# Latest

**URL:** https://discuss.elastic.co/latest.md?page=501

[Latest](https://discuss.elastic.co/latest.md) · [Categories](https://discuss.elastic.co/categories.md) · [Tags](https://discuss.elastic.co/tags.md)

**Page:** 502

---

## [Logstash Service With Plugin that close after finish](https://discuss.elastic.co/t/logstash-service-with-plugin-that-close-after-finish/345820)

<div class="topic-metadata">

**Author:** [@Samuele\_Lolli](https://discuss.elastic.co/u/Samuele_Lolli)\
**Replies:** 0\
**Last updated:** [October 26, 2023, 1:13pm UTC](https://discuss.elastic.co/t/logstash-service-with-plugin-that-close-after-finish/345820 "2023-10-26T13:13:58Z")

</div>

Hi everyone, i have a quick question. I created a pipeline that after completition end by closing the prompt and my current configuration is logstash as a service in a linux server. What happens if i add the pipeline t…

---

## [Filebeat: not found matching indicies with pattern](https://discuss.elastic.co/t/filebeat-not-found-matching-indicies-with-pattern/345810)

<div class="topic-metadata">

**Author:** [@libertey](https://discuss.elastic.co/u/libertey)\
**Replies:** 1\
**Last updated:** [October 26, 2023, 1:05pm UTC](https://discuss.elastic.co/t/filebeat-not-found-matching-indicies-with-pattern/345810 "2023-10-26T13:05:59Z")

</div>

Hey, im new to the complete elk stack now i tried to integrate it in one of our projects where only Elasticsearch was installed before. The Kibana installation worked great and was no problem. also the installation of l…

---

## [Runtime field component mapping with IF in script fails to parse due to compile error](https://discuss.elastic.co/t/runtime-field-component-mapping-with-if-in-script-fails-to-parse-due-to-compile-error/345816)

<div class="topic-metadata">

**Author:** [@dmgeurts](https://discuss.elastic.co/u/dmgeurts)\
**Replies:** 1\
**Last updated:** [October 26, 2023, 12:51pm UTC](https://discuss.elastic.co/t/runtime-field-component-mapping-with-if-in-script-fails-to-parse-due-to-compile-error/345816 "2023-10-26T12:51:54Z")

</div>

I'm trying to create a mapping based on a value. However, whatever I try to save the component template, I'm shown the following error: :warning: Unable to create component template Failed to parse mapping: compile er…

---

## [Securityadmin.sh unable to find valid certification path to requested target error](https://discuss.elastic.co/t/securityadmin-sh-unable-to-find-valid-certification-path-to-requested-target-error/345809)

<div class="topic-metadata">

**Author:** [@Xhar](https://discuss.elastic.co/u/Xhar)\
**Replies:** 2\
**Last updated:** [October 26, 2023, 12:49pm UTC](https://discuss.elastic.co/t/securityadmin-sh-unable-to-find-valid-certification-path-to-requested-target-error/345809 "2023-10-26T12:49:58Z")

</div>

Hello,when i'm trying to execute securityadmin.sh with command ./securityadmin.sh -f /home/user/Documents/opensearch-2.8.0/config/opensearch-security/config.yml -icl -nhnv -cert /home/user/Documents/opensearch-2.8.0/con…

---

## [\[Kibana\] Visualize number of documents having a field inferior to the 99th percentile of this field](https://discuss.elastic.co/t/kibana-visualize-number-of-documents-having-a-field-inferior-to-the-99th-percentile-of-this-field/344485)

<div class="topic-metadata">

**Author:** [@JeromeLavadou](https://discuss.elastic.co/u/JeromeLavadou)\
**Replies:** 4\
**Last updated:** [October 26, 2023, 12:40pm UTC](https://discuss.elastic.co/t/kibana-visualize-number-of-documents-having-a-field-inferior-to-the-99th-percentile-of-this-field/344485 "2023-10-26T12:40:17Z")

</div>

Hello, Is there a way, in a Kibana visualization (Lens, TSVB...), to display on a chart (line, bar, etc.), for each time bucket, the number of documents having a field, let's says "response\_time", inferior to the 99th p…

---

## [Anonymize part of string](https://discuss.elastic.co/t/anonymize-part-of-string/345631)

<div class="topic-metadata">

**Author:** [@ddoroshenko](https://discuss.elastic.co/u/ddoroshenko)\
**Replies:** 3\
**Last updated:** [October 26, 2023, 12:30pm UTC](https://discuss.elastic.co/t/anonymize-part-of-string/345631 "2023-10-26T12:30:56Z")

</div>

Hi, I have access logs which contains sensitive data \[2023-00-00T00:00:00.000\] ... "GET /example.com/foo/bar?password=SecretPassword&user=UserName" ... Is it possible to anonymize password value in that string?

---

## [Map azureAD roles or groups with elasticsearch roles](https://discuss.elastic.co/t/map-azuread-roles-or-groups-with-elasticsearch-roles/345763)

<div class="topic-metadata">

**Author:** [@ebuildy](https://discuss.elastic.co/u/ebuildy)\
**Replies:** 2\
**Last updated:** [October 26, 2023, 12:30pm UTC](https://discuss.elastic.co/t/map-azuread-roles-or-groups-with-elasticsearch-roles/345763 "2023-10-26T12:30:14Z")

</div>

We deploy ES 8.8.1 with ECK on kubernetes. We connect it to azureAD, login works fine. I would like to map azureAD roles or groups with elasticsearch roles, I have no idea how to start. Our config is: xpack.security.…

---

## [Download csv report is intermittently failing if documents are more](https://discuss.elastic.co/t/download-csv-report-is-intermittently-failing-if-documents-are-more/345775)

<div class="topic-metadata">

**Author:** [@rkidev](https://discuss.elastic.co/u/rkidev)\
**Replies:** 1\
**Last updated:** [October 26, 2023, 12:23pm UTC](https://discuss.elastic.co/t/download-csv-report-is-intermittently-failing-if-documents-are-more/345775 "2023-10-26T12:23:52Z")

</div>

Hi, download csv report is always failing if documents are more than 40k, and for around 30k documents it's getting success sometimes but sometimes it's failing. I am using Kibana 7.16.3 version single node cluster and…

---

## [Logstash stopped processing because of an error: (LoadError) failure to load file: java.io.FileNotFoundException: /usr/share/logstash/logstash-core/lib/logstash/build.rb (Permission denied)](https://discuss.elastic.co/t/logstash-stopped-processing-because-of-an-error-loaderror-failure-to-load-file-java-io-filenotfoundexception-usr-share-logstash-logstash-core-lib-logstash-build-rb-permission-denied/345801)

<div class="topic-metadata">

**Author:** [@jrajasek](https://discuss.elastic.co/u/jrajasek)\
**Replies:** 0\
**Last updated:** [October 26, 2023, 11:34am UTC](https://discuss.elastic.co/t/logstash-stopped-processing-because-of-an-error-loaderror-failure-to-load-file-java-io-filenotfoundexception-usr-share-logstash-logstash-core-lib-logstash-build-rb-permission-denied/345801 "2023-10-26T11:34:38Z")

</div>

Building the custom docker image with these below commands. FROM docker.elastic.co/logstash/logstash:8.10.4 RUN rm -f /usr/share/logstash/pipeline/logstash.conf COPY pipeline/ /usr/share/logstash/pipeline/ COPY confi…

---

## [Show complete xml content on mousehover in Kibana 8.3.2 table view](https://discuss.elastic.co/t/show-complete-xml-content-on-mousehover-in-kibana-8-3-2-table-view/345619)

<div class="topic-metadata">

**Author:** [@rkidev](https://discuss.elastic.co/u/rkidev)\
**Replies:** 3\
**Last updated:** [October 26, 2023, 10:07am UTC](https://discuss.elastic.co/t/show-complete-xml-content-on-mousehover-in-kibana-8-3-2-table-view/345619 "2023-10-26T10:07:10Z")

</div>

Hi, I added the fields from documents in Discover and save it. After that I visualized that saved table from library into dashboard. One of the field is having xml content but in table it's not showing complete content. …

---

## [Total number of shards](https://discuss.elastic.co/t/total-number-of-shards/345749)

<div class="topic-metadata">

**Author:** [@lemospt](https://discuss.elastic.co/u/lemospt)\
**Replies:** 2\
**Last updated:** [October 26, 2023, 9:25am UTC](https://discuss.elastic.co/t/total-number-of-shards/345749 "2023-10-26T09:25:27Z")

</div>

Hi Guys, i have an elastic cluster with 5 nodes. This cluster is configured 1290 indices, all indices is configured to have 2 primary shards and 1 replica shard. For me the cluster should have 3\*1290=3870 shards but ac…

---

## [Universal Profiling is not working after Upgrade 8.9.0 to 8.10.3](https://discuss.elastic.co/t/universal-profiling-is-not-working-after-upgrade-8-9-0-to-8-10-3/344928)

<div class="topic-metadata">

**Author:** [@Nabeel\_Ahmed\_NAK](https://discuss.elastic.co/u/Nabeel_Ahmed_NAK)\
**Replies:** 11\
**Last updated:** [October 26, 2023, 9:24am UTC](https://discuss.elastic.co/t/universal-profiling-is-not-working-after-upgrade-8-9-0-to-8-10-3/344928 "2023-10-26T09:24:35Z")

</div>

Hi All I have upgraded Elastic Search from 8.9.0 to 8.10.3. It was working fine previously. After upgrade, Universal Profiling is not working. I have also followed this guide Upgrade Universal Profiling | Elastic Obse…

---

## [Alternative to CLASSPATH for ecs-logging-core.jar and jul-ecs-formatter.jar with Tomcat](https://discuss.elastic.co/t/alternative-to-classpath-for-ecs-logging-core-jar-and-jul-ecs-formatter-jar-with-tomcat/345785)

<div class="topic-metadata">

**Author:** [@AlexanderDyas](https://discuss.elastic.co/u/AlexanderDyas)\
**Replies:** 0\
**Last updated:** [October 26, 2023, 9:00am UTC](https://discuss.elastic.co/t/alternative-to-classpath-for-ecs-logging-core-jar-and-jul-ecs-formatter-jar-with-tomcat/345785 "2023-10-26T09:00:17Z")

</div>

Tomcat 9.0.52 Java openjdk version "1.8.0\_302" Linux As per the suggestion (Get started | ECS Logging Java Reference \[1.x\] | Elastic) I have been successfully using ecs-logging-core.jar and jul-ecs-formatter.jar by ad…

---

## [ML CPU, Memory, of Host/Processes](https://discuss.elastic.co/t/ml-cpu-memory-of-host-processes/345781)

<div class="topic-metadata">

**Author:** [@Nabeel\_Ahmed\_NAK](https://discuss.elastic.co/u/Nabeel_Ahmed_NAK)\
**Replies:** 0\
**Last updated:** [October 26, 2023, 8:26am UTC](https://discuss.elastic.co/t/ml-cpu-memory-of-host-processes/345781 "2023-10-26T08:26:00Z")

</div>

Hi All Using Machine Learning Anomaly/data frame I want to find the root cause of high CPU and memory, concerning the host and processes. Moreover, if possible error logs and any APM are running, that data too. I need…

---

## [Trying to use sum\_bucket agg to summarize the last value per server into a total](https://discuss.elastic.co/t/trying-to-use-sum-bucket-agg-to-summarize-the-last-value-per-server-into-a-total/345729)

<div class="topic-metadata">

**Author:** [@mekberg](https://discuss.elastic.co/u/mekberg)\
**Replies:** 4\
**Last updated:** [October 26, 2023, 8:06am UTC](https://discuss.elastic.co/t/trying-to-use-sum-bucket-agg-to-summarize-the-last-value-per-server-into-a-total/345729 "2023-10-26T08:06:44Z")

</div>

I'm trying to create a search (ultimately a visualization) that will give me the total number of Controller nodes in a cluster. Each node reports metrics every 15 seconds, and each document will contain the value for tha…

---

## [I need to use the Suggester when I enable the DLS](https://discuss.elastic.co/t/i-need-to-use-the-suggester-when-i-enable-the-dls/345263)

<div class="topic-metadata">

**Author:** [@sjp.jamalian](https://discuss.elastic.co/u/sjp.jamalian)\
**Replies:** 4\
**Last updated:** [October 26, 2023, 6:34am UTC](https://discuss.elastic.co/t/i-need-to-use-the-suggester-when-i-enable-the-dls/345263 "2023-10-26T06:34:42Z")

</div>

Hello, When I enable the security and want to use the Suggester, I get this error: org.elasticsearch.ElasticsearchException: Elasticsearch exception \[type=security\_exception, reason=Suggest isn't supported if document …

---

## [How to compare value exactly from array of document with params in script plainess?](https://discuss.elastic.co/t/how-to-compare-value-exactly-from-array-of-document-with-params-in-script-plainess/345691)

<div class="topic-metadata">

**Author:** [@duyhunter1001](https://discuss.elastic.co/u/duyhunter1001)\
**Replies:** 2\
**Last updated:** [October 26, 2023, 6:19am UTC](https://discuss.elastic.co/t/how-to-compare-value-exactly-from-array-of-document-with-params-in-script-plainess/345691 "2023-10-26T06:19:16Z")

</div>

Hi everyone, I have a index example above: PUT target\_index { "mappings": { "properties": { "targetoperator": { "type": "keyword" }, "targetvalue": { "type": "float" } } } } PUT t…

---

## [Get repository folder name for an index](https://discuss.elastic.co/t/get-repository-folder-name-for-an-index/345737)

<div class="topic-metadata">

**Author:** [@karan\_c](https://discuss.elastic.co/u/karan_c)\
**Replies:** 2\
**Last updated:** [October 26, 2023, 6:15am UTC](https://discuss.elastic.co/t/get-repository-folder-name-for-an-index/345737 "2023-10-26T06:15:18Z")

</div>

Hi All, I'm creating day wise snapshots which contains multiple indices for different services (also day wise). I'm planning to move older snapshots from S3 Intelligent-Tiering to S3 Glacier Deep Archive storage class. …

---

## [Tracing between Reactive and Servlet applications](https://discuss.elastic.co/t/tracing-between-reactive-and-servlet-applications/345727)

<div class="topic-metadata">

**Author:** [@Askhat\_Abishev](https://discuss.elastic.co/u/Askhat_Abishev)\
**Replies:** 1\
**Last updated:** [October 26, 2023, 6:06am UTC](https://discuss.elastic.co/t/tracing-between-reactive-and-servlet-applications/345727 "2023-10-26T06:06:02Z")

</div>

I have several Spring Boot REST applications (Servlet) behind Spring Cloud Gateway (WebFlux) single entry point application. I've noticed that calls that are made between services have the same trace.id in scope of one r…

---

## [Elastic agent - Logs for Hosts](https://discuss.elastic.co/t/elastic-agent-logs-for-hosts/345772)

<div class="topic-metadata">

**Author:** [@The\_BlueishSky](https://discuss.elastic.co/u/The_BlueishSky)\
**Replies:** 0\
**Last updated:** [October 26, 2023, 5:58am UTC](https://discuss.elastic.co/t/elastic-agent-logs-for-hosts/345772 "2023-10-26T05:58:33Z")

</div>

We are in process of implementing ELK Agent and more focus for better SIEM detections. At the moment our config ships all the logs and we also don't want to tailor only security events. Is there a recommendation or exp…

---

## [Notes on Alerts or auto open case](https://discuss.elastic.co/t/notes-on-alerts-or-auto-open-case/345771)

<div class="topic-metadata">

**Author:** [@Renato\_Arraes](https://discuss.elastic.co/u/Renato_Arraes)\
**Replies:** 0\
**Last updated:** [October 26, 2023, 5:41am UTC](https://discuss.elastic.co/t/notes-on-alerts-or-auto-open-case/345771 "2023-10-26T05:41:51Z")

</div>

Hello everyone, Im currently doing the configuration of the Alerts, and i want to know if theres a way to put some notes or open directly a case from an alert, since we do have to treat the Alerts we need to input some …

---

## [Configuration Elastic Cluster 8.10.3 Certificates in roles master, coordinator anda data](https://discuss.elastic.co/t/configuration-elastic-cluster-8-10-3-certificates-in-roles-master-coordinator-anda-data/345750)

<div class="topic-metadata">

**Author:** [@efrainMZ](https://discuss.elastic.co/u/efrainMZ)\
**Replies:** 1\
**Last updated:** [October 26, 2023, 4:05am UTC](https://discuss.elastic.co/t/configuration-elastic-cluster-8-10-3-certificates-in-roles-master-coordinator-anda-data/345750 "2023-10-26T04:05:04Z")

</div>

I have a question, how can I configure the certificates for an elastic cluster in version 8.10.3, it will contain master roles, coordinators, data and machine learning. Is it intended to have several roles on the nodes,…

---

## ["could not read the current timestamp"](https://discuss.elastic.co/t/could-not-read-the-current-timestamp/344608)

<div class="topic-metadata">

**Author:** [@arunv707](https://discuss.elastic.co/u/arunv707)\
**Replies:** 1\
**Last updated:** [October 26, 2023, 3:59am UTC](https://discuss.elastic.co/t/could-not-read-the-current-timestamp/344608 "2023-10-26T03:59:25Z")

</div>

I get the following in application logs. Could someone please help? \[2023-09-19T17:07:52,876\]\[DEBUG\]\[o.e.a.s.TransportSearchAction\] \[O1onMaP\] \[xxxxxx\]\[0\], node\[a24qYwKTTUO6yFcWf8QRKg\], \[P\], s\[STARTED\], a\[id=50vjfxaPSuqA…

---

## [Old metrics of APM dont show when upgrading 7.17 to 8.9](https://discuss.elastic.co/t/old-metrics-of-apm-dont-show-when-upgrading-7-17-to-8-9/343927)

<div class="topic-metadata">

**Author:** [@ElasticLiver](https://discuss.elastic.co/u/ElasticLiver)\
**Replies:** 8\
**Last updated:** [October 26, 2023, 3:57am UTC](https://discuss.elastic.co/t/old-metrics-of-apm-dont-show-when-upgrading-7-17-to-8-9/343927 "2023-10-26T03:57:21Z")

</div>

Hi, I was tasked to upgrade elastic, kibana, logstash, and APM Server from 7.17 to 8.9, when I did the upgrade, old metrics from APM do not show in kibana APM section, only the new ones, so we restore the snapshot of th…

---

## [Fscrawler, error 415 when using REST API for upload PDF file](https://discuss.elastic.co/t/fscrawler-error-415-when-using-rest-api-for-upload-pdf-file/345760)

<div class="topic-metadata">

**Author:** [@Erik\_Bors](https://discuss.elastic.co/u/Erik_Bors)\
**Replies:** 4\
**Last updated:** [October 25, 2023, 9:25pm UTC](https://discuss.elastic.co/t/fscrawler-error-415-when-using-rest-api-for-upload-pdf-file/345760 "2023-10-25T21:25:59Z")

</div>

Trying to use the REST API service of the fscrawler. When using the POST MAN with PDF file, the app is answering with the 415 code - unsupported media type Content-Type header is correct with application/pdf. Using POS…

---

## [Deprecation info missing in the docs?](https://discuss.elastic.co/t/deprecation-info-missing-in-the-docs/345744)

<div class="topic-metadata">

**Author:** [@bunste](https://discuss.elastic.co/u/bunste)\
**Replies:** 2\
**Last updated:** [October 25, 2023, 8:59pm UTC](https://discuss.elastic.co/t/deprecation-info-missing-in-the-docs/345744 "2023-10-25T20:59:16Z")

</div>

I saw the following deprecation warning today: \[ignore\_throttled\] parameter is deprecated because frozen indices have been deprecated. Consider cold or frozen tiers in place of frozen indices. So far so good, finding a…

---

## [Superuser access in each Space](https://discuss.elastic.co/t/superuser-access-in-each-space/345405)

<div class="topic-metadata">

**Author:** [@Ryan\_Downey](https://discuss.elastic.co/u/Ryan_Downey)\
**Replies:** 8\
**Last updated:** [October 25, 2023, 7:19pm UTC](https://discuss.elastic.co/t/superuser-access-in-each-space/345405 "2023-10-25T19:19:47Z")

</div>

How do you implement superuser access to every Space for any users that need that level of access? For example, in a deployment utilizing SAML for access a user has superuser privileges in one Space to manage everything…

---

## [Fleet integrations page failing to load](https://discuss.elastic.co/t/fleet-integrations-page-failing-to-load/345473)

<div class="topic-metadata">

**Author:** [@tdanno](https://discuss.elastic.co/u/tdanno)\
**Replies:** 4\
**Last updated:** [October 25, 2023, 7:19pm UTC](https://discuss.elastic.co/t/fleet-integrations-page-failing-to-load/345473 "2023-10-25T19:19:32Z")

</div>

On three separate clusters in three different parts of the world everything is functioning fine except the ability to fully load the integrations page- it seems like whatever it needs to do to reach out to the central re…

---

## [Discover does not show any data for indices with \_source disabled](https://discuss.elastic.co/t/discover-does-not-show-any-data-for-indices-with-source-disabled/345652)

<div class="topic-metadata">

**Author:** [@leandrojmp](https://discuss.elastic.co/u/leandrojmp)\
**Replies:** 11\
**Last updated:** [October 25, 2023, 5:32pm UTC](https://discuss.elastic.co/t/discover-does-not-show-any-data-for-indices-with-source-disabled/345652 "2023-10-25T17:32:38Z")

</div>

Hello, I disabled the \_source field on a couple of indices yesterday and today I noticed that I can not see anything from those indices on Discover. I can filter on values and fields, but everything is empty on Kibana …

---

## [Parse single array json (Elastic Agent)](https://discuss.elastic.co/t/parse-single-array-json-elastic-agent/345558)

<div class="topic-metadata">

**Author:** [@dmgeurts](https://discuss.elastic.co/u/dmgeurts)\
**Replies:** 5\
**Last updated:** [October 25, 2023, 5:24pm UTC](https://discuss.elastic.co/t/parse-single-array-json-elastic-agent/345558 "2023-10-25T17:24:33Z")

</div>

I'm trying to parse parsedmarc json files. These log files contain a single array with multiple records. I've taken the json and am testing with a single record, and am struggling to find the right combination of filebea…

[Previous page](https://discuss.elastic.co/latest.md?page=500)

[Next page](https://discuss.elastic.co/latest.md?page=502)
