# \#none

**URL:** https://discuss.elastic.co/tag/none.md?no_tags=true&page=589

[Latest](https://discuss.elastic.co/latest.md) · [Categories](https://discuss.elastic.co/categories.md) · [Tags](https://discuss.elastic.co/tags.md)

**Page:** 590

---

## [Using Custom Elastic Charts Fork in Kibana](https://discuss.elastic.co/t/using-custom-elastic-charts-fork-in-kibana/302780)

<div class="topic-metadata">

**Author:** [@Jacob\_Williams](https://discuss.elastic.co/u/Jacob_Williams)\
**Replies:** 2\
**Last updated:** [July 8, 2022, 4:47pm UTC](https://discuss.elastic.co/t/using-custom-elastic-charts-fork-in-kibana/302780 "2022-07-08T16:47:31Z")

</div>

Like the title suggests I am trying to use a custom fork of elastic-charts in Kibana so I can do some custom themeing, mostly small things like adjusting font size on bar chart to client request. I was able to prepare a…

---

## [Convert json nested fields into integer](https://discuss.elastic.co/t/convert-json-nested-fields-into-integer/309167)

<div class="topic-metadata">

**Author:** [@mangeshmj1992](https://discuss.elastic.co/u/mangeshmj1992)\
**Replies:** 7\
**Last updated:** [July 8, 2022, 4:23pm UTC](https://discuss.elastic.co/t/convert-json-nested-fields-into-integer/309167 "2022-07-08T16:23:35Z")

</div>

Hi. I am trying to convert a field read by a json filter in logstash. I am used to convert fields from other sources, but with this nested field from a json log file, I cannot convert a quoted number string to a integer. …

---

## [Migrate Elasticsearch from Elastic Helm Charts to Elastic Operator (ECK)](https://discuss.elastic.co/t/migrate-elasticsearch-from-elastic-helm-charts-to-elastic-operator-eck/307924)

<div class="topic-metadata">

**Author:** [@DougR](https://discuss.elastic.co/u/DougR)\
**Replies:** 2\
**Last updated:** [July 8, 2022, 4:22pm UTC](https://discuss.elastic.co/t/migrate-elasticsearch-from-elastic-helm-charts-to-elastic-operator-eck/307924 "2022-07-08T16:22:41Z")

</div>

I'm migrating our stack from the Elastic Helm Charts to Elastic Operator (ECK). Are there any easy guides/recipes for migrating without losing all my data? Thx.

---

## [3.3.0 Released](https://discuss.elastic.co/t/3-3-0-released/309220)

<div class="topic-metadata">

**Author:** [@Olivier\_Bierlaire](https://discuss.elastic.co/u/Olivier_Bierlaire)\
**Replies:** 0\
**Last updated:** [July 8, 2022, 4:11pm UTC](https://discuss.elastic.co/t/3-3-0-released/309220 "2022-07-08T16:11:07Z")

</div>

We are pleased to announce that ECE 3.3.0 has been released today. Release notes: Elastic Cloud Enterprise 3.3.0 | Elastic Cloud Enterprise Reference \[3.3\] | Elastic

---

## [Flattening JSON string level with other fields](https://discuss.elastic.co/t/flattening-json-string-level-with-other-fields/309182)

<div class="topic-metadata">

**Author:** [@Mostafa\_Talebi](https://discuss.elastic.co/u/Mostafa_Talebi)\
**Replies:** 1\
**Last updated:** [July 8, 2022, 4:03pm UTC](https://discuss.elastic.co/t/flattening-json-string-level-with-other-fields/309182 "2022-07-08T16:03:43Z")

</div>

I have set up my kibana and Elastic. I am getting my logs from Fluentbit. My main app log, which is JSON, is sent by Fluent with other meta fields like this: { "containerId": "foo", "clusterId" : "bar", "s…

---

## [Kibana TSVB Markdown styling](https://discuss.elastic.co/t/kibana-tsvb-markdown-styling/309208)

<div class="topic-metadata">

**Author:** [@Adriann](https://discuss.elastic.co/u/Adriann)\
**Replies:** 1\
**Last updated:** [July 8, 2022, 3:26pm UTC](https://discuss.elastic.co/t/kibana-tsvb-markdown-styling/309208 "2022-07-08T15:26:34Z")

</div>

Hello, I want to create a pretty and highly functional dashboard containing all important information and metrics regarding the whole network. Right now I am working on displaying information on failover status for ASA …

---

## [Kiban show wrong time](https://discuss.elastic.co/t/kiban-show-wrong-time/309193)

<div class="topic-metadata">

**Author:** [@anton.potekhin](https://discuss.elastic.co/u/anton.potekhin)\
**Replies:** 4\
**Last updated:** [July 8, 2022, 3:01pm UTC](https://discuss.elastic.co/t/kiban-show-wrong-time/309193 "2022-07-08T15:01:16Z")

</div>

i have log messages in the following format: {"@timestamp":"2022-07-08T10:01:43.181Z","log.level":"info","message":"verifyReceipt: found receipt","ecs":{"version":"1.6.0"}} @timestamp in UTC. When i check logs in Kiban…

---

## [Grok Parsing](https://discuss.elastic.co/t/grok-parsing/309200)

<div class="topic-metadata">

**Author:** [@escanor\_sama](https://discuss.elastic.co/u/escanor_sama)\
**Replies:** 2\
**Last updated:** [July 8, 2022, 2:03pm UTC](https://discuss.elastic.co/t/grok-parsing/309200 "2022-07-08T14:03:28Z")

</div>

Hi everyone, I am having trouble when I want to parse this Fortigate Log \<189\>devname="FWFG240D" type="traffic" subtype="forward" level="notice" vd="root" eventtime=1565130979 srcip=146.0.138.202 srcport=61103 dstip=192…

---

## [Unable to search array values on filter](https://discuss.elastic.co/t/unable-to-search-array-values-on-filter/309196)

<div class="topic-metadata">

**Author:** [@Himanshu\_Joshi1](https://discuss.elastic.co/u/Himanshu_Joshi1)\
**Replies:** 2\
**Last updated:** [July 8, 2022, 1:07pm UTC](https://discuss.elastic.co/t/unable-to-search-array-values-on-filter/309196 "2022-07-08T13:07:43Z")

</div>

\*\*This is my data\*\* { "took" : 2, "timed\_out" : false, "\_shards" : { "total" : 6, "successful" : 6, "skipped" : 0, "failed" : 0 }, "hits" : { "total" : { "value" : 2, "relation" …

---

## [Elasticsearch - Score for a document pair](https://discuss.elastic.co/t/elasticsearch-score-for-a-document-pair/309172)

<div class="topic-metadata">

**Author:** [@Pazhaniyappan](https://discuss.elastic.co/u/Pazhaniyappan)\
**Replies:** 1\
**Last updated:** [July 8, 2022, 12:52pm UTC](https://discuss.elastic.co/t/elasticsearch-score-for-a-document-pair/309172 "2022-07-08T12:52:41Z")

</div>

Hello, Is there a way to find out the similarity between the two documents? For example, I have document A and document B in JSON format. I will select some parameters from the documents for calculating the match sco…

---

## [使用Filebeat创建新索引ILM的问题](https://discuss.elastic.co/t/filebeat-ilm/308777)

<div class="topic-metadata">

**Author:** [@busishe](https://discuss.elastic.co/u/busishe)\
**Replies:** 6\
**Last updated:** [July 8, 2022, 12:19pm UTC](https://discuss.elastic.co/t/filebeat-ilm/308777 "2022-07-08T12:19:42Z")

</div>

我编辑了 filebeat.yml 中的配置项"setup.ilm.policy\_name"指定索引的ilm策略为我在kibana中自建的测试策略。 filebeat日志启动的时候看到它做了相关的检测，这个配置是生效了的。 {"log.level":"info","@timestamp":"2022-07-04T02:51:11.473Z","log.logger":"index-management.ilm","log.origi…

---

## [Elasticsearch Unreachable Error](https://discuss.elastic.co/t/elasticsearch-unreachable-error/309185)

<div class="topic-metadata">

**Author:** [@pooja5](https://discuss.elastic.co/u/pooja5)\
**Replies:** 1\
**Last updated:** [July 8, 2022, 11:15am UTC](https://discuss.elastic.co/t/elasticsearch-unreachable-error/309185 "2022-07-08T11:15:55Z")

</div>

Hello! We have observed a log message \[ERROR\]\[logstash.outputs.elasticsearch\]\[.monitoring-logstash\] Attempted to send a bulk request to elasticsearch' but Elasticsearch appears to be unreachable or down! {:error\_messa…

---

## [PVC/PV for ECK](https://discuss.elastic.co/t/pvc-pv-for-eck/309192)

<div class="topic-metadata">

**Author:** [@Biplab](https://discuss.elastic.co/u/Biplab)\
**Replies:** 0\
**Last updated:** [July 8, 2022, 10:30am UTC](https://discuss.elastic.co/t/pvc-pv-for-eck/309192 "2022-07-08T10:30:55Z")

</div>

Hi, I wanted to create PVC (Persistence volume claim) for data node alone. For Master node and Kibana we are planning to have local/Network attached SSD. How do we create YAML file for such configuration, I have attach…

---

## [Log UI doesn't show log.level](https://discuss.elastic.co/t/log-ui-doesnt-show-log-level/309191)

<div class="topic-metadata">

**Author:** [@anton.potekhin](https://discuss.elastic.co/u/anton.potekhin)\
**Replies:** 0\
**Last updated:** [July 8, 2022, 10:26am UTC](https://discuss.elastic.co/t/log-ui-doesnt-show-log-level/309191 "2022-07-08T10:26:52Z")

</div>

I have filebeat that process my logs. Logs in the following format: {"@timestamp":"2022-07-08T10:01:43.181Z","log.level":"info","message":"verifyReceipt: found receipt","ecs":{"version":"1.6.0"}} When i use discover s…

---

## [Generar alerta compleja](https://discuss.elastic.co/t/generar-alerta-compleja/309189)

<div class="topic-metadata">

**Author:** [@magosama](https://discuss.elastic.co/u/magosama)\
**Replies:** 0\
**Last updated:** [July 8, 2022, 10:22am UTC](https://discuss.elastic.co/t/generar-alerta-compleja/309189 "2022-07-08T10:22:18Z")

</div>

Buenas a todos. Soy nuevo en esto de kibana y estoy aprendiendo. Me han planteado un problema que no soy capaz de resolver. Necesitan generar una alarma cuando se de una situación especial. En un dashboard visualizo todo…

---

## [Memory usage of completion/context suggester](https://discuss.elastic.co/t/memory-usage-of-completion-context-suggester/309186)

<div class="topic-metadata">

**Author:** [@mpinho](https://discuss.elastic.co/u/mpinho)\
**Replies:** 0\
**Last updated:** [July 8, 2022, 9:20am UTC](https://discuss.elastic.co/t/memory-usage-of-completion-context-suggester/309186 "2022-07-08T09:20:35Z")

</div>

Hello, I have a question regarding the context suggester implementation, on Elasticsearch 8.3.1. I have this mapping: { "mappings": { "properties": { "suggest": { "type": "completion", "contexts": \[ …

---

## [Dashboard - field Host.hostname not found error](https://discuss.elastic.co/t/dashboard-field-host-hostname-not-found-error/309173)

<div class="topic-metadata">

**Author:** [@Darshana](https://discuss.elastic.co/u/Darshana)\
**Replies:** 3\
**Last updated:** [July 8, 2022, 7:55am UTC](https://discuss.elastic.co/t/dashboard-field-host-hostname-not-found-error/309173 "2022-07-08T07:55:36Z")

</div>

Hi, I'm getting error for Kibana Dashboard : "Field host.hostname was not found Edit in Lens editor to see more errors"

---

## [Bulk Partial update of a Nested object List by condition](https://discuss.elastic.co/t/bulk-partial-update-of-a-nested-object-list-by-condition/308948)

<div class="topic-metadata">

**Author:** [@krishnapss](https://discuss.elastic.co/u/krishnapss)\
**Replies:** 2\
**Last updated:** [July 8, 2022, 7:28am UTC](https://discuss.elastic.co/t/bulk-partial-update-of-a-nested-object-list-by-condition/308948 "2022-07-08T07:28:08Z")

</div>

Hi, I have an index which has nested list object. I need to only update certain values based on a condition. List of history with dates and values I need to update only certain dates values. In the below example I only …

---

## [Deploy an Elasticsearch cluster with QuickStart](https://discuss.elastic.co/t/deploy-an-elasticsearch-cluster-with-quickstart/308656)

<div class="topic-metadata">

**Author:** [@Nortena](https://discuss.elastic.co/u/Nortena)\
**Replies:** 13\
**Last updated:** [July 8, 2022, 7:03am UTC](https://discuss.elastic.co/t/deploy-an-elasticsearch-cluster-with-quickstart/308656 "2022-07-08T07:03:40Z")

</div>

I have deployed ECK in a cluster and the quickstart has stayed in the "ApplyingChanges" phase and the quickstart pods are like this: NAMESPACE NAME HEALTH NODES VERSION PHASE AGE monitorin…

---

## [ElasticSearch POST \_doc and doc issue](https://discuss.elastic.co/t/elasticsearch-post-doc-and-doc-issue/309097)

<div class="topic-metadata">

**Author:** [@Even\_Zhang](https://discuss.elastic.co/u/Even_Zhang)\
**Replies:** 5\
**Last updated:** [July 8, 2022, 5:36am UTC](https://discuss.elastic.co/t/elasticsearch-post-doc-and-doc-issue/309097 "2022-07-08T05:36:58Z")

</div>

Hi everyone, I through curl to POST new index with doc like curl -XPOST -H "Content-Type: application/json" 'http://localhost:9200/portstats/doc/' -d '{"bytesReceived":0,"bytesSent":0,"@timestamp":"2022-07-10T23:43:01.…

---

## [Logstash output question](https://discuss.elastic.co/t/logstash-output-question/309138)

<div class="topic-metadata">

**Author:** [@jlbai](https://discuss.elastic.co/u/jlbai)\
**Replies:** 3\
**Last updated:** [July 7, 2022, 10:25pm UTC](https://discuss.elastic.co/t/logstash-output-question/309138 "2022-07-07T22:25:25Z")

</div>

sh-4.2$ sudo /usr/share/logstash/bin/logstash -f /etc/logstash/conf.d/firewall.conf Using bundled JDK: /usr/share/logstash/jdk OpenJDK 64-Bit Server VM warning: Option UseConcMarkSweepGC was deprecated in version 9.0 a…

---

## [How do I check if field contains certain string?](https://discuss.elastic.co/t/how-do-i-check-if-field-contains-certain-string/309148)

<div class="topic-metadata">

**Author:** [@DataStorageMuse](https://discuss.elastic.co/u/DataStorageMuse)\
**Replies:** 4\
**Last updated:** [July 7, 2022, 9:23pm UTC](https://discuss.elastic.co/t/how-do-i-check-if-field-contains-certain-string/309148 "2022-07-07T21:23:21Z")

</div>

How do I query an index to return documents where a field contains only a certain string (analagous to SQL contains). This is the corresponding SQL query I would like to do in ElasticSearch. SELECT \* FROM table WHERE CON…

---

## [Elastic SIEM miss leading text on analyzer](https://discuss.elastic.co/t/elastic-siem-miss-leading-text-on-analyzer/309150)

<div class="topic-metadata">

**Author:** [@PublicName](https://discuss.elastic.co/u/PublicName)\
**Replies:** 2\
**Last updated:** [July 7, 2022, 9:02pm UTC](https://discuss.elastic.co/t/elastic-siem-miss-leading-text-on-analyzer/309150 "2022-07-07T21:02:22Z")

</div>

Elastic Endpoint is Detect mode. All SIEM triggered alerts do the same for Endpoint injected events. Detect and Prevent should be clearly marked. In this example "Suspicious WMI Image Load from MS Office" is going to b…

---

## [More complicated calculation/visualisaton - is it possible?](https://discuss.elastic.co/t/more-complicated-calculation-visualisaton-is-it-possible/309136)

<div class="topic-metadata">

**Author:** [@Frantisek\_Sitler](https://discuss.elastic.co/u/Frantisek_Sitler)\
**Replies:** 1\
**Last updated:** [July 7, 2022, 7:52pm UTC](https://discuss.elastic.co/t/more-complicated-calculation-visualisaton-is-it-possible/309136 "2022-07-07T19:52:52Z")

</div>

Hello, I have an issue to create a bit more complex calculation and visualization. It should take data from multiple indices, always an record will be connected via one field - IN number. There is always multiple recor…

---

## [Project monitor | push throwing cannot be marked as external""](https://discuss.elastic.co/t/project-monitor-push-throwing-cannot-be-marked-as-external/309142)

<div class="topic-metadata">

**Author:** [@Harsha\_Nagasamudra](https://discuss.elastic.co/u/Harsha_Nagasamudra)\
**Replies:** 0\
**Last updated:** [July 7, 2022, 7:02pm UTC](https://discuss.elastic.co/t/project-monitor-push-throwing-cannot-be-marked-as-external/309142 "2022-07-07T19:02:53Z")

</div>

Hay Team. This is regarding the Synthetic monitoring, we were trying out project monitors . We followed all the steps but we ar getting " .ts file cannot be marked as external" on doing the npx push command. Can any one …

---

## [SecurityNetty4HttpServerTransport received plaintext http traffic on an https channel](https://discuss.elastic.co/t/securitynetty4httpservertransport-received-plaintext-http-traffic-on-an-https-channel/309137)

<div class="topic-metadata">

**Author:** [@Sameer\_Malik](https://discuss.elastic.co/u/Sameer_Malik)\
**Replies:** 0\
**Last updated:** [July 7, 2022, 6:11pm UTC](https://discuss.elastic.co/t/securitynetty4httpservertransport-received-plaintext-http-traffic-on-an-https-channel/309137 "2022-07-07T18:11:30Z")

</div>

Hello everyone! I'm quite new to Elasticsearch and networks. I just managed to install elasticsearch on an external disk, and it seemed to install just fine ✅ Elasticsearch security features have been automatically co…

---

## [Heartbeat Expression Body Content](https://discuss.elastic.co/t/heartbeat-expression-body-content/309134)

<div class="topic-metadata">

**Author:** [@Rossana](https://discuss.elastic.co/u/Rossana)\
**Replies:** 0\
**Last updated:** [July 7, 2022, 5:41pm UTC](https://discuss.elastic.co/t/heartbeat-expression-body-content/309134 "2022-07-07T17:41:12Z")

</div>

Hi, I am trying to monitor an endpoint but I need check if in the json response body exists this expression: "status":"Success" or only the word "Success" at least. This is my test: Json Response: { "latest\_run":…

---

## [Kibana logs is full](https://discuss.elastic.co/t/kibana-logs-is-full/307903)

<div class="topic-metadata">

**Author:** [@ptang](https://discuss.elastic.co/u/ptang)\
**Replies:** 3\
**Last updated:** [July 7, 2022, 2:55pm UTC](https://discuss.elastic.co/t/kibana-logs-is-full/307903 "2022-07-07T14:55:47Z")

</div>

can anyone help me how to cleanup the kibana.log files under /var/log/kibana directory. kibana.log filled my diskspace and no space to write the logs. Thanks, pradeep

---

## [Discuss UI issue. "Recommended for you"](https://discuss.elastic.co/t/discuss-ui-issue-recommended-for-you/309102)

<div class="topic-metadata">

**Author:** [@ruant](https://discuss.elastic.co/u/ruant)\
**Replies:** 1\
**Last updated:** [July 7, 2022, 2:38pm UTC](https://discuss.elastic.co/t/discuss-ui-issue-recommended-for-you/309102 "2022-07-07T14:38:51Z")

</div>

The "Recommended for you" is taking up a lot of space and is making the threads very hard to read... Tested on both Chrome (Version 103.0.5060.114 (Official Build) (64-bit)) and Firefox (102.0.1 (64-bit))

---

## [Conexión SharePoint a logstash](https://discuss.elastic.co/t/conexion-sharepoint-a-logstash/309047)

<div class="topic-metadata">

**Author:** [@arley\_nova\_salgado](https://discuss.elastic.co/u/arley_nova_salgado)\
**Replies:** 2\
**Last updated:** [July 7, 2022, 2:18pm UTC](https://discuss.elastic.co/t/conexion-sharepoint-a-logstash/309047 "2022-07-07T14:18:36Z")

</div>

I'm trying to create an input that receives data from sharepoint, but I can't find any information on this topic. Can you help me, please.

[Previous page](https://discuss.elastic.co/tag/none.md?no_tags=true&page=588)

[Next page](https://discuss.elastic.co/tag/none.md?no_tags=true&page=590)
