# \#none

**URL:** https://discuss.elastic.co/tag/none.md?no_tags=true&page=537

[Latest](https://discuss.elastic.co/latest.md) · [Categories](https://discuss.elastic.co/categories.md) · [Tags](https://discuss.elastic.co/tags.md)

**Page:** 538

---

## [Integrations / Kibana /Message d'erreur Kibana cannot connect to the Elastic Package Registry](https://discuss.elastic.co/t/integrations-kibana-message-derreur-kibana-cannot-connect-to-the-elastic-package-registry/314332)

<div class="topic-metadata">

**Author:** [@Phildefer](https://discuss.elastic.co/u/Phildefer)\
**Replies:** 3\
**Last updated:** [September 15, 2022, 12:56am UTC](https://discuss.elastic.co/t/integrations-kibana-message-derreur-kibana-cannot-connect-to-the-elastic-package-registry/314332 "2022-09-15T00:56:08Z")

</div>

Bonjour, Je creuse un peu l'utilisation d'ELK (installé chez moi en local sur un NAS et j'accède à Kibana via une adresse du type 192;XXX.XXX.XXX:5601) et je souhaiterais tester quelques intégrations. Mon problème est …

---

## [Parsing LEEF data](https://discuss.elastic.co/t/parsing-leef-data/314448)

<div class="topic-metadata">

**Author:** [@sta02](https://discuss.elastic.co/u/sta02)\
**Replies:** 1\
**Last updated:** [September 14, 2022, 11:48pm UTC](https://discuss.elastic.co/t/parsing-leef-data/314448 "2022-09-14T23:48:31Z")

</div>

Hello, How can I parse LEEF data. The format includes | separation in the heard and SPACE separation in Body. Below is a sample event, please advise. The objective is to parse both the LEEF header (LEEF:1.0|Cyber-Ark|V…

---

## [Synthetic monitoring Timeout 30 seconds](https://discuss.elastic.co/t/synthetic-monitoring-timeout-30-seconds/314367)

<div class="topic-metadata">

**Author:** [@ElasticLiver](https://discuss.elastic.co/u/ElasticLiver)\
**Replies:** 2\
**Last updated:** [September 14, 2022, 9:41pm UTC](https://discuss.elastic.co/t/synthetic-monitoring-timeout-30-seconds/314367 "2022-09-14T21:41:43Z")

</div>

Hi, Im new to Synthetic monitoring, after a month of good results, a couple of days ago the status of some of the monitors started to fail, with the error: Error message page.goto: Timeout 30000ms exceeded. The inlin…

---

## [Filter XML plugin namespace available?](https://discuss.elastic.co/t/filter-xml-plugin-namespace-available/314463)

<div class="topic-metadata">

**Author:** [@erwin339](https://discuss.elastic.co/u/erwin339)\
**Replies:** 0\
**Last updated:** [September 14, 2022, 9:37pm UTC](https://discuss.elastic.co/t/filter-xml-plugin-namespace-available/314463 "2022-09-14T21:37:30Z")

</div>

When using the namespace =\> { or the remove\_namespace I don't get any positive response when wanting to assign or remove the namespace, since I am getting this error Error parsing xml with XmlSimple \<REXML::UndefinedNa…

---

## [Drilldown option not showing](https://discuss.elastic.co/t/drilldown-option-not-showing/314442)

<div class="topic-metadata">

**Author:** [@Mary2022](https://discuss.elastic.co/u/Mary2022)\
**Replies:** 5\
**Last updated:** [September 14, 2022, 9:01pm UTC](https://discuss.elastic.co/t/drilldown-option-not-showing/314442 "2022-09-14T21:01:35Z")

</div>

Hi I still new to elasticsearch. I am trying to fix my dashboard. Every time someone click on one of the visualization it will zoom in but the other visualizations will change to not data. I started reading about drilld…

---

## [Filebeat v Logstash handling when Elastic endpoint is down](https://discuss.elastic.co/t/filebeat-v-logstash-handling-when-elastic-endpoint-is-down/314460)

<div class="topic-metadata">

**Author:** [@leemase004](https://discuss.elastic.co/u/leemase004)\
**Replies:** 1\
**Last updated:** [September 14, 2022, 8:58pm UTC](https://discuss.elastic.co/t/filebeat-v-logstash-handling-when-elastic-endpoint-is-down/314460 "2022-09-14T20:58:42Z")

</div>

Quick question on how both filebeat and logstash handle data if Elasticsearch is down. In this scenario both would be pulling from a Kafka topic. We are wondering how the two operate if the endpoint is down but data is …

---

## [Executing a search query with 30K+ clauses](https://discuss.elastic.co/t/executing-a-search-query-with-30k-clauses/314441)

<div class="topic-metadata">

**Author:** [@tnitave](https://discuss.elastic.co/u/tnitave)\
**Replies:** 2\
**Last updated:** [September 14, 2022, 8:29pm UTC](https://discuss.elastic.co/t/executing-a-search-query-with-30k-clauses/314441 "2022-09-14T20:29:38Z")

</div>

I am interested in executing an Elasticsearch search query with 5000+ terms across 5 different fields which leads to 25K+ clauses. According to documentation default max\_clause\_count limit is set to 1024 and updating thi…

---

## [Elastic Agent outputs to localhost?](https://discuss.elastic.co/t/elastic-agent-outputs-to-localhost/314341)

<div class="topic-metadata">

**Author:** [@simpleman](https://discuss.elastic.co/u/simpleman)\
**Replies:** 1\
**Last updated:** [September 14, 2022, 7:59pm UTC](https://discuss.elastic.co/t/elastic-agent-outputs-to-localhost/314341 "2022-09-14T19:59:51Z")

</div>

I have gone the path of install Fleet Server and Agents in my lab server. My setup is: Windows Server 2016 with Symantec Endpoint Protection installed A Linux VM at 192.168.1.10 running ELK stack properly A Linux VM at…

---

## [Graphite Input Logstash](https://discuss.elastic.co/t/graphite-input-logstash/314457)

<div class="topic-metadata">

**Author:** [@elrozario](https://discuss.elastic.co/u/elrozario)\
**Replies:** 0\
**Last updated:** [September 14, 2022, 7:27pm UTC](https://discuss.elastic.co/t/graphite-input-logstash/314457 "2022-09-14T19:27:30Z")

</div>

Hello, I am very new to ELK and trying to ingest data from Graphite but its not working. Here is my logstash pipeline: graphite { host =\> "\*\*\*\*" port =\> "\*\*\*\*" mode =\> "client" …

---

## [Cisco Duo Integration not working](https://discuss.elastic.co/t/cisco-duo-integration-not-working/314454)

<div class="topic-metadata">

**Author:** [@jpayne](https://discuss.elastic.co/u/jpayne)\
**Replies:** 0\
**Last updated:** [September 14, 2022, 7:18pm UTC](https://discuss.elastic.co/t/cisco-duo-integration-not-working/314454 "2022-09-14T19:18:25Z")

</div>

Continuing the discussion from Cisco Duo Integration not working: I am on an elastic 8.4.1 stack with Duo D249.8. I installed the duo integration and I do see logs showing up: but all of the dashboards just show emp…

---

## [\[ERROR\] \[\[main\]\<file\] json - JSON parse error, original data now in message fiel {:message=\>"incompatible json object type=java.lanString, only hash map or arrays are supported", :exception=\>LogStash::Json::ParserError, data=\>" /"bandwidthLimits](https://discuss.elastic.co/t/error-main-file-json-json-parse-error-original-data-now-in-message-fiel-message-incompatible-json-object-type-java-lanstring-only-hash-map-or-arrays-are-supported-exception-logstash-parsererror-data-bandwidthlimits/314447)

<div class="topic-metadata">

**Author:** [@Queren\_Santos](https://discuss.elastic.co/u/Queren_Santos)\
**Replies:** 0\
**Last updated:** [September 14, 2022, 6:21pm UTC](https://discuss.elastic.co/t/error-main-file-json-json-parse-error-original-data-now-in-message-fiel-message-incompatible-json-object-type-java-lanstring-only-hash-map-or-arrays-are-supported-exception-logstash-parsererror-data-bandwidthlimits/314447 "2022-09-14T18:21:04Z")

</div>

My logstash filter code catches incorrect data, can anyone help me with the correct syntax? input { file { path =\> "/var/tmp/wd/accounts/\*.json" codec =\> "json" start\_position =\> "beginning" sincedb\_pa…

---

## [Yet another case of Logstash Delays](https://discuss.elastic.co/t/yet-another-case-of-logstash-delays/314445)

<div class="topic-metadata">

**Author:** [@mread830](https://discuss.elastic.co/u/mread830)\
**Replies:** 0\
**Last updated:** [September 14, 2022, 6:07pm UTC](https://discuss.elastic.co/t/yet-another-case-of-logstash-delays/314445 "2022-09-14T18:07:11Z")

</div>

I’m working on a logging solution that is really nothing more than a forwarder. rsyslog on several servers are sending their logs to Logstash, which then send them out to HEC splunk endpoint. In Logstash, we are using …

---

## [Parsing JSON](https://discuss.elastic.co/t/parsing-json/314435)

<div class="topic-metadata">

**Author:** [@Aniket\_Pant](https://discuss.elastic.co/u/Aniket_Pant)\
**Replies:** 2\
**Last updated:** [September 14, 2022, 5:39pm UTC](https://discuss.elastic.co/t/parsing-json/314435 "2022-09-14T17:39:21Z")

</div>

I want to extract only JSON data but don't know how to do it 2022-09-14 10:08:37,597 DEBUG logging.RequestLoggingAdvice Request received=\[{ "Name" : "John", "var1" : "Value1", "var2" : "Value2", "var3" : "Value3", "var4…

---

## [Kibana server is not ready yet](https://discuss.elastic.co/t/kibana-server-is-not-ready-yet/314438)

<div class="topic-metadata">

**Author:** [@Neophyte](https://discuss.elastic.co/u/Neophyte)\
**Replies:** 4\
**Last updated:** [September 14, 2022, 5:05pm UTC](https://discuss.elastic.co/t/kibana-server-is-not-ready-yet/314438 "2022-09-14T17:05:58Z")

</div>

I am getting this in the browser. Here are my configs messi@fifa:~$ sudo systemctl status kibana elasticsearch ● kibana.service - Kibana Loaded: loaded (/lib/systemd/system/kibana.service; enabled; vendor preset: e…

---

## [Possibilty to show intime value of fileds in kibana as timseries](https://discuss.elastic.co/t/possibilty-to-show-intime-value-of-fileds-in-kibana-as-timseries/314437)

<div class="topic-metadata">

**Author:** [@PRASHANT\_MEHTA](https://discuss.elastic.co/u/PRASHANT_MEHTA)\
**Replies:** 0\
**Last updated:** [September 14, 2022, 3:48pm UTC](https://discuss.elastic.co/t/possibilty-to-show-intime-value-of-fileds-in-kibana-as-timseries/314437 "2022-09-14T15:48:25Z")

</div>

Continuing the discussion from Kibana visualization to show intime value count of different fieldski:

---

## [Using mutate to parse broken JSON](https://discuss.elastic.co/t/using-mutate-to-parse-broken-json/314436)

<div class="topic-metadata">

**Author:** [@Dan\_Fielder](https://discuss.elastic.co/u/Dan_Fielder)\
**Replies:** 0\
**Last updated:** [September 14, 2022, 3:43pm UTC](https://discuss.elastic.co/t/using-mutate-to-parse-broken-json/314436 "2022-09-14T15:43:09Z")

</div>

I have messages arriving with very large blocks of broken JSON. These logs fail to parse when they arrive, so I'm using Filebeat to read from logstash-plain.log and feed them back in for extra processing. Each log cont…

---

## [TSVB Kibana data representation](https://discuss.elastic.co/t/tsvb-kibana-data-representation/311712)

<div class="topic-metadata">

**Author:** [@PRASHANT\_MEHTA](https://discuss.elastic.co/u/PRASHANT_MEHTA)\
**Replies:** 4\
**Last updated:** [September 14, 2022, 3:38pm UTC](https://discuss.elastic.co/t/tsvb-kibana-data-representation/311712 "2022-09-14T15:38:34Z")

</div>

Hello All, Can someone help me with making timeseries visual for below use case: Display the amount value for different state coming from backend script and show in accordance to time. Qsearch index updated,nodes trav…

---

## [ES 6.4.2 - MapperParsingException when performing Bulk requests](https://discuss.elastic.co/t/es-6-4-2-mapperparsingexception-when-performing-bulk-requests/314057)

<div class="topic-metadata">

**Author:** [@JPS\_23](https://discuss.elastic.co/u/JPS_23)\
**Replies:** 3\
**Last updated:** [September 14, 2022, 1:54pm UTC](https://discuss.elastic.co/t/es-6-4-2-mapperparsingexception-when-performing-bulk-requests/314057 "2022-09-14T13:54:40Z")

</div>

Hi! I have been experiencing a MapperParsingException when performing Bulk requests on the Elastic Search 6.4.2 instance. This issue is happening on all the environments (development, qa, production). The weird thing is…

---

## [Kibana v7.16.1 login issue. Not able to login (ResponseError: version\_conflict\_engine\_exception)](https://discuss.elastic.co/t/kibana-v7-16-1-login-issue-not-able-to-login-responseerror-version-conflict-engine-exception/308670)

<div class="topic-metadata">

**Author:** [@Avinash\_09](https://discuss.elastic.co/u/Avinash_09)\
**Replies:** 35\
**Last updated:** [September 14, 2022, 1:22pm UTC](https://discuss.elastic.co/t/kibana-v7-16-1-login-issue-not-able-to-login-responseerror-version-conflict-engine-exception/308670 "2022-09-14T13:22:29Z")

</div>

Hello, We are on v7.16.1 of Kibana/Elastic and facing issues with Kibana login all of a sudden. It was working fine around couple of hours back When checked in the logs seeing below exceptions. {"type":"log","@times…

---

## [UDP Listener Died](https://discuss.elastic.co/t/udp-listener-died/314339)

<div class="topic-metadata">

**Author:** [@Technolust](https://discuss.elastic.co/u/Technolust)\
**Replies:** 2\
**Last updated:** [September 14, 2022, 12:37pm UTC](https://discuss.elastic.co/t/udp-listener-died/314339 "2022-09-14T12:37:51Z")

</div>

I'm seeing this error in my logstash-plain.log file and I ham not sure where to start looking: \[2022-09-13T17:25:47,905\]\[ERROR\]\[logstash.inputs.udp \]\[main\]\[8a46caaeb3cca4377e6163891fd9b8dd48405025c4a31918ce883ba824…

---

## [Restrict Concurrent Users getting same results for same search creiteria](https://discuss.elastic.co/t/restrict-concurrent-users-getting-same-results-for-same-search-creiteria/314373)

<div class="topic-metadata">

**Author:** [@anish\_a\_nair](https://discuss.elastic.co/u/anish_a_nair)\
**Replies:** 5\
**Last updated:** [September 14, 2022, 12:18pm UTC](https://discuss.elastic.co/t/restrict-concurrent-users-getting-same-results-for-same-search-creiteria/314373 "2022-09-14T12:18:56Z")

</div>

Hi, I have requirement to restrict the concurrent users viewing same results if they use same search criteria. The example of my use case is listed below let's assume i have below numbers in a field called "Numbers" 8…

---

## [Get a private key from http\_ca.crt](https://discuss.elastic.co/t/get-a-private-key-from-http-ca-crt/314408)

<div class="topic-metadata">

**Author:** [@elkuser1234](https://discuss.elastic.co/u/elkuser1234)\
**Replies:** 0\
**Last updated:** [September 14, 2022, 12:18pm UTC](https://discuss.elastic.co/t/get-a-private-key-from-http-ca-crt/314408 "2022-09-14T12:18:31Z")

</div>

Hi How i can get a private key from /etc/elasticsearch/certs/http\_ca.crt file ? I need that key to create cert for logstash ./bin/elasticsearch-certutil cert --name logstash --ca-cert /etc/elasticsearch/certs/http\_ca…

---

## [Elastic search response capped to 10k records](https://discuss.elastic.co/t/elastic-search-response-capped-to-10k-records/314192)

<div class="topic-metadata">

**Author:** [@Deepanshu\_Rai](https://discuss.elastic.co/u/Deepanshu_Rai)\
**Replies:** 4\
**Last updated:** [September 14, 2022, 12:07pm UTC](https://discuss.elastic.co/t/elastic-search-response-capped-to-10k-records/314192 "2022-09-14T12:07:16Z")

</div>

I am trying to query my index which has more then 500k records but i am only able to extract 10k records at a time. now i understand this has to do with performance of the application but how can i do bulk extract? with…

---

## [Help for my first open source contribution](https://discuss.elastic.co/t/help-for-my-first-open-source-contribution/314322)

<div class="topic-metadata">

**Author:** [@Akshay\_Bhadange](https://discuss.elastic.co/u/Akshay_Bhadange)\
**Replies:** 2\
**Last updated:** [September 14, 2022, 12:03pm UTC](https://discuss.elastic.co/t/help-for-my-first-open-source-contribution/314322 "2022-09-14T12:03:02Z")

</div>

I want to contribute to this project so i just want to know is my laptop specs sufficient enough for running this project and its a windows machine Specs: Os : windows 10 Ram : 8 gb Ssd : 120 Thanks in advance , lo…

---

## [Difference b/w Normal DBs vs Elasticsearch](https://discuss.elastic.co/t/difference-b-w-normal-dbs-vs-elasticsearch/314207)

<div class="topic-metadata">

**Author:** [@Karan\_Koya](https://discuss.elastic.co/u/Karan_Koya)\
**Replies:** 8\
**Last updated:** [September 14, 2022, 10:27am UTC](https://discuss.elastic.co/t/difference-b-w-normal-dbs-vs-elasticsearch/314207 "2022-09-14T10:27:45Z")

</div>

I have recently started exploring Elastic Stack and came across your Beginner's series which has solved many doubts about Elasticsearch but I am still not sure why we not use Database and prefer Elasticsearch, and why/ho…

---

## [Preprocessing of alerts to be send using httppost](https://discuss.elastic.co/t/preprocessing-of-alerts-to-be-send-using-httppost/313627)

<div class="topic-metadata">

**Author:** [@Pratik1](https://discuss.elastic.co/u/Pratik1)\
**Replies:** 2\
**Last updated:** [September 14, 2022, 10:25am UTC](https://discuss.elastic.co/t/preprocessing-of-alerts-to-be-send-using-httppost/313627 "2022-09-14T10:25:30Z")

</div>

I am using a tool called Kapacitor to send alerts using httppost method to elasticsearch. However, in one list I am getting both time and value column with datatypes date and float respectively. This is causing exceptio…

---

## [Split single object in array to multiple?](https://discuss.elastic.co/t/split-single-object-in-array-to-multiple/314392)

<div class="topic-metadata">

**Author:** [@Hamza\_Khalid](https://discuss.elastic.co/u/Hamza_Khalid)\
**Replies:** 0\
**Last updated:** [September 14, 2022, 9:37am UTC](https://discuss.elastic.co/t/split-single-object-in-array-to-multiple/314392 "2022-09-14T09:37:36Z")

</div>

I'm using logstash to index data from mysql to elasticsearch. Is there a way to convert this output: "interests" : \[ { "interest\_id" : "1,2", "interest\_name" : "Business,Farming" } \] To this: "interests" : \[ { …

---

## [Hot/warm architecture](https://discuss.elastic.co/t/hot-warm-architecture/314382)

<div class="topic-metadata">

**Author:** [@yuswanul](https://discuss.elastic.co/u/yuswanul)\
**Replies:** 2\
**Last updated:** [September 14, 2022, 8:52am UTC](https://discuss.elastic.co/t/hot-warm-architecture/314382 "2022-09-14T08:52:47Z")

</div>

Hi there, I'd like to ask. if an index enters a warm state, can it still perform write operations? i read this blog but didn't found the information i need Thanks

---

## [No exception lists found](https://discuss.elastic.co/t/no-exception-lists-found/312089)

<div class="topic-metadata">

**Author:** [@radovan](https://discuss.elastic.co/u/radovan)\
**Replies:** 16\
**Last updated:** [September 14, 2022, 8:48am UTC](https://discuss.elastic.co/t/no-exception-lists-found/312089 "2022-09-14T08:48:25Z")

</div>

Hi, in our default space I get a message saying "No exception lists found" and "We weren't able to find any exception lists." when I get into Exceptions in Security app even tho there are some exceptions (you can even s…

---

## [Unable to Join New node to existing cluster](https://discuss.elastic.co/t/unable-to-join-new-node-to-existing-cluster/314353)

<div class="topic-metadata">

**Author:** [@hiruni.insyncit.net](https://discuss.elastic.co/u/hiruni.insyncit.net)\
**Replies:** 5\
**Last updated:** [September 14, 2022, 7:15am UTC](https://discuss.elastic.co/t/unable-to-join-new-node-to-existing-cluster/314353 "2022-09-14T07:15:39Z")

</div>

Hi, I'm using Elasticsearch 8.4 version. I was able to install Elasticsearch and Kibana. Then I tried to install on 2nd node. I followed the steps in https://www.elastic.co/guide/en/elasticsearch/reference/current/rp…

[Previous page](https://discuss.elastic.co/tag/none.md?no_tags=true&page=536)

[Next page](https://discuss.elastic.co/tag/none.md?no_tags=true&page=538)
