# \#none

**URL:** https://discuss.elastic.co/tag/none.md?no_tags=true&page=300

[Latest](https://discuss.elastic.co/latest.md) · [Categories](https://discuss.elastic.co/categories.md) · [Tags](https://discuss.elastic.co/tags.md)

**Page:** 301

---

## [Create a max of 7 monitoring indices](https://discuss.elastic.co/t/create-a-max-of-7-monitoring-indices/343603)

<div class="topic-metadata">

**Author:** [@Rakhshunda\_Noorein\_J](https://discuss.elastic.co/u/Rakhshunda_Noorein_J)\
**Replies:** 4\
**Last updated:** [September 22, 2023, 11:56am UTC](https://discuss.elastic.co/t/create-a-max-of-7-monitoring-indices/343603 "2023-09-22T11:56:24Z")

</div>

Hello, I want to configure monitoring setting as such that only 7 days monitoring indices is created in my cluster in order to monitor for only 7 days and not more.. Also Is there a way that only 1 elasticsearch monito…

---

## [Logstash jdk vulnerability](https://discuss.elastic.co/t/logstash-jdk-vulnerability/343578)

<div class="topic-metadata">

**Author:** [@eh2021-elastic](https://discuss.elastic.co/u/eh2021-elastic)\
**Replies:** 1\
**Last updated:** [September 22, 2023, 11:12am UTC](https://discuss.elastic.co/t/logstash-jdk-vulnerability/343578 "2023-09-22T11:12:48Z")

</div>

We are currently running logstash 7.16.3 but are getting flagged for the version of JDK 11.0.13 that it is using and are being told we need to upgrade the JDK version to something higher that 11.0.13. How do one upgrade…

---

## [Kibana 8.9.0](https://discuss.elastic.co/t/kibana-8-9-0/343602)

<div class="topic-metadata">

**Author:** [@Daemon1](https://discuss.elastic.co/u/Daemon1)\
**Replies:** 3\
**Last updated:** [September 22, 2023, 10:34am UTC](https://discuss.elastic.co/t/kibana-8-9-0/343602 "2023-09-22T10:34:24Z")

</div>

Kibana dashboard's time range picker always shows the default value and doesn't remember the last used value from your previous login.

---

## [Create maximum of 7 monitoring index for kibana](https://discuss.elastic.co/t/create-maximum-of-7-monitoring-index-for-kibana/343604)

<div class="topic-metadata">

**Author:** [@Rakhshunda\_Noorein\_J](https://discuss.elastic.co/u/Rakhshunda_Noorein_J)\
**Replies:** 0\
**Last updated:** [September 22, 2023, 8:06am UTC](https://discuss.elastic.co/t/create-maximum-of-7-monitoring-index-for-kibana/343604 "2023-09-22T08:06:55Z")

</div>

Hello, I want to configure monitoring setting as such that only 7 days monitoring indices is created in my cluster in order to monitor for only 7 days and not more.. Also Is there a way that only 1 kibana monitoring in…

---

## [Kibana rules/alerts "If alert matches a query" not working for custom fields](https://discuss.elastic.co/t/kibana-rules-alerts-if-alert-matches-a-query-not-working-for-custom-fields/343580)

<div class="topic-metadata">

**Author:** [@arislawrence](https://discuss.elastic.co/u/arislawrence)\
**Replies:** 0\
**Last updated:** [September 21, 2023, 11:54pm UTC](https://discuss.elastic.co/t/kibana-rules-alerts-if-alert-matches-a-query-not-working-for-custom-fields/343580 "2023-09-21T23:54:25Z")

</div>

Elasticsearch, Kibana, Logstash and Beats using version 8.9.1 or 8.10.1 When creating Kibana rules for Log threshold or Metric threshold, the "If alert matches a query" defined is a custom fields, it will not process th…

---

## [Cannot start ES after upgrading from 7.x to 8.x](https://discuss.elastic.co/t/cannot-start-es-after-upgrading-from-7-x-to-8-x/343494)

<div class="topic-metadata">

**Author:** [@roman-tasi](https://discuss.elastic.co/u/roman-tasi)\
**Replies:** 4\
**Last updated:** [September 21, 2023, 5:56pm UTC](https://discuss.elastic.co/t/cannot-start-es-after-upgrading-from-7-x-to-8-x/343494 "2023-09-21T17:56:57Z")

</div>

This is the error in my journalctl: Sep 20 11:39:43 ELK-Stack.uhtasi.local systemd\[1\]: Starting Elasticsearch... Sep 20 11:39:50 ELK-Stack.uhtasi.local systemd-entrypoint\[29322\]: Error occurred during initialization of…

---

## [Force starting Elasticsearch, even with incorrect index files](https://discuss.elastic.co/t/force-starting-elasticsearch-even-with-incorrect-index-files/343480)

<div class="topic-metadata">

**Author:** [@Leonid\_P](https://discuss.elastic.co/u/Leonid_P)\
**Replies:** 8\
**Last updated:** [September 21, 2023, 4:16pm UTC](https://discuss.elastic.co/t/force-starting-elasticsearch-even-with-incorrect-index-files/343480 "2023-09-21T16:16:07Z")

</div>

Hi there! I tried to start Elasticsearch 8.6 with loading data from index which was initially created by Elasticsearch 7.13. It fails to start with message \[2023-09-20T11:17:13,331\]\[ERROR\]\[o.e.b.Elasticsearch \] \[…

---

## [How can I represent the most recurring document in a Kibana table?](https://discuss.elastic.co/t/how-can-i-represent-the-most-recurring-document-in-a-kibana-table/343288)

<div class="topic-metadata">

**Author:** [@KristinaRaja](https://discuss.elastic.co/u/KristinaRaja)\
**Replies:** 2\
**Last updated:** [September 21, 2023, 1:44pm UTC](https://discuss.elastic.co/t/how-can-i-represent-the-most-recurring-document-in-a-kibana-table/343288 "2023-09-21T13:44:37Z")

</div>

We are using an aggregated based kibana table that displays a bunch of users who had poor calls and where the majority of those poor calls took place, etc...(the user is set as the bucket). For each user, we would like …

---

## [Failed to parse field \[request.body\] of type \[text\] in document with id](https://discuss.elastic.co/t/failed-to-parse-field-request-body-of-type-text-in-document-with-id/343543)

<div class="topic-metadata">

**Author:** [@kaldaray](https://discuss.elastic.co/u/kaldaray)\
**Replies:** 1\
**Last updated:** [September 21, 2023, 1:06pm UTC](https://discuss.elastic.co/t/failed-to-parse-field-request-body-of-type-text-in-document-with-id/343543 "2023-09-21T13:06:52Z")

</div>

Hi all, i have the following log {"@timestamp": "2023-09-21T15:04:43.583+03:00","@version": "1","message": "Request log","thread\_name": "http-nio-8080-exec-9","level": "INFO","level\_value": 20000,"X-REQUEST-ID": "ca17be…

---

## [Lab Autocomplete Missing Required Fields](https://discuss.elastic.co/t/lab-autocomplete-missing-required-fields/343489)

<div class="topic-metadata">

**Author:** [@Matt\_Clairmont](https://discuss.elastic.co/u/Matt_Clairmont)\
**Replies:** 2\
**Last updated:** [September 21, 2023, 12:17pm UTC](https://discuss.elastic.co/t/lab-autocomplete-missing-required-fields/343489 "2023-09-21T12:17:05Z")

</div>

Course: Elastic Certified Engineer Version: 8.10 Question: I was directed here by the general support folks for a potential instructor review. I’m working my way through 3.3 and noticed that there were several autoco…

---

## [How to make multiple lines of json file to single line json file](https://discuss.elastic.co/t/how-to-make-multiple-lines-of-json-file-to-single-line-json-file/343424)

<div class="topic-metadata">

**Author:** [@Narayan\_Rao](https://discuss.elastic.co/u/Narayan_Rao)\
**Replies:** 2\
**Last updated:** [September 21, 2023, 11:29am UTC](https://discuss.elastic.co/t/how-to-make-multiple-lines-of-json-file-to-single-line-json-file/343424 "2023-09-21T11:29:08Z")

</div>

I am having issue with multiple lines json file. With single line json file able to process the file with below configuration. logstash.conf input { beats{ port =\> "5044" codec =\> json } } filter { json…

---

## [How to set number\_of\_replicas at creation index at elasticsearch?](https://discuss.elastic.co/t/how-to-set-number-of-replicas-at-creation-index-at-elasticsearch/343529)

<div class="topic-metadata">

**Author:** [@emoxam](https://discuss.elastic.co/u/emoxam)\
**Replies:** 0\
**Last updated:** [September 21, 2023, 10:42am UTC](https://discuss.elastic.co/t/how-to-set-number-of-replicas-at-creation-index-at-elasticsearch/343529 "2023-09-21T10:42:21Z")

</div>

How to set number\_of\_replicas at creation index at elasticsearch ? I am using template with { "index": { "number\_of\_replicas": "0", "mapping": { "total\_fields": { "limit": "10000" } }, "refresh\_interval": "5s" …

---

## [Implement Search After in Java](https://discuss.elastic.co/t/implement-search-after-in-java/343512)

<div class="topic-metadata">

**Author:** [@Kumar25](https://discuss.elastic.co/u/Kumar25)\
**Replies:** 1\
**Last updated:** [September 21, 2023, 9:46am UTC](https://discuss.elastic.co/t/implement-search-after-in-java/343512 "2023-09-21T09:46:42Z")

</div>

Hi All, I just migrated Elastic search from 7.17 to 8.2 in Java, but my code is breaking because many libraries are deprecated now, previously we used scroll but now I need to use search after, can you please help me on…

---

## [Ingesting Strange Behavior](https://discuss.elastic.co/t/ingesting-strange-behavior/343520)

<div class="topic-metadata">

**Author:** [@yuswanul](https://discuss.elastic.co/u/yuswanul)\
**Replies:** 0\
**Last updated:** [September 21, 2023, 9:32am UTC](https://discuss.elastic.co/t/ingesting-strange-behavior/343520 "2023-09-21T09:32:26Z")

</div>

Hi there, I have trouble with ingesting from one of our logs. let me tell you the conditions first: we have been ingesting our logs from OCP4 to Elastic through Logstash and generally, we have 2 sites of the Elastic …

---

## [Split string variable by Mustache in Rules (Kibana)](https://discuss.elastic.co/t/split-string-variable-by-mustache-in-rules-kibana/343519)

<div class="topic-metadata">

**Author:** [@VolodymyrPopyk](https://discuss.elastic.co/u/VolodymyrPopyk)\
**Replies:** 0\
**Last updated:** [September 21, 2023, 9:32am UTC](https://discuss.elastic.co/t/split-string-variable-by-mustache-in-rules-kibana/343519 "2023-09-21T09:32:12Z")

</div>

Is it possible split Rule action variable {{rule.name}} by Mustache. Split symbol \_ I didn´t find some way to do this!

---

## [Filter Alerts by data\_stream.namespace](https://discuss.elastic.co/t/filter-alerts-by-data-stream-namespace/343517)

<div class="topic-metadata">

**Author:** [@DVCS](https://discuss.elastic.co/u/DVCS)\
**Replies:** 0\
**Last updated:** [September 21, 2023, 8:56am UTC](https://discuss.elastic.co/t/filter-alerts-by-data-stream-namespace/343517 "2023-09-21T08:56:57Z")

</div>

Hi All, I'm trying to filter alerts with KQL using "data\_stream.namespace" in Security -\> Alerts but no results. Even using "Group alerts by" with "data\_stream.namespace" gives no result. But the field is visible and …

---

## [Data is not saved in Elasticsearch](https://discuss.elastic.co/t/data-is-not-saved-in-elasticsearch/343506)

<div class="topic-metadata">

**Author:** [@gwa99a9](https://discuss.elastic.co/u/gwa99a9)\
**Replies:** 1\
**Last updated:** [September 21, 2023, 7:46am UTC](https://discuss.elastic.co/t/data-is-not-saved-in-elasticsearch/343506 "2023-09-21T07:46:28Z")

</div>

Hi All, My ELK setup is, Logstash running in k8s, version 7.16.2 Elasticsearch in vm with cluster of 4 data nodes and 2 coordinators all running version 7.16.2 Issue: Data is not saved into Elasticsearch and there ar…

---

## [Kibana SSO via Azure role permissions issue](https://discuss.elastic.co/t/kibana-sso-via-azure-role-permissions-issue/343514)

<div class="topic-metadata">

**Author:** [@najeeb](https://discuss.elastic.co/u/najeeb)\
**Replies:** 0\
**Last updated:** [September 21, 2023, 8:17am UTC](https://discuss.elastic.co/t/kibana-sso-via-azure-role-permissions-issue/343514 "2023-09-21T08:17:45Z")

</div>

We've implemented single sign-on (SSO) for Kibana 8.10.1, using Azure, and created two roles "superuser" and "basic user." The "basic user" role has security tab restrictions in workspace, yet when a basic user logs in,…

---

## [How to parse multiple nested arrays](https://discuss.elastic.co/t/how-to-parse-multiple-nested-arrays/343409)

<div class="topic-metadata">

**Author:** [@Ankita\_Pachauri](https://discuss.elastic.co/u/Ankita_Pachauri)\
**Replies:** 2\
**Last updated:** [September 21, 2023, 8:17am UTC](https://discuss.elastic.co/t/how-to-parse-multiple-nested-arrays/343409 "2023-09-21T08:17:16Z")

</div>

Hello everyone, I am trying to parse a json document using logstash version 8.3.3. The json document has multiple nested arrays, to flatten the document split is being used inside the filter. The issue is that the split…

---

## [Logstash not create index in Elasticsearch](https://discuss.elastic.co/t/logstash-not-create-index-in-elasticsearch/343429)

<div class="topic-metadata">

**Author:** [@Raffy\_Revanza](https://discuss.elastic.co/u/Raffy_Revanza)\
**Replies:** 3\
**Last updated:** [September 21, 2023, 7:15am UTC](https://discuss.elastic.co/t/logstash-not-create-index-in-elasticsearch/343429 "2023-09-21T07:15:15Z")

</div>

So, i want to send my CSV file in my laptop to elasticsearch to build a dashboard. I have configured the conf files and it success on my logstash, but the index not readable by elastic ? why ? here's the logs "response:…

---

## [Logged out of elk](https://discuss.elastic.co/t/logged-out-of-elk/343445)

<div class="topic-metadata">

**Author:** [@theacodes](https://discuss.elastic.co/u/theacodes)\
**Replies:** 4\
**Last updated:** [September 21, 2023, 6:46am UTC](https://discuss.elastic.co/t/logged-out-of-elk/343445 "2023-09-21T06:46:51Z")

</div>

I am logged out of my admin account of elk and am not able to log in again. any idea how to get back to my account?

---

## [Error restoring state from URL - Kibana Dashboard](https://discuss.elastic.co/t/error-restoring-state-from-url-kibana-dashboard/343281)

<div class="topic-metadata">

**Author:** [@Kumar\_Abhinav](https://discuss.elastic.co/u/Kumar_Abhinav)\
**Replies:** 2\
**Last updated:** [September 21, 2023, 5:53am UTC](https://discuss.elastic.co/t/error-restoring-state-from-url-kibana-dashboard/343281 "2023-09-21T05:53:54Z")

</div>

Hello Elastic community, I am currently facing an issue with constructing a URL for Kibana dashboards with specific filters based on a given parameter. The objective is to filter the dashboard based on the user login ar…

---

## [How to get or extract Count of fields using logstash](https://discuss.elastic.co/t/how-to-get-or-extract-count-of-fields-using-logstash/343501)

<div class="topic-metadata">

**Author:** [@Ayushi\_bhardwaj](https://discuss.elastic.co/u/Ayushi_bhardwaj)\
**Replies:** 0\
**Last updated:** [September 21, 2023, 4:42am UTC](https://discuss.elastic.co/t/how-to-get-or-extract-count-of-fields-using-logstash/343501 "2023-09-21T04:42:50Z")

</div>

Hello, I want to extract or get count of fields using logstash. Below is the query i have written but when i put this query in logstash it does not work this query does not give me the count. pls help GET /abc-int-apl…

---

## [Aggregate function help](https://discuss.elastic.co/t/aggregate-function-help/343432)

<div class="topic-metadata">

**Author:** [@Ameeruddin\_Mohammed](https://discuss.elastic.co/u/Ameeruddin_Mohammed)\
**Replies:** 3\
**Last updated:** [September 20, 2023, 11:55pm UTC](https://discuss.elastic.co/t/aggregate-function-help/343432 "2023-09-20T23:55:05Z")

</div>

hi, i have logs in this format and i want to start the aggregation when start comes in the line and end the aggregation when end occurs. the aggregation is based on "username". i was able to use aggregate function but…

---

## [Logstash with email output plugin "no such file to load -- net/smtp"](https://discuss.elastic.co/t/logstash-with-email-output-plugin-no-such-file-to-load-net-smtp/343490)

<div class="topic-metadata">

**Author:** [@lee.clemens](https://discuss.elastic.co/u/lee.clemens)\
**Replies:** 2\
**Last updated:** [September 20, 2023, 9:21pm UTC](https://discuss.elastic.co/t/logstash-with-email-output-plugin-no-such-file-to-load-net-smtp/343490 "2023-09-20T21:21:47Z")

</div>

Hello, I recently upgraded RHEL 9 from logstash-8.8.2-1.x86\_64 to logstash-8.10.1-1.x86\_64 and now logstash fails to start. We are using the email output plugin and see this error in the logs: \[2023-09-20T13:48:49,401…

---

## [Top N User Control - In the Kibana Dashboard](https://discuss.elastic.co/t/top-n-user-control-in-the-kibana-dashboard/343488)

<div class="topic-metadata">

**Author:** [@Kumar\_Abhinav](https://discuss.elastic.co/u/Kumar_Abhinav)\
**Replies:** 1\
**Last updated:** [September 20, 2023, 9:21pm UTC](https://discuss.elastic.co/t/top-n-user-control-in-the-kibana-dashboard/343488 "2023-09-20T21:21:23Z")

</div>

I am grouping the visuals in my dashboard with Top 10 or 20 + others + missing. I want to give this control to users to filter the data to see themselves in how many counts they want to see that data. How should I do i…

---

## [Please delete account](https://discuss.elastic.co/t/please-delete-account/343485)

<div class="topic-metadata">

**Author:** [@AndyB](https://discuss.elastic.co/u/AndyB)\
**Replies:** 1\
**Last updated:** [September 20, 2023, 7:32pm UTC](https://discuss.elastic.co/t/please-delete-account/343485 "2023-09-20T19:32:31Z")

</div>

Please delete my account.

---

## [REST api: delete dashboard](https://discuss.elastic.co/t/rest-api-delete-dashboard/343471)

<div class="topic-metadata">

**Author:** [@emmanuel\_t](https://discuss.elastic.co/u/emmanuel_t)\
**Replies:** 1\
**Last updated:** [September 20, 2023, 7:24pm UTC](https://discuss.elastic.co/t/rest-api-delete-dashboard/343471 "2023-09-20T19:24:16Z")

</div>

I see that the saved objects API is deprecated, and that's a real bummer, the API was extremely useful for us. For most of our use cases we can probably get by using the import/export API as a worse (from our point of vi…

---

## [Integration Dashboard Links](https://discuss.elastic.co/t/integration-dashboard-links/342842)

<div class="topic-metadata">

**Author:** [@cappy](https://discuss.elastic.co/u/cappy)\
**Replies:** 3\
**Last updated:** [September 20, 2023, 6:08pm UTC](https://discuss.elastic.co/t/integration-dashboard-links/342842 "2023-09-20T18:08:08Z")

</div>

I am using version 8.8.2. No matter if I set server.basePath or server.publicBaseUrl, the links inside of the dashboards for the integrations still reference a static path like $host/app/dashboards/blah, even if I remov…

---

## [How can I remove the duplicate in the logs and prevent to create new docs](https://discuss.elastic.co/t/how-can-i-remove-the-duplicate-in-the-logs-and-prevent-to-create-new-docs/343417)

<div class="topic-metadata">

**Author:** [@Cruz](https://discuss.elastic.co/u/Cruz)\
**Replies:** 7\
**Last updated:** [September 20, 2023, 5:34pm UTC](https://discuss.elastic.co/t/how-can-i-remove-the-duplicate-in-the-logs-and-prevent-to-create-new-docs/343417 "2023-09-20T17:34:44Z")

</div>

Hello everyone! I have this logs { "\_index": ".ds-my-neoada-stream-2023.09.14-000005", "\_id": "T8v5sIoB0eBbzdbCLRnW", "\_version": 1, "\_score": 0, "\_source": { "from\_plant": "N/A", "tick\_current": "IT-…

[Previous page](https://discuss.elastic.co/tag/none.md?no_tags=true&page=299)

[Next page](https://discuss.elastic.co/tag/none.md?no_tags=true&page=301)
