# \#none

**URL:** https://discuss.elastic.co/tag/none.md?no_tags=true&page=540

[Latest](https://discuss.elastic.co/latest.md) · [Categories](https://discuss.elastic.co/categories.md) · [Tags](https://discuss.elastic.co/tags.md)

**Page:** 541

---

## [Ingest Lag or Pipeline not working?](https://discuss.elastic.co/t/ingest-lag-or-pipeline-not-working/314148)

<div class="topic-metadata">

**Author:** [@Ely\_96](https://discuss.elastic.co/u/Ely_96)\
**Replies:** 5\
**Last updated:** [September 12, 2022, 1:02pm UTC](https://discuss.elastic.co/t/ingest-lag-or-pipeline-not-working/314148 "2022-09-12T13:02:31Z")

</div>

Hi guys, I have a doubt my pipelines. I have 2 pipelines to see (in Kibana) the most recent requests within a platform. Each request is a json that has a couple of fields and: req-id req-timestamp My pipelines: T…

---

## [Analytics-Discover not displaying data](https://discuss.elastic.co/t/analytics-discover-not-displaying-data/313997)

<div class="topic-metadata">

**Author:** [@el-jefe3](https://discuss.elastic.co/u/el-jefe3)\
**Replies:** 3\
**Last updated:** [September 12, 2022, 12:37pm UTC](https://discuss.elastic.co/t/analytics-discover-not-displaying-data/313997 "2022-09-12T12:37:55Z")

</div>

Analytics - Discover is no longer displaying data that is ingested. I could see the data in Observability under stream but can't seem to figure out what would cause the data to not appear in the Analytics - Discover. D…

---

## [Automatically Kibana Login](https://discuss.elastic.co/t/automatically-kibana-login/313940)

<div class="topic-metadata">

**Author:** [@Irwan\_Kurniawan](https://discuss.elastic.co/u/Irwan_Kurniawan)\
**Replies:** 7\
**Last updated:** [September 12, 2022, 12:21pm UTC](https://discuss.elastic.co/t/automatically-kibana-login/313940 "2022-09-12T12:21:36Z")

</div>

I have login page on my own website. How can I pass the login information from my own website to Kibana login so the user no need to login twice?

---

## [How to set priority and how to ignore some words in search query](https://discuss.elastic.co/t/how-to-set-priority-and-how-to-ignore-some-words-in-search-query/314193)

<div class="topic-metadata">

**Author:** [@Fakeknox](https://discuss.elastic.co/u/Fakeknox)\
**Replies:** 0\
**Last updated:** [September 12, 2022, 12:10pm UTC](https://discuss.elastic.co/t/how-to-set-priority-and-how-to-ignore-some-words-in-search-query/314193 "2022-09-12T12:10:38Z")

</div>

hello in our database we have title brands , categories , attribute and ... i want to set some priority for search for example we want to search blue jacket jacket is our category and blue is our attribute how can we …

---

## [Performance... what is faster using 1 or 2 keyword field in term search?](https://discuss.elastic.co/t/performance-what-is-faster-using-1-or-2-keyword-field-in-term-search/314185)

<div class="topic-metadata">

**Author:** [@kk123](https://discuss.elastic.co/u/kk123)\
**Replies:** 0\
**Last updated:** [September 12, 2022, 10:41am UTC](https://discuss.elastic.co/t/performance-what-is-faster-using-1-or-2-keyword-field-in-term-search/314185 "2022-09-12T10:41:29Z")

</div>

Hi, I have ILM based indices that have multiple keyword fields. I want query the data based on these terms. As it turns out, the two keyword fields have the following property... Keyword2 is unique across the all Keywo…

---

## [Cluster\_health rule \[missing replica shards\] too much susceptible](https://discuss.elastic.co/t/cluster-health-rule-missing-replica-shards-too-much-susceptible/314183)

<div class="topic-metadata">

**Author:** [@rschirin](https://discuss.elastic.co/u/rschirin)\
**Replies:** 0\
**Last updated:** [September 12, 2022, 10:35am UTC](https://discuss.elastic.co/t/cluster-health-rule-missing-replica-shards-too-much-susceptible/314183 "2022-09-12T10:35:11Z")

</div>

Hey there, I have a 7.17 ES cluster with the embedded infrastructure rules & alerts enabled and the usage of ILM for specific kind of indices. I have enabled the "Cluster\_health" rule and I saw that when my ILM policy …

---

## [Java Upgrade doesn't stop elasticsearch. Why?](https://discuss.elastic.co/t/java-upgrade-doesnt-stop-elasticsearch-why/314179)

<div class="topic-metadata">

**Author:** [@Divit\_Sharma](https://discuss.elastic.co/u/Divit_Sharma)\
**Replies:** 1\
**Last updated:** [September 12, 2022, 10:13am UTC](https://discuss.elastic.co/t/java-upgrade-doesnt-stop-elasticsearch-why/314179 "2022-09-12T10:13:19Z")

</div>

I am using external JDK on Oracle Linux 7.9. Elasticsearch service is up and running when I upgrade the java. Also, there are no entries in log. I am not sure about this behavior. Elasticsearch uses ES\_JAVA\_HOME=/usr/bi…

---

## [Does sorting by \_doc remain consistent during paging](https://discuss.elastic.co/t/does-sorting-by-doc-remain-consistent-during-paging/314178)

<div class="topic-metadata">

**Author:** [@daniel-kr](https://discuss.elastic.co/u/daniel-kr)\
**Replies:** 0\
**Last updated:** [September 12, 2022, 9:48am UTC](https://discuss.elastic.co/t/does-sorting-by-doc-remain-consistent-during-paging/314178 "2022-09-12T09:48:08Z")

</div>

Hey, I want to page through my search results by using the parameters from and size (no scrolling or search after API with PIT involved). I don't care about the sort order of the whole result set. Therefore, I sort by \_…

---

## [Add client role to existing master node](https://discuss.elastic.co/t/add-client-role-to-existing-master-node/313666)

<div class="topic-metadata">

**Author:** [@tahseen\_fatima](https://discuss.elastic.co/u/tahseen_fatima)\
**Replies:** 4\
**Last updated:** [September 12, 2022, 9:19am UTC](https://discuss.elastic.co/t/add-client-role-to-existing-master-node/313666 "2022-09-12T09:19:08Z")

</div>

Hi Experts, I have 2 elasticsearch(7.16.2) monitoring cluster with 3 master + data eligible roles. I want enabling CCR between them, I am following document for doing this integration. CCR Link I have run the below c…

---

## [Benefit of Snapshot/Restore vs. raw data collection?](https://discuss.elastic.co/t/benefit-of-snapshot-restore-vs-raw-data-collection/314163)

<div class="topic-metadata">

**Author:** [@azeiner](https://discuss.elastic.co/u/azeiner)\
**Replies:** 4\
**Last updated:** [September 12, 2022, 8:28am UTC](https://discuss.elastic.co/t/benefit-of-snapshot-restore-vs-raw-data-collection/314163 "2022-09-12T08:28:18Z")

</div>

I've got a general question about datamanagement in elastic - we're running a couple of on-premise clusters and the data we produce are mostly from textfiles or are generated in various systems, collected in Redis from w…

---

## [Export Transactions](https://discuss.elastic.co/t/export-transactions/314113)

<div class="topic-metadata">

**Author:** [@ahmedakkaya](https://discuss.elastic.co/u/ahmedakkaya)\
**Replies:** 4\
**Last updated:** [September 12, 2022, 8:24am UTC](https://discuss.elastic.co/t/export-transactions/314113 "2022-09-12T08:24:13Z")

</div>

hello my original file; #!/bin/bash export PATH=/usr/local/sbin:/usr/local/bin:/usr/sbin:/usr/bin:/sbin:/bin:/snap/bin if \[ -z "$1" \]; then ADAYAGO=\`date --date="1 day ago" +%Y-%m-%d\` else ADAYAGO="$1…

---

## [Kibana Visulization Stats](https://discuss.elastic.co/t/kibana-visulization-stats/313999)

<div class="topic-metadata">

**Author:** [@krishns4](https://discuss.elastic.co/u/krishns4)\
**Replies:** 2\
**Last updated:** [September 12, 2022, 7:37am UTC](https://discuss.elastic.co/t/kibana-visulization-stats/313999 "2022-09-12T07:37:18Z")

</div>

Hi All, I was wondering if we have any way to find out what all fields from the logs in Elasticseach are referenced in a given visualization in kibana ? Thanks

---

## [Best way to reindex text to keyword](https://discuss.elastic.co/t/best-way-to-reindex-text-to-keyword/314119)

<div class="topic-metadata">

**Author:** [@Mark\_S](https://discuss.elastic.co/u/Mark_S)\
**Replies:** 2\
**Last updated:** [September 12, 2022, 6:35am UTC](https://discuss.elastic.co/t/best-way-to-reindex-text-to-keyword/314119 "2022-09-12T06:35:20Z")

</div>

I want to re-index a text field to keyword. I have multiple indices (myindex-000001, myindex-000002, etc) In order to reindex I must: a) get the mapping b) create a new index mynewindex-000001 same field name but diffe…

---

## [How get the \_source data when the \_source is disabled?](https://discuss.elastic.co/t/how-get-the-source-data-when-the-source-is-disabled/314160)

<div class="topic-metadata">

**Author:** [@Sarthak\_Agarwal](https://discuss.elastic.co/u/Sarthak_Agarwal)\
**Replies:** 2\
**Last updated:** [September 12, 2022, 6:07am UTC](https://discuss.elastic.co/t/how-get-the-source-data-when-the-source-is-disabled/314160 "2022-09-12T06:07:47Z")

</div>

I have one index whose \_source is disabled. Now I want to migrate data from this index to a different elasticsearch cluster ? The issue is I only get metadata fields while searching. How can I retrieve and transfer \_sour…

---

## [How to switch between multiple ES cluster from local kibana](https://discuss.elastic.co/t/how-to-switch-between-multiple-es-cluster-from-local-kibana/314081)

<div class="topic-metadata">

**Author:** [@pkv1982](https://discuss.elastic.co/u/pkv1982)\
**Replies:** 2\
**Last updated:** [September 12, 2022, 2:35am UTC](https://discuss.elastic.co/t/how-to-switch-between-multiple-es-cluster-from-local-kibana/314081 "2022-09-12T02:35:27Z")

</div>

is there a way to switch between multiple remote ES cluster from my local kibana? any documentation would be helpful.

---

## [ICU Analysis Plugin doesn't normalize some characters like other languages(PHP, Python)](https://discuss.elastic.co/t/icu-analysis-plugin-doesnt-normalize-some-characters-like-other-languages-php-python/314155)

<div class="topic-metadata">

**Author:** [@mictsai](https://discuss.elastic.co/u/mictsai)\
**Replies:** 0\
**Last updated:** [September 12, 2022, 2:15am UTC](https://discuss.elastic.co/t/icu-analysis-plugin-doesnt-normalize-some-characters-like-other-languages-php-python/314155 "2022-09-12T02:15:43Z")

</div>

Elasticsearch version: 7.10.1 Installed plugins: \[analysis-icu, analysis-kuromoji, analysis-nori\] 그래비티 and 그래비티 looks the same. When encoding to URL, 그래비티 is %EA%B7%B8%EB%9E%98%EB%B9%84%ED%8B%B0%20 and 그래비티 is …

---

## [Can we have 800 synonym in single synonym.txt file](https://discuss.elastic.co/t/can-we-have-800-synonym-in-single-synonym-txt-file/314150)

<div class="topic-metadata">

**Author:** [@pavithra\_arul](https://discuss.elastic.co/u/pavithra_arul)\
**Replies:** 1\
**Last updated:** [September 12, 2022, 1:52am UTC](https://discuss.elastic.co/t/can-we-have-800-synonym-in-single-synonym-txt-file/314150 "2022-09-12T01:52:34Z")

</div>

Hi Team, Need help Urgent ! I'm trying to add 800 synonym via synonym.txt file in elasticsearch. file got uploaded to server but results are not getting fetched. PFB for the seetings and mapping PUT synonym\_sample\_upd…

---

## [Grok date filter problem with french timestamp](https://discuss.elastic.co/t/grok-date-filter-problem-with-french-timestamp/314151)

<div class="topic-metadata">

**Author:** [@marwen](https://discuss.elastic.co/u/marwen)\
**Replies:** 4\
**Last updated:** [September 12, 2022, 12:13am UTC](https://discuss.elastic.co/t/grok-date-filter-problem-with-french-timestamp/314151 "2022-09-12T00:13:15Z")

</div>

good day everyone, using elastic stack 17.7.5 I'm parsing log events to logstash the problem is date filter not working with my logs (catalina) here is example: avr. 23, 2022 1:46:19 PM org.apache.coyote.AbstractProtoc…

---

## [Labs - Kibana server is not ready yet](https://discuss.elastic.co/t/labs-kibana-server-is-not-ready-yet/314147)

<div class="topic-metadata">

**Author:** [@allenangel82](https://discuss.elastic.co/u/allenangel82)\
**Replies:** 1\
**Last updated:** [September 11, 2022, 6:10pm UTC](https://discuss.elastic.co/t/labs-kibana-server-is-not-ready-yet/314147 "2022-09-11T18:10:54Z")

</div>

I am working on the Elastic Security Fundamentals: SIEM On-Demand lab, and I am having trouble getting Kibana to load. When I try to access the link the lab provided for Kibana, I receive a blank page with the text "Kib…

---

## [How to grok those multiline log syntax?](https://discuss.elastic.co/t/how-to-grok-those-multiline-log-syntax/314118)

<div class="topic-metadata">

**Author:** [@cowderwelsh](https://discuss.elastic.co/u/cowderwelsh)\
**Replies:** 2\
**Last updated:** [September 10, 2022, 7:33pm UTC](https://discuss.elastic.co/t/how-to-grok-those-multiline-log-syntax/314118 "2022-09-10T19:33:02Z")

</div>

Hi, I'm new to Elastic and after creating my first pipeline, I'm now trying to process a simple, local multiline Firewall log, it looks like this: Time: 01/28/2022 01:27:22 Event: Traffic IP-Address: 20.199.120.85 …

---

## [Subtract timestamps from logs basis a field and show as a view on dashboard](https://discuss.elastic.co/t/subtract-timestamps-from-logs-basis-a-field-and-show-as-a-view-on-dashboard/314116)

<div class="topic-metadata">

**Author:** [@Murali\_Y](https://discuss.elastic.co/u/Murali_Y)\
**Replies:** 1\
**Last updated:** [September 10, 2022, 7:25pm UTC](https://discuss.elastic.co/t/subtract-timestamps-from-logs-basis-a-field-and-show-as-a-view-on-dashboard/314116 "2022-09-10T19:25:48Z")

</div>

Hello all, My logs are having below 2 entries: @timestamp:Sep 10, 2022 @ 20:11:42.677 fingerprint:2222-605819443b6 Item\_Name:069931601477 jobId:4444-ff-4555 level:Info levelOrdinal:2 logF\_BusinessProcessName:Test logTy…

---

## [Kibana dashboard vs discover (top 5 values)](https://discuss.elastic.co/t/kibana-dashboard-vs-discover-top-5-values/314072)

<div class="topic-metadata">

**Author:** [@Mark\_S](https://discuss.elastic.co/u/Mark_S)\
**Replies:** 2\
**Last updated:** [September 10, 2022, 4:38pm UTC](https://discuss.elastic.co/t/kibana-dashboard-vs-discover-top-5-values/314072 "2022-09-10T16:38:35Z")

</div>

When using the "discover" mode, I hover over a text field and I can easily see the top 5 values. However when trying to create a dashboard showing exactly the same thing, I cannot find a way to do so since "a text field…

---

## [Error parsing csv](https://discuss.elastic.co/t/error-parsing-csv/314099)

<div class="topic-metadata">

**Author:** [@manuel.urbano](https://discuss.elastic.co/u/manuel.urbano)\
**Replies:** 11\
**Last updated:** [September 10, 2022, 4:06pm UTC](https://discuss.elastic.co/t/error-parsing-csv/314099 "2022-09-10T16:06:35Z")

</div>

Hi, I'm reading a CSV file and sending it to Elasticsearch, everything works fine but some rows are throwing an exception: Error parsing csv {:field=\>"message", :source=\>"6123464a-420f-4838-8ecb-fcce87f16297;20878376219…

---

## [Query to return documents with id not in a list](https://discuss.elastic.co/t/query-to-return-documents-with-id-not-in-a-list/314114)

<div class="topic-metadata">

**Author:** [@Ivo\_Tavares](https://discuss.elastic.co/u/Ivo_Tavares)\
**Replies:** 0\
**Last updated:** [September 10, 2022, 2:15pm UTC](https://discuss.elastic.co/t/query-to-return-documents-with-id-not-in-a-list/314114 "2022-09-10T14:15:28Z")

</div>

I'm trying to create a query, but I don't want the query to return documents which have already been fetched in a previous query. Here's the JSON {'query': {'bool': {'filter': \[{'term': {'tag': 'name'}}, {'bool': {…

---

## [Indexing html as raw content](https://discuss.elastic.co/t/indexing-html-as-raw-content/313990)

<div class="topic-metadata">

**Author:** [@pcyber](https://discuss.elastic.co/u/pcyber)\
**Replies:** 2\
**Last updated:** [September 10, 2022, 10:28am UTC](https://discuss.elastic.co/t/indexing-html-as-raw-content/313990 "2022-09-10T10:28:45Z")

</div>

hi folks, i´m realy new to Elasticsearch and trying to use it for my project. what i want to to in simple form: get html source from website with python push the source to Elasticsearch make it searchable so i´m get…

---

## [Saving document selection on table in dashboard session](https://discuss.elastic.co/t/saving-document-selection-on-table-in-dashboard-session/314067)

<div class="topic-metadata">

**Author:** [@Mike42](https://discuss.elastic.co/u/Mike42)\
**Replies:** 1\
**Last updated:** [September 9, 2022, 7:55pm UTC](https://discuss.elastic.co/t/saving-document-selection-on-table-in-dashboard-session/314067 "2022-09-09T19:55:26Z")

</div>

Hi, into a dashboard I included a table to list filtered documents. Well, this works as expected. I could also save my filters in a session, and further show just selected documents in a table (part of a dashboard), perf…

---

## [Can you filter on top ranked inner nested hit in same query](https://discuss.elastic.co/t/can-you-filter-on-top-ranked-inner-nested-hit-in-same-query/314085)

<div class="topic-metadata">

**Author:** [@chimauwah](https://discuss.elastic.co/u/chimauwah)\
**Replies:** 0\
**Last updated:** [September 9, 2022, 7:35pm UTC](https://discuss.elastic.co/t/can-you-filter-on-top-ranked-inner-nested-hit-in-same-query/314085 "2022-09-09T19:35:13Z")

</div>

Cheers all! Let's say I have a mapping with a nested object like this: { "APP\_APPLICATION\_ID": { "type": "long" }, "APP\_FNAME": { "type": "text", "fields": { "raw": { "type": "keyword" …

---

## [Single quotes makes MySQL statement invalid using jdbc\_streaming filter](https://discuss.elastic.co/t/single-quotes-makes-mysql-statement-invalid-using-jdbc-streaming-filter/314078)

<div class="topic-metadata">

**Author:** [@roeeklinger](https://discuss.elastic.co/u/roeeklinger)\
**Replies:** 0\
**Last updated:** [September 9, 2022, 4:39pm UTC](https://discuss.elastic.co/t/single-quotes-makes-mysql-statement-invalid-using-jdbc-streaming-filter/314078 "2022-09-09T16:39:48Z")

</div>

Hello, I am trying to use the jdbc\_streaming filter with a regexp statement, like this: jdbc\_streaming { jdbc\_driver\_library =\> "/usr/share/logstash/jdbc\_drivers/mysql-connector-java-8.0.30.jar" jdbc\_driver\_…

---

## [XML - Illegal Argument Exception](https://discuss.elastic.co/t/xml-illegal-argument-exception/313704)

<div class="topic-metadata">

**Author:** [@hnf](https://discuss.elastic.co/u/hnf)\
**Replies:** 9\
**Last updated:** [September 9, 2022, 4:17pm UTC](https://discuss.elastic.co/t/xml-illegal-argument-exception/313704 "2022-09-09T16:17:40Z")

</div>

Hello Everyone, I'm unable to dissect my xml file. I'm getting some error of "error"=\>{"type"=\>"illegal\_argument\_exception", "reason"=\>"mapper \[CELL\] cannot be changed from type \[text\] to \[ObjectMapper\]"}. Please find b…

---

## [LogStash Next Step](https://discuss.elastic.co/t/logstash-next-step/313927)

<div class="topic-metadata">

**Author:** [@Technolust](https://discuss.elastic.co/u/Technolust)\
**Replies:** 11\
**Last updated:** [September 9, 2022, 4:01pm UTC](https://discuss.elastic.co/t/logstash-next-step/313927 "2022-09-09T16:01:17Z")

</div>

Team, I'm not sure what I'm missing or I have broken here. I have an Elastic Server, Kibana Server, and Logstash Server. Elastic and Kibana are working. I'v setup one cisco switch to send logs to logstash and setup logs…

[Previous page](https://discuss.elastic.co/tag/none.md?no_tags=true&page=539)

[Next page](https://discuss.elastic.co/tag/none.md?no_tags=true&page=541)
