# \#none

**URL:** https://discuss.elastic.co/tag/none.md?no_tags=true&page=355

[Latest](https://discuss.elastic.co/latest.md) · [Categories](https://discuss.elastic.co/categories.md) · [Tags](https://discuss.elastic.co/tags.md)

**Page:** 356

---

## [Timelion Expression is not supporting .offset function](https://discuss.elastic.co/t/timelion-expression-is-not-supporting-offset-function/336619)

<div class="topic-metadata">

**Author:** [@Kumar\_Abhinav](https://discuss.elastic.co/u/Kumar_Abhinav)\
**Replies:** 1\
**Last updated:** [June 21, 2023, 9:18pm UTC](https://discuss.elastic.co/t/timelion-expression-is-not-supporting-offset-function/336619 "2023-06-21T21:18:13Z")

</div>

I am trying to visualize the counts of one field for this month and compare it with the count for the next month. I am using the time lion expression with .offset -1m but the same is not working. It gives me an error. My…

---

## [Fleet not sending data after cluster upgrade](https://discuss.elastic.co/t/fleet-not-sending-data-after-cluster-upgrade/336625)

<div class="topic-metadata">

**Author:** [@mhoward](https://discuss.elastic.co/u/mhoward)\
**Replies:** 0\
**Last updated:** [June 21, 2023, 8:21pm UTC](https://discuss.elastic.co/t/fleet-not-sending-data-after-cluster-upgrade/336625 "2023-06-21T20:21:00Z")

</div>

Hello. Last Thursday I upgraded an Elastic cluster to 7.17.10. Since then, Fleet has not been collecting any data from agents and the Fleet server itself doesn't appear to communicating with the cluster. After restart…

---

## [Parse failure (object mapping for \[trace.detail\] tried to parse field \[null\] as object, but found a concrete value)](https://discuss.elastic.co/t/parse-failure-object-mapping-for-trace-detail-tried-to-parse-field-null-as-object-but-found-a-concrete-value/336551)

<div class="topic-metadata">

**Author:** [@a.emrekaraman](https://discuss.elastic.co/u/a.emrekaraman)\
**Replies:** 1\
**Last updated:** [June 21, 2023, 7:20pm UTC](https://discuss.elastic.co/t/parse-failure-object-mapping-for-trace-detail-tried-to-parse-field-null-as-object-but-found-a-concrete-value/336551 "2023-06-21T19:20:17Z")

</div>

Hi Team, I basically use json filter to parse log. But somewhere in json have 2 different type of log that's why I get this error (object mapping for \[trace.detail\] tried to parse field \[null\] as object, but found a conc…

---

## [Different versions of ELK cluster](https://discuss.elastic.co/t/different-versions-of-elk-cluster/336486)

<div class="topic-metadata">

**Author:** [@zaeemmasood](https://discuss.elastic.co/u/zaeemmasood)\
**Replies:** 5\
**Last updated:** [June 21, 2023, 3:58pm UTC](https://discuss.elastic.co/t/different-versions-of-elk-cluster/336486 "2023-06-21T15:58:30Z")

</div>

Hi All, I was able to create a working cluster using variety of product versions. Please let me know if this is ok: Filebeat: 7.6.2 Logstash: 8.6.2 Elasticsearch: 8.7.0 Kibana: 8.5.3 Thanks in advance!

---

## [Elastic Agent for Windows - visibility of Docker Containers in Kibana](https://discuss.elastic.co/t/elastic-agent-for-windows-visibility-of-docker-containers-in-kibana/336597)

<div class="topic-metadata">

**Author:** [@JackBurton](https://discuss.elastic.co/u/JackBurton)\
**Replies:** 1\
**Last updated:** [June 21, 2023, 3:48pm UTC](https://discuss.elastic.co/t/elastic-agent-for-windows-visibility-of-docker-containers-in-kibana/336597 "2023-06-21T15:48:39Z")

</div>

Hi, we are trialing a move to Fleet and the Elastic Agent. Everything looks good for Linux Hosts, but with our Windows one if I look at Observability \> Infrastructure \> Inventory, filter for the hosts and then select 'Sh…

---

## [Unable to drop specific event code data using Kibana pipeline](https://discuss.elastic.co/t/unable-to-drop-specific-event-code-data-using-kibana-pipeline/336601)

<div class="topic-metadata">

**Author:** [@hiruni.insyncit.net](https://discuss.elastic.co/u/hiruni.insyncit.net)\
**Replies:** 0\
**Last updated:** [June 21, 2023, 3:28pm UTC](https://discuss.elastic.co/t/unable-to-drop-specific-event-code-data-using-kibana-pipeline/336601 "2023-06-21T15:28:41Z")

</div>

Hi, I'm using Elasticsearch 8.1.2. Elastic agent type: winlogbeat Elastic agent version: 7.14.2 Currently I'm getting data from this Elastic agent. I tried to drop some event code using ingest pipeline that is config…

---

## [Not able to restart kibana](https://discuss.elastic.co/t/not-able-to-restart-kibana/336576)

<div class="topic-metadata">

**Author:** [@Samir\_Pawar](https://discuss.elastic.co/u/Samir_Pawar)\
**Replies:** 1\
**Last updated:** [June 21, 2023, 3:20pm UTC](https://discuss.elastic.co/t/not-able-to-restart-kibana/336576 "2023-06-21T15:20:51Z")

</div>

Elasticsearch vesrion is 6.8. Elasticsearch install in GCP compute engine.

---

## [ES Index Rate drops after every few hours](https://discuss.elastic.co/t/es-index-rate-drops-after-every-few-hours/336540)

<div class="topic-metadata">

**Author:** [@mukularora89](https://discuss.elastic.co/u/mukularora89)\
**Replies:** 10\
**Last updated:** [June 21, 2023, 2:48pm UTC](https://discuss.elastic.co/t/es-index-rate-drops-after-every-few-hours/336540 "2023-06-21T14:48:51Z")

</div>

Hi, We are observing a drop in ES index rate after every few hours. We have indexes created on daily basis and data is pushed into ES from logstash. In a day we expect 8 billion documents pushed to given day index. At t…

---

## [Using the --tags option with @elastic/synthetics](https://discuss.elastic.co/t/using-the-tags-option-with-elastic-synthetics/330681)

<div class="topic-metadata">

**Author:** [@spaulovich](https://discuss.elastic.co/u/spaulovich)\
**Replies:** 2\
**Last updated:** [June 21, 2023, 1:50pm UTC](https://discuss.elastic.co/t/using-the-tags-option-with-elastic-synthetics/330681 "2023-06-21T13:50:28Z")

</div>

Any hints to correctly using the --tags option with @elastic/synthetics? Assuming a journey where I've added monitors.use({ tags: \["foo", "bar"\] }) If I run npx @elastic/synthetics . --tags "foo" I get No tests found! …

---

## [No access to kibana role management UI](https://discuss.elastic.co/t/no-access-to-kibana-role-management-ui/336286)

<div class="topic-metadata">

**Author:** [@Calvy93](https://discuss.elastic.co/u/Calvy93)\
**Replies:** 1\
**Last updated:** [June 21, 2023, 12:58pm UTC](https://discuss.elastic.co/t/no-access-to-kibana-role-management-ui/336286 "2023-06-21T12:58:54Z")

</div>

Hello everyone, I'm currently setting up the ELK-Stack + Filebeat and for the first configuration, I try to do without SSL as that was way too troublesome for a prototype when I first tried to implement it in every part…

---

## [Does Edge Ngram Token filter creates Synonym for tokens?](https://discuss.elastic.co/t/does-edge-ngram-token-filter-creates-synonym-for-tokens/336572)

<div class="topic-metadata">

**Author:** [@Farnaz](https://discuss.elastic.co/u/Farnaz)\
**Replies:** 0\
**Last updated:** [June 21, 2023, 12:03pm UTC](https://discuss.elastic.co/t/does-edge-ngram-token-filter-creates-synonym-for-tokens/336572 "2023-06-21T12:03:42Z")

</div>

ave added Edge Ngram Token Filter to my analyzer, ngram\_back\_fa. Here is my analyzer: "ngram\_back\_fa": { "tokenizer": "standard", "filter": \[ "lowercase", …

---

## [Rule for Applocker](https://discuss.elastic.co/t/rule-for-applocker/334299)

<div class="topic-metadata">

**Author:** [@Leitner](https://discuss.elastic.co/u/Leitner)\
**Replies:** 2\
**Last updated:** [June 21, 2023, 11:31am UTC](https://discuss.elastic.co/t/rule-for-applocker/334299 "2023-06-21T11:31:16Z")

</div>

Hi, first of all: I'm a newby with Elastic. So sorry for this question. But I just can't get any further. I want to create a rule for MS Applocker. At Analytics - Discover with filter event.code : 8004 and event.provi…

---

## [Migration from ES 6.8 to 7.17 : Issues with negative date epoch timestamp](https://discuss.elastic.co/t/migration-from-es-6-8-to-7-17-issues-with-negative-date-epoch-timestamp/335259)

<div class="topic-metadata">

**Author:** [@Abhilashsr2008](https://discuss.elastic.co/u/Abhilashsr2008)\
**Replies:** 7\
**Last updated:** [June 21, 2023, 10:19am UTC](https://discuss.elastic.co/t/migration-from-es-6-8-to-7-17-issues-with-negative-date-epoch-timestamp/335259 "2023-06-21T10:19:06Z")

</div>

Hi Guys We are migrating our applications from 6.8 ES cluster to 7.17.10 ES cluster . The one thing which we identified is that the negative values are not supported for date type fields( "format": "epoch\_millis") . Is …

---

## [Kibana to Elastic search communication is ending up with failure](https://discuss.elastic.co/t/kibana-to-elastic-search-communication-is-ending-up-with-failure/336438)

<div class="topic-metadata">

**Author:** [@Deepaklal\_KB](https://discuss.elastic.co/u/Deepaklal_KB)\
**Replies:** 5\
**Last updated:** [June 21, 2023, 9:42am UTC](https://discuss.elastic.co/t/kibana-to-elastic-search-communication-is-ending-up-with-failure/336438 "2023-06-21T09:42:23Z")

</div>

Getting an error as ünable to get issuer certificate in kibana logs once after starting the service. I am using DigicertCA.crt file to communicate with mu Elastic server LB. Which is a SAN certificate. This is happening…

---

## [CVE-2022-1471 is not listed in Security Issues site](https://discuss.elastic.co/t/cve-2022-1471-is-not-listed-in-security-issues-site/336553)

<div class="topic-metadata">

**Author:** [@Ayushi\_bhardwaj](https://discuss.elastic.co/u/Ayushi_bhardwaj)\
**Replies:** 1\
**Last updated:** [June 21, 2023, 8:38am UTC](https://discuss.elastic.co/t/cve-2022-1471-is-not-listed-in-security-issues-site/336553 "2023-06-21T08:38:33Z")

</div>

Is there any fix for that in any Logstash version? Is there any plan to update the damaged package of snakeyaml 1.31=\>2.0? Can I manually change the snakeyaml version? if so then how?

---

## [Elasitc-Agent APM integration on Kubernetes](https://discuss.elastic.co/t/elasitc-agent-apm-integration-on-kubernetes/336552)

<div class="topic-metadata">

**Author:** [@Piotr\_Pietka](https://discuss.elastic.co/u/Piotr_Pietka)\
**Replies:** 0\
**Last updated:** [June 21, 2023, 8:26am UTC](https://discuss.elastic.co/t/elasitc-agent-apm-integration-on-kubernetes/336552 "2023-06-21T08:26:44Z")

</div>

Hi, I've got deployed elastic-agents on kubernetes (rancher in my case). How to use APM integration to make it accessible to pods in cluster? Do I need to manualy create service or is that accessible by default? What is…

---

## [If condition loop on array](https://discuss.elastic.co/t/if-condition-loop-on-array/336518)

<div class="topic-metadata">

**Author:** [@plus](https://discuss.elastic.co/u/plus)\
**Replies:** 3\
**Last updated:** [June 21, 2023, 8:22am UTC](https://discuss.elastic.co/t/if-condition-loop-on-array/336518 "2023-06-21T08:22:29Z")

</div>

{ Hello, I was reading several posts how to loop through with array but I don't know how to iterate on each value and then rename. I tried with split but it creates a document for each value ( I want a doc with all val…

---

## [Why a cancelled task is still on the list?](https://discuss.elastic.co/t/why-a-cancelled-task-is-still-on-the-list/336413)

<div class="topic-metadata">

**Author:** [@HyebinHong](https://discuss.elastic.co/u/HyebinHong)\
**Replies:** 7\
**Last updated:** [June 21, 2023, 8:15am UTC](https://discuss.elastic.co/t/why-a-cancelled-task-is-still-on-the-list/336413 "2023-06-21T08:15:45Z")

</div>

Hello, elastic! While running multiple msearch API through Java clients, I found one of the tasks took abnormally long. So I executed Task Cancel API, but it doesn't seem cleanup properly. When I check the task via Ta…

---

## [java.util.concurrent.ExecutionException: ElasticsearchException\[java.util.concurrent.ExecutionException: CircuitBreakingException\[\[fielddata\] Data too large, data for \[apiVersion\] would be \[20659632080/19.2gb\], which is larger than the limit of \[206158430](https://discuss.elastic.co/t/java-util-concurrent-executionexception-elasticsearchexception-java-util-concurrent-executionexception-circuitbreakingexception-fielddata-data-too-large-data-for-apiversion-would-be-20659632080-19-2gb-which-is-larger-than-the-limit-of-206158430/336549)

<div class="topic-metadata">

**Author:** [@agusbuddi](https://discuss.elastic.co/u/agusbuddi)\
**Replies:** 1\
**Last updated:** [June 21, 2023, 8:05am UTC](https://discuss.elastic.co/t/java-util-concurrent-executionexception-elasticsearchexception-java-util-concurrent-executionexception-circuitbreakingexception-fielddata-data-too-large-data-for-apiversion-would-be-20659632080-19-2gb-which-is-larger-than-the-limit-of-206158430/336549 "2023-06-21T08:05:40Z")

</div>

java.util.concurrent.ExecutionException: ElasticsearchException\[java.util.concurrent.ExecutionException: CircuitBreakingException\[\[fielddata\] Data too large, data for \[apiVersion\] would be \[20659632080/19.2gb\], which is …

---

## [Rules and connectors](https://discuss.elastic.co/t/rules-and-connectors/336531)

<div class="topic-metadata">

**Author:** [@imaad](https://discuss.elastic.co/u/imaad)\
**Replies:** 0\
**Last updated:** [June 21, 2023, 6:01am UTC](https://discuss.elastic.co/t/rules-and-connectors/336531 "2023-06-21T06:01:56Z")

</div>

Hello, I want to create an Alert to monitor a specific pattern error every 4 hours which occurs in the message field. Could not connect to net.tcp: The connection attempt lasted for a time span of TCP error code 10061…

---

## [How to get Distinct results using Search API](https://discuss.elastic.co/t/how-to-get-distinct-results-using-search-api/336215)

<div class="topic-metadata">

**Author:** [@asimelastic](https://discuss.elastic.co/u/asimelastic)\
**Replies:** 4\
**Last updated:** [June 21, 2023, 7:38am UTC](https://discuss.elastic.co/t/how-to-get-distinct-results-using-search-api/336215 "2023-06-21T07:38:07Z")

</div>

I have a "customer" index with fields "FirstName" and "LastName". My index contains data as follows: First Name | LastName Richard | Lockwood Richard | Lockwood 2 Richard | Lockwood 3 Richard | Lockwood 4 Richard …

---

## [Issue with Custom Nginx Ingest Pipeline in Elasticsearch 8.7](https://discuss.elastic.co/t/issue-with-custom-nginx-ingest-pipeline-in-elasticsearch-8-7/336543)

<div class="topic-metadata">

**Author:** [@MIDHUN\_KRISHNA](https://discuss.elastic.co/u/MIDHUN_KRISHNA)\
**Replies:** 0\
**Last updated:** [June 21, 2023, 7:32am UTC](https://discuss.elastic.co/t/issue-with-custom-nginx-ingest-pipeline-in-elasticsearch-8-7/336543 "2023-06-21T07:32:57Z")

</div>

I'm currently facing an issue with Elasticsearch 8.7, specifically with the integration of Nginx logs and custom ingest pipelines. I have successfully installed Fleet Server with Elastic Agent, along with the Nginx integ…

---

## [API call to fetch kibana dashboard along with data in json format](https://discuss.elastic.co/t/api-call-to-fetch-kibana-dashboard-along-with-data-in-json-format/335940)

<div class="topic-metadata">

**Author:** [@Neelam\_Zanvar](https://discuss.elastic.co/u/Neelam_Zanvar)\
**Replies:** 2\
**Last updated:** [June 21, 2023, 7:15am UTC](https://discuss.elastic.co/t/api-call-to-fetch-kibana-dashboard-along-with-data-in-json-format/335940 "2023-06-21T07:15:17Z")

</div>

Hi, I am trying to generate the json file for kibana dashboard. I am trying this command but this gives me only the dashboard of the design. How can i get the data? curl -X GET 'http://demo.icebreaker.minutuscloud.com/…

---

## [Append a string to a field after mutate convert filter](https://discuss.elastic.co/t/append-a-string-to-a-field-after-mutate-convert-filter/336327)

<div class="topic-metadata">

**Author:** [@Neelam\_Zanvar](https://discuss.elastic.co/u/Neelam_Zanvar)\
**Replies:** 3\
**Last updated:** [June 21, 2023, 7:14am UTC](https://discuss.elastic.co/t/append-a-string-to-a-field-after-mutate-convert-filter/336327 "2023-06-21T07:14:11Z")

</div>

Hi I have the following log pattern \[19/Jun/2023:11:27:35 +0530\] | 503 | 1188 ms | 299 B | 172.31.40.179 | - | - | - | "GET /3dcomment/monitoring/healthcheck HTTP/1.1" I have applied grok to fetch the bytes field i.e 2…

---

## [Error in indexing polygon data in Elasticsearch 8.8](https://discuss.elastic.co/t/error-in-indexing-polygon-data-in-elasticsearch-8-8/335335)

<div class="topic-metadata">

**Author:** [@amal\_antony](https://discuss.elastic.co/u/amal_antony)\
**Replies:** 6\
**Last updated:** [June 21, 2023, 6:00am UTC](https://discuss.elastic.co/t/error-in-indexing-polygon-data-in-elasticsearch-8-8/335335 "2023-06-21T06:00:53Z")

</div>

Greetings to the community! I am experiencing issues while ingesting polygon data into Elasticsearch 8.8. An issue had been raised before in the same context, link. This was identified as a bug in Lucene, the fix for wh…

---

## [How we can calculate only Working days only Monday to Friday and skip Saturday and Sunday](https://discuss.elastic.co/t/how-we-can-calculate-only-working-days-only-monday-to-friday-and-skip-saturday-and-sunday/335731)

<div class="topic-metadata">

**Author:** [@PappuSingh](https://discuss.elastic.co/u/PappuSingh)\
**Replies:** 4\
**Last updated:** [June 21, 2023, 5:21am UTC](https://discuss.elastic.co/t/how-we-can-calculate-only-working-days-only-monday-to-friday-and-skip-saturday-and-sunday/335731 "2023-06-21T05:21:21Z")

</div>

How we can calculate only Working days only Monday to Friday and skip Saturday and Sunday

---

## [ELK upgrade to 7.17.10](https://discuss.elastic.co/t/elk-upgrade-to-7-17-10/336513)

<div class="topic-metadata">

**Author:** [@khadija70](https://discuss.elastic.co/u/khadija70)\
**Replies:** 2\
**Last updated:** [June 21, 2023, 5:11am UTC](https://discuss.elastic.co/t/elk-upgrade-to-7-17-10/336513 "2023-06-21T05:11:10Z")

</div>

Hi , We recentely upgraded the ELK cluster from the 7.15.1 to 7.17.10 in order to fix security vulnerabilities , however after upgrading we are still have the open JDK vulnerability on Elasticsearch servers : OpenJDK…

---

## [Store Old Indices in S3 and load when needed in future?](https://discuss.elastic.co/t/store-old-indices-in-s3-and-load-when-needed-in-future/336503)

<div class="topic-metadata">

**Author:** [@datencio](https://discuss.elastic.co/u/datencio)\
**Replies:** 2\
**Last updated:** [June 21, 2023, 3:59am UTC](https://discuss.elastic.co/t/store-old-indices-in-s3-and-load-when-needed-in-future/336503 "2023-06-21T03:59:01Z")

</div>

We would like to store lots of old indices in S3 for easy storage and the ability to import the indice from S3 back into Elasticsearch when needed. I have installed the repository-s3 plugin, and I have seen how i can do …

---

## [Aggregate filter の timeout\_timestamp\_field設定時の動作について](https://discuss.elastic.co/t/aggregate-filter-timeout-timestamp-field/336283)

<div class="topic-metadata">

**Author:** [@e-se](https://discuss.elastic.co/u/e-se)\
**Replies:** 3\
**Last updated:** [June 20, 2023, 9:48pm UTC](https://discuss.elastic.co/t/aggregate-filter-timeout-timestamp-field/336283 "2023-06-20T21:48:19Z")

</div>

Aggregate filter pluginのオプションtimeout\_timestamp\_fieldについて、 機能追加の経緯やドキュメントの記載から設定すると、タイムアウトの判定がシステム時間からログのタイムスタンプに変わると思っていたが、実際に動かしてみると、システム時間で判定されたような挙動をした。 （私と同じ疑問を持った方が過去にいたよう。https://discuss.elastic.co/t/aggregate-fi…

---

## [Limiting Response Data Using URI Based on Value of Search Term](https://discuss.elastic.co/t/limiting-response-data-using-uri-based-on-value-of-search-term/336507)

<div class="topic-metadata">

**Author:** [@Akaash\_Mukherjee](https://discuss.elastic.co/u/Akaash_Mukherjee)\
**Replies:** 0\
**Last updated:** [June 20, 2023, 7:51pm UTC](https://discuss.elastic.co/t/limiting-response-data-using-uri-based-on-value-of-search-term/336507 "2023-06-20T19:51:14Z")

</div>

I'm looking to filter out data in response objects based on the value of a search term. The request below for instance, filters the data within the objects themselves, excluding a particular field (attribute.betaalmethod…

[Previous page](https://discuss.elastic.co/tag/none.md?no_tags=true&page=354)

[Next page](https://discuss.elastic.co/tag/none.md?no_tags=true&page=356)
