# \#none

**URL:** https://discuss.elastic.co/tag/none.md?no_tags=true&page=465

[Latest](https://discuss.elastic.co/latest.md) · [Categories](https://discuss.elastic.co/categories.md) · [Tags](https://discuss.elastic.co/tags.md)

**Page:** 466

---

## [How to get the JSON for a BoolQuery](https://discuss.elastic.co/t/how-to-get-the-json-for-a-boolquery/322452)

<div class="topic-metadata">

**Author:** [@Alain\_Desilets](https://discuss.elastic.co/u/Alain_Desilets)\
**Replies:** 0\
**Last updated:** [January 4, 2023, 11:32am UTC](https://discuss.elastic.co/t/how-to-get-the-json-for-a-boolquery/322452 "2023-01-04T11:32:18Z")

</div>

Given an instance of BoolQuery, how can I find out the JSON string that will be sent to the ES server?

---

## ["Search as you type" and elasticsearch](https://discuss.elastic.co/t/search-as-you-type-and-elasticsearch/322438)

<div class="topic-metadata">

**Author:** [@Rhh](https://discuss.elastic.co/u/Rhh)\
**Replies:** 0\
**Last updated:** [January 4, 2023, 9:05am UTC](https://discuss.elastic.co/t/search-as-you-type-and-elasticsearch/322438 "2023-01-04T09:05:00Z")

</div>

Hi I have a text field with the type set to "search as you type". When I request data I get all data corresponding to BLAKER OR 288 in the street field. ( the street field contains the streetname + house number ) But …

---

## [Zoom into trace/transaction time interval](https://discuss.elastic.co/t/zoom-into-trace-transaction-time-interval/321774)

<div class="topic-metadata">

**Author:** [@zvrastil](https://discuss.elastic.co/u/zvrastil)\
**Replies:** 2\
**Last updated:** [January 4, 2023, 7:51am UTC](https://discuss.elastic.co/t/zoom-into-trace-transaction-time-interval/321774 "2023-01-04T07:51:31Z")

</div>

Hello, is there any way to zoom into time interval within a single trace/transaction view? Let's say I want to zoom into the time interval of some particular span because it is relatively short with respect to the whole…

---

## [Restore to a different cluster](https://discuss.elastic.co/t/restore-to-a-different-cluster/322357)

<div class="topic-metadata">

**Author:** [@hjsroldan](https://discuss.elastic.co/u/hjsroldan)\
**Replies:** 7\
**Last updated:** [January 4, 2023, 7:04am UTC](https://discuss.elastic.co/t/restore-to-a-different-cluster/322357 "2023-01-04T07:04:09Z")

</div>

Hi, Good day! I have a Production Environment (3 Nodes) and a DR Environment (3 Nodes). I received the error "snapshot does not exist" on the DR Environment after trying to restore the snapshot of the Production on the…

---

## [Role mapping API is not visible in Kibana dashboard](https://discuss.elastic.co/t/role-mapping-api-is-not-visible-in-kibana-dashboard/322399)

<div class="topic-metadata">

**Author:** [@anagha03](https://discuss.elastic.co/u/anagha03)\
**Replies:** 3\
**Last updated:** [January 4, 2023, 7:03am UTC](https://discuss.elastic.co/t/role-mapping-api-is-not-visible-in-kibana-dashboard/322399 "2023-01-04T07:03:41Z")

</div>

I configured Elastic and kibana using ansible playbook. Elastic and kibana are working fine but on kibana dashboard I am not able to see the role mapping section under security tab and logstash pipeline under ingest tab…

---

## [Best way to make a consistent copy of data](https://discuss.elastic.co/t/best-way-to-make-a-consistent-copy-of-data/322418)

<div class="topic-metadata">

**Author:** [@ankh](https://discuss.elastic.co/u/ankh)\
**Replies:** 1\
**Last updated:** [January 4, 2023, 7:03am UTC](https://discuss.elastic.co/t/best-way-to-make-a-consistent-copy-of-data/322418 "2023-01-04T07:03:16Z")

</div>

I have a system containing billions of documents. I have a requirement to have a consistent point in time copy of a subset of fields from 1 year's worth of data (eg 200M documents). The documents are subject to change, i…

---

## [Issue with ElasticSearch Highlighter](https://discuss.elastic.co/t/issue-with-elasticsearch-highlighter/322340)

<div class="topic-metadata">

**Author:** [@Sahil5](https://discuss.elastic.co/u/Sahil5)\
**Replies:** 0\
**Last updated:** [January 3, 2023, 6:18am UTC](https://discuss.elastic.co/t/issue-with-elasticsearch-highlighter/322340 "2023-01-03T06:18:28Z")

</div>

Hi Team, We are getting response time issue with elasticsearch highlighter. In Mapping we are using copy field with store: true parameter. When we are trying to fetch copy field in highlighter query it is taking around…

---

## [How to prevent duplicate log](https://discuss.elastic.co/t/how-to-prevent-duplicate-log/322279)

<div class="topic-metadata">

**Author:** [@yuswanul](https://discuss.elastic.co/u/yuswanul)\
**Replies:** 4\
**Last updated:** [January 4, 2023, 5:53am UTC](https://discuss.elastic.co/t/how-to-prevent-duplicate-log/322279 "2023-01-04T05:53:04Z")

</div>

Hi there, I have found something odd in my elastic cluster. I found the exact same log showing up twice in the message field as you can see. the logs have the same timestamp, same X-Request-ID all the same. but wh…

---

## [Horizontal scroll not visible in kibana dashboard](https://discuss.elastic.co/t/horizontal-scroll-not-visible-in-kibana-dashboard/322068)

<div class="topic-metadata">

**Author:** [@ayush-srivastava-ev](https://discuss.elastic.co/u/ayush-srivastava-ev)\
**Replies:** 20\
**Last updated:** [January 4, 2023, 4:43am UTC](https://discuss.elastic.co/t/horizontal-scroll-not-visible-in-kibana-dashboard/322068 "2023-01-04T04:43:41Z")

</div>

When i am seeing the data through kibana search. This horizontal scrollbar issue is big trouble for us especially when there are more number of columns and rows. While seeing the data, horizontal scroll bar is appearin…

---

## [Which visualisation type is best 2 layer histogram with time offset?](https://discuss.elastic.co/t/which-visualisation-type-is-best-2-layer-histogram-with-time-offset/314574)

<div class="topic-metadata">

**Author:** [@asp](https://discuss.elastic.co/u/asp)\
**Replies:** 3\
**Last updated:** [October 12, 2022, 1:00pm UTC](https://discuss.elastic.co/t/which-visualisation-type-is-best-2-layer-histogram-with-time-offset/314574 "2022-10-12T13:00:26Z")

</div>

Hi, I want to create a time based histogram visualization which shows two lines. Some performance curves like processing time. For that processing time I want to have two lines. One for the current time window and one …

---

## [Access is denied in case of elastic agent in Windows installation](https://discuss.elastic.co/t/access-is-denied-in-case-of-elastic-agent-in-windows-installation/322333)

<div class="topic-metadata">

**Author:** [@lovelike123](https://discuss.elastic.co/u/lovelike123)\
**Replies:** 2\
**Last updated:** [January 4, 2023, 1:17am UTC](https://discuss.elastic.co/t/access-is-denied-in-case-of-elastic-agent-in-windows-installation/322333 "2023-01-04T01:17:34Z")

</div>

Access is denied in case of elastic agent in Windows installation Version of windows server：windows server 2008r2

---

## [Dashboard drilldown does not carry filters from the panel of origin](https://discuss.elastic.co/t/dashboard-drilldown-does-not-carry-filters-from-the-panel-of-origin/319850)

<div class="topic-metadata">

**Author:** [@lpacheco](https://discuss.elastic.co/u/lpacheco)\
**Replies:** 3\
**Last updated:** [December 7, 2022, 12:22am UTC](https://discuss.elastic.co/t/dashboard-drilldown-does-not-carry-filters-from-the-panel-of-origin/319850 "2022-12-07T00:22:35Z")

</div>

I've created 2 dashboards: a macro view and a detailed view. In the macro view I have a series of lens panels that filter the index to show metrics from different AWS services. I configured each panel to drill down into…

---

## [Help with logstash conditional filter](https://discuss.elastic.co/t/help-with-logstash-conditional-filter/322402)

<div class="topic-metadata">

**Author:** [@RaonyO](https://discuss.elastic.co/u/RaonyO)\
**Replies:** 1\
**Last updated:** [January 3, 2023, 7:49pm UTC](https://discuss.elastic.co/t/help-with-logstash-conditional-filter/322402 "2023-01-03T19:49:48Z")

</div>

Hello, I'm trying to create a filter to drop events that don't have Lateral attack or Vulnerability exploit attack in the message field. but it is giving error, I would like to know what is wrong and what is the correct …

---

## [Elastic with salesforce integration](https://discuss.elastic.co/t/elastic-with-salesforce-integration/320851)

<div class="topic-metadata">

**Author:** [@Siva\_Suneel](https://discuss.elastic.co/u/Siva_Suneel)\
**Replies:** 1\
**Last updated:** [January 3, 2023, 7:32pm UTC](https://discuss.elastic.co/t/elastic-with-salesforce-integration/320851 "2023-01-03T19:32:57Z")

</div>

Facing errors while integration with salesforce. Deployment error. Has anyone worked on it before?

---

## [Is it possible to change the field name of 'Show title' using JSON input?](https://discuss.elastic.co/t/is-it-possible-to-change-the-field-name-of-show-title-using-json-input/315844)

<div class="topic-metadata">

**Author:** [@jaheim](https://discuss.elastic.co/u/jaheim)\
**Replies:** 2\
**Last updated:** [October 12, 2022, 4:44am UTC](https://discuss.elastic.co/t/is-it-possible-to-change-the-field-name-of-show-title-using-json-input/315844 "2022-10-12T04:44:15Z")

</div>

Hi! I add Split group in Buckets in Metric of Kibana. Aggregation is set to Terms. And I enable 'Show title'. The values of Field are used as the name of Show title. (0, 1, 2) I want to change the name. For example, 0…

---

## [Logstash pipeline with input+ filter to one output and other without filter to different output](https://discuss.elastic.co/t/logstash-pipeline-with-input-filter-to-one-output-and-other-without-filter-to-different-output/322350)

<div class="topic-metadata">

**Author:** [@shadu88](https://discuss.elastic.co/u/shadu88)\
**Replies:** 6\
**Last updated:** [January 3, 2023, 4:05pm UTC](https://discuss.elastic.co/t/logstash-pipeline-with-input-filter-to-one-output-and-other-without-filter-to-different-output/322350 "2023-01-03T16:05:08Z")

</div>

Hello Elkan s I wish you a happy new year!! Hope all are doings well. My scenario: collecting logs on port 9600 and adding filter to forward the logs to qradar I need to add one more output of azure sentinel without …

---

## [Query which return number range](https://discuss.elastic.co/t/query-which-return-number-range/322349)

<div class="topic-metadata">

**Author:** [@Serhii\_Maistruk](https://discuss.elastic.co/u/Serhii_Maistruk)\
**Replies:** 1\
**Last updated:** [January 3, 2023, 3:57pm UTC](https://discuss.elastic.co/t/query-which-return-number-range/322349 "2023-01-03T15:57:02Z")

</div>

Hi there, maybe someone has an idea if i'm able to do following query using kibana vizualization: I have huge index tag filled with phone numbers, and i need to check if they are "sequential". For example, we have n…

---

## [Kibana Security Analyst Lab Issue](https://discuss.elastic.co/t/kibana-security-analyst-lab-issue/322391)

<div class="topic-metadata">

**Author:** [@telowery](https://discuss.elastic.co/u/telowery)\
**Replies:** 0\
**Last updated:** [January 3, 2023, 3:14pm UTC](https://discuss.elastic.co/t/kibana-security-analyst-lab-issue/322391 "2023-01-03T15:14:51Z")

</div>

I'm taking the Kibana Security Analyst On-Demand course and attempting "Lab 1: Kibana for Operators Basic Visualizations: Data Table". I recieve an error on Step 7. "Drop down the Aggregation menu, scroll to the bottom …

---

## [Data Loss when cluster has hit Watermark](https://discuss.elastic.co/t/data-loss-when-cluster-has-hit-watermark/322389)

<div class="topic-metadata">

**Author:** [@jobypm](https://discuss.elastic.co/u/jobypm)\
**Replies:** 1\
**Last updated:** [January 3, 2023, 3:09pm UTC](https://discuss.elastic.co/t/data-loss-when-cluster-has-hit-watermark/322389 "2023-01-03T15:09:57Z")

</div>

If a cluster hits watermark and gets rectified few hrs later, will there be data loss for the duration when the cluster was readonly? If there is data lost, is there a way we can retrigger using any parameter in filebea…

---

## [Question on kv filter](https://discuss.elastic.co/t/question-on-kv-filter/322388)

<div class="topic-metadata">

**Author:** [@moberreiter](https://discuss.elastic.co/u/moberreiter)\
**Replies:** 1\
**Last updated:** [January 3, 2023, 3:09pm UTC](https://discuss.elastic.co/t/question-on-kv-filter/322388 "2023-01-03T15:09:05Z")

</div>

Hello everyone! I have a log from syslog which logstash should parse: Source: Jan 3 10:14:40 123.123.123.123 {"zone\_src":"SRC","zone\_dst":"DST","reason":"rule","rule\_id":12345,"rule\_description":"Rule Description","a…

---

## [Help my please realized clarifying filtering](https://discuss.elastic.co/t/help-my-please-realized-clarifying-filtering/322385)

<div class="topic-metadata">

**Author:** [@Parano9I](https://discuss.elastic.co/u/Parano9I)\
**Replies:** 1\
**Last updated:** [January 3, 2023, 2:59pm UTC](https://discuss.elastic.co/t/help-my-please-realized-clarifying-filtering/322385 "2023-01-03T14:59:05Z")

</div>

GET original\_docs/\_search { "\_source": \[ "styles", "production\_date\_start" \], "from": 20, "size": 20, "query": { "bool": { "filter": \[ { "nested": { "path": "styl…

---

## [How to extend /var file partition](https://discuss.elastic.co/t/how-to-extend-var-file-partition/322305)

<div class="topic-metadata">

**Author:** [@Kosala\_Randika\_Paran](https://discuss.elastic.co/u/Kosala_Randika_Paran)\
**Replies:** 7\
**Last updated:** [January 3, 2023, 2:57pm UTC](https://discuss.elastic.co/t/how-to-extend-var-file-partition/322305 "2023-01-03T14:57:36Z")

</div>

The /dev/mapper/centos-var partition got full Can anyone suggest a solution for extending it or any solution?

---

## [How to present score of current month and month -1 at one Lens table](https://discuss.elastic.co/t/how-to-present-score-of-current-month-and-month-1-at-one-lens-table/322306)

<div class="topic-metadata">

**Author:** [@przemek\_ironcode](https://discuss.elastic.co/u/przemek_ironcode)\
**Replies:** 1\
**Last updated:** [January 3, 2023, 2:28pm UTC](https://discuss.elastic.co/t/how-to-present-score-of-current-month-and-month-1-at-one-lens-table/322306 "2023-01-03T14:28:53Z")

</div>

Hello All, I have a problem displaying data in the Lens table. I want to display the score of the current month, month -1, and the difference between these scores. Below is a sample table. Thanks in advance for your he…

---

## [Increase Data count in elastic](https://discuss.elastic.co/t/increase-data-count-in-elastic/322292)

<div class="topic-metadata">

**Author:** [@khaled7](https://discuss.elastic.co/u/khaled7)\
**Replies:** 1\
**Last updated:** [January 3, 2023, 2:18pm UTC](https://discuss.elastic.co/t/increase-data-count-in-elastic/322292 "2023-01-03T14:18:08Z")

</div>

Hello, i've integrate fortigate firewall with logstash and forward logs to elasticsearch and visualize with kibana, th log count stopped after docs count : 117026 i want to increase index data

---

## [Export Metrics to csv](https://discuss.elastic.co/t/export-metrics-to-csv/320267)

<div class="topic-metadata">

**Author:** [@erloti](https://discuss.elastic.co/u/erloti)\
**Replies:** 2\
**Last updated:** [January 3, 2023, 2:03pm UTC](https://discuss.elastic.co/t/export-metrics-to-csv/320267 "2023-01-03T14:03:37Z")

</div>

Hello, I have one dashboard with lot of different metrics (simple counts) and filters (time range and data list). I would like to know the best way to export those values in a csv file with the correct filter. I can't…

---

## [Reuse APM Data on Analytics Dashboard](https://discuss.elastic.co/t/reuse-apm-data-on-analytics-dashboard/322286)

<div class="topic-metadata">

**Author:** [@Bayu\_Aji](https://discuss.elastic.co/u/Bayu_Aji)\
**Replies:** 0\
**Last updated:** [January 2, 2023, 7:03am UTC](https://discuss.elastic.co/t/reuse-apm-data-on-analytics-dashboard/322286 "2023-01-02T07:03:16Z")

</div>

Hi Is Elastic provide mechanism to allowing me export or reuse visualize data from APM (especially TPM data) to display on Analytics Dashboard? Thank you Best Regards Bayu Aji

---

## [\_jsonparsefailure with filebeat and logstash](https://discuss.elastic.co/t/jsonparsefailure-with-filebeat-and-logstash/322356)

<div class="topic-metadata">

**Author:** [@Lynow](https://discuss.elastic.co/u/Lynow)\
**Replies:** 10\
**Last updated:** [January 3, 2023, 1:43pm UTC](https://discuss.elastic.co/t/jsonparsefailure-with-filebeat-and-logstash/322356 "2023-01-03T13:43:08Z")

</div>

Hello, I use Filebeat to fetch data from Wazuh (HIDS) and send alerts to Logstash. Then Logstash sends its data to ES and everything usually works fine. However, sometimes after being away for a few days, I look on Ki…

---

## [Maximum requests per seconde on elasticsearch node](https://discuss.elastic.co/t/maximum-requests-per-seconde-on-elasticsearch-node/322369)

<div class="topic-metadata">

**Author:** [@b\_Ensberg](https://discuss.elastic.co/u/b_Ensberg)\
**Replies:** 2\
**Last updated:** [January 3, 2023, 1:36pm UTC](https://discuss.elastic.co/t/maximum-requests-per-seconde-on-elasticsearch-node/322369 "2023-01-03T13:36:03Z")

</div>

I installed elasticseach on a linux server, I have a single node of it. I have a csv file of several tens of thousands of lines which contains IDs, the goal is to iterate over this file and retrieve the data from the ela…

---

## [Kbn-ui-shared-deps-npm.dll.js blocked by meraki](https://discuss.elastic.co/t/kbn-ui-shared-deps-npm-dll-js-blocked-by-meraki/315519)

<div class="topic-metadata">

**Author:** [@NashSLX](https://discuss.elastic.co/u/NashSLX)\
**Replies:** 3\
**Last updated:** [November 8, 2022, 3:09pm UTC](https://discuss.elastic.co/t/kbn-ui-shared-deps-npm-dll-js-blocked-by-meraki/315519 "2022-11-08T15:09:27Z")

</div>

Hey everyone! Recently we've been having issues connecting to kibana under some circumstances: After not seeing anything in the server logs, we realized something seemed to be blocked in the console: And then IT…

---

## [Logstash conditional check if filed exist then replace timestamp value with another fileds timestamp](https://discuss.elastic.co/t/logstash-conditional-check-if-filed-exist-then-replace-timestamp-value-with-another-fileds-timestamp/322311)

<div class="topic-metadata">

**Author:** [@PRASHANT\_MEHTA](https://discuss.elastic.co/u/PRASHANT_MEHTA)\
**Replies:** 2\
**Last updated:** [January 3, 2023, 12:45pm UTC](https://discuss.elastic.co/t/logstash-conditional-check-if-filed-exist-then-replace-timestamp-value-with-another-fileds-timestamp/322311 "2023-01-03T12:45:14Z")

</div>

Hello All, I'm stuck in how to implement conditional check in logstash and how would it be implemented correctly. Usecase:I have data coming in my index with multiple fields value,I'd like to send data to elastic wher…

[Previous page](https://discuss.elastic.co/tag/none.md?no_tags=true&page=464)

[Next page](https://discuss.elastic.co/tag/none.md?no_tags=true&page=466)
