# Latest

**URL:** https://discuss.elastic.co/latest.md?page=387

[Latest](https://discuss.elastic.co/latest.md) · [Categories](https://discuss.elastic.co/categories.md) · [Tags](https://discuss.elastic.co/tags.md)

**Page:** 388

---

## [Semantic search - how to get correct results](https://discuss.elastic.co/t/semantic-search-how-to-get-correct-results/354269)

<div class="topic-metadata">

**Author:** [@neroo](https://discuss.elastic.co/u/neroo)\
**Replies:** 1\
**Last updated:** [February 28, 2024, 11:22am UTC](https://discuss.elastic.co/t/semantic-search-how-to-get-correct-results/354269 "2024-02-28T11:22:27Z")

</div>

Hi! I am using the michelin dataset from Getting Started with Elasticsearch | Elastic Videos and using semantic search following Semantic search | Elasticsearch Guide \[8.12\] | Elastic. For the cuisine field, I created a…

---

## [Elasticsearch doesn't start](https://discuss.elastic.co/t/elasticsearch-doesnt-start/354319)

<div class="topic-metadata">

**Author:** [@funny\_mackerel](https://discuss.elastic.co/u/funny_mackerel)\
**Replies:** 2\
**Last updated:** [February 28, 2024, 10:59am UTC](https://discuss.elastic.co/t/elasticsearch-doesnt-start/354319 "2024-02-28T10:59:58Z")

</div>

Hi. I have this weird problem. Every time I start bin/elasticsearch it prints Java usage output. I tried it on a newer version I downloaded and it does the same. It worked very well until some point and I can't remember…

---

## [Watcher : webhook action parsing error](https://discuss.elastic.co/t/watcher-webhook-action-parsing-error/354321)

<div class="topic-metadata">

**Author:** [@ramiwashere](https://discuss.elastic.co/u/ramiwashere)\
**Replies:** 0\
**Last updated:** [February 28, 2024, 10:27am UTC](https://discuss.elastic.co/t/watcher-webhook-action-parsing-error/354321 "2024-02-28T10:27:04Z")

</div>

Hi, I'm facing an error from watcher and the webhook action section: The watcher is working fine and send us via email the related information we need (ie count of error from an IP address and subcount of error rela…

---

## [How can we compare two indices in elasticsearch which are expected to be same?](https://discuss.elastic.co/t/how-can-we-compare-two-indices-in-elasticsearch-which-are-expected-to-be-same/354323)

<div class="topic-metadata">

**Author:** [@rampavandev](https://discuss.elastic.co/u/rampavandev)\
**Replies:** 0\
**Last updated:** [February 28, 2024, 10:38am UTC](https://discuss.elastic.co/t/how-can-we-compare-two-indices-in-elasticsearch-which-are-expected-to-be-same/354323 "2024-02-28T10:38:29Z")

</div>

I have a task which deals with comparing two indices on specific fields. I tried this query but I am not sure about the reliability of this query to compare? I have tried below query in Kibana. Please let me know if thi…

---

## [Generating short URL to hide filters](https://discuss.elastic.co/t/generating-short-url-to-hide-filters/354198)

<div class="topic-metadata">

**Author:** [@skouf](https://discuss.elastic.co/u/skouf)\
**Replies:** 1\
**Last updated:** [February 28, 2024, 10:38am UTC](https://discuss.elastic.co/t/generating-short-url-to-hide-filters/354198 "2024-02-28T10:38:23Z")

</div>

Hello We need to transform URL like this kibanaUrl/app/dashboards?auth\_provider\_hint=anonymous1#/view/7adfa750-4c81-11e8-b3d7-01146121b73d?embed=true&\_g=(filters:!(),refreshInterval:(pause:!f,value:0),time:(from:'${sel…

---

## [Is there a way we can have color coding in pie charts based on our requirements?](https://discuss.elastic.co/t/is-there-a-way-we-can-have-color-coding-in-pie-charts-based-on-our-requirements/354311)

<div class="topic-metadata">

**Author:** [@varshii](https://discuss.elastic.co/u/varshii)\
**Replies:** 2\
**Last updated:** [February 28, 2024, 9:33am UTC](https://discuss.elastic.co/t/is-there-a-way-we-can-have-color-coding-in-pie-charts-based-on-our-requirements/354311 "2024-02-28T09:33:00Z")

</div>

I need to change the color patterns used in the pie charts (ie to customize my own color pallet). Is this possible? If yes please let me know how!

---

## [Elasticsearch relevency search](https://discuss.elastic.co/t/elasticsearch-relevency-search/354274)

<div class="topic-metadata">

**Author:** [@Mohan\_T](https://discuss.elastic.co/u/Mohan_T)\
**Replies:** 2\
**Last updated:** [February 28, 2024, 3:48am UTC](https://discuss.elastic.co/t/elasticsearch-relevency-search/354274 "2024-02-28T03:48:52Z")

</div>

my search documents have the value of Doc 1 { "keyword\_values": "washbasin" } Doc 2 { "keyword\_values": "wash basin" } Doc 3 { "keyword\_values": "wash and basin" } Doc 4 { "keyword\_values": "wash …

---

## [Elastic Search Relavancy matching](https://discuss.elastic.co/t/elastic-search-relavancy-matching/354251)

<div class="topic-metadata">

**Author:** [@Mohandass](https://discuss.elastic.co/u/Mohandass)\
**Replies:** 1\
**Last updated:** [February 28, 2024, 8:56am UTC](https://discuss.elastic.co/t/elastic-search-relavancy-matching/354251 "2024-02-28T08:56:32Z")

</div>

I am having categories as below and respective products into those categories Basin Mixer Bath Shower Mixer Taps Automatic bib tap Basin Taps Washbasins CounterTop Basins When i search for washbasin OR wash basins, I …

---

## [Large number of Agent errors/missing data](https://discuss.elastic.co/t/large-number-of-agent-errors-missing-data/354124)

<div class="topic-metadata">

**Author:** [@gyterpena](https://discuss.elastic.co/u/gyterpena)\
**Replies:** 2\
**Last updated:** [February 28, 2024, 7:56am UTC](https://discuss.elastic.co/t/large-number-of-agent-errors-missing-data/354124 "2024-02-28T07:56:02Z")

</div>

Hello We have elastic agent with security policy(elastic defend) enabled and configured. When testing I can see that test file(EICAR) is detected by agent, but no alert shows in Kibana. I can see alert logged to syslog,…

---

## [Question about performance available with elastic cloud](https://discuss.elastic.co/t/question-about-performance-available-with-elastic-cloud/353988)

<div class="topic-metadata">

**Author:** [@skouf](https://discuss.elastic.co/u/skouf)\
**Replies:** 5\
**Last updated:** [February 28, 2024, 8:14am UTC](https://discuss.elastic.co/t/question-about-performance-available-with-elastic-cloud/353988 "2024-02-28T08:14:10Z")

</div>

Hello We are investigating the paid solutions with elasticsearch. We saw that the first option in the cloud is a 45 Gb storage, and only 1 Gb of RAM. Because we have some apps that have more than 1 million of docs (an…

---

## [PFsense Integration Issue](https://discuss.elastic.co/t/pfsense-integration-issue/354308)

<div class="topic-metadata">

**Author:** [@jaspreetjhans](https://discuss.elastic.co/u/jaspreetjhans)\
**Replies:** 0\
**Last updated:** [February 28, 2024, 8:03am UTC](https://discuss.elastic.co/t/pfsense-integration-issue/354308 "2024-02-28T08:03:35Z")

</div>

Hi After integration Pfsense , i am getting bellow error Provided Grok expressions do not match field value: \[\<134\>1 2024-02-28T09:58:56+02:00 OPNSense01.localdomain filterlog 90364 - \[meta sequenceId="1089"\] 56,,,fae5…

---

## [Can I get the data analysis range time?](https://discuss.elastic.co/t/can-i-get-the-data-analysis-range-time/354306)

<div class="topic-metadata">

**Author:** [@yuta.otsubo](https://discuss.elastic.co/u/yuta.otsubo)\
**Replies:** 0\
**Last updated:** [February 28, 2024, 7:50am UTC](https://discuss.elastic.co/t/can-i-get-the-data-analysis-range-time/354306 "2024-02-28T07:50:50Z")

</div>

I want to get the data analysis range time in kibana alert and use it for message setting. kibana version: 7.7.1 The monitor settings are as follows { "size": 0, "query": { "bool": { "filte…

---

## [Not able to start the Elasticsearch windows service in windows server 2016](https://discuss.elastic.co/t/not-able-to-start-the-elasticsearch-windows-service-in-windows-server-2016/354304)

<div class="topic-metadata">

**Author:** [@RSaha](https://discuss.elastic.co/u/RSaha)\
**Replies:** 0\
**Last updated:** [February 28, 2024, 7:22am UTC](https://discuss.elastic.co/t/not-able-to-start-the-elasticsearch-windows-service-in-windows-server-2016/354304 "2024-02-28T07:22:08Z")

</div>

Hi, We are using Elasticsearch 8.4. but when we tried to run the services we are getting the error. access denied. Can you please look into that and help us to fix the issue.

---

## [Parsing file containing sectional metadata and data](https://discuss.elastic.co/t/parsing-file-containing-sectional-metadata-and-data/354020)

<div class="topic-metadata">

**Author:** [@Diamond\_Mohanty](https://discuss.elastic.co/u/Diamond_Mohanty)\
**Replies:** 5\
**Last updated:** [February 28, 2024, 6:38am UTC](https://discuss.elastic.co/t/parsing-file-containing-sectional-metadata-and-data/354020 "2024-02-28T06:38:04Z")

</div>

I have a file with a structure where the actual events follow their meta. For example, the file has contents like below Columns = Name|Age|Gender Delimiter = | John|23|M Jane|25|F Columns = Country,State Delimiter…

---

## [Windows Server Integration to Elastic Search is failing elastic agent fleet enrollment is happening but elastic agent not starting and not sending data](https://discuss.elastic.co/t/windows-server-integration-to-elastic-search-is-failing-elastic-agent-fleet-enrollment-is-happening-but-elastic-agent-not-starting-and-not-sending-data/354239)

<div class="topic-metadata">

**Author:** [@nkreddyp](https://discuss.elastic.co/u/nkreddyp)\
**Replies:** 2\
**Last updated:** [February 28, 2024, 5:58am UTC](https://discuss.elastic.co/t/windows-server-integration-to-elastic-search-is-failing-elastic-agent-fleet-enrollment-is-happening-but-elastic-agent-not-starting-and-not-sending-data/354239 "2024-02-28T05:58:31Z")

</div>

please any one faces this kind of issue please help me i'm stuck almost from one month to integrate windows server due to this issue i have used selfsigned certificates for fleet server and Elasticsearch {"log.level":"i…

---

## [How to update elastic-agent API key?](https://discuss.elastic.co/t/how-to-update-elastic-agent-api-key/354293)

<div class="topic-metadata">

**Author:** [@Mang-Joo](https://discuss.elastic.co/u/Mang-Joo)\
**Replies:** 1\
**Last updated:** [February 28, 2024, 5:57am UTC](https://discuss.elastic.co/t/how-to-update-elastic-agent-api-key/354293 "2024-02-28T05:57:05Z")

</div>

hello. I want to unenroll and re-enroll an agent in fleet. Where can I update the API KEY? I want a way other than reinstalling.

---

## [AWS secrets for ECK](https://discuss.elastic.co/t/aws-secrets-for-eck/354294)

<div class="topic-metadata">

**Author:** [@Nau79](https://discuss.elastic.co/u/Nau79)\
**Replies:** 0\
**Last updated:** [February 28, 2024, 5:41am UTC](https://discuss.elastic.co/t/aws-secrets-for-eck/354294 "2024-02-28T05:41:31Z")

</div>

Hi All, I want to use aws secrets to store Kibana login credentials and pass them in the kibana deployment, has anyone done this before and any help is appreciated. apiVersion: kibana.k8s.elastic.co/v1 kind: Kibana met…

---

## [ElasticSearch output of Filebeat is empty, displays http error 400 Bad Request](https://discuss.elastic.co/t/elasticsearch-output-of-filebeat-is-empty-displays-http-error-400-bad-request/352407)

<div class="topic-metadata">

**Author:** [@NotTheRealV](https://discuss.elastic.co/u/NotTheRealV)\
**Replies:** 32\
**Last updated:** [February 28, 2024, 4:53am UTC](https://discuss.elastic.co/t/elasticsearch-output-of-filebeat-is-empty-displays-http-error-400-bad-request/352407 "2024-02-28T04:53:08Z")

</div>

So installed Elasticsearch (v8.12.0) for Windows as per the guide given here: Elasticsearch Installation Guide. I similarly, installed Kibana (v8.12.0) for Windows as per the guide given here: Kibana Installation Guide. …

---

## [Requesting help with Case-insensitive Analyzer](https://discuss.elastic.co/t/requesting-help-with-case-insensitive-analyzer/354273)

<div class="topic-metadata">

**Author:** [@mvkfg](https://discuss.elastic.co/u/mvkfg)\
**Replies:** 2\
**Last updated:** [February 28, 2024, 3:06am UTC](https://discuss.elastic.co/t/requesting-help-with-case-insensitive-analyzer/354273 "2024-02-28T03:06:51Z")

</div>

Hello, I have enabled a "lowercase" analyzer across all my indices, but I have run into an error while using it. My query parameter: "query": { "query\_string": { "query": "username.keyword:\\"Test\\"", "…

---

## [Custom name with Filebeat](https://discuss.elastic.co/t/custom-name-with-filebeat/354275)

<div class="topic-metadata">

**Author:** [@griffer98](https://discuss.elastic.co/u/griffer98)\
**Replies:** 4\
**Last updated:** [February 27, 2024, 10:30pm UTC](https://discuss.elastic.co/t/custom-name-with-filebeat/354275 "2024-02-27T22:30:22Z")

</div>

I am trying to send data from filebeat straight to elasticsearch. But no matter what I do I can't get the name to be what I want. I have tried everything the docs and all the forums are saying to do but nothing works. I …

---

## [We can use the scripted field to return a URL string and string field formatter to format that URL string into an hyper link when rendered. But what if I want to add the URL based on some conditions? For some fields I need the URL and for some not?](https://discuss.elastic.co/t/we-can-use-the-scripted-field-to-return-a-url-string-and-string-field-formatter-to-format-that-url-string-into-an-hyper-link-when-rendered-but-what-if-i-want-to-add-the-url-based-on-some-conditions-for-some-fields-i-need-the-url-and-for-some-not/354230)

<div class="topic-metadata">

**Author:** [@borahmridul](https://discuss.elastic.co/u/borahmridul)\
**Replies:** 1\
**Last updated:** [February 27, 2024, 9:47pm UTC](https://discuss.elastic.co/t/we-can-use-the-scripted-field-to-return-a-url-string-and-string-field-formatter-to-format-that-url-string-into-an-hyper-link-when-rendered-but-what-if-i-want-to-add-the-url-based-on-some-conditions-for-some-fields-i-need-the-url-and-for-some-not/354230 "2024-02-27T21:47:00Z")

</div>

Please help as it is on priority.

---

## [Sending data to new Data Stream with Elastic Agent](https://discuss.elastic.co/t/sending-data-to-new-data-stream-with-elastic-agent/353926)

<div class="topic-metadata">

**Author:** [@wrender1](https://discuss.elastic.co/u/wrender1)\
**Replies:** 19\
**Last updated:** [February 27, 2024, 8:09pm UTC](https://discuss.elastic.co/t/sending-data-to-new-data-stream-with-elastic-agent/353926 "2024-02-27T20:09:54Z")

</div>

Hi, We are trying to use a Standalone Elastic Agent on Kubernetes. Right now it is creating indexes for us, and sending all container logs to it. The indexes end up looking like: logs-kubernetes.container\_logs-cluster-…

---

## [Counting results by a value](https://discuss.elastic.co/t/counting-results-by-a-value/354256)

<div class="topic-metadata">

**Author:** [@user-27022024](https://discuss.elastic.co/u/user-27022024)\
**Replies:** 2\
**Last updated:** [February 27, 2024, 8:18pm UTC](https://discuss.elastic.co/t/counting-results-by-a-value/354256 "2024-02-27T20:18:10Z")

</div>

We store our load balancer logs in elasticsarch and use kibana for querying. In Kibana - Discover I can add a filter for IP address which will display the IP address from each request. But is it possible to just count e…

---

## [One-line log file](https://discuss.elastic.co/t/one-line-log-file/354060)

<div class="topic-metadata">

**Author:** [@Kamil2](https://discuss.elastic.co/u/Kamil2)\
**Replies:** 3\
**Last updated:** [February 27, 2024, 8:30pm UTC](https://discuss.elastic.co/t/one-line-log-file/354060 "2024-02-27T20:30:35Z")

</div>

Is it possible for filebeat to send the entire contents of the log file to index every specific time interval? I want to save the state of a specific process to a file, overwrite the file each time and not keep historica…

---

## [Log Threshold - Alert Body](https://discuss.elastic.co/t/log-threshold-alert-body/350979)

<div class="topic-metadata">

**Author:** [@erikg](https://discuss.elastic.co/u/erikg)\
**Replies:** 32\
**Last updated:** [February 27, 2024, 7:04pm UTC](https://discuss.elastic.co/t/log-threshold-alert-body/350979 "2024-02-27T19:04:19Z")

</div>

Hello, As referenced here: Action variables for a Logs threshold rule I created a log threshold rule. I would like to do is use variables/fields from the documents/logs to appear in the email body. Like how it was men…

---

## [How to setup a proxy in logstash using Windows?](https://discuss.elastic.co/t/how-to-setup-a-proxy-in-logstash-using-windows/354259)

<div class="topic-metadata">

**Author:** [@tcalvillo](https://discuss.elastic.co/u/tcalvillo)\
**Replies:** 0\
**Last updated:** [February 27, 2024, 5:08pm UTC](https://discuss.elastic.co/t/how-to-setup-a-proxy-in-logstash-using-windows/354259 "2024-02-27T17:08:50Z")

</div>

Hello Logstash team, I successfully installed and started Logstash on Windows server 2016. My issue is that I use a proxy and, when I try to see a list of plugins in bin using the below command: C:\\Logstash\\logstash-8.…

---

## [Elastic Defend integration: Is there a way to identify if an alert is caused due to prevention or detection?](https://discuss.elastic.co/t/elastic-defend-integration-is-there-a-way-to-identify-if-an-alert-is-caused-due-to-prevention-or-detection/354179)

<div class="topic-metadata">

**Author:** [@Krishna\_Teja](https://discuss.elastic.co/u/Krishna_Teja)\
**Replies:** 2\
**Last updated:** [February 27, 2024, 5:19pm UTC](https://discuss.elastic.co/t/elastic-defend-integration-is-there-a-way-to-identify-if-an-alert-is-caused-due-to-prevention-or-detection/354179 "2024-02-27T17:19:07Z")

</div>

Hi I'm using Endpoint Defend integration on a few agents. I want to know if an alert created was due to detection or prevention so I can trigger actions based on the status. Is there a way to identify the same? Also, c…

---

## [Curator forcemerge Exception](https://discuss.elastic.co/t/curator-forcemerge-exception/354245)

<div class="topic-metadata">

**Author:** [@Daniel314](https://discuss.elastic.co/u/Daniel314)\
**Replies:** 2\
**Last updated:** [February 27, 2024, 4:52pm UTC](https://discuss.elastic.co/t/curator-forcemerge-exception/354245 "2024-02-27T16:52:23Z")

</div>

Hi, I have an Elastic cluster running version 8.12.x with curator\_cli version 8.0.10. I recently had an odd timeout/connect issue with curator\_cli while it was doing a forcemerge (scheduled script -- not the focus of t…

---

## [Servicenow contains search](https://discuss.elastic.co/t/servicenow-contains-search/354222)

<div class="topic-metadata">

**Author:** [@brother\_info](https://discuss.elastic.co/u/brother_info)\
**Replies:** 1\
**Last updated:** [February 27, 2024, 3:58pm UTC](https://discuss.elastic.co/t/servicenow-contains-search/354222 "2024-02-27T15:58:12Z")

</div>

The servicenow catalog item in which the search item should be implemented with " conatins" logic I tried using user prefernce setting , but it will have a impact on all ctalogs , but i need a conatins logic only in one…

---

## [Reindex -API](https://discuss.elastic.co/t/reindex-api/354249)

<div class="topic-metadata">

**Author:** [@Gadapa\_Vasundhara](https://discuss.elastic.co/u/Gadapa_Vasundhara)\
**Replies:** 1\
**Last updated:** [February 27, 2024, 3:56pm UTC](https://discuss.elastic.co/t/reindex-api/354249 "2024-02-27T15:56:43Z")

</div>

Hi Team, Can i know reindex api, how much limit we can do for reindex size

[Previous page](https://discuss.elastic.co/latest.md?page=386)

[Next page](https://discuss.elastic.co/latest.md?page=388)
