# \#none

**URL:** https://discuss.elastic.co/tag/none.md?no_tags=true&page=243

[Latest](https://discuss.elastic.co/latest.md) · [Categories](https://discuss.elastic.co/categories.md) · [Tags](https://discuss.elastic.co/tags.md)

**Page:** 244

---

## [Unable to connect to the Kibana server Check your network connection and try again. Code 502](https://discuss.elastic.co/t/unable-to-connect-to-the-kibana-server-check-your-network-connection-and-try-again-code-502/351288)

<div class="topic-metadata">

**Author:** [@Leomar.V](https://discuss.elastic.co/u/Leomar.V)\
**Replies:** 0\
**Last updated:** [January 17, 2024, 2:52pm UTC](https://discuss.elastic.co/t/unable-to-connect-to-the-kibana-server-check-your-network-connection-and-try-again-code-502/351288 "2024-01-17T14:52:00Z")

</div>

Good morning community, how are you? I'm new to Kibana and I have a problem with code 502, but it only happens when I open a specific space and a specific report too.

---

## [Delete Indices/index/documents but 404 NotFound](https://discuss.elastic.co/t/delete-indices-index-documents-but-404-notfound/351250)

<div class="topic-metadata">

**Author:** [@martel](https://discuss.elastic.co/u/martel)\
**Replies:** 14\
**Last updated:** [January 17, 2024, 2:15pm UTC](https://discuss.elastic.co/t/delete-indices-index-documents-but-404-notfound/351250 "2024-01-17T14:15:27Z")

</div>

Hey, I want delete all indices, document, but want keep Template index. i have already try many operations see here in forum, but nothing clean my path data. A) \_settings with index.blocks.read\_only\_allow\_delete an…

---

## [Linux change monitoring](https://discuss.elastic.co/t/linux-change-monitoring/351281)

<div class="topic-metadata">

**Author:** [@Kiwisaki](https://discuss.elastic.co/u/Kiwisaki)\
**Replies:** 1\
**Last updated:** [January 17, 2024, 2:04pm UTC](https://discuss.elastic.co/t/linux-change-monitoring/351281 "2024-01-17T14:04:20Z")

</div>

Hi there, what is the best way to monitor any changes made to an linux server ? I am trying to think of the most efficient way of capturing from a very broad perspective of linux changes.

---

## [Replacing a cluster node](https://discuss.elastic.co/t/replacing-a-cluster-node/351253)

<div class="topic-metadata">

**Author:** [@rihad](https://discuss.elastic.co/u/rihad)\
**Replies:** 9\
**Last updated:** [January 17, 2024, 1:44pm UTC](https://discuss.elastic.co/t/replacing-a-cluster-node/351253 "2024-01-17T13:44:50Z")

</div>

Hi, we have a 3 node cluster, with 3 ME nodes. Today I needed to replace one node with another on a new server. I simply shut down ES on the old server, and started ES on the new server. It did join the cluster according…

---

## [Visualizations using the \_cat/indices API](https://discuss.elastic.co/t/visualizations-using-the-cat-indices-api/351276)

<div class="topic-metadata">

**Author:** [@jcruz](https://discuss.elastic.co/u/jcruz)\
**Replies:** 0\
**Last updated:** [January 17, 2024, 1:22pm UTC](https://discuss.elastic.co/t/visualizations-using-the-cat-indices-api/351276 "2024-01-17T13:22:20Z")

</div>

Hello guys, I would like to create some visualizations using the \_cat/indices API, so I can monitoring and understand the index usage during time. Is there any way to get the \_cat API output into some lens panels to cr…

---

## [Bug when using list with comma-number in elastic search template toJson](https://discuss.elastic.co/t/bug-when-using-list-with-comma-number-in-elastic-search-template-tojson/351274)

<div class="topic-metadata">

**Author:** [@bertie](https://discuss.elastic.co/u/bertie)\
**Replies:** 0\
**Last updated:** [January 17, 2024, 1:13pm UTC](https://discuss.elastic.co/t/bug-when-using-list-with-comma-number-in-elastic-search-template-tojson/351274 "2024-01-17T13:13:50Z")

</div>

Attempting the pass a list containing a comma-number (fx. 1.1) to the toJson functionality inbuilt in the search templates results in the following error: { "error": { "root\_cause": \[ { "type": "ille…

---

## [How to parse date field into @timestamp](https://discuss.elastic.co/t/how-to-parse-date-field-into-timestamp/351058)

<div class="topic-metadata">

**Author:** [@emoxam](https://discuss.elastic.co/u/emoxam)\
**Replies:** 9\
**Last updated:** [January 17, 2024, 12:10pm UTC](https://discuss.elastic.co/t/how-to-parse-date-field-into-timestamp/351058 "2024-01-17T12:10:13Z")

</div>

i receive the spring app logs and i want to parse time from logs to @timestamp that's what i got but timestamp is not the same. input { tcp { port =\> 5000 codec =\>plain } } filter { if \[message\] =~ /actions/ { …

---

## [Configure Elasticsearch with script](https://discuss.elastic.co/t/configure-elasticsearch-with-script/351264)

<div class="topic-metadata">

**Author:** [@cv123](https://discuss.elastic.co/u/cv123)\
**Replies:** 0\
**Last updated:** [January 17, 2024, 11:37am UTC](https://discuss.elastic.co/t/configure-elasticsearch-with-script/351264 "2024-01-17T11:37:23Z")

</div>

Hi everyone, i tried to deploy and configure an Elastic instance via script (first test with powershell) For that i wrote a terraform script to create 2 docker container (elasticsearch and kibana), create the enrollmen…

---

## [SSO error failed to establish trust with server at \[login.microsoftonline.com\]](https://discuss.elastic.co/t/sso-error-failed-to-establish-trust-with-server-at-login-microsoftonline-com/350858)

<div class="topic-metadata">

**Author:** [@krzychohoho](https://discuss.elastic.co/u/krzychohoho)\
**Replies:** 2\
**Last updated:** [January 17, 2024, 11:09am UTC](https://discuss.elastic.co/t/sso-error-failed-to-establish-trust-with-server-at-login-microsoftonline-com/350858 "2024-01-17T11:09:30Z")

</div>

Hi, I came across a problem recently and I need urgent help. The machine that was running Elasticsearch was restarted and now the service will not run. The error is: sun.security.validator.ValidatorException: PKIX path …

---

## [Shards failed The data might be incomplete or wrong](https://discuss.elastic.co/t/shards-failed-the-data-might-be-incomplete-or-wrong/351244)

<div class="topic-metadata">

**Author:** [@Bhavani90](https://discuss.elastic.co/u/Bhavani90)\
**Replies:** 1\
**Last updated:** [January 17, 2024, 11:01am UTC](https://discuss.elastic.co/t/shards-failed-the-data-might-be-incomplete-or-wrong/351244 "2024-01-17T11:01:57Z")

</div>

Hi I'm Bhavani. When I try to search for data within a message using quotation marks, I encounter an error like ( No results found 1 of 2868 shards failed The data might be incomplete or wrong.). How can I resolve …

---

## [Json processor Parsing Issue Workaround](https://discuss.elastic.co/t/json-processor-parsing-issue-workaround/351208)

<div class="topic-metadata">

**Author:** [@vishnu.a](https://discuss.elastic.co/u/vishnu.a)\
**Replies:** 1\
**Last updated:** [January 17, 2024, 10:53am UTC](https://discuss.elastic.co/t/json-processor-parsing-issue-workaround/351208 "2024-01-17T10:53:49Z")

</div>

Hello I'm trying to parse a field using the Json processor. the input is similar to the following: {"json": { \\"field1\\":\\"...\\", \\"field2\\":\\"...\\", ... , \\"Message\\":\\"\<message here\>\\", ... , \\"fieldn\\":\\"...\\" } The…

---

## [How does the search performance compare between standard and nested document structure](https://discuss.elastic.co/t/how-does-the-search-performance-compare-between-standard-and-nested-document-structure/351070)

<div class="topic-metadata">

**Author:** [@mmaccou](https://discuss.elastic.co/u/mmaccou)\
**Replies:** 1\
**Last updated:** [January 17, 2024, 10:36am UTC](https://discuss.elastic.co/t/how-does-the-search-performance-compare-between-standard-and-nested-document-structure/351070 "2024-01-17T10:36:12Z")

</div>

I’m exploring different ways to structure my indices. I found an article on the Elasticsearch blog about using nested documents. All else being equal, does this structure impact the speed or other performance/accuracy in…

---

## [Shards and Index states through Java Client](https://discuss.elastic.co/t/shards-and-index-states-through-java-client/351241)

<div class="topic-metadata">

**Author:** [@avnere](https://discuss.elastic.co/u/avnere)\
**Replies:** 1\
**Last updated:** [January 17, 2024, 10:23am UTC](https://discuss.elastic.co/t/shards-and-index-states-through-java-client/351241 "2024-01-17T10:23:35Z")

</div>

Hi, I am looking a way to get Shards and Index states through Java Client 7.17 The states getting from: GET \_cat/indices/?v GET \_cat/shards/?v Is it possible though HighLevelRestAPI?

---

## [Search with exact phrase in my index](https://discuss.elastic.co/t/search-with-exact-phrase-in-my-index/351213)

<div class="topic-metadata">

**Author:** [@Indilya](https://discuss.elastic.co/u/Indilya)\
**Replies:** 7\
**Last updated:** [January 17, 2024, 10:08am UTC](https://discuss.elastic.co/t/search-with-exact-phrase-in-my-index/351213 "2024-01-17T10:08:58Z")

</div>

Hello, First of all I want to apologize if my post is not correct. This is my first time on this forum and my first time using Elastic Search. I also take this opportunity to thank you in advance for the help. I have …

---

## [Map index creation\_date to new field in existing documents](https://discuss.elastic.co/t/map-index-creation-date-to-new-field-in-existing-documents/351235)

<div class="topic-metadata">

**Author:** [@es236908](https://discuss.elastic.co/u/es236908)\
**Replies:** 3\
**Last updated:** [January 17, 2024, 9:52am UTC](https://discuss.elastic.co/t/map-index-creation-date-to-new-field-in-existing-documents/351235 "2024-01-17T09:52:20Z")

</div>

Every day I create an index of my file system with Diskover so I have a large amount of indexes one for every day. Each of those indexes has documents for each file but there is no field for the time the index/document w…

---

## [Find an Phrase with addtional variants](https://discuss.elastic.co/t/find-an-phrase-with-addtional-variants/351067)

<div class="topic-metadata">

**Author:** [@libertey](https://discuss.elastic.co/u/libertey)\
**Replies:** 2\
**Last updated:** [January 17, 2024, 9:49am UTC](https://discuss.elastic.co/t/find-an-phrase-with-addtional-variants/351067 "2024-01-17T09:49:26Z")

</div>

Hello, i run into a Problem with matching of queries, I have an keyowrd like John Doe and now my System should find all Entries where the John Doe is mentioned as author. The main Problem is the Person John Doe is not a…

---

## [How to connect eStreamer with Elastic?](https://discuss.elastic.co/t/how-to-connect-estreamer-with-elastic/351090)

<div class="topic-metadata">

**Author:** [@hectorGC](https://discuss.elastic.co/u/hectorGC)\
**Replies:** 2\
**Last updated:** [January 17, 2024, 9:27am UTC](https://discuss.elastic.co/t/how-to-connect-estreamer-with-elastic/351090 "2024-01-17T09:27:44Z")

</div>

Hi Elastic researchers! I am trying to get more logs from the ftds since the logs are not complete in the IPS events and cisco suggests to use eStreamer. I am trying to understand the technology but some help related on…

---

## [Failed migration of system indices for the watcher and watcher not firing after update](https://discuss.elastic.co/t/failed-migration-of-system-indices-for-the-watcher-and-watcher-not-firing-after-update/350704)

<div class="topic-metadata">

**Author:** [@AEA27](https://discuss.elastic.co/u/AEA27)\
**Replies:** 2\
**Last updated:** [January 17, 2024, 7:45am UTC](https://discuss.elastic.co/t/failed-migration-of-system-indices-for-the-watcher-and-watcher-not-firing-after-update/350704 "2024-01-17T07:45:14Z")

</div>

continuation of Failed migration of system indices (.triggered\_watches) with Upgrade Assistant using v7.17.14 Summary, upgrade assistant was giving an error for the watcher when migrating system indices. I tried deleti…

---

## [Kibana Lens Dashboard Link Broken 404 Dashboard Not Found](https://discuss.elastic.co/t/kibana-lens-dashboard-link-broken-404-dashboard-not-found/350980)

<div class="topic-metadata">

**Author:** [@Ryan\_Downey](https://discuss.elastic.co/u/Ryan_Downey)\
**Replies:** 5\
**Last updated:** [January 16, 2024, 9:59pm UTC](https://discuss.elastic.co/t/kibana-lens-dashboard-link-broken-404-dashboard-not-found/350980 "2024-01-16T21:59:27Z")

</div>

Note: It may be necessary to check the user permissions first. TL/DR 1. (Hamburger Menu) --\> Stack Management --\> Saved Objects 2. Select the dashboard and Export 3. Open with Notepad++, CTRL +F, change the Search Mo…

---

## [\[ElasticSearch v.7.5\] How to merge daily and weekly indexes into a monthly index?](https://discuss.elastic.co/t/elasticsearch-v-7-5-how-to-merge-daily-and-weekly-indexes-into-a-monthly-index/351210)

<div class="topic-metadata">

**Author:** [@mpniel](https://discuss.elastic.co/u/mpniel)\
**Replies:** 1\
**Last updated:** [January 16, 2024, 9:34pm UTC](https://discuss.elastic.co/t/elasticsearch-v-7-5-how-to-merge-daily-and-weekly-indexes-into-a-monthly-index/351210 "2024-01-16T21:34:55Z")

</div>

How to merge daily and weekly indexes into a monthly index? In order to free shards.

---

## [After Installing Logstash version 8.11.4 it Exit because a System error](https://discuss.elastic.co/t/after-installing-logstash-version-8-11-4-it-exit-because-a-system-error/351035)

<div class="topic-metadata">

**Author:** [@jcourt2006](https://discuss.elastic.co/u/jcourt2006)\
**Replies:** 10\
**Last updated:** [January 16, 2024, 8:56pm UTC](https://discuss.elastic.co/t/after-installing-logstash-version-8-11-4-it-exit-because-a-system-error/351035 "2024-01-16T20:56:56Z")

</div>

I get the following error: \[root@app logstash\]# /usr/share/logstash/bin/logstash -t --path.settings /etc/logstash Using bundled JDK: /usr/share/logstash/jdk /usr/share/logstash/vendor/bundle/jruby/3.1.0/gems/concurrent-…

---

## [Why is a new index created with 0001 if you restart logstash?](https://discuss.elastic.co/t/why-is-a-new-index-created-with-0001-if-you-restart-logstash/351167)

<div class="topic-metadata">

**Author:** [@emoxam](https://discuss.elastic.co/u/emoxam)\
**Replies:** 2\
**Last updated:** [January 16, 2024, 5:39pm UTC](https://discuss.elastic.co/t/why-is-a-new-index-created-with-0001-if-you-restart-logstash/351167 "2024-01-16T17:39:27Z")

</div>

Why is a new index created with 0001 if you restart logstash? And does not continue to write to the main one, without numbers. But if you restart it again, it keeps writing to 0001 without creating 0002? /etc/logstash/c…

---

## [\[Ingest processor\] How to apply ingest pipeline on an index?](https://discuss.elastic.co/t/ingest-processor-how-to-apply-ingest-pipeline-on-an-index/351180)

<div class="topic-metadata">

**Author:** [@Keith\_Lin](https://discuss.elastic.co/u/Keith_Lin)\
**Replies:** 1\
**Last updated:** [January 16, 2024, 4:14pm UTC](https://discuss.elastic.co/t/ingest-processor-how-to-apply-ingest-pipeline-on-an-index/351180 "2024-01-16T16:14:58Z")

</div>

So in kibana i created an ingest pipeline. Is there a way to apply it to an index or it will be automatically applied?

---

## [Cannot restore open indices in new empty cluster](https://discuss.elastic.co/t/cannot-restore-open-indices-in-new-empty-cluster/351176)

<div class="topic-metadata">

**Author:** [@mebaj91360](https://discuss.elastic.co/u/mebaj91360)\
**Replies:** 1\
**Last updated:** [January 16, 2024, 3:43pm UTC](https://discuss.elastic.co/t/cannot-restore-open-indices-in-new-empty-cluster/351176 "2024-01-16T15:43:54Z")

</div>

Hello, I am trying to restore a snapshot on a new, empty cluster, but I get this error: \[restore-old:snapshot-2024.01.09-5ebjtwcnqksvliv3h9tcug/r4dfaUrJQXyQ0xxVa0OE8Q\] cannot restore index \[logstash-2023.09.02\] because…

---

## [Maintaining "time delta" between events when reindexing](https://discuss.elastic.co/t/maintaining-time-delta-between-events-when-reindexing/351155)

<div class="topic-metadata">

**Author:** [@petlit2049](https://discuss.elastic.co/u/petlit2049)\
**Replies:** 2\
**Last updated:** [January 16, 2024, 1:53pm UTC](https://discuss.elastic.co/t/maintaining-time-delta-between-events-when-reindexing/351155 "2024-01-16T13:53:21Z")

</div>

I'm trying to work out a process for maintaining the time difference between event records when re-indexing data from one index to another but with a new "t0" using only Elasticsearch with ingest pipelines and/or logstas…

---

## [Move data directory 8.5.2](https://discuss.elastic.co/t/move-data-directory-8-5-2/351168)

<div class="topic-metadata">

**Author:** [@Chel](https://discuss.elastic.co/u/Chel)\
**Replies:** 1\
**Last updated:** [January 16, 2024, 1:00pm UTC](https://discuss.elastic.co/t/move-data-directory-8-5-2/351168 "2024-01-16T13:00:45Z")

</div>

I want to move data directory from cluster A to Cluster B. Both have documents present. I want to copy the documents from cluster A to cluster B. Both cluster have different uuid's . Is it possible to change the cluster …

---

## [Logstash template](https://discuss.elastic.co/t/logstash-template/351131)

<div class="topic-metadata">

**Author:** [@SalehEska](https://discuss.elastic.co/u/SalehEska)\
**Replies:** 3\
**Last updated:** [January 16, 2024, 11:57am UTC](https://discuss.elastic.co/t/logstash-template/351131 "2024-01-16T11:57:08Z")

</div>

The problem is it does not create template , the template just for change things in the settings. this is the template : { "index\_patterns": \["audittrail\_transactions\_\*"\], "settings": { "number\_of\_shards": 2, "inde…

---

## [How to export large set data and write to csv using elasticsearch](https://discuss.elastic.co/t/how-to-export-large-set-data-and-write-to-csv-using-elasticsearch/351152)

<div class="topic-metadata">

**Author:** [@Bikash\_Hutait](https://discuss.elastic.co/u/Bikash_Hutait)\
**Replies:** 0\
**Last updated:** [January 16, 2024, 10:34am UTC](https://discuss.elastic.co/t/how-to-export-large-set-data-and-write-to-csv-using-elasticsearch/351152 "2024-01-16T10:34:13Z")

</div>

We have an application allowing users to export records based on search/filter criteria. I am looking for a solution to implement the "export all" functionality to a CSV file. I conducted a test utilizing the \_scroll AP…

---

## [Java::JavaLang::IllegalStateException\` for \`PipelineAction::Create\<main\>](https://discuss.elastic.co/t/java-illegalstateexception-for-pipelineaction-create-main/351142)

<div class="topic-metadata">

**Author:** [@bp\_cs](https://discuss.elastic.co/u/bp_cs)\
**Replies:** 1\
**Last updated:** [January 16, 2024, 9:58am UTC](https://discuss.elastic.co/t/java-illegalstateexception-for-pipelineaction-create-main/351142 "2024-01-16T09:58:30Z")

</div>

Thread.exclusive is deprecated, use Thread::Mutex Sending Logstash logs to D:/code/logstash/logstash-7.4.2/logs which is now configured via log4j2.properties \[2024-01-16T16:51:36,256\]\[WARN \]\[logstash.config.source.multil…

---

## [Persistent queue configuration in Windows OS using File IO](https://discuss.elastic.co/t/persistent-queue-configuration-in-windows-os-using-file-io/351145)

<div class="topic-metadata">

**Author:** [@sudipta.s](https://discuss.elastic.co/u/sudipta.s)\
**Replies:** 0\
**Last updated:** [January 16, 2024, 9:56am UTC](https://discuss.elastic.co/t/persistent-queue-configuration-in-windows-os-using-file-io/351145 "2024-01-16T09:56:39Z")

</div>

Hello team, We are looking for some support on Persistent queue configuration in windows OS. We are using file IO and exposed some shared location with all write privilege. With guided configuration in elastic documenta…

[Previous page](https://discuss.elastic.co/tag/none.md?no_tags=true&page=242)

[Next page](https://discuss.elastic.co/tag/none.md?no_tags=true&page=244)
