# \#none

**URL:** https://discuss.elastic.co/tag/none.md?no_tags=true&page=563

[Latest](https://discuss.elastic.co/latest.md) · [Categories](https://discuss.elastic.co/categories.md) · [Tags](https://discuss.elastic.co/tags.md)

**Page:** 564

---

## [How to move data from cold to warm tier](https://discuss.elastic.co/t/how-to-move-data-from-cold-to-warm-tier/311767)

<div class="topic-metadata">

**Author:** [@INS](https://discuss.elastic.co/u/INS)\
**Replies:** 7\
**Last updated:** [August 12, 2022, 6:35am UTC](https://discuss.elastic.co/t/how-to-move-data-from-cold-to-warm-tier/311767 "2022-08-12T06:35:22Z")

</div>

Hi I need to remove cold data tiers, then in this action I thought about shifting data tier from cold to warm? How I can handle such case?

---

## [Issues with Cisco Umbrella integration - Cisco-managed s3 bucket url's getting leading "s3." appended after https](https://discuss.elastic.co/t/issues-with-cisco-umbrella-integration-cisco-managed-s3-bucket-urls-getting-leading-s3-appended-after-https/311978)

<div class="topic-metadata">

**Author:** [@ethhack](https://discuss.elastic.co/u/ethhack)\
**Replies:** 0\
**Last updated:** [August 12, 2022, 5:29am UTC](https://discuss.elastic.co/t/issues-with-cisco-umbrella-integration-cisco-managed-s3-bucket-urls-getting-leading-s3-appended-after-https/311978 "2022-08-12T05:29:49Z")

</div>

Error message received when trying to configure the Umbrella integration with a Cisco-managed s3 bucket: Input 'aws-s3' failed with: failed to initialize s3 poller: failed to get AWS region for bucket: exceeded maximum …

---

## [Cluster Level Replica settings](https://discuss.elastic.co/t/cluster-level-replica-settings/311976)

<div class="topic-metadata">

**Author:** [@benedictDTony](https://discuss.elastic.co/u/benedictDTony)\
**Replies:** 0\
**Last updated:** [August 12, 2022, 5:12am UTC](https://discuss.elastic.co/t/cluster-level-replica-settings/311976 "2022-08-12T05:12:48Z")

</div>

Hi, I would like to set replica settings at the cluster level instead of index level. Despite the template settings I would like my indices to be created with 0 replicas. Could someone help me how to achieve this, h…

---

## [Geo\_bounds aggregation returns empty data for Multi-Polygon Country Geometries](https://discuss.elastic.co/t/geo-bounds-aggregation-returns-empty-data-for-multi-polygon-country-geometries/311886)

<div class="topic-metadata">

**Author:** [@corndog](https://discuss.elastic.co/u/corndog)\
**Replies:** 1\
**Last updated:** [August 12, 2022, 5:04am UTC](https://discuss.elastic.co/t/geo-bounds-aggregation-returns-empty-data-for-multi-polygon-country-geometries/311886 "2022-08-12T05:04:03Z")

</div>

geo\_bounds aggregation fails to generate geo\_bounds for SOME countries (large countries?) in my dataset, how can I fix this\>? My example query against a country "New Zealand" GET countries/\_search { "query": { …

---

## [Export results from query that is more than the default maxClauseCount](https://discuss.elastic.co/t/export-results-from-query-that-is-more-than-the-default-maxclausecount/311925)

<div class="topic-metadata">

**Author:** [@xynobob](https://discuss.elastic.co/u/xynobob)\
**Replies:** 0\
**Last updated:** [August 11, 2022, 12:21pm UTC](https://discuss.elastic.co/t/export-results-from-query-that-is-more-than-the-default-maxclausecount/311925 "2022-08-11T12:21:05Z")

</div>

Hi, I have this issue where for my needs, I am required to export all the rules from Elastic Security and keep it locally which I use this command to achieve it - POST api/detection\_engine/rules/\_export. However the mai…

---

## [Analyze the logs in Storage utilization](https://discuss.elastic.co/t/analyze-the-logs-in-storage-utilization/311848)

<div class="topic-metadata">

**Author:** [@Aravind1](https://discuss.elastic.co/u/Aravind1)\
**Replies:** 1\
**Last updated:** [August 12, 2022, 1:44am UTC](https://discuss.elastic.co/t/analyze-the-logs-in-storage-utilization/311848 "2022-08-12T01:44:16Z")

</div>

Hi, We are having a few queries on Elasticsearch logs optimization, we are doing the cost optimization and we want to know how to analyze the logs based on the storage utilization and also to know more about how many u…

---

## [Kibana Server not ready yet](https://discuss.elastic.co/t/kibana-server-not-ready-yet/311864)

<div class="topic-metadata">

**Author:** [@Naldo001](https://discuss.elastic.co/u/Naldo001)\
**Replies:** 1\
**Last updated:** [August 12, 2022, 1:34am UTC](https://discuss.elastic.co/t/kibana-server-not-ready-yet/311864 "2022-08-12T01:34:00Z")

</div>

kibana.service - Kibana Loaded: loaded (/usr/lib/systemd/system/kibana.service; enabled; vendor preset: disabled) Active: active (running) since Wed 2022-08-10 13:03:46 EDT; 20min ago Docs: https://www.elasti…

---

## [Create visualize -\> Success rate based on time](https://discuss.elastic.co/t/create-visualize-success-rate-based-on-time/311203)

<div class="topic-metadata">

**Author:** [@ShayWeizman](https://discuss.elastic.co/u/ShayWeizman)\
**Replies:** 3\
**Last updated:** [August 12, 2022, 1:10am UTC](https://discuss.elastic.co/t/create-visualize-success-rate-based-on-time/311203 "2022-08-12T01:10:25Z")

</div>

Hi, I'm using 7.16.2, here are the fields I've in my index... it holding data on builds in Jenkins.. build number, status: pass or fail... I need to create a graph of success rate based on time.. for example: % of the …

---

## [Elastic Siem external alerts](https://discuss.elastic.co/t/elastic-siem-external-alerts/310918)

<div class="topic-metadata">

**Author:** [@abr4xc](https://discuss.elastic.co/u/abr4xc)\
**Replies:** 4\
**Last updated:** [August 11, 2022, 7:58pm UTC](https://discuss.elastic.co/t/elastic-siem-external-alerts/310918 "2022-08-11T19:58:33Z")

</div>

I am trying to set up a new integration for an EDR that is not listed on the Kibana integrations yet, in order to set up the external alerts for that EDR i am adding the event.kind to alert but its not showing up in the …

---

## [To convert the Integers into a String](https://discuss.elastic.co/t/to-convert-the-integers-into-a-string/311936)

<div class="topic-metadata">

**Author:** [@Maruthappan\_Muthu](https://discuss.elastic.co/u/Maruthappan_Muthu)\
**Replies:** 2\
**Last updated:** [August 11, 2022, 7:14pm UTC](https://discuss.elastic.co/t/to-convert-the-integers-into-a-string/311936 "2022-08-11T19:14:42Z")

</div>

I have collected the metrics from a device through snmp input plugin and the field value is 0 & 1. How can I convert these values into strings (like 0 as Open, 1 as Close) in Kibana dashboards.

---

## [Create document with values from parent aggregation and sub aggregation](https://discuss.elastic.co/t/create-document-with-values-from-parent-aggregation-and-sub-aggregation/311954)

<div class="topic-metadata">

**Author:** [@ElasticLiver](https://discuss.elastic.co/u/ElasticLiver)\
**Replies:** 1\
**Last updated:** [August 11, 2022, 5:50pm UTC](https://discuss.elastic.co/t/create-document-with-values-from-parent-aggregation-and-sub-aggregation/311954 "2022-08-11T17:50:38Z")

</div>

Hi, Im queriyng elastic with logstash, exec input, and a bash script with curl. this is the response: "aggregations" : { "parent-agg" : { "buckets" : \[ { "key" : "one", "sub-aggs-t…

---

## [Need file location where can i edit elastic and logo "e" on top right corner side header bar](https://discuss.elastic.co/t/need-file-location-where-can-i-edit-elastic-and-logo-e-on-top-right-corner-side-header-bar/311918)

<div class="topic-metadata">

**Author:** [@Ayaan\_Shaik](https://discuss.elastic.co/u/Ayaan_Shaik)\
**Replies:** 3\
**Last updated:** [August 11, 2022, 1:39pm UTC](https://discuss.elastic.co/t/need-file-location-where-can-i-edit-elastic-and-logo-e-on-top-right-corner-side-header-bar/311918 "2022-08-11T13:39:23Z")

</div>

Hi Friends, Trying to find the location of a file for the header top right elastic symbol replace and "e" in /usr/share/kibana/src/......?????? where can i find this location in /usr/share/kibana ??? below is the im…

---

## [Logstash WARN: Could not index event to Elasticsearch .... Can't get text on a START\_OBJECT](https://discuss.elastic.co/t/logstash-warn-could-not-index-event-to-elasticsearch-cant-get-text-on-a-start-object/311910)

<div class="topic-metadata">

**Author:** [@d.silwon](https://discuss.elastic.co/u/d.silwon)\
**Replies:** 2\
**Last updated:** [August 11, 2022, 1:32pm UTC](https://discuss.elastic.co/t/logstash-warn-could-not-index-event-to-elasticsearch-cant-get-text-on-a-start-object/311910 "2022-08-11T13:32:46Z")

</div>

Dears, I have some problem with json. When I send json log to logstash there are many errors like this: Could not index event to Elasticsearch .... Can't get text on a START\_OBJECT at 1:670 My json log looks like: {…

---

## [How to use http input logstash](https://discuss.elastic.co/t/how-to-use-http-input-logstash/311928)

<div class="topic-metadata">

**Author:** [@cihady](https://discuss.elastic.co/u/cihady)\
**Replies:** 1\
**Last updated:** [August 11, 2022, 1:19pm UTC](https://discuss.elastic.co/t/how-to-use-http-input-logstash/311928 "2022-08-11T13:19:55Z")

</div>

I am trying to api call logstash by using http input but when I run logstash it failse and throws the error below Here is my config file input { http { host=\>0.0.0.0 port =\>2020 } } output { elasticsearch { …

---

## [Problem with Detections - Custom query rule](https://discuss.elastic.co/t/problem-with-detections-custom-query-rule/311543)

<div class="topic-metadata">

**Author:** [@Yuriy\_Tsarenko](https://discuss.elastic.co/u/Yuriy_Tsarenko)\
**Replies:** 9\
**Last updated:** [August 11, 2022, 12:24pm UTC](https://discuss.elastic.co/t/problem-with-detections-custom-query-rule/311543 "2022-08-11T12:24:47Z")

</div>

Good afternoon dear community. I turn to you with the following problem. The custom rule does not create security alerts, although it works without visible errors. Kibana Version: 8.3.1 Rule type: custom query. Rule …

---

## [Documentation for dynamic template mappings?](https://discuss.elastic.co/t/documentation-for-dynamic-template-mappings/311746)

<div class="topic-metadata">

**Author:** [@nisow95612](https://discuss.elastic.co/u/nisow95612)\
**Replies:** 3\
**Last updated:** [August 11, 2022, 8:55am UTC](https://discuss.elastic.co/t/documentation-for-dynamic-template-mappings/311746 "2022-08-11T08:55:47Z")

</div>

Hello, I have trouble finding API documentation for setting dynamic templates. I expected this to be documented at Update mapping API | Elasticsearch Guide \[8.3\] | Elastic , but this just points to "mapping object" (A …

---

## [Illegal\_argument\_exception](https://discuss.elastic.co/t/illegal-argument-exception/311847)

<div class="topic-metadata">

**Author:** [@Carlos\_Vinicius](https://discuss.elastic.co/u/Carlos_Vinicius)\
**Replies:** 2\
**Last updated:** [August 11, 2022, 11:59am UTC](https://discuss.elastic.co/t/illegal-argument-exception/311847 "2022-08-11T11:59:12Z")

</div>

Dears, good morning! I'm facing the error below, can someone shed some light on me? { "took": 461, "timed\_out": false, "\_shards": { "total": 39, "successful": 38, "skipped": 33, "failed": 1, "failures": \[ { …

---

## [Connecting to ElasticSearch from Tableau Desktop](https://discuss.elastic.co/t/connecting-to-elasticsearch-from-tableau-desktop/311906)

<div class="topic-metadata">

**Author:** [@Naresh\_Vadla](https://discuss.elastic.co/u/Naresh_Vadla)\
**Replies:** 1\
**Last updated:** [August 11, 2022, 8:22am UTC](https://discuss.elastic.co/t/connecting-to-elasticsearch-from-tableau-desktop/311906 "2022-08-11T08:22:36Z")

</div>

I am trying to connect to Elasticsearch from Tableau Desktop. I am using Tableau Desktop 2021.x, Tableau Desktop 2022.x versions. My Elastic search version is 7.11.2. I have followed everything mentioned in But It is …

---

## [Add new document using logstash](https://discuss.elastic.co/t/add-new-document-using-logstash/311833)

<div class="topic-metadata">

**Author:** [@alex\_vermex](https://discuss.elastic.co/u/alex_vermex)\
**Replies:** 2\
**Last updated:** [August 11, 2022, 7:23am UTC](https://discuss.elastic.co/t/add-new-document-using-logstash/311833 "2022-08-11T07:23:52Z")

</div>

Hi, i have a file so i read this file using filebeat and i do the multilne like this filebeat.yml: - type: log enabled: true paths: - D:\\elastic\_stack\\logs\\\* fields: kafka\_topic: "kafka-topic-1" ta…

---

## [Does elasticsearch not support nfs as data directory?](https://discuss.elastic.co/t/does-elasticsearch-not-support-nfs-as-data-directory/311692)

<div class="topic-metadata">

**Author:** [@wajika](https://discuss.elastic.co/u/wajika)\
**Replies:** 7\
**Last updated:** [August 11, 2022, 6:30am UTC](https://discuss.elastic.co/t/does-elasticsearch-not-support-nfs-as-data-directory/311692 "2022-08-11T06:30:37Z")

</div>

es: 7.17.3 I mount the nfs path locally, and then point the es data directory to the location of the nfs, but the es startup fails, if I change the es data directory to a local partition (var/lib/elasticsearch) , then e…

---

## [Elastic Agent 8.3.3 on MacOS x509: “XYZR" certificate is not standards compliant](https://discuss.elastic.co/t/elastic-agent-8-3-3-on-macos-x509-xyzr-certificate-is-not-standards-compliant/311896)

<div class="topic-metadata">

**Author:** [@ajj31](https://discuss.elastic.co/u/ajj31)\
**Replies:** 0\
**Last updated:** [August 11, 2022, 6:16am UTC](https://discuss.elastic.co/t/elastic-agent-8-3-3-on-macos-x509-xyzr-certificate-is-not-standards-compliant/311896 "2022-08-11T06:16:34Z")

</div>

Hello Team, Fleet server is healthy and working well with Linux elastic agents. Only when i run an agent with another Agent policy for MacOS, I get this error. siza:elastic-agent-8.3.3-darwin-x86\_64 macZ$ sudo ./elast…

---

## [How to see the data from the time range \>=90 days in discover and alerting](https://discuss.elastic.co/t/how-to-see-the-data-from-the-time-range-90-days-in-discover-and-alerting/311783)

<div class="topic-metadata">

**Author:** [@muthusundar.p](https://discuss.elastic.co/u/muthusundar.p)\
**Replies:** 2\
**Last updated:** [August 11, 2022, 1:46am UTC](https://discuss.elastic.co/t/how-to-see-the-data-from-the-time-range-90-days-in-discover-and-alerting/311783 "2022-08-11T01:46:25Z")

</div>

Dear Experts, Please let us know how to see or set a dashboard to view greater than 90days of data. every time we select the time range in the discover option.

---

## [Veeam Logstash Grok](https://discuss.elastic.co/t/veeam-logstash-grok/311774)

<div class="topic-metadata">

**Author:** [@rcraigncs](https://discuss.elastic.co/u/rcraigncs)\
**Replies:** 16\
**Last updated:** [August 10, 2022, 10:57pm UTC](https://discuss.elastic.co/t/veeam-logstash-grok/311774 "2022-08-10T22:57:30Z")

</div>

Hello, I'm trying to grok logs from Veeam logs \> filebeat file stream \> logstash to create a better filter on logs collected from Veeam. I'm relatively new when it comes to grok and I'm stuck on how I would go about gro…

---

## [Change type character varying to date elasticsearch](https://discuss.elastic.co/t/change-type-character-varying-to-date-elasticsearch/311885)

<div class="topic-metadata">

**Author:** [@5k\_pwc](https://discuss.elastic.co/u/5k_pwc)\
**Replies:** 1\
**Last updated:** [August 10, 2022, 10:52pm UTC](https://discuss.elastic.co/t/change-type-character-varying-to-date-elasticsearch/311885 "2022-08-10T22:52:11Z")

</div>

hi , anyone know how to changed data from char to date, i have inserted this code but she doesnt work . "datecons" : { "type" : "date" "format": "yyyy-MM-dd HH:mm:ss.SSSSSS" }, and my data like this:

---

## [Scaling of the Elastic](https://discuss.elastic.co/t/scaling-of-the-elastic/311846)

<div class="topic-metadata">

**Author:** [@Aravind1](https://discuss.elastic.co/u/Aravind1)\
**Replies:** 1\
**Last updated:** [August 10, 2022, 9:40pm UTC](https://discuss.elastic.co/t/scaling-of-the-elastic/311846 "2022-08-10T21:40:04Z")

</div>

Hi, How to check the current usage of the Elasticsearch and is there any possibility to do the scaling of the elastic

---

## [Map - Filter by boundary, shape or line](https://discuss.elastic.co/t/map-filter-by-boundary-shape-or-line/311682)

<div class="topic-metadata">

**Author:** [@Matt.Wash](https://discuss.elastic.co/u/Matt.Wash)\
**Replies:** 2\
**Last updated:** [August 10, 2022, 9:35pm UTC](https://discuss.elastic.co/t/map-filter-by-boundary-shape-or-line/311682 "2022-08-10T21:35:32Z")

</div>

creating the filter for heat map geolocation is awesome, but how do i delete a filtered area? There doesn't appear to have the the same UI as noted below. I am running 8.3.3 Any ideas? Cheers, Matt

---

## [Apply "doesn't equal" with nested query](https://discuss.elastic.co/t/apply-doesnt-equal-with-nested-query/311821)

<div class="topic-metadata">

**Author:** [@Anh\_Le](https://discuss.elastic.co/u/Anh_Le)\
**Replies:** 1\
**Last updated:** [August 10, 2022, 9:13pm UTC](https://discuss.elastic.co/t/apply-doesnt-equal-with-nested-query/311821 "2022-08-10T21:13:56Z")

</div>

Hi there! Please help to suggest queries to get data. How to get documents that don't have FilterFields. ContentFieldUseID = 20 and FilterFields.ContentFieldValues = "aaaa@gmail.com". Expected result: I want to get two…

---

## [Connection error with ssh and pem file (FSCrawler)](https://discuss.elastic.co/t/connection-error-with-ssh-and-pem-file-fscrawler/311878)

<div class="topic-metadata">

**Author:** [@Doddy\_Joel](https://discuss.elastic.co/u/Doddy_Joel)\
**Replies:** 0\
**Last updated:** [August 10, 2022, 9:02pm UTC](https://discuss.elastic.co/t/connection-error-with-ssh-and-pem-file-fscrawler/311878 "2022-08-10T21:02:39Z")

</div>

I'm using FSCrawler by @dadoonet and I'm trying to connect directory with ssh. I have ssh configured on my server so I can access a directory and use FSCrawler. The steps I have followed are as follows: Create a publ…

---

## [Convert Kibana Visualize to elasticsearch dsl](https://discuss.elastic.co/t/convert-kibana-visualize-to-elasticsearch-dsl/311738)

<div class="topic-metadata">

**Author:** [@zys864](https://discuss.elastic.co/u/zys864)\
**Replies:** 3\
**Last updated:** [August 10, 2022, 4:09pm UTC](https://discuss.elastic.co/t/convert-kibana-visualize-to-elasticsearch-dsl/311738 "2022-08-10T16:09:02Z")

</div>

Kibana Visualize internally use \_msearch,How to convert a Kibana Visualize to elasticsearch \_msearch dsl.

---

## [Creating success rate based on boolean field](https://discuss.elastic.co/t/creating-success-rate-based-on-boolean-field/311812)

<div class="topic-metadata">

**Author:** [@frederico](https://discuss.elastic.co/u/frederico)\
**Replies:** 0\
**Last updated:** [August 10, 2022, 9:36am UTC](https://discuss.elastic.co/t/creating-success-rate-based-on-boolean-field/311812 "2022-08-10T09:36:30Z")

</div>

Hello, I'm using elk 7.11.2 I want to do a line chart where I plot a ratio over time of a certain boolean field. Ie, i want aggregate by time (minutes or hours) and plot the percentage of records where the boolean fie…

[Previous page](https://discuss.elastic.co/tag/none.md?no_tags=true&page=562)

[Next page](https://discuss.elastic.co/tag/none.md?no_tags=true&page=564)
