# Latest

**URL:** https://discuss.elastic.co/latest.md?page=539

[Latest](https://discuss.elastic.co/latest.md) · [Categories](https://discuss.elastic.co/categories.md) · [Tags](https://discuss.elastic.co/tags.md)

**Page:** 540

---

## [Changing default configuration of Elastic Agent Integration to filter out events before ingestion](https://discuss.elastic.co/t/changing-default-configuration-of-elastic-agent-integration-to-filter-out-events-before-ingestion/343164)

<div class="topic-metadata">

**Author:** [@Sushant\_Bhatnagar](https://discuss.elastic.co/u/Sushant_Bhatnagar)\
**Replies:** 0\
**Last updated:** [September 15, 2023, 9:38pm UTC](https://discuss.elastic.co/t/changing-default-configuration-of-elastic-agent-integration-to-filter-out-events-before-ingestion/343164 "2023-09-15T21:38:27Z")

</div>

Hello, I created an Elastic agent policy to attach it few hosts and while creating it - I checked the Collect agent logs checkbox under Agent Monitoring section. Now in the events in discover tab, I see dataset as "el…

---

## [\[Netflow\] Issues with Module](https://discuss.elastic.co/t/netflow-issues-with-module/343158)

<div class="topic-metadata">

**Author:** [@Rossana](https://discuss.elastic.co/u/Rossana)\
**Replies:** 0\
**Last updated:** [September 15, 2023, 7:16pm UTC](https://discuss.elastic.co/t/netflow-issues-with-module/343158 "2023-09-15T19:16:02Z")

</div>

Hi! I try to avoid the use of netflow codec of logstash, cause i understand that is deprecated. I configure Netflow Module on filbeat. But does not work. I also configure as an input but still does not work. Netflow …

---

## [Advice needed on making logs available to application developer](https://discuss.elastic.co/t/advice-needed-on-making-logs-available-to-application-developer/341599)

<div class="topic-metadata">

**Author:** [@mubashar.tariq](https://discuss.elastic.co/u/mubashar.tariq)\
**Replies:** 3\
**Last updated:** [September 15, 2023, 6:48pm UTC](https://discuss.elastic.co/t/advice-needed-on-making-logs-available-to-application-developer/341599 "2023-09-15T18:48:25Z")

</div>

Background: We have number of large web applications deployed to WebLogic servers that are running on RedHat Linux 8. Development Teams need access to different logs (e.g. WebLogic, application logs) on these Linux machi…

---

## [Drop filter in Logstash filter not working for the below event](https://discuss.elastic.co/t/drop-filter-in-logstash-filter-not-working-for-the-below-event/343120)

<div class="topic-metadata">

**Author:** [@Subrato1](https://discuss.elastic.co/u/Subrato1)\
**Replies:** 1\
**Last updated:** [September 15, 2023, 6:31pm UTC](https://discuss.elastic.co/t/drop-filter-in-logstash-filter-not-working-for-the-below-event/343120 "2023-09-15T18:31:11Z")

</div>

Event in Logstash : { "timestamp" =\> "2023-09-13T05:10:52.527038098Z", "user" =\> "admin", "type" =\> "icd\_postgresql", "status" =\> "INSERT INTO t1 SELECT i/100, i/500 FROM generate\_series(1,1…

---

## [Metricbeat module Apache error - error fetching data: HTTP error 404 in : 404 Not Found](https://discuss.elastic.co/t/metricbeat-module-apache-error-error-fetching-data-http-error-404-in-404-not-found/343078)

<div class="topic-metadata">

**Author:** [@Carlos\_T](https://discuss.elastic.co/u/Carlos_T)\
**Replies:** 2\
**Last updated:** [September 15, 2023, 6:24pm UTC](https://discuss.elastic.co/t/metricbeat-module-apache-error-error-fetching-data-http-error-404-in-404-not-found/343078 "2023-09-15T18:24:41Z")

</div>

Hi all I having problems when trying to get metrics from my Apache installation running on a Centos 7 VM Env: ECK 2.6.1 1 ES Master Node 8.6.2 running on a single node K3S Kubernetes Cluster installed on Centos 7 Ser…

---

## [Deal with small indices (ILM Policy)](https://discuss.elastic.co/t/deal-with-small-indices-ilm-policy/342979)

<div class="topic-metadata">

**Author:** [@elk-user-0001](https://discuss.elastic.co/u/elk-user-0001)\
**Replies:** 3\
**Last updated:** [September 15, 2023, 4:33pm UTC](https://discuss.elastic.co/t/deal-with-small-indices-ilm-policy/342979 "2023-09-15T16:33:25Z")

</div>

Hello partners! :wave: I have set up an Elastic Stack cluster and i am performing multiple ingestions. Some of these ingestions are abundant, ingesting around 50 GB per day, however, others contain 500... 10000 docs...…

---

## [Srping data elasticsearch document count info using built in reactive client](https://discuss.elastic.co/t/srping-data-elasticsearch-document-count-info-using-built-in-reactive-client/343148)

<div class="topic-metadata">

**Author:** [@D1sturbance](https://discuss.elastic.co/u/D1sturbance)\
**Replies:** 0\
**Last updated:** [September 15, 2023, 2:50pm UTC](https://discuss.elastic.co/t/srping-data-elasticsearch-document-count-info-using-built-in-reactive-client/343148 "2023-09-15T14:50:57Z")

</div>

My problem: I am trying to get indices information: IndexName IndexCreationDate IndexAlias IndexDocumentCount IndexSize I am able to get some of that information via GetIndexResponse mentioned below. Which holds alia…

---

## [Add dynamic date range in CSV post url](https://discuss.elastic.co/t/add-dynamic-date-range-in-csv-post-url/342500)

<div class="topic-metadata">

**Author:** [@Atul\_Chadha](https://discuss.elastic.co/u/Atul_Chadha)\
**Replies:** 2\
**Last updated:** [September 15, 2023, 2:56pm UTC](https://discuss.elastic.co/t/add-dynamic-date-range-in-csv-post-url/342500 "2023-09-15T14:56:20Z")

</div>

I am using ES 7.x and trying to add POST URL from CSV share feature into another system. Is there a way to add date range dynamically Link here because the url provided by UI has fixed date and we do not want to come to …

---

## [EQL Language trouble when creating custom rule](https://discuss.elastic.co/t/eql-language-trouble-when-creating-custom-rule/343144)

<div class="topic-metadata">

**Author:** [@Brandon\_Duffy](https://discuss.elastic.co/u/Brandon_Duffy)\
**Replies:** 0\
**Last updated:** [September 15, 2023, 2:02pm UTC](https://discuss.elastic.co/t/eql-language-trouble-when-creating-custom-rule/343144 "2023-09-15T14:02:43Z")

</div>

Hello, I've been working on this rule for some time now, and it is only partially working. I am able to see the net.exe related alerts populate, and used to see 'systeminfo', 'hostname', 'nslookup', now i do not. I can…

---

## [Kibana Maps world countries does not have names](https://discuss.elastic.co/t/kibana-maps-world-countries-does-not-have-names/342872)

<div class="topic-metadata">

**Author:** [@rachelyang](https://discuss.elastic.co/u/rachelyang)\
**Replies:** 3\
**Last updated:** [September 15, 2023, 1:08pm UTC](https://discuss.elastic.co/t/kibana-maps-world-countries-does-not-have-names/342872 "2023-09-15T13:08:27Z")

</div>

I chose Data source EMS Boundaries Layer \[world\_countries\] , when I added a new layer to the map. The map does not contain the country names. Please check the attachment. How do I display the names? Thanks.

---

## [Custom filebeat docker image error](https://discuss.elastic.co/t/custom-filebeat-docker-image-error/343140)

<div class="topic-metadata">

**Author:** [@matheuscirillo](https://discuss.elastic.co/u/matheuscirillo)\
**Replies:** 1\
**Last updated:** [September 15, 2023, 1:05pm UTC](https://discuss.elastic.co/t/custom-filebeat-docker-image-error/343140 "2023-09-15T13:05:45Z")

</div>

The custom image configuration section on the docs says that we can do the following to create a customized image: FROM docker.elastic.co/beats/filebeat:8.10.0 COPY --chown=root:filebeat filebeat.yml /usr/share/filebeat…

---

## [One ELK Node is Down](https://discuss.elastic.co/t/one-elk-node-is-down/343041)

<div class="topic-metadata">

**Author:** [@linux\_admin](https://discuss.elastic.co/u/linux_admin)\
**Replies:** 1\
**Last updated:** [September 15, 2023, 12:53pm UTC](https://discuss.elastic.co/t/one-elk-node-is-down/343041 "2023-09-15T12:53:30Z")

</div>

Dear All, I have ELK cluster consists of three nodes elk01, elk02, elk03. One node elk01 is suddenly down. When I check the logs /var/log/elasticsearch/elasticsearch.log of elk01, I found these errors: "\[elk01\] Authent…

---

## [BulkIngester and Integration Testing](https://discuss.elastic.co/t/bulkingester-and-integration-testing/341595)

<div class="topic-metadata">

**Author:** [@toddcarv](https://discuss.elastic.co/u/toddcarv)\
**Replies:** 7\
**Last updated:** [September 15, 2023, 12:29pm UTC](https://discuss.elastic.co/t/bulkingester-and-integration-testing/341595 "2023-09-15T12:29:29Z")

</div>

Can someone point me to some examples of integration testing while using the BulkIngester? Specifically how to test a class method that uses the BulkIngester. I'm having timing issues with calling flush on the BulkIngest…

---

## [Painless script to convert from HEX to string](https://discuss.elastic.co/t/painless-script-to-convert-from-hex-to-string/343134)

<div class="topic-metadata">

**Author:** [@alextg](https://discuss.elastic.co/u/alextg)\
**Replies:** 0\
**Last updated:** [September 15, 2023, 11:12am UTC](https://discuss.elastic.co/t/painless-script-to-convert-from-hex-to-string/343134 "2023-09-15T11:12:40Z")

</div>

Hi, I need to convert an HEX field to string using Painless script. Please advise how can this be achieved.

---

## [Want to loop post text into MS team Channel but Error](https://discuss.elastic.co/t/want-to-loop-post-text-into-ms-team-channel-but-error/343129)

<div class="topic-metadata">

**Author:** [@rathasatekun](https://discuss.elastic.co/u/rathasatekun)\
**Replies:** 0\
**Last updated:** [September 15, 2023, 10:24am UTC](https://discuss.elastic.co/t/want-to-loop-post-text-into-ms-team-channel-but-error/343129 "2023-09-15T10:24:48Z")

</div>

Hi Elastic team I have watcher data from search from indices and then make text for post into ms team channel but i can not send text value into ms team channel it's error: "Newtonsoft.Json.JsonReaderException: After pa…

---

## [Read-only URL Repository](https://discuss.elastic.co/t/read-only-url-repository/343104)

<div class="topic-metadata">

**Author:** [@frh](https://discuss.elastic.co/u/frh)\
**Replies:** 1\
**Last updated:** [September 15, 2023, 10:17am UTC](https://discuss.elastic.co/t/read-only-url-repository/343104 "2023-09-15T10:17:45Z")

</div>

Hi, I just created read-only URL repository and give it a name as "test". I got this error when verify repository: { "error": { "root\_cause": \[ { "type": "repository\_exception", "reason": "\[…

---

## [Scores are inconsistent with data and query](https://discuss.elastic.co/t/scores-are-inconsistent-with-data-and-query/343121)

<div class="topic-metadata">

**Author:** [@appsol](https://discuss.elastic.co/u/appsol)\
**Replies:** 0\
**Last updated:** [September 15, 2023, 9:03am UTC](https://discuss.elastic.co/t/scores-are-inconsistent-with-data-and-query/343121 "2023-09-15T09:03:05Z")

</div>

Hello, My document has a title field and an intro field. I have given greater importance to the title field over the intro field in my query, yet all other fields being equal, the intro field is getting a higher score t…

---

## [Not able to connect to elastic from kibana](https://discuss.elastic.co/t/not-able-to-connect-to-elastic-from-kibana/341652)

<div class="topic-metadata">

**Author:** [@chitra\_perumal](https://discuss.elastic.co/u/chitra_perumal)\
**Replies:** 16\
**Last updated:** [September 15, 2023, 8:00am UTC](https://discuss.elastic.co/t/not-able-to-connect-to-elastic-from-kibana/341652 "2023-09-15T08:00:12Z")

</div>

Hello, I am trying to set up the OIDC authentication for Kibana in SSO . I have followed the steps from elastic guide. The CA and HTTP certificates are created as per the details provided in above link. The elastic is…

---

## [Summary listen time for audio file](https://discuss.elastic.co/t/summary-listen-time-for-audio-file/343113)

<div class="topic-metadata">

**Author:** [@abram](https://discuss.elastic.co/u/abram)\
**Replies:** 0\
**Last updated:** [September 15, 2023, 7:25am UTC](https://discuss.elastic.co/t/summary-listen-time-for-audio-file/343113 "2023-09-15T07:25:59Z")

</div>

I log listen time from my player, (second\_frame is integer\_range). How i can sumamry listen time, so in this case ranges are (2945 - 2970, 2957 - 2962, 2962 - 2977), it should response 32 second (first region + 25, secon…

---

## [Rally 2.9.1](https://discuss.elastic.co/t/rally-2-9-1/343112)

<div class="topic-metadata">

**Author:** [@Quentin\_Pradet](https://discuss.elastic.co/u/Quentin_Pradet)\
**Replies:** 0\
**Last updated:** [September 15, 2023, 7:25am UTC](https://discuss.elastic.co/t/rally-2-9-1/343112 "2023-09-15T07:25:10Z")

</div>

Rally 2.9.1 has just been released. Rally is the macrobenchmarking framework for Elasticsearch. The new continues to improve support for the upcoming Elasticsearch Serverless offering and fixes a bug introduced in Rally …

---

## [Adding Documents via REST API in ElasticSearch](https://discuss.elastic.co/t/adding-documents-via-rest-api-in-elasticsearch/343102)

<div class="topic-metadata">

**Author:** [@sanyam](https://discuss.elastic.co/u/sanyam)\
**Replies:** 4\
**Last updated:** [September 15, 2023, 6:45am UTC](https://discuss.elastic.co/t/adding-documents-via-rest-api-in-elasticsearch/343102 "2023-09-15T06:45:18Z")

</div>

I am getting this error while trying to run this code to add data/document In Elasticsearch version 6.4.1 in windows curl -X POST "localhost:9200/clusters/\_doc" -H "Content-Type" : application/json -d "{ "field1":"valu…

---

## [Help elk stack](https://discuss.elastic.co/t/help-elk-stack/342595)

<div class="topic-metadata">

**Author:** [@Farah\_Bannour](https://discuss.elastic.co/u/Farah_Bannour)\
**Replies:** 6\
**Last updated:** [September 15, 2023, 6:05am UTC](https://discuss.elastic.co/t/help-elk-stack/342595 "2023-09-15T06:05:54Z")

</div>

Bonjour j'ai une question j ai un champs date\_le(qui contient le date exemple 20 tte date juillet 2022,13 aout 2023 etc je voulais faire le split de ca comme l annee , le mois et apres la date comment je peux faire ca …

---

## [Filebeat not sending docker logs to logstash after enabling x-pack security features](https://discuss.elastic.co/t/filebeat-not-sending-docker-logs-to-logstash-after-enabling-x-pack-security-features/343100)

<div class="topic-metadata">

**Author:** [@Ajai\_Raj](https://discuss.elastic.co/u/Ajai_Raj)\
**Replies:** 0\
**Last updated:** [September 15, 2023, 5:02am UTC](https://discuss.elastic.co/t/filebeat-not-sending-docker-logs-to-logstash-after-enabling-x-pack-security-features/343100 "2023-09-15T05:02:01Z")

</div>

Please help me in this i've been trying to create a user in ELK after enabling the x-pack security feature in my elasticsearch.yml file. The docker container logs are not syncing in kibana after i enable the security fea…

---

## [Logstash Grok Pattern Watchguard Firewall](https://discuss.elastic.co/t/logstash-grok-pattern-watchguard-firewall/342317)

<div class="topic-metadata">

**Author:** [@Simon7](https://discuss.elastic.co/u/Simon7)\
**Replies:** 6\
**Last updated:** [September 15, 2023, 5:22am UTC](https://discuss.elastic.co/t/logstash-grok-pattern-watchguard-firewall/342317 "2023-09-15T05:22:41Z")

</div>

Hey Guys, this is my first topic here in this forum. I have established an Elasticsearch log management in our company. I'm having a bit of trouble with the grok pattern. If I can't use integrations, I need to create m…

---

## [Elasticsearch error in running service JAVA error](https://discuss.elastic.co/t/elasticsearch-error-in-running-service-java-error/342782)

<div class="topic-metadata">

**Author:** [@1337](https://discuss.elastic.co/u/1337)\
**Replies:** 15\
**Last updated:** [September 15, 2023, 4:51am UTC](https://discuss.elastic.co/t/elasticsearch-error-in-running-service-java-error/342782 "2023-09-15T04:51:26Z")

</div>

systemctl status elasticsearch × elasticsearch.service - Elasticsearch Loaded: loaded (/lib/systemd/system/elasticsearch.service; enabled; vendor preset: enabled) Active: failed (Result: exit-code) since Tue 2…

---

## [URI too long with custom routing](https://discuss.elastic.co/t/uri-too-long-with-custom-routing/342993)

<div class="topic-metadata">

**Author:** [@Dhineshkumar\_R](https://discuss.elastic.co/u/Dhineshkumar_R)\
**Replies:** 7\
**Last updated:** [September 15, 2023, 2:55am UTC](https://discuss.elastic.co/t/uri-too-long-with-custom-routing/342993 "2023-09-15T02:55:25Z")

</div>

Hi Team, I'm experimenting with custom routing to bring down the latency of search requests in my cluster. The routing\_ids are assigned in groups of N. For ex. a key with 1000 associated documents will be mapped to 10 d…

---

## [Error while using .scan() function call](https://discuss.elastic.co/t/error-while-using-scan-function-call/343039)

<div class="topic-metadata">

**Author:** [@hjazz6](https://discuss.elastic.co/u/hjazz6)\
**Replies:** 6\
**Last updated:** [September 15, 2023, 2:17am UTC](https://discuss.elastic.co/t/error-while-using-scan-function-call/343039 "2023-09-15T02:17:54Z")

</div>

Hi, I have the following Python code to query my ES cluster (v8.8.0). from elasticsearch import Elasticsearch from elasticsearch\_dsl import Search for i in range(0, 100): s = Search(using=es, index=index\_name) \\ …

---

## [Can Logstash use a file in an Azure BLOB container as its direct input?](https://discuss.elastic.co/t/can-logstash-use-a-file-in-an-azure-blob-container-as-its-direct-input/343080)

<div class="topic-metadata">

**Author:** [@Eugene\_Goldberg](https://discuss.elastic.co/u/Eugene_Goldberg)\
**Replies:** 0\
**Last updated:** [September 14, 2023, 9:34pm UTC](https://discuss.elastic.co/t/can-logstash-use-a-file-in-an-azure-blob-container-as-its-direct-input/343080 "2023-09-14T21:34:13Z")

</div>

Greetings, I am trying to configure Logstash to ingest changes to a JSON file which is stored in Azure BLOB storage container. There used to be an input plugin called \`\`\` logstash-input-azureblob When I attempted to i…

---

## [Multiple filters when creating a Metric Threshold](https://discuss.elastic.co/t/multiple-filters-when-creating-a-metric-threshold/342989)

<div class="topic-metadata">

**Author:** [@vsabado](https://discuss.elastic.co/u/vsabado)\
**Replies:** 22\
**Last updated:** [September 14, 2023, 9:17pm UTC](https://discuss.elastic.co/t/multiple-filters-when-creating-a-metric-threshold/342989 "2023-09-14T21:17:24Z")

</div>

I'm trying to create a rule in ES using the metric threshold. If I used a single filter, it works fine. But when I use a group of filters strung together using "and", like filter1 and filter2 and filter3, then it the rul…

---

## [How to set up alert based on value change over given amount of time](https://discuss.elastic.co/t/how-to-set-up-alert-based-on-value-change-over-given-amount-of-time/341083)

<div class="topic-metadata">

**Author:** [@Ruben\_Bajo](https://discuss.elastic.co/u/Ruben_Bajo)\
**Replies:** 6\
**Last updated:** [September 14, 2023, 9:08pm UTC](https://discuss.elastic.co/t/how-to-set-up-alert-based-on-value-change-over-given-amount-of-time/341083 "2023-09-14T21:08:07Z")

</div>

I have a costume log that contains a value that constantly increases over the day and gets back to 0 every midnight. I would like to set up a rule that can alert if this growth stops but I did not find a way to do that. …

[Previous page](https://discuss.elastic.co/latest.md?page=538)

[Next page](https://discuss.elastic.co/latest.md?page=540)
