# \#none

**URL:** https://discuss.elastic.co/tag/none.md?no_tags=true&page=436

[Latest](https://discuss.elastic.co/latest.md) · [Categories](https://discuss.elastic.co/categories.md) · [Tags](https://discuss.elastic.co/tags.md)

**Page:** 437

---

## [Editing a managed policy can break Kibana caution](https://discuss.elastic.co/t/editing-a-managed-policy-can-break-kibana-caution/325515)

<div class="topic-metadata">

**Author:** [@David41](https://discuss.elastic.co/u/David41)\
**Replies:** 1\
**Last updated:** [February 14, 2023, 10:54pm UTC](https://discuss.elastic.co/t/editing-a-managed-policy-can-break-kibana-caution/325515 "2023-02-14T22:54:04Z")

</div>

Hi, I am wanting to edit an existing policy and I notice that there is a caution symbol that states that "Editing a managed policy can break Kibana" I am not sure if it will break or not . However there is an option tha…

---

## [How to parse csv via Elastic Agent?](https://discuss.elastic.co/t/how-to-parse-csv-via-elastic-agent/324121)

<div class="topic-metadata">

**Author:** [@test\_qweqwe](https://discuss.elastic.co/u/test_qweqwe)\
**Replies:** 16\
**Last updated:** [February 14, 2023, 9:05pm UTC](https://discuss.elastic.co/t/how-to-parse-csv-via-elastic-agent/324121 "2023-02-14T21:05:22Z")

</div>

Hi! I want to collects csv logs and if I understand correct, I need to add new integration based on "Custom Logs"? I'm not sure how to do it. I have this config for logstash under conf.d folder and everything work fin…

---

## [Elasticsearch query for \`SELECT id FROM foo WHERE id NOT IN (SELECT id FROM foo WHERE ...)](https://discuss.elastic.co/t/elasticsearch-query-for-select-id-from-foo-where-id-not-in-select-id-from-foo-where/325302)

<div class="topic-metadata">

**Author:** [@learningelastic](https://discuss.elastic.co/u/learningelastic)\
**Replies:** 4\
**Last updated:** [February 14, 2023, 7:51pm UTC](https://discuss.elastic.co/t/elasticsearch-query-for-select-id-from-foo-where-id-not-in-select-id-from-foo-where/325302 "2023-02-14T19:51:34Z")

</div>

I want to do a "not in present index" type of operation. For example, let's say I have an index called customer\_subscription with just these 4 records: | customer\_id | pay\_date | +-------------+------------+ | …

---

## [Unable to edit synthetic monitors because of limited privilege](https://discuss.elastic.co/t/unable-to-edit-synthetic-monitors-because-of-limited-privilege/325384)

<div class="topic-metadata">

**Author:** [@shinki927](https://discuss.elastic.co/u/shinki927)\
**Replies:** 2\
**Last updated:** [February 14, 2023, 7:32pm UTC](https://discuss.elastic.co/t/unable-to-edit-synthetic-monitors-because-of-limited-privilege/325384 "2023-02-14T19:32:00Z")

</div>

Hello, I would like to figure out which privilege is necessary to fully access the monitor management in Uptime. We grant the following privilege according to Elastic doc: Our user is able to create and delete monit…

---

## [No data streams and logs under fleet server](https://discuss.elastic.co/t/no-data-streams-and-logs-under-fleet-server/325493)

<div class="topic-metadata">

**Author:** [@Leonardo\_Henrique](https://discuss.elastic.co/u/Leonardo_Henrique)\
**Replies:** 0\
**Last updated:** [February 14, 2023, 3:21pm UTC](https://discuss.elastic.co/t/no-data-streams-and-logs-under-fleet-server/325493 "2023-02-14T15:21:35Z")

</div>

Hey everyone. I have configured fleet server but I can not see any log messages or data streams in the Kibana UI. Elasticsearch nodes are configured with SSL (with elasticsearch-certutil) and fleet-server is using the …

---

## [Implement User interface buttons for Logstash](https://discuss.elastic.co/t/implement-user-interface-buttons-for-logstash/323641)

<div class="topic-metadata">

**Author:** [@Sandeep\_Raju](https://discuss.elastic.co/u/Sandeep_Raju)\
**Replies:** 1\
**Last updated:** [February 14, 2023, 3:42pm UTC](https://discuss.elastic.co/t/implement-user-interface-buttons-for-logstash/323641 "2023-02-14T15:42:39Z")

</div>

Hi all, I am currently pushing data to indices in my elasticsearch 8.4 using logstash in my terminal. However , One of my friends does not know logstash and wants to work with logstash in User interface and push data i…

---

## [Index Patterns](https://discuss.elastic.co/t/index-patterns/325496)

<div class="topic-metadata">

**Author:** [@hnclientes\_HN](https://discuss.elastic.co/u/hnclientes_HN)\
**Replies:** 2\
**Last updated:** [February 14, 2023, 4:48pm UTC](https://discuss.elastic.co/t/index-patterns/325496 "2023-02-14T16:48:48Z")

</div>

Hi, I'm testing this version (cloud), and I can't find the option to create an index pattern for an index that I create using devtools. Could you tell me how I can activate this option please? Thank you

---

## [Logstash fetched data not available in elastic search](https://discuss.elastic.co/t/logstash-fetched-data-not-available-in-elastic-search/325216)

<div class="topic-metadata">

**Author:** [@ekambaram\_varathan](https://discuss.elastic.co/u/ekambaram_varathan)\
**Replies:** 1\
**Last updated:** [February 14, 2023, 3:26am UTC](https://discuss.elastic.co/t/logstash-fetched-data-not-available-in-elastic-search/325216 "2023-02-14T03:26:58Z")

</div>

Hi Team, I am using ELK version: 6.8.23. Though Logstash uploaded csv file data are not present in elasticsearch. my logstash conf file content as follows, input { file { path =\> "/home/data/reports/\*.csv" …

---

## [Yum is unable to update/install from elastic repo](https://discuss.elastic.co/t/yum-is-unable-to-update-install-from-elastic-repo/325221)

<div class="topic-metadata">

**Author:** [@Thomas3](https://discuss.elastic.co/u/Thomas3)\
**Replies:** 3\
**Last updated:** [February 14, 2023, 2:20pm UTC](https://discuss.elastic.co/t/yum-is-unable-to-update-install-from-elastic-repo/325221 "2023-02-14T14:20:51Z")

</div>

Hello, when trying to perform updates in RHEL8, I'm getting Failed to download metadata for repo 'logstash-7.x': Cannot download repomd.xml: Cannot download repodata/repomd.xml: All mirrors were tried with the follo…

---

## [Parse different records in 1 document](https://discuss.elastic.co/t/parse-different-records-in-1-document/325471)

<div class="topic-metadata">

**Author:** [@Bart-d-sdlr](https://discuss.elastic.co/u/Bart-d-sdlr)\
**Replies:** 0\
**Last updated:** [February 14, 2023, 12:25pm UTC](https://discuss.elastic.co/t/parse-different-records-in-1-document/325471 "2023-02-14T12:25:52Z")

</div>

Hi, I have a (maybe stupid) question concerning parsing of custom logfile where the Date is the first record followed by the detailed lines (time,....) I don't use logstash, but filebeat and pipelines Simple example: …

---

## [Remove json object from nested log](https://discuss.elastic.co/t/remove-json-object-from-nested-log/325468)

<div class="topic-metadata">

**Author:** [@Sharoze\_Meraj](https://discuss.elastic.co/u/Sharoze_Meraj)\
**Replies:** 0\
**Last updated:** [February 14, 2023, 12:03pm UTC](https://discuss.elastic.co/t/remove-json-object-from-nested-log/325468 "2023-02-14T12:03:08Z")

</div>

How can I use ruby code or some other filter plugin to detect and remove json object fields from my nested json logs. This is required because the fields can either be json objects or strings. If I remove the json objec…

---

## [Elasticsearch Master Quorum is lost](https://discuss.elastic.co/t/elasticsearch-master-quorum-is-lost/325459)

<div class="topic-metadata">

**Author:** [@tusharnemade](https://discuss.elastic.co/u/tusharnemade)\
**Replies:** 3\
**Last updated:** [February 14, 2023, 11:46am UTC](https://discuss.elastic.co/t/elasticsearch-master-quorum-is-lost/325459 "2023-02-14T11:46:57Z")

</div>

Hello : We are having Elasticsearch version 7.8.0 , running with 6 node cluster. All 6 nodes were data and master nodes. We have lost 3 Nodes out of 6 , and now we have message in logfile \[2023-02-14T10:58:47,994\]\[WA…

---

## [Retrieve data having date from 1st, Jan to current date on a date field](https://discuss.elastic.co/t/retrieve-data-having-date-from-1st-jan-to-current-date-on-a-date-field/325451)

<div class="topic-metadata">

**Author:** [@kajalp](https://discuss.elastic.co/u/kajalp)\
**Replies:** 3\
**Last updated:** [February 14, 2023, 10:24am UTC](https://discuss.elastic.co/t/retrieve-data-having-date-from-1st-jan-to-current-date-on-a-date-field/325451 "2023-02-14T10:24:20Z")

</div>

Hi All, I have data with a date field having dates from last 3 years. What I want? I want to get all the records from Jan1st to current day at any given time over a year. I tried below query: GET index\_name/\_search …

---

## [Logstash issue](https://discuss.elastic.co/t/logstash-issue/325414)

<div class="topic-metadata">

**Author:** [@namdev](https://discuss.elastic.co/u/namdev)\
**Replies:** 1\
**Last updated:** [February 14, 2023, 10:00am UTC](https://discuss.elastic.co/t/logstash-issue/325414 "2023-02-14T10:00:44Z")

</div>

Hi , I am new to elk stack,I want to create a new field which is the difference between two dates field. I want to do it in logstash. The two dates field data is given. I am using filter like this but not getting the …

---

## [Kibana Visualize - Display count even if field not exists](https://discuss.elastic.co/t/kibana-visualize-display-count-even-if-field-not-exists/325246)

<div class="topic-metadata">

**Author:** [@Pedro\_Ventura](https://discuss.elastic.co/u/Pedro_Ventura)\
**Replies:** 3\
**Last updated:** [February 14, 2023, 9:41am UTC](https://discuss.elastic.co/t/kibana-visualize-display-count-even-if-field-not-exists/325246 "2023-02-14T09:41:02Z")

</div>

Hello! First time posting here, I've been looking around but haven't found anything to point me towards the right direction to solve my issue. I'm creating a data table which contains an aggregation by Terms for a date …

---

## [Ruby exception occurred: undefined method \`\*' for nil:NilClass](https://discuss.elastic.co/t/ruby-exception-occurred-undefined-method-for-nil-nilclass/325411)

<div class="topic-metadata">

**Author:** [@mc96](https://discuss.elastic.co/u/mc96)\
**Replies:** 2\
**Last updated:** [February 14, 2023, 9:25am UTC](https://discuss.elastic.co/t/ruby-exception-occurred-undefined-method-for-nil-nilclass/325411 "2023-02-14T09:25:03Z")

</div>

I have a filter that is as follows: event.set('\[json\]\[event\]\[packetloss1\]', event.get('\[packets-received\]') / event.get('\[packets-sent\]') \* 100) event.set('\[json\]\[event\]\[packetlosspercentage\]', 100 - event.get('\[json\]…

---

## [What is the time complexity of query a word in lucene?](https://discuss.elastic.co/t/what-is-the-time-complexity-of-query-a-word-in-lucene/325385)

<div class="topic-metadata">

**Author:** [@dan\_kim](https://discuss.elastic.co/u/dan_kim)\
**Replies:** 7\
**Last updated:** [February 14, 2023, 9:10am UTC](https://discuss.elastic.co/t/what-is-the-time-complexity-of-query-a-word-in-lucene/325385 "2023-02-14T09:10:22Z")

</div>

Hello! please let me know what is the time complexity of query in lucene index . for example, jus simple query to a index like "localhost:9200/index1/\_search?q={searchWord}" I know it is inverted index , but i think …

---

## [How to index a book](https://discuss.elastic.co/t/how-to-index-a-book/325448)

<div class="topic-metadata">

**Author:** [@Piyush\_Purohit](https://discuss.elastic.co/u/Piyush_Purohit)\
**Replies:** 1\
**Last updated:** [February 14, 2023, 8:54am UTC](https://discuss.elastic.co/t/how-to-index-a-book/325448 "2023-02-14T08:54:56Z")

</div>

I want to index a book, in that I want to store book\_name,page\_number and page\_content following is sample - { "book\_name": "first", "pages" : \[ { "page\_number" : 1, "page\_content" : "test data for check." }, { …

---

## [Elasticsearch instance hangs for a while](https://discuss.elastic.co/t/elasticsearch-instance-hangs-for-a-while/325442)

<div class="topic-metadata">

**Author:** [@taghizadeh](https://discuss.elastic.co/u/taghizadeh)\
**Replies:** 0\
**Last updated:** [February 14, 2023, 6:58am UTC](https://discuss.elastic.co/t/elasticsearch-instance-hangs-for-a-while/325442 "2023-02-14T06:58:13Z")

</div>

I have an instance of elasticsearch (v8.6.1) with single node configuration. The hardware spec is: RAM: 32GB Storage: 1TB NVME-M2 CPU: 20 core Currently less than 30% of storage is used and swap is off. The problem…

---

## [Improve filtering with control fields](https://discuss.elastic.co/t/improve-filtering-with-control-fields/325397)

<div class="topic-metadata">

**Author:** [@moep](https://discuss.elastic.co/u/moep)\
**Replies:** 0\
**Last updated:** [February 13, 2023, 2:40pm UTC](https://discuss.elastic.co/t/improve-filtering-with-control-fields/325397 "2023-02-13T14:40:27Z")

</div>

Hello Community, I'm working of a kind of project to visulaze the mail flow. (see also here: Issue in Controls - #19 by moep ). The main problem is, that my content is not in the same line for example a mail flow looks …

---

## [Installation Guide](https://discuss.elastic.co/t/installation-guide/325434)

<div class="topic-metadata">

**Author:** [@ELK\_USR1](https://discuss.elastic.co/u/ELK_USR1)\
**Replies:** 3\
**Last updated:** [February 14, 2023, 6:47am UTC](https://discuss.elastic.co/t/installation-guide/325434 "2023-02-14T06:47:48Z")

</div>

Hi, Can Somebody gives me the steps to install the ELK stack on Linux node through package installation.

---

## [Request contains unrecognized parameters for Search API](https://discuss.elastic.co/t/request-contains-unrecognized-parameters-for-search-api/325139)

<div class="topic-metadata">

**Author:** [@Abhilash\_Kumar](https://discuss.elastic.co/u/Abhilash_Kumar)\
**Replies:** 8\
**Last updated:** [February 14, 2023, 6:08am UTC](https://discuss.elastic.co/t/request-contains-unrecognized-parameters-for-search-api/325139 "2023-02-14T06:08:17Z")

</div>

Hi folks, In our project, when we are trying to query ES Search API we are getting the below error { "error": { "root\_cause": \[ { "type": "illegal\_argument\_exception", …

---

## [Resetting versions](https://discuss.elastic.co/t/resetting-versions/324994)

<div class="topic-metadata">

**Author:** [@Limess](https://discuss.elastic.co/u/Limess)\
**Replies:** 1\
**Last updated:** [February 14, 2023, 5:25am UTC](https://discuss.elastic.co/t/resetting-versions/324994 "2023-02-14T05:25:34Z")

</div>

Hello, I've seen a few posts on this in the past but was wondering if there's any newer solution: We have had issues in production where we indexed documents with an external, then had to restore older versions of the …

---

## [Unable to update the password of elastic user](https://discuss.elastic.co/t/unable-to-update-the-password-of-elastic-user/325422)

<div class="topic-metadata">

**Author:** [@quynhdn](https://discuss.elastic.co/u/quynhdn)\
**Replies:** 1\
**Last updated:** [February 14, 2023, 3:19am UTC](https://discuss.elastic.co/t/unable-to-update-the-password-of-elastic-user/325422 "2023-02-14T03:19:29Z")

</div>

I want to rotate the password of elastic user. I used this utility: bin/elasticsearch-users passwd elastic -p XXXXX It didn’t give any error, but when I tried to use the new password, it didn’t work. The old password co…

---

## [Spring boot visualize actuator health](https://discuss.elastic.co/t/spring-boot-visualize-actuator-health/325389)

<div class="topic-metadata">

**Author:** [@chrispos](https://discuss.elastic.co/u/chrispos)\
**Replies:** 1\
**Last updated:** [February 14, 2023, 12:34am UTC](https://discuss.elastic.co/t/spring-boot-visualize-actuator-health/325389 "2023-02-14T00:34:33Z")

</div>

Hello, I have a question. Our Java programmer has created a health API output for his Java program (output in json). Now I can get the API information by using an http pooler. I was wondering if there is a good way to v…

---

## [Add Matches inside a loop](https://discuss.elastic.co/t/add-matches-inside-a-loop/325427)

<div class="topic-metadata">

**Author:** [@chachew](https://discuss.elastic.co/u/chachew)\
**Replies:** 0\
**Last updated:** [February 13, 2023, 10:51pm UTC](https://discuss.elastic.co/t/add-matches-inside-a-loop/325427 "2023-02-13T22:51:22Z")

</div>

How can i add multiple Match clauses inside a loop? Currently when i do this, the only thing that gets added is the first item in the List and thats it. List\<string\> types = new(); b.Should(s =\> { types.ForEach(t =\>…

---

## [With the removal of doc types, must I reindex all the indices that use a custom doc\_type?](https://discuss.elastic.co/t/with-the-removal-of-doc-types-must-i-reindex-all-the-indices-that-use-a-custom-doc-type/325419)

<div class="topic-metadata">

**Author:** [@kexin-zhai](https://discuss.elastic.co/u/kexin-zhai)\
**Replies:** 0\
**Last updated:** [February 13, 2023, 8:36pm UTC](https://discuss.elastic.co/t/with-the-removal-of-doc-types-must-i-reindex-all-the-indices-that-use-a-custom-doc-type/325419 "2023-02-13T20:36:59Z")

</div>

I have a similar question regarding the removal of doc types as @smlbiobot 's post here With the removal of doc types, must I reindex all the indices that use a named type? . Do I have to reindex all the indices before …

---

## [Unified highlighter with function\_score](https://discuss.elastic.co/t/unified-highlighter-with-function-score/325281)

<div class="topic-metadata">

**Author:** [@Wonder\_Garance](https://discuss.elastic.co/u/Wonder_Garance)\
**Replies:** 1\
**Last updated:** [February 13, 2023, 8:18pm UTC](https://discuss.elastic.co/t/unified-highlighter-with-function-score/325281 "2023-02-13T20:18:40Z")

</div>

Hello, I have a query to search for the acronym: pin and "Personal Identification Number", with "auto\_generate\_synonyms\_phrase\_query": true I don't want results with 3 words Personal, Identification, Number highlighted …

---

## [New Elastic Network Security Analyst learning path](https://discuss.elastic.co/t/new-elastic-network-security-analyst-learning-path/325417)

<div class="topic-metadata">

**Author:** [@brian.reitz](https://discuss.elastic.co/u/brian.reitz)\
**Replies:** 0\
**Last updated:** [February 13, 2023, 7:44pm UTC](https://discuss.elastic.co/t/new-elastic-network-security-analyst-learning-path/325417 "2023-02-13T19:44:49Z")

</div>

Learn how to improve your security operations center with our new Elastic Network Security Analyst learning path. The path includes a series of on-demand training modules that explore how to analyze network data and det…

---

## [Elasticsearch Memory Optimization?](https://discuss.elastic.co/t/elasticsearch-memory-optimization/325335)

<div class="topic-metadata">

**Author:** [@Sheharyar\_Khalid](https://discuss.elastic.co/u/Sheharyar_Khalid)\
**Replies:** 5\
**Last updated:** [February 13, 2023, 4:23pm UTC](https://discuss.elastic.co/t/elasticsearch-memory-optimization/325335 "2023-02-13T16:23:13Z")

</div>

Hello, I have 64GB of RAM on my machine. I am trying to optimize the elasticsearch's performance by utilizing maximum possible hardware. I noticed that the elasticsearch is not utilizing as much RAM as allocated to it …

[Previous page](https://discuss.elastic.co/tag/none.md?no_tags=true&page=435)

[Next page](https://discuss.elastic.co/tag/none.md?no_tags=true&page=437)
