# \#none

**URL:** https://discuss.elastic.co/tag/none.md?no_tags=true&page=339

[Latest](https://discuss.elastic.co/latest.md) · [Categories](https://discuss.elastic.co/categories.md) · [Tags](https://discuss.elastic.co/tags.md)

**Page:** 340

---

## [Is there an API to return Anomaly Detection Job results? (Not a Rule)](https://discuss.elastic.co/t/is-there-an-api-to-return-anomaly-detection-job-results-not-a-rule/338599)

<div class="topic-metadata">

**Author:** [@McJava1967](https://discuss.elastic.co/u/McJava1967)\
**Replies:** 2\
**Last updated:** [July 17, 2023, 6:24pm UTC](https://discuss.elastic.co/t/is-there-an-api-to-return-anomaly-detection-job-results-not-a-rule/338599 "2023-07-17T18:24:29Z")

</div>

Hi all. Is there an API (or some way) to programmatically return the results displayed on this page? I can do without the chart. I just need some way to know there's some score over 90, for instance. I know about…

---

## [Elastic Defend Missing Logs](https://discuss.elastic.co/t/elastic-defend-missing-logs/337805)

<div class="topic-metadata">

**Author:** [@infernalz2](https://discuss.elastic.co/u/infernalz2)\
**Replies:** 1\
**Last updated:** [July 17, 2023, 6:20pm UTC](https://discuss.elastic.co/t/elastic-defend-missing-logs/337805 "2023-07-17T18:20:46Z")

</div>

Hi guys I am running Elastic Defend 8.7.1 on multiple Ubuntu 20.04.5 and CentOS 7 vms. In both cases network logs from outbound connections are missing (logged user or services), there are only for inbound. To my unders…

---

## [Return only last message based on a specific field](https://discuss.elastic.co/t/return-only-last-message-based-on-a-specific-field/336560)

<div class="topic-metadata">

**Author:** [@WimM](https://discuss.elastic.co/u/WimM)\
**Replies:** 4\
**Last updated:** [July 17, 2023, 5:27pm UTC](https://discuss.elastic.co/t/return-only-last-message-based-on-a-specific-field/336560 "2023-07-17T17:27:13Z")

</div>

Hi I work for a telco company and we are currently reporting on tests done by the technician at the customers location I have currently a graph showing the count on all tests in total (off course with some filters appl…

---

## [Auditing Kibana's user events](https://discuss.elastic.co/t/auditing-kibanas-user-events/338395)

<div class="topic-metadata">

**Author:** [@IsItPossible](https://discuss.elastic.co/u/IsItPossible)\
**Replies:** 1\
**Last updated:** [July 17, 2023, 4:18pm UTC](https://discuss.elastic.co/t/auditing-kibanas-user-events/338395 "2023-07-17T16:18:33Z")

</div>

Hello, I have some questions about monitoring access/events done by Kibana's users. Here are some examples of events im interested in: Create/Delete/Update/Enable/Disable rules Create/Update/Close cases Close/Delete a…

---

## [Help ingesting Data](https://discuss.elastic.co/t/help-ingesting-data/338580)

<div class="topic-metadata">

**Author:** [@Tom\_Dixon](https://discuss.elastic.co/u/Tom_Dixon)\
**Replies:** 2\
**Last updated:** [July 17, 2023, 4:14pm UTC](https://discuss.elastic.co/t/help-ingesting-data/338580 "2023-07-17T16:14:42Z")

</div>

Hi all, I'm new to Elastic and Logstash. I have a source of event data which I'm having problems ingesting. I think it is because the data itself, but being new to Logstash it could also be me, so I'm not sure where the …

---

## [Subtraction of Sum Aggregate Values in one Index from Sum Aggregate Values in Another Index](https://discuss.elastic.co/t/subtraction-of-sum-aggregate-values-in-one-index-from-sum-aggregate-values-in-another-index/338442)

<div class="topic-metadata">

**Author:** [@nickbarry](https://discuss.elastic.co/u/nickbarry)\
**Replies:** 2\
**Last updated:** [July 17, 2023, 3:58pm UTC](https://discuss.elastic.co/t/subtraction-of-sum-aggregate-values-in-one-index-from-sum-aggregate-values-in-another-index/338442 "2023-07-17T15:58:26Z")

</div>

I have two indices within a single data view that track 'compute cycles' in some unit like 'cycle-hours per month'. One of the indices is the total max available cycle-hours for each computer in the company's data cente…

---

## [Kafka input plugin cannot parse key or value due to message keys](https://discuss.elastic.co/t/kafka-input-plugin-cannot-parse-key-or-value-due-to-message-keys/338560)

<div class="topic-metadata">

**Author:** [@kohlbecker](https://discuss.elastic.co/u/kohlbecker)\
**Replies:** 2\
**Last updated:** [July 17, 2023, 3:38pm UTC](https://discuss.elastic.co/t/kafka-input-plugin-cannot-parse-key-or-value-due-to-message-keys/338560 "2023-07-17T15:38:03Z")

</div>

Key and value of the topic messages consumed by the Kafka input plugin are prefixed with the message ids, which causes the json parser to fail: Here an example from the logstash log with decorate\_events =\> "extended" pr…

---

## [1Password Rule Vault Accessed - Desktop app](https://discuss.elastic.co/t/1password-rule-vault-accessed-desktop-app/336774)

<div class="topic-metadata">

**Author:** [@Alex.W](https://discuss.elastic.co/u/Alex.W)\
**Replies:** 1\
**Last updated:** [July 17, 2023, 2:54pm UTC](https://discuss.elastic.co/t/1password-rule-vault-accessed-desktop-app/336774 "2023-07-17T14:54:06Z")

</div>

Hello, I have created a rule that alerts on users accessing a sensitive vault within 1Password (web) but this does not appear to fire when accessing the same vault through the desktop app. There are access logs for the…

---

## [Bytes value wraps to negative value](https://discuss.elastic.co/t/bytes-value-wraps-to-negative-value/338533)

<div class="topic-metadata">

**Author:** [@eddie4](https://discuss.elastic.co/u/eddie4)\
**Replies:** 1\
**Last updated:** [July 17, 2023, 1:48pm UTC](https://discuss.elastic.co/t/bytes-value-wraps-to-negative-value/338533 "2023-07-17T13:48:14Z")

</div>

Hello, Am attempting to multiply the number of bytes from netflow by 100. This is to offset the sampling rate. The pipeline has the following script: { "script": { "source": "ctx.network.true\_bytes2 = ctx.…

---

## [Implement proxy-protocol support for beats inputs](https://discuss.elastic.co/t/implement-proxy-protocol-support-for-beats-inputs/338561)

<div class="topic-metadata">

**Author:** [@bilel\_meddeb](https://discuss.elastic.co/u/bilel_meddeb)\
**Replies:** 0\
**Last updated:** [July 17, 2023, 1:14pm UTC](https://discuss.elastic.co/t/implement-proxy-protocol-support-for-beats-inputs/338561 "2023-07-17T13:14:41Z")

</div>

Hello :wave:t4: Would it be possible to support proxy-protocol for beats inputs ? I send logs from winlogbeat to logstash and i have Haproxy between them. without proxy and with this configuration of logstash, i got …

---

## [Elasticsearch License Expired](https://discuss.elastic.co/t/elasticsearch-license-expired/338546)

<div class="topic-metadata">

**Author:** [@Kosala\_Randika\_Paran](https://discuss.elastic.co/u/Kosala_Randika_Paran)\
**Replies:** 1\
**Last updated:** [July 17, 2023, 12:11pm UTC](https://discuss.elastic.co/t/elasticsearch-license-expired/338546 "2023-07-17T12:11:17Z")

</div>

Hi What happens when the Elasticsearch license expired? Currently, the cluster has assigned a commercial license and it will expire soon, so what will happen once the assigned date expired?

---

## [How to not show closed alerts in the "Alerts"-Overview?](https://discuss.elastic.co/t/how-to-not-show-closed-alerts-in-the-alerts-overview/336909)

<div class="topic-metadata">

**Author:** [@m-flow](https://discuss.elastic.co/u/m-flow)\
**Replies:** 4\
**Last updated:** [July 17, 2023, 10:36am UTC](https://discuss.elastic.co/t/how-to-not-show-closed-alerts-in-the-alerts-overview/336909 "2023-07-17T10:36:29Z")

</div>

Hello everyone, is there a way to suppress "closed" alerts in Kibana's "Alerts" view, when the status of all alerts changed from open to closed? The general filter exists, but is ineffective when no alerts with the sta…

---

## [Alerts Dashboard Showing All Alerts when "Open" alerts are cleared](https://discuss.elastic.co/t/alerts-dashboard-showing-all-alerts-when-open-alerts-are-cleared/338176)

<div class="topic-metadata">

**Author:** [@oloughlinp](https://discuss.elastic.co/u/oloughlinp)\
**Replies:** 2\
**Last updated:** [July 17, 2023, 10:34am UTC](https://discuss.elastic.co/t/alerts-dashboard-showing-all-alerts-when-open-alerts-are-cleared/338176 "2023-07-17T10:34:16Z")

</div>

Hi All, We recently upgraded to Kibana 8.8.0 from 8.0. When using the Alerts dashboard under Kibana Security, we typically use the status filter to filter the dashboard to show only "open" alerts, so that our analysts k…

---

## [Autofocus lose while typing in SearchBox](https://discuss.elastic.co/t/autofocus-lose-while-typing-in-searchbox/338091)

<div class="topic-metadata">

**Author:** [@raj22](https://discuss.elastic.co/u/raj22)\
**Replies:** 4\
**Last updated:** [July 17, 2023, 10:06am UTC](https://discuss.elastic.co/t/autofocus-lose-while-typing-in-searchbox/338091 "2023-07-17T10:06:22Z")

</div>

Hello, I have component from \> @elastic/react-search-ui . For searchbox desing customization used inputView. But when I started typing suddenly autofocus is losing , so I need to enter cusor again into input element …

---

## [Import dashboard on elk 8.5.3](https://discuss.elastic.co/t/import-dashboard-on-elk-8-5-3/338236)

<div class="topic-metadata">

**Author:** [@kibana\_dev\_iko](https://discuss.elastic.co/u/kibana_dev_iko)\
**Replies:** 6\
**Last updated:** [July 17, 2023, 9:54am UTC](https://discuss.elastic.co/t/import-dashboard-on-elk-8-5-3/338236 "2023-07-17T09:54:30Z")

</div>

hi can anyone help me i create dashboard on elk version 8.6.2 and i want to import them in elk version 8.5.3 but i get this warning in kibana UI The file could not be processed due to error: "Unprocessable Entity: Doc…

---

## [Is there a way to make the query string fuzzy by default?](https://discuss.elastic.co/t/is-there-a-way-to-make-the-query-string-fuzzy-by-default/338150)

<div class="topic-metadata">

**Author:** [@johnrodey](https://discuss.elastic.co/u/johnrodey)\
**Replies:** 1\
**Last updated:** [July 17, 2023, 9:50am UTC](https://discuss.elastic.co/t/is-there-a-way-to-make-the-query-string-fuzzy-by-default/338150 "2023-07-17T09:50:37Z")

</div>

I submit a query string via Java Rest API (QueryStringQueryBuilder). Right now I pass in whatever the user enters and use that as my query string however I would like to automatically apply fuzzy searching, when it make…

---

## [Adding multiple client to the ELK centralised logging system](https://discuss.elastic.co/t/adding-multiple-client-to-the-elk-centralised-logging-system/338526)

<div class="topic-metadata">

**Author:** [@Rahul\_Kumar\_Jaiswal](https://discuss.elastic.co/u/Rahul_Kumar_Jaiswal)\
**Replies:** 0\
**Last updated:** [July 17, 2023, 9:43am UTC](https://discuss.elastic.co/t/adding-multiple-client-to-the-elk-centralised-logging-system/338526 "2023-07-17T09:43:44Z")

</div>

How to add multiple clients to the ELK centralised logging system so that we can visualise their logs. I have already installed filebeat on the client nodes and configure the filebeat.yml file too. But, not able to see t…

---

## [Aggregation return data that do not match query](https://discuss.elastic.co/t/aggregation-return-data-that-do-not-match-query/338184)

<div class="topic-metadata">

**Author:** [@Edyta\_Szkiladz](https://discuss.elastic.co/u/Edyta_Szkiladz)\
**Replies:** 3\
**Last updated:** [July 17, 2023, 9:42am UTC](https://discuss.elastic.co/t/aggregation-return-data-that-do-not-match-query/338184 "2023-07-17T09:42:32Z")

</div>

I am trying to do aggregation on documents which contains categories field. Categories is an array of strings. Sample document: { "\_index": "test-v11", "\_type": "\_doc", "\_id": "954961", "\_version": 4, "\_score"…

---

## [Ruby into file](https://discuss.elastic.co/t/ruby-into-file/338102)

<div class="topic-metadata">

**Author:** [@hofrichterovak](https://discuss.elastic.co/u/hofrichterovak)\
**Replies:** 4\
**Last updated:** [July 17, 2023, 9:27am UTC](https://discuss.elastic.co/t/ruby-into-file/338102 "2023-07-17T09:27:23Z")

</div>

Hello, I read the documentation about the ruby script and I did not correctly understand the conversion of the ruby script into a file. If I have a converted ruby script into a file, do I have to rewrite the script int…

---

## [Add resiliency on .security-7 index](https://discuss.elastic.co/t/add-resiliency-on-security-7-index/338121)

<div class="topic-metadata">

**Author:** [@Josselin](https://discuss.elastic.co/u/Josselin)\
**Replies:** 2\
**Last updated:** [July 17, 2023, 9:23am UTC](https://discuss.elastic.co/t/add-resiliency-on-security-7-index/338121 "2023-07-17T09:23:39Z")

</div>

Hi, During multiple incident with cluster restart we lost the nodes where the index .security-7 was stored. It had a huge impact and we want to avoid as much as possible this situation to occur again. We have seen on t…

---

## [Limit of index pattern in Kibana for Elastic 8.8](https://discuss.elastic.co/t/limit-of-index-pattern-in-kibana-for-elastic-8-8/338516)

<div class="topic-metadata">

**Author:** [@elk1985](https://discuss.elastic.co/u/elk1985)\
**Replies:** 1\
**Last updated:** [July 17, 2023, 9:17am UTC](https://discuss.elastic.co/t/limit-of-index-pattern-in-kibana-for-elastic-8-8/338516 "2023-07-17T09:17:14Z")

</div>

Hello. Is still a hard deck limit of 100 index pattern per Kibana Data view in Elastic 8.8 ?

---

## [Connect oracle to elastic / kibana](https://discuss.elastic.co/t/connect-oracle-to-elastic-kibana/338436)

<div class="topic-metadata">

**Author:** [@Oytoch](https://discuss.elastic.co/u/Oytoch)\
**Replies:** 5\
**Last updated:** [July 17, 2023, 9:03am UTC](https://discuss.elastic.co/t/connect-oracle-to-elastic-kibana/338436 "2023-07-17T09:03:53Z")

</div>

Hi, I try to understand kibana / Elasticsearch to interface my oracle database in order to make dashboard with kibana ( BI) I work with an "on premise" version First question, is it possible to do that with kibana ? …

---

## [How to use Search templates in collate for phrase suggester](https://discuss.elastic.co/t/how-to-use-search-templates-in-collate-for-phrase-suggester/338515)

<div class="topic-metadata">

**Author:** [@To\_Noroozi](https://discuss.elastic.co/u/To_Noroozi)\
**Replies:** 0\
**Last updated:** [July 17, 2023, 8:33am UTC](https://discuss.elastic.co/t/how-to-use-search-templates-in-collate-for-phrase-suggester/338515 "2023-07-17T08:33:38Z")

</div>

Hi guys, according to the this link for collate: Suggesters | Elasticsearch Guide \[8.8\] | Elastic we can use our custom search template to use more complex query. i create sample search template and it is ok with name …

---

## [Persistent data support for logstash in ECK 2.8?](https://discuss.elastic.co/t/persistent-data-support-for-logstash-in-eck-2-8/338514)

<div class="topic-metadata">

**Author:** [@Claudio\_Tassini](https://discuss.elastic.co/u/Claudio_Tassini)\
**Replies:** 0\
**Last updated:** [July 17, 2023, 8:30am UTC](https://discuss.elastic.co/t/persistent-data-support-for-logstash-in-eck-2-8/338514 "2023-07-17T08:30:44Z")

</div>

Hi all! I'm trying to deploy an ECK cluster composed of elasticsearch, kibana, beats and a logstash instance. The only problem I'm facing is that the logstash CRD does not seem to support the definition of a volumeclaim…

---

## [ES fails to restart after reboot](https://discuss.elastic.co/t/es-fails-to-restart-after-reboot/338465)

<div class="topic-metadata">

**Author:** [@Russell\_Fulton](https://discuss.elastic.co/u/Russell_Fulton)\
**Replies:** 3\
**Last updated:** [July 17, 2023, 8:21am UTC](https://discuss.elastic.co/t/es-fails-to-restart-after-reboot/338465 "2023-07-17T08:21:20Z")

</div>

version 7.17.1 running on ubuntu -- started from systemctl When ever the server is rebooted ES fails to restart properly. Subsequent manual restart works just fine. \[2023-07-16T01:37:33,109\]\[INFO \]\[o.e.p.PluginsServic…

---

## [How does elastic react with x-pack crack](https://discuss.elastic.co/t/how-does-elastic-react-with-x-pack-crack/338503)

<div class="topic-metadata">

**Author:** [@Ernest\_Dong](https://discuss.elastic.co/u/Ernest_Dong)\
**Replies:** 1\
**Last updated:** [July 17, 2023, 8:13am UTC](https://discuss.elastic.co/t/how-does-elastic-react-with-x-pack-crack/338503 "2023-07-17T08:13:55Z")

</div>

I'm researching on ESTC stock and wondering how does elastic react with x-pack crack? If SMB modifies Elastic code and builds it on-premise, it seems ESTC will lost much revenue

---

## [Create Backup of all Kibana Objects](https://discuss.elastic.co/t/create-backup-of-all-kibana-objects/338226)

<div class="topic-metadata">

**Author:** [@tomx1](https://discuss.elastic.co/u/tomx1)\
**Replies:** 5\
**Last updated:** [July 17, 2023, 7:47am UTC](https://discuss.elastic.co/t/create-backup-of-all-kibana-objects/338226 "2023-07-17T07:47:38Z")

</div>

I would like to make sure that I'm able to restore all objects maintained by Kibana (Visualisations, Pipelines, Transformjobs, Dashboards, Templates, Fleet Settings and and and) from a snapshot. How can I achive that? I…

---

## [How to define time range Connection Graph](https://discuss.elastic.co/t/how-to-define-time-range-connection-graph/338485)

<div class="topic-metadata">

**Author:** [@leesever](https://discuss.elastic.co/u/leesever)\
**Replies:** 2\
**Last updated:** [July 17, 2023, 7:12am UTC](https://discuss.elastic.co/t/how-to-define-time-range-connection-graph/338485 "2023-07-17T07:12:05Z")

</div>

Hi, we using the graph for centrality analysis to identify the most central nodes in our platform (links between users). I wish to emphasize that I am not a programer or something as such and mostly use Kibana for fraud…

---

## [I have 2 aggregation in my query for Dau, Mau. how to combine them to find the ratio. have tried with bucket\_script, scripted metric. nothing works,](https://discuss.elastic.co/t/i-have-2-aggregation-in-my-query-for-dau-mau-how-to-combine-them-to-find-the-ratio-have-tried-with-bucket-script-scripted-metric-nothing-works/338373)

<div class="topic-metadata">

**Author:** [@Dev\_Profile](https://discuss.elastic.co/u/Dev_Profile)\
**Replies:** 2\
**Last updated:** [July 17, 2023, 6:58am UTC](https://discuss.elastic.co/t/i-have-2-aggregation-in-my-query-for-dau-mau-how-to-combine-them-to-find-the-ratio-have-tried-with-bucket-script-scripted-metric-nothing-works/338373 "2023-07-17T06:58:28Z")

</div>

Below is my query. is there any way to access multi-buckets value to manipulate n return the results. { "\_source": false, "aggs": { "nested\_dau": { "nested": { "path": "dau" }, "aggs": …

---

## [I want to render only kibana dashboard screen in python application,,how can I do that?](https://discuss.elastic.co/t/i-want-to-render-only-kibana-dashboard-screen-in-python-application-how-can-i-do-that/338173)

<div class="topic-metadata">

**Author:** [@Rushi\_Bagul](https://discuss.elastic.co/u/Rushi_Bagul)\
**Replies:** 2\
**Last updated:** [July 17, 2023, 6:46am UTC](https://discuss.elastic.co/t/i-want-to-render-only-kibana-dashboard-screen-in-python-application-how-can-i-do-that/338173 "2023-07-17T06:46:26Z")

</div>

I want to render only Kibana dashboard screen in python application for user purpose only they don't have access for modification. User want's to only read permission. I am new on elasticsearch so please help for that, …

[Previous page](https://discuss.elastic.co/tag/none.md?no_tags=true&page=338)

[Next page](https://discuss.elastic.co/tag/none.md?no_tags=true&page=340)
