# \#none

**URL:** https://discuss.elastic.co/tag/none.md?no_tags=true&page=534

[Latest](https://discuss.elastic.co/latest.md) · [Categories](https://discuss.elastic.co/categories.md) · [Tags](https://discuss.elastic.co/tags.md)

**Page:** 535

---

## [OpenTelemetry, Zipkin and Elastic APM](https://discuss.elastic.co/t/opentelemetry-zipkin-and-elastic-apm/314035)

<div class="topic-metadata">

**Author:** [@tmihaldinec](https://discuss.elastic.co/u/tmihaldinec)\
**Replies:** 1\
**Last updated:** [September 20, 2022, 5:41pm UTC](https://discuss.elastic.co/t/opentelemetry-zipkin-and-elastic-apm/314035 "2022-09-20T17:41:15Z")

</div>

Hi We are mostly using Elastic APM with native elastic apm agents (java mostly) One of the best perks is that we can also do correlation with logs which are already mostly in ECS format. Now, problem which we are faci…

---

## [How to convert this date type to a readable type '1661126482845'](https://discuss.elastic.co/t/how-to-convert-this-date-type-to-a-readable-type-1661126482845/314782)

<div class="topic-metadata">

**Author:** [@Vitoria\_De\_Lara](https://discuss.elastic.co/u/Vitoria_De_Lara)\
**Replies:** 1\
**Last updated:** [September 20, 2022, 4:00pm UTC](https://discuss.elastic.co/t/how-to-convert-this-date-type-to-a-readable-type-1661126482845/314782 "2022-09-20T16:00:36Z")

</div>

I need to convert this date type to a readable date type in my file. conf, I'm using the json filter. I've tried several conversion models but it's not working. can anybody help me?

---

## [Rollover actions over custom field](https://discuss.elastic.co/t/rollover-actions-over-custom-field/314784)

<div class="topic-metadata">

**Author:** [@Nicolaegis](https://discuss.elastic.co/u/Nicolaegis)\
**Replies:** 5\
**Last updated:** [September 20, 2022, 3:50pm UTC](https://discuss.elastic.co/t/rollover-actions-over-custom-field/314784 "2022-09-20T15:50:11Z")

</div>

Hello, I would like to know if it is possible to make a rollover action for a custom date field, if not, it is possible to write a custom plugin to achieve this? Thank you

---

## [Elastic Endpoint cannot send alerts to kibana](https://discuss.elastic.co/t/elastic-endpoint-cannot-send-alerts-to-kibana/314644)

<div class="topic-metadata">

**Author:** [@Fatima](https://discuss.elastic.co/u/Fatima)\
**Replies:** 1\
**Last updated:** [September 20, 2022, 3:24pm UTC](https://discuss.elastic.co/t/elastic-endpoint-cannot-send-alerts-to-kibana/314644 "2022-09-20T15:24:39Z")

</div>

Hi people, I have configured the beats and EDR and I am getting all the events from the different hosts. I have enabled all the preset security rules but I am not getting any alerts. This is the message I get when doi…

---

## [Query time increased after upgrade to ES version 8.3](https://discuss.elastic.co/t/query-time-increased-after-upgrade-to-es-version-8-3/314778)

<div class="topic-metadata">

**Author:** [@pratikshatiwari](https://discuss.elastic.co/u/pratikshatiwari)\
**Replies:** 0\
**Last updated:** [September 20, 2022, 1:33pm UTC](https://discuss.elastic.co/t/query-time-increased-after-upgrade-to-es-version-8-3/314778 "2022-09-20T13:33:49Z")

</div>

Hello We are facing an issue with elasticsearch query performance where we are trying to query elasticsearch index it is recording more than 5 second for most of the queries, we are testing through jmeter Before versio…

---

## [Documents are no longer saved after high disk watermark exceeded on an elasticsearch cluster](https://discuss.elastic.co/t/documents-are-no-longer-saved-after-high-disk-watermark-exceeded-on-an-elasticsearch-cluster/313975)

<div class="topic-metadata">

**Author:** [@Khaled\_Saidi](https://discuss.elastic.co/u/Khaled_Saidi)\
**Replies:** 9\
**Last updated:** [September 19, 2022, 2:53pm UTC](https://discuss.elastic.co/t/documents-are-no-longer-saved-after-high-disk-watermark-exceeded-on-an-elasticsearch-cluster/313975 "2022-09-19T14:53:28Z")

</div>

Hi everyone, I have a question about how load balance work on an elasticsearch servers cluster. The cluster is composed by : 4 "master, data" nodes, 2 "data" nodes 1 "coordinator" node The warning "high disk waterma…

---

## [I m unable to restart the logstash after updating the conf.d file](https://discuss.elastic.co/t/i-m-unable-to-restart-the-logstash-after-updating-the-conf-d-file/314768)

<div class="topic-metadata">

**Author:** [@prashanthk](https://discuss.elastic.co/u/prashanthk)\
**Replies:** 1\
**Last updated:** [September 20, 2022, 12:06pm UTC](https://discuss.elastic.co/t/i-m-unable-to-restart-the-logstash-after-updating-the-conf-d-file/314768 "2022-09-20T12:06:02Z")

</div>

Im unable to start logstash after updating the conf.d file in logstash. i checked the logs it is showing as Attempted to resurrect connection to dead ES instance, but got an error. I need to start the logstash now.

---

## [Slow querying of elasticsearch logs](https://discuss.elastic.co/t/slow-querying-of-elasticsearch-logs/314751)

<div class="topic-metadata">

**Author:** [@Faisal\_Umer](https://discuss.elastic.co/u/Faisal_Umer)\
**Replies:** 5\
**Last updated:** [September 20, 2022, 10:44am UTC](https://discuss.elastic.co/t/slow-querying-of-elasticsearch-logs/314751 "2022-09-20T10:44:35Z")

</div>

We have an index with 90 primaries & 0 replicas and a new index is created each day. The volume grows up to 7-8TB per day. We have lifecycle policies where the index is moved from hot to warm nodes after 3 days and then …

---

## [How to saved a query using API](https://discuss.elastic.co/t/how-to-saved-a-query-using-api/314683)

<div class="topic-metadata">

**Author:** [@Azhar\_Uddin1](https://discuss.elastic.co/u/Azhar_Uddin1)\
**Replies:** 3\
**Last updated:** [September 20, 2022, 10:05am UTC](https://discuss.elastic.co/t/how-to-saved-a-query-using-api/314683 "2022-09-20T10:05:51Z")

</div>

I am filtering out the elastic sample data using the elasticsearch client but how could I achieve to create a saved object using API (using Elasticsearch client) and apply it There is documentation for saved objects AP…

---

## [ElasticSearch: DSL Query](https://discuss.elastic.co/t/elasticsearch-dsl-query/314767)

<div class="topic-metadata">

**Author:** [@SalvoDM91](https://discuss.elastic.co/u/SalvoDM91)\
**Replies:** 0\
**Last updated:** [September 20, 2022, 9:58am UTC](https://discuss.elastic.co/t/elasticsearch-dsl-query/314767 "2022-09-20T09:58:49Z")

</div>

Hi guys, I am opening this topic because I have a problem with a large amount of data (14M). My dataset is composed as follows: {"h":{"id":"AA001","process":"AK01","update-timestamp":1663665372171}} {"h":{"id":"AA002",…

---

## [Cluster ElasticSearch Red](https://discuss.elastic.co/t/cluster-elasticsearch-red/314757)

<div class="topic-metadata">

**Author:** [@meyer1](https://discuss.elastic.co/u/meyer1)\
**Replies:** 5\
**Last updated:** [September 20, 2022, 9:10am UTC](https://discuss.elastic.co/t/cluster-elasticsearch-red/314757 "2022-09-20T09:10:10Z")

</div>

Hello everyone, here is my problem, I have my elastic cluster with a red status. I used this api : http://localhost:9200/\_cluster/health Answer: { cluster\_name : "elasticsearch", status : "red", timed\_out : false, num…

---

## [Logstash JDBC - All rows run only once](https://discuss.elastic.co/t/logstash-jdbc-all-rows-run-only-once/314756)

<div class="topic-metadata">

**Author:** [@tag\_v](https://discuss.elastic.co/u/tag_v)\
**Replies:** 0\
**Last updated:** [September 20, 2022, 8:54am UTC](https://discuss.elastic.co/t/logstash-jdbc-all-rows-run-only-once/314756 "2022-09-20T08:54:53Z")

</div>

I want to migrate DB table data with millions of rows to S3. I found jdbc plugin. But not clear how to make it run only once for all rows paginated way - The main question is on Scheduling: I don't want to run repeatedly…

---

## [Logstash filter string anywhere](https://discuss.elastic.co/t/logstash-filter-string-anywhere/314552)

<div class="topic-metadata">

**Author:** [@moberreiter](https://discuss.elastic.co/u/moberreiter)\
**Replies:** 5\
**Last updated:** [September 20, 2022, 8:37am UTC](https://discuss.elastic.co/t/logstash-filter-string-anywhere/314552 "2022-09-20T08:37:32Z")

</div>

Hi there, I want to filter firewall logs if some specific string matches anywhere in the message and do not know exactly how to do it. Sample Log message: {"zone\_src":"SOURCE","zone\_dst":"EXTERNAL","reason":"rule","ru…

---

## [Logstash S3 output prefix - Event field timestamp](https://discuss.elastic.co/t/logstash-s3-output-prefix-event-field-timestamp/314708)

<div class="topic-metadata">

**Author:** [@tag\_v](https://discuss.elastic.co/u/tag_v)\
**Replies:** 2\
**Last updated:** [September 20, 2022, 8:21am UTC](https://discuss.elastic.co/t/logstash-s3-output-prefix-event-field-timestamp/314708 "2022-09-20T08:21:48Z")

</div>

How to set Logstash S3 output prefix dynamically with an event field value in format: "%{+YYYY}/%{+MM}/%{+dd}/%{+HH}" ? input: {"record\_time":"2017-03-09T04:07:51.520Z"} required s3 prefix: 2017/03/09/04

---

## [Need to Parse a nested JSON message in #Logstash](https://discuss.elastic.co/t/need-to-parse-a-nested-json-message-in-logstash/312979)

<div class="topic-metadata">

**Author:** [@pavanKumar2K](https://discuss.elastic.co/u/pavanKumar2K)\
**Replies:** 2\
**Last updated:** [September 20, 2022, 7:29am UTC](https://discuss.elastic.co/t/need-to-parse-a-nested-json-message-in-logstash/312979 "2022-09-20T07:29:00Z")

</div>

Hello , I am trying to send my logs files ( .txt / json files ) to Logstash via Filebeat my sample log structure is as below : {"LogDetails":{"transaction-id":"1234","channel-id":"abc","APIName":"testapi","OperationNa…

---

## [Fetch Last 15 minute of data](https://discuss.elastic.co/t/fetch-last-15-minute-of-data/314695)

<div class="topic-metadata">

**Author:** [@Aniket\_Pant](https://discuss.elastic.co/u/Aniket_Pant)\
**Replies:** 4\
**Last updated:** [September 20, 2022, 6:56am UTC](https://discuss.elastic.co/t/fetch-last-15-minute-of-data/314695 "2022-09-20T06:56:58Z")

</div>

Here is my query for fetching the result of today last 15 minutes { "query": { "bool": { "filter": \[ { "bool": { "should": \[ { "match\_phrase": { …

---

## [Kibana Dashboard ElastiFlow 4.0.1 issue](https://discuss.elastic.co/t/kibana-dashboard-elastiflow-4-0-1-issue/311797)

<div class="topic-metadata">

**Author:** [@boot4root](https://discuss.elastic.co/u/boot4root)\
**Replies:** 7\
**Last updated:** [September 20, 2022, 6:45am UTC](https://discuss.elastic.co/t/kibana-dashboard-elastiflow-4-0-1-issue/311797 "2022-09-20T06:45:56Z")

</div>

Good afternoon, I ran into a problem, for some reason, after using ElastiFlow 4.0.1 on Dash Board for a while, the circles on dashboard began to distort, unfortunately ElastiFlow switched to the commercial version and cl…

---

## [How do I parse CEF messages comprises of json fields in between?](https://discuss.elastic.co/t/how-do-i-parse-cef-messages-comprises-of-json-fields-in-between/314718)

<div class="topic-metadata">

**Author:** [@Blason](https://discuss.elastic.co/u/Blason)\
**Replies:** 4\
**Last updated:** [September 20, 2022, 6:36am UTC](https://discuss.elastic.co/t/how-do-i-parse-cef-messages-comprises-of-json-fields-in-between/314718 "2022-09-20T06:36:03Z")

</div>

Hi Team, I am accepting Cisco Ironport messages into elasticsearch using logstash cef plugin. However certain messages comprises of json fields in between and those are not getting parsed. Can someone please help me abo…

---

## [Access aggregation key inside script](https://discuss.elastic.co/t/access-aggregation-key-inside-script/314739)

<div class="topic-metadata">

**Author:** [@WeiJun0827](https://discuss.elastic.co/u/WeiJun0827)\
**Replies:** 0\
**Last updated:** [September 20, 2022, 6:20am UTC](https://discuss.elastic.co/t/access-aggregation-key-inside-script/314739 "2022-09-20T06:20:16Z")

</div>

Hello, I'm working on Elasticsearch v7.10. I stored the result of each game as a doc. The players and their scores were stored in users and scores arrays. Sample data : \[ { "gameId": "game01", "users": \[ …

---

## [Query suggest not working on app search - elastic index backed engines](https://discuss.elastic.co/t/query-suggest-not-working-on-app-search-elastic-index-backed-engines/313583)

<div class="topic-metadata">

**Author:** [@metalshanked](https://discuss.elastic.co/u/metalshanked)\
**Replies:** 8\
**Last updated:** [September 20, 2022, 1:08am UTC](https://discuss.elastic.co/t/query-suggest-not-working-on-app-search-elastic-index-backed-engines/313583 "2022-09-20T01:08:00Z")

</div>

Hi, I am running 8.4.1 of App Search and see that query\_suggest does not work for engines created by elastic backends (i.e. non app search engines) No results return Can you please advise / provide a workaround ? Tha…

---

## [Connection refused errror for python elasticsearch client 6.8.22](https://discuss.elastic.co/t/connection-refused-errror-for-python-elasticsearch-client-6-8-22/314504)

<div class="topic-metadata">

**Author:** [@febryjose](https://discuss.elastic.co/u/febryjose)\
**Replies:** 1\
**Last updated:** [September 20, 2022, 12:03am UTC](https://discuss.elastic.co/t/connection-refused-errror-for-python-elasticsearch-client-6-8-22/314504 "2022-09-20T00:03:06Z")

</div>

Hello Team, I am facing issues related to python elasticsearch client, we have 3 VMs where elasticsearch is installed and we are using python to create elasticsearch client with host \[ip1,ip2,ip3\]. But connection refuse…

---

## [How to achieve Elasticsearch aggregation by grids of specific size?](https://discuss.elastic.co/t/how-to-achieve-elasticsearch-aggregation-by-grids-of-specific-size/314725)

<div class="topic-metadata">

**Author:** [@Daniel\_Garcia](https://discuss.elastic.co/u/Daniel_Garcia)\
**Replies:** 0\
**Last updated:** [September 19, 2022, 10:02pm UTC](https://discuss.elastic.co/t/how-to-achieve-elasticsearch-aggregation-by-grids-of-specific-size/314725 "2022-09-19T22:02:40Z")

</div>

Basically, what I have is a polygon that I use to filter my data through a Geoshape query. What I would like to achieve is to apply an Elasticsearch aggregation to that query that gives me a bucket for every grid of an s…

---

## [Training Recomandtion](https://discuss.elastic.co/t/training-recomandtion/314406)

<div class="topic-metadata">

**Author:** [@smm](https://discuss.elastic.co/u/smm)\
**Replies:** 1\
**Last updated:** [September 19, 2022, 5:25pm UTC](https://discuss.elastic.co/t/training-recomandtion/314406 "2022-09-19T17:25:00Z")

</div>

Hi there, I am an Elastic admin for observability. I would to start with the security (SIEM) topic as well. I am a newbie in this regard. Which of this trainings would you suggest to attend at first: Onsite & Online Tra…

---

## [Aggregating an index with parent-child runs forever](https://discuss.elastic.co/t/aggregating-an-index-with-parent-child-runs-forever/313624)

<div class="topic-metadata">

**Author:** [@t0mer](https://discuss.elastic.co/u/t0mer)\
**Replies:** 3\
**Last updated:** [September 19, 2022, 4:45pm UTC](https://discuss.elastic.co/t/aggregating-an-index-with-parent-child-runs-forever/313624 "2022-09-19T16:45:52Z")

</div>

Hi, I've recently decided to make an attempt to reindex an existing denormalized index to a new index with parent-chid relation. I've around 14M parent docs, each parent has up to 400 children. (total of around 270M do…

---

## [Synthetics 8.4.0 Release - New Workflow Video Walkthrough](https://discuss.elastic.co/t/synthetics-8-4-0-release-new-workflow-video-walkthrough/314712)

<div class="topic-metadata">

**Author:** [@Andrew\_Cholakian1](https://discuss.elastic.co/u/Andrew_Cholakian1)\
**Replies:** 0\
**Last updated:** [September 19, 2022, 4:27pm UTC](https://discuss.elastic.co/t/synthetics-8-4-0-release-new-workflow-video-walkthrough/314712 "2022-09-19T16:27:26Z")

</div>

Hey all, it's a little late in coming seeing as 8.4.0 was released almost a month ago, but we wanted to give you a walkthrough of what's new with the Elastic Uptime / Synthetics workflow in 8.4.0. We're trying something …

---

## [New Control Filter Version 8](https://discuss.elastic.co/t/new-control-filter-version-8/314654)

<div class="topic-metadata">

**Author:** [@Irwan\_Kurniawan](https://discuss.elastic.co/u/Irwan_Kurniawan)\
**Replies:** 1\
**Last updated:** [September 19, 2022, 2:01pm UTC](https://discuss.elastic.co/t/new-control-filter-version-8/314654 "2022-09-19T14:01:34Z")

</div>

Hi, I want to do drilldown with filter. I already apply with filter but when I do drill down, the filter doesn't work. It happen in new control for version 8. It works with old control (version 7). Is it a bug or need di…

---

## ["long objects" json pattern regular expression logstash](https://discuss.elastic.co/t/long-objects-json-pattern-regular-expression-logstash/314700)

<div class="topic-metadata">

**Author:** [@Vitoria\_De\_Lara](https://discuss.elastic.co/u/Vitoria_De_Lara)\
**Replies:** 0\
**Last updated:** [September 19, 2022, 1:56pm UTC](https://discuss.elastic.co/t/long-objects-json-pattern-regular-expression-logstash/314700 "2022-09-19T13:56:02Z")

</div>

I have a long json file and I need to capture it in parts for elasticsearch

---

## [Deploy Elasticsearch Custom Resource with Terraform](https://discuss.elastic.co/t/deploy-elasticsearch-custom-resource-with-terraform/314699)

<div class="topic-metadata">

**Author:** [@BenB196](https://discuss.elastic.co/u/BenB196)\
**Replies:** 0\
**Last updated:** [September 19, 2022, 1:24pm UTC](https://discuss.elastic.co/t/deploy-elasticsearch-custom-resource-with-terraform/314699 "2022-09-19T13:24:54Z")

</div>

(Preface - I recognize this question leans more towards Terraform, but wanted to ask it here as it mainly involves ECK/Elasticsearch). Hi All, I was wondering if anyone has a working example of using the Terraform Kube…

---

## [Connection Refused](https://discuss.elastic.co/t/connection-refused/313418)

<div class="topic-metadata">

**Author:** [@ombit](https://discuss.elastic.co/u/ombit)\
**Replies:** 10\
**Last updated:** [September 19, 2022, 1:08pm UTC](https://discuss.elastic.co/t/connection-refused/313418 "2022-09-19T13:08:23Z")

</div>

Hi all, I need to create a solution that amends syslogs to be RFC3164 compliant and ultimately send them on to a QRADAR at a customer's site. To test this I have created two linux VMs both of which can ping each other…

---

## [Logstash number of threads keeps increasing until crash](https://discuss.elastic.co/t/logstash-number-of-threads-keeps-increasing-until-crash/313463)

<div class="topic-metadata">

**Author:** [@Alain\_Bod](https://discuss.elastic.co/u/Alain_Bod)\
**Replies:** 13\
**Last updated:** [September 19, 2022, 1:06pm UTC](https://discuss.elastic.co/t/logstash-number-of-threads-keeps-increasing-until-crash/313463 "2022-09-19T13:06:06Z")

</div>

Hi, I'm testing the following pipeline (stack version 8.4.1): input { google\_cloud\_storage {...} } filter {csv {...} mutate {...} } output { elasticsearch {...} } with a large number of events (3M+). After a few min…

[Previous page](https://discuss.elastic.co/tag/none.md?no_tags=true&page=533)

[Next page](https://discuss.elastic.co/tag/none.md?no_tags=true&page=535)
