# \#none

**URL:** https://discuss.elastic.co/tag/none.md?no_tags=true&page=270

[Latest](https://discuss.elastic.co/latest.md) · [Categories](https://discuss.elastic.co/categories.md) · [Tags](https://discuss.elastic.co/tags.md)

**Page:** 271

---

## [Impossible to create a second index](https://discuss.elastic.co/t/impossible-to-create-a-second-index/347627)

<div class="topic-metadata">

**Author:** [@Christian\_1974](https://discuss.elastic.co/u/Christian_1974)\
**Replies:** 6\
**Last updated:** [November 21, 2023, 2:13pm UTC](https://discuss.elastic.co/t/impossible-to-create-a-second-index/347627 "2023-11-21T14:13:32Z")

</div>

Hi, (Sorry, I am not english. I am french, so, please, be patient with me, in english :)). I created a configuration to test logstash. The configuration log my local syslog in Kibana. That, that works. But if I try to …

---

## [Kibana 8.6 how to show the data per day per hour at the same time](https://discuss.elastic.co/t/kibana-8-6-how-to-show-the-data-per-day-per-hour-at-the-same-time/346812)

<div class="topic-metadata">

**Author:** [@RobertC1](https://discuss.elastic.co/u/RobertC1)\
**Replies:** 2\
**Last updated:** [November 21, 2023, 1:40pm UTC](https://discuss.elastic.co/t/kibana-8-6-how-to-show-the-data-per-day-per-hour-at-the-same-time/346812 "2023-11-21T13:40:47Z")

</div>

Hi guys! I am creating a dashboard where it has to show the data per day & per hour. I add 1 histogram field using @timestamp with minimal interval by day. Another histogram field using @timestamp with minimal inte…

---

## [Why it is showing java error in elastic log](https://discuss.elastic.co/t/why-it-is-showing-java-error-in-elastic-log/347622)

<div class="topic-metadata">

**Author:** [@baber1223](https://discuss.elastic.co/u/baber1223)\
**Replies:** 0\
**Last updated:** [November 21, 2023, 10:44am UTC](https://discuss.elastic.co/t/why-it-is-showing-java-error-in-elastic-log/347622 "2023-11-21T10:44:42Z")

</div>

It is showing follow in my elasticsearch log : at org.elasticsearch.ingest.geoip.GeoIpDownloader.updateDatabases(GeoIpDownloader.java:140) ~\[?:?\] at org.elasticsearch.ingest.geoip.GeoIpDownloader.runDownloader(G…

---

## [Use difference between two numeric values as query criteria in kibana](https://discuss.elastic.co/t/use-difference-between-two-numeric-values-as-query-criteria-in-kibana/347400)

<div class="topic-metadata">

**Author:** [@markus](https://discuss.elastic.co/u/markus)\
**Replies:** 6\
**Last updated:** [November 21, 2023, 10:38am UTC](https://discuss.elastic.co/t/use-difference-between-two-numeric-values-as-query-criteria-in-kibana/347400 "2023-11-21T10:38:09Z")

</div>

Hi, we have a logsource that we are ingesting into kibana using logstash fileinput. The logsource contains amon other things two numerical values. The fields are indexed as numerical values. What I'd like to do is fin…

---

## [How to copy the data from an index of 150 GB size to another](https://discuss.elastic.co/t/how-to-copy-the-data-from-an-index-of-150-gb-size-to-another/347574)

<div class="topic-metadata">

**Author:** [@Mohan91](https://discuss.elastic.co/u/Mohan91)\
**Replies:** 1\
**Last updated:** [November 21, 2023, 10:15am UTC](https://discuss.elastic.co/t/how-to-copy-the-data-from-an-index-of-150-gb-size-to-another/347574 "2023-11-21T10:15:15Z")

</div>

I have an index "Index A" of size 150+ GB, there are few fields which needs to be converted to NESTED and for few fields the type to be changed from "keyword" to "text" and vice versa. I have created a new index "Index …

---

## [First thoughts on ES|QL](https://discuss.elastic.co/t/first-thoughts-on-es-ql/347607)

<div class="topic-metadata">

**Author:** [@Wolfram\_Haussig](https://discuss.elastic.co/u/Wolfram_Haussig)\
**Replies:** 1\
**Last updated:** [November 21, 2023, 10:01am UTC](https://discuss.elastic.co/t/first-thoughts-on-es-ql/347607 "2023-11-21T10:01:48Z")

</div>

Dear all, We are currently trying out the new ES|QL query language and as far as I have used it it is a great improvement! The flexibility and the relatively easy grammar will surely make this my preferred language in t…

---

## [Build IndexSettings from two IndexSettings](https://discuss.elastic.co/t/build-indexsettings-from-two-indexsettings/347611)

<div class="topic-metadata">

**Author:** [@Ben5](https://discuss.elastic.co/u/Ben5)\
**Replies:** 0\
**Last updated:** [November 21, 2023, 9:45am UTC](https://discuss.elastic.co/t/build-indexsettings-from-two-indexsettings/347611 "2023-11-21T09:45:15Z")

</div>

Hi, Using Java Transport Client, I was able to build index Settings from two Settings like that: Settings.builder().put(SETTINGS\_1).put(SETTINGS\_2).build() How can I do the same with Elasticsearch Client and IndexSett…

---

## [SSL Error when running logstash avro schema registry in ubuntu](https://discuss.elastic.co/t/ssl-error-when-running-logstash-avro-schema-registry-in-ubuntu/347605)

<div class="topic-metadata">

**Author:** [@amaleswar](https://discuss.elastic.co/u/amaleswar)\
**Replies:** 0\
**Last updated:** [November 21, 2023, 9:19am UTC](https://discuss.elastic.co/t/ssl-error-when-running-logstash-avro-schema-registry-in-ubuntu/347605 "2023-11-21T09:19:59Z")

</div>

I\`m trying to migrate from CentOS to Ubuntu. Able to install the Logstash and added registry info and running the config locally to make sure, it is running as expected. But it is throwing below error. \[ERROR\] 2023-11-2…

---

## [Recover file from quarantine](https://discuss.elastic.co/t/recover-file-from-quarantine/346973)

<div class="topic-metadata">

**Author:** [@GKre](https://discuss.elastic.co/u/GKre)\
**Replies:** 9\
**Last updated:** [November 21, 2023, 8:32am UTC](https://discuss.elastic.co/t/recover-file-from-quarantine/346973 "2023-11-21T08:32:22Z")

</div>

well - Security quarantined nnotes.dll that is part of "HCL Notes" Installation. Now i am trying to find out how to get back the file without the need to reinstall the application. I created a rule exception and i can …

---

## [Logstash buffer for Sentinel - Architecture questions](https://discuss.elastic.co/t/logstash-buffer-for-sentinel-architecture-questions/347596)

<div class="topic-metadata">

**Author:** [@zatury](https://discuss.elastic.co/u/zatury)\
**Replies:** 1\
**Last updated:** [November 21, 2023, 8:11am UTC](https://discuss.elastic.co/t/logstash-buffer-for-sentinel-architecture-questions/347596 "2023-11-21T08:11:23Z")

</div>

Hello, My company is currently transitioning from Splunk to Sentinel, despite my preference for Elastic. Sentinel utilizes AMA agents to gather logs from various sources, listening on port 514. However, a significant ch…

---

## [Elastic-agents goes offline and get back online status frequently](https://discuss.elastic.co/t/elastic-agents-goes-offline-and-get-back-online-status-frequently/347195)

<div class="topic-metadata">

**Author:** [@cLaYYs](https://discuss.elastic.co/u/cLaYYs)\
**Replies:** 5\
**Last updated:** [November 21, 2023, 7:46am UTC](https://discuss.elastic.co/t/elastic-agents-goes-offline-and-get-back-online-status-frequently/347195 "2023-11-21T07:46:48Z")

</div>

Hi All, Version:8.9 OS:Windows Server I have encountered with this problem so recently. And it is not occurs for all elastic-agents. it happens for 4 elastic-agents. The problem is the agent status seems offline whe…

---

## [Send logs from filebeat to logstash via NGINX reverse proxy](https://discuss.elastic.co/t/send-logs-from-filebeat-to-logstash-via-nginx-reverse-proxy/347590)

<div class="topic-metadata">

**Author:** [@R\_H\_O\_M\_B\_I\_X](https://discuss.elastic.co/u/R_H_O_M_B_I_X)\
**Replies:** 0\
**Last updated:** [November 21, 2023, 7:22am UTC](https://discuss.elastic.co/t/send-logs-from-filebeat-to-logstash-via-nginx-reverse-proxy/347590 "2023-11-21T07:22:34Z")

</div>

Hi I'm looking for a way to forward my logs from filebeat where filebeat is reading logs from my local machine file and sending it to my private server in which logstash is installed via nginx reverse proxy where nginx …

---

## [Disabling GeoIP processor](https://discuss.elastic.co/t/disabling-geoip-processor/347581)

<div class="topic-metadata">

**Author:** [@hjazz6](https://discuss.elastic.co/u/hjazz6)\
**Replies:** 0\
**Last updated:** [November 21, 2023, 6:24am UTC](https://discuss.elastic.co/t/disabling-geoip-processor/347581 "2023-11-21T06:24:11Z")

</div>

Hi, I have currently set "ingest.geoip.downloader.enabled" : "false" in my elasticsearch.yml file as I am using offline databases. I'm using ES v8.8.0, and filebeat to ingest data into ES. I want to do some testing, wh…

---

## [Hashtag searches and Japanese full text search](https://discuss.elastic.co/t/hashtag-searches-and-japanese-full-text-search/347324)

<div class="topic-metadata">

**Author:** [@hari-ram-s](https://discuss.elastic.co/u/hari-ram-s)\
**Replies:** 1\
**Last updated:** [November 21, 2023, 6:11am UTC](https://discuss.elastic.co/t/hashtag-searches-and-japanese-full-text-search/347324 "2023-11-21T06:11:59Z")

</div>

We are trying to incorporate hashtag searches and Japanese full text searches in our data. We were able to achieve them separately but when we try to combine the two configs together, it doesn't work as expected. I foun…

---

## [Elastic Synthetics : Global Location on my ON-Prem Setup](https://discuss.elastic.co/t/elastic-synthetics-global-location-on-my-on-prem-setup/347341)

<div class="topic-metadata">

**Author:** [@Rudra\_Prakash\_Pal](https://discuss.elastic.co/u/Rudra_Prakash_Pal)\
**Replies:** 2\
**Last updated:** [November 21, 2023, 4:01am UTC](https://discuss.elastic.co/t/elastic-synthetics-global-location-on-my-on-prem-setup/347341 "2023-11-21T04:01:28Z")

</div>

Hi All, I have Elastic SETUP running in On-Prem \[Self-Managed\]. I am running Synthetics multi step Journeys with Private location setups, Is there a way we can connect with Elastic Global Locations and run my monitors f…

---

## [Highlight on all fields Java API](https://discuss.elastic.co/t/highlight-on-all-fields-java-api/347552)

<div class="topic-metadata">

**Author:** [@Jim\_Song](https://discuss.elastic.co/u/Jim_Song)\
**Replies:** 0\
**Last updated:** [November 20, 2023, 7:56pm UTC](https://discuss.elastic.co/t/highlight-on-all-fields-java-api/347552 "2023-11-20T19:56:04Z")

</div>

I am using Java client api to build a highlight configuration Highlight.of(h -\> h.type(HighlighterType.Unified) .fields(\<a map of fields\>) ... ... How do I specify to highlight on all…

---

## [CSV Export Permission Issue for Kibana Users (Non-Superuser) in Elasticsearch 8.6.1](https://discuss.elastic.co/t/csv-export-permission-issue-for-kibana-users-non-superuser-in-elasticsearch-8-6-1/346627)

<div class="topic-metadata">

**Author:** [@Behnam.R](https://discuss.elastic.co/u/Behnam.R)\
**Replies:** 3\
**Last updated:** [November 20, 2023, 5:46pm UTC](https://discuss.elastic.co/t/csv-export-permission-issue-for-kibana-users-non-superuser-in-elasticsearch-8-6-1/346627 "2023-11-20T17:46:21Z")

</div>

I have installed Elasticsearch with an active license, but I am encountering an issue when trying to export data to CSV while logged in as either the kibana-viewer or kibana-full user. Notably, exporting works fine when …

---

## [RequestAbortedError on bulk indexing happens randomly](https://discuss.elastic.co/t/requestabortederror-on-bulk-indexing-happens-randomly/347518)

<div class="topic-metadata">

**Author:** [@Ashan-FCC](https://discuss.elastic.co/u/Ashan-FCC)\
**Replies:** 1\
**Last updated:** [November 20, 2023, 5:23pm UTC](https://discuss.elastic.co/t/requestabortederror-on-bulk-indexing-happens-randomly/347518 "2023-11-20T17:23:25Z")

</div>

I use the bulk api to index fairly large objects. My indexing cronjob runs every 30 seconds which will index any objects updated in the last 30 seconds. I have another cronjob that runs at midnight which updates alot of …

---

## [Hide table column if used as filter](https://discuss.elastic.co/t/hide-table-column-if-used-as-filter/347391)

<div class="topic-metadata">

**Author:** [@gconradi](https://discuss.elastic.co/u/gconradi)\
**Replies:** 5\
**Last updated:** [November 20, 2023, 3:05pm UTC](https://discuss.elastic.co/t/hide-table-column-if-used-as-filter/347391 "2023-11-20T15:05:47Z")

</div>

Hi community, I'm using Kibana 8.10 (Cloud) for log analysis, with quite some columns shown in a lens table. When I filter for a specific column value, the value is shown in the filter bar and the column value is highli…

---

## [Is there any way to avoid using dfs\_query\_then\_fetch ?](https://discuss.elastic.co/t/is-there-any-way-to-avoid-using-dfs-query-then-fetch/347540)

<div class="topic-metadata">

**Author:** [@Arnaud\_Schneider](https://discuss.elastic.co/u/Arnaud_Schneider)\
**Replies:** 0\
**Last updated:** [November 20, 2023, 2:42pm UTC](https://discuss.elastic.co/t/is-there-any-way-to-avoid-using-dfs-query-then-fetch/347540 "2023-11-20T14:42:33Z")

</div>

Hello, i have an Elastic query using score to sort results by relevancy. Me, and others devs, have observed that, on one particular request, the order of the results is inconsistent, because the differents documents ar…

---

## [Elastic Agents don't see upgrade available in Kibana](https://discuss.elastic.co/t/elastic-agents-dont-see-upgrade-available-in-kibana/347271)

<div class="topic-metadata">

**Author:** [@aqiank](https://discuss.elastic.co/u/aqiank)\
**Replies:** 6\
**Last updated:** [November 20, 2023, 2:28pm UTC](https://discuss.elastic.co/t/elastic-agents-dont-see-upgrade-available-in-kibana/347271 "2023-11-20T14:28:55Z")

</div>

Hi, My Elastic Agents are currently at 8.11.0 but they don't seem to see that there is 8.11.1 so I am unable to upgrade them using Kibana. It was the same way when they were still at version 8.10.x and version 8.11.0 wa…

---

## [SSL\_ERROR\_SYSCALL error connecting to Elasticsearch using SSL CA Certificate](https://discuss.elastic.co/t/ssl-error-syscall-error-connecting-to-elasticsearch-using-ssl-ca-certificate/347536)

<div class="topic-metadata">

**Author:** [@Giovanni\_Martarello](https://discuss.elastic.co/u/Giovanni_Martarello)\
**Replies:** 0\
**Last updated:** [November 20, 2023, 2:11pm UTC](https://discuss.elastic.co/t/ssl-error-syscall-error-connecting-to-elasticsearch-using-ssl-ca-certificate/347536 "2023-11-20T14:11:38Z")

</div>

Hello I have an Elasticsearch server that uses ssl certificates issued by a certification unit. This is my configuration: #----------------------- BEGIN SECURITY AUTO CONFIGURATION ---------------------- - # # The fol…

---

## [How can create datastream automatically](https://discuss.elastic.co/t/how-can-create-datastream-automatically/347531)

<div class="topic-metadata">

**Author:** [@baber1223](https://discuss.elastic.co/u/baber1223)\
**Replies:** 1\
**Last updated:** [November 20, 2023, 2:04pm UTC](https://discuss.elastic.co/t/how-can-create-datastream-automatically/347531 "2023-11-20T14:04:53Z")

</div>

This is my logstash output part : after run , It will create index with the name of "TXT" but I want to create automatically datastream with all index templates and .. . Is that possible? output{ stdout{} elast…

---

## [Track changes in Logstash](https://discuss.elastic.co/t/track-changes-in-logstash/347452)

<div class="topic-metadata">

**Author:** [@Felicien\_Ihirwe](https://discuss.elastic.co/u/Felicien_Ihirwe)\
**Replies:** 1\
**Last updated:** [November 20, 2023, 12:05pm UTC](https://discuss.elastic.co/t/track-changes-in-logstash/347452 "2023-11-20T12:05:14Z")

</div>

How to come from data in 1 to data in 2? Note that the col1 is continuous. col1 2.3 2.3 2.3 5.7 5.7 6.1 6.1 .... .. . I want to achieve this: col1 | col2 2.3 | 1 2.3 |1 2.3 |1 5.7 |2 5.7 |2 6.1 |3 6.1…

---

## [UnavailableShardsException: at least one primary shard for the index \[.security-7\] is unavailable](https://discuss.elastic.co/t/unavailableshardsexception-at-least-one-primary-shard-for-the-index-security-7-is-unavailable/347393)

<div class="topic-metadata">

**Author:** [@rahul\_sirugudi](https://discuss.elastic.co/u/rahul_sirugudi)\
**Replies:** 5\
**Last updated:** [November 20, 2023, 11:03am UTC](https://discuss.elastic.co/t/unavailableshardsexception-at-least-one-primary-shard-for-the-index-security-7-is-unavailable/347393 "2023-11-20T11:03:48Z")

</div>

Hi, I have deleted all files manually from /var/lib/elasticsearch/nodes/0/indices/. Now when i restart Elasticsearch server. \[2023-11-17T09:20:22,899\]\[INFO \]\[o.e.x.s.a.RealmsAuthenticator\] \[ip\] Authentication of \[elast…

---

## [Logstash pipeline does not work](https://discuss.elastic.co/t/logstash-pipeline-does-not-work/347487)

<div class="topic-metadata">

**Author:** [@baber1223](https://discuss.elastic.co/u/baber1223)\
**Replies:** 2\
**Last updated:** [November 20, 2023, 10:56am UTC](https://discuss.elastic.co/t/logstash-pipeline-does-not-work/347487 "2023-11-20T10:56:27Z")

</div>

This is my pattern log : 80.253.157.26 - - \[19/Nov/2023:15:17:50 +0330\] "POST /followup/danesh/5b81bc62-d82d-4f98-aacd-eab80474faca HTTP/1.1" 200 852 This is apache log . As I know if I want to use this log in logstash…

---

## [Logstash The order of synchronized data fields is inconsistent with the source end](https://discuss.elastic.co/t/logstash-the-order-of-synchronized-data-fields-is-inconsistent-with-the-source-end/347509)

<div class="topic-metadata">

**Author:** [@haimaren](https://discuss.elastic.co/u/haimaren)\
**Replies:** 1\
**Last updated:** [November 20, 2023, 10:29am UTC](https://discuss.elastic.co/t/logstash-the-order-of-synchronized-data-fields-is-inconsistent-with-the-source-end/347509 "2023-11-20T10:29:58Z")

</div>

My Logstash Configuration input { elasticsearch { hosts =\> "http://172.19.23.12:9200" index =\> "\*" size =\> 1000 scroll =\> "5m" docinfo =\> true } } filter { mutate { …

---

## [Slow Wildcard searches are prioritized in Bool queries](https://discuss.elastic.co/t/slow-wildcard-searches-are-prioritized-in-bool-queries/347521)

<div class="topic-metadata">

**Author:** [@ratinhoo](https://discuss.elastic.co/u/ratinhoo)\
**Replies:** 0\
**Last updated:** [November 20, 2023, 10:07am UTC](https://discuss.elastic.co/t/slow-wildcard-searches-are-prioritized-in-bool-queries/347521 "2023-11-20T10:07:10Z")

</div>

Hi, we are dynamically generating bool queries that sometimes include wildcard searches. I understood that the execution order of bool queries is depending on term frequencies, document frequencies and other metrics. Pr…

---

## [Failed to retrieve password hash for reserved user \[elastic\] org.elasticsearch.action.UnavailableShardsException: at least one primary shard for the index \[.security-7\] is unavailable](https://discuss.elastic.co/t/failed-to-retrieve-password-hash-for-reserved-user-elastic-org-elasticsearch-action-unavailableshardsexception-at-least-one-primary-shard-for-the-index-security-7-is-unavailable/347499)

<div class="topic-metadata">

**Author:** [@NIK2501nc](https://discuss.elastic.co/u/NIK2501nc)\
**Replies:** 0\
**Last updated:** [November 20, 2023, 6:42am UTC](https://discuss.elastic.co/t/failed-to-retrieve-password-hash-for-reserved-user-elastic-org-elasticsearch-action-unavailableshardsexception-at-least-one-primary-shard-for-the-index-security-7-is-unavailable/347499 "2023-11-20T06:42:11Z")

</div>

failed to retrieve password hash for reserved user \[elastic\] org.elasticsearch.action.UnavailableShardsException: at least one primary shard for the index \[.security-7\] is unavailable You'll get this issue when in your …

---

## [Why does translate not work for me?](https://discuss.elastic.co/t/why-does-translate-not-work-for-me/347478)

<div class="topic-metadata">

**Author:** [@andre22](https://discuss.elastic.co/u/andre22)\
**Replies:** 2\
**Last updated:** [November 19, 2023, 5:45pm UTC](https://discuss.elastic.co/t/why-does-translate-not-work-for-me/347478 "2023-11-19T17:45:08Z")

</div>

Hi, I can't wrap my head around why I don't get this translate filter to work. I have a bunch of IoT logfiles (csv) that I want to import. One of the fields (KO-ID) does contain an internal ID of the old log engine, …

[Previous page](https://discuss.elastic.co/tag/none.md?no_tags=true&page=269)

[Next page](https://discuss.elastic.co/tag/none.md?no_tags=true&page=271)
