# \#none

**URL:** https://discuss.elastic.co/tag/none.md?no_tags=true&page=426

[Latest](https://discuss.elastic.co/latest.md) · [Categories](https://discuss.elastic.co/categories.md) · [Tags](https://discuss.elastic.co/tags.md)

**Page:** 427

---

## [Dynamic naming of elasticsearch data-streams](https://discuss.elastic.co/t/dynamic-naming-of-elasticsearch-data-streams/325278)

<div class="topic-metadata">

**Author:** [@sbocquet](https://discuss.elastic.co/u/sbocquet)\
**Replies:** 12\
**Last updated:** [February 28, 2023, 3:22pm UTC](https://discuss.elastic.co/t/dynamic-naming-of-elasticsearch-data-streams/325278 "2023-02-28T15:22:30Z")

</div>

Hi, I'm trying to have some dynamic naming for my data streams based on some syslog fields. Here is my rsyslog conf file for sending datas in JSON format to logstash. # cat logstash-json.conf template(name="json-templ…

---

## [Having trouble running elasticsearch](https://discuss.elastic.co/t/having-trouble-running-elasticsearch/326528)

<div class="topic-metadata">

**Author:** [@bawac](https://discuss.elastic.co/u/bawac)\
**Replies:** 2\
**Last updated:** [February 28, 2023, 2:37pm UTC](https://discuss.elastic.co/t/having-trouble-running-elasticsearch/326528 "2023-02-28T14:37:06Z")

</div>

I am trying to run elasticsearch from my terminal and I'm getting this error: warning: ignoring JAVA\_HOME=/usr/lib/jvm/java-11-openjdk-arm64; using bundled JDK Dynarec for ARM64, with extension: ASIMD AES CRC32 PMULL AT…

---

## [How to integrate user-specified Kibana fields with my data fields](https://discuss.elastic.co/t/how-to-integrate-user-specified-kibana-fields-with-my-data-fields/326684)

<div class="topic-metadata">

**Author:** [@gyannea](https://discuss.elastic.co/u/gyannea)\
**Replies:** 0\
**Last updated:** [February 28, 2023, 2:03pm UTC](https://discuss.elastic.co/t/how-to-integrate-user-specified-kibana-fields-with-my-data-fields/326684 "2023-02-28T14:03:38Z")

</div>

Here is a basic case I am trying to solve. The data provides events that indicate how long a device lost cellular connectivity. I can use Kibana to get the total amount of downtime. However, the downtime is in seconds an…

---

## [Explain API parsing and displaying tools](https://discuss.elastic.co/t/explain-api-parsing-and-displaying-tools/326677)

<div class="topic-metadata">

**Author:** [@Eylon\_Koren1](https://discuss.elastic.co/u/Eylon_Koren1)\
**Replies:** 1\
**Last updated:** [February 28, 2023, 11:35am UTC](https://discuss.elastic.co/t/explain-api-parsing-and-displaying-tools/326677 "2023-02-28T11:35:18Z")

</div>

Hey ! I'm using the Elasticsearch Explain API in order to understand the ES internal scoring. The explain results is complex json, which i extract the impact of each field on the query overall score. Are there any too…

---

## [Upgradation of elastic version](https://discuss.elastic.co/t/upgradation-of-elastic-version/326679)

<div class="topic-metadata">

**Author:** [@Sandeep\_Raju](https://discuss.elastic.co/u/Sandeep_Raju)\
**Replies:** 1\
**Last updated:** [February 28, 2023, 11:28am UTC](https://discuss.elastic.co/t/upgradation-of-elastic-version/326679 "2023-02-28T11:28:18Z")

</div>

Hi all, I'm having ES version 7.10 Now i want to upgrade to 8.6 version. So one way of upgradation, is to take snapshot, delete old version (7.10) and install new version (8.6) and then restore snapshot. Is there a …

---

## [Capture Log for Logstash For every successfull pipeline execution](https://discuss.elastic.co/t/capture-log-for-logstash-for-every-successfull-pipeline-execution/326298)

<div class="topic-metadata">

**Author:** [@Rakhshunda\_Noorein\_J](https://discuss.elastic.co/u/Rakhshunda_Noorein_J)\
**Replies:** 6\
**Last updated:** [February 28, 2023, 11:23am UTC](https://discuss.elastic.co/t/capture-log-for-logstash-for-every-successfull-pipeline-execution/326298 "2023-02-28T11:23:00Z")

</div>

Hello, I want to capture log for logstash sucessfully fetching the api data from http\_poller plugin and entering it to my elasticDB. My configuration is: input { http\_poller { id =\> "test-plugin" urls =\> { t…

---

## [How to list out / export all the fields along with data types](https://discuss.elastic.co/t/how-to-list-out-export-all-the-fields-along-with-data-types/325975)

<div class="topic-metadata">

**Author:** [@RajuParipelly](https://discuss.elastic.co/u/RajuParipelly)\
**Replies:** 7\
**Last updated:** [February 28, 2023, 10:20am UTC](https://discuss.elastic.co/t/how-to-list-out-export-all-the-fields-along-with-data-types/325975 "2023-02-28T10:20:19Z")

</div>

I have an index with 25000 fields and wanted to export all the fields into a csv file along with data type? is there any way to do this?

---

## [Prevent setting minimum\_master\_nodes to more than the current node count](https://discuss.elastic.co/t/prevent-setting-minimum-master-nodes-to-more-than-the-current-node-count/326536)

<div class="topic-metadata">

**Author:** [@zhoumengbo](https://discuss.elastic.co/u/zhoumengbo)\
**Replies:** 4\
**Last updated:** [February 28, 2023, 10:10am UTC](https://discuss.elastic.co/t/prevent-setting-minimum-master-nodes-to-more-than-the-current-node-count/326536 "2023-02-28T10:10:38Z")

</div>

Setting zen.discovery.minimum\_master\_nodes to a value higher than the current node count effectively leaves the cluster without a master and unable to process requests. The official website below has fixed this bug. ht…

---

## [Problem with adding node to elastic cluster](https://discuss.elastic.co/t/problem-with-adding-node-to-elastic-cluster/326671)

<div class="topic-metadata">

**Author:** [@reza\_setareh](https://discuss.elastic.co/u/reza_setareh)\
**Replies:** 4\
**Last updated:** [February 28, 2023, 10:05am UTC](https://discuss.elastic.co/t/problem-with-adding-node-to-elastic-cluster/326671 "2023-02-28T10:05:12Z")

</div>

hi every one.i want to add new node to elastic cluster by enrollment token but i got the error below E:\\node-1\\bin\>elasticsearch-create-enrollment-token.bat -s node ERROR: \[xpack.security.enrollment.enabled\] must be se…

---

## [Defining ranges but NOT one at a time](https://discuss.elastic.co/t/defining-ranges-but-not-one-at-a-time/326573)

<div class="topic-metadata">

**Author:** [@gyannea](https://discuss.elastic.co/u/gyannea)\
**Replies:** 5\
**Last updated:** [February 28, 2023, 9:06am UTC](https://discuss.elastic.co/t/defining-ranges-but-not-one-at-a-time/326573 "2023-02-28T09:06:34Z")

</div>

I want to create a bar graph of the time a cellular network was down. The y-axis gives the number of times and the x-axis is a set of ranges, 0-100 seconds, 100-200, seconds, in intervals of 100 seconds up to 100000. Tha…

---

## [Transforming logs into geo\_point to draw them in kibana](https://discuss.elastic.co/t/transforming-logs-into-geo-point-to-draw-them-in-kibana/323053)

<div class="topic-metadata">

**Author:** [@grillo](https://discuss.elastic.co/u/grillo)\
**Replies:** 10\
**Last updated:** [February 28, 2023, 8:29am UTC](https://discuss.elastic.co/t/transforming-logs-into-geo-point-to-draw-them-in-kibana/323053 "2023-02-28T08:29:41Z")

</div>

My goal is to be able to geolocate on a kibana map the connections that interest me. The problem is that the generated indices do not create the correct type of data for kibana to draw. It would be Geopoints. The data …

---

## [Must and should match doesn't return should matches](https://discuss.elastic.co/t/must-and-should-match-doesnt-return-should-matches/326657)

<div class="topic-metadata">

**Author:** [@ksh117](https://discuss.elastic.co/u/ksh117)\
**Replies:** 1\
**Last updated:** [February 28, 2023, 7:58am UTC](https://discuss.elastic.co/t/must-and-should-match-doesnt-return-should-matches/326657 "2023-02-28T07:58:12Z")

</div>

{ "track\_total\_hits": true, "from": 0, "size": 20, "query": { "bool": { "must": \[ { "term": { "item\_id": { "value": "item\_value\_1", "boost": 1 …

---

## [Dashboard creation using Query](https://discuss.elastic.co/t/dashboard-creation-using-query/326647)

<div class="topic-metadata">

**Author:** [@Haneesha](https://discuss.elastic.co/u/Haneesha)\
**Replies:** 4\
**Last updated:** [February 28, 2023, 7:49am UTC](https://discuss.elastic.co/t/dashboard-creation-using-query/326647 "2023-02-28T07:49:53Z")

</div>

Hi Team, We use filebeat, logstash, Elasticsearch and kibana for logs. And we have index patterns created and visualisations and then dashboards. Now I got a requirement saying to display the replication status that is…

---

## [Unable to split the data in message field](https://discuss.elastic.co/t/unable-to-split-the-data-in-message-field/325987)

<div class="topic-metadata">

**Author:** [@anik-27](https://discuss.elastic.co/u/anik-27)\
**Replies:** 10\
**Last updated:** [February 28, 2023, 7:45am UTC](https://discuss.elastic.co/t/unable-to-split-the-data-in-message-field/325987 "2023-02-28T07:45:19Z")

</div>

Hello I am running a python file using exec input plugin, the python file is making multiple api calls and collecting the data in a list(array). I am printing the list and getting the data in message field, but I am un…

---

## [Elastic search did not trust this server's certificate, closing connection](https://discuss.elastic.co/t/elastic-search-did-not-trust-this-servers-certificate-closing-connection/326663)

<div class="topic-metadata">

**Author:** [@vijay78](https://discuss.elastic.co/u/vijay78)\
**Replies:** 0\
**Last updated:** [February 28, 2023, 7:35am UTC](https://discuss.elastic.co/t/elastic-search-did-not-trust-this-servers-certificate-closing-connection/326663 "2023-02-28T07:35:08Z")

</div>

Elasticsearch is running successfully but when iam checking the logs its says "http client did not trust this server's certificate, closing connection" find the log below : WARN", "message":"http client did not trust t…

---

## [Threat Hunting Capstone with Network Telemetry Suspended](https://discuss.elastic.co/t/threat-hunting-capstone-with-network-telemetry-suspended/326660)

<div class="topic-metadata">

**Author:** [@merijn-weiss](https://discuss.elastic.co/u/merijn-weiss)\
**Replies:** 1\
**Last updated:** [February 28, 2023, 7:30am UTC](https://discuss.elastic.co/t/threat-hunting-capstone-with-network-telemetry-suspended/326660 "2023-02-28T07:30:08Z")

</div>

Course: Threat Hunting Capstone with Network Telemetry Version: n/a Question: The lab I'm trying to complete shows a 'suspended' message. I've tried whether this message would be lifted already for about a week, but it…

---

## [Is it possible to integrated Elasticsearh with OBM Microfocus?](https://discuss.elastic.co/t/is-it-possible-to-integrated-elasticsearh-with-obm-microfocus/326645)

<div class="topic-metadata">

**Author:** [@zerratriani](https://discuss.elastic.co/u/zerratriani)\
**Replies:** 1\
**Last updated:** [February 28, 2023, 6:57am UTC](https://discuss.elastic.co/t/is-it-possible-to-integrated-elasticsearh-with-obm-microfocus/326645 "2023-02-28T06:57:28Z")

</div>

I have question is it possible if elastic APM monitoring results be combined with other monitoring tools such as OBM from Microfocus? same thing as elasticsearch and splunk integration.

---

## [Map multiple fields to same user option in Kibana dashboard](https://discuss.elastic.co/t/map-multiple-fields-to-same-user-option-in-kibana-dashboard/326624)

<div class="topic-metadata">

**Author:** [@rvadiga](https://discuss.elastic.co/u/rvadiga)\
**Replies:** 1\
**Last updated:** [February 28, 2023, 6:15am UTC](https://discuss.elastic.co/t/map-multiple-fields-to-same-user-option-in-kibana-dashboard/326624 "2023-02-28T06:15:32Z")

</div>

I am new to Kibana, now trying to develop a dashboard where it has to take the values of 3 or more fields and provide a single option to choose from. For example: Any individual can be contacted by either phone, email,…

---

## [Is there any problem that set ES heap size to 64G?](https://discuss.elastic.co/t/is-there-any-problem-that-set-es-heap-size-to-64g/326546)

<div class="topic-metadata">

**Author:** [@vsop\_479](https://discuss.elastic.co/u/vsop_479)\
**Replies:** 1\
**Last updated:** [February 27, 2023, 10:46pm UTC](https://discuss.elastic.co/t/is-there-any-problem-that-set-es-heap-size-to-64g/326546 "2023-02-27T22:46:26Z")

</div>

My machine has 512G memory, and i only need 2 ES nodes( 2 shards is enough for my index). So, is there any problem that set ES heap size to 64G or more bigger?

---

## [Unable to retrieve version information from Elasticsearch nodes. connect ECONNREFUSED 192.168.100.5:9200](https://discuss.elastic.co/t/unable-to-retrieve-version-information-from-elasticsearch-nodes-connect-econnrefused-192-168-100-5-9200/326562)

<div class="topic-metadata">

**Author:** [@flapjack365](https://discuss.elastic.co/u/flapjack365)\
**Replies:** 1\
**Last updated:** [February 27, 2023, 10:45pm UTC](https://discuss.elastic.co/t/unable-to-retrieve-version-information-from-elasticsearch-nodes-connect-econnrefused-192-168-100-5-9200/326562 "2023-02-27T22:45:50Z")

</div>

Hi All, A few days ago I've successfully setup Elasticsearch and kibana on my local machine. I was reaching out :5601 and I've managed to create a few indices. Today Kibana returns "Kibana server is not ready yet." Wh…

---

## [Slow searches after changing daily to weekly indexes](https://discuss.elastic.co/t/slow-searches-after-changing-daily-to-weekly-indexes/326563)

<div class="topic-metadata">

**Author:** [@filipe-m-claudio](https://discuss.elastic.co/u/filipe-m-claudio)\
**Replies:** 3\
**Last updated:** [February 27, 2023, 10:22pm UTC](https://discuss.elastic.co/t/slow-searches-after-changing-daily-to-weekly-indexes/326563 "2023-02-27T22:22:38Z")

</div>

Currently the configuration is set to daily indices in a single-node, so we decided to move to weekly indices in order to reduce the number of shards in the cluster. Most of the time the client wants a 6 month history, …

---

## [Red Cluster Health - Unsure How to Fix](https://discuss.elastic.co/t/red-cluster-health-unsure-how-to-fix/326464)

<div class="topic-metadata">

**Author:** [@bcantrell](https://discuss.elastic.co/u/bcantrell)\
**Replies:** 3\
**Last updated:** [February 27, 2023, 10:08pm UTC](https://discuss.elastic.co/t/red-cluster-health-unsure-how-to-fix/326464 "2023-02-27T22:08:28Z")

</div>

Hi all, I have been trying to figure out a problem where my Kibana is not able to keep connections alive with the Elasticsearch instance, and I think it is because of red cluster/index health. When Kibana is running, I …

---

## [Search as you type for documents with digits, unicode and special characters](https://discuss.elastic.co/t/search-as-you-type-for-documents-with-digits-unicode-and-special-characters/326005)

<div class="topic-metadata">

**Author:** [@zdebyman](https://discuss.elastic.co/u/zdebyman)\
**Replies:** 2\
**Last updated:** [February 27, 2023, 9:46pm UTC](https://discuss.elastic.co/t/search-as-you-type-for-documents-with-digits-unicode-and-special-characters/326005 "2023-02-27T21:46:26Z")

</div>

Hi! Im very new to the ES and while learning and playing around with it, I got stuck with a problem that i'm not sure how to solve. REQUIREMENT I'm trying to build search-as-you-type autocomplete. I have a table with o…

---

## [Query on Logstash S3 input](https://discuss.elastic.co/t/query-on-logstash-s3-input/325964)

<div class="topic-metadata">

**Author:** [@pk.241011](https://discuss.elastic.co/u/pk.241011)\
**Replies:** 3\
**Last updated:** [February 27, 2023, 9:13pm UTC](https://discuss.elastic.co/t/query-on-logstash-s3-input/325964 "2023-02-27T21:13:39Z")

</div>

Hi Team, I wanted some clarification on the Logstash S3 input plugin behaviour. There is an option of "sincedb\_path" where as per documentation, it defines where to write the since database (keeps track of the date the…

---

## [Actual Size of a document - Mapper Size Plugin](https://discuss.elastic.co/t/actual-size-of-a-document-mapper-size-plugin/326631)

<div class="topic-metadata">

**Author:** [@prateek\_shekhar](https://discuss.elastic.co/u/prateek_shekhar)\
**Replies:** 0\
**Last updated:** [February 27, 2023, 8:48pm UTC](https://discuss.elastic.co/t/actual-size-of-a-document-mapper-size-plugin/326631 "2023-02-27T20:48:37Z")

</div>

Hi All, Recently we have enabled the mapper-size plugin on our ES cluster. We have also added the index mapping \_size as per the recommendations at this link: Using the \_size field | Elasticsearch Plugins and Integratio…

---

## [Kibana API output](https://discuss.elastic.co/t/kibana-api-output/325776)

<div class="topic-metadata">

**Author:** [@branden.heifner](https://discuss.elastic.co/u/branden.heifner)\
**Replies:** 2\
**Last updated:** [February 27, 2023, 8:16pm UTC](https://discuss.elastic.co/t/kibana-api-output/325776 "2023-02-27T20:16:36Z")

</div>

Hello everyone, I am using the Kibana API to output the list of agent for auditing purposes. Is there a built-in way to output the list of agents in CSV format instead of JSON? Below is the current API call I am using. …

---

## [Kibana Dashboard - Pie chart from two dependent fields](https://discuss.elastic.co/t/kibana-dashboard-pie-chart-from-two-dependent-fields/326625)

<div class="topic-metadata">

**Author:** [@rvadiga](https://discuss.elastic.co/u/rvadiga)\
**Replies:** 0\
**Last updated:** [February 27, 2023, 6:55pm UTC](https://discuss.elastic.co/t/kibana-dashboard-pie-chart-from-two-dependent-fields/326625 "2023-02-27T18:55:18Z")

</div>

Hi Team, I am newbie to Elasticsearch, but trying to make hand dirty. Trying to develop a pie chart in Kibana dashboard. Want to know how we can link two fields for generating a pie chart. Sample problem statement: W…

---

## [After parsing in logstash got error](https://discuss.elastic.co/t/after-parsing-in-logstash-got-error/326560)

<div class="topic-metadata">

**Author:** [@neeldey](https://discuss.elastic.co/u/neeldey)\
**Replies:** 1\
**Last updated:** [February 27, 2023, 5:09pm UTC](https://discuss.elastic.co/t/after-parsing-in-logstash-got-error/326560 "2023-02-27T17:09:49Z")

</div>

Hi all, i getting error, while to start logstash. logstash log is as bellow. \[2023-02-27T15:18:50,526\]\[FATAL\]\[org.logstash.Logstash \] Logstash stopped processing because of an error: (SystemExit) exit org.jruby.ex…

---

## [Correct parsing Syslog message to json](https://discuss.elastic.co/t/correct-parsing-syslog-message-to-json/326564)

<div class="topic-metadata">

**Author:** [@poky](https://discuss.elastic.co/u/poky)\
**Replies:** 1\
**Last updated:** [February 27, 2023, 5:07pm UTC](https://discuss.elastic.co/t/correct-parsing-syslog-message-to-json/326564 "2023-02-27T17:07:34Z")

</div>

Hi Folks! I'm trying to parse the following message from mcafee proxy syslog inside my logstash pipeline: \<30\>Feb 24 9:33:45 mwg-n3 mwg-n3: x-message="{"DateTime":"2023-02-22 14:03:44.927","MWG\_Source":"mwg-n3.foo.de",…

---

## [About Kibana's "Color mapping" in 8.X](https://discuss.elastic.co/t/about-kibanas-color-mapping-in-8-x/326607)

<div class="topic-metadata">

**Author:** [@Juanma](https://discuss.elastic.co/u/Juanma)\
**Replies:** 1\
**Last updated:** [February 27, 2023, 5:04pm UTC](https://discuss.elastic.co/t/about-kibanas-color-mapping-in-8-x/326607 "2023-02-27T17:04:25Z")

</div>

Hi! I was looking throught my kibana 7.17 advanced options, and I've notice that "color mapping" is deprecated and removed from 8.0... Is it deprecated/removed in favor of any other thing that gives the same functional…

[Previous page](https://discuss.elastic.co/tag/none.md?no_tags=true&page=425)

[Next page](https://discuss.elastic.co/tag/none.md?no_tags=true&page=427)
