# Latest

**URL:** https://discuss.elastic.co/latest.md?page=489

[Latest](https://discuss.elastic.co/latest.md) · [Categories](https://discuss.elastic.co/categories.md) · [Tags](https://discuss.elastic.co/tags.md)

**Page:** 490

---

## [Hybrid search by using knn and query in java client](https://discuss.elastic.co/t/hybrid-search-by-using-knn-and-query-in-java-client/346594)

<div class="topic-metadata">

**Author:** [@wshan13](https://discuss.elastic.co/u/wshan13)\
**Replies:** 1\
**Last updated:** [November 8, 2023, 12:18pm UTC](https://discuss.elastic.co/t/hybrid-search-by-using-knn-and-query-in-java-client/346594 "2023-11-08T12:18:50Z")

</div>

Hello. I want the hybrid search by using both the knn option and a query on the page below with java client. With spring-boot 3.1.5 and elasticsarch-java 8.7.1 environment, I made some codes as below, but seems like…

---

## [Aggregate alerts by a specific field and send a summary through an action for each field value encountered](https://discuss.elastic.co/t/aggregate-alerts-by-a-specific-field-and-send-a-summary-through-an-action-for-each-field-value-encountered/346698)

<div class="topic-metadata">

**Author:** [@Arty](https://discuss.elastic.co/u/Arty)\
**Replies:** 0\
**Last updated:** [November 8, 2023, 10:52am UTC](https://discuss.elastic.co/t/aggregate-alerts-by-a-specific-field-and-send-a-summary-through-an-action-for-each-field-value-encountered/346698 "2023-11-08T10:52:37Z")

</div>

Hi everyone, I have set up a Kibana alert security detection rule which creates an alert for all my incoming third-party system alerts (Suricata) and send each one of them to my SIRP using webhook. I have many alerts w…

---

## [Elasticsearch Unable to access 'path.repo' shared folder](https://discuss.elastic.co/t/elasticsearch-unable-to-access-path-repo-shared-folder/346377)

<div class="topic-metadata">

**Author:** [@Aasif\_Ansari](https://discuss.elastic.co/u/Aasif_Ansari)\
**Replies:** 2\
**Last updated:** [November 8, 2023, 10:23am UTC](https://discuss.elastic.co/t/elasticsearch-unable-to-access-path-repo-shared-folder/346377 "2023-11-08T10:23:36Z")

</div>

Hi Team, I have Elasticsearch installed to my windows server. And I have another windows server with file system shared with the first one. I have map network drive to "I" letter and path "I:\\Elasticsearch-Snapshot-v2" …

---

## [Indices got deleted anonymously](https://discuss.elastic.co/t/indices-got-deleted-anonymously/346641)

<div class="topic-metadata">

**Author:** [@aneesh](https://discuss.elastic.co/u/aneesh)\
**Replies:** 3\
**Last updated:** [November 8, 2023, 10:15am UTC](https://discuss.elastic.co/t/indices-got-deleted-anonymously/346641 "2023-11-08T10:15:22Z")

</div>

Hi, some of the indices are deleted. Following is the log we have. Can you please let us know for the possibilities for same. \[2023-11-07T00:52:00,000\]\[INFO \]\[o.e.x.m.MlDailyMaintenanceService\] \[ServerName1\] triggerin…

---

## [Elasticsearch installation issues](https://discuss.elastic.co/t/elasticsearch-installation-issues/346584)

<div class="topic-metadata">

**Author:** [@bosimaosh](https://discuss.elastic.co/u/bosimaosh)\
**Replies:** 2\
**Last updated:** [November 8, 2023, 10:10am UTC](https://discuss.elastic.co/t/elasticsearch-installation-issues/346584 "2023-11-08T10:10:57Z")

</div>

After installing Elasticsearch, when I try to start the elasticsearch.service service, it fails to start and I receive the following error. system is Ubuntu 20.04. Elasticsearch version is 7.17.14 sudo systemctl stat…

---

## [O365 no failed loggins shown](https://discuss.elastic.co/t/o365-no-failed-loggins-shown/346034)

<div class="topic-metadata">

**Author:** [@helldunkel](https://discuss.elastic.co/u/helldunkel)\
**Replies:** 5\
**Last updated:** [November 8, 2023, 10:08am UTC](https://discuss.elastic.co/t/o365-no-failed-loggins-shown/346034 "2023-11-08T10:08:00Z")

</div>

Hi, we test the o365 integration in elastic. Most works correct, but we don´t see the failed loggins. We only see the success state. In O365 it shows alle failed loggins, but no logs in elastic. ELK Stack: 8.8.2 Int…

---

## [Risks of Fleet and endpoint agents](https://discuss.elastic.co/t/risks-of-fleet-and-endpoint-agents/346521)

<div class="topic-metadata">

**Author:** [@ivahbo](https://discuss.elastic.co/u/ivahbo)\
**Replies:** 4\
**Last updated:** [November 8, 2023, 9:57am UTC](https://discuss.elastic.co/t/risks-of-fleet-and-endpoint-agents/346521 "2023-11-08T09:57:00Z")

</div>

If the Elastic/Fleet server is compromised, can the compromise be leveraged to gain access to the systems running endpoint agents? For example, can you push a malicious update to endpoint agents?

---

## [Understanding query difference](https://discuss.elastic.co/t/understanding-query-difference/346690)

<div class="topic-metadata">

**Author:** [@Vivek\_Burman](https://discuss.elastic.co/u/Vivek_Burman)\
**Replies:** 0\
**Last updated:** [November 8, 2023, 9:44am UTC](https://discuss.elastic.co/t/understanding-query-difference/346690 "2023-11-08T09:44:42Z")

</div>

Below are two queries with their respective responses. I would like to understand the difference between the below queries from the point of aggregation. In Request 1 I filter docs based on "unique\_name" and then group t…

---

## [Filebeat don't send files without errors in log](https://discuss.elastic.co/t/filebeat-dont-send-files-without-errors-in-log/346396)

<div class="topic-metadata">

**Author:** [@enp2s6](https://discuss.elastic.co/u/enp2s6)\
**Replies:** 16\
**Last updated:** [November 8, 2023, 7:49am UTC](https://discuss.elastic.co/t/filebeat-dont-send-files-without-errors-in-log/346396 "2023-11-08T07:49:58Z")

</div>

Hi forum, I apologize for having to spam again. However, I just can't find the solution. I have a newly installed elasticsearch + kibana + filebeat. Installed the latest 8.x packages from the Debian repositories. I …

---

## [How can I filter certain information from the logs?](https://discuss.elastic.co/t/how-can-i-filter-certain-information-from-the-logs/344293)

<div class="topic-metadata">

**Author:** [@hta](https://discuss.elastic.co/u/hta)\
**Replies:** 7\
**Last updated:** [November 8, 2023, 7:41am UTC](https://discuss.elastic.co/t/how-can-i-filter-certain-information-from-the-logs/344293 "2023-11-08T07:41:48Z")

</div>

We work with ELK Stack and I have the task of creating meaningful visualizations from the log entries. I have logs in the following format: { "@timestamp": \[ "2023-08-08T00:00:11.2123" \], "xxxxx": \[ "yyyyy…

---

## [ElasticSearch cluster backup](https://discuss.elastic.co/t/elasticsearch-cluster-backup/346680)

<div class="topic-metadata">

**Author:** [@laurentiusoica](https://discuss.elastic.co/u/laurentiusoica)\
**Replies:** 3\
**Last updated:** [November 8, 2023, 7:34am UTC](https://discuss.elastic.co/t/elasticsearch-cluster-backup/346680 "2023-11-08T07:34:24Z")

</div>

Hi, For an Elasticsearch cluster, is it a supported way to backup the cluster by completely shutting it down and take data volumes snapshots?

---

## [Error "String length exceeds the maximum length (5000000)" when transferring a large document to the attachment pipeline](https://discuss.elastic.co/t/error-string-length-exceeds-the-maximum-length-5000000-when-transferring-a-large-document-to-the-attachment-pipeline/345687)

<div class="topic-metadata">

**Author:** [@Vlad\_I](https://discuss.elastic.co/u/Vlad_I)\
**Replies:** 5\
**Last updated:** [November 8, 2023, 3:25am UTC](https://discuss.elastic.co/t/error-string-length-exceeds-the-maximum-length-5000000-when-transferring-a-large-document-to-the-attachment-pipeline/345687 "2023-11-08T03:25:44Z")

</div>

I'm using Elasticsearch 8.9.1 Using python, I send an 8MB xlsx document to the Elasticsearch index via attachment pipeline. But the error "String length (5046272) exceeds the maximum length (5000000)" appears. For exam…

---

## [I have a question, can I take the ldap attribute to create a role map? and the following is the ldap configuration in elasticsearch.yml](https://discuss.elastic.co/t/i-have-a-question-can-i-take-the-ldap-attribute-to-create-a-role-map-and-the-following-is-the-ldap-configuration-in-elasticsearch-yml/346676)

<div class="topic-metadata">

**Author:** [@Tsabitul\_azmi1](https://discuss.elastic.co/u/Tsabitul_azmi1)\
**Replies:** 0\
**Last updated:** [November 8, 2023, 3:04am UTC](https://discuss.elastic.co/t/i-have-a-question-can-i-take-the-ldap-attribute-to-create-a-role-map-and-the-following-is-the-ldap-configuration-in-elasticsearch-yml/346676 "2023-11-08T03:04:30Z")

</div>

xpack: security: authc: realms: ldap: ldap1: order: 0 url: "ldap://xxx.xxx.xxx.xxx:389" bind\_dn: "uid=xxxxx,ou=accounts,o=xxx,dc=xx,dc=xx" #user\_search.attribute: "branchalias" #user\_group\_attribute: "branchali…

---

## [Elastic agent(synthetics) error connecting to fleet](https://discuss.elastic.co/t/elastic-agent-synthetics-error-connecting-to-fleet/346669)

<div class="topic-metadata">

**Author:** [@senyam08](https://discuss.elastic.co/u/senyam08)\
**Replies:** 0\
**Last updated:** [November 7, 2023, 11:47pm UTC](https://discuss.elastic.co/t/elastic-agent-synthetics-error-connecting-to-fleet/346669 "2023-11-07T23:47:03Z")

</div>

Deployed elastic stack using ECK operator Trying to deploy elastic agent as deployment to run synthetics. Deployed fleet server as its required for synthetics elastic agent Followed the config from below https://raw.g…

---

## [Logstash export not working correctly, only a part of data exported](https://discuss.elastic.co/t/logstash-export-not-working-correctly-only-a-part-of-data-exported/346657)

<div class="topic-metadata">

**Author:** [@andre22](https://discuss.elastic.co/u/andre22)\
**Replies:** 1\
**Last updated:** [November 7, 2023, 10:27pm UTC](https://discuss.elastic.co/t/logstash-export-not-working-correctly-only-a-part-of-data-exported/346657 "2023-11-07T22:27:33Z")

</div>

Hi, i want to export some data from old indexes and write them into a text file. When I restart logstash, it exports some data (a part of one day, the index has a complete month) and goes back to do nothing. I am using …

---

## [Logstash s3 output plugin and linux fs inode](https://discuss.elastic.co/t/logstash-s3-output-plugin-and-linux-fs-inode/346437)

<div class="topic-metadata">

**Author:** [@alexus](https://discuss.elastic.co/u/alexus)\
**Replies:** 1\
**Last updated:** [November 7, 2023, 9:25pm UTC](https://discuss.elastic.co/t/logstash-s3-output-plugin-and-linux-fs-inode/346437 "2023-11-07T21:25:57Z")

</div>

Hello World! I'm using Logstash 7.17 and experiencing an issue with Logstash and S3 output plugin: $ logstash --version Using bundled JDK: /usr/share/logstash/jdk logstash 7.17.13 $ ./bin/logstash-plugin list logstash-…

---

## [VegaLite Code Error: Cannot convert undefined or null to object](https://discuss.elastic.co/t/vegalite-code-error-cannot-convert-undefined-or-null-to-object/346656)

<div class="topic-metadata">

**Author:** [@rahuja23](https://discuss.elastic.co/u/rahuja23)\
**Replies:** 0\
**Last updated:** [November 7, 2023, 9:02pm UTC](https://discuss.elastic.co/t/vegalite-code-error-cannot-convert-undefined-or-null-to-object/346656 "2023-11-07T21:02:35Z")

</div>

System Specifications: Kibana Version: 8.8.2 Elastic Search Version: 8.8.2 Environment: local (Mac OS arm64) I am new to vega. I am trying to create a Gantt chart visualisation using vega code but for some reason the…

---

## [🎉 What’s new in Elastic 8.11](https://discuss.elastic.co/t/what-s-new-in-elastic-8-11/346653)

<div class="topic-metadata">

**Author:** [@dadoonet](https://discuss.elastic.co/u/dadoonet)\
**Replies:** 0\
**Last updated:** [November 7, 2023, 8:34pm UTC](https://discuss.elastic.co/t/what-s-new-in-elastic-8-11/346653 "2023-11-07T20:34:42Z")

</div>

:tada: What’s new in Elastic 8.11 Learn about Elastic 8.11 which includes the GA of the Elastic Learned Sparse EncodeR (ELSER) and the technical preview of Elasticsearch Query Language (ES|QL), a new piped query language…

---

## [AWS Lambda with Webpack throws error](https://discuss.elastic.co/t/aws-lambda-with-webpack-throws-error/346575)

<div class="topic-metadata">

**Author:** [@Myths](https://discuss.elastic.co/u/Myths)\
**Replies:** 4\
**Last updated:** [November 7, 2023, 6:49pm UTC](https://discuss.elastic.co/t/aws-lambda-with-webpack-throws-error/346575 "2023-11-07T18:49:07Z")

</div>

I am trying to use the aws lambda layer to communicate with APM We use webpack for bundling , I am getting below error. I have tried including the elastic-apm-node in package.json with no luck . Just wondering if the…

---

## [How to solve \_geoip\_expired\_database](https://discuss.elastic.co/t/how-to-solve-geoip-expired-database/346583)

<div class="topic-metadata">

**Author:** [@yuswanul](https://discuss.elastic.co/u/yuswanul)\
**Replies:** 6\
**Last updated:** [November 7, 2023, 5:53pm UTC](https://discuss.elastic.co/t/how-to-solve-geoip-expired-database/346583 "2023-11-07T17:53:15Z")

</div>

Hi, I've been experiencing an issue with the GeoIP filter here. So, at the beginning of my logstash deployment, the GeoIP filter was working well but recently I saw a tag on all my documents that said \_geoip\_expired\_dat…

---

## [Failure to install package \[checkpoint\]](https://discuss.elastic.co/t/failure-to-install-package-checkpoint/346646)

<div class="topic-metadata">

**Author:** [@shaam1](https://discuss.elastic.co/u/shaam1)\
**Replies:** 0\
**Last updated:** [November 7, 2023, 5:44pm UTC](https://discuss.elastic.co/t/failure-to-install-package-checkpoint/346646 "2023-11-07T17:44:03Z")

</div>

Hi, I am not new to ELK, but I have an issue which I hope to solve with your help. I installed the Checkpoint integration using the button, but I get the error below: I am not able to \[WARN \]\[plugins.fleet\] Failure to…

---

## [How to add multiline on custom logs](https://discuss.elastic.co/t/how-to-add-multiline-on-custom-logs/346637)

<div class="topic-metadata">

**Author:** [@MirkoSpezie](https://discuss.elastic.co/u/MirkoSpezie)\
**Replies:** 0\
**Last updated:** [November 7, 2023, 3:39pm UTC](https://discuss.elastic.co/t/how-to-add-multiline-on-custom-logs/346637 "2023-11-07T15:39:36Z")

</div>

I'm trying to figure out on how to configure the custom logs integration to manage multiline logs (log4j)

---

## [Rally 2.10.0](https://discuss.elastic.co/t/rally-2-10-0/346632)

<div class="topic-metadata">

**Author:** [@gbanasiak](https://discuss.elastic.co/u/gbanasiak)\
**Replies:** 0\
**Last updated:** [November 7, 2023, 3:12pm UTC](https://discuss.elastic.co/t/rally-2-10-0/346632 "2023-11-07T15:12:32Z")

</div>

Rally 2.10.0 has just been released. This version brings support for Elastic Serverless. Highlights #1797: Document Rally use with Elastic Serverless Enhancements #1791: Add ESQL operator #1789: Add serverless-aware …

---

## [ILM for new indices created via Logstash](https://discuss.elastic.co/t/ilm-for-new-indices-created-via-logstash/346621)

<div class="topic-metadata">

**Author:** [@tecbox41](https://discuss.elastic.co/u/tecbox41)\
**Replies:** 0\
**Last updated:** [November 7, 2023, 1:40pm UTC](https://discuss.elastic.co/t/ilm-for-new-indices-created-via-logstash/346621 "2023-11-07T13:40:33Z")

</div>

I am trying to apply ILM to new indices created via Logstash, but it doesn't seem to show the new indices being managed by ILM. I am using the default index template and do not have streams configured for these indices. …

---

## [Add a custom field to separate customers](https://discuss.elastic.co/t/add-a-custom-field-to-separate-customers/346624)

<div class="topic-metadata">

**Author:** [@ElasticLiver](https://discuss.elastic.co/u/ElasticLiver)\
**Replies:** 0\
**Last updated:** [November 7, 2023, 2:24pm UTC](https://discuss.elastic.co/t/add-a-custom-field-to-separate-customers/346624 "2023-11-07T14:24:34Z")

</div>

Hi, I will have two diferent customers, they will use two separate APM server sending data to the same elasticsearch, is there a way to add a custom field "customer\_name" to do the filtering in the roles?

---

## [Logstash log containing huge nested JSON-objects](https://discuss.elastic.co/t/logstash-log-containing-huge-nested-json-objects/346623)

<div class="topic-metadata">

**Author:** [@apt-get\_install\_skil](https://discuss.elastic.co/u/apt-get_install_skil)\
**Replies:** 0\
**Last updated:** [November 7, 2023, 2:08pm UTC](https://discuss.elastic.co/t/logstash-log-containing-huge-nested-json-objects/346623 "2023-11-07T14:08:46Z")

</div>

Hey guys, since we upgraded our stack components to version 8.10.2, Logstash's internal logging behaviour has changed. For example, after all pipelines were startet, Logstash logs the following message: { "level": "…

---

## [How I can obtain an average from a normalization formula](https://discuss.elastic.co/t/how-i-can-obtain-an-average-from-a-normalization-formula/345644)

<div class="topic-metadata">

**Author:** [@Silvy20](https://discuss.elastic.co/u/Silvy20)\
**Replies:** 3\
**Last updated:** [November 7, 2023, 2:15pm UTC](https://discuss.elastic.co/t/how-i-can-obtain-an-average-from-a-normalization-formula/345644 "2023-11-07T14:15:04Z")

</div>

Hello, I've created a data histogram chart based in a formula where I'm expecting to analyze the amount of requests per device. However. I'd like to plot in the same chart a static line with the average around that day. …

---

## [Aggregation of aggregation](https://discuss.elastic.co/t/aggregation-of-aggregation/346472)

<div class="topic-metadata">

**Author:** [@Hakan\_Kucuk](https://discuss.elastic.co/u/Hakan_Kucuk)\
**Replies:** 1\
**Last updated:** [November 7, 2023, 1:37pm UTC](https://discuss.elastic.co/t/aggregation-of-aggregation/346472 "2023-11-07T13:37:39Z")

</div>

Hello, I’m struggling to create a query and dashboard for my specific scenario. I have a dataset of orders with the following structure: order\_id order\_status timestamp 1 started 01.01.2023 1 in\_progress 02.0…

---

## [Kibana custom labels missing from CSV export](https://discuss.elastic.co/t/kibana-custom-labels-missing-from-csv-export/346616)

<div class="topic-metadata">

**Author:** [@jonnyo](https://discuss.elastic.co/u/jonnyo)\
**Replies:** 0\
**Last updated:** [November 7, 2023, 12:00pm UTC](https://discuss.elastic.co/t/kibana-custom-labels-missing-from-csv-export/346616 "2023-11-07T12:00:52Z")

</div>

Hi. I have a Kibana report that utilises Custom Labels, but these labels do not get exported when using the Share option to CSV. Is it possible to export my report to CSV and retain the custom labels that I have set? Th…

---

## [Creating JSON structure for sensor.community API](https://discuss.elastic.co/t/creating-json-structure-for-sensor-community-api/346470)

<div class="topic-metadata">

**Author:** [@CargoBikoMeter](https://discuss.elastic.co/u/CargoBikoMeter)\
**Replies:** 8\
**Last updated:** [November 7, 2023, 11:47am UTC](https://discuss.elastic.co/t/creating-json-structure-for-sensor-community-api/346470 "2023-11-07T11:47:54Z")

</div>

I will send data from my logstash pipeline to the sensor.community API. The API requires the following structure which works with my curl command: curl --location --request POST 'https://api.sensor.community/v1/push-sen…

[Previous page](https://discuss.elastic.co/latest.md?page=488)

[Next page](https://discuss.elastic.co/latest.md?page=490)
