# \#none

**URL:** https://discuss.elastic.co/tag/none.md?no_tags=true&page=554

[Latest](https://discuss.elastic.co/latest.md) · [Categories](https://discuss.elastic.co/categories.md) · [Tags](https://discuss.elastic.co/tags.md)

**Page:** 555

---

## [Needs to drop audit beat data](https://discuss.elastic.co/t/needs-to-drop-audit-beat-data/312676)

<div class="topic-metadata">

**Author:** [@rajvel](https://discuss.elastic.co/u/rajvel)\
**Replies:** 1\
**Last updated:** [August 25, 2022, 4:08am UTC](https://discuss.elastic.co/t/needs-to-drop-audit-beat-data/312676 "2022-08-25T04:08:49Z")

</div>

Hello Team, Have configured the auditbeat with file integraity module to capture the folder/file date and time change. In the same server have configured the filebeat to capture the application logs. both beats output…

---

## [Is the MACOS AARCH64 installation package for the MACOS m1 chip system?](https://discuss.elastic.co/t/is-the-macos-aarch64-installation-package-for-the-macos-m1-chip-system/312862)

<div class="topic-metadata">

**Author:** [@xqaiviwjxzw](https://discuss.elastic.co/u/xqaiviwjxzw)\
**Replies:** 0\
**Last updated:** [August 25, 2022, 2:02am UTC](https://discuss.elastic.co/t/is-the-macos-aarch64-installation-package-for-the-macos-m1-chip-system/312862 "2022-08-25T02:02:16Z")

</div>

Is the MACOS AARCH64 installation package for the MACOS m1 chip system? MACOS AARCH64

---

## [I want to take the Certified Analyst exam this week](https://discuss.elastic.co/t/i-want-to-take-the-certified-analyst-exam-this-week/312864)

<div class="topic-metadata">

**Author:** [@Yoggi22r](https://discuss.elastic.co/u/Yoggi22r)\
**Replies:** 0\
**Last updated:** [August 25, 2022, 2:34am UTC](https://discuss.elastic.co/t/i-want-to-take-the-certified-analyst-exam-this-week/312864 "2022-08-25T02:34:46Z")

</div>

How can i be best prepared? Text version? Practice exams? Whats new? Inquiring minds wanna know!

---

## [How to setup a single node cluster for Elasticsearch 8.3 on Windows 10 on a laptop?](https://discuss.elastic.co/t/how-to-setup-a-single-node-cluster-for-elasticsearch-8-3-on-windows-10-on-a-laptop/312530)

<div class="topic-metadata">

**Author:** [@JamesD\_7](https://discuss.elastic.co/u/JamesD_7)\
**Replies:** 13\
**Last updated:** [August 25, 2022, 12:54am UTC](https://discuss.elastic.co/t/how-to-setup-a-single-node-cluster-for-elasticsearch-8-3-on-windows-10-on-a-laptop/312530 "2022-08-25T00:54:07Z")

</div>

Hello All, I downloaded Elasticsearch 8.3 and Kibana 8.3 and I've run into lots of questions and issues about setting up a simple configuration to read a small CSV file. After running into some errors I started chang…

---

## [How to custom sort](https://discuss.elastic.co/t/how-to-custom-sort/312838)

<div class="topic-metadata">

**Author:** [@Guilherme\_Mello](https://discuss.elastic.co/u/Guilherme_Mello)\
**Replies:** 1\
**Last updated:** [August 24, 2022, 10:30pm UTC](https://discuss.elastic.co/t/how-to-custom-sort/312838 "2022-08-24T22:30:25Z")

</div>

Hello. I'm building a retail search. This search needs to give priority to products from certain stores (they pay to be more relevant). The roducts from these stores need to appear more frequently in the search. I'm …

---

## [Is it possible to let elasticsearch choose the index to ingest](https://discuss.elastic.co/t/is-it-possible-to-let-elasticsearch-choose-the-index-to-ingest/312343)

<div class="topic-metadata">

**Author:** [@asp](https://discuss.elastic.co/u/asp)\
**Replies:** 3\
**Last updated:** [August 24, 2022, 9:20pm UTC](https://discuss.elastic.co/t/is-it-possible-to-let-elasticsearch-choose-the-index-to-ingest/312343 "2022-08-24T21:20:04Z")

</div>

Hi, we want to distribute / split out data to different indexes, because based on the type of the data we will have different retention times. In my last project I used logstash to parse and enrich log events and calcu…

---

## [How to call variables?](https://discuss.elastic.co/t/how-to-call-variables/312809)

<div class="topic-metadata">

**Author:** [@ToonKnight](https://discuss.elastic.co/u/ToonKnight)\
**Replies:** 0\
**Last updated:** [August 24, 2022, 12:22pm UTC](https://discuss.elastic.co/t/how-to-call-variables/312809 "2022-08-24T12:22:39Z")

</div>

Hey all, I made a script that would create a jew index, as soon as the currently running one reaches a space limit. I can't share the script but basically, I have two variables at the start that is could newindex and r…

---

## [\[warn \]\[logstash.config.source.multilocal\] ignoring the 'pipelines.yml' file because modules or command line options are specified](https://discuss.elastic.co/t/warn-logstash-config-source-multilocal-ignoring-the-pipelines-yml-file-because-modules-or-command-line-options-are-specified/312836)

<div class="topic-metadata">

**Author:** [@Vitoria\_De\_Lara](https://discuss.elastic.co/u/Vitoria_De_Lara)\
**Replies:** 0\
**Last updated:** [August 24, 2022, 6:38pm UTC](https://discuss.elastic.co/t/warn-logstash-config-source-multilocal-ignoring-the-pipelines-yml-file-because-modules-or-command-line-options-are-specified/312836 "2022-08-24T18:38:36Z")

</div>

input { file { path =\> "/tmp/spreadsheet\_data.csv" start\_position =\> "beginning" sincedb\_path =\> "/dev/null" } } filter { csv { separator =\> "," skip\_header =\> "true" columns =\> \['Name','Class','Dorm','Room','…

---

## [Query Option Similar to Vega Flatten Transform](https://discuss.elastic.co/t/query-option-similar-to-vega-flatten-transform/312835)

<div class="topic-metadata">

**Author:** [@LisaJ](https://discuss.elastic.co/u/LisaJ)\
**Replies:** 0\
**Last updated:** [August 24, 2022, 6:08pm UTC](https://discuss.elastic.co/t/query-option-similar-to-vega-flatten-transform/312835 "2022-08-24T18:08:18Z")

</div>

When using the Vega visualization engine to graph data, I use the flatten transform to turn a single document that contains an array of length n into n documents with a single element from the array. From: To: Thi…

---

## [Time intervals on x-axis](https://discuss.elastic.co/t/time-intervals-on-x-axis/312001)

<div class="topic-metadata">

**Author:** [@Sayali\_Gangodak](https://discuss.elastic.co/u/Sayali_Gangodak)\
**Replies:** 3\
**Last updated:** [August 24, 2022, 4:42pm UTC](https://discuss.elastic.co/t/time-intervals-on-x-axis/312001 "2022-08-24T16:42:53Z")

</div>

Hi, I am using elastic ui charts to plot a custom timeline graph. On x-axis I want to display time range which will change dynamically according to to timepicker selected by user on dashboard . I am able to plot time fo…

---

## [LogStash::ConfigurationError", :message=\>"Expected one of \[ \\\\t\\\\r\\\\n\], \\"#\\", \\"if\\", \[A-Za-z0-9\_-\], '\\"', \\"'\\", \\"}\\"](https://discuss.elastic.co/t/logstash-configurationerror-message-expected-one-of-t-r-n-if-a-za-z0-9/312402)

<div class="topic-metadata">

**Author:** [@Queren\_Santos](https://discuss.elastic.co/u/Queren_Santos)\
**Replies:** 12\
**Last updated:** [August 24, 2022, 3:33pm UTC](https://discuss.elastic.co/t/logstash-configurationerror-message-expected-one-of-t-r-n-if-a-za-z0-9/312402 "2022-08-24T15:33:18Z")

</div>

I'm having trouble understanding my code configuration error. Shows the following message when trying to run the logs and their settings: \[ERROR\]\[logstash.agent\] Failed to execute action {:action=\>LogStash::PipelineActi…

---

## [MongoDB (5+, json based) : some objects have variable types](https://discuss.elastic.co/t/mongodb-5-json-based-some-objects-have-variable-types/312445)

<div class="topic-metadata">

**Author:** [@LaBonave](https://discuss.elastic.co/u/LaBonave)\
**Replies:** 3\
**Last updated:** [August 24, 2022, 2:30pm UTC](https://discuss.elastic.co/t/mongodb-5-json-based-some-objects-have-variable-types/312445 "2022-08-24T14:30:51Z")

</div>

Hi (new here) I've successfully managed to send all of our mongodb 5 instances (JSON-based) logs, via filebeat, on a Logstash instance. MongoDB 5+ are JSON-based logs (https://www.mongodb.com/docs/manual/reference/log…

---

## [Logstash - Grok Syntax Issues](https://discuss.elastic.co/t/logstash-grok-syntax-issues/312807)

<div class="topic-metadata">

**Author:** [@RaiZiStyle](https://discuss.elastic.co/u/RaiZiStyle)\
**Replies:** 6\
**Last updated:** [August 24, 2022, 2:17pm UTC](https://discuss.elastic.co/t/logstash-grok-syntax-issues/312807 "2022-08-24T14:17:25Z")

</div>

I'm using filebeat to send log to logstash but I'm having issues with grok syntax on Logstash. I used the grok debugger on Kibanna and manager to come to a solution. The problem is that I can't find the same syntax for …

---

## [In Kibana need to graph average of the max value of a fieldA within a group keyed by fieldB over time](https://discuss.elastic.co/t/in-kibana-need-to-graph-average-of-the-max-value-of-a-fielda-within-a-group-keyed-by-fieldb-over-time/312819)

<div class="topic-metadata">

**Author:** [@jenrem](https://discuss.elastic.co/u/jenrem)\
**Replies:** 0\
**Last updated:** [August 24, 2022, 1:50pm UTC](https://discuss.elastic.co/t/in-kibana-need-to-graph-average-of-the-max-value-of-a-fielda-within-a-group-keyed-by-fieldb-over-time/312819 "2022-08-24T13:50:19Z")

</div>

I have an index that includes a field called session and a field called timeOnSite. The data can include several docs for each session. The highest value of timeOnSite for a given session is the session duration. I ha…

---

## [Cluster uuid different after cluster migration](https://discuss.elastic.co/t/cluster-uuid-different-after-cluster-migration/312640)

<div class="topic-metadata">

**Author:** [@Thomas\_Boutelier](https://discuss.elastic.co/u/Thomas_Boutelier)\
**Replies:** 3\
**Last updated:** [August 24, 2022, 12:56pm UTC](https://discuss.elastic.co/t/cluster-uuid-different-after-cluster-migration/312640 "2022-08-24T12:56:44Z")

</div>

Hello everybody, I performed a cluster migration; I've recreated a kubernetes cluster and reattached the existing elasticsearch ebs volumes (with all datas). When I recreated the Elastic manifest, it generated a cluste…

---

## [Elasticsearch and Kibana 8.3.3 basic setup not working in Azure Kubernetes](https://discuss.elastic.co/t/elasticsearch-and-kibana-8-3-3-basic-setup-not-working-in-azure-kubernetes/312032)

<div class="topic-metadata">

**Author:** [@levitoh123](https://discuss.elastic.co/u/levitoh123)\
**Replies:** 2\
**Last updated:** [August 24, 2022, 12:48pm UTC](https://discuss.elastic.co/t/elasticsearch-and-kibana-8-3-3-basic-setup-not-working-in-azure-kubernetes/312032 "2022-08-24T12:48:53Z")

</div>

Hi, I have installed ECK with the CRDS 2.3.0 (from the main documentation) and proceeded to install elasticsearch and kibana via the manifests provided in the documentation. After deploying the Kibana logs, I am seeing …

---

## [ECK Operator Error - Cannot parse Elasticsearch error response body](https://discuss.elastic.co/t/eck-operator-error-cannot-parse-elasticsearch-error-response-body/312675)

<div class="topic-metadata">

**Author:** [@x00m](https://discuss.elastic.co/u/x00m)\
**Replies:** 1\
**Last updated:** [August 24, 2022, 12:36pm UTC](https://discuss.elastic.co/t/eck-operator-error-cannot-parse-elasticsearch-error-response-body/312675 "2022-08-24T12:36:24Z")

</div>

I get this error with ECK 2.3.0 with elasticsearch 7.16.2 08-16-2022 12:05:48 Cannot parse Elasticsearch error response body elasticsearch-client {"message":"Cannot parse Elasticsearch error response body","namespace":n…

---

## [ECK Operator - Leader Election Lost causes Restart](https://discuss.elastic.co/t/eck-operator-leader-election-lost-causes-restart/312677)

<div class="topic-metadata">

**Author:** [@x00m](https://discuss.elastic.co/u/x00m)\
**Replies:** 1\
**Last updated:** [August 24, 2022, 12:33pm UTC](https://discuss.elastic.co/t/eck-operator-leader-election-lost-causes-restart/312677 "2022-08-24T12:33:20Z")

</div>

Using Fresh ECK setup v2.3.0 in Azure Kubernetes Service. Elasticsearch version 7.16.2 Getting these errors consistently across multiple ECK setups, which causes pod restart. (Replica for eck-operator = 1 only) E0820 …

---

## [Data split into multiple Documents](https://discuss.elastic.co/t/data-split-into-multiple-documents/312808)

<div class="topic-metadata">

**Author:** [@Maruthappan\_Muthu](https://discuss.elastic.co/u/Maruthappan_Muthu)\
**Replies:** 1\
**Last updated:** [August 24, 2022, 12:24pm UTC](https://discuss.elastic.co/t/data-split-into-multiple-documents/312808 "2022-08-24T12:24:13Z")

</div>

I am writing the Prometheus collected metrics into Elasticsearch for every 2 minutes. I see multiple documents for a single data collection and each documents has different fields. Is this the way Elasticsearch stores th…

---

## [Search as you type with 100k rows, help scoring](https://discuss.elastic.co/t/search-as-you-type-with-100k-rows-help-scoring/312412)

<div class="topic-metadata">

**Author:** [@samtwilliams](https://discuss.elastic.co/u/samtwilliams)\
**Replies:** 2\
**Last updated:** [August 24, 2022, 11:59am UTC](https://discuss.elastic.co/t/search-as-you-type-with-100k-rows-help-scoring/312412 "2022-08-24T11:59:47Z")

</div>

Hi All, I have an index that contains drug names (100k of them),I'm using a react front end to search as you type which is working quite well except the scoring coming back is not what I expect despite endless fiddling. …

---

## [Print arabic characters in logstash](https://discuss.elastic.co/t/print-arabic-characters-in-logstash/312793)

<div class="topic-metadata">

**Author:** [@Didi\_Sisi](https://discuss.elastic.co/u/Didi_Sisi)\
**Replies:** 0\
**Last updated:** [August 24, 2022, 10:31am UTC](https://discuss.elastic.co/t/print-arabic-characters-in-logstash/312793 "2022-08-24T10:31:52Z")

</div>

Hello, I created a python script which gathers tweets using “Tweepy”. Then, I return each tweet in a certain dict format. My tweets may contain arabic and latin caracters. This is my python script: import tweepy impor…

---

## [Add a new field in all the existing documents in ES](https://discuss.elastic.co/t/add-a-new-field-in-all-the-existing-documents-in-es/312739)

<div class="topic-metadata">

**Author:** [@ImranArif](https://discuss.elastic.co/u/ImranArif)\
**Replies:** 2\
**Last updated:** [August 24, 2022, 10:22am UTC](https://discuss.elastic.co/t/add-a-new-field-in-all-the-existing-documents-in-es/312739 "2022-08-24T10:22:25Z")

</div>

Hi, I want to update existing documents by adding a new field, the value of which will be looked up from a csv file hosted on an external path (ftp, probably). I read about the translate filter that can be used to look …

---

## [Kibana login page logo customization in version 8.x](https://discuss.elastic.co/t/kibana-login-page-logo-customization-in-version-8-x/312789)

<div class="topic-metadata">

**Author:** [@vikas.shirke](https://discuss.elastic.co/u/vikas.shirke)\
**Replies:** 0\
**Last updated:** [August 24, 2022, 10:14am UTC](https://discuss.elastic.co/t/kibana-login-page-logo-customization-in-version-8-x/312789 "2022-08-24T10:14:53Z")

</div>

Hi All, We have developed theme plugin to update login page logo via .css file. It was working fine till 7.17. But when we migrated to 8.2 version, it stopped working as that .css file is no longer available when user i…

---

## [The \_id field deprecated warning in the elasticsearch\_dsl python package](https://discuss.elastic.co/t/the-id-field-deprecated-warning-in-the-elasticsearch-dsl-python-package/312785)

<div class="topic-metadata">

**Author:** [@Ivo\_Tavares](https://discuss.elastic.co/u/Ivo_Tavares)\
**Replies:** 0\
**Last updated:** [August 24, 2022, 9:41am UTC](https://discuss.elastic.co/t/the-id-field-deprecated-warning-in-the-elasticsearch-dsl-python-package/312785 "2022-08-24T09:41:36Z")

</div>

I'm using a python client. There's a Document of the document class, with a data field called id. I've added a document to the default index, without defining a value for that id field. I was expecting ES to auto-popu…

---

## [Kibana crash because \["publicBaseUrl" is not allowed](https://discuss.elastic.co/t/kibana-crash-because-publicbaseurl-is-not-allowed/312786)

<div class="topic-metadata">

**Author:** [@knitehias](https://discuss.elastic.co/u/knitehias)\
**Replies:** 1\
**Last updated:** [August 24, 2022, 9:53am UTC](https://discuss.elastic.co/t/kibana-crash-because-publicbaseurl-is-not-allowed/312786 "2022-08-24T09:53:56Z")

</div>

Hello, I am building my own kibana image from debian. The image looks ok. But when I run my elasticsearch and kibana in kubernetes, kibana crashed due to FATAL ValidationError: child "server" fails because \["publicBa…

---

## [Kibana problem : infinite load time](https://discuss.elastic.co/t/kibana-problem-infinite-load-time/312784)

<div class="topic-metadata">

**Author:** [@meyer1](https://discuss.elastic.co/u/meyer1)\
**Replies:** 0\
**Last updated:** [August 24, 2022, 9:41am UTC](https://discuss.elastic.co/t/kibana-problem-infinite-load-time/312784 "2022-08-24T09:41:03Z")

</div>

Hello everyone I have a problem concerning kibana. When I launch elasticsearch and kibana on my terminal everything is fine. I go to my localhost:5601 and everything seems to work. But when I go on "discovery" or on th…

---

## [Kibana tables are showing very few rows(150) though there are around 4000 rows in the result](https://discuss.elastic.co/t/kibana-tables-are-showing-very-few-rows-150-though-there-are-around-4000-rows-in-the-result/312658)

<div class="topic-metadata">

**Author:** [@Vishwanatha.K](https://discuss.elastic.co/u/Vishwanatha.K)\
**Replies:** 5\
**Last updated:** [August 24, 2022, 9:28am UTC](https://discuss.elastic.co/t/kibana-tables-are-showing-very-few-rows-150-though-there-are-around-4000-rows-in-the-result/312658 "2022-08-24T09:28:00Z")

</div>

Hi, Kibana tables are showing very few rows(150) though there are around 4000 rows in the result. Is there anyway I can set the max rows to be displayed in tables data ? I tried to set the Stackmanagement-\>Advance sett…

---

## [Logstash does not parse if 'if' condition change](https://discuss.elastic.co/t/logstash-does-not-parse-if-if-condition-change/312700)

<div class="topic-metadata">

**Author:** [@Aniket\_Pant](https://discuss.elastic.co/u/Aniket_Pant)\
**Replies:** 5\
**Last updated:** [August 24, 2022, 8:59am UTC](https://discuss.elastic.co/t/logstash-does-not-parse-if-if-condition-change/312700 "2022-08-24T08:59:55Z")

</div>

Using single node ELK cluster version 7.16.3. Index won't appear in kibana if i used this configuration in logstash pipeline file output { if \[tags\] == "average\_weight" { elasticsearch { hosts =\> \["http://localhos…

---

## [HAProxy conf for Logstash](https://discuss.elastic.co/t/haproxy-conf-for-logstash/312773)

<div class="topic-metadata">

**Author:** [@magnorod](https://discuss.elastic.co/u/magnorod)\
**Replies:** 0\
**Last updated:** [August 24, 2022, 7:41am UTC](https://discuss.elastic.co/t/haproxy-conf-for-logstash/312773 "2022-08-24T07:41:35Z")

</div>

Hello, I'm contacting you because I can't get the load balancing of Logstash via HAproxy to work properly. I always have 2 Logstash out of the 4 that share the flow. I would like the flow to be fairly distributed betwe…

---

## [Multiple action, each with a condition in Watcher](https://discuss.elastic.co/t/multiple-action-each-with-a-condition-in-watcher/312766)

<div class="topic-metadata">

**Author:** [@Seemant\_Bind](https://discuss.elastic.co/u/Seemant_Bind)\
**Replies:** 0\
**Last updated:** [August 24, 2022, 6:37am UTC](https://discuss.elastic.co/t/multiple-action-each-with-a-condition-in-watcher/312766 "2022-08-24T06:37:10Z")

</div>

Hi, I am trying to get multiple action output each with different condition in watcher. For that I have tried to use this example(elasticsearch - how to send email alert to groups based on condition success in kibana wa…

[Previous page](https://discuss.elastic.co/tag/none.md?no_tags=true&page=553)

[Next page](https://discuss.elastic.co/tag/none.md?no_tags=true&page=555)
