# \#none

**URL:** https://discuss.elastic.co/tag/none.md?no_tags=true&page=444

[Latest](https://discuss.elastic.co/latest.md) · [Categories](https://discuss.elastic.co/categories.md) · [Tags](https://discuss.elastic.co/tags.md)

**Page:** 445

---

## [Fleet server data stream is not populating data](https://discuss.elastic.co/t/fleet-server-data-stream-is-not-populating-data/324554)

<div class="topic-metadata">

**Author:** [@Kosala\_Randika\_Paran](https://discuss.elastic.co/u/Kosala_Randika_Paran)\
**Replies:** 0\
**Last updated:** [February 2, 2023, 1:49pm UTC](https://discuss.elastic.co/t/fleet-server-data-stream-is-not-populating-data/324554 "2023-02-02T13:49:43Z")

</div>

Hi, We have configured fleet server and enrolled elastic agents to that but we can not see any data in Data Stream tab, anyone has an idea what was the issue?

---

## [Hardware Specifications for Storage Types](https://discuss.elastic.co/t/hardware-specifications-for-storage-types/324553)

<div class="topic-metadata">

**Author:** [@federica.forti](https://discuss.elastic.co/u/federica.forti)\
**Replies:** 0\
**Last updated:** [February 2, 2023, 1:44pm UTC](https://discuss.elastic.co/t/hardware-specifications-for-storage-types/324553 "2023-02-02T13:44:21Z")

</div>

Hi, we have choose the type of storage to associate to an Elasticsearch cluster. In particular, we wonder if there is any indication of the minimum characteristics that a certain type of storage must have; for example …

---

## [Reingenst CSV to change field names](https://discuss.elastic.co/t/reingenst-csv-to-change-field-names/324219)

<div class="topic-metadata">

**Author:** [@momoaux](https://discuss.elastic.co/u/momoaux)\
**Replies:** 3\
**Last updated:** [February 2, 2023, 11:18am UTC](https://discuss.elastic.co/t/reingenst-csv-to-change-field-names/324219 "2023-02-02T11:18:44Z")

</div>

Hello, I'm new to ELK stack. I have a lot of CSV files which share some common columns. But all have different names for their columns. Example: File 1: Name, Type, Code File 2: TP, NM, CD File 3: Co,Ty,Na My code…

---

## [Term query not working where type is "text"](https://discuss.elastic.co/t/term-query-not-working-where-type-is-text/324422)

<div class="topic-metadata">

**Author:** [@shebbi](https://discuss.elastic.co/u/shebbi)\
**Replies:** 6\
**Last updated:** [February 2, 2023, 10:05am UTC](https://discuss.elastic.co/t/term-query-not-working-where-type-is-text/324422 "2023-02-02T10:05:08Z")

</div>

Hi Team, We are using ES 7.16.2 version and below is the query which we have generated using Java apis, Please let us know why it is not working or are we doing something wrong? Query: - { "bool" : { "must" : \[ …

---

## [Sliced search not returning all hits](https://discuss.elastic.co/t/sliced-search-not-returning-all-hits/324513)

<div class="topic-metadata">

**Author:** [@jkruger](https://discuss.elastic.co/u/jkruger)\
**Replies:** 0\
**Last updated:** [February 2, 2023, 8:30am UTC](https://discuss.elastic.co/t/sliced-search-not-returning-all-hits/324513 "2023-02-02T08:30:38Z")

</div>

Hello, I am a new Elastic user, and I already ran into an issue. I am trying to extract all logs from a certain index. In order to deal with large indices I want to implement pagination using search\_after and PiTs (Poin…

---

## [Data Table limit of values](https://discuss.elastic.co/t/data-table-limit-of-values/324474)

<div class="topic-metadata">

**Author:** [@Brian\_Fernandez](https://discuss.elastic.co/u/Brian_Fernandez)\
**Replies:** 1\
**Last updated:** [February 2, 2023, 7:23am UTC](https://discuss.elastic.co/t/data-table-limit-of-values/324474 "2023-02-02T07:23:02Z")

</div>

Hi guys! I would like to know if there is anything i can do to expand the 100 rows value in a Data Table. Depending on the information you like to show, 100 rows are very few. Can you help me please? v 7.12.0

---

## [How to read logs with permanent \[NULL\]-characters at the end of file?](https://discuss.elastic.co/t/how-to-read-logs-with-permanent-null-characters-at-the-end-of-file/324408)

<div class="topic-metadata">

**Author:** [@Evgenii\_X](https://discuss.elastic.co/u/Evgenii_X)\
**Replies:** 1\
**Last updated:** [February 2, 2023, 6:46am UTC](https://discuss.elastic.co/t/how-to-read-logs-with-permanent-null-characters-at-the-end-of-file/324408 "2023-02-02T06:46:37Z")

</div>

We need to collect MT4 logs (MetaTrader 4 trading platform). Log-saving "Feature" in MT4 is implemented according to the following algorithm: When creating a log file (or adding new logs to the current one), the platfo…

---

## [Winlogbeat I am getting error when winlogbeat is 7.5 and elastic is 8.5.3](https://discuss.elastic.co/t/winlogbeat-i-am-getting-error-when-winlogbeat-is-7-5-and-elastic-is-8-5-3/324500)

<div class="topic-metadata">

**Author:** [@devdev7711](https://discuss.elastic.co/u/devdev7711)\
**Replies:** 1\
**Last updated:** [February 2, 2023, 6:02am UTC](https://discuss.elastic.co/t/winlogbeat-i-am-getting-error-when-winlogbeat-is-7-5-and-elastic-is-8-5-3/324500 "2023-02-02T06:02:50Z")

</div>

I am getting error when winlogbeat is 7.5 and elastic is 8.5.3 and kibana is also 8.5.3 if winlogbeat is 7.5 and elastic and kibana also 7.5 it is working fine ERROR pipeline/output.go:100 Failed to connect to backoff(…

---

## [Is number of documents in an Index is proportional to store.size or pri.store.size?](https://discuss.elastic.co/t/is-number-of-documents-in-an-index-is-proportional-to-store-size-or-pri-store-size/324496)

<div class="topic-metadata">

**Author:** [@vikasp](https://discuss.elastic.co/u/vikasp)\
**Replies:** 1\
**Last updated:** [February 2, 2023, 3:06am UTC](https://discuss.elastic.co/t/is-number-of-documents-in-an-index-is-proportional-to-store-size-or-pri-store-size/324496 "2023-02-02T03:06:12Z")

</div>

GET /\<index\>/\_count gives me the total number of documents in an index. GET /\_cat/indices/\<index\> gives me both total documents, store.size and pri.store.size. Say if I have an index with 1 primary and 1 replica. say …

---

## [Syntax error](https://discuss.elastic.co/t/syntax-error/324471)

<div class="topic-metadata">

**Author:** [@moep](https://discuss.elastic.co/u/moep)\
**Replies:** 3\
**Last updated:** [February 2, 2023, 12:32am UTC](https://discuss.elastic.co/t/syntax-error/324471 "2023-02-02T00:32:40Z")

</div>

Hey there, I'm working playing with Logstash and wrote alot of grok patterns. But right now, I have a syntax error in this snippet: if \[message\] =~ "SMTP error from remote mail server after RCPT TO" { grok { …

---

## [On-prem Kibana can't join elastic-package-registry (EPR) behind a proxy due to certificate issue - workaround tested](https://discuss.elastic.co/t/on-prem-kibana-cant-join-elastic-package-registry-epr-behind-a-proxy-due-to-certificate-issue-workaround-tested/324486)

<div class="topic-metadata">

**Author:** [@antoine\_duriez](https://discuss.elastic.co/u/antoine_duriez)\
**Replies:** 0\
**Last updated:** [February 1, 2023, 10:20pm UTC](https://discuss.elastic.co/t/on-prem-kibana-cant-join-elastic-package-registry-epr-behind-a-proxy-due-to-certificate-issue-workaround-tested/324486 "2023-02-01T22:20:35Z")

</div>

Hi, I have an on-prem stack 8.5.3 on RHEL 8 with high customer's restriction. Access to internet is done throught a proxy. Access to epr. elastic.co was opened and tested well with the command: nc epr.elastic.co 44…

---

## [Combining records that have the same id with a query](https://discuss.elastic.co/t/combining-records-that-have-the-same-id-with-a-query/324479)

<div class="topic-metadata">

**Author:** [@chachew](https://discuss.elastic.co/u/chachew)\
**Replies:** 2\
**Last updated:** [February 1, 2023, 9:24pm UTC](https://discuss.elastic.co/t/combining-records-that-have-the-same-id-with-a-query/324479 "2023-02-01T21:24:45Z")

</div>

I have records for call logs that i want to query and combine into 1 result per record instead of 2. This is for logging of calls from one person to another. The person that initiates the call has the 'initiator' flag se…

---

## [Make a copy of a running Elastic node](https://discuss.elastic.co/t/make-a-copy-of-a-running-elastic-node/324448)

<div class="topic-metadata">

**Author:** [@tmslara.a](https://discuss.elastic.co/u/tmslara.a)\
**Replies:** 8\
**Last updated:** [February 1, 2023, 9:02pm UTC](https://discuss.elastic.co/t/make-a-copy-of-a-running-elastic-node/324448 "2023-02-01T21:02:49Z")

</div>

Hi, I have a running Elastic node with an index. I'm constantly inserting documents into the index in a process that I can't stop. The whole process is running in a remote server. I need to make a copy of the index int…

---

## [Kibana control limitation](https://discuss.elastic.co/t/kibana-control-limitation/323872)

<div class="topic-metadata">

**Author:** [@elasticforme](https://discuss.elastic.co/u/elasticforme)\
**Replies:** 5\
**Last updated:** [February 1, 2023, 5:59pm UTC](https://discuss.elastic.co/t/kibana-control-limitation/323872 "2023-02-01T17:59:08Z")

</div>

using Kibana 8.5.3 new control can only show 10 value. How do I change that to see more value? in old control it was working

---

## [Any way to migrate Legacy templates to composable templates?](https://discuss.elastic.co/t/any-way-to-migrate-legacy-templates-to-composable-templates/324454)

<div class="topic-metadata">

**Author:** [@Monica\_majua](https://discuss.elastic.co/u/Monica_majua)\
**Replies:** 1\
**Last updated:** [February 1, 2023, 4:01pm UTC](https://discuss.elastic.co/t/any-way-to-migrate-legacy-templates-to-composable-templates/324454 "2023-02-01T16:01:25Z")

</div>

I have migrated to elasticsearch 7.8, I was reading that some of the changes include the replacement of Legacy index templates to composable index templates and I would like support to find a guide that can help me to mi…

---

## [Move config folder to another location on Window (v8.6.0)](https://discuss.elastic.co/t/move-config-folder-to-another-location-on-window-v8-6-0/324446)

<div class="topic-metadata">

**Author:** [@ykara84](https://discuss.elastic.co/u/ykara84)\
**Replies:** 0\
**Last updated:** [February 1, 2023, 2:53pm UTC](https://discuss.elastic.co/t/move-config-folder-to-another-location-on-window-v8-6-0/324446 "2023-02-01T14:53:03Z")

</div>

Hi, I have ES 8.6.0 on Windows (single-node). I am looking to move the config folder to another location. I have I have added two new environment variables: C:\\Windows\\system32\>echo %ES\_HOME% E:\\elk\\elasticsearch\\8.6.…

---

## [Combining fields into one for performance?](https://discuss.elastic.co/t/combining-fields-into-one-for-performance/324433)

<div class="topic-metadata">

**Author:** [@ryans](https://discuss.elastic.co/u/ryans)\
**Replies:** 0\
**Last updated:** [February 1, 2023, 1:59pm UTC](https://discuss.elastic.co/t/combining-fields-into-one-for-performance/324433 "2023-02-01T13:59:10Z")

</div>

I currently have 140 fields in my Elasticsearch index-based App Search Engine. I realized that 40 of those fields contain data that does not need to be indexed (it's display only data), so I marked them index:false in t…

---

## [Config monitoring moduels for Kind Elasticsearch](https://discuss.elastic.co/t/config-monitoring-moduels-for-kind-elasticsearch/324429)

<div class="topic-metadata">

**Author:** [@Ofir\_Edi](https://discuss.elastic.co/u/Ofir_Edi)\
**Replies:** 0\
**Last updated:** [February 1, 2023, 1:38pm UTC](https://discuss.elastic.co/t/config-monitoring-moduels-for-kind-elasticsearch/324429 "2023-02-01T13:38:39Z")

</div>

Hi, I'm configuring Monitoring in ECK using the spec.monitoring as defined here: Stack Monitoring | Elastic Cloud on Kubernetes \[master\] | Elastic I want to be able to better control the period in which metricbeat samp…

---

## [Use existing ElasticSearch tar while running integration/functional tests](https://discuss.elastic.co/t/use-existing-elasticsearch-tar-while-running-integration-functional-tests/324425)

<div class="topic-metadata">

**Author:** [@NamB](https://discuss.elastic.co/u/NamB)\
**Replies:** 0\
**Last updated:** [February 1, 2023, 12:48pm UTC](https://discuss.elastic.co/t/use-existing-elasticsearch-tar-while-running-integration-functional-tests/324425 "2023-02-01T12:48:59Z")

</div>

While running Kibana integration tests, could see that a daily Elasticsearch snapshot is downloaded and started. Is there some way to avoid this download and use locally built Elasticsearch file?

---

## [Logtash copy one field to another in a different log](https://discuss.elastic.co/t/logtash-copy-one-field-to-another-in-a-different-log/324423)

<div class="topic-metadata">

**Author:** [@tegerei](https://discuss.elastic.co/u/tegerei)\
**Replies:** 0\
**Last updated:** [February 1, 2023, 12:39pm UTC](https://discuss.elastic.co/t/logtash-copy-one-field-to-another-in-a-different-log/324423 "2023-02-01T12:39:45Z")

</div>

Hello, I have the following sample log. Feb 1 15:30:49 sudo: pam\_unix(sudo-i:auth): authentication failure; logname= uid=10050 euid=0 tty=/dev/pts/2 user=test Feb 1 15:30:50 sudo: pam\_sss(sudo-i:auth): authent…

---

## [Error on running Elasticsearch from the command line](https://discuss.elastic.co/t/error-on-running-elasticsearch-from-the-command-line/324305)

<div class="topic-metadata">

**Author:** [@umairsaeed](https://discuss.elastic.co/u/umairsaeed)\
**Replies:** 9\
**Last updated:** [February 1, 2023, 11:09am UTC](https://discuss.elastic.co/t/error-on-running-elasticsearch-from-the-command-line/324305 "2023-02-01T11:09:12Z")

</div>

I downloaded, unzipped, and run Elasticsearch from the command line successfully. But after closing the command line, I am trying to run the Elasticsearch from the command line again, but it is giving me an error "localh…

---

## [Can not install fleet server's elastic agent in Logstash server](https://discuss.elastic.co/t/can-not-install-fleet-servers-elastic-agent-in-logstash-server/324409)

<div class="topic-metadata">

**Author:** [@Kosala\_Randika\_Paran](https://discuss.elastic.co/u/Kosala_Randika_Paran)\
**Replies:** 0\
**Last updated:** [February 1, 2023, 10:30am UTC](https://discuss.elastic.co/t/can-not-install-fleet-servers-elastic-agent-in-logstash-server/324409 "2023-02-01T10:30:51Z")

</div>

Hi, I am trying to install fleet server's elastic agent in logstash server, but once I installed it given following error. any support on this?

---

## [Search Match for all tokens from decompound filter](https://discuss.elastic.co/t/search-match-for-all-tokens-from-decompound-filter/322483)

<div class="topic-metadata">

**Author:** [@florin\_olah](https://discuss.elastic.co/u/florin_olah)\
**Replies:** 3\
**Last updated:** [February 1, 2023, 10:03am UTC](https://discuss.elastic.co/t/search-match-for-all-tokens-from-decompound-filter/322483 "2023-02-01T10:03:47Z")

</div>

Hello, I am trying to do the same thing described in the topic here: German compound words in an e-commerce search simple example: searching for "sprachkurs" which is tokenized as "sprachkurs, sprach, kurs" Desired re…

---

## [ElasticsearchException\[failed to bind service\]; nested: IndexFormatTooNewException\[Format version is not supported](https://discuss.elastic.co/t/elasticsearchexception-failed-to-bind-service-nested-indexformattoonewexception-format-version-is-not-supported/324353)

<div class="topic-metadata">

**Author:** [@Doums\_D](https://discuss.elastic.co/u/Doums_D)\
**Replies:** 2\
**Last updated:** [February 1, 2023, 9:46am UTC](https://discuss.elastic.co/t/elasticsearchexception-failed-to-bind-service-nested-indexformattoonewexception-format-version-is-not-supported/324353 "2023-02-01T09:46:57Z")

</div>

Hello everyone, I have a issue on my elasticsearch server. i extended the storage from 1To to 2To and after rebooting i never could restart my elasticsearch service. Here is what i have actually in my journalctl when i…

---

## [Error on disable data\_detection](https://discuss.elastic.co/t/error-on-disable-data-detection/324265)

<div class="topic-metadata">

**Author:** [@sphawk](https://discuss.elastic.co/u/sphawk)\
**Replies:** 2\
**Last updated:** [February 1, 2023, 7:44am UTC](https://discuss.elastic.co/t/error-on-disable-data-detection/324265 "2023-02-01T07:44:27Z")

</div>

I'm trying to disable data\_detection via curl. I delete the shard curl -s -H 'Content-Type: application/json' -X DELETE 'http://localhost:9200/video?pretty' { "acknowledged" : true } then curl -H 'Content-Type: ap…

---

## [Upgrade Elasticsearch to 7.17.8](https://discuss.elastic.co/t/upgrade-elasticsearch-to-7-17-8/324391)

<div class="topic-metadata">

**Author:** [@Sandeepa\_Kariyawasam](https://discuss.elastic.co/u/Sandeepa_Kariyawasam)\
**Replies:** 1\
**Last updated:** [February 1, 2023, 7:27am UTC](https://discuss.elastic.co/t/upgrade-elasticsearch-to-7-17-8/324391 "2023-02-01T07:27:09Z")

</div>

I'm trying to upgrade my elasticsearch to version 7.17.8 from version 7.14.0. I have a single instant with kibana and logstash included. Current version has quiet a lot of data so it's hard to back it up. When I upgr…

---

## [Kibana control has white back ground](https://discuss.elastic.co/t/kibana-control-has-white-back-ground/323367)

<div class="topic-metadata">

**Author:** [@elasticforme](https://discuss.elastic.co/u/elasticforme)\
**Replies:** 3\
**Last updated:** [February 1, 2023, 6:48am UTC](https://discuss.elastic.co/t/kibana-control-has-white-back-ground/323367 "2023-02-01T06:48:59Z")

</div>

Kibana 8.5.3 after upgrade I notice that background is white and hardly able to read on it. how do I fix it. whole dashbaord is in dark mode. it was working ok on 7.x version. this selection is old style control which…

---

## [Export of Users & Roles in Kibana as CSV](https://discuss.elastic.co/t/export-of-users-roles-in-kibana-as-csv/324196)

<div class="topic-metadata">

**Author:** [@Sandeep\_Raju](https://discuss.elastic.co/u/Sandeep_Raju)\
**Replies:** 2\
**Last updated:** [February 1, 2023, 3:25am UTC](https://discuss.elastic.co/t/export-of-users-roles-in-kibana-as-csv/324196 "2023-02-01T03:25:29Z")

</div>

Hi all, For my internal purposes, I want to export a CSV of all users , roles and their permissions. I know I can see them in Roles & Users, but want an export of CSV. I believe every user is created as seperate inde…

---

## [Azure Event Hub Explanation](https://discuss.elastic.co/t/azure-event-hub-explanation/324373)

<div class="topic-metadata">

**Author:** [@gabrieligbastos](https://discuss.elastic.co/u/gabrieligbastos)\
**Replies:** 2\
**Last updated:** [February 1, 2023, 2:37am UTC](https://discuss.elastic.co/t/azure-event-hub-explanation/324373 "2023-02-01T02:37:23Z")

</div>

Hello, Im new to ELK Stack, and Im trying to increase observability with it. Im here have some doubts that I could not find a answer in other topics, probably because my problem is just too newbie! :slight\_smile: I dep…

---

## [Logstash occupies superior folder of log folder](https://discuss.elastic.co/t/logstash-occupies-superior-folder-of-log-folder/324379)

<div class="topic-metadata">

**Author:** [@Steven29](https://discuss.elastic.co/u/Steven29)\
**Replies:** 0\
**Last updated:** [February 1, 2023, 2:27am UTC](https://discuss.elastic.co/t/logstash-occupies-superior-folder-of-log-folder/324379 "2023-02-01T02:27:12Z")

</div>

I assigned the path ' /AllLog/Logstash'. But sometimes when I start the logstash, log(log of logstash) is not stacked because the AllLog folder is full(capacity). But when I stop the logstash, the capacity of AllLog f…

[Previous page](https://discuss.elastic.co/tag/none.md?no_tags=true&page=443)

[Next page](https://discuss.elastic.co/tag/none.md?no_tags=true&page=445)
