# \#none

**URL:** https://discuss.elastic.co/tag/none.md?no_tags=true&page=372

[Latest](https://discuss.elastic.co/latest.md) · [Categories](https://discuss.elastic.co/categories.md) · [Tags](https://discuss.elastic.co/tags.md)

**Page:** 373

---

## [Kibana webhook payload in XML](https://discuss.elastic.co/t/kibana-webhook-payload-in-xml/333864)

<div class="topic-metadata">

**Author:** [@batman](https://discuss.elastic.co/u/batman)\
**Replies:** 3\
**Last updated:** [May 26, 2023, 1:45pm UTC](https://discuss.elastic.co/t/kibana-webhook-payload-in-xml/333864 "2023-05-26T13:45:51Z")

</div>

Hello All, I would want to send events from Kibana to external ticketing system but the external system accepts only xml as payload for processing. Is it possible to somehow send xml as events payload from Kibana ? Hin…

---

## [Elasticsearch dynamic date field mapping](https://discuss.elastic.co/t/elasticsearch-dynamic-date-field-mapping/334436)

<div class="topic-metadata">

**Author:** [@riani.oussama](https://discuss.elastic.co/u/riani.oussama)\
**Replies:** 1\
**Last updated:** [May 26, 2023, 1:25pm UTC](https://discuss.elastic.co/t/elasticsearch-dynamic-date-field-mapping/334436 "2023-05-26T13:25:26Z")

</div>

Hi, I have a problem in handling dates in my indexes. My indexes were created automatically from my application. In one index the field "CreationDate" is of type text (Tue May 23 10:55:12 CEST 2023), in another index …

---

## [I lose all my data when master node restarts](https://discuss.elastic.co/t/i-lose-all-my-data-when-master-node-restarts/334410)

<div class="topic-metadata">

**Author:** [@daniela09](https://discuss.elastic.co/u/daniela09)\
**Replies:** 7\
**Last updated:** [May 26, 2023, 12:54pm UTC](https://discuss.elastic.co/t/i-lose-all-my-data-when-master-node-restarts/334410 "2023-05-26T12:54:45Z")

</div>

Hi, I have EKF stack on Kubernetes, now I have 1 client node, 1 master node and 3 data nodes. When my master node restarts I lose all the data and indices that I have and my master's UUID changes, so I need to restart a…

---

## [Ruby error found during Logstash start with IBM Semeru Java](https://discuss.elastic.co/t/ruby-error-found-during-logstash-start-with-ibm-semeru-java/334431)

<div class="topic-metadata">

**Author:** [@KevinT1](https://discuss.elastic.co/u/KevinT1)\
**Replies:** 1\
**Last updated:** [May 26, 2023, 12:35pm UTC](https://discuss.elastic.co/t/ruby-error-found-during-logstash-start-with-ibm-semeru-java/334431 "2023-05-26T12:35:53Z")

</div>

Logstash version: logstash-8.7.1 JDK: \> $ ./java -version \> java version "11.0.18" 2023-01-17 \> IBM Semeru Runtime Certified Edition 11.0.18.0 (build 11.0.18+10) \> Eclipse OpenJ9 VM 11.0.18.0 (build openj9-0.36.1, JRE …

---

## [How we can create two index in logstash](https://discuss.elastic.co/t/how-we-can-create-two-index-in-logstash/334082)

<div class="topic-metadata">

**Author:** [@subash\_k](https://discuss.elastic.co/u/subash_k)\
**Replies:** 5\
**Last updated:** [May 26, 2023, 12:10pm UTC](https://discuss.elastic.co/t/how-we-can-create-two-index-in-logstash/334082 "2023-05-26T12:10:38Z")

</div>

Hello, Anyone came across below scenario, I have a json as input and am filtering the data later creating index in output block to push it into elastic Here i want to split the data into two set and want them to send…

---

## [Mapping parser exception](https://discuss.elastic.co/t/mapping-parser-exception/334322)

<div class="topic-metadata">

**Author:** [@Anand\_Konagala](https://discuss.elastic.co/u/Anand_Konagala)\
**Replies:** 5\
**Last updated:** [May 26, 2023, 12:06pm UTC](https://discuss.elastic.co/t/mapping-parser-exception/334322 "2023-05-26T12:06:07Z")

</div>

I am using Elasticsearch 8.7.0....... While inserting any document I am getting this kind of error. In previously versions which includes the field path where got and error now It Shows only RequestError(400, 'mapper\_p…

---

## [Apm agent issue](https://discuss.elastic.co/t/apm-agent-issue/334408)

<div class="topic-metadata">

**Author:** [@fontexD](https://discuss.elastic.co/u/fontexD)\
**Replies:** 4\
**Last updated:** [May 26, 2023, 10:18am UTC](https://discuss.elastic.co/t/apm-agent-issue/334408 "2023-05-26T10:18:43Z")

</div>

ive installed a elastic agent with apm, i can fine see the agent in kibana, but it seems theres an issue with the apm, ive attacted some pictures apm address is a dns apm.domain.dk:8200 telnet to it works fine

---

## [Logstash pipeline for aws cloudfront fixing timestamp issue](https://discuss.elastic.co/t/logstash-pipeline-for-aws-cloudfront-fixing-timestamp-issue/334411)

<div class="topic-metadata">

**Author:** [@miiimooo](https://discuss.elastic.co/u/miiimooo)\
**Replies:** 0\
**Last updated:** [May 26, 2023, 9:38am UTC](https://discuss.elastic.co/t/logstash-pipeline-for-aws-cloudfront-fixing-timestamp-issue/334411 "2023-05-26T09:38:52Z")

</div>

This took me ages to figure out so I thought it might be helpful for someone else. I'm parsing AWS CloudFront standard logs in logstash (v8.x) The included grok pattern worked fine for me apart from the timestamp, sinc…

---

## [Elastic-agent: output by integration and not by policy](https://discuss.elastic.co/t/elastic-agent-output-by-integration-and-not-by-policy/334252)

<div class="topic-metadata">

**Author:** [@Ofir\_Edi](https://discuss.elastic.co/u/Ofir_Edi)\
**Replies:** 2\
**Last updated:** [May 26, 2023, 9:13am UTC](https://discuss.elastic.co/t/elastic-agent-output-by-integration-and-not-by-policy/334252 "2023-05-26T09:13:16Z")

</div>

Hi, i have an instance of elastic-agent on a server where i have multiple integrations. for most of them I need the Elasticsearch output. But, I also have some log files on that server which I want to send to Logstash f…

---

## [Can I take backup of indices from one cluster and restore it to another cluster](https://discuss.elastic.co/t/can-i-take-backup-of-indices-from-one-cluster-and-restore-it-to-another-cluster/334387)

<div class="topic-metadata">

**Author:** [@kunalhiremath](https://discuss.elastic.co/u/kunalhiremath)\
**Replies:** 14\
**Last updated:** [May 26, 2023, 8:55am UTC](https://discuss.elastic.co/t/can-i-take-backup-of-indices-from-one-cluster-and-restore-it-to-another-cluster/334387 "2023-05-26T08:55:37Z")

</div>

Can I take backup of indices from one cluster and restore it to another cluster by simply copying the snapshot/backup repository folder and sending it to another cluster and from there I will perform restore operation is…

---

## [Taking backup on one system and restoring it in another system](https://discuss.elastic.co/t/taking-backup-on-one-system-and-restoring-it-in-another-system/334392)

<div class="topic-metadata">

**Author:** [@kunalhiremath](https://discuss.elastic.co/u/kunalhiremath)\
**Replies:** 2\
**Last updated:** [May 26, 2023, 6:22am UTC](https://discuss.elastic.co/t/taking-backup-on-one-system-and-restoring-it-in-another-system/334392 "2023-05-26T06:22:41Z")

</div>

I have Elasticsearch running on one system where I take backup of indices regularly into a snapshot, but these indices(snapshot) I want to restore to different system. How can I proceed. I am unable to find clear answer…

---

## [Kibana Error - Error while updating search session conflict](https://discuss.elastic.co/t/kibana-error-error-while-updating-search-session-conflict/334396)

<div class="topic-metadata">

**Author:** [@Yos](https://discuss.elastic.co/u/Yos)\
**Replies:** 0\
**Last updated:** [May 26, 2023, 6:11am UTC](https://discuss.elastic.co/t/kibana-error-error-while-updating-search-session-conflict/334396 "2023-05-26T06:11:31Z")

</div>

Kibana Version : 8.5.3 Hello The following error is intermittently logged in Kibana's logs Is there a lack of authority? Or Is it an error that can be ignored? If you can give me any information on the cause or how …

---

## [How to check if Application run as administrator](https://discuss.elastic.co/t/how-to-check-if-application-run-as-administrator/333514)

<div class="topic-metadata">

**Author:** [@target\_test](https://discuss.elastic.co/u/target_test)\
**Replies:** 5\
**Last updated:** [May 26, 2023, 1:47am UTC](https://discuss.elastic.co/t/how-to-check-if-application-run-as-administrator/333514 "2023-05-26T01:47:14Z")

</div>

Hello i have a question Is there any rules to detect if any application run as administrator or if a user run the application as admin in windows machine ?

---

## [I have problem installing elastic agent](https://discuss.elastic.co/t/i-have-problem-installing-elastic-agent/334375)

<div class="topic-metadata">

**Author:** [@daniellopez](https://discuss.elastic.co/u/daniellopez)\
**Replies:** 0\
**Last updated:** [May 25, 2023, 10:55pm UTC](https://discuss.elastic.co/t/i-have-problem-installing-elastic-agent/334375 "2023-05-25T22:55:37Z")

</div>

Actually I am having a problem to install elastic agent. When I run the command that kibana gives me I get the following error 2023-05-25T10:46:57.852-0500 INFO cmd/enroll\_cmd.go:701 Fleet Server - Error - coul…

---

## [Kibana change the "now value" or current time](https://discuss.elastic.co/t/kibana-change-the-now-value-or-current-time/334203)

<div class="topic-metadata">

**Author:** [@JackieLaFrite](https://discuss.elastic.co/u/JackieLaFrite)\
**Replies:** 2\
**Last updated:** [May 25, 2023, 9:49pm UTC](https://discuss.elastic.co/t/kibana-change-the-now-value-or-current-time/334203 "2023-05-25T21:49:22Z")

</div>

Kibana "now" value is incorrect and i don't want it to modify the value of my time field. If it's currently 12h05, logstash send the logs from 12h05 but Kibana with this settings : Display the logs from 10h and add 2…

---

## [Where to find complete documentation for CRDs?](https://discuss.elastic.co/t/where-to-find-complete-documentation-for-crds/334367)

<div class="topic-metadata">

**Author:** [@nahh](https://discuss.elastic.co/u/nahh)\
**Replies:** 0\
**Last updated:** [May 25, 2023, 7:25pm UTC](https://discuss.elastic.co/t/where-to-find-complete-documentation-for-crds/334367 "2023-05-25T19:25:40Z")

</div>

I'm looking for the complete documentation for the ECK operator CRDs. For example, I'm looking into tweaking the config for Kibana pods so they may run on my cluster. I see that the CRD defines spec.podTemplate, but expl…

---

## [Scale out logstash server and configure the output in the Fleet UI](https://discuss.elastic.co/t/scale-out-logstash-server-and-configure-the-output-in-the-fleet-ui/333383)

<div class="topic-metadata">

**Author:** [@A113n](https://discuss.elastic.co/u/A113n)\
**Replies:** 1\
**Last updated:** [May 25, 2023, 5:29pm UTC](https://discuss.elastic.co/t/scale-out-logstash-server-and-configure-the-output-in-the-fleet-ui/333383 "2023-05-25T17:29:31Z")

</div>

Hi I have 1 logstash server configured and 1 fleet server. I now want to scale out logstash by 1 more server. The Elastic Agent have client side support for loadbalancing between multiple logstash servers: output.log…

---

## [Error starting Logstash pipeline after upgrading to Java 17](https://discuss.elastic.co/t/error-starting-logstash-pipeline-after-upgrading-to-java-17/334346)

<div class="topic-metadata">

**Author:** [@Nikhil\_Khurana](https://discuss.elastic.co/u/Nikhil_Khurana)\
**Replies:** 1\
**Last updated:** [May 25, 2023, 4:19pm UTC](https://discuss.elastic.co/t/error-starting-logstash-pipeline-after-upgrading-to-java-17/334346 "2023-05-25T16:19:21Z")

</div>

I have bundled Logstash within my Java application and launch it using JRuby. It worked fine until upgrading to Java 17. After upgrading, the pipeline fails to start with following exception : java.lang.IllegalAcce…

---

## [How to list non empty field names based on search criteria on elasticsearch](https://discuss.elastic.co/t/how-to-list-non-empty-field-names-based-on-search-criteria-on-elasticsearch/334349)

<div class="topic-metadata">

**Author:** [@ehmd96](https://discuss.elastic.co/u/ehmd96)\
**Replies:** 1\
**Last updated:** [May 25, 2023, 4:07pm UTC](https://discuss.elastic.co/t/how-to-list-non-empty-field-names-based-on-search-criteria-on-elasticsearch/334349 "2023-05-25T16:07:29Z")

</div>

we are encountering an issue on elasticsearch trying to display fields based on certain search criteria. We have an index with a "payload" field which has multiple properties What we are trying to do is to request t…

---

## [\[Logstash\] How to drop message if field is not a number](https://discuss.elastic.co/t/logstash-how-to-drop-message-if-field-is-not-a-number/333324)

<div class="topic-metadata">

**Author:** [@catalin.bulancea](https://discuss.elastic.co/u/catalin.bulancea)\
**Replies:** 4\
**Last updated:** [May 25, 2023, 3:59pm UTC](https://discuss.elastic.co/t/logstash-how-to-drop-message-if-field-is-not-a-number/333324 "2023-05-25T15:59:49Z")

</div>

Hi Logstash gurus, I need to drop the messages that contain specific fields that are not a number. The filter I have is: filter { csv { separator =\> "," skip\_header =\> "true" columns =\> \["process-n…

---

## [Documents being deleted after BulkRequest indexing](https://discuss.elastic.co/t/documents-being-deleted-after-bulkrequest-indexing/333674)

<div class="topic-metadata">

**Author:** [@vivss](https://discuss.elastic.co/u/vivss)\
**Replies:** 12\
**Last updated:** [May 25, 2023, 3:06pm UTC](https://discuss.elastic.co/t/documents-being-deleted-after-bulkrequest-indexing/333674 "2023-05-25T15:06:35Z")

</div>

Hi all, We are using Elasticsearch 7.17.7 and indexing documents via BulkRequest in Java API Client, and we noticed that many documents are being deleted after indexing. We retrieve the records from a Postgresql databas…

---

## [What does "managed namespaces" mean exactly?](https://discuss.elastic.co/t/what-does-managed-namespaces-mean-exactly/334054)

<div class="topic-metadata">

**Author:** [@nahh](https://discuss.elastic.co/u/nahh)\
**Replies:** 2\
**Last updated:** [May 25, 2023, 2:55pm UTC](https://discuss.elastic.co/t/what-does-managed-namespaces-mean-exactly/334054 "2023-05-25T14:55:59Z")

</div>

I'm looking in to installing ECK in my Kubernetes clusters and I'm stuck on one issue: in the helm chart for ECK we're asked to specify a list of "managed namespaces". What does that mean? Specifically, what is being man…

---

## [Remove ConfigMaps when uninstalling ECK](https://discuss.elastic.co/t/remove-configmaps-when-uninstalling-eck/332958)

<div class="topic-metadata">

**Author:** [@cturbe](https://discuss.elastic.co/u/cturbe)\
**Replies:** 2\
**Last updated:** [May 25, 2023, 2:14pm UTC](https://discuss.elastic.co/t/remove-configmaps-when-uninstalling-eck/332958 "2023-05-25T14:14:50Z")

</div>

Hello, Is it possible to delete the 3 remaining configMaps when uninstalling ECK via Helm? $helm uninstall eck-operator All resources are deleted except these 3 ConfigMap: kubectl get configmap elastic-licensing …

---

## [API Key delete by mistake in stack Management](https://discuss.elastic.co/t/api-key-delete-by-mistake-in-stack-management/334304)

<div class="topic-metadata">

**Author:** [@maniacci](https://discuss.elastic.co/u/maniacci)\
**Replies:** 3\
**Last updated:** [May 25, 2023, 1:04pm UTC](https://discuss.elastic.co/t/api-key-delete-by-mistake-in-stack-management/334304 "2023-05-25T13:04:11Z")

</div>

Hi , I have by mistake deleted API keys (while doing some manipulations following a test to add a Linux server on the SIEM). I would like to know if it is possible to restore his keys? I have Veeam backups . I would …

---

## [Elasticsearch 7.17.10 indexing bottleneck on i3.2xlarge and d3.2xlarge nodes in EKS](https://discuss.elastic.co/t/elasticsearch-7-17-10-indexing-bottleneck-on-i3-2xlarge-and-d3-2xlarge-nodes-in-eks/333503)

<div class="topic-metadata">

**Author:** [@Chris\_Austin](https://discuss.elastic.co/u/Chris_Austin)\
**Replies:** 52\
**Last updated:** [May 25, 2023, 1:03pm UTC](https://discuss.elastic.co/t/elasticsearch-7-17-10-indexing-bottleneck-on-i3-2xlarge-and-d3-2xlarge-nodes-in-eks/333503 "2023-05-25T13:03:25Z")

</div>

My 7.17.10 cluster is hosted in AWS EKS and is managed by ECK. It appears to top out at around 90k documents indexed per second (including replicas) per second and I haven't been able to identify the bottleneck. Adding m…

---

## [System.filesystem.used.pct showing 0.55 want to change it in 55% on Visualization](https://discuss.elastic.co/t/system-filesystem-used-pct-showing-0-55-want-to-change-it-in-55-on-visualization/334020)

<div class="topic-metadata">

**Author:** [@vaibhav.ubale](https://discuss.elastic.co/u/vaibhav.ubale)\
**Replies:** 3\
**Last updated:** [May 25, 2023, 11:54am UTC](https://discuss.elastic.co/t/system-filesystem-used-pct-showing-0-55-want-to-change-it-in-55-on-visualization/334020 "2023-05-25T11:54:39Z")

</div>

Hi All, system.filesystem.used.pct showing 0.55 want to change it in 55% on Visualization/Dashboard. How can I change this. Thanks in advance Vaibhav Ubale

---

## [Can U help with optimal search method?](https://discuss.elastic.co/t/can-u-help-with-optimal-search-method/334310)

<div class="topic-metadata">

**Author:** [@Nurm](https://discuss.elastic.co/u/Nurm)\
**Replies:** 0\
**Last updated:** [May 25, 2023, 11:03am UTC](https://discuss.elastic.co/t/can-u-help-with-optimal-search-method/334310 "2023-05-25T11:03:43Z")

</div>

Can you guys show the best way to find users by first and last name or by full name. Also, when the user enters a name, I want to search for that name in both Cyrillic and Latin. Any links, ideas? Client could enter N…

---

## [Polygon Self-Intersecting when there is minimal wrapping at -180/180 failing](https://discuss.elastic.co/t/polygon-self-intersecting-when-there-is-minimal-wrapping-at-180-180-failing/334065)

<div class="topic-metadata">

**Author:** [@Craig\_Roush](https://discuss.elastic.co/u/Craig_Roush)\
**Replies:** 13\
**Last updated:** [May 25, 2023, 10:05am UTC](https://discuss.elastic.co/t/polygon-self-intersecting-when-there-is-minimal-wrapping-at-180-180-failing/334065 "2023-05-25T10:05:31Z")

</div>

I am receiving a polygon-self intersecting error when I have a polygon that barely wraps across 180 to -180: I have a simple mapping for a index setup as: index\_mapping = { "time": { "type": "da…

---

## [Kibana conflicting field](https://discuss.elastic.co/t/kibana-conflicting-field/334301)

<div class="topic-metadata">

**Author:** [@jfrank](https://discuss.elastic.co/u/jfrank)\
**Replies:** 1\
**Last updated:** [May 25, 2023, 9:57am UTC](https://discuss.elastic.co/t/kibana-conflicting-field/334301 "2023-05-25T09:57:10Z")

</div>

Recently I've changed type of the field from text to long and now I see in documents in Kibana that this field is "conflicting". How Can I solve this? Kibana v 8.1.0

---

## [How to extract all log sources in ELK?](https://discuss.elastic.co/t/how-to-extract-all-log-sources-in-elk/334188)

<div class="topic-metadata">

**Author:** [@UP\_NEWS](https://discuss.elastic.co/u/UP_NEWS)\
**Replies:** 6\
**Last updated:** [May 25, 2023, 9:45am UTC](https://discuss.elastic.co/t/how-to-extract-all-log-sources-in-elk/334188 "2023-05-25T09:45:41Z")

</div>

Hi team, I'm new in elastic stack , please i need a procedure how to extract all the source logs IP and status if possible, for example i have 10 servers linux redhat integrated in elastic with auditbeat and i have 10 w…

[Previous page](https://discuss.elastic.co/tag/none.md?no_tags=true&page=371)

[Next page](https://discuss.elastic.co/tag/none.md?no_tags=true&page=373)
