# \#none

**URL:** https://discuss.elastic.co/tag/none.md?no_tags=true&page=396

[Latest](https://discuss.elastic.co/latest.md) · [Categories](https://discuss.elastic.co/categories.md) · [Tags](https://discuss.elastic.co/tags.md)

**Page:** 397

---

## [I am using the Sysmon-\> logstash -\> elasticsearch (ELK) architecture issues](https://discuss.elastic.co/t/i-am-using-the-sysmon-logstash-elasticsearch-elk-architecture-issues/330076)

<div class="topic-metadata">

**Author:** [@iqworks](https://discuss.elastic.co/u/iqworks)\
**Replies:** 0\
**Last updated:** [April 15, 2023, 11:14pm UTC](https://discuss.elastic.co/t/i-am-using-the-sysmon-logstash-elasticsearch-elk-architecture-issues/330076 "2023-04-15T23:14:36Z")

</div>

Hi, I am trying to use sysmon to logstash to elasticsearch. After advice from others in this forum, I finally came up with a combination of parms and processing that at least shows me data from my laptop IP in kibana. T…

---

## [Kibana not connecting on browser](https://discuss.elastic.co/t/kibana-not-connecting-on-browser/330148)

<div class="topic-metadata">

**Author:** [@Cyberpwc](https://discuss.elastic.co/u/Cyberpwc)\
**Replies:** 1\
**Last updated:** [April 17, 2023, 9:09pm UTC](https://discuss.elastic.co/t/kibana-not-connecting-on-browser/330148 "2023-04-17T21:09:20Z")

</div>

Hi, I'm new to the ELK stack and currently trying to configure Kibana however I am encountering an error regarding some security authentication issue. This is the Kibana log showing the error: Apr 17 16:56:52 CyberELK …

---

## [Error starting watcher](https://discuss.elastic.co/t/error-starting-watcher/330143)

<div class="topic-metadata">

**Author:** [@6igwig](https://discuss.elastic.co/u/6igwig)\
**Replies:** 1\
**Last updated:** [April 17, 2023, 6:34pm UTC](https://discuss.elastic.co/t/error-starting-watcher/330143 "2023-04-17T18:34:28Z")

</div>

We upgraded to 8.7.0 yesterday, since then none of our watchers have executed. We just keep getting this message in the elastic logs: error starting watcher I tried deleting the extra .watcher-history-\* indices via upda…

---

## [Limiting data in object properties coming to browser from elastic search](https://discuss.elastic.co/t/limiting-data-in-object-properties-coming-to-browser-from-elastic-search/329958)

<div class="topic-metadata">

**Author:** [@Akaash\_Mukherjee](https://discuss.elastic.co/u/Akaash_Mukherjee)\
**Replies:** 6\
**Last updated:** [April 17, 2023, 6:33pm UTC](https://discuss.elastic.co/t/limiting-data-in-object-properties-coming-to-browser-from-elastic-search/329958 "2023-04-17T18:33:07Z")

</div>

Hi, We are currently pulling large amounts of data from Elasticsearch for reporting products in our software. For our larger clients this means sending a large amount of data to the browser which is then loaded into a r…

---

## [Kibana 8.7 expensive queries](https://discuss.elastic.co/t/kibana-8-7-expensive-queries/330120)

<div class="topic-metadata">

**Author:** [@Jonas\_S](https://discuss.elastic.co/u/Jonas_S)\
**Replies:** 3\
**Last updated:** [April 17, 2023, 6:32pm UTC](https://discuss.elastic.co/t/kibana-8-7-expensive-queries/330120 "2023-04-17T18:32:35Z")

</div>

Hello, after upgrading Elastic and Kibana to 8.7 i get reports from users that they are seeing this: Combined with missing values in the control. If they type the value they are missing in the search field of the con…

---

## [Kibana 8.7 Control Sort](https://discuss.elastic.co/t/kibana-8-7-control-sort/329758)

<div class="topic-metadata">

**Author:** [@Jonas\_S](https://discuss.elastic.co/u/Jonas_S)\
**Replies:** 4\
**Last updated:** [April 17, 2023, 4:30pm UTC](https://discuss.elastic.co/t/kibana-8-7-control-sort/329758 "2023-04-17T16:30:35Z")

</div>

Hello, i just checked out the new sorting functionallity for controls. The default setting is to sort desc by doc count I want asc alphabetically on every control. How can i change that in an easy way? I could not …

---

## [Elasticsearch Transformed index and its dashboard](https://discuss.elastic.co/t/elasticsearch-transformed-index-and-its-dashboard/329827)

<div class="topic-metadata">

**Author:** [@rvadiga](https://discuss.elastic.co/u/rvadiga)\
**Replies:** 3\
**Last updated:** [April 17, 2023, 3:33pm UTC](https://discuss.elastic.co/t/elasticsearch-transformed-index-and-its-dashboard/329827 "2023-04-17T15:33:46Z")

</div>

Hi, I am building a Kibana dashboard using an transformed index. What I have observed is for every field change in ES transform, I need to create a new dashboard as object is deleted when deleting the ES transform. C…

---

## [How to display the last date on a grouping set](https://discuss.elastic.co/t/how-to-display-the-last-date-on-a-grouping-set/329854)

<div class="topic-metadata">

**Author:** [@FTOR](https://discuss.elastic.co/u/FTOR)\
**Replies:** 2\
**Last updated:** [April 17, 2023, 2:45pm UTC](https://discuss.elastic.co/t/how-to-display-the-last-date-on-a-grouping-set/329854 "2023-04-17T14:45:02Z")

</div>

Hello, I am working on a dashboard, and I would like to show the last date on a grouping set. I take the kibana\_sample\_data\_ecommerce as example. Attachedn an example of row part. I would like to group by product\_id…

---

## [Help pattern for multiline logs](https://discuss.elastic.co/t/help-pattern-for-multiline-logs/330134)

<div class="topic-metadata">

**Author:** [@JackieLaFrite](https://discuss.elastic.co/u/JackieLaFrite)\
**Replies:** 4\
**Last updated:** [April 17, 2023, 2:41pm UTC](https://discuss.elastic.co/t/help-pattern-for-multiline-logs/330134 "2023-04-17T14:41:54Z")

</div>

What pattern should I use to retrieve correctly multi-lines logs ? Normally I use : file { path =\> "/var/log/appslogs/\*\*/\*.log" start\_position =\> "beginning" sincedb\_path =\> "/dev/null" codec =\> multili…

---

## [Use reciprocal ranking fusion to combine the results of two queries](https://discuss.elastic.co/t/use-reciprocal-ranking-fusion-to-combine-the-results-of-two-queries/329614)

<div class="topic-metadata">

**Author:** [@flando](https://discuss.elastic.co/u/flando)\
**Replies:** 1\
**Last updated:** [April 17, 2023, 2:32pm UTC](https://discuss.elastic.co/t/use-reciprocal-ranking-fusion-to-combine-the-results-of-two-queries/329614 "2023-04-17T14:32:21Z")

</div>

Hi everyone, I'm trying to use reciprocal ranking fusion (RRF) to combine the results of two query performed with the following code: GET /books\_index/\_search { "query": { "bool": { "should": \[ { …

---

## [Perform aggregation on a modified term](https://discuss.elastic.co/t/perform-aggregation-on-a-modified-term/330141)

<div class="topic-metadata">

**Author:** [@manropinxu](https://discuss.elastic.co/u/manropinxu)\
**Replies:** 0\
**Last updated:** [April 17, 2023, 2:11pm UTC](https://discuss.elastic.co/t/perform-aggregation-on-a-modified-term/330141 "2023-04-17T14:11:29Z")

</div>

I'd like to perform an aggregation grouping by a modified version of amessage field. I have lots of messages like invalid x with uuid=1e659cfc-a375-4a8a-88f5-467419fdf87d invalid x with uuid=49c4742e-0368-49a2-aab4-7f…

---

## [Problems Accessing Kibana Lab](https://discuss.elastic.co/t/problems-accessing-kibana-lab/329545)

<div class="topic-metadata">

**Author:** [@ltan](https://discuss.elastic.co/u/ltan)\
**Replies:** 2\
**Last updated:** [April 17, 2023, 1:31pm UTC](https://discuss.elastic.co/t/problems-accessing-kibana-lab/329545 "2023-04-17T13:31:01Z")

</div>

Hi, I am currently enrolled in the Data Analysis with Kibana on-demand course. I have been trying to use the lab environment to use Kibana. But I have been getting multiple issues such as 'kibana server is not ready ye…

---

## [CVE-2022-1471 is not listed in Security Issues site](https://discuss.elastic.co/t/cve-2022-1471-is-not-listed-in-security-issues-site/330110)

<div class="topic-metadata">

**Author:** [@Mike\_Joseph](https://discuss.elastic.co/u/Mike_Joseph)\
**Replies:** 1\
**Last updated:** [April 17, 2023, 1:24pm UTC](https://discuss.elastic.co/t/cve-2022-1471-is-not-listed-in-security-issues-site/330110 "2023-04-17T13:24:13Z")

</div>

Continuing the discussion from Snakeyaml vulnerability (CVE-2022-1471) on latest ES version: @DavidTurner Forwarded the topic to Security issues but it is still not addressed in the site.

---

## [How to enable CORS for all possible connections?](https://discuss.elastic.co/t/how-to-enable-cors-for-all-possible-connections/330135)

<div class="topic-metadata">

**Author:** [@Eduard\_mart](https://discuss.elastic.co/u/Eduard_mart)\
**Replies:** 0\
**Last updated:** [April 17, 2023, 1:12pm UTC](https://discuss.elastic.co/t/how-to-enable-cors-for-all-possible-connections/330135 "2023-04-17T13:12:12Z")

</div>

How to enable CORS for all possible connections?

---

## [Failed to start Elasticsearch](https://discuss.elastic.co/t/failed-to-start-elasticsearch/330061)

<div class="topic-metadata">

**Author:** [@Hugo\_Demont](https://discuss.elastic.co/u/Hugo_Demont)\
**Replies:** 1\
**Last updated:** [April 17, 2023, 1:03pm UTC](https://discuss.elastic.co/t/failed-to-start-elasticsearch/330061 "2023-04-17T13:03:10Z")

</div>

Hello ! I'm try to run elasticsearch on my linux computer to download Magento 2 when I try sudo systemctl start elasticsearch I get an error and I dont know how to solve it :confused: Error : \`avril 15 10:34:55 demon…

---

## [Clarification on end of maintenance of elastic search 8.x](https://discuss.elastic.co/t/clarification-on-end-of-maintenance-of-elastic-search-8-x/330129)

<div class="topic-metadata">

**Author:** [@mohammed\_rizwan](https://discuss.elastic.co/u/mohammed_rizwan)\
**Replies:** 1\
**Last updated:** [April 17, 2023, 12:55pm UTC](https://discuss.elastic.co/t/clarification-on-end-of-maintenance-of-elastic-search-8-x/330129 "2023-04-17T12:55:01Z")

</div>

Hi team, From the Elasticsearch link Elastic Product End of Life Dates | Elastic, the Elasticsearch (8.x) end of maintenance is mentioned as "The later of 2024-08-10 or 6 months after the release date of 9.0 (TBD)". Is…

---

## [Can't sort by column/field in Kabana](https://discuss.elastic.co/t/cant-sort-by-column-field-in-kabana/329929)

<div class="topic-metadata">

**Author:** [@JackieLaFrite](https://discuss.elastic.co/u/JackieLaFrite)\
**Replies:** 4\
**Last updated:** [April 17, 2023, 8:31am UTC](https://discuss.elastic.co/t/cant-sort-by-column-field-in-kabana/329929 "2023-04-17T08:31:29Z")

</div>

Hello, I'm currently implementing ELK on my environment to retrieve the logs and I got a problem. In the discover tab, I can't sort a column. I can only sort by the @Timestamp. I would like to be able to sort by the…

---

## [Recommended RAM/CPU size for hot data nodes in gcp](https://discuss.elastic.co/t/recommended-ram-cpu-size-for-hot-data-nodes-in-gcp/330119)

<div class="topic-metadata">

**Author:** [@alok.nashikkar](https://discuss.elastic.co/u/alok.nashikkar)\
**Replies:** 1\
**Last updated:** [April 17, 2023, 11:16am UTC](https://discuss.elastic.co/t/recommended-ram-cpu-size-for-hot-data-nodes-in-gcp/330119 "2023-04-17T11:16:30Z")

</div>

Hello, I am exploring recommendations for infra sizing for Elasticsearch hot data nodes in GCP with recommendations for CPU and RAM for probably 3 TB SSD with machine types ex n2d/e2 or some other in similar performance…

---

## [Logstash throws java.lang.OutOfMemoryError: Java heap space no matter the heap size](https://discuss.elastic.co/t/logstash-throws-java-lang-outofmemoryerror-java-heap-space-no-matter-the-heap-size/330089)

<div class="topic-metadata">

**Author:** [@ste1](https://discuss.elastic.co/u/ste1)\
**Replies:** 6\
**Last updated:** [April 17, 2023, 10:57am UTC](https://discuss.elastic.co/t/logstash-throws-java-lang-outofmemoryerror-java-heap-space-no-matter-the-heap-size/330089 "2023-04-17T10:57:36Z")

</div>

Im attempting to parse a huge (few million lines) csv file with logstash and output it to elasticsearch. \[FATAL\] 2023-04-16 19:00:19.011 \[LogStash::Runner\] Logstash - java.lang.OutOfMemoryError: Java heap space …

---

## [Elasticsearch Transform API - Trying to Script a Moving Average](https://discuss.elastic.co/t/elasticsearch-transform-api-trying-to-script-a-moving-average/330115)

<div class="topic-metadata">

**Author:** [@Silver137](https://discuss.elastic.co/u/Silver137)\
**Replies:** 0\
**Last updated:** [April 17, 2023, 10:43am UTC](https://discuss.elastic.co/t/elasticsearch-transform-api-trying-to-script-a-moving-average/330115 "2023-04-17T10:43:09Z")

</div>

My use case requieres keeping the moving average over hours withing a windows of the last 12 hours, every time the transofrm is executed. It's possible to use the "pivot" "group by" to program a transform that keeps tra…

---

## [Is it possible to have a variable scripted field which changes based on Kibana Dashboard selection?](https://discuss.elastic.co/t/is-it-possible-to-have-a-variable-scripted-field-which-changes-based-on-kibana-dashboard-selection/329908)

<div class="topic-metadata">

**Author:** [@stramzik](https://discuss.elastic.co/u/stramzik)\
**Replies:** 2\
**Last updated:** [April 17, 2023, 10:15am UTC](https://discuss.elastic.co/t/is-it-possible-to-have-a-variable-scripted-field-which-changes-based-on-kibana-dashboard-selection/329908 "2023-04-17T10:15:46Z")

</div>

Hi, Is it possible to have a variable scripted field which changes based on Kibana Dashboard selection? I want a scripted field which changes to true of false based on kibana lens selection on the dashboard.

---

## [Kibana helmchart throws error](https://discuss.elastic.co/t/kibana-helmchart-throws-error/330101)

<div class="topic-metadata">

**Author:** [@arun\_udaiyar](https://discuss.elastic.co/u/arun_udaiyar)\
**Replies:** 1\
**Last updated:** [April 17, 2023, 8:40am UTC](https://discuss.elastic.co/t/kibana-helmchart-throws-error/330101 "2023-04-17T08:40:19Z")

</div>

Hi Team, I have used helmchart to deploy the stack and i have created own self-signed using openssl as per the documentation. seems fine for master, data and client communication. root@N81111:/mnt/d/elasticsearch# kub…

---

## [Alerts in a Cluster](https://discuss.elastic.co/t/alerts-in-a-cluster/330003)

<div class="topic-metadata">

**Author:** [@Joel\_Goncalves1](https://discuss.elastic.co/u/Joel_Goncalves1)\
**Replies:** 2\
**Last updated:** [April 17, 2023, 8:27am UTC](https://discuss.elastic.co/t/alerts-in-a-cluster/330003 "2023-04-17T08:27:08Z")

</div>

Is it possible to create a cluster and each node configure rules and when an alert is heard in a node, this alert is replicated to a master node? But I didn't want alerts from other nodes or master's alerts to be replica…

---

## [Multiple lines Canva Kibana](https://discuss.elastic.co/t/multiple-lines-canva-kibana/329926)

<div class="topic-metadata">

**Author:** [@Julie\_Gils](https://discuss.elastic.co/u/Julie_Gils)\
**Replies:** 2\
**Last updated:** [April 17, 2023, 7:45am UTC](https://discuss.elastic.co/t/multiple-lines-canva-kibana/329926 "2023-04-17T07:45:33Z")

</div>

Hi, I have several data that are calculated like this: I just wanna have the number of process by step. Data used (with aggregation) look like : And I want the chart looks like : but with canva line chart. At …

---

## [Ece & openshift](https://discuss.elastic.co/t/ece-openshift/329895)

<div class="topic-metadata">

**Author:** [@steman-provinzial](https://discuss.elastic.co/u/steman-provinzial)\
**Replies:** 2\
**Last updated:** [April 17, 2023, 6:00am UTC](https://discuss.elastic.co/t/ece-openshift/329895 "2023-04-17T06:00:39Z")

</div>

Hi there, I am new to ece - just made a small test installation. I know there is a another flavour called eck. My question: Is there alreadey an ece running on / with openshift? Thank you and kind regards Stefano

---

## [Document size, weight and performance in an automatic mapping and improve it afterwards manually](https://discuss.elastic.co/t/document-size-weight-and-performance-in-an-automatic-mapping-and-improve-it-afterwards-manually/330085)

<div class="topic-metadata">

**Author:** [@martel](https://discuss.elastic.co/u/martel)\
**Replies:** 3\
**Last updated:** [April 17, 2023, 5:13am UTC](https://discuss.elastic.co/t/document-size-weight-and-performance-in-an-automatic-mapping-and-improve-it-afterwards-manually/330085 "2023-04-17T05:13:21Z")

</div>

Is it possible to know the weight of a document in terms of bytes, to know the impact index in terms of indexing? All this in order to better optimize, to know how to configure a mapping of fields in such and such a way…

---

## [Metricbeat Azure Module - unable to get metrices of MSSQL Database Account](https://discuss.elastic.co/t/metricbeat-azure-module-unable-to-get-metrices-of-mssql-database-account/330091)

<div class="topic-metadata">

**Author:** [@vin89](https://discuss.elastic.co/u/vin89)\
**Replies:** 0\
**Last updated:** [April 17, 2023, 3:09am UTC](https://discuss.elastic.co/t/metricbeat-azure-module-unable-to-get-metrices-of-mssql-database-account/330091 "2023-04-17T03:09:58Z")

</div>

Hi, We are trying to implement metricbeat for our Azure resources where we are using Azure Module provided by metricbeat itself. Here we are facing a challenge that we are not able to capture MSSQL database metrices fro…

---

## [Send logs from filebeat to elastic search](https://discuss.elastic.co/t/send-logs-from-filebeat-to-elastic-search/330078)

<div class="topic-metadata">

**Author:** [@Abdolah\_Said](https://discuss.elastic.co/u/Abdolah_Said)\
**Replies:** 0\
**Last updated:** [April 16, 2023, 6:53am UTC](https://discuss.elastic.co/t/send-logs-from-filebeat-to-elastic-search/330078 "2023-04-16T06:53:10Z")

</div>

i'm using winlogbeat to send log to logstash and i store logs in file path \[ /var/log/file.log \] and i have file beat in this server who send logs from the path to elasticsearch the problem is the elasticsearch show logs…

---

## [One saved Discover search without "Time"](https://discuss.elastic.co/t/one-saved-discover-search-without-time/328258)

<div class="topic-metadata">

**Author:** [@ppic](https://discuss.elastic.co/u/ppic)\
**Replies:** 3\
**Last updated:** [April 15, 2023, 5:41pm UTC](https://discuss.elastic.co/t/one-saved-discover-search-without-time/328258 "2023-04-15T17:41:02Z")

</div>

Hello, In a dashboard, I need to display a table with 2 fields, with text as it is in Discover. I found it was possible with a saved search in Discover, and then in the dashboard: Add from library the saved search. …

---

## [Query questions (autocomplete)](https://discuss.elastic.co/t/query-questions-autocomplete/330047)

<div class="topic-metadata">

**Author:** [@tallboy](https://discuss.elastic.co/u/tallboy)\
**Replies:** 0\
**Last updated:** [April 14, 2023, 10:02pm UTC](https://discuss.elastic.co/t/query-questions-autocomplete/330047 "2023-04-14T22:02:17Z")

</div>

Hello, I am trying to craft a query which will allow a realtime search dropdown: My search data has 3 columns: name (text) alternate\_names (array of text) description (text) The only column which shows in the dro…

[Previous page](https://discuss.elastic.co/tag/none.md?no_tags=true&page=395)

[Next page](https://discuss.elastic.co/tag/none.md?no_tags=true&page=397)
