# \#none

**URL:** https://discuss.elastic.co/tag/none.md?no_tags=true&page=600

[Latest](https://discuss.elastic.co/latest.md) · [Categories](https://discuss.elastic.co/categories.md) · [Tags](https://discuss.elastic.co/tags.md)

**Page:** 601

---

## [How to write remote hostname to output file with logstash](https://discuss.elastic.co/t/how-to-write-remote-hostname-to-output-file-with-logstash/308161)

<div class="topic-metadata">

**Author:** [@Yunus\_Dal](https://discuss.elastic.co/u/Yunus_Dal)\
**Replies:** 2\
**Last updated:** [June 25, 2022, 2:03pm UTC](https://discuss.elastic.co/t/how-to-write-remote-hostname-to-output-file-with-logstash/308161 "2022-06-25T14:03:32Z")

</div>

Hi, I have java application which is running at 2 instance and collect logs from these instances. I want to create output log file so far as remote hostname. my logstash config; input { tcp { codec =\> json …

---

## [XPOST Failing](https://discuss.elastic.co/t/xpost-failing/308153)

<div class="topic-metadata">

**Author:** [@chandramouli\_ravi](https://discuss.elastic.co/u/chandramouli_ravi)\
**Replies:** 5\
**Last updated:** [June 25, 2022, 2:50pm UTC](https://discuss.elastic.co/t/xpost-failing/308153 "2022-06-25T14:50:47Z")

</div>

Hi, I am running elasticsearch 8.2.3 from my laptop. Able to check health, create index but insert document is failing. Could you please help what's the problem here. C:\\Users\\ravich\>curl --insecure -H "Content-Type:…

---

## [Changelog for Elastic Agent Integrations](https://discuss.elastic.co/t/changelog-for-elastic-agent-integrations/308159)

<div class="topic-metadata">

**Author:** [@zx8086](https://discuss.elastic.co/u/zx8086)\
**Replies:** 0\
**Last updated:** [June 25, 2022, 9:47am UTC](https://discuss.elastic.co/t/changelog-for-elastic-agent-integrations/308159 "2022-06-25T09:47:25Z")

</div>

The assumptions seems to be that we upgrade these integrations without easy access to know what we are upgrading or what potentially could break and what has been fixed. We have changelogs for all other components in a s…

---

## [Python 无法通过ssh使用Elasticsearch类和远程服务器建立连接](https://discuss.elastic.co/t/python-ssh-elasticsearch/308157)

<div class="topic-metadata">

**Author:** [@qigemingzihaonana](https://discuss.elastic.co/u/qigemingzihaonana)\
**Replies:** 2\
**Last updated:** [June 25, 2022, 8:11am UTC](https://discuss.elastic.co/t/python-ssh-elasticsearch/308157 "2022-06-25T08:11:45Z")

</div>

elasticsearch.exceptions.ConnectionError: ConnectionError(\<urllib3.connection.HTTPConnection object at 0x000001B539AC6C10\>: Failed to establish a new connection: \[WinError 10061\] 由于目标计算机积极拒绝，无法连接。) caused by: NewConnecti…

---

## [How to take input from kafka avro consumer](https://discuss.elastic.co/t/how-to-take-input-from-kafka-avro-consumer/308150)

<div class="topic-metadata">

**Author:** [@saurabhlam](https://discuss.elastic.co/u/saurabhlam)\
**Replies:** 0\
**Last updated:** [June 25, 2022, 5:55am UTC](https://discuss.elastic.co/t/how-to-take-input-from-kafka-avro-consumer/308150 "2022-06-25T05:55:49Z")

</div>

Hi Currently I have defined kafka as input in logstash but I want to take input from kafka avro consumer (avro-console-consumer) . Below is my current config input { kafka { bootstrap\_servers =\> "kafka:9092" topics…

---

## [Set data view format in index template](https://discuss.elastic.co/t/set-data-view-format-in-index-template/307445)

<div class="topic-metadata">

**Author:** [@seanziee](https://discuss.elastic.co/u/seanziee)\
**Replies:** 10\
**Last updated:** [June 25, 2022, 1:40am UTC](https://discuss.elastic.co/t/set-data-view-format-in-index-template/307445 "2022-06-25T01:40:06Z")

</div>

Hi, I have multiple spaces that all reference the same index with an index pattern - metricbeat-\*./ Metricbeat comes with MANY \*.pct fields and I'd like to display them all as percentages rather than numbers. It would …

---

## [Num\_reduce\_phases in query response](https://discuss.elastic.co/t/num-reduce-phases-in-query-response/308145)

<div class="topic-metadata">

**Author:** [@Akshay\_Pawar](https://discuss.elastic.co/u/Akshay_Pawar)\
**Replies:** 0\
**Last updated:** [June 25, 2022, 12:43am UTC](https://discuss.elastic.co/t/num-reduce-phases-in-query-response/308145 "2022-06-25T00:43:24Z")

</div>

Hello, we are using Elasticsearch's version 7.5.1 and noticed that sometimes (not always) Elasticsearch returns "num\_reduced\_phases" in query response for aggregate queries. Is there any specific query/scenario which can…

---

## [Canvas Charts Limiting Results](https://discuss.elastic.co/t/canvas-charts-limiting-results/304591)

<div class="topic-metadata">

**Author:** [@Tim\_Mobley](https://discuss.elastic.co/u/Tim_Mobley)\
**Replies:** 4\
**Last updated:** [June 24, 2022, 9:01pm UTC](https://discuss.elastic.co/t/canvas-charts-limiting-results/304591 "2022-06-24T21:01:59Z")

</div>

I am using an Elasticsearch SQL query in a horizontal bar chart in Kibana. At the end of my query I have LIMIT ALL, which should return all results that match the WHERE statement. Discover shows 292,589 hits for the same…

---

## [How to implement Keep alive in logstash using JDBC input](https://discuss.elastic.co/t/how-to-implement-keep-alive-in-logstash-using-jdbc-input/308140)

<div class="topic-metadata">

**Author:** [@Oskr](https://discuss.elastic.co/u/Oskr)\
**Replies:** 0\
**Last updated:** [June 24, 2022, 7:30pm UTC](https://discuss.elastic.co/t/how-to-implement-keep-alive-in-logstash-using-jdbc-input/308140 "2022-06-24T19:30:26Z")

</div>

Hello Team, I have a question about a bug in my environment, I am using logstash to extract data from the oracle database, our logstash is running on AWS the sql takes 100 sec to run on average, but at some times of the…

---

## [Changing node roles in an already existing ES environment](https://discuss.elastic.co/t/changing-node-roles-in-an-already-existing-es-environment/307013)

<div class="topic-metadata">

**Author:** [@Carlos\_T](https://discuss.elastic.co/u/Carlos_T)\
**Replies:** 3\
**Last updated:** [June 24, 2022, 6:17pm UTC](https://discuss.elastic.co/t/changing-node-roles-in-an-already-existing-es-environment/307013 "2022-06-24T18:17:10Z")

</div>

Good morning everybody. As, due to my job, I will have to get a Production ES environment in the future, I decided to create a testing ES environment at home. This environment has three multi-role node. The three of th…

---

## [SNMP Input - Stop Table Polling at Specific Table OID](https://discuss.elastic.co/t/snmp-input-stop-table-polling-at-specific-table-oid/308134)

<div class="topic-metadata">

**Author:** [@bennrtc](https://discuss.elastic.co/u/bennrtc)\
**Replies:** 0\
**Last updated:** [June 24, 2022, 4:54pm UTC](https://discuss.elastic.co/t/snmp-input-stop-table-polling-at-specific-table-oid/308134 "2022-06-24T16:54:54Z")

</div>

I'm using Logstash to query a network device that has a large number of interfaces (nearly 1500). I'm interested in a variety of interface metrics that are stored in different tables. I only need the metrics from the f…

---

## [Elastic search service is getting stopped automatically version 7.12](https://discuss.elastic.co/t/elastic-search-service-is-getting-stopped-automatically-version-7-12/308132)

<div class="topic-metadata">

**Author:** [@Azhar\_Uddin1](https://discuss.elastic.co/u/Azhar_Uddin1)\
**Replies:** 0\
**Last updated:** [June 24, 2022, 4:10pm UTC](https://discuss.elastic.co/t/elastic-search-service-is-getting-stopped-automatically-version-7-12/308132 "2022-06-24T16:10:20Z")

</div>

I am getting a warning in the kibana service after that elastic service stopped automatically executing the below commands yarn es snapshot --oss yarn start --run-examples and also executes yarn start but in both ca…

---

## [How to add a 0 before a field, with a condicion?](https://discuss.elastic.co/t/how-to-add-a-0-before-a-field-with-a-condicion/308106)

<div class="topic-metadata">

**Author:** [@jvinacio](https://discuss.elastic.co/u/jvinacio)\
**Replies:** 1\
**Last updated:** [June 24, 2022, 3:52pm UTC](https://discuss.elastic.co/t/how-to-add-a-0-before-a-field-with-a-condicion/308106 "2022-06-24T15:52:34Z")

</div>

Hello! I have different docs with different hours from 0 to 23 like the following { "date" : "2022-06-23", "eventDate" : "2022", "StoreID" : 190, "hour" : 0, "PosID" : 12, "tempo" : 0.0 } { "date" : "2022-06-2…

---

## [Calculate a delta between two time slices](https://discuss.elastic.co/t/calculate-a-delta-between-two-time-slices/307411)

<div class="topic-metadata">

**Author:** [@Kohlman](https://discuss.elastic.co/u/Kohlman)\
**Replies:** 9\
**Last updated:** [June 24, 2022, 3:50pm UTC](https://discuss.elastic.co/t/calculate-a-delta-between-two-time-slices/307411 "2022-06-24T15:50:26Z")

</div>

Is there a visualization that can calculate a delta between to two most recent records or any two time slices for that matter. Specifically we have metricbeat data from SQL server. Many of the metrics we extract are cumu…

---

## [Logstash filter for filtering out specific words from message](https://discuss.elastic.co/t/logstash-filter-for-filtering-out-specific-words-from-message/307853)

<div class="topic-metadata">

**Author:** [@Muhammed\_Danish](https://discuss.elastic.co/u/Muhammed_Danish)\
**Replies:** 6\
**Last updated:** [June 24, 2022, 3:42pm UTC](https://discuss.elastic.co/t/logstash-filter-for-filtering-out-specific-words-from-message/307853 "2022-06-24T15:42:10Z")

</div>

Hello team, I am looking for a filter to filter out based on the words in a log message. For example, Log messages - This is a test message from server hosted in AWS and This is a test message coming from server hoste…

---

## [EFK stack performance with large data](https://discuss.elastic.co/t/efk-stack-performance-with-large-data/308101)

<div class="topic-metadata">

**Author:** [@Mohit.Sharma](https://discuss.elastic.co/u/Mohit.Sharma)\
**Replies:** 3\
**Last updated:** [June 24, 2022, 3:06pm UTC](https://discuss.elastic.co/t/efk-stack-performance-with-large-data/308101 "2022-06-24T15:06:10Z")

</div>

Hello Team, We are planning to store logs in ElasticSearch DB through Filebeat and then create dashboards on Kibana for graphical visualization(Lens, TSVB, Aggregations) using basic license. As we are expecting around 2…

---

## [Grok filter some entries have additional fields](https://discuss.elastic.co/t/grok-filter-some-entries-have-additional-fields/308092)

<div class="topic-metadata">

**Author:** [@tartaarsap](https://discuss.elastic.co/u/tartaarsap)\
**Replies:** 2\
**Last updated:** [June 24, 2022, 1:55pm UTC](https://discuss.elastic.co/t/grok-filter-some-entries-have-additional-fields/308092 "2022-06-24T13:55:46Z")

</div>

I have the following dataset: 1613766382 FILE %computerName% MACB \[4096\] c:/$MFTMirr 1613766382 FILE %computerName% MACB \[4096\] c:/$MFTMirr ($FILE\_NAME) I am trying to build a GROK filter to match on both lines. Howe…

---

## [How to run FS Crawler in background on Ubuntu 20.04](https://discuss.elastic.co/t/how-to-run-fs-crawler-in-background-on-ubuntu-20-04/308072)

<div class="topic-metadata">

**Author:** [@zxuz111](https://discuss.elastic.co/u/zxuz111)\
**Replies:** 2\
**Last updated:** [June 24, 2022, 1:42pm UTC](https://discuss.elastic.co/t/how-to-run-fs-crawler-in-background-on-ubuntu-20-04/308072 "2022-06-24T13:42:38Z")

</div>

I tried to run FS Crawler in background on Ubuntu 20.04, and I changed the last line of file bin/fscrawler as following: exec "nohup $JAVA" ${JAVA\_OPTS} -cp "$FS\_CLASSPATH" "fr.pilato.elasticsearch.crawler.fs.cli.FsCraw…

---

## [Backport of a Lucene bugfix (Lucene 9.0/ES 8.0)?](https://discuss.elastic.co/t/backport-of-a-lucene-bugfix-lucene-9-0-es-8-0/308093)

<div class="topic-metadata">

**Author:** [@mhugo](https://discuss.elastic.co/u/mhugo)\
**Replies:** 2\
**Last updated:** [June 24, 2022, 1:23pm UTC](https://discuss.elastic.co/t/backport-of-a-lucene-bugfix-lucene-9-0-es-8-0/308093 "2022-06-24T13:23:37Z")

</div>

Hi, We are migrating from ES 6.8 to ES 7.17 and encountered a bug during indexing for some complex shapes. It turns out the issue is a tessellation bug in Lucene that has been fixed in Lucene 9.0 (see \[LUCENE-9580\] Tess…

---

## [Why query ignores slop value?](https://discuss.elastic.co/t/why-query-ignores-slop-value/307953)

<div class="topic-metadata">

**Author:** [@asil](https://discuss.elastic.co/u/asil)\
**Replies:** 3\
**Last updated:** [June 24, 2022, 12:47pm UTC](https://discuss.elastic.co/t/why-query-ignores-slop-value/307953 "2022-06-24T12:47:59Z")

</div>

I'm using elastic search 7.6.2 I have index with the following mapping: "mappings": { "properties": { "content": {"type": "text"}, } } with 3 documents: Distri…

---

## [Logstash JSON File input](https://discuss.elastic.co/t/logstash-json-file-input/308108)

<div class="topic-metadata">

**Author:** [@priyankamondalhcl](https://discuss.elastic.co/u/priyankamondalhcl)\
**Replies:** 0\
**Last updated:** [June 24, 2022, 11:39am UTC](https://discuss.elastic.co/t/logstash-json-file-input/308108 "2022-06-24T11:39:47Z")

</div>

Hi Team, Please help me to set logstash config from nested json input file. My json file look like below: \[ { "billing\_account\_id": "loma", "InvoiceMonth": "123456", "credits": \[ { "name": "abc", "amount": ,0.0…

---

## [Unable to multi\_match in php library](https://discuss.elastic.co/t/unable-to-multi-match-in-php-library/308107)

<div class="topic-metadata">

**Author:** [@Jeroen2](https://discuss.elastic.co/u/Jeroen2)\
**Replies:** 0\
**Last updated:** [June 24, 2022, 11:32am UTC](https://discuss.elastic.co/t/unable-to-multi-match-in-php-library/308107 "2022-06-24T11:32:07Z")

</div>

I'm trying to use a filter to search multiple fields and query between dates. The PHP looks like this: $params = \[ 'index' =\> $this-\>index . '\*', 'size' =\> self::HITS\_SIZE, 'from' =\> …

---

## [Logstash pipeline currently forwarding logs to elasticsearch](https://discuss.elastic.co/t/logstash-pipeline-currently-forwarding-logs-to-elasticsearch/307197)

<div class="topic-metadata">

**Author:** [@lhmzhou](https://discuss.elastic.co/u/lhmzhou)\
**Replies:** 5\
**Last updated:** [June 24, 2022, 11:28am UTC](https://discuss.elastic.co/t/logstash-pipeline-currently-forwarding-logs-to-elasticsearch/307197 "2022-06-24T11:28:50Z")

</div>

Hi, Currently, I have a logstash pipeline that is forwarding logs to Elasticsearch. I am planning to send logfiles to S3 as a batch using the aws s3 cli. What are some drawbacks to this approach? Is it possible to accou…

---

## [Disable incremental searching on Kibana dashboard visualize](https://discuss.elastic.co/t/disable-incremental-searching-on-kibana-dashboard-visualize/308089)

<div class="topic-metadata">

**Author:** [@rogerlee](https://discuss.elastic.co/u/rogerlee)\
**Replies:** 1\
**Last updated:** [June 24, 2022, 11:04am UTC](https://discuss.elastic.co/t/disable-incremental-searching-on-kibana-dashboard-visualize/308089 "2022-06-24T11:04:31Z")

</div>

Hi Experts, I am creating a dashboard for our customer. I found if we click a visualize, a filtering will be triggered automatically for all dashboards. Can I disable the click to filtering feature on visualize? Because…

---

## [Mutate - Geopoint - Copy Field](https://discuss.elastic.co/t/mutate-geopoint-copy-field/308095)

<div class="topic-metadata">

**Author:** [@shubham184](https://discuss.elastic.co/u/shubham184)\
**Replies:** 0\
**Last updated:** [June 24, 2022, 9:37am UTC](https://discuss.elastic.co/t/mutate-geopoint-copy-field/308095 "2022-06-24T09:37:21Z")

</div>

I need to convert 2 Fields (doc.geoLat and doc.geoLong) to geopoint datatype. I tried the following but it dosen't work Could you please show me where I might be making a mistake if \[type\] == \\"xxxxx\\" { …

---

## [Need-Help-On-elasticsearch in complex scenario](https://discuss.elastic.co/t/need-help-on-elasticsearch-in-complex-scenario/308074)

<div class="topic-metadata">

**Author:** [@yeziblo](https://discuss.elastic.co/u/yeziblo)\
**Replies:** 2\
**Last updated:** [June 24, 2022, 8:54am UTC](https://discuss.elastic.co/t/need-help-on-elasticsearch-in-complex-scenario/308074 "2022-06-24T08:54:48Z")

</div>

Hi team, I need your help with a very complex scenario. We have a user management system, which has a user index, which stores various attributes of user, and a user action log index, which records what the user has don…

---

## [Is there away to get a random word/words from a document?](https://discuss.elastic.co/t/is-there-away-to-get-a-random-word-words-from-a-document/307470)

<div class="topic-metadata">

**Author:** [@Tasdiq\_Shaikh](https://discuss.elastic.co/u/Tasdiq_Shaikh)\
**Replies:** 3\
**Last updated:** [June 24, 2022, 8:37am UTC](https://discuss.elastic.co/t/is-there-away-to-get-a-random-word-words-from-a-document/307470 "2022-06-24T08:37:27Z")

</div>

I want to display some random words on the screen which are present in the document. I'm using Elasticsearch 7.12.

---

## [Elastic Stack 7.17.4 and 8.2.1 Security Update](https://discuss.elastic.co/t/elastic-stack-7-17-4-and-8-2-1-security-update/305530)

<div class="topic-metadata">

**Author:** [@Levine](https://discuss.elastic.co/u/Levine)\
**Replies:** 0\
**Last updated:** [May 24, 2022, 4:55pm UTC](https://discuss.elastic.co/t/elastic-stack-7-17-4-and-8-2-1-security-update/305530 "2022-05-24T16:55:27Z")

</div>

Elastic Stack update for CVE-2022-21449 Java vulnerability in Elliptic Curve Digital Signature Algorithm (ECDSA) (ESA-2022-06) A vulnerability (CVE-2022-21449) affecting the implementation of Elliptic Curve Digital Sign…

---

## [Elastic Search Index Refresh Interval elastic.yaml file in Kubernetes](https://discuss.elastic.co/t/elastic-search-index-refresh-interval-elastic-yaml-file-in-kubernetes/308041)

<div class="topic-metadata">

**Author:** [@krishnav1](https://discuss.elastic.co/u/krishnav1)\
**Replies:** 1\
**Last updated:** [June 24, 2022, 7:58am UTC](https://discuss.elastic.co/t/elastic-search-index-refresh-interval-elastic-yaml-file-in-kubernetes/308041 "2022-06-24T07:58:43Z")

</div>

I am new to Elasticsearch. I have a 3 data node and 3 master node elastic cluster deployed in Kubernetes. It was working well until recently there is a large intake of data. Now, I am in a stage where I need to apply ind…

---

## [Parse json in the filed message](https://discuss.elastic.co/t/parse-json-in-the-filed-message/308079)

<div class="topic-metadata">

**Author:** [@Rustam\_Kulnazarov](https://discuss.elastic.co/u/Rustam_Kulnazarov)\
**Replies:** 0\
**Last updated:** [June 24, 2022, 6:44am UTC](https://discuss.elastic.co/t/parse-json-in-the-filed-message/308079 "2022-06-24T06:44:24Z")

</div>

Hello everyone! Tell me please, how can I parse json in the field message, if the message has: 2022-06-24 12:35:53 # {json structure}\\n text text\\n text

[Previous page](https://discuss.elastic.co/tag/none.md?no_tags=true&page=599)

[Next page](https://discuss.elastic.co/tag/none.md?no_tags=true&page=601)
