# \#none

**URL:** https://discuss.elastic.co/tag/none.md?no_tags=true&page=457

[Latest](https://discuss.elastic.co/latest.md) · [Categories](https://discuss.elastic.co/categories.md) · [Tags](https://discuss.elastic.co/tags.md)

**Page:** 458

---

## [Clarification on \`docs.deleted\` in regards to data deletion compliance requirements](https://discuss.elastic.co/t/clarification-on-docs-deleted-in-regards-to-data-deletion-compliance-requirements/323160)

<div class="topic-metadata">

**Author:** [@alee47](https://discuss.elastic.co/u/alee47)\
**Replies:** 1\
**Last updated:** [January 14, 2023, 9:26am UTC](https://discuss.elastic.co/t/clarification-on-docs-deleted-in-regards-to-data-deletion-compliance-requirements/323160 "2023-01-14T09:26:50Z")

</div>

My organization uses Elasticsearch to store and index information for one of our services. We have an internal compliance requirement to delete data whenever a user of our service requests their data to be deleted. In or…

---

## [Range Slider](https://discuss.elastic.co/t/range-slider/317068)

<div class="topic-metadata">

**Author:** [@linhz](https://discuss.elastic.co/u/linhz)\
**Replies:** 6\
**Last updated:** [October 24, 2022, 11:19am UTC](https://discuss.elastic.co/t/range-slider/317068 "2022-10-24T11:19:34Z")

</div>

Hi. Does the topic cover come with negative value for ranger slider. Anyone could share with me how to input the negative value or any documents? I have input a + value, but when input "-" it have the error status.

---

## [Signal status change time](https://discuss.elastic.co/t/signal-status-change-time/317301)

<div class="topic-metadata">

**Author:** [@Faycal\_B](https://discuss.elastic.co/u/Faycal_B)\
**Replies:** 0\
**Last updated:** [October 24, 2022, 9:12am UTC](https://discuss.elastic.co/t/signal-status-change-time/317301 "2022-10-24T09:12:35Z")

</div>

The signal api only return kibana.alert.workflow\_status field for the signal status change, is there a way to get a timestamp of the status change ?

---

## [Sign "+" was treated as wildcard in Elasticsearch API GET Search](https://discuss.elastic.co/t/sign-was-treated-as-wildcard-in-elasticsearch-api-get-search/323074)

<div class="topic-metadata">

**Author:** [@SooperTee](https://discuss.elastic.co/u/SooperTee)\
**Replies:** 2\
**Last updated:** [January 13, 2023, 6:20pm UTC](https://discuss.elastic.co/t/sign-was-treated-as-wildcard-in-elasticsearch-api-get-search/323074 "2023-01-13T18:20:07Z")

</div>

I was trying to access my Elasticsearch topic with API GET. please see below sample query. https://localhost:9200/my\_topic/\_search?pretty&q=trade.tradeType:"Delta +1" The problem with this search is that the result ret…

---

## [Logstash Plugin](https://discuss.elastic.co/t/logstash-plugin/323120)

<div class="topic-metadata">

**Author:** [@anik-27](https://discuss.elastic.co/u/anik-27)\
**Replies:** 8\
**Last updated:** [January 13, 2023, 5:25pm UTC](https://discuss.elastic.co/t/logstash-plugin/323120 "2023-01-13T17:25:38Z")

</div>

Hello friends, Is this possible to write a Logstash plugin for fetching data in Javascript just as we can do with Java ?

---

## [Index settings in elasticsearch 8+](https://discuss.elastic.co/t/index-settings-in-elasticsearch-8/323027)

<div class="topic-metadata">

**Author:** [@Idorasi\_Paul](https://discuss.elastic.co/u/Idorasi_Paul)\
**Replies:** 3\
**Last updated:** [January 13, 2023, 3:20pm UTC](https://discuss.elastic.co/t/index-settings-in-elasticsearch-8/323027 "2023-01-13T15:20:13Z")

</div>

Hello, from what I see, IndexSettings has a field of the same type called index. What is the difference if I set, for example, number\_of\_replicas like: index.number\_of\_replicas: 2 or directly: number\_of\_replicas: 2 ?

---

## [Query bool with must and should](https://discuss.elastic.co/t/query-bool-with-must-and-should/323135)

<div class="topic-metadata">

**Author:** [@sphawk](https://discuss.elastic.co/u/sphawk)\
**Replies:** 6\
**Last updated:** [January 13, 2023, 3:21pm UTC](https://discuss.elastic.co/t/query-bool-with-must-and-should/323135 "2023-01-13T15:21:57Z")

</div>

I'm trying to build a bool query. { "query": { "bool" : { "must" : \[ {"term": { "language": "es\_ES" }} \], "should": \[ { …

---

## [No old data in developer tool, but data are present in discover](https://discuss.elastic.co/t/no-old-data-in-developer-tool-but-data-are-present-in-discover/323134)

<div class="topic-metadata">

**Author:** [@vetsolution](https://discuss.elastic.co/u/vetsolution)\
**Replies:** 3\
**Last updated:** [January 13, 2023, 2:34pm UTC](https://discuss.elastic.co/t/no-old-data-in-developer-tool-but-data-are-present-in-discover/323134 "2023-01-13T14:34:55Z")

</div>

Modified today Hello, When I use the elastic api, via curl or the developper tool. I cannot got data from some old indice. But if I use the discover feature of Kibana, it can get those data. Moreover, if I go from di…

---

## [Need to more about store the logs on Hot node instead of warm node](https://discuss.elastic.co/t/need-to-more-about-store-the-logs-on-hot-node-instead-of-warm-node/323131)

<div class="topic-metadata">

**Author:** [@anushyaadam](https://discuss.elastic.co/u/anushyaadam)\
**Replies:** 3\
**Last updated:** [January 13, 2023, 2:16pm UTC](https://discuss.elastic.co/t/need-to-more-about-store-the-logs-on-hot-node-instead-of-warm-node/323131 "2023-01-13T14:16:42Z")

</div>

Hello Team, We would like to know about to store the data from Hot node instead of warm node. Normally the process was stored the data from hot node and warm node depends on ILM policies by 7days of retention period. H…

---

## [Searching through a document not knowing the path](https://discuss.elastic.co/t/searching-through-a-document-not-knowing-the-path/323132)

<div class="topic-metadata">

**Author:** [@Polala](https://discuss.elastic.co/u/Polala)\
**Replies:** 2\
**Last updated:** [January 13, 2023, 1:59pm UTC](https://discuss.elastic.co/t/searching-through-a-document-not-knowing-the-path/323132 "2023-01-13T13:59:03Z")

</div>

I want to search through a document and get data for Steven and all his children (so in this example James). Is there a way to do it not knowing the path for Steven - so it should be children.children.name - but what if…

---

## [Related to Logstash](https://discuss.elastic.co/t/related-to-logstash/323137)

<div class="topic-metadata">

**Author:** [@anik-27](https://discuss.elastic.co/u/anik-27)\
**Replies:** 0\
**Last updated:** [January 13, 2023, 1:51pm UTC](https://discuss.elastic.co/t/related-to-logstash/323137 "2023-01-13T13:51:19Z")

</div>

Hello friends I want to fetch some metrics data from the Vrops(VMware) api that includes following steps - Make a post request with login credentials to get the authentication token Use that authentication token with …

---

## [GROK pattern](https://discuss.elastic.co/t/grok-pattern/322443)

<div class="topic-metadata">

**Author:** [@Hamunaptroid](https://discuss.elastic.co/u/Hamunaptroid)\
**Replies:** 9\
**Last updated:** [January 13, 2023, 11:39am UTC](https://discuss.elastic.co/t/grok-pattern/322443 "2023-01-13T11:39:49Z")

</div>

Hello, I have trouble with writing GROK pattern for system logs. My goal is to parse logs in form "systemctl -o verbose" which looks like this Wed 2022-10-12 09:08:42.759756 \_TRANSPORT=kernel SYSLOG\_IDENTIFIER=…

---

## [Kibana - Table without time](https://discuss.elastic.co/t/kibana-table-without-time/323112)

<div class="topic-metadata">

**Author:** [@Chloe\_Boissavy](https://discuss.elastic.co/u/Chloe_Boissavy)\
**Replies:** 6\
**Last updated:** [January 13, 2023, 1:09pm UTC](https://discuss.elastic.co/t/kibana-table-without-time/323112 "2023-01-13T13:09:47Z")

</div>

Hello, I have Kibana 8.3.3. I have firewall data so data with IP address. In the same indices, I have list of IP address. I would like to create a table with IP address from firewall (src IP) and compare it with the …

---

## [UNASSIGNED ALLOCATION\_FAILED](https://discuss.elastic.co/t/unassigned-allocation-failed/323128)

<div class="topic-metadata">

**Author:** [@INS](https://discuss.elastic.co/u/INS)\
**Replies:** 1\
**Last updated:** [January 13, 2023, 12:28pm UTC](https://discuss.elastic.co/t/unassigned-allocation-failed/323128 "2023-01-13T12:28:27Z")

</div>

What can we do in below case? { "note" : "No shard was specified in the explain API request, so this response explains a randomly chosen unassigned shard. There may be other unassigned shards in this cluster which can…

---

## [KQL Syntax](https://discuss.elastic.co/t/kql-syntax/323031)

<div class="topic-metadata">

**Author:** [@Shashank02](https://discuss.elastic.co/u/Shashank02)\
**Replies:** 5\
**Last updated:** [January 13, 2023, 12:03pm UTC](https://discuss.elastic.co/t/kql-syntax/323031 "2023-01-13T12:03:47Z")

</div>

Does anybody know how to use dev tools? Because I'm thinking about updating the filter of a dashboard directly through python and I don't know how to do it. So, I am thinking of using KQL syntax. 2 questions I have is: d…

---

## [Elasticsearch - check if the parameter is not empty](https://discuss.elastic.co/t/elasticsearch-check-if-the-parameter-is-not-empty/323096)

<div class="topic-metadata">

**Author:** [@Java2avaj](https://discuss.elastic.co/u/Java2avaj)\
**Replies:** 3\
**Last updated:** [January 13, 2023, 11:29am UTC](https://discuss.elastic.co/t/elasticsearch-check-if-the-parameter-is-not-empty/323096 "2023-01-13T11:29:58Z")

</div>

In SQL, we can perform the following in the where clause: SELECT \* FROM tbl WHERE :parameter \<\> '' OR :parameter is not null Is this possible in Elasticsearch to check if the input parameter/value is not null or empty?…

---

## [How to contact Elastic Team because of a license?](https://discuss.elastic.co/t/how-to-contact-elastic-team-because-of-a-license/323116)

<div class="topic-metadata">

**Author:** [@acosta353](https://discuss.elastic.co/u/acosta353)\
**Replies:** 1\
**Last updated:** [January 13, 2023, 10:45am UTC](https://discuss.elastic.co/t/how-to-contact-elastic-team-because-of-a-license/323116 "2023-01-13T10:45:08Z")

</div>

Hello, I don't know if this is the correct topic, anyway, I'm trying to contact Elastic since beginning of December. First using the form that is available on their site, then trying to call to Sales team on Europe, and…

---

## [How to Hide the Zero records using JSON Input in Metric Dashboard](https://discuss.elastic.co/t/how-to-hide-the-zero-records-using-json-input-in-metric-dashboard/323013)

<div class="topic-metadata">

**Author:** [@Maruthappan\_Muthu](https://discuss.elastic.co/u/Maruthappan_Muthu)\
**Replies:** 5\
**Last updated:** [January 13, 2023, 10:21am UTC](https://discuss.elastic.co/t/how-to-hide-the-zero-records-using-json-input-in-metric-dashboard/323013 "2023-01-13T10:21:12Z")

</div>

My document gets the data on irregular interval.The field name is Ex.,SensexValue. There can be multiple values on the field (SensexValue) in every interval, with different timestamp(milliseconds) and some interval the f…

---

## [Logstash input imap plugin with attachment not decoding](https://discuss.elastic.co/t/logstash-input-imap-plugin-with-attachment-not-decoding/323113)

<div class="topic-metadata">

**Author:** [@anjuls](https://discuss.elastic.co/u/anjuls)\
**Replies:** 0\
**Last updated:** [January 13, 2023, 9:58am UTC](https://discuss.elastic.co/t/logstash-input-imap-plugin-with-attachment-not-decoding/323113 "2023-01-13T09:58:03Z")

</div>

Hi, I am trying to fetch emails with attachments from Office 365 using logstash and putting them on Kafka topic. During the process, I got to understand the logstash-imap-input plugin is unable to process it. When the a…

---

## [How to check details of version\_conflicts when wait\_for\_completion=false in update\_by\_query?](https://discuss.elastic.co/t/how-to-check-details-of-version-conflicts-when-wait-for-completion-false-in-update-by-query/323110)

<div class="topic-metadata">

**Author:** [@bkelastic](https://discuss.elastic.co/u/bkelastic)\
**Replies:** 0\
**Last updated:** [January 13, 2023, 9:40am UTC](https://discuss.elastic.co/t/how-to-check-details-of-version-conflicts-when-wait-for-completion-false-in-update-by-query/323110 "2023-01-13T09:40:30Z")

</div>

After executing \_update\_by\_query?conflicts=proceed&wait\_for\_completion=false I want to check details so I call GET \_tasks?detailed=true&actions=\*byquery and I receive response with number of "version\_conflicts" : {n…

---

## [Filtering by date field (other than the timestamp) in Kibana dashboard](https://discuss.elastic.co/t/filtering-by-date-field-other-than-the-timestamp-in-kibana-dashboard/322989)

<div class="topic-metadata">

**Author:** [@SaraAlshamsi](https://discuss.elastic.co/u/SaraAlshamsi)\
**Replies:** 3\
**Last updated:** [January 13, 2023, 8:56am UTC](https://discuss.elastic.co/t/filtering-by-date-field-other-than-the-timestamp-in-kibana-dashboard/322989 "2023-01-13T08:56:35Z")

</div>

Hello everyone, I have an index with several fields and more than 1 time field. For examle: Field names: "end\_date", "name", "sequence" & "start\_date". The mapping: { "check\_date\_filter": { "mappings": { …

---

## [How to know which element in the array is chosen by the fuzzysearch](https://discuss.elastic.co/t/how-to-know-which-element-in-the-array-is-chosen-by-the-fuzzysearch/323105)

<div class="topic-metadata">

**Author:** [@Heckler\_GlobalOperat](https://discuss.elastic.co/u/Heckler_GlobalOperat)\
**Replies:** 0\
**Last updated:** [January 13, 2023, 8:30am UTC](https://discuss.elastic.co/t/how-to-know-which-element-in-the-array-is-chosen-by-the-fuzzysearch/323105 "2023-01-13T08:30:59Z")

</div>

Hello, I have a tricky case and want to consult the experts here. We store our user info in Elasticsearch, an user may have different name aliases, all stored in a "names" array like below "names" : \[ { …

---

## [Kibana visualization error after restoring the snapshot](https://discuss.elastic.co/t/kibana-visualization-error-after-restoring-the-snapshot/317265)

<div class="topic-metadata">

**Author:** [@not\_correct](https://discuss.elastic.co/u/not_correct)\
**Replies:** 2\
**Last updated:** [October 23, 2022, 7:34pm UTC](https://discuss.elastic.co/t/kibana-visualization-error-after-restoring-the-snapshot/317265 "2022-10-23T19:34:12Z")

</div>

Hi, I have restored ElaticSearch snapsot that been managed by another person, I get the followng error when it comes to kibana dashboards Text fields are not optimised for operations that require per-document field da…

---

## [Elasticsearch Urdu Analyzer plug-in](https://discuss.elastic.co/t/elasticsearch-urdu-analyzer-plug-in/323088)

<div class="topic-metadata">

**Author:** [@Armeen\_Ashraf\_Khan\_F](https://discuss.elastic.co/u/Armeen_Ashraf_Khan_F)\
**Replies:** 0\
**Last updated:** [January 13, 2023, 6:32am UTC](https://discuss.elastic.co/t/elasticsearch-urdu-analyzer-plug-in/323088 "2023-01-13T06:32:50Z")

</div>

I am a Data Science Masters student doing thesis in Information Retrieval for my native language Urdu. Urdu is like Arabic in textual form. Currently, Urdu Analyzer has not been created in elasticsearch and I want to cre…

---

## [Logstash are not running properly](https://discuss.elastic.co/t/logstash-are-not-running-properly/323002)

<div class="topic-metadata">

**Author:** [@yasar](https://discuss.elastic.co/u/yasar)\
**Replies:** 7\
**Last updated:** [January 13, 2023, 4:26am UTC](https://discuss.elastic.co/t/logstash-are-not-running-properly/323002 "2023-01-13T04:26:42Z")

</div>

Hi team, We are trying to get the live logs from DEV Environment for testing.. But after started the Logstash (7.16.1) service, it through a error. Please check the below error. at RUBY.\<module:LibC\>(/usr/shar…

---

## [Add "Save Query" as one of Kibana sub-feature privileges](https://discuss.elastic.co/t/add-save-query-as-one-of-kibana-sub-feature-privileges/319017)

<div class="topic-metadata">

**Author:** [@bandodkarD](https://discuss.elastic.co/u/bandodkarD)\
**Replies:** 4\
**Last updated:** [November 18, 2022, 8:15am UTC](https://discuss.elastic.co/t/add-save-query-as-one-of-kibana-sub-feature-privileges/319017 "2022-11-18T08:15:38Z")

</div>

Hi Team, Is this feature available in recent versions of Kibana? # Add "Save Query" as one of Kibana sub-feature privileges If not is there a way for users with Read Only access to save query?

---

## [How are write requests handled to an index in the RED state](https://discuss.elastic.co/t/how-are-write-requests-handled-to-an-index-in-the-red-state/323044)

<div class="topic-metadata">

**Author:** [@alee47](https://discuss.elastic.co/u/alee47)\
**Replies:** 2\
**Last updated:** [January 12, 2023, 10:20pm UTC](https://discuss.elastic.co/t/how-are-write-requests-handled-to-an-index-in-the-red-state/323044 "2023-01-12T22:20:52Z")

</div>

Hello, My organization uses Elasticsearch to power one of our services and regularly receive write requests into our cluster. We use the routing parameter on all search and write requests, so they are directed to a sing…

---

## [Is it possible to count elements of an array of two levels? array of arrays](https://discuss.elastic.co/t/is-it-possible-to-count-elements-of-an-array-of-two-levels-array-of-arrays/323047)

<div class="topic-metadata">

**Author:** [@jcornejo](https://discuss.elastic.co/u/jcornejo)\
**Replies:** 2\
**Last updated:** [January 12, 2023, 9:40pm UTC](https://discuss.elastic.co/t/is-it-possible-to-count-elements-of-an-array-of-two-levels-array-of-arrays/323047 "2023-01-12T21:40:46Z")

</div>

I need to count the elements of the campaign\_promotions.promotion\_prices array it's possible? "hits" : \[ { "\_index" : "dev\_scrap\_campaigns", "\_type" : "\_doc", "\_id" : "2t0k7oQBF4RU85fFCPX\_…

---

## [Missing authentication credentials when visiting localhost:9200 after running elasticsearch.bat](https://discuss.elastic.co/t/missing-authentication-credentials-when-visiting-localhost-9200-after-running-elasticsearch-bat/323018)

<div class="topic-metadata">

**Author:** [@Arthur\_Medforth](https://discuss.elastic.co/u/Arthur_Medforth)\
**Replies:** 2\
**Last updated:** [January 12, 2023, 9:21pm UTC](https://discuss.elastic.co/t/missing-authentication-credentials-when-visiting-localhost-9200-after-running-elasticsearch-bat/323018 "2023-01-12T21:21:30Z")

</div>

{"error":{"root\_cause":\[{"type":"security\_exception","reason":"missing authentication credentials for REST request \[/\]","header":{"WWW-Authenticate":\["Basic realm="security" charset="UTF-8"","ApiKey"\]}}\],"type":"security…

---

## [ElasticSearch 7.15.1 / Unhappy Cluster](https://discuss.elastic.co/t/elasticsearch-7-15-1-unhappy-cluster/322974)

<div class="topic-metadata">

**Author:** [@Devin\_Acosta](https://discuss.elastic.co/u/Devin_Acosta)\
**Replies:** 5\
**Last updated:** [January 12, 2023, 9:19pm UTC](https://discuss.elastic.co/t/elasticsearch-7-15-1-unhappy-cluster/322974 "2023-01-12T21:19:20Z")

</div>

I am trying to troubleshoot an Elasticsearch 7.15.1 cluster that has 3 master nodes, and 30+ data nodes. Recently we have seen where data nodes are complaining about "master not discovered yet" after the nodes have been …

[Previous page](https://discuss.elastic.co/tag/none.md?no_tags=true&page=456)

[Next page](https://discuss.elastic.co/tag/none.md?no_tags=true&page=458)
