# Latest

**URL:** https://discuss.elastic.co/latest.md?page=578

[Latest](https://discuss.elastic.co/latest.md) · [Categories](https://discuss.elastic.co/categories.md) · [Tags](https://discuss.elastic.co/tags.md)

**Page:** 579

---

## [How Elasticsearch works with OIDC realm](https://discuss.elastic.co/t/how-elasticsearch-works-with-oidc-realm/340442)

<div class="topic-metadata">

**Author:** [@Aniket\_Pant](https://discuss.elastic.co/u/Aniket_Pant)\
**Replies:** 0\
**Last updated:** [August 9, 2023, 9:10am UTC](https://discuss.elastic.co/t/how-elasticsearch-works-with-oidc-realm/340442 "2023-08-09T09:10:51Z")

</div>

Hi Team, Recently we have integrated Azure AD OIDC with Elasticsearch and kibana. The OP will provide the token to users of kibana User of kibana will present the token to elasticsearch for accessing the resources Ela…

---

## [Adding noeud for elasticsearch cluster](https://discuss.elastic.co/t/adding-noeud-for-elasticsearch-cluster/340441)

<div class="topic-metadata">

**Author:** [@Ali\_Trache](https://discuss.elastic.co/u/Ali_Trache)\
**Replies:** 0\
**Last updated:** [August 9, 2023, 9:09am UTC](https://discuss.elastic.co/t/adding-noeud-for-elasticsearch-cluster/340441 "2023-08-09T09:09:56Z")

</div>

hello community , i need help please , i had installer ELK stack in my virtuelle machine with one noeud ( elasticsearch , kibana , logstash) now i wish add a second noeud for my cluster so i had installed a second V…

---

## [PHP APM Agent](https://discuss.elastic.co/t/php-apm-agent/340436)

<div class="topic-metadata">

**Author:** [@gnom92](https://discuss.elastic.co/u/gnom92)\
**Replies:** 4\
**Last updated:** [August 9, 2023, 9:06am UTC](https://discuss.elastic.co/t/php-apm-agent/340436 "2023-08-09T09:06:57Z")

</div>

Hello, I see the PHP APM Agent is available on Linux OS only: Is there really no way to get it working on Windows server ? Or is there something equivalent for Windows OS ? Thanks,

---

## [Remove or edit connector settings](https://discuss.elastic.co/t/remove-or-edit-connector-settings/340429)

<div class="topic-metadata">

**Author:** [@Sheereen](https://discuss.elastic.co/u/Sheereen)\
**Replies:** 1\
**Last updated:** [August 9, 2023, 8:45am UTC](https://discuss.elastic.co/t/remove-or-edit-connector-settings/340429 "2023-08-09T08:45:10Z")

</div>

Hi, I added a Jira connector to workplace search, using add sources. I want to change the client Id and secret I had given at the time of configuring. How can I do the same? I did not find any option to edit the config…

---

## [App Search: Bug in Filebeat IP parsing](https://discuss.elastic.co/t/app-search-bug-in-filebeat-ip-parsing/339224)

<div class="topic-metadata">

**Author:** [@frederik1](https://discuss.elastic.co/u/frederik1)\
**Replies:** 2\
**Last updated:** [August 9, 2023, 8:30am UTC](https://discuss.elastic.co/t/app-search-bug-in-filebeat-ip-parsing/339224 "2023-08-09T08:30:04Z")

</div>

Dear Community, I currently have the problem that query and click data are not being included in ES. It turns out that this is due to Filebeat not being able to read the log file correctly. An error is thrown: \*\*Previe…

---

## [Logstash date filter](https://discuss.elastic.co/t/logstash-date-filter/340427)

<div class="topic-metadata">

**Author:** [@Neelam\_Zanvar](https://discuss.elastic.co/u/Neelam_Zanvar)\
**Replies:** 10\
**Last updated:** [August 9, 2023, 8:29am UTC](https://discuss.elastic.co/t/logstash-date-filter/340427 "2023-08-09T08:29:42Z")

</div>

Hi i have a short\_date field in the following format 09/Aug/2023:12:44:15 +0530 This field is created as text. To convert it to date i am doing the following date { match =\> \[ "short\_date", "dd/MMM/yyyy…

---

## [How to use predicate / expression with C# client](https://discuss.elastic.co/t/how-to-use-predicate-expression-with-c-client/340437)

<div class="topic-metadata">

**Author:** [@Daniel\_Dudek](https://discuss.elastic.co/u/Daniel_Dudek)\
**Replies:** 0\
**Last updated:** [August 9, 2023, 8:29am UTC](https://discuss.elastic.co/t/how-to-use-predicate-expression-with-c-client/340437 "2023-08-09T08:29:15Z")

</div>

Hi, I was looking for a solution to use expression with Elasticsearch C# client. I'm using the Elastic.Clients.Elasticsearch in 8.9.1 version. In my repository I have a specification (based on the specification design …

---

## [Unable to configure oracle stored procedure in logstash jdbc pipeline](https://discuss.elastic.co/t/unable-to-configure-oracle-stored-procedure-in-logstash-jdbc-pipeline/340369)

<div class="topic-metadata">

**Author:** [@Sreenivas1](https://discuss.elastic.co/u/Sreenivas1)\
**Replies:** 3\
**Last updated:** [August 9, 2023, 7:30am UTC](https://discuss.elastic.co/t/unable-to-configure-oracle-stored-procedure-in-logstash-jdbc-pipeline/340369 "2023-08-09T07:30:43Z")

</div>

Hi all, I'm trying to call stored procedure created in oracle database using logstash jdbc pipeline but even I tried with many ways to pass stored procedure in statement it's getting failed with sql error exceptions . …

---

## [Logstash @timestamp in the input file](https://discuss.elastic.co/t/logstash-timestamp-in-the-input-file/340426)

<div class="topic-metadata">

**Author:** [@Tal\_Blat](https://discuss.elastic.co/u/Tal_Blat)\
**Replies:** 0\
**Last updated:** [August 9, 2023, 7:18am UTC](https://discuss.elastic.co/t/logstash-timestamp-in-the-input-file/340426 "2023-08-09T07:18:37Z")

</div>

Hello What will happen if my input file contain a field called @timestamp ? will it replace the logstash @timestamp automatically ? thanks

---

## [How to make a text field aggregate-able in Kibana](https://discuss.elastic.co/t/how-to-make-a-text-field-aggregate-able-in-kibana/340107)

<div class="topic-metadata">

**Author:** [@Pratishruti](https://discuss.elastic.co/u/Pratishruti)\
**Replies:** 4\
**Last updated:** [August 9, 2023, 6:25am UTC](https://discuss.elastic.co/t/how-to-make-a-text-field-aggregate-able-in-kibana/340107 "2023-08-09T06:25:24Z")

</div>

Hi, I am using Kibana 6.8.1 version. We are using EFK. There is a text field name Message, I want to make visualization by using this field. However the field is not showing in option. I have tried to do it by assignin…

---

## [Synchronize distributed term frequencies on READ ONLY shards?](https://discuss.elastic.co/t/synchronize-distributed-term-frequencies-on-read-only-shards/340420)

<div class="topic-metadata">

**Author:** [@Yukha\_Dharmeswara](https://discuss.elastic.co/u/Yukha_Dharmeswara)\
**Replies:** 0\
**Last updated:** [August 9, 2023, 6:06am UTC](https://discuss.elastic.co/t/synchronize-distributed-term-frequencies-on-read-only-shards/340420 "2023-08-09T06:06:32Z")

</div>

Hello, I wonder if it is possible to synchronize shard's distributed term frequencies so we are able to reliably sort data by relevancenes when using search\_type=query\_then\_fetch? query\_then\_fetch vs dfs\_query\_then\_fet…

---

## [Document written by Watcher index action is not visible in KIBANA index](https://discuss.elastic.co/t/document-written-by-watcher-index-action-is-not-visible-in-kibana-index/340290)

<div class="topic-metadata">

**Author:** [@mrunalini](https://discuss.elastic.co/u/mrunalini)\
**Replies:** 3\
**Last updated:** [August 9, 2023, 5:34am UTC](https://discuss.elastic.co/t/document-written-by-watcher-index-action-is-not-visible-in-kibana-index/340290 "2023-08-09T05:34:09Z")

</div>

Hi Team, I have created watcher to calculate some time difference and put the document of some fields in index . My watcher is getting executed successfully , fields are created in kibana . but Data is not visible in …

---

## [ php client 7.17](https://discuss.elastic.co/t/php-client-7-17/340413)

<div class="topic-metadata">

**Author:** [@gihaka](https://discuss.elastic.co/u/gihaka)\
**Replies:** 0\
**Last updated:** [August 9, 2023, 2:55am UTC](https://discuss.elastic.co/t/php-client-7-17/340413 "2023-08-09T02:55:54Z")

</div>

Здравствуйте! Кто знает, может ли работать php client 7.17 с elastic 8.9? Сайт работает на пхп 7.2, больше поднять не возможно

---

## [We are looking for having search solution for platform contain data from multiple application. Our use case is providing exact search and recommendation. We are exploring best to suit and ES/Vespa is what in discussion](https://discuss.elastic.co/t/we-are-looking-for-having-search-solution-for-platform-contain-data-from-multiple-application-our-use-case-is-providing-exact-search-and-recommendation-we-are-exploring-best-to-suit-and-es-vespa-is-what-in-discussion/339984)

<div class="topic-metadata">

**Author:** [@Nik\_Ag](https://discuss.elastic.co/u/Nik_Ag)\
**Replies:** 1\
**Last updated:** [August 9, 2023, 2:55am UTC](https://discuss.elastic.co/t/we-are-looking-for-having-search-solution-for-platform-contain-data-from-multiple-application-our-use-case-is-providing-exact-search-and-recommendation-we-are-exploring-best-to-suit-and-es-vespa-is-what-in-discussion/339984 "2023-08-09T02:55:39Z")

</div>

What difference between Vespa and ES? For longer term which would be better to choose? Elastic coming up with Elser model will it be available for GA if so, when?

---

## [Rejected execution of primary operation](https://discuss.elastic.co/t/rejected-execution-of-primary-operation/340391)

<div class="topic-metadata">

**Author:** [@yuswanul](https://discuss.elastic.co/u/yuswanul)\
**Replies:** 4\
**Last updated:** [August 9, 2023, 2:27am UTC](https://discuss.elastic.co/t/rejected-execution-of-primary-operation/340391 "2023-08-09T02:27:23Z")

</div>

Hi there, sometimes my logstash had printed the log that said "rejected execution of primary operation" with the error type "es\_rejected\_execution\_exception" can anyone explain to me what's going on actually? Thanks

---

## [Php client 7.17 for elastic 8.9 (client for php 7.2)](https://discuss.elastic.co/t/php-client-7-17-for-elastic-8-9-client-for-php-7-2/340406)

<div class="topic-metadata">

**Author:** [@vt\_g](https://discuss.elastic.co/u/vt_g)\
**Replies:** 0\
**Last updated:** [August 8, 2023, 9:08pm UTC](https://discuss.elastic.co/t/php-client-7-17-for-elastic-8-9-client-for-php-7-2/340406 "2023-08-08T21:08:09Z")

</div>

Hello! Who knows if php client 7.17 can work with elastic 8.9? The site works on PHP 7.2, it is not possible to upload more Thank you!

---

## [Why IDs query expands to terms query?](https://discuss.elastic.co/t/why-ids-query-expands-to-terms-query/340410)

<div class="topic-metadata">

**Author:** [@etki](https://discuss.elastic.co/u/etki)\
**Replies:** 0\
**Last updated:** [August 9, 2023, 12:53am UTC](https://discuss.elastic.co/t/why-ids-query-expands-to-terms-query/340410 "2023-08-09T00:53:25Z")

</div>

So i was poking around sources and looks like ids query doesn't do much by itself: protected Query doToQuery(SearchExecutionContext context) throws IOException { MappedFieldType idField = context.getFieldTyp…

---

## [Using Fingerprint on metricbeat](https://discuss.elastic.co/t/using-fingerprint-on-metricbeat/339584)

<div class="topic-metadata">

**Author:** [@yuswanul](https://discuss.elastic.co/u/yuswanul)\
**Replies:** 16\
**Last updated:** [August 9, 2023, 12:16am UTC](https://discuss.elastic.co/t/using-fingerprint-on-metricbeat/339584 "2023-08-09T00:16:12Z")

</div>

Hi there i'm trying to send data using metricbeat here v8.8.2 and i'm trying to use fingerprint as replacement of certificate\_authorities but i got an error like this {"log.level":"warn","@timestamp":"2023-07-29T07:26:…

---

## [Curator 7.0](https://discuss.elastic.co/t/curator-7-0/340407)

<div class="topic-metadata">

**Author:** [@Leandro\_Nieva](https://discuss.elastic.co/u/Leandro_Nieva)\
**Replies:** 0\
**Last updated:** [August 8, 2023, 9:11pm UTC](https://discuss.elastic.co/t/curator-7-0/340407 "2023-08-08T21:11:51Z")

</div>

Estoy arrancando con Curator y tengo un inconveniente, deseo realizar un snapshot de cada índice de wazuh dia a dia, el cual me esta tomando 36 indices al generar la tarea. Dejo el detalle de mi accion y de lo que realiz…

---

## [Elasticsearch Java API client 8.7.1, No Option available to generate the correct format for source ordering for composition aggregation](https://discuss.elastic.co/t/elasticsearch-java-api-client-8-7-1-no-option-available-to-generate-the-correct-format-for-source-ordering-for-composition-aggregation/337477)

<div class="topic-metadata">

**Author:** [@ramyogi](https://discuss.elastic.co/u/ramyogi)\
**Replies:** 12\
**Last updated:** [August 8, 2023, 8:39pm UTC](https://discuss.elastic.co/t/elasticsearch-java-api-client-8-7-1-no-option-available-to-generate-the-correct-format-for-source-ordering-for-composition-aggregation/337477 "2023-08-08T20:39:45Z")

</div>

Elasticsearch Java API client 8.7.1 does not have option to supply order for the composite term aggregation but it was available server lib. Query runs fine in KIBANA but cannot build same in Java client library {"from…

---

## [Logstash: MalformedCSVError](https://discuss.elastic.co/t/logstash-malformedcsverror/340330)

<div class="topic-metadata">

**Author:** [@benhartwich](https://discuss.elastic.co/u/benhartwich)\
**Replies:** 9\
**Last updated:** [August 8, 2023, 8:20pm UTC](https://discuss.elastic.co/t/logstash-malformedcsverror/340330 "2023-08-08T20:20:56Z")

</div>

Hi, can anybody help me to find the right mutate =\> gsub definition to avoid these warnings / errors: \[WARN \] 2023-08-08 07:05:15.003 \[\[main\]\>worker20\] csv - Error parsing csv {:field=\>"message", :source=\>"16600,26200,…

---

## [Create empty field in report / upload comments from excel](https://discuss.elastic.co/t/create-empty-field-in-report-upload-comments-from-excel/340006)

<div class="topic-metadata">

**Author:** [@Valerija](https://discuss.elastic.co/u/Valerija)\
**Replies:** 6\
**Last updated:** [August 8, 2023, 8:00pm UTC](https://discuss.elastic.co/t/create-empty-field-in-report-upload-comments-from-excel/340006 "2023-08-08T20:00:04Z")

</div>

Hello, I am supposed to create three empty columns in existing report and give possibility to users to upload comments in those columns from excel. I would appreciate if someone could tell me if this is feasible and…

---

## [Search where inside array ( like , search where in ) inside nested](https://discuss.elastic.co/t/search-where-inside-array-like-search-where-in-inside-nested/340307)

<div class="topic-metadata">

**Author:** [@Murilo\_Livorato](https://discuss.elastic.co/u/Murilo_Livorato)\
**Replies:** 2\
**Last updated:** [August 8, 2023, 7:10pm UTC](https://discuss.elastic.co/t/search-where-inside-array-like-search-where-in-inside-nested/340307 "2023-08-08T19:10:59Z")

</div>

hello , I have a nested search . It is working like this - GET /products/\_search { "size": 100, "query": { "bool": { "must": \[ { "nested": { "path": "owner", "query": { …

---

## [Document level permissions/security with signed search keys also for Elasticsearch indices](https://discuss.elastic.co/t/document-level-permissions-security-with-signed-search-keys-also-for-elasticsearch-indices/338420)

<div class="topic-metadata">

**Author:** [@sebastianboelling](https://discuss.elastic.co/u/sebastianboelling)\
**Replies:** 3\
**Last updated:** [August 8, 2023, 7:47pm UTC](https://discuss.elastic.co/t/document-level-permissions-security-with-signed-search-keys-also-for-elasticsearch-indices/338420 "2023-08-08T19:47:53Z")

</div>

Hi, I've read the documentation how to leverage Workplace Search document-level permissions in app search engine using a signed search key. Leverage Workplace Search document-level permissions in your search engine | E…

---

## [Query Kibana for strings WITHOUT commas?](https://discuss.elastic.co/t/query-kibana-for-strings-without-commas/340396)

<div class="topic-metadata">

**Author:** [@LogsandParsers](https://discuss.elastic.co/u/LogsandParsers)\
**Replies:** 1\
**Last updated:** [August 8, 2023, 7:22pm UTC](https://discuss.elastic.co/t/query-kibana-for-strings-without-commas/340396 "2023-08-08T19:22:25Z")

</div>

Hi all, I have a field on Kibana that has long text string values. Sometimes, these values contain commas and sometimes they do not. I want to search on Kibana for any of these values that DO NOT contain commas in the s…

---

## [XContentBuilder](https://discuss.elastic.co/t/xcontentbuilder/340399)

<div class="topic-metadata">

**Author:** [@toddcarv](https://discuss.elastic.co/u/toddcarv)\
**Replies:** 0\
**Last updated:** [August 8, 2023, 7:19pm UTC](https://discuss.elastic.co/t/xcontentbuilder/340399 "2023-08-08T19:19:00Z")

</div>

With the HLRC we were able to use XContentBuilder. For example: XContentBuilder xContentBuilder = // create XContentBuilder; IndexRequest request = new IndexRequest("index").id(id).source(xContentBuilder); Basically we…

---

## [If statement in winlogbeat configuration](https://discuss.elastic.co/t/if-statement-in-winlogbeat-configuration/340393)

<div class="topic-metadata">

**Author:** [@msylvestre](https://discuss.elastic.co/u/msylvestre)\
**Replies:** 2\
**Last updated:** [August 8, 2023, 6:44pm UTC](https://discuss.elastic.co/t/if-statement-in-winlogbeat-configuration/340393 "2023-08-08T18:44:35Z")

</div>

Hello, I'm trying to add an IF statement in my winlogbeat configuration, but I can't figure out how. Basically I have a field named token that I need to changed based on the agent\_name. What am I missing? #############…

---

## [Backfill old data for integration in elastic-agent integration](https://discuss.elastic.co/t/backfill-old-data-for-integration-in-elastic-agent-integration/340387)

<div class="topic-metadata">

**Author:** [@liquidkite](https://discuss.elastic.co/u/liquidkite)\
**Replies:** 1\
**Last updated:** [August 8, 2023, 5:16pm UTC](https://discuss.elastic.co/t/backfill-old-data-for-integration-in-elastic-agent-integration/340387 "2023-08-08T17:16:13Z")

</div>

Hello all, I've been using elastic agent to fetch logs from a variety of data sources. We ran into an issue where there was a misconfiguration with the pipeline and that caused to drop logs for that timeframe. Once the …

---

## [NameError with Cloudwatch plugin in logstash](https://discuss.elastic.co/t/nameerror-with-cloudwatch-plugin-in-logstash/340388)

<div class="topic-metadata">

**Author:** [@rmunjuluri](https://discuss.elastic.co/u/rmunjuluri)\
**Replies:** 0\
**Last updated:** [August 8, 2023, 4:13pm UTC](https://discuss.elastic.co/t/nameerror-with-cloudwatch-plugin-in-logstash/340388 "2023-08-08T16:13:33Z")

</div>

Hi, I am trying to pull Cloudwatch logs (specifically EC2 status) into Logstash. I can retrieve the status using AWS\_CLI, but the CloudWatch plugin throws the following error: Pipeline\_id:main Plugin: \<LogStash::Input…

---

## [Need help creating advanced watcher](https://discuss.elastic.co/t/need-help-creating-advanced-watcher/340384)

<div class="topic-metadata">

**Author:** [@RJC](https://discuss.elastic.co/u/RJC)\
**Replies:** 1\
**Last updated:** [August 8, 2023, 3:45pm UTC](https://discuss.elastic.co/t/need-help-creating-advanced-watcher/340384 "2023-08-08T15:45:15Z")

</div>

I am new to Watchers and Elasticsearch API. I need to create an email alert that will notify me if someone inserts an unauthorized mass storage device into a USB slot of Windows machines. The watcher needs to query even…

[Previous page](https://discuss.elastic.co/latest.md?page=577)

[Next page](https://discuss.elastic.co/latest.md?page=579)
