# \#none

**URL:** https://discuss.elastic.co/tag/none.md?no_tags=true&page=558

[Latest](https://discuss.elastic.co/latest.md) · [Categories](https://discuss.elastic.co/categories.md) · [Tags](https://discuss.elastic.co/tags.md)

**Page:** 559

---

## [Kibana PagerDuty Connector - ability to select document field as DedupKey option](https://discuss.elastic.co/t/kibana-pagerduty-connector-ability-to-select-document-field-as-dedupkey-option/311530)

<div class="topic-metadata">

**Author:** [@sivanov](https://discuss.elastic.co/u/sivanov)\
**Replies:** 4\
**Last updated:** [August 19, 2022, 7:46am UTC](https://discuss.elastic.co/t/kibana-pagerduty-connector-ability-to-select-document-field-as-dedupkey-option/311530 "2022-08-19T07:46:55Z")

</div>

Hi, As part of PagerDuty integration, we would like to use a document field as a DedupKey field in the setup. I am struggling to find documentation that explains how to reach out, if possible at all, to document fields…

---

## [Static Mappings Ignored by Some Fields While Others Work](https://discuss.elastic.co/t/static-mappings-ignored-by-some-fields-while-others-work/312415)

<div class="topic-metadata">

**Author:** [@othman](https://discuss.elastic.co/u/othman)\
**Replies:** 2\
**Last updated:** [August 19, 2022, 7:41am UTC](https://discuss.elastic.co/t/static-mappings-ignored-by-some-fields-while-others-work/312415 "2022-08-19T07:41:56Z")

</div>

I'm fairly new to ELK stack so most likely I'm just doing something dumb. I've failed to find suitable Google results hence this post. I have an Index Template configured with mappings, and I create a fresh index and st…

---

## [What are the Vulnerabilities of elk 7.17.3v?](https://discuss.elastic.co/t/what-are-the-vulnerabilities-of-elk-7-17-3v/312421)

<div class="topic-metadata">

**Author:** [@jisha](https://discuss.elastic.co/u/jisha)\
**Replies:** 4\
**Last updated:** [August 19, 2022, 7:39am UTC](https://discuss.elastic.co/t/what-are-the-vulnerabilities-of-elk-7-17-3v/312421 "2022-08-19T07:39:02Z")

</div>

what are the Vulnerabilities of elk 7.17.3v ? what are the Solutions to fix those vulnerabilities?

---

## [Regular Expression](https://discuss.elastic.co/t/regular-expression/312426)

<div class="topic-metadata">

**Author:** [@Pranjal\_Sett](https://discuss.elastic.co/u/Pranjal_Sett)\
**Replies:** 0\
**Last updated:** [August 19, 2022, 5:31am UTC](https://discuss.elastic.co/t/regular-expression/312426 "2022-08-19T05:31:09Z")

</div>

Hi, Can anyone please help me with this regular expression!! So, this is my string 'timerange={timerange from=\\"now/d\\" to=\\"now/d\\"}' I want to findall and replace with 'timerange={timerange from=\\"2022-08-19T04:00:00…

---

## [Can we change SSL CA cert after adding license with old SSL](https://discuss.elastic.co/t/can-we-change-ssl-ca-cert-after-adding-license-with-old-ssl/312404)

<div class="topic-metadata">

**Author:** [@Dipesh](https://discuss.elastic.co/u/Dipesh)\
**Replies:** 1\
**Last updated:** [August 19, 2022, 12:13am UTC](https://discuss.elastic.co/t/can-we-change-ssl-ca-cert-after-adding-license-with-old-ssl/312404 "2022-08-19T00:13:04Z")

</div>

HI Team, Currently i am working on Elasticsearch 8.3 with self generated CA Cert and ssl's and i want to add license but have a doubt. can we change CA Certs after Adding License with old certs?

---

## [Add timezone local to all events with fleet-managed elastic agent](https://discuss.elastic.co/t/add-timezone-local-to-all-events-with-fleet-managed-elastic-agent/312408)

<div class="topic-metadata">

**Author:** [@DougR](https://discuss.elastic.co/u/DougR)\
**Replies:** 0\
**Last updated:** [August 18, 2022, 7:55pm UTC](https://discuss.elastic.co/t/add-timezone-local-to-all-events-with-fleet-managed-elastic-agent/312408 "2022-08-18T19:55:04Z")

</div>

Is there a way to include an add\_locale.format: 'offset' processor by default for all events sent in by a fleet-managed elastic agent? I have a number of custom logs that don't have proper timezone indicators, so my inge…

---

## [Migrating the index from 7.14 version to the new elasticsearch cluster with 8.0 version](https://discuss.elastic.co/t/migrating-the-index-from-7-14-version-to-the-new-elasticsearch-cluster-with-8-0-version/312400)

<div class="topic-metadata">

**Author:** [@mruthyu](https://discuss.elastic.co/u/mruthyu)\
**Replies:** 1\
**Last updated:** [August 18, 2022, 7:33pm UTC](https://discuss.elastic.co/t/migrating-the-index-from-7-14-version-to-the-new-elasticsearch-cluster-with-8-0-version/312400 "2022-08-18T19:33:45Z")

</div>

Is it possible to migrate the data from elasticsearch cluster with 7.14 version to new cluster which is having 8.0 version? Is there any migration path has been defined for this activity? Any utilities available?

---

## [Within Enterprise Search Engine, data ingestion/Storage](https://discuss.elastic.co/t/within-enterprise-search-engine-data-ingestion-storage/312213)

<div class="topic-metadata">

**Author:** [@lcui\_dxc](https://discuss.elastic.co/u/lcui_dxc)\
**Replies:** 2\
**Last updated:** [August 18, 2022, 6:11pm UTC](https://discuss.elastic.co/t/within-enterprise-search-engine-data-ingestion-storage/312213 "2022-08-18T18:11:45Z")

</div>

Hello there, I'm new to Elastic Enterprise Search, I have a question: If the source data contains pictures/images, would Elastic ingests the data including the pictures/images and store it to Search Engine shards or ju…

---

## [Filtering directly from data table - Kibana dashboard](https://discuss.elastic.co/t/filtering-directly-from-data-table-kibana-dashboard/312075)

<div class="topic-metadata">

**Author:** [@SaraAlshamsi](https://discuss.elastic.co/u/SaraAlshamsi)\
**Replies:** 3\
**Last updated:** [August 18, 2022, 6:03pm UTC](https://discuss.elastic.co/t/filtering-directly-from-data-table-kibana-dashboard/312075 "2022-08-18T18:03:57Z")

</div>

Hello, I have an issue in filtering directly from a data table in Kibana dashboard. Case 1: When I select an item, to filter it, from the first page of the table, I can filter without any problem and the filter is app…

---

## [RELP plugin does not parse syslogs](https://discuss.elastic.co/t/relp-plugin-does-not-parse-syslogs/312365)

<div class="topic-metadata">

**Author:** [@Fastfox](https://discuss.elastic.co/u/Fastfox)\
**Replies:** 2\
**Last updated:** [August 18, 2022, 4:51pm UTC](https://discuss.elastic.co/t/relp-plugin-does-not-parse-syslogs/312365 "2022-08-18T16:51:30Z")

</div>

Hi there, Getting to know Elastic stack here and I noticed that normal TCP reliability is not enough for my usecase where the device will be powered off suddenly at at arbitrary times. It looks like rsyslog RELP protoco…

---

## [Grok Pattern for java duration](https://discuss.elastic.co/t/grok-pattern-for-java-duration/312386)

<div class="topic-metadata">

**Author:** [@rokka](https://discuss.elastic.co/u/rokka)\
**Replies:** 1\
**Last updated:** [August 18, 2022, 4:45pm UTC](https://discuss.elastic.co/t/grok-pattern-for-java-duration/312386 "2022-08-18T16:45:02Z")

</div>

Hi, how can I parse the Java duration format like "PT20M36.4402321S"? https://docs.oracle.com/javase/8/docs/api/java/time/Duration.html#parse-java.lang.CharSequence- I can´t find an existing pattern on logstash-patter…

---

## [Aggregating child highlights into parent's score and result](https://discuss.elastic.co/t/aggregating-child-highlights-into-parents-score-and-result/312224)

<div class="topic-metadata">

**Author:** [@nickchomey](https://discuss.elastic.co/u/nickchomey)\
**Replies:** 1\
**Last updated:** [August 18, 2022, 4:35pm UTC](https://discuss.elastic.co/t/aggregating-child-highlights-into-parents-score-and-result/312224 "2022-08-18T16:35:29Z")

</div>

I am trying to implement Elasticsearch for a forum (among other things), where we have Forum, Topics and Replies, each being a child of the previous. We can ignore Forum for now and just focus on the Topics and Replies a…

---

## [Update enrich index from logstash](https://discuss.elastic.co/t/update-enrich-index-from-logstash/312378)

<div class="topic-metadata">

**Author:** [@chapmantrain](https://discuss.elastic.co/u/chapmantrain)\
**Replies:** 2\
**Last updated:** [August 18, 2022, 4:12pm UTC](https://discuss.elastic.co/t/update-enrich-index-from-logstash/312378 "2022-08-18T16:12:22Z")

</div>

I have a logstash jdbc pull that updates an index of device information at hourly intervals. That index is used by an enrich processor to add the device information, like sector, country, lat/long, to the data we ingest…

---

## [Can't use elasticsearch connector properly](https://discuss.elastic.co/t/cant-use-elasticsearch-connector-properly/312392)

<div class="topic-metadata">

**Author:** [@Sarindra\_Therese](https://discuss.elastic.co/u/Sarindra_Therese)\
**Replies:** 0\
**Last updated:** [August 18, 2022, 2:18pm UTC](https://discuss.elastic.co/t/cant-use-elasticsearch-connector-properly/312392 "2022-08-18T14:18:23Z")

</div>

Hey, I need to use source connector elasticsearch to send data from elasticsearch to kafka. Unfortunately, i Have some trouble in elasticsearch, maybe i don't configure elasticsearch properly. when i go to this link h…

---

## [Is there something to Filter metrics on Lens?](https://discuss.elastic.co/t/is-there-something-to-filter-metrics-on-lens/312319)

<div class="topic-metadata">

**Author:** [@SamuelSMendes](https://discuss.elastic.co/u/SamuelSMendes)\
**Replies:** 1\
**Last updated:** [August 18, 2022, 1:54pm UTC](https://discuss.elastic.co/t/is-there-something-to-filter-metrics-on-lens/312319 "2022-08-18T13:54:22Z")

</div>

I've been exploring some data on Lens and got to the point where negative values ended up showing up on my data, I just want to pick the ones with "1" on it. I know that in canvas a simple "WHERE" would work but I don't …

---

## [Controlling Elasticsearch hidden indices .kibana\*](https://discuss.elastic.co/t/controlling-elasticsearch-hidden-indices-kibana/312391)

<div class="topic-metadata">

**Author:** [@Mark\_S](https://discuss.elastic.co/u/Mark_S)\
**Replies:** 0\
**Last updated:** [August 18, 2022, 1:31pm UTC](https://discuss.elastic.co/t/controlling-elasticsearch-hidden-indices-kibana/312391 "2022-08-18T13:31:24Z")

</div>

Elasticsearch hidden indices .kibana\_task\_manager and .kibana\_event\_logs are periodically updated. How to change this frequency? Maybe it is some index setting e.g. translog {sync\_interval : "5s"}, or maybe "refresh\_int…

---

## [\[7.10.1\] Elasticsearch java client InterruptedException](https://discuss.elastic.co/t/7-10-1-elasticsearch-java-client-interruptedexception/312389)

<div class="topic-metadata">

**Author:** [@thiago123789](https://discuss.elastic.co/u/thiago123789)\
**Replies:** 0\
**Last updated:** [August 18, 2022, 1:05pm UTC](https://discuss.elastic.co/t/7-10-1-elasticsearch-java-client-interruptedexception/312389 "2022-08-18T13:05:07Z")

</div>

I am using elasticsearch-rest-client version 7.10.1 with spring boot actuator to provide health check but sometimes elasticsearch is returning a null value with InterruptedException in a Future on RestClient. Caused by:…

---

## [How to add aggregions in KNN search?](https://discuss.elastic.co/t/how-to-add-aggregions-in-knn-search/310457)

<div class="topic-metadata">

**Author:** [@namespace-Pt](https://discuss.elastic.co/u/namespace-Pt)\
**Replies:** 4\
**Last updated:** [August 18, 2022, 11:21am UTC](https://discuss.elastic.co/t/how-to-add-aggregions-in-knn-search/310457 "2022-08-18T11:21:07Z")

</div>

I want to use aggregations over the search result of the knn\_search api (because I need facet search on the user interface), but I cannot pass the agg parameter as in the search api. Any suggestions?

---

## [Failed to deserialize response from handler](https://discuss.elastic.co/t/failed-to-deserialize-response-from-handler/312282)

<div class="topic-metadata">

**Author:** [@pspardeshi](https://discuss.elastic.co/u/pspardeshi)\
**Replies:** 2\
**Last updated:** [August 18, 2022, 10:32am UTC](https://discuss.elastic.co/t/failed-to-deserialize-response-from-handler/312282 "2022-08-18T10:32:17Z")

</div>

I am using scala+java application and running it on jdk 11 and calling Elasticsearch api for searching text. Recently upgraded from elasticsearch 5.5 to 7.17 and while search text getting below error. ERROR play.http.D…

---

## [What is the correct way to request /intake/v2/rum/events?](https://discuss.elastic.co/t/what-is-the-correct-way-to-request-intake-v2-rum-events/312362)

<div class="topic-metadata">

**Author:** [@wajika](https://discuss.elastic.co/u/wajika)\
**Replies:** 0\
**Last updated:** [August 18, 2022, 8:41am UTC](https://discuss.elastic.co/t/what-is-the-correct-way-to-request-intake-v2-rum-events/312362 "2022-08-18T08:41:56Z")

</div>

from locust import HttpLocust, TaskSet, task, HttpUser, run\_single\_user class QuickstartUser(HttpUser): host = "https://apmserver" @task() def user\_sign(self): payload = "{\\"metadata\\": {\\"service\\"…

---

## [Data Transformation : Create Dynamic field using ruby for array](https://discuss.elastic.co/t/data-transformation-create-dynamic-field-using-ruby-for-array/312249)

<div class="topic-metadata">

**Author:** [@priyankamondalhcl](https://discuss.elastic.co/u/priyankamondalhcl)\
**Replies:** 2\
**Last updated:** [August 18, 2022, 8:11am UTC](https://discuss.elastic.co/t/data-transformation-create-dynamic-field-using-ruby-for-array/312249 "2022-08-18T08:11:25Z")

</div>

Hi Team, Hope you doing well! I am facing problem in creating dynamic field for an array in logstash. The list of array is below: \[{"usage\_start\_time": "2022-08-07T22:00:00Z", "usage\_end\_time": "2022-08-07T23:00:00Z…

---

## [Coordonating statistics for coordonating nodes](https://discuss.elastic.co/t/coordonating-statistics-for-coordonating-nodes/311834)

<div class="topic-metadata">

**Author:** [@Nicolaegis](https://discuss.elastic.co/u/Nicolaegis)\
**Replies:** 8\
**Last updated:** [August 18, 2022, 8:02am UTC](https://discuss.elastic.co/t/coordonating-statistics-for-coordonating-nodes/311834 "2022-08-18T08:02:29Z")

</div>

Hello, I know that all data nodes (role) have coordinating role as well. If I make a coordinating node in a cluster, how can I check it's statistics and performance from an ordinary data node? Thank you

---

## [Upgrade from 5.3.1 to 6.8.23](https://discuss.elastic.co/t/upgrade-from-5-3-1-to-6-8-23/312339)

<div class="topic-metadata">

**Author:** [@Andrey\_Tyutyunov](https://discuss.elastic.co/u/Andrey_Tyutyunov)\
**Replies:** 1\
**Last updated:** [August 18, 2022, 7:53am UTC](https://discuss.elastic.co/t/upgrade-from-5-3-1-to-6-8-23/312339 "2022-08-18T07:53:52Z")

</div>

Good day! I have 3 nodes on 5.3.1 (index"es created in 5" version) and I need to upgrade to 6.8.23 without downtime. My plan is 5.3.1 -\> 5.6.16, 5.6.16 -\> 6.8.23. Can I upgrade according to this scheme? 5.3.1 + 5.3.1…

---

## [Searching array for empty string causes tab lockup and shows garbage](https://discuss.elastic.co/t/searching-array-for-empty-string-causes-tab-lockup-and-shows-garbage/312149)

<div class="topic-metadata">

**Author:** [@nisow95612](https://discuss.elastic.co/u/nisow95612)\
**Replies:** 4\
**Last updated:** [August 18, 2022, 7:52am UTC](https://discuss.elastic.co/t/searching-array-for-empty-string-causes-tab-lockup-and-shows-garbage/312149 "2022-08-18T07:52:35Z")

</div>

Hello. I have a keyword field in elastic. I index arrays of string into it. I usually search with KQL like field: value and it works. But how I search for empty string? I tried field:, but that gives Search Error. …

---

## [AWS WAF: Further parsing of http\_request in logstash](https://discuss.elastic.co/t/aws-waf-further-parsing-of-http-request-in-logstash/312347)

<div class="topic-metadata">

**Author:** [@kelk](https://discuss.elastic.co/u/kelk)\
**Replies:** 0\
**Last updated:** [August 18, 2022, 7:00am UTC](https://discuss.elastic.co/t/aws-waf-further-parsing-of-http-request-in-logstash/312347 "2022-08-18T07:00:24Z")

</div>

Further to the query: Writing multiline grok The raw data comes in json, so the NEW line is technically new line but \\r\\n in the json payload. "GET /myapp/health HTTP/1.1\\\\r\\\\nHost: 52.123.133.46\\\\r\\\\nUser-Agent: Mozil…

---

## [Value Mapping in Kibana](https://discuss.elastic.co/t/value-mapping-in-kibana/311902)

<div class="topic-metadata">

**Author:** [@saif.khan](https://discuss.elastic.co/u/saif.khan)\
**Replies:** 17\
**Last updated:** [August 18, 2022, 6:52am UTC](https://discuss.elastic.co/t/value-mapping-in-kibana/311902 "2022-08-18T06:52:42Z")

</div>

Hi, I'm setting up a dashboard and receiving data from prometheus through metricbeat, I'm facing problem when it comes to value mapping, in my case for "DoorStatus" i want to map the default integer values in 0 and 1 to…

---

## [Logstash Reading Same Data](https://discuss.elastic.co/t/logstash-reading-same-data/312251)

<div class="topic-metadata">

**Author:** [@mehmetalix](https://discuss.elastic.co/u/mehmetalix)\
**Replies:** 1\
**Last updated:** [August 18, 2022, 6:49am UTC](https://discuss.elastic.co/t/logstash-reading-same-data/312251 "2022-08-18T06:49:22Z")

</div>

Hi, I have a logstash .conf: input { jdbc { jdbc\_driver\_library =\> "${LOGSTASH\_JDBC\_DRIVER\_JAR\_LOCATION}" jdbc\_driver\_class =\> "${LOGSTASH\_JDBC\_DRIVER}" jdbc\_connection\_string =\> "${LOGSTASH…

---

## [Value not greater 20% of the average value of the same job](https://discuss.elastic.co/t/value-not-greater-20-of-the-average-value-of-the-same-job/310832)

<div class="topic-metadata">

**Author:** [@eddieyee](https://discuss.elastic.co/u/eddieyee)\
**Replies:** 2\
**Last updated:** [August 18, 2022, 6:23am UTC](https://discuss.elastic.co/t/value-not-greater-20-of-the-average-value-of-the-same-job/310832 "2022-08-18T06:23:11Z")

</div>

Hi I'm trying to create a data table as seem in the screenshot below. Basically I need to compare the current document duration field value not higher than 20% of the average duration of the same job. Have tried using …

---

## [Timezone problem when output to Elasticsearch](https://discuss.elastic.co/t/timezone-problem-when-output-to-elasticsearch/312252)

<div class="topic-metadata">

**Author:** [@kent010341](https://discuss.elastic.co/u/kent010341)\
**Replies:** 10\
**Last updated:** [August 18, 2022, 4:36am UTC](https://discuss.elastic.co/t/timezone-problem-when-output-to-elasticsearch/312252 "2022-08-18T04:36:14Z")

</div>

I have multiple log files with the date on their file name, and I want to read them with the file input plugin and send them to an Elasticsearch index (the index name contains the date). However, I have some logs being …

---

## [Gcp pubsub input error](https://discuss.elastic.co/t/gcp-pubsub-input-error/312333)

<div class="topic-metadata">

**Author:** [@Gustavo\_Llermaly](https://discuss.elastic.co/u/Gustavo_Llermaly)\
**Replies:** 0\
**Last updated:** [August 18, 2022, 3:02am UTC](https://discuss.elastic.co/t/gcp-pubsub-input-error/312333 "2022-08-18T03:02:56Z")

</div>

Logstash 8.3.3, having this error with gcp pubsub input. Trying with basic settings. \[2022-08-17T22:52:45,136\]\[ERROR\]\[logstash.javapipeline \]\[main\]\[69466b68efba17b190dd16bcd12466cd5488773b860c9a0f79fa6c7c65f5ec61\] A …

[Previous page](https://discuss.elastic.co/tag/none.md?no_tags=true&page=557)

[Next page](https://discuss.elastic.co/tag/none.md?no_tags=true&page=559)
