# Latest

**URL:** https://discuss.elastic.co/latest.md?page=587

[Latest](https://discuss.elastic.co/latest.md) · [Categories](https://discuss.elastic.co/categories.md) · [Tags](https://discuss.elastic.co/tags.md)

**Page:** 588

---

## [Tail-based sampling](https://discuss.elastic.co/t/tail-based-sampling/339701)

<div class="topic-metadata">

**Author:** [@Bertrand67](https://discuss.elastic.co/u/Bertrand67)\
**Replies:** 3\
**Last updated:** [August 1, 2023, 12:40pm UTC](https://discuss.elastic.co/t/tail-based-sampling/339701 "2023-08-01T12:40:30Z")

</div>

Kibana version: 8.7.0 Elasticsearch version: 8.7.0 APM Agent language and version: .NET Description of the problem including expected versus actual behavior. Please include screenshots (if relevant): Hello, I've con…

---

## [Fleet Server does not come up - ECK](https://discuss.elastic.co/t/fleet-server-does-not-come-up-eck/338966)

<div class="topic-metadata">

**Author:** [@VVK](https://discuss.elastic.co/u/VVK)\
**Replies:** 8\
**Last updated:** [August 1, 2023, 12:31pm UTC](https://discuss.elastic.co/t/fleet-server-does-not-come-up-eck/338966 "2023-08-01T12:31:15Z")

</div>

My problem is similar to below. Failed to deploy fleet-server via eck in kubernetes. My K8S Environment: kubectl version command output is here. clientVersion: buildDate: "2022-08-23T17:44:59Z" compiler: gc git…

---

## [Dont work preference in es version 6](https://discuss.elastic.co/t/dont-work-preference-in-es-version-6/339756)

<div class="topic-metadata">

**Author:** [@slowup](https://discuss.elastic.co/u/slowup)\
**Replies:** 2\
**Last updated:** [August 1, 2023, 12:22pm UTC](https://discuss.elastic.co/t/dont-work-preference-in-es-version-6/339756 "2023-08-01T12:22:44Z")

</div>

I know that the preference custome string is a function that allows you to search with the same shard, but every time you search, a different shard is searched, so the search results of search after are strange. What sh…

---

## [Configuring Filebeat to pack openresty/nginx logs and visualize in Kibana dashboards](https://discuss.elastic.co/t/configuring-filebeat-to-pack-openresty-nginx-logs-and-visualize-in-kibana-dashboards/339300)

<div class="topic-metadata">

**Author:** [@kpagcha](https://discuss.elastic.co/u/kpagcha)\
**Replies:** 4\
**Last updated:** [August 1, 2023, 12:15pm UTC](https://discuss.elastic.co/t/configuring-filebeat-to-pack-openresty-nginx-logs-and-visualize-in-kibana-dashboards/339300 "2023-08-01T12:15:25Z")

</div>

I am totally new with the ELK stack and not really a sysadmin either, just a web developer trying to figure this out. I have two droplets: one where I installed the ELK stack successfully to some extent (managed to vi…

---

## [URGENT: Handshake failed. unexpected remote node](https://discuss.elastic.co/t/urgent-handshake-failed-unexpected-remote-node/339796)

<div class="topic-metadata">

**Author:** [@Piyush\_Goyal1](https://discuss.elastic.co/u/Piyush_Goyal1)\
**Replies:** 0\
**Last updated:** [August 1, 2023, 12:05pm UTC](https://discuss.elastic.co/t/urgent-handshake-failed-unexpected-remote-node/339796 "2023-08-01T12:05:00Z")

</div>

Version: 8.5.0 The cluster has 3 nodes: node-001 (master) node-002 (data) node-003 (data) The master node VM crashed and upon restarting the master node, the data nodes are not getting discovered. The cluster was ru…

---

## [Ingest CSVs with filebeat into elastic cloud](https://discuss.elastic.co/t/ingest-csvs-with-filebeat-into-elastic-cloud/339790)

<div class="topic-metadata">

**Author:** [@Vog93](https://discuss.elastic.co/u/Vog93)\
**Replies:** 1\
**Last updated:** [August 1, 2023, 11:34am UTC](https://discuss.elastic.co/t/ingest-csvs-with-filebeat-into-elastic-cloud/339790 "2023-08-01T11:34:07Z")

</div>

I was able to import a csv using filebeat to elastic cloud. I did the following: First i uploaded the csv to elastic in order to have the filebeat yml configuration. Then I modified the filebeat.yml and installed fileb…

---

## [Rack Awarness and Node Aware](https://discuss.elastic.co/t/rack-awarness-and-node-aware/339786)

<div class="topic-metadata">

**Author:** [@mannoj87](https://discuss.elastic.co/u/mannoj87)\
**Replies:** 0\
**Last updated:** [August 1, 2023, 11:00am UTC](https://discuss.elastic.co/t/rack-awarness-and-node-aware/339786 "2023-08-01T11:00:23Z")

</div>

I'm in 7.17.7 ES. I have 6BareMetal(BM), each BM will have 4VirtualMachines(VM), each VM's having ES service running and all 5BM are in 3 Physical Racks. Reason: I dont want Primary and Replica to reside on same BM as …

---

## [Pivot Table](https://discuss.elastic.co/t/pivot-table/339318)

<div class="topic-metadata">

**Author:** [@sbottura](https://discuss.elastic.co/u/sbottura)\
**Replies:** 4\
**Last updated:** [August 1, 2023, 10:40am UTC](https://discuss.elastic.co/t/pivot-table/339318 "2023-08-01T10:40:29Z")

</div>

Hello, I am fairly new to the Elastic Stack and I was wondering whether it would be possible to create a pivot table in Kibana. Thanks, S.

---

## [How to query 3 indexes in logstash](https://discuss.elastic.co/t/how-to-query-3-indexes-in-logstash/339785)

<div class="topic-metadata">

**Author:** [@willsy](https://discuss.elastic.co/u/willsy)\
**Replies:** 0\
**Last updated:** [August 1, 2023, 10:41am UTC](https://discuss.elastic.co/t/how-to-query-3-indexes-in-logstash/339785 "2023-08-01T10:41:50Z")

</div>

In logstash i am trying to forward all of the logs in elasticsearch into logstash and then to a third party. What is the correct configuration for the index query? # Sample Logstash configuration for creating a simple #…

---

## [Lens formula conditionals](https://discuss.elastic.co/t/lens-formula-conditionals/339784)

<div class="topic-metadata">

**Author:** [@davidleongz](https://discuss.elastic.co/u/davidleongz)\
**Replies:** 0\
**Last updated:** [August 1, 2023, 10:36am UTC](https://discuss.elastic.co/t/lens-formula-conditionals/339784 "2023-08-01T10:36:16Z")

</div>

I want to use conditional on Lens Formula but I have this message "Operations if, eq not found" I'm using 7.16.2 version. What do I have to do to be able to use conditionals? Is possible?

---

## [EsHadoopIllegalArgumentException: Detected type name in resource On elastic 8.8.2](https://discuss.elastic.co/t/eshadoopillegalargumentexception-detected-type-name-in-resource-on-elastic-8-8-2/339660)

<div class="topic-metadata">

**Author:** [@Joachim\_Rodrigues](https://discuss.elastic.co/u/Joachim_Rodrigues)\
**Replies:** 1\
**Last updated:** [July 31, 2023, 9:27pm UTC](https://discuss.elastic.co/t/eshadoopillegalargumentexception-detected-type-name-in-resource-on-elastic-8-8-2/339660 "2023-07-31T21:27:19Z")

</div>

Hi I upgraded my elastic server fom 7.9.3 to 8.8.2 With my previous configuration : implementation("org.elasticsearch:elasticsearch-spark-20\_2.11:7.9.3") { exclude("org.apache.spark") } This code was …

---

## [How can I reindex TSDB enabled data stream?](https://discuss.elastic.co/t/how-can-i-reindex-tsdb-enabled-data-stream/339774)

<div class="topic-metadata">

**Author:** [@Aliabbas](https://discuss.elastic.co/u/Aliabbas)\
**Replies:** 0\
**Last updated:** [August 1, 2023, 8:48am UTC](https://discuss.elastic.co/t/how-can-i-reindex-tsdb-enabled-data-stream/339774 "2023-08-01T08:48:24Z")

</div>

Hi, I am currently facing conflicts in a fields host.ip. I can resolve that by using an Reindexing API but the problem is the data stream is TSDB enabled. Any idea how can we reindex a TSDB enabled data stream? FYI I am…

---

## [Kibana console is running very slow](https://discuss.elastic.co/t/kibana-console-is-running-very-slow/339766)

<div class="topic-metadata">

**Author:** [@Vartika\_Singh](https://discuss.elastic.co/u/Vartika_Singh)\
**Replies:** 2\
**Last updated:** [August 1, 2023, 10:10am UTC](https://discuss.elastic.co/t/kibana-console-is-running-very-slow/339766 "2023-08-01T10:10:36Z")

</div>

in kibana console sub tabs were working very slow...what is reason behind that?

---

## [Getting Null Pointer while using reloadable synonyms](https://discuss.elastic.co/t/getting-null-pointer-while-using-reloadable-synonyms/339775)

<div class="topic-metadata">

**Author:** [@Siddharth\_Gupta1](https://discuss.elastic.co/u/Siddharth_Gupta1)\
**Replies:** 2\
**Last updated:** [August 1, 2023, 10:06am UTC](https://discuss.elastic.co/t/getting-null-pointer-while-using-reloadable-synonyms/339775 "2023-08-01T10:06:17Z")

</div>

Hi Team I am currently facing an issue while utilizing readable synonyms from a file with my completion suggestor. The problem seems to be related to the search\_analyzers in my mappings. Strangely, the completion sugges…

---

## [Override filebeat input paths using command line configuration override?](https://discuss.elastic.co/t/override-filebeat-input-paths-using-command-line-configuration-override/339482)

<div class="topic-metadata">

**Author:** [@tolland](https://discuss.elastic.co/u/tolland)\
**Replies:** 2\
**Last updated:** [August 1, 2023, 9:52am UTC](https://discuss.elastic.co/t/override-filebeat-input-paths-using-command-line-configuration-override/339482 "2023-08-01T09:52:00Z")

</div>

I have a filebeat filestream input which parses a complicated message format. There are a few edge cases I'd like to create standalone tests for. I'd like to test single instances of the the message format from the comma…

---

## [\[API Logs\] - Pulling Latest Logs to Power BI](https://discuss.elastic.co/t/api-logs-pulling-latest-logs-to-power-bi/339657)

<div class="topic-metadata">

**Author:** [@aisyaharifin](https://discuss.elastic.co/u/aisyaharifin)\
**Replies:** 3\
**Last updated:** [August 1, 2023, 9:46am UTC](https://discuss.elastic.co/t/api-logs-pulling-latest-logs-to-power-bi/339657 "2023-08-01T09:46:01Z")

</div>

Hi Elastic, I want to ask is there a way we can continuously pulling the Elasticsearch data to Power BI Cloud for dashboard purposes? The team currently using Azure Data Factory to pull the data from our Elastic. Curr…

---

## [Standard Cloud Deployment unresponsive +12h](https://discuss.elastic.co/t/standard-cloud-deployment-unresponsive-12h/339765)

<div class="topic-metadata">

**Author:** [@Novel\_one](https://discuss.elastic.co/u/Novel_one)\
**Replies:** 1\
**Last updated:** [August 1, 2023, 9:41am UTC](https://discuss.elastic.co/t/standard-cloud-deployment-unresponsive-12h/339765 "2023-08-01T09:41:12Z")

</div>

Hi, thanks for any early response, I have been running a small deployment for almost a year. Yesterday I activated sending the internal logs and metrics to the same deployment, and during the last 12h any attempt on sto…

---

## [Handling of Multiline Scenarios](https://discuss.elastic.co/t/handling-of-multiline-scenarios/339069)

<div class="topic-metadata">

**Author:** [@dawiro](https://discuss.elastic.co/u/dawiro)\
**Replies:** 1\
**Last updated:** [August 1, 2023, 9:32am UTC](https://discuss.elastic.co/t/handling-of-multiline-scenarios/339069 "2023-08-01T09:32:42Z")

</div>

Hi, We have a need to add a second multiline block to our filebeat config. What isn't clear to me is the order in which multiline blocks are executed. Am I right to assume that they're executed in the order that the con…

---

## [Secure traffic via HTTPS - using kafka.output](https://discuss.elastic.co/t/secure-traffic-via-https-using-kafka-output/338779)

<div class="topic-metadata">

**Author:** [@ethrbunny](https://discuss.elastic.co/u/ethrbunny)\
**Replies:** 2\
**Last updated:** [August 1, 2023, 9:26am UTC](https://discuss.elastic.co/t/secure-traffic-via-https-using-kafka-output/338779 "2023-08-01T09:26:31Z")

</div>

I'd like to start using elastic-agent but doing so requires that I setup xpack security. In the docs (here) it gives an example for sending data directly to elasticsearch. We use 'kafka.output'. Is this not supported …

---

## [Winlogbeat/filebeat not sending data to elasticsearch](https://discuss.elastic.co/t/winlogbeat-filebeat-not-sending-data-to-elasticsearch/339135)

<div class="topic-metadata">

**Author:** [@Nirmal](https://discuss.elastic.co/u/Nirmal)\
**Replies:** 1\
**Last updated:** [August 1, 2023, 9:25am UTC](https://discuss.elastic.co/t/winlogbeat-filebeat-not-sending-data-to-elasticsearch/339135 "2023-08-01T09:25:02Z")

</div>

I am getting error when I run this command for winlogbeat .\\winlogbeat.exe setup -e and for filebeat filebeat setup -e error massage {"log.level":"error","@timestamp":"2023-07-24T22:08:16.309+0100","log.origin":{"fi…

---

## [After upgrading the filebeat 8.8.2 getting the error like publish events: temporary bulk send failure","service.name":"filebeat","ecs.version":"1.6.0"](https://discuss.elastic.co/t/after-upgrading-the-filebeat-8-8-2-getting-the-error-like-publish-events-temporary-bulk-send-failure-service-name-filebeat-ecs-version-1-6-0/339200)

<div class="topic-metadata">

**Author:** [@Pranjal\_Sett](https://discuss.elastic.co/u/Pranjal_Sett)\
**Replies:** 1\
**Last updated:** [August 1, 2023, 9:16am UTC](https://discuss.elastic.co/t/after-upgrading-the-filebeat-8-8-2-getting-the-error-like-publish-events-temporary-bulk-send-failure-service-name-filebeat-ecs-version-1-6-0/339200 "2023-08-01T09:16:08Z")

</div>

Hi, I have upgraded to the filebeat to 8.8.2. Configured it. After started in log I am getting the below error. {"log.level":"error","@timestamp":"2023-07-25T14:38:53.614+0200","log.logger":"publisher\_pipeline\_output",…

---

## [Adding new user in role mapping](https://discuss.elastic.co/t/adding-new-user-in-role-mapping/339755)

<div class="topic-metadata">

**Author:** [@Ganesh2303](https://discuss.elastic.co/u/Ganesh2303)\
**Replies:** 1\
**Last updated:** [August 1, 2023, 9:03am UTC](https://discuss.elastic.co/t/adding-new-user-in-role-mapping/339755 "2023-08-01T09:03:06Z")

</div>

HI Team, I'm trying to add new user in my existing role mapping and when i perform the action it delete all the existing user from it and create the new user which im parsing. I need to append this in my existing role …

---

## [How to remove a user from role mapping](https://discuss.elastic.co/t/how-to-remove-a-user-from-role-mapping/339688)

<div class="topic-metadata">

**Author:** [@Ganesh2303](https://discuss.elastic.co/u/Ganesh2303)\
**Replies:** 3\
**Last updated:** [August 1, 2023, 8:59am UTC](https://discuss.elastic.co/t/how-to-remove-a-user-from-role-mapping/339688 "2023-08-01T08:59:17Z")

</div>

HI Team, we are using ELK version 7.17.10 and we have created Roles to manage our indices. my question is if want to remove user from role mapping how do i perform by using Delete command. Looking forward your input. …

---

## [FunctionBeat not able to get CloudWatch Logs](https://discuss.elastic.co/t/functionbeat-not-able-to-get-cloudwatch-logs/339673)

<div class="topic-metadata">

**Author:** [@Vedant14](https://discuss.elastic.co/u/Vedant14)\
**Replies:** 1\
**Last updated:** [August 1, 2023, 8:50am UTC](https://discuss.elastic.co/t/functionbeat-not-able-to-get-cloudwatch-logs/339673 "2023-08-01T08:50:57Z")

</div>

We are trying to fetch the CloudWatch logs in Elastic using FunctionBeat. The function is getting deployed successfully but not able to give the Cloudwatch data in Elastic. We did the configurations for the FunctionBeat …

---

## [Failed to start Filebeat](https://discuss.elastic.co/t/failed-to-start-filebeat/339743)

<div class="topic-metadata">

**Author:** [@rkannan](https://discuss.elastic.co/u/rkannan)\
**Replies:** 1\
**Last updated:** [August 1, 2023, 8:36am UTC](https://discuss.elastic.co/t/failed-to-start-filebeat/339743 "2023-08-01T08:36:49Z")

</div>

Failed to start Filebeat sends log files to Logstash or directly to Elasticsearch , please find the attached screen shot,

---

## [Get all fieldnames of index from](https://discuss.elastic.co/t/get-all-fieldnames-of-index-from/339769)

<div class="topic-metadata">

**Author:** [@aniket\_mandhare](https://discuss.elastic.co/u/aniket_mandhare)\
**Replies:** 0\
**Last updated:** [August 1, 2023, 8:27am UTC](https://discuss.elastic.co/t/get-all-fieldnames-of-index-from/339769 "2023-08-01T08:27:39Z")

</div>

How to get all only fieldnames(key name) and not the values of it from index in Elasticsearch I tried using following request GET /my\_index/\_field\_caps?fields=\*&filter\_path=fields.\* Expected output { fields:{ "fiel…

---

## [Cluster config](https://discuss.elastic.co/t/cluster-config/339767)

<div class="topic-metadata">

**Author:** [@gagidza](https://discuss.elastic.co/u/gagidza)\
**Replies:** 0\
**Last updated:** [August 1, 2023, 8:21am UTC](https://discuss.elastic.co/t/cluster-config/339767 "2023-08-01T08:21:13Z")

</div>

Hi all. Expert help needed. I have a 1 node cluster with a 7.4 TB hard drive dedicated to it. The server has 32 GB of RAM. Elastic is configured automatically and here are some of its health/stats: health: { "cluster…

---

## [Elasticsearch-java query slowly](https://discuss.elastic.co/t/elasticsearch-java-query-slowly/339382)

<div class="topic-metadata">

**Author:** [@gaorui](https://discuss.elastic.co/u/gaorui)\
**Replies:** 12\
**Last updated:** [August 1, 2023, 8:19am UTC](https://discuss.elastic.co/t/elasticsearch-java-query-slowly/339382 "2023-08-01T08:19:58Z")

</div>

We have an es cluster, a single node, the version is 8.5.3, and then the java program is linked to do the query. The problem now is that the response speed is within 10ms when we directly curl the query on the host where…

---

## [Tuning of index segmentation](https://discuss.elastic.co/t/tuning-of-index-segmentation/339763)

<div class="topic-metadata">

**Author:** [@INS](https://discuss.elastic.co/u/INS)\
**Replies:** 0\
**Last updated:** [August 1, 2023, 8:11am UTC](https://discuss.elastic.co/t/tuning-of-index-segmentation/339763 "2023-08-01T08:11:11Z")

</div>

Hi I am curious if this is recommended or if there are any tips about set parameters for segmentation. In my case the index is refreshed frequently (new data is uploaded and old data is deleted) what values or segment…

---

## [A failure occurred due to an unknown query](https://discuss.elastic.co/t/a-failure-occurred-due-to-an-unknown-query/339591)

<div class="topic-metadata">

**Author:** [@slowup](https://discuss.elastic.co/u/slowup)\
**Replies:** 2\
**Last updated:** [August 1, 2023, 7:04am UTC](https://discuss.elastic.co/t/a-failure-occurred-due-to-an-unknown-query/339591 "2023-08-01T07:04:01Z")

</div>

A query was performed that didn't originate from our team, and this caused a brief breakdown. Do you know where this query originates from? The version is 6.8 and I am using elasticsearch, not opensearch. { "size":…

[Previous page](https://discuss.elastic.co/latest.md?page=586)

[Next page](https://discuss.elastic.co/latest.md?page=588)
