# \#none

**URL:** https://discuss.elastic.co/tag/none.md?no_tags=true&page=471

[Latest](https://discuss.elastic.co/latest.md) · [Categories](https://discuss.elastic.co/categories.md) · [Tags](https://discuss.elastic.co/tags.md)

**Page:** 472

---

## [How do I use prune inside of a specific field?](https://discuss.elastic.co/t/how-do-i-use-prune-inside-of-a-specific-field/321950)

<div class="topic-metadata">

**Author:** [@ste1](https://discuss.elastic.co/u/ste1)\
**Replies:** 1\
**Last updated:** [December 24, 2022, 3:10am UTC](https://discuss.elastic.co/t/how-do-i-use-prune-inside-of-a-specific-field/321950 "2022-12-24T03:10:54Z")

</div>

I have a bunch of csv files from which I need to extract the "user" and "hwid" columns from. The csv filter will pull out all of the columns and put them in a field called "data". I then use the prune filter to keep only…

---

## [Problem "grok"ing when there is a conditional part on it](https://discuss.elastic.co/t/problem-grok-ing-when-there-is-a-conditional-part-on-it/321919)

<div class="topic-metadata">

**Author:** [@syunusic](https://discuss.elastic.co/u/syunusic)\
**Replies:** 4\
**Last updated:** [December 23, 2022, 11:53pm UTC](https://discuss.elastic.co/t/problem-grok-ing-when-there-is-a-conditional-part-on-it/321919 "2022-12-23T23:53:54Z")

</div>

If I have this text: blah1=faa faa2 blah2=fee blah3=fii blah4=foo how can I have the values of each variable (the one that are before the equal sign) with regex? I’ve tried with this grok: blah1=(?\<blah1\>\[^=\]+) blah2=…

---

## [Significant\_terms aggregation with sampling](https://discuss.elastic.co/t/significant-terms-aggregation-with-sampling/321944)

<div class="topic-metadata">

**Author:** [@colinvdh](https://discuss.elastic.co/u/colinvdh)\
**Replies:** 1\
**Last updated:** [December 23, 2022, 10:19pm UTC](https://discuss.elastic.co/t/significant-terms-aggregation-with-sampling/321944 "2022-12-23T22:19:39Z")

</div>

Hi there, I am looking to extract top 100 most significant terms out of a very large index. In particular, terms that have increased the most significantly in frequency between some defined "background set" and "foregro…

---

## [Visualizations for Text Words in Kibana](https://discuss.elastic.co/t/visualizations-for-text-words-in-kibana/321863)

<div class="topic-metadata">

**Author:** [@Cal](https://discuss.elastic.co/u/Cal)\
**Replies:** 5\
**Last updated:** [December 23, 2022, 6:49pm UTC](https://discuss.elastic.co/t/visualizations-for-text-words-in-kibana/321863 "2022-12-23T18:49:33Z")

</div>

I'm looking for a way to do visualizations, a graph or a counter, that searches for a keyword in a text paragraph. I have a description text field that is roughly a paragraph of text, and I want it to pull when a descri…

---

## [If condition list in field](https://discuss.elastic.co/t/if-condition-list-in-field/321886)

<div class="topic-metadata">

**Author:** [@mikhatanu](https://discuss.elastic.co/u/mikhatanu)\
**Replies:** 1\
**Last updated:** [December 23, 2022, 6:02pm UTC](https://discuss.elastic.co/t/if-condition-list-in-field/321886 "2022-12-23T18:02:43Z")

</div>

hello, is it possible to do a searching of a list in field? e.g. filter{ if \["a","b","c","d"\] in \[message\]{ mutate{ add\_field=\>{"new\_field"=\>"%{message}"} } } } i want the "new\_field…

---

## [Aggregation Based Line Chart - Y axis is inverted](https://discuss.elastic.co/t/aggregation-based-line-chart-y-axis-is-inverted/321907)

<div class="topic-metadata">

**Author:** [@tinrik](https://discuss.elastic.co/u/tinrik)\
**Replies:** 8\
**Last updated:** [December 23, 2022, 5:46pm UTC](https://discuss.elastic.co/t/aggregation-based-line-chart-y-axis-is-inverted/321907 "2022-12-23T17:46:54Z")

</div>

Hi, I am running Kibana 7.16.1. I currently have an Aggregation-based Line Chart that works as intended: Now I have created a copy by clicking on "Clone", and simply changed the field of the Split Series to split by…

---

## [An unexpected authentication error occurred. Please log in again. kibana](https://discuss.elastic.co/t/an-unexpected-authentication-error-occurred-please-log-in-again-kibana/319790)

<div class="topic-metadata">

**Author:** [@Praveen\_Prakasan](https://discuss.elastic.co/u/Praveen_Prakasan)\
**Replies:** 2\
**Last updated:** [November 25, 2022, 5:46pm UTC](https://discuss.elastic.co/t/an-unexpected-authentication-error-occurred-please-log-in-again-kibana/319790 "2022-11-25T17:46:48Z")

</div>

HI Team, I am facing An unexpected authentication error occurred. Please log in again. issue could you please help me i am using helm chart

---

## [Elasticsearch Report Download of size more than 10000 using aggregation](https://discuss.elastic.co/t/elasticsearch-report-download-of-size-more-than-10000-using-aggregation/321927)

<div class="topic-metadata">

**Author:** [@PRASHANT\_MEHTA](https://discuss.elastic.co/u/PRASHANT_MEHTA)\
**Replies:** 1\
**Last updated:** [December 23, 2022, 3:47pm UTC](https://discuss.elastic.co/t/elasticsearch-report-download-of-size-more-than-10000-using-aggregation/321927 "2022-12-23T15:47:13Z")

</div>

Hello All, I'm facing issue when I'm trying to download data more than 10000 records. I've 25000 documents in my elastic index and all these documents are unique(logsatsh doc\_as\_upsert) used.The challenge is elastic re…

---

## [Kinana error:Your query is taking time](https://discuss.elastic.co/t/kinana-error-your-query-is-taking-time/321933)

<div class="topic-metadata">

**Author:** [@PRASHANT\_MEHTA](https://discuss.elastic.co/u/PRASHANT_MEHTA)\
**Replies:** 0\
**Last updated:** [December 23, 2022, 3:54pm UTC](https://discuss.elastic.co/t/kinana-error-your-query-is-taking-time/321933 "2022-12-23T15:54:47Z")

</div>

Hello All, I am trying to fetch the aggregation data of around 20000 records and visual I'm using is data table. I'm teasting in test server with 8 core cpus and with jvm size of 8GB. Can someone help me understand wh…

---

## [Security\_exception: current license is non-compliant for \[searchable-snapshots\]](https://discuss.elastic.co/t/security-exception-current-license-is-non-compliant-for-searchable-snapshots/321925)

<div class="topic-metadata">

**Author:** [@Frobeniusnorm](https://discuss.elastic.co/u/Frobeniusnorm)\
**Replies:** 3\
**Last updated:** [December 23, 2022, 3:16pm UTC](https://discuss.elastic.co/t/security-exception-current-license-is-non-compliant-for-searchable-snapshots/321925 "2022-12-23T15:16:41Z")

</div>

In my Index Management i get the warning: Index lifecycle error security\_exception: current license is non-compliant for \[searchable-snapshots\] But when i go to the policies, searchable snapshots are not activated. H…

---

## [Using the geoip filter with commercial databases](https://discuss.elastic.co/t/using-the-geoip-filter-with-commercial-databases/321874)

<div class="topic-metadata">

**Author:** [@patam](https://discuss.elastic.co/u/patam)\
**Replies:** 2\
**Last updated:** [December 23, 2022, 3:11pm UTC](https://discuss.elastic.co/t/using-the-geoip-filter-with-commercial-databases/321874 "2022-12-23T15:11:52Z")

</div>

I am trying to use the commercial Anonymous IP database for the geoip filter and I'm not sure how to retreive the information from the database. I have Logstash updating the db and the right .mmdb is there I am just unsu…

---

## [Logs are not Pushing to Elastic APM Server - FastAPI](https://discuss.elastic.co/t/logs-are-not-pushing-to-elastic-apm-server-fastapi/321922)

<div class="topic-metadata">

**Author:** [@azar8012](https://discuss.elastic.co/u/azar8012)\
**Replies:** 0\
**Last updated:** [December 23, 2022, 2:42pm UTC](https://discuss.elastic.co/t/logs-are-not-pushing-to-elastic-apm-server-fastapi/321922 "2022-12-23T14:42:12Z")

</div>

I have installed elastic-apm agent with my FastAPI application. I have configured the Elastic APM server. The logs are generated locally but these logs I can't able to see it on Elastic APM server. Here is the configura…

---

## [Is there any way to add custome time picker as start date and end date on user's end,and Dashboard will update on the basis of that time range?](https://discuss.elastic.co/t/is-there-any-way-to-add-custome-time-picker-as-start-date-and-end-date-on-users-end-and-dashboard-will-update-on-the-basis-of-that-time-range/321901)

<div class="topic-metadata">

**Author:** [@ysattvik](https://discuss.elastic.co/u/ysattvik)\
**Replies:** 5\
**Last updated:** [December 23, 2022, 1:14pm UTC](https://discuss.elastic.co/t/is-there-any-way-to-add-custome-time-picker-as-start-date-and-end-date-on-users-end-and-dashboard-will-update-on-the-basis-of-that-time-range/321901 "2022-12-23T13:14:12Z")

</div>

I am using Kibana 8.5.0 . please suggest some solution.

---

## [Get records only if condition persist for given span of time](https://discuss.elastic.co/t/get-records-only-if-condition-persist-for-given-span-of-time/319825)

<div class="topic-metadata">

**Author:** [@simone\_colombo](https://discuss.elastic.co/u/simone_colombo)\
**Replies:** 1\
**Last updated:** [December 23, 2022, 12:53pm UTC](https://discuss.elastic.co/t/get-records-only-if-condition-persist-for-given-span-of-time/319825 "2022-12-23T12:53:29Z")

</div>

I'm facing a querying problem with Kibana: I want to be returned all the records that match a given condition but only if they match it for at least a given span of time. Something like: Clock \> 50 and Vents is "off" \*\*…

---

## [Get all the fields from an index with specific type](https://discuss.elastic.co/t/get-all-the-fields-from-an-index-with-specific-type/321852)

<div class="topic-metadata">

**Author:** [@nikssssss](https://discuss.elastic.co/u/nikssssss)\
**Replies:** 4\
**Last updated:** [December 23, 2022, 12:45pm UTC](https://discuss.elastic.co/t/get-all-the-fields-from-an-index-with-specific-type/321852 "2022-12-23T12:45:45Z")

</div>

hi all, how it is possible to get the all the fields from an index that are mapped as a date for example

---

## [Search for documents matching some fields in a nested array](https://discuss.elastic.co/t/search-for-documents-matching-some-fields-in-a-nested-array/321808)

<div class="topic-metadata">

**Author:** [@Ali5](https://discuss.elastic.co/u/Ali5)\
**Replies:** 4\
**Last updated:** [December 23, 2022, 12:18pm UTC](https://discuss.elastic.co/t/search-for-documents-matching-some-fields-in-a-nested-array/321808 "2022-12-23T12:18:41Z")

</div>

I am learning to use Elasticsearch as a basic recommender engine. My elasticsearch document contains records with nested entities as follows POST feeds/\_doc { "feed\_id": "1", "title": "Mateen", "body": "This is ma…

---

## [How can we create list in elasticsearch](https://discuss.elastic.co/t/how-can-we-create-list-in-elasticsearch/321906)

<div class="topic-metadata">

**Author:** [@Ali5](https://discuss.elastic.co/u/Ali5)\
**Replies:** 3\
**Last updated:** [December 23, 2022, 11:48am UTC](https://discuss.elastic.co/t/how-can-we-create-list-in-elasticsearch/321906 "2022-12-23T11:48:40Z")

</div>

i want to create list of arrays in elasticsearch how we can search it to them as i want to create list of arrays not nested array

---

## [Logstash JDBC input plugin: Java::OrgPostgresqlUtil::PSQLException: An I/O error occurred while sending to the backend](https://discuss.elastic.co/t/logstash-jdbc-input-plugin-java-an-i-o-error-occurred-while-sending-to-the-backend/321900)

<div class="topic-metadata">

**Author:** [@Thijsvdp](https://discuss.elastic.co/u/Thijsvdp)\
**Replies:** 0\
**Last updated:** [December 23, 2022, 10:12am UTC](https://discuss.elastic.co/t/logstash-jdbc-input-plugin-java-an-i-o-error-occurred-while-sending-to-the-backend/321900 "2022-12-23T10:12:05Z")

</div>

Hi all, I have created a Logstash pipeline which aims to sync an Elasticsearch index with a Postgres database. Unfortunately, there is a query that does not perform well and takes quite some time. Once every now and the…

---

## [Kibana not connecting points in line](https://discuss.elastic.co/t/kibana-not-connecting-points-in-line/321821)

<div class="topic-metadata">

**Author:** [@tinrik](https://discuss.elastic.co/u/tinrik)\
**Replies:** 3\
**Last updated:** [December 23, 2022, 8:41am UTC](https://discuss.elastic.co/t/kibana-not-connecting-points-in-line/321821 "2022-12-23T08:41:32Z")

</div>

Hi! I'm running on Kibana 7.16.1. I'm trying to display a simple Lens Line chart. My dataset is a set of documents like: { timestamp: \<ISO time\>, violations: 123, file: "path/to/foo.cpp", owner: "Foo", } My go…

---

## [Parsing CSV with different header](https://discuss.elastic.co/t/parsing-csv-with-different-header/321887)

<div class="topic-metadata">

**Author:** [@SKiD](https://discuss.elastic.co/u/SKiD)\
**Replies:** 0\
**Last updated:** [December 23, 2022, 8:07am UTC](https://discuss.elastic.co/t/parsing-csv-with-different-header/321887 "2022-12-23T08:07:07Z")

</div>

Hello, I have some thousand CSV files which I need to index into elasticsearch. All of those CSV files have different headers. I tried to use the CSV filter for logstash, but then I read THAT. Besides of my incomprehens…

---

## [Do we have any provision to DRAG the new "CONTROLS" at any position in the Kibana dashboard ? If possible please convey the process for the same](https://discuss.elastic.co/t/do-we-have-any-provision-to-drag-the-new-controls-at-any-position-in-the-kibana-dashboard-if-possible-please-convey-the-process-for-the-same/321884)

<div class="topic-metadata">

**Author:** [@ysattvik](https://discuss.elastic.co/u/ysattvik)\
**Replies:** 1\
**Last updated:** [December 23, 2022, 8:04am UTC](https://discuss.elastic.co/t/do-we-have-any-provision-to-drag-the-new-controls-at-any-position-in-the-kibana-dashboard-if-possible-please-convey-the-process-for-the-same/321884 "2022-12-23T08:04:14Z")

</div>

Currently controls are freezed at the TOP of the Dashboard.

---

## [Multiple logstash instances consume kafka, only one is working](https://discuss.elastic.co/t/multiple-logstash-instances-consume-kafka-only-one-is-working/321880)

<div class="topic-metadata">

**Author:** [@TemplateXu](https://discuss.elastic.co/u/TemplateXu)\
**Replies:** 1\
**Last updated:** [December 23, 2022, 6:45am UTC](https://discuss.elastic.co/t/multiple-logstash-instances-consume-kafka-only-one-is-working/321880 "2022-12-23T06:45:47Z")

</div>

Multiple logstash instances consume log messages in kafka, but only one of them is working. When I close one of them, the other starts to work. How to make two logstash instances work together

---

## [Update index pattern in order to remove unused fields](https://discuss.elastic.co/t/update-index-pattern-in-order-to-remove-unused-fields/320144)

<div class="topic-metadata">

**Author:** [@nunex\_17](https://discuss.elastic.co/u/nunex_17)\
**Replies:** 1\
**Last updated:** [December 23, 2022, 5:18am UTC](https://discuss.elastic.co/t/update-index-pattern-in-order-to-remove-unused-fields/320144 "2022-12-23T05:18:08Z")

</div>

Hello, I update my index-template mappings and removed some fields that i do not need. But, after this change, the index pattern still have the fields that were deleted. So: How can i update the index pattern in orde…

---

## [Embed dashboard using reverse proxy - Incorrect HTTP method for uri](https://discuss.elastic.co/t/embed-dashboard-using-reverse-proxy-incorrect-http-method-for-uri/321878)

<div class="topic-metadata">

**Author:** [@Tzachi.shachar](https://discuss.elastic.co/u/Tzachi.shachar)\
**Replies:** 1\
**Last updated:** [December 23, 2022, 4:09am UTC](https://discuss.elastic.co/t/embed-dashboard-using-reverse-proxy-incorrect-http-method-for-uri/321878 "2022-12-23T04:09:23Z")

</div>

Hi, I'm using nginx as a reverse proxy with the following configuration: server { listen 4443 ssl; server\_name localhost; ssl\_certificate /etc/nginx/ssl/nginx.crt; ssl\_certificate\_key /etc/nginx/…

---

## [Float type rounding issues](https://discuss.elastic.co/t/float-type-rounding-issues/321859)

<div class="topic-metadata">

**Author:** [@etnachtman](https://discuss.elastic.co/u/etnachtman)\
**Replies:** 8\
**Last updated:** [December 23, 2022, 3:50am UTC](https://discuss.elastic.co/t/float-type-rounding-issues/321859 "2022-12-23T03:50:30Z")

</div>

I am trying to debug a kibana display issue with an index field of type float. When I look at the data in the index directly using dev tools it appears correctly. "balance": 10000.3675 However when I view the value th…

---

## [How to add another condition to SearchRequest.Builder in Java API](https://discuss.elastic.co/t/how-to-add-another-condition-to-searchrequest-builder-in-java-api/321812)

<div class="topic-metadata">

**Author:** [@cchuang4](https://discuss.elastic.co/u/cchuang4)\
**Replies:** 2\
**Last updated:** [December 23, 2022, 2:36am UTC](https://discuss.elastic.co/t/how-to-add-another-condition-to-searchrequest-builder-in-java-api/321812 "2022-12-23T02:36:54Z")

</div>

For new Java API, If I want to make a search like below: my code below, but I will set range and terms in different place, how should I combination the second setting to exist condition. In my code, the second .quer…

---

## [Measure throughput of interfaces in a machine, it is posible with any agent?](https://discuss.elastic.co/t/measure-throughput-of-interfaces-in-a-machine-it-is-posible-with-any-agent/321861)

<div class="topic-metadata">

**Author:** [@ElasticLiver](https://discuss.elastic.co/u/ElasticLiver)\
**Replies:** 1\
**Last updated:** [December 22, 2022, 11:06pm UTC](https://discuss.elastic.co/t/measure-throughput-of-interfaces-in-a-machine-it-is-posible-with-any-agent/321861 "2022-12-22T23:06:12Z")

</div>

it is posible to get the throughput of each interface in a machine? I was looking for it in packetbeat exported fields but I didn't find anything.

---

## [Data Isolation on ELK data pipeline](https://discuss.elastic.co/t/data-isolation-on-elk-data-pipeline/321855)

<div class="topic-metadata">

**Author:** [@Tiharqa](https://discuss.elastic.co/u/Tiharqa)\
**Replies:** 1\
**Last updated:** [December 22, 2022, 6:07pm UTC](https://discuss.elastic.co/t/data-isolation-on-elk-data-pipeline/321855 "2022-12-22T18:07:09Z")

</div>

Hello , Can some one speak in to the data isolation part of elastic especially when you have data with different labeling ? For example I have : finance data sales data users data I can create spaces for each typ…

---

## [Kibana not saving query with space properly](https://discuss.elastic.co/t/kibana-not-saving-query-with-space-properly/321717)

<div class="topic-metadata">

**Author:** [@Deb](https://discuss.elastic.co/u/Deb)\
**Replies:** 1\
**Last updated:** [December 22, 2022, 5:00pm UTC](https://discuss.elastic.co/t/kibana-not-saving-query-with-space-properly/321717 "2022-12-22T17:00:10Z")

</div>

I am trying to save a query of the form "Released Hold without any captures" After saving whenever I am trying load the saved query the double quotes are getting dropped and the query is becoming like below Relea…

---

## [Elastic Agent, Ingest pipeline processing fields](https://discuss.elastic.co/t/elastic-agent-ingest-pipeline-processing-fields/321629)

<div class="topic-metadata">

**Author:** [@searchtastic](https://discuss.elastic.co/u/searchtastic)\
**Replies:** 2\
**Last updated:** [December 22, 2022, 4:40pm UTC](https://discuss.elastic.co/t/elastic-agent-ingest-pipeline-processing-fields/321629 "2022-12-22T16:40:51Z")

</div>

I apologise if this is a silly question. I have been reading the documentation and trying to understand how to use the ingest pipelines to get my data into fields. I have had some success, However I have become stuck wit…

[Previous page](https://discuss.elastic.co/tag/none.md?no_tags=true&page=470)

[Next page](https://discuss.elastic.co/tag/none.md?no_tags=true&page=472)
