# \#none

**URL:** https://discuss.elastic.co/tag/none.md?no_tags=true&page=422

[Latest](https://discuss.elastic.co/latest.md) · [Categories](https://discuss.elastic.co/categories.md) · [Tags](https://discuss.elastic.co/tags.md)

**Page:** 423

---

## [Configuracion del Node.Roles \[master\]](https://discuss.elastic.co/t/configuracion-del-node-roles-master/327098)

<div class="topic-metadata">

**Author:** [@LeonardoCord](https://discuss.elastic.co/u/LeonardoCord)\
**Replies:** 5\
**Last updated:** [March 7, 2023, 9:33pm UTC](https://discuss.elastic.co/t/configuracion-del-node-roles-master/327098 "2023-03-07T21:33:11Z")

</div>

Buenas Estoy tratando de configurar el Node.Roles \[master\] debido a que es una configuracion obsoleta en la version que tengo 7.17.6 y he configurado mi .YML pero a la hora de correrlo mi elastic no arranca.

---

## [Importing multiple large csv and json files into a single index](https://discuss.elastic.co/t/importing-multiple-large-csv-and-json-files-into-a-single-index/326738)

<div class="topic-metadata">

**Author:** [@mansi\_raval](https://discuss.elastic.co/u/mansi_raval)\
**Replies:** 10\
**Last updated:** [March 7, 2023, 9:29pm UTC](https://discuss.elastic.co/t/importing-multiple-large-csv-and-json-files-into-a-single-index/326738 "2023-03-07T21:29:17Z")

</div>

I have an folder containing data (20 GB) and this folder contains 26 subfolders that are sorted city-wise. Each of these subfolder contain many more subfolders comprising of csv and json files (The data that is stored in…

---

## [Disk size and performance optimization for Elasticsearch cluster](https://discuss.elastic.co/t/disk-size-and-performance-optimization-for-elasticsearch-cluster/327071)

<div class="topic-metadata">

**Author:** [@yago82](https://discuss.elastic.co/u/yago82)\
**Replies:** 1\
**Last updated:** [March 7, 2023, 9:20pm UTC](https://discuss.elastic.co/t/disk-size-and-performance-optimization-for-elasticsearch-cluster/327071 "2023-03-07T21:20:48Z")

</div>

Hi everyone, I'm currently running an Elasticsearch cluster with 6 nodes, and (for every node) the disk usage is around 5.5 TB out of a total disk size of 20 TB. I don't anticipate a significant increase in data storag…

---

## [Logs definition](https://discuss.elastic.co/t/logs-definition/327211)

<div class="topic-metadata">

**Author:** [@Stefan7](https://discuss.elastic.co/u/Stefan7)\
**Replies:** 4\
**Last updated:** [March 7, 2023, 8:01pm UTC](https://discuss.elastic.co/t/logs-definition/327211 "2023-03-07T20:01:45Z")

</div>

Greetings, Can someone please direct me to a location where I can find a definition of logs? Here's a preliminary list that I am trying to clarify: 'logs-elastic\_agent' 'metrics-elastic\_agent.elastic\_agent ' 'logs-e…

---

## [Elasticsearch monitor with metricbeat](https://discuss.elastic.co/t/elasticsearch-monitor-with-metricbeat/327223)

<div class="topic-metadata">

**Author:** [@elasticforme](https://discuss.elastic.co/u/elasticforme)\
**Replies:** 4\
**Last updated:** [March 7, 2023, 7:26pm UTC](https://discuss.elastic.co/t/elasticsearch-monitor-with-metricbeat/327223 "2023-03-07T19:26:47Z")

</div>

I am so crazy confuse on this setup. can't seems to make it work. this is my test setup that I am trying and getting more confuse every min. here is my configuration. monitor cluster:: elkdev11 monitoring cluster: …

---

## [Extracting year in short format from the log file name](https://discuss.elastic.co/t/extracting-year-in-short-format-from-the-log-file-name/327172)

<div class="topic-metadata">

**Author:** [@lupsya](https://discuss.elastic.co/u/lupsya)\
**Replies:** 1\
**Last updated:** [March 7, 2023, 5:38pm UTC](https://discuss.elastic.co/t/extracting-year-in-short-format-from-the-log-file-name/327172 "2023-03-07T17:38:01Z")

</div>

Hello, I am extracting Year, Month, and Day from the following testing log name and converting it to timestamp later. log20230225.log I am using the following grok filter: log%{YEAR:year}%{MONTHNUM:month}%{MONTHDAY:d…

---

## [Difference between Timestamp and @timestamp in kibana logs](https://discuss.elastic.co/t/difference-between-timestamp-and-timestamp-in-kibana-logs/327203)

<div class="topic-metadata">

**Author:** [@Amani188](https://discuss.elastic.co/u/Amani188)\
**Replies:** 3\
**Last updated:** [March 7, 2023, 4:33pm UTC](https://discuss.elastic.co/t/difference-between-timestamp-and-timestamp-in-kibana-logs/327203 "2023-03-07T16:33:17Z")

</div>

Hi everyone, I noticed that there is a difference of time between Timestamp and @timestamp generated with logstash . Is there a way to synchronise the value of @timestamp to be equal to Timestamp on kibana logs? Thank …

---

## [Issue with RecyclerBytesStreamOutput](https://discuss.elastic.co/t/issue-with-recyclerbytesstreamoutput/325996)

<div class="topic-metadata">

**Author:** [@aurelien.guillaume](https://discuss.elastic.co/u/aurelien.guillaume)\
**Replies:** 3\
**Last updated:** [March 7, 2023, 4:03pm UTC](https://discuss.elastic.co/t/issue-with-recyclerbytesstreamoutput/325996 "2023-03-07T16:03:26Z")

</div>

Hi, I'm new in the usage of Elasticsearch (integrated into a security onion appliance) I'm working to get a huge query (2.5M logs), and I'm stuck with this error message { "error": { "root\_cause": \[ { …

---

## [Help needed for scripting for runtime fields](https://discuss.elastic.co/t/help-needed-for-scripting-for-runtime-fields/326001)

<div class="topic-metadata">

**Author:** [@jreyes25](https://discuss.elastic.co/u/jreyes25)\
**Replies:** 26\
**Last updated:** [March 7, 2023, 3:35pm UTC](https://discuss.elastic.co/t/help-needed-for-scripting-for-runtime-fields/326001 "2023-03-07T15:35:29Z")

</div>

Hello everyone, I am completely new to Elastic and scripting in general. I was told to install ElasticStack on our network for monitoring purposes. I now have both Elasticsearch and Kibana installed. I am currently try…

---

## [Markdown link to a secondary dashboard is not time persistent](https://discuss.elastic.co/t/markdown-link-to-a-secondary-dashboard-is-not-time-persistent/326980)

<div class="topic-metadata">

**Author:** [@Shreesh\_Narayanan](https://discuss.elastic.co/u/Shreesh_Narayanan)\
**Replies:** 4\
**Last updated:** [March 7, 2023, 3:31pm UTC](https://discuss.elastic.co/t/markdown-link-to-a-secondary-dashboard-is-not-time-persistent/326980 "2023-03-07T15:31:00Z")

</div>

Hi Folks, I have a primary dashboard that uses a markdown visualization that links to a secondary dashboard , while the page opens just fine. The time values from the primary dashboard are not carried over to the second…

---

## [Filebeat: failed to parse field \[user\_agent.version\] of type \[date\]](https://discuss.elastic.co/t/filebeat-failed-to-parse-field-user-agent-version-of-type-date/327124)

<div class="topic-metadata">

**Author:** [@mevan](https://discuss.elastic.co/u/mevan)\
**Replies:** 12\
**Last updated:** [March 7, 2023, 2:43pm UTC](https://discuss.elastic.co/t/filebeat-failed-to-parse-field-user-agent-version-of-type-date/327124 "2023-03-07T14:43:29Z")

</div>

This begins as a filebeat issue but I think it's now a matter of elasticsearch index. I'm seeing repeated messages like this in our logging. I can see this is related to the nginx module but I'm unsure how to go about f…

---

## [Kibana - one visualization should not be affected by user click on another](https://discuss.elastic.co/t/kibana-one-visualization-should-not-be-affected-by-user-click-on-another/327123)

<div class="topic-metadata">

**Author:** [@richfish](https://discuss.elastic.co/u/richfish)\
**Replies:** 1\
**Last updated:** [March 7, 2023, 2:30pm UTC](https://discuss.elastic.co/t/kibana-one-visualization-should-not-be-affected-by-user-click-on-another/327123 "2023-03-07T14:30:11Z")

</div>

I have a dashboard with 4 pie charts, a data table and a search. When the user clicks on a slice on one of the pies, I want the data table and the search to reflect what they clicked. But I don't want the other 3 pie cha…

---

## [Is there a way to remove or hide the black "Elastic" bar with the "Search Elastic" box from Kibana 7.x?](https://discuss.elastic.co/t/is-there-a-way-to-remove-or-hide-the-black-elastic-bar-with-the-search-elastic-box-from-kibana-7-x/327017)

<div class="topic-metadata">

**Author:** [@quan\_w](https://discuss.elastic.co/u/quan_w)\
**Replies:** 1\
**Last updated:** [March 7, 2023, 1:57pm UTC](https://discuss.elastic.co/t/is-there-a-way-to-remove-or-hide-the-black-elastic-bar-with-the-search-elastic-box-from-kibana-7-x/327017 "2023-03-07T13:57:42Z")

</div>

how to remove or hide the black "Elastic" bar in the header ?

---

## [Table of contents with parameters](https://discuss.elastic.co/t/table-of-contents-with-parameters/326936)

<div class="topic-metadata">

**Author:** [@Alice\_Ionescu](https://discuss.elastic.co/u/Alice_Ionescu)\
**Replies:** 1\
**Last updated:** [March 7, 2023, 1:33pm UTC](https://discuss.elastic.co/t/table-of-contents-with-parameters/326936 "2023-03-07T13:33:18Z")

</div>

Hello, I have a markdown visualization with links to other dashboards. (a table of content) I would like to add a parameter (css combo box, a control visualization) and to pass the value to the links in the markdown vi…

---

## [Falied to start Elasticsearch to my group volumes](https://discuss.elastic.co/t/falied-to-start-elasticsearch-to-my-group-volumes/325501)

<div class="topic-metadata">

**Author:** [@MonkeyD.J](https://discuss.elastic.co/u/MonkeyD.J)\
**Replies:** 9\
**Last updated:** [March 7, 2023, 12:17pm UTC](https://discuss.elastic.co/t/falied-to-start-elasticsearch-to-my-group-volumes/325501 "2023-03-07T12:17:15Z")

</div>

Hello, Mrs,Mr, I try to start Elasticsearch on my volum group. So I am on a debian 11.3 and I install java jre1.8.0\_121. I Install the version elastick 7.17.6 amd64.deb on my folder with this command dpkg -x /applis…

---

## [502 Bad Gateway Ingress nginx with kibana](https://discuss.elastic.co/t/502-bad-gateway-ingress-nginx-with-kibana/327175)

<div class="topic-metadata">

**Author:** [@A\_Mightiev](https://discuss.elastic.co/u/A_Mightiev)\
**Replies:** 1\
**Last updated:** [March 7, 2023, 12:13pm UTC](https://discuss.elastic.co/t/502-bad-gateway-ingress-nginx-with-kibana/327175 "2023-03-07T12:13:56Z")

</div>

I deployed kibana on a kubernetes cluster the port-forward locally works, I can surf on kibana but when set my ingress configuration, it comes back with a 502 Bad Gateway. Please help! This is my ingress configuration: …

---

## [Elasticsearch update by query](https://discuss.elastic.co/t/elasticsearch-update-by-query/327167)

<div class="topic-metadata">

**Author:** [@v-lixiubo](https://discuss.elastic.co/u/v-lixiubo)\
**Replies:** 1\
**Last updated:** [March 7, 2023, 11:30am UTC](https://discuss.elastic.co/t/elasticsearch-update-by-query/327167 "2023-03-07T11:30:14Z")

</div>

hi , I use the java client updateByQuery to update the data, and the returned result is successful, but the data has not actually changed

---

## [LogStash - Issue with sql\_last\_value and last\_run\_metadata\_path](https://discuss.elastic.co/t/logstash-issue-with-sql-last-value-and-last-run-metadata-path/327087)

<div class="topic-metadata">

**Author:** [@CedMathis](https://discuss.elastic.co/u/CedMathis)\
**Replies:** 1\
**Last updated:** [March 7, 2023, 11:08am UTC](https://discuss.elastic.co/t/logstash-issue-with-sql-last-value-and-last-run-metadata-path/327087 "2023-03-07T11:08:07Z")

</div>

Hello, I'm new to ELK and I'm currently struggling with some setup - maybe I missed a point. I have set up my Logstash to parse my DB (MySql), and I've got 2 cases: "Unforeseen maintenance" -\> In this case, I would…

---

## [Change the stream names](https://discuss.elastic.co/t/change-the-stream-names/327153)

<div class="topic-metadata">

**Author:** [@bex](https://discuss.elastic.co/u/bex)\
**Replies:** 3\
**Last updated:** [March 7, 2023, 9:15am UTC](https://discuss.elastic.co/t/change-the-stream-names/327153 "2023-03-07T09:15:30Z")

</div>

Is it possible to change or indicate the stream(index) name like "index =\> "client-1-%{+dd.MM.YYYY}" when using fleet server and elastic agent in logstash output. There are streams with default name like "logs-auditd.lo…

---

## [Apply minimum score parameter for the child queries](https://discuss.elastic.co/t/apply-minimum-score-parameter-for-the-child-queries/327139)

<div class="topic-metadata">

**Author:** [@Rahul\_S1](https://discuss.elastic.co/u/Rahul_S1)\
**Replies:** 0\
**Last updated:** [March 7, 2023, 5:42am UTC](https://discuss.elastic.co/t/apply-minimum-score-parameter-for-the-child-queries/327139 "2023-03-07T05:42:19Z")

</div>

I'm trying to apply some minimum score criteria for my has child queries, my data looks like this: {"Product Code": "A", "properties" :\[{"PROPERTY\_NAME":"density","PROPERTY\_NAME Encoded":\[0.22,0.432,.....\],"value":"low"…

---

## [Different Version Elasticsearch, Kibana, Metricbeat](https://discuss.elastic.co/t/different-version-elasticsearch-kibana-metricbeat/327136)

<div class="topic-metadata">

**Author:** [@Tw1cUser](https://discuss.elastic.co/u/Tw1cUser)\
**Replies:** 2\
**Last updated:** [March 7, 2023, 5:47am UTC](https://discuss.elastic.co/t/different-version-elasticsearch-kibana-metricbeat/327136 "2023-03-07T05:47:01Z")

</div>

is it ok if use Elasticsearch, Kibana, Metricbeat version 8.6.1 to connect to version 8.6.2?

---

## [How to write a collation rule for icu\_collation\_keyword field, with alphabets having atmost precedence?](https://discuss.elastic.co/t/how-to-write-a-collation-rule-for-icu-collation-keyword-field-with-alphabets-having-atmost-precedence/327019)

<div class="topic-metadata">

**Author:** [@Karthik\_Amar](https://discuss.elastic.co/u/Karthik_Amar)\
**Replies:** 3\
**Last updated:** [March 7, 2023, 5:27am UTC](https://discuss.elastic.co/t/how-to-write-a-collation-rule-for-icu-collation-keyword-field-with-alphabets-having-atmost-precedence/327019 "2023-03-07T05:27:10Z")

</div>

Instead of using alternative locale option, I want to write a rules parameter to customise the sort behaviour with alphabets having atmost precedence. for the text values, $1232, Abi, £7232, 87343, Karthik I want the…

---

## [Is there query char length limit of a match query](https://discuss.elastic.co/t/is-there-query-char-length-limit-of-a-match-query/327020)

<div class="topic-metadata">

**Author:** [@chenchuangc](https://discuss.elastic.co/u/chenchuangc)\
**Replies:** 2\
**Last updated:** [March 7, 2023, 1:49am UTC](https://discuss.elastic.co/t/is-there-query-char-length-limit-of-a-match-query/327020 "2023-03-07T01:49:34Z")

</div>

Thank you so much for having a look of my issue. ES Version 7.5.0 Query GET search\_vietnamese/\_search { "query": { "bool": { "should": \[ { "match": { "address": { …

---

## [Parsing an html inside a Json](https://discuss.elastic.co/t/parsing-an-html-inside-a-json/327104)

<div class="topic-metadata">

**Author:** [@Mhag](https://discuss.elastic.co/u/Mhag)\
**Replies:** 2\
**Last updated:** [March 6, 2023, 11:06pm UTC](https://discuss.elastic.co/t/parsing-an-html-inside-a-json/327104 "2023-03-06T23:06:35Z")

</div>

Hi, \*\* a longer explanation of the problem is in the second response to @Badger \*\* I need to parse a log with a JSON that contain a field which contains an HTML document, ex : 2023-03-04 20:20:06,817 \[http-nio-8080-ex…

---

## [Reindex document count does not match the source](https://discuss.elastic.co/t/reindex-document-count-does-not-match-the-source/327116)

<div class="topic-metadata">

**Author:** [@Parvatayya\_Malimath](https://discuss.elastic.co/u/Parvatayya_Malimath)\
**Replies:** 1\
**Last updated:** [March 6, 2023, 8:41pm UTC](https://discuss.elastic.co/t/reindex-document-count-does-not-match-the-source/327116 "2023-03-06T20:41:46Z")

</div>

I am reindexing an index from one cluster (elastic 6.8) to another cluster (elastic 7.17) Source: GET \<index\_name\>/\_count { "count" : 827908, "\_shards" : { "total" : 5, "successful" : 5, "skipped" : 0, "failed" …

---

## [Saving the content of a file in an elasticsearch index using springboot RESTAPI](https://discuss.elastic.co/t/saving-the-content-of-a-file-in-an-elasticsearch-index-using-springboot-restapi/327112)

<div class="topic-metadata">

**Author:** [@BEY\_MEHREZ](https://discuss.elastic.co/u/BEY_MEHREZ)\
**Replies:** 0\
**Last updated:** [March 6, 2023, 5:14pm UTC](https://discuss.elastic.co/t/saving-the-content-of-a-file-in-an-elasticsearch-index-using-springboot-restapi/327112 "2023-03-06T17:14:53Z")

</div>

So I am building a Spring Boot rest api that it takes a file ( Multipart file ) ( and it is a log file ) as an argument and saves its content in a unique elasticsearch index ! Each line of the file will be in a document.…

---

## [Debugging lost data in logstash coming from filebeat](https://discuss.elastic.co/t/debugging-lost-data-in-logstash-coming-from-filebeat/327110)

<div class="topic-metadata">

**Author:** [@mayer](https://discuss.elastic.co/u/mayer)\
**Replies:** 0\
**Last updated:** [March 6, 2023, 5:07pm UTC](https://discuss.elastic.co/t/debugging-lost-data-in-logstash-coming-from-filebeat/327110 "2023-03-06T17:07:51Z")

</div>

Dear All, I am running a central ELK stack 8.6.2 with logstash to collect data from some server around. More than 2 years ago I compiled filebeat by myself as it was not available on ARM architecture. With a minimal con…

---

## [Bufforing logs using ingest node](https://discuss.elastic.co/t/bufforing-logs-using-ingest-node/327103)

<div class="topic-metadata">

**Author:** [@krzychohoho](https://discuss.elastic.co/u/krzychohoho)\
**Replies:** 1\
**Last updated:** [March 6, 2023, 4:50pm UTC](https://discuss.elastic.co/t/bufforing-logs-using-ingest-node/327103 "2023-03-06T16:50:27Z")

</div>

Hi, I need to create an Elastic SIEM cluster in which logs will be buffered in the event of a data node failure. When the data node is brought back to life, the logs from the period when the node was not functioning wil…

---

## [Elasticsearch Compilation issues on Linux](https://discuss.elastic.co/t/elasticsearch-compilation-issues-on-linux/327096)

<div class="topic-metadata">

**Author:** [@markchennai](https://discuss.elastic.co/u/markchennai)\
**Replies:** 2\
**Last updated:** [March 6, 2023, 3:19pm UTC](https://discuss.elastic.co/t/elasticsearch-compilation-issues-on-linux/327096 "2023-03-06T15:19:47Z")

</div>

Team, I am facing issues while compiling Elasticsearch 8.5.1, the source code is allowed to pull the files from the in-house repo, FAILURE: Build failed with an exception. What went wrong: A problem occurred configu…

---

## [Logstash still holding onto deleted logstash application logs](https://discuss.elastic.co/t/logstash-still-holding-onto-deleted-logstash-application-logs/325479)

<div class="topic-metadata">

**Author:** [@Shreesh\_Narayanan](https://discuss.elastic.co/u/Shreesh_Narayanan)\
**Replies:** 3\
**Last updated:** [March 6, 2023, 3:09pm UTC](https://discuss.elastic.co/t/logstash-still-holding-onto-deleted-logstash-application-logs/325479 "2023-03-06T15:09:12Z")

</div>

Hello, It seems logstash refuses to let go of deleted logs (logstash's own logs) and this takes up all the space on disks , until a service restart takes place . Is there a way , we could fix this ? Is something need to…

[Previous page](https://discuss.elastic.co/tag/none.md?no_tags=true&page=421)

[Next page](https://discuss.elastic.co/tag/none.md?no_tags=true&page=423)
