# \#none

**URL:** https://discuss.elastic.co/tag/none.md?no_tags=true&page=536

[Latest](https://discuss.elastic.co/latest.md) · [Categories](https://discuss.elastic.co/categories.md) · [Tags](https://discuss.elastic.co/tags.md)

**Page:** 537

---

## [Issue with logstash agent](https://discuss.elastic.co/t/issue-with-logstash-agent/314578)

<div class="topic-metadata">

**Author:** [@yas](https://discuss.elastic.co/u/yas)\
**Replies:** 0\
**Last updated:** [September 16, 2022, 1:34pm UTC](https://discuss.elastic.co/t/issue-with-logstash-agent/314578 "2022-09-16T13:34:02Z")

</div>

Having an issue with Logstash agents ( linux hosts ) sending files to a server - what seems to happen is on the agent starting up , the first few rows of the logs are sent after which it just stops and nothing further is…

---

## [Custom API integration](https://discuss.elastic.co/t/custom-api-integration/314538)

<div class="topic-metadata">

**Author:** [@alextg](https://discuss.elastic.co/u/alextg)\
**Replies:** 1\
**Last updated:** [September 16, 2022, 11:51am UTC](https://discuss.elastic.co/t/custom-api-integration/314538 "2022-09-16T11:51:19Z")

</div>

Hello, I'm running into issues while implementing the Custom API integration which sends API get requests. I have setup successfully other integrations using the Custom Logs integration, however, the Custom API integrat…

---

## [Process events from split](https://discuss.elastic.co/t/process-events-from-split/314564)

<div class="topic-metadata">

**Author:** [@sirReeall](https://discuss.elastic.co/u/sirReeall)\
**Replies:** 1\
**Last updated:** [September 16, 2022, 10:01am UTC](https://discuss.elastic.co/t/process-events-from-split/314564 "2022-09-16T10:01:34Z")

</div>

Is it possible to have logstash process the events generated from a split? For example, give the following: 2022-09-06 23:39:01.034+0000 INFO \[my.java.class\] Process started \\n some lines \\n some more lines \\n …

---

## [Create elastic field alias](https://discuss.elastic.co/t/create-elastic-field-alias/313966)

<div class="topic-metadata">

**Author:** [@sirReeall](https://discuss.elastic.co/u/sirReeall)\
**Replies:** 4\
**Last updated:** [September 16, 2022, 9:25am UTC](https://discuss.elastic.co/t/create-elastic-field-alias/313966 "2022-09-16T09:25:34Z")

</div>

Hello, Is it possible for logstash to alias fields as described in the elastic docs below?

---

## [Invalid Index Name-Index name must be lowercase error](https://discuss.elastic.co/t/invalid-index-name-index-name-must-be-lowercase-error/314287)

<div class="topic-metadata">

**Author:** [@tapas](https://discuss.elastic.co/u/tapas)\
**Replies:** 15\
**Last updated:** [September 16, 2022, 7:55am UTC](https://discuss.elastic.co/t/invalid-index-name-index-name-must-be-lowercase-error/314287 "2022-09-16T07:55:52Z")

</div>

I am getting error in logstash logs saying that the index is invalid and reason is it should be lower case.but the index name in the log is different from the index i declared in the logstash.config file.in log file it i…

---

## [Kibana visualization to show intime value count of different fieldski](https://discuss.elastic.co/t/kibana-visualization-to-show-intime-value-count-of-different-fieldski/312642)

<div class="topic-metadata">

**Author:** [@PRASHANT\_MEHTA](https://discuss.elastic.co/u/PRASHANT_MEHTA)\
**Replies:** 3\
**Last updated:** [September 16, 2022, 7:42am UTC](https://discuss.elastic.co/t/kibana-visualization-to-show-intime-value-count-of-different-fieldski/312642 "2022-09-16T07:42:32Z")

</div>

Hello All, How to make TSVB visualization displaying all the count values for given filelds. Here I'm trying to dispaly the index updated,nodes travered,entrie process and chunk "intime" count value wrt statistic time.…

---

## [Logstash filter taking. high cpu](https://discuss.elastic.co/t/logstash-filter-taking-high-cpu/314550)

<div class="topic-metadata">

**Author:** [@krishan.kumar](https://discuss.elastic.co/u/krishan.kumar)\
**Replies:** 0\
**Last updated:** [September 16, 2022, 6:35am UTC](https://discuss.elastic.co/t/logstash-filter-taking-high-cpu/314550 "2022-09-16T06:35:54Z")

</div>

Hi, My logstash grok pattern taking high CPU This is my log format I, \[2022-09-16T06:27:40.386003 #13375\] INFO -- : \[s45g0-e726-56y7-adcf-3382276c1a77\] \[user\_id: xxxxxx, portfolio\_id: xxxxxxx\] {"method":"GET","path":…

---

## [Nodes do not release RAM when idle](https://discuss.elastic.co/t/nodes-do-not-release-ram-when-idle/314321)

<div class="topic-metadata">

**Author:** [@Thijsvdp](https://discuss.elastic.co/u/Thijsvdp)\
**Replies:** 17\
**Last updated:** [September 16, 2022, 6:17am UTC](https://discuss.elastic.co/t/nodes-do-not-release-ram-when-idle/314321 "2022-09-16T06:17:51Z")

</div>

Hi all, I have experienced some weird behavior on my development cluster while reading an index using the Elasticsearch-Hadoop connector. I am benchmarking the read performance, by running some scripts that read the ful…

---

## [Problem with aggs queries returning null?](https://discuss.elastic.co/t/problem-with-aggs-queries-returning-null/314529)

<div class="topic-metadata">

**Author:** [@JamesD\_7](https://discuss.elastic.co/u/JamesD_7)\
**Replies:** 1\
**Last updated:** [September 15, 2022, 11:17pm UTC](https://discuss.elastic.co/t/problem-with-aggs-queries-returning-null/314529 "2022-09-15T23:17:09Z")

</div>

Hello, I'm having trouble getting a simple aggs query to return data. GET mydata1/\_search { "aggs": { "avg\_num\_days": { "avg": { "field": "myField" } } } } I was getting an error: "error"…

---

## [Is it possible to configure filters that use boolean logic for SearchProvider?](https://discuss.elastic.co/t/is-it-possible-to-configure-filters-that-use-boolean-logic-for-searchprovider/314352)

<div class="topic-metadata">

**Author:** [@Beratna](https://discuss.elastic.co/u/Beratna)\
**Replies:** 9\
**Last updated:** [September 15, 2022, 5:50pm UTC](https://discuss.elastic.co/t/is-it-possible-to-configure-filters-that-use-boolean-logic-for-searchprovider/314352 "2022-09-15T17:50:52Z")

</div>

Hi there, I'm currently using App Search with search-ui react library. I'm looking for a way to apply boolean logic to the filters inside my searchQuery config. Let's say I have 10 documents in my search engine. Each…

---

## [Logstash cipher fragment error](https://discuss.elastic.co/t/logstash-cipher-fragment-error/314523)

<div class="topic-metadata">

**Author:** [@RaonyO](https://discuss.elastic.co/u/RaonyO)\
**Replies:** 3\
**Last updated:** [September 15, 2022, 3:41pm UTC](https://discuss.elastic.co/t/logstash-cipher-fragment-error/314523 "2022-09-15T15:41:03Z")

</div>

I have an error in a pipeline in logstash, the input is via tcp and ssl. config: input { tcp { port =\> 7771 codec =\> line ssl\_verify =\> false ssl\_enable =\> true ssl\_cert =\> "/etc/logstash/certs/cert.crt…

---

## [Has support for percolating multiple EXISTING documents been added?](https://discuss.elastic.co/t/has-support-for-percolating-multiple-existing-documents-been-added/314450)

<div class="topic-metadata">

**Author:** [@fedreg](https://discuss.elastic.co/u/fedreg)\
**Replies:** 2\
**Last updated:** [September 15, 2022, 1:52pm UTC](https://discuss.elastic.co/t/has-support-for-percolating-multiple-existing-documents-been-added/314450 "2022-09-15T13:52:49Z")

</div>

Hello! Question about Percolator Queries in ES 8.x... Wondering if the ability to query multiple EXISTING docs has been added to the API? I know I can query multiple raw documents such as GET /my-index-000001/\_search…

---

## [CSV Export not available when xpack.reporting.roles.enabled set to false](https://discuss.elastic.co/t/csv-export-not-available-when-xpack-reporting-roles-enabled-set-to-false/313445)

<div class="topic-metadata">

**Author:** [@Harm](https://discuss.elastic.co/u/Harm)\
**Replies:** 5\
**Last updated:** [September 15, 2022, 1:49pm UTC](https://discuss.elastic.co/t/csv-export-not-available-when-xpack-reporting-roles-enabled-set-to-false/313445 "2022-09-15T13:49:48Z")

</div>

Hi, since the xpack.reporting.roles settings are deprecated since v7.14.0, I have disabled the use of the reporting role in our 7.17.6 environment by setting: xpack.reporting.roles.enabled: false The new subfeatures …

---

## [Logstash and filebeat data streams](https://discuss.elastic.co/t/logstash-and-filebeat-data-streams/314488)

<div class="topic-metadata">

**Author:** [@gborg](https://discuss.elastic.co/u/gborg)\
**Replies:** 1\
**Last updated:** [September 15, 2022, 1:24pm UTC](https://discuss.elastic.co/t/logstash-and-filebeat-data-streams/314488 "2022-09-15T13:24:35Z")

</div>

Hello I have a setup where I run filebeats, which send their logs to a queue, logstash reads off the queue and writes the data to elasticsearch. With version 7 I had no issues, I recently upgraded to elasticsearch to e…

---

## [Elasticsearch cut strings with forward slash](https://discuss.elastic.co/t/elasticsearch-cut-strings-with-forward-slash/314355)

<div class="topic-metadata">

**Author:** [@abolinhas](https://discuss.elastic.co/u/abolinhas)\
**Replies:** 1\
**Last updated:** [September 15, 2022, 12:43pm UTC](https://discuss.elastic.co/t/elasticsearch-cut-strings-with-forward-slash/314355 "2022-09-15T12:43:43Z")

</div>

I have configured my squid proxy to send the logs to Elasticsearch 7.17.6, everything is working fine, except the USER mapping. The string expect is DOMAIN/USER, the ELK recieves it correctly on original message but the…

---

## [While creating new dashboard and search I get fields just from one index](https://discuss.elastic.co/t/while-creating-new-dashboard-and-search-i-get-fields-just-from-one-index/314416)

<div class="topic-metadata">

**Author:** [@111363](https://discuss.elastic.co/u/111363)\
**Replies:** 3\
**Last updated:** [September 15, 2022, 11:38am UTC](https://discuss.elastic.co/t/while-creating-new-dashboard-and-search-i-get-fields-just-from-one-index/314416 "2022-09-15T11:38:34Z")

</div>

Hi, I have few indexes in Kibana ("index1", "index2", ...). I have created a new dashboard. Added some visualizations that I created with "index2". Now I use search for filter data but the only fields I get are from "i…

---

## [Search a string in Kibana](https://discuss.elastic.co/t/search-a-string-in-kibana/314468)

<div class="topic-metadata">

**Author:** [@sree3](https://discuss.elastic.co/u/sree3)\
**Replies:** 2\
**Last updated:** [September 15, 2022, 11:01am UTC](https://discuss.elastic.co/t/search-a-string-in-kibana/314468 "2022-09-15T11:01:34Z")

</div>

Hi, We could see below custom message from one of the indices. I'm trying to filter a string "heap.memory.used/total=7" so that an action can triggered if the used heap memory used greater than 9\*%. Every time if is try…

---

## [Fetch results with wildcard issue](https://discuss.elastic.co/t/fetch-results-with-wildcard-issue/314254)

<div class="topic-metadata">

**Author:** [@mani7](https://discuss.elastic.co/u/mani7)\
**Replies:** 2\
**Last updated:** [September 15, 2022, 10:22am UTC](https://discuss.elastic.co/t/fetch-results-with-wildcard-issue/314254 "2022-09-15T10:22:52Z")

</div>

is there have any way to fetch elastic results with lower case letter with wildcard. but data in elastic index is in capital letter.

---

## [Rang query with format](https://discuss.elastic.co/t/rang-query-with-format/314495)

<div class="topic-metadata">

**Author:** [@casterQ](https://discuss.elastic.co/u/casterQ)\
**Replies:** 0\
**Last updated:** [September 15, 2022, 9:59am UTC](https://discuss.elastic.co/t/rang-query-with-format/314495 "2022-09-15T09:59:51Z")

</div>

This DSL works: POST xxxxx/\_search?size=1 { "profile": "true", "query": { "range": { "date\_createdAt": { "gte": "2005W161", "lt": "2005W171", "format": "basic\_week\_date" } …

---

## [Logic Error after ingesting number](https://discuss.elastic.co/t/logic-error-after-ingesting-number/314331)

<div class="topic-metadata">

**Author:** [@hnf](https://discuss.elastic.co/u/hnf)\
**Replies:** 7\
**Last updated:** [September 15, 2022, 8:32am UTC](https://discuss.elastic.co/t/logic-error-after-ingesting-number/314331 "2022-09-15T08:32:38Z")

</div>

I have an xlsx file that I convert in CSV file using ssconvert tool. In the new generated file, there's one field in floating point type. But after ingestion, the values taken from the file is no more in float. For exem…

---

## [Kibana Ingress in GCP showing backend config as unhealthy eck 1.1.0](https://discuss.elastic.co/t/kibana-ingress-in-gcp-showing-backend-config-as-unhealthy-eck-1-1-0/235514)

<div class="topic-metadata">

**Author:** [@aman26ps](https://discuss.elastic.co/u/aman26ps)\
**Replies:** 9\
**Last updated:** [September 15, 2022, 7:54am UTC](https://discuss.elastic.co/t/kibana-ingress-in-gcp-showing-backend-config-as-unhealthy-eck-1-1-0/235514 "2022-09-15T07:54:27Z")

</div>

Hi Team, I had patcheck my eck from 1.0.1 to 1.1.0 and i have added readiness probe in kibana CR , everything was fine , but recently i enabled filerealm with native realm in elasticsearch-cr like this : xpack.securit…

---

## [FATAL CLI ERROR Error: EACCES: permission denied, open '/etc/kibana/kibana.yml'](https://discuss.elastic.co/t/fatal-cli-error-error-eacces-permission-denied-open-etc-kibana-kibana-yml/314474)

<div class="topic-metadata">

**Author:** [@Neyo](https://discuss.elastic.co/u/Neyo)\
**Replies:** 1\
**Last updated:** [September 15, 2022, 4:33am UTC](https://discuss.elastic.co/t/fatal-cli-error-error-eacces-permission-denied-open-etc-kibana-kibana-yml/314474 "2022-09-15T04:33:25Z")

</div>

am unable to access the webpage via ip-address it gives "Unable to Connect Error" but without configuring I can access that with the localhost:5601/?code=xxxxxx and having the enrollment token messi@football:/etc$ sudo …

---

## [Question about metrics](https://discuss.elastic.co/t/question-about-metrics/314317)

<div class="topic-metadata">

**Author:** [@Kirtash](https://discuss.elastic.co/u/Kirtash)\
**Replies:** 2\
**Last updated:** [September 15, 2022, 6:27am UTC](https://discuss.elastic.co/t/question-about-metrics/314317 "2022-09-15T06:27:04Z")

</div>

Hi! I have a theory question about the metric indices. I use .net core and when I create a new service I specify the serviceName to be more clearly in APM. In this moment, I see that elastic create automatically the ne…

---

## [How to search for specific word and exact match in Elasticsearch](https://discuss.elastic.co/t/how-to-search-for-specific-word-and-exact-match-in-elasticsearch/314471)

<div class="topic-metadata">

**Author:** [@Amitav](https://discuss.elastic.co/u/Amitav)\
**Replies:** 1\
**Last updated:** [September 15, 2022, 5:49am UTC](https://discuss.elastic.co/t/how-to-search-for-specific-word-and-exact-match-in-elasticsearch/314471 "2022-09-15T05:49:10Z")

</div>

sample data for title actiontype test booleanTest test-demo test\_demo Test new account object sync accounts data test default Mapping for title "title": { "type": "text", "fields": { "keyword…

---

## [Error 7024 windows 10 pro](https://discuss.elastic.co/t/error-7024-windows-10-pro/313812)

<div class="topic-metadata">

**Author:** [@David\_Dudi\_Hefer](https://discuss.elastic.co/u/David_Dudi_Hefer)\
**Replies:** 15\
**Last updated:** [September 15, 2022, 5:41am UTC](https://discuss.elastic.co/t/error-7024-windows-10-pro/313812 "2022-09-15T05:41:39Z")

</div>

The Elasticsearch 7.16.3 (elasticsearch-service-x64) service terminated with the following service-specific error: Incorrect function. can't browse localhost:9200 please help !!

---

## [From Kibana Server not ready yet to Unable to Connect Error](https://discuss.elastic.co/t/from-kibana-server-not-ready-yet-to-unable-to-connect-error/314415)

<div class="topic-metadata">

**Author:** [@Neophyte](https://discuss.elastic.co/u/Neophyte)\
**Replies:** 1\
**Last updated:** [September 15, 2022, 4:39am UTC](https://discuss.elastic.co/t/from-kibana-server-not-ready-yet-to-unable-to-connect-error/314415 "2022-09-15T04:39:31Z")

</div>

Earlier I was receiving that "Kibana Server is not ready yet." and after the following changes given below am receiving Unable to Connect error: messi@fifa:/etc$ sudo systemctl status kibana elasticsearch ● kibana.servi…

---

## [How to print input data to logstash-plain.log file?](https://discuss.elastic.co/t/how-to-print-input-data-to-logstash-plain-log-file/314466)

<div class="topic-metadata">

**Author:** [@WonhyeongCho](https://discuss.elastic.co/u/WonhyeongCho)\
**Replies:** 3\
**Last updated:** [September 15, 2022, 4:37am UTC](https://discuss.elastic.co/t/how-to-print-input-data-to-logstash-plain-log-file/314466 "2022-09-15T04:37:49Z")

</div>

Hello. I'm using logstash for log collection. I want to write data coming into logstash to a log file. I tried many plugins to write data to log file but it didn't work. And I edit log4j2 settings like logger.logstas…

---

## [SHA256 GPG Key](https://discuss.elastic.co/t/sha256-gpg-key/314426)

<div class="topic-metadata">

**Author:** [@6igwig](https://discuss.elastic.co/u/6igwig)\
**Replies:** 0\
**Last updated:** [September 14, 2022, 2:38pm UTC](https://discuss.elastic.co/t/sha256-gpg-key/314426 "2022-09-14T14:38:38Z")

</div>

Installing logstash on Rocky Linux 9 is failing with this error message: "Key import failed (code 2)" I'm not 100% sure, but I think the problem may be that RHEL 9 has deprecated SHA-1. Is there a SHA256 or SHA521 vers…

---

## [Elastic Agent Windows Deployment Symlink Issue 8.4.1](https://discuss.elastic.co/t/elastic-agent-windows-deployment-symlink-issue-8-4-1/314462)

<div class="topic-metadata">

**Author:** [@Ad3t0](https://discuss.elastic.co/u/Ad3t0)\
**Replies:** 1\
**Last updated:** [September 15, 2022, 4:19am UTC](https://discuss.elastic.co/t/elastic-agent-windows-deployment-symlink-issue-8-4-1/314462 "2022-09-15T04:19:59Z")

</div>

Hello, When attempting to deploy the Elastic agent via Windows Server GPO I receive the error "Error: symlink C:\\Program Files\\Elastic\\Agent\\data\\elastic-agent-8d7885\\elastic-agent .exe C:\\Program Files\\Elastic\\Agent\\…

---

## [Install Elasticsearch 8.4. on windows](https://discuss.elastic.co/t/install-elasticsearch-8-4-on-windows/314347)

<div class="topic-metadata">

**Author:** [@Isay](https://discuss.elastic.co/u/Isay)\
**Replies:** 3\
**Last updated:** [September 15, 2022, 4:01am UTC](https://discuss.elastic.co/t/install-elasticsearch-8-4-on-windows/314347 "2022-09-15T04:01:28Z")

</div>

I did the installation of Elasticsearch 8.4 on windows but when executing elasticsearch.bat it runs the command, but it does not show the configuration information and it also does not save information in the elasticsear…

[Previous page](https://discuss.elastic.co/tag/none.md?no_tags=true&page=535)

[Next page](https://discuss.elastic.co/tag/none.md?no_tags=true&page=537)
