# \#none

**URL:** https://discuss.elastic.co/tag/none.md?no_tags=true&page=467

[Latest](https://discuss.elastic.co/latest.md) · [Categories](https://discuss.elastic.co/categories.md) · [Tags](https://discuss.elastic.co/tags.md)

**Page:** 468

---

## [Integrate Fortigate with Logstash](https://discuss.elastic.co/t/integrate-fortigate-with-logstash/322262)

<div class="topic-metadata">

**Author:** [@khaled7](https://discuss.elastic.co/u/khaled7)\
**Replies:** 0\
**Last updated:** [January 1, 2023, 12:51pm UTC](https://discuss.elastic.co/t/integrate-fortigate-with-logstash/322262 "2023-01-01T12:51:56Z")

</div>

Hello Team can anyone tell me a way or video explain how to integrate fortigate logs with logstash and elasticsearch and a way to make it appear in kibana i have elasticsearch 7.17.6 Kibana 7.17.6 Logstash 7.17.6 T…

---

## [Subtract timestamps from logs basis a field and show as a view on dashboard](https://discuss.elastic.co/t/subtract-timestamps-from-logs-basis-a-field-and-show-as-a-view-on-dashboard/317718)

<div class="topic-metadata">

**Author:** [@Murali\_Y](https://discuss.elastic.co/u/Murali_Y)\
**Replies:** 3\
**Last updated:** [November 7, 2022, 6:58am UTC](https://discuss.elastic.co/t/subtract-timestamps-from-logs-basis-a-field-and-show-as-a-view-on-dashboard/317718 "2022-11-07T06:58:22Z")

</div>

Apologies for reposting this. As a newbie to Kiabana, I couldn't achieve the earlier proposed solution from Kibana views. Can someone please guide me how and where to add equation or add code to achieve below? Any snippe…

---

## [How to get api url to perform this action from my mobile app](https://discuss.elastic.co/t/how-to-get-api-url-to-perform-this-action-from-my-mobile-app/318254)

<div class="topic-metadata">

**Author:** [@Gilles\_GNANAGBE](https://discuss.elastic.co/u/Gilles_GNANAGBE)\
**Replies:** 1\
**Last updated:** [November 7, 2022, 6:01am UTC](https://discuss.elastic.co/t/how-to-get-api-url-to-perform-this-action-from-my-mobile-app/318254 "2022-11-07T06:01:41Z")

</div>

Example : DELETE index PUT index/\_doc/1 { "foo": "bar" } GET index/\_search { "query": { "match": { "foo": "bar" } } } from what api url can i perform this from my mobile app ? I'm very new in thi…

---

## [Kibana Visualization Bar/Line color not stable](https://discuss.elastic.co/t/kibana-visualization-bar-line-color-not-stable/316054)

<div class="topic-metadata">

**Author:** [@PRASHANT\_MEHTA](https://discuss.elastic.co/u/PRASHANT_MEHTA)\
**Replies:** 2\
**Last updated:** [October 10, 2022, 5:37am UTC](https://discuss.elastic.co/t/kibana-visualization-bar-line-color-not-stable/316054 "2022-10-10T05:37:52Z")

</div>

Hello All, I want to make a visual with stable bar colors but colors are changing once i add those visuals on dashboard. And also they change when i try to change them from dashboard or from inside the visual. Is there …

---

## [Cisco FTD cisco.ftd.security Unknown Field Search](https://discuss.elastic.co/t/cisco-ftd-cisco-ftd-security-unknown-field-search/320814)

<div class="topic-metadata">

**Author:** [@cmenuey](https://discuss.elastic.co/u/cmenuey)\
**Replies:** 2\
**Last updated:** [December 31, 2022, 6:27pm UTC](https://discuss.elastic.co/t/cisco-ftd-cisco-ftd-security-unknown-field-search/320814 "2022-12-31T18:27:35Z")

</div>

Hi all, I'm trying to figure out the best way I can build some dashboards or perform searches against the data field cisco.ftd.security from the Cisco FTD integration. When I attempt to search any of the terms in this f…

---

## [Elastic search: running with the root UID is forbidden](https://discuss.elastic.co/t/elastic-search-running-with-the-root-uid-is-forbidden/322221)

<div class="topic-metadata">

**Author:** [@gopublog](https://discuss.elastic.co/u/gopublog)\
**Replies:** 2\
**Last updated:** [December 31, 2022, 6:22pm UTC](https://discuss.elastic.co/t/elastic-search-running-with-the-root-uid-is-forbidden/322221 "2022-12-31T18:22:41Z")

</div>

I am trying to install elasticsearch in my aks cluster and it is failing. I have followed the below steps: root@developer1:~/elasticsearch# git clone https://github.com/elastic/helm-charts.git Cloning into 'helm-charts…

---

## [Elasticsearch connection problem in elassandra](https://discuss.elastic.co/t/elasticsearch-connection-problem-in-elassandra/322236)

<div class="topic-metadata">

**Author:** [@priyankaksa](https://discuss.elastic.co/u/priyankaksa)\
**Replies:** 3\
**Last updated:** [December 31, 2022, 2:48pm UTC](https://discuss.elastic.co/t/elasticsearch-connection-problem-in-elassandra/322236 "2022-12-31T14:48:36Z")

</div>

I am new to Elassandra. I want to make setup(windows 10) and hit queries from Elasticsearch url. I have installed Elassandra and start it is working fine but am not able to access Elasticsearch url. I also tried to c…

---

## [How to give shorter hit a higher score?](https://discuss.elastic.co/t/how-to-give-shorter-hit-a-higher-score/322245)

<div class="topic-metadata">

**Author:** [@JohnDope](https://discuss.elastic.co/u/JohnDope)\
**Replies:** 0\
**Last updated:** [December 31, 2022, 2:07pm UTC](https://discuss.elastic.co/t/how-to-give-shorter-hit-a-higher-score/322245 "2022-12-31T14:07:10Z")

</div>

I am building a ngram search example with ES. Is is possible to take account the shortest length of all the hits? Here's an example: Documents: {"aliases": \["ElonMuskTesla", "ElonTesla"\]} {"aliases": \["ElonMusk"\]} De…

---

## [Color code table row and graph bar depending depending on a threshold](https://discuss.elastic.co/t/color-code-table-row-and-graph-bar-depending-depending-on-a-threshold/318233)

<div class="topic-metadata">

**Author:** [@Murali\_Y](https://discuss.elastic.co/u/Murali_Y)\
**Replies:** 5\
**Last updated:** [November 6, 2022, 5:25pm UTC](https://discuss.elastic.co/t/color-code-table-row-and-graph-bar-depending-depending-on-a-threshold/318233 "2022-11-06T17:25:59Z")

</div>

Referring below/attached table screenshot: We want to show different color coding of a bar graph (or) a row item in a table depending on a threshold value. Threshold is not same for processes mentioned under 'processes…

---

## [Kibana is Not Loading Properly using Nginx reverse Proxy](https://discuss.elastic.co/t/kibana-is-not-loading-properly-using-nginx-reverse-proxy/317098)

<div class="topic-metadata">

**Author:** [@sugriv\_1605](https://discuss.elastic.co/u/sugriv_1605)\
**Replies:** 2\
**Last updated:** [November 6, 2022, 3:16pm UTC](https://discuss.elastic.co/t/kibana-is-not-loading-properly-using-nginx-reverse-proxy/317098 "2022-11-06T15:16:47Z")

</div>

Hi, I am hosting Kibana using Nginx reverse proxy but the in browser getting 404 /spaces/enter output. Kibana is running on http://IP:5601 Elasticsearch Open on http://IP:9200 I am able to open Kibana on my servers u…

---

## [Logstash pipeline High avliliblity](https://discuss.elastic.co/t/logstash-pipeline-high-avliliblity/321965)

<div class="topic-metadata">

**Author:** [@m3bgwad](https://discuss.elastic.co/u/m3bgwad)\
**Replies:** 13\
**Last updated:** [December 31, 2022, 1:30am UTC](https://discuss.elastic.co/t/logstash-pipeline-high-avliliblity/321965 "2022-12-31T01:30:02Z")

</div>

hello Everyone, How to achieve The Logstash Pipeline HA? I have 3 Nodes if any node opening count of pipeline after that the node is down what happen? what is the solutions to achieve the HA?

---

## [Could not retrieve Elasticsearch deprecation issues](https://discuss.elastic.co/t/could-not-retrieve-elasticsearch-deprecation-issues/315274)

<div class="topic-metadata">

**Author:** [@mikewillis](https://discuss.elastic.co/u/mikewillis)\
**Replies:** 4\
**Last updated:** [November 5, 2022, 4:31pm UTC](https://discuss.elastic.co/t/could-not-retrieve-elasticsearch-deprecation-issues/315274 "2022-11-05T16:31:00Z")

</div>

I've got a test cluster with a separate monitoring cluster and a production cluster with a separate monitoring cluster. "Review deprecated settings and resolve issues" in the Kibana Upgrade Assistant works on all four cl…

---

## [Kibana scripted field is not showing value](https://discuss.elastic.co/t/kibana-scripted-field-is-not-showing-value/322183)

<div class="topic-metadata">

**Author:** [@gloria123451](https://discuss.elastic.co/u/gloria123451)\
**Replies:** 2\
**Last updated:** [December 30, 2022, 10:23pm UTC](https://discuss.elastic.co/t/kibana-scripted-field-is-not-showing-value/322183 "2022-12-30T22:23:40Z")

</div>

I am new to kibana.. I am trying to create a scripted field, when I run the script nothing is displayed in the result. however, when I filter the field I get the expected result.. why is this not propagating?... what …

---

## [Iptables intergrations Processors](https://discuss.elastic.co/t/iptables-intergrations-processors/321289)

<div class="topic-metadata">

**Author:** [@david-a76](https://discuss.elastic.co/u/david-a76)\
**Replies:** 1\
**Last updated:** [December 30, 2022, 7:52pm UTC](https://discuss.elastic.co/t/iptables-intergrations-processors/321289 "2022-12-30T19:52:52Z")

</div>

I wourd like to add a field when source ip is one of 192.168.100.0/24 or 172.17.100.0/24 subnet So i added this precocessor in iptables integration field on my agnet policy but It's totaly ignored. That's wrong with …

---

## [Kibana not starting. \[.kibana\_task\_manager\] Action failed with 'Request timed out'](https://discuss.elastic.co/t/kibana-not-starting-kibana-task-manager-action-failed-with-request-timed-out/317898)

<div class="topic-metadata">

**Author:** [@rkimera](https://discuss.elastic.co/u/rkimera)\
**Replies:** 7\
**Last updated:** [November 5, 2022, 11:31am UTC](https://discuss.elastic.co/t/kibana-not-starting-kibana-task-manager-action-failed-with-request-timed-out/317898 "2022-11-05T11:31:58Z")

</div>

I am able to run the elasticsearch server at port 9200. But this kibana server is failing to start throwing an error. I have downgraded to version 7. x.x from 8. x.x but still get the same error. I am using a Mac os. \</…

---

## [ESSingleNodeTestCase / unit tests / official recommendations?](https://discuss.elastic.co/t/essinglenodetestcase-unit-tests-official-recommendations/322222)

<div class="topic-metadata">

**Author:** [@PzYon](https://discuss.elastic.co/u/PzYon)\
**Replies:** 2\
**Last updated:** [December 30, 2022, 6:19pm UTC](https://discuss.elastic.co/t/essinglenodetestcase-unit-tests-official-recommendations/322222 "2022-12-30T18:19:33Z")

</div>

I asked this question regarding unit tests a couple of weeks ago: Best practices for automated tests Now I would like to come back to the ESSingleNodeTestCase-class. I managed to get it to start an elastic server with …

---

## [Need to apply filter to KIBANA dashboard automatically through html](https://discuss.elastic.co/t/need-to-apply-filter-to-kibana-dashboard-automatically-through-html/322122)

<div class="topic-metadata">

**Author:** [@Shashank02](https://discuss.elastic.co/u/Shashank02)\
**Replies:** 4\
**Last updated:** [December 30, 2022, 4:41pm UTC](https://discuss.elastic.co/t/need-to-apply-filter-to-kibana-dashboard-automatically-through-html/322122 "2022-12-30T16:41:59Z")

</div>

My idea is that I have 2 cards - Virat Kohli and Leo Messi. And in the dashboard, I have 1 dashboard named "main" and in that, I have a filter called "event". In the "event" I have given 2 topics - viratkohli and lionelm…

---

## [\_delete\_by\_query with timestamp](https://discuss.elastic.co/t/delete-by-query-with-timestamp/318157)

<div class="topic-metadata">

**Author:** [@Yiming\_Gong](https://discuss.elastic.co/u/Yiming_Gong)\
**Replies:** 8\
**Last updated:** [December 30, 2022, 3:46pm UTC](https://discuss.elastic.co/t/delete-by-query-with-timestamp/318157 "2022-12-30T15:46:17Z")

</div>

The data I uploaded to Elasticsearch database is like the following { "took" : 0, "timed\_out" : false, "\_shards" : { "total" : 1, "successful" : 1, "skipped" : 0, "failed" : 0 }, "hits" : { …

---

## [Login to kibana iframe using ApiKey](https://discuss.elastic.co/t/login-to-kibana-iframe-using-apikey/322147)

<div class="topic-metadata">

**Author:** [@dinesh.mandrekar](https://discuss.elastic.co/u/dinesh.mandrekar)\
**Replies:** 1\
**Last updated:** [December 30, 2022, 3:20pm UTC](https://discuss.elastic.co/t/login-to-kibana-iframe-using-apikey/322147 "2022-12-30T15:20:48Z")

</div>

We want to use Attribute-Based Access Control for accessing kibana dashboard. For this we are generating multiple ApiKeys with different set of security attributes. We want to embed the kibana iframe into our applicatio…

---

## [Best practices for automated tests](https://discuss.elastic.co/t/best-practices-for-automated-tests/320872)

<div class="topic-metadata">

**Author:** [@PzYon](https://discuss.elastic.co/u/PzYon)\
**Replies:** 3\
**Last updated:** [December 30, 2022, 2:47pm UTC](https://discuss.elastic.co/t/best-practices-for-automated-tests/320872 "2022-12-30T14:47:34Z")

</div>

In our (Java) unit tests we would like to test the integration of Elasticsearch (e.g. do queries work, can docs be indexed correctly, etc.). I'm wondering if there are any best practices or recommendations regarding this…

---

## [Embedded code not working](https://discuss.elastic.co/t/embedded-code-not-working/320307)

<div class="topic-metadata">

**Author:** [@Akjal](https://discuss.elastic.co/u/Akjal)\
**Replies:** 1\
**Last updated:** [December 2, 2022, 5:17pm UTC](https://discuss.elastic.co/t/embedded-code-not-working/320307 "2022-12-02T17:17:21Z")

</div>

Hello there, Having some issues rendering the embedded iframe code link from kibana to other platforms. For some reason it works when I run it on a local static file, but does not work when I test it on public platfor…

---

## [We are getting "unindexed fields or ignored values cannot be searched"](https://discuss.elastic.co/t/we-are-getting-unindexed-fields-or-ignored-values-cannot-be-searched/322148)

<div class="topic-metadata">

**Author:** [@upreddy](https://discuss.elastic.co/u/upreddy)\
**Replies:** 1\
**Last updated:** [December 30, 2022, 2:18pm UTC](https://discuss.elastic.co/t/we-are-getting-unindexed-fields-or-ignored-values-cannot-be-searched/322148 "2022-12-30T14:18:03Z")

</div>

Hi, In Kibana (7.16.2) discover there are so many fields whose format is text which is not searchable like if we hover on the field it gives below message "unindexed fields or ignored values cannot be searched". But s…

---

## [Not able to get Source filename in the logstash output](https://discuss.elastic.co/t/not-able-to-get-source-filename-in-the-logstash-output/322130)

<div class="topic-metadata">

**Author:** [@Ramesh\_Perumal](https://discuss.elastic.co/u/Ramesh_Perumal)\
**Replies:** 2\
**Last updated:** [December 30, 2022, 10:57am UTC](https://discuss.elastic.co/t/not-able-to-get-source-filename-in-the-logstash-output/322130 "2022-12-30T10:57:43Z")

</div>

Hi, We are using filebeat 7.10.2 and logstash 8.10.4. Filebeat transfer the files from Machine A (Filebeat) to Machine B (Logstash) and Logstash writes the same in machine B's path (/va/pm/sfile/%{hostname}/%{\[log\]\[file…

---

## [로그스태시 동작이 안 됩니다](https://discuss.elastic.co/t/topic/322200)

<div class="topic-metadata">

**Author:** [@Horang](https://discuss.elastic.co/u/Horang)\
**Replies:** 0\
**Last updated:** [December 30, 2022, 8:58am UTC](https://discuss.elastic.co/t/topic/322200 "2022-12-30T08:58:20Z")

</div>

로그스태시 파이프라인 설정파일은 다음과 같습니다 path를 여러 개 지정해서 가져오는데요 파이프라인 ID가 jdbc\_app\_tr\_mon, jdbc\_app\_bm\_tr\_mon 두 개는 동작하지가 않네요 나머지는 데이터 잘 가져옵니다 jdbc 이용해서 오라클 DB 붙어서 sql로 들고 오고 있습니다. es 로그를 봐도 별다른 오류가 뜨지도 않고, 파이프라인 연결은 성공했다고 남습니다. …

---

## [Add custom index in Observability/alerts section](https://discuss.elastic.co/t/add-custom-index-in-observability-alerts-section/318088)

<div class="topic-metadata">

**Author:** [@federica.forti](https://discuss.elastic.co/u/federica.forti)\
**Replies:** 2\
**Last updated:** [November 4, 2022, 12:55pm UTC](https://discuss.elastic.co/t/add-custom-index-in-observability-alerts-section/318088 "2022-11-04T12:55:45Z")

</div>

Hi, do you know if is it possible, working on Kibana's Advanced Settings (or otherwise), to consider in the Alerts (Observability) section also alerts that trigger from custom indexes, in order to have a single dashboar…

---

## [How to Show multiple project log in differnt dashborad?](https://discuss.elastic.co/t/how-to-show-multiple-project-log-in-differnt-dashborad/322191)

<div class="topic-metadata">

**Author:** [@manish2](https://discuss.elastic.co/u/manish2)\
**Replies:** 0\
**Last updated:** [December 30, 2022, 6:44am UTC](https://discuss.elastic.co/t/how-to-show-multiple-project-log-in-differnt-dashborad/322191 "2022-12-30T06:44:56Z")

</div>

please anyone help me!... in my dashboard i get all log of different project but now i am want to filter all log of multiple project in differnet dashboard......i am new in ELK . Help me !

---

## [Your Query Is Taking While-Kibana/Report download (Aggregation on documents with unique id more than 20000)](https://discuss.elastic.co/t/your-query-is-taking-while-kibana-report-download-aggregation-on-documents-with-unique-id-more-than-20000/322156)

<div class="topic-metadata">

**Author:** [@PRASHANT\_MEHTA](https://discuss.elastic.co/u/PRASHANT_MEHTA)\
**Replies:** 1\
**Last updated:** [December 29, 2022, 4:35pm UTC](https://discuss.elastic.co/t/your-query-is-taking-while-kibana-report-download-aggregation-on-documents-with-unique-id-more-than-20000/322156 "2022-12-29T16:35:06Z")

</div>

Hello All, Issue 1: In my dashboard I've intrgrated 5 visuals,4 bar charts and 1 enhanced data table. While I select time range for 2 week,it fetches around 18000 unique documents that is visible in enhanced data tabl…

---

## [About Sending Logs from External SIEM (include ArcSight, Qradar, Splunk, ELK...) to Receiver Elastic Agent or Logstash with method TCP/UDP](https://discuss.elastic.co/t/about-sending-logs-from-external-siem-include-arcsight-qradar-splunk-elk-to-receiver-elastic-agent-or-logstash-with-method-tcp-udp/322139)

<div class="topic-metadata">

**Author:** [@Louis\_Wales](https://discuss.elastic.co/u/Louis_Wales)\
**Replies:** 4\
**Last updated:** [December 30, 2022, 3:45am UTC](https://discuss.elastic.co/t/about-sending-logs-from-external-siem-include-arcsight-qradar-splunk-elk-to-receiver-elastic-agent-or-logstash-with-method-tcp-udp/322139 "2022-12-30T03:45:10Z")

</div>

Hi everyone, I have a question when should I use TCP, and when should I use UDP to forward logs? Or is it better to use TCP or UDP? The situation is about Sending Logs from External SIEM (include ArcSight, Qradar, Splun…

---

## [After restart Ubuntu , Elastic does not work](https://discuss.elastic.co/t/after-restart-ubuntu-elastic-does-not-work/322065)

<div class="topic-metadata">

**Author:** [@Mursel](https://discuss.elastic.co/u/Mursel)\
**Replies:** 1\
**Last updated:** [December 30, 2022, 2:20am UTC](https://discuss.elastic.co/t/after-restart-ubuntu-elastic-does-not-work/322065 "2022-12-30T02:20:17Z")

</div>

Hello. I have an issue. Elastic installed on Ubuntu (ESXI). I have restarted ubuntu, but after that, I can't see any logs in Kibana. In the terminal, I can see logs (syslog).

---

## [Advice on paging with Parent-Child relation (And grouping)](https://discuss.elastic.co/t/advice-on-paging-with-parent-child-relation-and-grouping/322180)

<div class="topic-metadata">

**Author:** [@CJohn](https://discuss.elastic.co/u/CJohn)\
**Replies:** 0\
**Last updated:** [December 29, 2022, 10:53pm UTC](https://discuss.elastic.co/t/advice-on-paging-with-parent-child-relation-and-grouping/322180 "2022-12-29T22:53:28Z")

</div>

Hi, I am having a few issues in the returning the right paged results with a parent - child relationship. There are two scenarios in which I display the data that impact the shape returning from elastic. For the momen…

[Previous page](https://discuss.elastic.co/tag/none.md?no_tags=true&page=466)

[Next page](https://discuss.elastic.co/tag/none.md?no_tags=true&page=468)
