# \#none

**URL:** https://discuss.elastic.co/tag/none.md?no_tags=true&page=470

[Latest](https://discuss.elastic.co/latest.md) · [Categories](https://discuss.elastic.co/categories.md) · [Tags](https://discuss.elastic.co/tags.md)

**Page:** 471

---

## [Adding items to a new field](https://discuss.elastic.co/t/adding-items-to-a-new-field/321995)

<div class="topic-metadata">

**Author:** [@Glad](https://discuss.elastic.co/u/Glad)\
**Replies:** 0\
**Last updated:** [December 26, 2022, 4:15pm UTC](https://discuss.elastic.co/t/adding-items-to-a-new-field/321995 "2022-12-26T16:15:31Z")

</div>

Hi, I recently started using Elastic and I'm having a problem. I am using a monitoring system for my tests to retrieve various data from the machines I am using. This monitoring system has an api that allows Logstash to …

---

## [Extract timestamp from multiple records](https://discuss.elastic.co/t/extract-timestamp-from-multiple-records/321993)

<div class="topic-metadata">

**Author:** [@mail2shanth](https://discuss.elastic.co/u/mail2shanth)\
**Replies:** 0\
**Last updated:** [December 26, 2022, 3:38pm UTC](https://discuss.elastic.co/t/extract-timestamp-from-multiple-records/321993 "2022-12-26T15:38:45Z")

</div>

Hi, Below is my config file, input { file{ path =\> "/Users/.../Work/Projects/ELK/Logstash/Input/\*.txt" start\_position =\> beginning codec =\> "json" type =\> "data" sincedb\_path =\> "NUL" } } filter { …

---

## [How to get the graph similar to kibana demo](https://discuss.elastic.co/t/how-to-get-the-graph-similar-to-kibana-demo/317936)

<div class="topic-metadata">

**Author:** [@sixsenseninja](https://discuss.elastic.co/u/sixsenseninja)\
**Replies:** 1\
**Last updated:** [November 2, 2022, 9:55am UTC](https://discuss.elastic.co/t/how-to-get-the-graph-similar-to-kibana-demo/317936 "2022-11-02T09:55:53Z")

</div>

Hi, i saw a graph from the following url: Elastic Demos) I wonder what widget being use and how can i achieve the similar result? I can't figure out what widget being used for that.

---

## [String to IP Convert](https://discuss.elastic.co/t/string-to-ip-convert/321984)

<div class="topic-metadata">

**Author:** [@nonameo](https://discuss.elastic.co/u/nonameo)\
**Replies:** 5\
**Last updated:** [December 26, 2022, 12:59pm UTC](https://discuss.elastic.co/t/string-to-ip-convert/321984 "2022-12-26T12:59:16Z")

</div>

Hi everyone, I have a problem converting the string field to IP datatype. I'm trying to convert via convert processor in the pipeline, also tried with the grok but nothing. How can I do that? Why the processors do not w…

---

## [Pagination issue on elasticsearch query result](https://discuss.elastic.co/t/pagination-issue-on-elasticsearch-query-result/321990)

<div class="topic-metadata">

**Author:** [@Manzoor\_Faisal](https://discuss.elastic.co/u/Manzoor_Faisal)\
**Replies:** 0\
**Last updated:** [December 26, 2022, 12:52pm UTC](https://discuss.elastic.co/t/pagination-issue-on-elasticsearch-query-result/321990 "2022-12-26T12:52:47Z")

</div>

Hy, I hope you are good and doing well. I am facing issue during search query result of ELS. I configured ELS with my Code and When I search using ELS it shows result fine but the issue is it shows loading sign (three do…

---

## [Which URLs should allow for Kibana](https://discuss.elastic.co/t/which-urls-should-allow-for-kibana/317873)

<div class="topic-metadata">

**Author:** [@Kosala\_Randika\_Paran](https://discuss.elastic.co/u/Kosala_Randika_Paran)\
**Replies:** 1\
**Last updated:** [November 1, 2022, 9:47am UTC](https://discuss.elastic.co/t/which-urls-should-allow-for-kibana/317873 "2022-11-01T09:47:22Z")

</div>

Hi Which URL or links should allow for the Kibana server since we have restricted internet from our servers. Once disconnected from the internet then integration and other services are getting stuck (not loading) so is…

---

## [What type to choose for Dates Column](https://discuss.elastic.co/t/what-type-to-choose-for-dates-column/321979)

<div class="topic-metadata">

**Author:** [@Hasan](https://discuss.elastic.co/u/Hasan)\
**Replies:** 0\
**Last updated:** [December 26, 2022, 9:26am UTC](https://discuss.elastic.co/t/what-type-to-choose-for-dates-column/321979 "2022-12-26T09:26:42Z")

</div>

Hello, I have got the dataset consisting of a date column. The Format for the date in my data file is MM-DD-YYYY. While importing the dataset to Kibana what type should I choose in the pipeline and in mappings to make it…

---

## [How to start Elastic Observability](https://discuss.elastic.co/t/how-to-start-elastic-observability/321978)

<div class="topic-metadata">

**Author:** [@Aniket\_Pant](https://discuss.elastic.co/u/Aniket_Pant)\
**Replies:** 0\
**Last updated:** [December 26, 2022, 9:13am UTC](https://discuss.elastic.co/t/how-to-start-elastic-observability/321978 "2022-12-26T09:13:09Z")

</div>

We are using heartbeat for node availability and filebeat for logs shipment. Now we want to explore elastic observability features. In kibana observability section there is uptime option with heartbeat we have used one o…

---

## [Logstash filter not working](https://discuss.elastic.co/t/logstash-filter-not-working/321948)

<div class="topic-metadata">

**Author:** [@parisila](https://discuss.elastic.co/u/parisila)\
**Replies:** 2\
**Last updated:** [December 26, 2022, 8:29am UTC](https://discuss.elastic.co/t/logstash-filter-not-working/321948 "2022-12-26T08:29:36Z")

</div>

I have filebeat, logstash and elasticsearch. My logstash config.d looks like this 02-beats-input.conf receives the message from filebeat 30-elasticsearch-output.conf sends to elasticsearch ingest pipeline. Logstash…

---

## [Document is not saved](https://discuss.elastic.co/t/document-is-not-saved/321976)

<div class="topic-metadata">

**Author:** [@dave3](https://discuss.elastic.co/u/dave3)\
**Replies:** 0\
**Last updated:** [December 26, 2022, 8:18am UTC](https://discuss.elastic.co/t/document-is-not-saved/321976 "2022-12-26T08:18:59Z")

</div>

I have created a documet with many fields, some of them are lists of Strings as follows: @Field(type = FieldType.Nested) private Set\<String\> locationList = new HashSet\<\>(); but when I try to save this document, i get t…

---

## [Upgrade from 7.16.2 to 7.171.7](https://discuss.elastic.co/t/upgrade-from-7-16-2-to-7-171-7/320439)

<div class="topic-metadata">

**Author:** [@sahere37](https://discuss.elastic.co/u/sahere37)\
**Replies:** 4\
**Last updated:** [December 26, 2022, 7:37am UTC](https://discuss.elastic.co/t/upgrade-from-7-16-2-to-7-171-7/320439 "2022-12-26T07:37:07Z")

</div>

Hi, I have a three-node cluster version 716.2 and I want to upgrade it to 7.17.7. in my current cluster, TLS setting is activated by following: xpack.security.enabled: true xpack.security.transport.ssl.enabled: true xpa…

---

## [Matching data in two different indexes](https://discuss.elastic.co/t/matching-data-in-two-different-indexes/317741)

<div class="topic-metadata">

**Author:** [@OlegBochkarev](https://discuss.elastic.co/u/OlegBochkarev)\
**Replies:** 2\
**Last updated:** [October 31, 2022, 11:59pm UTC](https://discuss.elastic.co/t/matching-data-in-two-different-indexes/317741 "2022-10-31T23:59:00Z")

</div>

Hi, team! I collect authorising logs from two systems into two separate indexes. Index content: Index1: system1\_timestamp system1\_username system1\_ip ... Index2: system2\_timesamp system2\_username system2\_ip ..…

---

## [CSPM third Party](https://discuss.elastic.co/t/cspm-third-party/321805)

<div class="topic-metadata">

**Author:** [@Dea\_Agra](https://discuss.elastic.co/u/Dea_Agra)\
**Replies:** 1\
**Last updated:** [December 25, 2022, 11:52pm UTC](https://discuss.elastic.co/t/cspm-third-party/321805 "2022-12-25T23:52:06Z")

</div>

Hi Elastic Team, We want to integrate our Elastic SIEM with CSPM third part tools, is there any tool recommandation taht we can integrate with our Elastic SIEM?

---

## [Agent Spoofing - Multiple Hosts Using Same Agent after update to 8.5.3](https://discuss.elastic.co/t/agent-spoofing-multiple-hosts-using-same-agent-after-update-to-8-5-3/321276)

<div class="topic-metadata">

**Author:** [@Paradox](https://discuss.elastic.co/u/Paradox)\
**Replies:** 1\
**Last updated:** [December 25, 2022, 11:39pm UTC](https://discuss.elastic.co/t/agent-spoofing-multiple-hosts-using-same-agent-after-update-to-8-5-3/321276 "2022-12-25T23:39:33Z")

</div>

Hello, since the update to ELS 8.5.3 we receive "Agent Spoofing - Multiple Hosts Using Same Agent" messages. We were able to narrow down the message to be related to the DHCP integration. As soon as this is activated…

---

## [See data in Kibana](https://discuss.elastic.co/t/see-data-in-kibana/319893)

<div class="topic-metadata">

**Author:** [@vassiliy.vins](https://discuss.elastic.co/u/vassiliy.vins)\
**Replies:** 1\
**Last updated:** [November 28, 2022, 12:01am UTC](https://discuss.elastic.co/t/see-data-in-kibana/319893 "2022-11-28T00:01:58Z")

</div>

Hello Installed ELK on one host and FileBeat on another. Configured FileBeat to send data to Elasticsearch How can I see my logs in Kibana? Thank you

---

## [Create time-series with stream data](https://discuss.elastic.co/t/create-time-series-with-stream-data/317352)

<div class="topic-metadata">

**Author:** [@Ismael\_Alvarez](https://discuss.elastic.co/u/Ismael_Alvarez)\
**Replies:** 4\
**Last updated:** [October 31, 2022, 4:17pm UTC](https://discuss.elastic.co/t/create-time-series-with-stream-data/317352 "2022-10-31T16:17:55Z")

</div>

hey there! I need to create a graph with the stream data, I attach an example graph that I need to create and stream logs. I appreciate the support, I have tried to create but without results, best Regards Ismael …

---

## [Kibana case sensitive search?](https://discuss.elastic.co/t/kibana-case-sensitive-search/317788)

<div class="topic-metadata">

**Author:** [@Nikolas1306](https://discuss.elastic.co/u/Nikolas1306)\
**Replies:** 2\
**Last updated:** [December 25, 2022, 2:18pm UTC](https://discuss.elastic.co/t/kibana-case-sensitive-search/317788 "2022-12-25T14:18:05Z")

</div>

kibana case sensitive search? i try but is not have operator base on dashboard

---

## [Safe usage of \`\_forcemerge\` with \`only\_expunge\_deletes\`](https://discuss.elastic.co/t/safe-usage-of-forcemerge-with-only-expunge-deletes/321964)

<div class="topic-metadata">

**Author:** [@Au6ojlut](https://discuss.elastic.co/u/Au6ojlut)\
**Replies:** 0\
**Last updated:** [December 25, 2022, 10:31am UTC](https://discuss.elastic.co/t/safe-usage-of-forcemerge-with-only-expunge-deletes/321964 "2022-12-25T10:31:37Z")

</div>

Hello Team I am using the Elasticsearch 8.4.2. I have several indices, that is receiving updates (or deletes). On some indices update operation goes with the optimistic-concurrency-control. After some time, when the p…

---

## [Logstash configuration](https://discuss.elastic.co/t/logstash-configuration/321963)

<div class="topic-metadata">

**Author:** [@SaM9](https://discuss.elastic.co/u/SaM9)\
**Replies:** 0\
**Last updated:** [December 25, 2022, 9:59am UTC](https://discuss.elastic.co/t/logstash-configuration/321963 "2022-12-25T09:59:41Z")

</div>

in my elastic stack i have the following components : elastic agnet , fleet server , logstach and ealsticsearch cluster in my logstach output config do I have to send data directory to ealstcisearch data nodes or to flee…

---

## [Translog\_ops too slow while moving shards](https://discuss.elastic.co/t/translog-ops-too-slow-while-moving-shards/321960)

<div class="topic-metadata">

**Author:** [@DJ\_Zhu](https://discuss.elastic.co/u/DJ_Zhu)\
**Replies:** 0\
**Last updated:** [December 25, 2022, 8:52am UTC](https://discuss.elastic.co/t/translog-ops-too-slow-while-moving-shards/321960 "2022-12-25T08:52:14Z")

</div>

I have serval ES cluster that will do shards moving periodically(from hot node to cold node). Recently I notice that some of the shards are moved very slow compared to others. Here is one of the slow cluster: $ curl -XG…

---

## [Retrieve filters KQL Query](https://discuss.elastic.co/t/retrieve-filters-kql-query/317784)

<div class="topic-metadata">

**Author:** [@bandodkarD](https://discuss.elastic.co/u/bandodkarD)\
**Replies:** 5\
**Last updated:** [October 31, 2022, 12:08pm UTC](https://discuss.elastic.co/t/retrieve-filters-kql-query/317784 "2022-10-31T12:08:41Z")

</div>

Can you advise how we can retrieve the backend KQL query once we filter out data on Kibana Dashboard? Our requirement is to filter out data using charts and other visualisations are retrieve the query generated in backe…

---

## [Filtering expired child document while searching](https://discuss.elastic.co/t/filtering-expired-child-document-while-searching/321957)

<div class="topic-metadata">

**Author:** [@Lokesh\_Reddy1](https://discuss.elastic.co/u/Lokesh_Reddy1)\
**Replies:** 0\
**Last updated:** [December 24, 2022, 10:50pm UTC](https://discuss.elastic.co/t/filtering-expired-child-document-while-searching/321957 "2022-12-24T22:50:26Z")

</div>

Hi Everyone, I am struck with this unique problem and hopefully one of you might know the answer. Here is the situation: I have an object hierarchy Asset -\> Media Items (One to Many). Some of the Media Items may expir…

---

## [Upgrade from 7.17.1 to 8.5.3 failed](https://discuss.elastic.co/t/upgrade-from-7-17-1-to-8-5-3-failed/321946)

<div class="topic-metadata">

**Author:** [@elasticforme](https://discuss.elastic.co/u/elasticforme)\
**Replies:** 8\
**Last updated:** [December 24, 2022, 11:03pm UTC](https://discuss.elastic.co/t/upgrade-from-7-17-1-to-8-5-3-failed/321946 "2022-12-24T23:03:01Z")

</div>

here is error. java.lang.IllegalStateException: cannot upgrade node because incompatible indices created with version \[6.5.4\] exist, while the minimum compatible index version is \[7.0.0\]. Upgrade your older indices by …

---

## [Records field not getting updated in Kibana dashboard](https://discuss.elastic.co/t/records-field-not-getting-updated-in-kibana-dashboard/321345)

<div class="topic-metadata">

**Author:** [@Shashank02](https://discuss.elastic.co/u/Shashank02)\
**Replies:** 1\
**Last updated:** [December 24, 2022, 6:24pm UTC](https://discuss.elastic.co/t/records-field-not-getting-updated-in-kibana-dashboard/321345 "2022-12-24T18:24:51Z")

</div>

I'm pushing my CSV data directly to Elasticsearch using python. Because of that, an index is getting created. But, then I am creating a data view manually in order to use it for KIBANA DASHBOARDS. The error I am facing i…

---

## [Dashboard building](https://discuss.elastic.co/t/dashboard-building/320883)

<div class="topic-metadata">

**Author:** [@moep](https://discuss.elastic.co/u/moep)\
**Replies:** 5\
**Last updated:** [December 24, 2022, 2:48pm UTC](https://discuss.elastic.co/t/dashboard-building/320883 "2022-12-24T14:48:03Z")

</div>

Dear Community, Im running Kibana 8.4.3 and want to create a speacial typ of visulization. I'm analysing my my flow and Im interessted into the MSD ID and the timestamp (I want to see the newest on the top). Right now…

---

## [Send “raw log” and “filter log” from single server to elastic server](https://discuss.elastic.co/t/send-raw-log-and-filter-log-from-single-server-to-elastic-server/321824)

<div class="topic-metadata">

**Author:** [@Indeed2000](https://discuss.elastic.co/u/Indeed2000)\
**Replies:** 7\
**Last updated:** [December 24, 2022, 1:42pm UTC](https://discuss.elastic.co/t/send-raw-log-and-filter-log-from-single-server-to-elastic-server/321824 "2022-12-24T13:42:40Z")

</div>

Hi Need to Send “raw log” and “filter log” from single server to elastic server, but in different index. Like this: Host1 (rawlog) \> elastic (rawindex) Host1 (filter log) \> elastic (filterindex) Is it possible? Any…

---

## [Order documents by multiple geolocations](https://discuss.elastic.co/t/order-documents-by-multiple-geolocations/321449)

<div class="topic-metadata">

**Author:** [@merianos](https://discuss.elastic.co/u/merianos)\
**Replies:** 1\
**Last updated:** [December 24, 2022, 9:14am UTC](https://discuss.elastic.co/t/order-documents-by-multiple-geolocations/321449 "2022-12-24T09:14:28Z")

</div>

I am new to Elasticsearch and I try to create an index for companies that come with multiple branches in the city. Each of the branches it has it's own geolocation point. My companies document looks like this: { "…

---

## [Dec 24th, 2022: \[FR\] Définissez vos propres facettes avec les sources Custom dans Workplace Search](https://discuss.elastic.co/t/dec-24th-2022-fr-definissez-vos-propres-facettes-avec-les-sources-custom-dans-workplace-search/318641)

<div class="topic-metadata">

**Author:** [@dadoonet](https://discuss.elastic.co/u/dadoonet)\
**Replies:** 0\
**Last updated:** [December 24, 2022, 8:00am UTC](https://discuss.elastic.co/t/dec-24th-2022-fr-definissez-vos-propres-facettes-avec-les-sources-custom-dans-workplace-search/318641 "2022-12-24T08:00:55Z")

</div>

This article is also available in english. Workplace Search fournit un moyen sympa et facile pour rechercher dans tous les documents que vous pouvez avoir dans votre entreprise/entité. Vous pouvez ainsi chercher dep…

---

## [Dec 24th, 2022: \[EN\] Define your own facets for Custom Sources in Workplace Search](https://discuss.elastic.co/t/dec-24th-2022-en-define-your-own-facets-for-custom-sources-in-workplace-search/318640)

<div class="topic-metadata">

**Author:** [@dadoonet](https://discuss.elastic.co/u/dadoonet)\
**Replies:** 0\
**Last updated:** [December 24, 2022, 8:00am UTC](https://discuss.elastic.co/t/dec-24th-2022-en-define-your-own-facets-for-custom-sources-in-workplace-search/318640 "2022-12-24T08:00:55Z")

</div>

Cet article est aussi disponible en français. Workplace Search provides a very nice and easy way to search within all the documents you have within your company/entity. You can get content from various sources, like…

---

## [Trouble with filter conditional logic](https://discuss.elastic.co/t/trouble-with-filter-conditional-logic/321930)

<div class="topic-metadata">

**Author:** [@willdennis](https://discuss.elastic.co/u/willdennis)\
**Replies:** 5\
**Last updated:** [December 24, 2022, 3:53am UTC](https://discuss.elastic.co/t/trouble-with-filter-conditional-logic/321930 "2022-12-24T03:53:21Z")

</div>

I have had the following filter conditional logic in place for a while now, and it's working well: filter { mutate { \[...\] } if "STRING1" in \[message\] { \[...\] } else if \[type\] == "syslog" { \[...\] } …

[Previous page](https://discuss.elastic.co/tag/none.md?no_tags=true&page=469)

[Next page](https://discuss.elastic.co/tag/none.md?no_tags=true&page=471)
