# Latest

**URL:** https://discuss.elastic.co/latest.md?page=544

[Latest](https://discuss.elastic.co/latest.md) · [Categories](https://discuss.elastic.co/categories.md) · [Tags](https://discuss.elastic.co/tags.md)

**Page:** 545

---

## [Kibana maintenance window question](https://discuss.elastic.co/t/kibana-maintenance-window-question/342786)

<div class="topic-metadata">

**Author:** [@mkf1](https://discuss.elastic.co/u/mkf1)\
**Replies:** 3\
**Last updated:** [September 12, 2023, 10:37am UTC](https://discuss.elastic.co/t/kibana-maintenance-window-question/342786 "2023-09-12T10:37:34Z")

</div>

Hi, I couldn't see much in the documentation so I though I would ask my question here. It might be a dumb question, but in the Maintenance Window settings, I'm a bit confused on the timezone setting. For example if I s…

---

## [Use new dataview in an existing dashboard](https://discuss.elastic.co/t/use-new-dataview-in-an-existing-dashboard/342656)

<div class="topic-metadata">

**Author:** [@javierelastic](https://discuss.elastic.co/u/javierelastic)\
**Replies:** 2\
**Last updated:** [September 12, 2023, 9:38am UTC](https://discuss.elastic.co/t/use-new-dataview-in-an-existing-dashboard/342656 "2023-09-12T09:38:25Z")

</div>

Hi. I have a dashboard created with a set of data that I passed through logstash to elasticsearch. But now I have created a new index and a new dataview with similar data. And I want to use the complete dashboard with t…

---

## [Failed to fetch https://artifacts.elastic.co/packages/7.x/apt/dists/stable/InRelease 403 Forbidden \[IP: 2600:1901:0:1d7:: 443\]](https://discuss.elastic.co/t/failed-to-fetch-https-artifacts-elastic-co-packages-7-x-apt-dists-stable-inrelease-403-forbidden-ip-26000-443/341442)

<div class="topic-metadata">

**Author:** [@Andi0r](https://discuss.elastic.co/u/Andi0r)\
**Replies:** 8\
**Last updated:** [September 12, 2023, 9:35am UTC](https://discuss.elastic.co/t/failed-to-fetch-https-artifacts-elastic-co-packages-7-x-apt-dists-stable-inrelease-403-forbidden-ip-26000-443/341442 "2023-09-12T09:35:06Z")

</div>

Hi, i am trying to install Elastic Search but i am getting the error: Failed to fetch https://artifacts.elastic.co/packages/7.x/apt/dists/stable/InRelease 403 Forbidden \[IP: 2600:1901:0:1d7:: 443\] Could it be that y…

---

## [Is it possible to get only the types of fields I want from metricbeat?](https://discuss.elastic.co/t/is-it-possible-to-get-only-the-types-of-fields-i-want-from-metricbeat/342770)

<div class="topic-metadata">

**Author:** [@20wjsdudtj](https://discuss.elastic.co/u/20wjsdudtj)\
**Replies:** 2\
**Last updated:** [September 12, 2023, 9:12am UTC](https://discuss.elastic.co/t/is-it-possible-to-get-only-the-types-of-fields-i-want-from-metricbeat/342770 "2023-09-12T09:12:43Z")

</div>

My metricbeat default field brings in too much unnecessary data. (For example, kubernetes. Kubernetes-related data such as pod.name, uid, namespace.., etc. There are only a few data I need. Can I specify and import this?…

---

## [Is Is watcher is free in elastic search? if paid than what is the cost?](https://discuss.elastic.co/t/is-is-watcher-is-free-in-elastic-search-if-paid-than-what-is-the-cost/342785)

<div class="topic-metadata">

**Author:** [@jaimika\_kosambia](https://discuss.elastic.co/u/jaimika_kosambia)\
**Replies:** 1\
**Last updated:** [September 12, 2023, 9:05am UTC](https://discuss.elastic.co/t/is-is-watcher-is-free-in-elastic-search-if-paid-than-what-is-the-cost/342785 "2023-09-12T09:05:03Z")

</div>

Is watcher is free in Elasticsearch? if paid than what is the cost?

---

## [I need to use search\_after sort by \_score and \_id in a rescore query](https://discuss.elastic.co/t/i-need-to-use-search-after-sort-by-score-and-id-in-a-rescore-query/342789)

<div class="topic-metadata">

**Author:** [@George\_Githinji](https://discuss.elastic.co/u/George_Githinji)\
**Replies:** 0\
**Last updated:** [September 12, 2023, 8:20am UTC](https://discuss.elastic.co/t/i-need-to-use-search-after-sort-by-score-and-id-in-a-rescore-query/342789 "2023-09-12T08:20:03Z")

</div>

I want to implement the search\_after pagination technique, I want to sort out the data using \_score and \_id. The problem I am facing is that I have built my query using rescore and you can't use the sort and rescore at t…

---

## [Which Rule Type is Better to Monitor the data streams and raise an alert](https://discuss.elastic.co/t/which-rule-type-is-better-to-monitor-the-data-streams-and-raise-an-alert/342561)

<div class="topic-metadata">

**Author:** [@vinay.bommarati](https://discuss.elastic.co/u/vinay.bommarati)\
**Replies:** 4\
**Last updated:** [September 12, 2023, 8:28am UTC](https://discuss.elastic.co/t/which-rule-type-is-better-to-monitor-the-data-streams-and-raise-an-alert/342561 "2023-09-12T08:28:12Z")

</div>

Hi Team , we are exploring elastic observability. At the moment , using logstash pipelines as intermediary , we are able to push our logs from different applications to central elastic. Every application logs go into…

---

## [Error pipeline/output.go:180 failed to publish events: temporary bulk send failure](https://discuss.elastic.co/t/error-pipeline-output-go-180-failed-to-publish-events-temporary-bulk-send-failure/342788)

<div class="topic-metadata">

**Author:** [@Sevde\_Nur\_Canli](https://discuss.elastic.co/u/Sevde_Nur_Canli)\
**Replies:** 0\
**Last updated:** [September 12, 2023, 8:09am UTC](https://discuss.elastic.co/t/error-pipeline-output-go-180-failed-to-publish-events-temporary-bulk-send-failure/342788 "2023-09-12T08:09:56Z")

</div>

Hello I recently got the following error, pipeline/output.go:180 failed to publish events: temporary bulk send failure I tried everything to solve this problem and look every info in the internet but no solution still. …

---

## [Unable to add tags-field to APM documents through ingest pipeline](https://discuss.elastic.co/t/unable-to-add-tags-field-to-apm-documents-through-ingest-pipeline/342580)

<div class="topic-metadata">

**Author:** [@apt-get\_install\_skil](https://discuss.elastic.co/u/apt-get_install_skil)\
**Replies:** 2\
**Last updated:** [September 12, 2023, 7:44am UTC](https://discuss.elastic.co/t/unable-to-add-tags-field-to-apm-documents-through-ingest-pipeline/342580 "2023-09-12T07:44:40Z")

</div>

I'm implementing some ingest pipelines to enrich our APM/RUM data. Works fine so far. However, I noticed that when I try to add a tags field, neither Kibana nor Elasticsearch can properly handle it. For example a very ba…

---

## [Generating term vectors on the fly](https://discuss.elastic.co/t/generating-term-vectors-on-the-fly/342784)

<div class="topic-metadata">

**Author:** [@d\_u](https://discuss.elastic.co/u/d_u)\
**Replies:** 0\
**Last updated:** [September 12, 2023, 6:47am UTC](https://discuss.elastic.co/t/generating-term-vectors-on-the-fly/342784 "2023-09-12T06:47:54Z")

</div>

Suppose, I have more than 1mil documents where I have a text field lets say "Contents". We have not enabled termvector for the index. Now when we want to find count of occurrence of a word lets say "data" in "Contents" …

---

## [Kibana data view containing runtime composite fields](https://discuss.elastic.co/t/kibana-data-view-containing-runtime-composite-fields/341586)

<div class="topic-metadata">

**Author:** [@i.raisr](https://discuss.elastic.co/u/i.raisr)\
**Replies:** 2\
**Last updated:** [September 12, 2023, 6:23am UTC](https://discuss.elastic.co/t/kibana-data-view-containing-runtime-composite-fields/341586 "2023-09-12T06:23:13Z")

</div>

Kibana data views. Cool stuff and thank you for them! For some stupid reason I cannot figure out how to use "composite" fields in the runtime mapping. Consider the following simple example: { "data\_view": { "id"…

---

## [How to get metrics on telegraf endpoint](https://discuss.elastic.co/t/how-to-get-metrics-on-telegraf-endpoint/341092)

<div class="topic-metadata">

**Author:** [@A\_Mightiev](https://discuss.elastic.co/u/A_Mightiev)\
**Replies:** 1\
**Last updated:** [September 12, 2023, 6:04am UTC](https://discuss.elastic.co/t/how-to-get-metrics-on-telegraf-endpoint/341092 "2023-09-12T06:04:22Z")

</div>

Hi, I'm trying to use metricbeat to read from a server that has exposed host:9050/metrics, in one of the metrics looks like \[...\] # HELP mongodb\_active\_reads Telegraf collected metric # TYPE mongodb\_active\_reads untype…

---

## [Change text mapping from text to integer](https://discuss.elastic.co/t/change-text-mapping-from-text-to-integer/342484)

<div class="topic-metadata">

**Author:** [@Geeboy](https://discuss.elastic.co/u/Geeboy)\
**Replies:** 4\
**Last updated:** [September 12, 2023, 3:21am UTC](https://discuss.elastic.co/t/change-text-mapping-from-text-to-integer/342484 "2023-09-12T03:21:08Z")

</div>

Good day! Im creating new index, when I add this to "data views", it was tagged as TEXT type. I need it to be integer. do you have step by step guide for this case? my temporary solution is this command -\> emit (Intege…

---

## [File /run/elastic-agent.sock no such file and directory when i finished installing the agent on linux](https://discuss.elastic.co/t/file-run-elastic-agent-sock-no-such-file-and-directory-when-i-finished-installing-the-agent-on-linux/342775)

<div class="topic-metadata">

**Author:** [@Yanuar\_Ahmad\_Adhari](https://discuss.elastic.co/u/Yanuar_Ahmad_Adhari)\
**Replies:** 0\
**Last updated:** [September 12, 2023, 3:15am UTC](https://discuss.elastic.co/t/file-run-elastic-agent-sock-no-such-file-and-directory-when-i-finished-installing-the-agent-on-linux/342775 "2023-09-12T03:15:48Z")

</div>

Error: failed to communicate with Elastic Agent daemon: rpc error: code = Unavailable desc = connection error: desc = "transport: Error while dialing dial unix /run/elastic-agent.sock: connect: no such file or directory"…

---

## [Grok patterns for nginx](https://discuss.elastic.co/t/grok-patterns-for-nginx/342692)

<div class="topic-metadata">

**Author:** [@vanhaiit90](https://discuss.elastic.co/u/vanhaiit90)\
**Replies:** 1\
**Last updated:** [September 11, 2023, 3:24am UTC](https://discuss.elastic.co/t/grok-patterns-for-nginx/342692 "2023-09-11T03:24:40Z")

</div>

Today I have text log format about nginx\_access {"timestamp": "2023-09-07T03:03:33+00:00", "remote\_addr": "10.0.x.x", "remote\_user": "-", "request\_time": "0.002 s", "status\_request": "200", "request\_Size": "510", "requ…

---

## [GET api by doc\_id returns different result whenever i try](https://discuss.elastic.co/t/get-api-by-doc-id-returns-different-result-whenever-i-try/342293)

<div class="topic-metadata">

**Author:** [@ycice](https://discuss.elastic.co/u/ycice)\
**Replies:** 7\
**Last updated:** [September 12, 2023, 1:53am UTC](https://discuss.elastic.co/t/get-api-by-doc-id-returns-different-result-whenever-i-try/342293 "2023-09-12T01:53:49Z")

</div>

Hi, i manage more than 100 ES clusters in my company for 3 years But at last week, I faced very strange issue. I think it is not possible... Could you carefully check this? ES version : 6.8.2 Cluster health : Green G…

---

## [Alerting on Run Failures](https://discuss.elastic.co/t/alerting-on-run-failures/342623)

<div class="topic-metadata">

**Author:** [@Kris\_Felscher](https://discuss.elastic.co/u/Kris_Felscher)\
**Replies:** 1\
**Last updated:** [September 11, 2023, 11:46pm UTC](https://discuss.elastic.co/t/alerting-on-run-failures/342623 "2023-09-11T23:46:06Z")

</div>

We have a scheduled app that performs a nightly processing job across several different target "markets". I'm trying to figure out how to fire off an alert when a market fails to run. So, let's say I typically see the …

---

## [Custom URL not directing to correct ML job in Anomaly Explorer from email alert](https://discuss.elastic.co/t/custom-url-not-directing-to-correct-ml-job-in-anomaly-explorer-from-email-alert/342763)

<div class="topic-metadata">

**Author:** [@emi\_rose](https://discuss.elastic.co/u/emi_rose)\
**Replies:** 1\
**Last updated:** [September 11, 2023, 11:32pm UTC](https://discuss.elastic.co/t/custom-url-not-directing-to-correct-ml-job-in-anomaly-explorer-from-email-alert/342763 "2023-09-11T23:32:58Z")

</div>

Hello, I generated a few rules to alert on a severity threshold for different Anomaly Detection jobs. Whenever I click the url to open the job in anomaly explorer, it takes me to the same unrelated ML job. I'm using ({{…

---

## [How to build docker image from local clone copy of source](https://discuss.elastic.co/t/how-to-build-docker-image-from-local-clone-copy-of-source/342767)

<div class="topic-metadata">

**Author:** [@balakr](https://discuss.elastic.co/u/balakr)\
**Replies:** 0\
**Last updated:** [September 11, 2023, 9:57pm UTC](https://discuss.elastic.co/t/how-to-build-docker-image-from-local-clone-copy-of-source/342767 "2023-09-11T21:57:27Z")

</div>

i have an enlistment of logstash, would like to build a docker image, what is my command for this

---

## [How to build docker images for logstash, kibana, elastic](https://discuss.elastic.co/t/how-to-build-docker-images-for-logstash-kibana-elastic/342754)

<div class="topic-metadata">

**Author:** [@balakr](https://discuss.elastic.co/u/balakr)\
**Replies:** 3\
**Last updated:** [September 11, 2023, 9:00pm UTC](https://discuss.elastic.co/t/how-to-build-docker-images-for-logstash-kibana-elastic/342754 "2023-09-11T21:00:51Z")

</div>

i am trying to learn elastic, kibana, logstash. i have cloned source copies. what are the steps to build docker images, can someone point me to link/video which helps me in installing dependencies and build docker image

---

## [No logs from /var/containers/\* in kubernetes integration](https://discuss.elastic.co/t/no-logs-from-var-containers-in-kubernetes-integration/342671)

<div class="topic-metadata">

**Author:** [@georgi.hristov](https://discuss.elastic.co/u/georgi.hristov)\
**Replies:** 0\
**Last updated:** [September 10, 2023, 7:34am UTC](https://discuss.elastic.co/t/no-logs-from-var-containers-in-kubernetes-integration/342671 "2023-09-10T07:34:30Z")

</div>

Hello guys, I have been trying to setup ECK lately as a monitoring solution for our local K8s cluster. I have used the examples provided in the official documentation for Fleet-managed Elastic Agent on ECK with system …

---

## [Kind:Elasticsearch Kind:Kibana not creating any nodes in K8s why?](https://discuss.elastic.co/t/kind-elasticsearch-kind-kibana-not-creating-any-nodes-in-k8s-why/342758)

<div class="topic-metadata">

**Author:** [@Esakki](https://discuss.elastic.co/u/Esakki)\
**Replies:** 1\
**Last updated:** [September 11, 2023, 5:32pm UTC](https://discuss.elastic.co/t/kind-elasticsearch-kind-kibana-not-creating-any-nodes-in-k8s-why/342758 "2023-09-11T17:32:12Z")

</div>

Hi All, I had elasticsearch and kibana deployed in my on-prem K8s cluster, due to some config issue I deleted both deployments (I deployed, deployments, svc, and secrets) in my cluster and trying to re-deploy but it's n…

---

## [Confusion regarding elasticsearch enterprise search and app search](https://discuss.elastic.co/t/confusion-regarding-elasticsearch-enterprise-search-and-app-search/342744)

<div class="topic-metadata">

**Author:** [@elitzur\_e](https://discuss.elastic.co/u/elitzur_e)\
**Replies:** 1\
**Last updated:** [September 11, 2023, 3:11pm UTC](https://discuss.elastic.co/t/confusion-regarding-elasticsearch-enterprise-search-and-app-search/342744 "2023-09-11T15:11:07Z")

</div>

Hi. after playing around in elastic cloud. i would like to setup a real (enterprise grade) solution for a big site. in the instance i made there is a category "enterprise search" in that there is (among other things) El…

---

## [Netflow gigamon - Flowset id error](https://discuss.elastic.co/t/netflow-gigamon-flowset-id-error/342747)

<div class="topic-metadata">

**Author:** [@SilasMuniz1](https://discuss.elastic.co/u/SilasMuniz1)\
**Replies:** 0\
**Last updated:** [September 11, 2023, 2:40pm UTC](https://discuss.elastic.co/t/netflow-gigamon-flowset-id-error/342747 "2023-09-11T14:40:42Z")

</div>

Hi everybody. I still have a problem about neflow gigamon. I used netflow codec for parsing logs received from gigamon however I continuous received flowset error. My logstash is 8.4.3 version. Netflow codec versio…

---

## [Mongodb-connector not syncing data](https://discuss.elastic.co/t/mongodb-connector-not-syncing-data/342677)

<div class="topic-metadata">

**Author:** [@pulsy](https://discuss.elastic.co/u/pulsy)\
**Replies:** 3\
**Last updated:** [September 11, 2023, 2:37pm UTC](https://discuss.elastic.co/t/mongodb-connector-not-syncing-data/342677 "2023-09-11T14:37:07Z")

</div>

I'd like to try out the enterprise search functionality on my mocal machine using the enterprise search mongodb connector. I've managed to get everything running locally using docker compose, but when i start to sync col…

---

## [Failed to authenticate user 'elastic' against https://192.168.xx.xx:9200/\_security/\_authenticate?pretty](https://discuss.elastic.co/t/failed-to-authenticate-user-elastic-against-https-192-168-xx-xx-9200-security-authenticate-pretty/342654)

<div class="topic-metadata">

**Author:** [@uli67](https://discuss.elastic.co/u/uli67)\
**Replies:** 3\
**Last updated:** [September 11, 2023, 2:00pm UTC](https://discuss.elastic.co/t/failed-to-authenticate-user-elastic-against-https-192-168-xx-xx-9200-security-authenticate-pretty/342654 "2023-09-11T14:00:33Z")

</div>

Hi fellows, your help is needed. I have installed elasticsearch for the first time on my Alma-Linux9. That worked so far elastisearch runs on port 9200 tcp6 0 0 :::9200 :::\* …

---

## [Filebeat creating write disk i/o when filtering](https://discuss.elastic.co/t/filebeat-creating-write-disk-i-o-when-filtering/342540)

<div class="topic-metadata">

**Author:** [@rdang](https://discuss.elastic.co/u/rdang)\
**Replies:** 1\
**Last updated:** [September 11, 2023, 1:43pm UTC](https://discuss.elastic.co/t/filebeat-creating-write-disk-i-o-when-filtering/342540 "2023-09-11T13:43:32Z")

</div>

Hi folks, we are using filebeat 6.8 on Ubuntu 18.04.5 LTS with ESM. Filebeat is reading from mysql-audit.log thats configured to log CONNECT and QUERY events. Filebeat sends to a load balancer fronting logstash receiver…

---

## [Bootstrap.password for first installation with scripting](https://discuss.elastic.co/t/bootstrap-password-for-first-installation-with-scripting/342611)

<div class="topic-metadata">

**Author:** [@pepite](https://discuss.elastic.co/u/pepite)\
**Replies:** 5\
**Last updated:** [September 11, 2023, 1:32pm UTC](https://discuss.elastic.co/t/bootstrap-password-for-first-installation-with-scripting/342611 "2023-09-11T13:32:19Z")

</div>

Hi everybody, I need test for a script to change passwords of the built-in users. I test on a single-node cluster. I understand that i have to stop service on the node create bootstrap.password printf "tititi" …

---

## [Kibana :Invalid string. Length must be a multiple of 4](https://discuss.elastic.co/t/kibana-invalid-string-length-must-be-a-multiple-of-4/342685)

<div class="topic-metadata">

**Author:** [@Amani188](https://discuss.elastic.co/u/Amani188)\
**Replies:** 2\
**Last updated:** [September 11, 2023, 1:21pm UTC](https://discuss.elastic.co/t/kibana-invalid-string-length-must-be-a-multiple-of-4/342685 "2023-09-11T13:21:54Z")

</div>

Hi everyone, I'm trying to load data through kibana but i had this error message below : The response message shows internal server error

---

## [Determining number of clients to achieve target-throughput](https://discuss.elastic.co/t/determining-number-of-clients-to-achieve-target-throughput/342634)

<div class="topic-metadata">

**Author:** [@Dhineshkumar\_R](https://discuss.elastic.co/u/Dhineshkumar_R)\
**Replies:** 2\
**Last updated:** [September 11, 2023, 12:50pm UTC](https://discuss.elastic.co/t/determining-number-of-clients-to-achieve-target-throughput/342634 "2023-09-11T12:50:16Z")

</div>

Continuing the discussion from The number of clients in search operation: Hi Folks, I found this thread on relationship between number of clients and target throughput. @dliappis Can you help me understand how did yo…

[Previous page](https://discuss.elastic.co/latest.md?page=543)

[Next page](https://discuss.elastic.co/latest.md?page=545)
