# \#none

**URL:** https://discuss.elastic.co/tag/none.md?no_tags=true&page=371

[Latest](https://discuss.elastic.co/latest.md) · [Categories](https://discuss.elastic.co/categories.md) · [Tags](https://discuss.elastic.co/tags.md)

**Page:** 372

---

## [How to group similar log messages and show in bar chart](https://discuss.elastic.co/t/how-to-group-similar-log-messages-and-show-in-bar-chart/333586)

<div class="topic-metadata">

**Author:** [@balaji-khandekar-osv](https://discuss.elastic.co/u/balaji-khandekar-osv)\
**Replies:** 1\
**Last updated:** [May 29, 2023, 4:46pm UTC](https://discuss.elastic.co/t/how-to-group-similar-log-messages-and-show-in-bar-chart/333586 "2023-05-29T16:46:19Z")

</div>

Hello, I wanted to group the similar messages and display them in chart. The message format is not unique, its slightly change every time. below is the sample message: "NO TRANSLATION AVAILABLE From:XYZ Code:ABC To:O…

---

## [Logstash - Creating new field by taking first word from an other field](https://discuss.elastic.co/t/logstash-creating-new-field-by-taking-first-word-from-an-other-field/334536)

<div class="topic-metadata">

**Author:** [@Carlos\_T](https://discuss.elastic.co/u/Carlos_T)\
**Replies:** 4\
**Last updated:** [May 29, 2023, 4:38pm UTC](https://discuss.elastic.co/t/logstash-creating-new-field-by-taking-first-word-from-an-other-field/334536 "2023-05-29T16:38:32Z")

</div>

Hi all. It must be something plenty of people has answered but I can´t find it :slight\_smile: I've got a pipeline reading a log with the following structure: \[12/May/2022:19:04:50 +0200\] 192.168.0.2 server2 "DROP: Est…

---

## [Date format problem with Kibana ingestion](https://discuss.elastic.co/t/date-format-problem-with-kibana-ingestion/333357)

<div class="topic-metadata">

**Author:** [@Phildefer](https://discuss.elastic.co/u/Phildefer)\
**Replies:** 1\
**Last updated:** [May 29, 2023, 3:41pm UTC](https://discuss.elastic.co/t/date-format-problem-with-kibana-ingestion/333357 "2023-05-29T15:41:07Z")

</div>

Hi, I have a CSV file with a field date 5in french) like this : samedi 13 mai 2023 and I don't find any ISO format in Kibana to make this field recognizable as a date field during the ingestion. If you have a solution…

---

## [Elasticsearch Query: Array field length mismatch](https://discuss.elastic.co/t/elasticsearch-query-array-field-length-mismatch/334551)

<div class="topic-metadata">

**Author:** [@kusumakarb](https://discuss.elastic.co/u/kusumakarb)\
**Replies:** 1\
**Last updated:** [May 29, 2023, 2:04pm UTC](https://discuss.elastic.co/t/elasticsearch-query-array-field-length-mismatch/334551 "2023-05-29T14:04:34Z")

</div>

Trying out the following query to get the values of 2 array fields and their corresponding lengths, the array values and the lengths don't match Query: GET my\_index/\_search { "\_source": \["file\_types", "link\_to\_file"\]…

---

## [It takes a long time to query the keyword field](https://discuss.elastic.co/t/it-takes-a-long-time-to-query-the-keyword-field/333297)

<div class="topic-metadata">

**Author:** [@Ruwi](https://discuss.elastic.co/u/Ruwi)\
**Replies:** 3\
**Last updated:** [May 29, 2023, 1:03pm UTC](https://discuss.elastic.co/t/it-takes-a-long-time-to-query-the-keyword-field/333297 "2023-05-29T13:03:26Z")

</div>

Hi, I have a question regarding query performance. What is the difference between querying the normal field and querying the keyword field? I did a test. The data types of the fields I am querying are as follows. …

---

## [Not able to get indices for all services in kibana](https://discuss.elastic.co/t/not-able-to-get-indices-for-all-services-in-kibana/334563)

<div class="topic-metadata">

**Author:** [@kirankumarb](https://discuss.elastic.co/u/kirankumarb)\
**Replies:** 1\
**Last updated:** [May 29, 2023, 9:14am UTC](https://discuss.elastic.co/t/not-able-to-get-indices-for-all-services-in-kibana/334563 "2023-05-29T09:14:50Z")

</div>

I am not getting indices for most of services, but unable to get indices for few services. So I am unable to create index patterns. Please help on this

---

## [Filebeat autodiscover for Kubernetes uses incorrect log path](https://discuss.elastic.co/t/filebeat-autodiscover-for-kubernetes-uses-incorrect-log-path/317635)

<div class="topic-metadata">

**Author:** [@nlang](https://discuss.elastic.co/u/nlang)\
**Replies:** 2\
**Last updated:** [May 29, 2023, 8:05am UTC](https://discuss.elastic.co/t/filebeat-autodiscover-for-kubernetes-uses-incorrect-log-path/317635 "2023-05-29T08:05:04Z")

</div>

I'm trying to configure filebeat and my pods in kubernetes to use auto disscover and hints. I found this previous topic: Filebeat autodiscover for Kubernetes uses inconsistent log files path by default but it's now close…

---

## [Setting max\_analyzed\_offset permanently for an index](https://discuss.elastic.co/t/setting-max-analyzed-offset-permanently-for-an-index/334470)

<div class="topic-metadata">

**Author:** [@zaeemmasood](https://discuss.elastic.co/u/zaeemmasood)\
**Replies:** 2\
**Last updated:** [May 29, 2023, 7:48am UTC](https://discuss.elastic.co/t/setting-max-analyzed-offset-permanently-for-an-index/334470 "2023-05-29T07:48:56Z")

</div>

Hi All, We are using ELK stack 7.13.2 I came across an error while displaying an index in dashboard as follows: The length \[2134324\] of field \[additionalInfo\] in doc\[100496\]/index\[370844-2023.05.24\] exceeds the \[index…

---

## [How to make elasticdump faster](https://discuss.elastic.co/t/how-to-make-elasticdump-faster/334380)

<div class="topic-metadata">

**Author:** [@sonujatav35](https://discuss.elastic.co/u/sonujatav35)\
**Replies:** 4\
**Last updated:** [May 29, 2023, 7:24am UTC](https://discuss.elastic.co/t/how-to-make-elasticdump-faster/334380 "2023-05-29T07:24:05Z")

</div>

Hi Elastic Community members, I would like to know, Is there any way to speed up the elastic-dump. I need to migrate data from one elasticsearch to another elasticsearch cluster. I noticed for 1GB of data is taking aro…

---

## [ElasticSearch - search\_after pagination sort](https://discuss.elastic.co/t/elasticsearch-search-after-pagination-sort/334502)

<div class="topic-metadata">

**Author:** [@VJ052023](https://discuss.elastic.co/u/VJ052023)\
**Replies:** 4\
**Last updated:** [May 29, 2023, 4:52am UTC](https://discuss.elastic.co/t/elasticsearch-search-after-pagination-sort/334502 "2023-05-29T04:52:32Z")

</div>

I am trying to fetch results from Elasticsearch API using search\_after for pagination. However, in order to iterate to the subsequent data I am using a sort in the request Body of the API call as shown below "sort": \[ …

---

## [Disable \_source field from indexing](https://discuss.elastic.co/t/disable-source-field-from-indexing/334486)

<div class="topic-metadata">

**Author:** [@Mhag](https://discuss.elastic.co/u/Mhag)\
**Replies:** 6\
**Last updated:** [May 29, 2023, 2:47am UTC](https://discuss.elastic.co/t/disable-source-field-from-indexing/334486 "2023-05-29T02:47:27Z")

</div>

Hi, To reduce the size of an indice I decide not to store \_source field in elasticsearch, but I got this error when I try to diable it. PUT /myindice/\_mapping { "properties": { "\_source": { "enabled": fals…

---

## [How do i create a dashboard and get a url to the dashboard using REST API](https://discuss.elastic.co/t/how-do-i-create-a-dashboard-and-get-a-url-to-the-dashboard-using-rest-api/334056)

<div class="topic-metadata">

**Author:** [@Rishi\_Shukla](https://discuss.elastic.co/u/Rishi_Shukla)\
**Replies:** 1\
**Last updated:** [May 29, 2023, 1:42am UTC](https://discuss.elastic.co/t/how-do-i-create-a-dashboard-and-get-a-url-to-the-dashboard-using-rest-api/334056 "2023-05-29T01:42:32Z")

</div>

How do i create a dashboard and get a url to the dashboard using REST API. I am running v7.13.0 which i cannot upgrade in the near term.

---

## [How to print out the data in Kibana from AWS WAF?](https://discuss.elastic.co/t/how-to-print-out-the-data-in-kibana-from-aws-waf/334374)

<div class="topic-metadata">

**Author:** [@ecommd4wg](https://discuss.elastic.co/u/ecommd4wg)\
**Replies:** 3\
**Last updated:** [May 29, 2023, 12:05am UTC](https://discuss.elastic.co/t/how-to-print-out-the-data-in-kibana-from-aws-waf/334374 "2023-05-29T00:05:55Z")

</div>

n00b here. I have kibana in AWS with AWF data. I need to print out the fields and the data to see what is in them. Is there a default query to do this, that I can plug into the dev tools window? Thank you

---

## [Cannot run service elastic](https://discuss.elastic.co/t/cannot-run-service-elastic/334478)

<div class="topic-metadata">

**Author:** [@Wiwatsapon\_Lertworas](https://discuss.elastic.co/u/Wiwatsapon_Lertworas)\
**Replies:** 3\
**Last updated:** [May 28, 2023, 11:20pm UTC](https://discuss.elastic.co/t/cannot-run-service-elastic/334478 "2023-05-28T23:20:31Z")

</div>

This is my error on run sudo service elasticsearch start May 27 03:07:57 elk-stack systemd-entrypoint\[354840\]: Exception in thread "main" java.lang.NullPointerException: Cannot invoke "org.apache.logging.log4j.core.con…

---

## [Jaro Winkler algorithm in elasticsearch](https://discuss.elastic.co/t/jaro-winkler-algorithm-in-elasticsearch/334505)

<div class="topic-metadata">

**Author:** [@Bakhodur\_Karomatov](https://discuss.elastic.co/u/Bakhodur_Karomatov)\
**Replies:** 4\
**Last updated:** [May 28, 2023, 11:18pm UTC](https://discuss.elastic.co/t/jaro-winkler-algorithm-in-elasticsearch/334505 "2023-05-28T23:18:32Z")

</div>

can i use jaro winkler algorithm in elasticsearch?

---

## [Elasticsearch Kuromoji plugin](https://discuss.elastic.co/t/elasticsearch-kuromoji-plugin/334361)

<div class="topic-metadata">

**Author:** [@a4amann](https://discuss.elastic.co/u/a4amann)\
**Replies:** 0\
**Last updated:** [May 25, 2023, 6:25pm UTC](https://discuss.elastic.co/t/elasticsearch-kuromoji-plugin/334361 "2023-05-25T18:25:40Z")

</div>

What is the expected output when we run : PUT test { "settings": { "index": { "analysis": { "filter": { "kuromoji\_number": { "type": "kuromoji\_number" }, "ku…

---

## [What is timezone that schedule (configuration option in elasticsearch input logstash) is based on?](https://discuss.elastic.co/t/what-is-timezone-that-schedule-configuration-option-in-elasticsearch-input-logstash-is-based-on/334223)

<div class="topic-metadata">

**Author:** [@alex\_petrov](https://discuss.elastic.co/u/alex_petrov)\
**Replies:** 2\
**Last updated:** [May 28, 2023, 4:15pm UTC](https://discuss.elastic.co/t/what-is-timezone-that-schedule-configuration-option-in-elasticsearch-input-logstash-is-based-on/334223 "2023-05-28T16:15:04Z")

</div>

I have following configuration in my logstash pipeline, I want to schedule to run the query for specific hour every day (schedule =\> "\*/5 \* \* \* \*" already working) , but it doesn't work. I have a distributed environment …

---

## [How to pass variable from Logstash filter into ruby parameter](https://discuss.elastic.co/t/how-to-pass-variable-from-logstash-filter-into-ruby-parameter/334438)

<div class="topic-metadata">

**Author:** [@Jirka\_Liska](https://discuss.elastic.co/u/Jirka_Liska)\
**Replies:** 4\
**Last updated:** [May 28, 2023, 3:59pm UTC](https://discuss.elastic.co/t/how-to-pass-variable-from-logstash-filter-into-ruby-parameter/334438 "2023-05-28T15:59:27Z")

</div>

Hi I'm trying to create a variable which holds information from input file path. I'm able to do so for example for creating index in Kibana but I'm unable to pass this variable into ruby /plugin/ code. Anyone knows what…

---

## [Help restoring / recreating .security-7](https://discuss.elastic.co/t/help-restoring-recreating-security-7/334499)

<div class="topic-metadata">

**Author:** [@A.Hani](https://discuss.elastic.co/u/A.Hani)\
**Replies:** 12\
**Last updated:** [May 28, 2023, 2:31pm UTC](https://discuss.elastic.co/t/help-restoring-recreating-security-7/334499 "2023-05-28T14:31:39Z")

</div>

Hello, Faced an error where kibana failed to retrieve password hash for reserved user \[kibana\] at least one primary shard for the index .security-7 was missing. Followed the instructions provided here at https://discus…

---

## [How to display images stored per record in Kibana](https://discuss.elastic.co/t/how-to-display-images-stored-per-record-in-kibana/334487)

<div class="topic-metadata">

**Author:** [@damonmaria](https://discuss.elastic.co/u/damonmaria)\
**Replies:** 3\
**Last updated:** [May 28, 2023, 8:03am UTC](https://discuss.elastic.co/t/how-to-display-images-stored-per-record-in-kibana/334487 "2023-05-28T08:03:49Z")

</div>

Our records contain URLs to images (stored outside of ES). My goal is to be able to ad-hoc filter for records and then see all these images from the records. The best I've been able to achieve is switching from the Docu…

---

## [Can not find mongodb log in Discover](https://discuss.elastic.co/t/can-not-find-mongodb-log-in-discover/334202)

<div class="topic-metadata">

**Author:** [@miladghasemi](https://discuss.elastic.co/u/miladghasemi)\
**Replies:** 2\
**Last updated:** [May 27, 2023, 10:05pm UTC](https://discuss.elastic.co/t/can-not-find-mongodb-log-in-discover/334202 "2023-05-27T22:05:43Z")

</div>

Hi (sorry for my bad english) I'm enabled mongodb module in filebeat to send mongodb log into elasticsearch. Filebeat created dashboard, my log show in discover but when i want to search in Dicover,it not show \[event.o…

---

## [Most minimal logstash.yml possible?](https://discuss.elastic.co/t/most-minimal-logstash-yml-possible/334512)

<div class="topic-metadata">

**Author:** [@newmember](https://discuss.elastic.co/u/newmember)\
**Replies:** 1\
**Last updated:** [May 27, 2023, 9:37pm UTC](https://discuss.elastic.co/t/most-minimal-logstash-yml-possible/334512 "2023-05-27T21:37:20Z")

</div>

I would like to load all my inputs via the conf.d folder. What is most minimal logstash.yml fle I can have that will allow logstash to start and then load all the yml files in the conf.d folder? Current logstash.yml fi…

---

## [Understanding filters cache for filters nested inside should clause of parent boolean query](https://discuss.elastic.co/t/understanding-filters-cache-for-filters-nested-inside-should-clause-of-parent-boolean-query/334511)

<div class="topic-metadata">

**Author:** [@Sarthak\_Madaan](https://discuss.elastic.co/u/Sarthak_Madaan)\
**Replies:** 0\
**Last updated:** [May 27, 2023, 8:52pm UTC](https://discuss.elastic.co/t/understanding-filters-cache-for-filters-nested-inside-should-clause-of-parent-boolean-query/334511 "2023-05-27T20:52:39Z")

</div>

{ "from": 0, "size": 2, "timeout": "10ms", "query": { "bool": { "should": \[ { "bool": { "filter": \[ …

---

## [Observability machine learning use cases](https://discuss.elastic.co/t/observability-machine-learning-use-cases/334417)

<div class="topic-metadata">

**Author:** [@abu7midandev](https://discuss.elastic.co/u/abu7midandev)\
**Replies:** 1\
**Last updated:** [May 27, 2023, 7:16pm UTC](https://discuss.elastic.co/t/observability-machine-learning-use-cases/334417 "2023-05-27T19:16:10Z")

</div>

dears i hope all of you doing well i am new with elastic and i need support in some points i have built APM dashboard with elastic agent and monitor our services i didn't find any topics about how to use elastic ml i…

---

## [Logstash Split Message with Multiple Messages](https://discuss.elastic.co/t/logstash-split-message-with-multiple-messages/334466)

<div class="topic-metadata">

**Author:** [@balogan](https://discuss.elastic.co/u/balogan)\
**Replies:** 3\
**Last updated:** [May 27, 2023, 2:36pm UTC](https://discuss.elastic.co/t/logstash-split-message-with-multiple-messages/334466 "2023-05-27T14:36:39Z")

</div>

Logfile I need to ingest. You can see there are 3 separate messages under alerts. We need to split that up into 3 separate messages. { "@timestamp": "2023-05-23T18:15:30.537972Z", "alerts": \[ { "s…

---

## [Logstash aggregate and calculate the sum of counts](https://discuss.elastic.co/t/logstash-aggregate-and-calculate-the-sum-of-counts/334495)

<div class="topic-metadata">

**Author:** [@m3bgwad](https://discuss.elastic.co/u/m3bgwad)\
**Replies:** 0\
**Last updated:** [May 27, 2023, 10:20am UTC](https://discuss.elastic.co/t/logstash-aggregate-and-calculate-the-sum-of-counts/334495 "2023-05-27T10:20:07Z")

</div>

Hello All, I have a scenario, I need the expertise to support this, and thanks in advanced I have a statement running by the JDBC input plugin every 1 minute, so the results returned every 1 minute until if the result…

---

## [Kibana is not getting up](https://discuss.elastic.co/t/kibana-is-not-getting-up/334317)

<div class="topic-metadata">

**Author:** [@PRASHANT\_MEHTA](https://discuss.elastic.co/u/PRASHANT_MEHTA)\
**Replies:** 3\
**Last updated:** [May 26, 2023, 2:38pm UTC](https://discuss.elastic.co/t/kibana-is-not-getting-up/334317 "2023-05-26T14:38:25Z")

</div>

Hello All, I am trying to connect my elasticsearch hosted in aws cloud with kibana(on premise host). My elastic comes up properly but kibana is not getting up. always same message: Logs: {"service":{"node":{"roles…

---

## [Configpathloader no config files found in path= /etc/logstash/conf.d/\*.conf](https://discuss.elastic.co/t/configpathloader-no-config-files-found-in-path-etc-logstash-conf-d-conf/334465)

<div class="topic-metadata">

**Author:** [@Saud555](https://discuss.elastic.co/u/Saud555)\
**Replies:** 0\
**Last updated:** [May 26, 2023, 6:03pm UTC](https://discuss.elastic.co/t/configpathloader-no-config-files-found-in-path-etc-logstash-conf-d-conf/334465 "2023-05-26T18:03:54Z")

</div>

I am getting an error while running the logstash Error configpathloader no config files found in path= /etc/logstash/conf.d/\* I have logstash.yml and pipelines.yml in place and cross checked all the configuration. but…

---

## [Failed to install microsoft-sentinel-logstash-output-plugin , error execution expired](https://discuss.elastic.co/t/failed-to-install-microsoft-sentinel-logstash-output-plugin-error-execution-expired/331085)

<div class="topic-metadata">

**Author:** [@SAMY-ELK](https://discuss.elastic.co/u/SAMY-ELK)\
**Replies:** 2\
**Last updated:** [May 26, 2023, 5:54pm UTC](https://discuss.elastic.co/t/failed-to-install-microsoft-sentinel-logstash-output-plugin-error-execution-expired/331085 "2023-05-26T17:54:47Z")

</div>

Hi, I am unable to install the microsoft-sentinel-logstash-output-plugin on logstash server. I am running rhel7.9. I get the following error : ERROR: Something went wrong when installing install, microsoft-sentinel-lo…

---

## [Manipulation of Drilldown position](https://discuss.elastic.co/t/manipulation-of-drilldown-position/334442)

<div class="topic-metadata">

**Author:** [@martinsbleu](https://discuss.elastic.co/u/martinsbleu)\
**Replies:** 0\
**Last updated:** [May 26, 2023, 2:38pm UTC](https://discuss.elastic.co/t/manipulation-of-drilldown-position/334442 "2023-05-26T14:38:16Z")

</div>

Hello Team, After reading drilldown documentation, pardon if I am wrong but I couldn't find how to position drilldowns. For example, given 3 drilldowns : The number are the order which drilldown are created. and my…

[Previous page](https://discuss.elastic.co/tag/none.md?no_tags=true&page=370)

[Next page](https://discuss.elastic.co/tag/none.md?no_tags=true&page=372)
