# \#none

**URL:** https://discuss.elastic.co/tag/none.md?no_tags=true&page=429

[Latest](https://discuss.elastic.co/latest.md) · [Categories](https://discuss.elastic.co/categories.md) · [Tags](https://discuss.elastic.co/tags.md)

**Page:** 430

---

## [Tag events based in words in different fields](https://discuss.elastic.co/t/tag-events-based-in-words-in-different-fields/326382)

<div class="topic-metadata">

**Author:** [@xalmer](https://discuss.elastic.co/u/xalmer)\
**Replies:** 0\
**Last updated:** [February 23, 2023, 11:35pm UTC](https://discuss.elastic.co/t/tag-events-based-in-words-in-different-fields/326382 "2023-02-23T23:35:04Z")

</div>

Hello everybody, I want to make a better code, but i try a lot of thing and nothing works. I need to tag the input based in many words in 4 different fields. Im doing like this, but need to replicate all the filter fo…

---

## [Runtime Field Convert String to Number](https://discuss.elastic.co/t/runtime-field-convert-string-to-number/326370)

<div class="topic-metadata">

**Author:** [@sparker22](https://discuss.elastic.co/u/sparker22)\
**Replies:** 1\
**Last updated:** [February 23, 2023, 10:49pm UTC](https://discuss.elastic.co/t/runtime-field-convert-string-to-number/326370 "2023-02-23T22:49:05Z")

</div>

Is there a way to convert string / text to a number in a runtime field script? We have data that is getting ingested into Elastic as keyword / text fields, but I need to convert that data at runtime from a string to numb…

---

## [Upload of multiple CSV files into same index](https://discuss.elastic.co/t/upload-of-multiple-csv-files-into-same-index/326156)

<div class="topic-metadata">

**Author:** [@Raj4](https://discuss.elastic.co/u/Raj4)\
**Replies:** 4\
**Last updated:** [February 23, 2023, 10:07pm UTC](https://discuss.elastic.co/t/upload-of-multiple-csv-files-into-same-index/326156 "2023-02-23T22:07:07Z")

</div>

Hi, Please advise me on the below. I want to upload CSV file into the same index name on daily basis and need to create Kibana dashboard. Is it possible for me to upload the CSV file directly into Elasticsearch autom…

---

## [Feature Request: minimum\_should\_match support for Terms Set query](https://discuss.elastic.co/t/feature-request-minimum-should-match-support-for-terms-set-query/326374)

<div class="topic-metadata">

**Author:** [@kulinsj](https://discuss.elastic.co/u/kulinsj)\
**Replies:** 2\
**Last updated:** [February 23, 2023, 9:32pm UTC](https://discuss.elastic.co/t/feature-request-minimum-should-match-support-for-terms-set-query/326374 "2023-02-23T21:32:36Z")

</div>

The Terms Set Query lets you match documents that have some minimum number of matches to a given array of input search terms. The minimum number of matches however can only be specified by referencing another field on th…

---

## [DakMode in kibana spaces](https://discuss.elastic.co/t/dakmode-in-kibana-spaces/326343)

<div class="topic-metadata">

**Author:** [@thomas4](https://discuss.elastic.co/u/thomas4)\
**Replies:** 8\
**Last updated:** [February 23, 2023, 8:38pm UTC](https://discuss.elastic.co/t/dakmode-in-kibana-spaces/326343 "2023-02-23T20:38:14Z")

</div>

Hi all, new to Kibana and setting up new spaces, but i want them in darkMode but can't figure out how to do it, any help would be appreciated. I'm using Kibana 7.6.1

---

## [How to Set Default Integer Value in Search Template](https://discuss.elastic.co/t/how-to-set-default-integer-value-in-search-template/325279)

<div class="topic-metadata">

**Author:** [@krmathieu](https://discuss.elastic.co/u/krmathieu)\
**Replies:** 1\
**Last updated:** [February 23, 2023, 6:58pm UTC](https://discuss.elastic.co/t/how-to-set-default-integer-value-in-search-template/325279 "2023-02-23T18:58:53Z")

</div>

I am getting a number\_format\_exception when trying to run a search against a search template containing this snippet of code. It defines a CityID variable and tries to set a wildcard default and the CityID field is defin…

---

## [Elasticsearch rolling restart without indexing down time](https://discuss.elastic.co/t/elasticsearch-rolling-restart-without-indexing-down-time/326358)

<div class="topic-metadata">

**Author:** [@ebuildy](https://discuss.elastic.co/u/ebuildy)\
**Replies:** 2\
**Last updated:** [February 23, 2023, 6:50pm UTC](https://discuss.elastic.co/t/elasticsearch-rolling-restart-without-indexing-down-time/326358 "2023-02-23T18:50:06Z")

</div>

We run an elasticsearch cluster 7.17, with 3 data nodes and 3 master nodes. The use case is for monitoring with elasticAPM. We follow official documentation at Full cluster restart upgrade | Elasticsearch Guide \[7.17\] |…

---

## [Logs reflecting late in kibana](https://discuss.elastic.co/t/logs-reflecting-late-in-kibana/326291)

<div class="topic-metadata">

**Author:** [@Haneesha](https://discuss.elastic.co/u/Haneesha)\
**Replies:** 1\
**Last updated:** [February 23, 2023, 6:39pm UTC](https://discuss.elastic.co/t/logs-reflecting-late-in-kibana/326291 "2023-02-23T18:39:42Z")

</div>

Hi Team, Logs are reflecting after 20 min after the generation for a particular service. How can I sort this out.

---

## [Kibana Search on field endTime not working](https://discuss.elastic.co/t/kibana-search-on-field-endtime-not-working/326318)

<div class="topic-metadata">

**Author:** [@garmy](https://discuss.elastic.co/u/garmy)\
**Replies:** 1\
**Last updated:** [February 23, 2023, 6:04pm UTC](https://discuss.elastic.co/t/kibana-search-on-field-endtime-not-working/326318 "2023-02-23T18:04:56Z")

</div>

Hi gang, Trying to identify documents that have a time field called "endTime" \>= future times..... since this field is a UTC Time field, some may, and do have 'Future' dates and those are what I want to see (as well as …

---

## [Reindex w/ a regex](https://discuss.elastic.co/t/reindex-w-a-regex/326348)

<div class="topic-metadata">

**Author:** [@vfeydel](https://discuss.elastic.co/u/vfeydel)\
**Replies:** 1\
**Last updated:** [February 23, 2023, 5:44pm UTC](https://discuss.elastic.co/t/reindex-w-a-regex/326348 "2023-02-23T17:44:51Z")

</div>

I have lot of indices with same prefix. In those indices, I need to keep only document that have for example the field "abc" with 7 numbers only. My indices are already index in Elastic. It is possible , with a query or…

---

## [Connecting Render web service to Elasticsearch via TLS-enabled syslog drain](https://discuss.elastic.co/t/connecting-render-web-service-to-elasticsearch-via-tls-enabled-syslog-drain/326200)

<div class="topic-metadata">

**Author:** [@pocketcolin](https://discuss.elastic.co/u/pocketcolin)\
**Replies:** 8\
**Last updated:** [February 23, 2023, 4:12pm UTC](https://discuss.elastic.co/t/connecting-render-web-service-to-elasticsearch-via-tls-enabled-syslog-drain/326200 "2023-02-23T16:12:49Z")

</div>

Hello, I'm new to configuring Elasticsearch observability but my goal right now is to get syslogs from my web service setup on Render (render.com) into my Elasticsearch instance (Render log stream docs here). Is this ev…

---

## [Add AWS EKS Cluster name dynamically to metrics/logs collection via fleet agent](https://discuss.elastic.co/t/add-aws-eks-cluster-name-dynamically-to-metrics-logs-collection-via-fleet-agent/326341)

<div class="topic-metadata">

**Author:** [@ekane\_bksy](https://discuss.elastic.co/u/ekane_bksy)\
**Replies:** 0\
**Last updated:** [February 23, 2023, 3:41pm UTC](https://discuss.elastic.co/t/add-aws-eks-cluster-name-dynamically-to-metrics-logs-collection-via-fleet-agent/326341 "2023-02-23T15:41:04Z")

</div>

How to configure elastic-agent dynamically with AWS EKS cluster name to metrics and logs forwarded to ElasticCloud? Documentation details configuring ElasticCloud side with processor. What method can be used on agent-si…

---

## [How to analyse nested fields?](https://discuss.elastic.co/t/how-to-analyse-nested-fields/325944)

<div class="topic-metadata">

**Author:** [@Amine16](https://discuss.elastic.co/u/Amine16)\
**Replies:** 1\
**Last updated:** [February 23, 2023, 3:28pm UTC](https://discuss.elastic.co/t/how-to-analyse-nested-fields/325944 "2023-02-23T15:28:45Z")

</div>

I am working in e-health project and we have a lot of clinical data (JSON format) stored in our data base. We want to do some research in these data, that’s why we think that Elastic Search tool can help us in this proj…

---

## [Observability Lab 2.2 - mysql incorrect creds](https://discuss.elastic.co/t/observability-lab-2-2-mysql-incorrect-creds/326111)

<div class="topic-metadata">

**Author:** [@deccman](https://discuss.elastic.co/u/deccman)\
**Replies:** 3\
**Last updated:** [February 23, 2023, 2:44pm UTC](https://discuss.elastic.co/t/observability-lab-2-2-mysql-incorrect-creds/326111 "2023-02-23T14:44:59Z")

</div>

Course: Observability Engineer Version: 7.9 Question: I am currently doing the Observability Engineer Training for version 7.9 and have hit a roadblock in the lab training. In lab 2.2 you set up Metricbeats for MySQL. …

---

## [UNABLE TO START FILEBEAT ON ELASTIC V7.9 LAB](https://discuss.elastic.co/t/unable-to-start-filebeat-on-elastic-v7-9-lab/326269)

<div class="topic-metadata">

**Author:** [@chikugerson](https://discuss.elastic.co/u/chikugerson)\
**Replies:** 3\
**Last updated:** [February 23, 2023, 2:43pm UTC](https://discuss.elastic.co/t/unable-to-start-filebeat-on-elastic-v7-9-lab/326269 "2023-02-23T14:43:14Z")

</div>

Elastic Certified Observability Engineer practice lab when i start the filebeat with the command ./filebeat i get the below logs the filebeat is not starting. \[elastic@mysql filebeat\]$ ./filebeat -e 2023-02-23T07:31:49.…

---

## [Copy Dashboard th onther space](https://discuss.elastic.co/t/copy-dashboard-th-onther-space/326194)

<div class="topic-metadata">

**Author:** [@hiba](https://discuss.elastic.co/u/hiba)\
**Replies:** 1\
**Last updated:** [February 23, 2023, 2:26pm UTC](https://discuss.elastic.co/t/copy-dashboard-th-onther-space/326194 "2023-02-23T14:26:36Z")

</div>

Hi, I copied a dashboard to another space, but I noticed that there are visualizations whose X axis is not the same For example : i copy this dashboard (original) But i get this

---

## [How to grab the trace for bulkprocessor](https://discuss.elastic.co/t/how-to-grab-the-trace-for-bulkprocessor/326149)

<div class="topic-metadata">

**Author:** [@INS](https://discuss.elastic.co/u/INS)\
**Replies:** 1\
**Last updated:** [February 23, 2023, 2:19pm UTC](https://discuss.elastic.co/t/how-to-grab-the-trace-for-bulkprocessor/326149 "2023-02-23T14:19:41Z")

</div>

Hi I need to trace same stack for bulkprocessor for tracing the cause of the error on elastic, why does the application get a timeout ERROR e.i.u.r.i.BulkIndexingProcessorConfig - - Failed to execute bulk request. Reas…

---

## [Logstash is taking high cpu](https://discuss.elastic.co/t/logstash-is-taking-high-cpu/326316)

<div class="topic-metadata">

**Author:** [@divya.m](https://discuss.elastic.co/u/divya.m)\
**Replies:** 1\
**Last updated:** [February 23, 2023, 2:00pm UTC](https://discuss.elastic.co/t/logstash-is-taking-high-cpu/326316 "2023-02-23T14:00:24Z")

</div>

Without any load consistently logstash is using 46% of CPU, after performance load testing logstash cpu is high root@::~ $ docker logs XXXXX | grep -i "2023-02-23 10:57" | wc 86 1238 18546

---

## [Unable to search data containing math expression](https://discuss.elastic.co/t/unable-to-search-data-containing-math-expression/326287)

<div class="topic-metadata">

**Author:** [@Hassan\_zaib\_Hayat](https://discuss.elastic.co/u/Hassan_zaib_Hayat)\
**Replies:** 1\
**Last updated:** [February 23, 2023, 1:39pm UTC](https://discuss.elastic.co/t/unable-to-search-data-containing-math-expression/326287 "2023-02-23T13:39:14Z")

</div>

Hi ES folks, Hope everyone is doing fine. I am facing a problem when querying data containing mathematical expressions. For example I have following data indexed in my ES what is 3+4 what is 3-4 what is 3\*4 what is 3/…

---

## [Why Kibana not showing date when minimum interval is selected in minutes](https://discuss.elastic.co/t/why-kibana-not-showing-date-when-minimum-interval-is-selected-in-minutes/326319)

<div class="topic-metadata">

**Author:** [@Arshukla](https://discuss.elastic.co/u/Arshukla)\
**Replies:** 1\
**Last updated:** [February 23, 2023, 12:52pm UTC](https://discuss.elastic.co/t/why-kibana-not-showing-date-when-minimum-interval-is-selected-in-minutes/326319 "2023-02-23T12:52:45Z")

</div>

When I am selecting minimum interval as "Minutes", Kibana is not having dates in timestamp column. Whereas when i am selecting "Hour", it is working as per expectation. Screenshot -when minutes selected Screenshot -…

---

## [Problems with cloudwatch input plugin - namespace AWS/EC2 NameError](https://discuss.elastic.co/t/problems-with-cloudwatch-input-plugin-namespace-aws-ec2-nameerror/326297)

<div class="topic-metadata">

**Author:** [@wodnd6646](https://discuss.elastic.co/u/wodnd6646)\
**Replies:** 0\
**Last updated:** [February 23, 2023, 10:27am UTC](https://discuss.elastic.co/t/problems-with-cloudwatch-input-plugin-namespace-aws-ec2-nameerror/326297 "2023-02-23T10:27:27Z")

</div>

Hello All, problem summary: logstash can't recognize 'AWS/EC2' I am setting up a logstash configuration file to get cloudwatch(EC2, RDS) data. I have written input plugin code as below, and RDS is working as I expecte…

---

## [Transform a log fields integer value received with snmp](https://discuss.elastic.co/t/transform-a-log-fields-integer-value-received-with-snmp/326292)

<div class="topic-metadata">

**Author:** [@Christer\_Palmen](https://discuss.elastic.co/u/Christer_Palmen)\
**Replies:** 0\
**Last updated:** [February 23, 2023, 9:52am UTC](https://discuss.elastic.co/t/transform-a-log-fields-integer-value-received-with-snmp/326292 "2023-02-23T09:52:56Z")

</div>

Blockquote Hello. I am setting up a logstash pipeline to monitor the environment of my customers server cabinets with the snmp plugin. Everything looks good except for the value of the temperature, which is shown in…

---

## [Replacing an Elasticsearch node](https://discuss.elastic.co/t/replacing-an-elasticsearch-node/326203)

<div class="topic-metadata">

**Author:** [@smutel](https://discuss.elastic.co/u/smutel)\
**Replies:** 4\
**Last updated:** [February 23, 2023, 9:22am UTC](https://discuss.elastic.co/t/replacing-an-elasticsearch-node/326203 "2023-02-23T09:22:29Z")

</div>

Hello, I have a cluster with 5 nodes (3 master nodes and 2 data nodes) hosted on vms. I am using Elasticsearch version 7.17.8. I need to replace these VMs (to destroy them and to create new ones). I replaced the seco…

---

## [What is the desired elastic-operator replica count in ECK (k8s)?](https://discuss.elastic.co/t/what-is-the-desired-elastic-operator-replica-count-in-eck-k8s/326284)

<div class="topic-metadata">

**Author:** [@jane.hwang](https://discuss.elastic.co/u/jane.hwang)\
**Replies:** 0\
**Last updated:** [February 23, 2023, 8:39am UTC](https://discuss.elastic.co/t/what-is-the-desired-elastic-operator-replica-count-in-eck-k8s/326284 "2023-02-23T08:39:37Z")

</div>

Hello, I'm using ECK. What is the desired elastic-operator replica count in ECK (k8s)? I already tested elastic-operator having one replica and elastic-operator having two replicas in ECK. I couldn't find significant d…

---

## [Failed to obtain node locks, tried \[/usr/share/elasticsearch/data\]; maybe these locations are not writable or multiple nodes were started on the same data path?](https://discuss.elastic.co/t/failed-to-obtain-node-locks-tried-usr-share-elasticsearch-data-maybe-these-locations-are-not-writable-or-multiple-nodes-were-started-on-the-same-data-path/326264)

<div class="topic-metadata">

**Author:** [@limedong1](https://discuss.elastic.co/u/limedong1)\
**Replies:** 7\
**Last updated:** [February 23, 2023, 7:15am UTC](https://discuss.elastic.co/t/failed-to-obtain-node-locks-tried-usr-share-elasticsearch-data-maybe-these-locations-are-not-writable-or-multiple-nodes-were-started-on-the-same-data-path/326264 "2023-02-23T07:15:49Z")

</div>

I use k8s built a ela cluster, I in the yaml document data directory: / usr/share/elasticsearch/data local hostpath path is: / data/elasticsearch/data This is directory permission information: drwxr-xr-x. 3 1000 100…

---

## [Kibana visualization](https://discuss.elastic.co/t/kibana-visualization/326253)

<div class="topic-metadata">

**Author:** [@joelle\_umutoni](https://discuss.elastic.co/u/joelle_umutoni)\
**Replies:** 1\
**Last updated:** [February 23, 2023, 4:36am UTC](https://discuss.elastic.co/t/kibana-visualization/326253 "2023-02-23T04:36:39Z")

</div>

What to do when you click on visualization for filtering purpose but the other visualization does not update to show the data related to the one clicked

---

## [io.netty.handler.ssl.SslHandshakeTimeoutException: handshake timed out after 10000ms](https://discuss.elastic.co/t/io-netty-handler-ssl-sslhandshaketimeoutexception-handshake-timed-out-after-10000ms/326117)

<div class="topic-metadata">

**Author:** [@Raghulvishal](https://discuss.elastic.co/u/Raghulvishal)\
**Replies:** 6\
**Last updated:** [February 23, 2023, 3:25am UTC](https://discuss.elastic.co/t/io-netty-handler-ssl-sslhandshaketimeoutexception-handshake-timed-out-after-10000ms/326117 "2023-02-23T03:25:11Z")

</div>

Hi Team, We are getting this below exception daily. so, can you please give solution for this exception. we are using Elasticsearch 7.3.2, java version 1.8.0\_131 and tomcat version 9. 2023-02-19 18:55:20.683 \[elastic…

---

## [Elasticsearch getting killed by the oom killer because an out of memory](https://discuss.elastic.co/t/elasticsearch-getting-killed-by-the-oom-killer-because-an-out-of-memory/326218)

<div class="topic-metadata">

**Author:** [@noreddinelam](https://discuss.elastic.co/u/noreddinelam)\
**Replies:** 4\
**Last updated:** [February 23, 2023, 3:03am UTC](https://discuss.elastic.co/t/elasticsearch-getting-killed-by-the-oom-killer-because-an-out-of-memory/326218 "2023-02-23T03:03:13Z")

</div>

Good morning, We are facing the problem "Out Of Memory" with elasticsearch. Our configuration : We are running on ec2 instance (tg4.micro) with 1gb ram and 1cpu. I know that perhaps it is not sufficient but i want to …

---

## [How to get current/existing pipelines from ELK](https://discuss.elastic.co/t/how-to-get-current-existing-pipelines-from-elk/326217)

<div class="topic-metadata">

**Author:** [@tymercer](https://discuss.elastic.co/u/tymercer)\
**Replies:** 4\
**Last updated:** [February 22, 2023, 10:51pm UTC](https://discuss.elastic.co/t/how-to-get-current-existing-pipelines-from-elk/326217 "2023-02-22T22:51:50Z")

</div>

I just became the owner of a very old ELK cluster and need to get all of the configs pulled from it to migrate to a cloud hosted instance. The system shows there are several pipelines in Kibana Management, Logstash, Pip…

---

## [Config Map condition based on the log event on child element](https://discuss.elastic.co/t/config-map-condition-based-on-the-log-event-on-child-element/326213)

<div class="topic-metadata">

**Author:** [@rravitech](https://discuss.elastic.co/u/rravitech)\
**Replies:** 4\
**Last updated:** [February 22, 2023, 10:09pm UTC](https://discuss.elastic.co/t/config-map-condition-based-on-the-log-event-on-child-element/326213 "2023-02-22T22:09:24Z")

</div>

Here is what i am trying to achieve. Below is my log event { "version" : "1.0.0", "message" : "noisemaker draftsmanship's soundproofing grads werewolf's", "@version" : "1", "logplane"…

[Previous page](https://discuss.elastic.co/tag/none.md?no_tags=true&page=428)

[Next page](https://discuss.elastic.co/tag/none.md?no_tags=true&page=430)
