# Latest

**URL:** https://discuss.elastic.co/latest.md?page=588

[Latest](https://discuss.elastic.co/latest.md) · [Categories](https://discuss.elastic.co/categories.md) · [Tags](https://discuss.elastic.co/tags.md)

**Page:** 589

---

## [Elasticsearch Python Lib](https://discuss.elastic.co/t/elasticsearch-python-lib/339751)

<div class="topic-metadata">

**Author:** [@Vivek\_Burman](https://discuss.elastic.co/u/Vivek_Burman)\
**Replies:** 0\
**Last updated:** [August 1, 2023, 6:17am UTC](https://discuss.elastic.co/t/elasticsearch-python-lib/339751 "2023-08-01T06:17:58Z")

</div>

Hi, I'm using Elastic Search python lib (8.8.2) to bulk insert data into a index. There are almost 2lakh+ documents I need to insert. I'm using parallel\_bulk api to sync them, but as I track the process RAM usage I see …

---

## [Kibana discover page does not show all documents in list, the timeline does](https://discuss.elastic.co/t/kibana-discover-page-does-not-show-all-documents-in-list-the-timeline-does/339710)

<div class="topic-metadata">

**Author:** [@jori-be](https://discuss.elastic.co/u/jori-be)\
**Replies:** 2\
**Last updated:** [August 1, 2023, 6:13am UTC](https://discuss.elastic.co/t/kibana-discover-page-does-not-show-all-documents-in-list-the-timeline-does/339710 "2023-08-01T06:13:20Z")

</div>

Hi guys, I see strange behavior in Kibana 8.5.3 in the discover page. When I'm filtering on data in discover page, I do not see all the documents that exist in the index-pattern. As you see on the screenshot above,…

---

## [At which step does Bulkresponse occur](https://discuss.elastic.co/t/at-which-step-does-bulkresponse-occur/339740)

<div class="topic-metadata">

**Author:** [@Logan-lxw](https://discuss.elastic.co/u/Logan-lxw)\
**Replies:** 0\
**Last updated:** [August 1, 2023, 3:40am UTC](https://discuss.elastic.co/t/at-which-step-does-bulkresponse-occur/339740 "2023-08-01T03:40:24Z")

</div>

At which stage does the BulkResponse corresponding to BulkRequest occur? Which step does this response specifically refer to before returning? Does it mean that the request was successfully written to the translog and fl…

---

## [Runtime get month()](https://discuss.elastic.co/t/runtime-get-month/339721)

<div class="topic-metadata">

**Author:** [@Murilo\_Livorato](https://discuss.elastic.co/u/Murilo_Livorato)\
**Replies:** 1\
**Last updated:** [August 1, 2023, 3:07am UTC](https://discuss.elastic.co/t/runtime-get-month/339721 "2023-08-01T03:07:22Z")

</div>

hello , I have this runtime - GET my-index-000006-test/\_search { "runtime\_mappings": { "day\_of\_week": { "type": "keyword", "script": { "source": "emit(doc\['timestamp'\].value.dayOfWeek…

---

## [An index has stayed on the same action longer than expected](https://discuss.elastic.co/t/an-index-has-stayed-on-the-same-action-longer-than-expected/339636)

<div class="topic-metadata">

**Author:** [@nitinkapoor](https://discuss.elastic.co/u/nitinkapoor)\
**Replies:** 2\
**Last updated:** [August 1, 2023, 1:46am UTC](https://discuss.elastic.co/t/an-index-has-stayed-on-the-same-action-longer-than-expected/339636 "2023-08-01T01:46:06Z")

</div>

I have upgraded my Elastic stack from 8.82 to 8.9 and facing this warning for one of my indices Deployment\_management Automatic index lifecycle and data retention management cannot make progress on one or more indices.…

---

## [Logstash JDBC Input Plugin Connection Pooling](https://discuss.elastic.co/t/logstash-jdbc-input-plugin-connection-pooling/337823)

<div class="topic-metadata">

**Author:** [@alromos](https://discuss.elastic.co/u/alromos)\
**Replies:** 4\
**Last updated:** [July 31, 2023, 11:08pm UTC](https://discuss.elastic.co/t/logstash-jdbc-input-plugin-connection-pooling/337823 "2023-07-31T23:08:35Z")

</div>

Our team is actively using Logstash JDBC Input plugin with MSSQL JDBC driver for reading some data from DB for further processing. Logstash version: 8.5.1 MSSQL JDBC version: 11.2.1.jre17 At the moment we are facing s…

---

## [Fetching substring from a string in kibana](https://discuss.elastic.co/t/fetching-substring-from-a-string-in-kibana/338203)

<div class="topic-metadata">

**Author:** [@Neelam\_Zanvar](https://discuss.elastic.co/u/Neelam_Zanvar)\
**Replies:** 8\
**Last updated:** [July 31, 2023, 8:58pm UTC](https://discuss.elastic.co/t/fetching-substring-from-a-string-in-kibana/338203 "2023-07-31T20:58:31Z")

</div>

Hi, I have a field called url in elasticsearch document. The sample value for the field is /3dpassport/login I want to extract only the first string before / that is 3dpassport and store it in a field. I am okay with …

---

## [Question on Vega Circle plot](https://discuss.elastic.co/t/question-on-vega-circle-plot/339734)

<div class="topic-metadata">

**Author:** [@vkon](https://discuss.elastic.co/u/vkon)\
**Replies:** 1\
**Last updated:** [July 31, 2023, 8:29pm UTC](https://discuss.elastic.co/t/question-on-vega-circle-plot/339734 "2023-07-31T20:29:12Z")

</div>

Hi, I'm using Elastic 7.17 version and trying to create Circle visualization using Vega. I have the below sample data; \[ {"stage":"s1","indicator":"i1","score":3,"maxscore":4}, {"stage":"s1","indicator":"i1","score":1…

---

## [Select latest docs for each transactions and apply filters on selections with pagination capability](https://discuss.elastic.co/t/select-latest-docs-for-each-transactions-and-apply-filters-on-selections-with-pagination-capability/339730)

<div class="topic-metadata">

**Author:** [@pramodbhade](https://discuss.elastic.co/u/pramodbhade)\
**Replies:** 0\
**Last updated:** [July 31, 2023, 8:12pm UTC](https://discuss.elastic.co/t/select-latest-docs-for-each-transactions-and-apply-filters-on-selections-with-pagination-capability/339730 "2023-07-31T20:12:31Z")

</div>

I have a situation where I need to load 100 records per page with the latest values and be able to paginate as well. The selected latest records also get filtered for a set of filter values. I'm using aggregation in th…

---

## [Aggregate filter plugin](https://discuss.elastic.co/t/aggregate-filter-plugin/339709)

<div class="topic-metadata">

**Author:** [@pero](https://discuss.elastic.co/u/pero)\
**Replies:** 2\
**Last updated:** [July 31, 2023, 8:06pm UTC](https://discuss.elastic.co/t/aggregate-filter-plugin/339709 "2023-07-31T20:06:22Z")

</div>

I have these two json documents Document 1 is { "\_index": "auditbeat-2023.07.31", "\_type": "\_doc", "\_id": "KhknrIkBBEGDHOFEynSE", "\_version": 1, "\_score": null, "\_source": { "ecs": { "version": "1…

---

## [It is that possible to I return in my Elasticsearch query a new field , that does not exist in the mapping . With a new format from other field?](https://discuss.elastic.co/t/it-is-that-possible-to-i-return-in-my-elasticsearch-query-a-new-field-that-does-not-exist-in-the-mapping-with-a-new-format-from-other-field/339616)

<div class="topic-metadata">

**Author:** [@Murilo\_Livorato](https://discuss.elastic.co/u/Murilo_Livorato)\
**Replies:** 4\
**Last updated:** [July 31, 2023, 6:46pm UTC](https://discuss.elastic.co/t/it-is-that-possible-to-i-return-in-my-elasticsearch-query-a-new-field-that-does-not-exist-in-the-mapping-with-a-new-format-from-other-field/339616 "2023-07-31T18:46:41Z")

</div>

It is that possible to I return in my Elasticsearch query a new field ( that does not exist in the mapping ), with a new format from other field ? something like that - This is my Mapping - PUT /user-product-2023-06…

---

## [I want to create kibana dashboard with clickable field](https://discuss.elastic.co/t/i-want-to-create-kibana-dashboard-with-clickable-field/339682)

<div class="topic-metadata">

**Author:** [@fenixon](https://discuss.elastic.co/u/fenixon)\
**Replies:** 1\
**Last updated:** [July 31, 2023, 5:48pm UTC](https://discuss.elastic.co/t/i-want-to-create-kibana-dashboard-with-clickable-field/339682 "2023-07-31T17:48:13Z")

</div>

This is one of my dashboard.I want to create this field(I marked with red colour round) as clickable and open the popup and show details of this number.

---

## [Metricbeat beats x-pack monitoring + Logstash output not appearing in Kibana monitoring GUI](https://discuss.elastic.co/t/metricbeat-beats-x-pack-monitoring-logstash-output-not-appearing-in-kibana-monitoring-gui/339716)

<div class="topic-metadata">

**Author:** [@novaksam](https://discuss.elastic.co/u/novaksam)\
**Replies:** 1\
**Last updated:** [July 31, 2023, 5:33pm UTC](https://discuss.elastic.co/t/metricbeat-beats-x-pack-monitoring-logstash-output-not-appearing-in-kibana-monitoring-gui/339716 "2023-07-31T17:33:43Z")

</div>

Hey all, As I migrate to Elastic Stack 8 I'm working on migrating all monitoring over to Metricbeat, and because I may have beats installed on more widely accessible locations, I'm wanting to use Logstash output for met…

---

## [Add multiple filters based on geo distance on same index](https://discuss.elastic.co/t/add-multiple-filters-based-on-geo-distance-on-same-index/339623)

<div class="topic-metadata">

**Author:** [@alchemist23](https://discuss.elastic.co/u/alchemist23)\
**Replies:** 2\
**Last updated:** [July 31, 2023, 5:27pm UTC](https://discuss.elastic.co/t/add-multiple-filters-based-on-geo-distance-on-same-index/339623 "2023-07-31T17:27:16Z")

</div>

Hello , I have a single index containing starbucks location data , a data view is based on an index from Elasticsearch I wish to display results on kibana visualization based on the distance with different color coding …

---

## [Cardinality Limitation Work Around](https://discuss.elastic.co/t/cardinality-limitation-work-around/339453)

<div class="topic-metadata">

**Author:** [@edang](https://discuss.elastic.co/u/edang)\
**Replies:** 0\
**Last updated:** [July 27, 2023, 2:44pm UTC](https://discuss.elastic.co/t/cardinality-limitation-work-around/339453 "2023-07-27T14:44:22Z")

</div>

Hi All, With my data set I have seen a mismatch of data between ELK and my DB. For my purpose, I have used the cardinality aggregation to count the unique ids of a field but ran into some issues. The issues comes from t…

---

## [Autocomplete using Completion Suggesters](https://discuss.elastic.co/t/autocomplete-using-completion-suggesters/338823)

<div class="topic-metadata">

**Author:** [@Senchok](https://discuss.elastic.co/u/Senchok)\
**Replies:** 7\
**Last updated:** [July 31, 2023, 5:12pm UTC](https://discuss.elastic.co/t/autocomplete-using-completion-suggesters/338823 "2023-07-31T17:12:04Z")

</div>

Hello, I want to write Autocomplete using Elasticsearch. I use Completion Suggesters and I have problems with it. For example I have fullName and title fields "fullName": "John Smith" "title": "Python Developer" B…

---

## [Error when setting up Alerts in Observability](https://discuss.elastic.co/t/error-when-setting-up-alerts-in-observability/339468)

<div class="topic-metadata">

**Author:** [@elastic12](https://discuss.elastic.co/u/elastic12)\
**Replies:** 0\
**Last updated:** [July 27, 2023, 5:45pm UTC](https://discuss.elastic.co/t/error-when-setting-up-alerts-in-observability/339468 "2023-07-27T17:45:25Z")

</div>

I am setting up an Log Threshold alert using index connector. I followed all the steps shown in the documentation Index connector and action | Kibana Guide \[8.6\] | Elastic and I am getting an error shown below "Rule re…

---

## [Collecting Sophos XG logs using the Sophos integration feature](https://discuss.elastic.co/t/collecting-sophos-xg-logs-using-the-sophos-integration-feature/339565)

<div class="topic-metadata">

**Author:** [@TIT](https://discuss.elastic.co/u/TIT)\
**Replies:** 5\
**Last updated:** [July 31, 2023, 5:10pm UTC](https://discuss.elastic.co/t/collecting-sophos-xg-logs-using-the-sophos-integration-feature/339565 "2023-07-31T17:10:00Z")

</div>

Hello, I'm currently trying to integrate Sophos XG firewall logs into my ELK stack via the Filebeat Sophos module. My setup involves sending logs directly from my Sophos XG device to Elasticsearch, bypassing Logstash. T…

---

## [Logstash filter mutate problem](https://discuss.elastic.co/t/logstash-filter-mutate-problem/339690)

<div class="topic-metadata">

**Author:** [@pero](https://discuss.elastic.co/u/pero)\
**Replies:** 12\
**Last updated:** [July 31, 2023, 3:01pm UTC](https://discuss.elastic.co/t/logstash-filter-mutate-problem/339690 "2023-07-31T15:01:14Z")

</div>

I have created a filter as shown below filter { if \[application\] == "today" { if field1 { mutate { add\_field =\> { mynewfield =\> "%{\[field1\]}" } …

---

## [ECE Fundamentals - step 3.13](https://discuss.elastic.co/t/ece-fundamentals-step-3-13/339479)

<div class="topic-metadata">

**Author:** [@mbowman](https://discuss.elastic.co/u/mbowman)\
**Replies:** 1\
**Last updated:** [July 31, 2023, 2:42pm UTC](https://discuss.elastic.co/t/ece-fundamentals-step-3-13/339479 "2023-07-31T14:42:18Z")

</div>

Course: ECE Fundamental Version: E-E04NO1 Question: When trying to access Kibana on lab 3 step 13, I am receiving a SAML related error and that the endpoint is not reachable. I have tried restarting my\_cluster but it …

---

## [Kibana Machine Learning Job Alert](https://discuss.elastic.co/t/kibana-machine-learning-job-alert/339151)

<div class="topic-metadata">

**Author:** [@Aniket\_Pant](https://discuss.elastic.co/u/Aniket_Pant)\
**Replies:** 7\
**Last updated:** [July 31, 2023, 2:38pm UTC](https://discuss.elastic.co/t/kibana-machine-learning-job-alert/339151 "2023-07-31T14:38:56Z")

</div>

Hi Team, We have created alert for anomaly detection and we are getting this alert on email. It is showing different timestamp Elastic Stack Machine Learning Alert: - Job IDs: {{context.jobIds}} - Time: {{context.time…

---

## [Where is the certificate authority that signs elastic images using cosign?](https://discuss.elastic.co/t/where-is-the-certificate-authority-that-signs-elastic-images-using-cosign/339699)

<div class="topic-metadata">

**Author:** [@data\_smith](https://discuss.elastic.co/u/data_smith)\
**Replies:** 0\
**Last updated:** [July 31, 2023, 1:45pm UTC](https://discuss.elastic.co/t/where-is-the-certificate-authority-that-signs-elastic-images-using-cosign/339699 "2023-07-31T13:45:05Z")

</div>

Elastic now signs images using cosign to strengthen the supply chain. I'd like to run these images in Kubernetes and use Kyverno to verify the images but i get the error: "certificate signed by unknown authority". Wher…

---

## [Hide black bar in iframe](https://discuss.elastic.co/t/hide-black-bar-in-iframe/339698)

<div class="topic-metadata">

**Author:** [@Rushi\_Bagul](https://discuss.elastic.co/u/Rushi_Bagul)\
**Replies:** 2\
**Last updated:** [July 31, 2023, 1:54pm UTC](https://discuss.elastic.co/t/hide-black-bar-in-iframe/339698 "2023-07-31T13:54:29Z")

</div>

I have Python application in which I want render iframe kibana dashboard and want hide black bar in which elastic logo also view. I am attach photo please suggest how can I hide this black bar .

---

## [Searching with runtime, without mapping with runtime](https://discuss.elastic.co/t/searching-with-runtime-without-mapping-with-runtime/339696)

<div class="topic-metadata">

**Author:** [@Murilo\_Livorato](https://discuss.elastic.co/u/Murilo_Livorato)\
**Replies:** 2\
**Last updated:** [July 31, 2023, 1:48pm UTC](https://discuss.elastic.co/t/searching-with-runtime-without-mapping-with-runtime/339696 "2023-07-31T13:48:55Z")

</div>

hello , I am trying to learn runtime . it uses in the script the painless language , It wold be nice to I understand this language , that I could test it before mapping . the way to test it before mapping it is search …

---

## [Heartbeath - error: Please make sure that multiple beats are not sharing the same data path (path.data)](https://discuss.elastic.co/t/heartbeath-error-please-make-sure-that-multiple-beats-are-not-sharing-the-same-data-path-path-data/339396)

<div class="topic-metadata">

**Author:** [@yari\_arcopinto](https://discuss.elastic.co/u/yari_arcopinto)\
**Replies:** 8\
**Last updated:** [July 31, 2023, 1:45pm UTC](https://discuss.elastic.co/t/heartbeath-error-please-make-sure-that-multiple-beats-are-not-sharing-the-same-data-path-path-data/339396 "2023-07-31T13:45:16Z")

</div>

Hello to all, I have installed on my ubuntu server the module Heartbeat for monitoring the healthy of infrastructure server, by the way i'm facing with the issue: Please make sure that multiple beats are not sharing th…

---

## [Removing prefix from field names](https://discuss.elastic.co/t/removing-prefix-from-field-names/339674)

<div class="topic-metadata">

**Author:** [@VirusProtect](https://discuss.elastic.co/u/VirusProtect)\
**Replies:** 2\
**Last updated:** [July 31, 2023, 1:39pm UTC](https://discuss.elastic.co/t/removing-prefix-from-field-names/339674 "2023-07-31T13:39:33Z")

</div>

Hi, I have fields in Kibana such as fw.ip, fw.name, fw.test.old, and so on. I am trying to remove the "fw" prefix from all these fields using a Ruby filter in Logstash. Here's the code I'm using: ruby { code =\> " …

---

## [Filebeat to add extra fields for logstash 7.17, it worked previously but not anymore?](https://discuss.elastic.co/t/filebeat-to-add-extra-fields-for-logstash-7-17-it-worked-previously-but-not-anymore/339670)

<div class="topic-metadata">

**Author:** [@fribse](https://discuss.elastic.co/u/fribse)\
**Replies:** 1\
**Last updated:** [July 31, 2023, 1:12pm UTC](https://discuss.elastic.co/t/filebeat-to-add-extra-fields-for-logstash-7-17-it-worked-previously-but-not-anymore/339670 "2023-07-31T13:12:14Z")

</div>

I have my dmarc interpreter running here, and noticed that it didn't produce any data to the kibana. It looks like the config is ignored with the 7.17, and back when it was 6.x it worked. Can you tell me what I've done…

---

## [It is possible to set (logstash.conf )output for particular file location in logstash server](https://discuss.elastic.co/t/it-is-possible-to-set-logstash-conf-output-for-particular-file-location-in-logstash-server/339664)

<div class="topic-metadata">

**Author:** [@rkannan](https://discuss.elastic.co/u/rkannan)\
**Replies:** 2\
**Last updated:** [July 31, 2023, 12:47pm UTC](https://discuss.elastic.co/t/it-is-possible-to-set-logstash-conf-output-for-particular-file-location-in-logstash-server/339664 "2023-07-31T12:47:17Z")

</div>

It is possible to set (logstash.conf )output for particular file location in logstash server

---

## [Diferencia valores desde visualice con DevTools](https://discuss.elastic.co/t/diferencia-valores-desde-visualice-con-devtools/339691)

<div class="topic-metadata">

**Author:** [@Javier\_Garcia\_Alvare](https://discuss.elastic.co/u/Javier_Garcia_Alvare)\
**Replies:** 0\
**Last updated:** [July 31, 2023, 12:15pm UTC](https://discuss.elastic.co/t/diferencia-valores-desde-visualice-con-devtools/339691 "2023-07-31T12:15:30Z")

</div>

Hola, elasticSearch: 7.17.5 Diferencia de valores cuando el datos se presenta mediante lens tipo tabla con diferentes métricas y query desde DevTools. La métrica que se aplica en un count del filtro que se ejecuta en l…

---

## [Auditbeat logs many warnings](https://discuss.elastic.co/t/auditbeat-logs-many-warnings/339689)

<div class="topic-metadata">

**Author:** [@floriankoenig-work](https://discuss.elastic.co/u/floriankoenig-work)\
**Replies:** 0\
**Last updated:** [July 31, 2023, 12:10pm UTC](https://discuss.elastic.co/t/auditbeat-logs-many-warnings/339689 "2023-07-31T12:10:27Z")

</div>

I've noticed auditbeat spamming (sometimes ~10/sec) the log with following messages: Jul 30 00:04:44 HOSTNAME auditbeat\[2327385\]: {"log.level":"warn","@timestamp":"2023-07-30T00:04:44.668+0200","log.logger":"process","l…

[Previous page](https://discuss.elastic.co/latest.md?page=587)

[Next page](https://discuss.elastic.co/latest.md?page=589)
