# \#none

**URL:** https://discuss.elastic.co/tag/none.md?no_tags=true&page=564

[Latest](https://discuss.elastic.co/latest.md) · [Categories](https://discuss.elastic.co/categories.md) · [Tags](https://discuss.elastic.co/tags.md)

**Page:** 565

---

## [Oauth2 proxy and kibana authentication](https://discuss.elastic.co/t/oauth2-proxy-and-kibana-authentication/311840)

<div class="topic-metadata">

**Author:** [@crimson\_riot](https://discuss.elastic.co/u/crimson_riot)\
**Replies:** 1\
**Last updated:** [August 10, 2022, 2:51pm UTC](https://discuss.elastic.co/t/oauth2-proxy-and-kibana-authentication/311840 "2022-08-10T14:51:15Z")

</div>

We are using Oauth2 reverse proxy to authenticate the users via google. We want to use a static username and password from kibana+elasticsearch once the user gets authenticate via google so that we dont have to add or de…

---

## [Extract value from message field ( runtime fields)](https://discuss.elastic.co/t/extract-value-from-message-field-runtime-fields/311679)

<div class="topic-metadata">

**Author:** [@jplopezy](https://discuss.elastic.co/u/jplopezy)\
**Replies:** 16\
**Last updated:** [August 10, 2022, 2:23pm UTC](https://discuss.elastic.co/t/extract-value-from-message-field-runtime-fields/311679 "2022-08-10T14:23:44Z")

</div>

Hello everyone, Currently, I have an OpenVPN log that is sent from the server to elastic... from what I see the fields are pretty generic and the most important one is "message", it has all the information and I can't p…

---

## [Merge two csv files into single csv file using logstash](https://discuss.elastic.co/t/merge-two-csv-files-into-single-csv-file-using-logstash/311478)

<div class="topic-metadata">

**Author:** [@r.ganeshbabu](https://discuss.elastic.co/u/r.ganeshbabu)\
**Replies:** 4\
**Last updated:** [August 10, 2022, 2:21pm UTC](https://discuss.elastic.co/t/merge-two-csv-files-into-single-csv-file-using-logstash/311478 "2022-08-10T14:21:31Z")

</div>

Hi All, I am trying to merge two csv files into single csv file using logstash and below is the sample data and config I have tried, logstash-1.csv Sample,Gender,Age 1,dentist,10 2,doctor,20 3,rep,30 logstash-2.csv S…

---

## [Nested search works not as expected](https://discuss.elastic.co/t/nested-search-works-not-as-expected/311841)

<div class="topic-metadata">

**Author:** [@wegad61878](https://discuss.elastic.co/u/wegad61878)\
**Replies:** 0\
**Last updated:** [August 10, 2022, 2:17pm UTC](https://discuss.elastic.co/t/nested-search-works-not-as-expected/311841 "2022-08-10T14:17:57Z")

</div>

Hello, I have the following documents \[ { "id": "Car#1", "accessories": \[ { "type": "Turbo", "price": 20 }, { "type": "Supercharger", "price": 30 } …

---

## [Lots of open ports and traffic towards elasticsearch](https://discuss.elastic.co/t/lots-of-open-ports-and-traffic-towards-elasticsearch/311835)

<div class="topic-metadata">

**Author:** [@Mark\_S](https://discuss.elastic.co/u/Mark_S)\
**Replies:** 3\
**Last updated:** [August 10, 2022, 2:09pm UTC](https://discuss.elastic.co/t/lots-of-open-ports-and-traffic-towards-elasticsearch/311835 "2022-08-10T14:09:08Z")

</div>

I have logstash, kibana on one server and another one runs elasticsearch. I have three open pipelines collecting logfile data. I noticed a lot of open ports (277 established TCP connections in the range 45000 - 55000). …

---

## [Elastic Search Queries](https://discuss.elastic.co/t/elastic-search-queries/311764)

<div class="topic-metadata">

**Author:** [@Aravind1](https://discuss.elastic.co/u/Aravind1)\
**Replies:** 3\
**Last updated:** [August 10, 2022, 1:51pm UTC](https://discuss.elastic.co/t/elastic-search-queries/311764 "2022-08-10T13:51:29Z")

</div>

Hi, We are having a few queries on Elasticsearch logs optimization, We want to see the breakup of logs in each running resource also we have quires on how to analyze the logs based on the storage utilization and how man…

---

## [Can dynamic mapping templates block a particular field from being mapped?](https://discuss.elastic.co/t/can-dynamic-mapping-templates-block-a-particular-field-from-being-mapped/311837)

<div class="topic-metadata">

**Author:** [@nisow95612](https://discuss.elastic.co/u/nisow95612)\
**Replies:** 0\
**Last updated:** [August 10, 2022, 1:45pm UTC](https://discuss.elastic.co/t/can-dynamic-mapping-templates-block-a-particular-field-from-being-mapped/311837 "2022-08-10T13:45:41Z")

</div>

I have an index template set to "dynamic": "enable", which causes all fields to be added into the mapping. But what if there are fields that I explicitely do not want to be mapped? I know that dynamic templates can chan…

---

## [Elastic cluster nodes in different subnet](https://discuss.elastic.co/t/elastic-cluster-nodes-in-different-subnet/311771)

<div class="topic-metadata">

**Author:** [@elasticforme](https://discuss.elastic.co/u/elasticforme)\
**Replies:** 3\
**Last updated:** [August 10, 2022, 1:40pm UTC](https://discuss.elastic.co/t/elastic-cluster-nodes-in-different-subnet/311771 "2022-08-10T13:40:38Z")

</div>

If I setup data node in X network subnet and master in Y subnet will it give me grief? all systems will have 10x2 = 20gig bonded network. They are not in different zone. Same datacenter just different subnet.

---

## [Shard allocation filtering for replications](https://discuss.elastic.co/t/shard-allocation-filtering-for-replications/311813)

<div class="topic-metadata">

**Author:** [@Pieter\_Agenbag](https://discuss.elastic.co/u/Pieter_Agenbag)\
**Replies:** 2\
**Last updated:** [August 10, 2022, 1:37pm UTC](https://discuss.elastic.co/t/shard-allocation-filtering-for-replications/311813 "2022-08-10T13:37:36Z")

</div>

Hi i was wondering if there was a way to route replicas to specific nodes in a cluster in the same way you can do shards with the allocation filtering. ?? My scenario is : I have a server with two blades in - each blad…

---

## [Unable to Vizualize Documents with Dates](https://discuss.elastic.co/t/unable-to-vizualize-documents-with-dates/311762)

<div class="topic-metadata">

**Author:** [@jhop](https://discuss.elastic.co/u/jhop)\
**Replies:** 3\
**Last updated:** [August 10, 2022, 1:23pm UTC](https://discuss.elastic.co/t/unable-to-vizualize-documents-with-dates/311762 "2022-08-10T13:23:09Z")

</div>

I am having trouble visualizing indices with dates in Kibana. It appears I am entering data correctly since I see the data when I do a GET request. However, I cannot visualize it after I create a data view. Kibana see…

---

## [Logstash conf file will not work after filter section is added](https://discuss.elastic.co/t/logstash-conf-file-will-not-work-after-filter-section-is-added/311770)

<div class="topic-metadata">

**Author:** [@Lori\_Wallace](https://discuss.elastic.co/u/Lori_Wallace)\
**Replies:** 6\
**Last updated:** [August 10, 2022, 1:02pm UTC](https://discuss.elastic.co/t/logstash-conf-file-will-not-work-after-filter-section-is-added/311770 "2022-08-10T13:02:28Z")

</div>

I am trying to ingest logs from a checkpoint firewall. My logstash config file checks out and works as long as I don't have the filter section in it. However, I need the data filtered so can you guys help me figure out w…

---

## [Logstash 6.8.23 Cannot put data into elastic index, mapping issue](https://discuss.elastic.co/t/logstash-6-8-23-cannot-put-data-into-elastic-index-mapping-issue/310940)

<div class="topic-metadata">

**Author:** [@Akhil\_Chandran](https://discuss.elastic.co/u/Akhil_Chandran)\
**Replies:** 8\
**Last updated:** [August 10, 2022, 12:59pm UTC](https://discuss.elastic.co/t/logstash-6-8-23-cannot-put-data-into-elastic-index-mapping-issue/310940 "2022-08-10T12:59:26Z")

</div>

HI, I am trying to pass data from logstash to ES index, but it throws error as shown below 2022-07-28T10:28:17,909\]\[WARN \]\[logstash.outputs.elasticsearch\] Could not index event to Elasticsearch. {:status=\>400, :action=\>\[…

---

## [Can Kibana do this?](https://discuss.elastic.co/t/can-kibana-do-this/311337)

<div class="topic-metadata">

**Author:** [@Va1-ha11a](https://discuss.elastic.co/u/Va1-ha11a)\
**Replies:** 1\
**Last updated:** [August 10, 2022, 12:14pm UTC](https://discuss.elastic.co/t/can-kibana-do-this/311337 "2022-08-10T12:14:26Z")

</div>

I'm new to Elastic and Kibana. I've been tasked with investigating Kibana as a solution for our system uptime reporting. Our Elastic 7 logs state codes for our system, where up =1, down =2 etc. every two minutes. For rep…

---

## [Unsupported Media Type when calling import API](https://discuss.elastic.co/t/unsupported-media-type-when-calling-import-api/311742)

<div class="topic-metadata">

**Author:** [@Martin\_Hartmann](https://discuss.elastic.co/u/Martin_Hartmann)\
**Replies:** 1\
**Last updated:** [August 10, 2022, 11:19am UTC](https://discuss.elastic.co/t/unsupported-media-type-when-calling-import-api/311742 "2022-08-10T11:19:51Z")

</div>

Hi. We run Kibana in v 7.17.3 and when calling the /api/saved\_objects/\_imports API, we get a 415 - Unsupported Media Type error as response for some clients. Our go client doesn't work: REQUEST: POST /api/saved\_objects/…

---

## [Unable to update the index.mapping.total\_fields.limit value](https://discuss.elastic.co/t/unable-to-update-the-index-mapping-total-fields-limit-value/311795)

<div class="topic-metadata">

**Author:** [@Maruthappan\_Muthu](https://discuss.elastic.co/u/Maruthappan_Muthu)\
**Replies:** 4\
**Last updated:** [August 10, 2022, 10:22am UTC](https://discuss.elastic.co/t/unable-to-update-the-index-mapping-total-fields-limit-value/311795 "2022-08-10T10:22:37Z")

</div>

We are trying to poll the data from a device (PDU) through SNMP Input Plugin. The device MIB file has been imported to ELK logstash, as per SNMP input plugin | Logstash Reference \[8.3\] | Elastic. When executing the snmp…

---

## [Kibana search d](https://discuss.elastic.co/t/kibana-search-d/311809)

<div class="topic-metadata">

**Author:** [@cihady](https://discuss.elastic.co/u/cihady)\
**Replies:** 4\
**Last updated:** [August 10, 2022, 9:06am UTC](https://discuss.elastic.co/t/kibana-search-d/311809 "2022-08-10T09:06:13Z")

</div>

I am searching for specific text in my logs text is $2a$10$Ltijvm9V in KQL search I wrote message.keyword : "$2a$10$Ltijvm9V2eA" it returns nothing and says expand your time rang but before search I can see the text. …

---

## [Why does the must\_not query work if you place it before a nested query but not if you place it inside the nested query?](https://discuss.elastic.co/t/why-does-the-must-not-query-work-if-you-place-it-before-a-nested-query-but-not-if-you-place-it-inside-the-nested-query/311748)

<div class="topic-metadata">

**Author:** [@Vincent92](https://discuss.elastic.co/u/Vincent92)\
**Replies:** 0\
**Last updated:** [August 9, 2022, 2:34pm UTC](https://discuss.elastic.co/t/why-does-the-must-not-query-work-if-you-place-it-before-a-nested-query-but-not-if-you-place-it-inside-the-nested-query/311748 "2022-08-09T14:34:32Z")

</div>

Hello, I'm writing an application to search for logs in the elastic of my organization and the user can search for nested queries of this form: pathName:{ field1: "value1" AND field2: "value2" OR field3: "value3" } I …

---

## [To control the log flows in kibana end through logstash config](https://discuss.elastic.co/t/to-control-the-log-flows-in-kibana-end-through-logstash-config/310499)

<div class="topic-metadata">

**Author:** [@yasar](https://discuss.elastic.co/u/yasar)\
**Replies:** 16\
**Last updated:** [August 10, 2022, 8:57am UTC](https://discuss.elastic.co/t/to-control-the-log-flows-in-kibana-end-through-logstash-config/310499 "2022-08-10T08:57:32Z")

</div>

HI team, We have getting the huge logs when application team doing the Performance testing. At that time, Our cluster is not stable due to unable to handle the huge much of load. Could you please help us to control the…

---

## [How to use aggregation fields in Watcher action body (with foreach loop)?](https://discuss.elastic.co/t/how-to-use-aggregation-fields-in-watcher-action-body-with-foreach-loop/310758)

<div class="topic-metadata">

**Author:** [@111238](https://discuss.elastic.co/u/111238)\
**Replies:** 1\
**Last updated:** [August 10, 2022, 8:20am UTC](https://discuss.elastic.co/t/how-to-use-aggregation-fields-in-watcher-action-body-with-foreach-loop/310758 "2022-08-10T08:20:17Z")

</div>

Hi there. I'm currently trying to create a watcher with foreach loop (per aggregation bucket). The actual loop works fine. Though, I have a problem accessing "ctx.payload.aggregations." to include a specific field from…

---

## [Elasticsearch returns two documents with same ID but different versions](https://discuss.elastic.co/t/elasticsearch-returns-two-documents-with-same-id-but-different-versions/311802)

<div class="topic-metadata">

**Author:** [@Andrey\_Tyutyunov](https://discuss.elastic.co/u/Andrey_Tyutyunov)\
**Replies:** 11\
**Last updated:** [August 10, 2022, 8:13am UTC](https://discuss.elastic.co/t/elasticsearch-returns-two-documents-with-same-id-but-different-versions/311802 "2022-08-10T08:13:59Z")

</div>

ES version: 5.3.1 Some documents returns twice, updated and previous version rq /purchases/payments/\_search?q=\_id:AYKCmqWVUjd1dFdxujwy&version=true Why it happens? How to fix it?

---

## [System index responsible for \_cat/shards](https://discuss.elastic.co/t/system-index-responsible-for-cat-shards/311678)

<div class="topic-metadata">

**Author:** [@kossde](https://discuss.elastic.co/u/kossde)\
**Replies:** 7\
**Last updated:** [August 10, 2022, 7:36am UTC](https://discuss.elastic.co/t/system-index-responsible-for-cat-shards/311678 "2022-08-10T07:36:36Z")

</div>

Can anyone tell me which indices are responsible for the data pulled in when using the \_cat/shards API?

---

## [Do i have to make user and role in kibana?](https://discuss.elastic.co/t/do-i-have-to-make-user-and-role-in-kibana/311801)

<div class="topic-metadata">

**Author:** [@hellocomputer](https://discuss.elastic.co/u/hellocomputer)\
**Replies:** 0\
**Last updated:** [August 10, 2022, 7:23am UTC](https://discuss.elastic.co/t/do-i-have-to-make-user-and-role-in-kibana/311801 "2022-08-10T07:23:09Z")

</div>

Hello! I'm using ELK stack 8.3.2 version and ubuntu20.04 version. I want to know that I have to make user in kibana? First, I tried to https SSL security in elasticsearch, kibana. But I couldn't make trusted cert fil…

---

## [Elasticsearch - Could not index event to Elasticsearch status=\>400](https://discuss.elastic.co/t/elasticsearch-could-not-index-event-to-elasticsearch-status-400/311101)

<div class="topic-metadata">

**Author:** [@Maruthappan\_Muthu](https://discuss.elastic.co/u/Maruthappan_Muthu)\
**Replies:** 4\
**Last updated:** [August 10, 2022, 6:38am UTC](https://discuss.elastic.co/t/elasticsearch-could-not-index-event-to-elasticsearch-status-400/311101 "2022-08-10T06:38:35Z")

</div>

We are trying to poll the data from a device (PDU) through SNMP Input Plugin. The device MIB file has been imported to ELK logstash, as per SNMP input plugin | Logstash Reference \[8.3\] | Elastic. When executing the snmp…

---

## [Where is logstash.service file?](https://discuss.elastic.co/t/where-is-logstash-service-file/311784)

<div class="topic-metadata">

**Author:** [@hellocomputer](https://discuss.elastic.co/u/hellocomputer)\
**Replies:** 0\
**Last updated:** [August 10, 2022, 3:47am UTC](https://discuss.elastic.co/t/where-is-logstash-service-file/311784 "2022-08-10T03:47:00Z")

</div>

Hello I'm using ubuntu20.04 and logstash 8.3.2 version. I want to set TimeoutStopSec=300 this command! but I couldn't find logstash.service file in /etc/systemd/system/logstash.service in this location. so, wh…

---

## [How to filter json object field class, java.lang.ClassCastException: class org.jruby.RubyHash cannot be cast to class org.jruby.RubyIO](https://discuss.elastic.co/t/how-to-filter-json-object-field-class-java-lang-classcastexception-class-org-jruby-rubyhash-cannot-be-cast-to-class-org-jruby-rubyio/311779)

<div class="topic-metadata">

**Author:** [@HeChuanXUPT](https://discuss.elastic.co/u/HeChuanXUPT)\
**Replies:** 0\
**Last updated:** [August 10, 2022, 1:20am UTC](https://discuss.elastic.co/t/how-to-filter-json-object-field-class-java-lang-classcastexception-class-org-jruby-rubyhash-cannot-be-cast-to-class-org-jruby-rubyio/311779 "2022-08-10T01:20:45Z")

</div>

input file content: {"\_source": {"timestamp": 1612256372000, "date": "2021-02-02 16:59:32", "ip": "127.175.208.130"}} logstash.conf: input { file { path =\> \["/tmp/test\_file"\] start\_position =\> "beginning" …

---

## [How to set start and end point of a prebuild grok pattern](https://discuss.elastic.co/t/how-to-set-start-and-end-point-of-a-prebuild-grok-pattern/311749)

<div class="topic-metadata">

**Author:** [@cihady](https://discuss.elastic.co/u/cihady)\
**Replies:** 6\
**Last updated:** [August 9, 2022, 8:43pm UTC](https://discuss.elastic.co/t/how-to-set-start-and-end-point-of-a-prebuild-grok-pattern/311749 "2022-08-09T20:43:59Z")

</div>

My grok patter broken when there is a |(pipe) in my data . here is my log \> 16:29:52.143 \[kafka-producer-network-thread | producer-1\] INFO c.h.h.d.e.ApiMessageProducer - ===============================================…

---

## [Elastic Certified Observability Engineer Practice Exam in still in V7.9](https://discuss.elastic.co/t/elastic-certified-observability-engineer-practice-exam-in-still-in-v7-9/311765)

<div class="topic-metadata">

**Author:** [@julie.zhong](https://discuss.elastic.co/u/julie.zhong)\
**Replies:** 2\
**Last updated:** [August 9, 2022, 8:20pm UTC](https://discuss.elastic.co/t/elastic-certified-observability-engineer-practice-exam-in-still-in-v7-9/311765 "2022-08-09T20:20:53Z")

</div>

Hi, dear elastic training team, I enrolled in the Elastic Certified Observability Engineer Practice Exam on Aug 05th, and I expected it should be using kibana V8, as the Elastic Certified Observability Engineer Exam is …

---

## [ES filter composite aggregation result by doc\_count](https://discuss.elastic.co/t/es-filter-composite-aggregation-result-by-doc-count/311727)

<div class="topic-metadata">

**Author:** [@mirokrastev](https://discuss.elastic.co/u/mirokrastev)\
**Replies:** 3\
**Last updated:** [August 9, 2022, 7:29pm UTC](https://discuss.elastic.co/t/es-filter-composite-aggregation-result-by-doc-count/311727 "2022-08-09T19:29:28Z")

</div>

I have the following ES query: GET my-index/\_search { "size": 0, "aggs": { "my\_bucket": { "composite": { "size": 10000, "sources": \[ { "stk1": { "terms":…

---

## [Data node calculation based on "Number of shards per node below 20 per GB heap it has configured"](https://discuss.elastic.co/t/data-node-calculation-based-on-number-of-shards-per-node-below-20-per-gb-heap-it-has-configured/311534)

<div class="topic-metadata">

**Author:** [@sree\_sk](https://discuss.elastic.co/u/sree_sk)\
**Replies:** 7\
**Last updated:** [August 9, 2022, 7:17pm UTC](https://discuss.elastic.co/t/data-node-calculation-based-on-number-of-shards-per-node-below-20-per-gb-heap-it-has-configured/311534 "2022-08-09T19:17:46Z")

</div>

I have the following scenario where, Data volume of an index is 85GB/day with a daily index rotation and retention of 90 days. Similarly I have 14 other indices with the same data volume per day. I have a system which…

---

## [Elastic Agent Doesn't Seem To Be Collecting Winlogbeat Data](https://discuss.elastic.co/t/elastic-agent-doesnt-seem-to-be-collecting-winlogbeat-data/311761)

<div class="topic-metadata">

**Author:** [@Jared9922](https://discuss.elastic.co/u/Jared9922)\
**Replies:** 0\
**Last updated:** [August 9, 2022, 4:56pm UTC](https://discuss.elastic.co/t/elastic-agent-doesnt-seem-to-be-collecting-winlogbeat-data/311761 "2022-08-09T16:56:09Z")

</div>

I am working on getting elastic security setup. I am using a self-managed elastic stack. I have successfully added a fleet server and an elastic agent. The elastic agent is added to a Windows machine. The agent is sendin…

[Previous page](https://discuss.elastic.co/tag/none.md?no_tags=true&page=563)

[Next page](https://discuss.elastic.co/tag/none.md?no_tags=true&page=565)
