# Latest

**URL:** https://discuss.elastic.co/latest.md?page=386

[Latest](https://discuss.elastic.co/latest.md) · [Categories](https://discuss.elastic.co/categories.md) · [Tags](https://discuss.elastic.co/tags.md)

**Page:** 387

---

## [Logstash-input-snmp-1.3.2 modify max\_repetitions](https://discuss.elastic.co/t/logstash-input-snmp-1-3-2-modify-max-repetitions/354392)

<div class="topic-metadata">

**Author:** [@KikeI](https://discuss.elastic.co/u/KikeI)\
**Replies:** 0\
**Last updated:** [February 28, 2024, 10:28pm UTC](https://discuss.elastic.co/t/logstash-input-snmp-1-3-2-modify-max-repetitions/354392 "2024-02-28T22:28:58Z")

</div>

Hi, I am migrating services from prometheus snmp\_exporter to logstash-input-snmp-1.3.2. In snmp\_exporter the value of max\_repetitions is default "25" and gives the option to modify it. In logstash-input-snmp-1.3.2 the d…

---

## [Aggregation Based Data Tables - Hide the Metric Column](https://discuss.elastic.co/t/aggregation-based-data-tables-hide-the-metric-column/354003)

<div class="topic-metadata">

**Author:** [@erikg](https://discuss.elastic.co/u/erikg)\
**Replies:** 4\
**Last updated:** [February 28, 2024, 9:59pm UTC](https://discuss.elastic.co/t/aggregation-based-data-tables-hide-the-metric-column/354003 "2024-02-28T21:59:30Z")

</div>

Hello, I am using aggregation based data table, instead of lens. My aggregation based table looks great but I want to hide the metric column. Is there a way to do this? Note: I don't want to use Lens because of in m…

---

## [Save search results as a file. Which is continually updated](https://discuss.elastic.co/t/save-search-results-as-a-file-which-is-continually-updated/354261)

<div class="topic-metadata">

**Author:** [@sharbich](https://discuss.elastic.co/u/sharbich)\
**Replies:** 8\
**Last updated:** [February 28, 2024, 8:16pm UTC](https://discuss.elastic.co/t/save-search-results-as-a-file-which-is-continually-updated/354261 "2024-02-28T20:16:13Z")

</div>

Hello, i capture logs from a Docker container according to the following pattern. routes: - multiline+logstash+tcp://logstash.intern.example.com:50000 env: - name: SYSLOG\_HOSTNAME value: homeassistant - name:…

---

## [Orchestrate Elastic SIEM for training labs](https://discuss.elastic.co/t/orchestrate-elastic-siem-for-training-labs/353607)

<div class="topic-metadata">

**Author:** [@lastshadow](https://discuss.elastic.co/u/lastshadow)\
**Replies:** 2\
**Last updated:** [February 28, 2024, 6:22pm UTC](https://discuss.elastic.co/t/orchestrate-elastic-siem-for-training-labs/353607 "2024-02-28T18:22:28Z")

</div>

I have a cybersecurity training program that I teach. Currently I teach it live and I use Elastic SIEM. I think it is a great product and not just because of the cost. I deploy Elastic on docker and have it running for t…

---

## [Dont see any logs in logstash-json.log](https://discuss.elastic.co/t/dont-see-any-logs-in-logstash-json-log/354377)

<div class="topic-metadata">

**Author:** [@Pooort](https://discuss.elastic.co/u/Pooort)\
**Replies:** 0\
**Last updated:** [February 28, 2024, 6:17pm UTC](https://discuss.elastic.co/t/dont-see-any-logs-in-logstash-json-log/354377 "2024-02-28T18:17:05Z")

</div>

My log4j2.properties setup: appender.rolling.type = RollingFile appender.rolling.name = plain\_rolling appender.rolling.fileName = ${sys:ls.logs}/logstash-plain.log appender.rolling.filePattern = ${sys:ls.logs}/logstash-…

---

## [How to see what logstash version a plugin version supports](https://discuss.elastic.co/t/how-to-see-what-logstash-version-a-plugin-version-supports/354362)

<div class="topic-metadata">

**Author:** [@tylersiemers](https://discuss.elastic.co/u/tylersiemers)\
**Replies:** 1\
**Last updated:** [February 28, 2024, 5:58pm UTC](https://discuss.elastic.co/t/how-to-see-what-logstash-version-a-plugin-version-supports/354362 "2024-02-28T17:58:07Z")

</div>

logstash 7.17.2 I am looking to update the logstash-integration-kafka logstash-integration-kafka (10.9.0) to a newer version that supports Kafka 3.X Where do I see in the README or docs what version logstash I need f…

---

## [java.lang.RuntimeException: unable to install test security manager running ES Tests](https://discuss.elastic.co/t/java-lang-runtimeexception-unable-to-install-test-security-manager-running-es-tests/354372)

<div class="topic-metadata">

**Author:** [@Steph\_van\_Schalkwyk](https://discuss.elastic.co/u/Steph_van_Schalkwyk)\
**Replies:** 0\
**Last updated:** [February 28, 2024, 4:31pm UTC](https://discuss.elastic.co/t/java-lang-runtimeexception-unable-to-install-test-security-manager-running-es-tests/354372 "2024-02-28T16:31:05Z")

</div>

Using Gradle 8.6. Any fix for this? Occurs when building Elasticsearch 8.x.y from the Github repo. Apparently not a bug. JDK 11, etc. etc. Caused by: java.lang.RuntimeException: unable to install test security manage…

---

## [I want to migrate an index from a cluster to another index in the another cluster but I get error](https://discuss.elastic.co/t/i-want-to-migrate-an-index-from-a-cluster-to-another-index-in-the-another-cluster-but-i-get-error/354314)

<div class="topic-metadata">

**Author:** [@Hatef\_Alipour](https://discuss.elastic.co/u/Hatef_Alipour)\
**Replies:** 9\
**Last updated:** [February 28, 2024, 4:11pm UTC](https://discuss.elastic.co/t/i-want-to-migrate-an-index-from-a-cluster-to-another-index-in-the-another-cluster-but-i-get-error/354314 "2024-02-28T16:11:46Z")

</div>

Hi, I want to migrate an index to another cluster. I can't use reindex because source IP is not whitelisted. also I can't use snapshot I decided to do this task by writing a logstash pipeline you can see my pipeline be…

---

## [Deleting Agent Permanently from Cosnole](https://discuss.elastic.co/t/deleting-agent-permanently-from-cosnole/354367)

<div class="topic-metadata">

**Author:** [@Nouman\_Ahmed](https://discuss.elastic.co/u/Nouman_Ahmed)\
**Replies:** 1\
**Last updated:** [February 28, 2024, 4:03pm UTC](https://discuss.elastic.co/t/deleting-agent-permanently-from-cosnole/354367 "2024-02-28T16:03:55Z")

</div>

How can i permanently delete agent from fleet? I can see its showing offline. I have uninstalled it by navigating to /usr/bin and running "./elastic-agent uninstall" command. How can i delete it so it no longer shows in…

---

## [In Elasticsearch client for .NET v8.x, how to check if SearchRequest object contains an index to target?](https://discuss.elastic.co/t/in-elasticsearch-client-for-net-v8-x-how-to-check-if-searchrequest-object-contains-an-index-to-target/354357)

<div class="topic-metadata">

**Author:** [@yansklyarenko](https://discuss.elastic.co/u/yansklyarenko)\
**Replies:** 0\
**Last updated:** [February 28, 2024, 3:03pm UTC](https://discuss.elastic.co/t/in-elasticsearch-client-for-net-v8-x-how-to-check-if-searchrequest-object-contains-an-index-to-target/354357 "2024-02-28T15:03:40Z")

</div>

When creating a SearchRequest object, there's an option to provide an index name. However, it is optional, and if not provided, a default index is taken, etc. In my code, I need to be absolutely sure the object is creat…

---

## [Shiiping audit logs for DB with no connector available in Integrations](https://discuss.elastic.co/t/shiiping-audit-logs-for-db-with-no-connector-available-in-integrations/354232)

<div class="topic-metadata">

**Author:** [@Nouman\_Ahmed](https://discuss.elastic.co/u/Nouman_Ahmed)\
**Replies:** 4\
**Last updated:** [February 28, 2024, 2:58pm UTC](https://discuss.elastic.co/t/shiiping-audit-logs-for-db-with-no-connector-available-in-integrations/354232 "2024-02-28T14:58:53Z")

</div>

I have question why there are no connectors available for DBs like mongoDB, SQLite etc to capture audit logs while they are availble for SQL server, mysql?? and if there is no connector avaible to capture audit logs of m…

---

## [Agents upgradeable or not](https://discuss.elastic.co/t/agents-upgradeable-or-not/354354)

<div class="topic-metadata">

**Author:** [@Balu](https://discuss.elastic.co/u/Balu)\
**Replies:** 0\
**Last updated:** [February 28, 2024, 2:34pm UTC](https://discuss.elastic.co/t/agents-upgradeable-or-not/354354 "2024-02-28T14:34:59Z")

</div>

Hello everyone, I have just upgraded my cluster to 8.12.2, now some of my agents are upgradeable, others (including the fleet server) are not. All of them are installed from tarballs and were able to be upgraded before…

---

## [Number of Elastic Agent requests sent to Azure Monitor API](https://discuss.elastic.co/t/number-of-elastic-agent-requests-sent-to-azure-monitor-api/354352)

<div class="topic-metadata">

**Author:** [@s.buksa](https://discuss.elastic.co/u/s.buksa)\
**Replies:** 0\
**Last updated:** [February 28, 2024, 1:50pm UTC](https://discuss.elastic.co/t/number-of-elastic-agent-requests-sent-to-azure-monitor-api/354352 "2024-02-28T13:50:39Z")

</div>

Hello, Could someone help me to understand how Elastic Agent performed API calls to Azure monitor for metrics ingestion is being calculated? The following snippet of configuration: period: 60s client\_id: xxxx client\_s…

---

## [Difference between KNN similarity and document score](https://discuss.elastic.co/t/difference-between-knn-similarity-and-document-score/354182)

<div class="topic-metadata">

**Author:** [@maorethians](https://discuss.elastic.co/u/maorethians)\
**Replies:** 1\
**Last updated:** [February 28, 2024, 1:40pm UTC](https://discuss.elastic.co/t/difference-between-knn-similarity-and-document-score/354182 "2024-02-28T13:40:20Z")

</div>

Assume we have some documents with a VECTOR field storing normalized vectors in it. this is the mapping we use for this field: { type: 'dense\_vector', similarity: 'dot\_product', index: true, } Now, we perform KNN…

---

## [App Search: Exact matching with Precision Tuning](https://discuss.elastic.co/t/app-search-exact-matching-with-precision-tuning/354350)

<div class="topic-metadata">

**Author:** [@StefanHeijden](https://discuss.elastic.co/u/StefanHeijden)\
**Replies:** 0\
**Last updated:** [February 28, 2024, 1:37pm UTC](https://discuss.elastic.co/t/app-search-exact-matching-with-precision-tuning/354350 "2024-02-28T13:37:42Z")

</div>

We are trying to tweak our search results using precision tuning. In the image we have set the precision tuning to 11. We we then search for parts of words, like "Koni" or "Konin" or even "Koningi", we find nothing. As e…

---

## [Cannot create map layer with GEOIP with KIBANA 8.12.1](https://discuss.elastic.co/t/cannot-create-map-layer-with-geoip-with-kibana-8-12-1/353996)

<div class="topic-metadata">

**Author:** [@jlbassereau](https://discuss.elastic.co/u/jlbassereau)\
**Replies:** 3\
**Last updated:** [February 28, 2024, 1:26pm UTC](https://discuss.elastic.co/t/cannot-create-map-layer-with-geoip-with-kibana-8-12-1/353996 "2024-02-28T13:26:55Z")

</div>

Hello, I´m trying to create a map from GEOIP coordinate retrieved from a log file. My workflow goes this way : logfile -\> filebeat -\> logstash -\> es That workflow worked as expected with ELK stack version 7 In versi…

---

## [Filebeat not loading one index in Kibana Dataview](https://discuss.elastic.co/t/filebeat-not-loading-one-index-in-kibana-dataview/354238)

<div class="topic-metadata">

**Author:** [@FileFile](https://discuss.elastic.co/u/FileFile)\
**Replies:** 3\
**Last updated:** [February 28, 2024, 1:22pm UTC](https://discuss.elastic.co/t/filebeat-not-loading-one-index-in-kibana-dataview/354238 "2024-02-28T13:22:00Z")

</div>

Hello I have the following Index and pipeline created from a csv { "mappings": { "\_meta": { "created\_by": "file-data-visualizer" }, "properties": { "@timestamp": { "type": "date" …

---

## [Mapping works in default index, but not in custom one](https://discuss.elastic.co/t/mapping-works-in-default-index-but-not-in-custom-one/354347)

<div class="topic-metadata">

**Author:** [@Multiply0057](https://discuss.elastic.co/u/Multiply0057)\
**Replies:** 0\
**Last updated:** [February 28, 2024, 1:21pm UTC](https://discuss.elastic.co/t/mapping-works-in-default-index-but-not-in-custom-one/354347 "2024-02-28T13:21:48Z")

</div>

Hello, fellow Elastic enthusiasts! Despite following the documentation and various online resources, I find myself at a standstill. Here's a brief overview of my setup: My Logstash pipeline is configured to output data…

---

## [Control is disabled although the field exist with a value (I can see it in discover)](https://discuss.elastic.co/t/control-is-disabled-although-the-field-exist-with-a-value-i-can-see-it-in-discover/352140)

<div class="topic-metadata">

**Author:** [@ShayWeizman](https://discuss.elastic.co/u/ShayWeizman)\
**Replies:** 4\
**Last updated:** [February 28, 2024, 1:07pm UTC](https://discuss.elastic.co/t/control-is-disabled-although-the-field-exist-with-a-value-i-can-see-it-in-discover/352140 "2024-02-28T13:07:15Z")

</div>

I'm using Version 7.17.3. I've added few controls and some of them are disabled: Please advise? Thanks, Shay

---

## [Reasonable size for max\_async\_search\_response\_size with 40% of docs - size 200kb - 700kb](https://discuss.elastic.co/t/reasonable-size-for-max-async-search-response-size-with-40-of-docs-size-200kb-700kb/354341)

<div class="topic-metadata">

**Author:** [@elk1985](https://discuss.elastic.co/u/elk1985)\
**Replies:** 0\
**Last updated:** [February 28, 2024, 12:37pm UTC](https://discuss.elastic.co/t/reasonable-size-for-max-async-search-response-size-with-40-of-docs-size-200kb-700kb/354341 "2024-02-28T12:37:43Z")

</div>

Hello. My cluster is growing. Lately I have done an analysis because of max\_async\_search\_response\_size error - that was making my searches imposible in some cases. Around 40% of my documents (not indexes) are size from…

---

## [Badly formatted index, after interpolation still contains placeholder](https://discuss.elastic.co/t/badly-formatted-index-after-interpolation-still-contains-placeholder/354231)

<div class="topic-metadata">

**Author:** [@Jirka\_Liska](https://discuss.elastic.co/u/Jirka_Liska)\
**Replies:** 2\
**Last updated:** [February 28, 2024, 12:38pm UTC](https://discuss.elastic.co/t/badly-formatted-index-after-interpolation-still-contains-placeholder/354231 "2024-02-28T12:38:17Z")

</div>

Hello, after migration to the 8.12.1 I've started getting error "Badly formatted index, after interpolation still contains placeholder". When I'm trying to process report with Filebeat. More interesting is I get this mes…

---

## [Export from Discovery to CSV](https://discuss.elastic.co/t/export-from-discovery-to-csv/353983)

<div class="topic-metadata">

**Author:** [@sourcreamnormanbates](https://discuss.elastic.co/u/sourcreamnormanbates)\
**Replies:** 4\
**Last updated:** [February 28, 2024, 12:38pm UTC](https://discuss.elastic.co/t/export-from-discovery-to-csv/353983 "2024-02-28T12:38:17Z")

</div>

I have an ESQL search that outputs a list of unique IP addresses. When I Share to CSV, I'm getting "CSV may contain formulas, The report contains characters which spreadsheet applications can interpret as formulas. Whe…

---

## [Force field type](https://discuss.elastic.co/t/force-field-type/354342)

<div class="topic-metadata">

**Author:** [@goncalobsantos](https://discuss.elastic.co/u/goncalobsantos)\
**Replies:** 0\
**Last updated:** [February 28, 2024, 12:38pm UTC](https://discuss.elastic.co/t/force-field-type/354342 "2024-02-28T12:38:02Z")

</div>

I'm using the SQL integration to get the rows in a table as documents in an index/datastream. The column phone\_number in the table is mapped to a field metrics.sql.phone\_number that is automatically assigned the type nu…

---

## [Duplicate session ID](https://discuss.elastic.co/t/duplicate-session-id/353877)

<div class="topic-metadata">

**Author:** [@Mbrezzy](https://discuss.elastic.co/u/Mbrezzy)\
**Replies:** 2\
**Last updated:** [February 28, 2024, 12:34pm UTC](https://discuss.elastic.co/t/duplicate-session-id/353877 "2024-02-28T12:34:42Z")

</div>

Hi everyone, I have configured Fortigate to send logs to Elasticsearch. However, when there's a long live session, Fortigate creates a duplicate session ID every 2 minutes and consistently adds data size to the previous …

---

## [Create snapshot on on-prem S3](https://discuss.elastic.co/t/create-snapshot-on-on-prem-s3/354336)

<div class="topic-metadata">

**Author:** [@Patryk\_Ostrowski](https://discuss.elastic.co/u/Patryk_Ostrowski)\
**Replies:** 4\
**Last updated:** [February 28, 2024, 12:20pm UTC](https://discuss.elastic.co/t/create-snapshot-on-on-prem-s3/354336 "2024-02-28T12:20:31Z")

</div>

Hello, I have problem with integration with snapshot. I have on-prem s3 and when I tried to create repository I have a error: Unknown s3 client name \[test\]. Existing client configs: default. PUT \_snapshot/my\_s3\_reposit…

---

## [\[ingest-pipeline\] remove field from target index](https://discuss.elastic.co/t/ingest-pipeline-remove-field-from-target-index/354113)

<div class="topic-metadata">

**Author:** [@seddikalaouiismaili](https://discuss.elastic.co/u/seddikalaouiismaili)\
**Replies:** 4\
**Last updated:** [February 28, 2024, 12:20pm UTC](https://discuss.elastic.co/t/ingest-pipeline-remove-field-from-target-index/354113 "2024-02-28T12:20:02Z")

</div>

Hi community, I'm trying delete some unused fields from index, through the ingest pipeline. Current config : "remove": { "if": "ctx.\_index.contains('stg-index-short-')", "field": "messa…

---

## [No implicit conversion of Pathname into String when logstash plugin installed](https://discuss.elastic.co/t/no-implicit-conversion-of-pathname-into-string-when-logstash-plugin-installed/354328)

<div class="topic-metadata">

**Author:** [@rindarapu](https://discuss.elastic.co/u/rindarapu)\
**Replies:** 0\
**Last updated:** [February 28, 2024, 11:04am UTC](https://discuss.elastic.co/t/no-implicit-conversion-of-pathname-into-string-when-logstash-plugin-installed/354328 "2024-02-28T11:04:15Z")

</div>

getting "no implicit conversion of Pathname into String" when installing offline plugin. Downloaded logstash 8.12.2 and installed logstash-output-mongodb plugin created offline pack and trying to install on the server…

---

## [Remove new lines when copy/pasting in Discover](https://discuss.elastic.co/t/remove-new-lines-when-copy-pasting-in-discover/354326)

<div class="topic-metadata">

**Author:** [@mch](https://discuss.elastic.co/u/mch)\
**Replies:** 1\
**Last updated:** [February 28, 2024, 11:46am UTC](https://discuss.elastic.co/t/remove-new-lines-when-copy-pasting-in-discover/354326 "2024-02-28T11:46:10Z")

</div>

Hello, I coming back on this subject since the last topic was automatically closed. There is still issues when copy/pasting the Discover's output. In the following example, there is 3 columns (@timestamp, host, report\_…

---

## [Cluster creation best practices](https://discuss.elastic.co/t/cluster-creation-best-practices/354333)

<div class="topic-metadata">

**Author:** [@kruzadmn](https://discuss.elastic.co/u/kruzadmn)\
**Replies:** 0\
**Last updated:** [February 28, 2024, 11:43am UTC](https://discuss.elastic.co/t/cluster-creation-best-practices/354333 "2024-02-28T11:43:08Z")

</div>

Hello everyone. I need to deploy an Elasticsearch cluster. To do this, I have a server in the data center with the following specifications that I need to maximize. CPU: 100 GHz RAM: 1.7 TB DISK: 15 TB SSD I can use …

---

## [Choose another indicator](https://discuss.elastic.co/t/choose-another-indicator/354252)

<div class="topic-metadata">

**Author:** [@FaycalH](https://discuss.elastic.co/u/FaycalH)\
**Replies:** 1\
**Last updated:** [February 28, 2024, 11:23am UTC](https://discuss.elastic.co/t/choose-another-indicator/354252 "2024-02-28T11:23:58Z")

</div>

I wanted to know if there is a way to choose a second bucket when there is no data in the first one, like an 'if the first bucket doesn't have data, then look in the second bucket and combine them to obtain a final set o…

[Previous page](https://discuss.elastic.co/latest.md?page=385)

[Next page](https://discuss.elastic.co/latest.md?page=387)
