# Latest

**URL:** https://discuss.elastic.co/latest.md?page=443

[Latest](https://discuss.elastic.co/latest.md) · [Categories](https://discuss.elastic.co/categories.md) · [Tags](https://discuss.elastic.co/tags.md)

**Page:** 444

---

## [Conditional formatting for data and colors according to input field available for dashboard users](https://discuss.elastic.co/t/conditional-formatting-for-data-and-colors-according-to-input-field-available-for-dashboard-users/350177)

<div class="topic-metadata">

**Author:** [@Magdy](https://discuss.elastic.co/u/Magdy)\
**Replies:** 0\
**Last updated:** [January 1, 2024, 7:17am UTC](https://discuss.elastic.co/t/conditional-formatting-for-data-and-colors-according-to-input-field-available-for-dashboard-users/350177 "2024-01-01T07:17:38Z")

</div>

Create text input on the screen and compare it with the value in the tree map to change the background of cells accordingly.

---

## [Why data is inserting in index in delete phase, why not new index ... are we missing any configuration?](https://discuss.elastic.co/t/why-data-is-inserting-in-index-in-delete-phase-why-not-new-index-are-we-missing-any-configuration/350054)

<div class="topic-metadata">

**Author:** [@Shahzaib\_Khan](https://discuss.elastic.co/u/Shahzaib_Khan)\
**Replies:** 3\
**Last updated:** [January 1, 2024, 7:06am UTC](https://discuss.elastic.co/t/why-data-is-inserting-in-index-in-delete-phase-why-not-new-index-are-we-missing-any-configuration/350054 "2024-01-01T07:06:07Z")

</div>

I am facing an issue with Elasticsearch where, even after the rollover phase is successfully completed and a new index is created, data continues to be inserted into the old rollover index instead of the newly created in…

---

## [Elasticserach installation on linux preferences](https://discuss.elastic.co/t/elasticserach-installation-on-linux-preferences/350169)

<div class="topic-metadata">

**Author:** [@sahere37](https://discuss.elastic.co/u/sahere37)\
**Replies:** 0\
**Last updated:** [January 1, 2024, 5:45am UTC](https://discuss.elastic.co/t/elasticserach-installation-on-linux-preferences/350169 "2024-01-01T05:45:39Z")

</div>

in order to install the latest (8.11.1) elasticsearch cluster in a production environment (oracle linux based), which method of installation is better? rpm or zip/tar.gz? in each method which user can we use ? root or …

---

## [How to read filebeat keystore?](https://discuss.elastic.co/t/how-to-read-filebeat-keystore/350153)

<div class="topic-metadata">

**Author:** [@Aparna\_R](https://discuss.elastic.co/u/Aparna_R)\
**Replies:** 3\
**Last updated:** [January 1, 2024, 5:40am UTC](https://discuss.elastic.co/t/how-to-read-filebeat-keystore/350153 "2024-01-01T05:40:13Z")

</div>

Hi, I am using Powershell Desired State Configuration (DSC) to manage filebeat on my VM. In the DSC script, I need to be able to compare the secure strings used in Filebeat configuration through keystore with the source…

---

## [How to compare the value of field with the input value from the screen to take an action?](https://discuss.elastic.co/t/how-to-compare-the-value-of-field-with-the-input-value-from-the-screen-to-take-an-action/350168)

<div class="topic-metadata">

**Author:** [@adnan-ali](https://discuss.elastic.co/u/adnan-ali)\
**Replies:** 0\
**Last updated:** [January 1, 2024, 5:37am UTC](https://discuss.elastic.co/t/how-to-compare-the-value-of-field-with-the-input-value-from-the-screen-to-take-an-action/350168 "2024-01-01T05:37:32Z")

</div>

in the tree map value ,we need to change the background color of tree map cell depend on the input value from the screen to comparing with value on tree map EX: tree map value is 1000 . input value from screen is 1200…

---

## [Unable to convert \[0.0\] to long](https://discuss.elastic.co/t/unable-to-convert-0-0-to-long/350031)

<div class="topic-metadata">

**Author:** [@Ethan777100](https://discuss.elastic.co/u/Ethan777100)\
**Replies:** 9\
**Last updated:** [January 1, 2024, 4:30am UTC](https://discuss.elastic.co/t/unable-to-convert-0-0-to-long/350031 "2024-01-01T04:30:11Z")

</div>

Been a while. Things have been smooth sailing for my other data, until this set here. I am not sure why I get this error when ingesting it. \[2023-12-27T16:46:33,099\]\[WARN \]\[logstash.outputs.elasticsearch\]\[main\]\[5612df4…

---

## [Filebeat.yml not recognized environment variable](https://discuss.elastic.co/t/filebeat-yml-not-recognized-environment-variable/350087)

<div class="topic-metadata">

**Author:** [@Alejandro\_Avila\_Pere](https://discuss.elastic.co/u/Alejandro_Avila_Pere)\
**Replies:** 1\
**Last updated:** [December 31, 2023, 6:52pm UTC](https://discuss.elastic.co/t/filebeat-yml-not-recognized-environment-variable/350087 "2023-12-31T18:52:09Z")

</div>

Hello everyone, I am trying to obtain the logs generated by the console in a container that has a backend with the ECS format from the @elastic/ecs-winston-format library, with a filebeat service. However, it does not re…

---

## [ when downgrading version 8.11 to a lower version. my datanodes did restore on version downgrade but starting elastic search the data on the new nodes was not found. Is there any way to restore this data?](https://discuss.elastic.co/t/when-downgrading-version-8-11-to-a-lower-version-my-datanodes-did-restore-on-version-downgrade-but-starting-elastic-search-the-data-on-the-new-nodes-was-not-found-is-there-any-way-to-restore-this-data/350114)

<div class="topic-metadata">

**Author:** [@Cody-Test](https://discuss.elastic.co/u/Cody-Test)\
**Replies:** 3\
**Last updated:** [December 31, 2023, 4:48pm UTC](https://discuss.elastic.co/t/when-downgrading-version-8-11-to-a-lower-version-my-datanodes-did-restore-on-version-downgrade-but-starting-elastic-search-the-data-on-the-new-nodes-was-not-found-is-there-any-way-to-restore-this-data/350114 "2023-12-31T16:48:33Z")

</div>

Hello friend, currently my lab tests elasticsearch when downgrading version 8.11 to a lower version. my datanodes did restore on version downgrade but starting Elasticsearch the data on the new nodes was not found. Is th…

---

## [ERROR: Failed to determine the health of the cluster. , with exit code 69](https://discuss.elastic.co/t/error-failed-to-determine-the-health-of-the-cluster-with-exit-code-69/350150)

<div class="topic-metadata">

**Author:** [@zeynepyz](https://discuss.elastic.co/u/zeynepyz)\
**Replies:** 5\
**Last updated:** [December 31, 2023, 3:18pm UTC](https://discuss.elastic.co/t/error-failed-to-determine-the-health-of-the-cluster-with-exit-code-69/350150 "2023-12-31T15:18:35Z")

</div>

In /usr/share/elasticsearch/bin file i run "sudo ./elasticsearch-create-enrollment-token --scope kibana" command and i get this output: 03:26:10.736 \[main\] WARN org.elasticsearch.common.ssl.DiagnosticTrustManager - fai…

---

## [Logstash configuration with multiple http\_poller did'nt ran for some indices](https://discuss.elastic.co/t/logstash-configuration-with-multiple-http-poller-didnt-ran-for-some-indices/350151)

<div class="topic-metadata">

**Author:** [@Rakhshunda\_Noorein\_J](https://discuss.elastic.co/u/Rakhshunda_Noorein_J)\
**Replies:** 0\
**Last updated:** [December 31, 2023, 8:02am UTC](https://discuss.elastic.co/t/logstash-configuration-with-multiple-http-poller-didnt-ran-for-some-indices/350151 "2023-12-31T08:02:11Z")

</div>

Hello, I have a logstash configuration with multiple http\_poller input plugins. say input { http\_poller { id =\> "s1-input" urls =\> { sector\_api =\> { method =\> "POST" url =\> "url1" headers =\>…

---

## [No data passed from Filebeat](https://discuss.elastic.co/t/no-data-passed-from-filebeat/350137)

<div class="topic-metadata">

**Author:** [@OAuthority](https://discuss.elastic.co/u/OAuthority)\
**Replies:** 4\
**Last updated:** [December 29, 2023, 10:46pm UTC](https://discuss.elastic.co/t/no-data-passed-from-filebeat/350137 "2023-12-29T22:46:32Z")

</div>

I'm pretty new to this software, but trying to set up Kibana, Elasticsearch, Filebeat, and Logstash. The set up I'm trying to achieve is as such. Kibana, ES, Logstash are all on one server, for this sake, we'll say 1.1.…

---

## [BM25 score when do search in multi field](https://discuss.elastic.co/t/bm25-score-when-do-search-in-multi-field/350146)

<div class="topic-metadata">

**Author:** [@r1ckC139](https://discuss.elastic.co/u/r1ckC139)\
**Replies:** 1\
**Last updated:** [December 30, 2023, 2:14pm UTC](https://discuss.elastic.co/t/bm25-score-when-do-search-in-multi-field/350146 "2023-12-30T14:14:26Z")

</div>

es\_query = { "bool": { "must": \[ {"match": {"title": title\_text}}, {"match": {"year": year\_text}} \] } } when i do search 2 field match, how elasticsearch combine score of 2 match?

---

## [How to integrate syslog input plugin](https://discuss.elastic.co/t/how-to-integrate-syslog-input-plugin/349025)

<div class="topic-metadata">

**Author:** [@Ravi\_Pattar](https://discuss.elastic.co/u/Ravi_Pattar)\
**Replies:** 41\
**Last updated:** [December 26, 2023, 12:24pm UTC](https://discuss.elastic.co/t/how-to-integrate-syslog-input-plugin/349025 "2023-12-26T12:24:13Z")

</div>

Hi, I have installed full stack ELK (version 7.17.13) and now I want to integrate syslog input plugin. Need some directions on the same on how to setup. Also when I tried with some changes in logstash.conf but I am fa…

---

## [Vega Force Directed Graph and Kibana: Use data from index not from a json](https://discuss.elastic.co/t/vega-force-directed-graph-and-kibana-use-data-from-index-not-from-a-json/349405)

<div class="topic-metadata">

**Author:** [@Ranger\_Rick](https://discuss.elastic.co/u/Ranger_Rick)\
**Replies:** 2\
**Last updated:** [December 30, 2023, 12:51pm UTC](https://discuss.elastic.co/t/vega-force-directed-graph-and-kibana-use-data-from-index-not-from-a-json/349405 "2023-12-30T12:51:41Z")

</div>

Good afternoon! I have two indexes with data in my instances and am trying to make a force directed graph to visualize relationships. There is an excellent example available Vega's github (Vega Github's Force Directed La…

---

## [Azure Monitor Metrics for StorageAccounts namespaces does not ingest data, no error message returned](https://discuss.elastic.co/t/azure-monitor-metrics-for-storageaccounts-namespaces-does-not-ingest-data-no-error-message-returned/350135)

<div class="topic-metadata">

**Author:** [@s.buksa](https://discuss.elastic.co/u/s.buksa)\
**Replies:** 2\
**Last updated:** [December 30, 2023, 1:19am UTC](https://discuss.elastic.co/t/azure-monitor-metrics-for-storageaccounts-namespaces-does-not-ingest-data-no-error-message-returned/350135 "2023-12-30T01:19:03Z")

</div>

Hello, Could someone, please, help me to understand where is the issue in the following configurations? I am trying to scrape metrics from specific resource namespace "Microsoft.Storage/storageAccounts/queueServices" na…

---

## [Help parsing custom nginx logs using Filebeat and Ingest Pipelines](https://discuss.elastic.co/t/help-parsing-custom-nginx-logs-using-filebeat-and-ingest-pipelines/349974)

<div class="topic-metadata">

**Author:** [@BDeveloper](https://discuss.elastic.co/u/BDeveloper)\
**Replies:** 17\
**Last updated:** [December 29, 2023, 7:09pm UTC](https://discuss.elastic.co/t/help-parsing-custom-nginx-logs-using-filebeat-and-ingest-pipelines/349974 "2023-12-29T19:09:18Z")

</div>

Hi, I am new to using ELK stack. I have custom logs for my nginx access.log files and I am needing help parsing them by using filebeat and ingest pipeline (Log Files -\> Filebeat -\> (Parse with Ingest Pipeline Parse) Ela…

---

## [How to replace multiple new lines with one in Ingest Pipeline gsub](https://discuss.elastic.co/t/how-to-replace-multiple-new-lines-with-one-in-ingest-pipeline-gsub/350127)

<div class="topic-metadata">

**Author:** [@Bowfish](https://discuss.elastic.co/u/Bowfish)\
**Replies:** 3\
**Last updated:** [December 29, 2023, 4:57pm UTC](https://discuss.elastic.co/t/how-to-replace-multiple-new-lines-with-one-in-ingest-pipeline-gsub/350127 "2023-12-29T16:57:34Z")

</div>

I want to replace multiple new lines (\\n\\n+) with one single new line (\\n) with a gsub processor in the ingest pipeline. This is my gsub processor: { "gsub": { "field": "attachment.content\_processed", …

---

## [Are there any issues or topics on shrinking elastic-agent's install size?](https://discuss.elastic.co/t/are-there-any-issues-or-topics-on-shrinking-elastic-agents-install-size/350099)

<div class="topic-metadata">

**Author:** [@jerrac](https://discuss.elastic.co/u/jerrac)\
**Replies:** 3\
**Last updated:** [December 29, 2023, 4:46pm UTC](https://discuss.elastic.co/t/are-there-any-issues-or-topics-on-shrinking-elastic-agents-install-size/350099 "2023-12-29T16:46:48Z")

</div>

Today I ran into issues trying to install, and ended up figuring out that you need at least 1.7G of disk for Agent. It had been a while since I last looked at the minimum requirements for Elastic Agent. Considering I re…

---

## [I need help](https://discuss.elastic.co/t/i-need-help/349630)

<div class="topic-metadata">

**Author:** [@omlett](https://discuss.elastic.co/u/omlett)\
**Replies:** 2\
**Last updated:** [December 29, 2023, 4:07pm UTC](https://discuss.elastic.co/t/i-need-help/349630 "2023-12-29T16:07:40Z")

</div>

i am trying to make a parsedmarc elasticsearch and Kibana docker container, everything is running fine except i dont see any data on Kibana and i dont know what im doing wrong, because with the same configs they were run…

---

## [Create visualization on kibana for one filed if the other filed is present in document](https://discuss.elastic.co/t/create-visualization-on-kibana-for-one-filed-if-the-other-filed-is-present-in-document/350116)

<div class="topic-metadata">

**Author:** [@RameshNagargoje](https://discuss.elastic.co/u/RameshNagargoje)\
**Replies:** 1\
**Last updated:** [December 29, 2023, 3:21pm UTC](https://discuss.elastic.co/t/create-visualization-on-kibana-for-one-filed-if-the-other-filed-is-present-in-document/350116 "2023-12-29T15:21:23Z")

</div>

I have use case is to create the pie chart for "name" present in documents when documents has a "status" field available. We have several documents in an index; for all documents, we have "name" available, but the "sta…

---

## [Logstash pipeline to filter rss document](https://discuss.elastic.co/t/logstash-pipeline-to-filter-rss-document/349800)

<div class="topic-metadata">

**Author:** [@ramiwashere](https://discuss.elastic.co/u/ramiwashere)\
**Replies:** 3\
**Last updated:** [December 29, 2023, 2:52pm UTC](https://discuss.elastic.co/t/logstash-pipeline-to-filter-rss-document/349800 "2023-12-29T14:52:53Z")

</div>

I've just created a logstash that will retrieve documents from a feed. I receive the documents in return but the fields I want to add are all on the same document. Here's an example: \<rss \<item\> \<title\> \<desc\>…

---

## [Full Join Pattern](https://discuss.elastic.co/t/full-join-pattern/350101)

<div class="topic-metadata">

**Author:** [@AlanRocha](https://discuss.elastic.co/u/AlanRocha)\
**Replies:** 4\
**Last updated:** [December 29, 2023, 2:35pm UTC](https://discuss.elastic.co/t/full-join-pattern/350101 "2023-12-29T14:35:36Z")

</div>

Hello everyone, everything good? I need to do a full join with four different patterns ex: datalake-1-, tool-v1-, za-ho-, cmdb-grupos-. I'm filtering mine based on a dashboard I have in Power BI and I migrate all of th…

---

## [Rolling upgrade from 7.14.2 to 7.17.16 no working](https://discuss.elastic.co/t/rolling-upgrade-from-7-14-2-to-7-17-16-no-working/350106)

<div class="topic-metadata">

**Author:** [@fory](https://discuss.elastic.co/u/fory)\
**Replies:** 4\
**Last updated:** [December 29, 2023, 1:46pm UTC](https://discuss.elastic.co/t/rolling-upgrade-from-7-14-2-to-7-17-16-no-working/350106 "2023-12-29T13:46:01Z")

</div>

According to 7.17.16 documentation, upgrading from 7.14.2 to 7.17.16 can be done by rolling upgrade. I have a two node cluster both are master eligible. Following the rolling upgrade documentation, I upgraded one of the…

---

## [Machine Learning node Pricing](https://discuss.elastic.co/t/machine-learning-node-pricing/350113)

<div class="topic-metadata">

**Author:** [@haopv](https://discuss.elastic.co/u/haopv)\
**Replies:** 1\
**Last updated:** [December 29, 2023, 11:30am UTC](https://discuss.elastic.co/t/machine-learning-node-pricing/350113 "2023-12-29T11:30:59Z")

</div>

Hi Elastic, I have 20 nodes data Elastic in my Cluster on Premises with Basic License, Can I add 2 nodes machine learning for ML Job (Security Rule ML) and pay license for only 2 nodes ML ? If not! What is the way to o…

---

## [Need help with ScriptedMetricAggregation in Elasticsearch v8.7](https://discuss.elastic.co/t/need-help-with-scriptedmetricaggregation-in-elasticsearch-v8-7/350088)

<div class="topic-metadata">

**Author:** [@Chetan\_Ramaiah](https://discuss.elastic.co/u/Chetan_Ramaiah)\
**Replies:** 2\
**Last updated:** [December 29, 2023, 9:58am UTC](https://discuss.elastic.co/t/need-help-with-scriptedmetricaggregation-in-elasticsearch-v8-7/350088 "2023-12-29T09:58:38Z")

</div>

Hello, I am working on migrating ES 6.8 java code to ES 8.7.1 rest API java. But, I am unable to understand or find how to write script metric aggregation with ES 8.7.1. Could you please guide me using the below code fr…

---

## [Stuck on authentication URL and loose the entire connection why?](https://discuss.elastic.co/t/stuck-on-authentication-url-and-loose-the-entire-connection-why/350096)

<div class="topic-metadata">

**Author:** [@Praful\_Shrivastava](https://discuss.elastic.co/u/Praful_Shrivastava)\
**Replies:** 1\
**Last updated:** [December 28, 2023, 8:25pm UTC](https://discuss.elastic.co/t/stuck-on-authentication-url-and-loose-the-entire-connection-why/350096 "2023-12-28T20:25:10Z")

</div>

I just tried to sign up for an Elastic Cloud free account with Google, and after creating a deployment using Google Cloud as the base, whenever I try to open the deployment, it stuck on the authentication URL and lost th…

---

## [I have a requirement where in I have to move selected data from Elasticsearch INDEX to oracle Table {RDBMS}](https://discuss.elastic.co/t/i-have-a-requirement-where-in-i-have-to-move-selected-data-from-elasticsearch-index-to-oracle-table-rdbms/350083)

<div class="topic-metadata">

**Author:** [@AkshayP21296](https://discuss.elastic.co/u/AkshayP21296)\
**Replies:** 2\
**Last updated:** [December 28, 2023, 8:16pm UTC](https://discuss.elastic.co/t/i-have-a-requirement-where-in-i-have-to-move-selected-data-from-elasticsearch-index-to-oracle-table-rdbms/350083 "2023-12-28T20:16:45Z")

</div>

I have a requirement where in I have to move selected data from Elasticsearch INDEX to oracle Table {RDBMS}

---

## [TVSB - Top N Filtering](https://discuss.elastic.co/t/tvsb-top-n-filtering/350089)

<div class="topic-metadata">

**Author:** [@erikg](https://discuss.elastic.co/u/erikg)\
**Replies:** 4\
**Last updated:** [December 28, 2023, 5:21pm UTC](https://discuss.elastic.co/t/tvsb-top-n-filtering/350089 "2023-12-28T17:21:46Z")

</div>

Hello, I created this TVSB - Top N visualization, and I was wondering how I can have it be "filterable". Normally with a lens, I can click on the visualization, and it would apply the filter based on the selection. But …

---

## [Need help on aggregation and sub aggregation with ES 8.7 rest api](https://discuss.elastic.co/t/need-help-on-aggregation-and-sub-aggregation-with-es-8-7-rest-api/350093)

<div class="topic-metadata">

**Author:** [@Chetan\_Ramaiah](https://discuss.elastic.co/u/Chetan_Ramaiah)\
**Replies:** 0\
**Last updated:** [December 28, 2023, 4:59pm UTC](https://discuss.elastic.co/t/need-help-on-aggregation-and-sub-aggregation-with-es-8-7-rest-api/350093 "2023-12-28T16:59:01Z")

</div>

Hello, I am working on migrating ES 6.8 java code to ES 8.7 rest api java. While working on aggregation, I am able to construct aggregation layer but not as per the required format. ----- \*\*expected result\*\* ----- "a…

---

## [Integration with cisco ISE, PaloAlto and Fortigate Firewall](https://discuss.elastic.co/t/integration-with-cisco-ise-paloalto-and-fortigate-firewall/349848)

<div class="topic-metadata">

**Author:** [@Ganesh\_DV](https://discuss.elastic.co/u/Ganesh_DV)\
**Replies:** 15\
**Last updated:** [December 28, 2023, 3:08pm UTC](https://discuss.elastic.co/t/integration-with-cisco-ise-paloalto-and-fortigate-firewall/349848 "2023-12-28T15:08:46Z")

</div>

Hi team. im new to elasticsearch, kindly help me to resolve with below mentioned problem in integartion. I configured cisco ise, fortinet and paloalto firewalls to push logs to elasticsearch via Load balancer . Logs ar…

[Previous page](https://discuss.elastic.co/latest.md?page=442)

[Next page](https://discuss.elastic.co/latest.md?page=444)
