# Latest

**URL:** https://discuss.elastic.co/latest.md?page=579

[Latest](https://discuss.elastic.co/latest.md) · [Categories](https://discuss.elastic.co/categories.md) · [Tags](https://discuss.elastic.co/tags.md)

**Page:** 580

---

## [What is difference between Elastic Agent and Beat?](https://discuss.elastic.co/t/what-is-difference-between-elastic-agent-and-beat/340383)

<div class="topic-metadata">

**Author:** [@musialny](https://discuss.elastic.co/u/musialny)\
**Replies:** 3\
**Last updated:** [August 8, 2023, 3:28pm UTC](https://discuss.elastic.co/t/what-is-difference-between-elastic-agent-and-beat/340383 "2023-08-08T15:28:51Z")

</div>

What is difference between Elastic Agent and Beat?

---

## [Run\_from config](https://discuss.elastic.co/t/run-from-config/340378)

<div class="topic-metadata">

**Author:** [@wwalker](https://discuss.elastic.co/u/wwalker)\
**Replies:** 1\
**Last updated:** [August 8, 2023, 2:38pm UTC](https://discuss.elastic.co/t/run-from-config/340378 "2023-08-08T14:38:19Z")

</div>

Simple question here, if I have 10 different monitors setup on a single agent, do I have to duplicate the run\_from section (example below) and specify the id for each of them, or if I exclude the id field, will the run\_f…

---

## [I am trying to execute bulk query using Postman but getting an Error](https://discuss.elastic.co/t/i-am-trying-to-execute-bulk-query-using-postman-but-getting-an-error/340332)

<div class="topic-metadata">

**Author:** [@Subrato1](https://discuss.elastic.co/u/Subrato1)\
**Replies:** 3\
**Last updated:** [August 8, 2023, 2:33pm UTC](https://discuss.elastic.co/t/i-am-trying-to-execute-bulk-query-using-postman-but-getting-an-error/340332 "2023-08-08T14:33:05Z")

</div>

PUT /library/\_bulk?refresh {"index":{"\_id": "Leviathan Wakes"}} {"name": "Leviathan Wakes", "author": "James S.A. Corey", "release\_date": "2011-06-02", "page\_count": 561} {"index":{"\_id": "Hyperion"}} {"name": "Hyperion"…

---

## [LABs 5.4. petclinic-react does not show up, CORS policy error on PetClinic page](https://discuss.elastic.co/t/labs-5-4-petclinic-react-does-not-show-up-cors-policy-error-on-petclinic-page/339907)

<div class="topic-metadata">

**Author:** [@Renata](https://discuss.elastic.co/u/Renata)\
**Replies:** 7\
**Last updated:** [August 8, 2023, 2:31pm UTC](https://discuss.elastic.co/t/labs-5-4-petclinic-react-does-not-show-up-cors-policy-error-on-petclinic-page/339907 "2023-08-08T14:31:37Z")

</div>

Course: Elastic Observability Engineer Version: 7.9 Hello, I cannot figure out how to solve this. I all the steps in 5.4. seem to be successful but at the end petclinic-react does not show up on Elastic APM. Chrome D…

---

## [Could not index event to Elasticsearch](https://discuss.elastic.co/t/could-not-index-event-to-elasticsearch/339545)

<div class="topic-metadata">

**Author:** [@lduvnjak](https://discuss.elastic.co/u/lduvnjak)\
**Replies:** 4\
**Last updated:** [August 8, 2023, 1:53pm UTC](https://discuss.elastic.co/t/could-not-index-event-to-elasticsearch/339545 "2023-08-08T13:53:56Z")

</div>

Hey Everyone, I'm having some issues trying to get APM logs to Elasticsearch going through Logstash. Since it's a POC I'm using the Logstash JVM to test it out. ELK version is 8.8.1, that includes the APM server. APM …

---

## [Upgrading to a patch version resulting in replication failure?](https://discuss.elastic.co/t/upgrading-to-a-patch-version-resulting-in-replication-failure/340374)

<div class="topic-metadata">

**Author:** [@jaykb77](https://discuss.elastic.co/u/jaykb77)\
**Replies:** 2\
**Last updated:** [August 8, 2023, 1:30pm UTC](https://discuss.elastic.co/t/upgrading-to-a-patch-version-resulting-in-replication-failure/340374 "2023-08-08T13:30:41Z")

</div>

Hi all, We recently tried to upgrade from 7.17.0 -\> 7.17.8 in a rolling way, but in the middle of the upgrade we found replication error. explanation" : "cannot allocate replica shard to a node with version \[7.17.0\] si…

---

## [EQL query to alert 1 alert per each user](https://discuss.elastic.co/t/eql-query-to-alert-1-alert-per-each-user/339539)

<div class="topic-metadata">

**Author:** [@yzaritskyi](https://discuss.elastic.co/u/yzaritskyi)\
**Replies:** 2\
**Last updated:** [August 8, 2023, 1:15pm UTC](https://discuss.elastic.co/t/eql-query-to-alert-1-alert-per-each-user/339539 "2023-08-08T13:15:08Z")

</div>

Hello all! I'd like to create a Rule based on the EQL query that will trigger an alert only once per user. For example: The input list of logs is user1 ip1 user1 ip1 user2 ip2 user5 ip5 user4 ip4 user4 ip4 user…

---

## [Different Dashboard views for different entities](https://discuss.elastic.co/t/different-dashboard-views-for-different-entities/340375)

<div class="topic-metadata">

**Author:** [@Marian\_Abou\_fares](https://discuss.elastic.co/u/Marian_Abou_fares)\
**Replies:** 0\
**Last updated:** [August 8, 2023, 1:13pm UTC](https://discuss.elastic.co/t/different-dashboard-views-for-different-entities/340375 "2023-08-08T13:13:21Z")

</div>

I have different stores that can access only certain parts of a dashboard. for instance each department can view only performance of its employees. How can I implement this authentication on Kibana? I dont have the " cre…

---

## [Elastic Package custom integration testing network issues](https://discuss.elastic.co/t/elastic-package-custom-integration-testing-network-issues/340372)

<div class="topic-metadata">

**Author:** [@popeio](https://discuss.elastic.co/u/popeio)\
**Replies:** 1\
**Last updated:** [August 8, 2023, 1:02pm UTC](https://discuss.elastic.co/t/elastic-package-custom-integration-testing-network-issues/340372 "2023-08-08T13:02:36Z")

</div>

Hey Community, I'm facing some issues with testing a simple integration for ingesting logs from a peculiar service into the stack via a custom Elastic Agent integration. I've followed all recommendations, and my custom…

---

## [New Java API Client GetResponse](https://discuss.elastic.co/t/new-java-api-client-getresponse/340287)

<div class="topic-metadata">

**Author:** [@toddcarv](https://discuss.elastic.co/u/toddcarv)\
**Replies:** 8\
**Last updated:** [August 8, 2023, 12:35pm UTC](https://discuss.elastic.co/t/new-java-api-client-getresponse/340287 "2023-08-08T12:35:40Z")

</div>

The HLRC provided getSourceAsMap in GetResponse. I'm trying to get the source as a map. How do I do this with the new client? Thanks.

---

## [Logstash troubleshooting](https://discuss.elastic.co/t/logstash-troubleshooting/340115)

<div class="topic-metadata">

**Author:** [@sta02](https://discuss.elastic.co/u/sta02)\
**Replies:** 1\
**Last updated:** [August 8, 2023, 12:33pm UTC](https://discuss.elastic.co/t/logstash-troubleshooting/340115 "2023-08-08T12:33:35Z")

</div>

Hello, We have logstash performing dual feed. The first output writes to Elastic and the second output writes to Azure Sentinel. There is a clear delta in number of logs sent to Azure Sentinel and Elastic. Elastic rece…

---

## [Lucene query](https://discuss.elastic.co/t/lucene-query/340367)

<div class="topic-metadata">

**Author:** [@ZahraZare](https://discuss.elastic.co/u/ZahraZare)\
**Replies:** 0\
**Last updated:** [August 8, 2023, 12:18pm UTC](https://discuss.elastic.co/t/lucene-query/340367 "2023-08-08T12:18:41Z")

</div>

The following document is from the "mart-index" index in Elasticsearch. I want to use this index as a data source in Grafana 9. I want to have only "IS\_AVAILABLE" and "GPRS\_CNT" values from "DTLS\_MA" object as table colu…

---

## [Bug: APM Java - Springboot, v1.39.0+ - No JVM Metrics Found](https://discuss.elastic.co/t/bug-apm-java-springboot-v1-39-0-no-jvm-metrics-found/339104)

<div class="topic-metadata">

**Author:** [@6fears7](https://discuss.elastic.co/u/6fears7)\
**Replies:** 13\
**Last updated:** [August 8, 2023, 12:10pm UTC](https://discuss.elastic.co/t/bug-apm-java-springboot-v1-39-0-no-jvm-metrics-found/339104 "2023-08-08T12:10:44Z")

</div>

After reviewing the following post and appropriate GitHub issue, utilizing the Java APM agent on versions 1.39.0+ (including 1.40.0), JVM Metrics fail to display in the Metrics tab of APM. Below is an example of me swapp…

---

## [ESXI to ELK](https://discuss.elastic.co/t/esxi-to-elk/340366)

<div class="topic-metadata">

**Author:** [@lliadan](https://discuss.elastic.co/u/lliadan)\
**Replies:** 0\
**Last updated:** [August 8, 2023, 12:06pm UTC](https://discuss.elastic.co/t/esxi-to-elk/340366 "2023-08-08T12:06:04Z")

</div>

Hi ! I'm setting up an ELK server in my company to receive connection logs. My server is ready and operational. I still have one machine to do, but I confess I'm stuck. I need to get the logs from the ESXI server, and…

---

## [99.9 / Custom percentiles?](https://discuss.elastic.co/t/99-9-custom-percentiles/340346)

<div class="topic-metadata">

**Author:** [@georgms](https://discuss.elastic.co/u/georgms)\
**Replies:** 1\
**Last updated:** [August 8, 2023, 12:04pm UTC](https://discuss.elastic.co/t/99-9-custom-percentiles/340346 "2023-08-08T12:04:17Z")

</div>

In the Elastic APM dashboard latencies can be displayed as average, 95 percentile or 99 percentile: Additionally, we would like to be able to display the 99.9 percentile and use that in SLOs / alerts as well. Can thi…

---

## [Change field name instead of requirement field](https://discuss.elastic.co/t/change-field-name-instead-of-requirement-field/340353)

<div class="topic-metadata">

**Author:** [@younus](https://discuss.elastic.co/u/younus)\
**Replies:** 0\
**Last updated:** [August 8, 2023, 10:16am UTC](https://discuss.elastic.co/t/change-field-name-instead-of-requirement-field/340353 "2023-08-08T10:16:23Z")

</div>

i want to change the field name agent.ephemeral\_id instead of ELK\_Id.

---

## [See duplicate transaction with same date and time](https://discuss.elastic.co/t/see-duplicate-transaction-with-same-date-and-time/340340)

<div class="topic-metadata">

**Author:** [@younus](https://discuss.elastic.co/u/younus)\
**Replies:** 3\
**Last updated:** [August 8, 2023, 10:04am UTC](https://discuss.elastic.co/t/see-duplicate-transaction-with-same-date-and-time/340340 "2023-08-08T10:04:24Z")

</div>

See duplicate transaction with same date and time .

---

## [How the upsert script will work in elastci search](https://discuss.elastic.co/t/how-the-upsert-script-will-work-in-elastci-search/340352)

<div class="topic-metadata">

**Author:** [@Sukhdeob\_95](https://discuss.elastic.co/u/Sukhdeob_95)\
**Replies:** 1\
**Last updated:** [August 8, 2023, 9:57am UTC](https://discuss.elastic.co/t/how-the-upsert-script-will-work-in-elastci-search/340352 "2023-08-08T09:57:57Z")

</div>

Here is my logstash config file . In the output plugin I have added upsert script it compare the ingestionHash value with old documentation ingestionHash value. If the document\_id doesn't exist (new document ie 1st ti…

---

## [Visualization not working in Canvas, once some other timestamp field is selected in time filter column](https://discuss.elastic.co/t/visualization-not-working-in-canvas-once-some-other-timestamp-field-is-selected-in-time-filter-column/340351)

<div class="topic-metadata">

**Author:** [@mathur7vidit](https://discuss.elastic.co/u/mathur7vidit)\
**Replies:** 0\
**Last updated:** [August 8, 2023, 9:55am UTC](https://discuss.elastic.co/t/visualization-not-working-in-canvas-once-some-other-timestamp-field-is-selected-in-time-filter-column/340351 "2023-08-08T09:55:16Z")

</div>

Hi Team, we have index where sorting is done based on modified\_date instead of @timestamp. we have selected the same in time filter as well. now when we are trying to create a visualization in Canvas, its throwing e…

---

## [Perform CRUD Operation on Elasticsearch With REST API](https://discuss.elastic.co/t/perform-crud-operation-on-elasticsearch-with-rest-api/340329)

<div class="topic-metadata">

**Author:** [@Debasis\_Mallick](https://discuss.elastic.co/u/Debasis_Mallick)\
**Replies:** 5\
**Last updated:** [August 8, 2023, 9:48am UTC](https://discuss.elastic.co/t/perform-crud-operation-on-elasticsearch-with-rest-api/340329 "2023-08-08T09:48:37Z")

</div>

Hi Team, Could anyone share how to perform CRUD operation in Elastic search with REST API. I had tried the below one with the curl command but getting error as "curl: (52) Empty reply from server" . Could you please gui…

---

## [Possible Feature Request: Redis Authentication with Username/Password](https://discuss.elastic.co/t/possible-feature-request-redis-authentication-with-username-password/340349)

<div class="topic-metadata">

**Author:** [@alces](https://discuss.elastic.co/u/alces)\
**Replies:** 0\
**Last updated:** [August 8, 2023, 9:25am UTC](https://discuss.elastic.co/t/possible-feature-request-redis-authentication-with-username-password/340349 "2023-08-08T09:25:01Z")

</div>

Hi everyone. We are planing to use redis between beats and logstash as a buffer for high utilization timespots. In this setup currently there is only a "password" option for the redis output/input plugin, so every part…

---

## [// "reason": "Arrays (returned by \[ss\]) are not supported"](https://discuss.elastic.co/t/reason-arrays-returned-by-ss-are-not-supported/340136)

<div class="topic-metadata">

**Author:** [@fangyan](https://discuss.elastic.co/u/fangyan)\
**Replies:** 2\
**Last updated:** [August 8, 2023, 9:21am UTC](https://discuss.elastic.co/t/reason-arrays-returned-by-ss-are-not-supported/340136 "2023-08-08T09:21:00Z")

</div>

Elasticsearch updated version to 8.9, using SQL function, found abnormal collection data reports. Has anyone encountered them?

---

## [ECK fleet-server-agent errors after adding "policyID: eck-fleet-server"](https://discuss.elastic.co/t/eck-fleet-server-agent-errors-after-adding-policyid-eck-fleet-server/340347)

<div class="topic-metadata">

**Author:** [@khteh](https://discuss.elastic.co/u/khteh)\
**Replies:** 0\
**Last updated:** [August 8, 2023, 9:18am UTC](https://discuss.elastic.co/t/eck-fleet-server-agent-errors-after-adding-policyid-eck-fleet-server/340347 "2023-08-08T09:18:04Z")

</div>

Hit the following errors after adding the suggested configuration according to https://www.elastic.co/guide/en/cloud-on-k8s/current/k8s-elastic-agent-fleet-quickstart.html: {"log.level":"error","@timestamp":"2023-08-08T…

---

## [Purge index](https://discuss.elastic.co/t/purge-index/340265)

<div class="topic-metadata">

**Author:** [@Hanni](https://discuss.elastic.co/u/Hanni)\
**Replies:** 13\
**Last updated:** [August 8, 2023, 9:14am UTC](https://discuss.elastic.co/t/purge-index/340265 "2023-08-08T09:14:40Z")

</div>

hello, I would like to purge my data from my indexes in elasticsearch. I'd like to know how to do this without having to delete my index. How can I achieve that?

---

## [Send custom logs to elasticsearch with predefined list of fields](https://discuss.elastic.co/t/send-custom-logs-to-elasticsearch-with-predefined-list-of-fields/338681)

<div class="topic-metadata">

**Author:** [@Johannnnnn](https://discuss.elastic.co/u/Johannnnnn)\
**Replies:** 2\
**Last updated:** [August 8, 2023, 8:43am UTC](https://discuss.elastic.co/t/send-custom-logs-to-elasticsearch-with-predefined-list-of-fields/338681 "2023-08-08T08:43:40Z")

</div>

Disclaimer: I am very confused about filebeat help files. If I need anything more technical than sending a log line to elasticsearch, it does not explain anything. It just states options and leaves me to find out which o…

---

## [Elasticsearch upgrade from 7.17 to 8.x](https://discuss.elastic.co/t/elasticsearch-upgrade-from-7-17-to-8-x/340338)

<div class="topic-metadata">

**Author:** [@jaykb77](https://discuss.elastic.co/u/jaykb77)\
**Replies:** 1\
**Last updated:** [August 8, 2023, 8:16am UTC](https://discuss.elastic.co/t/elasticsearch-upgrade-from-7-17-to-8-x/340338 "2023-08-08T08:16:39Z")

</div>

Hi all, We are planning to upgrade our elasticsearch cluster from 7.17.x to 8.X. Apart from general upgrade recommendations from elastic, is there a specific 8.X version that we should be upgrading to?

---

## [Error on lifecycle policy alias](https://discuss.elastic.co/t/error-on-lifecycle-policy-alias/340337)

<div class="topic-metadata">

**Author:** [@fribse](https://discuss.elastic.co/u/fribse)\
**Replies:** 0\
**Last updated:** [August 8, 2023, 8:09am UTC](https://discuss.elastic.co/t/error-on-lifecycle-policy-alias/340337 "2023-08-08T08:09:00Z")

</div>

I wasn't aware of the alias requirement on lifecycle management, so now I have a ton of data imported, on indexes with this pattern based on an index template: dmarc-7.17.4-2023.08 Where the version, year and month var…

---

## [Visualisation based on multiple fields](https://discuss.elastic.co/t/visualisation-based-on-multiple-fields/340333)

<div class="topic-metadata">

**Author:** [@Zuhaib\_Ul\_Zaman](https://discuss.elastic.co/u/Zuhaib_Ul_Zaman)\
**Replies:** 0\
**Last updated:** [August 8, 2023, 7:32am UTC](https://discuss.elastic.co/t/visualisation-based-on-multiple-fields/340333 "2023-08-08T07:32:38Z")

</div>

{ "Name1":{ "total" : 500, "subname1":{ "total":250, "cpu" : 100 }, "subname2" : { "total" : 250, "cpu" : 10000 } }, "Name2":{ "total":25, "subname1" : { "total" : 25, "cpu" : 10 }, …

---

## [Group by id base of sum of range of value](https://discuss.elastic.co/t/group-by-id-base-of-sum-of-range-of-value/340322)

<div class="topic-metadata">

**Author:** [@Suresh\_Ghatuwa](https://discuss.elastic.co/u/Suresh_Ghatuwa)\
**Replies:** 4\
**Last updated:** [August 8, 2023, 8:05am UTC](https://discuss.elastic.co/t/group-by-id-base-of-sum-of-range-of-value/340322 "2023-08-08T08:05:45Z")

</div>

I had some data as below: \[ { "PAY\_DATE": "2019-10-24", "STATE": "Utah", "id": "1", "SALARY": 6045, "UUID": "a879492b-b402-40bd-8f5d-afc34d66d152" }, { "PAY\_DATE": "2021-01-17", "STATE"…

---

## [Filebeat in docker, permission denied when trying to place registry on the host](https://discuss.elastic.co/t/filebeat-in-docker-permission-denied-when-trying-to-place-registry-on-the-host/339694)

<div class="topic-metadata">

**Author:** [@fribse](https://discuss.elastic.co/u/fribse)\
**Replies:** 3\
**Last updated:** [August 8, 2023, 7:59am UTC](https://discuss.elastic.co/t/filebeat-in-docker-permission-denied-when-trying-to-place-registry-on-the-host/339694 "2023-08-08T07:59:55Z")

</div>

I would like to move the registry outside the filebeat folder, to be able to easy kill it. I have this config file: filebeat\_for\_dmarc: image: docker.elastic.co/beats/filebeat:${STACK\_VERSION} container\_name:…

[Previous page](https://discuss.elastic.co/latest.md?page=578)

[Next page](https://discuss.elastic.co/latest.md?page=580)
