# \#none

**URL:** https://discuss.elastic.co/tag/none.md?no_tags=true&page=456

[Latest](https://discuss.elastic.co/latest.md) · [Categories](https://discuss.elastic.co/categories.md) · [Tags](https://discuss.elastic.co/tags.md)

**Page:** 457

---

## [Logstash horizontal autoscaling](https://discuss.elastic.co/t/logstash-horizontal-autoscaling/323256)

<div class="topic-metadata">

**Author:** [@yuvalweber](https://discuss.elastic.co/u/yuvalweber)\
**Replies:** 0\
**Last updated:** [January 16, 2023, 2:10pm UTC](https://discuss.elastic.co/t/logstash-horizontal-autoscaling/323256 "2023-01-16T14:10:50Z")

</div>

I want to create autoscaling for our logstash based on prometheus queries we have from the api of logstash. I am using Persistent Queue has a way for backing up our messages in case of disaster and I thought that based …

---

## [Coremigration error while importing dashboards from dev instance to prod instance](https://discuss.elastic.co/t/coremigration-error-while-importing-dashboards-from-dev-instance-to-prod-instance/323239)

<div class="topic-metadata">

**Author:** [@krishnaabylle](https://discuss.elastic.co/u/krishnaabylle)\
**Replies:** 2\
**Last updated:** [January 16, 2023, 2:08pm UTC](https://discuss.elastic.co/t/coremigration-error-while-importing-dashboards-from-dev-instance-to-prod-instance/323239 "2023-01-16T14:08:13Z")

</div>

Hi everyone Can anyone help me with this error.We have a dev and prod instance.i exported one dashboard in dev and While migrating dashboard from dev instance to prod instane getting the error as …

---

## [Winlogbeat to Logstash over SSL](https://discuss.elastic.co/t/winlogbeat-to-logstash-over-ssl/322705)

<div class="topic-metadata">

**Author:** [@Mark\_Marais](https://discuss.elastic.co/u/Mark_Marais)\
**Replies:** 11\
**Last updated:** [January 16, 2023, 1:56pm UTC](https://discuss.elastic.co/t/winlogbeat-to-logstash-over-ssl/322705 "2023-01-16T13:56:11Z")

</div>

Good day, Can someone assist me with a secure connection from my beats to my logstash instances. Thanks.

---

## [Query dsl span\_or vs bool should](https://discuss.elastic.co/t/query-dsl-span-or-vs-bool-should/323254)

<div class="topic-metadata">

**Author:** [@IvanTushin](https://discuss.elastic.co/u/IvanTushin)\
**Replies:** 0\
**Last updated:** [January 16, 2023, 1:34pm UTC](https://discuss.elastic.co/t/query-dsl-span-or-vs-bool-should/323254 "2023-01-16T13:34:13Z")

</div>

Hi! I have two "span\_near" queries. What's the difference between bool-\>should and span\_or? Does it affect on "index.query.bool.max\_clause\_count" limit or query performance? { "span\_or": { "clauses": \[ …

---

## [Kibana REST API for integrations setup](https://discuss.elastic.co/t/kibana-rest-api-for-integrations-setup/322151)

<div class="topic-metadata">

**Author:** [@OlLap](https://discuss.elastic.co/u/OlLap)\
**Replies:** 16\
**Last updated:** [January 16, 2023, 12:49pm UTC](https://discuss.elastic.co/t/kibana-rest-api-for-integrations-setup/322151 "2023-01-16T12:49:24Z")

</div>

Hello, I have installed Elastic stack using ECK (Elasticsearch, Kibana, Beats, APM Server + agents), and trying to automate setup moving manual configuration steps to Kubernetes jobs that use Elasticsearch REST API. Bu…

---

## [Elasticearch and Power BI](https://discuss.elastic.co/t/elasticearch-and-power-bi/323250)

<div class="topic-metadata">

**Author:** [@palko.balazs](https://discuss.elastic.co/u/palko.balazs)\
**Replies:** 0\
**Last updated:** [January 16, 2023, 12:35pm UTC](https://discuss.elastic.co/t/elasticearch-and-power-bi/323250 "2023-01-16T12:35:02Z")

</div>

Hi, I'm trying to import our data stored in Elasticsearch into a BI Tool. I tried Power BI with ODBC using this guide and this guide for Tableau. I was able to get our data into both PowerBi and Tableau, however I'm st…

---

## [Need proper example and resource for xml filter plugin](https://discuss.elastic.co/t/need-proper-example-and-resource-for-xml-filter-plugin/323087)

<div class="topic-metadata">

**Author:** [@Nikhil27](https://discuss.elastic.co/u/Nikhil27)\
**Replies:** 3\
**Last updated:** [January 16, 2023, 12:25pm UTC](https://discuss.elastic.co/t/need-proper-example-and-resource-for-xml-filter-plugin/323087 "2023-01-16T12:25:38Z")

</div>

I want to parse unstructured xml log data.I am not getting any proper resource for reference.The xml filter plugin documentation is not that able to sort my problem. I am new to the ELK please help me out of this....

---

## [Using wildcard and must\_not to search](https://discuss.elastic.co/t/using-wildcard-and-must-not-to-search/323236)

<div class="topic-metadata">

**Author:** [@geeky\_human](https://discuss.elastic.co/u/geeky_human)\
**Replies:** 1\
**Last updated:** [January 16, 2023, 11:12am UTC](https://discuss.elastic.co/t/using-wildcard-and-must-not-to-search/323236 "2023-01-16T11:12:27Z")

</div>

Hi, I’m new to ELK. For searching, I’m using dev tools in kibana. I want to find all the results that do not match a wildcard term. "must\_not": \[ {"wildcard": { "agent.keyword": {"value":"python\*"} }}\] I…

---

## [Please keep the old expand document, the new "pop-out" makes everything slow](https://discuss.elastic.co/t/please-keep-the-old-expand-document-the-new-pop-out-makes-everything-slow/322941)

<div class="topic-metadata">

**Author:** [@blommis](https://discuss.elastic.co/u/blommis)\
**Replies:** 6\
**Last updated:** [January 16, 2023, 10:54am UTC](https://discuss.elastic.co/t/please-keep-the-old-expand-document-the-new-pop-out-makes-everything-slow/322941 "2023-01-16T10:54:30Z")

</div>

We just upgraded version and expanding a document in the table is now in a popup covering halv the screen. Before this change it was shown as more details below every row, making it possible to view details on multiple …

---

## [Elasticsearch DSL Query - Field is not null or not empty](https://discuss.elastic.co/t/elasticsearch-dsl-query-field-is-not-null-or-not-empty/323005)

<div class="topic-metadata">

**Author:** [@Java2avaj](https://discuss.elastic.co/u/Java2avaj)\
**Replies:** 8\
**Last updated:** [January 16, 2023, 10:49am UTC](https://discuss.elastic.co/t/elasticsearch-dsl-query-field-is-not-null-or-not-empty/323005 "2023-01-16T10:49:18Z")

</div>

I have an existing DSL query that needs to modify such that the id "12345" should be not null or not empty: { "bool":{ "must":\[ { "bool":{ "should":\[ { …

---

## [This node is locked](https://discuss.elastic.co/t/this-node-is-locked/323040)

<div class="topic-metadata">

**Author:** [@Randomize](https://discuss.elastic.co/u/Randomize)\
**Replies:** 11\
**Last updated:** [January 16, 2023, 10:25am UTC](https://discuss.elastic.co/t/this-node-is-locked/323040 "2023-01-16T10:25:02Z")

</div>

Hello I updated elasticsearch to version 8.4.1 Now im trying to start elasticsearch using discovery.type: single-node in config file. But its does not starting. I can see status activating in systemctl status. In elast…

---

## [Problems deploying ECK on k8 v1.23.10](https://discuss.elastic.co/t/problems-deploying-eck-on-k8-v1-23-10/323129)

<div class="topic-metadata">

**Author:** [@Dennis\_Christensen](https://discuss.elastic.co/u/Dennis_Christensen)\
**Replies:** 2\
**Last updated:** [January 16, 2023, 8:10am UTC](https://discuss.elastic.co/t/problems-deploying-eck-on-k8-v1-23-10/323129 "2023-01-16T08:10:04Z")

</div>

Hi. I am new to ECK, and would like to install it on our development cluster. But I have problems just installing the CRDs. From the quickstart I've tried to install the CRDs: kubectl apply -f https://download.elastic…

---

## [How to apply search on special characters when search is limited to specific fields?](https://discuss.elastic.co/t/how-to-apply-search-on-special-characters-when-search-is-limited-to-specific-fields/323220)

<div class="topic-metadata">

**Author:** [@Moazzam\_Saleem](https://discuss.elastic.co/u/Moazzam_Saleem)\
**Replies:** 0\
**Last updated:** [January 16, 2023, 6:58am UTC](https://discuss.elastic.co/t/how-to-apply-search-on-special-characters-when-search-is-limited-to-specific-fields/323220 "2023-01-16T06:58:49Z")

</div>

I'm new to elasticsearch, I'm trying to give global search but when I limited my search to apply of specific fields by giving fields param in query, search doesn't apply on special characters Here is my JSON query: { …

---

## [How to mask card number of xml message](https://discuss.elastic.co/t/how-to-mask-card-number-of-xml-message/322925)

<div class="topic-metadata">

**Author:** [@Anil0110](https://discuss.elastic.co/u/Anil0110)\
**Replies:** 5\
**Last updated:** [January 16, 2023, 7:19am UTC](https://discuss.elastic.co/t/how-to-mask-card-number-of-xml-message/322925 "2023-01-16T07:19:27Z")

</div>

Hello the requirement is we need to mask the cardnumber of xml message our input message looks like : message : output message expected

---

## [How to Get Control Filter in my custom plugin](https://discuss.elastic.co/t/how-to-get-control-filter-in-my-custom-plugin/323221)

<div class="topic-metadata">

**Author:** [@monusharma](https://discuss.elastic.co/u/monusharma)\
**Replies:** 0\
**Last updated:** [January 16, 2023, 6:59am UTC](https://discuss.elastic.co/t/how-to-get-control-filter-in-my-custom-plugin/323221 "2023-01-16T06:59:28Z")

</div>

In this regards, I have searched on internet and found deprecated below mentioned code: import FilterBarQueryFilterProvider from 'ui/filter\_bar/query\_filter'; // Somewhere in your directive, service, or controller con…

---

## [Cluter removed timeout Coordinating node](https://discuss.elastic.co/t/cluter-removed-timeout-coordinating-node/323208)

<div class="topic-metadata">

**Author:** [@chengdihua](https://discuss.elastic.co/u/chengdihua)\
**Replies:** 1\
**Last updated:** [January 16, 2023, 6:45am UTC](https://discuss.elastic.co/t/cluter-removed-timeout-coordinating-node/323208 "2023-01-16T06:45:25Z")

</div>

Hello, everyone! We have 15 nodes in our ES cluster, including 3 master nodes, 9 data nodes, and 3 coordinate/client nodes. There are 3 physical hosts in the cluster, and 5 ES nodes are deployed on each host. (1 master…

---

## [Regarding daily active users count formula](https://discuss.elastic.co/t/regarding-daily-active-users-count-formula/323188)

<div class="topic-metadata">

**Author:** [@bhavin.shah](https://discuss.elastic.co/u/bhavin.shah)\
**Replies:** 3\
**Last updated:** [January 16, 2023, 5:52am UTC](https://discuss.elastic.co/t/regarding-daily-active-users-count-formula/323188 "2023-01-16T05:52:57Z")

</div>

Hello team, I am trying to calculate one number output as , how many customers have placed daily atleast one order in last one day. My index formation is like following Ord\_order\_no - unique record / document ID Clien…

---

## [I want contribute to kibana](https://discuss.elastic.co/t/i-want-contribute-to-kibana/322845)

<div class="topic-metadata">

**Author:** [@dawn023349](https://discuss.elastic.co/u/dawn023349)\
**Replies:** 7\
**Last updated:** [January 15, 2023, 4:41pm UTC](https://discuss.elastic.co/t/i-want-contribute-to-kibana/322845 "2023-01-15T16:41:02Z")

</div>

I finished installing and testing the Linux version of Kibana. And I forked git repo. But "kibana\\src\\plugins\\data\\target\\public\\data.plugin.js" file did not exist. What should I do?

---

## [Help me with logstash config (Feature Request)](https://discuss.elastic.co/t/help-me-with-logstash-config-feature-request/322992)

<div class="topic-metadata">

**Author:** [@Md\_Shariful\_Islam](https://discuss.elastic.co/u/Md_Shariful_Islam)\
**Replies:** 4\
**Last updated:** [January 15, 2023, 5:30am UTC](https://discuss.elastic.co/t/help-me-with-logstash-config-feature-request/322992 "2023-01-15T05:30:36Z")

</div>

I am using logstash aggregate filter and I want timeout value for infinite time. How to do that? Current config for aggregate filter given below if \[src\_ip\] { aggregate { task\_id =\> "%{src\_ip}" …

---

## [Failed to start Elasticsearch](https://discuss.elastic.co/t/failed-to-start-elasticsearch/322433)

<div class="topic-metadata">

**Author:** [@alam02](https://discuss.elastic.co/u/alam02)\
**Replies:** 1\
**Last updated:** [January 15, 2023, 3:09am UTC](https://discuss.elastic.co/t/failed-to-start-elasticsearch/322433 "2023-01-15T03:09:50Z")

</div>

Hello i have kibana, logstash started but impossible to start elastic.service and i got this error code when i run systemctl start elastic.service. Also on the website i receive this message " kibana is not ready yet". …

---

## [Adding score to SearchHit via REST Template](https://discuss.elastic.co/t/adding-score-to-searchhit-via-rest-template/323154)

<div class="topic-metadata">

**Author:** [@timothystone](https://discuss.elastic.co/u/timothystone)\
**Replies:** 3\
**Last updated:** [January 15, 2023, 3:07am UTC](https://discuss.elastic.co/t/adding-score-to-searchhit-via-rest-template/323154 "2023-01-15T03:07:04Z")

</div>

I'm using a NativeSearchQuery with setTrackScores(true). This query is passed to the ElasticsearchRestTemplate#search(Query, Clazz) (inherited from AbstractElasticsearchTemplate#(Query, Clazz) The Clazz here is a typica…

---

## [Upload file / Pb formats](https://discuss.elastic.co/t/upload-file-pb-formats/323186)

<div class="topic-metadata">

**Author:** [@Phildefer](https://discuss.elastic.co/u/Phildefer)\
**Replies:** 0\
**Last updated:** [January 14, 2023, 10:40pm UTC](https://discuss.elastic.co/t/upload-file-pb-formats/323186 "2023-01-14T22:40:06Z")

</div>

Bonjour, Je souhaiterais savoir s'il est possible lors de l'import d'un fichier csv via Kibana: De faire reconnaitre automatiquement un champ du type "15 janvier 2023 " comme un champ date pour elk De faire reconnaitr…

---

## [Merging fields of two index pattern](https://discuss.elastic.co/t/merging-fields-of-two-index-pattern/315564)

<div class="topic-metadata">

**Author:** [@random\_dash](https://discuss.elastic.co/u/random_dash)\
**Replies:** 1\
**Last updated:** [October 24, 2022, 2:19pm UTC](https://discuss.elastic.co/t/merging-fields-of-two-index-pattern/315564 "2022-10-24T14:19:49Z")

</div>

Hi, I have two data streams in Kibana with similar information. I am trying to aggregate them by creating a new index pattern. Each of them has a field "state". For one of them, the state can be \[passed, failed\], and f…

---

## [Field value not found in aggregatable field](https://discuss.elastic.co/t/field-value-not-found-in-aggregatable-field/323182)

<div class="topic-metadata">

**Author:** [@nnet](https://discuss.elastic.co/u/nnet)\
**Replies:** 2\
**Last updated:** [January 14, 2023, 8:40pm UTC](https://discuss.elastic.co/t/field-value-not-found-in-aggregatable-field/323182 "2023-01-14T20:40:16Z")

</div>

Hi folks, I'm at a loss to understand this. ELK stack 5.6. Using filebeat i send json logs of nginx to logstash where they're parsed and fed into elasticsearch. No errors, all seems good. In kibana I have a visualizat…

---

## [Logstash Elasticsearch filter Bad URI Exception](https://discuss.elastic.co/t/logstash-elasticsearch-filter-bad-uri-exception/323176)

<div class="topic-metadata">

**Author:** [@eraste](https://discuss.elastic.co/u/eraste)\
**Replies:** 9\
**Last updated:** [January 14, 2023, 7:02pm UTC](https://discuss.elastic.co/t/logstash-elasticsearch-filter-bad-uri-exception/323176 "2023-01-14T19:02:12Z")

</div>

Hello Everyone. I have an exception in Logstash with Elasticsearch filter in the hosts parameter. When i give manually the hosts parameter like this, all thing is good, i don't get error : filter { elasticsearch {…

---

## [Print logs into a file before parsing with GROK](https://discuss.elastic.co/t/print-logs-into-a-file-before-parsing-with-grok/323145)

<div class="topic-metadata">

**Author:** [@danishbit09](https://discuss.elastic.co/u/danishbit09)\
**Replies:** 3\
**Last updated:** [January 14, 2023, 5:52pm UTC](https://discuss.elastic.co/t/print-logs-into-a-file-before-parsing-with-grok/323145 "2023-01-14T17:52:15Z")

</div>

Is there any option to store logs into a file before parsing it in GROK. Please suggest. Can I use logger.info() in Filter plugin.

---

## [Load Eland dataframe partially by query](https://discuss.elastic.co/t/load-eland-dataframe-partially-by-query/323180)

<div class="topic-metadata">

**Author:** [@mruiter](https://discuss.elastic.co/u/mruiter)\
**Replies:** 0\
**Last updated:** [January 14, 2023, 2:15pm UTC](https://discuss.elastic.co/t/load-eland-dataframe-partially-by-query/323180 "2023-01-14T14:15:13Z")

</div>

I'm trying to fetch data from Elasticsearch into an Eland dataframe partially, because it takes too much time to load the entire index. The following works, except for the \_query\_compiler. The official Eland docs contai…

---

## [Kibana Iframe Share Issue with Xframe and SameSite Cookie](https://discuss.elastic.co/t/kibana-iframe-share-issue-with-xframe-and-samesite-cookie/316824)

<div class="topic-metadata">

**Author:** [@hidanny](https://discuss.elastic.co/u/hidanny)\
**Replies:** 1\
**Last updated:** [October 24, 2022, 12:49pm UTC](https://discuss.elastic.co/t/kibana-iframe-share-issue-with-xframe-and-samesite-cookie/316824 "2022-10-24T12:49:34Z")

</div>

Hello all, This may be a super dumb question. For reference, I am using latest React and Google Chrome. Also, to note, this is working completely fine in Firefox. Just not in Google Chrome. Essentially, I am trying to …

---

## [Can an ID of an index be not null but empty?](https://discuss.elastic.co/t/can-an-id-of-an-index-be-not-null-but-empty/323167)

<div class="topic-metadata">

**Author:** [@Java2avaj](https://discuss.elastic.co/u/Java2avaj)\
**Replies:** 3\
**Last updated:** [January 14, 2023, 11:46am UTC](https://discuss.elastic.co/t/can-an-id-of-an-index-be-not-null-but-empty/323167 "2023-01-14T11:46:05Z")

</div>

Just a question if by default, an id of an index be empty string value “”? If yes, how to prevent from saving an empty id?

---

## [Plot a table based on aggregate key values](https://discuss.elastic.co/t/plot-a-table-based-on-aggregate-key-values/322635)

<div class="topic-metadata">

**Author:** [@Tukaram](https://discuss.elastic.co/u/Tukaram)\
**Replies:** 2\
**Last updated:** [January 14, 2023, 9:46am UTC](https://discuss.elastic.co/t/plot-a-table-based-on-aggregate-key-values/322635 "2023-01-14T09:46:35Z")

</div>

Hi and HNY! I am looking to put this kind of data every 30 minutes to Kibana under 1 index. data1- {key: 'key1', user: 'A', manager: 'C', cnt1: 2, cnt2:4} data2- {key: 'key2', user: 'B', manager: 'C', cnt1: 4, cnt2:5} …

[Previous page](https://discuss.elastic.co/tag/none.md?no_tags=true&page=455)

[Next page](https://discuss.elastic.co/tag/none.md?no_tags=true&page=457)
