# \#none

**URL:** https://discuss.elastic.co/tag/none.md?no_tags=true&page=365

[Latest](https://discuss.elastic.co/latest.md) · [Categories](https://discuss.elastic.co/categories.md) · [Tags](https://discuss.elastic.co/tags.md)

**Page:** 366

---

## [How to stop index from getting throttled?](https://discuss.elastic.co/t/how-to-stop-index-from-getting-throttled/334923)

<div class="topic-metadata">

**Author:** [@hjazz6](https://discuss.elastic.co/u/hjazz6)\
**Replies:** 18\
**Last updated:** [June 7, 2023, 3:26am UTC](https://discuss.elastic.co/t/how-to-stop-index-from-getting-throttled/334923 "2023-06-07T03:26:32Z")

</div>

Hi, I am ingesting netflow data into my ES 8.3.3 node at a very high rate. As I increase the ingest to ES where the index rate is about 30+K/s, I started to get the messages below: \[INFO\] \[o.e.i.e.I.EngineMergeSchedule…

---

## [Elastic agent](https://discuss.elastic.co/t/elastic-agent/335353)

<div class="topic-metadata">

**Author:** [@kafikone](https://discuss.elastic.co/u/kafikone)\
**Replies:** 1\
**Last updated:** [June 6, 2023, 11:27pm UTC](https://discuss.elastic.co/t/elastic-agent/335353 "2023-06-06T23:27:29Z")

</div>

J'ai deployé elasticsearch,kibana et logstash sur une machine virtuel CentOS 7, tout fonctionne correctement. puis j'ai créé un serveur fleet et installé un agent elastic sur une Vm windows 11. Le satatut de mon agent es…

---

## [Elastic agent](https://discuss.elastic.co/t/elastic-agent/335367)

<div class="topic-metadata">

**Author:** [@kafikone](https://discuss.elastic.co/u/kafikone)\
**Replies:** 0\
**Last updated:** [June 6, 2023, 3:02pm UTC](https://discuss.elastic.co/t/elastic-agent/335367 "2023-06-06T15:02:12Z")

</div>

J'ai deployé elasticsearch,kibana et logstash sur une machine virtuel CentOS 7, tout fonctionne correctement. puis j'ai créé un serveur fleet et installé un agent elastic sur une Vm windows 11. Le satatut de mon agent es…

---

## [Show only results that are relevent to my shopping history](https://discuss.elastic.co/t/show-only-results-that-are-relevent-to-my-shopping-history/333149)

<div class="topic-metadata">

**Author:** [@searchwithme](https://discuss.elastic.co/u/searchwithme)\
**Replies:** 1\
**Last updated:** [June 6, 2023, 11:05pm UTC](https://discuss.elastic.co/t/show-only-results-that-are-relevent-to-my-shopping-history/333149 "2023-06-06T23:05:38Z")

</div>

I want to understand if elasticsearch + knn could be used to accomplish this ask: a search on an item should only show relevent results with my shopping history. eg) search on dress should only show red or black or full…

---

## [Logstash not pulling data fast enough from Kafka](https://discuss.elastic.co/t/logstash-not-pulling-data-fast-enough-from-kafka/334377)

<div class="topic-metadata">

**Author:** [@Francisco\_Yanez](https://discuss.elastic.co/u/Francisco_Yanez)\
**Replies:** 3\
**Last updated:** [June 6, 2023, 10:43pm UTC](https://discuss.elastic.co/t/logstash-not-pulling-data-fast-enough-from-kafka/334377 "2023-06-06T22:43:48Z")

</div>

I have a huge problem. My kafka is on a different DC and we are using logstash to pull data. Our Elastic stack is running in kubernetes but our data is getting pulled very slow. How can I optimize logstash to pull data f…

---

## [Unable to see the "Available fields column" in the logs forwarding for Devbyok cluster](https://discuss.elastic.co/t/unable-to-see-the-available-fields-column-in-the-logs-forwarding-for-devbyok-cluster/334807)

<div class="topic-metadata">

**Author:** [@subagh](https://discuss.elastic.co/u/subagh)\
**Replies:** 3\
**Last updated:** [June 6, 2023, 10:15pm UTC](https://discuss.elastic.co/t/unable-to-see-the-available-fields-column-in-the-logs-forwarding-for-devbyok-cluster/334807 "2023-06-06T22:15:09Z")

</div>

Pic 1 - Does not shows any available fields in Dashboard Can anyone please tell me why I cannot see the relevant "string fields" tab to select options from DevByok cluster but with similar configuration, I am able to se…

---

## [How to "join" two different types of documents on the closest value of a common integer key](https://discuss.elastic.co/t/how-to-join-two-different-types-of-documents-on-the-closest-value-of-a-common-integer-key/333226)

<div class="topic-metadata">

**Author:** [@Mathemaphysics](https://discuss.elastic.co/u/Mathemaphysics)\
**Replies:** 3\
**Last updated:** [June 6, 2023, 9:27pm UTC](https://discuss.elastic.co/t/how-to-join-two-different-types-of-documents-on-the-closest-value-of-a-common-integer-key/333226 "2023-06-06T21:27:32Z")

</div>

I have a problem. I've inherited legacy code for which ELK stack is now being used to capture and detect problems. Logstash + Filebeat are being used and an index template is being used to correctly map WGS84 points. I …

---

## [Palo Alto Networks - Logstash \> Elastic \> Kibana](https://discuss.elastic.co/t/palo-alto-networks-logstash-elastic-kibana/335380)

<div class="topic-metadata">

**Author:** [@thunt](https://discuss.elastic.co/u/thunt)\
**Replies:** 7\
**Last updated:** [June 6, 2023, 9:16pm UTC](https://discuss.elastic.co/t/palo-alto-networks-logstash-elastic-kibana/335380 "2023-06-06T21:16:01Z")

</div>

Hello Everyone - Hoping I have a simple solution. Testing out Elastic Stack with Palo Alto syslogs, and running into issues with GeoIP's and combining the lon/lat to use Maps in Kibana. Not sure what else needs to be d…

---

## [Grok multi-line mode](https://discuss.elastic.co/t/grok-multi-line-mode/335101)

<div class="topic-metadata">

**Author:** [@M\_D](https://discuss.elastic.co/u/M_D)\
**Replies:** 7\
**Last updated:** [June 6, 2023, 7:44pm UTC](https://discuss.elastic.co/t/grok-multi-line-mode/335101 "2023-06-06T19:44:27Z")

</div>

I am using (?ms) in my grok filter, but got an error (see RegexpError: undefined). What should be the right way to lookup multiple lines using grok? in regular regex i amd doing (?sm)(?\<starttime\>\[0-9\]{4}-\[0-9\]{2}-\[0-9…

---

## [Returning count of buckets from aggregation terms search](https://discuss.elastic.co/t/returning-count-of-buckets-from-aggregation-terms-search/335373)

<div class="topic-metadata">

**Author:** [@pocketcolin](https://discuss.elastic.co/u/pocketcolin)\
**Replies:** 0\
**Last updated:** [June 6, 2023, 6:48pm UTC](https://discuss.elastic.co/t/returning-count-of-buckets-from-aggregation-terms-search/335373 "2023-06-06T18:48:17Z")

</div>

Before anyone suggests it, I am trying to use the terms aggregation with a very large size value to get a more exact number as opposed to using cardinality. I realize it's less efficient but I'm only searching around 75k…

---

## [Log4j2 vulnerability mitigation - JndiLookup Removal](https://discuss.elastic.co/t/log4j2-vulnerability-mitigation-jndilookup-removal/335356)

<div class="topic-metadata">

**Author:** [@JosephAnis](https://discuss.elastic.co/u/JosephAnis)\
**Replies:** 1\
**Last updated:** [June 6, 2023, 6:43pm UTC](https://discuss.elastic.co/t/log4j2-vulnerability-mitigation-jndilookup-removal/335356 "2023-06-06T18:43:49Z")

</div>

Hi All, We are working on mitigating the Log4j2 vulnerability by removing the JndiLookup class as described here: We are using version 7.9.2 for all ELK components and currently we can't upgrade to newer version. My …

---

## [Cluster takes too long to apply cluster state](https://discuss.elastic.co/t/cluster-takes-too-long-to-apply-cluster-state/328407)

<div class="topic-metadata">

**Author:** [@Vadym](https://discuss.elastic.co/u/Vadym)\
**Replies:** 26\
**Last updated:** [June 6, 2023, 6:14pm UTC](https://discuss.elastic.co/t/cluster-takes-too-long-to-apply-cluster-state/328407 "2023-06-06T18:14:51Z")

</div>

Hi guys, We have some 1Tb+ indices and it takes more than a minute to drop these indices when we rotate them. During the deletion cluster takes too long to apply cluster state and master nodes start to kick data nodes o…

---

## [How do you set up the user account to run Elasticsearch service on Linux?](https://discuss.elastic.co/t/how-do-you-set-up-the-user-account-to-run-elasticsearch-service-on-linux/335368)

<div class="topic-metadata">

**Author:** [@Latitude](https://discuss.elastic.co/u/Latitude)\
**Replies:** 5\
**Last updated:** [June 6, 2023, 5:22pm UTC](https://discuss.elastic.co/t/how-do-you-set-up-the-user-account-to-run-elasticsearch-service-on-linux/335368 "2023-06-06T17:22:28Z")

</div>

Hello, I'm new to my organization and to Elasticsearch. I'm the new server administrator for Liferay 7.4 DXP which uses Elasticsearch 7.17.x. I'm developing our migration procedure as we're migrating to Liferay 7.4 DXP …

---

## [Logstash unable to collect logs from filebeat due to protocol mismatch](https://discuss.elastic.co/t/logstash-unable-to-collect-logs-from-filebeat-due-to-protocol-mismatch/335269)

<div class="topic-metadata">

**Author:** [@Chel\_Db](https://discuss.elastic.co/u/Chel_Db)\
**Replies:** 16\
**Last updated:** [June 6, 2023, 4:31pm UTC](https://discuss.elastic.co/t/logstash-unable-to-collect-logs-from-filebeat-due-to-protocol-mismatch/335269 "2023-06-06T16:31:33Z")

</div>

I've installed filebeat in our k8s following official elastic document (kubernetes/filebeat-kubernetes.yaml ) to collect logs of our microservices and push it to the Logstash which is installed in a different VM as a co…

---

## [Add custom field for action to teams webhook](https://discuss.elastic.co/t/add-custom-field-for-action-to-teams-webhook/334779)

<div class="topic-metadata">

**Author:** [@fontexD](https://discuss.elastic.co/u/fontexD)\
**Replies:** 3\
**Last updated:** [June 6, 2023, 12:58pm UTC](https://discuss.elastic.co/t/add-custom-field-for-action-to-teams-webhook/334779 "2023-06-06T12:58:02Z")

</div>

im trying to add a custom field from the table of the event but it dosent pass the value into the teams webhook

---

## [Best Practice: Update metadata on larger documents](https://discuss.elastic.co/t/best-practice-update-metadata-on-larger-documents/335311)

<div class="topic-metadata">

**Author:** [@Hiketas](https://discuss.elastic.co/u/Hiketas)\
**Replies:** 5\
**Last updated:** [June 6, 2023, 12:21pm UTC](https://discuss.elastic.co/t/best-practice-update-metadata-on-larger-documents/335311 "2023-06-06T12:21:51Z")

</div>

I have a question about best practice in the following scenario: I have documents with some meta fields among others with a full text field which can be up to 10 MB in size. We currently do not use parent/child relation…

---

## [Displaying Latest Image with filter from Log Message](https://discuss.elastic.co/t/displaying-latest-image-with-filter-from-log-message/335160)

<div class="topic-metadata">

**Author:** [@witwit](https://discuss.elastic.co/u/witwit)\
**Replies:** 4\
**Last updated:** [June 6, 2023, 11:19am UTC](https://discuss.elastic.co/t/displaying-latest-image-with-filter-from-log-message/335160 "2023-06-06T11:19:25Z")

</div>

Hi everyone. So currently, I'm getting logs from various services. I manage to tag these services as a field when it's ingested into elasticsearch via logstash. I'm currently stump with one part where i'm trying to disp…

---

## [Hide the time filter in dashboards](https://discuss.elastic.co/t/hide-the-time-filter-in-dashboards/335321)

<div class="topic-metadata">

**Author:** [@Alice\_Ionescu](https://discuss.elastic.co/u/Alice_Ionescu)\
**Replies:** 2\
**Last updated:** [June 6, 2023, 11:08am UTC](https://discuss.elastic.co/t/hide-the-time-filter-in-dashboards/335321 "2023-06-06T11:08:51Z")

</div>

Hello, I have an index pattern for which I did not set a time field. I created a visualization based on this pattern index, and added it to a dashboard. In the dashboard I still have the time picker. How can I make it…

---

## [Kibana Version in Hindi Language](https://discuss.elastic.co/t/kibana-version-in-hindi-language/335277)

<div class="topic-metadata">

**Author:** [@Sandeep\_Raju](https://discuss.elastic.co/u/Sandeep_Raju)\
**Replies:** 1\
**Last updated:** [June 6, 2023, 10:59am UTC](https://discuss.elastic.co/t/kibana-version-in-hindi-language/335277 "2023-06-06T10:59:51Z")

</div>

Hi all, I want a Kibana version in Hindi language that can display everything in Hindi including Dashboard name, visualization Name, options etc. Any setting for language or Kibana version for Hindi language that I can…

---

## [Performance issue found : Upgade elasticsearch 7.8 to 7.17](https://discuss.elastic.co/t/performance-issue-found-upgade-elasticsearch-7-8-to-7-17/335324)

<div class="topic-metadata">

**Author:** [@Abhishek\_Tiwari1](https://discuss.elastic.co/u/Abhishek_Tiwari1)\
**Replies:** 0\
**Last updated:** [June 6, 2023, 10:53am UTC](https://discuss.elastic.co/t/performance-issue-found-upgade-elasticsearch-7-8-to-7-17/335324 "2023-06-06T10:53:22Z")

</div>

Hi Team, We are facing major performance issue after upgrade elasticsearch from 7.8 to 7.17 by rolling method. Our Query hits elasticsearch using java rest api(7.2.1). Perfomance degrade form 20ms to 300ms. I need to…

---

## [Show HTML Character Entities as symbols in Kibana](https://discuss.elastic.co/t/show-html-character-entities-as-symbols-in-kibana/335191)

<div class="topic-metadata">

**Author:** [@ddoroshenko](https://discuss.elastic.co/u/ddoroshenko)\
**Replies:** 4\
**Last updated:** [June 6, 2023, 10:43am UTC](https://discuss.elastic.co/t/show-html-character-entities-as-symbols-in-kibana/335191 "2023-06-06T10:43:38Z")

</div>

Hi, I have records in ES where symbols are presented as Character Entities. For example | as &#124; and a record could looks like bla&#124;bla&#124;bla. Is it posible in Kibana to show these entities as symbols, i.e. b…

---

## [Shuffle sorted documents](https://discuss.elastic.co/t/shuffle-sorted-documents/335255)

<div class="topic-metadata">

**Author:** [@Novel\_one](https://discuss.elastic.co/u/Novel_one)\
**Replies:** 3\
**Last updated:** [June 6, 2023, 10:10am UTC](https://discuss.elastic.co/t/shuffle-sorted-documents/335255 "2023-06-06T10:10:22Z")

</div>

Hi, I want to create a promotional box in my marketplace, with the top rated articles. I dont want always to be the same articles, so i want them be shuffled a little by multiplying the article avg rate by a random num…

---

## [Kibana cluster acces via F5 load balancer](https://discuss.elastic.co/t/kibana-cluster-acces-via-f5-load-balancer/335285)

<div class="topic-metadata">

**Author:** [@kannan2096](https://discuss.elastic.co/u/kannan2096)\
**Replies:** 1\
**Last updated:** [June 6, 2023, 9:31am UTC](https://discuss.elastic.co/t/kibana-cluster-acces-via-f5-load-balancer/335285 "2023-06-06T09:31:18Z")

</div>

Hi I'm new to ELK and I'm doing POC to implement ELK with cluster setup. With the basic cluster configuration of Elasticsearch(2nodes), the Kibana GUI working fine. But via F5 load balance URL it is not working. The log…

---

## [Running elastic search](https://discuss.elastic.co/t/running-elastic-search/335182)

<div class="topic-metadata">

**Author:** [@waqar\_jamali](https://discuss.elastic.co/u/waqar_jamali)\
**Replies:** 1\
**Last updated:** [June 6, 2023, 9:20am UTC](https://discuss.elastic.co/t/running-elastic-search/335182 "2023-06-06T09:20:34Z")

</div>

How can I run elasticsearch using python client on google colab. I have a python code which is running on my machine. I want to run it on google colab or other notebook online platform. What setup or instruction I need f…

---

## [Single node yellow](https://discuss.elastic.co/t/single-node-yellow/335249)

<div class="topic-metadata">

**Author:** [@decibel83](https://discuss.elastic.co/u/decibel83)\
**Replies:** 2\
**Last updated:** [June 6, 2023, 8:38am UTC](https://discuss.elastic.co/t/single-node-yellow/335249 "2023-06-06T08:38:07Z")

</div>

Hi have a single node elastic cluster which is yellow: GET /\_cluster/health: { "cluster\_name": "log", "status": "yellow", "timed\_out": false, "number\_of\_nodes": 1, "number\_of\_data\_nodes": 1, "act…

---

## [Log4j Vulnerability Elasticsearch 7.8.0](https://discuss.elastic.co/t/log4j-vulnerability-elasticsearch-7-8-0/333035)

<div class="topic-metadata">

**Author:** [@Faisal\_Umer](https://discuss.elastic.co/u/Faisal_Umer)\
**Replies:** 7\
**Last updated:** [June 6, 2023, 8:08am UTC](https://discuss.elastic.co/t/log4j-vulnerability-elasticsearch-7-8-0/333035 "2023-06-06T08:08:01Z")

</div>

We have Elasticsearch 7.8.0 cluster which has CVE-2021-44228. Can we somehow patch it without upgrading the Elasticsearch version? If yes, can you please share any relevant thread or documentation?

---

## [How to get docs in aggregated format in ElasticSearch aggregation query?](https://discuss.elastic.co/t/how-to-get-docs-in-aggregated-format-in-elasticsearch-aggregation-query/335292)

<div class="topic-metadata">

**Author:** [@maulik\_trapasiya](https://discuss.elastic.co/u/maulik_trapasiya)\
**Replies:** 0\
**Last updated:** [June 6, 2023, 7:27am UTC](https://discuss.elastic.co/t/how-to-get-docs-in-aggregated-format-in-elasticsearch-aggregation-query/335292 "2023-06-06T07:27:25Z")

</div>

My query { "aggs": { "distinct\_colours": { "terms": { "field": "colour" } } } } Required Result: { "took" : 2037, "timed\_out" : false, "\_shards" : { "total" : 1, "successf…

---

## [TSVB - Top N - Item URL: keep time interval when link to other dashboard](https://discuss.elastic.co/t/tsvb-top-n-item-url-keep-time-interval-when-link-to-other-dashboard/335151)

<div class="topic-metadata">

**Author:** [@Ofir\_Edi](https://discuss.elastic.co/u/Ofir_Edi)\
**Replies:** 2\
**Last updated:** [June 6, 2023, 7:04am UTC](https://discuss.elastic.co/t/tsvb-top-n-item-url-keep-time-interval-when-link-to-other-dashboard/335151 "2023-06-06T07:04:29Z")

</div>

Hi, This is a duplicate of this thread which was not answered. I have TSVB top n visualization of host names and i'm using item URL feature to drilldown to more specific dashboard with the {{key}} place holder. However…

---

## [How to use mapper size pluging?](https://discuss.elastic.co/t/how-to-use-mapper-size-pluging/335131)

<div class="topic-metadata">

**Author:** [@Amirhossein\_eidy](https://discuss.elastic.co/u/Amirhossein_eidy)\
**Replies:** 2\
**Last updated:** [June 6, 2023, 5:12am UTC](https://discuss.elastic.co/t/how-to-use-mapper-size-pluging/335131 "2023-06-06T05:12:24Z")

</div>

Hi folks I want to find the largest documents in my indices and I have installed the mapper size plugin and added the field to index as it explained I have two questions now how to add it to index pattern in kibana? …

---

## [How to calculate percentage of a field over all documents present in index](https://discuss.elastic.co/t/how-to-calculate-percentage-of-a-field-over-all-documents-present-in-index/334544)

<div class="topic-metadata">

**Author:** [@Amit\_Charkha](https://discuss.elastic.co/u/Amit_Charkha)\
**Replies:** 5\
**Last updated:** [June 6, 2023, 4:54am UTC](https://discuss.elastic.co/t/how-to-calculate-percentage-of-a-field-over-all-documents-present-in-index/334544 "2023-06-06T04:54:48Z")

</div>

how to calculate percentage of a field log\_count over all documents present in index.

[Previous page](https://discuss.elastic.co/tag/none.md?no_tags=true&page=364)

[Next page](https://discuss.elastic.co/tag/none.md?no_tags=true&page=366)
