# \#none

**URL:** https://discuss.elastic.co/tag/none.md?no_tags=true&page=283

[Latest](https://discuss.elastic.co/latest.md) · [Categories](https://discuss.elastic.co/categories.md) · [Tags](https://discuss.elastic.co/tags.md)

**Page:** 284

---

## [Display Overall Max and Average of Sum in TSVB in Metric and Markdown Visualizations (v8.6.1)](https://discuss.elastic.co/t/display-overall-max-and-average-of-sum-in-tsvb-in-metric-and-markdown-visualizations-v8-6-1/345411)

<div class="topic-metadata">

**Author:** [@Behnam.R](https://discuss.elastic.co/u/Behnam.R)\
**Replies:** 3\
**Last updated:** [October 27, 2023, 8:57am UTC](https://discuss.elastic.co/t/display-overall-max-and-average-of-sum-in-tsvb-in-metric-and-markdown-visualizations-v8-6-1/345411 "2023-10-27T08:57:05Z")

</div>

Hi all, I'm using Elastic version 8.6.1. In Kibana's TSVB, I've set up a Time Series visualization where I've first aggregated using the Sum of a specific field. I then applied a secondary pipeline aggregation to comput…

---

## [Logstash JMX plugin offline installation - why the creator dont create a zip with all dependency for install offline?](https://discuss.elastic.co/t/logstash-jmx-plugin-offline-installation-why-the-creator-dont-create-a-zip-with-all-dependency-for-install-offline/345884)

<div class="topic-metadata">

**Author:** [@martel](https://discuss.elastic.co/u/martel)\
**Replies:** 0\
**Last updated:** [October 27, 2023, 6:58am UTC](https://discuss.elastic.co/t/logstash-jmx-plugin-offline-installation-why-the-creator-dont-create-a-zip-with-all-dependency-for-install-offline/345884 "2023-10-27T06:58:36Z")

</div>

Hey, Im very bored, I read the post about installing a plugin in offline mode, but why not force the creators to make a zip with everything needed to do it offline?? seriously.. only have one gem file and this one must…

---

## [Ordering Gauge Visualisation](https://discuss.elastic.co/t/ordering-gauge-visualisation/345690)

<div class="topic-metadata">

**Author:** [@Ric\_UTS](https://discuss.elastic.co/u/Ric_UTS)\
**Replies:** 2\
**Last updated:** [October 27, 2023, 1:30am UTC](https://discuss.elastic.co/t/ordering-gauge-visualisation/345690 "2023-10-27T01:30:15Z")

</div>

Hello. I have been trying to create a gauge-based dashboard visualisation but it appears that I am unable to oder it, either by count or by the metric keyword. Please see attached image. I would have preferred it to b…

---

## [JSON timestamp coming as text](https://discuss.elastic.co/t/json-timestamp-coming-as-text/345633)

<div class="topic-metadata">

**Author:** [@ataylor](https://discuss.elastic.co/u/ataylor)\
**Replies:** 6\
**Last updated:** [October 27, 2023, 12:45am UTC](https://discuss.elastic.co/t/json-timestamp-coming-as-text/345633 "2023-10-27T00:45:25Z")

</div>

Basically I am not getting a @timestamp field that is a date - its coming through as text. #this is my .conf file (with some stuff excluded for security) input{ beats{ port =\> 5048 } } filter { json { …

---

## [Extract hostname from log file name](https://discuss.elastic.co/t/extract-hostname-from-log-file-name/345761)

<div class="topic-metadata">

**Author:** [@Indeed2000](https://discuss.elastic.co/u/Indeed2000)\
**Replies:** 9\
**Last updated:** [October 26, 2023, 8:44pm UTC](https://discuss.elastic.co/t/extract-hostname-from-log-file-name/345761 "2023-10-26T20:44:26Z")

</div>

Hi on logstash need to use file as input, output as http. now question is how can i extract hostname from log filename, here is file name: /tmp/log.hostname1.20230720 /tmp/log.hostname2.20230720 Any idea Thanks

---

## [How to move indexes withing one node between mount points](https://discuss.elastic.co/t/how-to-move-indexes-withing-one-node-between-mount-points/345707)

<div class="topic-metadata">

**Author:** [@secsec](https://discuss.elastic.co/u/secsec)\
**Replies:** 2\
**Last updated:** [October 26, 2023, 7:26pm UTC](https://discuss.elastic.co/t/how-to-move-indexes-withing-one-node-between-mount-points/345707 "2023-10-26T19:26:50Z")

</div>

Hello, im running one Elastic node 8.10.4. Im using logstash to create one index per linux machines per day as can be seen below: But because of huge amount of data. I would like move indexes 30days and older from c…

---

## [Stop shard balancing](https://discuss.elastic.co/t/stop-shard-balancing/345678)

<div class="topic-metadata">

**Author:** [@SleekPainter01](https://discuss.elastic.co/u/SleekPainter01)\
**Replies:** 2\
**Last updated:** [October 26, 2023, 7:21pm UTC](https://discuss.elastic.co/t/stop-shard-balancing/345678 "2023-10-26T19:21:13Z")

</div>

Good morning everything is fine? I have 3 clients receiving logs via filebeat. And I have 1 Elasticsearch node for each client. However, load balancing of fragments between nodes is taking place. How could this balan…

---

## [One of the primary shard of the index is corrupt](https://discuss.elastic.co/t/one-of-the-primary-shard-of-the-index-is-corrupt/345838)

<div class="topic-metadata">

**Author:** [@Aayush\_Kumar1](https://discuss.elastic.co/u/Aayush_Kumar1)\
**Replies:** 1\
**Last updated:** [October 26, 2023, 7:04pm UTC](https://discuss.elastic.co/t/one-of-the-primary-shard-of-the-index-is-corrupt/345838 "2023-10-26T19:04:52Z")

</div>

Hi, I am getting this error. Is there any way to restore this shard? /\_cluster/allocation/explain?pretty { "index" : "es-document-000004", "shard" : 2, "primary" : true, "current\_state" : "unassigned", "unass…

---

## [Kibana 8.6 TVSB Gauge chart does not show large numbers](https://discuss.elastic.co/t/kibana-8-6-tvsb-gauge-chart-does-not-show-large-numbers/345738)

<div class="topic-metadata">

**Author:** [@RobertC1](https://discuss.elastic.co/u/RobertC1)\
**Replies:** 5\
**Last updated:** [October 26, 2023, 3:52pm UTC](https://discuss.elastic.co/t/kibana-8-6-tvsb-gauge-chart-does-not-show-large-numbers/345738 "2023-10-26T15:52:19Z")

</div>

FInd out the nunber of a SUM in a lens visualization. But when I try to do the same visualization in TVSB gauge option, and this is the value that shows: Are there parameters to adjust? Thanks in advance

---

## [Academic Research of OpenSource Communities Culture](https://discuss.elastic.co/t/academic-research-of-opensource-communities-culture/345847)

<div class="topic-metadata">

**Author:** [@xxxphobic](https://discuss.elastic.co/u/xxxphobic)\
**Replies:** 0\
**Last updated:** [October 26, 2023, 3:12pm UTC](https://discuss.elastic.co/t/academic-research-of-opensource-communities-culture/345847 "2023-10-26T15:12:39Z")

</div>

Hello everyone! My name is Zoya, and I am a student from the University of Białystok, Poland. Together with my project partner Zosia, we are conducting a study on OpenSource Communities: the culture of collaborations an…

---

## [ "How can I implement a phrase suggester using .NET Elastic.Client.Elasticsearch?"](https://discuss.elastic.co/t/how-can-i-implement-a-phrase-suggester-using-net-elastic-client-elasticsearch/345836)

<div class="topic-metadata">

**Author:** [@zain12](https://discuss.elastic.co/u/zain12)\
**Replies:** 0\
**Last updated:** [October 26, 2023, 2:21pm UTC](https://discuss.elastic.co/t/how-can-i-implement-a-phrase-suggester-using-net-elastic-client-elasticsearch/345836 "2023-10-26T14:21:19Z")

</div>

"What's the most effective approach to implementing a Phrase suggester using .NET Elastic.Client.Elasticsearch?"

---

## [How are multiple conditions interpreted in Kibana rules](https://discuss.elastic.co/t/how-are-multiple-conditions-interpreted-in-kibana-rules/345419)

<div class="topic-metadata">

**Author:** [@zvazquez](https://discuss.elastic.co/u/zvazquez)\
**Replies:** 1\
**Last updated:** [October 26, 2023, 1:46pm UTC](https://discuss.elastic.co/t/how-are-multiple-conditions-interpreted-in-kibana-rules/345419 "2023-10-26T13:46:39Z")

</div>

Hi, Just looking for some guidance on how multiple conditions behave within a Kibana rule. For example, the screenshot above shows a rule with 2 conditions, are those conditions interpreted as an "and" operator, and …

---

## [Logstash Service With Plugin that close after finish](https://discuss.elastic.co/t/logstash-service-with-plugin-that-close-after-finish/345820)

<div class="topic-metadata">

**Author:** [@Samuele\_Lolli](https://discuss.elastic.co/u/Samuele_Lolli)\
**Replies:** 0\
**Last updated:** [October 26, 2023, 1:13pm UTC](https://discuss.elastic.co/t/logstash-service-with-plugin-that-close-after-finish/345820 "2023-10-26T13:13:58Z")

</div>

Hi everyone, i have a quick question. I created a pipeline that after completition end by closing the prompt and my current configuration is logstash as a service in a linux server. What happens if i add the pipeline t…

---

## [\[Kibana\] Visualize number of documents having a field inferior to the 99th percentile of this field](https://discuss.elastic.co/t/kibana-visualize-number-of-documents-having-a-field-inferior-to-the-99th-percentile-of-this-field/344485)

<div class="topic-metadata">

**Author:** [@JeromeLavadou](https://discuss.elastic.co/u/JeromeLavadou)\
**Replies:** 4\
**Last updated:** [October 26, 2023, 12:40pm UTC](https://discuss.elastic.co/t/kibana-visualize-number-of-documents-having-a-field-inferior-to-the-99th-percentile-of-this-field/344485 "2023-10-26T12:40:17Z")

</div>

Hello, Is there a way, in a Kibana visualization (Lens, TSVB...), to display on a chart (line, bar, etc.), for each time bucket, the number of documents having a field, let's says "response\_time", inferior to the 99th p…

---

## [Download csv report is intermittently failing if documents are more](https://discuss.elastic.co/t/download-csv-report-is-intermittently-failing-if-documents-are-more/345775)

<div class="topic-metadata">

**Author:** [@rkidev](https://discuss.elastic.co/u/rkidev)\
**Replies:** 1\
**Last updated:** [October 26, 2023, 12:23pm UTC](https://discuss.elastic.co/t/download-csv-report-is-intermittently-failing-if-documents-are-more/345775 "2023-10-26T12:23:52Z")

</div>

Hi, download csv report is always failing if documents are more than 40k, and for around 30k documents it's getting success sometimes but sometimes it's failing. I am using Kibana 7.16.3 version single node cluster and…

---

## [Show complete xml content on mousehover in Kibana 8.3.2 table view](https://discuss.elastic.co/t/show-complete-xml-content-on-mousehover-in-kibana-8-3-2-table-view/345619)

<div class="topic-metadata">

**Author:** [@rkidev](https://discuss.elastic.co/u/rkidev)\
**Replies:** 3\
**Last updated:** [October 26, 2023, 10:07am UTC](https://discuss.elastic.co/t/show-complete-xml-content-on-mousehover-in-kibana-8-3-2-table-view/345619 "2023-10-26T10:07:10Z")

</div>

Hi, I added the fields from documents in Discover and save it. After that I visualized that saved table from library into dashboard. One of the field is having xml content but in table it's not showing complete content. …

---

## [Total number of shards](https://discuss.elastic.co/t/total-number-of-shards/345749)

<div class="topic-metadata">

**Author:** [@lemospt](https://discuss.elastic.co/u/lemospt)\
**Replies:** 2\
**Last updated:** [October 26, 2023, 9:25am UTC](https://discuss.elastic.co/t/total-number-of-shards/345749 "2023-10-26T09:25:27Z")

</div>

Hi Guys, i have an elastic cluster with 5 nodes. This cluster is configured 1290 indices, all indices is configured to have 2 primary shards and 1 replica shard. For me the cluster should have 3\*1290=3870 shards but ac…

---

## [Alternative to CLASSPATH for ecs-logging-core.jar and jul-ecs-formatter.jar with Tomcat](https://discuss.elastic.co/t/alternative-to-classpath-for-ecs-logging-core-jar-and-jul-ecs-formatter-jar-with-tomcat/345785)

<div class="topic-metadata">

**Author:** [@AlexanderDyas](https://discuss.elastic.co/u/AlexanderDyas)\
**Replies:** 0\
**Last updated:** [October 26, 2023, 9:00am UTC](https://discuss.elastic.co/t/alternative-to-classpath-for-ecs-logging-core-jar-and-jul-ecs-formatter-jar-with-tomcat/345785 "2023-10-26T09:00:17Z")

</div>

Tomcat 9.0.52 Java openjdk version "1.8.0\_302" Linux As per the suggestion (Get started | ECS Logging Java Reference \[1.x\] | Elastic) I have been successfully using ecs-logging-core.jar and jul-ecs-formatter.jar by ad…

---

## [Trying to use sum\_bucket agg to summarize the last value per server into a total](https://discuss.elastic.co/t/trying-to-use-sum-bucket-agg-to-summarize-the-last-value-per-server-into-a-total/345729)

<div class="topic-metadata">

**Author:** [@mekberg](https://discuss.elastic.co/u/mekberg)\
**Replies:** 4\
**Last updated:** [October 26, 2023, 8:06am UTC](https://discuss.elastic.co/t/trying-to-use-sum-bucket-agg-to-summarize-the-last-value-per-server-into-a-total/345729 "2023-10-26T08:06:44Z")

</div>

I'm trying to create a search (ultimately a visualization) that will give me the total number of Controller nodes in a cluster. Each node reports metrics every 15 seconds, and each document will contain the value for tha…

---

## [I need to use the Suggester when I enable the DLS](https://discuss.elastic.co/t/i-need-to-use-the-suggester-when-i-enable-the-dls/345263)

<div class="topic-metadata">

**Author:** [@sjp.jamalian](https://discuss.elastic.co/u/sjp.jamalian)\
**Replies:** 4\
**Last updated:** [October 26, 2023, 6:34am UTC](https://discuss.elastic.co/t/i-need-to-use-the-suggester-when-i-enable-the-dls/345263 "2023-10-26T06:34:42Z")

</div>

Hello, When I enable the security and want to use the Suggester, I get this error: org.elasticsearch.ElasticsearchException: Elasticsearch exception \[type=security\_exception, reason=Suggest isn't supported if document …

---

## [Tracing between Reactive and Servlet applications](https://discuss.elastic.co/t/tracing-between-reactive-and-servlet-applications/345727)

<div class="topic-metadata">

**Author:** [@Askhat\_Abishev](https://discuss.elastic.co/u/Askhat_Abishev)\
**Replies:** 1\
**Last updated:** [October 26, 2023, 6:06am UTC](https://discuss.elastic.co/t/tracing-between-reactive-and-servlet-applications/345727 "2023-10-26T06:06:02Z")

</div>

I have several Spring Boot REST applications (Servlet) behind Spring Cloud Gateway (WebFlux) single entry point application. I've noticed that calls that are made between services have the same trace.id in scope of one r…

---

## [Elastic agent - Logs for Hosts](https://discuss.elastic.co/t/elastic-agent-logs-for-hosts/345772)

<div class="topic-metadata">

**Author:** [@The\_BlueishSky](https://discuss.elastic.co/u/The_BlueishSky)\
**Replies:** 0\
**Last updated:** [October 26, 2023, 5:58am UTC](https://discuss.elastic.co/t/elastic-agent-logs-for-hosts/345772 "2023-10-26T05:58:33Z")

</div>

We are in process of implementing ELK Agent and more focus for better SIEM detections. At the moment our config ships all the logs and we also don't want to tailor only security events. Is there a recommendation or exp…

---

## [Notes on Alerts or auto open case](https://discuss.elastic.co/t/notes-on-alerts-or-auto-open-case/345771)

<div class="topic-metadata">

**Author:** [@Renato\_Arraes](https://discuss.elastic.co/u/Renato_Arraes)\
**Replies:** 0\
**Last updated:** [October 26, 2023, 5:41am UTC](https://discuss.elastic.co/t/notes-on-alerts-or-auto-open-case/345771 "2023-10-26T05:41:51Z")

</div>

Hello everyone, Im currently doing the configuration of the Alerts, and i want to know if theres a way to put some notes or open directly a case from an alert, since we do have to treat the Alerts we need to input some …

---

## [Configuration Elastic Cluster 8.10.3 Certificates in roles master, coordinator anda data](https://discuss.elastic.co/t/configuration-elastic-cluster-8-10-3-certificates-in-roles-master-coordinator-anda-data/345750)

<div class="topic-metadata">

**Author:** [@efrainMZ](https://discuss.elastic.co/u/efrainMZ)\
**Replies:** 1\
**Last updated:** [October 26, 2023, 4:05am UTC](https://discuss.elastic.co/t/configuration-elastic-cluster-8-10-3-certificates-in-roles-master-coordinator-anda-data/345750 "2023-10-26T04:05:04Z")

</div>

I have a question, how can I configure the certificates for an elastic cluster in version 8.10.3, it will contain master roles, coordinators, data and machine learning. Is it intended to have several roles on the nodes,…

---

## [Fscrawler, error 415 when using REST API for upload PDF file](https://discuss.elastic.co/t/fscrawler-error-415-when-using-rest-api-for-upload-pdf-file/345760)

<div class="topic-metadata">

**Author:** [@Erik\_Bors](https://discuss.elastic.co/u/Erik_Bors)\
**Replies:** 4\
**Last updated:** [October 25, 2023, 9:25pm UTC](https://discuss.elastic.co/t/fscrawler-error-415-when-using-rest-api-for-upload-pdf-file/345760 "2023-10-25T21:25:59Z")

</div>

Trying to use the REST API service of the fscrawler. When using the POST MAN with PDF file, the app is answering with the 415 code - unsupported media type Content-Type header is correct with application/pdf. Using POS…

---

## [Deprecation info missing in the docs?](https://discuss.elastic.co/t/deprecation-info-missing-in-the-docs/345744)

<div class="topic-metadata">

**Author:** [@bunste](https://discuss.elastic.co/u/bunste)\
**Replies:** 2\
**Last updated:** [October 25, 2023, 8:59pm UTC](https://discuss.elastic.co/t/deprecation-info-missing-in-the-docs/345744 "2023-10-25T20:59:16Z")

</div>

I saw the following deprecation warning today: \[ignore\_throttled\] parameter is deprecated because frozen indices have been deprecated. Consider cold or frozen tiers in place of frozen indices. So far so good, finding a…

---

## [Superuser access in each Space](https://discuss.elastic.co/t/superuser-access-in-each-space/345405)

<div class="topic-metadata">

**Author:** [@Ryan\_Downey](https://discuss.elastic.co/u/Ryan_Downey)\
**Replies:** 8\
**Last updated:** [October 25, 2023, 7:19pm UTC](https://discuss.elastic.co/t/superuser-access-in-each-space/345405 "2023-10-25T19:19:47Z")

</div>

How do you implement superuser access to every Space for any users that need that level of access? For example, in a deployment utilizing SAML for access a user has superuser privileges in one Space to manage everything…

---

## [Discover does not show any data for indices with \_source disabled](https://discuss.elastic.co/t/discover-does-not-show-any-data-for-indices-with-source-disabled/345652)

<div class="topic-metadata">

**Author:** [@leandrojmp](https://discuss.elastic.co/u/leandrojmp)\
**Replies:** 11\
**Last updated:** [October 25, 2023, 5:32pm UTC](https://discuss.elastic.co/t/discover-does-not-show-any-data-for-indices-with-source-disabled/345652 "2023-10-25T17:32:38Z")

</div>

Hello, I disabled the \_source field on a couple of indices yesterday and today I noticed that I can not see anything from those indices on Discover. I can filter on values and fields, but everything is empty on Kibana …

---

## [Redirecting postgresql tables to Elasticsearch](https://discuss.elastic.co/t/redirecting-postgresql-tables-to-elasticsearch/345458)

<div class="topic-metadata">

**Author:** [@krzychohoho](https://discuss.elastic.co/u/krzychohoho)\
**Replies:** 1\
**Last updated:** [October 25, 2023, 5:21pm UTC](https://discuss.elastic.co/t/redirecting-postgresql-tables-to-elasticsearch/345458 "2023-10-25T17:21:22Z")

</div>

Hi, I am trying to redirect my postgresql tables to elasticsearch using JDBC and Logstash. I was able to do it but i came across a problem of ingesting the same data over and over again. I know i need to use tracking co…

---

## [Elastic Agent - listen on tcp/9200?](https://discuss.elastic.co/t/elastic-agent-listen-on-tcp-9200/345756)

<div class="topic-metadata">

**Author:** [@dmgeurts](https://discuss.elastic.co/u/dmgeurts)\
**Replies:** 0\
**Last updated:** [October 25, 2023, 5:17pm UTC](https://discuss.elastic.co/t/elastic-agent-listen-on-tcp-9200/345756 "2023-10-25T17:17:54Z")

</div>

Parsedmarc can send to Elasticsearch using xpack, but rather than go through the pain of this I was hoping to use the Elastic Agent already installed on this server to do the shipping of the data. Is there an Elastic Ag…

[Previous page](https://discuss.elastic.co/tag/none.md?no_tags=true&page=282)

[Next page](https://discuss.elastic.co/tag/none.md?no_tags=true&page=284)
