# Latest

**URL:** https://discuss.elastic.co/latest.md?page=404

[Latest](https://discuss.elastic.co/latest.md) · [Categories](https://discuss.elastic.co/categories.md) · [Tags](https://discuss.elastic.co/tags.md)

**Page:** 405

---

## [New to Kibana: How to Remove Lingering Active Alerts? (Rules Deleted)](https://discuss.elastic.co/t/new-to-kibana-how-to-remove-lingering-active-alerts-rules-deleted/353072)

<div class="topic-metadata">

**Author:** [@skumarsingh](https://discuss.elastic.co/u/skumarsingh)\
**Replies:** 1\
**Last updated:** [February 12, 2024, 1:52pm UTC](https://discuss.elastic.co/t/new-to-kibana-how-to-remove-lingering-active-alerts-rules-deleted/353072 "2024-02-12T13:52:24Z")

</div>

Hi everyone, I'm relatively new to Kibana and I'm encountering some persistent active alerts that I'd like to remove. I've already deleted the rules associated with these alerts, but they're still showing up under "Acti…

---

## [Shape mapping, only return certain type(s) on a query](https://discuss.elastic.co/t/shape-mapping-only-return-certain-type-s-on-a-query/352552)

<div class="topic-metadata">

**Author:** [@paul5](https://discuss.elastic.co/u/paul5)\
**Replies:** 8\
**Last updated:** [February 12, 2024, 1:23pm UTC](https://discuss.elastic.co/t/shape-mapping-only-return-certain-type-s-on-a-query/352552 "2024-02-12T13:23:39Z")

</div>

I don't see a way for a query on mapping type shape to only return certain shapes. Something like this: POST /example/\_doc { "location" : { "type" : "point", "coordinates" : \[-377.03653, 389.897676\] }, "ret…

---

## [Update security certificates with a different CA](https://discuss.elastic.co/t/update-security-certificates-with-a-different-ca/352766)

<div class="topic-metadata">

**Author:** [@amitjadhav0384](https://discuss.elastic.co/u/amitjadhav0384)\
**Replies:** 5\
**Last updated:** [February 12, 2024, 1:00pm UTC](https://discuss.elastic.co/t/update-security-certificates-with-a-different-ca/352766 "2024-02-12T13:00:53Z")

</div>

I am trying to update new CA which are signed using trusted source given by our organization. ./bin/elasticsearch-certutil cert --ca-cert ca/ca.crt --ca-key ca/ca.key While trying to create new certificate using the ab…

---

## [Fully custom sparse search](https://discuss.elastic.co/t/fully-custom-sparse-search/353070)

<div class="topic-metadata">

**Author:** [@mwon](https://discuss.elastic.co/u/mwon)\
**Replies:** 0\
**Last updated:** [February 12, 2024, 12:57pm UTC](https://discuss.elastic.co/t/fully-custom-sparse-search/353070 "2024-02-12T12:57:27Z")

</div>

Hi! I want to try to create an index, where for each document it will index directly the document's tokens and respective score. Then, at query time, I want to multiply each query token score with the correspond token i…

---

## [Alerts to ServiceNow Generic Pipeline](https://discuss.elastic.co/t/alerts-to-servicenow-generic-pipeline/352631)

<div class="topic-metadata">

**Author:** [@sajmeister](https://discuss.elastic.co/u/sajmeister)\
**Replies:** 4\
**Last updated:** [February 12, 2024, 12:50pm UTC](https://discuss.elastic.co/t/alerts-to-servicenow-generic-pipeline/352631 "2024-02-12T12:50:48Z")

</div>

Hi, We use the free edition of Elasticsearch and don't use watchers. Would like to know is there a generic pipeline code that can be used to send alerts to ServiceNow ? If yes, please provide code so can test it. Che…

---

## [Help with using dynamic template](https://discuss.elastic.co/t/help-with-using-dynamic-template/353054)

<div class="topic-metadata">

**Author:** [@Sharath\_G](https://discuss.elastic.co/u/Sharath_G)\
**Replies:** 2\
**Last updated:** [February 12, 2024, 12:38pm UTC](https://discuss.elastic.co/t/help-with-using-dynamic-template/353054 "2024-02-12T12:38:22Z")

</div>

I get the following error when using dynamic\_templates, I'd like to map the fields with k8s.\* as text and nested object field "network" as a flat\_object. I've tried using both regex and path\_match but get the same error…

---

## [Elasticsearch Enterprise On-Prem Licensing details](https://discuss.elastic.co/t/elasticsearch-enterprise-on-prem-licensing-details/353057)

<div class="topic-metadata">

**Author:** [@Rehmat](https://discuss.elastic.co/u/Rehmat)\
**Replies:** 4\
**Last updated:** [February 12, 2024, 12:23pm UTC](https://discuss.elastic.co/t/elasticsearch-enterprise-on-prem-licensing-details/353057 "2024-02-12T12:23:56Z")

</div>

Hi Everyone, can someone share some detail about Elasticsearch Enterprise License On-Prem, will allow how many nodes, cluster, storage capacity per bare-metal node/vm, CPU/RAM ? thanks in advance

---

## [Kibana for open mobility data in Berlin](https://discuss.elastic.co/t/kibana-for-open-mobility-data-in-berlin/353056)

<div class="topic-metadata">

**Author:** [@CargoBikoMeter](https://discuss.elastic.co/u/CargoBikoMeter)\
**Replies:** 0\
**Last updated:** [February 12, 2024, 11:12am UTC](https://discuss.elastic.co/t/kibana-for-open-mobility-data-in-berlin/353056 "2024-02-12T11:12:42Z")

</div>

In Berlin we have setup a Kibana based dashboard for open mobility data, which are based on data from Telraam devices. We have setup a system which reads the data via Telraam-API and provides these data as CSV files. The…

---

## [I am having this pipeline problem while integrating Wazuh with ELK](https://discuss.elastic.co/t/i-am-having-this-pipeline-problem-while-integrating-wazuh-with-elk/353034)

<div class="topic-metadata">

**Author:** [@fahim2024](https://discuss.elastic.co/u/fahim2024)\
**Replies:** 3\
**Last updated:** [February 12, 2024, 10:14am UTC](https://discuss.elastic.co/t/i-am-having-this-pipeline-problem-while-integrating-wazuh-with-elk/353034 "2024-02-12T10:14:10Z")

</div>

What can I do ?

---

## [Ansible Tower Integration (AWX) with APM ](https://discuss.elastic.co/t/ansible-tower-integration-awx-with-apm/352890)

<div class="topic-metadata">

**Author:** [@danyseve](https://discuss.elastic.co/u/danyseve)\
**Replies:** 1\
**Last updated:** [February 12, 2024, 10:10am UTC](https://discuss.elastic.co/t/ansible-tower-integration-awx-with-apm/352890 "2024-02-12T10:10:27Z")

</div>

Good afternoon. I wanted to know if anyone has been able to implement AWX ansible monitoring using elasticsearch APM. I am currently running Elastic 8.12 with APM-server, on the other hand AWX 23.5.1 needs to be monito…

---

## [Add integration for Gitlab monitoring](https://discuss.elastic.co/t/add-integration-for-gitlab-monitoring/353038)

<div class="topic-metadata">

**Author:** [@Alphayeeeet](https://discuss.elastic.co/u/Alphayeeeet)\
**Replies:** 2\
**Last updated:** [February 12, 2024, 9:48am UTC](https://discuss.elastic.co/t/add-integration-for-gitlab-monitoring/353038 "2024-02-12T09:48:23Z")

</div>

We have our own on-premise Gitlab server, which we want to monitor using Elastic Stack. We are currently using Fleet-managed Elastic Agent to ship data from our different systems. As stated out above, we now want to ing…

---

## [Filebeat causing a very large iowait and lagging after uncontrolled reboot](https://discuss.elastic.co/t/filebeat-causing-a-very-large-iowait-and-lagging-after-uncontrolled-reboot/351981)

<div class="topic-metadata">

**Author:** [@emmanuel\_t](https://discuss.elastic.co/u/emmanuel_t)\
**Replies:** 1\
**Last updated:** [February 12, 2024, 9:12am UTC](https://discuss.elastic.co/t/filebeat-causing-a-very-large-iowait-and-lagging-after-uncontrolled-reboot/351981 "2024-02-12T09:12:57Z")

</div>

Hello, we have now for the second time had an issue of filebeat not reacting well to an uncontrolled reboot on production. It causes a large iowait on the server and lags considerably sending logs to the elasticsearch b…

---

## [Elasticsearch http.host default value](https://discuss.elastic.co/t/elasticsearch-http-host-default-value/351384)

<div class="topic-metadata">

**Author:** [@ilya-popkov](https://discuss.elastic.co/u/ilya-popkov)\
**Replies:** 4\
**Last updated:** [February 12, 2024, 9:19am UTC](https://discuss.elastic.co/t/elasticsearch-http-host-default-value/351384 "2024-02-12T09:19:35Z")

</div>

In the elasticsearch version 8.12 docs says "network.host default value is localhost and http.host value defaults is address given by network.host". But for default in fresh new elasticsearch http.host is equal 0.0.0.0 w…

---

## [Elasticsearch-setup-passwords auto -url "http://localhost:9200" i want to run this command but getting error](https://discuss.elastic.co/t/elasticsearch-setup-passwords-auto-url-http-localhost-9200-i-want-to-run-this-command-but-getting-error/352920)

<div class="topic-metadata">

**Author:** [@Karan37](https://discuss.elastic.co/u/Karan37)\
**Replies:** 2\
**Last updated:** [February 12, 2024, 9:07am UTC](https://discuss.elastic.co/t/elasticsearch-setup-passwords-auto-url-http-localhost-9200-i-want-to-run-this-command-but-getting-error/352920 "2024-02-12T09:07:51Z")

</div>

while running this command in the elasticsearch bin folder cli elasticsearch-setup-passwords auto -url "http://localhost:9200" it is giving this error Failed to authenticate user 'elastic' against http://localhost:920…

---

## [Boost results that starts with exact query](https://discuss.elastic.co/t/boost-results-that-starts-with-exact-query/352959)

<div class="topic-metadata">

**Author:** [@MMkMkMk](https://discuss.elastic.co/u/MMkMkMk)\
**Replies:** 2\
**Last updated:** [February 12, 2024, 8:57am UTC](https://discuss.elastic.co/t/boost-results-that-starts-with-exact-query/352959 "2024-02-12T08:57:17Z")

</div>

Hello, I'm trying to have a full-text query that boost results that starts with the entered query. For instance i have 2 book titles: "Viva Harry Potter" and "Harry Potter and the whatever stone". If the user search fo…

---

## [Log Shipping and Access Issues in Application Pod using filebeat](https://discuss.elastic.co/t/log-shipping-and-access-issues-in-application-pod-using-filebeat/353043)

<div class="topic-metadata">

**Author:** [@Arsalan\_Muhammad](https://discuss.elastic.co/u/Arsalan_Muhammad)\
**Replies:** 0\
**Last updated:** [February 12, 2024, 8:41am UTC](https://discuss.elastic.co/t/log-shipping-and-access-issues-in-application-pod-using-filebeat/353043 "2024-02-12T08:41:45Z")

</div>

I'm encountering difficulties shipping logs from my application pod, which is operational within the abc namespace, to the Elasticsearch cluster. Despite my efforts, I haven't been successful in resolving this issue. Cou…

---

## [How to use minimum\_should\_match for prefix search?](https://discuss.elastic.co/t/how-to-use-minimum-should-match-for-prefix-search/352363)

<div class="topic-metadata">

**Author:** [@Leonid\_P](https://discuss.elastic.co/u/Leonid_P)\
**Replies:** 1\
**Last updated:** [February 12, 2024, 7:38am UTC](https://discuss.elastic.co/t/how-to-use-minimum-should-match-for-prefix-search/352363 "2024-02-12T07:38:10Z")

</div>

I want to make a search-as-you-type search service (with tokenization, analyzer etc.) and to use minimum\_should\_match in it, i.e. to show pages with three of four typed tokens but not with two of four. What is the best …

---

## [What is the best way to search one index with keyword and another index with vector and combine the search results?](https://discuss.elastic.co/t/what-is-the-best-way-to-search-one-index-with-keyword-and-another-index-with-vector-and-combine-the-search-results/352628)

<div class="topic-metadata">

**Author:** [@zli](https://discuss.elastic.co/u/zli)\
**Replies:** 1\
**Last updated:** [February 12, 2024, 7:33am UTC](https://discuss.elastic.co/t/what-is-the-best-way-to-search-one-index-with-keyword-and-another-index-with-vector-and-combine-the-search-results/352628 "2024-02-12T07:33:17Z")

</div>

Hi there, I'm currently working on a project where I need to perform searches across multiple indices in Elasticsearch and combine the results into a single ranked list. I have one index where keyword search is performe…

---

## [Best practices for managing lifecycles of small units of data](https://discuss.elastic.co/t/best-practices-for-managing-lifecycles-of-small-units-of-data/352670)

<div class="topic-metadata">

**Author:** [@japem](https://discuss.elastic.co/u/japem)\
**Replies:** 2\
**Last updated:** [February 12, 2024, 7:28am UTC](https://discuss.elastic.co/t/best-practices-for-managing-lifecycles-of-small-units-of-data/352670 "2024-02-12T07:28:48Z")

</div>

I have a use case where I have small-ish units of data (generally \<1GB) that I want to be able to manage the lifecycles of separately. Essentially, each user has information that we want to store in a hot data tier durin…

---

## [Logstash pipeline indexing error](https://discuss.elastic.co/t/logstash-pipeline-indexing-error/352388)

<div class="topic-metadata">

**Author:** [@mr\_ph](https://discuss.elastic.co/u/mr_ph)\
**Replies:** 2\
**Last updated:** [February 12, 2024, 7:26am UTC](https://discuss.elastic.co/t/logstash-pipeline-indexing-error/352388 "2024-02-12T07:26:42Z")

</div>

Hi team, I am using ELK stack 8.12 for observability. I am collecting input data from SNMP plugin and filtering the data as per my requirement but while doing that i have multiple index for multiple events that I am col…

---

## [Elasticsearch Java Api Client (7.17.16) - GetIndexResponse](https://discuss.elastic.co/t/elasticsearch-java-api-client-7-17-16-getindexresponse/353035)

<div class="topic-metadata">

**Author:** [@SElasticsearch](https://discuss.elastic.co/u/SElasticsearch)\
**Replies:** 0\
**Last updated:** [February 12, 2024, 5:41am UTC](https://discuss.elastic.co/t/elasticsearch-java-api-client-7-17-16-getindexresponse/353035 "2024-02-12T05:41:55Z")

</div>

I am trying to fetch the list of index names matching an index prefix (for example: abc-2024-02\*) GetIndexRequest request = new GetIndexRequest.Builder().index("abc-2024-02\*").allowNoIndices(false).expandWildcards(Expan…

---

## [Canvas table to have a count](https://discuss.elastic.co/t/canvas-table-to-have-a-count/353028)

<div class="topic-metadata">

**Author:** [@encathal](https://discuss.elastic.co/u/encathal)\
**Replies:** 1\
**Last updated:** [February 12, 2024, 3:18am UTC](https://discuss.elastic.co/t/canvas-table-to-have-a-count/353028 "2024-02-12T03:18:29Z")

</div>

Hi, I have a question how can I turn my fields.userinfo.Email.Keywords into a count column. I tried a few ways and I keep getting errors. Thanks

---

## [Kibana CPU Load](https://discuss.elastic.co/t/kibana-cpu-load/353030)

<div class="topic-metadata">

**Author:** [@zsnops](https://discuss.elastic.co/u/zsnops)\
**Replies:** 2\
**Last updated:** [February 12, 2024, 1:49am UTC](https://discuss.elastic.co/t/kibana-cpu-load/353030 "2024-02-12T01:49:35Z")

</div>

Hi, I am running a small single ELK instance just for visualizing some logs. Because the process consumes around 12 % CPU when idle, I have tried to deactivate a few things in kibana.yml: telemetry.enabled: false xpac…

---

## [Ingest Pipeline Creating Grok Pattern with string as dependency](https://discuss.elastic.co/t/ingest-pipeline-creating-grok-pattern-with-string-as-dependency/353014)

<div class="topic-metadata">

**Author:** [@pupit](https://discuss.elastic.co/u/pupit)\
**Replies:** 1\
**Last updated:** [February 11, 2024, 10:57pm UTC](https://discuss.elastic.co/t/ingest-pipeline-creating-grok-pattern-with-string-as-dependency/353014 "2024-02-11T22:57:36Z")

</div>

Hi, I am exploring ingest pipeline. The grok is working as expected. But, I am looking into just executing/running the grok pattern if the field have a certain string. How can I add a if condition where "if message =~…

---

## [Permission denied when reading /proc/$pid/io](https://discuss.elastic.co/t/permission-denied-when-reading-proc-pid-io/353026)

<div class="topic-metadata">

**Author:** [@i.raisr](https://discuss.elastic.co/u/i.raisr)\
**Replies:** 0\
**Last updated:** [February 11, 2024, 6:49pm UTC](https://discuss.elastic.co/t/permission-denied-when-reading-proc-pid-io/353026 "2024-02-11T18:49:25Z")

</div>

Dear all, Please could you comment what is the reason behind specifying required capabilities NET\_ADMIN and SETUID in the following document which describes how to setup a private location for synthetics monitoring: M…

---

## [Jar hell issue during loading custom plugin in elastic 8.4.1](https://discuss.elastic.co/t/jar-hell-issue-during-loading-custom-plugin-in-elastic-8-4-1/353016)

<div class="topic-metadata">

**Author:** [@msubbu](https://discuss.elastic.co/u/msubbu)\
**Replies:** 1\
**Last updated:** [February 11, 2024, 4:00pm UTC](https://discuss.elastic.co/t/jar-hell-issue-during-loading-custom-plugin-in-elastic-8-4-1/353016 "2024-02-11T16:00:31Z")

</div>

Hello Team, we are facing below while loading one of our custom plugin into Elasticsearch 8.4.1. Kindly need your valuable inputs on below issue.. Exception in thread "main" java.lang.IllegalStateException: failed to lo…

---

## [Unable to drop fields in filebeat using drop\_field](https://discuss.elastic.co/t/unable-to-drop-fields-in-filebeat-using-drop-field/352978)

<div class="topic-metadata">

**Author:** [@vyjayanth](https://discuss.elastic.co/u/vyjayanth)\
**Replies:** 11\
**Last updated:** [February 11, 2024, 1:56pm UTC](https://discuss.elastic.co/t/unable-to-drop-fields-in-filebeat-using-drop-field/352978 "2024-02-11T13:56:22Z")

</div>

Looking to drop a field called: Event.Original using drop\_field. As Message Field produces same information as Event.Original. I worked with remove\_field of logstash filter, but it isn’t reflecting by dropping the field…

---

## [XML into JSON value](https://discuss.elastic.co/t/xml-into-json-value/352933)

<div class="topic-metadata">

**Author:** [@martel](https://discuss.elastic.co/u/martel)\
**Replies:** 5\
**Last updated:** [February 11, 2024, 8:09am UTC](https://discuss.elastic.co/t/xml-into-json-value/352933 "2024-02-11T08:09:09Z")

</div>

Hey, If i have a Json message, into has an element "error" : "\<?xml version=\\"1.0\\" encoding=\\"UTF-8\\"?\> zefzefzfzef " how can extract and parse XML for create a sub-doc with all element xml example : "json" : "value…

---

## [Elasticsearch High CPU usage](https://discuss.elastic.co/t/elasticsearch-high-cpu-usage/352998)

<div class="topic-metadata">

**Author:** [@kkkk7](https://discuss.elastic.co/u/kkkk7)\
**Replies:** 2\
**Last updated:** [February 11, 2024, 2:54am UTC](https://discuss.elastic.co/t/elasticsearch-high-cpu-usage/352998 "2024-02-11T02:54:59Z")

</div>

Hello I'm using version 7.3.2 (this is a project since 2019 so a bit old version) After a years pass by my elastic stack CPU usage very high so we decide extends the CPU core but seem like the usage will growth bigger …

---

## [Metricbeat can't connect to Oracle 10g database](https://discuss.elastic.co/t/metricbeat-cant-connect-to-oracle-10g-database/352931)

<div class="topic-metadata">

**Author:** [@gurbelunder](https://discuss.elastic.co/u/gurbelunder)\
**Replies:** 8\
**Last updated:** [February 10, 2024, 5:11pm UTC](https://discuss.elastic.co/t/metricbeat-cant-connect-to-oracle-10g-database/352931 "2024-02-10T17:11:55Z")

</div>

Hi community, I'm trying to configure metricbeat on a Windows Server 2008 R2 server for 3 oracle 10.2.0.5 databases. I know both is not newest, but customer uses this still and of course these databases are important a…

[Previous page](https://discuss.elastic.co/latest.md?page=403)

[Next page](https://discuss.elastic.co/latest.md?page=405)
