# Latest

**URL:** https://discuss.elastic.co/latest.md?page=536

[Latest](https://discuss.elastic.co/latest.md) · [Categories](https://discuss.elastic.co/categories.md) · [Tags](https://discuss.elastic.co/tags.md)

**Page:** 537

---

## [Calculate percentage based on status of max per group in Elasticsearch](https://discuss.elastic.co/t/calculate-percentage-based-on-status-of-max-per-group-in-elasticsearch/343171)

<div class="topic-metadata">

**Author:** [@carollyl](https://discuss.elastic.co/u/carollyl)\
**Replies:** 5\
**Last updated:** [September 19, 2023, 4:27pm UTC](https://discuss.elastic.co/t/calculate-percentage-based-on-status-of-max-per-group-in-elasticsearch/343171 "2023-09-19T16:27:48Z")

</div>

Given the dataset below, I'd like to calculate percentage of status over unique count of workflow. id,workflow,status 1,A,FAILURE 2,A,ABORTED 3,A,SUCCESS 4,A,SUCCESS 1,B,FAILURE 2,B,SUCCESS 3,B,FAILURE 1,C,FAILURE 2,C,F…

---

## [Cardinality problem](https://discuss.elastic.co/t/cardinality-problem/343387)

<div class="topic-metadata">

**Author:** [@YvorL](https://discuss.elastic.co/u/YvorL)\
**Replies:** 0\
**Last updated:** [September 19, 2023, 4:27pm UTC](https://discuss.elastic.co/t/cardinality-problem/343387 "2023-09-19T16:27:18Z")

</div>

Hi, I'm not sure if this can be done, but it's worth asking :slight\_smile: I would like to see a specific metric, but it'd need a lot of conditions and cardinality. Let's say I have an index where I have documents fro…

---

## [ECK sample config to run elastiic agent for synthetic monitoring](https://discuss.elastic.co/t/eck-sample-config-to-run-elastiic-agent-for-synthetic-monitoring/343386)

<div class="topic-metadata">

**Author:** [@senyam08](https://discuss.elastic.co/u/senyam08)\
**Replies:** 0\
**Last updated:** [September 19, 2023, 4:06pm UTC](https://discuss.elastic.co/t/eck-sample-config-to-run-elastiic-agent-for-synthetic-monitoring/343386 "2023-09-19T16:06:26Z")

</div>

Looking to setup synthetic monitoring private location with elastic agent deployment using ECK operator. is there ECK operator recipe or sample config to run standalone elastic agent with elastic-agent-complete Docker im…

---

## [Enrolling agent on Graviton ARM processor](https://discuss.elastic.co/t/enrolling-agent-on-graviton-arm-processor/342351)

<div class="topic-metadata">

**Author:** [@Jasonespo](https://discuss.elastic.co/u/Jasonespo)\
**Replies:** 4\
**Last updated:** [September 19, 2023, 3:26pm UTC](https://discuss.elastic.co/t/enrolling-agent-on-graviton-arm-processor/342351 "2023-09-19T15:26:59Z")

</div>

Hi, I was wondering if it is possible to run the agent on aarm64 architecture? We're potentially aiming to migrate all of our hosts from x86\_64 to aarm64. However when I try to run the agent install command on a host r…

---

## [Transaction\_sample\_rate post 8 release versions](https://discuss.elastic.co/t/transaction-sample-rate-post-8-release-versions/343290)

<div class="topic-metadata">

**Author:** [@senyam08](https://discuss.elastic.co/u/senyam08)\
**Replies:** 4\
**Last updated:** [September 19, 2023, 3:10pm UTC](https://discuss.elastic.co/t/transaction-sample-rate-post-8-release-versions/343290 "2023-09-19T15:10:40Z")

</div>

We haev java agent 1.42 and Elasticsearch/APM servers are in 8.10 version. I haev tried with sampling rate of .2 and .5. Both values and 1 are getting response time/throughput for all samples. But document has change in…

---

## [FileBeat filestream ndjson breaking array with nested objects](https://discuss.elastic.co/t/filebeat-filestream-ndjson-breaking-array-with-nested-objects/343383)

<div class="topic-metadata">

**Author:** [@dusatvoj](https://discuss.elastic.co/u/dusatvoj)\
**Replies:** 0\
**Last updated:** [September 19, 2023, 3:07pm UTC](https://discuss.elastic.co/t/filebeat-filestream-ndjson-breaking-array-with-nested-objects/343383 "2023-09-19T15:07:30Z")

</div>

Hello, I have ndjson which is scraped by filebeat, transferred via redis and logstash (which has no filter rule, except date) into elasticsearch. The ndjson structure is smth like: { "array\_of\_objects": \[ { "a…

---

## [What's the equivalent for NEST's MultiTermQueryRewrite class and/or RewriteMultiTerm enum in Elastic.Clients.Elasticsearch (8.x)](https://discuss.elastic.co/t/whats-the-equivalent-for-nests-multitermqueryrewrite-class-and-or-rewritemultiterm-enum-in-elastic-clients-elasticsearch-8-x/343379)

<div class="topic-metadata">

**Author:** [@yansklyarenko](https://discuss.elastic.co/u/yansklyarenko)\
**Replies:** 0\
**Last updated:** [September 19, 2023, 2:45pm UTC](https://discuss.elastic.co/t/whats-the-equivalent-for-nests-multitermqueryrewrite-class-and-or-rewritemultiterm-enum-in-elastic-clients-elasticsearch-8-x/343379 "2023-09-19T14:45:41Z")

</div>

Basically, the title says it all. During migration from the NEST (7.x) client to Elastic.Clients.Elasticsearch (8.x) client I can't find the equivalent of MultiTermQueryRewrite class and/or RewriteMultiTerm enum. Could …

---

## [Eck-licence from external secret](https://discuss.elastic.co/t/eck-licence-from-external-secret/343348)

<div class="topic-metadata">

**Author:** [@Francisco\_Javier\_Ort](https://discuss.elastic.co/u/Francisco_Javier_Ort)\
**Replies:** 4\
**Last updated:** [September 19, 2023, 2:10pm UTC](https://discuss.elastic.co/t/eck-licence-from-external-secret/343348 "2023-09-19T14:10:52Z")

</div>

Hi All, according to this Manage licenses in ECK | Elastic Cloud on Kubernetes \[2.9\] | Elastic we need to create a secret eck-license to add our licence. Will it work if we create the same but using an ExternalSecret ? …

---

## [Add\_field processor on empty env provider fields stop ingest](https://discuss.elastic.co/t/add-field-processor-on-empty-env-provider-fields-stop-ingest/343371)

<div class="topic-metadata">

**Author:** [@sholzhauer](https://discuss.elastic.co/u/sholzhauer)\
**Replies:** 0\
**Last updated:** [September 19, 2023, 1:36pm UTC](https://discuss.elastic.co/t/add-field-processor-on-empty-env-provider-fields-stop-ingest/343371 "2023-09-19T13:36:06Z")

</div>

Hi, Our nodes have some attributes to define what asset they belong to (environment, application, component). With migrating to agent these fields got lost and we have utilized the environment provider and the add\_field…

---

## [How to map ambiguous data](https://discuss.elastic.co/t/how-to-map-ambiguous-data/343271)

<div class="topic-metadata">

**Author:** [@francieliton\_araujo](https://discuss.elastic.co/u/francieliton_araujo)\
**Replies:** 3\
**Last updated:** [September 19, 2023, 1:56pm UTC](https://discuss.elastic.co/t/how-to-map-ambiguous-data/343271 "2023-09-19T13:56:36Z")

</div>

There is a more practical way to map ambiguous data other than deleting and creating index, I need to make a query to the canvas but try to show a column with an error because the data cannot be ambiguous

---

## [Clarification regarding filebeat and metricbeat support policy](https://discuss.elastic.co/t/clarification-regarding-filebeat-and-metricbeat-support-policy/342940)

<div class="topic-metadata">

**Author:** [@ishaq](https://discuss.elastic.co/u/ishaq)\
**Replies:** 3\
**Last updated:** [September 19, 2023, 1:04pm UTC](https://discuss.elastic.co/t/clarification-regarding-filebeat-and-metricbeat-support-policy/342940 "2023-09-19T13:04:53Z")

</div>

Hey :wave: I've been going over the docs and this forum for an official version support policy for metricbeat and filebeat but I have not had any luck yet. I'd be grateful if someone could link me to it, if it exists. I…

---

## [Trying to find the plugin download url for Kibana](https://discuss.elastic.co/t/trying-to-find-the-plugin-download-url-for-kibana/342179)

<div class="topic-metadata">

**Author:** [@Max\_Karimi](https://discuss.elastic.co/u/Max_Karimi)\
**Replies:** 8\
**Last updated:** [September 19, 2023, 12:57pm UTC](https://discuss.elastic.co/t/trying-to-find-the-plugin-download-url-for-kibana/342179 "2023-09-19T12:57:00Z")

</div>

Hi, I am trying to download and install APM plugin for Kibana according to this document Install Kibana plugins | Elastic Cloud on Kubernetes \[2.9\] | Elastic but I cannot find any download link for that plugin. anyone c…

---

## [Substituting Match Phrase Prefix Query with a MUST combination of Match Phrase and Prefix](https://discuss.elastic.co/t/substituting-match-phrase-prefix-query-with-a-must-combination-of-match-phrase-and-prefix/343218)

<div class="topic-metadata">

**Author:** [@aliyanamu](https://discuss.elastic.co/u/aliyanamu)\
**Replies:** 1\
**Last updated:** [September 19, 2023, 12:24pm UTC](https://discuss.elastic.co/t/substituting-match-phrase-prefix-query-with-a-must-combination-of-match-phrase-and-prefix/343218 "2023-09-19T12:24:55Z")

</div>

Hi, I am using match phrase prefix for suggestion and querying search result. I'm using this for searching employee name, skill name, etc... basically name / title field which is not long. When I'm searching name like …

---

## [Unable to filter older indices](https://discuss.elastic.co/t/unable-to-filter-older-indices/343359)

<div class="topic-metadata">

**Author:** [@pbmamatha](https://discuss.elastic.co/u/pbmamatha)\
**Replies:** 0\
**Last updated:** [September 19, 2023, 12:16pm UTC](https://discuss.elastic.co/t/unable-to-filter-older-indices/343359 "2023-09-19T12:16:04Z")

</div>

Hello, I am tasked to create an alert for indices older than 3 days, however, the filter query is not working. Could you please help me identify the issue. Have tried the below queries: 1. GET /\_search { "query":…

---

## [Send emails with PDF Dashboard](https://discuss.elastic.co/t/send-emails-with-pdf-dashboard/341105)

<div class="topic-metadata">

**Author:** [@hofrichterovak](https://discuss.elastic.co/u/hofrichterovak)\
**Replies:** 2\
**Last updated:** [September 19, 2023, 12:01pm UTC](https://discuss.elastic.co/t/send-emails-with-pdf-dashboard/341105 "2023-09-19T12:01:36Z")

</div>

Hello, I read the documentation about sending email with PDF dashboard in the attachment \>\>\> Automatically generate reports | Kibana Guide \[8.9\] | Elastic I wanted to create my own watcher. My Kibana version is 7.17.8 …

---

## [Error: could not start the HTTP server for the API: listen tcp 127.0.0.1:6791: bind: address already in use](https://discuss.elastic.co/t/error-could-not-start-the-http-server-for-the-api-listen-tcp-127-0-0-1-bind-address-already-in-use/342447)

<div class="topic-metadata">

**Author:** [@tirelibirefe](https://discuss.elastic.co/u/tirelibirefe)\
**Replies:** 1\
**Last updated:** [September 19, 2023, 10:04am UTC](https://discuss.elastic.co/t/error-could-not-start-the-http-server-for-the-api-listen-tcp-127-0-0-1-bind-address-already-in-use/342447 "2023-09-19T10:04:21Z")

</div>

Hello, I have 6 node EKS cluster and installed Elasticsearch/Kibana 8.9.1 . I have been struggling with Fleet. Although 5 elastic-agent pods works on 5 nodes, 1 elastic-agent on 1 node gives following error: Error: co…

---

## [Log threshold alerting rule to check the presence of logs on specific hosts](https://discuss.elastic.co/t/log-threshold-alerting-rule-to-check-the-presence-of-logs-on-specific-hosts/342799)

<div class="topic-metadata">

**Author:** [@melkamar](https://discuss.elastic.co/u/melkamar)\
**Replies:** 6\
**Last updated:** [September 19, 2023, 9:40am UTC](https://discuss.elastic.co/t/log-threshold-alerting-rule-to-check-the-presence-of-logs-on-specific-hosts/342799 "2023-09-19T09:40:28Z")

</div>

Hi, I am trying to set up an alert rule that will alert me when a job that I expect to run at particular servers stops writing into the syslog. The idea is that I want to receive alerts when: Any host with a field ser…

---

## [Which Node.js client should I use for Elastic search?](https://discuss.elastic.co/t/which-node-js-client-should-i-use-for-elastic-search/343115)

<div class="topic-metadata">

**Author:** [@cosieLq](https://discuss.elastic.co/u/cosieLq)\
**Replies:** 8\
**Last updated:** [September 19, 2023, 9:40am UTC](https://discuss.elastic.co/t/which-node-js-client-should-i-use-for-elastic-search/343115 "2023-09-19T09:40:20Z")

</div>

Which package should I use as a Node.js client to connect to Elastic search? I've found this one: elasticsearch-js (GitHub - elastic/elasticsearch-js: Official Elasticsearch client library for Node.js) It seems to be r…

---

## [Installation Freeze (adding index template)](https://discuss.elastic.co/t/installation-freeze-adding-index-template/343324)

<div class="topic-metadata">

**Author:** [@fizzyBubblech](https://discuss.elastic.co/u/fizzyBubblech)\
**Replies:** 3\
**Last updated:** [September 19, 2023, 8:56am UTC](https://discuss.elastic.co/t/installation-freeze-adding-index-template/343324 "2023-09-19T08:56:06Z")

</div>

Hello My Goal: Install Kibana and Elasticsearch on my Windows 11 VM. Our Infrastructure We run our VMs on ESXi and managed them in vCenter. I have Admin rights but just for my VM. Install processes 1.) Downloaded …

---

## [Calculating the difference between datetime cells for an average](https://discuss.elastic.co/t/calculating-the-difference-between-datetime-cells-for-an-average/343225)

<div class="topic-metadata">

**Author:** [@SpicyS](https://discuss.elastic.co/u/SpicyS)\
**Replies:** 8\
**Last updated:** [September 19, 2023, 8:46am UTC](https://discuss.elastic.co/t/calculating-the-difference-between-datetime-cells-for-an-average/343225 "2023-09-19T08:46:54Z")

</div>

Hello, I'm new to kibana and I would like to know if it is possible to calculate the difference between 2 datetime fields named: "start\_date" and "end\_date", the reason for this is the fact I want to show the average du…

---

## [Error when converting Eland Dataframe to Pandas Dataframe using Eland on Jupyter](https://discuss.elastic.co/t/error-when-converting-eland-dataframe-to-pandas-dataframe-using-eland-on-jupyter/343331)

<div class="topic-metadata">

**Author:** [@xynobob](https://discuss.elastic.co/u/xynobob)\
**Replies:** 0\
**Last updated:** [September 19, 2023, 8:46am UTC](https://discuss.elastic.co/t/error-when-converting-eland-dataframe-to-pandas-dataframe-using-eland-on-jupyter/343331 "2023-09-19T08:46:50Z")

</div>

I currently have setup Eland to pull data from Elasticsearch and I am trying to rename some of the columns. However, I realised that to use the .rename() function, I would have to convert the data to Pandas Dataframe as …

---

## [Is it possible to generate or export a csv from Kibana dev tool](https://discuss.elastic.co/t/is-it-possible-to-generate-or-export-a-csv-from-kibana-dev-tool/343027)

<div class="topic-metadata">

**Author:** [@JasonREC](https://discuss.elastic.co/u/JasonREC)\
**Replies:** 2\
**Last updated:** [September 19, 2023, 8:38am UTC](https://discuss.elastic.co/t/is-it-possible-to-generate-or-export-a-csv-from-kibana-dev-tool/343027 "2023-09-19T08:38:11Z")

</div>

Hi, I wonder if it is possible to generate a CSV report from dev tool ? The following is my query run on Kibana dev tool, it composed of query and aggregation. I want to generate the query response to a csv. if it is …

---

## [Kibana server is not ready yet](https://discuss.elastic.co/t/kibana-server-is-not-ready-yet/343270)

<div class="topic-metadata">

**Author:** [@emoxam](https://discuss.elastic.co/u/emoxam)\
**Replies:** 4\
**Last updated:** [September 19, 2023, 6:38am UTC](https://discuss.elastic.co/t/kibana-server-is-not-ready-yet/343270 "2023-09-19T06:38:25Z")

</div>

I got one host with elasticsearch and kibana, i don't want to use any ssl/tls. That's an error i got in logs now. How can i fix kibana ? It's web page shows me "Kibana server is not ready yet" journalctl -efu kibana.se…

---

## [Some Questions About Security Vulnerabilities: ESA-2023-14](https://discuss.elastic.co/t/some-questions-about-security-vulnerabilities-esa-2023-14/343317)

<div class="topic-metadata">

**Author:** [@zekaifeng](https://discuss.elastic.co/u/zekaifeng)\
**Replies:** 0\
**Last updated:** [September 19, 2023, 6:33am UTC](https://discuss.elastic.co/t/some-questions-about-security-vulnerabilities-esa-2023-14/343317 "2023-09-19T06:33:09Z")

</div>

Hello, everybody. According to the community's safety announcement: I don't know which issue is associated with this security update or which pr fixed the issue.

---

## [Elastic-agent and Veeam man plugin](https://discuss.elastic.co/t/elastic-agent-and-veeam-man-plugin/343316)

<div class="topic-metadata">

**Author:** [@thiesens](https://discuss.elastic.co/u/thiesens)\
**Replies:** 0\
**Last updated:** [September 19, 2023, 6:16am UTC](https://discuss.elastic.co/t/elastic-agent-and-veeam-man-plugin/343316 "2023-09-19T06:16:36Z")

</div>

Hi all.. I have a few Oracle servers, where I want to install elastic-agent. The problem for me is that I have Veeam RMAN plugin installed, and it seems that both are using port 6791. Is it possible to change the elas…

---

## [Query\_string does not perform consistently in versions 6 and 7](https://discuss.elastic.co/t/query-string-does-not-perform-consistently-in-versions-6-and-7/343228)

<div class="topic-metadata">

**Author:** [@casterQ](https://discuss.elastic.co/u/casterQ)\
**Replies:** 2\
**Last updated:** [September 19, 2023, 6:04am UTC](https://discuss.elastic.co/t/query-string-does-not-perform-consistently-in-versions-6-and-7/343228 "2023-09-19T06:04:55Z")

</div>

version: 6.7.0 and 7.17.6 mapping: { "t1": { "type": "text", "analyzer": "ik\_max\_word" }, "t2": { "type": "text", "analyzer": "ik\_max\_word" } } DSL: POST test1/\_search { "query": { "boo…

---

## [Logstash - How to Dynamic Parse Log's value](https://discuss.elastic.co/t/logstash-how-to-dynamic-parse-logs-value/343125)

<div class="topic-metadata">

**Author:** [@Huy\_Hoang\_Le](https://discuss.elastic.co/u/Huy_Hoang_Le)\
**Replies:** 8\
**Last updated:** [September 19, 2023, 3:36am UTC](https://discuss.elastic.co/t/logstash-how-to-dynamic-parse-logs-value/343125 "2023-09-19T03:36:25Z")

</div>

Hi I have this sample Document \[Thread-13\]\[2023-09-15 09:32:35\]\[INFO\]:{'\[Sub\]0-BaseTransformer\]': '0.0004', '\[Sub\]1-NGINX Feature Extractor Service\]': '0.0135', '\[Dataloader\]\[#0.-PutToQueue\]': '0.0005', '\[Sub\]\[#1.EMA\_FP…

---

## [Install Elasticsearch with Docker](https://discuss.elastic.co/t/install-elasticsearch-with-docker/342271)

<div class="topic-metadata">

**Author:** [@alexus](https://discuss.elastic.co/u/alexus)\
**Replies:** 26\
**Last updated:** [September 19, 2023, 2:35am UTC](https://discuss.elastic.co/t/install-elasticsearch-with-docker/342271 "2023-09-19T02:35:52Z")

</div>

Hello World! I'm trying to follow https://www.elastic.co/guide/en/elasticsearch/reference/current/docker.html#docker-compose-file, I copy .env file, change password, then copy and paste docker-compose.yml and then the …

---

## [Filestream take\_over mode seems to be ignored](https://discuss.elastic.co/t/filestream-take-over-mode-seems-to-be-ignored/343220)

<div class="topic-metadata">

**Author:** [@gparks](https://discuss.elastic.co/u/gparks)\
**Replies:** 1\
**Last updated:** [September 19, 2023, 1:09am UTC](https://discuss.elastic.co/t/filestream-take-over-mode-seems-to-be-ignored/343220 "2023-09-19T01:09:06Z")

</div>

I'm running filebeat 8.8.2 on centos 7 I'm in the process of switching from log inputs to filestream inputs on pre-existing servers so I was trying to use the take\_over mode in order to not re-process the logs. I'm not…

---

## [I was deploying docker and ran into a problem, unable to access port 3002](https://discuss.elastic.co/t/i-was-deploying-docker-and-ran-into-a-problem-unable-to-access-port-3002/343197)

<div class="topic-metadata">

**Author:** [@qinskysky](https://discuss.elastic.co/u/qinskysky)\
**Replies:** 6\
**Last updated:** [September 19, 2023, 12:18am UTC](https://discuss.elastic.co/t/i-was-deploying-docker-and-ran-into-a-problem-unable-to-access-port-3002/343197 "2023-09-19T00:18:07Z")

</div>

Add the Enterprise Search host URL to the Kibana configuration In the config/kibana.yml file, set enterpriseSearch.host to the URL of the Enterprise Search instance. For example: enterpriseSearch.host: 'http://localhos…

[Previous page](https://discuss.elastic.co/latest.md?page=535)

[Next page](https://discuss.elastic.co/latest.md?page=537)
