# \#none

**URL:** https://discuss.elastic.co/tag/none.md?no_tags=true&page=253

[Latest](https://discuss.elastic.co/latest.md) · [Categories](https://discuss.elastic.co/categories.md) · [Tags](https://discuss.elastic.co/tags.md)

**Page:** 254

---

## [My data view in kibana has no fields](https://discuss.elastic.co/t/my-data-view-in-kibana-has-no-fields/349902)

<div class="topic-metadata">

**Author:** [@Fatiha](https://discuss.elastic.co/u/Fatiha)\
**Replies:** 3\
**Last updated:** [December 24, 2023, 7:04pm UTC](https://discuss.elastic.co/t/my-data-view-in-kibana-has-no-fields/349902 "2023-12-24T19:04:51Z")

</div>

HI I want to visualize my data from mysql to kibana I create my file logstash.conf input { jdbc { jdbc\_driver\_library =\> "E:/ELK/mysql-connector-java-8.0.17.jar" jdbc\_driver\_class =\> "com.mysql.cj.jdbc.Driver…

---

## [Logstash helm chart with Elasticsearch input/output starts over after finishing](https://discuss.elastic.co/t/logstash-helm-chart-with-elasticsearch-input-output-starts-over-after-finishing/349900)

<div class="topic-metadata">

**Author:** [@shaigbdb](https://discuss.elastic.co/u/shaigbdb)\
**Replies:** 0\
**Last updated:** [December 24, 2023, 5:12pm UTC](https://discuss.elastic.co/t/logstash-helm-chart-with-elasticsearch-input-output-starts-over-after-finishing/349900 "2023-12-24T17:12:00Z")

</div>

Hi, I'm using the logstash helm chart with Logstash 8.9.0. The pipeline has an input and an output of Elasticsearch, basically importing an index from one cluster to another (using snapshots or reindex would've been be…

---

## [Change duration after which warning "Datafeed has been retrieving no data for a while" appears](https://discuss.elastic.co/t/change-duration-after-which-warning-datafeed-has-been-retrieving-no-data-for-a-while-appears/348501)

<div class="topic-metadata">

**Author:** [@marmai16](https://discuss.elastic.co/u/marmai16)\
**Replies:** 1\
**Last updated:** [December 24, 2023, 2:36pm UTC](https://discuss.elastic.co/t/change-duration-after-which-warning-datafeed-has-been-retrieving-no-data-for-a-while-appears/348501 "2023-12-24T14:36:53Z")

</div>

Hello everyone, is it possible to change the duration, after which the warning "Datafeed has been retrieving no data for a while" appears relating to an anomaly detection job? It is perfectly fine, that the datafeed oc…

---

## [.ds indices creating automatically in our env](https://discuss.elastic.co/t/ds-indices-creating-automatically-in-our-env/349861)

<div class="topic-metadata">

**Author:** [@Siva\_Karan](https://discuss.elastic.co/u/Siva_Karan)\
**Replies:** 1\
**Last updated:** [December 24, 2023, 2:24pm UTC](https://discuss.elastic.co/t/ds-indices-creating-automatically-in-our-env/349861 "2023-12-24T14:24:59Z")

</div>

Hi Team, After upgrdation of elasticearch from 7.3.2 to 7.17.16 .ds\* index automatically creating like below .ds-ilm-history-5-2023.12.18-000002 .ds-.logs-deprecation.elasticsearch-default-2023.11.18-000001 How to st…

---

## [Dec 24th, 2023: \[EN\] Generating the ultimate Christmas song with Elasticsearch and LLMs](https://discuss.elastic.co/t/dec-24th-2023-en-generating-the-ultimate-christmas-song-with-elasticsearch-and-llms/347313)

<div class="topic-metadata">

**Author:** [@carly.richmond](https://discuss.elastic.co/u/carly.richmond)\
**Replies:** 0\
**Last updated:** [December 24, 2023, 8:00am UTC](https://discuss.elastic.co/t/dec-24th-2023-en-generating-the-ultimate-christmas-song-with-elasticsearch-and-llms/347313 "2023-12-24T08:00:17Z")

</div>

Introduction We've all played with those song generators out there on the internet to generate songs. More recently we've used LLMs such as ChatGPT to generate songs or poems in the style of a particular artist. But w…

---

## [Dec 23rd, 2023: \[EN\] Novice Kibana user goes metal in analytics](https://discuss.elastic.co/t/dec-23rd-2023-en-novice-kibana-user-goes-metal-in-analytics/347312)

<div class="topic-metadata">

**Author:** [@bhavyarm](https://discuss.elastic.co/u/bhavyarm)\
**Replies:** 0\
**Last updated:** [December 23, 2023, 8:00am UTC](https://discuss.elastic.co/t/dec-23rd-2023-en-novice-kibana-user-goes-metal-in-analytics/347312 "2023-12-23T08:00:38Z")

</div>

For this year's advent calendar, I thought I will try to ingest some music data into elasticsearch and talk about few of my favourite features in Discover and Dashboard for analytics in Kibana 8.11 (our latest release)…

---

## [Kibana 7.17 点線ラインで表示するには？](https://discuss.elastic.co/t/kibana-7-17/349876)

<div class="topic-metadata">

**Author:** [@toshihisa-nakamura](https://discuss.elastic.co/u/toshihisa-nakamura)\
**Replies:** 1\
**Last updated:** [December 23, 2023, 7:47am UTC](https://discuss.elastic.co/t/kibana-7-17/349876 "2023-12-23T07:47:08Z")

</div>

kibana7.17のDashboardでデータをLineで表示させていますが、ver6まではあったVisualoptionsのDot表示＆Line非表示がなくなり設定できません。 ver7以降ではどのようにすればDot＆Line非表示にできますか？ 教えていただけるとありがたいです。

---

## [Osquery fails to return any data from Windows 10 or MACOS elastic agents](https://discuss.elastic.co/t/osquery-fails-to-return-any-data-from-windows-10-or-macos-elastic-agents/349880)

<div class="topic-metadata">

**Author:** [@hotcobra](https://discuss.elastic.co/u/hotcobra)\
**Replies:** 0\
**Last updated:** [December 23, 2023, 7:40am UTC](https://discuss.elastic.co/t/osquery-fails-to-return-any-data-from-windows-10-or-macos-elastic-agents/349880 "2023-12-23T07:40:11Z")

</div>

I can see all agents are healthy (in Security Onion 2.4.30), I attempt query and all I get back is error. I assume it's a configuration or permission issue but can't find it. Recommendations?

---

## [Invalid or malformed certificate using caFingerprint](https://discuss.elastic.co/t/invalid-or-malformed-certificate-using-cafingerprint/349754)

<div class="topic-metadata">

**Author:** [@joe\_recra](https://discuss.elastic.co/u/joe_recra)\
**Replies:** 11\
**Last updated:** [December 23, 2023, 12:54am UTC](https://discuss.elastic.co/t/invalid-or-malformed-certificate-using-cafingerprint/349754 "2023-12-23T00:54:34Z")

</div>

hi, I generated a CA certificate using: ./elasticsearch-certutil ca --pem --out /certs/ca.zip and then generated a cert using: ./bin/elasticsearch-certutil cert \\ --out /var/snap/amazon-ssm-agent/7628/elasticsearch-8…

---

## [Logstash SNMP input plugin not seeing metadata](https://discuss.elastic.co/t/logstash-snmp-input-plugin-not-seeing-metadata/349524)

<div class="topic-metadata">

**Author:** [@bytelink](https://discuss.elastic.co/u/bytelink)\
**Replies:** 6\
**Last updated:** [December 22, 2023, 5:04pm UTC](https://discuss.elastic.co/t/logstash-snmp-input-plugin-not-seeing-metadata/349524 "2023-12-22T17:04:26Z")

</div>

I am trying to implement the SNMP input plugin to gther network data however when I try and access the metadata it returns the line of code not the data. I even tried copying the example from the documentation and get t…

---

## [Failed to indices:data/write/bulk\[s\] on replica because of Netty4TcpChannel / CompositeBytesReference more than 2GB](https://discuss.elastic.co/t/failed-to-indices-data-write-bulk-s-on-replica-because-of-netty4tcpchannel-compositebytesreference-more-than-2gb/349797)

<div class="topic-metadata">

**Author:** [@Martin\_Berlin](https://discuss.elastic.co/u/Martin_Berlin)\
**Replies:** 5\
**Last updated:** [December 22, 2023, 3:11pm UTC](https://discuss.elastic.co/t/failed-to-indices-data-write-bulk-s-on-replica-because-of-netty4tcpchannel-compositebytesreference-more-than-2gb/349797 "2023-12-22T15:11:59Z")

</div>

While Indexing to our Cluster sometimes this error occures turning the cluster in red & yellow state: One node is trying to "perform indices:data/write/bulk\[s\] on replica" on another node but fails because of "exception…

---

## [Challenges while migrating elasticsearch client 6.8 to 8.7 (is mandatory)](https://discuss.elastic.co/t/challenges-while-migrating-elasticsearch-client-6-8-to-8-7-is-mandatory/349856)

<div class="topic-metadata">

**Author:** [@Chetan\_Ramaiah](https://discuss.elastic.co/u/Chetan_Ramaiah)\
**Replies:** 0\
**Last updated:** [December 22, 2023, 1:36pm UTC](https://discuss.elastic.co/t/challenges-while-migrating-elasticsearch-client-6-8-to-8-7-is-mandatory/349856 "2023-12-22T13:36:39Z")

</div>

Hello, Currently, I am in the midst of transitioning from Elasticsearch HLRC 6.8 to Elasticsearch REST API Java Client 8.7 within a Spring Boot application. This migration aligns with the broader upgrade of the Spring v…

---

## [Disk usage grows indefinitely over time](https://discuss.elastic.co/t/disk-usage-grows-indefinitely-over-time/349751)

<div class="topic-metadata">

**Author:** [@Tommaso\_Parisi](https://discuss.elastic.co/u/Tommaso_Parisi)\
**Replies:** 2\
**Last updated:** [December 22, 2023, 1:29pm UTC](https://discuss.elastic.co/t/disk-usage-grows-indefinitely-over-time/349751 "2023-12-22T13:29:14Z")

</div>

Hello, as you see in the screenshot above the disk usage of my index grows indefinitely over time. If I close the index and then reopen it the usage drops, as you can see from the graph. I did a \_close followed by a…

---

## [What's the new FilterAggregator in the java client 8](https://discuss.elastic.co/t/whats-the-new-filteraggregator-in-the-java-client-8/349737)

<div class="topic-metadata">

**Author:** [@Darth\_vader\_22](https://discuss.elastic.co/u/Darth_vader_22)\
**Replies:** 3\
**Last updated:** [December 22, 2023, 8:36am UTC](https://discuss.elastic.co/t/whats-the-new-filteraggregator-in-the-java-client-8/349737 "2023-12-22T08:36:24Z")

</div>

hello guys , i'm having hard times trying to find a way to create a FilterAggregationBuilder in the new java client 8.11 , if anyone could point me te the solution i'll be grateful FiltersAggregationBuilder agg…

---

## [Dec 22nd, 2023: \[EN\] Santa Claus Meets GenAI: Deciphering Handwritten Christmas Letters with LLM, LangChain and Elasticsearch](https://discuss.elastic.co/t/dec-22nd-2023-en-santa-claus-meets-genai-deciphering-handwritten-christmas-letters-with-llm-langchain-and-elasticsearch/347311)

<div class="topic-metadata">

**Author:** [@Alex\_Salgado-Elastic](https://discuss.elastic.co/u/Alex_Salgado-Elastic)\
**Replies:** 0\
**Last updated:** [December 22, 2023, 8:00am UTC](https://discuss.elastic.co/t/dec-22nd-2023-en-santa-claus-meets-genai-deciphering-handwritten-christmas-letters-with-llm-langchain-and-elasticsearch/347311 "2023-12-22T08:00:37Z")

</div>

This post is also available in portuguese. In the heart of the North Pole, Santa's team of elves faced a formidable logistical challenge: how to handle millions of letters from children around the world. With a deter…

---

## [Dec 22nd, 2023: \[PT\] Papai Noel Encontra a IA Generativa: Decifrando Cartas de Natal Escritas à Mão com LLM, LangChain e Elasticsearch](https://discuss.elastic.co/t/dec-22nd-2023-pt-papai-noel-encontra-a-ia-generativa-decifrando-cartas-de-natal-escritas-a-mao-com-llm-langchain-e-elasticsearch/347310)

<div class="topic-metadata">

**Author:** [@Alex\_Salgado-Elastic](https://discuss.elastic.co/u/Alex_Salgado-Elastic)\
**Replies:** 0\
**Last updated:** [December 22, 2023, 8:00am UTC](https://discuss.elastic.co/t/dec-22nd-2023-pt-papai-noel-encontra-a-ia-generativa-decifrando-cartas-de-natal-escritas-a-mao-com-llm-langchain-e-elasticsearch/347310 "2023-12-22T08:00:37Z")

</div>

This post is also available in english. No coração do Polo Norte, a equipe de duendes de Papai Noel enfrentava um desafio logístico formidável: como lidar com milhões de cartas de crianças de todo o mundo. Com um olh…

---

## [Index distribution clarification](https://discuss.elastic.co/t/index-distribution-clarification/349835)

<div class="topic-metadata">

**Author:** [@Atul\_Chadha](https://discuss.elastic.co/u/Atul_Chadha)\
**Replies:** 1\
**Last updated:** [December 22, 2023, 2:20am UTC](https://discuss.elastic.co/t/index-distribution-clarification/349835 "2023-12-22T02:20:05Z")

</div>

I am trying to add a node in my cluster running on 7.17x with 3 existing nodes ( master eligible ), the new 4th node is data only node. I am seeing new index have all primary shards allocated to 1 node, shouldn't they b…

---

## [대시보드에서 각 패널별로 날짜를 고정하는 방법](https://discuss.elastic.co/t/topic/349834)

<div class="topic-metadata">

**Author:** [@kindah7469](https://discuss.elastic.co/u/kindah7469)\
**Replies:** 0\
**Last updated:** [December 22, 2023, 1:12am UTC](https://discuss.elastic.co/t/topic/349834 "2023-12-22T01:12:04Z")

</div>

대시보드에서 데이터를 시각화 할때 2023년이면 2023년부터의 data를 보여주고, 2024년이면 2024년의 data를 보여주는 방법이 궁금합니다. 패널에도 커스텀 필터가 있고 대시보드에도 필터가 있어서 헷갈리고 어렵네요 ㅜㅜ

---

## [Logstash xml input plugin - parsing log4net:event](https://discuss.elastic.co/t/logstash-xml-input-plugin-parsing-log4net-event/349817)

<div class="topic-metadata">

**Author:** [@pumiki](https://discuss.elastic.co/u/pumiki)\
**Replies:** 4\
**Last updated:** [December 21, 2023, 10:04pm UTC](https://discuss.elastic.co/t/logstash-xml-input-plugin-parsing-log4net-event/349817 "2023-12-21T22:04:50Z")

</div>

Hello, log4net generates xml file. every event is stored in xml element called log4net:event. The issue is that logstash cant parse the element with the ":" in it. any idea ? The xml \<log4net:event\>\<log4netmessage\>…

---

## [Cant parse xml file generated with log4net using logstash](https://discuss.elastic.co/t/cant-parse-xml-file-generated-with-log4net-using-logstash/349728)

<div class="topic-metadata">

**Author:** [@pumiki](https://discuss.elastic.co/u/pumiki)\
**Replies:** 5\
**Last updated:** [December 21, 2023, 8:18pm UTC](https://discuss.elastic.co/t/cant-parse-xml-file-generated-with-log4net-using-logstash/349728 "2023-12-21T20:18:02Z")

</div>

Hello, I have c# app that logs xml file using log4net and log4net.Layout.XmlLayout (see configuration below). The generated log events contains message ang name-value collection: \<log4net:\*\*message\*\*\>\<Message from …

---

## [Default dynamic template uses enum for text fields instead of keyword](https://discuss.elastic.co/t/default-dynamic-template-uses-enum-for-text-fields-instead-of-keyword/349821)

<div class="topic-metadata">

**Author:** [@Julia\_Dai](https://discuss.elastic.co/u/Julia_Dai)\
**Replies:** 0\
**Last updated:** [December 21, 2023, 6:57pm UTC](https://discuss.elastic.co/t/default-dynamic-template-uses-enum-for-text-fields-instead-of-keyword/349821 "2023-12-21T18:57:06Z")

</div>

We're using Elasticsearch dynamic mapping for our indexes, but for some reason our indexes are mapping text fields to enum sub fields instead of keyword sub fields like it says in the docs (Dynamic field mapping | Elasti…

---

## [Locator.click: Timeout 50000ms exceeded. problem in a synthetic monitor](https://discuss.elastic.co/t/locator-click-timeout-50000ms-exceeded-problem-in-a-synthetic-monitor/349808)

<div class="topic-metadata">

**Author:** [@pagliardini](https://discuss.elastic.co/u/pagliardini)\
**Replies:** 1\
**Last updated:** [December 21, 2023, 5:44pm UTC](https://discuss.elastic.co/t/locator-click-timeout-50000ms-exceeded-problem-in-a-synthetic-monitor/349808 "2023-12-21T17:44:50Z")

</div>

Hello, I am having problems with a synthetic monitor. is this step step('Click internal:text="Available domain"i', async () =\> { await page1.getByText('Available domain').click(); await page1.getByText('Register').…

---

## [Export aggregated reports into Postgres](https://discuss.elastic.co/t/export-aggregated-reports-into-postgres/349806)

<div class="topic-metadata">

**Author:** [@tmslara.a](https://discuss.elastic.co/u/tmslara.a)\
**Replies:** 2\
**Last updated:** [December 21, 2023, 5:42pm UTC](https://discuss.elastic.co/t/export-aggregated-reports-into-postgres/349806 "2023-12-21T17:42:32Z")

</div>

Hello, I am indexing data into an Elasticsearch cluster (of one node) based on events associated with different devices, each identified by an ID. Many events can occur during the day. At the end of each day, I would li…

---

## [Migrated elasticsearch data from a failed node](https://discuss.elastic.co/t/migrated-elasticsearch-data-from-a-failed-node/349814)

<div class="topic-metadata">

**Author:** [@anon85145925](https://discuss.elastic.co/u/anon85145925)\
**Replies:** 1\
**Last updated:** [December 21, 2023, 5:33pm UTC](https://discuss.elastic.co/t/migrated-elasticsearch-data-from-a-failed-node/349814 "2023-12-21T17:33:02Z")

</div>

Hello all, One of our elasticsearch nodes (not a master node) failed yesterday, and by failed it was a human error, when trying to add disk space - the underlying disk was shrinked. We managed to expand the disk again, …

---

## [Create an alert in Kibata when no documents are received](https://discuss.elastic.co/t/create-an-alert-in-kibata-when-no-documents-are-received/349787)

<div class="topic-metadata">

**Author:** [@stobbe](https://discuss.elastic.co/u/stobbe)\
**Replies:** 1\
**Last updated:** [December 21, 2023, 4:36pm UTC](https://discuss.elastic.co/t/create-an-alert-in-kibata-when-no-documents-are-received/349787 "2023-12-21T16:36:15Z")

</div>

I want to create an Alert when no new documents (of a certain type) are created in an index for a certain amount if time. What is the best wat to achieve this? And It would be nice to in corporate this in the standard A…

---

## [Determine the user that acknowledged an Alert](https://discuss.elastic.co/t/determine-the-user-that-acknowledged-an-alert/349426)

<div class="topic-metadata">

**Author:** [@lastshadow](https://discuss.elastic.co/u/lastshadow)\
**Replies:** 5\
**Last updated:** [December 21, 2023, 4:21pm UTC](https://discuss.elastic.co/t/determine-the-user-that-acknowledged-an-alert/349426 "2023-12-21T16:21:32Z")

</div>

I have several SOC analysts in my SIEM and need to figure out the following: How do I determine who acknowledged an alert? How can the analysts filter their acknowledged alerts so they only see what they have acknowled…

---

## [Unable to upgrade ECK since v2.7.0](https://discuss.elastic.co/t/unable-to-upgrade-eck-since-v2-7-0/347915)

<div class="topic-metadata">

**Author:** [@Shiftmaj](https://discuss.elastic.co/u/Shiftmaj)\
**Replies:** 1\
**Last updated:** [December 21, 2023, 3:09pm UTC](https://discuss.elastic.co/t/unable-to-upgrade-eck-since-v2-7-0/347915 "2023-12-21T15:09:38Z")

</div>

Hi, I tried to upgrade ECK from version 2.7.0. Unfortunately, ECK version 2.8.0 and up are unable to manage my Elastic cluster. I upgraded Elastic a couple of time with ECK version 2.7.0 and it actually runs version 8.9…

---

## [Recommended exceptions for Elastic Endpoint](https://discuss.elastic.co/t/recommended-exceptions-for-elastic-endpoint/349545)

<div class="topic-metadata">

**Author:** [@slash24](https://discuss.elastic.co/u/slash24)\
**Replies:** 2\
**Last updated:** [December 21, 2023, 2:53pm UTC](https://discuss.elastic.co/t/recommended-exceptions-for-elastic-endpoint/349545 "2023-12-21T14:53:26Z")

</div>

We've got elastic (8.8) defend on few hundreds windows-servers, but also rely on Windows Defender. Due to this, we want to make sure we exclude them from one another. From Windows Defender, what processes, folders or fi…

---

## [Osquery yara rules](https://discuss.elastic.co/t/osquery-yara-rules/349795)

<div class="topic-metadata">

**Author:** [@sh1dow3r](https://discuss.elastic.co/u/sh1dow3r)\
**Replies:** 0\
**Last updated:** [December 21, 2023, 12:57pm UTC](https://discuss.elastic.co/t/osquery-yara-rules/349795 "2023-12-21T12:57:35Z")

</div>

Hey there.. I've already tried slack but no luck; hopefully someone here has encounter this issue and solved it. I have over 50 yara rules stored on gitlab in one file that I want to sweep the environment with the elas…

---

## [How to reshard the indices to overcome latency during high traffic in elasticsearch cluster](https://discuss.elastic.co/t/how-to-reshard-the-indices-to-overcome-latency-during-high-traffic-in-elasticsearch-cluster/349677)

<div class="topic-metadata">

**Author:** [@Karthikeyan\_Amaresan](https://discuss.elastic.co/u/Karthikeyan_Amaresan)\
**Replies:** 2\
**Last updated:** [December 21, 2023, 10:44am UTC](https://discuss.elastic.co/t/how-to-reshard-the-indices-to-overcome-latency-during-high-traffic-in-elasticsearch-cluster/349677 "2023-12-21T10:44:08Z")

</div>

During high traffic times, our Elasticsearch cluster is experiencing latency, and we are considering a resharding strategy to optimize performance. Below is our current index setup and the proposed resharding plan: Curr…

[Previous page](https://discuss.elastic.co/tag/none.md?no_tags=true&page=252)

[Next page](https://discuss.elastic.co/tag/none.md?no_tags=true&page=254)
