# \#none

**URL:** https://discuss.elastic.co/tag/none.md?no_tags=true&page=572

[Latest](https://discuss.elastic.co/latest.md) · [Categories](https://discuss.elastic.co/categories.md) · [Tags](https://discuss.elastic.co/tags.md)

**Page:** 573

---

## [Logstash 8 @timestamp field format was changed to microseconds percision](https://discuss.elastic.co/t/logstash-8-timestamp-field-format-was-changed-to-microseconds-percision/310852)

<div class="topic-metadata">

**Author:** [@Ofir\_Edi](https://discuss.elastic.co/u/Ofir_Edi)\
**Replies:** 7\
**Last updated:** [August 1, 2022, 7:23am UTC](https://discuss.elastic.co/t/logstash-8-timestamp-field-format-was-changed-to-microseconds-percision/310852 "2022-08-01T07:23:38Z")

</div>

Hi, I have been using Logstash for a while now and when upgrading to version 8 I can see the @timestamp field format was changed from milliseconds percision to microseconds percision (meaning instead of 2022-07-28T09:46…

---

## [Kibana visualization Interval change automatic issue](https://discuss.elastic.co/t/kibana-visualization-interval-change-automatic-issue/310882)

<div class="topic-metadata">

**Author:** [@PRASHANT\_MEHTA](https://discuss.elastic.co/u/PRASHANT_MEHTA)\
**Replies:** 4\
**Last updated:** [August 1, 2022, 6:36am UTC](https://discuss.elastic.co/t/kibana-visualization-interval-change-automatic-issue/310882 "2022-08-01T06:36:19Z")

</div>

Hello All, I've selected timerange as 90 days(quick select),then applied visualization interval as \>=15m but in visualization the interval is showing per "12 hours" automatically,Note:Everytime the quick select option …

---

## [\[error\]\[savedobjects-service\] \[.kibana\_task\_manager\] Action failed with 'Request timed out'. \[savedobjects-service\] \[.kibana\_task\_manager\] REINDEX\_SOURCE\_TO\_TEMP\_INDEX\_BULK -\> REINDEX\_SOURCE\_TO\_TEMP\_INDEX\_BULK](https://discuss.elastic.co/t/error-savedobjects-service-kibana-task-manager-action-failed-with-request-timed-out-savedobjects-service-kibana-task-manager-reindex-source-to-temp-index-bulk-reindex-source-to-temp-index-bulk/311039)

<div class="topic-metadata">

**Author:** [@mujtabah](https://discuss.elastic.co/u/mujtabah)\
**Replies:** 8\
**Last updated:** [August 1, 2022, 12:25am UTC](https://discuss.elastic.co/t/error-savedobjects-service-kibana-task-manager-action-failed-with-request-timed-out-savedobjects-service-kibana-task-manager-reindex-source-to-temp-index-bulk-reindex-source-to-temp-index-bulk/311039 "2022-08-01T00:25:45Z")

</div>

Hi guys i have a running cluster with 5 nodes(3master and 2 data nodes). i have done rolling upgrade of elastic for all the 5 nodes from v7.10.0 to v7.16.2 and it was successfully upgraded and all the 5 nodes are in clu…

---

## [Logstash stuck after Restart/Stop command](https://discuss.elastic.co/t/logstash-stuck-after-restart-stop-command/310797)

<div class="topic-metadata">

**Author:** [@Oriya](https://discuss.elastic.co/u/Oriya)\
**Replies:** 2\
**Last updated:** [July 31, 2022, 9:48pm UTC](https://discuss.elastic.co/t/logstash-stuck-after-restart-stop-command/310797 "2022-07-31T21:48:30Z")

</div>

Hi, i have a logstash server (8.1.3 version) with 3 pipelines. each pipeline configure with jdbc to collect data from sql server. everything works ok until i try to execute the : "systemctl restart logstash" and it'…

---

## [Errno::EACCES: Permission denied - NUL not fixed with enableADS](https://discuss.elastic.co/t/errno-permission-denied-nul-not-fixed-with-enableads/310846)

<div class="topic-metadata">

**Author:** [@Bert\_Van\_der\_Heyden](https://discuss.elastic.co/u/Bert_Van_der_Heyden)\
**Replies:** 3\
**Last updated:** [July 31, 2022, 9:03pm UTC](https://discuss.elastic.co/t/errno-permission-denied-nul-not-fixed-with-enableads/310846 "2022-07-31T21:03:35Z")

</div>

Running logstash (latest version 8.3.2) on Windows gives me: Errno::EACCES: Permission denied - NUL sysopen at org/jruby/RubyIO.java:1237 Found out that this is a known issue and fixed with -Djdk.io.File.enableADS=tru…

---

## [CPU:Memory ratio for a general-purpose cluster](https://discuss.elastic.co/t/cpu-memory-ratio-for-a-general-purpose-cluster/311060)

<div class="topic-metadata">

**Author:** [@x00m](https://discuss.elastic.co/u/x00m)\
**Replies:** 1\
**Last updated:** [July 31, 2022, 7:51pm UTC](https://discuss.elastic.co/t/cpu-memory-ratio-for-a-general-purpose-cluster/311060 "2022-07-31T19:51:34Z")

</div>

How can we determine a good ratio of CPU/memory configuration for elasticsearch nodes for general purpose usage? I see 1:4 ratio in most places, I am not sure though, how that ratio is derived.

---

## [Composite aggregation query with bucket\_sort does not work properly](https://discuss.elastic.co/t/composite-aggregation-query-with-bucket-sort-does-not-work-properly/311055)

<div class="topic-metadata">

**Author:** [@fabiobozzo](https://discuss.elastic.co/u/fabiobozzo)\
**Replies:** 0\
**Last updated:** [July 31, 2022, 10:51am UTC](https://discuss.elastic.co/t/composite-aggregation-query-with-bucket-sort-does-not-work-properly/311055 "2022-07-31T10:51:07Z")

</div>

I have an index to store financial transactions: { "mappings": { "\_doc": { "properties": { "amount": { "type": "long" }, "currencyCode": { "type": "keyword" …

---

## [Kibana Dashboard](https://discuss.elastic.co/t/kibana-dashboard/311047)

<div class="topic-metadata">

**Author:** [@Sahil\_Bindra](https://discuss.elastic.co/u/Sahil_Bindra)\
**Replies:** 2\
**Last updated:** [July 31, 2022, 6:01am UTC](https://discuss.elastic.co/t/kibana-dashboard/311047 "2022-07-31T06:01:59Z")

</div>

Hi, I have a log like this: User content\_id ankur 879fdd7979 mohak 4345grg66 havel 1224asa34 ankur 98089rtf6 sonam 2134ssded245 tunnu 843juy566 ankur 225cc865 havel 09744qqw67 sonam 234mmk566 I want the visua…

---

## [Elasticsearch Linux User](https://discuss.elastic.co/t/elasticsearch-linux-user/311031)

<div class="topic-metadata">

**Author:** [@lucian1094](https://discuss.elastic.co/u/lucian1094)\
**Replies:** 5\
**Last updated:** [July 30, 2022, 6:04pm UTC](https://discuss.elastic.co/t/elasticsearch-linux-user/311031 "2022-07-30T18:04:33Z")

</div>

I installed an Elasticsearch on CentOS using rpm file. After install, elaticsearch user and group is created, user which can't be used to manage (start/stop/restart) elasticsearch (nologin, nonexistent). I don't want to …

---

## [Logstash not starting; error reason : Your settings are invalid](https://discuss.elastic.co/t/logstash-not-starting-error-reason-your-settings-are-invalid/310440)

<div class="topic-metadata">

**Author:** [@sanuboy](https://discuss.elastic.co/u/sanuboy)\
**Replies:** 7\
**Last updated:** [July 30, 2022, 5:36pm UTC](https://discuss.elastic.co/t/logstash-not-starting-error-reason-your-settings-are-invalid/310440 "2022-07-30T17:36:38Z")

</div>

Hi, This is the first time i am trying to setup ELK stack to read my application log files and i have been struggling to get through this issue for about two days and finally resorted to asking for help. I have illustrat…

---

## [Trying to make logstash work with multiline logs on a SIEM platform](https://discuss.elastic.co/t/trying-to-make-logstash-work-with-multiline-logs-on-a-siem-platform/310951)

<div class="topic-metadata">

**Author:** [@currybread](https://discuss.elastic.co/u/currybread)\
**Replies:** 1\
**Last updated:** [July 30, 2022, 12:49pm UTC](https://discuss.elastic.co/t/trying-to-make-logstash-work-with-multiline-logs-on-a-siem-platform/310951 "2022-07-30T12:49:23Z")

</div>

Situation: Multiline logs collected are sent to a SIEM event collector via Logstash but having issues test.log: \[5/8/22 7:31:23:546 SGT\] FFDC Exception:java.io.FileNotFoundException SourceId:com.ibm.ws.webcontaine…

---

## [How to count matched phrases with slop](https://discuss.elastic.co/t/how-to-count-matched-phrases-with-slop/311036)

<div class="topic-metadata">

**Author:** [@Daniil](https://discuss.elastic.co/u/Daniil)\
**Replies:** 0\
**Last updated:** [July 30, 2022, 9:56am UTC](https://discuss.elastic.co/t/how-to-count-matched-phrases-with-slop/311036 "2022-07-30T09:56:16Z")

</div>

Now I am using scripted similarity to count phrases in matched documents. "similarity": { "my\_scripted\_formula": { "type": "scripted", "script": {"source": "double tf = doc.freq; return query.boost \*…

---

## [Can elasticsearch-1.13.3 work with kibana-1.13.3](https://discuss.elastic.co/t/can-elasticsearch-1-13-3-work-with-kibana-1-13-3/311003)

<div class="topic-metadata">

**Author:** [@Rain\_Water](https://discuss.elastic.co/u/Rain_Water)\
**Replies:** 3\
**Last updated:** [July 30, 2022, 7:03am UTC](https://discuss.elastic.co/t/can-elasticsearch-1-13-3-work-with-kibana-1-13-3/311003 "2022-07-30T07:03:02Z")

</div>

Is kibana version 1.13.2 compatible with elasticsearch 1.13.3 can both work together with different version?

---

## [Where is the elastic community team?](https://discuss.elastic.co/t/where-is-the-elastic-community-team/311022)

<div class="topic-metadata">

**Author:** [@morad\_della3](https://discuss.elastic.co/u/morad_della3)\
**Replies:** 1\
**Last updated:** [July 29, 2022, 11:25pm UTC](https://discuss.elastic.co/t/where-is-the-elastic-community-team/311022 "2022-07-29T23:25:21Z")

</div>

where is the elastic comunity team ?I asked a question and any response ....

---

## [Using Scripted field to display a sub-string](https://discuss.elastic.co/t/using-scripted-field-to-display-a-sub-string/310798)

<div class="topic-metadata">

**Author:** [@zaeemmasood](https://discuss.elastic.co/u/zaeemmasood)\
**Replies:** 6\
**Last updated:** [July 29, 2022, 8:18pm UTC](https://discuss.elastic.co/t/using-scripted-field-to-display-a-sub-string/310798 "2022-07-29T20:18:55Z")

</div>

Hello. We are using ELK 7.6.2 stack. I have a field named host.name which displays a value such as ad-c2ff-v2bg.taz.root.net I need to extract the second substring (taz) using Scripted field. When I try to define a n…

---

## [Change Elastic Agent GRPC port via Environment Variable?](https://discuss.elastic.co/t/change-elastic-agent-grpc-port-via-environment-variable/311014)

<div class="topic-metadata">

**Author:** [@BenB196](https://discuss.elastic.co/u/BenB196)\
**Replies:** 4\
**Last updated:** [July 29, 2022, 7:47pm UTC](https://discuss.elastic.co/t/change-elastic-agent-grpc-port-via-environment-variable/311014 "2022-07-29T19:47:56Z")

</div>

Hi All, I was wonder if there is a way to change the GRPC port the Elastic Agent uses via an environment variable. Use case: I have a Kubernetes cluster that runs with a complete underlying OS, because of this, I run …

---

## [Force a synchronous refresh when updating documents](https://discuss.elastic.co/t/force-a-synchronous-refresh-when-updating-documents/311012)

<div class="topic-metadata">

**Author:** [@sz\_bb](https://discuss.elastic.co/u/sz_bb)\
**Replies:** 0\
**Last updated:** [July 29, 2022, 6:30pm UTC](https://discuss.elastic.co/t/force-a-synchronous-refresh-when-updating-documents/311012 "2022-07-29T18:30:02Z")

</div>

As is well-documented, Elastic provides "near real-time search capabilities". My data is typically ingested with through the Bulk API and we use a 30 second refresh interval as the data typically does not need to be avai…

---

## [Could not index event to Elasticsearch due to opType: \[-1\]](https://discuss.elastic.co/t/could-not-index-event-to-elasticsearch-due-to-optype-1/311010)

<div class="topic-metadata">

**Author:** [@co88liwan](https://discuss.elastic.co/u/co88liwan)\
**Replies:** 0\
**Last updated:** [July 29, 2022, 5:41pm UTC](https://discuss.elastic.co/t/could-not-index-event-to-elasticsearch-due-to-optype-1/311010 "2022-07-29T17:41:48Z")

</div>

Hi all, We encountered a transient issue with the \[WARN\] said: Could not index event to Elasticsearch From the log, the response is like :response =\> {"create"=\>{"\_index"=\>"zzzzzzzzzz"}, "\_type"=\>"\_doc", "\_id"=\>"xxxx…

---

## [Speed of dense vector search with 512 or more dimensions](https://discuss.elastic.co/t/speed-of-dense-vector-search-with-512-or-more-dimensions/307121)

<div class="topic-metadata">

**Author:** [@telunyang](https://discuss.elastic.co/u/telunyang)\
**Replies:** 7\
**Last updated:** [July 29, 2022, 5:43pm UTC](https://discuss.elastic.co/t/speed-of-dense-vector-search-with-512-or-more-dimensions/307121 "2022-07-29T17:43:37Z")

</div>

Hi Team, Reading the article Introducing approximate nearest neighbor search in Elasticsearch 8.0 is very useful to our lab for building an Elasticsearch service, so I would like to consult you on how to speed up our qu…

---

## [LEEF Input Plugin](https://discuss.elastic.co/t/leef-input-plugin/311008)

<div class="topic-metadata">

**Author:** [@sta02](https://discuss.elastic.co/u/sta02)\
**Replies:** 0\
**Last updated:** [July 29, 2022, 4:44pm UTC](https://discuss.elastic.co/t/leef-input-plugin/311008 "2022-07-29T16:44:32Z")

</div>

Hello, I am looking for LEEF Input plugin for Logstash. How can I configure Logstash to consume events in LEEF format sent over syslog. Please advise. -- Thanks, Siddarth

---

## [How to create Custom Endpoints with an API?](https://discuss.elastic.co/t/how-to-create-custom-endpoints-with-an-api/311004)

<div class="topic-metadata">

**Author:** [@rcorfield](https://discuss.elastic.co/u/rcorfield)\
**Replies:** 0\
**Last updated:** [July 29, 2022, 4:36pm UTC](https://discuss.elastic.co/t/how-to-create-custom-endpoints-with-an-api/311004 "2022-07-29T16:36:50Z")

</div>

Hi I've created custom endpoints for my ECE cluster via the Cloud UI using the guidance here: However in future I'd like to use an API call, or some other programmatic method (writing config files directly?). Can some…

---

## [Elasticsearch json logging @timestamp missing](https://discuss.elastic.co/t/elasticsearch-json-logging-timestamp-missing/310992)

<div class="topic-metadata">

**Author:** [@logger](https://discuss.elastic.co/u/logger)\
**Replies:** 0\
**Last updated:** [July 29, 2022, 2:01pm UTC](https://discuss.elastic.co/t/elasticsearch-json-logging-timestamp-missing/310992 "2022-07-29T14:01:25Z")

</div>

Hello there, I have a problem with elasticsearch logging and the filebeat module. I collect the logs from elasticsearch with the filebeat module. For example the deprecation logs: - module: elasticsearch deprecatio…

---

## [Fleet : Kubernetes integration different index from namespace](https://discuss.elastic.co/t/fleet-kubernetes-integration-different-index-from-namespace/310989)

<div class="topic-metadata">

**Author:** [@davide.lilliu](https://discuss.elastic.co/u/davide.lilliu)\
**Replies:** 0\
**Last updated:** [July 29, 2022, 1:29pm UTC](https://discuss.elastic.co/t/fleet-kubernetes-integration-different-index-from-namespace/310989 "2022-07-29T13:29:00Z")

</div>

Hi, is it possibile, using Kubernetes integration on Fleet, to have different index from different k8s namespace? Davide L.

---

## [Logstash-keystore permission denied](https://discuss.elastic.co/t/logstash-keystore-permission-denied/309426)

<div class="topic-metadata">

**Author:** [@Christer\_Palmen](https://discuss.elastic.co/u/Christer_Palmen)\
**Replies:** 2\
**Last updated:** [July 29, 2022, 1:03pm UTC](https://discuss.elastic.co/t/logstash-keystore-permission-denied/309426 "2022-07-29T13:03:13Z")

</div>

\`Hello. I´m going to install ELK for an customer, and as a start I´m setting up an test ELK with version 8.3.2 to see how it works. I am using Windows10 as the host for ELK As a start I have setup the Elasticsearch and …

---

## [How do you bootstrap an elastic cluster for production with security enabled? The documentation feels unclear](https://discuss.elastic.co/t/how-do-you-bootstrap-an-elastic-cluster-for-production-with-security-enabled-the-documentation-feels-unclear/310915)

<div class="topic-metadata">

**Author:** [@Atharv\_Kirtikar](https://discuss.elastic.co/u/Atharv_Kirtikar)\
**Replies:** 2\
**Last updated:** [July 29, 2022, 1:02pm UTC](https://discuss.elastic.co/t/how-do-you-bootstrap-an-elastic-cluster-for-production-with-security-enabled-the-documentation-feels-unclear/310915 "2022-07-29T13:02:47Z")

</div>

I am trying to create a 3 node cluster for production. The documentation here implies that with security creating an enrolment token is the way to go. However it also recommends here that you should have at least three…

---

## [Fleet - Elastic Agent | 8.3.2 Cannot upgrade agent via GUI](https://discuss.elastic.co/t/fleet-elastic-agent-8-3-2-cannot-upgrade-agent-via-gui/310984)

<div class="topic-metadata">

**Author:** [@AgnosticPriest](https://discuss.elastic.co/u/AgnosticPriest)\
**Replies:** 0\
**Last updated:** [July 29, 2022, 12:50pm UTC](https://discuss.elastic.co/t/fleet-elastic-agent-8-3-2-cannot-upgrade-agent-via-gui/310984 "2022-07-29T12:50:46Z")

</div>

Hello everyone, Member of newly formed SOC in a mid sized company (3k monitored hosts/machines) Data: ELK 8.3.2 on 3 VM machines. Logstash, Fleet Server on a separate VM machine. Ubuntu 22 LTS 4 cores, 16 GB RAM, 2…

---

## [Integration with OCI logs ( Oracle cloud)](https://discuss.elastic.co/t/integration-with-oci-logs-oracle-cloud/310972)

<div class="topic-metadata">

**Author:** [@paolajuarez](https://discuss.elastic.co/u/paolajuarez)\
**Replies:** 0\
**Last updated:** [July 29, 2022, 9:51am UTC](https://discuss.elastic.co/t/integration-with-oci-logs-oracle-cloud/310972 "2022-07-29T09:51:27Z")

</div>

How can I ingest logs from OCI to elastisearch? Any recommendation?

---

## [ConsumerConfig values with kafka input plugin](https://discuss.elastic.co/t/consumerconfig-values-with-kafka-input-plugin/310964)

<div class="topic-metadata">

**Author:** [@AlexB2](https://discuss.elastic.co/u/AlexB2)\
**Replies:** 0\
**Last updated:** [July 29, 2022, 9:13am UTC](https://discuss.elastic.co/t/consumerconfig-values-with-kafka-input-plugin/310964 "2022-07-29T09:13:27Z")

</div>

Hi there I have a question: Is there a way to configure ConsumerConfig values for kafka input plugin I am interested in configure sasl.client.callback.handler.class There is no direct such option with kafka input pl…

---

## [Rollover issue when upgrading from ES5.6 to 6.8](https://discuss.elastic.co/t/rollover-issue-when-upgrading-from-es5-6-to-6-8/310886)

<div class="topic-metadata">

**Author:** [@Teddy\_Santos](https://discuss.elastic.co/u/Teddy_Santos)\
**Replies:** 2\
**Last updated:** [July 29, 2022, 7:41am UTC](https://discuss.elastic.co/t/rollover-issue-when-upgrading-from-es5-6-to-6-8/310886 "2022-07-29T07:41:29Z")

</div>

I am receiving this issue below in ES6.8 when performing the same rollover function I have in ES5.6 { "error": { "root\_cause": \[ { "type": "remote\_transport\_exception", "reason": "\[TrekrMZ\]\[x.x.x.x:9300\]\[indices:ad…

---

## [How to check elasticsearch current version after login to linux ? How to upgrade it with new version?](https://discuss.elastic.co/t/how-to-check-elasticsearch-current-version-after-login-to-linux-how-to-upgrade-it-with-new-version/310865)

<div class="topic-metadata">

**Author:** [@jisha](https://discuss.elastic.co/u/jisha)\
**Replies:** 5\
**Last updated:** [July 29, 2022, 6:23am UTC](https://discuss.elastic.co/t/how-to-check-elasticsearch-current-version-after-login-to-linux-how-to-upgrade-it-with-new-version/310865 "2022-07-29T06:23:33Z")

</div>

Hi , I am new to elk in linux. How to check elasticsearch current version after login to linux ? I want to upgrade it with new version also .

[Previous page](https://discuss.elastic.co/tag/none.md?no_tags=true&page=571)

[Next page](https://discuss.elastic.co/tag/none.md?no_tags=true&page=573)
