)\
**Replies:** 1\
**Last updated:** [October 6, 2022, 12:21pm UTC](https://discuss.elastic.co/t/azure-vnet-nsg-flow-logs/315957 "2022-10-06T12:21:45Z")

</div>

How to ingest Azure VNet / NSG flow logs into elasticsearch ?

---

## [ElasticSearch 2-out-of-4 Master Replica goes down](https://discuss.elastic.co/t/elasticsearch-2-out-of-4-master-replica-goes-down/315840)

<div class="topic-metadata">

**Author:** [@roybalderama](https://discuss.elastic.co/u/roybalderama)\
**Replies:** 7\
**Last updated:** [October 6, 2022, 12:18pm UTC](https://discuss.elastic.co/t/elasticsearch-2-out-of-4-master-replica-goes-down/315840 "2022-10-06T12:18:52Z")

</div>

Hi, We bootstraped ELK Stack (in kubernetes using helm) to collect all the audit and application logs of the system. This has been running for almost a year now, and we were able to achieve the high-availability using t…

---

## [How to pass pagination to java scroll api](https://discuss.elastic.co/t/how-to-pass-pagination-to-java-scroll-api/315965)

<div class="topic-metadata">

**Author:** [@mahfuj\_asif](https://discuss.elastic.co/u/mahfuj_asif)\
**Replies:** 0\
**Last updated:** [October 6, 2022, 12:10pm UTC](https://discuss.elastic.co/t/how-to-pass-pagination-to-java-scroll-api/315965 "2022-10-06T12:10:40Z")

</div>

I am trying to fetch all data from elastic index with scroll id. SearchQuery searchQuery = new NativeSearchQueryBuilder() .withIndices(ELASTIC\_INDEX) .withTypes(DOC\_TYPE) …

---

## [Disabling a monitor doesn't actually disable it](https://discuss.elastic.co/t/disabling-a-monitor-doesnt-actually-disable-it/315936)

<div class="topic-metadata">

**Author:** [@woodywoodsta](https://discuss.elastic.co/u/woodywoodsta)\
**Replies:** 2\
**Last updated:** [October 6, 2022, 10:46am UTC](https://discuss.elastic.co/t/disabling-a-monitor-doesnt-actually-disable-it/315936 "2022-10-06T10:46:34Z")

</div>

Hey! I've got a couple of monitors disabled via the Monitor Management screen, but the monitors continue to run. Is this a known issue? My monitors are executed on fleet managed elastic agents via Kubernetes. I've tried…

---

## [Need to disable idle indices in logstash config](https://discuss.elastic.co/t/need-to-disable-idle-indices-in-logstash-config/315942)

<div class="topic-metadata">

**Author:** [@yasar](https://discuss.elastic.co/u/yasar)\
**Replies:** 0\
**Last updated:** [October 6, 2022, 8:53am UTC](https://discuss.elastic.co/t/need-to-disable-idle-indices-in-logstash-config/315942 "2022-10-06T08:53:33Z")

</div>

Hi team, In our TEST Environment, N number of indices are idle in position. Those are unwantedly roll back over itself. Could you giude us, what are the procedure to disable the unwanted indices in logstash config or s…

---

## [Sending logs to a previously created index using Custom Logs integration](https://discuss.elastic.co/t/sending-logs-to-a-previously-created-index-using-custom-logs-integration/315948)

<div class="topic-metadata">

**Author:** [@RP5](https://discuss.elastic.co/u/RP5)\
**Replies:** 0\
**Last updated:** [October 6, 2022, 9:24am UTC](https://discuss.elastic.co/t/sending-logs-to-a-previously-created-index-using-custom-logs-integration/315948 "2022-10-06T09:24:10Z")

</div>

I was using filebeat to send data to an index that I had created. (say indextest) Can I send data to the above index (indextest) using Elastic Agent Custom Logs Integration? Thank you

---

## [Logstasg ERROR filewatch.tailmode.handlers.grow](https://discuss.elastic.co/t/logstasg-error-filewatch-tailmode-handlers-grow/315550)

<div class="topic-metadata">

**Author:** [@alex\_96](https://discuss.elastic.co/u/alex_96)\
**Replies:** 4\
**Last updated:** [October 6, 2022, 8:12am UTC](https://discuss.elastic.co/t/logstasg-error-filewatch-tailmode-handlers-grow/315550 "2022-10-06T08:12:57Z")

</div>

Hi, set up reading mysql logs from nfs using multiline codec and grok filter The first problem is that it doesn’t read the file after rotation, restarting doesn’t help, it still doesn’t seem to see it, there was an erro…

---

## [Is it possible to install multiple Fleet Servers?](https://discuss.elastic.co/t/is-it-possible-to-install-multiple-fleet-servers/315744)

<div class="topic-metadata">

**Author:** [@sirineb](https://discuss.elastic.co/u/sirineb)\
**Replies:** 4\
**Last updated:** [October 6, 2022, 7:15am UTC](https://discuss.elastic.co/t/is-it-possible-to-install-multiple-fleet-servers/315744 "2022-10-06T07:15:03Z")

</div>

Hi everyone, I was wondering, is it possible to install multiple Fleet Servers connected to the same ES ? I explain myself, I already have a Fleet Server installed but there might be a lot more Elastic agents than now …

---

## [Logstash health check failing for TG](https://discuss.elastic.co/t/logstash-health-check-failing-for-tg/315541)

<div class="topic-metadata">

**Author:** [@sandeepbisht](https://discuss.elastic.co/u/sandeepbisht)\
**Replies:** 1\
**Last updated:** [October 6, 2022, 7:04am UTC](https://discuss.elastic.co/t/logstash-health-check-failing-for-tg/315541 "2022-10-06T07:04:02Z")

</div>

Hi All, I had one logstash ec2 ubuntu machine, Due to frequent load issue i have added one more logstash machine and put both machines behind AWS ALB. Now both my instances are unhealthy under TG and i am not sure what…

---

## [Order legend items](https://discuss.elastic.co/t/order-legend-items/314168)

<div class="topic-metadata">

**Author:** [@fabrizio1979](https://discuss.elastic.co/u/fabrizio1979)\
**Replies:** 2\
**Last updated:** [October 6, 2022, 5:57am UTC](https://discuss.elastic.co/t/order-legend-items/314168 "2022-10-06T05:57:51Z")

</div>

Hi there, How to order the legend items displayed on graphs? I used graphs. I would like legend items ordered as A1 A2 B1 B2 Thanks

---

## [Logstash service is not started in linux](https://discuss.elastic.co/t/logstash-service-is-not-started-in-linux/315802)

<div class="topic-metadata">

**Author:** [@Jathurshan\_Sumandira](https://discuss.elastic.co/u/Jathurshan_Sumandira)\
**Replies:** 3\
**Last updated:** [October 6, 2022, 5:11am UTC](https://discuss.elastic.co/t/logstash-service-is-not-started-in-linux/315802 "2022-10-06T05:11:49Z")

</div>

Hi, I am beginner to ELK stack and I am working on Linux server, I could try to start the logstash service but the service does not start and I could not see any logs in the command line(empty). Even though the permissio…

---

## [Get a mapping/schema of flattened field](https://discuss.elastic.co/t/get-a-mapping-schema-of-flattened-field/315919)

<div class="topic-metadata">

**Author:** [@getorca](https://discuss.elastic.co/u/getorca)\
**Replies:** 2\
**Last updated:** [October 6, 2022, 4:10am UTC](https://discuss.elastic.co/t/get-a-mapping-schema-of-flattened-field/315919 "2022-10-06T04:10:46Z")

</div>

Is there a way to get a mapping or schema of all the sub-fields that exist in my flattened field?

---

## [Constant\_scores w/ boost upon matching properties within nested](https://discuss.elastic.co/t/constant-scores-w-boost-upon-matching-properties-within-nested/315930)

<div class="topic-metadata">

**Author:** [@Paul\_Kim](https://discuss.elastic.co/u/Paul_Kim)\
**Replies:** 0\
**Last updated:** [October 6, 2022, 4:14am UTC](https://discuss.elastic.co/t/constant-scores-w-boost-upon-matching-properties-within-nested/315930 "2022-10-06T04:14:17Z")

</div>

I have below as my mapping for some\_index. { "some\_index": "properties": { "people": { "type": "nested", "properties": { "name": { "type": "keyword" …

---

## [Logstash fails to fetch Configuration](https://discuss.elastic.co/t/logstash-fails-to-fetch-configuration/315915)

<div class="topic-metadata">

**Author:** [@Chma](https://discuss.elastic.co/u/Chma)\
**Replies:** 6\
**Last updated:** [October 6, 2022, 1:32am UTC](https://discuss.elastic.co/t/logstash-fails-to-fetch-configuration/315915 "2022-10-06T01:32:40Z")

</div>

My logstash isn't starting. When I check the logs, I see these: Could not fetch all the sources {:exception=\>Errno::EACCES, :message=\>"Permission denied - /etc/logstash/conf.d/log.conf", :backtrace=\>\["org/jruby/RubyIO.j…

---

## [What does the host refer to when configuring APM integration?](https://discuss.elastic.co/t/what-does-the-host-refer-to-when-configuring-apm-integration/315922)

<div class="topic-metadata">

**Author:** [@pedroaugusto](https://discuss.elastic.co/u/pedroaugusto)\
**Replies:** 0\
**Last updated:** [October 6, 2022, 12:29am UTC](https://discuss.elastic.co/t/what-does-the-host-refer-to-when-configuring-apm-integration/315922 "2022-10-06T00:29:09Z")

</div>

Hello! I'm configuring the APM Integration and I have a question. In General -\> Server Configuration. What's the host? Is Kibana's host? Or Elastic's host? Or APM Server's host? Or the host of the application that A…

---

## ["match-boolean-query doesn't return the "exact match word" of the query](https://discuss.elastic.co/t/match-boolean-query-doesnt-return-the-exact-match-word-of-the-query/315918)

<div class="topic-metadata">

**Author:** [@paris1](https://discuss.elastic.co/u/paris1)\
**Replies:** 0\
**Last updated:** [October 5, 2022, 11:54pm UTC](https://discuss.elastic.co/t/match-boolean-query-doesnt-return-the-exact-match-word-of-the-query/315918 "2022-10-05T23:54:18Z")

</div>

I'm using "match-Boolean-prefix query but I can't get the exact match of the query.I can't use prefix queries because I also need "not exact match" results and I also need the fuzziness and word completion.I get every th…

---

## [Exclude multiple patterns in logstash s3 input](https://discuss.elastic.co/t/exclude-multiple-patterns-in-logstash-s3-input/315917)

<div class="topic-metadata">

**Author:** [@Elias\_Ojeda](https://discuss.elastic.co/u/Elias_Ojeda)\
**Replies:** 1\
**Last updated:** [October 5, 2022, 11:55pm UTC](https://discuss.elastic.co/t/exclude-multiple-patterns-in-logstash-s3-input/315917 "2022-10-05T23:55:59Z")

</div>

Logstash S3 input has an option to exclude a pattern. The example shows how to exclude a single pattern. For example: "exclude\_pattern" =\> "/2020/04/" Is it possible to exclude multiple patterns? For example, exclude…

---

## [Filter unique value fron url field](https://discuss.elastic.co/t/filter-unique-value-fron-url-field/314378)

<div class="topic-metadata">

**Author:** [@Vivek\_Nigam](https://discuss.elastic.co/u/Vivek_Nigam)\
**Replies:** 5\
**Last updated:** [October 5, 2022, 8:41pm UTC](https://discuss.elastic.co/t/filter-unique-value-fron-url-field/314378 "2022-10-05T20:41:49Z")

</div>

I want to filer all unique device id from url message , is it possible?? please help url: "/v1/default/hls-ts-fk/vodm/f452aa15-87ca-5013-856e-b0758db7c3d5/default\_ott.m3u8?PID=testing.30d&PAID=TITL0000000000391111&devic…

---

## [Kibana dashboard table view results in "Aborted"](https://discuss.elastic.co/t/kibana-dashboard-table-view-results-in-aborted/313065)

<div class="topic-metadata">

**Author:** [@matled](https://discuss.elastic.co/u/matled)\
**Replies:** 2\
**Last updated:** [October 5, 2022, 8:40pm UTC](https://discuss.elastic.co/t/kibana-dashboard-table-view-results-in-aborted/313065 "2022-10-05T20:40:37Z")

</div>

Currently we have a large Dashboard displaying multiple visualizations. However, since 8.4.0 we encounter on the following message on two table views in Kibana. I'm not sure if it is a problem with a timeout or response …

---

## [Unable to view winlogbeat log data](https://discuss.elastic.co/t/unable-to-view-winlogbeat-log-data/315910)

<div class="topic-metadata">

**Author:** [@tyc-4](https://discuss.elastic.co/u/tyc-4)\
**Replies:** 0\
**Last updated:** [October 5, 2022, 7:58pm UTC](https://discuss.elastic.co/t/unable-to-view-winlogbeat-log-data/315910 "2022-10-05T19:58:26Z")

</div>

I tried to send logs using winlogbeat to a self hosted ELK stack but I am unable to view any information other than the \_id and \_index. How do I fix this?

---

## [Count of files in sincedb and file\_completed\_log\_path](https://discuss.elastic.co/t/count-of-files-in-sincedb-and-file-completed-log-path/315907)

<div class="topic-metadata">

**Author:** [@INS](https://discuss.elastic.co/u/INS)\
**Replies:** 3\
**Last updated:** [October 5, 2022, 7:07pm UTC](https://discuss.elastic.co/t/count-of-files-in-sincedb-and-file-completed-log-path/315907 "2022-10-05T19:07:09Z")

</div>

Hi Can You explain why I have a so much difference in count of particular daily file in sincedb and file\_complete\_log\_path. It seems that sincedb does not reflect the actual number of reprocessed files, hence there are n…

---

## [Null terminated message string](https://discuss.elastic.co/t/null-terminated-message-string/315905)

<div class="topic-metadata">

**Author:** [@LisaJ](https://discuss.elastic.co/u/LisaJ)\
**Replies:** 2\
**Last updated:** [October 5, 2022, 6:59pm UTC](https://discuss.elastic.co/t/null-terminated-message-string/315905 "2022-10-05T18:59:57Z")

</div>

I have a syslog message that contains a null terminated string: "syslog\_message":"A10\\u0000" -- these messages represent is-alive checks from a load balancer to the logstash servers. I would prefer not to have thousands …

[Previous page](https://discuss.elastic.co/tag/none.md?no_tags=true&page=522)

[Next page](https://discuss.elastic.co/tag/none.md?no_tags=true&page=524)
