# Latest

**URL:** https://discuss.elastic.co/latest.md?page=557

[Latest](https://discuss.elastic.co/latest.md) · [Categories](https://discuss.elastic.co/categories.md) · [Tags](https://discuss.elastic.co/tags.md)

**Page:** 558

---

## [Field with type date when added in table visualization in kibana gets stuck](https://discuss.elastic.co/t/field-with-type-date-when-added-in-table-visualization-in-kibana-gets-stuck/341940)

<div class="topic-metadata">

**Author:** [@Neelam\_Zanvar](https://discuss.elastic.co/u/Neelam_Zanvar)\
**Replies:** 2\
**Last updated:** [August 30, 2023, 7:29am UTC](https://discuss.elastic.co/t/field-with-type-date-when-added-in-table-visualization-in-kibana-gets-stuck/341940 "2023-08-30T07:29:01Z")

</div>

Hi, I have a field short\_date which is of type date. I want to display details with respect to tiime in the table. But every single time i add the short date row in the table kibana gets stuck up. the entire VM hangs for…

---

## [Watcher Alert based on Status down for tomcat and not trigger based on time interval](https://discuss.elastic.co/t/watcher-alert-based-on-status-down-for-tomcat-and-not-trigger-based-on-time-interval/341944)

<div class="topic-metadata">

**Author:** [@PRASHANT\_MEHTA](https://discuss.elastic.co/u/PRASHANT_MEHTA)\
**Replies:** 0\
**Last updated:** [August 30, 2023, 7:16am UTC](https://discuss.elastic.co/t/watcher-alert-based-on-status-down-for-tomcat-and-not-trigger-based-on-time-interval/341944 "2023-08-30T07:16:03Z")

</div>

Hello All, I have a requirement where in watcher should trigger on the basis of status down and not based on time interval settings. Below is my working watcher script that triggers every 15 min or 8hrs accordingly se…

---

## [Elasticsearch node down after run kibana in same host ubuntu](https://discuss.elastic.co/t/elasticsearch-node-down-after-run-kibana-in-same-host-ubuntu/341767)

<div class="topic-metadata">

**Author:** [@phu\_phat](https://discuss.elastic.co/u/phu_phat)\
**Replies:** 4\
**Last updated:** [August 30, 2023, 6:25am UTC](https://discuss.elastic.co/t/elasticsearch-node-down-after-run-kibana-in-same-host-ubuntu/341767 "2023-08-30T06:25:57Z")

</div>

After upgrade elasticsearch and kibana from 6.x to 8.9 when start kibana my elasticsearch node in that host down but if i change config kibana to not connect with elasticsearch cluster, elasticsearch can run normally \[…

---

## [Elasticsearch java API client trackTotalHits](https://discuss.elastic.co/t/elasticsearch-java-api-client-tracktotalhits/341935)

<div class="topic-metadata">

**Author:** [@hld942614](https://discuss.elastic.co/u/hld942614)\
**Replies:** 2\
**Last updated:** [August 30, 2023, 5:46am UTC](https://discuss.elastic.co/t/elasticsearch-java-api-client-tracktotalhits/341935 "2023-08-30T05:46:06Z")

</div>

I am trying to search my data and expect to get all data，but I can't get more than 10000 result，so I try to use trackTotalHits ，can someone tell me how to use it? try { ElasticsearchClient client = elasticsearchConfi…

---

## [Failed to start crawler: creating module reloader failed in filebeat](https://discuss.elastic.co/t/failed-to-start-crawler-creating-module-reloader-failed-in-filebeat/341922)

<div class="topic-metadata">

**Author:** [@SOMU\_REDDY](https://discuss.elastic.co/u/SOMU_REDDY)\
**Replies:** 1\
**Last updated:** [August 30, 2023, 4:23am UTC](https://discuss.elastic.co/t/failed-to-start-crawler-creating-module-reloader-failed-in-filebeat/341922 "2023-08-30T04:23:46Z")

</div>

getting this error while trying to send logs to Elasticsearch using this ./filebeat -c filebeat.yml -e getting this message":"Exiting: Failed to start crawler: creating module reloader failed: loading configs: 1 error: i…

---

## [Using ECK, Elastic search does not start up after enabling SAML](https://discuss.elastic.co/t/using-eck-elastic-search-does-not-start-up-after-enabling-saml/341864)

<div class="topic-metadata">

**Author:** [@johanw](https://discuss.elastic.co/u/johanw)\
**Replies:** 2\
**Last updated:** [August 30, 2023, 3:17am UTC](https://discuss.elastic.co/t/using-eck-elastic-search-does-not-start-up-after-enabling-saml/341864 "2023-08-30T03:17:03Z")

</div>

We are trying to enable SAML on our ELK stack on Kubernetes. We are using ECK and custom resource definitions to manage and run our Elastic cluster. Instructions followed: Set up SAML with Azure Active Directory | Elast…

---

## [Elastic-agent is triggering HTTP 413 (entity too large) errors](https://discuss.elastic.co/t/elastic-agent-is-triggering-http-413-entity-too-large-errors/341932)

<div class="topic-metadata">

**Author:** [@Craig\_Rodrigues](https://discuss.elastic.co/u/Craig_Rodrigues)\
**Replies:** 0\
**Last updated:** [August 30, 2023, 12:42am UTC](https://discuss.elastic.co/t/elastic-agent-is-triggering-http-413-entity-too-large-errors/341932 "2023-08-30T00:42:49Z")

</div>

I have an elastic agent: elastic-agent version Binary: 8.9.0 (build: dc443bc2427920a26141b05f9c07a52191881af5 at 2023-07-19 20:55:16 +0000 UTC) Daemon: 8.9.0 (build: dc443bc2427920a26141b05f9c07a52191881af5 at 2023-07-…

---

## [Certification exams: Elastic Docs allowed but no other notes, but Elastic Docs very limited](https://discuss.elastic.co/t/certification-exams-elastic-docs-allowed-but-no-other-notes-but-elastic-docs-very-limited/341928)

<div class="topic-metadata">

**Author:** [@pezhed](https://discuss.elastic.co/u/pezhed)\
**Replies:** 1\
**Last updated:** [August 30, 2023, 12:18am UTC](https://discuss.elastic.co/t/certification-exams-elastic-docs-allowed-but-no-other-notes-but-elastic-docs-very-limited/341928 "2023-08-30T00:18:39Z")

</div>

I am studying for the Elasticsearch Engineer certification exam after completing the On-Demand training course. I took copious notes documenting every step of the way for every topic. However, it looks like I can't use…

---

## [Beats vs multiple outputs while transisting to a new elastic cluster](https://discuss.elastic.co/t/beats-vs-multiple-outputs-while-transisting-to-a-new-elastic-cluster/341799)

<div class="topic-metadata">

**Author:** [@stefws](https://discuss.elastic.co/u/stefws)\
**Replies:** 2\
**Last updated:** [August 29, 2023, 9:56pm UTC](https://discuss.elastic.co/t/beats-vs-multiple-outputs-while-transisting-to-a-new-elastic-cluster/341799 "2023-08-29T21:56:42Z")

</div>

Running a PoC with filebeat + metricbeat agents on a number of endpoints sending data through ingest nodes running various pipelines on the filebeat events. While preparing move to a new elastic cluster, we would like t…

---

## [Logstash Output to Kibana with SSL?](https://discuss.elastic.co/t/logstash-output-to-kibana-with-ssl/341905)

<div class="topic-metadata">

**Author:** [@paolovalladolid](https://discuss.elastic.co/u/paolovalladolid)\
**Replies:** 12\
**Last updated:** [August 29, 2023, 9:45pm UTC](https://discuss.elastic.co/t/logstash-output-to-kibana-with-ssl/341905 "2023-08-29T21:45:43Z")

</div>

I am new to Logstash, having previous experience with Filebeat and Winlogbeat. In the Filebeat/Winlogbeat configuration we have separate output sections for Elasticsearch and Kibana. We configure the Kibana output sect…

---

## [Cisco ISE - associate with this object no longer exists in the index pattern. please use another field](https://discuss.elastic.co/t/cisco-ise-associate-with-this-object-no-longer-exists-in-the-index-pattern-please-use-another-field/341924)

<div class="topic-metadata">

**Author:** [@sebast.ssoto](https://discuss.elastic.co/u/sebast.ssoto)\
**Replies:** 0\
**Last updated:** [August 29, 2023, 8:57pm UTC](https://discuss.elastic.co/t/cisco-ise-associate-with-this-object-no-longer-exists-in-the-index-pattern-please-use-another-field/341924 "2023-08-29T20:57:02Z")

</div>

was found in a Cisco ISE dashboard which leaves the following error Someone knows why the complete syntax of the error detected is:

---

## [Deploy python connector with docker ca\_cert parameter is not a path (run locally)](https://discuss.elastic.co/t/deploy-python-connector-with-docker-ca-cert-parameter-is-not-a-path-run-locally/340642)

<div class="topic-metadata">

**Author:** [@sk30613](https://discuss.elastic.co/u/sk30613)\
**Replies:** 1\
**Last updated:** [August 29, 2023, 5:58pm UTC](https://discuss.elastic.co/t/deploy-python-connector-with-docker-ca-cert-parameter-is-not-a-path-run-locally/340642 "2023-08-29T17:58:45Z")

</div>

Hi, I have an error during the run of docker image (run connector service in docker). I have been following the instructions from https://github.com/elastic/connectors-python/blob/main/docs/DOCKER.md (steps: 1-5). Plea…

---

## [How to get Average of 2 timestamp in Kibana metric visualization](https://discuss.elastic.co/t/how-to-get-average-of-2-timestamp-in-kibana-metric-visualization/340616)

<div class="topic-metadata">

**Author:** [@yash\_mangla](https://discuss.elastic.co/u/yash_mangla)\
**Replies:** 1\
**Last updated:** [August 29, 2023, 5:26pm UTC](https://discuss.elastic.co/t/how-to-get-average-of-2-timestamp-in-kibana-metric-visualization/340616 "2023-08-29T17:26:21Z")

</div>

Hi Team, I want to create a metric visualization with average difference showing for entire records. and every record is having multiple timestamp. So, we want to show average difference between start\_time and acknoele…

---

## [URL shortening services monitoring via ELK](https://discuss.elastic.co/t/url-shortening-services-monitoring-via-elk/341911)

<div class="topic-metadata">

**Author:** [@Ragul\_venkatasubban](https://discuss.elastic.co/u/Ragul_venkatasubban)\
**Replies:** 0\
**Last updated:** [August 29, 2023, 4:05pm UTC](https://discuss.elastic.co/t/url-shortening-services-monitoring-via-elk/341911 "2023-08-29T16:05:42Z")

</div>

Hey, I have integrated firewall logs in ELK. I came across some logs which are of URL shorteners eg., bit\[.\]ly, etc.. the interesting part is when a user clicks on these kinds of URLs we won't know the original URL and …

---

## [Creating an Elasticsearch resource in Minikube multi-node cluster fails](https://discuss.elastic.co/t/creating-an-elasticsearch-resource-in-minikube-multi-node-cluster-fails/340184)

<div class="topic-metadata">

**Author:** [@wh1te\_rabb1t](https://discuss.elastic.co/u/wh1te_rabb1t)\
**Replies:** 1\
**Last updated:** [August 29, 2023, 3:52pm UTC](https://discuss.elastic.co/t/creating-an-elasticsearch-resource-in-minikube-multi-node-cluster-fails/340184 "2023-08-29T15:52:10Z")

</div>

What did you do? Created an Elasticsearch resource on a multi-node Minikube cluster: $ minikube start -n 4 --cni=calico $ apply -f https://download.elastic.co/downloads/eck/2.9.0/crds.yaml $ apply -f https://download.e…

---

## [Building a Basic Query That Orders Results](https://discuss.elastic.co/t/building-a-basic-query-that-orders-results/341906)

<div class="topic-metadata">

**Author:** [@kocakserdar](https://discuss.elastic.co/u/kocakserdar)\
**Replies:** 0\
**Last updated:** [August 29, 2023, 3:37pm UTC](https://discuss.elastic.co/t/building-a-basic-query-that-orders-results/341906 "2023-08-29T15:37:50Z")

</div>

Hello, As a newbie, I'm trying to build a compound query for my NodeJS/Express web app. All I need is to give priority to phrases first in the search results if they exist... For example let's search for "customers are"…

---

## [Line graph in 5 min interval showing previous values](https://discuss.elastic.co/t/line-graph-in-5-min-interval-showing-previous-values/341868)

<div class="topic-metadata">

**Author:** [@Saili\_Bakalkar](https://discuss.elastic.co/u/Saili_Bakalkar)\
**Replies:** 7\
**Last updated:** [August 29, 2023, 3:30pm UTC](https://discuss.elastic.co/t/line-graph-in-5-min-interval-showing-previous-values/341868 "2023-08-29T15:30:17Z")

</div>

Value Time 6.55 2023-08-24 18:08:00 6.49 2023-08-24 18:11:40 6.50 2023-08-24 18:13:30 I have a line graph of value vs time with minimum interval set to 5m I want to create a 5 min window of this data so when when the…

---

## [\[Elasticsearch Client .Net\] need help Create Index mapping Nested field type](https://discuss.elastic.co/t/elasticsearch-client-net-need-help-create-index-mapping-nested-field-type/341786)

<div class="topic-metadata">

**Author:** [@Steven\_Vo](https://discuss.elastic.co/u/Steven_Vo)\
**Replies:** 1\
**Last updated:** [August 29, 2023, 3:10pm UTC](https://discuss.elastic.co/t/elasticsearch-client-net-need-help-create-index-mapping-nested-field-type/341786 "2023-08-29T15:10:13Z")

</div>

public class EsProductEto { public Guid Id { get; set; } ..... public List\<EsAttributeEto\> Items { get; set; } } ----- public class EsAttributeEto { public Guid Id { get; set; …

---

## [Semantic search with search correlation between fields](https://discuss.elastic.co/t/semantic-search-with-search-correlation-between-fields/341564)

<div class="topic-metadata">

**Author:** [@sivagurlinka](https://discuss.elastic.co/u/sivagurlinka)\
**Replies:** 4\
**Last updated:** [August 29, 2023, 2:49pm UTC](https://discuss.elastic.co/t/semantic-search-with-search-correlation-between-fields/341564 "2023-08-29T14:49:14Z")

</div>

Can semantic search with correlation between fields can be implemented with Elasticsearch ? I have ecommerce data indexed to Elasticsearch with below fields and description is vector text embedded. Name : product name(…

---

## [Elastic search order of the highlighted fields not matching with the ranking](https://discuss.elastic.co/t/elastic-search-order-of-the-highlighted-fields-not-matching-with-the-ranking/341889)

<div class="topic-metadata">

**Author:** [@Vikram\_Jadhav](https://discuss.elastic.co/u/Vikram_Jadhav)\
**Replies:** 0\
**Last updated:** [August 29, 2023, 2:19pm UTC](https://discuss.elastic.co/t/elastic-search-order-of-the-highlighted-fields-not-matching-with-the-ranking/341889 "2023-08-29T14:19:23Z")

</div>

Hello, In the below document, I am trying to match multiple fields and I also want to know what fields are getting matched from the document that's why used the highlighted fields. sample doc: { "therapeutic\_area": "…

---

## [How to compare document fields in a elasticsearch query](https://discuss.elastic.co/t/how-to-compare-document-fields-in-a-elasticsearch-query/341814)

<div class="topic-metadata">

**Author:** [@juanmgarciaf](https://discuss.elastic.co/u/juanmgarciaf)\
**Replies:** 1\
**Last updated:** [August 29, 2023, 2:17pm UTC](https://discuss.elastic.co/t/how-to-compare-document-fields-in-a-elasticsearch-query/341814 "2023-08-29T14:17:06Z")

</div>

Hello! I have an index with a lot of documents and I need to group these documents by an specific field and after this I need to compare if the two last documents (with the most recent timestamp) from each group have a s…

---

## [Hi elasticsearch resthighlevelclient SocketTimeOutException issue](https://discuss.elastic.co/t/hi-elasticsearch-resthighlevelclient-sockettimeoutexception-issue/341885)

<div class="topic-metadata">

**Author:** [@slowup](https://discuss.elastic.co/u/slowup)\
**Replies:** 0\
**Last updated:** [August 29, 2023, 1:59pm UTC](https://discuss.elastic.co/t/hi-elasticsearch-resthighlevelclient-sockettimeoutexception-issue/341885 "2023-08-29T13:59:19Z")

</div>

As the title says, I'm currently facing a SocketTimeoutException. There are almost no servers and it happens even expected (about 2 per traffic?) So I think it's a client problem, not a server performance problem. It …

---

## [Preferred proxy for fleet](https://discuss.elastic.co/t/preferred-proxy-for-fleet/341884)

<div class="topic-metadata">

**Author:** [@Atul\_Chadha](https://discuss.elastic.co/u/Atul_Chadha)\
**Replies:** 0\
**Last updated:** [August 29, 2023, 1:55pm UTC](https://discuss.elastic.co/t/preferred-proxy-for-fleet/341884 "2023-08-29T13:55:13Z")

</div>

Is there a preferred proxy software recommended for fleet setup on elasticsearch 8.9 self hosted setup. I am dicey between squid and nginx.

---

## [No\_shard\_available\_action\_exception](https://discuss.elastic.co/t/no-shard-available-action-exception/341883)

<div class="topic-metadata">

**Author:** [@Nibort](https://discuss.elastic.co/u/Nibort)\
**Replies:** 0\
**Last updated:** [August 29, 2023, 1:25pm UTC](https://discuss.elastic.co/t/no-shard-available-action-exception/341883 "2023-08-29T13:25:32Z")

</div>

Hello, I'm trying to send rsyslog with filebeat to my Elasticsearch cluster I've added the global path where logs are stored (/var/log/\*.log) filebeat.yml filebeat.inputs: - type: log id: rsyslog paths: - /va…

---

## [How to do float comparison](https://discuss.elastic.co/t/how-to-do-float-comparison/341881)

<div class="topic-metadata">

**Author:** [@lostsoul352](https://discuss.elastic.co/u/lostsoul352)\
**Replies:** 3\
**Last updated:** [August 29, 2023, 1:16pm UTC](https://discuss.elastic.co/t/how-to-do-float-comparison/341881 "2023-08-29T13:16:29Z")

</div>

I'm trying to drop events if the value of a float field is less than -90000 Here is a code snippet: if \[type\] == "node\_perf" { mutate { convert =\> { "nodeperf\_value" =\> "float"} …

---

## [Aggregate filter plugin - final event contains empty message](https://discuss.elastic.co/t/aggregate-filter-plugin-final-event-contains-empty-message/339702)

<div class="topic-metadata">

**Author:** [@Anca\_Linca](https://discuss.elastic.co/u/Anca_Linca)\
**Replies:** 8\
**Last updated:** [August 29, 2023, 1:02pm UTC](https://discuss.elastic.co/t/aggregate-filter-plugin-final-event-contains-empty-message/339702 "2023-08-29T13:02:03Z")

</div>

Hello, Logstash version: 7.17 Aggregate filter plugin: v2.10.0 Contents for /var/log/logstash/input.log: {"timestamp": "2023-07-31T15:10:45.141Z", "parentOnly": 1, "logger\_name": "activity\_stream", "job": 102693, "ty…

---

## [Querying on large docs](https://discuss.elastic.co/t/querying-on-large-docs/341759)

<div class="topic-metadata">

**Author:** [@m4kkur0](https://discuss.elastic.co/u/m4kkur0)\
**Replies:** 4\
**Last updated:** [August 29, 2023, 12:53pm UTC](https://discuss.elastic.co/t/querying-on-large-docs/341759 "2023-08-29T12:53:15Z")

</div>

Hello all, I would like to know what are some good options to query an index that each doc in it structured like: field1, keyword field2, long field3, object, enabled: false (mostly below 1 mb but sometimes goes up t…

---

## [When to use SLO and when normal alerts in kibana?](https://discuss.elastic.co/t/when-to-use-slo-and-when-normal-alerts-in-kibana/341772)

<div class="topic-metadata">

**Author:** [@Navya1](https://discuss.elastic.co/u/Navya1)\
**Replies:** 1\
**Last updated:** [August 29, 2023, 11:02am UTC](https://discuss.elastic.co/t/when-to-use-slo-and-when-normal-alerts-in-kibana/341772 "2023-08-29T11:02:33Z")

</div>

Hello All, I have a questions on SLO when compared to normal alert setup in kibana. What is the difference ? Which option has to choose ? When to choose SLO and when to use normal alerts ? Please advise. Thanks, Navy…

---

## [Can Logstash support jvm security policy to restrict ruby exec policy](https://discuss.elastic.co/t/can-logstash-support-jvm-security-policy-to-restrict-ruby-exec-policy/341871)

<div class="topic-metadata">

**Author:** [@weizijun](https://discuss.elastic.co/u/weizijun)\
**Replies:** 0\
**Last updated:** [August 29, 2023, 9:35am UTC](https://discuss.elastic.co/t/can-logstash-support-jvm-security-policy-to-restrict-ruby-exec-policy/341871 "2023-08-29T09:35:44Z")

</div>

Since elasticsearch can configure security policies, can logstash do the same?

---

## [Logstash index is not having the autosuggestions](https://discuss.elastic.co/t/logstash-index-is-not-having-the-autosuggestions/341866)

<div class="topic-metadata">

**Author:** [@uma\_parvathy](https://discuss.elastic.co/u/uma_parvathy)\
**Replies:** 0\
**Last updated:** [August 29, 2023, 8:26am UTC](https://discuss.elastic.co/t/logstash-index-is-not-having-the-autosuggestions/341866 "2023-08-29T08:26:45Z")

</div>

i've been trying to populate the data from postgresql db to elasticsearch7.17 using logstash. The data is imported but it's missing the autosuggestions and fuzzy logic suggestions which is needed to query from django ap…

[Previous page](https://discuss.elastic.co/latest.md?page=556)

[Next page](https://discuss.elastic.co/latest.md?page=558)
