# Latest

**URL:** https://discuss.elastic.co/latest.md?page=519

[Latest](https://discuss.elastic.co/latest.md) · [Categories](https://discuss.elastic.co/categories.md) · [Tags](https://discuss.elastic.co/tags.md)

**Page:** 520

---

## [Reindex in elasticsearch 7.17 as pre-upgrade to 8.x](https://discuss.elastic.co/t/reindex-in-elasticsearch-7-17-as-pre-upgrade-to-8-x/344575)

<div class="topic-metadata">

**Author:** [@Indu\_Nallithodi](https://discuss.elastic.co/u/Indu_Nallithodi)\
**Replies:** 0\
**Last updated:** [October 7, 2023, 11:48pm UTC](https://discuss.elastic.co/t/reindex-in-elasticsearch-7-17-as-pre-upgrade-to-8-x/344575 "2023-10-07T23:48:24Z")

</div>

Elasticsearch team: in need of a guidancee/help Now am in a upgrade from 6.8 to 8.x(latest) Progress: Have 6.8 server with 6.8 indices(created in 5.6 and upgraded to 6.8 few years back) with multi-type Reindexed to s…

---

## [Deleting Array Element USING NEST](https://discuss.elastic.co/t/deleting-array-element-using-nest/344573)

<div class="topic-metadata">

**Author:** [@xef](https://discuss.elastic.co/u/xef)\
**Replies:** 0\
**Last updated:** [October 7, 2023, 7:45pm UTC](https://discuss.elastic.co/t/deleting-array-element-using-nest/344573 "2023-10-07T19:45:40Z")

</div>

Can anyone assist us in how to delete an element of an array in Elasticsearch using NEST syntax. Thanks

---

## [How Can I Open Document Explorer Graph?](https://discuss.elastic.co/t/how-can-i-open-document-explorer-graph/344565)

<div class="topic-metadata">

**Author:** [@newx](https://discuss.elastic.co/u/newx)\
**Replies:** 2\
**Last updated:** [October 7, 2023, 2:02pm UTC](https://discuss.elastic.co/t/how-can-i-open-document-explorer-graph/344565 "2023-10-07T14:02:42Z")

</div>

Hi, I created one node elastic cluster with one rollover index. This stage works very well. BUT, there is no default green counter graph with time selector(you can see from their original documents: https://www.elastic…

---

## [Date Maths in Kibana Query Language](https://discuss.elastic.co/t/date-maths-in-kibana-query-language/344556)

<div class="topic-metadata">

**Author:** [@Marcos\_Ivan\_Robles\_H](https://discuss.elastic.co/u/Marcos_Ivan_Robles_H)\
**Replies:** 2\
**Last updated:** [October 7, 2023, 2:25am UTC](https://discuss.elastic.co/t/date-maths-in-kibana-query-language/344556 "2023-10-07T02:25:40Z")

</div>

I am trying to use date math in my query without success. When I paste a KQL query on the web explorer's address bar I got a successful result with an example like this: base url + time:(from:'2023-10-06T20:44:13.558Z…

---

## [Using Date plugin to parse apache2 error log datetime](https://discuss.elastic.co/t/using-date-plugin-to-parse-apache2-error-log-datetime/344547)

<div class="topic-metadata">

**Author:** [@lobart78](https://discuss.elastic.co/u/lobart78)\
**Replies:** 2\
**Last updated:** [October 6, 2023, 11:00pm UTC](https://discuss.elastic.co/t/using-date-plugin-to-parse-apache2-error-log-datetime/344547 "2023-10-06T23:00:07Z")

</div>

Hi all ! I am trying to use Logstash to parse apache2 error logs. These logs contain a dattime in a format e.g. Fri Oct 03 09:07:41.570 2023. I have already successfully transfered this string into a field "eventfire" …

---

## [How to give specific disk threshold for specific node in a Elastic cluster](https://discuss.elastic.co/t/how-to-give-specific-disk-threshold-for-specific-node-in-a-elastic-cluster/344247)

<div class="topic-metadata">

**Author:** [@hiruni.insyncit.net](https://discuss.elastic.co/u/hiruni.insyncit.net)\
**Replies:** 5\
**Last updated:** [October 6, 2023, 7:00pm UTC](https://discuss.elastic.co/t/how-to-give-specific-disk-threshold-for-specific-node-in-a-elastic-cluster/344247 "2023-10-06T19:00:03Z")

</div>

Hi, I have a multi-node cluster. I want to allocate only 100 shards to a specific node in the elastic cluster. (But other nodes should be allocated more than 100 shards.) I have one node that has less disk space than …

---

## [How to calculate EPS-Events per second in Elastic cluster](https://discuss.elastic.co/t/how-to-calculate-eps-events-per-second-in-elastic-cluster/344548)

<div class="topic-metadata">

**Author:** [@hiruni.insyncit.net](https://discuss.elastic.co/u/hiruni.insyncit.net)\
**Replies:** 0\
**Last updated:** [October 6, 2023, 6:55pm UTC](https://discuss.elastic.co/t/how-to-calculate-eps-events-per-second-in-elastic-cluster/344548 "2023-10-06T18:55:27Z")

</div>

Hi, I want to calculate the average and maximum EPS in my cluster. I'm using the ELK 8.1.2 version. Thank you..! Hiruni

---

## [Documented options to disable xpack plugins in kibana not working as expected and cause container fail to start](https://discuss.elastic.co/t/documented-options-to-disable-xpack-plugins-in-kibana-not-working-as-expected-and-cause-container-fail-to-start/344529)

<div class="topic-metadata">

**Author:** [@hakakuma](https://discuss.elastic.co/u/hakakuma)\
**Replies:** 1\
**Last updated:** [October 6, 2023, 3:55pm UTC](https://discuss.elastic.co/t/documented-options-to-disable-xpack-plugins-in-kibana-not-working-as-expected-and-cause-container-fail-to-start/344529 "2023-10-06T15:55:24Z")

</div>

We are trying kibana 8.9.0 container as a standalone server for the first time and we are trying to disable certain xpack packages using kibana.yml We wanted to disable the below plugins and we are following elastic doc…

---

## [Difference between number of fortigate firewall logs on Logstash and Elastic-agent managed by fleet](https://discuss.elastic.co/t/difference-between-number-of-fortigate-firewall-logs-on-logstash-and-elastic-agent-managed-by-fleet/344502)

<div class="topic-metadata">

**Author:** [@mrz](https://discuss.elastic.co/u/mrz)\
**Replies:** 4\
**Last updated:** [October 6, 2023, 4:00pm UTC](https://discuss.elastic.co/t/difference-between-number-of-fortigate-firewall-logs-on-logstash-and-elastic-agent-managed-by-fleet/344502 "2023-10-06T16:00:46Z")

</div>

Hi there, we have a cluster of Elasticsearch and have shipped firewall (FortiGate) logs to Logstash, everything is going well and we have a huge number of logs about 3.5M logs in 15 minutes, recently we decided to upgra…

---

## [Collect all Prometheus Metrics 8.7 integration, also looking to target live\_msgs](https://discuss.elastic.co/t/collect-all-prometheus-metrics-8-7-integration-also-looking-to-target-live-msgs/344536)

<div class="topic-metadata">

**Author:** [@Ryan\_Downey](https://discuss.elastic.co/u/Ryan_Downey)\
**Replies:** 0\
**Last updated:** [October 6, 2023, 3:25pm UTC](https://discuss.elastic.co/t/collect-all-prometheus-metrics-8-7-integration-also-looking-to-target-live-msgs/344536 "2023-10-06T15:25:26Z")

</div>

Team, I'm having trouble understanding how to collect all of the Prometheus metrics available. We currently have Elastic Agent (EA) working and connected to the Prometheus server but its not pulling any data for one of…

---

## [Time\_zone in Lucence query](https://discuss.elastic.co/t/time-zone-in-lucence-query/344534)

<div class="topic-metadata">

**Author:** [@Michael7](https://discuss.elastic.co/u/Michael7)\
**Replies:** 0\
**Last updated:** [October 6, 2023, 2:17pm UTC](https://discuss.elastic.co/t/time-zone-in-lucence-query/344534 "2023-10-06T14:17:34Z")

</div>

Hi, Im trying to realize how to specify time\_zone in URI query for elastic. ...&q=Mobile AND delivered\_at:\["now-30d" TO "now"\] How I can add time\_zone +03:00 to delivered\_at field?

---

## [Does elastic cloud provide any specific IP address for the deployment?](https://discuss.elastic.co/t/does-elastic-cloud-provide-any-specific-ip-address-for-the-deployment/344447)

<div class="topic-metadata">

**Author:** [@surya\_dadi\_dhamarake](https://discuss.elastic.co/u/surya_dadi_dhamarake)\
**Replies:** 2\
**Last updated:** [October 6, 2023, 2:10pm UTC](https://discuss.elastic.co/t/does-elastic-cloud-provide-any-specific-ip-address-for-the-deployment/344447 "2023-10-06T14:10:33Z")

</div>

Hi Team, Does elastic cloud provide any specific IPs for the deployment that we create? If we have to whitelist the traffic into our office network we might need specific Ip address to configure. If elastic cloud is not…

---

## [Auth0 integration issues](https://discuss.elastic.co/t/auth0-integration-issues/344392)

<div class="topic-metadata">

**Author:** [@Srinivasan\_Rajagopal](https://discuss.elastic.co/u/Srinivasan_Rajagopal)\
**Replies:** 2\
**Last updated:** [October 6, 2023, 1:13pm UTC](https://discuss.elastic.co/t/auth0-integration-issues/344392 "2023-10-06T13:13:37Z")

</div>

Hey , I am working with a client who is interested in using ELK as log solution and asked to do POC on integration feasibility between Auth0 & Elastic. I have signed up for a elastic cloud trial tenant. I am following t…

---

## [Deployment upgrade from 8.2.2 to 8.10.2 disk space error](https://discuss.elastic.co/t/deployment-upgrade-from-8-2-2-to-8-10-2-disk-space-error/344399)

<div class="topic-metadata">

**Author:** [@Ryan\_Downey](https://discuss.elastic.co/u/Ryan_Downey)\
**Replies:** 2\
**Last updated:** [October 6, 2023, 1:05pm UTC](https://discuss.elastic.co/t/deployment-upgrade-from-8-2-2-to-8-10-2-disk-space-error/344399 "2023-10-06T13:05:03Z")

</div>

I'm trying to upgrade a deployment from 8.2.2 to 8.10.2 and keep hitting the error below. The basics are pretty clear, there isn't enough disk space, but is this for just one of the nodes or the entire deployment? If …

---

## [ELS 8 Java Client performance issue](https://discuss.elastic.co/t/els-8-java-client-performance-issue/344465)

<div class="topic-metadata">

**Author:** [@paulkeogh](https://discuss.elastic.co/u/paulkeogh)\
**Replies:** 0\
**Last updated:** [October 5, 2023, 9:42am UTC](https://discuss.elastic.co/t/els-8-java-client-performance-issue/344465 "2023-10-05T09:42:50Z")

</div>

We have replaced the ELS 7 REST client with the ELS 8 Java client in our application and our soak/performance tests are showing a slight performance degradation. Is this expected ? I had thought the Java client would be…

---

## [Change Log format](https://discuss.elastic.co/t/change-log-format/344476)

<div class="topic-metadata">

**Author:** [@Suleman\_Ahmed](https://discuss.elastic.co/u/Suleman_Ahmed)\
**Replies:** 1\
**Last updated:** [October 6, 2023, 12:35pm UTC](https://discuss.elastic.co/t/change-log-format/344476 "2023-10-06T12:35:17Z")

</div>

Hello! I want to change format of below mentioned log. I am new to Elk any help will be much appreciated. Thanks \[Mon Oct 02 13:14:00.967345 2023\] \[security2:error\] \[pid 186:tid 140439170467520\] \[client 192.168.76.181:…

---

## [Upload CSV File to Kibana Dashboard](https://discuss.elastic.co/t/upload-csv-file-to-kibana-dashboard/342821)

<div class="topic-metadata">

**Author:** [@Debasis\_Mallick](https://discuss.elastic.co/u/Debasis_Mallick)\
**Replies:** 25\
**Last updated:** [October 6, 2023, 10:53am UTC](https://discuss.elastic.co/t/upload-csv-file-to-kibana-dashboard/342821 "2023-10-06T10:53:19Z")

</div>

Hi Team, I need help on below two points while uploading csv file through kibana dashboard. How to upload a csv file size of more than 100MB through the kibana dashboard. How to upload multiple csv files to same indic…

---

## [Deserialising Avro data in losgstash](https://discuss.elastic.co/t/deserialising-avro-data-in-losgstash/344531)

<div class="topic-metadata">

**Author:** [@DivyaDileep](https://discuss.elastic.co/u/DivyaDileep)\
**Replies:** 0\
**Last updated:** [October 6, 2023, 10:22am UTC](https://discuss.elastic.co/t/deserialising-avro-data-in-losgstash/344531 "2023-10-06T10:22:07Z")

</div>

Continuing the discussion from Unable to Parse AVRO using Kafka Input and Avro Codec:

---

## [Functionality of alertOnNoData flag in Metric threshold rule \[8.10.2\]](https://discuss.elastic.co/t/functionality-of-alertonnodata-flag-in-metric-threshold-rule-8-10-2/344530)

<div class="topic-metadata">

**Author:** [@c\_rox](https://discuss.elastic.co/u/c_rox)\
**Replies:** 0\
**Last updated:** [October 6, 2023, 10:14am UTC](https://discuss.elastic.co/t/functionality-of-alertonnodata-flag-in-metric-threshold-rule-8-10-2/344530 "2023-10-06T10:14:41Z")

</div>

I have created elastic metric threshold rule to monitor on the disk usages of each node on elastic deployments it self and enabled alertOnData so if the query returned no data or query execution had an issue I would get …

---

## [Elasticsearch License](https://discuss.elastic.co/t/elasticsearch-license/344471)

<div class="topic-metadata">

**Author:** [@Debasis\_Mallick](https://discuss.elastic.co/u/Debasis_Mallick)\
**Replies:** 7\
**Last updated:** [October 6, 2023, 10:10am UTC](https://discuss.elastic.co/t/elasticsearch-license/344471 "2023-10-06T10:10:36Z")

</div>

Hi Team, Could you please help me to understand the licensing part of Elasticsearch. Because I had installed Elasticsearch from below link and now while using Kibana dashboard today it is showing License related error.…

---

## [How to disable transactions being sent from Java APM agent, and how to only send error events?](https://discuss.elastic.co/t/how-to-disable-transactions-being-sent-from-java-apm-agent-and-how-to-only-send-error-events/344488)

<div class="topic-metadata">

**Author:** [@Jrdunkley](https://discuss.elastic.co/u/Jrdunkley)\
**Replies:** 4\
**Last updated:** [October 6, 2023, 9:42am UTC](https://discuss.elastic.co/t/how-to-disable-transactions-being-sent-from-java-apm-agent-and-how-to-only-send-error-events/344488 "2023-10-06T09:42:53Z")

</div>

Kibana version: 8.9.1 Elasticsearch version: 8.9.1 APM Server version: 8.9.1 APM Agent language and version: Java 1.42.0 Using Springboot 2.5.6 Environment variables used. ELASTIC\_APM\_APPLICATIONS\_PACKAGES=com.exam…

---

## [Elastic and kibana logs](https://discuss.elastic.co/t/elastic-and-kibana-logs/344448)

<div class="topic-metadata">

**Author:** [@MahithaSarala](https://discuss.elastic.co/u/MahithaSarala)\
**Replies:** 3\
**Last updated:** [October 6, 2023, 9:23am UTC](https://discuss.elastic.co/t/elastic-and-kibana-logs/344448 "2023-10-06T09:23:42Z")

</div>

Hi Team, I have deployed elasticsearch (v8.5.3) and kibana through eck , How to enable debugs for kibana, can you help on this . Thanks&Regards, SM

---

## [Creating index with field type keyword in app search](https://discuss.elastic.co/t/creating-index-with-field-type-keyword-in-app-search/344178)

<div class="topic-metadata">

**Author:** [@kabilsharma](https://discuss.elastic.co/u/kabilsharma)\
**Replies:** 7\
**Last updated:** [October 6, 2023, 8:06am UTC](https://discuss.elastic.co/t/creating-index-with-field-type-keyword-in-app-search/344178 "2023-10-06T08:06:16Z")

</div>

We are using docker compose to self manage elastic enterprise search , kibana and Elasticsearch 8.4.1 . license Gold Everything works fine but as we are trying to create geocoding search engine giving us some issues. w…

---

## [It's possible to encrypt Snapshots or ElasticSearch Snapshot repository?](https://discuss.elastic.co/t/its-possible-to-encrypt-snapshots-or-elasticsearch-snapshot-repository/344524)

<div class="topic-metadata">

**Author:** [@Alberto\_Roca](https://discuss.elastic.co/u/Alberto_Roca)\
**Replies:** 0\
**Last updated:** [October 6, 2023, 7:37am UTC](https://discuss.elastic.co/t/its-possible-to-encrypt-snapshots-or-elasticsearch-snapshot-repository/344524 "2023-10-06T07:37:05Z")

</div>

Currently the structure I have is made up of a cluster with Elasticsearch nodes, which take snapshots and are saved in their corresponding repository. This data is later sent to an already encrypted Ceph bucket. Is there…

---

## [How can we create synthetic light weight monitor for private URLs?](https://discuss.elastic.co/t/how-can-we-create-synthetic-light-weight-monitor-for-private-urls/344444)

<div class="topic-metadata">

**Author:** [@surya\_dadi\_dhamarake](https://discuss.elastic.co/u/surya_dadi_dhamarake)\
**Replies:** 3\
**Last updated:** [October 6, 2023, 7:37am UTC](https://discuss.elastic.co/t/how-can-we-create-synthetic-light-weight-monitor-for-private-urls/344444 "2023-10-06T07:37:06Z")

</div>

Hi , I am trying to reach the URLs which are hosted on private VPC which are only accessible through vpn. Is there any way to connect to the URLs using synthetic lightweight monitor?

---

## [Filebeat 7.17.6 does not overwrite agent.type and agent.version if they are already present](https://discuss.elastic.co/t/filebeat-7-17-6-does-not-overwrite-agent-type-and-agent-version-if-they-are-already-present/344521)

<div class="topic-metadata">

**Author:** [@andreycha](https://discuss.elastic.co/u/andreycha)\
**Replies:** 0\
**Last updated:** [October 6, 2023, 7:18am UTC](https://discuss.elastic.co/t/filebeat-7-17-6-does-not-overwrite-agent-type-and-agent-version-if-they-are-already-present/344521 "2023-10-06T07:18:02Z")

</div>

Hi. We're writing application logs to the files using Elastic.CommonSchema.Serilog package and then ship them with Filebeat to Elastic. Here is how agent field looks like in log files: "agent": { "type": "Elastic.Co…

---

## [Throughput tweaks for Elastic Agent Integrations? Agent integration not able to keep up with volume of events within an Eventhub](https://discuss.elastic.co/t/throughput-tweaks-for-elastic-agent-integrations-agent-integration-not-able-to-keep-up-with-volume-of-events-within-an-eventhub/344515)

<div class="topic-metadata">

**Author:** [@elasticnub](https://discuss.elastic.co/u/elasticnub)\
**Replies:** 0\
**Last updated:** [October 6, 2023, 3:17am UTC](https://discuss.elastic.co/t/throughput-tweaks-for-elastic-agent-integrations-agent-integration-not-able-to-keep-up-with-volume-of-events-within-an-eventhub/344515 "2023-10-06T03:17:32Z")

</div>

We are having issues with the agent being able to support roughly ~80GB a day of M365 event data ingestion being pulled from an EventHub. The aggregation server is by no means pegged on any resources so I am trying to fi…

---

## [Kibana: Getting "missing authentication credentials for REST request" after creating plugin](https://discuss.elastic.co/t/kibana-getting-missing-authentication-credentials-for-rest-request-after-creating-plugin/344514)

<div class="topic-metadata">

**Author:** [@Akshay\_Kumar\_Gupta](https://discuss.elastic.co/u/Akshay_Kumar_Gupta)\
**Replies:** 0\
**Last updated:** [October 6, 2023, 2:55am UTC](https://discuss.elastic.co/t/kibana-getting-missing-authentication-credentials-for-rest-request-after-creating-plugin/344514 "2023-10-06T02:55:26Z")

</div>

Hi, I am trying to create a new kibana plugin. whenever I create a new plugin using node scripts/generate\_plugin new\_pl command and start the kibana using yarn start --oss then I get the below error on browser. { "statu…

---

## [Filebeat logging MSSQL ERROR log, but not able to search on Message field in Kibana](https://discuss.elastic.co/t/filebeat-logging-mssql-error-log-but-not-able-to-search-on-message-field-in-kibana/344428)

<div class="topic-metadata">

**Author:** [@dbaddorf](https://discuss.elastic.co/u/dbaddorf)\
**Replies:** 1\
**Last updated:** [October 5, 2023, 10:26pm UTC](https://discuss.elastic.co/t/filebeat-logging-mssql-error-log-but-not-able-to-search-on-message-field-in-kibana/344428 "2023-10-05T22:26:19Z")

</div>

I have Filebeat using the MSSQL module running on a Windows SQL Server exporting logs to an Elasticsearch server. I can view the Filebeat logs in Kibana. But I can't (seem) to search on the Message field. For example,…

---

## [Painless code in watcher for replacing doble quotes](https://discuss.elastic.co/t/painless-code-in-watcher-for-replacing-doble-quotes/344508)

<div class="topic-metadata">

**Author:** [@juanmgarciaf](https://discuss.elastic.co/u/juanmgarciaf)\
**Replies:** 0\
**Last updated:** [October 5, 2023, 9:23pm UTC](https://discuss.elastic.co/t/painless-code-in-watcher-for-replacing-doble-quotes/344508 "2023-10-05T21:23:07Z")

</div>

Hello, I have a problem using painless code in a watcher. I need to replace all the double quotes characters and put a single quote instead, but I don't know how I can do this. After read the Elastic documentation I pu…

[Previous page](https://discuss.elastic.co/latest.md?page=518)

[Next page](https://discuss.elastic.co/latest.md?page=520)
