# \#none

**URL:** https://discuss.elastic.co/tag/none.md?no_tags=true&page=362

[Latest](https://discuss.elastic.co/latest.md) · [Categories](https://discuss.elastic.co/categories.md) · [Tags](https://discuss.elastic.co/tags.md)

**Page:** 363

---

## [Three Plots from one Data View With Two Different Split Series Applying Individually](https://discuss.elastic.co/t/three-plots-from-one-data-view-with-two-different-split-series-applying-individually/335647)

<div class="topic-metadata">

**Author:** [@nickbarry](https://discuss.elastic.co/u/nickbarry)\
**Replies:** 21\
**Last updated:** [June 12, 2023, 3:59pm UTC](https://discuss.elastic.co/t/three-plots-from-one-data-view-with-two-different-split-series-applying-individually/335647 "2023-06-12T15:59:43Z")

</div>

I have three data plots I wish to display in one visualization. All data is from one wildcard data view and I have defined three y-axes. I would like to have two stacked data plots (line charts, in this case), split by…

---

## [Install Logstash-jdbc-integration plugin offline](https://discuss.elastic.co/t/install-logstash-jdbc-integration-plugin-offline/335785)

<div class="topic-metadata">

**Author:** [@ztzy1907](https://discuss.elastic.co/u/ztzy1907)\
**Replies:** 1\
**Last updated:** [June 12, 2023, 3:07pm UTC](https://discuss.elastic.co/t/install-logstash-jdbc-integration-plugin-offline/335785 "2023-06-12T15:07:32Z")

</div>

Hi, this is Richard. I'm trying to install logstash-jdbc-integration plugin on Logstash 7.8.0 on a machine that does not have internet access. What I'm trying to do is like below which is similar to install plugin on e…

---

## [This really helped me on Elastic with Logstash 8.x](https://discuss.elastic.co/t/this-really-helped-me-on-elastic-with-logstash-8-x/335781)

<div class="topic-metadata">

**Author:** [@dpresbit](https://discuss.elastic.co/u/dpresbit)\
**Replies:** 0\
**Last updated:** [June 12, 2023, 2:27pm UTC](https://discuss.elastic.co/t/this-really-helped-me-on-elastic-with-logstash-8-x/335781 "2023-06-12T14:27:36Z")

</div>

Continuing the discussion from Where is the object mapping for \[host\] defined?:

---

## [{"statusCode":503,"error":"Service Unavailable","message":"License is not available."}](https://discuss.elastic.co/t/statuscode-503-error-service-unavailable-message-license-is-not-available/335741)

<div class="topic-metadata">

**Author:** [@R1d3rBG](https://discuss.elastic.co/u/R1d3rBG)\
**Replies:** 6\
**Last updated:** [June 12, 2023, 1:41pm UTC](https://discuss.elastic.co/t/statuscode-503-error-service-unavailable-message-license-is-not-available/335741 "2023-06-12T13:41:52Z")

</div>

Hello, I have installed Elastic, but after 2-3 days stops working with the following error. {"statusCode":503,"error":"Service Unavailable","message":"License is not available."} Could you help me with investigation w…

---

## [Error message: the node is expected to continue to exceed the high disk watermark when these relocations are complete](https://discuss.elastic.co/t/error-message-the-node-is-expected-to-continue-to-exceed-the-high-disk-watermark-when-these-relocations-are-complete/335660)

<div class="topic-metadata">

**Author:** [@Mhvrke](https://discuss.elastic.co/u/Mhvrke)\
**Replies:** 2\
**Last updated:** [June 12, 2023, 1:00pm UTC](https://discuss.elastic.co/t/error-message-the-node-is-expected-to-continue-to-exceed-the-high-disk-watermark-when-these-relocations-are-complete/335660 "2023-06-12T13:00:02Z")

</div>

Hi! There’s this scenario where my cluster elasticsearch in rke logs is showing the following message: the node is expected to continue to exceed the high disk watermark when these relocations are complete. It keeps lo…

---

## [Rally 2.8.0](https://discuss.elastic.co/t/rally-2-8-0/335769)

<div class="topic-metadata">

**Author:** [@gbanasiak](https://discuss.elastic.co/u/gbanasiak)\
**Replies:** 0\
**Last updated:** [June 12, 2023, 12:11pm UTC](https://discuss.elastic.co/t/rally-2-8-0/335769 "2023-06-12T12:11:32Z")

</div>

Rally 2.8.0 has just been released. The new release brings support for Python 3.11. Highlights #1683: Upgrade Elasticsearch client to 8.6.1 #1669: Upgrade ES Client to 8.x Enhancements #1727: Allow configuring…

---

## [Which storage type should I use for Elasticsearch?](https://discuss.elastic.co/t/which-storage-type-should-i-use-for-elasticsearch/335511)

<div class="topic-metadata">

**Author:** [@Yasser\_Alsawy](https://discuss.elastic.co/u/Yasser_Alsawy)\
**Replies:** 1\
**Last updated:** [June 12, 2023, 11:33am UTC](https://discuss.elastic.co/t/which-storage-type-should-i-use-for-elasticsearch/335511 "2023-06-12T11:33:59Z")

</div>

I'm installing elasticsearch and needs 2 TB storage for shipping from filesystem log files using beats and logstash. What is the proper storage type as per our required design (frequent writes, many nodes and less read) …

---

## [Which table to use/how to filter columns in aggreagtion based data table](https://discuss.elastic.co/t/which-table-to-use-how-to-filter-columns-in-aggreagtion-based-data-table/334209)

<div class="topic-metadata">

**Author:** [@Jonas\_S](https://discuss.elastic.co/u/Jonas_S)\
**Replies:** 1\
**Last updated:** [June 12, 2023, 11:18am UTC](https://discuss.elastic.co/t/which-table-to-use-how-to-filter-columns-in-aggreagtion-based-data-table/334209 "2023-06-12T11:18:57Z")

</div>

Hello, i'm using Kibana 8.7.0 and i have data in this form: {id: 1, valueToFilterBy: 0, valueToSum: 10, stringValue: "someString1"}, {id: 1, valueToFilterBy: 0, valueToSum: 20, stringValue: "someString2"}, {id: 1, va…

---

## [Kibana failing to start due to unable to verify the first certificate](https://discuss.elastic.co/t/kibana-failing-to-start-due-to-unable-to-verify-the-first-certificate/335608)

<div class="topic-metadata">

**Author:** [@Sudhir\_Batchu](https://discuss.elastic.co/u/Sudhir_Batchu)\
**Replies:** 1\
**Last updated:** [June 12, 2023, 9:58am UTC](https://discuss.elastic.co/t/kibana-failing-to-start-due-to-unable-to-verify-the-first-certificate/335608 "2023-06-12T09:58:16Z")

</div>

Hi need help in fixing this ES version 8.8 Kibana version 8.8 Here is Kibana logs Jun 09 08:28:10 ip-100-90-3-56.us-west-2.compute.internal kibana\[20111\]: \[2023-06-09T08:28:10.667+00:00\]\[INFO \]\[plugins.screenshotting…

---

## [Is is possible to disable clock skew adjustment for APM dashboard (kibana)](https://discuss.elastic.co/t/is-is-possible-to-disable-clock-skew-adjustment-for-apm-dashboard-kibana/335737)

<div class="topic-metadata">

**Author:** [@Xumin\_Zhou](https://discuss.elastic.co/u/Xumin_Zhou)\
**Replies:** 1\
**Last updated:** [June 12, 2023, 6:49am UTC](https://discuss.elastic.co/t/is-is-possible-to-disable-clock-skew-adjustment-for-apm-dashboard-kibana/335737 "2023-06-12T06:49:53Z")

</div>

As the title says. First-hand information (real readout) is important for monitoring and tracing. There're a lot of problems not solved with this adjustment, for example, it does not preserve the relative positions of …

---

## [Add unique value for each fields](https://discuss.elastic.co/t/add-unique-value-for-each-fields/335695)

<div class="topic-metadata">

**Author:** [@sevbans](https://discuss.elastic.co/u/sevbans)\
**Replies:** 6\
**Last updated:** [June 11, 2023, 9:26pm UTC](https://discuss.elastic.co/t/add-unique-value-for-each-fields/335695 "2023-06-11T21:26:30Z")

</div>

I have a index something like this: All countries' names, along with their populations, exist in my index. Since Kibana does not allow us to use the countries' normal names, I have to add unique country codes such as…

---

## [Metrics do nothing in my file](https://discuss.elastic.co/t/metrics-do-nothing-in-my-file/335700)

<div class="topic-metadata">

**Author:** [@javierelastic](https://discuss.elastic.co/u/javierelastic)\
**Replies:** 2\
**Last updated:** [June 11, 2023, 10:35am UTC](https://discuss.elastic.co/t/metrics-do-nothing-in-my-file/335700 "2023-06-11T10:35:19Z")

</div>

I am trying to count the number of logs that appear in my file. Now I am using a file with logs as an example, but later I will use a syslog, and I want it to count the logs that arrive in 2 minutes. if \[msgFinal\] =~…

---

## [URL Drilldown - How to pass specific column value](https://discuss.elastic.co/t/url-drilldown-how-to-pass-specific-column-value/335719)

<div class="topic-metadata">

**Author:** [@azulgrana](https://discuss.elastic.co/u/azulgrana)\
**Replies:** 0\
**Last updated:** [June 11, 2023, 10:32am UTC](https://discuss.elastic.co/t/url-drilldown-how-to-pass-specific-column-value/335719 "2023-06-11T10:32:22Z")

</div>

Hi there, I have a table with 3 fields. Id, IOC, Severity. And I have a set of drilldowns to perform an IOC search against virustotal, Whois and map the Id to an internal app. I'm using {{event.value}} across all the dr…

---

## [Too many open files](https://discuss.elastic.co/t/too-many-open-files/335677)

<div class="topic-metadata">

**Author:** [@lchqlchq](https://discuss.elastic.co/u/lchqlchq)\
**Replies:** 4\
**Last updated:** [June 11, 2023, 7:36am UTC](https://discuss.elastic.co/t/too-many-open-files/335677 "2023-06-11T07:36:32Z")

</div>

i have a three node es7.4 cluster without data. choose one node,ifdown the network，and es filehandler increasing quickly until the ulimit filehandler fills up。the new added filehandler point the same socket id as:ll /pro…

---

## [How to add \_size mapping to index template in elasticsearch?](https://discuss.elastic.co/t/how-to-add-size-mapping-to-index-template-in-elasticsearch/335432)

<div class="topic-metadata">

**Author:** [@Amirhossein\_eidy](https://discuss.elastic.co/u/Amirhossein_eidy)\
**Replies:** 6\
**Last updated:** [June 11, 2023, 6:54am UTC](https://discuss.elastic.co/t/how-to-add-size-mapping-to-index-template-in-elasticsearch/335432 "2023-06-11T06:54:38Z")

</div>

Hi friends I have installed size mapping plugin and I added it to Kibana meta fields too I could successfully enable "\_size" in Elasticsearch via bellow command and see the result in kibana PUT logstash-2023-06-06 { …

---

## [Convert 2 nodes with roles \[data\] to \[data\_hot, data\_content\] and \[warm\]](https://discuss.elastic.co/t/convert-2-nodes-with-roles-data-to-data-hot-data-content-and-warm/335685)

<div class="topic-metadata">

**Author:** [@kaismax](https://discuss.elastic.co/u/kaismax)\
**Replies:** 1\
**Last updated:** [June 11, 2023, 2:51am UTC](https://discuss.elastic.co/t/convert-2-nodes-with-roles-data-to-data-hot-data-content-and-warm/335685 "2023-06-11T02:51:26Z")

</div>

Salut, Elastic Fulks My production cluster is set up as follows: 1 master node two data nodes \[data\] 1 coordinator I want to convert the 2 data nodes to first one to \[data\_content,data\_hot\]. second one to \[data\_war…

---

## [How to filter against a wildcard name of a field?](https://discuss.elastic.co/t/how-to-filter-against-a-wildcard-name-of-a-field/335693)

<div class="topic-metadata">

**Author:** [@Wpq](https://discuss.elastic.co/u/Wpq)\
**Replies:** 2\
**Last updated:** [June 10, 2023, 7:54pm UTC](https://discuss.elastic.co/t/how-to-filter-against-a-wildcard-name-of-a-field/335693 "2023-06-10T19:54:31Z")

</div>

I have documents that have fields such as vulns.something\_1.a vulns.something\_1.b the element something\_1 may change between documents some documents have the vulns entries, and some do not. My problem: I would like …

---

## [How to add hostname to logs from syslog or snmp source if they don't include only IP, no hostname](https://discuss.elastic.co/t/how-to-add-hostname-to-logs-from-syslog-or-snmp-source-if-they-dont-include-only-ip-no-hostname/335691)

<div class="topic-metadata">

**Author:** [@PackElend](https://discuss.elastic.co/u/PackElend)\
**Replies:** 2\
**Last updated:** [June 10, 2023, 2:54pm UTC](https://discuss.elastic.co/t/how-to-add-hostname-to-logs-from-syslog-or-snmp-source-if-they-dont-include-only-ip-no-hostname/335691 "2023-06-10T14:54:40Z")

</div>

Hello, I'm aware of How to add hostname to logs that normally do not contain hostname? but that is not applicable to my case. My router's firewall sends syslog message but they only contain the IP of the host causing t…

---

## [Elasticsearch in RKE in running status but not active](https://discuss.elastic.co/t/elasticsearch-in-rke-in-running-status-but-not-active/335655)

<div class="topic-metadata">

**Author:** [@Mhvrke](https://discuss.elastic.co/u/Mhvrke)\
**Replies:** 10\
**Last updated:** [June 10, 2023, 6:10am UTC](https://discuss.elastic.co/t/elasticsearch-in-rke-in-running-status-but-not-active/335655 "2023-06-10T06:10:38Z")

</div>

Hi! I need help with the following escenario: I’m running Elasticsearch in cluster mode in 3 worker nodes in RKE. Suddenly stopped from working and Kibana went down as Elasticsearch presents 503 error service unavailable…

---

## [Setting multinode elk cluster](https://discuss.elastic.co/t/setting-multinode-elk-cluster/335165)

<div class="topic-metadata">

**Author:** [@rajeshri](https://discuss.elastic.co/u/rajeshri)\
**Replies:** 2\
**Last updated:** [June 10, 2023, 6:05am UTC](https://discuss.elastic.co/t/setting-multinode-elk-cluster/335165 "2023-06-10T06:05:25Z")

</div>

cluster.name: my-cluster node.name: master-1 path.data: /var/lib/elasticsearch path.logs: /var/log/elasticsearch network.host: 172.31.82.55 http.port: 9200 discovery.seed\_hosts: \["172.31.82.55", "172.31.86.217"\] c…

---

## [How to add \_size mapping to index legacy template in elasticsearch?](https://discuss.elastic.co/t/how-to-add-size-mapping-to-index-legacy-template-in-elasticsearch/335672)

<div class="topic-metadata">

**Author:** [@Amirhossein\_eidy](https://discuss.elastic.co/u/Amirhossein_eidy)\
**Replies:** 1\
**Last updated:** [June 10, 2023, 5:16am UTC](https://discuss.elastic.co/t/how-to-add-size-mapping-to-index-legacy-template-in-elasticsearch/335672 "2023-06-10T05:16:38Z")

</div>

Hi friends I have installed size mapping plugin and I added it to Kibana meta fields too I could successfully enable "\_size" in Elasticsearch via bellow command and see the result in kibana PUT logstash-2023-06-06 { …

---

## [Elastic Store Data](https://discuss.elastic.co/t/elastic-store-data/335624)

<div class="topic-metadata">

**Author:** [@Suleman\_Ahmed](https://discuss.elastic.co/u/Suleman_Ahmed)\
**Replies:** 1\
**Last updated:** [June 9, 2023, 10:49pm UTC](https://discuss.elastic.co/t/elastic-store-data/335624 "2023-06-09T22:49:25Z")

</div>

Hello! I am new to elastic and wanted to know that Elastic store data in indexes or in text? Will be greateful if refer to any documentation link. Thanks Suleman

---

## [ElasticSearch returns "index not found error" for an index that exists](https://discuss.elastic.co/t/elasticsearch-returns-index-not-found-error-for-an-index-that-exists/335658)

<div class="topic-metadata">

**Author:** [@RA31](https://discuss.elastic.co/u/RA31)\
**Replies:** 1\
**Last updated:** [June 9, 2023, 9:08pm UTC](https://discuss.elastic.co/t/elasticsearch-returns-index-not-found-error-for-an-index-that-exists/335658 "2023-06-09T21:08:53Z")

</div>

I have an index pattern "barney", which shows on Kibana Management screen and on Discover. But when I hit the \_cat/indices API, it does not show the index pattern in the list of indices returned. When triggering barney/…

---

## [Use of PHP overloads](https://discuss.elastic.co/t/use-of-php-overloads/335653)

<div class="topic-metadata">

**Author:** [@Marcelo\_Saldanha](https://discuss.elastic.co/u/Marcelo_Saldanha)\
**Replies:** 0\
**Last updated:** [June 9, 2023, 6:59pm UTC](https://discuss.elastic.co/t/use-of-php-overloads/335653 "2023-06-09T18:59:07Z")

</div>

Could you help me? Since the 06/01 I have my website being crashed by PHP load, and generates the following errors: Elasticsearch\\Common\\Exceptions\\Missing404Exception: {"error":{"root\_cause":\[{"type":"illegal\_argume…

---

## [Document insertion not showing in Kibana](https://discuss.elastic.co/t/document-insertion-not-showing-in-kibana/335640)

<div class="topic-metadata">

**Author:** [@John\_Connolly](https://discuss.elastic.co/u/John_Connolly)\
**Replies:** 2\
**Last updated:** [June 9, 2023, 5:19pm UTC](https://discuss.elastic.co/t/document-insertion-not-showing-in-kibana/335640 "2023-06-09T17:19:33Z")

</div>

I inherited an Elasticsearch instance that is on version 6.3. I am able to insert data into it and retrieve this data using the \_search endpoint. When I go into Kibana and try to view this data though it is not able to s…

---

## [Issue with Range query using hour\_minute format](https://discuss.elastic.co/t/issue-with-range-query-using-hour-minute-format/335567)

<div class="topic-metadata">

**Author:** [@Daniel\_Scott](https://discuss.elastic.co/u/Daniel_Scott)\
**Replies:** 4\
**Last updated:** [June 9, 2023, 3:33pm UTC](https://discuss.elastic.co/t/issue-with-range-query-using-hour-minute-format/335567 "2023-06-09T15:33:52Z")

</div>

I'm having issue using the range query with the various time formats. Here is my query in question: { "\_source": \["created\_on"\], "fields": \[{ "field": "created\_on", "format": "hour\_minute" }\], "query": { "rang…

---

## [Runninning two configs in parallel without conflict with schedule](https://discuss.elastic.co/t/runninning-two-configs-in-parallel-without-conflict-with-schedule/335575)

<div class="topic-metadata">

**Author:** [@geothomas](https://discuss.elastic.co/u/geothomas)\
**Replies:** 3\
**Last updated:** [June 9, 2023, 3:19pm UTC](https://discuss.elastic.co/t/runninning-two-configs-in-parallel-without-conflict-with-schedule/335575 "2023-06-09T15:19:55Z")

</div>

I am trying to create elasticsearch index from oracle table. I have two configs, one delta.conf \*input {\* \* jdbc\* \*{\* \* jdbc\_driver\_library =\> "\<path\>/ojdbc10.jar"\* \* jdbc\_driver\_class =\> "Java::oracle.jdbc.dri…

---

## [Sending logs to syslog using logstash](https://discuss.elastic.co/t/sending-logs-to-syslog-using-logstash/334952)

<div class="topic-metadata">

**Author:** [@mariya](https://discuss.elastic.co/u/mariya)\
**Replies:** 16\
**Last updated:** [June 9, 2023, 2:43pm UTC](https://discuss.elastic.co/t/sending-logs-to-syslog-using-logstash/334952 "2023-06-09T14:43:43Z")

</div>

I installed winlogbeat and Logstash on my WInodows and I want to send logs to Logstash that will forward the logs to pfSense,I mean using Logstash as an aggregator with the logstash-output-tcp to send events to Syslog. a…

---

## [Elastic APM agent not instrumenting on simple Kafka producer](https://discuss.elastic.co/t/elastic-apm-agent-not-instrumenting-on-simple-kafka-producer/335641)

<div class="topic-metadata">

**Author:** [@sangramreddy](https://discuss.elastic.co/u/sangramreddy)\
**Replies:** 0\
**Last updated:** [June 9, 2023, 2:29pm UTC](https://discuss.elastic.co/t/elastic-apm-agent-not-instrumenting-on-simple-kafka-producer/335641 "2023-06-09T14:29:42Z")

</div>

We are trying Elastic APM in our org. Our apps are all backend Java communicated over Kafka. We noticed that the out of the box instrumentation is not properly working. So we created 3 basic java spring boot apps which…

---

## [Does "filebeat setup -e" need to be run every time I enable a module, or only once for all modules?](https://discuss.elastic.co/t/does-filebeat-setup-e-need-to-be-run-every-time-i-enable-a-module-or-only-once-for-all-modules/335557)

<div class="topic-metadata">

**Author:** [@andrew.klaassen](https://discuss.elastic.co/u/andrew.klaassen)\
**Replies:** 2\
**Last updated:** [June 9, 2023, 2:25pm UTC](https://discuss.elastic.co/t/does-filebeat-setup-e-need-to-be-run-every-time-i-enable-a-module-or-only-once-for-all-modules/335557 "2023-06-09T14:25:22Z")

</div>

So far I've been running "filebeat setup -e" every time I enable a new filebeat module. However, looking at its output, it seems to be setting stuff up for all of my modules, even the disabled ones. Do I need to run "f…

[Previous page](https://discuss.elastic.co/tag/none.md?no_tags=true&page=361)

[Next page](https://discuss.elastic.co/tag/none.md?no_tags=true&page=363)
