# \#none

**URL:** https://discuss.elastic.co/tag/none.md?no_tags=true&page=550

[Latest](https://discuss.elastic.co/latest.md) · [Categories](https://discuss.elastic.co/categories.md) · [Tags](https://discuss.elastic.co/tags.md)

**Page:** 551

---

## [Executing bash script in logstash's filter and geting data back to field](https://discuss.elastic.co/t/executing-bash-script-in-logstashs-filter-and-geting-data-back-to-field/313297)

<div class="topic-metadata">

**Author:** [@rayg00n](https://discuss.elastic.co/u/rayg00n)\
**Replies:** 3\
**Last updated:** [August 30, 2022, 10:17pm UTC](https://discuss.elastic.co/t/executing-bash-script-in-logstashs-filter-and-geting-data-back-to-field/313297 "2022-08-30T22:17:47Z")

</div>

Hello friends! I need some help with my logstash config. I want to get event field "winlog.event\_data.ObjectName" and take it to a bash script. Then I want to get the result back and put it in the "winlog.event\_data.O…

---

## [New cluster -\> single node to cluster](https://discuss.elastic.co/t/new-cluster-single-node-to-cluster/313035)

<div class="topic-metadata">

**Author:** [@PSFletchTheTek](https://discuss.elastic.co/u/PSFletchTheTek)\
**Replies:** 4\
**Last updated:** [August 30, 2022, 10:14pm UTC](https://discuss.elastic.co/t/new-cluster-single-node-to-cluster/313035 "2022-08-30T22:14:47Z")

</div>

Hi all, This has been bugging me for ages. I've never been able to get a cluster built using a internal ca. I've used certutil to make the car's. Signed them using my ca. Put all of the certs on the clusters. But n…

---

## [ElasticSearchClient Search function](https://discuss.elastic.co/t/elasticsearchclient-search-function/313290)

<div class="topic-metadata">

**Author:** [@rayyanalbaz1](https://discuss.elastic.co/u/rayyanalbaz1)\
**Replies:** 0\
**Last updated:** [August 30, 2022, 8:22pm UTC](https://discuss.elastic.co/t/elasticsearchclient-search-function/313290 "2022-08-30T20:22:51Z")

</div>

Hello, We are trying to implement nested queries like this provided example: And was wondering if it is possible that we can add the query objects dynamically depending on the number of the query objects created. For …

---

## [How to create a webhook endpoint url in ELK](https://discuss.elastic.co/t/how-to-create-a-webhook-endpoint-url-in-elk/313271)

<div class="topic-metadata">

**Author:** [@srek3502](https://discuss.elastic.co/u/srek3502)\
**Replies:** 1\
**Last updated:** [August 30, 2022, 6:34pm UTC](https://discuss.elastic.co/t/how-to-create-a-webhook-endpoint-url-in-elk/313271 "2022-08-30T18:34:25Z")

</div>

Hi, Can anyone please share the relevant document for ELK to create a webhook endpoint url. ? I need to configure this ELK webhook endpoint url to be used in other application to POST a payload. Any useful information …

---

## [Problem with similar terms](https://discuss.elastic.co/t/problem-with-similar-terms/313276)

<div class="topic-metadata">

**Author:** [@Guilherme\_Mello](https://discuss.elastic.co/u/Guilherme_Mello)\
**Replies:** 1\
**Last updated:** [August 30, 2022, 6:22pm UTC](https://discuss.elastic.co/t/problem-with-similar-terms/313276 "2022-08-30T18:22:01Z")

</div>

I have a search using term "calca" but the result list contains "calce" Is there a way to avoid this type of behavior? Thanks

---

## [Performance issue running on ECK vs EC2 on AWS](https://discuss.elastic.co/t/performance-issue-running-on-eck-vs-ec2-on-aws/313263)

<div class="topic-metadata">

**Author:** [@PascalB](https://discuss.elastic.co/u/PascalB)\
**Replies:** 2\
**Last updated:** [August 30, 2022, 5:18pm UTC](https://discuss.elastic.co/t/performance-issue-running-on-eck-vs-ec2-on-aws/313263 "2022-08-30T17:18:32Z")

</div>

Hello, I am new here and I am trying to understand performance issues. I am running an index on two different deployments of Elasticsearch. The index is the same (I've used the backup/restore operation to make sure I ha…

---

## [ILM alias errors - illegal\_argument\_exception: index.lifecycle.rollover\_alias](https://discuss.elastic.co/t/ilm-alias-errors-illegal-argument-exception-index-lifecycle-rollover-alias/313167)

<div class="topic-metadata">

**Author:** [@vee](https://discuss.elastic.co/u/vee)\
**Replies:** 2\
**Last updated:** [August 30, 2022, 4:31pm UTC](https://discuss.elastic.co/t/ilm-alias-errors-illegal-argument-exception-index-lifecycle-rollover-alias/313167 "2022-08-30T16:31:46Z")

</div>

Hi, am seeing this issue even though I believe the seed index was created with the correct write index: illegal\_argument\_exception: index.lifecycle.rollover\_alias \[test-logs\] does not point to index \[test-logs-2022.08.1…

---

## [Kibana Controls Filter missing IP Filter by type](https://discuss.elastic.co/t/kibana-controls-filter-missing-ip-filter-by-type/313070)

<div class="topic-metadata">

**Author:** [@matled](https://discuss.elastic.co/u/matled)\
**Replies:** 2\
**Last updated:** [August 30, 2022, 3:25pm UTC](https://discuss.elastic.co/t/kibana-controls-filter-missing-ip-filter-by-type/313070 "2022-08-30T15:25:18Z")

</div>

Not sure if this is intended but I'm missing the type "IP" for filtering with the new custom controls. The old version can filter ip fields. Am I missing something or does anyone know a workaround?

---

## [Query\_string query with asterisk and escaped char not working](https://discuss.elastic.co/t/query-string-query-with-asterisk-and-escaped-char-not-working/313181)

<div class="topic-metadata">

**Author:** [@Nick\_Lipnyagov](https://discuss.elastic.co/u/Nick_Lipnyagov)\
**Replies:** 2\
**Last updated:** [August 30, 2022, 2:41pm UTC](https://discuss.elastic.co/t/query-string-query-with-asterisk-and-escaped-char-not-working/313181 "2022-08-30T14:41:25Z")

</div>

Hi everyone! Could you please help me on how to use query\_string with \* and escaped characters? For example: Mapping: { "index": "test\_user\_name", "mappings": { "properties": { "userId": { "type…

---

## [Multiple fields ranking sorting](https://discuss.elastic.co/t/multiple-fields-ranking-sorting/313163)

<div class="topic-metadata">

**Author:** [@maxim-pushchinskiy](https://discuss.elastic.co/u/maxim-pushchinskiy)\
**Replies:** 1\
**Last updated:** [August 30, 2022, 2:17pm UTC](https://discuss.elastic.co/t/multiple-fields-ranking-sorting/313163 "2022-08-30T14:17:07Z")

</div>

Hi everyone. I have business needs to create multiple fields ranking sorting. What does it mean? It means that I want to be able to sort by several fields with custom boost and different order. test dataset : interfac…

---

## [Design Validation](https://discuss.elastic.co/t/design-validation/313252)

<div class="topic-metadata">

**Author:** [@zain](https://discuss.elastic.co/u/zain)\
**Replies:** 3\
**Last updated:** [August 30, 2022, 2:04pm UTC](https://discuss.elastic.co/t/design-validation/313252 "2022-08-30T14:04:20Z")

</div>

Hello, Hierarchy: parent { child { grandchild { grandgrandchild { ....grandgrandgrandchildren } grandgrandchild { ....grandgrandgrandchild } } } } User { } Rules: User having access of …

---

## [Unable to create Kafka consumer from given configuration after upgrade to 8.4.0](https://discuss.elastic.co/t/unable-to-create-kafka-consumer-from-given-configuration-after-upgrade-to-8-4-0/313254)

<div class="topic-metadata">

**Author:** [@mcosta](https://discuss.elastic.co/u/mcosta)\
**Replies:** 0\
**Last updated:** [August 30, 2022, 12:48pm UTC](https://discuss.elastic.co/t/unable-to-create-kafka-consumer-from-given-configuration-after-upgrade-to-8-4-0/313254 "2022-08-30T12:48:02Z")

</div>

Hi all, Today Elastic and Kibana was upgraded from 7.17.3 to 8.4.0 without problems. This is an DEV/QA environment. After that, I upgrade logstash also from 7.17.3 to 8.4.0. Since logstash upgrade it can't connect to K…

---

## [Search by child product when search by sku in elastic search query](https://discuss.elastic.co/t/search-by-child-product-when-search-by-sku-in-elastic-search-query/313256)

<div class="topic-metadata">

**Author:** [@Sangeet\_Shah](https://discuss.elastic.co/u/Sangeet_Shah)\
**Replies:** 0\
**Last updated:** [August 30, 2022, 1:23pm UTC](https://discuss.elastic.co/t/search-by-child-product-when-search-by-sku-in-elastic-search-query/313256 "2022-08-30T13:23:05Z")

</div>

I have some products below Id Name SKU isParent 1 A 100 True 2 A1 101 False 3 A2 102 False 4 A3 103 False 5 A4 104 False 6 B 105 True 7 B1 106 False 8 B2 107 False I …

---

## [Elastic Cisco Duo Integration](https://discuss.elastic.co/t/elastic-cisco-duo-integration/312703)

<div class="topic-metadata">

**Author:** [@suraj.srinivasa](https://discuss.elastic.co/u/suraj.srinivasa)\
**Replies:** 4\
**Last updated:** [August 30, 2022, 1:28pm UTC](https://discuss.elastic.co/t/elastic-cisco-duo-integration/312703 "2022-08-30T13:28:36Z")

</div>

Hi, I am trying to fetch Cisco Duo logs with the elastic agent integration. The Duo setup in my organization is a managed service by a vendor, so I have received the Integration Key, api hostname and secret key and conf…

---

## [How to create alerts kibana](https://discuss.elastic.co/t/how-to-create-alerts-kibana/312627)

<div class="topic-metadata">

**Author:** [@danielbsilva2](https://discuss.elastic.co/u/danielbsilva2)\
**Replies:** 3\
**Last updated:** [August 30, 2022, 1:27pm UTC](https://discuss.elastic.co/t/how-to-create-alerts-kibana/312627 "2022-08-30T13:27:52Z")

</div>

hello guys my english is not very good i hope you can understand I need to create alerts on kibana my license is the basic and when I try to do I get this mensangem ai print, but i have already consulted the documentatio…

---

## [Problem: Switching from a cluster to a single node ES](https://discuss.elastic.co/t/problem-switching-from-a-cluster-to-a-single-node-es/313225)

<div class="topic-metadata">

**Author:** [@ASRLO](https://discuss.elastic.co/u/ASRLO)\
**Replies:** 2\
**Last updated:** [August 30, 2022, 12:26pm UTC](https://discuss.elastic.co/t/problem-switching-from-a-cluster-to-a-single-node-es/313225 "2022-08-30T12:26:33Z")

</div>

Hi there, My ES infrastructure is composed of 2 servers: An ELK server and another server only with Elasticsearch. So there were 2 elasticsearch nodes. However for internal needs. The second server with only elasticse…

---

## [Kibana visual to show intime values coming from background script](https://discuss.elastic.co/t/kibana-visual-to-show-intime-values-coming-from-background-script/313246)

<div class="topic-metadata">

**Author:** [@PRASHANT\_MEHTA](https://discuss.elastic.co/u/PRASHANT_MEHTA)\
**Replies:** 0\
**Last updated:** [August 30, 2022, 11:20am UTC](https://discuss.elastic.co/t/kibana-visual-to-show-intime-values-coming-from-background-script/313246 "2022-08-30T11:20:59Z")

</div>

Hello All, Can someone suggest how can one draw below visalization in kibana,I suppose the line graph serves the purpose but,I want to display "in time values of duartion" for GROUP,PROJECTS,DURATION. Plz note the da…

---

## [Elastic agent - nginx integration: Not respecting Hosts setting](https://discuss.elastic.co/t/elastic-agent-nginx-integration-not-respecting-hosts-setting/313250)

<div class="topic-metadata">

**Author:** [@mzurborg](https://discuss.elastic.co/u/mzurborg)\
**Replies:** 0\
**Last updated:** [August 30, 2022, 11:36am UTC](https://discuss.elastic.co/t/elastic-agent-nginx-integration-not-respecting-hosts-setting/313250 "2022-08-30T11:36:28Z")

</div>

The Elastic integration "NGINX" for elastic agent, when deployed over fleet does not fully respect the "Hosts" setting for the integration even though the tooltip says "The following settings are applicable to all inputs…

---

## [How to create dashboard for API status codes](https://discuss.elastic.co/t/how-to-create-dashboard-for-api-status-codes/313091)

<div class="topic-metadata">

**Author:** [@Rajes](https://discuss.elastic.co/u/Rajes)\
**Replies:** 5\
**Last updated:** [August 30, 2022, 11:02am UTC](https://discuss.elastic.co/t/how-to-create-dashboard-for-api-status-codes/313091 "2022-08-30T11:02:07Z")

</div>

Hi Team, I'm new to this Kibana , I want to create a dash board for API status codes like 200 count and 404 count and 404 count , Can anyone help me here. Thanks, Rajes

---

## [Date histogram omitting buckets](https://discuss.elastic.co/t/date-histogram-omitting-buckets/311209)

<div class="topic-metadata">

**Author:** [@thahgr](https://discuss.elastic.co/u/thahgr)\
**Replies:** 1\
**Last updated:** [August 30, 2022, 10:41am UTC](https://discuss.elastic.co/t/date-histogram-omitting-buckets/311209 "2022-08-30T10:41:39Z")

</div>

I am trying to get a result like the kibana "discover" tab like below via date\_histogram functionality my request is as below GET index-\*/\_search { "size": 0, "aggs": { "stats": { "date\_histogram": { …

---

## [How to install elasticsearch in ubuntu and configure it to be standalone?](https://discuss.elastic.co/t/how-to-install-elasticsearch-in-ubuntu-and-configure-it-to-be-standalone/313237)

<div class="topic-metadata">

**Author:** [@morad\_della3](https://discuss.elastic.co/u/morad_della3)\
**Replies:** 5\
**Last updated:** [August 30, 2022, 10:19am UTC](https://discuss.elastic.co/t/how-to-install-elasticsearch-in-ubuntu-and-configure-it-to-be-standalone/313237 "2022-08-30T10:19:54Z")

</div>

how to install elasticsearch in ubuntu and configure it to be standalone?

---

## [Elastic: Filtering data after grouping](https://discuss.elastic.co/t/elastic-filtering-data-after-grouping/313240)

<div class="topic-metadata">

**Author:** [@fchen521](https://discuss.elastic.co/u/fchen521)\
**Replies:** 0\
**Last updated:** [August 30, 2022, 9:52am UTC](https://discuss.elastic.co/t/elastic-filtering-data-after-grouping/313240 "2022-08-30T09:52:53Z")

</div>

First aggregate according to the people, then count the data in each group, and filter out the people whose start time field is \> minimum time - 10 days and whose start time is \< minimum time + 10 days Is this all right…

---

## [Modeling product data with frequent updates](https://discuss.elastic.co/t/modeling-product-data-with-frequent-updates/312712)

<div class="topic-metadata">

**Author:** [@t0mer](https://discuss.elastic.co/u/t0mer)\
**Replies:** 1\
**Last updated:** [August 30, 2022, 9:00am UTC](https://discuss.elastic.co/t/modeling-product-data-with-frequent-updates/312712 "2022-08-30T09:00:38Z")

</div>

Hi, We're struggling with modeling our data in Elasticsearch, and decided to change it. What we have today: single index to store product data, which holds data of 2 types - \[1\] Some product data that changes rarely - …

---

## [Error No index created - reason"=\>"Validation Failed: 1: this action would add \[2\] shards](https://discuss.elastic.co/t/error-no-index-created-reason-validation-failed-1-this-action-would-add-2-shards/313144)

<div class="topic-metadata">

**Author:** [@ehmontesinos](https://discuss.elastic.co/u/ehmontesinos)\
**Replies:** 7\
**Last updated:** [August 30, 2022, 8:39am UTC](https://discuss.elastic.co/t/error-no-index-created-reason-validation-failed-1-this-action-would-add-2-shards/313144 "2022-08-30T08:39:49Z")

</div>

Good morning, I have an ELK environment installed in version 8.1. Within this environment, I have configured several pipelines that collect daily csv files to process them and convert them into indexes in Elasticsearch …

---

## [Using MISP alerts on my network](https://discuss.elastic.co/t/using-misp-alerts-on-my-network/313168)

<div class="topic-metadata">

**Author:** [@VitorBarroso](https://discuss.elastic.co/u/VitorBarroso)\
**Replies:** 2\
**Last updated:** [August 30, 2022, 8:27am UTC](https://discuss.elastic.co/t/using-misp-alerts-on-my-network/313168 "2022-08-30T08:27:45Z")

</div>

Hello, Can I use Misp alerts on my network? One exemple, i access one website and this site have alerts on MISP, can i connect the MISP alert of this website to my elasticsearch?

---

## [Date\_time\_exception: Invalid value for MonthOfYear (valid values 1 - 12): 28](https://discuss.elastic.co/t/date-time-exception-invalid-value-for-monthofyear-valid-values-1-12-28/313208)

<div class="topic-metadata">

**Author:** [@Gex1](https://discuss.elastic.co/u/Gex1)\
**Replies:** 11\
**Last updated:** [August 30, 2022, 7:50am UTC](https://discuss.elastic.co/t/date-time-exception-invalid-value-for-monthofyear-valid-values-1-12-28/313208 "2022-08-30T07:50:14Z")

</div>

I am using ES 7.10.0 In my case I expect date values like: Case1: 28/09/2022:02:00:00 Case2: 09/28/2022:02:00:00 Case3: 2022-09-28T02:00:00 Below is the template, which I am using: PUT \_template/template\_1 { "ind…

---

## [Create and edit elasticseaarch index](https://discuss.elastic.co/t/create-and-edit-elasticseaarch-index/313152)

<div class="topic-metadata">

**Author:** [@Ismet](https://discuss.elastic.co/u/Ismet)\
**Replies:** 3\
**Last updated:** [August 30, 2022, 7:13am UTC](https://discuss.elastic.co/t/create-and-edit-elasticseaarch-index/313152 "2022-08-30T07:13:15Z")

</div>

I have created an index with default mapping. In my case, I need to search data with special characters like čćš, and nested data up to 3 levels. Questions: Is it possible to override default settings, analyzer and fi…

---

## [False Positive Report](https://discuss.elastic.co/t/false-positive-report/311191)

<div class="topic-metadata">

**Author:** [@ChristianR](https://discuss.elastic.co/u/ChristianR)\
**Replies:** 6\
**Last updated:** [August 30, 2022, 7:06am UTC](https://discuss.elastic.co/t/false-positive-report/311191 "2022-08-30T07:06:42Z")

</div>

Hi, we followed your advice and forwarded a false positive report to fp\_reports@elastic.co but have not received any response. Pls advise: Filename: mavwin\_8\_35\_0\_9.exe Hash (SHA256): 3987CB0CCDD1FABB879AF8E59EB847E104…

---

## [ES 6.8.23 too many Full GC](https://discuss.elastic.co/t/es-6-8-23-too-many-full-gc/312478)

<div class="topic-metadata">

**Author:** [@Andrey\_Tyutyunov](https://discuss.elastic.co/u/Andrey_Tyutyunov)\
**Replies:** 3\
**Last updated:** [August 30, 2022, 3:55am UTC](https://discuss.elastic.co/t/es-6-8-23-too-many-full-gc/312478 "2022-08-30T03:55:31Z")

</div>

Good day! Version 6.8.23 3 nodes, 26GB heap per node, 64GB RAM on each node java 14 Indices: 49 Documents 516,257,116 Disk Usage 872.0 GB Primary Shards 165 Replica Shards 165 Search Rate (/s) ~ 750 /s (total sh…

---

## [Resolving mapping parser errors](https://discuss.elastic.co/t/resolving-mapping-parser-errors/312840)

<div class="topic-metadata">

**Author:** [@Austin\_ES\_Questions](https://discuss.elastic.co/u/Austin_ES_Questions)\
**Replies:** 3\
**Last updated:** [August 29, 2022, 11:40pm UTC](https://discuss.elastic.co/t/resolving-mapping-parser-errors/312840 "2022-08-29T23:40:41Z")

</div>

I'm using filebeat -\> pipeline -\> Elasticsearch, so at the moment everything is going to one index. at some point this field structure was inferred from my data "name": { "properties":…

[Previous page](https://discuss.elastic.co/tag/none.md?no_tags=true&page=549)

[Next page](https://discuss.elastic.co/tag/none.md?no_tags=true&page=551)
