# \#none

**URL:** https://discuss.elastic.co/tag/none.md?no_tags=true&page=543

[Latest](https://discuss.elastic.co/latest.md) · [Categories](https://discuss.elastic.co/categories.md) · [Tags](https://discuss.elastic.co/tags.md)

**Page:** 544

---

## [Using misp detection](https://discuss.elastic.co/t/using-misp-detection/312830)

<div class="topic-metadata">

**Author:** [@VitorBarroso](https://discuss.elastic.co/u/VitorBarroso)\
**Replies:** 1\
**Last updated:** [September 7, 2022, 7:29pm UTC](https://discuss.elastic.co/t/using-misp-detection/312830 "2022-09-07T19:29:02Z")

</div>

It's possible to use misp on endpoint security? What i need to do is, when i have a detect/prevent event, i need to say is which category of malware is. If this is not possible with misp, any other solution of this?

---

## [Ecommerce site test data](https://discuss.elastic.co/t/ecommerce-site-test-data/313524)

<div class="topic-metadata">

**Author:** [@Gayrat\_Vlasov](https://discuss.elastic.co/u/Gayrat_Vlasov)\
**Replies:** 1\
**Last updated:** [September 7, 2022, 6:53pm UTC](https://discuss.elastic.co/t/ecommerce-site-test-data/313524 "2022-09-07T18:53:15Z")

</div>

In documentation I fond excellent ecommerce example: live: github: I want to repeat this project from scratch: make new App search engines, load test data , configure search Is it possible to get json test data t…

---

## [Jdbc input plugin connection pooling?](https://discuss.elastic.co/t/jdbc-input-plugin-connection-pooling/313915)

<div class="topic-metadata">

**Author:** [@steevhise](https://discuss.elastic.co/u/steevhise)\
**Replies:** 1\
**Last updated:** [September 7, 2022, 6:50pm UTC](https://discuss.elastic.co/t/jdbc-input-plugin-connection-pooling/313915 "2022-09-07T18:50:44Z")

</div>

Is there a way to give logstash jdbc plugin several db servers (all replicas of same master) to connect to? Do you just provide an array of connection strings? or what?

---

## [CSPM for AWS](https://discuss.elastic.co/t/cspm-for-aws/313715)

<div class="topic-metadata">

**Author:** [@keiransteele](https://discuss.elastic.co/u/keiransteele)\
**Replies:** 1\
**Last updated:** [September 7, 2022, 6:05pm UTC](https://discuss.elastic.co/t/cspm-for-aws/313715 "2022-09-07T18:05:08Z")

</div>

Are there plans to have CSPM for AWS rather than just a misleading name and only Kubernetes?

---

## [JSON filter wipes out existing objects in memory](https://discuss.elastic.co/t/json-filter-wipes-out-existing-objects-in-memory/312047)

<div class="topic-metadata">

**Author:** [@juan.domenech](https://discuss.elastic.co/u/juan.domenech)\
**Replies:** 3\
**Last updated:** [September 7, 2022, 5:40pm UTC](https://discuss.elastic.co/t/json-filter-wipes-out-existing-objects-in-memory/312047 "2022-09-07T17:40:45Z")

</div>

I'd like to share this behaviour to find out whether or not is expected or desired. Problem: A field exists in memory (i.e. log.syslog.hostname:ZEUS1 ) A JSON message arrives that includes a sub-field of the existing …

---

## [Aggregation in Ingest Pipeline of Elastic Agent - Custom Logs integration](https://discuss.elastic.co/t/aggregation-in-ingest-pipeline-of-elastic-agent-custom-logs-integration/313910)

<div class="topic-metadata">

**Author:** [@rowra](https://discuss.elastic.co/u/rowra)\
**Replies:** 0\
**Last updated:** [September 7, 2022, 4:56pm UTC](https://discuss.elastic.co/t/aggregation-in-ingest-pipeline-of-elastic-agent-custom-logs-integration/313910 "2022-09-07T16:56:29Z")

</div>

Hey, Currently I have a Logstash pipeline parsing, aggregating and finally delivering Postfix logs to the Elasticsearch. I want to retire Logstash completely and use Fleet to deploy a policy with Custom Logs integration…

---

## [Trace sample logs error KQL](https://discuss.elastic.co/t/trace-sample-logs-error-kql/313703)

<div class="topic-metadata">

**Author:** [@davjl](https://discuss.elastic.co/u/davjl)\
**Replies:** 1\
**Last updated:** [September 6, 2022, 11:38pm UTC](https://discuss.elastic.co/t/trace-sample-logs-error-kql/313703 "2022-09-06T23:38:23Z")

</div>

Hi All, We have recently upgraded our older ELK cluster which was on 7.15.2 to 8.4, We used Log correlation but when upgrade cluster we have the next error When use investigate \> trace logs I have results do i ne…

---

## [Export Transformations Kibana](https://discuss.elastic.co/t/export-transformations-kibana/312708)

<div class="topic-metadata">

**Author:** [@atony](https://discuss.elastic.co/u/atony)\
**Replies:** 1\
**Last updated:** [September 7, 2022, 4:07pm UTC](https://discuss.elastic.co/t/export-transformations-kibana/312708 "2022-09-07T16:07:18Z")

</div>

Hello guys, I would like to export all my dashboards, transformations and new indexes from a Kibana instance to another one. I have found that with saved objects -\> export, I can export all dashboards and related object…

---

## [Output Heap Space Usage for Kibana](https://discuss.elastic.co/t/output-heap-space-usage-for-kibana/313827)

<div class="topic-metadata">

**Author:** [@andreakatie](https://discuss.elastic.co/u/andreakatie)\
**Replies:** 2\
**Last updated:** [September 7, 2022, 3:45pm UTC](https://discuss.elastic.co/t/output-heap-space-usage-for-kibana/313827 "2022-09-07T15:45:25Z")

</div>

Hello all -- I was wondering if there was a way to gather heap space usage data for Kibana (and NGINX) specifically. Using JMeter, I am able to gather real-time heap data usage for the Elasticsearch service, but I have …

---

## [Fail to restore a snapshot of a rollover index without any error message](https://discuss.elastic.co/t/fail-to-restore-a-snapshot-of-a-rollover-index-without-any-error-message/313691)

<div class="topic-metadata">

**Author:** [@rutika\_kamble](https://discuss.elastic.co/u/rutika_kamble)\
**Replies:** 0\
**Last updated:** [September 5, 2022, 1:42pm UTC](https://discuss.elastic.co/t/fail-to-restore-a-snapshot-of-a-rollover-index-without-any-error-message/313691 "2022-09-05T13:42:41Z")

</div>

I have two indices in my setup. marimba-000001 & marimba-000002 with alias marimba. Before applying to ILM I created a policy with rollover action. Then, on the existing template, I added that policy, added an alias, …

---

## [Elasticsearch no longer boots](https://discuss.elastic.co/t/elasticsearch-no-longer-boots/313452)

<div class="topic-metadata">

**Author:** [@dw5304](https://discuss.elastic.co/u/dw5304)\
**Replies:** 10\
**Last updated:** [September 7, 2022, 2:55pm UTC](https://discuss.elastic.co/t/elasticsearch-no-longer-boots/313452 "2022-09-07T14:55:24Z")

</div>

came in this morning to find a non working bootable version of elasticsearch. \[2022-09-01T14:02:06,208\]\[ERROR\]\[o.e.b.Elasticsearch \] \[redacted\] fatal exception while booting Elasticsearch java.lang.IllegalArgumentE…

---

## [Fleet Server - Duplicate key](https://discuss.elastic.co/t/fleet-server-duplicate-key/313896)

<div class="topic-metadata">

**Author:** [@el-jefe3](https://discuss.elastic.co/u/el-jefe3)\
**Replies:** 0\
**Last updated:** [September 7, 2022, 2:31pm UTC](https://discuss.elastic.co/t/fleet-server-duplicate-key/313896 "2022-09-07T14:31:09Z")

</div>

Hello everyone, I recently configured Fleet Server on my stack. During the configuration I selected Production and entered my keys (Wildcard Certificates). These are the same ones I used for transport and have obvious…

---

## [Does FIPS 140-2 Mode Work on Kubernetes?](https://discuss.elastic.co/t/does-fips-140-2-mode-work-on-kubernetes/254417)

<div class="topic-metadata">

**Author:** [@BenB196](https://discuss.elastic.co/u/BenB196)\
**Replies:** 5\
**Last updated:** [September 7, 2022, 2:25pm UTC](https://discuss.elastic.co/t/does-fips-140-2-mode-work-on-kubernetes/254417 "2022-09-07T14:25:06Z")

</div>

Hi All, I was looking into FIPS 140-2 mode support on Kubernetes with Elastic's k8s operator, however, I didn't see any mention of FIPS 140-2 at all within the docs. Is this something that is supported? If it is does it…

---

## [Is it Better to use Elastic UI with other framework?](https://discuss.elastic.co/t/is-it-better-to-use-elastic-ui-with-other-framework/313846)

<div class="topic-metadata">

**Author:** [@Azhar\_Uddin1](https://discuss.elastic.co/u/Azhar_Uddin1)\
**Replies:** 1\
**Last updated:** [September 7, 2022, 1:55pm UTC](https://discuss.elastic.co/t/is-it-better-to-use-elastic-ui-with-other-framework/313846 "2022-09-07T13:55:39Z")

</div>

Can I use Elastic UI with other Technology like Django? or with any other backends it's Says Elastic UI The framework powering the Elastic Stack I have been wondering if I could use it with Django or Node etc

---

## [Options List Control Ignores Filters and Queries](https://discuss.elastic.co/t/options-list-control-ignores-filters-and-queries/308962)

<div class="topic-metadata">

**Author:** [@MakoWish](https://discuss.elastic.co/u/MakoWish)\
**Replies:** 7\
**Last updated:** [September 7, 2022, 1:52pm UTC](https://discuss.elastic.co/t/options-list-control-ignores-filters-and-queries/308962 "2022-09-07T13:52:44Z")

</div>

The Controls visualization has now been available for quite some time, but it is still being noted as a technical preview. Is there any plan to move this to GA? Since it was first introduced, it seems the Options List co…

---

## [Lifecycle delete phase question](https://discuss.elastic.co/t/lifecycle-delete-phase-question/313876)

<div class="topic-metadata">

**Author:** [@artax\_sb](https://discuss.elastic.co/u/artax_sb)\
**Replies:** 3\
**Last updated:** [September 7, 2022, 1:22pm UTC](https://discuss.elastic.co/t/lifecycle-delete-phase-question/313876 "2022-09-07T13:22:11Z")

</div>

Hi all, I want to make a lifecycle policy to my index I want the conditions are delete after 15days or 25gb but in delete phase it only allows me delete after n days not by n gb too Is there some way to make that? (w…

---

## [Inconsistent Term and Terms query resolution in filter context](https://discuss.elastic.co/t/inconsistent-term-and-terms-query-resolution-in-filter-context/313884)

<div class="topic-metadata">

**Author:** [@robertasg](https://discuss.elastic.co/u/robertasg)\
**Replies:** 0\
**Last updated:** [September 7, 2022, 12:45pm UTC](https://discuss.elastic.co/t/inconsistent-term-and-terms-query-resolution-in-filter-context/313884 "2022-09-07T12:45:53Z")

</div>

According to Elasticsearch docs it says that TermsQuery is the same as a TermQuery but can be operate with multiple values. The terms query is the same as the term query, except you can search for multiple values. Ho…

---

## [Monitoring Elastic License On Prometheus](https://discuss.elastic.co/t/monitoring-elastic-license-on-prometheus/313870)

<div class="topic-metadata">

**Author:** [@takshika\_jambhule](https://discuss.elastic.co/u/takshika_jambhule)\
**Replies:** 1\
**Last updated:** [September 7, 2022, 12:34pm UTC](https://discuss.elastic.co/t/monitoring-elastic-license-on-prometheus/313870 "2022-09-07T12:34:50Z")

</div>

I have installed elasticsearch\_exporter on my elastic boxes to set up alerts and monitoring on Prometheus.(GitHub - prometheus-community/elasticsearch\_exporter: Elasticsearch stats exporter for Prometheus) However, elast…

---

## [How to implement query termsAgregation to get the documents for each of the buckets that the query generates. I am using java spring boot](https://discuss.elastic.co/t/how-to-implement-query-termsagregation-to-get-the-documents-for-each-of-the-buckets-that-the-query-generates-i-am-using-java-spring-boot/313883)

<div class="topic-metadata">

**Author:** [@Ernesto\_Rodolfo\_Cast](https://discuss.elastic.co/u/Ernesto_Rodolfo_Cast)\
**Replies:** 0\
**Last updated:** [September 7, 2022, 12:31pm UTC](https://discuss.elastic.co/t/how-to-implement-query-termsagregation-to-get-the-documents-for-each-of-the-buckets-that-the-query-generates-i-am-using-java-spring-boot/313883 "2022-09-07T12:31:05Z")

</div>

Hi, I am trying to get each of the elements that the elasticsearch group by generates. What I get now is the key and the amount of elements for each of the buckets, my interest is to get each of those elements that conta…

---

## [ISSUE WITH INSTALATION KIBANA IN CENTOS](https://discuss.elastic.co/t/issue-with-instalation-kibana-in-centos/312451)

<div class="topic-metadata">

**Author:** [@andres07](https://discuss.elastic.co/u/andres07)\
**Replies:** 1\
**Last updated:** [September 7, 2022, 11:59am UTC](https://discuss.elastic.co/t/issue-with-instalation-kibana-in-centos/312451 "2022-09-07T11:59:23Z")

</div>

Hi, I am trying to install Kibana on a centos server so that I can collect logs from different machines. On my server and installed kibana, elasticsearch and logstash. All these agents are working, but I am not able to…

---

## [Copy paste Kibana settings to multiple clusters](https://discuss.elastic.co/t/copy-paste-kibana-settings-to-multiple-clusters/313464)

<div class="topic-metadata">

**Author:** [@Austin\_ES\_Questions](https://discuss.elastic.co/u/Austin_ES_Questions)\
**Replies:** 1\
**Last updated:** [September 7, 2022, 11:49am UTC](https://discuss.elastic.co/t/copy-paste-kibana-settings-to-multiple-clusters/313464 "2022-09-07T11:49:53Z")

</div>

We are running several elasticsearch/kibana clusters, with some modifications to the "advanced settings" in kibana Is there a way that we can automatically sync/propagate settings from one instance to another, to avoid …

---

## [How can I dynamically create elasticsearch indices using logtsash using jdbc?](https://discuss.elastic.co/t/how-can-i-dynamically-create-elasticsearch-indices-using-logtsash-using-jdbc/313873)

<div class="topic-metadata">

**Author:** [@shantam\_saxena](https://discuss.elastic.co/u/shantam_saxena)\
**Replies:** 0\
**Last updated:** [September 7, 2022, 10:21am UTC](https://discuss.elastic.co/t/how-can-i-dynamically-create-elasticsearch-indices-using-logtsash-using-jdbc/313873 "2022-09-07T10:21:43Z")

</div>

I have a table in snowflake for which I have a target column. The target column has 20 distinct values and will increase with time. My intention is to use logstash to create separate indices for all the unique values in …

---

## [Query regarding scoring of ES8. 2](https://discuss.elastic.co/t/query-regarding-scoring-of-es8-2/312687)

<div class="topic-metadata">

**Author:** [@sajeeda](https://discuss.elastic.co/u/sajeeda)\
**Replies:** 3\
**Last updated:** [September 7, 2022, 9:10am UTC](https://discuss.elastic.co/t/query-regarding-scoring-of-es8-2/312687 "2022-09-07T09:10:54Z")

</div>

Hi All, I am trying to upgrade from ES6.3 to ES8.2. I am new to Elasticsearch and wanted to understand how the scoring is done on text search in both the versions. scores and the result set is all different when compa…

---

## [Find the number of search requests per day hitting ES Cluster](https://discuss.elastic.co/t/find-the-number-of-search-requests-per-day-hitting-es-cluster/313865)

<div class="topic-metadata">

**Author:** [@sandeepkanabar](https://discuss.elastic.co/u/sandeepkanabar)\
**Replies:** 0\
**Last updated:** [September 7, 2022, 8:57am UTC](https://discuss.elastic.co/t/find-the-number-of-search-requests-per-day-hitting-es-cluster/313865 "2022-09-07T08:57:52Z")

</div>

Is there a way to know the (average) number of search requests per day hitting the Elasticsearch cluster? If my ES cluster contains day-wise indices and I want find the no of search requests that hit ES cluster in last …

---

## [Sorting by date in log stream](https://discuss.elastic.co/t/sorting-by-date-in-log-stream/313339)

<div class="topic-metadata">

**Author:** [@conor\_c](https://discuss.elastic.co/u/conor_c)\
**Replies:** 4\
**Last updated:** [September 7, 2022, 8:55am UTC](https://discuss.elastic.co/t/sorting-by-date-in-log-stream/313339 "2022-09-07T08:55:48Z")

</div>

Hi All, I've been searching and searching for a solution, but I've not managed to find any relevant answers. I suspect I am looking in the wrong place or have misunderstood how some of the ELK stack tools are connected. …

---

## [Auto\_expand\_replicas not working on enrich index](https://discuss.elastic.co/t/auto-expand-replicas-not-working-on-enrich-index/313569)

<div class="topic-metadata">

**Author:** [@ddolcimascolo](https://discuss.elastic.co/u/ddolcimascolo)\
**Replies:** 31\
**Last updated:** [September 7, 2022, 8:38am UTC](https://discuss.elastic.co/t/auto-expand-replicas-not-working-on-enrich-index/313569 "2022-09-07T08:38:03Z")

</div>

Hi guys, Our enrich indices are not replicated on our production cluster, and I don't understand why... Can you help to troubleshoot the issue? Context ES 7.17.1 3 Nodes Many various data indices Many ingest pipeline…

---

## [Kibana TSVB to filter out aggregated result](https://discuss.elastic.co/t/kibana-tsvb-to-filter-out-aggregated-result/313859)

<div class="topic-metadata">

**Author:** [@inhinyera16](https://discuss.elastic.co/u/inhinyera16)\
**Replies:** 0\
**Last updated:** [September 7, 2022, 8:01am UTC](https://discuss.elastic.co/t/kibana-tsvb-to-filter-out-aggregated-result/313859 "2022-09-07T08:01:43Z")

</div>

Anyone knows how to filter tsvb aggregated result? In my example below, I used 3 aggregations then grouped by Cluster, to capture the remaining memory % avg (MemoryUsageGB) avg(MemoryTotalGB) bucket script to get the …

---

## [Logstash I/O error](https://discuss.elastic.co/t/logstash-i-o-error/313858)

<div class="topic-metadata">

**Author:** [@Hardy\_Fong](https://discuss.elastic.co/u/Hardy_Fong)\
**Replies:** 0\
**Last updated:** [September 7, 2022, 8:00am UTC](https://discuss.elastic.co/t/logstash-i-o-error/313858 "2022-09-07T08:00:51Z")

</div>

Dear all , I have one elk server collecting all decive syslog, and we found one of fibre switch(DELL DS6610B) have prompt this error in starting logstash. But the weird point is we have 3 fibre switch which are same c…

---

## [Grok pattern - sometimes nesting bracket](https://discuss.elastic.co/t/grok-pattern-sometimes-nesting-bracket/313797)

<div class="topic-metadata">

**Author:** [@elkuser1234](https://discuss.elastic.co/u/elkuser1234)\
**Replies:** 2\
**Last updated:** [September 7, 2022, 6:34am UTC](https://discuss.elastic.co/t/grok-pattern-sometimes-nesting-bracket/313797 "2022-09-07T06:34:08Z")

</div>

Hi I have a difficult log for me. Because sometimes I have nested bracket and sometimes i don't How to parse it in a grok. \[2022-09-05 17:27:24,537\] \[apps-thread | test-policy\] WARN \[2022-09-06 14:19:25,708\] \[App (ap…

---

## [Reverting Index Logging Settings](https://discuss.elastic.co/t/reverting-index-logging-settings/313770)

<div class="topic-metadata">

**Author:** [@nutcno](https://discuss.elastic.co/u/nutcno)\
**Replies:** 1\
**Last updated:** [September 7, 2022, 5:50am UTC](https://discuss.elastic.co/t/reverting-index-logging-settings/313770 "2022-09-07T05:50:15Z")

</div>

I want to add new index settings for all indices to add some additional configs to debug/info/warn and trace. So like below I have this curl command - curl -XPUT 'http://localhost:9200/\_all/\_settings?preserve\_existing=…

[Previous page](https://discuss.elastic.co/tag/none.md?no_tags=true&page=542)

[Next page](https://discuss.elastic.co/tag/none.md?no_tags=true&page=544)
