# \#none

**URL:** https://discuss.elastic.co/tag/none.md?no_tags=true&page=581

[Latest](https://discuss.elastic.co/latest.md) · [Categories](https://discuss.elastic.co/categories.md) · [Tags](https://discuss.elastic.co/tags.md)

**Page:** 582

---

## [Integrating Serilog with applications](https://discuss.elastic.co/t/integrating-serilog-with-applications/310068)

<div class="topic-metadata">

**Author:** [@wes.campbell](https://discuss.elastic.co/u/wes.campbell)\
**Replies:** 0\
**Last updated:** [July 19, 2022, 9:08pm UTC](https://discuss.elastic.co/t/integrating-serilog-with-applications/310068 "2022-07-19T21:08:56Z")

</div>

The logs for our applications are captured by Serilog and sent to Elasticsearch. All of our configuration info for connecting to Elasticsearch is in the application config file. What do I need to enter in the config rega…

---

## [ES response shows ~20 secs delay when observed from the browser network logs](https://discuss.elastic.co/t/es-response-shows-20-secs-delay-when-observed-from-the-browser-network-logs/310049)

<div class="topic-metadata">

**Author:** [@kkumar.e](https://discuss.elastic.co/u/kkumar.e)\
**Replies:** 2\
**Last updated:** [July 19, 2022, 6:10pm UTC](https://discuss.elastic.co/t/es-response-shows-20-secs-delay-when-observed-from-the-browser-network-logs/310049 "2022-07-19T18:10:00Z")

</div>

Hi All, We are observing a random ~20 sec delay on ES responses on an ES cluster with 2 nodes created on 2 AWS EC2 servers spread across 2 subnets. I followed the steps in the below ref link to generate CA and elastic-s…

---

## [Incorrect Kibana Mappings From Winlogbeats Setup Command](https://discuss.elastic.co/t/incorrect-kibana-mappings-from-winlogbeats-setup-command/309953)

<div class="topic-metadata">

**Author:** [@Jared9922](https://discuss.elastic.co/u/Jared9922)\
**Replies:** 2\
**Last updated:** [July 19, 2022, 3:47pm UTC](https://discuss.elastic.co/t/incorrect-kibana-mappings-from-winlogbeats-setup-command/309953 "2022-07-19T15:47:24Z")

</div>

I have installed Winlogbeat on my computer and data seems to be flowing correctly. My data flows through my stack as shown Winlogbeat -\> logstash -\> elasticsearch I am trying to setup the index templates for Winlogbeat…

---

## [Not able to recognize rsyslogs in SIEM](https://discuss.elastic.co/t/not-able-to-recognize-rsyslogs-in-siem/309750)

<div class="topic-metadata">

**Author:** [@Rao\_Nelakurti](https://discuss.elastic.co/u/Rao_Nelakurti)\
**Replies:** 5\
**Last updated:** [July 18, 2022, 2:59pm UTC](https://discuss.elastic.co/t/not-able-to-recognize-rsyslogs-in-siem/309750 "2022-07-18T14:59:08Z")

</div>

I'm trying to send rsyslogs to SIEM (rsyslog-\> filebeat-\> logstash-\> siem) filebeat.conf, filebeat.spool\_size: 2048 filebeat.idle\_timeout: 5s output.logstash: hosts: \['10.x.x.5:6045'\] - type: log paths: - /var/l…

---

## [How to update index to allow nested queries?](https://discuss.elastic.co/t/how-to-update-index-to-allow-nested-queries/310027)

<div class="topic-metadata">

**Author:** [@Migodden](https://discuss.elastic.co/u/Migodden)\
**Replies:** 0\
**Last updated:** [July 19, 2022, 1:17pm UTC](https://discuss.elastic.co/t/how-to-update-index-to-allow-nested-queries/310027 "2022-07-19T13:17:28Z")

</div>

We have an index with a property that stores an array of objects with properties of strings. I want to be able to query against these array of objects to find a document where the objects properties match certain conditi…

---

## [1 huge pipelines vs 2 medium ones](https://discuss.elastic.co/t/1-huge-pipelines-vs-2-medium-ones/309925)

<div class="topic-metadata">

**Author:** [@anon90868141](https://discuss.elastic.co/u/anon90868141)\
**Replies:** 5\
**Last updated:** [July 19, 2022, 12:28pm UTC](https://discuss.elastic.co/t/1-huge-pipelines-vs-2-medium-ones/309925 "2022-07-19T12:28:41Z")

</div>

Hello, let's say I've got a cluster with 10 machines a 12 cores and I see data not being collected fast enough, so I need to raise my threads which is already at 12. Is better to go with the same pipeline and raise the…

---

## [Creating a NOT EQUAL filter in Java Fluent API](https://discuss.elastic.co/t/creating-a-not-equal-filter-in-java-fluent-api/309859)

<div class="topic-metadata">

**Author:** [@bweston](https://discuss.elastic.co/u/bweston)\
**Replies:** 4\
**Last updated:** [July 19, 2022, 12:29pm UTC](https://discuss.elastic.co/t/creating-a-not-equal-filter-in-java-fluent-api/309859 "2022-07-19T12:29:37Z")

</div>

Hi, I'm trying to compose a NOT EQUAL filter with the new Java Fluent API, querying Elastic 8.2 and have drawn a blank. The query below returns all documents that have expired according to our company retention policy, …

---

## [Terminate after not working for elasticsearch count ? Count optimization issue](https://discuss.elastic.co/t/terminate-after-not-working-for-elasticsearch-count-count-optimization-issue/310016)

<div class="topic-metadata">

**Author:** [@mehdiz](https://discuss.elastic.co/u/mehdiz)\
**Replies:** 0\
**Last updated:** [July 19, 2022, 12:04pm UTC](https://discuss.elastic.co/t/terminate-after-not-working-for-elasticsearch-count-count-optimization-issue/310016 "2022-07-19T12:04:02Z")

</div>

I want to have the total count of documents matching a specific query using the count query api of Elasticsearch on Python. I'm using the count to have a check of maximum documents that we can fetch for one query, somet…

---

## [Kibana doesn't start properly at upgrade from 7.17.1 to 8.3.2](https://discuss.elastic.co/t/kibana-doesnt-start-properly-at-upgrade-from-7-17-1-to-8-3-2/309586)

<div class="topic-metadata">

**Author:** [@gerib](https://discuss.elastic.co/u/gerib)\
**Replies:** 3\
**Last updated:** [July 19, 2022, 11:12am UTC](https://discuss.elastic.co/t/kibana-doesnt-start-properly-at-upgrade-from-7-17-1-to-8-3-2/309586 "2022-07-19T11:12:01Z")

</div>

Log message(s): ... ... \[ERROR\]\[savedobjects-service\] \[.kibana\] Action failed with 'security\_exception: \[security\_exception\] Reason: action \[indices:admin/create\] is unauthorized for user \[kibanaserver\] with roles \[…

---

## [\[8.3.2\] Message at Kibana's login page "Please upgrade your browser" when applying a Tampermonkey userscript](https://discuss.elastic.co/t/8-3-2-message-at-kibanas-login-page-please-upgrade-your-browser-when-applying-a-tampermonkey-userscript/309796)

<div class="topic-metadata">

**Author:** [@gerib](https://discuss.elastic.co/u/gerib)\
**Replies:** 2\
**Last updated:** [July 19, 2022, 10:51am UTC](https://discuss.elastic.co/t/8-3-2-message-at-kibanas-login-page-please-upgrade-your-browser-when-applying-a-tampermonkey-userscript/309796 "2022-07-19T10:51:49Z")

</div>

When applying the following userscript in Tampermonkey: // ==UserScript== // @name tab-size: 2 // @description Sets the tab (U+9) character's display size to 2. // @version 22.07.16-1645 // @author G…

---

## [Logstash JDBC connection for 3000 databases](https://discuss.elastic.co/t/logstash-jdbc-connection-for-3000-databases/310004)

<div class="topic-metadata">

**Author:** [@Poojan](https://discuss.elastic.co/u/Poojan)\
**Replies:** 0\
**Last updated:** [July 19, 2022, 10:17am UTC](https://discuss.elastic.co/t/logstash-jdbc-connection-for-3000-databases/310004 "2022-07-19T10:17:54Z")

</div>

Hello guys, I want to connect to 3000 databases which are on the same host using logstash. how can I connect those dbs and push data to elasticsearch?

---

## [Discovery.type : single-node but the new indexes are always : index.number\_of\_replicas" : "1"?](https://discuss.elastic.co/t/discovery-type-single-node-but-the-new-indexes-are-always-index-number-of-replicas-1/309318)

<div class="topic-metadata">

**Author:** [@PM75](https://discuss.elastic.co/u/PM75)\
**Replies:** 5\
**Last updated:** [July 19, 2022, 10:21am UTC](https://discuss.elastic.co/t/discovery-type-single-node-but-the-new-indexes-are-always-index-number-of-replicas-1/309318 "2022-07-19T10:21:43Z")

</div>

Hello, \[root@STL-SAS-025 ~\]# /usr/share/elasticsearch/bin/elasticsearch --version Version: 8.3.1, Build: rpm/b9a6b2867996ba92ceac66cb5bafc6db25e7910e/2022-06-29T18:39:55.731992798Z, JVM: 18.0.1.1 I'm having trouble und…

---

## [Phrase\_query for multiple should and must](https://discuss.elastic.co/t/phrase-query-for-multiple-should-and-must/309998)

<div class="topic-metadata">

**Author:** [@puff2fakie](https://discuss.elastic.co/u/puff2fakie)\
**Replies:** 0\
**Last updated:** [July 19, 2022, 9:44am UTC](https://discuss.elastic.co/t/phrase-query-for-multiple-should-and-must/309998 "2022-07-19T09:44:57Z")

</div>

I've indexed my documents as follows: doc = { "\_index": index\_name, "\_source": { "field": "bm25", "passage": passage, "passage\_id": pid, "level1": level1, "level2": level2…

---

## [JSON file parse error](https://discuss.elastic.co/t/json-file-parse-error/309869)

<div class="topic-metadata">

**Author:** [@ichasco\_heytrade](https://discuss.elastic.co/u/ichasco_heytrade)\
**Replies:** 2\
**Last updated:** [July 19, 2022, 8:58am UTC](https://discuss.elastic.co/t/json-file-parse-error/309869 "2022-07-19T08:58:44Z")

</div>

Hi, I am trying to parse a JSON file with this structure: \[ { "plugin": "cloudtrailBucketAccessLogging", "category": "CloudTrail", "title": "CloudTrail Bucket Access Logging", "description": "Ensures C…

---

## [How to pin elasticsearch version using “ec” Terraform provider?](https://discuss.elastic.co/t/how-to-pin-elasticsearch-version-using-ec-terraform-provider/307812)

<div class="topic-metadata">

**Author:** [@amruth](https://discuss.elastic.co/u/amruth)\
**Replies:** 1\
**Last updated:** [July 19, 2022, 6:41am UTC](https://discuss.elastic.co/t/how-to-pin-elasticsearch-version-using-ec-terraform-provider/307812 "2022-07-19T06:41:47Z")

</div>

Hello Everyone, how to pin elasticsearch version using “ec” Terraform provider? I am using the following data "ec\_stack" "latest" { version\_regex = "8.2.1" region = var.region } but it throws “Error: failed…

---

## [More like this query using an existing document, but I don't know its ID](https://discuss.elastic.co/t/more-like-this-query-using-an-existing-document-but-i-dont-know-its-id/309843)

<div class="topic-metadata">

**Author:** [@catmanjan](https://discuss.elastic.co/u/catmanjan)\
**Replies:** 4\
**Last updated:** [July 19, 2022, 5:29am UTC](https://discuss.elastic.co/t/more-like-this-query-using-an-existing-document-but-i-dont-know-its-id/309843 "2022-07-19T05:29:39Z")

</div>

I want to do a more like this query to return similar documents to a document that already exists in my index. I don't know the documents ID ahead of time, but I do know a term value that I can use to look it up (also, …

---

## [Indexes cannot be referenced after cluster configuration](https://discuss.elastic.co/t/indexes-cannot-be-referenced-after-cluster-configuration/309970)

<div class="topic-metadata">

**Author:** [@its-ogawa](https://discuss.elastic.co/u/its-ogawa)\
**Replies:** 12\
**Last updated:** [July 19, 2022, 5:15am UTC](https://discuss.elastic.co/t/indexes-cannot-be-referenced-after-cluster-configuration/309970 "2022-07-19T05:15:08Z")

</div>

I am creating an Elasticsearch cluster. I am deleting the Elasticsearch node configuration that was already running on a single node and configuring a cluster with two newly created Elasticsearch nodes. Here, the clust…

---

## [Elasticsearch complaining about space issues when there is plenty of space available](https://discuss.elastic.co/t/elasticsearch-complaining-about-space-issues-when-there-is-plenty-of-space-available/309844)

<div class="topic-metadata">

**Author:** [@pushshift](https://discuss.elastic.co/u/pushshift)\
**Replies:** 7\
**Last updated:** [July 19, 2022, 5:11am UTC](https://discuss.elastic.co/t/elasticsearch-complaining-about-space-issues-when-there-is-plenty-of-space-available/309844 "2022-07-19T05:11:09Z")

</div>

I received the following error this evening while indexing a large dataset: WARNING:root:{'create': {'\_index': 'fh\_hot\_en\_2021-05-05', '\_id': '1390039787566821378', 'status': 429, 'error': {'type': 'cluster\_block\_except…

---

## [Logstash stuck at stage pipelines running](https://discuss.elastic.co/t/logstash-stuck-at-stage-pipelines-running/309951)

<div class="topic-metadata">

**Author:** [@sridharnetha](https://discuss.elastic.co/u/sridharnetha)\
**Replies:** 4\
**Last updated:** [July 19, 2022, 4:46am UTC](https://discuss.elastic.co/t/logstash-stuck-at-stage-pipelines-running/309951 "2022-07-19T04:46:14Z")

</div>

I am trying to ingest a csv file to include data on the elasticsearch server on the existing index. The csv file contains whitespaces in header column names. Here is an example "MOBILE NO" should be renamed to "MOBILE\_N…

---

## [Checked Exception "reference to termsQuery is ambiguous \[ERROR\]"](https://discuss.elastic.co/t/checked-exception-reference-to-termsquery-is-ambiguous-error/309969)

<div class="topic-metadata">

**Author:** [@willowHB](https://discuss.elastic.co/u/willowHB)\
**Replies:** 0\
**Last updated:** [July 19, 2022, 3:17am UTC](https://discuss.elastic.co/t/checked-exception-reference-to-termsquery-is-ambiguous-error/309969 "2022-07-19T03:17:03Z")

</div>

version：elasticsearch-7.15.2.jar 1、I think this is an api method error.When you use “QueryBuilders.termsQuery("status", 3,4)” query, an error “reference to termsQuery is ambiguous \[ERROR\] both method termsQuery(java.…

---

## [Sort by time received instead of timestamp](https://discuss.elastic.co/t/sort-by-time-received-instead-of-timestamp/308992)

<div class="topic-metadata">

**Author:** [@MADxHAWK](https://discuss.elastic.co/u/MADxHAWK)\
**Replies:** 7\
**Last updated:** [July 19, 2022, 2:16am UTC](https://discuss.elastic.co/t/sort-by-time-received-instead-of-timestamp/308992 "2022-07-19T02:16:59Z")

</div>

Hello, im using ELK-Stack to search through Cisco logs received by filebeat from our loghost. the problem is, i only can sort the discover by Timestamp from Elasticsearch and not by the timestamp the message was receiv…

---

## [Check agent status with api](https://discuss.elastic.co/t/check-agent-status-with-api/309640)

<div class="topic-metadata">

**Author:** [@ericdb](https://discuss.elastic.co/u/ericdb)\
**Replies:** 0\
**Last updated:** [July 14, 2022, 12:00pm UTC](https://discuss.elastic.co/t/check-agent-status-with-api/309640 "2022-07-14T12:00:49Z")

</div>

Is it possible to get the status from fleet agents with api using the hostname? document says there is a request with agentID https://petstore.swagger.io/?url=https://raw.githubusercontent.com/elastic/kibana/master/x-p…

---

## [Is there a section in the documentation that breaks down all available subcommands for a command?](https://discuss.elastic.co/t/is-there-a-section-in-the-documentation-that-breaks-down-all-available-subcommands-for-a-command/309601)

<div class="topic-metadata">

**Author:** [@pushshift](https://discuss.elastic.co/u/pushshift)\
**Replies:** 1\
**Last updated:** [July 19, 2022, 2:08am UTC](https://discuss.elastic.co/t/is-there-a-section-in-the-documentation-that-breaks-down-all-available-subcommands-for-a-command/309601 "2022-07-19T02:08:00Z")

</div>

When you do: curl -XGET https://localhost:9200/\_cat/ You get a nice little directory of available subcommands beneath \_cat. However, when I try to do the same for other sections like "\_cluster", I get the following: c…

---

## [ElasticSearch-Service install is not working](https://discuss.elastic.co/t/elasticsearch-service-install-is-not-working/309676)

<div class="topic-metadata">

**Author:** [@Muhammad\_Umair\_Sheik](https://discuss.elastic.co/u/Muhammad_Umair_Sheik)\
**Replies:** 1\
**Last updated:** [July 19, 2022, 2:04am UTC](https://discuss.elastic.co/t/elasticsearch-service-install-is-not-working/309676 "2022-07-19T02:04:45Z")

</div>

I am not able to install elastic as a windows service when there is space in the path. Without space, it is working fine. In the past, I was using version 6 which was working perfectly fine with both options. I have att…

---

## [Trying to run all tests on my app yields "too many open files" error](https://discuss.elastic.co/t/trying-to-run-all-tests-on-my-app-yields-too-many-open-files-error/309759)

<div class="topic-metadata">

**Author:** [@juno](https://discuss.elastic.co/u/juno)\
**Replies:** 1\
**Last updated:** [July 19, 2022, 2:01am UTC](https://discuss.elastic.co/t/trying-to-run-all-tests-on-my-app-yields-too-many-open-files-error/309759 "2022-07-19T02:01:22Z")

</div>

I'm building a reasonably small web app in Clojure and trying to run all the tests in order to get code coverage, but if I try to run them all, I get "too many open files" errors from elasticsearch. I have already tried…

---

## [Possible to scroll call ES v. 1.7 - how? I get errors](https://discuss.elastic.co/t/possible-to-scroll-call-es-v-1-7-how-i-get-errors/309653)

<div class="topic-metadata">

**Author:** [@johand\_erst](https://discuss.elastic.co/u/johand_erst)\
**Replies:** 2\
**Last updated:** [July 19, 2022, 1:54am UTC](https://discuss.elastic.co/t/possible-to-scroll-call-es-v-1-7-how-i-get-errors/309653 "2022-07-19T01:54:12Z")

</div>

Can someone help me what to do to call ES v. 1.7 with \_scroll\_id, please? According to the documentation it should be possible. Currently, I get one of these errors trying to pass \_scroll\_id in the payload: I write in…

---

## [Logstash syncing from Mongodb to Elasticsearch - Null values in array data objects](https://discuss.elastic.co/t/logstash-syncing-from-mongodb-to-elasticsearch-null-values-in-array-data-objects/309965)

<div class="topic-metadata">

**Author:** [@bindu1](https://discuss.elastic.co/u/bindu1)\
**Replies:** 0\
**Last updated:** [July 19, 2022, 1:44am UTC](https://discuss.elastic.co/t/logstash-syncing-from-mongodb-to-elasticsearch-null-values-in-array-data-objects/309965 "2022-07-19T01:44:44Z")

</div>

Hello Community, I'm using logstash to sync data from Mongdb to Elasticsearch & Kibana using JDBC input plugin. But array data fields are being synced as NULL values in ES/Kibana. Below is logstash.conf: input { …

---

## [Resolve Indices API: Missing documentation for params \`allow\_no\_indices\`, \`ignore\_unavailable\` and target \`\_all\`](https://discuss.elastic.co/t/resolve-indices-api-missing-documentation-for-params-allow-no-indices-ignore-unavailable-and-target-all/309964)

<div class="topic-metadata">

**Author:** [@pavan02](https://discuss.elastic.co/u/pavan02)\
**Replies:** 0\
**Last updated:** [July 19, 2022, 1:38am UTC](https://discuss.elastic.co/t/resolve-indices-api-missing-documentation-for-params-allow-no-indices-ignore-unavailable-and-target-all/309964 "2022-07-19T01:38:11Z")

</div>

Resolve index API | Elasticsearch Guide \[8.3\] | Elastic documentation doesn't describe params allow\_no\_indices, ignore\_unavailable and \_all target. However, those params and target is actually working. Does resolve API …

---

## [Installing ELK...Stuck in Elasticsearch not able to get Token and username password on windows 10 pro10](https://discuss.elastic.co/t/installing-elk-stuck-in-elasticsearch-not-able-to-get-token-and-username-password-on-windows-10-pro10/309776)

<div class="topic-metadata">

**Author:** [@sarvesh\_singh](https://discuss.elastic.co/u/sarvesh_singh)\
**Replies:** 1\
**Last updated:** [July 19, 2022, 1:27am UTC](https://discuss.elastic.co/t/installing-elk-stuck-in-elasticsearch-not-able-to-get-token-and-username-password-on-windows-10-pro10/309776 "2022-07-19T01:27:39Z")

</div>

\[2022-07-16T04:10:17,949\]\[INFO \]\[o.e.g.GatewayService \] \[DESKTOP-MJL6HRR\] recovered \[1\] indices into cluster\_state \[2022-07-16T04:10:18,325\]\[ERROR\]\[o.e.i.g.GeoIpDownloader \] \[DESKTOP-MJL6HRR\] exception during geoip…

---

## [Logstash fillter](https://discuss.elastic.co/t/logstash-fillter/309846)

<div class="topic-metadata">

**Author:** [@Jathurshan\_Sumandira](https://discuss.elastic.co/u/Jathurshan_Sumandira)\
**Replies:** 0\
**Last updated:** [July 18, 2022, 6:16am UTC](https://discuss.elastic.co/t/logstash-fillter/309846 "2022-07-18T06:16:13Z")

</div>

Hi Team, We are using 2 filters. First one is to get the token and by getting the token we are going to call the next url with bearer token First http getting the response but second http method is not giving data ht…

[Previous page](https://discuss.elastic.co/tag/none.md?no_tags=true&page=580)

[Next page](https://discuss.elastic.co/tag/none.md?no_tags=true&page=582)
