# \#none

**URL:** https://discuss.elastic.co/tag/none.md?no_tags=true&page=468

[Latest](https://discuss.elastic.co/latest.md) · [Categories](https://discuss.elastic.co/categories.md) · [Tags](https://discuss.elastic.co/tags.md)

**Page:** 469

---

## [Prebuilt security detection rules not showing any alters](https://discuss.elastic.co/t/prebuilt-security-detection-rules-not-showing-any-alters/320541)

<div class="topic-metadata">

**Author:** [@satendra1987](https://discuss.elastic.co/u/satendra1987)\
**Replies:** 1\
**Last updated:** [December 30, 2022, 12:00am UTC](https://discuss.elastic.co/t/prebuilt-security-detection-rules-not-showing-any-alters/320541 "2022-12-30T00:00:52Z")

</div>

Hi, i am trying to work on elasticsearch security. i have installed elastic agent using fleet. Now i have enabled prebuilt security detection rules and status shows as successful when rules are executed however i dont s…

---

## [Trying to understand a previous setup/pipeline](https://discuss.elastic.co/t/trying-to-understand-a-previous-setup-pipeline/322175)

<div class="topic-metadata">

**Author:** [@jason3](https://discuss.elastic.co/u/jason3)\
**Replies:** 1\
**Last updated:** [December 29, 2022, 9:52pm UTC](https://discuss.elastic.co/t/trying-to-understand-a-previous-setup-pipeline/322175 "2022-12-29T21:52:07Z")

</div>

Hello all, Im trying to understand and learn Elastic while working though and improving some bad setups of my predecessors. I was hoping you could help with confirming my understanding after what I have been reading. …

---

## [Minimum files needed for search only?](https://discuss.elastic.co/t/minimum-files-needed-for-search-only/322056)

<div class="topic-metadata">

**Author:** [@Cliffster](https://discuss.elastic.co/u/Cliffster)\
**Replies:** 5\
**Last updated:** [December 29, 2022, 9:22pm UTC](https://discuss.elastic.co/t/minimum-files-needed-for-search-only/322056 "2022-12-29T21:22:44Z")

</div>

Our non profit (Chipster.org) is creating offline educational collections for people who lack internet. The collections will be distributed on flash drives and designed so that a user can copy their collection freely t…

---

## [I have Kibana Running and Elasticsearch also running but I can not get to the Kibana URL](https://discuss.elastic.co/t/i-have-kibana-running-and-elasticsearch-also-running-but-i-can-not-get-to-the-kibana-url/322124)

<div class="topic-metadata">

**Author:** [@Peter\_Lilley](https://discuss.elastic.co/u/Peter_Lilley)\
**Replies:** 4\
**Last updated:** [December 29, 2022, 6:00pm UTC](https://discuss.elastic.co/t/i-have-kibana-running-and-elasticsearch-also-running-but-i-can-not-get-to-the-kibana-url/322124 "2022-12-29T18:00:28Z")

</div>

I am using an Ubuntu VM hosted in Azure, I have the ports 9200 open and 5601 open. When i go to \<MY\_IP\>:9200 i get this "name" : "node-YBA", "cluster\_name" : "my-application", "cluster\_uuid" : "PIsS2fqrR62icScNqyi…

---

## [Creating Custom dashboard with grouping and math function](https://discuss.elastic.co/t/creating-custom-dashboard-with-grouping-and-math-function/322115)

<div class="topic-metadata">

**Author:** [@vamsi2](https://discuss.elastic.co/u/vamsi2)\
**Replies:** 1\
**Last updated:** [December 29, 2022, 5:11pm UTC](https://discuss.elastic.co/t/creating-custom-dashboard-with-grouping-and-math-function/322115 "2022-12-29T17:11:07Z")

</div>

Hi Is it possible to create a complex custom dashboards with grouping and math functions in elastic ?

---

## [Elastic SIEM Fundamentals Course Kibana will not display data](https://discuss.elastic.co/t/elastic-siem-fundamentals-course-kibana-will-not-display-data/321601)

<div class="topic-metadata">

**Author:** [@tthiry](https://discuss.elastic.co/u/tthiry)\
**Replies:** 1\
**Last updated:** [December 29, 2022, 4:58pm UTC](https://discuss.elastic.co/t/elastic-siem-fundamentals-course-kibana-will-not-display-data/321601 "2022-12-29T16:58:18Z")

</div>

Just starting the SIEM Fundamentals on-demand course. I have logged into Strigo and am trying to access the Kibana instance. The "Loading Elastic" message is displayed but it never displays anything. I've been waiting ov…

---

## [Ingest-attachment not found](https://discuss.elastic.co/t/ingest-attachment-not-found/322150)

<div class="topic-metadata">

**Author:** [@WhatCouldGoWrong](https://discuss.elastic.co/u/WhatCouldGoWrong)\
**Replies:** 7\
**Last updated:** [December 29, 2022, 2:53pm UTC](https://discuss.elastic.co/t/ingest-attachment-not-found/322150 "2022-12-29T14:53:08Z")

</div>

Hi, I'm trying to install the ingest-attachment (using elasticsearch-plugin install ingest-attachment). I'm behind a proxy, so I use this line: sudo CLI\_JAVA\_OPTS="-Dhttp.proxyHost=192.168.0.1 -Dhttp.proxyPort=8080 -D…

---

## [Kibana - unknown configuration key deprecation.skip\_deprecated\_settings](https://discuss.elastic.co/t/kibana-unknown-configuration-key-deprecation-skip-deprecated-settings/321575)

<div class="topic-metadata">

**Author:** [@h0llym0lly](https://discuss.elastic.co/u/h0llym0lly)\
**Replies:** 4\
**Last updated:** [December 29, 2022, 2:19pm UTC](https://discuss.elastic.co/t/kibana-unknown-configuration-key-deprecation-skip-deprecated-settings/321575 "2022-12-29T14:19:44Z")

</div>

I have an instance of Kibana which was not installed via RPM or DEB package. Whole application was started via script and now I wanted to add it to systemd. I am facing this error when I am trying to start kibana via s…

---

## [Type: long fields show wrong values in kibana](https://discuss.elastic.co/t/type-long-fields-show-wrong-values-in-kibana/322154)

<div class="topic-metadata">

**Author:** [@nisow95612](https://discuss.elastic.co/u/nisow95612)\
**Replies:** 7\
**Last updated:** [December 29, 2022, 2:13pm UTC](https://discuss.elastic.co/t/type-long-fields-show-wrong-values-in-kibana/322154 "2022-12-29T14:13:53Z")

</div>

Hello, I have noticed a problem with Kibana. Values with "type": "long" do not display correctly. For example let's take the value "1 671 607 837 241 650 688" displayed in Discover: This is wrong. When I swith to …

---

## [Elasticsearch ingest large of data](https://discuss.elastic.co/t/elasticsearch-ingest-large-of-data/322099)

<div class="topic-metadata">

**Author:** [@m3bgwad](https://discuss.elastic.co/u/m3bgwad)\
**Replies:** 5\
**Last updated:** [December 29, 2022, 1:24pm UTC](https://discuss.elastic.co/t/elasticsearch-ingest-large-of-data/322099 "2022-12-29T13:24:47Z")

</div>

is there capability of Elasticsearch to ingest amount large of data at a rate of 300TB in the year after that archive data in offline storage? what is challenges facing me to ingest that much volume?

---

## [Index created via python not seen in UI and vice-versa](https://discuss.elastic.co/t/index-created-via-python-not-seen-in-ui-and-vice-versa/321923)

<div class="topic-metadata">

**Author:** [@nikhilkvn](https://discuss.elastic.co/u/nikhilkvn)\
**Replies:** 1\
**Last updated:** [December 29, 2022, 1:14pm UTC](https://discuss.elastic.co/t/index-created-via-python-not-seen-in-ui-and-vice-versa/321923 "2022-12-29T13:14:07Z")

</div>

This is weird. Index created via Dev-Console is not seen in the Python-client. Index created via Python-client is not seen on Dev-Console. Both ways I am able to write/Read data. But have to choose only one way I am …

---

## [Ruby Code Exception](https://discuss.elastic.co/t/ruby-code-exception/322155)

<div class="topic-metadata">

**Author:** [@Rohit\_Kumbhar](https://discuss.elastic.co/u/Rohit_Kumbhar)\
**Replies:** 1\
**Last updated:** [December 29, 2022, 12:26pm UTC](https://discuss.elastic.co/t/ruby-code-exception/322155 "2022-12-29T12:26:01Z")

</div>

Hi Team, I am getting Ruby exception occurred: undefined method \`length' for nil error while using the following Ruby Code ruby { code =\> ' names = event.get("\[message\]").split(".") event.set("number\_…

---

## [Logstash pipeline worker stops processing events because of exception](https://discuss.elastic.co/t/logstash-pipeline-worker-stops-processing-events-because-of-exception/322126)

<div class="topic-metadata">

**Author:** [@tcapp24](https://discuss.elastic.co/u/tcapp24)\
**Replies:** 3\
**Last updated:** [December 29, 2022, 1:19am UTC](https://discuss.elastic.co/t/logstash-pipeline-worker-stops-processing-events-because-of-exception/322126 "2022-12-29T01:19:59Z")

</div>

Hello, Currently our beats-dead-letter-queue-processing-pipeline is causing a exception which makes events stop outputting to Elasticsearch: beats-dead-letter-queue-processing-pipeline\] Pipeline worker error, the pipe…

---

## [Logstash Filter for Cisco ASA Source Destination and Communication](https://discuss.elastic.co/t/logstash-filter-for-cisco-asa-source-destination-and-communication/322063)

<div class="topic-metadata">

**Author:** [@Pratik\_Srivastava](https://discuss.elastic.co/u/Pratik_Srivastava)\
**Replies:** 5\
**Last updated:** [December 28, 2022, 9:41pm UTC](https://discuss.elastic.co/t/logstash-filter-for-cisco-asa-source-destination-and-communication/322063 "2022-12-28T21:41:31Z")

</div>

I want to configure logstash filter to see asa logs with communication detail. LOG Sample: Dec 27 02:48:08 Test-FW : %ASA-6-302014: Teardown TCP connection 3505833084 for Test-OUT:192.168.1.10/58538 to Mgmt-IN:192.168.1…

---

## [How to configure ILM hot phase, when cluster has only warm nodes](https://discuss.elastic.co/t/how-to-configure-ilm-hot-phase-when-cluster-has-only-warm-nodes/322118)

<div class="topic-metadata">

**Author:** [@hiruni.insyncit.net](https://discuss.elastic.co/u/hiruni.insyncit.net)\
**Replies:** 3\
**Last updated:** [December 28, 2022, 8:16pm UTC](https://discuss.elastic.co/t/how-to-configure-ilm-hot-phase-when-cluster-has-only-warm-nodes/322118 "2022-12-28T20:16:34Z")

</div>

Hi, Elasticsearch version: 8.1.2 It has 4 warm nodes(no hot nodes). I want to configure ILM policy in this cluster. So, how can configure hot-warm ILM policy in Elastic cluster which has only warm node. Thank you...…

---

## [Cluster yellow b/c .security-7 index in unassigned state](https://discuss.elastic.co/t/cluster-yellow-b-c-security-7-index-in-unassigned-state/322112)

<div class="topic-metadata">

**Author:** [@Dimitry\_Feigin](https://discuss.elastic.co/u/Dimitry_Feigin)\
**Replies:** 2\
**Last updated:** [December 28, 2022, 7:06pm UTC](https://discuss.elastic.co/t/cluster-yellow-b-c-security-7-index-in-unassigned-state/322112 "2022-12-28T19:06:53Z")

</div>

We started the upgrade of the cluster that was in green state. The upgrade (through ansible) failed on node1 while it was not able to download rpm. We found the issue and fixed. Now the cluster after restart w/o any actu…

---

## [Macos M1 Ventura 13.0.1 Elastic agent install fail](https://discuss.elastic.co/t/macos-m1-ventura-13-0-1-elastic-agent-install-fail/319262)

<div class="topic-metadata">

**Author:** [@xqaiviwjxzw](https://discuss.elastic.co/u/xqaiviwjxzw)\
**Replies:** 9\
**Last updated:** [December 28, 2022, 5:27pm UTC](https://discuss.elastic.co/t/macos-m1-ventura-13-0-1-elastic-agent-install-fail/319262 "2022-12-28T17:27:57Z")

</div>

I installed the elastic agent on macos Ventura 13.0.1 using the command line and the installation failed showing： panic: getwd: invalid argument goroutine 1 \[running\]: github.com/elastic/elastic-agent/internal/pkg/age…

---

## [Restored from snapshoots 2 master nodes but several indecies are in unassigned state](https://discuss.elastic.co/t/restored-from-snapshoots-2-master-nodes-but-several-indecies-are-in-unassigned-state/322113)

<div class="topic-metadata">

**Author:** [@Dimitry\_Feigin](https://discuss.elastic.co/u/Dimitry_Feigin)\
**Replies:** 3\
**Last updated:** [December 28, 2022, 4:57pm UTC](https://discuss.elastic.co/t/restored-from-snapshoots-2-master-nodes-but-several-indecies-are-in-unassigned-state/322113 "2022-12-28T16:57:03Z")

</div>

We had 3 node cluster where all nodes were masters. We accidently deleted 2 master nodes. We restore them from snapshots. However we have several indecies in unassign state:| externalkeyhandler-000005 4 p START…

---

## [Has anyone worked with Language Analyzers, Arabic analyzer in specific?](https://discuss.elastic.co/t/has-anyone-worked-with-language-analyzers-arabic-analyzer-in-specific/316611)

<div class="topic-metadata">

**Author:** [@Hassan\_Abbas](https://discuss.elastic.co/u/Hassan_Abbas)\
**Replies:** 1\
**Last updated:** [December 28, 2022, 3:41pm UTC](https://discuss.elastic.co/t/has-anyone-worked-with-language-analyzers-arabic-analyzer-in-specific/316611 "2022-12-28T15:41:37Z")

</div>

I'm finding difficulties implementing the analyzer on a certain field that will be used in a search function for an Arabic news platform

---

## [Increase ignore above threshold - Kibana UI](https://discuss.elastic.co/t/increase-ignore-above-threshold-kibana-ui/319880)

<div class="topic-metadata">

**Author:** [@Murali\_Y](https://discuss.elastic.co/u/Murali_Y)\
**Replies:** 4\
**Last updated:** [December 28, 2022, 3:30pm UTC](https://discuss.elastic.co/t/increase-ignore-above-threshold-kibana-ui/319880 "2022-12-28T15:30:15Z")

</div>

Hello all, We are using Kibana for logging/viewing/reporting our UiPath BOT logs. But we are unable to view one field on Kibana due to the 256 characters threshold that is set on that field mapping. From How to set the…

---

## [Kibana import error in python](https://discuss.elastic.co/t/kibana-import-error-in-python/320643)

<div class="topic-metadata">

**Author:** [@Shashank02](https://discuss.elastic.co/u/Shashank02)\
**Replies:** 1\
**Last updated:** [December 28, 2022, 2:22pm UTC](https://discuss.elastic.co/t/kibana-import-error-in-python/320643 "2022-12-28T14:22:17Z")

</div>

This is the error I'm getting while I'm trying to create a data view in Kibana using python. I'm trying to create a data view in Kibana cloud. ImportError: cannot import name 'Kibana' from 'kibana'. Can someone help me w…

---

## [Поиск по вложенному nested type](https://discuss.elastic.co/t/nested-type/322102)

<div class="topic-metadata">

**Author:** [@One\_Two](https://discuss.elastic.co/u/One_Two)\
**Replies:** 0\
**Last updated:** [December 28, 2022, 2:13pm UTC](https://discuss.elastic.co/t/nested-type/322102 "2022-12-28T14:13:40Z")

</div>

Здравствуйте, возможно ли в одном запросе сделать две разные query. Изначально мой запрос выглядел так { "query": { "bool": { "must": { "match\_all": {} }, "filter": \[ { …

---

## [Is there any way to add custom date like financial year (01 April to 31 March) in Time filter quick ranges in Kibana 8.5](https://discuss.elastic.co/t/is-there-any-way-to-add-custom-date-like-financial-year-01-april-to-31-march-in-time-filter-quick-ranges-in-kibana-8-5/321977)

<div class="topic-metadata">

**Author:** [@ysattvik](https://discuss.elastic.co/u/ysattvik)\
**Replies:** 4\
**Last updated:** [December 28, 2022, 1:37pm UTC](https://discuss.elastic.co/t/is-there-any-way-to-add-custom-date-like-financial-year-01-april-to-31-march-in-time-filter-quick-ranges-in-kibana-8-5/321977 "2022-12-28T13:37:34Z")

</div>

{ "from": "now-1y/d", "to": "now", "display": "Last 1 year" } Here, can we add a date range like (01 April to 31 March) as Financial Year?

---

## [Is there any way to make some changes in available time picker format or disable some option in Kibana?](https://discuss.elastic.co/t/is-there-any-way-to-make-some-changes-in-available-time-picker-format-or-disable-some-option-in-kibana/322090)

<div class="topic-metadata">

**Author:** [@ysattvik](https://discuss.elastic.co/u/ysattvik)\
**Replies:** 1\
**Last updated:** [December 28, 2022, 1:34pm UTC](https://discuss.elastic.co/t/is-there-any-way-to-make-some-changes-in-available-time-picker-format-or-disable-some-option-in-kibana/322090 "2022-12-28T13:34:12Z")

</div>

In the given image if we want only absolute date not relative section, now section and time section. Is it possible to do this? If possible, then please suggest the way. My second requirement is that in the below …

---

## [API intgrations](https://discuss.elastic.co/t/api-intgrations/321627)

<div class="topic-metadata">

**Author:** [@m3bgwad](https://discuss.elastic.co/u/m3bgwad)\
**Replies:** 4\
**Last updated:** [December 28, 2022, 1:08pm UTC](https://discuss.elastic.co/t/api-intgrations/321627 "2022-12-28T13:08:46Z")

</div>

hello everyone, What is the best way to exploit Elasticsearch RESTful API to integrate with other services can supported APIs?

---

## [How to add an analyzer that can remove duplicate tokens from the analyzed field?](https://discuss.elastic.co/t/how-to-add-an-analyzer-that-can-remove-duplicate-tokens-from-the-analyzed-field/322098)

<div class="topic-metadata">

**Author:** [@hemangr8](https://discuss.elastic.co/u/hemangr8)\
**Replies:** 0\
**Last updated:** [December 28, 2022, 12:45pm UTC](https://discuss.elastic.co/t/how-to-add-an-analyzer-that-can-remove-duplicate-tokens-from-the-analyzed-field/322098 "2022-12-28T12:45:00Z")

</div>

I want to add a token filter in my custom analyzer to remove duplicate tokens in the text field while matching. Eg: Input: "random petrol pump, beside random2 petrol pump" After analyzer: \["random", "petrol", "pump", "…

---

## [Building Kibana Dashboard Dynamically](https://discuss.elastic.co/t/building-kibana-dashboard-dynamically/33713)

<div class="topic-metadata">

**Author:** [@Asad\_Rehman](https://discuss.elastic.co/u/Asad_Rehman)\
**Replies:** 9\
**Last updated:** [June 13, 2017, 12:55am UTC](https://discuss.elastic.co/t/building-kibana-dashboard-dynamically/33713 "2017-06-13T00:55:07Z")

</div>

Hi All, I have some indexes in elasticsearch and I have build my required dashboard with required visualizations in Kibana. My index contains data from different shops regarding their sales and revenues and visualization…

---

## [Limit number of rows count](https://discuss.elastic.co/t/limit-number-of-rows-count/322069)

<div class="topic-metadata">

**Author:** [@ayush-srivastava-ev](https://discuss.elastic.co/u/ayush-srivastava-ev)\
**Replies:** 1\
**Last updated:** [December 28, 2022, 9:42am UTC](https://discuss.elastic.co/t/limit-number-of-rows-count/322069 "2022-12-28T09:42:44Z")

</div>

How we can limit number of rows per page so that we can get horizontal scroll bar. We don't want to limit no. of searches. We are using version 7.5

---

## [Typeがtextのfieldに長文を入れると、\_ignoredになってしまう。](https://discuss.elastic.co/t/type-text-field-ignored/321622)

<div class="topic-metadata">

**Author:** [@humo](https://discuss.elastic.co/u/humo)\
**Replies:** 1\
**Last updated:** [December 28, 2022, 8:45am UTC](https://discuss.elastic.co/t/type-text-field-ignored/321622 "2022-12-28T08:45:23Z")

</div>

mappingで "full\_text\_colum\_ja": { "type": "text", "store": true, "analyzer": "sudachi\_analyzer" }, と定義しているフィールドにある一定の文字数の長文を入れると、 検索結果で、このfieldが自動的に\_ignoreに設定されてしまいます。 \[14\] =\> Array …

---

## [Do I need track\_total\_hits for reindex java api command?](https://discuss.elastic.co/t/do-i-need-track-total-hits-for-reindex-java-api-command/322058)

<div class="topic-metadata">

**Author:** [@linkerc](https://discuss.elastic.co/u/linkerc)\
**Replies:** 1\
**Last updated:** [December 28, 2022, 8:36am UTC](https://discuss.elastic.co/t/do-i-need-track-total-hits-for-reindex-java-api-command/322058 "2022-12-28T08:36:20Z")

</div>

The title says it all. I have a query for time range within the reindex command. Just wondering if "track\_total\_hits" is necessary. My doc size will be in the millions.

[Previous page](https://discuss.elastic.co/tag/none.md?no_tags=true&page=467)

[Next page](https://discuss.elastic.co/tag/none.md?no_tags=true&page=469)
