# Latest

**URL:** https://discuss.elastic.co/latest.md?page=605

[Latest](https://discuss.elastic.co/latest.md) · [Categories](https://discuss.elastic.co/categories.md) · [Tags](https://discuss.elastic.co/tags.md)

**Page:** 606

---

## [Prevent Functionbeat from deleting log groups](https://discuss.elastic.co/t/prevent-functionbeat-from-deleting-log-groups/338538)

<div class="topic-metadata">

**Author:** [@shlant](https://discuss.elastic.co/u/shlant)\
**Replies:** 0\
**Last updated:** [July 17, 2023, 10:49am UTC](https://discuss.elastic.co/t/prevent-functionbeat-from-deleting-log-groups/338538 "2023-07-17T10:49:26Z")

</div>

So I am wanting to stream logs from a number of existing cloudwatch log groups to my ELK stack. I seem to have the setup basically ready but I noticed during the debugging of the setup process that when I deleted the Clo…

---

## [How to not show closed alerts in the "Alerts"-Overview?](https://discuss.elastic.co/t/how-to-not-show-closed-alerts-in-the-alerts-overview/336909)

<div class="topic-metadata">

**Author:** [@m-flow](https://discuss.elastic.co/u/m-flow)\
**Replies:** 4\
**Last updated:** [July 17, 2023, 10:36am UTC](https://discuss.elastic.co/t/how-to-not-show-closed-alerts-in-the-alerts-overview/336909 "2023-07-17T10:36:29Z")

</div>

Hello everyone, is there a way to suppress "closed" alerts in Kibana's "Alerts" view, when the status of all alerts changed from open to closed? The general filter exists, but is ineffective when no alerts with the sta…

---

## [Alerts Dashboard Showing All Alerts when "Open" alerts are cleared](https://discuss.elastic.co/t/alerts-dashboard-showing-all-alerts-when-open-alerts-are-cleared/338176)

<div class="topic-metadata">

**Author:** [@oloughlinp](https://discuss.elastic.co/u/oloughlinp)\
**Replies:** 2\
**Last updated:** [July 17, 2023, 10:34am UTC](https://discuss.elastic.co/t/alerts-dashboard-showing-all-alerts-when-open-alerts-are-cleared/338176 "2023-07-17T10:34:16Z")

</div>

Hi All, We recently upgraded to Kibana 8.8.0 from 8.0. When using the Alerts dashboard under Kibana Security, we typically use the status filter to filter the dashboard to show only "open" alerts, so that our analysts k…

---

## [Elastic Security rule with Index action](https://discuss.elastic.co/t/elastic-security-rule-with-index-action/338508)

<div class="topic-metadata">

**Author:** [@alextd](https://discuss.elastic.co/u/alextd)\
**Replies:** 1\
**Last updated:** [July 17, 2023, 10:32am UTC](https://discuss.elastic.co/t/elastic-security-rule-with-index-action/338508 "2023-07-17T10:32:32Z")

</div>

Hello All, I'm new work with Elastic Security. I'm using the Elastic Security basic version and I want to create the detection rule with Index action. My situation is, I created a rule to detect any connect malicious I…

---

## [Autofocus lose while typing in SearchBox](https://discuss.elastic.co/t/autofocus-lose-while-typing-in-searchbox/338091)

<div class="topic-metadata">

**Author:** [@raj22](https://discuss.elastic.co/u/raj22)\
**Replies:** 4\
**Last updated:** [July 17, 2023, 10:06am UTC](https://discuss.elastic.co/t/autofocus-lose-while-typing-in-searchbox/338091 "2023-07-17T10:06:22Z")

</div>

Hello, I have component from \> @elastic/react-search-ui . For searchbox desing customization used inputView. But when I started typing suddenly autofocus is losing , so I need to enter cusor again into input element …

---

## [Unable to create Custom index for metricbeat](https://discuss.elastic.co/t/unable-to-create-custom-index-for-metricbeat/336887)

<div class="topic-metadata">

**Author:** [@lalchand\_rajak](https://discuss.elastic.co/u/lalchand_rajak)\
**Replies:** 5\
**Last updated:** [July 17, 2023, 9:59am UTC](https://discuss.elastic.co/t/unable-to-create-custom-index-for-metricbeat/336887 "2023-07-17T09:59:18Z")

</div>

Hello, I am trying to create the custom index for metricbeat with same template as metricbeat but not able to create the index using below configs. ###################### Metricbeat Configuration Example ##############…

---

## [Dotnet apm agent samples transactions locally but not when running on Azure App Service](https://discuss.elastic.co/t/dotnet-apm-agent-samples-transactions-locally-but-not-when-running-on-azure-app-service/335948)

<div class="topic-metadata">

**Author:** [@tpoiesz](https://discuss.elastic.co/u/tpoiesz)\
**Replies:** 1\
**Last updated:** [July 17, 2023, 9:56am UTC](https://discuss.elastic.co/t/dotnet-apm-agent-samples-transactions-locally-but-not-when-running-on-azure-app-service/335948 "2023-07-17T09:56:46Z")

</div>

Kibana version: 8.7.1 Elasticsearch version: 8.7.1 (Elastic Cloud) APM Server version: 8.7.1 APM Agent language and version: Elastic APM dotnet Agent, v1.22.0 .Net Runtime: 6.0.16 Original install method (e.g. downl…

---

## [Creating a traceparent header in the .net agent](https://discuss.elastic.co/t/creating-a-traceparent-header-in-the-net-agent/338402)

<div class="topic-metadata">

**Author:** [@csurfleet](https://discuss.elastic.co/u/csurfleet)\
**Replies:** 1\
**Last updated:** [July 17, 2023, 9:54am UTC](https://discuss.elastic.co/t/creating-a-traceparent-header-in-the-net-agent/338402 "2023-07-17T09:54:51Z")

</div>

I have some .net core APIs with APM enabled. They are taking requests and when making sub-calls to other APIs is attaching various trace data such as trace.id, transaction.id, transaction.span\_count etc, but traceparent …

---

## [Filebeat: Index not getting created at Elasticsearch](https://discuss.elastic.co/t/filebeat-index-not-getting-created-at-elasticsearch/338530)

<div class="topic-metadata">

**Author:** [@mohammad\_messiah](https://discuss.elastic.co/u/mohammad_messiah)\
**Replies:** 0\
**Last updated:** [July 17, 2023, 9:54am UTC](https://discuss.elastic.co/t/filebeat-index-not-getting-created-at-elasticsearch/338530 "2023-07-17T09:54:32Z")

</div>

Hi All, I have installed filebeat on few servers but somehow logs are not getting created tried reinstalling the filebeat didn't worked. For previously configured servers index are getting created on daily basis Please …

---

## [Import dashboard on elk 8.5.3](https://discuss.elastic.co/t/import-dashboard-on-elk-8-5-3/338236)

<div class="topic-metadata">

**Author:** [@kibana\_dev\_iko](https://discuss.elastic.co/u/kibana_dev_iko)\
**Replies:** 6\
**Last updated:** [July 17, 2023, 9:54am UTC](https://discuss.elastic.co/t/import-dashboard-on-elk-8-5-3/338236 "2023-07-17T09:54:30Z")

</div>

hi can anyone help me i create dashboard on elk version 8.6.2 and i want to import them in elk version 8.5.3 but i get this warning in kibana UI The file could not be processed due to error: "Unprocessable Entity: Doc…

---

## [Search by script with field range + docs without exesting fields](https://discuss.elastic.co/t/search-by-script-with-field-range-docs-without-exesting-fields/338403)

<div class="topic-metadata">

**Author:** [@orlenkoda5](https://discuss.elastic.co/u/orlenkoda5)\
**Replies:** 2\
**Last updated:** [July 17, 2023, 9:54am UTC](https://discuss.elastic.co/t/search-by-script-with-field-range-docs-without-exesting-fields/338403 "2023-07-17T09:54:24Z")

</div>

Hi, I try to make a query using template. Here are docs in my index: { "\_index" : "instruments", "\_type" : "\_doc", "\_id" : "721905", "\_score" : null, "\_source" : { "sess…

---

## [Is there a way to make the query string fuzzy by default?](https://discuss.elastic.co/t/is-there-a-way-to-make-the-query-string-fuzzy-by-default/338150)

<div class="topic-metadata">

**Author:** [@johnrodey](https://discuss.elastic.co/u/johnrodey)\
**Replies:** 1\
**Last updated:** [July 17, 2023, 9:50am UTC](https://discuss.elastic.co/t/is-there-a-way-to-make-the-query-string-fuzzy-by-default/338150 "2023-07-17T09:50:37Z")

</div>

I submit a query string via Java Rest API (QueryStringQueryBuilder). Right now I pass in whatever the user enters and use that as my query string however I would like to automatically apply fuzzy searching, when it make…

---

## [Adding multiple client to the ELK centralised logging system](https://discuss.elastic.co/t/adding-multiple-client-to-the-elk-centralised-logging-system/338526)

<div class="topic-metadata">

**Author:** [@Rahul\_Kumar\_Jaiswal](https://discuss.elastic.co/u/Rahul_Kumar_Jaiswal)\
**Replies:** 0\
**Last updated:** [July 17, 2023, 9:43am UTC](https://discuss.elastic.co/t/adding-multiple-client-to-the-elk-centralised-logging-system/338526 "2023-07-17T09:43:44Z")

</div>

How to add multiple clients to the ELK centralised logging system so that we can visualise their logs. I have already installed filebeat on the client nodes and configure the filebeat.yml file too. But, not able to see t…

---

## [Aggregation return data that do not match query](https://discuss.elastic.co/t/aggregation-return-data-that-do-not-match-query/338184)

<div class="topic-metadata">

**Author:** [@Edyta\_Szkiladz](https://discuss.elastic.co/u/Edyta_Szkiladz)\
**Replies:** 3\
**Last updated:** [July 17, 2023, 9:42am UTC](https://discuss.elastic.co/t/aggregation-return-data-that-do-not-match-query/338184 "2023-07-17T09:42:32Z")

</div>

I am trying to do aggregation on documents which contains categories field. Categories is an array of strings. Sample document: { "\_index": "test-v11", "\_type": "\_doc", "\_id": "954961", "\_version": 4, "\_score"…

---

## [Curl error when connecting with ElasticSearch running from docker - Windows](https://discuss.elastic.co/t/curl-error-when-connecting-with-elasticsearch-running-from-docker-windows/338525)

<div class="topic-metadata">

**Author:** [@Chaitanya\_Kanth](https://discuss.elastic.co/u/Chaitanya_Kanth)\
**Replies:** 0\
**Last updated:** [July 17, 2023, 9:41am UTC](https://discuss.elastic.co/t/curl-error-when-connecting-with-elasticsearch-running-from-docker-windows/338525 "2023-07-17T09:41:50Z")

</div>

I installed Elasticsearch docker image on windows 10 machine. Docker v4.21.1 and elasticsearch v8.2.2. I downloaded the cert file and running the curl command from same location where file is downloaded. Running below co…

---

## [Ruby into file](https://discuss.elastic.co/t/ruby-into-file/338102)

<div class="topic-metadata">

**Author:** [@hofrichterovak](https://discuss.elastic.co/u/hofrichterovak)\
**Replies:** 4\
**Last updated:** [July 17, 2023, 9:27am UTC](https://discuss.elastic.co/t/ruby-into-file/338102 "2023-07-17T09:27:23Z")

</div>

Hello, I read the documentation about the ruby script and I did not correctly understand the conversion of the ruby script into a file. If I have a converted ruby script into a file, do I have to rewrite the script int…

---

## [Add resiliency on .security-7 index](https://discuss.elastic.co/t/add-resiliency-on-security-7-index/338121)

<div class="topic-metadata">

**Author:** [@Josselin](https://discuss.elastic.co/u/Josselin)\
**Replies:** 2\
**Last updated:** [July 17, 2023, 9:23am UTC](https://discuss.elastic.co/t/add-resiliency-on-security-7-index/338121 "2023-07-17T09:23:39Z")

</div>

Hi, During multiple incident with cluster restart we lost the nodes where the index .security-7 was stored. It had a huge impact and we want to avoid as much as possible this situation to occur again. We have seen on t…

---

## [Limit of index pattern in Kibana for Elastic 8.8](https://discuss.elastic.co/t/limit-of-index-pattern-in-kibana-for-elastic-8-8/338516)

<div class="topic-metadata">

**Author:** [@elk1985](https://discuss.elastic.co/u/elk1985)\
**Replies:** 1\
**Last updated:** [July 17, 2023, 9:17am UTC](https://discuss.elastic.co/t/limit-of-index-pattern-in-kibana-for-elastic-8-8/338516 "2023-07-17T09:17:14Z")

</div>

Hello. Is still a hard deck limit of 100 index pattern per Kibana Data view in Elastic 8.8 ?

---

## [Connect oracle to elastic / kibana](https://discuss.elastic.co/t/connect-oracle-to-elastic-kibana/338436)

<div class="topic-metadata">

**Author:** [@Oytoch](https://discuss.elastic.co/u/Oytoch)\
**Replies:** 5\
**Last updated:** [July 17, 2023, 9:03am UTC](https://discuss.elastic.co/t/connect-oracle-to-elastic-kibana/338436 "2023-07-17T09:03:53Z")

</div>

Hi, I try to understand kibana / Elasticsearch to interface my oracle database in order to make dashboard with kibana ( BI) I work with an "on premise" version First question, is it possible to do that with kibana ? …

---

## [How to use Search templates in collate for phrase suggester](https://discuss.elastic.co/t/how-to-use-search-templates-in-collate-for-phrase-suggester/338515)

<div class="topic-metadata">

**Author:** [@To\_Noroozi](https://discuss.elastic.co/u/To_Noroozi)\
**Replies:** 0\
**Last updated:** [July 17, 2023, 8:33am UTC](https://discuss.elastic.co/t/how-to-use-search-templates-in-collate-for-phrase-suggester/338515 "2023-07-17T08:33:38Z")

</div>

Hi guys, according to the this link for collate: Suggesters | Elasticsearch Guide \[8.8\] | Elastic we can use our custom search template to use more complex query. i create sample search template and it is ok with name …

---

## [Persistent data support for logstash in ECK 2.8?](https://discuss.elastic.co/t/persistent-data-support-for-logstash-in-eck-2-8/338514)

<div class="topic-metadata">

**Author:** [@Claudio\_Tassini](https://discuss.elastic.co/u/Claudio_Tassini)\
**Replies:** 0\
**Last updated:** [July 17, 2023, 8:30am UTC](https://discuss.elastic.co/t/persistent-data-support-for-logstash-in-eck-2-8/338514 "2023-07-17T08:30:44Z")

</div>

Hi all! I'm trying to deploy an ECK cluster composed of elasticsearch, kibana, beats and a logstash instance. The only problem I'm facing is that the logstash CRD does not seem to support the definition of a volumeclaim…

---

## [ES fails to restart after reboot](https://discuss.elastic.co/t/es-fails-to-restart-after-reboot/338465)

<div class="topic-metadata">

**Author:** [@Russell\_Fulton](https://discuss.elastic.co/u/Russell_Fulton)\
**Replies:** 3\
**Last updated:** [July 17, 2023, 8:21am UTC](https://discuss.elastic.co/t/es-fails-to-restart-after-reboot/338465 "2023-07-17T08:21:20Z")

</div>

version 7.17.1 running on ubuntu -- started from systemctl When ever the server is rebooted ES fails to restart properly. Subsequent manual restart works just fine. \[2023-07-16T01:37:33,109\]\[INFO \]\[o.e.p.PluginsServic…

---

## [How does elastic react with x-pack crack](https://discuss.elastic.co/t/how-does-elastic-react-with-x-pack-crack/338503)

<div class="topic-metadata">

**Author:** [@Ernest\_Dong](https://discuss.elastic.co/u/Ernest_Dong)\
**Replies:** 1\
**Last updated:** [July 17, 2023, 8:13am UTC](https://discuss.elastic.co/t/how-does-elastic-react-with-x-pack-crack/338503 "2023-07-17T08:13:55Z")

</div>

I'm researching on ESTC stock and wondering how does elastic react with x-pack crack? If SMB modifies Elastic code and builds it on-premise, it seems ESTC will lost much revenue

---

## [Create Backup of all Kibana Objects](https://discuss.elastic.co/t/create-backup-of-all-kibana-objects/338226)

<div class="topic-metadata">

**Author:** [@tomx1](https://discuss.elastic.co/u/tomx1)\
**Replies:** 5\
**Last updated:** [July 17, 2023, 7:47am UTC](https://discuss.elastic.co/t/create-backup-of-all-kibana-objects/338226 "2023-07-17T07:47:38Z")

</div>

I would like to make sure that I'm able to restore all objects maintained by Kibana (Visualisations, Pipelines, Transformjobs, Dashboards, Templates, Fleet Settings and and and) from a snapshot. How can I achive that? I…

---

## [How to define time range Connection Graph](https://discuss.elastic.co/t/how-to-define-time-range-connection-graph/338485)

<div class="topic-metadata">

**Author:** [@leesever](https://discuss.elastic.co/u/leesever)\
**Replies:** 2\
**Last updated:** [July 17, 2023, 7:12am UTC](https://discuss.elastic.co/t/how-to-define-time-range-connection-graph/338485 "2023-07-17T07:12:05Z")

</div>

Hi, we using the graph for centrality analysis to identify the most central nodes in our platform (links between users). I wish to emphasize that I am not a programer or something as such and mostly use Kibana for fraud…

---

## [I have 2 aggregation in my query for Dau, Mau. how to combine them to find the ratio. have tried with bucket\_script, scripted metric. nothing works,](https://discuss.elastic.co/t/i-have-2-aggregation-in-my-query-for-dau-mau-how-to-combine-them-to-find-the-ratio-have-tried-with-bucket-script-scripted-metric-nothing-works/338373)

<div class="topic-metadata">

**Author:** [@Dev\_Profile](https://discuss.elastic.co/u/Dev_Profile)\
**Replies:** 2\
**Last updated:** [July 17, 2023, 6:58am UTC](https://discuss.elastic.co/t/i-have-2-aggregation-in-my-query-for-dau-mau-how-to-combine-them-to-find-the-ratio-have-tried-with-bucket-script-scripted-metric-nothing-works/338373 "2023-07-17T06:58:28Z")

</div>

Below is my query. is there any way to access multi-buckets value to manipulate n return the results. { "\_source": false, "aggs": { "nested\_dau": { "nested": { "path": "dau" }, "aggs": …

---

## [I want to render only kibana dashboard screen in python application,,how can I do that?](https://discuss.elastic.co/t/i-want-to-render-only-kibana-dashboard-screen-in-python-application-how-can-i-do-that/338173)

<div class="topic-metadata">

**Author:** [@Rushi\_Bagul](https://discuss.elastic.co/u/Rushi_Bagul)\
**Replies:** 2\
**Last updated:** [July 17, 2023, 6:46am UTC](https://discuss.elastic.co/t/i-want-to-render-only-kibana-dashboard-screen-in-python-application-how-can-i-do-that/338173 "2023-07-17T06:46:26Z")

</div>

I want to render only Kibana dashboard screen in python application for user purpose only they don't have access for modification. User want's to only read permission. I am new on elasticsearch so please help for that, …

---

## [Filebeat module ingest pipeline not working in logstash](https://discuss.elastic.co/t/filebeat-module-ingest-pipeline-not-working-in-logstash/338500)

<div class="topic-metadata">

**Author:** [@nbindal](https://discuss.elastic.co/u/nbindal)\
**Replies:** 4\
**Last updated:** [July 17, 2023, 5:55am UTC](https://discuss.elastic.co/t/filebeat-module-ingest-pipeline-not-working-in-logstash/338500 "2023-07-17T05:55:43Z")

</div>

Hi Team, I am using apache module and fileset in Beats+ELK stack where Filebeat is sending logs to logstash, logstash is using Ingest pipeline(we get module ingest pipeline - filebeat-8.7.1-apache-access-pipeline) , but…

---

## [How to sort my data in elasticsearch](https://discuss.elastic.co/t/how-to-sort-my-data-in-elasticsearch/338072)

<div class="topic-metadata">

**Author:** [@lz840408](https://discuss.elastic.co/u/lz840408)\
**Replies:** 8\
**Last updated:** [July 17, 2023, 5:13am UTC](https://discuss.elastic.co/t/how-to-sort-my-data-in-elasticsearch/338072 "2023-07-17T05:13:38Z")

</div>

how to sort by asc in logstash? i want new add field,it's self increment column,and insert dest index,how make it?

---

## [Getting logstasg error in rhel 8 and not running in logstash in rhel 8](https://discuss.elastic.co/t/getting-logstasg-error-in-rhel-8-and-not-running-in-logstash-in-rhel-8/338480)

<div class="topic-metadata">

**Author:** [@talbehat](https://discuss.elastic.co/u/talbehat)\
**Replies:** 3\
**Last updated:** [July 17, 2023, 4:28am UTC](https://discuss.elastic.co/t/getting-logstasg-error-in-rhel-8-and-not-running-in-logstash-in-rhel-8/338480 "2023-07-17T04:28:47Z")

</div>

Logstash is not running in rhel 8 and getting error while start logstash. logstash version :- 7.4.3 \[ERROR\] 2023-07-15 18:52:56.228 \[main\] Logstash - java.lang.IllegalStateException: Logstash stopped processing because…

[Previous page](https://discuss.elastic.co/latest.md?page=604)

[Next page](https://discuss.elastic.co/latest.md?page=606)
