# Latest

**URL:** https://discuss.elastic.co/latest.md?page=586

[Latest](https://discuss.elastic.co/latest.md) · [Categories](https://discuss.elastic.co/categories.md) · [Tags](https://discuss.elastic.co/tags.md)

**Page:** 587

---

## [Installing Elasticsearch 7.17](https://discuss.elastic.co/t/installing-elasticsearch-7-17/339887)

<div class="topic-metadata">

**Author:** [@Rahul\_Kumar\_Jaiswal](https://discuss.elastic.co/u/Rahul_Kumar_Jaiswal)\
**Replies:** 0\
**Last updated:** [August 2, 2023, 5:12am UTC](https://discuss.elastic.co/t/installing-elasticsearch-7-17/339887 "2023-08-02T05:12:10Z")

</div>

I am trying to reinstall the elasticsearch same version on ubuntu 20.04 but I am getting the below error again and again. I have tried almost all the solution given on google but the error was not resolved. Previously sa…

---

## [Using Maxmind databases without access to ES cluster](https://discuss.elastic.co/t/using-maxmind-databases-without-access-to-es-cluster/339736)

<div class="topic-metadata">

**Author:** [@hjazz6](https://discuss.elastic.co/u/hjazz6)\
**Replies:** 5\
**Last updated:** [August 2, 2023, 4:47am UTC](https://discuss.elastic.co/t/using-maxmind-databases-without-access-to-es-cluster/339736 "2023-08-02T04:47:38Z")

</div>

Hi, I'm using a ES cluster (v8.8.0) running on Kubenetes that is managed by someone else, and I was told by them that I would not be able to directly access the cluster. Previously, when I was managing my own cluster r…

---

## [ELK Update](https://discuss.elastic.co/t/elk-update/339880)

<div class="topic-metadata">

**Author:** [@juancamiloll](https://discuss.elastic.co/u/juancamiloll)\
**Replies:** 0\
**Last updated:** [August 2, 2023, 3:19am UTC](https://discuss.elastic.co/t/elk-update/339880 "2023-08-02T03:19:27Z")

</div>

Hello everyone, I currently have an ELK version 7.6.0 implementation which I use hand in hand with Splunk version 8.0.1. I realize they are old versions, but it is working for what I need. The plugin I use from Splunk…

---

## [Is elastic Near-Real-Time when we discussing Observability?](https://discuss.elastic.co/t/is-elastic-near-real-time-when-we-discussing-observability/339323)

<div class="topic-metadata">

**Author:** [@Ernest\_Dong](https://discuss.elastic.co/u/Ernest_Dong)\
**Replies:** 2\
**Last updated:** [August 2, 2023, 2:35am UTC](https://discuss.elastic.co/t/is-elastic-near-real-time-when-we-discussing-observability/339323 "2023-08-02T02:35:03Z")

</div>

Elasticsearch is Near real-time. I just wonder when it comes to observability(and security), does NRT means that I can't get insight instantly when my cluster is hacked very quickly? E.g. I got hacked and this event data…

---

## [Unable to create a new Field in Logstash ElasticSearch please help](https://discuss.elastic.co/t/unable-to-create-a-new-field-in-logstash-elasticsearch-please-help/339874)

<div class="topic-metadata">

**Author:** [@Jennifer\_Coley](https://discuss.elastic.co/u/Jennifer_Coley)\
**Replies:** 0\
**Last updated:** [August 2, 2023, 12:58am UTC](https://discuss.elastic.co/t/unable-to-create-a-new-field-in-logstash-elasticsearch-please-help/339874 "2023-08-02T00:58:14Z")

</div>

hello sir, I really need an help, I'm new to elasticsearch Kibana but learnt in recent days to understand terms used. I have a Index name "logstash-\*" which receives logs constantly, my task is to filter from all logs …

---

## [Logstash pipeline getting terminated](https://discuss.elastic.co/t/logstash-pipeline-getting-terminated/339871)

<div class="topic-metadata">

**Author:** [@Arinjay\_Jain](https://discuss.elastic.co/u/Arinjay_Jain)\
**Replies:** 0\
**Last updated:** [August 2, 2023, 12:10am UTC](https://discuss.elastic.co/t/logstash-pipeline-getting-terminated/339871 "2023-08-02T00:10:06Z")

</div>

Hi Experts, I am running Logstash in a docker container and have the following pipeline configuration. input { tcp { port =\> 5000 codec =\> line } } filter { grok { match =\> {"message…

---

## [Multi-index query returning no results](https://discuss.elastic.co/t/multi-index-query-returning-no-results/339855)

<div class="topic-metadata">

**Author:** [@PedroD](https://discuss.elastic.co/u/PedroD)\
**Replies:** 4\
**Last updated:** [August 2, 2023, 12:01am UTC](https://discuss.elastic.co/t/multi-index-query-returning-no-results/339855 "2023-08-02T00:01:47Z")

</div>

Hey guys, I have 2 different indexes that store information about my users. Both use a hashed version of their id\_number as their doc\_id, I\`m trying to create a query that will look for different fields in both indexes …

---

## [Aggregate latest values of documents](https://discuss.elastic.co/t/aggregate-latest-values-of-documents/339868)

<div class="topic-metadata">

**Author:** [@MrFuxi](https://discuss.elastic.co/u/MrFuxi)\
**Replies:** 0\
**Last updated:** [August 1, 2023, 10:40pm UTC](https://discuss.elastic.co/t/aggregate-latest-values-of-documents/339868 "2023-08-01T22:40:42Z")

</div>

I have items that over the time can go from one category to the other. Each change results in a new document with current state of the item. I'm tying to get run basic analytics based on the latest state of the item li…

---

## [Logstash filtering](https://discuss.elastic.co/t/logstash-filtering/339864)

<div class="topic-metadata">

**Author:** [@Jennifer\_Coley](https://discuss.elastic.co/u/Jennifer_Coley)\
**Replies:** 0\
**Last updated:** [August 1, 2023, 9:45pm UTC](https://discuss.elastic.co/t/logstash-filtering/339864 "2023-08-01T21:45:00Z")

</div>

In my logstash every second logs will update, In a field name "message" consists group of data like '2023-08-01T21:11:54 \<local.info\> web.site.com IncomingMax1\[123\] 2023-08-01 11:10:54,123 INFO 987654321 Message.py 12 I…

---

## [CSV and XLS import to Elastic Cloud](https://discuss.elastic.co/t/csv-and-xls-import-to-elastic-cloud/339120)

<div class="topic-metadata">

**Author:** [@Vog93](https://discuss.elastic.co/u/Vog93)\
**Replies:** 14\
**Last updated:** [August 1, 2023, 9:36pm UTC](https://discuss.elastic.co/t/csv-and-xls-import-to-elastic-cloud/339120 "2023-08-01T21:36:08Z")

</div>

Hello, I would like to automatically integrate some CSV and XLS files into Elastic Cloud. How could I do this?

---

## [How to create a field that filters the data](https://discuss.elastic.co/t/how-to-create-a-field-that-filters-the-data/339861)

<div class="topic-metadata">

**Author:** [@Jennifer\_Coley](https://discuss.elastic.co/u/Jennifer_Coley)\
**Replies:** 0\
**Last updated:** [August 1, 2023, 9:01pm UTC](https://discuss.elastic.co/t/how-to-create-a-field-that-filters-the-data/339861 "2023-08-01T21:01:50Z")

</div>

I have a "message" field contains bulk of data(like customerName,number,address) in logstash, Now I want to create a new field that filter the data contains only word "Incoming Message:" I'm using ELK 8.6.0 I am tryin…

---

## [Can't set my log file timestamp as Time Filter in Kibana](https://discuss.elastic.co/t/cant-set-my-log-file-timestamp-as-time-filter-in-kibana/339628)

<div class="topic-metadata">

**Author:** [@younes-gr](https://discuss.elastic.co/u/younes-gr)\
**Replies:** 7\
**Last updated:** [August 1, 2023, 8:23pm UTC](https://discuss.elastic.co/t/cant-set-my-log-file-timestamp-as-time-filter-in-kibana/339628 "2023-08-01T20:23:52Z")

</div>

I am trying to process my log file in logstash using the following configuration: Example of log file content: 2023-07-15T07:32:01,645 ERROR \[00000003\] :01234567891011 - ERROR: Some error message 2023-07-15T07:32:01,64…

---

## [How to use runtime mapping on field that is nested](https://discuss.elastic.co/t/how-to-use-runtime-mapping-on-field-that-is-nested/339853)

<div class="topic-metadata">

**Author:** [@jlucas](https://discuss.elastic.co/u/jlucas)\
**Replies:** 0\
**Last updated:** [August 1, 2023, 7:57pm UTC](https://discuss.elastic.co/t/how-to-use-runtime-mapping-on-field-that-is-nested/339853 "2023-08-01T19:57:18Z")

</div>

Lets say I have the following document on some index. { "\_source" : { "process1": { "part1": { "start": "2022-10-04T18:35:01.540Z", "end": "2022-10-04T18:35:01.540Z" }, "part2": {…

---

## [KEYSTORE\_PASSWORD\_FILE](https://discuss.elastic.co/t/keystore-password-file/339627)

<div class="topic-metadata">

**Author:** [@toughcoding](https://discuss.elastic.co/u/toughcoding)\
**Replies:** 3\
**Last updated:** [August 1, 2023, 7:27pm UTC](https://discuss.elastic.co/t/keystore-password-file/339627 "2023-08-01T19:27:39Z")

</div>

Running Elasticsearch as docker container with --env KEYSTORE\_PASSWORD\_FILE=/run/secrets/keystore\_password does not setup password for elasticsearch keystore. Although I am successfull with Elasticsearch password itse…

---

## [Indices.fielddata.cache.size will be allocated within heap or outside heap?](https://discuss.elastic.co/t/indices-fielddata-cache-size-will-be-allocated-within-heap-or-outside-heap/339846)

<div class="topic-metadata">

**Author:** [@mannoj87](https://discuss.elastic.co/u/mannoj87)\
**Replies:** 0\
**Last updated:** [August 1, 2023, 6:54pm UTC](https://discuss.elastic.co/t/indices-fielddata-cache-size-will-be-allocated-within-heap-or-outside-heap/339846 "2023-08-01T18:54:49Z")

</div>

Hi Team, Q1). indices.fielddata.cache.size is set as 10% of heap by default. Does it mean it will consider 10% of heap lets say 1.2GB and it will allocate within heap or will it go outside of heap and take from overall …

---

## [Minimal Filebeat configuration for sending Logstash message in JSON format to Logstash](https://discuss.elastic.co/t/minimal-filebeat-configuration-for-sending-logstash-message-in-json-format-to-logstash/339811)

<div class="topic-metadata">

**Author:** [@jba](https://discuss.elastic.co/u/jba)\
**Replies:** 8\
**Last updated:** [August 1, 2023, 6:51pm UTC](https://discuss.elastic.co/t/minimal-filebeat-configuration-for-sending-logstash-message-in-json-format-to-logstash/339811 "2023-08-01T18:51:32Z")

</div>

Until now, we have had Logstash produce its log messages in plain-text format (written to /var/log/logstash/logstash-plain.log). And we had Filebeat ship the log messages to a Logstash cluster where the log messages were…

---

## [Can I update ES mappings to exclude copy\_to?](https://discuss.elastic.co/t/can-i-update-es-mappings-to-exclude-copy-to/339834)

<div class="topic-metadata">

**Author:** [@Vlado](https://discuss.elastic.co/u/Vlado)\
**Replies:** 1\
**Last updated:** [August 1, 2023, 6:34pm UTC](https://discuss.elastic.co/t/can-i-update-es-mappings-to-exclude-copy-to/339834 "2023-08-01T18:34:48Z")

</div>

Hi, What are ES back-compat rules around directives? Say, I have a copy\_to mapping on several fields with data already indexed and wanted to remove the "copy\_to" directive on some of those. Is this allowed? Or is it an…

---

## [How to filter a table based on another table's contents](https://discuss.elastic.co/t/how-to-filter-a-table-based-on-another-tables-contents/338965)

<div class="topic-metadata">

**Author:** [@Dillard\_Coffey](https://discuss.elastic.co/u/Dillard_Coffey)\
**Replies:** 3\
**Last updated:** [August 1, 2023, 6:32pm UTC](https://discuss.elastic.co/t/how-to-filter-a-table-based-on-another-tables-contents/338965 "2023-08-01T18:32:45Z")

</div>

Hello, I am using Kibana 7.10 and am trying to find a way to visualize the relationship that is between two tables of data I have. Table 1 is similar to: +-------------+-------------+------------+---------------+------…

---

## [Separate ELK pattern for log files](https://discuss.elastic.co/t/separate-elk-pattern-for-log-files/339817)

<div class="topic-metadata">

**Author:** [@sanjeev1895](https://discuss.elastic.co/u/sanjeev1895)\
**Replies:** 4\
**Last updated:** [August 1, 2023, 6:14pm UTC](https://discuss.elastic.co/t/separate-elk-pattern-for-log-files/339817 "2023-08-01T18:14:09Z")

</div>

Hi team, Can any one help me to find the solution for my below requirement. I have two apache server and I want to send the apache access and error logs to elk server via filebeat apache module to logstash. I configure…

---

## [Aggregation in Elasticserach Query Alert](https://discuss.elastic.co/t/aggregation-in-elasticserach-query-alert/339429)

<div class="topic-metadata">

**Author:** [@Dasher](https://discuss.elastic.co/u/Dasher)\
**Replies:** 1\
**Last updated:** [August 1, 2023, 6:11pm UTC](https://discuss.elastic.co/t/aggregation-in-elasticserach-query-alert/339429 "2023-08-01T18:11:23Z")

</div>

Hi All, If we go in the rules and select rule as elasticsearch query. Can we do an aggregation in the elasticsearch query.

---

## [Filebeat timestamp not working](https://discuss.elastic.co/t/filebeat-timestamp-not-working/339827)

<div class="topic-metadata">

**Author:** [@McJava1967](https://discuss.elastic.co/u/McJava1967)\
**Replies:** 1\
**Last updated:** [August 1, 2023, 6:05pm UTC](https://discuss.elastic.co/t/filebeat-timestamp-not-working/339827 "2023-08-01T18:05:53Z")

</div>

Hi all. I'm trying to tell Filebeat to use my timestamp, rather than creating one. I'm getting this error: "error": "failed parsing time field \_app.ACTUAL\_TIME='2023-08-01T11:49:09.386Z'", "errorCauses": \[{"error": "f…

---

## [Retrieving stored fields using java client](https://discuss.elastic.co/t/retrieving-stored-fields-using-java-client/339812)

<div class="topic-metadata">

**Author:** [@Jagadeesh12](https://discuss.elastic.co/u/Jagadeesh12)\
**Replies:** 2\
**Last updated:** [August 1, 2023, 5:37pm UTC](https://discuss.elastic.co/t/retrieving-stored-fields-using-java-client/339812 "2023-08-01T17:37:21Z")

</div>

Hi, I am facing issues while retrieving stored fields from Elasticsearch using java client. creating template: PUT \_index\_template/test\_tf\_template { "index\_patterns": \["test-tf-\*"\], "template": { "mappings":…

---

## [Need help in configuring filebeat 8.9 on windows server 2012 R2](https://discuss.elastic.co/t/need-help-in-configuring-filebeat-8-9-on-windows-server-2012-r2/339836)

<div class="topic-metadata">

**Author:** [@Shan2](https://discuss.elastic.co/u/Shan2)\
**Replies:** 0\
**Last updated:** [August 1, 2023, 4:36pm UTC](https://discuss.elastic.co/t/need-help-in-configuring-filebeat-8-9-on-windows-server-2012-r2/339836 "2023-08-01T16:36:48Z")

</div>

Hi All, First time implementing filebeat 8.9 on windows to pick files from Samba share and send it to Elasticsearch. The netwoek firewall rules has been allowed and telnet is also happening from windows server. We are g…

---

## [Is new Geometry simplifier (ES 8.9.0) available for direct use?](https://discuss.elastic.co/t/is-new-geometry-simplifier-es-8-9-0-available-for-direct-use/339832)

<div class="topic-metadata">

**Author:** [@Tomas\_Bartek](https://discuss.elastic.co/u/Tomas_Bartek)\
**Replies:** 0\
**Last updated:** [August 1, 2023, 4:33pm UTC](https://discuss.elastic.co/t/is-new-geometry-simplifier-es-8-9-0-available-for-direct-use/339832 "2023-08-01T16:33:47Z")

</div>

Hello ES friends, Is the new Geometry simplifier in ES version 8.9.0. available for direct use or is it only an internally callable feature ? From What's new document, it seems to me that it can be used merely for int…

---

## [Naming convention for ingest pipelines etc](https://discuss.elastic.co/t/naming-convention-for-ingest-pipelines-etc/339480)

<div class="topic-metadata">

**Author:** [@rsk0](https://discuss.elastic.co/u/rsk0)\
**Replies:** 6\
**Last updated:** [August 1, 2023, 3:32pm UTC](https://discuss.elastic.co/t/naming-convention-for-ingest-pipelines-etc/339480 "2023-08-01T15:32:59Z")

</div>

Elastic-Provided Naming Convention :question: Is there a naming convention for ingest pipelines, index templates, component templates, or any other such configuration objects? I see in the docs \[1,2,3,4\] there are examp…

---

## [retrieving a date format column in Logstash](https://discuss.elastic.co/t/retrieving-a-date-format-column-in-logstash/339821)

<div class="topic-metadata">

**Author:** [@Amal\_Krizi](https://discuss.elastic.co/u/Amal_Krizi)\
**Replies:** 0\
**Last updated:** [August 1, 2023, 3:22pm UTC](https://discuss.elastic.co/t/retrieving-a-date-format-column-in-logstash/339821 "2023-08-01T15:22:35Z")

</div>

good morning, I have a database that contains several columns, including date type columns. I was able to retrieve these date fields via logstach, but one in particular is stuck. This column takes a null date by defaul…

---

## [Elasticsearch for Data Science](https://discuss.elastic.co/t/elasticsearch-for-data-science/339818)

<div class="topic-metadata">

**Author:** [@tmslara.a](https://discuss.elastic.co/u/tmslara.a)\
**Replies:** 0\
**Last updated:** [August 1, 2023, 3:02pm UTC](https://discuss.elastic.co/t/elasticsearch-for-data-science/339818 "2023-08-01T15:02:14Z")

</div>

Hi, Some context. I'm using Elasticsearch and filebeat to store documents. I have 6 fields. One field represents the timestamp and the other 5 are keywords. Two fields correspond to IDs (id\_1 and id\_2). The IDs have man…

---

## [Combine data older then x days](https://discuss.elastic.co/t/combine-data-older-then-x-days/339804)

<div class="topic-metadata">

**Author:** [@Soren\_vdc](https://discuss.elastic.co/u/Soren_vdc)\
**Replies:** 0\
**Last updated:** [August 1, 2023, 1:53pm UTC](https://discuss.elastic.co/t/combine-data-older-then-x-days/339804 "2023-08-01T13:53:18Z")

</div>

Hi, I want to combine network data (based on scr/dst/port) to an aggregated index after 20 days. This to decrease the disk usage of this indices but still have the combined data available for specific searches. I'm che…

---

## [Iframed url expired after some time](https://discuss.elastic.co/t/iframed-url-expired-after-some-time/339646)

<div class="topic-metadata">

**Author:** [@Rushi\_Bagul](https://discuss.elastic.co/u/Rushi_Bagul)\
**Replies:** 3\
**Last updated:** [August 1, 2023, 1:32pm UTC](https://discuss.elastic.co/t/iframed-url-expired-after-some-time/339646 "2023-08-01T13:32:55Z")

</div>

Hi team, I have my kibana dashboard iframed short url in which some words I can't understand what is their meaning and can I used in python application? I am attached this short url please let explain what meaning of …

---

## [Setup a elastic cluster](https://discuss.elastic.co/t/setup-a-elastic-cluster/339741)

<div class="topic-metadata">

**Author:** [@psanggabuana](https://discuss.elastic.co/u/psanggabuana)\
**Replies:** 2\
**Last updated:** [August 1, 2023, 12:50pm UTC](https://discuss.elastic.co/t/setup-a-elastic-cluster/339741 "2023-08-01T12:50:09Z")

</div>

Hi everyone, I want to set up my cluster with the right server requirement. My cluster consists of: Master Data Coordinating Transform Ingest Can anyone share with me how much CPU, RAM, and storage for each server? …

[Previous page](https://discuss.elastic.co/latest.md?page=585)

[Next page](https://discuss.elastic.co/latest.md?page=587)
