# \#none

**URL:** https://discuss.elastic.co/tag/none.md?no_tags=true&page=557

[Latest](https://discuss.elastic.co/latest.md) · [Categories](https://discuss.elastic.co/categories.md) · [Tags](https://discuss.elastic.co/tags.md)

**Page:** 558

---

## [Documentation Formating issues](https://discuss.elastic.co/t/documentation-formating-issues/312476)

<div class="topic-metadata">

**Author:** [@leandrojmp](https://discuss.elastic.co/u/leandrojmp)\
**Replies:** 1\
**Last updated:** [August 22, 2022, 12:25am UTC](https://discuss.elastic.co/t/documentation-formating-issues/312476 "2022-08-22T00:25:43Z")

</div>

Hello, It seems that the documentation site for Elastic Stack is changing and some things are broken at the moment, are you guys aware of this issue? For example this page Create transform API | Elasticsearch Guide \[8.…

---

## [Elasticsearch -not starting after boot on ubuntu server 22.04.1](https://discuss.elastic.co/t/elasticsearch-not-starting-after-boot-on-ubuntu-server-22-04-1/312528)

<div class="topic-metadata">

**Author:** [@bezder](https://discuss.elastic.co/u/bezder)\
**Replies:** 1\
**Last updated:** [August 22, 2022, 12:24am UTC](https://discuss.elastic.co/t/elasticsearch-not-starting-after-boot-on-ubuntu-server-22-04-1/312528 "2022-08-22T00:24:35Z")

</div>

Hello, when i reboot my ubuntu server and run systemctl status elasticsearch i am getting errror as below, when i execute afterward systemctl restart elasticsearch; all works okay ... any idea why its not starting p…

---

## [How to return hour by hour average for the last X days?](https://discuss.elastic.co/t/how-to-return-hour-by-hour-average-for-the-last-x-days/312560)

<div class="topic-metadata">

**Author:** [@Yi\_HAN](https://discuss.elastic.co/u/Yi_HAN)\
**Replies:** 0\
**Last updated:** [August 21, 2022, 10:03pm UTC](https://discuss.elastic.co/t/how-to-return-hour-by-hour-average-for-the-last-x-days/312560 "2022-08-21T22:03:34Z")

</div>

I have the following script to return an aggregation hour by hour of last x days on ExecNom: GET /mkt-with-time/\_search { "size": 0, "query": { "range": { "@timestamp": { "gte": "now-7d/d", …

---

## [\[Solved\] Cast/Map IP Field to IP Type](https://discuss.elastic.co/t/solved-cast-map-ip-field-to-ip-type/312558)

<div class="topic-metadata">

**Author:** [@snkhan](https://discuss.elastic.co/u/snkhan)\
**Replies:** 1\
**Last updated:** [August 21, 2022, 9:59pm UTC](https://discuss.elastic.co/t/solved-cast-map-ip-field-to-ip-type/312558 "2022-08-21T21:59:15Z")

</div>

Hello, I am a new ELK user, and am trying in vain to cast an existing field containing an IP address to an IP data type. From the copious searches it is clear that I must use mappings, but my attempts to do so have fail…

---

## [The program ./load\_blogs.sh doesn't do anything](https://discuss.elastic.co/t/the-program-load-blogs-sh-doesnt-do-anything/312508)

<div class="topic-metadata">

**Author:** [@ingmar](https://discuss.elastic.co/u/ingmar)\
**Replies:** 1\
**Last updated:** [August 21, 2022, 1:01pm UTC](https://discuss.elastic.co/t/the-program-load-blogs-sh-doesnt-do-anything/312508 "2022-08-21T13:01:01Z")

</div>

Hello, While doing the labs for module 1 for Elasticsearch Engineer, I am required to run the bash script ./load\_blogs.sh. It doesn't load the blogs into the blogs index after I see the script complete. When I go back…

---

## [Add Runtime Field By UpdateQueryAsync](https://discuss.elastic.co/t/add-runtime-field-by-updatequeryasync/312532)

<div class="topic-metadata">

**Author:** [@Rahma\_Boughale](https://discuss.elastic.co/u/Rahma_Boughale)\
**Replies:** 2\
**Last updated:** [August 21, 2022, 12:19pm UTC](https://discuss.elastic.co/t/add-runtime-field-by-updatequeryasync/312532 "2022-08-21T12:19:45Z")

</div>

Hello all, i am new to elasticsearch, i am trying to add a new field(runtime field) by UpdateByQueryAsync in my index(it already created), i did some research and i saw that we can add a new fiel by this syntax : var u…

---

## [Initializing a new grok filter from ruby filter](https://discuss.elastic.co/t/initializing-a-new-grok-filter-from-ruby-filter/311722)

<div class="topic-metadata">

**Author:** [@who](https://discuss.elastic.co/u/who)\
**Replies:** 2\
**Last updated:** [August 21, 2022, 6:19am UTC](https://discuss.elastic.co/t/initializing-a-new-grok-filter-from-ruby-filter/311722 "2022-08-21T06:19:00Z")

</div>

I'm going to declare and call grok filter from inside a ruby filter like this: ruby { code =\> "@grok = LogStash::Filters::Grok @grok.new(event.get("message"), "\\d+") #call grok plugin for this pipleline " }…

---

## [Jdbc\_streaming statement using a field from input?](https://discuss.elastic.co/t/jdbc-streaming-statement-using-a-field-from-input/312537)

<div class="topic-metadata">

**Author:** [@deep08](https://discuss.elastic.co/u/deep08)\
**Replies:** 0\
**Last updated:** [August 21, 2022, 2:55am UTC](https://discuss.elastic.co/t/jdbc-streaming-statement-using-a-field-from-input/312537 "2022-08-21T02:55:34Z")

</div>

Hello , I have a jdbc\_streaming filter and I want to pass statement as a field value from input . I tried different ways to inject field value in statement but always seeing "exception":"Java::JavaSql::SQLSyntaxErrorEx…

---

## [Options to Create/Add a New Field](https://discuss.elastic.co/t/options-to-create-add-a-new-field/312507)

<div class="topic-metadata">

**Author:** [@Yolanda.darricarrere](https://discuss.elastic.co/u/Yolanda.darricarrere)\
**Replies:** 1\
**Last updated:** [August 21, 2022, 1:53am UTC](https://discuss.elastic.co/t/options-to-create-add-a-new-field/312507 "2022-08-21T01:53:14Z")

</div>

Using the ecommerce data, I want to create a new field that is the total of products.taxful\_price minus products.discount\_amount (make it a double), then add the new field to a line graph using data from the past 7-days.…

---

## [How to append the nested fields in already created elasticsearch index using ES API](https://discuss.elastic.co/t/how-to-append-the-nested-fields-in-already-created-elasticsearch-index-using-es-api/312525)

<div class="topic-metadata">

**Author:** [@Sabaridass10](https://discuss.elastic.co/u/Sabaridass10)\
**Replies:** 0\
**Last updated:** [August 20, 2022, 7:51pm UTC](https://discuss.elastic.co/t/how-to-append-the-nested-fields-in-already-created-elasticsearch-index-using-es-api/312525 "2022-08-20T19:51:48Z")

</div>

I tried to append the nested field using below syntax but showing some error. Can anyone please help me on this? PUT url : es\_index/\_mappings { "properties": { "assignee": { "properties": { "components": { "proper…

---

## [Fiels does not contain any data after loading data using bulk](https://discuss.elastic.co/t/fiels-does-not-contain-any-data-after-loading-data-using-bulk/312510)

<div class="topic-metadata">

**Author:** [@SofiaContreras](https://discuss.elastic.co/u/SofiaContreras)\
**Replies:** 5\
**Last updated:** [August 20, 2022, 6:14pm UTC](https://discuss.elastic.co/t/fiels-does-not-contain-any-data-after-loading-data-using-bulk/312510 "2022-08-20T18:14:44Z")

</div>

I'm trying to make some visualizations using kibana, but the fields have any data. I thought that if I fill up an index in dev ops using bulk, then I would be able to interact with the data using kibana. Here is the cod…

---

## [Right structure for index](https://discuss.elastic.co/t/right-structure-for-index/312515)

<div class="topic-metadata">

**Author:** [@Kimblis](https://discuss.elastic.co/u/Kimblis)\
**Replies:** 3\
**Last updated:** [August 20, 2022, 3:28pm UTC](https://discuss.elastic.co/t/right-structure-for-index/312515 "2022-08-20T15:28:04Z")

</div>

Hello, in my application I have registered users (Users), unregistered users (Guests) and service providers (Providers). Provider can have clients, it's either Users or Guests. I want to have autosuggest and search for s…

---

## [Pourquoi les requêtes construites par Kibana dans discover n'utilisent-elles pas la requête must?](https://discuss.elastic.co/t/pourquoi-les-requetes-construites-par-kibana-dans-discover-nutilisent-elles-pas-la-requete-must/311438)

<div class="topic-metadata">

**Author:** [@Vincent92](https://discuss.elastic.co/u/Vincent92)\
**Replies:** 1\
**Last updated:** [August 20, 2022, 1:39pm UTC](https://discuss.elastic.co/t/pourquoi-les-requetes-construites-par-kibana-dans-discover-nutilisent-elles-pas-la-requete-must/311438 "2022-08-20T13:39:08Z")

</div>

Bonjour, Je développe une application web pour visualiser des données dans un elastic et je m'inspire des requêtes faites par Kibana dans l'application Discover en allant inspecter l'objet requête créé dans l'onglet Ins…

---

## [Indexation fulltext et organisation des données](https://discuss.elastic.co/t/indexation-fulltext-et-organisation-des-donnees/304227)

<div class="topic-metadata">

**Author:** [@lfourny](https://discuss.elastic.co/u/lfourny)\
**Replies:** 1\
**Last updated:** [August 20, 2022, 11:38am UTC](https://discuss.elastic.co/t/indexation-fulltext-et-organisation-des-donnees/304227 "2022-08-20T11:38:30Z")

</div>

Bonjour à tous, Je vais devoir très bientôt indexer un ensemble de documents en fulltext et plusieurs langues. Chaque document est repéré par un code et existe en plusieurs langues. Chaque document est lié à un produi…

---

## [Shard reroute and exchange Primary and Replica on a node](https://discuss.elastic.co/t/shard-reroute-and-exchange-primary-and-replica-on-a-node/312514)

<div class="topic-metadata">

**Author:** [@Farid\_N](https://discuss.elastic.co/u/Farid_N)\
**Replies:** 1\
**Last updated:** [August 20, 2022, 10:45am UTC](https://discuss.elastic.co/t/shard-reroute-and-exchange-primary-and-replica-on-a-node/312514 "2022-08-20T10:45:30Z")

</div>

Hi dears I have a cluster with 2 nodes. one of them is master and another is replica Bellow is all shards in monitor-node-01 : As you see, all of shards in this node is "Primary" and all "Replica" shards are on m…

---

## [Logstash http input fails](https://discuss.elastic.co/t/logstash-http-input-fails/312268)

<div class="topic-metadata">

**Author:** [@cihady](https://discuss.elastic.co/u/cihady)\
**Replies:** 3\
**Last updated:** [August 20, 2022, 6:56am UTC](https://discuss.elastic.co/t/logstash-http-input-fails/312268 "2022-08-20T06:56:27Z")

</div>

I am trying to api call logstash by using http input but when I send request I got error below Here is my config file input { http { host=\>"0.0.0.0" port =\>"2020" } } output { elasticsearch { hosts =\> …

---

## [How to iterate through aggregation buckets and send mail corresponding to each bucket using watcher action](https://discuss.elastic.co/t/how-to-iterate-through-aggregation-buckets-and-send-mail-corresponding-to-each-bucket-using-watcher-action/312474)

<div class="topic-metadata">

**Author:** [@bhavya](https://discuss.elastic.co/u/bhavya)\
**Replies:** 2\
**Last updated:** [August 19, 2022, 6:14pm UTC](https://discuss.elastic.co/t/how-to-iterate-through-aggregation-buckets-and-send-mail-corresponding-to-each-bucket-using-watcher-action/312474 "2022-08-19T18:14:12Z")

</div>

I am trying to iterate through the aggregation bucket results. The aggregation response is : "aggregations" : { "agg1" : { "doc\_count\_error\_upper\_bound" : 0, "sum\_other\_doc\_count" : 0, "buckets" : …

---

## [How to filter my hosts?](https://discuss.elastic.co/t/how-to-filter-my-hosts/312491)

<div class="topic-metadata">

**Author:** [@yyie](https://discuss.elastic.co/u/yyie)\
**Replies:** 3\
**Last updated:** [August 19, 2022, 9:53pm UTC](https://discuss.elastic.co/t/how-to-filter-my-hosts/312491 "2022-08-19T21:53:31Z")

</div>

Hi, i'm new in ELK and I'm planning to add several hosts to my SIEM. I have several hosts distributed in several company locations and I want to be able to analyze each location separately. I tried to add tags to the ag…

---

## [How to write a filter for a file containing a mix of xml and non xml messages](https://discuss.elastic.co/t/how-to-write-a-filter-for-a-file-containing-a-mix-of-xml-and-non-xml-messages/312503)

<div class="topic-metadata">

**Author:** [@Patr123](https://discuss.elastic.co/u/Patr123)\
**Replies:** 2\
**Last updated:** [August 19, 2022, 9:46pm UTC](https://discuss.elastic.co/t/how-to-write-a-filter-for-a-file-containing-a-mix-of-xml-and-non-xml-messages/312503 "2022-08-19T21:46:15Z")

</div>

Hello, I have a log file which is a mix of xml and regular (non xml) lines. I need to apply grok filer + xml filter to the lines that has xml block and apply only grok filter to the regular lines. For that I need help i…

---

## [Search across different indices with consistent ranking](https://discuss.elastic.co/t/search-across-different-indices-with-consistent-ranking/311916)

<div class="topic-metadata">

**Author:** [@stelitz](https://discuss.elastic.co/u/stelitz)\
**Replies:** 5\
**Last updated:** [August 19, 2022, 8:21pm UTC](https://discuss.elastic.co/t/search-across-different-indices-with-consistent-ranking/311916 "2022-08-19T20:21:32Z")

</div>

Hi everyone, I just got started with Elasticsearch and it's really awesome! I am, however, struggling with implementing one specific use case. Let's say I have different logical entities like books and authors and I wan…

---

## [Using event.get to get variable initialized to string](https://discuss.elastic.co/t/using-event-get-to-get-variable-initialized-to-string/312360)

<div class="topic-metadata">

**Author:** [@Mor\_Y](https://discuss.elastic.co/u/Mor_Y)\
**Replies:** 2\
**Last updated:** [August 19, 2022, 6:32pm UTC](https://discuss.elastic.co/t/using-event-get-to-get-variable-initialized-to-string/312360 "2022-08-19T18:32:18Z")

</div>

Hi, I want to add some fields that will have the same values of others but with different names: for Example the input json: {"Environment" : "x", "Name" : "y"} The output will be: {"Environment" : "x", "Name" : "y",…

---

## [I'm using "match-Boolean-prefix query but I can't get the exact match of the query](https://discuss.elastic.co/t/im-using-match-boolean-prefix-query-but-i-cant-get-the-exact-match-of-the-query/312492)

<div class="topic-metadata">

**Author:** [@paris1](https://discuss.elastic.co/u/paris1)\
**Replies:** 0\
**Last updated:** [August 19, 2022, 6:18pm UTC](https://discuss.elastic.co/t/im-using-match-boolean-prefix-query-but-i-cant-get-the-exact-match-of-the-query/312492 "2022-08-19T18:18:57Z")

</div>

I'm using "match-Boolean-prefix query but I can't get the exact match of the query.I can't use prefix queries because I also need "not exact match" results and I also need the fuzziness and word completion.I get every th…

---

## [SSL issue Logstash sending logs to a Kafka instance](https://discuss.elastic.co/t/ssl-issue-logstash-sending-logs-to-a-kafka-instance/312489)

<div class="topic-metadata">

**Author:** [@shanem](https://discuss.elastic.co/u/shanem)\
**Replies:** 0\
**Last updated:** [August 19, 2022, 5:33pm UTC](https://discuss.elastic.co/t/ssl-issue-logstash-sending-logs-to-a-kafka-instance/312489 "2022-08-19T17:33:27Z")

</div>

We are getting a SSL error sending to Kafka from Logstash. We generated a csr, which was signed by the Kafka's CA. Then we took the pub and private key and converted them to a pkcs12 format with openssl with something …

---

## [Proper maintenance of the Elastic Stack](https://discuss.elastic.co/t/proper-maintenance-of-the-elastic-stack/312030)

<div class="topic-metadata">

**Author:** [@MKirby](https://discuss.elastic.co/u/MKirby)\
**Replies:** 3\
**Last updated:** [August 19, 2022, 4:53pm UTC](https://discuss.elastic.co/t/proper-maintenance-of-the-elastic-stack/312030 "2022-08-19T16:53:45Z")

</div>

Good Afternoon Elasticsearch Guru's I have been running my ELK SIEM for a few months now, almost a year actually and my syslogs stopped being shown. I have them coming in again now, but I need to clean up my indices so…

---

## [Line graph with split by chart is not drawing all data points](https://discuss.elastic.co/t/line-graph-with-split-by-chart-is-not-drawing-all-data-points/312484)

<div class="topic-metadata">

**Author:** [@lachlann562](https://discuss.elastic.co/u/lachlann562)\
**Replies:** 0\
**Last updated:** [August 19, 2022, 3:50pm UTC](https://discuss.elastic.co/t/line-graph-with-split-by-chart-is-not-drawing-all-data-points/312484 "2022-08-19T15:50:46Z")

</div>

I have created a line graph that shows the response time of our webservice in categories of 2-4 sec, 4-8, 8-16,16-32,32-64, 64+ seconds. We have set the visualization to split the chart by server so its easy to see which…

---

## [How to send email alert to groups based on condition success using Kibana Rules](https://discuss.elastic.co/t/how-to-send-email-alert-to-groups-based-on-condition-success-using-kibana-rules/312198)

<div class="topic-metadata">

**Author:** [@bhavya](https://discuss.elastic.co/u/bhavya)\
**Replies:** 0\
**Last updated:** [August 16, 2022, 2:53pm UTC](https://discuss.elastic.co/t/how-to-send-email-alert-to-groups-based-on-condition-success-using-kibana-rules/312198 "2022-08-16T14:53:49Z")

</div>

I have created a rule using Kibana rules, by following the below steps: Created a new rule by selecting "Rule" under the "Security" section Then selected the rule type as "Event Correlation", wherein I added the index …

---

## [Scoring issue with copy\_to](https://discuss.elastic.co/t/scoring-issue-with-copy-to/312472)

<div class="topic-metadata">

**Author:** [@lucie-wartelle](https://discuss.elastic.co/u/lucie-wartelle)\
**Replies:** 0\
**Last updated:** [August 19, 2022, 2:06pm UTC](https://discuss.elastic.co/t/scoring-issue-with-copy-to/312472 "2022-08-19T14:06:40Z")

</div>

Hello ! I'm facing an issue with elasticsearch 8. I have an index that contains companies and I use a copy\_to parameters to group searchable fields of these companies. However, some fields can be null, and some can cont…

---

## [Restore data from data folder](https://discuss.elastic.co/t/restore-data-from-data-folder/312448)

<div class="topic-metadata">

**Author:** [@meternich](https://discuss.elastic.co/u/meternich)\
**Replies:** 3\
**Last updated:** [August 19, 2022, 1:31pm UTC](https://discuss.elastic.co/t/restore-data-from-data-folder/312448 "2022-08-19T13:31:00Z")

</div>

I've messed up something with my backups an I accidently deleted few indexes. I have a file system copy of an index (from elastic data folder), but I have deleted index in elastic. When I copy the files into elastic data…

---

## [Index lifecycle management (cleanup) based on document fields](https://discuss.elastic.co/t/index-lifecycle-management-cleanup-based-on-document-fields/312465)

<div class="topic-metadata">

**Author:** [@joeripeeters](https://discuss.elastic.co/u/joeripeeters)\
**Replies:** 1\
**Last updated:** [August 19, 2022, 12:38pm UTC](https://discuss.elastic.co/t/index-lifecycle-management-cleanup-based-on-document-fields/312465 "2022-08-19T12:38:01Z")

</div>

Hi all, I have an index with data that contains a start-date and end-date. Documents that have an end-date past today, are not valuable anymore. So ideally, I want them out of the index. Is there a way to have index li…

---

## [How to get logs of multiple hostnames using scoll api](https://discuss.elastic.co/t/how-to-get-logs-of-multiple-hostnames-using-scoll-api/312453)

<div class="topic-metadata">

**Author:** [@Gojo](https://discuss.elastic.co/u/Gojo)\
**Replies:** 1\
**Last updated:** [August 19, 2022, 10:08am UTC](https://discuss.elastic.co/t/how-to-get-logs-of-multiple-hostnames-using-scoll-api/312453 "2022-08-19T10:08:33Z")

</div>

hi all , is it possible to pass multiple hosts in scroll api , i want to get multiple logs from multiple hosts using scroll request url = '{0}/{1}/\_search?scroll=1m&ignore\_unavailable=true'.format( …

[Previous page](https://discuss.elastic.co/tag/none.md?no_tags=true&page=556)

[Next page](https://discuss.elastic.co/tag/none.md?no_tags=true&page=558)
