# \#none

**URL:** https://discuss.elastic.co/tag/none.md?no_tags=true&page=299

[Latest](https://discuss.elastic.co/latest.md) · [Categories](https://discuss.elastic.co/categories.md) · [Tags](https://discuss.elastic.co/tags.md)

**Page:** 300

---

## [Backend calls not being traced](https://discuss.elastic.co/t/backend-calls-not-being-traced/343657)

<div class="topic-metadata">

**Author:** [@johngregg](https://discuss.elastic.co/u/johngregg)\
**Replies:** 1\
**Last updated:** [September 25, 2023, 3:11pm UTC](https://discuss.elastic.co/t/backend-calls-not-being-traced/343657 "2023-09-25T15:11:08Z")

</div>

I am using the 1.42 java agent with java 11. Some of my backend calls are not being traced. I have multiple backends that I use Apache HttpClient 4.5 with. Some are traced and some are not. I took thread dumps and th…

---

## [GROK pattern help for Audit Log](https://discuss.elastic.co/t/grok-pattern-help-for-audit-log/343761)

<div class="topic-metadata">

**Author:** [@ataylor](https://discuss.elastic.co/u/ataylor)\
**Replies:** 2\
**Last updated:** [September 25, 2023, 2:48pm UTC](https://discuss.elastic.co/t/grok-pattern-help-for-audit-log/343761 "2023-09-25T14:48:14Z")

</div>

I am struggling to find an appropriate GROK pattern to appropriately dissect my log that is being generated by the xpack Audit. My Logs currently look like {"type":"audit", "timestamp":"2023-09-07T14:34:58,359+0100", "…

---

## [How to implement Phrase suggester using .net elastic.clients.elasticsearch?](https://discuss.elastic.co/t/how-to-implement-phrase-suggester-using-net-elastic-clients-elasticsearch/343757)

<div class="topic-metadata">

**Author:** [@Bhavyagc](https://discuss.elastic.co/u/Bhavyagc)\
**Replies:** 1\
**Last updated:** [September 25, 2023, 1:25pm UTC](https://discuss.elastic.co/t/how-to-implement-phrase-suggester-using-net-elastic-clients-elasticsearch/343757 "2023-09-25T13:25:39Z")

</div>

How to implement Phrase suggester using .net elastic.clients.elasticsearch in a best way

---

## [Calculate the number of ERUs (Elasticsearch Resource Units) with an enterprise license](https://discuss.elastic.co/t/calculate-the-number-of-erus-elasticsearch-resource-units-with-an-enterprise-license/343754)

<div class="topic-metadata">

**Author:** [@Manal\_A](https://discuss.elastic.co/u/Manal_A)\
**Replies:** 0\
**Last updated:** [September 25, 2023, 12:32pm UTC](https://discuss.elastic.co/t/calculate-the-number-of-erus-elasticsearch-resource-units-with-an-enterprise-license/343754 "2023-09-25T12:32:33Z")

</div>

How do you calculate the number of ERUs (Elasticsearch Resource Units) with an enterprise license for master and data nodes in Elasticsearch ,please ?

---

## [Add link to a dashboard in the email alert of Kibana Watcher](https://discuss.elastic.co/t/add-link-to-a-dashboard-in-the-email-alert-of-kibana-watcher/343565)

<div class="topic-metadata">

**Author:** [@RJC](https://discuss.elastic.co/u/RJC)\
**Replies:** 3\
**Last updated:** [September 25, 2023, 12:12pm UTC](https://discuss.elastic.co/t/add-link-to-a-dashboard-in-the-email-alert-of-kibana-watcher/343565 "2023-09-25T12:12:45Z")

</div>

I have a watcher that send email every time a condition is met. I wonder if it is possible - and if so, then how - to add to the body text a link to a Kibana dashboard? When the recipients get that email they would the…

---

## [Not able to see watchers UI in kibana 8.7.1 version](https://discuss.elastic.co/t/not-able-to-see-watchers-ui-in-kibana-8-7-1-version/343593)

<div class="topic-metadata">

**Author:** [@prashant1](https://discuss.elastic.co/u/prashant1)\
**Replies:** 4\
**Last updated:** [September 25, 2023, 12:02pm UTC](https://discuss.elastic.co/t/not-able-to-see-watchers-ui-in-kibana-8-7-1-version/343593 "2023-09-25T12:02:56Z")

</div>

Hi, We have updated the kibana from version 7.10.2 to 8.7.1. We are not able to see watcher UI tab. With the dev tools command we are able to see the watchers. Is there any way to get watchers UI? Could someone please…

---

## [Default space](https://discuss.elastic.co/t/default-space/343747)

<div class="topic-metadata">

**Author:** [@ponpon](https://discuss.elastic.co/u/ponpon)\
**Replies:** 2\
**Last updated:** [September 25, 2023, 11:05am UTC](https://discuss.elastic.co/t/default-space/343747 "2023-09-25T11:05:48Z")

</div>

Hi, my default space is unaccessible. when I am presented with the " Select your space" page and I choose Default, I am redirected to one of the other spaces. I have restarted Kibana and I have checked that .kabana is w…

---

## [Does ece persist data outside of the container?](https://discuss.elastic.co/t/does-ece-persist-data-outside-of-the-container/343453)

<div class="topic-metadata">

**Author:** [@steman-provinzial](https://discuss.elastic.co/u/steman-provinzial)\
**Replies:** 1\
**Last updated:** [September 25, 2023, 9:56am UTC](https://discuss.elastic.co/t/does-ece-persist-data-outside-of-the-container/343453 "2023-09-25T09:56:52Z")

</div>

Hi there, does ECE persist the data / indices also locally on the respective allocator / host? All I can find is the data in the container itself. For example: sh-5.0# ls -ltr total 12 -rw-rw-r-- 1 elasticsearch e…

---

## [UNASSIGNED NODE\_LEFT](https://discuss.elastic.co/t/unassigned-node-left/343737)

<div class="topic-metadata">

**Author:** [@PugachevLB](https://discuss.elastic.co/u/PugachevLB)\
**Replies:** 0\
**Last updated:** [September 25, 2023, 9:51am UTC](https://discuss.elastic.co/t/unassigned-node-left/343737 "2023-09-25T09:51:30Z")

</div>

We have a cluster of 30 nodes (3 phys servers 64 cpu + 512 mem with 10 ES instances on each (1 master + 9 data)). Sometimes after uploading a new index (~700 Gb 24 shards \* 2 rep factor) we have some instances crushed (…

---

## [Implement word cloud in Kibana](https://discuss.elastic.co/t/implement-word-cloud-in-kibana/307480)

<div class="topic-metadata">

**Author:** [@Abhishek\_Shinde](https://discuss.elastic.co/u/Abhishek_Shinde)\
**Replies:** 2\
**Last updated:** [September 25, 2023, 8:41am UTC](https://discuss.elastic.co/t/implement-word-cloud-in-kibana/307480 "2023-09-25T08:41:28Z")

</div>

I wanted to implement Word Cloud visualization using Kibana in my application. The example is attached. I'm looking for reference material on the Elastic site on how to get this done. It would be good if someone can shar…

---

## [How to access APM server config file from ECE?](https://discuss.elastic.co/t/how-to-access-apm-server-config-file-from-ece/343716)

<div class="topic-metadata">

**Author:** [@Ong](https://discuss.elastic.co/u/Ong)\
**Replies:** 0\
**Last updated:** [September 25, 2023, 8:14am UTC](https://discuss.elastic.co/t/how-to-access-apm-server-config-file-from-ece/343716 "2023-09-25T08:14:51Z")

</div>

I am setting up RUM on a APM server on ECE. Based on the documentation , RUM needs to be enabled with this line apm-server.rum.enabled: true The problem is how do I add this line to the APM server? Unlike Elasticsearch…

---

## [Sophos integration with elastic agent v 8.9.1](https://discuss.elastic.co/t/sophos-integration-with-elastic-agent-v-8-9-1/341953)

<div class="topic-metadata">

**Author:** [@Ahmad\_Shrateh](https://discuss.elastic.co/u/Ahmad_Shrateh)\
**Replies:** 1\
**Last updated:** [September 25, 2023, 7:21am UTC](https://discuss.elastic.co/t/sophos-integration-with-elastic-agent-v-8-9-1/341953 "2023-09-25T07:21:22Z")

</div>

I working on integrating Sophos firewall via UDP --\> screenshot attached I'm receiving the logs perfectly but I had an issue with no correct parsing of the data, and since all the log details are on the same field and t…

---

## [Creating Multi-Fields using Kibana UI](https://discuss.elastic.co/t/creating-multi-fields-using-kibana-ui/343707)

<div class="topic-metadata">

**Author:** [@randomnamegenerator](https://discuss.elastic.co/u/randomnamegenerator)\
**Replies:** 0\
**Last updated:** [September 25, 2023, 6:24am UTC](https://discuss.elastic.co/t/creating-multi-fields-using-kibana-ui/343707 "2023-09-25T06:24:51Z")

</div>

Hello All, Apologies in advance if this is the wrong sub-forum to ask the question. I am new to the forum and ELK in general. I am looking to create multi-field mapping for a legacy index template using the Kibana crea…

---

## [How to fetch nested json data in separate fields](https://discuss.elastic.co/t/how-to-fetch-nested-json-data-in-separate-fields/343701)

<div class="topic-metadata">

**Author:** [@bharti](https://discuss.elastic.co/u/bharti)\
**Replies:** 1\
**Last updated:** [September 25, 2023, 5:23am UTC](https://discuss.elastic.co/t/how-to-fetch-nested-json-data-in-separate-fields/343701 "2023-09-25T05:23:02Z")

</div>

Hello I need a little help. I want to fetch some nested json data into separate fields input { beats { port =\> 5044 } } filter { if "/var/log/ABC.log" in \[log\]\[file\]\[path\] { grok { match =\> …

---

## [Elasticsearch Node went down abruptly and lost data](https://discuss.elastic.co/t/elasticsearch-node-went-down-abruptly-and-lost-data/343566)

<div class="topic-metadata">

**Author:** [@nsoni](https://discuss.elastic.co/u/nsoni)\
**Replies:** 4\
**Last updated:** [September 25, 2023, 5:16am UTC](https://discuss.elastic.co/t/elasticsearch-node-went-down-abruptly-and-lost-data/343566 "2023-09-25T05:16:23Z")

</div>

I am running Elasticsearch cluster version 7.10.0 It's running for a year now, never faced any issues. Our setup comprises 1 primary and 1 replica in a different availability zone. Distribution is through the rack\_id a…

---

## [Elastic Agent, aws-s3-default-aws-s3-vpcflow keeps failing](https://discuss.elastic.co/t/elastic-agent-aws-s3-default-aws-s3-vpcflow-keeps-failing/343697)

<div class="topic-metadata">

**Author:** [@digital-thought](https://discuss.elastic.co/u/digital-thought)\
**Replies:** 5\
**Last updated:** [September 25, 2023, 4:51am UTC](https://discuss.elastic.co/t/elastic-agent-aws-s3-default-aws-s3-vpcflow-keeps-failing/343697 "2023-09-25T04:51:41Z")

</div>

I have an AWS environment which ships VPC logs to a S3 bucket. I am using the AWS VPC Log Processing integration within Elastic Agent to process these logs and to monitor for new logs. It connects to the bucket success…

---

## [Regarding the usage of nested fields](https://discuss.elastic.co/t/regarding-the-usage-of-nested-fields/343655)

<div class="topic-metadata">

**Author:** [@yeikel](https://discuss.elastic.co/u/yeikel)\
**Replies:** 1\
**Last updated:** [September 25, 2023, 4:22am UTC](https://discuss.elastic.co/t/regarding-the-usage-of-nested-fields/343655 "2023-09-25T04:22:45Z")

</div>

Hi all, I need to ingest a large volume of records from one data source to another and one topic that I am currently debating is regarding the usage of Nested Field with Arrays or using Multi match and search across mu…

---

## [Api to get saved objects info like Dashboard for kibana 8.9.0?](https://discuss.elastic.co/t/api-to-get-saved-objects-info-like-dashboard-for-kibana-8-9-0/341855)

<div class="topic-metadata">

**Author:** [@Daemon1](https://discuss.elastic.co/u/Daemon1)\
**Replies:** 7\
**Last updated:** [September 24, 2023, 11:48pm UTC](https://discuss.elastic.co/t/api-to-get-saved-objects-info-like-dashboard-for-kibana-8-9-0/341855 "2023-09-24T23:48:24Z")

</div>

GET \<kibana host\>:\<port\>/api/saved\_objects/\<type\>/\<id\> The above API is deprecated for version 8.9.0 GET \<kibana host\>:\<port\>/api/data\_views This API only returns the info about data\_views not dashboard. What is the …

---

## [Kibana Table (dashboard) - compute percentage when all row are filters](https://discuss.elastic.co/t/kibana-table-dashboard-compute-percentage-when-all-row-are-filters/343647)

<div class="topic-metadata">

**Author:** [@ctinp](https://discuss.elastic.co/u/ctinp)\
**Replies:** 2\
**Last updated:** [September 23, 2023, 10:49pm UTC](https://discuss.elastic.co/t/kibana-table-dashboard-compute-percentage-when-all-row-are-filters/343647 "2023-09-23T22:49:14Z")

</div>

One of the fields in my logs contains a list of vulnerabilities separated by comma (e.g. attacks=XSS,SQLI,LOG4J. In Kibana, I have created a table visualisation where each row is a filter for one of the signals (e.g. at…

---

## [Do collapse keys benefit from document routing?](https://discuss.elastic.co/t/do-collapse-keys-benefit-from-document-routing/343677)

<div class="topic-metadata">

**Author:** [@davidgAID](https://discuss.elastic.co/u/davidgAID)\
**Replies:** 0\
**Last updated:** [September 23, 2023, 7:02pm UTC](https://discuss.elastic.co/t/do-collapse-keys-benefit-from-document-routing/343677 "2023-09-23T19:02:29Z")

</div>

I have an index with denormalized data that is almost exclusively used with collapse queries. If I configure index routing to use the collapse key, which would keep denormalized sibling documents on the same shard, would…

---

## [I have elk, logstash, kibana and filebeat version 7.10.1 and want upgarde to latest](https://discuss.elastic.co/t/i-have-elk-logstash-kibana-and-filebeat-version-7-10-1-and-want-upgarde-to-latest/343662)

<div class="topic-metadata">

**Author:** [@Mostafa\_Faridi](https://discuss.elastic.co/u/Mostafa_Faridi)\
**Replies:** 5\
**Last updated:** [September 23, 2023, 5:33pm UTC](https://discuss.elastic.co/t/i-have-elk-logstash-kibana-and-filebeat-version-7-10-1-and-want-upgarde-to-latest/343662 "2023-09-23T17:33:18Z")

</div>

I have install ELK stack with RPM on my Oracle Linux and its work and I have six Oracle Linux and install elasticserch and kibana and logstash on one server and install filebeat on other servers. I want right now upgrad…

---

## [DEMORA EN CARGAR INTERFAZ GRAFICA WAZUH](https://discuss.elastic.co/t/demora-en-cargar-interfaz-grafica-wazuh/343653)

<div class="topic-metadata">

**Author:** [@stefanny\_chavez\_anto](https://discuss.elastic.co/u/stefanny_chavez_anto)\
**Replies:** 1\
**Last updated:** [September 23, 2023, 2:04am UTC](https://discuss.elastic.co/t/demora-en-cargar-interfaz-grafica-wazuh/343653 "2023-09-23T02:04:04Z")

</div>

Tengo un problema al visualizar la interfaz grafica de Wazuh, he procedido a reinicar el servidor ubuntu y al momento de encender todos los servicios (filebeat, elasticsearch, kibana y wazuh-manager) están activos, pero …

---

## [Alter Index so every user can see it](https://discuss.elastic.co/t/alter-index-so-every-user-can-see-it/343537)

<div class="topic-metadata">

**Author:** [@yogobah921](https://discuss.elastic.co/u/yogobah921)\
**Replies:** 1\
**Last updated:** [September 23, 2023, 12:11am UTC](https://discuss.elastic.co/t/alter-index-so-every-user-can-see-it/343537 "2023-09-23T00:11:33Z")

</div>

I have multiple accounts with different roles and now I created a new index. Now the roles can't access the new index because it is not listed in their indices configuration. how can I alter the index so every user can…

---

## [Want to create monitoring indices for only 7 days](https://discuss.elastic.co/t/want-to-create-monitoring-indices-for-only-7-days/343605)

<div class="topic-metadata">

**Author:** [@Rakhshunda\_Noorein\_J](https://discuss.elastic.co/u/Rakhshunda_Noorein_J)\
**Replies:** 10\
**Last updated:** [September 22, 2023, 5:08pm UTC](https://discuss.elastic.co/t/want-to-create-monitoring-indices-for-only-7-days/343605 "2023-09-22T17:08:53Z")

</div>

Hello, I am monitoring my logstash instance through metricbeat monitoring. I want to configure monitoring setting as such that only 7 days monitoring indices is created in my cluster in order to monitor for only 7 days…

---

## [{:exception=\>"Java::OrgLogstash::MissingConverterException: Missing Converter handling for full class name=org.bson.types.ObjectId, simple name=ObjectId"}](https://discuss.elastic.co/t/exception-java-missing-converter-handling-for-full-class-name-org-bson-types-objectid-simple-name-objectid/343636)

<div class="topic-metadata">

**Author:** [@EL\_MALKI\_MOHAMED](https://discuss.elastic.co/u/EL_MALKI_MOHAMED)\
**Replies:** 0\
**Last updated:** [September 22, 2023, 3:26pm UTC](https://discuss.elastic.co/t/exception-java-missing-converter-handling-for-full-class-name-org-bson-types-objectid-simple-name-objectid/343636 "2023-09-22T15:26:13Z")

</div>

It not works. Please help me.the problem still persists this is my config : input { jdbc { jdbc\_driver\_library =\> "/etc/logstash/jdbc/mongojdbc3.1.jar" jdbc\_driver\_class =\> "com.dbschema…

---

## [Can I limit the search on sub items based on other fields of subitems?](https://discuss.elastic.co/t/can-i-limit-the-search-on-sub-items-based-on-other-fields-of-subitems/343574)

<div class="topic-metadata">

**Author:** [@Carlos\_Barros](https://discuss.elastic.co/u/Carlos_Barros)\
**Replies:** 1\
**Last updated:** [September 22, 2023, 2:51pm UTC](https://discuss.elastic.co/t/can-i-limit-the-search-on-sub-items-based-on-other-fields-of-subitems/343574 "2023-09-22T14:51:37Z")

</div>

Hello guys I'm new in elastic and here comes the doubt. When querying a json index, I need to find in an array of complex objects a string only in some array items. In example: considering the following info I need to…

---

## [Scroll documents with ElasticSearch 8.9 for dotnet](https://discuss.elastic.co/t/scroll-documents-with-elasticsearch-8-9-for-dotnet/343627)

<div class="topic-metadata">

**Author:** [@erhogaihe](https://discuss.elastic.co/u/erhogaihe)\
**Replies:** 0\
**Last updated:** [September 22, 2023, 1:54pm UTC](https://discuss.elastic.co/t/scroll-documents-with-elasticsearch-8-9-for-dotnet/343627 "2023-09-22T13:54:12Z")

</div>

Hi, I am looking for some assisstance in getting scrolling working for ES client (Version 8.9) for .NET. I have tried a few things but cannot get them to work, I have tried as per example in documentation for v7.17 but …

---

## [Filebeat timestamp is shown with a 4hr offset](https://discuss.elastic.co/t/filebeat-timestamp-is-shown-with-a-4hr-offset/343575)

<div class="topic-metadata">

**Author:** [@artschooldropout](https://discuss.elastic.co/u/artschooldropout)\
**Replies:** 3\
**Last updated:** [September 22, 2023, 1:37pm UTC](https://discuss.elastic.co/t/filebeat-timestamp-is-shown-with-a-4hr-offset/343575 "2023-09-22T13:37:51Z")

</div>

We have a Filebeat server (8.9) that ingests Syslog logs. The timestamp shown in GUI is 4 hours earlier than it should be. The timezone is set correctly in Kibana. The timestamp is correct when viewing JSON; it looks lik…

---

## [Elk loses contact with the master every morning at 8am and the cluster turns red](https://discuss.elastic.co/t/elk-loses-contact-with-the-master-every-morning-at-8am-and-the-cluster-turns-red/343621)

<div class="topic-metadata">

**Author:** [@abcdbdocker](https://discuss.elastic.co/u/abcdbdocker)\
**Replies:** 1\
**Last updated:** [September 22, 2023, 1:23pm UTC](https://discuss.elastic.co/t/elk-loses-contact-with-the-master-every-morning-at-8am-and-the-cluster-turns-red/343621 "2023-09-22T13:23:13Z")

</div>

重点词汇 690/5000 传统翻译模型 通用场景 hello Our cluster will turn red after 8 am every day. The cluster size is 6 hot data nodes 3 warm data nodes. The primary node is the same as the hot data node. Recently, we found a strange …

---

## [Elasticsearch Architecture nodes](https://discuss.elastic.co/t/elasticsearch-architecture-nodes/343435)

<div class="topic-metadata">

**Author:** [@Chloe\_Boissavy](https://discuss.elastic.co/u/Chloe_Boissavy)\
**Replies:** 2\
**Last updated:** [September 22, 2023, 11:58am UTC](https://discuss.elastic.co/t/elasticsearch-architecture-nodes/343435 "2023-09-22T11:58:11Z")

</div>

Hello, I have an ECK with 1 kibana + 4 nodes Elasticsearch + 1 Logstash. I am using hot warm cold rotation. I would like to change my design. I would like to change for 1 kibana + 3 nodes HOT + 3 nodes WARM + 3 nodes…

[Previous page](https://discuss.elastic.co/tag/none.md?no_tags=true&page=298)

[Next page](https://discuss.elastic.co/tag/none.md?no_tags=true&page=300)
