# \#none

**URL:** https://discuss.elastic.co/tag/none.md?no_tags=true&page=609

[Latest](https://discuss.elastic.co/latest.md) · [Categories](https://discuss.elastic.co/categories.md) · [Tags](https://discuss.elastic.co/tags.md)

**Page:** 610

---

## [GC issues causing high CPU](https://discuss.elastic.co/t/gc-issues-causing-high-cpu/307341)

<div class="topic-metadata">

**Author:** [@Shubham\_Singh](https://discuss.elastic.co/u/Shubham_Singh)\
**Replies:** 8\
**Last updated:** [June 16, 2022, 7:46am UTC](https://discuss.elastic.co/t/gc-issues-causing-high-cpu/307341 "2022-06-16T07:46:26Z")

</div>

Hello, I have setup a 2 node cluster for our production environment. We are using t3a.xlarge instance type. APM and log analysis is currently enabled for our cluster, observing high CPU frequently. Upon checking the log…

---

## [Platinum on-prem](https://discuss.elastic.co/t/platinum-on-prem/307351)

<div class="topic-metadata">

**Author:** [@samiujan](https://discuss.elastic.co/u/samiujan)\
**Replies:** 1\
**Last updated:** [June 16, 2022, 7:17am UTC](https://discuss.elastic.co/t/platinum-on-prem/307351 "2022-06-16T07:17:29Z")

</div>

I have contacted ES directly too but haven't heard back What's the pricing for the platinum license if I want to deploy my system on-prem? Thanks

---

## [How to add multiple fields in cardinality](https://discuss.elastic.co/t/how-to-add-multiple-fields-in-cardinality/307274)

<div class="topic-metadata">

**Author:** [@NAVEEN\_MEENA](https://discuss.elastic.co/u/NAVEEN_MEENA)\
**Replies:** 1\
**Last updated:** [June 16, 2022, 7:16am UTC](https://discuss.elastic.co/t/how-to-add-multiple-fields-in-cardinality/307274 "2022-06-16T07:16:30Z")

</div>

Hi all , I have created a table visualization in kibana 7.7 and there are 2 metrics of unique count fields present in the table and one bucket .Let's say time1 and time2 are 2 metrics of unique count and let's say the n…

---

## [Log stash pipeline not connecting to Elasticsearch](https://discuss.elastic.co/t/log-stash-pipeline-not-connecting-to-elasticsearch/307259)

<div class="topic-metadata">

**Author:** [@harijld](https://discuss.elastic.co/u/harijld)\
**Replies:** 3\
**Last updated:** [June 16, 2022, 7:07am UTC](https://discuss.elastic.co/t/log-stash-pipeline-not-connecting-to-elasticsearch/307259 "2022-06-16T07:07:49Z")

</div>

HI, I am getting below error while establishing connection from logstash pipeline to Elasticsearch. I am able to do the telnet from logstash server to Elasticsearch server but not able to establish the connection. logs…

---

## [Log stash not connecting to Elasticsearch](https://discuss.elastic.co/t/log-stash-not-connecting-to-elasticsearch/307263)

<div class="topic-metadata">

**Author:** [@harijld](https://discuss.elastic.co/u/harijld)\
**Replies:** 4\
**Last updated:** [June 16, 2022, 7:01am UTC](https://discuss.elastic.co/t/log-stash-not-connecting-to-elasticsearch/307263 "2022-06-16T07:01:36Z")

</div>

Hi Team, my log stash is unable to connect Elastic search. Telnet is working fine but log stash pipeline is not able to create connection with Elasticsearch. input { stdin{} } output { elasticsearch { hosts =\> …

---

## [Multiple \_id for same document or document alias](https://discuss.elastic.co/t/multiple-id-for-same-document-or-document-alias/307296)

<div class="topic-metadata">

**Author:** [@nerd2000](https://discuss.elastic.co/u/nerd2000)\
**Replies:** 2\
**Last updated:** [June 16, 2022, 7:00am UTC](https://discuss.elastic.co/t/multiple-id-for-same-document-or-document-alias/307296 "2022-06-16T07:00:23Z")

</div>

Is it possible to have multiple ids for the same document or have a alias to a document? Already found this topic but a long time ago, checking if it was implemented meanwhile. The use case: I have a sql database with…

---

## [Which is better between Scroll and Search\_After when extract lots of document to other database?](https://discuss.elastic.co/t/which-is-better-between-scroll-and-search-after-when-extract-lots-of-document-to-other-database/307349)

<div class="topic-metadata">

**Author:** [@Haocheng\_Wang](https://discuss.elastic.co/u/Haocheng_Wang)\
**Replies:** 0\
**Last updated:** [June 16, 2022, 6:55am UTC](https://discuss.elastic.co/t/which-is-better-between-scroll-and-search-after-when-extract-lots-of-document-to-other-database/307349 "2022-06-16T06:55:19Z")

</div>

Hi community! I note that since 7.0, scroll is deprecated in deep pagination from the document But the document also said : the scroll API can be used to retrieve large numbers of results (or even all results) from a s…

---

## [Create drop-down control to select index pattern](https://discuss.elastic.co/t/create-drop-down-control-to-select-index-pattern/307331)

<div class="topic-metadata">

**Author:** [@eddieyee](https://discuss.elastic.co/u/eddieyee)\
**Replies:** 1\
**Last updated:** [June 16, 2022, 6:05am UTC](https://discuss.elastic.co/t/create-drop-down-control-to-select-index-pattern/307331 "2022-06-16T06:05:43Z")

</div>

Hi is this possible on the version 7.17.2 which I'm using? Or it can only be use to select the value of the field

---

## [How to put ":" into if statement in filter?](https://discuss.elastic.co/t/how-to-put-into-if-statement-in-filter/307319)

<div class="topic-metadata">

**Author:** [@roman-tasi](https://discuss.elastic.co/u/roman-tasi)\
**Replies:** 2\
**Last updated:** [June 15, 2022, 10:59pm UTC](https://discuss.elastic.co/t/how-to-put-into-if-statement-in-filter/307319 "2022-06-15T22:59:32Z")

</div>

I am currently trying this: if ":" in dst { I also have tried ":" and ':' (backslash before the colon) but neither worked. Is it possible to still try this?

---

## [Query suggestion api](https://discuss.elastic.co/t/query-suggestion-api/307317)

<div class="topic-metadata">

**Author:** [@usman.os](https://discuss.elastic.co/u/usman.os)\
**Replies:** 0\
**Last updated:** [June 15, 2022, 8:24pm UTC](https://discuss.elastic.co/t/query-suggestion-api/307317 "2022-06-15T20:24:19Z")

</div>

I am using query suggestion to show auto complete, I need to pass filter to get more accurate data How i can achieve this?

---

## [Date Filter - \_dateparsefailure](https://discuss.elastic.co/t/date-filter-dateparsefailure/307199)

<div class="topic-metadata">

**Author:** [@yquirion](https://discuss.elastic.co/u/yquirion)\
**Replies:** 8\
**Last updated:** [June 15, 2022, 6:11pm UTC](https://discuss.elastic.co/t/date-filter-dateparsefailure/307199 "2022-06-15T18:11:46Z")

</div>

Dear all, I'm running into a strange problem converting syslogtimestamp field into @timestamp. After reading the thread: https://discuss.elastic.co/t/date-filter--dateparsefailure-solved/64692, I can't make it to work.…

---

## [How to identify source of the PCF logs in elastic stack](https://discuss.elastic.co/t/how-to-identify-source-of-the-pcf-logs-in-elastic-stack/307302)

<div class="topic-metadata">

**Author:** [@gpvikas145](https://discuss.elastic.co/u/gpvikas145)\
**Replies:** 2\
**Last updated:** [June 15, 2022, 5:30pm UTC](https://discuss.elastic.co/t/how-to-identify-source-of-the-pcf-logs-in-elastic-stack/307302 "2022-06-15T17:30:38Z")

</div>

Hi, I am trying to implement Elastic Stack for PCF environment where I have to two datacenters SCC, GCC . How to identify whether the log is from SCC or GCC

---

## [Ruby filter to map different array elements into one record](https://discuss.elastic.co/t/ruby-filter-to-map-different-array-elements-into-one-record/307219)

<div class="topic-metadata">

**Author:** [@santhoshi.p](https://discuss.elastic.co/u/santhoshi.p)\
**Replies:** 1\
**Last updated:** [June 15, 2022, 4:48pm UTC](https://discuss.elastic.co/t/ruby-filter-to-map-different-array-elements-into-one-record/307219 "2022-06-15T16:48:58Z")

</div>

Hi, I have a response like below I'm unable to figure how i need to proceed further. Kindly provide any solution. Response: { "columns": \[ \[0\] { "label": "ICMP", "ingress": true }, \[1\] { "label": "ICMP", "ingr…

---

## [Number in 0,0a format downloading as text in CSV](https://discuss.elastic.co/t/number-in-0-0a-format-downloading-as-text-in-csv/307216)

<div class="topic-metadata">

**Author:** [@behappy\_alwayz0401](https://discuss.elastic.co/u/behappy_alwayz0401)\
**Replies:** 4\
**Last updated:** [June 15, 2022, 4:26pm UTC](https://discuss.elastic.co/t/number-in-0-0a-format-downloading-as-text-in-csv/307216 "2022-06-15T16:26:15Z")

</div>

Hi, this is an important feature request. We observe that Kibana gives the user the flexibility to display number in the format as 100k rather than 100,000. However, when a report of such kind is downloaded to CSV, the …

---

## [Logstash file input to file output is not working. No errors seen in the logs](https://discuss.elastic.co/t/logstash-file-input-to-file-output-is-not-working-no-errors-seen-in-the-logs/307273)

<div class="topic-metadata">

**Author:** [@rajivraghu](https://discuss.elastic.co/u/rajivraghu)\
**Replies:** 1\
**Last updated:** [June 15, 2022, 3:53pm UTC](https://discuss.elastic.co/t/logstash-file-input-to-file-output-is-not-working-no-errors-seen-in-the-logs/307273 "2022-06-15T15:53:55Z")

</div>

Hello, I am new to logstash. I am using 8.2.3. I dont have Elasticsearch running. I wanted to see if logstash is able to take log file as input and convert into json and store it in a file . This is my code below . in…

---

## [IDE/editor for logstash .conf files](https://discuss.elastic.co/t/ide-editor-for-logstash-conf-files/307303)

<div class="topic-metadata">

**Author:** [@hsalim](https://discuss.elastic.co/u/hsalim)\
**Replies:** 0\
**Last updated:** [June 15, 2022, 3:50pm UTC](https://discuss.elastic.co/t/ide-editor-for-logstash-conf-files/307303 "2022-06-15T15:50:37Z")

</div>

Hello, Is there a IDE or an editor for logstash pipeline development? i am currently using visual studio and was wondering if there is something else out there? i found this so far \[Logstash Editor - Visual Studio Mark…

---

## [Displaying number](https://discuss.elastic.co/t/displaying-number/307091)

<div class="topic-metadata">

**Author:** [@behappy\_alwayz0401](https://discuss.elastic.co/u/behappy_alwayz0401)\
**Replies:** 4\
**Last updated:** [June 15, 2022, 3:29pm UTC](https://discuss.elastic.co/t/displaying-number/307091 "2022-06-15T15:29:16Z")

</div>

Hi, is there a way to store a number as 0,0a format but for report download purposes it still shows as the full number? The reason being, when you download the 0,0a format to a CSV it doesnt show up as a number for furt…

---

## [Connection sqlserver to elasticsearch](https://discuss.elastic.co/t/connection-sqlserver-to-elasticsearch/307039)

<div class="topic-metadata">

**Author:** [@Khadija\_BOUDINAR1](https://discuss.elastic.co/u/Khadija_BOUDINAR1)\
**Replies:** 11\
**Last updated:** [June 15, 2022, 2:53pm UTC](https://discuss.elastic.co/t/connection-sqlserver-to-elasticsearch/307039 "2022-06-15T14:53:45Z")

</div>

hi All, to connect sqlserver to Elasticsearch i have configure the file :sql.conf as following : input { jdbc { # SqlServer jdbc connection string to our database, employeedb # "jdbc:sqlserver://…

---

## [Reconciler error: auth secret key default-quickstart-kibana-user doesn't exist](https://discuss.elastic.co/t/reconciler-error-auth-secret-key-default-quickstart-kibana-user-doesnt-exist/307136)

<div class="topic-metadata">

**Author:** [@oliverrahner](https://discuss.elastic.co/u/oliverrahner)\
**Replies:** 7\
**Last updated:** [June 15, 2022, 2:07pm UTC](https://discuss.elastic.co/t/reconciler-error-auth-secret-key-default-quickstart-kibana-user-doesnt-exist/307136 "2022-06-15T14:07:40Z")

</div>

I am currently upgrading my sandbox ECK installation from 7.14.0 to 8.2.2, via 7.17, as required. I managed to finish this for Elasticsearch, but during the 7.14 -\> 7.17 step for Kibana, I stumbled across an issue. The…

---

## [Add new calculated field when processing file in logstash](https://discuss.elastic.co/t/add-new-calculated-field-when-processing-file-in-logstash/307014)

<div class="topic-metadata">

**Author:** [@eduhernandezm](https://discuss.elastic.co/u/eduhernandezm)\
**Replies:** 4\
**Last updated:** [June 15, 2022, 1:54pm UTC](https://discuss.elastic.co/t/add-new-calculated-field-when-processing-file-in-logstash/307014 "2022-06-15T13:54:46Z")

</div>

Hello, I have the following configuration in Logstash to read data from a CSV file that I pass every day. I have it working correctly. My doubt is that I need to add a new field based on a mathematical function against …

---

## [Elastic Contributor off](https://discuss.elastic.co/t/elastic-contributor-off/307037)

<div class="topic-metadata">

**Author:** [@wsouza](https://discuss.elastic.co/u/wsouza)\
**Replies:** 2\
**Last updated:** [June 15, 2022, 12:55pm UTC](https://discuss.elastic.co/t/elastic-contributor-off/307037 "2022-06-15T12:55:34Z")

</div>

The Elastic Contributor portal is experiencing an error during the log on process. Anyone else with this problem?

---

## [Logstash configuration not working on read csv file](https://discuss.elastic.co/t/logstash-configuration-not-working-on-read-csv-file/306515)

<div class="topic-metadata">

**Author:** [@selflabs](https://discuss.elastic.co/u/selflabs)\
**Replies:** 11\
**Last updated:** [June 15, 2022, 12:24pm UTC](https://discuss.elastic.co/t/logstash-configuration-not-working-on-read-csv-file/306515 "2022-06-15T12:24:49Z")

</div>

Hello Everyone, Logstash not reading csv file, i have tried all possible case but unable to pick data from the csv file. my ultimate goal is read data from REST API and mapping with CSV file. Please suggest, Configuratio…

---

## [Logstash pipeline issues with flowfile attributes](https://discuss.elastic.co/t/logstash-pipeline-issues-with-flowfile-attributes/307260)

<div class="topic-metadata">

**Author:** [@Mary2022](https://discuss.elastic.co/u/Mary2022)\
**Replies:** 1\
**Last updated:** [June 15, 2022, 12:07pm UTC](https://discuss.elastic.co/t/logstash-pipeline-issues-with-flowfile-attributes/307260 "2022-06-15T12:07:34Z")

</div>

We get json files from a Nifi and when I checked in Kibana They have a \_jsonparsefailure. When I looked at the logs I see inside "message" "flowfile.attributes0000644 0000 000 000 000 and other garbage about ECDS and at …

---

## [Unable to read Cluster Stats index](https://discuss.elastic.co/t/unable-to-read-cluster-stats-index/306936)

<div class="topic-metadata">

**Author:** [@Abhi\_Abhishek](https://discuss.elastic.co/u/Abhi_Abhishek)\
**Replies:** 1\
**Last updated:** [June 15, 2022, 12:04pm UTC](https://discuss.elastic.co/t/unable-to-read-cluster-stats-index/306936 "2022-06-15T12:04:30Z")

</div>

I am unable to read or fetch data from cluster Stats field. GET /\_cluster/stats I need data in this index to be used in the kibana dashboard visualization to fetch the details like disk usage, cpu & jvm usage just like…

---

## [Enterprise Search Native Credentials Required Privileges](https://discuss.elastic.co/t/enterprise-search-native-credentials-required-privileges/306889)

<div class="topic-metadata">

**Author:** [@TonyWRobinson](https://discuss.elastic.co/u/TonyWRobinson)\
**Replies:** 7\
**Last updated:** [June 15, 2022, 11:37am UTC](https://discuss.elastic.co/t/enterprise-search-native-credentials-required-privileges/306889 "2022-06-15T11:37:20Z")

</div>

Our elastic cluster is on-premise. We deploy the different components (kibana, logstash, enterprise search) to different nodes and configure them to connect / talk to the Elasticsearch cluster. What I see in the docume…

---

## [Cannot access through http://ipaddress:5601 but localhost:5601](https://discuss.elastic.co/t/cannot-access-through-http-ipaddress-5601-but-localhost-5601/307247)

<div class="topic-metadata">

**Author:** [@ghostmomo](https://discuss.elastic.co/u/ghostmomo)\
**Replies:** 2\
**Last updated:** [June 15, 2022, 11:14am UTC](https://discuss.elastic.co/t/cannot-access-through-http-ipaddress-5601-but-localhost-5601/307247 "2022-06-15T11:14:52Z")

</div>

Elasticsarch and Kibana version: 8.2.2 OS: Windows server 2019 Hello, been struggling below problems while I setup the Elasticsearch and kibana on windows platform. unable to get into http://ipaddress:5601 but it's f…

---

## [Filter the metrics column](https://discuss.elastic.co/t/filter-the-metrics-column/307230)

<div class="topic-metadata">

**Author:** [@GinkoLucas](https://discuss.elastic.co/u/GinkoLucas)\
**Replies:** 6\
**Last updated:** [June 15, 2022, 11:04am UTC](https://discuss.elastic.co/t/filter-the-metrics-column/307230 "2022-06-15T11:04:46Z")

</div>

Hello, I created with TSVB a table with two columns. The table displays the date of the last document of each server (Top hit..). server 2 | 2022-06-15 server 2 | 2022-06-15 server 3 | 2022-06-12 I would like to f…

---

## [Alert on Process failures only if existing](https://discuss.elastic.co/t/alert-on-process-failures-only-if-existing/307172)

<div class="topic-metadata">

**Author:** [@jeffo](https://discuss.elastic.co/u/jeffo)\
**Replies:** 1\
**Last updated:** [June 15, 2022, 10:36am UTC](https://discuss.elastic.co/t/alert-on-process-failures-only-if-existing/307172 "2022-06-15T10:36:14Z")

</div>

I'm relatively new to elastic, and I have a plethora of systems (windows) that all have unique monitoring requirements for processes with some overlap. We are running version 7.16.2. I can make alerts on a condition WH…

---

## [Log4j management of access files created by Elasticsearch](https://discuss.elastic.co/t/log4j-management-of-access-files-created-by-elasticsearch/307249)

<div class="topic-metadata">

**Author:** [@intrepid1](https://discuss.elastic.co/u/intrepid1)\
**Replies:** 0\
**Last updated:** [June 15, 2022, 10:00am UTC](https://discuss.elastic.co/t/log4j-management-of-access-files-created-by-elasticsearch/307249 "2022-06-15T10:00:09Z")

</div>

Hi there, I am running Elasticsearch 7.16.1 and also have auditing configured. I am using a default log4j properties files which I had to extend to gzip the audit files. This is not included in the 7.16.1 log4j2 propert…

---

## [Kibana: Failed to decrypt "apiKey" attribute: Unsupported state or unable to authenticate data](https://discuss.elastic.co/t/kibana-failed-to-decrypt-apikey-attribute-unsupported-state-or-unable-to-authenticate-data/251236)

<div class="topic-metadata">

**Author:** [@Abdelhalim](https://discuss.elastic.co/u/Abdelhalim)\
**Replies:** 3\
**Last updated:** [June 15, 2022, 9:49am UTC](https://discuss.elastic.co/t/kibana-failed-to-decrypt-apikey-attribute-unsupported-state-or-unable-to-authenticate-data/251236 "2022-06-15T09:49:58Z")

</div>

Hello everybody, I am facing the error: Kibana: Failed to decrypt "apiKey" attribute: Unsupported state or unable to authenticate data After that I added the line below to Kibana configuration file: xpack.encryptedSa…

[Previous page](https://discuss.elastic.co/tag/none.md?no_tags=true&page=608)

[Next page](https://discuss.elastic.co/tag/none.md?no_tags=true&page=610)
