# Latest

**URL:** https://discuss.elastic.co/latest.md?page=411

[Latest](https://discuss.elastic.co/latest.md) · [Categories](https://discuss.elastic.co/categories.md) · [Tags](https://discuss.elastic.co/tags.md)

**Page:** 412

---

## [Highlighting the latest logs within Visualization/Discover](https://discuss.elastic.co/t/highlighting-the-latest-logs-within-visualization-discover/352285)

<div class="topic-metadata">

**Author:** [@ksaimohan2k](https://discuss.elastic.co/u/ksaimohan2k)\
**Replies:** 2\
**Last updated:** [February 5, 2024, 5:41am UTC](https://discuss.elastic.co/t/highlighting-the-latest-logs-within-visualization-discover/352285 "2024-02-05T05:41:52Z")

</div>

Is there any way to highlight the new logs within the discovery or visualization ? I just want to highlight the latest, like the top 10 latest logs. or any coloring mechanism that should be erased when the user clicks o…

---

## [NearRealTime aggregation on recent inserted document](https://discuss.elastic.co/t/nearrealtime-aggregation-on-recent-inserted-document/352481)

<div class="topic-metadata">

**Author:** [@abduimrn](https://discuss.elastic.co/u/abduimrn)\
**Replies:** 4\
**Last updated:** [February 5, 2024, 5:20am UTC](https://discuss.elastic.co/t/nearrealtime-aggregation-on-recent-inserted-document/352481 "2024-02-05T05:20:50Z")

</div>

Hello, Elasticsearch is Near Real Time. Which in short it indicates that after issuing an insert request, it will not directly appear to all search and aggregation queries. In my application I first insert a document t…

---

## [Can not login elastic web interface](https://discuss.elastic.co/t/can-not-login-elastic-web-interface/352500)

<div class="topic-metadata">

**Author:** [@Ting\_sf](https://discuss.elastic.co/u/Ting_sf)\
**Replies:** 1\
**Last updated:** [February 5, 2024, 4:18am UTC](https://discuss.elastic.co/t/can-not-login-elastic-web-interface/352500 "2024-02-05T04:18:34Z")

</div>

I can not login elastic web interface at localhose:5601. Not matter what I put in username and password, it shows “we couldn’t log you in, please try again” I do have user “elastic” and password correct, but can not log…

---

## [Logstash output email plugin failure](https://discuss.elastic.co/t/logstash-output-email-plugin-failure/351847)

<div class="topic-metadata">

**Author:** [@shailendra1](https://discuss.elastic.co/u/shailendra1)\
**Replies:** 9\
**Last updated:** [February 5, 2024, 3:38am UTC](https://discuss.elastic.co/t/logstash-output-email-plugin-failure/351847 "2024-02-05T03:38:51Z")

</div>

Hello Team, i am using elk 8.5.3 and in the logstash output plugin , its failing with SMTP syntax error as pasted below ERROR\]\[logstash.outputs.email \]\[main\]\[9ab43dc1824014b9cc39372f569aeded7925e535ec037015bed8af1439…

---

## [Wallboard display](https://discuss.elastic.co/t/wallboard-display/352495)

<div class="topic-metadata">

**Author:** [@Ross\_Wakelin](https://discuss.elastic.co/u/Ross_Wakelin)\
**Replies:** 1\
**Last updated:** [February 4, 2024, 10:31pm UTC](https://discuss.elastic.co/t/wallboard-display/352495 "2024-02-04T22:31:39Z")

</div>

Hi We are setting up a new Security management room, and want to have some dashboards etc. from Kibana displayed permanently on a wall screen. I can't seem to find any hints or tips anywhere on how to set up autologon …

---

## [elasticsearch has opened a 30-day premium license trial, causing previously taken snapshots to be unusable](https://discuss.elastic.co/t/elasticsearch-has-opened-a-30-day-premium-license-trial-causing-previously-taken-snapshots-to-be-unusable/352487)

<div class="topic-metadata">

**Author:** [@guohuil142](https://discuss.elastic.co/u/guohuil142)\
**Replies:** 0\
**Last updated:** [February 4, 2024, 5:09pm UTC](https://discuss.elastic.co/t/elasticsearch-has-opened-a-30-day-premium-license-trial-causing-previously-taken-snapshots-to-be-unusable/352487 "2024-02-04T17:09:18Z")

</div>

elasticsearch has opened a 30-day premium license trial, causing previously taken snapshots to be unusable，After the 30-day license expires, the system reports AUnable to restore snapshot to restore snapshot current lic…

---

## [Monitoring de site avec ELK comment ça marche?](https://discuss.elastic.co/t/monitoring-de-site-avec-elk-comment-ca-marche/352443)

<div class="topic-metadata">

**Author:** [@sossoulokoariel](https://discuss.elastic.co/u/sossoulokoariel)\
**Replies:** 4\
**Last updated:** [February 4, 2024, 3:16pm UTC](https://discuss.elastic.co/t/monitoring-de-site-avec-elk-comment-ca-marche/352443 "2024-02-04T15:16:25Z")

</div>

Bonjour la communauté. Est-ce que quelqu'un a fait de la supervision sur un site web avec ELK ?

---

## [Regex double quotation use Lucene on Elasticsearch](https://discuss.elastic.co/t/regex-double-quotation-use-lucene-on-elasticsearch/352484)

<div class="topic-metadata">

**Author:** [@S\_n\_Ngo\_Hoang](https://discuss.elastic.co/u/S_n_Ngo_Hoang)\
**Replies:** 0\
**Last updated:** [February 4, 2024, 2:48pm UTC](https://discuss.elastic.co/t/regex-double-quotation-use-lucene-on-elasticsearch/352484 "2024-02-04T14:48:48Z")

</div>

Hello everyone, I'm new to ELK and I'm eager to learn about searching and regex with Lucene. I want to know how to regex double quotation marks in logs. For example, in the "message" field, I want to filter logs that con…

---

## [Unnest JSON](https://discuss.elastic.co/t/unnest-json/352447)

<div class="topic-metadata">

**Author:** [@Wilks](https://discuss.elastic.co/u/Wilks)\
**Replies:** 6\
**Last updated:** [February 4, 2024, 2:28pm UTC](https://discuss.elastic.co/t/unnest-json/352447 "2024-02-04T14:28:21Z")

</div>

Good Day, I am trying to unnest a JSON log and I can't seem to get it to work. When I try to unnest I get the already unnested JSON showing up 3 times and I while I am able to unnest the JSON I can't write the actual f…

---

## [About reindex](https://discuss.elastic.co/t/about-reindex/350833)

<div class="topic-metadata">

**Author:** [@jevonsnotes](https://discuss.elastic.co/u/jevonsnotes)\
**Replies:** 6\
**Last updated:** [February 4, 2024, 9:21am UTC](https://discuss.elastic.co/t/about-reindex/350833 "2024-02-04T09:21:53Z")

</div>

I have a concern when reindex, which is how to ensure seamless integration during the re indexing process as the original index continues to write data?

---

## [Can anyone provide a arm image of package-registry for the env?](https://discuss.elastic.co/t/can-anyone-provide-a-arm-image-of-package-registry-for-the-env/351428)

<div class="topic-metadata">

**Author:** [@jevonsnotes](https://discuss.elastic.co/u/jevonsnotes)\
**Replies:** 3\
**Last updated:** [February 4, 2024, 8:49am UTC](https://discuss.elastic.co/t/can-anyone-provide-a-arm-image-of-package-registry-for-the-env/351428 "2024-02-04T08:49:42Z")

</div>

my elk works at the air-gapped env. i need to deploy a package-registry for the fleet,but the image only the amd,anyone helps?

---

## [Why the kibana action so slow?](https://discuss.elastic.co/t/why-the-kibana-action-so-slow/350702)

<div class="topic-metadata">

**Author:** [@jevonsnotes](https://discuss.elastic.co/u/jevonsnotes)\
**Replies:** 9\
**Last updated:** [February 4, 2024, 8:43am UTC](https://discuss.elastic.co/t/why-the-kibana-action-so-slow/350702 "2024-02-04T08:43:01Z")

</div>

version 8.11.3 such as the Synthetics func ,it take a few minutes to action when i change the switch

---

## [Logstash keystore create error](https://discuss.elastic.co/t/logstash-keystore-create-error/351854)

<div class="topic-metadata">

**Author:** [@jevonsnotes](https://discuss.elastic.co/u/jevonsnotes)\
**Replies:** 2\
**Last updated:** [February 4, 2024, 8:23am UTC](https://discuss.elastic.co/t/logstash-keystore-create-error/351854 "2024-02-04T08:23:32Z")

</div>

logstash version 7.11.1 when i try to create a keystore but got an error as \>uninitialized constant LogStash::Util::Password, how to resolve this? \[elk@centos70\_112 logstash-7.11.1\]$ ./bin/logstash-keystore --path.sett…

---

## [Logstash failed to differentiate log filtering based on data source IP address](https://discuss.elastic.co/t/logstash-failed-to-differentiate-log-filtering-based-on-data-source-ip-address/352471)

<div class="topic-metadata">

**Author:** [@pacoxpk](https://discuss.elastic.co/u/pacoxpk)\
**Replies:** 2\
**Last updated:** [February 4, 2024, 7:03am UTC](https://discuss.elastic.co/t/logstash-failed-to-differentiate-log-filtering-based-on-data-source-ip-address/352471 "2024-02-04T07:03:56Z")

</div>

Send logs from multiple systems through syslog to logstash, which can receive logs normally. In order to distinguish logs sent from different systems, it is necessary to distinguish them based on the IP address of the da…

---

## [How to fix Index Lifecycle Rollover Alias is empty or not defined](https://discuss.elastic.co/t/how-to-fix-index-lifecycle-rollover-alias-is-empty-or-not-defined/351675)

<div class="topic-metadata">

**Author:** [@roman-tasi](https://discuss.elastic.co/u/roman-tasi)\
**Replies:** 28\
**Last updated:** [February 4, 2024, 1:10am UTC](https://discuss.elastic.co/t/how-to-fix-index-lifecycle-rollover-alias-is-empty-or-not-defined/351675 "2024-02-04T01:10:54Z")

</div>

I've been running this (uses date math) but it doesn't seem to be working: PUT /%3Cos-linux-%7Bnow%2Fd%7D-000001%3E { "aliases": { "os-linux": { "is\_write\_index": true } } } which pr…

---

## [Custom Logstash user role](https://discuss.elastic.co/t/custom-logstash-user-role/352398)

<div class="topic-metadata">

**Author:** [@rokkolesa](https://discuss.elastic.co/u/rokkolesa)\
**Replies:** 3\
**Last updated:** [February 3, 2024, 10:48pm UTC](https://discuss.elastic.co/t/custom-logstash-user-role/352398 "2024-02-03T22:48:11Z")

</div>

Hi, I'm trying to deploy multiple Logstash instances to two separate k8s namespaces and they both connect to the same Elasticsearch cluster. The problem is that they both write to different ES indices but use the same u…

---

## [Elastic hive configuration](https://discuss.elastic.co/t/elastic-hive-configuration/352458)

<div class="topic-metadata">

**Author:** [@John\_Papadopoulos](https://discuss.elastic.co/u/John_Papadopoulos)\
**Replies:** 0\
**Last updated:** [February 3, 2024, 12:47pm UTC](https://discuss.elastic.co/t/elastic-hive-configuration/352458 "2024-02-03T12:47:37Z")

</div>

Hello. What i have is elastic running in a host windows server and i want to install hive from a WSL ubuntu which will be hosted in the windows server. My elastic config file only accepts https connections. SO i have set…

---

## [File Integrity Monitor Missing Events](https://discuss.elastic.co/t/file-integrity-monitor-missing-events/352141)

<div class="topic-metadata">

**Author:** [@wrsnrno](https://discuss.elastic.co/u/wrsnrno)\
**Replies:** 2\
**Last updated:** [February 3, 2024, 12:40pm UTC](https://discuss.elastic.co/t/file-integrity-monitor-missing-events/352141 "2024-02-03T12:40:19Z")

</div>

File Integrity Monitor missed several events in a recent planned software deployment. FIM is configured to track the application folder on a dozen nearly identical hosts and was first initialized about a month ago. Oth…

---

## [Monitoring ES JVM with jolokia javaagent](https://discuss.elastic.co/t/monitoring-es-jvm-with-jolokia-javaagent/352454)

<div class="topic-metadata">

**Author:** [@Kalpesh\_Shekhat](https://discuss.elastic.co/u/Kalpesh_Shekhat)\
**Replies:** 0\
**Last updated:** [February 3, 2024, 9:39am UTC](https://discuss.elastic.co/t/monitoring-es-jvm-with-jolokia-javaagent/352454 "2024-02-03T09:39:38Z")

</div>

Hi, I want to monitor ES JVM using jolokia java agent. I have configured below options in /etc/elasticsearch/jvm.options.d/jmx.options -javaagent:/opt/jolokia/jolokia-agent-jvm-javaagent.jar=port=8081,host=localhost a…

---

## [Does elastic have a timestamp field as part of metadata as to when was the document written to index?](https://discuss.elastic.co/t/does-elastic-have-a-timestamp-field-as-part-of-metadata-as-to-when-was-the-document-written-to-index/352449)

<div class="topic-metadata">

**Author:** [@Rachana\_Maniyar](https://discuss.elastic.co/u/Rachana_Maniyar)\
**Replies:** 1\
**Last updated:** [February 3, 2024, 2:32am UTC](https://discuss.elastic.co/t/does-elastic-have-a-timestamp-field-as-part-of-metadata-as-to-when-was-the-document-written-to-index/352449 "2024-02-03T02:32:28Z")

</div>

Does elastic have a timestamp field as part of metadata as to when was the document written to index ? current meta fields that i see are only these - I have a usecase where the timestamps in the records could be diffe…

---

## [Logstash for application.log + application.log.1.gz](https://discuss.elastic.co/t/logstash-for-application-log-application-log-1-gz/351577)

<div class="topic-metadata">

**Author:** [@RavaliJ](https://discuss.elastic.co/u/RavaliJ)\
**Replies:** 5\
**Last updated:** [February 2, 2024, 8:59pm UTC](https://discuss.elastic.co/t/logstash-for-application-log-application-log-1-gz/351577 "2024-02-02T20:59:08Z")

</div>

Hi, I have Rolling file appenders in my java code which creates log files like - application.log, application.log.1.gz,application.log.2.gz so on. I want to index all of these and make sure messages from log files are r…

---

## [Problems Joining a Cluster](https://discuss.elastic.co/t/problems-joining-a-cluster/351904)

<div class="topic-metadata">

**Author:** [@bryanrood](https://discuss.elastic.co/u/bryanrood)\
**Replies:** 32\
**Last updated:** [February 2, 2024, 8:03pm UTC](https://discuss.elastic.co/t/problems-joining-a-cluster/351904 "2024-02-02T20:03:04Z")

</div>

Hi Everyone, I think I posted my first post in the wrong elasticsearch category. I'm trying to get my new cluster up and working and I'm really struggling with order of operation. I have tried a whole bunch of things bu…

---

## [Elasticsearch issue when indexing nanoseconds](https://discuss.elastic.co/t/elasticsearch-issue-when-indexing-nanoseconds/352345)

<div class="topic-metadata">

**Author:** [@kannan\_raj](https://discuss.elastic.co/u/kannan_raj)\
**Replies:** 2\
**Last updated:** [February 2, 2024, 7:57pm UTC](https://discuss.elastic.co/t/elasticsearch-issue-when-indexing-nanoseconds/352345 "2024-02-02T19:57:32Z")

</div>

Hi Team, Could not able to index the nanaseconds? PUT \_template/datenanos { "index\_patterns": \["datenanos"\], "mappings": { "properties": { "timestamp": { "type": "date\_nanos" } } } } …

---

## [How to group documents and show latest document per group](https://discuss.elastic.co/t/how-to-group-documents-and-show-latest-document-per-group/351165)

<div class="topic-metadata">

**Author:** [@mrusch](https://discuss.elastic.co/u/mrusch)\
**Replies:** 2\
**Last updated:** [February 2, 2024, 7:55pm UTC](https://discuss.elastic.co/t/how-to-group-documents-and-show-latest-document-per-group/351165 "2024-02-02T19:55:11Z")

</div>

Scenario: We have a third party tool for server patching and it sucks when it comes to reporting. So I want to build a dashboard in Kibana which shows patch status of thousands of servers. Available data so far per serv…

---

## [How to do a distance sort over entities which each have multiple locations](https://discuss.elastic.co/t/how-to-do-a-distance-sort-over-entities-which-each-have-multiple-locations/352439)

<div class="topic-metadata">

**Author:** [@BradDotyBWell](https://discuss.elastic.co/u/BradDotyBWell)\
**Replies:** 12\
**Last updated:** [February 2, 2024, 7:30pm UTC](https://discuss.elastic.co/t/how-to-do-a-distance-sort-over-entities-which-each-have-multiple-locations/352439 "2024-02-02T19:30:50Z")

</div>

Your product is simple-minded when it comes to distance searches. We have organizations who have multiple locations each. When a user does a search, we MUST use the closest location for each org to that user. Your pro…

---

## [Half\_float for Dense vector field](https://discuss.elastic.co/t/half-float-for-dense-vector-field/352387)

<div class="topic-metadata">

**Author:** [@mwon](https://discuss.elastic.co/u/mwon)\
**Replies:** 2\
**Last updated:** [February 2, 2024, 6:42pm UTC](https://discuss.elastic.co/t/half-float-for-dense-vector-field/352387 "2024-02-02T18:42:58Z")

</div>

Hi, Currently, Dense vector field is restricted to float (32bit) or byte (int8). Is there any plan to add half\_float option? Thanks

---

## [Pagination on logstash http filter](https://discuss.elastic.co/t/pagination-on-logstash-http-filter/352320)

<div class="topic-metadata">

**Author:** [@Johnson\_will](https://discuss.elastic.co/u/Johnson_will)\
**Replies:** 7\
**Last updated:** [February 2, 2024, 6:40pm UTC](https://discuss.elastic.co/t/pagination-on-logstash-http-filter/352320 "2024-02-02T18:40:15Z")

</div>

I am generating a token by using http\_poller input plugin, using the generated token in http filter part and splitting the fields from results, Can anyone please suggest me on Pagination. As the api results are around 4…

---

## [Agent 8.12.0 Standalone ignoring agent.logging settings](https://discuss.elastic.co/t/agent-8-12-0-standalone-ignoring-agent-logging-settings/352441)

<div class="topic-metadata">

**Author:** [@mgotechlock](https://discuss.elastic.co/u/mgotechlock)\
**Replies:** 0\
**Last updated:** [February 2, 2024, 6:33pm UTC](https://discuss.elastic.co/t/agent-8-12-0-standalone-ignoring-agent-logging-settings/352441 "2024-02-02T18:33:23Z")

</div>

I have these settings logging: level: error files: name: elastic-agent keepfiles: 7 metrics: enabled: false logging.level:error is not working. I am still seeing info and warning level logs. …

---

## [Filter fields in TVSB Data Tables](https://discuss.elastic.co/t/filter-fields-in-tvsb-data-tables/352434)

<div class="topic-metadata">

**Author:** [@erikg](https://discuss.elastic.co/u/erikg)\
**Replies:** 0\
**Last updated:** [February 2, 2024, 5:36pm UTC](https://discuss.elastic.co/t/filter-fields-in-tvsb-data-tables/352434 "2024-02-02T17:36:45Z")

</div>

Hello, I was wondering if there's a way to make TVSB fields filterable? I have created this table in TVSB: The fields are not filterable. Why did I choose this method? The reason I didn't use lens, is because I w…

---

## [Access RBAC features on Kibana without having to enable SSL on ElasticSearch](https://discuss.elastic.co/t/access-rbac-features-on-kibana-without-having-to-enable-ssl-on-elasticsearch/352234)

<div class="topic-metadata">

**Author:** [@Albatross](https://discuss.elastic.co/u/Albatross)\
**Replies:** 1\
**Last updated:** [February 2, 2024, 5:33pm UTC](https://discuss.elastic.co/t/access-rbac-features-on-kibana-without-having-to-enable-ssl-on-elasticsearch/352234 "2024-02-02T17:33:33Z")

</div>

I have a multi-node ES Cluster with mandatory in-house mTLS capabilities between different nodes hence I do not want to enable SSL on Elastic Search. However, I would like to take advantage of the RBAC features available…

[Previous page](https://discuss.elastic.co/latest.md?page=410)

[Next page](https://discuss.elastic.co/latest.md?page=412)
