# \#none

**URL:** https://discuss.elastic.co/tag/none.md?no_tags=true&page=405

[Latest](https://discuss.elastic.co/latest.md) · [Categories](https://discuss.elastic.co/categories.md) · [Tags](https://discuss.elastic.co/tags.md)

**Page:** 406

---

## [QueryBuilders.nested() in new Java REST Client works not as expected (no "nested" attribute generated), comparing to older (deprecated) HRC](https://discuss.elastic.co/t/querybuilders-nested-in-new-java-rest-client-works-not-as-expected-no-nested-attribute-generated-comparing-to-older-deprecated-hrc/329099)

<div class="topic-metadata">

**Author:** [@Mattteo](https://discuss.elastic.co/u/Mattteo)\
**Replies:** 3\
**Last updated:** [April 3, 2023, 11:31am UTC](https://discuss.elastic.co/t/querybuilders-nested-in-new-java-rest-client-works-not-as-expected-no-nested-attribute-generated-comparing-to-older-deprecated-hrc/329099 "2023-04-03T11:31:51Z")

</div>

The problem: I am trying to upgrade from deprecated HRC (7.13) to new REST Client 8.6 in Java. We use nested queries, but although there is a special NestedQuery.Builder object in the new java client, its not possible t…

---

## [Experience with Large Memory Nodes (1TB, 2TB, and more)](https://discuss.elastic.co/t/experience-with-large-memory-nodes-1tb-2tb-and-more/329124)

<div class="topic-metadata">

**Author:** [@Michael\_Sander](https://discuss.elastic.co/u/Michael_Sander)\
**Replies:** 1\
**Last updated:** [April 3, 2023, 10:53am UTC](https://discuss.elastic.co/t/experience-with-large-memory-nodes-1tb-2tb-and-more/329124 "2023-04-03T10:53:07Z")

</div>

Google Cloud, AWS, and others are now offering nodes with 2TB or more of memory. In the past, the conventional wisdom has been to not provide Elasticsearch with more than 32GB so it uses 32 bit pointers, but I wonder if …

---

## [Creación de usuarios](https://discuss.elastic.co/t/creacion-de-usuarios/328845)

<div class="topic-metadata">

**Author:** [@JorgeGV](https://discuss.elastic.co/u/JorgeGV)\
**Replies:** 3\
**Last updated:** [April 3, 2023, 10:26am UTC](https://discuss.elastic.co/t/creacion-de-usuarios/328845 "2023-04-03T10:26:35Z")

</div>

Tengo un dashboard con información global de un país y sus respectivas regiones. Ahora quiero crear usuarios para este dashboard, pero que sólo puedan acceder a la información de su región. ¿Cómo puedo hacerlo?. Gracias …

---

## [Recommended configuration](https://discuss.elastic.co/t/recommended-configuration/329120)

<div class="topic-metadata">

**Author:** [@Noam\_Huri](https://discuss.elastic.co/u/Noam_Huri)\
**Replies:** 3\
**Last updated:** [April 3, 2023, 9:48am UTC](https://discuss.elastic.co/t/recommended-configuration/329120 "2023-04-03T09:48:59Z")

</div>

Hi, could someone please help me and guide me on how to calculate the cost or the recommended configuration that would best suit my needs? unfortunately, I'm not an IT guy :slight\_smile: Our data set consists of approx…

---

## [How to Filter Desired Container Logs in Docker Integration in Fleet？](https://discuss.elastic.co/t/how-to-filter-desired-container-logs-in-docker-integration-in-fleet/329030)

<div class="topic-metadata">

**Author:** [@XYYYYY](https://discuss.elastic.co/u/XYYYYY)\
**Replies:** 5\
**Last updated:** [April 3, 2023, 9:20am UTC](https://discuss.elastic.co/t/how-to-filter-desired-container-logs-in-docker-integration-in-fleet/329030 "2023-04-03T09:20:10Z")

</div>

Hello everyone, I am a newcomer using elastic agent. I have tried to collect container logs using Docker integration, but I have a wide variety of container logs. I only want to obtain a few of them. How can I achieve th…

---

## [Embedding iframe dashboards -auto login](https://discuss.elastic.co/t/embedding-iframe-dashboards-auto-login/329159)

<div class="topic-metadata">

**Author:** [@Sandeep\_Raju](https://discuss.elastic.co/u/Sandeep_Raju)\
**Replies:** 1\
**Last updated:** [April 3, 2023, 9:03am UTC](https://discuss.elastic.co/t/embedding-iframe-dashboards-auto-login/329159 "2023-04-03T09:03:05Z")

</div>

I want to embed my iframe dashboard links in another application. But when i embed them , it is asking for login. I cannot add login & password in my iframe link. How can i configure auto login for dashboards when it …

---

## [Elastic Dissect](https://discuss.elastic.co/t/elastic-dissect/329117)

<div class="topic-metadata">

**Author:** [@oleksiiorel](https://discuss.elastic.co/u/oleksiiorel)\
**Replies:** 5\
**Last updated:** [April 3, 2023, 8:25am UTC](https://discuss.elastic.co/t/elastic-dissect/329117 "2023-04-03T08:25:13Z")

</div>

Hi everyone :slight\_smile: How to split a single cell with a different number of strings in CVS file into separate cells (fields). Assign the names of the fields from the string itself. If I manually write the names of…

---

## [Query template that will append to existing query for further filtering out results](https://discuss.elastic.co/t/query-template-that-will-append-to-existing-query-for-further-filtering-out-results/329151)

<div class="topic-metadata">

**Author:** [@Java2avaj](https://discuss.elastic.co/u/Java2avaj)\
**Replies:** 3\
**Last updated:** [April 3, 2023, 8:23am UTC](https://discuss.elastic.co/t/query-template-that-will-append-to-existing-query-for-further-filtering-out-results/329151 "2023-04-03T08:23:02Z")

</div>

We have an existing "person" index that has "status" field in it. We have several (around 6) existing queries for retrieving person document with different parameters and logic. However, we have a new requirement that o…

---

## [Removing \\ from raw input log data](https://discuss.elastic.co/t/removing-from-raw-input-log-data/329062)

<div class="topic-metadata">

**Author:** [@Merdesz](https://discuss.elastic.co/u/Merdesz)\
**Replies:** 2\
**Last updated:** [April 3, 2023, 8:17am UTC](https://discuss.elastic.co/t/removing-from-raw-input-log-data/329062 "2023-04-03T08:17:59Z")

</div>

I have a device sending in logs which have "" before every string caracter and I would like to remove them or rewrite them to a simple ". So this " --\> " to this. Logs: srcintfrole="undefined" dstip=255.255.255.255 dst…

---

## [Call External API through Kibana](https://discuss.elastic.co/t/call-external-api-through-kibana/329169)

<div class="topic-metadata">

**Author:** [@ANUBHAV\_GUPTA](https://discuss.elastic.co/u/ANUBHAV_GUPTA)\
**Replies:** 0\
**Last updated:** [April 3, 2023, 7:24am UTC](https://discuss.elastic.co/t/call-external-api-through-kibana/329169 "2023-04-03T07:24:49Z")

</div>

Can we do something like this in Kibana:- Suppose I am querying an index with a particular document whose value is in some other format(let's say jumbled) and what I need to do is to convert it into some other format(m…

---

## [Logstash and mongodb connection error](https://discuss.elastic.co/t/logstash-and-mongodb-connection-error/329153)

<div class="topic-metadata">

**Author:** [@jskang](https://discuss.elastic.co/u/jskang)\
**Replies:** 0\
**Last updated:** [April 3, 2023, 5:50am UTC](https://discuss.elastic.co/t/logstash-and-mongodb-connection-error/329153 "2023-04-03T05:50:34Z")

</div>

input{ jdbc{ jdbc\_driver\_library =\> "/home/admin/lg-862/lgstash-core/lib/jars/mongojdbc4.8.jar" jdbc\_driver\_class =\> "Java::com.wisecoders.dbschema.mongodb.JdbcDriver" jdbc\_connection\_string =\> "mongodb://XXXXXX:XXXX…

---

## [Kibana bar chart aggr query doc\_count](https://discuss.elastic.co/t/kibana-bar-chart-aggr-query-doc-count/329149)

<div class="topic-metadata">

**Author:** [@math1](https://discuss.elastic.co/u/math1)\
**Replies:** 4\
**Last updated:** [April 3, 2023, 5:44am UTC](https://discuss.elastic.co/t/kibana-bar-chart-aggr-query-doc-count/329149 "2023-04-03T05:44:38Z")

</div>

I want to draw the query statement below as a bar chart in Kibana. GET food\_info/\_search { "size": 0, "aggs": { "country": { "terms": { "field": "food.countryCode" }, "aggs": { …

---

## [Can't match string to format date](https://discuss.elastic.co/t/cant-match-string-to-format-date/329132)

<div class="topic-metadata">

**Author:** [@german](https://discuss.elastic.co/u/german)\
**Replies:** 4\
**Last updated:** [April 3, 2023, 3:30am UTC](https://discuss.elastic.co/t/cant-match-string-to-format-date/329132 "2023-04-03T03:30:23Z")

</div>

Hi everybody, I have a problem while I try to convert a string variable to timestamp. I'm using date module without successful result. Format date is dd/MM/yyyy hh:mm:ss.SSSSSS and originally the variable newDate is: …

---

## [Synthetics monitors are not working on Elastic Agent (Complete)](https://discuss.elastic.co/t/synthetics-monitors-are-not-working-on-elastic-agent-complete/328978)

<div class="topic-metadata">

**Author:** [@chrispangg](https://discuss.elastic.co/u/chrispangg)\
**Replies:** 1\
**Last updated:** [April 3, 2023, 12:31am UTC](https://discuss.elastic.co/t/synthetics-monitors-are-not-working-on-elastic-agent-complete/328978 "2023-04-03T00:31:15Z")

</div>

The Elastic Agent is running within a container, just like the rest of the stack, in my local environment. Tried this across different versions (on 8.7 now) and they all come back with the same error. Elastic Agent - Do…

---

## [Help with using Grok to parse these three log formats](https://discuss.elastic.co/t/help-with-using-grok-to-parse-these-three-log-formats/329107)

<div class="topic-metadata">

**Author:** [@roman-tasi](https://discuss.elastic.co/u/roman-tasi)\
**Replies:** 8\
**Last updated:** [April 2, 2023, 10:37pm UTC](https://discuss.elastic.co/t/help-with-using-grok-to-parse-these-three-log-formats/329107 "2023-04-02T22:37:55Z")

</div>

Hi I am experienced with Dissect but not Grok. I think I need to use Grok here because the log format varies between the logs, so dissect will only work on one format, not all three: Case 1: 2023-03-31 00:01:24,366 INF…

---

## [Users and Groups export](https://discuss.elastic.co/t/users-and-groups-export/329133)

<div class="topic-metadata">

**Author:** [@mruthyu](https://discuss.elastic.co/u/mruthyu)\
**Replies:** 0\
**Last updated:** [April 2, 2023, 6:47pm UTC](https://discuss.elastic.co/t/users-and-groups-export/329133 "2023-04-02T18:47:26Z")

</div>

Is it possible to export and import users and groups from Kibana, so that these can be managed in multiple life cycle environments? or the user and role related apis needs to be used?

---

## [Enhanced data table slow response in comparison to kibana discover search?](https://discuss.elastic.co/t/enhanced-data-table-slow-response-in-comparison-to-kibana-discover-search/329047)

<div class="topic-metadata">

**Author:** [@PRASHANT\_MEHTA](https://discuss.elastic.co/u/PRASHANT_MEHTA)\
**Replies:** 3\
**Last updated:** [April 2, 2023, 4:49pm UTC](https://discuss.elastic.co/t/enhanced-data-table-slow-response-in-comparison-to-kibana-discover-search/329047 "2023-04-02T16:49:55Z")

</div>

Hello @fbaligand , Can you please let me understand why enhanced table/document table provides data slow or sometime hangs when filtered for huge data. Example 1 month data fetch,document count 20 million(here the data…

---

## [Getting Peak day and corresponding count based on last 30 days data](https://discuss.elastic.co/t/getting-peak-day-and-corresponding-count-based-on-last-30-days-data/329126)

<div class="topic-metadata">

**Author:** [@Yadhav](https://discuss.elastic.co/u/Yadhav)\
**Replies:** 0\
**Last updated:** [April 2, 2023, 3:05pm UTC](https://discuss.elastic.co/t/getting-peak-day-and-corresponding-count-based-on-last-30-days-data/329126 "2023-04-02T15:05:49Z")

</div>

Hi, I have requirement to get max of count value along with its date in last 7 days time frame. Below is my kibana visualization setting. Here I need to get max of count value along with its date. Seeing forward to…

---

## [Upstream prematurely closed connection while connecting to Kibana](https://discuss.elastic.co/t/upstream-prematurely-closed-connection-while-connecting-to-kibana/329056)

<div class="topic-metadata">

**Author:** [@Ravi\_Prakash1](https://discuss.elastic.co/u/Ravi_Prakash1)\
**Replies:** 1\
**Last updated:** [April 2, 2023, 2:26pm UTC](https://discuss.elastic.co/t/upstream-prematurely-closed-connection-while-connecting-to-kibana/329056 "2023-04-02T14:26:03Z")

</div>

Hello , Need some help with issue which we are facing while connecting to Kibana via Nginx using proxy\_pass. We are using ECK operator on Openshift ( Elasticsearch (ECK) Operator 2.6.2 provided by Elastic ) . While d…

---

## [Timestamp search between two fields](https://discuss.elastic.co/t/timestamp-search-between-two-fields/329048)

<div class="topic-metadata">

**Author:** [@Farah\_Bhr](https://discuss.elastic.co/u/Farah_Bhr)\
**Replies:** 4\
**Last updated:** [April 2, 2023, 11:32am UTC](https://discuss.elastic.co/t/timestamp-search-between-two-fields/329048 "2023-04-02T11:32:53Z")

</div>

In my use case, I created two fields for the values of start\_time and end\_time based on some indicators in the log lines with kibana discover , I want to search for all the log lines that their timestamp is between thes…

---

## [Elastic Filter](https://discuss.elastic.co/t/elastic-filter/329104)

<div class="topic-metadata">

**Author:** [@oleksiiorel](https://discuss.elastic.co/u/oleksiiorel)\
**Replies:** 8\
**Last updated:** [April 1, 2023, 4:57pm UTC](https://discuss.elastic.co/t/elastic-filter/329104 "2023-04-01T16:57:52Z")

</div>

I import a csv file via logstash "filter cvs" into Elasticsearch. One of the cells in a table (CVS file) contains several strings example: (categoty, subcategory, sub\_subcategory). I would like to split these strings int…

---

## [Master not discovered yet, this node has not previously joined a bootstrapped](https://discuss.elastic.co/t/master-not-discovered-yet-this-node-has-not-previously-joined-a-bootstrapped/329093)

<div class="topic-metadata">

**Author:** [@williamsun](https://discuss.elastic.co/u/williamsun)\
**Replies:** 1\
**Last updated:** [April 1, 2023, 6:20am UTC](https://discuss.elastic.co/t/master-not-discovered-yet-this-node-has-not-previously-joined-a-bootstrapped/329093 "2023-04-01T06:20:37Z")

</div>

My issue is related to the last post. Master not discovered yet, this node has not previously joined a bootstrapped ====== I installed Elasticsearch 8.7.0 on AWS EKS 1.23 with three master Pods, three Data Pods and tw…

---

## [Elastic Defend - impact on application](https://discuss.elastic.co/t/elastic-defend-impact-on-application/328880)

<div class="topic-metadata">

**Author:** [@GKre](https://discuss.elastic.co/u/GKre)\
**Replies:** 1\
**Last updated:** [April 1, 2023, 4:48am UTC](https://discuss.elastic.co/t/elastic-defend-impact-on-application/328880 "2023-04-01T04:48:50Z")

</div>

Hello, i deployed Elastic Defend Integration on my endpoints and also on my two DC's. One of the DC's is hosting go1984 - a video surveilance application i use since many years. Soon after the Integration had been dep…

---

## [How can I join or paste array elements as of a one element?](https://discuss.elastic.co/t/how-can-i-join-or-paste-array-elements-as-of-a-one-element/329089)

<div class="topic-metadata">

**Author:** [@german](https://discuss.elastic.co/u/german)\
**Replies:** 2\
**Last updated:** [April 1, 2023, 3:08am UTC](https://discuss.elastic.co/t/how-can-i-join-or-paste-array-elements-as-of-a-one-element/329089 "2023-04-01T03:08:19Z")

</div>

Hi everybody, First of all, thanks for your time. I have a question regarding to Logstash. I would like to join some array elements as of a specific element. The log that I am processing, the first six fields have the …

---

## [Update Existing document through logstash](https://discuss.elastic.co/t/update-existing-document-through-logstash/329077)

<div class="topic-metadata">

**Author:** [@rubhamra](https://discuss.elastic.co/u/rubhamra)\
**Replies:** 4\
**Last updated:** [March 31, 2023, 8:40pm UTC](https://discuss.elastic.co/t/update-existing-document-through-logstash/329077 "2023-03-31T20:40:21Z")

</div>

logstash pipeline is not updating existing document for the same id, I have couples of fields which got updated frequestly for example Last Modified Date. I have below logstash config. output { elasticsearch { …

---

## [Data stream timestamp in the name of index](https://discuss.elastic.co/t/data-stream-timestamp-in-the-name-of-index/329080)

<div class="topic-metadata">

**Author:** [@INS](https://discuss.elastic.co/u/INS)\
**Replies:** 1\
**Last updated:** [March 31, 2023, 8:25pm UTC](https://discuss.elastic.co/t/data-stream-timestamp-in-the-name-of-index/329080 "2023-03-31T20:25:48Z")

</div>

Hi Is it possible to achieve name with timestamp from ingest data to elasticsearch in the index name like .ds-\<data-stream\>-\<yyyy.MM.dd\>-\<generation\> .ds-\<data-stream\>\<mytimestamp\_from\_log\>-\<generation\> I've tried to…

---

## [Kibana not give logs](https://discuss.elastic.co/t/kibana-not-give-logs/328695)

<div class="topic-metadata">

**Author:** [@Prabhath\_samarasingh](https://discuss.elastic.co/u/Prabhath_samarasingh)\
**Replies:** 7\
**Last updated:** [March 31, 2023, 8:13pm UTC](https://discuss.elastic.co/t/kibana-not-give-logs/328695 "2023-03-31T20:13:11Z")

</div>

Configured basic ELK set up.But my kibana interface had no logs. This is the guide I followed. What is the mistake I have done. Installing and Configuring Elasticsearch curl -fsSL https://artifacts.elastic.co/GPG-KEY…

---

## [Reading date format in logstash date filter](https://discuss.elastic.co/t/reading-date-format-in-logstash-date-filter/329070)

<div class="topic-metadata">

**Author:** [@UsmanNiazi](https://discuss.elastic.co/u/UsmanNiazi)\
**Replies:** 7\
**Last updated:** [March 31, 2023, 7:45pm UTC](https://discuss.elastic.co/t/reading-date-format-in-logstash-date-filter/329070 "2023-03-31T19:45:21Z")

</div>

Hi, I am unable to convert this string "03/31/2023 03:15 AM PDT" to date when using logstash date filter. Getting error dateparse failure. I am using below script date { match =\> \[ "start\_time", "mm/dd/yyyy HH:mm Z",…

---

## [Elasticsearch Malformed Query, Expected \[END\_OBJECT\] but found \[Field\_Name\]](https://discuss.elastic.co/t/elasticsearch-malformed-query-expected-end-object-but-found-field-name/329072)

<div class="topic-metadata">

**Author:** [@elrozario](https://discuss.elastic.co/u/elrozario)\
**Replies:** 2\
**Last updated:** [March 31, 2023, 7:33pm UTC](https://discuss.elastic.co/t/elasticsearch-malformed-query-expected-end-object-but-found-field-name/329072 "2023-03-31T19:33:54Z")

</div>

Hello, I am trying to run reindex with query but getting the error Malformed Query, Expected \[END\_OBJECT\] but found \[Field\_Name\]. { "source": { "index": "index-\*", "\_source" : \[ "@timestamp", "message"\], …

---

## [Elastic Search Api with Python](https://discuss.elastic.co/t/elastic-search-api-with-python/329009)

<div class="topic-metadata">

**Author:** [@Sharath\_B.S](https://discuss.elastic.co/u/Sharath_B.S)\
**Replies:** 2\
**Last updated:** [March 31, 2023, 6:45pm UTC](https://discuss.elastic.co/t/elastic-search-api-with-python/329009 "2023-03-31T18:45:31Z")

</div>

Im trying to sort the search results according to the date in ascending order. it would be helpful if i could get to know how to sort the results according to the date.

[Previous page](https://discuss.elastic.co/tag/none.md?no_tags=true&page=404)

[Next page](https://discuss.elastic.co/tag/none.md?no_tags=true&page=406)
