# \#none

**URL:** https://discuss.elastic.co/tag/none.md?no_tags=true&page=575

[Latest](https://discuss.elastic.co/latest.md) · [Categories](https://discuss.elastic.co/categories.md) · [Tags](https://discuss.elastic.co/tags.md)

**Page:** 576

---

## [Bug with legend when it's bottom](https://discuss.elastic.co/t/bug-with-legend-when-its-bottom/308663)

<div class="topic-metadata">

**Author:** [@franckfct](https://discuss.elastic.co/u/franckfct)\
**Replies:** 5\
**Last updated:** [July 27, 2022, 9:30am UTC](https://discuss.elastic.co/t/bug-with-legend-when-its-bottom/308663 "2022-07-27T09:30:09Z")

</div>

I've ugraded to V8 yesterday, and i have some bugs. When i modify a graph, if the legend is "bottom", when i save, i have a big white space under the graph between the legend and the bottom of the frame. The space i…

---

## [Can we search the documents from multiple index by specifying the index with wildcard character like "test\*"?](https://discuss.elastic.co/t/can-we-search-the-documents-from-multiple-index-by-specifying-the-index-with-wildcard-character-like-test/310645)

<div class="topic-metadata">

**Author:** [@Aurovindo\_Sahu](https://discuss.elastic.co/u/Aurovindo_Sahu)\
**Replies:** 1\
**Last updated:** [July 27, 2022, 8:55am UTC](https://discuss.elastic.co/t/can-we-search-the-documents-from-multiple-index-by-specifying-the-index-with-wildcard-character-like-test/310645 "2022-07-27T08:55:12Z")

</div>

I want to search data from multiple indices and all the indices prefix is test. Is this possible to have the index name in the get request like test\*

---

## [My Macos elastic-endpoint process CPU is too high, up to 103%](https://discuss.elastic.co/t/my-macos-elastic-endpoint-process-cpu-is-too-high-up-to-103/310640)

<div class="topic-metadata">

**Author:** [@xqaiviwjxzw](https://discuss.elastic.co/u/xqaiviwjxzw)\
**Replies:** 3\
**Last updated:** [July 27, 2022, 7:55am UTC](https://discuss.elastic.co/t/my-macos-elastic-endpoint-process-cpu-is-too-high-up-to-103/310640 "2022-07-27T07:55:11Z")

</div>

My Macos elastic-endpoint process CPU is too high, up to 103%，It causes the computer to heat up badly, how can I solve this problem：

---

## [Kibana lens display one line with multiple values](https://discuss.elastic.co/t/kibana-lens-display-one-line-with-multiple-values/310602)

<div class="topic-metadata">

**Author:** [@rkidev](https://discuss.elastic.co/u/rkidev)\
**Replies:** 2\
**Last updated:** [July 27, 2022, 3:23am UTC](https://discuss.elastic.co/t/kibana-lens-display-one-line-with-multiple-values/310602 "2022-07-27T03:23:56Z")

</div>

I am trying to create time series graph using Kibana(version 8.3) lens. In my document I have following fields - {"timestamp":"2019-06-02T10:16:44", "byte":17, "tName":"Group 1", "reg":"4"} I am able to show byte on th…

---

## [ERR"reason"Unable to Tessellate shape Possible malformed shape detected](https://discuss.elastic.co/t/err-reason-unable-to-tessellate-shape-possible-malformed-shape-detected/309989)

<div class="topic-metadata">

**Author:** [@baiwenbo1997](https://discuss.elastic.co/u/baiwenbo1997)\
**Replies:** 4\
**Last updated:** [July 27, 2022, 2:07am UTC](https://discuss.elastic.co/t/err-reason-unable-to-tessellate-shape-possible-malformed-shape-detected/309989 "2022-07-27T02:07:55Z")

</div>

I want to know why it failed, because of accuracy?Why does this polygon be judged as a self -intersecting graph, which causes storage POLYGON((38628095.0171 3322658.2041,38628095.2386 3322662.567299999,38628095.1811 332…

---

## [Whats best practices to apply elastic search on Kubernetes unmanaged cluster](https://discuss.elastic.co/t/whats-best-practices-to-apply-elastic-search-on-kubernetes-unmanaged-cluster/310636)

<div class="topic-metadata">

**Author:** [@ahmad\_ins](https://discuss.elastic.co/u/ahmad_ins)\
**Replies:** 1\
**Last updated:** [July 27, 2022, 1:42am UTC](https://discuss.elastic.co/t/whats-best-practices-to-apply-elastic-search-on-kubernetes-unmanaged-cluster/310636 "2022-07-27T01:42:50Z")

</div>

what's best practices to apply Elasticsearch on Kubernetes unmanaged cluster?

---

## [Unable to start Elasticsearch](https://discuss.elastic.co/t/unable-to-start-elasticsearch/310685)

<div class="topic-metadata">

**Author:** [@Ifty](https://discuss.elastic.co/u/Ifty)\
**Replies:** 4\
**Last updated:** [July 26, 2022, 10:00pm UTC](https://discuss.elastic.co/t/unable-to-start-elasticsearch/310685 "2022-07-26T22:00:29Z")

</div>

Good Day! I am trying to setup Elasticsearch in a 3 node cluster, I am getting below error while I am trying to start Elasticsearch, // \[root@HRC-ESDC-GLES11 log\]# systemctl status elasticsearch.service â elasticsearc…

---

## [Url similarity scoring](https://discuss.elastic.co/t/url-similarity-scoring/310560)

<div class="topic-metadata">

**Author:** [@Moverton](https://discuss.elastic.co/u/Moverton)\
**Replies:** 2\
**Last updated:** [July 26, 2022, 7:01pm UTC](https://discuss.elastic.co/t/url-similarity-scoring/310560 "2022-07-26T19:01:58Z")

</div>

I want to create a search that scores by the similarity of Url's. So searching for https://www.sample.com/abc/def/index.html in a field with these values https://www.test.com/abc/ (different host, only one path par…

---

## [How to separate objects inside an array of objects?](https://discuss.elastic.co/t/how-to-separate-objects-inside-an-array-of-objects/310274)

<div class="topic-metadata">

**Author:** [@Mary2022](https://discuss.elastic.co/u/Mary2022)\
**Replies:** 3\
**Last updated:** [July 26, 2022, 6:56pm UTC](https://discuss.elastic.co/t/how-to-separate-objects-inside-an-array-of-objects/310274 "2022-07-26T18:56:51Z")

</div>

Hi, I still new to ELK and I have been trying to process data that come to me as json file. The json file looks lie this. \[ { "user": "Beta", "percent": 28, "startTime": "2022-07-07T11:31:45", "type": "CPU",…

---

## [After creating new config file and run it copy also old config file data in newly created index](https://discuss.elastic.co/t/after-creating-new-config-file-and-run-it-copy-also-old-config-file-data-in-newly-created-index/310669)

<div class="topic-metadata">

**Author:** [@bbkunbi](https://discuss.elastic.co/u/bbkunbi)\
**Replies:** 0\
**Last updated:** [July 26, 2022, 4:54pm UTC](https://discuss.elastic.co/t/after-creating-new-config-file-and-run-it-copy-also-old-config-file-data-in-newly-created-index/310669 "2022-07-26T16:54:38Z")

</div>

Initially i have created c10.conf file it store csv data in recordv2 index it is working fine. After that i have created new configuration file gmrtant.conf to read multiple csv file to read new data which is different t…

---

## [Security events and rules matching](https://discuss.elastic.co/t/security-events-and-rules-matching/309922)

<div class="topic-metadata">

**Author:** [@Alexander\_A](https://discuss.elastic.co/u/Alexander_A)\
**Replies:** 2\
**Last updated:** [July 26, 2022, 4:49pm UTC](https://discuss.elastic.co/t/security-events-and-rules-matching/309922 "2022-07-26T16:49:20Z")

</div>

We are trying to understand what security events Elastic SIEM covers but it’s quite difficult cause there is no list of such events in the documentation or may be we don’t know where it is. We've decided to start with Wi…

---

## [Visualization: upgrading from 6 to 7](https://discuss.elastic.co/t/visualization-upgrading-from-6-to-7/310665)

<div class="topic-metadata">

**Author:** [@Malec](https://discuss.elastic.co/u/Malec)\
**Replies:** 0\
**Last updated:** [July 26, 2022, 3:38pm UTC](https://discuss.elastic.co/t/visualization-upgrading-from-6-to-7/310665 "2022-07-26T15:38:54Z")

</div>

Hi everyone! I have been googling quite a bit to try and find some info on how Kibana dashboards are affected during a Major migration from v6 to V7. The only bit of info I found is here and that does not worry me too …

---

## [Kibana not connected to epr.elastic.co Package Registry](https://discuss.elastic.co/t/kibana-not-connected-to-epr-elastic-co-package-registry/310028)

<div class="topic-metadata">

**Author:** [@shuuny-matrix](https://discuss.elastic.co/u/shuuny-matrix)\
**Replies:** 3\
**Last updated:** [July 26, 2022, 3:19pm UTC](https://discuss.elastic.co/t/kibana-not-connected-to-epr-elastic-co-package-registry/310028 "2022-07-26T15:19:41Z")

</div>

I have installed Elasticsearch and Kibana in my Ubuntu System in a corporate environment behind firewall and proxies. We have two crt files to use internet in browser. My elasticsearch is running fine. But when I run Ki…

---

## [Looukps with memcahed or tanslate filter](https://discuss.elastic.co/t/looukps-with-memcahed-or-tanslate-filter/310650)

<div class="topic-metadata">

**Author:** [@paulohperes](https://discuss.elastic.co/u/paulohperes)\
**Replies:** 1\
**Last updated:** [July 26, 2022, 2:43pm UTC](https://discuss.elastic.co/t/looukps-with-memcahed-or-tanslate-filter/310650 "2022-07-26T14:43:39Z")

</div>

Hi, I am doubt about lookups. Recently I implemented a pipeline using the filter plugin Memcached, but the Memcached plugin does not work well with json values. I needed to do this for work: memcached { hosts =\>…

---

## [Logstash-output-cloudwatchlogs](https://discuss.elastic.co/t/logstash-output-cloudwatchlogs/310653)

<div class="topic-metadata">

**Author:** [@jlbai](https://discuss.elastic.co/u/jlbai)\
**Replies:** 0\
**Last updated:** [July 26, 2022, 2:20pm UTC](https://discuss.elastic.co/t/logstash-output-cloudwatchlogs/310653 "2022-07-26T14:20:53Z")

</div>

I am looking to get logs out our network devices, firewalls, aruba controllers, switches etc. I am looking at using the output plugin for cloud watch logs GitHub - amazon-archives/logstash-output-cloudwatchlogs: A logsta…

---

## [What is proper order of nodes for rolling upgrade?](https://discuss.elastic.co/t/what-is-proper-order-of-nodes-for-rolling-upgrade/310317)

<div class="topic-metadata">

**Author:** [@javadevmtl](https://discuss.elastic.co/u/javadevmtl)\
**Replies:** 2\
**Last updated:** [July 26, 2022, 2:11pm UTC](https://discuss.elastic.co/t/what-is-proper-order-of-nodes-for-rolling-upgrade/310317 "2022-07-26T14:11:26Z")

</div>

Hi upgrading an Elastic 6.x to latest 6.x Is there like a particular order that the nodes should be upgraded? Masters first, then data, then coordinators. And then applications like Kibana, Filebeat, logstash etc... T…

---

## [\[copy\] Data Stop ingesting after deleting index](https://discuss.elastic.co/t/copy-data-stop-ingesting-after-deleting-index/310649)

<div class="topic-metadata">

**Author:** [@noa-ru](https://discuss.elastic.co/u/noa-ru)\
**Replies:** 0\
**Last updated:** [July 26, 2022, 1:55pm UTC](https://discuss.elastic.co/t/copy-data-stop-ingesting-after-deleting-index/310649 "2022-07-26T13:55:33Z")

</div>

Hello all! i not found a solution for my problem, but i found this post with same problem. And when i found a solution, i discovered what i cant write it in this post. that's why i registered here and created this post…

---

## [Multiple instances of beats running](https://discuss.elastic.co/t/multiple-instances-of-beats-running/310336)

<div class="topic-metadata">

**Author:** [@DefensiveDepth](https://discuss.elastic.co/u/DefensiveDepth)\
**Replies:** 1\
**Last updated:** [July 26, 2022, 1:48pm UTC](https://discuss.elastic.co/t/multiple-instances-of-beats-running/310336 "2022-07-26T13:48:13Z")

</div>

Fleet + Elastic Agent 8.3.2. Agent is installed on Win10, with only the system integration with all defaults. Looking at the processes running, it appears that there are multiple instances of filebeat & metricbeat runni…

---

## [Security Onion - Kibana - Unable to load tooltip content in Maps](https://discuss.elastic.co/t/security-onion-kibana-unable-to-load-tooltip-content-in-maps/310535)

<div class="topic-metadata">

**Author:** [@DigitalDick](https://discuss.elastic.co/u/DigitalDick)\
**Replies:** 5\
**Last updated:** [July 26, 2022, 1:30pm UTC](https://discuss.elastic.co/t/security-onion-kibana-unable-to-load-tooltip-content-in-maps/310535 "2022-07-26T13:30:28Z")

</div>

Hi, New here and new to Kibana. Any help greatly appreciated. So I have setup Security Onion 2.3, I am using netflow to send logs from Meraki to Security Onion. I can see the logs, I can see the dots on the maps etc. Wh…

---

## [Dashboard Autorefresh still not working in Kibana 8.1.1](https://discuss.elastic.co/t/dashboard-autorefresh-still-not-working-in-kibana-8-1-1/310002)

<div class="topic-metadata">

**Author:** [@ondrej-ivanko](https://discuss.elastic.co/u/ondrej-ivanko)\
**Replies:** 3\
**Last updated:** [July 26, 2022, 12:50pm UTC](https://discuss.elastic.co/t/dashboard-autorefresh-still-not-working-in-kibana-8-1-1/310002 "2022-07-26T12:50:58Z")

</div>

Hi, the dashboard autorefresh issue still seem to persist in Kibana 8.1.1. I created custom dashboard with filters to display some application logs collected by Fluentd and sent to ElasticSearch. AutoReferesh is working…

---

## [Three nodes cluster without quorum](https://discuss.elastic.co/t/three-nodes-cluster-without-quorum/310632)

<div class="topic-metadata">

**Author:** [@vnovotny98](https://discuss.elastic.co/u/vnovotny98)\
**Replies:** 1\
**Last updated:** [July 26, 2022, 12:18pm UTC](https://discuss.elastic.co/t/three-nodes-cluster-without-quorum/310632 "2022-07-26T12:18:52Z")

</div>

Hello. I am new here in this community. I have a three nodes cluster but two nodes are on the same virt and one on another. I need to set them like three masters and three data nodes. When I am updating the virt I nee…

---

## [Multiple filebeat log with logstash not working](https://discuss.elastic.co/t/multiple-filebeat-log-with-logstash-not-working/310472)

<div class="topic-metadata">

**Author:** [@sazzad114](https://discuss.elastic.co/u/sazzad114)\
**Replies:** 4\
**Last updated:** [July 26, 2022, 12:15pm UTC](https://discuss.elastic.co/t/multiple-filebeat-log-with-logstash-not-working/310472 "2022-07-26T12:15:55Z")

</div>

filebeat.input: - type: log enabled: true paths: - /var/log/nginx/\*log tags: \["server-log"\] fields: {log\_type: Server-log} - type: log enabled: true paths: - /var/www/laravel/storage/logs/\*.log tags…

---

## [App search - Semantic search and machine learning NLP models](https://discuss.elastic.co/t/app-search-semantic-search-and-machine-learning-nlp-models/306860)

<div class="topic-metadata">

**Author:** [@Gerardo\_Zenobi](https://discuss.elastic.co/u/Gerardo_Zenobi)\
**Replies:** 3\
**Last updated:** [July 26, 2022, 10:41am UTC](https://discuss.elastic.co/t/app-search-semantic-search-and-machine-learning-nlp-models/306860 "2022-07-26T10:41:42Z")

</div>

Hi there :wave: The following webinar "Introduction to NLP models and vector search" gives a very nice demo on uploading and using NLP models to improve search relevance. However, it might seem it is only focused on co…

---

## [Geo-bounding box query returns results outside of the box](https://discuss.elastic.co/t/geo-bounding-box-query-returns-results-outside-of-the-box/310618)

<div class="topic-metadata">

**Author:** [@xinyuluo](https://discuss.elastic.co/u/xinyuluo)\
**Replies:** 1\
**Last updated:** [July 26, 2022, 10:29am UTC](https://discuss.elastic.co/t/geo-bounding-box-query-returns-results-outside-of-the-box/310618 "2022-07-26T10:29:37Z")

</div>

Hi! I am new to this space. I was trying to use geo-bounding box feature to match geo\_points inside a bounding box, but it seems that my query always generates returns outside of the box. for instance, the following quer…

---

## [Elastic Agent elasticsearch metrics/logs integration?](https://discuss.elastic.co/t/elastic-agent-elasticsearch-metrics-logs-integration/310619)

<div class="topic-metadata">

**Author:** [@markn](https://discuss.elastic.co/u/markn)\
**Replies:** 0\
**Last updated:** [July 26, 2022, 10:06am UTC](https://discuss.elastic.co/t/elastic-agent-elasticsearch-metrics-logs-integration/310619 "2022-07-26T10:06:01Z")

</div>

Hi, for self monitoring we want to use the elastic agent to ship Elasticsearch logs and metrics to our monitoring cluster. According to documentation there should be a version 0.2.0 elasticsearch (technical preview) pa…

---

## [My ES client always receives "Request execution exceeded the timeout"](https://discuss.elastic.co/t/my-es-client-always-receives-request-execution-exceeded-the-timeout/310309)

<div class="topic-metadata">

**Author:** [@fraf](https://discuss.elastic.co/u/fraf)\
**Replies:** 3\
**Last updated:** [July 26, 2022, 9:59am UTC](https://discuss.elastic.co/t/my-es-client-always-receives-request-execution-exceeded-the-timeout/310309 "2022-07-26T09:59:04Z")

</div>

Hi everyone, When validating my indexes on client side, requests are sent to my ES server. After 100s, I received a timeout exception from the client. Failure: org.hibernate.search.util.common.SearchException: HSEARCH4…

---

## [How does Logstash determine that a field matches a string regularly？](https://discuss.elastic.co/t/how-does-logstash-determine-that-a-field-matches-a-string-regularly/310586)

<div class="topic-metadata">

**Author:** [@wentao\_Xiong](https://discuss.elastic.co/u/wentao_Xiong)\
**Replies:** 3\
**Last updated:** [July 26, 2022, 9:16am UTC](https://discuss.elastic.co/t/how-does-logstash-determine-that-a-field-matches-a-string-regularly/310586 "2022-07-26T09:16:30Z")

</div>

I am a newcomer to ELK, and now I encounter a problem as shown in the title: How does Logstash determine that a field matches a string regularly? such as whether the \[path\] field contains the "err" string? (the path fie…

---

## [Multiple languages documents](https://discuss.elastic.co/t/multiple-languages-documents/309885)

<div class="topic-metadata">

**Author:** [@Gerardo\_Zenobi](https://discuss.elastic.co/u/Gerardo_Zenobi)\
**Replies:** 8\
**Last updated:** [July 26, 2022, 8:31am UTC](https://discuss.elastic.co/t/multiple-languages-documents/309885 "2022-07-26T08:31:36Z")

</div>

Hi there :wave: Context Within a particular engine I will have documents in multiple languages. e.g Document 1 -\> english Document 2 -\> french Document 3 -\> slovenian ... At the same time, each of those documents cou…

---

## [Regarding Proximity search with wildcard in Query String](https://discuss.elastic.co/t/regarding-proximity-search-with-wildcard-in-query-string/310609)

<div class="topic-metadata">

**Author:** [@Pratik\_Lahudkar](https://discuss.elastic.co/u/Pratik_Lahudkar)\
**Replies:** 0\
**Last updated:** [July 26, 2022, 8:31am UTC](https://discuss.elastic.co/t/regarding-proximity-search-with-wildcard-in-query-string/310609 "2022-07-26T08:31:19Z")

</div>

Hi All, I am trying to implement proximity search with Wildcard in my data My query is - {"query": ""Hello world"~1"} I want to use it like "query": ""Hello\* world"~1" if there is any way to do so, please reply o…

---

## [How to archive data from a Transform?](https://discuss.elastic.co/t/how-to-archive-data-from-a-transform/310313)

<div class="topic-metadata">

**Author:** [@bianca6](https://discuss.elastic.co/u/bianca6)\
**Replies:** 3\
**Last updated:** [July 26, 2022, 8:20am UTC](https://discuss.elastic.co/t/how-to-archive-data-from-a-transform/310313 "2022-07-26T08:20:57Z")

</div>

Hi, A Transform add data to a unique index. This index is getting too big. I would like to store the data (more than 2 days old) to another warm index. How could I achieve that? Thanks a lot for your time!

[Previous page](https://discuss.elastic.co/tag/none.md?no_tags=true&page=574)

[Next page](https://discuss.elastic.co/tag/none.md?no_tags=true&page=576)
