# \#none

**URL:** https://discuss.elastic.co/tag/none.md?no_tags=true&page=580

[Latest](https://discuss.elastic.co/latest.md) · [Categories](https://discuss.elastic.co/categories.md) · [Tags](https://discuss.elastic.co/tags.md)

**Page:** 581

---

## [Segregate Multiple Applications per each ELK Instance](https://discuss.elastic.co/t/segregate-multiple-applications-per-each-elk-instance/310019)

<div class="topic-metadata">

**Author:** [@amseshadri](https://discuss.elastic.co/u/amseshadri)\
**Replies:** 5\
**Last updated:** [July 20, 2022, 4:25pm UTC](https://discuss.elastic.co/t/segregate-multiple-applications-per-each-elk-instance/310019 "2022-07-20T16:25:37Z")

</div>

Hi, I am a newbie to ELK, exploring the things from few days. Using the ELK 8.1.4 version We recently got the ELK Stack installed as a SaaS in our Azure Cloud Subscription. So we have one instance of ELK in each envir…

---

## [Minimum access required by developer to ELK tool](https://discuss.elastic.co/t/minimum-access-required-by-developer-to-elk-tool/310024)

<div class="topic-metadata">

**Author:** [@amseshadri](https://discuss.elastic.co/u/amseshadri)\
**Replies:** 4\
**Last updated:** [July 20, 2022, 4:06pm UTC](https://discuss.elastic.co/t/minimum-access-required-by-developer-to-elk-tool/310024 "2022-07-20T16:06:01Z")

</div>

Hi, We are using ELK 8.1.4 running on cluster. Setting up the roles and permissions for users utilising spaces and all. Just want to know what is minimum level of access privilege required by a developer? Thanks Ses…

---

## [Fleet server certificate problem (I think)](https://discuss.elastic.co/t/fleet-server-certificate-problem-i-think/310168)

<div class="topic-metadata">

**Author:** [@rugenl](https://discuss.elastic.co/u/rugenl)\
**Replies:** 0\
**Last updated:** [July 20, 2022, 2:40pm UTC](https://discuss.elastic.co/t/fleet-server-certificate-problem-i-think/310168 "2022-07-20T14:40:33Z")

</div>

I see posts similar, people point to the problem, but none point to the fix. I installed an 8.3.1 fleet server. when trying to enroll the first host, I get error Error: fail to enroll: fail to execute request to fleet…

---

## [Top\_metric for Geo\_Point](https://discuss.elastic.co/t/top-metric-for-geo-point/310164)

<div class="topic-metadata">

**Author:** [@bianca6](https://discuss.elastic.co/u/bianca6)\
**Replies:** 0\
**Last updated:** [July 20, 2022, 2:15pm UTC](https://discuss.elastic.co/t/top-metric-for-geo-point/310164 "2022-07-20T14:15:50Z")

</div>

Hi, In the Transform examples we can find the top\_metrics aggregation. Here is an example: POST \_transform/\_preview { "source": { "index": "kibana\_sample\_data\_ecommerce" }, "pivot": { "group\_by": { …

---

## [Average per day for a period](https://discuss.elastic.co/t/average-per-day-for-a-period/308942)

<div class="topic-metadata">

**Author:** [@Igor-lkm](https://discuss.elastic.co/u/Igor-lkm)\
**Replies:** 1\
**Last updated:** [July 20, 2022, 12:53pm UTC](https://discuss.elastic.co/t/average-per-day-for-a-period/308942 "2022-07-20T12:53:20Z")

</div>

Hello, I have a quite simple aggregation to get sum and average total price for a period (1 day, 7 days, 30 days etc.) from my index. That works quite good. Aggregation for 30 days looks like this: { "size": 10000, …

---

## [Replace a value to another value logstash](https://discuss.elastic.co/t/replace-a-value-to-another-value-logstash/310129)

<div class="topic-metadata">

**Author:** [@mikhatanu](https://discuss.elastic.co/u/mikhatanu)\
**Replies:** 1\
**Last updated:** [July 20, 2022, 12:47pm UTC](https://discuss.elastic.co/t/replace-a-value-to-another-value-logstash/310129 "2022-07-20T12:47:42Z")

</div>

Hello, i have a log with an id. In another file, i have list file of the id mapping. for example id 1 has a name, description, etc in the list file. I want to replace the id in that log to the data in the list file. Log…

---

## [Sourcemaps - not mapping for all errors](https://discuss.elastic.co/t/sourcemaps-not-mapping-for-all-errors/310125)

<div class="topic-metadata">

**Author:** [@Hamunaptroid](https://discuss.elastic.co/u/Hamunaptroid)\
**Replies:** 0\
**Last updated:** [July 20, 2022, 9:45am UTC](https://discuss.elastic.co/t/sourcemaps-not-mapping-for-all-errors/310125 "2022-07-20T09:45:21Z")

</div>

Hello, I would like to follow up with the thread which was closed already - it seemed like problem with sourcemaps was fixed, but it seems it isn't working 100%. I have managed to get it working partially with help of…

---

## [How to add suggestion inside term query in DSL](https://discuss.elastic.co/t/how-to-add-suggestion-inside-term-query-in-dsl/309893)

<div class="topic-metadata">

**Author:** [@sim\_elastic](https://discuss.elastic.co/u/sim_elastic)\
**Replies:** 6\
**Last updated:** [July 20, 2022, 8:51am UTC](https://discuss.elastic.co/t/how-to-add-suggestion-inside-term-query-in-dsl/309893 "2022-07-20T08:51:06Z")

</div>

My DOc is below \[ {'id':1, 'name': 'sachin messi', 'description': 'football@football.com', 'type': 'football', 'var':'sports'}, {'id':2, 'name': 'lionel messi', 'description': 'messi@fifa.com','type': 'soccer','var':'sp…

---

## [IO processing speed requirements for Elastic product line](https://discuss.elastic.co/t/io-processing-speed-requirements-for-elastic-product-line/310108)

<div class="topic-metadata">

**Author:** [@its-ogawa](https://discuss.elastic.co/u/its-ogawa)\
**Replies:** 5\
**Last updated:** [July 20, 2022, 9:47am UTC](https://discuss.elastic.co/t/io-processing-speed-requirements-for-elastic-product-line/310108 "2022-07-20T09:47:41Z")

</div>

We are considering moving Elasticsearch from vsan to fnas or synology nas. We are thinking that the IO processing speed will be reduced, but how much is the impact? Or are there any hardware requirements for IO process…

---

## [Update to 8.3.1 from 8.3.0 has broken Fleet - please help!](https://discuss.elastic.co/t/update-to-8-3-1-from-8-3-0-has-broken-fleet-please-help/308654)

<div class="topic-metadata">

**Author:** [@finbarr996](https://discuss.elastic.co/u/finbarr996)\
**Replies:** 10\
**Last updated:** [July 20, 2022, 8:32am UTC](https://discuss.elastic.co/t/update-to-8-3-1-from-8-3-0-has-broken-fleet-please-help/308654 "2022-07-20T08:32:37Z")

</div>

Upgraded to 8.3 a few days ago - everything working fine. Updated to 8.3.1 this morning and now the elastic-agent service won't start on my single on-prem node - this is also the Fleet Server. Error in the logs is: Er…

---

## [Stats endpoints response slow](https://discuss.elastic.co/t/stats-endpoints-response-slow/310062)

<div class="topic-metadata">

**Author:** [@scroodj](https://discuss.elastic.co/u/scroodj)\
**Replies:** 3\
**Last updated:** [July 20, 2022, 8:27am UTC](https://discuss.elastic.co/t/stats-endpoints-response-slow/310062 "2022-07-20T08:27:12Z")

</div>

Elasticsearch: 7.5.1 Infrastructure: Azure AKS Storage: Standard SSD \_cat/nodes name m role ip ramMax ramPercent ramCurrent heapMax heapPercent heapCurrent diskTotal diskUsed cpu uptime iic…

---

## [ECK service](https://discuss.elastic.co/t/eck-service/310110)

<div class="topic-metadata">

**Author:** [@Biplab](https://discuss.elastic.co/u/Biplab)\
**Replies:** 0\
**Last updated:** [July 20, 2022, 8:22am UTC](https://discuss.elastic.co/t/eck-service/310110 "2022-07-20T08:22:22Z")

</div>

Hi, We are planning to deploy elastic cluster first on ECK and then will run the service and Ingress configuration file separately to access Elasticsearch from outside kubernetes cluster, Can anyone please help whether …

---

## [Type join,Why do you get no data over 80, but you can get data over 100](https://discuss.elastic.co/t/type-join-why-do-you-get-no-data-over-80-but-you-can-get-data-over-100/310109)

<div class="topic-metadata">

**Author:** [@yangyu](https://discuss.elastic.co/u/yangyu)\
**Replies:** 0\
**Last updated:** [July 20, 2022, 8:18am UTC](https://discuss.elastic.co/t/type-join-why-do-you-get-no-data-over-80-but-you-can-get-data-over-100/310109 "2022-07-20T08:18:38Z")

</div>

Elasticsearch Version 7.17.4 Installed Plugins analysis-ik,analysis-pinyin,analysis-stconvert Java Version 1.8.0\_331-b09 OS Version MacBook-Pro.local 21.5.0 Darwin Kernel Version 21.5.0: Tue Apr 26 21:08:37 PDT 2022; …

---

## [ECE Fundamentals: "Not enough capacity to allocate instance(s)"](https://discuss.elastic.co/t/ece-fundamentals-not-enough-capacity-to-allocate-instance-s/309907)

<div class="topic-metadata">

**Author:** [@rcorfield](https://discuss.elastic.co/u/rcorfield)\
**Replies:** 4\
**Last updated:** [July 20, 2022, 8:15am UTC](https://discuss.elastic.co/t/ece-fundamentals-not-enough-capacity-to-allocate-instance-s/309907 "2022-07-20T08:15:01Z")

</div>

Hi, I'm trying the complete the "ECE Fundamentals" labs, but I've hit a problem when I trying to create a new deployment via the Cloud UI in Lab 3. I receive the following message: Latest change to Elasticsearch config…

---

## [Elasticsearch - filter index on aggregated field](https://discuss.elastic.co/t/elasticsearch-filter-index-on-aggregated-field/310105)

<div class="topic-metadata">

**Author:** [@Julynell](https://discuss.elastic.co/u/Julynell)\
**Replies:** 0\
**Last updated:** [July 20, 2022, 8:00am UTC](https://discuss.elastic.co/t/elasticsearch-filter-index-on-aggregated-field/310105 "2022-07-20T08:00:48Z")

</div>

Hi, We could use your help. We have Elasticsearch with logstash. It is inserting data in elastic index from a jdbc source. In logstash we use an aggregate filter. The config looks like this: input { jdbc { …

---

## [Adding fields based on match](https://discuss.elastic.co/t/adding-fields-based-on-match/310094)

<div class="topic-metadata">

**Author:** [@rusty\_cole](https://discuss.elastic.co/u/rusty_cole)\
**Replies:** 0\
**Last updated:** [July 20, 2022, 6:53am UTC](https://discuss.elastic.co/t/adding-fields-based-on-match/310094 "2022-07-20T06:53:04Z")

</div>

Hi All, I have the following scenario: 1 index containing json fields. I need to match Event1\_fieldA to Event2\_fieldB. If there is a match, add additional existing field from Event2 to Event1. How would I achieve t…

---

## [Kibana not installing on Ubuntu Server](https://discuss.elastic.co/t/kibana-not-installing-on-ubuntu-server/309988)

<div class="topic-metadata">

**Author:** [@Ronald\_Chinomona](https://discuss.elastic.co/u/Ronald_Chinomona)\
**Replies:** 3\
**Last updated:** [July 20, 2022, 7:50am UTC](https://discuss.elastic.co/t/kibana-not-installing-on-ubuntu-server/309988 "2022-07-20T07:50:27Z")

</div>

I have been trying to install Kibana on Ubuntu Server for the last two days. The package unpacking progress just gets stuck on 20%. I have tried on different VM's with different specs. I have made sure there is enough me…

---

## [Logstash pipeline grok issue with regex](https://discuss.elastic.co/t/logstash-pipeline-grok-issue-with-regex/308252)

<div class="topic-metadata">

**Author:** [@Sharon\_Hacham](https://discuss.elastic.co/u/Sharon_Hacham)\
**Replies:** 24\
**Last updated:** [July 20, 2022, 6:49am UTC](https://discuss.elastic.co/t/logstash-pipeline-grok-issue-with-regex/308252 "2022-07-20T06:49:18Z")

</div>

Hi , we have a Logstash pipeline , for Kafka on-premise Confluent Platform logs - shipped using Filebeat Kafka module , We are using a grok pattern to extract some of the entries in the data in order to use that data i…

---

## [How logstash extracts specific characters from a path?](https://discuss.elastic.co/t/how-logstash-extracts-specific-characters-from-a-path/310090)

<div class="topic-metadata">

**Author:** [@wajika](https://discuss.elastic.co/u/wajika)\
**Replies:** 2\
**Last updated:** [July 20, 2022, 6:45am UTC](https://discuss.elastic.co/t/how-logstash-extracts-specific-characters-from-a-path/310090 "2022-07-20T06:45:21Z")

</div>

I want to extract "acpro" as the service name from the path below, can anyone offer some advice? /api/acpro/filter/dowork/ayc /api/acpro/filter/toko /api/acpro/filter/toko/user/passwd /api/acpro/account/getsales/b77dd0b…

---

## [Some elasticsearch index deleted after elasticsearch cluster restart](https://discuss.elastic.co/t/some-elasticsearch-index-deleted-after-elasticsearch-cluster-restart/310088)

<div class="topic-metadata">

**Author:** [@deepakdinkar311](https://discuss.elastic.co/u/deepakdinkar311)\
**Replies:** 1\
**Last updated:** [July 20, 2022, 6:36am UTC](https://discuss.elastic.co/t/some-elasticsearch-index-deleted-after-elasticsearch-cluster-restart/310088 "2022-07-20T06:36:16Z")

</div>

After restarting elasticsearch cluster some index are deleted automatically.

---

## [Logstash Dissect against \\e control character](https://discuss.elastic.co/t/logstash-dissect-against-e-control-character/309993)

<div class="topic-metadata">

**Author:** [@Silver137](https://discuss.elastic.co/u/Silver137)\
**Replies:** 2\
**Last updated:** [July 20, 2022, 6:01am UTC](https://discuss.elastic.co/t/logstash-dissect-against-e-control-character/309993 "2022-07-20T06:01:38Z")

</div>

My line to dissect begins with \\e\[92mContent , I need extract Content avoiding \\e\[92 I have already try: dissect { mapping =\> { "message" =\> "\\e\[92m%{content}"}} But not works

---

## [Have configured Heartbeat and logstash and influxdb but measurements are not getting created in database](https://discuss.elastic.co/t/have-configured-heartbeat-and-logstash-and-influxdb-but-measurements-are-not-getting-created-in-database/310085)

<div class="topic-metadata">

**Author:** [@sagarpathak](https://discuss.elastic.co/u/sagarpathak)\
**Replies:** 0\
**Last updated:** [July 20, 2022, 5:48am UTC](https://discuss.elastic.co/t/have-configured-heartbeat-and-logstash-and-influxdb-but-measurements-are-not-getting-created-in-database/310085 "2022-07-20T05:48:05Z")

</div>

have configured Heartbeat and logstash and influxdb but measurements are not getting created in database(telegraf)

---

## [Logstash running without logstash.yml](https://discuss.elastic.co/t/logstash-running-without-logstash-yml/307338)

<div class="topic-metadata">

**Author:** [@vikram\_singh](https://discuss.elastic.co/u/vikram_singh)\
**Replies:** 5\
**Last updated:** [July 20, 2022, 5:47am UTC](https://discuss.elastic.co/t/logstash-running-without-logstash-yml/307338 "2022-07-20T05:47:40Z")

</div>

Hi, I am running logstash for a single file by sudo /usr/share/logstash/bin/logstash --path.settings /etc/logstash/ -f /etc/logstash/conf.d/myfile.conf it is running correctly. But when I start logstash as a service…

---

## [Http input plugins is not behaving as expected](https://discuss.elastic.co/t/http-input-plugins-is-not-behaving-as-expected/309982)

<div class="topic-metadata">

**Author:** [@priyankamondalhcl](https://discuss.elastic.co/u/priyankamondalhcl)\
**Replies:** 2\
**Last updated:** [July 20, 2022, 5:20am UTC](https://discuss.elastic.co/t/http-input-plugins-is-not-behaving-as-expected/309982 "2022-07-20T05:20:22Z")

</div>

Hi, I am using http input plugins, which should be capable to expect json events, and the amount of data is huge (around 7,00,000 in 30 mins). after processing some data it stopped working and throwing error: \[13004ae0f…

---

## [Copy contents of one field to same field of another row if certain condition matches](https://discuss.elastic.co/t/copy-contents-of-one-field-to-same-field-of-another-row-if-certain-condition-matches/308339)

<div class="topic-metadata">

**Author:** [@Ashutosh\_Vaidya](https://discuss.elastic.co/u/Ashutosh_Vaidya)\
**Replies:** 14\
**Last updated:** [July 20, 2022, 5:20am UTC](https://discuss.elastic.co/t/copy-contents-of-one-field-to-same-field-of-another-row-if-certain-condition-matches/308339 "2022-07-20T05:20:07Z")

</div>

I need to copy contents of “Service” field from No. 15256 into the :path field of No.15257 if “Stream\_Identifier” of both lines in 15256 and 15257 are matching. Kindly suggest how to get this done in the conf file of lo…

---

## [This article is outdated, what's the updated article about this?](https://discuss.elastic.co/t/this-article-is-outdated-whats-the-updated-article-about-this/310078)

<div class="topic-metadata">

**Author:** [@davecomputertips](https://discuss.elastic.co/u/davecomputertips)\
**Replies:** 1\
**Last updated:** [July 20, 2022, 2:54am UTC](https://discuss.elastic.co/t/this-article-is-outdated-whats-the-updated-article-about-this/310078 "2022-07-20T02:54:09Z")

</div>

Please share a latest updated article about Elasticsearch types of index(same topic mentioned there and many).

---

## [Upgrade ES 6 Index to 7 Without Reindex](https://discuss.elastic.co/t/upgrade-es-6-index-to-7-without-reindex/309940)

<div class="topic-metadata">

**Author:** [@Jerjef](https://discuss.elastic.co/u/Jerjef)\
**Replies:** 5\
**Last updated:** [July 20, 2022, 12:05am UTC](https://discuss.elastic.co/t/upgrade-es-6-index-to-7-without-reindex/309940 "2022-07-20T00:05:35Z")

</div>

I know this sounds obvious, but I need to ask to be sure. I have an ES 6 index in an ES 7 instance. I know it's backward compatible, but is there a way or upgrading the index to an ES 7 schema without reindexing due to…

---

## [How to create filter for strings with separator and calculate string?](https://discuss.elastic.co/t/how-to-create-filter-for-strings-with-separator-and-calculate-string/310073)

<div class="topic-metadata">

**Author:** [@Bohdan\_Repetskyi](https://discuss.elastic.co/u/Bohdan_Repetskyi)\
**Replies:** 0\
**Last updated:** [July 19, 2022, 9:57pm UTC](https://discuss.elastic.co/t/how-to-create-filter-for-strings-with-separator-and-calculate-string/310073 "2022-07-19T21:57:26Z")

</div>

I have a simple config file: input { file{ path =\> "/tmp/data\_for\_logstach" start\_position =\> "beginning" } } filter { } output { file{ path =\> "/tmp/logstash\_convert" action =\> "update" } } H…

---

## [Logstash kafka](https://discuss.elastic.co/t/logstash-kafka/310064)

<div class="topic-metadata">

**Author:** [@emmanuel\_stevens\_LED](https://discuss.elastic.co/u/emmanuel_stevens_LED)\
**Replies:** 0\
**Last updated:** [July 19, 2022, 7:55pm UTC](https://discuss.elastic.co/t/logstash-kafka/310064 "2022-07-19T19:55:03Z")

</div>

Hello, I need some help to understand someting. I am new in elk stack so i will ask a lot of questions for the next weeks. With th persistant queue in logstash and the Filebeat backpressure-sensitive protocol when send…

---

## [Updating Debian package does not copy state.yml](https://discuss.elastic.co/t/updating-debian-package-does-not-copy-state-yml/310037)

<div class="topic-metadata">

**Author:** [@nessus](https://discuss.elastic.co/u/nessus)\
**Replies:** 0\
**Last updated:** [July 19, 2022, 2:55pm UTC](https://discuss.elastic.co/t/updating-debian-package-does-not-copy-state-yml/310037 "2022-07-19T14:55:46Z")

</div>

Hello I just wanted to report a probably not wanted interaction between the elastic-agent debian packages when managed by a fleet Server. We had the problem, that we always needed to enroll an agent again after an upda…

[Previous page](https://discuss.elastic.co/tag/none.md?no_tags=true&page=579)

[Next page](https://discuss.elastic.co/tag/none.md?no_tags=true&page=581)
