# \#none

**URL:** https://discuss.elastic.co/tag/none.md?no_tags=true&page=539

[Latest](https://discuss.elastic.co/latest.md) · [Categories](https://discuss.elastic.co/categories.md) · [Tags](https://discuss.elastic.co/tags.md)

**Page:** 540

---

## [Kibana 8.4.1 TSVB group by function not working correctly](https://discuss.elastic.co/t/kibana-8-4-1-tsvb-group-by-function-not-working-correctly/314208)

<div class="topic-metadata">

**Author:** [@schmittberger](https://discuss.elastic.co/u/schmittberger)\
**Replies:** 2\
**Last updated:** [September 13, 2022, 8:43am UTC](https://discuss.elastic.co/t/kibana-8-4-1-tsvb-group-by-function-not-working-correctly/314208 "2022-09-13T08:43:51Z")

</div>

Hello, I am trying to visualize the network input and output data rates that are received using the system module of metricbeat - for multiple hosts - in kibana. I am using the predefined TSVB visualization of metricbeat…

---

## [Configuring logstash to connect to Oracle AQ (JMS) without a web server](https://discuss.elastic.co/t/configuring-logstash-to-connect-to-oracle-aq-jms-without-a-web-server/314266)

<div class="topic-metadata">

**Author:** [@ztine77](https://discuss.elastic.co/u/ztine77)\
**Replies:** 0\
**Last updated:** [September 13, 2022, 8:35am UTC](https://discuss.elastic.co/t/configuring-logstash-to-connect-to-oracle-aq-jms-without-a-web-server/314266 "2022-09-13T08:35:30Z")

</div>

I use dockerized version of logstash and would like to use Oracle AQ as an input. This is my ./pipeline/logstash.conf file: input { jms { broker\_url =\> 'jdbc:oracle:thin:@server:1521:sid' destination =\> 'MYQ…

---

## [Kibana server is not ready yet](https://discuss.elastic.co/t/kibana-server-is-not-ready-yet/314247)

<div class="topic-metadata">

**Author:** [@khanchand](https://discuss.elastic.co/u/khanchand)\
**Replies:** 1\
**Last updated:** [September 13, 2022, 7:52am UTC](https://discuss.elastic.co/t/kibana-server-is-not-ready-yet/314247 "2022-09-13T07:52:30Z")

</div>

Hi everyone, I am new on Elasticsearch and have created my lab before going to deploy in production. For lab purpose I have deployed all three (elasticsearch, kibana & logstash) on a single centos server. While I am faci…

---

## [Some values in the field is String, some is Integer, though Mapping is Integer](https://discuss.elastic.co/t/some-values-in-the-field-is-string-some-is-integer-though-mapping-is-integer/314253)

<div class="topic-metadata">

**Author:** [@Abhishek\_Soni1](https://discuss.elastic.co/u/Abhishek_Soni1)\
**Replies:** 2\
**Last updated:** [September 13, 2022, 7:52am UTC](https://discuss.elastic.co/t/some-values-in-the-field-is-string-some-is-integer-though-mapping-is-integer/314253 "2022-09-13T07:52:17Z")

</div>

I have created a schema config, where I have mapped "Total Number of Changes" field to "Integer". But I can see the values are both number, and string. I have also tried re-indexing but results are same. How can I deal …

---

## [Kibana 8.4.1 columns of saved search in dashboard cannot be changed](https://discuss.elastic.co/t/kibana-8-4-1-columns-of-saved-search-in-dashboard-cannot-be-changed/314142)

<div class="topic-metadata">

**Author:** [@bertr](https://discuss.elastic.co/u/bertr)\
**Replies:** 2\
**Last updated:** [September 13, 2022, 7:47am UTC](https://discuss.elastic.co/t/kibana-8-4-1-columns-of-saved-search-in-dashboard-cannot-be-changed/314142 "2022-09-13T07:47:32Z")

</div>

When a saved search from discover is added to a dashboard, the columns from the saved search are shown (which is good). When trying to add or remove columns in the dashboard panel the columns are not added or removed, so…

---

## [ES version range comparision is not working as expected semantic version comparison](https://discuss.elastic.co/t/es-version-range-comparision-is-not-working-as-expected-semantic-version-comparison/312904)

<div class="topic-metadata">

**Author:** [@Krishna\_Sailesh](https://discuss.elastic.co/u/Krishna_Sailesh)\
**Replies:** 7\
**Last updated:** [September 13, 2022, 7:30am UTC](https://discuss.elastic.co/t/es-version-range-comparision-is-not-working-as-expected-semantic-version-comparison/312904 "2022-09-13T07:30:31Z")

</div>

Hi Folks I have a version mapping field data type with the property name "softwareVersion" in the Elasticsearch index. I have "softwareVersion" property values like Z100, Z300, 6.7, 7.0(3)I7(3), and 6.8.9 when I searc…

---

## [Saved Visualizations from Discover](https://discuss.elastic.co/t/saved-visualizations-from-discover/312795)

<div class="topic-metadata">

**Author:** [@tepus](https://discuss.elastic.co/u/tepus)\
**Replies:** 5\
**Last updated:** [September 13, 2022, 7:28am UTC](https://discuss.elastic.co/t/saved-visualizations-from-discover/312795 "2022-09-13T07:28:48Z")

</div>

Dear Elastic Community, One customer is using Discover to search their logs. Sometimes they create a very specific query by which they obtain some interesting results. They would like to visualize them with one of the e…

---

## [How to take children filed while use sql query it's parent?](https://discuss.elastic.co/t/how-to-take-children-filed-while-use-sql-query-its-parent/314251)

<div class="topic-metadata">

**Author:** [@robocon20x](https://discuss.elastic.co/u/robocon20x)\
**Replies:** 0\
**Last updated:** [September 13, 2022, 7:03am UTC](https://discuss.elastic.co/t/how-to-take-children-filed-while-use-sql-query-its-parent/314251 "2022-09-13T07:03:10Z")

</div>

i everyone, i have an parent child index with format like this parent\_child ES doc. "customer\_segment": { "type": "join", "eager\_global\_ordinals": true, "relations": { "customer": …

---

## [After provide time format I get; (elastic: Error 400 (Bad Request): all shards failed \[type=search\_phase\_execution\_exception\] ) error](https://discuss.elastic.co/t/after-provide-time-format-i-get-elastic-error-400-bad-request-all-shards-failed-type-search-phase-execution-exception-error/314243)

<div class="topic-metadata">

**Author:** [@golofetuk](https://discuss.elastic.co/u/golofetuk)\
**Replies:** 1\
**Last updated:** [September 13, 2022, 7:18am UTC](https://discuss.elastic.co/t/after-provide-time-format-i-get-elastic-error-400-bad-request-all-shards-failed-type-search-phase-execution-exception-error/314243 "2022-09-13T07:18:44Z")

</div>

Please use the following questions as a guideline to help me answer your issue/question without further inquiry. Thank you. Which version of Elastic are you using? \[ v\] elastic.v7 (for Elasticsearch 7.x) Please descri…

---

## [Kibana logs](https://discuss.elastic.co/t/kibana-logs/312915)

<div class="topic-metadata">

**Author:** [@irivas95](https://discuss.elastic.co/u/irivas95)\
**Replies:** 8\
**Last updated:** [September 13, 2022, 7:03am UTC](https://discuss.elastic.co/t/kibana-logs/312915 "2022-09-13T07:03:51Z")

</div>

Hi, I have been trying for a while to configure a logrotate file to rotate my kibana logs(version 7.16.3),without success. I need my logs to rotate daily and delete logs older than 7 days. The configuration file I am us…

---

## [How to do Bulk API iteration from JSON lines using Python?](https://discuss.elastic.co/t/how-to-do-bulk-api-iteration-from-json-lines-using-python/314218)

<div class="topic-metadata">

**Author:** [@Ramu\_Kakaji](https://discuss.elastic.co/u/Ramu_Kakaji)\
**Replies:** 0\
**Last updated:** [September 12, 2022, 6:11pm UTC](https://discuss.elastic.co/t/how-to-do-bulk-api-iteration-from-json-lines-using-python/314218 "2022-09-12T18:11:33Z")

</div>

Hi All, i have json data like this json\_data = { "title": "Rush", "year": 2013, "budget":500000, "earning":300000,"genere":"action"} { "title": "Jurrasic", "year": 2014,"budget":1500000, "earning":2300000,"genere":"ac…

---

## [Elasticsearch 7 // Log4j configuration SocketAppender](https://discuss.elastic.co/t/elasticsearch-7-log4j-configuration-socketappender/314249)

<div class="topic-metadata">

**Author:** [@CrKontrol](https://discuss.elastic.co/u/CrKontrol)\
**Replies:** 0\
**Last updated:** [September 13, 2022, 6:44am UTC](https://discuss.elastic.co/t/elasticsearch-7-log4j-configuration-socketappender/314249 "2022-09-13T06:44:50Z")

</div>

Hello, I'm using Elasticsearch 7.17 under basic licence with the security features. Since Elasticsearch does not support syslog appender on log4j anymore (still the case ?), i'm trying to use SocketAppender but it seem…

---

## [Hardware requirements - good resilency - Elastic 8.4](https://discuss.elastic.co/t/hardware-requirements-good-resilency-elastic-8-4/314090)

<div class="topic-metadata">

**Author:** [@elkstack1](https://discuss.elastic.co/u/elkstack1)\
**Replies:** 4\
**Last updated:** [September 13, 2022, 4:23am UTC](https://discuss.elastic.co/t/hardware-requirements-good-resilency-elastic-8-4/314090 "2022-09-13T04:23:42Z")

</div>

I would like the hardware requirements for good resiliency - Elastic 8.4 I looked on the documentation and didnt find any info pertaining to hardware specs. We currently have 3 master nodes and 17 data nodes - 13 warm …

---

## [Query hostname field with zero hit count](https://discuss.elastic.co/t/query-hostname-field-with-zero-hit-count/314240)

<div class="topic-metadata">

**Author:** [@lchan](https://discuss.elastic.co/u/lchan)\
**Replies:** 0\
**Last updated:** [September 13, 2022, 2:47am UTC](https://discuss.elastic.co/t/query-hostname-field-with-zero-hit-count/314240 "2022-09-13T02:47:22Z")

</div>

Hi all, I am trying to write a watcher alert if any host hostname.keyword has a 0 hit count in the last 1d. This has asked numerous times but most of them is circulating around entire indices, not for the host field. A…

---

## [WIFI NIC Blocked by Elastic Agent](https://discuss.elastic.co/t/wifi-nic-blocked-by-elastic-agent/314030)

<div class="topic-metadata">

**Author:** [@xqaiviwjxzw](https://discuss.elastic.co/u/xqaiviwjxzw)\
**Replies:** 2\
**Last updated:** [September 13, 2022, 2:29am UTC](https://discuss.elastic.co/t/wifi-nic-blocked-by-elastic-agent/314030 "2022-09-13T02:29:01Z")

</div>

I have installed elastic agent on my windoes 10, but the wifi NIC is not working and I can't connect to wifi, but I uninstalled elastic agent and the wifi NIC is working and the wifi is working, what is the reason for th…

---

## [Logstash high CPU](https://discuss.elastic.co/t/logstash-high-cpu/314238)

<div class="topic-metadata">

**Author:** [@jpeppard](https://discuss.elastic.co/u/jpeppard)\
**Replies:** 6\
**Last updated:** [September 13, 2022, 1:30am UTC](https://discuss.elastic.co/t/logstash-high-cpu/314238 "2022-09-13T01:30:18Z")

</div>

Hi all. Just installed ELKstack v8.4.1 on ubuntu server 20 to play around with. All is well with the data itself, Metricbeat is sending data to Elasticsearch from two other Ubuntu server machines. Visualizations and dat…

---

## [Certified Analyst practice exam issues](https://discuss.elastic.co/t/certified-analyst-practice-exam-issues/314217)

<div class="topic-metadata">

**Author:** [@Baron](https://discuss.elastic.co/u/Baron)\
**Replies:** 1\
**Last updated:** [September 12, 2022, 8:32pm UTC](https://discuss.elastic.co/t/certified-analyst-practice-exam-issues/314217 "2022-09-12T20:32:54Z")

</div>

Hi, I'm having the same issue as described in the topic linked below. I cannot access any of the data in the user\_messages or raw-logs (which I assume is supposed to be used in the place of the apachelogs\* index in the …

---

## [Cannot access Pet Clinic application in the Strigo Lab](https://discuss.elastic.co/t/cannot-access-pet-clinic-application-in-the-strigo-lab/313600)

<div class="topic-metadata">

**Author:** [@timmo](https://discuss.elastic.co/u/timmo)\
**Replies:** 5\
**Last updated:** [September 12, 2022, 8:27pm UTC](https://discuss.elastic.co/t/cannot-access-pet-clinic-application-in-the-strigo-lab/313600 "2022-09-12T20:27:44Z")

</div>

Hi, I have started taking the Elasticsearch Observability Engineer (On-Demand) course. I managed to reach lab 3.3 (Collecting APM data) and suddenly cannot access Pet Clinic application. How can I restart the Pet Clini…

---

## [Unable to perform Fuzzy search for search query template](https://discuss.elastic.co/t/unable-to-perform-fuzzy-search-for-search-query-template/314226)

<div class="topic-metadata">

**Author:** [@pratikshatiwari](https://discuss.elastic.co/u/pratikshatiwari)\
**Replies:** 0\
**Last updated:** [September 12, 2022, 8:07pm UTC](https://discuss.elastic.co/t/unable-to-perform-fuzzy-search-for-search-query-template/314226 "2022-09-12T20:07:50Z")

</div>

Hello Team I am trying to create search query template to allow fuzzy search to search even incomplete values from field, After following the elastic document tried to create search query but it is not working. Using b…

---

## [There is insufficient memory for the Java Runtime Environment to continue](https://discuss.elastic.co/t/there-is-insufficient-memory-for-the-java-runtime-environment-to-continue/313926)

<div class="topic-metadata">

**Author:** [@Akhil2](https://discuss.elastic.co/u/Akhil2)\
**Replies:** 7\
**Last updated:** [September 12, 2022, 8:01pm UTC](https://discuss.elastic.co/t/there-is-insufficient-memory-for-the-java-runtime-environment-to-continue/313926 "2022-09-12T20:01:10Z")

</div>

Hello all, I am using ELK 8.4.1. I have a cluster setup with 3 nodes. But when I tried to Ingest data through Logstash it gave me following errors. OpenJDK 64-Bit Server VM warning: INFO: os::commit\_memory(0x00000000c…

---

## [Apache Error Logs Not Parsing Correctly](https://discuss.elastic.co/t/apache-error-logs-not-parsing-correctly/314211)

<div class="topic-metadata">

**Author:** [@Loc\_Tran](https://discuss.elastic.co/u/Loc_Tran)\
**Replies:** 0\
**Last updated:** [September 12, 2022, 5:39pm UTC](https://discuss.elastic.co/t/apache-error-logs-not-parsing-correctly/314211 "2022-09-12T17:39:30Z")

</div>

I'm not able to parse the apache error logs. I keep getting these errors: \[0\] "\_grokparsefailure" which means that there's an error in parsing the logs. Apache Error Logs \[Wed Aug 17 20:00:00.661037 2022\] \[proxy:err…

---

## [How to display @timestamp as Horizontal axis on kibana](https://discuss.elastic.co/t/how-to-display-timestamp-as-horizontal-axis-on-kibana/314165)

<div class="topic-metadata">

**Author:** [@amir\_Bialek](https://discuss.elastic.co/u/amir_Bialek)\
**Replies:** 1\
**Last updated:** [September 12, 2022, 4:22pm UTC](https://discuss.elastic.co/t/how-to-display-timestamp-as-horizontal-axis-on-kibana/314165 "2022-09-12T16:22:36Z")

</div>

Hey, trying to set @timestamp as Horizontal axis on kibana does not display anything, see here: Under 'discover' The logs include timestamp: @timestamp:Sep 8, 2022 @ 18:46:27.235 @timestamp:Sep 8, 2022 @ 18:37:53.9…

---

## [How to search for a bracket using simple\_query\_string?](https://discuss.elastic.co/t/how-to-search-for-a-bracket-using-simple-query-string/314096)

<div class="topic-metadata">

**Author:** [@reisner](https://discuss.elastic.co/u/reisner)\
**Replies:** 4\
**Last updated:** [September 12, 2022, 4:14pm UTC](https://discuss.elastic.co/t/how-to-search-for-a-bracket-using-simple-query-string/314096 "2022-09-12T16:14:33Z")

</div>

I'm trying to search for documents that contain a bracket in the text using simple\_query\_string. The documentation here says that "To use one of these characters literally, escape it with a preceding backslash ()." Howe…

---

## [LOGSTASH Using different input index than the one specified](https://discuss.elastic.co/t/logstash-using-different-input-index-than-the-one-specified/314139)

<div class="topic-metadata">

**Author:** [@Moshe\_Sharon1](https://discuss.elastic.co/u/Moshe_Sharon1)\
**Replies:** 3\
**Last updated:** [September 12, 2022, 4:03pm UTC](https://discuss.elastic.co/t/logstash-using-different-input-index-than-the-one-specified/314139 "2022-09-12T16:03:54Z")

</div>

In logstash configuration file I set input to use "my \_indsex" as input and "result" as output after restarting logstash I found that the output have documents from another configuration input index ׳׳׳ input { elast…

---

## [Error parsing xml with XmlSimple / UndefinedNamespaceException: undefined prefix log4j found](https://discuss.elastic.co/t/error-parsing-xml-with-xmlsimple-undefinednamespaceexception-undefined-prefix-log4j-found/314097)

<div class="topic-metadata">

**Author:** [@erwin339](https://discuss.elastic.co/u/erwin339)\
**Replies:** 2\
**Last updated:** [September 12, 2022, 3:07pm UTC](https://discuss.elastic.co/t/error-parsing-xml-with-xmlsimple-undefinednamespaceexception-undefined-prefix-log4j-found/314097 "2022-09-12T15:07:09Z")

</div>

I am working with local filebeat and logstash and elasticsearch and kibana on a server. I need to convert the information that comes to me from the logs from xml to json. My configuration works when it reads a file with …

---

## [Data Streams vs "Traditionally" Elastic Indexes](https://discuss.elastic.co/t/data-streams-vs-traditionally-elastic-indexes/313980)

<div class="topic-metadata">

**Author:** [@huowen](https://discuss.elastic.co/u/huowen)\
**Replies:** 6\
**Last updated:** [September 12, 2022, 3:03pm UTC](https://discuss.elastic.co/t/data-streams-vs-traditionally-elastic-indexes/313980 "2022-09-12T15:03:21Z")

</div>

I have recently upgraded my ELK stack and deployed in a kubernetes cluster and wanted to optimise the way I'm using it. Use Case: Many developer teams push their logs to a logstash pipeline which then outputs into elas…

---

## [Unexpected pod restart after operator upgrade to 2.3](https://discuss.elastic.co/t/unexpected-pod-restart-after-operator-upgrade-to-2-3/314202)

<div class="topic-metadata">

**Author:** [@pup\_seba](https://discuss.elastic.co/u/pup_seba)\
**Replies:** 0\
**Last updated:** [September 12, 2022, 2:51pm UTC](https://discuss.elastic.co/t/unexpected-pod-restart-after-operator-upgrade-to-2-3/314202 "2022-09-12T14:51:17Z")

</div>

Hi, According to documentation, updating our current ECK operator from version 2.2 to 2.3 should have gone without operated pods being restarted. From our operated elasticsearch clusters running in this k8s cluster, 1 w…

---

## [Comment parser un fichier log avec grok](https://discuss.elastic.co/t/comment-parser-un-fichier-log-avec-grok/314166)

<div class="topic-metadata">

**Author:** [@dataslayer](https://discuss.elastic.co/u/dataslayer)\
**Replies:** 2\
**Last updated:** [September 12, 2022, 2:50pm UTC](https://discuss.elastic.co/t/comment-parser-un-fichier-log-avec-grok/314166 "2022-09-12T14:50:03Z")

</div>

Bonjour, Je souhaite que logstash récupère les champs "création", "modification" et "suppression" avec les lignes "Nb traitements", "dont crees" et "dont rejetes" mais je ne sais pas comment m'y prendre avec grok même e…

---

## [Logstash error : invalid setting for elasticsearch output plugin](https://discuss.elastic.co/t/logstash-error-invalid-setting-for-elasticsearch-output-plugin/314196)

<div class="topic-metadata">

**Author:** [@sirineb](https://discuss.elastic.co/u/sirineb)\
**Replies:** 2\
**Last updated:** [September 12, 2022, 1:50pm UTC](https://discuss.elastic.co/t/logstash-error-invalid-setting-for-elasticsearch-output-plugin/314196 "2022-09-12T13:50:41Z")

</div>

Hi, I have two pipeline configurations located in /etc/logstash/conf.d. I can make work both seperately by running /usr/share/logstash/bin/logstash -f /etc/logstash/conf.d/\*\*.conf -r, and it sends data to elasticsearch …

---

## [Check if index value is substring of input string](https://discuss.elastic.co/t/check-if-index-value-is-substring-of-input-string/314191)

<div class="topic-metadata">

**Author:** [@rahulkothanath](https://discuss.elastic.co/u/rahulkothanath)\
**Replies:** 2\
**Last updated:** [September 12, 2022, 1:24pm UTC](https://discuss.elastic.co/t/check-if-index-value-is-substring-of-input-string/314191 "2022-09-12T13:24:27Z")

</div>

I have an index with field and value like(ES\_VAL: AMERICAN EXPRESS), I want to check if the entire ES\_VAL is substring of an input string(eg: CANADA AMERICAN EXPRESS). this is reverse of normal substring operation as w…

[Previous page](https://discuss.elastic.co/tag/none.md?no_tags=true&page=538)

[Next page](https://discuss.elastic.co/tag/none.md?no_tags=true&page=540)
