# \#none

**URL:** https://discuss.elastic.co/tag/none.md?no_tags=true&page=315

[Latest](https://discuss.elastic.co/latest.md) · [Categories](https://discuss.elastic.co/categories.md) · [Tags](https://discuss.elastic.co/tags.md)

**Page:** 316

---

## [Getting "no field found in the mapping" when creating a scripted field](https://discuss.elastic.co/t/getting-no-field-found-in-the-mapping-when-creating-a-scripted-field/341684)

<div class="topic-metadata">

**Author:** [@mr\_ph](https://discuss.elastic.co/u/mr_ph)\
**Replies:** 0\
**Last updated:** [August 25, 2023, 11:45am UTC](https://discuss.elastic.co/t/getting-no-field-found-in-the-mapping-when-creating-a-scripted-field/341684 "2023-08-25T11:45:15Z")

</div>

Hi team, I am using FortiGate integration in my ELK. So I need to create a new scripted fields for more visibility into that logs. Created a scripted field with the following condition. if ( doc\['fortinet.firewall.acti…

---

## [Elastic Agent restore data views](https://discuss.elastic.co/t/elastic-agent-restore-data-views/341678)

<div class="topic-metadata">

**Author:** [@Daniel\_Lopez](https://discuss.elastic.co/u/Daniel_Lopez)\
**Replies:** 0\
**Last updated:** [August 25, 2023, 11:06am UTC](https://discuss.elastic.co/t/elastic-agent-restore-data-views/341678 "2023-08-25T11:06:48Z")

</div>

Hi guys! Data views from fleet server integrations have been removed, how could I reinstall data views and templates again? BR

---

## [Using multi-term aggregation on rollup jobs](https://discuss.elastic.co/t/using-multi-term-aggregation-on-rollup-jobs/341674)

<div class="topic-metadata">

**Author:** [@hjazz6](https://discuss.elastic.co/u/hjazz6)\
**Replies:** 0\
**Last updated:** [August 25, 2023, 10:03am UTC](https://discuss.elastic.co/t/using-multi-term-aggregation-on-rollup-jobs/341674 "2023-08-25T10:03:38Z")

</div>

Hi, Can I use multi-term aggregation on rollup jobs? My goal is to save disk space on older data, which has 6 fields (say, Field1 to Field6). After the rollup, I would like to query for the presence of records with the…

---

## [Logstash configuration file for self join field with error object mapping found a concrete value](https://discuss.elastic.co/t/logstash-configuration-file-for-self-join-field-with-error-object-mapping-found-a-concrete-value/341071)

<div class="topic-metadata">

**Author:** [@uma\_parvathy](https://discuss.elastic.co/u/uma_parvathy)\
**Replies:** 8\
**Last updated:** [August 25, 2023, 9:08am UTC](https://discuss.elastic.co/t/logstash-configuration-file-for-self-join-field-with-error-object-mapping-found-a-concrete-value/341071 "2023-08-25T09:08:26Z")

</div>

I've a logstash integration with postgresql table. the table has a self join from incident\_parent\_id to incident\_number. incident\_number ( primary key) incident\_parent\_id ( self join with incident number). But the r…

---

## [Huge disk read count when MapperParsingException](https://discuss.elastic.co/t/huge-disk-read-count-when-mapperparsingexception/341673)

<div class="topic-metadata">

**Author:** [@ShanYang](https://discuss.elastic.co/u/ShanYang)\
**Replies:** 1\
**Last updated:** [August 25, 2023, 9:41am UTC](https://discuss.elastic.co/t/huge-disk-read-count-when-mapperparsingexception/341673 "2023-08-25T09:41:52Z")

</div>

I found that the indexing efficiency of the entire cluster gradually decreased with each passing day. After checking the size of all the indices, I didn't find any abnormalities. However, at the same time, I noticed an…

---

## [Adding Custom headers to Kibana Dashboard Pdf Report](https://discuss.elastic.co/t/adding-custom-headers-to-kibana-dashboard-pdf-report/341464)

<div class="topic-metadata">

**Author:** [@Sandeep\_Raju](https://discuss.elastic.co/u/Sandeep_Raju)\
**Replies:** 1\
**Last updated:** [August 25, 2023, 9:18am UTC](https://discuss.elastic.co/t/adding-custom-headers-to-kibana-dashboard-pdf-report/341464 "2023-08-25T09:18:49Z")

</div>

Hi , I'm using Kibana 7.10 version in one of my old servers. I'm downloading a pdf report of the dashboard under "Reporting" Section. But I need to customize the Dashboard pdf header. Currently it shows blank. Is …

---

## [Elasticsearch being open source](https://discuss.elastic.co/t/elasticsearch-being-open-source/341632)

<div class="topic-metadata">

**Author:** [@JasonGoldman](https://discuss.elastic.co/u/JasonGoldman)\
**Replies:** 1\
**Last updated:** [August 25, 2023, 7:56am UTC](https://discuss.elastic.co/t/elasticsearch-being-open-source/341632 "2023-08-25T07:56:31Z")

</div>

The GitHub repository of Elasticsearch and Elastic's website should not be afraid to call Elasticsearch "open source". The upcoming release of the Open Source Definition (v1.11) will acknowledge that Server Side Public L…

---

## [Comparing disk usage on ES with different configurations](https://discuss.elastic.co/t/comparing-disk-usage-on-es-with-different-configurations/341655)

<div class="topic-metadata">

**Author:** [@hjazz6](https://discuss.elastic.co/u/hjazz6)\
**Replies:** 0\
**Last updated:** [August 25, 2023, 7:15am UTC](https://discuss.elastic.co/t/comparing-disk-usage-on-es-with-different-configurations/341655 "2023-08-25T07:15:30Z")

</div>

Hi, I'm trying to optimize the disk usage on my Elasticsearch (version 8.8), and I want to see how much disk space was used (saved) after configuring different things, e.g. dynamic vs static mapping, default compression…

---

## [How to integrate Elasticsearch (8.x) with Nest.js](https://discuss.elastic.co/t/how-to-integrate-elasticsearch-8-x-with-nest-js/341166)

<div class="topic-metadata">

**Author:** [@inkweon7269](https://discuss.elastic.co/u/inkweon7269)\
**Replies:** 3\
**Last updated:** [August 25, 2023, 6:09am UTC](https://discuss.elastic.co/t/how-to-integrate-elasticsearch-8-x-with-nest-js/341166 "2023-08-25T06:09:16Z")

</div>

I have a question about connecting Elasticsearch with Nest.js. When I make an API call to Elasticsearch, it works fine. In Nest.js, I've written the code as follows. search.module.ts import { Module } from '@nestj…

---

## [Login to kibana and access it from my website](https://discuss.elastic.co/t/login-to-kibana-and-access-it-from-my-website/341639)

<div class="topic-metadata">

**Author:** [@Neelam\_Zanvar](https://discuss.elastic.co/u/Neelam_Zanvar)\
**Replies:** 0\
**Last updated:** [August 25, 2023, 5:58am UTC](https://discuss.elastic.co/t/login-to-kibana-and-access-it-from-my-website/341639 "2023-08-25T05:58:30Z")

</div>

Hi i am trying to embed the kibana url in zabbix dashboard url widget. when i put in the kibana url, instead of giving login page it gives a blank page. Is there a way to do this?

---

## [Logstash 8.6 add a field "log.file.path"](https://discuss.elastic.co/t/logstash-8-6-add-a-field-log-file-path/341597)

<div class="topic-metadata">

**Author:** [@RobertC1](https://discuss.elastic.co/u/RobertC1)\
**Replies:** 3\
**Last updated:** [August 25, 2023, 3:33am UTC](https://discuss.elastic.co/t/logstash-8-6-add-a-field-log-file-path/341597 "2023-08-25T03:33:38Z")

</div>

Hi there I use .conf file to ingest data in my index. With the version 8.6 is added the field "log.file.path." I tried with mutate { remove\_field =\> \[ "message", "@version","host","log.file.path" \] } without suceed. …

---

## [Accurate decryption logstash data in Javascript](https://discuss.elastic.co/t/accurate-decryption-logstash-data-in-javascript/341538)

<div class="topic-metadata">

**Author:** [@Nik\_Ameer](https://discuss.elastic.co/u/Nik_Ameer)\
**Replies:** 2\
**Last updated:** [August 25, 2023, 3:26am UTC](https://discuss.elastic.co/t/accurate-decryption-logstash-data-in-javascript/341538 "2023-08-25T03:26:16Z")

</div>

I used logstash to encrypt my data using the cipher filter. My logstash.conf file are like so cipher { algorithm =\> "aes-256-cbc" cipher\_padding =\> 1 mode =\> "encrypt" so…

---

## [Kibana stumbling over a colon in APM Service Names](https://discuss.elastic.co/t/kibana-stumbling-over-a-colon-in-apm-service-names/341618)

<div class="topic-metadata">

**Author:** [@johngregg](https://discuss.elastic.co/u/johngregg)\
**Replies:** 1\
**Last updated:** [August 25, 2023, 12:20am UTC](https://discuss.elastic.co/t/kibana-stumbling-over-a-colon-in-apm-service-names/341618 "2023-08-25T00:20:29Z")

</div>

We thought it would be a good idea to have a colon in our service node names, like abc:def. However Kibana doubly escapes the colon. The page listing our services has the correct link. The colon is escaped as %3A. Na…

---

## [Implement Multi-tenancy using an Index per tenant or 10 index per tenant which is better approach](https://discuss.elastic.co/t/implement-multi-tenancy-using-an-index-per-tenant-or-10-index-per-tenant-which-is-better-approach/341610)

<div class="topic-metadata">

**Author:** [@HARSHAL\_CHAUDHARI](https://discuss.elastic.co/u/HARSHAL_CHAUDHARI)\
**Replies:** 1\
**Last updated:** [August 24, 2023, 9:11pm UTC](https://discuss.elastic.co/t/implement-multi-tenancy-using-an-index-per-tenant-or-10-index-per-tenant-which-is-better-approach/341610 "2023-08-24T21:11:22Z")

</div>

Implement Multi-tenancy using an Index per tenant or 10 indexes per tenant which is a better approach, by considering Security, Scalability, Cost-effectiveness, and Complexity.

---

## [Multi-Tenant - Shard and Index strategy / Optimizing Elasticsearch configuration?](https://discuss.elastic.co/t/multi-tenant-shard-and-index-strategy-optimizing-elasticsearch-configuration/341605)

<div class="topic-metadata">

**Author:** [@HARSHAL\_CHAUDHARI](https://discuss.elastic.co/u/HARSHAL_CHAUDHARI)\
**Replies:** 3\
**Last updated:** [August 24, 2023, 7:40pm UTC](https://discuss.elastic.co/t/multi-tenant-shard-and-index-strategy-optimizing-elasticsearch-configuration/341605 "2023-08-24T19:40:30Z")

</div>

Hi Team, Could you please suggest the Elasticsearch configuration? (for scale and performance) My use case is below I have 1000 - 2000 thousands of customers - each customer has a 100-200 index, How data nodes can b…

---

## [How do drop logs from being forwarded? My drop rule doesn't seem to be working](https://discuss.elastic.co/t/how-do-drop-logs-from-being-forwarded-my-drop-rule-doesnt-seem-to-be-working/341520)

<div class="topic-metadata">

**Author:** [@feo13](https://discuss.elastic.co/u/feo13)\
**Replies:** 4\
**Last updated:** [August 24, 2023, 6:48pm UTC](https://discuss.elastic.co/t/how-do-drop-logs-from-being-forwarded-my-drop-rule-doesnt-seem-to-be-working/341520 "2023-08-24T18:48:44Z")

</div>

I'm ingesting AWS WAF logs and would like to drop the 'ALLOW' logs. I have the following filter in place but it doesn't seem to be working: filter { if "\\"action\\":\\"ALLOW\\"" in \[message\] { drop {} } if \[ty…

---

## [Help with file name to date logstash grok](https://discuss.elastic.co/t/help-with-file-name-to-date-logstash-grok/341592)

<div class="topic-metadata">

**Author:** [@ethranes](https://discuss.elastic.co/u/ethranes)\
**Replies:** 2\
**Last updated:** [August 24, 2023, 5:07pm UTC](https://discuss.elastic.co/t/help-with-file-name-to-date-logstash-grok/341592 "2023-08-24T17:07:15Z")

</div>

Hi, the date isn't included in my log files. But the filename itself has the date. So I'm trying to extract the year month and day from the filename and then put that into a field. But logstash can't parse my filename, I…

---

## [What is the impact of aggregated queries on performance](https://discuss.elastic.co/t/what-is-the-impact-of-aggregated-queries-on-performance/341525)

<div class="topic-metadata">

**Author:** [@fangyan](https://discuss.elastic.co/u/fangyan)\
**Replies:** 3\
**Last updated:** [August 24, 2023, 4:59pm UTC](https://discuss.elastic.co/t/what-is-the-impact-of-aggregated-queries-on-performance/341525 "2023-08-24T16:59:46Z")

</div>

What is the impact of aggregated queries on performance, with a data volume of 300000, requiring 2-3 layers of aggregation :grinning:

---

## [Retry on conflict](https://discuss.elastic.co/t/retry-on-conflict/341591)

<div class="topic-metadata">

**Author:** [@Vamsi\_krishna\_Ramaya](https://discuss.elastic.co/u/Vamsi_krishna_Ramaya)\
**Replies:** 0\
**Last updated:** [August 24, 2023, 4:02pm UTC](https://discuss.elastic.co/t/retry-on-conflict/341591 "2023-08-24T16:02:20Z")

</div>

Hi I am working on a node ja project with elasticsearch so i am trying to create index with out replica even though i added that number\_of\_replicas 0 replica is generating and that gives me problem that document is geti…

---

## [Two nested Grok patterns not working](https://discuss.elastic.co/t/two-nested-grok-patterns-not-working/341533)

<div class="topic-metadata">

**Author:** [@Priyaansh\_Dwivedi](https://discuss.elastic.co/u/Priyaansh_Dwivedi)\
**Replies:** 3\
**Last updated:** [August 24, 2023, 3:54pm UTC](https://discuss.elastic.co/t/two-nested-grok-patterns-not-working/341533 "2023-08-24T15:54:46Z")

</div>

Hey everyone, I'm new to using Logstash and Elasticsearch. I've been working on collecting logs through Filebeat and then using Logstash for parsing and data cleaning. I have two Grok patterns in place. The first one ex…

---

## [Structured Data set in Elastic](https://discuss.elastic.co/t/structured-data-set-in-elastic/341379)

<div class="topic-metadata">

**Author:** [@ishani.sengupta](https://discuss.elastic.co/u/ishani.sengupta)\
**Replies:** 2\
**Last updated:** [August 24, 2023, 3:44pm UTC](https://discuss.elastic.co/t/structured-data-set-in-elastic/341379 "2023-08-24T15:44:26Z")

</div>

Working on Analytics using ELK stack, the data being used is a structure data where we are facing issue with migration and correlation. Can elastic stack handle structure data within an index or any other ways to handle…

---

## [Mendix cloud integration to Elastic for performance monitoring](https://discuss.elastic.co/t/mendix-cloud-integration-to-elastic-for-performance-monitoring/341587)

<div class="topic-metadata">

**Author:** [@latsayya](https://discuss.elastic.co/u/latsayya)\
**Replies:** 0\
**Last updated:** [August 24, 2023, 3:34pm UTC](https://discuss.elastic.co/t/mendix-cloud-integration-to-elastic-for-performance-monitoring/341587 "2023-08-24T15:34:09Z")

</div>

Our organization is using Medix Cloud services. We want to monitor the performance of the Mendix application using Elastic Kibana. I would like to know if there is any available integration to collect performance metric…

---

## [Aws ingest pipeline error in processor rename "message" to "event.original"](https://discuss.elastic.co/t/aws-ingest-pipeline-error-in-processor-rename-message-to-event-original/341472)

<div class="topic-metadata">

**Author:** [@diogoeverson](https://discuss.elastic.co/u/diogoeverson)\
**Replies:** 8\
**Last updated:** [August 24, 2023, 2:46pm UTC](https://discuss.elastic.co/t/aws-ingest-pipeline-error-in-processor-rename-message-to-event-original/341472 "2023-08-24T14:46:48Z")

</div>

Parse aws vpcflow or cloudtrail logs is not working. When testing the pipeline auto generate by filebeat it returns an error: field \[event.original\] already exists. Processors: \[ { "drop": { "if": "ctx.mess…

---

## [Reload Logstash config on shutdown](https://discuss.elastic.co/t/reload-logstash-config-on-shutdown/341545)

<div class="topic-metadata">

**Author:** [@Ljapunov](https://discuss.elastic.co/u/Ljapunov)\
**Replies:** 2\
**Last updated:** [August 24, 2023, 2:25pm UTC](https://discuss.elastic.co/t/reload-logstash-config-on-shutdown/341545 "2023-08-24T14:25:19Z")

</div>

Hi everyone, we have a multiple-node logstash cluster using a distributor pipeline that distributes events depending on their types, eg input { beats { # ... } } output { if \[type\] == "foo" { pi…

---

## [Why my Logstash work normal with an recursively error log](https://discuss.elastic.co/t/why-my-logstash-work-normal-with-an-recursively-error-log/341537)

<div class="topic-metadata">

**Author:** [@waitspring](https://discuss.elastic.co/u/waitspring)\
**Replies:** 1\
**Last updated:** [August 24, 2023, 2:07pm UTC](https://discuss.elastic.co/t/why-my-logstash-work-normal-with-an-recursively-error-log/341537 "2023-08-24T14:07:52Z")

</div>

I have make my logstash conf as: ... ... filter { grok { match =\> { "message" =\> \[ "\\\<时间: (?\<timestamp\>.\*)\\\> \\\<进程号:(?\<process\>%{NUMBER}+)\\\>(?\<body\>.\*$)", "\\\<时间:(?\<t…

---

## [Elastic.Clients fails indexing my data type with an IntegerRange (integer\_range) in it even though I'm using a template mapping](https://discuss.elastic.co/t/elastic-clients-fails-indexing-my-data-type-with-an-integerrange-integer-range-in-it-even-though-im-using-a-template-mapping/341513)

<div class="topic-metadata">

**Author:** [@Mathemaphysics](https://discuss.elastic.co/u/Mathemaphysics)\
**Replies:** 1\
**Last updated:** [August 24, 2023, 2:07pm UTC](https://discuss.elastic.co/t/elastic-clients-fails-indexing-my-data-type-with-an-integerrange-integer-range-in-it-even-though-im-using-a-template-mapping/341513 "2023-08-24T14:07:30Z")

</div>

The problem was caused by the use of the JsonPropertyName decorator on my data structure properties.

---

## [Index is getting deleted automatically](https://discuss.elastic.co/t/index-is-getting-deleted-automatically/341578)

<div class="topic-metadata">

**Author:** [@HardikSCaypro](https://discuss.elastic.co/u/HardikSCaypro)\
**Replies:** 3\
**Last updated:** [August 24, 2023, 1:58pm UTC](https://discuss.elastic.co/t/index-is-getting-deleted-automatically/341578 "2023-08-24T13:58:40Z")

</div>

Hello Team, We are using Elasticsearch from last few years. However recently we found that few of our indexes were getting deleted automatically, so we searched and found that we should reinstall it in different system. …

---

## [Logstash uses 80GB of memory with pipelines and 10 configurations](https://discuss.elastic.co/t/logstash-uses-80gb-of-memory-with-pipelines-and-10-configurations/341474)

<div class="topic-metadata">

**Author:** [@nilsen](https://discuss.elastic.co/u/nilsen)\
**Replies:** 11\
**Last updated:** [August 24, 2023, 1:20pm UTC](https://discuss.elastic.co/t/logstash-uses-80gb-of-memory-with-pipelines-and-10-configurations/341474 "2023-08-24T13:20:06Z")

</div>

A while back we had issues when we ran multiple Logstash instances, each using around 1GB of memory. We got advised to use pipelines instead. Keep in mind we are still in the POC stages, so very new to the ELK stack. We …

---

## [Wildcard search string in Discover](https://discuss.elastic.co/t/wildcard-search-string-in-discover/341575)

<div class="topic-metadata">

**Author:** [@wapevo5067](https://discuss.elastic.co/u/wapevo5067)\
**Replies:** 0\
**Last updated:** [August 24, 2023, 12:30pm UTC](https://discuss.elastic.co/t/wildcard-search-string-in-discover/341575 "2023-08-24T12:30:38Z")

</div>

V 7.17 I am using Discover from Analytics section. I am just using the simple search box. Lets say I have lots of logs which are: "Connection Server\[N\] Started" I can use: "Connection" and "Started" But I wonder if …

---

## [API to create new dashboard in Kibana 8.9.0](https://discuss.elastic.co/t/api-to-create-new-dashboard-in-kibana-8-9-0/341570)

<div class="topic-metadata">

**Author:** [@Daemon1](https://discuss.elastic.co/u/Daemon1)\
**Replies:** 1\
**Last updated:** [August 24, 2023, 12:06pm UTC](https://discuss.elastic.co/t/api-to-create-new-dashboard-in-kibana-8-9-0/341570 "2023-08-24T12:06:53Z")

</div>

POST \<kibana host\>:\<port\>/api/kibana/dashboards/import POST \<kibana host\>:\<port\>/s/\<space-id\>/api/kibana/dashboards/import The above apis are deprecated. Could you please help with alternate APIs to create new dashboar…

[Previous page](https://discuss.elastic.co/tag/none.md?no_tags=true&page=314)

[Next page](https://discuss.elastic.co/tag/none.md?no_tags=true&page=316)
