# \#none

**URL:** https://discuss.elastic.co/tag/none.md?no_tags=true&page=585

[Latest](https://discuss.elastic.co/latest.md) · [Categories](https://discuss.elastic.co/categories.md) · [Tags](https://discuss.elastic.co/tags.md)

**Page:** 586

---

## [After exporting to csv getting different value](https://discuss.elastic.co/t/after-exporting-to-csv-getting-different-value/309551)

<div class="topic-metadata">

**Author:** [@Muhammed\_Ashique](https://discuss.elastic.co/u/Muhammed_Ashique)\
**Replies:** 5\
**Last updated:** [July 14, 2022, 11:19am UTC](https://discuss.elastic.co/t/after-exporting-to-csv-getting-different-value/309551 "2022-07-14T11:19:23Z")

</div>

I have some filed to export as csv . on elasticsearch it is have proper value. once i export into csv file this field is become rounded value. here attached before exporting and after exporting.

---

## [No data to display for the selected metrics should be shown for IP reputation when it does not have data](https://discuss.elastic.co/t/no-data-to-display-for-the-selected-metrics-should-be-shown-for-ip-reputation-when-it-does-not-have-data/307750)

<div class="topic-metadata">

**Author:** [@BalajeP](https://discuss.elastic.co/u/BalajeP)\
**Replies:** 3\
**Last updated:** [July 14, 2022, 10:38am UTC](https://discuss.elastic.co/t/no-data-to-display-for-the-selected-metrics-should-be-shown-for-ip-reputation-when-it-does-not-have-data/307750 "2022-07-14T10:38:40Z")

</div>

No data to display for the selected metrics should be shown for IP reputation when it does not have data The graph should be shown when having data ,if there is no data should shown no data to display. for this case not…

---

## [Ingesting surricata logs](https://discuss.elastic.co/t/ingesting-surricata-logs/309437)

<div class="topic-metadata">

**Author:** [@username82](https://discuss.elastic.co/u/username82)\
**Replies:** 12\
**Last updated:** [July 14, 2022, 9:12am UTC](https://discuss.elastic.co/t/ingesting-surricata-logs/309437 "2022-07-14T09:12:26Z")

</div>

Hi, I am trying to ingest surricata logs into ElasticStack. The architecture is as follows, Suricata\>\>\>FileBeat\>\>\>ElasticSearch\>\>\>Kibana I have followed this guide to letter. How To Build A SIEM with Suricata and Elas…

---

## [Watcher payload entries group together in the index](https://discuss.elastic.co/t/watcher-payload-entries-group-together-in-the-index/309622)

<div class="topic-metadata">

**Author:** [@Jacky\_Kwok](https://discuss.elastic.co/u/Jacky_Kwok)\
**Replies:** 0\
**Last updated:** [July 14, 2022, 9:12am UTC](https://discuss.elastic.co/t/watcher-payload-entries-group-together-in-the-index/309622 "2022-07-14T09:12:23Z")

</div>

I have used the transform which the output looks like this. "payload": { "\_doc": { "TransactionAmount": \[ 50000, 565 \], "CompanyName"…

---

## [Connection refused in cluster configuration](https://discuss.elastic.co/t/connection-refused-in-cluster-configuration/309293)

<div class="topic-metadata">

**Author:** [@its-ogawa](https://discuss.elastic.co/u/its-ogawa)\
**Replies:** 1\
**Last updated:** [July 14, 2022, 9:03am UTC](https://discuss.elastic.co/t/connection-refused-in-cluster-configuration/309293 "2022-07-14T09:03:33Z")

</div>

I am using elasticsearch and have outgrown one server. Therefore, I would like to create a cluster configuration of two elasticsearch servers with the following manual. I have deployed elasticsearch on two servers, bu…

---

## [Pipeline - Create a delta field](https://discuss.elastic.co/t/pipeline-create-a-delta-field/309618)

<div class="topic-metadata">

**Author:** [@Ely\_96](https://discuss.elastic.co/u/Ely_96)\
**Replies:** 0\
**Last updated:** [July 14, 2022, 8:29am UTC](https://discuss.elastic.co/t/pipeline-create-a-delta-field/309618 "2022-07-14T08:29:50Z")

</div>

Hi Guys, I'm trying to study how to create a delta field: I mean a field that should contains a difference between 2 fields inside an existing index. So, I have 2 examples of CSVs: ID;Month;Date;Date\_string;Name;Surna…

---

## [Elastic Engineer (on-Demand) Training - Lab instructions Chapter 3.3 not displayed correctly](https://discuss.elastic.co/t/elastic-engineer-on-demand-training-lab-instructions-chapter-3-3-not-displayed-correctly/309617)

<div class="topic-metadata">

**Author:** [@bianca1](https://discuss.elastic.co/u/bianca1)\
**Replies:** 0\
**Last updated:** [July 14, 2022, 8:13am UTC](https://discuss.elastic.co/t/elastic-engineer-on-demand-training-lab-instructions-chapter-3-3-not-displayed-correctly/309617 "2022-07-14T08:13:48Z")

</div>

Hi there, I am currently doing the Elastic Engineer (on-Demand) Training. I now wanted to do the labs of Chapter 3.3 („Developing search applications“). However the page of the lab instructions for that chapter seems t…

---

## [Deploy Elasticsearch in kubernetes using ECK](https://discuss.elastic.co/t/deploy-elasticsearch-in-kubernetes-using-eck/308900)

<div class="topic-metadata">

**Author:** [@Biplab](https://discuss.elastic.co/u/Biplab)\
**Replies:** 2\
**Last updated:** [July 14, 2022, 8:09am UTC](https://discuss.elastic.co/t/deploy-elasticsearch-in-kubernetes-using-eck/308900 "2022-07-14T08:09:47Z")

</div>

Hi, I want to deploy an Elasticsearch cluster using ECK with the following architecture : Kubernetes cluster details: 4 Nodes and each node have one POD. Elasticsearch cluster details: 4 Nodes. One Master, One data,…

---

## [Vector-Based search using cosineSimilarity](https://discuss.elastic.co/t/vector-based-search-using-cosinesimilarity/307672)

<div class="topic-metadata">

**Author:** [@Biplab](https://discuss.elastic.co/u/Biplab)\
**Replies:** 3\
**Last updated:** [July 14, 2022, 8:08am UTC](https://discuss.elastic.co/t/vector-based-search-using-cosinesimilarity/307672 "2022-07-14T08:08:46Z")

</div>

Hi, I am indexing text and vector in Elasticsearch, working on an use case where I am using cosineSimilarity to get the result. The query search is returning the list of documents with decreasing Confidence Scores with t…

---

## [How can I change timezone](https://discuss.elastic.co/t/how-can-i-change-timezone/309615)

<div class="topic-metadata">

**Author:** [@msjhbhh](https://discuss.elastic.co/u/msjhbhh)\
**Replies:** 0\
**Last updated:** [July 14, 2022, 8:02am UTC](https://discuss.elastic.co/t/how-can-i-change-timezone/309615 "2022-07-14T08:02:29Z")

</div>

how can I change timezone $ date -Is -d '2022-07-14 15:25:26.867' 2022-07-14T15:25:26.867+0200

---

## [User Creation can do All users](https://discuss.elastic.co/t/user-creation-can-do-all-users/307840)

<div class="topic-metadata">

**Author:** [@Muhammed\_Ashique](https://discuss.elastic.co/u/Muhammed_Ashique)\
**Replies:** 3\
**Last updated:** [July 14, 2022, 7:56am UTC](https://discuss.elastic.co/t/user-creation-can-do-all-users/307840 "2022-07-14T07:56:12Z")

</div>

I have created a user and this user is login via SSO . But the users who login via sso all users can manage user and Role session under stack management. How can i restrict/disable User creation functionalities for a use…

---

## [Can't create Visualize Library using span.db.statement field](https://discuss.elastic.co/t/cant-create-visualize-library-using-span-db-statement-field/309471)

<div class="topic-metadata">

**Author:** [@Ahmad\_Arif](https://discuss.elastic.co/u/Ahmad_Arif)\
**Replies:** 3\
**Last updated:** [July 14, 2022, 2:45am UTC](https://discuss.elastic.co/t/cant-create-visualize-library-using-span-db-statement-field/309471 "2022-07-14T02:45:59Z")

</div>

Why I can't add field span.db.statement in Visualize Library? I want to show what query with long duration process, btw I'm using APM nodejs Agent. Thanks

---

## [Can kibana compare logs from different area and find the missing one?](https://discuss.elastic.co/t/can-kibana-compare-logs-from-different-area-and-find-the-missing-one/309509)

<div class="topic-metadata">

**Author:** [@josephLiu](https://discuss.elastic.co/u/josephLiu)\
**Replies:** 3\
**Last updated:** [July 14, 2022, 2:31am UTC](https://discuss.elastic.co/t/can-kibana-compare-logs-from-different-area-and-find-the-missing-one/309509 "2022-07-14T02:31:00Z")

</div>

I want to send some logs into elastic index continuous. When my program started logs will be sent into index1 . Finally some logs may lost and other logs will sent into index2 Can kibana compare 2 indexes and find the…

---

## [Add monitor name and URL on Uptime TLS Alert](https://discuss.elastic.co/t/add-monitor-name-and-url-on-uptime-tls-alert/309440)

<div class="topic-metadata">

**Author:** [@zvazquez](https://discuss.elastic.co/u/zvazquez)\
**Replies:** 1\
**Last updated:** [July 14, 2022, 1:41am UTC](https://discuss.elastic.co/t/add-monitor-name-and-url-on-uptime-tls-alert/309440 "2022-07-14T01:41:03Z")

</div>

Hi, Is there any rule variable to add monitor name and/or URL? We are setting Uptime TLS Alert and we would like to add more context information into the action. We were able to add information about the Common Name by…

---

## [How to run curl with Basic Security ( TLS / HTTPS )](https://discuss.elastic.co/t/how-to-run-curl-with-basic-security-tls-https/309479)

<div class="topic-metadata">

**Author:** [@Atul\_Chadha](https://discuss.elastic.co/u/Atul_Chadha)\
**Replies:** 2\
**Last updated:** [July 14, 2022, 1:38am UTC](https://discuss.elastic.co/t/how-to-run-curl-with-basic-security-tls-https/309479 "2022-07-14T01:38:17Z")

</div>

I have configured elasticsearch 7.17 to use TLS and HTTPS and trying to run curl commands to get index stats. The response i get is curl: (52) Empty reply from server. I am debugging an issue wherein post TLS implementa…

---

## [Using tcp plugin to parse logs from multiple sources](https://discuss.elastic.co/t/using-tcp-plugin-to-parse-logs-from-multiple-sources/309565)

<div class="topic-metadata">

**Author:** [@zaeemmasood](https://discuss.elastic.co/u/zaeemmasood)\
**Replies:** 3\
**Last updated:** [July 13, 2022, 9:16pm UTC](https://discuss.elastic.co/t/using-tcp-plugin-to-parse-logs-from-multiple-sources/309565 "2022-07-13T21:16:21Z")

</div>

We are using ELK 7.6.2 stack. I am trying to configure Logstash to parse inputs based on tcp plugin. My config looks like this: input { tcp { port =\> 6789 codec =\> json\_lines tags =\>…

---

## [NMON to JSON Converted Files Will Not Import](https://discuss.elastic.co/t/nmon-to-json-converted-files-will-not-import/309566)

<div class="topic-metadata">

**Author:** [@yoscar](https://discuss.elastic.co/u/yoscar)\
**Replies:** 1\
**Last updated:** [July 13, 2022, 8:14pm UTC](https://discuss.elastic.co/t/nmon-to-json-converted-files-will-not-import/309566 "2022-07-13T20:14:45Z")

</div>

We're trying to ingest nmon data that's recorded over a 24 hour timespan into Logstash. We first convert it to json usin nmon2json (I understand that njmon is an option, but we are trying to use existing nmon files for n…

---

## [Need to extract doc\_count value from ctx.payload.aggregations.by\_store.buckets\_doc\_count](https://discuss.elastic.co/t/need-to-extract-doc-count-value-from-ctx-payload-aggregations-by-store-buckets-doc-count/309577)

<div class="topic-metadata">

**Author:** [@dkumar89](https://discuss.elastic.co/u/dkumar89)\
**Replies:** 2\
**Last updated:** [July 13, 2022, 7:59pm UTC](https://discuss.elastic.co/t/need-to-extract-doc-count-value-from-ctx-payload-aggregations-by-store-buckets-doc-count/309577 "2022-07-13T19:59:38Z")

</div>

Need to extract doc\_count value from each key and do a watcher condition ctx.payload.aggregations.by\_store.buckets\_doc\_count \> 2.

---

## [How to imported file GEOJSON to kibana](https://discuss.elastic.co/t/how-to-imported-file-geojson-to-kibana/309456)

<div class="topic-metadata">

**Author:** [@Khadija\_BOUDINAR1](https://discuss.elastic.co/u/Khadija_BOUDINAR1)\
**Replies:** 10\
**Last updated:** [July 13, 2022, 7:11pm UTC](https://discuss.elastic.co/t/how-to-imported-file-geojson-to-kibana/309456 "2022-07-13T19:11:49Z")

</div>

hi all, i have created new layers in kibana maps and i upload my file geojson but I can't visualize the file have you any suggestion please

---

## [Elasticsearch symlink does not start the service if installed from archive](https://discuss.elastic.co/t/elasticsearch-symlink-does-not-start-the-service-if-installed-from-archive/309574)

<div class="topic-metadata">

**Author:** [@marius03](https://discuss.elastic.co/u/marius03)\
**Replies:** 1\
**Last updated:** [July 13, 2022, 7:10pm UTC](https://discuss.elastic.co/t/elasticsearch-symlink-does-not-start-the-service-if-installed-from-archive/309574 "2022-07-13T19:10:56Z")

</div>

I installed Elasticsearch & Kibana in Linux Mint 20.3 localhost with archive option because installation from Debian Package does not work as expected: Install Elasticsearch from archive on Linux or MacOS | Elasticsearch…

---

## [Grok for data](https://discuss.elastic.co/t/grok-for-data/309093)

<div class="topic-metadata">

**Author:** [@INS](https://discuss.elastic.co/u/INS)\
**Replies:** 17\
**Last updated:** [July 13, 2022, 11:57am UTC](https://discuss.elastic.co/t/grok-for-data/309093 "2022-07-13T11:57:35Z")

</div>

Can anyone try to build grok for below data it's important that timestamp should be took from the first line of document 20220704061503 and interesting columns number: 0000080 data1:abort 0 type: onlist yes input of …

---

## [Creating Index Patterns and Dashboards Using API](https://discuss.elastic.co/t/creating-index-patterns-and-dashboards-using-api/309548)

<div class="topic-metadata">

**Author:** [@christng](https://discuss.elastic.co/u/christng)\
**Replies:** 3\
**Last updated:** [July 13, 2022, 4:54pm UTC](https://discuss.elastic.co/t/creating-index-patterns-and-dashboards-using-api/309548 "2022-07-13T16:54:40Z")

</div>

I'm using Kubernetes and trying to create index patterns and dashboards on Kibana 7.17 using the curl commands but they do not seem to be working. I've followed everything at these sources: Saved objects APIs | Kibana Gu…

---

## [Understanding the result for the query](https://discuss.elastic.co/t/understanding-the-result-for-the-query/307861)

<div class="topic-metadata">

**Author:** [@Seemant\_Bind](https://discuss.elastic.co/u/Seemant_Bind)\
**Replies:** 1\
**Last updated:** [July 13, 2022, 4:47pm UTC](https://discuss.elastic.co/t/understanding-the-result-for-the-query/307861 "2022-07-13T16:47:26Z")

</div>

Continuing the discussion from Restrict specific time range: Hi, As per the issue, you have recommended that time:(from:now%2Fd-12h,to:now%2Fd-12h)) will give data from today's date - 12 hour i.e 12am to 12pm. In my c…

---

## [When field \_index in elasticsearch is generated?](https://discuss.elastic.co/t/when-field-index-in-elasticsearch-is-generated/309519)

<div class="topic-metadata">

**Author:** [@maoxuguang](https://discuss.elastic.co/u/maoxuguang)\
**Replies:** 1\
**Last updated:** [July 13, 2022, 4:19pm UTC](https://discuss.elastic.co/t/when-field-index-in-elasticsearch-is-generated/309519 "2022-07-13T16:19:12Z")

</div>

in elasticsearch, there is a field named \_index, is this field generated by logstash? In logstash we output same data to both elasticsearch and mongodb, while elasticsearch has a field named \_index, but mongodb has no s…

---

## [Elasticsearch Index mappings( version 6.5.4)](https://discuss.elastic.co/t/elasticsearch-index-mappings-version-6-5-4/309535)

<div class="topic-metadata">

**Author:** [@gyrao\_72](https://discuss.elastic.co/u/gyrao_72)\
**Replies:** 2\
**Last updated:** [July 13, 2022, 4:14pm UTC](https://discuss.elastic.co/t/elasticsearch-index-mappings-version-6-5-4/309535 "2022-07-13T16:14:36Z")

</div>

I am using filebeat to fetch logs, logstash to filter, and pushing them to elasticsearch. I have created an index on elasticsearch import-export-logger. This id mapping of import-export-logger. { "import-export-logg…

---

## [My ELK stack the /dev/mapper/centos-root directory is getting full (95%)](https://discuss.elastic.co/t/my-elk-stack-the-dev-mapper-centos-root-directory-is-getting-full-95/309544)

<div class="topic-metadata">

**Author:** [@zanoob](https://discuss.elastic.co/u/zanoob)\
**Replies:** 1\
**Last updated:** [July 13, 2022, 2:57pm UTC](https://discuss.elastic.co/t/my-elk-stack-the-dev-mapper-centos-root-directory-is-getting-full-95/309544 "2022-07-13T14:57:16Z")

</div>

Hello All, Trying to figure out how, but still no luck. If someone can help me out here in this. My Elasticsearch node is getting full \[root@srvde432 nodes\]# df -h Filesystem Size Used Avail Use% Mount…

---

## [Error setting up Fleet Server to monitor .NET or JAVA code monitoring using APM feature](https://discuss.elastic.co/t/error-setting-up-fleet-server-to-monitor-net-or-java-code-monitoring-using-apm-feature/309352)

<div class="topic-metadata">

**Author:** [@aviral\_srivastava](https://discuss.elastic.co/u/aviral_srivastava)\
**Replies:** 1\
**Last updated:** [July 13, 2022, 3:55pm UTC](https://discuss.elastic.co/t/error-setting-up-fleet-server-to-monitor-net-or-java-code-monitoring-using-apm-feature/309352 "2022-07-13T15:55:47Z")

</div>

Hi, I want to use APM feature for my .NET or JAVA code monitoring. Going through APM Guide 8.1, it tells us in order to install APM, we must have below 4 components: APM Agents, Elastic APM Integration, Elasticsearch,…

---

## [Visualize (Count) Keywords in Kibana](https://discuss.elastic.co/t/visualize-count-keywords-in-kibana/309335)

<div class="topic-metadata">

**Author:** [@Cal](https://discuss.elastic.co/u/Cal)\
**Replies:** 1\
**Last updated:** [July 13, 2022, 3:59pm UTC](https://discuss.elastic.co/t/visualize-count-keywords-in-kibana/309335 "2022-07-13T15:59:02Z")

</div>

Hello, I am trying to count the number of times a keyword occurs and graph it alongside other keywords. An example CSV file is: Store | Item | Item | Item A Apple Orange B …

---

## [Failed to find a X509ExtendedTrustManager in the trust manager factory for \[PKIX\] and truststore \[null\]](https://discuss.elastic.co/t/failed-to-find-a-x509extendedtrustmanager-in-the-trust-manager-factory-for-pkix-and-truststore-null/309547)

<div class="topic-metadata">

**Author:** [@blaked](https://discuss.elastic.co/u/blaked)\
**Replies:** 0\
**Last updated:** [July 13, 2022, 3:14pm UTC](https://discuss.elastic.co/t/failed-to-find-a-x509extendedtrustmanager-in-the-trust-manager-factory-for-pkix-and-truststore-null/309547 "2022-07-13T15:14:38Z")

</div>

I'm using Sonarqube Development Edition on Windows 2019 (I've previously posted this to the SQ forums but only gotten light feedback). Things have worked fine for years with the current config - but when I upgraded to S…

---

## [Add dynapmic alias field if target field exist](https://discuss.elastic.co/t/add-dynapmic-alias-field-if-target-field-exist/309543)

<div class="topic-metadata">

**Author:** [@Denergym](https://discuss.elastic.co/u/Denergym)\
**Replies:** 0\
**Last updated:** [July 13, 2022, 2:15pm UTC](https://discuss.elastic.co/t/add-dynapmic-alias-field-if-target-field-exist/309543 "2022-07-13T14:15:59Z")

</div>

Hi ! I need add alias field if target field exist or string. I do this with dynamic templates and aliases field { "mappings": { "dynamic\_templates": \[ { "add\_alias\_for\_open": { "mat…

[Previous page](https://discuss.elastic.co/tag/none.md?no_tags=true&page=584)

[Next page](https://discuss.elastic.co/tag/none.md?no_tags=true&page=586)
