# \#none

**URL:** https://discuss.elastic.co/tag/none.md?no_tags=true&page=441

[Latest](https://discuss.elastic.co/latest.md) · [Categories](https://discuss.elastic.co/categories.md) · [Tags](https://discuss.elastic.co/tags.md)

**Page:** 442

---

## [GET Document from Index with Kibana API](https://discuss.elastic.co/t/get-document-from-index-with-kibana-api/324887)

<div class="topic-metadata">

**Author:** [@Jonathan\_Emami](https://discuss.elastic.co/u/Jonathan_Emami)\
**Replies:** 3\
**Last updated:** [February 7, 2023, 2:58pm UTC](https://discuss.elastic.co/t/get-document-from-index-with-kibana-api/324887 "2023-02-07T14:58:21Z")

</div>

Hi, I'm writing here cause I've read through all of the Kibana REST API, but I still have not found an answer to my question REST API | Kibana Guide \[8.6\] | Elastic I basically want to access a document in the index, i…

---

## [Infrastructure tab in the APM UI/App](https://discuss.elastic.co/t/infrastructure-tab-in-the-apm-ui-app/323577)

<div class="topic-metadata">

**Author:** [@marsdea](https://discuss.elastic.co/u/marsdea)\
**Replies:** 5\
**Last updated:** [February 7, 2023, 2:54pm UTC](https://discuss.elastic.co/t/infrastructure-tab-in-the-apm-ui-app/323577 "2023-02-07T14:54:32Z")

</div>

Hi there, Anyone know what the 'key' is to correlate infrastructure metrics with APM agent metrics so they appear in the infrastructure tab in the APM UI? I am not seeing any infra metrics for an APM service but I know…

---

## [How much time by the query is spent in Disk I/O?](https://discuss.elastic.co/t/how-much-time-by-the-query-is-spent-in-disk-i-o/324915)

<div class="topic-metadata">

**Author:** [@Sheharyar\_Khalid](https://discuss.elastic.co/u/Sheharyar_Khalid)\
**Replies:** 1\
**Last updated:** [February 7, 2023, 2:17pm UTC](https://discuss.elastic.co/t/how-much-time-by-the-query-is-spent-in-disk-i-o/324915 "2023-02-07T14:17:50Z")

</div>

Hello, I am trying to optimize my hardware for elasticsearch deployment. I am getting inconsistent results on the time by changing the JVM settings. I wanted to know if there is any other measure apart from the "took" i…

---

## [Can't connect to Kibana API with CURL. I keep receiving {"statusCode":404,"error":"Not Found","message":"Not Found"}](https://discuss.elastic.co/t/cant-connect-to-kibana-api-with-curl-i-keep-receiving-statuscode-404-error-not-found-message-not-found/324804)

<div class="topic-metadata">

**Author:** [@Piotrek](https://discuss.elastic.co/u/Piotrek)\
**Replies:** 4\
**Last updated:** [February 7, 2023, 1:17pm UTC](https://discuss.elastic.co/t/cant-connect-to-kibana-api-with-curl-i-keep-receiving-statuscode-404-error-not-found-message-not-found/324804 "2023-02-07T13:17:06Z")

</div>

I'm trying to connect to Kibana API via CURL: curl -X "GET" "http://\<my-elastic-host\>:5601/status" --user \<my-username\> --noproxy '\*' -H 'kbn-xsrf: true' But all I receive is: {"statusCode":404,"error":"Not Found",…

---

## [About the integration between elasticsearch and logstash](https://discuss.elastic.co/t/about-the-integration-between-elasticsearch-and-logstash/324845)

<div class="topic-metadata">

**Author:** [@choilee](https://discuss.elastic.co/u/choilee)\
**Replies:** 5\
**Last updated:** [February 7, 2023, 1:07pm UTC](https://discuss.elastic.co/t/about-the-integration-between-elasticsearch-and-logstash/324845 "2023-02-07T13:07:23Z")

</div>

Hi, I am creating log analizing system using logstash and elasticsearch. But I couldn't send any data to elastic from logstash. (But Delete prune fillter, then could send data) I found under this error message, but i c…

---

## [Logstash CSV output plugin not flushing to disk](https://discuss.elastic.co/t/logstash-csv-output-plugin-not-flushing-to-disk/324413)

<div class="topic-metadata">

**Author:** [@lduvnjak](https://discuss.elastic.co/u/lduvnjak)\
**Replies:** 4\
**Last updated:** [February 7, 2023, 11:31am UTC](https://discuss.elastic.co/t/logstash-csv-output-plugin-not-flushing-to-disk/324413 "2023-02-07T11:31:37Z")

</div>

Hey Everyone, I'm having some trouble with my Logstash config for exporting Elasticsearch data to CSV after upgrading my ELK stack from 7 to 8.6. When running my exporter.conf file it just never flushes to disk. It fil…

---

## [Java time migration guide (upgrading to ES 8.x)](https://discuss.elastic.co/t/java-time-migration-guide-upgrading-to-es-8-x/323942)

<div class="topic-metadata">

**Author:** [@YvorL](https://discuss.elastic.co/u/YvorL)\
**Replies:** 5\
**Last updated:** [February 7, 2023, 10:35am UTC](https://discuss.elastic.co/t/java-time-migration-guide-upgrading-to-es-8-x/323942 "2023-02-07T10:35:09Z")

</div>

Hi, During reading release notes and breaking changes, I stumbled upon this guide: Java time migration guide | Elasticsearch Guide \[8.0\] | Elastic At the bottom, it says that the format "yyyy/MM/dd HH:mm:ss||yyyy/MM/…

---

## [Will attribute script make elasticsearch write slower?](https://discuss.elastic.co/t/will-attribute-script-make-elasticsearch-write-slower/324212)

<div class="topic-metadata">

**Author:** [@robocon20x](https://discuss.elastic.co/u/robocon20x)\
**Replies:** 4\
**Last updated:** [February 7, 2023, 9:34am UTC](https://discuss.elastic.co/t/will-attribute-script-make-elasticsearch-write-slower/324212 "2023-02-07T09:34:20Z")

</div>

Hi everyone, i am going to create many script columns for my index, will this make elasticsearch write to this index slower than before, because it will create many columns per document of index?

---

## [Java RestClient multi host configuration to access ES on Kubernetes](https://discuss.elastic.co/t/java-restclient-multi-host-configuration-to-access-es-on-kubernetes/324870)

<div class="topic-metadata">

**Author:** [@franck.valentin](https://discuss.elastic.co/u/franck.valentin)\
**Replies:** 0\
**Last updated:** [February 7, 2023, 8:39am UTC](https://discuss.elastic.co/t/java-restclient-multi-host-configuration-to-access-es-on-kubernetes/324870 "2023-02-07T08:39:21Z")

</div>

Hi, I try to figure out how to configure a Java RESTClient to access ES 7.17 deployed on Kubernetes, more precisely how to \[set several hosts\](Initialization | Elasticsearch Java API Client \[7.17\] | Elastic and take adv…

---

## [Unable to import kibana saved objectki](https://discuss.elastic.co/t/unable-to-import-kibana-saved-objectki/324815)

<div class="topic-metadata">

**Author:** [@PRASHANT\_MEHTA](https://discuss.elastic.co/u/PRASHANT_MEHTA)\
**Replies:** 2\
**Last updated:** [February 7, 2023, 7:44am UTC](https://discuss.elastic.co/t/unable-to-import-kibana-saved-objectki/324815 "2023-02-07T07:44:09Z")

</div>

Hello All, I'm unable to import the saved object in kibana.Earlier the saved object size was around 700 kb.Now I have many visuals and dashboards and now the size is around 1.6 mb of saved object.When importing saved o…

---

## [Fleet hosts settings](https://discuss.elastic.co/t/fleet-hosts-settings/324821)

<div class="topic-metadata">

**Author:** [@adrien\_moreau](https://discuss.elastic.co/u/adrien_moreau)\
**Replies:** 1\
**Last updated:** [February 7, 2023, 7:20am UTC](https://discuss.elastic.co/t/fleet-hosts-settings/324821 "2023-02-07T07:20:18Z")

</div>

Hello, I am running elk in a self managed environment and my question concerns the following fleet setting: xpack.fleet.agents.elasticsearch.hosts This parameter is described in documentation as: "Hostnames used by E…

---

## [Saved Object: Internal Server Error](https://discuss.elastic.co/t/saved-object-internal-server-error/324856)

<div class="topic-metadata">

**Author:** [@mike21](https://discuss.elastic.co/u/mike21)\
**Replies:** 2\
**Last updated:** [February 7, 2023, 7:00am UTC](https://discuss.elastic.co/t/saved-object-internal-server-error/324856 "2023-02-07T07:00:39Z")

</div>

Firstly, there are around 7 saved objects, I was trying to import a new object pattern, with the existing one object, but removed a few criteria, Then the import has failed, and all the saved objects were missing. Th…

---

## [Error=\>logstash Pipeline worker error :"(EACCES) Permission denied](https://discuss.elastic.co/t/error-logstash-pipeline-worker-error-eacces-permission-denied/324788)

<div class="topic-metadata">

**Author:** [@vaibhav.ubale](https://discuss.elastic.co/u/vaibhav.ubale)\
**Replies:** 2\
**Last updated:** [February 7, 2023, 6:26am UTC](https://discuss.elastic.co/t/error-logstash-pipeline-worker-error-eacces-permission-denied/324788 "2023-02-07T06:26:23Z")

</div>

Hi Team/Everyone, I am facing a pipeline error and my pipeline is terminating randomly with error=\>"(EACCES) Permission denied - /var/myrepo/devops/mytask\_watcher.csv" My logstash output conf is as below output { csv…

---

## [Kibana shows Failed to poll for work: Error: work has timed out](https://discuss.elastic.co/t/kibana-shows-failed-to-poll-for-work-error-work-has-timed-out/324447)

<div class="topic-metadata">

**Author:** [@yuswanul](https://discuss.elastic.co/u/yuswanul)\
**Replies:** 1\
**Last updated:** [February 7, 2023, 6:15am UTC](https://discuss.elastic.co/t/kibana-shows-failed-to-poll-for-work-error-work-has-timed-out/324447 "2023-02-07T06:15:48Z")

</div>

Hi there, i've got this log from kibana.log {"type":"log","@timestamp":"2023-02-01T14:48:06+07:00","tags":\["error","plugins","taskManager"\],"pid":57144,"message":"Failed to poll for work: Error: work has timed out"} a…

---

## [バイナリデータを全文検索対象にしたい](https://discuss.elastic.co/t/topic/324853)

<div class="topic-metadata">

**Author:** [@wackrisan](https://discuss.elastic.co/u/wackrisan)\
**Replies:** 0\
**Last updated:** [February 7, 2023, 5:32am UTC](https://discuss.elastic.co/t/topic/324853 "2023-02-07T05:32:25Z")

</div>

WordやExcelファイルをbinary型で保存しているDBのレコードを Elasticsearchに取り込んでWordやExcelファイルの内容を全文検索の対象にすることは実現可能でしょうか？ 具体的な手順などがあれば併せてご教授ください。 宜しくお願い致します。

---

## [Logstash microsoft-sentinel-logstash-output-plugin](https://discuss.elastic.co/t/logstash-microsoft-sentinel-logstash-output-plugin/324787)

<div class="topic-metadata">

**Author:** [@shadu88](https://discuss.elastic.co/u/shadu88)\
**Replies:** 2\
**Last updated:** [February 7, 2023, 5:27am UTC](https://discuss.elastic.co/t/logstash-microsoft-sentinel-logstash-output-plugin/324787 "2023-02-07T05:27:30Z")

</div>

Hello ELKs, Hope you doing well!! has anyone tried IF ELSE condition in "microsoft-sentinel-logstash-output-plugin" output logstash plugin? I'm trying to forward the logs based on log source type to respective DCR en…

---

## [Can use variables for output influxdb db and measurement field?](https://discuss.elastic.co/t/can-use-variables-for-output-influxdb-db-and-measurement-field/324508)

<div class="topic-metadata">

**Author:** [@AlanChan](https://discuss.elastic.co/u/AlanChan)\
**Replies:** 10\
**Last updated:** [February 7, 2023, 5:27am UTC](https://discuss.elastic.co/t/can-use-variables-for-output-influxdb-db-and-measurement-field/324508 "2023-02-07T05:27:16Z")

</div>

Hi I'm wondering if a configuration like this can work or not. filter { mutate { if \[topic\] == "xxxx" { add\_field =\> { "db" =\> "test2", "measurement" =\> "access\_logs" } } else { add\_field =\> { "db…

---

## [How to include a custom rule variable in Elastic Email alert](https://discuss.elastic.co/t/how-to-include-a-custom-rule-variable-in-elastic-email-alert/324849)

<div class="topic-metadata">

**Author:** [@yoshiouchi](https://discuss.elastic.co/u/yoshiouchi)\
**Replies:** 0\
**Last updated:** [February 7, 2023, 3:55am UTC](https://discuss.elastic.co/t/how-to-include-a-custom-rule-variable-in-elastic-email-alert/324849 "2023-02-07T03:55:47Z")

</div>

I would like to know a way to create a custom rule variable in Elastic Email alert i.e. we have some pre-built variables like {{alertName}} or {{context.group}} but I want to output the name of kubernetes.pod.name in Ela…

---

## [User elasticsearch lost after reboot](https://discuss.elastic.co/t/user-elasticsearch-lost-after-reboot/324839)

<div class="topic-metadata">

**Author:** [@bhirani](https://discuss.elastic.co/u/bhirani)\
**Replies:** 3\
**Last updated:** [February 7, 2023, 3:44am UTC](https://discuss.elastic.co/t/user-elasticsearch-lost-after-reboot/324839 "2023-02-07T03:44:56Z")

</div>

I have installed Elasticsearch on TrueNAS using dpkg. I have setup fs2es-indexer to index my files. I have indexed the files and tested that all works. After reboot, the user elasticsearch is lost. id elasticsearch i…

---

## [Clarification - Upload of CSV file without Date / timestamp file in Kibana](https://discuss.elastic.co/t/clarification-upload-of-csv-file-without-date-timestamp-file-in-kibana/324818)

<div class="topic-metadata">

**Author:** [@Raj4](https://discuss.elastic.co/u/Raj4)\
**Replies:** 2\
**Last updated:** [February 7, 2023, 3:20am UTC](https://discuss.elastic.co/t/clarification-upload-of-csv-file-without-date-timestamp-file-in-kibana/324818 "2023-02-07T03:20:18Z")

</div>

Hi All, Please advise me on the below, I am using Kibana 7.10 version On daily basis I will receive an CSV file (without date/timestamp field), I need to visualize it by comparing the values. Please let me know what …

---

## [How to perform aggregation on nested of nested of nested field?](https://discuss.elastic.co/t/how-to-perform-aggregation-on-nested-of-nested-of-nested-field/324843)

<div class="topic-metadata">

**Author:** [@learningelastic](https://discuss.elastic.co/u/learningelastic)\
**Replies:** 1\
**Last updated:** [February 7, 2023, 2:05am UTC](https://discuss.elastic.co/t/how-to-perform-aggregation-on-nested-of-nested-of-nested-field/324843 "2023-02-07T02:05:40Z")

</div>

I saw basic examples of how to do a nested aggregation on 1 tiered level of a nested field. But I'm not sure how to perform aggregation when there is more than 1 level of nesting. I tried the following which sets up 2 …

---

## [Migrate from Visualization "Controls" in 7.17 to "Controls" in 8.5](https://discuss.elastic.co/t/migrate-from-visualization-controls-in-7-17-to-controls-in-8-5/324836)

<div class="topic-metadata">

**Author:** [@zvazquez](https://discuss.elastic.co/u/zvazquez)\
**Replies:** 1\
**Last updated:** [February 6, 2023, 11:18pm UTC](https://discuss.elastic.co/t/migrate-from-visualization-controls-in-7-17-to-controls-in-8-5/324836 "2023-02-06T23:18:34Z")

</div>

Hi, We are in the process to upgrade from version 7.17 to version 8.5 and we have realized in our development landscape that the old "controls" visualization is deprecated and the style of the controller certainly looks…

---

## [Kibana Crash while loading index list](https://discuss.elastic.co/t/kibana-crash-while-loading-index-list/324795)

<div class="topic-metadata">

**Author:** [@dslavescu](https://discuss.elastic.co/u/dslavescu)\
**Replies:** 1\
**Last updated:** [February 6, 2023, 11:02pm UTC](https://discuss.elastic.co/t/kibana-crash-while-loading-index-list/324795 "2023-02-06T23:02:38Z")

</div>

Hello, I have an ELK Cluster of 3M+12D nodes , with 64GB and 8 cores for the data nodes and a total of 53 TB of data, 3243 indices, 7602 shards. On top, i have a Kibana instance of 8GB RAM + 4 CPU. Both Kibana and ELK a…

---

## [How does elastic agent have it's debug logging turn on without anyone turning it on?](https://discuss.elastic.co/t/how-does-elastic-agent-have-its-debug-logging-turn-on-without-anyone-turning-it-on/324831)

<div class="topic-metadata">

**Author:** [@jerrac](https://discuss.elastic.co/u/jerrac)\
**Replies:** 0\
**Last updated:** [February 6, 2023, 8:24pm UTC](https://discuss.elastic.co/t/how-does-elastic-agent-have-its-debug-logging-turn-on-without-anyone-turning-it-on/324831 "2023-02-06T20:24:25Z")

</div>

Ok, so, I'm not even sure how to search on this one. Right around midnight 1/28-1/29, my fleet server agent had it's debug logging turned on. That server went from 50 docs/min to 60,000 docs/min. Didn't figure it out u…

---

## [Work with xml in logstash](https://discuss.elastic.co/t/work-with-xml-in-logstash/324784)

<div class="topic-metadata">

**Author:** [@sahere37](https://discuss.elastic.co/u/sahere37)\
**Replies:** 1\
**Last updated:** [February 6, 2023, 7:05pm UTC](https://discuss.elastic.co/t/work-with-xml-in-logstash/324784 "2023-02-06T19:05:39Z")

</div>

Hi all, I have a xml data as below which is harvesting by filebeat and sending to logstash. \<event name="first check"\> \<Data name="id"\> \<Value\>5\</Value\> \</Data\> \<Data name="object\_id"\> \<Value\>123\</Value\> \</Data\> …

---

## [Grok fiels are removed by aggregate section](https://discuss.elastic.co/t/grok-fiels-are-removed-by-aggregate-section/324798)

<div class="topic-metadata">

**Author:** [@Miriam](https://discuss.elastic.co/u/Miriam)\
**Replies:** 1\
**Last updated:** [February 6, 2023, 5:54pm UTC](https://discuss.elastic.co/t/grok-fiels-are-removed-by-aggregate-section/324798 "2023-02-06T17:54:09Z")

</div>

I have follwoing file structure: id, iduser,datetimInit, dateTimeends 0001 0001 2023-02-03 04:45:16.78 2023-02-03 04:46:16.78 0002 0001 2023-02-03 08:45:16.78 2023-02-03 08:46:16.78 0003 0002 2023-02-04 04:45:16.78 2023…

---

## [Query\_shard\_exception](https://discuss.elastic.co/t/query-shard-exception/324756)

<div class="topic-metadata">

**Author:** [@Tussingh](https://discuss.elastic.co/u/Tussingh)\
**Replies:** 7\
**Last updated:** [February 6, 2023, 5:35pm UTC](https://discuss.elastic.co/t/query-shard-exception/324756 "2023-02-06T17:35:28Z")

</div>

I am getting below error when I am trying to query :slight\_smile : { "error": { "root\_cause": \[ { "type": "query\_shard\_exception", "reason": "failed to create query: \[nested\] failed to find nested object under path…

---

## [Logstash slow processing of events](https://discuss.elastic.co/t/logstash-slow-processing-of-events/324392)

<div class="topic-metadata">

**Author:** [@PRASHANT\_MEHTA](https://discuss.elastic.co/u/PRASHANT_MEHTA)\
**Replies:** 11\
**Last updated:** [February 6, 2023, 5:02pm UTC](https://discuss.elastic.co/t/logstash-slow-processing-of-events/324392 "2023-02-06T17:02:58Z")

</div>

Hello, I'm trying to process events from logstash and I'm facing issue of slow processing of events.There are around 100k records.In logstash.yml I've enabled log.level debug. So far I can observe in 2 hours around 110…

---

## [Filebeat interface name](https://discuss.elastic.co/t/filebeat-interface-name/324812)

<div class="topic-metadata">

**Author:** [@teplyukdimka](https://discuss.elastic.co/u/teplyukdimka)\
**Replies:** 0\
**Last updated:** [February 6, 2023, 3:58pm UTC](https://discuss.elastic.co/t/filebeat-interface-name/324812 "2023-02-06T15:58:17Z")

</div>

Доброго времени суток. Подскажите, пожалуйста, я собираю netflow с помощью filebeat. Есть поля ''' "egress\_interface" : 199, "ingress\_interface" : 277, ''' Через SNMP я узнал, какие сетевые интерфейсы соответствую…

---

## [Kibana sorting in asc/desc order in Discover not working](https://discuss.elastic.co/t/kibana-sorting-in-asc-desc-order-in-discover-not-working/324582)

<div class="topic-metadata">

**Author:** [@zaeemmasood](https://discuss.elastic.co/u/zaeemmasood)\
**Replies:** 2\
**Last updated:** [February 6, 2023, 3:26pm UTC](https://discuss.elastic.co/t/kibana-sorting-in-asc-desc-order-in-discover-not-working/324582 "2023-02-06T15:26:22Z")

</div>

Hello, In Discover mode I am not able to sort the duration field in ascending order. It continues to show in descending order. Please guide. We are using 7.6.2 stack Thanks

[Previous page](https://discuss.elastic.co/tag/none.md?no_tags=true&page=440)

[Next page](https://discuss.elastic.co/tag/none.md?no_tags=true&page=442)
