# Elastic Stack

**URL:** https://discuss.elastic.co/c/elastic-stack/81.md?page=520

[Latest](https://discuss.elastic.co/latest.md) · [Categories](https://discuss.elastic.co/categories.md) · [Tags](https://discuss.elastic.co/tags.md)

**Page:** 521

---

## [How to search a value by special character](https://discuss.elastic.co/t/how-to-search-a-value-by-special-character/334611)

<div class="topic-metadata">

**Author:** [@yuswanul](https://discuss.elastic.co/u/yuswanul)\
**Replies:** 17\
**Last updated:** [June 6, 2023, 11:17am UTC](https://discuss.elastic.co/t/how-to-search-a-value-by-special-character/334611 "2023-06-06T11:17:22Z")

</div>

Hi there, so i have a field named uri\_api and some of them have a value like this: /scrt/kpi/v3/code/shean%20jeremy%20patok i want to search other value like that in uri\_api field. how can i achieve it? i already try …

---

## [Hide the time filter in dashboards](https://discuss.elastic.co/t/hide-the-time-filter-in-dashboards/335321)

<div class="topic-metadata">

**Author:** [@Alice\_Ionescu](https://discuss.elastic.co/u/Alice_Ionescu)\
**Replies:** 2\
**Last updated:** [June 6, 2023, 11:08am UTC](https://discuss.elastic.co/t/hide-the-time-filter-in-dashboards/335321 "2023-06-06T11:08:51Z")

</div>

Hello, I have an index pattern for which I did not set a time field. I created a visualization based on this pattern index, and added it to a dashboard. In the dashboard I still have the time picker. How can I make it…

---

## [Kibana Version in Hindi Language](https://discuss.elastic.co/t/kibana-version-in-hindi-language/335277)

<div class="topic-metadata">

**Author:** [@Sandeep\_Raju](https://discuss.elastic.co/u/Sandeep_Raju)\
**Replies:** 1\
**Last updated:** [June 6, 2023, 10:59am UTC](https://discuss.elastic.co/t/kibana-version-in-hindi-language/335277 "2023-06-06T10:59:51Z")

</div>

Hi all, I want a Kibana version in Hindi language that can display everything in Hindi including Dashboard name, visualization Name, options etc. Any setting for language or Kibana version for Hindi language that I can…

---

## [Kibana TSVB - Percentage of Samples crossing Threshold Filter Ratio Always Returning 0 for one Index](https://discuss.elastic.co/t/kibana-tsvb-percentage-of-samples-crossing-threshold-filter-ratio-always-returning-0-for-one-index/334988)

<div class="topic-metadata">

**Author:** [@shgpde](https://discuss.elastic.co/u/shgpde)\
**Replies:** 4\
**Last updated:** [June 6, 2023, 10:55am UTC](https://discuss.elastic.co/t/kibana-tsvb-percentage-of-samples-crossing-threshold-filter-ratio-always-returning-0-for-one-index/334988 "2023-06-06T10:55:38Z")

</div>

Hi, First time poster, I'm having difficulty getting the data I want from a Kibana visualisation and I'm hoping for some insight. I'm using Kibana v7.6.1 and have been running into an issue trying to use a Filter Ratio…

---

## [Performance issue found : Upgade elasticsearch 7.8 to 7.17](https://discuss.elastic.co/t/performance-issue-found-upgade-elasticsearch-7-8-to-7-17/335324)

<div class="topic-metadata">

**Author:** [@Abhishek\_Tiwari1](https://discuss.elastic.co/u/Abhishek_Tiwari1)\
**Replies:** 0\
**Last updated:** [June 6, 2023, 10:53am UTC](https://discuss.elastic.co/t/performance-issue-found-upgade-elasticsearch-7-8-to-7-17/335324 "2023-06-06T10:53:22Z")

</div>

Hi Team, We are facing major performance issue after upgrade elasticsearch from 7.8 to 7.17 by rolling method. Our Query hits elasticsearch using java rest api(7.2.1). Perfomance degrade form 20ms to 300ms. I need to…

---

## [Show HTML Character Entities as symbols in Kibana](https://discuss.elastic.co/t/show-html-character-entities-as-symbols-in-kibana/335191)

<div class="topic-metadata">

**Author:** [@ddoroshenko](https://discuss.elastic.co/u/ddoroshenko)\
**Replies:** 4\
**Last updated:** [June 6, 2023, 10:43am UTC](https://discuss.elastic.co/t/show-html-character-entities-as-symbols-in-kibana/335191 "2023-06-06T10:43:38Z")

</div>

Hi, I have records in ES where symbols are presented as Character Entities. For example | as &#124; and a record could looks like bla&#124;bla&#124;bla. Is it posible in Kibana to show these entities as symbols, i.e. b…

---

## [Role based Access in Kibana](https://discuss.elastic.co/t/role-based-access-in-kibana/335218)

<div class="topic-metadata">

**Author:** [@nitinkapoor](https://discuss.elastic.co/u/nitinkapoor)\
**Replies:** 3\
**Last updated:** [June 6, 2023, 10:23am UTC](https://discuss.elastic.co/t/role-based-access-in-kibana/335218 "2023-06-06T10:23:31Z")

</div>

Hi I have a use case where based on Role user should be able to see only selected Indices for example compliance auditors should be able to see only compliance indices , they should not be able to see any other indices…

---

## [Shuffle sorted documents](https://discuss.elastic.co/t/shuffle-sorted-documents/335255)

<div class="topic-metadata">

**Author:** [@Novel\_one](https://discuss.elastic.co/u/Novel_one)\
**Replies:** 3\
**Last updated:** [June 6, 2023, 10:10am UTC](https://discuss.elastic.co/t/shuffle-sorted-documents/335255 "2023-06-06T10:10:22Z")

</div>

Hi, I want to create a promotional box in my marketplace, with the top rated articles. I dont want always to be the same articles, so i want them be shuffled a little by multiplying the article avg rate by a random num…

---

## [Kibana cluster acces via F5 load balancer](https://discuss.elastic.co/t/kibana-cluster-acces-via-f5-load-balancer/335285)

<div class="topic-metadata">

**Author:** [@kannan2096](https://discuss.elastic.co/u/kannan2096)\
**Replies:** 1\
**Last updated:** [June 6, 2023, 9:31am UTC](https://discuss.elastic.co/t/kibana-cluster-acces-via-f5-load-balancer/335285 "2023-06-06T09:31:18Z")

</div>

Hi I'm new to ELK and I'm doing POC to implement ELK with cluster setup. With the basic cluster configuration of Elasticsearch(2nodes), the Kibana GUI working fine. But via F5 load balance URL it is not working. The log…

---

## [Running elastic search](https://discuss.elastic.co/t/running-elastic-search/335182)

<div class="topic-metadata">

**Author:** [@waqar\_jamali](https://discuss.elastic.co/u/waqar_jamali)\
**Replies:** 1\
**Last updated:** [June 6, 2023, 9:20am UTC](https://discuss.elastic.co/t/running-elastic-search/335182 "2023-06-06T09:20:34Z")

</div>

How can I run elasticsearch using python client on google colab. I have a python code which is running on my machine. I want to run it on google colab or other notebook online platform. What setup or instruction I need f…

---

## [Kibana support for System for Cross-Domain Identity Management (SCIM)](https://discuss.elastic.co/t/kibana-support-for-system-for-cross-domain-identity-management-scim/334930)

<div class="topic-metadata">

**Author:** [@sivanov](https://discuss.elastic.co/u/sivanov)\
**Replies:** 4\
**Last updated:** [June 6, 2023, 8:44am UTC](https://discuss.elastic.co/t/kibana-support-for-system-for-cross-domain-identity-management-scim/334930 "2023-06-06T08:44:22Z")

</div>

Hi, Does Kibana / Elastic Stack support SCIM for identity providers like Microsoft (Azure/AD)? There is no documentation available on the topic. A short info on SCIM systems: SCIM synchronization with Azure Active Dir…

---

## [Single node yellow](https://discuss.elastic.co/t/single-node-yellow/335249)

<div class="topic-metadata">

**Author:** [@decibel83](https://discuss.elastic.co/u/decibel83)\
**Replies:** 2\
**Last updated:** [June 6, 2023, 8:38am UTC](https://discuss.elastic.co/t/single-node-yellow/335249 "2023-06-06T08:38:07Z")

</div>

Hi have a single node elastic cluster which is yellow: GET /\_cluster/health: { "cluster\_name": "log", "status": "yellow", "timed\_out": false, "number\_of\_nodes": 1, "number\_of\_data\_nodes": 1, "act…

---

## [Curator 7 is failing to delete indices](https://discuss.elastic.co/t/curator-7-is-failing-to-delete-indices/335287)

<div class="topic-metadata">

**Author:** [@chiranjeevirao](https://discuss.elastic.co/u/chiranjeevirao)\
**Replies:** 2\
**Last updated:** [June 6, 2023, 8:35am UTC](https://discuss.elastic.co/t/curator-7-is-failing-to-delete-indices/335287 "2023-06-06T08:35:13Z")

</div>

Hi We are using opensearch 1.2.4 (derived from Elasticsearch 7.10.2). We could see in the curator release document that curator 7 will work with Elasticsearch 7.x and is functionally identical to 5.8.4 and uplifted cur…

---

## [Migration from HighRestLevelCLient to ElasticSearchClient](https://discuss.elastic.co/t/migration-from-highrestlevelclient-to-elasticsearchclient/335023)

<div class="topic-metadata">

**Author:** [@neodeveloper](https://discuss.elastic.co/u/neodeveloper)\
**Replies:** 1\
**Last updated:** [June 6, 2023, 8:21am UTC](https://discuss.elastic.co/t/migration-from-highrestlevelclient-to-elasticsearchclient/335023 "2023-06-06T08:21:47Z")

</div>

Good morning, We are planning to upgrade to springboot3.0 and we are heavily using the deprecated client named HighRestLevelClient which is removed in springboot3 and replaced with the new java api client named ElasticS…

---

## [Log4j Vulnerability Elasticsearch 7.8.0](https://discuss.elastic.co/t/log4j-vulnerability-elasticsearch-7-8-0/333035)

<div class="topic-metadata">

**Author:** [@Faisal\_Umer](https://discuss.elastic.co/u/Faisal_Umer)\
**Replies:** 7\
**Last updated:** [June 6, 2023, 8:08am UTC](https://discuss.elastic.co/t/log4j-vulnerability-elasticsearch-7-8-0/333035 "2023-06-06T08:08:01Z")

</div>

We have Elasticsearch 7.8.0 cluster which has CVE-2021-44228. Can we somehow patch it without upgrading the Elasticsearch version? If yes, can you please share any relevant thread or documentation?

---

## [I want to use spark to read data from es, but I don't know what es.net.ssl.keystore.pass is](https://discuss.elastic.co/t/i-want-to-use-spark-to-read-data-from-es-but-i-dont-know-what-es-net-ssl-keystore-pass-is/335210)

<div class="topic-metadata">

**Author:** [@gaorui](https://discuss.elastic.co/u/gaorui)\
**Replies:** 3\
**Last updated:** [June 6, 2023, 7:58am UTC](https://discuss.elastic.co/t/i-want-to-use-spark-to-read-data-from-es-but-i-dont-know-what-es-net-ssl-keystore-pass-is/335210 "2023-06-06T07:58:51Z")

</div>

When I built the es cluster, I used bin/elasticsearch-certutil to generate the CA certificate and p12 certificate, but I did not enter the password, but chose to press Enter directly. When I want to use spark to connect…

---

## [Applying ILM on custom index](https://discuss.elastic.co/t/applying-ilm-on-custom-index/334924)

<div class="topic-metadata">

**Author:** [@hjazz6](https://discuss.elastic.co/u/hjazz6)\
**Replies:** 3\
**Last updated:** [June 6, 2023, 7:53am UTC](https://discuss.elastic.co/t/applying-ilm-on-custom-index/334924 "2023-06-06T07:53:56Z")

</div>

Hi, I am using filebeat 8.3.3 with several inputs and writing them to the same ES 8.3.3. To separate the different inputs on ES, I have the following in my filebeat.yml. output.elasticsearch: indices: - index: "f…

---

## [How to get docs in aggregated format in ElasticSearch aggregation query?](https://discuss.elastic.co/t/how-to-get-docs-in-aggregated-format-in-elasticsearch-aggregation-query/335292)

<div class="topic-metadata">

**Author:** [@maulik\_trapasiya](https://discuss.elastic.co/u/maulik_trapasiya)\
**Replies:** 0\
**Last updated:** [June 6, 2023, 7:27am UTC](https://discuss.elastic.co/t/how-to-get-docs-in-aggregated-format-in-elasticsearch-aggregation-query/335292 "2023-06-06T07:27:25Z")

</div>

My query { "aggs": { "distinct\_colours": { "terms": { "field": "colour" } } } } Required Result: { "took" : 2037, "timed\_out" : false, "\_shards" : { "total" : 1, "successf…

---

## [TSVB - Top N - Item URL: keep time interval when link to other dashboard](https://discuss.elastic.co/t/tsvb-top-n-item-url-keep-time-interval-when-link-to-other-dashboard/335151)

<div class="topic-metadata">

**Author:** [@Ofir\_Edi](https://discuss.elastic.co/u/Ofir_Edi)\
**Replies:** 2\
**Last updated:** [June 6, 2023, 7:04am UTC](https://discuss.elastic.co/t/tsvb-top-n-item-url-keep-time-interval-when-link-to-other-dashboard/335151 "2023-06-06T07:04:29Z")

</div>

Hi, This is a duplicate of this thread which was not answered. I have TSVB top n visualization of host names and i'm using item URL feature to drilldown to more specific dashboard with the {{key}} place holder. However…

---

## [Failed to parse date field \[message.details.message.keyword\] with format \[strict\_date\_optional\_time\]](https://discuss.elastic.co/t/failed-to-parse-date-field-message-details-message-keyword-with-format-strict-date-optional-time/335099)

<div class="topic-metadata">

**Author:** [@gustavo6](https://discuss.elastic.co/u/gustavo6)\
**Replies:** 0\
**Last updated:** [June 2, 2023, 3:26pm UTC](https://discuss.elastic.co/t/failed-to-parse-date-field-message-details-message-keyword-with-format-strict-date-optional-time/335099 "2023-06-02T15:26:43Z")

</div>

Hi! I'm getting this error: \[essql\] \> Unexpected error from Elasticsearch: illegal\_argument\_exception - failed to parse date field \[message.details.message.keyword\] with format \[strict\_date\_optional\_time\] on this quer…

---

## [Indices in DR Cluster (CCR dest cluster) stuck on forcemerge causing the Space filled up](https://discuss.elastic.co/t/indices-in-dr-cluster-ccr-dest-cluster-stuck-on-forcemerge-causing-the-space-filled-up/335276)

<div class="topic-metadata">

**Author:** [@vikasp](https://discuss.elastic.co/u/vikasp)\
**Replies:** 1\
**Last updated:** [June 6, 2023, 6:01am UTC](https://discuss.elastic.co/t/indices-in-dr-cluster-ccr-dest-cluster-stuck-on-forcemerge-causing-the-space-filled-up/335276 "2023-06-06T06:01:18Z")

</div>

I have 2 elasticsearch clusters deployed in 2 different regions in Amazon EKS. replicating data from east1 to east2 using CCR. I only keep the indices in east2 (dest cluster) for 2 days. 0 day after roller to warm (also…

---

## [CVE-2022-30123	- Rack Vulnerability](https://discuss.elastic.co/t/cve-2022-30123-rack-vulnerability/335274)

<div class="topic-metadata">

**Author:** [@priya\_dhana](https://discuss.elastic.co/u/priya_dhana)\
**Replies:** 1\
**Last updated:** [June 6, 2023, 5:46am UTC](https://discuss.elastic.co/t/cve-2022-30123-rack-vulnerability/335274 "2023-06-06T05:46:47Z")

</div>

Security Scan has flagged Critical CVE-2022-30123 Rack::RELEASE in the logstash 8.7.1 tar file. How can we remove rack or upgrade to a newer version? Thanks, Priya V

---

## [How to use mapper size pluging?](https://discuss.elastic.co/t/how-to-use-mapper-size-pluging/335131)

<div class="topic-metadata">

**Author:** [@Amirhossein\_eidy](https://discuss.elastic.co/u/Amirhossein_eidy)\
**Replies:** 2\
**Last updated:** [June 6, 2023, 5:12am UTC](https://discuss.elastic.co/t/how-to-use-mapper-size-pluging/335131 "2023-06-06T05:12:24Z")

</div>

Hi folks I want to find the largest documents in my indices and I have installed the mapper size plugin and added the field to index as it explained I have two questions now how to add it to index pattern in kibana? …

---

## [How to calculate percentage of a field over all documents present in index](https://discuss.elastic.co/t/how-to-calculate-percentage-of-a-field-over-all-documents-present-in-index/334544)

<div class="topic-metadata">

**Author:** [@Amit\_Charkha](https://discuss.elastic.co/u/Amit_Charkha)\
**Replies:** 5\
**Last updated:** [June 6, 2023, 4:54am UTC](https://discuss.elastic.co/t/how-to-calculate-percentage-of-a-field-over-all-documents-present-in-index/334544 "2023-06-06T04:54:48Z")

</div>

how to calculate percentage of a field log\_count over all documents present in index.

---

## [Why docker run elasticsearch working well and docker compose up stuck on starting, i am confused](https://discuss.elastic.co/t/why-docker-run-elasticsearch-working-well-and-docker-compose-up-stuck-on-starting-i-am-confused/335132)

<div class="topic-metadata">

**Author:** [@Wuxy-Bleu](https://discuss.elastic.co/u/Wuxy-Bleu)\
**Replies:** 2\
**Last updated:** [June 6, 2023, 4:52am UTC](https://discuss.elastic.co/t/why-docker-run-elasticsearch-working-well-and-docker-compose-up-stuck-on-starting-i-am-confused/335132 "2023-06-06T04:52:05Z")

</div>

docker run -it -p 9201:9200 -p 9301:9300 --network elastic --name es2 -e discovery.type=single-node -e cluster.routing.allocation.disk.watermark.high=95% -e cluster.routing.allocation.disk.watermark.low=90% elasticsearch…

---

## [Enable CORS on Kibana](https://discuss.elastic.co/t/enable-cors-on-kibana/334084)

<div class="topic-metadata">

**Author:** [@Shreyansh\_Jain](https://discuss.elastic.co/u/Shreyansh_Jain)\
**Replies:** 12\
**Last updated:** [June 6, 2023, 4:33am UTC](https://discuss.elastic.co/t/enable-cors-on-kibana/334084 "2023-06-06T04:33:58Z")

</div>

Hi all, I am using kibana version v 7.17.9 I am trying to use this api endpoint to generate cookies in my front end angular application : "/internal/security/login". But while making a post call from my web application…

---

## [Single-node. Manage Lifecycle Policy](https://discuss.elastic.co/t/single-node-manage-lifecycle-policy/334347)

<div class="topic-metadata">

**Author:** [@Thales\_Eduardo](https://discuss.elastic.co/u/Thales_Eduardo)\
**Replies:** 5\
**Last updated:** [June 6, 2023, 4:29am UTC](https://discuss.elastic.co/t/single-node-manage-lifecycle-policy/334347 "2023-06-06T04:29:14Z")

</div>

I have an elk siem (single node) version 8.7.1 in production. On it is a 5TB data partition with about 90% disk usage. I would like to allow lifecycle policies to rotate data every 180 days (6 months). It's possible? W…

---

## [Indexing requests and time goes high on 1 node in cluster](https://discuss.elastic.co/t/indexing-requests-and-time-goes-high-on-1-node-in-cluster/334491)

<div class="topic-metadata">

**Author:** [@tarund](https://discuss.elastic.co/u/tarund)\
**Replies:** 1\
**Last updated:** [June 6, 2023, 4:28am UTC](https://discuss.elastic.co/t/indexing-requests-and-time-goes-high-on-1-node-in-cluster/334491 "2023-06-06T04:28:49Z")

</div>

Hi Team I am using ES 7.17.1. Pushing logs from Fluent to 5 node cluster. Enabled xpack monitoring on ES. we observe that sometime during the day the indexing requests & indexing time goes very high on a single node. So…

---

## [TLS error after fresh install of elastic search](https://discuss.elastic.co/t/tls-error-after-fresh-install-of-elastic-search/335264)

<div class="topic-metadata">

**Author:** [@antarr](https://discuss.elastic.co/u/antarr)\
**Replies:** 3\
**Last updated:** [June 6, 2023, 2:36am UTC](https://discuss.elastic.co/t/tls-error-after-fresh-install-of-elastic-search/335264 "2023-06-06T02:36:34Z")

</div>

I'm trying to get Elasticsearch working on Ubuntu 22. I've uninstalled it a few times but keep getting an SSL error when testing using curl. I've tried 7.17, 7.10, and 8.8. uninstall sudo apt-get remove --purge elastic…

---

## [Push Logs from Elastic Search to Alien Vault USM Anywhere](https://discuss.elastic.co/t/push-logs-from-elastic-search-to-alien-vault-usm-anywhere/334781)

<div class="topic-metadata">

**Author:** [@Zu\_kun](https://discuss.elastic.co/u/Zu_kun)\
**Replies:** 4\
**Last updated:** [June 6, 2023, 2:16am UTC](https://discuss.elastic.co/t/push-logs-from-elastic-search-to-alien-vault-usm-anywhere/334781 "2023-06-06T02:16:58Z")

</div>

Hi, I'm a legit noob when it comes to ELK so my questions might not make sense or will probably have some obvious answers to it. Getting straight to the point, I want to pull the logs from my on premises Elasticsearch …

[Previous page](https://discuss.elastic.co/c/elastic-stack/81.md?page=519)

[Next page](https://discuss.elastic.co/c/elastic-stack/81.md?page=521)
