# \#none

**URL:** https://discuss.elastic.co/tag/none.md?no_tags=true&page=447

[Latest](https://discuss.elastic.co/latest.md) · [Categories](https://discuss.elastic.co/categories.md) · [Tags](https://discuss.elastic.co/tags.md)

**Page:** 448

---

## [Get just some fields of all elements using curl](https://discuss.elastic.co/t/get-just-some-fields-of-all-elements-using-curl/324184)

<div class="topic-metadata">

**Author:** [@sphawk](https://discuss.elastic.co/u/sphawk)\
**Replies:** 2\
**Last updated:** [January 30, 2023, 9:36am UTC](https://discuss.elastic.co/t/get-just-some-fields-of-all-elements-using-curl/324184 "2023-01-30T09:36:21Z")

</div>

Hi people. I need some help. I'm trying to make a query via curl to get some fields of all elements of a shard. I've tried this command: curl -s -H 'Content-Type: application/json' 'http://localhost:9200/video/\_searc…

---

## [Trouble replacing leading/trailing whitespace in nested json](https://discuss.elastic.co/t/trouble-replacing-leading-trailing-whitespace-in-nested-json/324129)

<div class="topic-metadata">

**Author:** [@mark54g](https://discuss.elastic.co/u/mark54g)\
**Replies:** 4\
**Last updated:** [January 30, 2023, 9:33am UTC](https://discuss.elastic.co/t/trouble-replacing-leading-trailing-whitespace-in-nested-json/324129 "2023-01-30T09:33:59Z")

</div>

Hey, folks Trying to figure out a clean way to solve this problem I have nested json coming in from an SQS queue, and I've been playing with mocking it up with a static file example and filebeat, which I know is not pe…

---

## [Remove extra options from visualisations](https://discuss.elastic.co/t/remove-extra-options-from-visualisations/324084)

<div class="topic-metadata">

**Author:** [@bandodkarD](https://discuss.elastic.co/u/bandodkarD)\
**Replies:** 1\
**Last updated:** [January 30, 2023, 9:25am UTC](https://discuss.elastic.co/t/remove-extra-options-from-visualisations/324084 "2023-01-30T09:25:00Z")

</div>

Is it possible to remove some options that are highlighted ??

---

## [How can i disable filters in Respective visualizations present in kibana dashboard?](https://discuss.elastic.co/t/how-can-i-disable-filters-in-respective-visualizations-present-in-kibana-dashboard/316751)

<div class="topic-metadata">

**Author:** [@andy4](https://discuss.elastic.co/u/andy4)\
**Replies:** 6\
**Last updated:** [January 30, 2023, 9:18am UTC](https://discuss.elastic.co/t/how-can-i-disable-filters-in-respective-visualizations-present-in-kibana-dashboard/316751 "2023-01-30T09:18:19Z")

</div>

multiple visualizations collectively makes up a dashboard and we have interactive filter application feature available through most of the visualization , Now suppose I want to disable filters to be applied on dashboard …

---

## [Gradle assemble error](https://discuss.elastic.co/t/gradle-assemble-error/324198)

<div class="topic-metadata">

**Author:** [@mkkim](https://discuss.elastic.co/u/mkkim)\
**Replies:** 0\
**Last updated:** [January 30, 2023, 8:18am UTC](https://discuss.elastic.co/t/gradle-assemble-error/324198 "2023-01-30T08:18:16Z")

</div>

\[kor\] 안녕하세요, 저는 한국인입니다. 저는 엘라스틱서치에 사용자 사전을 이용한 노리 플러그인을 이용하고자 합니다. 다음 링크를 참고해서 사용하고 있었습니다. (https://github.com/jimczi/nori/blob/master/how-to-custom-dict.asciidoc) 하지만 elasticsearch를 git pull한 후 gradle assemble을 할 …

---

## [Monitor SAP on azure](https://discuss.elastic.co/t/monitor-sap-on-azure/324072)

<div class="topic-metadata">

**Author:** [@ElasticLiver](https://discuss.elastic.co/u/ElasticLiver)\
**Replies:** 1\
**Last updated:** [January 30, 2023, 5:12am UTC](https://discuss.elastic.co/t/monitor-sap-on-azure/324072 "2023-01-30T05:12:37Z")

</div>

It is posible to monitor SAP on azure with beats or extract metrics with logstash? Thanks!

---

## [Is there a slow log (or something similar) for shard refresh durations?](https://discuss.elastic.co/t/is-there-a-slow-log-or-something-similar-for-shard-refresh-durations/324188)

<div class="topic-metadata">

**Author:** [@BenB196](https://discuss.elastic.co/u/BenB196)\
**Replies:** 0\
**Last updated:** [January 30, 2023, 12:02am UTC](https://discuss.elastic.co/t/is-there-a-slow-log-or-something-similar-for-shard-refresh-durations/324188 "2023-01-30T00:02:07Z")

</div>

Hi All, I'm attempting to debug a somewhat strange issue. Where I have a query which runs every 60 seconds to check a set of logs and if there are no logs for 90 seconds then trigger an alert (this is done via a Kibana …

---

## [Shard lock issue](https://discuss.elastic.co/t/shard-lock-issue/324094)

<div class="topic-metadata">

**Author:** [@akihu](https://discuss.elastic.co/u/akihu)\
**Replies:** 10\
**Last updated:** [January 29, 2023, 10:49pm UTC](https://discuss.elastic.co/t/shard-lock-issue/324094 "2023-01-29T22:49:33Z")

</div>

Dear Community, Would you happen to have any hints what might be wrong (and how to resolve it) with my elasticsearch cluster. I've cluster with three master nodes and two data nodes. Most of the indices are configured …

---

## [On-premise pricing?](https://discuss.elastic.co/t/on-premise-pricing/324183)

<div class="topic-metadata">

**Author:** [@johber](https://discuss.elastic.co/u/johber)\
**Replies:** 6\
**Last updated:** [January 29, 2023, 8:28pm UTC](https://discuss.elastic.co/t/on-premise-pricing/324183 "2023-01-29T20:28:38Z")

</div>

Hello, I'm developing a public e-commerce site. Can it use a self hosted Elasticsearch instance for free, without violating the new license model?

---

## [Logstash & JSON array split](https://discuss.elastic.co/t/logstash-json-array-split/324180)

<div class="topic-metadata">

**Author:** [@Jalpesh1689](https://discuss.elastic.co/u/Jalpesh1689)\
**Replies:** 1\
**Last updated:** [January 29, 2023, 6:16pm UTC](https://discuss.elastic.co/t/logstash-json-array-split/324180 "2023-01-29T18:16:56Z")

</div>

Hi Team, We have below array of JSON & want to ingest these JSON into Elasticsearch. We want split this & ingest into 2 rows : \[{ "RequestEventList":\[ { "Instant":"2015-09-28T12:46:50.713Z", "RequestKey":"11bcf87b…

---

## [Can the size in pixels, vh or other units of a dashboard in an iframe or its visualizations be calculated? How is its size connected with the gridData width and height?](https://discuss.elastic.co/t/can-the-size-in-pixels-vh-or-other-units-of-a-dashboard-in-an-iframe-or-its-visualizations-be-calculated-how-is-its-size-connected-with-the-griddata-width-and-height/322624)

<div class="topic-metadata">

**Author:** [@DMinovski](https://discuss.elastic.co/u/DMinovski)\
**Replies:** 2\
**Last updated:** [January 29, 2023, 2:19pm UTC](https://discuss.elastic.co/t/can-the-size-in-pixels-vh-or-other-units-of-a-dashboard-in-an-iframe-or-its-visualizations-be-calculated-how-is-its-size-connected-with-the-griddata-width-and-height/322624 "2023-01-29T14:19:31Z")

</div>

Is there a way to get a dashboard-in-iframe's height in pixels or other CSS units that can be measured in the browse and its viewport, outside Kibana? Or maybe get the height of individual visualizations based on their g…

---

## [How to add searched value with terms query results](https://discuss.elastic.co/t/how-to-add-searched-value-with-terms-query-results/324174)

<div class="topic-metadata">

**Author:** [@Nowrin\_Hossain](https://discuss.elastic.co/u/Nowrin_Hossain)\
**Replies:** 0\
**Last updated:** [January 29, 2023, 11:23am UTC](https://discuss.elastic.co/t/how-to-add-searched-value-with-terms-query-results/324174 "2023-01-29T11:23:39Z")

</div>

Hello, I want to do search an index with multiple values. I want to also know which search result comes for which searched value. Can I do this in case of terms query. e.g. GET /\_search { "query": { "terms": { …

---

## [2.4.1 groovy script aggregation make high cpu](https://discuss.elastic.co/t/2-4-1-groovy-script-aggregation-make-high-cpu/323107)

<div class="topic-metadata">

**Author:** [@huasheng\_zeng](https://discuss.elastic.co/u/huasheng_zeng)\
**Replies:** 2\
**Last updated:** [January 29, 2023, 4:04am UTC](https://discuss.elastic.co/t/2-4-1-groovy-script-aggregation-make-high-cpu/323107 "2023-01-29T04:04:25Z")

</div>

es version is 2.4.1 query request is {"aggregations":{"0-0":{"aggregations":{"0-1":{"aggregations":{"0-2":{"aggregations":{"1-0":{"aggregations":{"1-1":{"reverse\_nested":{}}},"filters":{"filters":\[{"script":{"script":{…

---

## [Replace one value with another logstash](https://discuss.elastic.co/t/replace-one-value-with-another-logstash/324130)

<div class="topic-metadata">

**Author:** [@Jose\_Campos](https://discuss.elastic.co/u/Jose_Campos)\
**Replies:** 2\
**Last updated:** [January 27, 2023, 8:44pm UTC](https://discuss.elastic.co/t/replace-one-value-with-another-logstash/324130 "2023-01-27T20:44:05Z")

</div>

Hi, I was trying to convert the value of one field with another, for example: I currently have a field called "priority" and the value of that field is = 1, priority=1. What I want to do is change that value 1 to critic…

---

## [Mutate a specific JSON field but not another](https://discuss.elastic.co/t/mutate-a-specific-json-field-but-not-another/324079)

<div class="topic-metadata">

**Author:** [@hexoffender](https://discuss.elastic.co/u/hexoffender)\
**Replies:** 3\
**Last updated:** [January 27, 2023, 8:18pm UTC](https://discuss.elastic.co/t/mutate-a-specific-json-field-but-not-another/324079 "2023-01-27T20:18:40Z")

</div>

Hello, I have data that looks like this. { "remote\_addr": "127.0.0.1", "time\_local": "26/Jan/2023:17:07:18 -0800", "request": "POST /abcd HTTP/1.1", "request\_method": "POST", "status": "200", "us…

---

## [Creating an index with existing index](https://discuss.elastic.co/t/creating-an-index-with-existing-index/323550)

<div class="topic-metadata">

**Author:** [@elrozario](https://discuss.elastic.co/u/elrozario)\
**Replies:** 1\
**Last updated:** [January 27, 2023, 8:15pm UTC](https://discuss.elastic.co/t/creating-an-index-with-existing-index/323550 "2023-01-27T20:15:28Z")

</div>

Hello, I have many indexes named .ds-traces-apm-default-2022.12.12-000124 .ds-traces-apm-default-2022.12.17-000125 .ds-traces-apm-default-2022.12.20-000126 .ds-traces-apm-default-2022.12.22-000127 .ds-traces-apm-de…

---

## ["upgrade Assistant" is not visible under "management tab"](https://discuss.elastic.co/t/upgrade-assistant-is-not-visible-under-management-tab/324055)

<div class="topic-metadata">

**Author:** [@shahulyousuf](https://discuss.elastic.co/u/shahulyousuf)\
**Replies:** 2\
**Last updated:** [January 27, 2023, 6:18pm UTC](https://discuss.elastic.co/t/upgrade-assistant-is-not-visible-under-management-tab/324055 "2023-01-27T18:18:38Z")

</div>

Hey, I'm new to elasticsearch, I have installed elasticsearch 8.5.2 in single node and configured Kibana. Now I'm trying to upgrade to 8.6.1 through upgrade assistant as elastic user but cant find the upgrade assistant…

---

## [Provided Grok expressions do not match field value](https://discuss.elastic.co/t/provided-grok-expressions-do-not-match-field-value/324133)

<div class="topic-metadata">

**Author:** [@a.emrekaraman](https://discuss.elastic.co/u/a.emrekaraman)\
**Replies:** 0\
**Last updated:** [January 27, 2023, 6:04pm UTC](https://discuss.elastic.co/t/provided-grok-expressions-do-not-match-field-value/324133 "2023-01-27T18:04:38Z")

</div>

Hi Team, I installed 7.12.1 filebeat and enabled apache module but I'm getting "error.message Provided Grok expressions do not match field value". I checked apache log format for my website.it seems like below; LogFo…

---

## [There is a way to use search\_after to restart an scroll?](https://discuss.elastic.co/t/there-is-a-way-to-use-search-after-to-restart-an-scroll/324128)

<div class="topic-metadata">

**Author:** [@Guillermo\_Garcia1](https://discuss.elastic.co/u/Guillermo_Garcia1)\
**Replies:** 0\
**Last updated:** [January 27, 2023, 5:13pm UTC](https://discuss.elastic.co/t/there-is-a-way-to-use-search-after-to-restart-an-scroll/324128 "2023-01-27T17:13:45Z")

</div>

It is possible to start an scroll with search\_after ? The idea is to : Create an scroll with a good "sort" Iterate thanks to the scroll\_id and process each batch of docs If when asking for the next batch, a "search\_con…

---

## [Why do get results for some strings within a field, but not others?](https://discuss.elastic.co/t/why-do-get-results-for-some-strings-within-a-field-but-not-others/324011)

<div class="topic-metadata">

**Author:** [@eeijlar](https://discuss.elastic.co/u/eeijlar)\
**Replies:** 1\
**Last updated:** [January 27, 2023, 4:53pm UTC](https://discuss.elastic.co/t/why-do-get-results-for-some-strings-within-a-field-but-not-others/324011 "2023-01-27T16:53:11Z")

</div>

I can search for ERROR within the message field, but if I try transactionId, I get no hits..

---

## [Work with multiples inputs/outputs in microsoft-logstash-output-azure-loganalytics plugin](https://discuss.elastic.co/t/work-with-multiples-inputs-outputs-in-microsoft-logstash-output-azure-loganalytics-plugin/324068)

<div class="topic-metadata">

**Author:** [@Rafael\_Oliveira](https://discuss.elastic.co/u/Rafael_Oliveira)\
**Replies:** 3\
**Last updated:** [January 27, 2023, 4:08pm UTC](https://discuss.elastic.co/t/work-with-multiples-inputs-outputs-in-microsoft-logstash-output-azure-loganalytics-plugin/324068 "2023-01-27T16:08:19Z")

</div>

I'm working with microsoft-logstash-output-azure-loganalytics plugin and have to receive different inputs and send to different output based on tags or port. Is is possible? Let's my config file: input { tcp { …

---

## [Kibana 7.10 - "Evidence of administrator activity being logged and monitoring."](https://discuss.elastic.co/t/kibana-7-10-evidence-of-administrator-activity-being-logged-and-monitoring/324059)

<div class="topic-metadata">

**Author:** [@cade.carpenter](https://discuss.elastic.co/u/cade.carpenter)\
**Replies:** 3\
**Last updated:** [January 27, 2023, 2:23pm UTC](https://discuss.elastic.co/t/kibana-7-10-evidence-of-administrator-activity-being-logged-and-monitoring/324059 "2023-01-27T14:23:42Z")

</div>

Hello everyone, I am assisting in data gathering for an upcoming audit and I am trying to use Kibana to search for 'Evidence of admin activity being logged' but I cannot seem to grasp the needed search parameters. I am…

---

## [java.lang.NullPointerException: Cannot invoke "java.util.List.stream()" because the return value of "org.elasticsearch.indices.NodeIndicesStats.getShardStats(org.elasticsearch.index.Index)" is null](https://discuss.elastic.co/t/java-lang-nullpointerexception-cannot-invoke-java-util-list-stream-because-the-return-value-of-org-elasticsearch-indices-nodeindicesstats-getshardstats-org-elasticsearch-index-index-is-null/324091)

<div class="topic-metadata">

**Author:** [@sasvmware](https://discuss.elastic.co/u/sasvmware)\
**Replies:** 1\
**Last updated:** [January 27, 2023, 2:12pm UTC](https://discuss.elastic.co/t/java-lang-nullpointerexception-cannot-invoke-java-util-list-stream-because-the-return-value-of-org-elasticsearch-indices-nodeindicesstats-getshardstats-org-elasticsearch-index-index-is-null/324091 "2023-01-27T14:12:40Z")

</div>

Hi We are getting below in prod \[2023-01-26T23:55:54,079\]\[ERROR\]\[o.e.x.m.c.c.ClusterStatsCollector\] \[xxx-prd-elkmd1.xxxxxx.com\] collector \[cluster\_stats\] failed to collect data java.lang.NullPointerException: Cannot i…

---

## [Logstash starting error with JSON codec plugin](https://discuss.elastic.co/t/logstash-starting-error-with-json-codec-plugin/324100)

<div class="topic-metadata">

**Author:** [@sbocquet](https://discuss.elastic.co/u/sbocquet)\
**Replies:** 2\
**Last updated:** [January 27, 2023, 1:43pm UTC](https://discuss.elastic.co/t/logstash-starting-error-with-json-codec-plugin/324100 "2023-01-27T13:43:49Z")

</div>

Hi, I'm trying to send some logs with rsyslog in JSON format to my logstash v8.6 server, but it seems that there is a problem with my JSON codec. Here is the error log : \[2023-01-27T11:31:47,917\]\[INFO \]\[logstash.runne…

---

## [Integración con Microsoft Exchange Online Message Trace](https://discuss.elastic.co/t/integracion-con-microsoft-exchange-online-message-trace/324111)

<div class="topic-metadata">

**Author:** [@Gonzalo\_Sandoval\_A](https://discuss.elastic.co/u/Gonzalo_Sandoval_A)\
**Replies:** 0\
**Last updated:** [January 27, 2023, 1:29pm UTC](https://discuss.elastic.co/t/integracion-con-microsoft-exchange-online-message-trace/324111 "2023-01-27T13:29:49Z")

</div>

Hi, I need to integrate the Microsoft Exchange Online Message Trace, I am using the elastic agent integration and I don't know which url to put, please help as I think there is missing information and I am not very rela…

---

## [Add message in Kibana login page](https://discuss.elastic.co/t/add-message-in-kibana-login-page/324110)

<div class="topic-metadata">

**Author:** [@ismael\_boumedien](https://discuss.elastic.co/u/ismael_boumedien)\
**Replies:** 1\
**Last updated:** [January 27, 2023, 1:24pm UTC](https://discuss.elastic.co/t/add-message-in-kibana-login-page/324110 "2023-01-27T13:24:49Z")

</div>

Hi, We want to add a message in Kibana login page. We are using Kibana 5.6.8, Is't possible. If yes please advice us. Regards Ismaël

---

## [Logstash 8.5.2 how to parse special character in a string value](https://discuss.elastic.co/t/logstash-8-5-2-how-to-parse-special-character-in-a-string-value/324107)

<div class="topic-metadata">

**Author:** [@gaetano](https://discuss.elastic.co/u/gaetano)\
**Replies:** 3\
**Last updated:** [January 27, 2023, 1:14pm UTC](https://discuss.elastic.co/t/logstash-8-5-2-how-to-parse-special-character-in-a-string-value/324107 "2023-01-27T13:14:10Z")

</div>

Parsing a value of string field http://127.0.0.1:27336/notify logstash maps in Elastic search index many values for the original string. In this case values are http, 127.0.0.1, 27336 and notify. When it encounters t…

---

## [Logstash Value too large to output](https://discuss.elastic.co/t/logstash-value-too-large-to-output/323495)

<div class="topic-metadata">

**Author:** [@Doremanilka](https://discuss.elastic.co/u/Doremanilka)\
**Replies:** 10\
**Last updated:** [January 27, 2023, 11:43am UTC](https://discuss.elastic.co/t/logstash-value-too-large-to-output/323495 "2023-01-27T11:43:09Z")

</div>

Hello, I have new core app that I need to parse. This app has strange big message output field and I need somehow add it to ELK. Log pattern: grok { match =\> \[ "message", "%{DATA:\[event\]\[ti…

---

## [Single Server Single Node vs Single Server Multiple Node](https://discuss.elastic.co/t/single-server-single-node-vs-single-server-multiple-node/324081)

<div class="topic-metadata">

**Author:** [@sramana235](https://discuss.elastic.co/u/sramana235)\
**Replies:** 4\
**Last updated:** [January 27, 2023, 10:06am UTC](https://discuss.elastic.co/t/single-server-single-node-vs-single-server-multiple-node/324081 "2023-01-27T10:06:16Z")

</div>

As the title suggests, I wonder if it is better to configure a single node or multiple nodes when configuring a node on a single server. I understood that the reason for configuring multiple nodes can have the advantage…

---

## [Received plaintext http traffic on an https channel](https://discuss.elastic.co/t/received-plaintext-http-traffic-on-an-https-channel/324074)

<div class="topic-metadata">

**Author:** [@Cruz](https://discuss.elastic.co/u/Cruz)\
**Replies:** 3\
**Last updated:** [January 27, 2023, 10:01am UTC](https://discuss.elastic.co/t/received-plaintext-http-traffic-on-an-https-channel/324074 "2023-01-27T10:01:14Z")

</div>

Is it normal for this to appear as a warning in the elasticsearch logs? The first time I installed elasticsearch, this is what I saw in the elasticsearch logs. \[2023-01-27T06:18:35,815\]\[WARN \]\[o.e.x.s.t.n.SecurityNetty…

[Previous page](https://discuss.elastic.co/tag/none.md?no_tags=true&page=446)

[Next page](https://discuss.elastic.co/tag/none.md?no_tags=true&page=448)
