# Latest

**URL:** https://discuss.elastic.co/latest.md?page=558

[Latest](https://discuss.elastic.co/latest.md) · [Categories](https://discuss.elastic.co/categories.md) · [Tags](https://discuss.elastic.co/tags.md)

**Page:** 559

---

## [Aggregrating data from Nested Fields](https://discuss.elastic.co/t/aggregrating-data-from-nested-fields/341845)

<div class="topic-metadata">

**Author:** [@Kumar\_Abhinav](https://discuss.elastic.co/u/Kumar_Abhinav)\
**Replies:** 1\
**Last updated:** [August 29, 2023, 8:15am UTC](https://discuss.elastic.co/t/aggregrating-data-from-nested-fields/341845 "2023-08-29T08:15:37Z")

</div>

I am currently navigating Elasticsearch and Kibana version 8.7.1 and have encountered a challenge The Challenge: Aggregating Nested Fields My primary goal is to efficiently aggregate data residing within nested fields …

---

## [Elastic Cloud managed on Azure: how to set nodes and replicas?](https://discuss.elastic.co/t/elastic-cloud-managed-on-azure-how-to-set-nodes-and-replicas/341863)

<div class="topic-metadata">

**Author:** [@MarGraz](https://discuss.elastic.co/u/MarGraz)\
**Replies:** 0\
**Last updated:** [August 29, 2023, 8:05am UTC](https://discuss.elastic.co/t/elastic-cloud-managed-on-azure-how-to-set-nodes-and-replicas/341863 "2023-08-29T08:05:57Z")

</div>

Hi, I'm new in using Elastic Cloud managed by Azure and I searched a lot on the web without finding a clear explanation. I didn't understand how to set and manage nodes and replicas using Elastic Cloud managed by Azure. …

---

## [Plot 2 line with different filter on the same canvas](https://discuss.elastic.co/t/plot-2-line-with-different-filter-on-the-same-canvas/341698)

<div class="topic-metadata">

**Author:** [@fdevoto](https://discuss.elastic.co/u/fdevoto)\
**Replies:** 4\
**Last updated:** [August 29, 2023, 7:45am UTC](https://discuss.elastic.co/t/plot-2-line-with-different-filter-on-the-same-canvas/341698 "2023-08-29T07:45:32Z")

</div>

Hello, I am really newbie in Elastic/Kibana etc sorry if my teminology is not correct. I am trying to create a line plot with two lines, each line has a different filter. I can create the 2 plots separately, but I don…

---

## [Aggregate filter の timeout\_timestamp\_field設定時の動作について （続き）](https://discuss.elastic.co/t/aggregate-filter-timeout-timestamp-field/341858)

<div class="topic-metadata">

**Author:** [@e-se](https://discuss.elastic.co/u/e-se)\
**Replies:** 0\
**Last updated:** [August 29, 2023, 7:18am UTC](https://discuss.elastic.co/t/aggregate-filter-timeout-timestamp-field/341858 "2023-08-29T07:18:38Z")

</div>

Continuing the discussion from Aggregate filter の timeout\_timestamp\_field設定時の動作について: 2 行目は 2 番目の集計フィルターを通過しますが、タイムアウト オプションが設定されていないため、タイムアウト処理は行われません。 とありますが、システム時間でタイムアウトを計測する場合、フィルターを通過するかどうかに関係なく、timeoutオプションに設定し…

---

## [How to get in C# client not-null response even for failed search requests?](https://discuss.elastic.co/t/how-to-get-in-c-client-not-null-response-even-for-failed-search-requests/341358)

<div class="topic-metadata">

**Author:** [@Leonid\_P](https://discuss.elastic.co/u/Leonid_P)\
**Replies:** 2\
**Last updated:** [August 29, 2023, 7:15am UTC](https://discuss.elastic.co/t/how-to-get-in-c-client-not-null-response-even-for-failed-search-requests/341358 "2023-08-29T07:15:17Z")

</div>

Hi there! There is C# code that generates searches through code like that: searchResult = client.Search(descriptor); The request generated contains inappropriate data, and therefore I get Elasticsearch.Net.Elasticsea…

---

## [Remove old 7.x Kibana indices after upgrade to 8.9](https://discuss.elastic.co/t/remove-old-7-x-kibana-indices-after-upgrade-to-8-9/341212)

<div class="topic-metadata">

**Author:** [@chouben](https://discuss.elastic.co/u/chouben)\
**Replies:** 2\
**Last updated:** [August 29, 2023, 6:36am UTC](https://discuss.elastic.co/t/remove-old-7-x-kibana-indices-after-upgrade-to-8-9/341212 "2023-08-29T06:36:27Z")

</div>

Hi I posted my question in "elasticsearch" channel first. I didn't get a response yet, nor did I find a way to move it over here: Original post: https://discuss.elastic.co/t/remove-7-x-indices-after-upgrade-to-8-x I w…

---

## [Can I configure elastic agent to have logs indexed by elastic search?](https://discuss.elastic.co/t/can-i-configure-elastic-agent-to-have-logs-indexed-by-elastic-search/341856)

<div class="topic-metadata">

**Author:** [@Ong\_Yi\_Chong](https://discuss.elastic.co/u/Ong_Yi_Chong)\
**Replies:** 0\
**Last updated:** [August 29, 2023, 6:35am UTC](https://discuss.elastic.co/t/can-i-configure-elastic-agent-to-have-logs-indexed-by-elastic-search/341856 "2023-08-29T06:35:24Z")

</div>

Hi, I have just started learning about elastic stack one day ago. I have managed to add an elastic agent apm integration to a sample node JS server and I am able to view the log outputs on Observability \> Logs section. …

---

## [Remove 7.x indices after upgrade to 8.x](https://discuss.elastic.co/t/remove-7-x-indices-after-upgrade-to-8-x/341000)

<div class="topic-metadata">

**Author:** [@chouben](https://discuss.elastic.co/u/chouben)\
**Replies:** 6\
**Last updated:** [August 29, 2023, 6:34am UTC](https://discuss.elastic.co/t/remove-7-x-indices-after-upgrade-to-8-x/341000 "2023-08-29T06:34:57Z")

</div>

Hi I was wondering if we could remove the old 7.x indices from our Elastic Stack, since we upgraded to 8.x? E.g. Kibana: Remark: I found out about the allow\_restricted\_indices setting, which would probably allow me…

---

## [Problem create Engine - Enterprise Search encountered an error. Check Kibana Server logs for details](https://discuss.elastic.co/t/problem-create-engine-enterprise-search-encountered-an-error-check-kibana-server-logs-for-details/341835)

<div class="topic-metadata">

**Author:** [@PustyB](https://discuss.elastic.co/u/PustyB)\
**Replies:** 4\
**Last updated:** [August 29, 2023, 6:27am UTC](https://discuss.elastic.co/t/problem-create-engine-enterprise-search-encountered-an-error-check-kibana-server-logs-for-details/341835 "2023-08-29T06:27:40Z")

</div>

Hi. I have a problem with creating an engine. When creating a new index-based engine, this problem pops up: Enterprise Search encountered an error. Check Kibana Server logs for details. In the kibana logs I find someth…

---

## [Uptime showing no uptime moniters but I do see heartbeat info in discovery tab](https://discuss.elastic.co/t/uptime-showing-no-uptime-moniters-but-i-do-see-heartbeat-info-in-discovery-tab/341781)

<div class="topic-metadata">

**Author:** [@LiRi\_Elgozi](https://discuss.elastic.co/u/LiRi_Elgozi)\
**Replies:** 4\
**Last updated:** [August 29, 2023, 6:10am UTC](https://discuss.elastic.co/t/uptime-showing-no-uptime-moniters-but-i-do-see-heartbeat-info-in-discovery-tab/341781 "2023-08-29T06:10:56Z")

</div>

I recently installed elasticsearch / kibana / hearbeat 8.9.1 (each on a separate server) created automated terraform and ansible to do that. I configured heartbeat and was able to see the information for one day in the…

---

## [How to store/compress large string field in index (V6.8)](https://discuss.elastic.co/t/how-to-store-compress-large-string-field-in-index-v6-8/341777)

<div class="topic-metadata">

**Author:** [@elron](https://discuss.elastic.co/u/elron)\
**Replies:** 1\
**Last updated:** [August 29, 2023, 6:08am UTC](https://discuss.elastic.co/t/how-to-store-compress-large-string-field-in-index-v6-8/341777 "2023-08-29T06:08:04Z")

</div>

We are planning to store in the index a large string(error log) with a classifier for future use in a machine learning project. The error log can get to the size of tens of megabytes and we are planning to store tens of …

---

## [Elastic-agent metricbeat no verification mode](https://discuss.elastic.co/t/elastic-agent-metricbeat-no-verification-mode/341851)

<div class="topic-metadata">

**Author:** [@Daniel\_Lopez](https://discuss.elastic.co/u/Daniel_Lopez)\
**Replies:** 0\
**Last updated:** [August 29, 2023, 5:46am UTC](https://discuss.elastic.co/t/elastic-agent-metricbeat-no-verification-mode/341851 "2023-08-29T05:46:02Z")

</div>

Hi guys! I think i found a bug on elastic-agent. I configured the whole fleet server with --insecure and ssl.verification\_mode: none options and i'm getting logs to elastic but not metricbeat metrics as i show in the se…

---

## [Data getting SWAPPED in Elasticsearch with pipeline](https://discuss.elastic.co/t/data-getting-swapped-in-elasticsearch-with-pipeline/341796)

<div class="topic-metadata">

**Author:** [@tusharnemade](https://discuss.elastic.co/u/tusharnemade)\
**Replies:** 2\
**Last updated:** [August 29, 2023, 5:33am UTC](https://discuss.elastic.co/t/data-getting-swapped-in-elasticsearch-with-pipeline/341796 "2023-08-29T05:33:36Z")

</div>

Hello Team We are using Elasticsearch version 7.8.0 We are having Index with Pipeline Defined .. Our Problem is data is getting SWAPPED between two fields of Elasticsearch. Data of "OBJ\_NAM\_FILDT" is getting posted i…

---

## [Kibana authentication-Should ask credentials access in kibana UI and Bypass authentication in CUSTOM WEBUI angular based](https://discuss.elastic.co/t/kibana-authentication-should-ask-credentials-access-in-kibana-ui-and-bypass-authentication-in-custom-webui-angular-based/339435)

<div class="topic-metadata">

**Author:** [@PRASHANT\_MEHTA](https://discuss.elastic.co/u/PRASHANT_MEHTA)\
**Replies:** 2\
**Last updated:** [August 28, 2023, 10:32am UTC](https://discuss.elastic.co/t/kibana-authentication-should-ask-credentials-access-in-kibana-ui-and-bypass-authentication-in-custom-webui-angular-based/339435 "2023-08-28T10:32:03Z")

</div>

Hello All, I've requirement where in custom web ui it should not ask any authentication i.e direct access of dashboards in custom website.(This is achieved using anonymous user setting in kibana.yml) But now this same …

---

## [Need confirmation for few Elasticsearch queries](https://discuss.elastic.co/t/need-confirmation-for-few-elasticsearch-queries/341849)

<div class="topic-metadata">

**Author:** [@ashishshukla](https://discuss.elastic.co/u/ashishshukla)\
**Replies:** 1\
**Last updated:** [August 29, 2023, 5:15am UTC](https://discuss.elastic.co/t/need-confirmation-for-few-elasticsearch-queries/341849 "2023-08-29T05:15:30Z")

</div>

Hi Team, Can you please confirm below query comes under SQL query or DSL query ? curl -X POST "https://localhost:9200/\_sql?format=txt&pretty" -H 'Content-Type: application/json' -d' { "query": "SELECT \* FROM custo…

---

## [Elasticsearch snapshot google.cloud.storage.StorageException](https://discuss.elastic.co/t/elasticsearch-snapshot-google-cloud-storage-storageexception/341848)

<div class="topic-metadata">

**Author:** [@navaneethan](https://discuss.elastic.co/u/navaneethan)\
**Replies:** 0\
**Last updated:** [August 29, 2023, 4:45am UTC](https://discuss.elastic.co/t/elasticsearch-snapshot-google-cloud-storage-storageexception/341848 "2023-08-29T04:45:52Z")

</div>

Elastic GCS bucket snapshot failed and we cannot able to retrive the old inremental backup in that bucket, Is there any possibility to recover the back FYI, we can able to view the data storage inside that bucket in th…

---

## [MY SQL database to Kibana directly](https://discuss.elastic.co/t/my-sql-database-to-kibana-directly/341831)

<div class="topic-metadata">

**Author:** [@Kumar\_Abhinav](https://discuss.elastic.co/u/Kumar_Abhinav)\
**Replies:** 6\
**Last updated:** [August 29, 2023, 3:12am UTC](https://discuss.elastic.co/t/my-sql-database-to-kibana-directly/341831 "2023-08-29T03:12:34Z")

</div>

Hello Elastic Community, I'm exploring the use of JDBC to connect Kibana(bypassing Elastic) directly to MySQL. This would help us overcome the challenge of joining data from different indices in Elasticsearch. I'd appre…

---

## [Authentication failed: missing or improperly formatted Authorization header: expected 'Authorization: Bearer secret\_token' or 'Authorization: ApiKey base64(API key ID:API key)'](https://discuss.elastic.co/t/authentication-failed-missing-or-improperly-formatted-authorization-header-expected-authorization-bearer-secret-token-or-authorization-apikey-base64-api-key-id-api-key/340321)

<div class="topic-metadata">

**Author:** [@khteh](https://discuss.elastic.co/u/khteh)\
**Replies:** 6\
**Last updated:** [August 29, 2023, 2:40am UTC](https://discuss.elastic.co/t/authentication-failed-missing-or-improperly-formatted-authorization-header-expected-authorization-bearer-secret-token-or-authorization-apikey-base64-api-key-id-api-key/340321 "2023-08-29T02:40:12Z")

</div>

What does this error mean? \[my-apm-server-7f75cffcf7-grj2t apm-server\] {"log.level":"error","@timestamp":"2023-08-08T05:32:12.641Z","log.logger":"request","log.origin":{"file.name":"middleware/log\_middleware.go","file.l…

---

## [Metricbeat - Limit of total fields \[1000\] has been exceeded-urgent](https://discuss.elastic.co/t/metricbeat-limit-of-total-fields-1000-has-been-exceeded-urgent/341824)

<div class="topic-metadata">

**Author:** [@EL\_MALKI\_MOHAMED](https://discuss.elastic.co/u/EL_MALKI_MOHAMED)\
**Replies:** 5\
**Last updated:** [August 29, 2023, 12:50am UTC](https://discuss.elastic.co/t/metricbeat-limit-of-total-fields-1000-has-been-exceeded-urgent/341824 "2023-08-29T00:50:03Z")

</div>

Hello, Can u help me I have problem. I am having errors trying to ingest system metrics (system module) .The logs are ingested via a common beats pipeline running having the following configuration: logstashPipeline: …

---

## [Term negation and fuzziness](https://discuss.elastic.co/t/term-negation-and-fuzziness/341645)

<div class="topic-metadata">

**Author:** [@cvarano](https://discuss.elastic.co/u/cvarano)\
**Replies:** 1\
**Last updated:** [August 28, 2023, 9:47pm UTC](https://discuss.elastic.co/t/term-negation-and-fuzziness/341645 "2023-08-28T21:47:49Z")

</div>

The use case is a search engine over text documents for the general public. We were previously using a simple match query, but recently switched to simple\_query\_string in order to easily support phrase matching. I'm fi…

---

## [Is it safe to delete logs-deprecation indices, where can we disable creation of these indices?](https://discuss.elastic.co/t/is-it-safe-to-delete-logs-deprecation-indices-where-can-we-disable-creation-of-these-indices/341714)

<div class="topic-metadata">

**Author:** [@Vadym](https://discuss.elastic.co/u/Vadym)\
**Replies:** 2\
**Last updated:** [August 28, 2023, 9:34pm UTC](https://discuss.elastic.co/t/is-it-safe-to-delete-logs-deprecation-indices-where-can-we-disable-creation-of-these-indices/341714 "2023-08-28T21:34:44Z")

</div>

We have some system indices generated by ES, can we turn off generation of these indices and is it safe to delete them? health status index green open .ds-ilm-history-5-2023.06.02-000012 green open .ds-.logs-dep…

---

## [Logstash Logs output for jdbc](https://discuss.elastic.co/t/logstash-logs-output-for-jdbc/341826)

<div class="topic-metadata">

**Author:** [@nbrenke](https://discuss.elastic.co/u/nbrenke)\
**Replies:** 4\
**Last updated:** [August 28, 2023, 8:12pm UTC](https://discuss.elastic.co/t/logstash-logs-output-for-jdbc/341826 "2023-08-28T20:12:08Z")

</div>

I have a silly question:: I have several jdbc pipelines setup that pull data directly from a sql database. Short of the following that shows up in my logs \[2022-10-28T18:40:00,344\]\[INFO \]\[logstash.inputs.jdbc \] (0…

---

## [Investigate high GC time when indexing](https://discuss.elastic.co/t/investigate-high-gc-time-when-indexing/341154)

<div class="topic-metadata">

**Author:** [@ktech007](https://discuss.elastic.co/u/ktech007)\
**Replies:** 17\
**Last updated:** [August 28, 2023, 7:42pm UTC](https://discuss.elastic.co/t/investigate-high-gc-time-when-indexing/341154 "2023-08-28T19:42:54Z")

</div>

Hello, I am looking for some advice as to why we are seeing a high GC time on our Elasticsearch cluster. On average, we see 5 - 8% of GC time across all the nodes. This is the setup we have: 150 data nodes 1000 primar…

---

## [Retrieving millions of large documents](https://discuss.elastic.co/t/retrieving-millions-of-large-documents/341803)

<div class="topic-metadata">

**Author:** [@Tomer\_Avira](https://discuss.elastic.co/u/Tomer_Avira)\
**Replies:** 6\
**Last updated:** [August 28, 2023, 6:06pm UTC](https://discuss.elastic.co/t/retrieving-millions-of-large-documents/341803 "2023-08-28T18:06:58Z")

</div>

Hello everyone, first time i am requesting your help. I am working with elastic version 8.5.3 with java client 7.17.1, let me represent you with the problem I'm having. I have daily indices with the largest of them hol…

---

## [Where is Kibana Watcher UI?](https://discuss.elastic.co/t/where-is-kibana-watcher-ui/341832)

<div class="topic-metadata">

**Author:** [@Constantine\_White](https://discuss.elastic.co/u/Constantine_White)\
**Replies:** 4\
**Last updated:** [August 28, 2023, 5:53pm UTC](https://discuss.elastic.co/t/where-is-kibana-watcher-ui/341832 "2023-08-28T17:53:43Z")

</div>

Hello Elastic forums, Could you please tell me what am I doing wrong or am I just a bit opposite of smart? I'm trying to set up Kibana alerts on logs events, I've discovered that a "Watcher" is a thing and it's (curren…

---

## [Disable logstash license check?](https://discuss.elastic.co/t/disable-logstash-license-check/341788)

<div class="topic-metadata">

**Author:** [@jacobdanielrose](https://discuss.elastic.co/u/jacobdanielrose)\
**Replies:** 1\
**Last updated:** [August 28, 2023, 4:40pm UTC](https://discuss.elastic.co/t/disable-logstash-license-check/341788 "2023-08-28T16:40:42Z")

</div>

Hi! I am trying to connect a logstash instance to an elasticseach which is part of a deployment of IBM Cloudpak for AIOps. It uses an elasticsearch instance to store related incident data from ticket systems. The versio…

---

## [Problem multiline pattern matching](https://discuss.elastic.co/t/problem-multiline-pattern-matching/341107)

<div class="topic-metadata">

**Author:** [@mcondamin](https://discuss.elastic.co/u/mcondamin)\
**Replies:** 8\
**Last updated:** [August 28, 2023, 5:25pm UTC](https://discuss.elastic.co/t/problem-multiline-pattern-matching/341107 "2023-08-28T17:25:52Z")

</div>

Hi guys ! I defer to you because I encounter a problem concerning the configuration of the pattern to aggregate several lines of logs on the same document. Here is an excerpt from my log: 2023-08-17 16:13:15.389 |CB R…

---

## [Performance impact of setting 'namespace' in Elastic agent policy config](https://discuss.elastic.co/t/performance-impact-of-setting-namespace-in-elastic-agent-policy-config/341294)

<div class="topic-metadata">

**Author:** [@Craig\_Rodrigues](https://discuss.elastic.co/u/Craig_Rodrigues)\
**Replies:** 2\
**Last updated:** [August 28, 2023, 5:14pm UTC](https://discuss.elastic.co/t/performance-impact-of-setting-namespace-in-elastic-agent-policy-config/341294 "2023-08-28T17:14:22Z")

</div>

I have about 2000 Elastic agents (version 8.9.0) connected to a system with 3 Fleet servers (version 8.9.0). We have about 20 different agent policies, because the various Elastic agents are sending slightly different …

---

## [Elastic to logs management](https://discuss.elastic.co/t/elastic-to-logs-management/341716)

<div class="topic-metadata">

**Author:** [@Flavio\_Alves](https://discuss.elastic.co/u/Flavio_Alves)\
**Replies:** 2\
**Last updated:** [August 28, 2023, 4:44pm UTC](https://discuss.elastic.co/t/elastic-to-logs-management/341716 "2023-08-28T16:44:52Z")

</div>

Hey, guys! I'm new to using elastic What is the best way to build this structure? and what features should i use? at the moment I will only use the stack to centralize the logs

---

## [How to setup Cloudflare Logpush via HTTP Endpoint?](https://discuss.elastic.co/t/how-to-setup-cloudflare-logpush-via-http-endpoint/341818)

<div class="topic-metadata">

**Author:** [@nlcsdev](https://discuss.elastic.co/u/nlcsdev)\
**Replies:** 0\
**Last updated:** [August 28, 2023, 3:35pm UTC](https://discuss.elastic.co/t/how-to-setup-cloudflare-logpush-via-http-endpoint/341818 "2023-08-28T15:35:51Z")

</div>

Hello, I am trying to use the Cloudflare Logpush integration via HTTP Endpoint. I have read both the documentation on Cloudflare and Elasticsearch and I am still confused. I have Elasticsearch and Kibana 8.9.0 deployed…

[Previous page](https://discuss.elastic.co/latest.md?page=557)

[Next page](https://discuss.elastic.co/latest.md?page=559)
