# \#none

**URL:** https://discuss.elastic.co/tag/none.md?no_tags=true&page=433

[Latest](https://discuss.elastic.co/latest.md) · [Categories](https://discuss.elastic.co/categories.md) · [Tags](https://discuss.elastic.co/tags.md)

**Page:** 434

---

## [Restoring Dashboards](https://discuss.elastic.co/t/restoring-dashboards/325738)

<div class="topic-metadata">

**Author:** [@Faisaljodayn](https://discuss.elastic.co/u/Faisaljodayn)\
**Replies:** 6\
**Last updated:** [February 19, 2023, 5:39am UTC](https://discuss.elastic.co/t/restoring-dashboards/325738 "2023-02-19T05:39:17Z")

</div>

Hi everyone, Today while we were working on dashboards. We deleted a model package by mistake and it affected all the dashboards. Basically, all the indices are present but with no data. All the configurations and every…

---

## [Can elasticsearch/kibana/... export trace/span log as datasets?](https://discuss.elastic.co/t/can-elasticsearch-kibana-export-trace-span-log-as-datasets/325855)

<div class="topic-metadata">

**Author:** [@elkLearner](https://discuss.elastic.co/u/elkLearner)\
**Replies:** 3\
**Last updated:** [February 19, 2023, 4:07am UTC](https://discuss.elastic.co/t/can-elasticsearch-kibana-export-trace-span-log-as-datasets/325855 "2023-02-19T04:07:09Z")

</div>

I'm a freshman here. I'm using skywalking+elasticsearch monitoring a microservice application in k8s. l know skywalking can collect trace/span logs from microservice and store the data in elasticsearch, and then display …

---

## [How to use mutli\_match with same value](https://discuss.elastic.co/t/how-to-use-mutli-match-with-same-value/325882)

<div class="topic-metadata">

**Author:** [@anhhungxdieu](https://discuss.elastic.co/u/anhhungxdieu)\
**Replies:** 4\
**Last updated:** [February 19, 2023, 2:49am UTC](https://discuss.elastic.co/t/how-to-use-mutli-match-with-same-value/325882 "2023-02-19T02:49:35Z")

</div>

I'm using elastic ver7.17 My sample documents : { "title" : "Firmly stepping forward under the glorious banner of the Party", "intro": "In celebration of the Party’s founding anniversary and the new spring, we proudl…

---

## [What happens when the document data has special characters like "party-planning" or "Michelle\_obama" ? I see that Elasticsearch includes them in the hit. how do we ignore such documents? Is Elasticsearch case sensitive?](https://discuss.elastic.co/t/what-happens-when-the-document-data-has-special-characters-like-party-planning-or-michelle-obama-i-see-that-elasticsearch-includes-them-in-the-hit-how-do-we-ignore-such-documents-is-elasticsearch-case-sensitive/325901)

<div class="topic-metadata">

**Author:** [@pathaniaamn](https://discuss.elastic.co/u/pathaniaamn)\
**Replies:** 0\
**Last updated:** [February 19, 2023, 1:17am UTC](https://discuss.elastic.co/t/what-happens-when-the-document-data-has-special-characters-like-party-planning-or-michelle-obama-i-see-that-elasticsearch-includes-them-in-the-hit-how-do-we-ignore-such-documents-is-elasticsearch-case-sensitive/325901 "2023-02-19T01:17:32Z")

</div>

Two questions: What happens when the document data has special characters like "party-planning" or "Michelle\_obama" ? I see that Elasticsearch includes them in the hit. how do we ignore such documents? Is Elasticsearch…

---

## [UNABLE to filter the fields in the security alerts window](https://discuss.elastic.co/t/unable-to-filter-the-fields-in-the-security-alerts-window/324242)

<div class="topic-metadata">

**Author:** [@frank\_rib](https://discuss.elastic.co/u/frank_rib)\
**Replies:** 9\
**Last updated:** [February 18, 2023, 11:11pm UTC](https://discuss.elastic.co/t/unable-to-filter-the-fields-in-the-security-alerts-window/324242 "2023-02-18T23:11:07Z")

</div>

Hello every body, Many alerts are generated in the security Alerts window of elastic 8.3.1, Especially attempts of brute force: The winlog. event\_data. The TargetUserName field is the user-specific field. I'm no…

---

## [Is cloudfront codec ever works before?](https://discuss.elastic.co/t/is-cloudfront-codec-ever-works-before/325879)

<div class="topic-metadata">

**Author:** [@stwang](https://discuss.elastic.co/u/stwang)\
**Replies:** 1\
**Last updated:** [February 18, 2023, 5:15am UTC](https://discuss.elastic.co/t/is-cloudfront-codec-ever-works-before/325879 "2023-02-18T05:15:56Z")

</div>

Hi There, I am try to parse cloudfront log in logstash, and I found there has a cloudfront codec can be used. but I never make it works. Can someone pointing me a vaild config, or this codec never works before? Cheers…

---

## [Shodan.io query return json mapping, nested dynamic mapping](https://discuss.elastic.co/t/shodan-io-query-return-json-mapping-nested-dynamic-mapping/325761)

<div class="topic-metadata">

**Author:** [@stcdarrell](https://discuss.elastic.co/u/stcdarrell)\
**Replies:** 3\
**Last updated:** [February 17, 2023, 8:52pm UTC](https://discuss.elastic.co/t/shodan-io-query-return-json-mapping-nested-dynamic-mapping/325761 "2023-02-17T20:52:13Z")

</div>

hi, i'm using some python to query shodan.io, it returns a reasonably complex json that i'd like to push into Elasticsearch. i've got most mapped out and its work, but there is one field i just cant to map correctly. the…

---

## [How to Search word and digits](https://discuss.elastic.co/t/how-to-search-word-and-digits/325848)

<div class="topic-metadata">

**Author:** [@Mohamed\_Farshath](https://discuss.elastic.co/u/Mohamed_Farshath)\
**Replies:** 3\
**Last updated:** [February 17, 2023, 8:24pm UTC](https://discuss.elastic.co/t/how-to-search-word-and-digits/325848 "2023-02-17T20:24:39Z")

</div>

Hey guys, I need help searching this message's contents which has a word and a code that varies from 4 to 6 digits. examples are follows: enter this : 4567 enter this : 567893

---

## [Parse Date with RFC\_1123\_DATE\_TIME format](https://discuss.elastic.co/t/parse-date-with-rfc-1123-date-time-format/325863)

<div class="topic-metadata">

**Author:** [@valleram](https://discuss.elastic.co/u/valleram)\
**Replies:** 4\
**Last updated:** [February 17, 2023, 7:03pm UTC](https://discuss.elastic.co/t/parse-date-with-rfc-1123-date-time-format/325863 "2023-02-17T19:03:42Z")

</div>

Hi All, I'm ingesting documents to my ES cluster with a field called CREATION\_TIME with format Wed, 13 Oct 2021 13:04:54 GMT. I've tried to parse it using below mappings, but Kibana is still ignoring the value. { "p…

---

## [Index/alias Filter(s)](https://discuss.elastic.co/t/index-alias-filter-s/325851)

<div class="topic-metadata">

**Author:** [@Talvaro](https://discuss.elastic.co/u/Talvaro)\
**Replies:** 3\
**Last updated:** [February 17, 2023, 5:52pm UTC](https://discuss.elastic.co/t/index-alias-filter-s/325851 "2023-02-17T17:52:59Z")

</div>

I'm researching an issue with a existing application I just got as responsible. I am not too familiar with Elastic/Kibana. The issue is the application reading docs from an Alias is not getting all expected results. I no…

---

## [Certificate issue](https://discuss.elastic.co/t/certificate-issue/325813)

<div class="topic-metadata">

**Author:** [@akhilkv43](https://discuss.elastic.co/u/akhilkv43)\
**Replies:** 1\
**Last updated:** [February 17, 2023, 5:02pm UTC](https://discuss.elastic.co/t/certificate-issue/325813 "2023-02-17T17:02:23Z")

</div>

How can i generate a pem certificate in Elasticsearch I am using 8.5 version

---

## [How to plan and implement shard allocation awareness for the below 3 master 6 data node setup](https://discuss.elastic.co/t/how-to-plan-and-implement-shard-allocation-awareness-for-the-below-3-master-6-data-node-setup/325858)

<div class="topic-metadata">

**Author:** [@H\_K7](https://discuss.elastic.co/u/H_K7)\
**Replies:** 0\
**Last updated:** [February 17, 2023, 3:23pm UTC](https://discuss.elastic.co/t/how-to-plan-and-implement-shard-allocation-awareness-for-the-below-3-master-6-data-node-setup/325858 "2023-02-17T15:23:27Z")

</div>

Current setup hosted in aws ec2, self managed/hosted opensource version of elasticsearch master-1 - us-east-1a master-2 - us-east-1b master-2 - us-east-1c data-1 - us-east-1a data-2 - us-east-1b data-3 - us-east-1c …

---

## [Custom grok write for my message](https://discuss.elastic.co/t/custom-grok-write-for-my-message/325728)

<div class="topic-metadata">

**Author:** [@dharminfadia](https://discuss.elastic.co/u/dharminfadia)\
**Replies:** 5\
**Last updated:** [February 17, 2023, 2:37pm UTC](https://discuss.elastic.co/t/custom-grok-write-for-my-message/325728 "2023-02-17T14:37:47Z")

</div>

Hello Everyone I am having following example logs I want to extract field using filebeat any one can help ? 0.0.0.0 - - \[16/Feb/2023:09:54:40 +0000\] "POST /api/WebsiteCategory/ProductDesigns HTTP/1.1" 200 95521 "https:…

---

## [Elastic Defend host is not registered to the endpoint](https://discuss.elastic.co/t/elastic-defend-host-is-not-registered-to-the-endpoint/325805)

<div class="topic-metadata">

**Author:** [@xqaiviwjxzw](https://discuss.elastic.co/u/xqaiviwjxzw)\
**Replies:** 1\
**Last updated:** [February 17, 2023, 2:35pm UTC](https://discuss.elastic.co/t/elastic-defend-host-is-not-registered-to-the-endpoint/325805 "2023-02-17T14:35:50Z")

</div>

Hello everyone, I have this problem and I am looking for your help. I created a new policy in Fleet that includes Elastic Defend integration, but my newly registered elastic agent is not registered to the host of the en…

---

## [How to keep only longest token occupying the same positions](https://discuss.elastic.co/t/how-to-keep-only-longest-token-occupying-the-same-positions/325849)

<div class="topic-metadata">

**Author:** [@Valentin\_Pletzer](https://discuss.elastic.co/u/Valentin_Pletzer)\
**Replies:** 0\
**Last updated:** [February 17, 2023, 2:04pm UTC](https://discuss.elastic.co/t/how-to-keep-only-longest-token-occupying-the-same-positions/325849 "2023-02-17T14:04:09Z")

</div>

Is there a way too keep only the longest token if two or more tokens occupy the same positions? e.g. if I define "fox" and "quick fox" as keep words obviously both would be return when analyzing the sentence "the quick …

---

## [Fielddata on a custom analyzer that is of keyword tokenizer](https://discuss.elastic.co/t/fielddata-on-a-custom-analyzer-that-is-of-keyword-tokenizer/325846)

<div class="topic-metadata">

**Author:** [@drjz](https://discuss.elastic.co/u/drjz)\
**Replies:** 0\
**Last updated:** [February 17, 2023, 1:35pm UTC](https://discuss.elastic.co/t/fielddata-on-a-custom-analyzer-that-is-of-keyword-tokenizer/325846 "2023-02-17T13:35:18Z")

</div>

I created a custom analyzer that does lowercasing. The reason why I did not use a normalizer is because I need to apply stopword filter that the normalizer is not supporting. "lowercase\_analyzer": { …

---

## [Filter working in "Discover" field, but the same filter in Dashboard/lense does not](https://discuss.elastic.co/t/filter-working-in-discover-field-but-the-same-filter-in-dashboard-lense-does-not/323395)

<div class="topic-metadata">

**Author:** [@JCW](https://discuss.elastic.co/u/JCW)\
**Replies:** 7\
**Last updated:** [February 17, 2023, 1:33pm UTC](https://discuss.elastic.co/t/filter-working-in-discover-field-but-the-same-filter-in-dashboard-lense-does-not/323395 "2023-02-17T13:33:46Z")

</div>

I'm using a tags - is - snort filter, on the discover tab it shows 5 hits in the last hour. I have a visualisation, that used the same index pattern etc, with the same filter and timeframe (tags - is - snort) which does…

---

## [ELK setup on ARO](https://discuss.elastic.co/t/elk-setup-on-aro/325837)

<div class="topic-metadata">

**Author:** [@vijay78](https://discuss.elastic.co/u/vijay78)\
**Replies:** 2\
**Last updated:** [February 17, 2023, 12:20pm UTC](https://discuss.elastic.co/t/elk-setup-on-aro/325837 "2023-02-17T12:20:38Z")

</div>

i would like to know that is it possible to setup ELK on ARO or no .as per some references ,says its not possible . if yes could you pls let me know how to setup ELK on ARO thanking in advance :slight\_smile:

---

## [I wanted to add comments in Chinese to make it easier to learn and understand. Why did the build fail?](https://discuss.elastic.co/t/i-wanted-to-add-comments-in-chinese-to-make-it-easier-to-learn-and-understand-why-did-the-build-fail/325826)

<div class="topic-metadata">

**Author:** [@xiaodizi](https://discuss.elastic.co/u/xiaodizi)\
**Replies:** 0\
**Last updated:** [February 17, 2023, 9:35am UTC](https://discuss.elastic.co/t/i-wanted-to-add-comments-in-chinese-to-make-it-easier-to-learn-and-understand-why-did-the-build-fail/325826 "2023-02-17T09:35:39Z")

</div>

!\[image|690x183\](upload: //nMdNEBcTf10uHBGKWm5z6abOYth.jpeg) I wanted to add comments in Chinese to make it easier to learn and understand. Why did the build fail?

---

## [Dashboards not showing in custom kibana space](https://discuss.elastic.co/t/dashboards-not-showing-in-custom-kibana-space/325420)

<div class="topic-metadata">

**Author:** [@huzaifa224](https://discuss.elastic.co/u/huzaifa224)\
**Replies:** 4\
**Last updated:** [February 17, 2023, 7:07am UTC](https://discuss.elastic.co/t/dashboards-not-showing-in-custom-kibana-space/325420 "2023-02-17T07:07:40Z")

</div>

I have created a two space in kibana one for production which is default space and second is for staging. on my production space all indexes are showing into it but on my staging space there is only staging index is show…

---

## [ELK setup on kubernetes](https://discuss.elastic.co/t/elk-setup-on-kubernetes/325811)

<div class="topic-metadata">

**Author:** [@vijay78](https://discuss.elastic.co/u/vijay78)\
**Replies:** 0\
**Last updated:** [February 17, 2023, 6:25am UTC](https://discuss.elastic.co/t/elk-setup-on-kubernetes/325811 "2023-02-17T06:25:04Z")

</div>

Iam trying to setup ELK on Azure kubernetes services (AKS) iam finding difficulties as not able to run Elasticsearch,logstash,kibana as a containers kindly help me on this as i don't want to go with ECK let me know if we…

---

## [ElasticSearch losing documents](https://discuss.elastic.co/t/elasticsearch-losing-documents/325185)

<div class="topic-metadata">

**Author:** [@apelk](https://discuss.elastic.co/u/apelk)\
**Replies:** 12\
**Last updated:** [February 17, 2023, 4:42am UTC](https://discuss.elastic.co/t/elasticsearch-losing-documents/325185 "2023-02-17T04:42:32Z")

</div>

Using ELK 7.8. We have a Logstash pipeline from JDBC database to Elasticsearch. Using persisted queues and DLQ. We lose about 1% of the documents we send to Elasticsearch. We have enabled TRACE on Elasticsearch and t…

---

## [Logstash to load input file based on time change](https://discuss.elastic.co/t/logstash-to-load-input-file-based-on-time-change/325806)

<div class="topic-metadata">

**Author:** [@dhiyaneshwaran](https://discuss.elastic.co/u/dhiyaneshwaran)\
**Replies:** 0\
**Last updated:** [February 17, 2023, 3:31am UTC](https://discuss.elastic.co/t/logstash-to-load-input-file-based-on-time-change/325806 "2023-02-17T03:31:13Z")

</div>

I'm using Logstash 7.17.0, in that i'm trying to load file using pipeline. It is taking file based on size or checksum changes, but i wanted to pick the file even if the size same but change in file timings. For exampl…

---

## [X-Forwarded-For in Elasticsearch/Kibana Logs](https://discuss.elastic.co/t/x-forwarded-for-in-elasticsearch-kibana-logs/325779)

<div class="topic-metadata">

**Author:** [@MakoWish](https://discuss.elastic.co/u/MakoWish)\
**Replies:** 2\
**Last updated:** [February 16, 2023, 11:31pm UTC](https://discuss.elastic.co/t/x-forwarded-for-in-elasticsearch-kibana-logs/325779 "2023-02-16T23:31:11Z")

</div>

We have Kibana and Elasticsearch behind AVI (Nginx) load-balancers, and that is unfortunately masking the true client IP addresses that are accessing Kibana/Elasticsearch. We are logging XFF headers on all the LB configs…

---

## [Automatic synonyms generation using ChatGPT or other AI solution?](https://discuss.elastic.co/t/automatic-synonyms-generation-using-chatgpt-or-other-ai-solution/325785)

<div class="topic-metadata">

**Author:** [@Youxu](https://discuss.elastic.co/u/Youxu)\
**Replies:** 0\
**Last updated:** [February 16, 2023, 11:24pm UTC](https://discuss.elastic.co/t/automatic-synonyms-generation-using-chatgpt-or-other-ai-solution/325785 "2023-02-16T23:24:35Z")

</div>

Anyone know if there is out-of-box automatic synonym generation based on index data using AI, like ChatGPT?

---

## [Confused by deprecation message](https://discuss.elastic.co/t/confused-by-deprecation-message/325780)

<div class="topic-metadata">

**Author:** [@Russell\_Fulton](https://discuss.elastic.co/u/Russell_Fulton)\
**Replies:** 0\
**Last updated:** [February 16, 2023, 10:10pm UTC](https://discuss.elastic.co/t/confused-by-deprecation-message/325780 "2023-02-16T22:10:43Z")

</div>

I am looking at upgrading my 7.17 cluster to version 8, first stop the depreciation logs! I notice that there is both a deprecation.log and a deprecation.json and they have different data. deprecation.log: \[2020-11-16…

---

## [Kibana 7.17.9 and 8.6.2 Security Update](https://discuss.elastic.co/t/kibana-7-17-9-and-8-6-2-security-update/325782)

<div class="topic-metadata">

**Author:** [@Levine](https://discuss.elastic.co/u/Levine)\
**Replies:** 0\
**Last updated:** [February 16, 2023, 10:56pm UTC](https://discuss.elastic.co/t/kibana-7-17-9-and-8-6-2-security-update/325782 "2023-02-16T22:56:41Z")

</div>

Kibana open redirect issue (ESA-2023-03) An open redirect issue was discovered in Kibana that could lead to a user being redirected to an arbitrary website if they use a maliciously crafted Kibana URL. Affected Versions…

---

## [Update API can't find document](https://discuss.elastic.co/t/update-api-cant-find-document/325777)

<div class="topic-metadata">

**Author:** [@friaca](https://discuss.elastic.co/u/friaca)\
**Replies:** 1\
**Last updated:** [February 16, 2023, 9:37pm UTC](https://discuss.elastic.co/t/update-api-cant-find-document/325777 "2023-02-16T21:37:25Z")

</div>

I'm trying to update a document field but had no success doing it. I can do a GET by ID with ticket-2/ticketelastic/134532 so that clarifies that the ID is valid and the document exists. { "\_index" : "ticket-2", "\_…

---

## [Kibana error - can't start due to error (problem with ES)](https://discuss.elastic.co/t/kibana-error-cant-start-due-to-error-problem-with-es/325409)

<div class="topic-metadata">

**Author:** [@Blazej\_Makula](https://discuss.elastic.co/u/Blazej_Makula)\
**Replies:** 5\
**Last updated:** [February 16, 2023, 8:47pm UTC](https://discuss.elastic.co/t/kibana-error-cant-start-due-to-error-problem-with-es/325409 "2023-02-16T20:47:58Z")

</div>

Hello, can you please help me with my home lab log collection system. I have two hosts one with logstash + elasticsearch + kibana and the other with logstash + elasticsearch. I want to connect kibana to both ES cluster…

---

## [Error while uploading bulk json to elasticsearch domain](https://discuss.elastic.co/t/error-while-uploading-bulk-json-to-elasticsearch-domain/325774)

<div class="topic-metadata">

**Author:** [@truptivala](https://discuss.elastic.co/u/truptivala)\
**Replies:** 2\
**Last updated:** [February 16, 2023, 8:18pm UTC](https://discuss.elastic.co/t/error-while-uploading-bulk-json-to-elasticsearch-domain/325774 "2023-02-16T20:18:36Z")

</div>

I am trying to upload the below json file to the elasticsearch domain I have on aws and getting the below error: Input json file: {"index": {"\_index": "ods-pcd-poc","\_id": "1"}}{"Page": 0,"Path": "//Document/Figure","T…

[Previous page](https://discuss.elastic.co/tag/none.md?no_tags=true&page=432)

[Next page](https://discuss.elastic.co/tag/none.md?no_tags=true&page=434)
