# \#none

**URL:** https://discuss.elastic.co/tag/none.md?no_tags=true&page=615

[Latest](https://discuss.elastic.co/latest.md) · [Categories](https://discuss.elastic.co/categories.md) · [Tags](https://discuss.elastic.co/tags.md)

**Page:** 616

---

## [Find nested document by min value of its field and apply another filters on this document](https://discuss.elastic.co/t/find-nested-document-by-min-value-of-its-field-and-apply-another-filters-on-this-document/306689)

<div class="topic-metadata">

**Author:** [@Nat123](https://discuss.elastic.co/u/Nat123)\
**Replies:** 0\
**Last updated:** [June 8, 2022, 11:31am UTC](https://discuss.elastic.co/t/find-nested-document-by-min-value-of-its-field-and-apply-another-filters-on-this-document/306689 "2022-06-08T11:31:27Z")

</div>

Hello, I have a document (user) and a list of nested documents (orders) in Elastic. I need to find a user with an order satisfied a bunch of conditions: the status of order should have some specific value, its id should…

---

## [How to write kql query in kibana to include only 9 characters of a field?](https://discuss.elastic.co/t/how-to-write-kql-query-in-kibana-to-include-only-9-characters-of-a-field/306672)

<div class="topic-metadata">

**Author:** [@Arifullah](https://discuss.elastic.co/u/Arifullah)\
**Replies:** 5\
**Last updated:** [June 8, 2022, 11:02am UTC](https://discuss.elastic.co/t/how-to-write-kql-query-in-kibana-to-include-only-9-characters-of-a-field/306672 "2022-06-08T11:02:04Z")

</div>

I am using kibana 8.1 so I want to filter the data in discover section. Tha index has a field whic is in number format and it has different kinds of numbers which range from 4 characters up to 12 or 13 characters. So I w…

---

## [Increase max\_bucket to 60,000 or make 6 msearch returning 10,000 buckets each?](https://discuss.elastic.co/t/increase-max-bucket-to-60-000-or-make-6-msearch-returning-10-000-buckets-each/306480)

<div class="topic-metadata">

**Author:** [@misterone](https://discuss.elastic.co/u/misterone)\
**Replies:** 2\
**Last updated:** [June 8, 2022, 10:50am UTC](https://discuss.elastic.co/t/increase-max-bucket-to-60-000-or-make-6-msearch-returning-10-000-buckets-each/306480 "2022-06-08T10:50:55Z")

</div>

hey, I have a query that does this. It's a bunch of terms aggregations. (group by = terms) filter by date from year 2015 to 2020 group by region group by date from year 2015 to 2020 group by country grou…

---

## [Elasticsearch input plugin used to \_count documents. Is it possible?](https://discuss.elastic.co/t/elasticsearch-input-plugin-used-to-count-documents-is-it-possible/306682)

<div class="topic-metadata">

**Author:** [@rschirin](https://discuss.elastic.co/u/rschirin)\
**Replies:** 0\
**Last updated:** [June 8, 2022, 10:46am UTC](https://discuss.elastic.co/t/elasticsearch-input-plugin-used-to-count-documents-is-it-possible/306682 "2022-06-08T10:46:44Z")

</div>

Hey there, I was trying to use the Elasticsearch input plugin just to count documents in a specific timerange or to count the specific \_type documents or so on, but I saw that I cannot use the \_count method and I saw al…

---

## [Saved Objectsにて「-」を含む名称の検索について](https://discuss.elastic.co/t/saved-objects/306642)

<div class="topic-metadata">

**Author:** [@na\_taka](https://discuss.elastic.co/u/na_taka)\
**Replies:** 5\
**Last updated:** [June 8, 2022, 10:33am UTC](https://discuss.elastic.co/t/saved-objects/306642 "2022-06-08T10:33:11Z")

</div>

zzz-zzzのようなObject名称である場合に、名称を完全一致で検索を行うには、どのように指定したら検索できるのでしょうか。 部分一致では、以下のように検索は可能である。 しかし、以下のように完全一致となるように指定した場合には該当しない。 "zzz-zzz"と「"」で囲ってみた場合でも検索がでませんでした。

---

## [Rubyフィルターで指定したフィールドを特定フィールド配下に格納したい](https://discuss.elastic.co/t/ruby/306516)

<div class="topic-metadata">

**Author:** [@t-nakata](https://discuss.elastic.co/u/t-nakata)\
**Replies:** 2\
**Last updated:** [June 8, 2022, 10:20am UTC](https://discuss.elastic.co/t/ruby/306516 "2022-06-08T10:20:48Z")

</div>

下記の構成のドキュメントをlogstashからElasticsearchに連携しております ～省略～ "timestamp\_log": "2022-06-03T09:01:28.000+09:00", "awsRegion": "us-east-1", "requestParameters": { "template": false, "resourceId": "5tfEXAMPLE", "restApiId": "3r…

---

## [Numeric values on timeline](https://discuss.elastic.co/t/numeric-values-on-timeline/306548)

<div class="topic-metadata">

**Author:** [@g\_k\_b](https://discuss.elastic.co/u/g_k_b)\
**Replies:** 6\
**Last updated:** [June 8, 2022, 9:36am UTC](https://discuss.elastic.co/t/numeric-values-on-timeline/306548 "2022-06-08T09:36:20Z")

</div>

Hello Kibana users! Can anyone suggest me how can I represent numeric values on a timeline?he fields I'm referrering to are @timestamp and used.bytes; I want to see the distribution of this field over time. thank you in…

---

## [How to install kibana and logstash as service in windows server](https://discuss.elastic.co/t/how-to-install-kibana-and-logstash-as-service-in-windows-server/306587)

<div class="topic-metadata">

**Author:** [@jisha](https://discuss.elastic.co/u/jisha)\
**Replies:** 1\
**Last updated:** [June 8, 2022, 8:57am UTC](https://discuss.elastic.co/t/how-to-install-kibana-and-logstash-as-service-in-windows-server/306587 "2022-06-08T08:57:53Z")

</div>

How to install kibana and logstash as service in windows server? Can please someone help with the command

---

## [How to identify whether a elasticsearch document is modified or not?](https://discuss.elastic.co/t/how-to-identify-whether-a-elasticsearch-document-is-modified-or-not/306537)

<div class="topic-metadata">

**Author:** [@Souvik\_Das](https://discuss.elastic.co/u/Souvik_Das)\
**Replies:** 1\
**Last updated:** [June 8, 2022, 8:37am UTC](https://discuss.elastic.co/t/how-to-identify-whether-a-elasticsearch-document-is-modified-or-not/306537 "2022-06-08T08:37:38Z")

</div>

Hi All, If a logstash pipeline (conf file) is used to update and insert both i.e., enabled below in the conf file. doc\_as\_upsert =\> true action =\> "update" How to know which documents are updated and which are inserte…

---

## [Timelion Aggregate graph with different interval/condition](https://discuss.elastic.co/t/timelion-aggregate-graph-with-different-interval-condition/306651)

<div class="topic-metadata">

**Author:** [@Robert\_Naccache](https://discuss.elastic.co/u/Robert_Naccache)\
**Replies:** 0\
**Last updated:** [June 8, 2022, 8:15am UTC](https://discuss.elastic.co/t/timelion-aggregate-graph-with-different-interval-condition/306651 "2022-06-08T08:15:40Z")

</div>

Hello, I'm trying to create a Timelion aggregation and wondering if its possible. Basically the case is, I have documents that includes http response codes. What i'm trying to do is: The default interval could be day…

---

## [How to assign index routing allocation with APM](https://discuss.elastic.co/t/how-to-assign-index-routing-allocation-with-apm/306650)

<div class="topic-metadata">

**Author:** [@Kay\_Khan](https://discuss.elastic.co/u/Kay_Khan)\
**Replies:** 0\
**Last updated:** [June 8, 2022, 8:10am UTC](https://discuss.elastic.co/t/how-to-assign-index-routing-allocation-with-apm/306650 "2022-06-08T08:10:53Z")

</div>

I am using APM version 8.2.0, how do i allocate the indexes/data-streams to be on a specific nodeset. For example in my metricbeat.yml and filebeat.yml i might do the following: setup.template.settings: index: …

---

## [Aggregration buckets can access in Elasticsearch query of "Rules and Connectors"](https://discuss.elastic.co/t/aggregration-buckets-can-access-in-elasticsearch-query-of-rules-and-connectors/306641)

<div class="topic-metadata">

**Author:** [@hari\_priya1](https://discuss.elastic.co/u/hari_priya1)\
**Replies:** 0\
**Last updated:** [June 8, 2022, 7:17am UTC](https://discuss.elastic.co/t/aggregration-buckets-can-access-in-elasticsearch-query-of-rules-and-connectors/306641 "2022-06-08T07:17:58Z")

</div>

I am trying to trigger an alert if BindRequestCount is zero for the last 30 mins. So I have created a rule using the Elasticsearch query rule type. { "query": { "bool": { "must": \[ { "term"…

---

## [How to search in attachment content?](https://discuss.elastic.co/t/how-to-search-in-attachment-content/305287)

<div class="topic-metadata">

**Author:** [@frankmehlhop](https://discuss.elastic.co/u/frankmehlhop)\
**Replies:** 2\
**Last updated:** [June 8, 2022, 7:17am UTC](https://discuss.elastic.co/t/how-to-search-in-attachment-content/305287 "2022-06-08T07:17:33Z")

</div>

I ingest pdf files into elastic. I can successful search in it using Kibana Console. But at my C# code I don't get any result. I'm quit sure the problem is syntax of my code. But I tried many things and still I don't…

---

## [ELK 7.16.2 hardware requirements - suggestions?](https://discuss.elastic.co/t/elk-7-16-2-hardware-requirements-suggestions/306475)

<div class="topic-metadata">

**Author:** [@Ely\_96](https://discuss.elastic.co/u/Ely_96)\
**Replies:** 7\
**Last updated:** [June 8, 2022, 7:12am UTC](https://discuss.elastic.co/t/elk-7-16-2-hardware-requirements-suggestions/306475 "2022-06-08T07:12:07Z")

</div>

Hi Guys, I am using the ELK stack in version 7.16.2 and I would like to ask for some suggestions about the hardware configuration. My Elastic will receive a log of 5 MB every day and I would like to have a retention of …

---

## [Configuration of Logstash to remove domain from URL](https://discuss.elastic.co/t/configuration-of-logstash-to-remove-domain-from-url/305667)

<div class="topic-metadata">

**Author:** [@wii](https://discuss.elastic.co/u/wii)\
**Replies:** 2\
**Last updated:** [June 8, 2022, 6:06am UTC](https://discuss.elastic.co/t/configuration-of-logstash-to-remove-domain-from-url/305667 "2022-06-08T06:06:17Z")

</div>

Is it possible to configure Logstash to remove domain name when receiving URL input? E.g: Picture above as an example, I would like to eliminate everthing behind 'path' to send to Elasticsearch. If it is possible, ma…

---

## [Visualize datatable : reformat aggrated value](https://discuss.elastic.co/t/visualize-datatable-reformat-aggrated-value/306562)

<div class="topic-metadata">

**Author:** [@Espen\_Schulstad](https://discuss.elastic.co/u/Espen_Schulstad)\
**Replies:** 1\
**Last updated:** [June 8, 2022, 5:38am UTC](https://discuss.elastic.co/t/visualize-datatable-reformat-aggrated-value/306562 "2022-06-08T05:38:44Z")

</div>

Hi, I'd like to use a value in an aggregation to create a link in the datatable. Is this possible? Eg; in the datatable I have a value "specific app name", I'd like to reformat that value to be a string that ends up as…

---

## [How to install Kibana and logstash as service in winodws?](https://discuss.elastic.co/t/how-to-install-kibana-and-logstash-as-service-in-winodws/306622)

<div class="topic-metadata">

**Author:** [@jisha](https://discuss.elastic.co/u/jisha)\
**Replies:** 1\
**Last updated:** [June 8, 2022, 4:15am UTC](https://discuss.elastic.co/t/how-to-install-kibana-and-logstash-as-service-in-winodws/306622 "2022-06-08T04:15:09Z")

</div>

how to install Kibana and logstash(v.7.17.3) as service in winodws can please someone help with command line

---

## [Reindex from Remote not working](https://discuss.elastic.co/t/reindex-from-remote-not-working/306532)

<div class="topic-metadata">

**Author:** [@Bit\_Addict](https://discuss.elastic.co/u/Bit_Addict)\
**Replies:** 3\
**Last updated:** [June 8, 2022, 4:04am UTC](https://discuss.elastic.co/t/reindex-from-remote-not-working/306532 "2022-06-08T04:04:40Z")

</div>

Hi, I am trying to migrate all watchers from one cluster to another (both on 7.9.2) using the "Reindex from remote" feature, but it looks like the reindex is not picking up any documents. POST \_reindex { "source": { …

---

## [Explain API for Phrase Suggester](https://discuss.elastic.co/t/explain-api-for-phrase-suggester/306619)

<div class="topic-metadata">

**Author:** [@KR09](https://discuss.elastic.co/u/KR09)\
**Replies:** 0\
**Last updated:** [June 8, 2022, 3:31am UTC](https://discuss.elastic.co/t/explain-api-for-phrase-suggester/306619 "2022-06-08T03:31:10Z")

</div>

Hi All, We are using Phrase Suggester to implement "Did you mean" functionality. We have added direct\_generator to control min\_word\_length,collate to only return the suggestion based on the documents present in the inde…

---

## [Query : GET average document count](https://discuss.elastic.co/t/query-get-average-document-count/306556)

<div class="topic-metadata">

**Author:** [@A\_j\_xx](https://discuss.elastic.co/u/A_j_xx)\
**Replies:** 2\
**Last updated:** [June 8, 2022, 1:46am UTC](https://discuss.elastic.co/t/query-get-average-document-count/306556 "2022-06-08T01:46:41Z")

</div>

Hi all , What would be the query to get average number of documents added per day on my index ? Is there any workaround or query to aggregate this data ? Thanks ! Hope to get a response

---

## [Time Filter in Kibana Disappeared for Some Users](https://discuss.elastic.co/t/time-filter-in-kibana-disappeared-for-some-users/306494)

<div class="topic-metadata">

**Author:** [@Datt\_Mamon](https://discuss.elastic.co/u/Datt_Mamon)\
**Replies:** 5\
**Last updated:** [June 7, 2022, 7:57pm UTC](https://discuss.elastic.co/t/time-filter-in-kibana-disappeared-for-some-users/306494 "2022-06-07T19:57:06Z")

</div>

Hey all! Ran into a little issue with my Kibana instance that I'm hoping the wonderful community can help me out with. I created a new space and roles for a group of users to look at logs specific to their groups' work…

---

## [How to group logstash output files based on incoming input date?](https://discuss.elastic.co/t/how-to-group-logstash-output-files-based-on-incoming-input-date/306275)

<div class="topic-metadata">

**Author:** [@newelastic](https://discuss.elastic.co/u/newelastic)\
**Replies:** 6\
**Last updated:** [June 7, 2022, 10:56pm UTC](https://discuss.elastic.co/t/how-to-group-logstash-output-files-based-on-incoming-input-date/306275 "2022-06-07T22:56:20Z")

</div>

Hello, I've thousands of records in my Elasticsearch which span across different dates, month and year. I would like to output the data by year, month and date wise using output plugin. Here is my pipeline. Can someone…

---

## [Unassigned shards](https://discuss.elastic.co/t/unassigned-shards/306526)

<div class="topic-metadata">

**Author:** [@petezhang](https://discuss.elastic.co/u/petezhang)\
**Replies:** 2\
**Last updated:** [June 7, 2022, 10:55pm UTC](https://discuss.elastic.co/t/unassigned-shards/306526 "2022-06-07T22:55:38Z")

</div>

Really need help on the unassigned-shard: "unassigned\_info": { "reason": "INDEX\_REOPENED", "details": null, "allocation\_status": "no\_valid\_shard\_copy" }, "index": "\<service\_name\>~\<inde…

---

## [Not getting the latest logs in kibana](https://discuss.elastic.co/t/not-getting-the-latest-logs-in-kibana/306167)

<div class="topic-metadata">

**Author:** [@Dev220](https://discuss.elastic.co/u/Dev220)\
**Replies:** 5\
**Last updated:** [June 7, 2022, 9:01pm UTC](https://discuss.elastic.co/t/not-getting-the-latest-logs-in-kibana/306167 "2022-06-07T21:01:39Z")

</div>

Hi Team, I am new to kibana. For collecting the logs from my application pods I am using fluent-bit configuration as a pod. Both the Elasticsearch and kiban services are up and running. I am able to see the logs in k…

---

## [Query help - return proximity between terms?](https://discuss.elastic.co/t/query-help-return-proximity-between-terms/306604)

<div class="topic-metadata">

**Author:** [@iross](https://discuss.elastic.co/u/iross)\
**Replies:** 0\
**Last updated:** [June 7, 2022, 8:57pm UTC](https://discuss.elastic.co/t/query-help-return-proximity-between-terms/306604 "2022-06-07T20:57:14Z")

</div>

Hello- I'm interested in returning the minimum "distance" between two terms within an (analyzed) text document. For example, given a sentence of "The quick brown fox jumped over the lazy dog," I'd like to be able to ext…

---

## [Alert to connectors](https://discuss.elastic.co/t/alert-to-connectors/306598)

<div class="topic-metadata">

**Author:** [@dlazure](https://discuss.elastic.co/u/dlazure)\
**Replies:** 0\
**Last updated:** [June 7, 2022, 6:25pm UTC](https://discuss.elastic.co/t/alert-to-connectors/306598 "2022-06-07T18:25:12Z")

</div>

Hi, I am sending elastic security alerts to microsoft teams. I am using suricata for IDS and the alerts are sending fine, however, it always show External Alerts as the name. It does not provide the real alert name. I…

---

## [Logstash - Error to connecting ES and SQL Server](https://discuss.elastic.co/t/logstash-error-to-connecting-es-and-sql-server/306594)

<div class="topic-metadata">

**Author:** [@Furok](https://discuss.elastic.co/u/Furok)\
**Replies:** 0\
**Last updated:** [June 7, 2022, 4:45pm UTC](https://discuss.elastic.co/t/logstash-error-to-connecting-es-and-sql-server/306594 "2022-06-07T16:45:20Z")

</div>

Hi guys, I'm trying to connect SQL server with ES using logstash, nevertheless, I have the following error . \[Ruby-0-Thread-9: :1\] elasticsearch - Attempted to resurrect connection to dead ES instance, but got an error…

---

## [Parse dynamic field names](https://discuss.elastic.co/t/parse-dynamic-field-names/306558)

<div class="topic-metadata">

**Author:** [@Soren\_vdc](https://discuss.elastic.co/u/Soren_vdc)\
**Replies:** 1\
**Last updated:** [June 7, 2022, 4:43pm UTC](https://discuss.elastic.co/t/parse-dynamic-field-names/306558 "2022-06-07T16:43:27Z")

</div>

Hi, I want to parse some code in message field where the field names contains a number. Example: responseGENERATED\_100=76 SENT\_100=76 responseGENERATED\_180=221 SENT\_180=221 responseGENERATED\_190=0 SENT\_183=0 The fil…

---

## [Logstash - Error parsing a concrete value into object field](https://discuss.elastic.co/t/logstash-error-parsing-a-concrete-value-into-object-field/306559)

<div class="topic-metadata">

**Author:** [@Thuunder7](https://discuss.elastic.co/u/Thuunder7)\
**Replies:** 1\
**Last updated:** [June 7, 2022, 4:38pm UTC](https://discuss.elastic.co/t/logstash-error-parsing-a-concrete-value-into-object-field/306559 "2022-06-07T16:38:35Z")

</div>

Hello guys, I have a pipeline on Logstash that is parsing and filtering some data from a kafka topic. Everything is working fine but from time to time i got this error message: "error"=\>{"type"=\>"mapper\_parsing\_excepti…

---

## [Do these "could not index" errors actually end up in Elastic anywhere?](https://discuss.elastic.co/t/do-these-could-not-index-errors-actually-end-up-in-elastic-anywhere/306582)

<div class="topic-metadata">

**Author:** [@ckes](https://discuss.elastic.co/u/ckes)\
**Replies:** 2\
**Last updated:** [June 7, 2022, 3:58pm UTC](https://discuss.elastic.co/t/do-these-could-not-index-errors-actually-end-up-in-elastic-anywhere/306582 "2022-06-07T15:58:40Z")

</div>

I've noticed quite a few of these errors with the elastic output plugin in /var/log/logstash/logstash-plain.log: "Could not index event to Elasticsearch. {:status=\>400, :action=\>\["create", ... The solution to fix the…

[Previous page](https://discuss.elastic.co/tag/none.md?no_tags=true&page=614)

[Next page](https://discuss.elastic.co/tag/none.md?no_tags=true&page=616)
