# Latest

**URL:** https://discuss.elastic.co/latest.md?page=388

[Latest](https://discuss.elastic.co/latest.md) · [Categories](https://discuss.elastic.co/categories.md) · [Tags](https://discuss.elastic.co/tags.md)

**Page:** 389

---

## [Filtering nested lists using scripts](https://discuss.elastic.co/t/filtering-nested-lists-using-scripts/354248)

<div class="topic-metadata">

**Author:** [@oliver3](https://discuss.elastic.co/u/oliver3)\
**Replies:** 0\
**Last updated:** [February 27, 2024, 3:02pm UTC](https://discuss.elastic.co/t/filtering-nested-lists-using-scripts/354248 "2024-02-27T15:02:29Z")

</div>

Hi all, I have spent days trying to come up with a very specific query. Here is the challenge: I have an index that stores ecommerce products. One product has lots of variants, which store the variant's price. The pri…

---

## [Elastic agent fleet server stuck in "updating" in UI](https://discuss.elastic.co/t/elastic-agent-fleet-server-stuck-in-updating-in-ui/354237)

<div class="topic-metadata">

**Author:** [@Marcus\_Berglund](https://discuss.elastic.co/u/Marcus_Berglund)\
**Replies:** 0\
**Last updated:** [February 27, 2024, 2:00pm UTC](https://discuss.elastic.co/t/elastic-agent-fleet-server-stuck-in-updating-in-ui/354237 "2024-02-27T14:00:45Z")

</div>

Hi, When upgrading from 8.6.2 to 8.12.1 the fleet server agent is stuck at updating. Initially we missed the sha file, but that is fixed. Still no luck. The artifact repo is reachble and we are running on windows. we …

---

## [Pushed Configuration of Mysql and Apache](https://discuss.elastic.co/t/pushed-configuration-of-mysql-and-apache/354206)

<div class="topic-metadata">

**Author:** [@Nouman\_Ahmed](https://discuss.elastic.co/u/Nouman_Ahmed)\
**Replies:** 3\
**Last updated:** [February 27, 2024, 1:24pm UTC](https://discuss.elastic.co/t/pushed-configuration-of-mysql-and-apache/354206 "2024-02-27T13:24:28Z")

</div>

I have a query. When we install a an integration for a service, lets say mysql or Apache. When i use the integration for mysql then which file configuration for msql will be pushed on linux? I can see Elastci-agent.yml b…

---

## [Individual scores query](https://discuss.elastic.co/t/individual-scores-query/354225)

<div class="topic-metadata">

**Author:** [@Rui\_Goncalves](https://discuss.elastic.co/u/Rui_Goncalves)\
**Replies:** 1\
**Last updated:** [February 27, 2024, 1:21pm UTC](https://discuss.elastic.co/t/individual-scores-query/354225 "2024-02-27T13:21:54Z")

</div>

Hello, Our client needs a way to perform a query and extract the results containing not only the score per row, but also the individual scores of each search keyword. To be more precise, they are performing a query wit…

---

## [Search Application and App Search Query](https://discuss.elastic.co/t/search-application-and-app-search-query/354162)

<div class="topic-metadata">

**Author:** [@aisyaharifin](https://discuss.elastic.co/u/aisyaharifin)\
**Replies:** 1\
**Last updated:** [February 27, 2024, 1:08pm UTC](https://discuss.elastic.co/t/search-application-and-app-search-query/354162 "2024-02-27T13:08:44Z")

</div>

Hi Elastic team, I need confirmation if what I'm doing is the correct ways of implementing the Search. The use case is that I have an application site where I would like to embed Elastic Search in it. I'm using MSSQL …

---

## [Elastic Stack Agentless Installation](https://discuss.elastic.co/t/elastic-stack-agentless-installation/354218)

<div class="topic-metadata">

**Author:** [@spazzrabbit](https://discuss.elastic.co/u/spazzrabbit)\
**Replies:** 7\
**Last updated:** [February 27, 2024, 1:02pm UTC](https://discuss.elastic.co/t/elastic-stack-agentless-installation/354218 "2024-02-27T13:02:58Z")

</div>

Hello everyone ! Is there any way to monitor windows machines without agent/script on target machine ? ForExample: Tool/Script on logstash to login and read logs from the target machine via SSH etc. Then process in the…

---

## [I want to use lamda insead of logstash to send the logs from the local computer to the aws s3 using filebeat](https://discuss.elastic.co/t/i-want-to-use-lamda-insead-of-logstash-to-send-the-logs-from-the-local-computer-to-the-aws-s3-using-filebeat/354183)

<div class="topic-metadata">

**Author:** [@K\_Prem\_sivam\_reddy](https://discuss.elastic.co/u/K_Prem_sivam_reddy)\
**Replies:** 1\
**Last updated:** [February 27, 2024, 12:41pm UTC](https://discuss.elastic.co/t/i-want-to-use-lamda-insead-of-logstash-to-send-the-logs-from-the-local-computer-to-the-aws-s3-using-filebeat/354183 "2024-02-27T12:41:37Z")

</div>

i want to send the logs from the local to the aws s3 using the filebeat and aws s3 and i want to use the lamda , please assist me.

---

## [Request for Retry Limit Feature in Logstash OpenSearch Output Plugin](https://discuss.elastic.co/t/request-for-retry-limit-feature-in-logstash-opensearch-output-plugin/354195)

<div class="topic-metadata">

**Author:** [@nw-engineer](https://discuss.elastic.co/u/nw-engineer)\
**Replies:** 2\
**Last updated:** [February 27, 2024, 12:27pm UTC](https://discuss.elastic.co/t/request-for-retry-limit-feature-in-logstash-opensearch-output-plugin/354195 "2024-02-27T12:27:20Z")

</div>

Dear LogstashTeam, I hope this message finds you well. I am currently using Logstash version 8.4.3 with OpenSearch and have come across a behavior in the OpenSearch output plugin that I believe could be improved for bet…

---

## [CVE-2014-9152 on Unsafe.dll dependency with Elastic Search](https://discuss.elastic.co/t/cve-2014-9152-on-unsafe-dll-dependency-with-elastic-search/354219)

<div class="topic-metadata">

**Author:** [@silo](https://discuss.elastic.co/u/silo)\
**Replies:** 0\
**Last updated:** [February 27, 2024, 11:04am UTC](https://discuss.elastic.co/t/cve-2014-9152-on-unsafe-dll-dependency-with-elastic-search/354219 "2024-02-27T11:04:11Z")

</div>

https://nvd.nist.gov/vuln/detail/CVE-2014-9152 Hi, I have performed recent dependency scan and found the above CVE vulnerability is detected. As i am using Elastic Search .net dll in my project and this has indirect dep…

---

## [How to send syslog logs to google chronicle using logstash?](https://discuss.elastic.co/t/how-to-send-syslog-logs-to-google-chronicle-using-logstash/354216)

<div class="topic-metadata">

**Author:** [@harry24](https://discuss.elastic.co/u/harry24)\
**Replies:** 0\
**Last updated:** [February 27, 2024, 10:52am UTC](https://discuss.elastic.co/t/how-to-send-syslog-logs-to-google-chronicle-using-logstash/354216 "2024-02-27T10:52:03Z")

</div>

Iam want to send the encrypted logs which are coming from syslog server. Need to collect those logs and filter out the logs and send one copy to elasticsearch and one copy to google chronicle using logstash plugin with T…

---

## [Elastic web crawler limitations with platinum license](https://discuss.elastic.co/t/elastic-web-crawler-limitations-with-platinum-license/354213)

<div class="topic-metadata">

**Author:** [@sravank](https://discuss.elastic.co/u/sravank)\
**Replies:** 0\
**Last updated:** [February 27, 2024, 10:21am UTC](https://discuss.elastic.co/t/elastic-web-crawler-limitations-with-platinum-license/354213 "2024-02-27T10:21:37Z")

</div>

Hi team, We are about to purchase the platinum license use the Web Crawl functionality. Can anyone please help me understand on bellow queries. Limitation on adding domains (or number of webpages per domain) collecti…

---

## [Kafka output. How to set a key from message value?](https://discuss.elastic.co/t/kafka-output-how-to-set-a-key-from-message-value/353185)

<div class="topic-metadata">

**Author:** [@Pooort](https://discuss.elastic.co/u/Pooort)\
**Replies:** 1\
**Last updated:** [February 27, 2024, 10:14am UTC](https://discuss.elastic.co/t/kafka-output-how-to-set-a-key-from-message-value/353185 "2024-02-27T10:14:40Z")

</div>

I'm using logstash to ingest data from Redshift table and put into Kafka. It works great. But how to use input field as Kafka's key?

---

## [File Beat to Elasticsearch unable to publish Events](https://discuss.elastic.co/t/file-beat-to-elasticsearch-unable-to-publish-events/354092)

<div class="topic-metadata">

**Author:** [@Mani\_Manikanta](https://discuss.elastic.co/u/Mani_Manikanta)\
**Replies:** 7\
**Last updated:** [February 27, 2024, 10:11am UTC](https://discuss.elastic.co/t/file-beat-to-elasticsearch-unable-to-publish-events/354092 "2024-02-27T10:11:34Z")

</div>

Hi Team, Why I am Getting the below Error 2024-02-26T14:40:53.019+0700 ERROR \[elasticsearch\] elasticsearch/client.go:226 failed to perform any bulk index operations: Post "https://x.x.x.x:9200/\_bulk": net/http…

---

## [How to find all SIEM rules where field "timestampOverride" is not equal to "event.ingested"?](https://discuss.elastic.co/t/how-to-find-all-siem-rules-where-field-timestampoverride-is-not-equal-to-event-ingested/352383)

<div class="topic-metadata">

**Author:** [@dsv](https://discuss.elastic.co/u/dsv)\
**Replies:** 1\
**Last updated:** [February 27, 2024, 10:10am UTC](https://discuss.elastic.co/t/how-to-find-all-siem-rules-where-field-timestampoverride-is-not-equal-to-event-ingested/352383 "2024-02-27T10:10:33Z")

</div>

Hey everyone 8.12.0 Trying to find SIEM detection rules where field "timestampOverride" is not equal to "event.ingested" GET kbn:/api/alerting/rules/\_find?search\_fields=params.timestampOverride&search=event.ingested …

---

## [Unable to setup kafka with metricbeat](https://discuss.elastic.co/t/unable-to-setup-kafka-with-metricbeat/354210)

<div class="topic-metadata">

**Author:** [@kriti\_dabas](https://discuss.elastic.co/u/kriti_dabas)\
**Replies:** 0\
**Last updated:** [February 27, 2024, 10:02am UTC](https://discuss.elastic.co/t/unable-to-setup-kafka-with-metricbeat/354210 "2024-02-27T10:02:03Z")

</div>

metricbeat.yml path: ${path.config}/modules.d/\*.yml reload.enabled: true setup.kibana: host: "https://#.#.#.#:443" protocol: "https" ssl.verification\_mode: none output.elasticsearch: hosts: \["https://ec1:9200","ht…

---

## [Want to display tot average count of whole data present in column at the end of each columns in visualization](https://discuss.elastic.co/t/want-to-display-tot-average-count-of-whole-data-present-in-column-at-the-end-of-each-columns-in-visualization/354205)

<div class="topic-metadata">

**Author:** [@2328943\_dc](https://discuss.elastic.co/u/2328943_dc)\
**Replies:** 0\
**Last updated:** [February 27, 2024, 9:53am UTC](https://discuss.elastic.co/t/want-to-display-tot-average-count-of-whole-data-present-in-column-at-the-end-of-each-columns-in-visualization/354205 "2024-02-27T09:53:22Z")

</div>

Hi, we have created one visualization \[in rows dates are added and columns represents hours wise data \] as attached in screenshot but we want to show column-wise average count at the below of each columns at the place o…

---

## [Finding documents with message field exceeding 1 mln characters](https://discuss.elastic.co/t/finding-documents-with-message-field-exceeding-1-mln-characters/353788)

<div class="topic-metadata">

**Author:** [@elk1985](https://discuss.elastic.co/u/elk1985)\
**Replies:** 4\
**Last updated:** [February 27, 2024, 8:47am UTC](https://discuss.elastic.co/t/finding-documents-with-message-field-exceeding-1-mln-characters/353788 "2024-02-27T08:47:17Z")

</div>

Hello. I'm getting error regarding exceeded message field length (over 1 mln characters). I want to identify them. I found a script in painless language: GET /your\_index/\_search { "query": { "bool": { "mu…

---

## [Unable to run elasticsearch rally in docker](https://discuss.elastic.co/t/unable-to-run-elasticsearch-rally-in-docker/354174)

<div class="topic-metadata">

**Author:** [@uttamkrpanda](https://discuss.elastic.co/u/uttamkrpanda)\
**Replies:** 1\
**Last updated:** [February 27, 2024, 8:16am UTC](https://discuss.elastic.co/t/unable-to-run-elasticsearch-rally-in-docker/354174 "2024-02-27T08:16:30Z")

</div>

I am unable to run elasticsearch rally with docker its getting "No such file or directory" error . How can i fix this ? docker run elastic/rally race --track=nyc\_taxis --test-mode --pipeline=benchmark-only --target-hos…

---

## [CSV export in discover without . keyword fields](https://discuss.elastic.co/t/csv-export-in-discover-without-keyword-fields/354173)

<div class="topic-metadata">

**Author:** [@sai7276p](https://discuss.elastic.co/u/sai7276p)\
**Replies:** 1\
**Last updated:** [February 27, 2024, 7:40am UTC](https://discuss.elastic.co/t/csv-export-in-discover-without-keyword-fields/354173 "2024-02-27T07:40:32Z")

</div>

Hello, I am using 8.11x stack in my cluster and I want to extract CSV export in discover without .keyword fields. Is there any way to do this? other than selecting available fields from left side of discover page or dat…

---

## [How to get Percentage from count of records](https://discuss.elastic.co/t/how-to-get-percentage-from-count-of-records/353902)

<div class="topic-metadata">

**Author:** [@yuswanul](https://discuss.elastic.co/u/yuswanul)\
**Replies:** 5\
**Last updated:** [February 27, 2024, 6:57am UTC](https://discuss.elastic.co/t/how-to-get-percentage-from-count-of-records/353902 "2024-02-27T06:57:00Z")

</div>

Hi there, I'm using Elastic and kibana v7.17, and I want to get the percentage from each term in my table. look at this picture below as you can see there are many counts of records of each term on the right side, ho…

---

## [Okta certificate revokation](https://discuss.elastic.co/t/okta-certificate-revokation/354177)

<div class="topic-metadata">

**Author:** [@ursyathi](https://discuss.elastic.co/u/ursyathi)\
**Replies:** 0\
**Last updated:** [February 27, 2024, 6:33am UTC](https://discuss.elastic.co/t/okta-certificate-revokation/354177 "2024-02-27T06:33:49Z")

</div>

I am using Okta for SAML sign-on. I need to change the default self-signed certificate of Okta and use a certificate signed by third party. I need this because I need to revoke Okta certificate and check the OCSP flow in…

---

## [Correlation Query for spam email - not working](https://discuss.elastic.co/t/correlation-query-for-spam-email-not-working/354175)

<div class="topic-metadata">

**Author:** [@hamidijaz](https://discuss.elastic.co/u/hamidijaz)\
**Replies:** 0\
**Last updated:** [February 27, 2024, 4:55am UTC](https://discuss.elastic.co/t/correlation-query-for-spam-email-not-working/354175 "2024-02-27T04:55:55Z")

</div>

Hi, I have created a correlation rule with the following query, that runs every 5 mins. This is to detect if any external email address sends multiple emails to our internal email within given time (an hour), then it sh…

---

## [Windows Elastic-Agent Group Deployment](https://discuss.elastic.co/t/windows-elastic-agent-group-deployment/354149)

<div class="topic-metadata">

**Author:** [@Patrick.kirk](https://discuss.elastic.co/u/Patrick.kirk)\
**Replies:** 1\
**Last updated:** [February 26, 2024, 10:18pm UTC](https://discuss.elastic.co/t/windows-elastic-agent-group-deployment/354149 "2024-02-26T22:18:13Z")

</div>

I’m looking at doing a mass deployment of the windows elastic agent (1000+ workstations) and looking for a “best or recommend” way. I have not seen an MSI for the agent. What are the recommendations for this?

---

## [Lab mentions to add the path --certificate-authorities=/home/elastic/certs/ca/ca.crt. But doesn't say where to add. Or maybe I missed something](https://discuss.elastic.co/t/lab-mentions-to-add-the-path-certificate-authorities-home-elastic-certs-ca-ca-crt-but-doesnt-say-where-to-add-or-maybe-i-missed-something/354151)

<div class="topic-metadata">

**Author:** [@ericatwood](https://discuss.elastic.co/u/ericatwood)\
**Replies:** 0\
**Last updated:** [February 26, 2024, 9:41pm UTC](https://discuss.elastic.co/t/lab-mentions-to-add-the-path-certificate-authorities-home-elastic-certs-ca-ca-crt-but-doesnt-say-where-to-add-or-maybe-i-missed-something/354151 "2024-02-26T21:41:30Z")

</div>

!\[image|690x286\](upload://fDHjrY46od2qYIcWn7yTf2VEtIt.png

---

## [Logs dont' show up when trying to use filter](https://discuss.elastic.co/t/logs-dont-show-up-when-trying-to-use-filter/354120)

<div class="topic-metadata">

**Author:** [@haktoggle](https://discuss.elastic.co/u/haktoggle)\
**Replies:** 3\
**Last updated:** [February 26, 2024, 8:47pm UTC](https://discuss.elastic.co/t/logs-dont-show-up-when-trying-to-use-filter/354120 "2024-02-26T20:47:24Z")

</div>

Hi, I'm attempting to utilize the filter with the accessible logs that are displayed on one of my dashboards; however, those available logs do not appear when using a filter. For example, the logs are displaying, and I…

---

## [Error about schema casting when updating documents attributes different than the error ones](https://discuss.elastic.co/t/error-about-schema-casting-when-updating-documents-attributes-different-than-the-error-ones/354142)

<div class="topic-metadata">

**Author:** [@alexandervcc](https://discuss.elastic.co/u/alexandervcc)\
**Replies:** 0\
**Last updated:** [February 26, 2024, 5:44pm UTC](https://discuss.elastic.co/t/error-about-schema-casting-when-updating-documents-attributes-different-than-the-error-ones/354142 "2024-02-26T17:44:33Z")

</div>

Hello, I got some issue with elastic. I have a request which updates docs on elastics. this looks like: POST /index/\_update\_by\_query { "query":{ "match":{ "load": "sync" } }, …

---

## [How To Fix : code 429 - circuit\_breaking\_exception - Data too large, data for \[indices:data/write/bulk\[s\]\]](https://discuss.elastic.co/t/how-to-fix-code-429-circuit-breaking-exception-data-too-large-data-for-indices-data-write-bulk-s/354138)

<div class="topic-metadata">

**Author:** [@Leo\_K](https://discuss.elastic.co/u/Leo_K)\
**Replies:** 0\
**Last updated:** [February 26, 2024, 4:37pm UTC](https://discuss.elastic.co/t/how-to-fix-code-429-circuit-breaking-exception-data-too-large-data-for-indices-data-write-bulk-s/354138 "2024-02-26T16:37:23Z")

</div>

Hello everyone, Configuration : Elastic Cloud - ES 8.11 I've been benchmarking Elastic for the past days and had multiple errors coming up and I couldn't find a viable answer on the most annoying one : { \_index: 'MY\_I…

---

## [Network Maps with Packetbeat- Using Graphs?](https://discuss.elastic.co/t/network-maps-with-packetbeat-using-graphs/353993)

<div class="topic-metadata">

**Author:** [@erikg](https://discuss.elastic.co/u/erikg)\
**Replies:** 2\
**Last updated:** [February 26, 2024, 4:25pm UTC](https://discuss.elastic.co/t/network-maps-with-packetbeat-using-graphs/353993 "2024-02-26T16:25:49Z")

</div>

Hello, I am new to using Graphs. I was wondering with Packetbeat/Network Packet Capture integration, if it was possible to create a graph or topology of the traffic between source.ip and destination.ip . If graphs can h…

---

## [Elastic Cloud - Datadog Integration - Failing](https://discuss.elastic.co/t/elastic-cloud-datadog-integration-failing/354100)

<div class="topic-metadata">

**Author:** [@csr1](https://discuss.elastic.co/u/csr1)\
**Replies:** 4\
**Last updated:** [February 26, 2024, 4:23pm UTC](https://discuss.elastic.co/t/elastic-cloud-datadog-integration-failing/354100 "2024-02-26T16:23:18Z")

</div>

I am trying to integrate Datadog with Elastic Cloud for monitoring the deployments. But I am getting the below error when following the instructions. Any suggestions: Error: Your Elastic Cloud credentials are not auth…

---

## [Kibana URL uses a Single host to serve all request](https://discuss.elastic.co/t/kibana-url-uses-a-single-host-to-serve-all-request/353003)

<div class="topic-metadata">

**Author:** [@upadhyayaaman](https://discuss.elastic.co/u/upadhyayaaman)\
**Replies:** 3\
**Last updated:** [February 26, 2024, 4:17pm UTC](https://discuss.elastic.co/t/kibana-url-uses-a-single-host-to-serve-all-request/353003 "2024-02-26T16:17:09Z")

</div>

Hi All, We have 3 nodes in the cluster with 1 primary and 2 replicas. For DR activities we perform below steps : We are setting number of replica to 1 and then Exclude 1st node from cluster in single DC , while other…

[Previous page](https://discuss.elastic.co/latest.md?page=387)

[Next page](https://discuss.elastic.co/latest.md?page=389)
