# \#none

**URL:** https://discuss.elastic.co/tag/none.md?no_tags=true&page=239

[Latest](https://discuss.elastic.co/latest.md) · [Categories](https://discuss.elastic.co/categories.md) · [Tags](https://discuss.elastic.co/tags.md)

**Page:** 240

---

## [Whether Kibana inbuilt "viewer" role can be restricted only to view the Analytics feature for a user](https://discuss.elastic.co/t/whether-kibana-inbuilt-viewer-role-can-be-restricted-only-to-view-the-analytics-feature-for-a-user/351434)

<div class="topic-metadata">

**Author:** [@Subrahmanyam\_Veerank](https://discuss.elastic.co/u/Subrahmanyam_Veerank)\
**Replies:** 1\
**Last updated:** [January 25, 2024, 4:30am UTC](https://discuss.elastic.co/t/whether-kibana-inbuilt-viewer-role-can-be-restricted-only-to-view-the-analytics-feature-for-a-user/351434 "2024-01-25T04:30:53Z")

</div>

I am working in default namespace and i want to create an user with viewer role. Whether Kibana inbuilt "viewer" role can be restricted only to view the Analytics feature of kibana for a user and i dont want to create a…

---

## [Create Helper Functions within Pipeline](https://discuss.elastic.co/t/create-helper-functions-within-pipeline/351581)

<div class="topic-metadata">

**Author:** [@michael\_c\_michael](https://discuss.elastic.co/u/michael_c_michael)\
**Replies:** 3\
**Last updated:** [January 24, 2024, 11:54pm UTC](https://discuss.elastic.co/t/create-helper-functions-within-pipeline/351581 "2024-01-24T23:54:40Z")

</div>

I have a function in my pipeline that does some math and another that does some translation. Is there a way to create a function like in python, so that I don't have to retype the same code everytime I want to do this op…

---

## [Trying to find the path to the nested found text](https://discuss.elastic.co/t/trying-to-find-the-path-to-the-nested-found-text/351752)

<div class="topic-metadata">

**Author:** [@warrengoldman](https://discuss.elastic.co/u/warrengoldman)\
**Replies:** 1\
**Last updated:** [January 24, 2024, 9:50pm UTC](https://discuss.elastic.co/t/trying-to-find-the-path-to-the-nested-found-text/351752 "2024-01-24T21:50:15Z")

</div>

What I need that I have NOT figured out I would like to get the path(s) to the found text. Where the path would be book name -\> chapter number -\> verse number (which is a sibling to verses.text) What I did figure out …

---

## [Running an ESQL query periodally and output the result into an index](https://discuss.elastic.co/t/running-an-esql-query-periodally-and-output-the-result-into-an-index/351481)

<div class="topic-metadata">

**Author:** [@lizozom](https://discuss.elastic.co/u/lizozom)\
**Replies:** 8\
**Last updated:** [January 24, 2024, 8:52pm UTC](https://discuss.elastic.co/t/running-an-esql-query-periodally-and-output-the-result-into-an-index/351481 "2024-01-24T20:52:38Z")

</div>

I have built an ESQL query that calculates today's inventory of products. I want to run it daily and output the result into a different index. I thought of using Transforms, could I use an ESQL query there? If not, I …

---

## [Kibana Heatmap - Filters Axis Side Effect](https://discuss.elastic.co/t/kibana-heatmap-filters-axis-side-effect/349398)

<div class="topic-metadata">

**Author:** [@Ryan\_Berry1](https://discuss.elastic.co/u/Ryan_Berry1)\
**Replies:** 3\
**Last updated:** [January 24, 2024, 6:41pm UTC](https://discuss.elastic.co/t/kibana-heatmap-filters-axis-side-effect/349398 "2024-01-24T18:41:58Z")

</div>

Hello, My Kibana visualization has an unintended side effect. Some background: my heatmap shows red or green boxes based on the number of failed tests (\>= 1 failed test gives red box). The horizontal axis represents th…

---

## [Kibana Missing Share Option Setup Guide Prevents Options From Displaying Potentially](https://discuss.elastic.co/t/kibana-missing-share-option-setup-guide-prevents-options-from-displaying-potentially/351657)

<div class="topic-metadata">

**Author:** [@Ryan\_Downey](https://discuss.elastic.co/u/Ryan_Downey)\
**Replies:** 3\
**Last updated:** [January 24, 2024, 5:18pm UTC](https://discuss.elastic.co/t/kibana-missing-share-option-setup-guide-prevents-options-from-displaying-potentially/351657 "2024-01-24T17:18:42Z")

</div>

Just putting this out there if any other users run into this issue as this may be a possible solution. A user was unable to use the Share feature in the Discover section to export logs even though they have Superuser an…

---

## [Data not getting synced properly from SQL to elastic](https://discuss.elastic.co/t/data-not-getting-synced-properly-from-sql-to-elastic/351742)

<div class="topic-metadata">

**Author:** [@abhishek\_agarwal](https://discuss.elastic.co/u/abhishek_agarwal)\
**Replies:** 2\
**Last updated:** [January 24, 2024, 5:10pm UTC](https://discuss.elastic.co/t/data-not-getting-synced-properly-from-sql-to-elastic/351742 "2024-01-24T17:10:09Z")

</div>

I am syncing data from sql to elastic and in filter in the code block I am appending to map eg features but what is happening is that when I am running the bulk sql query ,not all features are getting appended to each in…

---

## [How to get only matched value for field that has multiple values](https://discuss.elastic.co/t/how-to-get-only-matched-value-for-field-that-has-multiple-values/351667)

<div class="topic-metadata">

**Author:** [@elasticfan1](https://discuss.elastic.co/u/elasticfan1)\
**Replies:** 2\
**Last updated:** [January 24, 2024, 4:57pm UTC](https://discuss.elastic.co/t/how-to-get-only-matched-value-for-field-that-has-multiple-values/351667 "2024-01-24T16:57:29Z")

</div>

Let's say I have a document with a type as you go field that has multiple values. tags : \["cool beans", "great job", hello there"\] I do a phrase prefix search with the term "coo". I want to display the user "cool beans…

---

## [Upgrade Elasticsearch 8.2 to 8.x leads to ssl problems](https://discuss.elastic.co/t/upgrade-elasticsearch-8-2-to-8-x-leads-to-ssl-problems/351724)

<div class="topic-metadata">

**Author:** [@Ljapunov](https://discuss.elastic.co/u/Ljapunov)\
**Replies:** 1\
**Last updated:** [January 24, 2024, 3:14pm UTC](https://discuss.elastic.co/t/upgrade-elasticsearch-8-2-to-8-x-leads-to-ssl-problems/351724 "2024-01-24T15:14:38Z")

</div>

Hi everyone, I tried to upgrade two different clusters containing 3 or 5 nodes. Both are running elasticsearch 8.2.0 and I tried upgrading to different versions 8.11.4, 8.5.3 and 8.4.3. But all attempts failed with the …

---

## [ILM to delete only doc counts in a simple indice elasticsearch](https://discuss.elastic.co/t/ilm-to-delete-only-doc-counts-in-a-simple-indice-elasticsearch/351714)

<div class="topic-metadata">

**Author:** [@Musled](https://discuss.elastic.co/u/Musled)\
**Replies:** 2\
**Last updated:** [January 24, 2024, 1:59pm UTC](https://discuss.elastic.co/t/ilm-to-delete-only-doc-counts-in-a-simple-indice-elasticsearch/351714 "2024-01-24T13:59:24Z")

</div>

Hi there ! I'm working on a lifecycle for my indices in elasticsearch. To put you in context, I recover the logs of 20 applications with the ELK stack but I notice that my storage disk is filling up very quickly. Ther…

---

## [Exception caught while applying mutate filter {:exception=\>"Could not set field 'product' on object 'x' to value 'y'.This is probably due to trying to set a field like \[foo\]\[bar\] = someValuewhen \[foo\] is not either a map or a string"}](https://discuss.elastic.co/t/exception-caught-while-applying-mutate-filter-exception-could-not-set-field-product-on-object-x-to-value-y-this-is-probably-due-to-trying-to-set-a-field-like-foo-bar-somevaluewhen-foo-is-not-either-a-map-or-a-string/351707)

<div class="topic-metadata">

**Author:** [@mwitsas](https://discuss.elastic.co/u/mwitsas)\
**Replies:** 1\
**Last updated:** [January 24, 2024, 1:22pm UTC](https://discuss.elastic.co/t/exception-caught-while-applying-mutate-filter-exception-could-not-set-field-product-on-object-x-to-value-y-this-is-probably-due-to-trying-to-set-a-field-like-foo-bar-somevaluewhen-foo-is-not-either-a-map-or-a-string/351707 "2024-01-24T13:22:41Z")

</div>

When attempting to rename fields as in the following example: mutate { rename =\> { "vendor" =\> "\[abc\]\[vendor\]" "vendor\_product" =\> "\[abc\]\[vendor\]\[product\]" "vendor\_product\_version" =\> "\[abc\]\[vend…

---

## [Problem with an IF statement not working](https://discuss.elastic.co/t/problem-with-an-if-statement-not-working/351608)

<div class="topic-metadata">

**Author:** [@FaisalParkar](https://discuss.elastic.co/u/FaisalParkar)\
**Replies:** 10\
**Last updated:** [January 24, 2024, 10:15am UTC](https://discuss.elastic.co/t/problem-with-an-if-statement-not-working/351608 "2024-01-24T10:15:42Z")

</div>

Hello Everyone, I hope someone is able to assist. I am running ELK stack 8.11.3 and am using Logstash to ingest Syslogs in a CEF format. I have everything working and it works nicely, however I want to add an IF stateme…

---

## [Elasticsearch unstable cluster](https://discuss.elastic.co/t/elasticsearch-unstable-cluster/350157)

<div class="topic-metadata">

**Author:** [@elasticexpert](https://discuss.elastic.co/u/elasticexpert)\
**Replies:** 26\
**Last updated:** [January 24, 2024, 9:55am UTC](https://discuss.elastic.co/t/elasticsearch-unstable-cluster/350157 "2024-01-24T09:55:18Z")

</div>

Hey! I have an elastic cluster (version 8.11.1, upgraded from 8.5.3 but the problem is before the upgrade) with 10 datanode physical servers that is unstable (node are disconnecting and connecting automaticly) with two r…

---

## [\[elastic\_agent\]\[error\] Cannot checkin in with fleet-server, retrying](https://discuss.elastic.co/t/elastic-agent-error-cannot-checkin-in-with-fleet-server-retrying/351595)

<div class="topic-metadata">

**Author:** [@AnkurYogi](https://discuss.elastic.co/u/AnkurYogi)\
**Replies:** 1\
**Last updated:** [January 23, 2024, 8:34am UTC](https://discuss.elastic.co/t/elastic-agent-error-cannot-checkin-in-with-fleet-server-retrying/351595 "2024-01-23T08:34:58Z")

</div>

Hi everyone All my agents are showing offline and I am not sure why. Here are some logs and info to start the discussion..! { "log.level": "info", "@timestamp": "2024-01-23T06:21:39.097Z", "message": "ApiKey fail…

---

## [Logs proccessed via Filebeat](https://discuss.elastic.co/t/logs-proccessed-via-filebeat/351698)

<div class="topic-metadata">

**Author:** [@Pavlo\_Pylypiv](https://discuss.elastic.co/u/Pavlo_Pylypiv)\
**Replies:** 0\
**Last updated:** [January 24, 2024, 8:58am UTC](https://discuss.elastic.co/t/logs-proccessed-via-filebeat/351698 "2024-01-24T08:58:51Z")

</div>

Hi! I would like to ask you what filebeat does with logs, which are not related to module? For example, I have Barracuda WAF and Barracuda FW running through Filebeat Barracuda Module (it works only for WAF). Will filebe…

---

## [Elasticsearch Cluster health is RED](https://discuss.elastic.co/t/elasticsearch-cluster-health-is-red/351622)

<div class="topic-metadata">

**Author:** [@Debasis\_Mallick](https://discuss.elastic.co/u/Debasis_Mallick)\
**Replies:** 3\
**Last updated:** [January 24, 2024, 8:02am UTC](https://discuss.elastic.co/t/elasticsearch-cluster-health-is-red/351622 "2024-01-24T08:02:17Z")

</div>

Hi Team, We had Elasticsearch with two node and due to some infra issues the server went down . Once it become online , I started the service and it was successful. But while checking the log showing below error. Could…

---

## [Normalize data on time interval](https://discuss.elastic.co/t/normalize-data-on-time-interval/351556)

<div class="topic-metadata">

**Author:** [@venturieffect](https://discuss.elastic.co/u/venturieffect)\
**Replies:** 2\
**Last updated:** [January 24, 2024, 7:34am UTC](https://discuss.elastic.co/t/normalize-data-on-time-interval/351556 "2024-01-24T07:34:26Z")

</div>

Hello Everyone, This might seem stupid but it's an issue I can't find a definitive answer and I'm not really sure how to search for it, so I might ask here: I'm trying to visualize server requests rate over time by sen…

---

## [Seeking Guidance on Implementing Retry Mechanism and Handling Delayed PubSub Messages in Bulk Document Operations](https://discuss.elastic.co/t/seeking-guidance-on-implementing-retry-mechanism-and-handling-delayed-pubsub-messages-in-bulk-document-operations/351627)

<div class="topic-metadata">

**Author:** [@Ivelin\_Yanev](https://discuss.elastic.co/u/Ivelin_Yanev)\
**Replies:** 3\
**Last updated:** [January 24, 2024, 7:27am UTC](https://discuss.elastic.co/t/seeking-guidance-on-implementing-retry-mechanism-and-handling-delayed-pubsub-messages-in-bulk-document-operations/351627 "2024-01-24T07:27:04Z")

</div>

Dear all, I hope this message finds you well. I am currently immersed in the implementation of bulk operations for handling documents. The process involves receiving PubSub messages and dynamically generating correspon…

---

## [Logstash cannot upload to https Elasticsearch](https://discuss.elastic.co/t/logstash-cannot-upload-to-https-elasticsearch/351601)

<div class="topic-metadata">

**Author:** [@cisupport-zkb](https://discuss.elastic.co/u/cisupport-zkb)\
**Replies:** 13\
**Last updated:** [January 24, 2024, 7:13am UTC](https://discuss.elastic.co/t/logstash-cannot-upload-to-https-elasticsearch/351601 "2024-01-24T07:13:11Z")

</div>

Hi everyone, I'm having troubles on uploading data from a csv file to https Elasticsearch, using Logstash. This is the logstash.conf configured: input { file { path =\> "${pwd}/some-metrics.csv" fil…

---

## [API for Managing Synthetic monitoring](https://discuss.elastic.co/t/api-for-managing-synthetic-monitoring/350819)

<div class="topic-metadata">

**Author:** [@Raj\_Jikadra](https://discuss.elastic.co/u/Raj_Jikadra)\
**Replies:** 6\
**Last updated:** [January 24, 2024, 2:58am UTC](https://discuss.elastic.co/t/api-for-managing-synthetic-monitoring/350819 "2024-01-24T02:58:10Z")

</div>

To manage Monitors created via Synthetic monitoring, we can use @elastic/synthetics package, as per the code of @elastic/synthetics , it internally uses API to communicate with Kibana regarding monitor changes. I want t…

---

## [How to retrieve data from a data stream using Elasticsearch API keys](https://discuss.elastic.co/t/how-to-retrieve-data-from-a-data-stream-using-elasticsearch-api-keys/351343)

<div class="topic-metadata">

**Author:** [@YUUTA.INOUE-JPN](https://discuss.elastic.co/u/YUUTA.INOUE-JPN)\
**Replies:** 2\
**Last updated:** [January 24, 2024, 12:41am UTC](https://discuss.elastic.co/t/how-to-retrieve-data-from-a-data-stream-using-elasticsearch-api-keys/351343 "2024-01-24T00:41:54Z")

</div>

Hello from Japan I have a question for you respected engineers. I would like to know about Elasticsearch API keys. I am using Winlogbeat (Ver8.11.1) to send Windows log information to Elasticsearch (Ver8.11.1). I wou…

---

## [Monitoring specific processes via Elastic Agent?](https://discuss.elastic.co/t/monitoring-specific-processes-via-elastic-agent/350037)

<div class="topic-metadata">

**Author:** [@jerrac](https://discuss.elastic.co/u/jerrac)\
**Replies:** 3\
**Last updated:** [January 23, 2024, 11:31pm UTC](https://discuss.elastic.co/t/monitoring-specific-processes-via-elastic-agent/350037 "2024-01-23T23:31:21Z")

</div>

Does anyone have a good method for monitoring that specific processes are running, even if said processes are not in the top N cpu/ram usage group? The System integration lets you monitor the Top N processes. You can li…

---

## [Align date histogram to 6:00 instead of 0:00](https://discuss.elastic.co/t/align-date-histogram-to-6-00-instead-of-0-00/351436)

<div class="topic-metadata">

**Author:** [@allatrue](https://discuss.elastic.co/u/allatrue)\
**Replies:** 1\
**Last updated:** [January 23, 2024, 9:48pm UTC](https://discuss.elastic.co/t/align-date-histogram-to-6-00-instead-of-0-00/351436 "2024-01-23T21:48:23Z")

</div>

Hello all! I'm trying to create a bar chart in Lens. It should aggregate some metrics using 8h buckets and use starting point at 6:00/14:00/22:00. I configured date histogram for horizontal axis, set minimum interval to…

---

## [Elastic Search causing major page memory errors on Azure Kubernetes (AKS)](https://discuss.elastic.co/t/elastic-search-causing-major-page-memory-errors-on-azure-kubernetes-aks/351670)

<div class="topic-metadata">

**Author:** [@DavidDean](https://discuss.elastic.co/u/DavidDean)\
**Replies:** 2\
**Last updated:** [January 23, 2024, 9:35pm UTC](https://discuss.elastic.co/t/elastic-search-causing-major-page-memory-errors-on-azure-kubernetes-aks/351670 "2024-01-23T21:35:18Z")

</div>

ES version: 7.17.5.1 Hosting: Azure Kubernetes (AKS) Kubernetes: 1.24.9 Virtual machine: D8ads v5 (8 vCPUs, 32 GB RAM) Virtual machine OS: Ubuntu 18.04.6 LTS Prometheus is reporting very high rates of major memory p…

---

## [Funcionamiento pipelines](https://discuss.elastic.co/t/funcionamiento-pipelines/351553)

<div class="topic-metadata">

**Author:** [@marotaal](https://discuss.elastic.co/u/marotaal)\
**Replies:** 4\
**Last updated:** [January 23, 2024, 9:24pm UTC](https://discuss.elastic.co/t/funcionamiento-pipelines/351553 "2024-01-23T21:24:27Z")

</div>

Hola Estoy generando un laboratorio para la recogida de logs (Apache, Sophos,.....) Si tengo dos ficheros de apache (access y error) como especifico que cada fichero utilice su pipeline. filebeat-7.17.15-apache-access…

---

## [FULL SCREEN mode](https://discuss.elastic.co/t/full-screen-mode/351435)

<div class="topic-metadata">

**Author:** [@Charan\_Kumar\_reddy](https://discuss.elastic.co/u/Charan_Kumar_reddy)\
**Replies:** 1\
**Last updated:** [January 23, 2024, 9:15pm UTC](https://discuss.elastic.co/t/full-screen-mode/351435 "2024-01-23T21:15:19Z")

</div>

Hi, Is there a way to set "Full screen" mode as default for a dashboard? The goal is that every time we call the dashboard, it will open in full screen mode, without having to click on the button. Thanks

---

## [Cant create a data view on fresh kibana deployment on k8s](https://discuss.elastic.co/t/cant-create-a-data-view-on-fresh-kibana-deployment-on-k8s/351663)

<div class="topic-metadata">

**Author:** [@kAs1m](https://discuss.elastic.co/u/kAs1m)\
**Replies:** 1\
**Last updated:** [January 23, 2024, 8:30pm UTC](https://discuss.elastic.co/t/cant-create-a-data-view-on-fresh-kibana-deployment-on-k8s/351663 "2024-01-23T20:30:52Z")

</div>

I've deployed elasticsearch:8.5.1, fluent-bit:2.2.1 and kibana:8.5.1 via helm charts on my kubernetes cluster. When I login in kibana web interface and go to Analytics - Discover, this is the page I'm ending with: i.po…

---

## [Error reading empty line from CSV file with CSV codec](https://discuss.elastic.co/t/error-reading-empty-line-from-csv-file-with-csv-codec/351635)

<div class="topic-metadata">

**Author:** [@tsegars](https://discuss.elastic.co/u/tsegars)\
**Replies:** 2\
**Last updated:** [January 23, 2024, 7:59pm UTC](https://discuss.elastic.co/t/error-reading-empty-line-from-csv-file-with-csv-codec/351635 "2024-01-23T19:59:08Z")

</div>

My input CSV files will have empty lines interspersed in them. The CSV codec decoder generates the following error when encountering an empty line: \[ERROR\]\[filewatch.tailmode.handlers.grow\]\[main\]\[62dd5eb2b6763ff5522ed54…

---

## [Failed parsing date from field Oracle alert log](https://discuss.elastic.co/t/failed-parsing-date-from-field-oracle-alert-log/351590)

<div class="topic-metadata">

**Author:** [@Prabhu\_Athithan](https://discuss.elastic.co/u/Prabhu_Athithan)\
**Replies:** 19\
**Last updated:** [January 23, 2024, 7:00pm UTC](https://discuss.elastic.co/t/failed-parsing-date-from-field-oracle-alert-log/351590 "2024-01-23T19:00:26Z")

</div>

Failed parsing date from field {:field=\>"timestamp", :value=\>"%{year} %{month} %{monthday} %{time}", :exception=\>"Invalid format: "%{year} %{month} %{monthday} %{t..."", :config\_parsers=\>"yyyy MMM dd HH:mm:ss", :config\_l…

---

## [Help in capturing E2E timestamp from raw logs](https://discuss.elastic.co/t/help-in-capturing-e2e-timestamp-from-raw-logs/351335)

<div class="topic-metadata">

**Author:** [@Anurag101](https://discuss.elastic.co/u/Anurag101)\
**Replies:** 5\
**Last updated:** [January 23, 2024, 5:41pm UTC](https://discuss.elastic.co/t/help-in-capturing-e2e-timestamp-from-raw-logs/351335 "2024-01-23T17:41:55Z")

</div>

Hi All, I am new to ELK and am trying to achieve a real time monitoring framework which captures E2E timestamp of an ansync logback application. The ask is to capture the timestamp corresponding to a unique ID in the l…

[Previous page](https://discuss.elastic.co/tag/none.md?no_tags=true&page=238)

[Next page](https://discuss.elastic.co/tag/none.md?no_tags=true&page=240)
