# \#none

**URL:** https://discuss.elastic.co/tag/none.md?no_tags=true&page=584

[Latest](https://discuss.elastic.co/latest.md) · [Categories](https://discuss.elastic.co/categories.md) · [Tags](https://discuss.elastic.co/tags.md)

**Page:** 585

---

## [Logstash logfile manipulation](https://discuss.elastic.co/t/logstash-logfile-manipulation/309513)

<div class="topic-metadata">

**Author:** [@hiteshadabala](https://discuss.elastic.co/u/hiteshadabala)\
**Replies:** 1\
**Last updated:** [July 15, 2022, 7:09am UTC](https://discuss.elastic.co/t/logstash-logfile-manipulation/309513 "2022-07-15T07:09:16Z")

</div>

one log file is this way line1 line2 line3 When givenn as input to logstash with grok match "message":".\*$", the log file is entered into ES as "message":"line1\\nline2\\nline3" Each \\n is considered new line and can s…

---

## [Assistance with Grok and regex](https://discuss.elastic.co/t/assistance-with-grok-and-regex/309600)

<div class="topic-metadata">

**Author:** [@JeremyP](https://discuss.elastic.co/u/JeremyP)\
**Replies:** 2\
**Last updated:** [July 15, 2022, 7:00am UTC](https://discuss.elastic.co/t/assistance-with-grok-and-regex/309600 "2022-07-15T07:00:18Z")

</div>

Hello, I'm attempting to pull the name of a software package from a CPE from NIST. This is my sample data: cpe:2.3:a:libexpat\_project:libexpat:\*:\*:\*:\*:\*:\*:\*:\* With regular regex the following expression matches the st…

---

## [Get distinct values from "text field" without remapping](https://discuss.elastic.co/t/get-distinct-values-from-text-field-without-remapping/309694)

<div class="topic-metadata">

**Author:** [@lwwalker](https://discuss.elastic.co/u/lwwalker)\
**Replies:** 5\
**Last updated:** [July 15, 2022, 6:23am UTC](https://discuss.elastic.co/t/get-distinct-values-from-text-field-without-remapping/309694 "2022-07-15T06:23:01Z")

</div>

I'm querying ~350 TB of documents. Re-indexing is not an option. Performance, within reason, is not a concern. my documents have a field s3\_filename {"type": "text"}. It doesn't have any subfields. Setting fielddata:…

---

## [ECK Fleet TLS Disabled NOT Working](https://discuss.elastic.co/t/eck-fleet-tls-disabled-not-working/309706)

<div class="topic-metadata">

**Author:** [@aung.mm](https://discuss.elastic.co/u/aung.mm)\
**Replies:** 0\
**Last updated:** [July 15, 2022, 6:10am UTC](https://discuss.elastic.co/t/eck-fleet-tls-disabled-not-working/309706 "2022-07-15T06:10:41Z")

</div>

I would like to disable TLS in the fleet server that I deployed with eck. According to documentation, I should be able to disable with "http" configuration. But it is not working at all. Please see the following configu…

---

## [Version consistency of Elastic products](https://discuss.elastic.co/t/version-consistency-of-elastic-products/309620)

<div class="topic-metadata">

**Author:** [@its-ogawa](https://discuss.elastic.co/u/its-ogawa)\
**Replies:** 3\
**Last updated:** [July 15, 2022, 6:03am UTC](https://discuss.elastic.co/t/version-consistency-of-elastic-products/309620 "2022-07-15T06:03:02Z")

</div>

I am currently attempting to configure an Elasticsearch cluster. At this time I found the following article According to this article, it is not possible to configure a cluster between different versions of Elasticsea…

---

## [Elastic-agent loading default Dashboards](https://discuss.elastic.co/t/elastic-agent-loading-default-dashboards/309556)

<div class="topic-metadata">

**Author:** [@Muhammed\_Ashique](https://discuss.elastic.co/u/Muhammed_Ashique)\
**Replies:** 5\
**Last updated:** [July 15, 2022, 5:50am UTC](https://discuss.elastic.co/t/elastic-agent-loading-default-dashboards/309556 "2022-07-15T05:50:36Z")

</div>

I am upgrading beats to elastic-agents for shipping the logs. How can i load default dashboards using elastic beats. what are the communication port i need to enable to achieve this requirements

---

## [Cannot change omitNorms=false to inconsistent omitNorms=true](https://discuss.elastic.co/t/cannot-change-omitnorms-false-to-inconsistent-omitnorms-true/309361)

<div class="topic-metadata">

**Author:** [@Johnny\_Yang](https://discuss.elastic.co/u/Johnny_Yang)\
**Replies:** 3\
**Last updated:** [July 15, 2022, 1:48am UTC](https://discuss.elastic.co/t/cannot-change-omitnorms-false-to-inconsistent-omitnorms-true/309361 "2022-07-15T01:48:26Z")

</div>

I recently used the update\_mapping API to set one of the fields in my index to "norms:false", but then when I try to save new documents to it, it gives error: "{"error":{"root\_cause":\[{"type":"illegal\_argument\_exception"…

---

## [Master not discovered exception](https://discuss.elastic.co/t/master-not-discovered-exception/309677)

<div class="topic-metadata">

**Author:** [@NadyLeez123](https://discuss.elastic.co/u/NadyLeez123)\
**Replies:** 1\
**Last updated:** [July 15, 2022, 1:36am UTC](https://discuss.elastic.co/t/master-not-discovered-exception/309677 "2022-07-15T01:36:57Z")

</div>

We have an elasticsearch cluster of 2 masters et 6 data nodes since 2 years. Yesterday, requests became very slow, we started experiencing a time out in elasticsearch and kibana. We then discovered this on one of the tw…

---

## [Trying to analyze data but getting wrong data format from log what are the options its big data](https://discuss.elastic.co/t/trying-to-analyze-data-but-getting-wrong-data-format-from-log-what-are-the-options-its-big-data/309376)

<div class="topic-metadata">

**Author:** [@Gaming\_zone](https://discuss.elastic.co/u/Gaming_zone)\
**Replies:** 2\
**Last updated:** [July 15, 2022, 1:27am UTC](https://discuss.elastic.co/t/trying-to-analyze-data-but-getting-wrong-data-format-from-log-what-are-the-options-its-big-data/309376 "2022-07-15T01:27:17Z")

</div>

I have to analyze the given kind of data but the data format is not n json what is the problem and how i might change it. this is the dummy json and i have to analyze data in original {"\_index": "dummy\_elk","\_id": "dum…

---

## [Kibana alerting mechanism](https://discuss.elastic.co/t/kibana-alerting-mechanism/309414)

<div class="topic-metadata">

**Author:** [@Jathurshan\_Sumandira](https://discuss.elastic.co/u/Jathurshan_Sumandira)\
**Replies:** 1\
**Last updated:** [July 15, 2022, 12:27am UTC](https://discuss.elastic.co/t/kibana-alerting-mechanism/309414 "2022-07-15T00:27:02Z")

</div>

Hi Team, I am using Kibana alert rules and I used Elasticsearch query type. This query is scheduled to run every 1 minute. I have 20 alert rules with Elasticsearch query types. I need to know that, is it possible to co…

---

## [Exiting: fail to create the Kibana loader: Error creating Kibana client: Error creating Kibana client: fail to get the Kibana version: HTTP GET request ls: fail to execute the HTTP GET request: Get http://localhost:5601/api/status: dial tcp localhost:5601](https://discuss.elastic.co/t/exiting-fail-to-create-the-kibana-loader-error-creating-kibana-client-error-creating-kibana-client-fail-to-get-the-kibana-version-http-get-request-ls-fail-to-execute-the-http-get-request-get-http-localhost-5601-api-status-dial-tcp-localhost-5601/309310)

<div class="topic-metadata">

**Author:** [@Jass](https://discuss.elastic.co/u/Jass)\
**Replies:** 1\
**Last updated:** [July 14, 2022, 11:48pm UTC](https://discuss.elastic.co/t/exiting-fail-to-create-the-kibana-loader-error-creating-kibana-client-error-creating-kibana-client-fail-to-get-the-kibana-version-http-get-request-ls-fail-to-execute-the-http-get-request-get-http-localhost-5601-api-status-dial-tcp-localhost-5601/309310 "2022-07-14T23:48:11Z")

</div>

Hello, Currently I am working on Elasticsearch, filebeat and Kibana. I do have a problem with Kibana. When I execute the commande "sudo filebeat setup" , I got this kind of message error : Loaded index template Loadin…

---

## [View Specific Index-pattern data in a specific kibana space](https://discuss.elastic.co/t/view-specific-index-pattern-data-in-a-specific-kibana-space/309299)

<div class="topic-metadata">

**Author:** [@Saad\_Ansari](https://discuss.elastic.co/u/Saad_Ansari)\
**Replies:** 1\
**Last updated:** [July 14, 2022, 11:41pm UTC](https://discuss.elastic.co/t/view-specific-index-pattern-data-in-a-specific-kibana-space/309299 "2022-07-14T23:41:15Z")

</div>

Hi Team, I have a single elastic-cloud managed cluster, all my app env's (prod/stage/dev/etc...) are streaming data to this single cluster. Now to separate these diff env data, I've created different agent policies with…

---

## [Set Limit for Date Filter in Elastic cluster](https://discuss.elastic.co/t/set-limit-for-date-filter-in-elastic-cluster/309247)

<div class="topic-metadata">

**Author:** [@lstoneir](https://discuss.elastic.co/u/lstoneir)\
**Replies:** 2\
**Last updated:** [July 14, 2022, 11:28pm UTC](https://discuss.elastic.co/t/set-limit-for-date-filter-in-elastic-cluster/309247 "2022-07-14T23:28:17Z")

</div>

Hi I have a general question! I have a elastic with a lot of docs in index! I want to set threshold on datetime filter and not allow users to execute heavy queries on cluster. for example i set datetime\_max\_filter = …

---

## [Sort script input needed](https://discuss.elastic.co/t/sort-script-input-needed/309527)

<div class="topic-metadata">

**Author:** [@ansamHox](https://discuss.elastic.co/u/ansamHox)\
**Replies:** 8\
**Last updated:** [July 14, 2022, 10:40pm UTC](https://discuss.elastic.co/t/sort-script-input-needed/309527 "2022-07-14T22:40:15Z")

</div>

I have a dataset like this (sometimes Source field does not exist): Id Source Sender -------------------------------------------------------------------- 1 …

---

## [How to get and post kibana spaces by api call?](https://discuss.elastic.co/t/how-to-get-and-post-kibana-spaces-by-api-call/308684)

<div class="topic-metadata">

**Author:** [@Gabriel\_Vasconcelos](https://discuss.elastic.co/u/Gabriel_Vasconcelos)\
**Replies:** 2\
**Last updated:** [July 14, 2022, 9:40pm UTC](https://discuss.elastic.co/t/how-to-get-and-post-kibana-spaces-by-api-call/308684 "2022-07-14T21:40:21Z")

</div>

Hello everyone, I would like to know how I can return kibana spaces via api, I tried from the documentation: Kibana spaces APIs | Kibana Guide \[8.3\] | Elastic, but when I give a get , I don't get the default spaces and s…

---

## [KIbana not showing kube-state-metrics](https://discuss.elastic.co/t/kibana-not-showing-kube-state-metrics/309689)

<div class="topic-metadata">

**Author:** [@Lucas\_Roberto](https://discuss.elastic.co/u/Lucas_Roberto)\
**Replies:** 0\
**Last updated:** [July 14, 2022, 9:09pm UTC](https://discuss.elastic.co/t/kibana-not-showing-kube-state-metrics/309689 "2022-07-14T21:09:04Z")

</div>

Hello, everyone. I'm deploying our monitoring system, with ES, Metricbeat and Kibana. We have a GCP cluster, with some pods to monitor the metrics. I followed the guide provided by Kibana's dashboard Kubernetes metrics,…

---

## [Multiple Stomp servers](https://discuss.elastic.co/t/multiple-stomp-servers/309686)

<div class="topic-metadata">

**Author:** [@luv4diamonds](https://discuss.elastic.co/u/luv4diamonds)\
**Replies:** 2\
**Last updated:** [July 14, 2022, 8:03pm UTC](https://discuss.elastic.co/t/multiple-stomp-servers/309686 "2022-07-14T20:03:16Z")

</div>

Hi, I am trying to configure Stomp input with 3 servers but this doesn't appear to work in ES 7.17.3. I have tried host =\> "host1", "host2", "host3" which does not work. Does anyone know how to configure this or is it…

---

## [Remove Spaces and text between these \<\> brackets](https://discuss.elastic.co/t/remove-spaces-and-text-between-these-brackets/309683)

<div class="topic-metadata">

**Author:** [@errupeshmca](https://discuss.elastic.co/u/errupeshmca)\
**Replies:** 0\
**Last updated:** [July 14, 2022, 7:52pm UTC](https://discuss.elastic.co/t/remove-spaces-and-text-between-these-brackets/309683 "2022-07-14T19:52:11Z")

</div>

Hi , I am new to the elasticsearch i have to filter the logs removing larges spaces and less than, greater than signs around the text, \<NHTR\> \<HNANE: main \> \<INFO \> \<GHMonitorDaemon …

---

## [Two strings with one grok](https://discuss.elastic.co/t/two-strings-with-one-grok/309646)

<div class="topic-metadata">

**Author:** [@PJss](https://discuss.elastic.co/u/PJss)\
**Replies:** 3\
**Last updated:** [July 14, 2022, 6:09pm UTC](https://discuss.elastic.co/t/two-strings-with-one-grok/309646 "2022-07-14T18:09:32Z")

</div>

Hello, please help to read this two strings with one grok rule first: mgmgmg : TTY=unknown ; PWD=/usr/local/gtail/basecomps/deploy/cache ; USER=root ; ENV=HEALTHCHECK=no BACKUP=no ; COMMAND=/usr/bin/dpkg --install goser…

---

## [Logstash Ruby filter - init not working](https://discuss.elastic.co/t/logstash-ruby-filter-init-not-working/309670)

<div class="topic-metadata">

**Author:** [@Hichem](https://discuss.elastic.co/u/Hichem)\
**Replies:** 1\
**Last updated:** [July 14, 2022, 6:01pm UTC](https://discuss.elastic.co/t/logstash-ruby-filter-init-not-working/309670 "2022-07-14T18:01:16Z")

</div>

I'm trying to initialize a variable in a ruby filter. It works properly with the code tag, but not when using a ruby file. Here is my code: pipeline.conf ruby { init =\> "@val = 5 " path =\> "script.rb" }…

---

## [A question about the Profile API](https://discuss.elastic.co/t/a-question-about-the-profile-api/309680)

<div class="topic-metadata">

**Author:** [@kpachar](https://discuss.elastic.co/u/kpachar)\
**Replies:** 0\
**Last updated:** [July 14, 2022, 5:55pm UTC](https://discuss.elastic.co/t/a-question-about-the-profile-api/309680 "2022-07-14T17:55:31Z")

</div>

Hello, I am trying to debug some intermittent slowness in my cluster. I send this simple term query, to a specific shard, which is local to the node. I also enabled the profile option, so that the profile output is ava…

---

## [Problem with date filter](https://discuss.elastic.co/t/problem-with-date-filter/309642)

<div class="topic-metadata">

**Author:** [@Thuunder7](https://discuss.elastic.co/u/Thuunder7)\
**Replies:** 11\
**Last updated:** [July 14, 2022, 5:26pm UTC](https://discuss.elastic.co/t/problem-with-date-filter/309642 "2022-07-14T17:26:24Z")

</div>

Hello, I am trying to parse the following message (e.g): 2022-07-14T13:06:16 Using the dissect filter correctly: dissect { mapping =\> { "\[message\]" =\> "%{\[my\]\[date\]}" …

---

## [Index management yellow](https://discuss.elastic.co/t/index-management-yellow/309576)

<div class="topic-metadata">

**Author:** [@Khadija\_BOUDINAR1](https://discuss.elastic.co/u/Khadija_BOUDINAR1)\
**Replies:** 4\
**Last updated:** [July 14, 2022, 5:17pm UTC](https://discuss.elastic.co/t/index-management-yellow/309576 "2022-07-14T17:17:15Z")

</div>

hi all, when i create a new index some take yellow health and some take green health what's the probleme in ?

---

## [Value ( 1.0. ) ( Notice the last dot after 0 ) getting stored as type Date in Elastic search](https://discuss.elastic.co/t/value-1-0-notice-the-last-dot-after-0-getting-stored-as-type-date-in-elastic-search/309411)

<div class="topic-metadata">

**Author:** [@ajitw](https://discuss.elastic.co/u/ajitw)\
**Replies:** 4\
**Last updated:** [July 14, 2022, 3:43pm UTC](https://discuss.elastic.co/t/value-1-0-notice-the-last-dot-after-0-getting-stored-as-type-date-in-elastic-search/309411 "2022-07-14T15:43:06Z")

</div>

We store logs data in Elasticsearch we have added functionality which makes the JSON logs stored in Elasticsearch as seperate fields. In one of the logs appVersion value was coming as - ( 1.0. ) - Notice the last dot a…

---

## [Cloudwatch Output from logstash](https://discuss.elastic.co/t/cloudwatch-output-from-logstash/309661)

<div class="topic-metadata">

**Author:** [@jlbai](https://discuss.elastic.co/u/jlbai)\
**Replies:** 0\
**Last updated:** [July 14, 2022, 2:56pm UTC](https://discuss.elastic.co/t/cloudwatch-output-from-logstash/309661 "2022-07-14T14:56:14Z")

</div>

I am looking to out to cloudwatch from logstash. I can not use an IAM user access and secret access key to connect to cloud watch Does anyone have experience or solution so I can talk to my aws cloudwatch input { udp { …

---

## [Haystack EU - The Search Relevance Conference - Call for Presentations](https://discuss.elastic.co/t/haystack-eu-the-search-relevance-conference-call-for-presentations/309658)

<div class="topic-metadata">

**Author:** [@flaxsearch](https://discuss.elastic.co/u/flaxsearch)\
**Replies:** 0\
**Last updated:** [July 14, 2022, 2:10pm UTC](https://discuss.elastic.co/t/haystack-eu-the-search-relevance-conference-call-for-presentations/309658 "2022-07-14T14:10:32Z")

</div>

Haystack is the conference for improving search relevance. If you're like us, you work to understand the shiny new tools or dense academic papers out there that promise the moon. Then you puzzle how to apply those insigh…

---

## [Elastic APM log4j2 EcsLayout](https://discuss.elastic.co/t/elastic-apm-log4j2-ecslayout/309649)

<div class="topic-metadata">

**Author:** [@tbglazer](https://discuss.elastic.co/u/tbglazer)\
**Replies:** 0\
**Last updated:** [July 14, 2022, 1:04pm UTC](https://discuss.elastic.co/t/elastic-apm-log4j2-ecslayout/309649 "2022-07-14T13:04:52Z")

</div>

We want to log messages using the EcsLayout in a Java app and when we add a KeyValuePair like where branch is a log4j is a field in \[org\](eclipse-javadoc:%E2%98%82=MatafC the Ecs layout builds incorrectly in the log r…

---

## [Nodes didn't discovery in ElasticSearch Cluster](https://discuss.elastic.co/t/nodes-didnt-discovery-in-elasticsearch-cluster/309560)

<div class="topic-metadata">

**Author:** [@SilasMuniz1](https://discuss.elastic.co/u/SilasMuniz1)\
**Replies:** 5\
**Last updated:** [July 14, 2022, 12:36pm UTC](https://discuss.elastic.co/t/nodes-didnt-discovery-in-elasticsearch-cluster/309560 "2022-07-14T12:36:46Z")

</div>

Hello, I am setting up one cluster with two nodes to elasticsearch. I am using virtualbox with ubuntu 22.04 image. I already configurated all nodes with these elasticsearch.yml: Node1: root@osboxes:/var/log/elasticse…

---

## [I have installed File beat 7.17.3 version on a Windows server, it is not getting the logs to the ELK Server](https://discuss.elastic.co/t/i-have-installed-file-beat-7-17-3-version-on-a-windows-server-it-is-not-getting-the-logs-to-the-elk-server/309075)

<div class="topic-metadata">

**Author:** [@AKAM14](https://discuss.elastic.co/u/AKAM14)\
**Replies:** 1\
**Last updated:** [July 14, 2022, 11:55am UTC](https://discuss.elastic.co/t/i-have-installed-file-beat-7-17-3-version-on-a-windows-server-it-is-not-getting-the-logs-to-the-elk-server/309075 "2022-07-14T11:55:12Z")

</div>

We re trying to send data from Filebeat to ELastic search directly .. but it is not going .. it says it needs kibana connections and dashboards not loaded ###################### Filebeat Configuration Example ##########…

---

## [Java 17 support for elasticsearch 6.6.0](https://discuss.elastic.co/t/java-17-support-for-elasticsearch-6-6-0/309605)

<div class="topic-metadata">

**Author:** [@gilh](https://discuss.elastic.co/u/gilh)\
**Replies:** 3\
**Last updated:** [July 14, 2022, 11:44am UTC](https://discuss.elastic.co/t/java-17-support-for-elasticsearch-6-6-0/309605 "2022-07-14T11:44:35Z")

</div>

Hi. I'm using elasticsearch version 6.6.0. Now I want to upgrade from java 8 to java 17. Can I expect this version to work fine with java 17? Or I would need to upgrade my elasticsearch client before moving to java 17? …

[Previous page](https://discuss.elastic.co/tag/none.md?no_tags=true&page=583)

[Next page](https://discuss.elastic.co/tag/none.md?no_tags=true&page=585)
