# \#none

**URL:** https://discuss.elastic.co/tag/none.md?no_tags=true&page=361

[Latest](https://discuss.elastic.co/latest.md) · [Categories](https://discuss.elastic.co/categories.md) · [Tags](https://discuss.elastic.co/tags.md)

**Page:** 362

---

## [Aggregate data per document](https://discuss.elastic.co/t/aggregate-data-per-document/334812)

<div class="topic-metadata">

**Author:** [@JohnJoe](https://discuss.elastic.co/u/JohnJoe)\
**Replies:** 2\
**Last updated:** [June 13, 2023, 7:18pm UTC](https://discuss.elastic.co/t/aggregate-data-per-document/334812 "2023-06-13T19:18:31Z")

</div>

Hi All, I am wondering if the following is possible. I want to be able aggregate nested data within a document and then filter by the aggregated data. So if we have PUT warehouse/ { "mappings": { "properties": { …

---

## [Elastic agent unable to send logs to elasticsearch](https://discuss.elastic.co/t/elastic-agent-unable-to-send-logs-to-elasticsearch/335870)

<div class="topic-metadata">

**Author:** [@kafikone](https://discuss.elastic.co/u/kafikone)\
**Replies:** 1\
**Last updated:** [June 13, 2023, 6:47pm UTC](https://discuss.elastic.co/t/elastic-agent-unable-to-send-logs-to-elasticsearch/335870 "2023-06-13T18:47:51Z")

</div>

I deployed elasticsearch, kibana and logstash on a CentOS 7 virtual machine, and everything is working correctly. Then I created a fleet server and installed an elastic agent on a Windows 11 Vm. The status of my agent is…

---

## [When create controls in kibana Visualize : message '00' index doesn't match any options!](https://discuss.elastic.co/t/when-create-controls-in-kibana-visualize-message-00-index-doesnt-match-any-options/335728)

<div class="topic-metadata">

**Author:** [@Changjae\_Lee](https://discuss.elastic.co/u/Changjae_Lee)\
**Replies:** 3\
**Last updated:** [June 13, 2023, 6:22pm UTC](https://discuss.elastic.co/t/when-create-controls-in-kibana-visualize-message-00-index-doesnt-match-any-options/335728 "2023-06-13T18:22:10Z")

</div>

i'got the message. visualize controls \> Index Pattern \> "\_\_\_\_" (index name) doesn't match any options is it a version problem? need to update?

---

## [Fleet-server is unauthorized on indice](https://discuss.elastic.co/t/fleet-server-is-unauthorized-on-indice/332566)

<div class="topic-metadata">

**Author:** [@stenbot1](https://discuss.elastic.co/u/stenbot1)\
**Replies:** 3\
**Last updated:** [June 13, 2023, 5:59pm UTC](https://discuss.elastic.co/t/fleet-server-is-unauthorized-on-indice/332566 "2023-06-13T17:59:56Z")

</div>

Hello! I am pretty green when it comes to Elastic but I recently set up a brand new stack to test ingesting a log file. I installed the Elastic Agent on a Windows machine that outputs logs to a file. I have the integrat…

---

## [How to find the number of affected results from Collapse?](https://discuss.elastic.co/t/how-to-find-the-number-of-affected-results-from-collapse/335896)

<div class="topic-metadata">

**Author:** [@\_zogaj](https://discuss.elastic.co/u/_zogaj)\
**Replies:** 0\
**Last updated:** [June 13, 2023, 4:53pm UTC](https://discuss.elastic.co/t/how-to-find-the-number-of-affected-results-from-collapse/335896 "2023-06-13T16:53:57Z")

</div>

I am using collapse to remove duplicated docs. How to find affected results from Collapse ?

---

## [Unable to show Current & Max values in Gauge or Goal](https://discuss.elastic.co/t/unable-to-show-current-max-values-in-gauge-or-goal/335864)

<div class="topic-metadata">

**Author:** [@Sandeep\_Raju](https://discuss.elastic.co/u/Sandeep_Raju)\
**Replies:** 1\
**Last updated:** [June 13, 2023, 4:11pm UTC](https://discuss.elastic.co/t/unable-to-show-current-max-values-in-gauge-or-goal/335864 "2023-06-13T16:11:31Z")

</div>

Hi all, I'm having 2 fields, currentscore and maximumscore in my indexpattern I'm trying to show How much my current score is compared to max value or goal it must achieve. Both current score and max score are in dyna…

---

## [Normalizing the Huawei firewall logs](https://discuss.elastic.co/t/normalizing-the-huawei-firewall-logs/335861)

<div class="topic-metadata">

**Author:** [@Imad\_TAMELGHAGHET](https://discuss.elastic.co/u/Imad_TAMELGHAGHET)\
**Replies:** 4\
**Last updated:** [June 13, 2023, 3:07pm UTC](https://discuss.elastic.co/t/normalizing-the-huawei-firewall-logs/335861 "2023-06-13T15:07:58Z")

</div>

Hello , I am actually working on a ELK SIEM project, and one of the logs sources i am woking with is a Huawei Firewall .Since Huawei firewall logs have differents formats, I would appreciate some suggestions and insight…

---

## [Adding a negative boost in a multi\_match query](https://discuss.elastic.co/t/adding-a-negative-boost-in-a-multi-match-query/335534)

<div class="topic-metadata">

**Author:** [@daansk44](https://discuss.elastic.co/u/daansk44)\
**Replies:** 3\
**Last updated:** [June 13, 2023, 2:52pm UTC](https://discuss.elastic.co/t/adding-a-negative-boost-in-a-multi-match-query/335534 "2023-06-13T14:52:49Z")

</div>

Hi everyone, I just started with Elastic Search I wanted to make some items in the query less relevant, so I am trying to give them a negative boost (make the two items in the must\_not sub-query less relevant). And exa…

---

## [Kibana: Not able to maximize panel permanently](https://discuss.elastic.co/t/kibana-not-able-to-maximize-panel-permanently/335420)

<div class="topic-metadata">

**Author:** [@alexander\_esser](https://discuss.elastic.co/u/alexander_esser)\
**Replies:** 4\
**Last updated:** [June 13, 2023, 2:49pm UTC](https://discuss.elastic.co/t/kibana-not-able-to-maximize-panel-permanently/335420 "2023-06-13T14:49:40Z")

</div>

Hello, In Kibana 8.6.2, I would like to maximize a panel permanently. So, I click on the panel's "Options" \> "Maximize panel": However, when I load the Kibana dashboard next time, the panel is minimized again. It d…

---

## [Cluster fails to elect master after using new data store](https://discuss.elastic.co/t/cluster-fails-to-elect-master-after-using-new-data-store/335450)

<div class="topic-metadata">

**Author:** [@Xand](https://discuss.elastic.co/u/Xand)\
**Replies:** 6\
**Last updated:** [June 13, 2023, 2:36pm UTC](https://discuss.elastic.co/t/cluster-fails-to-elect-master-after-using-new-data-store/335450 "2023-06-13T14:36:41Z")

</div>

We have a 2-node cluster running on an Openshift platform. Recently, we installed new NFS volume shares to be used as data stores for the cluster, and we want to make a new cluster using those volumes. After deleting the…

---

## [\[warn\]: #0 Could not communicate to Elasticsearch, resetting connection and trying again. EOFError (EOFError)](https://discuss.elastic.co/t/warn-0-could-not-communicate-to-elasticsearch-resetting-connection-and-trying-again-eoferror-eoferror/335875)

<div class="topic-metadata">

**Author:** [@Resul\_Zoroglu](https://discuss.elastic.co/u/Resul_Zoroglu)\
**Replies:** 0\
**Last updated:** [June 13, 2023, 1:31pm UTC](https://discuss.elastic.co/t/warn-0-could-not-communicate-to-elasticsearch-resetting-connection-and-trying-again-eoferror-eoferror/335875 "2023-06-13T13:31:25Z")

</div>

I'm installing elasticsearch, kibana and fluentd in kubernetes with helm chart Elasticsearch and kibana pods stand up smoothly, but fluentd pods don't stand up I get the following errors: 2023-06-13 13:29:39 +0000 \[warn…

---

## [KIbana - telemetry disabled - notice](https://discuss.elastic.co/t/kibana-telemetry-disabled-notice/335866)

<div class="topic-metadata">

**Author:** [@fkurucz](https://discuss.elastic.co/u/fkurucz)\
**Replies:** 2\
**Last updated:** [June 13, 2023, 12:41pm UTC](https://discuss.elastic.co/t/kibana-telemetry-disabled-notice/335866 "2023-06-13T12:41:38Z")

</div>

Hi, I have telemetry disabled and i get this "Help us improve the Elastic Stack" notice on Kibana. Is there any way to permanently disable the above notice in Kibana? It becomes very annoying to dismiss it each time i …

---

## [Problem in Kibana](https://discuss.elastic.co/t/problem-in-kibana/335846)

<div class="topic-metadata">

**Author:** [@Anass.EL](https://discuss.elastic.co/u/Anass.EL)\
**Replies:** 4\
**Last updated:** [June 13, 2023, 10:55am UTC](https://discuss.elastic.co/t/problem-in-kibana/335846 "2023-06-13T10:55:57Z")

</div>

Hello everyone, I was using ELK stack to put in place an internal SOC, all was well there was only a problem with the license but it was resolved, and then suddenky kibana stoped functioning it just gives me the error: …

---

## [Logstash Kafka input DNS lookup for Kafka is not working](https://discuss.elastic.co/t/logstash-kafka-input-dns-lookup-for-kafka-is-not-working/335862)

<div class="topic-metadata">

**Author:** [@youngin.son.naver](https://discuss.elastic.co/u/youngin.son.naver)\
**Replies:** 0\
**Last updated:** [June 13, 2023, 10:53am UTC](https://discuss.elastic.co/t/logstash-kafka-input-dns-lookup-for-kafka-is-not-working/335862 "2023-06-13T10:53:45Z")

</div>

Using Logstash 7.12.1 and Kafka input option, Logstash does not automatically do DNS lookup when Kafka cluster has been restarted. \[org.apache.kafka.clients.NetworkClient\]\[main\]\[kafka\_test\] \[Consumer clientId=\*\*\*\*\*\*.lo…

---

## [TSVB | Kibana document](https://discuss.elastic.co/t/tsvb-kibana-document/335766)

<div class="topic-metadata">

**Author:** [@Amber](https://discuss.elastic.co/u/Amber)\
**Replies:** 1\
**Last updated:** [June 13, 2023, 9:46am UTC](https://discuss.elastic.co/t/tsvb-kibana-document/335766 "2023-06-13T09:46:56Z")

</div>

Does the official document about the TSVB | Kibana Guide \[8.8\] | Elastic got a misspelling?

---

## [Elasticsearch synonym mappings - illegal\_argument\_exception](https://discuss.elastic.co/t/elasticsearch-synonym-mappings-illegal-argument-exception/335746)

<div class="topic-metadata">

**Author:** [@Jacques\_du\_Plessis](https://discuss.elastic.co/u/Jacques_du_Plessis)\
**Replies:** 1\
**Last updated:** [June 13, 2023, 8:25am UTC](https://discuss.elastic.co/t/elasticsearch-synonym-mappings-illegal-argument-exception/335746 "2023-06-13T08:25:35Z")

</div>

is there a way to tell the mappings to ignore the synonym file if it does not exist? currently i always have to make sure that the synonym file exist, but just wondering of there is a way to ignore it if its not there, …

---

## [Removing redundancy in query](https://discuss.elastic.co/t/removing-redundancy-in-query/335778)

<div class="topic-metadata">

**Author:** [@searchwithme](https://discuss.elastic.co/u/searchwithme)\
**Replies:** 2\
**Last updated:** [June 13, 2023, 7:38am UTC](https://discuss.elastic.co/t/removing-redundancy-in-query/335778 "2023-06-13T07:38:56Z")

</div>

Can this query: { "query": { "bool": { "must": \[ { "match": { "title": "elasticsearch" } }, { "match": { "author": "jondoe" } }, { "range": { "price": { "gte": 10, "lte": 100 } } } \], "must\_not": \[ { "match": {…

---

## [Fluentd pods don't see elasticsearch\[Efk on Kubernetes using Helm\]](https://discuss.elastic.co/t/fluentd-pods-dont-see-elasticsearch-efk-on-kubernetes-using-helm/335830)

<div class="topic-metadata">

**Author:** [@Resul\_Zoroglu](https://discuss.elastic.co/u/Resul_Zoroglu)\
**Replies:** 0\
**Last updated:** [June 13, 2023, 7:39am UTC](https://discuss.elastic.co/t/fluentd-pods-dont-see-elasticsearch-efk-on-kubernetes-using-helm/335830 "2023-06-13T07:39:39Z")

</div>

elastic image from helm chart repo I install elasticsearch and kibana without any problem and pods are standing up on kubernetes. helm-charts/charts/fluentd-elasticsearch at main · kokuwaio/helm-charts · GitHub I am i…

---

## [Understanding Agent Status Value Matching and Check-in Criteria in Elastic Stack](https://discuss.elastic.co/t/understanding-agent-status-value-matching-and-check-in-criteria-in-elastic-stack/335829)

<div class="topic-metadata">

**Author:** [@Erick\_Choi](https://discuss.elastic.co/u/Erick_Choi)\
**Replies:** 0\
**Last updated:** [June 13, 2023, 7:15am UTC](https://discuss.elastic.co/t/understanding-agent-status-value-matching-and-check-in-criteria-in-elastic-stack/335829 "2023-06-13T07:15:00Z")

</div>

Hello, I have several questions regarding the agent status value matching as well as check-in criteria in Elastic Stack. How is the matching process between unit.state field values for agent status information in Inde…

---

## [Get data view api returns 404 even if the data view exists](https://discuss.elastic.co/t/get-data-view-api-returns-404-even-if-the-data-view-exists/335822)

<div class="topic-metadata">

**Author:** [@Neelam\_Zanvar](https://discuss.elastic.co/u/Neelam_Zanvar)\
**Replies:** 13\
**Last updated:** [June 13, 2023, 6:08am UTC](https://discuss.elastic.co/t/get-data-view-api-returns-404-even-if-the-data-view-exists/335822 "2023-06-13T06:08:38Z")

</div>

Hi i am using the following command to check if the data view exists curl -X GET "http://demo.icebreaker.minutuscloud.com/kibana/api/data\_views/data\_view/3dxp\_servicetrace" -H 'kbn-xsrf: true' -u elastic:minutus -k E…

---

## [Kibana\_system user ID is unable to connect to elasticsearch](https://discuss.elastic.co/t/kibana-system-user-id-is-unable-to-connect-to-elasticsearch/335623)

<div class="topic-metadata">

**Author:** [@swchandu](https://discuss.elastic.co/u/swchandu)\
**Replies:** 2\
**Last updated:** [June 13, 2023, 4:52am UTC](https://discuss.elastic.co/t/kibana-system-user-id-is-unable-to-connect-to-elasticsearch/335623 "2023-06-13T04:52:10Z")

</div>

Hi, I have created a new Elasticsearch cluster 8.8.0(on Linux) and tried to start kibana. But found this error for the first time. BTW, kibana\_system/new id's password is set already with APIs. kibana.yml server.port…

---

## [LogStash setting Date error](https://discuss.elastic.co/t/logstash-setting-date-error/335733)

<div class="topic-metadata">

**Author:** [@yy\_isam](https://discuss.elastic.co/u/yy_isam)\
**Replies:** 8\
**Last updated:** [June 13, 2023, 4:46am UTC](https://discuss.elastic.co/t/logstash-setting-date-error/335733 "2023-06-13T04:46:20Z")

</div>

Hello guys! I want to run my logtstash connect to elastic using input jdbc. Then i create conf file to run logstash but i always get this error, i try any changes in conf file but still not working. Anyone can help me t…

---

## [Var/run/elastic-agent.sock: connect: no such file or directory](https://discuss.elastic.co/t/var-run-elastic-agent-sock-connect-no-such-file-or-directory/335817)

<div class="topic-metadata">

**Author:** [@xqaiviwjxzw](https://discuss.elastic.co/u/xqaiviwjxzw)\
**Replies:** 0\
**Last updated:** [June 13, 2023, 3:31am UTC](https://discuss.elastic.co/t/var-run-elastic-agent-sock-connect-no-such-file-or-directory/335817 "2023-06-13T03:31:49Z")

</div>

The installation of the elastic agent is not successful, and the following error is displayed when executing the elastic-agent status query. What is the solution? % sudo /Library/Elastic/Agent/elastic-agent status Error…

---

## [There is no "Create Index" Tab](https://discuss.elastic.co/t/there-is-no-create-index-tab/335790)

<div class="topic-metadata">

**Author:** [@Resul\_Zoroglu](https://discuss.elastic.co/u/Resul_Zoroglu)\
**Replies:** 1\
**Last updated:** [June 13, 2023, 1:49am UTC](https://discuss.elastic.co/t/there-is-no-create-index-tab/335790 "2023-06-13T01:49:26Z")

</div>

I installed the latest version of elasticsearch and kibana with helm chart on kubernetes. There is no create index tab in Kibana. Is it up or is there something I missed? helm install elasticsearch elastic/elasticsearch…

---

## [Get list of documents from a specific segment](https://discuss.elastic.co/t/get-list-of-documents-from-a-specific-segment/335663)

<div class="topic-metadata">

**Author:** [@cvarano](https://discuss.elastic.co/u/cvarano)\
**Replies:** 3\
**Last updated:** [June 13, 2023, 1:45am UTC](https://discuss.elastic.co/t/get-list-of-documents-from-a-specific-segment/335663 "2023-06-13T01:45:36Z")

</div>

Is there a way to inspect which documents are stored in a specific segment? I can get the segments from the cat segments api, but it only tells me the total # of docs. I want to perform two functions: Given a segment …

---

## [Is there a way to avoid elastic agent installation on host?](https://discuss.elastic.co/t/is-there-a-way-to-avoid-elastic-agent-installation-on-host/335643)

<div class="topic-metadata">

**Author:** [@Marcos\_Ivan\_Robles\_H](https://discuss.elastic.co/u/Marcos_Ivan_Robles_H)\
**Replies:** 0\
**Last updated:** [June 9, 2023, 3:49pm UTC](https://discuss.elastic.co/t/is-there-a-way-to-avoid-elastic-agent-installation-on-host/335643 "2023-06-09T15:49:39Z")

</div>

I wonder if it is possible to enroll to the predefined elastic agent in cloud without having to install it on my local host or any host. So far. I understand elastic agent is installed by default in cloud environments. …

---

## [Estimate resource usage in ES 6](https://discuss.elastic.co/t/estimate-resource-usage-in-es-6/335803)

<div class="topic-metadata">

**Author:** [@louisdeveloper](https://discuss.elastic.co/u/louisdeveloper)\
**Replies:** 1\
**Last updated:** [June 13, 2023, 12:39am UTC](https://discuss.elastic.co/t/estimate-resource-usage-in-es-6/335803 "2023-06-13T00:39:08Z")

</div>

However I have a self-hosted server with Elasticsearch 6. Does it allow me to get an estimate of how many GB were read during a period and how many API calls were made in a period?

---

## [Theme settings for the forum are being ignored](https://discuss.elastic.co/t/theme-settings-for-the-forum-are-being-ignored/335540)

<div class="topic-metadata">

**Author:** [@leandrojmp](https://discuss.elastic.co/u/leandrojmp)\
**Replies:** 9\
**Last updated:** [June 12, 2023, 10:21pm UTC](https://discuss.elastic.co/t/theme-settings-for-the-forum-are-being-ignored/335540 "2023-06-12T22:21:42Z")

</div>

Hello, Is there any way to force a theme for the forum? I want to use the Light theme, but it is forcing the dark theme to me. Is it a bug on Discuss? The Light (Main) theme is already selected on the settings and the…

---

## [Logstash filter issue](https://discuss.elastic.co/t/logstash-filter-issue/335314)

<div class="topic-metadata">

**Author:** [@namdev](https://discuss.elastic.co/u/namdev)\
**Replies:** 4\
**Last updated:** [June 12, 2023, 5:34pm UTC](https://discuss.elastic.co/t/logstash-filter-issue/335314 "2023-06-12T17:34:55Z")

</div>

Hi team, I am using logstash filter to get the duration between two dates. StartDate =2023-05-23T 10:25:53.123Z EndDate =2023-05-23T 18:25:43.123Z using the code below:-- match =\> \[ "Start Date", "ISO86…

---

## [Will the documentation be accessible for Elastic Certified Analyst Exam?](https://discuss.elastic.co/t/will-the-documentation-be-accessible-for-elastic-certified-analyst-exam/335413)

<div class="topic-metadata">

**Author:** [@Sheereen](https://discuss.elastic.co/u/Sheereen)\
**Replies:** 2\
**Last updated:** [June 12, 2023, 4:55pm UTC](https://discuss.elastic.co/t/will-the-documentation-be-accessible-for-elastic-certified-analyst-exam/335413 "2023-06-12T16:55:18Z")

</div>

Hi, Will the Kibana documentation link be provided/accessible for the Elastic Certified Analyst examination? Thanks

[Previous page](https://discuss.elastic.co/tag/none.md?no_tags=true&page=360)

[Next page](https://discuss.elastic.co/tag/none.md?no_tags=true&page=362)
