# \#none

**URL:** https://discuss.elastic.co/tag/none.md?no_tags=true&page=287

[Latest](https://discuss.elastic.co/latest.md) · [Categories](https://discuss.elastic.co/categories.md) · [Tags](https://discuss.elastic.co/tags.md)

**Page:** 288

---

## [Elastic Agent not matching @timestamp](https://discuss.elastic.co/t/elastic-agent-not-matching-timestamp/345334)

<div class="topic-metadata">

**Author:** [@Cara410](https://discuss.elastic.co/u/Cara410)\
**Replies:** 0\
**Last updated:** [October 18, 2023, 9:19pm UTC](https://discuss.elastic.co/t/elastic-agent-not-matching-timestamp/345334 "2023-10-18T21:19:28Z")

</div>

Hello, I migrated to Elastic Agent from Filebeat and I am having trouble getting the log timestamp to match the @timestamp. My configuration goes from Elastic Agent -\> Logstash -\> elasticsearch. I have this in my elasti…

---

## [ElasticAgent not creating new index](https://discuss.elastic.co/t/elasticagent-not-creating-new-index/345326)

<div class="topic-metadata">

**Author:** [@Cara410](https://discuss.elastic.co/u/Cara410)\
**Replies:** 1\
**Last updated:** [October 18, 2023, 9:09pm UTC](https://discuss.elastic.co/t/elasticagent-not-creating-new-index/345326 "2023-10-18T21:09:35Z")

</div>

Hello, I just migrated from using Filebeat to using Elastic Agent. I am using the custom logs integration to ingest some custom logs I have been able to get the logs into the generic default logs in Discover and have th…

---

## [Retrieving sorted results using a point-in-time search with slicing](https://discuss.elastic.co/t/retrieving-sorted-results-using-a-point-in-time-search-with-slicing/345328)

<div class="topic-metadata">

**Author:** [@valasatava](https://discuss.elastic.co/u/valasatava)\
**Replies:** 0\
**Last updated:** [October 18, 2023, 8:58pm UTC](https://discuss.elastic.co/t/retrieving-sorted-results-using-a-point-in-time-search-with-slicing/345328 "2023-10-18T20:58:16Z")

</div>

Hi everyone, I'm running into issues with retrieving results using Paginate search results | Elasticsearch Guide \[8.10\] | Elastic and preserving the sorted order across the whole data set. I need to pull lots of docume…

---

## [Ingest Pipelines in Logstash](https://discuss.elastic.co/t/ingest-pipelines-in-logstash/345316)

<div class="topic-metadata">

**Author:** [@lucasyuki](https://discuss.elastic.co/u/lucasyuki)\
**Replies:** 1\
**Last updated:** [October 18, 2023, 6:28pm UTC](https://discuss.elastic.co/t/ingest-pipelines-in-logstash/345316 "2023-10-18T18:28:32Z")

</div>

Hi, In the ingestion pipelines tab that I created and tested the dissect , how can I index it since it changes daily, in the index file I can see that the pipeline is as default, how can I change this default to the pip…

---

## [Multi-get vs Terms query performance](https://discuss.elastic.co/t/multi-get-vs-terms-query-performance/345241)

<div class="topic-metadata">

**Author:** [@CletusTSJY](https://discuss.elastic.co/u/CletusTSJY)\
**Replies:** 1\
**Last updated:** [October 18, 2023, 3:55pm UTC](https://discuss.elastic.co/t/multi-get-vs-terms-query-performance/345241 "2023-10-18T15:55:45Z")

</div>

I'm using Elasticsearch 7.16.2 and for one of my use-cases I need to fetch documents out of my Elasticsearch index in batches of 200 to 400 at a time. Each document is around 40k on disk but I only fetch certain fields, …

---

## [Elastic agent not running](https://discuss.elastic.co/t/elastic-agent-not-running/345153)

<div class="topic-metadata">

**Author:** [@Akshay\_Ranka](https://discuss.elastic.co/u/Akshay_Ranka)\
**Replies:** 1\
**Last updated:** [October 18, 2023, 3:49pm UTC](https://discuss.elastic.co/t/elastic-agent-not-running/345153 "2023-10-18T15:49:11Z")

</div>

Hi, I am facing the error Error: failed to communicate with Elastic Agent daemon: rpc error: code = Unavailable desc = connection error: desc = "transport: Error while dialing: dial unix /run/elastic-agent.sock: connec…

---

## [I can't find kibana when I open tpot](https://discuss.elastic.co/t/i-cant-find-kibana-when-i-open-tpot/345299)

<div class="topic-metadata">

**Author:** [@Chacko\_Devasia](https://discuss.elastic.co/u/Chacko_Devasia)\
**Replies:** 2\
**Last updated:** [October 18, 2023, 2:29pm UTC](https://discuss.elastic.co/t/i-cant-find-kibana-when-i-open-tpot/345299 "2023-10-18T14:29:09Z")

</div>

I have installed tpot in my vms on cloud. However after a few days of deployment I cant see kibana, the page opens up as follows. The option just disappears. This has been happening multiple times. can someone suggest a …

---

## [Plug in's into Kibana](https://discuss.elastic.co/t/plug-ins-into-kibana/345188)

<div class="topic-metadata">

**Author:** [@Manasa\_BR](https://discuss.elastic.co/u/Manasa_BR)\
**Replies:** 1\
**Last updated:** [October 18, 2023, 2:22pm UTC](https://discuss.elastic.co/t/plug-ins-into-kibana/345188 "2023-10-18T14:22:35Z")

</div>

Is it possible plugin charts into existing Kibana Dashboard? If possible do let me know how to do it , what's the procedure?

---

## [LogStash not processing log as specified in pipeline.conf](https://discuss.elastic.co/t/logstash-not-processing-log-as-specified-in-pipeline-conf/345266)

<div class="topic-metadata">

**Author:** [@AmnonH](https://discuss.elastic.co/u/AmnonH)\
**Replies:** 3\
**Last updated:** [October 18, 2023, 2:22pm UTC](https://discuss.elastic.co/t/logstash-not-processing-log-as-specified-in-pipeline-conf/345266 "2023-10-18T14:22:27Z")

</div>

I am using a pipeline.conf file to start LS It looks like this: input { file { path ==\> "C:/Elastic-stack/logstash/event-data/apache\_access.log" } } output { stdout { codec ==\> rubydebug } } However, …

---

## [Scripted URL field of optional field](https://discuss.elastic.co/t/scripted-url-field-of-optional-field/345245)

<div class="topic-metadata">

**Author:** [@Bohdan\_Dubyk](https://discuss.elastic.co/u/Bohdan_Dubyk)\
**Replies:** 1\
**Last updated:** [October 18, 2023, 2:06pm UTC](https://discuss.elastic.co/t/scripted-url-field-of-optional-field/345245 "2023-10-18T14:06:13Z")

</div>

Some of my logs/documents contain request information, and one of the fields is message.request\_id, so that field does not exist on every document. What I want to achieve is to add a Scripted Field of URL type, that'll …

---

## [Logstash - using jdbc input plugin as input. And pipiline delay as 30 seconds and batch size as 1000. Still input plugin reads all data from database doesnt get impacted by pipeline configuration of size and delay](https://discuss.elastic.co/t/logstash-using-jdbc-input-plugin-as-input-and-pipiline-delay-as-30-seconds-and-batch-size-as-1000-still-input-plugin-reads-all-data-from-database-doesnt-get-impacted-by-pipeline-configuration-of-size-and-delay/344480)

<div class="topic-metadata">

**Author:** [@Lovin\_Saini](https://discuss.elastic.co/u/Lovin_Saini)\
**Replies:** 4\
**Last updated:** [October 18, 2023, 1:56pm UTC](https://discuss.elastic.co/t/logstash-using-jdbc-input-plugin-as-input-and-pipiline-delay-as-30-seconds-and-batch-size-as-1000-still-input-plugin-reads-all-data-from-database-doesnt-get-impacted-by-pipeline-configuration-of-size-and-delay/344480 "2023-10-18T13:56:51Z")

</div>

JDBC input plugin input { jdbc { jdbc\_driver\_library =\> "/usr/share/logstash/driver/mysql-connector-java-8.0.32.jar" jdbc\_driver\_class =\> "com.mysql.cj.jdbc.Driver" jdbc\_connection\_stri…

---

## [How to implement max\_analyzed\_offset limit in Kibana \> Discovery for extra long fields](https://discuss.elastic.co/t/how-to-implement-max-analyzed-offset-limit-in-kibana-discovery-for-extra-long-fields/344892)

<div class="topic-metadata">

**Author:** [@elk1985](https://discuss.elastic.co/u/elk1985)\
**Replies:** 1\
**Last updated:** [October 18, 2023, 1:55pm UTC](https://discuss.elastic.co/t/how-to-implement-max-analyzed-offset-limit-in-kibana-discovery-for-extra-long-fields/344892 "2023-10-18T13:55:02Z")

</div>

Hello. I have problems with logs that having field message even 10 millions characters long. I will be removed from logs in future. But for now I'm getting shard fail error. The solution is setting max\_analyzed\_offset l…

---

## [Is point in time ID considered sensitive information?](https://discuss.elastic.co/t/is-point-in-time-id-considered-sensitive-information/345292)

<div class="topic-metadata">

**Author:** [@matheisco](https://discuss.elastic.co/u/matheisco)\
**Replies:** 0\
**Last updated:** [October 18, 2023, 1:47pm UTC](https://discuss.elastic.co/t/is-point-in-time-id-considered-sensitive-information/345292 "2023-10-18T13:47:31Z")

</div>

Hi! I'm implementing pagination using search\_after and the PIT API and am wondering if it's safe to propagate the PIT ID to an end user device. Am I exposing internal information to end users this way? Thank you!

---

## [Logstash not ready, when output goes down and then comes up during certificate renewal](https://discuss.elastic.co/t/logstash-not-ready-when-output-goes-down-and-then-comes-up-during-certificate-renewal/345269)

<div class="topic-metadata">

**Author:** [@djrshn2346](https://discuss.elastic.co/u/djrshn2346)\
**Replies:** 2\
**Last updated:** [October 18, 2023, 12:14pm UTC](https://discuss.elastic.co/t/logstash-not-ready-when-output-goes-down-and-then-comes-up-during-certificate-renewal/345269 "2023-10-18T12:14:55Z")

</div>

I was running a test scenario where I was using TTL period 15 mins. After first 15 mins, certificate got renewed, then I scaled down elasticsearch to zero and waited for another 15 mins, it showed that elasticsearch Host…

---

## [Plugin syslog output](https://discuss.elastic.co/t/plugin-syslog-output/345282)

<div class="topic-metadata">

**Author:** [@Manal\_A](https://discuss.elastic.co/u/Manal_A)\
**Replies:** 1\
**Last updated:** [October 18, 2023, 12:11pm UTC](https://discuss.elastic.co/t/plugin-syslog-output/345282 "2023-10-18T12:11:26Z")

</div>

I successfully installed the syslog output plugin on my Red Hat virtual machine. However, when I attempt to start Logstash and use the syslog output in my Logstash configuration file, I encounter the following error mess…

---

## [Showing visualizaiton in custom plugin kibana v.8.8.0](https://discuss.elastic.co/t/showing-visualizaiton-in-custom-plugin-kibana-v-8-8-0/345178)

<div class="topic-metadata">

**Author:** [@Amit\_Dhiman](https://discuss.elastic.co/u/Amit_Dhiman)\
**Replies:** 8\
**Last updated:** [October 18, 2023, 12:10pm UTC](https://discuss.elastic.co/t/showing-visualizaiton-in-custom-plugin-kibana-v-8-8-0/345178 "2023-10-18T12:10:10Z")

</div>

I want to render visualizations in my plugin using embeddables. Here is my code, I am stuck in the errors and unable to solve this. : Uncaught TypeError: Cannot read properties of undefined (reading 'create') Uncaught…

---

## [TTL Value for Documents Under the Indices](https://discuss.elastic.co/t/ttl-value-for-documents-under-the-indices/345194)

<div class="topic-metadata">

**Author:** [@Debasis\_Mallick](https://discuss.elastic.co/u/Debasis_Mallick)\
**Replies:** 8\
**Last updated:** [October 18, 2023, 11:54am UTC](https://discuss.elastic.co/t/ttl-value-for-documents-under-the-indices/345194 "2023-10-18T11:54:09Z")

</div>

Hi Team, We had one requirement to set the TTL value for the documents present in a index. Could you please help me how to achieve the same. Thanks, Debasis

---

## [Elastic Translog corrupted error (Unassigned shards)](https://discuss.elastic.co/t/elastic-translog-corrupted-error-unassigned-shards/345255)

<div class="topic-metadata">

**Author:** [@Rajesh123](https://discuss.elastic.co/u/Rajesh123)\
**Replies:** 1\
**Last updated:** [October 18, 2023, 11:39am UTC](https://discuss.elastic.co/t/elastic-translog-corrupted-error-unassigned-shards/345255 "2023-10-18T11:39:18Z")

</div>

Hello Friends, Can you suggest below error related translog corrupted .100+ shards are red (unassigned state) due disk failure and most of the shards recover but few shards not getting recovery. tried below option to r…

---

## [Creating a "join" mapping between two indexes using lookup](https://discuss.elastic.co/t/creating-a-join-mapping-between-two-indexes-using-lookup/345204)

<div class="topic-metadata">

**Author:** [@ugurcandede](https://discuss.elastic.co/u/ugurcandede)\
**Replies:** 4\
**Last updated:** [October 18, 2023, 11:22am UTC](https://discuss.elastic.co/t/creating-a-join-mapping-between-two-indexes-using-lookup/345204 "2023-10-18T11:22:48Z")

</div>

when I make following request. I got the following error. PUT /develop\_tickets\_dev/\_mapping { "properties": { "fieldMap": { "type": "nested", "properties": { "ts.requester": { "type":…

---

## [Logstash is restarting when trying to reload certificate](https://discuss.elastic.co/t/logstash-is-restarting-when-trying-to-reload-certificate/345100)

<div class="topic-metadata">

**Author:** [@djrshn2346](https://discuss.elastic.co/u/djrshn2346)\
**Replies:** 8\
**Last updated:** [October 18, 2023, 10:06am UTC](https://discuss.elastic.co/t/logstash-is-restarting-when-trying-to-reload-certificate/345100 "2023-10-18T10:06:18Z")

</div>

I am trying to reduce the TTL period to 10 mins and then after 8 mins, the certificate should reload but it does not happens, then it fails and restarts the Logstash, this process restart also fails and the complete pod …

---

## [AIOps no data views or saved searches found](https://discuss.elastic.co/t/aiops-no-data-views-or-saved-searches-found/344981)

<div class="topic-metadata">

**Author:** [@willemdh](https://discuss.elastic.co/u/willemdh)\
**Replies:** 10\
**Last updated:** [October 18, 2023, 8:59am UTC](https://discuss.elastic.co/t/aiops-no-data-views-or-saved-searches-found/344981 "2023-10-18T08:59:26Z")

</div>

Hello, AIOps no data views or saved searches found.. We definitely have data views / saves searches. So why don't we find them? Willem

---

## [How to know when indices mapping was updated](https://discuss.elastic.co/t/how-to-know-when-indices-mapping-was-updated/345046)

<div class="topic-metadata">

**Author:** [@pratik\_jain163](https://discuss.elastic.co/u/pratik_jain163)\
**Replies:** 6\
**Last updated:** [October 18, 2023, 7:58am UTC](https://discuss.elastic.co/t/how-to-know-when-indices-mapping-was-updated/345046 "2023-10-18T07:58:17Z")

</div>

hi All, Someone has updated the mapping of any indices, so I want to know how we can find this. And also, is there a way we can get all indices to also get udpated. and if we want to enable auditing in ES how we can d…

---

## [ES failed to connect to master node](https://discuss.elastic.co/t/es-failed-to-connect-to-master-node/344986)

<div class="topic-metadata">

**Author:** [@Genesys\_Bagus](https://discuss.elastic.co/u/Genesys_Bagus)\
**Replies:** 9\
**Last updated:** [October 18, 2023, 6:42am UTC](https://discuss.elastic.co/t/es-failed-to-connect-to-master-node/344986 "2023-10-18T06:42:08Z")

</div>

hi team, i have 3 nodes elasticsearch cluster, but at one time elasticsearch couldn't function properly because the master node left (reason = shutdown) \</\> \[2023-09-13T01:14:28,394\]\[INFO \]\[o.e.n.Node \] …

---

## [Rebalance is Not Working In Elasticsearch](https://discuss.elastic.co/t/rebalance-is-not-working-in-elasticsearch/345003)

<div class="topic-metadata">

**Author:** [@Debasis\_Mallick](https://discuss.elastic.co/u/Debasis_Mallick)\
**Replies:** 4\
**Last updated:** [October 18, 2023, 6:24am UTC](https://discuss.elastic.co/t/rebalance-is-not-working-in-elasticsearch/345003 "2023-10-18T06:24:52Z")

</div>

Hi Team, I had below scenario in my Elasticsearch setup. The cluster previously consists of 2 nodes and one index having docs around 125M. I had added one more node to the cluster but the data is not getting distribut…

---

## [Index Pattern](https://discuss.elastic.co/t/index-pattern/345214)

<div class="topic-metadata">

**Author:** [@Suleman\_Ahmed](https://discuss.elastic.co/u/Suleman_Ahmed)\
**Replies:** 2\
**Last updated:** [October 18, 2023, 5:40am UTC](https://discuss.elastic.co/t/index-pattern/345214 "2023-10-18T05:40:14Z")

</div>

hello! I am running ELK on my kubernetes cluster and unable to create index pattern. Any help will be highly appreciated. My logstash yaml is as under:- apiVersion: v1 kind: ConfigMap metadata: name: logstash-config …

---

## [Logstash-plugin kv useragent question](https://discuss.elastic.co/t/logstash-plugin-kv-useragent-question/345182)

<div class="topic-metadata">

**Author:** [@Mick1](https://discuss.elastic.co/u/Mick1)\
**Replies:** 2\
**Last updated:** [October 18, 2023, 12:53am UTC](https://discuss.elastic.co/t/logstash-plugin-kv-useragent-question/345182 "2023-10-18T00:53:47Z")

</div>

Dear ELK technical experts I have a basic logstash kv question to ask, experts please help. message data1:abcde,;,useragent:Mozilla/5.0 (X11; Linux x86\_64) AppleWebKit/537.36 (KHTML, like Gecko) Chrome/56.0.2924.87 Sa…

---

## [ELK service stops when space is limited](https://discuss.elastic.co/t/elk-service-stops-when-space-is-limited/345248)

<div class="topic-metadata">

**Author:** [@juancamiloll](https://discuss.elastic.co/u/juancamiloll)\
**Replies:** 3\
**Last updated:** [October 17, 2023, 11:23pm UTC](https://discuss.elastic.co/t/elk-service-stops-when-space-is-limited/345248 "2023-10-17T23:23:53Z")

</div>

Hello, I am working with an old version of ELK 7.6.0. I have detected that sometimes one of the 3 services stops when the disk reaches 94% or 95% of its capacity. I don't know if this is a default setting, I don't know…

---

## [How to enable user experience in kibana](https://discuss.elastic.co/t/how-to-enable-user-experience-in-kibana/344965)

<div class="topic-metadata">

**Author:** [@Manjari](https://discuss.elastic.co/u/Manjari)\
**Replies:** 1\
**Last updated:** [October 17, 2023, 8:57pm UTC](https://discuss.elastic.co/t/how-to-enable-user-experience-in-kibana/344965 "2023-10-17T20:57:43Z")

</div>

How to enable user experience in kibana. APM monitoring on java

---

## [Elasticsearch falsely(?) reporting it has reached the field limit](https://discuss.elastic.co/t/elasticsearch-falsely-reporting-it-has-reached-the-field-limit/343794)

<div class="topic-metadata">

**Author:** [@dpitchford](https://discuss.elastic.co/u/dpitchford)\
**Replies:** 3\
**Last updated:** [October 17, 2023, 5:26pm UTC](https://discuss.elastic.co/t/elasticsearch-falsely-reporting-it-has-reached-the-field-limit/343794 "2023-10-17T17:26:45Z")

</div>

When trying to index documents into an Elasticsearch 6.8.22 instance, I am seeing error messages like this: {'index': {'\_index': 'data\_explorer', '\_type': 'flywheel', '\_id': '64ff3d667ed067064bf7bd7e', 'status': 400, 'e…

---

## [Getting next 10k documents with AppSearch.list\_documents()](https://discuss.elastic.co/t/getting-next-10k-documents-with-appsearch-list-documents/345216)

<div class="topic-metadata">

**Author:** [@marc.schwarzschild](https://discuss.elastic.co/u/marc.schwarzschild)\
**Replies:** 5\
**Last updated:** [October 17, 2023, 5:14pm UTC](https://discuss.elastic.co/t/getting-next-10k-documents-with-appsearch-list-documents/345216 "2023-10-17T17:14:32Z")

</div>

Hi, I'm trying to get IDs for all our 300k+ documents. The AppSearch API has list\_documents which only lists 10k documents. Is there an argument I can use with it to get the next 10k documents? I have searched and fo…

[Previous page](https://discuss.elastic.co/tag/none.md?no_tags=true&page=286)

[Next page](https://discuss.elastic.co/tag/none.md?no_tags=true&page=288)
