# \#none

**URL:** https://discuss.elastic.co/tag/none.md?no_tags=true&page=578

[Latest](https://discuss.elastic.co/latest.md) · [Categories](https://discuss.elastic.co/categories.md) · [Tags](https://discuss.elastic.co/tags.md)

**Page:** 579

---

## [Sort with limiting consecutive amount of hits by field value](https://discuss.elastic.co/t/sort-with-limiting-consecutive-amount-of-hits-by-field-value/310154)

<div class="topic-metadata">

**Author:** [@vitalyiegorov](https://discuss.elastic.co/u/vitalyiegorov)\
**Replies:** 1\
**Last updated:** [July 22, 2022, 4:09pm UTC](https://discuss.elastic.co/t/sort-with-limiting-consecutive-amount-of-hits-by-field-value/310154 "2022-07-22T16:09:36Z")

</div>

We have an ecommerce products index, which has Brand field(keyword) and a PublishDate field(date). We need a New items sort, which should sort results by returning no more than 5 consecutive products of each brand sort…

---

## [Cisco integrations fields naming convention](https://discuss.elastic.co/t/cisco-integrations-fields-naming-convention/310413)

<div class="topic-metadata">

**Author:** [@leandrojmp](https://discuss.elastic.co/u/leandrojmp)\
**Replies:** 0\
**Last updated:** [July 22, 2022, 2:56pm UTC](https://discuss.elastic.co/t/cisco-integrations-fields-naming-convention/310413 "2022-07-22T14:56:27Z")

</div>

Hello, Currently in our company we are using Logstash to collect and parse logs from a couple of cisco devices (asa, ise, ftd and also duo and umbrella). To make our data integrate better with the builtin dashboards an…

---

## [Error in elasticsearch Backup via HMAC](https://discuss.elastic.co/t/error-in-elasticsearch-backup-via-hmac/310297)

<div class="topic-metadata">

**Author:** [@Sagar\_Shivani](https://discuss.elastic.co/u/Sagar_Shivani)\
**Replies:** 1\
**Last updated:** [July 22, 2022, 2:44pm UTC](https://discuss.elastic.co/t/error-in-elasticsearch-backup-via-hmac/310297 "2022-07-22T14:44:54Z")

</div>

I was trying using s3 for uploading to data on to GCP via HMAC keys..I am getting this error Register Repository Response: {"error":{"root\_cause":\[{"type":"repository\_verification\_exception","reason":"\[dev--110425--elas…

---

## [Visualize in a graph the match value from multiple indexes](https://discuss.elastic.co/t/visualize-in-a-graph-the-match-value-from-multiple-indexes/310402)

<div class="topic-metadata">

**Author:** [@mrestrepo](https://discuss.elastic.co/u/mrestrepo)\
**Replies:** 2\
**Last updated:** [July 22, 2022, 1:01pm UTC](https://discuss.elastic.co/t/visualize-in-a-graph-the-match-value-from-multiple-indexes/310402 "2022-07-22T13:01:16Z")

</div>

Hi all. I have 2 different indexes in kibana, first one is an early alert from something and the other one is when the user report the event, so i need to visualize when the alert and the user report match. So i can ha…

---

## [Problem with Kibana timestamp format](https://discuss.elastic.co/t/problem-with-kibana-timestamp-format/310366)

<div class="topic-metadata">

**Author:** [@bobus](https://discuss.elastic.co/u/bobus)\
**Replies:** 6\
**Last updated:** [July 22, 2022, 12:51pm UTC](https://discuss.elastic.co/t/problem-with-kibana-timestamp-format/310366 "2022-07-22T12:51:38Z")

</div>

A newbie question for you: On my Kibana "discover" page, timestamps appear as "2022-07-Th 18:21:00.234" (Th for Thursday rather than 21st of the month). Under Stack Mgmt --\> advance settings, the format is DD.MM.YY @ H…

---

## [Elasticsearch logs params](https://discuss.elastic.co/t/elasticsearch-logs-params/310403)

<div class="topic-metadata">

**Author:** [@mirisu2](https://discuss.elastic.co/u/mirisu2)\
**Replies:** 0\
**Last updated:** [July 22, 2022, 12:47pm UTC](https://discuss.elastic.co/t/elasticsearch-logs-params/310403 "2022-07-22T12:47:38Z")

</div>

Hi, elasticsearch logs settings have many params like "logger.org.elasticsearch.index.reindex" : "logger.org.elasticsearch.transport": "logger.org.elasticsearch.discovery": I would like to find all possible params l…

---

## [Elastic cluster destroyes SSD's?](https://discuss.elastic.co/t/elastic-cluster-destroyes-ssds/308985)

<div class="topic-metadata">

**Author:** [@azeiner](https://discuss.elastic.co/u/azeiner)\
**Replies:** 12\
**Last updated:** [July 22, 2022, 12:11pm UTC](https://discuss.elastic.co/t/elastic-cluster-destroyes-ssds/308985 "2022-07-22T12:11:49Z")

</div>

I'm using Elastic 7.17.3 in a 3 Node Cluster on Windows - we have Redis as a ingest and cache database and running logstash to transfer daten from redis to the cluster - so far so good. Now i'm encoutering issues like …

---

## [Mutate add\_field attribute accidently become duplicate when using multiple logstash](https://discuss.elastic.co/t/mutate-add-field-attribute-accidently-become-duplicate-when-using-multiple-logstash/309536)

<div class="topic-metadata">

**Author:** [@mahendrapratitos](https://discuss.elastic.co/u/mahendrapratitos)\
**Replies:** 2\
**Last updated:** [July 22, 2022, 11:23am UTC](https://discuss.elastic.co/t/mutate-add-field-attribute-accidently-become-duplicate-when-using-multiple-logstash/309536 "2022-07-22T11:23:48Z")

</div>

I tried to execute 8 logstash that accept different port and different filebeat. I run this logstash on Linux environment. when I run the logstash, turns out some attribute that I create by using script mutate add\_fiel…

---

## [Kibana TSVB doesn't display all annotations that has the same timestamp](https://discuss.elastic.co/t/kibana-tsvb-doesnt-display-all-annotations-that-has-the-same-timestamp/310312)

<div class="topic-metadata">

**Author:** [@Henry\_Le](https://discuss.elastic.co/u/Henry_Le)\
**Replies:** 1\
**Last updated:** [July 22, 2022, 9:51am UTC](https://discuss.elastic.co/t/kibana-tsvb-doesnt-display-all-annotations-that-has-the-same-timestamp/310312 "2022-07-22T09:51:21Z")

</div>

I have a use case to show annotations of all events that have the same timestamp on the time series visualization of Kibana. The field name in interest is sale\_event. When creating the annotations, I put {{sale\_event}} i…

---

## [Theory question: How to recover data from 3 node cluster after 2 nodes failed](https://discuss.elastic.co/t/theory-question-how-to-recover-data-from-3-node-cluster-after-2-nodes-failed/310262)

<div class="topic-metadata">

**Author:** [@defalt](https://discuss.elastic.co/u/defalt)\
**Replies:** 3\
**Last updated:** [July 22, 2022, 8:07am UTC](https://discuss.elastic.co/t/theory-question-how-to-recover-data-from-3-node-cluster-after-2-nodes-failed/310262 "2022-07-22T08:07:54Z")

</div>

Long time no see, but hello again. We had a 3 Node cluster running very well till it stopped running very well. The SSD's of 2 Nodes failed in a timespan of 4 hours. This was in the middle of the night so no actions cou…

---

## [SIEM - Network scan](https://discuss.elastic.co/t/siem-network-scan/309691)

<div class="topic-metadata">

**Author:** [@ldmontoya](https://discuss.elastic.co/u/ldmontoya)\
**Replies:** 3\
**Last updated:** [July 22, 2022, 9:13am UTC](https://discuss.elastic.co/t/siem-network-scan/309691 "2022-07-22T09:13:47Z")

</div>

Hi guys! I'm setting up the SIEM feature on kibana and one of my use cases is to detect network scans using nmap or any other tool. After digging on the community I've found the following threshold rule: Query: event.c…

---

## [Value 'none' is not among the allowed options for argument](https://discuss.elastic.co/t/value-none-is-not-among-the-allowed-options-for-argument/310316)

<div class="topic-metadata">

**Author:** [@cyberzlo](https://discuss.elastic.co/u/cyberzlo)\
**Replies:** 1\
**Last updated:** [July 22, 2022, 8:26am UTC](https://discuss.elastic.co/t/value-none-is-not-among-the-allowed-options-for-argument/310316 "2022-07-22T08:26:28Z")

</div>

\[layeredXyVis\] \> \[referenceLineLayer\] \> \[extendedYConfig\] \> Value 'none' is not among the allowed options for argument 'icon': 'empty', 'asterisk', 'alert', 'bell', 'bolt', 'bug', 'circle', 'editorComment', 'flag', 'hear…

---

## [Logstash exec input and sdtout](https://discuss.elastic.co/t/logstash-exec-input-and-sdtout/310369)

<div class="topic-metadata">

**Author:** [@Silver137](https://discuss.elastic.co/u/Silver137)\
**Replies:** 0\
**Last updated:** [July 22, 2022, 7:30am UTC](https://discuss.elastic.co/t/logstash-exec-input-and-sdtout/310369 "2022-07-22T07:30:44Z")

</div>

I'm trying to execute a custom 5 minutes duration bash script in logstash using exec input plugin. but imposible to get output. Trying things, i realized that redirecting the script stdout to stderr the script makes ou…

---

## [Prevent nested json from appearing in elasticsaerch field](https://discuss.elastic.co/t/prevent-nested-json-from-appearing-in-elasticsaerch-field/310328)

<div class="topic-metadata">

**Author:** [@mikhatanu](https://discuss.elastic.co/u/mikhatanu)\
**Replies:** 6\
**Last updated:** [July 22, 2022, 4:04am UTC](https://discuss.elastic.co/t/prevent-nested-json-from-appearing-in-elasticsaerch-field/310328 "2022-07-22T04:04:11Z")

</div>

Hello, i'm using http filter to do api call to a rest api server. The data returned is json. it looks like this example: { a:{ b:{ c:{} d:{} e:{} } } } I want…

---

## [How to recreate shard failure](https://discuss.elastic.co/t/how-to-recreate-shard-failure/310114)

<div class="topic-metadata">

**Author:** [@vel](https://discuss.elastic.co/u/vel)\
**Replies:** 3\
**Last updated:** [July 22, 2022, 6:03am UTC](https://discuss.elastic.co/t/how-to-recreate-shard-failure/310114 "2022-07-22T06:03:50Z")

</div>

I am trying to find a way for recreating the shard failure in Elasticsearch When querying ES can return a 200 response , even if one of the shards had failed to respond. how do I recreate error, for testing. { "too…

---

## [Logstash filter not working, when all the filters are applied at once, but working when applied only one filter](https://discuss.elastic.co/t/logstash-filter-not-working-when-all-the-filters-are-applied-at-once-but-working-when-applied-only-one-filter/310186)

<div class="topic-metadata">

**Author:** [@djrshn2346](https://discuss.elastic.co/u/djrshn2346)\
**Replies:** 7\
**Last updated:** [July 22, 2022, 5:15am UTC](https://discuss.elastic.co/t/logstash-filter-not-working-when-all-the-filters-are-applied-at-once-but-working-when-applied-only-one-filter/310186 "2022-07-22T05:15:23Z")

</div>

I have added 3 filters in Logstash but at a time only 2 are working, but all the three are not working at the same time. One of the filter is throwing error. When I applied single filter that is working fine, when 2 that…

---

## [Query for end date greater than now or doesn't exist not working](https://discuss.elastic.co/t/query-for-end-date-greater-than-now-or-doesnt-exist-not-working/310361)

<div class="topic-metadata">

**Author:** [@Ellie\_Y](https://discuss.elastic.co/u/Ellie_Y)\
**Replies:** 0\
**Last updated:** [July 22, 2022, 3:43am UTC](https://discuss.elastic.co/t/query-for-end-date-greater-than-now-or-doesnt-exist-not-working/310361 "2022-07-22T03:43:40Z")

</div>

My 'must' query works fine but the should returns the following error: "No query registered for \[exists\]" I want to find documents that either do not have a stopPublishDate or if they do have one the date must be in th…

---

## [Search template: Only aggregate with param condition](https://discuss.elastic.co/t/search-template-only-aggregate-with-param-condition/310350)

<div class="topic-metadata">

**Author:** [@Emporea](https://discuss.elastic.co/u/Emporea)\
**Replies:** 0\
**Last updated:** [July 21, 2022, 11:00pm UTC](https://discuss.elastic.co/t/search-template-only-aggregate-with-param-condition/310350 "2022-07-21T23:00:59Z")

</div>

Maybe I am misunderstanding the obvious. But how am i able to use a search template (mustache) and only aggregate certain aggs if a param is set to true? For example I have this search template { id: "test\_template",…

---

## [How can I 'start over' from scratch with a clean installation of ES?](https://discuss.elastic.co/t/how-can-i-start-over-from-scratch-with-a-clean-installation-of-es/310349)

<div class="topic-metadata">

**Author:** [@KKora](https://discuss.elastic.co/u/KKora)\
**Replies:** 2\
**Last updated:** [July 21, 2022, 10:55pm UTC](https://discuss.elastic.co/t/how-can-i-start-over-from-scratch-with-a-clean-installation-of-es/310349 "2022-07-21T22:55:18Z")

</div>

I installed ES and deleted the Elasticsearch folder. When I 'start over' from scratch with a clean installation, It does not creating certificate files? How to clean ES installation from my machine ?

---

## [ELK bin modules don't work - x.pack,security issues?](https://discuss.elastic.co/t/elk-bin-modules-dont-work-x-pack-security-issues/310344)

<div class="topic-metadata">

**Author:** [@Nate\_F](https://discuss.elastic.co/u/Nate_F)\
**Replies:** 1\
**Last updated:** [July 21, 2022, 10:48pm UTC](https://discuss.elastic.co/t/elk-bin-modules-dont-work-x-pack-security-issues/310344 "2022-07-21T22:48:14Z")

</div>

I could be very wrong here as I have not deployed ELK in years. I opted to use the bitnami image to speed things up but I'm not sure if I should just scrap what I have and do the install manually. I'm trying to set perm…

---

## [Logstash Elapsed filter not working](https://discuss.elastic.co/t/logstash-elapsed-filter-not-working/310220)

<div class="topic-metadata">

**Author:** [@nakula](https://discuss.elastic.co/u/nakula)\
**Replies:** 8\
**Last updated:** [July 21, 2022, 8:02pm UTC](https://discuss.elastic.co/t/logstash-elapsed-filter-not-working/310220 "2022-07-21T20:02:37Z")

</div>

I am trying to find the different between the start time and end time of a transaction. I am using the sample log file as below.. 2022-07-17T12:36:30.3081415Z Info 38 \[xxx.frame.logging.serviceCols\] \["Level3"\] : Wires-…

---

## [Setting Default Time Window Dynamically](https://discuss.elastic.co/t/setting-default-time-window-dynamically/310203)

<div class="topic-metadata">

**Author:** [@badmire](https://discuss.elastic.co/u/badmire)\
**Replies:** 2\
**Last updated:** [July 21, 2022, 6:17pm UTC](https://discuss.elastic.co/t/setting-default-time-window-dynamically/310203 "2022-07-21T18:17:50Z")

</div>

Hello! I am trying to build a dashboard that will act a lot like the discover tab, but offer visualizations and some shortcuts for our less tech savvy users. I have the setting for "save time with dashboard" set to tru…

---

## [Aggregation with script](https://discuss.elastic.co/t/aggregation-with-script/310216)

<div class="topic-metadata">

**Author:** [@Jason\_Yu1](https://discuss.elastic.co/u/Jason_Yu1)\
**Replies:** 4\
**Last updated:** [July 21, 2022, 5:53pm UTC](https://discuss.elastic.co/t/aggregation-with-script/310216 "2022-07-21T17:53:56Z")

</div>

I have some containers like those "\_source": { "testId": "test001", "containers": \[ { "name": "containers1", …

---

## [Index is empty using Transform](https://discuss.elastic.co/t/index-is-empty-using-transform/310181)

<div class="topic-metadata">

**Author:** [@Ruben\_Marinho](https://discuss.elastic.co/u/Ruben_Marinho)\
**Replies:** 4\
**Last updated:** [July 21, 2022, 4:33pm UTC](https://discuss.elastic.co/t/index-is-empty-using-transform/310181 "2022-07-21T16:33:16Z")

</div>

Hi all, I'm trying to create a transform on ElasticSearch. I started by creating this using console and got the expected results. In the console I use: POST \_transform/\_preview { "source": { "index": "test", …

---

## [Discover UI slow after upgrade](https://discuss.elastic.co/t/discover-ui-slow-after-upgrade/310211)

<div class="topic-metadata">

**Author:** [@Brian\_Turnbull](https://discuss.elastic.co/u/Brian_Turnbull)\
**Replies:** 5\
**Last updated:** [July 21, 2022, 4:19pm UTC](https://discuss.elastic.co/t/discover-ui-slow-after-upgrade/310211 "2022-07-21T16:19:53Z")

</div>

We have a ~100TB logs cluster with 26 nodes that currently has about 20k shards in total. We had previously been running 7.6 and upgraded to 7.17.4. We're running into problems with very slow initial load and refresh. …

---

## [How to add new column in the datatable](https://discuss.elastic.co/t/how-to-add-new-column-in-the-datatable/310172)

<div class="topic-metadata">

**Author:** [@malik123](https://discuss.elastic.co/u/malik123)\
**Replies:** 5\
**Last updated:** [July 21, 2022, 4:13pm UTC](https://discuss.elastic.co/t/how-to-add-new-column-in-the-datatable/310172 "2022-07-21T16:13:03Z")

</div>

Hi all, Currently I am working on the sample data that is provided by the kibana. I want to display a new column in the datatable named "total\_Hours". I want to add "Unique Visits (Total)" and "Unique Visits (Last Hour…

---

## [CSP blocking Kibana](https://discuss.elastic.co/t/csp-blocking-kibana/310314)

<div class="topic-metadata">

**Author:** [@cyberzlo](https://discuss.elastic.co/u/cyberzlo)\
**Replies:** 3\
**Last updated:** [July 21, 2022, 4:04pm UTC](https://discuss.elastic.co/t/csp-blocking-kibana/310314 "2022-07-21T16:04:30Z")

</div>

Kibana now has experimental support for a more restrictive Content Security Policy(CSP). Hi, how can I disable it? Since update to 8.3 I have problems with view Kibana because of CSP blocking content in new Chrome. Ple…

---

## [Manipulating data in logstash](https://discuss.elastic.co/t/manipulating-data-in-logstash/310304)

<div class="topic-metadata">

**Author:** [@KeithL](https://discuss.elastic.co/u/KeithL)\
**Replies:** 1\
**Last updated:** [July 21, 2022, 2:47pm UTC](https://discuss.elastic.co/t/manipulating-data-in-logstash/310304 "2022-07-21T14:47:17Z")

</div>

Beginner's question; pardon my potentially poor terminology. I'd like to manipulate ingested data to include geo\_point data to facilitate visualisation in elastic/kibana e.g given this: { "Entities" =\> \[ \[…

---

## [Input beats - output syslog, what in the middle](https://discuss.elastic.co/t/input-beats-output-syslog-what-in-the-middle/310310)

<div class="topic-metadata">

**Author:** [@Kakos](https://discuss.elastic.co/u/Kakos)\
**Replies:** 0\
**Last updated:** [July 21, 2022, 2:40pm UTC](https://discuss.elastic.co/t/input-beats-output-syslog-what-in-the-middle/310310 "2022-07-21T14:40:43Z")

</div>

Hi, The messages i get from beats are completely unstructured. The most important of all they include characters like \\t and \\n and actually don't recognize the new lines and tabs which exist in the raw data. So they lo…

---

## [Modular pipeline construction with same input plugin (Kafka) but different topic name](https://discuss.elastic.co/t/modular-pipeline-construction-with-same-input-plugin-kafka-but-different-topic-name/310300)

<div class="topic-metadata">

**Author:** [@ibrahim.ramadan](https://discuss.elastic.co/u/ibrahim.ramadan)\
**Replies:** 0\
**Last updated:** [July 21, 2022, 1:26pm UTC](https://discuss.elastic.co/t/modular-pipeline-construction-with-same-input-plugin-kafka-but-different-topic-name/310300 "2022-07-21T13:26:37Z")

</div>

Hi, I am trying to construct modular multiple pipeline in logstash. I have the same input plugin from (kafka) in all pipelines but at each one some attributes like topic name and broker address different from each input…

[Previous page](https://discuss.elastic.co/tag/none.md?no_tags=true&page=577)

[Next page](https://discuss.elastic.co/tag/none.md?no_tags=true&page=579)
