# Elastic Stack

**URL:** https://discuss.elastic.co/c/elastic-stack/81.md?page=438

[Latest](https://discuss.elastic.co/latest.md) · [Categories](https://discuss.elastic.co/categories.md) · [Tags](https://discuss.elastic.co/tags.md)

**Page:** 439

---

## [How to get Average of 2 timestamp in Kibana metric visualization](https://discuss.elastic.co/t/how-to-get-average-of-2-timestamp-in-kibana-metric-visualization/340616)

<div class="topic-metadata">

**Author:** [@yash\_mangla](https://discuss.elastic.co/u/yash_mangla)\
**Replies:** 1\
**Last updated:** [August 29, 2023, 5:26pm UTC](https://discuss.elastic.co/t/how-to-get-average-of-2-timestamp-in-kibana-metric-visualization/340616 "2023-08-29T17:26:21Z")

</div>

Hi Team, I want to create a metric visualization with average difference showing for entire records. and every record is having multiple timestamp. So, we want to show average difference between start\_time and acknoele…

---

## [Building a Basic Query That Orders Results](https://discuss.elastic.co/t/building-a-basic-query-that-orders-results/341906)

<div class="topic-metadata">

**Author:** [@kocakserdar](https://discuss.elastic.co/u/kocakserdar)\
**Replies:** 0\
**Last updated:** [August 29, 2023, 3:37pm UTC](https://discuss.elastic.co/t/building-a-basic-query-that-orders-results/341906 "2023-08-29T15:37:50Z")

</div>

Hello, As a newbie, I'm trying to build a compound query for my NodeJS/Express web app. All I need is to give priority to phrases first in the search results if they exist... For example let's search for "customers are"…

---

## [Line graph in 5 min interval showing previous values](https://discuss.elastic.co/t/line-graph-in-5-min-interval-showing-previous-values/341868)

<div class="topic-metadata">

**Author:** [@Saili\_Bakalkar](https://discuss.elastic.co/u/Saili_Bakalkar)\
**Replies:** 7\
**Last updated:** [August 29, 2023, 3:30pm UTC](https://discuss.elastic.co/t/line-graph-in-5-min-interval-showing-previous-values/341868 "2023-08-29T15:30:17Z")

</div>

Value Time 6.55 2023-08-24 18:08:00 6.49 2023-08-24 18:11:40 6.50 2023-08-24 18:13:30 I have a line graph of value vs time with minimum interval set to 5m I want to create a 5 min window of this data so when when the…

---

## [\[Elasticsearch Client .Net\] need help Create Index mapping Nested field type](https://discuss.elastic.co/t/elasticsearch-client-net-need-help-create-index-mapping-nested-field-type/341786)

<div class="topic-metadata">

**Author:** [@Steven\_Vo](https://discuss.elastic.co/u/Steven_Vo)\
**Replies:** 1\
**Last updated:** [August 29, 2023, 3:10pm UTC](https://discuss.elastic.co/t/elasticsearch-client-net-need-help-create-index-mapping-nested-field-type/341786 "2023-08-29T15:10:13Z")

</div>

public class EsProductEto { public Guid Id { get; set; } ..... public List\<EsAttributeEto\> Items { get; set; } } ----- public class EsAttributeEto { public Guid Id { get; set; …

---

## [Semantic search with search correlation between fields](https://discuss.elastic.co/t/semantic-search-with-search-correlation-between-fields/341564)

<div class="topic-metadata">

**Author:** [@sivagurlinka](https://discuss.elastic.co/u/sivagurlinka)\
**Replies:** 4\
**Last updated:** [August 29, 2023, 2:49pm UTC](https://discuss.elastic.co/t/semantic-search-with-search-correlation-between-fields/341564 "2023-08-29T14:49:14Z")

</div>

Can semantic search with correlation between fields can be implemented with Elasticsearch ? I have ecommerce data indexed to Elasticsearch with below fields and description is vector text embedded. Name : product name(…

---

## [Elastic search order of the highlighted fields not matching with the ranking](https://discuss.elastic.co/t/elastic-search-order-of-the-highlighted-fields-not-matching-with-the-ranking/341889)

<div class="topic-metadata">

**Author:** [@Vikram\_Jadhav](https://discuss.elastic.co/u/Vikram_Jadhav)\
**Replies:** 0\
**Last updated:** [August 29, 2023, 2:19pm UTC](https://discuss.elastic.co/t/elastic-search-order-of-the-highlighted-fields-not-matching-with-the-ranking/341889 "2023-08-29T14:19:23Z")

</div>

Hello, In the below document, I am trying to match multiple fields and I also want to know what fields are getting matched from the document that's why used the highlighted fields. sample doc: { "therapeutic\_area": "…

---

## [How to compare document fields in a elasticsearch query](https://discuss.elastic.co/t/how-to-compare-document-fields-in-a-elasticsearch-query/341814)

<div class="topic-metadata">

**Author:** [@juanmgarciaf](https://discuss.elastic.co/u/juanmgarciaf)\
**Replies:** 1\
**Last updated:** [August 29, 2023, 2:17pm UTC](https://discuss.elastic.co/t/how-to-compare-document-fields-in-a-elasticsearch-query/341814 "2023-08-29T14:17:06Z")

</div>

Hello! I have an index with a lot of documents and I need to group these documents by an specific field and after this I need to compare if the two last documents (with the most recent timestamp) from each group have a s…

---

## [Hi elasticsearch resthighlevelclient SocketTimeOutException issue](https://discuss.elastic.co/t/hi-elasticsearch-resthighlevelclient-sockettimeoutexception-issue/341885)

<div class="topic-metadata">

**Author:** [@slowup](https://discuss.elastic.co/u/slowup)\
**Replies:** 0\
**Last updated:** [August 29, 2023, 1:59pm UTC](https://discuss.elastic.co/t/hi-elasticsearch-resthighlevelclient-sockettimeoutexception-issue/341885 "2023-08-29T13:59:19Z")

</div>

As the title says, I'm currently facing a SocketTimeoutException. There are almost no servers and it happens even expected (about 2 per traffic?) So I think it's a client problem, not a server performance problem. It …

---

## [Preferred proxy for fleet](https://discuss.elastic.co/t/preferred-proxy-for-fleet/341884)

<div class="topic-metadata">

**Author:** [@Atul\_Chadha](https://discuss.elastic.co/u/Atul_Chadha)\
**Replies:** 0\
**Last updated:** [August 29, 2023, 1:55pm UTC](https://discuss.elastic.co/t/preferred-proxy-for-fleet/341884 "2023-08-29T13:55:13Z")

</div>

Is there a preferred proxy software recommended for fleet setup on elasticsearch 8.9 self hosted setup. I am dicey between squid and nginx.

---

## [No\_shard\_available\_action\_exception](https://discuss.elastic.co/t/no-shard-available-action-exception/341883)

<div class="topic-metadata">

**Author:** [@Nibort](https://discuss.elastic.co/u/Nibort)\
**Replies:** 0\
**Last updated:** [August 29, 2023, 1:25pm UTC](https://discuss.elastic.co/t/no-shard-available-action-exception/341883 "2023-08-29T13:25:32Z")

</div>

Hello, I'm trying to send rsyslog with filebeat to my Elasticsearch cluster I've added the global path where logs are stored (/var/log/\*.log) filebeat.yml filebeat.inputs: - type: log id: rsyslog paths: - /va…

---

## [How to do float comparison](https://discuss.elastic.co/t/how-to-do-float-comparison/341881)

<div class="topic-metadata">

**Author:** [@lostsoul352](https://discuss.elastic.co/u/lostsoul352)\
**Replies:** 3\
**Last updated:** [August 29, 2023, 1:16pm UTC](https://discuss.elastic.co/t/how-to-do-float-comparison/341881 "2023-08-29T13:16:29Z")

</div>

I'm trying to drop events if the value of a float field is less than -90000 Here is a code snippet: if \[type\] == "node\_perf" { mutate { convert =\> { "nodeperf\_value" =\> "float"} …

---

## [Aggregate filter plugin - final event contains empty message](https://discuss.elastic.co/t/aggregate-filter-plugin-final-event-contains-empty-message/339702)

<div class="topic-metadata">

**Author:** [@Anca\_Linca](https://discuss.elastic.co/u/Anca_Linca)\
**Replies:** 8\
**Last updated:** [August 29, 2023, 1:02pm UTC](https://discuss.elastic.co/t/aggregate-filter-plugin-final-event-contains-empty-message/339702 "2023-08-29T13:02:03Z")

</div>

Hello, Logstash version: 7.17 Aggregate filter plugin: v2.10.0 Contents for /var/log/logstash/input.log: {"timestamp": "2023-07-31T15:10:45.141Z", "parentOnly": 1, "logger\_name": "activity\_stream", "job": 102693, "ty…

---

## [Querying on large docs](https://discuss.elastic.co/t/querying-on-large-docs/341759)

<div class="topic-metadata">

**Author:** [@m4kkur0](https://discuss.elastic.co/u/m4kkur0)\
**Replies:** 4\
**Last updated:** [August 29, 2023, 12:53pm UTC](https://discuss.elastic.co/t/querying-on-large-docs/341759 "2023-08-29T12:53:15Z")

</div>

Hello all, I would like to know what are some good options to query an index that each doc in it structured like: field1, keyword field2, long field3, object, enabled: false (mostly below 1 mb but sometimes goes up t…

---

## [When to use SLO and when normal alerts in kibana?](https://discuss.elastic.co/t/when-to-use-slo-and-when-normal-alerts-in-kibana/341772)

<div class="topic-metadata">

**Author:** [@Navya1](https://discuss.elastic.co/u/Navya1)\
**Replies:** 1\
**Last updated:** [August 29, 2023, 11:02am UTC](https://discuss.elastic.co/t/when-to-use-slo-and-when-normal-alerts-in-kibana/341772 "2023-08-29T11:02:33Z")

</div>

Hello All, I have a questions on SLO when compared to normal alert setup in kibana. What is the difference ? Which option has to choose ? When to choose SLO and when to use normal alerts ? Please advise. Thanks, Navy…

---

## [Can Logstash support jvm security policy to restrict ruby exec policy](https://discuss.elastic.co/t/can-logstash-support-jvm-security-policy-to-restrict-ruby-exec-policy/341871)

<div class="topic-metadata">

**Author:** [@weizijun](https://discuss.elastic.co/u/weizijun)\
**Replies:** 0\
**Last updated:** [August 29, 2023, 9:35am UTC](https://discuss.elastic.co/t/can-logstash-support-jvm-security-policy-to-restrict-ruby-exec-policy/341871 "2023-08-29T09:35:44Z")

</div>

Since elasticsearch can configure security policies, can logstash do the same?

---

## [Logstash index is not having the autosuggestions](https://discuss.elastic.co/t/logstash-index-is-not-having-the-autosuggestions/341866)

<div class="topic-metadata">

**Author:** [@uma\_parvathy](https://discuss.elastic.co/u/uma_parvathy)\
**Replies:** 0\
**Last updated:** [August 29, 2023, 8:26am UTC](https://discuss.elastic.co/t/logstash-index-is-not-having-the-autosuggestions/341866 "2023-08-29T08:26:45Z")

</div>

i've been trying to populate the data from postgresql db to elasticsearch7.17 using logstash. The data is imported but it's missing the autosuggestions and fuzzy logic suggestions which is needed to query from django ap…

---

## [Aggregrating data from Nested Fields](https://discuss.elastic.co/t/aggregrating-data-from-nested-fields/341845)

<div class="topic-metadata">

**Author:** [@Kumar\_Abhinav](https://discuss.elastic.co/u/Kumar_Abhinav)\
**Replies:** 1\
**Last updated:** [August 29, 2023, 8:15am UTC](https://discuss.elastic.co/t/aggregrating-data-from-nested-fields/341845 "2023-08-29T08:15:37Z")

</div>

I am currently navigating Elasticsearch and Kibana version 8.7.1 and have encountered a challenge The Challenge: Aggregating Nested Fields My primary goal is to efficiently aggregate data residing within nested fields …

---

## [Plot 2 line with different filter on the same canvas](https://discuss.elastic.co/t/plot-2-line-with-different-filter-on-the-same-canvas/341698)

<div class="topic-metadata">

**Author:** [@fdevoto](https://discuss.elastic.co/u/fdevoto)\
**Replies:** 4\
**Last updated:** [August 29, 2023, 7:45am UTC](https://discuss.elastic.co/t/plot-2-line-with-different-filter-on-the-same-canvas/341698 "2023-08-29T07:45:32Z")

</div>

Hello, I am really newbie in Elastic/Kibana etc sorry if my teminology is not correct. I am trying to create a line plot with two lines, each line has a different filter. I can create the 2 plots separately, but I don…

---

## [Aggregate filter の timeout\_timestamp\_field設定時の動作について （続き）](https://discuss.elastic.co/t/aggregate-filter-timeout-timestamp-field/341858)

<div class="topic-metadata">

**Author:** [@e-se](https://discuss.elastic.co/u/e-se)\
**Replies:** 0\
**Last updated:** [August 29, 2023, 7:18am UTC](https://discuss.elastic.co/t/aggregate-filter-timeout-timestamp-field/341858 "2023-08-29T07:18:38Z")

</div>

Continuing the discussion from Aggregate filter の timeout\_timestamp\_field設定時の動作について: 2 行目は 2 番目の集計フィルターを通過しますが、タイムアウト オプションが設定されていないため、タイムアウト処理は行われません。 とありますが、システム時間でタイムアウトを計測する場合、フィルターを通過するかどうかに関係なく、timeoutオプションに設定し…

---

## [How to get in C# client not-null response even for failed search requests?](https://discuss.elastic.co/t/how-to-get-in-c-client-not-null-response-even-for-failed-search-requests/341358)

<div class="topic-metadata">

**Author:** [@Leonid\_P](https://discuss.elastic.co/u/Leonid_P)\
**Replies:** 2\
**Last updated:** [August 29, 2023, 7:15am UTC](https://discuss.elastic.co/t/how-to-get-in-c-client-not-null-response-even-for-failed-search-requests/341358 "2023-08-29T07:15:17Z")

</div>

Hi there! There is C# code that generates searches through code like that: searchResult = client.Search(descriptor); The request generated contains inappropriate data, and therefore I get Elasticsearch.Net.Elasticsea…

---

## [Remove old 7.x Kibana indices after upgrade to 8.9](https://discuss.elastic.co/t/remove-old-7-x-kibana-indices-after-upgrade-to-8-9/341212)

<div class="topic-metadata">

**Author:** [@chouben](https://discuss.elastic.co/u/chouben)\
**Replies:** 2\
**Last updated:** [August 29, 2023, 6:36am UTC](https://discuss.elastic.co/t/remove-old-7-x-kibana-indices-after-upgrade-to-8-9/341212 "2023-08-29T06:36:27Z")

</div>

Hi I posted my question in "elasticsearch" channel first. I didn't get a response yet, nor did I find a way to move it over here: Original post: https://discuss.elastic.co/t/remove-7-x-indices-after-upgrade-to-8-x I w…

---

## [Can I configure elastic agent to have logs indexed by elastic search?](https://discuss.elastic.co/t/can-i-configure-elastic-agent-to-have-logs-indexed-by-elastic-search/341856)

<div class="topic-metadata">

**Author:** [@Ong\_Yi\_Chong](https://discuss.elastic.co/u/Ong_Yi_Chong)\
**Replies:** 0\
**Last updated:** [August 29, 2023, 6:35am UTC](https://discuss.elastic.co/t/can-i-configure-elastic-agent-to-have-logs-indexed-by-elastic-search/341856 "2023-08-29T06:35:24Z")

</div>

Hi, I have just started learning about elastic stack one day ago. I have managed to add an elastic agent apm integration to a sample node JS server and I am able to view the log outputs on Observability \> Logs section. …

---

## [Remove 7.x indices after upgrade to 8.x](https://discuss.elastic.co/t/remove-7-x-indices-after-upgrade-to-8-x/341000)

<div class="topic-metadata">

**Author:** [@chouben](https://discuss.elastic.co/u/chouben)\
**Replies:** 6\
**Last updated:** [August 29, 2023, 6:34am UTC](https://discuss.elastic.co/t/remove-7-x-indices-after-upgrade-to-8-x/341000 "2023-08-29T06:34:57Z")

</div>

Hi I was wondering if we could remove the old 7.x indices from our Elastic Stack, since we upgraded to 8.x? E.g. Kibana: Remark: I found out about the allow\_restricted\_indices setting, which would probably allow me…

---

## [How to store/compress large string field in index (V6.8)](https://discuss.elastic.co/t/how-to-store-compress-large-string-field-in-index-v6-8/341777)

<div class="topic-metadata">

**Author:** [@elron](https://discuss.elastic.co/u/elron)\
**Replies:** 1\
**Last updated:** [August 29, 2023, 6:08am UTC](https://discuss.elastic.co/t/how-to-store-compress-large-string-field-in-index-v6-8/341777 "2023-08-29T06:08:04Z")

</div>

We are planning to store in the index a large string(error log) with a classifier for future use in a machine learning project. The error log can get to the size of tens of megabytes and we are planning to store tens of …

---

## [Elastic-agent metricbeat no verification mode](https://discuss.elastic.co/t/elastic-agent-metricbeat-no-verification-mode/341851)

<div class="topic-metadata">

**Author:** [@Daniel\_Lopez](https://discuss.elastic.co/u/Daniel_Lopez)\
**Replies:** 0\
**Last updated:** [August 29, 2023, 5:46am UTC](https://discuss.elastic.co/t/elastic-agent-metricbeat-no-verification-mode/341851 "2023-08-29T05:46:02Z")

</div>

Hi guys! I think i found a bug on elastic-agent. I configured the whole fleet server with --insecure and ssl.verification\_mode: none options and i'm getting logs to elastic but not metricbeat metrics as i show in the se…

---

## [Data getting SWAPPED in Elasticsearch with pipeline](https://discuss.elastic.co/t/data-getting-swapped-in-elasticsearch-with-pipeline/341796)

<div class="topic-metadata">

**Author:** [@tusharnemade](https://discuss.elastic.co/u/tusharnemade)\
**Replies:** 2\
**Last updated:** [August 29, 2023, 5:33am UTC](https://discuss.elastic.co/t/data-getting-swapped-in-elasticsearch-with-pipeline/341796 "2023-08-29T05:33:36Z")

</div>

Hello Team We are using Elasticsearch version 7.8.0 We are having Index with Pipeline Defined .. Our Problem is data is getting SWAPPED between two fields of Elasticsearch. Data of "OBJ\_NAM\_FILDT" is getting posted i…

---

## [Kibana authentication-Should ask credentials access in kibana UI and Bypass authentication in CUSTOM WEBUI angular based](https://discuss.elastic.co/t/kibana-authentication-should-ask-credentials-access-in-kibana-ui-and-bypass-authentication-in-custom-webui-angular-based/339435)

<div class="topic-metadata">

**Author:** [@PRASHANT\_MEHTA](https://discuss.elastic.co/u/PRASHANT_MEHTA)\
**Replies:** 2\
**Last updated:** [August 28, 2023, 10:32am UTC](https://discuss.elastic.co/t/kibana-authentication-should-ask-credentials-access-in-kibana-ui-and-bypass-authentication-in-custom-webui-angular-based/339435 "2023-08-28T10:32:03Z")

</div>

Hello All, I've requirement where in custom web ui it should not ask any authentication i.e direct access of dashboards in custom website.(This is achieved using anonymous user setting in kibana.yml) But now this same …

---

## [Need confirmation for few Elasticsearch queries](https://discuss.elastic.co/t/need-confirmation-for-few-elasticsearch-queries/341849)

<div class="topic-metadata">

**Author:** [@ashishshukla](https://discuss.elastic.co/u/ashishshukla)\
**Replies:** 1\
**Last updated:** [August 29, 2023, 5:15am UTC](https://discuss.elastic.co/t/need-confirmation-for-few-elasticsearch-queries/341849 "2023-08-29T05:15:30Z")

</div>

Hi Team, Can you please confirm below query comes under SQL query or DSL query ? curl -X POST "https://localhost:9200/\_sql?format=txt&pretty" -H 'Content-Type: application/json' -d' { "query": "SELECT \* FROM custo…

---

## [Elasticsearch snapshot google.cloud.storage.StorageException](https://discuss.elastic.co/t/elasticsearch-snapshot-google-cloud-storage-storageexception/341848)

<div class="topic-metadata">

**Author:** [@navaneethan](https://discuss.elastic.co/u/navaneethan)\
**Replies:** 0\
**Last updated:** [August 29, 2023, 4:45am UTC](https://discuss.elastic.co/t/elasticsearch-snapshot-google-cloud-storage-storageexception/341848 "2023-08-29T04:45:52Z")

</div>

Elastic GCS bucket snapshot failed and we cannot able to retrive the old inremental backup in that bucket, Is there any possibility to recover the back FYI, we can able to view the data storage inside that bucket in th…

---

## [MY SQL database to Kibana directly](https://discuss.elastic.co/t/my-sql-database-to-kibana-directly/341831)

<div class="topic-metadata">

**Author:** [@Kumar\_Abhinav](https://discuss.elastic.co/u/Kumar_Abhinav)\
**Replies:** 6\
**Last updated:** [August 29, 2023, 3:12am UTC](https://discuss.elastic.co/t/my-sql-database-to-kibana-directly/341831 "2023-08-29T03:12:34Z")

</div>

Hello Elastic Community, I'm exploring the use of JDBC to connect Kibana(bypassing Elastic) directly to MySQL. This would help us overcome the challenge of joining data from different indices in Elasticsearch. I'd appre…

[Previous page](https://discuss.elastic.co/c/elastic-stack/81.md?page=437)

[Next page](https://discuss.elastic.co/c/elastic-stack/81.md?page=439)
