# Latest

**URL:** https://discuss.elastic.co/latest.md?page=548

[Latest](https://discuss.elastic.co/latest.md) · [Categories](https://discuss.elastic.co/categories.md) · [Tags](https://discuss.elastic.co/tags.md)

**Page:** 549

---

## [Limited score precision for a big score hierarchy](https://discuss.elastic.co/t/limited-score-precision-for-a-big-score-hierarchy/340759)

<div class="topic-metadata">

**Author:** [@Grisha](https://discuss.elastic.co/u/Grisha)\
**Replies:** 14\
**Last updated:** [September 7, 2023, 3:02pm UTC](https://discuss.elastic.co/t/limited-score-precision-for-a-big-score-hierarchy/340759 "2023-09-07T15:02:20Z")

</div>

Hi, I'm trying to implement a kind of score hierarchy using different boosts for different fields (there are multiple fields and type of search (full match, fuzzy, etc.)). Simplified example of boosts: field\_1 fuzzy b…

---

## [JSON Parsing issue with elasticsearch ingest pipeline](https://discuss.elastic.co/t/json-parsing-issue-with-elasticsearch-ingest-pipeline/342519)

<div class="topic-metadata">

**Author:** [@Jobin\_James](https://discuss.elastic.co/u/Jobin_James)\
**Replies:** 4\
**Last updated:** [September 7, 2023, 1:51pm UTC](https://discuss.elastic.co/t/json-parsing-issue-with-elasticsearch-ingest-pipeline/342519 "2023-09-07T13:51:55Z")

</div>

Hello, I am building an Elasticsearch cluster to aggregate and monitor application logs. I am using ECK for deploying and managing the cluster in k8s and fleet-managed elastic agent deployed across multiple clusters to …

---

## [Question elk](https://discuss.elastic.co/t/question-elk/342529)

<div class="topic-metadata">

**Author:** [@Farah\_Bannour](https://discuss.elastic.co/u/Farah_Bannour)\
**Replies:** 0\
**Last updated:** [September 7, 2023, 1:49pm UTC](https://discuss.elastic.co/t/question-elk/342529 "2023-09-07T13:49:46Z")

</div>

Bonjour ,je voulais dans cette cas supprimer seulement la premier numero comme par exemple ici "create\_uid" : \[ 1, "Support" \], je voudrais supprimer 1 dans le champs create\_uid comment je peux faire ca

---

## [Watcher to send email alerts when Windows Defender detects malware](https://discuss.elastic.co/t/watcher-to-send-email-alerts-when-windows-defender-detects-malware/342528)

<div class="topic-metadata">

**Author:** [@RJC](https://discuss.elastic.co/u/RJC)\
**Replies:** 0\
**Last updated:** [September 7, 2023, 1:28pm UTC](https://discuss.elastic.co/t/watcher-to-send-email-alerts-when-windows-defender-detects-malware/342528 "2023-09-07T13:28:47Z")

</div>

I created a Watcher in Kibana to send email notification when malware is detected on one of the monitored hosts. Maleware detection event has a Windows Event Log ID 1116 and it is generated by Winlog channel "Microsoft-…

---

## [No Logs, Observability 2.1-2.3](https://discuss.elastic.co/t/no-logs-observability-2-1-2-3/342526)

<div class="topic-metadata">

**Author:** [@emmanine89](https://discuss.elastic.co/u/emmanine89)\
**Replies:** 0\
**Last updated:** [September 7, 2023, 1:20pm UTC](https://discuss.elastic.co/t/no-logs-observability-2-1-2-3/342526 "2023-09-07T13:20:20Z")

</div>

I've been working on labs 2.1-2.3 for a few hours now and no matter what I can't seem to get any logs coming through the elastic agent even after installing the nginx, mysql and docker integrations. The logs\* dataview re…

---

## [LABs logs not coming through](https://discuss.elastic.co/t/labs-logs-not-coming-through/342524)

<div class="topic-metadata">

**Author:** [@Renata](https://discuss.elastic.co/u/Renata)\
**Replies:** 0\
**Last updated:** [September 7, 2023, 12:39pm UTC](https://discuss.elastic.co/t/labs-logs-not-coming-through/342524 "2023-09-07T12:39:01Z")

</div>

Course: Elastic Observability Engineer (On-Demand) Version: 8.2 Question: Something not working properly with Logs for mysql (either sporadic, or not generated at all) Generally I am in 5.4. LABs section to test out a…

---

## [How does cluster.auto\_shrink\_voting\_configuration prevent split brain?](https://discuss.elastic.co/t/how-does-cluster-auto-shrink-voting-configuration-prevent-split-brain/342418)

<div class="topic-metadata">

**Author:** [@etki](https://discuss.elastic.co/u/etki)\
**Replies:** 9\
**Last updated:** [September 7, 2023, 11:31am UTC](https://discuss.elastic.co/t/how-does-cluster-auto-shrink-voting-configuration-prevent-split-brain/342418 "2023-09-07T11:31:15Z")

</div>

We have some docs telling that it's not possible, but they don't explain much, just stating some things. How is the following situation avoided? A cluster has voting configuration of 5 nodes. A network partition occurs…

---

## [Install Elastic Search](https://discuss.elastic.co/t/install-elastic-search/342320)

<div class="topic-metadata">

**Author:** [@Debasis\_Mallick](https://discuss.elastic.co/u/Debasis_Mallick)\
**Replies:** 14\
**Last updated:** [September 7, 2023, 11:39am UTC](https://discuss.elastic.co/t/install-elastic-search/342320 "2023-09-07T11:39:54Z")

</div>

Hi Team, I had a requirement to create elasticsearch cluster with three nodes . I had install the elasticsearch binaries on these three nodes individually and updated the elasticsearch.yml file with node information bu…

---

## [IP match failed](https://discuss.elastic.co/t/ip-match-failed/342475)

<div class="topic-metadata">

**Author:** [@javierelastic](https://discuss.elastic.co/u/javierelastic)\
**Replies:** 4\
**Last updated:** [September 7, 2023, 11:27am UTC](https://discuss.elastic.co/t/ip-match-failed/342475 "2023-09-07T11:27:38Z")

</div>

Hi everyone! Something strange happens to me. I'm trying to see if a source ip matches a pattern I indicate. The ip is 100.44.1.128 and it tells me that it matches "^10.\*" How is it possible? if \[IPorigen\] =~ "^10.\*"…

---

## [Hybrid Search aggregations count mismatch on filters](https://discuss.elastic.co/t/hybrid-search-aggregations-count-mismatch-on-filters/342496)

<div class="topic-metadata">

**Author:** [@Ramgopalbhat10](https://discuss.elastic.co/u/Ramgopalbhat10)\
**Replies:** 1\
**Last updated:** [September 7, 2023, 11:23am UTC](https://discuss.elastic.co/t/hybrid-search-aggregations-count-mismatch-on-filters/342496 "2023-09-07T11:23:27Z")

</div>

I want to use aggregations on the hybrid search (query + knn), which will give me some facets that I can select in the UI and use as filters for subsequent queries. I'm using num\_candidates=100 and k=20. I read in the d…

---

## [TraceId and TransactionId stop displaying in Console Appender after running Java application with -javaagent](https://discuss.elastic.co/t/traceid-and-transactionid-stop-displaying-in-console-appender-after-running-java-application-with-javaagent/341323)

<div class="topic-metadata">

**Author:** [@Rishi\_Maharaj](https://discuss.elastic.co/u/Rishi_Maharaj)\
**Replies:** 6\
**Last updated:** [September 7, 2023, 10:49am UTC](https://discuss.elastic.co/t/traceid-and-transactionid-stop-displaying-in-console-appender-after-running-java-application-with-javaagent/341323 "2023-09-07T10:49:01Z")

</div>

Version: 7.17 (per local docker-compose Quick start development environment | APM User Guide \[7.17\] | Elastic) Is there anything special in your setup? We were originally using the micrometer-tracing-brave-bridge and ex…

---

## [Winlogbeat "ignore\_older" rule not working](https://discuss.elastic.co/t/winlogbeat-ignore-older-rule-not-working/342454)

<div class="topic-metadata">

**Author:** [@cesq](https://discuss.elastic.co/u/cesq)\
**Replies:** 6\
**Last updated:** [September 7, 2023, 10:12am UTC](https://discuss.elastic.co/t/winlogbeat-ignore-older-rule-not-working/342454 "2023-09-07T10:12:12Z")

</div>

I've been deploying winlogbeat with graylog-sidecar and for some reason the "ignore\_older" option does not work for me. I am using the latest graylog-sidecar version as well as winlogbeat. In my configuration I have spe…

---

## [Export Teleport Audit Events to the Elastic Stack](https://discuss.elastic.co/t/export-teleport-audit-events-to-the-elastic-stack/340997)

<div class="topic-metadata">

**Author:** [@jana1](https://discuss.elastic.co/u/jana1)\
**Replies:** 1\
**Last updated:** [September 7, 2023, 10:02am UTC](https://discuss.elastic.co/t/export-teleport-audit-events-to-the-elastic-stack/340997 "2023-09-07T10:02:44Z")

</div>

i need help with Exporting Teleport Audit logs to the Elastic Stack - KIbana i am beginner on everything thats way i faced a problem in each step . i need help on explaining how to do all that the things that i did i…

---

## [Where are memories go?](https://discuss.elastic.co/t/where-are-memories-go/342338)

<div class="topic-metadata">

**Author:** [@huajun\_qi](https://discuss.elastic.co/u/huajun_qi)\
**Replies:** 3\
**Last updated:** [September 7, 2023, 9:42am UTC](https://discuss.elastic.co/t/where-are-memories-go/342338 "2023-09-07T09:42:44Z")

</div>

Our clients encountered errors below recently when performing index and query requests: org.elasticsearch.client.ResponseException: org.elasticsearch.client.ResponseException: method \[POST\], host \[http://192.168.12.171:…

---

## [Adding an app plugin inside a dashboard](https://discuss.elastic.co/t/adding-an-app-plugin-inside-a-dashboard/342515)

<div class="topic-metadata">

**Author:** [@Javier\_Mazario\_Picaz](https://discuss.elastic.co/u/Javier_Mazario_Picaz)\
**Replies:** 0\
**Last updated:** [September 7, 2023, 9:45am UTC](https://discuss.elastic.co/t/adding-an-app-plugin-inside-a-dashboard/342515 "2023-09-07T09:45:06Z")

</div>

I have generated an app Kibana plugin with the script generate\_plugin in Kibana 7.17 and I want to use my plugin in a dashboard. It is possible? I think I have to change the plugin.ts file but I don't know exactly how. …

---

## [Alternative grok with API](https://discuss.elastic.co/t/alternative-grok-with-api/342265)

<div class="topic-metadata">

**Author:** [@sam1975](https://discuss.elastic.co/u/sam1975)\
**Replies:** 3\
**Last updated:** [September 7, 2023, 9:11am UTC](https://discuss.elastic.co/t/alternative-grok-with-api/342265 "2023-09-07T09:11:30Z")

</div>

Hello, I've some pipeline which use grok to parse logs and apply some modifications. As i collect in input data from Elastic index, make some modifications and send it directly data transformed in an Elastic index, is …

---

## [Logstash 8.9.0](https://discuss.elastic.co/t/logstash-8-9-0/342362)

<div class="topic-metadata">

**Author:** [@ranjini](https://discuss.elastic.co/u/ranjini)\
**Replies:** 2\
**Last updated:** [September 7, 2023, 8:53am UTC](https://discuss.elastic.co/t/logstash-8-9-0/342362 "2023-09-07T08:53:59Z")

</div>

Please help me. I m running logstash 8.9.0. I recieve the below error in the pod logs. \[2023-09-05T16:25:32,904\]\[ERROR\]\[logstash.javapipeline \]\[main\]\[d9383b2c5e755b975c5f06446fd24ec66c0265c309ed53bd78ed6e05939579ec\] …

---

## [Count only sum value of ID on their last date](https://discuss.elastic.co/t/count-only-sum-value-of-id-on-their-last-date/342227)

<div class="topic-metadata">

**Author:** [@Guillaume\_V](https://discuss.elastic.co/u/Guillaume_V)\
**Replies:** 6\
**Last updated:** [September 7, 2023, 8:23am UTC](https://discuss.elastic.co/t/count-only-sum-value-of-id-on-their-last-date/342227 "2023-09-07T08:23:27Z")

</div>

Hi, I have a problem i would like to share you. This is my data And my table in Dashboard look like this : Level descending | Count 1 | 4 0 …

---

## [Cannot configure grok pipeline to processors in the elastic agent](https://discuss.elastic.co/t/cannot-configure-grok-pipeline-to-processors-in-the-elastic-agent/341933)

<div class="topic-metadata">

**Author:** [@vanhaiit90](https://discuss.elastic.co/u/vanhaiit90)\
**Replies:** 8\
**Last updated:** [September 7, 2023, 6:45am UTC](https://discuss.elastic.co/t/cannot-configure-grok-pipeline-to-processors-in-the-elastic-agent/341933 "2023-09-07T06:45:03Z")

</div>

Hi everyone! I completed and successful configure grok debuger log format of haproxy. And next I was added code grok pattens to pipeline Finally step I have added pipeline to processors in the elastic agent but …

---

## [Creating custom grok pattern](https://discuss.elastic.co/t/creating-custom-grok-pattern/342303)

<div class="topic-metadata">

**Author:** [@Cruz](https://discuss.elastic.co/u/Cruz)\
**Replies:** 4\
**Last updated:** [September 7, 2023, 6:30am UTC](https://discuss.elastic.co/t/creating-custom-grok-pattern/342303 "2023-09-07T06:30:00Z")

</div>

I was working with Logstash to structure the following types of logs: 2023-09-05 11:53:25 (152.32.73.6)-Logistics Request Approved: {"id":7355,"lr\_number":"LR-M006108","lr\_type":"2","lr\_type\_list":"1","lr\_type\_others":n…

---

## [Elasticsearch 8.9.2 and 7.17.13 Security Update](https://discuss.elastic.co/t/elasticsearch-8-9-2-and-7-17-13-security-update/342479)

<div class="topic-metadata">

**Author:** [@Levine](https://discuss.elastic.co/u/Levine)\
**Replies:** 0\
**Last updated:** [September 6, 2023, 10:30pm UTC](https://discuss.elastic.co/t/elasticsearch-8-9-2-and-7-17-13-security-update/342479 "2023-09-06T22:30:46Z")

</div>

Elasticsearch Insertion of sensitive information in audit logs (ESA-2023-12) Elasticsearch generally filters out sensitive information and credentials before logging to the audit log. It was found that this filtering was…

---

## [Logstash lumberjack output kept on using IP instead of hostname](https://discuss.elastic.co/t/logstash-lumberjack-output-kept-on-using-ip-instead-of-hostname/342493)

<div class="topic-metadata">

**Author:** [@mikhatanu](https://discuss.elastic.co/u/mikhatanu)\
**Replies:** 0\
**Last updated:** [September 7, 2023, 3:20am UTC](https://discuss.elastic.co/t/logstash-lumberjack-output-kept-on-using-ip-instead-of-hostname/342493 "2023-09-07T03:20:14Z")

</div>

Hello, i currently have a logstash in openshift exposed through openshift route with beats input. I tried to send some logs using powershell with logstash for windows: bin/logstash -e 'input { generator { count =\> 5 } }…

---

## [I want to get the total number of keyword hits for each document in the query results](https://discuss.elastic.co/t/i-want-to-get-the-total-number-of-keyword-hits-for-each-document-in-the-query-results/342490)

<div class="topic-metadata">

**Author:** [@z\_Henry](https://discuss.elastic.co/u/z_Henry)\
**Replies:** 0\
**Last updated:** [September 7, 2023, 2:12am UTC](https://discuss.elastic.co/t/i-want-to-get-the-total-number-of-keyword-hits-for-each-document-in-the-query-results/342490 "2023-09-07T02:12:11Z")

</div>

My field mapping settings are as follows "functionPoint": { "type": "text", "index": true, "analyzer": "ik\_smart", "search\_analyzer": "ik\_smart", "fielddata": true, "fielddata\_frequency\_filter": { "min":…

---

## [Please help me Install Elasticsearch in EC2](https://discuss.elastic.co/t/please-help-me-install-elasticsearch-in-ec2/342487)

<div class="topic-metadata">

**Author:** [@chobo](https://discuss.elastic.co/u/chobo)\
**Replies:** 0\
**Last updated:** [September 7, 2023, 1:26am UTC](https://discuss.elastic.co/t/please-help-me-install-elasticsearch-in-ec2/342487 "2023-09-07T01:26:51Z")

</div>

Hello I'm installing Elasticsearch in EC2 environment and setting elasticsearch.yml file, but I keep getting the following error fatal exception while booting Elasticsearch org.elasticsearch.transport.BindTransportExce…

---

## [Reset Kibana to blank state](https://discuss.elastic.co/t/reset-kibana-to-blank-state/342376)

<div class="topic-metadata">

**Author:** [@rsk0](https://discuss.elastic.co/u/rsk0)\
**Replies:** 2\
**Last updated:** [September 7, 2023, 1:32am UTC](https://discuss.elastic.co/t/reset-kibana-to-blank-state/342376 "2023-09-07T01:32:32Z")

</div>

On startup Kibana creates configuration in ES, and that config accumulates with web UI config changes, I believe. Is there a way to zero out the Kibana config to start fresh? Or do I have to find every change and delet…

---

## [Error creating rule via API](https://discuss.elastic.co/t/error-creating-rule-via-api/342381)

<div class="topic-metadata">

**Author:** [@Gabriel\_Camara](https://discuss.elastic.co/u/Gabriel_Camara)\
**Replies:** 2\
**Last updated:** [September 6, 2023, 11:45pm UTC](https://discuss.elastic.co/t/error-creating-rule-via-api/342381 "2023-09-06T23:45:00Z")

</div>

Hello, I'm trying to explain the example of creating a rule via API that is in the documentation, but I've been getting this error: {"statusCode":400,"error":"Bad Request","message":"Error creating rule: could not creat…

---

## [Does the Elasticsearch Ruby gem support both http and https hosts?](https://discuss.elastic.co/t/does-the-elasticsearch-ruby-gem-support-both-http-and-https-hosts/342477)

<div class="topic-metadata">

**Author:** [@ddzz](https://discuss.elastic.co/u/ddzz)\
**Replies:** 0\
**Last updated:** [September 6, 2023, 9:38pm UTC](https://discuss.elastic.co/t/does-the-elasticsearch-ruby-gem-support-both-http-and-https-hosts/342477 "2023-09-06T21:38:57Z")

</div>

I want to transition a cluster of ES nodes from HTTP to HTTPS. When the list of hosts I pass in to the ES client is either all http or https, it works fine. But when it's a mix I run into a variety of errors. Does the ge…

---

## [What is actually causing these shard snapshot failures?](https://discuss.elastic.co/t/what-is-actually-causing-these-shard-snapshot-failures/342203)

<div class="topic-metadata">

**Author:** [@Russell\_Fulton](https://discuss.elastic.co/u/Russell_Fulton)\
**Replies:** 7\
**Last updated:** [September 6, 2023, 9:35pm UTC](https://discuss.elastic.co/t/what-is-actually-causing-these-shard-snapshot-failures/342203 "2023-09-06T21:35:59Z")

</div>

And how do I fix them ; ) I have 7 shards failing with a message of the form: INTERNAL\_SERVER\_ERROR: NoSuchFileException\[/data/elasticsearch/backups/daily/indices/L0OEoJ\_DSqOk8aNpntkxqQ/0/index-MD1wjtsmTBuEPMY\_zenaaQ\] I…

---

## [PFsense integration not working](https://discuss.elastic.co/t/pfsense-integration-not-working/342388)

<div class="topic-metadata">

**Author:** [@Rob\_wylde](https://discuss.elastic.co/u/Rob_wylde)\
**Replies:** 2\
**Last updated:** [September 6, 2023, 8:30pm UTC](https://discuss.elastic.co/t/pfsense-integration-not-working/342388 "2023-09-06T20:30:11Z")

</div>

I have configured pfsense to send UDP logs to a Linux host with the pfense integration added to the policy. I have confirmed that pfsense is sending logs to the desired destination via nc -ul 9001, and I can see the plai…

---

## [Detecting specific event sequences in data streams](https://discuss.elastic.co/t/detecting-specific-event-sequences-in-data-streams/342469)

<div class="topic-metadata">

**Author:** [@Kargo](https://discuss.elastic.co/u/Kargo)\
**Replies:** 0\
**Last updated:** [September 6, 2023, 7:40pm UTC](https://discuss.elastic.co/t/detecting-specific-event-sequences-in-data-streams/342469 "2023-09-06T19:40:14Z")

</div>

Hey there. I have a datastream in Elasticsearch with mappings similar to this: { "mappings": { "properties": { "@timestamp": {"type": "date"}, "event-type": {"type": "keyword"}, "session": {"…

[Previous page](https://discuss.elastic.co/latest.md?page=547)

[Next page](https://discuss.elastic.co/latest.md?page=549)
