# \#none

**URL:** https://discuss.elastic.co/tag/none.md?no_tags=true&page=510

[Latest](https://discuss.elastic.co/latest.md) · [Categories](https://discuss.elastic.co/categories.md) · [Tags](https://discuss.elastic.co/tags.md)

**Page:** 511

---

## [System integration doesn't populate ECS Fields -\> Predefined Dashboards not usable anymore](https://discuss.elastic.co/t/system-integration-doesnt-populate-ecs-fields-predefined-dashboards-not-usable-anymore/317559)

<div class="topic-metadata">

**Author:** [@matled](https://discuss.elastic.co/u/matled)\
**Replies:** 0\
**Last updated:** [October 26, 2022, 9:09pm UTC](https://discuss.elastic.co/t/system-integration-doesnt-populate-ecs-fields-predefined-dashboards-not-usable-anymore/317559 "2022-10-26T21:09:33Z")

</div>

Hey there We've observed a change in the populated fields from the system integration. Since about two weeks we have very different fields populated (or not) therefore leading to missing fields in our own and the predef…

---

## [Index template with only one field across multiple indices](https://discuss.elastic.co/t/index-template-with-only-one-field-across-multiple-indices/317315)

<div class="topic-metadata">

**Author:** [@not\_correct](https://discuss.elastic.co/u/not_correct)\
**Replies:** 14\
**Last updated:** [October 26, 2022, 6:03pm UTC](https://discuss.elastic.co/t/index-template-with-only-one-field-across-multiple-indices/317315 "2022-10-26T18:03:36Z")

</div>

Hi, I have multiple indices like mailbox-xx- xxxx .The xx-xxxx values are assigned dynamically. Each index contains various fields with date as a common field. The problem that date field has been read as long type by …

---

## [Kibana not showing data after turning on xpack security and TLS](https://discuss.elastic.co/t/kibana-not-showing-data-after-turning-on-xpack-security-and-tls/317470)

<div class="topic-metadata">

**Author:** [@Bruceclegg](https://discuss.elastic.co/u/Bruceclegg)\
**Replies:** 4\
**Last updated:** [October 26, 2022, 4:57pm UTC](https://discuss.elastic.co/t/kibana-not-showing-data-after-turning-on-xpack-security-and-tls/317470 "2022-10-26T16:57:27Z")

</div>

Yesterday I updated the security on our small 3 node cluster of Elasticsearch 7.17.5 running on CentOS 7. I did my best to follow the documentation: I added the passwords for the built in accounts, set up the kibana\_ke…

---

## [Data Path Change](https://discuss.elastic.co/t/data-path-change/317430)

<div class="topic-metadata">

**Author:** [@Safty](https://discuss.elastic.co/u/Safty)\
**Replies:** 4\
**Last updated:** [October 26, 2022, 4:19pm UTC](https://discuss.elastic.co/t/data-path-change/317430 "2022-10-26T16:19:13Z")

</div>

Hello, I am interested in best practices for changing the default data and log path in the elasticsearch.yml file. I have found various references on the web about how this is done (a simple copy of the data as well as…

---

## [Action/metadata line \[1\] contains an unknown parameter \[\_script\]](https://discuss.elastic.co/t/action-metadata-line-1-contains-an-unknown-parameter-script/317548)

<div class="topic-metadata">

**Author:** [@nimish](https://discuss.elastic.co/u/nimish)\
**Replies:** 0\
**Last updated:** [October 26, 2022, 3:32pm UTC](https://discuss.elastic.co/t/action-metadata-line-1-contains-an-unknown-parameter-script/317548 "2022-10-26T15:32:41Z")

</div>

facing following issue while updating document using script Encountered a retryable error (will retry with exponential backoff) { "error": { "root\_cause": \[ { "type": "illegal\_argument\_exception", "reason"…

---

## [My dashboard](https://discuss.elastic.co/t/my-dashboard/317534)

<div class="topic-metadata">

**Author:** [@VitorBarroso](https://discuss.elastic.co/u/VitorBarroso)\
**Replies:** 3\
**Last updated:** [October 26, 2022, 3:00pm UTC](https://discuss.elastic.co/t/my-dashboard/317534 "2022-10-26T15:00:19Z")

</div>

Hello I want to remove the value "Não existe" from the dashboard. Can i do it without touch any information?

---

## [Referenced config files FileBeat (Windows)](https://discuss.elastic.co/t/referenced-config-files-filebeat-windows/317310)

<div class="topic-metadata">

**Author:** [@Remco1985](https://discuss.elastic.co/u/Remco1985)\
**Replies:** 6\
**Last updated:** [October 26, 2022, 1:15pm UTC](https://discuss.elastic.co/t/referenced-config-files-filebeat-windows/317310 "2022-10-26T13:15:20Z")

</div>

Hi, Recently we have successfully installed Filebeat on our (test) Windows server. Right now I’m investigating to find out the best deployment strategy for Filebeat agents on all of our Windows Server systems. We would…

---

## [Please tell me How to custom Kibana logo in 7.17.6](https://discuss.elastic.co/t/please-tell-me-how-to-custom-kibana-logo-in-7-17-6/316487)

<div class="topic-metadata">

**Author:** [@soniya](https://discuss.elastic.co/u/soniya)\
**Replies:** 1\
**Last updated:** [October 26, 2022, 12:58pm UTC](https://discuss.elastic.co/t/please-tell-me-how-to-custom-kibana-logo-in-7-17-6/316487 "2022-10-26T12:58:34Z")

</div>

Hi all, I am working on Kibana 7.17.6 version. I want to change Kibana logo and found some articles on logo change of Kibana, but they are for older version. please do help me with this query.

---

## [Highlight produce unexpected invalid results on multivalue fields copied from other fields](https://discuss.elastic.co/t/highlight-produce-unexpected-invalid-results-on-multivalue-fields-copied-from-other-fields/317394)

<div class="topic-metadata">

**Author:** [@Maxim\_Kollegov](https://discuss.elastic.co/u/Maxim_Kollegov)\
**Replies:** 1\
**Last updated:** [October 26, 2022, 12:24pm UTC](https://discuss.elastic.co/t/highlight-produce-unexpected-invalid-results-on-multivalue-fields-copied-from-other-fields/317394 "2022-10-26T12:24:27Z")

</div>

Steps to reproduce create mapping post /test/\_mapping { "properties": { "family": { "type": "text", "index": true, "term\_vector": "with\_positions\_offsets", …

---

## [Searching two terms inside array of object](https://discuss.elastic.co/t/searching-two-terms-inside-array-of-object/317507)

<div class="topic-metadata">

**Author:** [@yashveer](https://discuss.elastic.co/u/yashveer)\
**Replies:** 4\
**Last updated:** [October 26, 2022, 12:23pm UTC](https://discuss.elastic.co/t/searching-two-terms-inside-array-of-object/317507 "2022-10-26T12:23:07Z")

</div>

"rno" : 1, "narratives": \[ { "compl": "call drop", "ts": "2015-05-01" }, { "compl": "internet connection lost ", "ts": "2016-01-…

---

## [Need to delete my topic in Elastic Forum - User not able to access their dashboards](https://discuss.elastic.co/t/need-to-delete-my-topic-in-elastic-forum-user-not-able-to-access-their-dashboards/317503)

<div class="topic-metadata">

**Author:** [@yasar](https://discuss.elastic.co/u/yasar)\
**Replies:** 2\
**Last updated:** [October 26, 2022, 12:10pm UTC](https://discuss.elastic.co/t/need-to-delete-my-topic-in-elastic-forum-user-not-able-to-access-their-dashboards/317503 "2022-10-26T12:10:50Z")

</div>

Hi team, Some info in my posts is considered as sensitive (but really it is not), so i need to remove it. I already give it as a flag. But still, it's not removed. Can anyone remove this topic as soon as possible, ple…

---

## [Elastic agent enrollment via configuration management](https://discuss.elastic.co/t/elastic-agent-enrollment-via-configuration-management/317515)

<div class="topic-metadata">

**Author:** [@UPPERCASE](https://discuss.elastic.co/u/UPPERCASE)\
**Replies:** 0\
**Last updated:** [October 26, 2022, 12:10pm UTC](https://discuss.elastic.co/t/elastic-agent-enrollment-via-configuration-management/317515 "2022-10-26T12:10:48Z")

</div>

In ECE clients are enrolled with elastic-agent enroll --url=example.com:9243 --enrollment-token=$token and then the rest is managed by Fleet. However, I would like to enroll clients not with a command, but with a proper…

---

## [Kibana dataview namespace](https://discuss.elastic.co/t/kibana-dataview-namespace/317475)

<div class="topic-metadata">

**Author:** [@dms6978](https://discuss.elastic.co/u/dms6978)\
**Replies:** 1\
**Last updated:** [October 26, 2022, 10:54am UTC](https://discuss.elastic.co/t/kibana-dataview-namespace/317475 "2022-10-26T10:54:16Z")

</div>

There is "namespace" properties of the data\_view object when create Data Views. (doc: Create data view API | Kibana Guide \[master\] | Elastic) curl -X POST "kibanahost:port/api/data\_views/data\_view" -H 'kbn-xsrf: true' …

---

## [Pmacct as\_path graphs](https://discuss.elastic.co/t/pmacct-as-path-graphs/317502)

<div class="topic-metadata">

**Author:** [@arphillips](https://discuss.elastic.co/u/arphillips)\
**Replies:** 0\
**Last updated:** [October 26, 2022, 10:40am UTC](https://discuss.elastic.co/t/pmacct-as-path-graphs/317502 "2022-10-26T10:40:50Z")

</div>

I am trying to make something akin to a sankey graph using showing the ASN paths. I'd like to be able to visualize the full path and each hop, pmacct is my netflow collector it sends the key "as\_path" in the format "6500…

---

## [Log threshold rules does not allow filtering with boolean fields](https://discuss.elastic.co/t/log-threshold-rules-does-not-allow-filtering-with-boolean-fields/317175)

<div class="topic-metadata">

**Author:** [@qatium-developers](https://discuss.elastic.co/u/qatium-developers)\
**Replies:** 3\
**Last updated:** [October 26, 2022, 10:10am UTC](https://discuss.elastic.co/t/log-threshold-rules-does-not-allow-filtering-with-boolean-fields/317175 "2022-10-26T10:10:18Z")

</div>

Hello, we are trying to generate a Log Threshold rule that requires checking a boolean field to detect if the alert must be raised or not, but UI interface does not allow to use this kind of fields. We have checked the…

---

## [Tcp output exception](https://discuss.elastic.co/t/tcp-output-exception/317227)

<div class="topic-metadata">

**Author:** [@Anusha\_Kusanghi](https://discuss.elastic.co/u/Anusha_Kusanghi)\
**Replies:** 5\
**Last updated:** [October 26, 2022, 9:44am UTC](https://discuss.elastic.co/t/tcp-output-exception/317227 "2022-10-26T09:44:14Z")

</div>

Hie Everyone, I have configured pipeline to read logs over tcp plugin. But im feeling tcp output exception every now and than the tcp connection is getting closed. Error logs: tcp output exception {:host=\>"10.109.0.0"…

---

## [Filter on nested object to return all fields under nested object with value zero](https://discuss.elastic.co/t/filter-on-nested-object-to-return-all-fields-under-nested-object-with-value-zero/317488)

<div class="topic-metadata">

**Author:** [@monaadelrabea](https://discuss.elastic.co/u/monaadelrabea)\
**Replies:** 0\
**Last updated:** [October 26, 2022, 9:07am UTC](https://discuss.elastic.co/t/filter-on-nested-object-to-return-all-fields-under-nested-object-with-value-zero/317488 "2022-10-26T09:07:01Z")

</div>

I need to filter on an index that have nested object called params, this object contains dynamic fields how to return only docs that contain fields with zero value under params nesetd object Ex: "params": { "ePwrV":\[ …

---

## [No new data in Kibana - elastic fails to create shard](https://discuss.elastic.co/t/no-new-data-in-kibana-elastic-fails-to-create-shard/316318)

<div class="topic-metadata">

**Author:** [@cjabrantes](https://discuss.elastic.co/u/cjabrantes)\
**Replies:** 1\
**Last updated:** [October 26, 2022, 9:33am UTC](https://discuss.elastic.co/t/no-new-data-in-kibana-elastic-fails-to-create-shard/316318 "2022-10-26T09:33:21Z")

</div>

Hi All, from time to time i see that kibana stops showing new data, its always the same, i have daily index (naming from LS) in ES that gets unassigned on both shard when its created, the logs i can find: obtaining sh…

---

## [Divide query in separate new lines](https://discuss.elastic.co/t/divide-query-in-separate-new-lines/317389)

<div class="topic-metadata">

**Author:** [@oalimerko](https://discuss.elastic.co/u/oalimerko)\
**Replies:** 3\
**Last updated:** [October 26, 2022, 8:39am UTC](https://discuss.elastic.co/t/divide-query-in-separate-new-lines/317389 "2022-10-26T08:39:30Z")

</div>

Hello team, this is my new post here,i am looking forward share my experience and knowledge with community. I'm using elasticsearch and kibana for logs monitoring and also for this purpose i use the ES-Exporter for cat…

---

## [Word delimeter graph doesn't work with ICU tokenizer](https://discuss.elastic.co/t/word-delimeter-graph-doesnt-work-with-icu-tokenizer/317482)

<div class="topic-metadata">

**Author:** [@Mariusz\_Pala](https://discuss.elastic.co/u/Mariusz_Pala)\
**Replies:** 0\
**Last updated:** [October 26, 2022, 8:20am UTC](https://discuss.elastic.co/t/word-delimeter-graph-doesnt-work-with-icu-tokenizer/317482 "2022-10-26T08:20:39Z")

</div>

Hi, I want to be able to search word like "Wi-Fi" by wifi and it is possible with word delimeter graph with whitespace tokenizer. But I need the icu\_tokenizer and then it doesn't work at all, it indexes only "wi" and "f…

---

## [What should I do in case of a complete failure during the upgrade process?](https://discuss.elastic.co/t/what-should-i-do-in-case-of-a-complete-failure-during-the-upgrade-process/317326)

<div class="topic-metadata">

**Author:** [@Leonardo\_Henrique](https://discuss.elastic.co/u/Leonardo_Henrique)\
**Replies:** 1\
**Last updated:** [October 26, 2022, 7:56am UTC](https://discuss.elastic.co/t/what-should-i-do-in-case-of-a-complete-failure-during-the-upgrade-process/317326 "2022-10-26T07:56:56Z")

</div>

Hello, everyone. How have you been? I have a question related to the upgrade process. In docs (and viewing some posts here in the forum), it is said that the concept of rollback does not exist in Elasticsearch, but we h…

---

## [Binary logs parsing Logstash sent via filebeat?](https://discuss.elastic.co/t/binary-logs-parsing-logstash-sent-via-filebeat/317281)

<div class="topic-metadata">

**Author:** [@ShubhamKumarJena](https://discuss.elastic.co/u/ShubhamKumarJena)\
**Replies:** 1\
**Last updated:** [October 26, 2022, 7:47am UTC](https://discuss.elastic.co/t/binary-logs-parsing-logstash-sent-via-filebeat/317281 "2022-10-26T07:47:23Z")

</div>

Hello ! I am trying to parse few logs which are in binary format hence can somebody guide how do we proceed with that? I am attaching the message field for reference: "message" =\> "\\u0000\\u0000\\u0000\\u000384p�\<�\\u0000…

---

## [Phrase words matches anywhere in the multi fields and stemming also reduce the boosting on keyword stuffing](https://discuss.elastic.co/t/phrase-words-matches-anywhere-in-the-multi-fields-and-stemming-also-reduce-the-boosting-on-keyword-stuffing/317477)

<div class="topic-metadata">

**Author:** [@sagarc](https://discuss.elastic.co/u/sagarc)\
**Replies:** 0\
**Last updated:** [October 26, 2022, 7:25am UTC](https://discuss.elastic.co/t/phrase-words-matches-anywhere-in-the-multi-fields-and-stemming-also-reduce-the-boosting-on-keyword-stuffing/317477 "2022-10-26T07:25:02Z")

</div>

Data Types: Title: string Keywords: string Description: string Search Requirements: 1. ALL search terms MUST be found somewhere in the title or keywords or description a) Don’t search the whole DOCUMENT for terms… …

---

## [Unable to Register Azure Repo in Elasticsearch - 2.4.4](https://discuss.elastic.co/t/unable-to-register-azure-repo-in-elasticsearch-2-4-4/317466)

<div class="topic-metadata">

**Author:** [@Sandipan\_Deb](https://discuss.elastic.co/u/Sandipan_Deb)\
**Replies:** 3\
**Last updated:** [October 26, 2022, 6:56am UTC](https://discuss.elastic.co/t/unable-to-register-azure-repo-in-elasticsearch-2-4-4/317466 "2022-10-26T06:56:32Z")

</div>

I am getting below error while trying to register a repo in azure storage. It was working fine before 2-3 months. Suddenly it started giving error. Not able to understand what might have changed. Any help is appreciated…

---

## [Max compilations rate setting - cluster level or node level?](https://discuss.elastic.co/t/max-compilations-rate-setting-cluster-level-or-node-level/317299)

<div class="topic-metadata">

**Author:** [@shaigbdb](https://discuss.elastic.co/u/shaigbdb)\
**Replies:** 1\
**Last updated:** [October 26, 2022, 4:20am UTC](https://discuss.elastic.co/t/max-compilations-rate-setting-cluster-level-or-node-level/317299 "2022-10-26T04:20:55Z")

</div>

Does the limit defined in script.max\_compilations\_rate apply for the concurrent number of scripts on a node, or for the total concurrent number of scripts for the entire cluster? Thanks.

---

## [How to store configmap in elasticsearch](https://discuss.elastic.co/t/how-to-store-configmap-in-elasticsearch/317454)

<div class="topic-metadata">

**Author:** [@hanweisen](https://discuss.elastic.co/u/hanweisen)\
**Replies:** 0\
**Last updated:** [October 26, 2022, 2:38am UTC](https://discuss.elastic.co/t/how-to-store-configmap-in-elasticsearch/317454 "2022-10-26T02:38:32Z")

</div>

Recently I am indexing the k8s resource object in ES. There are some problems with storing configmap. configmap defines as bellow: // +genclient // +k8s:deepcopy-gen:interfaces=k8s.io/apimachinery/pkg/runtime.Object …

---

## [Could we support timeout mechanism for replica bulk request？](https://discuss.elastic.co/t/could-we-support-timeout-mechanism-for-replica-bulk-request/316977)

<div class="topic-metadata">

**Author:** [@howardhuang](https://discuss.elastic.co/u/howardhuang)\
**Replies:** 6\
**Last updated:** [October 26, 2022, 1:39am UTC](https://discuss.elastic.co/t/could-we-support-timeout-mechanism-for-replica-bulk-request/316977 "2022-10-26T01:39:25Z")

</div>

Assume that shard has 1 primary + 1 replica, if a bulk request goes to primary and finished the shard bulk write operation, then transfer the bulk request to replica node, if the replica node is a really slow node, for e…

---

## [Failed to Load Service Token](https://discuss.elastic.co/t/failed-to-load-service-token/317391)

<div class="topic-metadata">

**Author:** [@EExisT](https://discuss.elastic.co/u/EExisT)\
**Replies:** 1\
**Last updated:** [October 26, 2022, 1:17am UTC](https://discuss.elastic.co/t/failed-to-load-service-token/317391 "2022-10-26T01:17:06Z")

</div>

Hello, at the start of Elastic I got these errors: \[2022-10-25T09:31:12,342\]\[ERROR\]\[o.e.b.Elasticsearch \] \[node-1\] fatal exception while booting Elasticsearch java.lang.IllegalStateException: security initializati…

---

## [Setup multi nodes on elastic 8.4.3 to run only when 2 nodes are active](https://discuss.elastic.co/t/setup-multi-nodes-on-elastic-8-4-3-to-run-only-when-2-nodes-are-active/317407)

<div class="topic-metadata">

**Author:** [@juandreww](https://discuss.elastic.co/u/juandreww)\
**Replies:** 1\
**Last updated:** [October 26, 2022, 1:14am UTC](https://discuss.elastic.co/t/setup-multi-nodes-on-elastic-8-4-3-to-run-only-when-2-nodes-are-active/317407 "2022-10-26T01:14:55Z")

</div>

Hi, I would like to configure the Elastic Search for multiple nodes but only when 2 nodes running from 3 nodes, then the localhost can be accessed I have tried: node.name: node-3 (in folder node2 then node-2, etc) net…

---

## [Using search as you type field for prefix queries](https://discuss.elastic.co/t/using-search-as-you-type-field-for-prefix-queries/317432)

<div class="topic-metadata">

**Author:** [@caseydm](https://discuss.elastic.co/u/caseydm)\
**Replies:** 0\
**Last updated:** [October 25, 2022, 5:28pm UTC](https://discuss.elastic.co/t/using-search-as-you-type-field-for-prefix-queries/317432 "2022-10-25T17:28:44Z")

</div>

I indexed some of my data as a "search as you type" field in Kibana. Specifically, in the query below the field authorships.author.display\_name.autocomplete is indexed this way. From looking at the documentation, indexin…

[Previous page](https://discuss.elastic.co/tag/none.md?no_tags=true&page=509)

[Next page](https://discuss.elastic.co/tag/none.md?no_tags=true&page=511)
