# \#none

**URL:** https://discuss.elastic.co/tag/none.md?no_tags=true&page=608

[Latest](https://discuss.elastic.co/latest.md) · [Categories](https://discuss.elastic.co/categories.md) · [Tags](https://discuss.elastic.co/tags.md)

**Page:** 609

---

## [Search on Multiple Indices](https://discuss.elastic.co/t/search-on-multiple-indices/307105)

<div class="topic-metadata">

**Author:** [@QuanMinhTran](https://discuss.elastic.co/u/QuanMinhTran)\
**Replies:** 4\
**Last updated:** [June 17, 2022, 3:31am UTC](https://discuss.elastic.co/t/search-on-multiple-indices/307105 "2022-06-17T03:31:05Z")

</div>

I doing a query to search for multiple indices on Elasticsearch. The problem here is the priority of the result doesn't follow what I think. For example, I have 2 indices: index\_1 and index\_2 In Index\_1 have ~80 docs, …

---

## [Kibana / Map /Result narrowed](https://discuss.elastic.co/t/kibana-map-result-narrowed/307456)

<div class="topic-metadata">

**Author:** [@Phildefer](https://discuss.elastic.co/u/Phildefer)\
**Replies:** 0\
**Last updated:** [June 17, 2022, 1:35am UTC](https://discuss.elastic.co/t/kibana-map-result-narrowed/307456 "2022-06-17T01:35:06Z")

</div>

Bonjour, J'ai un problème pour contourner le fait que l'utilisation d'un control sur une map dans un dashboard influence un autre layer. Je m'explique : J'ai un layer L1 avec certaines données que j'affiche sur carte, j…

---

## [Changed node port - now it doesn't have shards, but storage is still used](https://discuss.elastic.co/t/changed-node-port-now-it-doesnt-have-shards-but-storage-is-still-used/307451)

<div class="topic-metadata">

**Author:** [@matiasgarciaisaia](https://discuss.elastic.co/u/matiasgarciaisaia)\
**Replies:** 0\
**Last updated:** [June 16, 2022, 8:40pm UTC](https://discuss.elastic.co/t/changed-node-port-now-it-doesnt-have-shards-but-storage-is-still-used/307451 "2022-06-16T20:40:08Z")

</div>

I've setup a 6-node Elasticsearch 7.17.0 cluster which has to serve a single read-only ~1TB index. The nodes have 2TB of storage, so I've set that index to be a single shard, with 5 replicas (so each node gets a full co…

---

## [Kibana shows double with slightly changed value](https://discuss.elastic.co/t/kibana-shows-double-with-slightly-changed-value/307318)

<div class="topic-metadata">

**Author:** [@paolovalladolid](https://discuss.elastic.co/u/paolovalladolid)\
**Replies:** 2\
**Last updated:** [June 16, 2022, 8:51pm UTC](https://discuss.elastic.co/t/kibana-shows-double-with-slightly-changed-value/307318 "2022-06-16T20:51:52Z")

</div>

How do I get Kibana Discover to display a double (number) as a double? I have a document indexed with the double value 2555417833004 for a particular field. But when Kibana Discover shows the same document, it displays…

---

## [Elasticsearch service won't start](https://discuss.elastic.co/t/elasticsearch-service-wont-start/307290)

<div class="topic-metadata">

**Author:** [@Lukasz1](https://discuss.elastic.co/u/Lukasz1)\
**Replies:** 4\
**Last updated:** [June 16, 2022, 8:45pm UTC](https://discuss.elastic.co/t/elasticsearch-service-wont-start/307290 "2022-06-16T20:45:42Z")

</div>

Elasticsearch (7.17.0) service won't start The config file is so simple that I can't find any error there. My config is: cluster.name: elkos node.name: elkos-1 path.data: /mnt/elasticsearch/data path.logs: /mnt/elast…

---

## [Subtracting two values of a field](https://discuss.elastic.co/t/subtracting-two-values-of-a-field/306915)

<div class="topic-metadata">

**Author:** [@zaeemmasood](https://discuss.elastic.co/u/zaeemmasood)\
**Replies:** 4\
**Last updated:** [June 16, 2022, 8:36pm UTC](https://discuss.elastic.co/t/subtracting-two-values-of-a-field/306915 "2022-06-16T20:36:41Z")

</div>

Hello All, I have a set up which parses the following line in a log file: \[2022-06-10T19:52:05.017+0000\]\[info\]\[gc \] GC(35959) Pause Full (Diagnostic Command) 1850M-\>1140M(2560M) 506.831ms The resultant get…

---

## [Format is showing wrong in label](https://discuss.elastic.co/t/format-is-showing-wrong-in-label/306627)

<div class="topic-metadata">

**Author:** [@akshay\_bhardwaj](https://discuss.elastic.co/u/akshay_bhardwaj)\
**Replies:** 3\
**Last updated:** [June 16, 2022, 6:30pm UTC](https://discuss.elastic.co/t/format-is-showing-wrong-in-label/306627 "2022-06-16T18:30:54Z")

</div>

I draw a vertical bar graph but in one of my column, values are in decimal and i set it to 0 also but still label are showing decimal values.

---

## [Unknown response error when running using \`\_disk\_usage\` api](https://discuss.elastic.co/t/unknown-response-error-when-running-using-disk-usage-api/307330)

<div class="topic-metadata">

**Author:** [@Ryan\_Morrison](https://discuss.elastic.co/u/Ryan_Morrison)\
**Replies:** 9\
**Last updated:** [June 16, 2022, 6:06pm UTC](https://discuss.elastic.co/t/unknown-response-error-when-running-using-disk-usage-api/307330 "2022-06-16T18:06:38Z")

</div>

I'm looking at utilizing the new \[\_disk\_usage\](https://www.elastic.co/guide/en/elasticsearch/reference/master/indices-disk-usage.html) api and doing so successfully in our staging environment. However, when running agai…

---

## [Combine two different aggregation results into one](https://discuss.elastic.co/t/combine-two-different-aggregation-results-into-one/307143)

<div class="topic-metadata">

**Author:** [@shi](https://discuss.elastic.co/u/shi)\
**Replies:** 2\
**Last updated:** [June 16, 2022, 6:00pm UTC](https://discuss.elastic.co/t/combine-two-different-aggregation-results-into-one/307143 "2022-06-16T18:00:19Z")

</div>

We have traffic logs from and to WAN. We need to :slight\_smile: We need to add/aggregate the sentbytes when the source interface is WAN. We need to add/aggregate the receivedbytes when the destination interface is WAN…

---

## [Display All X values](https://discuss.elastic.co/t/display-all-x-values/306804)

<div class="topic-metadata">

**Author:** [@Greninja\_San](https://discuss.elastic.co/u/Greninja_San)\
**Replies:** 1\
**Last updated:** [June 16, 2022, 5:39pm UTC](https://discuss.elastic.co/t/display-all-x-values/306804 "2022-06-16T17:39:39Z")

</div>

I'm currently creating a bar chart. However, as you can see, it on shows some of the months, and not all of them. Is there a way to show them all ? Thanks

---

## [Create new Event Renderers](https://discuss.elastic.co/t/create-new-event-renderers/307382)

<div class="topic-metadata">

**Author:** [@kotvmrc](https://discuss.elastic.co/u/kotvmrc)\
**Replies:** 1\
**Last updated:** [June 16, 2022, 3:36pm UTC](https://discuss.elastic.co/t/create-new-event-renderers/307382 "2022-06-16T15:36:34Z")

</div>

Hi guys, I'm looking for creating/customizing "Events Renderers" the ones used inside the timelines or in the "Alerts" page. I've found only a little piece of configuration where I can select what renderer enable or no…

---

## [Can we do : Analyser-\>Tokenizer-\>Token Filter-\>Re-tokenize and considers only these last tokens](https://discuss.elastic.co/t/can-we-do-analyser-tokenizer-token-filter-re-tokenize-and-considers-only-these-last-tokens/307298)

<div class="topic-metadata">

**Author:** [@fraf](https://discuss.elastic.co/u/fraf)\
**Replies:** 7\
**Last updated:** [June 16, 2022, 2:36pm UTC](https://discuss.elastic.co/t/can-we-do-analyser-tokenizer-token-filter-re-tokenize-and-considers-only-these-last-tokens/307298 "2022-06-16T14:36:54Z")

</div>

Hello, I want, given the input text : { "analyzer": "parapheur\_shingle", "text": "W 4.8.4.1 NI FNA NP 4.8.4 TEST 2" } having fllowing steps : tokenize as standard (word break with spaces =\> 8 tokens) filter …

---

## [Sort based on a Python List (array) and this list is not stored in the Elastic search](https://discuss.elastic.co/t/sort-based-on-a-python-list-array-and-this-list-is-not-stored-in-the-elastic-search/306528)

<div class="topic-metadata">

**Author:** [@Kv\_Karthik](https://discuss.elastic.co/u/Kv_Karthik)\
**Replies:** 4\
**Last updated:** [June 16, 2022, 2:32pm UTC](https://discuss.elastic.co/t/sort-based-on-a-python-list-array-and-this-list-is-not-stored-in-the-elastic-search/306528 "2022-06-16T14:32:52Z")

</div>

I would like to sort the hits in my results in a specific order and this order can be made available from a Python list or a python dictionary. I already tried using the script fields like mentioned in Medium website( M…

---

## [Sort data based on result of Vertical axis in vertical Bar graph(lens)](https://discuss.elastic.co/t/sort-data-based-on-result-of-vertical-axis-in-vertical-bar-graph-lens/307392)

<div class="topic-metadata">

**Author:** [@Mohit.Sharma](https://discuss.elastic.co/u/Mohit.Sharma)\
**Replies:** 6\
**Last updated:** [June 16, 2022, 2:01pm UTC](https://discuss.elastic.co/t/sort-data-based-on-result-of-vertical-axis-in-vertical-bar-graph-lens/307392 "2022-06-16T14:01:04Z")

</div>

Hello Team, I am new to Kibana & Elasticsearch and trying to create a vertical Bar graph(Lens) that will show top 10 failure Interfaces based on failure percentage and sort interfaces based on percentage of failure. mea…

---

## [Date conversion adds one microsecond](https://discuss.elastic.co/t/date-conversion-adds-one-microsecond/307418)

<div class="topic-metadata">

**Author:** [@sudden](https://discuss.elastic.co/u/sudden)\
**Replies:** 0\
**Last updated:** [June 16, 2022, 1:49pm UTC](https://discuss.elastic.co/t/date-conversion-adds-one-microsecond/307418 "2022-06-16T13:49:24Z")

</div>

I'm converting date from string but for some strange reason it sometimes add one microsecond in the timestamp field: logstash 8.1.3 String field: 2022-06-16T13:44:04.615 Logstash code: date { match =\> \[ "fluent\_time…

---

## [Comparison between Elasticsearch version](https://discuss.elastic.co/t/comparison-between-elasticsearch-version/307212)

<div class="topic-metadata">

**Author:** [@Wan\_Nur\_Athirah\_Wan](https://discuss.elastic.co/u/Wan_Nur_Athirah_Wan)\
**Replies:** 4\
**Last updated:** [June 16, 2022, 1:42pm UTC](https://discuss.elastic.co/t/comparison-between-elasticsearch-version/307212 "2022-06-16T13:42:25Z")

</div>

Hai there. Do anyone knows how to do comparison or is there any document that shows or list all the changes between this version and other version. example for Elasticsearch version 7.3.1, what is the changes or what has…

---

## [Query to get results based on priority of fields](https://discuss.elastic.co/t/query-to-get-results-based-on-priority-of-fields/307214)

<div class="topic-metadata">

**Author:** [@dawood\_abdullah](https://discuss.elastic.co/u/dawood_abdullah)\
**Replies:** 8\
**Last updated:** [June 16, 2022, 1:31pm UTC](https://discuss.elastic.co/t/query-to-get-results-based-on-priority-of-fields/307214 "2022-06-16T13:31:16Z")

</div>

Hi, I have following mapping : \> PUT products \> { \> "mappings" : { \> "properties" : { \> "item\_name" : {"type" : "keyword"}, \> "catalog\_name" : {"type" : "keyword"}, \> "group" : {"type" : "keyword"}, \> "l…

---

## [Confusion around geo.country\_iso\_code vs country\_code2](https://discuss.elastic.co/t/confusion-around-geo-country-iso-code-vs-country-code2/306857)

<div class="topic-metadata">

**Author:** [@cawoodm](https://discuss.elastic.co/u/cawoodm)\
**Replies:** 2\
**Last updated:** [June 16, 2022, 1:06pm UTC](https://discuss.elastic.co/t/confusion-around-geo-country-iso-code-vs-country-code2/306857 "2022-06-16T13:06:14Z")

</div>

When we parse an IP for geo info using: geoip { source =\> "ip" target =\> "client" fields =\> \["location", "country\_code2", "country\_name"\] } LogStash creates documents with: client: { geo: { country\_iso\_c…

---

## [Grok Pattern for dynamic json](https://discuss.elastic.co/t/grok-pattern-for-dynamic-json/307408)

<div class="topic-metadata">

**Author:** [@Ahmad\_Ahsan\_Saleem](https://discuss.elastic.co/u/Ahmad_Ahsan_Saleem)\
**Replies:** 0\
**Last updated:** [June 16, 2022, 1:01pm UTC](https://discuss.elastic.co/t/grok-pattern-for-dynamic-json/307408 "2022-06-16T13:01:15Z")

</div>

Hi, My data is coming live from spring boot logs and in successful execution the logs show in json format (each json has different input fields).In case of any error the logs show error with a string format Here is a s…

---

## [LOG SOURCES](https://discuss.elastic.co/t/log-sources/307137)

<div class="topic-metadata">

**Author:** [@mkibani](https://discuss.elastic.co/u/mkibani)\
**Replies:** 2\
**Last updated:** [June 16, 2022, 11:06am UTC](https://discuss.elastic.co/t/log-sources/307137 "2022-06-16T11:06:38Z")

</div>

Hello, I'am fairly new to ELK STACK, and i'm wondering if there's way to list all of the log sources integrated with the STACK, i received bunch of logs from multiple security solutions and i would love to list all the …

---

## [Best way to contains search in elastic search](https://discuss.elastic.co/t/best-way-to-contains-search-in-elastic-search/307369)

<div class="topic-metadata">

**Author:** [@khasim\_vali\_dudekula](https://discuss.elastic.co/u/khasim_vali_dudekula)\
**Replies:** 1\
**Last updated:** [June 16, 2022, 11:01am UTC](https://discuss.elastic.co/t/best-way-to-contains-search-in-elastic-search/307369 "2022-06-16T11:01:36Z")

</div>

Hi, I am working on a use case which does contains search in logs data indexed in elastic server. the query is a case-insensitive one I am aware of match, match\_phrase and query string. But none of the seems to be wor…

---

## [How to use search-ui Conditional Facets](https://discuss.elastic.co/t/how-to-use-search-ui-conditional-facets/307386)

<div class="topic-metadata">

**Author:** [@fkvivid](https://discuss.elastic.co/u/fkvivid)\
**Replies:** 0\
**Last updated:** [June 16, 2022, 10:44am UTC](https://discuss.elastic.co/t/how-to-use-search-ui-conditional-facets/307386 "2022-06-16T10:44:29Z")

</div>

How to use Conditional Facets in my App-search I read the example github elastic docs but not working any help :pray: Target: if choose California of states Then show conditional Facet Here is a national park example …

---

## [Collapse in In-group and out-of-group sorting problem](https://discuss.elastic.co/t/collapse-in-in-group-and-out-of-group-sorting-problem/307378)

<div class="topic-metadata">

**Author:** [@EaChou](https://discuss.elastic.co/u/EaChou)\
**Replies:** 0\
**Last updated:** [June 16, 2022, 10:01am UTC](https://discuss.elastic.co/t/collapse-in-in-group-and-out-of-group-sorting-problem/307378 "2022-06-16T10:01:57Z")

</div>

I want to group by a certain field, take only one of each group, and then sort by this document outside the group I used collapse to group and deduplicate, but after deduplication, it is not the first result after sorti…

---

## [Get sum of created metrics](https://discuss.elastic.co/t/get-sum-of-created-metrics/307311)

<div class="topic-metadata">

**Author:** [@chamod\_maduranga](https://discuss.elastic.co/u/chamod_maduranga)\
**Replies:** 7\
**Last updated:** [June 16, 2022, 10:11am UTC](https://discuss.elastic.co/t/get-sum-of-created-metrics/307311 "2022-06-16T10:11:18Z")

</div>

what i need to get is get top hits for each TYPE and need to get the summation of them. For this example summation should be 25(1+1+1+22). .Can i get 25 as in one metric visual so that i can add to dashboard as one …

---

## [Can we use same index for 2 different sources?](https://discuss.elastic.co/t/can-we-use-same-index-for-2-different-sources/307366)

<div class="topic-metadata">

**Author:** [@Avinash\_Pattnaik](https://discuss.elastic.co/u/Avinash_Pattnaik)\
**Replies:** 3\
**Last updated:** [June 16, 2022, 9:46am UTC](https://discuss.elastic.co/t/can-we-use-same-index-for-2-different-sources/307366 "2022-06-16T09:46:45Z")

</div>

Hello, I am new to Elastic and have a query. We are feeding Elastic with logs from our VMware infrastructure via vrops. All vrops logs are uploaded to Elastic with the index check\_vrops.mm.yyyy Now, I want to send some…

---

## [Retention policy for Transform's index](https://discuss.elastic.co/t/retention-policy-for-transforms-index/306767)

<div class="topic-metadata">

**Author:** [@bianca6](https://discuss.elastic.co/u/bianca6)\
**Replies:** 1\
**Last updated:** [June 16, 2022, 9:11am UTC](https://discuss.elastic.co/t/retention-policy-for-transforms-index/306767 "2022-06-16T09:11:19Z")

</div>

Hi, If I set a retention policy on a Transform, like 7 days, the whole index will be deleted after 7 days. How can I set up something like "delete the data older than 7 days, and keep the rest alive"? Thanks!

---

## [Query field value to reindex existing indexes](https://discuss.elastic.co/t/query-field-value-to-reindex-existing-indexes/307367)

<div class="topic-metadata">

**Author:** [@dapmI](https://discuss.elastic.co/u/dapmI)\
**Replies:** 0\
**Last updated:** [June 16, 2022, 9:07am UTC](https://discuss.elastic.co/t/query-field-value-to-reindex-existing-indexes/307367 "2022-06-16T09:07:52Z")

</div>

Hello, I'm trying to achieve a complex action where we currently have a common index filebeat-%{beat version}-%{YY-mm-dd} type of index with multiple log.file.path different. The idea is to have them in other index depe…

---

## [Anyone has a performance evaluation with NGram tokenizer?](https://discuss.elastic.co/t/anyone-has-a-performance-evaluation-with-ngram-tokenizer/307356)

<div class="topic-metadata">

**Author:** [@fraf](https://discuss.elastic.co/u/fraf)\
**Replies:** 1\
**Last updated:** [June 16, 2022, 8:59am UTC](https://discuss.elastic.co/t/anyone-has-a-performance-evaluation-with-ngram-tokenizer/307356 "2022-06-16T08:59:09Z")

</div>

Hello searchers, I think, one of the best tokenizer algorithm (and maybe the most used), is the NGram tokenizer (equivalent to the SQL : where table.column like '%search\_text%'. Indeed, given an input text, it can gene…

---

## [Filter applied to specific data view (index pattern)](https://discuss.elastic.co/t/filter-applied-to-specific-data-view-index-pattern/304669)

<div class="topic-metadata">

**Author:** [@andersg](https://discuss.elastic.co/u/andersg)\
**Replies:** 4\
**Last updated:** [June 16, 2022, 7:58am UTC](https://discuss.elastic.co/t/filter-applied-to-specific-data-view-index-pattern/304669 "2022-06-16T07:58:22Z")

</div>

Hi, I find it powerful to mix content from different types of indexes in Kibana dashboards, but have a difficult time setting up useful dashboards because of global filtering. I do however want to use filters and add co…

---

## [Migrate Datastreams](https://discuss.elastic.co/t/migrate-datastreams/307357)

<div class="topic-metadata">

**Author:** [@EllBil](https://discuss.elastic.co/u/EllBil)\
**Replies:** 0\
**Last updated:** [June 16, 2022, 7:54am UTC](https://discuss.elastic.co/t/migrate-datastreams/307357 "2022-06-16T07:54:09Z")

</div>

Hello, I'm trying to migrate to a new server and a new cluster. My Data pipeline's output is being now on the new server, and I'm starting to receive data. However I can't restore my old data using \_reindex neither Ela…

[Previous page](https://discuss.elastic.co/tag/none.md?no_tags=true&page=607)

[Next page](https://discuss.elastic.co/tag/none.md?no_tags=true&page=609)
