# Latest

**URL:** https://discuss.elastic.co/latest.md?page=582

[Latest](https://discuss.elastic.co/latest.md) · [Categories](https://discuss.elastic.co/categories.md) · [Tags](https://discuss.elastic.co/tags.md)

**Page:** 583

---

## [Issue with metricbeat kibana module when using custom path for Kibana](https://discuss.elastic.co/t/issue-with-metricbeat-kibana-module-when-using-custom-path-for-kibana/338976)

<div class="topic-metadata">

**Author:** [@Pierig\_Le\_Saux](https://discuss.elastic.co/u/Pierig_Le_Saux)\
**Replies:** 4\
**Last updated:** [August 5, 2023, 1:30am UTC](https://discuss.elastic.co/t/issue-with-metricbeat-kibana-module-when-using-custom-path-for-kibana/338976 "2023-08-05T01:30:47Z")

</div>

My kibana setup uses SERVER\_PUBLICBASEURL = http://www.example.com/kibana SERVER\_BASEPATH = /kibana SERVER\_REWRITEBASEPATH = "true" My metricbeat autodiscovery for the kibana module uses: - condition: contains: …

---

## [How to apply filter(s) to all the embedded iframe visuals](https://discuss.elastic.co/t/how-to-apply-filter-s-to-all-the-embedded-iframe-visuals/340071)

<div class="topic-metadata">

**Author:** [@Amphagory](https://discuss.elastic.co/u/Amphagory)\
**Replies:** 8\
**Last updated:** [August 5, 2023, 1:11am UTC](https://discuss.elastic.co/t/how-to-apply-filter-s-to-all-the-embedded-iframe-visuals/340071 "2023-08-05T01:11:26Z")

</div>

I would like to embed visuals into a webpage. I guess I can use a dashboard to have a filter applied to all the visuals, but I was wondering if I only had a bunch of visuals on a webpage, is it possible to have a filter…

---

## [Elasticsearch search based on term position and fuzzy](https://discuss.elastic.co/t/elasticsearch-search-based-on-term-position-and-fuzzy/340163)

<div class="topic-metadata">

**Author:** [@JohnsM](https://discuss.elastic.co/u/JohnsM)\
**Replies:** 0\
**Last updated:** [August 4, 2023, 10:39pm UTC](https://discuss.elastic.co/t/elasticsearch-search-based-on-term-position-and-fuzzy/340163 "2023-08-04T22:39:30Z")

</div>

I am a beginner in Elasticsearch and I try to combine a query with term position and fuzzy and the results are not what I expected. I tried this query { "query": { "bool": { "must": \[ …

---

## [How to use event.set to get the values of a variable?](https://discuss.elastic.co/t/how-to-use-event-set-to-get-the-values-of-a-variable/340155)

<div class="topic-metadata">

**Author:** [@mohsin106](https://discuss.elastic.co/u/mohsin106)\
**Replies:** 1\
**Last updated:** [August 4, 2023, 10:34pm UTC](https://discuss.elastic.co/t/how-to-use-event-set-to-get-the-values-of-a-variable/340155 "2023-08-04T22:34:59Z")

</div>

I'm using Kafka's input plugin within my logstash pipline and I have enabled decorated\_events =\> true If I want to get the kafka topic and partition names I can do this: mutate { add\_field =\> { "\[topic\_na…

---

## [Monitor users (requests, CPU usage, etc.)](https://discuss.elastic.co/t/monitor-users-requests-cpu-usage-etc/340018)

<div class="topic-metadata">

**Author:** [@GinkoLucas](https://discuss.elastic.co/u/GinkoLucas)\
**Replies:** 1\
**Last updated:** [August 4, 2023, 7:23pm UTC](https://discuss.elastic.co/t/monitor-users-requests-cpu-usage-etc/340018 "2023-08-04T19:23:28Z")

</div>

Hello, I'd like to be able to find out what my users are doing, and more specifically list the users who are consuming CPU, consult the list of "big" requests and the linked user. Basically, I'd like to know if someone…

---

## [ECK Autoscaler Object Race Condition](https://discuss.elastic.co/t/eck-autoscaler-object-race-condition/338718)

<div class="topic-metadata">

**Author:** [@Phillip\_Mabry](https://discuss.elastic.co/u/Phillip_Mabry)\
**Replies:** 1\
**Last updated:** [August 4, 2023, 5:23pm UTC](https://discuss.elastic.co/t/eck-autoscaler-object-race-condition/338718 "2023-08-04T17:23:23Z")

</div>

One of our customers uses helm charts to deploy elasticsearch on ECK which has been working correctly. They recently added autoscaler to the helm chart and they get inconsistent results. Sometimes the deployment works,…

---

## [Data is redundant in filebeat system module](https://discuss.elastic.co/t/data-is-redundant-in-filebeat-system-module/340096)

<div class="topic-metadata">

**Author:** [@e997cd7e8d9915436150](https://discuss.elastic.co/u/e997cd7e8d9915436150)\
**Replies:** 1\
**Last updated:** [August 4, 2023, 5:18pm UTC](https://discuss.elastic.co/t/data-is-redundant-in-filebeat-system-module/340096 "2023-08-04T17:18:07Z")

</div>

Hi, i indexed linux secure log via filebeat system module. And the user.name field is duplicated. Most user.name has two versions. The version that start with a blank and the other version that doesn't. There a…

---

## [I want create a kibana table, combining the 2 latest documents grouped by a common field](https://discuss.elastic.co/t/i-want-create-a-kibana-table-combining-the-2-latest-documents-grouped-by-a-common-field/339937)

<div class="topic-metadata">

**Author:** [@MJohansen](https://discuss.elastic.co/u/MJohansen)\
**Replies:** 1\
**Last updated:** [August 4, 2023, 5:05pm UTC](https://discuss.elastic.co/t/i-want-create-a-kibana-table-combining-the-2-latest-documents-grouped-by-a-common-field/339937 "2023-08-04T17:05:00Z")

</div>

Hey guys, I'm fairly new working with Kibana and the ELK stack. I currently have logs being sent roughly every 12 hours, containing packages and their versions. My goal, is to create a table that groups the data by the…

---

## [Wildcard query took 200 seconds with version 8.8 but only a few seconds with 6.3](https://discuss.elastic.co/t/wildcard-query-took-200-seconds-with-version-8-8-but-only-a-few-seconds-with-6-3/340152)

<div class="topic-metadata">

**Author:** [@xluan](https://discuss.elastic.co/u/xluan)\
**Replies:** 0\
**Last updated:** [August 4, 2023, 4:53pm UTC](https://discuss.elastic.co/t/wildcard-query-took-200-seconds-with-version-8-8-but-only-a-few-seconds-with-6-3/340152 "2023-08-04T16:53:49Z")

</div>

We are migrating Elastic from 6.3 to 8,8. But the wildcard queries (in query string) are excessively slow in 8,8 as compared with 6.3. For example, for query "abcddcba\*" that does not actually match anything, it takes 4 …

---

## [How we can remove deduplication event in logstash](https://discuss.elastic.co/t/how-we-can-remove-deduplication-event-in-logstash/340060)

<div class="topic-metadata">

**Author:** [@Sukhdeob\_95](https://discuss.elastic.co/u/Sukhdeob_95)\
**Replies:** 6\
**Last updated:** [August 4, 2023, 4:53pm UTC](https://discuss.elastic.co/t/how-we-can-remove-deduplication-event-in-logstash/340060 "2023-08-04T16:53:48Z")

</div>

I want to remove the duplicate event based on particular field of my input i wrote logic like following but i got an error aggregate { task\_id =\> "%{\[meta\]\[ingestionHash\]}" code =\> " map\['@metadata'\]\['keep'\] ||= ev…

---

## [Making charts for data like machine learning](https://discuss.elastic.co/t/making-charts-for-data-like-machine-learning/339971)

<div class="topic-metadata">

**Author:** [@INS](https://discuss.elastic.co/u/INS)\
**Replies:** 2\
**Last updated:** [August 4, 2023, 4:21pm UTC](https://discuss.elastic.co/t/making-charts-for-data-like-machine-learning/339971 "2023-08-04T16:21:16Z")

</div>

Hi I would like to know how can I achieve very likely graph as You have in machine learning module. I have already uploaded data from side car cluster (tensorflow, spark etc) but I need to plot a graph with envelopes an…

---

## [Do we have any possibility to integrate Third-party map (Google Map) with ELK](https://discuss.elastic.co/t/do-we-have-any-possibility-to-integrate-third-party-map-google-map-with-elk/339042)

<div class="topic-metadata">

**Author:** [@Abj\_Ins](https://discuss.elastic.co/u/Abj_Ins)\
**Replies:** 1\
**Last updated:** [August 4, 2023, 4:17pm UTC](https://discuss.elastic.co/t/do-we-have-any-possibility-to-integrate-third-party-map-google-map-with-elk/339042 "2023-08-04T16:17:46Z")

</div>

Hi Team, Can we integrate any third-party map(Google Map) as a plug-in into ELK stack to view the Steet level findings in the Map. Thanks in Advance.

---

## [Session storage for embedded iframes with kibana dashboards and anonymous user](https://discuss.elastic.co/t/session-storage-for-embedded-iframes-with-kibana-dashboards-and-anonymous-user/339960)

<div class="topic-metadata">

**Author:** [@Jordan\_Rutland](https://discuss.elastic.co/u/Jordan_Rutland)\
**Replies:** 1\
**Last updated:** [August 4, 2023, 3:44pm UTC](https://discuss.elastic.co/t/session-storage-for-embedded-iframes-with-kibana-dashboards-and-anonymous-user/339960 "2023-08-04T15:44:42Z")

</div>

Quick questions. My team is using iframes to host embeded dashboards and we want to use anonymous users to avoid having users have to provide their own credentials. The how to for that piece is clear. We however are worr…

---

## [Is there a way to have an aggregation bucket that delivery the sum of other values](https://discuss.elastic.co/t/is-there-a-way-to-have-an-aggregation-bucket-that-delivery-the-sum-of-other-values/340148)

<div class="topic-metadata">

**Author:** [@Fabio\_Batalha](https://discuss.elastic.co/u/Fabio_Batalha)\
**Replies:** 0\
**Last updated:** [August 4, 2023, 3:35pm UTC](https://discuss.elastic.co/t/is-there-a-way-to-have-an-aggregation-bucket-that-delivery-the-sum-of-other-values/340148 "2023-08-04T15:35:26Z")

</div>

I'm doing an aggregation, limiting the buckets size to 6, and I would have a bucket having the sum of the other values. I see Kibana deal with that in a hidden way. At Kibana we can configure an aggregation to delivery …

---

## [Becoming ECS Compliant](https://discuss.elastic.co/t/becoming-ecs-compliant/340080)

<div class="topic-metadata">

**Author:** [@wwalker](https://discuss.elastic.co/u/wwalker)\
**Replies:** 6\
**Last updated:** [August 4, 2023, 3:33pm UTC](https://discuss.elastic.co/t/becoming-ecs-compliant/340080 "2023-08-04T15:33:31Z")

</div>

I've been ingesting datasets from before ECS was a thing that now have an ECS mapping. What would be the most efficient means of ingesting data (moving forward) so that it is ECS compliant? Examples of datasets are For…

---

## [Need to email syslog messages from alert](https://discuss.elastic.co/t/need-to-email-syslog-messages-from-alert/340146)

<div class="topic-metadata">

**Author:** [@mmercaldi](https://discuss.elastic.co/u/mmercaldi)\
**Replies:** 0\
**Last updated:** [August 4, 2023, 2:55pm UTC](https://discuss.elastic.co/t/need-to-email-syslog-messages-from-alert/340146 "2023-08-04T14:55:54Z")

</div>

I am trying to be alerted whenever a port security issue comes up, however I can only view content on {{context.hits}}. The table for the syslog message contains fields such as @timestamp, @version, host, message I am …

---

## [Getting an error while running the logstash email output plugin - Unknown Garbage collector name- "G1 -Concurrent GC"](https://discuss.elastic.co/t/getting-an-error-while-running-the-logstash-email-output-plugin-unknown-garbage-collector-name-g1-concurrent-gc/340133)

<div class="topic-metadata">

**Author:** [@AKCG23](https://discuss.elastic.co/u/AKCG23)\
**Replies:** 1\
**Last updated:** [August 4, 2023, 2:47pm UTC](https://discuss.elastic.co/t/getting-an-error-while-running-the-logstash-email-output-plugin-unknown-garbage-collector-name-g1-concurrent-gc/340133 "2023-08-04T14:47:18Z")

</div>

I Have configured Logstash 7.17.3 and Heart beats 7.17.3. I am trying to send an email alert , if the url returns a code 401 . I have configured the email output plugin. While running the logstash i get this error. \[20…

---

## [Double Quotes being truncated](https://discuss.elastic.co/t/double-quotes-being-truncated/340143)

<div class="topic-metadata">

**Author:** [@tech7857](https://discuss.elastic.co/u/tech7857)\
**Replies:** 0\
**Last updated:** [August 4, 2023, 2:41pm UTC](https://discuss.elastic.co/t/double-quotes-being-truncated/340143 "2023-08-04T14:41:02Z")

</div>

Hi We are shipping all our K8s logs to ELK. We noticed that double quotes are being truncated in ELK. Not sure what is the issue. Can you please guide us K8s logs "{\\r\\n \\"param1\\": true,\\r\\n \\"param2\\":…

---

## [Kibana Input controls old v/s new](https://discuss.elastic.co/t/kibana-input-controls-old-v-s-new/339915)

<div class="topic-metadata">

**Author:** [@VVK](https://discuss.elastic.co/u/VVK)\
**Replies:** 4\
**Last updated:** [August 4, 2023, 1:56pm UTC](https://discuss.elastic.co/t/kibana-input-controls-old-v-s-new/339915 "2023-08-04T13:56:51Z")

</div>

Hi, We are using Kibana/Elasticsearch /eck managed for our dev/production (non customer facing UIs) to analyse many things. Sometime back kibana depricated beta version / non-guaranteed (non production ready) versions …

---

## [How to change password "changeme" ?](https://discuss.elastic.co/t/how-to-change-password-changeme/340138)

<div class="topic-metadata">

**Author:** [@Vahan\_Alaverdyan](https://discuss.elastic.co/u/Vahan_Alaverdyan)\
**Replies:** 1\
**Last updated:** [August 4, 2023, 1:46pm UTC](https://discuss.elastic.co/t/how-to-change-password-changeme/340138 "2023-08-04T13:46:54Z")

</div>

I will install apm-server with docker compose , it works fine, but when I want to change password for admin user, it doesn't work . Can you tell me how to change the password ? docker-compose

---

## [MD5 hash of fingerprint processor in ingest pipeline](https://discuss.elastic.co/t/md5-hash-of-fingerprint-processor-in-ingest-pipeline/340135)

<div class="topic-metadata">

**Author:** [@Zaid\_Raza](https://discuss.elastic.co/u/Zaid_Raza)\
**Replies:** 1\
**Last updated:** [August 4, 2023, 1:39pm UTC](https://discuss.elastic.co/t/md5-hash-of-fingerprint-processor-in-ingest-pipeline/340135 "2023-08-04T13:39:48Z")

</div>

Hi, My elastic stack version is 8.5.3. I am using a fingerprint processor in ingest pipeline to create an MD5 hash. By default, it gives a hash in base64. I want a 128-bit MD5 hash. Is there any solution to this issue?

---

## [Logstash / Beats Encryption Error](https://discuss.elastic.co/t/logstash-beats-encryption-error/340140)

<div class="topic-metadata">

**Author:** [@WLhelp](https://discuss.elastic.co/u/WLhelp)\
**Replies:** 0\
**Last updated:** [August 4, 2023, 1:44pm UTC](https://discuss.elastic.co/t/logstash-beats-encryption-error/340140 "2023-08-04T13:44:09Z")

</div>

Hey folks, i have trouble setting up encryption for Beats send to logstash server. Test Config says "ok", test output on the client gives me: logstash: 10.1.7.27:5044... connection... parse host... OK dns lookup...…

---

## [Multipath in the pipeline not working](https://discuss.elastic.co/t/multipath-in-the-pipeline-not-working/339842)

<div class="topic-metadata">

**Author:** [@anupvtr](https://discuss.elastic.co/u/anupvtr)\
**Replies:** 2\
**Last updated:** [August 4, 2023, 1:09pm UTC](https://discuss.elastic.co/t/multipath-in-the-pipeline-not-working/339842 "2023-08-04T13:09:11Z")

</div>

Hello All, Thanks in advance. We have succesfully sending the data to the Logz.io console via custom application. There was a specific request to add one more path in addition to the existing path. The logs that are p…

---

## [Elastic Serverless Forwarder for AWS adding reserved \_id field when sending to logstash](https://discuss.elastic.co/t/elastic-serverless-forwarder-for-aws-adding-reserved-id-field-when-sending-to-logstash/340084)

<div class="topic-metadata">

**Author:** [@stabbotco1](https://discuss.elastic.co/u/stabbotco1)\
**Replies:** 3\
**Last updated:** [August 4, 2023, 12:55pm UTC](https://discuss.elastic.co/t/elastic-serverless-forwarder-for-aws-adding-reserved-id-field-when-sending-to-logstash/340084 "2023-08-04T12:55:27Z")

</div>

Hi All! I am new to ES, so apologies in advance if I mis-state some things. We are looking to use the ES Serverless Forwarder for AWS (Elastic Serverless Forwarder for AWS | Elastic Serverless Forwarder Guide | Elastic)…

---

## [Can Logstash be setup separately after deploying Elasticsearch using AzureRM template?](https://discuss.elastic.co/t/can-logstash-be-setup-separately-after-deploying-elasticsearch-using-azurerm-template/339152)

<div class="topic-metadata">

**Author:** [@Haralambie\_Lungu](https://discuss.elastic.co/u/Haralambie_Lungu)\
**Replies:** 1\
**Last updated:** [August 4, 2023, 11:59am UTC](https://discuss.elastic.co/t/can-logstash-be-setup-separately-after-deploying-elasticsearch-using-azurerm-template/339152 "2023-08-04T11:59:58Z")

</div>

Hi everyone, We have deployed Elasticsearch Self-Managed using the ARM template from Azure Marketplace. We haven't checked Logstash during the setup process, we only created the kibana, master-0,1 and 2 and also the da…

---

## [Enterprise search on k8s can't connect to the kibana](https://discuss.elastic.co/t/enterprise-search-on-k8s-cant-connect-to-the-kibana/340120)

<div class="topic-metadata">

**Author:** [@PustyB](https://discuss.elastic.co/u/PustyB)\
**Replies:** 1\
**Last updated:** [August 4, 2023, 11:59am UTC](https://discuss.elastic.co/t/enterprise-search-on-k8s-cant-connect-to-the-kibana/340120 "2023-08-04T11:59:55Z")

</div>

Hi I wanted to install Enterprise Search on my k8s cluster. I did it according to this instruction: Configuration | Elastic Cloud on Kubernetes \[2.9\] | Elastic The problem is that not enterprise search can not connect t…

---

## [Sorting help with query](https://discuss.elastic.co/t/sorting-help-with-query/340128)

<div class="topic-metadata">

**Author:** [@lakhr034](https://discuss.elastic.co/u/lakhr034)\
**Replies:** 0\
**Last updated:** [August 4, 2023, 11:58am UTC](https://discuss.elastic.co/t/sorting-help-with-query/340128 "2023-08-04T11:58:40Z")

</div>

{ "query": { "bool": { "must": \[ { "term": { "status": { "value": 1 } } } \], "should": \[ { "wildcard": {…

---

## [Elasticsearch not generating certificates and enrollment tokens when started from a DockerFile](https://discuss.elastic.co/t/elasticsearch-not-generating-certificates-and-enrollment-tokens-when-started-from-a-dockerfile/340119)

<div class="topic-metadata">

**Author:** [@Tanmay\_Sharma](https://discuss.elastic.co/u/Tanmay_Sharma)\
**Replies:** 0\
**Last updated:** [August 4, 2023, 9:38am UTC](https://discuss.elastic.co/t/elasticsearch-not-generating-certificates-and-enrollment-tokens-when-started-from-a-dockerfile/340119 "2023-08-04T09:38:22Z")

</div>

Hello everyone, i'm trying to spin up a docker container for elasticsearch using the Dockerfile: FROM elasticsearch:8.8.1 # Set the environment variables for Elasticsearch. ENV discovery.type=single-node ENV xpack.secu…

---

## [Search slowlog in JSON format is truncating the query](https://discuss.elastic.co/t/search-slowlog-in-json-format-is-truncating-the-query/340095)

<div class="topic-metadata">

**Author:** [@gshankar-elastic](https://discuss.elastic.co/u/gshankar-elastic)\
**Replies:** 1\
**Last updated:** [August 4, 2023, 7:53am UTC](https://discuss.elastic.co/t/search-slowlog-in-json-format-is-truncating-the-query/340095 "2023-08-04T07:53:46Z")

</div>

I am on Elasticsearch 7.10.0 and recently I have changed the slowlogs format from plaintext to json anticipating that large query truncation issue will be resolved automatically in the json format. But I am still seeing …

---

## [Help me to query this document](https://discuss.elastic.co/t/help-me-to-query-this-document/340110)

<div class="topic-metadata">

**Author:** [@marcin\_cron](https://discuss.elastic.co/u/marcin_cron)\
**Replies:** 3\
**Last updated:** [August 4, 2023, 9:19am UTC](https://discuss.elastic.co/t/help-me-to-query-this-document/340110 "2023-08-04T09:19:02Z")

</div>

This is my documents: //document 1 { "place": "galaxy", "range": { "area": { "planet": "mars", "country": \[ -----------country 1------------------ …

[Previous page](https://discuss.elastic.co/latest.md?page=581)

[Next page](https://discuss.elastic.co/latest.md?page=583)
