# Latest

**URL:** https://discuss.elastic.co/latest.md?page=438

[Latest](https://discuss.elastic.co/latest.md) · [Categories](https://discuss.elastic.co/categories.md) · [Tags](https://discuss.elastic.co/tags.md)

**Page:** 439

---

## [The s3 input for creating the index does not work with preffix and csv files](https://discuss.elastic.co/t/the-s3-input-for-creating-the-index-does-not-work-with-preffix-and-csv-files/350496)

<div class="topic-metadata">

**Author:** [@Marcos\_Daniel\_Santos](https://discuss.elastic.co/u/Marcos_Daniel_Santos)\
**Replies:** 3\
**Last updated:** [January 6, 2024, 12:33pm UTC](https://discuss.elastic.co/t/the-s3-input-for-creating-the-index-does-not-work-with-preffix-and-csv-files/350496 "2024-01-06T12:33:04Z")

</div>

Hi everyone, I have a bucekt s3 with 2 csv files, one that is a securityhub repot and the other a guardduty report, both AWS services and security. I'm using the preffix to get my object, using the logstash -f file.conf…

---

## [How to replace unicode \\u00a0 with space with ingest pipeline processor](https://discuss.elastic.co/t/how-to-replace-unicode-u00a0-with-space-with-ingest-pipeline-processor/350484)

<div class="topic-metadata">

**Author:** [@Bowfish](https://discuss.elastic.co/u/Bowfish)\
**Replies:** 1\
**Last updated:** [January 6, 2024, 12:29pm UTC](https://discuss.elastic.co/t/how-to-replace-unicode-u00a0-with-space-with-ingest-pipeline-processor/350484 "2024-01-06T12:29:52Z")

</div>

I want to replace all non breaking space (\\u00a0) characters with a normal spaces in a gsub processor in an ingest pipeline. I tried it with this: POST \_ingest/pipeline/\_simulate { "pipeline": { "processors": \[ …

---

## [APM/Kibana: Redis not shown as a Dependency in php agent](https://discuss.elastic.co/t/apm-kibana-redis-not-shown-as-a-dependency-in-php-agent/350508)

<div class="topic-metadata">

**Author:** [@hetii](https://discuss.elastic.co/u/hetii)\
**Replies:** 0\
**Last updated:** [January 6, 2024, 10:30am UTC](https://discuss.elastic.co/t/apm-kibana-redis-not-shown-as-a-dependency-in-php-agent/350508 "2024-01-06T10:30:24Z")

</div>

Hi. I have a drupal instance that use redis. In the Newrelic I see redis as a dependency. For APM in kibana it's missing. Any clue or tip how to force it to be included? APM agent: apm-agent-php\_1.10.0\_all.apk APM …

---

## [Adding support for new protocols under packetbeat](https://discuss.elastic.co/t/adding-support-for-new-protocols-under-packetbeat/350425)

<div class="topic-metadata">

**Author:** [@ACodingfreak](https://discuss.elastic.co/u/ACodingfreak)\
**Replies:** 2\
**Last updated:** [January 6, 2024, 12:38am UTC](https://discuss.elastic.co/t/adding-support-for-new-protocols-under-packetbeat/350425 "2024-01-06T00:38:31Z")

</div>

Hi All, I do have couple of questions with respect to packetbeat and need your help in understanding the same Is there any updated article or document in adding support for new protocols in packetbeat? Did anyone …

---

## [Help understanding boolean should query results](https://discuss.elastic.co/t/help-understanding-boolean-should-query-results/350495)

<div class="topic-metadata">

**Author:** [@allan.silverstein](https://discuss.elastic.co/u/allan.silverstein)\
**Replies:** 0\
**Last updated:** [January 5, 2024, 10:46pm UTC](https://discuss.elastic.co/t/help-understanding-boolean-should-query-results/350495 "2024-01-05T22:46:45Z")

</div>

Hello, I'm not understanding why the following query does not show any documents hits for the "support\_files.bgp\_evpn\_routes" field. It does show hits for the first match\_phrase (name a). As a troubleshooting test, I c…

---

## [Kibana Maps Service Custom Icons in the Layer Style Section](https://discuss.elastic.co/t/kibana-maps-service-custom-icons-in-the-layer-style-section/205304)

<div class="topic-metadata">

**Author:** [@14kporter](https://discuss.elastic.co/u/14kporter)\
**Replies:** 2\
**Last updated:** [January 5, 2024, 8:37pm UTC](https://discuss.elastic.co/t/kibana-maps-service-custom-icons-in-the-layer-style-section/205304 "2024-01-05T20:37:37Z")

</div>

Currently I am using Kibana Map Service and plotting Geopoints. I want to change the icons of the points to something that is not one of the pre-selected Maiki icons and import another icon in the SVG format. Is this …

---

## [Filebeat not getting logs from kubernetes pods](https://discuss.elastic.co/t/filebeat-not-getting-logs-from-kubernetes-pods/350403)

<div class="topic-metadata">

**Author:** [@gustavo\_luigi\_cev](https://discuss.elastic.co/u/gustavo_luigi_cev)\
**Replies:** 4\
**Last updated:** [January 5, 2024, 7:58pm UTC](https://discuss.elastic.co/t/filebeat-not-getting-logs-from-kubernetes-pods/350403 "2024-01-05T19:58:17Z")

</div>

Hi! I'm trying to use Filebeat on my aws eks to get my containers logs. filebeat-configmap.yaml apiVersion: v1 kind: ConfigMap metadata: name: filebeat-config namespace: elk data: filebeat.yml: |- logging.le…

---

## [Query and Aggregation result doesn't match](https://discuss.elastic.co/t/query-and-aggregation-result-doesnt-match/350362)

<div class="topic-metadata">

**Author:** [@shufan](https://discuss.elastic.co/u/shufan)\
**Replies:** 4\
**Last updated:** [January 5, 2024, 7:07pm UTC](https://discuss.elastic.co/t/query-and-aggregation-result-doesnt-match/350362 "2024-01-05T19:07:59Z")

</div>

Hi team, got a strange issue when doing query and aggregation. Here is my script GET userindex/\_search { "\_source":\["response4"\], "query":{ "bool": { "filter": \[ {"script": { "script": { …

---

## [Percolating returns more results that i expect](https://discuss.elastic.co/t/percolating-returns-more-results-that-i-expect/350481)

<div class="topic-metadata">

**Author:** [@oli.girling](https://discuss.elastic.co/u/oli.girling)\
**Replies:** 4\
**Last updated:** [January 5, 2024, 6:56pm UTC](https://discuss.elastic.co/t/percolating-returns-more-results-that-i-expect/350481 "2024-01-05T18:56:42Z")

</div>

Smashing my head against the wall with this, wondering if anyone can point anything out thats obvious. Using ES 5.6 (I know its out of date, im in the process of upgrading) I have an advert in ES GET /gb/classified/15…

---

## [Installed Elastic-Agent cannot be removed](https://discuss.elastic.co/t/installed-elastic-agent-cannot-be-removed/350473)

<div class="topic-metadata">

**Author:** [@ghuie](https://discuss.elastic.co/u/ghuie)\
**Replies:** 9\
**Last updated:** [January 5, 2024, 6:50pm UTC](https://discuss.elastic.co/t/installed-elastic-agent-cannot-be-removed/350473 "2024-01-05T18:50:54Z")

</div>

So, I have a self-hosted ELK Stack (v. 8.11) in which I've been working for a few weeks. I've configured the certificates using the elasticsearch-certutil util and Elastic + Kibana are working fine. After that I wanted…

---

## [Elastic agent uninstall](https://discuss.elastic.co/t/elastic-agent-uninstall/349659)

<div class="topic-metadata">

**Author:** [@secsec](https://discuss.elastic.co/u/secsec)\
**Replies:** 9\
**Last updated:** [January 5, 2024, 5:53pm UTC](https://discuss.elastic.co/t/elastic-agent-uninstall/349659 "2024-01-05T17:53:32Z")

</div>

Hello, it seeemed to be simple but, im trying to uninstall elastic agent, but unfortunately no luck root@elk:/opt/elastic-agent-8.11.2-linux-x86\_64# elastic-agent uninstall Error: can only be uninstalled by executing …

---

## [Visualize documents that have multiple versions](https://discuss.elastic.co/t/visualize-documents-that-have-multiple-versions/350480)

<div class="topic-metadata">

**Author:** [@nnikushkin](https://discuss.elastic.co/u/nnikushkin)\
**Replies:** 0\
**Last updated:** [January 5, 2024, 5:25pm UTC](https://discuss.elastic.co/t/visualize-documents-that-have-multiple-versions/350480 "2024-01-05T17:25:00Z")

</div>

Hello community! I am trying to build visualizations in Kibana for documents that have multiple revisions. Just in case, I know that Elasticsearch does not keep the previous versions of the documents, however, in this t…

---

## [Metric Threshold - Email Alert Body](https://discuss.elastic.co/t/metric-threshold-email-alert-body/350478)

<div class="topic-metadata">

**Author:** [@erikg](https://discuss.elastic.co/u/erikg)\
**Replies:** 0\
**Last updated:** [January 5, 2024, 4:50pm UTC](https://discuss.elastic.co/t/metric-threshold-email-alert-body/350478 "2024-01-05T16:50:21Z")

</div>

Hello, I am using a simple alert to capture CPU usage. Using Email Action, the alert is working as expected but I want to see if I can edit the body to include the same data but more cleaned up. This is expected and d…

---

## [How i put a response into a kibana URL](https://discuss.elastic.co/t/how-i-put-a-response-into-a-kibana-url/350410)

<div class="topic-metadata">

**Author:** [@Natanael\_Rodrigues](https://discuss.elastic.co/u/Natanael_Rodrigues)\
**Replies:** 3\
**Last updated:** [January 5, 2024, 3:25pm UTC](https://discuss.elastic.co/t/how-i-put-a-response-into-a-kibana-url/350410 "2024-01-05T15:25:06Z")

</div>

Hello all, I have a script that will execute at a Unix serve curl -X POST "htt..xxxxx/xxxxx\*/\_search?pretty=" -H 'authorization: Basic xxxxxxxx' -H 'content-type: application/json' -d '{ "aggs": { "2": { …

---

## [Plugin index-pattern loading issues on multiple spaces](https://discuss.elastic.co/t/plugin-index-pattern-loading-issues-on-multiple-spaces/350396)

<div class="topic-metadata">

**Author:** [@JSFern83](https://discuss.elastic.co/u/JSFern83)\
**Replies:** 2\
**Last updated:** [January 5, 2024, 4:06pm UTC](https://discuss.elastic.co/t/plugin-index-pattern-loading-issues-on-multiple-spaces/350396 "2024-01-05T16:06:25Z")

</div>

Hi All, Our team is having trouble getting our plugin to load on multiple spaces. We have created an index-pattern for each space. Below is the configuration for the index-patterns saved in Elasticsearch. Space 1 { …

---

## [Observability Alerts - Recreate Watcher into Threshold Alert](https://discuss.elastic.co/t/observability-alerts-recreate-watcher-into-threshold-alert/350259)

<div class="topic-metadata">

**Author:** [@erikg](https://discuss.elastic.co/u/erikg)\
**Replies:** 2\
**Last updated:** [January 5, 2024, 4:00pm UTC](https://discuss.elastic.co/t/observability-alerts-recreate-watcher-into-threshold-alert/350259 "2024-01-05T16:00:43Z")

</div>

Hello, I am trying to recreate this Watcher into a Metric Threshold alert: { "trigger": { "schedule": { "cron": "0 \*/1 15-23 ? \* MON-SUN" } }, "input": { "search": { "request": { "…

---

## [How to map geo points (coordinates) to reginal layer](https://discuss.elastic.co/t/how-to-map-geo-points-coordinates-to-reginal-layer/350225)

<div class="topic-metadata">

**Author:** [@mharari](https://discuss.elastic.co/u/mharari)\
**Replies:** 5\
**Last updated:** [January 5, 2024, 3:43pm UTC](https://discuss.elastic.co/t/how-to-map-geo-points-coordinates-to-reginal-layer/350225 "2024-01-05T15:43:04Z")

</div>

I have docs with a geo location field (coordinates I get from the user's browser), and I want to add a layer to my map - where those geo locations are mapped into regions map ? like so - All I have is coordinates . I…

---

## [Configure LDAP Authentication](https://discuss.elastic.co/t/configure-ldap-authentication/350460)

<div class="topic-metadata">

**Author:** [@kadmin](https://discuss.elastic.co/u/kadmin)\
**Replies:** 3\
**Last updated:** [January 5, 2024, 3:34pm UTC](https://discuss.elastic.co/t/configure-ldap-authentication/350460 "2024-01-05T15:34:53Z")

</div>

Hello I want to configure LDAP authentication for my elastic cluster. On a test cluster I can check the configs before going to production. For this I use docker with this git repo. elasticsearch.yml cluster.name: do…

---

## [How to delete huge number of documents from Index? What can be better option?](https://discuss.elastic.co/t/how-to-delete-huge-number-of-documents-from-index-what-can-be-better-option/350469)

<div class="topic-metadata">

**Author:** [@msabnis79](https://discuss.elastic.co/u/msabnis79)\
**Replies:** 0\
**Last updated:** [January 5, 2024, 2:31pm UTC](https://discuss.elastic.co/t/how-to-delete-huge-number-of-documents-from-index-what-can-be-better-option/350469 "2024-01-05T14:31:48Z")

</div>

For example, we are having 2 billion documents in an index in ES and want to delete 1 billion documents based on some data from Oracle database? So i have to copy data from Oracle 1 billion records and based on Primary …

---

## [Kibana Discover browser title (looks) not set 1st time](https://discuss.elastic.co/t/kibana-discover-browser-title-looks-not-set-1st-time/350458)

<div class="topic-metadata">

**Author:** [@nisow95612](https://discuss.elastic.co/u/nisow95612)\
**Replies:** 2\
**Last updated:** [January 5, 2024, 1:48pm UTC](https://discuss.elastic.co/t/kibana-discover-browser-title-looks-not-set-1st-time/350458 "2024-01-05T13:48:53Z")

</div>

Hello, I noticed Kibana puts name of Discover search in browser title. This is very useful feature, but I see it is "unreliable". When I save search for first time, it sets title to "Discover: Errors". When I load sa…

---

## [X\_content\_parse\_exception](https://discuss.elastic.co/t/x-content-parse-exception/350381)

<div class="topic-metadata">

**Author:** [@redk1te](https://discuss.elastic.co/u/redk1te)\
**Replies:** 3\
**Last updated:** [January 5, 2024, 1:35pm UTC](https://discuss.elastic.co/t/x-content-parse-exception/350381 "2024-01-05T13:35:18Z")

</div>

Hi, I get the x\_content\_parse\_exception error with the next query. "reason": "\[10:13\] \[bool\] unknown field \[wildcard\]" without the "bool" section I get the error: "reason": "unknown query \[must\_not\]" Any suggestions…

---

## [APM service is unable to record backend process](https://discuss.elastic.co/t/apm-service-is-unable-to-record-backend-process/350426)

<div class="topic-metadata">

**Author:** [@weilin](https://discuss.elastic.co/u/weilin)\
**Replies:** 2\
**Last updated:** [January 5, 2024, 1:24pm UTC](https://discuss.elastic.co/t/apm-service-is-unable-to-record-backend-process/350426 "2024-01-05T13:24:30Z")

</div>

APM service is unable to record backend process service calls Kibana version: 8.11.3 Elasticsearch version: 8.11.3 elastic-agent-8.11.3 elastic-apm-agent-1.45.0.jar run jar: java -javaagent:$APP\_PATH/elastic-apm-…

---

## [Sharding and index settings](https://discuss.elastic.co/t/sharding-and-index-settings/350457)

<div class="topic-metadata">

**Author:** [@Mertozturkk](https://discuss.elastic.co/u/Mertozturkk)\
**Replies:** 2\
**Last updated:** [January 5, 2024, 12:31pm UTC](https://discuss.elastic.co/t/sharding-and-index-settings/350457 "2024-01-05T12:31:39Z")

</div>

The 3 Node Elasticsearch we have set up currently has a 6TB index set into 16 P and 1 R shards and is slow to respond to queries. If we want to create an index from scratch that will reach a similar volume in the new ver…

---

## [Data analysis with Kibana - How to get v8 Lab environment (current is still v7)](https://discuss.elastic.co/t/data-analysis-with-kibana-how-to-get-v8-lab-environment-current-is-still-v7/350449)

<div class="topic-metadata">

**Author:** [@AdW](https://discuss.elastic.co/u/AdW)\
**Replies:** 2\
**Last updated:** [January 5, 2024, 11:53am UTC](https://discuss.elastic.co/t/data-analysis-with-kibana-how-to-get-v8-lab-environment-current-is-still-v7/350449 "2024-01-05T11:53:30Z")

</div>

Hello, Some time ago I started the Data analysis with Kibana course which runs the v7.15.1 Lab environment. Recently the exam got moved to v8 and I think my course updated, but my Lab environment is still at v7.15.1. M…

---

## [Csp error for custom kibana login page](https://discuss.elastic.co/t/csp-error-for-custom-kibana-login-page/348701)

<div class="topic-metadata">

**Author:** [@Karan\_Lobo](https://discuss.elastic.co/u/Karan_Lobo)\
**Replies:** 9\
**Last updated:** [January 5, 2024, 11:42am UTC](https://discuss.elastic.co/t/csp-error-for-custom-kibana-login-page/348701 "2024-01-05T11:42:28Z")

</div>

heeyy i am using a custom plugin for my kibana that changes the login page to give a custom look but i am getting an errror relating to csp

---

## [Visualize customerId mapped to customer name in e.g. Kibana table](https://discuss.elastic.co/t/visualize-customerid-mapped-to-customer-name-in-e-g-kibana-table/350390)

<div class="topic-metadata">

**Author:** [@rickardo](https://discuss.elastic.co/u/rickardo)\
**Replies:** 2\
**Last updated:** [January 5, 2024, 9:43am UTC](https://discuss.elastic.co/t/visualize-customerid-mapped-to-customer-name-in-e-g-kibana-table/350390 "2024-01-05T09:43:30Z")

</div>

We have reports entries like below and Visualize statistics from "reports" in a Kibana table. But to show customerId=1 makes no sense so want to show them by their name that are defined in another Index in this case. L…

---

## [LDAP Configuration - ELK 8.8.1](https://discuss.elastic.co/t/ldap-configuration-elk-8-8-1/350444)

<div class="topic-metadata">

**Author:** [@Manal\_A](https://discuss.elastic.co/u/Manal_A)\
**Replies:** 0\
**Last updated:** [January 5, 2024, 9:42am UTC](https://discuss.elastic.co/t/ldap-configuration-elk-8-8-1/350444 "2024-01-05T09:42:50Z")

</div>

I'm currently configuring the LDAP on my coordinator & Kibana nodes (8.8.1) Here are the steps I've taken: Tested the connection with the LDAP server on my coordinator, and it's successful. Configured my elasticsearc…

---

## [Logstash tcp input plugin connection reset error](https://discuss.elastic.co/t/logstash-tcp-input-plugin-connection-reset-error/350441)

<div class="topic-metadata">

**Author:** [@fmelk65](https://discuss.elastic.co/u/fmelk65)\
**Replies:** 0\
**Last updated:** [January 5, 2024, 9:10am UTC](https://discuss.elastic.co/t/logstash-tcp-input-plugin-connection-reset-error/350441 "2024-01-05T09:10:16Z")

</div>

Hello, I have 25 Kubernetes clusters forward their logs to logstash VM (k8s fluentd ---\> logstash). I'm getting a lot of connection reset errors. It's been discussed here before, can @true64gurus specifically help? \[…

---

## [How to set volume map for logstash.conf file in docker compose file](https://discuss.elastic.co/t/how-to-set-volume-map-for-logstash-conf-file-in-docker-compose-file/350422)

<div class="topic-metadata">

**Author:** [@Sunny84](https://discuss.elastic.co/u/Sunny84)\
**Replies:** 1\
**Last updated:** [January 5, 2024, 8:46am UTC](https://discuss.elastic.co/t/how-to-set-volume-map-for-logstash-conf-file-in-docker-compose-file/350422 "2024-01-05T08:46:06Z")

</div>

Hello, I am trying to setup a docker compose file for setting up ELK stack to be able to use logging on local machine. Below is the error shown in the terminal window, my stack is windows 11 home, Docker Engine v24.0.7,…

---

## [What is the meaning of brackets in an index name?](https://discuss.elastic.co/t/what-is-the-meaning-of-brackets-in-an-index-name/350376)

<div class="topic-metadata">

**Author:** [@mbby](https://discuss.elastic.co/u/mbby)\
**Replies:** 4\
**Last updated:** [January 5, 2024, 7:24am UTC](https://discuss.elastic.co/t/what-is-the-meaning-of-brackets-in-an-index-name/350376 "2024-01-05T07:24:22Z")

</div>

We are using heartbeat and I saw a data view like this: (synthetics-data-view),heartbeat-8,heartbeat-7\*,synthetics-\* Why is synthetics-data-view written in brackets?

[Previous page](https://discuss.elastic.co/latest.md?page=437)

[Next page](https://discuss.elastic.co/latest.md?page=439)
