# \#none

**URL:** https://discuss.elastic.co/tag/none.md?no_tags=true&page=590

[Latest](https://discuss.elastic.co/latest.md) · [Categories](https://discuss.elastic.co/categories.md) · [Tags](https://discuss.elastic.co/tags.md)

**Page:** 591

---

## [Change existing field to nested field in index mappinfg](https://discuss.elastic.co/t/change-existing-field-to-nested-field-in-index-mappinfg/309090)

<div class="topic-metadata">

**Author:** [@anand\_tripathi](https://discuss.elastic.co/u/anand_tripathi)\
**Replies:** 1\
**Last updated:** [July 7, 2022, 2:10pm UTC](https://discuss.elastic.co/t/change-existing-field-to-nested-field-in-index-mappinfg/309090 "2022-07-07T14:10:30Z")

</div>

Hi Everyone, I have an existing index with the mapping below { "family": { "mappings": { "properties": { "@timestamp": { "type": "date" }, "@version": { "type": "…

---

## [Duvida filtros kibana](https://discuss.elastic.co/t/duvida-filtros-kibana/308829)

<div class="topic-metadata">

**Author:** [@danielbsilva2](https://discuss.elastic.co/u/danielbsilva2)\
**Replies:** 1\
**Last updated:** [July 7, 2022, 1:35pm UTC](https://discuss.elastic.co/t/duvida-filtros-kibana/308829 "2022-07-07T13:35:56Z")

</div>

boa tarde pessoal sou iniciante ainda nesse mundo de elastic e tenho a seguinte duvida como crio um filtro de busca no meu kibana no discovery (no caso é o que estou usando no momento não sei se é o certo pra isso) do …

---

## [What exactly does "size" mean for a data stream in Kibana](https://discuss.elastic.co/t/what-exactly-does-size-mean-for-a-data-stream-in-kibana/308982)

<div class="topic-metadata">

**Author:** [@woodywoodsta](https://discuss.elastic.co/u/woodywoodsta)\
**Replies:** 4\
**Last updated:** [July 7, 2022, 1:28pm UTC](https://discuss.elastic.co/t/what-exactly-does-size-mean-for-a-data-stream-in-kibana/308982 "2022-07-07T13:28:13Z")

</div>

Hey all. I've got a fleet managed agent which is, via the kubernetes integration (and others), creating data streams. I'm trying to understand what the size column is telling me and I don't seem to be able to find any do…

---

## [Which prometheus metric will give information about snapshot backups](https://discuss.elastic.co/t/which-prometheus-metric-will-give-information-about-snapshot-backups/309117)

<div class="topic-metadata">

**Author:** [@prabhakar\_talari](https://discuss.elastic.co/u/prabhakar_talari)\
**Replies:** 0\
**Last updated:** [July 7, 2022, 1:07pm UTC](https://discuss.elastic.co/t/which-prometheus-metric-will-give-information-about-snapshot-backups/309117 "2022-07-07T13:07:24Z")

</div>

Hi Team, Could some help me is there any promethesu metric which will give information about elastic snapshot backups. As i am using elasticsearch exporter and sending the data to prometheus Thanks,

---

## [How to resolve "Can not decode an entire message...." error in logstash while usingImap plugin?](https://discuss.elastic.co/t/how-to-resolve-can-not-decode-an-entire-message-error-in-logstash-while-usingimap-plugin/309114)

<div class="topic-metadata">

**Author:** [@Ayush\_Gupta](https://discuss.elastic.co/u/Ayush_Gupta)\
**Replies:** 0\
**Last updated:** [July 7, 2022, 12:32pm UTC](https://discuss.elastic.co/t/how-to-resolve-can-not-decode-an-entire-message-error-in-logstash-while-usingimap-plugin/309114 "2022-07-07T12:32:19Z")

</div>

Hi, I am new to Elasticsearch and logstash when I use imap plugin "Can not decode an entire message...." error appears. I have read many posts, understood a few but still unable to get what to do to resolve these errors …

---

## [Date field is not Parsing](https://discuss.elastic.co/t/date-field-is-not-parsing/309006)

<div class="topic-metadata">

**Author:** [@Muhammed\_Ashique](https://discuss.elastic.co/u/Muhammed_Ashique)\
**Replies:** 3\
**Last updated:** [July 7, 2022, 12:14pm UTC](https://discuss.elastic.co/t/date-field-is-not-parsing/309006 "2022-07-07T12:14:43Z")

</div>

Hello Team, i have some data carrying date and this data is tagged with date data type. but sometime this filed is carrying empty body (without Date String) How can i parse for both conditions ? In the Time of Date is i…

---

## [Error while installing index templates](https://discuss.elastic.co/t/error-while-installing-index-templates/309110)

<div class="topic-metadata">

**Author:** [@Thuunder7](https://discuss.elastic.co/u/Thuunder7)\
**Replies:** 0\
**Last updated:** [July 7, 2022, 12:11pm UTC](https://discuss.elastic.co/t/error-while-installing-index-templates/309110 "2022-07-07T12:11:30Z")

</div>

Hi guys, I am having a problem across some pipelines on logstash. Everytime i restart or start logstash i can see that it outputs an error line for some of the pipelines configured. The error is the following: Failed …

---

## [Help with logstash output](https://discuss.elastic.co/t/help-with-logstash-output/309011)

<div class="topic-metadata">

**Author:** [@PJss](https://discuss.elastic.co/u/PJss)\
**Replies:** 3\
**Last updated:** [July 7, 2022, 12:03pm UTC](https://discuss.elastic.co/t/help-with-logstash-output/309011 "2022-07-07T12:03:55Z")

</div>

Hello I'm getting ELK running node in command, that i don't configure, and this string below goes to arcsight: 2022-07-04T12:50:30.046Z {name=TST-FT13} Jul 4 15:50:29 TST-FT13 sshd\[1872\]: Accepted keyboard-interactive/p…

---

## [Kibana index .kibana\_task\_manager goes unassigned after few days and cause Red cluster health on ECK](https://discuss.elastic.co/t/kibana-index-kibana-task-manager-goes-unassigned-after-few-days-and-cause-red-cluster-health-on-eck/309104)

<div class="topic-metadata">

**Author:** [@AaronSarkissian](https://discuss.elastic.co/u/AaronSarkissian)\
**Replies:** 0\
**Last updated:** [July 7, 2022, 11:40am UTC](https://discuss.elastic.co/t/kibana-index-kibana-task-manager-goes-unassigned-after-few-days-and-cause-red-cluster-health-on-eck/309104 "2022-07-07T11:40:08Z")

</div>

I'm setting up a cluster on Azure using ECK. The specifications are following: ECK version: 2.2, 2.3 (tried both) Elastic version: 8.0, 8.1.0, 8.2.0, 8.3.1 (tried all versions) K8s version: 1.23.5 Node size: Standard…

---

## [ElasticSearch Grok Filter](https://discuss.elastic.co/t/elasticsearch-grok-filter/308295)

<div class="topic-metadata">

**Author:** [@HKN\_MZ](https://discuss.elastic.co/u/HKN_MZ)\
**Replies:** 4\
**Last updated:** [July 7, 2022, 11:10am UTC](https://discuss.elastic.co/t/elasticsearch-grok-filter/308295 "2022-07-07T11:10:03Z")

</div>

Hi Everyone, I try to apply grok filter for my logs. As you see I am getting some of them. But I don't get first.jobId=0 or first.applicationname=POLY2 How can I get these fields?

---

## [Issue in extracting all available data in index in elastic using python library elasticsearch](https://discuss.elastic.co/t/issue-in-extracting-all-available-data-in-index-in-elastic-using-python-library-elasticsearch/308470)

<div class="topic-metadata">

**Author:** [@aniketdatir](https://discuss.elastic.co/u/aniketdatir)\
**Replies:** 5\
**Last updated:** [July 7, 2022, 10:56am UTC](https://discuss.elastic.co/t/issue-in-extracting-all-available-data-in-index-in-elastic-using-python-library-elasticsearch/308470 "2022-07-07T10:56:10Z")

</div>

Hi, I am facing below issue. I want to extract full dump that is all available documents from index "X" using python code and save it to json file. But currently M able to extract few documents only using below command.…

---

## [Zabbix + Logstash = Field referenced by ... is missing](https://discuss.elastic.co/t/zabbix-logstash-field-referenced-by-is-missing/309100)

<div class="topic-metadata">

**Author:** [@voidx](https://discuss.elastic.co/u/voidx)\
**Replies:** 0\
**Last updated:** [July 7, 2022, 10:50am UTC](https://discuss.elastic.co/t/zabbix-logstash-field-referenced-by-is-missing/309100 "2022-07-07T10:50:29Z")

</div>

I'm trying to configure sending messages from the log to Zabbix, I ran into this problem. When running Logstash, there are a bunch of errors of this type in the log \[logstash.outputs.zabbix\]\[main\]\[2ef3e6f6411863c21dc15…

---

## [Logstash filter is not working ...kindly help](https://discuss.elastic.co/t/logstash-filter-is-not-working-kindly-help/306306)

<div class="topic-metadata">

**Author:** [@aniketdatir](https://discuss.elastic.co/u/aniketdatir)\
**Replies:** 11\
**Last updated:** [July 7, 2022, 10:20am UTC](https://discuss.elastic.co/t/logstash-filter-is-not-working-kindly-help/306306 "2022-07-07T10:20:18Z")

</div>

Hi, Need your help I've bunch of messages if kafka. few samples are given below. {"processId":40,"parentProcessId":40,"type":"Info","service":"a-b-c","object":"common\_factory","method":"listUsers","log":"Start listUs…

---

## [Search Api doesn't give result of analytics clicks](https://discuss.elastic.co/t/search-api-doesnt-give-result-of-analytics-clicks/309089)

<div class="topic-metadata">

**Author:** [@bilal.shahid](https://discuss.elastic.co/u/bilal.shahid)\
**Replies:** 0\
**Last updated:** [July 7, 2022, 8:55am UTC](https://discuss.elastic.co/t/search-api-doesnt-give-result-of-analytics-clicks/309089 "2022-07-07T08:55:05Z")

</div>

I have a table of Search Terms in Analytics of ElasticSearch with the columns of document\_ids of their products, Analytics tags, and clicks. I am searching the query on Postman using Search API of Elasticsearch to get th…

---

## [Kibana index .kibana\_task\_manager goes unassigned after few days and cause Red cluster health](https://discuss.elastic.co/t/kibana-index-kibana-task-manager-goes-unassigned-after-few-days-and-cause-red-cluster-health/309028)

<div class="topic-metadata">

**Author:** [@AaronSarkissian](https://discuss.elastic.co/u/AaronSarkissian)\
**Replies:** 2\
**Last updated:** [July 7, 2022, 8:37am UTC](https://discuss.elastic.co/t/kibana-index-kibana-task-manager-goes-unassigned-after-few-days-and-cause-red-cluster-health/309028 "2022-07-07T08:37:44Z")

</div>

I'm setting up a cluster on Azure using ECK. The specifications are following: ECK version: 2.2, 2.3 (tried both) Elastic version: 8.0, 8.1.0, 8.2.0, 8.3.1 (tried all versions) K8s version: 1.23.5 Node size: Standard…

---

## [Can search\_as\_you\_type field show the prefix match results firstly](https://discuss.elastic.co/t/can-search-as-you-type-field-show-the-prefix-match-results-firstly/309083)

<div class="topic-metadata">

**Author:** [@zhengpq](https://discuss.elastic.co/u/zhengpq)\
**Replies:** 0\
**Last updated:** [July 7, 2022, 7:29am UTC](https://discuss.elastic.co/t/can-search-as-you-type-field-show-the-prefix-match-results-firstly/309083 "2022-07-07T07:29:47Z")

</div>

i am using the search\_as\_you\_type to auto complete, it is good, but i find the result is sorted by the score, now i need the prefix match results to come firstly, look the example blow: POST page-new/\_search { "\_sour…

---

## [Failed to resolve publish address - error in eck on-premise deployment with kubeadm kubernetes](https://discuss.elastic.co/t/failed-to-resolve-publish-address-error-in-eck-on-premise-deployment-with-kubeadm-kubernetes/307765)

<div class="topic-metadata">

**Author:** [@sanju\_techie](https://discuss.elastic.co/u/sanju_techie)\
**Replies:** 1\
**Last updated:** [July 7, 2022, 7:19am UTC](https://discuss.elastic.co/t/failed-to-resolve-publish-address-error-in-eck-on-premise-deployment-with-kubeadm-kubernetes/307765 "2022-07-07T07:19:25Z")

</div>

Hi All, I have setup a kubernetes cluster with kubeadm where I am trying to deploy the eck , I am trying with the simple deployment mentioned below. apiVersion: elasticsearch.k8s.elastic.co/v1 kind: Elasticsearch metad…

---

## [Edge-ngram not working for single edge case!](https://discuss.elastic.co/t/edge-ngram-not-working-for-single-edge-case/309059)

<div class="topic-metadata">

**Author:** [@corndog](https://discuss.elastic.co/u/corndog)\
**Replies:** 1\
**Last updated:** [July 7, 2022, 7:06am UTC](https://discuss.elastic.co/t/edge-ngram-not-working-for-single-edge-case/309059 "2022-07-07T07:06:49Z")

</div>

My edge-ngram solution does not return any results for the following search: "10th A" Where 3 documents exist with the field values: "10th Avenue, Red Beach, New Zealand", "4 10th Avenue, Red Beach, New Zealand", …

---

## [Visualizeのデータテーブルについて](https://discuss.elastic.co/t/visualize/309079)

<div class="topic-metadata">

**Author:** [@na\_taka](https://discuss.elastic.co/u/na_taka)\
**Replies:** 0\
**Last updated:** [July 7, 2022, 6:40am UTC](https://discuss.elastic.co/t/visualize/309079 "2022-07-07T06:40:20Z")

</div>

お世話になっております。 Visualizeのデータテーブルの設定について質問です。 【input data】 code result a OK a OK a NG b NG b NG 上記のようなデータに対し、以下のようにデータテーブルで表示させたいのですが、 実現できませんでしょうか。実現できる場合、どの様な設定を行えば良いかご教示頂けませんでしょうか。 ==== 【データテーブル…

---

## [Sorting on nested field and then apply aggregation](https://discuss.elastic.co/t/sorting-on-nested-field-and-then-apply-aggregation/309078)

<div class="topic-metadata">

**Author:** [@aryamansingh888](https://discuss.elastic.co/u/aryamansingh888)\
**Replies:** 0\
**Last updated:** [July 7, 2022, 6:34am UTC](https://discuss.elastic.co/t/sorting-on-nested-field-and-then-apply-aggregation/309078 "2022-07-07T06:34:19Z")

</div>

"visitor\_data": \[ { "end\_date": "2021-06-08", "pre\_status": "1", "evisitor": true, "edition\_id": "644659", "flag": "1", "event\_functionality": "o…

---

## [Format issue using http output plugin to send logs from logstash to azure eventhub](https://discuss.elastic.co/t/format-issue-using-http-output-plugin-to-send-logs-from-logstash-to-azure-eventhub/309073)

<div class="topic-metadata">

**Author:** [@Shakib\_farooq](https://discuss.elastic.co/u/Shakib_farooq)\
**Replies:** 1\
**Last updated:** [July 7, 2022, 6:02am UTC](https://discuss.elastic.co/t/format-issue-using-http-output-plugin-to-send-logs-from-logstash-to-azure-eventhub/309073 "2022-07-07T06:02:02Z")

</div>

Hello, I am facing an issue in forwarding logs from logstash to the event hub, below is the conf file. the requirement is to forward winlog beats logs to the event hub. I am receiving logs in elastic if I kept the form…

---

## [Send an email when Logstash service is down/not running](https://discuss.elastic.co/t/send-an-email-when-logstash-service-is-down-not-running/309068)

<div class="topic-metadata">

**Author:** [@suresh\_u](https://discuss.elastic.co/u/suresh_u)\
**Replies:** 2\
**Last updated:** [July 7, 2022, 5:56am UTC](https://discuss.elastic.co/t/send-an-email-when-logstash-service-is-down-not-running/309068 "2022-07-07T05:56:33Z")

</div>

Hi team, I have run Logstash as a service in Remote windows. It is working fine now. But in case of failure scenario, If Logstash service shuts down unexpectedly, then I need to send(alert) an email to the team. How c…

---

## [Cannot use scripted field in Elasticsearch query?](https://discuss.elastic.co/t/cannot-use-scripted-field-in-elasticsearch-query/309040)

<div class="topic-metadata">

**Author:** [@Sandeep\_Raju](https://discuss.elastic.co/u/Sandeep_Raju)\
**Replies:** 1\
**Last updated:** [July 7, 2022, 2:41am UTC](https://discuss.elastic.co/t/cannot-use-scripted-field-in-elasticsearch-query/309040 "2022-07-07T02:41:11Z")

</div>

Hi all, I'm using a scripted field, but I'm unable to query with scripted field. Anyway we can use scripted field in elasticsearch? For ex if I query below in dev tools it always gives count as 0: GET my\_index\_\*/\_sea…

---

## [Node Not Showing in Kibana](https://discuss.elastic.co/t/node-not-showing-in-kibana/309027)

<div class="topic-metadata">

**Author:** [@bkamiche](https://discuss.elastic.co/u/bkamiche)\
**Replies:** 1\
**Last updated:** [July 7, 2022, 2:04am UTC](https://discuss.elastic.co/t/node-not-showing-in-kibana/309027 "2022-07-07T02:04:50Z")

</div>

I have a 9 node Cluster (6 data and 3 Masters), with version 7.15.5 (all on Intel platform), the cluster works fine. I've added a new data node, with the same version but in ARM, the node has been recognized by the clus…

---

## [Block 32844 not found](https://discuss.elastic.co/t/block-32844-not-found/308873)

<div class="topic-metadata">

**Author:** [@zhilong](https://discuss.elastic.co/u/zhilong)\
**Replies:** 5\
**Last updated:** [July 7, 2022, 1:41am UTC](https://discuss.elastic.co/t/block-32844-not-found/308873 "2022-07-07T01:41:31Z")

</div>

This category relates to the Enterprise Search set of products - App Search, Site Search and Workplace Search. If your question relates to core Elasticsearch functionality, please head over to the #elastic-stack:elastic…

---

## [Http input logstash I want filter logs](https://discuss.elastic.co/t/http-input-logstash-i-want-filter-logs/307724)

<div class="topic-metadata">

**Author:** [@dharminfadia](https://discuss.elastic.co/u/dharminfadia)\
**Replies:** 1\
**Last updated:** [July 6, 2022, 11:37pm UTC](https://discuss.elastic.co/t/http-input-logstash-i-want-filter-logs/307724 "2022-07-06T23:37:12Z")

</div>

Hello Everyone I am using http input plugin in logstash I want to filter only POST request from Perticular URL logs should be input and output to elasticsearch how can I achive this.

---

## [Error while starting logstash 8.3.1](https://discuss.elastic.co/t/error-while-starting-logstash-8-3-1/308811)

<div class="topic-metadata">

**Author:** [@Thuunder7](https://discuss.elastic.co/u/Thuunder7)\
**Replies:** 2\
**Last updated:** [July 6, 2022, 10:01pm UTC](https://discuss.elastic.co/t/error-while-starting-logstash-8-3-1/308811 "2022-07-06T22:01:21Z")

</div>

Hello guys, Recently i upgraded my logstash instance from 7.x to 8.3.1. But now when i try to start the logstash service, i get the following log: \[ERROR\]\[logstash.runner \] Logging configuration uses Script …

---

## [Java API update index](https://discuss.elastic.co/t/java-api-update-index/308928)

<div class="topic-metadata">

**Author:** [@Dorian](https://discuss.elastic.co/u/Dorian)\
**Replies:** 2\
**Last updated:** [July 6, 2022, 9:18pm UTC](https://discuss.elastic.co/t/java-api-update-index/308928 "2022-07-06T21:18:43Z")

</div>

HI everyone, I want to add a new field to a document already indexed. I find this in the documentation: curl -X POST "localhost:9200/home2/\_update/Y\_vIvoEB3cv\_8tuHzt7j?pretty" -H 'Content-Type: application/json' -d' { …

---

## [Manipulate fields in Kibana](https://discuss.elastic.co/t/manipulate-fields-in-kibana/308512)

<div class="topic-metadata">

**Author:** [@zaeemmasood](https://discuss.elastic.co/u/zaeemmasood)\
**Replies:** 2\
**Last updated:** [July 6, 2022, 8:48pm UTC](https://discuss.elastic.co/t/manipulate-fields-in-kibana/308512 "2022-07-06T20:48:23Z")

</div>

Hello. We are using ELK 7.6.2 stack. Kibana console shows the fields as follows: I want to introduce/ add a new field displayed as say "sum" and it should display the sum of "before" and "after" (highlighted as yell…

---

## [Logstash isn't starting. Getting a FATAL error](https://discuss.elastic.co/t/logstash-isnt-starting-getting-a-fatal-error/309045)

<div class="topic-metadata">

**Author:** [@kakkarsachin7](https://discuss.elastic.co/u/kakkarsachin7)\
**Replies:** 6\
**Last updated:** [July 6, 2022, 8:40pm UTC](https://discuss.elastic.co/t/logstash-isnt-starting-getting-a-fatal-error/309045 "2022-07-06T20:40:00Z")

</div>

I am new to ELK stack. I am able to start Elasticsearch and Kibana but unable to start Logstash using command logstash -f logstash-studio.conf Version 7.14 Java Version 1.8 Here are the logs:- Using JAVA\_HOME defined…

[Previous page](https://discuss.elastic.co/tag/none.md?no_tags=true&page=589)

[Next page](https://discuss.elastic.co/tag/none.md?no_tags=true&page=591)
