# \#none

**URL:** https://discuss.elastic.co/tag/none.md?no_tags=true&page=561

[Latest](https://discuss.elastic.co/latest.md) · [Categories](https://discuss.elastic.co/categories.md) · [Tags](https://discuss.elastic.co/tags.md)

**Page:** 562

---

## [Disover without \_source field?](https://discuss.elastic.co/t/disover-without-source-field/311410)

<div class="topic-metadata">

**Author:** [@Dargod](https://discuss.elastic.co/u/Dargod)\
**Replies:** 3\
**Last updated:** [August 15, 2022, 3:00pm UTC](https://discuss.elastic.co/t/disover-without-source-field/311410 "2022-08-15T15:00:30Z")

</div>

Is it possible to fully use the section Discover in Kibana with disabled \_source? I disabled this field and set option: Read fields from \_source (discover:searchFieldsFromSource) - False However, I still get the erro…

---

## [Download 200k records from Elasticsearch](https://discuss.elastic.co/t/download-200k-records-from-elasticsearch/311960)

<div class="topic-metadata">

**Author:** [@snambu5878](https://discuss.elastic.co/u/snambu5878)\
**Replies:** 2\
**Last updated:** [August 15, 2022, 2:54pm UTC](https://discuss.elastic.co/t/download-200k-records-from-elasticsearch/311960 "2022-08-15T14:54:13Z")

</div>

Hi Everyone, We have built custom analytics UI (React) and using Elasticsearch as backend for SQL queries/analysis. We have Export results button that exports the queried dataset. The requirement is to download upto 20…

---

## [Elastic Agent SOMETIMES Opens Ports to Listen for Syslog Traffic (Buggy Behaviour)](https://discuss.elastic.co/t/elastic-agent-sometimes-opens-ports-to-listen-for-syslog-traffic-buggy-behaviour/312046)

<div class="topic-metadata">

**Author:** [@othman](https://discuss.elastic.co/u/othman)\
**Replies:** 1\
**Last updated:** [August 15, 2022, 1:51pm UTC](https://discuss.elastic.co/t/elastic-agent-sometimes-opens-ports-to-listen-for-syslog-traffic-buggy-behaviour/312046 "2022-08-15T13:51:35Z")

</div>

Greetings, I'm having this rather inconsistent behaviour where my elastic agent deployed on my Syslog server sometimes opens ports for incoming traffic and sometimes decides not to. Currently the agent has few integrat…

---

## [Is it possible that this happens again in an upgrade?](https://discuss.elastic.co/t/is-it-possible-that-this-happens-again-in-an-upgrade/312039)

<div class="topic-metadata">

**Author:** [@odelacruzc](https://discuss.elastic.co/u/odelacruzc)\
**Replies:** 2\
**Last updated:** [August 15, 2022, 1:42pm UTC](https://discuss.elastic.co/t/is-it-possible-that-this-happens-again-in-an-upgrade/312039 "2022-08-15T13:42:31Z")

</div>

Hi friends, we are going to migrate to the latest version of elastic 8.3, so before when we migrated from 6.x to 7.x, the alerts were affected since some configurations were automatically activated through some checkboxe…

---

## [Kibana - Alert data viewer and Edit Rule are stuck and slow](https://discuss.elastic.co/t/kibana-alert-data-viewer-and-edit-rule-are-stuck-and-slow/312103)

<div class="topic-metadata">

**Author:** [@Mor123460](https://discuss.elastic.co/u/Mor123460)\
**Replies:** 0\
**Last updated:** [August 15, 2022, 12:52pm UTC](https://discuss.elastic.co/t/kibana-alert-data-viewer-and-edit-rule-are-stuck-and-slow/312103 "2022-08-15T12:52:03Z")

</div>

Hey. I'm running a cluster in 2 different environments. With the same versions for all of the nodes and the kibana (8.1.2). But in one of the environments, the Alert data viewer or the Edit rule (any rule) are getting…

---

## [Viewing Documents in Kibana](https://discuss.elastic.co/t/viewing-documents-in-kibana/311459)

<div class="topic-metadata">

**Author:** [@jhop](https://discuss.elastic.co/u/jhop)\
**Replies:** 7\
**Last updated:** [August 15, 2022, 12:48pm UTC](https://discuss.elastic.co/t/viewing-documents-in-kibana/311459 "2022-08-15T12:48:46Z")

</div>

Hi, I am new to Elastic. I have successfully mapped and created a new index using Management\>Dev Tools\>Console. I can view the index on the Index Management screen. Using the console I successfully created two document…

---

## [Failed to parse field \[msg.RequestPort\] of type \[long\]](https://discuss.elastic.co/t/failed-to-parse-field-msg-requestport-of-type-long/312080)

<div class="topic-metadata">

**Author:** [@ayarosh](https://discuss.elastic.co/u/ayarosh)\
**Replies:** 4\
**Last updated:** [August 15, 2022, 12:14pm UTC](https://discuss.elastic.co/t/failed-to-parse-field-msg-requestport-of-type-long/312080 "2022-08-15T12:14:41Z")

</div>

Filebeat cannot parse and drop the logs when receives the different type of input. "RequestPort":"-" (it usually contains the long type number) Error: {\\"type\\":\\"mapper\_parsing\_exception\\",\\"reason\\":\\"failed to pars…

---

## [Using app.kubernetes.io/name label](https://discuss.elastic.co/t/using-app-kubernetes-io-name-label/312088)

<div class="topic-metadata">

**Author:** [@AssafKatz3](https://discuss.elastic.co/u/AssafKatz3)\
**Replies:** 0\
**Last updated:** [August 15, 2022, 11:04am UTC](https://discuss.elastic.co/t/using-app-kubernetes-io-name-label/312088 "2022-08-15T11:04:46Z")

</div>

Hi, I am trying to define service as the content of app.kubernetes.io/name label if it empty by: if !\[service\] and \[kubernetes\]\[labels\]\[app\_kubernetes\_io/name\] { mutate { add\_field =\> { "service…

---

## [Index \_stats index\_total should be calculated with scroll?](https://discuss.elastic.co/t/index-stats-index-total-should-be-calculated-with-scroll/312085)

<div class="topic-metadata">

**Author:** [@kin122](https://discuss.elastic.co/u/kin122)\
**Replies:** 0\
**Last updated:** [August 15, 2022, 10:55am UTC](https://discuss.elastic.co/t/index-stats-index-total-should-be-calculated-with-scroll/312085 "2022-08-15T10:55:52Z")

</div>

hi i monitors indices with \_stats API. i found index\_total affected by scroll its calculated by irate of prometheus. How do I remove the effection of scroll to get the right statsdata？

---

## [How to (offsite) backup and recover snapshots](https://discuss.elastic.co/t/how-to-offsite-backup-and-recover-snapshots/312081)

<div class="topic-metadata">

**Author:** [@Pieter\_Agenbag](https://discuss.elastic.co/u/Pieter_Agenbag)\
**Replies:** 5\
**Last updated:** [August 15, 2022, 10:30am UTC](https://discuss.elastic.co/t/how-to-offsite-backup-and-recover-snapshots/312081 "2022-08-15T10:30:15Z")

</div>

Hi - have a ES cluster consisting of lets say 20 nodes for arguments sake. Of course the indexes and shards are spread across the nodes... now lets say I do a snapshot. It looks like each node snapshots the data on its…

---

## [Error using API to connect to cluster](https://discuss.elastic.co/t/error-using-api-to-connect-to-cluster/311970)

<div class="topic-metadata">

**Author:** [@Russell\_Fulton](https://discuss.elastic.co/u/Russell_Fulton)\
**Replies:** 2\
**Last updated:** [August 15, 2022, 9:18am UTC](https://discuss.elastic.co/t/error-using-api-to-connect-to-cluster/311970 "2022-08-15T09:18:05Z")

</div>

ES version 7.17.1 I have just enabled security on an existing cluster that date back to the time when one had to pay to get "security". ;). I can connect using curl on the elastic user and get the cluster health. So t…

---

## [Logstash match Thai timestamp](https://discuss.elastic.co/t/logstash-match-thai-timestamp/312077)

<div class="topic-metadata">

**Author:** [@Denis\_Smereka](https://discuss.elastic.co/u/Denis_Smereka)\
**Replies:** 0\
**Last updated:** [August 15, 2022, 8:22am UTC](https://discuss.elastic.co/t/logstash-match-thai-timestamp/312077 "2022-08-15T08:22:09Z")

</div>

I have certain logs which contain the following entries: 2022-08-10 12:55:58.535 Started. ๒๐๒๒-๐๘-๑๐ ๑๘:๓๔:๔๘.๒๗๑ Reader #0: ... The first line successfully matches using the pattern TIMESTAMP\_ISO8601. Second line als…

---

## [The \_ignored field not working?](https://discuss.elastic.co/t/the-ignored-field-not-working/310460)

<div class="topic-metadata">

**Author:** [@rokcarl](https://discuss.elastic.co/u/rokcarl)\
**Replies:** 4\
**Last updated:** [August 15, 2022, 8:16am UTC](https://discuss.elastic.co/t/the-ignored-field-not-working/310460 "2022-08-15T08:16:18Z")

</div>

Summary I'm using ignore\_malformed, but get no results when searching for the \_ignored field. Details I've isolated the problem to a small example. I: Create the index with ignore\_malformed set to true. Insert a cou…

---

## [Ruby exception occurred: uninitialized constant when i am trying to devide a field value by 100](https://discuss.elastic.co/t/ruby-exception-occurred-uninitialized-constant-when-i-am-trying-to-devide-a-field-value-by-100/312058)

<div class="topic-metadata">

**Author:** [@Faiz\_Shamri](https://discuss.elastic.co/u/Faiz_Shamri)\
**Replies:** 7\
**Last updated:** [August 14, 2022, 6:19pm UTC](https://discuss.elastic.co/t/ruby-exception-occurred-uninitialized-constant-when-i-am-trying-to-devide-a-field-value-by-100/312058 "2022-08-14T18:19:08Z")

</div>

I am trying to devide filed value by 100 but i am getting Pipelines running {:count=\>1, :running\_pipelines=\>\[:main\], :non\_running\_pipelines=\>\[\]} \[ERROR\] 2022-08-14 00:10:07.738 \[\[main\]\>worker2\] ruby - Ruby exception occu…

---

## [\[Logstash\] \[Filebeat\] Using codec Plain and JSON for the same input](https://discuss.elastic.co/t/logstash-filebeat-using-codec-plain-and-json-for-the-same-input/310836)

<div class="topic-metadata">

**Author:** [@hdryx](https://discuss.elastic.co/u/hdryx)\
**Replies:** 8\
**Last updated:** [August 14, 2022, 4:55pm UTC](https://discuss.elastic.co/t/logstash-filebeat-using-codec-plain-and-json-for-the-same-input/310836 "2022-08-14T16:55:46Z")

</div>

Hi, Actually we have this architecture : Filebeat --\> Kafaka --\> Logstash The Logstash is using this input config : file1.conf input { kafka { codec =\> json bootstrap\_servers =\> "....." topics\_pattern =\>…

---

## [\[Filebeat Threat Intel\] MISP doesnt show anything](https://discuss.elastic.co/t/filebeat-threat-intel-misp-doesnt-show-anything/311539)

<div class="topic-metadata">

**Author:** [@VitorBarroso](https://discuss.elastic.co/u/VitorBarroso)\
**Replies:** 2\
**Last updated:** [August 14, 2022, 3:18pm UTC](https://discuss.elastic.co/t/filebeat-threat-intel-misp-doesnt-show-anything/311539 "2022-08-14T15:18:45Z")

</div>

\[Filebeat Threat Intel\] MISP doesnt show any information. What can i do to resolve this problem?

---

## [Deploy Elastic Agent successful but has no data steams](https://discuss.elastic.co/t/deploy-elastic-agent-successful-but-has-no-data-steams/311955)

<div class="topic-metadata">

**Author:** [@Han\_Cloud\_Strife](https://discuss.elastic.co/u/Han_Cloud_Strife)\
**Replies:** 1\
**Last updated:** [August 14, 2022, 3:00pm UTC](https://discuss.elastic.co/t/deploy-elastic-agent-successful-but-has-no-data-steams/311955 "2022-08-14T15:00:11Z")

</div>

Hi there! I got a problem with Elastic Agent when using ELK on docker. I have two docker-compose files for creating certificate and deploying ELK purpose. I enrolled elastic agent successfull \[1\] however I got bad\_certi…

---

## [Version\_conflict\_engine\_exception，help me](https://discuss.elastic.co/t/version-conflict-engine-exception-help-me/312065)

<div class="topic-metadata">

**Author:** [@wangshouqi111](https://discuss.elastic.co/u/wangshouqi111)\
**Replies:** 1\
**Last updated:** [August 14, 2022, 12:29pm UTC](https://discuss.elastic.co/t/version-conflict-engine-exception-help-me/312065 "2022-08-14T12:29:17Z")

</div>

Elasticsearch Version 7.1.1 client: public void index(List\<PromoSkuInfoEsEntry\> promoSkuInfoEsEntries) throws IOException { BulkRequest request = new BulkRequest(); List\<List\<PromoSkuInfoEsEntry\>\> list…

---

## [Kibana 7.17.1 -- can't find index pattern uuids?](https://discuss.elastic.co/t/kibana-7-17-1-cant-find-index-pattern-uuids/312059)

<div class="topic-metadata">

**Author:** [@Russell\_Fulton](https://discuss.elastic.co/u/Russell_Fulton)\
**Replies:** 1\
**Last updated:** [August 13, 2022, 10:25pm UTC](https://discuss.elastic.co/t/kibana-7-17-1-cant-find-index-pattern-uuids/312059 "2022-08-13T22:25:23Z")

</div>

On several occasions with older release I have exported saved objects fiddled with the pattern uuid and then imported them back. I am now doing a major migration of dashboards where I need to change the index patterns, …

---

## [Help to parse date time](https://discuss.elastic.co/t/help-to-parse-date-time/312045)

<div class="topic-metadata">

**Author:** [@Claudio\_Ract\_Costa](https://discuss.elastic.co/u/Claudio_Ract_Costa)\
**Replies:** 1\
**Last updated:** [August 13, 2022, 4:15pm UTC](https://discuss.elastic.co/t/help-to-parse-date-time/312045 "2022-08-13T16:15:47Z")

</div>

Hi, I am trying to parse datetime bellow on logstash but i couldnt. The line is: "Aug 13, 2022 02:24:02.532177318 -03"|10.191.69.248|60542|10.110.62.45|3868|||PABLM01-SAECIS01-Gx-Openet;787252731;575065246;62f6e893-9…

---

## [When sorting by distance truncating the distance sort value for fallback sort criteria](https://discuss.elastic.co/t/when-sorting-by-distance-truncating-the-distance-sort-value-for-fallback-sort-criteria/312055)

<div class="topic-metadata">

**Author:** [@quesurifn](https://discuss.elastic.co/u/quesurifn)\
**Replies:** 0\
**Last updated:** [August 13, 2022, 2:50pm UTC](https://discuss.elastic.co/t/when-sorting-by-distance-truncating-the-distance-sort-value-for-fallback-sort-criteria/312055 "2022-08-13T14:50:21Z")

</div>

Hello all, We're sorting with elasticsearch like so: { "size": 300, "from": 0, "sort": \[ { "\_geo\_distance": { "geoLocation": { "lat": 29.7407, …

---

## [Remove Arguments from URI in kibana visualization](https://discuss.elastic.co/t/remove-arguments-from-uri-in-kibana-visualization/312053)

<div class="topic-metadata">

**Author:** [@Vaibhav\_Mathur1](https://discuss.elastic.co/u/Vaibhav_Mathur1)\
**Replies:** 0\
**Last updated:** [August 13, 2022, 12:37pm UTC](https://discuss.elastic.co/t/remove-arguments-from-uri-in-kibana-visualization/312053 "2022-08-13T12:37:09Z")

</div>

I am creating a visualisation with counting total urls hits I am able to get all urls and counts but i am getting url with arguments as below ur1?a=1. =\> count 100 url1?b=2 =\> count 100 what i want is url1 =\> co…

---

## [Ece proxy 9200 Connection reset by peer](https://discuss.elastic.co/t/ece-proxy-9200-connection-reset-by-peer/311889)

<div class="topic-metadata">

**Author:** [@bxl](https://discuss.elastic.co/u/bxl)\
**Replies:** 1\
**Last updated:** [August 13, 2022, 3:47am UTC](https://discuss.elastic.co/t/ece-proxy-9200-connection-reset-by-peer/311889 "2022-08-13T03:47:34Z")

</div>

ece version: 2.3.1 os: CentOS Linux release 7.9.2009 (Core) #curl 127.0.0.1:9200 curl: (56) Recv failure: Connection reset by peer proxy error log \[2022-08-11 01:19:54,648\]\[ERROR\]\[akka.io.SelectionHandler$$anon$1\] a…

---

## [Getting exception while searching search as type field type](https://discuss.elastic.co/t/getting-exception-while-searching-search-as-type-field-type/310839)

<div class="topic-metadata">

**Author:** [@Munish\_Bhardwaj](https://discuss.elastic.co/u/Munish_Bhardwaj)\
**Replies:** 1\
**Last updated:** [August 13, 2022, 2:04am UTC](https://discuss.elastic.co/t/getting-exception-while-searching-search-as-type-field-type/310839 "2022-08-13T02:04:16Z")

</div>

I have a requirement where I need to implement search recommendations and I have opted for the search as you type field. My existing mapping for the field was "text" and now I have changed it to "search\_as\_you\_type" and …

---

## [\_meta: Root mapping definition has unsupported parameters](https://discuss.elastic.co/t/meta-root-mapping-definition-has-unsupported-parameters/311024)

<div class="topic-metadata">

**Author:** [@NLSVTN](https://discuss.elastic.co/u/NLSVTN)\
**Replies:** 5\
**Last updated:** [August 13, 2022, 12:00am UTC](https://discuss.elastic.co/t/meta-root-mapping-definition-has-unsupported-parameters/311024 "2022-08-13T00:00:27Z")

</div>

I have ES7. Currently the mapping looks like: { 'mappings': { 'properties': { 'aIndex': {'type': 'integer'}, 'AC': {'type': 'integer'}, 'AF': {'type': 'double'}, ... …

---

## [Report of Total Inventory](https://discuss.elastic.co/t/report-of-total-inventory/310496)

<div class="topic-metadata">

**Author:** [@Ashish10195](https://discuss.elastic.co/u/Ashish10195)\
**Replies:** 0\
**Last updated:** [July 25, 2022, 4:57am UTC](https://discuss.elastic.co/t/report-of-total-inventory/310496 "2022-07-25T04:57:43Z")

</div>

Hi ,How can we download/Export total devices inventory on which Agent is installed .

---

## [How enable syntax error](https://discuss.elastic.co/t/how-enable-syntax-error/311270)

<div class="topic-metadata">

**Author:** [@tomASZ1](https://discuss.elastic.co/u/tomASZ1)\
**Replies:** 1\
**Last updated:** [August 12, 2022, 10:30pm UTC](https://discuss.elastic.co/t/how-enable-syntax-error/311270 "2022-08-12T22:30:36Z")

</div>

hi i use ace in kibana but hi dont show my syntax in ace is this option \<EuiCodeEditor mode="yaml" theme={chrome.getUiSettingsClient().get('theme:darkMode') ? 'dracula' : 'github'} width="1…

---

## [Simple query giving error: Query contains too many nested clauses](https://discuss.elastic.co/t/simple-query-giving-error-query-contains-too-many-nested-clauses/310779)

<div class="topic-metadata">

**Author:** [@gabrsar](https://discuss.elastic.co/u/gabrsar)\
**Replies:** 1\
**Last updated:** [August 12, 2022, 10:24pm UTC](https://discuss.elastic.co/t/simple-query-giving-error-query-contains-too-many-nested-clauses/310779 "2022-08-12T22:24:31Z")

</div>

Hi! A few weeks ago I started noticing that any query I made with more than one word give me the error "Query contains too many nested clauses; maxClauseCount is set to 1024". I'm doing something wrong? Example of quer…

---

## [Kibana drill-down Single click vs Context menu trigger on maps](https://discuss.elastic.co/t/kibana-drill-down-single-click-vs-context-menu-trigger-on-maps/311379)

<div class="topic-metadata">

**Author:** [@petersedivec](https://discuss.elastic.co/u/petersedivec)\
**Replies:** 1\
**Last updated:** [August 12, 2022, 10:18pm UTC](https://discuss.elastic.co/t/kibana-drill-down-single-click-vs-context-menu-trigger-on-maps/311379 "2022-08-12T22:18:20Z")

</div>

We're using 7.17 and I'm trying to understand in Kibana drilldowns the option between Single click and Context menu when creating a drill-down. I am using drill-downs on maps and I have a working "Go to URL" drill down …

---

## [Need a customize scale for showing colors & labels in Heat Map](https://discuss.elastic.co/t/need-a-customize-scale-for-showing-colors-labels-in-heat-map/311365)

<div class="topic-metadata">

**Author:** [@SunderRajan](https://discuss.elastic.co/u/SunderRajan)\
**Replies:** 1\
**Last updated:** [August 12, 2022, 10:02pm UTC](https://discuss.elastic.co/t/need-a-customize-scale-for-showing-colors-labels-in-heat-map/311365 "2022-08-12T22:02:20Z")

</div>

Hi Team, We're exploring the possibilities for using ELK for one of our requirement. We need the heat map visualization as part of our Dashboard. Currently in HeatMap, Labels are displayed based on Data Aggregation and…

[Previous page](https://discuss.elastic.co/tag/none.md?no_tags=true&page=560)

[Next page](https://discuss.elastic.co/tag/none.md?no_tags=true&page=562)
