# \#none

**URL:** https://discuss.elastic.co/tag/none.md?no_tags=true&page=574

[Latest](https://discuss.elastic.co/latest.md) · [Categories](https://discuss.elastic.co/categories.md) · [Tags](https://discuss.elastic.co/tags.md)

**Page:** 575

---

## [Fleet Server Deployment on kubernetes](https://discuss.elastic.co/t/fleet-server-deployment-on-kubernetes/310408)

<div class="topic-metadata">

**Author:** [@Mehran\_Hafizi](https://discuss.elastic.co/u/Mehran_Hafizi)\
**Replies:** 1\
**Last updated:** [July 28, 2022, 10:10am UTC](https://discuss.elastic.co/t/fleet-server-deployment-on-kubernetes/310408 "2022-07-28T10:10:25Z")

</div>

Hello , I wanted to install Fleet server on the AKS cluster , but I got the following errror , would you please help me to solve this issue? Error: message: Application: fleet-server--7.17.0\[\]: State changed to FAILED…

---

## [Output Logstash plugin for Azure Data Explorer (ADX) quickly running out of capacity](https://discuss.elastic.co/t/output-logstash-plugin-for-azure-data-explorer-adx-quickly-running-out-of-capacity/310599)

<div class="topic-metadata">

**Author:** [@stillfreem](https://discuss.elastic.co/u/stillfreem)\
**Replies:** 1\
**Last updated:** [July 28, 2022, 9:29am UTC](https://discuss.elastic.co/t/output-logstash-plugin-for-azure-data-explorer-adx-quickly-running-out-of-capacity/310599 "2022-07-28T09:29:03Z")

</div>

Dear All, I use the ADX output plugin to send FW logs to ADX. I first tried it with a stdout{} plugin to massage the data and parse it my way and it was working fine. Now when I enabled the kusto output (That is how i…

---

## [Logstash CEF codec and ECS cannot parse 'rt' field throws an error](https://discuss.elastic.co/t/logstash-cef-codec-and-ecs-cannot-parse-rt-field-throws-an-error/310705)

<div class="topic-metadata">

**Author:** [@wii](https://discuss.elastic.co/u/wii)\
**Replies:** 2\
**Last updated:** [July 28, 2022, 8:54am UTC](https://discuss.elastic.co/t/logstash-cef-codec-and-ecs-cannot-parse-rt-field-throws-an-error/310705 "2022-07-28T08:54:29Z")

</div>

Without ECS, the 'rt' field could be parsed fine and mapped into 'deviceReceiptTime' field. But after enabling ECS in Logstash configuration it throws me an error in log ingesting. Could somebody guide me through this as…

---

## [Synthetic Monitoring in 7.12 version](https://discuss.elastic.co/t/synthetic-monitoring-in-7-12-version/310506)

<div class="topic-metadata">

**Author:** [@Baishali](https://discuss.elastic.co/u/Baishali)\
**Replies:** 2\
**Last updated:** [July 28, 2022, 7:33am UTC](https://discuss.elastic.co/t/synthetic-monitoring-in-7-12-version/310506 "2022-07-28T07:33:54Z")

</div>

I have installed Elasticsearch ver:7.12.1, Kibana ver:7.12.1, Heartbeat ver:7.17 I want to add Synthetic monitoring for a URL. Tried a sample inline code but it was not working. Steps followed: Installed Elasticsearc…

---

## [Logstah : nonexistent lob error from jdbc plugin](https://discuss.elastic.co/t/logstah-nonexistent-lob-error-from-jdbc-plugin/310823)

<div class="topic-metadata">

**Author:** [@Venkatesan\_M](https://discuss.elastic.co/u/Venkatesan_M)\
**Replies:** 0\
**Last updated:** [July 28, 2022, 7:33am UTC](https://discuss.elastic.co/t/logstah-nonexistent-lob-error-from-jdbc-plugin/310823 "2022-07-28T07:33:52Z")

</div>

While selecting blob data from input jdbc getting nonexistent lob value error.Could you someone help me on this.

---

## [Unable to Start Elasticserach](https://discuss.elastic.co/t/unable-to-start-elasticserach/310811)

<div class="topic-metadata">

**Author:** [@Zerra\_Triani](https://discuss.elastic.co/u/Zerra_Triani)\
**Replies:** 3\
**Last updated:** [July 28, 2022, 6:57am UTC](https://discuss.elastic.co/t/unable-to-start-elasticserach/310811 "2022-07-28T06:57:48Z")

</div>

Hi I can't turn on elasticsearch services after enabling xpack.security.enable : true and changing master account password. And I tried to disable the xpack but elasticsearch still can't run Here's the journalctl -xe -…

---

## [Logstash not listening port 5044 even when we configured the beats](https://discuss.elastic.co/t/logstash-not-listening-port-5044-even-when-we-configured-the-beats/310792)

<div class="topic-metadata">

**Author:** [@KALAVATHI\_YALAMANCHA](https://discuss.elastic.co/u/KALAVATHI_YALAMANCHA)\
**Replies:** 17\
**Last updated:** [July 28, 2022, 5:34am UTC](https://discuss.elastic.co/t/logstash-not-listening-port-5044-even-when-we-configured-the-beats/310792 "2022-07-28T05:34:16Z")

</div>

input { beats { type =\> beats host =\> "localhost" port =\> 5044 }

---

## [Grokparsefailure for same kind of logs](https://discuss.elastic.co/t/grokparsefailure-for-same-kind-of-logs/310596)

<div class="topic-metadata">

**Author:** [@Priyanka\_chauhan](https://discuss.elastic.co/u/Priyanka_chauhan)\
**Replies:** 1\
**Last updated:** [July 28, 2022, 4:55am UTC](https://discuss.elastic.co/t/grokparsefailure-for-same-kind-of-logs/310596 "2022-07-28T04:55:22Z")

</div>

I have applied grokpattern to parsed logs,but it happens at kibana that some logs are parsed and some are unparsed while unparsed message is same for both,Kindly help me to find out the issue. sample of parsed and unpar…

---

## [Kibana server is not ready yet - Unable to retrieve version information from Elasticsearch nodes. security\_exception](https://discuss.elastic.co/t/kibana-server-is-not-ready-yet-unable-to-retrieve-version-information-from-elasticsearch-nodes-security-exception/310757)

<div class="topic-metadata">

**Author:** [@ShaheerBadar](https://discuss.elastic.co/u/ShaheerBadar)\
**Replies:** 4\
**Last updated:** [July 28, 2022, 3:12am UTC](https://discuss.elastic.co/t/kibana-server-is-not-ready-yet-unable-to-retrieve-version-information-from-elasticsearch-nodes-security-exception/310757 "2022-07-28T03:12:39Z")

</div>

Hi All, I am new in ELK stack. I have installed elasticsearch & Kibana version 8.3.2 on RedHat Linux 8.6. Elasticsearch configured properly and running fine. But while starting up Kibana we see "Unable to retrieve versi…

---

## [Issue when switch trial license to basic license on Azure self-manage](https://discuss.elastic.co/t/issue-when-switch-trial-license-to-basic-license-on-azure-self-manage/310724)

<div class="topic-metadata">

**Author:** [@wl02302677](https://discuss.elastic.co/u/wl02302677)\
**Replies:** 3\
**Last updated:** [July 28, 2022, 2:28am UTC](https://discuss.elastic.co/t/issue-when-switch-trial-license-to-basic-license-on-azure-self-manage/310724 "2022-07-28T02:28:06Z")

</div>

Hi, I build my elasticsearch cluster by Azure - self-manage. And when I want to switch my ES license to basic, I follow below step and went some cluster error issue Switch license on kibana license management page Che…

---

## [Observability Elastic Lab Insufficient privileges Lab1.2](https://discuss.elastic.co/t/observability-elastic-lab-insufficient-privileges-lab1-2/310503)

<div class="topic-metadata">

**Author:** [@linhz](https://discuss.elastic.co/u/linhz)\
**Replies:** 4\
**Last updated:** [July 28, 2022, 1:11am UTC](https://discuss.elastic.co/t/observability-elastic-lab-insufficient-privileges-lab1-2/310503 "2022-07-28T01:11:07Z")

</div>

Encounter issue when running the lab 1.2. There is not enough permission to grant the ICMP. Thanks.

---

## [Query to determine http.max\_content\_length prior to sending?](https://discuss.elastic.co/t/query-to-determine-http-max-content-length-prior-to-sending/310803)

<div class="topic-metadata">

**Author:** [@matty\_r](https://discuss.elastic.co/u/matty_r)\
**Replies:** 3\
**Last updated:** [July 28, 2022, 12:15am UTC](https://discuss.elastic.co/t/query-to-determine-http-max-content-length-prior-to-sending/310803 "2022-07-28T00:15:24Z")

</div>

Hi all, Is there a query to return the http.max\_content\_length prior to sending data? Cheers

---

## [How can I check if a log file was analyzed by logstash or not?](https://discuss.elastic.co/t/how-can-i-check-if-a-log-file-was-analyzed-by-logstash-or-not/310375)

<div class="topic-metadata">

**Author:** [@maoxuguang](https://discuss.elastic.co/u/maoxuguang)\
**Replies:** 2\
**Last updated:** [July 27, 2022, 11:56pm UTC](https://discuss.elastic.co/t/how-can-i-check-if-a-log-file-was-analyzed-by-logstash-or-not/310375 "2022-07-27T23:56:28Z")

</div>

I found one of my log is missing in elasticsearch， how can I know if logstash analyzed it or not? or how can I know what problem logstah meet? In logstash-plain.log the information is limited, there is no information a…

---

## [Elasticsearch nodes not running after reboot linux](https://discuss.elastic.co/t/elasticsearch-nodes-not-running-after-reboot-linux/308975)

<div class="topic-metadata">

**Author:** [@lstoneir](https://discuss.elastic.co/u/lstoneir)\
**Replies:** 8\
**Last updated:** [July 27, 2022, 6:31pm UTC](https://discuss.elastic.co/t/elasticsearch-nodes-not-running-after-reboot-linux/308975 "2022-07-27T18:31:57Z")

</div>

Hi every one I have a problem with elasticsearch cluster. when the nodes of elasticsearch turned off, i turned on again, the elasticsearch service state is ● elasticsearch.service - Elasticsearch Loaded: loaded (/lib…

---

## [Managing event filters outside the UI](https://discuss.elastic.co/t/managing-event-filters-outside-the-ui/310762)

<div class="topic-metadata">

**Author:** [@ryanturner03](https://discuss.elastic.co/u/ryanturner03)\
**Replies:** 3\
**Last updated:** [July 27, 2022, 10:12pm UTC](https://discuss.elastic.co/t/managing-event-filters-outside-the-ui/310762 "2022-07-27T22:12:37Z")

</div>

Hi all, I'm looking for a way to manage event filters across a number of deployments. Is there any API available to create / manage those or can it only be done in the UI? The feature I'm referring to:

---

## [Elastic Security Endpoint Security](https://discuss.elastic.co/t/elastic-security-endpoint-security/310802)

<div class="topic-metadata">

**Author:** [@Jared9922](https://discuss.elastic.co/u/Jared9922)\
**Replies:** 0\
**Last updated:** [July 27, 2022, 9:02pm UTC](https://discuss.elastic.co/t/elastic-security-endpoint-security/310802 "2022-07-27T21:02:44Z")

</div>

Hello, I am trying to setup endpoint security for our elastic stack and I am a little confused and I have a few questions. Firstly, to use endpoint security do you need to install elastic agent on each of your hosts? …

---

## [Backward pagination with search\_after when sorting value is null](https://discuss.elastic.co/t/backward-pagination-with-search-after-when-sorting-value-is-null/310799)

<div class="topic-metadata">

**Author:** [@M\_L](https://discuss.elastic.co/u/M_L)\
**Replies:** 0\
**Last updated:** [July 27, 2022, 8:48pm UTC](https://discuss.elastic.co/t/backward-pagination-with-search-after-when-sorting-value-is-null/310799 "2022-07-27T20:48:01Z")

</div>

Hello, I have an application which has a dashboard, basically a table with hundreds of thousands of records. This table has up to 50 different columns. These columns have different types in mapping: keyword, text, bool…

---

## [Elastic Learning Portal](https://discuss.elastic.co/t/elastic-learning-portal/310576)

<div class="topic-metadata">

**Author:** [@Kimberly](https://discuss.elastic.co/u/Kimberly)\
**Replies:** 3\
**Last updated:** [July 27, 2022, 7:24pm UTC](https://discuss.elastic.co/t/elastic-learning-portal/310576 "2022-07-27T19:24:33Z")

</div>

I am having an issue to do the Lab: Introduction to Elastic App Search for the class 1 . I created a deployment named enterprise-search-fundamentals and finished "TUNE THE RELEVANCE OF YOUR QUERIES" and continued to "AN…

---

## [Does min\_doc\_count impact the documents returned?](https://discuss.elastic.co/t/does-min-doc-count-impact-the-documents-returned/310787)

<div class="topic-metadata">

**Author:** [@mattkallo](https://discuss.elastic.co/u/mattkallo)\
**Replies:** 0\
**Last updated:** [July 27, 2022, 6:32pm UTC](https://discuss.elastic.co/t/does-min-doc-count-impact-the-documents-returned/310787 "2022-07-27T18:32:59Z")

</div>

Hi - I have 2 questions regarding term aggregations min\_doc\_count setting. Will min\_doc\_count limit the documents returned or just the bucket/term in aggregation? Say I have 200 documents and 120 of them have the te…

---

## [To identify the elastic search breakup pricing for each resources](https://discuss.elastic.co/t/to-identify-the-elastic-search-breakup-pricing-for-each-resources/310782)

<div class="topic-metadata">

**Author:** [@Aravind1](https://discuss.elastic.co/u/Aravind1)\
**Replies:** 1\
**Last updated:** [July 27, 2022, 6:04pm UTC](https://discuss.elastic.co/t/to-identify-the-elastic-search-breakup-pricing-for-each-resources/310782 "2022-07-27T18:04:14Z")

</div>

Hello, We are from Virtusasystem LLC . We have been utilizing the Elasticsearch facility for quite a while now where we are utilizing approximately around 37 or more operating systems. We are looking for a breakdown of …

---

## [Output jdbc data inserts](https://discuss.elastic.co/t/output-jdbc-data-inserts/310780)

<div class="topic-metadata">

**Author:** [@Calvete](https://discuss.elastic.co/u/Calvete)\
**Replies:** 0\
**Last updated:** [July 27, 2022, 5:33pm UTC](https://discuss.elastic.co/t/output-jdbc-data-inserts/310780 "2022-07-27T17:33:16Z")

</div>

Hello, my input is a file in s3 and I am making insections to an amazon aurora postgresq database. The time is not good to insert more than 1 million records, it takes 1 hour and a half. Help me pipeline: batch: siz…

---

## [Drilldown without filtering possible?](https://discuss.elastic.co/t/drilldown-without-filtering-possible/310693)

<div class="topic-metadata">

**Author:** [@paolovalladolid](https://discuss.elastic.co/u/paolovalladolid)\
**Replies:** 1\
**Last updated:** [July 27, 2022, 4:34pm UTC](https://discuss.elastic.co/t/drilldown-without-filtering-possible/310693 "2022-07-27T16:34:40Z")

</div>

We're on Kibana 7.16.3 I have a dashboard with a panel that has a drilldown set up, to go to another dashboard. The panel is a table with two columns. When I hover the cursor over a cell to get the little blue icon (r…

---

## [Issue while configuring metricbeat in logstash version 7.16.3](https://discuss.elastic.co/t/issue-while-configuring-metricbeat-in-logstash-version-7-16-3/310677)

<div class="topic-metadata">

**Author:** [@Subhanwita\_Mullick](https://discuss.elastic.co/u/Subhanwita_Mullick)\
**Replies:** 0\
**Last updated:** [July 26, 2022, 6:24pm UTC](https://discuss.elastic.co/t/issue-while-configuring-metricbeat-in-logstash-version-7-16-3/310677 "2022-07-26T18:24:02Z")

</div>

Hello, I am migrating the logstash to version 7.16.3 from 7.9.3. But there is some error while updating the metricbeat in logstash. Error: Class org.jruby.RubyFloat cannot be cast to class Java.lang.double PFA the scr…

---

## [Reset lab environment and progress](https://discuss.elastic.co/t/reset-lab-environment-and-progress/310721)

<div class="topic-metadata">

**Author:** [@mekberg](https://discuss.elastic.co/u/mekberg)\
**Replies:** 2\
**Last updated:** [July 27, 2022, 2:00pm UTC](https://discuss.elastic.co/t/reset-lab-environment-and-progress/310721 "2022-07-27T14:00:58Z")

</div>

I'm doing an on-demand Elastic Engineer course, which I have finished, but I'd like to run through the labs once more to refresh my knowledge before attempting a certification. I can't find anywhere to reset the complete…

---

## [Is there any way to reference the actual record from a graph created in Dashboard?](https://discuss.elastic.co/t/is-there-any-way-to-reference-the-actual-record-from-a-graph-created-in-dashboard/310738)

<div class="topic-metadata">

**Author:** [@its-ogawa](https://discuss.elastic.co/u/its-ogawa)\
**Replies:** 2\
**Last updated:** [July 27, 2022, 1:23pm UTC](https://discuss.elastic.co/t/is-there-any-way-to-reference-the-actual-record-from-a-graph-created-in-dashboard/310738 "2022-07-27T13:23:45Z")

</div>

I have created several graphs in Dashboard using Lens. This allows me to visually monitor the incidences. Now I would like to see the logs of the areas of interest in the graphs. Is it possible to see the logs around …

---

## [Can I reset the lab](https://discuss.elastic.co/t/can-i-reset-the-lab/310726)

<div class="topic-metadata">

**Author:** [@stepheng](https://discuss.elastic.co/u/stepheng)\
**Replies:** 1\
**Last updated:** [July 27, 2022, 12:54pm UTC](https://discuss.elastic.co/t/can-i-reset-the-lab/310726 "2022-07-27T12:54:03Z")

</div>

I'm new to ES as well as Linux. I just started the \[Elastic Observability Engineer\] courses. (Loading) On Lab 1.2: Heartbeat and Uptime, I somehow covered a executable file which stop me from going further. Then I delet…

---

## [How do the Endpoint preventions work?](https://discuss.elastic.co/t/how-do-the-endpoint-preventions-work/310179)

<div class="topic-metadata">

**Author:** [@tmahany419](https://discuss.elastic.co/u/tmahany419)\
**Replies:** 2\
**Last updated:** [July 27, 2022, 12:49pm UTC](https://discuss.elastic.co/t/how-do-the-endpoint-preventions-work/310179 "2022-07-27T12:49:12Z")

</div>

On this page under the policies: If click the link to "related detection rules" it just shows all the elastic rules. How do I know which rules will prevent traffic because it is ransomeware?

---

## [Pattern analyzer regex help](https://discuss.elastic.co/t/pattern-analyzer-regex-help/310694)

<div class="topic-metadata">

**Author:** [@ansamHox](https://discuss.elastic.co/u/ansamHox)\
**Replies:** 2\
**Last updated:** [July 27, 2022, 12:31pm UTC](https://discuss.elastic.co/t/pattern-analyzer-regex-help/310694 "2022-07-27T12:31:10Z")

</div>

Got a question regarding the pattern analyzer. Example text: S6UlZgYCJaSIQcy03OOA==Ieuwc7Ix/CQfwoDSOVJl== 2oZjflRSRkcj4/OHcp78== It's encrypted (each letter is hashed to 20 characters ending with == sign). I would like…

---

## [Remove/Prevent duplicates with rollover](https://discuss.elastic.co/t/remove-prevent-duplicates-with-rollover/310717)

<div class="topic-metadata">

**Author:** [@bianca6](https://discuss.elastic.co/u/bianca6)\
**Replies:** 14\
**Last updated:** [July 27, 2022, 9:49am UTC](https://discuss.elastic.co/t/remove-prevent-duplicates-with-rollover/310717 "2022-07-27T09:49:19Z")

</div>

Hi, One of my index has an ILM (index lifecycle management) with rollovers. The problem is, when the index receive data and rollover at the same time, the latest data are duplicated (present in both the new and old ind…

---

## [Date\_histogram interval versus fixed\_interval and calendar\_interval](https://discuss.elastic.co/t/date-histogram-interval-versus-fixed-interval-and-calendar-interval/310733)

<div class="topic-metadata">

**Author:** [@sbruinsje](https://discuss.elastic.co/u/sbruinsje)\
**Replies:** 0\
**Last updated:** [July 27, 2022, 9:35am UTC](https://discuss.elastic.co/t/date-histogram-interval-versus-fixed-interval-and-calendar-interval/310733 "2022-07-27T09:35:45Z")

</div>

I am upgrading to elasticsearch 8 which doesn't support the interval on date\_histogram anymore. Instead it expects a fixed\_interval or calendar\_interval. I am a bit confused about the old interval field. Does interval: …

[Previous page](https://discuss.elastic.co/tag/none.md?no_tags=true&page=573)

[Next page](https://discuss.elastic.co/tag/none.md?no_tags=true&page=575)
