# Latest

**URL:** https://discuss.elastic.co/latest.md?page=710

[Latest](https://discuss.elastic.co/latest.md) · [Categories](https://discuss.elastic.co/categories.md) · [Tags](https://discuss.elastic.co/tags.md)

**Page:** 711

---

## [Send logs from filebeat to elastic search](https://discuss.elastic.co/t/send-logs-from-filebeat-to-elastic-search/330078)

<div class="topic-metadata">

**Author:** [@Abdolah\_Said](https://discuss.elastic.co/u/Abdolah_Said)\
**Replies:** 0\
**Last updated:** [April 16, 2023, 6:53am UTC](https://discuss.elastic.co/t/send-logs-from-filebeat-to-elastic-search/330078 "2023-04-16T06:53:10Z")

</div>

i'm using winlogbeat to send log to logstash and i store logs in file path \[ /var/log/file.log \] and i have file beat in this server who send logs from the path to elasticsearch the problem is the elasticsearch show logs…

---

## [One saved Discover search without "Time"](https://discuss.elastic.co/t/one-saved-discover-search-without-time/328258)

<div class="topic-metadata">

**Author:** [@ppic](https://discuss.elastic.co/u/ppic)\
**Replies:** 3\
**Last updated:** [April 15, 2023, 5:41pm UTC](https://discuss.elastic.co/t/one-saved-discover-search-without-time/328258 "2023-04-15T17:41:02Z")

</div>

Hello, In a dashboard, I need to display a table with 2 fields, with text as it is in Discover. I found it was possible with a saved search in Discover, and then in the dashboard: Add from library the saved search. …

---

## [Query questions (autocomplete)](https://discuss.elastic.co/t/query-questions-autocomplete/330047)

<div class="topic-metadata">

**Author:** [@tallboy](https://discuss.elastic.co/u/tallboy)\
**Replies:** 0\
**Last updated:** [April 14, 2023, 10:02pm UTC](https://discuss.elastic.co/t/query-questions-autocomplete/330047 "2023-04-14T22:02:17Z")

</div>

Hello, I am trying to craft a query which will allow a realtime search dropdown: My search data has 3 columns: name (text) alternate\_names (array of text) description (text) The only column which shows in the dro…

---

## [Reduce load time of Kibana-8.6.2](https://discuss.elastic.co/t/reduce-load-time-of-kibana-8-6-2/330065)

<div class="topic-metadata">

**Author:** [@akansha.agarwal1](https://discuss.elastic.co/u/akansha.agarwal1)\
**Replies:** 0\
**Last updated:** [April 15, 2023, 12:51pm UTC](https://discuss.elastic.co/t/reduce-load-time-of-kibana-8-6-2/330065 "2023-04-15T12:51:34Z")

</div>

hi I am using Elastic stack 8.6.2 Average time to load dashboard is close to 13sec with a single user. Please note that visualizations consists of a mix of Kibana lens & Vega lite. Most of the time is consumed in load…

---

## [How can I get several search results on a huge document? (like a book or a big article)](https://discuss.elastic.co/t/how-can-i-get-several-search-results-on-a-huge-document-like-a-book-or-a-big-article/329885)

<div class="topic-metadata">

**Author:** [@Eduard\_mart](https://discuss.elastic.co/u/Eduard_mart)\
**Replies:** 3\
**Last updated:** [April 15, 2023, 9:47am UTC](https://discuss.elastic.co/t/how-can-i-get-several-search-results-on-a-huge-document-like-a-book-or-a-big-article/329885 "2023-04-15T09:47:35Z")

</div>

Is it possible to use elasticsearch to get several search results when preforming search on big documents? Like a book or huge articles.. So I get not only the article itself but also all the positions of relevant data…

---

## [Error - circuit\_breaking\_exception, \[parent\] Data too large](https://discuss.elastic.co/t/error-circuit-breaking-exception-parent-data-too-large/330055)

<div class="topic-metadata">

**Author:** [@Bugsbee](https://discuss.elastic.co/u/Bugsbee)\
**Replies:** 1\
**Last updated:** [April 15, 2023, 7:39am UTC](https://discuss.elastic.co/t/error-circuit-breaking-exception-parent-data-too-large/330055 "2023-04-15T07:39:39Z")

</div>

Hi Community Whenever i try to search in dashboard i keep on getting this error. any idea how to fix this? I confirm my storage is fine . how to fix this polease Request error: circuit\_breaking\_exception, \[parent\] D…

---

## [Elasticsearch - search by two fields. And how to use one text with Text type and custom analyzer](https://discuss.elastic.co/t/elasticsearch-search-by-two-fields-and-how-to-use-one-text-with-text-type-and-custom-analyzer/330054)

<div class="topic-metadata">

**Author:** [@Eduard\_mart](https://discuss.elastic.co/u/Eduard_mart)\
**Replies:** 0\
**Last updated:** [April 15, 2023, 6:04am UTC](https://discuss.elastic.co/t/elasticsearch-search-by-two-fields-and-how-to-use-one-text-with-text-type-and-custom-analyzer/330054 "2023-04-15T06:04:49Z")

</div>

There is a set of data that I want to fit into Elasticsearch. Product description - a few paragraphs. I have a lot of them - about 250mln. At the same time I want to remove stop words, hunspell and a couple of other thi…

---

## [Loading Kibana dashboards using Metricbeat through HELM charts](https://discuss.elastic.co/t/loading-kibana-dashboards-using-metricbeat-through-helm-charts/329414)

<div class="topic-metadata">

**Author:** [@RoshRagh](https://discuss.elastic.co/u/RoshRagh)\
**Replies:** 0\
**Last updated:** [April 5, 2023, 10:33am UTC](https://discuss.elastic.co/t/loading-kibana-dashboards-using-metricbeat-through-helm-charts/329414 "2023-04-05T10:33:10Z")

</div>

Hi, I am looking to load the default dashboards that come pre-built in Kibana by setting up a Kibana endpoint in metricbeat configuration. The "setup.kibana" option is not really available in the official metricbeat hel…

---

## [How to create proper alert for multiple hits?](https://discuss.elastic.co/t/how-to-create-proper-alert-for-multiple-hits/329432)

<div class="topic-metadata">

**Author:** [@jackshan](https://discuss.elastic.co/u/jackshan)\
**Replies:** 1\
**Last updated:** [April 15, 2023, 5:10am UTC](https://discuss.elastic.co/t/how-to-create-proper-alert-for-multiple-hits/329432 "2023-04-15T05:10:41Z")

</div>

I have a scenario where i am matching two metadata along with "level" = "error". I am setting the time to last 15 minutes for running the query. The monitor does capture what i want, but when there are multiple hits in …

---

## [Metricbeat - INDEX LIFECYCLE ERROR](https://discuss.elastic.co/t/metricbeat-index-lifecycle-error/328149)

<div class="topic-metadata">

**Author:** [@Swathi12](https://discuss.elastic.co/u/Swathi12)\
**Replies:** 1\
**Last updated:** [April 15, 2023, 5:07am UTC](https://discuss.elastic.co/t/metricbeat-index-lifecycle-error/328149 "2023-04-15T05:07:41Z")

</div>

Hi i have an indices which the ILM get an error. Could you please help me here ? "lifecycle": { "name": "metricbeat", "rollover\_alias": "metricbeat" }, If more information is needed ple…

---

## [Kibana Alerts USAGE](https://discuss.elastic.co/t/kibana-alerts-usage/329467)

<div class="topic-metadata">

**Author:** [@Rossana](https://discuss.elastic.co/u/Rossana)\
**Replies:** 1\
**Last updated:** [April 15, 2023, 5:04am UTC](https://discuss.elastic.co/t/kibana-alerts-usage/329467 "2023-04-15T05:04:40Z")

</div>

Hi, I am looking a way to know which is the usage of every alert in my cluster. Elastic has any predefine dashboard for this? or there is an index that has this information? Thanks,

---

## [Remove Processor return an illegal\_argument\_exception error](https://discuss.elastic.co/t/remove-processor-return-an-illegal-argument-exception-error/329470)

<div class="topic-metadata">

**Author:** [@Anh\_Nguyen](https://discuss.elastic.co/u/Anh_Nguyen)\
**Replies:** 0\
**Last updated:** [April 6, 2023, 2:47am UTC](https://discuss.elastic.co/t/remove-processor-return-an-illegal-argument-exception-error/329470 "2023-04-06T02:47:37Z")

</div>

I want to remove some duplicated fileds' value by using remove processor in ingest pipeline. I using Elastic Agent to collect log. The problem is I always got an error in output is: "field \[field\_name\] not present as par…

---

## [Difference of timing](https://discuss.elastic.co/t/difference-of-timing/329493)

<div class="topic-metadata">

**Author:** [@Haytham\_Shammout](https://discuss.elastic.co/u/Haytham_Shammout)\
**Replies:** 1\
**Last updated:** [April 15, 2023, 5:02am UTC](https://discuss.elastic.co/t/difference-of-timing/329493 "2023-04-15T05:02:04Z")

</div>

Hello, I faced an issue that when I send the data from the data source to logstash and elastic the data reach Kibana with a specific time but when Kibana display the records the time on it is delayed for 7 minutes as be…

---

## [\_id field not aggregatable after Elastic migration to 8.6.2](https://discuss.elastic.co/t/id-field-not-aggregatable-after-elastic-migration-to-8-6-2/329490)

<div class="topic-metadata">

**Author:** [@Sandeep\_Raju](https://discuss.elastic.co/u/Sandeep_Raju)\
**Replies:** 1\
**Last updated:** [April 15, 2023, 4:59am UTC](https://discuss.elastic.co/t/id-field-not-aggregatable-after-elastic-migration-to-8-6-2/329490 "2023-04-15T04:59:53Z")

</div>

Hi all, I migrated my Elastic & kibana versions from 7.9 to 7.17 to 8.6.2. I continued to use same dashboards and data. But in new ES version, I'm getting below issue for \_id field. I noticed that in old version, …

---

## [Watcher's transform adds smaller number of the values](https://discuss.elastic.co/t/watchers-transform-adds-smaller-number-of-the-values/329497)

<div class="topic-metadata">

**Author:** [@ddoroshenko](https://discuss.elastic.co/u/ddoroshenko)\
**Replies:** 0\
**Last updated:** [April 6, 2023, 9:07am UTC](https://discuss.elastic.co/t/watchers-transform-adds-smaller-number-of-the-values/329497 "2023-04-06T09:07:48Z")

</div>

Hi, I'd like to make watcher which will write to a certain index unique values of the particular field. A part of my query is { "query" : { "bool": { "must": \[ { "wildcard": { "field": { "value"…

---

## [Kibana Dashboards in MS Teams](https://discuss.elastic.co/t/kibana-dashboards-in-ms-teams/329530)

<div class="topic-metadata">

**Author:** [@htunahan](https://discuss.elastic.co/u/htunahan)\
**Replies:** 1\
**Last updated:** [April 15, 2023, 4:57am UTC](https://discuss.elastic.co/t/kibana-dashboards-in-ms-teams/329530 "2023-04-15T04:57:29Z")

</div>

Hi Guys, I have already prepared some dashboard with Kibana and now I would like to show them in MS Teams if it is possible. I have tried to add a website to my Teams channel and put my dashboard URL but it didn't work.…

---

## [KIbana automatic-reports post url changes](https://discuss.elastic.co/t/kibana-automatic-reports-post-url-changes/329667)

<div class="topic-metadata">

**Author:** [@ElasticLiver](https://discuss.elastic.co/u/ElasticLiver)\
**Replies:** 1\
**Last updated:** [April 15, 2023, 4:46am UTC](https://discuss.elastic.co/t/kibana-automatic-reports-post-url-changes/329667 "2023-04-15T04:46:31Z")

</div>

Hi, in older version of kibana 7.x the post url for reporting was very long, but you could manipulate the string to filter de data, so you put the names of the hosts in an array and iterate trouhg it and use one dashboa…

---

## [Saved visualisation on kibana pods](https://discuss.elastic.co/t/saved-visualisation-on-kibana-pods/329690)

<div class="topic-metadata">

**Author:** [@Sibasish\_Behera](https://discuss.elastic.co/u/Sibasish_Behera)\
**Replies:** 1\
**Last updated:** [April 15, 2023, 4:45am UTC](https://discuss.elastic.co/t/saved-visualisation-on-kibana-pods/329690 "2023-04-15T04:45:14Z")

</div>

Is there any way to save predefined visualisation for kibana running as a kubernetes pod for eg i can make make a metric visualisation on number of request to my service but i want it to be a default visualisation when…

---

## [How to filter a different field when a value is selected in another field in Kibana?](https://discuss.elastic.co/t/how-to-filter-a-different-field-when-a-value-is-selected-in-another-field-in-kibana/329762)

<div class="topic-metadata">

**Author:** [@stramzik](https://discuss.elastic.co/u/stramzik)\
**Replies:** 1\
**Last updated:** [April 15, 2023, 4:33am UTC](https://discuss.elastic.co/t/how-to-filter-a-different-field-when-a-value-is-selected-in-another-field-in-kibana/329762 "2023-04-15T04:33:18Z")

</div>

hi, Lets says I have the below index PUT /testindex/ { "mappings": { "properties": { "field1": { "type": "keyword" }, "Data": { "type": "keyword" } } } } POST /testindex/\_…

---

## [Kibana server.publicBaseUrl](https://discuss.elastic.co/t/kibana-server-publicbaseurl/328444)

<div class="topic-metadata">

**Author:** [@MahithaSarala](https://discuss.elastic.co/u/MahithaSarala)\
**Replies:** 1\
**Last updated:** [April 15, 2023, 4:05am UTC](https://discuss.elastic.co/t/kibana-server-publicbaseurl/328444 "2023-04-15T04:05:17Z")

</div>

Hi Team , Deployed kibana 8.5.3 through ECK Facing issue like Kibana server.publicBaseUrl Please find kibana manifest file apiVersion: kibana.k8s.elastic.co/v1 kind: Kibana metadata: name: kibana spec: version: 8.…

---

## [Kibana Node High Load](https://discuss.elastic.co/t/kibana-node-high-load/329882)

<div class="topic-metadata">

**Author:** [@Sandeep\_Raju](https://discuss.elastic.co/u/Sandeep_Raju)\
**Replies:** 1\
**Last updated:** [April 15, 2023, 4:02am UTC](https://discuss.elastic.co/t/kibana-node-high-load/329882 "2023-04-15T04:02:20Z")

</div>

Hi all, I"m using Kibana 8.6.2 version cluster with 5 nodes. To handle the query load, I'm using 5 nodes. But ultimately, I have to host Kibana in only 1 node. So even when querying is high and there is a crash for ES…

---

## [TSVB plot to project the rate of a counter against the auto time scale](https://discuss.elastic.co/t/tsvb-plot-to-project-the-rate-of-a-counter-against-the-auto-time-scale/329890)

<div class="topic-metadata">

**Author:** [@rvadiga](https://discuss.elastic.co/u/rvadiga)\
**Replies:** 1\
**Last updated:** [April 15, 2023, 3:59am UTC](https://discuss.elastic.co/t/tsvb-plot-to-project-the-rate-of-a-counter-against-the-auto-time-scale/329890 "2023-04-15T03:59:17Z")

</div>

Hi I wanted to create a TSVB for plotting a counter value against the time period. Timestamp is set to 'auto' so that Kibana can plot any number of data points. Now, i want to define a math aggregation to plot a rate …

---

## [Convert Date of birth into Age in KQL](https://discuss.elastic.co/t/convert-date-of-birth-into-age-in-kql/329894)

<div class="topic-metadata">

**Author:** [@Sam\_Armstrong](https://discuss.elastic.co/u/Sam_Armstrong)\
**Replies:** 1\
**Last updated:** [April 15, 2023, 3:54am UTC](https://discuss.elastic.co/t/convert-date-of-birth-into-age-in-kql/329894 "2023-04-15T03:54:55Z")

</div>

Hi there I currently have data stored as 2022-01-25 and am wanting to get out my records in brackets of say 10 yrs. Example: Bar/Pie Chart showing 0-7 yrs - X Clients 8-15 yrs - X Clients 16-25 - X Clients 26-35 - …

---

## [Kibana - Node JS gets terminated without leaving trace](https://discuss.elastic.co/t/kibana-node-js-gets-terminated-without-leaving-trace/329922)

<div class="topic-metadata">

**Author:** [@kiril\_penkov](https://discuss.elastic.co/u/kiril_penkov)\
**Replies:** 1\
**Last updated:** [April 15, 2023, 3:39am UTC](https://discuss.elastic.co/t/kibana-node-js-gets-terminated-without-leaving-trace/329922 "2023-04-15T03:39:30Z")

</div>

Hi, We have an On-Premise clustered deployment on version 7.16.3 of Elasticsearch and Kibana. Our issue is that sometimes, on random the Node.js gets terminated without leaving any trace in Windows or Kibana logs and we…

---

## [Do I have to restart Elasticsearch cluster if I replace CA certificate?](https://discuss.elastic.co/t/do-i-have-to-restart-elasticsearch-cluster-if-i-replace-ca-certificate/329927)

<div class="topic-metadata">

**Author:** [@Petr.Simik](https://discuss.elastic.co/u/Petr.Simik)\
**Replies:** 1\
**Last updated:** [April 15, 2023, 3:29am UTC](https://discuss.elastic.co/t/do-i-have-to-restart-elasticsearch-cluster-if-i-replace-ca-certificate/329927 "2023-04-15T03:29:35Z")

</div>

Hi, I have elasticsearch 8.6 My certificate is going to expire so I followed the process where restart of cluster is required however I have tested just simple file replacement of CA cert and it seems to work even w…

---

## [TSVB Axis names](https://discuss.elastic.co/t/tsvb-axis-names/329979)

<div class="topic-metadata">

**Author:** [@rvadiga](https://discuss.elastic.co/u/rvadiga)\
**Replies:** 1\
**Last updated:** [April 15, 2023, 1:35am UTC](https://discuss.elastic.co/t/tsvb-axis-names/329979 "2023-04-15T01:35:07Z")

</div>

Hi Could anyone please suggest any method to add custom axis names in TSVB chart? I wanted to give suitable names for both Y-axis and X-Axis. I do not see any options in Elasticsearch 8.6.2. Regards Venkatesh

---

## [Drop\_fields](https://discuss.elastic.co/t/drop-fields/330045)

<div class="topic-metadata">

**Author:** [@y34rz3r0](https://discuss.elastic.co/u/y34rz3r0)\
**Replies:** 2\
**Last updated:** [April 15, 2023, 12:00am UTC](https://discuss.elastic.co/t/drop-fields/330045 "2023-04-15T00:00:40Z")

</div>

Hello! I've just started learning ELK and I'm having some confusion with filebeat's drop\_fields processor. My configuration: filebeat.inputs: - type: log paths: - /mnt/var/log/ovpnagent.log fields\_unde…

---

## [Elasticsearch keyword not generated](https://discuss.elastic.co/t/elasticsearch-keyword-not-generated/330043)

<div class="topic-metadata">

**Author:** [@pjangam](https://discuss.elastic.co/u/pjangam)\
**Replies:** 0\
**Last updated:** [April 14, 2023, 9:20pm UTC](https://discuss.elastic.co/t/elasticsearch-keyword-not-generated/330043 "2023-04-14T21:20:01Z")

</div>

I have Elasticsearch entry with text field value as 14-Apr-2023 20:44:46.693 INFO \[pool-2-thread-24\] com.xyz.log \[app\_id:uuid\] calling execute-task with url=https://example.com/api/applications/uuid/tasks/TASK\_NAME/exec…

---

## [How to implement a search by multiple fields and support whitespace, symbols, case insensitive](https://discuss.elastic.co/t/how-to-implement-a-search-by-multiple-fields-and-support-whitespace-symbols-case-insensitive/330030)

<div class="topic-metadata">

**Author:** [@Juan\_Manuel](https://discuss.elastic.co/u/Juan_Manuel)\
**Replies:** 4\
**Last updated:** [April 14, 2023, 8:00pm UTC](https://discuss.elastic.co/t/how-to-implement-a-search-by-multiple-fields-and-support-whitespace-symbols-case-insensitive/330030 "2023-04-14T20:00:12Z")

</div>

I have an index with many fields and I want to be able to search by some of them at the same time, and this search should support partial match (in any position), case insensitive, support some symbols. Example of my in…

---

## [Find Unique values of field while using match query on other field](https://discuss.elastic.co/t/find-unique-values-of-field-while-using-match-query-on-other-field/330037)

<div class="topic-metadata">

**Author:** [@emi\_rose](https://discuss.elastic.co/u/emi_rose)\
**Replies:** 0\
**Last updated:** [April 14, 2023, 7:02pm UTC](https://discuss.elastic.co/t/find-unique-values-of-field-while-using-match-query-on-other-field/330037 "2023-04-14T19:02:34Z")

</div>

Hello, I would like find all unique set values of field3 that roll up under a specific value of field1 and a specific value of field2. I've tried collapsing on field3 but it gives me the error that no mapping was found…

[Previous page](https://discuss.elastic.co/latest.md?page=709)

[Next page](https://discuss.elastic.co/latest.md?page=711)
