# Latest

**URL:** https://discuss.elastic.co/latest.md?page=475

[Latest](https://discuss.elastic.co/latest.md) · [Categories](https://discuss.elastic.co/categories.md) · [Tags](https://discuss.elastic.co/tags.md)

**Page:** 476

---

## [Logstash / problem with windows index](https://discuss.elastic.co/t/logstash-problem-with-windows-index/347545)

<div class="topic-metadata">

**Author:** [@secsec](https://discuss.elastic.co/u/secsec)\
**Replies:** 4\
**Last updated:** [November 23, 2023, 3:35am UTC](https://discuss.elastic.co/t/logstash-problem-with-windows-index/347545 "2023-11-23T03:35:21Z")

</div>

Hello, could you please help me? Im using Elastic version 8.11.1 Im trying to create new 2 indexes for windows and linux. This code below is working for linux (it is automaticaly creating indexes every day), but it i…

---

## [org.elasticsearch.hadoop.rest.EsHadoopRemoteException: illegal\_argument\_exception: value for key \[X-Opaque-Id\] already present](https://discuss.elastic.co/t/org-elasticsearch-hadoop-rest-eshadoopremoteexception-illegal-argument-exception-value-for-key-x-opaque-id-already-present/347380)

<div class="topic-metadata">

**Author:** [@Akhil\_parmar](https://discuss.elastic.co/u/Akhil_parmar)\
**Replies:** 2\
**Last updated:** [November 23, 2023, 3:18am UTC](https://discuss.elastic.co/t/org-elasticsearch-hadoop-rest-eshadoopremoteexception-illegal-argument-exception-value-for-key-x-opaque-id-already-present/347380 "2023-11-23T03:18:13Z")

</div>

I am working on ETL job where target to load data to elasticsearch, I am facing an error when trying to index document org.elasticsearch.hadoop.rest.EsHadoopRemoteException: illegal\_argument\_exception: value for key \[X-…

---

## [Can I convert epoch time via data views to be readable?](https://discuss.elastic.co/t/can-i-convert-epoch-time-via-data-views-to-be-readable/347677)

<div class="topic-metadata">

**Author:** [@geeboy1](https://discuss.elastic.co/u/geeboy1)\
**Replies:** 6\
**Last updated:** [November 23, 2023, 3:15am UTC](https://discuss.elastic.co/t/can-i-convert-epoch-time-via-data-views-to-be-readable/347677 "2023-11-23T03:15:45Z")

</div>

good day, my app log is in epoch time format (sample: 1700529701700), can I convert this using script in data views to be human readable format in discover menu? or any suggestion how to convert this? i saw this in goo…

---

## [L2norm script in source compiles error because Cannot cast from \[double\] to \[int\]](https://discuss.elastic.co/t/l2norm-script-in-source-compiles-error-because-cannot-cast-from-double-to-int/347799)

<div class="topic-metadata">

**Author:** [@wensi](https://discuss.elastic.co/u/wensi)\
**Replies:** 0\
**Last updated:** [November 23, 2023, 1:38am UTC](https://discuss.elastic.co/t/l2norm-script-in-source-compiles-error-because-cannot-cast-from-double-to-int/347799 "2023-11-23T01:38:56Z")

</div>

"source": "double norm=l2norm(params.queryVector, 'vec')^2; return 1/(1+norm);" or "source": "1/(1+l2norm(params.queryVector, 'vec')^2)" or "source": "1.0/(1.0+l2norm(params.queryVector, 'vec')^2)" all result in "c…

---

## [AKAMAI SIEM Integration not working](https://discuss.elastic.co/t/akamai-siem-integration-not-working/347173)

<div class="topic-metadata">

**Author:** [@jvgarita](https://discuss.elastic.co/u/jvgarita)\
**Replies:** 0\
**Last updated:** [November 14, 2023, 11:18pm UTC](https://discuss.elastic.co/t/akamai-siem-integration-not-working/347173 "2023-11-14T23:18:20Z")

</div>

Hi all, I have deployed an ELK server using version 8.11.0 ad used the option for AKAMAI SIEM integration but the visualization pane is giving me an error "Could not locate field: akamai.siem.rules.ruleTags" and is not s…

---

## [Importing Index Patterns](https://discuss.elastic.co/t/importing-index-patterns/347275)

<div class="topic-metadata">

**Author:** [@randomnamegenerator](https://discuss.elastic.co/u/randomnamegenerator)\
**Replies:** 1\
**Last updated:** [November 22, 2023, 10:28pm UTC](https://discuss.elastic.co/t/importing-index-patterns/347275 "2023-11-22T22:28:04Z")

</div>

Hello there, I have read it is possible to export index patterns from one elasticsearch cluster to another. Will this include all the fields and scripted fields and is this a viable way of insuring the mapping is the s…

---

## [How to parse a stringify sale on the label?](https://discuss.elastic.co/t/how-to-parse-a-stringify-sale-on-the-label/347794)

<div class="topic-metadata">

**Author:** [@thiagobr](https://discuss.elastic.co/u/thiagobr)\
**Replies:** 0\
**Last updated:** [November 22, 2023, 10:25pm UTC](https://discuss.elastic.co/t/how-to-parse-a-stringify-sale-on-the-label/347794 "2023-11-22T22:25:52Z")

</div>

I'm using the library "@elastic/apm-rum-angular": "^2.1.7" for Angular 11, I'm already receiving the data through transaction + span + addLabels. However, the addLabel parameter only accepts string, boolean or number, a…

---

## [ALB health check failure while checking Elasticsearch cluster health](https://discuss.elastic.co/t/alb-health-check-failure-while-checking-elasticsearch-cluster-health/347018)

<div class="topic-metadata">

**Author:** [@siddharthavempa](https://discuss.elastic.co/u/siddharthavempa)\
**Replies:** 0\
**Last updated:** [November 13, 2023, 1:33pm UTC](https://discuss.elastic.co/t/alb-health-check-failure-while-checking-elasticsearch-cluster-health/347018 "2023-11-13T13:33:35Z")

</div>

Hi Team, I am creating a two node Elasticsearch cluster in AWS using EC2 instances. I installed Elasticsearch in node-1 using rpm. Then I used the below commands to modify the elasticsearch.yaml file and started elasti…

---

## [Display partially structured data into multiple columns in Kibana Discover](https://discuss.elastic.co/t/display-partially-structured-data-into-multiple-columns-in-kibana-discover/347254)

<div class="topic-metadata">

**Author:** [@Selma](https://discuss.elastic.co/u/Selma)\
**Replies:** 1\
**Last updated:** [November 22, 2023, 10:11pm UTC](https://discuss.elastic.co/t/display-partially-structured-data-into-multiple-columns-in-kibana-discover/347254 "2023-11-22T22:11:25Z")

</div>

I am trying to get the data as separate columns based on the fields serviceName, flowName, correlationId and timestamp from below log field. can this be achieved through scripts in Kibana UI itself ? If not is there an a…

---

## [Upgrading system indices to version 8](https://discuss.elastic.co/t/upgrading-system-indices-to-version-8/347364)

<div class="topic-metadata">

**Author:** [@bermanb](https://discuss.elastic.co/u/bermanb)\
**Replies:** 1\
**Last updated:** [November 22, 2023, 10:07pm UTC](https://discuss.elastic.co/t/upgrading-system-indices-to-version-8/347364 "2023-11-22T22:07:23Z")

</div>

We recently updated Elasticsearch and Kibana from 7.17 to 8.10.2, and noticed that we can't find how to upgrade the system indices from 7 to 8 (like in the 7 to 8 upgrade assistant where we were able to upgrade our indic…

---

## [Cannot see custom transaction](https://discuss.elastic.co/t/cannot-see-custom-transaction/347500)

<div class="topic-metadata">

**Author:** [@sumitk](https://discuss.elastic.co/u/sumitk)\
**Replies:** 0\
**Last updated:** [November 20, 2023, 6:46am UTC](https://discuss.elastic.co/t/cannot-see-custom-transaction/347500 "2023-11-20T06:46:51Z")

</div>

Hi I am doing custom transaction for analytics, but not able to see them in the kibana dashboard , I can see the events are happening in the network tab with 202 but the payload is encrpted .Can some body help me? Dashb…

---

## [Winlogbeat error on alias](https://discuss.elastic.co/t/winlogbeat-error-on-alias/347785)

<div class="topic-metadata">

**Author:** [@Michael\_Ryan\_Dinio](https://discuss.elastic.co/u/Michael_Ryan_Dinio)\
**Replies:** 1\
**Last updated:** [November 22, 2023, 10:00pm UTC](https://discuss.elastic.co/t/winlogbeat-error-on-alias/347785 "2023-11-22T22:00:30Z")

</div>

Hi I got an error on my client with Winlogbeat running below is the error log 2023-11-22T03:58:49.082+0800 ERROR \[publisher\_pipeline\_output\] pipeline/output.go:154 Failed to connect to backoff(elasticsearch(https://54.…

---

## [Color stops acting strange](https://discuss.elastic.co/t/color-stops-acting-strange/347701)

<div class="topic-metadata">

**Author:** [@Negan](https://discuss.elastic.co/u/Negan)\
**Replies:** 1\
**Last updated:** [November 22, 2023, 9:57pm UTC](https://discuss.elastic.co/t/color-stops-acting-strange/347701 "2023-11-22T21:57:13Z")

</div>

Hi. The colour stops I am trying to use are not showing as they should be. See images: as you can see in this image for some reason it starts to be green at -60,21 while it needs to be green under 0. I tried changing…

---

## [Annotations @ Lens - query automatically derived annotations](https://discuss.elastic.co/t/annotations-lens-query-automatically-derived-annotations/347671)

<div class="topic-metadata">

**Author:** [@lodooowa](https://discuss.elastic.co/u/lodooowa)\
**Replies:** 0\
**Last updated:** [November 21, 2023, 9:35pm UTC](https://discuss.elastic.co/t/annotations-lens-query-automatically-derived-annotations/347671 "2023-11-21T21:35:00Z")

</div>

Tracking application deployment with annotations seems to be very useful feature. However out of the box it is shown only on very few transaction charts. Is there any way to query those automatically derived annotations…

---

## [Kibana 8.9.1 yarn build issue](https://discuss.elastic.co/t/kibana-8-9-1-yarn-build-issue/346993)

<div class="topic-metadata">

**Author:** [@epyonss](https://discuss.elastic.co/u/epyonss)\
**Replies:** 1\
**Last updated:** [November 22, 2023, 9:44pm UTC](https://discuss.elastic.co/t/kibana-8-9-1-yarn-build-issue/346993 "2023-11-22T21:44:16Z")

</div>

hi guys "I tried to use the 'yarn build --skip-os-packages' command to build 'kibana source', but I'm encountering the following results. Any suggestions? Thanks

---

## [What is the proper request body format for saved\_objects/\_bulk\_delete API?](https://discuss.elastic.co/t/what-is-the-proper-request-body-format-for-saved-objects-bulk-delete-api/346813)

<div class="topic-metadata">

**Author:** [@Evgeni\_Dzhelyov](https://discuss.elastic.co/u/Evgeni_Dzhelyov)\
**Replies:** 1\
**Last updated:** [November 22, 2023, 9:41pm UTC](https://discuss.elastic.co/t/what-is-the-proper-request-body-format-for-saved-objects-bulk-delete-api/346813 "2023-11-22T21:41:36Z")

</div>

I'm unable to use the bulk\_delete API on 8.8.2 neither using Kibana Console or curl. Can you give me a working example? curl -X POST "http://localhost:5601/api/saved\_objects/\_bulk\_delete" -H 'kbn-xsrf: true' -H 'Content…

---

## [Filtering the redundant dataView column value](https://discuss.elastic.co/t/filtering-the-redundant-dataview-column-value/347087)

<div class="topic-metadata">

**Author:** [@talk2raja](https://discuss.elastic.co/u/talk2raja)\
**Replies:** 1\
**Last updated:** [November 22, 2023, 9:38pm UTC](https://discuss.elastic.co/t/filtering-the-redundant-dataview-column-value/347087 "2023-11-22T21:38:18Z")

</div>

I am using an Elasticsearch query, trying to send an alert based on FPS\_MIN, My query & conditions, My problem is, that I got 39 hits, I am looping the hits result in alert action message section, server.name value…

---

## [Page not indexed if a content extraction rule with CSS selector fails if the references element is not part of the page](https://discuss.elastic.co/t/page-not-indexed-if-a-content-extraction-rule-with-css-selector-fails-if-the-references-element-is-not-part-of-the-page/346647)

<div class="topic-metadata">

**Author:** [@sebastianboelling](https://discuss.elastic.co/u/sebastianboelling)\
**Replies:** 1\
**Last updated:** [November 22, 2023, 8:44pm UTC](https://discuss.elastic.co/t/page-not-indexed-if-a-content-extraction-rule-with-css-selector-fails-if-the-references-element-is-not-part-of-the-page/346647 "2023-11-22T20:44:54Z")

</div>

Hi all, we are using content extraction rules with CSS selectors as described here: Web crawler content extraction rules | Enterprise Search documentation \[8.11\] | Elastic We've found out that a page is NOT indexed if …

---

## [Filter stays when moving to another dashboard](https://discuss.elastic.co/t/filter-stays-when-moving-to-another-dashboard/347751)

<div class="topic-metadata">

**Author:** [@ElasticLiver](https://discuss.elastic.co/u/ElasticLiver)\
**Replies:** 3\
**Last updated:** [November 22, 2023, 8:22pm UTC](https://discuss.elastic.co/t/filter-stays-when-moving-to-another-dashboard/347751 "2023-11-22T20:22:03Z")

</div>

Hi, after updating from 7.17.5 to 8.9.2 Im having some issues with vega-lite links. this is what worked before: "transform": \[ { "calculate": "'../app/dashboards#/view/6a0b5de8-55a0-5c59-8427-6bf1f9a8…

---

## [Kibana Log Error on Start](https://discuss.elastic.co/t/kibana-log-error-on-start/347783)

<div class="topic-metadata">

**Author:** [@sgrubb](https://discuss.elastic.co/u/sgrubb)\
**Replies:** 4\
**Last updated:** [November 22, 2023, 8:07pm UTC](https://discuss.elastic.co/t/kibana-log-error-on-start/347783 "2023-11-22T20:07:30Z")

</div>

Hello! I recently upgraded my elasticsearch and kibana from 8.3 to 8.11. elasticsearch is running fine but I can not get kibana to start after the upgrade. I installed Kibana via manual Deb and am using the same .yml fil…

---

## [Changing Index Mapping & Making Long Texts Keyword For Elasticsearch](https://discuss.elastic.co/t/changing-index-mapping-making-long-texts-keyword-for-elasticsearch/347709)

<div class="topic-metadata">

**Author:** [@Ethan777100](https://discuss.elastic.co/u/Ethan777100)\
**Replies:** 3\
**Last updated:** [November 22, 2023, 6:35pm UTC](https://discuss.elastic.co/t/changing-index-mapping-making-long-texts-keyword-for-elasticsearch/347709 "2023-11-22T18:35:03Z")

</div>

Moving forward, should I find a need to change my index mapping after the data is ingested, I have this description column which I realised was ingested as Text and not a keyword. PUT /ats-mainline-logs-2023-01,ats-mai…

---

## [Imported dashboard and their "sub" dashboards does not work in Kibana](https://discuss.elastic.co/t/imported-dashboard-and-their-sub-dashboards-does-not-work-in-kibana/346096)

<div class="topic-metadata">

**Author:** [@petlit2049](https://discuss.elastic.co/u/petlit2049)\
**Replies:** 1\
**Last updated:** [November 22, 2023, 6:22pm UTC](https://discuss.elastic.co/t/imported-dashboard-and-their-sub-dashboards-does-not-work-in-kibana/346096 "2023-11-22T18:22:54Z")

</div>

I use ansible in order to list the available (imported) beat-dashboards. I select a number of dashboards to import to a number of spaces and it works fine. However, I get a 404 error when I click a "sub/included" dashboa…

---

## [Ingest log in specific index](https://discuss.elastic.co/t/ingest-log-in-specific-index/347571)

<div class="topic-metadata">

**Author:** [@Nitin08bisht](https://discuss.elastic.co/u/Nitin08bisht)\
**Replies:** 2\
**Last updated:** [November 22, 2023, 6:16pm UTC](https://discuss.elastic.co/t/ingest-log-in-specific-index/347571 "2023-11-22T18:16:58Z")

</div>

Hi, I'm using ELK version 7.16.2 and I have configured Filebeat and I want to ingest log on dedicated index rather than on default filebeat index. Please help me on this. Please find the filebeat.yml file configuration…

---

## [Logstash unable to receive data from MQTT](https://discuss.elastic.co/t/logstash-unable-to-receive-data-from-mqtt/347712)

<div class="topic-metadata">

**Author:** [@Shah\_Zain](https://discuss.elastic.co/u/Shah_Zain)\
**Replies:** 6\
**Last updated:** [November 22, 2023, 6:08pm UTC](https://discuss.elastic.co/t/logstash-unable-to-receive-data-from-mqtt/347712 "2023-11-22T18:08:10Z")

</div>

Logstash unable to receive data from MQTT. Getting this from logs: //Stack: C:/Users/Shah Zain/Downloads/logstash-8.11.1-windows-x86\_64/logstash-8.11.1/vendor/bundle/jruby/3.1.0/gems/logstash-input-mqtt-0.0.2/lib/logst…

---

## [Ad-hoc data views rationale](https://discuss.elastic.co/t/ad-hoc-data-views-rationale/345355)

<div class="topic-metadata">

**Author:** [@tancredi](https://discuss.elastic.co/u/tancredi)\
**Replies:** 1\
**Last updated:** [November 22, 2023, 6:01pm UTC](https://discuss.elastic.co/t/ad-hoc-data-views-rationale/345355 "2023-11-22T18:01:24Z")

</div>

I'm not sure about the ad-hoc data views use case. I cannot find any rationale behind it in documentation. For now I have a lot of problems as many of lens/visualisations from integrations are using them, then I cannot c…

---

## [Send logstash output to questdb](https://discuss.elastic.co/t/send-logstash-output-to-questdb/347717)

<div class="topic-metadata">

**Author:** [@Indeed2000](https://discuss.elastic.co/u/Indeed2000)\
**Replies:** 4\
**Last updated:** [November 22, 2023, 5:57pm UTC](https://discuss.elastic.co/t/send-logstash-output-to-questdb/347717 "2023-11-22T17:57:01Z")

</div>

Hi, how can i send logstash output to questdb? which plugin suitable for this aim and compatible with questdb? which port suitable on questdb for this aim? I have if condition on output if tag = send then write to tab…

---

## [Logstash Permission Issue](https://discuss.elastic.co/t/logstash-permission-issue/347771)

<div class="topic-metadata">

**Author:** [@ranjini](https://discuss.elastic.co/u/ranjini)\
**Replies:** 7\
**Last updated:** [November 22, 2023, 5:40pm UTC](https://discuss.elastic.co/t/logstash-permission-issue/347771 "2023-11-22T17:40:54Z")

</div>

Error Message \[2023-11-22T13:15:51,460\]\[WARN \]\[filewatch.sincedbcollection\]\[main\]\[fd97ffae0e8f2b3b8d71c9b308ee7a3feac45d9133bd3968160c580a4d2e603e\] sincedb\_write: unable to write atomically due to permissions error, fal…

---

## [How to write to the same datastream from MetricBeat and Logstash](https://discuss.elastic.co/t/how-to-write-to-the-same-datastream-from-metricbeat-and-logstash/347778)

<div class="topic-metadata">

**Author:** [@Igal\_Hanoch](https://discuss.elastic.co/u/Igal_Hanoch)\
**Replies:** 0\
**Last updated:** [November 22, 2023, 5:26pm UTC](https://discuss.elastic.co/t/how-to-write-to-the-same-datastream-from-metricbeat-and-logstash/347778 "2023-11-22T17:26:18Z")

</div>

I'm writing metricbeat data from several computes to my elasticsearch. Some metricbeats are writing directly to ElasicSearch and some through logstash. The data from the metricbeat is written to a datastream named .ds-…

---

## [Metricbeat 8.11.1 not reporting cgroup.io.pressure for some machines](https://discuss.elastic.co/t/metricbeat-8-11-1-not-reporting-cgroup-io-pressure-for-some-machines/347777)

<div class="topic-metadata">

**Author:** [@dhairav](https://discuss.elastic.co/u/dhairav)\
**Replies:** 0\
**Last updated:** [November 22, 2023, 5:23pm UTC](https://discuss.elastic.co/t/metricbeat-8-11-1-not-reporting-cgroup-io-pressure-for-some-machines/347777 "2023-11-22T17:23:48Z")

</div>

We are using one of the more recent versions of Metricbeat - v8.1.1 for 2 types of instances. Cloud Instances (Ubuntu 22.04) and Bare Metal installations (Debian 11). I have observed specifically that the metrics under …

---

## [I can't add custom data to the custom transaction](https://discuss.elastic.co/t/i-cant-add-custom-data-to-the-custom-transaction/347675)

<div class="topic-metadata">

**Author:** [@thiagobr](https://discuss.elastic.co/u/thiagobr)\
**Replies:** 5\
**Last updated:** [November 22, 2023, 5:03pm UTC](https://discuss.elastic.co/t/i-cant-add-custom-data-to-the-custom-transaction/347675 "2023-11-22T17:03:54Z")

</div>

Hello, I'm new to Elastic, I created an account to test the power of the tool. What I'm trying to do is the following: Capture all RestFul requests; Capture all Socket connections; Capture all route change even…

[Previous page](https://discuss.elastic.co/latest.md?page=474)

[Next page](https://discuss.elastic.co/latest.md?page=476)
