# \#none

**URL:** https://discuss.elastic.co/tag/none.md?no_tags=true&page=252

[Latest](https://discuss.elastic.co/latest.md) · [Categories](https://discuss.elastic.co/categories.md) · [Tags](https://discuss.elastic.co/tags.md)

**Page:** 253

---

## [Percentage Metric](https://discuss.elastic.co/t/percentage-metric/349388)

<div class="topic-metadata">

**Author:** [@sbottura](https://discuss.elastic.co/u/sbottura)\
**Replies:** 1\
**Last updated:** [December 27, 2023, 10:26pm UTC](https://discuss.elastic.co/t/percentage-metric/349388 "2023-12-27T22:26:17Z")

</div>

Hello, I need to create a Metric which shows the percentage of the sum of one field to the sum of another field. Let's say "a" is the sum of all the money I cashed in so far and "b" is the sum of all the money I am set…

---

## [Kibana plugin installation: Error when installing plugin in kibana 8.8.2](https://discuss.elastic.co/t/kibana-plugin-installation-error-when-installing-plugin-in-kibana-8-8-2/348475)

<div class="topic-metadata">

**Author:** [@Bisrat\_Awoke](https://discuss.elastic.co/u/Bisrat_Awoke)\
**Replies:** 1\
**Last updated:** [December 27, 2023, 10:17pm UTC](https://discuss.elastic.co/t/kibana-plugin-installation-error-when-installing-plugin-in-kibana-8-8-2/348475 "2023-12-27T22:17:55Z")

</div>

I developed a custom plugin and when i try to install it i get the following error. The browser is making a request to fetch my plugins plugin.js file but the server is responding with 404. Whats weird is that i this…

---

## [Can I create Kibana Heat Map based on many different saved DSL queries?](https://discuss.elastic.co/t/can-i-create-kibana-heat-map-based-on-many-different-saved-dsl-queries/349618)

<div class="topic-metadata">

**Author:** [@allan.silverstein](https://discuss.elastic.co/u/allan.silverstein)\
**Replies:** 1\
**Last updated:** [December 27, 2023, 9:33pm UTC](https://discuss.elastic.co/t/can-i-create-kibana-heat-map-based-on-many-different-saved-dsl-queries/349618 "2023-12-27T21:33:50Z")

</div>

Here is what I'd like to do: In Kibana, I'd like to create a Heat Map where each box in the heat map represents the result of a specific saved query. Each box in the heatmap should represent the count of the result of …

---

## [Kibana can not generate CSV file ,it show internal server error](https://discuss.elastic.co/t/kibana-can-not-generate-csv-file-it-show-internal-server-error/348629)

<div class="topic-metadata">

**Author:** [@hejunliang1234](https://discuss.elastic.co/u/hejunliang1234)\
**Replies:** 2\
**Last updated:** [December 27, 2023, 9:06pm UTC](https://discuss.elastic.co/t/kibana-can-not-generate-csv-file-it-show-internal-server-error/348629 "2023-12-27T21:06:15Z")

</div>

Dear all, When i want to generate CSV file, it show internal server error .Below is log. {"type":"response","@timestamp":"2023-12-05T18:59:23+08:00","tags":\[\],"pid":3078,"method":"post","statusCode":200,"req":{"url":"/…

---

## [How to increase font size in Metric chart (kibana 8.9.2)?](https://discuss.elastic.co/t/how-to-increase-font-size-in-metric-chart-kibana-8-9-2/349942)

<div class="topic-metadata">

**Author:** [@Charan\_Kumar\_reddy](https://discuss.elastic.co/u/Charan_Kumar_reddy)\
**Replies:** 1\
**Last updated:** [December 27, 2023, 8:54pm UTC](https://discuss.elastic.co/t/how-to-increase-font-size-in-metric-chart-kibana-8-9-2/349942 "2023-12-27T20:54:21Z")

</div>

I am using kibana version 8.9.2. I have created a metric chart it's showing text at right bottom corner. Which is not much visible , i want to increase the size . How to do that please help me? .

---

## [Error fetching data for metricset kibana.node\_rules: error making http request](https://discuss.elastic.co/t/error-fetching-data-for-metricset-kibana-node-rules-error-making-http-request/349990)

<div class="topic-metadata">

**Author:** [@husoelasticbe](https://discuss.elastic.co/u/husoelasticbe)\
**Replies:** 10\
**Last updated:** [December 27, 2023, 8:15pm UTC](https://discuss.elastic.co/t/error-fetching-data-for-metricset-kibana-node-rules-error-making-http-request/349990 "2023-12-27T20:15:15Z")

</div>

Hi Folks, I am almost getting mad. Please help me our here. I am trying to collect kibana monitoring data with metricbeat. I get strangely the following error: {"file.name":"module/wrapper.go","file.line":256},"messa…

---

## [How can I search for the latest data entered in the indexes? ](https://discuss.elastic.co/t/how-can-i-search-for-the-latest-data-entered-in-the-indexes/349972)

<div class="topic-metadata">

**Author:** [@deep1](https://discuss.elastic.co/u/deep1)\
**Replies:** 17\
**Last updated:** [December 27, 2023, 5:32pm UTC](https://discuss.elastic.co/t/how-can-i-search-for-the-latest-data-entered-in-the-indexes/349972 "2023-12-27T17:32:15Z")

</div>

For example, I want to search in 100,000 documents from each index, and it is not possible to add to that, and they are first loaded into the cache, then only this data is searched

---

## [Gather Data from Yesterday Until Today](https://discuss.elastic.co/t/gather-data-from-yesterday-until-today/349740)

<div class="topic-metadata">

**Author:** [@hi\_xavier](https://discuss.elastic.co/u/hi_xavier)\
**Replies:** 2\
**Last updated:** [December 27, 2023, 4:19pm UTC](https://discuss.elastic.co/t/gather-data-from-yesterday-until-today/349740 "2023-12-27T16:19:48Z")

</div>

Hello, I'm currently using the elk api to gather data between yesterday and today (12/19 @ 00:00:000 -- 12/20@00:00:000) Would this be the equivalent of that using a range query? "range": { "timestamp": { …

---

## [Different results of aggregation query on same version](https://discuss.elastic.co/t/different-results-of-aggregation-query-on-same-version/349872)

<div class="topic-metadata">

**Author:** [@apari](https://discuss.elastic.co/u/apari)\
**Replies:** 1\
**Last updated:** [December 27, 2023, 3:17pm UTC](https://discuss.elastic.co/t/different-results-of-aggregation-query-on-same-version/349872 "2023-12-27T15:17:24Z")

</div>

I am running the following query on multiple servers, same build (same hash, build date, and version number) of ES. 7.16.2 { "size": 0, "query": { "terms": { "FileFeedID": \[ // Some values …

---

## [Elastic SIEM](https://discuss.elastic.co/t/elastic-siem/350026)

<div class="topic-metadata">

**Author:** [@Ammar\_Mostafa](https://discuss.elastic.co/u/Ammar_Mostafa)\
**Replies:** 0\
**Last updated:** [December 27, 2023, 2:54pm UTC](https://discuss.elastic.co/t/elastic-siem/350026 "2023-12-27T14:54:06Z")

</div>

Hello All, I hope all is well with you. I'm new to elastic and I want to inquire if we can fully depend on elastic security as siem solution? Thnk you in advance.

---

## [Removing master node permanently](https://discuss.elastic.co/t/removing-master-node-permanently/350002)

<div class="topic-metadata">

**Author:** [@artechkey](https://discuss.elastic.co/u/artechkey)\
**Replies:** 4\
**Last updated:** [December 27, 2023, 2:31pm UTC](https://discuss.elastic.co/t/removing-master-node-permanently/350002 "2023-12-27T14:31:14Z")

</div>

Hi, We currently have a 2 node + master-voting only node cluster. We are expanding the cluster by adding 3 more nodes to it. As part of the expansion, we want to designate one of the new nodes as a master and take out t…

---

## [Optimizing Elasticsearch Snapshot Recovery for Node Disk Space Utilization](https://discuss.elastic.co/t/optimizing-elasticsearch-snapshot-recovery-for-node-disk-space-utilization/350013)

<div class="topic-metadata">

**Author:** [@jakub0011](https://discuss.elastic.co/u/jakub0011)\
**Replies:** 1\
**Last updated:** [December 27, 2023, 2:15pm UTC](https://discuss.elastic.co/t/optimizing-elasticsearch-snapshot-recovery-for-node-disk-space-utilization/350013 "2023-12-27T14:15:01Z")

</div>

I'm seeking advice on optimizing the snapshot recovery process in our Elasticsearch cluster, which consists of 8 nodes. Currently, when recovering various snapshots, the indices are restored to nodes based on the percent…

---

## [How to parse date field into @timestamp](https://discuss.elastic.co/t/how-to-parse-date-field-into-timestamp/349849)

<div class="topic-metadata">

**Author:** [@emoxam](https://discuss.elastic.co/u/emoxam)\
**Replies:** 11\
**Last updated:** [December 22, 2023, 2:26pm UTC](https://discuss.elastic.co/t/how-to-parse-date-field-into-timestamp/349849 "2023-12-22T14:26:55Z")

</div>

I want to move the fulltime from message field to @timestamp. That's what i created. filter { if \[message\] =~ /actions/ { json { source =\> "message" } date { match =\> \[ "message", "yyyy-MM-dd …

---

## [ELK Stack: Logstash shows that it's receiving log entries from Filebeat, but Elasticsearch is not creating my index](https://discuss.elastic.co/t/elk-stack-logstash-shows-that-its-receiving-log-entries-from-filebeat-but-elasticsearch-is-not-creating-my-index/349826)

<div class="topic-metadata">

**Author:** [@BDeveloper](https://discuss.elastic.co/u/BDeveloper)\
**Replies:** 8\
**Last updated:** [December 26, 2023, 4:40pm UTC](https://discuss.elastic.co/t/elk-stack-logstash-shows-that-its-receiving-log-entries-from-filebeat-but-elasticsearch-is-not-creating-my-index/349826 "2023-12-26T16:40:57Z")

</div>

I am new to the ELK stack and I wanted to try and test it out to see if I wanted to use it. I have elasticsearch, kibana, and logstash installed on one virtual machine and I have filebeat and nginx installed on another v…

---

## [Display the last 100k documents](https://discuss.elastic.co/t/display-the-last-100k-documents/349961)

<div class="topic-metadata">

**Author:** [@1337](https://discuss.elastic.co/u/1337)\
**Replies:** 3\
**Last updated:** [December 26, 2023, 3:58pm UTC](https://discuss.elastic.co/t/display-the-last-100k-documents/349961 "2023-12-26T15:58:24Z")

</div>

I want to display the last 100k documents for all indices. Each index with the last 100k

---

## [Index Life Cycle Management](https://discuss.elastic.co/t/index-life-cycle-management/349964)

<div class="topic-metadata">

**Author:** [@Debasis\_Mallick](https://discuss.elastic.co/u/Debasis_Mallick)\
**Replies:** 3\
**Last updated:** [December 26, 2023, 3:10pm UTC](https://discuss.elastic.co/t/index-life-cycle-management/349964 "2023-12-26T15:10:24Z")

</div>

HI Team, Can Index rollover happened on the basis of field value of attribute instead of calendar date. Thanks, Debasis

---

## [MSK to Elasticksearch using logstash](https://discuss.elastic.co/t/msk-to-elasticksearch-using-logstash/349945)

<div class="topic-metadata">

**Author:** [@Gersi\_Tafili](https://discuss.elastic.co/u/Gersi_Tafili)\
**Replies:** 4\
**Last updated:** [December 26, 2023, 1:14pm UTC](https://discuss.elastic.co/t/msk-to-elasticksearch-using-logstash/349945 "2023-12-26T13:14:29Z")

</div>

I have create MSK in AWS also Elastic search cluster hostes in AWS. I am trying to read data from topic in MSK and send this data to elasticsearch index. input { kafka { bootstrap\_servers =\> "x:9096" topics =\>…

---

## [Can not create a custom normalizer using char filter \[html\_strip\]](https://discuss.elastic.co/t/can-not-create-a-custom-normalizer-using-char-filter-html-strip/349939)

<div class="topic-metadata">

**Author:** [@voaix](https://discuss.elastic.co/u/voaix)\
**Replies:** 1\
**Last updated:** [December 26, 2023, 12:45pm UTC](https://discuss.elastic.co/t/can-not-create-a-custom-normalizer-using-char-filter-html-strip/349939 "2023-12-26T12:45:20Z")

</div>

Hello, I try to save the custom normalizer as part of composite template. Receiving below error: illegal\_argument\_exception', 'Custom normalizer \[lower\_normalizer\] may not use char filter \[html\_strip\] Normalizer is de…

---

## [Select option from drop downs and update,delete the documents accordingly in kibana](https://discuss.elastic.co/t/select-option-from-drop-downs-and-update-delete-the-documents-accordingly-in-kibana/349931)

<div class="topic-metadata">

**Author:** [@PRASHANT\_MEHTA](https://discuss.elastic.co/u/PRASHANT_MEHTA)\
**Replies:** 1\
**Last updated:** [December 26, 2023, 12:43pm UTC](https://discuss.elastic.co/t/select-option-from-drop-downs-and-update-delete-the-documents-accordingly-in-kibana/349931 "2023-12-26T12:43:33Z")

</div>

Hello All, I've a requirement in kibana where in I want to select options from drop down(This is possible using options, I am aware of this). Now this is where I'm struggling: After selecting multiple options from drop…

---

## [Using must query in filter section of DSl elastic](https://discuss.elastic.co/t/using-must-query-in-filter-section-of-dsl-elastic/349953)

<div class="topic-metadata">

**Author:** [@Aniket\_Pant](https://discuss.elastic.co/u/Aniket_Pant)\
**Replies:** 1\
**Last updated:** [December 26, 2023, 12:20pm UTC](https://discuss.elastic.co/t/using-must-query-in-filter-section-of-dsl-elastic/349953 "2023-12-26T12:20:25Z")

</div>

GET rds\_database-\*/\_search { "\_source": \["failure\_error\_text"\], "query": { "bool": { "filter": \[ { "must":\[ { "term":{ "status.keyword":"F" …

---

## [Using toJson in big search template](https://discuss.elastic.co/t/using-tojson-in-big-search-template/349951)

<div class="topic-metadata">

**Author:** [@bertie](https://discuss.elastic.co/u/bertie)\
**Replies:** 0\
**Last updated:** [December 26, 2023, 11:51am UTC](https://discuss.elastic.co/t/using-tojson-in-big-search-template/349951 "2023-12-26T11:51:18Z")

</div>

I cannot figure out how I should use the toJson when prototyping templates in the kibana dev console. If I simply use it like others mustache functions like the following example Kibana simply classifies it as a "bad str…

---

## [Duplicate messages with logstash and log4net RollingFileAppender](https://discuss.elastic.co/t/duplicate-messages-with-logstash-and-log4net-rollingfileappender/349932)

<div class="topic-metadata">

**Author:** [@pumiki](https://discuss.elastic.co/u/pumiki)\
**Replies:** 1\
**Last updated:** [December 26, 2023, 10:53am UTC](https://discuss.elastic.co/t/duplicate-messages-with-logstash-and-log4net-rollingfileappender/349932 "2023-12-26T10:53:46Z")

</div>

Hello, My app writes events using log4net with rolling file appender. I get messages duplicated in the file gerenated by logstash. I found the issue mentioned also here However, I am not sure about the solution. Cou…

---

## [Sort is incorrect](https://discuss.elastic.co/t/sort-is-incorrect/349906)

<div class="topic-metadata">

**Author:** [@Binh\_Phan\_Thanh](https://discuss.elastic.co/u/Binh_Phan_Thanh)\
**Replies:** 12\
**Last updated:** [December 26, 2023, 10:45am UTC](https://discuss.elastic.co/t/sort-is-incorrect/349906 "2023-12-26T10:45:04Z")

</div>

My mapping: { "my\_index": { "mappings": { "properties": { "attributesRecommend": { "type": "text", "fields": { "keyword": { "type": "keyword", …

---

## [Lucene : Regex & group by](https://discuss.elastic.co/t/lucene-regex-group-by/349929)

<div class="topic-metadata">

**Author:** [@Jagadeesh\_Venkatesh](https://discuss.elastic.co/u/Jagadeesh_Venkatesh)\
**Replies:** 0\
**Last updated:** [December 26, 2023, 7:59am UTC](https://discuss.elastic.co/t/lucene-regex-group-by/349929 "2023-12-26T07:59:56Z")

</div>

write a regular expression for this " Generating JWT token for user : psi-sci-3 " using Lucene in Kibana search to extract the keyword "psi-sci-3" and group by count by "psi-sci-3"?

---

## [I can not login elastic](https://discuss.elastic.co/t/i-can-not-login-elastic/348450)

<div class="topic-metadata">

**Author:** [@miladmohabati](https://discuss.elastic.co/u/miladmohabati)\
**Replies:** 32\
**Last updated:** [December 25, 2023, 8:10pm UTC](https://discuss.elastic.co/t/i-can-not-login-elastic/348450 "2023-12-25T20:10:10Z")

</div>

hi my disk space is full and I can not login to elastic web how can I clear cache disk plz help me

---

## [Logstash terminating pipelines error "const\_missing, block in JDBC"](https://discuss.elastic.co/t/logstash-terminating-pipelines-error-const-missing-block-in-jdbc/349715)

<div class="topic-metadata">

**Author:** [@SamehSaeed](https://discuss.elastic.co/u/SamehSaeed)\
**Replies:** 3\
**Last updated:** [December 25, 2023, 1:10pm UTC](https://discuss.elastic.co/t/logstash-terminating-pipelines-error-const-missing-block-in-jdbc/349715 "2023-12-25T13:10:21Z")

</div>

Hello, I have a problem when running logstash with multiple pipelines (around 70). Logstash will always terminate some of them if i run more than 30 concurrently 1- First error : \[ERROR\]\[logstash.javapipeline \]\[bkge…

---

## [Error with http-plugin output Encountered non-2xx HTTP code 400](https://discuss.elastic.co/t/error-with-http-plugin-output-encountered-non-2xx-http-code-400/348215)

<div class="topic-metadata">

**Author:** [@bilal\_adoui](https://discuss.elastic.co/u/bilal_adoui)\
**Replies:** 3\
**Last updated:** [December 25, 2023, 10:27am UTC](https://discuss.elastic.co/t/error-with-http-plugin-output-encountered-non-2xx-http-code-400/348215 "2023-12-25T10:27:04Z")

</div>

Hi, I am trying to send a notification from Logstash to our Teams channel, using HTTP plugin however I am getting : \[HTTP Output Failure\] Encountered non-2xx HTTP code 400 {:response\_code=\>400 and this is my output c…

---

## [Elasticsearch Aggregations Pagination](https://discuss.elastic.co/t/elasticsearch-aggregations-pagination/349915)

<div class="topic-metadata">

**Author:** [@Azizi\_BESSEM](https://discuss.elastic.co/u/Azizi_BESSEM)\
**Replies:** 0\
**Last updated:** [December 25, 2023, 9:54am UTC](https://discuss.elastic.co/t/elasticsearch-aggregations-pagination/349915 "2023-12-25T09:54:21Z")

</div>

Dear Elasticsearch Team, I hope this message finds you well. I am currently working with an alert index in Elasticsearch, which contains information such as "device-ref" and "alert type." My goal is to retrieve the late…

---

## [Dec 25th, 2023: \[EN\] How to investigate a Malicious Alert for Threat Hunting in Elastic Security](https://discuss.elastic.co/t/dec-25th-2023-en-how-to-investigate-a-malicious-alert-for-threat-hunting-in-elastic-security/347618)

<div class="topic-metadata">

**Author:** [@Tanisha\_L\_Turner](https://discuss.elastic.co/u/Tanisha_L_Turner)\
**Replies:** 0\
**Last updated:** [December 25, 2023, 8:00am UTC](https://discuss.elastic.co/t/dec-25th-2023-en-how-to-investigate-a-malicious-alert-for-threat-hunting-in-elastic-security/347618 "2023-12-25T08:00:27Z")

</div>

Introduction When investigating malicious alerts in Elastic Security, it is essential to determine the type of malicious activity that is detected from an alert for response and remediation. There are many methods to pe…

---

## [Elastic agent not sending logs to elastic search](https://discuss.elastic.co/t/elastic-agent-not-sending-logs-to-elastic-search/349909)

<div class="topic-metadata">

**Author:** [@ramapdev](https://discuss.elastic.co/u/ramapdev)\
**Replies:** 0\
**Last updated:** [December 25, 2023, 5:18am UTC](https://discuss.elastic.co/t/elastic-agent-not-sending-logs-to-elastic-search/349909 "2023-12-25T05:18:48Z")

</div>

HI All, i am able to launch the elastic agent and fleet successfully \[ec2-user@ip-172-31-56-159 testlogs\]$ sudo /usr/bin/elastic-agent status ┌─ fleet │ └─ status: (HEALTHY) Connected └─ elastic-agent └─ status: (…

[Previous page](https://discuss.elastic.co/tag/none.md?no_tags=true&page=251)

[Next page](https://discuss.elastic.co/tag/none.md?no_tags=true&page=253)
