# \#none

**URL:** https://discuss.elastic.co/tag/none.md?no_tags=true&page=443

[Latest](https://discuss.elastic.co/latest.md) · [Categories](https://discuss.elastic.co/categories.md) · [Tags](https://discuss.elastic.co/tags.md)

**Page:** 444

---

## [Time shift Kibana vs. Elasticsearch](https://discuss.elastic.co/t/time-shift-kibana-vs-elasticsearch/324653)

<div class="topic-metadata">

**Author:** [@tmslara.a](https://discuss.elastic.co/u/tmslara.a)\
**Replies:** 2\
**Last updated:** [February 3, 2023, 4:22pm UTC](https://discuss.elastic.co/t/time-shift-kibana-vs-elasticsearch/324653 "2023-02-03T16:22:47Z")

</div>

Hi, I have an index in Elasticsearch. When I check - using the search API - the oldest timestamp of my data is 2023-01-13 00:00:00 (I previously applied a filter). However, when generating a Data View in Kibana the olde…

---

## [Elastic Version Moves very fast](https://discuss.elastic.co/t/elastic-version-moves-very-fast/323338)

<div class="topic-metadata">

**Author:** [@elasticforme](https://discuss.elastic.co/u/elasticforme)\
**Replies:** 12\
**Last updated:** [February 3, 2023, 4:22pm UTC](https://discuss.elastic.co/t/elastic-version-moves-very-fast/323338 "2023-02-03T16:22:19Z")

</div>

What is the reason Elastic introduce and release different version at fast pace? it is very hard to keep up with it. And if you fall too much behind version then upgrade process gets harder and harder. for example I w…

---

## [It is possible to change the bulk\_max\_size and workers on a fleet managed agent?](https://discuss.elastic.co/t/it-is-possible-to-change-the-bulk-max-size-and-workers-on-a-fleet-managed-agent/324380)

<div class="topic-metadata">

**Author:** [@leandrojmp](https://discuss.elastic.co/u/leandrojmp)\
**Replies:** 4\
**Last updated:** [February 3, 2023, 3:50pm UTC](https://discuss.elastic.co/t/it-is-possible-to-change-the-bulk-max-size-and-workers-on-a-fleet-managed-agent/324380 "2023-02-03T15:50:33Z")

</div>

Hello, I'm using Elastic Agent with the AWS Cloudwatch integration to consume some logs, the volume of logs are pretty high and I'm trying to improve the performance of the Elastic Agent. Filebeat per default uses just…

---

## [Logstash jdbc input mantain sql row order](https://discuss.elastic.co/t/logstash-jdbc-input-mantain-sql-row-order/324470)

<div class="topic-metadata">

**Author:** [@Ricardo\_Canuto](https://discuss.elastic.co/u/Ricardo_Canuto)\
**Replies:** 8\
**Last updated:** [February 3, 2023, 2:51pm UTC](https://discuss.elastic.co/t/logstash-jdbc-input-mantain-sql-row-order/324470 "2023-02-03T14:51:27Z")

</div>

Hi, I'm new to logstash and I'm trying to check if an sql job (and its steps) runs successfully. The query gets the step 0 (job output) and all the steps that have errors or warnings. I want to gather all the steps…

---

## [Compare data from two different Elasticsearch documents](https://discuss.elastic.co/t/compare-data-from-two-different-elasticsearch-documents/324660)

<div class="topic-metadata">

**Author:** [@slaterar](https://discuss.elastic.co/u/slaterar)\
**Replies:** 0\
**Last updated:** [February 3, 2023, 2:16pm UTC](https://discuss.elastic.co/t/compare-data-from-two-different-elasticsearch-documents/324660 "2023-02-03T14:16:36Z")

</div>

I have two namespaces that I want to compare data from. The first is ab\*:cd.blah1 and second is ab\*:cd.blah2 and each contain a reference ID for a transaction in the same field name. I want to return values in ab\*:cd.bl…

---

## [How to create mapping for special characters and autocomplete search](https://discuss.elastic.co/t/how-to-create-mapping-for-special-characters-and-autocomplete-search/324115)

<div class="topic-metadata">

**Author:** [@Ismet](https://discuss.elastic.co/u/Ismet)\
**Replies:** 5\
**Last updated:** [February 3, 2023, 2:14pm UTC](https://discuss.elastic.co/t/how-to-create-mapping-for-special-characters-and-autocomplete-search/324115 "2023-02-03T14:14:06Z")

</div>

Hi, In my project, I need to search data with special characters like č,ć,ž,đ, ?, !. What is the best practice for searching special characters in version 8.5? Also, how to create a mapping for autocomplete search? Ho…

---

## [Logstash - Dateformat yyyyMMdd HHmmss](https://discuss.elastic.co/t/logstash-dateformat-yyyymmdd-hhmmss/324311)

<div class="topic-metadata">

**Author:** [@A.Klos](https://discuss.elastic.co/u/A.Klos)\
**Replies:** 3\
**Last updated:** [February 3, 2023, 2:08pm UTC](https://discuss.elastic.co/t/logstash-dateformat-yyyymmdd-hhmmss/324311 "2023-02-03T14:08:04Z")

</div>

Hi, I have still problem to get right timestamp in elastic. One Row of log looks like: 20210611 111146 SOME Date Field ... I tried: grok { match =\> \[ "message" , "%{DATA:timestamp}" \] } date { …

---

## [Index CSV Timestamp](https://discuss.elastic.co/t/index-csv-timestamp/324579)

<div class="topic-metadata">

**Author:** [@gabrile\_jaime\_gomez](https://discuss.elastic.co/u/gabrile_jaime_gomez)\
**Replies:** 6\
**Last updated:** [February 3, 2023, 1:06pm UTC](https://discuss.elastic.co/t/index-csv-timestamp/324579 "2023-02-03T13:06:11Z")

</div>

hello I want to index some csv files. I want to be indexed with the modification date, not with the date entered in Elastic. Example My file has a modification date of 01/23/2022, that is the date that I would like to…

---

## [Create data view api](https://discuss.elastic.co/t/create-data-view-api/324641)

<div class="topic-metadata">

**Author:** [@Neelam\_Zanvar](https://discuss.elastic.co/u/Neelam_Zanvar)\
**Replies:** 0\
**Last updated:** [February 3, 2023, 10:52am UTC](https://discuss.elastic.co/t/create-data-view-api/324641 "2023-02-03T10:52:23Z")

</div>

Hi I have filebeat installed on one machine. and elasticsearch and kibana on one machine. and logstash on another machine. I am using an ansible playbook which picks logs using filebeat and ships it to logstash. Eevryth…

---

## [Can't add Integrations to agents](https://discuss.elastic.co/t/cant-add-integrations-to-agents/324512)

<div class="topic-metadata">

**Author:** [@NathanLau](https://discuss.elastic.co/u/NathanLau)\
**Replies:** 8\
**Last updated:** [February 3, 2023, 10:04am UTC](https://discuss.elastic.co/t/cant-add-integrations-to-agents/324512 "2023-02-03T10:04:02Z")

</div>

Hi , I have a problem with can't add integration with agents. Now sure is it kibana cannot get the integration or other not updated. let see the img as below. Please help Thanks.

---

## [Create elastic user with more roles](https://discuss.elastic.co/t/create-elastic-user-with-more-roles/324632)

<div class="topic-metadata">

**Author:** [@smiley\_tamy](https://discuss.elastic.co/u/smiley_tamy)\
**Replies:** 0\
**Last updated:** [February 3, 2023, 9:31am UTC](https://discuss.elastic.co/t/create-elastic-user-with-more-roles/324632 "2023-02-03T09:31:12Z")

</div>

As part of bootstrap, Can we create the builtin user "elastic" with providing more roles other than superuser role When elastic user gets created it is assigned with super user role. I need to assign few more privilege…

---

## [Logstash cann not read encrypted key](https://discuss.elastic.co/t/logstash-cann-not-read-encrypted-key/324629)

<div class="topic-metadata">

**Author:** [@AfeefGhannam](https://discuss.elastic.co/u/AfeefGhannam)\
**Replies:** 0\
**Last updated:** [February 3, 2023, 9:23am UTC](https://discuss.elastic.co/t/logstash-cann-not-read-encrypted-key/324629 "2023-02-03T09:23:26Z")

</div>

Hi, when we create an encrypted and compatible Logstash key, Logstash can not read the key and give the following error in log: message=\>"File does not contain valid private key: /etc/logstash/certs/logstash-pkcs8.key"…

---

## [S3 optimization in elk](https://discuss.elastic.co/t/s3-optimization-in-elk/324298)

<div class="topic-metadata">

**Author:** [@Shalinicts](https://discuss.elastic.co/u/Shalinicts)\
**Replies:** 22\
**Last updated:** [February 3, 2023, 9:03am UTC](https://discuss.elastic.co/t/s3-optimization-in-elk/324298 "2023-02-03T09:03:39Z")

</div>

Hi , We have a 8 node cluster in on premise with 3 years data (3 master + 5 data node) one data node out of this being acting as s3 for cold storage. Our s3 is getting space issues and we would like to optimize by mov…

---

## [Elastic Case Insensitive Search](https://discuss.elastic.co/t/elastic-case-insensitive-search/324527)

<div class="topic-metadata">

**Author:** [@Tam2](https://discuss.elastic.co/u/Tam2)\
**Replies:** 12\
**Last updated:** [February 3, 2023, 8:19am UTC](https://discuss.elastic.co/t/elastic-case-insensitive-search/324527 "2023-02-03T08:19:06Z")

</div>

Hi All, I have a schema which uses Keywords to store values an example of a document would be something like this: We aggregate on a number of properties too such as make/model/colour/condition etc { "properties": {…

---

## [Not all primary shards of \[.geoip\_databases\] index are active](https://discuss.elastic.co/t/not-all-primary-shards-of-geoip-databases-index-are-active/324401)

<div class="topic-metadata">

**Author:** [@LiuJintao](https://discuss.elastic.co/u/LiuJintao)\
**Replies:** 4\
**Last updated:** [February 3, 2023, 8:51am UTC](https://discuss.elastic.co/t/not-all-primary-shards-of-geoip-databases-index-are-active/324401 "2023-02-03T08:51:36Z")

</div>

When I start elasticsearch cluster with a single node,it throw an error: \[2023-02-01T15:34:09,249\]\[ERROR\]\[o.e.i.g.GeoIpDownloader \] \[node1\] exception during geoip databases updateorg.elasticsearch.ElasticsearchExceptio…

---

## [Copy a remote index using Reindex API](https://discuss.elastic.co/t/copy-a-remote-index-using-reindex-api/324548)

<div class="topic-metadata">

**Author:** [@tmslara.a](https://discuss.elastic.co/u/tmslara.a)\
**Replies:** 5\
**Last updated:** [February 3, 2023, 7:47am UTC](https://discuss.elastic.co/t/copy-a-remote-index-using-reindex-api/324548 "2023-02-03T07:47:00Z")

</div>

Hi, I have a running Elastic node with an index. I'm constantly inserting documents into the index in a process that I can't stop. The whole process is running in a remote server. I need to make a copy of the index into…

---

## [Elastic search does not work during operation, causing problems in restarting](https://discuss.elastic.co/t/elastic-search-does-not-work-during-operation-causing-problems-in-restarting/324556)

<div class="topic-metadata">

**Author:** [@sramana235](https://discuss.elastic.co/u/sramana235)\
**Replies:** 3\
**Last updated:** [February 3, 2023, 7:22am UTC](https://discuss.elastic.co/t/elastic-search-does-not-work-during-operation-causing-problems-in-restarting/324556 "2023-02-03T07:22:33Z")

</div>

\[2023-02-02T18:22:39,230\]\[INFO \]\[o.e.e.NodeEnvironment \] \[name\] using \[1\] data paths, mounts \[\[/data (/dev/data)\]\], net usable\_space \[55.9gb\], net total\_space \[98.4gb\], types \[ext4\] \[2023-02-02T18:22:39,231\]\[INFO \]\[o.…

---

## [Search returning zero document and zero shards | Index was closed and then opened](https://discuss.elastic.co/t/search-returning-zero-document-and-zero-shards-index-was-closed-and-then-opened/324603)

<div class="topic-metadata">

**Author:** [@esuser27](https://discuss.elastic.co/u/esuser27)\
**Replies:** 0\
**Last updated:** [February 3, 2023, 6:42am UTC](https://discuss.elastic.co/t/search-returning-zero-document-and-zero-shards-index-was-closed-and-then-opened/324603 "2023-02-03T06:42:05Z")

</div>

Hi Folks, I had closed few of my indices for maintenance activity and I opened them after some time. Health wise the index is green and has a shard, but my search query is getting empty results even though there are do…

---

## [Which privilege is necessary for creation of runtime field](https://discuss.elastic.co/t/which-privilege-is-necessary-for-creation-of-runtime-field/324507)

<div class="topic-metadata">

**Author:** [@shinki927](https://discuss.elastic.co/u/shinki927)\
**Replies:** 4\
**Last updated:** [February 3, 2023, 6:17am UTC](https://discuss.elastic.co/t/which-privilege-is-necessary-for-creation-of-runtime-field/324507 "2023-02-03T06:17:46Z")

</div>

Hello, I'd like to know which cluster and index privilege are needed to create runtime field. I didn't find it in the doc. Thanks in advance

---

## [I am also facing the same issue, did someone found the solution or workaround for this](https://discuss.elastic.co/t/i-am-also-facing-the-same-issue-did-someone-found-the-solution-or-workaround-for-this/324342)

<div class="topic-metadata">

**Author:** [@mohit\_bairagi](https://discuss.elastic.co/u/mohit_bairagi)\
**Replies:** 1\
**Last updated:** [February 3, 2023, 3:50am UTC](https://discuss.elastic.co/t/i-am-also-facing-the-same-issue-did-someone-found-the-solution-or-workaround-for-this/324342 "2023-02-03T03:50:27Z")

</div>

Continuing the discussion from S3 Input Plugin Following Errors Execution Expired and Net::OpenTimeout:

---

## [Logstash ruby filter](https://discuss.elastic.co/t/logstash-ruby-filter/324590)

<div class="topic-metadata">

**Author:** [@sheetal3](https://discuss.elastic.co/u/sheetal3)\
**Replies:** 0\
**Last updated:** [February 3, 2023, 2:20am UTC](https://discuss.elastic.co/t/logstash-ruby-filter/324590 "2023-02-03T02:20:15Z")

</div>

Getting Error: \[2023-02-02T19:25:48,535\]\[ERROR\]\[logstash.filters.ruby \]\[main\]\[b7126651d97050c2a450765cb1ad946624dc0b4a1ea72baecc762eb17b892bdd\] Ruby exception occurred: undefined method each' for #\<String:0xa01d55c\> …

---

## [Nested Aggregation to just get some nested type without aggregatioon](https://discuss.elastic.co/t/nested-aggregation-to-just-get-some-nested-type-without-aggregatioon/324588)

<div class="topic-metadata">

**Author:** [@Jason\_Yu1](https://discuss.elastic.co/u/Jason_Yu1)\
**Replies:** 0\
**Last updated:** [February 3, 2023, 1:59am UTC](https://discuss.elastic.co/t/nested-aggregation-to-just-get-some-nested-type-without-aggregatioon/324588 "2023-02-03T01:59:06Z")

</div>

I am not sure if is that possible. We have a set of documents with the same testId, and each set of those docs, always only have 1 of them has the frames nested type. So I want to do the aggression with the data, there …

---

## [Kibana server is not ready yet](https://discuss.elastic.co/t/kibana-server-is-not-ready-yet/322684)

<div class="topic-metadata">

**Author:** [@magen\_lahat](https://discuss.elastic.co/u/magen_lahat)\
**Replies:** 31\
**Last updated:** [February 2, 2023, 9:16pm UTC](https://discuss.elastic.co/t/kibana-server-is-not-ready-yet/322684 "2023-02-02T21:16:29Z")

</div>

hello, im a new user to elasticsearch and hoping to explore it further for my project, So I just installed elasticsearch and kibana on my ubuntu and im getting "Kibana server is not ready yet." after runnig http://loca…

---

## [Issue in Controls](https://discuss.elastic.co/t/issue-in-controls/320882)

<div class="topic-metadata">

**Author:** [@moep](https://discuss.elastic.co/u/moep)\
**Replies:** 27\
**Last updated:** [February 2, 2023, 7:06pm UTC](https://discuss.elastic.co/t/issue-in-controls/320882 "2023-02-02T19:06:34Z")

</div>

Dear Community, Im running Kibana 8.4.3 and I noticed a deprecation warning. So I used the new way for Controls. I have two fields, where I can add email addresses (sender and recipient). When Im looking for "jira@" th…

---

## [Kibana is unable to connect to ElasticSearch](https://discuss.elastic.co/t/kibana-is-unable-to-connect-to-elasticsearch/324561)

<div class="topic-metadata">

**Author:** [@MKirby](https://discuss.elastic.co/u/MKirby)\
**Replies:** 1\
**Last updated:** [February 2, 2023, 6:46pm UTC](https://discuss.elastic.co/t/kibana-is-unable-to-connect-to-elasticsearch/324561 "2023-02-02T18:46:07Z")

</div>

I have been using ELK now for about a year and half. I decided it was time to re-install my lab for better troubleshooting of the main environment. Now I am unable to get kibana to open. Both the Elasticsearch and Log…

---

## [Kibana dashboard](https://discuss.elastic.co/t/kibana-dashboard/324170)

<div class="topic-metadata">

**Author:** [@Swetha.B](https://discuss.elastic.co/u/Swetha.B)\
**Replies:** 2\
**Last updated:** [February 2, 2023, 6:12pm UTC](https://discuss.elastic.co/t/kibana-dashboard/324170 "2023-02-02T18:12:00Z")

</div>

We recently started using Kibana dashboard to analyze the logs for our QnAbot. In Kibana discover what is the tag name that represents whether the user has navigated(via clicking on the buttons) through the QnAbot or if…

---

## [How to Import a Kibana Dashboard with Ansible?](https://discuss.elastic.co/t/how-to-import-a-kibana-dashboard-with-ansible/324487)

<div class="topic-metadata">

**Author:** [@silentfilm](https://discuss.elastic.co/u/silentfilm)\
**Replies:** 2\
**Last updated:** [February 2, 2023, 5:56pm UTC](https://discuss.elastic.co/t/how-to-import-a-kibana-dashboard-with-ansible/324487 "2023-02-02T17:56:33Z")

</div>

We are upgrading from 7.9.3 to 7.17.8. I see that the method to import Kibana dashboards has changed. I can successfully import a dashboard using curl and using Postman. curl -k -u \<username\>:\<password\> -X POST https:…

---

## [Different aggregation count for the same value](https://discuss.elastic.co/t/different-aggregation-count-for-the-same-value/324566)

<div class="topic-metadata">

**Author:** [@mbklein](https://discuss.elastic.co/u/mbklein)\
**Replies:** 0\
**Last updated:** [February 2, 2023, 4:47pm UTC](https://discuss.elastic.co/t/different-aggregation-count-for-the-same-value/324566 "2023-02-02T16:47:22Z")

</div>

I don't understand the results I'm seeing. I am asking for two different aggs in the same query. The first is “show me the doc counts for subject.label for these specific values,” and the second is “show me the doc count…

---

## [Common points in two geo\_bounding\_box](https://discuss.elastic.co/t/common-points-in-two-geo-bounding-box/324387)

<div class="topic-metadata">

**Author:** [@maya\_khan](https://discuss.elastic.co/u/maya_khan)\
**Replies:** 10\
**Last updated:** [February 2, 2023, 7:00am UTC](https://discuss.elastic.co/t/common-points-in-two-geo-bounding-box/324387 "2023-02-02T07:00:17Z")

</div>

I have two geo\_bounding\_box within these two shapes many points exist. i want only those points that are common in both geo\_bounding\_box. { "bool":{ "should":\[ { "geo\_bounding\_box":{ "geo\_coords":{ "top\_left": { …

---

## [Query in rated requests should not contain aggregations](https://discuss.elastic.co/t/query-in-rated-requests-should-not-contain-aggregations/324559)

<div class="topic-metadata">

**Author:** [@ocastaneda](https://discuss.elastic.co/u/ocastaneda)\
**Replies:** 0\
**Last updated:** [February 2, 2023, 2:51pm UTC](https://discuss.elastic.co/t/query-in-rated-requests-should-not-contain-aggregations/324559 "2023-02-02T14:51:07Z")

</div>

Hello! Our search team is considering diversifying search results with diversified\_sampler aggregation and child top\_hits aggregation. I noticed that aggregations don’t work with the ranking evaluation API. Anyone got s…

[Previous page](https://discuss.elastic.co/tag/none.md?no_tags=true&page=442)

[Next page](https://discuss.elastic.co/tag/none.md?no_tags=true&page=444)
