# \#none

**URL:** https://discuss.elastic.co/tag/none.md?no_tags=true&page=493

[Latest](https://discuss.elastic.co/latest.md) · [Categories](https://discuss.elastic.co/categories.md) · [Tags](https://discuss.elastic.co/tags.md)

**Page:** 494

---

## [Server Kibana I want to stopped](https://discuss.elastic.co/t/server-kibana-i-want-to-stopped/319420)

<div class="topic-metadata">

**Author:** [@m3bgwad](https://discuss.elastic.co/u/m3bgwad)\
**Replies:** 2\
**Last updated:** [November 22, 2022, 10:29am UTC](https://discuss.elastic.co/t/server-kibana-i-want-to-stopped/319420 "2022-11-22T10:29:43Z")

</div>

Hello, I have two servers the first in it Kibana, GrafanaI and the second server in it Elasticsearch and Logstash pipeline is running, I want to reboot the server that in it kibana and Grafana, what is happens to the …

---

## [Query configuration in annotation in TSVB visual](https://discuss.elastic.co/t/query-configuration-in-annotation-in-tsvb-visual/319511)

<div class="topic-metadata">

**Author:** [@Seemant\_Bind](https://discuss.elastic.co/u/Seemant_Bind)\
**Replies:** 1\
**Last updated:** [November 22, 2022, 9:22am UTC](https://discuss.elastic.co/t/query-configuration-in-annotation-in-tsvb-visual/319511 "2022-11-22T09:22:56Z")

</div>

Hi, I wanted to create a visual in TSVB to display Bell icon when total count of category exceeds particular threshold. I have tried category.keyword.count\>10 (referring to this creating a trend graph based on tsvb + a…

---

## [Is it possible to add condition in elasticsearch logstash jdbc input plugin](https://discuss.elastic.co/t/is-it-possible-to-add-condition-in-elasticsearch-logstash-jdbc-input-plugin/319195)

<div class="topic-metadata">

**Author:** [@niveditakathal](https://discuss.elastic.co/u/niveditakathal)\
**Replies:** 7\
**Last updated:** [November 22, 2022, 9:07am UTC](https://discuss.elastic.co/t/is-it-possible-to-add-condition-in-elasticsearch-logstash-jdbc-input-plugin/319195 "2022-11-22T09:07:50Z")

</div>

Hi Experts, Is it possible to add condition in elasticsearch logstash jdbc input plugin for the use case mentioned below - Usecase - Select data from table1 If datetime (refer elapseTime in code mentioned below) fetc…

---

## [Should I need raw data to create a Grok Filter?](https://discuss.elastic.co/t/should-i-need-raw-data-to-create-a-grok-filter/319386)

<div class="topic-metadata">

**Author:** [@aaron.chang](https://discuss.elastic.co/u/aaron.chang)\
**Replies:** 1\
**Last updated:** [November 22, 2022, 8:33am UTC](https://discuss.elastic.co/t/should-i-need-raw-data-to-create-a-grok-filter/319386 "2022-11-22T08:33:08Z")

</div>

Hi , I am a new user to use ELK. I want to analyze Aruba Controller & MM's syslog. But ELK don't have Aruba's template to show clearly. So I need to grok it by myself. From some article ,I know that ELK will not save…

---

## [Search single character](https://discuss.elastic.co/t/search-single-character/319516)

<div class="topic-metadata">

**Author:** [@Zaid\_Raza](https://discuss.elastic.co/u/Zaid_Raza)\
**Replies:** 0\
**Last updated:** [November 22, 2022, 7:23am UTC](https://discuss.elastic.co/t/search-single-character/319516 "2022-11-22T07:23:34Z")

</div>

Hi, I am creating a search query in which I am searching course name. For example if I search "Introduction to R" then the output is "Introduction to Scrum". In this query "R" is not considered as a single word while se…

---

## [Logstash server label shipped with logs](https://discuss.elastic.co/t/logstash-server-label-shipped-with-logs/319478)

<div class="topic-metadata">

**Author:** [@lubimamp](https://discuss.elastic.co/u/lubimamp)\
**Replies:** 2\
**Last updated:** [November 22, 2022, 2:46am UTC](https://discuss.elastic.co/t/logstash-server-label-shipped-with-logs/319478 "2022-11-22T02:46:37Z")

</div>

Hi Everyone, i have 2+ logstash servers in cluster and i would like to have some tag/flag/whatever which to tell me from which logstash server exactly the message was shipped. I have cases in which one of the logstash s…

---

## [Data nodes unable to see the data in path.data](https://discuss.elastic.co/t/data-nodes-unable-to-see-the-data-in-path-data/319385)

<div class="topic-metadata">

**Author:** [@Joseph\_Khoury](https://discuss.elastic.co/u/Joseph_Khoury)\
**Replies:** 9\
**Last updated:** [November 22, 2022, 1:40am UTC](https://discuss.elastic.co/t/data-nodes-unable-to-see-the-data-in-path-data/319385 "2022-11-22T01:40:38Z")

</div>

Hello all, Initially my Elastic cluster was down after a trial license expired. I was able to successfully delete the license and revert back to the basic one. After that, all the nodes are up with a master. Nonethele…

---

## [Dynamic template vs Index template with explicit mapping in terms of performance](https://discuss.elastic.co/t/dynamic-template-vs-index-template-with-explicit-mapping-in-terms-of-performance/319399)

<div class="topic-metadata">

**Author:** [@2019240081](https://discuss.elastic.co/u/2019240081)\
**Replies:** 4\
**Last updated:** [November 22, 2022, 12:42am UTC](https://discuss.elastic.co/t/dynamic-template-vs-index-template-with-explicit-mapping-in-terms-of-performance/319399 "2022-11-22T00:42:01Z")

</div>

Considering both search response speed and indexing rate (in my case the latter is more important ), which is more efficient? Dynamic template or Index template with explicit mapping ? It depends on my environment?

---

## [Does the aggregation-based area graph visualize correctly in Kibana v.7.17.0?](https://discuss.elastic.co/t/does-the-aggregation-based-area-graph-visualize-correctly-in-kibana-v-7-17-0/319394)

<div class="topic-metadata">

**Author:** [@m-amano](https://discuss.elastic.co/u/m-amano)\
**Replies:** 2\
**Last updated:** [November 22, 2022, 12:09am UTC](https://discuss.elastic.co/t/does-the-aggregation-based-area-graph-visualize-correctly-in-kibana-v-7-17-0/319394 "2022-11-22T00:09:10Z")

</div>

I'm comparing the visualization of the aggregation-based area graph between Kibana v.7.6.1 and v.7.17.0. Each graph's view looks like below here. ・Kibana v.7.6.1 ・Kibana v.7.17.0 The graph of the later version(v…

---

## [Elastic 8.0 refuses connections using hostname instead of localhost](https://discuss.elastic.co/t/elastic-8-0-refuses-connections-using-hostname-instead-of-localhost/319416)

<div class="topic-metadata">

**Author:** [@Rudolf\_Reddy\_Macejka](https://discuss.elastic.co/u/Rudolf_Reddy_Macejka)\
**Replies:** 1\
**Last updated:** [November 21, 2022, 10:51pm UTC](https://discuss.elastic.co/t/elastic-8-0-refuses-connections-using-hostname-instead-of-localhost/319416 "2022-11-21T22:51:59Z")

</div>

Hello team, I would like to ask you for your expertized advice. After an one of Elastic restart WITHOUT TOUCHING CONFIG :slight\_smile: it started refuse connections using hostname:9200. I have tried variations found …

---

## [Deleting document by query](https://discuss.elastic.co/t/deleting-document-by-query/318570)

<div class="topic-metadata">

**Author:** [@sssamant](https://discuss.elastic.co/u/sssamant)\
**Replies:** 4\
**Last updated:** [November 21, 2022, 12:09am UTC](https://discuss.elastic.co/t/deleting-document-by-query/318570 "2022-11-21T00:09:00Z")

</div>

I am trying to use delete\_by\_query to delete some documents for a particular index. But it fails with illegal version value and I read that delete\_by\_query cannot be used to delete documents with index version zero. Is t…

---

## [Logstash s3 input .gz/folder/file patter possible?](https://discuss.elastic.co/t/logstash-s3-input-gz-folder-file-patter-possible/319493)

<div class="topic-metadata">

**Author:** [@acavalier](https://discuss.elastic.co/u/acavalier)\
**Replies:** 3\
**Last updated:** [November 21, 2022, 9:14pm UTC](https://discuss.elastic.co/t/logstash-s3-input-gz-folder-file-patter-possible/319493 "2022-11-21T21:14:29Z")

</div>

I want the s3 input to read the .gz/folder/file is this possible or will i need to use somthing else i.e. lambda to extract the files first. Currently the s3 input is reading the folder as the file. Any help is appreciat…

---

## [Elasticsearch refreshing indices, but documents still don't show up in search](https://discuss.elastic.co/t/elasticsearch-refreshing-indices-but-documents-still-dont-show-up-in-search/319325)

<div class="topic-metadata">

**Author:** [@Ivo\_Tavares](https://discuss.elastic.co/u/Ivo_Tavares)\
**Replies:** 2\
**Last updated:** [November 21, 2022, 8:51pm UTC](https://discuss.elastic.co/t/elasticsearch-refreshing-indices-but-documents-still-dont-show-up-in-search/319325 "2022-11-21T20:51:45Z")

</div>

I'm creating some documents on an index, using bulk. I can access them using get or mget. When I did a search, those documents didn't show up. So, I decided to refresh the indices. However, in some cases, it still happen…

---

## [Problem bringing string part in ElasticSearch](https://discuss.elastic.co/t/problem-bringing-string-part-in-elasticsearch/319492)

<div class="topic-metadata">

**Author:** [@Diego\_Souza](https://discuss.elastic.co/u/Diego_Souza)\
**Replies:** 0\
**Last updated:** [November 21, 2022, 8:04pm UTC](https://discuss.elastic.co/t/problem-bringing-string-part-in-elasticsearch/319492 "2022-11-21T20:04:55Z")

</div>

I'm having a problem getting string part in Elasticsearch. Below is the configuration of index. PUT exemplo { "settings": { "analysis": { "analyzer": { "portuguese\_br": { "type": "portugu…

---

## [Dashboard ID update or complete redo](https://discuss.elastic.co/t/dashboard-id-update-or-complete-redo/318982)

<div class="topic-metadata">

**Author:** [@cronwel](https://discuss.elastic.co/u/cronwel)\
**Replies:** 4\
**Last updated:** [November 21, 2022, 7:50pm UTC](https://discuss.elastic.co/t/dashboard-id-update-or-complete-redo/318982 "2022-11-21T19:50:02Z")

</div>

I'm developing a dashboard with saved objects(visualizations) that I had to reingest. I've been remaking the visualization because I receive error messages related to the id. Is there a way to update visualizations/dash…

---

## [Logstash input google pubsub - clarification](https://discuss.elastic.co/t/logstash-input-google-pubsub-clarification/319489)

<div class="topic-metadata">

**Author:** [@metalshanked](https://discuss.elastic.co/u/metalshanked)\
**Replies:** 0\
**Last updated:** [November 21, 2022, 6:48pm UTC](https://discuss.elastic.co/t/logstash-input-google-pubsub-clarification/319489 "2022-11-21T18:48:28Z")

</div>

Hi, I wanted clarification on the below statement in the docs for the logstash Google pubsub input plugin All messages received from Pub/Sub will be converted to a logstash event and added to the processing pipeline qu…

---

## [Kibana TSVB how to visualize unique records count](https://discuss.elastic.co/t/kibana-tsvb-how-to-visualize-unique-records-count/319474)

<div class="topic-metadata">

**Author:** [@azulgrana](https://discuss.elastic.co/u/azulgrana)\
**Replies:** 4\
**Last updated:** [November 21, 2022, 5:28pm UTC](https://discuss.elastic.co/t/kibana-tsvb-how-to-visualize-unique-records-count/319474 "2022-11-21T17:28:48Z")

</div>

Hi there! I'm exploring TSVB and I couldn't find a way to report unique record count w/ the "counter" viz. Any guidance on that? TIA Azulgrana

---

## [Elasticsearch does not start CentOS7](https://discuss.elastic.co/t/elasticsearch-does-not-start-centos7/318373)

<div class="topic-metadata">

**Author:** [@vassiliy.vins](https://discuss.elastic.co/u/vassiliy.vins)\
**Replies:** 36\
**Last updated:** [November 21, 2022, 4:54pm UTC](https://discuss.elastic.co/t/elasticsearch-does-not-start-centos7/318373 "2022-11-21T16:54:38Z")

</div>

Hi! Installed Elasticsearch as mentioned in Elastic Docs Generated certificates and keys - followed this link - How to install Elasticsearch and Kibana 8.0 on Centos 7 puppet here in the log - just name of the serve…

---

## [Logstash dissect change datatype to timestamp](https://discuss.elastic.co/t/logstash-dissect-change-datatype-to-timestamp/319470)

<div class="topic-metadata">

**Author:** [@edim2525](https://discuss.elastic.co/u/edim2525)\
**Replies:** 1\
**Last updated:** [November 21, 2022, 3:04pm UTC](https://discuss.elastic.co/t/logstash-dissect-change-datatype-to-timestamp/319470 "2022-11-21T15:04:40Z")

</div>

Hi , Is there a way to change the mapping field to timestamp ? This is my input "Time :2022-11-21 12:01:30.85" I'm using "dissect \> mapping" to map this field, but the output data type is "text" and I want it as a tim…

---

## [Parsing errors in Winlogbeat Powershell module](https://discuss.elastic.co/t/parsing-errors-in-winlogbeat-powershell-module/319468)

<div class="topic-metadata">

**Author:** [@amitypete](https://discuss.elastic.co/u/amitypete)\
**Replies:** 0\
**Last updated:** [November 21, 2022, 2:49pm UTC](https://discuss.elastic.co/t/parsing-errors-in-winlogbeat-powershell-module/319468 "2022-11-21T14:49:26Z")

</div>

I am trying to determine why I am getting so many Powershell parsing errors for event.code 800 events when ingesting with winlogbeat v 7.17.5. I'm seeing more than 50% of these ingested events being tagged with "\_js\_exc…

---

## [Aggregate on multiple data fields from time series data](https://discuss.elastic.co/t/aggregate-on-multiple-data-fields-from-time-series-data/319466)

<div class="topic-metadata">

**Author:** [@rvadiga](https://discuss.elastic.co/u/rvadiga)\
**Replies:** 0\
**Last updated:** [November 21, 2022, 2:40pm UTC](https://discuss.elastic.co/t/aggregate-on-multiple-data-fields-from-time-series-data/319466 "2022-11-21T14:40:10Z")

</div>

Dear Team, I am a newbie to ELK world so far. Please bear with my question. I have a time-series data which has many numeric data fields, needs a way to define an aggregation of those fields across time-series period. …

---

## [Rarest term filter](https://discuss.elastic.co/t/rarest-term-filter/319455)

<div class="topic-metadata">

**Author:** [@Karel\_Haerens](https://discuss.elastic.co/u/Karel_Haerens)\
**Replies:** 0\
**Last updated:** [November 21, 2022, 1:20pm UTC](https://discuss.elastic.co/t/rarest-term-filter/319455 "2022-11-21T13:20:22Z")

</div>

Hi all, would there be a way to filter matches to a query in such a way that only matches are accepted where (at least) the rarest term in the result occurs in the query. worded differently: there cannot be any unmatch…

---

## [Fail to checkin to fleet server](https://discuss.elastic.co/t/fail-to-checkin-to-fleet-server/318932)

<div class="topic-metadata">

**Author:** [@subash](https://discuss.elastic.co/u/subash)\
**Replies:** 7\
**Last updated:** [November 21, 2022, 1:42pm UTC](https://discuss.elastic.co/t/fail-to-checkin-to-fleet-server/318932 "2022-11-21T13:42:18Z")

</div>

We are using Elasticsearch 7.17.4 on private cloud. We have 4 elastic agents installed on windows 10 PCs and managed by fleet. It is observed that the Elastic agent status switches between 'Healthy' and 'Offline'. Belo…

---

## [\[Kibana Helm chart\] - UNABLE\_TO\_GET\_ISSUER\_CERT](https://discuss.elastic.co/t/kibana-helm-chart-unable-to-get-issuer-cert/319432)

<div class="topic-metadata">

**Author:** [@Vignesh\_Karthikeyan](https://discuss.elastic.co/u/Vignesh_Karthikeyan)\
**Replies:** 0\
**Last updated:** [November 21, 2022, 11:16am UTC](https://discuss.elastic.co/t/kibana-helm-chart-unable-to-get-issuer-cert/319432 "2022-11-21T11:16:18Z")

</div>

I was trying to deploy kibana helm chart where Elasticsearch was already deployed and running fine. kibana helm chart - helm-charts/kibana at main · elastic/helm-charts · GitHub After helm installation the deployment f…

---

## [Logstash Filter output in different files according to incomming IP address](https://discuss.elastic.co/t/logstash-filter-output-in-different-files-according-to-incomming-ip-address/319305)

<div class="topic-metadata">

**Author:** [@Flo\_h](https://discuss.elastic.co/u/Flo_h)\
**Replies:** 4\
**Last updated:** [November 21, 2022, 1:10pm UTC](https://discuss.elastic.co/t/logstash-filter-output-in-different-files-according-to-incomming-ip-address/319305 "2022-11-21T13:10:17Z")

</div>

Hello, I am using the last version of Logstash 8.5.1. And I am trying to output log in files according to the source IP in the logstash input. I DO know the incomming IPs. I am trying to filter them out in the filter pa…

---

## [Elastic log Events ingest rate optimization](https://discuss.elastic.co/t/elastic-log-events-ingest-rate-optimization/319440)

<div class="topic-metadata">

**Author:** [@abkonred](https://discuss.elastic.co/u/abkonred)\
**Replies:** 0\
**Last updated:** [November 21, 2022, 12:11pm UTC](https://discuss.elastic.co/t/elastic-log-events-ingest-rate-optimization/319440 "2022-11-21T12:11:56Z")

</div>

Hello Team, I have ingested the data around 14.7GB, it took me around 29 minutes (From Filebeat-Logstash-Elasticsearch)to load the complete data. and later on next day the shard has been compressed to 10.5 GB. could yo…

---

## [Setup Logstash with Loki in Kubernetes](https://discuss.elastic.co/t/setup-logstash-with-loki-in-kubernetes/319431)

<div class="topic-metadata">

**Author:** [@jijesh\_vu](https://discuss.elastic.co/u/jijesh_vu)\
**Replies:** 0\
**Last updated:** [November 21, 2022, 11:13am UTC](https://discuss.elastic.co/t/setup-logstash-with-loki-in-kubernetes/319431 "2022-11-21T11:13:44Z")

</div>

Hi any documentations for configuring Logstash with Loki in kubernetes without filebeat

---

## [Dynamic rule risk score](https://discuss.elastic.co/t/dynamic-rule-risk-score/319428)

<div class="topic-metadata">

**Author:** [@Faycal\_B](https://discuss.elastic.co/u/Faycal_B)\
**Replies:** 0\
**Last updated:** [November 21, 2022, 11:09am UTC](https://discuss.elastic.co/t/dynamic-rule-risk-score/319428 "2022-11-21T11:09:15Z")

</div>

The risk score is defined in the rule but cant be influenced by the alert itself, is there a way other than external API workflows ?

---

## [Replace special character in stirng to other special character](https://discuss.elastic.co/t/replace-special-character-in-stirng-to-other-special-character/319382)

<div class="topic-metadata">

**Author:** [@lusynda](https://discuss.elastic.co/u/lusynda)\
**Replies:** 2\
**Last updated:** [November 21, 2022, 9:54am UTC](https://discuss.elastic.co/t/replace-special-character-in-stirng-to-other-special-character/319382 "2022-11-21T09:54:08Z")

</div>

Hi all I have a case that i've been trying to do for a very long time. I have a string that contain #0D#0A character that i want to replace them with the string \\r\\n I've been trying to use gsub but it doesn't seem to…

---

## [Drain Allocator Nodes with Ansible?](https://discuss.elastic.co/t/drain-allocator-nodes-with-ansible/319419)

<div class="topic-metadata">

**Author:** [@Oliver2](https://discuss.elastic.co/u/Oliver2)\
**Replies:** 0\
**Last updated:** [November 21, 2022, 10:15am UTC](https://discuss.elastic.co/t/drain-allocator-nodes-with-ansible/319419 "2022-11-21T10:15:35Z")

</div>

has anyone ever experimented with draining allocator nodes with Ansible and then reboot for the purpose of automated patching?

[Previous page](https://discuss.elastic.co/tag/none.md?no_tags=true&page=492)

[Next page](https://discuss.elastic.co/tag/none.md?no_tags=true&page=494)
