# \#none

**URL:** https://discuss.elastic.co/tag/none.md?no_tags=true&page=477

[Latest](https://discuss.elastic.co/latest.md) · [Categories](https://discuss.elastic.co/categories.md) · [Tags](https://discuss.elastic.co/tags.md)

**Page:** 478

---

## [Logstash convert existing timestamp format in message](https://discuss.elastic.co/t/logstash-convert-existing-timestamp-format-in-message/321309)

<div class="topic-metadata">

**Author:** [@Groove](https://discuss.elastic.co/u/Groove)\
**Replies:** 0\
**Last updated:** [December 15, 2022, 1:10pm UTC](https://discuss.elastic.co/t/logstash-convert-existing-timestamp-format-in-message/321309 "2022-12-15T13:10:09Z")

</div>

Hello, I have 2 different application logs. OUTPUT: \<135\>1 2022-12-12T16:28:02Z HOSTNAME EvntSLog - - - Le service Service de licences de client (ClipSVC) est entré dans l’état : arrêté. \<134\>Dec 12 16:28:02 HOSTNAME…

---

## [Best strategy for re-indexing?](https://discuss.elastic.co/t/best-strategy-for-re-indexing/320567)

<div class="topic-metadata">

**Author:** [@Michal\_Stefaniuk](https://discuss.elastic.co/u/Michal_Stefaniuk)\
**Replies:** 5\
**Last updated:** [December 15, 2022, 11:56am UTC](https://discuss.elastic.co/t/best-strategy-for-re-indexing/320567 "2022-12-15T11:56:15Z")

</div>

Hey guys! I have an index in my ES and apparently I've added a new fields in the mapping (on the spring boot application side). Now the application will be released to the client and on the client side we will have to c…

---

## [Upgrade ES version managed by ECK on terraform - all pods terminated](https://discuss.elastic.co/t/upgrade-es-version-managed-by-eck-on-terraform-all-pods-terminated/320897)

<div class="topic-metadata">

**Author:** [@Roberto\_D\_Arco](https://discuss.elastic.co/u/Roberto_D_Arco)\
**Replies:** 6\
**Last updated:** [December 15, 2022, 11:19am UTC](https://discuss.elastic.co/t/upgrade-es-version-managed-by-eck-on-terraform-all-pods-terminated/320897 "2022-12-15T11:19:36Z")

</div>

Hello everyone, Our current Production Elasticsearch cluster for logs collection is manually managed and runs on AWS. I'm creating the same cluster using ECK deployed with Helm under Terraform. I was able to get all t…

---

## [Bug in eck operator? Cluster upgrade fails (under terraform)](https://discuss.elastic.co/t/bug-in-eck-operator-cluster-upgrade-fails-under-terraform/321149)

<div class="topic-metadata">

**Author:** [@Roberto\_D\_Arco](https://discuss.elastic.co/u/Roberto_D_Arco)\
**Replies:** 1\
**Last updated:** [December 15, 2022, 11:13am UTC](https://discuss.elastic.co/t/bug-in-eck-operator-cluster-upgrade-fails-under-terraform/321149 "2022-12-15T11:13:30Z")

</div>

Hello everyone, Our current Production Elasticsearch cluster for logs collection is manually managed and runs on AWS. I'm creating the same cluster using ECK deployed with Helm under Terraform. I was able to get all t…

---

## [Forward logs from Kafka to Elastic](https://discuss.elastic.co/t/forward-logs-from-kafka-to-elastic/320075)

<div class="topic-metadata">

**Author:** [@Deepika1](https://discuss.elastic.co/u/Deepika1)\
**Replies:** 3\
**Last updated:** [December 15, 2022, 10:10am UTC](https://discuss.elastic.co/t/forward-logs-from-kafka-to-elastic/320075 "2022-12-15T10:10:44Z")

</div>

Hello, I'm trying to forward logs from Kafka machine to Elasticsearch machine using kafka elastic connect referring below document configurations are: name=elasticsearch-sink connector.class=io.confluent.connect.ela…

---

## [Kibana 8.2.3 "Donut chart can't render with negative values"](https://discuss.elastic.co/t/kibana-8-2-3-donut-chart-cant-render-with-negative-values/314508)

<div class="topic-metadata">

**Author:** [@nesretep](https://discuss.elastic.co/u/nesretep)\
**Replies:** 20\
**Last updated:** [October 20, 2022, 4:08pm UTC](https://discuss.elastic.co/t/kibana-8-2-3-donut-chart-cant-render-with-negative-values/314508 "2022-10-20T16:08:21Z")

</div>

Previously donuts and pies just rendered. Now this message is shown when negative values exist on buckets. How can this message be turned off, and thereby achieve the rendering of all buckets which are in fact positive. …

---

## [\[7.5\] How to grant a user permission to create an index pattern?](https://discuss.elastic.co/t/7-5-how-to-grant-a-user-permission-to-create-an-index-pattern/319588)

<div class="topic-metadata">

**Author:** [@mpniel](https://discuss.elastic.co/u/mpniel)\
**Replies:** 9\
**Last updated:** [December 15, 2022, 9:15am UTC](https://discuss.elastic.co/t/7-5-how-to-grant-a-user-permission-to-create-an-index-pattern/319588 "2022-12-15T09:15:37Z")

</div>

Hi \[7.5\] How to grant a user permission to create an index pattern?

---

## [Problem configure output Email in logstash.conf?](https://discuss.elastic.co/t/problem-configure-output-email-in-logstash-conf/321269)

<div class="topic-metadata">

**Author:** [@tpot\_IT](https://discuss.elastic.co/u/tpot_IT)\
**Replies:** 0\
**Last updated:** [December 15, 2022, 8:07am UTC](https://discuss.elastic.co/t/problem-configure-output-email-in-logstash-conf/321269 "2022-12-15T08:07:10Z")

</div>

Hello, My goal is to get email alerts from the Tpot . Do I need to install alerta before configure the logstash.conf to send emails ? I'm trying to follow those instructions: (gitHub) and insert the Email output to…

---

## [Shard size increase right after rollover](https://discuss.elastic.co/t/shard-size-increase-right-after-rollover/321261)

<div class="topic-metadata">

**Author:** [@nairobi](https://discuss.elastic.co/u/nairobi)\
**Replies:** 2\
**Last updated:** [December 15, 2022, 7:48am UTC](https://discuss.elastic.co/t/shard-size-increase-right-after-rollover/321261 "2022-12-15T07:48:01Z")

</div>

I have index that primaries 3 replicas 1 ilm: roll over when any primary shard reaches 50gb (hot to warm) So when it reached to 300gb, it roll over to warm phase. But after it roll over, size of shard increase to abo…

---

## [Show first record of each group](https://discuss.elastic.co/t/show-first-record-of-each-group/319446)

<div class="topic-metadata">

**Author:** [@johnnyh](https://discuss.elastic.co/u/johnnyh)\
**Replies:** 2\
**Last updated:** [December 15, 2022, 7:41am UTC](https://discuss.elastic.co/t/show-first-record-of-each-group/319446 "2022-12-15T07:41:21Z")

</div>

Hi guys, I have been trying to find a way perform group by, and then obtaining the first of each group. This set should also be filterable and sort-able, and should also be able to count each group. Wondering if what I…

---

## [Windows event logs into the ECS format](https://discuss.elastic.co/t/windows-event-logs-into-the-ecs-format/321002)

<div class="topic-metadata">

**Author:** [@alex\_su](https://discuss.elastic.co/u/alex_su)\
**Replies:** 2\
**Last updated:** [December 15, 2022, 5:53am UTC](https://discuss.elastic.co/t/windows-event-logs-into-the-ecs-format/321002 "2022-12-15T05:53:57Z")

</div>

Hello, I want to ask how to use python convert windows event logs into the ECS format. not use beats or logstash method.

---

## [Exporting data from a visualization](https://discuss.elastic.co/t/exporting-data-from-a-visualization/320976)

<div class="topic-metadata">

**Author:** [@zivza](https://discuss.elastic.co/u/zivza)\
**Replies:** 4\
**Last updated:** [December 15, 2022, 12:14am UTC](https://discuss.elastic.co/t/exporting-data-from-a-visualization/320976 "2022-12-15T00:14:52Z")

</div>

Hi, I'm new to Kibana, and I need to export some data from a table visualization (pull it once in a while, with the current time), using python. What I actually want, is basically a csv or a JSONI can turn to a pandas …

---

## [Edit protection for Kibana visuals or dashboards](https://discuss.elastic.co/t/edit-protection-for-kibana-visuals-or-dashboards/321238)

<div class="topic-metadata">

**Author:** [@Buddha](https://discuss.elastic.co/u/Buddha)\
**Replies:** 1\
**Last updated:** [December 15, 2022, 12:04am UTC](https://discuss.elastic.co/t/edit-protection-for-kibana-visuals-or-dashboards/321238 "2022-12-15T00:04:07Z")

</div>

Hello, I was wondering if there was a way to protect Kibana visuals or dashboards from being edited? Even sending a warning if they open the object to not to edit it would be the bare minimal. Mike

---

## [Automatically remove old reports](https://discuss.elastic.co/t/automatically-remove-old-reports/321201)

<div class="topic-metadata">

**Author:** [@JohnJ\_M](https://discuss.elastic.co/u/JohnJ_M)\
**Replies:** 2\
**Last updated:** [December 14, 2022, 11:46pm UTC](https://discuss.elastic.co/t/automatically-remove-old-reports/321201 "2022-12-14T23:46:22Z")

</div>

Hi the community. I've alerters that generates multiple report once per week sent per mail automatically. Reports older than 2 weeks are not necessary and I want to be able to setup an automatic cleaning of those report…

---

## [Getting data from lagging database](https://discuss.elastic.co/t/getting-data-from-lagging-database/321244)

<div class="topic-metadata">

**Author:** [@raunakraje](https://discuss.elastic.co/u/raunakraje)\
**Replies:** 0\
**Last updated:** [December 14, 2022, 9:46pm UTC](https://discuss.elastic.co/t/getting-data-from-lagging-database/321244 "2022-12-14T21:46:51Z")

</div>

Hi Guys, I have 2 MSSQL databases a Production db(A) and a Backup db (B). Data from Production DB gets updated in Backup DB with a lag of 15 mins. I am trying to get data from Backup DB but due to this lag I am unable t…

---

## [Dec 15th, 2022: \[EN\] NLP: Using a Question Answering model to talk to your favorite Christmas song](https://discuss.elastic.co/t/dec-15th-2022-en-nlp-using-a-question-answering-model-to-talk-to-your-favorite-christmas-song/321125)

<div class="topic-metadata">

**Author:** [@Priscilla\_Parodi](https://discuss.elastic.co/u/Priscilla_Parodi)\
**Replies:** 0\
**Last updated:** [December 14, 2022, 11:00pm UTC](https://discuss.elastic.co/t/dec-15th-2022-en-nlp-using-a-question-answering-model-to-talk-to-your-favorite-christmas-song/321125 "2022-12-14T23:00:00Z")

</div>

Natural language processing (NLP) is the branch of artificial intelligence (AI) that aims to understand human language as close as possible to human interpretation by combining computational linguistics with statistic…

---

## [Add Metric Aggregation inside the bucket aggregation query to get metrics of all buckets using DSL Query](https://discuss.elastic.co/t/add-metric-aggregation-inside-the-bucket-aggregation-query-to-get-metrics-of-all-buckets-using-dsl-query/321217)

<div class="topic-metadata">

**Author:** [@Divyank\_Mahalle](https://discuss.elastic.co/u/Divyank_Mahalle)\
**Replies:** 1\
**Last updated:** [December 14, 2022, 7:27pm UTC](https://discuss.elastic.co/t/add-metric-aggregation-inside-the-bucket-aggregation-query-to-get-metrics-of-all-buckets-using-dsl-query/321217 "2022-12-14T19:27:39Z")

</div>

Hi, I am able to get bucket aggregation results for below DSL Query,But I want to get metric aggregation for all buckets inside the same bucket aggregation query. Bucket aggrgation query: { "size": 0, "query":…

---

## [Can I run multiple Elasticsearch instances in one server?](https://discuss.elastic.co/t/can-i-run-multiple-elasticsearch-instances-in-one-server/321230)

<div class="topic-metadata">

**Author:** [@Lakshmi\_Kumari](https://discuss.elastic.co/u/Lakshmi_Kumari)\
**Replies:** 3\
**Last updated:** [December 14, 2022, 5:50pm UTC](https://discuss.elastic.co/t/can-i-run-multiple-elasticsearch-instances-in-one-server/321230 "2022-12-14T17:50:50Z")

</div>

Can I run multiple Elasticsearch instances in one server? -If yes, How can I install 2 Elasticsearch instances in a single Linux server. I am aware if we use "yum install" will be installed without any issue. Thanks i…

---

## [How to access Kibana in different VM](https://discuss.elastic.co/t/how-to-access-kibana-in-different-vm/321224)

<div class="topic-metadata">

**Author:** [@Vivek\_Arumugam](https://discuss.elastic.co/u/Vivek_Arumugam)\
**Replies:** 3\
**Last updated:** [December 14, 2022, 3:37pm UTC](https://discuss.elastic.co/t/how-to-access-kibana-in-different-vm/321224 "2022-12-14T15:37:19Z")

</div>

Hi Team, I have installed Kibana and Elasticsearch in server. I am able access Kibana in same machine. But in different VM it not working. Please help me out

---

## [Log collector solution](https://discuss.elastic.co/t/log-collector-solution/320964)

<div class="topic-metadata">

**Author:** [@Indeed2000](https://discuss.elastic.co/u/Indeed2000)\
**Replies:** 2\
**Last updated:** [December 14, 2022, 3:32pm UTC](https://discuss.elastic.co/t/log-collector-solution/320964 "2022-12-14T15:32:48Z")

</div>

Hi TL;DR: need log collector for file with minimum configuration, and support different conditions. I have 3 servers that generate log file daily with size about 12GB (12\*3=36GB) How can I gather these files on centra…

---

## [How to aggregate data across multiple fields?](https://discuss.elastic.co/t/how-to-aggregate-data-across-multiple-fields/318943)

<div class="topic-metadata">

**Author:** [@tinrik](https://discuss.elastic.co/u/tinrik)\
**Replies:** 4\
**Last updated:** [November 16, 2022, 3:14pm UTC](https://discuss.elastic.co/t/how-to-aggregate-data-across-multiple-fields/318943 "2022-11-16T15:14:59Z")

</div>

Hi! I'm fairly new to Kibana. I'm trying to perform data aggregation across multiple fields, but don't seem to be approaching the problem the right way. Example use case: I have data about house prices. E.g. house "a" …

---

## [How to consume a Elastic indexs between different Clouds](https://discuss.elastic.co/t/how-to-consume-a-elastic-indexs-between-different-clouds/321162)

<div class="topic-metadata">

**Author:** [@Rodrigoscotti](https://discuss.elastic.co/u/Rodrigoscotti)\
**Replies:** 5\
**Last updated:** [December 14, 2022, 12:35pm UTC](https://discuss.elastic.co/t/how-to-consume-a-elastic-indexs-between-different-clouds/321162 "2022-12-14T12:35:15Z")

</div>

We run Elasticsearch using a self-hosting solution from GCP. Our services consume a BD in Elastic to work correctly. A new client asks us if it is possible to consume their Elastic BD directly from their Elastic self-hos…

---

## [Send raw logs to elastic server](https://discuss.elastic.co/t/send-raw-logs-to-elastic-server/321096)

<div class="topic-metadata">

**Author:** [@Indeed2000](https://discuss.elastic.co/u/Indeed2000)\
**Replies:** 13\
**Last updated:** [December 14, 2022, 11:54am UTC](https://discuss.elastic.co/t/send-raw-logs-to-elastic-server/321096 "2022-12-14T11:54:36Z")

</div>

Hi I have 2 question about elastic 1-how can i send all files located in specific path with random name via filebeat like this: /var/log/app/serverlog.log /var/log/app/applog.log /var/log/app/exceptionlog.log ... t…

---

## [Timestamp includes different timezones](https://discuss.elastic.co/t/timestamp-includes-different-timezones/321190)

<div class="topic-metadata">

**Author:** [@PRASHANT\_MEHTA](https://discuss.elastic.co/u/PRASHANT_MEHTA)\
**Replies:** 1\
**Last updated:** [December 14, 2022, 11:52am UTC](https://discuss.elastic.co/t/timestamp-includes-different-timezones/321190 "2022-12-14T11:52:41Z")

</div>

Hello All, In response from backend data I have event with timezone, i have added one field in elastic templte :nextEvent. The date format of above fields are important, it has timezone in it.. like below: "nextEvent"…

---

## [After enabling the https not able to launch kibana dashboard](https://discuss.elastic.co/t/after-enabling-the-https-not-able-to-launch-kibana-dashboard/321200)

<div class="topic-metadata">

**Author:** [@Manjiri](https://discuss.elastic.co/u/Manjiri)\
**Replies:** 2\
**Last updated:** [December 14, 2022, 10:06am UTC](https://discuss.elastic.co/t/after-enabling-the-https-not-able-to-launch-kibana-dashboard/321200 "2022-12-14T10:06:41Z")

</div>

We enable https but we are able to launch the Elasticsearch URL but we are not able to launch kibana it is showing can't reach the page

---

## [Dec 14, 2022: \[EN\] Our favorite Kibana application - Discover](https://discuss.elastic.co/t/dec-14-2022-en-our-favorite-kibana-application-discover/321052)

<div class="topic-metadata">

**Author:** [@bhavyarm](https://discuss.elastic.co/u/bhavyarm)\
**Replies:** 0\
**Last updated:** [December 14, 2022, 8:00am UTC](https://discuss.elastic.co/t/dec-14-2022-en-our-favorite-kibana-application-discover/321052 "2022-12-14T08:00:16Z")

</div>

For this advent post, I decided I will ask my teammates for their favourite Kibana application. We all picked discover. Kibana's discover is the most used application of Kibana. It lets you explore your data and ask …

---

## [Ordering on parent-aggregations based on sub-aggregrations](https://discuss.elastic.co/t/ordering-on-parent-aggregations-based-on-sub-aggregrations/320437)

<div class="topic-metadata">

**Author:** [@Rajamallikeerthana\_R](https://discuss.elastic.co/u/Rajamallikeerthana_R)\
**Replies:** 1\
**Last updated:** [December 14, 2022, 7:51am UTC](https://discuss.elastic.co/t/ordering-on-parent-aggregations-based-on-sub-aggregrations/320437 "2022-12-14T07:51:34Z")

</div>

Hi, I am using elasticsearch 6.3 . I have an index event\_v4 which store the data of all events handled by our company. Now i need to get a list of cities that satisfy a certain conditions. But if the count is less than r…

---

## [Regarding Ingest Node Pipeline](https://discuss.elastic.co/t/regarding-ingest-node-pipeline/321094)

<div class="topic-metadata">

**Author:** [@yasar](https://discuss.elastic.co/u/yasar)\
**Replies:** 9\
**Last updated:** [December 14, 2022, 7:26am UTC](https://discuss.elastic.co/t/regarding-ingest-node-pipeline/321094 "2022-12-14T07:26:52Z")

</div>

Hi team, We would like to know about the ingest node pipeline. we are new in this platform. Normally, an application team sending the logs through the below mentioned path. Logs Flow Path: FileBeat/MetricBeat -\> AWS K…

---

## [Elastic search in splitting the words if dot comes between](https://discuss.elastic.co/t/elastic-search-in-splitting-the-words-if-dot-comes-between/321187)

<div class="topic-metadata">

**Author:** [@jothi\_mano](https://discuss.elastic.co/u/jothi_mano)\
**Replies:** 1\
**Last updated:** [December 14, 2022, 7:21am UTC](https://discuss.elastic.co/t/elastic-search-in-splitting-the-words-if-dot-comes-between/321187 "2022-12-14T07:21:37Z")

</div>

If a dot comes between the search string , it is not returning the proper results. Example : search string ' 0002.AB' Need a result which should list the results that matches the whole word first and followed by other…

---

## [How to handle missing values for date datatype while ingesting the data in Elasticsearch](https://discuss.elastic.co/t/how-to-handle-missing-values-for-date-datatype-while-ingesting-the-data-in-elasticsearch/320524)

<div class="topic-metadata">

**Author:** [@Durga\_Prasad](https://discuss.elastic.co/u/Durga_Prasad)\
**Replies:** 3\
**Last updated:** [December 14, 2022, 5:49am UTC](https://discuss.elastic.co/t/how-to-handle-missing-values-for-date-datatype-while-ingesting-the-data-in-elasticsearch/320524 "2022-12-14T05:49:12Z")

</div>

There are few empty values for date datatype field in a csv file. So, while ingesting the data in Kibana (uploading csv file), getting the below error. Some documents could not be imported 1445 out of 45436 documents c…

[Previous page](https://discuss.elastic.co/tag/none.md?no_tags=true&page=476)

[Next page](https://discuss.elastic.co/tag/none.md?no_tags=true&page=478)
