# Latest

**URL:** https://discuss.elastic.co/latest.md?page=487

[Latest](https://discuss.elastic.co/latest.md) · [Categories](https://discuss.elastic.co/categories.md) · [Tags](https://discuss.elastic.co/tags.md)

**Page:** 488

---

## [Want to create new index daily with date associated with index name](https://discuss.elastic.co/t/want-to-create-new-index-daily-with-date-associated-with-index-name/346197)

<div class="topic-metadata">

**Author:** [@Swapnadeep\_Mondal](https://discuss.elastic.co/u/Swapnadeep_Mondal)\
**Replies:** 2\
**Last updated:** [November 10, 2023, 6:57am UTC](https://discuss.elastic.co/t/want-to-create-new-index-daily-with-date-associated-with-index-name/346197 "2023-11-10T06:57:22Z")

</div>

Hello Team, I've recently learned about date math and I'm interested in creating an ILM (Index Lifecycle Management) policy to generate a new index every day, with the index name associated with the date. For example, I…

---

## [Ingest kafka syslog to elasticsearch or kibana](https://discuss.elastic.co/t/ingest-kafka-syslog-to-elasticsearch-or-kibana/346834)

<div class="topic-metadata">

**Author:** [@manasi](https://discuss.elastic.co/u/manasi)\
**Replies:** 0\
**Last updated:** [November 10, 2023, 6:08am UTC](https://discuss.elastic.co/t/ingest-kafka-syslog-to-elasticsearch-or-kibana/346834 "2023-11-10T06:08:37Z")

</div>

Hi all, How to ingest kafka syslog to elasticsearch or kibana? I'm using elasticsearch and Kibana of 8.10.4 version. I want to visualize kafka syslogs on kibana dashboards. But I don't know how to push or integrate the…

---

## [Kibana Plugin error : "Elastic did not load properly. Check the server output for more information."](https://discuss.elastic.co/t/kibana-plugin-error-elastic-did-not-load-properly-check-the-server-output-for-more-information/346412)

<div class="topic-metadata">

**Author:** [@Srini-99](https://discuss.elastic.co/u/Srini-99)\
**Replies:** 2\
**Last updated:** [November 10, 2023, 3:53am UTC](https://discuss.elastic.co/t/kibana-plugin-error-elastic-did-not-load-properly-check-the-server-output-for-more-information/346412 "2023-11-10T03:53:15Z")

</div>

Hi ! ES Version - 8.10.2 Kibana version - 8.10.2 So i have written a plugin to add to kibana. and i did this in kibana 8.10.2 dev only. it works perfectly in my wsl (my dev env). when i use "yarn build" and use it, …

---

## [Set "index.mapping.dimension\_fields.limit" does not work](https://discuss.elastic.co/t/set-index-mapping-dimension-fields-limit-does-not-work/346330)

<div class="topic-metadata">

**Author:** [@VietDuc](https://discuss.elastic.co/u/VietDuc)\
**Replies:** 1\
**Last updated:** [November 10, 2023, 3:39am UTC](https://discuss.elastic.co/t/set-index-mapping-dimension-fields-limit-does-not-work/346330 "2023-11-10T03:39:59Z")

</div>

Hi everyone, We would like to extend the number of dimension\_fields of our TSDS by POST \_index\_template/ds-micrometer-metrics-prod { "index\_patterns": \[ "micrometer" \], "data\_stream": {}, "template": { …

---

## [Unable to get Metricbeat to communicate with Elasticsearch](https://discuss.elastic.co/t/unable-to-get-metricbeat-to-communicate-with-elasticsearch/346747)

<div class="topic-metadata">

**Author:** [@james\_fourth](https://discuss.elastic.co/u/james_fourth)\
**Replies:** 17\
**Last updated:** [November 10, 2023, 1:47am UTC](https://discuss.elastic.co/t/unable-to-get-metricbeat-to-communicate-with-elasticsearch/346747 "2023-11-10T01:47:01Z")

</div>

I'm working on upgrading the Elastic stack to the current version for my company. So, I'm testing the deployment of Elasticsearch, Kibana, Logstash, and Metricbeat. Each component is in a separate docker container but al…

---

## [Kibana bouncing degraded - available](https://discuss.elastic.co/t/kibana-bouncing-degraded-available/346685)

<div class="topic-metadata">

**Author:** [@wrsnrno](https://discuss.elastic.co/u/wrsnrno)\
**Replies:** 4\
**Last updated:** [November 10, 2023, 1:06am UTC](https://discuss.elastic.co/t/kibana-bouncing-degraded-available/346685 "2023-11-10T01:06:28Z")

</div>

Would appreciate some points in the right direction here. I have a new stack up and running but Kibana is bouncing availalbe - degraded, frequently but not at regular intervals. The environment is new, (so am I to Elas…

---

## [Sorting results not working properly](https://discuss.elastic.co/t/sorting-results-not-working-properly/346816)

<div class="topic-metadata">

**Author:** [@Mubolio](https://discuss.elastic.co/u/Mubolio)\
**Replies:** 1\
**Last updated:** [November 9, 2023, 11:27pm UTC](https://discuss.elastic.co/t/sorting-results-not-working-properly/346816 "2023-11-09T23:27:38Z")

</div>

Hello, I have a datastream that is updated often, I want to get unique results for the field @timestamp, I use this query: GET datastream\_name/\_search { "sort" : \[ { "@timestamp" : { "order":"desc…

---

## [You are not authorized to access Monitoring. To use Monitoring, you need the privileges granted by both the \`kibana\_admin\` and \`monitoring\_user \` roles](https://discuss.elastic.co/t/you-are-not-authorized-to-access-monitoring-to-use-monitoring-you-need-the-privileges-granted-by-both-the-kibana-admin-and-monitoring-user-roles/346448)

<div class="topic-metadata">

**Author:** [@alexus](https://discuss.elastic.co/u/alexus)\
**Replies:** 1\
**Last updated:** [November 9, 2023, 8:43pm UTC](https://discuss.elastic.co/t/you-are-not-authorized-to-access-monitoring-to-use-monitoring-you-need-the-privileges-granted-by-both-the-kibana-admin-and-monitoring-user-roles/346448 "2023-11-09T20:43:19Z")

</div>

Hello World! I'm trying out eck'quickstart: and even though I'm logging in as elastic user, which is superadmin, I get the following message when I try to access Kibana'Monitoring app: Access Denied You are not aut…

---

## [Prune filter does not work with whitelist but it does with blacklist](https://discuss.elastic.co/t/prune-filter-does-not-work-with-whitelist-but-it-does-with-blacklist/346549)

<div class="topic-metadata">

**Author:** [@elk-user-0001](https://discuss.elastic.co/u/elk-user-0001)\
**Replies:** 1\
**Last updated:** [November 9, 2023, 8:11pm UTC](https://discuss.elastic.co/t/prune-filter-does-not-work-with-whitelist-but-it-does-with-blacklist/346549 "2023-11-09T20:11:15Z")

</div>

Hello colleagues! I am trying to use the prune filter with first level fields ( I know the problem with nested fields ) but I can't get it to work. I have a json of 900 fields and I am interested in keeping only a few,…

---

## [Using Key-value(KV) with multiple Value splits](https://discuss.elastic.co/t/using-key-value-kv-with-multiple-value-splits/346527)

<div class="topic-metadata">

**Author:** [@robnew](https://discuss.elastic.co/u/robnew)\
**Replies:** 6\
**Last updated:** [November 9, 2023, 7:53pm UTC](https://discuss.elastic.co/t/using-key-value-kv-with-multiple-value-splits/346527 "2023-11-09T19:53:20Z")

</div>

I have a wineventlog-application log which has (ie) 'EventCode=33210 EventRecordID=12345' then changes to session\_id:69,server\_principal\_id:226,etc etc so from = to : with , instead of spaces. Is there a way I can use th…

---

## [Mapping Geospatial Time Events](https://discuss.elastic.co/t/mapping-geospatial-time-events/345958)

<div class="topic-metadata">

**Author:** [@Cal](https://discuss.elastic.co/u/Cal)\
**Replies:** 5\
**Last updated:** [November 9, 2023, 6:20pm UTC](https://discuss.elastic.co/t/mapping-geospatial-time-events/345958 "2023-11-09T18:20:25Z")

</div>

I have an index wherein one of the pieces of data is the date a last even occurred as well as location. Using geospatial I want to map the events occurring based on the dates assigned to each document. I want to use th…

---

## [Search for any error exceptions or any specific string in a log file which is pushed from client machine using filebeat agent to Elastic stack server](https://discuss.elastic.co/t/search-for-any-error-exceptions-or-any-specific-string-in-a-log-file-which-is-pushed-from-client-machine-using-filebeat-agent-to-elastic-stack-server/346534)

<div class="topic-metadata">

**Author:** [@kaushalshriyan](https://discuss.elastic.co/u/kaushalshriyan)\
**Replies:** 7\
**Last updated:** [November 9, 2023, 6:09pm UTC](https://discuss.elastic.co/t/search-for-any-error-exceptions-or-any-specific-string-in-a-log-file-which-is-pushed-from-client-machine-using-filebeat-agent-to-elastic-stack-server/346534 "2023-11-09T18:09:12Z")

</div>

Hi, I have this log file /opt/apigee/var/log/edge-message-processor/messagelogging/apigee-dac-training/test/sf-response-parameters/6/log-api/elk.log which is seen in the kibana dashboard. I am searching for a specific s…

---

## [Create Rules in kibana-\> unknown field \[aggs\]](https://discuss.elastic.co/t/create-rules-in-kibana-unknown-field-aggs/346522)

<div class="topic-metadata">

**Author:** [@INS](https://discuss.elastic.co/u/INS)\
**Replies:** 1\
**Last updated:** [November 9, 2023, 5:53pm UTC](https://discuss.elastic.co/t/create-rules-in-kibana-unknown-field-aggs/346522 "2023-11-09T17:53:10Z")

</div>

Hi I need to create some rules in kibana over aggregation function but I don't understand what's wrong I got "Error testing query: EsError: \[1:118\] unknown field \[aggs\]" { "query":{ "aggs": { "last\_values"…

---

## [Fingerprint for json does not get resolved](https://discuss.elastic.co/t/fingerprint-for-json-does-not-get-resolved/346772)

<div class="topic-metadata">

**Author:** [@ranjini](https://discuss.elastic.co/u/ranjini)\
**Replies:** 9\
**Last updated:** [November 9, 2023, 5:12pm UTC](https://discuss.elastic.co/t/fingerprint-for-json-does-not-get-resolved/346772 "2023-11-09T17:12:08Z")

</div>

fingerprint for json is not working input { file { path =\> "/shared/logs/logi2/stats.\*" start\_position =\> "beginning" sincedb\_path =\> "/shared/logs/.sincedb" type =\> "logi2-stats" …

---

## [Showing query parameters in DSL query results](https://discuss.elastic.co/t/showing-query-parameters-in-dsl-query-results/345758)

<div class="topic-metadata">

**Author:** [@bgyomorei\_c](https://discuss.elastic.co/u/bgyomorei_c)\
**Replies:** 1\
**Last updated:** [November 9, 2023, 5:00pm UTC](https://discuss.elastic.co/t/showing-query-parameters-in-dsl-query-results/345758 "2023-11-09T17:00:10Z")

</div>

Let's take the DSL query example below. I'd like to see the value of fixed\_interval in date\_histogram in the generated response. Is it possible to tell in the DSL query to display this or any parameter value in the resul…

---

## [Understanding search-as-you-type Fields](https://discuss.elastic.co/t/understanding-search-as-you-type-fields/346661)

<div class="topic-metadata">

**Author:** [@safakkbilici](https://discuss.elastic.co/u/safakkbilici)\
**Replies:** 2\
**Last updated:** [November 9, 2023, 4:36pm UTC](https://discuss.elastic.co/t/understanding-search-as-you-type-fields/346661 "2023-11-09T16:36:43Z")

</div>

Hello community, I am using ES on my local machine with version of 8.10.4 I was experimenting with search-as-you-type lately and I am confused by ".\_2gram" and ".\_3gram" fields. I created a basic index as PUT autosugg…

---

## [Containerized Metricbeat/Filebeat to monitor E,K,EntSearch](https://discuss.elastic.co/t/containerized-metricbeat-filebeat-to-monitor-e-k-entsearch/346707)

<div class="topic-metadata">

**Author:** [@alongaks](https://discuss.elastic.co/u/alongaks)\
**Replies:** 1\
**Last updated:** [November 9, 2023, 4:30pm UTC](https://discuss.elastic.co/t/containerized-metricbeat-filebeat-to-monitor-e-k-entsearch/346707 "2023-11-09T16:30:33Z")

</div>

Hello, I am working on getting metricbeat (and eventually filebeat ) to report on Elasticsearch, Kibana and Enterprise Search via Docker. I'm using RHEL as the single-node host and as such it is using Podman as the Doc…

---

## [Same shards on different physicals servers](https://discuss.elastic.co/t/same-shards-on-different-physicals-servers/346768)

<div class="topic-metadata">

**Author:** [@daniela09](https://discuss.elastic.co/u/daniela09)\
**Replies:** 7\
**Last updated:** [November 9, 2023, 4:01pm UTC](https://discuss.elastic.co/t/same-shards-on-different-physicals-servers/346768 "2023-11-09T16:01:04Z")

</div>

Hi I have deployed EFK stack on Kubernetes cluster, I have 3 nodes that have both roles data and master, the 3 Elasticsearch nodes are on 3 different Kubernetes nodes, but the Kubernetes nodes are on 2 different physical…

---

## [How to know wich grok is failing?](https://discuss.elastic.co/t/how-to-know-wich-grok-is-failing/346535)

<div class="topic-metadata">

**Author:** [@ElasticLiver](https://discuss.elastic.co/u/ElasticLiver)\
**Replies:** 2\
**Last updated:** [November 9, 2023, 3:46pm UTC](https://discuss.elastic.co/t/how-to-know-wich-grok-is-failing/346535 "2023-11-09T15:46:11Z")

</div>

Hi, Im reviewing the pipeline of an ex colleague, and there is almos 30 grok filters, wich will be the best way to identify wich grok is failing? Im using stdout in the output. Thanks!

---

## [Showcasing Date as yesterday, this week, this month in Kibana Dashboard control options](https://discuss.elastic.co/t/showcasing-date-as-yesterday-this-week-this-month-in-kibana-dashboard-control-options/345435)

<div class="topic-metadata">

**Author:** [@mathur7vidit](https://discuss.elastic.co/u/mathur7vidit)\
**Replies:** 2\
**Last updated:** [November 9, 2023, 3:39pm UTC](https://discuss.elastic.co/t/showcasing-date-as-yesterday-this-week-this-month-in-kibana-dashboard-control-options/345435 "2023-11-09T15:39:56Z")

</div>

Hi Team, i have a date field which showcases date only as per below snap. this date is basically being extracted from one of the available field invoice\_date. Now my requirement is that suppose today is 20 Oct and i…

---

## [Metric Threshold Alert reporting incorrect document count](https://discuss.elastic.co/t/metric-threshold-alert-reporting-incorrect-document-count/346553)

<div class="topic-metadata">

**Author:** [@vsabado](https://discuss.elastic.co/u/vsabado)\
**Replies:** 32\
**Last updated:** [November 9, 2023, 3:34pm UTC](https://discuss.elastic.co/t/metric-threshold-alert-reporting-incorrect-document-count/346553 "2023-11-09T15:34:20Z")

</div>

I have a metric threshold alert that will trigger when document count is above 30. This alert seems to trigger just fine. For the body I'm setting this: And this is the data that I get back when the alert fires up: {…

---

## [Azure EventHub Plugin for Logstash Errors](https://discuss.elastic.co/t/azure-eventhub-plugin-for-logstash-errors/346811)

<div class="topic-metadata">

**Author:** [@Kris\_Felscher](https://discuss.elastic.co/u/Kris_Felscher)\
**Replies:** 0\
**Last updated:** [November 9, 2023, 2:42pm UTC](https://discuss.elastic.co/t/azure-eventhub-plugin-for-logstash-errors/346811 "2023-11-09T14:42:49Z")

</div>

We have Logstash installed on Kubernetes running on 2 pods. My main pipeline is configured to receive events from 2 separate EventHub instances. Here's my Pipeline Input: input { azure\_event\_hubs { config\_m…

---

## [How to create an histogram with many aggregations on X axis and a formula on Y axis](https://discuss.elastic.co/t/how-to-create-an-histogram-with-many-aggregations-on-x-axis-and-a-formula-on-y-axis/346518)

<div class="topic-metadata">

**Author:** [@FIFI](https://discuss.elastic.co/u/FIFI)\
**Replies:** 3\
**Last updated:** [November 9, 2023, 2:35pm UTC](https://discuss.elastic.co/t/how-to-create-an-histogram-with-many-aggregations-on-x-axis-and-a-formula-on-y-axis/346518 "2023-11-09T14:35:03Z")

</div>

Hi, Goal: I would like to create a histogram With two aggregations on X axis. One over terms. One over time. With one aggregation on Y axis. One over terms With a formula to compute value (using lens formula : sum(v…

---

## [Wrong dynamic mapping in Elasticsearch 8.11 prevents indexation of arrays of more than 127 strings](https://discuss.elastic.co/t/wrong-dynamic-mapping-in-elasticsearch-8-11-prevents-indexation-of-arrays-of-more-than-127-strings/346803)

<div class="topic-metadata">

**Author:** [@JulienCarnec](https://discuss.elastic.co/u/JulienCarnec)\
**Replies:** 4\
**Last updated:** [November 9, 2023, 2:24pm UTC](https://discuss.elastic.co/t/wrong-dynamic-mapping-in-elasticsearch-8-11-prevents-indexation-of-arrays-of-more-than-127-strings/346803 "2023-11-09T14:24:54Z")

</div>

Since 8.11.0, when using dynamic mapping, there is a defect preventing the indexation of documents with an array field containing more than 127 strings. Here is how to reproduce: 1- start Elasticsearch 8.11.0: docker …

---

## [Why should we not use Metricbeat with scope: node for clusters with dedicated master nodes](https://discuss.elastic.co/t/why-should-we-not-use-metricbeat-with-scope-node-for-clusters-with-dedicated-master-nodes/346715)

<div class="topic-metadata">

**Author:** [@bunste](https://discuss.elastic.co/u/bunste)\
**Replies:** 9\
**Last updated:** [November 9, 2023, 1:35pm UTC](https://discuss.elastic.co/t/why-should-we-not-use-metricbeat-with-scope-node-for-clusters-with-dedicated-master-nodes/346715 "2023-11-09T13:35:36Z")

</div>

I am currently reading the documentation on collecting Elasticsearch monitoring data with Metricbeat. I had already posted something about this here in the forum, which led to this issue. The documentation has improved s…

---

## [How to improve fuzzy match performance](https://discuss.elastic.co/t/how-to-improve-fuzzy-match-performance/346794)

<div class="topic-metadata">

**Author:** [@chengyang.backend](https://discuss.elastic.co/u/chengyang.backend)\
**Replies:** 1\
**Last updated:** [November 9, 2023, 1:19pm UTC](https://discuss.elastic.co/t/how-to-improve-fuzzy-match-performance/346794 "2023-11-09T13:19:22Z")

</div>

---

## [Watcher log history not available for some watchers scripts](https://discuss.elastic.co/t/watcher-log-history-not-available-for-some-watchers-scripts/346795)

<div class="topic-metadata">

**Author:** [@Seemant\_Bind](https://discuss.elastic.co/u/Seemant_Bind)\
**Replies:** 0\
**Last updated:** [November 9, 2023, 12:48pm UTC](https://discuss.elastic.co/t/watcher-log-history-not-available-for-some-watchers-scripts/346795 "2023-11-09T12:48:29Z")

</div>

Hi, I am currently facing issue with the watcher logs, currently I am using ELK version 7.11 and when I check Execution history of some watcher for last 1 hour, 1 day or even last week , no logs are available. For few w…

---

## [Extract substring from the path](https://discuss.elastic.co/t/extract-substring-from-the-path/346787)

<div class="topic-metadata">

**Author:** [@Xhar](https://discuss.elastic.co/u/Xhar)\
**Replies:** 2\
**Last updated:** [November 9, 2023, 12:43pm UTC](https://discuss.elastic.co/t/extract-substring-from-the-path/346787 "2023-11-09T12:43:16Z")

</div>

in this config input { file { mode =\> "read" path =\> "/opt/stromReciever/parsed\_data/changedRights/csv/\*.json" start\_position =\> "beginning" sincedb\_path =\> "/dev/null" codec =\> "json" type =\> …

---

## [Cloudflare integration not working](https://discuss.elastic.co/t/cloudflare-integration-not-working/346024)

<div class="topic-metadata">

**Author:** [@theacodes](https://discuss.elastic.co/u/theacodes)\
**Replies:** 7\
**Last updated:** [November 9, 2023, 12:28pm UTC](https://discuss.elastic.co/t/cloudflare-integration-not-working/346024 "2023-11-09T12:28:41Z")

</div>

I added this integration and entered all the required key and creds needed. still I am not getting any logs from cloudflare and the dashboard and saved search both are empty. what am I missing?

---

## [Unable to scale down ECK-managed cluster](https://discuss.elastic.co/t/unable-to-scale-down-eck-managed-cluster/346790)

<div class="topic-metadata">

**Author:** [@Philipp\_B](https://discuss.elastic.co/u/Philipp_B)\
**Replies:** 0\
**Last updated:** [November 9, 2023, 12:21pm UTC](https://discuss.elastic.co/t/unable-to-scale-down-eck-managed-cluster/346790 "2023-11-09T12:21:03Z")

</div>

Hi, we're running an ECK 1.7.1, Elastic 7.14.1 cluster with 3 nodes on an Azure Kubernetes cluster (v 1.26.6). The cluster is generally running fine. Now, in order to test scaling scenarios, we expanded the cluster to 6…

[Previous page](https://discuss.elastic.co/latest.md?page=486)

[Next page](https://discuss.elastic.co/latest.md?page=488)
