# Latest

**URL:** https://discuss.elastic.co/latest.md?page=595

[Latest](https://discuss.elastic.co/latest.md) · [Categories](https://discuss.elastic.co/categories.md) · [Tags](https://discuss.elastic.co/tags.md)

**Page:** 596

---

## [How to set up 3 dedicate master + 4 data nodes also master elegible](https://discuss.elastic.co/t/how-to-set-up-3-dedicate-master-4-data-nodes-also-master-elegible/338887)

<div class="topic-metadata">

**Author:** [@hlcxpl](https://discuss.elastic.co/u/hlcxpl)\
**Replies:** 15\
**Last updated:** [July 25, 2023, 7:05pm UTC](https://discuss.elastic.co/t/how-to-set-up-3-dedicate-master-4-data-nodes-also-master-elegible/338887 "2023-07-25T19:05:02Z")

</div>

i need to set up 3 master node dedicate and 4 data node and master elegibles this is my yml configuration path.data: /var/lib/elasticsearch path.logs: /var/log/elasticsearch bootstrap.memory\_lock: true cluster.name: C…

---

## [Aligning array elements with parent in table visualization](https://discuss.elastic.co/t/aligning-array-elements-with-parent-in-table-visualization/338962)

<div class="topic-metadata">

**Author:** [@Thomas.c](https://discuss.elastic.co/u/Thomas.c)\
**Replies:** 3\
**Last updated:** [July 25, 2023, 7:16pm UTC](https://discuss.elastic.co/t/aligning-array-elements-with-parent-in-table-visualization/338962 "2023-07-25T19:16:53Z")

</div>

I'm trying to create a table visualization in Kibana. My data structure is like this: Vehicle{ Vehicle Number Vehicle make Vehicle model Vehicle year} Each record can have multiple vehicles in it, so the parent Veh…

---

## [Completely remove mapping check](https://discuss.elastic.co/t/completely-remove-mapping-check/339198)

<div class="topic-metadata">

**Author:** [@dastial](https://discuss.elastic.co/u/dastial)\
**Replies:** 2\
**Last updated:** [July 25, 2023, 6:15pm UTC](https://discuss.elastic.co/t/completely-remove-mapping-check/339198 "2023-07-25T18:15:23Z")

</div>

I'm using ES8+ to store a lot of different document, but I've encountered some problems with property mapping. I am working with documents, each of which has hundreds of different fields, many of them with the same name.…

---

## [Join two searches with nested field](https://discuss.elastic.co/t/join-two-searches-with-nested-field/339213)

<div class="topic-metadata">

**Author:** [@Murilo\_Livorato](https://discuss.elastic.co/u/Murilo_Livorato)\
**Replies:** 2\
**Last updated:** [July 25, 2023, 5:23pm UTC](https://discuss.elastic.co/t/join-two-searches-with-nested-field/339213 "2023-07-25T17:23:05Z")

</div>

hello , I have been trying to join those two searches , but I didnt managed . I want to do this - SELECT user-data WHERE company.id = 1 AND timestamp BETWEEEN 2023-05-04 - 2023-06-05 // RESULT 100 GET /user-data/\_se…

---

## [Kibana server is not ready yet](https://discuss.elastic.co/t/kibana-server-is-not-ready-yet/339009)

<div class="topic-metadata">

**Author:** [@SUNA](https://discuss.elastic.co/u/SUNA)\
**Replies:** 9\
**Last updated:** [July 25, 2023, 4:27pm UTC](https://discuss.elastic.co/t/kibana-server-is-not-ready-yet/339009 "2023-07-25T16:27:43Z")

</div>

Hi Team, My ELK cluster running in one node. while clearing Queue, I had restarted kibana and elk services. from now my URL is stuck with below error. Kibana server is not ready yet In order to fix this i have restar…

---

## [Following the quickstart guide: getting "Kibana server is not ready yet."](https://discuss.elastic.co/t/following-the-quickstart-guide-getting-kibana-server-is-not-ready-yet/338938)

<div class="topic-metadata">

**Author:** [@chadleywilson](https://discuss.elastic.co/u/chadleywilson)\
**Replies:** 6\
**Last updated:** [July 25, 2023, 3:58pm UTC](https://discuss.elastic.co/t/following-the-quickstart-guide-getting-kibana-server-is-not-ready-yet/338938 "2023-07-25T15:58:32Z")

</div>

Hi I have followed the 2.8.0 quickstart guide to the letter I have used the own certificate method and the sites are secure, I am happy with that. I have configured DNS and load balancing, and the pods and services lo…

---

## [Multiple pipelines bug with pipe-to-pipe config and CEF codec](https://discuss.elastic.co/t/multiple-pipelines-bug-with-pipe-to-pipe-config-and-cef-codec/338889)

<div class="topic-metadata">

**Author:** [@Markenstein](https://discuss.elastic.co/u/Markenstein)\
**Replies:** 23\
**Last updated:** [July 25, 2023, 3:52pm UTC](https://discuss.elastic.co/t/multiple-pipelines-bug-with-pipe-to-pipe-config-and-cef-codec/338889 "2023-07-25T15:52:09Z")

</div>

Hi, everyone! I have faced with such problem: several CEF strings pushed into the following pipelines configuration causing \_cefparseerror in result cause to incorrect string in the input. It's break original message in…

---

## [Kibana cuts HH:mm:ss off date in Table visualization](https://discuss.elastic.co/t/kibana-cuts-hhss-off-date-in-table-visualization/339195)

<div class="topic-metadata">

**Author:** [@OrangeBanana](https://discuss.elastic.co/u/OrangeBanana)\
**Replies:** 2\
**Last updated:** [July 25, 2023, 3:23pm UTC](https://discuss.elastic.co/t/kibana-cuts-hhss-off-date-in-table-visualization/339195 "2023-07-25T15:23:50Z")

</div>

In Elasticsearch I have dates saved in the yyyy-MM-ddTHH:mm:ssZ format. However in my Kibana Table visualization only the yyyy-MM-dd part is shown. When I click on the data field in Kibana the date format is also shown a…

---

## [Filtering messages from Logstash codec rubydebug output](https://discuss.elastic.co/t/filtering-messages-from-logstash-codec-rubydebug-output/339212)

<div class="topic-metadata">

**Author:** [@zaeemmasood](https://discuss.elastic.co/u/zaeemmasood)\
**Replies:** 0\
**Last updated:** [July 25, 2023, 3:15pm UTC](https://discuss.elastic.co/t/filtering-messages-from-logstash-codec-rubydebug-output/339212 "2023-07-25T15:15:06Z")

</div>

Our logtsash conf file is using tcp input plugin to ingest messages from different ports. The output part is as follows: output { if \[@metadata\]\[indexPrefix\] { file { path =\> "/opt/total/l…

---

## [Alert when winlogbeat host stop sending events](https://discuss.elastic.co/t/alert-when-winlogbeat-host-stop-sending-events/339141)

<div class="topic-metadata">

**Author:** [@vladislav](https://discuss.elastic.co/u/vladislav)\
**Replies:** 3\
**Last updated:** [July 25, 2023, 2:47pm UTC](https://discuss.elastic.co/t/alert-when-winlogbeat-host-stop-sending-events/339141 "2023-07-25T14:47:04Z")

</div>

Hello and thanks in advance. I have a group of 100+ hosts with winlogbeat installed and sending events to elasticsearch cluster. Is there any options to generate an alert (on security or any other page) when one or gro…

---

## [Expired ca.crt/nodes certificates - how to renew such certificates?](https://discuss.elastic.co/t/expired-ca-crt-nodes-certificates-how-to-renew-such-certificates/339114)

<div class="topic-metadata">

**Author:** [@d.silwon](https://discuss.elastic.co/u/d.silwon)\
**Replies:** 4\
**Last updated:** [July 25, 2023, 2:39pm UTC](https://discuss.elastic.co/t/expired-ca-crt-nodes-certificates-how-to-renew-such-certificates/339114 "2023-07-25T14:39:40Z")

</div>

Dears, To secure our ELK cluster we are using self-signed certificates generated by elasticsearch-certutil tool. Our ca.crt and certificates of nodes expired. I would like to mention that many external filebeats connec…

---

## [Kibana alert with index connector: indexing {{context}} as JSON](https://discuss.elastic.co/t/kibana-alert-with-index-connector-indexing-context-as-json/339205)

<div class="topic-metadata">

**Author:** [@dmcarmen](https://discuss.elastic.co/u/dmcarmen)\
**Replies:** 0\
**Last updated:** [July 25, 2023, 2:04pm UTC](https://discuss.elastic.co/t/kibana-alert-with-index-connector-indexing-context-as-json/339205 "2023-07-25T14:04:48Z")

</div>

Hi, I am trying to setup an ES query alert using an index connector. I would like to have a similar behavior to the predefined alert index, but my ELK version is 7.12 and that index was not available for that version. I…

---

## [Is it possible modify query results before aggregations](https://discuss.elastic.co/t/is-it-possible-modify-query-results-before-aggregations/339136)

<div class="topic-metadata">

**Author:** [@Dalin](https://discuss.elastic.co/u/Dalin)\
**Replies:** 2\
**Last updated:** [July 25, 2023, 1:57pm UTC](https://discuss.elastic.co/t/is-it-possible-modify-query-results-before-aggregations/339136 "2023-07-25T13:57:46Z")

</div>

I need to modify Elasticsearch query results based on user permissions determined by an external authorizer, before the results are used for aggregations. Anyone know if it's possible to intercept the query results, modi…

---

## [Elasticsearch index pattern in Tableau](https://discuss.elastic.co/t/elasticsearch-index-pattern-in-tableau/339183)

<div class="topic-metadata">

**Author:** [@subash](https://discuss.elastic.co/u/subash)\
**Replies:** 2\
**Last updated:** [July 25, 2023, 1:52pm UTC](https://discuss.elastic.co/t/elasticsearch-index-pattern-in-tableau/339183 "2023-07-25T13:52:25Z")

</div>

Hello, I am trying to create a visualization in Tableau with Elasticsearch as the data source. I am able to connect Tableau and Elasticsearch successfully . But the problem is I can't select the index pattern in Tablea…

---

## [App Search: Analytics stopped working; no values shown](https://discuss.elastic.co/t/app-search-analytics-stopped-working-no-values-shown/339080)

<div class="topic-metadata">

**Author:** [@frederik1](https://discuss.elastic.co/u/frederik1)\
**Replies:** 2\
**Last updated:** [July 25, 2023, 12:59pm UTC](https://discuss.elastic.co/t/app-search-analytics-stopped-working-no-values-shown/339080 "2023-07-25T12:59:22Z")

</div>

Dear Community, I have installed Elastic Enterprise Search version 8.8. Here I used App Search and that with 30 engines and 5 meta engines. Everything was running fine, even the analytics were kept. Both queries and cli…

---

## [I cant search nested](https://discuss.elastic.co/t/i-cant-search-nested/339187)

<div class="topic-metadata">

**Author:** [@Murilo\_Livorato](https://discuss.elastic.co/u/Murilo_Livorato)\
**Replies:** 3\
**Last updated:** [July 25, 2023, 12:52pm UTC](https://discuss.elastic.co/t/i-cant-search-nested/339187 "2023-07-25T12:52:16Z")

</div>

hello , I am trying to search nested . I dont know what I am doing wrong . MY MAPPING { "user-data-info": { "mappings": { "dynamic": "false", "properties": { "company": { "type": "…

---

## [Native Language Translation (not analyzers)](https://discuss.elastic.co/t/native-language-translation-not-analyzers/336906)

<div class="topic-metadata">

**Author:** [@Yossi11](https://discuss.elastic.co/u/Yossi11)\
**Replies:** 1\
**Last updated:** [July 25, 2023, 12:46pm UTC](https://discuss.elastic.co/t/native-language-translation-not-analyzers/336906 "2023-07-25T12:46:59Z")

</div>

Hello, My name is Yossi. I'm pretty new to elastic. Just stated using it a few months. I work a lot of different languages - English, German, Arabic (different dialects), French, Hebrew, Spanish and more. I'm using Dav…

---

## [There was problem checking fleet permission](https://discuss.elastic.co/t/there-was-problem-checking-fleet-permission/339192)

<div class="topic-metadata">

**Author:** [@Nirmal](https://discuss.elastic.co/u/Nirmal)\
**Replies:** 0\
**Last updated:** [July 25, 2023, 12:18pm UTC](https://discuss.elastic.co/t/there-was-problem-checking-fleet-permission/339192 "2023-07-25T12:18:28Z")

</div>

I am trying to setup fleet server, but I am facing this issue. Please anybody knows what I am missing here.

---

## [Nested sorting differs between ES7 and ES8?](https://discuss.elastic.co/t/nested-sorting-differs-between-es7-and-es8/337904)

<div class="topic-metadata">

**Author:** [@MarynaCherniavska](https://discuss.elastic.co/u/MarynaCherniavska)\
**Replies:** 1\
**Last updated:** [July 25, 2023, 12:17pm UTC](https://discuss.elastic.co/t/nested-sorting-differs-between-es7-and-es8/337904 "2023-07-25T12:17:59Z")

</div>

Dear team, we're moving from 7.17 to 8.7 (I know, big jump) and as part of the move, we have been running the e2e tests of the application on the new cluster, before actually switching the application to it. Some tests, …

---

## [Snapshot policy will continue to backup fail when the backup jumps out of shard error](https://discuss.elastic.co/t/snapshot-policy-will-continue-to-backup-fail-when-the-backup-jumps-out-of-shard-error/337738)

<div class="topic-metadata">

**Author:** [@Lily1](https://discuss.elastic.co/u/Lily1)\
**Replies:** 6\
**Last updated:** [July 25, 2023, 12:16pm UTC](https://discuss.elastic.co/t/snapshot-policy-will-continue-to-backup-fail-when-the-backup-jumps-out-of-shard-error/337738 "2023-07-25T12:16:26Z")

</div>

Version: Elasticsearch 7.16.2 S3 Storage Classes: new file saving S3 Standard, after month turn to S3 Glacier Regularly back up the index of the same Aliases to s3 every day. Recently, the following error suddenly po…

---

## [Ingest pipeline with conditions runs tests correct but no documents are processed](https://discuss.elastic.co/t/ingest-pipeline-with-conditions-runs-tests-correct-but-no-documents-are-processed/339150)

<div class="topic-metadata">

**Author:** [@fgjensen](https://discuss.elastic.co/u/fgjensen)\
**Replies:** 4\
**Last updated:** [July 25, 2023, 11:55am UTC](https://discuss.elastic.co/t/ingest-pipeline-with-conditions-runs-tests-correct-but-no-documents-are-processed/339150 "2023-07-25T11:55:45Z")

</div>

Hi; Elasticsearch version: 8.6.2 Logstash version: 8.6.2 I have created and tested at simple ingest pipeline, which adds an event.ingested field to Filebeat documents, which do not already have this field set b…

---

## [Fleet server agent output not supported](https://discuss.elastic.co/t/fleet-server-agent-output-not-supported/339174)

<div class="topic-metadata">

**Author:** [@quic22](https://discuss.elastic.co/u/quic22)\
**Replies:** 1\
**Last updated:** [July 25, 2023, 11:54am UTC](https://discuss.elastic.co/t/fleet-server-agent-output-not-supported/339174 "2023-07-25T11:54:04Z")

</div>

Hello, I just installed elastic stack (with fleet server on the same host) with logstash as output in fleet settings and that was working until I rebooted. Everything seems to work only is the server not listening on por…

---

## [Log4j framework can no longer reconnect because the security manager on logstash restart](https://discuss.elastic.co/t/log4j-framework-can-no-longer-reconnect-because-the-security-manager-on-logstash-restart/339115)

<div class="topic-metadata">

**Author:** [@ansk98](https://discuss.elastic.co/u/ansk98)\
**Replies:** 1\
**Last updated:** [July 25, 2023, 11:54am UTC](https://discuss.elastic.co/t/log4j-framework-can-no-longer-reconnect-because-the-security-manager-on-logstash-restart/339115 "2023-07-25T11:54:01Z")

</div>

Hi all, For the logging of the Elasticsearch processes, the log4j2 was configured to log server, slowlog indexing, and slowlog search information to logstash by adding a socket appender that sends relevant logs to the r…

---

## [Option to search matching phrase with post fix and prefix while maintaining the order in Elasticsearch 7.x](https://discuss.elastic.co/t/option-to-search-matching-phrase-with-post-fix-and-prefix-while-maintaining-the-order-in-elasticsearch-7-x/339161)

<div class="topic-metadata">

**Author:** [@Vithu](https://discuss.elastic.co/u/Vithu)\
**Replies:** 3\
**Last updated:** [July 25, 2023, 11:35am UTC](https://discuss.elastic.co/t/option-to-search-matching-phrase-with-post-fix-and-prefix-while-maintaining-the-order-in-elasticsearch-7-x/339161 "2023-07-25T11:35:56Z")

</div>

I have a requirement to modify Elasticsearch query from 1.x to 7.x. The 1.x query is given below: { "query": { "filtered": { "filter": { "and": { "filters": \[ { "t…

---

## [How to get details of fleet server](https://discuss.elastic.co/t/how-to-get-details-of-fleet-server/338868)

<div class="topic-metadata">

**Author:** [@Nishant\_Chauhan](https://discuss.elastic.co/u/Nishant_Chauhan)\
**Replies:** 3\
**Last updated:** [July 25, 2023, 10:00am UTC](https://discuss.elastic.co/t/how-to-get-details-of-fleet-server/338868 "2023-07-25T10:00:49Z")

</div>

How can I list number/name of hosts connected to any specific Fleet server.

---

## [Integrations not updating and fleet server page not loading](https://discuss.elastic.co/t/integrations-not-updating-and-fleet-server-page-not-loading/338517)

<div class="topic-metadata">

**Author:** [@theacodes](https://discuss.elastic.co/u/theacodes)\
**Replies:** 4\
**Last updated:** [July 25, 2023, 9:43am UTC](https://discuss.elastic.co/t/integrations-not-updating-and-fleet-server-page-not-loading/338517 "2023-07-25T09:43:16Z")

</div>

Integrations are not updating and the fleet server page is not loading. Using ELK 8.8.1

---

## [How to include thread name in span?](https://discuss.elastic.co/t/how-to-include-thread-name-in-span/338347)

<div class="topic-metadata">

**Author:** [@johngregg](https://discuss.elastic.co/u/johngregg)\
**Replies:** 8\
**Last updated:** [July 25, 2023, 9:36am UTC](https://discuss.elastic.co/t/how-to-include-thread-name-in-span/338347 "2023-07-25T09:36:04Z")

</div>

I'm using the java agent version 1.35.0. Is there a way to include the thread name in the span? Knowing the thread name helps understand a lot about how the app is doing multi-threading. thanks

---

## [Elastic Search Unclear Mapper Parsing Exception](https://discuss.elastic.co/t/elastic-search-unclear-mapper-parsing-exception/339108)

<div class="topic-metadata">

**Author:** [@optimaX](https://discuss.elastic.co/u/optimaX)\
**Replies:** 2\
**Last updated:** [July 25, 2023, 9:25am UTC](https://discuss.elastic.co/t/elastic-search-unclear-mapper-parsing-exception/339108 "2023-07-25T09:25:30Z")

</div>

Incident: I'm currently working on a log pipeline which forwards the logs from an API - of our Anti-Virus solution - to Graylog and therefore Elasticsearch behind that. However, I encountered a very strange mapper-parsi…

---

## [NOOB, Elastic Stack (Search/Logstash) Netflow Cisco SD-WAN](https://discuss.elastic.co/t/noob-elastic-stack-search-logstash-netflow-cisco-sd-wan/338687)

<div class="topic-metadata">

**Author:** [@mhollingsworth1](https://discuss.elastic.co/u/mhollingsworth1)\
**Replies:** 0\
**Last updated:** [July 18, 2023, 2:01pm UTC](https://discuss.elastic.co/t/noob-elastic-stack-search-logstash-netflow-cisco-sd-wan/338687 "2023-07-18T14:01:36Z")

</div>

I've been using an ELK stack for Netflow collection for roughly 1.5yr with my Cisco environment. Recently I've migrated onto SD-WAN and am sending my netflow data to the collector but for whatever reason all I'm seeing i…

---

## [Rebuild builtin indices](https://discuss.elastic.co/t/rebuild-builtin-indices/337098)

<div class="topic-metadata">

**Author:** [@rokka](https://discuss.elastic.co/u/rokka)\
**Replies:** 1\
**Last updated:** [July 25, 2023, 9:19am UTC](https://discuss.elastic.co/t/rebuild-builtin-indices/337098 "2023-07-25T09:19:12Z")

</div>

Hi, for an unkown reason some builtin indices like ".geoip\_databases" or ".kibana\_7.16.2\_001" are corrupt in my ES instance. Is there a way to rebuilt them? Greetings Andre

[Previous page](https://discuss.elastic.co/latest.md?page=594)

[Next page](https://discuss.elastic.co/latest.md?page=596)
