# \#none

**URL:** https://discuss.elastic.co/tag/none.md?no_tags=true&page=483

[Latest](https://discuss.elastic.co/latest.md) · [Categories](https://discuss.elastic.co/categories.md) · [Tags](https://discuss.elastic.co/tags.md)

**Page:** 484

---

## [Elasticsearch increase total\_in\_bytes value Memory](https://discuss.elastic.co/t/elasticsearch-increase-total-in-bytes-value-memory/320578)

<div class="topic-metadata">

**Author:** [@b\_Ensberg](https://discuss.elastic.co/u/b_Ensberg)\
**Replies:** 13\
**Last updated:** [December 7, 2022, 10:13am UTC](https://discuss.elastic.co/t/elasticsearch-increase-total-in-bytes-value-memory/320578 "2022-12-07T10:13:09Z")

</div>

Hello I'm running a single node on an Ubuntu machine. Currently I have not enough space on my node. "mem" : { "total\_in\_bytes" : 25217441792, "free\_in\_bytes" : 674197504, "used\_in\_bytes"…

---

## [Deleting Snapshot via Kibana - safe for data?](https://discuss.elastic.co/t/deleting-snapshot-via-kibana-safe-for-data/320663)

<div class="topic-metadata">

**Author:** [@smm](https://discuss.elastic.co/u/smm)\
**Replies:** 1\
**Last updated:** [December 7, 2022, 9:15am UTC](https://discuss.elastic.co/t/deleting-snapshot-via-kibana-safe-for-data/320663 "2022-12-07T09:15:35Z")

</div>

Hi there, I am running 7.17.4. In Kibana under: Stack Management -\> Snapshot and Restore -\> Snapshots and here in the Menu 'Snapshots' a have a list of (obviously) snapshots I did. My question: In case these snapshots…

---

## [Dec 7th, 2022: \[EN\] Map your distributed team in Kibana](https://discuss.elastic.co/t/dec-7th-2022-en-map-your-distributed-team-in-kibana/320438)

<div class="topic-metadata">

**Author:** [@xeraa](https://discuss.elastic.co/u/xeraa)\
**Replies:** 0\
**Last updated:** [December 7, 2022, 8:00am UTC](https://discuss.elastic.co/t/dec-7th-2022-en-map-your-distributed-team-in-kibana/320438 "2022-12-07T08:00:46Z")

</div>

Working in a distributed company like Elastic is great, but can sometimes be hard to grasp. Answering some seemingly simple questions can be surprisingly complicated, like: Show our team on a map, so I can explain o…

---

## [Upgraded to RHEL8 and cant start the instances or create new deployements](https://discuss.elastic.co/t/upgraded-to-rhel8-and-cant-start-the-instances-or-create-new-deployements/320597)

<div class="topic-metadata">

**Author:** [@mahesthogarpally](https://discuss.elastic.co/u/mahesthogarpally)\
**Replies:** 2\
**Last updated:** [December 7, 2022, 6:54am UTC](https://discuss.elastic.co/t/upgraded-to-rhel8-and-cant-start-the-instances-or-create-new-deployements/320597 "2022-12-07T06:54:52Z")

</div>

we have recently upgraded the OS on all of our servers to rhel 8.5,(3 directors/coordinators , 3 proxies,2 load balancers and 6 allocators). After the upgrade i noticed that i am not able to create a new deployment(clust…

---

## [Missing error details when adding Elasticsearch Datasource in Grafana](https://discuss.elastic.co/t/missing-error-details-when-adding-elasticsearch-datasource-in-grafana/320570)

<div class="topic-metadata">

**Author:** [@woocats](https://discuss.elastic.co/u/woocats)\
**Replies:** 0\
**Last updated:** [December 6, 2022, 11:23am UTC](https://discuss.elastic.co/t/missing-error-details-when-adding-elasticsearch-datasource-in-grafana/320570 "2022-12-06T11:23:42Z")

</div>

I'm trying to add an Elasticsearch instance that is deployed on a machine inside our network. We have a Grafana instance, that can add datasources from Elasticsearch cloud but when we try to add an Elasticsearch datasou…

---

## [Logstash mutate nested dynamic field path](https://discuss.elastic.co/t/logstash-mutate-nested-dynamic-field-path/320594)

<div class="topic-metadata">

**Author:** [@Shrouk\_Negm](https://discuss.elastic.co/u/Shrouk_Negm)\
**Replies:** 0\
**Last updated:** [December 6, 2022, 2:40pm UTC](https://discuss.elastic.co/t/logstash-mutate-nested-dynamic-field-path/320594 "2022-12-06T14:40:13Z")

</div>

logstash add field from third level BUT second level name is dynamic based on another field value like the bellow example entityType value depending on serviceName value so how should i do it input { kafka{ codec…

---

## [Cannot start elasticsearch with the root user](https://discuss.elastic.co/t/cannot-start-elasticsearch-with-the-root-user/320607)

<div class="topic-metadata">

**Author:** [@ericmalta](https://discuss.elastic.co/u/ericmalta)\
**Replies:** 9\
**Last updated:** [December 7, 2022, 3:02am UTC](https://discuss.elastic.co/t/cannot-start-elasticsearch-with-the-root-user/320607 "2022-12-07T03:02:44Z")

</div>

Have you seen that when you start the cluster it says you cannot start with the root user but then you change the /usr/share/elasticsearch and elasticsearch data directory ownership to the elasticsearch user and still th…

---

## [Manage kibana dashboard,visualization queries,configurations in distributed version control system like GIT](https://discuss.elastic.co/t/manage-kibana-dashboard-visualization-queries-configurations-in-distributed-version-control-system-like-git/316403)

<div class="topic-metadata">

**Author:** [@sai\_gddm](https://discuss.elastic.co/u/sai_gddm)\
**Replies:** 1\
**Last updated:** [November 9, 2022, 5:46am UTC](https://discuss.elastic.co/t/manage-kibana-dashboard-visualization-queries-configurations-in-distributed-version-control-system-like-git/316403 "2022-11-09T05:46:41Z")

</div>

I'm new to kibana and found from UI that we cannot get back saved dashboard once after deleting it.Is it possible to integrate the kibana dashboard configurations in GIT ?

---

## [Logstash applying json filter on all messages in filter when I did not apply it](https://discuss.elastic.co/t/logstash-applying-json-filter-on-all-messages-in-filter-when-i-did-not-apply-it/320628)

<div class="topic-metadata">

**Author:** [@d14](https://discuss.elastic.co/u/d14)\
**Replies:** 1\
**Last updated:** [December 7, 2022, 12:08am UTC](https://discuss.elastic.co/t/logstash-applying-json-filter-on-all-messages-in-filter-when-i-did-not-apply-it/320628 "2022-12-07T00:08:42Z")

</div>

I have a pipeline that looks like the below, for some reason I still get \[2022-12-06T17:30:17,641\]\[ERROR\]\[logstash.codecs.json \]\[main\] \[f764d264.....\] JSON parse error, original data now in message field ...........…

---

## [How do I transfer mappings from one index to another with Java Api Client](https://discuss.elastic.co/t/how-do-i-transfer-mappings-from-one-index-to-another-with-java-api-client/320489)

<div class="topic-metadata">

**Author:** [@JDev64](https://discuss.elastic.co/u/JDev64)\
**Replies:** 1\
**Last updated:** [December 6, 2022, 10:31pm UTC](https://discuss.elastic.co/t/how-do-i-transfer-mappings-from-one-index-to-another-with-java-api-client/320489 "2022-12-06T22:31:38Z")

</div>

Hello, I'm currently building a Spring Java application and I use the \[Elastic Java Client\] (Elasticsearch Java API Client \[8.5\] | Elastic) (Version: 8.3.3) to communicate between my application and my elastic cluster. I…

---

## [How to create a data view and an index aat the same time in elastic search using python](https://discuss.elastic.co/t/how-to-create-a-data-view-and-an-index-aat-the-same-time-in-elastic-search-using-python/320620)

<div class="topic-metadata">

**Author:** [@Shashank02](https://discuss.elastic.co/u/Shashank02)\
**Replies:** 3\
**Last updated:** [December 6, 2022, 7:39pm UTC](https://discuss.elastic.co/t/how-to-create-a-data-view-and-an-index-aat-the-same-time-in-elastic-search-using-python/320620 "2022-12-06T19:39:46Z")

</div>

I am trying to push a CSV file directly into Elasticsearch using python and it's working. But, it is only creating an index. I want to create a data view along with it so that I can create a dashboard in Kibana but I'm g…

---

## [How does logstash match?](https://discuss.elastic.co/t/how-does-logstash-match/320610)

<div class="topic-metadata">

**Author:** [@stefanocog](https://discuss.elastic.co/u/stefanocog)\
**Replies:** 4\
**Last updated:** [December 6, 2022, 4:57pm UTC](https://discuss.elastic.co/t/how-does-logstash-match/320610 "2022-12-06T16:57:45Z")

</div>

Hello, I need to match some logs that differ only in one fields (url), I match with grok, each grok rule matches a log, so I have different filters but with different grok rules, but now I realize that some logs after d…

---

## [DLQ Processing](https://discuss.elastic.co/t/dlq-processing/320603)

<div class="topic-metadata">

**Author:** [@dawiro](https://discuss.elastic.co/u/dawiro)\
**Replies:** 1\
**Last updated:** [December 6, 2022, 4:34pm UTC](https://discuss.elastic.co/t/dlq-processing/320603 "2022-12-06T16:34:54Z")

</div>

Hi, I'm trying to process events written to a dlq due to mapping conflicts. I'm not trying to preprocess any of those messages (yet). Instead, am just reading them in and writing them to a new index name. However, I get…

---

## [How to setup watcher condition ctx.payload.hits.total in percentage?](https://discuss.elastic.co/t/how-to-setup-watcher-condition-ctx-payload-hits-total-in-percentage/320593)

<div class="topic-metadata">

**Author:** [@dharini\_u](https://discuss.elastic.co/u/dharini_u)\
**Replies:** 0\
**Last updated:** [December 6, 2022, 2:22pm UTC](https://discuss.elastic.co/t/how-to-setup-watcher-condition-ctx-payload-hits-total-in-percentage/320593 "2022-12-06T14:22:51Z")

</div>

Hi Folks, Please help me in setting up a watcher with the below condition: percentage of ctx.payload.hits.total of variable1 in percentage of variable2 \> 10% currently the condition is ctx.payload.hits.total \> params.…

---

## [It is possible to limit amount of hits per token?](https://discuss.elastic.co/t/it-is-possible-to-limit-amount-of-hits-per-token/320561)

<div class="topic-metadata">

**Author:** [@va2dim](https://discuss.elastic.co/u/va2dim)\
**Replies:** 2\
**Last updated:** [December 6, 2022, 1:47pm UTC](https://discuss.elastic.co/t/it-is-possible-to-limit-amount-of-hits-per-token/320561 "2022-12-06T13:47:00Z")

</div>

I have indexed refBook of materials: doc/id name 1 polibutilen 5 polibutelenteraftalat 13 elastan, 23 elastodien, 25 elastodin query could contain many materials (using OR operator): elastan, polibutilen. (examp…

---

## [How to grok haproxy Log](https://discuss.elastic.co/t/how-to-grok-haproxy-log/320566)

<div class="topic-metadata">

**Author:** [@Roccof97](https://discuss.elastic.co/u/Roccof97)\
**Replies:** 3\
**Last updated:** [December 6, 2022, 1:59pm UTC](https://discuss.elastic.co/t/how-to-grok-haproxy-log/320566 "2022-12-06T13:59:13Z")

</div>

Hi, I'm parsing this log, but I get stuck in curly braces, I don't know what exception to add to export dns and ip. This is my log: Dec 6 10:31:43 eu01-test-test haproxy\[1311\]: eu01-test.test.lan x.x.x.x:xxxx \[06/Dec…

---

## [How to download only desired entry rows from Eland (Elasticsearch python+pandas client)?](https://discuss.elastic.co/t/how-to-download-only-desired-entry-rows-from-eland-elasticsearch-python-pandas-client/320591)

<div class="topic-metadata">

**Author:** [@Ivo\_Tavares](https://discuss.elastic.co/u/Ivo_Tavares)\
**Replies:** 0\
**Last updated:** [December 6, 2022, 1:58pm UTC](https://discuss.elastic.co/t/how-to-download-only-desired-entry-rows-from-eland-elasticsearch-python-pandas-client/320591 "2022-12-06T13:58:10Z")

</div>

Currently, if I want to create a dataframe with specific entries from an index, using Eland, I must first download a dataframe with all the entries, and then filter them out, locally... this is hardly desirable in terms …

---

## [Ingestion pipeline dynamically creates empty object upon nested JSON](https://discuss.elastic.co/t/ingestion-pipeline-dynamically-creates-empty-object-upon-nested-json/320480)

<div class="topic-metadata">

**Author:** [@Douglas\_Korgut](https://discuss.elastic.co/u/Douglas_Korgut)\
**Replies:** 2\
**Last updated:** [December 6, 2022, 1:37pm UTC](https://discuss.elastic.co/t/ingestion-pipeline-dynamically-creates-empty-object-upon-nested-json/320480 "2022-12-06T13:37:08Z")

</div>

Hello guys! I've been trying to ingest documents through the ingestion pipeline provided by elastic. The idea is quite simple, transform the original JSON into one that has well formatted field names that at some point …

---

## [Unable to retrieve version information from Elasticsearch nodes](https://discuss.elastic.co/t/unable-to-retrieve-version-information-from-elasticsearch-nodes/320128)

<div class="topic-metadata">

**Author:** [@ali\_haider](https://discuss.elastic.co/u/ali_haider)\
**Replies:** 4\
**Last updated:** [December 6, 2022, 1:21pm UTC](https://discuss.elastic.co/t/unable-to-retrieve-version-information-from-elasticsearch-nodes/320128 "2022-12-06T13:21:42Z")

</div>

I am using Elasticsearch and Kibana 7.17 free and basic version. I am trying to setting up the minimal security. I did all of the following steps mentioned in the following document : I saw multiple solutions in whic…

---

## [Cannot parse empty date](https://discuss.elastic.co/t/cannot-parse-empty-date/320575)

<div class="topic-metadata">

**Author:** [@stefanocog](https://discuss.elastic.co/u/stefanocog)\
**Replies:** 4\
**Last updated:** [December 6, 2022, 1:16pm UTC](https://discuss.elastic.co/t/cannot-parse-empty-date/320575 "2022-12-06T13:16:58Z")

</div>

Hi, I have a log that has a json field inside that can have empty fields, specifically I have a date field, the log can be like this "2022-11-28 09:24:46:705"|"+0100"|"transId: xxxxxx"|"resId: xxxxxx"|"1.1.1.1"|"https:…

---

## [Фильтр по nested объектам](https://discuss.elastic.co/t/nested/320579)

<div class="topic-metadata">

**Author:** [@Alexkab](https://discuss.elastic.co/u/Alexkab)\
**Replies:** 0\
**Last updated:** [December 6, 2022, 12:46pm UTC](https://discuss.elastic.co/t/nested/320579 "2022-12-06T12:46:23Z")

</div>

Добрый день! Подскажите, пожалуйста, как вывести только нужные nested объекты PUT test { "mappings": { "properties": { "title": { "type": "text" }, "author": { "type": "object", …

---

## [ElasticSearch phrase search not working for wildcard search](https://discuss.elastic.co/t/elasticsearch-phrase-search-not-working-for-wildcard-search/320543)

<div class="topic-metadata">

**Author:** [@golofetuk](https://discuss.elastic.co/u/golofetuk)\
**Replies:** 6\
**Last updated:** [December 6, 2022, 12:18pm UTC](https://discuss.elastic.co/t/elasticsearch-phrase-search-not-working-for-wildcard-search/320543 "2022-12-06T12:18:55Z")

</div>

I have a word index and I can't search phrases on elasticsearch. there is no result. I check tons of solutions but I can't implement them to my query. My mapping looks like this; PUT /words/\_mapping { "properties": {…

---

## [Indicator match](https://discuss.elastic.co/t/indicator-match/320569)

<div class="topic-metadata">

**Author:** [@ramiwashere](https://discuss.elastic.co/u/ramiwashere)\
**Replies:** 0\
**Last updated:** [December 6, 2022, 11:17am UTC](https://discuss.elastic.co/t/indicator-match/320569 "2022-12-06T11:17:22Z")

</div>

Hello, I'm sorry if this information had already been asked but I didn't find my answer on old topic. I'm stuck on a indicator match rule and idk if I misunderstand this type of rule: I have 2 index, lets call them in…

---

## [When adding a filter in kibana all string fields have a entry and .keyword entry](https://discuss.elastic.co/t/when-adding-a-filter-in-kibana-all-string-fields-have-a-entry-and-keyword-entry/320552)

<div class="topic-metadata">

**Author:** [@Rajesh\_R](https://discuss.elastic.co/u/Rajesh_R)\
**Replies:** 2\
**Last updated:** [December 6, 2022, 11:13am UTC](https://discuss.elastic.co/t/when-adding-a-filter-in-kibana-all-string-fields-have-a-entry-and-keyword-entry/320552 "2022-12-06T11:13:35Z")

</div>

When adding a filter in kibana all string fields have an entry and .keyword entry. please assist how to remove the keyword

---

## [Cannot change timestamp field in an existing data view in kibana](https://discuss.elastic.co/t/cannot-change-timestamp-field-in-an-existing-data-view-in-kibana/320532)

<div class="topic-metadata">

**Author:** [@mikhatanu](https://discuss.elastic.co/u/mikhatanu)\
**Replies:** 4\
**Last updated:** [December 6, 2022, 8:45am UTC](https://discuss.elastic.co/t/cannot-change-timestamp-field-in-an-existing-data-view-in-kibana/320532 "2022-12-06T08:45:45Z")

</div>

Hello, I have created a dataview that uses @timetamp field which is generated from logstash. I wanted to change (edit) the default timestamp field to another field (timestamp\_seconds) in the dataview, but it is greyed o…

---

## [Dec 6th, 2022: \[EN\] A completion suggester for Santa's little helpers](https://discuss.elastic.co/t/dec-6th-2022-en-a-completion-suggester-for-santas-little-helpers/319231)

<div class="topic-metadata">

**Author:** [@Alexis\_Roberson](https://discuss.elastic.co/u/Alexis_Roberson)\
**Replies:** 0\
**Last updated:** [December 6, 2022, 8:00am UTC](https://discuss.elastic.co/t/dec-6th-2022-en-a-completion-suggester-for-santas-little-helpers/319231 "2022-12-06T08:00:07Z")

</div>

A completion suggester for Santa’s little helpers Introduction What is a completion suggester? Major components of a completion suggester Walkthrough / Demo Drawbacks Conclusion Introduction The elves have spun up …

---

## [Logstash input elasticsearch argument error](https://discuss.elastic.co/t/logstash-input-elasticsearch-argument-error/320538)

<div class="topic-metadata">

**Author:** [@CherryGoose](https://discuss.elastic.co/u/CherryGoose)\
**Replies:** 0\
**Last updated:** [December 6, 2022, 7:59am UTC](https://discuss.elastic.co/t/logstash-input-elasticsearch-argument-error/320538 "2022-12-06T07:59:32Z")

</div>

Hello. Im trying to setup my logstash to take docs from elastic and output them to console and im getting the following error \[ERROR\]\[logstash.agent \] Failed to execute action {:action=\>LogStash::PipelineActio…

---

## [DataNode disk full, despite on flood\_stage configuration](https://discuss.elastic.co/t/datanode-disk-full-despite-on-flood-stage-configuration/320468)

<div class="topic-metadata">

**Author:** [@gidonshn](https://discuss.elastic.co/u/gidonshn)\
**Replies:** 4\
**Last updated:** [December 6, 2022, 7:40am UTC](https://discuss.elastic.co/t/datanode-disk-full-despite-on-flood-stage-configuration/320468 "2022-12-06T07:40:22Z")

</div>

Hi All. I have a cluster (7.16.2) running on k8s, with multiple DataNodes, dedicated ClientNodes, and Dedicated MasterNodes. Some of the DataNodes are "hot" data nodes, and some of them are "warm". I have daily indice…

---

## [Logstash drop filter plugin](https://discuss.elastic.co/t/logstash-drop-filter-plugin/320526)

<div class="topic-metadata">

**Author:** [@bex](https://discuss.elastic.co/u/bex)\
**Replies:** 1\
**Last updated:** [December 6, 2022, 7:19am UTC](https://discuss.elastic.co/t/logstash-drop-filter-plugin/320526 "2022-12-06T07:19:31Z")

</div>

As we know, we can drop like that: if \[log\]\[file\]\[path\] == "/var/log/messages" { drop {} } But I have case when I am getting logs in format "/var/log/messages-20221212" or "/var/log/messages-date" But logstash drop …

---

## [Unable to restart a node - index.mapper.dynamic was removed after version 6.0.0](https://discuss.elastic.co/t/unable-to-restart-a-node-index-mapper-dynamic-was-removed-after-version-6-0-0/320506)

<div class="topic-metadata">

**Author:** [@newkidtopc](https://discuss.elastic.co/u/newkidtopc)\
**Replies:** 2\
**Last updated:** [December 6, 2022, 6:32am UTC](https://discuss.elastic.co/t/unable-to-restart-a-node-index-mapper-dynamic-was-removed-after-version-6-0-0/320506 "2022-12-06T06:32:08Z")

</div>

We have been running our ES cluster (ES Version 7.16.3) for a few months now. This cluster was built using the data from earlier ES version (ES 6.8) and the cluster has been running smoothly after the upgrade. We run on…

[Previous page](https://discuss.elastic.co/tag/none.md?no_tags=true&page=482)

[Next page](https://discuss.elastic.co/tag/none.md?no_tags=true&page=484)
