# \#none

**URL:** https://discuss.elastic.co/tag/none.md?no_tags=true&page=549

[Latest](https://discuss.elastic.co/latest.md) · [Categories](https://discuss.elastic.co/categories.md) · [Tags](https://discuss.elastic.co/tags.md)

**Page:** 550

---

## [Change expected date format for Kibana dashboard add/edit filter dialogue with date field and range operator](https://discuss.elastic.co/t/change-expected-date-format-for-kibana-dashboard-add-edit-filter-dialogue-with-date-field-and-range-operator/313355)

<div class="topic-metadata">

**Author:** [@Jonas\_S](https://discuss.elastic.co/u/Jonas_S)\
**Replies:** 1\
**Last updated:** [August 31, 2022, 12:46pm UTC](https://discuss.elastic.co/t/change-expected-date-format-for-kibana-dashboard-add-edit-filter-dialogue-with-date-field-and-range-operator/313355 "2022-08-31T12:46:05Z")

</div>

Hello, i'm using Kibana 8.2, is it possible to change the date format that Kibana expects within the add/edit filter dialogue within a dashboard for a date field using a range operator? The default expects MM.DD.YYYY, …

---

## [Multiple Labels for same field](https://discuss.elastic.co/t/multiple-labels-for-same-field/313358)

<div class="topic-metadata">

**Author:** [@saif.khan](https://discuss.elastic.co/u/saif.khan)\
**Replies:** 0\
**Last updated:** [August 31, 2022, 12:31pm UTC](https://discuss.elastic.co/t/multiple-labels-for-same-field/313358 "2022-08-31T12:31:45Z")

</div>

Hi, I'm using SNMP-Logstash plugin to get data from SNMP enabled Network devices(PDUs), It works fine to an extent, The issues comes in for a field that has multiple values, example "IP Address " as I have 3 endpoint d…

---

## [Custom id when inserting a document in existing index](https://discuss.elastic.co/t/custom-id-when-inserting-a-document-in-existing-index/313352)

<div class="topic-metadata">

**Author:** [@kibanauser4](https://discuss.elastic.co/u/kibanauser4)\
**Replies:** 2\
**Last updated:** [August 31, 2022, 12:13pm UTC](https://discuss.elastic.co/t/custom-id-when-inserting-a-document-in-existing-index/313352 "2022-08-31T12:13:02Z")

</div>

I am using Dev tools in Kibana to insert a new document in an existing index. But I can't figure out if I can set the \_id field to a custom value. Is there a way to do this? This is what I'm doing now: POST user/\_doc/1…

---

## [ERROR: Failed to determine the health of the cluster](https://discuss.elastic.co/t/error-failed-to-determine-the-health-of-the-cluster/313242)

<div class="topic-metadata">

**Author:** [@morad\_della3](https://discuss.elastic.co/u/morad_della3)\
**Replies:** 1\
**Last updated:** [August 31, 2022, 12:12pm UTC](https://discuss.elastic.co/t/error-failed-to-determine-the-health-of-the-cluster/313242 "2022-08-31T12:12:14Z")

</div>

when i try to create a password to kibana interface i get this problem root@kibana:/home/kibana# /usr/share/elasticsearch/bin/elasticsearch-reset-password -i -u elastic --url http://192.168.43.157:9200 ERROR: Failed t…

---

## [Logstash date filter error](https://discuss.elastic.co/t/logstash-date-filter-error/313253)

<div class="topic-metadata">

**Author:** [@Aniket\_Pant](https://discuss.elastic.co/u/Aniket_Pant)\
**Replies:** 10\
**Last updated:** [August 31, 2022, 12:07pm UTC](https://discuss.elastic.co/t/logstash-date-filter-error/313253 "2022-08-31T12:07:58Z")

</div>

I have this field in my logs event\_time=2022-08-30 17:30:42.000 my logstash pipeline file is filter { if "average\_weight" in \[tags\] { kv { source=\>"message" target =\> "test" field\_split=\>"," } mutate { rename =\> { "\[t…

---

## [Elastic Agent Synthetics integration - How to separate hosts in icmp monitor](https://discuss.elastic.co/t/elastic-agent-synthetics-integration-how-to-separate-hosts-in-icmp-monitor/313354)

<div class="topic-metadata">

**Author:** [@norgro2601](https://discuss.elastic.co/u/norgro2601)\
**Replies:** 0\
**Last updated:** [August 31, 2022, 12:07pm UTC](https://discuss.elastic.co/t/elastic-agent-synthetics-integration-how-to-separate-hosts-in-icmp-monitor/313354 "2022-08-31T12:07:10Z")

</div>

Hi, we want to start using the Synthetics integration to replace Heartbeats, but I'm not sure how to handle icmp monitors for different hosts in a single agent policy. When I setup the integration in the policy with ho…

---

## [How to calculate first pass logic and reren for testcase using logstash grok](https://discuss.elastic.co/t/how-to-calculate-first-pass-logic-and-reren-for-testcase-using-logstash-grok/313089)

<div class="topic-metadata">

**Author:** [@aish794726](https://discuss.elastic.co/u/aish794726)\
**Replies:** 4\
**Last updated:** [August 31, 2022, 11:23am UTC](https://discuss.elastic.co/t/how-to-calculate-first-pass-logic-and-reren-for-testcase-using-logstash-grok/313089 "2022-08-31T11:23:50Z")

</div>

am working on grok, have very few knowledge about it, we are preparing regression dashboard there we need first pass and reren so that system should understand, these script got pass infirst these are fail n might requir…

---

## [SIEM case connector](https://discuss.elastic.co/t/siem-case-connector/312031)

<div class="topic-metadata">

**Author:** [@dlazure](https://discuss.elastic.co/u/dlazure)\
**Replies:** 2\
**Last updated:** [August 31, 2022, 11:19am UTC](https://discuss.elastic.co/t/siem-case-connector/312031 "2022-08-31T11:19:36Z")

</div>

Hi, Is there a way to connect the SIEM cases to TheHive ? Thank you,

---

## [How to add additional timestamp field in an index](https://discuss.elastic.co/t/how-to-add-additional-timestamp-field-in-an-index/313346)

<div class="topic-metadata">

**Author:** [@Aniket\_Pant](https://discuss.elastic.co/u/Aniket_Pant)\
**Replies:** 0\
**Last updated:** [August 31, 2022, 10:38am UTC](https://discuss.elastic.co/t/how-to-add-additional-timestamp-field-in-an-index/313346 "2022-08-31T10:38:25Z")

</div>

pipeline file date { match =\>\["\[event\]\[time\]","YYYY-MM-dd HH:mm:ss.SSS"\] target =\> "time" } however when i do GET my\_index/\_mapping there is no time field , my objective is two have two field one is @timestamp defaul…

---

## [What's the cause of this prob and what's the solution](https://discuss.elastic.co/t/whats-the-cause-of-this-prob-and-whats-the-solution/313086)

<div class="topic-metadata">

**Author:** [@morad\_della3](https://discuss.elastic.co/u/morad_della3)\
**Replies:** 12\
**Last updated:** [August 31, 2022, 10:32am UTC](https://discuss.elastic.co/t/whats-the-cause-of-this-prob-and-whats-the-solution/313086 "2022-08-31T10:32:13Z")

</div>

what's the cause of this prob and what's the solution when i want to create a token for kibana ileged$0(SocketAccess.java:42) ~\[?:?\] at java.security.AccessController.doPrivileged(AccessController.java:569) ~\[?:…

---

## [Plugin imap: get attachment](https://discuss.elastic.co/t/plugin-imap-get-attachment/313342)

<div class="topic-metadata">

**Author:** [@Bepsi](https://discuss.elastic.co/u/Bepsi)\
**Replies:** 0\
**Last updated:** [August 31, 2022, 10:17am UTC](https://discuss.elastic.co/t/plugin-imap-get-attachment/313342 "2022-08-31T10:17:17Z")

</div>

Hi all, With logstash-oss v7.17.6, i want to read a .zip attachment in a mail. I can read the mail itself, but the attachment can not be read. Logstash conf file: input { imap { id =\> "dmarc" host =\> "xxx" …

---

## [Elastic certificates](https://discuss.elastic.co/t/elastic-certificates/313340)

<div class="topic-metadata">

**Author:** [@morad\_della3](https://discuss.elastic.co/u/morad_della3)\
**Replies:** 0\
**Last updated:** [August 31, 2022, 9:55am UTC](https://discuss.elastic.co/t/elastic-certificates/313340 "2022-08-31T09:55:03Z")

</div>

Hello, it's is necessary when i install Elasticsearch and Kibana i should configure the elastic certificates in this doc ici : elasticsearch-certutil | Elasticsearch Guide \[8.4\] | Elastic thanks.

---

## [Elasticsearch disk usage issue](https://discuss.elastic.co/t/elasticsearch-disk-usage-issue/313338)

<div class="topic-metadata">

**Author:** [@xalastoi](https://discuss.elastic.co/u/xalastoi)\
**Replies:** 0\
**Last updated:** [August 31, 2022, 9:39am UTC](https://discuss.elastic.co/t/elasticsearch-disk-usage-issue/313338 "2022-08-31T09:39:36Z")

</div>

Hello! i have a strange issue in my elasticsearch cluster so i have 5 nodes ( 4 data and masters and 1 master only node ) so each node has 5.7 tb disk space on it but on the first node my disk is almost completely ful…

---

## [EQL - Rule creation](https://discuss.elastic.co/t/eql-rule-creation/311732)

<div class="topic-metadata">

**Author:** [@Rahulvanadavsi](https://discuss.elastic.co/u/Rahulvanadavsi)\
**Replies:** 1\
**Last updated:** [August 31, 2022, 9:10am UTC](https://discuss.elastic.co/t/eql-rule-creation/311732 "2022-08-31T09:10:35Z")

</div>

Hi, We would like to create a use case for password spraying attack and Impossible travel activity in our environment. Password Spraying Attack - Attacker tying to bruteforce using default passwords for multiple accou…

---

## [Alert is not populating the right fields](https://discuss.elastic.co/t/alert-is-not-populating-the-right-fields/312663)

<div class="topic-metadata">

**Author:** [@aids123](https://discuss.elastic.co/u/aids123)\
**Replies:** 1\
**Last updated:** [August 31, 2022, 9:07am UTC](https://discuss.elastic.co/t/alert-is-not-populating-the-right-fields/312663 "2022-08-31T09:07:55Z")

</div>

I am trying to create an alert containing the fields populated(host.name,user.name,file.name,process.name), however when the rule trigger the alert it seems that these are not populated. I was advised that it is because …

---

## [Inquiry about the configuration of network.host in elasticsearch.yml](https://discuss.elastic.co/t/inquiry-about-the-configuration-of-network-host-in-elasticsearch-yml/313329)

<div class="topic-metadata">

**Author:** [@morad\_della3](https://discuss.elastic.co/u/morad_della3)\
**Replies:** 3\
**Last updated:** [August 31, 2022, 9:06am UTC](https://discuss.elastic.co/t/inquiry-about-the-configuration-of-network-host-in-elasticsearch-yml/313329 "2022-08-31T09:06:40Z")

</div>

I already installed Elasticsearch 8.4.0 in ubuntu and I find in the elasticsearch.yml file that the HTTP.host: 0.0.0.0 and #transport.host: 0.0.0.0 is that mean that I should put the network.host also 0.0.0.0 ?? than…

---

## [What's the cause and the solution of this problem plz](https://discuss.elastic.co/t/whats-the-cause-and-the-solution-of-this-problem-plz/313269)

<div class="topic-metadata">

**Author:** [@morad\_della3](https://discuss.elastic.co/u/morad_della3)\
**Replies:** 3\
**Last updated:** [August 31, 2022, 9:05am UTC](https://discuss.elastic.co/t/whats-the-cause-and-the-solution-of-this-problem-plz/313269 "2022-08-31T09:05:05Z")

</div>

I installed elasticsearch and kibana 8.4.0 in the same ubuntu 22.04 VM and i try to connect them by token and when i try to create a token i get this error help plz and thanks kibana@kibana:/usr/share/elasticsearch/bin$…

---

## [Detect Rules](https://discuss.elastic.co/t/detect-rules/313182)

<div class="topic-metadata">

**Author:** [@VitorBarroso](https://discuss.elastic.co/u/VitorBarroso)\
**Replies:** 1\
**Last updated:** [August 31, 2022, 8:59am UTC](https://discuss.elastic.co/t/detect-rules/313182 "2022-08-31T08:59:56Z")

</div>

Can I detect a acess to website through endpoint security? Because i want to know if a host acess a certain website and "shot" a alert.

---

## [To find out which agent has not sent logs](https://discuss.elastic.co/t/to-find-out-which-agent-has-not-sent-logs/313334)

<div class="topic-metadata">

**Author:** [@hadi\_farzipour](https://discuss.elastic.co/u/hadi_farzipour)\
**Replies:** 1\
**Last updated:** [August 31, 2022, 8:29am UTC](https://discuss.elastic.co/t/to-find-out-which-agent-has-not-sent-logs/313334 "2022-08-31T08:29:07Z")

</div>

I have 1000 agents sending their logs to my ELK stack like following lines every 10 seconds { "\_index": "my\_logs", "@timestamp": "2022-08-31T08:11:21.622Z", "agent\_name":"agent\_1", "size" : 15 } I know a way to…

---

## [Logstash CSV filter plugins](https://discuss.elastic.co/t/logstash-csv-filter-plugins/313327)

<div class="topic-metadata">

**Author:** [@priyankamondalhcl](https://discuss.elastic.co/u/priyankamondalhcl)\
**Replies:** 1\
**Last updated:** [August 31, 2022, 8:19am UTC](https://discuss.elastic.co/t/logstash-csv-filter-plugins/313327 "2022-08-31T08:19:18Z")

</div>

Hi Team, I am trying to read csv file and storing it in elasticsearch. Is there any way to read column from file itself (header of csv file ) in logstash "csv filter plugins". currently I am manually setting up the co…

---

## [Getting aggregate statistics about a dense\_vector field](https://discuss.elastic.co/t/getting-aggregate-statistics-about-a-dense-vector-field/268694)

<div class="topic-metadata">

**Author:** [@MaJaHa95](https://discuss.elastic.co/u/MaJaHa95)\
**Replies:** 2\
**Last updated:** [August 31, 2022, 8:04am UTC](https://discuss.elastic.co/t/getting-aggregate-statistics-about-a-dense-vector-field/268694 "2022-08-31T08:04:51Z")

</div>

Hey, I'm making lots of great use of the dense\_vector field type, but I've hit a bit of a wall now. Is there any way I can get the "average" from a vector field? Context My real use-case is a bit more complex, but imag…

---

## [Doing a significant text aggregation with a custom analyzer](https://discuss.elastic.co/t/doing-a-significant-text-aggregation-with-a-custom-analyzer/313059)

<div class="topic-metadata">

**Author:** [@Ivo\_Tavares](https://discuss.elastic.co/u/Ivo_Tavares)\
**Replies:** 5\
**Last updated:** [August 31, 2022, 7:09am UTC](https://discuss.elastic.co/t/doing-a-significant-text-aggregation-with-a-custom-analyzer/313059 "2022-08-31T07:09:51Z")

</div>

I have an ES index with a mapping like this: {'texts-temp': {'aliases': {}, 'mappings': {'properties': {'data': {'properties': (...) 'user\_text': {'type': 'text', 'fields…

---

## [Unable to rollout Elastic-Agent (Windows) to fleet](https://discuss.elastic.co/t/unable-to-rollout-elastic-agent-windows-to-fleet/313315)

<div class="topic-metadata">

**Author:** [@nlstbv-winter](https://discuss.elastic.co/u/nlstbv-winter)\
**Replies:** 0\
**Last updated:** [August 31, 2022, 6:34am UTC](https://discuss.elastic.co/t/unable-to-rollout-elastic-agent-windows-to-fleet/313315 "2022-08-31T06:34:13Z")

</div>

Hi, since updating Elastic to 8.4 (coming from 8.3), I'm unable to rollout elastic-agent for windows to one client. I've checked the token, it's valid and I'm able to rollout elastic-agent to other clients with this tok…

---

## [I can't find logs on elasticsearch](https://discuss.elastic.co/t/i-cant-find-logs-on-elasticsearch/313224)

<div class="topic-metadata">

**Author:** [@mammodde](https://discuss.elastic.co/u/mammodde)\
**Replies:** 8\
**Last updated:** [August 31, 2022, 6:49am UTC](https://discuss.elastic.co/t/i-cant-find-logs-on-elasticsearch/313224 "2022-08-31T06:49:30Z")

</div>

Hi, I have a problem on finding the logs on the elasticsearch docker. I can see them on kibana but I don't know where to find them. this is the docker-compose.yml that I used in order to create all the containers versi…

---

## [How to change indexing\_pressure.memory.limit configuration](https://discuss.elastic.co/t/how-to-change-indexing-pressure-memory-limit-configuration/312444)

<div class="topic-metadata">

**Author:** [@DesireWithin](https://discuss.elastic.co/u/DesireWithin)\
**Replies:** 5\
**Last updated:** [August 31, 2022, 5:56am UTC](https://discuss.elastic.co/t/how-to-change-indexing-pressure-memory-limit-configuration/312444 "2022-08-31T05:56:22Z")

</div>

My es version is 7.17.5, single node. I notice that my fluent-bit return following error log: {"log":"{\\"error\\":{\\"root\_cause\\":\[{\\"type\\":\\"es\_rejected\_execution\_exception\\",\\"reason\\":\\"rejected execution of coordin…

---

## [\_update Object filed with json or flattened](https://discuss.elastic.co/t/update-object-filed-with-json-or-flattened/313308)

<div class="topic-metadata">

**Author:** [@liurui](https://discuss.elastic.co/u/liurui)\
**Replies:** 0\
**Last updated:** [August 31, 2022, 4:57am UTC](https://discuss.elastic.co/t/update-object-filed-with-json-or-flattened/313308 "2022-08-31T04:57:13Z")

</div>

hello~ I have an index with mapping like this: "test" : { "aliases" : { }, "mappings" : { "properties" : { "out" : { "properties" : { "in" : { "type" : "keywor…

---

## [Logstash import XML/ HTTP fails](https://discuss.elastic.co/t/logstash-import-xml-http-fails/313305)

<div class="topic-metadata">

**Author:** [@phamquenhu95](https://discuss.elastic.co/u/phamquenhu95)\
**Replies:** 0\
**Last updated:** [August 31, 2022, 4:02am UTC](https://discuss.elastic.co/t/logstash-import-xml-http-fails/313305 "2022-08-31T04:02:53Z")

</div>

I am new in this field. I have the following XML file, I want to separate the fields eg "so2Grade", "coFlag",... into rows one by one. My conf file is as follows: input { http\_poller { urls =\> { urlname =\> …

---

## [Recommended configuration for dedicated master nodes in ECK](https://discuss.elastic.co/t/recommended-configuration-for-dedicated-master-nodes-in-eck/313197)

<div class="topic-metadata">

**Author:** [@ejsmith](https://discuss.elastic.co/u/ejsmith)\
**Replies:** 2\
**Last updated:** [August 31, 2022, 3:12am UTC](https://discuss.elastic.co/t/recommended-configuration-for-dedicated-master-nodes-in-eck/313197 "2022-08-31T03:12:38Z")

</div>

When setting up an Elasticsearch cluster with dedicated master nodes, is it recommended that those dedicated master nodes be on separate Kubernetes nodes than the data nodes?

---

## [Any suggestions for creating logstash pipeline by REST APIs](https://discuss.elastic.co/t/any-suggestions-for-creating-logstash-pipeline-by-rest-apis/313219)

<div class="topic-metadata">

**Author:** [@jskuo](https://discuss.elastic.co/u/jskuo)\
**Replies:** 0\
**Last updated:** [August 30, 2022, 7:02am UTC](https://discuss.elastic.co/t/any-suggestions-for-creating-logstash-pipeline-by-rest-apis/313219 "2022-08-30T07:02:17Z")

</div>

platform: es/logstash 7.17.5 on centos 7 I intend to create a logstash pipeline, named test, by REST APIs curl -XPUT localhost:9600/\_logstash/pipeline/test?pretty -H "content-type:application/json" -d '{"pipeline": "in…

---

## [Version conflict (409) question](https://discuss.elastic.co/t/version-conflict-409-question/311335)

<div class="topic-metadata">

**Author:** [@linkerc](https://discuss.elastic.co/u/linkerc)\
**Replies:** 10\
**Last updated:** [August 30, 2022, 11:43pm UTC](https://discuss.elastic.co/t/version-conflict-409-question/311335 "2022-08-30T23:43:48Z")

</div>

Is version conflict bulk write error (409) only occur when I'm updating the same document from 2 different writers? I am starting to see this error more often in our system and trying to figure out if our data pattern h…

[Previous page](https://discuss.elastic.co/tag/none.md?no_tags=true&page=548)

[Next page](https://discuss.elastic.co/tag/none.md?no_tags=true&page=550)
