# Latest

**URL:** https://discuss.elastic.co/latest.md?page=446

[Latest](https://discuss.elastic.co/latest.md) · [Categories](https://discuss.elastic.co/categories.md) · [Tags](https://discuss.elastic.co/tags.md)

**Page:** 447

---

## [Index Life Cycle Management](https://discuss.elastic.co/t/index-life-cycle-management/349964)

<div class="topic-metadata">

**Author:** [@Debasis\_Mallick](https://discuss.elastic.co/u/Debasis_Mallick)\
**Replies:** 3\
**Last updated:** [December 26, 2023, 3:10pm UTC](https://discuss.elastic.co/t/index-life-cycle-management/349964 "2023-12-26T15:10:24Z")

</div>

HI Team, Can Index rollover happened on the basis of field value of attribute instead of calendar date. Thanks, Debasis

---

## [MSK to Elasticksearch using logstash](https://discuss.elastic.co/t/msk-to-elasticksearch-using-logstash/349945)

<div class="topic-metadata">

**Author:** [@Gersi\_Tafili](https://discuss.elastic.co/u/Gersi_Tafili)\
**Replies:** 4\
**Last updated:** [December 26, 2023, 1:14pm UTC](https://discuss.elastic.co/t/msk-to-elasticksearch-using-logstash/349945 "2023-12-26T13:14:29Z")

</div>

I have create MSK in AWS also Elastic search cluster hostes in AWS. I am trying to read data from topic in MSK and send this data to elasticsearch index. input { kafka { bootstrap\_servers =\> "x:9096" topics =\>…

---

## [Elastic Agent](https://discuss.elastic.co/t/elastic-agent/349925)

<div class="topic-metadata">

**Author:** [@Phyo\_WaThone\_Win](https://discuss.elastic.co/u/Phyo_WaThone_Win)\
**Replies:** 1\
**Last updated:** [December 26, 2023, 12:55pm UTC](https://discuss.elastic.co/t/elastic-agent/349925 "2023-12-26T12:55:16Z")

</div>

Dear team, In my current organization have at least 5000 employees. So, when I use the ELK for security information and event management, is it ok for all employees? Thanks and regards,

---

## [Can not create a custom normalizer using char filter \[html\_strip\]](https://discuss.elastic.co/t/can-not-create-a-custom-normalizer-using-char-filter-html-strip/349939)

<div class="topic-metadata">

**Author:** [@voaix](https://discuss.elastic.co/u/voaix)\
**Replies:** 1\
**Last updated:** [December 26, 2023, 12:45pm UTC](https://discuss.elastic.co/t/can-not-create-a-custom-normalizer-using-char-filter-html-strip/349939 "2023-12-26T12:45:20Z")

</div>

Hello, I try to save the custom normalizer as part of composite template. Receiving below error: illegal\_argument\_exception', 'Custom normalizer \[lower\_normalizer\] may not use char filter \[html\_strip\] Normalizer is de…

---

## [Select option from drop downs and update,delete the documents accordingly in kibana](https://discuss.elastic.co/t/select-option-from-drop-downs-and-update-delete-the-documents-accordingly-in-kibana/349931)

<div class="topic-metadata">

**Author:** [@PRASHANT\_MEHTA](https://discuss.elastic.co/u/PRASHANT_MEHTA)\
**Replies:** 1\
**Last updated:** [December 26, 2023, 12:43pm UTC](https://discuss.elastic.co/t/select-option-from-drop-downs-and-update-delete-the-documents-accordingly-in-kibana/349931 "2023-12-26T12:43:33Z")

</div>

Hello All, I've a requirement in kibana where in I want to select options from drop down(This is possible using options, I am aware of this). Now this is where I'm struggling: After selecting multiple options from drop…

---

## [Using must query in filter section of DSl elastic](https://discuss.elastic.co/t/using-must-query-in-filter-section-of-dsl-elastic/349953)

<div class="topic-metadata">

**Author:** [@Aniket\_Pant](https://discuss.elastic.co/u/Aniket_Pant)\
**Replies:** 1\
**Last updated:** [December 26, 2023, 12:20pm UTC](https://discuss.elastic.co/t/using-must-query-in-filter-section-of-dsl-elastic/349953 "2023-12-26T12:20:25Z")

</div>

GET rds\_database-\*/\_search { "\_source": \["failure\_error\_text"\], "query": { "bool": { "filter": \[ { "must":\[ { "term":{ "status.keyword":"F" …

---

## [Using toJson in big search template](https://discuss.elastic.co/t/using-tojson-in-big-search-template/349951)

<div class="topic-metadata">

**Author:** [@bertie](https://discuss.elastic.co/u/bertie)\
**Replies:** 0\
**Last updated:** [December 26, 2023, 11:51am UTC](https://discuss.elastic.co/t/using-tojson-in-big-search-template/349951 "2023-12-26T11:51:18Z")

</div>

I cannot figure out how I should use the toJson when prototyping templates in the kibana dev console. If I simply use it like others mustache functions like the following example Kibana simply classifies it as a "bad str…

---

## [Duplicate messages with logstash and log4net RollingFileAppender](https://discuss.elastic.co/t/duplicate-messages-with-logstash-and-log4net-rollingfileappender/349932)

<div class="topic-metadata">

**Author:** [@pumiki](https://discuss.elastic.co/u/pumiki)\
**Replies:** 1\
**Last updated:** [December 26, 2023, 10:53am UTC](https://discuss.elastic.co/t/duplicate-messages-with-logstash-and-log4net-rollingfileappender/349932 "2023-12-26T10:53:46Z")

</div>

Hello, My app writes events using log4net with rolling file appender. I get messages duplicated in the file gerenated by logstash. I found the issue mentioned also here However, I am not sure about the solution. Cou…

---

## [Sort is incorrect](https://discuss.elastic.co/t/sort-is-incorrect/349906)

<div class="topic-metadata">

**Author:** [@Binh\_Phan\_Thanh](https://discuss.elastic.co/u/Binh_Phan_Thanh)\
**Replies:** 12\
**Last updated:** [December 26, 2023, 10:45am UTC](https://discuss.elastic.co/t/sort-is-incorrect/349906 "2023-12-26T10:45:04Z")

</div>

My mapping: { "my\_index": { "mappings": { "properties": { "attributesRecommend": { "type": "text", "fields": { "keyword": { "type": "keyword", …

---

## [Add another one sorting to lift 3 docs to positions 3,4,5](https://discuss.elastic.co/t/add-another-one-sorting-to-lift-3-docs-to-positions-3-4-5/349918)

<div class="topic-metadata">

**Author:** [@sahkdevel](https://discuss.elastic.co/u/sahkdevel)\
**Replies:** 2\
**Last updated:** [December 26, 2023, 8:49am UTC](https://discuss.elastic.co/t/add-another-one-sorting-to-lift-3-docs-to-positions-3-4-5/349918 "2023-12-26T08:49:48Z")

</div>

I have a query with several sortings. Here is the sorting part: "sort": \[ "isHistorical", "\_score", { "\_script": { "type": "number", "script": { …

---

## [Lucene : Regex & group by](https://discuss.elastic.co/t/lucene-regex-group-by/349929)

<div class="topic-metadata">

**Author:** [@Jagadeesh\_Venkatesh](https://discuss.elastic.co/u/Jagadeesh_Venkatesh)\
**Replies:** 0\
**Last updated:** [December 26, 2023, 7:59am UTC](https://discuss.elastic.co/t/lucene-regex-group-by/349929 "2023-12-26T07:59:56Z")

</div>

write a regular expression for this " Generating JWT token for user : psi-sci-3 " using Lucene in Kibana search to extract the keyword "psi-sci-3" and group by count by "psi-sci-3"?

---

## [Elasticsearch Java Client Aggregation Exception - all shards failed](https://discuss.elastic.co/t/elasticsearch-java-client-aggregation-exception-all-shards-failed/349860)

<div class="topic-metadata">

**Author:** [@bharath.krishn2](https://discuss.elastic.co/u/bharath.krishn2)\
**Replies:** 7\
**Last updated:** [December 26, 2023, 7:10am UTC](https://discuss.elastic.co/t/elasticsearch-java-client-aggregation-exception-all-shards-failed/349860 "2023-12-26T07:10:28Z")

</div>

Hi, I'm trying to create an aggregation on Elasticsearch through Java client using this below link But I'm getting the exception: co.elastic.clients.elasticsearch.\_types.ElasticsearchException: \[es/search\] failed: \[…

---

## [Logstash with log4net](https://discuss.elastic.co/t/logstash-with-log4net/349919)

<div class="topic-metadata">

**Author:** [@pumiki](https://discuss.elastic.co/u/pumiki)\
**Replies:** 0\
**Last updated:** [December 25, 2023, 11:39pm UTC](https://discuss.elastic.co/t/logstash-with-log4net/349919 "2023-12-25T23:39:20Z")

</div>

Hello, we have c# app (many microservices), running without docker. for now, All the microservices use log4net to log to file. we want to write those logs to log4net. the question is how to do it ? Question 1: w…

---

## [I can not login elastic](https://discuss.elastic.co/t/i-can-not-login-elastic/348450)

<div class="topic-metadata">

**Author:** [@miladmohabati](https://discuss.elastic.co/u/miladmohabati)\
**Replies:** 32\
**Last updated:** [December 25, 2023, 8:10pm UTC](https://discuss.elastic.co/t/i-can-not-login-elastic/348450 "2023-12-25T20:10:10Z")

</div>

hi my disk space is full and I can not login to elastic web how can I clear cache disk plz help me

---

## [Logstash terminating pipelines error "const\_missing, block in JDBC"](https://discuss.elastic.co/t/logstash-terminating-pipelines-error-const-missing-block-in-jdbc/349715)

<div class="topic-metadata">

**Author:** [@SamehSaeed](https://discuss.elastic.co/u/SamehSaeed)\
**Replies:** 3\
**Last updated:** [December 25, 2023, 1:10pm UTC](https://discuss.elastic.co/t/logstash-terminating-pipelines-error-const-missing-block-in-jdbc/349715 "2023-12-25T13:10:21Z")

</div>

Hello, I have a problem when running logstash with multiple pipelines (around 70). Logstash will always terminate some of them if i run more than 30 concurrently 1- First error : \[ERROR\]\[logstash.javapipeline \]\[bkge…

---

## [Error with http-plugin output Encountered non-2xx HTTP code 400](https://discuss.elastic.co/t/error-with-http-plugin-output-encountered-non-2xx-http-code-400/348215)

<div class="topic-metadata">

**Author:** [@bilal\_adoui](https://discuss.elastic.co/u/bilal_adoui)\
**Replies:** 3\
**Last updated:** [December 25, 2023, 10:27am UTC](https://discuss.elastic.co/t/error-with-http-plugin-output-encountered-non-2xx-http-code-400/348215 "2023-12-25T10:27:04Z")

</div>

Hi, I am trying to send a notification from Logstash to our Teams channel, using HTTP plugin however I am getting : \[HTTP Output Failure\] Encountered non-2xx HTTP code 400 {:response\_code=\>400 and this is my output c…

---

## [Elasticsearch Aggregations Pagination](https://discuss.elastic.co/t/elasticsearch-aggregations-pagination/349915)

<div class="topic-metadata">

**Author:** [@Azizi\_BESSEM](https://discuss.elastic.co/u/Azizi_BESSEM)\
**Replies:** 0\
**Last updated:** [December 25, 2023, 9:54am UTC](https://discuss.elastic.co/t/elasticsearch-aggregations-pagination/349915 "2023-12-25T09:54:21Z")

</div>

Dear Elasticsearch Team, I hope this message finds you well. I am currently working with an alert index in Elasticsearch, which contains information such as "device-ref" and "alert type." My goal is to retrieve the late…

---

## [Enabling kibana Audit logs to monitor login/logout activities](https://discuss.elastic.co/t/enabling-kibana-audit-logs-to-monitor-login-logout-activities/349760)

<div class="topic-metadata">

**Author:** [@mangeshmj1992](https://discuss.elastic.co/u/mangeshmj1992)\
**Replies:** 2\
**Last updated:** [December 25, 2023, 8:59am UTC](https://discuss.elastic.co/t/enabling-kibana-audit-logs-to-monitor-login-logout-activities/349760 "2023-12-25T08:59:20Z")

</div>

Hello team, We are enabling kibana Audit logs to monitor login/logout activities. But we need only authentication type logs and event.category: database or web we need to drop. We have added below config in kibana.yml …

---

## [Dec 25th, 2023: \[EN\] How to investigate a Malicious Alert for Threat Hunting in Elastic Security](https://discuss.elastic.co/t/dec-25th-2023-en-how-to-investigate-a-malicious-alert-for-threat-hunting-in-elastic-security/347618)

<div class="topic-metadata">

**Author:** [@Tanisha\_L\_Turner](https://discuss.elastic.co/u/Tanisha_L_Turner)\
**Replies:** 0\
**Last updated:** [December 25, 2023, 8:00am UTC](https://discuss.elastic.co/t/dec-25th-2023-en-how-to-investigate-a-malicious-alert-for-threat-hunting-in-elastic-security/347618 "2023-12-25T08:00:27Z")

</div>

Introduction When investigating malicious alerts in Elastic Security, it is essential to determine the type of malicious activity that is detected from an alert for response and remediation. There are many methods to pe…

---

## [Logstash pipelines not visible in stack monitoring](https://discuss.elastic.co/t/logstash-pipelines-not-visible-in-stack-monitoring/349894)

<div class="topic-metadata">

**Author:** [@SamehSaeed](https://discuss.elastic.co/u/SamehSaeed)\
**Replies:** 4\
**Last updated:** [December 25, 2023, 6:56am UTC](https://discuss.elastic.co/t/logstash-pipelines-not-visible-in-stack-monitoring/349894 "2023-12-25T06:56:04Z")

</div>

I'm unable to monitor pipelines through kibana ==\> So i tried to pick elasticsearch, then ingest pipelines and this error popped up upon trying to install elasticsearch integration ==\> How can i monitor pipelin…

---

## [Elastic agent not sending logs to elastic search](https://discuss.elastic.co/t/elastic-agent-not-sending-logs-to-elastic-search/349909)

<div class="topic-metadata">

**Author:** [@ramapdev](https://discuss.elastic.co/u/ramapdev)\
**Replies:** 0\
**Last updated:** [December 25, 2023, 5:18am UTC](https://discuss.elastic.co/t/elastic-agent-not-sending-logs-to-elastic-search/349909 "2023-12-25T05:18:48Z")

</div>

HI All, i am able to launch the elastic agent and fleet successfully \[ec2-user@ip-172-31-56-159 testlogs\]$ sudo /usr/bin/elastic-agent status ┌─ fleet │ └─ status: (HEALTHY) Connected └─ elastic-agent └─ status: (…

---

## [My grok Pattern is not working using Filebeat](https://discuss.elastic.co/t/my-grok-pattern-is-not-working-using-filebeat/349897)

<div class="topic-metadata">

**Author:** [@Ibrahim\_Kholil](https://discuss.elastic.co/u/Ibrahim_Kholil)\
**Replies:** 1\
**Last updated:** [December 24, 2023, 6:40pm UTC](https://discuss.elastic.co/t/my-grok-pattern-is-not-working-using-filebeat/349897 "2023-12-24T18:40:12Z")

</div>

\*\* ###################### Filebeat Configuration Example #########################\*\* # This file is an example configuration file highlighting only the most common # options. The filebeat.reference.yml file from the sa…

---

## [My data view in kibana has no fields](https://discuss.elastic.co/t/my-data-view-in-kibana-has-no-fields/349902)

<div class="topic-metadata">

**Author:** [@Fatiha](https://discuss.elastic.co/u/Fatiha)\
**Replies:** 3\
**Last updated:** [December 24, 2023, 7:04pm UTC](https://discuss.elastic.co/t/my-data-view-in-kibana-has-no-fields/349902 "2023-12-24T19:04:51Z")

</div>

HI I want to visualize my data from mysql to kibana I create my file logstash.conf input { jdbc { jdbc\_driver\_library =\> "E:/ELK/mysql-connector-java-8.0.17.jar" jdbc\_driver\_class =\> "com.mysql.cj.jdbc.Driver…

---

## [Creating a data view from logstash](https://discuss.elastic.co/t/creating-a-data-view-from-logstash/349899)

<div class="topic-metadata">

**Author:** [@Dor-Alter](https://discuss.elastic.co/u/Dor-Alter)\
**Replies:** 1\
**Last updated:** [December 24, 2023, 6:59pm UTC](https://discuss.elastic.co/t/creating-a-data-view-from-logstash/349899 "2023-12-24T18:59:16Z")

</div>

I have created a pipeline that loads my logs into elasticsearch. When I run the pipeline it works and in the developer console, in elasticsearch, I can see and run queries to the index. However, when I go to discover in …

---

## [Logstash helm chart with Elasticsearch input/output starts over after finishing](https://discuss.elastic.co/t/logstash-helm-chart-with-elasticsearch-input-output-starts-over-after-finishing/349900)

<div class="topic-metadata">

**Author:** [@shaigbdb](https://discuss.elastic.co/u/shaigbdb)\
**Replies:** 0\
**Last updated:** [December 24, 2023, 5:12pm UTC](https://discuss.elastic.co/t/logstash-helm-chart-with-elasticsearch-input-output-starts-over-after-finishing/349900 "2023-12-24T17:12:00Z")

</div>

Hi, I'm using the logstash helm chart with Logstash 8.9.0. The pipeline has an input and an output of Elasticsearch, basically importing an index from one cluster to another (using snapshots or reindex would've been be…

---

## [How to obtain data from multiple vsphere nodes?](https://discuss.elastic.co/t/how-to-obtain-data-from-multiple-vsphere-nodes/349308)

<div class="topic-metadata">

**Author:** [@dianne25](https://discuss.elastic.co/u/dianne25)\
**Replies:** 1\
**Last updated:** [December 24, 2023, 2:52pm UTC](https://discuss.elastic.co/t/how-to-obtain-data-from-multiple-vsphere-nodes/349308 "2023-12-24T14:52:25Z")

</div>

There's vsphere module in the metricbeat to pull data, as described in document here. I can successfuly acquire information from a single host, such as vCenter server. However, when I try to acquire data from more than …

---

## [Change duration after which warning "Datafeed has been retrieving no data for a while" appears](https://discuss.elastic.co/t/change-duration-after-which-warning-datafeed-has-been-retrieving-no-data-for-a-while-appears/348501)

<div class="topic-metadata">

**Author:** [@marmai16](https://discuss.elastic.co/u/marmai16)\
**Replies:** 1\
**Last updated:** [December 24, 2023, 2:36pm UTC](https://discuss.elastic.co/t/change-duration-after-which-warning-datafeed-has-been-retrieving-no-data-for-a-while-appears/348501 "2023-12-24T14:36:53Z")

</div>

Hello everyone, is it possible to change the duration, after which the warning "Datafeed has been retrieving no data for a while" appears relating to an anomaly detection job? It is perfectly fine, that the datafeed oc…

---

## [.ds indices creating automatically in our env](https://discuss.elastic.co/t/ds-indices-creating-automatically-in-our-env/349861)

<div class="topic-metadata">

**Author:** [@Siva\_Karan](https://discuss.elastic.co/u/Siva_Karan)\
**Replies:** 1\
**Last updated:** [December 24, 2023, 2:24pm UTC](https://discuss.elastic.co/t/ds-indices-creating-automatically-in-our-env/349861 "2023-12-24T14:24:59Z")

</div>

Hi Team, After upgrdation of elasticearch from 7.3.2 to 7.17.16 .ds\* index automatically creating like below .ds-ilm-history-5-2023.12.18-000002 .ds-.logs-deprecation.elasticsearch-default-2023.11.18-000001 How to st…

---

## [How is Alert Recovery Decided?](https://discuss.elastic.co/t/how-is-alert-recovery-decided/349874)

<div class="topic-metadata">

**Author:** [@shiktec](https://discuss.elastic.co/u/shiktec)\
**Replies:** 1\
**Last updated:** [December 24, 2023, 2:16pm UTC](https://discuss.elastic.co/t/how-is-alert-recovery-decided/349874 "2023-12-24T14:16:42Z")

</div>

Hi Guys, Have a scenario based questions on alerting , How does ES decides if an alert is "recovered"? Whats the core logic ? i am setting Airflow DAG failure alerts , i receive a document which contains fields DAG:xy…

---

## [Restoring the snapshot in our local cluster](https://discuss.elastic.co/t/restoring-the-snapshot-in-our-local-cluster/349845)

<div class="topic-metadata">

**Author:** [@Shashank\_Nagumantri](https://discuss.elastic.co/u/Shashank_Nagumantri)\
**Replies:** 3\
**Last updated:** [December 24, 2023, 10:31am UTC](https://discuss.elastic.co/t/restoring-the-snapshot-in-our-local-cluster/349845 "2023-12-24T10:31:58Z")

</div>

So, I have an elastic cloud account in which I have created dashboards and stored indices to work with. But now I have installed Elastic Search and Kibana in my local system and I don't want to use the cloud anymore. So,…

[Previous page](https://discuss.elastic.co/latest.md?page=445)

[Next page](https://discuss.elastic.co/latest.md?page=447)
