# \#none

**URL:** https://discuss.elastic.co/tag/none.md?no_tags=true&page=484

[Latest](https://discuss.elastic.co/latest.md) · [Categories](https://discuss.elastic.co/categories.md) · [Tags](https://discuss.elastic.co/tags.md)

**Page:** 485

---

## [How to "explore" labels from custom RUM transactions?](https://discuss.elastic.co/t/how-to-explore-labels-from-custom-rum-transactions/320520)

<div class="topic-metadata">

**Author:** [@Mike\_Cann](https://discuss.elastic.co/u/Mike_Cann)\
**Replies:** 2\
**Last updated:** [December 6, 2022, 5:08am UTC](https://discuss.elastic.co/t/how-to-explore-labels-from-custom-rum-transactions/320520 "2022-12-06T05:08:01Z")

</div>

Hi, I have added a custom transaction to track average FPS for our game. I added three custom labels. I am not sure how I can search and graph the results of this however. Any help or link to appropriate docs appre…

---

## [Can i update child document while update parent document from script](https://discuss.elastic.co/t/can-i-update-child-document-while-update-parent-document-from-script/320515)

<div class="topic-metadata">

**Author:** [@robocon20x](https://discuss.elastic.co/u/robocon20x)\
**Replies:** 0\
**Last updated:** [December 6, 2022, 3:20am UTC](https://discuss.elastic.co/t/can-i-update-child-document-while-update-parent-document-from-script/320515 "2022-12-06T03:20:07Z")

</div>

can i update special document while update a document? For example: i have 2 docs, doc parent A and doc child B. whenever i update doc child B, i want filed a1 of doc A have value v1. is it possible? cause as i know 1 …

---

## [Kibana error while querying in Discover](https://discuss.elastic.co/t/kibana-error-while-querying-in-discover/318764)

<div class="topic-metadata">

**Author:** [@Michael\_Sanchez](https://discuss.elastic.co/u/Michael_Sanchez)\
**Replies:** 34\
**Last updated:** [December 5, 2022, 10:00pm UTC](https://discuss.elastic.co/t/kibana-error-while-querying-in-discover/318764 "2022-12-05T22:00:28Z")

</div>

Hello team, I'm seeing the following error while making a search in "Discover": search\_phase\_execution\_exception Error: Bad Request at Fetch.\_callee3$ (kibana/36063/bundles/core/core.entry.js:6:59535) at l (k…

---

## [Xpath fails to extract](https://discuss.elastic.co/t/xpath-fails-to-extract/320479)

<div class="topic-metadata">

**Author:** [@stefanocog](https://discuss.elastic.co/u/stefanocog)\
**Replies:** 4\
**Last updated:** [December 5, 2022, 8:36pm UTC](https://discuss.elastic.co/t/xpath-fails-to-extract/320479 "2022-12-05T20:36:49Z")

</div>

Hi, i need extract one value from a parsed XML, my logstash configuration is xml { source =\> "contentRequest" target =\> "contentRequest\_field" store\_xml =\> false xpath =\> \[ "/datianagrafici/datipersonali…

---

## [Data not appearing in dashboards](https://discuss.elastic.co/t/data-not-appearing-in-dashboards/317582)

<div class="topic-metadata">

**Author:** [@gunlomboy](https://discuss.elastic.co/u/gunlomboy)\
**Replies:** 2\
**Last updated:** [November 8, 2022, 2:08am UTC](https://discuss.elastic.co/t/data-not-appearing-in-dashboards/317582 "2022-11-08T02:08:32Z")

</div>

Hi, I have two filebeat indices/datastreams: filebeat-8.4.0 filebeat-8.4.0-custom These are both targeted by a Data View : filebeat-\* Using this data view in Discover, I can see all the events from both indices, how…

---

## [Kubernetes integration logs missing](https://discuss.elastic.co/t/kubernetes-integration-logs-missing/320495)

<div class="topic-metadata">

**Author:** [@Vojtech\_Vavra](https://discuss.elastic.co/u/Vojtech_Vavra)\
**Replies:** 0\
**Last updated:** [December 5, 2022, 6:56pm UTC](https://discuss.elastic.co/t/kubernetes-integration-logs-missing/320495 "2022-12-05T18:56:47Z")

</div>

Hi I have installed ECK (quickstart) with Kubernetes integration to watch logs from cluster containers. However, I can see only logs from namespace where ECK is installed. I have changed path to aks k8s logs from /v…

---

## [ECE Platform upgrade from 2.13.2 to 3.3.0 failed and stuck during rollback](https://discuss.elastic.co/t/ece-platform-upgrade-from-2-13-2-to-3-3-0-failed-and-stuck-during-rollback/320491)

<div class="topic-metadata">

**Author:** [@mahesthogarpally](https://discuss.elastic.co/u/mahesthogarpally)\
**Replies:** 2\
**Last updated:** [December 5, 2022, 6:34pm UTC](https://discuss.elastic.co/t/ece-platform-upgrade-from-2-13-2-to-3-3-0-failed-and-stuck-during-rollback/320491 "2022-12-05T18:34:07Z")

</div>

I tried to upgrade the ece platform version from 2.13.2 to 3.3 using "elastic-cloud-enterprise.sh" script,The upgrade failed and it got stuck during rollback.I tried to restart frc-runner-runner and now i see all the all…

---

## [How can i exclude 0 from an uniqe count?](https://discuss.elastic.co/t/how-can-i-exclude-0-from-an-uniqe-count/320471)

<div class="topic-metadata">

**Author:** [@Jakomo04](https://discuss.elastic.co/u/Jakomo04)\
**Replies:** 1\
**Last updated:** [December 5, 2022, 4:46pm UTC](https://discuss.elastic.co/t/how-can-i-exclude-0-from-an-uniqe-count/320471 "2022-12-05T16:46:48Z")

</div>

Hi, I have to do a Visualization that only shows the data over 10 of an unique count i tried "clamp(unique\_count('info.job-id.keyword') - 10, 0, 1) \* unique\_count('info.job-id.keyword')" . Now i have all the data under …

---

## [Logstash multiline and clone](https://discuss.elastic.co/t/logstash-multiline-and-clone/320478)

<div class="topic-metadata">

**Author:** [@adrianfusco](https://discuss.elastic.co/u/adrianfusco)\
**Replies:** 2\
**Last updated:** [December 5, 2022, 4:28pm UTC](https://discuss.elastic.co/t/logstash-multiline-and-clone/320478 "2022-12-05T16:28:40Z")

</div>

I am sending some information from filebeat using one kind of multiline pattern. At some point, I realized I need to use another multiline pattern based on the log\_source. My idea was clone the beat and if the log\_sour…

---

## [Dashboard panels don't show data though underlying visualizations appear to work](https://discuss.elastic.co/t/dashboard-panels-dont-show-data-though-underlying-visualizations-appear-to-work/318588)

<div class="topic-metadata">

**Author:** [@jenrem](https://discuss.elastic.co/u/jenrem)\
**Replies:** 2\
**Last updated:** [December 5, 2022, 3:44pm UTC](https://discuss.elastic.co/t/dashboard-panels-dont-show-data-though-underlying-visualizations-appear-to-work/318588 "2022-12-05T15:44:41Z")

</div>

Some panels on a dashboard no longer show data though when you go in to edit the visualization, it does show the data. The affected visualizations are based on follower indexes that had stopped receiving data from…

---

## [Rollover of Index and delete delta data as per customer configuration](https://discuss.elastic.co/t/rollover-of-index-and-delete-delta-data-as-per-customer-configuration/320452)

<div class="topic-metadata">

**Author:** [@atpr](https://discuss.elastic.co/u/atpr)\
**Replies:** 3\
**Last updated:** [December 5, 2022, 2:48pm UTC](https://discuss.elastic.co/t/rollover-of-index-and-delete-delta-data-as-per-customer-configuration/320452 "2022-12-05T14:48:32Z")

</div>

Hi Experts, I have customer requirement where each customer can opt XGB of data or Y days of data and n no of records. Customer is saying they only want this much, if more data is coming, please delete oldest among all.…

---

## [Tune for indexing speed](https://discuss.elastic.co/t/tune-for-indexing-speed/318873)

<div class="topic-metadata">

**Author:** [@lduvnjak](https://discuss.elastic.co/u/lduvnjak)\
**Replies:** 10\
**Last updated:** [December 5, 2022, 2:15pm UTC](https://discuss.elastic.co/t/tune-for-indexing-speed/318873 "2022-12-05T14:15:37Z")

</div>

Hey Everyone, We're having some issues optimizing the indexing speed on our cluster. Try as we might, we can't go over 200k/s. Here are the things we tried: Increasing the amount of documents used in a bulk request - …

---

## [64 Gb limit for per NODE](https://discuss.elastic.co/t/64-gb-limit-for-per-node/319950)

<div class="topic-metadata">

**Author:** [@Kamran\_Ahmadzade](https://discuss.elastic.co/u/Kamran_Ahmadzade)\
**Replies:** 11\
**Last updated:** [December 5, 2022, 2:03pm UTC](https://discuss.elastic.co/t/64-gb-limit-for-per-node/319950 "2022-12-05T14:03:54Z")

</div>

Why do we have 64 GB limit for per node in cluster ?

---

## [Logstash netscaler citrix input](https://discuss.elastic.co/t/logstash-netscaler-citrix-input/319571)

<div class="topic-metadata">

**Author:** [@perezdev](https://discuss.elastic.co/u/perezdev)\
**Replies:** 2\
**Last updated:** [December 5, 2022, 1:58pm UTC](https://discuss.elastic.co/t/logstash-netscaler-citrix-input/319571 "2022-12-05T13:58:41Z")

</div>

Hello, I'm trying to collect logs from Netscaler Citrix using ipfix protocol, but I'm not able to decode properly the message. This is my input configuration file: input { udp { port =\> 9913 codec =\> netflow…

---

## [What is External Alerts Detection Rule?](https://discuss.elastic.co/t/what-is-external-alerts-detection-rule/316817)

<div class="topic-metadata">

**Author:** [@lamp123432](https://discuss.elastic.co/u/lamp123432)\
**Replies:** 4\
**Last updated:** [December 5, 2022, 1:53pm UTC](https://discuss.elastic.co/t/what-is-external-alerts-detection-rule/316817 "2022-12-05T13:53:19Z")

</div>

Hello, what exactly is "External Alerts" in the SIEM rules? It doesn't do anything for us.

---

## [Kibana: how to set up alerts on a boolean field](https://discuss.elastic.co/t/kibana-how-to-set-up-alerts-on-a-boolean-field/318694)

<div class="topic-metadata">

**Author:** [@mohsin106](https://discuss.elastic.co/u/mohsin106)\
**Replies:** 1\
**Last updated:** [December 5, 2022, 1:11pm UTC](https://discuss.elastic.co/t/kibana-how-to-set-up-alerts-on-a-boolean-field/318694 "2022-12-05T13:11:23Z")

</div>

Hi, I have a dataset that contains fields pertaining to a specific optical transport device. My dataset: "slot": "LM-1", "source": "1.3.1.8", "timestamp": 1668113939, "serial\_no": "xxxxxxxx", "hardware\_version": "001"…

---

## [How to special date time format to timestamp format](https://discuss.elastic.co/t/how-to-special-date-time-format-to-timestamp-format/320444)

<div class="topic-metadata">

**Author:** [@akif\_bal](https://discuss.elastic.co/u/akif_bal)\
**Replies:** 6\
**Last updated:** [December 5, 2022, 1:09pm UTC](https://discuss.elastic.co/t/how-to-special-date-time-format-to-timestamp-format/320444 "2022-12-05T13:09:56Z")

</div>

I have a log type that I cannot manipulate. How can I convert the Time format in the log to timestamp format? Example log: "0001 021222 095725 00240541029896158 11 00 00 0000000000 000 0" Date and time that comes with …

---

## [Some devices(routers/firewall) logs are not coming in ELK Kibana](https://discuss.elastic.co/t/some-devices-routers-firewall-logs-are-not-coming-in-elk-kibana/319610)

<div class="topic-metadata">

**Author:** [@Sivaramakrishhna\_Amb](https://discuss.elastic.co/u/Sivaramakrishhna_Amb)\
**Replies:** 1\
**Last updated:** [December 5, 2022, 11:38am UTC](https://discuss.elastic.co/t/some-devices-routers-firewall-logs-are-not-coming-in-elk-kibana/319610 "2022-12-05T11:38:59Z")

</div>

Some devices(routers/firewall) logs are not coming in ELK Kibana protocol used is tcp

---

## [Rolling upgrades, master nodes & voting\_config\_exclusions](https://discuss.elastic.co/t/rolling-upgrades-master-nodes-voting-config-exclusions/320463)

<div class="topic-metadata">

**Author:** [@aidofitz](https://discuss.elastic.co/u/aidofitz)\
**Replies:** 2\
**Last updated:** [December 5, 2022, 11:33am UTC](https://discuss.elastic.co/t/rolling-upgrades-master-nodes-voting-config-exclusions/320463 "2022-12-05T11:33:44Z")

</div>

Hi, We are planning to upgrade our v7.8 cluster to v7.17, in a rolling upgrade. The cluster has 22 nodes and all nodes have both Master and Data roles. We're planning to leave the currently elected master node till la…

---

## [Search\_after but with paging](https://discuss.elastic.co/t/search-after-but-with-paging/319886)

<div class="topic-metadata">

**Author:** [@daniel77](https://discuss.elastic.co/u/daniel77)\
**Replies:** 5\
**Last updated:** [December 5, 2022, 10:55am UTC](https://discuss.elastic.co/t/search-after-but-with-paging/319886 "2022-12-05T10:55:04Z")

</div>

We know the from + size parameters in a search query are limited to 10000. In a search which returns 20k hits, and assuming each page is 1k results, it's impossible to retrieve any page beyond #10 (like page 11, from set…

---

## [Integration of ELK in TheHive](https://discuss.elastic.co/t/integration-of-elk-in-thehive/320455)

<div class="topic-metadata">

**Author:** [@Midiou\_00](https://discuss.elastic.co/u/Midiou_00)\
**Replies:** 0\
**Last updated:** [December 5, 2022, 9:50am UTC](https://discuss.elastic.co/t/integration-of-elk-in-thehive/320455 "2022-12-05T09:50:29Z")

</div>

Hi everyone, I want to integrate ELK in Thehive SOAR. This is an open source SOAR. May somebody help me for the processus please ?

---

## [Do EQL deprecations also imply deprecation of the Java API?](https://discuss.elastic.co/t/do-eql-deprecations-also-imply-deprecation-of-the-java-api/320462)

<div class="topic-metadata">

**Author:** [@martinwun](https://discuss.elastic.co/u/martinwun)\
**Replies:** 0\
**Last updated:** [December 5, 2022, 10:48am UTC](https://discuss.elastic.co/t/do-eql-deprecations-also-imply-deprecation-of-the-java-api/320462 "2022-12-05T10:48:50Z")

</div>

Hello, in the release notes for 7.13 it states the following in the section on "EQL deprecations": "The wildcard function is deprecated." What is not clear to me is whether or not this is also affecting the Java API…

---

## [Kibana import CSV only return partial data](https://discuss.elastic.co/t/kibana-import-csv-only-return-partial-data/319255)

<div class="topic-metadata">

**Author:** [@Virendra\_Negi](https://discuss.elastic.co/u/Virendra_Negi)\
**Replies:** 1\
**Last updated:** [December 5, 2022, 10:28am UTC](https://discuss.elastic.co/t/kibana-import-csv-only-return-partial-data/319255 "2022-12-05T10:28:57Z")

</div>

I see there is already a reference ticket around this Reporting - CSV Export: contains partial data nothing conclusive came out from it, Hence creating a new one. the OP in the previous post is correct Kibana does not r…

---

## [How to alert based on filter query count? Index Threshold Rule Type?](https://discuss.elastic.co/t/how-to-alert-based-on-filter-query-count-index-threshold-rule-type/319119)

<div class="topic-metadata">

**Author:** [@learningelastic](https://discuss.elastic.co/u/learningelastic)\
**Replies:** 1\
**Last updated:** [December 5, 2022, 10:12am UTC](https://discuss.elastic.co/t/how-to-alert-based-on-filter-query-count-index-threshold-rule-type/319119 "2022-12-05T10:12:03Z")

</div>

I want to set up an alert in Kibana Observability where if the number of records returned for event.dataset: login and event.outcome: failure is greater than 10 for the past minute, then set the alert rule to active. I'…

---

## [Dec 5th, 2022: \[EN\] On-season troubleshooting](https://discuss.elastic.co/t/dec-5th-2022-en-on-season-troubleshooting/319857)

<div class="topic-metadata">

**Author:** [@gmarouli](https://discuss.elastic.co/u/gmarouli)\
**Replies:** 0\
**Last updated:** [December 5, 2022, 8:00am UTC](https://discuss.elastic.co/t/dec-5th-2022-en-on-season-troubleshooting/319857 "2022-12-05T08:00:03Z")

</div>

While many people are singing "It's the Most Wonderful Time of the Year...", I catch myself making a small adjustment: "It's the Most Exciting Time of the Year..." I live in the Netherlands and the mid November to m…

---

## [2 nodes logstash](https://discuss.elastic.co/t/2-nodes-logstash/320012)

<div class="topic-metadata">

**Author:** [@maxxl](https://discuss.elastic.co/u/maxxl)\
**Replies:** 9\
**Last updated:** [December 5, 2022, 6:26am UTC](https://discuss.elastic.co/t/2-nodes-logstash/320012 "2022-12-05T06:26:35Z")

</div>

1 logstash works fine 2 logstash, wrong view in kibana

---

## [Need to bypass authentication in kibana as dashboards are embedd using iframes in custom website](https://discuss.elastic.co/t/need-to-bypass-authentication-in-kibana-as-dashboards-are-embedd-using-iframes-in-custom-website/316539)

<div class="topic-metadata">

**Author:** [@PRASHANT\_MEHTA](https://discuss.elastic.co/u/PRASHANT_MEHTA)\
**Replies:** 3\
**Last updated:** [November 7, 2022, 6:19am UTC](https://discuss.elastic.co/t/need-to-bypass-authentication-in-kibana-as-dashboards-are-embedd-using-iframes-in-custom-website/316539 "2022-11-07T06:19:06Z")

</div>

Hello All, I want to know possible ways to bypass basic authentication that is enabled in kibana. Issue: I have custom website that has dashboards integrated using iframes.Now Issue is whenever the user logins to webs…

---

## [GC on elastic search data nodes and node automatically reconnect from the cluster](https://discuss.elastic.co/t/gc-on-elastic-search-data-nodes-and-node-automatically-reconnect-from-the-cluster/319426)

<div class="topic-metadata">

**Author:** [@Siva\_Karan](https://discuss.elastic.co/u/Siva_Karan)\
**Replies:** 4\
**Last updated:** [December 5, 2022, 4:23am UTC](https://discuss.elastic.co/t/gc-on-elastic-search-data-nodes-and-node-automatically-reconnect-from-the-cluster/319426 "2022-12-05T04:23:47Z")

</div>

Hi Team, we are getting the below alerts in elasticsearch data nodes. \[2022-11-20T21:27:36,237\]\[INFO \]\[o.e.m.j.JvmGcMonitorService\] \[esnode1\] \[gc\]\[438806\] overhead, spent \[276ms\] collecting in the last \[1s\] \[2022-11-2…

---

## [Backup Centralized Pipeline Management](https://discuss.elastic.co/t/backup-centralized-pipeline-management/318294)

<div class="topic-metadata">

**Author:** [@heric](https://discuss.elastic.co/u/heric)\
**Replies:** 0\
**Last updated:** [November 7, 2022, 7:09am UTC](https://discuss.elastic.co/t/backup-centralized-pipeline-management/318294 "2022-11-07T07:09:15Z")

</div>

Hi, Is there any API / command that we can use to backup logstash pipelines that are created in centralized pipeline management ? i have quite a lot of pipelines and copy paste from centralized pipeline management will…

---

## [Kibana pod stopped after restoring the index pattern](https://discuss.elastic.co/t/kibana-pod-stopped-after-restoring-the-index-pattern/320229)

<div class="topic-metadata">

**Author:** [@MahithaSarala](https://discuss.elastic.co/u/MahithaSarala)\
**Replies:** 7\
**Last updated:** [December 4, 2022, 9:18pm UTC](https://discuss.elastic.co/t/kibana-pod-stopped-after-restoring-the-index-pattern/320229 "2022-12-04T21:18:33Z")

</div>

Hi Team, We have deleted the data from index in elasticvue , we had backup so we have restored the index pattern now kibana pod not running after restoring . please find the kibana pod logs {"type":"log","@timestamp":…

[Previous page](https://discuss.elastic.co/tag/none.md?no_tags=true&page=483)

[Next page](https://discuss.elastic.co/tag/none.md?no_tags=true&page=485)
