# \#none

**URL:** https://discuss.elastic.co/tag/none.md?no_tags=true&page=512

[Latest](https://discuss.elastic.co/latest.md) · [Categories](https://discuss.elastic.co/categories.md) · [Tags](https://discuss.elastic.co/tags.md)

**Page:** 513

---

## [How to find the percentage for any query success?](https://discuss.elastic.co/t/how-to-find-the-percentage-for-any-query-success/317194)

<div class="topic-metadata">

**Author:** [@HemabhRavee](https://discuss.elastic.co/u/HemabhRavee)\
**Replies:** 1\
**Last updated:** [October 24, 2022, 12:38pm UTC](https://discuss.elastic.co/t/how-to-find-the-percentage-for-any-query-success/317194 "2022-10-24T12:38:21Z")

</div>

I want to write an aggregation which returns the percentage of hits for any query Let say I have a query Q which returns me 20 docs out of the 100 present in the target index. Then that aggregation should return me 20%…

---

## [Filter vs query](https://discuss.elastic.co/t/filter-vs-query/317297)

<div class="topic-metadata">

**Author:** [@Ismet](https://discuss.elastic.co/u/Ismet)\
**Replies:** 1\
**Last updated:** [October 24, 2022, 12:20pm UTC](https://discuss.elastic.co/t/filter-vs-query/317297 "2022-10-24T12:20:52Z")

</div>

Hi, can we use only filter without query and can we use query string with wildcard in filter. What are benefits of using only filter and using query string + filter? There is example of using only filter. Is this code o…

---

## [Grab everything upto a specific word](https://discuss.elastic.co/t/grab-everything-upto-a-specific-word/317280)

<div class="topic-metadata">

**Author:** [@Rajeev\_Shrestha](https://discuss.elastic.co/u/Rajeev_Shrestha)\
**Replies:** 5\
**Last updated:** [October 24, 2022, 12:19pm UTC](https://discuss.elastic.co/t/grab-everything-upto-a-specific-word/317280 "2022-10-24T12:19:02Z")

</div>

Hi Guys, I am new to GROK and appreciate your help. The goal is to put everything leading up to the word 'user-agent' to a fieldname "details" and everything after "user-agent" to a fieldname "user-agent". The excerpt…

---

## [Add index\_options option to all text fields with dynamic templates](https://discuss.elastic.co/t/add-index-options-option-to-all-text-fields-with-dynamic-templates/317303)

<div class="topic-metadata">

**Author:** [@frank\_esg](https://discuss.elastic.co/u/frank_esg)\
**Replies:** 0\
**Last updated:** [October 24, 2022, 9:21am UTC](https://discuss.elastic.co/t/add-index-options-option-to-all-text-fields-with-dynamic-templates/317303 "2022-10-24T09:21:55Z")

</div>

Hello, we´re using component templates to define field mappings based on ECS for all of our indices. In the past we had some issues with search highlighting in Kibana , when text fields are very big. Now i would like t…

---

## [Kibana 8.4.2 new Control does not show options for runtime field](https://discuss.elastic.co/t/kibana-8-4-2-new-control-does-not-show-options-for-runtime-field/315015)

<div class="topic-metadata">

**Author:** [@Jonas\_S](https://discuss.elastic.co/u/Jonas_S)\
**Replies:** 7\
**Last updated:** [October 24, 2022, 8:18am UTC](https://discuss.elastic.co/t/kibana-8-4-2-new-control-does-not-show-options-for-runtime-field/315015 "2022-10-24T08:18:44Z")

</div>

Hello, i upgraded to the newest Kibana version to use the new Controls. I have a runtime field in my Data View that gets a value from the indexname: It can be used in all visualizations without problems. I tried to …

---

## [Indexes created automatically by the system](https://discuss.elastic.co/t/indexes-created-automatically-by-the-system/317125)

<div class="topic-metadata">

**Author:** [@dpelaezb](https://discuss.elastic.co/u/dpelaezb)\
**Replies:** 4\
**Last updated:** [October 24, 2022, 7:47am UTC](https://discuss.elastic.co/t/indexes-created-automatically-by-the-system/317125 "2022-10-24T07:47:40Z")

</div>

Hello everyone, We have an infrastructure that consists of several Filebeats that send the traces to a Logstash located on another machine where there is also a Metricbeat to plot Logstash. We have detected that a seri…

---

## [Impact of CVE-2022-42889 on Elastic stack](https://discuss.elastic.co/t/impact-of-cve-2022-42889-on-elastic-stack/316858)

<div class="topic-metadata">

**Author:** [@jgimenez](https://discuss.elastic.co/u/jgimenez)\
**Replies:** 4\
**Last updated:** [October 24, 2022, 7:28am UTC](https://discuss.elastic.co/t/impact-of-cve-2022-42889-on-elastic-stack/316858 "2022-10-24T07:28:56Z")

</div>

Hi there, is the Elastic software affected by CVE-2022-42889, and if so, what are the actions recommended? Thanks.

---

## [How to push json into elasticsearch](https://discuss.elastic.co/t/how-to-push-json-into-elasticsearch/317275)

<div class="topic-metadata">

**Author:** [@ZahraZare](https://discuss.elastic.co/u/ZahraZare)\
**Replies:** 11\
**Last updated:** [October 24, 2022, 5:41am UTC](https://discuss.elastic.co/t/how-to-push-json-into-elasticsearch/317275 "2022-10-24T05:41:12Z")

</div>

I want to push the following Json data using Python in elasticsearch, I used the following code but there is no data in the index. json data : \[ "break", false, -1314177328.9280925, \[ -107585784.0005331, 11732320…

---

## [I can't get Elastic and Kibana to work with real certificates](https://discuss.elastic.co/t/i-cant-get-elastic-and-kibana-to-work-with-real-certificates/317282)

<div class="topic-metadata">

**Author:** [@abkrim](https://discuss.elastic.co/u/abkrim)\
**Replies:** 5\
**Last updated:** [October 24, 2022, 5:23am UTC](https://discuss.elastic.co/t/i-cant-get-elastic-and-kibana-to-work-with-real-certificates/317282 "2022-10-24T05:23:35Z")

</div>

I can't get Elastic and Kibana to work with real certificates from either Let's encrypt or Comodo. I've thought about it a thousand times, but no matter how much I read and reread, I can't find the error of something as…

---

## [Can I know the basic specifications for master, ingest, coordinate node?](https://discuss.elastic.co/t/can-i-know-the-basic-specifications-for-master-ingest-coordinate-node/317289)

<div class="topic-metadata">

**Author:** [@dms6978](https://discuss.elastic.co/u/dms6978)\
**Replies:** 2\
**Last updated:** [October 24, 2022, 2:00am UTC](https://discuss.elastic.co/t/can-i-know-the-basic-specifications-for-master-ingest-coordinate-node/317289 "2022-10-24T02:00:36Z")

</div>

Can I know the basic specifications for master, ingest, coordinate node? CPU, memory, heapsize.....

---

## [Can't Automatically Start Elasticsearch Service After Upgrade to 8.4.3](https://discuss.elastic.co/t/cant-automatically-start-elasticsearch-service-after-upgrade-to-8-4-3/317262)

<div class="topic-metadata">

**Author:** [@krmathieu](https://discuss.elastic.co/u/krmathieu)\
**Replies:** 1\
**Last updated:** [October 24, 2022, 1:25am UTC](https://discuss.elastic.co/t/cant-automatically-start-elasticsearch-service-after-upgrade-to-8-4-3/317262 "2022-10-24T01:25:40Z")

</div>

I can't get the Elasticsearch service to start using the Windows service on a Windows 10 machine after upgrading to 8.4.3.. I successfully used elasticsearch-service.bat to install the service and see it listed as an ava…

---

## [REGION MAP VISUALIZATION DOES NOT LOADING INITIALLY](https://discuss.elastic.co/t/region-map-visualization-does-not-loading-initially/316787)

<div class="topic-metadata">

**Author:** [@Sinchana\_P](https://discuss.elastic.co/u/Sinchana_P)\
**Replies:** 2\
**Last updated:** [October 24, 2022, 1:21am UTC](https://discuss.elastic.co/t/region-map-visualization-does-not-loading-initially/316787 "2022-10-24T01:21:12Z")

</div>

The region map does not load fully in the initial view. Initially, the region map dashboard is shown grey without loading any data in it as shown in the image below: Once page is reloaded or refresh button is clicked…

---

## [Delete Duplicate id documents in Search Result](https://discuss.elastic.co/t/delete-duplicate-id-documents-in-search-result/317190)

<div class="topic-metadata">

**Author:** [@manupoti](https://discuss.elastic.co/u/manupoti)\
**Replies:** 1\
**Last updated:** [October 23, 2022, 11:14pm UTC](https://discuss.elastic.co/t/delete-duplicate-id-documents-in-search-result/317190 "2022-10-23T23:14:11Z")

</div>

1.Created two indexes and with same alias name 2.Inseart document with \_id in "doc1" index with alias 3.Insert same document with same \_id in "doc2" with alias 4.Search with \_id and Search result should return only on…

---

## [Pattern: grok/mutate dont work?](https://discuss.elastic.co/t/pattern-grok-mutate-dont-work/317212)

<div class="topic-metadata">

**Author:** [@kurdit](https://discuss.elastic.co/u/kurdit)\
**Replies:** 9\
**Last updated:** [October 23, 2022, 10:59pm UTC](https://discuss.elastic.co/t/pattern-grok-mutate-dont-work/317212 "2022-10-23T22:59:40Z")

</div>

hi all! i ran into a problem. i have a pipeline: input { tcp { host =\> "10.10.10.10" port =\> "5959" codec =\> "json" type =\> "my\_type" mode =\> "server" } } filter { if \[…

---

## [Throw error when doc id already exists in index with NEST](https://discuss.elastic.co/t/throw-error-when-doc-id-already-exists-in-index-with-nest/317283)

<div class="topic-metadata">

**Author:** [@johanwallenborg](https://discuss.elastic.co/u/johanwallenborg)\
**Replies:** 2\
**Last updated:** [October 23, 2022, 7:29pm UTC](https://discuss.elastic.co/t/throw-error-when-doc-id-already-exists-in-index-with-nest/317283 "2022-10-23T19:29:37Z")

</div>

Hello, I'm using BulkAll-method when indexing documents. Everything works fine but I wonder if there's a way too report back if an document with same document id already exists in index. Is there any?

---

## [Replace empty field with a meaning word](https://discuss.elastic.co/t/replace-empty-field-with-a-meaning-word/317266)

<div class="topic-metadata">

**Author:** [@Roger\_Huang](https://discuss.elastic.co/u/Roger_Huang)\
**Replies:** 3\
**Last updated:** [October 23, 2022, 4:23pm UTC](https://discuss.elastic.co/t/replace-empty-field-with-a-meaning-word/317266 "2022-10-23T16:23:53Z")

</div>

Hi everyone, I am trying to replace empty fields instead of %{} So i used this code: if ! \[xxevent.fw\_app\_id\] { mutate { update =\> { "xxevent.fw\_app\_id" =\> "EMPTY" } } } …

---

## [ERROR: Failed to determine the health of the cluster when initial password setting](https://discuss.elastic.co/t/error-failed-to-determine-the-health-of-the-cluster-when-initial-password-setting/317252)

<div class="topic-metadata">

**Author:** [@tmdgk490255](https://discuss.elastic.co/u/tmdgk490255)\
**Replies:** 5\
**Last updated:** [October 23, 2022, 3:31pm UTC](https://discuss.elastic.co/t/error-failed-to-determine-the-health-of-the-cluster-when-initial-password-setting/317252 "2022-10-23T15:31:45Z")

</div>

I tried to set up initial password with following command and got this error message $ ./elasticsearch-reset-password -u elasticsearch ERROR: Failed to determine the health of the cluster. Here is my elasticsearch.ym…

---

## [Module system syslog logs of Filebeat and auditbeat](https://discuss.elastic.co/t/module-system-syslog-logs-of-filebeat-and-auditbeat/317250)

<div class="topic-metadata">

**Author:** [@morad\_della3](https://discuss.elastic.co/u/morad_della3)\
**Replies:** 1\
**Last updated:** [October 22, 2022, 4:29pm UTC](https://discuss.elastic.co/t/module-system-syslog-logs-of-filebeat-and-auditbeat/317250 "2022-10-22T16:29:56Z")

</div>

Difference btween module system syslog logs of Filebeat and auditbeat the two collect the linux logs ?

---

## [Proposed way to use Elasticsearch Java API Client to generate requests](https://discuss.elastic.co/t/proposed-way-to-use-elasticsearch-java-api-client-to-generate-requests/317239)

<div class="topic-metadata">

**Author:** [@Michael\_Gattinger](https://discuss.elastic.co/u/Michael_Gattinger)\
**Replies:** 0\
**Last updated:** [October 22, 2022, 5:37am UTC](https://discuss.elastic.co/t/proposed-way-to-use-elasticsearch-java-api-client-to-generate-requests/317239 "2022-10-22T05:37:00Z")

</div>

Hello, as i found for my self there are a bunch of ways how to use Elasticsearch Java API Client to generate requests. write JSON (in file or programm code) and push it over the low level Rest Client instead of the ES…

---

## [Provision ECK - no pods are created](https://discuss.elastic.co/t/provision-eck-no-pods-are-created/317094)

<div class="topic-metadata">

**Author:** [@charlot\_Attard](https://discuss.elastic.co/u/charlot_Attard)\
**Replies:** 1\
**Last updated:** [October 22, 2022, 8:40am UTC](https://discuss.elastic.co/t/provision-eck-no-pods-are-created/317094 "2022-10-22T08:40:43Z")

</div>

Hello, I am trying to provision an ECK cluster, after I create the Elasticsearch operator, no pods or statefulset are created. I cannot view any logs. kubectl describe elasticsearch (name) does not give me any events. I…

---

## [Index by hostname?](https://discuss.elastic.co/t/index-by-hostname/317187)

<div class="topic-metadata">

**Author:** [@Nikolas1306](https://discuss.elastic.co/u/Nikolas1306)\
**Replies:** 2\
**Last updated:** [October 22, 2022, 7:14am UTC](https://discuss.elastic.co/t/index-by-hostname/317187 "2022-10-22T07:14:25Z")

</div>

elasticsearch { hosts =\> \["localhost:9200"\] index =\> "logstash-%{\[host\]\[hostname\]}%{+YYYY.MM.dd}" } but have

---

## [Logstash convert single quoted json log to double quoted](https://discuss.elastic.co/t/logstash-convert-single-quoted-json-log-to-double-quoted/317164)

<div class="topic-metadata">

**Author:** [@babuzrb](https://discuss.elastic.co/u/babuzrb)\
**Replies:** 4\
**Last updated:** [October 22, 2022, 3:40am UTC](https://discuss.elastic.co/t/logstash-convert-single-quoted-json-log-to-double-quoted/317164 "2022-10-22T03:40:05Z")

</div>

Hi I have log files with multiple json lines. Each json has single quotes and some of the values do not even has any quote. Due to this single quote and absence of quote issue, I cannot index them to elasticsearch. Thro…

---

## [HTTP Poller \[API\] input in Logstash - Does it support "Request\_data" on top of "Headers"?](https://discuss.elastic.co/t/http-poller-api-input-in-logstash-does-it-support-request-data-on-top-of-headers/316327)

<div class="topic-metadata">

**Author:** [@Roger\_Huang](https://discuss.elastic.co/u/Roger_Huang)\
**Replies:** 34\
**Last updated:** [October 22, 2022, 2:33am UTC](https://discuss.elastic.co/t/http-poller-api-input-in-logstash-does-it-support-request-data-on-top-of-headers/316327 "2022-10-22T02:33:41Z")

</div>

Hi everyone, I am new to ELK and I am trying to pull JSON data from Palo Alto platform into Logstash for processing. Some info redacted as xxxx. API DOCS: Get Alerts Does Logstash support such http headers? input …

---

## [I want to delete my account here. How do I remove or disable my account?](https://discuss.elastic.co/t/i-want-to-delete-my-account-here-how-do-i-remove-or-disable-my-account/317218)

<div class="topic-metadata">

**Author:** [@anon65617794](https://discuss.elastic.co/u/anon65617794)\
**Replies:** 3\
**Last updated:** [October 22, 2022, 1:39am UTC](https://discuss.elastic.co/t/i-want-to-delete-my-account-here-how-do-i-remove-or-disable-my-account/317218 "2022-10-22T01:39:19Z")

</div>

I want to delete my account here. How do I remove or disable my account?

---

## [.kibana index failed](https://discuss.elastic.co/t/kibana-index-failed/316948)

<div class="topic-metadata">

**Author:** [@Harper\_S1](https://discuss.elastic.co/u/Harper_S1)\
**Replies:** 8\
**Last updated:** [October 21, 2022, 5:56pm UTC](https://discuss.elastic.co/t/kibana-index-failed/316948 "2022-10-21T17:56:42Z")

</div>

hi, could someone please advise on this. 2022-10-19T04:16:31.786+00:00\]\[INFO \]\[savedobjects-service\] Waiting until all Elasticsearch nodes are compatible with Kibana before starting saved objects migrations... \[2022-10…

---

## [Max number of Spaces and Roles in Kibana](https://discuss.elastic.co/t/max-number-of-spaces-and-roles-in-kibana/316933)

<div class="topic-metadata">

**Author:** [@tifty](https://discuss.elastic.co/u/tifty)\
**Replies:** 2\
**Last updated:** [October 21, 2022, 5:00pm UTC](https://discuss.elastic.co/t/max-number-of-spaces-and-roles-in-kibana/316933 "2022-10-21T17:00:22Z")

</div>

Hi everyone, Is there a max limit to consider for creating Spaces and Roles in Kibana. Moreover, should I worry about cluster performance if I keep increasing number of spaces. Thanks

---

## [Delete document in read only Index](https://discuss.elastic.co/t/delete-document-in-read-only-index/317199)

<div class="topic-metadata">

**Author:** [@manupoti](https://discuss.elastic.co/u/manupoti)\
**Replies:** 1\
**Last updated:** [October 21, 2022, 4:33pm UTC](https://discuss.elastic.co/t/delete-document-in-read-only-index/317199 "2022-10-21T16:33:16Z")

</div>

I have two indexes leader index support read write operations and follower index support read operation only but need to delete document in follower index, How can we delete the documents from follower index? Please hel…

---

## [Logstash is blocked by elasticsearch-setup-passwords](https://discuss.elastic.co/t/logstash-is-blocked-by-elasticsearch-setup-passwords/317142)

<div class="topic-metadata">

**Author:** [@Nikolas1306](https://discuss.elastic.co/u/Nikolas1306)\
**Replies:** 19\
**Last updated:** [October 21, 2022, 1:34pm UTC](https://discuss.elastic.co/t/logstash-is-blocked-by-elasticsearch-setup-passwords/317142 "2022-10-21T13:34:26Z")

</div>

this a very bad procedure i have used this command for create password for kibana elasticsearch-setup-passwords but logstash is non started

---

## [Elastic Cases events trigger an external SOAR](https://discuss.elastic.co/t/elastic-cases-events-trigger-an-external-soar/316999)

<div class="topic-metadata">

**Author:** [@yzaritskyi](https://discuss.elastic.co/u/yzaritskyi)\
**Replies:** 3\
**Last updated:** [October 21, 2022, 1:08pm UTC](https://discuss.elastic.co/t/elastic-cases-events-trigger-an-external-soar/316999 "2022-10-21T13:08:43Z")

</div>

Hey all! I have a big question for you guys. Does anybody know about the opportunity to trigger an external API from the Elastic Case? I mean, Is there a way to implement some webhook or index in elastic that could col…

---

## [Reconfigure to default \`max\_num\_segments\`](https://discuss.elastic.co/t/reconfigure-to-default-max-num-segments/317186)

<div class="topic-metadata">

**Author:** [@yago82](https://discuss.elastic.co/u/yago82)\
**Replies:** 1\
**Last updated:** [October 21, 2022, 10:37am UTC](https://discuss.elastic.co/t/reconfigure-to-default-max-num-segments/317186 "2022-10-21T10:37:27Z")

</div>

Hi, according documentation: max\_num\_segments (Optional, integer) The number of segments to merge to. To fully merge indices, set it to 1. Defaults to checking if a merge needs to execute. If so, executes it. Once d…

[Previous page](https://discuss.elastic.co/tag/none.md?no_tags=true&page=511)

[Next page](https://discuss.elastic.co/tag/none.md?no_tags=true&page=513)
