# Elastic Stack

**URL:** https://discuss.elastic.co/c/elastic-stack/81.md?page=667

[Latest](https://discuss.elastic.co/latest.md) · [Categories](https://discuss.elastic.co/categories.md) · [Tags](https://discuss.elastic.co/tags.md)

**Page:** 668

---

## [Can an ID of an index be not null but empty?](https://discuss.elastic.co/t/can-an-id-of-an-index-be-not-null-but-empty/323167)

<div class="topic-metadata">

**Author:** [@Java2avaj](https://discuss.elastic.co/u/Java2avaj)\
**Replies:** 3\
**Last updated:** [January 14, 2023, 11:46am UTC](https://discuss.elastic.co/t/can-an-id-of-an-index-be-not-null-but-empty/323167 "2023-01-14T11:46:05Z")

</div>

Just a question if by default, an id of an index be empty string value “”? If yes, how to prevent from saving an empty id?

---

## [Plot a table based on aggregate key values](https://discuss.elastic.co/t/plot-a-table-based-on-aggregate-key-values/322635)

<div class="topic-metadata">

**Author:** [@Tukaram](https://discuss.elastic.co/u/Tukaram)\
**Replies:** 2\
**Last updated:** [January 14, 2023, 9:46am UTC](https://discuss.elastic.co/t/plot-a-table-based-on-aggregate-key-values/322635 "2023-01-14T09:46:35Z")

</div>

Hi and HNY! I am looking to put this kind of data every 30 minutes to Kibana under 1 index. data1- {key: 'key1', user: 'A', manager: 'C', cnt1: 2, cnt2:4} data2- {key: 'key2', user: 'B', manager: 'C', cnt1: 4, cnt2:5} …

---

## [Clarification on \`docs.deleted\` in regards to data deletion compliance requirements](https://discuss.elastic.co/t/clarification-on-docs-deleted-in-regards-to-data-deletion-compliance-requirements/323160)

<div class="topic-metadata">

**Author:** [@alee47](https://discuss.elastic.co/u/alee47)\
**Replies:** 1\
**Last updated:** [January 14, 2023, 9:26am UTC](https://discuss.elastic.co/t/clarification-on-docs-deleted-in-regards-to-data-deletion-compliance-requirements/323160 "2023-01-14T09:26:50Z")

</div>

My organization uses Elasticsearch to store and index information for one of our services. We have an internal compliance requirement to delete data whenever a user of our service requests their data to be deleted. In or…

---

## [Create visualize builder gauge using conditional value from document](https://discuss.elastic.co/t/create-visualize-builder-gauge-using-conditional-value-from-document/316371)

<div class="topic-metadata">

**Author:** [@carollyl](https://discuss.elastic.co/u/carollyl)\
**Replies:** 1\
**Last updated:** [October 24, 2022, 11:49am UTC](https://discuss.elastic.co/t/create-visualize-builder-gauge-using-conditional-value-from-document/316371 "2022-10-24T11:49:26Z")

</div>

I'd like to dynamically set the value for the gauge according to the source data. How do I access the source data that has a variable named 'func'. Appreciate your advice. if (params.\_source\['func'\] == 'secret1') { para…

---

## [Is it possible to remove the UUID appended by SLM policies to snapshot names?](https://discuss.elastic.co/t/is-it-possible-to-remove-the-uuid-appended-by-slm-policies-to-snapshot-names/323172)

<div class="topic-metadata">

**Author:** [@nvnsv](https://discuss.elastic.co/u/nvnsv)\
**Replies:** 0\
**Last updated:** [January 14, 2023, 4:21am UTC](https://discuss.elastic.co/t/is-it-possible-to-remove-the-uuid-appended-by-slm-policies-to-snapshot-names/323172 "2023-01-14T04:21:09Z")

</div>

Hello! I was able to get SLM implemented however, I saw that there is a UUID appended to each snapshot name. Is it possible to remove that UUID? my policy runs every four hours and its named to be exact to the second \<s…

---

## [Range Slider](https://discuss.elastic.co/t/range-slider/317068)

<div class="topic-metadata">

**Author:** [@linhz](https://discuss.elastic.co/u/linhz)\
**Replies:** 6\
**Last updated:** [October 24, 2022, 11:19am UTC](https://discuss.elastic.co/t/range-slider/317068 "2022-10-24T11:19:34Z")

</div>

Hi. Does the topic cover come with negative value for ranger slider. Anyone could share with me how to input the negative value or any documents? I have input a + value, but when input "-" it have the error status.

---

## [Signal status change time](https://discuss.elastic.co/t/signal-status-change-time/317301)

<div class="topic-metadata">

**Author:** [@Faycal\_B](https://discuss.elastic.co/u/Faycal_B)\
**Replies:** 0\
**Last updated:** [October 24, 2022, 9:12am UTC](https://discuss.elastic.co/t/signal-status-change-time/317301 "2022-10-24T09:12:35Z")

</div>

The signal api only return kibana.alert.workflow\_status field for the signal status change, is there a way to get a timestamp of the status change ?

---

## [Machine Learning (Anomaly Detection) Random Sampling Support](https://discuss.elastic.co/t/machine-learning-anomaly-detection-random-sampling-support/323158)

<div class="topic-metadata">

**Author:** [@BenB196](https://discuss.elastic.co/u/BenB196)\
**Replies:** 0\
**Last updated:** [January 13, 2023, 8:17pm UTC](https://discuss.elastic.co/t/machine-learning-anomaly-detection-random-sampling-support/323158 "2023-01-13T20:17:41Z")

</div>

Hi All, I was wondering if anyone knows if/how to use random sampling with machine learning anomaly detection? Use Case I would like to monitor data rates sent by various agents to various indices/data streams and wou…

---

## [Sign "+" was treated as wildcard in Elasticsearch API GET Search](https://discuss.elastic.co/t/sign-was-treated-as-wildcard-in-elasticsearch-api-get-search/323074)

<div class="topic-metadata">

**Author:** [@SooperTee](https://discuss.elastic.co/u/SooperTee)\
**Replies:** 2\
**Last updated:** [January 13, 2023, 6:20pm UTC](https://discuss.elastic.co/t/sign-was-treated-as-wildcard-in-elasticsearch-api-get-search/323074 "2023-01-13T18:20:07Z")

</div>

I was trying to access my Elasticsearch topic with API GET. please see below sample query. https://localhost:9200/my\_topic/\_search?pretty&q=trade.tradeType:"Delta +1" The problem with this search is that the result ret…

---

## [Logstash Plugin](https://discuss.elastic.co/t/logstash-plugin/323120)

<div class="topic-metadata">

**Author:** [@anik-27](https://discuss.elastic.co/u/anik-27)\
**Replies:** 8\
**Last updated:** [January 13, 2023, 5:25pm UTC](https://discuss.elastic.co/t/logstash-plugin/323120 "2023-01-13T17:25:38Z")

</div>

Hello friends, Is this possible to write a Logstash plugin for fetching data in Javascript just as we can do with Java ?

---

## [Log all queries from Kibana 8.3 with custom data](https://discuss.elastic.co/t/log-all-queries-from-kibana-8-3-with-custom-data/321424)

<div class="topic-metadata">

**Author:** [@Anthony\_Gaskins1](https://discuss.elastic.co/u/Anthony_Gaskins1)\
**Replies:** 0\
**Last updated:** [December 16, 2022, 5:50pm UTC](https://discuss.elastic.co/t/log-all-queries-from-kibana-8-3-with-custom-data/321424 "2022-12-16T17:50:29Z")

</div>

I want to make a plugin that captures all of the queries to elasticsearch and logs them with some custom information. How do I intercept the queries so I can add my info?

---

## [Docs discrepancy in 'Change the index name' vs filebeat.reference.yml](https://discuss.elastic.co/t/docs-discrepancy-in-change-the-index-name-vs-filebeat-reference-yml/323152)

<div class="topic-metadata">

**Author:** [@brsolomon](https://discuss.elastic.co/u/brsolomon)\
**Replies:** 0\
**Last updated:** [January 13, 2023, 3:58pm UTC](https://discuss.elastic.co/t/docs-discrepancy-in-change-the-index-name-vs-filebeat-reference-yml/323152 "2023-01-13T15:58:49Z")

</div>

From Change the index name | Filebeat Reference \[8.6\] | Elastic output.elasticsearch.index: "customname-%{\[agent.version\]}" setup.template.name: "customname" setup.template.pattern: "customname-%{\[agent.version\]}" From…

---

## [Color change based on field value instead of count](https://discuss.elastic.co/t/color-change-based-on-field-value-instead-of-count/323117)

<div class="topic-metadata">

**Author:** [@alytkowski](https://discuss.elastic.co/u/alytkowski)\
**Replies:** 1\
**Last updated:** [January 13, 2023, 3:27pm UTC](https://discuss.elastic.co/t/color-change-based-on-field-value-instead-of-count/323117 "2023-01-13T15:27:57Z")

</div>

I'm trying to create a visualization, which will allow me to show my data from a community created Beats - Processbeat. It's a monitoring of processes with statuses like "RUNNING" or "STOPPED". Now to the point, below i…

---

## [Index settings in elasticsearch 8+](https://discuss.elastic.co/t/index-settings-in-elasticsearch-8/323027)

<div class="topic-metadata">

**Author:** [@Idorasi\_Paul](https://discuss.elastic.co/u/Idorasi_Paul)\
**Replies:** 3\
**Last updated:** [January 13, 2023, 3:20pm UTC](https://discuss.elastic.co/t/index-settings-in-elasticsearch-8/323027 "2023-01-13T15:20:13Z")

</div>

Hello, from what I see, IndexSettings has a field of the same type called index. What is the difference if I set, for example, number\_of\_replicas like: index.number\_of\_replicas: 2 or directly: number\_of\_replicas: 2 ?

---

## [Query bool with must and should](https://discuss.elastic.co/t/query-bool-with-must-and-should/323135)

<div class="topic-metadata">

**Author:** [@sphawk](https://discuss.elastic.co/u/sphawk)\
**Replies:** 6\
**Last updated:** [January 13, 2023, 3:21pm UTC](https://discuss.elastic.co/t/query-bool-with-must-and-should/323135 "2023-01-13T15:21:57Z")

</div>

I'm trying to build a bool query. { "query": { "bool" : { "must" : \[ {"term": { "language": "es\_ES" }} \], "should": \[ { …

---

## [\[BUG\] Bug in logs related to Kafka connection](https://discuss.elastic.co/t/bug-bug-in-logs-related-to-kafka-connection/269625)

<div class="topic-metadata">

**Author:** [@dacamposol](https://discuss.elastic.co/u/dacamposol)\
**Replies:** 1\
**Last updated:** [January 13, 2023, 3:10pm UTC](https://discuss.elastic.co/t/bug-bug-in-logs-related-to-kafka-connection/269625 "2023-01-13T15:10:02Z")

</div>

Good afternoon everyone, I think that I have found a bug in the logs of Filebeat, version 7.12.0. I have a Kafka machine in a datacenter, let's call it Datacenter A, and I setup the Filebeat in another datacenter, in t…

---

## [No old data in developer tool, but data are present in discover](https://discuss.elastic.co/t/no-old-data-in-developer-tool-but-data-are-present-in-discover/323134)

<div class="topic-metadata">

**Author:** [@vetsolution](https://discuss.elastic.co/u/vetsolution)\
**Replies:** 3\
**Last updated:** [January 13, 2023, 2:34pm UTC](https://discuss.elastic.co/t/no-old-data-in-developer-tool-but-data-are-present-in-discover/323134 "2023-01-13T14:34:55Z")

</div>

Modified today Hello, When I use the elastic api, via curl or the developper tool. I cannot got data from some old indice. But if I use the discover feature of Kibana, it can get those data. Moreover, if I go from di…

---

## [Parse Elasticsearch json logs in filebeat](https://discuss.elastic.co/t/parse-elasticsearch-json-logs-in-filebeat/322533)

<div class="topic-metadata">

**Author:** [@qwinkler](https://discuss.elastic.co/u/qwinkler)\
**Replies:** 6\
**Last updated:** [January 13, 2023, 2:20pm UTC](https://discuss.elastic.co/t/parse-elasticsearch-json-logs-in-filebeat/322533 "2023-01-13T14:20:29Z")

</div>

Hello. I want to properly collect Elasticsearch logs. I have the following architecture. On the Linux node, I have Docker installed. I configured the Journald logging driver using official documentation (Journald loggin…

---

## [Need to more about store the logs on Hot node instead of warm node](https://discuss.elastic.co/t/need-to-more-about-store-the-logs-on-hot-node-instead-of-warm-node/323131)

<div class="topic-metadata">

**Author:** [@anushyaadam](https://discuss.elastic.co/u/anushyaadam)\
**Replies:** 3\
**Last updated:** [January 13, 2023, 2:16pm UTC](https://discuss.elastic.co/t/need-to-more-about-store-the-logs-on-hot-node-instead-of-warm-node/323131 "2023-01-13T14:16:42Z")

</div>

Hello Team, We would like to know about to store the data from Hot node instead of warm node. Normally the process was stored the data from hot node and warm node depends on ILM policies by 7days of retention period. H…

---

## [Searching through a document not knowing the path](https://discuss.elastic.co/t/searching-through-a-document-not-knowing-the-path/323132)

<div class="topic-metadata">

**Author:** [@Polala](https://discuss.elastic.co/u/Polala)\
**Replies:** 2\
**Last updated:** [January 13, 2023, 1:59pm UTC](https://discuss.elastic.co/t/searching-through-a-document-not-knowing-the-path/323132 "2023-01-13T13:59:03Z")

</div>

I want to search through a document and get data for Steven and all his children (so in this example James). Is there a way to do it not knowing the path for Steven - so it should be children.children.name - but what if…

---

## [Related to Logstash](https://discuss.elastic.co/t/related-to-logstash/323137)

<div class="topic-metadata">

**Author:** [@anik-27](https://discuss.elastic.co/u/anik-27)\
**Replies:** 0\
**Last updated:** [January 13, 2023, 1:51pm UTC](https://discuss.elastic.co/t/related-to-logstash/323137 "2023-01-13T13:51:19Z")

</div>

Hello friends I want to fetch some metrics data from the Vrops(VMware) api that includes following steps - Make a post request with login credentials to get the authentication token Use that authentication token with …

---

## [Search by newly added wildcard field to existing index](https://discuss.elastic.co/t/search-by-newly-added-wildcard-field-to-existing-index/323122)

<div class="topic-metadata">

**Author:** [@bkelastic](https://discuss.elastic.co/u/bkelastic)\
**Replies:** 1\
**Last updated:** [January 13, 2023, 1:43pm UTC](https://discuss.elastic.co/t/search-by-newly-added-wildcard-field-to-existing-index/323122 "2023-01-13T13:43:16Z")

</div>

I have in mappings "fooField": { "type": "double" } I want to search by this field using wildcard query, so I added wildcard multifield "fooField": { "type": "double", "fields": {…

---

## [Kibana - Table without time](https://discuss.elastic.co/t/kibana-table-without-time/323112)

<div class="topic-metadata">

**Author:** [@Chloe\_Boissavy](https://discuss.elastic.co/u/Chloe_Boissavy)\
**Replies:** 6\
**Last updated:** [January 13, 2023, 1:09pm UTC](https://discuss.elastic.co/t/kibana-table-without-time/323112 "2023-01-13T13:09:47Z")

</div>

Hello, I have Kibana 8.3.3. I have firewall data so data with IP address. In the same indices, I have list of IP address. I would like to create a table with IP address from firewall (src IP) and compare it with the …

---

## [UNASSIGNED ALLOCATION\_FAILED](https://discuss.elastic.co/t/unassigned-allocation-failed/323128)

<div class="topic-metadata">

**Author:** [@INS](https://discuss.elastic.co/u/INS)\
**Replies:** 1\
**Last updated:** [January 13, 2023, 12:28pm UTC](https://discuss.elastic.co/t/unassigned-allocation-failed/323128 "2023-01-13T12:28:27Z")

</div>

What can we do in below case? { "note" : "No shard was specified in the explain API request, so this response explains a randomly chosen unassigned shard. There may be other unassigned shards in this cluster which can…

---

## [Wrong timestamp in Alerting new elastic](https://discuss.elastic.co/t/wrong-timestamp-in-alerting-new-elastic/321286)

<div class="topic-metadata">

**Author:** [@diegomarting](https://discuss.elastic.co/u/diegomarting)\
**Replies:** 2\
**Last updated:** [December 16, 2022, 1:35pm UTC](https://discuss.elastic.co/t/wrong-timestamp-in-alerting-new-elastic/321286 "2022-12-16T13:35:07Z")

</div>

Hello, I am migrating some alerts to te new version of Elastic Stack. I created the rules and the actions to send a message to a Google Webhook when an error log is ingested, but when I formatted the message with the mu…

---

## [KQL Syntax](https://discuss.elastic.co/t/kql-syntax/323031)

<div class="topic-metadata">

**Author:** [@Shashank02](https://discuss.elastic.co/u/Shashank02)\
**Replies:** 5\
**Last updated:** [January 13, 2023, 12:03pm UTC](https://discuss.elastic.co/t/kql-syntax/323031 "2023-01-13T12:03:47Z")

</div>

Does anybody know how to use dev tools? Because I'm thinking about updating the filter of a dashboard directly through python and I don't know how to do it. So, I am thinking of using KQL syntax. 2 questions I have is: d…

---

## [Filebeat-\>Kafka-\>Logstash-\>Elasticsearch fails for system.auth: "Provided Grok expressions do not match field value"](https://discuss.elastic.co/t/filebeat-kafka-logstash-elasticsearch-fails-for-system-auth-provided-grok-expressions-do-not-match-field-value/323068)

<div class="topic-metadata">

**Author:** [@brsolomon](https://discuss.elastic.co/u/brsolomon)\
**Replies:** 11\
**Last updated:** [January 13, 2023, 11:46am UTC](https://discuss.elastic.co/t/filebeat-kafka-logstash-elasticsearch-fails-for-system-auth-provided-grok-expressions-do-not-match-field-value/323068 "2023-01-13T11:46:31Z")

</div>

The ingest scenario below perplexingly fails for the Filebeat system module with the auth fileset with Provided Grok expressions do not match field value. It doesn't matter what the event is from /var/log/secure; every s…

---

## [Where does Elasticsearch store/read logs](https://discuss.elastic.co/t/where-does-elasticsearch-store-read-logs/323119)

<div class="topic-metadata">

**Author:** [@Ibicf](https://discuss.elastic.co/u/Ibicf)\
**Replies:** 1\
**Last updated:** [January 13, 2023, 11:36am UTC](https://discuss.elastic.co/t/where-does-elasticsearch-store-read-logs/323119 "2023-01-13T11:36:41Z")

</div>

Greetings for eveyone! I'm newbie to Elasticsearch as much as in programming in general and I don't understand some things. I have a little Django-project for practise and I install Elasticsearch into project. I'm also…

---

## [Elasticsearch - check if the parameter is not empty](https://discuss.elastic.co/t/elasticsearch-check-if-the-parameter-is-not-empty/323096)

<div class="topic-metadata">

**Author:** [@Java2avaj](https://discuss.elastic.co/u/Java2avaj)\
**Replies:** 3\
**Last updated:** [January 13, 2023, 11:29am UTC](https://discuss.elastic.co/t/elasticsearch-check-if-the-parameter-is-not-empty/323096 "2023-01-13T11:29:58Z")

</div>

In SQL, we can perform the following in the where clause: SELECT \* FROM tbl WHERE :parameter \<\> '' OR :parameter is not null Is this possible in Elasticsearch to check if the input parameter/value is not null or empty?…

---

## [Kibana index data binding in the Vega Tree graph is difficult](https://discuss.elastic.co/t/kibana-index-data-binding-in-the-vega-tree-graph-is-difficult/323103)

<div class="topic-metadata">

**Author:** [@Dimple.P](https://discuss.elastic.co/u/Dimple.P)\
**Replies:** 1\
**Last updated:** [January 13, 2023, 11:23am UTC](https://discuss.elastic.co/t/kibana-index-data-binding-in-the-vega-tree-graph-is-difficult/323103 "2023-01-13T11:23:33Z")

</div>

Static data was successfully connected to the Vega-V5 tree graph, however when I attempted to attach Kibana index data, it failed. Is it feasible to link the index data from Kibana to the Vega Tree graph? Eg: my\_index \[…

[Previous page](https://discuss.elastic.co/c/elastic-stack/81.md?page=666)

[Next page](https://discuss.elastic.co/c/elastic-stack/81.md?page=668)
