# \#none

**URL:** https://discuss.elastic.co/tag/none.md?no_tags=true&page=568

[Latest](https://discuss.elastic.co/latest.md) · [Categories](https://discuss.elastic.co/categories.md) · [Tags](https://discuss.elastic.co/tags.md)

**Page:** 569

---

## [How to get the sum in time of values in Lens](https://discuss.elastic.co/t/how-to-get-the-sum-in-time-of-values-in-lens/310735)

<div class="topic-metadata">

**Author:** [@its-ogawa](https://discuss.elastic.co/u/its-ogawa)\
**Replies:** 51\
**Last updated:** [August 5, 2022, 6:13am UTC](https://discuss.elastic.co/t/how-to-get-the-sum-in-time-of-values-in-lens/310735 "2022-08-05T06:13:32Z")

</div>

I collect logs in Elasticsearch and keep track of certain values in the logs with fields. Since the values are numeric, I would like to calculate the sum over a certain time interval and see the transition. However, wh…

---

## [SIEM alert based on CVE](https://discuss.elastic.co/t/siem-alert-based-on-cve/311251)

<div class="topic-metadata">

**Author:** [@n2x4](https://discuss.elastic.co/u/n2x4)\
**Replies:** 7\
**Last updated:** [August 5, 2022, 2:23am UTC](https://discuss.elastic.co/t/siem-alert-based-on-cve/311251 "2022-08-05T02:23:57Z")

</div>

I'm currently ingesting vulnerability data into elastic, including CVE ID. I would like to generate an alert whenever a vulnerabilty is ingested that shows up on a predefined list of "priority" CVEs. I'm not quite sure …

---

## [How to display data compared to yesterday?](https://discuss.elastic.co/t/how-to-display-data-compared-to-yesterday/311455)

<div class="topic-metadata">

**Author:** [@Kibanosi](https://discuss.elastic.co/u/Kibanosi)\
**Replies:** 1\
**Last updated:** [August 4, 2022, 11:38pm UTC](https://discuss.elastic.co/t/how-to-display-data-compared-to-yesterday/311455 "2022-08-04T23:38:52Z")

</div>

Hi, I'm looking for a dashboard view. Is there a way to display for example today's data and then show the data in percentage from yesterday like in this image?

---

## [Logstash http input plugin, 429 busy and max\_pending\_requests](https://discuss.elastic.co/t/logstash-http-input-plugin-429-busy-and-max-pending-requests/311462)

<div class="topic-metadata">

**Author:** [@dorth](https://discuss.elastic.co/u/dorth)\
**Replies:** 0\
**Last updated:** [August 4, 2022, 10:20pm UTC](https://discuss.elastic.co/t/logstash-http-input-plugin-429-busy-and-max-pending-requests/311462 "2022-08-04T22:20:42Z")

</div>

I am using the Logstash Http Input Plugin to receive logging data from an API Gateway (Apigee) and then send it into various S3 buckets. There are 6 Logstash nodes (m5.large 2 CPU/8 GB) sitting behind an AWS Application…

---

## [Documents not showing up in Discover, but are showing up in queries in Dev Tools](https://discuss.elastic.co/t/documents-not-showing-up-in-discover-but-are-showing-up-in-queries-in-dev-tools/311451)

<div class="topic-metadata">

**Author:** [@Arjun\_Meena](https://discuss.elastic.co/u/Arjun_Meena)\
**Replies:** 10\
**Last updated:** [August 4, 2022, 9:19pm UTC](https://discuss.elastic.co/t/documents-not-showing-up-in-discover-but-are-showing-up-in-queries-in-dev-tools/311451 "2022-08-04T21:19:07Z")

</div>

I have an index spoms-audit-2022.08.04 in which there are 4 documents. When I search them from the dev console, i am able to see all the documents. Below is the search query: These are the results I get back: As…

---

## [New Elasticsearch 8 Java API - Insert date time field](https://discuss.elastic.co/t/new-elasticsearch-8-java-api-insert-date-time-field/311351)

<div class="topic-metadata">

**Author:** [@zxuz111](https://discuss.elastic.co/u/zxuz111)\
**Replies:** 1\
**Last updated:** [August 4, 2022, 9:10pm UTC](https://discuss.elastic.co/t/new-elasticsearch-8-java-api-insert-date-time-field/311351 "2022-08-04T21:10:46Z")

</div>

I am using the new Elasticsearch 8 Java client API to persist document that contains datetime field. Also, this is a spring boot application. The issue I got is, if I set a field as LocalDateTime, and try to save to Ela…

---

## [If Condition in JSON filter](https://discuss.elastic.co/t/if-condition-in-json-filter/311456)

<div class="topic-metadata">

**Author:** [@sta02](https://discuss.elastic.co/u/sta02)\
**Replies:** 5\
**Last updated:** [August 4, 2022, 8:10pm UTC](https://discuss.elastic.co/t/if-condition-in-json-filter/311456 "2022-08-04T20:10:15Z")

</div>

Hello, I am ingesting JSON data to logstash, and I am using JSON filter. In the JSON data, when the KEY is either Value 1 or Value 2, I should add a field, and if this key is missing in the logs, I will have to drop it…

---

## [Create a field such that lookup is faster on that field](https://discuss.elastic.co/t/create-a-field-such-that-lookup-is-faster-on-that-field/311449)

<div class="topic-metadata">

**Author:** [@Aditya\_Verma2](https://discuss.elastic.co/u/Aditya_Verma2)\
**Replies:** 5\
**Last updated:** [August 4, 2022, 7:28pm UTC](https://discuss.elastic.co/t/create-a-field-such-that-lookup-is-faster-on-that-field/311449 "2022-08-04T19:28:02Z")

</div>

Is there any way i can keep a field and its mapping in memory or cached so that lookup on the basis of that field is faster even though there may be more than 1000 clauses specified for that field in search query.

---

## [Prune Plugin error](https://discuss.elastic.co/t/prune-plugin-error/311323)

<div class="topic-metadata">

**Author:** [@sta02](https://discuss.elastic.co/u/sta02)\
**Replies:** 4\
**Last updated:** [August 4, 2022, 6:09pm UTC](https://discuss.elastic.co/t/prune-plugin-error/311323 "2022-08-04T18:09:50Z")

</div>

Hello, I am trying to use Prune filter to parse the data because the data format is foo:bar, but I am unsuccessful. I am getting the below error. The configuration is working without the prune filter. Please advise on …

---

## [ELK-functionbeat-not-able-to-push-data](https://discuss.elastic.co/t/elk-functionbeat-not-able-to-push-data/311333)

<div class="topic-metadata">

**Author:** [@sadik](https://discuss.elastic.co/u/sadik)\
**Replies:** 0\
**Last updated:** [August 3, 2022, 5:28pm UTC](https://discuss.elastic.co/t/elk-functionbeat-not-able-to-push-data/311333 "2022-08-03T17:28:15Z")

</div>

Hello Team, We are facing the below error in AWS function beat lambda. Cannot index event publisher.Event{Content:beat.Event More error details as below: Error: 2022-07-22T15:15:01.087Z WARN \[elasticsearch\] elasticse…

---

## [Pattern to extract specific integer and string](https://discuss.elastic.co/t/pattern-to-extract-specific-integer-and-string/311332)

<div class="topic-metadata">

**Author:** [@Aniket\_Pant](https://discuss.elastic.co/u/Aniket_Pant)\
**Replies:** 6\
**Last updated:** [August 4, 2022, 3:57pm UTC](https://discuss.elastic.co/t/pattern-to-extract-specific-integer-and-string/311332 "2022-08-04T15:57:59Z")

</div>

Input: CEES:1.0|NGINX|NGINX|1.17.6|400|devTime=03/Aug Output response\_code: 400 message: devTime=03/Aug Pattern i have applied ^LEEF.\*\\|%{INT:response\_code}%{GREEDYDATA:log\_message Output i got response\_code: 400 …

---

## [Highlighting using words from another field](https://discuss.elastic.co/t/highlighting-using-words-from-another-field/311444)

<div class="topic-metadata">

**Author:** [@stobyer](https://discuss.elastic.co/u/stobyer)\
**Replies:** 0\
**Last updated:** [August 4, 2022, 2:52pm UTC](https://discuss.elastic.co/t/highlighting-using-words-from-another-field/311444 "2022-08-04T14:52:12Z")

</div>

Hello, I'm trying to highlight text using words from other field. What do I mean? I have a documents similar to the following: { property: 1, content: "a lot of animals including cats and dogs", keywords: \["cat", "…

---

## [RUM and React-Native](https://discuss.elastic.co/t/rum-and-react-native/310648)

<div class="topic-metadata">

**Author:** [@abeasley](https://discuss.elastic.co/u/abeasley)\
**Replies:** 0\
**Last updated:** [July 26, 2022, 1:47pm UTC](https://discuss.elastic.co/t/rum-and-react-native/310648 "2022-07-26T13:47:43Z")

</div>

I'm researching adding Elastic logging to our application which is written in React-Native. It appears that the RUM integration for the Elastic Agent has everything we are looking for but there doesn't appear to be a cu…

---

## [ElasticSearch on Kubernetes (ECK): Enable OR Disable cluster-autoscaler.kubernetes.io/safe-to-evict](https://discuss.elastic.co/t/elasticsearch-on-kubernetes-eck-enable-or-disable-cluster-autoscaler-kubernetes-io-safe-to-evict/311431)

<div class="topic-metadata">

**Author:** [@aqueous](https://discuss.elastic.co/u/aqueous)\
**Replies:** 0\
**Last updated:** [August 4, 2022, 1:44pm UTC](https://discuss.elastic.co/t/elasticsearch-on-kubernetes-eck-enable-or-disable-cluster-autoscaler-kubernetes-io-safe-to-evict/311431 "2022-08-04T13:44:03Z")

</div>

I am using the Elastic on Kubernetes (operator version 2.1). How can I enable or disable the following annotation on the ElasticSearch nodes managed by ECK? "cluster-autoscaler.kubernetes.io/safe-to-evict": \<Set it to …

---

## [New Elasticsearch 8 Java API - Sort by](https://discuss.elastic.co/t/new-elasticsearch-8-java-api-sort-by/311352)

<div class="topic-metadata">

**Author:** [@zxuz111](https://discuss.elastic.co/u/zxuz111)\
**Replies:** 4\
**Last updated:** [August 4, 2022, 1:33pm UTC](https://discuss.elastic.co/t/new-elasticsearch-8-java-api-sort-by/311352 "2022-08-04T13:33:28Z")

</div>

I am using the new Elasticsearch 8 Java client API to query data and sort by one field. esClient.search(s -\> { return s .index("employee") .query(q -\> q …

---

## [MUTIPULE VALUES SEARCH](https://discuss.elastic.co/t/mutipule-values-search/311422)

<div class="topic-metadata">

**Author:** [@shanker241](https://discuss.elastic.co/u/shanker241)\
**Replies:** 0\
**Last updated:** [August 4, 2022, 1:08pm UTC](https://discuss.elastic.co/t/mutipule-values-search/311422 "2022-08-04T13:08:11Z")

</div>

HI ALL, I Unable to search with mutipule values Please find the follwoing code its not working . function getRiskRegister(monthYear) { const client = new elasticsearch.Client({ host: elasticHost }); monthYear = 'Ma…

---

## [Logstash filling up my space inside/var/log/messages file](https://discuss.elastic.co/t/logstash-filling-up-my-space-inside-var-log-messages-file/311415)

<div class="topic-metadata">

**Author:** [@zanoob](https://discuss.elastic.co/u/zanoob)\
**Replies:** 1\
**Last updated:** [August 4, 2022, 1:06pm UTC](https://discuss.elastic.co/t/logstash-filling-up-my-space-inside-var-log-messages-file/311415 "2022-08-04T13:06:39Z")

</div>

Hello all, I been tying to find a solution for this since long. Trying to reach out to the community. The logstash is filling up the file /var/log/messages file space, I understand logstash does not log to /var/log/me…

---

## [I cant acces Elasticsearch via Webrowser](https://discuss.elastic.co/t/i-cant-acces-elasticsearch-via-webrowser/311402)

<div class="topic-metadata">

**Author:** [@notaelasticsearcher](https://discuss.elastic.co/u/notaelasticsearcher)\
**Replies:** 4\
**Last updated:** [August 4, 2022, 12:44pm UTC](https://discuss.elastic.co/t/i-cant-acces-elasticsearch-via-webrowser/311402 "2022-08-04T12:44:47Z")

</div>

I use elasticsearch 8.3.3. When i type curl -X GET "localhost:9200" { "name" : "elkvm", "cluster\_name" : "elasticsearch", "cluster\_uuid" : "P\_UJ2AcOSRmj3AWwMylLvQ", "version" : { "number" : "8.3.3", "bui…

---

## [Duplicate field.keyword and field in data stream within Observability](https://discuss.elastic.co/t/duplicate-field-keyword-and-field-in-data-stream-within-observability/311383)

<div class="topic-metadata">

**Author:** [@Mark\_Rodman](https://discuss.elastic.co/u/Mark_Rodman)\
**Replies:** 1\
**Last updated:** [August 4, 2022, 12:44pm UTC](https://discuss.elastic.co/t/duplicate-field-keyword-and-field-in-data-stream-within-observability/311383 "2022-08-04T12:44:26Z")

</div>

Hi, I recently moved an existing configuration of Logstash indexing to a setup with Logstash using a data stream with component templates. As recommended the component template was broken down into two templates, one fo…

---

## [Rollover policy is not working](https://discuss.elastic.co/t/rollover-policy-is-not-working/311377)

<div class="topic-metadata">

**Author:** [@Ankit\_Grover](https://discuss.elastic.co/u/Ankit_Grover)\
**Replies:** 6\
**Last updated:** [August 4, 2022, 12:14pm UTC](https://discuss.elastic.co/t/rollover-policy-is-not-working/311377 "2022-08-04T12:14:50Z")

</div>

my rollover policy is not working after the condition fail of 2mb document size can anyone please help me. I am newbie in elk stack. Thanks

---

## [Failed to parse field](https://discuss.elastic.co/t/failed-to-parse-field/311392)

<div class="topic-metadata">

**Author:** [@Kevin\_Galarza](https://discuss.elastic.co/u/Kevin_Galarza)\
**Replies:** 2\
**Last updated:** [August 4, 2022, 11:13am UTC](https://discuss.elastic.co/t/failed-to-parse-field/311392 "2022-08-04T11:13:03Z")

</div>

---

## [If condition in logstash output doesn't work](https://discuss.elastic.co/t/if-condition-in-logstash-output-doesnt-work/311276)

<div class="topic-metadata">

**Author:** [@zzcpower](https://discuss.elastic.co/u/zzcpower)\
**Replies:** 8\
**Last updated:** [August 4, 2022, 11:05am UTC](https://discuss.elastic.co/t/if-condition-in-logstash-output-doesnt-work/311276 "2022-08-04T11:05:58Z")

</div>

The config file is shown as below input { kafka { bootstrap\_servers =\> "localhost:9092" group\_id =\> "log\_monitor" auto\_offset\_reset =\> "latest" consumer\_threads =\> 1 topics =\> \["test\_log"\] } } f…

---

## [Порядок слов в полнотекстном поиске](https://discuss.elastic.co/t/topic/310239)

<div class="topic-metadata">

**Author:** [@Evgeny\_Antipin](https://discuss.elastic.co/u/Evgeny_Antipin)\
**Replies:** 4\
**Last updated:** [August 4, 2022, 11:00am UTC](https://discuss.elastic.co/t/topic/310239 "2022-08-04T11:00:54Z")

</div>

Доброго дня. Есть такой индекс: { "ta": { "mappings": { "properties": { "address": { "type": "text" }, "obj\_id": { …

---

## [Could not find or load main class "-](https://discuss.elastic.co/t/could-not-find-or-load-main-class/311307)

<div class="topic-metadata">

**Author:** [@AULIA\_KHOIRUN\_NISA\_N](https://discuss.elastic.co/u/AULIA_KHOIRUN_NISA_N)\
**Replies:** 10\
**Last updated:** [August 4, 2022, 9:39am UTC](https://discuss.elastic.co/t/could-not-find-or-load-main-class/311307 "2022-08-04T09:39:04Z")

</div>

''' can anybody help me, cause I'm trying to start elasticsearch bu it did't work Job for elasticsearch.service failed because the control process exited with error code. See "systemctl status elasticsearch.service" and…

---

## [Custom Aggregations in ES](https://discuss.elastic.co/t/custom-aggregations-in-es/311385)

<div class="topic-metadata">

**Author:** [@vishnu\_teja](https://discuss.elastic.co/u/vishnu_teja)\
**Replies:** 3\
**Last updated:** [August 4, 2022, 9:18am UTC](https://discuss.elastic.co/t/custom-aggregations-in-es/311385 "2022-08-04T09:18:31Z")

</div>

Hi, I would like to know, if we can have custom aggregations in ElasticSearch, For EX: we have a use-case where we need a function like any\_value(), it works like this: Say I have the following documents in my index: {…

---

## [Kibana APIs: No handler found for uri](https://discuss.elastic.co/t/kibana-apis-no-handler-found-for-uri/310971)

<div class="topic-metadata">

**Author:** [@aman\_mahajan](https://discuss.elastic.co/u/aman_mahajan)\
**Replies:** 1\
**Last updated:** [August 4, 2022, 8:57am UTC](https://discuss.elastic.co/t/kibana-apis-no-handler-found-for-uri/310971 "2022-08-04T08:57:26Z")

</div>

Hi, I am trying to do a curl request to the Kibana APIs but getting error that the handler does not exist. For eg. curl -H 'kbn-xsrf: true' -H "Authorization: Basic \<token\>" \<kibana\_host\>:\<kibana\_port\>/api/saved\_objects…

---

## [Getting 403 forbidden error while starting service for uptime monitoring](https://discuss.elastic.co/t/getting-403-forbidden-error-while-starting-service-for-uptime-monitoring/310812)

<div class="topic-metadata">

**Author:** [@amseshadri](https://discuss.elastic.co/u/amseshadri)\
**Replies:** 3\
**Last updated:** [August 4, 2022, 8:49am UTC](https://discuss.elastic.co/t/getting-403-forbidden-error-while-starting-service-for-uptime-monitoring/310812 "2022-08-04T08:49:53Z")

</div>

Hi, I am trying to setup Uptime Monitoring for our application URL, and trying to setup the Elastic Observability Uptime Monitoring. While executing the below getting 403 Forbidden Error: .\\heartbeat.exe setup Error: …

---

## [Compare two indexes different field value](https://discuss.elastic.co/t/compare-two-indexes-different-field-value/311303)

<div class="topic-metadata">

**Author:** [@alex\_vermex](https://discuss.elastic.co/u/alex_vermex)\
**Replies:** 2\
**Last updated:** [August 4, 2022, 8:40am UTC](https://discuss.elastic.co/t/compare-two-indexes-different-field-value/311303 "2022-08-04T08:40:11Z")

</div>

Hi, i would like to know if it is possible to compare field.value with different indexes i mean for example i have index1 and index2 and each index has fields so i want to compare field value of index1 with field value …

---

## [Query returns empty result when filtering on labels and timestamp](https://discuss.elastic.co/t/query-returns-empty-result-when-filtering-on-labels-and-timestamp/311305)

<div class="topic-metadata">

**Author:** [@ithline](https://discuss.elastic.co/u/ithline)\
**Replies:** 3\
**Last updated:** [August 4, 2022, 8:38am UTC](https://discuss.elastic.co/t/query-returns-empty-result-when-filtering-on-labels-and-timestamp/311305 "2022-08-04T08:38:11Z")

</div>

Hello there, I'm having some problems with querying in Kibana, so I tried to create manual query using the /\_search API. My index template is composed of .alerts-ecs-mappings, logs-mappings and logs-settings component …

---

## [How to visualise data geometric point](https://discuss.elastic.co/t/how-to-visualise-data-geometric-point/311345)

<div class="topic-metadata">

**Author:** [@5k\_pwc](https://discuss.elastic.co/u/5k_pwc)\
**Replies:** 1\
**Last updated:** [August 4, 2022, 8:19am UTC](https://discuss.elastic.co/t/how-to-visualise-data-geometric-point/311345 "2022-08-04T08:19:22Z")

</div>

Hi, i would visualise my field 'geom' in kibana , but i have no idea at the moment have some one any solution

[Previous page](https://discuss.elastic.co/tag/none.md?no_tags=true&page=567)

[Next page](https://discuss.elastic.co/tag/none.md?no_tags=true&page=569)
