# \#none

**URL:** https://discuss.elastic.co/tag/none.md?no_tags=true&page=464

[Latest](https://discuss.elastic.co/latest.md) · [Categories](https://discuss.elastic.co/categories.md) · [Tags](https://discuss.elastic.co/tags.md)

**Page:** 465

---

## [Fatal exception while booting Elasticsearch](https://discuss.elastic.co/t/fatal-exception-while-booting-elasticsearch/322390)

<div class="topic-metadata">

**Author:** [@diegz](https://discuss.elastic.co/u/diegz)\
**Replies:** 11\
**Last updated:** [January 5, 2023, 11:45am UTC](https://discuss.elastic.co/t/fatal-exception-while-booting-elasticsearch/322390 "2023-01-05T11:45:14Z")

</div>

Hello, I have 5 nodes under rhel 8.7, the system is hardened so the partitions /var /var/tmp /var/log /home /var/log/audit and /tmp are in noexec I managed to work around the problem on the first two nodes by adding th…

---

## [Create Rule when I have problems with the machine host](https://discuss.elastic.co/t/create-rule-when-i-have-problems-with-the-machine-host/322536)

<div class="topic-metadata">

**Author:** [@Kirtash](https://discuss.elastic.co/u/Kirtash)\
**Replies:** 2\
**Last updated:** [January 5, 2023, 11:43am UTC](https://discuss.elastic.co/t/create-rule-when-i-have-problems-with-the-machine-host/322536 "2023-01-05T11:43:26Z")

</div>

Good morning! Is it possible create a rule to detect when the host machine is stopped or the cpu\_usage is superior than 90% I know that exists the inventory metric but I don't know if I can specify the host. I have man…

---

## [Warm node is failing to connecting with master node](https://discuss.elastic.co/t/warm-node-is-failing-to-connecting-with-master-node/322522)

<div class="topic-metadata">

**Author:** [@rahul\_sirugudi](https://discuss.elastic.co/u/rahul_sirugudi)\
**Replies:** 1\
**Last updated:** [January 5, 2023, 11:33am UTC](https://discuss.elastic.co/t/warm-node-is-failing-to-connecting-with-master-node/322522 "2023-01-05T11:33:26Z")

</div>

I am migrating single-node cluster to multi node. I have started up with setting up basic security on master node using this link. As mentioned in point 2 i have copied the output file to the warm node and i have saved…

---

## [Help with kibana and elastic-agent no work](https://discuss.elastic.co/t/help-with-kibana-and-elastic-agent-no-work/322477)

<div class="topic-metadata">

**Author:** [@hernani33](https://discuss.elastic.co/u/hernani33)\
**Replies:** 4\
**Last updated:** [January 5, 2023, 11:32am UTC](https://discuss.elastic.co/t/help-with-kibana-and-elastic-agent-no-work/322477 "2023-01-05T11:32:55Z")

</div>

i have elasticsearch kibana and elastic-agent installed ok. but elastic-agent not work in kibana, I ALWAYS SAY LISTENING FOR AGENT WHEN I GO TO CLICK ADD AGENT. IN STEP 3 IN INTEGRATION POLICIE CONFIRM AGENT ENROLLMENT,…

---

## [Security\_exception while Restoring Snapshot | ES 8.3.2](https://discuss.elastic.co/t/security-exception-while-restoring-snapshot-es-8-3-2/322511)

<div class="topic-metadata">

**Author:** [@zeus7](https://discuss.elastic.co/u/zeus7)\
**Replies:** 3\
**Last updated:** [January 5, 2023, 11:24am UTC](https://discuss.elastic.co/t/security-exception-while-restoring-snapshot-es-8-3-2/322511 "2023-01-05T11:24:26Z")

</div>

I m trying to restore snapshot from version 6.2.4 to 8.3.2, getting error : { "error": { "root\_cause": \[ { "type": "security\_exception", "reason": "current license…

---

## [Multiple score fields?](https://discuss.elastic.co/t/multiple-score-fields/322323)

<div class="topic-metadata">

**Author:** [@petrskokan11](https://discuss.elastic.co/u/petrskokan11)\
**Replies:** 1\
**Last updated:** [January 5, 2023, 11:03am UTC](https://discuss.elastic.co/t/multiple-score-fields/322323 "2023-01-05T11:03:50Z")

</div>

Maybe a dummy question: is it possible to have multiple score fields? I use a custom score based on function\_score query. This score is being displayed to the user to show, how much each document matches his/her prefere…

---

## [Allow multiple selection on data tables](https://discuss.elastic.co/t/allow-multiple-selection-on-data-tables/322515)

<div class="topic-metadata">

**Author:** [@bandodkarD](https://discuss.elastic.co/u/bandodkarD)\
**Replies:** 1\
**Last updated:** [January 5, 2023, 10:49am UTC](https://discuss.elastic.co/t/allow-multiple-selection-on-data-tables/322515 "2023-01-05T10:49:00Z")

</div>

Is it possible to filter multiple options from Kibana visualisations? Right now, it narrows down to only 1 selected item.

---

## [Installing ElasticSearch via Helm without VolumeClaim using existing volumeMount?](https://discuss.elastic.co/t/installing-elasticsearch-via-helm-without-volumeclaim-using-existing-volumemount/322532)

<div class="topic-metadata">

**Author:** [@cawoodm](https://discuss.elastic.co/u/cawoodm)\
**Replies:** 0\
**Last updated:** [January 5, 2023, 10:47am UTC](https://discuss.elastic.co/t/installing-elasticsearch-via-helm-without-volumeclaim-using-existing-volumemount/322532 "2023-01-05T10:47:24Z")

</div>

We want to install Elasticsearch via helm chart and provide our own volumeMount. We don't really want to have anything to do with PVCs. Ideally the resulting container should have something like: volumeMounts…

---

## [Howto switch dashboards keeping the very same filter settings (aka grammar of markdown link filter)](https://discuss.elastic.co/t/howto-switch-dashboards-keeping-the-very-same-filter-settings-aka-grammar-of-markdown-link-filter/321895)

<div class="topic-metadata">

**Author:** [@DrG](https://discuss.elastic.co/u/DrG)\
**Replies:** 4\
**Last updated:** [January 5, 2023, 10:25am UTC](https://discuss.elastic.co/t/howto-switch-dashboards-keeping-the-very-same-filter-settings-aka-grammar-of-markdown-link-filter/321895 "2023-01-05T10:25:41Z")

</div>

Hello everybody, (Even this question might sound like a duplicate to Markdown link with current filter - Elastic Stack / Kibana - Discuss the Elastic Stack ) But the proposed solution of that post is not working for my…

---

## [Fail to install Elastic-Agent](https://discuss.elastic.co/t/fail-to-install-elastic-agent/322495)

<div class="topic-metadata">

**Author:** [@pntmky](https://discuss.elastic.co/u/pntmky)\
**Replies:** 8\
**Last updated:** [January 5, 2023, 7:46am UTC](https://discuss.elastic.co/t/fail-to-install-elastic-agent/322495 "2023-01-05T07:46:33Z")

</div>

First of all, I installed Elastic Agent by DEB successfully, but I realize that cannot upgrade, so I uninstall Elastic Agent and remove installation layout of Elastic Agent. And now when I install by Linux Tar, it fai…

---

## [Show dynamic info from field names in a pie chart?](https://discuss.elastic.co/t/show-dynamic-info-from-field-names-in-a-pie-chart/322259)

<div class="topic-metadata">

**Author:** [@tallavi](https://discuss.elastic.co/u/tallavi)\
**Replies:** 2\
**Last updated:** [January 5, 2023, 7:41am UTC](https://discuss.elastic.co/t/show-dynamic-info-from-field-names-in-a-pie-chart/322259 "2023-01-05T07:41:44Z")

</div>

Hi, I have a use-case which I can't seem to resolve. I have in a document a map of animals, the key is the animal name, the values is an object with information on that animal, for example: { "animals": { "cats"…

---

## [Elasticsearch,Kibana,logstash,filebeat](https://discuss.elastic.co/t/elasticsearch-kibana-logstash-filebeat/322133)

<div class="topic-metadata">

**Author:** [@Mursel](https://discuss.elastic.co/u/Mursel)\
**Replies:** 15\
**Last updated:** [January 5, 2023, 7:27am UTC](https://discuss.elastic.co/t/elasticsearch-kibana-logstash-filebeat/322133 "2023-01-05T07:27:50Z")

</div>

The hit point in Kibana was more than one hundred thousand for 3 hours. Then I observed that this number has dropped to three thousand. The reason for this was that 90 percent of the memory was full. To fix this, I remov…

---

## [How to visualize json data obtained from filebeat in kibana](https://discuss.elastic.co/t/how-to-visualize-json-data-obtained-from-filebeat-in-kibana/317793)

<div class="topic-metadata">

**Author:** [@anu1](https://discuss.elastic.co/u/anu1)\
**Replies:** 3\
**Last updated:** [November 10, 2022, 4:25am UTC](https://discuss.elastic.co/t/how-to-visualize-json-data-obtained-from-filebeat-in-kibana/317793 "2022-11-10T04:25:06Z")

</div>

Hi, I'm new to elk. I've configured elk as a server and filebeat as a client and through filebeat, i'm sending the json format data (temperature values) to elk.Now i'm finding it difficulty to visualize only temperatur…

---

## [Adding a global label for all metrics and logs coming from an agent policy](https://discuss.elastic.co/t/adding-a-global-label-for-all-metrics-and-logs-coming-from-an-agent-policy/322143)

<div class="topic-metadata">

**Author:** [@slogger](https://discuss.elastic.co/u/slogger)\
**Replies:** 2\
**Last updated:** [January 4, 2023, 8:46pm UTC](https://discuss.elastic.co/t/adding-a-global-label-for-all-metrics-and-logs-coming-from-an-agent-policy/322143 "2023-01-04T20:46:46Z")

</div>

Hello I need to have a way to filter all the logs and metrics that come from all elastic agent (and integrations) with a certain policy. For example all dev metrics collected by the dev agents should have a lable: env:…

---

## [Issues with agent on windows service start loop](https://discuss.elastic.co/t/issues-with-agent-on-windows-service-start-loop/322250)

<div class="topic-metadata">

**Author:** [@pshilling](https://discuss.elastic.co/u/pshilling)\
**Replies:** 1\
**Last updated:** [January 4, 2023, 7:14pm UTC](https://discuss.elastic.co/t/issues-with-agent-on-windows-service-start-loop/322250 "2023-01-04T19:14:46Z")

</div>

I installed the agent on my windows 10 test machine using the script generated from my fleet server. I used cmd run as administrator to run the installer. I seem to be stuck in a service start loop. The error logs show t…

---

## [Restrict index privilege on space level](https://discuss.elastic.co/t/restrict-index-privilege-on-space-level/320588)

<div class="topic-metadata">

**Author:** [@shinki927](https://discuss.elastic.co/u/shinki927)\
**Replies:** 1\
**Last updated:** [December 7, 2022, 7:22pm UTC](https://discuss.elastic.co/t/restrict-index-privilege-on-space-level/320588 "2022-12-07T19:22:56Z")

</div>

Hello, I have a question about how to restrict the index access on space level. I know in general we can create separate role with different index permission to a specific space. But in our use case, we sometimes need t…

---

## [Unfreeze, Read-Only, Move to Cold/Frozen](https://discuss.elastic.co/t/unfreeze-read-only-move-to-cold-frozen/322395)

<div class="topic-metadata">

**Author:** [@Ryan\_Downey](https://discuss.elastic.co/u/Ryan_Downey)\
**Replies:** 2\
**Last updated:** [January 4, 2023, 6:40pm UTC](https://discuss.elastic.co/t/unfreeze-read-only-move-to-cold-frozen/322395 "2023-01-04T18:40:33Z")

</div>

Team, I'm working through the Elastic Upgrade Assistant and its telling me I have 38 Warnings, all the same warning, that I need to, "Index \[XYZ\] is frozen. Frozen indices no longer offer any advantages. Instead, unfree…

---

## [Field with long type show integer value in table visualization](https://discuss.elastic.co/t/field-with-long-type-show-integer-value-in-table-visualization/322401)

<div class="topic-metadata">

**Author:** [@ShayWeizman](https://discuss.elastic.co/u/ShayWeizman)\
**Replies:** 6\
**Last updated:** [January 4, 2023, 6:35pm UTC](https://discuss.elastic.co/t/field-with-long-type-show-integer-value-in-table-visualization/322401 "2023-01-04T18:35:06Z")

</div>

Hi, I'm using Elastic v 7.17.3 I have data as followed: { "\_index" : "degradedtests", "\_type" : "\_doc", "\_id" : "87b7eIUB8OjwSAfblzEq", "\_score" : null, "\_source" : { …

---

## [Logging to logstash gets timeout from laravel application once the logstash instance(EC2) goes down](https://discuss.elastic.co/t/logging-to-logstash-gets-timeout-from-laravel-application-once-the-logstash-instance-ec2-goes-down/322456)

<div class="topic-metadata">

**Author:** [@yuguerthen](https://discuss.elastic.co/u/yuguerthen)\
**Replies:** 3\
**Last updated:** [January 4, 2023, 6:04pm UTC](https://discuss.elastic.co/t/logging-to-logstash-gets-timeout-from-laravel-application-once-the-logstash-instance-ec2-goes-down/322456 "2023-01-04T18:04:55Z")

</div>

Hello, I have a Laravel application that sends log data to Logstash on an AWS EC2 instance. Recently, the EC2 instance went down, and I noticed that the Laravel application started prompting timeouts when I tried to log …

---

## [Cannot index event publisher ERROR](https://discuss.elastic.co/t/cannot-index-event-publisher-error/322285)

<div class="topic-metadata">

**Author:** [@theacodes](https://discuss.elastic.co/u/theacodes)\
**Replies:** 5\
**Last updated:** [January 4, 2023, 5:01pm UTC](https://discuss.elastic.co/t/cannot-index-event-publisher-error/322285 "2023-01-04T17:01:45Z")

</div>

Getting this error {"type":"mapper\_parsing\_exception","reason":"failed to parse field \[network.forwarded\_ip\] of type \[ip\] in document with id 'msD2cIUBIsfwhIgCSPy9'. Preview of field's value: '0'","caused\_by":{"type":"i…

---

## [Logstash service keep on restarting](https://discuss.elastic.co/t/logstash-service-keep-on-restarting/322370)

<div class="topic-metadata">

**Author:** [@Shalinicts](https://discuss.elastic.co/u/Shalinicts)\
**Replies:** 12\
**Last updated:** [January 4, 2023, 3:27pm UTC](https://discuss.elastic.co/t/logstash-service-keep-on-restarting/322370 "2023-01-04T15:27:28Z")

</div>

Hi Team , Logstash service keeps on restarting and this is the message found in logs . Tried doing pqcheck and pqrepair, removed the problematic queue etc.. No issues related to user access , memory, disk Any suggest…

---

## [Compatibility with grafana](https://discuss.elastic.co/t/compatibility-with-grafana/322469)

<div class="topic-metadata">

**Author:** [@m3bgwad](https://discuss.elastic.co/u/m3bgwad)\
**Replies:** 2\
**Last updated:** [January 4, 2023, 3:27pm UTC](https://discuss.elastic.co/t/compatibility-with-grafana/322469 "2023-01-04T15:27:28Z")

</div>

hello everyone. Is there compatibility Grafana version 9.2 and ELK 7.2.11 as data source?

---

## [Add image in visualization](https://discuss.elastic.co/t/add-image-in-visualization/322472)

<div class="topic-metadata">

**Author:** [@Alice\_Ionescu](https://discuss.elastic.co/u/Alice_Ionescu)\
**Replies:** 1\
**Last updated:** [January 4, 2023, 3:12pm UTC](https://discuss.elastic.co/t/add-image-in-visualization/322472 "2023-01-04T15:12:31Z")

</div>

Hello, I would like to display pictures in visualizations, the pictures are stored in in eleasticsearch in a base64 format. So I have a field on an index that is the base64 format of an image and I want to display it i…

---

## [Installing Elasticsearch - archive vs DEB](https://discuss.elastic.co/t/installing-elasticsearch-archive-vs-deb/322478)

<div class="topic-metadata">

**Author:** [@Evram\_Yousef](https://discuss.elastic.co/u/Evram_Yousef)\
**Replies:** 0\
**Last updated:** [January 4, 2023, 3:04pm UTC](https://discuss.elastic.co/t/installing-elasticsearch-archive-vs-deb/322478 "2023-01-04T15:04:59Z")

</div>

Hello All, Now I've been using this ES on linux machines - Azure machines simply by downloading archive - tar - and install Now I wanted to move to multiple nodes. I found that I can't communicate between two nodes…

---

## [JSON parse error, original data now in message field {:message=\>"Unexpected character ('\<' (code 60)): expected a valid value (number, String, array, object, 'true', 'false' or 'null')\\n at \[Source: (String)](https://discuss.elastic.co/t/json-parse-error-original-data-now-in-message-field-message-unexpected-character-code-60-expected-a-valid-value-number-string-array-object-true-false-or-null-n-at-source-string/322015)

<div class="topic-metadata">

**Author:** [@shafiwebsphere](https://discuss.elastic.co/u/shafiwebsphere)\
**Replies:** 11\
**Last updated:** [January 4, 2023, 2:26pm UTC](https://discuss.elastic.co/t/json-parse-error-original-data-now-in-message-field-message-unexpected-character-code-60-expected-a-valid-value-number-string-array-object-true-false-or-null-n-at-source-string/322015 "2023-01-04T14:26:44Z")

</div>

Same code worked in previous version 7 but i have updated to latest version Elasticsearch logstash and kibana 7.17 , the logstash code is not working and getting error, i have been trying this from 15 days , When i have …

---

## ["stream page" in "observability" and "discover page"](https://discuss.elastic.co/t/stream-page-in-observability-and-discover-page/319867)

<div class="topic-metadata">

**Author:** [@morad\_della3](https://discuss.elastic.co/u/morad_della3)\
**Replies:** 1\
**Last updated:** [December 7, 2022, 3:41pm UTC](https://discuss.elastic.co/t/stream-page-in-observability-and-discover-page/319867 "2022-12-07T15:41:33Z")

</div>

what's the difference between "stream page" in "observability" and "discover page" of kibana? thanks.

---

## [Error sending logs to Elastic from UIPATH system](https://discuss.elastic.co/t/error-sending-logs-to-elastic-from-uipath-system/322471)

<div class="topic-metadata">

**Author:** [@aviadhaim18](https://discuss.elastic.co/u/aviadhaim18)\
**Replies:** 0\
**Last updated:** [January 4, 2023, 1:53pm UTC](https://discuss.elastic.co/t/error-sending-logs-to-elastic-from-uipath-system/322471 "2023-01-04T13:53:35Z")

</div>

Hi, When I try to send logs to Elastic, I get the following error: Elasticsearch: Bulk item failed: index:rpa\_test-2023.01.04 result: type:logEvent error:Type: illegal\_argument\_exception Reason: "Invalid type: expectin…

---

## [What happens to \>5GB segments?](https://discuss.elastic.co/t/what-happens-to-5gb-segments/322460)

<div class="topic-metadata">

**Author:** [@sezuan](https://discuss.elastic.co/u/sezuan)\
**Replies:** 0\
**Last updated:** [January 4, 2023, 12:33pm UTC](https://discuss.elastic.co/t/what-happens-to-5gb-segments/322460 "2023-01-04T12:33:43Z")

</div>

Hello, I'm wondering what happens to segments that are larger than 5gb (index.merge.policy.max\_merged\_segment ) and the index has more than 33% deleted documents (index.merge.policy.deletes\_pct\_allowed) and it's no poss…

---

## [Key with dot notation in rank features of ES v8.4.0](https://discuss.elastic.co/t/key-with-dot-notation-in-rank-features-of-es-v8-4-0/322424)

<div class="topic-metadata">

**Author:** [@Chen\_Bright](https://discuss.elastic.co/u/Chen_Bright)\
**Replies:** 2\
**Last updated:** [January 4, 2023, 11:42am UTC](https://discuss.elastic.co/t/key-with-dot-notation-in-rank-features-of-es-v8-4-0/322424 "2023-01-04T11:42:36Z")

</div>

ENV: Elasticsearch v8.4.0 operation steps(very simple): what i wanna know is, how can i insert this kind of data in the rank features field?(i tested in es v7.10.2, it works, so maybe es changed the way to treat the…

---

## [Sending logs from splunk forward to logstash](https://discuss.elastic.co/t/sending-logs-from-splunk-forward-to-logstash/322454)

<div class="topic-metadata">

**Author:** [@mangeshmj1992](https://discuss.elastic.co/u/mangeshmj1992)\
**Replies:** 0\
**Last updated:** [January 4, 2023, 11:37am UTC](https://discuss.elastic.co/t/sending-logs-from-splunk-forward-to-logstash/322454 "2023-01-04T11:37:17Z")

</div>

Hi team, we are trying to send data from splunk to logstash and kibana . we are getting data but data is not in proper format. We have tested below codec but now luck. Every time data changing but no original data is c…

[Previous page](https://discuss.elastic.co/tag/none.md?no_tags=true&page=463)

[Next page](https://discuss.elastic.co/tag/none.md?no_tags=true&page=465)
