# \#none

**URL:** https://discuss.elastic.co/tag/none.md?no_tags=true&page=432

[Latest](https://discuss.elastic.co/latest.md) · [Categories](https://discuss.elastic.co/categories.md) · [Tags](https://discuss.elastic.co/tags.md)

**Page:** 433

---

## [Kibana UI Change](https://discuss.elastic.co/t/kibana-ui-change/325938)

<div class="topic-metadata">

**Author:** [@Ajay\_Kotnala](https://discuss.elastic.co/u/Ajay_Kotnala)\
**Replies:** 3\
**Last updated:** [February 20, 2023, 1:00pm UTC](https://discuss.elastic.co/t/kibana-ui-change/325938 "2023-02-20T13:00:54Z")

</div>

Is there a way to remove the option toggle dialog with the details option in Kibana UI. Need to rollback to older layout.

---

## [Details of Elasticserver receiving logs](https://discuss.elastic.co/t/details-of-elasticserver-receiving-logs/325969)

<div class="topic-metadata">

**Author:** [@Kosala\_Randika\_Paran](https://discuss.elastic.co/u/Kosala_Randika_Paran)\
**Replies:** 1\
**Last updated:** [February 20, 2023, 12:45pm UTC](https://discuss.elastic.co/t/details-of-elasticserver-receiving-logs/325969 "2023-02-20T12:45:13Z")

</div>

Hi flocks, We have a fresh ELK stack and now I am trying to create a details dashboard for ES receiving logs daily, weekly and monthly, so we do not have much indexes but default ones. since I am new to this subject is …

---

## [Aliases API : error deleting index](https://discuss.elastic.co/t/aliases-api-error-deleting-index/325265)

<div class="topic-metadata">

**Author:** [@quentin.renoux](https://discuss.elastic.co/u/quentin.renoux)\
**Replies:** 2\
**Last updated:** [February 20, 2023, 12:36pm UTC](https://discuss.elastic.co/t/aliases-api-error-deleting-index/325265 "2023-02-20T12:36:06Z")

</div>

Hi everyone, TL;DR : the \_aliases API throw error trying to remove index saying it doesn't exist but it does. I'm using the aliases API to swap two indices behind an alias in a single atomic operation. I'm following th…

---

## [How to Install APM Server in Legacy mode without Elastic APM Integration](https://discuss.elastic.co/t/how-to-install-apm-server-in-legacy-mode-without-elastic-apm-integration/325724)

<div class="topic-metadata">

**Author:** [@Mikele](https://discuss.elastic.co/u/Mikele)\
**Replies:** 2\
**Last updated:** [February 20, 2023, 11:50am UTC](https://discuss.elastic.co/t/how-to-install-apm-server-in-legacy-mode-without-elastic-apm-integration/325724 "2023-02-20T11:50:05Z")

</div>

I would like to install APM Server in old way so in Legacy. I have few problems with this installation. Could someone explain me two cases: Is it possible to install APM in Legacy mode without this step? Step 2: Set…

---

## [Kibana UI Not Accessible](https://discuss.elastic.co/t/kibana-ui-not-accessible/325904)

<div class="topic-metadata">

**Author:** [@altif](https://discuss.elastic.co/u/altif)\
**Replies:** 2\
**Last updated:** [February 20, 2023, 11:12am UTC](https://discuss.elastic.co/t/kibana-ui-not-accessible/325904 "2023-02-20T11:12:24Z")

</div>

Greetings, I'm a Kibana novice who recently imported saved-objects via the Kibana UI. However, upon importing the saved-objects JSON file, I encountered an error as illustrated in the attached screenshot. Whenever I…

---

## [Mapper\_parsing\_exception](https://discuss.elastic.co/t/mapper-parsing-exception/325962)

<div class="topic-metadata">

**Author:** [@Roshan\_M\_Thomas](https://discuss.elastic.co/u/Roshan_M_Thomas)\
**Replies:** 0\
**Last updated:** [February 20, 2023, 11:04am UTC](https://discuss.elastic.co/t/mapper-parsing-exception/325962 "2023-02-20T11:04:53Z")

</div>

Hi , getting this error in elastic 7.8.1 and 8.0.0 while inserting mapping using PUT method. Please help us to resolve it. { "error": { "root\_cause": \[ { "type": "mapper\_parsing\_exception", "reason": "Root mapping …

---

## [Elasticsearch creates empty directories in /tmp, can I delete these empty directories](https://discuss.elastic.co/t/elasticsearch-creates-empty-directories-in-tmp-can-i-delete-these-empty-directories/325887)

<div class="topic-metadata">

**Author:** [@eranga\_bandara](https://discuss.elastic.co/u/eranga_bandara)\
**Replies:** 2\
**Last updated:** [February 20, 2023, 8:59am UTC](https://discuss.elastic.co/t/elasticsearch-creates-empty-directories-in-tmp-can-i-delete-these-empty-directories/325887 "2023-02-20T08:59:47Z")

</div>

Elasticsearch creates directories inside /tmp. These directories used to execute native code by jna and libffi. Most of the time these directories are empty and have the name like elasticsearch.KNoHBn19. more info here. …

---

## [How to check the index size on daily basis using python scripts?](https://discuss.elastic.co/t/how-to-check-the-index-size-on-daily-basis-using-python-scripts/325377)

<div class="topic-metadata">

**Author:** [@jisha](https://discuss.elastic.co/u/jisha)\
**Replies:** 1\
**Last updated:** [February 20, 2023, 9:48am UTC](https://discuss.elastic.co/t/how-to-check-the-index-size-on-daily-basis-using-python-scripts/325377 "2023-02-20T09:48:01Z")

</div>

Hi, Does anyone know how to check the index size on daily basis using python scripts?

---

## [When Downloading CSV, one variable value's is getting in two different column because of comma](https://discuss.elastic.co/t/when-downloading-csv-one-variable-values-is-getting-in-two-different-column-because-of-comma/324984)

<div class="topic-metadata">

**Author:** [@Arshukla](https://discuss.elastic.co/u/Arshukla)\
**Replies:** 5\
**Last updated:** [February 20, 2023, 9:25am UTC](https://discuss.elastic.co/t/when-downloading-csv-one-variable-values-is-getting-in-two-different-column-because-of-comma/324984 "2023-02-20T09:25:07Z")

</div>

When Downloading CSV from Tabular format, each variable is getting separated with Comma (,). Due to this variable which are numerical values (for e.g., 2,946) are also getting in different columns. As shown in below ima…

---

## [Unable to get real time logs for Elastic-Github Integration](https://discuss.elastic.co/t/unable-to-get-real-time-logs-for-elastic-github-integration/324993)

<div class="topic-metadata">

**Author:** [@Pallavi\_Kshirsagar](https://discuss.elastic.co/u/Pallavi_Kshirsagar)\
**Replies:** 0\
**Last updated:** [February 8, 2023, 10:09am UTC](https://discuss.elastic.co/t/unable-to-get-real-time-logs-for-elastic-github-integration/324993 "2023-02-08T10:09:39Z")

</div>

I've performed Github integration using elastic agent, where I'm running the agent on an EC2 instance. When I go to Discover the logs I see that logs aren't pulled in real time and I get to see too old logs until a certa…

---

## [Two data folder present](https://discuss.elastic.co/t/two-data-folder-present/325834)

<div class="topic-metadata">

**Author:** [@dev\_sab](https://discuss.elastic.co/u/dev_sab)\
**Replies:** 2\
**Last updated:** [February 20, 2023, 8:59am UTC](https://discuss.elastic.co/t/two-data-folder-present/325834 "2023-02-20T08:59:00Z")

</div>

Hello All, I am having the scenario two data folder present. I have accidently changed the path.data in elasticsearch.yml file. So, Two data folder present, one with old data and another with new data. I need to merge …

---

## [Logstash masking logs syntax](https://discuss.elastic.co/t/logstash-masking-logs-syntax/325699)

<div class="topic-metadata">

**Author:** [@furkano](https://discuss.elastic.co/u/furkano)\
**Replies:** 3\
**Last updated:** [February 20, 2023, 5:32am UTC](https://discuss.elastic.co/t/logstash-masking-logs-syntax/325699 "2023-02-20T05:32:58Z")

</div>

Hi, I want to mask some logs in spesific fields, for example if end point ends with api or token i want to remove userKey messages from field ResponseMessage But not whole field that i want to remove or mask, only the …

---

## [Проблема с парсингом логов в Logstash](https://discuss.elastic.co/t/logstash/325927)

<div class="topic-metadata">

**Author:** [@Bender1](https://discuss.elastic.co/u/Bender1)\
**Replies:** 0\
**Last updated:** [February 20, 2023, 3:39am UTC](https://discuss.elastic.co/t/logstash/325927 "2023-02-20T03:39:47Z")

</div>

Пришла в голову идея добывать и хранить логи с большого зоопарка сетевого оборудования с помощью ELK. Все шло отлично, пока не добрался до фильтров. Вот пример моих логов: 23-Nov-2008 03:53:27 :%STP-W-PORTSTATUS: e1: …

---

## [Elasticsearch error all shards failed on single node](https://discuss.elastic.co/t/elasticsearch-error-all-shards-failed-on-single-node/325812)

<div class="topic-metadata">

**Author:** [@yc99](https://discuss.elastic.co/u/yc99)\
**Replies:** 6\
**Last updated:** [February 20, 2023, 3:19am UTC](https://discuss.elastic.co/t/elasticsearch-error-all-shards-failed-on-single-node/325812 "2023-02-20T03:19:13Z")

</div>

Caused by: org.elasticsearch.action.NoShardAvailableActionException: \[ip-13-35-23-200.ap-1.compute.internal\]\[13.35.23.200:9300\]\[indices:data/read/search\[phase/query\]\] \[2023-02-17T08:14:15,934\]\[WARN \]\[r.suppressed …

---

## [Beginner’s Crash Course to Elastic Stack - Part 4: Aggregations | Issues with data](https://discuss.elastic.co/t/beginner-s-crash-course-to-elastic-stack-part-4-aggregations-issues-with-data/325902)

<div class="topic-metadata">

**Author:** [@pathaniaamn](https://discuss.elastic.co/u/pathaniaamn)\
**Replies:** 4\
**Last updated:** [February 20, 2023, 3:13am UTC](https://discuss.elastic.co/t/beginner-s-crash-course-to-elastic-stack-part-4-aggregations-issues-with-data/325902 "2023-02-20T03:13:24Z")

</div>

After importing the data.csv file and running the STEP 1: Create a new index(ecommerce\_data) with the following mapping., I am getting an error: { "error": { "root\_cause": \[ { "type": "resource\_already\_exists\_except…

---

## [Elasticsearch data node out of memory](https://discuss.elastic.co/t/elasticsearch-data-node-out-of-memory/325866)

<div class="topic-metadata">

**Author:** [@sssamant](https://discuss.elastic.co/u/sssamant)\
**Replies:** 6\
**Last updated:** [February 20, 2023, 2:26am UTC](https://discuss.elastic.co/t/elasticsearch-data-node-out-of-memory/325866 "2023-02-20T02:26:02Z")

</div>

Hello everyone, We are having out of memory issue for the elasticsearch data nodes? Can you please help me out to find the issue. Here is log from elasticsearch cluster. \[2023-02-17 10:02:47,551\]\[WARN \]\[netty.channel.…

---

## [Kibana not found in custom definitions using Istio](https://discuss.elastic.co/t/kibana-not-found-in-custom-definitions-using-istio/325925)

<div class="topic-metadata">

**Author:** [@Fran\_D](https://discuss.elastic.co/u/Fran_D)\
**Replies:** 0\
**Last updated:** [February 20, 2023, 12:19am UTC](https://discuss.elastic.co/t/kibana-not-found-in-custom-definitions-using-istio/325925 "2023-02-20T00:19:57Z")

</div>

The deployment of the elastic operator is working fine, following the steps of this guide: https://www.elastic.co/guide/en/cloud-on-k8s/current/k8s-service-mesh-istio.html After deploying the Kibana, anything is starti…

---

## [Installed Lateral movement detection package but couldn't find the package under ML preconfigured jobs](https://discuss.elastic.co/t/installed-lateral-movement-detection-package-but-couldnt-find-the-package-under-ml-preconfigured-jobs/325809)

<div class="topic-metadata">

**Author:** [@deepthi.manam](https://discuss.elastic.co/u/deepthi.manam)\
**Replies:** 2\
**Last updated:** [February 20, 2023, 1:31am UTC](https://discuss.elastic.co/t/installed-lateral-movement-detection-package-but-couldnt-find-the-package-under-ml-preconfigured-jobs/325809 "2023-02-20T01:31:40Z")

</div>

I have installed lateral movement detection package under Integrations but haven't created any policies. I couldn't find Lateral movement detection under ML preconfigured jobs while creating a job. Does this require a i…

---

## [Kubectl can not create elastic podse](https://discuss.elastic.co/t/kubectl-can-not-create-elastic-podse/325917)

<div class="topic-metadata">

**Author:** [@suminlim](https://discuss.elastic.co/u/suminlim)\
**Replies:** 0\
**Last updated:** [February 19, 2023, 4:23pm UTC](https://discuss.elastic.co/t/kubectl-can-not-create-elastic-podse/325917 "2023-02-19T16:23:03Z")

</div>

root@~# kubectl get elasticsearch NAME HEALTH NODES VERSION PHASE AGE quickstart 50s root@~# kubectl get pods --selector='elasticsearch.k8s.elastic.co/cluster-name=…

---

## [Unassigned Shards - issue](https://discuss.elastic.co/t/unassigned-shards-issue/325692)

<div class="topic-metadata">

**Author:** [@azuramazda](https://discuss.elastic.co/u/azuramazda)\
**Replies:** 1\
**Last updated:** [February 19, 2023, 9:00pm UTC](https://discuss.elastic.co/t/unassigned-shards-issue/325692 "2023-02-19T21:00:59Z")

</div>

I am facing an issue with ES where it shows 174 shards are unassigned. and allocate\_explanation is :"cannot allocate because all found copies of the shard are there stale or corrupt". This issue is arising since yesterd…

---

## [Systemctl reload elasticsearch.service or systemctl restart elasticsearch.service](https://discuss.elastic.co/t/systemctl-reload-elasticsearch-service-or-systemctl-restart-elasticsearch-service/325703)

<div class="topic-metadata">

**Author:** [@firdaussaad](https://discuss.elastic.co/u/firdaussaad)\
**Replies:** 1\
**Last updated:** [February 19, 2023, 8:59pm UTC](https://discuss.elastic.co/t/systemctl-reload-elasticsearch-service-or-systemctl-restart-elasticsearch-service/325703 "2023-02-19T20:59:33Z")

</div>

Hi all, I am currently working on a bash script. Whenever i make changes to elasticsearch.yml file, should i perform systemctl reload elascticsearch.service or systemctl restart elasticsearch.service? Any difference be…

---

## [Integration Elastic : bonnes pratiques](https://discuss.elastic.co/t/integration-elastic-bonnes-pratiques/325742)

<div class="topic-metadata">

**Author:** [@franck67](https://discuss.elastic.co/u/franck67)\
**Replies:** 4\
**Last updated:** [February 19, 2023, 8:59pm UTC](https://discuss.elastic.co/t/integration-elastic-bonnes-pratiques/325742 "2023-02-19T20:59:03Z")

</div>

Bonjour, Ayant vu la puissance d'Elastic lors de presentations en ligne, je voudrais installer ceci chez moi. Je vois pleins de documentations, mais malheureusement, je ne trouve pas vraiment de doc en francais, avec u…

---

## [Is it possible to configure SAML authentication in kibana 7.17 version without changing the elasticsearch.yml](https://discuss.elastic.co/t/is-it-possible-to-configure-saml-authentication-in-kibana-7-17-version-without-changing-the-elasticsearch-yml/325727)

<div class="topic-metadata">

**Author:** [@Vlada\_Homyakova](https://discuss.elastic.co/u/Vlada_Homyakova)\
**Replies:** 1\
**Last updated:** [February 19, 2023, 8:57pm UTC](https://discuss.elastic.co/t/is-it-possible-to-configure-saml-authentication-in-kibana-7-17-version-without-changing-the-elasticsearch-yml/325727 "2023-02-19T20:57:06Z")

</div>

Hi I'm trying to integrate kibana with okta saml, I try to get constantly FATAL Error: \[config validation of \[xpack.security\].authc.realm\]: Epexted a String but got an object xpack.security.authc.providers: - saml …

---

## [LogDriver.StartLogging: error creating client config: A hosts flag is required](https://discuss.elastic.co/t/logdriver-startlogging-error-creating-client-config-a-hosts-flag-is-required/325800)

<div class="topic-metadata">

**Author:** [@cavarzan](https://discuss.elastic.co/u/cavarzan)\
**Replies:** 1\
**Last updated:** [February 19, 2023, 8:54pm UTC](https://discuss.elastic.co/t/logdriver-startlogging-error-creating-client-config-a-hosts-flag-is-required/325800 "2023-02-19T20:54:15Z")

</div>

I'm receiving the following error when I try to start a docker-compose service with elastic-apm.jar configured. LogDriver.StartLogging: error creating client config: A hosts flag is required I've looked at this answer,…

---

## [Is "http://localhost:9200/\_all/\_stats/\_all" an expensive call?](https://discuss.elastic.co/t/is-http-localhost-9200-all-stats-all-an-expensive-call/325907)

<div class="topic-metadata">

**Author:** [@junhuangli](https://discuss.elastic.co/u/junhuangli)\
**Replies:** 6\
**Last updated:** [February 19, 2023, 8:43pm UTC](https://discuss.elastic.co/t/is-http-localhost-9200-all-stats-all-an-expensive-call/325907 "2023-02-19T20:43:02Z")

</div>

We are using open-telemetry to monitor the es cluster. And I found the open-telemetry receiver is sending request to "http://localhost:9200/\_all/\_stats/\_all" to pull the metrics. One issue I notice is if the receiver is …

---

## ["Elasticsearch Unreachable: \[http://localhost:9200/\]\[Manticore::ClientProtocolException\] localhost:9200 failed to respond"}](https://discuss.elastic.co/t/elasticsearch-unreachable-http-localhost-9200-manticore-clientprotocolexception-localhost-9200-failed-to-respond/325897)

<div class="topic-metadata">

**Author:** [@Matt\_Johnston](https://discuss.elastic.co/u/Matt_Johnston)\
**Replies:** 10\
**Last updated:** [February 19, 2023, 7:20pm UTC](https://discuss.elastic.co/t/elasticsearch-unreachable-http-localhost-9200-manticore-clientprotocolexception-localhost-9200-failed-to-respond/325897 "2023-02-19T19:20:51Z")

</div>

Hi. I'm trying to follow the "Parsing Logs with Logstash" (Tutorial), and I am having trouble when I try to connect my pipeline to Elasticsearch. My first-pipeline.conf file looks like this: input { beats { …

---

## [Closing node](https://discuss.elastic.co/t/closing-node/325913)

<div class="topic-metadata">

**Author:** [@avnere](https://discuss.elastic.co/u/avnere)\
**Replies:** 7\
**Last updated:** [February 19, 2023, 3:53pm UTC](https://discuss.elastic.co/t/closing-node/325913 "2023-02-19T15:53:31Z")

</div>

Hi, I want to close node, and want elastic to move his to different node. What is the procedure for closing node? How it can be done automatically? Thanks.

---

## [Joining two indexes](https://discuss.elastic.co/t/joining-two-indexes/325876)

<div class="topic-metadata">

**Author:** [@etp](https://discuss.elastic.co/u/etp)\
**Replies:** 2\
**Last updated:** [February 19, 2023, 2:57pm UTC](https://discuss.elastic.co/t/joining-two-indexes/325876 "2023-02-19T14:57:06Z")

</div>

Hi, I have two indices A and B. I wanted to perform inner join on the two indices using a common field such that I can collect the fields(spread across both indices) into another index using transforms. What aggregatio…

---

## [Improve search performance beyond 2x](https://discuss.elastic.co/t/improve-search-performance-beyond-2x/325537)

<div class="topic-metadata">

**Author:** [@pathaniaamn](https://discuss.elastic.co/u/pathaniaamn)\
**Replies:** 3\
**Last updated:** [February 19, 2023, 10:15am UTC](https://discuss.elastic.co/t/improve-search-performance-beyond-2x/325537 "2023-02-19T10:15:22Z")

</div>

Question on replica shard: Node1 P0 Node2 P1 Node3 R0 Node4 R1 So, overall search performance can get 2x as Primary and Replica shards will share the search load. But what is next if search load increases to 5 f…

---

## [ICU Tokenizer to keep tags and hashtags in token](https://discuss.elastic.co/t/icu-tokenizer-to-keep-tags-and-hashtags-in-token/325909)

<div class="topic-metadata">

**Author:** [@kaanebv](https://discuss.elastic.co/u/kaanebv)\
**Replies:** 0\
**Last updated:** [February 19, 2023, 9:07am UTC](https://discuss.elastic.co/t/icu-tokenizer-to-keep-tags-and-hashtags-in-token/325909 "2023-02-19T09:07:56Z")

</div>

I'm using ICU tokenizer with a custom analyzer but it doesn't keep hashtag in token. I have tried word\_delimiter and icu\_normalizer but they didn't work. Is there any solution to this?

[Previous page](https://discuss.elastic.co/tag/none.md?no_tags=true&page=431)

[Next page](https://discuss.elastic.co/tag/none.md?no_tags=true&page=433)
