# \#none

**URL:** https://discuss.elastic.co/tag/none.md?no_tags=true&page=501

[Latest](https://discuss.elastic.co/latest.md) · [Categories](https://discuss.elastic.co/categories.md) · [Tags](https://discuss.elastic.co/tags.md)

**Page:** 502

---

## [Reindex just one specific index in datastrem](https://discuss.elastic.co/t/reindex-just-one-specific-index-in-datastrem/317079)

<div class="topic-metadata">

**Author:** [@Oleksandr\_Isniuk](https://discuss.elastic.co/u/Oleksandr_Isniuk)\
**Replies:** 8\
**Last updated:** [November 10, 2022, 3:58pm UTC](https://discuss.elastic.co/t/reindex-just-one-specific-index-in-datastrem/317079 "2022-11-10T15:58:35Z")

</div>

We changed field mappings in our template. After rollover new index file works with correct field types. We supposed that we can use smaller time ranges to be sure that all data was read fro the new file. But it is not e…

---

## [Incompatible encodings: IBM437 and UTF-8](https://discuss.elastic.co/t/incompatible-encodings-ibm437-and-utf-8/316918)

<div class="topic-metadata">

**Author:** [@Helmut](https://discuss.elastic.co/u/Helmut)\
**Replies:** 11\
**Last updated:** [November 10, 2022, 3:48pm UTC](https://discuss.elastic.co/t/incompatible-encodings-ibm437-and-utf-8/316918 "2022-11-10T15:48:06Z")

</div>

Hi, I just installed logstash 8.4.3 on Windows Server 2019 and copied over configs from 8.2.3. logstash doesn't start: \[2022-10-18T18:24:26,830\]\[ERROR\]\[logstash.outputs.elasticsearch\]\[main\]\[42989fb99e78bec7495dbe5bfe5a…

---

## [Kibana csv reporting error randomly](https://discuss.elastic.co/t/kibana-csv-reporting-error-randomly/318609)

<div class="topic-metadata">

**Author:** [@sbyunnn](https://discuss.elastic.co/u/sbyunnn)\
**Replies:** 1\
**Last updated:** [November 10, 2022, 1:34pm UTC](https://discuss.elastic.co/t/kibana-csv-reporting-error-randomly/318609 "2022-11-10T13:34:34Z")

</div>

my kibana error randomly when reporting a csv file. error: Unable to generate report Error: Failed to decrypt report job data. Please ensure that xpack.reporting.encryptionKey is set and re-generate this report. Erro…

---

## [HTTP Headers response Logstash http filter](https://discuss.elastic.co/t/http-headers-response-logstash-http-filter/318652)

<div class="topic-metadata">

**Author:** [@S-elk](https://discuss.elastic.co/u/S-elk)\
**Replies:** 0\
**Last updated:** [November 10, 2022, 12:08pm UTC](https://discuss.elastic.co/t/http-headers-response-logstash-http-filter/318652 "2022-11-10T12:08:54Z")

</div>

Hello! I am trying to use logstash's http filter to get some data from apis. One of the most important values is received as a header and yet logstash is not showing me all the headers. Including those that have the sa…

---

## [Using http poller for https server](https://discuss.elastic.co/t/using-http-poller-for-https-server/318648)

<div class="topic-metadata">

**Author:** [@yuswanul](https://discuss.elastic.co/u/yuswanul)\
**Replies:** 0\
**Last updated:** [November 10, 2022, 11:58am UTC](https://discuss.elastic.co/t/using-http-poller-for-https-server/318648 "2022-11-10T11:58:38Z")

</div>

Hi there i want to ask about http poller. so i test this plugin in my VM, and this is the configuration: input{ http\_poller{ urls =\> { test =\> { method =\> get user =\> "elastic" password =\> "myPassword" url =\> "h…

---

## [Strange behavior of "no data" alerts](https://discuss.elastic.co/t/strange-behavior-of-no-data-alerts/318531)

<div class="topic-metadata">

**Author:** [@EDzhelyov](https://discuss.elastic.co/u/EDzhelyov)\
**Replies:** 1\
**Last updated:** [November 10, 2022, 11:47am UTC](https://discuss.elastic.co/t/strange-behavior-of-no-data-alerts/318531 "2022-11-10T11:47:09Z")

</div>

We have an alert that checks if there is a controllermanager.master, it's configured to use the document count function, see the screenshot below. It started to report "no data" and triggered the alert after we creat…

---

## [How to visualize deeper into a donut chart?](https://discuss.elastic.co/t/how-to-visualize-deeper-into-a-donut-chart/318017)

<div class="topic-metadata">

**Author:** [@tinrik](https://discuss.elastic.co/u/tinrik)\
**Replies:** 6\
**Last updated:** [November 10, 2022, 10:23am UTC](https://discuss.elastic.co/t/how-to-visualize-deeper-into-a-donut-chart/318017 "2022-11-10T10:23:57Z")

</div>

Hi! We'd like to implement something similar to the "baobab" tool on Ubuntu. It's a tool that displays information about the size of all the folders and files in the hard drive. It starts with a simple donut chart repr…

---

## [Access request header in plugin configuration](https://discuss.elastic.co/t/access-request-header-in-plugin-configuration/318642)

<div class="topic-metadata">

**Author:** [@dhggw](https://discuss.elastic.co/u/dhggw)\
**Replies:** 0\
**Last updated:** [November 10, 2022, 10:08am UTC](https://discuss.elastic.co/t/access-request-header-in-plugin-configuration/318642 "2022-11-10T10:08:47Z")

</div>

Hi all, we use the Http input plugin to process events via http request in Logstash. The Logstash version is 7.16.2. With the http request we get a special http header, e.g. x-test-header: test-value We now want to r…

---

## [Join two indices query where there is 1-to-many relationship](https://discuss.elastic.co/t/join-two-indices-query-where-there-is-1-to-many-relationship/318306)

<div class="topic-metadata">

**Author:** [@areobode](https://discuss.elastic.co/u/areobode)\
**Replies:** 1\
**Last updated:** [November 10, 2022, 9:58am UTC](https://discuss.elastic.co/t/join-two-indices-query-where-there-is-1-to-many-relationship/318306 "2022-11-10T09:58:57Z")

</div>

I have two indices; authors and articles. Since one author writes several articles, there are 1-to-many relationship between them. The article index has title, vote, and authorId attributes. Here is an example index. …

---

## [Logstash and elasticsearch certification issue](https://discuss.elastic.co/t/logstash-and-elasticsearch-certification-issue/318326)

<div class="topic-metadata">

**Author:** [@manasa3](https://discuss.elastic.co/u/manasa3)\
**Replies:** 8\
**Last updated:** [November 10, 2022, 9:37am UTC](https://discuss.elastic.co/t/logstash-and-elasticsearch-certification-issue/318326 "2022-11-10T09:37:44Z")

</div>

below is the configuration of our conf file input { file { path =\> "C:\\Users\\Windows\\Documents\\elk\\mule.csv" start\_position =\> "beginning" } } filter { csv { columns =\> \["Title", "Author", "ID","Pages"\] …

---

## [How can we compare no of hits in query](https://discuss.elastic.co/t/how-can-we-compare-no-of-hits-in-query/318631)

<div class="topic-metadata">

**Author:** [@Aniket\_Pant](https://discuss.elastic.co/u/Aniket_Pant)\
**Replies:** 0\
**Last updated:** [November 10, 2022, 8:58am UTC](https://discuss.elastic.co/t/how-can-we-compare-no-of-hits-in-query/318631 "2022-11-10T08:58:40Z")

</div>

I am using metricbeat for getting system uptime. When a system goes down , the no of hits is less than 1. Is there any way we can add that no\_of\_hits \< 1 in a query. Earlier i am using this query. But i did not get any …

---

## [To get the data of Index size into Kibana Dashboards](https://discuss.elastic.co/t/to-get-the-data-of-index-size-into-kibana-dashboards/318080)

<div class="topic-metadata">

**Author:** [@anushyaadam](https://discuss.elastic.co/u/anushyaadam)\
**Replies:** 5\
**Last updated:** [November 10, 2022, 8:19am UTC](https://discuss.elastic.co/t/to-get-the-data-of-index-size-into-kibana-dashboards/318080 "2022-11-10T08:19:56Z")

</div>

Hi Team, We would like to open the same topic (To get the data of Index size into Kibana Dashboards) due to that topic has been closed automatically and we need more clarification to know about this. Actually we are ma…

---

## [Splitting a json array format with same fields name](https://discuss.elastic.co/t/splitting-a-json-array-format-with-same-fields-name/318509)

<div class="topic-metadata">

**Author:** [@Adabi\_Raihan](https://discuss.elastic.co/u/Adabi_Raihan)\
**Replies:** 3\
**Last updated:** [November 10, 2022, 7:44am UTC](https://discuss.elastic.co/t/splitting-a-json-array-format-with-same-fields-name/318509 "2022-11-10T07:44:06Z")

</div>

Hi Everyone, Currently, i have this kind of JSON array with the same field, what I wanted is to split this data into an independent field and the field name is based on a "name" field events.parameters (this is the fie…

---

## [Error: fail to enroll: error 400 fleet-server BadRequest](https://discuss.elastic.co/t/error-fail-to-enroll-error-400-fleet-server-badrequest/317329)

<div class="topic-metadata">

**Author:** [@Mouc](https://discuss.elastic.co/u/Mouc)\
**Replies:** 3\
**Last updated:** [November 10, 2022, 7:41am UTC](https://discuss.elastic.co/t/error-fail-to-enroll-error-400-fleet-server-badrequest/317329 "2022-11-10T07:41:25Z")

</div>

Hello, After reading all the topics linked to my problem, i still could not solve it. My Elastic-Agent was installed correctly but the enrollment doesn't work, at first i only read the warning saying that remote server…

---

## [Requirement to build a Multiple Input system in Logstash as given below, Can I build something like this?](https://discuss.elastic.co/t/requirement-to-build-a-multiple-input-system-in-logstash-as-given-below-can-i-build-something-like-this/318584)

<div class="topic-metadata">

**Author:** [@rravitech](https://discuss.elastic.co/u/rravitech)\
**Replies:** 2\
**Last updated:** [November 10, 2022, 6:56am UTC](https://discuss.elastic.co/t/requirement-to-build-a-multiple-input-system-in-logstash-as-given-below-can-i-build-something-like-this/318584 "2022-11-10T06:56:39Z")

</div>

I need to implement a UDP system in between the input and output patterns as mentioned below. inputs : beats, tcp output: elastic-search meanwhile i need to send all the data from the inputs like beats, tcp to an UDPO…

---

## [Trace capturing taking time after updating dynamic configuration](https://discuss.elastic.co/t/trace-capturing-taking-time-after-updating-dynamic-configuration/318612)

<div class="topic-metadata">

**Author:** [@sarthik](https://discuss.elastic.co/u/sarthik)\
**Replies:** 0\
**Last updated:** [November 10, 2022, 6:09am UTC](https://discuss.elastic.co/t/trace-capturing-taking-time-after-updating-dynamic-configuration/318612 "2022-11-10T06:09:36Z")

</div>

Trace capturing taking time after updating dynamic configuration. After I update instrumentation and recording both, there is a loss of trace data for some initial time. Is there a fixed span of time to wait after upda…

---

## [How to ingest a log file from source system to Kibana through Filebeat](https://discuss.elastic.co/t/how-to-ingest-a-log-file-from-source-system-to-kibana-through-filebeat/315544)

<div class="topic-metadata">

**Author:** [@cadrija](https://discuss.elastic.co/u/cadrija)\
**Replies:** 15\
**Last updated:** [November 10, 2022, 5:50am UTC](https://discuss.elastic.co/t/how-to-ingest-a-log-file-from-source-system-to-kibana-through-filebeat/315544 "2022-11-10T05:50:26Z")

</div>

Hi experts! I am new to elastic. I have installed ELK (7.17.6) on a Ubuntu system (suppose u.u.u.u). Now I am trying to fetch/ingest a log file from a windows system (suppose w.w.w.w). Steps I followed leaning from tut…

---

## [Index security in kibana](https://discuss.elastic.co/t/index-security-in-kibana/318428)

<div class="topic-metadata">

**Author:** [@Petr.Simik](https://discuss.elastic.co/u/Petr.Simik)\
**Replies:** 3\
**Last updated:** [November 10, 2022, 5:02am UTC](https://discuss.elastic.co/t/index-security-in-kibana/318428 "2022-11-10T05:02:06Z")

</div>

if the user does not have access to the index, no message is displayed (insufficient privileges). but just doesn't display any data which confuses my users, and they call me saying the data is missing. This is a situa…

---

## [How to divide a single field of a log in elasticsearch into multiple fields in a single event only using logstash filter plugin](https://discuss.elastic.co/t/how-to-divide-a-single-field-of-a-log-in-elasticsearch-into-multiple-fields-in-a-single-event-only-using-logstash-filter-plugin/318538)

<div class="topic-metadata">

**Author:** [@khushi](https://discuss.elastic.co/u/khushi)\
**Replies:** 3\
**Last updated:** [November 10, 2022, 4:32am UTC](https://discuss.elastic.co/t/how-to-divide-a-single-field-of-a-log-in-elasticsearch-into-multiple-fields-in-a-single-event-only-using-logstash-filter-plugin/318538 "2022-11-10T04:32:39Z")

</div>

I am sending emails from a mail service to elasticsearch. Now I want to have multiple fields of a single field.

---

## [Best Practices for Saving and Maintaining Kibana Saved Objects (Index Patterns & Dashboards)](https://discuss.elastic.co/t/best-practices-for-saving-and-maintaining-kibana-saved-objects-index-patterns-dashboards/318603)

<div class="topic-metadata">

**Author:** [@dante10](https://discuss.elastic.co/u/dante10)\
**Replies:** 0\
**Last updated:** [November 10, 2022, 2:52am UTC](https://discuss.elastic.co/t/best-practices-for-saving-and-maintaining-kibana-saved-objects-index-patterns-dashboards/318603 "2022-11-10T02:52:17Z")

</div>

What is the best practice for maintaining kibana saved objects for index-patterns and dashboards in github? 1. Do you save index-patterns and dashboards in one file? Ex: saved\_objects.ndjson {"type":"index-pattern", …

---

## [Elasticsearch Fails to Start Up within Kubernetes](https://discuss.elastic.co/t/elasticsearch-fails-to-start-up-within-kubernetes/318462)

<div class="topic-metadata">

**Author:** [@argsv](https://discuss.elastic.co/u/argsv)\
**Replies:** 0\
**Last updated:** [November 8, 2022, 6:12pm UTC](https://discuss.elastic.co/t/elasticsearch-fails-to-start-up-within-kubernetes/318462 "2022-11-08T18:12:37Z")

</div>

I am using elasticsearch 7.17.2 within Kubernetes. I am using the elastic operator. I am getting the following error Exception in thread "main" java.nio.file.AccessDeniedException: /usr/share/elasticsearch/plugins/lost+…

---

## [Restricting kibana access - iframe](https://discuss.elastic.co/t/restricting-kibana-access-iframe/315455)

<div class="topic-metadata">

**Author:** [@shivendra95](https://discuss.elastic.co/u/shivendra95)\
**Replies:** 12\
**Last updated:** [November 9, 2022, 9:32pm UTC](https://discuss.elastic.co/t/restricting-kibana-access-iframe/315455 "2022-11-09T21:32:02Z")

</div>

Hi, We have a kibana instance and we are using kibana iframe embedding into our application page. This is working fine, the problem that we are facing is that we have different clients and for every client we have creat…

---

## [How to query documents than not include nested objects field](https://discuss.elastic.co/t/how-to-query-documents-than-not-include-nested-objects-field/318583)

<div class="topic-metadata">

**Author:** [@Volna13](https://discuss.elastic.co/u/Volna13)\
**Replies:** 1\
**Last updated:** [November 9, 2022, 8:41pm UTC](https://discuss.elastic.co/t/how-to-query-documents-than-not-include-nested-objects-field/318583 "2022-11-09T20:41:43Z")

</div>

I have a psaInfo field which is nested. It is optional and not available on all events, how can I write a query to get all events where there is no psaInfo field? Here is what I have tried The impression is that the …

---

## [Kibana Monitors (Private Location) APIs](https://discuss.elastic.co/t/kibana-monitors-private-location-apis/316470)

<div class="topic-metadata">

**Author:** [@BenB196](https://discuss.elastic.co/u/BenB196)\
**Replies:** 3\
**Last updated:** [October 12, 2022, 9:47pm UTC](https://discuss.elastic.co/t/kibana-monitors-private-location-apis/316470 "2022-10-12T21:47:25Z")

</div>

Hi All, I was wondering if anyone knows where I can find any Kibana API docs (if they exist) for setting up lightweight private location monitors? The docs mention how to use the push command to setup browser monitors, …

---

## [No data straming](https://discuss.elastic.co/t/no-data-straming/318581)

<div class="topic-metadata">

**Author:** [@mustafa.husny](https://discuss.elastic.co/u/mustafa.husny)\
**Replies:** 0\
**Last updated:** [November 9, 2022, 6:38pm UTC](https://discuss.elastic.co/t/no-data-straming/318581 "2022-11-09T18:38:24Z")

</div>

I am trying to install elastic agent to ship logs and metrics from linux machine to Elastic (fleet server) Elastic version : 8.5 kibana version : 8.5 Elastic-agent version : 8.5 After logging in to kibana and navigati…

---

## [Circuit Breaker Exception](https://discuss.elastic.co/t/circuit-breaker-exception/318572)

<div class="topic-metadata">

**Author:** [@Somya\_Sharma](https://discuss.elastic.co/u/Somya_Sharma)\
**Replies:** 4\
**Last updated:** [November 9, 2022, 6:01pm UTC](https://discuss.elastic.co/t/circuit-breaker-exception/318572 "2022-11-09T18:01:24Z")

</div>

{ 'error': { 'type': 'circuit\_breaking\_exception', 'reason': '\[parent\] Data too large, data for \[\<http\_request\>\] would be \[123848638/118.1mb\], which is larger than the limit of \[123273216/117.5mb\], real usage: …

---

## [8.5 Elastic Deployment on ECK results in error validation data](https://discuss.elastic.co/t/8-5-elastic-deployment-on-eck-results-in-error-validation-data/318483)

<div class="topic-metadata">

**Author:** [@dataRunner](https://discuss.elastic.co/u/dataRunner)\
**Replies:** 0\
**Last updated:** [November 9, 2022, 12:07am UTC](https://discuss.elastic.co/t/8-5-elastic-deployment-on-eck-results-in-error-validation-data/318483 "2022-11-09T00:07:14Z")

</div>

Hi - following the ECK on k8s guide for 8.5 on Azure, I performed the following steps: Created AKS via Azr portal Using the azure command interface, ran the kubectl command to apply the crds.yaml Downloaded the operat…

---

## [Logstash input json splitted by newline "\\n"](https://discuss.elastic.co/t/logstash-input-json-splitted-by-newline-n/318146)

<div class="topic-metadata">

**Author:** [@dmrlixos](https://discuss.elastic.co/u/dmrlixos)\
**Replies:** 7\
**Last updated:** [November 9, 2022, 4:49pm UTC](https://discuss.elastic.co/t/logstash-input-json-splitted-by-newline-n/318146 "2022-11-09T16:49:45Z")

</div>

Hi I have a logstash pipeline running on tcp port 8080, that receive a log from another application. These application send logs with header "application/json;charset=UTF-8" and maybe send 1 json line or many json sppl…

---

## [\`Provided Grok expressions do not match field value:\` for logs ingested using nginx elastic agent integration](https://discuss.elastic.co/t/provided-grok-expressions-do-not-match-field-value-for-logs-ingested-using-nginx-elastic-agent-integration/318565)

<div class="topic-metadata">

**Author:** [@jolt](https://discuss.elastic.co/u/jolt)\
**Replies:** 0\
**Last updated:** [November 9, 2022, 4:24pm UTC](https://discuss.elastic.co/t/provided-grok-expressions-do-not-match-field-value-for-logs-ingested-using-nginx-elastic-agent-integration/318565 "2022-11-09T16:24:53Z")

</div>

We are seeing GROK errors when ingesting nginx logs using the elastic agent nginx integration. The nginx access & error logs are by default written out to stdout and stderr respectively. K8s picks these up and funnels …

---

## [ILM Hot Tier Searchable Snapshots](https://discuss.elastic.co/t/ilm-hot-tier-searchable-snapshots/318043)

<div class="topic-metadata">

**Author:** [@Safty](https://discuss.elastic.co/u/Safty)\
**Replies:** 4\
**Last updated:** [November 9, 2022, 4:18pm UTC](https://discuss.elastic.co/t/ilm-hot-tier-searchable-snapshots/318043 "2022-11-09T16:18:06Z")

</div>

What is the use case around Hot Tier Searchable Snapshots in ILM? I was thinking maybe... if you have an s3 repository available, do you need Cold/Frozen at all? Response time and replica requirements notwithstanding, …

[Previous page](https://discuss.elastic.co/tag/none.md?no_tags=true&page=500)

[Next page](https://discuss.elastic.co/tag/none.md?no_tags=true&page=502)
