# Latest

**URL:** https://discuss.elastic.co/latest.md?page=464

[Latest](https://discuss.elastic.co/latest.md) · [Categories](https://discuss.elastic.co/categories.md) · [Tags](https://discuss.elastic.co/tags.md)

**Page:** 465

---

## [Winlogbeats xml\_query support for new line chars](https://discuss.elastic.co/t/winlogbeats-xml-query-support-for-new-line-chars/348005)

<div class="topic-metadata">

**Author:** [@grants](https://discuss.elastic.co/u/grants)\
**Replies:** 6\
**Last updated:** [December 4, 2023, 10:41pm UTC](https://discuss.elastic.co/t/winlogbeats-xml-query-support-for-new-line-chars/348005 "2023-12-04T22:41:53Z")

</div>

Running winlogbeat version 8.11.1 and trying to use a custom xml\_query for the event logs. My issue is the data I need to match contains a new line sequence that is proving difficult to filter for. Provided here in an i…

---

## [Unable to generate pdf report from canvas](https://discuss.elastic.co/t/unable-to-generate-pdf-report-from-canvas/348513)

<div class="topic-metadata">

**Author:** [@BIMWash](https://discuss.elastic.co/u/BIMWash)\
**Replies:** 1\
**Last updated:** [December 4, 2023, 10:07pm UTC](https://discuss.elastic.co/t/unable-to-generate-pdf-report-from-canvas/348513 "2023-12-04T22:07:52Z")

</div>

I am attempting to create a report using Canvas but keep running in to the same issues "Error Error: Max attempts reached (3). Queue timeout reached." I have updated the Kibana.yml to increase the timeout xpack.repor…

---

## [How seriously Elastic takes the topic of product safety / software quality](https://discuss.elastic.co/t/how-seriously-elastic-takes-the-topic-of-product-safety-software-quality/348582)

<div class="topic-metadata">

**Author:** [@Stefan\_Sabolowitsch](https://discuss.elastic.co/u/Stefan_Sabolowitsch)\
**Replies:** 1\
**Last updated:** [December 4, 2023, 6:29pm UTC](https://discuss.elastic.co/t/how-seriously-elastic-takes-the-topic-of-product-safety-software-quality/348582 "2023-12-04T18:29:10Z")

</div>

Hi there, Two weeks ago i opened a ticket for a memory leak at Metricbeat. The memory leak was highly risky for productive environments. It took several days until the problem was recognized, understood and fixed. …

---

## [Collect logs from AWS Fargate application to Elastic Cloud](https://discuss.elastic.co/t/collect-logs-from-aws-fargate-application-to-elastic-cloud/344223)

<div class="topic-metadata">

**Author:** [@georgms](https://discuss.elastic.co/u/georgms)\
**Replies:** 5\
**Last updated:** [December 4, 2023, 7:52pm UTC](https://discuss.elastic.co/t/collect-logs-from-aws-fargate-application-to-elastic-cloud/344223 "2023-12-04T19:52:10Z")

</div>

I have an application running on AWS Fargate. I have already added the Elastic APM agent to the application so I get metrics, transactions etc. but no log yet. So how do I collect logs from an AWS Fargate application to…

---

## [Accessing nested aggregations in a watcher's action](https://discuss.elastic.co/t/accessing-nested-aggregations-in-a-watchers-action/348592)

<div class="topic-metadata">

**Author:** [@Wave](https://discuss.elastic.co/u/Wave)\
**Replies:** 0\
**Last updated:** [December 4, 2023, 7:17pm UTC](https://discuss.elastic.co/t/accessing-nested-aggregations-in-a-watchers-action/348592 "2023-12-04T19:17:59Z")

</div>

This isn't a question, but just wanted to share something I've learned. There are similar posts that talk about nested aggregations, but nothing that quite explained what I was looking for. Creating advanced watchers in…

---

## [Elastic Snapshot Restore from S3 Strangeness](https://discuss.elastic.co/t/elastic-snapshot-restore-from-s3-strangeness/348583)

<div class="topic-metadata">

**Author:** [@datencio](https://discuss.elastic.co/u/datencio)\
**Replies:** 1\
**Last updated:** [December 4, 2023, 6:11pm UTC](https://discuss.elastic.co/t/elastic-snapshot-restore-from-s3-strangeness/348583 "2023-12-04T18:11:04Z")

</div>

I am testing out the Elasticsearch Snapshot & Restore feature in my Lab environment. I ran into a strange situation where on a particular cluster the restore seems to complete but seeing strange behavior. For instance, a…

---

## [Inconsistent fields in Kibana 8 Connector / Rule APIs -- connector\_type\_id](https://discuss.elastic.co/t/inconsistent-fields-in-kibana-8-connector-rule-apis-connector-type-id/348590)

<div class="topic-metadata">

**Author:** [@jwhitby](https://discuss.elastic.co/u/jwhitby)\
**Replies:** 0\
**Last updated:** [December 4, 2023, 6:10pm UTC](https://discuss.elastic.co/t/inconsistent-fields-in-kibana-8-connector-rule-apis-connector-type-id/348590 "2023-12-04T18:10:24Z")

</div>

Tested using Elastic / Kibana Version 8.11.1 docker containers. The Kibana 8 connector / rule APIs documentation notes that the field actionTypeId has been updated to connector\_type\_id. This field is accepted when you …

---

## [Change Index Ingestion method](https://discuss.elastic.co/t/change-index-ingestion-method/348242)

<div class="topic-metadata">

**Author:** [@RodAndTom](https://discuss.elastic.co/u/RodAndTom)\
**Replies:** 2\
**Last updated:** [December 4, 2023, 4:49pm UTC](https://discuss.elastic.co/t/change-index-ingestion-method/348242 "2023-12-04T16:49:01Z")

</div>

Hi, I finally managed to setup a MongoDB connector integration with Elastic through Kibana, but it create a index and I can't change the settings and mappings for this Index (Ingestion method is shown as "Connector". S…

---

## [Anomaly Job - implications of low cardinality in population analysis](https://discuss.elastic.co/t/anomaly-job-implications-of-low-cardinality-in-population-analysis/348584)

<div class="topic-metadata">

**Author:** [@marmai16](https://discuss.elastic.co/u/marmai16)\
**Replies:** 0\
**Last updated:** [December 4, 2023, 4:41pm UTC](https://discuss.elastic.co/t/anomaly-job-implications-of-low-cardinality-in-population-analysis/348584 "2023-12-04T16:41:06Z")

</div>

Hello everybody, i'am testing an anomaly job. At creation, it warned me that the cardinality is below 10 and it might not be suitable for population analysis. I was asking myself, under which circumstances it might be …

---

## [The highlight is not returned when using prefixing query](https://discuss.elastic.co/t/the-highlight-is-not-returned-when-using-prefixing-query/348581)

<div class="topic-metadata">

**Author:** [@eric\_liu2007](https://discuss.elastic.co/u/eric_liu2007)\
**Replies:** 0\
**Last updated:** [December 4, 2023, 4:05pm UTC](https://discuss.elastic.co/t/the-highlight-is-not-returned-when-using-prefixing-query/348581 "2023-12-04T16:05:01Z")

</div>

hi all i am searching by using prefix query, the highlight was return on old version (tested 7.6.2, 7.10.3), but not in latest versions (tested 7.11.0, 7.17.5, 8.10.2, 8.10.4, 8.11.1). if ""index\_prefixes" sub-field …

---

## [Moving Averages In Kibana](https://discuss.elastic.co/t/moving-averages-in-kibana/348580)

<div class="topic-metadata">

**Author:** [@Ethan777100](https://discuss.elastic.co/u/Ethan777100)\
**Replies:** 0\
**Last updated:** [December 4, 2023, 3:59pm UTC](https://discuss.elastic.co/t/moving-averages-in-kibana/348580 "2023-12-04T15:59:39Z")

</div>

Trying to do a moving average visualisation of 92 objects specific fault occurrence using a 7-day window Want to clarify about Window Size i can't seem to infer the unit of measurement. Days Hours Mins weeks? How can…

---

## [Rally eventdata track combined-indexing-and-querying challenge - results](https://discuss.elastic.co/t/rally-eventdata-track-combined-indexing-and-querying-challenge-results/348579)

<div class="topic-metadata">

**Author:** [@jelliott1](https://discuss.elastic.co/u/jelliott1)\
**Replies:** 0\
**Last updated:** [December 4, 2023, 3:59pm UTC](https://discuss.elastic.co/t/rally-eventdata-track-combined-indexing-and-querying-challenge-results/348579 "2023-12-04T15:59:07Z")

</div>

Hello, I ran some tests on my Elasticsearch cluster with rally, using the eventdata track and the combined-indexing-and-querying challenge, and am hoping to get some help interpreting the results. I'm interested in the…

---

## [Drop event does not work for specific field](https://discuss.elastic.co/t/drop-event-does-not-work-for-specific-field/348535)

<div class="topic-metadata">

**Author:** [@s0p4L1n3](https://discuss.elastic.co/u/s0p4L1n3)\
**Replies:** 1\
**Last updated:** [December 4, 2023, 3:34pm UTC](https://discuss.elastic.co/t/drop-event-does-not-work-for-specific-field/348535 "2023-12-04T15:34:41Z")

</div>

Hello, I'm using Winlogbeat 7.17.13.0. I want to monitor File/folder activities on the computers and servers. And I want to drop on the client side all useless/not needed events. As monitoring files activites generat…

---

## [Unable to retrieve version information from Elasticsearch nodes. unable to get issuer certificate](https://discuss.elastic.co/t/unable-to-retrieve-version-information-from-elasticsearch-nodes-unable-to-get-issuer-certificate/348518)

<div class="topic-metadata">

**Author:** [@Nauman\_Kyani](https://discuss.elastic.co/u/Nauman_Kyani)\
**Replies:** 2\
**Last updated:** [December 4, 2023, 1:44pm UTC](https://discuss.elastic.co/t/unable-to-retrieve-version-information-from-elasticsearch-nodes-unable-to-get-issuer-certificate/348518 "2023-12-04T13:44:52Z")

</div>

I have 2 master node and 2 worker node cluster setup in kubernets. I want to deploy Elasticsearch in this manner 1 master 2 data and 1 client . I did this its working fine. And i run this in load balancer with my k8 mast…

---

## [Selinux Restrictions](https://discuss.elastic.co/t/selinux-restrictions/348566)

<div class="topic-metadata">

**Author:** [@juancamiloll](https://discuss.elastic.co/u/juancamiloll)\
**Replies:** 6\
**Last updated:** [December 4, 2023, 3:24pm UTC](https://discuss.elastic.co/t/selinux-restrictions/348566 "2023-12-04T15:24:14Z")

</div>

I am installing ELK 8.7.1 on an Oracle Linux version. I was able to install ELK without any problems and the services are in active state without any errors. When I try to access Kibana through port 5601 from the brows…

---

## [Sir I try everything for contacts with your sales but your sales never message me back](https://discuss.elastic.co/t/sir-i-try-everything-for-contacts-with-your-sales-but-your-sales-never-message-me-back/348565)

<div class="topic-metadata">

**Author:** [@zabtech](https://discuss.elastic.co/u/zabtech)\
**Replies:** 1\
**Last updated:** [December 4, 2023, 3:24pm UTC](https://discuss.elastic.co/t/sir-i-try-everything-for-contacts-with-your-sales-but-your-sales-never-message-me-back/348565 "2023-12-04T15:24:12Z")

</div>

I don't know what wrong with your sale , my company interest with your product and need to use your product , but it's look like your sale never care about us, We scheduled a meeting around 9:00 PM, but there was no Goog…

---

## [Deleting and index data with two params is not allowing - 8.11.0](https://discuss.elastic.co/t/deleting-and-index-data-with-two-params-is-not-allowing-8-11-0/348571)

<div class="topic-metadata">

**Author:** [@Rubsy](https://discuss.elastic.co/u/Rubsy)\
**Replies:** 1\
**Last updated:** [December 4, 2023, 3:23pm UTC](https://discuss.elastic.co/t/deleting-and-index-data-with-two-params-is-not-allowing-8-11-0/348571 "2023-12-04T15:23:37Z")

</div>

Here is my data PUT dynamicasset/\_doc/E3EBDC84-9281-46D3-9DA1-31672642C7D3 { "CustomerId":"E3EBDC84-9281-46D3-9DA1-31672642C7D3", "InvoiceNumber": "301", "InvoiceAmount": 450, "Description": "Test Sample for deleting ba…

---

## [Connect Logstash 8.10 to Elasticsearch 8.10](https://discuss.elastic.co/t/connect-logstash-8-10-to-elasticsearch-8-10/348564)

<div class="topic-metadata">

**Author:** [@Abdeljalil\_El\_Yousso](https://discuss.elastic.co/u/Abdeljalil_El_Yousso)\
**Replies:** 1\
**Last updated:** [December 4, 2023, 3:20pm UTC](https://discuss.elastic.co/t/connect-logstash-8-10-to-elasticsearch-8-10/348564 "2023-12-04T15:20:28Z")

</div>

Can anyone please provide an example to connect Logstash with elasticsearch runing on docker on a debian environement , the connection using SSL "very important" i followed the documentation but i guess im missing somet…

---

## [Sorting script with tiebreaker](https://discuss.elastic.co/t/sorting-script-with-tiebreaker/348528)

<div class="topic-metadata">

**Author:** [@\_baba](https://discuss.elastic.co/u/_baba)\
**Replies:** 1\
**Last updated:** [December 4, 2023, 3:08pm UTC](https://discuss.elastic.co/t/sorting-script-with-tiebreaker/348528 "2023-12-04T15:08:25Z")

</div>

Hi, We have multiple documents in an index with duplicate field value (product\_id). I want to sort based on product\_id with a condition that for 2 records having same product\_id, sort based on product\_cost. Recreation …

---

## [Elasticsearch Connection Error](https://discuss.elastic.co/t/elasticsearch-connection-error/348536)

<div class="topic-metadata">

**Author:** [@Burak\_Karatay](https://discuss.elastic.co/u/Burak_Karatay)\
**Replies:** 1\
**Last updated:** [December 4, 2023, 3:08pm UTC](https://discuss.elastic.co/t/elasticsearch-connection-error/348536 "2023-12-04T15:08:08Z")

</div>

I have physical server with elasticsearch installed and from another computer I try to connect the elasticsearch with this code: const esClient = new Client({node: 'https://my-ip-address:5621', auth: {username: 'elastic…

---

## [Visualización de logs en kibana, desde aplicaciones alojadas en azure kubernetes](https://discuss.elastic.co/t/visualizacion-de-logs-en-kibana-desde-aplicaciones-alojadas-en-azure-kubernetes/348568)

<div class="topic-metadata">

**Author:** [@Wilson\_Monsalve](https://discuss.elastic.co/u/Wilson_Monsalve)\
**Replies:** 0\
**Last updated:** [December 4, 2023, 2:57pm UTC](https://discuss.elastic.co/t/visualizacion-de-logs-en-kibana-desde-aplicaciones-alojadas-en-azure-kubernetes/348568 "2023-12-04T14:57:36Z")

</div>

Hola buen día, mi escenario y problema es el siguiente: Tengo un servidor en azure Linux donde instale elastic-kibana por medio de docker, con las imágenes 8.6.1; elasticsearh y kibana lo tengo implementado con tls, cer…

---

## [Need to send data from .log file to AWS opensearch](https://discuss.elastic.co/t/need-to-send-data-from-log-file-to-aws-opensearch/348555)

<div class="topic-metadata">

**Author:** [@anupvtr](https://discuss.elastic.co/u/anupvtr)\
**Replies:** 5\
**Last updated:** [December 4, 2023, 2:43pm UTC](https://discuss.elastic.co/t/need-to-send-data-from-log-file-to-aws-opensearch/348555 "2023-12-04T14:43:32Z")

</div>

Hello all, Could you please help me on this. I am quite new to the Elasticsearch ocean. My requirement is, I need to send data from .log file to AWS opensearch. Whether the below option will work for me. Download t…

---

## [Similarity field in KNN](https://discuss.elastic.co/t/similarity-field-in-knn/348552)

<div class="topic-metadata">

**Author:** [@Sai\_Krishna\_D](https://discuss.elastic.co/u/Sai_Krishna_D)\
**Replies:** 4\
**Last updated:** [December 4, 2023, 2:30pm UTC](https://discuss.elastic.co/t/similarity-field-in-knn/348552 "2023-12-04T14:30:06Z")

</div>

When using the Similarity field in KNN Query, The response is not expected, The similarity value I gave was 0.6 and the boost as 1. Even though there are more than 30 documents which have score greater than 0.7 only one …

---

## [Null pointer exception for explain with boost mode replace](https://discuss.elastic.co/t/null-pointer-exception-for-explain-with-boost-mode-replace/348545)

<div class="topic-metadata">

**Author:** [@elvanja](https://discuss.elastic.co/u/elvanja)\
**Replies:** 2\
**Last updated:** [December 4, 2023, 2:06pm UTC](https://discuss.elastic.co/t/null-pointer-exception-for-explain-with-boost-mode-replace/348545 "2023-12-04T14:06:46Z")

</div>

We seem to have odd situation for requesting explanation when boost mode is set to replace, the stack returns null pointer exception. Running on Version: 8.7.1, Build: docker/f229ed3f893a515d590d0f39b05f68913e2d9b53/2023…

---

## [Anomaly Job scroll\_size parameter behaviour](https://discuss.elastic.co/t/anomaly-job-scroll-size-parameter-behaviour/348533)

<div class="topic-metadata">

**Author:** [@marmai16](https://discuss.elastic.co/u/marmai16)\
**Replies:** 1\
**Last updated:** [December 4, 2023, 2:07pm UTC](https://discuss.elastic.co/t/anomaly-job-scroll-size-parameter-behaviour/348533 "2023-12-04T14:07:04Z")

</div>

Hello everyone, a quick question regarding the scroll\_size parameter of a datafeed in an anomaly job. Is the scroll\_size just limiting the number of results per query returned, but every document is processed (thus a r…

---

## [Nested inner\_hits more than 100 results](https://discuss.elastic.co/t/nested-inner-hits-more-than-100-results/348562)

<div class="topic-metadata">

**Author:** [@Vinicius\_Junges](https://discuss.elastic.co/u/Vinicius_Junges)\
**Replies:** 0\
**Last updated:** [December 4, 2023, 1:41pm UTC](https://discuss.elastic.co/t/nested-inner-hits-more-than-100-results/348562 "2023-12-04T13:41:52Z")

</div>

Hey guys. I don't know if I'm in the right place, is my first time here. I'm doing a nested query with inner\_hits, but the elasticsearch configuration is limited to 100 by default. Is there any way to get more than 100 r…

---

## [Alert changes in documents](https://discuss.elastic.co/t/alert-changes-in-documents/348561)

<div class="topic-metadata">

**Author:** [@tmslara.a](https://discuss.elastic.co/u/tmslara.a)\
**Replies:** 0\
**Last updated:** [December 4, 2023, 1:37pm UTC](https://discuss.elastic.co/t/alert-changes-in-documents/348561 "2023-12-04T13:37:47Z")

</div>

Hello, I'm trying to implement an alert system in Elasticsearch. I'll describe the key elements of the problem and my solution attempts until now. Scenario We are ingesting information into an Elasticsearch index usin…

---

## [Filebeat not starting](https://discuss.elastic.co/t/filebeat-not-starting/348486)

<div class="topic-metadata">

**Author:** [@tagba](https://discuss.elastic.co/u/tagba)\
**Replies:** 7\
**Last updated:** [December 4, 2023, 1:35pm UTC](https://discuss.elastic.co/t/filebeat-not-starting/348486 "2023-12-04T13:35:15Z")

</div>

I have installed elk version 7.3.2 on an ubuntu machine running on a VM, but the filebeat is not starting. Below is the error message. × filebeat.service - Filebeat sends log files to Logstash or directly to Elasticsea…

---

## [Kibana 8.11.1 - ClamAV Infected file -\> security\_detection\_engine-8.11.1.zip](https://discuss.elastic.co/t/kibana-8-11-1-clamav-infected-file-security-detection-engine-8-11-1-zip/347939)

<div class="topic-metadata">

**Author:** [@RafaelE](https://discuss.elastic.co/u/RafaelE)\
**Replies:** 3\
**Last updated:** [December 4, 2023, 12:49pm UTC](https://discuss.elastic.co/t/kibana-8-11-1-clamav-infected-file-security-detection-engine-8-11-1-zip/347939 "2023-12-04T12:49:12Z")

</div>

Hello everyone, I'm creating this topic to report a situation where the antivirus ClamAV have identified a possible infected file on your Debian package ClamAV report /usr/share/kibana/node\_modules/@kbn/fleet-plugin/t…

---

## [Node.js Application Fail to Connect Elasticsearch](https://discuss.elastic.co/t/node-js-application-fail-to-connect-elasticsearch/348223)

<div class="topic-metadata">

**Author:** [@Burak\_Karatay](https://discuss.elastic.co/u/Burak_Karatay)\
**Replies:** 5\
**Last updated:** [December 4, 2023, 11:50am UTC](https://discuss.elastic.co/t/node-js-application-fail-to-connect-elasticsearch/348223 "2023-12-04T11:50:27Z")

</div>

I have very simple Node.js Application to connect my local Elasticsearch engine, when I try to use Kibana, I can connect after provide user and email but when I try to send ping from my Node.js app It gives following err…

[Previous page](https://discuss.elastic.co/latest.md?page=463)

[Next page](https://discuss.elastic.co/latest.md?page=465)
