# Latest

**URL:** https://discuss.elastic.co/latest.md?page=505

[Latest](https://discuss.elastic.co/latest.md) · [Categories](https://discuss.elastic.co/categories.md) · [Tags](https://discuss.elastic.co/tags.md)

**Page:** 506

---

## [Correct configuration Elastic Search 8.10.4](https://discuss.elastic.co/t/correct-configuration-elastic-search-8-10-4/345238)

<div class="topic-metadata">

**Author:** [@Fernando\_Oliveira](https://discuss.elastic.co/u/Fernando_Oliveira)\
**Replies:** 9\
**Last updated:** [October 23, 2023, 1:50pm UTC](https://discuss.elastic.co/t/correct-configuration-elastic-search-8-10-4/345238 "2023-10-23T13:50:11Z")

</div>

I'm starting a new Elastic installation search and Kibana, version 8.10.4.. My goal is to make a better distribution following some recommendations I saw, for example 3 master, 2 data hot, 2 warm in different zones.. S…

---

## [Kibana Lens - Line Type - How to show the percentage of each terms](https://discuss.elastic.co/t/kibana-lens-line-type-how-to-show-the-percentage-of-each-terms/345321)

<div class="topic-metadata">

**Author:** [@Claudio\_Ract\_Costa](https://discuss.elastic.co/u/Claudio_Ract_Costa)\
**Replies:** 1\
**Last updated:** [October 23, 2023, 1:46pm UTC](https://discuss.elastic.co/t/kibana-lens-line-type-how-to-show-the-percentage-of-each-terms/345321 "2023-10-23T13:46:27Z")

</div>

Hi all, I would like to create a visualization of Line type using Lens that display the percentage of each terms. The challange here is: in some documents, I have a field of type array with different values So, as exa…

---

## [Foilebeat IIS Module Config](https://discuss.elastic.co/t/foilebeat-iis-module-config/345325)

<div class="topic-metadata">

**Author:** [@dfir](https://discuss.elastic.co/u/dfir)\
**Replies:** 4\
**Last updated:** [October 23, 2023, 12:08pm UTC](https://discuss.elastic.co/t/foilebeat-iis-module-config/345325 "2023-10-23T12:08:57Z")

</div>

I am working on version 8.10.2 of Elastic, Kibana and Filebeat. I am trying to get IIS.YML to work but I am running into a some errors. I am running this command: .\\filebeat.exe -e -c D:\\Filebeat\\modules.d\\iis.yml and…

---

## [Date Histogram bucket boundaries](https://discuss.elastic.co/t/date-histogram-bucket-boundaries/345301)

<div class="topic-metadata">

**Author:** [@arunachala](https://discuss.elastic.co/u/arunachala)\
**Replies:** 1\
**Last updated:** [October 23, 2023, 11:18am UTC](https://discuss.elastic.co/t/date-histogram-bucket-boundaries/345301 "2023-10-23T11:18:35Z")

</div>

Hi, I understand that the bucket boundaries for date\_histogram are calculated with respect to epoch time. Is there any option to change this to a specific time? I am trying to achieve similar results as what some of da…

---

## [Aggregate two records in one index](https://discuss.elastic.co/t/aggregate-two-records-in-one-index/345503)

<div class="topic-metadata">

**Author:** [@reza\_sabz](https://discuss.elastic.co/u/reza_sabz)\
**Replies:** 6\
**Last updated:** [October 23, 2023, 9:52am UTC](https://discuss.elastic.co/t/aggregate-two-records-in-one-index/345503 "2023-10-23T09:52:42Z")

</div>

Hello guys, I have an index with a lot of records, like these: "\_source": { "terminal\_number": " 123456", "date": "2023-10-18 12:02:31.676", "iin": " 111111111 ", "service\_type": "o.t.s.transactions.trm.TerminalServ…

---

## [Issues with kibana visualization data table not showing matching results](https://discuss.elastic.co/t/issues-with-kibana-visualization-data-table-not-showing-matching-results/345553)

<div class="topic-metadata">

**Author:** [@Srikanth\_V](https://discuss.elastic.co/u/Srikanth_V)\
**Replies:** 0\
**Last updated:** [October 23, 2023, 9:31am UTC](https://discuss.elastic.co/t/issues-with-kibana-visualization-data-table-not-showing-matching-results/345553 "2023-10-23T09:31:19Z")

</div>

Dear, I am using kibana data table visualization to show various fields in my dashboard. There is an issue that I am facing with regards to missing rows. I have 2 indexes, for french and dutch. There seems to be a mism…

---

## [Help constructing yaml file](https://discuss.elastic.co/t/help-constructing-yaml-file/345550)

<div class="topic-metadata">

**Author:** [@Emorta](https://discuss.elastic.co/u/Emorta)\
**Replies:** 1\
**Last updated:** [October 23, 2023, 9:25am UTC](https://discuss.elastic.co/t/help-constructing-yaml-file/345550 "2023-10-23T09:25:05Z")

</div>

Hello, I'm trying to monitor Windows events (security only) and DHCP event logs (files). The first part works well; logs are collected and shipped, and it has been running for 3 months. I now want to add file logging for…

---

## [Elasticsearch "ignore\_above" issues. Unable to use the updated mapping setting after reindex](https://discuss.elastic.co/t/elasticsearch-ignore-above-issues-unable-to-use-the-updated-mapping-setting-after-reindex/345498)

<div class="topic-metadata">

**Author:** [@Shi\_Eng\_Ng](https://discuss.elastic.co/u/Shi_Eng_Ng)\
**Replies:** 1\
**Last updated:** [October 23, 2023, 8:35am UTC](https://discuss.elastic.co/t/elasticsearch-ignore-above-issues-unable-to-use-the-updated-mapping-setting-after-reindex/345498 "2023-10-23T08:35:47Z")

</div>

Index Mapping(In Kibana) GET /new\_index/\_mapping I already reset the "ignore\_above" to the larger size, but it seems not working for my index when I query for searching. I heard from other solutions that I need to rei…

---

## [Can anyone please explain me the time difference between the json view and the table view?](https://discuss.elastic.co/t/can-anyone-please-explain-me-the-time-difference-between-the-json-view-and-the-table-view/344906)

<div class="topic-metadata">

**Author:** [@surya\_dadi\_dhamarake](https://discuss.elastic.co/u/surya_dadi_dhamarake)\
**Replies:** 6\
**Last updated:** [October 23, 2023, 6:46am UTC](https://discuss.elastic.co/t/can-anyone-please-explain-me-the-time-difference-between-the-json-view-and-the-table-view/344906 "2023-10-23T06:46:17Z")

</div>

Hi Team, I am using an elastic cloud account. My application is sending the data with timestamp in Sydney timezone. I have configured the same in kibana as well. I am almost seeing 11 hours difference between time stamp…

---

## [Create a graph where the connections' width is based on another column](https://discuss.elastic.co/t/create-a-graph-where-the-connections-width-is-based-on-another-column/345543)

<div class="topic-metadata">

**Author:** [@hjazz6](https://discuss.elastic.co/u/hjazz6)\
**Replies:** 0\
**Last updated:** [October 23, 2023, 6:20am UTC](https://discuss.elastic.co/t/create-a-graph-where-the-connections-width-is-based-on-another-column/345543 "2023-10-23T06:20:37Z")

</div>

Hi, I have an index with 3 fields - source.ip, destination.ip, and num\_bytes. Is there a way to create a graph (from the graph analytics feature) where the vertices are the source.ip and destination.ip, and the width of…

---

## [Not condition met after configure watcher alert to email](https://discuss.elastic.co/t/not-condition-met-after-configure-watcher-alert-to-email/345538)

<div class="topic-metadata">

**Author:** [@vanhaiit90](https://discuss.elastic.co/u/vanhaiit90)\
**Replies:** 0\
**Last updated:** [October 23, 2023, 4:10am UTC](https://discuss.elastic.co/t/not-condition-met-after-configure-watcher-alert-to-email/345538 "2023-10-23T04:10:18Z")

</div>

Hi everyone! I have text configured alert send watcher to email. However it is seem wrong text and not condition met send to email: code: { "trigger": { "schedule": { "interval": "1m" } }, "input": { "search":…

---

## [How to suppress ElasticSearch output stats](https://discuss.elastic.co/t/how-to-suppress-elasticsearch-output-stats/345533)

<div class="topic-metadata">

**Author:** [@hs121](https://discuss.elastic.co/u/hs121)\
**Replies:** 0\
**Last updated:** [October 23, 2023, 2:34am UTC](https://discuss.elastic.co/t/how-to-suppress-elasticsearch-output-stats/345533 "2023-10-23T02:34:26Z")

</div>

Hi, Upon creating connection to Elasticsearch or indexing using python API, the output console shows elastic\_transport.transport stats. Is there a way I can suppress this information? Thanks e.g nodes = \[ https://el…

---

## [APM Integration Issue](https://discuss.elastic.co/t/apm-integration-issue/345468)

<div class="topic-metadata">

**Author:** [@fenixon](https://discuss.elastic.co/u/fenixon)\
**Replies:** 1\
**Last updated:** [October 23, 2023, 1:55am UTC](https://discuss.elastic.co/t/apm-integration-issue/345468 "2023-10-23T01:55:10Z")

</div>

{"log.level":"error","@timestamp":"2023-10-20T13:15:35.973Z","log.logger":"agentcfg","log.origin":{"file.name":"agentcfg/elasticsearch.go","file.line":134},"message":"refresh cache error: context deadline exceeded","serv…

---

## [ElasticSearch 7.10 Spark hadoop support for sign requests ( AWS Signature V4)](https://discuss.elastic.co/t/elasticsearch-7-10-spark-hadoop-support-for-sign-requests-aws-signature-v4/345531)

<div class="topic-metadata">

**Author:** [@deepblue1618](https://discuss.elastic.co/u/deepblue1618)\
**Replies:** 0\
**Last updated:** [October 23, 2023, 1:48am UTC](https://discuss.elastic.co/t/elasticsearch-7-10-spark-hadoop-support-for-sign-requests-aws-signature-v4/345531 "2023-10-23T01:48:48Z")

</div>

We are using Elasticsearch v7.10 and use spark to write bulk documents to the index. I was under the impression that we can sign request by passing headers like beow: df.write.mode("append").format('org.elasticsearch.s…

---

## [Recuperer puis indexer des donnees via une api via logstash](https://discuss.elastic.co/t/recuperer-puis-indexer-des-donnees-via-une-api-via-logstash/345527)

<div class="topic-metadata">

**Author:** [@Phildefer](https://discuss.elastic.co/u/Phildefer)\
**Replies:** 0\
**Last updated:** [October 22, 2023, 5:02pm UTC](https://discuss.elastic.co/t/recuperer-puis-indexer-des-donnees-via-une-api-via-logstash/345527 "2023-10-22T17:02:24Z")

</div>

Bonjour, (Je reposte au bon endroit, ce topic etait dans la section russe ...) Je cherche à automatiser la récupération régulière (toutes les semaines) de données via une API. Les requêtes se présentent sous cette fo…

---

## [Custom sorting](https://discuss.elastic.co/t/custom-sorting/345525)

<div class="topic-metadata">

**Author:** [@maxim-pushchinskiy](https://discuss.elastic.co/u/maxim-pushchinskiy)\
**Replies:** 1\
**Last updated:** [October 22, 2023, 4:52pm UTC](https://discuss.elastic.co/t/custom-sorting/345525 "2023-10-22T16:52:26Z")

</div>

I have documents like: POST /your-index-name/\_doc/1 { "bbCategories": \["Shirts"\], "otherField": "value1" } POST /your-index-name/\_doc/2 { "bbCategories": \["Trousers"\], "otherField": "value2" } POST /your-index…

---

## [Installation Logstash - Docker](https://discuss.elastic.co/t/installation-logstash-docker/345526)

<div class="topic-metadata">

**Author:** [@Phildefer](https://discuss.elastic.co/u/Phildefer)\
**Replies:** 0\
**Last updated:** [October 22, 2023, 4:14pm UTC](https://discuss.elastic.co/t/installation-logstash-docker/345526 "2023-10-22T16:14:18Z")

</div>

Bonjour, J'essaye d'installer Logstash via une image docker et contrairement aux images d'Elasticsearch et de Kibana celle de Logstash pose problème. en effet, après installation, il est impossible d'écrire dans les rép…

---

## [Elasticsearch stopped working , it is not extracting contents from documents](https://discuss.elastic.co/t/elasticsearch-stopped-working-it-is-not-extracting-contents-from-documents/345072)

<div class="topic-metadata">

**Author:** [@priyankaa](https://discuss.elastic.co/u/priyankaa)\
**Replies:** 16\
**Last updated:** [October 21, 2023, 10:24pm UTC](https://discuss.elastic.co/t/elasticsearch-stopped-working-it-is-not-extracting-contents-from-documents/345072 "2023-10-21T22:24:26Z")

</div>

due to disk storage got full , Elasticsearch was stopped working , so we have now increased it , still after increasing disk storage Elasticsearch is not working , I performed reindexing as per my senior suggestion , but…

---

## [Setting the data\_stream.namespace](https://discuss.elastic.co/t/setting-the-data-stream-namespace/345506)

<div class="topic-metadata">

**Author:** [@Kevin\_Patterson](https://discuss.elastic.co/u/Kevin_Patterson)\
**Replies:** 5\
**Last updated:** [October 21, 2023, 10:18pm UTC](https://discuss.elastic.co/t/setting-the-data-stream-namespace/345506 "2023-10-21T22:18:58Z")

</div>

I've seen numerous posts for folks requesting how to set the data\_stream.namespace in the apm-server.yml, but I dont think any have a response. They've all been closed after 20 days, so attempting to ask that same questi…

---

## [Elastic Agent upgrade option is grayed out on Fleet Server](https://discuss.elastic.co/t/elastic-agent-upgrade-option-is-grayed-out-on-fleet-server/344753)

<div class="topic-metadata">

**Author:** [@leandrojmp](https://discuss.elastic.co/u/leandrojmp)\
**Replies:** 5\
**Last updated:** [October 21, 2023, 7:25pm UTC](https://discuss.elastic.co/t/elastic-agent-upgrade-option-is-grayed-out-on-fleet-server/344753 "2023-10-21T19:25:49Z")

</div>

Hello, In the product compatibility support matrix page it says that Elasticsearch 8.10.X is compatible with Elastic Agent 7.17.x - 8.10.X, so I would expect the there is no incompatibility issues between patch versions…

---

## [Index with multiple replicas turned red when node with primary went down](https://discuss.elastic.co/t/index-with-multiple-replicas-turned-red-when-node-with-primary-went-down/345439)

<div class="topic-metadata">

**Author:** [@jaykb77](https://discuss.elastic.co/u/jaykb77)\
**Replies:** 10\
**Last updated:** [October 21, 2023, 6:46pm UTC](https://discuss.elastic.co/t/index-with-multiple-replicas-turned-red-when-node-with-primary-went-down/345439 "2023-10-21T18:46:33Z")

</div>

Hi all, I saw an unusual issue in our cluster where one of the indices configured with 1p:2r turned red when the node with primary shard went down. By the time I was checking the node was already back in cluster and the…

---

## [How to excute size function in script Plainess when I want access my field with type nested?](https://discuss.elastic.co/t/how-to-excute-size-function-in-script-plainess-when-i-want-access-my-field-with-type-nested/345429)

<div class="topic-metadata">

**Author:** [@duyhunter1001](https://discuss.elastic.co/u/duyhunter1001)\
**Replies:** 1\
**Last updated:** [October 21, 2023, 3:58pm UTC](https://discuss.elastic.co/t/how-to-excute-size-function-in-script-plainess-when-i-want-access-my-field-with-type-nested/345429 "2023-10-21T15:58:18Z")

</div>

Example, I have index following: PUT candidates { "mappings": { "language": { type: "nested" } } } POST candidates/\_doc { "firstname": "Mike", "age": 31, "city": "New York", "language":\[ { …

---

## [Does Spring Boot 3.1 require Elasticsearch 8?](https://discuss.elastic.co/t/does-spring-boot-3-1-require-elasticsearch-8/345335)

<div class="topic-metadata">

**Author:** [@Michal\_Stefaniuk](https://discuss.elastic.co/u/Michal_Stefaniuk)\
**Replies:** 7\
**Last updated:** [October 21, 2023, 3:31pm UTC](https://discuss.elastic.co/t/does-spring-boot-3-1-require-elasticsearch-8/345335 "2023-10-21T15:31:29Z")

</div>

Hey, quick question. We're working on an application that is currently using java 11, spring boot 2.7 and elasticsearch 7.17.10. We are migrating to java 17 and spring boot 3.1. Recently we stumbled upon a document tha…

---

## [Please delete my account](https://discuss.elastic.co/t/please-delete-my-account/345501)

<div class="topic-metadata">

**Author:** [@anon45970649](https://discuss.elastic.co/u/anon45970649)\
**Replies:** 2\
**Last updated:** [October 21, 2023, 2:13pm UTC](https://discuss.elastic.co/t/please-delete-my-account/345501 "2023-10-21T14:13:57Z")

</div>

Please delete my account.

---

## [Unable to segregate messages from two Input files](https://discuss.elastic.co/t/unable-to-segregate-messages-from-two-input-files/345492)

<div class="topic-metadata">

**Author:** [@Blason](https://discuss.elastic.co/u/Blason)\
**Replies:** 3\
**Last updated:** [October 21, 2023, 1:26pm UTC](https://discuss.elastic.co/t/unable-to-segregate-messages-from-two-input-files/345492 "2023-10-21T13:26:44Z")

</div>

Hi Team, I posted this message on stack but not getting any replies. Can someone please help? I need help in seggregrating messages from my two different conf files. I am bit confused about ingestion Here is my first f…

---

## [How do I stringify entire event object in logstash and put it in one field](https://discuss.elastic.co/t/how-do-i-stringify-entire-event-object-in-logstash-and-put-it-in-one-field/345496)

<div class="topic-metadata">

**Author:** [@ghanshyam\_baviskar](https://discuss.elastic.co/u/ghanshyam_baviskar)\
**Replies:** 4\
**Last updated:** [October 21, 2023, 1:24pm UTC](https://discuss.elastic.co/t/how-do-i-stringify-entire-event-object-in-logstash-and-put-it-in-one-field/345496 "2023-10-21T13:24:30Z")

</div>

I am trying to implement a dead letter queue pipeline, I want to take entire event , stringify it and put it into a field "strigified\_event". so that it can be monitored for elasticsearch mapper errors input { dead\_le…

---

## [Logstash failing to starting due to the error related to the "i18n" gem](https://discuss.elastic.co/t/logstash-failing-to-starting-due-to-the-error-related-to-the-i18n-gem/345341)

<div class="topic-metadata">

**Author:** [@akhilatham](https://discuss.elastic.co/u/akhilatham)\
**Replies:** 3\
**Last updated:** [October 21, 2023, 12:41am UTC](https://discuss.elastic.co/t/logstash-failing-to-starting-due-to-the-error-related-to-the-i18n-gem/345341 "2023-10-21T00:41:35Z")

</div>

I am getting the below error: \[2023-10-18T17:37:02,573\]\[FATAL\]\[logstash.runner\] An unexpected error occurred! {:error=\>#\<ArgumentError: wrong number of arguments (given 2, expected 0..1)\>, :backtrace=\>\["/usr/share/logst…

---

## [Splitting query returns](https://discuss.elastic.co/t/splitting-query-returns/345416)

<div class="topic-metadata">

**Author:** [@ken.s](https://discuss.elastic.co/u/ken.s)\
**Replies:** 0\
**Last updated:** [October 19, 2023, 7:09pm UTC](https://discuss.elastic.co/t/splitting-query-returns/345416 "2023-10-19T19:09:36Z")

</div>

Hi there. I'm working on returning multple query results based on an inner array. For instance, I have an object that looks like this: { "customer\_order\_number": "T391704031545", "aggregation\_date\_time": "2023-…

---

## [Web crawler and semantic search](https://discuss.elastic.co/t/web-crawler-and-semantic-search/345485)

<div class="topic-metadata">

**Author:** [@Michal\_Stoklasa](https://discuss.elastic.co/u/Michal_Stoklasa)\
**Replies:** 0\
**Last updated:** [October 20, 2023, 8:13pm UTC](https://discuss.elastic.co/t/web-crawler-and-semantic-search/345485 "2023-10-20T20:13:18Z")

</div>

Hi, im looking for web crawler connected to similarity search for my chatbot product. I have to be able to crawl website and then search similar parts based on query. Something like classic vector search with embedding…

---

## [Filebeat Grok pattern for access log](https://discuss.elastic.co/t/filebeat-grok-pattern-for-access-log/345455)

<div class="topic-metadata">

**Author:** [@tucker](https://discuss.elastic.co/u/tucker)\
**Replies:** 5\
**Last updated:** [October 20, 2023, 6:52pm UTC](https://discuss.elastic.co/t/filebeat-grok-pattern-for-access-log/345455 "2023-10-20T18:52:15Z")

</div>

Hi, I have an access log for which I am trying to write a Grok pattern but in the filebeat log, I always see "Provided Grok expressions do not match field value:". The log entries look like: \[20/Oct/2023:09:52:33 +000…

[Previous page](https://discuss.elastic.co/latest.md?page=504)

[Next page](https://discuss.elastic.co/latest.md?page=506)
