# \#none

**URL:** https://discuss.elastic.co/tag/none.md?no_tags=true&page=538

[Latest](https://discuss.elastic.co/latest.md) · [Categories](https://discuss.elastic.co/categories.md) · [Tags](https://discuss.elastic.co/tags.md)

**Page:** 539

---

## [Unable to start Elastic.service 'setting \[cluster.initial\_master\_nodes\] is not allowed when \[discovery.type\] is set to \[single-node\]'](https://discuss.elastic.co/t/unable-to-start-elastic-service-setting-cluster-initial-master-nodes-is-not-allowed-when-discovery-type-is-set-to-single-node/314375)

<div class="topic-metadata">

**Author:** [@Neophyte](https://discuss.elastic.co/u/Neophyte)\
**Replies:** 2\
**Last updated:** [September 14, 2022, 6:59am UTC](https://discuss.elastic.co/t/unable-to-start-elastic-service-setting-cluster-initial-master-nodes-is-not-allowed-when-discovery-type-is-set-to-single-node/314375 "2022-09-14T06:59:35Z")

</div>

I am trying to set up a SIEM HOME LAB environment and install the latest Elastic and kibana on Ubuntu, but the service is not starting up, and am receiving the following errors: messi@fifa:~/Desktop$ sudo systemctl rest…

---

## [Transform Mapping Errors](https://discuss.elastic.co/t/transform-mapping-errors/313382)

<div class="topic-metadata">

**Author:** [@bm11100](https://discuss.elastic.co/u/bm11100)\
**Replies:** 12\
**Last updated:** [September 14, 2022, 6:57am UTC](https://discuss.elastic.co/t/transform-mapping-errors/313382 "2022-09-14T06:57:51Z")

</div>

Hello, I've set up a transform to aggregate on process.name, however it continues to fail exactly on the same date with the following error - Failed to index documents into destination index due to permanent error: \[or…

---

## [Upgrading Elastic Stack from 7.7.0 to 7.17.6](https://discuss.elastic.co/t/upgrading-elastic-stack-from-7-7-0-to-7-17-6/314224)

<div class="topic-metadata">

**Author:** [@ozonshak](https://discuss.elastic.co/u/ozonshak)\
**Replies:** 3\
**Last updated:** [September 14, 2022, 6:27am UTC](https://discuss.elastic.co/t/upgrading-elastic-stack-from-7-7-0-to-7-17-6/314224 "2022-09-14T06:27:24Z")

</div>

Hello. It has been over 2 years since I last installed the Elastic stack locally in our environment (Kibana, Elasticsearch, Logstash, FileBeat). The version we are on right now is 7.7.0 for all products. I'm not sure …

---

## [How to avoid double indexing when using rollover indice](https://discuss.elastic.co/t/how-to-avoid-double-indexing-when-using-rollover-indice/314366)

<div class="topic-metadata">

**Author:** [@PRASHANT\_MEHTA](https://discuss.elastic.co/u/PRASHANT_MEHTA)\
**Replies:** 7\
**Last updated:** [September 14, 2022, 6:18am UTC](https://discuss.elastic.co/t/how-to-avoid-double-indexing-when-using-rollover-indice/314366 "2022-09-14T06:18:52Z")

</div>

Hello All, I'm using the rollover feature for my indices on daily basis along with doc\_as\_upsert,to maintain unique documents only.The rollover Index gets deleted after 30 days. I can see the issue of double indexing,E…

---

## [Filter http - delete by query doesn't work](https://discuss.elastic.co/t/filter-http-delete-by-query-doesnt-work/314371)

<div class="topic-metadata">

**Author:** [@Ely\_96](https://discuss.elastic.co/u/Ely_96)\
**Replies:** 0\
**Last updated:** [September 14, 2022, 6:18am UTC](https://discuss.elastic.co/t/filter-http-delete-by-query-doesnt-work/314371 "2022-09-14T06:18:22Z")

</div>

Hi guys, in my pipeline, filter section I use the http plugin in order to remove old data: http { url =\> "http://localhost:9200/test-main/\_delete\_by\_query" verb =\> "POST" body\_format =\> …

---

## [Selective deletion of indices](https://discuss.elastic.co/t/selective-deletion-of-indices/314370)

<div class="topic-metadata">

**Author:** [@newbie2022](https://discuss.elastic.co/u/newbie2022)\
**Replies:** 1\
**Last updated:** [September 14, 2022, 6:13am UTC](https://discuss.elastic.co/t/selective-deletion-of-indices/314370 "2022-09-14T06:13:42Z")

</div>

I have a ruby web app with a search function that is enabled by Elasticsearch. There are 2 types of content Content A which should be searchable indefinitely Content B which is time-sensitive and no longer relevant af…

---

## [How to convert dates to months format](https://discuss.elastic.co/t/how-to-convert-dates-to-months-format/314252)

<div class="topic-metadata">

**Author:** [@Ritikapawar](https://discuss.elastic.co/u/Ritikapawar)\
**Replies:** 2\
**Last updated:** [September 14, 2022, 6:07am UTC](https://discuss.elastic.co/t/how-to-convert-dates-to-months-format/314252 "2022-09-14T06:07:09Z")

</div>

Hi I've data in this format "Admission \_date" : "2020-01-28", "id" : 78 when I visualize the data in this format I get results like this X axis : admission date Y axis : count of records I want the mon…

---

## [Logstash unable to start and collect logs](https://discuss.elastic.co/t/logstash-unable-to-start-and-collect-logs/314296)

<div class="topic-metadata">

**Author:** [@khanchand](https://discuss.elastic.co/u/khanchand)\
**Replies:** 10\
**Last updated:** [September 14, 2022, 5:24am UTC](https://discuss.elastic.co/t/logstash-unable-to-start-and-collect-logs/314296 "2022-09-14T05:24:15Z")

</div>

Hi I have configure Elasticsearch, kibana & logstash on same machine. Want to receive firewall logs in logstash but facing below error. For now want to show these event on console only once received will forward in elast…

---

## [Unassigned shards on data-streams indices following upgrade to 7.17.5](https://discuss.elastic.co/t/unassigned-shards-on-data-streams-indices-following-upgrade-to-7-17-5/314130)

<div class="topic-metadata">

**Author:** [@nadler](https://discuss.elastic.co/u/nadler)\
**Replies:** 5\
**Last updated:** [September 14, 2022, 5:08am UTC](https://discuss.elastic.co/t/unassigned-shards-on-data-streams-indices-following-upgrade-to-7-17-5/314130 "2022-09-14T05:08:42Z")

</div>

Hey, Recently i have upgraded a few of our clusters from 7.12.0 to 7.17.5. After the upgrade two indices were created: .ds-.logs-deprecation.elasticsearch-default-2022.09.07-000001 and .ds-ilm-history-5-2022.09.07-000…

---

## [Can I display search box and search results in separate React components](https://discuss.elastic.co/t/can-i-display-search-box-and-search-results-in-separate-react-components/314364)

<div class="topic-metadata">

**Author:** [@Sheng111](https://discuss.elastic.co/u/Sheng111)\
**Replies:** 0\
**Last updated:** [September 14, 2022, 5:04am UTC](https://discuss.elastic.co/t/can-i-display-search-box-and-search-results-in-separate-react-components/314364 "2022-09-14T05:04:32Z")

</div>

I am thinking to create a search box with Elastic search UI library, my requirements are display search box in header of all the website, but search results will display in a different React components as a part of the p…

---

## [Kibana cannot connect to the Elastic Package Registry, which provides Elastic Agent integrations](https://discuss.elastic.co/t/kibana-cannot-connect-to-the-elastic-package-registry-which-provides-elastic-agent-integrations/314107)

<div class="topic-metadata">

**Author:** [@Sher\_Khan](https://discuss.elastic.co/u/Sher_Khan)\
**Replies:** 8\
**Last updated:** [September 14, 2022, 4:37am UTC](https://discuss.elastic.co/t/kibana-cannot-connect-to-the-elastic-package-registry-which-provides-elastic-agent-integrations/314107 "2022-09-14T04:37:54Z")

</div>

How to resolve this issue?

---

## [Threat detection EQL error](https://discuss.elastic.co/t/threat-detection-eql-error/314250)

<div class="topic-metadata">

**Author:** [@zhixiang\_hao](https://discuss.elastic.co/u/zhixiang_hao)\
**Replies:** 2\
**Last updated:** [September 14, 2022, 1:19am UTC](https://discuss.elastic.co/t/threat-detection-eql-error/314250 "2022-09-14T01:19:33Z")

</div>

Does anyone know what's causing it?

---

## [Sending events from specific ip adress to specific index](https://discuss.elastic.co/t/sending-events-from-specific-ip-adress-to-specific-index/314344)

<div class="topic-metadata">

**Author:** [@wmulobole1](https://discuss.elastic.co/u/wmulobole1)\
**Replies:** 1\
**Last updated:** [September 13, 2022, 11:36pm UTC](https://discuss.elastic.co/t/sending-events-from-specific-ip-adress-to-specific-index/314344 "2022-09-13T23:36:16Z")

</div>

Hi, I am trying to separate my indexes by ip address. I want logs coming from three particular ips to go a specific index and the rest to go another index. I am not successful because the index is not showing up in Kiban…

---

## [Can I change the locations to local infra for the monitor using Project monitors to Synthetic monitoring](https://discuss.elastic.co/t/can-i-change-the-locations-to-local-infra-for-the-monitor-using-project-monitors-to-synthetic-monitoring/312398)

<div class="topic-metadata">

**Author:** [@odelacruzc](https://discuss.elastic.co/u/odelacruzc)\
**Replies:** 4\
**Last updated:** [September 13, 2022, 9:03pm UTC](https://discuss.elastic.co/t/can-i-change-the-locations-to-local-infra-for-the-monitor-using-project-monitors-to-synthetic-monitoring/312398 "2022-09-13T21:03:07Z")

</div>

Can I change the locations to local infra for the monitor using Project monitors to Synthetic monitoring? In the future, we don't have any cost about that we will use the private infra elastic.

---

## [Urgent : How to get the IOPS logs from Windows Server 2003](https://discuss.elastic.co/t/urgent-how-to-get-the-iops-logs-from-windows-server-2003/314335)

<div class="topic-metadata">

**Author:** [@zaheernew](https://discuss.elastic.co/u/zaheernew)\
**Replies:** 1\
**Last updated:** [September 13, 2022, 8:10pm UTC](https://discuss.elastic.co/t/urgent-how-to-get-the-iops-logs-from-windows-server-2003/314335 "2022-09-13T20:10:13Z")

</div>

Hi Community, I'm new to the community and I need an urgent support. I have a windows server 2003 R2 based couple of DB servers. My questions is how can I collect the IOPS log and monitor via Kibana interface. Note: …

---

## [Data Analysis with Kibana On-Demand: Lab1.1 Machine Learning and Graph not available](https://discuss.elastic.co/t/data-analysis-with-kibana-on-demand-lab1-1-machine-learning-and-graph-not-available/314329)

<div class="topic-metadata">

**Author:** [@mpb9010](https://discuss.elastic.co/u/mpb9010)\
**Replies:** 0\
**Last updated:** [September 13, 2022, 6:31pm UTC](https://discuss.elastic.co/t/data-analysis-with-kibana-on-demand-lab1-1-machine-learning-and-graph-not-available/314329 "2022-09-13T18:31:32Z")

</div>

I am following the instructions on Lab 1.1 step 10 and Machine Learning (ML) and Graph are not an option in the drop down, I have removed the sample data and re-added it, refreshed and it’s still not working, I am not ab…

---

## [Need to know ways of controlling the write to storage account for event hub access](https://discuss.elastic.co/t/need-to-know-ways-of-controlling-the-write-to-storage-account-for-event-hub-access/313551)

<div class="topic-metadata">

**Author:** [@karthik\_Ravichandran](https://discuss.elastic.co/u/karthik_Ravichandran)\
**Replies:** 17\
**Last updated:** [September 13, 2022, 6:00pm UTC](https://discuss.elastic.co/t/need-to-know-ways-of-controlling-the-write-to-storage-account-for-event-hub-access/313551 "2022-09-13T18:00:41Z")

</div>

I am having azure event hub as input logstash code , please advise how can i controlling events the write to storage account for event Hub Acess , this method will help in cost saving. please advise your thoughts

---

## [Elasticsearch Installation 8.4](https://discuss.elastic.co/t/elasticsearch-installation-8-4/313601)

<div class="topic-metadata">

**Author:** [@Ankita\_Pachauri](https://discuss.elastic.co/u/Ankita_Pachauri)\
**Replies:** 9\
**Last updated:** [September 13, 2022, 5:42pm UTC](https://discuss.elastic.co/t/elasticsearch-installation-8-4/313601 "2022-09-13T17:42:19Z")

</div>

Hi Team, I am trying to install elasticsearch-8.4 version on a centos vm. The steps i followed are: Java Installation Creating a repo file Install Elasticsearch Start ES Note: i have not made any changes in yml file.…

---

## [Pause between events ingested in elasticsearch](https://discuss.elastic.co/t/pause-between-events-ingested-in-elasticsearch/314025)

<div class="topic-metadata">

**Author:** [@RaonyO](https://discuss.elastic.co/u/RaonyO)\
**Replies:** 13\
**Last updated:** [September 13, 2022, 5:22pm UTC](https://discuss.elastic.co/t/pause-between-events-ingested-in-elasticsearch/314025 "2022-09-13T17:22:54Z")

</div>

hello, I would like to know if it is possible, and if there is any filter that can put a time between events before sending them to elastic, for example: I have logs in elastic that are being ingested in the same second,…

---

## [Elasticsearch 6.8.23 on Oracle Linux 8](https://discuss.elastic.co/t/elasticsearch-6-8-23-on-oracle-linux-8/314313)

<div class="topic-metadata">

**Author:** [@spincity57](https://discuss.elastic.co/u/spincity57)\
**Replies:** 1\
**Last updated:** [September 13, 2022, 3:58pm UTC](https://discuss.elastic.co/t/elasticsearch-6-8-23-on-oracle-linux-8/314313 "2022-09-13T15:58:30Z")

</div>

Hello, I am trying to install elasticsearch 6.8.23 on Oracle Linux 8. I am using openjdk version "11.0.16.1". I have this error at starting elasticsearch : Caused by: java.lang.IllegalArgumentException: none of the ci…

---

## [Not able to deploy Fleet-managed elastic agent on k8s (quickstart template)](https://discuss.elastic.co/t/not-able-to-deploy-fleet-managed-elastic-agent-on-k8s-quickstart-template/314304)

<div class="topic-metadata">

**Author:** [@Asaf\_balink](https://discuss.elastic.co/u/Asaf_balink)\
**Replies:** 0\
**Last updated:** [September 13, 2022, 2:19pm UTC](https://discuss.elastic.co/t/not-able-to-deploy-fleet-managed-elastic-agent-on-k8s-quickstart-template/314304 "2022-09-13T14:19:59Z")

</div>

Hey, I'm trying to deploy Fleet Server and Elastic Agent on Kubernetes using the quickstart manual: Since I've deployed my stack under a different namespace, all I did was changing the namespace on the provided manife…

---

## [Copy speciifc data to another index automatically](https://discuss.elastic.co/t/copy-speciifc-data-to-another-index-automatically/314300)

<div class="topic-metadata">

**Author:** [@queried1](https://discuss.elastic.co/u/queried1)\
**Replies:** 1\
**Last updated:** [September 13, 2022, 2:00pm UTC](https://discuss.elastic.co/t/copy-speciifc-data-to-another-index-automatically/314300 "2022-09-13T14:00:15Z")

</div>

Hello! Currently I use FIlebeat to send data to Logstash and then to Elasticsearch. There are mostly application logs that contain a lot of data. Everything is sent to an index called filebeat--0000x and is rolled over …

---

## [Could Not Index Event to Elasticsearch Error?](https://discuss.elastic.co/t/could-not-index-event-to-elasticsearch-error/314188)

<div class="topic-metadata">

**Author:** [@Priyanka4](https://discuss.elastic.co/u/Priyanka4)\
**Replies:** 14\
**Last updated:** [September 13, 2022, 12:42pm UTC](https://discuss.elastic.co/t/could-not-index-event-to-elasticsearch-error/314188 "2022-09-13T12:42:43Z")

</div>

message: \[2022-09-12T11:02:46,381\]\[WARN \]\[logstash.outputs.elasticsearch\]\[main\]\[2a206be8e9b0598adfe625bef432d5a7f49b90230ff74f12fb3baf9c5024173f\] Could not index event to Elasticsearch. {:status=\>400, :action=

---

## [Elasticsearch array of an object using logstash](https://discuss.elastic.co/t/elasticsearch-array-of-an-object-using-logstash/314295)

<div class="topic-metadata">

**Author:** [@Hamza\_Khalid](https://discuss.elastic.co/u/Hamza_Khalid)\
**Replies:** 0\
**Last updated:** [September 13, 2022, 12:37pm UTC](https://discuss.elastic.co/t/elasticsearch-array-of-an-object-using-logstash/314295 "2022-09-13T12:37:27Z")

</div>

I have a mysql database working as a primary database and i'm ingesting data into elasticsearch from mysql using logstash. I have successfully indexed the users table into elasticsearch and it is working perfectly fine h…

---

## [S3 input plugin taking really long time to process](https://discuss.elastic.co/t/s3-input-plugin-taking-really-long-time-to-process/313261)

<div class="topic-metadata">

**Author:** [@priyankamondalhcl](https://discuss.elastic.co/u/priyankamondalhcl)\
**Replies:** 4\
**Last updated:** [September 13, 2022, 12:26pm UTC](https://discuss.elastic.co/t/s3-input-plugin-taking-really-long-time-to-process/313261 "2022-09-13T12:26:27Z")

</div>

Hi Team, I am using s3 input plugins to get billing data from aws. There are almost 15-20 files (ending with .csv.gz), each 115-120 MB of size. Now these files are replaced next day with new set of files Logstash conf…

---

## [Logstash not working](https://discuss.elastic.co/t/logstash-not-working/314123)

<div class="topic-metadata">

**Author:** [@sta02](https://discuss.elastic.co/u/sta02)\
**Replies:** 8\
**Last updated:** [September 13, 2022, 12:23pm UTC](https://discuss.elastic.co/t/logstash-not-working/314123 "2022-09-13T12:23:07Z")

</div>

Hello, My logstash instance which is integrated with Azure Sentinel was working well with out any error (All the pipelines were functional, and the events were received at Azure Sentinel). A while ago, I made a couple o…

---

## [Include empty rows not working for date field in Kibana table lens](https://discuss.elastic.co/t/include-empty-rows-not-working-for-date-field-in-kibana-table-lens/313792)

<div class="topic-metadata">

**Author:** [@Jonas\_S](https://discuss.elastic.co/u/Jonas_S)\
**Replies:** 5\
**Last updated:** [September 13, 2022, 11:18am UTC](https://discuss.elastic.co/t/include-empty-rows-not-working-for-date-field-in-kibana-table-lens/313792 "2022-09-13T11:18:44Z")

</div>

Hello, i'm creating ES indices every month where one of the date fields can be empty for all documents from time to time. To make sure that visualizations do not break if this happens i added a mapping for this field to…

---

## [Kibana server is not ready yet](https://discuss.elastic.co/t/kibana-server-is-not-ready-yet/314273)

<div class="topic-metadata">

**Author:** [@khanchand](https://discuss.elastic.co/u/khanchand)\
**Replies:** 10\
**Last updated:** [September 13, 2022, 10:00am UTC](https://discuss.elastic.co/t/kibana-server-is-not-ready-yet/314273 "2022-09-13T10:00:46Z")

</div>

Hi everyone, I am new on Elasticsearch and have created my lab before going to deploy in production. For lab purpose I have deployed all three (elasticsearch, kibana & logstash) on a single centos server. While I am faci…

---

## [Multiple user per index](https://discuss.elastic.co/t/multiple-user-per-index/314278)

<div class="topic-metadata">

**Author:** [@RaiZiStyle](https://discuss.elastic.co/u/RaiZiStyle)\
**Replies:** 0\
**Last updated:** [September 13, 2022, 9:58am UTC](https://discuss.elastic.co/t/multiple-user-per-index/314278 "2022-09-13T09:58:03Z")

</div>

Hey everyone, I'm having kind of an issue with the user, role and space We have multiple application log in ELK, each application as an index template (For example, we have one apache-MM-YYYY, one moodle-MM-YYYY, and s…

---

## [Are replicase required when using external volumes like EBS?](https://discuss.elastic.co/t/are-replicase-required-when-using-external-volumes-like-ebs/314267)

<div class="topic-metadata">

**Author:** [@Thijsvdp](https://discuss.elastic.co/u/Thijsvdp)\
**Replies:** 3\
**Last updated:** [September 13, 2022, 9:26am UTC](https://discuss.elastic.co/t/are-replicase-required-when-using-external-volumes-like-ebs/314267 "2022-09-13T09:26:58Z")

</div>

Hi all, We are currently running our Elasticsearch cluster in Kubernetes and use EBS gp3 volumes as storage. We are reading everywhere that during initial load of the data one could disable replicas to speed up indexing…

[Previous page](https://discuss.elastic.co/tag/none.md?no_tags=true&page=537)

[Next page](https://discuss.elastic.co/tag/none.md?no_tags=true&page=539)
