# Latest

**URL:** https://discuss.elastic.co/latest.md?page=559

[Latest](https://discuss.elastic.co/latest.md) · [Categories](https://discuss.elastic.co/categories.md) · [Tags](https://discuss.elastic.co/tags.md)

**Page:** 560

---

## [How do parse log format apache access](https://discuss.elastic.co/t/how-do-parse-log-format-apache-access/341790)

<div class="topic-metadata">

**Author:** [@vanhaiit90](https://discuss.elastic.co/u/vanhaiit90)\
**Replies:** 1\
**Last updated:** [August 28, 2023, 3:19pm UTC](https://discuss.elastic.co/t/how-do-parse-log-format-apache-access/341790 "2023-08-28T15:19:04Z")

</div>

Good afternoon I have a log with the format of the apache access log service (access\_log) 10.0.xx.xx - - \[28/Aug/2023:15:25:18 +0700\] "GET /xxx/en/neoclassic/cases/main HTTP/1.0" 200 2007 133793 "-" "Mozilla/5.0 (Wind…

---

## [Varying data types in object causing mapping errors](https://discuss.elastic.co/t/varying-data-types-in-object-causing-mapping-errors/341717)

<div class="topic-metadata">

**Author:** [@Wesley84](https://discuss.elastic.co/u/Wesley84)\
**Replies:** 2\
**Last updated:** [August 28, 2023, 2:39pm UTC](https://discuss.elastic.co/t/varying-data-types-in-object-causing-mapping-errors/341717 "2023-08-28T14:39:28Z")

</div>

I have a data object called "weekly\_values" that I want to send to an existing elastic index. This object contains fields which when populated have a float data type. However these fields do not always have a value and w…

---

## [Elastic master node down, how to make slave new master?](https://discuss.elastic.co/t/elastic-master-node-down-how-to-make-slave-new-master/341568)

<div class="topic-metadata">

**Author:** [@webfr](https://discuss.elastic.co/u/webfr)\
**Replies:** 7\
**Last updated:** [August 28, 2023, 2:32pm UTC](https://discuss.elastic.co/t/elastic-master-node-down-how-to-make-slave-new-master/341568 "2023-08-28T14:32:26Z")

</div>

Hello, my master node is currently down since few days, how to make my slave new master if problem on master persists? Thanks.

---

## [Migrate elasticsearch data from 7.17 to 8.6.2 server](https://discuss.elastic.co/t/migrate-elasticsearch-data-from-7-17-to-8-6-2-server/341807)

<div class="topic-metadata">

**Author:** [@HiteshSingh](https://discuss.elastic.co/u/HiteshSingh)\
**Replies:** 1\
**Last updated:** [August 28, 2023, 2:00pm UTC](https://discuss.elastic.co/t/migrate-elasticsearch-data-from-7-17-to-8-6-2-server/341807 "2023-08-28T14:00:19Z")

</div>

We are running elasticsearch on a single node. We are in the process of upgrading our Elasticsearch server from 7.17 to 8.6.2 and we want to migrate elasticsearch data from 7.17 to 8.6.2 version. What is the best appro…

---

## [Rust - How to use PIT?](https://discuss.elastic.co/t/rust-how-to-use-pit/341809)

<div class="topic-metadata">

**Author:** [@Frederick\_Sauvage](https://discuss.elastic.co/u/Frederick_Sauvage)\
**Replies:** 0\
**Last updated:** [August 28, 2023, 1:35pm UTC](https://discuss.elastic.co/t/rust-how-to-use-pit/341809 "2023-08-28T13:35:28Z")

</div>

Hi, I'm trying to add PIT in but I don't find how to do. My code is similar as : let client = Elasticsearch::default(); let s = client.search(SearchParts::None).size(1000).timeout("120s"); let search = Search::new().…

---

## [Setup Elasticsearch cluster mode](https://discuss.elastic.co/t/setup-elasticsearch-cluster-mode/341228)

<div class="topic-metadata">

**Author:** [@HiteshSingh](https://discuss.elastic.co/u/HiteshSingh)\
**Replies:** 13\
**Last updated:** [August 28, 2023, 1:16pm UTC](https://discuss.elastic.co/t/setup-elasticsearch-cluster-mode/341228 "2023-08-28T13:16:58Z")

</div>

I want to setup cluster mode between 2 linux servers One of them will be master and data node and other one will only be a data node. Whenever i try to setup any external IP/interfaces to transport.host, elasticsearch …

---

## [Logstash connecting to more than 1 Database](https://discuss.elastic.co/t/logstash-connecting-to-more-than-1-database/341791)

<div class="topic-metadata">

**Author:** [@Ong](https://discuss.elastic.co/u/Ong)\
**Replies:** 1\
**Last updated:** [August 28, 2023, 1:10pm UTC](https://discuss.elastic.co/t/logstash-connecting-to-more-than-1-database/341791 "2023-08-28T13:10:00Z")

</div>

I have 2 separate MSSQL databases and would like to extract data from them, combine it and send it to ES for indexing. Can Logstash connect to more than 1 MSSQL database, retrieve certain data from them then combine the…

---

## [New python client (8.x) for sql query](https://discuss.elastic.co/t/new-python-client-8-x-for-sql-query/340083)

<div class="topic-metadata">

**Author:** [@elasticforme](https://discuss.elastic.co/u/elasticforme)\
**Replies:** 3\
**Last updated:** [August 28, 2023, 12:52pm UTC](https://discuss.elastic.co/t/new-python-client-8-x-for-sql-query/340083 "2023-08-28T12:52:50Z")

</div>

I am using sql query in my old python client 7.x and it works like this data = es.sql.query(body={"query": sql\_query1, "fetch\_size": 30000}) now using new client 8.x it give me this warning DeprecationWarning: The 'b…

---

## [Error during build for Beats version 8.9.1](https://discuss.elastic.co/t/error-during-build-for-beats-version-8-9-1/341778)

<div class="topic-metadata">

**Author:** [@Nikhitha\_Karennagari](https://discuss.elastic.co/u/Nikhitha_Karennagari)\
**Replies:** 2\
**Last updated:** [August 28, 2023, 12:25pm UTC](https://discuss.elastic.co/t/error-during-build-for-beats-version-8-9-1/341778 "2023-08-28T12:25:28Z")

</div>

Hi, I am facing the below error while building the beats repo. Please help to resolve the issue. Thanks Error: running "go build -o build/golang-crossbuild/filebeat-linux-amd64 -buildmode pie -trimpath -tags=withjourna…

---

## [Cannot retrieve search results in kibana:\[parent\] Data too large, data for \[indices:data/read/async\_search/get\]](https://discuss.elastic.co/t/cannot-retrieve-search-results-in-kibana-parent-data-too-large-data-for-indices-data-read-async-search-get/341514)

<div class="topic-metadata">

**Author:** [@PRASHANT\_MEHTA](https://discuss.elastic.co/u/PRASHANT_MEHTA)\
**Replies:** 2\
**Last updated:** [August 28, 2023, 10:24am UTC](https://discuss.elastic.co/t/cannot-retrieve-search-results-in-kibana-parent-data-too-large-data-for-indices-data-read-async-search-get/341514 "2023-08-28T10:24:16Z")

</div>

Hello All, I am facing one issue while executing a perl script from logstash and getting data,the data is configured to get from perl script execution through loh=gstash every 30 min. I am unbale to see any data in disc…

---

## [Fleet Integration Assets Fail After Upgrade to 8.9.0](https://discuss.elastic.co/t/fleet-integration-assets-fail-after-upgrade-to-8-9-0/341368)

<div class="topic-metadata">

**Author:** [@tomx1](https://discuss.elastic.co/u/tomx1)\
**Replies:** 2\
**Last updated:** [August 28, 2023, 10:00am UTC](https://discuss.elastic.co/t/fleet-integration-assets-fail-after-upgrade-to-8-9-0/341368 "2023-08-28T10:00:56Z")

</div>

I've just upgraded our Cluster from 8.8.0 to 8.9.0 and now all the dashboards and visualizations shipping with fleet integrations are no longer working. If I try to re-install the fleet integration it fails and in the Ki…

---

## [Pls help me on Kibana Piechart Donut with center total count](https://discuss.elastic.co/t/pls-help-me-on-kibana-piechart-donut-with-center-total-count/341677)

<div class="topic-metadata">

**Author:** [@Ram\_Raj](https://discuss.elastic.co/u/Ram_Raj)\
**Replies:** 3\
**Last updated:** [August 28, 2023, 9:23am UTC](https://discuss.elastic.co/t/pls-help-me-on-kibana-piechart-donut-with-center-total-count/341677 "2023-08-28T09:23:36Z")

</div>

I have to show PieChart with center value as total count and each slice to show the value. Example like. Total number of Invoices in the center of Pie Chart and slices with invoice source like Contracts, Projects, onli…

---

## [Show data in a Dashboard/Visualization only if a condition is met - Anonymization of Data](https://discuss.elastic.co/t/show-data-in-a-dashboard-visualization-only-if-a-condition-is-met-anonymization-of-data/341495)

<div class="topic-metadata">

**Author:** [@JD11](https://discuss.elastic.co/u/JD11)\
**Replies:** 3\
**Last updated:** [August 28, 2023, 7:16am UTC](https://discuss.elastic.co/t/show-data-in-a-dashboard-visualization-only-if-a-condition-is-met-anonymization-of-data/341495 "2023-08-28T07:16:08Z")

</div>

Hi together, I have to create a visualization that MUST only show the data/graphic if a condition is met. More context to this question: In Elasticsearch we have docs containing the stock information of different bicy…

---

## [Elastic Agent tags not part of the log content](https://discuss.elastic.co/t/elastic-agent-tags-not-part-of-the-log-content/341009)

<div class="topic-metadata">

**Author:** [@raulgs](https://discuss.elastic.co/u/raulgs)\
**Replies:** 1\
**Last updated:** [August 28, 2023, 6:07am UTC](https://discuss.elastic.co/t/elastic-agent-tags-not-part-of-the-log-content/341009 "2023-08-28T06:07:55Z")

</div>

Hi community, at my company we use managed Elastic Agents to collect logs from kubernetes. To figure out which cluster the logs belong, every cluster is labeled with a specific kubernetes label that identifies it. This…

---

## [Aggregating In Elastic Search](https://discuss.elastic.co/t/aggregating-in-elastic-search/341762)

<div class="topic-metadata">

**Author:** [@Harinder\_Singh](https://discuss.elastic.co/u/Harinder_Singh)\
**Replies:** 1\
**Last updated:** [August 27, 2023, 11:45pm UTC](https://discuss.elastic.co/t/aggregating-in-elastic-search/341762 "2023-08-27T23:45:36Z")

</div>

Hi @leandrojmp , I have a below requirement, where I need to perform aggregation based on certain fields of Elasticsearch. Documents indexed are as below PUT rollup-index/\_doc/1 { "environment" : "preview", "person…

---

## [Slicing without point in time](https://discuss.elastic.co/t/slicing-without-point-in-time/341765)

<div class="topic-metadata">

**Author:** [@kmcclellan](https://discuss.elastic.co/u/kmcclellan)\
**Replies:** 0\
**Last updated:** [August 27, 2023, 10:04pm UTC](https://discuss.elastic.co/t/slicing-without-point-in-time/341765 "2023-08-27T22:04:13Z")

</div>

When you specify "slices" for a search request, you will receive an error if the search is not a point-in-time or scrolled query: "\[slice\] can only be used with \[scroll\] or \[point-in-time\] requests". I don't quite under…

---

## [Atlassian access logs Index not getting created or data not sent / visible in Opensearch](https://discuss.elastic.co/t/atlassian-access-logs-index-not-getting-created-or-data-not-sent-visible-in-opensearch/341742)

<div class="topic-metadata">

**Author:** [@danmed](https://discuss.elastic.co/u/danmed)\
**Replies:** 29\
**Last updated:** [August 27, 2023, 8:04pm UTC](https://discuss.elastic.co/t/atlassian-access-logs-index-not-getting-created-or-data-not-sent-visible-in-opensearch/341742 "2023-08-27T20:04:18Z")

</div>

I'm trying to use Logstash to send Atlassian access logs to opensearch. I'm absolutely new to the topic but can successfully send other logs and view them. It's the jira access logs that I cannot make work. Having tri…

---

## [Elastic Agent/Beats DNS Processor Caching Bad Performance?](https://discuss.elastic.co/t/elastic-agent-beats-dns-processor-caching-bad-performance/341757)

<div class="topic-metadata">

**Author:** [@BenB196](https://discuss.elastic.co/u/BenB196)\
**Replies:** 0\
**Last updated:** [August 27, 2023, 4:37pm UTC](https://discuss.elastic.co/t/elastic-agent-beats-dns-processor-caching-bad-performance/341757 "2023-08-27T16:37:08Z")

</div>

Hello All, I was recently messing around with an Elastic Agent Netflow integration setup, but was noticing that events were being dropped. The integration definition looked something like: inputs: - id: netflow-netf…

---

## [Why Elastic Search allow to put number in text field?](https://discuss.elastic.co/t/why-elastic-search-allow-to-put-number-in-text-field/341756)

<div class="topic-metadata">

**Author:** [@Krzysztof\_Lempicki](https://discuss.elastic.co/u/Krzysztof_Lempicki)\
**Replies:** 1\
**Last updated:** [August 27, 2023, 3:04pm UTC](https://discuss.elastic.co/t/why-elastic-search-allow-to-put-number-in-text-field/341756 "2023-08-27T15:04:54Z")

</div>

Hi, I have mapping like this: "mappings": { "dynamic": "strict", "properties": { "name": { "typ…

---

## [How to use your default defined layer as input for our simple mapbox GL map?](https://discuss.elastic.co/t/how-to-use-your-default-defined-layer-as-input-for-our-simple-mapbox-gl-map/340382)

<div class="topic-metadata">

**Author:** [@jzarei1996](https://discuss.elastic.co/u/jzarei1996)\
**Replies:** 15\
**Last updated:** [August 27, 2023, 1:26pm UTC](https://discuss.elastic.co/t/how-to-use-your-default-defined-layer-as-input-for-our-simple-mapbox-gl-map/340382 "2023-08-27T13:26:02Z")

</div>

Hi everyone. We want to create a sample map from the Mapbox GL JS library in our own plugin according to its documentation. We want a simple mode and during the review we found out that your Maps plugin also uses this li…

---

## [Logstash ingesting Netflow traffic, the probability of parsing errors increases with larger data volumes](https://discuss.elastic.co/t/logstash-ingesting-netflow-traffic-the-probability-of-parsing-errors-increases-with-larger-data-volumes/340539)

<div class="topic-metadata">

**Author:** [@gaorui](https://discuss.elastic.co/u/gaorui)\
**Replies:** 1\
**Last updated:** [August 27, 2023, 12:02pm UTC](https://discuss.elastic.co/t/logstash-ingesting-netflow-traffic-the-probability-of-parsing-errors-increases-with-larger-data-volumes/340539 "2023-08-27T12:02:45Z")

</div>

I am using Logstash to ingest Netflow traffic and after parsing, I store the data in Kafka. As the Netflow traffic I am ingesting increases, the probability of incorrect structured data being parsed also increases. Howev…

---

## [Presumably udp input threads are soaking up cpu](https://discuss.elastic.co/t/presumably-udp-input-threads-are-soaking-up-cpu/341590)

<div class="topic-metadata">

**Author:** [@udp\_issues\_are\_one](https://discuss.elastic.co/u/udp_issues_are_one)\
**Replies:** 5\
**Last updated:** [August 27, 2023, 11:47am UTC](https://discuss.elastic.co/t/presumably-udp-input-threads-are-soaking-up-cpu/341590 "2023-08-27T11:47:32Z")

</div>

We have logstash running on ubuntu, logstash version 8.4.1 from the ubuntu repositories. We have a number of pipelines running, most of them work fine but the CPU utilization on the box is a bit high. From the linux co…

---

## [Is it possible to search only when there are a certain number of terms in the query?](https://discuss.elastic.co/t/is-it-possible-to-search-only-when-there-are-a-certain-number-of-terms-in-the-query/341420)

<div class="topic-metadata">

**Author:** [@gony](https://discuss.elastic.co/u/gony)\
**Replies:** 2\
**Last updated:** [August 27, 2023, 11:05am UTC](https://discuss.elastic.co/t/is-it-possible-to-search-only-when-there-are-a-certain-number-of-terms-in-the-query/341420 "2023-08-27T11:05:01Z")

</div>

When using a match query, is it possible to search only when there are a certain number of terms in the query? I need that functionality, not for the entire query, but as part of a subquery that I will put inside a bool…

---

## [Install Curator 7.0.0 in rhel](https://discuss.elastic.co/t/install-curator-7-0-0-in-rhel/341223)

<div class="topic-metadata">

**Author:** [@johnashish](https://discuss.elastic.co/u/johnashish)\
**Replies:** 5\
**Last updated:** [August 27, 2023, 8:12am UTC](https://discuss.elastic.co/t/install-curator-7-0-0-in-rhel/341223 "2023-08-27T08:12:51Z")

</div>

As per official doc https://www.elastic.co/guide/en/elasticsearch/client/curator/7.0/pip.html Current system - RHEL 8 Elasticsearch - 7.17.3 I am trying to install curator in linux machine and i have install python3 …

---

## [DNS Queries grok pattern working on devtools but not in kibana dashboards](https://discuss.elastic.co/t/dns-queries-grok-pattern-working-on-devtools-but-not-in-kibana-dashboards/341748)

<div class="topic-metadata">

**Author:** [@Poubelle\_Dirty](https://discuss.elastic.co/u/Poubelle_Dirty)\
**Replies:** 4\
**Last updated:** [August 27, 2023, 7:11am UTC](https://discuss.elastic.co/t/dns-queries-grok-pattern-working-on-devtools-but-not-in-kibana-dashboards/341748 "2023-08-27T07:11:37Z")

</div>

Hello, I'm new to ELK stack and I encounter a problem. I'm using the DNS grok pattern from here to parse dns queries from my bind server : https://github.com/cjslack/grok-debugger/blob/master/public/patterns/bind It w…

---

## [MISP integration no data](https://discuss.elastic.co/t/misp-integration-no-data/341190)

<div class="topic-metadata">

**Author:** [@lamp123432](https://discuss.elastic.co/u/lamp123432)\
**Replies:** 5\
**Last updated:** [August 24, 2023, 8:37am UTC](https://discuss.elastic.co/t/misp-integration-no-data/341190 "2023-08-24T08:37:10Z")

</div>

Good day, Setup a MISP server and trying to ingest data with MISP integration but there is no data coming into elastic. Got the right authkey and no restrictions on the MISP Server firewall. Also able to get data when r…

---

## [Help: auditbeat's file\_integrity module not sending logs for created/modified/deleted files](https://discuss.elastic.co/t/help-auditbeats-file-integrity-module-not-sending-logs-for-created-modified-deleted-files/341754)

<div class="topic-metadata">

**Author:** [@roman-tasi](https://discuss.elastic.co/u/roman-tasi)\
**Replies:** 0\
**Last updated:** [August 27, 2023, 2:50am UTC](https://discuss.elastic.co/t/help-auditbeats-file-integrity-module-not-sending-logs-for-created-modified-deleted-files/341754 "2023-08-27T02:50:08Z")

</div>

When I create, modify, or delete a file called test.txt on my server auditbeat does not send a log for it. Not sure why because my other modules appear to be working as intended. Here's the relevant portion from my confi…

---

## [After update , changes order list](https://discuss.elastic.co/t/after-update-changes-order-list/341751)

<div class="topic-metadata">

**Author:** [@Murilo\_Livorato](https://discuss.elastic.co/u/Murilo_Livorato)\
**Replies:** 0\
**Last updated:** [August 26, 2023, 5:01pm UTC](https://discuss.elastic.co/t/after-update-changes-order-list/341751 "2023-08-26T17:01:23Z")

</div>

hello , I have a crud . that I list products , in admin area . I change the price of a product , in a CRUD . after , I give a refresh on the page . and it changed the order that is searching this product . does have …

---

## [How can we use your service tile to load our map in Kibana?](https://discuss.elastic.co/t/how-can-we-use-your-service-tile-to-load-our-map-in-kibana/341726)

<div class="topic-metadata">

**Author:** [@jzarei1996](https://discuss.elastic.co/u/jzarei1996)\
**Replies:** 2\
**Last updated:** [August 26, 2023, 3:21pm UTC](https://discuss.elastic.co/t/how-can-we-use-your-service-tile-to-load-our-map-in-kibana/341726 "2023-08-26T15:21:01Z")

</div>

We have created a map from mapbox gl in our plugin in Kibana. My map codes are very simple, please look at them and guide me what to give as options which include layer and source to my map so that your basemap can be sh…

---

## [The issue of fetching duplicate data in Logstash](https://discuss.elastic.co/t/the-issue-of-fetching-duplicate-data-in-logstash/341643)

<div class="topic-metadata">

**Author:** [@inkweon7269](https://discuss.elastic.co/u/inkweon7269)\
**Replies:** 2\
**Last updated:** [August 26, 2023, 1:40pm UTC](https://discuss.elastic.co/t/the-issue-of-fetching-duplicate-data-in-logstash/341643 "2023-08-26T13:40:13Z")

</div>

I have written the following code within the input section, but I'm experiencing a problem where data is being fetched redundantly. Which part should I modify? logstash.conf input { beats { port =\> 5044 …

[Previous page](https://discuss.elastic.co/latest.md?page=558)

[Next page](https://discuss.elastic.co/latest.md?page=560)
