# \#none

**URL:** https://discuss.elastic.co/tag/none.md?no_tags=true&page=452

[Latest](https://discuss.elastic.co/latest.md) · [Categories](https://discuss.elastic.co/categories.md) · [Tags](https://discuss.elastic.co/tags.md)

**Page:** 453

---

## [Privileged containers should be avoided](https://discuss.elastic.co/t/privileged-containers-should-be-avoided/323382)

<div class="topic-metadata">

**Author:** [@ddhote](https://discuss.elastic.co/u/ddhote)\
**Replies:** 2\
**Last updated:** [January 20, 2023, 11:52am UTC](https://discuss.elastic.co/t/privileged-containers-should-be-avoided/323382 "2023-01-20T11:52:44Z")

</div>

Hello Team, We have Elasticsearch containers in AKS where initial container has "Privileged= True" which is against our security policy. But, init container is failing with "Privileged=False", can someone please help ho…

---

## [TSVB aggregation impossible](https://discuss.elastic.co/t/tsvb-aggregation-impossible/323586)

<div class="topic-metadata">

**Author:** [@NickLudd](https://discuss.elastic.co/u/NickLudd)\
**Replies:** 0\
**Last updated:** [January 20, 2023, 11:05am UTC](https://discuss.elastic.co/t/tsvb-aggregation-impossible/323586 "2023-01-20T11:05:03Z")

</div>

Hi all, I have created a TSVB visualization that represents thousands of operations(count aggregation & math aggregation grouped by filter) and a specific error(count aggregation filtered by query string), in a single c…

---

## [Alert recovery not triggering connector action](https://discuss.elastic.co/t/alert-recovery-not-triggering-connector-action/323584)

<div class="topic-metadata">

**Author:** [@RaJiska](https://discuss.elastic.co/u/RaJiska)\
**Replies:** 0\
**Last updated:** [January 20, 2023, 11:01am UTC](https://discuss.elastic.co/t/alert-recovery-not-triggering-connector-action/323584 "2023-01-20T11:01:11Z")

</div>

Hi, I am trying to have Kibana send active and recovered alerts into an index, however only active alerts get sent there while recovered alert do not generate an entry inside the index. The following configuration is u…

---

## [Indexing Kibana visualization](https://discuss.elastic.co/t/indexing-kibana-visualization/323568)

<div class="topic-metadata">

**Author:** [@Chirag\_Gupta](https://discuss.elastic.co/u/Chirag_Gupta)\
**Replies:** 5\
**Last updated:** [January 20, 2023, 9:57am UTC](https://discuss.elastic.co/t/indexing-kibana-visualization/323568 "2023-01-20T09:57:21Z")

</div>

Is there any method through which we can directly create a bar-graph with supplied data in spring code in kibana. Without using any kibana interface.

---

## [Grey out "elastic-agent" in login items in Ventura](https://discuss.elastic.co/t/grey-out-elastic-agent-in-login-items-in-ventura/323578)

<div class="topic-metadata">

**Author:** [@jadi](https://discuss.elastic.co/u/jadi)\
**Replies:** 0\
**Last updated:** [January 20, 2023, 9:49am UTC](https://discuss.elastic.co/t/grey-out-elastic-agent-in-login-items-in-ventura/323578 "2023-01-20T09:49:02Z")

</div>

Hey guys, Anyone managed to hide/grey out the "elastic-agent" that appears in login items in macOS Ventura? I created a service management profile with the bundleID "co.elastic.elastic-agent" but it's still doesn't wor…

---

## [Différence entre le Grok Debugger et le grok dans le filter](https://discuss.elastic.co/t/difference-entre-le-grok-debugger-et-le-grok-dans-le-filter/323507)

<div class="topic-metadata">

**Author:** [@martel](https://discuss.elastic.co/u/martel)\
**Replies:** 3\
**Last updated:** [January 20, 2023, 9:30am UTC](https://discuss.elastic.co/t/difference-entre-le-grok-debugger-et-le-grok-dans-le-filter/323507 "2023-01-20T09:30:15Z")

</div>

Bonjour, Je ne trouve pas la bonne manière de faire remplacer ce @timestamp par celui qui se trouve dans mon message. Le principe est simple 1 log = 1 ligne, c'est au format JSON {"startTime":"2023-01-17 14:17:50.238"…

---

## [Reading APM and Uptime data in C#](https://discuss.elastic.co/t/reading-apm-and-uptime-data-in-c/323575)

<div class="topic-metadata">

**Author:** [@basavaraja\_c\_n](https://discuss.elastic.co/u/basavaraja_c_n)\
**Replies:** 0\
**Last updated:** [January 20, 2023, 9:20am UTC](https://discuss.elastic.co/t/reading-apm-and-uptime-data-in-c/323575 "2023-01-20T09:20:15Z")

</div>

I want to read the uptime and APM services data in a C# Application, Not seeing any api's exposed or i am not getting how to read? Any clue??

---

## [Data loss without my consent](https://discuss.elastic.co/t/data-loss-without-my-consent/323319)

<div class="topic-metadata">

**Author:** [@smam](https://discuss.elastic.co/u/smam)\
**Replies:** 2\
**Last updated:** [January 20, 2023, 8:52am UTC](https://discuss.elastic.co/t/data-loss-without-my-consent/323319 "2023-01-20T08:52:41Z")

</div>

Hello, I have a logstash script that takes files as input and sends them to an according elasticsearch index. Said script is run at 1am every night as a scheduled task, which worked in the beginning.But now, every time …

---

## [Unable to use 2 fie log and 2 different index for them](https://discuss.elastic.co/t/unable-to-use-2-fie-log-and-2-different-index-for-them/323563)

<div class="topic-metadata">

**Author:** [@devdev7711](https://discuss.elastic.co/u/devdev7711)\
**Replies:** 0\
**Last updated:** [January 20, 2023, 5:39am UTC](https://discuss.elastic.co/t/unable-to-use-2-fie-log-and-2-different-index-for-them/323563 "2023-01-20T05:39:21Z")

</div>

below is my filebeat it is working fine for 1 log location and 1 index but i want to use 2 file log location and 2 diifferent index 1 index for 1 log path. how can we do this filebeat.inputs: type: log enabled: true …

---

## [Discard non-letter characters during Completion Suggestor indexing](https://discuss.elastic.co/t/discard-non-letter-characters-during-completion-suggestor-indexing/323561)

<div class="topic-metadata">

**Author:** [@vikk](https://discuss.elastic.co/u/vikk)\
**Replies:** 0\
**Last updated:** [January 20, 2023, 3:58am UTC](https://discuss.elastic.co/t/discard-non-letter-characters-during-completion-suggestor-indexing/323561 "2023-01-20T03:58:31Z")

</div>

Here's my index: PUT autocomplete-food { "mappings": { "properties": { "suggest": { "type": "completion" } } } } Adding a document to this index: PUT autocomplete-food/\_doc/1?refresh { …

---

## [How to get enrollment token when re-install Elasticsearch to Windows](https://discuss.elastic.co/t/how-to-get-enrollment-token-when-re-install-elasticsearch-to-windows/323314)

<div class="topic-metadata">

**Author:** [@oga](https://discuss.elastic.co/u/oga)\
**Replies:** 2\
**Last updated:** [January 20, 2023, 3:36am UTC](https://discuss.elastic.co/t/how-to-get-enrollment-token-when-re-install-elasticsearch-to-windows/323314 "2023-01-20T03:36:08Z")

</div>

When installing Elasticsarch8.6 on Windows, after runnning elasticsearch.bat I forgot to write down the enrollment token. To get the enrollment token,delete the elasticsearch directory and unzip the elasticsearch an…

---

## [Vulnerabilities Related to Java (in January 2023.)](https://discuss.elastic.co/t/vulnerabilities-related-to-java-in-january-2023/323557)

<div class="topic-metadata">

**Author:** [@its-ogawa](https://discuss.elastic.co/u/its-ogawa)\
**Replies:** 2\
**Last updated:** [January 20, 2023, 2:33am UTC](https://discuss.elastic.co/t/vulnerabilities-related-to-java-in-january-2023/323557 "2023-01-20T02:33:39Z")

</div>

Oracle released "Critical Patch Updates, Security Alerts and Bulletins" in January 2023. These include vulnerabilities involving Java. Is there any official word on the impact on Elastic products? cf.

---

## [How to do Calculation in Elasticsearch Query](https://discuss.elastic.co/t/how-to-do-calculation-in-elasticsearch-query/323496)

<div class="topic-metadata">

**Author:** [@yuswanul](https://discuss.elastic.co/u/yuswanul)\
**Replies:** 5\
**Last updated:** [January 20, 2023, 1:39am UTC](https://discuss.elastic.co/t/how-to-do-calculation-in-elasticsearch-query/323496 "2023-01-20T01:39:44Z")

</div>

Hi there, to continue discussion below, I decided to create a new topic. please read the topic below first so you can understand it. OK, so the next question is how if i use elasticsearch query to calculate expire dat…

---

## [Bool query with boost for should clause](https://discuss.elastic.co/t/bool-query-with-boost-for-should-clause/323555)

<div class="topic-metadata">

**Author:** [@seeminglee](https://discuss.elastic.co/u/seeminglee)\
**Replies:** 1\
**Last updated:** [January 20, 2023, 1:33am UTC](https://discuss.elastic.co/t/bool-query-with-boost-for-should-clause/323555 "2023-01-20T01:33:55Z")

</div>

How can you add boost to specific part of a should query. For example: { "query": { "bool": { "should": \[ {"term":{"fruit.keyword":"apple"}}, {"term":{"fruit.keyword":"banana"}}, {"te…

---

## [Custom code for pagination in Logstash](https://discuss.elastic.co/t/custom-code-for-pagination-in-logstash/323474)

<div class="topic-metadata">

**Author:** [@anik-27](https://discuss.elastic.co/u/anik-27)\
**Replies:** 2\
**Last updated:** [January 19, 2023, 11:00pm UTC](https://discuss.elastic.co/t/custom-code-for-pagination-in-logstash/323474 "2023-01-19T23:00:08Z")

</div>

Hello there ! I am fetching some data using the vRealize api, I want to add pagination using the custom code. which programming language can I use and how can I achieve this ? Can someone please help me with this !

---

## [Elastic fleet server fails to install after 8.6.0](https://discuss.elastic.co/t/elastic-fleet-server-fails-to-install-after-8-6-0/323063)

<div class="topic-metadata">

**Author:** [@PublicName](https://discuss.elastic.co/u/PublicName)\
**Replies:** 6\
**Last updated:** [January 19, 2023, 10:39pm UTC](https://discuss.elastic.co/t/elastic-fleet-server-fails-to-install-after-8-6-0/323063 "2023-01-19T22:39:23Z")

</div>

"Fleet Server - Waiting on fleet-server input to be added to default policy","ecs.version":"1.6.0"} {"log.level":"info","@timestamp":"2023-01-12T12:57:55.988-0800","log.origin":{"file.name":"cmd/enroll\_cmd.go","file.lin…

---

## [My cluster frequently has shards on initializing\_shards](https://discuss.elastic.co/t/my-cluster-frequently-has-shards-on-initializing-shards/323446)

<div class="topic-metadata">

**Author:** [@Lohanna\_Sarah](https://discuss.elastic.co/u/Lohanna_Sarah)\
**Replies:** 12\
**Last updated:** [January 19, 2023, 9:57pm UTC](https://discuss.elastic.co/t/my-cluster-frequently-has-shards-on-initializing-shards/323446 "2023-01-19T21:57:03Z")

</div>

My cluster frequently has shards in the initializing\_shards state. The cluster is running on ks8. Exists any fix that I could do to fix it? The data nodes are restarted at least once a day

---

## [Elastic Search for Frequent Location Updates](https://discuss.elastic.co/t/elastic-search-for-frequent-location-updates/323542)

<div class="topic-metadata">

**Author:** [@nsarvesh](https://discuss.elastic.co/u/nsarvesh)\
**Replies:** 0\
**Last updated:** [January 19, 2023, 7:32pm UTC](https://discuss.elastic.co/t/elastic-search-for-frequent-location-updates/323542 "2023-01-19T19:32:03Z")

</div>

Hi Team, We are planning to build a calendar application with Location-based Search Capabilities. We want to store the user availability and the geolocation. Eg: { User: "foo" day: "Jan-19-2022…

---

## [Reindex API: An unexpected authentication error occurred](https://discuss.elastic.co/t/reindex-api-an-unexpected-authentication-error-occurred/323538)

<div class="topic-metadata">

**Author:** [@Verdugo\_Gonzalo](https://discuss.elastic.co/u/Verdugo_Gonzalo)\
**Replies:** 0\
**Last updated:** [January 19, 2023, 6:39pm UTC](https://discuss.elastic.co/t/reindex-api-an-unexpected-authentication-error-occurred/323538 "2023-01-19T18:39:59Z")

</div>

Hello everyone, I'm trying to migrate an index from Cluster A to Cluster B using the Reindex from remote Add each ip segment in my whitelist in both cluster: reindex.remote.whitelist: \["123.176.49.\*:9200","123.188.49.…

---

## [Issues with Exception lists automatically combining rules](https://discuss.elastic.co/t/issues-with-exception-lists-automatically-combining-rules/323106)

<div class="topic-metadata">

**Author:** [@aforfot](https://discuss.elastic.co/u/aforfot)\
**Replies:** 5\
**Last updated:** [January 19, 2023, 6:39pm UTC](https://discuss.elastic.co/t/issues-with-exception-lists-automatically-combining-rules/323106 "2023-01-19T18:39:52Z")

</div>

When creating multiple Rules in Elastic Security we have started to notice an issue where exception list items created for one specific rule will also affect other rules. In our case the issue affects 2 specific rules th…

---

## [Elasticsearch windows server high split i/o and service restart](https://discuss.elastic.co/t/elasticsearch-windows-server-high-split-i-o-and-service-restart/323147)

<div class="topic-metadata">

**Author:** [@elastic101](https://discuss.elastic.co/u/elastic101)\
**Replies:** 4\
**Last updated:** [January 19, 2023, 4:39pm UTC](https://discuss.elastic.co/t/elasticsearch-windows-server-high-split-i-o-and-service-restart/323147 "2023-01-19T16:39:08Z")

</div>

Hello, We are using an app that has Elasticsearch database. The version is old and we are seeing a lot of issues lately. The split I/O increases to 50% + and the service becomes unresponsive. Below are the cluster detai…

---

## [Incorrect JSON logs parsing](https://discuss.elastic.co/t/incorrect-json-logs-parsing/323447)

<div class="topic-metadata">

**Author:** [@ira-zaya](https://discuss.elastic.co/u/ira-zaya)\
**Replies:** 1\
**Last updated:** [January 19, 2023, 3:46pm UTC](https://discuss.elastic.co/t/incorrect-json-logs-parsing/323447 "2023-01-19T15:46:25Z")

</div>

Hi. I have json format logs, looks like this: { "dt":"2023-01-18T17:41:04.8723262+00:00", "tz":"Etc/UTC", "host":"host-name", "containerName":"container-name", "level":"INFO", "scope":"Web API", "message":"exitin…

---

## [Importing dashboards using kibana api through curl](https://discuss.elastic.co/t/importing-dashboards-using-kibana-api-through-curl/323320)

<div class="topic-metadata">

**Author:** [@Aniket\_Pant](https://discuss.elastic.co/u/Aniket_Pant)\
**Replies:** 3\
**Last updated:** [January 19, 2023, 3:29pm UTC](https://discuss.elastic.co/t/importing-dashboards-using-kibana-api-through-curl/323320 "2023-01-19T15:29:14Z")

</div>

Hi Community, I want to import metricbeat dashboard , but i can't find the id. ELK version 7.17 command used curl -u user:pass -k -X POST "https://localhost:5601/api/saved\_objects/\_export -H 'kbn-xsrf: true' -H 'Cont…

---

## [No config file found - help me pleaseee](https://discuss.elastic.co/t/no-config-file-found-help-me-pleaseee/323521)

<div class="topic-metadata">

**Author:** [@Jonathan\_Or](https://discuss.elastic.co/u/Jonathan_Or)\
**Replies:** 1\
**Last updated:** [January 19, 2023, 2:33pm UTC](https://discuss.elastic.co/t/no-config-file-found-help-me-pleaseee/323521 "2023-01-19T14:33:01Z")

</div>

hey , i have a problem with my logstash thats running on my ubuntu 18.04 machine. when i run journalctl -u logstash it presents one error that says that no config file found in path etc/log..... but when i go to conf…

---

## [How i can rename dynamical fields](https://discuss.elastic.co/t/how-i-can-rename-dynamical-fields/323321)

<div class="topic-metadata">

**Author:** [@Glad](https://discuss.elastic.co/u/Glad)\
**Replies:** 3\
**Last updated:** [January 19, 2023, 1:55pm UTC](https://discuss.elastic.co/t/how-i-can-rename-dynamical-fields/323321 "2023-01-19T13:55:46Z")

</div>

Hello, I would like some help with my little problem. I would like to be able to automatically rename fields that I get with my snmp plugin in input. I obtain this result: "host" =\> \[ \[1\] { "iso...hrProcessorLoa…

---

## [Dsl Query - calculate incidence in percentage (%) or bucket\_script](https://discuss.elastic.co/t/dsl-query-calculate-incidence-in-percentage-or-bucket-script/323501)

<div class="topic-metadata">

**Author:** [@SalvoDM91](https://discuss.elastic.co/u/SalvoDM91)\
**Replies:** 0\
**Last updated:** [January 19, 2023, 11:24am UTC](https://discuss.elastic.co/t/dsl-query-calculate-incidence-in-percentage-or-bucket-script/323501 "2023-01-19T11:24:21Z")

</div>

Hi guys, I've a sample dataset with 3 columns (ID, ACTION and AMOUNT): I would like to create a DSL query in order to check minute by minute: number of documents with ACTION = "purchase" (paramA) number of documen…

---

## [I get no data from Elastic via asp.net core](https://discuss.elastic.co/t/i-get-no-data-from-elastic-via-asp-net-core/323515)

<div class="topic-metadata">

**Author:** [@fozgul](https://discuss.elastic.co/u/fozgul)\
**Replies:** 0\
**Last updated:** [January 19, 2023, 12:54pm UTC](https://discuss.elastic.co/t/i-get-no-data-from-elastic-via-asp-net-core/323515 "2023-01-19T12:54:57Z")

</div>

My Elastic server(7.16.2) is running on an on-prem server with certain Ip. (Free version) I have the following setup for client creation in asp.net core: var pool = new SingleNodeConnectionPool(new Uri("http://username…

---

## [Complex queries inside nested fields](https://discuss.elastic.co/t/complex-queries-inside-nested-fields/323514)

<div class="topic-metadata">

**Author:** [@Hemabh\_Ravee\_Fox](https://discuss.elastic.co/u/Hemabh_Ravee_Fox)\
**Replies:** 0\
**Last updated:** [January 19, 2023, 12:51pm UTC](https://discuss.elastic.co/t/complex-queries-inside-nested-fields/323514 "2023-01-19T12:51:32Z")

</div>

I have some documents which contain a nested field planList which is an array of objects. It's length will always be 2 or 3. And the objects always have 3 keys - planName, planType, and planId. I want to write a query w…

---

## [Multiple logstash instances listening to the same redis channel](https://discuss.elastic.co/t/multiple-logstash-instances-listening-to-the-same-redis-channel/323506)

<div class="topic-metadata">

**Author:** [@trondhindenes](https://discuss.elastic.co/u/trondhindenes)\
**Replies:** 1\
**Last updated:** [January 19, 2023, 12:33pm UTC](https://discuss.elastic.co/t/multiple-logstash-instances-listening-to-the-same-redis-channel/323506 "2023-01-19T12:33:21Z")

</div>

We're using redis to pass data between logstash instances. I have 2 logstash instances currently with the same config: input { redis { data\_type =\> "channel" host =\> "${REDIS\_HOST}" key =\> "l…

---

## [Customise the field that a option list is applied to](https://discuss.elastic.co/t/customise-the-field-that-a-option-list-is-applied-to/322950)

<div class="topic-metadata">

**Author:** [@Jan\_De\_Smet](https://discuss.elastic.co/u/Jan_De_Smet)\
**Replies:** 2\
**Last updated:** [January 19, 2023, 12:20pm UTC](https://discuss.elastic.co/t/customise-the-field-that-a-option-list-is-applied-to/322950 "2023-01-19T12:20:15Z")

</div>

Hi, I have a data set containing containing objects in the following format: { "id": 123, "displayName": "foo" } I would like to use this to populate an option list. It is important that the user only sees the dis…

[Previous page](https://discuss.elastic.co/tag/none.md?no_tags=true&page=451)

[Next page](https://discuss.elastic.co/tag/none.md?no_tags=true&page=453)
