# \#none

**URL:** https://discuss.elastic.co/tag/none.md?no_tags=true&page=502

[Latest](https://discuss.elastic.co/latest.md) · [Categories](https://discuss.elastic.co/categories.md) · [Tags](https://discuss.elastic.co/tags.md)

**Page:** 503

---

## [Date\_range field does not refresh my dashboard](https://discuss.elastic.co/t/date-range-field-does-not-refresh-my-dashboard/318328)

<div class="topic-metadata">

**Author:** [@Ilyas\_Badr](https://discuss.elastic.co/u/Ilyas_Badr)\
**Replies:** 9\
**Last updated:** [November 9, 2022, 3:50pm UTC](https://discuss.elastic.co/t/date-range-field-does-not-refresh-my-dashboard/318328 "2022-11-09T15:50:47Z")

</div>

I am using kibana to search the document of elasticsearch, somehow my dashboard stopped to be refreshed I found that date\_range filed ,which represents the time that event occurred. any idea how to fix the issue?

---

## [Integrating Power Automate flows with Azure Elastic](https://discuss.elastic.co/t/integrating-power-automate-flows-with-azure-elastic/316465)

<div class="topic-metadata">

**Author:** [@mohan.guttula](https://discuss.elastic.co/u/mohan.guttula)\
**Replies:** 0\
**Last updated:** [October 12, 2022, 6:56pm UTC](https://discuss.elastic.co/t/integrating-power-automate-flows-with-azure-elastic/316465 "2022-10-12T18:56:22Z")

</div>

how to ingest telemetry from Power Automate to Azure Elastic ?

---

## [Alerts: Calculate the 99 percentile of a histogram metric](https://discuss.elastic.co/t/alerts-calculate-the-99-percentile-of-a-histogram-metric/318556)

<div class="topic-metadata">

**Author:** [@EDzhelyov](https://discuss.elastic.co/u/EDzhelyov)\
**Replies:** 0\
**Last updated:** [November 9, 2022, 3:37pm UTC](https://discuss.elastic.co/t/alerts-calculate-the-99-percentile-of-a-histogram-metric/318556 "2022-11-09T15:37:09Z")

</div>

I have the following Prometheus alert using the etcd\_disk\_wal\_fsync\_duration\_seconds\_bucket metric: histogram\_quantile(0.99, rate(etcd\_disk\_wal\_fsync\_duration\_seconds\_bucket\[1m\])) \> 0.5 What will be equivalen…

---

## [Exporting rules to ndjson generates incomplete file](https://discuss.elastic.co/t/exporting-rules-to-ndjson-generates-incomplete-file/318214)

<div class="topic-metadata">

**Author:** [@ElasticUser11](https://discuss.elastic.co/u/ElasticUser11)\
**Replies:** 4\
**Last updated:** [November 9, 2022, 2:52pm UTC](https://discuss.elastic.co/t/exporting-rules-to-ndjson-generates-incomplete-file/318214 "2022-11-09T14:52:06Z")

</div>

I'm trying to export all the 722 rules into an ndjson file, but the file is incomplete. There are two sets of rule: Elastic rules and Custom rules. I go to Security \> Overview \> Rules \> Select all 722 rules \> Bulk Actio…

---

## [Remove domain from username](https://discuss.elastic.co/t/remove-domain-from-username/318464)

<div class="topic-metadata">

**Author:** [@aivazisd](https://discuss.elastic.co/u/aivazisd)\
**Replies:** 4\
**Last updated:** [November 9, 2022, 3:05pm UTC](https://discuss.elastic.co/t/remove-domain-from-username/318464 "2022-11-09T15:05:29Z")

</div>

Working with a string: user-identity: Delete IP-User mapping 555.55.55.555 - LOCAL\\user Succeeded - VPN user logout I'm trying to extract the user field without the 'LOCAL'. I can capture the IP and string 'logout' for…

---

## [Help including host name in httpjson post request from UI](https://discuss.elastic.co/t/help-including-host-name-in-httpjson-post-request-from-ui/318456)

<div class="topic-metadata">

**Author:** [@Mark\_Round](https://discuss.elastic.co/u/Mark_Round)\
**Replies:** 0\
**Last updated:** [November 8, 2022, 4:12pm UTC](https://discuss.elastic.co/t/help-including-host-name-in-httpjson-post-request-from-ui/318456 "2022-11-08T16:12:14Z")

</div>

I am configuring an HTTPJSON Input from Fleet using the UI and doing a POST on a REST endpoint. I need to send a body in the request. If I hard code the body as json {'hostname': 'currenthostname'} with a host name it w…

---

## [Filebeat auditd module causes mapping explosion](https://discuss.elastic.co/t/filebeat-auditd-module-causes-mapping-explosion/318205)

<div class="topic-metadata">

**Author:** [@Kosodrom](https://discuss.elastic.co/u/Kosodrom)\
**Replies:** 1\
**Last updated:** [November 9, 2022, 12:07pm UTC](https://discuss.elastic.co/t/filebeat-auditd-module-causes-mapping-explosion/318205 "2022-11-09T12:07:24Z")

</div>

Hi folks, I am using Filebeat and auditd module to collect audit logs from linux vm. I am often running into mapping limit because the ingest pipeline creates a new field for every argument given in the log message. f…

---

## [Cold and frozen node recommended memory specification](https://discuss.elastic.co/t/cold-and-frozen-node-recommended-memory-specification/318520)

<div class="topic-metadata">

**Author:** [@dms6978](https://discuss.elastic.co/u/dms6978)\
**Replies:** 2\
**Last updated:** [November 9, 2022, 9:38am UTC](https://discuss.elastic.co/t/cold-and-frozen-node-recommended-memory-specification/318520 "2022-11-09T09:38:39Z")

</div>

As far as I know, hot node needs 4TB of ssd, how much is cold and frozen node?

---

## [Query\_string does not work with multiple tokens with the same position](https://discuss.elastic.co/t/query-string-does-not-work-with-multiple-tokens-with-the-same-position/318454)

<div class="topic-metadata">

**Author:** [@Alex\_Shkop](https://discuss.elastic.co/u/Alex_Shkop)\
**Replies:** 2\
**Last updated:** [November 9, 2022, 8:30am UTC](https://discuss.elastic.co/t/query-string-does-not-work-with-multiple-tokens-with-the-same-position/318454 "2022-11-09T08:30:04Z")

</div>

I'm having troubles with query\_string query when my analyzer returns multiple tokens for the same position. Here's an output of \_analyze for my query: { "tokens" : \[ { "token" : "d", "start\_offset" : 6…

---

## [Multiple pre & post tags in highlighter query](https://discuss.elastic.co/t/multiple-pre-post-tags-in-highlighter-query/318492)

<div class="topic-metadata">

**Author:** [@mayanknc](https://discuss.elastic.co/u/mayanknc)\
**Replies:** 1\
**Last updated:** [November 9, 2022, 7:53am UTC](https://discuss.elastic.co/t/multiple-pre-post-tags-in-highlighter-query/318492 "2022-11-09T07:53:04Z")

</div>

Hi I want to highlight individual query string's match result with different pre & post tags. Create Index PUT multilang\_index { "mappings": { "dynamic\_templates": \[ { "stripped\_section\_template": { …

---

## [How to check old pipeline is terminated or not in logstash during config reload](https://discuss.elastic.co/t/how-to-check-old-pipeline-is-terminated-or-not-in-logstash-during-config-reload/318514)

<div class="topic-metadata">

**Author:** [@teja\_tata](https://discuss.elastic.co/u/teja_tata)\
**Replies:** 0\
**Last updated:** [November 9, 2022, 7:25am UTC](https://discuss.elastic.co/t/how-to-check-old-pipeline-is-terminated-or-not-in-logstash-during-config-reload/318514 "2022-11-09T07:25:14Z")

</div>

From the above documentation we could see that Logstash swaps the existing pipeline with the new pipeline. If the checks fail, the old pipeline continues to function, and the errors are propagated to the console. How …

---

## [I was logging my log from .net application using seilog before enabling Xpack security in stack the logs stopped comming](https://discuss.elastic.co/t/i-was-logging-my-log-from-net-application-using-seilog-before-enabling-xpack-security-in-stack-the-logs-stopped-comming/318499)

<div class="topic-metadata">

**Author:** [@DIVYANSH\_SINGH](https://discuss.elastic.co/u/DIVYANSH_SINGH)\
**Replies:** 4\
**Last updated:** [November 9, 2022, 6:47am UTC](https://discuss.elastic.co/t/i-was-logging-my-log-from-net-application-using-seilog-before-enabling-xpack-security-in-stack-the-logs-stopped-comming/318499 "2022-11-09T06:47:28Z")

</div>

I was logging my log from .net application using serilog before enabling Xpack security in stack the logs stopped comming How will i solve this

---

## [Import kibana dashboard using ansible playbook](https://discuss.elastic.co/t/import-kibana-dashboard-using-ansible-playbook/317965)

<div class="topic-metadata">

**Author:** [@Neelam\_Zanvar](https://discuss.elastic.co/u/Neelam_Zanvar)\
**Replies:** 4\
**Last updated:** [November 9, 2022, 6:03am UTC](https://discuss.elastic.co/t/import-kibana-dashboard-using-ansible-playbook/317965 "2022-11-09T06:03:55Z")

</div>

Hi, I have created a kibana dashboard and exported it. This have a .ndjson file with me. Now I want to import this dashboard to kibana (other severs) using ansible playbook using the .ndjson file i already have. How can…

---

## [INDEX CLOSED EXCEPTION](https://discuss.elastic.co/t/index-closed-exception/318507)

<div class="topic-metadata">

**Author:** [@Gojo](https://discuss.elastic.co/u/Gojo)\
**Replies:** 0\
**Last updated:** [November 9, 2022, 6:03am UTC](https://discuss.elastic.co/t/index-closed-exception/318507 "2022-11-09T06:03:36Z")

</div>

Continuing the discussion from Index\_closed\_exception: so how can i resolve this ?

---

## [INDEX IN CLOSED STATE NOT ABLE TO OPEN](https://discuss.elastic.co/t/index-in-closed-state-not-able-to-open/318396)

<div class="topic-metadata">

**Author:** [@Gojo](https://discuss.elastic.co/u/Gojo)\
**Replies:** 10\
**Last updated:** [November 9, 2022, 5:00am UTC](https://discuss.elastic.co/t/index-in-closed-state-not-able-to-open/318396 "2022-11-09T05:00:44Z")

</div>

hi all , we did rollback to our server after that suddenly all indices went to closed state

---

## [Can somebody interpret the data if the shard is unbalanced?](https://discuss.elastic.co/t/can-somebody-interpret-the-data-if-the-shard-is-unbalanced/318491)

<div class="topic-metadata">

**Author:** [@Java2avaj](https://discuss.elastic.co/u/Java2avaj)\
**Replies:** 1\
**Last updated:** [November 9, 2022, 4:19am UTC](https://discuss.elastic.co/t/can-somebody-interpret-the-data-if-the-shard-is-unbalanced/318491 "2022-11-09T04:19:48Z")

</div>

Based on the following data, may I know if the shard is unbalanced or is it evenly distributed for people index? We have 2 primary shards and 1 replica health status index uuid pri rep docs.…

---

## [How to remove elasticsearch and reinstall to reset cluster](https://discuss.elastic.co/t/how-to-remove-elasticsearch-and-reinstall-to-reset-cluster/317904)

<div class="topic-metadata">

**Author:** [@tmdgk490255](https://discuss.elastic.co/u/tmdgk490255)\
**Replies:** 1\
**Last updated:** [November 9, 2022, 1:03am UTC](https://discuss.elastic.co/t/how-to-remove-elasticsearch-and-reinstall-to-reset-cluster/317904 "2022-11-09T01:03:58Z")

</div>

I want to remove es on ec2 instance and reinstall it to initialize cluster and node info How can I? I tried but it always had same cluster uuid even I uninstalled it First I installed es following these steps sudo rpm…

---

## [Sorting collapsed results based on nested documents](https://discuss.elastic.co/t/sorting-collapsed-results-based-on-nested-documents/318480)

<div class="topic-metadata">

**Author:** [@tombrisland](https://discuss.elastic.co/u/tombrisland)\
**Replies:** 0\
**Last updated:** [November 8, 2022, 10:20pm UTC](https://discuss.elastic.co/t/sorting-collapsed-results-based-on-nested-documents/318480 "2022-11-08T22:20:10Z")

</div>

I have a query which makes use of collapse to de-duplicate results. I'm expecting some collapsed results to have multiple duplicates, and some to be unique. I would like to sort the entries in such a way that the results…

---

## [Send syslogs in batches/an array of events records?](https://discuss.elastic.co/t/send-syslogs-in-batches-an-array-of-events-records/318477)

<div class="topic-metadata">

**Author:** [@ianbv](https://discuss.elastic.co/u/ianbv)\
**Replies:** 0\
**Last updated:** [November 8, 2022, 9:41pm UTC](https://discuss.elastic.co/t/send-syslogs-in-batches-an-array-of-events-records/318477 "2022-11-08T21:41:03Z")

</div>

Is there a way to group linux syslogs events together in to an array with a logstash filter or output plugin? Here is the example schema I need to get the logs into for sending to ADX: \[ { "records": \[ { r1 …

---

## [Send Ubuntu Syslogs to Azure Event Hub with Logstash - json issue](https://discuss.elastic.co/t/send-ubuntu-syslogs-to-azure-event-hub-with-logstash-json-issue/317990)

<div class="topic-metadata">

**Author:** [@ianbv](https://discuss.elastic.co/u/ianbv)\
**Replies:** 1\
**Last updated:** [November 8, 2022, 9:11pm UTC](https://discuss.elastic.co/t/send-ubuntu-syslogs-to-azure-event-hub-with-logstash-json-issue/317990 "2022-11-08T21:11:23Z")

</div>

Situation: Using Logstash to forward ubuntu (azure vm) syslogs to an azure event hub. Problem: Using "json" or "json\_batch" results in adding the \_jsonparseerror tag to events because the syslog isn't in json format. Is…

---

## [Split HTTP Poller Responses to Multiple Documents using Split Filter](https://discuss.elastic.co/t/split-http-poller-responses-to-multiple-documents-using-split-filter/318418)

<div class="topic-metadata">

**Author:** [@sajid](https://discuss.elastic.co/u/sajid)\
**Replies:** 3\
**Last updated:** [November 8, 2022, 8:33pm UTC](https://discuss.elastic.co/t/split-http-poller-responses-to-multiple-documents-using-split-filter/318418 "2022-11-08T20:33:14Z")

</div>

We have multiple healthcheck endpoint of different applications which give response in json about the health status of that application and its dependencies. Below are the response of two of the hc URLs: URL 1 Response…

---

## [Logstash failed to start (org.jruby.RubyKernel.exit(org/jruby/RubyKernel.java:790) ~\[jruby.jar:?\])](https://discuss.elastic.co/t/logstash-failed-to-start-org-jruby-rubykernel-exit-org-jruby-rubykernel-java-790-jruby-jar/318457)

<div class="topic-metadata">

**Author:** [@Rootlente](https://discuss.elastic.co/u/Rootlente)\
**Replies:** 12\
**Last updated:** [November 8, 2022, 8:18pm UTC](https://discuss.elastic.co/t/logstash-failed-to-start-org-jruby-rubykernel-exit-org-jruby-rubykernel-java-790-jruby-jar/318457 "2022-11-08T20:18:04Z")

</div>

Hello, I am building home lab environment to collect winevent logs using filebat and send them on my Ubuntu machine where i installed everything and configured them by documentation but every time i get this error i d…

---

## [Can someone see the dashboard without the need for sign in](https://discuss.elastic.co/t/can-someone-see-the-dashboard-without-the-need-for-sign-in/318388)

<div class="topic-metadata">

**Author:** [@Shashank02](https://discuss.elastic.co/u/Shashank02)\
**Replies:** 9\
**Last updated:** [November 8, 2022, 5:29pm UTC](https://discuss.elastic.co/t/can-someone-see-the-dashboard-without-the-need-for-sign-in/318388 "2022-11-08T17:29:49Z")

</div>

So, I've been building a website, where I want to show the dashboards of Kibana. So, on the website whenever the user clicks the link they will be redirected to the dashboard page in Kibana. but, the only thing I want to…

---

## [How to work with es enrollment token and kibana verification code when working in kubernetes](https://discuss.elastic.co/t/how-to-work-with-es-enrollment-token-and-kibana-verification-code-when-working-in-kubernetes/316394)

<div class="topic-metadata">

**Author:** [@Kracozebr](https://discuss.elastic.co/u/Kracozebr)\
**Replies:** 0\
**Last updated:** [October 12, 2022, 3:24am UTC](https://discuss.elastic.co/t/how-to-work-with-es-enrollment-token-and-kibana-verification-code-when-working-in-kubernetes/316394 "2022-10-12T03:24:29Z")

</div>

I need to have opportunity to collect logs from my embedded device and has chosen elasticsearch and kibana for that. I can connect to my embedded device through Ethernet from my PC. I installed elasticsearch and kibana …

---

## [How to stop refresh activity while using scroll](https://discuss.elastic.co/t/how-to-stop-refresh-activity-while-using-scroll/318382)

<div class="topic-metadata">

**Author:** [@ykonathala](https://discuss.elastic.co/u/ykonathala)\
**Replies:** 5\
**Last updated:** [November 8, 2022, 5:08pm UTC](https://discuss.elastic.co/t/how-to-stop-refresh-activity-while-using-scroll/318382 "2022-11-08T17:08:55Z")

</div>

Team Can someone help or suggest the way to pause or disable refresh while I update all the docs within scroll request ?? I do see there is a http curl request that we can do against single or multiple indexes but I am…

---

## [How to plot a line chart pointing to zero instead of smoothing out till end](https://discuss.elastic.co/t/how-to-plot-a-line-chart-pointing-to-zero-instead-of-smoothing-out-till-end/317979)

<div class="topic-metadata">

**Author:** [@Tukaram](https://discuss.elastic.co/u/Tukaram)\
**Replies:** 7\
**Last updated:** [November 8, 2022, 5:03pm UTC](https://discuss.elastic.co/t/how-to-plot-a-line-chart-pointing-to-zero-instead-of-smoothing-out-till-end/317979 "2022-11-08T17:03:06Z")

</div>

As per attached graph, I am expecting that line graph should show some round circle if values after 5 on x axis are missing or just drop to zero on x axis.

---

## [Stop auto-placement of visualisations within a dashboard](https://discuss.elastic.co/t/stop-auto-placement-of-visualisations-within-a-dashboard/318442)

<div class="topic-metadata">

**Author:** [@ChrizK](https://discuss.elastic.co/u/ChrizK)\
**Replies:** 2\
**Last updated:** [November 8, 2022, 3:53pm UTC](https://discuss.elastic.co/t/stop-auto-placement-of-visualisations-within-a-dashboard/318442 "2022-11-08T15:53:12Z")

</div>

Continuing the discussion from Stop Graphs Auto-Filling Blank Space in Dashboard: Hi, could you provide the steps to creating an empty markdown visualisation? Sorry, I don't understand how this is done. I am editing …

---

## [Elastic agent healthy but no logs sent](https://discuss.elastic.co/t/elastic-agent-healthy-but-no-logs-sent/318447)

<div class="topic-metadata">

**Author:** [@mammodde](https://discuss.elastic.co/u/mammodde)\
**Replies:** 0\
**Last updated:** [November 8, 2022, 3:49pm UTC](https://discuss.elastic.co/t/elastic-agent-healthy-but-no-logs-sent/318447 "2022-11-08T15:49:11Z")

</div>

Hi, I am trying to install Elastic Agents, they are labelled as healthy but I do not receive any log. I am pretty sure it has to do with certificates, as always. sorry for the image, but why I cannot choose a differ…

---

## [Sending report (csv or pdf) or rollup indices to third party apps (e.g. kafka)](https://discuss.elastic.co/t/sending-report-csv-or-pdf-or-rollup-indices-to-third-party-apps-e-g-kafka/315931)

<div class="topic-metadata">

**Author:** [@mikhatanu](https://discuss.elastic.co/u/mikhatanu)\
**Replies:** 3\
**Last updated:** [November 8, 2022, 3:30pm UTC](https://discuss.elastic.co/t/sending-report-csv-or-pdf-or-rollup-indices-to-third-party-apps-e-g-kafka/315931 "2022-11-08T15:30:59Z")

</div>

Hello, I'm thinking of sending data of kibana reports to third party service. So far, i can generate report automatically (csv) using the API and create rollup jobs but it does not download or sent automatically. Is ther…

---

## [Elasticsearch 7.17.7 does not start - "java.security.AccessControlException: access denied"](https://discuss.elastic.co/t/elasticsearch-7-17-7-does-not-start-java-security-accesscontrolexception-access-denied/318013)

<div class="topic-metadata">

**Author:** [@jacotec](https://discuss.elastic.co/u/jacotec)\
**Replies:** 5\
**Last updated:** [November 8, 2022, 2:51pm UTC](https://discuss.elastic.co/t/elasticsearch-7-17-7-does-not-start-java-security-accesscontrolexception-access-denied/318013 "2022-11-08T14:51:45Z")

</div>

Hi, I'm despairing with Elasticsearch on one of my Ubuntu 20.04 LTS VM's. I've just installed ES 7.17.7 from the official repo, did no config changes or something else, just did apt install elasticsearch systemctl daem…

[Previous page](https://discuss.elastic.co/tag/none.md?no_tags=true&page=501)

[Next page](https://discuss.elastic.co/tag/none.md?no_tags=true&page=503)
