# \#none

**URL:** https://discuss.elastic.co/tag/none.md?no_tags=true&page=476

[Latest](https://discuss.elastic.co/latest.md) · [Categories](https://discuss.elastic.co/categories.md) · [Tags](https://discuss.elastic.co/tags.md)

**Page:** 477

---

## [Sum Aggregation using multiple fields](https://discuss.elastic.co/t/sum-aggregation-using-multiple-fields/321357)

<div class="topic-metadata">

**Author:** [@searchwithme](https://discuss.elastic.co/u/searchwithme)\
**Replies:** 5\
**Last updated:** [December 16, 2022, 7:02pm UTC](https://discuss.elastic.co/t/sum-aggregation-using-multiple-fields/321357 "2022-12-16T19:02:00Z")

</div>

Hi team! I am indexing the following sample data: travel index Flight price - 550 Hotel price - 220 Meals - 120 (Total Expense - 890) If I query for travel index with total expense \< 1000, it should return result…

---

## [Calculate time difference between 2 events with unique id](https://discuss.elastic.co/t/calculate-time-difference-between-2-events-with-unique-id/321388)

<div class="topic-metadata">

**Author:** [@yago82](https://discuss.elastic.co/u/yago82)\
**Replies:** 1\
**Last updated:** [December 16, 2022, 5:48pm UTC](https://discuss.elastic.co/t/calculate-time-difference-between-2-events-with-unique-id/321388 "2022-12-16T17:48:28Z")

</div>

Hi, I have two events with same field idRda like the following, I need to calculate the difference between the timestamp "message": "2022-12-13 14:52:00.399 {\[ACTIVE\] ExecuteThread: 5 for queue: weblogic.kernel.Default…

---

## [Arbitrary hash to CEF custom fields?](https://discuss.elastic.co/t/arbitrary-hash-to-cef-custom-fields/321422)

<div class="topic-metadata">

**Author:** [@j00bar](https://discuss.elastic.co/u/j00bar)\
**Replies:** 1\
**Last updated:** [December 16, 2022, 4:37pm UTC](https://discuss.elastic.co/t/arbitrary-hash-to-cef-custom-fields/321422 "2022-12-16T16:37:14Z")

</div>

I'm using the cef codec for encoding data. CEF lets you add custom attributes with a series of deviceCustom\* fields. If you've got an attribute confidence and its value is high, you can say in CEF: deviceCustomString1La…

---

## [Shard Failed. Null Node](https://discuss.elastic.co/t/shard-failed-null-node/317204)

<div class="topic-metadata">

**Author:** [@Shep](https://discuss.elastic.co/u/Shep)\
**Replies:** 1\
**Last updated:** [October 23, 2022, 11:07pm UTC](https://discuss.elastic.co/t/shard-failed-null-node/317204 "2022-10-23T23:07:29Z")

</div>

Kibana 7.14 I am getting a "no\_shard\_available\_action\_exception". It seems to be suggesting the reason is because the node is "null". Any Advice? { "took": 65, "timed\_out": false, "\_shards": { "total": 13…

---

## [Duplication Due to rollover policy in kibana,data coming from logstash pipeline](https://discuss.elastic.co/t/duplication-due-to-rollover-policy-in-kibana-data-coming-from-logstash-pipeline/319959)

<div class="topic-metadata">

**Author:** [@PRASHANT\_MEHTA](https://discuss.elastic.co/u/PRASHANT_MEHTA)\
**Replies:** 9\
**Last updated:** [December 5, 2022, 5:52pm UTC](https://discuss.elastic.co/t/duplication-due-to-rollover-policy-in-kibana-data-coming-from-logstash-pipeline/319959 "2022-12-05T17:52:25Z")

</div>

Hello All, I am ingesting data into a rollover index. The data comes from perl scripts running every 15 min,20 min,4hour,12 hour,16 hour etc and gives updates on previously ingested events through doc\_as\_upsert used in …

---

## [ElasticSearch pri.store.size](https://discuss.elastic.co/t/elasticsearch-pri-store-size/321397)

<div class="topic-metadata">

**Author:** [@gjahagir](https://discuss.elastic.co/u/gjahagir)\
**Replies:** 2\
**Last updated:** [December 16, 2022, 1:43pm UTC](https://discuss.elastic.co/t/elasticsearch-pri-store-size/321397 "2022-12-16T13:43:58Z")

</div>

Hi, We are performing capacity planning in elastic to evaluate the storage sizes. For this we indexed one doc with dummy fields (7 simple fields and 13 nested) took the size of the doc which is 1148 bytes. Then we ex…

---

## [Customized UI for Elastic Security as SIEM](https://discuss.elastic.co/t/customized-ui-for-elastic-security-as-siem/321360)

<div class="topic-metadata">

**Author:** [@camiyu1](https://discuss.elastic.co/u/camiyu1)\
**Replies:** 2\
**Last updated:** [December 16, 2022, 12:54pm UTC](https://discuss.elastic.co/t/customized-ui-for-elastic-security-as-siem/321360 "2022-12-16T12:54:51Z")

</div>

I am working on deploying Elastic Security in an on-prem environment. After installing Elasticsearch, Kibana, Logstash, I managed to configure to ingest different log sources such as firewall, proxy gateway, intrusion d…

---

## [Parse context\_hits](https://discuss.elastic.co/t/parse-context-hits/321299)

<div class="topic-metadata">

**Author:** [@Pablo\_Sagrera\_Garcia](https://discuss.elastic.co/u/Pablo_Sagrera_Garcia)\
**Replies:** 1\
**Last updated:** [December 16, 2022, 12:13pm UTC](https://discuss.elastic.co/t/parse-context-hits/321299 "2022-12-16T12:13:13Z")

</div>

I've create a rule whose connector is write to index. I wonder if possible to parse context\_hits to create an additional field when hit the rule. For example I would like to create an additional field called message o…

---

## [Which codec parameter we can use for logstash http input section](https://discuss.elastic.co/t/which-codec-parameter-we-can-use-for-logstash-http-input-section/321405)

<div class="topic-metadata">

**Author:** [@prashant1](https://discuss.elastic.co/u/prashant1)\
**Replies:** 0\
**Last updated:** [December 16, 2022, 11:30am UTC](https://discuss.elastic.co/t/which-codec-parameter-we-can-use-for-logstash-http-input-section/321405 "2022-12-16T11:30:31Z")

</div>

We are sending logs from fluentd with http to logstash having version 7.10.2. But looks like codec =\> fluent does not work for http for logstash as we got some \_fluentparse error. We have tried also using codec =\> json…

---

## [Upsert a document with unique id but same fields and different values](https://discuss.elastic.co/t/upsert-a-document-with-unique-id-but-same-fields-and-different-values/321403)

<div class="topic-metadata">

**Author:** [@yago82](https://discuss.elastic.co/u/yago82)\
**Replies:** 0\
**Last updated:** [December 16, 2022, 11:24am UTC](https://discuss.elastic.co/t/upsert-a-document-with-unique-id-but-same-fields-and-different-values/321403 "2022-12-16T11:24:08Z")

</div>

Hi, I have two events with same id idRda like the following, I need to unify the logs in one document, but adding two fields "timestamp1" and "timestamp2" example: idRda:\[4040477\] timestamp1:\[1670939520399\] timestam…

---

## [\_id is not unique. is repeated in indexes addressed by a single alias](https://discuss.elastic.co/t/id-is-not-unique-is-repeated-in-indexes-addressed-by-a-single-alias/321386)

<div class="topic-metadata">

**Author:** [@Petr.Simik](https://discuss.elastic.co/u/Petr.Simik)\
**Replies:** 4\
**Last updated:** [December 16, 2022, 10:55am UTC](https://discuss.elastic.co/t/id-is-not-unique-is-repeated-in-indexes-addressed-by-a-single-alias/321386 "2022-12-16T10:55:12Z")

</div>

I experience the situation that index is having multiple same \_id within the same index I have version 7.17.0 the data are ingested by python requests lib via API this way the uniqueness is broken among multiple inde…

---

## [Order of documents when using a transform](https://discuss.elastic.co/t/order-of-documents-when-using-a-transform/321183)

<div class="topic-metadata">

**Author:** [@Hemabh\_Ravee\_Fox](https://discuss.elastic.co/u/Hemabh_Ravee_Fox)\
**Replies:** 4\
**Last updated:** [December 16, 2022, 10:51am UTC](https://discuss.elastic.co/t/order-of-documents-when-using-a-transform/321183 "2022-12-16T10:51:00Z")

</div>

I'm using elasticsearch to store the events data for web sessions. Each event is it's own document. Then I'm using transforms to aggregate this data grouping them by a sessionId key and also creating a field eventFlow wh…

---

## [Complex filter query](https://discuss.elastic.co/t/complex-filter-query/321234)

<div class="topic-metadata">

**Author:** [@Henri\_L](https://discuss.elastic.co/u/Henri_L)\
**Replies:** 1\
**Last updated:** [December 15, 2022, 9:38pm UTC](https://discuss.elastic.co/t/complex-filter-query/321234 "2022-12-15T21:38:46Z")

</div>

Sorry if it might be obvious but I'm stuck with this query. Here are some example input: { "\_index" : "education", "\_type" : "logs", "\_id" : "educ\_0610426G", "\_score" : 10.917585, …

---

## [Elasticsearch 7.17.8 mvnrepository artifact](https://discuss.elastic.co/t/elasticsearch-7-17-8-mvnrepository-artifact/320775)

<div class="topic-metadata">

**Author:** [@Charis\_Yfantis](https://discuss.elastic.co/u/Charis_Yfantis)\
**Replies:** 4\
**Last updated:** [December 16, 2022, 8:27am UTC](https://discuss.elastic.co/t/elasticsearch-7-17-8-mvnrepository-artifact/320775 "2022-12-16T08:27:59Z")

</div>

Hello everyone, I just upgraded elasticsearch to 7.17.8 and i need to build a plugin for that version, but it seems https://mvnrepository.com/artifact/org.elasticsearch/elasticsearch does not have the artifact for 7.17…

---

## [Dec 16th, 2022: \[EN\] Cleaner dashboards with the new metric chart](https://discuss.elastic.co/t/dec-16th-2022-en-cleaner-dashboards-with-the-new-metric-chart/321104)

<div class="topic-metadata">

**Author:** [@Giovanni\_Magni](https://discuss.elastic.co/u/Giovanni_Magni)\
**Replies:** 0\
**Last updated:** [December 16, 2022, 8:00am UTC](https://discuss.elastic.co/t/dec-16th-2022-en-cleaner-dashboards-with-the-new-metric-chart/321104 "2022-12-16T08:00:34Z")

</div>

Over the past months, the Elastic team has been involved in a series of initiatives created to improve the readability and aesthetic of dashboards, the ongoing work on existing charts and components is one of these. I…

---

## [One line per year with monthly buckets in line chart](https://discuss.elastic.co/t/one-line-per-year-with-monthly-buckets-in-line-chart/321294)

<div class="topic-metadata">

**Author:** [@Jonas\_S](https://discuss.elastic.co/u/Jonas_S)\
**Replies:** 13\
**Last updated:** [December 15, 2022, 5:41pm UTC](https://discuss.elastic.co/t/one-line-per-year-with-monthly-buckets-in-line-chart/321294 "2022-12-15T17:41:47Z")

</div>

Hello, i have a line chart with a date histogram with monthly buckets on the horizontal axis. And a proportion of two cumulative sums on the vertical axis. Is there a way to overlay all years to have only a single y…

---

## [If statement not working as expected](https://discuss.elastic.co/t/if-statement-not-working-as-expected/321054)

<div class="topic-metadata">

**Author:** [@Mistral](https://discuss.elastic.co/u/Mistral)\
**Replies:** 3\
**Last updated:** [December 16, 2022, 7:49am UTC](https://discuss.elastic.co/t/if-statement-not-working-as-expected/321054 "2022-12-16T07:49:45Z")

</div>

Hi guys, I know this topic has been posted a few times, but I'm unable to find any tracks to help me since a few days. I'm trying to adapt the logstash 5.8 configuration provided by stormshield to a higher (latest) vers…

---

## [How to use custom ID for inserting document using java sdk](https://discuss.elastic.co/t/how-to-use-custom-id-for-inserting-document-using-java-sdk/321380)

<div class="topic-metadata">

**Author:** [@suresh\_chaudhari](https://discuss.elastic.co/u/suresh_chaudhari)\
**Replies:** 1\
**Last updated:** [December 16, 2022, 7:44am UTC](https://discuss.elastic.co/t/how-to-use-custom-id-for-inserting-document-using-java-sdk/321380 "2022-12-16T07:44:32Z")

</div>

Hi I want to use java sdk to insert document using ID .I will have custom my own IDs to insert docs. Thanks Suresh

---

## [Does elastic support transfer old data to ecs format?](https://discuss.elastic.co/t/does-elastic-support-transfer-old-data-to-ecs-format/321378)

<div class="topic-metadata">

**Author:** [@alex\_su](https://discuss.elastic.co/u/alex_su)\
**Replies:** 0\
**Last updated:** [December 16, 2022, 7:06am UTC](https://discuss.elastic.co/t/does-elastic-support-transfer-old-data-to-ecs-format/321378 "2022-12-16T07:06:30Z")

</div>

Hi, I want to know if i have old data (ex: windows event log) as below , does elasitc has package support transfer this format to ecs ? thanks. "{ ""configSource"": ""XXX"", ""\_User"": """", ""@version"": ""1"", …

---

## [Container logs not ingesting properly to elastic fleet agents](https://discuss.elastic.co/t/container-logs-not-ingesting-properly-to-elastic-fleet-agents/321377)

<div class="topic-metadata">

**Author:** [@krishnaabylle](https://discuss.elastic.co/u/krishnaabylle)\
**Replies:** 0\
**Last updated:** [December 16, 2022, 6:54am UTC](https://discuss.elastic.co/t/container-logs-not-ingesting-properly-to-elastic-fleet-agents/321377 "2022-12-16T06:54:40Z")

</div>

Hi, As we rolled out our elastic agents in new clusters through fleets, all logs are coming to Metrics-\* and Logs-\* from Kubernetes containers. As per documentation all the logs should come to Logs-\* and Metrics-\*. We …

---

## [Update Fields Based On The Same Value Of The Other Field (Same Index)](https://discuss.elastic.co/t/update-fields-based-on-the-same-value-of-the-other-field-same-index/321376)

<div class="topic-metadata">

**Author:** [@baoletrg](https://discuss.elastic.co/u/baoletrg)\
**Replies:** 0\
**Last updated:** [December 16, 2022, 6:52am UTC](https://discuss.elastic.co/t/update-fields-based-on-the-same-value-of-the-other-field-same-index/321376 "2022-12-16T06:52:29Z")

</div>

Hi guys, Im new to ELK and have googled for a solution for this case. For example, in my index, one transaction has 3 records logged, they all has the same ofsID field. Then I want to update a field named durationTime in…

---

## [Logs in discover tab are in ascending order](https://discuss.elastic.co/t/logs-in-discover-tab-are-in-ascending-order/321252)

<div class="topic-metadata">

**Author:** [@Neelam\_Zanvar](https://discuss.elastic.co/u/Neelam_Zanvar)\
**Replies:** 2\
**Last updated:** [December 16, 2022, 6:13am UTC](https://discuss.elastic.co/t/logs-in-discover-tab-are-in-ascending-order/321252 "2022-12-16T06:13:28Z")

</div>

Hi, As u can see in the image the logs are showing the timestamp of Dec 12 first. The latest one's are of Dec 15. elasticsearch\_syslog is the data view created for indices elasticsearch\_syslog%timestamp. What can i d…

---

## [Confused issue when I search indices using wildcard pattern](https://discuss.elastic.co/t/confused-issue-when-i-search-indices-using-wildcard-pattern/321369)

<div class="topic-metadata">

**Author:** [@Young\_Edmond](https://discuss.elastic.co/u/Young_Edmond)\
**Replies:** 0\
**Last updated:** [December 16, 2022, 6:01am UTC](https://discuss.elastic.co/t/confused-issue-when-i-search-indices-using-wildcard-pattern/321369 "2022-12-16T06:01:14Z")

</div>

Hi. I meet such interesting issue, I have created 3 indices named as below es-os-complex-neo-000001 es-os-complex-neo-000002 es-os-complex-neo-yudyang, when I try to get index using the specific name in dev tools, …

---

## [Can I use update statement in jdbc output plugin logstash](https://discuss.elastic.co/t/can-i-use-update-statement-in-jdbc-output-plugin-logstash/321358)

<div class="topic-metadata">

**Author:** [@Big\_Man](https://discuss.elastic.co/u/Big_Man)\
**Replies:** 1\
**Last updated:** [December 16, 2022, 4:21am UTC](https://discuss.elastic.co/t/can-i-use-update-statement-in-jdbc-output-plugin-logstash/321358 "2022-12-16T04:21:51Z")

</div>

I need to update specific row in my database. Can i use update statement? If yes how do that Or any other solution to achieve that.

---

## [Index sizes increasing after upgrade from 7.10.2 -\> 7.17.0](https://discuss.elastic.co/t/index-sizes-increasing-after-upgrade-from-7-10-2-7-17-0/321352)

<div class="topic-metadata">

**Author:** [@zfisher](https://discuss.elastic.co/u/zfisher)\
**Replies:** 0\
**Last updated:** [December 15, 2022, 10:24pm UTC](https://discuss.elastic.co/t/index-sizes-increasing-after-upgrade-from-7-10-2-7-17-0/321352 "2022-12-15T22:24:29Z")

</div>

We recently upgraded our cluster from version 7.10.2 to version 7.17 and have noticed that, starting on the day of the upgrade, the total storage size for our indices has grown while our event count has stayed relatively…

---

## [TCP-input Receiving an encoding error](https://discuss.elastic.co/t/tcp-input-receiving-an-encoding-error/321344)

<div class="topic-metadata">

**Author:** [@elrozario](https://discuss.elastic.co/u/elrozario)\
**Replies:** 1\
**Last updated:** [December 15, 2022, 8:49pm UTC](https://discuss.elastic.co/t/tcp-input-receiving-an-encoding-error/321344 "2022-12-15T20:49:24Z")

</div>

Hello, I have a TCP input and getting data with some special characters. How do I resolve this issue? Here is my config input { tcp { host =\> "0.0.0.0" port =\> "0000" mode =\> "server" …

---

## [Mapping conflict between object, text, & keyword](https://discuss.elastic.co/t/mapping-conflict-between-object-text-keyword/321343)

<div class="topic-metadata">

**Author:** [@datdoo](https://discuss.elastic.co/u/datdoo)\
**Replies:** 2\
**Last updated:** [December 15, 2022, 8:39pm UTC](https://discuss.elastic.co/t/mapping-conflict-between-object-text-keyword/321343 "2022-12-15T20:39:59Z")

</div>

I have this mapping currently "response": { "properties": { "body": { "properties": { "id": { "type": "long" }, "json…

---

## [Not getting output with CEF codec](https://discuss.elastic.co/t/not-getting-output-with-cef-codec/321341)

<div class="topic-metadata">

**Author:** [@j00bar](https://discuss.elastic.co/u/j00bar)\
**Replies:** 2\
**Last updated:** [December 15, 2022, 8:18pm UTC](https://discuss.elastic.co/t/not-getting-output-with-cef-codec/321341 "2022-12-15T20:18:56Z")

</div>

I've got a working pipeline in Logstash where non-ECS JSON (I have ecs\_compatibility disabled in my pipeline) is coming in from SQS, getting transformed using mutate filters, and then output using stdout and the rubydebu…

---

## [Learning to Rank not working for nested field type](https://discuss.elastic.co/t/learning-to-rank-not-working-for-nested-field-type/321182)

<div class="topic-metadata">

**Author:** [@varunbharti48](https://discuss.elastic.co/u/varunbharti48)\
**Replies:** 1\
**Last updated:** [December 15, 2022, 2:34pm UTC](https://discuss.elastic.co/t/learning-to-rank-not-working-for-nested-field-type/321182 "2022-12-15T14:34:29Z")

</div>

Hi, I am implementing learning to rank on a nested field type. It is working completely fine for object field type(non-nested). But in case of nested field we are using score\_mode : "sum" to cumulate the score of child …

---

## [Cant parse logs with - in bytes field](https://discuss.elastic.co/t/cant-parse-logs-with-in-bytes-field/321281)

<div class="topic-metadata">

**Author:** [@bill210kouk](https://discuss.elastic.co/u/bill210kouk)\
**Replies:** 4\
**Last updated:** [December 15, 2022, 1:43pm UTC](https://discuss.elastic.co/t/cant-parse-logs-with-in-bytes-field/321281 "2022-12-15T13:43:30Z")

</div>

Hello! I facing an issue with my grok format pattern even though i managed to change the type of the bytes log field to numbers (this type will be used for better Kibana visualizations) some of logs have the bytes field…

[Previous page](https://discuss.elastic.co/tag/none.md?no_tags=true&page=475)

[Next page](https://discuss.elastic.co/tag/none.md?no_tags=true&page=477)
