# Latest

**URL:** https://discuss.elastic.co/latest.md?page=584

[Latest](https://discuss.elastic.co/latest.md) · [Categories](https://discuss.elastic.co/categories.md) · [Tags](https://discuss.elastic.co/tags.md)

**Page:** 585

---

## [Regarding Container Input](https://discuss.elastic.co/t/regarding-container-input/339707)

<div class="topic-metadata">

**Author:** [@dawiro](https://discuss.elastic.co/u/dawiro)\
**Replies:** 14\
**Last updated:** [August 3, 2023, 1:06pm UTC](https://discuss.elastic.co/t/regarding-container-input/339707 "2023-08-03T13:06:17Z")

</div>

Hi, I see that combine\_partial is not a parameter for the container input. Does the input now automatically handle docker's 16kb message limit? Thx D

---

## [Multi match query does not work for nested types](https://discuss.elastic.co/t/multi-match-query-does-not-work-for-nested-types/339936)

<div class="topic-metadata">

**Author:** [@Teqqan](https://discuss.elastic.co/u/Teqqan)\
**Replies:** 4\
**Last updated:** [August 3, 2023, 12:26pm UTC](https://discuss.elastic.co/t/multi-match-query-does-not-work-for-nested-types/339936 "2023-08-03T12:26:30Z")

</div>

Hi, I'm trying to perform a multi match query on some data I have structured as nested types. When I search for something like "gadget plushy" I get no matches for a document with two nested fields "gadget" and "plushy"…

---

## [Elastic Security - Host No longer logging Alert](https://discuss.elastic.co/t/elastic-security-host-no-longer-logging-alert/340043)

<div class="topic-metadata">

**Author:** [@g.spasov](https://discuss.elastic.co/u/g.spasov)\
**Replies:** 0\
**Last updated:** [August 3, 2023, 12:22pm UTC](https://discuss.elastic.co/t/elastic-security-host-no-longer-logging-alert/340043 "2023-08-03T12:22:58Z")

</div>

Hello, I want to create a detection rule in Elastic Security that would trigger when no logs have been injested to Elastic for more than 24 hours from a particular host.name. The idea is to detect potential logging pro…

---

## [Filebeat not ingesting Juniper SRX correctly](https://discuss.elastic.co/t/filebeat-not-ingesting-juniper-srx-correctly/339807)

<div class="topic-metadata">

**Author:** [@fredmoped](https://discuss.elastic.co/u/fredmoped)\
**Replies:** 2\
**Last updated:** [August 3, 2023, 11:57am UTC](https://discuss.elastic.co/t/filebeat-not-ingesting-juniper-srx-correctly/339807 "2023-08-03T11:57:36Z")

</div>

Hi all, I am running Elastic,Kibana and Filebeat 8.8.1 on docker and it somewhat works for what i want to achieve, but i am struggling to get Juniper module to ingest my data correctly. From what i see at : https://git…

---

## [AppSearch: Web Crawler - add custom field](https://discuss.elastic.co/t/appsearch-web-crawler-add-custom-field/339914)

<div class="topic-metadata">

**Author:** [@AlanNggg](https://discuss.elastic.co/u/AlanNggg)\
**Replies:** 2\
**Last updated:** [August 3, 2023, 10:50am UTC](https://discuss.elastic.co/t/appsearch-web-crawler-add-custom-field/339914 "2023-08-03T10:50:50Z")

</div>

Hello, I am currently using the AppSearch Web Crawler and would like to add custom fields to the crawled documents. Unfortunately, the websites that the web crawler is crawling do not allow the addition of meta tags fo…

---

## [Java, Spring Boot 3.1.1 - The attached APM agent doesn't separate KafkaListeners and Scheduled tasks to separate transactions](https://discuss.elastic.co/t/java-spring-boot-3-1-1-the-attached-apm-agent-doesnt-separate-kafkalisteners-and-scheduled-tasks-to-separate-transactions/338764)

<div class="topic-metadata">

**Author:** [@SerhiiM](https://discuss.elastic.co/u/SerhiiM)\
**Replies:** 20\
**Last updated:** [August 3, 2023, 10:03am UTC](https://discuss.elastic.co/t/java-spring-boot-3-1-1-the-attached-apm-agent-doesnt-separate-kafkalisteners-and-scheduled-tasks-to-separate-transactions/338764 "2023-08-03T10:03:18Z")

</div>

Kibana version: docker.elastic.co/kibana/kibana:8.7.0 Elasticsearch version: docker.elastic.co/elasticsearch/elasticsearch:8.7.0 APM Server version: docker.elastic.co/apm/apm-server:8.7.0 APM Agent language and versio…

---

## [Unable to authenticate user](https://discuss.elastic.co/t/unable-to-authenticate-user/340001)

<div class="topic-metadata">

**Author:** [@Vamsi\_krishna\_Ramaya](https://discuss.elastic.co/u/Vamsi_krishna_Ramaya)\
**Replies:** 3\
**Last updated:** [August 3, 2023, 9:06am UTC](https://discuss.elastic.co/t/unable-to-authenticate-user/340001 "2023-08-03T09:06:16Z")

</div>

Hi, I have been facing some issues with Elasticsearch the error i am getting is “unable to authenticate user \[elastic\] for REST request \[/va\_vrm\_202308030888/\_doc\] Can anyone help to resolve this? Thanks in advance

---

## [Giving Access to User for Enterprise Search](https://discuss.elastic.co/t/giving-access-to-user-for-enterprise-search/339655)

<div class="topic-metadata">

**Author:** [@aisyaharifin](https://discuss.elastic.co/u/aisyaharifin)\
**Replies:** 1\
**Last updated:** [August 3, 2023, 8:56am UTC](https://discuss.elastic.co/t/giving-access-to-user-for-enterprise-search/339655 "2023-08-03T08:56:19Z")

</div>

Hello Elastic, I would like to give my user to access Enterprise Search only without getting access to other features. How do I do this? In order to login to prod kibana, we use the Azure AD Login to enter Elastic. B…

---

## [Can't install a custom plugin even with a sufficient subscription level - Elastic Cloud](https://discuss.elastic.co/t/cant-install-a-custom-plugin-even-with-a-sufficient-subscription-level-elastic-cloud/339998)

<div class="topic-metadata">

**Author:** [@yechankim-paytalab](https://discuss.elastic.co/u/yechankim-paytalab)\
**Replies:** 1\
**Last updated:** [August 3, 2023, 8:15am UTC](https://discuss.elastic.co/t/cant-install-a-custom-plugin-even-with-a-sufficient-subscription-level-elastic-cloud/339998 "2023-08-03T08:15:01Z")

</div>

Hi there. Somehow I can't install a custom plugin on my Elastic Cloud cluster, even though my subscription level is "Gold" right now. The Type - "An installable plugin (compiled, no source code)" is not clickable for m…

---

## [Monitoring Oracle Alert log by using Logstash](https://discuss.elastic.co/t/monitoring-oracle-alert-log-by-using-logstash/339889)

<div class="topic-metadata">

**Author:** [@Debasis\_Mallick](https://discuss.elastic.co/u/Debasis_Mallick)\
**Replies:** 2\
**Last updated:** [August 3, 2023, 8:01am UTC](https://discuss.elastic.co/t/monitoring-oracle-alert-log-by-using-logstash/339889 "2023-08-03T08:01:45Z")

</div>

Hi Team, We had one requirement to monitor oracle alert log by using ELK stack. Could someone guide me . In my environment ELK stack running with 8.x version. Thanks, Debasis

---

## [Secure Logstash and Filebeats communication](https://discuss.elastic.co/t/secure-logstash-and-filebeats-communication/339912)

<div class="topic-metadata">

**Author:** [@Seemant\_Bind](https://discuss.elastic.co/u/Seemant_Bind)\
**Replies:** 4\
**Last updated:** [August 3, 2023, 7:51am UTC](https://discuss.elastic.co/t/secure-logstash-and-filebeats-communication/339912 "2023-08-03T07:51:17Z")

</div>

We are working on an integration where we need to take logs from Filebeat through Logstash. However, Filebeat and Logstash are hosted in different networks. In order to secure the communication, we want to implement SSL.…

---

## [Numerato/Denominator representation in TSVB](https://discuss.elastic.co/t/numerato-denominator-representation-in-tsvb/340000)

<div class="topic-metadata">

**Author:** [@mathur7vidit](https://discuss.elastic.co/u/mathur7vidit)\
**Replies:** 3\
**Last updated:** [August 3, 2023, 7:35am UTC](https://discuss.elastic.co/t/numerato-denominator-representation-in-tsvb/340000 "2023-08-03T07:35:33Z")

</div>

Hi Team, I am using filter ratio in Gauge TSVB visualization as below. Now in my data formatter, I want to showcase it as Numerator/Denominator value instead of overall filter ratio value. Is it achievable?

---

## [Group fields in a visualization for time series](https://discuss.elastic.co/t/group-fields-in-a-visualization-for-time-series/325934)

<div class="topic-metadata">

**Author:** [@dannie-ml](https://discuss.elastic.co/u/dannie-ml)\
**Replies:** 2\
**Last updated:** [August 3, 2023, 7:20am UTC](https://discuss.elastic.co/t/group-fields-in-a-visualization-for-time-series/325934 "2023-08-03T07:20:16Z")

</div>

Hi, im new in Elastic and i want to build some visualization of this table: But when building both lens or line chart or vega-lite (in this one i really dont know how to achieve a visualization) but for the other ones…

---

## [Search Applications with Search UI](https://discuss.elastic.co/t/search-applications-with-search-ui/340004)

<div class="topic-metadata">

**Author:** [@sebastianboelling](https://discuss.elastic.co/u/sebastianboelling)\
**Replies:** 0\
**Last updated:** [August 3, 2023, 7:09am UTC](https://discuss.elastic.co/t/search-applications-with-search-ui/340004 "2023-08-03T07:09:41Z")

</div>

Hi, I tried to integrate Search Applications with Search UI as described in the Kibana frontend when I created a new Search Application sample-search-app. import EnginesAPIConnector from "@elastic/search-ui-engines-con…

---

## [Modules system and nginx is not showing any data when looking in discover](https://discuss.elastic.co/t/modules-system-and-nginx-is-not-showing-any-data-when-looking-in-discover/339076)

<div class="topic-metadata">

**Author:** [@Prem\_Pratap\_Singh](https://discuss.elastic.co/u/Prem_Pratap_Singh)\
**Replies:** 2\
**Last updated:** [August 3, 2023, 6:38am UTC](https://discuss.elastic.co/t/modules-system-and-nginx-is-not-showing-any-data-when-looking-in-discover/339076 "2023-08-03T06:38:23Z")

</div>

Hi All, I have deployed Elasticsearch, kibana and filebeat on my kubernetes cluster but the enable modules such as nginx and system are not showing any data when i filter it using event.module: system on my dashboard bu…

---

## [How to read logs from newrelic?](https://discuss.elastic.co/t/how-to-read-logs-from-newrelic/339995)

<div class="topic-metadata">

**Author:** [@talbehat](https://discuss.elastic.co/u/talbehat)\
**Replies:** 0\
**Last updated:** [August 3, 2023, 4:28am UTC](https://discuss.elastic.co/t/how-to-read-logs-from-newrelic/339995 "2023-08-03T04:28:46Z")

</div>

is there any logstash-input-newrelic plugins for read data from new relic enviornment?

---

## [Detection Rule During Specific Hours](https://discuss.elastic.co/t/detection-rule-during-specific-hours/338493)

<div class="topic-metadata">

**Author:** [@SomeRobot](https://discuss.elastic.co/u/SomeRobot)\
**Replies:** 3\
**Last updated:** [August 3, 2023, 3:24am UTC](https://discuss.elastic.co/t/detection-rule-during-specific-hours/338493 "2023-08-03T03:24:54Z")

</div>

We need to write a detection rule that only looks for matches between specific hours of the day, say 12AM - 4AM EST. I assume there is a way to do this, because it would be a huge oversight if there wasn't, but I can't s…

---

## [How to query elasticsearch with array as parameter](https://discuss.elastic.co/t/how-to-query-elasticsearch-with-array-as-parameter/339991)

<div class="topic-metadata">

**Author:** [@rae93](https://discuss.elastic.co/u/rae93)\
**Replies:** 0\
**Last updated:** [August 3, 2023, 3:23am UTC](https://discuss.elastic.co/t/how-to-query-elasticsearch-with-array-as-parameter/339991 "2023-08-03T03:23:50Z")

</div>

I have a logstash config like this input { http { port =\> 8092 } } filter { ruby { code =\> ' event.set("\[@metadata\]\[leadArr\]", \[\]) c = event.get("\[@metadata\]\[leads\]") c.each { |value, index| temp = even…

---

## [How to create a complex detection rule (indicator + correlation)?](https://discuss.elastic.co/t/how-to-create-a-complex-detection-rule-indicator-correlation/337249)

<div class="topic-metadata">

**Author:** [@VellayLoket](https://discuss.elastic.co/u/VellayLoket)\
**Replies:** 7\
**Last updated:** [August 3, 2023, 2:07am UTC](https://discuss.elastic.co/t/how-to-create-a-complex-detection-rule-indicator-correlation/337249 "2023-08-03T02:07:04Z")

</div>

For example, i have list with malware domains. I save logs from my DNS servers. I want to create alert when any client of my network has request for malware domain name. And with this, i need to aggregate this request…

---

## [Elasticsearch 7.4 query\_then\_fetch slow log](https://discuss.elastic.co/t/elasticsearch-7-4-query-then-fetch-slow-log/339780)

<div class="topic-metadata">

**Author:** [@taoyantu](https://discuss.elastic.co/u/taoyantu)\
**Replies:** 7\
**Last updated:** [August 3, 2023, 1:21am UTC](https://discuss.elastic.co/t/elasticsearch-7-4-query-then-fetch-slow-log/339780 "2023-08-03T01:21:22Z")

</div>

A cluster of elasticsearch version 7.4 is deployed. There are about 20 servers in the cluster. Three nodes are started on each machine. The startup memory occupies 30G. The server is 88-core cpu and 256G memory. The ind…

---

## [Logstash failling to make connection to ElasticSearch](https://discuss.elastic.co/t/logstash-failling-to-make-connection-to-elasticsearch/339731)

<div class="topic-metadata">

**Author:** [@Ilyass\_Taybi](https://discuss.elastic.co/u/Ilyass_Taybi)\
**Replies:** 2\
**Last updated:** [July 31, 2023, 11:53pm UTC](https://discuss.elastic.co/t/logstash-failling-to-make-connection-to-elasticsearch/339731 "2023-07-31T23:53:07Z")

</div>

Hello, i am having troubles with Logstash for a week now. I do not know why does the error persists. To start Logstash, i use the following command : ./bin/logstash -f /"relative path to the file"/logstash-sample.conf . …

---

## [Using logstash to route APM data to two servers](https://discuss.elastic.co/t/using-logstash-to-route-apm-data-to-two-servers/339977)

<div class="topic-metadata">

**Author:** [@ElasticLiver](https://discuss.elastic.co/u/ElasticLiver)\
**Replies:** 0\
**Last updated:** [August 2, 2023, 10:13pm UTC](https://discuss.elastic.co/t/using-logstash-to-route-apm-data-to-two-servers/339977 "2023-08-02T22:13:20Z")

</div>

Im am getting APM data on a APM server, I was wondering if its posible to place a logstash before the APM server, so I can send the same data to another server, so both receive the same data? Something like this: if …

---

## [Elastic-Agent - Collect Custom \[Linux\] text file logs](https://discuss.elastic.co/t/elastic-agent-collect-custom-linux-text-file-logs/339593)

<div class="topic-metadata">

**Author:** [@Bryan\_Hamilton](https://discuss.elastic.co/u/Bryan_Hamilton)\
**Replies:** 2\
**Last updated:** [August 2, 2023, 9:39pm UTC](https://discuss.elastic.co/t/elastic-agent-collect-custom-linux-text-file-logs/339593 "2023-08-02T21:39:08Z")

</div>

Hi, I have created a github issue for this question (Support for Custom \[Linux\] text file logs · Issue #7186 · elastic/integrations · GitHub), but I am also adding it here for greater visibility. We have custom applica…

---

## [Vaccum Deleted Documents](https://discuss.elastic.co/t/vaccum-deleted-documents/339974)

<div class="topic-metadata">

**Author:** [@TomTom](https://discuss.elastic.co/u/TomTom)\
**Replies:** 1\
**Last updated:** [August 2, 2023, 9:13pm UTC](https://discuss.elastic.co/t/vaccum-deleted-documents/339974 "2023-08-02T21:13:53Z")

</div>

I learned that Elasticsearch does not update a document, but instead, deletes the current document and creates a new one with the updates. It happens that I have several documents that are updated several times during t…

---

## [Error displaying fleet agents -"Error fetching agents Cannot read properties of undefined (reading 'map')"](https://discuss.elastic.co/t/error-displaying-fleet-agents-error-fetching-agents-cannot-read-properties-of-undefined-reading-map/339840)

<div class="topic-metadata">

**Author:** [@M\_S](https://discuss.elastic.co/u/M_S)\
**Replies:** 3\
**Last updated:** [August 2, 2023, 8:09pm UTC](https://discuss.elastic.co/t/error-displaying-fleet-agents-error-fetching-agents-cannot-read-properties-of-undefined-reading-map/339840 "2023-08-02T20:09:56Z")

</div>

One fine morning, fleet section just decided not to show agents enrolled in a particular policy. I suspected two issues, @timestamp was not present in some of the fleet related indices, I added mapping for the same, seco…

---

## [Stuck on module 3 elastic observability node.js](https://discuss.elastic.co/t/stuck-on-module-3-elastic-observability-node-js/339760)

<div class="topic-metadata">

**Author:** [@Vartika\_Singh](https://discuss.elastic.co/u/Vartika_Singh)\
**Replies:** 3\
**Last updated:** [August 2, 2023, 7:54pm UTC](https://discuss.elastic.co/t/stuck-on-module-3-elastic-observability-node-js/339760 "2023-08-02T19:54:45Z")

</div>

Course: Version:8.2.3 Question: I tried on ECE module 3 but getting stuck with node.js in APM part also i share few images

---

## [\_template vs \_index\_template](https://discuss.elastic.co/t/template-vs-index-template/339969)

<div class="topic-metadata">

**Author:** [@linkerc](https://discuss.elastic.co/u/linkerc)\
**Replies:** 0\
**Last updated:** [August 2, 2023, 7:13pm UTC](https://discuss.elastic.co/t/template-vs-index-template/339969 "2023-08-02T19:13:16Z")

</div>

I'm running ES 7.15. \_template seems to be legacy. \_index\_template is the one moving forward. I also noticed that there's no command to list all \_index\_templates. Is there a template migration guide somewhere?

---

## [Job for elasticsearch.service failed because the control process exited with error code.](https://discuss.elastic.co/t/job-for-elasticsearch-service-failed-because-the-control-process-exited-with-error-code/339884)

<div class="topic-metadata">

**Author:** [@Armel](https://discuss.elastic.co/u/Armel)\
**Replies:** 2\
**Last updated:** [August 2, 2023, 6:13pm UTC](https://discuss.elastic.co/t/job-for-elasticsearch-service-failed-because-the-control-process-exited-with-error-code/339884 "2023-08-02T18:13:38Z")

</div>

---

## [Drop event processor not working on Filebeat](https://discuss.elastic.co/t/drop-event-processor-not-working-on-filebeat/339725)

<div class="topic-metadata">

**Author:** [@JeremyP](https://discuss.elastic.co/u/JeremyP)\
**Replies:** 4\
**Last updated:** [August 2, 2023, 6:01pm UTC](https://discuss.elastic.co/t/drop-event-processor-not-working-on-filebeat/339725 "2023-08-02T18:01:38Z")

</div>

Hello, I'm trying to create a drop\_event processor to only allow elasticsearch audit logs which have a request.name = "AuthenticateRequest". Clearly my process it not working as all events are not matching and everythin…

---

## [Index keeps getting deleted and new index created called read-me-to-recover-data is created](https://discuss.elastic.co/t/index-keeps-getting-deleted-and-new-index-created-called-read-me-to-recover-data-is-created/339882)

<div class="topic-metadata">

**Author:** [@AndyX](https://discuss.elastic.co/u/AndyX)\
**Replies:** 5\
**Last updated:** [August 2, 2023, 4:06pm UTC](https://discuss.elastic.co/t/index-keeps-getting-deleted-and-new-index-created-called-read-me-to-recover-data-is-created/339882 "2023-08-02T16:06:47Z")

</div>

Every few days my Elasticsearch index gets deleted. I assume this is due to me running with the following: xpack.security.enabled: false When my index is deleted a new index with the name: read-me-to-recover-data is …

[Previous page](https://discuss.elastic.co/latest.md?page=583)

[Next page](https://discuss.elastic.co/latest.md?page=585)
