# \#none

**URL:** https://discuss.elastic.co/tag/none.md?no_tags=true&page=491

[Latest](https://discuss.elastic.co/latest.md) · [Categories](https://discuss.elastic.co/categories.md) · [Tags](https://discuss.elastic.co/tags.md)

**Page:** 492

---

## [How to loop through the values of array list to exactly match all the values](https://discuss.elastic.co/t/how-to-loop-through-the-values-of-array-list-to-exactly-match-all-the-values/319787)

<div class="topic-metadata">

**Author:** [@bhavya](https://discuss.elastic.co/u/bhavya)\
**Replies:** 5\
**Last updated:** [November 25, 2022, 6:56am UTC](https://discuss.elastic.co/t/how-to-loop-through-the-values-of-array-list-to-exactly-match-all-the-values/319787 "2022-11-25T06:56:41Z")

</div>

Consider the below documents: Documents Doc 1 { "id": \[ "1a", "1b", "1c" \] } Doc 2 { "id": \[ "1a", "1b" \] } Doc 3 { "id": \[ "1a" \] } Now if …

---

## [Logstash sometimes ignoring datastream configuration in elasticsearch output](https://discuss.elastic.co/t/logstash-sometimes-ignoring-datastream-configuration-in-elasticsearch-output/319743)

<div class="topic-metadata">

**Author:** [@Alexander\_A](https://discuss.elastic.co/u/Alexander_A)\
**Replies:** 1\
**Last updated:** [November 25, 2022, 6:25am UTC](https://discuss.elastic.co/t/logstash-sometimes-ignoring-datastream-configuration-in-elasticsearch-output/319743 "2022-11-25T06:25:26Z")

</div>

Hello, we are running logstash 8.5.0 with multiple pipelines outputting to elasticsearch. Most of the time this works fine, but sometimes logstash will ignore the datastream configuration on startup and tries to write …

---

## [Does "track\_total\_hits" affect "max\_score" calculation?](https://discuss.elastic.co/t/does-track-total-hits-affect-max-score-calculation/319784)

<div class="topic-metadata">

**Author:** [@zhang8473](https://discuss.elastic.co/u/zhang8473)\
**Replies:** 0\
**Last updated:** [November 25, 2022, 3:08am UTC](https://discuss.elastic.co/t/does-track-total-hits-affect-max-score-calculation/319784 "2022-11-25T03:08:45Z")

</div>

If I setup track\_total\_hits:1 in a \_search query, it only tracks one document, then how about the max\_score, will it be accurate or just approx? I tried some. It looks like the "max\_score" is still accurate. Is that cor…

---

## [Elastic-agent with system module does not send any data to elasticsearch](https://discuss.elastic.co/t/elastic-agent-with-system-module-does-not-send-any-data-to-elasticsearch/319689)

<div class="topic-metadata">

**Author:** [@zozo6015](https://discuss.elastic.co/u/zozo6015)\
**Replies:** 24\
**Last updated:** [November 24, 2022, 8:38pm UTC](https://discuss.elastic.co/t/elastic-agent-with-system-module-does-not-send-any-data-to-elasticsearch/319689 "2022-11-24T20:38:20Z")

</div>

Hello, I have deployed a simple elastic-agent with a system system module where I wanted to have the /var/log/syslog ad messages parsed and send metrics (pretty default). But the module does not send any data into the e…

---

## [Logstash retries 404 instead of dropping - output stuck](https://discuss.elastic.co/t/logstash-retries-404-instead-of-dropping-output-stuck/319741)

<div class="topic-metadata">

**Author:** [@Harm](https://discuss.elastic.co/u/Harm)\
**Replies:** 3\
**Last updated:** [November 24, 2022, 7:08pm UTC](https://discuss.elastic.co/t/logstash-retries-404-instead-of-dropping-output-stuck/319741 "2022-11-24T19:08:08Z")

</div>

Hi! Today I had a situation where one of our Elasticsearch outputs in logstash got unavailable. It replied with a 404. Based upon the documentation logstash should give a warning and drop the event. We have no DLQ confi…

---

## [How to use other language stop filter in \_analyze?](https://discuss.elastic.co/t/how-to-use-other-language-stop-filter-in-analyze/319767)

<div class="topic-metadata">

**Author:** [@Michael\_Gattinger](https://discuss.elastic.co/u/Michael_Gattinger)\
**Replies:** 2\
**Last updated:** [November 24, 2022, 5:47pm UTC](https://discuss.elastic.co/t/how-to-use-other-language-stop-filter-in-analyze/319767 "2022-11-24T17:47:37Z")

</div>

Hi, States that it has a \[Stop Token Filter\] (disabled by default) So to test the Standard Analyzer we type: POST \_analyze { "analyzer": "standard", "text": "The 2 QUICK Brown-Foxes jumped over the lazy dog's b…

---

## [How to run two Elasticsearch Service on Window Server 2019?](https://discuss.elastic.co/t/how-to-run-two-elasticsearch-service-on-window-server-2019/319477)

<div class="topic-metadata">

**Author:** [@stramzik](https://discuss.elastic.co/u/stramzik)\
**Replies:** 5\
**Last updated:** [November 24, 2022, 4:21pm UTC](https://discuss.elastic.co/t/how-to-run-two-elasticsearch-service-on-window-server-2019/319477 "2022-11-24T16:21:59Z")

</div>

Hello, I have two instance of Elastic installed and configured to run on a different port on Windows server. I am required to run both the instance simultaneously. However when I try to run the second Elasticsearch ser…

---

## [Permission denied just after installation](https://discuss.elastic.co/t/permission-denied-just-after-installation/319568)

<div class="topic-metadata">

**Author:** [@Broot](https://discuss.elastic.co/u/Broot)\
**Replies:** 5\
**Last updated:** [November 24, 2022, 3:58pm UTC](https://discuss.elastic.co/t/permission-denied-just-after-installation/319568 "2022-11-24T15:58:35Z")

</div>

I'm trying to install and run Elasticsearch and Kibana and I can't do it because every time I try, I always get some Access Permission Denied. I'm on Ubuntu 20.04 thus installing via Debian for example : /usr/share/el…

---

## [Need help in undertsanding Elastic Hot Threads API output](https://discuss.elastic.co/t/need-help-in-undertsanding-elastic-hot-threads-api-output/319265)

<div class="topic-metadata">

**Author:** [@vinit0711](https://discuss.elastic.co/u/vinit0711)\
**Replies:** 16\
**Last updated:** [November 24, 2022, 2:43pm UTC](https://discuss.elastic.co/t/need-help-in-undertsanding-elastic-hot-threads-api-output/319265 "2022-11-24T14:43:30Z")

</div>

I am running a single Node Elastic Cluster on a Server . Filebeat is used as collector for netflow data . Further FIlebeat is giving output to Elastic . Some Important Point Server has 32 core CPU and 500 GB RAM . I se…

---

## [Multi matching wildcard text](https://discuss.elastic.co/t/multi-matching-wildcard-text/319619)

<div class="topic-metadata">

**Author:** [@Chitrank\_Bisht](https://discuss.elastic.co/u/Chitrank_Bisht)\
**Replies:** 2\
**Last updated:** [November 24, 2022, 2:38pm UTC](https://discuss.elastic.co/t/multi-matching-wildcard-text/319619 "2022-11-24T14:38:12Z")

</div>

I have to apply search on two fields, and I have a wildcard text to search. if the text is found in either of the fields that should result in a hit. I am using Olivere golang package. I tried a combination of should and…

---

## [Combining queries while preserving order](https://discuss.elastic.co/t/combining-queries-while-preserving-order/319760)

<div class="topic-metadata">

**Author:** [@Peter\_Strasser](https://discuss.elastic.co/u/Peter_Strasser)\
**Replies:** 0\
**Last updated:** [November 24, 2022, 1:59pm UTC](https://discuss.elastic.co/t/combining-queries-while-preserving-order/319760 "2022-11-24T13:59:09Z")

</div>

Hi Elastic Community, I have the use case, that I want to search blocks of data in order. If we take products as an example a requirement could look like this: Group1: First 5 products are products with the id 120, 12…

---

## [How to add token\_chars: symbol using linq notation?](https://discuss.elastic.co/t/how-to-add-token-chars-symbol-using-linq-notation/319736)

<div class="topic-metadata">

**Author:** [@frankmehlhop.com](https://discuss.elastic.co/u/frankmehlhop.com)\
**Replies:** 1\
**Last updated:** [November 24, 2022, 1:30pm UTC](https://discuss.elastic.co/t/how-to-add-token-chars-symbol-using-linq-notation/319736 "2022-11-24T13:30:08Z")

</div>

I want that I can also search for symbols like "§123". I find that I should add token\_chars: symbol. (example) "token\_chars": \["letter", "digit", "punctuation", "symbol"\] At my C#-code I'm using elasticClient.Indices…

---

## [How to do calculations in Logstash](https://discuss.elastic.co/t/how-to-do-calculations-in-logstash/319759)

<div class="topic-metadata">

**Author:** [@Rakhshunda\_Noorein\_J](https://discuss.elastic.co/u/Rakhshunda_Noorein_J)\
**Replies:** 0\
**Last updated:** [November 24, 2022, 1:23pm UTC](https://discuss.elastic.co/t/how-to-do-calculations-in-logstash/319759 "2022-11-24T13:23:30Z")

</div>

Hello, Please find my configuration file structure input{ http\_poller{ // here I have mentioned API url and authorisation tags =\> \["tag1"\] } http\_poller{ // here I have mentioned API url and authorisation tags =\> \["tag…

---

## [Elasticsearch 7.15 Multi terms aggregation with several fields, sort by key](https://discuss.elastic.co/t/elasticsearch-7-15-multi-terms-aggregation-with-several-fields-sort-by-key/319716)

<div class="topic-metadata">

**Author:** [@anna1](https://discuss.elastic.co/u/anna1)\
**Replies:** 0\
**Last updated:** [November 24, 2022, 8:22am UTC](https://discuss.elastic.co/t/elasticsearch-7-15-multi-terms-aggregation-with-several-fields-sort-by-key/319716 "2022-11-24T08:22:38Z")

</div>

Hello everyone, I have a question regarding the case of multi terms aggregation with several fields and sort by key. How does the sorting work if the key is an array? According to which field / value is the sorting do…

---

## [How to use WrapperQuery in new Java API client 8.4.3 to fire a raw elasticsearch query?](https://discuss.elastic.co/t/how-to-use-wrapperquery-in-new-java-api-client-8-4-3-to-fire-a-raw-elasticsearch-query/319727)

<div class="topic-metadata">

**Author:** [@p4charu](https://discuss.elastic.co/u/p4charu)\
**Replies:** 0\
**Last updated:** [November 24, 2022, 9:36am UTC](https://discuss.elastic.co/t/how-to-use-wrapperquery-in-new-java-api-client-8-4-3-to-fire-a-raw-elasticsearch-query/319727 "2022-11-24T09:36:53Z")

</div>

I'm trying to use WrapperQuery to run a raw query like this String queryStr = "{\\n" + " \\"query\\": {\\n" + " \\"bool\\": {\\n" + " \\"must\\": \[\\n" + " {\\n" + " \\"match\\": {\\n" +…

---

## [Logstash Shutiing Down](https://discuss.elastic.co/t/logstash-shutiing-down/319744)

<div class="topic-metadata">

**Author:** [@ChinigamiHunter](https://discuss.elastic.co/u/ChinigamiHunter)\
**Replies:** 0\
**Last updated:** [November 24, 2022, 11:19am UTC](https://discuss.elastic.co/t/logstash-shutiing-down/319744 "2022-11-24T11:19:38Z")

</div>

i'm new to ELK i have a folder contient json files and i'm using logstash for indexing sometimes i get this error \[2022-11-24T11:08:58,748\]\[WARN \]\[logstash.runner \] SIGINT received. Shutting down. \[2022-11-24…

---

## [TVSB Markdown visualization null values](https://discuss.elastic.co/t/tvsb-markdown-visualization-null-values/319718)

<div class="topic-metadata">

**Author:** [@Alice\_Ionescu](https://discuss.elastic.co/u/Alice_Ionescu)\
**Replies:** 2\
**Last updated:** [November 24, 2022, 11:01am UTC](https://discuss.elastic.co/t/tvsb-markdown-visualization-null-values/319718 "2022-11-24T11:01:18Z")

</div>

Hello, How can I display null values using each\_all in a markdown visualization? I have this until now {{#each \_all}} {{#with office as myoffice Office {{../label}} {{/with}} {{/each}} wher…

---

## [I get error Unable to configure plugins: (ArgumentError) Cannot determine timezone from nil](https://discuss.elastic.co/t/i-get-error-unable-to-configure-plugins-argumenterror-cannot-determine-timezone-from-nil/319531)

<div class="topic-metadata">

**Author:** [@mdinalova](https://discuss.elastic.co/u/mdinalova)\
**Replies:** 5\
**Last updated:** [November 24, 2022, 9:08am UTC](https://discuss.elastic.co/t/i-get-error-unable-to-configure-plugins-argumenterror-cannot-determine-timezone-from-nil/319531 "2022-11-24T09:08:18Z")

</div>

Hello guys! I want to run my logtstash connect to elastic using input jdbc. Then i create conf file to run logstash but i always get this error, i try any changes in conf file but still not working. Anyone can help me t…

---

## [Shipping logs from Logstash to multiple Elasticsearch node in the cluster](https://discuss.elastic.co/t/shipping-logs-from-logstash-to-multiple-elasticsearch-node-in-the-cluster/319708)

<div class="topic-metadata">

**Author:** [@chaunguyen.3979](https://discuss.elastic.co/u/chaunguyen.3979)\
**Replies:** 1\
**Last updated:** [November 24, 2022, 8:43am UTC](https://discuss.elastic.co/t/shipping-logs-from-logstash-to-multiple-elasticsearch-node-in-the-cluster/319708 "2022-11-24T08:43:47Z")

</div>

Hello, I create a cluster with 3 Elasticsearch nodes, and intend to ship logs from the Logstash to all Elasticsearch nodes simultaneously (Eg: I have cluster with node A - master node, node B and C - data node, and ever…

---

## [How to run wildcard queries for long types?](https://discuss.elastic.co/t/how-to-run-wildcard-queries-for-long-types/319706)

<div class="topic-metadata">

**Author:** [@golofetuk](https://discuss.elastic.co/u/golofetuk)\
**Replies:** 0\
**Last updated:** [November 24, 2022, 7:35am UTC](https://discuss.elastic.co/t/how-to-run-wildcard-queries-for-long-types/319706 "2022-11-24T07:35:51Z")

</div>

I just run a simple wildcard query on my elasticsearch server. My query is; GET calls-\*/\_search { "query": { "bool": { "filter": \[ { "bool": { "should": \[ { …

---

## [Logstash stopped processing](https://discuss.elastic.co/t/logstash-stopped-processing/319641)

<div class="topic-metadata">

**Author:** [@shubham.s](https://discuss.elastic.co/u/shubham.s)\
**Replies:** 10\
**Last updated:** [November 24, 2022, 7:27am UTC](https://discuss.elastic.co/t/logstash-stopped-processing/319641 "2022-11-24T07:27:29Z")

</div>

Hi, The elasticsearch and kibana are working as intentional but after installing and configuring logstash in centos , the service stops \[2022-11-23T15:20:38,842\]\[INFO \]\[logstash.runner \] Log4j configuration pa…

---

## [How will create a global variable in logstash?](https://discuss.elastic.co/t/how-will-create-a-global-variable-in-logstash/319705)

<div class="topic-metadata">

**Author:** [@Rakhshunda\_Noorein\_J](https://discuss.elastic.co/u/Rakhshunda_Noorein_J)\
**Replies:** 0\
**Last updated:** [November 24, 2022, 7:08am UTC](https://discuss.elastic.co/t/how-will-create-a-global-variable-in-logstash/319705 "2022-11-24T07:08:57Z")

</div>

Hello, My config is like this - input{ http\_poller{ // here I have mentioned API url and authorisation tags =\> \["tag1"\] } http\_poller{ // here I have mentioned API url and authorisation tags =\> \["tag2"\] } http\_poller{ …

---

## [Ingest only ERROR and warning logs to elastic search](https://discuss.elastic.co/t/ingest-only-error-and-warning-logs-to-elastic-search/319634)

<div class="topic-metadata">

**Author:** [@rahul\_sirugudi](https://discuss.elastic.co/u/rahul_sirugudi)\
**Replies:** 2\
**Last updated:** [November 24, 2022, 4:55am UTC](https://discuss.elastic.co/t/ingest-only-error-and-warning-logs-to-elastic-search/319634 "2022-11-24T04:55:28Z")

</div>

Hi I am trying to ingest only ERROR and warning logs to Elasticsearch. Currently filebeat is shipping logs to log stash, i am using grok pattern. grok { match =\> { "message" =\> "%{IPV4:ip} - \\\[%{TIMESTAMP\_ISO8601:timest…

---

## [Logstash tcp plugin](https://discuss.elastic.co/t/logstash-tcp-plugin/319584)

<div class="topic-metadata">

**Author:** [@SilasMuniz1](https://discuss.elastic.co/u/SilasMuniz1)\
**Replies:** 3\
**Last updated:** [November 24, 2022, 12:08am UTC](https://discuss.elastic.co/t/logstash-tcp-plugin/319584 "2022-11-24T00:08:35Z")

</div>

Hello, I need convert a data field to date field. I am working in restore processed, where I get an old file and insert into elasticsearch by logstash. I received a file with this date format \[06/Jun/2022:13:20:01 -03…

---

## [Possible to hide "panel filters" in Kibana 8.5.x?](https://discuss.elastic.co/t/possible-to-hide-panel-filters-in-kibana-8-5-x/319082)

<div class="topic-metadata">

**Author:** [@rcowart](https://discuss.elastic.co/u/rcowart)\
**Replies:** 3\
**Last updated:** [November 23, 2022, 7:32pm UTC](https://discuss.elastic.co/t/possible-to-hide-panel-filters-in-kibana-8-5-x/319082 "2022-11-23T19:32:12Z")

</div>

This "panel filters" thing has been added in Kibana 8.5. Is there any configuration option to hide this? We find that it... does not to add any real value is distracting takes up valuable screen real estate

---

## [Kibana is not starting](https://discuss.elastic.co/t/kibana-is-not-starting/319649)

<div class="topic-metadata">

**Author:** [@venkata\_pavan\_kalyan](https://discuss.elastic.co/u/venkata_pavan_kalyan)\
**Replies:** 1\
**Last updated:** [November 23, 2022, 7:41pm UTC](https://discuss.elastic.co/t/kibana-is-not-starting/319649 "2022-11-23T19:41:18Z")

</div>

Kibana is not starting from ansible kibana service is starting when ansible role executed after playbook execution completed automatically kibana service stopping immediately cmd: /usr/bin/nohup ./kibana &

---

## [How to iterate through json array and print a formatted string?](https://discuss.elastic.co/t/how-to-iterate-through-json-array-and-print-a-formatted-string/319676)

<div class="topic-metadata">

**Author:** [@learningelastic](https://discuss.elastic.co/u/learningelastic)\
**Replies:** 1\
**Last updated:** [November 23, 2022, 6:27pm UTC](https://discuss.elastic.co/t/how-to-iterate-through-json-array-and-print-a-formatted-string/319676 "2022-11-23T18:27:47Z")

</div>

I'm learning how to use logstash and I got things to mostly work. But I want to learn how to iterate through a json array and print a formatted result set. For example, I created a file called /root/test.log with the fo…

---

## [Logstash x handling duplicate](https://discuss.elastic.co/t/logstash-x-handling-duplicate/319604)

<div class="topic-metadata">

**Author:** [@lchan](https://discuss.elastic.co/u/lchan)\
**Replies:** 2\
**Last updated:** [November 23, 2022, 5:27pm UTC](https://discuss.elastic.co/t/logstash-x-handling-duplicate/319604 "2022-11-23T17:27:26Z")

</div>

Hi all, I am trying to increase number of logstash servers for redundancy and want to know if using fingerprint would achieve it. Does this basically sending the same stream of logs/messages via multiple logstash serve…

---

## [Retrieve records and update a field at the same time](https://discuss.elastic.co/t/retrieve-records-and-update-a-field-at-the-same-time/319465)

<div class="topic-metadata">

**Author:** [@xef](https://discuss.elastic.co/u/xef)\
**Replies:** 8\
**Last updated:** [November 23, 2022, 5:35pm UTC](https://discuss.elastic.co/t/retrieve-records-and-update-a-field-at-the-same-time/319465 "2022-11-23T17:35:38Z")

</div>

Is there anyway when making a query in Elasticsearch, to update a field (such as say a counter++) in each record that is selected by the query. Thanks

---

## [Kibana start but not accessible](https://discuss.elastic.co/t/kibana-start-but-not-accessible/319666)

<div class="topic-metadata">

**Author:** [@mohamedjmal](https://discuss.elastic.co/u/mohamedjmal)\
**Replies:** 2\
**Last updated:** [November 23, 2022, 3:13pm UTC](https://discuss.elastic.co/t/kibana-start-but-not-accessible/319666 "2022-11-23T15:13:10Z")

</div>

elasticsearch and kibana started successfully but the kibana interface does not show anything this is the kibana log , tell me that the host is "elastic1.sifast.local" but it is the ip adress in the kibana.yml ela…

[Previous page](https://discuss.elastic.co/tag/none.md?no_tags=true&page=490)

[Next page](https://discuss.elastic.co/tag/none.md?no_tags=true&page=492)
