# Elastic Stack

**URL:** https://discuss.elastic.co/c/elastic-stack/81.md?page=474

[Latest](https://discuss.elastic.co/latest.md) · [Categories](https://discuss.elastic.co/categories.md) · [Tags](https://discuss.elastic.co/tags.md)

**Page:** 475

---

## [Change in Time In elasticsearch and Database](https://discuss.elastic.co/t/change-in-time-in-elasticsearch-and-database/338869)

<div class="topic-metadata">

**Author:** [@UshasMerrinGeorge](https://discuss.elastic.co/u/UshasMerrinGeorge)\
**Replies:** 3\
**Last updated:** [July 21, 2023, 8:01am UTC](https://discuss.elastic.co/t/change-in-time-in-elasticsearch-and-database/338869 "2023-07-21T08:01:04Z")

</div>

Hi all, I'm having trouble with data parsing from a database to Elasticsearch. The "downloaddate" field in the database has a value like "2023-07-12 17:30:17.000." When I print it in the terminal using stdout, it's co…

---

## [Creating day of week filter on my dashboard](https://discuss.elastic.co/t/creating-day-of-week-filter-on-my-dashboard/338391)

<div class="topic-metadata">

**Author:** [@Valerija](https://discuss.elastic.co/u/Valerija)\
**Replies:** 11\
**Last updated:** [July 21, 2023, 6:40am UTC](https://discuss.elastic.co/t/creating-day-of-week-filter-on-my-dashboard/338391 "2023-07-21T06:40:32Z")

</div>

Hello there, I am trying to create Day of Week filter that would enable me to exclude day of the week which I do not want to see in the reports on my Dashboard. What I did is created a new script: doc\['createdDate'\].v…

---

## [Calculate the difference between two fields with time](https://discuss.elastic.co/t/calculate-the-difference-between-two-fields-with-time/338859)

<div class="topic-metadata">

**Author:** [@akeelow](https://discuss.elastic.co/u/akeelow)\
**Replies:** 2\
**Last updated:** [July 21, 2023, 5:06am UTC](https://discuss.elastic.co/t/calculate-the-difference-between-two-fields-with-time/338859 "2023-07-21T05:06:26Z")

</div>

Hello! One event has two fields ConnectTime and DisconnectTime. We need to calculate how long the event lasted. To do this, we need to subtract ConnectTime from DisconnectTime. It seems to be very close to the solution,…

---

## [Monitor indexes from ELK with monitoring feature enabled](https://discuss.elastic.co/t/monitor-indexes-from-elk-with-monitoring-feature-enabled/338724)

<div class="topic-metadata">

**Author:** [@dominbdg](https://discuss.elastic.co/u/dominbdg)\
**Replies:** 2\
**Last updated:** [July 20, 2023, 11:17pm UTC](https://discuss.elastic.co/t/monitor-indexes-from-elk-with-monitoring-feature-enabled/338724 "2023-07-20T23:17:57Z")

</div>

Hello I deployed ELK Monitoring Cluster (ELK with feature of monitoring enabled ) and I have couple of other clusters with metricbeat connecting to elasticsearch on it. I would like to implement rule that when in index…

---

## [Mocking an Aggregation](https://discuss.elastic.co/t/mocking-an-aggregation/338363)

<div class="topic-metadata">

**Author:** [@silentfilm](https://discuss.elastic.co/u/silentfilm)\
**Replies:** 1\
**Last updated:** [July 20, 2023, 8:14pm UTC](https://discuss.elastic.co/t/mocking-an-aggregation/338363 "2023-07-20T20:14:29Z")

</div>

I'm trying to mock an Aggregation result for a Unit Test. var mockedSearchResponse = SearchResponse.of(r -\> r .took(10) .timedOut(false) .hits(h -\> h …

---

## [String\_query doesn't respond to some characters](https://discuss.elastic.co/t/string-query-doesnt-respond-to-some-characters/338567)

<div class="topic-metadata">

**Author:** [@y34rz3r0](https://discuss.elastic.co/u/y34rz3r0)\
**Replies:** 2\
**Last updated:** [July 20, 2023, 7:40pm UTC](https://discuss.elastic.co/t/string-query-doesnt-respond-to-some-characters/338567 "2023-07-20T19:40:03Z")

</div>

Hello! I have a misunderstanding of how string\_query works. Index creating: PUT \_index\_template/test { "priority": 500, "template": { "settings": { "index.default\_pipeline": "set-timestamp" }, "ma…

---

## [Plot values for a single field over time](https://discuss.elastic.co/t/plot-values-for-a-single-field-over-time/337914)

<div class="topic-metadata">

**Author:** [@Ryan\_Downey](https://discuss.elastic.co/u/Ryan_Downey)\
**Replies:** 8\
**Last updated:** [July 20, 2023, 7:02pm UTC](https://discuss.elastic.co/t/plot-values-for-a-single-field-over-time/337914 "2023-07-20T19:02:01Z")

</div>

All I'm looking to do is create a line visualization where the 5\_sec\_eps field displays its values. 5\_sec\_eps on the Y axis and time on the bottom. Thats all I need, thank you.

---

## [ElasticsearchClient datetime?](https://discuss.elastic.co/t/elasticsearchclient-datetime/338899)

<div class="topic-metadata">

**Author:** [@McJava1967](https://discuss.elastic.co/u/McJava1967)\
**Replies:** 1\
**Last updated:** [July 20, 2023, 5:47pm UTC](https://discuss.elastic.co/t/elasticsearchclient-datetime/338899 "2023-07-20T17:47:58Z")

</div>

Hi all. I just upgraded ElasticsearchClient to 8.8. A Builder that used to accept a String ("now-7d") now needs a DateTime object. Does anyone have a working example of DateTime usage? This used to work: requestBui…

---

## [Help with aggregation code](https://discuss.elastic.co/t/help-with-aggregation-code/338794)

<div class="topic-metadata">

**Author:** [@vymk](https://discuss.elastic.co/u/vymk)\
**Replies:** 3\
**Last updated:** [July 20, 2023, 4:22pm UTC](https://discuss.elastic.co/t/help-with-aggregation-code/338794 "2023-07-20T16:22:21Z")

</div>

We process mails through multiple modules resulting in logs with the same mail\_id, kinda like this: mail\_id\_X module1: key1 key2 mail\_id\_X module2: key3 key4 mail\_id\_X module3: key5 key6 key7 What I would like to do …

---

## [Elastic Agent to OpenTelemetry Collector](https://discuss.elastic.co/t/elastic-agent-to-opentelemetry-collector/338789)

<div class="topic-metadata">

**Author:** [@chadr](https://discuss.elastic.co/u/chadr)\
**Replies:** 3\
**Last updated:** [July 20, 2023, 4:15pm UTC](https://discuss.elastic.co/t/elastic-agent-to-opentelemetry-collector/338789 "2023-07-20T16:15:34Z")

</div>

Hi all, I am researching the capabilities of the current and future roadmap for the Elastic Agent. We have a very diverse infra/app/coding language environment. Specifically, I looking to understand if the Elastic Age…

---

## [Best disk modes for data nodes (VMVare ESX)](https://discuss.elastic.co/t/best-disk-modes-for-data-nodes-vmvare-esx/338898)

<div class="topic-metadata">

**Author:** [@alissan](https://discuss.elastic.co/u/alissan)\
**Replies:** 0\
**Last updated:** [July 20, 2023, 3:57pm UTC](https://discuss.elastic.co/t/best-disk-modes-for-data-nodes-vmvare-esx/338898 "2023-07-20T15:57:44Z")

</div>

I need to create a cluster on vmware esx with 60 data nodes. Every node have 100GB disk for OS and 10TB disk (SSD) with for data fiber channel. I'm looking for best vmware disk mode option for data nodes. There are 3 o…

---

## [Streamingbulk vs parallel bulk](https://discuss.elastic.co/t/streamingbulk-vs-parallel-bulk/338895)

<div class="topic-metadata">

**Author:** [@Vivek\_Burman](https://discuss.elastic.co/u/Vivek_Burman)\
**Replies:** 0\
**Last updated:** [July 20, 2023, 3:02pm UTC](https://discuss.elastic.co/t/streamingbulk-vs-parallel-bulk/338895 "2023-07-20T15:02:44Z")

</div>

Hi, I've stumbled upon a case where I see one of my index goes to RED state and taking ES down with it. Here are the JVM options I've set it to. -Xms10g -Xmx10g In my case I need to migrate around 6lakh of data from …

---

## [Unable to login to kibana with valid elastic user credentials after few days](https://discuss.elastic.co/t/unable-to-login-to-kibana-with-valid-elastic-user-credentials-after-few-days/338785)

<div class="topic-metadata">

**Author:** [@shiva\_ratnavarapu](https://discuss.elastic.co/u/shiva_ratnavarapu)\
**Replies:** 1\
**Last updated:** [July 20, 2023, 2:50pm UTC](https://discuss.elastic.co/t/unable-to-login-to-kibana-with-valid-elastic-user-credentials-after-few-days/338785 "2023-07-20T14:50:50Z")

</div>

Kibana version: kibana:8.5.1 Elasticsearch version: elasticsearch:8.5.1 We have installed the elasticsearch and kibana using helm chart. Post installation able to access kibana with elasticsearch credentials user/pass…

---

## [Help with simple ILM rollover configuration for existing index](https://discuss.elastic.co/t/help-with-simple-ilm-rollover-configuration-for-existing-index/338843)

<div class="topic-metadata">

**Author:** [@Stephen\_Joiner](https://discuss.elastic.co/u/Stephen_Joiner)\
**Replies:** 1\
**Last updated:** [July 20, 2023, 2:45pm UTC](https://discuss.elastic.co/t/help-with-simple-ilm-rollover-configuration-for-existing-index/338843 "2023-07-20T14:45:01Z")

</div>

Hey everyone! I have a super basic Elastic Stack set up in docker on my personal server. I am using Logstash to gather the logs of my non-elastic containers. The stack works great and has for years. The problem I'm runn…

---

## [Set minimum value for sum aggregation in stacked bar chart](https://discuss.elastic.co/t/set-minimum-value-for-sum-aggregation-in-stacked-bar-chart/338822)

<div class="topic-metadata">

**Author:** [@emi\_rose](https://discuss.elastic.co/u/emi_rose)\
**Replies:** 1\
**Last updated:** [July 20, 2023, 2:43pm UTC](https://discuss.elastic.co/t/set-minimum-value-for-sum-aggregation-in-stacked-bar-chart/338822 "2023-07-20T14:43:37Z")

</div>

Hi there, I made a stacked bar chart where the bars are sums of a duration field, each bar representing a day. The bars are split on field1. Some duration sums for some values of field1 much smaller in relation to other…

---

## [Re-indexing ElasticSearch](https://discuss.elastic.co/t/re-indexing-elasticsearch/338816)

<div class="topic-metadata">

**Author:** [@randallkiddsr](https://discuss.elastic.co/u/randallkiddsr)\
**Replies:** 4\
**Last updated:** [July 20, 2023, 2:38pm UTC](https://discuss.elastic.co/t/re-indexing-elasticsearch/338816 "2023-07-20T14:38:40Z")

</div>

I am trying to get clarity on the necessity and steps to re indexing Elasticsearch. After performing a search on one account, that account is coming up blank.

---

## [Kibana - Sending email from Microsoft Exchange with Certificate Auth](https://discuss.elastic.co/t/kibana-sending-email-from-microsoft-exchange-with-certificate-auth/338892)

<div class="topic-metadata">

**Author:** [@jsoule6](https://discuss.elastic.co/u/jsoule6)\
**Replies:** 0\
**Last updated:** [July 20, 2023, 2:19pm UTC](https://discuss.elastic.co/t/kibana-sending-email-from-microsoft-exchange-with-certificate-auth/338892 "2023-07-20T14:19:05Z")

</div>

Hello, We are trying to use the Kibana integration with Microsoft Exchange. We are being told that the requirement is to use certificate based authentication instead of the clientSecret string. Is there a supported way …

---

## [Removing backslashes (\\)](https://discuss.elastic.co/t/removing-backslashes/338828)

<div class="topic-metadata">

**Author:** [@CodeMonky](https://discuss.elastic.co/u/CodeMonky)\
**Replies:** 1\
**Last updated:** [July 20, 2023, 2:16pm UTC](https://discuss.elastic.co/t/removing-backslashes/338828 "2023-07-20T14:16:45Z")

</div>

Good day all! I have log files that I'm trying to ingest into a test pipeline. I have my grok patterns and everything but when I run the pipeline it fails. I believe it is failing due to the logs having back-slashes in …

---

## [Couldn't configure Elastic Retry or update the kibana.yml file manually](https://discuss.elastic.co/t/couldnt-configure-elastic-retry-or-update-the-kibana-yml-file-manually/338624)

<div class="topic-metadata">

**Author:** [@Aditya\_Bollam](https://discuss.elastic.co/u/Aditya_Bollam)\
**Replies:** 31\
**Last updated:** [July 20, 2023, 2:00pm UTC](https://discuss.elastic.co/t/couldnt-configure-elastic-retry-or-update-the-kibana-yml-file-manually/338624 "2023-07-20T14:00:09Z")

</div>

even after editing manually same problem is persisiting.

---

## [Backup and restore](https://discuss.elastic.co/t/backup-and-restore/338872)

<div class="topic-metadata">

**Author:** [@stephane\_chan](https://discuss.elastic.co/u/stephane_chan)\
**Replies:** 1\
**Last updated:** [July 20, 2023, 1:47pm UTC](https://discuss.elastic.co/t/backup-and-restore/338872 "2023-07-20T13:47:26Z")

</div>

Hi , I need to make a backup of elasticsearch data, due to maintenance, and restore it afterwards, My question is: Does elasticsearch save the configurations of each indices, I'm talking about the number of shards, th…

---

## [Export canvas with live data](https://discuss.elastic.co/t/export-canvas-with-live-data/338850)

<div class="topic-metadata">

**Author:** [@Sayed\_Aktar](https://discuss.elastic.co/u/Sayed_Aktar)\
**Replies:** 1\
**Last updated:** [July 20, 2023, 1:41pm UTC](https://discuss.elastic.co/t/export-canvas-with-live-data/338850 "2023-07-20T13:41:04Z")

</div>

Hello ! I want to export the live canvas visualisation charts in our Website(Nextjs). How can i do that ?

---

## [Uptime not showing Readonly Users](https://discuss.elastic.co/t/uptime-not-showing-readonly-users/337174)

<div class="topic-metadata">

**Author:** [@praveen\_raju](https://discuss.elastic.co/u/praveen_raju)\
**Replies:** 1\
**Last updated:** [July 20, 2023, 1:36pm UTC](https://discuss.elastic.co/t/uptime-not-showing-readonly-users/337174 "2023-07-20T13:36:57Z")

</div>

Hi, We are using custom role (Read Only) to access Uptime from Observability section. But we are getting "contact your administrator" screen. Below is the scrennshot for your reference. Also attaching index privileges …

---

## ["\[my\_s3\_repo\] path is not accessible on master node](https://discuss.elastic.co/t/my-s3-repo-path-is-not-accessible-on-master-node/338885)

<div class="topic-metadata">

**Author:** [@Samuel\_Emmanuel](https://discuss.elastic.co/u/Samuel_Emmanuel)\
**Replies:** 0\
**Last updated:** [July 20, 2023, 1:32pm UTC](https://discuss.elastic.co/t/my-s3-repo-path-is-not-accessible-on-master-node/338885 "2023-07-20T13:32:08Z")

</div>

I am trying to setup a repository using minIO s3 bucket to implement a snapshot for my Elasticsearch running in a kubernetes cluster, but I encountered the error as seen below on kibana dev too. { "error" : { "roo…

---

## [Landing Filebeat data in two different Kafka clusters](https://discuss.elastic.co/t/landing-filebeat-data-in-two-different-kafka-clusters/338883)

<div class="topic-metadata">

**Author:** [@Kevinesan\_Pillay](https://discuss.elastic.co/u/Kevinesan_Pillay)\
**Replies:** 0\
**Last updated:** [July 20, 2023, 1:22pm UTC](https://discuss.elastic.co/t/landing-filebeat-data-in-two-different-kafka-clusters/338883 "2023-07-20T13:22:33Z")

</div>

Good day, all I have the following environments in place: A functional Production environment: A. Host1 with filebeat polling a file sending to: B. A 3-node Kafka cluster on Topic1. (version: kafka\_2.13-3.2.0) C. 2 …

---

## [ILM rollover](https://discuss.elastic.co/t/ilm-rollover/338771)

<div class="topic-metadata">

**Author:** [@kruzadmn](https://discuss.elastic.co/u/kruzadmn)\
**Replies:** 12\
**Last updated:** [July 20, 2023, 1:20pm UTC](https://discuss.elastic.co/t/ilm-rollover/338771 "2023-07-20T13:20:51Z")

</div>

Hi! Please help me. I have configured ILM to rollover the index when it reaches 120GB or 7 days. I have a problem that ILM does not rollover the index because it thinks that the index size is for example 117GB, when in …

---

## [Kibana Alerts](https://discuss.elastic.co/t/kibana-alerts/338844)

<div class="topic-metadata">

**Author:** [@schandup](https://discuss.elastic.co/u/schandup)\
**Replies:** 1\
**Last updated:** [July 20, 2023, 1:16pm UTC](https://discuss.elastic.co/t/kibana-alerts/338844 "2023-07-20T13:16:30Z")

</div>

Hi, Can you help how to setup an alert in Kibana. We could see "Transaction not found" exception response in Kibana logs for one particular transaction. So, I would like to set up an in alert in Kibana if this exception…

---

## ['Time shift' defaults to previous year - in legacy Metric lens](https://discuss.elastic.co/t/time-shift-defaults-to-previous-year-in-legacy-metric-lens/337273)

<div class="topic-metadata">

**Author:** [@Andreas\_Schennings](https://discuss.elastic.co/u/Andreas_Schennings)\
**Replies:** 1\
**Last updated:** [July 20, 2023, 1:11pm UTC](https://discuss.elastic.co/t/time-shift-defaults-to-previous-year-in-legacy-metric-lens/337273 "2023-07-20T13:11:42Z")

</div>

Hi! I´ve created a Legacy Metric lens that should display the Trend (in percent CO2) compared to a baseyear of 2019. But it always defaults to display the trend compared to previous year. I´ve created a small video her…

---

## [Need help with creating a Watcher and trigger Email](https://discuss.elastic.co/t/need-help-with-creating-a-watcher-and-trigger-email/338542)

<div class="topic-metadata">

**Author:** [@Jayakrishna\_Manokara](https://discuss.elastic.co/u/Jayakrishna_Manokara)\
**Replies:** 4\
**Last updated:** [July 20, 2023, 12:57pm UTC](https://discuss.elastic.co/t/need-help-with-creating-a-watcher-and-trigger-email/338542 "2023-07-20T12:57:31Z")

</div>

I would like to create a Watcher Alert using Watcher JSON and trigger email. Could you help me create a Watcher JSON that is equivalent to the below formula: unique\_count(id, kql='abcresult.keyword : "SUCCESS" ') / (un…

---

## [ElasticsearchClient GetRecordsRequest examples?](https://discuss.elastic.co/t/elasticsearchclient-getrecordsrequest-examples/338820)

<div class="topic-metadata">

**Author:** [@McJava1967](https://discuss.elastic.co/u/McJava1967)\
**Replies:** 1\
**Last updated:** [July 20, 2023, 12:57pm UTC](https://discuss.elastic.co/t/elasticsearchclient-getrecordsrequest-examples/338820 "2023-07-20T12:57:05Z")

</div>

Hi all. Could anyone point me to examples of using the Java ElasticsearchClient GetRecordsRequest to return results from \_ml/anomaly\_detectors? Thanks!

---

## [Requirement for designing elastic search in aws](https://discuss.elastic.co/t/requirement-for-designing-elastic-search-in-aws/338879)

<div class="topic-metadata">

**Author:** [@uma\_parvathy](https://discuss.elastic.co/u/uma_parvathy)\
**Replies:** 0\
**Last updated:** [July 20, 2023, 12:35pm UTC](https://discuss.elastic.co/t/requirement-for-designing-elastic-search-in-aws/338879 "2023-07-20T12:35:23Z")

</div>

Hi All, I've asked to design a Elasticsearch for my project . I'm a new joiner to my project and new to Elasticsearch. I saw minimum requirement as such 8 GM Ram,4 CPU core, and 50 Gb disk space with 1 GBps network …

[Previous page](https://discuss.elastic.co/c/elastic-stack/81.md?page=473)

[Next page](https://discuss.elastic.co/c/elastic-stack/81.md?page=475)
