# \#none

**URL:** https://discuss.elastic.co/tag/none.md?no_tags=true&page=614

[Latest](https://discuss.elastic.co/latest.md) · [Categories](https://discuss.elastic.co/categories.md) · [Tags](https://discuss.elastic.co/tags.md)

**Page:** 615

---

## [Splunk vs. Elastic: Lookup Tables](https://discuss.elastic.co/t/splunk-vs-elastic-lookup-tables/306669)

<div class="topic-metadata">

**Author:** [@alaine](https://discuss.elastic.co/u/alaine)\
**Replies:** 4\
**Last updated:** [June 9, 2022, 12:07pm UTC](https://discuss.elastic.co/t/splunk-vs-elastic-lookup-tables/306669 "2022-06-09T12:07:32Z")

</div>

Good Morning, I have been working with a customer for a while and they have chosen to migrate from Splunk to Elastic. One sticking point has been lookup tables. They had very specific lookup tables that provided them wi…

---

## [How to sort buckets in Elasticsearch on their first occurrence in a search](https://discuss.elastic.co/t/how-to-sort-buckets-in-elasticsearch-on-their-first-occurrence-in-a-search/306776)

<div class="topic-metadata">

**Author:** [@Peter\_Dewachtere](https://discuss.elastic.co/u/Peter_Dewachtere)\
**Replies:** 0\
**Last updated:** [June 9, 2022, 9:24am UTC](https://discuss.elastic.co/t/how-to-sort-buckets-in-elasticsearch-on-their-first-occurrence-in-a-search/306776 "2022-06-09T09:24:29Z")

</div>

I have an Elasticsearch query (version 7) that returns a paged result of products. The query has a specific sort on multiple fields: Product A - image 1 Product B - image 1 Product C - image 2 Product D - image 2 Prod…

---

## [Why does elasticsearch assign shards to cold nodes?](https://discuss.elastic.co/t/why-does-elasticsearch-assign-shards-to-cold-nodes/306774)

<div class="topic-metadata">

**Author:** [@wajika](https://discuss.elastic.co/u/wajika)\
**Replies:** 0\
**Last updated:** [June 9, 2022, 9:04am UTC](https://discuss.elastic.co/t/why-does-elasticsearch-assign-shards-to-cold-nodes/306774 "2022-06-09T09:04:19Z")

</div>

elk: 7.17.3 01-03 nodes I want to use for hot data search and storage and 04-05 nodes as cold and frozen nodes. I have read the es documentation. By default, the data of the collector will be sent to the data\_content n…

---

## [Need help with special character search](https://discuss.elastic.co/t/need-help-with-special-character-search/306692)

<div class="topic-metadata">

**Author:** [@Kapil.Lanjewar](https://discuss.elastic.co/u/Kapil.Lanjewar)\
**Replies:** 8\
**Last updated:** [June 9, 2022, 7:12am UTC](https://discuss.elastic.co/t/need-help-with-special-character-search/306692 "2022-06-09T07:12:14Z")

</div>

I have difficulties searching the special characters from my documents. One of the attribute of the document - "phrase" - contains special characters. Its value is -\> "The 2 QUICK Brown-Foxes jumped over the lazy dog's…

---

## [Appending data to existing index](https://discuss.elastic.co/t/appending-data-to-existing-index/306533)

<div class="topic-metadata">

**Author:** [@behappy\_alwayz0401](https://discuss.elastic.co/u/behappy_alwayz0401)\
**Replies:** 2\
**Last updated:** [June 9, 2022, 6:23am UTC](https://discuss.elastic.co/t/appending-data-to-existing-index/306533 "2022-06-09T06:23:40Z")

</div>

I have an index that already has data. One of the lines in the CSV that was uploaded, had location field which reflects the co-ordinates for Vietname, showing null values due to which that particular line from the CSV d…

---

## [$ in Top N graph of TSVB](https://discuss.elastic.co/t/in-top-n-graph-of-tsvb/306666)

<div class="topic-metadata">

**Author:** [@behappy\_alwayz0401](https://discuss.elastic.co/u/behappy_alwayz0401)\
**Replies:** 2\
**Last updated:** [June 9, 2022, 6:04am UTC](https://discuss.elastic.co/t/in-top-n-graph-of-tsvb/306666 "2022-06-09T06:04:22Z")

</div>

Hi, I have a run time field "Abs Delta Value" which has format as $0,0.\[000\]. The $ sign is showing on all charts in lens and elsewhere except on TSVB. In the "Top N" chart under TSVB, it is only showing the number wi…

---

## [Index pattern doesn't have a UUID](https://discuss.elastic.co/t/index-pattern-doesnt-have-a-uuid/306596)

<div class="topic-metadata">

**Author:** [@Mary2022](https://discuss.elastic.co/u/Mary2022)\
**Replies:** 3\
**Last updated:** [June 9, 2022, 5:02am UTC](https://discuss.elastic.co/t/index-pattern-doesnt-have-a-uuid/306596 "2022-06-09T05:02:46Z")

</div>

Hi, I exported all the objects (index patterns, visualizations, dashboards, etc.) to my new cluster. I need to change the index pattern to our visualizations. I noticed the old index pattern url doesn't have a UUID in i…

---

## [Can i recover cert folder in elastic search?](https://discuss.elastic.co/t/can-i-recover-cert-folder-in-elastic-search/306602)

<div class="topic-metadata">

**Author:** [@akshay\_bhardwaj](https://discuss.elastic.co/u/akshay_bhardwaj)\
**Replies:** 6\
**Last updated:** [June 9, 2022, 4:22am UTC](https://discuss.elastic.co/t/can-i-recover-cert-folder-in-elastic-search/306602 "2022-06-09T04:22:44Z")

</div>

By mistake i deleted the cert folder present in config folder of Elasticsearch is there any command so i can recover below certificates:- transport.p12 http.p12

---

## [Elasticsearch storage full after activate endpoint security integration](https://discuss.elastic.co/t/elasticsearch-storage-full-after-activate-endpoint-security-integration/306754)

<div class="topic-metadata">

**Author:** [@ads92](https://discuss.elastic.co/u/ads92)\
**Replies:** 0\
**Last updated:** [June 9, 2022, 3:55am UTC](https://discuss.elastic.co/t/elasticsearch-storage-full-after-activate-endpoint-security-integration/306754 "2022-06-09T03:55:48Z")

</div>

I have 20 agent running that has the 'Endpoint Security', 'Prebuilt Security Detection Rules' and the 'System Integration'. This is running on a Windows 10/11 & Ubuntu 20.04 and reporting into ECK with fleet management …

---

## [GeoIP filter does not work with a subfield](https://discuss.elastic.co/t/geoip-filter-does-not-work-with-a-subfield/306750)

<div class="topic-metadata">

**Author:** [@austin0918](https://discuss.elastic.co/u/austin0918)\
**Replies:** 2\
**Last updated:** [June 9, 2022, 3:20am UTC](https://discuss.elastic.co/t/geoip-filter-does-not-work-with-a-subfield/306750 "2022-06-09T03:20:16Z")

</div>

I have a field client.ip that needs to get geo info. I tried below GeoIP filter but it didn't work. Looks like GeoIP does not work with a subfield. Please advise. filter { if \[client\]\[ip\] { geoip { source =\> "\[cli…

---

## [Line and barchart on same visualization for one sample point makes the linechart a single point](https://discuss.elastic.co/t/line-and-barchart-on-same-visualization-for-one-sample-point-makes-the-linechart-a-single-point/306748)

<div class="topic-metadata">

**Author:** [@tee101](https://discuss.elastic.co/u/tee101)\
**Replies:** 0\
**Last updated:** [June 9, 2022, 12:59am UTC](https://discuss.elastic.co/t/line-and-barchart-on-same-visualization-for-one-sample-point-makes-the-linechart-a-single-point/306748 "2022-06-09T00:59:43Z")

</div>

In the following snapshot metric U is a barchart and metric A is a linechart. If there is one sample point, the linechart is just a point, and gets immersed in a big wide bar. Is there a way to have the point extrapolate…

---

## [Recommended resource setting for a Logstash Pod](https://discuss.elastic.co/t/recommended-resource-setting-for-a-logstash-pod/306747)

<div class="topic-metadata">

**Author:** [@amruth](https://discuss.elastic.co/u/amruth)\
**Replies:** 0\
**Last updated:** [June 9, 2022, 12:48am UTC](https://discuss.elastic.co/t/recommended-resource-setting-for-a-logstash-pod/306747 "2022-06-09T00:48:26Z")

</div>

Is there any recommended resource setting for a Logstash Pod handling small amount(100GB) of data everyday and no filtering in place? Logstash just reads data from SQLServer and pushes it to Elasticsearch without any fil…

---

## [Add\_field in logstash does not work](https://discuss.elastic.co/t/add-field-in-logstash-does-not-work/306616)

<div class="topic-metadata">

**Author:** [@PriyaM21](https://discuss.elastic.co/u/PriyaM21)\
**Replies:** 0\
**Last updated:** [June 8, 2022, 2:04am UTC](https://discuss.elastic.co/t/add-field-in-logstash-does-not-work/306616 "2022-06-08T02:04:50Z")

</div>

I am trying to add a new custom field from the message but new field do not show up in Kabana. There is no error in logstash logs. Below is my logstash code if \[fields\]\[app\_name\] == "cobra" { if \[source\] =~ /^".\*(\\|/…

---

## [Logstash connectivity from aws to on-premise](https://discuss.elastic.co/t/logstash-connectivity-from-aws-to-on-premise/306638)

<div class="topic-metadata">

**Author:** [@narasingarao.katta](https://discuss.elastic.co/u/narasingarao.katta)\
**Replies:** 0\
**Last updated:** [June 8, 2022, 7:04am UTC](https://discuss.elastic.co/t/logstash-connectivity-from-aws-to-on-premise/306638 "2022-06-08T07:04:42Z")

</div>

Hi i want move my cloud watch logs to elk which is hosted out of aws . can any one give some inputs in this

---

## [How to solve elastic error of "Readiness probe failed: Error: Got HTTP code 503 but expected a 200" in GKE?](https://discuss.elastic.co/t/how-to-solve-elastic-error-of-readiness-probe-failed-error-got-http-code-503-but-expected-a-200-in-gke/306726)

<div class="topic-metadata">

**Author:** [@Samuel\_Arogbonlo](https://discuss.elastic.co/u/Samuel_Arogbonlo)\
**Replies:** 0\
**Last updated:** [June 8, 2022, 4:22pm UTC](https://discuss.elastic.co/t/how-to-solve-elastic-error-of-readiness-probe-failed-error-got-http-code-503-but-expected-a-200-in-gke/306726 "2022-06-08T16:22:02Z")

</div>

0 I am installing Elastic on GKE with the helm chart here. But after running this command helm upgrade kibana elastic/kibana --values kibana.yaml , it runs successfully but the pod gives this error Readiness probe faile…

---

## [So many layers with same data in MAP](https://discuss.elastic.co/t/so-many-layers-with-same-data-in-map/306676)

<div class="topic-metadata">

**Author:** [@akshay\_bhardwaj](https://discuss.elastic.co/u/akshay_bhardwaj)\
**Replies:** 3\
**Last updated:** [June 8, 2022, 9:25pm UTC](https://discuss.elastic.co/t/so-many-layers-with-same-data-in-map/306676 "2022-06-08T21:25:57Z")

</div>

When i draw a map with data there are so many layers on hover showing same data how i can reduce the same.

---

## [Modify the string into another form in Logstash](https://discuss.elastic.co/t/modify-the-string-into-another-form-in-logstash/306732)

<div class="topic-metadata">

**Author:** [@Pranjal\_Sett](https://discuss.elastic.co/u/Pranjal_Sett)\
**Replies:** 1\
**Last updated:** [June 8, 2022, 6:35pm UTC](https://discuss.elastic.co/t/modify-the-string-into-another-form-in-logstash/306732 "2022-06-08T18:35:10Z")

</div>

Hello, I am having one csv file, in that csv file there is a attribute named as Time field. And the format of that time field is not as a standard format. Here is the format: \[30/Nov/2017:15:28:27 And I want to change…

---

## [Drop filter to avoid documents to be sent to ES not working](https://discuss.elastic.co/t/drop-filter-to-avoid-documents-to-be-sent-to-es-not-working/306584)

<div class="topic-metadata">

**Author:** [@Carlos\_T](https://discuss.elastic.co/u/Carlos_T)\
**Replies:** 8\
**Last updated:** [June 8, 2022, 6:29pm UTC](https://discuss.elastic.co/t/drop-filter-to-avoid-documents-to-be-sent-to-es-not-working/306584 "2022-06-08T18:29:50Z")

</div>

Hi everybody. I've have a ES + Kib + Logstash + Filebeat environment ready for testing purposes, and after installing Filebeat so it sends the data to Logstash, I've realiced that I'm recieving more documents than necce…

---

## [Index\_out\_of\_bounds\_exception](https://discuss.elastic.co/t/index-out-of-bounds-exception/306736)

<div class="topic-metadata">

**Author:** [@magedmakled](https://discuss.elastic.co/u/magedmakled)\
**Replies:** 0\
**Last updated:** [June 8, 2022, 6:29pm UTC](https://discuss.elastic.co/t/index-out-of-bounds-exception/306736 "2022-06-08T18:29:53Z")

</div>

Hello All, I have a query that was working but all the sudden it is returning index\_out\_of\_bounds\_exception. The document has a nested field events . I ran this directly from Kibana Elasticsearch 6. GET event\_lists/\_…

---

## [Insert to elasticsearch from logstash IF NOT EXISTS](https://discuss.elastic.co/t/insert-to-elasticsearch-from-logstash-if-not-exists/306368)

<div class="topic-metadata">

**Author:** [@seanziee](https://discuss.elastic.co/u/seanziee)\
**Replies:** 7\
**Last updated:** [June 8, 2022, 6:09pm UTC](https://discuss.elastic.co/t/insert-to-elasticsearch-from-logstash-if-not-exists/306368 "2022-06-08T18:09:58Z")

</div>

Hi, I currently have an index that I set unique ids and sometimes there is replica data. In my use case, older data is often more accurate than newer data. So I would like to have logstash only insert if the \_id current…

---

## [Parse ISO 8601 duration format (PT(n)H(n)M(n)S)](https://discuss.elastic.co/t/parse-iso-8601-duration-format-pt-n-h-n-m-n-s/306605)

<div class="topic-metadata">

**Author:** [@Iss](https://discuss.elastic.co/u/Iss)\
**Replies:** 5\
**Last updated:** [June 8, 2022, 5:53pm UTC](https://discuss.elastic.co/t/parse-iso-8601-duration-format-pt-n-h-n-m-n-s/306605 "2022-06-08T17:53:03Z")

</div>

Hi! I have a ISO 8601 duration format P(n)Y(n)M(n)DT(n)H(n)M(n)S fields as "duration"=\>"PT0H0M0S" I have to parse it to get time duration in seconds or in format HH:MM:SS. How can I do it with logstash filter? Than…

---

## [Using IBM common data provider for z systems](https://discuss.elastic.co/t/using-ibm-common-data-provider-for-z-systems/306723)

<div class="topic-metadata">

**Author:** [@Akhil2](https://discuss.elastic.co/u/Akhil2)\
**Replies:** 0\
**Last updated:** [June 8, 2022, 4:05pm UTC](https://discuss.elastic.co/t/using-ibm-common-data-provider-for-z-systems/306723 "2022-06-08T16:05:45Z")

</div>

Hello all, Hope you are doing well. I have been using ELK 7.16.2. and I want to use IBM Common Data Provider to stream logs to my Logstash instance. But I have a few questions about installation of IBM CDPz, from where…

---

## [Grok pattern matching in debugger but not on logstash](https://discuss.elastic.co/t/grok-pattern-matching-in-debugger-but-not-on-logstash/306624)

<div class="topic-metadata">

**Author:** [@smtp\_server](https://discuss.elastic.co/u/smtp_server)\
**Replies:** 3\
**Last updated:** [June 8, 2022, 3:44pm UTC](https://discuss.elastic.co/t/grok-pattern-matching-in-debugger-but-not-on-logstash/306624 "2022-06-08T15:44:57Z")

</div>

Obvious from question, I've been trying to look for fault for so long but still don't seem to be coming around solution. Here's config filter{ grok{ pattern\_definitions =\> { "CUSTOMMONTH" =\> "(Jan|Feb|Mar|Apr|Ma…

---

## [Logstash not working, if installed in a location where the path contains parentheses (on windows)](https://discuss.elastic.co/t/logstash-not-working-if-installed-in-a-location-where-the-path-contains-parentheses-on-windows/306721)

<div class="topic-metadata">

**Author:** [@simon137](https://discuss.elastic.co/u/simon137)\
**Replies:** 0\
**Last updated:** [June 8, 2022, 3:40pm UTC](https://discuss.elastic.co/t/logstash-not-working-if-installed-in-a-location-where-the-path-contains-parentheses-on-windows/306721 "2022-06-08T15:40:29Z")

</div>

Hello together, As the title suggests, with a sample path of "C:\\ProgramData\\Test)Test\\logstash", the call to ".\\bin\\logstash.bat" fails with the message: "Test\\logstash\\jdk\\bin\\java.exe" cannot be processed syntactical…

---

## [Fscrawler \_settings.yaml nodes settings](https://discuss.elastic.co/t/fscrawler-settings-yaml-nodes-settings/306717)

<div class="topic-metadata">

**Author:** [@newschapmj1](https://discuss.elastic.co/u/newschapmj1)\
**Replies:** 0\
**Last updated:** [June 8, 2022, 2:47pm UTC](https://discuss.elastic.co/t/fscrawler-settings-yaml-nodes-settings/306717 "2022-06-08T14:47:54Z")

</div>

We have a cluster of 7 nodes (ES 7.10). We run 5 Fscrawlers on 2 other separate servers. In the nodes section of \_settings.yaml At present we have the 7 IP addresses of the 7 nodes listed in ascending order on each of…

---

## [Are these reasonable/expected metrics for an idle cluster?](https://discuss.elastic.co/t/are-these-reasonable-expected-metrics-for-an-idle-cluster/306644)

<div class="topic-metadata">

**Author:** [@AS11](https://discuss.elastic.co/u/AS11)\
**Replies:** 0\
**Last updated:** [June 8, 2022, 7:30am UTC](https://discuss.elastic.co/t/are-these-reasonable-expected-metrics-for-an-idle-cluster/306644 "2022-06-08T07:30:16Z")

</div>

For an idle 3-node cluster (7.17.4), where all nodes are masters, i.e. listed under initial\_master\_nodes, is it normal that: Documents merged rate, red-bordered on the image below, would be on the order of 1000/s on a…

---

## [Logstash not sending all data to elasti search](https://discuss.elastic.co/t/logstash-not-sending-all-data-to-elasti-search/306699)

<div class="topic-metadata">

**Author:** [@Mary2022](https://discuss.elastic.co/u/Mary2022)\
**Replies:** 0\
**Last updated:** [June 8, 2022, 1:39pm UTC](https://discuss.elastic.co/t/logstash-not-sending-all-data-to-elasti-search/306699 "2022-06-08T13:39:31Z")

</div>

Hi, My logstash is getting data continuously. I know this because I can see it at the logs (logstash debugging mode) but the if I go to kibana I see that 8 or 7 hrs ago I got 10 min of data and that was it when it was …

---

## [Remove documents with existing value in given field](https://discuss.elastic.co/t/remove-documents-with-existing-value-in-given-field/306572)

<div class="topic-metadata">

**Author:** [@fran\_hernandez](https://discuss.elastic.co/u/fran_hernandez)\
**Replies:** 4\
**Last updated:** [June 8, 2022, 1:09pm UTC](https://discuss.elastic.co/t/remove-documents-with-existing-value-in-given-field/306572 "2022-06-08T13:09:33Z")

</div>

Hello, I am trying to delete or pipe (Delete), an event that already has the same indexed value for a given field. The scenario is as follows: I have a fleet server and an agent to fetch logs from AD Server, Windows f…

---

## [Not able to add Elasticsearch Cloud in Azure due to required "Subscription owner" permission not allowed](https://discuss.elastic.co/t/not-able-to-add-elasticsearch-cloud-in-azure-due-to-required-subscription-owner-permission-not-allowed/306197)

<div class="topic-metadata">

**Author:** [@arunvelu](https://discuss.elastic.co/u/arunvelu)\
**Replies:** 4\
**Last updated:** [June 8, 2022, 12:10pm UTC](https://discuss.elastic.co/t/not-able-to-add-elasticsearch-cloud-in-azure-due-to-required-subscription-owner-permission-not-allowed/306197 "2022-06-08T12:10:36Z")

</div>

Hello, We are looking to try Elasticsearch in Azure for analyzing the application's log data. To do this, I planned on creating an instance in Azure, but I get an error message at creation – “Validation failed. Only sub…

---

## [Getting incorrect inner hits from parent child relationship when combined with boolean query](https://discuss.elastic.co/t/getting-incorrect-inner-hits-from-parent-child-relationship-when-combined-with-boolean-query/306688)

<div class="topic-metadata">

**Author:** [@Mohammad\_Parsa](https://discuss.elastic.co/u/Mohammad_Parsa)\
**Replies:** 0\
**Last updated:** [June 8, 2022, 11:26am UTC](https://discuss.elastic.co/t/getting-incorrect-inner-hits-from-parent-child-relationship-when-combined-with-boolean-query/306688 "2022-06-08T11:26:52Z")

</div>

Hi Everyone I am getting incorrect inner hits results when combining parent-child query with boolean query. To reproduce the issue, I create this Index PUT /my-index-000001 { "mappings": { "\_routing": { "r…

[Previous page](https://discuss.elastic.co/tag/none.md?no_tags=true&page=613)

[Next page](https://discuss.elastic.co/tag/none.md?no_tags=true&page=615)
