# \#none

**URL:** https://discuss.elastic.co/tag/none.md?no_tags=true&page=478

[Latest](https://discuss.elastic.co/latest.md) · [Categories](https://discuss.elastic.co/categories.md) · [Tags](https://discuss.elastic.co/tags.md)

**Page:** 479

---

## [Incorrect date format in Aggregation Based Table in Kibana](https://discuss.elastic.co/t/incorrect-date-format-in-aggregation-based-table-in-kibana/320819)

<div class="topic-metadata">

**Author:** [@victorhmorales](https://discuss.elastic.co/u/victorhmorales)\
**Replies:** 2\
**Last updated:** [December 13, 2022, 10:42pm UTC](https://discuss.elastic.co/t/incorrect-date-format-in-aggregation-based-table-in-kibana/320819 "2022-12-13T22:42:51Z")

</div>

Hello, I just upgraded Elastic from 8.4.3 to 8.5.2 and I'm having a problem using fields of type "date" in tables created in Aggregation Based in Kibana. The reason for using table in Aggregation Based is the 'Export' …

---

## [Using Curl to change cluster settings](https://discuss.elastic.co/t/using-curl-to-change-cluster-settings/321086)

<div class="topic-metadata">

**Author:** [@matt\_dee](https://discuss.elastic.co/u/matt_dee)\
**Replies:** 2\
**Last updated:** [December 13, 2022, 10:21pm UTC](https://discuss.elastic.co/t/using-curl-to-change-cluster-settings/321086 "2022-12-13T22:21:39Z")

</div>

Hi. I'm quite new to ES and have done most of the admin through kibana I was doing a cluster restart and disabled shard allocation via dev tools through Kibana. Now I've started the nodes back up Kibana is giving an e…

---

## [Error when opening kibana](https://discuss.elastic.co/t/error-when-opening-kibana/321164)

<div class="topic-metadata">

**Author:** [@Soren\_vdc](https://discuss.elastic.co/u/Soren_vdc)\
**Replies:** 0\
**Last updated:** [December 13, 2022, 8:06pm UTC](https://discuss.elastic.co/t/error-when-opening-kibana/321164 "2022-12-13T20:06:41Z")

</div>

Hi, In ECE, I have created new cluster but when I want to start kibana, I receive the error: {"ok":false,"message":"There was an internal server error."} 500 Internal Server Error Any idea what could cause this? br …

---

## [Logstash.conf error](https://discuss.elastic.co/t/logstash-conf-error/321157)

<div class="topic-metadata">

**Author:** [@limitless](https://discuss.elastic.co/u/limitless)\
**Replies:** 1\
**Last updated:** [December 13, 2022, 6:57pm UTC](https://discuss.elastic.co/t/logstash-conf-error/321157 "2022-12-13T18:57:04Z")

</div>

.\\bin\\logstash.bat -f logstash.conf "Using bundled JDK: A:\\logstash-8.5.3\\jdk\\bin\\java.exe" Sending Logstash logs to A:/logstash-8.5.3/logs which is now configured via log4j2.properties \[2022-12-13T22:19:36,586\]\[INFO …

---

## [Elastic agent on EKS unhealthy](https://discuss.elastic.co/t/elastic-agent-on-eks-unhealthy/321155)

<div class="topic-metadata">

**Author:** [@wh1sss](https://discuss.elastic.co/u/wh1sss)\
**Replies:** 0\
**Last updated:** [December 13, 2022, 5:34pm UTC](https://discuss.elastic.co/t/elastic-agent-on-eks-unhealthy/321155 "2022-12-13T17:34:14Z")

</div>

Hi everyone, I created a cluster on the elastic cloud and I'm using the "Kubernetes Security", "Kubernetes" and "Elastic APM" integrations. The agents are being installed directly on the EKS cluster on AWS with the m…

---

## [Request Body is Required](https://discuss.elastic.co/t/request-body-is-required/321139)

<div class="topic-metadata">

**Author:** [@Jonas\_S](https://discuss.elastic.co/u/Jonas_S)\
**Replies:** 6\
**Last updated:** [December 13, 2022, 3:24pm UTC](https://discuss.elastic.co/t/request-body-is-required/321139 "2022-12-13T15:24:23Z")

</div>

Hello, every time i try to use the Kibana Dev Tools, if the request has a body it fails with this: Yes, there are no newlines and also the request body is there: I saw many similar threads, but all without soluti…

---

## [During terms aggregation with partition we get sum\_other\_doc\_count \> 0 in between partitions](https://discuss.elastic.co/t/during-terms-aggregation-with-partition-we-get-sum-other-doc-count-0-in-between-partitions/321140)

<div class="topic-metadata">

**Author:** [@akleiber](https://discuss.elastic.co/u/akleiber)\
**Replies:** 3\
**Last updated:** [December 13, 2022, 3:29pm UTC](https://discuss.elastic.co/t/during-terms-aggregation-with-partition-we-get-sum-other-doc-count-0-in-between-partitions/321140 "2022-12-13T15:29:10Z")

</div>

We are running ES 6.8 and move some documents to another ES Cluster with a more recent version. We also transform the documents during that process. We need to group documents by a field, so we do this via a terms aggre…

---

## [Inconsistency in the number of documents](https://discuss.elastic.co/t/inconsistency-in-the-number-of-documents/321129)

<div class="topic-metadata">

**Author:** [@Ariel\_Zach](https://discuss.elastic.co/u/Ariel_Zach)\
**Replies:** 4\
**Last updated:** [December 13, 2022, 3:25pm UTC](https://discuss.elastic.co/t/inconsistency-in-the-number-of-documents/321129 "2022-12-13T15:25:38Z")

</div>

I have an index with 2 shards which have 1600M documents each (~3200M total), but when I calculate a histogram, the sum does not give me the total number of documents, the result is much less, what is the reason?

---

## [Store query in cache](https://discuss.elastic.co/t/store-query-in-cache/318994)

<div class="topic-metadata">

**Author:** [@Ismet](https://discuss.elastic.co/u/Ismet)\
**Replies:** 4\
**Last updated:** [December 13, 2022, 2:22pm UTC](https://discuss.elastic.co/t/store-query-in-cache/318994 "2022-12-13T14:22:53Z")

</div>

Hi, how to put query with aggregation in ram cache? I can't find an example. Version: 7.9 There is my query: GET product/\_search { "size": 0, "query": { "bool": { "must\_not": { "match": { …

---

## [Elastic search cluster showing unhealthy, Cluster "red"](https://discuss.elastic.co/t/elastic-search-cluster-showing-unhealthy-cluster-red/321070)

<div class="topic-metadata">

**Author:** [@Harsh3](https://discuss.elastic.co/u/Harsh3)\
**Replies:** 5\
**Last updated:** [December 13, 2022, 1:51pm UTC](https://discuss.elastic.co/t/elastic-search-cluster-showing-unhealthy-cluster-red/321070 "2022-12-13T13:51:35Z")

</div>

Hello ! I am new to Elasticsearch! This is the first time i am doing installation, if someone can pls help, have spent days searching for the issue but no luck .. We have kibana running inside EKS cluster and Elastic-s…

---

## [ElasticSearch Azure storage](https://discuss.elastic.co/t/elasticsearch-azure-storage/321124)

<div class="topic-metadata">

**Author:** [@OlLap](https://discuss.elastic.co/u/OlLap)\
**Replies:** 1\
**Last updated:** [December 13, 2022, 1:30pm UTC](https://discuss.elastic.co/t/elasticsearch-azure-storage/321124 "2022-12-13T13:30:54Z")

</div>

Hello everyone, is it possible to use Azure Storage account (Files share or Blob container) for Elasticsearch data nodes?

---

## [ECK managed elasticsearch (with TLS enabled) getting flooded with "received plaintext http traffic on an https channel" logs](https://discuss.elastic.co/t/eck-managed-elasticsearch-with-tls-enabled-getting-flooded-with-received-plaintext-http-traffic-on-an-https-channel-logs/321117)

<div class="topic-metadata">

**Author:** [@Daithi\_O\_Conchobhair](https://discuss.elastic.co/u/Daithi_O_Conchobhair)\
**Replies:** 4\
**Last updated:** [December 13, 2022, 12:36pm UTC](https://discuss.elastic.co/t/eck-managed-elasticsearch-with-tls-enabled-getting-flooded-with-received-plaintext-http-traffic-on-an-https-channel-logs/321117 "2022-12-13T12:36:33Z")

</div>

Hi there, This is such a strange issue I am not sure if it is a defect or something that I am doing wrong. I will say in my defence that I see it when I just use the quickstart guide also. Versions: IBM Kubernetes Se…

---

## [Kibana dashboard search view "aborted"](https://discuss.elastic.co/t/kibana-dashboard-search-view-aborted/320448)

<div class="topic-metadata">

**Author:** [@Marcin\_Frankiewicz](https://discuss.elastic.co/u/Marcin_Frankiewicz)\
**Replies:** 3\
**Last updated:** [December 13, 2022, 12:08pm UTC](https://discuss.elastic.co/t/kibana-dashboard-search-view-aborted/320448 "2022-12-13T12:08:04Z")

</div>

Hello, That topic is similar to : Kibana dashboard table view results in "Aborted" I have few a dashboard with every contains few visualisation, and they works fine, but one of them (search view) often shows me a messa…

---

## [Child Documents performance](https://discuss.elastic.co/t/child-documents-performance/321120)

<div class="topic-metadata">

**Author:** [@Emanuel\_Zienecker](https://discuss.elastic.co/u/Emanuel_Zienecker)\
**Replies:** 0\
**Last updated:** [December 13, 2022, 11:43am UTC](https://discuss.elastic.co/t/child-documents-performance/321120 "2022-12-13T11:43:26Z")

</div>

Hello, I am planning to change the model from nested of parent-child. The following model: Questions -\> Answer. Currently these were all stored nested, now just as parent-child. My question now is this: What makes more…

---

## [Logstash escaping characters, want to disable](https://discuss.elastic.co/t/logstash-escaping-characters-want-to-disable/318984)

<div class="topic-metadata">

**Author:** [@Johanna12221](https://discuss.elastic.co/u/Johanna12221)\
**Replies:** 2\
**Last updated:** [December 13, 2022, 7:51am UTC](https://discuss.elastic.co/t/logstash-escaping-characters-want-to-disable/318984 "2022-12-13T07:51:32Z")

</div>

Hi! I'm having a problem with how Logstash with JDBC input escapes characters. When I run the SQL query in SSMS I get the result fine: "\\publicerat\\IN0022.pdf" The JDBC input looks like this: input { jdbc { …

---

## [Installation on ubantu](https://discuss.elastic.co/t/installation-on-ubantu/316961)

<div class="topic-metadata">

**Author:** [@smitak](https://discuss.elastic.co/u/smitak)\
**Replies:** 15\
**Last updated:** [December 13, 2022, 7:30am UTC](https://discuss.elastic.co/t/installation-on-ubantu/316961 "2022-12-13T07:30:02Z")

</div>

Hello Sir, I have done the search functionality with fscrawler on local server. It is working good. Now I am uploading on ubantu server. Elastic search is active. But for fscralwer getting error for file content. Elast…

---

## [Kibana status yellow and taskmanager is unhealth](https://discuss.elastic.co/t/kibana-status-yellow-and-taskmanager-is-unhealth/321092)

<div class="topic-metadata">

**Author:** [@lusynda](https://discuss.elastic.co/u/lusynda)\
**Replies:** 2\
**Last updated:** [December 13, 2022, 7:16am UTC](https://discuss.elastic.co/t/kibana-status-yellow-and-taskmanager-is-unhealth/321092 "2022-12-13T07:16:30Z")

</div>

Hi all I have 1 kibana instance running for a elastic cluster. For sometime i have notice that my kibana always from green to yellow in the monitor tab so when i check the status of kibana it said that the taskManager …

---

## [How to split a message from rabbit?](https://discuss.elastic.co/t/how-to-split-a-message-from-rabbit/321067)

<div class="topic-metadata">

**Author:** [@TheZadok42](https://discuss.elastic.co/u/TheZadok42)\
**Replies:** 4\
**Last updated:** [December 13, 2022, 5:31am UTC](https://discuss.elastic.co/t/how-to-split-a-message-from-rabbit/321067 "2022-12-13T05:31:56Z")

</div>

Hi! I am trying to split this message: {"test": "Test"} {"test": "Test2"} into two messages using this simple config: input { rabbitmq { …

---

## [Track and show transactions progress based on codes](https://discuss.elastic.co/t/track-and-show-transactions-progress-based-on-codes/318867)

<div class="topic-metadata">

**Author:** [@Murali\_Y](https://discuss.elastic.co/u/Murali_Y)\
**Replies:** 3\
**Last updated:** [November 15, 2022, 3:26am UTC](https://discuss.elastic.co/t/track-and-show-transactions-progress-based-on-codes/318867 "2022-11-15T03:26:28Z")

</div>

Hello, We are writing our business flow related transactions start and end state using different state codes i.e. When we pick the transaction it will logged with code 10001 (in progress) and end of it will be logged wi…

---

## [Logstash GeoIP Database Manager: PKIX path building failed, \_geoip\_expired\_database tag](https://discuss.elastic.co/t/logstash-geoip-database-manager-pkix-path-building-failed-geoip-expired-database-tag/321073)

<div class="topic-metadata">

**Author:** [@leandrojmp](https://discuss.elastic.co/u/leandrojmp)\
**Replies:** 2\
**Last updated:** [December 12, 2022, 11:31pm UTC](https://discuss.elastic.co/t/logstash-geoip-database-manager-pkix-path-building-failed-geoip-expired-database-tag/321073 "2022-12-12T23:31:24Z")

</div>

Hello, I started to get this error on a couple of Logstash nodes. \[2022-12-12T20:10:23,983\]\[ERROR\]\[logstash.filters.geoip.databasemanager\] PKIX path building failed: sun.security.provider.certpath.SunCertPathBuilderExc…

---

## [Kibana Dashboard syslog ECS](https://discuss.elastic.co/t/kibana-dashboard-syslog-ecs/318911)

<div class="topic-metadata">

**Author:** [@sharbich](https://discuss.elastic.co/u/sharbich)\
**Replies:** 0\
**Last updated:** [November 14, 2022, 11:54pm UTC](https://discuss.elastic.co/t/kibana-dashboard-syslog-ecs/318911 "2022-11-14T23:54:59Z")

</div>

Hello, I get the following message in my Kibana Dashboard. "1 of 2 shards failed. The data you are seeing might be incomplete or wrong." The message disappears after 30 seconds and only comes back when i refresh the D…

---

## [Does Cloud Workload Protection requires license?](https://discuss.elastic.co/t/does-cloud-workload-protection-requires-license/320799)

<div class="topic-metadata">

**Author:** [@German\_Bravo](https://discuss.elastic.co/u/German_Bravo)\
**Replies:** 3\
**Last updated:** [December 12, 2022, 6:54pm UTC](https://discuss.elastic.co/t/does-cloud-workload-protection-requires-license/320799 "2022-12-12T18:54:16Z")

</div>

Hello, I just updated to v8.x from 7.x, and Im curious about Cloud Workload Protection. I saw that it is necessary to have a license for CIS benchmarking Kubernetes (findings section in Elastic Security), but for protec…

---

## [Read from Logstash file and format](https://discuss.elastic.co/t/read-from-logstash-file-and-format/320970)

<div class="topic-metadata">

**Author:** [@mail2shanth](https://discuss.elastic.co/u/mail2shanth)\
**Replies:** 1\
**Last updated:** [December 12, 2022, 6:22pm UTC](https://discuss.elastic.co/t/read-from-logstash-file-and-format/320970 "2022-12-12T18:22:35Z")

</div>

Hi, I am new to the Logstash. I've below log that I want to read in from a file, it is basically from another logstash server. Below is just one row from the file, there are millions of such rows. {"@timestamp":"2022-…

---

## [Disable auto refresh for Monitoring dashboards](https://discuss.elastic.co/t/disable-auto-refresh-for-monitoring-dashboards/320965)

<div class="topic-metadata">

**Author:** [@Animesh\_Agarwal](https://discuss.elastic.co/u/Animesh_Agarwal)\
**Replies:** 1\
**Last updated:** [December 12, 2022, 6:08pm UTC](https://discuss.elastic.co/t/disable-auto-refresh-for-monitoring-dashboards/320965 "2022-12-12T18:08:38Z")

</div>

Hi By default the refresh interval is 10s for monitoring dashboards in Kibana. Even though I can disable auto refresh, but if we load the page again, it gets reverted to 10s. How can we set the auto refresh to off per…

---

## [Using Grok filter](https://discuss.elastic.co/t/using-grok-filter/321051)

<div class="topic-metadata">

**Author:** [@Groove](https://discuss.elastic.co/u/Groove)\
**Replies:** 0\
**Last updated:** [December 12, 2022, 3:31pm UTC](https://discuss.elastic.co/t/using-grok-filter/321051 "2022-12-12T15:31:40Z")

</div>

Hello, I am pretty new to ELK stack. Currently I am trying to parse my application log using grok pattern. But since my logs are not structured I may have to use grok conditions, because in output I have windows event an…

---

## [Elastic Endpoint respond not working](https://discuss.elastic.co/t/elastic-endpoint-respond-not-working/320966)

<div class="topic-metadata">

**Author:** [@lusynda](https://discuss.elastic.co/u/lusynda)\
**Replies:** 1\
**Last updated:** [December 12, 2022, 2:54pm UTC](https://discuss.elastic.co/t/elastic-endpoint-respond-not-working/320966 "2022-12-12T14:54:38Z")

</div>

Hi all I'm trying the elastic endpoint security and i see that there is a respond option for the endpoint. But mine got greyout and it said my current version of the Agent is not supported and i need to upgrade the ver…

---

## [Using transform with enrich pipeline to enrich ip with latest vulnerabilities](https://discuss.elastic.co/t/using-transform-with-enrich-pipeline-to-enrich-ip-with-latest-vulnerabilities/320553)

<div class="topic-metadata">

**Author:** [@siginigin](https://discuss.elastic.co/u/siginigin)\
**Replies:** 6\
**Last updated:** [December 12, 2022, 2:51pm UTC](https://discuss.elastic.co/t/using-transform-with-enrich-pipeline-to-enrich-ip-with-latest-vulnerabilities/320553 "2022-12-12T14:51:05Z")

</div>

Hi, I want to enrich incoming event that contains local source.ip/destination.ip with vulnerability field with this logic: match source.ip with server.ip, get highest vulnerability.severity\_num from latest vulnerabilit…

---

## [Audit log time based deletion policy not working](https://discuss.elastic.co/t/audit-log-time-based-deletion-policy-not-working/321022)

<div class="topic-metadata">

**Author:** [@irivas95](https://discuss.elastic.co/u/irivas95)\
**Replies:** 3\
**Last updated:** [December 12, 2022, 12:59pm UTC](https://discuss.elastic.co/t/audit-log-time-based-deletion-policy-not-working/321022 "2022-12-12T12:59:00Z")

</div>

Hi, I have the following policy for deleting audit logs older than 7 days in my log4j2.properties config file: appender.audit\_rolling.type = RollingFile appender.audit\_rolling.name = audit\_rolling appender.audit\_rollin…

---

## [Is there any way to get past logs with elasticsearch?](https://discuss.elastic.co/t/is-there-any-way-to-get-past-logs-with-elasticsearch/320001)

<div class="topic-metadata">

**Author:** [@Halil\_Ibrahim\_Celik](https://discuss.elastic.co/u/Halil_Ibrahim_Celik)\
**Replies:** 2\
**Last updated:** [December 12, 2022, 12:16pm UTC](https://discuss.elastic.co/t/is-there-any-way-to-get-past-logs-with-elasticsearch/320001 "2022-12-12T12:16:14Z")

</div>

Hello everyone, I am using Elasticsearch and Kibana version 7.17.6 with UiPath orchestrator to view logs. I created dashboard in Kibana to view UiPath robot's usage. Sometimes Elasticsearch and Kibana is closing because…

---

## [Ordering of two fields in ELastic, specifically first one is of text and second is from integer](https://discuss.elastic.co/t/ordering-of-two-fields-in-elastic-specifically-first-one-is-of-text-and-second-is-from-integer/321026)

<div class="topic-metadata">

**Author:** [@rvadiga](https://discuss.elastic.co/u/rvadiga)\
**Replies:** 0\
**Last updated:** [December 12, 2022, 11:50am UTC](https://discuss.elastic.co/t/ordering-of-two-fields-in-elastic-specifically-first-one-is-of-text-and-second-is-from-integer/321026 "2022-12-12T11:50:12Z")

</div>

Hi Team, Could someone please show hints to implement the below requirement? I have an index where two fields, first one is text field, and second is of integer. I need to take the highest number row from the unique(f…

[Previous page](https://discuss.elastic.co/tag/none.md?no_tags=true&page=477)

[Next page](https://discuss.elastic.co/tag/none.md?no_tags=true&page=479)
