# \#none

**URL:** https://discuss.elastic.co/tag/none.md?no_tags=true&page=378

[Latest](https://discuss.elastic.co/latest.md) · [Categories](https://discuss.elastic.co/categories.md) · [Tags](https://discuss.elastic.co/tags.md)

**Page:** 379

---

## [Create a rule without a query](https://discuss.elastic.co/t/create-a-rule-without-a-query/333314)

<div class="topic-metadata">

**Author:** [@WhiteOwl](https://discuss.elastic.co/u/WhiteOwl)\
**Replies:** 1\
**Last updated:** [May 16, 2023, 10:14pm UTC](https://discuss.elastic.co/t/create-a-rule-without-a-query/333314 "2023-05-16T22:14:25Z")

</div>

Hello, is it possible to create a rule that does not have a query? For example, if I want a rule to fire off every 4-6hrs for analyst to perform a specific task, is that possible?

---

## [No persistent volumes available for this claim on kubernetes](https://discuss.elastic.co/t/no-persistent-volumes-available-for-this-claim-on-kubernetes/333607)

<div class="topic-metadata">

**Author:** [@Resul\_Zoroglu](https://discuss.elastic.co/u/Resul_Zoroglu)\
**Replies:** 0\
**Last updated:** [May 16, 2023, 9:08pm UTC](https://discuss.elastic.co/t/no-persistent-volumes-available-for-this-claim-on-kubernetes/333607 "2023-05-16T21:08:53Z")

</div>

I'm trying to set up elasticsearch on kubernetes with Helm(helm install elasticsearch elastic/elasticsearch -n efk). I get the error "no persistent volumes available for this claim and no storage class is set". In my ku…

---

## [Kibana dashboard filters that recognize multiple views?](https://discuss.elastic.co/t/kibana-dashboard-filters-that-recognize-multiple-views/333507)

<div class="topic-metadata">

**Author:** [@learningelastic](https://discuss.elastic.co/u/learningelastic)\
**Replies:** 4\
**Last updated:** [May 16, 2023, 6:31pm UTC](https://discuss.elastic.co/t/kibana-dashboard-filters-that-recognize-multiple-views/333507 "2023-05-16T18:31:01Z")

</div>

I created a dashboard that shows visualizations . Each visualization references a different Kibana data view. And each kibana data view references a different index. For example, let's say I have two indices with the f…

---

## [ThreatIntel Module - missing field \[otx.id\] when calculating fingerprint](https://discuss.elastic.co/t/threatintel-module-missing-field-otx-id-when-calculating-fingerprint/330928)

<div class="topic-metadata">

**Author:** [@jlopezsec](https://discuss.elastic.co/u/jlopezsec)\
**Replies:** 3\
**Last updated:** [May 16, 2023, 6:15pm UTC](https://discuss.elastic.co/t/threatintel-module-missing-field-otx-id-when-calculating-fingerprint/330928 "2023-05-16T18:15:37Z")

</div>

Dear Elastic community, I am encountering an error in the Threat Intel module of Elastic where I am receiving the following message: "missing field \[otx.id\] when calculating fingerprint." After researching the error, I …

---

## [Csv parse failure](https://discuss.elastic.co/t/csv-parse-failure/333049)

<div class="topic-metadata">

**Author:** [@Hanni](https://discuss.elastic.co/u/Hanni)\
**Replies:** 9\
**Last updated:** [May 16, 2023, 2:45pm UTC](https://discuss.elastic.co/t/csv-parse-failure/333049 "2023-05-16T14:45:10Z")

</div>

Hello, I'm trying to parse a CSV file with Logstash, but I'm encountering a CSV parse failure. Can you please help me?

---

## [Mutate -\> Copy is not working as expected](https://discuss.elastic.co/t/mutate-copy-is-not-working-as-expected/333541)

<div class="topic-metadata">

**Author:** [@FALEN](https://discuss.elastic.co/u/FALEN)\
**Replies:** 1\
**Last updated:** [May 16, 2023, 2:42pm UTC](https://discuss.elastic.co/t/mutate-copy-is-not-working-as-expected/333541 "2023-05-16T14:42:54Z")

</div>

Im working on some json data, transforming and remapping fields add\_field, rename plugins are working as expected But whenever im using copy, output does not include these \[events\]\[date\], \[env\]\[app\] fields. But does in…

---

## [How to create dynamic Query DSL for Includes](https://discuss.elastic.co/t/how-to-create-dynamic-query-dsl-for-includes/333581)

<div class="topic-metadata">

**Author:** [@Koi\_Kin](https://discuss.elastic.co/u/Koi_Kin)\
**Replies:** 0\
**Last updated:** [May 16, 2023, 2:38pm UTC](https://discuss.elastic.co/t/how-to-create-dynamic-query-dsl-for-includes/333581 "2023-05-16T14:38:20Z")

</div>

I have this query: .Search\<Person\>("person", s =\> s .Index("person") .Source(s =\> s .Includes(i =\> i .Fields( f =\> f.Id, ) ) ) .Query(q =\> q …

---

## [Loadbalancing config in Kibana](https://discuss.elastic.co/t/loadbalancing-config-in-kibana/333464)

<div class="topic-metadata">

**Author:** [@zaeemmasood](https://discuss.elastic.co/u/zaeemmasood)\
**Replies:** 4\
**Last updated:** [May 16, 2023, 1:31pm UTC](https://discuss.elastic.co/t/loadbalancing-config-in-kibana/333464 "2023-05-16T13:31:36Z")

</div>

Hi All, Filebeat output has an ability to be configured with load balancing config as follows: output.logstash: hosts: \["hostA:5044","hostB:5044","hostC:5044"\] loadbalance: true Do we have a similar set up for K…

---

## [Add a quick range based on server time to Kibana Time filter quick ranges](https://discuss.elastic.co/t/add-a-quick-range-based-on-server-time-to-kibana-time-filter-quick-ranges/333564)

<div class="topic-metadata">

**Author:** [@gizem](https://discuss.elastic.co/u/gizem)\
**Replies:** 1\
**Last updated:** [May 16, 2023, 12:07pm UTC](https://discuss.elastic.co/t/add-a-quick-range-based-on-server-time-to-kibana-time-filter-quick-ranges/333564 "2023-05-16T12:07:14Z")

</div>

Hello, I want to add a quick range based on server time to Kibana. For example: \<{ "from": "now-15m", "to": "now", "display": "Last 15 minutes" }, /\> 'now' is set by client time. But if client time is wrong, filt…

---

## [Aggregations: How to get number of combinations](https://discuss.elastic.co/t/aggregations-how-to-get-number-of-combinations/333560)

<div class="topic-metadata">

**Author:** [@es\_make](https://discuss.elastic.co/u/es_make)\
**Replies:** 0\
**Last updated:** [May 16, 2023, 11:24am UTC](https://discuss.elastic.co/t/aggregations-how-to-get-number-of-combinations/333560 "2023-05-16T11:24:11Z")

</div>

Hello, Let's say we have a simple ES index having two fields: "name" (string) and "expired" (boolean) in one nested object "products" (array). Each product name can be mentioned only once in each document. Here's the e…

---

## [Storage polygon is judged to be self-intersecting](https://discuss.elastic.co/t/storage-polygon-is-judged-to-be-self-intersecting/333555)

<div class="topic-metadata">

**Author:** [@baiwenbo1997](https://discuss.elastic.co/u/baiwenbo1997)\
**Replies:** 1\
**Last updated:** [May 16, 2023, 10:45am UTC](https://discuss.elastic.co/t/storage-polygon-is-judged-to-be-self-intersecting/333555 "2023-05-16T10:45:27Z")

</div>

I want to know the tolerance or precision of self-intersecting graphics when storing. error: Polygon self-intersection at lat=22.773210573949637 lon=113.95022321162234 Here is my figure： \[0\] 113.950224078 22.77320374…

---

## [Logstash Mapping - Duplicate values in nested properties](https://discuss.elastic.co/t/logstash-mapping-duplicate-values-in-nested-properties/333554)

<div class="topic-metadata">

**Author:** [@kgazula](https://discuss.elastic.co/u/kgazula)\
**Replies:** 0\
**Last updated:** [May 16, 2023, 10:05am UTC](https://discuss.elastic.co/t/logstash-mapping-duplicate-values-in-nested-properties/333554 "2023-05-16T10:05:58Z")

</div>

Hello, can someone please help with mapping when there are more than 1 nested type properties in the mapping? We are using the 8.0 version and using Logstash we are synching the data from our Database to the ES index. P…

---

## [Elasticsearch not showing correct count of documents in index](https://discuss.elastic.co/t/elasticsearch-not-showing-correct-count-of-documents-in-index/330986)

<div class="topic-metadata">

**Author:** [@Taby](https://discuss.elastic.co/u/Taby)\
**Replies:** 9\
**Last updated:** [May 16, 2023, 10:08am UTC](https://discuss.elastic.co/t/elasticsearch-not-showing-correct-count-of-documents-in-index/330986 "2023-05-16T10:08:28Z")

</div>

Hi. Our Java 8 based application is sending an input data of total 17061816 documents to elasticsearch 7.17.4 to index these documents. However, after all indexing is completed, the curl \_count is showing a total of 168…

---

## [About using a two node cluster for data loss prevention](https://discuss.elastic.co/t/about-using-a-two-node-cluster-for-data-loss-prevention/333509)

<div class="topic-metadata">

**Author:** [@usaadi](https://discuss.elastic.co/u/usaadi)\
**Replies:** 4\
**Last updated:** [May 16, 2023, 10:01am UTC](https://discuss.elastic.co/t/about-using-a-two-node-cluster-for-data-loss-prevention/333509 "2023-05-16T10:01:06Z")

</div>

Hello... I have a question about whether a two nodes cluster can be a sufficient setup in avoiding data loss in the event of the complete failure of one node. In other words, for a two nodes cluster, can it be set up s…

---

## [Pause a node of the cluster](https://discuss.elastic.co/t/pause-a-node-of-the-cluster/330964)

<div class="topic-metadata">

**Author:** [@Blacktek](https://discuss.elastic.co/u/Blacktek)\
**Replies:** 6\
**Last updated:** [May 16, 2023, 9:34am UTC](https://discuss.elastic.co/t/pause-a-node-of-the-cluster/330964 "2023-05-16T09:34:15Z")

</div>

Hello, we've a three nodes cluster, and every once in a while we need to restart services or nodes to perform updates. We'd like to perform such activity in a graceful manner, waiting that current in-flight requests co…

---

## [Importing dashboard to kibana using rest api method](https://discuss.elastic.co/t/importing-dashboard-to-kibana-using-rest-api-method/333535)

<div class="topic-metadata">

**Author:** [@\_Zeyad\_Elshater](https://discuss.elastic.co/u/_Zeyad_Elshater)\
**Replies:** 3\
**Last updated:** [May 16, 2023, 9:13am UTC](https://discuss.elastic.co/t/importing-dashboard-to-kibana-using-rest-api-method/333535 "2023-05-16T09:13:33Z")

</div>

hello guys , I'm new to ELK , I'm trying to automate the process of integrating my metricbeat system with multible apps and systems , I have exported my desired dashboard and i want to automate the process of importing i…

---

## [Issues starting elastic search](https://discuss.elastic.co/t/issues-starting-elastic-search/333496)

<div class="topic-metadata">

**Author:** [@tanchev](https://discuss.elastic.co/u/tanchev)\
**Replies:** 1\
**Last updated:** [May 16, 2023, 8:59am UTC](https://discuss.elastic.co/t/issues-starting-elastic-search/333496 "2023-05-16T08:59:29Z")

</div>

I'm currently attempting to install and run Elasticsearch on CloudLinux, but I'm encountering some difficulties. The main issue is the absence of a .log file in the directory: /var/log/elasticsearch Despite the log pat…

---

## [Installed elasticsearch and Kibana on my GCP Red Hat Linux 9 but its not working](https://discuss.elastic.co/t/installed-elasticsearch-and-kibana-on-my-gcp-red-hat-linux-9-but-its-not-working/333240)

<div class="topic-metadata">

**Author:** [@Patr123](https://discuss.elastic.co/u/Patr123)\
**Replies:** 3\
**Last updated:** [May 16, 2023, 7:15am UTC](https://discuss.elastic.co/t/installed-elasticsearch-and-kibana-on-my-gcp-red-hat-linux-9-but-its-not-working/333240 "2023-05-16T07:15:06Z")

</div>

I installed elastic and kibana v.7.17.9 using rpm and was able to start the service with no issues. I don't see any errors in logs but when I try to access http://localhost:5601, it doesn't work and I get can't connect t…

---

## [Logstash errors](https://discuss.elastic.co/t/logstash-errors/333531)

<div class="topic-metadata">

**Author:** [@VellayLoket](https://discuss.elastic.co/u/VellayLoket)\
**Replies:** 0\
**Last updated:** [May 16, 2023, 6:48am UTC](https://discuss.elastic.co/t/logstash-errors/333531 "2023-05-16T06:48:32Z")

</div>

In some moment after i try to restart logstash i start to get errors like this, so everithing stoped to work. \[2023-05-16T16:43:06,516\]\[ERROR\]\[logstash.javapipeline \]\[main\] Pipeline worker error, the pipeline will be…

---

## [Error restoring state from URL rison decoder error: missing ':'](https://discuss.elastic.co/t/error-restoring-state-from-url-rison-decoder-error-missing/330053)

<div class="topic-metadata">

**Author:** [@carollyl](https://discuss.elastic.co/u/carollyl)\
**Replies:** 10\
**Last updated:** [May 16, 2023, 5:06am UTC](https://discuss.elastic.co/t/error-restoring-state-from-url-rison-decoder-error-missing/330053 "2023-05-16T05:06:38Z")

</div>

Hi, since updated from 6.8.8 to 7.12.0, always get this message "Error restoring state from URL". I have used a scripted field as URL to link one dashboard to another. See below for the URL (sample.com). I've verified w…

---

## [Why my elk always report an error "{"statusCode":503,"error":"Service Unavailable","message":"License is not available."}"](https://discuss.elastic.co/t/why-my-elk-always-report-an-error-statuscode-503-error-service-unavailable-message-license-is-not-available/332780)

<div class="topic-metadata">

**Author:** [@maf\_77](https://discuss.elastic.co/u/maf_77)\
**Replies:** 6\
**Last updated:** [May 16, 2023, 4:59am UTC](https://discuss.elastic.co/t/why-my-elk-always-report-an-error-statuscode-503-error-service-unavailable-message-license-is-not-available/332780 "2023-05-16T04:59:39Z")

</div>

I made a ELK system,but there offen have a error,the kibana html report:{"statusCode":503,"error":"Service Unavailable","message":"License is not available."} I don't know how to find the reason,so i had restart the ser…

---

## [Custom label size issue in transaction metadata](https://discuss.elastic.co/t/custom-label-size-issue-in-transaction-metadata/333520)

<div class="topic-metadata">

**Author:** [@APandey](https://discuss.elastic.co/u/APandey)\
**Replies:** 0\
**Last updated:** [May 16, 2023, 4:37am UTC](https://discuss.elastic.co/t/custom-label-size-issue-in-transaction-metadata/333520 "2023-05-16T04:37:25Z")

</div>

Hi team, We have modified the apm java agent code to add some metadata in transactions that is having dynamic length. One issue we are facing is that sometimes when the size of that metadata value is large let say more …

---

## [I am getting this error in fluentd pods , i have a efk setup in eks cluster , can someone help me with this please - error\_class=Fluent::Plugin::ElasticsearchErrorHandler::ElasticsearchError error="400 - Rejected by Elasticsearch" location=nil tag="ku](https://discuss.elastic.co/t/i-am-getting-this-error-in-fluentd-pods-i-have-a-efk-setup-in-eks-cluster-can-someone-help-me-with-this-please-error-class-fluent-elasticsearcherror-error-400-rejected-by-elasticsearch-location-nil-tag-ku/333040)

<div class="topic-metadata">

**Author:** [@jatinarora0](https://discuss.elastic.co/u/jatinarora0)\
**Replies:** 2\
**Last updated:** [May 16, 2023, 4:48am UTC](https://discuss.elastic.co/t/i-am-getting-this-error-in-fluentd-pods-i-have-a-efk-setup-in-eks-cluster-can-someone-help-me-with-this-please-error-class-fluent-elasticsearcherror-error-400-rejected-by-elasticsearch-location-nil-tag-ku/333040 "2023-05-16T04:48:24Z")

</div>

error\_class=Fluent::Plugin::ElasticsearchErrorHandler::ElasticsearchError error="400 - Rejected by Elasticsearch" location=nil tag="kubernetes.var.log.containers.fluentd

---

## [Kibana service keeps failing after upgrade from 7.17 to 8.7](https://discuss.elastic.co/t/kibana-service-keeps-failing-after-upgrade-from-7-17-to-8-7/333099)

<div class="topic-metadata">

**Author:** [@A\_Abdellah](https://discuss.elastic.co/u/A_Abdellah)\
**Replies:** 2\
**Last updated:** [May 16, 2023, 12:17am UTC](https://discuss.elastic.co/t/kibana-service-keeps-failing-after-upgrade-from-7-17-to-8-7/333099 "2023-05-16T00:17:04Z")

</div>

Hi, I'm trying to upgrade my cluster from 7.17.7 to 8.7 and I'm testing the upgrade on a single node cluster. I treated all the errors found by the upgrade assistant and upgraded elasticsearch just fine and tried witho…

---

## [Logstash and/or Kibana config wrong](https://discuss.elastic.co/t/logstash-and-or-kibana-config-wrong/333317)

<div class="topic-metadata">

**Author:** [@mariolanno](https://discuss.elastic.co/u/mariolanno)\
**Replies:** 3\
**Last updated:** [May 15, 2023, 9:50pm UTC](https://discuss.elastic.co/t/logstash-and-or-kibana-config-wrong/333317 "2023-05-15T21:50:26Z")

</div>

Hi, I cannot understand why I create two indexes on logstash to grab syslogs from two devices and then send to EL. input { udp { host =\> "192.168.0.73" port =\> "5515" } } filter {} output { ela…

---

## [Full disk access is not enabled, no error is displayed on the fleet side](https://discuss.elastic.co/t/full-disk-access-is-not-enabled-no-error-is-displayed-on-the-fleet-side/332793)

<div class="topic-metadata">

**Author:** [@xqaiviwjxzw](https://discuss.elastic.co/u/xqaiviwjxzw)\
**Replies:** 5\
**Last updated:** [May 15, 2023, 8:56pm UTC](https://discuss.elastic.co/t/full-disk-access-is-not-enabled-no-error-is-displayed-on-the-fleet-side/332793 "2023-05-15T20:56:41Z")

</div>

Full disk access was not enabled before, and an error will be displayed on the fleet side Now that full disk access is not enabled, no errors are displayed on the fleet side?

---

## [Kibana bootstrap fails 8.7.1](https://discuss.elastic.co/t/kibana-bootstrap-fails-8-7-1/333480)

<div class="topic-metadata">

**Author:** [@kbujold\_wr](https://discuss.elastic.co/u/kbujold_wr)\
**Replies:** 1\
**Last updated:** [May 15, 2023, 8:55pm UTC](https://discuss.elastic.co/t/kibana-bootstrap-fails-8-7-1/333480 "2023-05-15T20:55:59Z")

</div>

Trying to build kibana 8.7.1 and I am getting this error I was not getting when I build 8.6.2 yarn kbn bootstrap yarn run v1.22.19 $ node scripts/kbn bootstrap \[bazel\] INFO: Invocation ID: ff0c547e-d7a4-489e-a5ac-693642…

---

## [Add built-in normalizer to existing indices](https://discuss.elastic.co/t/add-built-in-normalizer-to-existing-indices/333360)

<div class="topic-metadata">

**Author:** [@NishuGoel](https://discuss.elastic.co/u/NishuGoel)\
**Replies:** 1\
**Last updated:** [May 15, 2023, 8:52pm UTC](https://discuss.elastic.co/t/add-built-in-normalizer-to-existing-indices/333360 "2023-05-15T20:52:09Z")

</div>

Hi there, I was going through the documentation where it says for some mapping parameters, we CAN update the existing index using PUT index/\_mapping. "normalizer" being one of those parameters - Update mapping API | El…

---

## [JVM Heap size issue. ElasticSearch stops sometimes due to this error](https://discuss.elastic.co/t/jvm-heap-size-issue-elasticsearch-stops-sometimes-due-to-this-error/333157)

<div class="topic-metadata">

**Author:** [@theacodes](https://discuss.elastic.co/u/theacodes)\
**Replies:** 10\
**Last updated:** [May 15, 2023, 7:55pm UTC](https://discuss.elastic.co/t/jvm-heap-size-issue-elasticsearch-stops-sometimes-due-to-this-error/333157 "2023-05-15T19:55:13Z")

</div>

Caused by: org.elasticsearch.common.breaker.CircuitBreakingException: \[parent\] Data too large, data for \[preallocate\[aggregations\]\] would be \[4143070784/3.8gb\], which is larger than the limit of \[4080218931/3.7gb\], real …

---

## [Elastic Agent silent install](https://discuss.elastic.co/t/elastic-agent-silent-install/329543)

<div class="topic-metadata">

**Author:** [@poky](https://discuss.elastic.co/u/poky)\
**Replies:** 2\
**Last updated:** [May 15, 2023, 7:47pm UTC](https://discuss.elastic.co/t/elastic-agent-silent-install/329543 "2023-05-15T19:47:49Z")

</div>

Hi Folks, I want to distribute the Elastic Agent through Windows SCCM onto 100 Windows Server. Therefore, I would like to do a silent install of the elastic Agent on Windows. Is there a way to give all the required pa…

[Previous page](https://discuss.elastic.co/tag/none.md?no_tags=true&page=377)

[Next page](https://discuss.elastic.co/tag/none.md?no_tags=true&page=379)
