# Latest

**URL:** https://discuss.elastic.co/latest.md?page=452

[Latest](https://discuss.elastic.co/latest.md) · [Categories](https://discuss.elastic.co/categories.md) · [Tags](https://discuss.elastic.co/tags.md)

**Page:** 453

---

## [Best data structure for sensor data](https://discuss.elastic.co/t/best-data-structure-for-sensor-data/349497)

<div class="topic-metadata">

**Author:** [@allatrue](https://discuss.elastic.co/u/allatrue)\
**Replies:** 1\
**Last updated:** [December 17, 2023, 5:10pm UTC](https://discuss.elastic.co/t/best-data-structure-for-sensor-data/349497 "2023-12-17T17:10:18Z")

</div>

Hello everyone, We are setting up a cluster for collecting of IoT/sensor data. And I'm not sure what is the best structure for this kind of data. The simplest way would be to use single index for all similar (numeric) d…

---

## [Same enterprise license on two different operator in two separate K8s clusters](https://discuss.elastic.co/t/same-enterprise-license-on-two-different-operator-in-two-separate-k8s-clusters/349420)

<div class="topic-metadata">

**Author:** [@Nicoletta](https://discuss.elastic.co/u/Nicoletta)\
**Replies:** 1\
**Last updated:** [December 17, 2023, 5:07pm UTC](https://discuss.elastic.co/t/same-enterprise-license-on-two-different-operator-in-two-separate-k8s-clusters/349420 "2023-12-17T17:07:33Z")

</div>

Hello, is it possible to use the same Enterprise License on two different Elasticsearch operators in two separate Kubernetes clusters? Thanks, Nicoletta

---

## [Podman or Docker CE 20.10 for best performance?](https://discuss.elastic.co/t/podman-or-docker-ce-20-10-for-best-performance/348308)

<div class="topic-metadata">

**Author:** [@jojsf](https://discuss.elastic.co/u/jojsf)\
**Replies:** 4\
**Last updated:** [December 17, 2023, 4:35pm UTC](https://discuss.elastic.co/t/podman-or-docker-ce-20-10-for-best-performance/348308 "2023-12-17T16:35:20Z")

</div>

Hi, I would like to know if anyone have noticed any performance issues with Redhat 8 and Podaman? We are in the decision to either use podman or docker ce 20.10 on red hat 8 on new hw, cisco ucs 240 m7 with nvme drives…

---

## [Cannot login to Elastic Cloud](https://discuss.elastic.co/t/cannot-login-to-elastic-cloud/349439)

<div class="topic-metadata">

**Author:** [@develop-finline](https://discuss.elastic.co/u/develop-finline)\
**Replies:** 4\
**Last updated:** [December 17, 2023, 3:50pm UTC](https://discuss.elastic.co/t/cannot-login-to-elastic-cloud/349439 "2023-12-17T15:50:09Z")

</div>

Hi team, I'm not able to reach out to any of my clusters, I'm not able to login to Elastic Cloud. Endpoints of clusters aren't available. I've tried to reset my elastic cloud account password but still cannot login a…

---

## [Registery blow ups](https://discuss.elastic.co/t/registery-blow-ups/349500)

<div class="topic-metadata">

**Author:** [@stefws](https://discuss.elastic.co/u/stefws)\
**Replies:** 3\
**Last updated:** [December 17, 2023, 1:46pm UTC](https://discuss.elastic.co/t/registery-blow-ups/349500 "2023-12-17T13:46:15Z")

</div>

Hey, Running a filebeat on a NFS share which stores backup of json message files from our application's communication with external applications and wonder how to best avoid registery to blow up in size while also ensur…

---

## [Sir I have issue with storage for 7 days](https://discuss.elastic.co/t/sir-i-have-issue-with-storage-for-7-days/349509)

<div class="topic-metadata">

**Author:** [@zabtech](https://discuss.elastic.co/u/zabtech)\
**Replies:** 3\
**Last updated:** [December 17, 2023, 12:42pm UTC](https://discuss.elastic.co/t/sir-i-have-issue-with-storage-for-7-days/349509 "2023-12-17T12:42:40Z")

</div>

I have issue with storage, my storage is full more than 7 days, I can't use APM for 7 days also, I try to created cases and use enterprise plan, but it's look like no one really can't help me. What can I do with my issue…

---

## [Dec 17th, 2023: \[EN\] Elasticsearch geospatial; go beyond OpenSearch](https://discuss.elastic.co/t/dec-17th-2023-en-elasticsearch-geospatial-go-beyond-opensearch/345512)

<div class="topic-metadata">

**Author:** [@Nathan\_Reese](https://discuss.elastic.co/u/Nathan_Reese)\
**Replies:** 0\
**Last updated:** [December 17, 2023, 8:00am UTC](https://discuss.elastic.co/t/dec-17th-2023-en-elasticsearch-geospatial-go-beyond-opensearch/345512 "2023-12-17T08:00:10Z")

</div>

In 2021, OpenSearch and OpenSearch Dashboards began as a fork from Elasticsearch and Kibana. Although they share similar lineage, OpenSearch and OpenSearch Dashboards do not provide the same functionality. At the time…

---

## [Logstash ran as service won't read logs only when ran through the command line](https://discuss.elastic.co/t/logstash-ran-as-service-wont-read-logs-only-when-ran-through-the-command-line/349403)

<div class="topic-metadata">

**Author:** [@ELI\_MA](https://discuss.elastic.co/u/ELI_MA)\
**Replies:** 14\
**Last updated:** [December 17, 2023, 5:10am UTC](https://discuss.elastic.co/t/logstash-ran-as-service-wont-read-logs-only-when-ran-through-the-command-line/349403 "2023-12-17T05:10:27Z")

</div>

Hi, I’m running Logstash on SUSE Linux where I’ve installed the RPM package for compatibility. Currently, When I start logstash as a service sudo systemctl stop logstash.service and check service status it seems to be r…

---

## [Not able to search a specific log file in Kibana UI](https://discuss.elastic.co/t/not-able-to-search-a-specific-log-file-in-kibana-ui/347428)

<div class="topic-metadata">

**Author:** [@kaushalshriyan](https://discuss.elastic.co/u/kaushalshriyan)\
**Replies:** 3\
**Last updated:** [December 17, 2023, 5:02am UTC](https://discuss.elastic.co/t/not-able-to-search-a-specific-log-file-in-kibana-ui/347428 "2023-12-17T05:02:03Z")

</div>

Hi, I am running the Elastic Stack on Red Hat Enterprise Linux release 8.8 (Ootpa) and the versions are as below. # rpm -qa | grep logstash logstash-8.11.0-1.x86\_64 # rpm -qa | grep elasticsearch elasticsearch-8.11.0-1…

---

## [Elastic Synthetic Monitoring - Soft Assertions](https://discuss.elastic.co/t/elastic-synthetic-monitoring-soft-assertions/349498)

<div class="topic-metadata">

**Author:** [@zx8086](https://discuss.elastic.co/u/zx8086)\
**Replies:** 0\
**Last updated:** [December 17, 2023, 3:56am UTC](https://discuss.elastic.co/t/elastic-synthetic-monitoring-soft-assertions/349498 "2023-12-17T03:56:45Z")

</div>

How do you do soft assertions in synthetics to skip or fail as step, but run the subsequent steps after ?

---

## [Elasticsearch upgrade assistant](https://discuss.elastic.co/t/elasticsearch-upgrade-assistant/349447)

<div class="topic-metadata">

**Author:** [@jaykb77](https://discuss.elastic.co/u/jaykb77)\
**Replies:** 2\
**Last updated:** [December 16, 2023, 11:26pm UTC](https://discuss.elastic.co/t/elasticsearch-upgrade-assistant/349447 "2023-12-16T23:26:59Z")

</div>

Hi all, We are trying to upgrade our Elasticsearch cluster from 7.17 to 8.X and found that its recommended to use Upgrade assistant for this. But we do not use Kibana in our cluster. The ES is acting as a search backend…

---

## [Dec 16th, 2023: \[PT\] Sinfonia da Eficiência: AIOps Orquestrando a Excelência Operacional](https://discuss.elastic.co/t/dec-16th-2023-pt-sinfonia-da-eficiencia-aiops-orquestrando-a-excelencia-operacional/347297)

<div class="topic-metadata">

**Author:** [@Priscilla\_Parodi](https://discuss.elastic.co/u/Priscilla_Parodi)\
**Replies:** 0\
**Last updated:** [December 16, 2023, 8:00am UTC](https://discuss.elastic.co/t/dec-16th-2023-pt-sinfonia-da-eficiencia-aiops-orquestrando-a-excelencia-operacional/347297 "2023-12-16T08:00:54Z")

</div>

This post is also available in english. Antes de explorarmos o AIOps, vamos esclarecer alguns conceitos-chave relacionados a alguns (não todos :sweat\_smile:) dos diferentes "Ops": DevOps: DEV + OPS Você provavelme…

---

## [Dec 16th, 2023: \[EN\] Symphony of Efficiency: AIOps Orchestrating Operational Excellence](https://discuss.elastic.co/t/dec-16th-2023-en-symphony-of-efficiency-aiops-orchestrating-operational-excellence/347295)

<div class="topic-metadata">

**Author:** [@Priscilla\_Parodi](https://discuss.elastic.co/u/Priscilla_Parodi)\
**Replies:** 0\
**Last updated:** [December 16, 2023, 8:00am UTC](https://discuss.elastic.co/t/dec-16th-2023-en-symphony-of-efficiency-aiops-orchestrating-operational-excellence/347295 "2023-12-16T08:00:54Z")

</div>

This post is also available in portuguese. Before we explore AIOps, let’s clarify some key concepts related to some \[not all :sweat\_smile:\] of the different Ops: DevOps: DEV + OPS You've probably already heard of …

---

## [Some fields are missing after rename.](https://discuss.elastic.co/t/some-fields-are-missing-after-rename/349459)

<div class="topic-metadata">

**Author:** [@JHub-Wei](https://discuss.elastic.co/u/JHub-Wei)\
**Replies:** 11\
**Last updated:** [December 16, 2023, 2:22am UTC](https://discuss.elastic.co/t/some-fields-are-missing-after-rename/349459 "2023-12-16T02:22:57Z")

</div>

After logstash-oss is upgraded from 7.6.0 to 7.12.1, some fields are lost after parsing the nested JSON data of Kafka. Kafka JSON example data: {"timestamp":1702630468791,"region":"cn-north-3","eventId":"QER\_INFO","args…

---

## [Plugin installation issue, probably related to YAML](https://discuss.elastic.co/t/plugin-installation-issue-probably-related-to-yaml/349404)

<div class="topic-metadata">

**Author:** [@jediD83](https://discuss.elastic.co/u/jediD83)\
**Replies:** 4\
**Last updated:** [December 15, 2023, 10:38pm UTC](https://discuss.elastic.co/t/plugin-installation-issue-probably-related-to-yaml/349404 "2023-12-15T22:38:05Z")

</div>

Good day. The installation of the Elasticsearch's plugin for Zammad should be straightforward. After apt install elasticsearch using Set up Elasticsearch guide, its just sudo /usr/share/elasticsearch/bin/elasticsearch-p…

---

## [What could be the cause of error ""](https://discuss.elastic.co/t/what-could-be-the-cause-of-error/349436)

<div class="topic-metadata">

**Author:** [@Chen\_Wei](https://discuss.elastic.co/u/Chen_Wei)\
**Replies:** 1\
**Last updated:** [December 15, 2023, 7:07pm UTC](https://discuss.elastic.co/t/what-could-be-the-cause-of-error/349436 "2023-12-15T19:07:29Z")

</div>

I recently met a error about timestamp, the error appears after the logstash pipeline start and work for a while. I could not reproduce it. But I wonder where the error could happen. Does it happen in the input plugin?…

---

## [Kibana / Remplacement d'une valeur en fonction de deux autres pour une variable](https://discuss.elastic.co/t/kibana-remplacement-dune-valeur-en-fonction-de-deux-autres-pour-une-variable/349471)

<div class="topic-metadata">

**Author:** [@Phildefer](https://discuss.elastic.co/u/Phildefer)\
**Replies:** 4\
**Last updated:** [December 15, 2023, 7:19pm UTC](https://discuss.elastic.co/t/kibana-remplacement-dune-valeur-en-fonction-de-deux-autres-pour-une-variable/349471 "2023-12-15T19:19:38Z")

</div>

Bonjour, J'ai dans un index deux variables X et Y qui contiennent des valeurs textuelles (A ou B ou C ou D). Je souhaiterais faire en sorte que lorsqu'un document a pour valeur A ou B dans les variables X ou Y, cette va…

---

## [Drop complete row or message](https://discuss.elastic.co/t/drop-complete-row-or-message/349415)

<div class="topic-metadata">

**Author:** [@kundan](https://discuss.elastic.co/u/kundan)\
**Replies:** 1\
**Last updated:** [December 15, 2023, 7:08pm UTC](https://discuss.elastic.co/t/drop-complete-row-or-message/349415 "2023-12-15T19:08:38Z")

</div>

Hi, I want to drop full row based on one of the field. I am using following in filter. filter { grok { match =\> {"message" =\> \["%{IP:ip} %{SPACE}\\{user:%{USERNAME:UserId}\\}"\]} } date…

---

## [Show Alerts Data in Custom Dashboard](https://discuss.elastic.co/t/show-alerts-data-in-custom-dashboard/349466)

<div class="topic-metadata">

**Author:** [@erikg](https://discuss.elastic.co/u/erikg)\
**Replies:** 2\
**Last updated:** [December 15, 2023, 6:48pm UTC](https://discuss.elastic.co/t/show-alerts-data-in-custom-dashboard/349466 "2023-12-15T18:48:48Z")

</div>

Hello, I want to see if its possible to recreate alerts visualizations in a custom dashboard. Currently the alerts are under their areas (like Observability, Security). I wanted to see if I can make a similar visualiz…

---

## [Search any term startswith including special char](https://discuss.elastic.co/t/search-any-term-startswith-including-special-char/349288)

<div class="topic-metadata">

**Author:** [@Sankar\_S](https://discuss.elastic.co/u/Sankar_S)\
**Replies:** 4\
**Last updated:** [December 15, 2023, 4:48pm UTC](https://discuss.elastic.co/t/search-any-term-startswith-including-special-char/349288 "2023-12-15T16:48:45Z")

</div>

Hello All, I have a field called title and it has value "title" : "Toddler- $kitkat @taste &roll ^yart !here #you %ice ^oops \*jam (pot) \[beat\] pep |old {jet} \`egg /lol" For given input i would like to match any term s…

---

## [Logstash 8.10.3 ERROR Badly formatted index, after interpolation still contains placeholder](https://discuss.elastic.co/t/logstash-8-10-3-error-badly-formatted-index-after-interpolation-still-contains-placeholder/349377)

<div class="topic-metadata">

**Author:** [@efrainMZ](https://discuss.elastic.co/u/efrainMZ)\
**Replies:** 5\
**Last updated:** [December 15, 2023, 4:33pm UTC](https://discuss.elastic.co/t/logstash-8-10-3-error-badly-formatted-index-after-interpolation-still-contains-placeholder/349377 "2023-12-15T16:33:43Z")

</div>

good day! I am trying to extract data from redis using logstash, the data comes from an apm version 8.10.3 but I receive a warining that does not allow me to see the data in kibana. The log I receive is the following: …

---

## [Implementing Custom BERT-Based Text Embedding Model for Semantic Search in Elasticsearch](https://discuss.elastic.co/t/implementing-custom-bert-based-text-embedding-model-for-semantic-search-in-elasticsearch/349434)

<div class="topic-metadata">

**Author:** [@Ali\_Zare](https://discuss.elastic.co/u/Ali_Zare)\
**Replies:** 1\
**Last updated:** [December 15, 2023, 4:10pm UTC](https://discuss.elastic.co/t/implementing-custom-bert-based-text-embedding-model-for-semantic-search-in-elasticsearch/349434 "2023-12-15T16:10:22Z")

</div>

Hello everyone, I'm exploring the possibility of setting up a custom text embedding model using the BERT architecture for semantic search within Elasticsearch. I'm curious if it's feasible to integrate a personalized te…

---

## [SNMP uptime monitoring](https://discuss.elastic.co/t/snmp-uptime-monitoring/348827)

<div class="topic-metadata">

**Author:** [@Martin\_Hood](https://discuss.elastic.co/u/Martin_Hood)\
**Replies:** 3\
**Last updated:** [December 15, 2023, 3:59pm UTC](https://discuss.elastic.co/t/snmp-uptime-monitoring/348827 "2023-12-15T15:59:07Z")

</div>

Hi, I'm currently in the planning stage of an observability system. For a number of hosts snmp is the most effective way to check status but, as I understand, this isn't currently supported by Heartbeat. Is it possible…

---

## [SystemCallError, :message=\>"Unknown error (SystemCallError)](https://discuss.elastic.co/t/systemcallerror-message-unknown-error-systemcallerror/347909)

<div class="topic-metadata">

**Author:** [@berta](https://discuss.elastic.co/u/berta)\
**Replies:** 5\
**Last updated:** [December 15, 2023, 3:49pm UTC](https://discuss.elastic.co/t/systemcallerror-message-unknown-error-systemcallerror/347909 "2023-12-15T15:49:09Z")

</div>

Hello, We have a server RHEL7 running with logstash, sending the logs to an opensearch with elasticsearch engine, and every few seconds the files are not send with this error: 2023-09-28T06:33:37,702\]\[ERROR\]\[filewatch.…

---

## [Recency Boost on date field containing nulls](https://discuss.elastic.co/t/recency-boost-on-date-field-containing-nulls/349170)

<div class="topic-metadata">

**Author:** [@Brad\_Hall](https://discuss.elastic.co/u/Brad_Hall)\
**Replies:** 1\
**Last updated:** [December 15, 2023, 3:01pm UTC](https://discuss.elastic.co/t/recency-boost-on-date-field-containing-nulls/349170 "2023-12-15T15:01:06Z")

</div>

Hi, I have an issue with an App Search engine where I'm attempting to apply a recency boost on a date field. Some of the documents in the engine do not have values for the date field and they are boosted to the top of t…

---

## [File sharing between multiple logstash instance](https://discuss.elastic.co/t/file-sharing-between-multiple-logstash-instance/349445)

<div class="topic-metadata">

**Author:** [@kishan\_vadalia](https://discuss.elastic.co/u/kishan_vadalia)\
**Replies:** 1\
**Last updated:** [December 15, 2023, 2:49pm UTC](https://discuss.elastic.co/t/file-sharing-between-multiple-logstash-instance/349445 "2023-12-15T14:49:47Z")

</div>

I have 3 logstash instance running on same machine and putting data to same ES index. all 3 are reading file input from same location (/etc/logstash/conf.d). If there are 500 files in that location than on ES index numbe…

---

## [Issue with Date Formatting in Transform Script on Elasticsearch 8.6.1](https://discuss.elastic.co/t/issue-with-date-formatting-in-transform-script-on-elasticsearch-8-6-1/349463)

<div class="topic-metadata">

**Author:** [@Behnam.R](https://discuss.elastic.co/u/Behnam.R)\
**Replies:** 0\
**Last updated:** [December 15, 2023, 2:49pm UTC](https://discuss.elastic.co/t/issue-with-date-formatting-in-transform-script-on-elasticsearch-8-6-1/349463 "2023-12-15T14:49:39Z")

</div>

Hello, I'm encountering an issue with date formatting in a transform script on Elasticsearch 8.6.1 (licensed version). My goal is to pivot existing index and store the date as it is. However, the output in the transform…

---

## [Kibana doesn't work due to change ip](https://discuss.elastic.co/t/kibana-doesnt-work-due-to-change-ip/349282)

<div class="topic-metadata">

**Author:** [@Gabin\_17](https://discuss.elastic.co/u/Gabin_17)\
**Replies:** 13\
**Last updated:** [December 15, 2023, 2:47pm UTC](https://discuss.elastic.co/t/kibana-doesnt-work-due-to-change-ip/349282 "2023-12-15T14:47:39Z")

</div>

Hi Guys, I need your help ! I installed ELK few days ago, however, my Ip has changed and now i canno't reach the Kibana page. It's write " Kibana server is not ready yet". What's the process to fix it ? I guess, I have…

---

## [Metricbeat hostPath alternative](https://discuss.elastic.co/t/metricbeat-hostpath-alternative/349457)

<div class="topic-metadata">

**Author:** [@Jame\_M](https://discuss.elastic.co/u/Jame_M)\
**Replies:** 0\
**Last updated:** [December 15, 2023, 1:56pm UTC](https://discuss.elastic.co/t/metricbeat-hostpath-alternative/349457 "2023-12-15T13:56:53Z")

</div>

Hello all, I have a quick question. I am installing Metricbeat into a K8s cluster. I do not have rights to it, and we are simply adding a feature for monitering the cluster. And this is on a remote intranet sever so I c…

---

## [License is not available](https://discuss.elastic.co/t/license-is-not-available/349449)

<div class="topic-metadata">

**Author:** [@secsec](https://discuss.elastic.co/u/secsec)\
**Replies:** 2\
**Last updated:** [December 15, 2023, 1:55pm UTC](https://discuss.elastic.co/t/license-is-not-available/349449 "2023-12-15T13:55:28Z")

</div>

Hello im using ELK 8.11 version, only one node and under tail -f /var/log/syslog | grep license i can see this so many problems with licence (im using basic): Dec 15 12:37:03 SPTWS-ELK-NODE01 metricbeat\[607\]: {"log.l…

[Previous page](https://discuss.elastic.co/latest.md?page=451)

[Next page](https://discuss.elastic.co/latest.md?page=453)
