# \#none

**URL:** https://discuss.elastic.co/tag/none.md?no_tags=true&page=553

[Latest](https://discuss.elastic.co/latest.md) · [Categories](https://discuss.elastic.co/categories.md) · [Tags](https://discuss.elastic.co/tags.md)

**Page:** 554

---

## [How do I match a newline in logstash grok](https://discuss.elastic.co/t/how-do-i-match-a-newline-in-logstash-grok/311596)

<div class="topic-metadata">

**Author:** [@yts85205107](https://discuss.elastic.co/u/yts85205107)\
**Replies:** 5\
**Last updated:** [August 25, 2022, 10:50pm UTC](https://discuss.elastic.co/t/how-do-i-match-a-newline-in-logstash-grok/311596 "2022-08-25T22:50:48Z")

</div>

this is my log sample as below: \[2022-08-07T15:57:54+08:00\] 9.9.9.9 "Request-Method-URL: GET XXX Sex - Free Porn Videos on XXX.com" "Status-Code: 200" "Request-Length: 1" "Request-Time: 1.23" "Upstream-Server: 1.1.1.1:1…

---

## [Script score vector search performance](https://discuss.elastic.co/t/script-score-vector-search-performance/312341)

<div class="topic-metadata">

**Author:** [@zyyme](https://discuss.elastic.co/u/zyyme)\
**Replies:** 2\
**Last updated:** [August 25, 2022, 9:21pm UTC](https://discuss.elastic.co/t/script-score-vector-search-performance/312341 "2022-08-25T21:21:20Z")

</div>

Hello! I use Elasticsearch 7.14 and I have a mapping like this: { "mappings": { "properties": { "vector": { "type": "dense\_vector", "dims": 512 }, "category": { "type": "…

---

## [Elastic search match Query string query (blue OR red OR yellow) AND cake](https://discuss.elastic.co/t/elastic-search-match-query-string-query-blue-or-red-or-yellow-and-cake/312704)

<div class="topic-metadata">

**Author:** [@qub123](https://discuss.elastic.co/u/qub123)\
**Replies:** 4\
**Last updated:** [August 25, 2022, 8:13pm UTC](https://discuss.elastic.co/t/elastic-search-match-query-string-query-blue-or-red-or-yellow-and-cake/312704 "2022-08-25T20:13:27Z")

</div>

Hi, I am trying to create a query to request all the "cake" with blue or red or yellow color, and I guess the condition similar to (blue OR red OR yellow) AND cake. And I have look at the Elasticsearch Query String q…

---

## [We need a currency type in Elastic String validators and converters to currencies of other countries. We must store currency values in the native country currency and we need field validators to remove currency formatting characters](https://discuss.elastic.co/t/we-need-a-currency-type-in-elastic-string-validators-and-converters-to-currencies-of-other-countries-we-must-store-currency-values-in-the-native-country-currency-and-we-need-field-validators-to-remove-currency-formatting-characters/312965)

<div class="topic-metadata">

**Author:** [@jmkdev](https://discuss.elastic.co/u/jmkdev)\
**Replies:** 0\
**Last updated:** [August 25, 2022, 8:04pm UTC](https://discuss.elastic.co/t/we-need-a-currency-type-in-elastic-string-validators-and-converters-to-currencies-of-other-countries-we-must-store-currency-values-in-the-native-country-currency-and-we-need-field-validators-to-remove-currency-formatting-characters/312965 "2022-08-25T20:04:09Z")

</div>

Continuing the discussion from How to store currency datatype in elasticsearch?:

---

## [Search in Discover](https://discuss.elastic.co/t/search-in-discover/312958)

<div class="topic-metadata">

**Author:** [@papilocheg1992](https://discuss.elastic.co/u/papilocheg1992)\
**Replies:** 0\
**Last updated:** [August 25, 2022, 6:13pm UTC](https://discuss.elastic.co/t/search-in-discover/312958 "2022-08-25T18:13:46Z")

</div>

we have some value (word) that we want to find in an index with a large number of fields. How can this be done using the Kibana Discovery interface?

---

## [Failed to install template](https://discuss.elastic.co/t/failed-to-install-template/312949)

<div class="topic-metadata">

**Author:** [@Queren\_Santos](https://discuss.elastic.co/u/Queren_Santos)\
**Replies:** 1\
**Last updated:** [August 25, 2022, 5:58pm UTC](https://discuss.elastic.co/t/failed-to-install-template/312949 "2022-08-25T17:58:07Z")

</div>

Can anyone help? My template in Elasticsearch is ready, but Logstash does not send the index to which it is already created: ERROR\]\[logstash.outputs.elasticsearch\]\[main\] Failed to install template {:message=\>"Got respon…

---

## [Logstash only logs the word 'log' on completion](https://discuss.elastic.co/t/logstash-only-logs-the-word-log-on-completion/312916)

<div class="topic-metadata">

**Author:** [@usman1](https://discuss.elastic.co/u/usman1)\
**Replies:** 3\
**Last updated:** [August 25, 2022, 5:03pm UTC](https://discuss.elastic.co/t/logstash-only-logs-the-word-log-on-completion/312916 "2022-08-25T17:03:14Z")

</div>

I am using the following input configurations for deleting the files once read and log the information. input { file { path =\> "C:/.log" mode =\> "read" file\_completed\_action =\> "log\_and\_delete" file\_co…

---

## [Invalid Index Name Exception](https://discuss.elastic.co/t/invalid-index-name-exception/312908)

<div class="topic-metadata">

**Author:** [@hnf](https://discuss.elastic.co/u/hnf)\
**Replies:** 2\
**Last updated:** [August 25, 2022, 4:42pm UTC](https://discuss.elastic.co/t/invalid-index-name-exception/312908 "2022-08-25T16:42:29Z")

</div>

Hello everyone, I have an issue when I try to make an index a field created using add\_field by referencing them when outputing. I create three .conf files that begin by a number , like 1file.conf, 2file.conf and 99outp…

---

## [Dynamic filter according to the presence of a field](https://discuss.elastic.co/t/dynamic-filter-according-to-the-presence-of-a-field/312944)

<div class="topic-metadata">

**Author:** [@arnoz](https://discuss.elastic.co/u/arnoz)\
**Replies:** 0\
**Last updated:** [August 25, 2022, 4:10pm UTC](https://discuss.elastic.co/t/dynamic-filter-according-to-the-presence-of-a-field/312944 "2022-08-25T16:10:55Z")

</div>

I have for example this type of documents. { "name": "sylvie dupont", "age": 25, "accounts": \[ { "name": "BankOfAmerica", "amount": 33 }, { "name": "GoldBank", "amount": 578 …

---

## [Logstash IndexOutOfBoundsException: writerIndex + minWritableBytes exceeds maxCapacity](https://discuss.elastic.co/t/logstash-indexoutofboundsexception-writerindex-minwritablebytes-exceeds-maxcapacity/312943)

<div class="topic-metadata">

**Author:** [@cotjoey](https://discuss.elastic.co/u/cotjoey)\
**Replies:** 0\
**Last updated:** [August 25, 2022, 3:37pm UTC](https://discuss.elastic.co/t/logstash-indexoutofboundsexception-writerindex-minwritablebytes-exceeds-maxcapacity/312943 "2022-08-25T15:37:17Z")

</div>

Hello, Lately my logstash instance has been throwing the following exceptions intermittently. I cannot find a solution anywhere. All the posts in this forum with the string "writerIndex" with similar issues are left una…

---

## [Logstash http input plugin and azure load balancer](https://discuss.elastic.co/t/logstash-http-input-plugin-and-azure-load-balancer/312940)

<div class="topic-metadata">

**Author:** [@chapmantrain](https://discuss.elastic.co/u/chapmantrain)\
**Replies:** 0\
**Last updated:** [August 25, 2022, 3:25pm UTC](https://discuss.elastic.co/t/logstash-http-input-plugin-and-azure-load-balancer/312940 "2022-08-25T15:25:25Z")

</div>

I am not able to get the http input plugin to connect to our azure load balancer. The input input { http { host =\> "igemsng-eastus2-nprd-elkcluster.test.att.com" port =\> 8808 password =\> XXXX…

---

## [Why does Kibana stops after 10seconds?](https://discuss.elastic.co/t/why-does-kibana-stops-after-10seconds/312860)

<div class="topic-metadata">

**Author:** [@Vinyl\_Down](https://discuss.elastic.co/u/Vinyl_Down)\
**Replies:** 12\
**Last updated:** [August 25, 2022, 3:08pm UTC](https://discuss.elastic.co/t/why-does-kibana-stops-after-10seconds/312860 "2022-08-25T15:08:59Z")

</div>

Dear all, I really didn't want to post a question here, and i am trying for a week to fix my issue, but i can't seem to figure this out. I am trying to do some tests on Elastic Search Endpoint Security (using elastic a…

---

## [Failed to install template {:message=\>"Got response code '400' contacting Elasticsearch at URL](https://discuss.elastic.co/t/failed-to-install-template-message-got-response-code-400-contacting-elasticsearch-at-url/312939)

<div class="topic-metadata">

**Author:** [@Queren\_Santos](https://discuss.elastic.co/u/Queren_Santos)\
**Replies:** 0\
**Last updated:** [August 25, 2022, 3:05pm UTC](https://discuss.elastic.co/t/failed-to-install-template-message-got-response-code-400-contacting-elasticsearch-at-url/312939 "2022-08-25T15:05:48Z")

</div>

Can anyone help? My template in Elasticsearch is ready, but Logstash does not send the index to which it is already created: ERROR\]\[logstash.outputs.elasticsearch\]\[main\] Failed to install template {:message=\>"Got respon…

---

## [Mapper\_parsing\_exception: failed to parse ( Dataframe to Elastic - batch process)](https://discuss.elastic.co/t/mapper-parsing-exception-failed-to-parse-dataframe-to-elastic-batch-process/312930)

<div class="topic-metadata">

**Author:** [@visit2siva](https://discuss.elastic.co/u/visit2siva)\
**Replies:** 0\
**Last updated:** [August 25, 2022, 2:10pm UTC](https://discuss.elastic.co/t/mapper-parsing-exception-failed-to-parse-dataframe-to-elastic-batch-process/312930 "2022-08-25T14:10:38Z")

</div>

We are adding documents through a pyspark dataframe to elastic. df.write.mode('append').format('org.elasticsearch.spark.sql') .option('es.nodes', 'https://xyz.com') .option('es.net.http.auth.user','userid') .optio…

---

## [MongoDB to Elasticsearch synchronisation using Logstash JDBC Input plugin](https://discuss.elastic.co/t/mongodb-to-elasticsearch-synchronisation-using-logstash-jdbc-input-plugin/312934)

<div class="topic-metadata">

**Author:** [@hrasheed90](https://discuss.elastic.co/u/hrasheed90)\
**Replies:** 0\
**Last updated:** [August 25, 2022, 2:27pm UTC](https://discuss.elastic.co/t/mongodb-to-elasticsearch-synchronisation-using-logstash-jdbc-input-plugin/312934 "2022-08-25T14:27:53Z")

</div>

I have defined several pipelines (each pipeline represents one to one relation with mongodb collection to elasticsearch index i.e. each mongodb collection will have its own index in elasticsearch). all my pipelines look…

---

## [Unable to upgrade from elastic-agent 8.3.3 to 8.4.0, or install 8.4.0 cleanly](https://discuss.elastic.co/t/unable-to-upgrade-from-elastic-agent-8-3-3-to-8-4-0-or-install-8-4-0-cleanly/312928)

<div class="topic-metadata">

**Author:** [@Curtis\_Ruck](https://discuss.elastic.co/u/Curtis_Ruck)\
**Replies:** 0\
**Last updated:** [August 25, 2022, 1:57pm UTC](https://discuss.elastic.co/t/unable-to-upgrade-from-elastic-agent-8-3-3-to-8-4-0-or-install-8-4-0-cleanly/312928 "2022-08-25T13:57:22Z")

</div>

On Ubuntu 22.04.1, system had Elastic Agent 8.3.3 installed, doing daily apt upgrade -y and the 8.4.0 upgrade fails. Removing elastic-agent and reinstalling also fails. It fails during package configuration running ela…

---

## [Deleting processed objects from S3 when using Beats input (and Filebeat with aws-s3 input)](https://discuss.elastic.co/t/deleting-processed-objects-from-s3-when-using-beats-input-and-filebeat-with-aws-s3-input/312922)

<div class="topic-metadata">

**Author:** [@G.E](https://discuss.elastic.co/u/G.E)\
**Replies:** 0\
**Last updated:** [August 25, 2022, 1:15pm UTC](https://discuss.elastic.co/t/deleting-processed-objects-from-s3-when-using-beats-input-and-filebeat-with-aws-s3-input/312922 "2022-08-25T13:15:37Z")

</div>

Hi, Can anyone suggest a (hopefully uncomplicated) way to delete processed log files from S3 when using Filebeat and Logstash with SQS and S3? I had previously used the Logstash S3 plugin alone which does support this …

---

## [Unable to install Elastic Agent 7.17.5 (Windows)](https://discuss.elastic.co/t/unable-to-install-elastic-agent-7-17-5-windows/311284)

<div class="topic-metadata">

**Author:** [@sirineb](https://discuss.elastic.co/u/sirineb)\
**Replies:** 2\
**Last updated:** [August 25, 2022, 12:19pm UTC](https://discuss.elastic.co/t/unable-to-install-elastic-agent-7-17-5-windows/311284 "2022-08-25T12:19:35Z")

</div>

Hi everyone, I have an issue trying to enroll elastic agent 7.17.5 in Windows. (My fleet server is 7.17.5 too) The first time I installed it, it worked perfectly but due to a storage issue on the machine that hosts ELK,…

---

## [Runtime Environment Requirement for FS Crawler](https://discuss.elastic.co/t/runtime-environment-requirement-for-fs-crawler/312753)

<div class="topic-metadata">

**Author:** [@zxuz111](https://discuss.elastic.co/u/zxuz111)\
**Replies:** 1\
**Last updated:** [August 25, 2022, 12:07pm UTC](https://discuss.elastic.co/t/runtime-environment-requirement-for-fs-crawler/312753 "2022-08-25T12:07:39Z")

</div>

We are planning to deploy FS Crawler to the VM on Azure, and I am trying to provisioning the VM. Here is the information to support the provision: OS: Ubuntu 20.4 PDF files total size: 1.5 TB FS Crawler Schedule: Set a…

---

## [Can Elasticsearch return position of the text within document](https://discuss.elastic.co/t/can-elasticsearch-return-position-of-the-text-within-document/312901)

<div class="topic-metadata">

**Author:** [@Dinesh\_Zende](https://discuss.elastic.co/u/Dinesh_Zende)\
**Replies:** 4\
**Last updated:** [August 25, 2022, 11:45am UTC](https://discuss.elastic.co/t/can-elasticsearch-return-position-of-the-text-within-document/312901 "2022-08-25T11:45:59Z")

</div>

I have created index with the attributes \<Filename,pageno, content\>, where the contents are the page content of the document. When I search for the particular query, it returns the appropriate Filename, Pageno. But to b…

---

## [Index size based on Kibana Query Output](https://discuss.elastic.co/t/index-size-based-on-kibana-query-output/312909)

<div class="topic-metadata">

**Author:** [@hari\_priya1](https://discuss.elastic.co/u/hari_priya1)\
**Replies:** 0\
**Last updated:** [August 25, 2022, 11:12am UTC](https://discuss.elastic.co/t/index-size-based-on-kibana-query-output/312909 "2022-08-25T11:12:15Z")

</div>

I have an index with a key field called adapter-id which I have to aggregate by adapter\_ids and calculate the index storage size for those buckets. Is it possible to get the index size concerning a certain key field in …

---

## [Serveur status RED](https://discuss.elastic.co/t/serveur-status-red/312891)

<div class="topic-metadata">

**Author:** [@Joachim\_Rodrigues](https://discuss.elastic.co/u/Joachim_Rodrigues)\
**Replies:** 1\
**Last updated:** [August 25, 2022, 10:16am UTC](https://discuss.elastic.co/t/serveur-status-red/312891 "2022-08-25T10:16:07Z")

</div>

Hi When i run : GET /\_cluster/health I can see that the cluster is RED : { "cluster\_name" : "es-monit-cluster", "status" : "red", "timed\_out" : false, "number\_of\_nodes" : 7, "number\_of\_data\_nodes" : 5, "acti…

---

## [Can´t remove mapping from index template](https://discuss.elastic.co/t/can-t-remove-mapping-from-index-template/312900)

<div class="topic-metadata">

**Author:** [@nunex\_17](https://discuss.elastic.co/u/nunex_17)\
**Replies:** 0\
**Last updated:** [August 25, 2022, 10:13am UTC](https://discuss.elastic.co/t/can-t-remove-mapping-from-index-template/312900 "2022-08-25T10:13:31Z")

</div>

Hello, In an effort to trying to reduce the index size, i am removing unnecessary mapping from the index template. In Stack management -\> Index management -\> Templates -\> Edit template -\> Mappings i´m trying to delete …

---

## [Upgrade to 8.4.0 fails when snoozed alerting rules are defined \[Known issue\]](https://discuss.elastic.co/t/upgrade-to-8-4-0-fails-when-snoozed-alerting-rules-are-defined-known-issue/312875)

<div class="topic-metadata">

**Author:** [@Shani\_Sagiv](https://discuss.elastic.co/u/Shani_Sagiv)\
**Replies:** 0\
**Last updated:** [August 25, 2022, 7:19am UTC](https://discuss.elastic.co/t/upgrade-to-8-4-0-fails-when-snoozed-alerting-rules-are-defined-known-issue/312875 "2022-08-25T07:19:16Z")

</div>

Users that use Elastic 8.3.x and contain a currently snoozed rule, will fail to upgrade to 8.4 due to a known issue with saved object migration. This does not apply to indefinite snooze or mute, only to an on-demand snoo…

---

## [Kibana dashboard is giving bad gateway](https://discuss.elastic.co/t/kibana-dashboard-is-giving-bad-gateway/312882)

<div class="topic-metadata">

**Author:** [@sandeep\_kumar5](https://discuss.elastic.co/u/sandeep_kumar5)\
**Replies:** 2\
**Last updated:** [August 25, 2022, 8:26am UTC](https://discuss.elastic.co/t/kibana-dashboard-is-giving-bad-gateway/312882 "2022-08-25T08:26:38Z")

</div>

Hi I have set up kibana and elasticsearch thru helm chart on a k8s cluster with Xpack. my elstic search urls is someting like elk.abc.com and kibana url is like kibana.abc.com but kibana dashboard is giving me bad gate…

---

## [How to embed dashboard into website with auto login user?](https://discuss.elastic.co/t/how-to-embed-dashboard-into-website-with-auto-login-user/311619)

<div class="topic-metadata">

**Author:** [@Irwan\_Kurniawan](https://discuss.elastic.co/u/Irwan_Kurniawan)\
**Replies:** 4\
**Last updated:** [August 25, 2022, 8:27am UTC](https://discuss.elastic.co/t/how-to-embed-dashboard-into-website-with-auto-login-user/311619 "2022-08-25T08:27:21Z")

</div>

I want to embed the dashboard with auto login user.. So when the user login into website, it automatically login into Kibana also with same user and role.. Is it possible? Thank you!

---

## [Logstash filter elasticsearch aggregation](https://discuss.elastic.co/t/logstash-filter-elasticsearch-aggregation/312883)

<div class="topic-metadata">

**Author:** [@Moshe\_Sharon1](https://discuss.elastic.co/u/Moshe_Sharon1)\
**Replies:** 0\
**Last updated:** [August 25, 2022, 8:11am UTC](https://discuss.elastic.co/t/logstash-filter-elasticsearch-aggregation/312883 "2022-08-25T08:11:44Z")

</div>

Using logstash I am trying to filter elasticsearch index to get one of few documents with same value thanks

---

## [Unable to parse date value '2022-12-16T10:55:22.000Z' of property 'UserSign.signDate' with configured converters](https://discuss.elastic.co/t/unable-to-parse-date-value-2022-12-16t1022-000z-of-property-usersign-signdate-with-configured-converters/312876)

<div class="topic-metadata">

**Author:** [@zhou\_Mr](https://discuss.elastic.co/u/zhou_Mr)\
**Replies:** 0\
**Last updated:** [August 25, 2022, 7:23am UTC](https://discuss.elastic.co/t/unable-to-parse-date-value-2022-12-16t1022-000z-of-property-usersign-signdate-with-configured-converters/312876 "2022-08-25T07:23:15Z")

</div>

Why can't the name attribute be mapped to the data in elasticsearch without adding it, but a date conversion error will occur after adding it？？？ @JsonFormat(pattern = "yyyy-MM-dd HH:mm:ss",timezone="GMT+8") @DateTimeFo…

---

## [Embedding Kibana dashboard iframe with authentication](https://discuss.elastic.co/t/embedding-kibana-dashboard-iframe-with-authentication/312370)

<div class="topic-metadata">

**Author:** [@bhushan\_pathak](https://discuss.elastic.co/u/bhushan_pathak)\
**Replies:** 1\
**Last updated:** [August 25, 2022, 5:36am UTC](https://discuss.elastic.co/t/embedding-kibana-dashboard-iframe-with-authentication/312370 "2022-08-25T05:36:12Z")

</div>

Hello People, We are using Kibana v7.16.3 in our production. I know there are lots of similar questions asked regarding this topic and I have gone through many of them but they don't seem to answer my question. I am t…

---

## [Any way to make messages on discover readable like the observability version?](https://discuss.elastic.co/t/any-way-to-make-messages-on-discover-readable-like-the-observability-version/312780)

<div class="topic-metadata">

**Author:** [@Houss](https://discuss.elastic.co/u/Houss)\
**Replies:** 2\
**Last updated:** [August 25, 2022, 5:39am UTC](https://discuss.elastic.co/t/any-way-to-make-messages-on-discover-readable-like-the-observability-version/312780 "2022-08-25T05:39:33Z")

</div>

Hello, In the discover panel, the messages look like this : I have to unfold the message to view in the same format as the log file : Is there a way to have it look like this by default ? Observality also has a …

[Previous page](https://discuss.elastic.co/tag/none.md?no_tags=true&page=552)

[Next page](https://discuss.elastic.co/tag/none.md?no_tags=true&page=554)
