# \#none

**URL:** https://discuss.elastic.co/tag/none.md?no_tags=true&page=338

[Latest](https://discuss.elastic.co/latest.md) · [Categories](https://discuss.elastic.co/categories.md) · [Tags](https://discuss.elastic.co/tags.md)

**Page:** 339

---

## [TSVB markdown with conditional values](https://discuss.elastic.co/t/tsvb-markdown-with-conditional-values/338582)

<div class="topic-metadata">

**Author:** [@hkhalil](https://discuss.elastic.co/u/hkhalil)\
**Replies:** 2\
**Last updated:** [July 18, 2023, 4:25pm UTC](https://discuss.elastic.co/t/tsvb-markdown-with-conditional-values/338582 "2023-07-18T16:25:35Z")

</div>

Hi, We're looking to create in our dashboard a markdown using the TSVB control type. Our dashboard has controls for filtering purposes. We would like the markdown to display different predetermined numerical values bas…

---

## [Fast Vector Highlighting is not working stable on Synonym based fields](https://discuss.elastic.co/t/fast-vector-highlighting-is-not-working-stable-on-synonym-based-fields/338673)

<div class="topic-metadata">

**Author:** [@Pavithra2014](https://discuss.elastic.co/u/Pavithra2014)\
**Replies:** 3\
**Last updated:** [July 18, 2023, 4:05pm UTC](https://discuss.elastic.co/t/fast-vector-highlighting-is-not-working-stable-on-synonym-based-fields/338673 "2023-07-18T16:05:20Z")

</div>

Here , we are using Fast Vector highlight on a field where it has the copy field for synonym . for some records FVH highlights properly but for some it is not. Field mapping: title: { type: "text", term\_vector: "with\_p…

---

## [\*I am working with wireshark pcaps inside of SO kibana and hunt. Seems like the timestamps do not match?](https://discuss.elastic.co/t/i-am-working-with-wireshark-pcaps-inside-of-so-kibana-and-hunt-seems-like-the-timestamps-do-not-match/338612)

<div class="topic-metadata">

**Author:** [@iqworks](https://discuss.elastic.co/u/iqworks)\
**Replies:** 2\
**Last updated:** [July 18, 2023, 3:32pm UTC](https://discuss.elastic.co/t/i-am-working-with-wireshark-pcaps-inside-of-so-kibana-and-hunt-seems-like-the-timestamps-do-not-match/338612 "2023-07-18T15:32:27Z")

</div>

Hi, I am using windows 11, SO, winlogbeat and logstash output.logstash: The Logstash hosts hosts: \["192.168.1.226:5044"\] I have saved a wireshark session as a pcap. I moved the pcap from my windows 10 machine with win…

---

## [Substract value of one attribute from the previous day value in ELasticsearch for Kibana Visualization](https://discuss.elastic.co/t/substract-value-of-one-attribute-from-the-previous-day-value-in-elasticsearch-for-kibana-visualization/337184)

<div class="topic-metadata">

**Author:** [@gauravpks](https://discuss.elastic.co/u/gauravpks)\
**Replies:** 1\
**Last updated:** [July 18, 2023, 3:17pm UTC](https://discuss.elastic.co/t/substract-value-of-one-attribute-from-the-previous-day-value-in-elasticsearch-for-kibana-visualization/337184 "2023-07-18T15:17:25Z")

</div>

My elastic index has 3 attributes: - accountNumber, timestamp and score. I want to calculate the difference in score from today to the previous day (or the last value) for each account and build visualizations for the di…

---

## [Facing permission issues on running up \`elastic-package stack up\`](https://discuss.elastic.co/t/facing-permission-issues-on-running-up-elastic-package-stack-up/338566)

<div class="topic-metadata">

**Author:** [@hari\_ibm](https://discuss.elastic.co/u/hari_ibm)\
**Replies:** 2\
**Last updated:** [July 18, 2023, 3:08pm UTC](https://discuss.elastic.co/t/facing-permission-issues-on-running-up-elastic-package-stack-up/338566 "2023-07-18T15:08:16Z")

</div>

Getting the below exception on running elastic-package stack up ERROR: Elasticsearch exited unexpectedly java.nio.file.AccessDeniedException: /usr/share/elasticsearch/config/certs at java.base/sun.nio.fs.UnixException.…

---

## [ECS version is different](https://discuss.elastic.co/t/ecs-version-is-different/338630)

<div class="topic-metadata">

**Author:** [@Nishant\_Chauhan](https://discuss.elastic.co/u/Nishant_Chauhan)\
**Replies:** 1\
**Last updated:** [July 18, 2023, 3:06pm UTC](https://discuss.elastic.co/t/ecs-version-is-different/338630 "2023-07-18T15:06:37Z")

</div>

We are getting below error in our Kibana logs 8.7.1 and Elasticsearch version is also same 8.7.1 why ECS version is 8.6.0 ? is it ok , if wrong how we can correct it? {"service":{"node":{"roles":\["background\_tasks","u…

---

## [Configuration scheme issue](https://discuss.elastic.co/t/configuration-scheme-issue/338110)

<div class="topic-metadata">

**Author:** [@hlcxpl](https://discuss.elastic.co/u/hlcxpl)\
**Replies:** 0\
**Last updated:** [July 11, 2023, 1:52pm UTC](https://discuss.elastic.co/t/configuration-scheme-issue/338110 "2023-07-11T13:52:08Z")

</div>

i have to cofigure a clúster with 5Teras data ingest per day in 4 data nodes the thing is, if I installed elastisearch 8.8 which configuration is the best for these schema, single node configuration with the voting s…

---

## [Kibana - Every user gets their own space](https://discuss.elastic.co/t/kibana-every-user-gets-their-own-space/338375)

<div class="topic-metadata">

**Author:** [@sc6698](https://discuss.elastic.co/u/sc6698)\
**Replies:** 1\
**Last updated:** [July 18, 2023, 2:51pm UTC](https://discuss.elastic.co/t/kibana-every-user-gets-their-own-space/338375 "2023-07-18T14:51:57Z")

</div>

Hi, How am I going to achieve this by allowing every logged in user to have their own space and saved objects? All users are allowed to see their own space but not others. I understand that it could be done by creating…

---

## [How to set the static range's in vertical axis for time-series graph in Kibana](https://discuss.elastic.co/t/how-to-set-the-static-ranges-in-vertical-axis-for-time-series-graph-in-kibana/338295)

<div class="topic-metadata">

**Author:** [@rkidev](https://discuss.elastic.co/u/rkidev)\
**Replies:** 1\
**Last updated:** [July 18, 2023, 2:13pm UTC](https://discuss.elastic.co/t/how-to-set-the-static-ranges-in-vertical-axis-for-time-series-graph-in-kibana/338295 "2023-07-18T14:13:18Z")

</div>

I am trying to create time-series graph. I have 6 fields with random numbers(max 2000). How can we set the y-axis ranges (like 0,400, 1000, 1500, 2000) instead of dynamic. I am using ELK 8.2.3 version.

---

## [Custom 3rd party integration for outgoing connectors](https://discuss.elastic.co/t/custom-3rd-party-integration-for-outgoing-connectors/338675)

<div class="topic-metadata">

**Author:** [@mha1](https://discuss.elastic.co/u/mha1)\
**Replies:** 2\
**Last updated:** [July 18, 2023, 1:43pm UTC](https://discuss.elastic.co/t/custom-3rd-party-integration-for-outgoing-connectors/338675 "2023-07-18T13:43:28Z")

</div>

Is there an update about the development of custom alerting connectors? I saw this question was asked twice in 2021. Add custom connectors to 3rd party Kibana Plugin Idea: Custom Alert Connector Any updates? I´ll als…

---

## [Optimize logstash tcp input plugin](https://discuss.elastic.co/t/optimize-logstash-tcp-input-plugin/337847)

<div class="topic-metadata">

**Author:** [@true64gurus](https://discuss.elastic.co/u/true64gurus)\
**Replies:** 7\
**Last updated:** [July 18, 2023, 1:33pm UTC](https://discuss.elastic.co/t/optimize-logstash-tcp-input-plugin/337847 "2023-07-18T13:33:26Z")

</div>

Hello, I have 10 Kubernetes clusters forward their logs to logstash VM (k8s fluentd ---\> logstash port 7000) . Logstash gets to a point where logs are being missed and source pods doing retries to get logs through . (…

---

## [Logstash not showing field with null values](https://discuss.elastic.co/t/logstash-not-showing-field-with-null-values/338648)

<div class="topic-metadata">

**Author:** [@Mohit\_Gupta2](https://discuss.elastic.co/u/Mohit_Gupta2)\
**Replies:** 5\
**Last updated:** [July 18, 2023, 12:44pm UTC](https://discuss.elastic.co/t/logstash-not-showing-field-with-null-values/338648 "2023-07-18T12:44:26Z")

</div>

I am indexing elasticsearch via logstash but it is showing only document's fields with not null values. Earlier I used to do this through transporter and it returns the null values as well. Also the mapping in both case…

---

## [How to add labels in apm for python lamda to reflect in kibana](https://discuss.elastic.co/t/how-to-add-labels-in-apm-for-python-lamda-to-reflect-in-kibana/338665)

<div class="topic-metadata">

**Author:** [@sairam\_kadakuntla](https://discuss.elastic.co/u/sairam_kadakuntla)\
**Replies:** 0\
**Last updated:** [July 18, 2023, 11:51am UTC](https://discuss.elastic.co/t/how-to-add-labels-in-apm-for-python-lamda-to-reflect-in-kibana/338665 "2023-07-18T11:51:13Z")

</div>

i have created a elastic apm object like client = Client({ 'SERVICE\_NAME': os.environ.get("ELASTIC\_APM\_SERVICE\_NAME"), 'SERVER\_URL': os.environ.get("ELASTIC\_APM\_LAMBDA\_APM\_SERVER") }) starting with client.begin\_trans…

---

## [In data table visualization i have 5 columns but in one column, only one data is coming](https://discuss.elastic.co/t/in-data-table-visualization-i-have-5-columns-but-in-one-column-only-one-data-is-coming/338421)

<div class="topic-metadata">

**Author:** [@Malikmamta](https://discuss.elastic.co/u/Malikmamta)\
**Replies:** 4\
**Last updated:** [July 18, 2023, 10:11am UTC](https://discuss.elastic.co/t/in-data-table-visualization-i-have-5-columns-but-in-one-column-only-one-data-is-coming/338421 "2023-07-18T10:11:35Z")

</div>

in data table visualization, I have 5 columns but in one column, only one row is missing instead of 10 rows. in that column multiline are there. In discover, i can see complete data but for that one column, only single …

---

## [How to change the kibana jvm memory](https://discuss.elastic.co/t/how-to-change-the-kibana-jvm-memory/338647)

<div class="topic-metadata">

**Author:** [@tan\_minkee](https://discuss.elastic.co/u/tan_minkee)\
**Replies:** 2\
**Last updated:** [July 18, 2023, 10:00am UTC](https://discuss.elastic.co/t/how-to-change-the-kibana-jvm-memory/338647 "2023-07-18T10:00:13Z")

</div>

I would like to set the kibana jvm memory to 8Gb instead of default value, May I know how to do that? What I have done is edit the field "--max-old-space-size=8192" in the node.options under /etc/kibana but I am not sur…

---

## [How to create email alerts in kibana](https://discuss.elastic.co/t/how-to-create-email-alerts-in-kibana/338219)

<div class="topic-metadata">

**Author:** [@kibana\_dev\_iko](https://discuss.elastic.co/u/kibana_dev_iko)\
**Replies:** 11\
**Last updated:** [July 18, 2023, 9:37am UTC](https://discuss.elastic.co/t/how-to-create-email-alerts-in-kibana/338219 "2023-07-18T09:37:00Z")

</div>

how can i create email alert for logs in elasticsearch and how can i create connectors in kibana UI

---

## [Elastic Agent by Docker Image](https://discuss.elastic.co/t/elastic-agent-by-docker-image/338636)

<div class="topic-metadata">

**Author:** [@Retrogamer](https://discuss.elastic.co/u/Retrogamer)\
**Replies:** 0\
**Last updated:** [July 18, 2023, 8:56am UTC](https://discuss.elastic.co/t/elastic-agent-by-docker-image/338636 "2023-07-18T08:56:05Z")

</div>

I want to deploy Stand-alone Elastic Agent using Docker image. I followed the instruction in this page but, I am not sure which environment variables I should use to deploy the Agent as Stand-alone. Elastic Search and Ki…

---

## [Running multiple pipelines and a single pipeline triggered with shell script simultaneously](https://discuss.elastic.co/t/running-multiple-pipelines-and-a-single-pipeline-triggered-with-shell-script-simultaneously/338441)

<div class="topic-metadata">

**Author:** [@PodarcisMuralis](https://discuss.elastic.co/u/PodarcisMuralis)\
**Replies:** 1\
**Last updated:** [July 18, 2023, 7:48am UTC](https://discuss.elastic.co/t/running-multiple-pipelines-and-a-single-pipeline-triggered-with-shell-script-simultaneously/338441 "2023-07-18T07:48:22Z")

</div>

Hi. I have 5 pipelines already running on linux server. The conf files are listed in a pipeline.yml and it has already been started with sudo systemctl start logstash, up and running. I created another single pipeline…

---

## [Can't send data to elastic after upgrade the version](https://discuss.elastic.co/t/cant-send-data-to-elastic-after-upgrade-the-version/338634)

<div class="topic-metadata">

**Author:** [@zerratriani](https://discuss.elastic.co/u/zerratriani)\
**Replies:** 0\
**Last updated:** [July 18, 2023, 7:41am UTC](https://discuss.elastic.co/t/cant-send-data-to-elastic-after-upgrade-the-version/338634 "2023-07-18T07:41:36Z")

</div>

Hi, previously we used Elastic & Logstash version 7.15 to store data. But after we upgraded to version 8 the data could not be sent. We used the same Logstash configuration and added a few things that changed in version …

---

## [Elasticsearch failed to start 8.8](https://discuss.elastic.co/t/elasticsearch-failed-to-start-8-8/338616)

<div class="topic-metadata">

**Author:** [@Aditya\_Bollam](https://discuss.elastic.co/u/Aditya_Bollam)\
**Replies:** 2\
**Last updated:** [July 18, 2023, 7:35am UTC](https://discuss.elastic.co/t/elasticsearch-failed-to-start-8-8/338616 "2023-07-18T07:35:41Z")

</div>

I am not able to start the service

---

## [Can I find out why is my elastic node has a high read rate every 12 hours](https://discuss.elastic.co/t/can-i-find-out-why-is-my-elastic-node-has-a-high-read-rate-every-12-hours/338194)

<div class="topic-metadata">

**Author:** [@JasonREC](https://discuss.elastic.co/u/JasonREC)\
**Replies:** 5\
**Last updated:** [July 18, 2023, 7:34am UTC](https://discuss.elastic.co/t/can-i-find-out-why-is-my-elastic-node-has-a-high-read-rate-every-12-hours/338194 "2023-07-18T07:34:08Z")

</div>

Hi, Above is my elastic 3 days IO rate chart, it does have a special pattern between every 12 hours, the read will reach to a peak, but I am not sure what is the thing that can potentially cause this happens... is there…

---

## [Rackaware good practises](https://discuss.elastic.co/t/rackaware-good-practises/338632)

<div class="topic-metadata">

**Author:** [@bombovy](https://discuss.elastic.co/u/bombovy)\
**Replies:** 0\
**Last updated:** [July 18, 2023, 6:43am UTC](https://discuss.elastic.co/t/rackaware-good-practises/338632 "2023-07-18T06:43:44Z")

</div>

Hello, We have really big log elastic cluster hosted on EKS in AWS. We are generating 17TB of logs each day. Also we are using data tiers for savings. The big costs issue that we are struggling now is the Data Transfer …

---

## [ExecStart=/usr/share/kibana/bin/kibana (code=exited, status=78)](https://discuss.elastic.co/t/execstart-usr-share-kibana-bin-kibana-code-exited-status-78/338474)

<div class="topic-metadata">

**Author:** [@Nghia\_D\_ng](https://discuss.elastic.co/u/Nghia_D_ng)\
**Replies:** 3\
**Last updated:** [July 18, 2023, 2:31am UTC](https://discuss.elastic.co/t/execstart-usr-share-kibana-bin-kibana-code-exited-status-78/338474 "2023-07-18T02:31:02Z")

</div>

Please help me!

---

## [How to delete system indices?](https://discuss.elastic.co/t/how-to-delete-system-indices/338510)

<div class="topic-metadata">

**Author:** [@lusynda](https://discuss.elastic.co/u/lusynda)\
**Replies:** 3\
**Last updated:** [July 18, 2023, 1:37am UTC](https://discuss.elastic.co/t/how-to-delete-system-indices/338510 "2023-07-18T01:37:09Z")

</div>

Hi all, My current cluster is an upgraded cluster from version 7.x to 8.x It has alot of system indices that nolonger require in the cluster but whenever i tried to delete it. I got this message { "error": { "ro…

---

## [Truststore does not contain any trusted certificate entries](https://discuss.elastic.co/t/truststore-does-not-contain-any-trusted-certificate-entries/338610)

<div class="topic-metadata">

**Author:** [@sslgeorge](https://discuss.elastic.co/u/sslgeorge)\
**Replies:** 0\
**Last updated:** [July 17, 2023, 11:36pm UTC](https://discuss.elastic.co/t/truststore-does-not-contain-any-trusted-certificate-entries/338610 "2023-07-17T23:36:57Z")

</div>

I used openssl to generate self signed certs for elasticsearch, but I am unable to use this certs to start elasticsearch. I keep getting the below error \[2023-07-16T19:42:22,649\]\[ERROR\]\[o.e.b.Elasticsearch \] \[Mac…

---

## [Composite aggregation returns after\_key even when there are no more buckets](https://discuss.elastic.co/t/composite-aggregation-returns-after-key-even-when-there-are-no-more-buckets/338606)

<div class="topic-metadata">

**Author:** [@cdhowie](https://discuss.elastic.co/u/cdhowie)\
**Replies:** 0\
**Last updated:** [July 17, 2023, 10:00pm UTC](https://discuss.elastic.co/t/composite-aggregation-returns-after-key-even-when-there-are-no-more-buckets/338606 "2023-07-17T22:00:35Z")

</div>

I've been working on a query that performs a composite aggregation with a large number of buckets. When I set the aggregation size to 50,000, all buckets fit in the response. However, after\_key is still present in the re…

---

## [Installer Claims Version is Already Installed](https://discuss.elastic.co/t/installer-claims-version-is-already-installed/338603)

<div class="topic-metadata">

**Author:** [@mreeg](https://discuss.elastic.co/u/mreeg)\
**Replies:** 0\
**Last updated:** [July 17, 2023, 7:21pm UTC](https://discuss.elastic.co/t/installer-claims-version-is-already-installed/338603 "2023-07-17T19:21:45Z")

</div>

Hello, I'm trying to Install a piece of software that utilizes Elasticsearch, and includes the Elasticsearch install as part of the installation process. Due to other errors, I had to uninstall the software (includin…

---

## [Logstash HTTP code 400 {:response\_code=\>400}](https://discuss.elastic.co/t/logstash-http-code-400-response-code-400/338501)

<div class="topic-metadata">

**Author:** [@Indeed2000](https://discuss.elastic.co/u/Indeed2000)\
**Replies:** 1\
**Last updated:** [July 17, 2023, 7:19pm UTC](https://discuss.elastic.co/t/logstash-http-code-400-response-code-400/338501 "2023-07-17T19:19:13Z")

</div>

Hi when i try to send data with logstash to influxdb return this error: \[ERROR\] 2023-07-17 09:21:36.133 \[\[main\]\>worker1\] http - Encountered non-2xx HTTP code 400 {:response\_code=\>400, :url=\>"http://192.168.1.2:8086/api…

---

## [99th Percentile of index rate](https://discuss.elastic.co/t/99th-percentile-of-index-rate/338569)

<div class="topic-metadata">

**Author:** [@veryelastic](https://discuss.elastic.co/u/veryelastic)\
**Replies:** 1\
**Last updated:** [July 17, 2023, 6:57pm UTC](https://discuss.elastic.co/t/99th-percentile-of-index-rate/338569 "2023-07-17T18:57:34Z")

</div>

Hello, I have an Elastic 8.8.1 cluster up and running, and being monitored via Metricbeat feeding into stack monitoring, and I can see a chart of index rate. I'd like to visualise the 99th percentile index rate across …

---

## [How to delete docs.deleted from ELK?](https://discuss.elastic.co/t/how-to-delete-docs-deleted-from-elk/338597)

<div class="topic-metadata">

**Author:** [@Yuri\_Pires](https://discuss.elastic.co/u/Yuri_Pires)\
**Replies:** 1\
**Last updated:** [July 17, 2023, 6:50pm UTC](https://discuss.elastic.co/t/how-to-delete-docs-deleted-from-elk/338597 "2023-07-17T18:50:01Z")

</div>

Hello, in this logstash index I used the delete\_by\_query endpoint to clean old logs from storage, I was successful in this step, but I found that the docs are still on the HD and I want to delete them to free up space. h…

[Previous page](https://discuss.elastic.co/tag/none.md?no_tags=true&page=337)

[Next page](https://discuss.elastic.co/tag/none.md?no_tags=true&page=339)
