# Latest

**URL:** https://discuss.elastic.co/latest.md?page=590

[Latest](https://discuss.elastic.co/latest.md) · [Categories](https://discuss.elastic.co/categories.md) · [Tags](https://discuss.elastic.co/tags.md)

**Page:** 591

---

## [Split type failure Logstash](https://discuss.elastic.co/t/split-type-failure-logstash/339594)

<div class="topic-metadata">

**Author:** [@Bharat\_Lahori](https://discuss.elastic.co/u/Bharat_Lahori)\
**Replies:** 2\
**Last updated:** [July 29, 2023, 5:58pm UTC](https://discuss.elastic.co/t/split-type-failure-logstash/339594 "2023-07-29T17:58:16Z")

</div>

Dear Team, I have configured below logstash conf file . Trying to give stdin input and getting an error as split type failure. PFB details. We need to create two events based on metricValues. Conf file input { stdi…

---

## [Data storage location for elasticseach on docker](https://discuss.elastic.co/t/data-storage-location-for-elasticseach-on-docker/339602)

<div class="topic-metadata">

**Author:** [@Mataz](https://discuss.elastic.co/u/Mataz)\
**Replies:** 1\
**Last updated:** [July 29, 2023, 5:47pm UTC](https://discuss.elastic.co/t/data-storage-location-for-elasticseach-on-docker/339602 "2023-07-29T17:47:31Z")

</div>

I am trying to install elasticsearch for docker but I got stuck with configuring the data storage location for the logs collected from the log aggregators coming to elasticsearch. Basically I need to store the data on th…

---

## [routingOptions: how to merge custom functions with defaults?](https://discuss.elastic.co/t/routingoptions-how-to-merge-custom-functions-with-defaults/339578)

<div class="topic-metadata">

**Author:** [@dorothea](https://discuss.elastic.co/u/dorothea)\
**Replies:** 3\
**Last updated:** [July 29, 2023, 12:00pm UTC](https://discuss.elastic.co/t/routingoptions-how-to-merge-custom-functions-with-defaults/339578 "2023-07-29T12:00:30Z")

</div>

I see that it's possible to customize how search parameters get serialized by writing my own routingOptions object as shown here: Configuration | Elastic docs Can I customize selected parts of this, perhaps just the sta…

---

## [Add alias to existing indices (and newly created indices) using Kibana UI](https://discuss.elastic.co/t/add-alias-to-existing-indices-and-newly-created-indices-using-kibana-ui/339147)

<div class="topic-metadata">

**Author:** [@shawnmin](https://discuss.elastic.co/u/shawnmin)\
**Replies:** 3\
**Last updated:** [July 29, 2023, 2:54am UTC](https://discuss.elastic.co/t/add-alias-to-existing-indices-and-newly-created-indices-using-kibana-ui/339147 "2023-07-29T02:54:27Z")

</div>

I've set up an EFK stack on my Kubernetes cluster. I want to automatically delete indices after certain days later (i.e., log retention and rotation), so I've created an index lifecycle policy. The policy's name is dele…

---

## [Simple Anomaly Detection Question](https://discuss.elastic.co/t/simple-anomaly-detection-question/339580)

<div class="topic-metadata">

**Author:** [@McJava1967](https://discuss.elastic.co/u/McJava1967)\
**Replies:** 1\
**Last updated:** [July 29, 2023, 1:01am UTC](https://discuss.elastic.co/t/simple-anomaly-detection-question/339580 "2023-07-29T01:01:04Z")

</div>

Hi all. I'm a newbie at Anomaly Detection. Let's say I have a key, "PET", with two possible values, "CAT" and "DOG". I want to detect when there are an unusual number of CATs in an hour. Is that possible? I thought …

---

## [Logstash Json Parsing Error](https://discuss.elastic.co/t/logstash-json-parsing-error/339515)

<div class="topic-metadata">

**Author:** [@fizem](https://discuss.elastic.co/u/fizem)\
**Replies:** 1\
**Last updated:** [July 28, 2023, 9:03pm UTC](https://discuss.elastic.co/t/logstash-json-parsing-error/339515 "2023-07-28T21:03:46Z")

</div>

Hi, I have setup the following pipeline to consolidate my logs in Elastic Search Cluster : filebeat to gather nginx logs ==\> logstash to parse the log and mutate them if needed ==\> Elasticsearch cluster. I'm facing an…

---

## [How to validate a json value is numeric](https://discuss.elastic.co/t/how-to-validate-a-json-value-is-numeric/339562)

<div class="topic-metadata">

**Author:** [@sc5283](https://discuss.elastic.co/u/sc5283)\
**Replies:** 4\
**Last updated:** [July 28, 2023, 9:01pm UTC](https://discuss.elastic.co/t/how-to-validate-a-json-value-is-numeric/339562 "2023-07-28T21:01:27Z")

</div>

noob question I have a JSON as follows: {"attr1":"One", "attr2":"300"} {"attr1":"Two","attr2":45.0} {"attr1":"Three","attr2":"Not Set"} attr2 is a numeric value How do I check if attr2 is numeric, not a string befo…

---

## [.NET client connect to elastic search using SSL](https://discuss.elastic.co/t/net-client-connect-to-elastic-search-using-ssl/339554)

<div class="topic-metadata">

**Author:** [@Nilesh\_Jethwani](https://discuss.elastic.co/u/Nilesh_Jethwani)\
**Replies:** 0\
**Last updated:** [July 28, 2023, 1:43pm UTC](https://discuss.elastic.co/t/net-client-connect-to-elastic-search-using-ssl/339554 "2023-07-28T13:43:53Z")

</div>

We want to connect our .NET application to elasticsearch 8.5.2 single node cluster. We want to use https and ssl communication. We have 3 certificates from our CA. root , intermediate and main along with private key. …

---

## [Phrase suggester giving suggestion on correct terms containing number values](https://discuss.elastic.co/t/phrase-suggester-giving-suggestion-on-correct-terms-containing-number-values/339579)

<div class="topic-metadata">

**Author:** [@Pavithra2014](https://discuss.elastic.co/u/Pavithra2014)\
**Replies:** 0\
**Last updated:** [July 28, 2023, 6:14pm UTC](https://discuss.elastic.co/t/phrase-suggester-giving-suggestion-on-correct-terms-containing-number-values/339579 "2023-07-28T18:14:33Z")

</div>

Team, We are using Phrase suggestion with below configuration. but this is returning suggestion on correct speeled words having numeric values on it. eg: Product 2023 is giving the suggestion Product 2022 . I'm expect…

---

## [I want send a duplicate or clone of my data throught logstash to another kibana/elastic adminitrador](https://discuss.elastic.co/t/i-want-send-a-duplicate-or-clone-of-my-data-throught-logstash-to-another-kibana-elastic-adminitrador/339228)

<div class="topic-metadata">

**Author:** [@hlcxpl](https://discuss.elastic.co/u/hlcxpl)\
**Replies:** 3\
**Last updated:** [July 28, 2023, 5:10pm UTC](https://discuss.elastic.co/t/i-want-send-a-duplicate-or-clone-of-my-data-throught-logstash-to-another-kibana-elastic-adminitrador/339228 "2023-07-28T17:10:56Z")

</div>

how could i duplicate the data or send de same data to another elastic, the logstash version is 7.17 while elastic version where i want to receive is 8.8.2, i try with the output configuration but i received this err…

---

## [Is it possible to for winlogbeat to send original raw logs?](https://discuss.elastic.co/t/is-it-possible-to-for-winlogbeat-to-send-original-raw-logs/339559)

<div class="topic-metadata">

**Author:** [@reswob](https://discuss.elastic.co/u/reswob)\
**Replies:** 2\
**Last updated:** [July 28, 2023, 4:37pm UTC](https://discuss.elastic.co/t/is-it-possible-to-for-winlogbeat-to-send-original-raw-logs/339559 "2023-07-28T16:37:54Z")

</div>

For management reasons I need to ask: Is it possible to send the raw windows log (xml or text uncooked) via winlogbeat? Thanks

---

## [Sharing dashboard link publically in an iframe](https://discuss.elastic.co/t/sharing-dashboard-link-publically-in-an-iframe/339570)

<div class="topic-metadata">

**Author:** [@Mitali\_Surwase](https://discuss.elastic.co/u/Mitali_Surwase)\
**Replies:** 1\
**Last updated:** [July 28, 2023, 4:12pm UTC](https://discuss.elastic.co/t/sharing-dashboard-link-publically-in-an-iframe/339570 "2023-07-28T16:12:24Z")

</div>

I want to share the dashboard link to the front end to show the dashboard on the angular ./net application and give the link in the form of iframe. I want the dashboard to be seen to everyone publically without login , s…

---

## [Validate document before sending to elasticsearch](https://discuss.elastic.co/t/validate-document-before-sending-to-elasticsearch/337859)

<div class="topic-metadata">

**Author:** [@A\_Mightiev](https://discuss.elastic.co/u/A_Mightiev)\
**Replies:** 2\
**Last updated:** [July 28, 2023, 3:19pm UTC](https://discuss.elastic.co/t/validate-document-before-sending-to-elasticsearch/337859 "2023-07-28T15:19:00Z")

</div>

Hi, I have a strict mapping in my ES cluster and send documents via Logstash, sometimes the documents get dropped because they don't conform the strict mapping, is there a way to check if the document conforms or not to…

---

## [Translation does not work in Logged Out Page and Apply Filters in Unified Search](https://discuss.elastic.co/t/translation-does-not-work-in-logged-out-page-and-apply-filters-in-unified-search/338341)

<div class="topic-metadata">

**Author:** [@wsbr](https://discuss.elastic.co/u/wsbr)\
**Replies:** 8\
**Last updated:** [July 28, 2023, 3:12pm UTC](https://discuss.elastic.co/t/translation-does-not-work-in-logged-out-page-and-apply-filters-in-unified-search/338341 "2023-07-28T15:12:11Z")

</div>

Hi, We are using Elasticsearch 8.7.1 and some actions does not be translated. How to solve this problem?

---

## [How to use the JSON filter correctly?](https://discuss.elastic.co/t/how-to-use-the-json-filter-correctly/339372)

<div class="topic-metadata">

**Author:** [@Chel\_Db](https://discuss.elastic.co/u/Chel_Db)\
**Replies:** 13\
**Last updated:** [July 28, 2023, 2:27pm UTC](https://discuss.elastic.co/t/how-to-use-the-json-filter-correctly/339372 "2023-07-28T14:27:51Z")

</div>

Application logs is of below JSON format and I'm unsure what should be the source field incase I'm using the JSON filter ? I would like to have all the fields appear on the Kibana output, particularly the message field,…

---

## [Kibana login problem](https://discuss.elastic.co/t/kibana-login-problem/339538)

<div class="topic-metadata">

**Author:** [@Ibrahim\_Z\_HIDIR](https://discuss.elastic.co/u/Ibrahim_Z_HIDIR)\
**Replies:** 3\
**Last updated:** [July 28, 2023, 2:20pm UTC](https://discuss.elastic.co/t/kibana-login-problem/339538 "2023-07-28T14:20:36Z")

</div>

Hi all We are experiencing a problem when trying to login kibana 8.8.2, I could't find anythink, does anybody has an idea? thanks

---

## [Pass min\_score to shoudl close](https://discuss.elastic.co/t/pass-min-score-to-shoudl-close/339561)

<div class="topic-metadata">

**Author:** [@john\_nicolas](https://discuss.elastic.co/u/john_nicolas)\
**Replies:** 0\
**Last updated:** [July 28, 2023, 2:16pm UTC](https://discuss.elastic.co/t/pass-min-score-to-shoudl-close/339561 "2023-07-28T14:16:43Z")

</div>

i want to pass a min\_score but for only should clauses, i want filter should clause by min\_score to eliminate docs which have cosinesimilarity poor {'bool': {'filter': {'term': {'hidden': 'false'}}, 'must': \[{'bool': {'…

---

## [Can I reindex using a search template?](https://discuss.elastic.co/t/can-i-reindex-using-a-search-template/339556)

<div class="topic-metadata">

**Author:** [@A\_Mightiev](https://discuss.elastic.co/u/A_Mightiev)\
**Replies:** 1\
**Last updated:** [July 28, 2023, 2:03pm UTC](https://discuss.elastic.co/t/can-i-reindex-using-a-search-template/339556 "2023-07-28T14:03:14Z")

</div>

Would it be possible to use the \_reindex but instead of specifying the query, call a search template stored?

---

## [How to take the fleet server backup](https://discuss.elastic.co/t/how-to-take-the-fleet-server-backup/339068)

<div class="topic-metadata">

**Author:** [@ankitha\_sn](https://discuss.elastic.co/u/ankitha_sn)\
**Replies:** 13\
**Last updated:** [July 28, 2023, 1:51pm UTC](https://discuss.elastic.co/t/how-to-take-the-fleet-server-backup/339068 "2023-07-28T13:51:58Z")

</div>

Hi Team, Can I know how to take the backup of the fleet server? I have looked into the documentation and did not find any useful links. Thanks, Ankitha

---

## [Kibana is using 'anonymus\_access' instead of kibana\_system username](https://discuss.elastic.co/t/kibana-is-using-anonymus-access-instead-of-kibana-system-username/339544)

<div class="topic-metadata">

**Author:** [@Filip\_Drzewiecki](https://discuss.elastic.co/u/Filip_Drzewiecki)\
**Replies:** 1\
**Last updated:** [July 28, 2023, 1:27pm UTC](https://discuss.elastic.co/t/kibana-is-using-anonymus-access-instead-of-kibana-system-username/339544 "2023-07-28T13:27:26Z")

</div>

Hello everyone, First, let me say that I'm quite new to the ELK but I've tried my best to solve that issue myself. I'm trying to migrate my ELK stack from docker-compose to kubernetes (so I'm not using elastic operator…

---

## [Could not push logs to Elasticsearch cluster](https://discuss.elastic.co/t/could-not-push-logs-to-elasticsearch-cluster/339488)

<div class="topic-metadata">

**Author:** [@Vikas1633](https://discuss.elastic.co/u/Vikas1633)\
**Replies:** 1\
**Last updated:** [July 28, 2023, 1:16pm UTC](https://discuss.elastic.co/t/could-not-push-logs-to-elasticsearch-cluster/339488 "2023-07-28T13:16:04Z")

</div>

I am facing issue could not push logs to Elasticsearch cluster but when i change the buffer path and restart elastic it gets solved and every odd day I have to do this, looking for some permanent solution over this. :El…

---

## [Filebeat only sends the first log input](https://discuss.elastic.co/t/filebeat-only-sends-the-first-log-input/339549)

<div class="topic-metadata">

**Author:** [@dcz01](https://discuss.elastic.co/u/dcz01)\
**Replies:** 0\
**Last updated:** [July 28, 2023, 1:09pm UTC](https://discuss.elastic.co/t/filebeat-only-sends-the-first-log-input/339549 "2023-07-28T13:09:37Z")

</div>

Hello, I got an filebeat.yml with an filebeat 7.8.0 instance on an server which should send some logs to a central logstash but it only sends the first log input and the others seemd to be ignored or anything else. Can…

---

## [\_mget vs \_search for large amount of documents](https://discuss.elastic.co/t/mget-vs-search-for-large-amount-of-documents/339521)

<div class="topic-metadata">

**Author:** [@hattorihanzo](https://discuss.elastic.co/u/hattorihanzo)\
**Replies:** 4\
**Last updated:** [July 28, 2023, 12:40pm UTC](https://discuss.elastic.co/t/mget-vs-search-for-large-amount-of-documents/339521 "2023-07-28T12:40:39Z")

</div>

Hi there! I'm looking for some guidance around what's the most fit way to retrieve a large amount of documents (\>=1000) when you know their ID. I'd like it to be fast, yet efficient and not put unnecessary strain on ES s…

---

## [Need help dropping specific messages](https://discuss.elastic.co/t/need-help-dropping-specific-messages/339441)

<div class="topic-metadata">

**Author:** [@RJC](https://discuss.elastic.co/u/RJC)\
**Replies:** 4\
**Last updated:** [July 28, 2023, 12:31pm UTC](https://discuss.elastic.co/t/need-help-dropping-specific-messages/339441 "2023-07-28T12:31:15Z")

</div>

My logstash server generates the following messages every time it is restarted: {"syslog\_severity\_code":5,"syslog\_severity":"notice","syslog\_facility\_code":1,"message":"\\u0000\\u0016\\u0000\\u0014\\u0000\\u0017\\u0000\\u0018\\u…

---

## [Bulk indexing failed and after retrying 2 times. at Nest.BulkAllObservable\`1.\<BulkAsync\>d\_\_20.MoveNext()](https://discuss.elastic.co/t/bulk-indexing-failed-and-after-retrying-2-times-at-nest-bulkallobservable-1-bulkasync-d-20-movenext/339546)

<div class="topic-metadata">

**Author:** [@stkollamp](https://discuss.elastic.co/u/stkollamp)\
**Replies:** 0\
**Last updated:** [July 28, 2023, 12:26pm UTC](https://discuss.elastic.co/t/bulk-indexing-failed-and-after-retrying-2-times-at-nest-bulkallobservable-1-bulkasync-d-20-movenext/339546 "2023-07-28T12:26:08Z")

</div>

ElastiSearch 7.x is working completely fine with 7.15.x Nest Client and then I have migrated to Elasticsearch 8.8.1 and its response has shown that "minimum\_wire\_compatibility\_version" : "7.17.0". As suggested upgrade…

---

## [Alerting on watermark threshold - Available API or field inside elasticsearch?](https://discuss.elastic.co/t/alerting-on-watermark-threshold-available-api-or-field-inside-elasticsearch/339451)

<div class="topic-metadata">

**Author:** [@chouben](https://discuss.elastic.co/u/chouben)\
**Replies:** 1\
**Last updated:** [July 28, 2023, 12:05pm UTC](https://discuss.elastic.co/t/alerting-on-watermark-threshold-available-api-or-field-inside-elasticsearch/339451 "2023-07-28T12:05:41Z")

</div>

Hi I'm looking into a way on how to achieve monitoring of the watermark thresholds. We would like to add alerting once the first threshold passes. I do not want to use fixed sizes inside the alerts, but would like to u…

---

## [Colors for line graph](https://discuss.elastic.co/t/colors-for-line-graph/339370)

<div class="topic-metadata">

**Author:** [@Rushi\_Bagul](https://discuss.elastic.co/u/Rushi_Bagul)\
**Replies:** 2\
**Last updated:** [July 28, 2023, 11:24am UTC](https://discuss.elastic.co/t/colors-for-line-graph/339370 "2023-07-28T11:24:36Z")

</div>

I want to create line chart or area with different background colors on specific areas as per following image. Can anyone tell me how it is possible? Suggest me to better approach

---

## [Ingest sharepoint on premises files to elk](https://discuss.elastic.co/t/ingest-sharepoint-on-premises-files-to-elk/339522)

<div class="topic-metadata">

**Author:** [@sunny2502](https://discuss.elastic.co/u/sunny2502)\
**Replies:** 1\
**Last updated:** [July 28, 2023, 9:54am UTC](https://discuss.elastic.co/t/ingest-sharepoint-on-premises-files-to-elk/339522 "2023-07-28T09:54:22Z")

</div>

Hi I want to ingest data from local sharepoint to elastic using python, can anyone please help me in same.

---

## [Limit on number of Clusters supported by Cross cluster search (CCS)](https://discuss.elastic.co/t/limit-on-number-of-clusters-supported-by-cross-cluster-search-ccs/339525)

<div class="topic-metadata">

**Author:** [@siddhartha\_c](https://discuss.elastic.co/u/siddhartha_c)\
**Replies:** 0\
**Last updated:** [July 28, 2023, 9:52am UTC](https://discuss.elastic.co/t/limit-on-number-of-clusters-supported-by-cross-cluster-search-ccs/339525 "2023-07-28T09:52:55Z")

</div>

Can I have a Architectural design where in we have around 100 clusters of Elastic. Where in each cluster is basically a small set of Master Node and Data Nodes . Using Cross Cluster Search if we send the search queries…

---

## [Logstash - GCP cloud storage Output plugin](https://discuss.elastic.co/t/logstash-gcp-cloud-storage-output-plugin/339524)

<div class="topic-metadata">

**Author:** [@Luko](https://discuss.elastic.co/u/Luko)\
**Replies:** 0\
**Last updated:** [July 28, 2023, 9:48am UTC](https://discuss.elastic.co/t/logstash-gcp-cloud-storage-output-plugin/339524 "2023-07-28T09:48:21Z")

</div>

Hello Does Losgatsh Output plugin - google\_cloud\_storage, support the action based on the content of the field. I want to do something like that: output { google\_cloud\_storage { bucket =\> "bucket\_name/%{…

[Previous page](https://discuss.elastic.co/latest.md?page=589)

[Next page](https://discuss.elastic.co/latest.md?page=591)
