# \#none

**URL:** https://discuss.elastic.co/tag/none.md?no_tags=true&page=560

[Latest](https://discuss.elastic.co/latest.md) · [Categories](https://discuss.elastic.co/categories.md) · [Tags](https://discuss.elastic.co/tags.md)

**Page:** 561

---

## [Splitting table based on text value](https://discuss.elastic.co/t/splitting-table-based-on-text-value/312208)

<div class="topic-metadata">

**Author:** [@Marius\_Kunauskas](https://discuss.elastic.co/u/Marius_Kunauskas)\
**Replies:** 1\
**Last updated:** [August 16, 2022, 6:37pm UTC](https://discuss.elastic.co/t/splitting-table-based-on-text-value/312208 "2022-08-16T18:37:16Z")

</div>

As a complete elastic-newbie, how could I split a column based on its text value? I.e. Instead of splitting rows on different Field values (e.g. country), I want to split it based on WHETHER a field starts with a certai…

---

## [Edit file using logstash](https://discuss.elastic.co/t/edit-file-using-logstash/312157)

<div class="topic-metadata">

**Author:** [@alex\_vermex](https://discuss.elastic.co/u/alex_vermex)\
**Replies:** 2\
**Last updated:** [August 16, 2022, 6:08pm UTC](https://discuss.elastic.co/t/edit-file-using-logstash/312157 "2022-08-16T18:08:55Z")

</div>

Hi, I have already created a topic here to add \[\] to the beginning and end of the file and I can't find the solution so I want to ask if I can edit the file using logstash now my file like this: {"field1": "value1","fi…

---

## [Add \[ \] to codec =\> json](https://discuss.elastic.co/t/add-to-codec-json/312104)

<div class="topic-metadata">

**Author:** [@alex\_vermex](https://discuss.elastic.co/u/alex_vermex)\
**Replies:** 4\
**Last updated:** [August 16, 2022, 5:49pm UTC](https://discuss.elastic.co/t/add-to-codec-json/312104 "2022-08-16T17:49:27Z")

</div>

Hi, can i add \[ \] to json file ? because output{ file { codec =\> json path =\> \["D:/elastic\_stack/test/temp.json"\] } } it gives me { 'a':'a','b':'b'}{'c':'c'} i want to add \[ \] so i wanted like this \[{ 'a' : 'a','b':'…

---

## [Logstash rabbitmq input plugin doesn't read "host" value](https://discuss.elastic.co/t/logstash-rabbitmq-input-plugin-doesnt-read-host-value/312204)

<div class="topic-metadata">

**Author:** [@thinkorhiking](https://discuss.elastic.co/u/thinkorhiking)\
**Replies:** 0\
**Last updated:** [August 16, 2022, 5:01pm UTC](https://discuss.elastic.co/t/logstash-rabbitmq-input-plugin-doesnt-read-host-value/312204 "2022-08-16T17:01:42Z")

</div>

I'm having trouble to setup logstash rabbitmq input plugin, to connect to the rabbitmq pod host name. Why it still tries to connect @localhost. logstash does not read the config correctly. Is this a bug or is there any …

---

## [Shards failed in kibana](https://discuss.elastic.co/t/shards-failed-in-kibana/310559)

<div class="topic-metadata">

**Author:** [@OoO](https://discuss.elastic.co/u/OoO)\
**Replies:** 3\
**Last updated:** [August 16, 2022, 4:27pm UTC](https://discuss.elastic.co/t/shards-failed-in-kibana/310559 "2022-08-16T16:27:34Z")

</div>

Hello world, Since I upgraded filebeat from 7.x to 8.x ( the version of my ELK and filebeat is 8.2.3 now), I can't see the dashboard anymore, I have encountered this problem on kibana: 1 of 8 shards failed The data y…

---

## [Could not index event to Elasticsearch](https://discuss.elastic.co/t/could-not-index-event-to-elasticsearch/312023)

<div class="topic-metadata">

**Author:** [@syedabdullah](https://discuss.elastic.co/u/syedabdullah)\
**Replies:** 6\
**Last updated:** [August 16, 2022, 3:57pm UTC](https://discuss.elastic.co/t/could-not-index-event-to-elasticsearch/312023 "2022-08-16T15:57:58Z")

</div>

Hi I am getting this error in Elasticsearch (Please look at the bolded statements), any sort of help will be welcome. Thank you so much in advance: \[2022-05-03T12:41:26,871\]\[WARN \]\[logstash.outputs.elasticsearch\]\[rtt\_kf…

---

## [Kibana Table visualization for different weeks,showing reports for current date](https://discuss.elastic.co/t/kibana-table-visualization-for-different-weeks-showing-reports-for-current-date/311485)

<div class="topic-metadata">

**Author:** [@PRASHANT\_MEHTA](https://discuss.elastic.co/u/PRASHANT_MEHTA)\
**Replies:** 2\
**Last updated:** [August 16, 2022, 2:34pm UTC](https://discuss.elastic.co/t/kibana-table-visualization-for-different-weeks-showing-reports-for-current-date/311485 "2022-08-16T14:34:45Z")

</div>

Hello All, I'm not sure how this can be achieved through kibana table visualization,I want to display the converter details in accordance to week wise and the date displayed should always be current date. KW-calendar …

---

## [Sorting a house number field](https://discuss.elastic.co/t/sorting-a-house-number-field/312194)

<div class="topic-metadata">

**Author:** [@Nicolai\_Jee](https://discuss.elastic.co/u/Nicolai_Jee)\
**Replies:** 1\
**Last updated:** [August 16, 2022, 3:05pm UTC](https://discuss.elastic.co/t/sorting-a-house-number-field/312194 "2022-08-16T15:05:18Z")

</div>

Hi I have a house number field that contains stringbased data like 1,2A,3,3B,10,100A. Right now it is a basic textfield and it does string sorting, which is not working for me. I need it to sort numerically and then a…

---

## [ActionNotFoundTransportException\[No handler for action \[indices:admin/exists\]](https://discuss.elastic.co/t/actionnotfoundtransportexception-no-handler-for-action-indices-admin-exists/312176)

<div class="topic-metadata">

**Author:** [@Sathiya\_Kennady](https://discuss.elastic.co/u/Sathiya_Kennady)\
**Replies:** 1\
**Last updated:** [August 16, 2022, 2:17pm UTC](https://discuss.elastic.co/t/actionnotfoundtransportexception-no-handler-for-action-indices-admin-exists/312176 "2022-08-16T14:17:24Z")

</div>

While checking index is exists are not i am getting below error : ClusterConnectionManager:225 - transport connection to \[{lutw}{Bz3WvABkSsuCLyVoF3kDsg}{exNsn6r4TFGF4KrMm4aduw}{192.168.1.84}{192.168.1.84:9300}{cdfhilmrs…

---

## [Wildcard query on text field](https://discuss.elastic.co/t/wildcard-query-on-text-field/311676)

<div class="topic-metadata">

**Author:** [@maxfriz](https://discuss.elastic.co/u/maxfriz)\
**Replies:** 2\
**Last updated:** [August 16, 2022, 2:11pm UTC](https://discuss.elastic.co/t/wildcard-query-on-text-field/311676 "2022-08-16T14:11:41Z")

</div>

From a best practice and cautionary perspective, am I missing any other critical information I should be considering specific to a wildcard query on a text field? See bullets below. I have reviewed the documentation i…

---

## [Filter out (drop) a log sent to Logstash, based on the values of its fields](https://discuss.elastic.co/t/filter-out-drop-a-log-sent-to-logstash-based-on-the-values-of-its-fields/310664)

<div class="topic-metadata">

**Author:** [@zoug](https://discuss.elastic.co/u/zoug)\
**Replies:** 5\
**Last updated:** [July 28, 2022, 1:47pm UTC](https://discuss.elastic.co/t/filter-out-drop-a-log-sent-to-logstash-based-on-the-values-of-its-fields/310664 "2022-07-28T13:47:15Z")

</div>

Hello, I use a pipeline to ingest logs generated by suricata, everything set up with filebeat setup --pipelines --modules suricata,\<other\_modules\>. I don't want to ingest any "event" logs, only "alert" logs. So I added …

---

## [Problem with an implementation on my array in a Pie Chart](https://discuss.elastic.co/t/problem-with-an-implementation-on-my-array-in-a-pie-chart/311145)

<div class="topic-metadata">

**Author:** [@Dave23](https://discuss.elastic.co/u/Dave23)\
**Replies:** 2\
**Last updated:** [August 16, 2022, 1:33pm UTC](https://discuss.elastic.co/t/problem-with-an-implementation-on-my-array-in-a-pie-chart/311145 "2022-08-16T13:33:30Z")

</div>

Hello everyone, I have the following array and I want to make a pie chart with each of the "holders.address" and the "amount" of each of them, but I can't get that information, I don't know what calculation field to use …

---

## [Elasticsearch does not load ES\_PATH\_CONF or any values that are present in sysconfig](https://discuss.elastic.co/t/elasticsearch-does-not-load-es-path-conf-or-any-values-that-are-present-in-sysconfig/311411)

<div class="topic-metadata">

**Author:** [@nightwatch92](https://discuss.elastic.co/u/nightwatch92)\
**Replies:** 2\
**Last updated:** [August 16, 2022, 1:16pm UTC](https://discuss.elastic.co/t/elasticsearch-does-not-load-es-path-conf-or-any-values-that-are-present-in-sysconfig/311411 "2022-08-16T13:16:07Z")

</div>

Hi, ES version: 8.3.3 OS: CENTOS 8 We are using packages to distribute our config files in custom directory for the ES service. We can't replace /etc/sysconfig/elasticsearch, because it is owned by the elasticsearch p…

---

## [Kibana 7.16.3 Create Index patter API doesn't recognize field](https://discuss.elastic.co/t/kibana-7-16-3-create-index-patter-api-doesnt-recognize-field/312185)

<div class="topic-metadata">

**Author:** [@Enrique\_Flores](https://discuss.elastic.co/u/Enrique_Flores)\
**Replies:** 0\
**Last updated:** [August 16, 2022, 12:56pm UTC](https://discuss.elastic.co/t/kibana-7-16-3-create-index-patter-api-doesnt-recognize-field/312185 "2022-08-16T12:56:33Z")

</div>

Im trying to create a index pattern via POST /api/index\_patterns/index\_pattern using a json already parsed, that json was generate with a kibana used in PRO via GET /api/index\_patterns/index\_pattern/, i don't know what i…

---

## [Kibana - aggregation in graphs (average number of things per bucket)](https://discuss.elastic.co/t/kibana-aggregation-in-graphs-average-number-of-things-per-bucket/311291)

<div class="topic-metadata">

**Author:** [@RonGros](https://discuss.elastic.co/u/RonGros)\
**Replies:** 7\
**Last updated:** [August 16, 2022, 10:57am UTC](https://discuss.elastic.co/t/kibana-aggregation-in-graphs-average-number-of-things-per-bucket/311291 "2022-08-16T10:57:53Z")

</div>

Hi, I have a situation and I am stuck, I think what I want to do is not currently achievable but I hope I'm wrong. Let's assume I have the following data about people going to the movies: Name of person Which movies …

---

## [Sort data in sub level](https://discuss.elastic.co/t/sort-data-in-sub-level/312166)

<div class="topic-metadata">

**Author:** [@aneesh](https://discuss.elastic.co/u/aneesh)\
**Replies:** 0\
**Last updated:** [August 16, 2022, 10:11am UTC](https://discuss.elastic.co/t/sort-data-in-sub-level/312166 "2022-08-16T10:11:04Z")

</div>

i am doing a sorting for a column that is in sub level. The issue there is , the sub level contains an array and i want to sort the data depending on the condition. My data looks like below I need to do sorting on colu…

---

## [Ability to search ES based on the result of previous search in the query](https://discuss.elastic.co/t/ability-to-search-es-based-on-the-result-of-previous-search-in-the-query/312093)

<div class="topic-metadata">

**Author:** [@Ananya\_Chowdhury](https://discuss.elastic.co/u/Ananya_Chowdhury)\
**Replies:** 4\
**Last updated:** [August 16, 2022, 8:36am UTC](https://discuss.elastic.co/t/ability-to-search-es-based-on-the-result-of-previous-search-in-the-query/312093 "2022-08-16T08:36:14Z")

</div>

Hi, We want to build a query which will search for a particular string and then it will perform a search based on the result that we have received from previous result. Can any one help us how we can achieve this. How …

---

## [Deleted Docs - SQL SYNC](https://discuss.elastic.co/t/deleted-docs-sql-sync/312153)

<div class="topic-metadata">

**Author:** [@Berat\_Demirci](https://discuss.elastic.co/u/Berat_Demirci)\
**Replies:** 0\
**Last updated:** [August 16, 2022, 8:57am UTC](https://discuss.elastic.co/t/deleted-docs-sql-sync/312153 "2022-08-16T08:57:41Z")

</div>

I will sync data from sql to elastic. My config was running a few tries but now It is deleting my docs. Sync is successful and I dont see any error. My config input { jdbc { jdbc\_driver\_library =\> "C:\\Program Files\\…

---

## [How to get all rules from Elasticsearch Security using curl API?](https://discuss.elastic.co/t/how-to-get-all-rules-from-elasticsearch-security-using-curl-api/311618)

<div class="topic-metadata">

**Author:** [@xynobob](https://discuss.elastic.co/u/xynobob)\
**Replies:** 3\
**Last updated:** [August 16, 2022, 8:54am UTC](https://discuss.elastic.co/t/how-to-get-all-rules-from-elasticsearch-security-using-curl-api/311618 "2022-08-16T08:54:38Z")

</div>

I have been trying to get all the rules (thousands of them) from my Elasticsearch Security using the curl API, however the only example and way shown on the website is able to obtain only one single rule at a time by run…

---

## [Elasticsearch curator & ES version 8.x](https://discuss.elastic.co/t/elasticsearch-curator-es-version-8-x/312134)

<div class="topic-metadata">

**Author:** [@smm](https://discuss.elastic.co/u/smm)\
**Replies:** 1\
**Last updated:** [August 16, 2022, 6:15am UTC](https://discuss.elastic.co/t/elasticsearch-curator-es-version-8-x/312134 "2022-08-16T06:15:29Z")

</div>

Hi there, am I correct that the latest curatr version does NOT work with ES 8.x., but is limited to / till 7.x? Thanks!! Stefano

---

## [Failed to execute action:message=\>"Unable to configure plugins](https://discuss.elastic.co/t/failed-to-execute-action-message-unable-to-configure-plugins/312106)

<div class="topic-metadata">

**Author:** [@Eina\_Zia](https://discuss.elastic.co/u/Eina_Zia)\
**Replies:** 2\
**Last updated:** [August 16, 2022, 3:35am UTC](https://discuss.elastic.co/t/failed-to-execute-action-message-unable-to-configure-plugins/312106 "2022-08-16T03:35:59Z")

</div>

Hello everyone1 I am new to logstash and I have been trying for so long to import dataset through logstash. I keep on getting error. This is my recent attempt. Without super user, it is not giving me permission even afte…

---

## [Kibana Visualization](https://discuss.elastic.co/t/kibana-visualization/312107)

<div class="topic-metadata">

**Author:** [@Pranta\_Saha](https://discuss.elastic.co/u/Pranta_Saha)\
**Replies:** 1\
**Last updated:** [August 16, 2022, 2:59am UTC](https://discuss.elastic.co/t/kibana-visualization/312107 "2022-08-16T02:59:18Z")

</div>

Hello, I am trying to create a visualization of my Elasticsearch cluster health in Kibana. Can any one give me a hint how it can be done?

---

## [How to search data and show like this,all the fields in result are connected by dot?](https://discuss.elastic.co/t/how-to-search-data-and-show-like-this-all-the-fields-in-result-are-connected-by-dot/312133)

<div class="topic-metadata">

**Author:** [@jin\_liu](https://discuss.elastic.co/u/jin_liu)\
**Replies:** 0\
**Last updated:** [August 16, 2022, 2:46am UTC](https://discuss.elastic.co/t/how-to-search-data-and-show-like-this-all-the-fields-in-result-are-connected-by-dot/312133 "2022-08-16T02:46:23Z")

</div>

i found this when discover es data by kibana,all the fields are connected by dot,i wonder how to make this by es dsl? { "\_index": "zk\_mysql\_log-2022\_08", "\_type": "\_doc", "\_id": "DoEekIIBmO8s27BbCb\_1", "\_version…

---

## [How to make an interval of minutes in a timestamp on Lens \[Dashboards\]](https://discuss.elastic.co/t/how-to-make-an-interval-of-minutes-in-a-timestamp-on-lens-dashboards/312123)

<div class="topic-metadata">

**Author:** [@SamuelSMendes](https://discuss.elastic.co/u/SamuelSMendes)\
**Replies:** 3\
**Last updated:** [August 16, 2022, 1:48am UTC](https://discuss.elastic.co/t/how-to-make-an-interval-of-minutes-in-a-timestamp-on-lens-dashboards/312123 "2022-08-16T01:48:06Z")

</div>

Hello everyone, I'm new to the making of dashboards and now I'm having a bit of problem dealing with a specific field on Lens. First here is the image in question: On the left is a random ID given to a device and on…

---

## [Watcher not passing variables to an e-mail message](https://discuss.elastic.co/t/watcher-not-passing-variables-to-an-e-mail-message/310932)

<div class="topic-metadata">

**Author:** [@srpmic](https://discuss.elastic.co/u/srpmic)\
**Replies:** 2\
**Last updated:** [August 16, 2022, 12:32am UTC](https://discuss.elastic.co/t/watcher-not-passing-variables-to-an-e-mail-message/310932 "2022-08-16T00:32:21Z")

</div>

Hello, I'm ingesting my Windows logs via WinlogBeat. I want to receive an e-mail when winlog.event\_id is equal to either 17, 34, 130, 21. The e-mail should contain the event.code, agent.name, time and the raw event me…

---

## [What happened to the "Gold" subscription?](https://discuss.elastic.co/t/what-happened-to-the-gold-subscription/311506)

<div class="topic-metadata">

**Author:** [@CoaxVex](https://discuss.elastic.co/u/CoaxVex)\
**Replies:** 2\
**Last updated:** [August 15, 2022, 10:36pm UTC](https://discuss.elastic.co/t/what-happened-to-the-gold-subscription/311506 "2022-08-15T22:36:57Z")

</div>

I was just made aware that the "Gold" subscription has been discontinued. When did this happen, and what is the reasoning behind it? Is this part of a strategy to push users to the cloud service? Many "Elastic stack" u…

---

## [Calculating a formula on nested fields in classic, aggregation-based visualizations](https://discuss.elastic.co/t/calculating-a-formula-on-nested-fields-in-classic-aggregation-based-visualizations/311988)

<div class="topic-metadata">

**Author:** [@slhck](https://discuss.elastic.co/u/slhck)\
**Replies:** 7\
**Last updated:** [August 15, 2022, 6:17pm UTC](https://discuss.elastic.co/t/calculating-a-formula-on-nested-fields-in-classic-aggregation-based-visualizations/311988 "2022-08-15T18:17:15Z")

</div>

I have a document field that gives me a result in kBit/s, but I would like to convert it to MBit/s (by dividing by 1,000). This should only be done during visualization; there is no need to create a runtime field or scri…

---

## [Performance of using Elasticsearch to search for people](https://discuss.elastic.co/t/performance-of-using-elasticsearch-to-search-for-people/309687)

<div class="topic-metadata">

**Author:** [@AymanHamdoun](https://discuss.elastic.co/u/AymanHamdoun)\
**Replies:** 15\
**Last updated:** [August 15, 2022, 5:18pm UTC](https://discuss.elastic.co/t/performance-of-using-elasticsearch-to-search-for-people/309687 "2022-08-15T17:18:54Z")

</div>

Problem Context I am trying to use Elasticsearch to implement user search in a platform. However its taking way too long to search. usually around 100 ms - 200 ms. I am trying to achieve something closer to 40 ms maximum…

---

## [Creating a New Cluster -- To Use or Not to Use Virtualization?](https://discuss.elastic.co/t/creating-a-new-cluster-to-use-or-not-to-use-virtualization/312102)

<div class="topic-metadata">

**Author:** [@pushshift](https://discuss.elastic.co/u/pushshift)\
**Replies:** 2\
**Last updated:** [August 15, 2022, 4:43pm UTC](https://discuss.elastic.co/t/creating-a-new-cluster-to-use-or-not-to-use-virtualization/312102 "2022-08-15T16:43:42Z")

</div>

We are in the process of securing COLO space to install new servers into a rack and to move our current Elasticsearch clusters into one larger cluster. I've read some material on virtualization and ES and I was hoping to…

---

## [How can I resolve "could not use PowerShell to find Visual Studio 2017 or newer" while installing kibana](https://discuss.elastic.co/t/how-can-i-resolve-could-not-use-powershell-to-find-visual-studio-2017-or-newer-while-installing-kibana/309932)

<div class="topic-metadata">

**Author:** [@najmiehsa](https://discuss.elastic.co/u/najmiehsa)\
**Replies:** 8\
**Last updated:** [August 15, 2022, 4:12pm UTC](https://discuss.elastic.co/t/how-can-i-resolve-could-not-use-powershell-to-find-visual-studio-2017-or-newer-while-installing-kibana/309932 "2022-08-15T16:12:36Z")

</div>

Hi, I have visual studio 2022 community and visual studio 2022 build tools installed and config them with npm. But when I try to install kibana I encounter this error: could not use PowerShell to find Visual Studio 20…

[Previous page](https://discuss.elastic.co/tag/none.md?no_tags=true&page=559)

[Next page](https://discuss.elastic.co/tag/none.md?no_tags=true&page=561)
