# \#none

**URL:** https://discuss.elastic.co/tag/none.md?no_tags=true&page=592

[Latest](https://discuss.elastic.co/latest.md) · [Categories](https://discuss.elastic.co/categories.md) · [Tags](https://discuss.elastic.co/tags.md)

**Page:** 593

---

## [Logstash parsing XML failing on second and subsequent records](https://discuss.elastic.co/t/logstash-parsing-xml-failing-on-second-and-subsequent-records/308905)

<div class="topic-metadata">

**Author:** [@Gerrard](https://discuss.elastic.co/u/Gerrard)\
**Replies:** 2\
**Last updated:** [July 5, 2022, 2:54pm UTC](https://discuss.elastic.co/t/logstash-parsing-xml-failing-on-second-and-subsequent-records/308905 "2022-07-05T14:54:55Z")

</div>

Hi, I'm struggling to understand why logstash is unable to process any records beyond the first in my XML log file. The first record is parsed fine, but then any following ones get the "\_xmlparsefailure" tag. My log fil…

---

## [Logstash 'file\_chunk\_size'](https://discuss.elastic.co/t/logstash-file-chunk-size/308659)

<div class="topic-metadata">

**Author:** [@ChinigamiHunter](https://discuss.elastic.co/u/ChinigamiHunter)\
**Replies:** 3\
**Last updated:** [July 5, 2022, 2:23pm UTC](https://discuss.elastic.co/t/logstash-file-chunk-size/308659 "2022-07-05T14:23:06Z")

</div>

hi all, i have some files in a folder and i want to index them in Elasticsearch using logstash. some of the files are indexed, but i get a lot of this error i don't know why : \[2022-06-30T16:15:24,966\]\[INFO \]\[filewatc…

---

## [Send only one field in pipeline to pipeline communication](https://discuss.elastic.co/t/send-only-one-field-in-pipeline-to-pipeline-communication/308002)

<div class="topic-metadata">

**Author:** [@Laetitia\_RICHARD](https://discuss.elastic.co/u/Laetitia_RICHARD)\
**Replies:** 9\
**Last updated:** [July 5, 2022, 2:17pm UTC](https://discuss.elastic.co/t/send-only-one-field-in-pipeline-to-pipeline-communication/308002 "2022-07-05T14:17:08Z")

</div>

Hello, I'd like my 1st pipeline to send the event to an Elasticsearch output and only a field's event to the input of a 2nd pipeline. Is it possible to send only one field in a pipeline and not a complete event?

---

## [Regarding if else condition for grok filter](https://discuss.elastic.co/t/regarding-if-else-condition-for-grok-filter/308863)

<div class="topic-metadata">

**Author:** [@suresh\_u](https://discuss.elastic.co/u/suresh_u)\
**Replies:** 5\
**Last updated:** [July 5, 2022, 2:11pm UTC](https://discuss.elastic.co/t/regarding-if-else-condition-for-grok-filter/308863 "2022-07-05T14:11:39Z")

</div>

Hi @sudhagar\_ramesh @Badger I have 1 date field in my oracle db. If the date field value is empty then I am getting grokparsefailure error as I am doing grok on that value. I need to put 1 condition like if date is nil…

---

## [How to stop logstash using default address when using pipeline](https://discuss.elastic.co/t/how-to-stop-logstash-using-default-address-when-using-pipeline/308922)

<div class="topic-metadata">

**Author:** [@michael.rhys](https://discuss.elastic.co/u/michael.rhys)\
**Replies:** 0\
**Last updated:** [July 5, 2022, 2:00pm UTC](https://discuss.elastic.co/t/how-to-stop-logstash-using-default-address-when-using-pipeline/308922 "2022-07-05T14:00:06Z")

</div>

I am configuring logstash inside kubernetes using the pipeline and it is connecting to my central elk stack fine. However not only is it connecting to the ELK Host I specify it is repeatedly trying to contact http://ela…

---

## [Regular expression query](https://discuss.elastic.co/t/regular-expression-query/308865)

<div class="topic-metadata">

**Author:** [@Krishna\_Sai\_Nag\_G](https://discuss.elastic.co/u/Krishna_Sai_Nag_G)\
**Replies:** 1\
**Last updated:** [July 5, 2022, 1:17pm UTC](https://discuss.elastic.co/t/regular-expression-query/308865 "2022-07-05T13:17:05Z")

</div>

Hi, i have data as below in my elastic 'My ORDER NO. 013-2009-01 and the order date is March 11, 2009 and delivered date is 13-03-2009 and the product id is B-43.' I am using regular expression query to get the data fr…

---

## [Json input script for converting bytes to GB and percentage?](https://discuss.elastic.co/t/json-input-script-for-converting-bytes-to-gb-and-percentage/308862)

<div class="topic-metadata">

**Author:** [@jisha](https://discuss.elastic.co/u/jisha)\
**Replies:** 1\
**Last updated:** [July 5, 2022, 1:06pm UTC](https://discuss.elastic.co/t/json-input-script-for-converting-bytes-to-gb-and-percentage/308862 "2022-07-05T13:06:44Z")

</div>

Hi , I want to convert memory size and cpu usage into GB in dashboard , please help me with json input script for that

---

## [Kibana error](https://discuss.elastic.co/t/kibana-error/308861)

<div class="topic-metadata">

**Author:** [@tharunkumar](https://discuss.elastic.co/u/tharunkumar)\
**Replies:** 1\
**Last updated:** [July 5, 2022, 1:05pm UTC](https://discuss.elastic.co/t/kibana-error/308861 "2022-07-05T13:05:11Z")

</div>

Hi i am facing this error while starting the kibana service.can you provide me the solution \[fatal\]\[root\] Error: Unable to complete saved object migrations for the \[.kibana\_task\_manager\] index: Unable to complete the OU…

---

## [How to change memory, disk space into GB and %](https://discuss.elastic.co/t/how-to-change-memory-disk-space-into-gb-and/308855)

<div class="topic-metadata">

**Author:** [@jisha](https://discuss.elastic.co/u/jisha)\
**Replies:** 1\
**Last updated:** [July 5, 2022, 1:01pm UTC](https://discuss.elastic.co/t/how-to-change-memory-disk-space-into-gb-and/308855 "2022-07-05T13:01:37Z")

</div>

Hi, i have to change disk space in bytes into GB and % .i tried by changing the fields into bytes, pct, size etc but its showing up as bytes only.

---

## [Count API with track\_total\_hits](https://discuss.elastic.co/t/count-api-with-track-total-hits/308912)

<div class="topic-metadata">

**Author:** [@James\_Conkling](https://discuss.elastic.co/u/James_Conkling)\
**Replies:** 0\
**Last updated:** [July 5, 2022, 12:54pm UTC](https://discuss.elastic.co/t/count-api-with-track-total-hits/308912 "2022-07-05T12:54:07Z")

</div>

While the search API has the track\_total\_hits optimization to approximate search hit count, I noticed the count API does not. If I am only looking for the approximate hit count, is it more performant to use the search A…

---

## [Configuration ingest from file](https://discuss.elastic.co/t/configuration-ingest-from-file/308910)

<div class="topic-metadata">

**Author:** [@mololkin.kirill.mol](https://discuss.elastic.co/u/mololkin.kirill.mol)\
**Replies:** 1\
**Last updated:** [July 5, 2022, 12:53pm UTC](https://discuss.elastic.co/t/configuration-ingest-from-file/308910 "2022-07-05T12:53:06Z")

</div>

Hello is there an opportunity for configuration ingest pipelines with elasticsearch.yaml?

---

## [How to use filter on a column if it's from a nested field on Kibana Canvas?](https://discuss.elastic.co/t/how-to-use-filter-on-a-column-if-its-from-a-nested-field-on-kibana-canvas/308763)

<div class="topic-metadata">

**Author:** [@Gvinfinity](https://discuss.elastic.co/u/Gvinfinity)\
**Replies:** 1\
**Last updated:** [July 5, 2022, 12:46pm UTC](https://discuss.elastic.co/t/how-to-use-filter-on-a-column-if-its-from-a-nested-field-on-kibana-canvas/308763 "2022-07-05T12:46:09Z")

</div>

Whenever I use a filter, be it a dropdown or time filter on a column that is from a nested field no data, even data that match the filter, appears in data tables. Is there another way to do this that I'm not aware of?

---

## [Get list of current hot indexes in elasticSearch](https://discuss.elastic.co/t/get-list-of-current-hot-indexes-in-elasticsearch/308870)

<div class="topic-metadata">

**Author:** [@avnere](https://discuss.elastic.co/u/avnere)\
**Replies:** 2\
**Last updated:** [July 5, 2022, 12:42pm UTC](https://discuss.elastic.co/t/get-list-of-current-hot-indexes-in-elasticsearch/308870 "2022-07-05T12:42:41Z")

</div>

Hi, Currently I am getting list of current hot indexes through Low Level Client: Request request = new Request("GET", "/\_cat/aliases/" + ALIAS\_NAME+ "?format=json&s=is\_write\_index:desc,"); Is there a way to get list…

---

## [Can we use wildcard in the field\_name or Can we apply condition in fields block inside query\_string](https://discuss.elastic.co/t/can-we-use-wildcard-in-the-field-name-or-can-we-apply-condition-in-fields-block-inside-query-string/308904)

<div class="topic-metadata">

**Author:** [@deepak\_prem](https://discuss.elastic.co/u/deepak_prem)\
**Replies:** 0\
**Last updated:** [July 5, 2022, 11:56am UTC](https://discuss.elastic.co/t/can-we-use-wildcard-in-the-field-name-or-can-we-apply-condition-in-fields-block-inside-query-string/308904 "2022-07-05T11:56:30Z")

</div>

Hi friends, I have the following questions related to the Elasticsearch:- I want to know Can we use the wildcard in the fields name in term block in the query, if not is there any alternate way to achieve this.like In …

---

## [Help me to parse a string to fields (grok)](https://discuss.elastic.co/t/help-me-to-parse-a-string-to-fields-grok/308903)

<div class="topic-metadata">

**Author:** [@Kosodrom](https://discuss.elastic.co/u/Kosodrom)\
**Replies:** 0\
**Last updated:** [July 5, 2022, 11:53am UTC](https://discuss.elastic.co/t/help-me-to-parse-a-string-to-fields-grok/308903 "2022-07-05T11:53:05Z")

</div>

Hi folks, I have following key: key = "value1/value2/value3" or key = "value1/value2/value3/value4" I want to split this to following structure: key1: value1 key2: value2 key3: value3 This would be easy by using a…

---

## [Very uncommon things happening with 7.17.0 ELK Cluster](https://discuss.elastic.co/t/very-uncommon-things-happening-with-7-17-0-elk-cluster/308664)

<div class="topic-metadata">

**Author:** [@Ravi\_S1](https://discuss.elastic.co/u/Ravi_S1)\
**Replies:** 6\
**Last updated:** [July 5, 2022, 11:05am UTC](https://discuss.elastic.co/t/very-uncommon-things-happening-with-7-17-0-elk-cluster/308664 "2022-07-05T11:05:07Z")

</div>

I have been observing that ELK 7.17.0 version is playing with my time & efforts. As i can observe, after changes happen in heap memory of ELK pods, have been observed that all thread pools are automatically consuming hi…

---

## [Sending data to Logstash TCP](https://discuss.elastic.co/t/sending-data-to-logstash-tcp/308879)

<div class="topic-metadata">

**Author:** [@Johnnyboi](https://discuss.elastic.co/u/Johnnyboi)\
**Replies:** 0\
**Last updated:** [July 5, 2022, 9:15am UTC](https://discuss.elastic.co/t/sending-data-to-logstash-tcp/308879 "2022-07-05T09:15:51Z")

</div>

So I have logstash configured like this: input: tcp { port =\> 5401 } output: stdout { codec =\> rubydebug } When I try to connect to the port via browser, I can see the connection incoming in logstash lo…

---

## [Index not appearing in kibana via logstash](https://discuss.elastic.co/t/index-not-appearing-in-kibana-via-logstash/308178)

<div class="topic-metadata">

**Author:** [@bhatiac](https://discuss.elastic.co/u/bhatiac)\
**Replies:** 7\
**Last updated:** [July 5, 2022, 6:27am UTC](https://discuss.elastic.co/t/index-not-appearing-in-kibana-via-logstash/308178 "2022-07-05T06:27:31Z")

</div>

Hello, I am new to ELK, trying to read my application logs and wishing to show it on kibana dashboard for analysis purposes. Elasticsearch, kibana and logstash instances are up and running. While trying to see the newly…

---

## [To set a daily time range in kibana](https://discuss.elastic.co/t/to-set-a-daily-time-range-in-kibana/308738)

<div class="topic-metadata">

**Author:** [@hadi\_farzipour](https://discuss.elastic.co/u/hadi_farzipour)\
**Replies:** 1\
**Last updated:** [July 5, 2022, 9:03am UTC](https://discuss.elastic.co/t/to-set-a-daily-time-range-in-kibana/308738 "2022-07-05T09:03:35Z")

</div>

I am using ELK stack 7.6.1 to store and retrieve daily logs. I want to created a visualize(table) to show all daily logs between 00:00am to 10:00am automatically. while in the time span there is no option to select daily…

---

## [Elasticsearch Apply filters with results from aggregations](https://discuss.elastic.co/t/elasticsearch-apply-filters-with-results-from-aggregations/308744)

<div class="topic-metadata">

**Author:** [@Eddie\_Vuong](https://discuss.elastic.co/u/Eddie_Vuong)\
**Replies:** 7\
**Last updated:** [July 5, 2022, 8:53am UTC](https://discuss.elastic.co/t/elasticsearch-apply-filters-with-results-from-aggregations/308744 "2022-07-05T08:53:37Z")

</div>

Is there anyway I can using the results obtained from aggregations to filter out the final hits in the query? I want to obtain a list of users who have more than 2 devices and the list of their devices in the database. …

---

## [Remove Special character from message before sending to json filter](https://discuss.elastic.co/t/remove-special-character-from-message-before-sending-to-json-filter/308434)

<div class="topic-metadata">

**Author:** [@Basel](https://discuss.elastic.co/u/Basel)\
**Replies:** 4\
**Last updated:** [July 5, 2022, 8:10am UTC](https://discuss.elastic.co/t/remove-special-character-from-message-before-sending-to-json-filter/308434 "2022-07-05T08:10:46Z")

</div>

Hi, we are using ELK with Apigee to send the transaction logs, the logstash configuration is as recommended by the community as below: input { tcp { port =\> 8080 type =\> syslog } } filter { m…

---

## [Learn.elastic.co - Expired certificate - unable to access Elastic Learning Portal](https://discuss.elastic.co/t/learn-elastic-co-expired-certificate-unable-to-access-elastic-learning-portal/308807)

<div class="topic-metadata">

**Author:** [@aaronm](https://discuss.elastic.co/u/aaronm)\
**Replies:** 1\
**Last updated:** [July 5, 2022, 8:11am UTC](https://discuss.elastic.co/t/learn-elastic-co-expired-certificate-unable-to-access-elastic-learning-portal/308807 "2022-07-05T08:11:54Z")

</div>

Hi, Myself and a few colleagues are unable to access the Elastic Learning portal as the site cert has expired. Thanks for your help.

---

## [Logstash include filter](https://discuss.elastic.co/t/logstash-include-filter/308853)

<div class="topic-metadata">

**Author:** [@tharunkumar](https://discuss.elastic.co/u/tharunkumar)\
**Replies:** 2\
**Last updated:** [July 5, 2022, 7:02am UTC](https://discuss.elastic.co/t/logstash-include-filter/308853 "2022-07-05T07:02:34Z")

</div>

Hi i need to send the logs of particular lines to logstash .i have tried by using include filter is not working .can u provide me the solution Eg: 2022-06-30 00:00:07 10.32.13.12 POST /maruvayaparpaidhee-cug/MF/Mfajax…

---

## [Filebeat include filter](https://discuss.elastic.co/t/filebeat-include-filter/308860)

<div class="topic-metadata">

**Author:** [@tharunkumar](https://discuss.elastic.co/u/tharunkumar)\
**Replies:** 1\
**Last updated:** [July 5, 2022, 6:58am UTC](https://discuss.elastic.co/t/filebeat-include-filter/308860 "2022-07-05T06:58:11Z")

</div>

Hi i need to send the logs of particular lines to logstash by using filebeat .i have tried by using include filter is not working .can u provide me the solution Eg: 2022-06-30 00:00:07 10.32.13.12 POST /maruvayaparpa…

---

## [Ingest pipeline split MESSAGE field into multiple fields](https://discuss.elastic.co/t/ingest-pipeline-split-message-field-into-multiple-fields/308834)

<div class="topic-metadata">

**Author:** [@moberreiter](https://discuss.elastic.co/u/moberreiter)\
**Replies:** 6\
**Last updated:** [July 5, 2022, 6:20am UTC](https://discuss.elastic.co/t/ingest-pipeline-split-message-field-into-multiple-fields/308834 "2022-07-05T06:20:37Z")

</div>

Hello everybody, I am new to elasticsearch and kibana and wanted to ask how to split a message into multiple fields. I tried creating an ingest pipeline with MESSAGE field and "," as separator, but it doesn't work as I…

---

## [Circuit break exception](https://discuss.elastic.co/t/circuit-break-exception/308774)

<div class="topic-metadata">

**Author:** [@Rajesh\_Sahu](https://discuss.elastic.co/u/Rajesh_Sahu)\
**Replies:** 5\
**Last updated:** [July 5, 2022, 6:13am UTC](https://discuss.elastic.co/t/circuit-break-exception/308774 "2022-07-05T06:13:17Z")

</div>

Hi all, I have been using Elasticsearch with multiple node setup from last 2 years, but currently all of sudden , got below exception of circuit\_breaking\_exception . \< {"error":{"root\_cause":\[{"type":"circuit\_breaking…

---

## [Unique id for multiple indices having same alias](https://discuss.elastic.co/t/unique-id-for-multiple-indices-having-same-alias/308854)

<div class="topic-metadata">

**Author:** [@suj0](https://discuss.elastic.co/u/suj0)\
**Replies:** 1\
**Last updated:** [July 5, 2022, 5:03am UTC](https://discuss.elastic.co/t/unique-id-for-multiple-indices-having-same-alias/308854 "2022-07-05T05:03:00Z")

</div>

Is it possible to set unique id for multiple indices having same alias? for example I have 2 indices A001 and A002 under alias A . A001 have data with id as "1" and A002 dont have data with id "1" and my write index is…

---

## [Setting hour in KQL or Lucene](https://discuss.elastic.co/t/setting-hour-in-kql-or-lucene/308740)

<div class="topic-metadata">

**Author:** [@hadi\_farzipour](https://discuss.elastic.co/u/hadi_farzipour)\
**Replies:** 4\
**Last updated:** [July 5, 2022, 5:02am UTC](https://discuss.elastic.co/t/setting-hour-in-kql-or-lucene/308740 "2022-07-05T05:02:59Z")

</div>

Hello I have @timestamp field which is in following format Jul 3, 2022 @ 06:55:55.153 How can I filter logs between 06:00 and 10:00 without mentioning days and months in KQL or Lucene query language.

---

## [Question about create data view API](https://discuss.elastic.co/t/question-about-create-data-view-api/308530)

<div class="topic-metadata">

**Author:** [@busishe](https://discuss.elastic.co/u/busishe)\
**Replies:** 4\
**Last updated:** [July 5, 2022, 1:20am UTC](https://discuss.elastic.co/t/question-about-create-data-view-api/308530 "2022-07-05T01:20:32Z")

</div>

i want to create a dataview with only "message" field,how can i make the post request? the example only show "fields" is an object,but didnt tell the detail properties in the object. $ curl -X POST api/data\_views/dat…

---

## [Curl command as streaming](https://discuss.elastic.co/t/curl-command-as-streaming/308838)

<div class="topic-metadata">

**Author:** [@Didi\_Sisi](https://discuss.elastic.co/u/Didi_Sisi)\
**Replies:** 0\
**Last updated:** [July 4, 2022, 11:38pm UTC](https://discuss.elastic.co/t/curl-command-as-streaming/308838 "2022-07-04T23:38:46Z")

</div>

Hello ; I want to use twitter streaming api V2. because the twitter plugin of logstash is not working with twitter api 2. I decided to use curl commands. I defined the rules. like this: curl --location --request POST …

[Previous page](https://discuss.elastic.co/tag/none.md?no_tags=true&page=591)

[Next page](https://discuss.elastic.co/tag/none.md?no_tags=true&page=593)
