# \#none

**URL:** https://discuss.elastic.co/tag/none.md?no_tags=true&page=541

[Latest](https://discuss.elastic.co/latest.md) · [Categories](https://discuss.elastic.co/categories.md) · [Tags](https://discuss.elastic.co/tags.md)

**Page:** 542

---

## [Need to frequently change url-timestamp value within logstash input](https://discuss.elastic.co/t/need-to-frequently-change-url-timestamp-value-within-logstash-input/314026)

<div class="topic-metadata">

**Author:** [@Pukar](https://discuss.elastic.co/u/Pukar)\
**Replies:** 3\
**Last updated:** [September 9, 2022, 3:56pm UTC](https://discuss.elastic.co/t/need-to-frequently-change-url-timestamp-value-within-logstash-input/314026 "2022-09-09T15:56:39Z")

</div>

Hi, I'm parsing some json data from a website using rest api with start\_timestamp of 4 hours before current time period. Is there a way within logstash to write such code to get data from last 4 hours on every runtime o…

---

## [Watcher license does not allow action execution](https://discuss.elastic.co/t/watcher-license-does-not-allow-action-execution/312615)

<div class="topic-metadata">

**Author:** [@Nina\_Nikolaeva](https://discuss.elastic.co/u/Nina_Nikolaeva)\
**Replies:** 1\
**Last updated:** [September 9, 2022, 3:47pm UTC](https://discuss.elastic.co/t/watcher-license-does-not-allow-action-execution/312615 "2022-09-09T15:47:22Z")

</div>

Hello, my company is using a few environments with trial license and we are negotiating to sign a contract with you for a higher tier. We have configured some watchers (6), 5 of them work ok, however one of them gives t…

---

## [Multiple syslog messages in one event](https://discuss.elastic.co/t/multiple-syslog-messages-in-one-event/314071)

<div class="topic-metadata">

**Author:** [@simpleman](https://discuss.elastic.co/u/simpleman)\
**Replies:** 0\
**Last updated:** [September 9, 2022, 3:09pm UTC](https://discuss.elastic.co/t/multiple-syslog-messages-in-one-event/314071 "2022-09-09T15:09:41Z")

</div>

I am trying to send logs from Symantec Endpoint Protection to Logstash using syslog. Unfortunately, Beats is not an option for our setup. So I have SEP send syslogs over tcp at port 50000. At the moment, I simply print t…

---

## [Performance degradation in 7.16.3 when compared to 5.6.9](https://discuss.elastic.co/t/performance-degradation-in-7-16-3-when-compared-to-5-6-9/314070)

<div class="topic-metadata">

**Author:** [@chaitu0292](https://discuss.elastic.co/u/chaitu0292)\
**Replies:** 0\
**Last updated:** [September 9, 2022, 3:08pm UTC](https://discuss.elastic.co/t/performance-degradation-in-7-16-3-when-compared-to-5-6-9/314070 "2022-09-09T15:08:42Z")

</div>

Observed performance degradation in 7.16.3 when compared to 5.6.9 Run ES\_version AVG(ms) Max(ms) 1 7.16.3 294 913 2 7.16.3 434 1038 1 5.6.9 83 619 2 5.6.9 107 …

---

## [\_bulk\_create / index-pattern / saved object name](https://discuss.elastic.co/t/bulk-create-index-pattern-saved-object-name/314066)

<div class="topic-metadata">

**Author:** [@orcema](https://discuss.elastic.co/u/orcema)\
**Replies:** 0\
**Last updated:** [September 9, 2022, 2:31pm UTC](https://discuss.elastic.co/t/bulk-create-index-pattern-saved-object-name/314066 "2022-09-09T14:31:57Z")

</div>

According to \_bulk\_create example here i have to specify an id and a title as an attribute. The created object has as name and index-pattern the value of the title from the request. How can i setup a different n…

---

## [Question about email notification alert](https://discuss.elastic.co/t/question-about-email-notification-alert/314044)

<div class="topic-metadata">

**Author:** [@morad\_della3](https://discuss.elastic.co/u/morad_della3)\
**Replies:** 8\
**Last updated:** [September 9, 2022, 2:30pm UTC](https://discuss.elastic.co/t/question-about-email-notification-alert/314044 "2022-09-09T14:30:53Z")

</div>

does elasticsearch SIEM email notification alert is free in the current version of elastic stack 8.4.1 ?? I heard that this tool is gold or somethinglike that i don't know more about it. or i will use elasticalert?

---

## [Time Difference between two logs](https://discuss.elastic.co/t/time-difference-between-two-logs/314028)

<div class="topic-metadata">

**Author:** [@Anil\_Alapati](https://discuss.elastic.co/u/Anil_Alapati)\
**Replies:** 6\
**Last updated:** [September 9, 2022, 1:11pm UTC](https://discuss.elastic.co/t/time-difference-between-two-logs/314028 "2022-09-09T13:11:05Z")

</div>

I have two logs. log1 is the start of the process and log2 is the end of the process. How can I get the time taken to complete the process. that is the difference between log2 and log 1. And also I have log3 , now how …

---

## [File transfer error from logstash to elasticsearch](https://discuss.elastic.co/t/file-transfer-error-from-logstash-to-elasticsearch/313950)

<div class="topic-metadata">

**Author:** [@Sagar\_Shrestha](https://discuss.elastic.co/u/Sagar_Shrestha)\
**Replies:** 9\
**Last updated:** [September 9, 2022, 12:54pm UTC](https://discuss.elastic.co/t/file-transfer-error-from-logstash-to-elasticsearch/313950 "2022-09-09T12:54:41Z")

</div>

In my windows machine. My Logstash is working fine as administrator. When I input any raw data in the console (when input is stdin { } ) it is indexed into the Elasticsearch. But when any file format document is executed…

---

## [Logstash to logstash](https://discuss.elastic.co/t/logstash-to-logstash/314051)

<div class="topic-metadata">

**Author:** [@alaine](https://discuss.elastic.co/u/alaine)\
**Replies:** 1\
**Last updated:** [September 9, 2022, 11:59am UTC](https://discuss.elastic.co/t/logstash-to-logstash/314051 "2022-09-09T11:59:20Z")

</div>

Hello, I am trying to add another output to some of our logstashes to output beats data to another logstash. I am attempting to use the lumberjack protocol and have been following the elastic documentation to do so. I h…

---

## [How to send only error logs path from filebeat to logstash](https://discuss.elastic.co/t/how-to-send-only-error-logs-path-from-filebeat-to-logstash/314050)

<div class="topic-metadata">

**Author:** [@poojitha0812](https://discuss.elastic.co/u/poojitha0812)\
**Replies:** 0\
**Last updated:** [September 9, 2022, 10:55am UTC](https://discuss.elastic.co/t/how-to-send-only-error-logs-path-from-filebeat-to-logstash/314050 "2022-09-09T10:55:07Z")

</div>

Hi , I am able to send logs from filebeat to logstash but i enabled logging level and given path to save under /var/log/filebeat to save the error files . filebeat is connected to logstash and now i am want logstash to …

---

## [Refer highlight fields in webhook message](https://discuss.elastic.co/t/refer-highlight-fields-in-webhook-message/314049)

<div class="topic-metadata">

**Author:** [@Ananya\_Chowdhury](https://discuss.elastic.co/u/Ananya_Chowdhury)\
**Replies:** 0\
**Last updated:** [September 9, 2022, 10:28am UTC](https://discuss.elastic.co/t/refer-highlight-fields-in-webhook-message/314049 "2022-09-09T10:28:43Z")

</div>

In my elastic query where i have highlight fields as shortmessage to custom the length of short message and i want to refere that in webhook message. But when i am referring under contexthits as highlight.short\_message i…

---

## [Elasticsearch script weak at handle string change while use for loop?](https://discuss.elastic.co/t/elasticsearch-script-weak-at-handle-string-change-while-use-for-loop/313936)

<div class="topic-metadata">

**Author:** [@robocon20x](https://discuss.elastic.co/u/robocon20x)\
**Replies:** 4\
**Last updated:** [September 9, 2022, 10:26am UTC](https://discuss.elastic.co/t/elasticsearch-script-weak-at-handle-string-change-while-use-for-loop/313936 "2022-09-09T10:26:19Z")

</div>

Elasticsearch really weak at handle string change. i have a script like this def newSegment; if(params.data !=null){ for (entry in params.data.entrySet()){ if (entry.getValue() != null) { ctx.\_source\[entry.g…

---

## [Kibana visualizations changed to No result found when select one visualization from dashboard](https://discuss.elastic.co/t/kibana-visualizations-changed-to-no-result-found-when-select-one-visualization-from-dashboard/312582)

<div class="topic-metadata">

**Author:** [@Mary2022](https://discuss.elastic.co/u/Mary2022)\
**Replies:** 2\
**Last updated:** [September 9, 2022, 9:17am UTC](https://discuss.elastic.co/t/kibana-visualizations-changed-to-no-result-found-when-select-one-visualization-from-dashboard/312582 "2022-09-09T09:17:41Z")

</div>

I am running Kibana 7.17.1. I created a dashboard in kibana with multiple visualizations on it. I noticed that when I select/click on one of the visualizations the other ones changed to "No results found". How can I st…

---

## [Force merge is taking long time](https://discuss.elastic.co/t/force-merge-is-taking-long-time/312574)

<div class="topic-metadata">

**Author:** [@prasath\_s](https://discuss.elastic.co/u/prasath_s)\
**Replies:** 6\
**Last updated:** [September 9, 2022, 8:14am UTC](https://discuss.elastic.co/t/force-merge-is-taking-long-time/312574 "2022-09-09T08:14:21Z")

</div>

After migrating from elastic version 5.2 to 7.16.2 force merge for few indices are taking long time. These indices are around 120GB. In the force merge step we are making total segement as 1. Any help here

---

## [ELK ingress with multiple subdomains not working with certmanager http01 letsencrypt validation](https://discuss.elastic.co/t/elk-ingress-with-multiple-subdomains-not-working-with-certmanager-http01-letsencrypt-validation/314036)

<div class="topic-metadata">

**Author:** [@agonzalez](https://discuss.elastic.co/u/agonzalez)\
**Replies:** 0\
**Last updated:** [September 9, 2022, 7:56am UTC](https://discuss.elastic.co/t/elk-ingress-with-multiple-subdomains-not-working-with-certmanager-http01-letsencrypt-validation/314036 "2022-09-09T07:56:38Z")

</div>

I am deploying my app and ELK using ECK in AKS. When i deploy i autocreate letsencrypt certs using certmanager, the certs for my apps are created succesfully but the certs to access kibana and elasticsearch on the ingres…

---

## [UDP input codec](https://discuss.elastic.co/t/udp-input-codec/313740)

<div class="topic-metadata">

**Author:** [@Laurent\_DEGEN](https://discuss.elastic.co/u/Laurent_DEGEN)\
**Replies:** 7\
**Last updated:** [September 9, 2022, 7:48am UTC](https://discuss.elastic.co/t/udp-input-codec/313740 "2022-09-09T07:48:54Z")

</div>

Hi, I have an NB-IOT sensor that outputs UDP packets containing some data. I used the default UDP input plugin and default plain codec but It does not decode the packet's UDP payload the way I want it to (headers work …

---

## [Unable to configure Elastic , Kibana tool in new environment](https://discuss.elastic.co/t/unable-to-configure-elastic-kibana-tool-in-new-environment/313938)

<div class="topic-metadata">

**Author:** [@Infratech](https://discuss.elastic.co/u/Infratech)\
**Replies:** 10\
**Last updated:** [September 9, 2022, 7:37am UTC](https://discuss.elastic.co/t/unable-to-configure-elastic-kibana-tool-in-new-environment/313938 "2022-09-09T07:37:14Z")

</div>

I have logged in but showing below error. I have already assigned Admin, PowerUser role to user.. Please look in to this….

---

## [Logstash process killed and as a result the ingestion stopped](https://discuss.elastic.co/t/logstash-process-killed-and-as-a-result-the-ingestion-stopped/314032)

<div class="topic-metadata">

**Author:** [@stillfreem](https://discuss.elastic.co/u/stillfreem)\
**Replies:** 0\
**Last updated:** [September 9, 2022, 6:59am UTC](https://discuss.elastic.co/t/logstash-process-killed-and-as-a-result-the-ingestion-stopped/314032 "2022-09-09T06:59:14Z")

</div>

Hi All, I had a perfectly fine working configuration of Logstash. I colleague of mine tried to troubleshoote and killed the Logstash process thought. After Logstash restarted the ingestion stopped and in the log file …

---

## [Logstash create plugin tutorial](https://discuss.elastic.co/t/logstash-create-plugin-tutorial/314031)

<div class="topic-metadata">

**Author:** [@Laurent\_DEGEN](https://discuss.elastic.co/u/Laurent_DEGEN)\
**Replies:** 0\
**Last updated:** [September 9, 2022, 5:31am UTC](https://discuss.elastic.co/t/logstash-create-plugin-tutorial/314031 "2022-09-09T05:31:31Z")

</div>

Hi, I'am looking for good/updated ressources to learn how to create a codec-plugin. I have tried to follow this one : How to write a Logstash codec plugin | Logstash Reference \[8.4\] | Elastic ( I used the plugin genera…

---

## [Elastic Log data transfer in remote server](https://discuss.elastic.co/t/elastic-log-data-transfer-in-remote-server/314029)

<div class="topic-metadata">

**Author:** [@saifulshihab](https://discuss.elastic.co/u/saifulshihab)\
**Replies:** 0\
**Last updated:** [September 9, 2022, 4:06am UTC](https://discuss.elastic.co/t/elastic-log-data-transfer-in-remote-server/314029 "2022-09-09T04:06:49Z")

</div>

I have 3 node cluster all three node have same configuration node.master: true node.data: true so now my storage i filled up almost 800GB. I want to transfer some data for future reference from the path : /var/lib/el…

---

## [When access to enterprise search it automatically redirect to kibana](https://discuss.elastic.co/t/when-access-to-enterprise-search-it-automatically-redirect-to-kibana/313656)

<div class="topic-metadata">

**Author:** [@MaralErdene\_Tumursuh](https://discuss.elastic.co/u/MaralErdene_Tumursuh)\
**Replies:** 3\
**Last updated:** [September 9, 2022, 3:57am UTC](https://discuss.elastic.co/t/when-access-to-enterprise-search-it-automatically-redirect-to-kibana/313656 "2022-09-09T03:57:45Z")

</div>

Hello, I installed enterprise search on premise. Then access to http://my\_ip:3002 it redirect to kibana. My kibana installed another server. Is there any config i missed? My enterprise-search.yml has below config. a…

---

## [Health agent but no data sent to fleet server / elasticsearch?](https://discuss.elastic.co/t/health-agent-but-no-data-sent-to-fleet-server-elasticsearch/313559)

<div class="topic-metadata">

**Author:** [@smm](https://discuss.elastic.co/u/smm)\
**Replies:** 1\
**Last updated:** [September 9, 2022, 3:56am UTC](https://discuss.elastic.co/t/health-agent-but-no-data-sent-to-fleet-server-elasticsearch/313559 "2022-09-09T03:56:07Z")

</div>

Hi there, I am running an all-in-one node with elasticsearch, kibana, logstash all 7.17.4 and fleet running. I have 2 agents. One on the this all-in-one node. The other installes to a second, empy ubuntu VM - just to co…

---

## [Unable to export Kibana dashboard using API](https://discuss.elastic.co/t/unable-to-export-kibana-dashboard-using-api/313941)

<div class="topic-metadata">

**Author:** [@rt\_888](https://discuss.elastic.co/u/rt_888)\
**Replies:** 13\
**Last updated:** [September 9, 2022, 3:26am UTC](https://discuss.elastic.co/t/unable-to-export-kibana-dashboard-using-api/313941 "2022-09-09T03:26:49Z")

</div>

// curl -X POST “http://localhost:5601/api/saved\_objects/\_export” -H ‘kbn-xsrf: true’ -H ‘Content-Type: application/json’ -d’ { “type”: “index-pattern” } ‘ I use this as to export my dashboard but i get the error "Incor…

---

## [Issue with selecting date fields from the \`jdbc\_streaming\` \`filter\` plugin](https://discuss.elastic.co/t/issue-with-selecting-date-fields-from-the-jdbc-streaming-filter-plugin/314023)

<div class="topic-metadata">

**Author:** [@nkumarcc](https://discuss.elastic.co/u/nkumarcc)\
**Replies:** 0\
**Last updated:** [September 8, 2022, 10:39pm UTC](https://discuss.elastic.co/t/issue-with-selecting-date-fields-from-the-jdbc-streaming-filter-plugin/314023 "2022-09-08T22:39:34Z")

</div>

I have a nested field in my Elasticsearch mapping which holds an array of objects. We wanted to add this array to records via a jdbc\_streaming filter. However, 2 of the fields we query for are timestamp fields, which cau…

---

## [Add Elastic Agent tags to log events](https://discuss.elastic.co/t/add-elastic-agent-tags-to-log-events/312737)

<div class="topic-metadata">

**Author:** [@DougR](https://discuss.elastic.co/u/DougR)\
**Replies:** 7\
**Last updated:** [September 8, 2022, 7:58pm UTC](https://discuss.elastic.co/t/add-elastic-agent-tags-to-log-events/312737 "2022-09-08T19:58:53Z")

</div>

Is there a way to append the Elastic Agent tags to the event, or at least to log events? My use case is that I designate agents by application environment (e.g., dev/qa/stage/prod), and would like that tag to be availabl…

---

## [Strigo lab has ended but haven't finished the course](https://discuss.elastic.co/t/strigo-lab-has-ended-but-havent-finished-the-course/314012)

<div class="topic-metadata">

**Author:** [@jbalandranocoro-goda](https://discuss.elastic.co/u/jbalandranocoro-goda)\
**Replies:** 1\
**Last updated:** [September 8, 2022, 7:04pm UTC](https://discuss.elastic.co/t/strigo-lab-has-ended-but-havent-finished-the-course/314012 "2022-09-08T19:04:42Z")

</div>

Hi, I'm trying to finish a course in elasticsearch training but when I go to the strigo lab it says "this course has ended" and I have no way to restart it. Can anyone help me with this? Thanks1

---

## [Logstash remove N/A field](https://discuss.elastic.co/t/logstash-remove-n-a-field/314002)

<div class="topic-metadata">

**Author:** [@mleg](https://discuss.elastic.co/u/mleg)\
**Replies:** 1\
**Last updated:** [September 8, 2022, 6:29pm UTC](https://discuss.elastic.co/t/logstash-remove-n-a-field/314002 "2022-09-08T18:29:11Z")

</div>

I am trying to remove all the fields which have N/A next to the them like "toto: N/A", I am currently removing them with a enormous IF forest which I have hard coded but I would like a better alternative, to an enormous …

---

## [Redirecting stdout to /dev/null](https://discuss.elastic.co/t/redirecting-stdout-to-dev-null/313973)

<div class="topic-metadata">

**Author:** [@jatindavey](https://discuss.elastic.co/u/jatindavey)\
**Replies:** 2\
**Last updated:** [September 8, 2022, 6:02pm UTC](https://discuss.elastic.co/t/redirecting-stdout-to-dev-null/313973 "2022-09-08T18:02:57Z")

</div>

Hi I am not sure if this has already been discussed in the forums but i could not find a definitive help in this regard. Basically when i run logstash as a systemd service , whenever logstash gets log files for process…

---

## [Create visualization table horizontally aligned](https://discuss.elastic.co/t/create-visualization-table-horizontally-aligned/313529)

<div class="topic-metadata">

**Author:** [@Alice\_Ionescu](https://discuss.elastic.co/u/Alice_Ionescu)\
**Replies:** 1\
**Last updated:** [September 8, 2022, 5:56pm UTC](https://discuss.elastic.co/t/create-visualization-table-horizontally-aligned/313529 "2022-09-08T17:56:11Z")

</div>

Hello, Is there a possibility to create a new visualization to look like this: ||column\_name ||column\_value|| ||column\_name ||column\_value|| And display information only on a row from an index. Thanks!

---

## [Field missing when select Top Hit on Y-axis for bar chart](https://discuss.elastic.co/t/field-missing-when-select-top-hit-on-y-axis-for-bar-chart/313442)

<div class="topic-metadata">

**Author:** [@siwapong.cha](https://discuss.elastic.co/u/siwapong.cha)\
**Replies:** 3\
**Last updated:** [September 8, 2022, 2:22pm UTC](https://discuss.elastic.co/t/field-missing-when-select-top-hit-on-y-axis-for-bar-chart/313442 "2022-09-08T14:22:44Z")

</div>

Hi all, I'm trying to use Top Hit on my bar chart but many fields are missing from the field selection. Below are my custom field which came from filebeat (ansible.xxxxxx) Here when I selected Top Hit, all my ansi…

[Previous page](https://discuss.elastic.co/tag/none.md?no_tags=true&page=540)

[Next page](https://discuss.elastic.co/tag/none.md?no_tags=true&page=542)
