# Latest

**URL:** https://discuss.elastic.co/latest.md?page=448

[Latest](https://discuss.elastic.co/latest.md) · [Categories](https://discuss.elastic.co/categories.md) · [Tags](https://discuss.elastic.co/tags.md)

**Page:** 449

---

## [Migrated elasticsearch data from a failed node](https://discuss.elastic.co/t/migrated-elasticsearch-data-from-a-failed-node/349814)

<div class="topic-metadata">

**Author:** [@anon85145925](https://discuss.elastic.co/u/anon85145925)\
**Replies:** 1\
**Last updated:** [December 21, 2023, 5:33pm UTC](https://discuss.elastic.co/t/migrated-elasticsearch-data-from-a-failed-node/349814 "2023-12-21T17:33:02Z")

</div>

Hello all, One of our elasticsearch nodes (not a master node) failed yesterday, and by failed it was a human error, when trying to add disk space - the underlying disk was shrinked. We managed to expand the disk again, …

---

## [Create an alert in Kibata when no documents are received](https://discuss.elastic.co/t/create-an-alert-in-kibata-when-no-documents-are-received/349787)

<div class="topic-metadata">

**Author:** [@stobbe](https://discuss.elastic.co/u/stobbe)\
**Replies:** 1\
**Last updated:** [December 21, 2023, 4:36pm UTC](https://discuss.elastic.co/t/create-an-alert-in-kibata-when-no-documents-are-received/349787 "2023-12-21T16:36:15Z")

</div>

I want to create an Alert when no new documents (of a certain type) are created in an index for a certain amount if time. What is the best wat to achieve this? And It would be nice to in corporate this in the standard A…

---

## [Determine the user that acknowledged an Alert](https://discuss.elastic.co/t/determine-the-user-that-acknowledged-an-alert/349426)

<div class="topic-metadata">

**Author:** [@lastshadow](https://discuss.elastic.co/u/lastshadow)\
**Replies:** 5\
**Last updated:** [December 21, 2023, 4:21pm UTC](https://discuss.elastic.co/t/determine-the-user-that-acknowledged-an-alert/349426 "2023-12-21T16:21:32Z")

</div>

I have several SOC analysts in my SIEM and need to figure out the following: How do I determine who acknowledged an alert? How can the analysts filter their acknowledged alerts so they only see what they have acknowled…

---

## [Unable to upgrade ECK since v2.7.0](https://discuss.elastic.co/t/unable-to-upgrade-eck-since-v2-7-0/347915)

<div class="topic-metadata">

**Author:** [@Shiftmaj](https://discuss.elastic.co/u/Shiftmaj)\
**Replies:** 1\
**Last updated:** [December 21, 2023, 3:09pm UTC](https://discuss.elastic.co/t/unable-to-upgrade-eck-since-v2-7-0/347915 "2023-12-21T15:09:38Z")

</div>

Hi, I tried to upgrade ECK from version 2.7.0. Unfortunately, ECK version 2.8.0 and up are unable to manage my Elastic cluster. I upgraded Elastic a couple of time with ECK version 2.7.0 and it actually runs version 8.9…

---

## [Recommended exceptions for Elastic Endpoint](https://discuss.elastic.co/t/recommended-exceptions-for-elastic-endpoint/349545)

<div class="topic-metadata">

**Author:** [@slash24](https://discuss.elastic.co/u/slash24)\
**Replies:** 2\
**Last updated:** [December 21, 2023, 2:53pm UTC](https://discuss.elastic.co/t/recommended-exceptions-for-elastic-endpoint/349545 "2023-12-21T14:53:26Z")

</div>

We've got elastic (8.8) defend on few hundreds windows-servers, but also rely on Windows Defender. Due to this, we want to make sure we exclude them from one another. From Windows Defender, what processes, folders or fi…

---

## [Parsing Exception - "no \[query\] registered for \[has\_child\]"](https://discuss.elastic.co/t/parsing-exception-no-query-registered-for-has-child/349799)

<div class="topic-metadata">

**Author:** [@Prayas\_Arora](https://discuss.elastic.co/u/Prayas_Arora)\
**Replies:** 1\
**Last updated:** [December 21, 2023, 2:13pm UTC](https://discuss.elastic.co/t/parsing-exception-no-query-registered-for-has-child/349799 "2023-12-21T14:13:17Z")

</div>

Hi I was using ES version 5.0.5. Recently I made a security patch update that takes it me to 5.0.6. Earlier it was working absolutely fine but now It have started throwing the following error - Elasticsearch::Transport…

---

## [Osquery yara rules](https://discuss.elastic.co/t/osquery-yara-rules/349795)

<div class="topic-metadata">

**Author:** [@sh1dow3r](https://discuss.elastic.co/u/sh1dow3r)\
**Replies:** 0\
**Last updated:** [December 21, 2023, 12:57pm UTC](https://discuss.elastic.co/t/osquery-yara-rules/349795 "2023-12-21T12:57:35Z")

</div>

Hey there.. I've already tried slack but no luck; hopefully someone here has encounter this issue and solved it. I have over 50 yara rules stored on gitlab in one file that I want to sweep the environment with the elas…

---

## [How to reshard the indices to overcome latency during high traffic in elasticsearch cluster](https://discuss.elastic.co/t/how-to-reshard-the-indices-to-overcome-latency-during-high-traffic-in-elasticsearch-cluster/349677)

<div class="topic-metadata">

**Author:** [@Karthikeyan\_Amaresan](https://discuss.elastic.co/u/Karthikeyan_Amaresan)\
**Replies:** 2\
**Last updated:** [December 21, 2023, 10:44am UTC](https://discuss.elastic.co/t/how-to-reshard-the-indices-to-overcome-latency-during-high-traffic-in-elasticsearch-cluster/349677 "2023-12-21T10:44:08Z")

</div>

During high traffic times, our Elasticsearch cluster is experiencing latency, and we are considering a resharding strategy to optimize performance. Below is our current index setup and the proposed resharding plan: Curr…

---

## [How to use timefilter element to filter time and affect to some element that integrate with itself?](https://discuss.elastic.co/t/how-to-use-timefilter-element-to-filter-time-and-affect-to-some-element-that-integrate-with-itself/349781)

<div class="topic-metadata">

**Author:** [@Dy\_Vanrith](https://discuss.elastic.co/u/Dy_Vanrith)\
**Replies:** 0\
**Last updated:** [December 21, 2023, 9:40am UTC](https://discuss.elastic.co/t/how-to-use-timefilter-element-to-filter-time-and-affect-to-some-element-that-integrate-with-itself/349781 "2023-12-21T09:40:22Z")

</div>

Example i have 2 element One element for report canvas base on date that i want to filter filters | essql query= { string "SELECT \* FROM "2023.12.\*" " } | markdown " {{#each rows}} Total Rejected Total Retract …

---

## [Alerts not working (stack version 8.2)](https://discuss.elastic.co/t/alerts-not-working-stack-version-8-2/349773)

<div class="topic-metadata">

**Author:** [@ooaleksiienko](https://discuss.elastic.co/u/ooaleksiienko)\
**Replies:** 0\
**Last updated:** [December 21, 2023, 8:32am UTC](https://discuss.elastic.co/t/alerts-not-working-stack-version-8-2/349773 "2023-12-21T08:32:46Z")

</div>

Problem with: Installing namespace-level resources and creating concrete index for .alerts-security.alerts-default when restarting Kibana I've checked and can see that after fleet setup next Component Templates downlo…

---

## [Apm for django, filter errors by cusotm field](https://discuss.elastic.co/t/apm-for-django-filter-errors-by-cusotm-field/349762)

<div class="topic-metadata">

**Author:** [@k\_cf](https://discuss.elastic.co/u/k_cf)\
**Replies:** 1\
**Last updated:** [December 21, 2023, 8:03am UTC](https://discuss.elastic.co/t/apm-for-django-filter-errors-by-cusotm-field/349762 "2023-12-21T08:03:12Z")

</div>

I have set up elastic apm for a django project with logging (elasticapm.contrib.django.handlers.LoggingHandler). Upon logging a message as follows: logger.exception( custom\_logging\_message, exc\_info=True, ex…

---

## [Dec 21st, 2023: \[RO\] SLO-ul rău, SLO-ul bun: o aventură pe tema SRE](https://discuss.elastic.co/t/dec-21st-2023-ro-slo-ul-rau-slo-ul-bun-o-aventura-pe-tema-sre/347305)

<div class="topic-metadata">

**Author:** [@virginiadiana.todea](https://discuss.elastic.co/u/virginiadiana.todea)\
**Replies:** 0\
**Last updated:** [December 21, 2023, 8:00am UTC](https://discuss.elastic.co/t/dec-21st-2023-ro-slo-ul-rau-slo-ul-bun-o-aventura-pe-tema-sre/347305 "2023-12-21T08:00:44Z")

</div>

This post is also available in English. This post is also available in Espagnol. Dacă te-ai aventurat vreodată în orașul SRE, există șanse foarte mari să fi întâlnit deja unele dintre personajele mele preferate: SLO…

---

## [Dec 21st, 2023: \[EN\] Good SLO, Bad SLO: an SRE adventure theme](https://discuss.elastic.co/t/dec-21st-2023-en-good-slo-bad-slo-an-sre-adventure-theme/347304)

<div class="topic-metadata">

**Author:** [@virginiadiana.todea](https://discuss.elastic.co/u/virginiadiana.todea)\
**Replies:** 0\
**Last updated:** [December 21, 2023, 8:00am UTC](https://discuss.elastic.co/t/dec-21st-2023-en-good-slo-bad-slo-an-sre-adventure-theme/347304 "2023-12-21T08:00:44Z")

</div>

This post is also available in espagnol. This post is also available in romanian. If you ever endeavoured in the SRE town, there is a very good chance that you already have met some of my favourite characters: the S…

---

## [Dec 21st, 2023: \[ES\] El SLO bueno, el SLO malo: una aventura SRE](https://discuss.elastic.co/t/dec-21st-2023-es-el-slo-bueno-el-slo-malo-una-aventura-sre/347306)

<div class="topic-metadata">

**Author:** [@virginiadiana.todea](https://discuss.elastic.co/u/virginiadiana.todea)\
**Replies:** 0\
**Last updated:** [December 21, 2023, 8:00am UTC](https://discuss.elastic.co/t/dec-21st-2023-es-el-slo-bueno-el-slo-malo-una-aventura-sre/347306 "2023-12-21T08:00:44Z")

</div>

This post is also available in English. This post is also available in Romanian. Si alguna vez te aventuraste en la ciudad de los SRE, es muy probable que ya hayas conocido a algunos de mis personajes favoritos: SLO…

---

## [Extracting nested fileds with grok or kv](https://discuss.elastic.co/t/extracting-nested-fileds-with-grok-or-kv/349766)

<div class="topic-metadata">

**Author:** [@cass1ope1a](https://discuss.elastic.co/u/cass1ope1a)\
**Replies:** 0\
**Last updated:** [December 21, 2023, 7:29am UTC](https://discuss.elastic.co/t/extracting-nested-fileds-with-grok-or-kv/349766 "2023-12-21T07:29:38Z")

</div>

I have logs like: Server response. Body={"valid":\[{"someId":"12345","someType":"somevalue123","isSome":true}\],"invalid":\[\]} current pipeline config: if \[syslog\_tag\] =~ "json" { json { source =\> root\_…

---

## [Dashboard level DSL filter does not work for Vega/Aggregate charts](https://discuss.elastic.co/t/dashboard-level-dsl-filter-does-not-work-for-vega-aggregate-charts/349746)

<div class="topic-metadata">

**Author:** [@xiyuewan](https://discuss.elastic.co/u/xiyuewan)\
**Replies:** 3\
**Last updated:** [December 20, 2023, 10:48pm UTC](https://discuss.elastic.co/t/dashboard-level-dsl-filter-does-not-work-for-vega-aggregate-charts/349746 "2023-12-20T22:48:25Z")

</div>

Hello - I have a dashboard level DSL filter (geo filter) and it won't apply to aggregate charts and vega charts, but works fine for Lens. Is this expected?

---

## [Create a Java Query from a DSL terms query](https://discuss.elastic.co/t/create-a-java-query-from-a-dsl-terms-query/349584)

<div class="topic-metadata">

**Author:** [@Edgar\_Osorio](https://discuss.elastic.co/u/Edgar_Osorio)\
**Replies:** 2\
**Last updated:** [December 20, 2023, 9:52pm UTC](https://discuss.elastic.co/t/create-a-java-query-from-a-dsl-terms-query/349584 "2023-12-20T21:52:46Z")

</div>

Given the following Query { "query":{ "bool" : { "must" : \[ { "terms" : { "\_id" : \["8606874","21387518","16704862","23947520","23897437","1050114","24967566","50356…

---

## [Question about parsed files](https://discuss.elastic.co/t/question-about-parsed-files/349747)

<div class="topic-metadata">

**Author:** [@astateofmind](https://discuss.elastic.co/u/astateofmind)\
**Replies:** 1\
**Last updated:** [December 20, 2023, 7:08pm UTC](https://discuss.elastic.co/t/question-about-parsed-files/349747 "2023-12-20T19:08:46Z")

</div>

Quite simple: If I configure a bunch of log files as paths and I apply that config to a diverse set of servers (so some servers will not have some of those log files) will that affect performance or anything? Lets say …

---

## [Persistent ECS warning](https://discuss.elastic.co/t/persistent-ecs-warning/349743)

<div class="topic-metadata">

**Author:** [@Chris\_Stone](https://discuss.elastic.co/u/Chris_Stone)\
**Replies:** 3\
**Last updated:** [December 20, 2023, 6:03pm UTC](https://discuss.elastic.co/t/persistent-ecs-warning/349743 "2023-12-20T18:03:45Z")

</div>

logstash 8.11.3 Can anyone tell me why with the following config, and everything else at the default install, why I continue to get the \[logstash.codecs.jsonlines\] ECS compatibility is enabled but \`target\` option was n…

---

## [Time-series data out of order](https://discuss.elastic.co/t/time-series-data-out-of-order/349741)

<div class="topic-metadata">

**Author:** [@lkw](https://discuss.elastic.co/u/lkw)\
**Replies:** 0\
**Last updated:** [December 20, 2023, 4:54pm UTC](https://discuss.elastic.co/t/time-series-data-out-of-order/349741 "2023-12-20T16:54:21Z")

</div>

I have a data stream in use for some custom application logs. There are about 10 months of logs in it and a handful of rolled-over backing indices. I also have about 3 years worth of historic application logs that I'd l…

---

## [How to add permission for short url for user?](https://discuss.elastic.co/t/how-to-add-permission-for-short-url-for-user/349713)

<div class="topic-metadata">

**Author:** [@PeLbmaN](https://discuss.elastic.co/u/PeLbmaN)\
**Replies:** 1\
**Last updated:** [December 20, 2023, 4:23pm UTC](https://discuss.elastic.co/t/how-to-add-permission-for-short-url-for-user/349713 "2023-12-20T16:23:04Z")

</div>

I have a question about how to add the ability to create short links, which role is responsible for this (I have a basic license)?

---

## [How to select multiple new index patterns in Kiban](https://discuss.elastic.co/t/how-to-select-multiple-new-index-patterns-in-kiban/349456)

<div class="topic-metadata">

**Author:** [@Satsan](https://discuss.elastic.co/u/Satsan)\
**Replies:** 2\
**Last updated:** [December 20, 2023, 3:58pm UTC](https://discuss.elastic.co/t/how-to-select-multiple-new-index-patterns-in-kiban/349456 "2023-12-20T15:58:24Z")

</div>

How to efficiently add or select multiple new index patterns in Kibana? I need to incorporate over 90 + directory logs into the Kibana dashboard. Manually adding the index pattern for each of them is time-consuming. Is t…

---

## [Enrich document with data from same index](https://discuss.elastic.co/t/enrich-document-with-data-from-same-index/349705)

<div class="topic-metadata">

**Author:** [@rickardo](https://discuss.elastic.co/u/rickardo)\
**Replies:** 8\
**Last updated:** [December 20, 2023, 3:37pm UTC](https://discuss.elastic.co/t/enrich-document-with-data-from-same-index/349705 "2023-12-20T15:37:31Z")

</div>

Hi, we got one index that we insert documents where one can follow e.g. a session and what is done, i.e.: document 1; sessionId = 17 type=created country=DE document 2: sessionId = 17 type=action now at insertion…

---

## [Logstash with ouput clickhouse plugin more than 80% logs are missing](https://discuss.elastic.co/t/logstash-with-ouput-clickhouse-plugin-more-than-80-logs-are-missing/349724)

<div class="topic-metadata">

**Author:** [@Anandh\_Kumar1](https://discuss.elastic.co/u/Anandh_Kumar1)\
**Replies:** 1\
**Last updated:** [December 20, 2023, 2:58pm UTC](https://discuss.elastic.co/t/logstash-with-ouput-clickhouse-plugin-more-than-80-logs-are-missing/349724 "2023-12-20T14:58:11Z")

</div>

I am using logstash version 7.17.15 in production environment, In that i am using the ouput plugin is clickhouse and the version is 20.8.3.18. Using the filebeat I am moving the logs into logstash which is there is remo…

---

## [Stack\_Elasticsearch\_Log\_Kibana7.17.15](https://discuss.elastic.co/t/stack-elasticsearch-log-kibana7-17-15/349714)

<div class="topic-metadata">

**Author:** [@sossoulokoariel](https://discuss.elastic.co/u/sossoulokoariel)\
**Replies:** 4\
**Last updated:** [December 20, 2023, 2:57pm UTC](https://discuss.elastic.co/t/stack-elasticsearch-log-kibana7-17-15/349714 "2023-12-20T14:57:12Z")

</div>

Help me

---

## [Elastic Endpoint Restarted](https://discuss.elastic.co/t/elastic-endpoint-restarted/349375)

<div class="topic-metadata">

**Author:** [@sourcreamnormanbates](https://discuss.elastic.co/u/sourcreamnormanbates)\
**Replies:** 2\
**Last updated:** [December 20, 2023, 2:51pm UTC](https://discuss.elastic.co/t/elastic-endpoint-restarted/349375 "2023-12-20T14:51:36Z")

</div>

I'm trying to understand what happened recently where this command ran on a desktop "sc.exe start ElasticEndpoint restarted" We also use SentinelOne, and SentinelOne detected that activity as malicious, so I'm trying to…

---

## [Bucket aggregation with java api version 8.11](https://discuss.elastic.co/t/bucket-aggregation-with-java-api-version-8-11/349729)

<div class="topic-metadata">

**Author:** [@Darth\_vader\_22](https://discuss.elastic.co/u/Darth_vader_22)\
**Replies:** 0\
**Last updated:** [December 20, 2023, 1:54pm UTC](https://discuss.elastic.co/t/bucket-aggregation-with-java-api-version-8-11/349729 "2023-12-20T13:54:51Z")

</div>

Hi everyone ! can anyone please help me convert below query in java i'm struggling with the aggregation part i have been stuck to this for days now , any help would be appreciated { "query": {}, "aggregations": { "a…

---

## [Change number of shards and refresh interval for all datastreams of Elastic Agent](https://discuss.elastic.co/t/change-number-of-shards-and-refresh-interval-for-all-datastreams-of-elastic-agent/349725)

<div class="topic-metadata">

**Author:** [@leandrojmp](https://discuss.elastic.co/u/leandrojmp)\
**Replies:** 0\
**Last updated:** [December 20, 2023, 1:14pm UTC](https://discuss.elastic.co/t/change-number-of-shards-and-refresh-interval-for-all-datastreams-of-elastic-agent/349725 "2023-12-20T13:14:35Z")

</div>

Hello, Currently all the data collected by the Elastic Agent integrations uses a default number of shards of 1 and a refresh interval of 1s, those configurations are not optimal for our use case and are starting to impa…

---

## [Dedicated ILM for each telemetry data stream](https://discuss.elastic.co/t/dedicated-ilm-for-each-telemetry-data-stream/349719)

<div class="topic-metadata">

**Author:** [@jan-nemo](https://discuss.elastic.co/u/jan-nemo)\
**Replies:** 0\
**Last updated:** [December 20, 2023, 12:39pm UTC](https://discuss.elastic.co/t/dedicated-ilm-for-each-telemetry-data-stream/349719 "2023-12-20T12:39:49Z")

</div>

Greetings! We are in the process of integrating Elastic Observability into our system. At present, we operate a variety of unique services. Each of these services transmits telemetry data first to an OTEL collector and …

---

## [Installation of logstash-output-opensearch in an airgap environment(no internet access on server)](https://discuss.elastic.co/t/installation-of-logstash-output-opensearch-in-an-airgap-environment-no-internet-access-on-server/349717)

<div class="topic-metadata">

**Author:** [@kushak\_kain](https://discuss.elastic.co/u/kushak_kain)\
**Replies:** 2\
**Last updated:** [December 20, 2023, 12:34pm UTC](https://discuss.elastic.co/t/installation-of-logstash-output-opensearch-in-an-airgap-environment-no-internet-access-on-server/349717 "2023-12-20T12:34:06Z")

</div>

Hello Experts, I need your assistance in installing logstash-output-opensearch in an airgap environment(our servers can not connect to internet) We are receiving the following error while executing the command : ./log…

[Previous page](https://discuss.elastic.co/latest.md?page=447)

[Next page](https://discuss.elastic.co/latest.md?page=449)
