# Latest

**URL:** https://discuss.elastic.co/latest.md?page=602

[Latest](https://discuss.elastic.co/latest.md) · [Categories](https://discuss.elastic.co/categories.md) · [Tags](https://discuss.elastic.co/tags.md)

**Page:** 603

---

## [Search Bar for Facets](https://discuss.elastic.co/t/search-bar-for-facets/337974)

<div class="topic-metadata">

**Author:** [@aisyaharifin](https://discuss.elastic.co/u/aisyaharifin)\
**Replies:** 1\
**Last updated:** [July 19, 2023, 8:46am UTC](https://discuss.elastic.co/t/search-bar-for-facets/337974 "2023-07-19T08:46:22Z")

</div>

Hello, I would like to ask, can we custom the Facets components to have a search bar so user can search for specific value filters they want if the facets list is too long? For example on top of the 'STATES' we have…

---

## [Discect rule with a "+" sign in the message, can't escape it](https://discuss.elastic.co/t/discect-rule-with-a-sign-in-the-message-cant-escape-it/338661)

<div class="topic-metadata">

**Author:** [@UPPERCASE](https://discuss.elastic.co/u/UPPERCASE)\
**Replies:** 2\
**Last updated:** [July 19, 2023, 8:36am UTC](https://discuss.elastic.co/t/discect-rule-with-a-sign-in-the-message-cant-escape-it/338661 "2023-07-19T08:36:05Z")

</div>

I have the following disect rule: %{timestamp} queries: info: client @%{dns\_client} %{source\_ip}#%{source\_port} (%{query}): query: %{query\_2} IN %{class} + (%{dns\_server}), which is from a BIND DNS server (querylog). Wh…

---

## [observing error in elasticsearch logs as :   ClusterBlockException: index \[.ds-.logs-deprecation.elasticsearch-default-2022.10.27-000023\] blocked by: \[TOO\_MANY\_REQUESTS/12/disk usage exceeded flood-stage watermark, index has read-only-allow-delete block\];](https://discuss.elastic.co/t/observing-error-in-elasticsearch-logs-as-clusterblockexception-index-ds-logs-deprecation-elasticsearch-default-2022-10-27-000023-blocked-by-too-many-requests-12-disk-usage-exceeded-flood-stage-watermark-index-has-read-only-allow-delete-block/338688)

<div class="topic-metadata">

**Author:** [@2328943\_dc](https://discuss.elastic.co/u/2328943_dc)\
**Replies:** 1\
**Last updated:** [July 19, 2023, 8:14am UTC](https://discuss.elastic.co/t/observing-error-in-elasticsearch-logs-as-clusterblockexception-index-ds-logs-deprecation-elasticsearch-default-2022-10-27-000023-blocked-by-too-many-requests-12-disk-usage-exceeded-flood-stage-watermark-index-has-read-only-allow-delete-block/338688 "2023-07-19T08:14:44Z")

</div>

observing error in elasticsearch logs as : ClusterBlockException: index \[.ds-.logs-deprecation.elasticsearch-default-2022.10.27-000023\] blocked by: \[TOO\_MANY\_REQUESTS/12/disk usage exceeded flood-stage watermark, index…

---

## [The connection between Logstash and Elasticsearch is not working](https://discuss.elastic.co/t/the-connection-between-logstash-and-elasticsearch-is-not-working/338750)

<div class="topic-metadata">

**Author:** [@chldnjs8899](https://discuss.elastic.co/u/chldnjs8899)\
**Replies:** 1\
**Last updated:** [July 19, 2023, 8:14am UTC](https://discuss.elastic.co/t/the-connection-between-logstash-and-elasticsearch-is-not-working/338750 "2023-07-19T08:14:42Z")

</div>

The following content has been translated using ChatGPT. Thank you for your understanding. Hello, I'm currently learning Elasticsearch. I'm using Elasticsearch version 8.8.2. I have written the following pipeline in ord…

---

## [Visualize user journey on a website](https://discuss.elastic.co/t/visualize-user-journey-on-a-website/338060)

<div class="topic-metadata">

**Author:** [@Neelam\_Zanvar](https://discuss.elastic.co/u/Neelam_Zanvar)\
**Replies:** 4\
**Last updated:** [July 19, 2023, 7:52am UTC](https://discuss.elastic.co/t/visualize-user-journey-on-a-website/338060 "2023-07-19T07:52:59Z")

</div>

Hi , I want to visualize the various url visited by a spcific user along with the timestamp in a graph. i have the following data in es index, date: 11/Jul/2023:11:15:13.705 +0530 remote ip: 49.37.163.204 url: /3…

---

## [How to create security rule for Windows Authentication - Success from Public IPs Alert with KQL language?](https://discuss.elastic.co/t/how-to-create-security-rule-for-windows-authentication-success-from-public-ips-alert-with-kql-language/338588)

<div class="topic-metadata">

**Author:** [@aungsoemin](https://discuss.elastic.co/u/aungsoemin)\
**Replies:** 2\
**Last updated:** [July 19, 2023, 7:27am UTC](https://discuss.elastic.co/t/how-to-create-security-rule-for-windows-authentication-success-from-public-ips-alert-with-kql-language/338588 "2023-07-19T07:27:01Z")

</div>

Hi, I'm trying to create the custom use case "Windows Authentication - Success from Public IPs Alert" with below informations. Event code = 4624 Action = Success IP Range = Any Public IP Here is my KQL query to cre…

---

## [Data Stored for Enterprise Search](https://discuss.elastic.co/t/data-stored-for-enterprise-search/337972)

<div class="topic-metadata">

**Author:** [@aisyaharifin](https://discuss.elastic.co/u/aisyaharifin)\
**Replies:** 1\
**Last updated:** [July 19, 2023, 7:17am UTC](https://discuss.elastic.co/t/data-stored-for-enterprise-search/337972 "2023-07-19T07:17:28Z")

</div>

Hello, I would like to ask and understand, where is exactly the data in the search engine of Enterprise Search for App Search have been stored? I found this discussion said it stored in Elasticsearch. If it's been st…

---

## [ES node handshake failed](https://discuss.elastic.co/t/es-node-handshake-failed/338743)

<div class="topic-metadata">

**Author:** [@emmning](https://discuss.elastic.co/u/emmning)\
**Replies:** 0\
**Last updated:** [July 19, 2023, 6:17am UTC](https://discuss.elastic.co/t/es-node-handshake-failed/338743 "2023-07-19T06:17:43Z")

</div>

Hi team, I am trying to start cluster on my MacBook. I got below error \[2023-07-19T14:16:03,014\]\[WARN \]\[o.e.d.HandshakingTransportAddressConnector\] \[node-2\] \[connectToRemoteMasterNode\[127.0.0.1:9301\]\] completed handsha…

---

## [How to connect Stand Alone Elastic Agent to SentinelOne and Logstash?](https://discuss.elastic.co/t/how-to-connect-stand-alone-elastic-agent-to-sentinelone-and-logstash/338726)

<div class="topic-metadata">

**Author:** [@toman](https://discuss.elastic.co/u/toman)\
**Replies:** 1\
**Last updated:** [July 19, 2023, 4:29am UTC](https://discuss.elastic.co/t/how-to-connect-stand-alone-elastic-agent-to-sentinelone-and-logstash/338726 "2023-07-19T04:29:30Z")

</div>

I am trying to make a connection from our SentinelOne environment to our existing Logstash server where we process data. We do not use Fleet or Elasticsearch. It seems that we could use Elastic Agent for this connection…

---

## [Index rollover ealier than described in ILM index lifecycle management](https://discuss.elastic.co/t/index-rollover-ealier-than-described-in-ilm-index-lifecycle-management/337996)

<div class="topic-metadata">

**Author:** [@VietDuc](https://discuss.elastic.co/u/VietDuc)\
**Replies:** 1\
**Last updated:** [July 19, 2023, 3:29am UTC](https://discuss.elastic.co/t/index-rollover-ealier-than-described-in-ilm-index-lifecycle-management/337996 "2023-07-19T03:29:22Z")

</div>

Hi everyone, I have setup a TSDS with following ILM in ES 8.8.2 GET .ds-micrometer-metrics-2023.07.08-000036/\_ilm/explain ".ds-micrometer-metrics-2023.07.08-000036": { "index": ".ds-micrometer-metrics-2023.07.0…

---

## [Elastic APM - Plotting traceID start and end timestamps](https://discuss.elastic.co/t/elastic-apm-plotting-traceid-start-and-end-timestamps/338703)

<div class="topic-metadata">

**Author:** [@sangramreddy](https://discuss.elastic.co/u/sangramreddy)\
**Replies:** 10\
**Last updated:** [July 19, 2023, 2:55am UTC](https://discuss.elastic.co/t/elastic-apm-plotting-traceid-start-and-end-timestamps/338703 "2023-07-19T02:55:06Z")

</div>

We have bunch of applications through which a trace ID passes. We would like to calculate total time taken by the trace and plot them. Elastic APM UI doesn't show this information out of the box for asynchronous applica…

---

## [Add some default data to ES when docker first run](https://discuss.elastic.co/t/add-some-default-data-to-es-when-docker-first-run/338701)

<div class="topic-metadata">

**Author:** [@TranTruongMMCII](https://discuss.elastic.co/u/TranTruongMMCII)\
**Replies:** 2\
**Last updated:** [July 19, 2023, 2:30am UTC](https://discuss.elastic.co/t/add-some-default-data-to-es-when-docker-first-run/338701 "2023-07-19T02:30:28Z")

</div>

Dear all, I am new to ES. Now I want to create a docker to run ES, but I faced some errors. Firstly, I can create a docker to run ES and can interact with it. But I want to add some default data to index when docker fir…

---

## [Set top\_hits size dynamically for each bucket based on its doc\_count with a script](https://discuss.elastic.co/t/set-top-hits-size-dynamically-for-each-bucket-based-on-its-doc-count-with-a-script/338728)

<div class="topic-metadata">

**Author:** [@DMinovski](https://discuss.elastic.co/u/DMinovski)\
**Replies:** 0\
**Last updated:** [July 18, 2023, 11:31pm UTC](https://discuss.elastic.co/t/set-top-hits-size-dynamically-for-each-bucket-based-on-its-doc-count-with-a-script/338728 "2023-07-18T23:31:51Z")

</div>

I use a query to find the duplicates in an index based on a field. Some documents have the same value in this field and they are duplicates. { "size": 0, "aggs": { "duplicate\_terms": { "terms…

---

## [Data streams stuck in frozen searchable\_snapshot phase (wait state inconsistent with indices status)](https://discuss.elastic.co/t/data-streams-stuck-in-frozen-searchable-snapshot-phase-wait-state-inconsistent-with-indices-status/338727)

<div class="topic-metadata">

**Author:** [@Adrien\_WATTEZ](https://discuss.elastic.co/u/Adrien_WATTEZ)\
**Replies:** 0\
**Last updated:** [July 18, 2023, 10:51pm UTC](https://discuss.elastic.co/t/data-streams-stuck-in-frozen-searchable-snapshot-phase-wait-state-inconsistent-with-indices-status/338727 "2023-07-18T22:51:40Z")

</div>

This request follows a previous ticket that was never really answered. ES 8.8.2 - free trial in local - paid enterprise licence on other environment Same problem, I have created a data stream with ILM with phases rang…

---

## [Elasticsearch delete docs during the indexations](https://discuss.elastic.co/t/elasticsearch-delete-docs-during-the-indexations/338674)

<div class="topic-metadata">

**Author:** [@atombrownbear](https://discuss.elastic.co/u/atombrownbear)\
**Replies:** 1\
**Last updated:** [July 18, 2023, 9:53pm UTC](https://discuss.elastic.co/t/elasticsearch-delete-docs-during-the-indexations/338674 "2023-07-18T21:53:06Z")

</div>

Hi all! When im do indexation, my backend app sends 1234 pages (for example). if I call /stats? by curl I will see that 1234 pages have been indexed and 234 pages have been deleted, although they should not be deleted. w…

---

## [Make query case sensitive](https://discuss.elastic.co/t/make-query-case-sensitive/338333)

<div class="topic-metadata">

**Author:** [@ankur.kumar](https://discuss.elastic.co/u/ankur.kumar)\
**Replies:** 1\
**Last updated:** [July 18, 2023, 9:03pm UTC](https://discuss.elastic.co/t/make-query-case-sensitive/338333 "2023-07-18T21:03:02Z")

</div>

I'm using enterprise\_search and sorry I'm new to it. I want make query case sensitive. Like if name is Elastic then I don't want to get this doc with queryString elastic or ela If queryString is Ela, E, stic then it …

---

## [Custom analyser for numeric string](https://discuss.elastic.co/t/custom-analyser-for-numeric-string/338529)

<div class="topic-metadata">

**Author:** [@hmkhitaryan](https://discuss.elastic.co/u/hmkhitaryan)\
**Replies:** 3\
**Last updated:** [July 18, 2023, 8:32pm UTC](https://discuss.elastic.co/t/custom-analyser-for-numeric-string/338529 "2023-07-18T20:32:19Z")

</div>

Hi everyone. I have this kind of issue: I have a numeric string field, seperated with dots, like "1.1.2", "11.2.1", and the like. I have a requirement to do sorting by this field, and when I try to sort by that field, i…

---

## [Which configuration schemes are avaliable in 8.8 version of elastic clusterization?](https://discuss.elastic.co/t/which-configuration-schemes-are-avaliable-in-8-8-version-of-elastic-clusterization/338137)

<div class="topic-metadata">

**Author:** [@hlcxpl](https://discuss.elastic.co/u/hlcxpl)\
**Replies:** 20\
**Last updated:** [July 18, 2023, 7:57pm UTC](https://discuss.elastic.co/t/which-configuration-schemes-are-avaliable-in-8-8-version-of-elastic-clusterization/338137 "2023-07-18T19:57:03Z")

</div>

which configuration schemes are avaliable in 8.8 version of slatic clusterization?

---

## [Setup filebeat to send different logs to different indexes (to elasticsearch)](https://discuss.elastic.co/t/setup-filebeat-to-send-different-logs-to-different-indexes-to-elasticsearch/338709)

<div class="topic-metadata">

**Author:** [@perfecto25](https://discuss.elastic.co/u/perfecto25)\
**Replies:** 0\
**Last updated:** [July 18, 2023, 6:36pm UTC](https://discuss.elastic.co/t/setup-filebeat-to-send-different-logs-to-different-indexes-to-elasticsearch/338709 "2023-07-18T18:36:10Z")

</div>

Hello, I setup a filebeat 8.8.2 on redhat host and configured my filebeat.yml like this, Im sending all my log data to ES directly, filebeat.inputs: - type: filestream id: my\_id enabled: true paths: - /home/cu…

---

## [TSVB markdown with conditional values](https://discuss.elastic.co/t/tsvb-markdown-with-conditional-values/338582)

<div class="topic-metadata">

**Author:** [@hkhalil](https://discuss.elastic.co/u/hkhalil)\
**Replies:** 2\
**Last updated:** [July 18, 2023, 4:25pm UTC](https://discuss.elastic.co/t/tsvb-markdown-with-conditional-values/338582 "2023-07-18T16:25:35Z")

</div>

Hi, We're looking to create in our dashboard a markdown using the TSVB control type. Our dashboard has controls for filtering purposes. We would like the markdown to display different predetermined numerical values bas…

---

## [Filter results in table](https://discuss.elastic.co/t/filter-results-in-table/338697)

<div class="topic-metadata">

**Author:** [@vils](https://discuss.elastic.co/u/vils)\
**Replies:** 1\
**Last updated:** [July 18, 2023, 4:39pm UTC](https://discuss.elastic.co/t/filter-results-in-table/338697 "2023-07-18T16:39:50Z")

</div>

Hi all, I'm currently working with a Lens table where my values are displayed as percentages. I'm interested in filtering these results so that only certain percentage ranges are displayed - for example, I might want to…

---

## [Does Platinum Anomaly Detection Rule Work At All?](https://discuss.elastic.co/t/does-platinum-anomaly-detection-rule-work-at-all/338439)

<div class="topic-metadata">

**Author:** [@McJava1967](https://discuss.elastic.co/u/McJava1967)\
**Replies:** 1\
**Last updated:** [July 18, 2023, 4:07pm UTC](https://discuss.elastic.co/t/does-platinum-anomaly-detection-rule-work-at-all/338439 "2023-07-18T16:07:54Z")

</div>

Hi all. Can anyone confirm that the Platinum Anomaly Detection Rule works? I know it says it's "beta". I've been beating my head against this wall for two days! I do have a different kind of Rule that works, and send…

---

## [Fast Vector Highlighting is not working stable on Synonym based fields](https://discuss.elastic.co/t/fast-vector-highlighting-is-not-working-stable-on-synonym-based-fields/338673)

<div class="topic-metadata">

**Author:** [@Pavithra2014](https://discuss.elastic.co/u/Pavithra2014)\
**Replies:** 3\
**Last updated:** [July 18, 2023, 4:05pm UTC](https://discuss.elastic.co/t/fast-vector-highlighting-is-not-working-stable-on-synonym-based-fields/338673 "2023-07-18T16:05:20Z")

</div>

Here , we are using Fast Vector highlight on a field where it has the copy field for synonym . for some records FVH highlights properly but for some it is not. Field mapping: title: { type: "text", term\_vector: "with\_p…

---

## [\*I am working with wireshark pcaps inside of SO kibana and hunt. Seems like the timestamps do not match?](https://discuss.elastic.co/t/i-am-working-with-wireshark-pcaps-inside-of-so-kibana-and-hunt-seems-like-the-timestamps-do-not-match/338612)

<div class="topic-metadata">

**Author:** [@iqworks](https://discuss.elastic.co/u/iqworks)\
**Replies:** 2\
**Last updated:** [July 18, 2023, 3:32pm UTC](https://discuss.elastic.co/t/i-am-working-with-wireshark-pcaps-inside-of-so-kibana-and-hunt-seems-like-the-timestamps-do-not-match/338612 "2023-07-18T15:32:27Z")

</div>

Hi, I am using windows 11, SO, winlogbeat and logstash output.logstash: The Logstash hosts hosts: \["192.168.1.226:5044"\] I have saved a wireshark session as a pcap. I moved the pcap from my windows 10 machine with win…

---

## [Substract value of one attribute from the previous day value in ELasticsearch for Kibana Visualization](https://discuss.elastic.co/t/substract-value-of-one-attribute-from-the-previous-day-value-in-elasticsearch-for-kibana-visualization/337184)

<div class="topic-metadata">

**Author:** [@gauravpks](https://discuss.elastic.co/u/gauravpks)\
**Replies:** 1\
**Last updated:** [July 18, 2023, 3:17pm UTC](https://discuss.elastic.co/t/substract-value-of-one-attribute-from-the-previous-day-value-in-elasticsearch-for-kibana-visualization/337184 "2023-07-18T15:17:25Z")

</div>

My elastic index has 3 attributes: - accountNumber, timestamp and score. I want to calculate the difference in score from today to the previous day (or the last value) for each account and build visualizations for the di…

---

## [Facing permission issues on running up \`elastic-package stack up\`](https://discuss.elastic.co/t/facing-permission-issues-on-running-up-elastic-package-stack-up/338566)

<div class="topic-metadata">

**Author:** [@hari\_ibm](https://discuss.elastic.co/u/hari_ibm)\
**Replies:** 2\
**Last updated:** [July 18, 2023, 3:08pm UTC](https://discuss.elastic.co/t/facing-permission-issues-on-running-up-elastic-package-stack-up/338566 "2023-07-18T15:08:16Z")

</div>

Getting the below exception on running elastic-package stack up ERROR: Elasticsearch exited unexpectedly java.nio.file.AccessDeniedException: /usr/share/elasticsearch/config/certs at java.base/sun.nio.fs.UnixException.…

---

## [ECS version is different](https://discuss.elastic.co/t/ecs-version-is-different/338630)

<div class="topic-metadata">

**Author:** [@Nishant\_Chauhan](https://discuss.elastic.co/u/Nishant_Chauhan)\
**Replies:** 1\
**Last updated:** [July 18, 2023, 3:06pm UTC](https://discuss.elastic.co/t/ecs-version-is-different/338630 "2023-07-18T15:06:37Z")

</div>

We are getting below error in our Kibana logs 8.7.1 and Elasticsearch version is also same 8.7.1 why ECS version is 8.6.0 ? is it ok , if wrong how we can correct it? {"service":{"node":{"roles":\["background\_tasks","u…

---

## [Configuration scheme issue](https://discuss.elastic.co/t/configuration-scheme-issue/338110)

<div class="topic-metadata">

**Author:** [@hlcxpl](https://discuss.elastic.co/u/hlcxpl)\
**Replies:** 0\
**Last updated:** [July 11, 2023, 1:52pm UTC](https://discuss.elastic.co/t/configuration-scheme-issue/338110 "2023-07-11T13:52:08Z")

</div>

i have to cofigure a clúster with 5Teras data ingest per day in 4 data nodes the thing is, if I installed elastisearch 8.8 which configuration is the best for these schema, single node configuration with the voting s…

---

## [Duplicate Data Views being Created when Copying Dashboard to another Space](https://discuss.elastic.co/t/duplicate-data-views-being-created-when-copying-dashboard-to-another-space/338136)

<div class="topic-metadata">

**Author:** [@m-sarmento](https://discuss.elastic.co/u/m-sarmento)\
**Replies:** 1\
**Last updated:** [July 18, 2023, 2:56pm UTC](https://discuss.elastic.co/t/duplicate-data-views-being-created-when-copying-dashboard-to-another-space/338136 "2023-07-18T14:56:09Z")

</div>

When copying a dashboard from one space to another it looks like a copy of the data view used in that dashboard is being created in the space it was copied into. What is the best way to go about copying dashboards to …

---

## [Kibana - Every user gets their own space](https://discuss.elastic.co/t/kibana-every-user-gets-their-own-space/338375)

<div class="topic-metadata">

**Author:** [@sc6698](https://discuss.elastic.co/u/sc6698)\
**Replies:** 1\
**Last updated:** [July 18, 2023, 2:51pm UTC](https://discuss.elastic.co/t/kibana-every-user-gets-their-own-space/338375 "2023-07-18T14:51:57Z")

</div>

Hi, How am I going to achieve this by allowing every logged in user to have their own space and saved objects? All users are allowed to see their own space but not others. I understand that it could be done by creating…

[Previous page](https://discuss.elastic.co/latest.md?page=601)

[Next page](https://discuss.elastic.co/latest.md?page=603)
