# Latest

**URL:** https://discuss.elastic.co/latest.md?page=575

[Latest](https://discuss.elastic.co/latest.md) · [Categories](https://discuss.elastic.co/categories.md) · [Tags](https://discuss.elastic.co/tags.md)

**Page:** 576

---

## [Obtener datos de una cadena](https://discuss.elastic.co/t/obtener-datos-de-una-cadena/340634)

<div class="topic-metadata">

**Author:** [@JorgeGV](https://discuss.elastic.co/u/JorgeGV)\
**Replies:** 0\
**Last updated:** [August 11, 2023, 10:36am UTC](https://discuss.elastic.co/t/obtener-datos-de-una-cadena/340634 "2023-08-11T10:36:59Z")

</div>

Hola, Tengo un código dentro del modelo de datos que en función de su posición dentro de la cadena indica diferentes conceptos, como puedo separarlo dentro del logstash para diferenciarlos y poder tratarlos como nuevas …

---

## [Poll data ingestion to an index should trigger data ingestion to another index](https://discuss.elastic.co/t/poll-data-ingestion-to-an-index-should-trigger-data-ingestion-to-another-index/340617)

<div class="topic-metadata">

**Author:** [@Sheereen](https://discuss.elastic.co/u/Sheereen)\
**Replies:** 6\
**Last updated:** [August 11, 2023, 10:25am UTC](https://discuss.elastic.co/t/poll-data-ingestion-to-an-index-should-trigger-data-ingestion-to-another-index/340617 "2023-08-11T10:25:00Z")

</div>

Hi, Let's say I have to indices, index\_poll and index\_latest. Index\_poll gets metrics data from devices using logstash and beats. When data is ingested into index\_poll, I want this to trigger the data ingestion/updatio…

---

## [Assign users to APM Agents](https://discuss.elastic.co/t/assign-users-to-apm-agents/340623)

<div class="topic-metadata">

**Author:** [@Namita\_Jaokar](https://discuss.elastic.co/u/Namita_Jaokar)\
**Replies:** 0\
**Last updated:** [August 11, 2023, 8:00am UTC](https://discuss.elastic.co/t/assign-users-to-apm-agents/340623 "2023-08-11T08:00:09Z")

</div>

Hi All, I am using ELK Version 8.6.2 and trying to create separate users for different Java APM Agents. For Example If I have 2 APM Agents namely 1\_agent & 2\_agent and 2 Users User1 and User2. My requirement is such…

---

## [How to create dynamic title in Markdown with Handlebars(mustache)?](https://discuss.elastic.co/t/how-to-create-dynamic-title-in-markdown-with-handlebars-mustache/339173)

<div class="topic-metadata">

**Author:** [@Aigerim\_Kubanychbeko](https://discuss.elastic.co/u/Aigerim_Kubanychbeko)\
**Replies:** 2\
**Last updated:** [August 11, 2023, 7:50am UTC](https://discuss.elastic.co/t/how-to-create-dynamic-title-in-markdown-with-handlebars-mustache/339173 "2023-08-11T07:50:37Z")

</div>

I wonder if there any way to create dynamic title in the TVSB visualization using Markdown and Handlebars. This visualization is a part of the dashboard. Whenever I filter particular field: title.keyword is ... this tit…

---

## [Auditbeat failed to load rules on aarch64/ARM 64 bits](https://discuss.elastic.co/t/auditbeat-failed-to-load-rules-on-aarch64-arm-64-bits/340612)

<div class="topic-metadata">

**Author:** [@albertchen](https://discuss.elastic.co/u/albertchen)\
**Replies:** 0\
**Last updated:** [August 11, 2023, 5:47am UTC](https://discuss.elastic.co/t/auditbeat-failed-to-load-rules-on-aarch64-arm-64-bits/340612 "2023-08-11T05:47:56Z")

</div>

Hi sir, When I try to load the following rules on aarch64 platform (ARM 64 bits) -a always,exit -F arch=b64 -S open,creat,truncate,ftruncate,openat,open\_by\_handle\_at -F exit=-EACCES -k access -a always,exit -F arch=b64…

---

## [Filebeat mssql module multiple drive paths in var.paths config](https://discuss.elastic.co/t/filebeat-mssql-module-multiple-drive-paths-in-var-paths-config/340554)

<div class="topic-metadata">

**Author:** [@Craig\_Sharp](https://discuss.elastic.co/u/Craig_Sharp)\
**Replies:** 1\
**Last updated:** [August 11, 2023, 6:56am UTC](https://discuss.elastic.co/t/filebeat-mssql-module-multiple-drive-paths-in-var-paths-config/340554 "2023-08-11T06:56:39Z")

</div>

I am ingesting mssql logs from a failover cluster. Due to the nature of the cluster each node has a different mount / drive letter for the log data. The cluster may have M:, N:, O: P:, etc. but only one per node. This ma…

---

## [How to pass variables to filebeat through the Elastic-Agent?](https://discuss.elastic.co/t/how-to-pass-variables-to-filebeat-through-the-elastic-agent/340031)

<div class="topic-metadata">

**Author:** [@Bryan\_Hamilton](https://discuss.elastic.co/u/Bryan_Hamilton)\
**Replies:** 2\
**Last updated:** [August 11, 2023, 6:34am UTC](https://discuss.elastic.co/t/how-to-pass-variables-to-filebeat-through-the-elastic-agent/340031 "2023-08-11T06:34:27Z")

</div>

Hi, We currently use stand-alone filebeat running as a systemd service to shipt cusom application logs to elasticsearch. On each application server, the main application creates/updates a file at boot time and populate …

---

## [Error executing logstash pipeline with jdbc select SQLDataException: ORA-01846: not a valid day of the week](https://discuss.elastic.co/t/error-executing-logstash-pipeline-with-jdbc-select-sqldataexception-ora-01846-not-a-valid-day-of-the-week/340368)

<div class="topic-metadata">

**Author:** [@cperzrt10](https://discuss.elastic.co/u/cperzrt10)\
**Replies:** 4\
**Last updated:** [August 11, 2023, 6:23am UTC](https://discuss.elastic.co/t/error-executing-logstash-pipeline-with-jdbc-select-sqldataexception-ora-01846-not-a-valid-day-of-the-week/340368 "2023-08-11T06:23:14Z")

</div>

We have into logstash pipeline the config to search into database and get the data, after the first search we want only select the new data, to do this we use the config of jdbc plugin, my pipeline config. input { jdb…

---

## [Ruby code include?](https://discuss.elastic.co/t/ruby-code-include/340336)

<div class="topic-metadata">

**Author:** [@michaelv](https://discuss.elastic.co/u/michaelv)\
**Replies:** 6\
**Last updated:** [August 11, 2023, 5:48am UTC](https://discuss.elastic.co/t/ruby-code-include/340336 "2023-08-11T05:48:03Z")

</div>

Hi All, I have this code that used to be working in ELK 7.12 now that I've upgrade to 8.7.1 it gives a weird error in logstash code =\> " ip\_src = Array.new ip\_…

---

## [Metricbeat](https://discuss.elastic.co/t/metricbeat/340611)

<div class="topic-metadata">

**Author:** [@Rahul\_Kumar\_Jaiswal](https://discuss.elastic.co/u/Rahul_Kumar_Jaiswal)\
**Replies:** 0\
**Last updated:** [August 11, 2023, 5:30am UTC](https://discuss.elastic.co/t/metricbeat/340611 "2023-08-11T05:30:23Z")

</div>

How to get the cpu and memory usage of each users in "CPU Usage \[Metricbeat System\] ECS in ELK" and "Memory Usage \[Metricbeat System\] ECS in ELK". Right now it is showing the metric of 'user' fields which contains all th…

---

## [Parse\_exception, status 400 while reindexing](https://discuss.elastic.co/t/parse-exception-status-400-while-reindexing/340610)

<div class="topic-metadata">

**Author:** [@viera120](https://discuss.elastic.co/u/viera120)\
**Replies:** 0\
**Last updated:** [August 11, 2023, 5:20am UTC](https://discuss.elastic.co/t/parse-exception-status-400-while-reindexing/340610 "2023-08-11T05:20:00Z")

</div>

We are re-indexing some indices with an updated field mapping. The approach taken is to create a new index with the updated mapping, then copy the existing index into the new index using the Reindex API. Code #create e…

---

## [Upgrading component template logs-settings failed after update to 8.9](https://discuss.elastic.co/t/upgrading-component-template-logs-settings-failed-after-update-to-8-9/340606)

<div class="topic-metadata">

**Author:** [@jordan](https://discuss.elastic.co/u/jordan)\
**Replies:** 0\
**Last updated:** [August 11, 2023, 4:15am UTC](https://discuss.elastic.co/t/upgrading-component-template-logs-settings-failed-after-update-to-8-9/340606 "2023-08-11T04:15:42Z")

</div>

After updating elasticsearch cloud service from version 8.6 to 8.9.0 I want to share the following issue, that's showing up in logs every 30 minutes: \[instance-0000000005\] upgrading component template \[logs-settings\] fo…

---

## [Kibana 8.9.0 Something went wrong :e.replaceAll is not a function](https://discuss.elastic.co/t/kibana-8-9-0-something-went-wrong-e-replaceall-is-not-a-function/340601)

<div class="topic-metadata">

**Author:** [@ss\_s](https://discuss.elastic.co/u/ss_s)\
**Replies:** 1\
**Last updated:** [August 11, 2023, 2:53am UTC](https://discuss.elastic.co/t/kibana-8-9-0-something-went-wrong-e-replaceall-is-not-a-function/340601 "2023-08-11T02:53:27Z")

</div>

Hey Elastic Community team, When I open Kibana on the web after login.This error occurred i try to refreshing the page,but the error continued； Microsoft Edge 84.0.522.52

---

## [We have cluster of 4 nodes, where 2 nodes are master and data and other 2 nodes are data nodes, the configuration was working fine since 2 yrs, today we have to restart the cluster and since then we are getting master not discovered exception](https://discuss.elastic.co/t/we-have-cluster-of-4-nodes-where-2-nodes-are-master-and-data-and-other-2-nodes-are-data-nodes-the-configuration-was-working-fine-since-2-yrs-today-we-have-to-restart-the-cluster-and-since-then-we-are-getting-master-not-discovered-exception/340122)

<div class="topic-metadata">

**Author:** [@vishnu\_ishpujani](https://discuss.elastic.co/u/vishnu_ishpujani)\
**Replies:** 25\
**Last updated:** [August 11, 2023, 2:41am UTC](https://discuss.elastic.co/t/we-have-cluster-of-4-nodes-where-2-nodes-are-master-and-data-and-other-2-nodes-are-data-nodes-the-configuration-was-working-fine-since-2-yrs-today-we-have-to-restart-the-cluster-and-since-then-we-are-getting-master-not-discovered-exception/340122 "2023-08-11T02:41:53Z")

</div>

Please fine attached the logs for master 1 and master 2 \[2023-08-04T20:42:56,086\]\[WARN \]\[r.suppressed \] \[ES-Master-2\] path: /\_license, params: {human=false} org.elasticsearch.discovery.MasterNotDiscoveredExc…

---

## [Decentralised architecture with elastic SIEM](https://discuss.elastic.co/t/decentralised-architecture-with-elastic-siem/340598)

<div class="topic-metadata">

**Author:** [@kafikone](https://discuss.elastic.co/u/kafikone)\
**Replies:** 1\
**Last updated:** [August 11, 2023, 2:15am UTC](https://discuss.elastic.co/t/decentralised-architecture-with-elastic-siem/340598 "2023-08-11T02:15:07Z")

</div>

Hi all I have a concern and I would like to have some leads if possible. I'd like to know if it's possible for elastic agents installed on machines at a company site in town A, for example, to be able to send logs to t…

---

## [Documentation for UpdateOperation](https://discuss.elastic.co/t/documentation-for-updateoperation/340566)

<div class="topic-metadata">

**Author:** [@toddcarv](https://discuss.elastic.co/u/toddcarv)\
**Replies:** 2\
**Last updated:** [August 10, 2023, 7:02pm UTC](https://discuss.elastic.co/t/documentation-for-updateoperation/340566 "2023-08-10T19:02:48Z")

</div>

Is there any documentation for using UpdateOperation with the new Java API Client. I can't seem to find any. Some examples would be helpful. Thanks.

---

## [Issue with APM integration with Meteor application](https://discuss.elastic.co/t/issue-with-apm-integration-with-meteor-application/338860)

<div class="topic-metadata">

**Author:** [@Kesha\_Shah](https://discuss.elastic.co/u/Kesha_Shah)\
**Replies:** 2\
**Last updated:** [August 10, 2023, 6:58pm UTC](https://discuss.elastic.co/t/issue-with-apm-integration-with-meteor-application/338860 "2023-08-10T18:58:04Z")

</div>

Kibana version: 8.8.1 Elasticsearch version: 8.8.1 APM Server version: 8.8.1 APM Agent language and version: Using NodeJS agent for Meteor App Description of the problem including expected versus actual behavior. Ple…

---

## [Unexpected I/O error while de-serializing auth scheme](https://discuss.elastic.co/t/unexpected-i-o-error-while-de-serializing-auth-scheme/340078)

<div class="topic-metadata">

**Author:** [@Jim\_Song](https://discuss.elastic.co/u/Jim_Song)\
**Replies:** 7\
**Last updated:** [August 10, 2023, 6:40pm UTC](https://discuss.elastic.co/t/unexpected-i-o-error-while-de-serializing-auth-scheme/340078 "2023-08-10T18:40:14Z")

</div>

I have a simple Java Rest client making an index() call. I am getting warning messages: IndexRequest\<Node\> irequest = IndexRequest.of(i -\> i .index("index-b") .id("123") .document(node) ); …

---

## [Fuzzy search](https://discuss.elastic.co/t/fuzzy-search/340584)

<div class="topic-metadata">

**Author:** [@moep](https://discuss.elastic.co/u/moep)\
**Replies:** 0\
**Last updated:** [August 10, 2023, 6:17pm UTC](https://discuss.elastic.co/t/fuzzy-search/340584 "2023-08-10T18:17:37Z")

</div>

Hey there, I take in to a project into elasticsearch. The task is a webshop. Right now the problem is, that its possible to search for foo 40 Liter but its not possible for search for foo 40L. My next step is, to use lo…

---

## [How to calculate number of licenses count for my Elastic cluster](https://discuss.elastic.co/t/how-to-calculate-number-of-licenses-count-for-my-elastic-cluster/340583)

<div class="topic-metadata">

**Author:** [@hiruni.insyncit.net](https://discuss.elastic.co/u/hiruni.insyncit.net)\
**Replies:** 1\
**Last updated:** [August 10, 2023, 6:14pm UTC](https://discuss.elastic.co/t/how-to-calculate-number-of-licenses-count-for-my-elastic-cluster/340583 "2023-08-10T18:14:33Z")

</div>

Hi, I want to know what criteria are going to apply, when calculating the number of licenses for my Elastic cluster. Thank you..! Hiruni

---

## [Encryption at rest](https://discuss.elastic.co/t/encryption-at-rest/340580)

<div class="topic-metadata">

**Author:** [@Buddha](https://discuss.elastic.co/u/Buddha)\
**Replies:** 1\
**Last updated:** [August 10, 2023, 6:02pm UTC](https://discuss.elastic.co/t/encryption-at-rest/340580 "2023-08-10T18:02:55Z")

</div>

Using the docker-compose.yml file found in the official Elastic documents: Install Elasticsearch with Docker | Elasticsearch Guide \[8.9\] | Elastic, is my data encryption at rest? Or do I need to add something to the env…

---

## ["Parse line error: parsing docker timestamp: parsing time \\"\\" as \\"2006-01-02T15:04:05Z07:00\\": cannot parse \\"\\" as \\"2006\\"","service.name":"filebeat","ecs.version":"1.6.0"}](https://discuss.elastic.co/t/parse-line-error-parsing-docker-timestamp-parsing-time-as-2006-01-02t1505z07-00-cannot-parse-as-2006-service-name-filebeat-ecs-version-1-6-0/338920)

<div class="topic-metadata">

**Author:** [@dell2](https://discuss.elastic.co/u/dell2)\
**Replies:** 2\
**Last updated:** [August 10, 2023, 5:09pm UTC](https://discuss.elastic.co/t/parse-line-error-parsing-docker-timestamp-parsing-time-as-2006-01-02t1505z07-00-cannot-parse-as-2006-service-name-filebeat-ecs-version-1-6-0/338920 "2023-08-10T17:09:19Z")

</div>

filebeat.autodiscover: providers: - type: kubernetes hints.enabled: true json.message\_key: message json.timestamp.key: timestamp json.keys\_under\_root: true …

---

## [SIEM LAB02 Zeek instalation error](https://discuss.elastic.co/t/siem-lab02-zeek-instalation-error/340194)

<div class="topic-metadata">

**Author:** [@Renato\_Arraes](https://discuss.elastic.co/u/Renato_Arraes)\
**Replies:** 1\
**Last updated:** [August 10, 2023, 4:49pm UTC](https://discuss.elastic.co/t/siem-lab02-zeek-instalation-error/340194 "2023-08-10T16:49:09Z")

</div>

Course: Elastic Security Fundamentals: SIEM Version: current Question: On lab 2 during the installation of zeek, there's a point in wich is requested to run a zeek.sh file, but when i try to run it, i receive the error…

---

## [Daily dashboard with metrics from the last document](https://discuss.elastic.co/t/daily-dashboard-with-metrics-from-the-last-document/339963)

<div class="topic-metadata">

**Author:** [@gueri](https://discuss.elastic.co/u/gueri)\
**Replies:** 2\
**Last updated:** [August 10, 2023, 4:06pm UTC](https://discuss.elastic.co/t/daily-dashboard-with-metrics-from-the-last-document/339963 "2023-08-10T16:06:18Z")

</div>

Hello I'm trying to use Vega as a new tool for me in Kibana. I read some basics tutorials and tried some examples with my editor. It is a powerfull tool ! I already used Kibana lens charts for networks logs with billi…

---

## [Query for an event that happens X times within a given timerange](https://discuss.elastic.co/t/query-for-an-event-that-happens-x-times-within-a-given-timerange/340550)

<div class="topic-metadata">

**Author:** [@blacklistme](https://discuss.elastic.co/u/blacklistme)\
**Replies:** 3\
**Last updated:** [August 10, 2023, 3:17pm UTC](https://discuss.elastic.co/t/query-for-an-event-that-happens-x-times-within-a-given-timerange/340550 "2023-08-10T15:17:51Z")

</div>

Hi, as the title already suggests, I am looking for a way in Kibana to generate an Seucurity-Alert, if one event ouccures x times within a given timespan. Example: Five Failed logins on a system within 5 Minutes I´ve …

---

## [Urgent Query: Upgrading Kibana from version 7.9.0 to 8.9.0](https://discuss.elastic.co/t/urgent-query-upgrading-kibana-from-version-7-9-0-to-8-9-0/340561)

<div class="topic-metadata">

**Author:** [@Prathamesh\_S\_Pai](https://discuss.elastic.co/u/Prathamesh_S_Pai)\
**Replies:** 1\
**Last updated:** [August 10, 2023, 2:57pm UTC](https://discuss.elastic.co/t/urgent-query-upgrading-kibana-from-version-7-9-0-to-8-9-0/340561 "2023-08-10T14:57:57Z")

</div>

I have been using Kibana version 7.9.0 for my tasks. I would like to upgrade it to the latest version, 8.9.0, as some features supported by the latest version are urgently required. Could you please let me know if upgra…

---

## [ApiKey for a rule maker viewer](https://discuss.elastic.co/t/apikey-for-a-rule-maker-viewer/340573)

<div class="topic-metadata">

**Author:** [@A\_Mightiev](https://discuss.elastic.co/u/A_Mightiev)\
**Replies:** 1\
**Last updated:** [August 10, 2023, 2:41pm UTC](https://discuss.elastic.co/t/apikey-for-a-rule-maker-viewer/340573 "2023-08-10T14:41:20Z")

</div>

Hi I'm trying to create an apikey that would allow to create/view rules/alerts in kibana. I tried this restrictions but apparently they are not enough: { "kibana\_rulemaker": { "cluster": \[\], "indices": \[\], …

---

## [Logstash JSON Filter Error](https://discuss.elastic.co/t/logstash-json-filter-error/340496)

<div class="topic-metadata">

**Author:** [@wwalker](https://discuss.elastic.co/u/wwalker)\
**Replies:** 2\
**Last updated:** [August 10, 2023, 2:25pm UTC](https://discuss.elastic.co/t/logstash-json-filter-error/340496 "2023-08-10T14:25:22Z")

</div>

I've pulled data from a SQL database that gets put into a field like below. "assignment": \[ { "assignedto": "1234", "assignedtoname": "John Doe", "assignedgroupid": 1 } \] I'm…

---

## [Bucket Script in Composite Aggregation using Java client 8.8.2](https://discuss.elastic.co/t/bucket-script-in-composite-aggregation-using-java-client-8-8-2/340569)

<div class="topic-metadata">

**Author:** [@tcpeiris](https://discuss.elastic.co/u/tcpeiris)\
**Replies:** 0\
**Last updated:** [August 10, 2023, 2:08pm UTC](https://discuss.elastic.co/t/bucket-script-in-composite-aggregation-using-java-client-8-8-2/340569 "2023-08-10T14:08:39Z")

</div>

Java method should be written for the following ES query and I'm getting an error on script() function. "AVERAGE": { "bucket\_script": { "buckets\_path": { …

---

## [Updating every document to prepare for reindexing](https://discuss.elastic.co/t/updating-every-document-to-prepare-for-reindexing/340568)

<div class="topic-metadata">

**Author:** [@supernat10](https://discuss.elastic.co/u/supernat10)\
**Replies:** 0\
**Last updated:** [August 10, 2023, 1:53pm UTC](https://discuss.elastic.co/t/updating-every-document-to-prepare-for-reindexing/340568 "2023-08-10T13:53:09Z")

</div>

Hi, I am in the process of upgrading to the latest version of Elasticsearch, and during our reindex testing from the old cluster to the new one (as we are jumping from 6.8 to 8.x), we ran into a couple of issues with th…

[Previous page](https://discuss.elastic.co/latest.md?page=574)

[Next page](https://discuss.elastic.co/latest.md?page=576)
