# Elastic Stack

**URL:** https://discuss.elastic.co/c/elastic-stack/81.md?page=668

[Latest](https://discuss.elastic.co/latest.md) · [Categories](https://discuss.elastic.co/categories.md) · [Tags](https://discuss.elastic.co/tags.md)

**Page:** 669

---

## [How to Hide the Zero records using JSON Input in Metric Dashboard](https://discuss.elastic.co/t/how-to-hide-the-zero-records-using-json-input-in-metric-dashboard/323013)

<div class="topic-metadata">

**Author:** [@Maruthappan\_Muthu](https://discuss.elastic.co/u/Maruthappan_Muthu)\
**Replies:** 5\
**Last updated:** [January 13, 2023, 10:21am UTC](https://discuss.elastic.co/t/how-to-hide-the-zero-records-using-json-input-in-metric-dashboard/323013 "2023-01-13T10:21:12Z")

</div>

My document gets the data on irregular interval.The field name is Ex.,SensexValue. There can be multiple values on the field (SensexValue) in every interval, with different timestamp(milliseconds) and some interval the f…

---

## [Logstash input imap plugin with attachment not decoding](https://discuss.elastic.co/t/logstash-input-imap-plugin-with-attachment-not-decoding/323113)

<div class="topic-metadata">

**Author:** [@anjuls](https://discuss.elastic.co/u/anjuls)\
**Replies:** 0\
**Last updated:** [January 13, 2023, 9:58am UTC](https://discuss.elastic.co/t/logstash-input-imap-plugin-with-attachment-not-decoding/323113 "2023-01-13T09:58:03Z")

</div>

Hi, I am trying to fetch emails with attachments from Office 365 using logstash and putting them on Kafka topic. During the process, I got to understand the logstash-imap-input plugin is unable to process it. When the a…

---

## [How to check details of version\_conflicts when wait\_for\_completion=false in update\_by\_query?](https://discuss.elastic.co/t/how-to-check-details-of-version-conflicts-when-wait-for-completion-false-in-update-by-query/323110)

<div class="topic-metadata">

**Author:** [@bkelastic](https://discuss.elastic.co/u/bkelastic)\
**Replies:** 0\
**Last updated:** [January 13, 2023, 9:40am UTC](https://discuss.elastic.co/t/how-to-check-details-of-version-conflicts-when-wait-for-completion-false-in-update-by-query/323110 "2023-01-13T09:40:30Z")

</div>

After executing \_update\_by\_query?conflicts=proceed&wait\_for\_completion=false I want to check details so I call GET \_tasks?detailed=true&actions=\*byquery and I receive response with number of "version\_conflicts" : {n…

---

## [Filtering by date field (other than the timestamp) in Kibana dashboard](https://discuss.elastic.co/t/filtering-by-date-field-other-than-the-timestamp-in-kibana-dashboard/322989)

<div class="topic-metadata">

**Author:** [@SaraAlshamsi](https://discuss.elastic.co/u/SaraAlshamsi)\
**Replies:** 3\
**Last updated:** [January 13, 2023, 8:56am UTC](https://discuss.elastic.co/t/filtering-by-date-field-other-than-the-timestamp-in-kibana-dashboard/322989 "2023-01-13T08:56:35Z")

</div>

Hello everyone, I have an index with several fields and more than 1 time field. For examle: Field names: "end\_date", "name", "sequence" & "start\_date". The mapping: { "check\_date\_filter": { "mappings": { …

---

## [How to know which element in the array is chosen by the fuzzysearch](https://discuss.elastic.co/t/how-to-know-which-element-in-the-array-is-chosen-by-the-fuzzysearch/323105)

<div class="topic-metadata">

**Author:** [@Heckler\_GlobalOperat](https://discuss.elastic.co/u/Heckler_GlobalOperat)\
**Replies:** 0\
**Last updated:** [January 13, 2023, 8:30am UTC](https://discuss.elastic.co/t/how-to-know-which-element-in-the-array-is-chosen-by-the-fuzzysearch/323105 "2023-01-13T08:30:59Z")

</div>

Hello, I have a tricky case and want to consult the experts here. We store our user info in Elasticsearch, an user may have different name aliases, all stored in a "names" array like below "names" : \[ { …

---

## [Last\_terminated\_reason metric is not collected](https://discuss.elastic.co/t/last-terminated-reason-metric-is-not-collected/323101)

<div class="topic-metadata">

**Author:** [@hyungsun\_lim](https://discuss.elastic.co/u/hyungsun_lim)\
**Replies:** 0\
**Last updated:** [January 13, 2023, 8:03am UTC](https://discuss.elastic.co/t/last-terminated-reason-metric-is-not-collected/323101 "2023-01-13T08:03:47Z")

</div>

I want to collect 'kubernetes.container.status.last\_terminated\_reason' metric in document (Kubernetes fields | Metricbeat Reference \[8.6\] | Elastic) So i use metricbeat(v7.10.1) to collect k8s event data. metricbeat.co…

---

## [Kibana visualization error after restoring the snapshot](https://discuss.elastic.co/t/kibana-visualization-error-after-restoring-the-snapshot/317265)

<div class="topic-metadata">

**Author:** [@not\_correct](https://discuss.elastic.co/u/not_correct)\
**Replies:** 2\
**Last updated:** [October 23, 2022, 7:34pm UTC](https://discuss.elastic.co/t/kibana-visualization-error-after-restoring-the-snapshot/317265 "2022-10-23T19:34:12Z")

</div>

Hi, I have restored ElaticSearch snapsot that been managed by another person, I get the followng error when it comes to kibana dashboards Text fields are not optimised for operations that require per-document field da…

---

## [Elasticsearch Urdu Analyzer plug-in](https://discuss.elastic.co/t/elasticsearch-urdu-analyzer-plug-in/323088)

<div class="topic-metadata">

**Author:** [@Armeen\_Ashraf\_Khan\_F](https://discuss.elastic.co/u/Armeen_Ashraf_Khan_F)\
**Replies:** 0\
**Last updated:** [January 13, 2023, 6:32am UTC](https://discuss.elastic.co/t/elasticsearch-urdu-analyzer-plug-in/323088 "2023-01-13T06:32:50Z")

</div>

I am a Data Science Masters student doing thesis in Information Retrieval for my native language Urdu. Urdu is like Arabic in textual form. Currently, Urdu Analyzer has not been created in elasticsearch and I want to cre…

---

## [Logstash are not running properly](https://discuss.elastic.co/t/logstash-are-not-running-properly/323002)

<div class="topic-metadata">

**Author:** [@yasar](https://discuss.elastic.co/u/yasar)\
**Replies:** 7\
**Last updated:** [January 13, 2023, 4:26am UTC](https://discuss.elastic.co/t/logstash-are-not-running-properly/323002 "2023-01-13T04:26:42Z")

</div>

Hi team, We are trying to get the live logs from DEV Environment for testing.. But after started the Logstash (7.16.1) service, it through a error. Please check the below error. at RUBY.\<module:LibC\>(/usr/shar…

---

## [Kibana\_task\_manager ALLOCATION\_FAILED](https://discuss.elastic.co/t/kibana-task-manager-allocation-failed/323081)

<div class="topic-metadata">

**Author:** [@kohkaw](https://discuss.elastic.co/u/kohkaw)\
**Replies:** 0\
**Last updated:** [January 13, 2023, 3:09am UTC](https://discuss.elastic.co/t/kibana-task-manager-allocation-failed/323081 "2023-01-13T03:09:27Z")

</div>

Hi everyone. I am encountering an error on Elasticsearch 7.17.3 deployed with k8s where the shard assignment fails for Kibana\_task\_manager. GET \_cat/shards?v&h=index,shard,prirep,state,unassigned.reason&s=state:asc in…

---

## [Add "Save Query" as one of Kibana sub-feature privileges](https://discuss.elastic.co/t/add-save-query-as-one-of-kibana-sub-feature-privileges/319017)

<div class="topic-metadata">

**Author:** [@bandodkarD](https://discuss.elastic.co/u/bandodkarD)\
**Replies:** 4\
**Last updated:** [November 18, 2022, 8:15am UTC](https://discuss.elastic.co/t/add-save-query-as-one-of-kibana-sub-feature-privileges/319017 "2022-11-18T08:15:38Z")

</div>

Hi Team, Is this feature available in recent versions of Kibana? # Add "Save Query" as one of Kibana sub-feature privileges If not is there a way for users with Read Only access to save query?

---

## [Elastic Agent Container - Secrets Management](https://discuss.elastic.co/t/elastic-agent-container-secrets-management/323067)

<div class="topic-metadata">

**Author:** [@MoreCowBell](https://discuss.elastic.co/u/MoreCowBell)\
**Replies:** 0\
**Last updated:** [January 12, 2023, 11:28pm UTC](https://discuss.elastic.co/t/elastic-agent-container-secrets-management/323067 "2023-01-12T23:28:10Z")

</div>

I'm looking to further harden the security of passing secrets into the elastic agent configuration at runtime. I'm wondering if the following would work. Scenario: Integration: Azure Active Directory Sensitive Values: …

---

## [How are write requests handled to an index in the RED state](https://discuss.elastic.co/t/how-are-write-requests-handled-to-an-index-in-the-red-state/323044)

<div class="topic-metadata">

**Author:** [@alee47](https://discuss.elastic.co/u/alee47)\
**Replies:** 2\
**Last updated:** [January 12, 2023, 10:20pm UTC](https://discuss.elastic.co/t/how-are-write-requests-handled-to-an-index-in-the-red-state/323044 "2023-01-12T22:20:52Z")

</div>

Hello, My organization uses Elasticsearch to power one of our services and regularly receive write requests into our cluster. We use the routing parameter on all search and write requests, so they are directed to a sing…

---

## [Is it possible to count elements of an array of two levels? array of arrays](https://discuss.elastic.co/t/is-it-possible-to-count-elements-of-an-array-of-two-levels-array-of-arrays/323047)

<div class="topic-metadata">

**Author:** [@jcornejo](https://discuss.elastic.co/u/jcornejo)\
**Replies:** 2\
**Last updated:** [January 12, 2023, 9:40pm UTC](https://discuss.elastic.co/t/is-it-possible-to-count-elements-of-an-array-of-two-levels-array-of-arrays/323047 "2023-01-12T21:40:46Z")

</div>

I need to count the elements of the campaign\_promotions.promotion\_prices array it's possible? "hits" : \[ { "\_index" : "dev\_scrap\_campaigns", "\_type" : "\_doc", "\_id" : "2t0k7oQBF4RU85fFCPX\_…

---

## [Missing authentication credentials when visiting localhost:9200 after running elasticsearch.bat](https://discuss.elastic.co/t/missing-authentication-credentials-when-visiting-localhost-9200-after-running-elasticsearch-bat/323018)

<div class="topic-metadata">

**Author:** [@Arthur\_Medforth](https://discuss.elastic.co/u/Arthur_Medforth)\
**Replies:** 2\
**Last updated:** [January 12, 2023, 9:21pm UTC](https://discuss.elastic.co/t/missing-authentication-credentials-when-visiting-localhost-9200-after-running-elasticsearch-bat/323018 "2023-01-12T21:21:30Z")

</div>

{"error":{"root\_cause":\[{"type":"security\_exception","reason":"missing authentication credentials for REST request \[/\]","header":{"WWW-Authenticate":\["Basic realm="security" charset="UTF-8"","ApiKey"\]}}\],"type":"security…

---

## [ElasticSearch 7.15.1 / Unhappy Cluster](https://discuss.elastic.co/t/elasticsearch-7-15-1-unhappy-cluster/322974)

<div class="topic-metadata">

**Author:** [@Devin\_Acosta](https://discuss.elastic.co/u/Devin_Acosta)\
**Replies:** 5\
**Last updated:** [January 12, 2023, 9:19pm UTC](https://discuss.elastic.co/t/elasticsearch-7-15-1-unhappy-cluster/322974 "2023-01-12T21:19:20Z")

</div>

I am trying to troubleshoot an Elasticsearch 7.15.1 cluster that has 3 master nodes, and 30+ data nodes. Recently we have seen where data nodes are complaining about "master not discovered yet" after the nodes have been …

---

## [Kibana can't connect to package directory](https://discuss.elastic.co/t/kibana-cant-connect-to-package-directory/316919)

<div class="topic-metadata">

**Author:** [@jpedroza2k20](https://discuss.elastic.co/u/jpedroza2k20)\
**Replies:** 5\
**Last updated:** [October 21, 2022, 1:53pm UTC](https://discuss.elastic.co/t/kibana-cant-connect-to-package-directory/316919 "2022-10-21T13:53:01Z")

</div>

I have seen this same issue on the forums twice (English and French) and there is no resolution listed. I get the following error: I can access the URL from the server in question (self hosted stack) and there is no …

---

## [How to make a blank space query?](https://discuss.elastic.co/t/how-to-make-a-blank-space-query/323062)

<div class="topic-metadata">

**Author:** [@sanil](https://discuss.elastic.co/u/sanil)\
**Replies:** 0\
**Last updated:** [January 12, 2023, 8:57pm UTC](https://discuss.elastic.co/t/how-to-make-a-blank-space-query/323062 "2023-01-12T20:57:33Z")

</div>

Hey everyone, I am trying to make an Elasticsearch request with a blank space as the query. The query should literally be a blank space as such: " ". For example, the query looks like this : {query": ( ) OR (\* ). Howe…

---

## [Compute a ratio of one-to-many sum aggregated values](https://discuss.elastic.co/t/compute-a-ratio-of-one-to-many-sum-aggregated-values/323058)

<div class="topic-metadata">

**Author:** [@fzar](https://discuss.elastic.co/u/fzar)\
**Replies:** 0\
**Last updated:** [January 12, 2023, 8:12pm UTC](https://discuss.elastic.co/t/compute-a-ratio-of-one-to-many-sum-aggregated-values/323058 "2023-01-12T20:12:21Z")

</div>

hey, I am trying to compute a ratio of one-to-many sum aggregated values - obtained via a filters aggregation - against a top-level sum aggregated value without luck. Basically I want to compute a score for all docs (su…

---

## [Error making http request](https://discuss.elastic.co/t/error-making-http-request/323056)

<div class="topic-metadata">

**Author:** [@Myagmarsuren-a](https://discuss.elastic.co/u/Myagmarsuren-a)\
**Replies:** 0\
**Last updated:** [January 12, 2023, 7:19pm UTC](https://discuss.elastic.co/t/error-making-http-request/323056 "2023-01-12T19:19:09Z")

</div>

I have issue. I added elastic-agent as fleet server. Also i installed elasticsearch and kibana using docker-compose. Then i wanted to monitor my kubernetes cluster with elastic agent with kubernetes integration in it. Wh…

---

## [ES is allocating indexes that are hot to nodes in the cold tier](https://discuss.elastic.co/t/es-is-allocating-indexes-that-are-hot-to-nodes-in-the-cold-tier/322972)

<div class="topic-metadata">

**Author:** [@Russell\_Fulton](https://discuss.elastic.co/u/Russell_Fulton)\
**Replies:** 9\
**Last updated:** [January 12, 2023, 7:07pm UTC](https://discuss.elastic.co/t/es-is-allocating-indexes-that-are-hot-to-nodes-in-the-cold-tier/322972 "2023-01-12T19:07:20Z")

</div>

I can't figure out how to diagnose what is happening here. I am using a hot/warm/cold data tier model but ES keeps allocating indexes to my overloaded cold tier when they are still in the hot phase (being actively writt…

---

## [Bucket\_path for array key](https://discuss.elastic.co/t/bucket-path-for-array-key/323052)

<div class="topic-metadata">

**Author:** [@rbrc](https://discuss.elastic.co/u/rbrc)\
**Replies:** 0\
**Last updated:** [January 12, 2023, 6:44pm UTC](https://discuss.elastic.co/t/bucket-path-for-array-key/323052 "2023-01-12T18:44:45Z")

</div>

I'm doing some agg queries against indexes where each doc has a locationId, and using a terms agg on that locationId to bucket the results. The problem is I want the NAME for that location, so I'm also doing a filter agg…

---

## [Event creation and processing times differ](https://discuss.elastic.co/t/event-creation-and-processing-times-differ/323051)

<div class="topic-metadata">

**Author:** [@alex\_96](https://discuss.elastic.co/u/alex_96)\
**Replies:** 0\
**Last updated:** [January 12, 2023, 5:45pm UTC](https://discuss.elastic.co/t/event-creation-and-processing-times-differ/323051 "2023-01-12T17:45:27Z")

</div>

Hi, let's talk about the config first: elk 7.17.5 (8 cpu, 20 ram, 2.5T disk space) and another host with filebeat 7.17.8 with zeek and suricata module enabled. I am using suricata and zeek as ids, i noticed that suricat…

---

## [Cisco IOS Elastic-agent no longer retrieving data](https://discuss.elastic.co/t/cisco-ios-elastic-agent-no-longer-retrieving-data/323050)

<div class="topic-metadata">

**Author:** [@rsaeks](https://discuss.elastic.co/u/rsaeks)\
**Replies:** 0\
**Last updated:** [January 12, 2023, 5:31pm UTC](https://discuss.elastic.co/t/cisco-ios-elastic-agent-no-longer-retrieving-data/323050 "2023-01-12T17:31:23Z")

</div>

After the recent update to the Cisco 1.11.0 elastic agent, data is no longer being processed from the connected Cisco devices. In version 1.10.0 this was working. When looking at netstat on the device that should be rec…

---

## [Aggregate document and "cumulate" fields](https://discuss.elastic.co/t/aggregate-document-and-cumulate-fields/323046)

<div class="topic-metadata">

**Author:** [@Fariddev](https://discuss.elastic.co/u/Fariddev)\
**Replies:** 0\
**Last updated:** [January 12, 2023, 5:00pm UTC](https://discuss.elastic.co/t/aggregate-document-and-cumulate-fields/323046 "2023-01-12T17:00:15Z")

</div>

Hi, i would like to know if it's possible to aggregate documents and cumulate other fields in an array like this : Documents : { "type": "fruit", "article": "apple", "price": 5 } { "type": "fruit", "article"…

---

## [Filebeat ERROR x509: certificate signed by unknown authority](https://discuss.elastic.co/t/filebeat-error-x509-certificate-signed-by-unknown-authority/322861)

<div class="topic-metadata">

**Author:** [@vassiliy.vins](https://discuss.elastic.co/u/vassiliy.vins)\
**Replies:** 24\
**Last updated:** [January 12, 2023, 4:38pm UTC](https://discuss.elastic.co/t/filebeat-error-x509-certificate-signed-by-unknown-authority/322861 "2023-01-12T16:38:15Z")

</div>

Hi! in my filebeat.yaml I configured output.elasticsearch: section like this tyoutput.elasticsearch: # Array of hosts to connect to. hosts: \["10.142.77.174:9200"\] # Protocol - either \`http\` (default) or \`https\`…

---

## [Space and data retention question](https://discuss.elastic.co/t/space-and-data-retention-question/322403)

<div class="topic-metadata">

**Author:** [@MKirby](https://discuss.elastic.co/u/MKirby)\
**Replies:** 11\
**Last updated:** [January 12, 2023, 4:20pm UTC](https://discuss.elastic.co/t/space-and-data-retention-question/322403 "2023-01-12T16:20:47Z")

</div>

Good Afternoon and Happy New Year to all my Elastic Stack friends and Guru's. I have been having an issue with my Elasticsearch and syslog retention. In the /var/lib/elasticsearch/log folder I have 4.3 Terrabytes of sp…

---

## [Rollup index name with date math](https://discuss.elastic.co/t/rollup-index-name-with-date-math/317161)

<div class="topic-metadata">

**Author:** [@mikhatanu](https://discuss.elastic.co/u/mikhatanu)\
**Replies:** 0\
**Last updated:** [October 21, 2022, 3:30am UTC](https://discuss.elastic.co/t/rollup-index-name-with-date-math/317161 "2022-10-21T03:30:19Z")

</div>

Hello, i tried to create rollup index in rollup job with rollup index name using date math, example of index name: my-log-%{+YYYY.MM.dd}, but kibana returned "Request failed with a 500 error. runtime\_exception: Could not…

---

## [Unable to access nested fields in vegalite](https://discuss.elastic.co/t/unable-to-access-nested-fields-in-vegalite/322551)

<div class="topic-metadata">

**Author:** [@pridhvi\_raj](https://discuss.elastic.co/u/pridhvi_raj)\
**Replies:** 1\
**Last updated:** [January 12, 2023, 3:03pm UTC](https://discuss.elastic.co/t/unable-to-access-nested-fields-in-vegalite/322551 "2023-01-12T15:03:17Z")

</div>

I am working on a dataset it contains application\_Id, status of each application and date columns and for each application\_Id representing its status as(start,declined,inProgress). I need to get the latest row of each a…

---

## [Exclude logs on kibana](https://discuss.elastic.co/t/exclude-logs-on-kibana/322968)

<div class="topic-metadata">

**Author:** [@khadija70](https://discuss.elastic.co/u/khadija70)\
**Replies:** 2\
**Last updated:** [January 12, 2023, 2:22pm UTC](https://discuss.elastic.co/t/exclude-logs-on-kibana/322968 "2023-01-12T14:22:15Z")

</div>

Hi , I need to exclude some logs , and stop showing them on kibana , those logs are based on a filter like : aut . All the logs containing a word on the filter have not to be shown on kibana . Could you please provi…

[Previous page](https://discuss.elastic.co/c/elastic-stack/81.md?page=667)

[Next page](https://discuss.elastic.co/c/elastic-stack/81.md?page=669)
