# \#none

**URL:** https://discuss.elastic.co/tag/none.md?no_tags=true&page=394

[Latest](https://discuss.elastic.co/latest.md) · [Categories](https://discuss.elastic.co/categories.md) · [Tags](https://discuss.elastic.co/tags.md)

**Page:** 395

---

## [Use data view or direct index](https://discuss.elastic.co/t/use-data-view-or-direct-index/330239)

<div class="topic-metadata">

**Author:** [@elasticforme](https://discuss.elastic.co/u/elasticforme)\
**Replies:** 7\
**Last updated:** [April 19, 2023, 9:22pm UTC](https://discuss.elastic.co/t/use-data-view-or-direct-index/330239 "2023-04-19T21:22:00Z")

</div>

I have 1000+ index myindex-\<date\>-00000x ( this is all rollover using ILM) in my REST calll should I use myindex-\* or use latest index by it's name like "myindex-\<date\>-00000x" most everytime I retrive data using @…

---

## [I am facing issue to open kibana url in iframe](https://discuss.elastic.co/t/i-am-facing-issue-to-open-kibana-url-in-iframe/330215)

<div class="topic-metadata">

**Author:** [@devdev7711](https://discuss.elastic.co/u/devdev7711)\
**Replies:** 1\
**Last updated:** [April 19, 2023, 8:25pm UTC](https://discuss.elastic.co/t/i-am-facing-issue-to-open-kibana-url-in-iframe/330215 "2023-04-19T20:25:14Z")

</div>

I have kibana setup in https and configuare previously. It is working fine for me. but when other user is login in webapplication they are getting errors. iframe src="https://1.2.111.111:8600/app/dashboards#/view/fe3f…

---

## [Can't see Kibana logs](https://discuss.elastic.co/t/cant-see-kibana-logs/330246)

<div class="topic-metadata">

**Author:** [@ishan.abhinit](https://discuss.elastic.co/u/ishan.abhinit)\
**Replies:** 7\
**Last updated:** [April 19, 2023, 7:15pm UTC](https://discuss.elastic.co/t/cant-see-kibana-logs/330246 "2023-04-19T19:15:40Z")

</div>

I had set up Elasticsearch and Kibana on Rocky Linux few months ago for a workshop. Everything worked fine then. I shut down the server after the workshop and restarted it last week. I don't see the logs appearing in Ki…

---

## [Keyword search not behaving as expected](https://discuss.elastic.co/t/keyword-search-not-behaving-as-expected/330328)

<div class="topic-metadata">

**Author:** [@developer3124](https://discuss.elastic.co/u/developer3124)\
**Replies:** 4\
**Last updated:** [April 19, 2023, 7:06pm UTC](https://discuss.elastic.co/t/keyword-search-not-behaving-as-expected/330328 "2023-04-19T19:06:52Z")

</div>

Hello, I'm having an issue with keyword search not behaving how I would expect from the docs. I can see that the following document exists in my index: { "\_index": "my-index", "\_type": "\_doc", "\_id": …

---

## [Logstash, parsing a localised date with HTTPDATE](https://discuss.elastic.co/t/logstash-parsing-a-localised-date-with-httpdate/330297)

<div class="topic-metadata">

**Author:** [@GreenEyed](https://discuss.elastic.co/u/GreenEyed)\
**Replies:** 3\
**Last updated:** [April 19, 2023, 6:15pm UTC](https://discuss.elastic.co/t/logstash-parsing-a-localised-date-with-httpdate/330297 "2023-04-19T18:15:06Z")

</div>

Hi there, We have a library that is sending access logs to logstash with a "similar" to Apache format. We have created the regexp in grok to parse it but I have detected that the library is using the default format, loc…

---

## [How to split data into spaces](https://discuss.elastic.co/t/how-to-split-data-into-spaces/330229)

<div class="topic-metadata">

**Author:** [@Joelgoncalves3000](https://discuss.elastic.co/u/Joelgoncalves3000)\
**Replies:** 9\
**Last updated:** [April 19, 2023, 5:15pm UTC](https://discuss.elastic.co/t/how-to-split-data-into-spaces/330229 "2023-04-19T17:15:50Z")

</div>

Hello, let's imagine that I have a cluster with 5 nodes and each node is a client, I want these 5 to divide the data from these clients into spaces, I would also like to install packebeat and filebeat on each node and se…

---

## [ELK 7.6.2 Licensing](https://discuss.elastic.co/t/elk-7-6-2-licensing/330324)

<div class="topic-metadata">

**Author:** [@zaeemmasood](https://discuss.elastic.co/u/zaeemmasood)\
**Replies:** 1\
**Last updated:** [April 19, 2023, 5:07pm UTC](https://discuss.elastic.co/t/elk-7-6-2-licensing/330324 "2023-04-19T17:07:36Z")

</div>

Hello, We are using a very old version of ELK cluster 7.6.2 (with Basic license) in our environment. We plan to upgrade to the latest 8.6 version in future. With the 7.6.2 version in place we want to look into the pos…

---

## [Central Elastic Stack setup for a company with 10+ applications using Elasticsearch](https://discuss.elastic.co/t/central-elastic-stack-setup-for-a-company-with-10-applications-using-elasticsearch/329800)

<div class="topic-metadata">

**Author:** [@murat3](https://discuss.elastic.co/u/murat3)\
**Replies:** 7\
**Last updated:** [April 19, 2023, 5:03pm UTC](https://discuss.elastic.co/t/central-elastic-stack-setup-for-a-company-with-10-applications-using-elasticsearch/329800 "2023-04-19T17:03:57Z")

</div>

Hello all, I am trying to understand the setup of a (central) Elastic Stack cluster used by 10+ projects and 20+ applications. Our applications consist of frontend web and Java backend applications. One Cluster Is one…

---

## [Project synthetics service.name](https://discuss.elastic.co/t/project-synthetics-service-name/330282)

<div class="topic-metadata">

**Author:** [@jasonwhetton](https://discuss.elastic.co/u/jasonwhetton)\
**Replies:** 1\
**Last updated:** [April 19, 2023, 2:43pm UTC](https://discuss.elastic.co/t/project-synthetics-service-name/330282 "2023-04-19T14:43:55Z")

</div>

Hi, It it possible right now to provide the related APM service name for project based synthetics? // Jason

---

## [Curl: (7) Failed to connect to 10.x.x.x port 5601: Connection refused](https://discuss.elastic.co/t/curl-7-failed-to-connect-to-10-x-x-x-port-5601-connection-refused/330138)

<div class="topic-metadata">

**Author:** [@ram\_222](https://discuss.elastic.co/u/ram_222)\
**Replies:** 11\
**Last updated:** [April 19, 2023, 2:43pm UTC](https://discuss.elastic.co/t/curl-7-failed-to-connect-to-10-x-x-x-port-5601-connection-refused/330138 "2023-04-19T14:43:35Z")

</div>

Here, I provide the Procedure what I follow to setup a Elastic Search and Kibana on GCP Vm's: Created a 2 Vm's of Es and Kibana with Reserved Internal and External Ip's. Successfully Deployed Es and Kibana Debian packa…

---

## [Handler for externaltraffic definition not working](https://discuss.elastic.co/t/handler-for-externaltraffic-definition-not-working/330308)

<div class="topic-metadata">

**Author:** [@ccaillet](https://discuss.elastic.co/u/ccaillet)\
**Replies:** 0\
**Last updated:** [April 19, 2023, 1:21pm UTC](https://discuss.elastic.co/t/handler-for-externaltraffic-definition-not-working/330308 "2023-04-19T13:21:55Z")

</div>

Hi all, WIth ECK 2.7.0, I've created a cluster and specifying the type LoadBalancer on http service Spec for elasticsearch object, but the externalTrafficPolicy directive is not handled correctly here is the sample of …

---

## [Hiding results in Data Table visualisation based on the count](https://discuss.elastic.co/t/hiding-results-in-data-table-visualisation-based-on-the-count/330303)

<div class="topic-metadata">

**Author:** [@Jakub\_J](https://discuss.elastic.co/u/Jakub_J)\
**Replies:** 0\
**Last updated:** [April 19, 2023, 12:17pm UTC](https://discuss.elastic.co/t/hiding-results-in-data-table-visualisation-based-on-the-count/330303 "2023-04-19T12:17:15Z")

</div>

Hello hive mind, After some time I reached a dead end, thus i'd like to ask you assistance from the gurus. here's what I try to achieve. I have an index pattern which includes (amongst others) ProductionID (String). I…

---

## [Uptime Monitors - Synthetic Monitors (Orphaned)](https://discuss.elastic.co/t/uptime-monitors-synthetic-monitors-orphaned/330036)

<div class="topic-metadata">

**Author:** [@zx8086](https://discuss.elastic.co/u/zx8086)\
**Replies:** 4\
**Last updated:** [April 19, 2023, 10:00am UTC](https://discuss.elastic.co/t/uptime-monitors-synthetic-monitors-orphaned/330036 "2023-04-19T10:00:30Z")

</div>

Hi, For some reason I have Uptime Monitors which are orphaned as I am not running any Browser Synthetic Integrations from within Fleet. Would like to somehow remove these. Kibana version: 8.7

---

## [Metricbeat Docker - Containers missing](https://discuss.elastic.co/t/metricbeat-docker-containers-missing/330280)

<div class="topic-metadata">

**Author:** [@thibaut\_a](https://discuss.elastic.co/u/thibaut_a)\
**Replies:** 0\
**Last updated:** [April 19, 2023, 9:01am UTC](https://discuss.elastic.co/t/metricbeat-docker-containers-missing/330280 "2023-04-19T09:01:17Z")

</div>

Hi, I have some containers running on a Debian server. I have installed Metricbeat and activated the Docker module (config below), but in Kibana dashboards, some are missing. I should see 7 lines (1 per started container…

---

## [Get a substring of a string](https://discuss.elastic.co/t/get-a-substring-of-a-string/330278)

<div class="topic-metadata">

**Author:** [@obelaisk](https://discuss.elastic.co/u/obelaisk)\
**Replies:** 0\
**Last updated:** [April 19, 2023, 8:53am UTC](https://discuss.elastic.co/t/get-a-substring-of-a-string/330278 "2023-04-19T08:53:22Z")

</div>

Hi, im using canvas and i don't know if it's possible to get a substring of a given string in expression editor

---

## [Logstash-8.7 fails to load YAML larger than 3MB](https://discuss.elastic.co/t/logstash-8-7-fails-to-load-yaml-larger-than-3mb/330269)

<div class="topic-metadata">

**Author:** [@Dheeraj\_Gupta](https://discuss.elastic.co/u/Dheeraj_Gupta)\
**Replies:** 0\
**Last updated:** [April 19, 2023, 7:55am UTC](https://discuss.elastic.co/t/logstash-8-7-fails-to-load-yaml-larger-than-3mb/330269 "2023-04-19T07:55:24Z")

</div>

We are using Logstash translate plugin to add user information to IP addresses in logs/events in our organization. The user data is loaded via YAML. The file is large (5.5MB with around 15K entries). Till Logstash-8.6, …

---

## [Remove setup directory agent old version](https://discuss.elastic.co/t/remove-setup-directory-agent-old-version/330244)

<div class="topic-metadata">

**Author:** [@GKre](https://discuss.elastic.co/u/GKre)\
**Replies:** 2\
**Last updated:** [April 19, 2023, 7:35am UTC](https://discuss.elastic.co/t/remove-setup-directory-agent-old-version/330244 "2023-04-19T07:35:05Z")

</div>

Hello, due to the wonderfull help inside this forum i come more and more into the system and i really like what i learn and see. I had the problem that upgrade of the agent to 8.7.0 did not work like expected. So i ch…

---

## [Count number of times an index was searched](https://discuss.elastic.co/t/count-number-of-times-an-index-was-searched/330260)

<div class="topic-metadata">

**Author:** [@searchwithme](https://discuss.elastic.co/u/searchwithme)\
**Replies:** 1\
**Last updated:** [April 19, 2023, 6:30am UTC](https://discuss.elastic.co/t/count-number-of-times-an-index-was-searched/330260 "2023-04-19T06:30:58Z")

</div>

Hi team! Is there a way to find out how many times a particular index was searched/queries? If not a direct API in elastic, is there a workaround to get this metric?

---

## [Kibana Dashboard in slideshow Mode](https://discuss.elastic.co/t/kibana-dashboard-in-slideshow-mode/330263)

<div class="topic-metadata">

**Author:** [@Dipesh](https://discuss.elastic.co/u/Dipesh)\
**Replies:** 0\
**Last updated:** [April 19, 2023, 6:01am UTC](https://discuss.elastic.co/t/kibana-dashboard-in-slideshow-mode/330263 "2023-04-19T06:01:16Z")

</div>

Hi, I have some dashboards with multiple visualisation attached in it, since it has 30+ Visualize charts added in the dashboard, its doesn't look good and also unable to see in a single screen, so i am searching for som…

---

## [Exiting: error initializing publisher: output type http undefined in filebeat.yml](https://discuss.elastic.co/t/exiting-error-initializing-publisher-output-type-http-undefined-in-filebeat-yml/330258)

<div class="topic-metadata">

**Author:** [@karthic](https://discuss.elastic.co/u/karthic)\
**Replies:** 1\
**Last updated:** [April 19, 2023, 5:39am UTC](https://discuss.elastic.co/t/exiting-error-initializing-publisher-output-type-http-undefined-in-filebeat-yml/330258 "2023-04-19T05:39:28Z")

</div>

Hi I need to forward the logs to my own api, In the config, i am using Http.output which says the error "Exiting: error initializing publisher: output type http undefined in filebeat" output.http: url: "https://API…

---

## [AI-powered Elastic search alternative, for small project?](https://discuss.elastic.co/t/ai-powered-elastic-search-alternative-for-small-project/330261)

<div class="topic-metadata">

**Author:** [@c\_u\_be\_binh\_an](https://discuss.elastic.co/u/c_u_be_binh_an)\
**Replies:** 0\
**Last updated:** [April 19, 2023, 4:51am UTC](https://discuss.elastic.co/t/ai-powered-elastic-search-alternative-for-small-project/330261 "2023-04-19T04:51:04Z")

</div>

I am developing a job board using NodeJs and it currently has around 1,000 items. However, I am facing an issue with deploying it on a 1GB RAM VPS as it cannot run Elastic Search on it. Therefore, I am searching for a li…

---

## [Mail enable smtp activity logs](https://discuss.elastic.co/t/mail-enable-smtp-activity-logs/329672)

<div class="topic-metadata">

**Author:** [@dharminfadia](https://discuss.elastic.co/u/dharminfadia)\
**Replies:** 2\
**Last updated:** [April 19, 2023, 4:29am UTC](https://discuss.elastic.co/t/mail-enable-smtp-activity-logs/329672 "2023-04-19T04:29:45Z")

</div>

Hello everyone I am trying to pars mail enable activity loga there are millions of logs in un even pattern I write some of the pattern and logs pars in well manner ans structured but now the issue is so many logs parsin…

---

## [Move all Indexes to new host](https://discuss.elastic.co/t/move-all-indexes-to-new-host/329825)

<div class="topic-metadata">

**Author:** [@acosta353](https://discuss.elastic.co/u/acosta353)\
**Replies:** 1\
**Last updated:** [April 19, 2023, 2:14am UTC](https://discuss.elastic.co/t/move-all-indexes-to-new-host/329825 "2023-04-19T02:14:39Z")

</div>

Hello, I have a host for Warm and another to Cold Phase without replicas configured. Now, I need to proceed to a maintenance on this Warm host, so i wanted to move all those Warm Indexes temporarily to Cold host (Added …

---

## [Error generating a custom certificate and private key for Fleet Server](https://discuss.elastic.co/t/error-generating-a-custom-certificate-and-private-key-for-fleet-server/330256)

<div class="topic-metadata">

**Author:** [@Lelc79](https://discuss.elastic.co/u/Lelc79)\
**Replies:** 0\
**Last updated:** [April 19, 2023, 12:57am UTC](https://discuss.elastic.co/t/error-generating-a-custom-certificate-and-private-key-for-fleet-server/330256 "2023-04-19T00:57:13Z")

</div>

Hi Elastic community I am generating my certificates to my Fleet Server Step1 ./bin/elasticsearch-certutil ca --pem i moved my CA.cert & ca.key to /path/to/ca Step2: ./bin/elasticsearch-certutil cert --name Flee…

---

## [Cluster health wrong yellow spikes (because new index ?)](https://discuss.elastic.co/t/cluster-health-wrong-yellow-spikes-because-new-index/330124)

<div class="topic-metadata">

**Author:** [@ebuildy](https://discuss.elastic.co/u/ebuildy)\
**Replies:** 7\
**Last updated:** [April 18, 2023, 10:53pm UTC](https://discuss.elastic.co/t/cluster-health-wrong-yellow-spikes-because-new-index/330124 "2023-04-18T22:53:25Z")

</div>

We are running elasticsearch on kubernetes, via the ECK operator. Every day we receive at least 4 alerts about elasticsearch cluster health go to yellow. Also, we use argocd to deploy it, the health check script here a…

---

## [Possible Bug in Timeline: Fields containing "\\\\" string](https://discuss.elastic.co/t/possible-bug-in-timeline-fields-containing-string/330248)

<div class="topic-metadata">

**Author:** [@nemhods](https://discuss.elastic.co/u/nemhods)\
**Replies:** 0\
**Last updated:** [April 18, 2023, 8:10pm UTC](https://discuss.elastic.co/t/possible-bug-in-timeline-fields-containing-string/330248 "2023-04-18T20:10:42Z")

</div>

Hey, I just experienced a possible bug with timeline: I have found events in a timeline view. All events in my timeline have the field "winlog.event\_data.ShareName "="\\\*\\Archiv". So when I filter for this field, nothi…

---

## [Embedding kibana via fastly edge proxy](https://discuss.elastic.co/t/embedding-kibana-via-fastly-edge-proxy/330242)

<div class="topic-metadata">

**Author:** [@Shubham\_Pancholi](https://discuss.elastic.co/u/Shubham_Pancholi)\
**Replies:** 0\
**Last updated:** [April 18, 2023, 5:23pm UTC](https://discuss.elastic.co/t/embedding-kibana-via-fastly-edge-proxy/330242 "2023-04-18T17:23:33Z")

</div>

We are using Elasticsearch and kibana, we are using kibana to create dashboard which we will are embedding into our system. We don't want to use login in kibana from fontend so we are using our fastly compute edge to re…

---

## [Logstash JDBC Static Filter Can't Connect to SQLite DB](https://discuss.elastic.co/t/logstash-jdbc-static-filter-cant-connect-to-sqlite-db/330171)

<div class="topic-metadata">

**Author:** [@Dustin527](https://discuss.elastic.co/u/Dustin527)\
**Replies:** 6\
**Last updated:** [April 18, 2023, 4:52pm UTC](https://discuss.elastic.co/t/logstash-jdbc-static-filter-cant-connect-to-sqlite-db/330171 "2023-04-18T16:52:00Z")

</div>

Hi I am having trouble getting the JDBC static filter to work with an SQLite DB. I am using the xerial sqlite jdbc lib on Debian and the latest logstash package. I even have a small java program that can connect to and …

---

## [Ask For help](https://discuss.elastic.co/t/ask-for-help/330234)

<div class="topic-metadata">

**Author:** [@Farah\_Bannour](https://discuss.elastic.co/u/Farah_Bannour)\
**Replies:** 2\
**Last updated:** [April 18, 2023, 3:50pm UTC](https://discuss.elastic.co/t/ask-for-help/330234 "2023-04-18T15:50:11Z")

</div>

Good morning I'm doing an internship in Business intelligence working to collect data from odoo.sh to ELK Stack I'm working in odoo.sh. I want to ask you about the integration of the module in odoo.sh is possible or no…

---

## [Filter result by collapsed date](https://discuss.elastic.co/t/filter-result-by-collapsed-date/330235)

<div class="topic-metadata">

**Author:** [@Mickael\_BARBIER](https://discuss.elastic.co/u/Mickael_BARBIER)\
**Replies:** 0\
**Last updated:** [April 18, 2023, 3:35pm UTC](https://discuss.elastic.co/t/filter-result-by-collapsed-date/330235 "2023-04-18T15:35:32Z")

</div>

Hello, i have a topic/news system (a topic can have many news in different language) i want to get the oldest news of each topic. And i want the result sorted by the oldest news displayedAt column. ex: topic1 -News…

[Previous page](https://discuss.elastic.co/tag/none.md?no_tags=true&page=393)

[Next page](https://discuss.elastic.co/tag/none.md?no_tags=true&page=395)
