# Latest

**URL:** https://discuss.elastic.co/latest.md?page=574

[Latest](https://discuss.elastic.co/latest.md) · [Categories](https://discuss.elastic.co/categories.md) · [Tags](https://discuss.elastic.co/tags.md)

**Page:** 575

---

## [Handle retries for bulk api](https://discuss.elastic.co/t/handle-retries-for-bulk-api/340640)

<div class="topic-metadata">

**Author:** [@akhil\_reddy](https://discuss.elastic.co/u/akhil_reddy)\
**Replies:** 1\
**Last updated:** [August 12, 2023, 9:20am UTC](https://discuss.elastic.co/t/handle-retries-for-bulk-api/340640 "2023-08-12T09:20:51Z")

</div>

Hi, I am trying to make a bulk request using BulkRequest in java. I am not finding any documentation to retry the failed requests. Is there any inbuilt functionality in the java client api to handle retries or do I need…

---

## [Why query result cannot be generated all data (csv) of specific days in Elastic Search](https://discuss.elastic.co/t/why-query-result-cannot-be-generated-all-data-csv-of-specific-days-in-elastic-search/340674)

<div class="topic-metadata">

**Author:** [@jt2023](https://discuss.elastic.co/u/jt2023)\
**Replies:** 9\
**Last updated:** [August 12, 2023, 9:14am UTC](https://discuss.elastic.co/t/why-query-result-cannot-be-generated-all-data-csv-of-specific-days-in-elastic-search/340674 "2023-08-12T09:14:11Z")

</div>

why query result cannot be generated all data (csv) of specific days in Elastic Search. For example, i searched for 15,16,17 July data, but only 17July can be generated and displayed in csv file

---

## [Query Precision/Recall vs Sort](https://discuss.elastic.co/t/query-precision-recall-vs-sort/340667)

<div class="topic-metadata">

**Author:** [@RabBit\_BR](https://discuss.elastic.co/u/RabBit_BR)\
**Replies:** 1\
**Last updated:** [August 12, 2023, 7:59am UTC](https://discuss.elastic.co/t/query-precision-recall-vs-sort/340667 "2023-08-12T07:59:55Z")

</div>

I have a catalog of products and I'm facing some problems when I try to sort the results by other criteria than by relevance. Today I can sort the results in order: most recent and most rated. My query has the characte…

---

## [Log.file.path with grok condition issue with multiple log files](https://discuss.elastic.co/t/log-file-path-with-grok-condition-issue-with-multiple-log-files/339600)

<div class="topic-metadata">

**Author:** [@sanjeev1895](https://discuss.elastic.co/u/sanjeev1895)\
**Replies:** 2\
**Last updated:** [August 12, 2023, 6:45am UTC](https://discuss.elastic.co/t/log-file-path-with-grok-condition-issue-with-multiple-log-files/339600 "2023-08-12T06:45:48Z")

</div>

Hi Team, Am I trying to create the index using log.file.path field in the grok if condition. Actually am I including the multiple file path. so while doing this the index was not creating. but if I include only one, the…

---

## [Extract date from filename, time from log line](https://discuss.elastic.co/t/extract-date-from-filename-time-from-log-line/339251)

<div class="topic-metadata">

**Author:** [@Indeed2000](https://discuss.elastic.co/u/Indeed2000)\
**Replies:** 3\
**Last updated:** [August 12, 2023, 6:00am UTC](https://discuss.elastic.co/t/extract-date-from-filename-time-from-log-line/339251 "2023-08-12T06:00:17Z")

</div>

Hi on logstash need to use file as input, output as http. here is the string must be send: mymeasure,tag=mytag field="myfield" 1689682934 this part "1689682934" is timestamp. now question is how can i extract date f…

---

## [Transport errors between elasticsearch nodes](https://discuss.elastic.co/t/transport-errors-between-elasticsearch-nodes/336685)

<div class="topic-metadata">

**Author:** [@Josselin](https://discuss.elastic.co/u/Josselin)\
**Replies:** 10\
**Last updated:** [August 12, 2023, 5:38am UTC](https://discuss.elastic.co/t/transport-errors-between-elasticsearch-nodes/336685 "2023-08-12T05:38:57Z")

</div>

Hi ! I am creating this topic to seek help about a major issues on our Elasticsearch cluster. We have a cluster with nearly 150 nodes (quite a bit :wink: ) We are sometime encountering a big issues, some nodes start t…

---

## [Is is possible to have elasticsearch status return "running" but to get "no alive nodes found in cluster" for the same app?](https://discuss.elastic.co/t/is-is-possible-to-have-elasticsearch-status-return-running-but-to-get-no-alive-nodes-found-in-cluster-for-the-same-app/340670)

<div class="topic-metadata">

**Author:** [@nfanh](https://discuss.elastic.co/u/nfanh)\
**Replies:** 0\
**Last updated:** [August 11, 2023, 11:01pm UTC](https://discuss.elastic.co/t/is-is-possible-to-have-elasticsearch-status-return-running-but-to-get-no-alive-nodes-found-in-cluster-for-the-same-app/340670 "2023-08-11T23:01:39Z")

</div>

is is possible to have elasticsearch status return "running" but to get "no alive nodes found in cluster" for the same app?

---

## [Discover Results Do Not Match Visualization Results](https://discuss.elastic.co/t/discover-results-do-not-match-visualization-results/339845)

<div class="topic-metadata">

**Author:** [@codewriterguy](https://discuss.elastic.co/u/codewriterguy)\
**Replies:** 6\
**Last updated:** [August 11, 2023, 9:55pm UTC](https://discuss.elastic.co/t/discover-results-do-not-match-visualization-results/339845 "2023-08-11T21:55:38Z")

</div>

Hi, Querying in Discover gives some number of results: The same query in a visualization isn't giving any results: Do both of these use the index pattern, and shouldn't both get the same query results for the sa…

---

## [Elastic Engineer Observality LAB 1.2 Heartbeat](https://discuss.elastic.co/t/elastic-engineer-observality-lab-1-2-heartbeat/339973)

<div class="topic-metadata">

**Author:** [@lucasyuki](https://discuss.elastic.co/u/lucasyuki)\
**Replies:** 2\
**Last updated:** [August 11, 2023, 8:11pm UTC](https://discuss.elastic.co/t/elastic-engineer-observality-lab-1-2-heartbeat/339973 "2023-08-11T20:11:13Z")

</div>

Problems with this code, could not create the monitor: job err can not convert object to string heartbeat.monitors: type: http ID used to uniquely identify this monitor in elasticsearch even if the config changes i…

---

## [Access Elasticsearch with HTTPs and HTTP](https://discuss.elastic.co/t/access-elasticsearch-with-https-and-http/340661)

<div class="topic-metadata">

**Author:** [@TomTom](https://discuss.elastic.co/u/TomTom)\
**Replies:** 1\
**Last updated:** [August 11, 2023, 7:53pm UTC](https://discuss.elastic.co/t/access-elasticsearch-with-https-and-http/340661 "2023-08-11T19:53:03Z")

</div>

I configured my Elasticsearch server to be secure, using a proprietary certificate. Similar to the configuration below: # security settings xpack.security.enabled: true xpack.security.autoconfiguration.enabled: false #…

---

## [Security Rules execution error](https://discuss.elastic.co/t/security-rules-execution-error/338484)

<div class="topic-metadata">

**Author:** [@A\_Abdellah](https://discuss.elastic.co/u/A_Abdellah)\
**Replies:** 2\
**Last updated:** [August 11, 2023, 7:36pm UTC](https://discuss.elastic.co/t/security-rules-execution-error/338484 "2023-08-11T19:36:00Z")

</div>

Hello, Kibana shows errors for some built in rules, the error says: \[security\_exception\] Reason: missing authentication credentials for REST request \[/\_security/user/\_has\_privileges\], caused by: "" and my master node …

---

## [In Kibana dashboard graph, what is unit of value format being selected as default? I have attached the snapshot below](https://discuss.elastic.co/t/in-kibana-dashboard-graph-what-is-unit-of-value-format-being-selected-as-default-i-have-attached-the-snapshot-below/340242)

<div class="topic-metadata">

**Author:** [@Abhinav\_Sharma](https://discuss.elastic.co/u/Abhinav_Sharma)\
**Replies:** 1\
**Last updated:** [August 11, 2023, 6:38pm UTC](https://discuss.elastic.co/t/in-kibana-dashboard-graph-what-is-unit-of-value-format-being-selected-as-default-i-have-attached-the-snapshot-below/340242 "2023-08-11T18:38:12Z")

</div>

---

## [\[Filebeat\]\[httpconf\] AuthenticationMissingOrInvalid](https://discuss.elastic.co/t/filebeat-httpconf-authenticationmissingorinvalid/340269)

<div class="topic-metadata">

**Author:** [@Mohammed\_Amine\_El\_ha](https://discuss.elastic.co/u/Mohammed_Amine_El_ha)\
**Replies:** 1\
**Last updated:** [August 11, 2023, 6:35pm UTC](https://discuss.elastic.co/t/filebeat-httpconf-authenticationmissingorinvalid/340269 "2023-08-11T18:35:36Z")

</div>

Hi, I need to get logs from a rest API, I tried this config in My filebeat.yml: filebeat.inputs: type: httpjson request.url: ---------------------------------- request.transforms: set: target: header.Authorizatio…

---

## [Split One Lined "Message" field information](https://discuss.elastic.co/t/split-one-lined-message-field-information/340281)

<div class="topic-metadata">

**Author:** [@Jennifer\_Coley](https://discuss.elastic.co/u/Jennifer_Coley)\
**Replies:** 1\
**Last updated:** [August 11, 2023, 6:32pm UTC](https://discuss.elastic.co/t/split-one-lined-message-field-information/340281 "2023-08-11T18:32:58Z")

</div>

Hi, In my dynamic syslogs in eleasticsearch, A fields called "messages" has over 7 lines of data, I need to split that single line into different field. I have a special character "\\r\\n" before required split informatio…

---

## [Script\_field](https://discuss.elastic.co/t/script-field/340660)

<div class="topic-metadata">

**Author:** [@poonamd](https://discuss.elastic.co/u/poonamd)\
**Replies:** 0\
**Last updated:** [August 11, 2023, 5:21pm UTC](https://discuss.elastic.co/t/script-field/340660 "2023-08-11T17:21:16Z")

</div>

I am trying to return a date from a painless script and then use that date in the query -\> bool -\> filter range query. But this does not seem to work. How should I access the first element of the newVal array? Is the S…

---

## [Elasticsearch cluster search performance is bad after upgrade from 7.17 to 8.8](https://discuss.elastic.co/t/elasticsearch-cluster-search-performance-is-bad-after-upgrade-from-7-17-to-8-8/340592)

<div class="topic-metadata">

**Author:** [@chandra123](https://discuss.elastic.co/u/chandra123)\
**Replies:** 3\
**Last updated:** [August 11, 2023, 5:12pm UTC](https://discuss.elastic.co/t/elasticsearch-cluster-search-performance-is-bad-after-upgrade-from-7-17-to-8-8/340592 "2023-08-11T17:12:56Z")

</div>

Hello Elasticsearch Community, We recently did in-place upgrade from 7.17 to 8.8 and after which we started to see degraded search performance/latency. We have 150 data nodes and we observed that at most 10 data nodes a…

---

## [How to filter the particular timestamp in KQL field](https://discuss.elastic.co/t/how-to-filter-the-particular-timestamp-in-kql-field/340655)

<div class="topic-metadata">

**Author:** [@sanjeev1895](https://discuss.elastic.co/u/sanjeev1895)\
**Replies:** 1\
**Last updated:** [August 11, 2023, 4:58pm UTC](https://discuss.elastic.co/t/how-to-filter-the-particular-timestamp-in-kql-field/340655 "2023-08-11T16:58:34Z")

</div>

Hi Can anyone tell me the how to search the particular timestamp in KQL. Am I using the below format in logstash filter. time\_stamp 11/Aug/2023:16:31:44 +0000 So how to use this time\_stamp field and grep the log…

---

## [Is it possible to develop a custom plugin for Filebeat](https://discuss.elastic.co/t/is-it-possible-to-develop-a-custom-plugin-for-filebeat/339952)

<div class="topic-metadata">

**Author:** [@uday22](https://discuss.elastic.co/u/uday22)\
**Replies:** 4\
**Last updated:** [August 11, 2023, 4:11pm UTC](https://discuss.elastic.co/t/is-it-possible-to-develop-a-custom-plugin-for-filebeat/339952 "2023-08-11T16:11:03Z")

</div>

Hi, I want to develop a custom plugin for filebeat, where the sensitive information in log files are encrypted. Finding sensitive information can be done by regular expression. I want to know weather the above requireme…

---

## [Terms list might be incomplete because the request is taking too long - Warn message on the dashboard](https://discuss.elastic.co/t/terms-list-might-be-incomplete-because-the-request-is-taking-too-long-warn-message-on-the-dashboard/340644)

<div class="topic-metadata">

**Author:** [@Kumbum](https://discuss.elastic.co/u/Kumbum)\
**Replies:** 0\
**Last updated:** [August 11, 2023, 2:28pm UTC](https://discuss.elastic.co/t/terms-list-might-be-incomplete-because-the-request-is-taking-too-long-warn-message-on-the-dashboard/340644 "2023-08-11T14:28:34Z")

</div>

Hi, I have been seeing the following warn message on the dashboard for the dropdown field. However, the dashboard shows expected results but not sure why has it been showing up there. Terms list might be incomplete bec…

---

## [Exclude logs and metrics related to Elastic Agents running on Kubernetes](https://discuss.elastic.co/t/exclude-logs-and-metrics-related-to-elastic-agents-running-on-kubernetes/340645)

<div class="topic-metadata">

**Author:** [@levitoh123](https://discuss.elastic.co/u/levitoh123)\
**Replies:** 0\
**Last updated:** [August 11, 2023, 2:32pm UTC](https://discuss.elastic.co/t/exclude-logs-and-metrics-related-to-elastic-agents-running-on-kubernetes/340645 "2023-08-11T14:32:23Z")

</div>

Hi, I have a deployment in elastic cloud (elasticsearch and kibana) and I recently added the Kubernetes integration. Everything is running good so far, but I do find it very clunky to use. The main problem being that I …

---

## [ELK Stack into AKS](https://discuss.elastic.co/t/elk-stack-into-aks/339086)

<div class="topic-metadata">

**Author:** [@izbant](https://discuss.elastic.co/u/izbant)\
**Replies:** 6\
**Last updated:** [August 11, 2023, 2:30pm UTC](https://discuss.elastic.co/t/elk-stack-into-aks/339086 "2023-08-11T14:30:11Z")

</div>

Hello, I am trying to deploy ELK Stack with basic license into my AKS cluster, but i am unable to secure connection between logstash and elasticsearch. Is there any documentation for deploying ELK Stack into an AKS clu…

---

## [SAML - Migrate to new IDP](https://discuss.elastic.co/t/saml-migrate-to-new-idp/340534)

<div class="topic-metadata">

**Author:** [@heric](https://discuss.elastic.co/u/heric)\
**Replies:** 2\
**Last updated:** [August 11, 2023, 2:29pm UTC](https://discuss.elastic.co/t/saml-migrate-to-new-idp/340534 "2023-08-11T14:29:14Z")

</div>

Hi All, I have 5 nodes cluster of elasticsearch integrated to SAML IDP. i want to migrate to new SAML IDP but i don't have working test environment to integrate to this new IDP. Below scenario that i can think of, do …

---

## [Msearch with PHP](https://discuss.elastic.co/t/msearch-with-php/340585)

<div class="topic-metadata">

**Author:** [@Murilo\_Livorato](https://discuss.elastic.co/u/Murilo_Livorato)\
**Replies:** 1\
**Last updated:** [August 11, 2023, 1:56pm UTC](https://discuss.elastic.co/t/msearch-with-php/340585 "2023-08-11T13:56:44Z")

</div>

Hello , I am using msearch like this doc - well it is working in kibana . but when I try to do it , in php . does not work . this is my test code - $this-\>elasticSeacrh-\>msearch(\[ …

---

## [Bin/logstash-plugin not found](https://discuss.elastic.co/t/bin-logstash-plugin-not-found/340574)

<div class="topic-metadata">

**Author:** [@roel82](https://discuss.elastic.co/u/roel82)\
**Replies:** 1\
**Last updated:** [August 11, 2023, 1:03pm UTC](https://discuss.elastic.co/t/bin-logstash-plugin-not-found/340574 "2023-08-11T13:03:21Z")

</div>

I have deployed LogStash on kubernetes using this image (logstash:8.8.1) and now I would like to install some plugins. I understand that I would need to use the 'logstash-plugin' tool, whis should be located in the bin …

---

## [If condition for null in json field](https://discuss.elastic.co/t/if-condition-for-null-in-json-field/340475)

<div class="topic-metadata">

**Author:** [@wwalker](https://discuss.elastic.co/u/wwalker)\
**Replies:** 1\
**Last updated:** [August 11, 2023, 12:59pm UTC](https://discuss.elastic.co/t/if-condition-for-null-in-json-field/340475 "2023-08-11T12:59:42Z")

</div>

I'm using the JDBC filter to pull info from a SQL database. If the field is blank, it generates the below: "example": \[ { "contoso": "" } \] I've tried the below to remove the empty field, but i…

---

## [Backup Detection Rules and Exceptions](https://discuss.elastic.co/t/backup-detection-rules-and-exceptions/340639)

<div class="topic-metadata">

**Author:** [@hanna](https://discuss.elastic.co/u/hanna)\
**Replies:** 0\
**Last updated:** [August 11, 2023, 12:48pm UTC](https://discuss.elastic.co/t/backup-detection-rules-and-exceptions/340639 "2023-08-11T12:48:29Z")

</div>

Hello everybody, I want to backup all security detection rules and the exceptions I defined for my Cluster. From the documentation I learned how to access rules via the kibana api but there must also be an elasticsearch…

---

## [Winlogbeat ForwardedEvents channels filtering](https://discuss.elastic.co/t/winlogbeat-forwardedevents-channels-filtering/340626)

<div class="topic-metadata">

**Author:** [@stanley783](https://discuss.elastic.co/u/stanley783)\
**Replies:** 1\
**Last updated:** [August 11, 2023, 12:21pm UTC](https://discuss.elastic.co/t/winlogbeat-forwardedevents-channels-filtering/340626 "2023-08-11T12:21:40Z")

</div>

Hi, we have servers forwarding various log channels (System, Security, Powershell..., Defender..) to WEC server via standard WEF service. Installed Winlogbeat on WEC server to forward those logs to ELK. However, we want…

---

## [Node roles impact on nodes](https://discuss.elastic.co/t/node-roles-impact-on-nodes/340625)

<div class="topic-metadata">

**Author:** [@Josselin](https://discuss.elastic.co/u/Josselin)\
**Replies:** 2\
**Last updated:** [August 11, 2023, 12:13pm UTC](https://discuss.elastic.co/t/node-roles-impact-on-nodes/340625 "2023-08-11T12:13:10Z")

</div>

Hi, We currently have a really big cluster with 150+ nodes. We are using node attributes to manage the data tiers and our ILM is based on it (node.attr.data). We are currently investigating the impact of migrating to …

---

## [Filters in the url are reset when redirect to Wazuh Dashboard](https://discuss.elastic.co/t/filters-in-the-url-are-reset-when-redirect-to-wazuh-dashboard/340622)

<div class="topic-metadata">

**Author:** [@Aigerim\_Kubanychbeko](https://discuss.elastic.co/u/Aigerim_Kubanychbeko)\
**Replies:** 2\
**Last updated:** [August 11, 2023, 12:00pm UTC](https://discuss.elastic.co/t/filters-in-the-url-are-reset-when-redirect-to-wazuh-dashboard/340622 "2023-08-11T12:00:40Z")

</div>

I have a table in my Opensearch Dashboard. Also, I have Dashboard in Wazuh, integrated in Elastic. Wazuh is like a security application with its built-in dashboards of different categories. I need to create an url for t…

---

## [I have a older version of Logstash 7.16.2 , is there a output plugin for email. i dont see it for 7.16.2 version](https://discuss.elastic.co/t/i-have-a-older-version-of-logstash-7-16-2-is-there-a-output-plugin-for-email-i-dont-see-it-for-7-16-2-version/339705)

<div class="topic-metadata">

**Author:** [@AKAM14](https://discuss.elastic.co/u/AKAM14)\
**Replies:** 3\
**Last updated:** [August 11, 2023, 11:06am UTC](https://discuss.elastic.co/t/i-have-a-older-version-of-logstash-7-16-2-is-there-a-output-plugin-for-email-i-dont-see-it-for-7-16-2-version/339705 "2023-08-11T11:06:40Z")

</div>

Hi Team, I have an older version of logstash 7.16.2 and i need install an Email output plugin for it . Is there a plugin available for this version . I see the 7.17.x versions have the output plugins. while i cannot f…

[Previous page](https://discuss.elastic.co/latest.md?page=573)

[Next page](https://discuss.elastic.co/latest.md?page=575)
