# Latest

**URL:** https://discuss.elastic.co/latest.md?page=560

[Latest](https://discuss.elastic.co/latest.md) · [Categories](https://discuss.elastic.co/categories.md) · [Tags](https://discuss.elastic.co/tags.md)

**Page:** 561

---

## [Empty indexes in Kibana](https://discuss.elastic.co/t/empty-indexes-in-kibana/341745)

<div class="topic-metadata">

**Author:** [@anshtyagi14](https://discuss.elastic.co/u/anshtyagi14)\
**Replies:** 0\
**Last updated:** [August 26, 2023, 12:43pm UTC](https://discuss.elastic.co/t/empty-indexes-in-kibana/341745 "2023-08-26T12:43:40Z")

</div>

I am trying to visualise system logs in kibana, for the process i am using 3's AWS Amazon Linux 2023 EC2 instance in the following way Instance 01 - Filebeat Instance 02 - Logstash Instance 03 - Elasticsearch, Kibana …

---

## [Problems with homebrew installation](https://discuss.elastic.co/t/problems-with-homebrew-installation/341132)

<div class="topic-metadata">

**Author:** [@dpa](https://discuss.elastic.co/u/dpa)\
**Replies:** 2\
**Last updated:** [August 26, 2023, 11:33am UTC](https://discuss.elastic.co/t/problems-with-homebrew-installation/341132 "2023-08-26T11:33:41Z")

</div>

I tried to follow the basic instructions here: Install Elasticsearch on macOS with Homebrew | Elasticsearch Guide \[7.17\] | Elastic but they don't work brew tap elastic/tap - works fine but brew install elastic/tap/ela…

---

## [How to calculate score after filter in Elasticsearch](https://discuss.elastic.co/t/how-to-calculate-score-after-filter-in-elasticsearch/341733)

<div class="topic-metadata">

**Author:** [@at\_ohn](https://discuss.elastic.co/u/at_ohn)\
**Replies:** 0\
**Last updated:** [August 26, 2023, 9:13am UTC](https://discuss.elastic.co/t/how-to-calculate-score-after-filter-in-elasticsearch/341733 "2023-08-26T09:13:54Z")

</div>

Does anyone know how we can get the score to be calculated AFTER the filter is applied? Rescoring doesn't help too because it still takes into account all documents in the index. I need a score that is independent of the…

---

## [Elastic agent unhealthy because of elastic defend integration](https://discuss.elastic.co/t/elastic-agent-unhealthy-because-of-elastic-defend-integration/340874)

<div class="topic-metadata">

**Author:** [@laale1](https://discuss.elastic.co/u/laale1)\
**Replies:** 5\
**Last updated:** [August 26, 2023, 9:12am UTC](https://discuss.elastic.co/t/elastic-agent-unhealthy-because-of-elastic-defend-integration/340874 "2023-08-26T09:12:38Z")

</div>

Hello community I'm having an issue in my elastic agent, I installed the agent in windows and Linux machines is working well and I can get the event logs and syslog, however when I try to add elastic defend integration t…

---

## [Keyword case insensitive search with non-ascii](https://discuss.elastic.co/t/keyword-case-insensitive-search-with-non-ascii/341460)

<div class="topic-metadata">

**Author:** [@Volodymyr\_Kovtun](https://discuss.elastic.co/u/Volodymyr_Kovtun)\
**Replies:** 5\
**Last updated:** [August 26, 2023, 7:49am UTC](https://discuss.elastic.co/t/keyword-case-insensitive-search-with-non-ascii/341460 "2023-08-26T07:49:13Z")

</div>

Hi Could you please clarify if it is possible to have case-insensitive term.keyword search with non-ascii symbols? It seems not to work. Here is the example: Indexing 4 documents (2 ascii and 2 non-ascii) \>\>\> es.in…

---

## [Unable to retrieve version information from Elasticsearch nodes](https://discuss.elastic.co/t/unable-to-retrieve-version-information-from-elasticsearch-nodes/341729)

<div class="topic-metadata">

**Author:** [@Sasan\_Askari](https://discuss.elastic.co/u/Sasan_Askari)\
**Replies:** 0\
**Last updated:** [August 26, 2023, 7:26am UTC](https://discuss.elastic.co/t/unable-to-retrieve-version-information-from-elasticsearch-nodes/341729 "2023-08-26T07:26:01Z")

</div>

Hi everyone! I have written a docoker-compose to up ELK,but when I run it i get Unable to retrieve version information from Elasticsearch nodes from my kibana container! Here is my structure: first my compoese is …

---

## [Slack Integration with ELK stack](https://discuss.elastic.co/t/slack-integration-with-elk-stack/340657)

<div class="topic-metadata">

**Author:** [@sanjeev1895](https://discuss.elastic.co/u/sanjeev1895)\
**Replies:** 10\
**Last updated:** [August 26, 2023, 2:02am UTC](https://discuss.elastic.co/t/slack-integration-with-elk-stack/340657 "2023-08-26T02:02:40Z")

</div>

Hi I have installed the ELK Stack 8.9.0 in AWS Ubuntu Instance. I was configured the elk stack and it's working fine. So, I want to integrate the slack with elk stack and send the alert to slack channel if any 500 statu…

---

## [Native IntegerRange type in Elastic.Clients (8.9) does not serialize correctly](https://discuss.elastic.co/t/native-integerrange-type-in-elastic-clients-8-9-does-not-serialize-correctly/341581)

<div class="topic-metadata">

**Author:** [@Mathemaphysics](https://discuss.elastic.co/u/Mathemaphysics)\
**Replies:** 0\
**Last updated:** [August 24, 2023, 2:26pm UTC](https://discuss.elastic.co/t/native-integerrange-type-in-elastic-clients-8-9-does-not-serialize-correctly/341581 "2023-08-24T14:26:47Z")

</div>

When I use IntegerRange it does not serialize to fields named gt, gte, lt, and lte. I have an index template which sends my field item\_index\_range to an explicit integer\_range type. I shouldn't need to do any mapping at…

---

## [Security Attributes for ELK Kibana](https://discuss.elastic.co/t/security-attributes-for-elk-kibana/341713)

<div class="topic-metadata">

**Author:** [@3rk1n](https://discuss.elastic.co/u/3rk1n)\
**Replies:** 0\
**Last updated:** [August 25, 2023, 5:36pm UTC](https://discuss.elastic.co/t/security-attributes-for-elk-kibana/341713 "2023-08-25T17:36:37Z")

</div>

Hi, I want to close security recommendations for Kubernetes Cluster in Microsoft Defender for Cloud. One of them is "Kubernetes clusters should disable automounting API credentials" and it can be solved by added "autom…

---

## [Composable Index template with java REST](https://discuss.elastic.co/t/composable-index-template-with-java-rest/341634)

<div class="topic-metadata">

**Author:** [@linkerc](https://discuss.elastic.co/u/linkerc)\
**Replies:** 1\
**Last updated:** [August 25, 2023, 5:25pm UTC](https://discuss.elastic.co/t/composable-index-template-with-java-rest/341634 "2023-08-25T17:25:28Z")

</div>

I'm running 7.15 so it's not the latest binary code. How do I add sorting index in setting? I'm getting invalid sort order error. It seems composable index only takes builder for settings; therefore, I convert all v…

---

## [Security Attributes for Elastic-Operator](https://discuss.elastic.co/t/security-attributes-for-elastic-operator/341710)

<div class="topic-metadata">

**Author:** [@3rk1n](https://discuss.elastic.co/u/3rk1n)\
**Replies:** 0\
**Last updated:** [August 25, 2023, 5:12pm UTC](https://discuss.elastic.co/t/security-attributes-for-elastic-operator/341710 "2023-08-25T17:12:45Z")

</div>

Hi, I want to close security recommendations for Kubernetes Cluster in Microsoft Defender for Cloud. One of them is "Kubernetes clusters should disable automounting API credentials" and it can be solved by added "autom…

---

## [Is it possible to disable HTTP Options method in Elastic Search v7.5?](https://discuss.elastic.co/t/is-it-possible-to-disable-http-options-method-in-elastic-search-v7-5/341700)

<div class="topic-metadata">

**Author:** [@James\_Brown2](https://discuss.elastic.co/u/James_Brown2)\
**Replies:** 1\
**Last updated:** [August 25, 2023, 5:00pm UTC](https://discuss.elastic.co/t/is-it-possible-to-disable-http-options-method-in-elastic-search-v7-5/341700 "2023-08-25T17:00:41Z")

</div>

Hi there, Does anyone know is it possible to disabled HTTP Options method in Elastic Search v7.5? and if it is safe to do so without affecting Elastic Search functionality? Many thanks, James

---

## [Duplicated events](https://discuss.elastic.co/t/duplicated-events/341389)

<div class="topic-metadata">

**Author:** [@Mohammed\_Amine\_El\_ha](https://discuss.elastic.co/u/Mohammed_Amine_El_ha)\
**Replies:** 2\
**Last updated:** [August 25, 2023, 4:26pm UTC](https://discuss.elastic.co/t/duplicated-events/341389 "2023-08-25T16:26:56Z")

</div>

Hi, I am fairely new to the elastic stack I am using filebeat to pull date from a Rest Api and push it to elastic. my configuration file is as follows: # ============================== Filebeat inputs ===============…

---

## [Fleet Server Setup failing](https://discuss.elastic.co/t/fleet-server-setup-failing/341380)

<div class="topic-metadata">

**Author:** [@sai\_kiran1](https://discuss.elastic.co/u/sai_kiran1)\
**Replies:** 11\
**Last updated:** [August 25, 2023, 4:00pm UTC](https://discuss.elastic.co/t/fleet-server-setup-failing/341380 "2023-08-25T16:00:55Z")

</div>

Hello, Trying to enroll fleet in docker env and the enroll is not happening with the below continuous log messages. \[root@eicillp949 ~\]# docker logs --since 10m -f elastic-agent Policy selected for enrollment: fleet-s…

---

## [Challenges of Indexing Large Arrays with Thousands of Fields in ELK Stack for Search Engine Development with Sailsjs](https://discuss.elastic.co/t/challenges-of-indexing-large-arrays-with-thousands-of-fields-in-elk-stack-for-search-engine-development-with-sailsjs/341705)

<div class="topic-metadata">

**Author:** [@priyanshu-kun](https://discuss.elastic.co/u/priyanshu-kun)\
**Replies:** 0\
**Last updated:** [August 25, 2023, 3:52pm UTC](https://discuss.elastic.co/t/challenges-of-indexing-large-arrays-with-thousands-of-fields-in-elk-stack-for-search-engine-development-with-sailsjs/341705 "2023-08-25T15:52:42Z")

</div>

I new to ELK stack and I want to index an array of object and each object have over 3000 fields for building a search engine using sailsjs. I tried lot of way and dig through the web but I cannot able to find the solutio…

---

## [How to set custom trace.id from header value](https://discuss.elastic.co/t/how-to-set-custom-trace-id-from-header-value/341635)

<div class="topic-metadata">

**Author:** [@zt9788](https://discuss.elastic.co/u/zt9788)\
**Replies:** 1\
**Last updated:** [August 25, 2023, 3:25pm UTC](https://discuss.elastic.co/t/how-to-set-custom-trace-id-from-header-value/341635 "2023-08-25T15:25:05Z")

</div>

I want set custom trace.id in apm like: if other organization's app http --\> header ('requestId',.....) ,so i want use the requestId to set apm's trace.id? is some way can make it?

---

## [Entreprise Elastic license](https://discuss.elastic.co/t/entreprise-elastic-license/341665)

<div class="topic-metadata">

**Author:** [@Manal\_A](https://discuss.elastic.co/u/Manal_A)\
**Replies:** 3\
**Last updated:** [August 25, 2023, 2:34pm UTC](https://discuss.elastic.co/t/entreprise-elastic-license/341665 "2023-08-25T14:34:32Z")

</div>

Does the enterprise license of Elastic depend on the basic system resource configuration or on the scalability ?

---

## [Syslog input plugin from Logstash, how to configure in Elastic agent?](https://discuss.elastic.co/t/syslog-input-plugin-from-logstash-how-to-configure-in-elastic-agent/341300)

<div class="topic-metadata">

**Author:** [@Craig\_Rodrigues](https://discuss.elastic.co/u/Craig_Rodrigues)\
**Replies:** 10\
**Last updated:** [August 25, 2023, 1:31pm UTC](https://discuss.elastic.co/t/syslog-input-plugin-from-logstash-how-to-configure-in-elastic-agent/341300 "2023-08-25T13:31:29Z")

</div>

I have about 2000 Elastic agents (version 8.9.0) connected to a system with 3 Fleet servers (version 8.9.0). We have about 20 different agent policies, because the various Elastic agents are sending slightly different …

---

## [Use custom analyzer in search query on selected fields only](https://discuss.elastic.co/t/use-custom-analyzer-in-search-query-on-selected-fields-only/341693)

<div class="topic-metadata">

**Author:** [@aniket\_mandhare](https://discuss.elastic.co/u/aniket_mandhare)\
**Replies:** 0\
**Last updated:** [August 25, 2023, 1:25pm UTC](https://discuss.elastic.co/t/use-custom-analyzer-in-search-query-on-selected-fields-only/341693 "2023-08-25T13:25:23Z")

</div>

I want to apply a custom analyzer to selected fields only in a search query without having to modify the field mappings. And also don't want to add subfield while mapping.

---

## [Unable to connect Kibana to Elasticsearch](https://discuss.elastic.co/t/unable-to-connect-kibana-to-elasticsearch/341646)

<div class="topic-metadata">

**Author:** [@ANUBHAV\_GUPTA](https://discuss.elastic.co/u/ANUBHAV_GUPTA)\
**Replies:** 5\
**Last updated:** [August 25, 2023, 1:14pm UTC](https://discuss.elastic.co/t/unable-to-connect-kibana-to-elasticsearch/341646 "2023-08-25T13:14:29Z")

</div>

Hi there, I am having an ES cluster running with the following config, with self signed certificates:- sudo docker run -it --privileged -p 9200:9200 -p 9300:9300 -e discovery.type=multi-node -e "cluster.name=my-elasti…

---

## [Elasticsearch nodes RED](https://discuss.elastic.co/t/elasticsearch-nodes-red/341638)

<div class="topic-metadata">

**Author:** [@d6036de2b54af16665f4](https://discuss.elastic.co/u/d6036de2b54af16665f4)\
**Replies:** 1\
**Last updated:** [August 25, 2023, 12:55pm UTC](https://discuss.elastic.co/t/elasticsearch-nodes-red/341638 "2023-08-25T12:55:22Z")

</div>

HI, On Elasticsearch Status is Showing as RED. With GET \_cat/allocation/?v Command i tried to check which nodes has no shards Allocated but it not giving that information like which node has 0 shards allocated. That's…

---

## [Filebeat Fortinet Module: Mismatch between event.action and event.type in Fortigate Logs](https://discuss.elastic.co/t/filebeat-fortinet-module-mismatch-between-event-action-and-event-type-in-fortigate-logs/341686)

<div class="topic-metadata">

**Author:** [@Adriann](https://discuss.elastic.co/u/Adriann)\
**Replies:** 0\
**Last updated:** [August 25, 2023, 12:53pm UTC](https://discuss.elastic.co/t/filebeat-fortinet-module-mismatch-between-event-action-and-event-type-in-fortigate-logs/341686 "2023-08-25T12:53:32Z")

</div>

Hello Elastic Community, We have set up Filebeat to use the Fortinet module for parsing logs from local files that are sent via Syslog to a Syslog server. We are currently running ELK Kibana and Filebeat version 8.7. As…

---

## [Handle specific type of ElasticsearchException](https://discuss.elastic.co/t/handle-specific-type-of-elasticsearchexception/341669)

<div class="topic-metadata">

**Author:** [@Raghunandan](https://discuss.elastic.co/u/Raghunandan)\
**Replies:** 3\
**Last updated:** [August 25, 2023, 11:52am UTC](https://discuss.elastic.co/t/handle-specific-type-of-elasticsearchexception/341669 "2023-08-25T11:52:58Z")

</div>

Hi Team, We are facing a very rare scenario, in our cluster deployment we have used dependent services in which the ES repository bean which creates an index is autowired in other service bean, so on startup index creat…

---

## [Getting "no field found in the mapping" when creating a scripted field](https://discuss.elastic.co/t/getting-no-field-found-in-the-mapping-when-creating-a-scripted-field/341684)

<div class="topic-metadata">

**Author:** [@mr\_ph](https://discuss.elastic.co/u/mr_ph)\
**Replies:** 0\
**Last updated:** [August 25, 2023, 11:45am UTC](https://discuss.elastic.co/t/getting-no-field-found-in-the-mapping-when-creating-a-scripted-field/341684 "2023-08-25T11:45:15Z")

</div>

Hi team, I am using FortiGate integration in my ELK. So I need to create a new scripted fields for more visibility into that logs. Created a scripted field with the following condition. if ( doc\['fortinet.firewall.acti…

---

## [Using scripted field in search query](https://discuss.elastic.co/t/using-scripted-field-in-search-query/341682)

<div class="topic-metadata">

**Author:** [@yuswanul](https://discuss.elastic.co/u/yuswanul)\
**Replies:** 0\
**Last updated:** [August 25, 2023, 11:36am UTC](https://discuss.elastic.co/t/using-scripted-field-in-search-query/341682 "2023-08-25T11:36:03Z")

</div>

hi there i have a question here. so for example I already made a scripted field with the name "api\_key" and I want include that field in my search query like http.code: 403 AND NOT api\_key: unknown I already included t…

---

## [Elastic Agent restore data views](https://discuss.elastic.co/t/elastic-agent-restore-data-views/341678)

<div class="topic-metadata">

**Author:** [@Daniel\_Lopez](https://discuss.elastic.co/u/Daniel_Lopez)\
**Replies:** 0\
**Last updated:** [August 25, 2023, 11:06am UTC](https://discuss.elastic.co/t/elastic-agent-restore-data-views/341678 "2023-08-25T11:06:48Z")

</div>

Hi guys! Data views from fleet server integrations have been removed, how could I reinstall data views and templates again? BR

---

## [How create a alert when logstash node goes down in a cluster? please help me how to do it](https://discuss.elastic.co/t/how-create-a-alert-when-logstash-node-goes-down-in-a-cluster-please-help-me-how-to-do-it/341676)

<div class="topic-metadata">

**Author:** [@mahesh\_sadhanagiri](https://discuss.elastic.co/u/mahesh_sadhanagiri)\
**Replies:** 0\
**Last updated:** [August 25, 2023, 10:34am UTC](https://discuss.elastic.co/t/how-create-a-alert-when-logstash-node-goes-down-in-a-cluster-please-help-me-how-to-do-it/341676 "2023-08-25T10:34:50Z")

</div>

I have a cluster with 3 logstash nodes. I want to create an alert to triiger if any of the Logstash node goes down.

---

## [Using multi-term aggregation on rollup jobs](https://discuss.elastic.co/t/using-multi-term-aggregation-on-rollup-jobs/341674)

<div class="topic-metadata">

**Author:** [@hjazz6](https://discuss.elastic.co/u/hjazz6)\
**Replies:** 0\
**Last updated:** [August 25, 2023, 10:03am UTC](https://discuss.elastic.co/t/using-multi-term-aggregation-on-rollup-jobs/341674 "2023-08-25T10:03:38Z")

</div>

Hi, Can I use multi-term aggregation on rollup jobs? My goal is to save disk space on older data, which has 6 fields (say, Field1 to Field6). After the rollup, I would like to query for the presence of records with the…

---

## [Logstash configuration file for self join field with error object mapping found a concrete value](https://discuss.elastic.co/t/logstash-configuration-file-for-self-join-field-with-error-object-mapping-found-a-concrete-value/341071)

<div class="topic-metadata">

**Author:** [@uma\_parvathy](https://discuss.elastic.co/u/uma_parvathy)\
**Replies:** 8\
**Last updated:** [August 25, 2023, 9:08am UTC](https://discuss.elastic.co/t/logstash-configuration-file-for-self-join-field-with-error-object-mapping-found-a-concrete-value/341071 "2023-08-25T09:08:26Z")

</div>

I've a logstash integration with postgresql table. the table has a self join from incident\_parent\_id to incident\_number. incident\_number ( primary key) incident\_parent\_id ( self join with incident number). But the r…

---

## [Kibana No results match your search criteria or wrong configurations](https://discuss.elastic.co/t/kibana-no-results-match-your-search-criteria-or-wrong-configurations/341541)

<div class="topic-metadata">

**Author:** [@Elite9400](https://discuss.elastic.co/u/Elite9400)\
**Replies:** 1\
**Last updated:** [August 25, 2023, 9:44am UTC](https://discuss.elastic.co/t/kibana-no-results-match-your-search-criteria-or-wrong-configurations/341541 "2023-08-25T09:44:42Z")

</div>

hello, I'm trying to use ELK in my laboratory for a study project but I'm having problems collecting log records. I currently set up my test environment like this: VM 1 - SRV401 (Windows Server 2022) I would like thi…

[Previous page](https://discuss.elastic.co/latest.md?page=559)

[Next page](https://discuss.elastic.co/latest.md?page=561)
