# \#none

**URL:** https://discuss.elastic.co/tag/none.md?no_tags=true&page=542

[Latest](https://discuss.elastic.co/latest.md) · [Categories](https://discuss.elastic.co/categories.md) · [Tags](https://discuss.elastic.co/tags.md)

**Page:** 543

---

## [Closing index and memory missing warning?](https://discuss.elastic.co/t/closing-index-and-memory-missing-warning/313993)

<div class="topic-metadata">

**Author:** [@ewolfman](https://discuss.elastic.co/u/ewolfman)\
**Replies:** 2\
**Last updated:** [September 8, 2022, 2:14pm UTC](https://discuss.elastic.co/t/closing-index-and-memory-missing-warning/313993 "2022-09-08T14:14:23Z")

</div>

Continuing the discussion from Does close index free up disk or memory: Maybe this warning about losing data ("To reduce the risk of data loss..." Open / Close Index API | Elasticsearch Guide \[6.8\] | Elastic) from 6.8 d…

---

## [Kibana - does not highlight search results](https://discuss.elastic.co/t/kibana-does-not-highlight-search-results/312806)

<div class="topic-metadata">

**Author:** [@elkuser1234](https://discuss.elastic.co/u/elkuser1234)\
**Replies:** 1\
**Last updated:** [September 8, 2022, 1:29pm UTC](https://discuss.elastic.co/t/kibana-does-not-highlight-search-results/312806 "2022-09-08T13:29:26Z")

</div>

Hello I don't understand why when searching through kibana, it doesn't highlight the result for the log\_message field. "log\_message" is the parsed "message" field, by grok. I can only assume that the kibana is not …

---

## [Logstash: filter unique key documents](https://discuss.elastic.co/t/logstash-filter-unique-key-documents/313880)

<div class="topic-metadata">

**Author:** [@Moshe\_Sharon1](https://discuss.elastic.co/u/Moshe_Sharon1)\
**Replies:** 4\
**Last updated:** [September 8, 2022, 1:08pm UTC](https://discuss.elastic.co/t/logstash-filter-unique-key-documents/313880 "2022-09-08T13:08:37Z")

</div>

Hello, We have an index which has multiple documents with the same phone number. Each document will always contain the phone number and may contain additional information (see example below) The documents are written …

---

## [Server Side Rendering](https://discuss.elastic.co/t/server-side-rendering/313863)

<div class="topic-metadata">

**Author:** [@FilFil](https://discuss.elastic.co/u/FilFil)\
**Replies:** 2\
**Last updated:** [September 8, 2022, 1:08pm UTC](https://discuss.elastic.co/t/server-side-rendering/313863 "2022-09-08T13:08:10Z")

</div>

Hi there. is SSR currently supported in Search UI?

---

## [How to get the value in aggregations in watcher](https://discuss.elastic.co/t/how-to-get-the-value-in-aggregations-in-watcher/313526)

<div class="topic-metadata">

**Author:** [@upreddy](https://discuss.elastic.co/u/upreddy)\
**Replies:** 1\
**Last updated:** [September 8, 2022, 1:04pm UTC](https://discuss.elastic.co/t/how-to-get-the-value-in-aggregations-in-watcher/313526 "2022-09-08T13:04:31Z")

</div>

Hi, we are trying to create a new watcher for getting total value in perticular field for that which value is select in aggregations. "aggs": { "abc": { "filter": { "term": { "field": "abc" in abc place we need di…

---

## [Logstash delay](https://discuss.elastic.co/t/logstash-delay/313991)

<div class="topic-metadata">

**Author:** [@tom.verbeek](https://discuss.elastic.co/u/tom.verbeek)\
**Replies:** 2\
**Last updated:** [September 8, 2022, 1:03pm UTC](https://discuss.elastic.co/t/logstash-delay/313991 "2022-09-08T13:03:31Z")

</div>

Hi, I have a problem with logs being ingested into elastic with a delay. This delay does not start from the beginning but it builds up. Right now the delay is 1 day and 10 hours. We checked the Source device sending th…

---

## [I am looking to add some custom data to the date sent using Elastic Agents](https://discuss.elastic.co/t/i-am-looking-to-add-some-custom-data-to-the-date-sent-using-elastic-agents/313995)

<div class="topic-metadata">

**Author:** [@Garry](https://discuss.elastic.co/u/Garry)\
**Replies:** 0\
**Last updated:** [September 8, 2022, 12:59pm UTC](https://discuss.elastic.co/t/i-am-looking-to-add-some-custom-data-to-the-date-sent-using-elastic-agents/313995 "2022-09-08T12:59:36Z")

</div>

Hi, I am am looking to add some custom data through the integrations used by elastic agents. For example, when I manually use metricbeat I can send through static custom fields using processors: add\_host\_metadata: ~ a…

---

## [Is it possible to join field via conditions?](https://discuss.elastic.co/t/is-it-possible-to-join-field-via-conditions/313952)

<div class="topic-metadata">

**Author:** [@Stanislau\_Karaliou](https://discuss.elastic.co/u/Stanislau_Karaliou)\
**Replies:** 4\
**Last updated:** [September 8, 2022, 12:26pm UTC](https://discuss.elastic.co/t/is-it-possible-to-join-field-via-conditions/313952 "2022-09-08T12:26:59Z")

</div>

I have structure { id: 1 name: "Root folder" parent\_id: 0, inherit\_folder\_id: null, inherit\_permission: false, permissions: \[some permissions\] }, { id: 2 name: "Accounts" parent\_id: 1, inherit\_folder…

---

## [Scroll query with slice](https://discuss.elastic.co/t/scroll-query-with-slice/313331)

<div class="topic-metadata">

**Author:** [@philkpler](https://discuss.elastic.co/u/philkpler)\
**Replies:** 1\
**Last updated:** [September 8, 2022, 12:23pm UTC](https://discuss.elastic.co/t/scroll-query-with-slice/313331 "2022-09-08T12:23:45Z")

</div>

Hello, Can someone confirm me that when querying using the scroll api, with slices, it will be targeting the same "state/snapshot" of the index ? As far as I know, to simplify, scroll allow to "freeze" a state of the …

---

## [Kibana, canvas, Image reveal problem after upgrade to 8.4.1 from 8.3.1](https://discuss.elastic.co/t/kibana-canvas-image-reveal-problem-after-upgrade-to-8-4-1-from-8-3-1/313986)

<div class="topic-metadata">

**Author:** [@Ibrahim\_Z\_HIDIR](https://discuss.elastic.co/u/Ibrahim_Z_HIDIR)\
**Replies:** 0\
**Last updated:** [September 8, 2022, 11:15am UTC](https://discuss.elastic.co/t/kibana-canvas-image-reveal-problem-after-upgrade-to-8-4-1-from-8-3-1/313986 "2022-09-08T11:15:30Z")

</div>

Hi I've just upgraded elastic clsuter from 8.3.1 to 8.4.1 and also kibana. After upgrade kibana all the Image reveal images turned exclamation mark, and when I've click on an image I'am getting error "Expression failed …

---

## [Cluster elasticsearch port](https://discuss.elastic.co/t/cluster-elasticsearch-port/313866)

<div class="topic-metadata">

**Author:** [@diegz](https://discuss.elastic.co/u/diegz)\
**Replies:** 6\
**Last updated:** [September 8, 2022, 11:00am UTC](https://discuss.elastic.co/t/cluster-elasticsearch-port/313866 "2022-09-08T11:00:57Z")

</div>

Hello, I want to set up a 3-node elasticsearch cluster in production. 2 nodes master & data and one voting-only or data. I would like to know if I can assign a single port per node and not a range. For example : node…

---

## [Unable to split the logs using child pipeline](https://discuss.elastic.co/t/unable-to-split-the-logs-using-child-pipeline/313944)

<div class="topic-metadata">

**Author:** [@Abinayaganesan](https://discuss.elastic.co/u/Abinayaganesan)\
**Replies:** 0\
**Last updated:** [September 8, 2022, 5:31am UTC](https://discuss.elastic.co/t/unable-to-split-the-logs-using-child-pipeline/313944 "2022-09-08T05:31:23Z")

</div>

Hi I can get all application logs in kibana dashboard. But I want to split the logs using log.file.path and send that respective logs to child pipeline that's why I tried conditions like if (\[log\]\[file\]\[path\] == \["/var…

---

## [How load balancing work between logstash and elasticsearch](https://discuss.elastic.co/t/how-load-balancing-work-between-logstash-and-elasticsearch/313821)

<div class="topic-metadata">

**Author:** [@Khaled\_Saidi](https://discuss.elastic.co/u/Khaled_Saidi)\
**Replies:** 8\
**Last updated:** [September 8, 2022, 10:51am UTC](https://discuss.elastic.co/t/how-load-balancing-work-between-logstash-and-elasticsearch/313821 "2022-09-08T10:51:14Z")

</div>

Hi everyone, I have a question about logstash and how it load balances to an elasticsearch servers cluster. The warning "high disk watermark \[90%\] exceeded" is displayed in the logstash log file, and documents are no l…

---

## [ElasticSearch IIS time-taken Field is Missing](https://discuss.elastic.co/t/elasticsearch-iis-time-taken-field-is-missing/313118)

<div class="topic-metadata">

**Author:** [@eagles40cnuh](https://discuss.elastic.co/u/eagles40cnuh)\
**Replies:** 2\
**Last updated:** [September 8, 2022, 10:50am UTC](https://discuss.elastic.co/t/elasticsearch-iis-time-taken-field-is-missing/313118 "2022-09-08T10:50:58Z")

</div>

My ELK Version 8.3 (Elasticsearch, Kibana, ElasticAgent, Beats....) ElasticAgent installed my Server Host (Complete) ALL IIS LogField Enabled Data collection was successful But.... Just 1 Field(Time-Taken) do…

---

## [About Voting Only Nodes](https://discuss.elastic.co/t/about-voting-only-nodes/313948)

<div class="topic-metadata">

**Author:** [@dawiro](https://discuss.elastic.co/u/dawiro)\
**Replies:** 9\
**Last updated:** [September 8, 2022, 10:47am UTC](https://discuss.elastic.co/t/about-voting-only-nodes/313948 "2022-09-08T10:47:44Z")

</div>

Hi, With voting configurations is it recommended that, when needed, a minimum of nodes are voting-only? Or is it legitimate to make all nodes voting-only? I ask because we have clusters whose topologies vary. For examp…

---

## [Authentication of \[elastic\] was terminated by realm \[reserved\] - failed to authenticate user \[elastic\]](https://discuss.elastic.co/t/authentication-of-elastic-was-terminated-by-realm-reserved-failed-to-authenticate-user-elastic/313838)

<div class="topic-metadata">

**Author:** [@hiruni.insyncit.net](https://discuss.elastic.co/u/hiruni.insyncit.net)\
**Replies:** 10\
**Last updated:** [September 8, 2022, 10:15am UTC](https://discuss.elastic.co/t/authentication-of-elastic-was-terminated-by-realm-reserved-failed-to-authenticate-user-elastic/313838 "2022-09-08T10:15:28Z")

</div>

I have elastic cluster, one node removed(automatically) from the cluster and log shows "Authentication of \[elastic\] was terminated by realm \[reserved\] - failed to authenticate user \[elastic\]" elastic version 8.1

---

## [How to use cardinality add more fields](https://discuss.elastic.co/t/how-to-use-cardinality-add-more-fields/313967)

<div class="topic-metadata">

**Author:** [@githup-DK](https://discuss.elastic.co/u/githup-DK)\
**Replies:** 0\
**Last updated:** [September 8, 2022, 8:50am UTC](https://discuss.elastic.co/t/how-to-use-cardinality-add-more-fields/313967 "2022-09-08T08:50:45Z")

</div>

Hi bro I can't upgrade my instance. my instance is 7.9.3. I want to use three field to search .I create a table with three cardinality \`fields\` ,but there is no effective,the data looks like repeated GET /testPrefor…

---

## [Elasticsearch index.blocks.read : true doesn't work with index pattern](https://discuss.elastic.co/t/elasticsearch-index-blocks-read-true-doesnt-work-with-index-pattern/313963)

<div class="topic-metadata">

**Author:** [@Ingram\_Gultom](https://discuss.elastic.co/u/Ingram_Gultom)\
**Replies:** 1\
**Last updated:** [September 8, 2022, 9:26am UTC](https://discuss.elastic.co/t/elasticsearch-index-blocks-read-true-doesnt-work-with-index-pattern/313963 "2022-09-08T09:26:59Z")

</div>

Hi all, I want to block read on some indices, using index.blocks.read : true, but it doesn't work if you try to read the indices with index pattern like index\_name\_\*. It will return error GET filebeat\*/\_search { "e…

---

## [Is it expected to have different versions in the \`\*\_LuceneXX\_X.\*\` filenames?](https://discuss.elastic.co/t/is-it-expected-to-have-different-versions-in-the-lucenexx-x-filenames/313898)

<div class="topic-metadata">

**Author:** [@vkatsikaros](https://discuss.elastic.co/u/vkatsikaros)\
**Replies:** 2\
**Last updated:** [September 8, 2022, 9:26am UTC](https://discuss.elastic.co/t/is-it-expected-to-have-different-versions-in-the-lucenexx-x-filenames/313898 "2022-09-08T09:26:29Z")

</div>

Hi This is mostly out of curiosity and not as a question tied to a specific problem. I was looking at the actual directories and files of some ES indices, I noticed a bunch of lucene files, but what got my attention is…

---

## [How to remove duplicates on 7.9.3Version](https://discuss.elastic.co/t/how-to-remove-duplicates-on-7-9-3version/313964)

<div class="topic-metadata">

**Author:** [@githup-DK](https://discuss.elastic.co/u/githup-DK)\
**Replies:** 0\
**Last updated:** [September 8, 2022, 8:31am UTC](https://discuss.elastic.co/t/how-to-remove-duplicates-on-7-9-3version/313964 "2022-09-08T08:31:54Z")

</div>

I want to use multi-field to remove duplicates datas,I gave it a try , but it didn't work . \* I want to know how to use it on 7.9.3Version. please help me . GET /test\_2022\_9/\_search { "query": { "bool": { "f…

---

## [Stop Token Filter Language Customization Not Working in Java](https://discuss.elastic.co/t/stop-token-filter-language-customization-not-working-in-java/313949)

<div class="topic-metadata">

**Author:** [@green12](https://discuss.elastic.co/u/green12)\
**Replies:** 0\
**Last updated:** [September 8, 2022, 6:34am UTC](https://discuss.elastic.co/t/stop-token-filter-language-customization-not-working-in-java/313949 "2022-09-08T06:34:05Z")

</div>

Hi everyone, I'm trying to create a customized Indonesian language stop token filter using the Java package. The following json is how the configuration looks like when using curl (which works just fine): "filter": { …

---

## [How do I update data across indexes](https://discuss.elastic.co/t/how-do-i-update-data-across-indexes/313945)

<div class="topic-metadata">

**Author:** [@chihao9332](https://discuss.elastic.co/u/chihao9332)\
**Replies:** 0\
**Last updated:** [September 8, 2022, 6:11am UTC](https://discuss.elastic.co/t/how-do-i-update-data-across-indexes/313945 "2022-09-08T06:11:11Z")

</div>

问题描述：索引B中新增加了两个字段，现需要从索引A中获取这两个字段的值并赋值给B 详细情况： 1.索引A中部分字段：pro\_id, tran\_id, app\_id, type ....... 2.索引B中部分字段：app\_id, type ....... 3. 现 索引B中新增 pro\_id和tran\_id字段，要求将存量数据与索引A中数据同步 4. 即：当 满足 A.app\_id=B.app\_id 和 A.type=B.ty…

---

## [What is the best way to change the dims for a dense\_vector in an index?](https://discuss.elastic.co/t/what-is-the-best-way-to-change-the-dims-for-a-dense-vector-in-an-index/313920)

<div class="topic-metadata">

**Author:** [@reisner](https://discuss.elastic.co/u/reisner)\
**Replies:** 1\
**Last updated:** [September 8, 2022, 4:01am UTC](https://discuss.elastic.co/t/what-is-the-best-way-to-change-the-dims-for-a-dense-vector-in-an-index/313920 "2022-09-08T04:01:18Z")

</div>

I have an index with a dense\_vector field with 256 dimensions. I want to change to a new embedding model that uses a different number of dimensions. I dont mind losing the data in the old field. What's the best way to ke…

---

## [Elasticsearch Super Slow and using low CPU](https://discuss.elastic.co/t/elasticsearch-super-slow-and-using-low-cpu/313922)

<div class="topic-metadata">

**Author:** [@abr4xc](https://discuss.elastic.co/u/abr4xc)\
**Replies:** 5\
**Last updated:** [September 8, 2022, 1:23am UTC](https://discuss.elastic.co/t/elasticsearch-super-slow-and-using-low-cpu/313922 "2022-09-08T01:23:48Z")

</div>

After gone offline for a day the elastic cluster started to be too slow, check of possible misconfigurations and could not fine anything to make it faster, the cluster is on green and there is not unassing shards, howeve…

---

## [How to list users that uses Elasticsearch/Kibana?](https://discuss.elastic.co/t/how-to-list-users-that-uses-elasticsearch-kibana/313934)

<div class="topic-metadata">

**Author:** [@Ggarcia](https://discuss.elastic.co/u/Ggarcia)\
**Replies:** 1\
**Last updated:** [September 8, 2022, 1:03am UTC](https://discuss.elastic.co/t/how-to-list-users-that-uses-elasticsearch-kibana/313934 "2022-09-08T01:03:53Z")

</div>

All, I am working in a project to try replace Splunk by ELK. I would like to list the users that logged in Elasticsearch/Kibana per day. Is there any internal index to audit users? Thank you in advanced, Gerson Garci…

---

## [Does Elastic Agent supports Kafka as an Input?](https://discuss.elastic.co/t/does-elastic-agent-supports-kafka-as-an-input/312290)

<div class="topic-metadata">

**Author:** [@leandrojmp](https://discuss.elastic.co/u/leandrojmp)\
**Replies:** 1\
**Last updated:** [September 7, 2022, 10:15pm UTC](https://discuss.elastic.co/t/does-elastic-agent-supports-kafka-as-an-input/312290 "2022-09-07T22:15:45Z")

</div>

Hello, We are thinking in migrate some of our ingestion from Logstash to the integrations of Elastic Agent, but while researching the documentation of the Elastic Agent we were not able to find anything about using Kafk…

---

## [JSON parse error, Could not set field 'ip' on object '\<hostname\>.\<domain\>.com' to value '10.XXX.XX.XX'.This is probably due to trying to set a field like \[foo\]\[bar\] = someValuewhen \[foo\] is not either a map or a string"](https://discuss.elastic.co/t/json-parse-error-could-not-set-field-ip-on-object-hostname-domain-com-to-value-10-xxx-xx-xx-this-is-probably-due-to-trying-to-set-a-field-like-foo-bar-somevaluewhen-foo-is-not-either-a-map-or-a-string/313928)

<div class="topic-metadata">

**Author:** [@Enzo\_baker](https://discuss.elastic.co/u/Enzo_baker)\
**Replies:** 0\
**Last updated:** [September 7, 2022, 9:41pm UTC](https://discuss.elastic.co/t/json-parse-error-could-not-set-field-ip-on-object-hostname-domain-com-to-value-10-xxx-xx-xx-this-is-probably-due-to-trying-to-set-a-field-like-foo-bar-somevaluewhen-foo-is-not-either-a-map-or-a-string/313928 "2022-09-07T21:41:51Z")

</div>

Hi, Error message - JSON parse error, Could not set field 'ip' on object '\<hostname\>.\<domain\>.com' to value '10.XXX.XX.XX'.This is probably due to trying to set a field like \[foo\]\[bar\] = someValuewhen \[foo\] is not eit…

---

## [Can't collect the logs of cisco router](https://discuss.elastic.co/t/cant-collect-the-logs-of-cisco-router/312318)

<div class="topic-metadata">

**Author:** [@morad\_della3](https://discuss.elastic.co/u/morad_della3)\
**Replies:** 13\
**Last updated:** [September 7, 2022, 8:47pm UTC](https://discuss.elastic.co/t/cant-collect-the-logs-of-cisco-router/312318 "2022-09-07T20:47:34Z")

</div>

this is my lab and i want to collect my router logs with syslog to filebeat installed in the same server of elasticsearch i follow this steps but i don't receive the logs my elastic server is a ubuntu server 22.04 , m…

---

## [Rule That Alerts When Logins Are Past a Certain Time](https://discuss.elastic.co/t/rule-that-alerts-when-logins-are-past-a-certain-time/311887)

<div class="topic-metadata">

**Author:** [@Jared9922](https://discuss.elastic.co/u/Jared9922)\
**Replies:** 1\
**Last updated:** [September 7, 2022, 7:45pm UTC](https://discuss.elastic.co/t/rule-that-alerts-when-logins-are-past-a-certain-time/311887 "2022-09-07T19:45:11Z")

</div>

I am trying to write a rule in Kibana that alerts when somebody logs in anytime after 7 PM and before 7 AM. I am trying to do this with a "Custom query" because this seems like the easiest approach. I have elastic agent …

---

## [Writing rules in KQL from a created index pattern](https://discuss.elastic.co/t/writing-rules-in-kql-from-a-created-index-pattern/312517)

<div class="topic-metadata">

**Author:** [@Didi\_Lilou](https://discuss.elastic.co/u/Didi_Lilou)\
**Replies:** 1\
**Last updated:** [September 7, 2022, 7:35pm UTC](https://discuss.elastic.co/t/writing-rules-in-kql-from-a-created-index-pattern/312517 "2022-09-07T19:35:24Z")

</div>

\#elastic-stack:logstash. Hello. I created an index pattern coming from snort in json format. I used logstash to create it But now i would like to write rules (xpack is activated) in kql coming from my snort index patt…

[Previous page](https://discuss.elastic.co/tag/none.md?no_tags=true&page=541)

[Next page](https://discuss.elastic.co/tag/none.md?no_tags=true&page=543)
