# \#none

**URL:** https://discuss.elastic.co/tag/none.md?no_tags=true&page=448

[Latest](https://discuss.elastic.co/latest.md) · [Categories](https://discuss.elastic.co/categories.md) · [Tags](https://discuss.elastic.co/tags.md)

**Page:** 449

---

## [Elastic Agent - Import only the latest data using Journald integration](https://discuss.elastic.co/t/elastic-agent-import-only-the-latest-data-using-journald-integration/324097)

<div class="topic-metadata">

**Author:** [@daniele.saccon](https://discuss.elastic.co/u/daniele.saccon)\
**Replies:** 0\
**Last updated:** [January 27, 2023, 9:53am UTC](https://discuss.elastic.co/t/elastic-agent-import-only-the-latest-data-using-journald-integration/324097 "2023-01-27T09:53:16Z")

</div>

Hello everybody, I'm using the Journald integration for the Elastic Agent. Is it possible to import only the last 7 days of the Journald instead of all the data? If it is possible how can I do? Thanks Daniele

---

## [Query a field that has a colon](https://discuss.elastic.co/t/query-a-field-that-has-a-colon/323966)

<div class="topic-metadata">

**Author:** [@ilias\_ioannou](https://discuss.elastic.co/u/ilias_ioannou)\
**Replies:** 2\
**Last updated:** [January 27, 2023, 9:34am UTC](https://discuss.elastic.co/t/query-a-field-that-has-a-colon/323966 "2023-01-27T09:34:21Z")

</div>

Hello, Is it possible to use elasticsearch dsl python client to implement a query that will run against a filed with colon? For example if a field is this properties.grid:code then a successfull query would be the foll…

---

## [Kibana Dev Tool Autocomplete](https://discuss.elastic.co/t/kibana-dev-tool-autocomplete/320916)

<div class="topic-metadata">

**Author:** [@M.Arbaz\_Ali](https://discuss.elastic.co/u/M.Arbaz_Ali)\
**Replies:** 1\
**Last updated:** [January 27, 2023, 9:33am UTC](https://discuss.elastic.co/t/kibana-dev-tool-autocomplete/320916 "2023-01-27T09:33:53Z")

</div>

autocomplete in dev tools console not working after GET there is no option of list of \_cluster or \_cat just showing a limited list when have (\_processor,\_search/template etc etc) but not showing \_cat or \_cluster

---

## [Elastic cluster running out of space, can't get cluster health to green](https://discuss.elastic.co/t/elastic-cluster-running-out-of-space-cant-get-cluster-health-to-green/323906)

<div class="topic-metadata">

**Author:** [@lostsoul352](https://discuss.elastic.co/u/lostsoul352)\
**Replies:** 6\
**Last updated:** [January 27, 2023, 9:22am UTC](https://discuss.elastic.co/t/elastic-cluster-running-out-of-space-cant-get-cluster-health-to-green/323906 "2023-01-27T09:22:35Z")

</div>

I have a 2 node elastic cluster. I noticed that I was not able to add more data to it, and it turned out the filesystem space is over at the flood limit on both machines. So to try and recover from this I shut down the …

---

## [Elasticsearch, Kibana does not work](https://discuss.elastic.co/t/elasticsearch-kibana-does-not-work/323472)

<div class="topic-metadata">

**Author:** [@Mursel](https://discuss.elastic.co/u/Mursel)\
**Replies:** 16\
**Last updated:** [January 27, 2023, 6:45am UTC](https://discuss.elastic.co/t/elasticsearch-kibana-does-not-work/323472 "2023-01-27T06:45:39Z")

</div>

I have an issue with Elasticsearch. After restarting ubuntu, Kibana does not show any logs.

---

## [Time based indexes](https://discuss.elastic.co/t/time-based-indexes/324067)

<div class="topic-metadata">

**Author:** [@mardo](https://discuss.elastic.co/u/mardo)\
**Replies:** 2\
**Last updated:** [January 27, 2023, 6:31am UTC](https://discuss.elastic.co/t/time-based-indexes/324067 "2023-01-27T06:31:04Z")

</div>

Its my understanding to remove data if it is 15 days old time based indexes is the way to go. I can't find any documentation or how-to article to accomplish this easily. I am using Kibana. Any help would be appreciate…

---

## [Can't install logstash-output-influxdb plugin](https://discuss.elastic.co/t/cant-install-logstash-output-influxdb-plugin/323890)

<div class="topic-metadata">

**Author:** [@AlanChan](https://discuss.elastic.co/u/AlanChan)\
**Replies:** 19\
**Last updated:** [January 27, 2023, 6:23am UTC](https://discuss.elastic.co/t/cant-install-logstash-output-influxdb-plugin/323890 "2023-01-27T06:23:37Z")

</div>

Hi, I'm using Logstash (8.6.0) and want to send data to influxdb2 (2.6.1). But I find that logstash-output-infludb isn't installed by default, so I'm trying to install it. Some errors happen but no details are shown. C…

---

## [Logstash plugins still displaying ECS v8 warnings](https://discuss.elastic.co/t/logstash-plugins-still-displaying-ecs-v8-warnings/324030)

<div class="topic-metadata">

**Author:** [@Oddly](https://discuss.elastic.co/u/Oddly)\
**Replies:** 4\
**Last updated:** [January 26, 2023, 10:18pm UTC](https://discuss.elastic.co/t/logstash-plugins-still-displaying-ecs-v8-warnings/324030 "2023-01-26T22:18:20Z")

</div>

I noticed that several plugins (grok and outputs.elasticsearchmonitoring to name a few) are still displaying warning messages like the following: \[WARN\]\[logstash.filters.grok\]\[\<pipeline\_redacted\] ECS v8 support is a pre…

---

## [Failed to perform request](https://discuss.elastic.co/t/failed-to-perform-request/324071)

<div class="topic-metadata">

**Author:** [@test\_qweqwe](https://discuss.elastic.co/u/test_qweqwe)\
**Replies:** 1\
**Last updated:** [January 26, 2023, 10:15pm UTC](https://discuss.elastic.co/t/failed-to-perform-request/324071 "2023-01-26T22:15:18Z")

</div>

\[2023-01-26T19:51:43,271\]\[INFO \]\[logstash.outputs.elasticsearch\]\[main\] Failed to perform request {:message=\>"192.168.0.108:9200 failed to respond", :exception=\>Manticore::ClientProtocolException, :cause=\>#\<Java::OrgApach…

---

## [Two types under one filter](https://discuss.elastic.co/t/two-types-under-one-filter/323978)

<div class="topic-metadata">

**Author:** [@rachelyang](https://discuss.elastic.co/u/rachelyang)\
**Replies:** 3\
**Last updated:** [January 26, 2023, 9:54pm UTC](https://discuss.elastic.co/t/two-types-under-one-filter/323978 "2023-01-26T21:54:30Z")

</div>

Can I have two types (plain txt log & json )under one filter in the logstash.yml file? input { beats { port =\> "5044" } } filter { if \[fields=='access'\] { grok { remove\_field =\> "message" } …

---

## [How to disable the traceparent and tracestate headers](https://discuss.elastic.co/t/how-to-disable-the-traceparent-and-tracestate-headers/324058)

<div class="topic-metadata">

**Author:** [@e03c5fccb551b6833a65](https://discuss.elastic.co/u/e03c5fccb551b6833a65)\
**Replies:** 0\
**Last updated:** [January 26, 2023, 6:23pm UTC](https://discuss.elastic.co/t/how-to-disable-the-traceparent-and-tracestate-headers/324058 "2023-01-26T18:23:08Z")

</div>

One of our services connects with a bank, and it's not allowing any requests with the tracepearent, tracestate header. I tried using the property use\_elastic\_traceparent\_header as false, but still I see the headers in t…

---

## [How many of you are using Otel for your K8S apps on Elastic vs docker?](https://discuss.elastic.co/t/how-many-of-you-are-using-otel-for-your-k8s-apps-on-elastic-vs-docker/324056)

<div class="topic-metadata">

**Author:** [@Bahubali\_Shetti](https://discuss.elastic.co/u/Bahubali_Shetti)\
**Replies:** 0\
**Last updated:** [January 26, 2023, 6:02pm UTC](https://discuss.elastic.co/t/how-many-of-you-are-using-otel-for-your-k8s-apps-on-elastic-vs-docker/324056 "2023-01-26T18:02:33Z")

</div>

OpenTelemetry and Elastic: An unbeatable combination for observability | Elastic Blog covers the baseline of what's being supported. Curious what people's experiences are on Otel with Elastic. Any interesting examples, e…

---

## [JVM options file vs. ES\_JAVA\_OPTS on ECK for setting heap size](https://discuss.elastic.co/t/jvm-options-file-vs-es-java-opts-on-eck-for-setting-heap-size/324051)

<div class="topic-metadata">

**Author:** [@Thomas\_Antonio](https://discuss.elastic.co/u/Thomas_Antonio)\
**Replies:** 0\
**Last updated:** [January 26, 2023, 5:25pm UTC](https://discuss.elastic.co/t/jvm-options-file-vs-es-java-opts-on-eck-for-setting-heap-size/324051 "2023-01-26T17:25:51Z")

</div>

ECK documentation says to configure heap size using ES\_JAVA\_OPTS environment variable. But Elasticsearch docs say to not use ES\_JAVA\_OPTS in production and instead use an options file. Is this a gap in ECK documentation…

---

## [Completion-Suggester that respects the number of word occurences](https://discuss.elastic.co/t/completion-suggester-that-respects-the-number-of-word-occurences/324031)

<div class="topic-metadata">

**Author:** [@Andromeda](https://discuss.elastic.co/u/Andromeda)\
**Replies:** 0\
**Last updated:** [January 26, 2023, 2:59pm UTC](https://discuss.elastic.co/t/completion-suggester-that-respects-the-number-of-word-occurences/324031 "2023-01-26T14:59:21Z")

</div>

Hello there, is there a way that Completion-Suggesters deliver suggests depending on how often matching words appear in the completion fields of all documents? For example, imagine "thinks" appears in completion fields…

---

## [Kibana markdown - clickable location for an image linked to URL](https://discuss.elastic.co/t/kibana-markdown-clickable-location-for-an-image-linked-to-url/323967)

<div class="topic-metadata">

**Author:** [@Buddha](https://discuss.elastic.co/u/Buddha)\
**Replies:** 3\
**Last updated:** [January 26, 2023, 3:39pm UTC](https://discuss.elastic.co/t/kibana-markdown-clickable-location-for-an-image-linked-to-url/323967 "2023-01-26T15:39:05Z")

</div>

Hello, I am seeing an issue with my current deployment of version 8.6.0 where a linked image is only clickable in a small portion at bottom. When editing the visual, the behaviour was correct where I was able to click …

---

## [Logstash configuration to IBM MQ using TLS and Cipher](https://discuss.elastic.co/t/logstash-configuration-to-ibm-mq-using-tls-and-cipher/323995)

<div class="topic-metadata">

**Author:** [@JHE](https://discuss.elastic.co/u/JHE)\
**Replies:** 0\
**Last updated:** [January 26, 2023, 7:43am UTC](https://discuss.elastic.co/t/logstash-configuration-to-ibm-mq-using-tls-and-cipher/323995 "2023-01-26T07:43:45Z")

</div>

Hi, I'm trying to connect logstash to IBM MQ using jms input. It's OK for an non secured connection. However I didn't find any example to configure a TLS connection and to specify a cipher suites. Here bellow my confi…

---

## [Kibana Action failed with 'search\_phase\_execution\_exception](https://discuss.elastic.co/t/kibana-action-failed-with-search-phase-execution-exception/324024)

<div class="topic-metadata">

**Author:** [@darinka.mandarinka](https://discuss.elastic.co/u/darinka.mandarinka)\
**Replies:** 1\
**Last updated:** [January 26, 2023, 2:27pm UTC](https://discuss.elastic.co/t/kibana-action-failed-with-search-phase-execution-exception/324024 "2023-01-26T14:27:31Z")

</div>

I have Elasticsearh, Kibana, Filebeat in our cluster. In kibana logs I see error Action failed with 'search\_phase\_execution\_exception How I can solve it? I'm new, first time working with this.

---

## [Migrating from ES 5 to ES 8, problems in index](https://discuss.elastic.co/t/migrating-from-es-5-to-es-8-problems-in-index/323454)

<div class="topic-metadata">

**Author:** [@Anibal\_Ardid](https://discuss.elastic.co/u/Anibal_Ardid)\
**Replies:** 4\
**Last updated:** [January 26, 2023, 2:17pm UTC](https://discuss.elastic.co/t/migrating-from-es-5-to-es-8-problems-in-index/323454 "2023-01-26T14:17:51Z")

</div>

Hi ! I have this json that i use to index { "settings":{ "number\_of\_shards":1, "number\_of\_replicas":0, "index.mapping.total\_fields.limit":100000, "analysis":{ "filter":{ …

---

## [Zscaler logs mapped to ECS](https://discuss.elastic.co/t/zscaler-logs-mapped-to-ecs/323963)

<div class="topic-metadata">

**Author:** [@reswob](https://discuss.elastic.co/u/reswob)\
**Replies:** 1\
**Last updated:** [January 26, 2023, 1:40pm UTC](https://discuss.elastic.co/t/zscaler-logs-mapped-to-ecs/323963 "2023-01-26T13:40:54Z")

</div>

I'm working on ingesting zscaler zia logs and I'm trying to understand the mapping. I'm looking at the following websites: Zscaler Internet Access | Elastic docs for what happens inside Elastic/Kibana and NSS Feed Out…

---

## [In ES 7.0, when using sequence numbers based recovery,primary and replica shard will be inconsistent](https://discuss.elastic.co/t/in-es-7-0-when-using-sequence-numbers-based-recovery-primary-and-replica-shard-will-be-inconsistent/324006)

<div class="topic-metadata">

**Author:** [@warriorswin](https://discuss.elastic.co/u/warriorswin)\
**Replies:** 3\
**Last updated:** [January 26, 2023, 1:29pm UTC](https://discuss.elastic.co/t/in-es-7-0-when-using-sequence-numbers-based-recovery-primary-and-replica-shard-will-be-inconsistent/324006 "2023-01-26T13:29:15Z")

</div>

add data=A node1 primary data=A seqNo=1 No persistence node2 replica data=A seqNo=1 Persistence node1,node2 shutdown node1 restart and add data=B node1 primary data=B seqNo=1 node2 restart When using sequence numb…

---

## [Can i sort my documents by date several conditions?](https://discuss.elastic.co/t/can-i-sort-my-documents-by-date-several-conditions/324015)

<div class="topic-metadata">

**Author:** [@Volodymyr\_Dzhuryn](https://discuss.elastic.co/u/Volodymyr_Dzhuryn)\
**Replies:** 2\
**Last updated:** [January 26, 2023, 11:55am UTC](https://discuss.elastic.co/t/can-i-sort-my-documents-by-date-several-conditions/324015 "2023-01-26T11:55:34Z")

</div>

I have index with document which have two field with dates "match\_date\_time" and "created\_at". I need query for getting documents sorted by next criteria 1. \[ASC order\] articles with future match date and time (sorted …

---

## [Delete index](https://discuss.elastic.co/t/delete-index/324016)

<div class="topic-metadata">

**Author:** [@mezzetto\_mezzetto](https://discuss.elastic.co/u/mezzetto_mezzetto)\
**Replies:** 0\
**Last updated:** [January 26, 2023, 11:19am UTC](https://discuss.elastic.co/t/delete-index/324016 "2023-01-26T11:19:17Z")

</div>

Hi all, I'm newbie on elastic. I've a custom installation an I need to free storage space; I've a rollover policy that creates a new index after 30 days or if it reach 50GB; I have 14 index, if I try to close a very old …

---

## [Change Elasticsearch and Kibana communication certificate](https://discuss.elastic.co/t/change-elasticsearch-and-kibana-communication-certificate/324000)

<div class="topic-metadata">

**Author:** [@Kosala\_Randika\_Paran](https://discuss.elastic.co/u/Kosala_Randika_Paran)\
**Replies:** 2\
**Last updated:** [January 26, 2023, 10:46am UTC](https://discuss.elastic.co/t/change-elasticsearch-and-kibana-communication-certificate/324000 "2023-01-26T10:46:49Z")

</div>

Hi All, Our certificates which are assign to Elasticsearch and Kibana are expired and seem like self sign certs are there, so I would appreciate that if anyone can guide how to do that? We have 3 ES and 1 Kibana server…

---

## [Storing APM data in custom/specific indices](https://discuss.elastic.co/t/storing-apm-data-in-custom-specific-indices/246381)

<div class="topic-metadata">

**Author:** [@axw](https://discuss.elastic.co/u/axw)\
**Replies:** 2\
**Last updated:** [January 26, 2023, 9:51am UTC](https://discuss.elastic.co/t/storing-apm-data-in-custom-specific-indices/246381 "2023-01-26T09:51:51Z")

</div>

If you'd like to split your APM indices by the service, you can use the advice from this topic. You can change the index name by setting either output.elasticsearch.index or output.elasticsearch.indices. These configura…

---

## [Elasticsearch and Kibana Zero SSL Certificate Issue](https://discuss.elastic.co/t/elasticsearch-and-kibana-zero-ssl-certificate-issue/324004)

<div class="topic-metadata">

**Author:** [@ali.sharjeel](https://discuss.elastic.co/u/ali.sharjeel)\
**Replies:** 0\
**Last updated:** [January 26, 2023, 9:10am UTC](https://discuss.elastic.co/t/elasticsearch-and-kibana-zero-ssl-certificate-issue/324004 "2023-01-26T09:10:59Z")

</div>

Hi Team! I am trying to install ZeroSSL certificate on Elasticsearch and Kibana node with the domain (www.secure-unified.tk). I have obtained the certificate from the ZeroSSL and got three files (private.key, certificate…

---

## [Is the logstash-plugins artifacts link correct?](https://discuss.elastic.co/t/is-the-logstash-plugins-artifacts-link-correct/323999)

<div class="topic-metadata">

**Author:** [@AlanChan](https://discuss.elastic.co/u/AlanChan)\
**Replies:** 0\
**Last updated:** [January 26, 2023, 8:16am UTC](https://discuss.elastic.co/t/is-the-logstash-plugins-artifacts-link-correct/323999 "2023-01-26T08:16:13Z")

</div>

Looking if package named: logstash-output-influxdb exists at https://artifacts.elastic.co/downloads/logstash-plugins/logstash-output-influxdb/logstash-output-influxdb-7.6.2.zip Net::OpenTimeout: execution expired …

---

## [Kibana Dashboard](https://discuss.elastic.co/t/kibana-dashboard/323970)

<div class="topic-metadata">

**Author:** [@suj0](https://discuss.elastic.co/u/suj0)\
**Replies:** 1\
**Last updated:** [January 26, 2023, 7:55am UTC](https://discuss.elastic.co/t/kibana-dashboard/323970 "2023-01-26T07:55:09Z")

</div>

Is there any way I can use the selected date and time range from date picker in the filter KQL

---

## [Visualization link output from watcher alert](https://discuss.elastic.co/t/visualization-link-output-from-watcher-alert/323960)

<div class="topic-metadata">

**Author:** [@Umar\_Farooq1](https://discuss.elastic.co/u/Umar_Farooq1)\
**Replies:** 1\
**Last updated:** [January 26, 2023, 7:50am UTC](https://discuss.elastic.co/t/visualization-link-output-from-watcher-alert/323960 "2023-01-26T07:50:54Z")

</div>

Hi there, I have many advanced based watchers setup which looks for various queries. when it alerts, we usually get our alerts on slack. I was wondering how can i add a link to it which will show me the specific data po…

---

## [Support of IAM for Elasticsearch Input plugin](https://discuss.elastic.co/t/support-of-iam-for-elasticsearch-input-plugin/323982)

<div class="topic-metadata">

**Author:** [@vijayalakshmi\_chanum](https://discuss.elastic.co/u/vijayalakshmi_chanum)\
**Replies:** 1\
**Last updated:** [January 26, 2023, 7:49am UTC](https://discuss.elastic.co/t/support-of-iam-for-elasticsearch-input-plugin/323982 "2023-01-26T07:49:04Z")

</div>

Do we have support for passing IAM credentials for logstash using Elasticsearch input plugin?

---

## [Elasticsearch templates](https://discuss.elastic.co/t/elasticsearch-templates/323984)

<div class="topic-metadata">

**Author:** [@cybersirp](https://discuss.elastic.co/u/cybersirp)\
**Replies:** 1\
**Last updated:** [January 26, 2023, 7:38am UTC](https://discuss.elastic.co/t/elasticsearch-templates/323984 "2023-01-26T07:38:04Z")

</div>

I notice that starting from elasticsearch 8.x everything has changed in relation to working with templates and I am very confused and I would like a Samaritan to help me solve this problem. curl -s -H "Content-type: app…

[Previous page](https://discuss.elastic.co/tag/none.md?no_tags=true&page=447)

[Next page](https://discuss.elastic.co/tag/none.md?no_tags=true&page=449)
