# \#none

**URL:** https://discuss.elastic.co/tag/none.md?no_tags=true&page=567

[Latest](https://discuss.elastic.co/latest.md) · [Categories](https://discuss.elastic.co/categories.md) · [Tags](https://discuss.elastic.co/tags.md)

**Page:** 568

---

## [Elasticsearch not forming a cluster in kubernetes](https://discuss.elastic.co/t/elasticsearch-not-forming-a-cluster-in-kubernetes/311463)

<div class="topic-metadata">

**Author:** [@willsc](https://discuss.elastic.co/u/willsc)\
**Replies:** 1\
**Last updated:** [August 6, 2022, 8:29am UTC](https://discuss.elastic.co/t/elasticsearch-not-forming-a-cluster-in-kubernetes/311463 "2022-08-06T08:29:53Z")

</div>

Can anyone assist with trying to work out why an es cluster doesnt discover it nodes in kubernetes. Currently deploying 7.17.4 in an rke2 cluster, that claims to have no network policy. Elastic is being deployed as a s…

---

## [Logstash showing error when executed from python but executes from terminal](https://discuss.elastic.co/t/logstash-showing-error-when-executed-from-python-but-executes-from-terminal/311508)

<div class="topic-metadata">

**Author:** [@Morning\_Star](https://discuss.elastic.co/u/Morning_Star)\
**Replies:** 4\
**Last updated:** [August 6, 2022, 6:15am UTC](https://discuss.elastic.co/t/logstash-showing-error-when-executed-from-python-but-executes-from-terminal/311508 "2022-08-06T06:15:49Z")

</div>

I'm new to ELK stack and any help would be appriciated I have tried both os and subprocess both are giving same error This is getting executed from terminal \` /usr/share/logstash/bin/logstash -f /root/folder1/folder…

---

## [Aggregated Logs and Reformatting for QRADAR](https://discuss.elastic.co/t/aggregated-logs-and-reformatting-for-qradar/311557)

<div class="topic-metadata">

**Author:** [@ombit](https://discuss.elastic.co/u/ombit)\
**Replies:** 1\
**Last updated:** [August 6, 2022, 5:28am UTC](https://discuss.elastic.co/t/aggregated-logs-and-reformatting-for-qradar/311557 "2022-08-06T05:28:03Z")

</div>

Hi all, I'm currently researching logstash (along with filebeat) as a possible solution for a problem we're seeing. We currently have a log server that is acting as a central manager, with a bunch of different Linux an…

---

## [Logstash port 5044 is not listening after logstash Installation](https://discuss.elastic.co/t/logstash-port-5044-is-not-listening-after-logstash-installation/311472)

<div class="topic-metadata">

**Author:** [@Nilesh1997](https://discuss.elastic.co/u/Nilesh1997)\
**Replies:** 2\
**Last updated:** [August 6, 2022, 4:56am UTC](https://discuss.elastic.co/t/logstash-port-5044-is-not-listening-after-logstash-installation/311472 "2022-08-06T04:56:52Z")

</div>

Dear all, I would like to receive log from remote server through file beat .However I find the port 5044 is not listening but status of logstash is active and enable. I did all the configuration needed for logstash.any …

---

## [I created a plugin in kibana, and I wanted to rename its header](https://discuss.elastic.co/t/i-created-a-plugin-in-kibana-and-i-wanted-to-rename-its-header/311441)

<div class="topic-metadata">

**Author:** [@Gabriel\_Vasconcelos](https://discuss.elastic.co/u/Gabriel_Vasconcelos)\
**Replies:** 1\
**Last updated:** [August 5, 2022, 8:46pm UTC](https://discuss.elastic.co/t/i-created-a-plugin-in-kibana-and-i-wanted-to-rename-its-header/311441 "2022-08-05T20:46:24Z")

</div>

Hi guys, I wanted to ask for your help. I created a plugin in kibana, but when I access it, in its header is the name "Kibana" and I would like to rename it to the name of my application, could you help me? Here is the i…

---

## [Repeat field extraction and aggregation](https://discuss.elastic.co/t/repeat-field-extraction-and-aggregation/311558)

<div class="topic-metadata">

**Author:** [@RitzMak](https://discuss.elastic.co/u/RitzMak)\
**Replies:** 6\
**Last updated:** [August 5, 2022, 7:49pm UTC](https://discuss.elastic.co/t/repeat-field-extraction-and-aggregation/311558 "2022-08-05T19:49:17Z")

</div>

Hello All, I have some logs as below and I would like to get a total of all CACHE\_TIMING and DATABASE\_TIMING fields. I am thinking to create an array of these fields using gsub replacement and kv filter and then add the…

---

## [Subfield query not returning any data](https://discuss.elastic.co/t/subfield-query-not-returning-any-data/311561)

<div class="topic-metadata">

**Author:** [@Baerswords](https://discuss.elastic.co/u/Baerswords)\
**Replies:** 4\
**Last updated:** [August 5, 2022, 6:44pm UTC](https://discuss.elastic.co/t/subfield-query-not-returning-any-data/311561 "2022-08-05T18:44:21Z")

</div>

New to Elasticsearch, so please bear with me if this is a simple question that I should know. I have an index with fairly simple documents. When I try to query against anything in AppDataDict, though, I don't ever get …

---

## [Enforcing events to be outputted in order](https://discuss.elastic.co/t/enforcing-events-to-be-outputted-in-order/311552)

<div class="topic-metadata">

**Author:** [@ebram96](https://discuss.elastic.co/u/ebram96)\
**Replies:** 0\
**Last updated:** [August 5, 2022, 3:27pm UTC](https://discuss.elastic.co/t/enforcing-events-to-be-outputted-in-order/311552 "2022-08-05T15:27:07Z")

</div>

I've a pipeline like this: input { jdbc { jdbc\_driver\_library =\> "/usr/share/logstash/logstash-core/lib/jars/postgresql-42.2.6.jar" jdbc\_driver\_class =\> "org.postgresql.Driver" jdbc\_connection\_string =\> "$…

---

## [FsCrawler add script to \_settings.yaml file](https://discuss.elastic.co/t/fscrawler-add-script-to-settings-yaml-file/311524)

<div class="topic-metadata">

**Author:** [@Julien70](https://discuss.elastic.co/u/Julien70)\
**Replies:** 2\
**Last updated:** [August 5, 2022, 3:05pm UTC](https://discuss.elastic.co/t/fscrawler-add-script-to-settings-yaml-file/311524 "2022-08-05T15:05:06Z")

</div>

Hi everyone, I have a lot of geotagged photos (among other geodata). I have imported them into Elastic (v7.11) with FsCrawler (v2.9 for es7). It's working pretty well. But, the fields "latitude" "longitude" taken from…

---

## [How can i extract timestamp from my log in logstash](https://discuss.elastic.co/t/how-can-i-extract-timestamp-from-my-log-in-logstash/311484)

<div class="topic-metadata">

**Author:** [@Akumar22](https://discuss.elastic.co/u/Akumar22)\
**Replies:** 1\
**Last updated:** [August 5, 2022, 2:41pm UTC](https://discuss.elastic.co/t/how-can-i-extract-timestamp-from-my-log-in-logstash/311484 "2022-08-05T14:41:59Z")

</div>

Below is the format of my logs 05-08-2022 13:20:13,468 INFO \[stdout\] (151\_bYD2+EULzJ\_SLR\_124219\_-\_mymailfc@mailinator.com) Subject: Products Offer exceeded threshold limit of 10% I want to extract the timestamp from t…

---

## [Can I use conditionals inside json {} filter?](https://discuss.elastic.co/t/can-i-use-conditionals-inside-json-filter/311547)

<div class="topic-metadata">

**Author:** [@mfloris](https://discuss.elastic.co/u/mfloris)\
**Replies:** 1\
**Last updated:** [August 5, 2022, 2:40pm UTC](https://discuss.elastic.co/t/can-i-use-conditionals-inside-json-filter/311547 "2022-08-05T14:40:07Z")

</div>

My input does not always contain some fields and I want to parse it accordingly, like this: filter { json { source =\> "message" if "thisField" in \[message\] { add\_field =\> { "MyField" =\> "%{\[message\]\[this…

---

## [Compare fields value](https://discuss.elastic.co/t/compare-fields-value/311387)

<div class="topic-metadata">

**Author:** [@alex\_vermex](https://discuss.elastic.co/u/alex_vermex)\
**Replies:** 2\
**Last updated:** [August 5, 2022, 2:12pm UTC](https://discuss.elastic.co/t/compare-fields-value/311387 "2022-08-05T14:12:53Z")

</div>

Hi, I would like if it is possible how to compare this value of two fields field1 : 123456XXXXXX1234 field2 : 1234567890001234 I mean i want to do if first 6 chars and last 4 chars of field1 are similar to field2 the…

---

## [Compare two fields with different documents](https://discuss.elastic.co/t/compare-two-fields-with-different-documents/311529)

<div class="topic-metadata">

**Author:** [@alex\_vermex](https://discuss.elastic.co/u/alex_vermex)\
**Replies:** 5\
**Last updated:** [August 5, 2022, 1:59pm UTC](https://discuss.elastic.co/t/compare-two-fields-with-different-documents/311529 "2022-08-05T13:59:45Z")

</div>

Hi, I want to compare two fields but not in the same document is that possible ? for example : if date.document1 == date.document2 and x.document1 == y.document2 { #DO somthing } Any help would be sincerely appre…

---

## [Range filter in should match query](https://discuss.elastic.co/t/range-filter-in-should-match-query/311435)

<div class="topic-metadata">

**Author:** [@ansamHox](https://discuss.elastic.co/u/ansamHox)\
**Replies:** 3\
**Last updated:** [August 5, 2022, 1:41pm UTC](https://discuss.elastic.co/t/range-filter-in-should-match-query/311435 "2022-08-05T13:41:14Z")

</div>

Hi, let's say I have 3 documents, id=1, "text" = "my name is john", "date" = "2021" id=2, "text" = "my name is alice", "date" = "2017" id=3, "text" = "my name is steven", "date" = "2019" I want to find all documents th…

---

## [How to pass url query string value into the elasticsearch SQL query in kibana canvas](https://discuss.elastic.co/t/how-to-pass-url-query-string-value-into-the-elasticsearch-sql-query-in-kibana-canvas/311540)

<div class="topic-metadata">

**Author:** [@sarvshresht6561](https://discuss.elastic.co/u/sarvshresht6561)\
**Replies:** 0\
**Last updated:** [August 5, 2022, 1:24pm UTC](https://discuss.elastic.co/t/how-to-pass-url-query-string-value-into-the-elasticsearch-sql-query-in-kibana-canvas/311540 "2022-08-05T13:24:06Z")

</div>

I am new to ELK stack. I am making line graphs in kibana canvas with elastic SQL query as a data source. I am trying to fetch the query string value from the url to the SQL query, but the result of the query is "no docum…

---

## [Elastic agent offline after upgrade](https://discuss.elastic.co/t/elastic-agent-offline-after-upgrade/311531)

<div class="topic-metadata">

**Author:** [@Leandre](https://discuss.elastic.co/u/Leandre)\
**Replies:** 0\
**Last updated:** [August 5, 2022, 1:01pm UTC](https://discuss.elastic.co/t/elastic-agent-offline-after-upgrade/311531 "2022-08-05T13:01:38Z")

</div>

Same issue than this one when upgrading agent from 8.3.2 to 8.3.3. The service fails because the symlink to the executable elastic-agent.exe points on a deleted elastic-agent.exe (or the old .exe, wich causes an error li…

---

## [Geo\_distance agg results not consistent](https://discuss.elastic.co/t/geo-distance-agg-results-not-consistent/311453)

<div class="topic-metadata">

**Author:** [@drfreed](https://discuss.elastic.co/u/drfreed)\
**Replies:** 2\
**Last updated:** [August 5, 2022, 12:45pm UTC](https://discuss.elastic.co/t/geo-distance-agg-results-not-consistent/311453 "2022-08-05T12:45:31Z")

</div>

I was trying out the geo\_distance aggreation and received different results based on the order of the ranges specified. I was able to replicate this using the example in the geo\_distance aggregation documentation page. …

---

## [How to enroll elastic agent on image master to deploy 160 VDA Citrix Servers](https://discuss.elastic.co/t/how-to-enroll-elastic-agent-on-image-master-to-deploy-160-vda-citrix-servers/311526)

<div class="topic-metadata">

**Author:** [@dpachot](https://discuss.elastic.co/u/dpachot)\
**Replies:** 0\
**Last updated:** [August 5, 2022, 12:35pm UTC](https://discuss.elastic.co/t/how-to-enroll-elastic-agent-on-image-master-to-deploy-160-vda-citrix-servers/311526 "2022-08-05T12:35:33Z")

</div>

Hi, i'am trying to enroll elastic-agent on Citrix's image master. When i deploy this image to my vda server, they are sharing the same id, so in the Fleet's menu, i can see only one VDA Server and the view is rotating o…

---

## [Is there a "stop" instruction in the block that skips to the next block?](https://discuss.elastic.co/t/is-there-a-stop-instruction-in-the-block-that-skips-to-the-next-block/311511)

<div class="topic-metadata">

**Author:** [@mfloris](https://discuss.elastic.co/u/mfloris)\
**Replies:** 1\
**Last updated:** [August 5, 2022, 12:31pm UTC](https://discuss.elastic.co/t/is-there-a-stop-instruction-in-the-block-that-skips-to-the-next-block/311511 "2022-08-05T12:31:59Z")

</div>

I want to split my filter block into separate files for better readability and easier maintenance and of course by doing that I cannot if-else through the various checks meaning that every input will go through all the f…

---

## [I want the full match text comes first than their prefixes than their substrings results](https://discuss.elastic.co/t/i-want-the-full-match-text-comes-first-than-their-prefixes-than-their-substrings-results/311512)

<div class="topic-metadata">

**Author:** [@Rakhshunda\_Noorein\_J](https://discuss.elastic.co/u/Rakhshunda_Noorein_J)\
**Replies:** 0\
**Last updated:** [August 5, 2022, 11:27am UTC](https://discuss.elastic.co/t/i-want-the-full-match-text-comes-first-than-their-prefixes-than-their-substrings-results/311512 "2022-08-05T11:27:50Z")

</div>

Suppose If I am searching for Rohan Roy, I want Rohan Roy matching results comes first then rohan , rohan chohan etc.... The query I have used : { "size": 1000, "query": { "bool": { "must": \[ { …

---

## [Unique value counts in kibana](https://discuss.elastic.co/t/unique-value-counts-in-kibana/311510)

<div class="topic-metadata">

**Author:** [@Kara1990](https://discuss.elastic.co/u/Kara1990)\
**Replies:** 0\
**Last updated:** [August 5, 2022, 11:23am UTC](https://discuss.elastic.co/t/unique-value-counts-in-kibana/311510 "2022-08-05T11:23:53Z")

</div>

Hello. I asked a question a while ago - see link Unique value counts in kibana After looking at your answer, my challenge is still that I cannot find the place where I can connect my visualization to an alert I have c…

---

## [Highlight not working when adjacent entities](https://discuss.elastic.co/t/highlight-not-working-when-adjacent-entities/311507)

<div class="topic-metadata">

**Author:** [@almeidajava](https://discuss.elastic.co/u/almeidajava)\
**Replies:** 0\
**Last updated:** [August 5, 2022, 10:59am UTC](https://discuss.elastic.co/t/highlight-not-working-when-adjacent-entities/311507 "2022-08-05T10:59:36Z")

</div>

This happens when using mapper-annotated-text highlighter type: eg Query: { "query": { "ids": { "values": \[ "1" \] } }, "\_source": { "includes"…

---

## [Drupal ElasticSearch Connector](https://discuss.elastic.co/t/drupal-elasticsearch-connector/311505)

<div class="topic-metadata">

**Author:** [@betd-vramdoo](https://discuss.elastic.co/u/betd-vramdoo)\
**Replies:** 1\
**Last updated:** [August 5, 2022, 10:46am UTC](https://discuss.elastic.co/t/drupal-elasticsearch-connector/311505 "2022-08-05T10:46:15Z")

</div>

Hello there, I am currently working on a Drupal project with the search engine ElasticSearch 7.10, my team is using the Elasticsearch Connector | Drupal.org module to interface Drupal with ElasticSearch. Do you know if…

---

## [Elasticsearch Java api client get index mapping in a Map](https://discuss.elastic.co/t/elasticsearch-java-api-client-get-index-mapping-in-a-map/311461)

<div class="topic-metadata">

**Author:** [@ijaxahmed](https://discuss.elastic.co/u/ijaxahmed)\
**Replies:** 2\
**Last updated:** [August 5, 2022, 7:42am UTC](https://discuss.elastic.co/t/elasticsearch-java-api-client-get-index-mapping-in-a-map/311461 "2022-08-05T07:42:11Z")

</div>

I have two qestion 1- I want to get mapping of an Index in a map as "Map\<String, Object\>", i successfully get the GetMappingResponse but from there not getting what to do in order to get mapping as a "Map\<String, Objec…

---

## [Elasticsearch pipeline doesn't Catch paths](https://discuss.elastic.co/t/elasticsearch-pipeline-doesnt-catch-paths/311501)

<div class="topic-metadata">

**Author:** [@nicfr9](https://discuss.elastic.co/u/nicfr9)\
**Replies:** 0\
**Last updated:** [August 5, 2022, 10:32am UTC](https://discuss.elastic.co/t/elasticsearch-pipeline-doesnt-catch-paths/311501 "2022-08-05T10:32:49Z")

</div>

i'm trying to catch the paths that contains a specified path like path/to/my/url/VARIABLEPART, in the pipeline condition i put ctx.url.path == 'path/to/my/url/\*' but unfortunately it takes only the logs that have path/to…

---

## [How to perform join between two indexes in ES?](https://discuss.elastic.co/t/how-to-perform-join-between-two-indexes-in-es/311078)

<div class="topic-metadata">

**Author:** [@Ritikapawar](https://discuss.elastic.co/u/Ritikapawar)\
**Replies:** 4\
**Last updated:** [August 5, 2022, 10:20am UTC](https://discuss.elastic.co/t/how-to-perform-join-between-two-indexes-in-es/311078 "2022-08-05T10:20:26Z")

</div>

I have two indexes as Student1.csv and lecture.csv sample student1.csv student\_id name Roll no 1 Amey 1 2 Neha 2 3 Shubham 3 4 Satish 4 5 Ritika 5 sample lecture.csv lec\_no lec student\_id 1 eng 1 1 eng 1 1 eng 3 1 …

---

## [S3 Output malformed JSON](https://discuss.elastic.co/t/s3-output-malformed-json/311495)

<div class="topic-metadata">

**Author:** [@Giridharan\_C](https://discuss.elastic.co/u/Giridharan_C)\
**Replies:** 0\
**Last updated:** [August 5, 2022, 9:07am UTC](https://discuss.elastic.co/t/s3-output-malformed-json/311495 "2022-08-05T09:07:36Z")

</div>

I am using some grok filter to parse the Syslog from TCP input and store them into S3. What I'm seeing is some malformed JSON. Some syslog events are good and some are not (Multiple events are grouping together as a sing…

---

## [Elastic Search matrix\_stats on both nested and non nested value](https://discuss.elastic.co/t/elastic-search-matrix-stats-on-both-nested-and-non-nested-value/311492)

<div class="topic-metadata">

**Author:** [@Mspprasath](https://discuss.elastic.co/u/Mspprasath)\
**Replies:** 0\
**Last updated:** [August 5, 2022, 8:53am UTC](https://discuss.elastic.co/t/elastic-search-matrix-stats-on-both-nested-and-non-nested-value/311492 "2022-08-05T08:53:48Z")

</div>

we have a doc structure \[{ score: 10, list: \[ // nested type { id : 3, value: 10 }, { id: 4 value: 20 }, { id: 5, value: 15 } \] }, { score: 1, list:…

---

## [Use terminate\_after and sort query can't get the latest data](https://discuss.elastic.co/t/use-terminate-after-and-sort-query-cant-get-the-latest-data/311490)

<div class="topic-metadata">

**Author:** [@Xavier\_Stuart](https://discuss.elastic.co/u/Xavier_Stuart)\
**Replies:** 0\
**Last updated:** [August 5, 2022, 8:24am UTC](https://discuss.elastic.co/t/use-terminate-after-and-sort-query-cant-get-the-latest-data/311490 "2022-08-05T08:24:55Z")

</div>

Why can't I find the latest data when I add terminated\_after when sorting by creation time, the query statement is as follows GET index-1/\_search { "from": 0, "size": 20, "terminate\_after": 1111112, "query": { …

---

## [How to fetch data from multiple hostnames in es](https://discuss.elastic.co/t/how-to-fetch-data-from-multiple-hostnames-in-es/311414)

<div class="topic-metadata">

**Author:** [@Gojo](https://discuss.elastic.co/u/Gojo)\
**Replies:** 2\
**Last updated:** [August 5, 2022, 6:16am UTC](https://discuss.elastic.co/t/how-to-fetch-data-from-multiple-hostnames-in-es/311414 "2022-08-05T06:16:41Z")

</div>

hey all iam new to elk , iam trying to get all the hosts in the Elasticsearch db , i tried using a wildcard and "wild\_card": "hosts", "query": { "host.keyword": "test\*", "severity.keyword": "err" }, consider there are …

[Previous page](https://discuss.elastic.co/tag/none.md?no_tags=true&page=566)

[Next page](https://discuss.elastic.co/tag/none.md?no_tags=true&page=568)
