# \#none

**URL:** https://discuss.elastic.co/tag/none.md?no_tags=true&page=525

[Latest](https://discuss.elastic.co/latest.md) · [Categories](https://discuss.elastic.co/categories.md) · [Tags](https://discuss.elastic.co/tags.md)

**Page:** 526

---

## [Mutate convert multiple fields at once](https://discuss.elastic.co/t/mutate-convert-multiple-fields-at-once/315730)

<div class="topic-metadata">

**Author:** [@mikhatanu](https://discuss.elastic.co/u/mikhatanu)\
**Replies:** 1\
**Last updated:** [October 4, 2022, 3:09pm UTC](https://discuss.elastic.co/t/mutate-convert-multiple-fields-at-once/315730 "2022-10-04T15:09:58Z")

</div>

Hello, can i mutate convert multiple fields to a data type at once, without putting it one by one? something like: filter{ mutate{ convert(\["someField1","someField2","someField3"\] =\> "integer") } } I have a lar…

---

## [Shipping Logs out of Elasticsearch](https://discuss.elastic.co/t/shipping-logs-out-of-elasticsearch/315786)

<div class="topic-metadata">

**Author:** [@secopsgeek](https://discuss.elastic.co/u/secopsgeek)\
**Replies:** 4\
**Last updated:** [October 4, 2022, 3:09pm UTC](https://discuss.elastic.co/t/shipping-logs-out-of-elasticsearch/315786 "2022-10-04T15:09:06Z")

</div>

Morning, I am trying to figure out a way to ship my elasticseach logs from one location to another syslog system. Is there a way for me to configure Elastic to handle shipping out a certain Index of log to another syslo…

---

## [Handling unmapped fields with Suggest feature](https://discuss.elastic.co/t/handling-unmapped-fields-with-suggest-feature/314937)

<div class="topic-metadata">

**Author:** [@schawla](https://discuss.elastic.co/u/schawla)\
**Replies:** 3\
**Last updated:** [October 4, 2022, 2:36pm UTC](https://discuss.elastic.co/t/handling-unmapped-fields-with-suggest-feature/314937 "2022-10-04T14:36:45Z")

</div>

I am trying to implement suggest feature - Suggest Usage | Elasticsearch .NET Client \[8.4\] | Elastic for handling misspelled words in my search implementation. My search query is executed across multiple indices but whi…

---

## [Sql query with like in "elasticSearch Sql" bugs?](https://discuss.elastic.co/t/sql-query-with-like-in-elasticsearch-sql-bugs/315621)

<div class="topic-metadata">

**Author:** [@Nikolas1306](https://discuss.elastic.co/u/Nikolas1306)\
**Replies:** 17\
**Last updated:** [October 4, 2022, 2:22pm UTC](https://discuss.elastic.co/t/sql-query-with-like-in-elasticsearch-sql-bugs/315621 "2022-10-04T14:22:41Z")

</div>

i' ve simple query but not have resulset with SELECT \* FROM "errors\_prima\*" where message like '%fiscal%' (sorry is closed on test not is the problem) but if use SELECT \* FROM "errors\_prima\*" where message like '%…

---

## [Using scroll for very large indices](https://discuss.elastic.co/t/using-scroll-for-very-large-indices/315776)

<div class="topic-metadata">

**Author:** [@SFarhanizade](https://discuss.elastic.co/u/SFarhanizade)\
**Replies:** 0\
**Last updated:** [October 4, 2022, 1:20pm UTC](https://discuss.elastic.co/t/using-scroll-for-very-large-indices/315776 "2022-10-04T13:20:25Z")

</div>

Hi. There is an index having arround 200 million documents. I want to scroll over all its documents, so I prefered to use sliced scroll to do so, but every time I use scroll for this index, after some minutes of getting …

---

## [Metricbeat showing failure](https://discuss.elastic.co/t/metricbeat-showing-failure/315203)

<div class="topic-metadata">

**Author:** [@Akaren](https://discuss.elastic.co/u/Akaren)\
**Replies:** 1\
**Last updated:** [October 4, 2022, 12:35pm UTC](https://discuss.elastic.co/t/metricbeat-showing-failure/315203 "2022-10-04T12:35:36Z")

</div>

Hi, I started playing with metricbeat. I set logstash module module: logstash #metricsets: - node - node\_stats period: 30s hosts: \["localhost:9600"\] and it works, output is ES index. When I get last event it shows…

---

## [Elasticsearch cluster \[6.8\] becomes unresponsive for a small duration when one of the nodes in the cluster does not respond to any requests & is not part of the cluster. Is this the expected behaviour?](https://discuss.elastic.co/t/elasticsearch-cluster-6-8-becomes-unresponsive-for-a-small-duration-when-one-of-the-nodes-in-the-cluster-does-not-respond-to-any-requests-is-not-part-of-the-cluster-is-this-the-expected-behaviour/315421)

<div class="topic-metadata">

**Author:** [@srivatsa](https://discuss.elastic.co/u/srivatsa)\
**Replies:** 4\
**Last updated:** [October 4, 2022, 11:54am UTC](https://discuss.elastic.co/t/elasticsearch-cluster-6-8-becomes-unresponsive-for-a-small-duration-when-one-of-the-nodes-in-the-cluster-does-not-respond-to-any-requests-is-not-part-of-the-cluster-is-this-the-expected-behaviour/315421 "2022-10-04T11:54:19Z")

</div>

Hi Folks, The observation in our ES cluster (6.8 version) consisting of 40 nodes is that when any one of the nodes becomes unresponsive, especially in scenarios where the thread pools on the machine are full & rejection…

---

## [Filter first match only using Grok or ruby code](https://discuss.elastic.co/t/filter-first-match-only-using-grok-or-ruby-code/315758)

<div class="topic-metadata">

**Author:** [@rootk1d](https://discuss.elastic.co/u/rootk1d)\
**Replies:** 1\
**Last updated:** [October 4, 2022, 11:52am UTC](https://discuss.elastic.co/t/filter-first-match-only-using-grok-or-ruby-code/315758 "2022-10-04T11:52:44Z")

</div>

I have a field that contains the following data "REQUEST-941-APPLICATION-ATTACK-XSS, REQUEST-941-APPLICATION-ATTACK-XSS, REQUEST-941-APPLICATION-ATTACK-XSS, REQUEST-942-APPLICATION-ATTACK-SQLI, REQUEST-949-BLOCKING-EVAL…

---

## [Help on getting query to count avg, min and max nestings](https://discuss.elastic.co/t/help-on-getting-query-to-count-avg-min-and-max-nestings/315768)

<div class="topic-metadata">

**Author:** [@sreekanth](https://discuss.elastic.co/u/sreekanth)\
**Replies:** 0\
**Last updated:** [October 4, 2022, 11:10am UTC](https://discuss.elastic.co/t/help-on-getting-query-to-count-avg-min-and-max-nestings/315768 "2022-10-04T11:10:04Z")

</div>

I have an index with one nested field. Some docs have 10 nested docs and a few may have thousands of nested docs. I want to find the average/min and max count of nested items count across the index. Sample data: in thi…

---

## [Logstash Cloudwatch Input Plugin](https://discuss.elastic.co/t/logstash-cloudwatch-input-plugin/314694)

<div class="topic-metadata">

**Author:** [@connectgeeks](https://discuss.elastic.co/u/connectgeeks)\
**Replies:** 2\
**Last updated:** [October 4, 2022, 11:09am UTC](https://discuss.elastic.co/t/logstash-cloudwatch-input-plugin/314694 "2022-10-04T11:09:23Z")

</div>

Hi I'm using input cloudwatch plugin for aws cloudwatch ingestion using logstash. I want to reingest the entire data now. How can I achieve that ? Also, where (path) logstash keeps the registry file to maintain the seq…

---

## [Helm chart - logstash elasticsearch connection configuration?](https://discuss.elastic.co/t/helm-chart-logstash-elasticsearch-connection-configuration/315756)

<div class="topic-metadata">

**Author:** [@tirelibirefe](https://discuss.elastic.co/u/tirelibirefe)\
**Replies:** 0\
**Last updated:** [October 4, 2022, 9:34am UTC](https://discuss.elastic.co/t/helm-chart-logstash-elasticsearch-connection-configuration/315756 "2022-10-04T09:34:01Z")

</div>

Hello, I installed Logstash by using Helm Chart here and need to configure Elasticsearch connection. I looked for documentation but couldn't have found... How can I configure elasticsearch connection? Thanks & Regar…

---

## [Sort performance since elastic 7.16](https://discuss.elastic.co/t/sort-performance-since-elastic-7-16/315740)

<div class="topic-metadata">

**Author:** [@vjgorla](https://discuss.elastic.co/u/vjgorla)\
**Replies:** 0\
**Last updated:** [October 4, 2022, 6:51am UTC](https://discuss.elastic.co/t/sort-performance-since-elastic-7-16/315740 "2022-10-04T06:51:43Z")

</div>

A query that sorts by a keyword field that we have been using on elastic 7.13.2 now performs quite badly on 8.4.1. There is no change to the query or mappings. Only change is the elastic version. This query is crucial i…

---

## [Data management](https://discuss.elastic.co/t/data-management/315371)

<div class="topic-metadata">

**Author:** [@Juanfer](https://discuss.elastic.co/u/Juanfer)\
**Replies:** 2\
**Last updated:** [October 4, 2022, 8:27am UTC](https://discuss.elastic.co/t/data-management/315371 "2022-10-04T08:27:12Z")

</div>

Hi there, I have a question regarding the organization in Kibana. Since I am a beginner I want to understand the scope and best practices for my data storage in there. I will have 3 datasets which at some point I will li…

---

## [Elasticsearch Group By](https://discuss.elastic.co/t/elasticsearch-group-by/315360)

<div class="topic-metadata">

**Author:** [@Ashish\_Grover](https://discuss.elastic.co/u/Ashish_Grover)\
**Replies:** 4\
**Last updated:** [October 4, 2022, 7:48am UTC](https://discuss.elastic.co/t/elasticsearch-group-by/315360 "2022-10-04T07:48:19Z")

</div>

Hi i want to convert this sql query to elasticsearch " Select field1,field2,field3,field4 From myTable Group By field1; " I want group by on field1 and on the basis of this i want field2, field3, and field4

---

## [Date diff elasticsearch wrong?](https://discuss.elastic.co/t/date-diff-elasticsearch-wrong/315745)

<div class="topic-metadata">

**Author:** [@robocon20x](https://discuss.elastic.co/u/robocon20x)\
**Replies:** 0\
**Last updated:** [October 4, 2022, 7:18am UTC](https://discuss.elastic.co/t/date-diff-elasticsearch-wrong/315745 "2022-10-04T07:18:36Z")

</div>

Hi everyone, i found a different between datediff function on my ES and phoenix,trino. when use SQL below my ES return 4 while phoenix and trino return 5. How this different could happened? POST \_sql?format=json { …

---

## [Method with @async annotation, not getting logged in APM for errors for spring application](https://discuss.elastic.co/t/method-with-async-annotation-not-getting-logged-in-apm-for-errors-for-spring-application/315741)

<div class="topic-metadata">

**Author:** [@Jawed-Aquib](https://discuss.elastic.co/u/Jawed-Aquib)\
**Replies:** 1\
**Last updated:** [October 4, 2022, 7:00am UTC](https://discuss.elastic.co/t/method-with-async-annotation-not-getting-logged-in-apm-for-errors-for-spring-application/315741 "2022-10-04T07:00:52Z")

</div>

I have configured the java APM agent through the elastic.apm.service\_name config for my springboot application. When there is any error occurring for my method annotated with @Async the error form this isn't availble…

---

## [How does the GET API function internally in real time?](https://discuss.elastic.co/t/how-does-the-get-api-function-internally-in-real-time/315734)

<div class="topic-metadata">

**Author:** [@bhavya](https://discuss.elastic.co/u/bhavya)\
**Replies:** 0\
**Last updated:** [October 4, 2022, 5:54am UTC](https://discuss.elastic.co/t/how-does-the-get-api-function-internally-in-real-time/315734 "2022-10-04T05:54:46Z")

</div>

Under the hood of the most recent operation, Elasticsearch records the value of the \_version meta field, primary term, and sequence number. We may use the GET API to obtain these meta field values and add them to the sea…

---

## [Writing to two data streams](https://discuss.elastic.co/t/writing-to-two-data-streams/315493)

<div class="topic-metadata">

**Author:** [@Ulrik](https://discuss.elastic.co/u/Ulrik)\
**Replies:** 1\
**Last updated:** [October 4, 2022, 5:19am UTC](https://discuss.elastic.co/t/writing-to-two-data-streams/315493 "2022-10-04T05:19:02Z")

</div>

We are collecting logs and uses fleet with agents. I would like to configure some agents to write data in two data streams instead of just one. As far as I can understand you specify the data stream to use in the integ…

---

## [Problem with integration fleet server](https://discuss.elastic.co/t/problem-with-integration-fleet-server/315433)

<div class="topic-metadata">

**Author:** [@sultan2224](https://discuss.elastic.co/u/sultan2224)\
**Replies:** 1\
**Last updated:** [October 4, 2022, 5:13am UTC](https://discuss.elastic.co/t/problem-with-integration-fleet-server/315433 "2022-10-04T05:13:22Z")

</div>

problem with integration fleet server and I can't take logs

---

## [Monthly rolling index with custom routing](https://discuss.elastic.co/t/monthly-rolling-index-with-custom-routing/315706)

<div class="topic-metadata">

**Author:** [@PV2000](https://discuss.elastic.co/u/PV2000)\
**Replies:** 1\
**Last updated:** [October 4, 2022, 5:02am UTC](https://discuss.elastic.co/t/monthly-rolling-index-with-custom-routing/315706 "2022-10-04T05:02:55Z")

</div>

Hi, I am trying to figure out the how to create a monthly rolling index with custom routing (multi-tenancy scenario) , with these requirements : WRITE flow : Each document will have a timestamp and the document shoul…

---

## [Got error in elastic search](https://discuss.elastic.co/t/got-error-in-elastic-search/315718)

<div class="topic-metadata">

**Author:** [@Rahul1300](https://discuss.elastic.co/u/Rahul1300)\
**Replies:** 1\
**Last updated:** [October 4, 2022, 5:01am UTC](https://discuss.elastic.co/t/got-error-in-elastic-search/315718 "2022-10-04T05:01:09Z")

</div>

i started new cluster i got this error plz help me to resolve this address \[127.0.0.1:9302\], node \[null\], requesting \[false\] discovery result: \[127.0.0.1:9302\] connect\_exception: Connection refused: /127.0.0.1:9302: Con…

---

## [Primary term and sequence number VS \_version meta field](https://discuss.elastic.co/t/primary-term-and-sequence-number-vs-version-meta-field/315733)

<div class="topic-metadata">

**Author:** [@bhavya](https://discuss.elastic.co/u/bhavya)\
**Replies:** 1\
**Last updated:** [October 4, 2022, 4:58am UTC](https://discuss.elastic.co/t/primary-term-and-sequence-number-vs-version-meta-field/315733 "2022-10-04T04:58:50Z")

</div>

Consider that there are three primary shards in my index. For indexing and update requests, the primary shards are used. Elasticsearch can distribute incoming requests (such as massive bulk requests) to various primary s…

---

## [Nested Aggregation with AND always return 0 match](https://discuss.elastic.co/t/nested-aggregation-with-and-always-return-0-match/315722)

<div class="topic-metadata">

**Author:** [@chattes](https://discuss.elastic.co/u/chattes)\
**Replies:** 3\
**Last updated:** [October 4, 2022, 1:26am UTC](https://discuss.elastic.co/t/nested-aggregation-with-and-always-return-0-match/315722 "2022-10-04T01:26:03Z")

</div>

Mapping { "example-profiles" : { "mappings" : { "dynamic" : "false", "properties" : { "organization" : { "properties" : { "enabled" : { "type" : "boolean" …

---

## [Elastic SIEM cloud data storage location? Canadian Data Residency](https://discuss.elastic.co/t/elastic-siem-cloud-data-storage-location-canadian-data-residency/315712)

<div class="topic-metadata">

**Author:** [@DabLab](https://discuss.elastic.co/u/DabLab)\
**Replies:** 1\
**Last updated:** [October 3, 2022, 8:13pm UTC](https://discuss.elastic.co/t/elastic-siem-cloud-data-storage-location-canadian-data-residency/315712 "2022-10-03T20:13:37Z")

</div>

I need to know if Elastic meets Canadian Data Residency requirements. Meaning the solution for a canadian company would store its data in canada. Thank you!

---

## [Getting two intervals in the result for fixed\_interval](https://discuss.elastic.co/t/getting-two-intervals-in-the-result-for-fixed-interval/314754)

<div class="topic-metadata">

**Author:** [@Divin](https://discuss.elastic.co/u/Divin)\
**Replies:** 7\
**Last updated:** [October 3, 2022, 6:05pm UTC](https://discuss.elastic.co/t/getting-two-intervals-in-the-result-for-fixed-interval/314754 "2022-10-03T18:05:22Z")

</div>

I have an ES query that search for 2 set of strings and calculating percentage based on the results of the match. This is expected to have work on fixed\_interval \[5 min\]on date histogram. But when I am getting the result…

---

## [Upgrade from ELK 7.7.1 to ELK 8.4.1](https://discuss.elastic.co/t/upgrade-from-elk-7-7-1-to-elk-8-4-1/315423)

<div class="topic-metadata">

**Author:** [@Ravi\_S1](https://discuss.elastic.co/u/Ravi_S1)\
**Replies:** 3\
**Last updated:** [October 3, 2022, 5:46pm UTC](https://discuss.elastic.co/t/upgrade-from-elk-7-7-1-to-elk-8-4-1/315423 "2022-10-03T17:46:24Z")

</div>

I upgraded recently ELK 7.7.1 to ELK 8.4.1. I am looking out the logs of ELK 8.4.1, finds the below logs. Is there any view point from these logs. {"@timestamp":"2022-09-15T16:17:36.167Z", "log.level": "WARN", "message…

---

## [Update By Query - status counts do not add up to total](https://discuss.elastic.co/t/update-by-query-status-counts-do-not-add-up-to-total/315709)

<div class="topic-metadata">

**Author:** [@BobH](https://discuss.elastic.co/u/BobH)\
**Replies:** 0\
**Last updated:** [October 3, 2022, 5:15pm UTC](https://discuss.elastic.co/t/update-by-query-status-counts-do-not-add-up-to-total/315709 "2022-10-03T17:15:44Z")

</div>

I'm running ES 7.17.3 with an index with 2.1M documents. I executed an update-by-query request with a script to clean up some data (there was no query, so it ran against all documents in the index). The script sets ctx.o…

---

## [Engineer Lab Instructions](https://discuss.elastic.co/t/engineer-lab-instructions/315695)

<div class="topic-metadata">

**Author:** [@Sonia1](https://discuss.elastic.co/u/Sonia1)\
**Replies:** 1\
**Last updated:** [October 3, 2022, 5:00pm UTC](https://discuss.elastic.co/t/engineer-lab-instructions/315695 "2022-10-03T17:00:15Z")

</div>

Hi I have started the Elasticsearch Engineer on-demand, but my strigo access have expired. I wanted to set up my own lab, but i cant find the download link for the lab instructions. Can somebody help me? Thanks

---

## [CSV Filter - Backslash double quote parse failure](https://discuss.elastic.co/t/csv-filter-backslash-double-quote-parse-failure/315703)

<div class="topic-metadata">

**Author:** [@Michele\_De\_Benedet](https://discuss.elastic.co/u/Michele_De_Benedet)\
**Replies:** 1\
**Last updated:** [October 3, 2022, 4:54pm UTC](https://discuss.elastic.co/t/csv-filter-backslash-double-quote-parse-failure/315703 "2022-10-03T16:54:07Z")

</div>

Hi, I am using version 7.12.0 I'm parsing a csv which looks like this: colA;colB;colC x;"hello \\"world\\" ";0 y;"hello world";1 I cannot parse the x row because I get the following: Error parsing csv {:field=\>"messag…

---

## [Split the Field values by comma](https://discuss.elastic.co/t/split-the-field-values-by-comma/315673)

<div class="topic-metadata">

**Author:** [@Maruthappan\_Muthu](https://discuss.elastic.co/u/Maruthappan_Muthu)\
**Replies:** 1\
**Last updated:** [October 3, 2022, 4:06pm UTC](https://discuss.elastic.co/t/split-the-field-values-by-comma/315673 "2022-10-03T16:06:23Z")

</div>

My field contains multiple values, which separated by comma. How can I split the each comma separated values and put on the same filed name. Ex. The consider the below field and values, SerialNumber =\> \[abc23, cde56, …

[Previous page](https://discuss.elastic.co/tag/none.md?no_tags=true&page=524)

[Next page](https://discuss.elastic.co/tag/none.md?no_tags=true&page=526)
