# Elastic Stack

**URL:** https://discuss.elastic.co/c/elastic-stack/81.md?page=614

[Latest](https://discuss.elastic.co/latest.md) · [Categories](https://discuss.elastic.co/categories.md) · [Tags](https://discuss.elastic.co/tags.md)

**Page:** 615

---

## [Date/time field formatting from csv input](https://discuss.elastic.co/t/date-time-field-formatting-from-csv-input/326984)

<div class="topic-metadata">

**Author:** [@karlkras](https://discuss.elastic.co/u/karlkras)\
**Replies:** 2\
**Last updated:** [March 4, 2023, 9:19pm UTC](https://discuss.elastic.co/t/date-time-field-formatting-from-csv-input/326984 "2023-03-04T21:19:27Z")

</div>

Please excuse the ignorance of my question, I'm still trying get my arms around working with elk, not my forte. I'm generating a csv for a report that contains a few columns that refer to date/time stamps. During gener…

---

## [Failed to expand fields: cannot expand "field" found conflicting key](https://discuss.elastic.co/t/failed-to-expand-fields-cannot-expand-field-found-conflicting-key/326924)

<div class="topic-metadata">

**Author:** [@nobeerhere](https://discuss.elastic.co/u/nobeerhere)\
**Replies:** 2\
**Last updated:** [March 4, 2023, 7:26pm UTC](https://discuss.elastic.co/t/failed-to-expand-fields-cannot-expand-field-found-conflicting-key/326924 "2023-03-04T19:26:30Z")

</div>

hi there I am using ECS logging for Java and so far it worked fine. I now have the issue that the log structure changed a bit (field trace.id & transation.id are new) and i am having a conflicting key value. This also m…

---

## [Speed of elastic search](https://discuss.elastic.co/t/speed-of-elastic-search/326554)

<div class="topic-metadata">

**Author:** [@smitak](https://discuss.elastic.co/u/smitak)\
**Replies:** 15\
**Last updated:** [March 4, 2023, 8:41pm UTC](https://discuss.elastic.co/t/speed-of-elastic-search/326554 "2023-03-04T20:41:03Z")

</div>

How to increase Elasticsearch speed . I am uploading 75 files at a time and i want to add pdf file content into database.But it is taking 15-20 min. Any suggestions.

---

## [Need an example to to multi value search](https://discuss.elastic.co/t/need-an-example-to-to-multi-value-search/326971)

<div class="topic-metadata">

**Author:** [@vkrishna](https://discuss.elastic.co/u/vkrishna)\
**Replies:** 6\
**Last updated:** [March 4, 2023, 8:02pm UTC](https://discuss.elastic.co/t/need-an-example-to-to-multi-value-search/326971 "2023-03-04T20:02:40Z")

</div>

Hi Team, We need an example to to multi value search using co.elastic.clients.elasticsearch.\_types.query\_dsl.Query. Assume we have a field called "rating" in Elasticsearch. I want a JAVA Elasticsearch query written us…

---

## [Log4j configuration to not display particular error](https://discuss.elastic.co/t/log4j-configuration-to-not-display-particular-error/326964)

<div class="topic-metadata">

**Author:** [@ElasticLiver](https://discuss.elastic.co/u/ElasticLiver)\
**Replies:** 2\
**Last updated:** [March 3, 2023, 6:14pm UTC](https://discuss.elastic.co/t/log4j-configuration-to-not-display-particular-error/326964 "2023-03-03T18:14:04Z")

</div>

Hi Im using kafka input, when I get errors it shows me to much data, how to silence this error: \[ERROR\]\[logstash.javapipeline \] in log4j2.properties? thanks

---

## [Kibana configure alert based upon dynamic value](https://discuss.elastic.co/t/kibana-configure-alert-based-upon-dynamic-value/326132)

<div class="topic-metadata">

**Author:** [@Raj4](https://discuss.elastic.co/u/Raj4)\
**Replies:** 9\
**Last updated:** [March 4, 2023, 3:15am UTC](https://discuss.elastic.co/t/kibana-configure-alert-based-upon-dynamic-value/326132 "2023-03-04T03:15:35Z")

</div>

Hello All, I am new to Kibana, I need to achieve the below. Please advise. I am using formula to calculate one column data, I want to alert only if the calculated column value is greater than 5% difference. Example: …

---

## [Multiple data different dates](https://discuss.elastic.co/t/multiple-data-different-dates/326918)

<div class="topic-metadata">

**Author:** [@TaNTal](https://discuss.elastic.co/u/TaNTal)\
**Replies:** 1\
**Last updated:** [March 4, 2023, 12:03am UTC](https://discuss.elastic.co/t/multiple-data-different-dates/326918 "2023-03-04T00:03:07Z")

</div>

How to search for data with different start date in multiple databases?

---

## [Filtering by date field with DSL returning invalid results](https://discuss.elastic.co/t/filtering-by-date-field-with-dsl-returning-invalid-results/326969)

<div class="topic-metadata">

**Author:** [@pocketcolin](https://discuss.elastic.co/u/pocketcolin)\
**Replies:** 7\
**Last updated:** [March 3, 2023, 8:18pm UTC](https://discuss.elastic.co/t/filtering-by-date-field-with-dsl-returning-invalid-results/326969 "2023-03-03T20:18:58Z")

</div>

I am trying to query one of my indexes for all records that have a date field (labels.expiresAt) set gte to now. In other words, the date field should be later than today. That seems super straightforward, but when I set…

---

## [Security Error while integrating SSO with elastic cloud cluster using Terraform](https://discuss.elastic.co/t/security-error-while-integrating-sso-with-elastic-cloud-cluster-using-terraform/326967)

<div class="topic-metadata">

**Author:** [@Saicharan\_M](https://discuss.elastic.co/u/Saicharan_M)\
**Replies:** 1\
**Last updated:** [March 3, 2023, 7:08pm UTC](https://discuss.elastic.co/t/security-error-while-integrating-sso-with-elastic-cloud-cluster-using-terraform/326967 "2023-03-03T19:08:16Z")

</div>

I've been trying to provision elastic cluster with SSO configured. As per the latest ec provider documentation we should be able to achieve this in a single workflow. But however, I do see below error while provisioning …

---

## [Grok - Extracting words between two phrases that remain constant](https://discuss.elastic.co/t/grok-extracting-words-between-two-phrases-that-remain-constant/326901)

<div class="topic-metadata">

**Author:** [@demonsquatch](https://discuss.elastic.co/u/demonsquatch)\
**Replies:** 2\
**Last updated:** [March 3, 2023, 5:47pm UTC](https://discuss.elastic.co/t/grok-extracting-words-between-two-phrases-that-remain-constant/326901 "2023-03-03T17:47:46Z")

</div>

Hi All, I'm currently trying to extract a VM name from vSphere logs and am having some issues as the VM names can be of variable length and contain an array of characters. So far the only delimiting factor for separatin…

---

## [How to configure different Networks](https://discuss.elastic.co/t/how-to-configure-different-networks/325822)

<div class="topic-metadata">

**Author:** [@Lamine](https://discuss.elastic.co/u/Lamine)\
**Replies:** 4\
**Last updated:** [March 3, 2023, 3:51pm UTC](https://discuss.elastic.co/t/how-to-configure-different-networks/325822 "2023-03-03T15:51:31Z")

</div>

Hello everyone, I am new to elastic and I am trying to configure my elastic cluster with two different networks, the first one for kibana connection and the second one for data collection from beats. How do I configure …

---

## [How to Import a Kibana Dashboard with Ansible? - update](https://discuss.elastic.co/t/how-to-import-a-kibana-dashboard-with-ansible-update/326939)

<div class="topic-metadata">

**Author:** [@pyton](https://discuss.elastic.co/u/pyton)\
**Replies:** 1\
**Last updated:** [March 3, 2023, 3:27pm UTC](https://discuss.elastic.co/t/how-to-import-a-kibana-dashboard-with-ansible-update/326939 "2023-03-03T15:27:20Z")

</div>

Hi i have update to closed thread -\> How to Import a Kibana Dashboard with Ansible? . I have been able to solve that nicely - ansible way. - name: Install custom dashboards ansible.builtin.uri: url: "{{ kibana\_end…

---

## [Question about develop an integration for XML input via TCP](https://discuss.elastic.co/t/question-about-develop-an-integration-for-xml-input-via-tcp/326670)

<div class="topic-metadata">

**Author:** [@Sebastian\_Huettersen](https://discuss.elastic.co/u/Sebastian_Huettersen)\
**Replies:** 1\
**Last updated:** [March 3, 2023, 7:52am UTC](https://discuss.elastic.co/t/question-about-develop-an-integration-for-xml-input-via-tcp/326670 "2023-03-03T07:52:44Z")

</div>

I am currently trying to develop an integration that takes reports from an appliance and then indexes them in elastic. The appliance sends these XML reports via TCP. Currently, I have the problem that I can't get the d…

---

## [Elastic Agent, specifying number of shards and ILM policy](https://discuss.elastic.co/t/elastic-agent-specifying-number-of-shards-and-ilm-policy/326945)

<div class="topic-metadata">

**Author:** [@Mirko\_Katunar](https://discuss.elastic.co/u/Mirko_Katunar)\
**Replies:** 3\
**Last updated:** [March 3, 2023, 3:06pm UTC](https://discuss.elastic.co/t/elastic-agent-specifying-number-of-shards-and-ilm-policy/326945 "2023-03-03T15:06:52Z")

</div>

Hello! I was wondering if someone can tell me where can I specify number of shards and ILM policy for specific data stream while using Elastic Agents. For example the default sys log data streams all use "Logs" as a de…

---

## [Logstash - A plugin had an unrecoverable error. Will restart this plugin. java.util.concurrent.ScheduledThreadPoolExecutor](https://discuss.elastic.co/t/logstash-a-plugin-had-an-unrecoverable-error-will-restart-this-plugin-java-util-concurrent-scheduledthreadpoolexecutor/326007)

<div class="topic-metadata">

**Author:** [@Grant\_Hope](https://discuss.elastic.co/u/Grant_Hope)\
**Replies:** 10\
**Last updated:** [March 3, 2023, 3:01pm UTC](https://discuss.elastic.co/t/logstash-a-plugin-had-an-unrecoverable-error-will-restart-this-plugin-java-util-concurrent-scheduledthreadpoolexecutor/326007 "2023-03-03T15:01:03Z")

</div>

I'm running into a problem with java.util.concurrent.ScheduledThreadPoolExecutor. Setup details: logstash 8.5.1 Logstash was installed via RPM Linux server1 4.18.0-372.26.1.el8\_6.x86\_64 #1 SMP Sat Aug 27 02:44:20 EDT…

---

## [Nested aggregation](https://discuss.elastic.co/t/nested-aggregation/326949)

<div class="topic-metadata">

**Author:** [@Sneha\_Rose](https://discuss.elastic.co/u/Sneha_Rose)\
**Replies:** 0\
**Last updated:** [March 3, 2023, 2:52pm UTC](https://discuss.elastic.co/t/nested-aggregation/326949 "2023-03-03T14:52:44Z")

</div>

I have an elastic index with authors field as array of objects: "authors" : \[ { "email" : "100@gmail.com", "authid" : "100", }, { "email" : "200@gmail.com", "authid" : "200", }, { "email" : "300@gmail.com", …

---

## [How to add public package registry and my custom package registry in same kibana](https://discuss.elastic.co/t/how-to-add-public-package-registry-and-my-custom-package-registry-in-same-kibana/326946)

<div class="topic-metadata">

**Author:** [@aurangzeb99](https://discuss.elastic.co/u/aurangzeb99)\
**Replies:** 0\
**Last updated:** [March 3, 2023, 2:21pm UTC](https://discuss.elastic.co/t/how-to-add-public-package-registry-and-my-custom-package-registry-in-same-kibana/326946 "2023-03-03T14:21:10Z")

</div>

can I manage only my custom integration with my custom registry and all the default integration should be present from public registry not from my custom package registry (docker container) ?

---

## [Multiple chain inputs and foreach](https://discuss.elastic.co/t/multiple-chain-inputs-and-foreach/326882)

<div class="topic-metadata">

**Author:** [@rajsolanki](https://discuss.elastic.co/u/rajsolanki)\
**Replies:** 2\
**Last updated:** [March 3, 2023, 1:16pm UTC](https://discuss.elastic.co/t/multiple-chain-inputs-and-foreach/326882 "2023-03-03T13:16:34Z")

</div>

I have following basic watcher. { "trigger": { "schedule": { "interval": "1m" } }, "input": { "chain": { "inputs": \[ { "first\_input": { "http": { …

---

## [Relevance tuning in platform search -scoring profile](https://discuss.elastic.co/t/relevance-tuning-in-platform-search-scoring-profile/326938)

<div class="topic-metadata">

**Author:** [@Arumugam](https://discuss.elastic.co/u/Arumugam)\
**Replies:** 0\
**Last updated:** [March 3, 2023, 12:46pm UTC](https://discuss.elastic.co/t/relevance-tuning-in-platform-search-scoring-profile/326938 "2023-03-03T12:46:06Z")

</div>

We would like to define the weight by default for some fields and those weight criteria applied for search query. We want to same functionality that's available in App Search(Relevance tuning) in platform search. For ex…

---

## [Entire Row color based on condition instead of one column in table lens](https://discuss.elastic.co/t/entire-row-color-based-on-condition-instead-of-one-column-in-table-lens/326917)

<div class="topic-metadata">

**Author:** [@PappuSingh](https://discuss.elastic.co/u/PappuSingh)\
**Replies:** 2\
**Last updated:** [March 3, 2023, 11:47am UTC](https://discuss.elastic.co/t/entire-row-color-based-on-condition-instead-of-one-column-in-table-lens/326917 "2023-03-03T11:47:56Z")

</div>

Hi, How do we apply color for the entire row? I applied the color based on the condition at 1 column but we need to apply the color for the entire row. please see the below snap for reference.

---

## [Kibana url format bug in visualization](https://discuss.elastic.co/t/kibana-url-format-bug-in-visualization/326757)

<div class="topic-metadata">

**Author:** [@bertr](https://discuss.elastic.co/u/bertr)\
**Replies:** 1\
**Last updated:** [March 3, 2023, 11:35am UTC](https://discuss.elastic.co/t/kibana-url-format-bug-in-visualization/326757 "2023-03-03T11:35:21Z")

</div>

Base on version 8.5.3 I know this bug has been mentioned before, but I think I have a new scenario: Create a field 'X' as string. In the index you will find 'X' and 'X.keyword' add url formatting to BOTH fields templa…

---

## [Use logstash to collect NextCloud Audit logs](https://discuss.elastic.co/t/use-logstash-to-collect-nextcloud-audit-logs/326928)

<div class="topic-metadata">

**Author:** [@GEHsu](https://discuss.elastic.co/u/GEHsu)\
**Replies:** 0\
**Last updated:** [March 3, 2023, 10:44am UTC](https://discuss.elastic.co/t/use-logstash-to-collect-nextcloud-audit-logs/326928 "2023-03-03T10:44:42Z")

</div>

Use logstash to collect NextCloud Audit logs, Chinese word will become a word starting with % or \\u, how to make it display normally I have added filter {urldecode {all\_fields =\> true}}, Chinese starting with % are disp…

---

## [Painlessly turning a string of multiple numbers into multiple fields of numbers](https://discuss.elastic.co/t/painlessly-turning-a-string-of-multiple-numbers-into-multiple-fields-of-numbers/326800)

<div class="topic-metadata">

**Author:** [@Mike\_Williams](https://discuss.elastic.co/u/Mike_Williams)\
**Replies:** 2\
**Last updated:** [March 3, 2023, 10:38am UTC](https://discuss.elastic.co/t/painlessly-turning-a-string-of-multiple-numbers-into-multiple-fields-of-numbers/326800 "2023-03-03T10:38:24Z")

</div>

Hey all, I'm ingesting JSON formatted logs from nginx. The JSON is all ECS style nested fields. I've currently got a need to visualize the upstream response time, http.upstream.response.time. Fundamentally this is a fl…

---

## [Integration upgrade is stuck and does not finish](https://discuss.elastic.co/t/integration-upgrade-is-stuck-and-does-not-finish/326919)

<div class="topic-metadata">

**Author:** [@norgro2601](https://discuss.elastic.co/u/norgro2601)\
**Replies:** 0\
**Last updated:** [March 3, 2023, 9:05am UTC](https://discuss.elastic.co/t/integration-upgrade-is-stuck-and-does-not-finish/326919 "2023-03-03T09:05:44Z")

</div>

I wanted to upgrade my integrations to the latest version and this is running fine on all integrations but one, which got stuck and never releases again to give the upgrade a second try. Is there a way to reset the upgr…

---

## [If we hover a mouse in specific visual then it will be highlight entire visual background? Is it expected behavior](https://discuss.elastic.co/t/if-we-hover-a-mouse-in-specific-visual-then-it-will-be-highlight-entire-visual-background-is-it-expected-behavior/326846)

<div class="topic-metadata">

**Author:** [@Abj\_Ins](https://discuss.elastic.co/u/Abj_Ins)\
**Replies:** 3\
**Last updated:** [March 3, 2023, 8:40am UTC](https://discuss.elastic.co/t/if-we-hover-a-mouse-in-specific-visual-then-it-will-be-highlight-entire-visual-background-is-it-expected-behavior/326846 "2023-03-03T08:40:55Z")

</div>

Hi Team, Suppose i have one visual as below. If i want to see only green color details then hover a mouse on that Green color bar so, background of that Green color bar only effect/highlight in the background. But, h…

---

## [Display only searched in dashboard](https://discuss.elastic.co/t/display-only-searched-in-dashboard/324780)

<div class="topic-metadata">

**Author:** [@TaNTal](https://discuss.elastic.co/u/TaNTal)\
**Replies:** 4\
**Last updated:** [March 3, 2023, 8:36am UTC](https://discuss.elastic.co/t/display-only-searched-in-dashboard/324780 "2023-03-03T08:36:54Z")

</div>

I am searching for X or Y or Z, which can be found in field A or B. I want results for only X and Y and Z found in A or B, and not other values that are not search. If A=X I also have B in graph.

---

## [How to check Mapping field not have any value](https://discuss.elastic.co/t/how-to-check-mapping-field-not-have-any-value/326906)

<div class="topic-metadata">

**Author:** [@PappuSingh](https://discuss.elastic.co/u/PappuSingh)\
**Replies:** 2\
**Last updated:** [March 3, 2023, 7:39am UTC](https://discuss.elastic.co/t/how-to-check-mapping-field-not-have-any-value/326906 "2023-03-03T07:39:21Z")

</div>

Hi, I am trying to create a new field to calculate the duration, during the creation of the field I did not find any issue or error, but while refreshing the Discover page throwing the below error. Please see the bel…

---

## [How to create date bucket in dashboard](https://discuss.elastic.co/t/how-to-create-date-bucket-in-dashboard/326904)

<div class="topic-metadata">

**Author:** [@ikonrao](https://discuss.elastic.co/u/ikonrao)\
**Replies:** 0\
**Last updated:** [March 3, 2023, 4:56am UTC](https://discuss.elastic.co/t/how-to-create-date-bucket-in-dashboard/326904 "2023-03-03T04:56:07Z")

</div>

Hi, I have some records with date fields like Feb 27, 2023 Feb 25, 2023 Feb 11, 2023 Feb 4, 2023 Jan 26, 2023 Jan 18, 2023 Now while presenting these records in kibana dashboard , i need to show records from Jan …

---

## [But,how to hide add filter?](https://discuss.elastic.co/t/but-how-to-hide-add-filter/326549)

<div class="topic-metadata">

**Author:** [@quan\_w](https://discuss.elastic.co/u/quan_w)\
**Replies:** 2\
**Last updated:** [March 3, 2023, 4:42am UTC](https://discuss.elastic.co/t/but-how-to-hide-add-filter/326549 "2023-03-03T04:42:48Z")

</div>

Continuing the discussion from Show / Hide Global Filter Bar in Kibana:

---

## [Logstash close\_older in tail mode](https://discuss.elastic.co/t/logstash-close-older-in-tail-mode/326896)

<div class="topic-metadata">

**Author:** [@akassabi](https://discuss.elastic.co/u/akassabi)\
**Replies:** 7\
**Last updated:** [March 3, 2023, 4:26am UTC](https://discuss.elastic.co/t/logstash-close-older-in-tail-mode/326896 "2023-03-03T04:26:01Z")

</div>

Suppose we have an input file input.dat and we are reading it in Logstash in tail mode. We set close\_older to 10 minutes. My questions are: Is the close\_older setting deprecated? The docs say it is "retained for back…

[Previous page](https://discuss.elastic.co/c/elastic-stack/81.md?page=613)

[Next page](https://discuss.elastic.co/c/elastic-stack/81.md?page=615)
