# \#none

**URL:** https://discuss.elastic.co/tag/none.md?no_tags=true&page=482

[Latest](https://discuss.elastic.co/latest.md) · [Categories](https://discuss.elastic.co/categories.md) · [Tags](https://discuss.elastic.co/tags.md)

**Page:** 483

---

## [Wrong number of result using match\_phrase\_prefix](https://discuss.elastic.co/t/wrong-number-of-result-using-match-phrase-prefix/318838)

<div class="topic-metadata">

**Author:** [@Gorelldk](https://discuss.elastic.co/u/Gorelldk)\
**Replies:** 12\
**Last updated:** [December 8, 2022, 8:15am UTC](https://discuss.elastic.co/t/wrong-number-of-result-using-match-phrase-prefix/318838 "2022-12-08T08:15:22Z")

</div>

Hi all I have a on-premise ELK instance where i have an index with roughly 50.000 documents with 30 columns. One of the columns is name, indexed as a text. I have 4500 documents called VFCXXXX where the X is numbers, i…

---

## [Extract base64 encoded field from JSON message and write the decoded field to a file](https://discuss.elastic.co/t/extract-base64-encoded-field-from-json-message-and-write-the-decoded-field-to-a-file/320398)

<div class="topic-metadata">

**Author:** [@Arinjay\_Jain](https://discuss.elastic.co/u/Arinjay_Jain)\
**Replies:** 5\
**Last updated:** [December 8, 2022, 7:48am UTC](https://discuss.elastic.co/t/extract-base64-encoded-field-from-json-message-and-write-the-decoded-field-to-a-file/320398 "2022-12-08T07:48:51Z")

</div>

Hi All, I have the following logstash pipeline configuration. input { tcp { port =\> 5102 codec =\> json } } filter { json { source =\> "message" } } output { stdout { c…

---

## [Storage recommendations for Elastic](https://discuss.elastic.co/t/storage-recommendations-for-elastic/320655)

<div class="topic-metadata">

**Author:** [@Sireesha](https://discuss.elastic.co/u/Sireesha)\
**Replies:** 4\
**Last updated:** [December 8, 2022, 7:38am UTC](https://discuss.elastic.co/t/storage-recommendations-for-elastic/320655 "2022-12-08T07:38:29Z")

</div>

Hi , What is the recommended storage to deploy Elastic search . We are weighting options between local vs netapp storage . Please guide.

---

## [Elastalert is not triggering the email notifications](https://discuss.elastic.co/t/elastalert-is-not-triggering-the-email-notifications/320735)

<div class="topic-metadata">

**Author:** [@vikash\_bugata](https://discuss.elastic.co/u/vikash_bugata)\
**Replies:** 2\
**Last updated:** [December 8, 2022, 6:17am UTC](https://discuss.elastic.co/t/elastalert-is-not-triggering-the-email-notifications/320735 "2022-12-08T06:17:14Z")

</div>

I have defined the rules under the rules folder but my rules were not triggering email alerts even the matching expression is found on the logs. I am running the elastalert on the Linux OS and our elasticsearch version …

---

## [Is there any funtionality in Elastic Search using which we can perform mathematical operations or calculations on the entries in an index?](https://discuss.elastic.co/t/is-there-any-funtionality-in-elastic-search-using-which-we-can-perform-mathematical-operations-or-calculations-on-the-entries-in-an-index/320741)

<div class="topic-metadata">

**Author:** [@Shraddha29](https://discuss.elastic.co/u/Shraddha29)\
**Replies:** 1\
**Last updated:** [December 8, 2022, 5:55am UTC](https://discuss.elastic.co/t/is-there-any-funtionality-in-elastic-search-using-which-we-can-perform-mathematical-operations-or-calculations-on-the-entries-in-an-index/320741 "2022-12-08T05:55:59Z")

</div>

Is there any functionality in Elastic Search using which we can perform mathematical operations or calculations on the entries in an index?

---

## [How to view remote clusters index metadata](https://discuss.elastic.co/t/how-to-view-remote-clusters-index-metadata/320518)

<div class="topic-metadata">

**Author:** [@prabhakar\_talari](https://discuss.elastic.co/u/prabhakar_talari)\
**Replies:** 4\
**Last updated:** [December 8, 2022, 5:24am UTC](https://discuss.elastic.co/t/how-to-view-remote-clusters-index-metadata/320518 "2022-12-08T05:24:58Z")

</div>

Hi Team, I have a 3 clustesr setup like below cluster-query cluster-a cluster-b I added a & b as a remote clusters in cluster-query to search the data from query cluster kibana. Now i want to get the index mapping …

---

## [High Seach/Query Latency during Indexing Jobs](https://discuss.elastic.co/t/high-seach-query-latency-during-indexing-jobs/320615)

<div class="topic-metadata">

**Author:** [@vishnu\_teja](https://discuss.elastic.co/u/vishnu_teja)\
**Replies:** 7\
**Last updated:** [December 8, 2022, 4:47am UTC](https://discuss.elastic.co/t/high-seach-query-latency-during-indexing-jobs/320615 "2022-12-08T04:47:07Z")

</div>

Hi Everyone, We are recently facing issues with high latency in our Elastic Search Cluster, especially during Ingestion/Indexing in cluster. We run a batchJob which calls the update API of ES, so it will either update t…

---

## [API for configuring Fleet Server settings?](https://discuss.elastic.co/t/api-for-configuring-fleet-server-settings/318879)

<div class="topic-metadata">

**Author:** [@learningelastic](https://discuss.elastic.co/u/learningelastic)\
**Replies:** 2\
**Last updated:** [December 8, 2022, 4:18am UTC](https://discuss.elastic.co/t/api-for-configuring-fleet-server-settings/318879 "2022-12-08T04:18:23Z")

</div>

Is there a programmatic way to set the values for Fleet Server as shown in this image here? I'm ok with command line tools, restful api, or some other automated service. There's a lot of elastic documentation, but I…

---

## [Termsvector of an element of array](https://discuss.elastic.co/t/termsvector-of-an-element-of-array/320732)

<div class="topic-metadata">

**Author:** [@tim2020work2](https://discuss.elastic.co/u/tim2020work2)\
**Replies:** 0\
**Last updated:** [December 8, 2022, 3:48am UTC](https://discuss.elastic.co/t/termsvector-of-an-element-of-array/320732 "2022-12-08T03:48:49Z")

</div>

How do I view terms vector of a field in an element of array? API \_termvectors accept input "fields". i.e "fields" : \["msg"\], } If I want to view term vector of an element of array, the following does not work "f…

---

## [What if there are no rules enabled?](https://discuss.elastic.co/t/what-if-there-are-no-rules-enabled/320714)

<div class="topic-metadata">

**Author:** [@lamp123432](https://discuss.elastic.co/u/lamp123432)\
**Replies:** 1\
**Last updated:** [December 8, 2022, 3:48am UTC](https://discuss.elastic.co/t/what-if-there-are-no-rules-enabled/320714 "2022-12-08T03:48:24Z")

</div>

Will Elastic Security / Endpoint Protection still protect/prevent malware without the rules enabled in the SIEM?

---

## [Elastic agent is unhealthy](https://discuss.elastic.co/t/elastic-agent-is-unhealthy/320664)

<div class="topic-metadata">

**Author:** [@lusynda](https://discuss.elastic.co/u/lusynda)\
**Replies:** 2\
**Last updated:** [December 8, 2022, 2:40am UTC](https://discuss.elastic.co/t/elastic-agent-is-unhealthy/320664 "2022-12-08T02:40:43Z")

</div>

Hi all, I have a case when after i enroll the fleet server to Elasticsearch. It become health for a while then became unhealthy. I checked the log then it said this: {"@timestamp":"2022-12-07T08:58:09.831566388Z","ag…

---

## [What privileges does the metricbeat api key need?](https://discuss.elastic.co/t/what-privileges-does-the-metricbeat-api-key-need/320727)

<div class="topic-metadata">

**Author:** [@Russell\_Fulton](https://discuss.elastic.co/u/Russell_Fulton)\
**Replies:** 0\
**Last updated:** [December 8, 2022, 2:28am UTC](https://discuss.elastic.co/t/what-privileges-does-the-metricbeat-api-key-need/320727 "2022-12-08T02:28:55Z")

</div>

Setting up monitoring and following the instruction https://www.elastic.co/guide/en/beats/metricbeat/7.17/metricbeat-installation-configuration.html I world rather not use Elastic...

---

## [Nodes stats API CPU usage value is -1](https://discuss.elastic.co/t/nodes-stats-api-cpu-usage-value-is-1/319782)

<div class="topic-metadata">

**Author:** [@ysk8830](https://discuss.elastic.co/u/ysk8830)\
**Replies:** 1\
**Last updated:** [December 8, 2022, 1:13am UTC](https://discuss.elastic.co/t/nodes-stats-api-cpu-usage-value-is-1/319782 "2022-12-08T01:13:40Z")

</div>

Hello, I have a question. I have installed elasticsearch on azure. OS is Ubuntu. And look up the cpu usage. I ran '\_cat/nodes?format=json' , and the cpu value is -1. can not understand. I browsed the documentation (G…

---

## [Deletion of existing index data when threshold reached](https://discuss.elastic.co/t/deletion-of-existing-index-data-when-threshold-reached/320598)

<div class="topic-metadata">

**Author:** [@atpr](https://discuss.elastic.co/u/atpr)\
**Replies:** 5\
**Last updated:** [December 7, 2022, 10:48pm UTC](https://discuss.elastic.co/t/deletion-of-existing-index-data-when-threshold-reached/320598 "2022-12-07T22:48:05Z")

</div>

Hi Expert, We are looking to support the customer use case where they are buying the license as per the GB of data they use or no of records they store or no of days data stored. As per license they can either buy more…

---

## [Convert text field to date](https://discuss.elastic.co/t/convert-text-field-to-date/320721)

<div class="topic-metadata">

**Author:** [@stefanocog](https://discuss.elastic.co/u/stefanocog)\
**Replies:** 2\
**Last updated:** [December 7, 2022, 10:36pm UTC](https://discuss.elastic.co/t/convert-text-field-to-date/320721 "2022-12-07T22:36:21Z")

</div>

Hello, I need convert a field in text format into date, i need to have another date field besides @timestamp, the @timestamp field identifies the arrival time of the log, instead the dataRisposta field (in case of respo…

---

## [Reproduce App search "Top queries with no clicks" in Kibana](https://discuss.elastic.co/t/reproduce-app-search-top-queries-with-no-clicks-in-kibana/318595)

<div class="topic-metadata">

**Author:** [@Gustavo\_Llermaly](https://discuss.elastic.co/u/Gustavo_Llermaly)\
**Replies:** 0\
**Last updated:** [November 9, 2022, 11:26pm UTC](https://discuss.elastic.co/t/reproduce-app-search-top-queries-with-no-clicks-in-kibana/318595 "2022-11-09T23:26:32Z")

</div>

Hello, I'm trying to reproduce the App Search analytics dashboard in Kibana to have more flexibility. I could reproduce everything but the "Top queries with no clicks" dashboard because combines two document types a…

---

## [How to integrate kibana dashboards as a widget to other javascript based native UI](https://discuss.elastic.co/t/how-to-integrate-kibana-dashboards-as-a-widget-to-other-javascript-based-native-ui/320265)

<div class="topic-metadata">

**Author:** [@Tukaram](https://discuss.elastic.co/u/Tukaram)\
**Replies:** 6\
**Last updated:** [December 7, 2022, 10:03pm UTC](https://discuss.elastic.co/t/how-to-integrate-kibana-dashboards-as-a-widget-to-other-javascript-based-native-ui/320265 "2022-12-07T22:03:39Z")

</div>

Is there any easy way to integrate Kibana dashboard / panel as a widget to third party UI(developed using the react js etc ). We dont want user to navigate to kibana from our native apps and instead show the dashboards …

---

## [Re-installing elasticsearch](https://discuss.elastic.co/t/re-installing-elasticsearch/320602)

<div class="topic-metadata">

**Author:** [@ericmalta](https://discuss.elastic.co/u/ericmalta)\
**Replies:** 4\
**Last updated:** [December 7, 2022, 9:20pm UTC](https://discuss.elastic.co/t/re-installing-elasticsearch/320602 "2022-12-07T21:20:32Z")

</div>

Hello team I have a quick question. If I re-install my elasticsearch cluster via apt like this: sudo apt install --reinstall -o Dpkg::Options::="--force-confask,confnew,confmiss" elasticsearch Will I lose my cluster da…

---

## [Cannot give custom plugin permission org.elasticsearch.secure\_sm.ThreadPermission "modifyArbitraryThreadGroup"](https://discuss.elastic.co/t/cannot-give-custom-plugin-permission-org-elasticsearch-secure-sm-threadpermission-modifyarbitrarythreadgroup/320720)

<div class="topic-metadata">

**Author:** [@smillies](https://discuss.elastic.co/u/smillies)\
**Replies:** 0\
**Last updated:** [December 7, 2022, 8:40pm UTC](https://discuss.elastic.co/t/cannot-give-custom-plugin-permission-org-elasticsearch-secure-sm-threadpermission-modifyarbitrarythreadgroup/320720 "2022-12-07T20:40:26Z")

</div>

I have written a custom plugin that includes some third-party jars that do magic stuff requiring certain permissions. So I have added them to my plugin-security.policy like this grant { permission java.lang.reflect.Re…

---

## [Ingest Pipeline for custom logs](https://discuss.elastic.co/t/ingest-pipeline-for-custom-logs/320380)

<div class="topic-metadata">

**Author:** [@shuuny-matrix](https://discuss.elastic.co/u/shuuny-matrix)\
**Replies:** 6\
**Last updated:** [December 7, 2022, 5:42pm UTC](https://discuss.elastic.co/t/ingest-pipeline-for-custom-logs/320380 "2022-12-07T17:42:37Z")

</div>

Hi, I am ingesting the standards syslogs using the elastic agent "custom logs" integration. I am trying to parse the logs before indexing and for that I am using ingest pipeline. I have two processors for that: Grok an…

---

## [Count the latest records in Kibana visualization?](https://discuss.elastic.co/t/count-the-latest-records-in-kibana-visualization/320669)

<div class="topic-metadata">

**Author:** [@Maruthappan\_Muthu](https://discuss.elastic.co/u/Maruthappan_Muthu)\
**Replies:** 6\
**Last updated:** [December 7, 2022, 6:28pm UTC](https://discuss.elastic.co/t/count-the-latest-records-in-kibana-visualization/320669 "2022-12-07T18:28:04Z")

</div>

I have document like as below Every two minutes once the "status" field records will get change and I want to count only the recent status records in Kibana visualization. Ex., The total count of status value 1 is 3 & …

---

## [Dec 4th 2022: \[EN\] Ingesting JSON logs with Elastic-Agent (and/or Filebeat)](https://discuss.elastic.co/t/dec-4th-2022-en-ingesting-json-logs-with-elastic-agent-and-or-filebeat/319536)

<div class="topic-metadata">

**Author:** [@TiagoQueiroz](https://discuss.elastic.co/u/TiagoQueiroz)\
**Replies:** 2\
**Last updated:** [December 7, 2022, 3:26pm UTC](https://discuss.elastic.co/t/dec-4th-2022-en-ingesting-json-logs-with-elastic-agent-and-or-filebeat/319536 "2022-12-07T15:26:13Z")

</div>

This article is also available in Portuguese. Structured logging has almost became a standard in the industry, allowing for easy understanding and parsing of the logs. While the Elastic-Agent provides integrations to…

---

## [New Logstash Grok add\_field](https://discuss.elastic.co/t/new-logstash-grok-add-field/320659)

<div class="topic-metadata">

**Author:** [@anon74213320](https://discuss.elastic.co/u/anon74213320)\
**Replies:** 2\
**Last updated:** [December 7, 2022, 3:14pm UTC](https://discuss.elastic.co/t/new-logstash-grok-add-field/320659 "2022-12-07T15:14:14Z")

</div>

Hi everyone I am trying to add a new field for pick up a hostname from a logfile like this format: Source : \\\\abc123 I tried with setting patterns file and add\_filed in grok and mutate but it is not added, it seems is…

---

## [Logstash: Optional fields in grok](https://discuss.elastic.co/t/logstash-optional-fields-in-grok/320604)

<div class="topic-metadata">

**Author:** [@anon99430464](https://discuss.elastic.co/u/anon99430464)\
**Replies:** 2\
**Last updated:** [December 7, 2022, 2:35pm UTC](https://discuss.elastic.co/t/logstash-optional-fields-in-grok/320604 "2022-12-07T14:35:34Z")

</div>

Hi there I'm trying to create a logstash for our logs. Our log files can look like the following 2022-11-22 10:43:59,061 INFO \[SERVER1.Subscription\] |\>\> | \[ctx:0ecaa086-f9b7-4d0e-bce4-1b8513238745\] \[req:facdaf2c-b8e6…

---

## [Insert Events with Changed Status Only using Logstash](https://discuss.elastic.co/t/insert-events-with-changed-status-only-using-logstash/319196)

<div class="topic-metadata">

**Author:** [@sajid](https://discuss.elastic.co/u/sajid)\
**Replies:** 2\
**Last updated:** [December 7, 2022, 1:17pm UTC](https://discuss.elastic.co/t/insert-events-with-changed-status-only-using-logstash/319196 "2022-12-07T13:17:56Z")

</div>

Hi All, Need your help to solve an issue. Below are the details: Pipeline1 : Polls multiple http endpoints every minute using http\_poller and insert the response to index1 in ES. Below is the sample response of one of…

---

## [Open a non-http link](https://discuss.elastic.co/t/open-a-non-http-link/320674)

<div class="topic-metadata">

**Author:** [@GinkoLucas](https://discuss.elastic.co/u/GinkoLucas)\
**Replies:** 1\
**Last updated:** [December 7, 2022, 11:39am UTC](https://discuss.elastic.co/t/open-a-non-http-link/320674 "2022-12-07T11:39:59Z")

</div>

Hello, In my data i have some ip adress. I would like to open a teamviewer connection with this IP adress. So, for this, i have modified the data view. I change the field's type in "Link", and i put this in the URL tem…

---

## [/usr/share/elasticsearch/bin/elasticsearch](https://discuss.elastic.co/t/usr-share-elasticsearch-bin-elasticsearch/320640)

<div class="topic-metadata">

**Author:** [@Alejandro\_Abeijon](https://discuss.elastic.co/u/Alejandro_Abeijon)\
**Replies:** 2\
**Last updated:** [December 7, 2022, 11:27am UTC](https://discuss.elastic.co/t/usr-share-elasticsearch-bin-elasticsearch/320640 "2022-12-07T11:27:58Z")

</div>

Hi, thanks in advance for the help. I installed Elasticsearch in a thousand ways and I always get the same error. Can someone guide me where to start exploring? Thank you very much! elasticsearch@test:~$ /usr/share/el…

---

## [How to remove .Keywords in kibana](https://discuss.elastic.co/t/how-to-remove-keywords-in-kibana/320677)

<div class="topic-metadata">

**Author:** [@vijay78](https://discuss.elastic.co/u/vijay78)\
**Replies:** 2\
**Last updated:** [December 7, 2022, 11:19am UTC](https://discuss.elastic.co/t/how-to-remove-keywords-in-kibana/320677 "2022-12-07T11:19:02Z")

</div>

Can someone assist here with how to remove (exclude)these highlighted .keywords in kibana ,thanking in advance.

---

## [Issue while updating the TLS certificates](https://discuss.elastic.co/t/issue-while-updating-the-tls-certificates/320472)

<div class="topic-metadata">

**Author:** [@h.allaoui](https://discuss.elastic.co/u/h.allaoui)\
**Replies:** 1\
**Last updated:** [December 7, 2022, 10:58am UTC](https://discuss.elastic.co/t/issue-while-updating-the-tls-certificates/320472 "2022-12-07T10:58:53Z")

</div>

Hi All, I tried to update the TLS certificates on ECE UI using below certificates got from GoDaddy but it is failing. 57736c67a7538a4.crt 57736c67a7538a4.pem gd\_bundle-g2-g1.crt The chain file uploaded was created b…

---

## [How to change the mappings of an index in python itself?](https://discuss.elastic.co/t/how-to-change-the-mappings-of-an-index-in-python-itself/320666)

<div class="topic-metadata">

**Author:** [@Shashank02](https://discuss.elastic.co/u/Shashank02)\
**Replies:** 2\
**Last updated:** [December 7, 2022, 10:15am UTC](https://discuss.elastic.co/t/how-to-change-the-mappings-of-an-index-in-python-itself/320666 "2022-12-07T10:15:23Z")

</div>

I want to change the type of text to keyword of a csv file that I'm uploading in Elasticsearch using the Elastic Search client in Python. But I'm getting this error: elasticsearch.BadRequestError: BadRequestError(400, '…

[Previous page](https://discuss.elastic.co/tag/none.md?no_tags=true&page=481)

[Next page](https://discuss.elastic.co/tag/none.md?no_tags=true&page=483)
