# \#none

**URL:** https://discuss.elastic.co/tag/none.md?no_tags=true&page=450

[Latest](https://discuss.elastic.co/latest.md) · [Categories](https://discuss.elastic.co/categories.md) · [Tags](https://discuss.elastic.co/tags.md)

**Page:** 451

---

## [Setting sameSiteCookies to None while kibana being behind a reverse proxy](https://discuss.elastic.co/t/setting-samesitecookies-to-none-while-kibana-being-behind-a-reverse-proxy/323877)

<div class="topic-metadata">

**Author:** [@vangap](https://discuss.elastic.co/u/vangap)\
**Replies:** 0\
**Last updated:** [January 25, 2023, 3:58am UTC](https://discuss.elastic.co/t/setting-samesitecookies-to-none-while-kibana-being-behind-a-reverse-proxy/323877 "2023-01-25T03:58:03Z")

</div>

I have kibana running with SSL disabled and a reverse proxy (nginx) to do the SSL termination. I also have xpack.security.sameSiteCookies: "None" which seems ot be causing issues with below error. Is there a way to tel…

---

## [\_size field (mapper size plugin)](https://discuss.elastic.co/t/size-field-mapper-size-plugin/323863)

<div class="topic-metadata">

**Author:** [@nikssssss](https://discuss.elastic.co/u/nikssssss)\
**Replies:** 0\
**Last updated:** [January 24, 2023, 6:03pm UTC](https://discuss.elastic.co/t/size-field-mapper-size-plugin/323863 "2023-01-24T18:03:15Z")

</div>

Hi all, as i understand when we enable this feature (mapper size plugin) the \_size meta field is not a new field in the index but a field on kibana index patern, correct? Because i can see the \_size field on kibana disc…

---

## [How to set a value in timestamp](https://discuss.elastic.co/t/how-to-set-a-value-in-timestamp/323762)

<div class="topic-metadata">

**Author:** [@mariana17](https://discuss.elastic.co/u/mariana17)\
**Replies:** 6\
**Last updated:** [January 24, 2023, 5:22pm UTC](https://discuss.elastic.co/t/how-to-set-a-value-in-timestamp/323762 "2023-01-24T17:22:13Z")

</div>

I have two values as my date and hour data and i want them to be my timestamp: "F-MESSAGE-CAB": "20221018","H-MESSAGE-CAB": "601006" "F-MESSAGE-CAB": "20221018","H-MESSAGE-CAB": "1338311" What i'm trying to do is putt…

---

## [Cannot deploy eck elasticsearch cluster after successful operator install](https://discuss.elastic.co/t/cannot-deploy-eck-elasticsearch-cluster-after-successful-operator-install/323861)

<div class="topic-metadata">

**Author:** [@levon.tumanyan](https://discuss.elastic.co/u/levon.tumanyan)\
**Replies:** 2\
**Last updated:** [January 24, 2023, 5:10pm UTC](https://discuss.elastic.co/t/cannot-deploy-eck-elasticsearch-cluster-after-successful-operator-install/323861 "2023-01-24T17:10:44Z")

</div>

Hi All, As mentioned I am trying to deploy eck elasticsearch through a manifest install. No helm used. It is failing on the first init container with the following message: bash: /mnt/elastic-internal/scripts/prepare-…

---

## [Logstash log](https://discuss.elastic.co/t/logstash-log/323775)

<div class="topic-metadata">

**Author:** [@kadamik](https://discuss.elastic.co/u/kadamik)\
**Replies:** 1\
**Last updated:** [January 24, 2023, 5:02pm UTC](https://discuss.elastic.co/t/logstash-log/323775 "2023-01-24T17:02:35Z")

</div>

I have having trouble getting logstash and elasticsearch setup. I have my rsyslog server sending my logs from my Unifi UDM device. I have it setup for the most-part but the problem is how logstash is trasforming the l…

---

## [Unable to install Fleet on 8.6.0](https://discuss.elastic.co/t/unable-to-install-fleet-on-8-6-0/323528)

<div class="topic-metadata">

**Author:** [@gyterpena](https://discuss.elastic.co/u/gyterpena)\
**Replies:** 1\
**Last updated:** [January 24, 2023, 3:19pm UTC](https://discuss.elastic.co/t/unable-to-install-fleet-on-8-6-0/323528 "2023-01-24T15:19:49Z")

</div>

Hello I'm unable to install/initiate fleet on our kibana. I get below error message Debug logs for plugin.fleet {"service":{"node":{"roles":\["background\_tasks","ui"\]}},"ecs":{"version":"8.4.0"},"@timestamp":"2023-01…

---

## [Mapper \[signal.ancestors.index\] cannot be changed from type \[text\] to \[keyword\]](https://discuss.elastic.co/t/mapper-signal-ancestors-index-cannot-be-changed-from-type-text-to-keyword/323331)

<div class="topic-metadata">

**Author:** [@Enrico\_Pasqualotto](https://discuss.elastic.co/u/Enrico_Pasqualotto)\
**Replies:** 8\
**Last updated:** [January 24, 2023, 2:13pm UTC](https://discuss.elastic.co/t/mapper-signal-ancestors-index-cannot-be-changed-from-type-text-to-keyword/323331 "2023-01-24T14:13:03Z")

</div>

Hello, probably after an upgrade (current ver. 7.17.6) every time we accesso to alerts/rules of Security section we got the following error: { "name": "Error", "body": { "message": "illegal\_argument\_exception: mapper…

---

## [Logstash, query not executing inside of the elasticsearch input plugin](https://discuss.elastic.co/t/logstash-query-not-executing-inside-of-the-elasticsearch-input-plugin/323655)

<div class="topic-metadata">

**Author:** [@mohsin106](https://discuss.elastic.co/u/mohsin106)\
**Replies:** 4\
**Last updated:** [January 24, 2023, 1:41pm UTC](https://discuss.elastic.co/t/logstash-query-not-executing-inside-of-the-elasticsearch-input-plugin/323655 "2023-01-24T13:41:08Z")

</div>

Hi, I have a logstash pipeline where I'm reading data in from Kafka and then inside of the filter plugin I have a conditional to call the elasticsearch input plugin if a certain condition is met. The condition: If ser…

---

## [Missing Legend Entries](https://discuss.elastic.co/t/missing-legend-entries/322625)

<div class="topic-metadata">

**Author:** [@acbiccy](https://discuss.elastic.co/u/acbiccy)\
**Replies:** 3\
**Last updated:** [January 24, 2023, 12:54pm UTC](https://discuss.elastic.co/t/missing-legend-entries/322625 "2023-01-24T12:54:21Z")

</div>

Hi Everyone I have a report that has approximately 200 legend entries, however the screen only displays around 25. I have tried moving the legend position but above and below give even less entries. I have tried diffe…

---

## [Kibana Dashboard is not getting updated with latest data](https://discuss.elastic.co/t/kibana-dashboard-is-not-getting-updated-with-latest-data/323303)

<div class="topic-metadata">

**Author:** [@vidvar](https://discuss.elastic.co/u/vidvar)\
**Replies:** 19\
**Last updated:** [January 24, 2023, 12:38pm UTC](https://discuss.elastic.co/t/kibana-dashboard-is-not-getting-updated-with-latest-data/323303 "2023-01-24T12:38:09Z")

</div>

In our Kibana, dashboards are not getting displayed the latest data from Nov 04, 2022 and we could see below logs snippets at kibana.log. Could someone please assist what is missing here. {"type":"log","@timestamp":"20…

---

## [Get random record using must\_not](https://discuss.elastic.co/t/get-random-record-using-must-not/323786)

<div class="topic-metadata">

**Author:** [@sphawk](https://discuss.elastic.co/u/sphawk)\
**Replies:** 4\
**Last updated:** [January 24, 2023, 12:20pm UTC](https://discuss.elastic.co/t/get-random-record-using-must-not/323786 "2023-01-24T12:20:36Z")

</div>

hello again I need to get a random record excluding some values using must\_not directive. this is the query i've created using some online post. { "index": "articles", "body": { "size": 1, …

---

## [Watcher and python client (8.6)](https://discuss.elastic.co/t/watcher-and-python-client-8-6/323811)

<div class="topic-metadata">

**Author:** [@MalfuncEddie](https://discuss.elastic.co/u/MalfuncEddie)\
**Replies:** 0\
**Last updated:** [January 24, 2023, 11:17am UTC](https://discuss.elastic.co/t/watcher-and-python-client-8-6/323811 "2023-01-24T11:17:21Z")

</div>

Hi, I was hoping someone can help me get started using the python client form elastic. Background: I just upgrades to 8.6 and e python script that reads .watches does not work anymore. results = es.search(size = 200,…

---

## [FSCrawler Rest with Elasticsearch](https://discuss.elastic.co/t/fscrawler-rest-with-elasticsearch/323803)

<div class="topic-metadata">

**Author:** [@Johnson\_F](https://discuss.elastic.co/u/Johnson_F)\
**Replies:** 4\
**Last updated:** [January 24, 2023, 11:09am UTC](https://discuss.elastic.co/t/fscrawler-rest-with-elasticsearch/323803 "2023-01-24T11:09:36Z")

</div>

Dear All, I had configured fscrawler 2.10 on ubuntu which works great, got some minor issues: - a. why touch is required? i can understand timestamp has to be new on copied or uploaded files in directory so fscrawler l…

---

## [Custom pattern in grok debugger](https://discuss.elastic.co/t/custom-pattern-in-grok-debugger/323805)

<div class="topic-metadata">

**Author:** [@ira-zaya](https://discuss.elastic.co/u/ira-zaya)\
**Replies:** 1\
**Last updated:** [January 24, 2023, 10:49am UTC](https://discuss.elastic.co/t/custom-pattern-in-grok-debugger/323805 "2023-01-24T10:49:08Z")

</div>

Hi I'm trying to set up a grok filter for custom logs, look like this: 2023-01-20 00:00:05.235+0000 \[L: DEBUG\] \[O: S.c.t.d.e.DSLScript\] \[I: \] \[U: Administrator\] \[S: \] \[P: \] \[T: TWEventProcessor-3\] @@@ Property Write Que…

---

## [Elasticsearch search by part of a word](https://discuss.elastic.co/t/elasticsearch-search-by-part-of-a-word/323748)

<div class="topic-metadata">

**Author:** [@maks1](https://discuss.elastic.co/u/maks1)\
**Replies:** 3\
**Last updated:** [January 24, 2023, 9:37am UTC](https://discuss.elastic.co/t/elasticsearch-search-by-part-of-a-word/323748 "2023-01-24T09:37:38Z")

</div>

Hello. Could you help me? There is an ELK cluster (version 5) and through kibana I execute a query for a part of a word using a wildcard, for example, examp\*, but nothing is found. If I search for the whole word example,…

---

## [Query\_string using special character work and dont work without escaping](https://discuss.elastic.co/t/query-string-using-special-character-work-and-dont-work-without-escaping/323794)

<div class="topic-metadata">

**Author:** [@eladonline](https://discuss.elastic.co/u/eladonline)\
**Replies:** 0\
**Last updated:** [January 24, 2023, 8:17am UTC](https://discuss.elastic.co/t/query-string-using-special-character-work-and-dont-work-without-escaping/323794 "2023-01-24T08:17:57Z")

</div>

Hey, what is the diferent that the first works and the others does not? GET /forensics/\_search { "query": { "query\_string": { "fields": \["referer"\], "query": "http://10.26.30.206\*" // but these doe…

---

## [Can not get details of ELK stack monitoring](https://discuss.elastic.co/t/can-not-get-details-of-elk-stack-monitoring/323731)

<div class="topic-metadata">

**Author:** [@Kosala\_Randika\_Paran](https://discuss.elastic.co/u/Kosala_Randika_Paran)\
**Replies:** 4\
**Last updated:** [January 24, 2023, 8:54am UTC](https://discuss.elastic.co/t/can-not-get-details-of-elk-stack-monitoring/323731 "2023-01-24T08:54:37Z")

</div>

Hi, Suddenly I got this error "Monitoring Request Error Connection error: Check the Elasticsearch Monitoring cluster network connection and refer to the Kibana logs for more information. HTTP 503" What would be the…

---

## [Field type changed results in a conflict - kibana reports an error](https://discuss.elastic.co/t/field-type-changed-results-in-a-conflict-kibana-reports-an-error/322970)

<div class="topic-metadata">

**Author:** [@mayer](https://discuss.elastic.co/u/mayer)\
**Replies:** 2\
**Last updated:** [January 24, 2023, 8:51am UTC](https://discuss.elastic.co/t/field-type-changed-results-in-a-conflict-kibana-reports-an-error/322970 "2023-01-24T08:51:09Z")

</div>

Dear All, from a firewall I send log information to filebeat into a self written module. Within a kibana dashboard I have several lenses to get information of different events and aggregations. This is now running sever…

---

## [Not able to parse logs while parsing mix json objects](https://discuss.elastic.co/t/not-able-to-parse-logs-while-parsing-mix-json-objects/323494)

<div class="topic-metadata">

**Author:** [@abhishek1111](https://discuss.elastic.co/u/abhishek1111)\
**Replies:** 8\
**Last updated:** [January 24, 2023, 8:17am UTC](https://discuss.elastic.co/t/not-able-to-parse-logs-while-parsing-mix-json-objects/323494 "2023-01-24T08:17:08Z")

</div>

Could someone please help me with parsing below mix json logs tried multiple ways of parsing it, but nothing has helped. Logs {"log":"\[GIN\] 2023/01/19 - 08:14:32 | 200 | 5.595393ms | 10.164.30.231 | POST "/api…

---

## [Logstash Module](https://discuss.elastic.co/t/logstash-module/323715)

<div class="topic-metadata">

**Author:** [@Adedolapo\_Okunsanmi](https://discuss.elastic.co/u/Adedolapo_Okunsanmi)\
**Replies:** 3\
**Last updated:** [January 24, 2023, 7:44am UTC](https://discuss.elastic.co/t/logstash-module/323715 "2023-01-24T07:44:50Z")

</div>

Hi Guys, I use the Cloud-Based Elastic/Kibana. I would like to know if there is a difference between Logstash module in Filebeats and Logstash installed directly on server,

---

## [How do we get scroll up/down option on Controls (Filters)](https://discuss.elastic.co/t/how-do-we-get-scroll-up-down-option-on-controls-filters/323720)

<div class="topic-metadata">

**Author:** [@Abj\_Ins](https://discuss.elastic.co/u/Abj_Ins)\
**Replies:** 2\
**Last updated:** [January 24, 2023, 6:52am UTC](https://discuss.elastic.co/t/how-do-we-get-scroll-up-down-option-on-controls-filters/323720 "2023-01-24T06:52:35Z")

</div>

Hi Team, We created one control having total 20 options, but its showing only 10 (It's not showing any scroll bar also). But, we are expecting here to view all 20 available options or at least scroll up/down. Please fin…

---

## [Import \`integer\_range\` from CSV with kibana \`Visualize data from a file\`?](https://discuss.elastic.co/t/import-integer-range-from-csv-with-kibana-visualize-data-from-a-file/323765)

<div class="topic-metadata">

**Author:** [@learningelastic](https://discuss.elastic.co/u/learningelastic)\
**Replies:** 1\
**Last updated:** [January 24, 2023, 2:00am UTC](https://discuss.elastic.co/t/import-integer-range-from-csv-with-kibana-visualize-data-from-a-file/323765 "2023-01-24T02:00:55Z")

</div>

Is it possible for the Machine Learning\>Data Visualizer\>Visualize data from file to import a csv file where one of the columns is an integer\_range? If so, what is the syntax that should be used in the integer\_range colu…

---

## [Aggregation of sums instead of sum of aggregation](https://discuss.elastic.co/t/aggregation-of-sums-instead-of-sum-of-aggregation/323751)

<div class="topic-metadata">

**Author:** [@rxtx](https://discuss.elastic.co/u/rxtx)\
**Replies:** 0\
**Last updated:** [January 23, 2023, 5:04pm UTC](https://discuss.elastic.co/t/aggregation-of-sums-instead-of-sum-of-aggregation/323751 "2023-01-23T17:04:46Z")

</div>

I'm trying to figure out if I can aggregate something by the sum of a value field rather than the number of value fields. I have an events index The events has the following fields: property\_id, name, value, timestamp I…

---

## [Elastic agent integration stuck on upgrade | fleet affected](https://discuss.elastic.co/t/elastic-agent-integration-stuck-on-upgrade-fleet-affected/322447)

<div class="topic-metadata">

**Author:** [@theacodes](https://discuss.elastic.co/u/theacodes)\
**Replies:** 4\
**Last updated:** [January 23, 2023, 4:44pm UTC](https://discuss.elastic.co/t/elastic-agent-integration-stuck-on-upgrade-fleet-affected/322447 "2023-01-23T16:44:10Z")

</div>

any idea how to stop the update process or update it properly

---

## [Reindexing of old v.6 index keeps stopping with reason kibana was restarted](https://discuss.elastic.co/t/reindexing-of-old-v-6-index-keeps-stopping-with-reason-kibana-was-restarted/323749)

<div class="topic-metadata">

**Author:** [@teesr5](https://discuss.elastic.co/u/teesr5)\
**Replies:** 0\
**Last updated:** [January 23, 2023, 4:05pm UTC](https://discuss.elastic.co/t/reindexing-of-old-v-6-index-keeps-stopping-with-reason-kibana-was-restarted/323749 "2023-01-23T16:05:46Z")

</div>

Hi, we're preparing to upgrade from v.7.10.0, the elk stack is running on an Ubuntu cluster with 3 nodes, although we have an index which we have to prepare for the upgrade, it keeps on looping: Details \[some\]-alias …

---

## [Remote Connection to Elastic](https://discuss.elastic.co/t/remote-connection-to-elastic/323732)

<div class="topic-metadata">

**Author:** [@Patryk\_Ostrowski](https://discuss.elastic.co/u/Patryk_Ostrowski)\
**Replies:** 0\
**Last updated:** [January 23, 2023, 1:49pm UTC](https://discuss.elastic.co/t/remote-connection-to-elastic/323732 "2023-01-23T13:49:58Z")

</div>

Hello, I have problem, and I cannot find solution of my problem. I have standalone Elasticsearch on 10.1.251.1, and hosts (Ubuntu 20) with Suricata on 10.2.251.5 and 10.1.251.5. When I try connect fro 10.1.251.1 to my e…

---

## [Problem when changing resources](https://discuss.elastic.co/t/problem-when-changing-resources/323408)

<div class="topic-metadata">

**Author:** [@ccaillet](https://discuss.elastic.co/u/ccaillet)\
**Replies:** 5\
**Last updated:** [January 23, 2023, 1:44pm UTC](https://discuss.elastic.co/t/problem-when-changing-resources/323408 "2023-01-23T13:44:28Z")

</div>

Hi all, When I change resources like cpu and memory on limits ECK does nothing, the only way for me to have the sts to be update with my changes is to edit the sts manifest with kubectl edit for applying new values to t…

---

## [Update\_by\_query](https://discuss.elastic.co/t/update-by-query/323730)

<div class="topic-metadata">

**Author:** [@Srujan](https://discuss.elastic.co/u/Srujan)\
**Replies:** 0\
**Last updated:** [January 23, 2023, 1:06pm UTC](https://discuss.elastic.co/t/update-by-query/323730 "2023-01-23T13:06:58Z")

</div>

I am new to Elasticsearch. I have a huge index with around 50k documents. I have to update all the document, when I run the update\_by\_query function it is throwing an error Traceback (most recent call last): File "E:\\A…

---

## [How to configure Cluster Filter - Cluster Name](https://discuss.elastic.co/t/how-to-configure-cluster-filter-cluster-name/323725)

<div class="topic-metadata">

**Author:** [@Swathi12](https://discuss.elastic.co/u/Swathi12)\
**Replies:** 0\
**Last updated:** [January 23, 2023, 12:31pm UTC](https://discuss.elastic.co/t/how-to-configure-cluster-filter-cluster-name/323725 "2023-01-23T12:31:25Z")

</div>

Hello, i am just find out how to configure the Cluster Filter here. Does anyone can help me ?

---

## [Haystack US 2023, The Search Relevance Conference - Dates & Call for Presentations - We need your talks!](https://discuss.elastic.co/t/haystack-us-2023-the-search-relevance-conference-dates-call-for-presentations-we-need-your-talks/323723)

<div class="topic-metadata">

**Author:** [@flaxsearch](https://discuss.elastic.co/u/flaxsearch)\
**Replies:** 0\
**Last updated:** [January 23, 2023, 11:47am UTC](https://discuss.elastic.co/t/haystack-us-2023-the-search-relevance-conference-dates-call-for-presentations-we-need-your-talks/323723 "2023-01-23T11:47:40Z")

</div>

Hi all, We've got exciting plans for this year's Haystack US - come and join us in Charlottesville, VA for a week of fun with the search community: Start with a Search Meetup the evening of Monday 24th April Main conf…

[Previous page](https://discuss.elastic.co/tag/none.md?no_tags=true&page=449)

[Next page](https://discuss.elastic.co/tag/none.md?no_tags=true&page=451)
