# Latest

**URL:** https://discuss.elastic.co/latest.md?page=613

[Latest](https://discuss.elastic.co/latest.md) · [Categories](https://discuss.elastic.co/categories.md) · [Tags](https://discuss.elastic.co/tags.md)

**Page:** 614

---

## [Splitting Using Runtime Field / Scripting Field](https://discuss.elastic.co/t/splitting-using-runtime-field-scripting-field/336468)

<div class="topic-metadata">

**Author:** [@ksaimohan2k](https://discuss.elastic.co/u/ksaimohan2k)\
**Replies:** 2\
**Last updated:** [July 10, 2023, 10:25am UTC](https://discuss.elastic.co/t/splitting-using-runtime-field-scripting-field/336468 "2023-07-10T10:25:51Z")

</div>

In one of the alerts, in the field host.ip, I am seeing a bunch of IP addresses. So I want to create a scripted or runtime field where I want to split each IP address and place them in a new field like host.ip1 and host.…

---

## [Filebeat K8s deployment - Duplicated Filestream ID](https://discuss.elastic.co/t/filebeat-k8s-deployment-duplicated-filestream-id/338008)

<div class="topic-metadata">

**Author:** [@msanft](https://discuss.elastic.co/u/msanft)\
**Replies:** 0\
**Last updated:** [July 10, 2023, 9:40am UTC](https://discuss.elastic.co/t/filebeat-k8s-deployment-duplicated-filestream-id/338008 "2023-07-10T09:40:27Z")

</div>

Hey all, I'm deploying Filebeat in a Kubernetes cluster as a daemonset. I see the following error message in the Filebeat Pod logs: { "log.level":"error", "@timestamp":"2023-07-10T09:18:38.720Z", "log.logger":…

---

## [Mapping an object field in order to show in the Kibana discover](https://discuss.elastic.co/t/mapping-an-object-field-in-order-to-show-in-the-kibana-discover/336843)

<div class="topic-metadata">

**Author:** [@JasonREC](https://discuss.elastic.co/u/JasonREC)\
**Replies:** 2\
**Last updated:** [July 10, 2023, 9:37am UTC](https://discuss.elastic.co/t/mapping-an-object-field-in-order-to-show-in-the-kibana-discover/336843 "2023-07-10T09:37:11Z")

</div>

HI, I have a field called "unqiue\_db\_tag" in my document. somehow it does not show on the table but only on JSON I looked at other discussion says it could be due to this field is not yet dont the mapping since I add …

---

## [How to take the backup of 3months data of elasticsearch?](https://discuss.elastic.co/t/how-to-take-the-backup-of-3months-data-of-elasticsearch/337653)

<div class="topic-metadata">

**Author:** [@merson](https://discuss.elastic.co/u/merson)\
**Replies:** 10\
**Last updated:** [July 10, 2023, 9:28am UTC](https://discuss.elastic.co/t/how-to-take-the-backup-of-3months-data-of-elasticsearch/337653 "2023-07-10T09:28:41Z")

</div>

In elasticsearch, it is runned three months and the size of elk is 40gb then I want to backup the elasticsearch datas. so what to do the backup of elasticsearch for 3months without using snapshot and restore.

---

## [Virtuelles deshboard with kibana and metribeat vshpere](https://discuss.elastic.co/t/virtuelles-deshboard-with-kibana-and-metribeat-vshpere/337997)

<div class="topic-metadata">

**Author:** [@Ali\_Trache](https://discuss.elastic.co/u/Ali_Trache)\
**Replies:** 0\
**Last updated:** [July 10, 2023, 8:14am UTC](https://discuss.elastic.co/t/virtuelles-deshboard-with-kibana-and-metribeat-vshpere/337997 "2023-07-10T08:14:56Z")

</div>

Hello community. I made an ELK infrastructure to collect the vmware vsphere logs then I added the metricbeat vsphere module I want to create vurtuelized dechboards for the vsphere (cpu -memory-disuque -network..) do you…

---

## [Filebeat TCP input with SSL - Logs not received in correct format](https://discuss.elastic.co/t/filebeat-tcp-input-with-ssl-logs-not-received-in-correct-format/337994)

<div class="topic-metadata">

**Author:** [@wasimasif](https://discuss.elastic.co/u/wasimasif)\
**Replies:** 0\
**Last updated:** [July 10, 2023, 6:47am UTC](https://discuss.elastic.co/t/filebeat-tcp-input-with-ssl-logs-not-received-in-correct-format/337994 "2023-07-10T06:47:36Z")

</div>

I have created a TCP input but i have to secure communication using SSL. Following is my filebeat input configuration. This input starts and don't have any errors. Clients is also able to connect (verified via openssl ). …

---

## [Which Elasticsearch node should I send my query to?](https://discuss.elastic.co/t/which-elasticsearch-node-should-i-send-my-query-to/337937)

<div class="topic-metadata">

**Author:** [@ANUBHAV\_GUPTA](https://discuss.elastic.co/u/ANUBHAV_GUPTA)\
**Replies:** 3\
**Last updated:** [July 10, 2023, 6:45am UTC](https://discuss.elastic.co/t/which-elasticsearch-node-should-i-send-my-query-to/337937 "2023-07-10T06:45:51Z")

</div>

Let's say I have a cluster with total of 10 nodes where 4 are master eligible and rest are data nodes. So, how can I decide to which endpoint I should ping to have the best availability?

---

## [Getting Error "Exiting: /usr/share/filebeat/data/filebeat.lock: data path already locked by another beat. Please make sure that multiple beats are not sharing the same data path (path.data)"](https://discuss.elastic.co/t/getting-error-exiting-usr-share-filebeat-data-filebeat-lock-data-path-already-locked-by-another-beat-please-make-sure-that-multiple-beats-are-not-sharing-the-same-data-path-path-data/337991)

<div class="topic-metadata">

**Author:** [@Sharad\_Nautiyal](https://discuss.elastic.co/u/Sharad_Nautiyal)\
**Replies:** 0\
**Last updated:** [July 10, 2023, 6:12am UTC](https://discuss.elastic.co/t/getting-error-exiting-usr-share-filebeat-data-filebeat-lock-data-path-already-locked-by-another-beat-please-make-sure-that-multiple-beats-are-not-sharing-the-same-data-path-path-data/337991 "2023-07-10T06:12:39Z")

</div>

Hi Everyone, We have a central system to monitor logs for all the K8s clusters pods including specific label. There are specific pods for which we want to setup a different pre-processing system but when we are deployi…

---

## [Filebeat cloudwatch input not reading dynamic log groups/ log streams](https://discuss.elastic.co/t/filebeat-cloudwatch-input-not-reading-dynamic-log-groups-log-streams/337982)

<div class="topic-metadata">

**Author:** [@arungiyer](https://discuss.elastic.co/u/arungiyer)\
**Replies:** 0\
**Last updated:** [July 10, 2023, 3:45am UTC](https://discuss.elastic.co/t/filebeat-cloudwatch-input-not-reading-dynamic-log-groups-log-streams/337982 "2023-07-10T03:45:51Z")

</div>

I am using filebeat docker image (8.7.1) to run an ecs service that reads cloudwatch logs and send to an index. My cloudwatch log groups gets created dynamically so i am using "log\_group\_name\_prefix" to identify all log …

---

## [\[APM Logs\] - How to Specify the API Data Field based on User Perspectives](https://discuss.elastic.co/t/apm-logs-how-to-specify-the-api-data-field-based-on-user-perspectives/337981)

<div class="topic-metadata">

**Author:** [@aisyaharifin](https://discuss.elastic.co/u/aisyaharifin)\
**Replies:** 0\
**Last updated:** [July 10, 2023, 3:40am UTC](https://discuss.elastic.co/t/apm-logs-how-to-specify-the-api-data-field-based-on-user-perspectives/337981 "2023-07-10T03:40:22Z")

</div>

Hello Elastic, I want to ask, I have a situation where my user would like to access the APM Error Logs to pull the data to display in their dashboard. I already give them the API Key and URL for them to access to the l…

---

## [How to provide source Field in \_msearch query in ElasticSearch java client version 8](https://discuss.elastic.co/t/how-to-provide-source-field-in-msearch-query-in-elasticsearch-java-client-version-8/337924)

<div class="topic-metadata">

**Author:** [@maulik\_trapasiya](https://discuss.elastic.co/u/maulik_trapasiya)\
**Replies:** 2\
**Last updated:** [July 10, 2023, 3:19am UTC](https://discuss.elastic.co/t/how-to-provide-source-field-in-msearch-query-in-elasticsearch-java-client-version-8/337924 "2023-07-10T03:19:14Z")

</div>

My Elasticsearch's documents are of high size. My service is Java application and its using Elasticsearch java client version 8. Need to run \_msearch query on ES. MultisearchBody don't have field of \_source. in ES native…

---

## [Restriction for API Key](https://discuss.elastic.co/t/restriction-for-api-key/337973)

<div class="topic-metadata">

**Author:** [@aisyaharifin](https://discuss.elastic.co/u/aisyaharifin)\
**Replies:** 0\
**Last updated:** [July 10, 2023, 1:32am UTC](https://discuss.elastic.co/t/restriction-for-api-key/337973 "2023-07-10T01:32:36Z")

</div>

Hello, I would like to ask, how do I restrict the privileges roles for API Key, to pin point to specific "service.name" field in APM data? Thank you.

---

## [Ingest Pipeline for parsing multiline fields giving provided Grok expressions do not match field value error error](https://discuss.elastic.co/t/ingest-pipeline-for-parsing-multiline-fields-giving-provided-grok-expressions-do-not-match-field-value-error-error/337699)

<div class="topic-metadata">

**Author:** [@SecretAsianMan](https://discuss.elastic.co/u/SecretAsianMan)\
**Replies:** 1\
**Last updated:** [July 9, 2023, 9:40pm UTC](https://discuss.elastic.co/t/ingest-pipeline-for-parsing-multiline-fields-giving-provided-grok-expressions-do-not-match-field-value-error-error/337699 "2023-07-09T21:40:24Z")

</div>

I am trying to parse a multiline log file as shown below. This is the processor that I have currently configured for the multiline log file. \[ { "grok": { "field": "message", "patterns": \[ "…

---

## [Reindexing an index which had document added by ingest pipeline](https://discuss.elastic.co/t/reindexing-an-index-which-had-document-added-by-ingest-pipeline/337951)

<div class="topic-metadata">

**Author:** [@Aditya\_Teltia](https://discuss.elastic.co/u/Aditya_Teltia)\
**Replies:** 12\
**Last updated:** [July 9, 2023, 8:02pm UTC](https://discuss.elastic.co/t/reindexing-an-index-which-had-document-added-by-ingest-pipeline/337951 "2023-07-09T20:02:52Z")

</div>

I have an index my-idx-09-2022. I made a ingest pipeline so that all the updates from now of my-idx-09-2022 will go to a new index i.e my-idx-new-09-2023. Python code: def create\_write\_redirect\_pipeline(source\_client, …

---

## [Gork regex](https://discuss.elastic.co/t/gork-regex/337623)

<div class="topic-metadata">

**Author:** [@Indeed2000](https://discuss.elastic.co/u/Indeed2000)\
**Replies:** 8\
**Last updated:** [July 9, 2023, 6:29pm UTC](https://discuss.elastic.co/t/gork-regex/337623 "2023-07-09T18:29:28Z")

</div>

Hi I use this logstash gork: %{TIMESTAMP\_ISO8601:timestamp} %{LOGLEVEL:loglevel} %{DATA:id} \[%{DATA}\] %{DATA:jboss\_errors}(?=:|$) here is the log: 2023-06-30 09:09:55,941 ERROR CUS.InEP-AAAA-123194144 \[invocation\] WF…

---

## [How does Allocation of shards happens, when a node leaves cluster?](https://discuss.elastic.co/t/how-does-allocation-of-shards-happens-when-a-node-leaves-cluster/337960)

<div class="topic-metadata">

**Author:** [@Shashank\_Agrawal](https://discuss.elastic.co/u/Shashank_Agrawal)\
**Replies:** 3\
**Last updated:** [July 9, 2023, 5:09pm UTC](https://discuss.elastic.co/t/how-does-allocation-of-shards-happens-when-a-node-leaves-cluster/337960 "2023-07-09T17:09:33Z")

</div>

I want to know the exact procedure followed, for the allocation of shards on a node when the node leaves the cluster. Facts I know - 1.) ES waits for sometime before the reassigning the shards. 2.) For primary shards, …

---

## [Elasticsearch service not starting](https://discuss.elastic.co/t/elasticsearch-service-not-starting/337954)

<div class="topic-metadata">

**Author:** [@Jefferson\_Lourthusam](https://discuss.elastic.co/u/Jefferson_Lourthusam)\
**Replies:** 5\
**Last updated:** [July 9, 2023, 3:17pm UTC](https://discuss.elastic.co/t/elasticsearch-service-not-starting/337954 "2023-07-09T15:17:49Z")

</div>

Elasticsearch service not starting , we can see below in Elasticsearch-STG logs low disk watermark \[85%\] exceeded on free: 37.4gb\[14.9%\], replicas will not be assigned to this node

---

## [ELK for Ransomware Identification and Mitigation on Virtual Machines](https://discuss.elastic.co/t/elk-for-ransomware-identification-and-mitigation-on-virtual-machines/337350)

<div class="topic-metadata">

**Author:** [@ADUBOAHENE0016](https://discuss.elastic.co/u/ADUBOAHENE0016)\
**Replies:** 4\
**Last updated:** [July 9, 2023, 1:52pm UTC](https://discuss.elastic.co/t/elk-for-ransomware-identification-and-mitigation-on-virtual-machines/337350 "2023-07-09T13:52:25Z")

</div>

1.Setting up the ELK stack 2.Virtualbox 3.Forwarding logs from the virtual machine to ELK 4.Constructing rules for ransomware detection 5.Isolation, containment, remediation, recovery continuous improvement and maint…

---

## [Ingest pipeline routing documents to appropriate target index requires permissions on target index](https://discuss.elastic.co/t/ingest-pipeline-routing-documents-to-appropriate-target-index-requires-permissions-on-target-index/337923)

<div class="topic-metadata">

**Author:** [@Jurgen\_Wagner\_DVT](https://discuss.elastic.co/u/Jurgen_Wagner_DVT)\
**Replies:** 4\
**Last updated:** [July 8, 2023, 9:20pm UTC](https://discuss.elastic.co/t/ingest-pipeline-routing-documents-to-appropriate-target-index-requires-permissions-on-target-index/337923 "2023-07-08T21:20:46Z")

</div>

Suppose you don't trust data-feeding users to place documents into the right index, so you create a virtual index with an ingestion pipeline that determines the proper target index alias based on a few fields in each doc…

---

## [Missing authentication credential for REST request](https://discuss.elastic.co/t/missing-authentication-credential-for-rest-request/337339)

<div class="topic-metadata">

**Author:** [@kbfifi](https://discuss.elastic.co/u/kbfifi)\
**Replies:** 2\
**Last updated:** [July 8, 2023, 1:24pm UTC](https://discuss.elastic.co/t/missing-authentication-credential-for-rest-request/337339 "2023-07-08T13:24:06Z")

</div>

I'm trying to finish my single node setup with elasticsearch(ES) and kibana. I'm using docker-compose and ES version 7.17. I wanted to go without security however it is my understanding that adding adapters like Mongo DB…

---

## [Extract value from path in logstash](https://discuss.elastic.co/t/extract-value-from-path-in-logstash/337936)

<div class="topic-metadata">

**Author:** [@Indeed2000](https://discuss.elastic.co/u/Indeed2000)\
**Replies:** 0\
**Last updated:** [July 8, 2023, 12:20pm UTC](https://discuss.elastic.co/t/extract-value-from-path-in-logstash/337936 "2023-07-08T12:20:18Z")

</div>

Hi need to extract value from path in logstash, here is my logpath: /data/app/20230707/\*/\* /data/app1/20230707/host1/\*.log /data/app2/20230707/host2/\*.log need to extract these field from path (FYI: hostname must be …

---

## [Filtering logic in elastic search output](https://discuss.elastic.co/t/filtering-logic-in-elastic-search-output/337922)

<div class="topic-metadata">

**Author:** [@Minika](https://discuss.elastic.co/u/Minika)\
**Replies:** 0\
**Last updated:** [July 8, 2023, 12:29am UTC](https://discuss.elastic.co/t/filtering-logic-in-elastic-search-output/337922 "2023-07-08T00:29:07Z")

</div>

Hi, I am trying to apply a filter logic in OCP Logstash pipeline. My pipeline receive logs from filebeat which contain a fields tag named logtype(that states the type of log) My motive is to use the logtype value and sen…

---

## [Mocking Search Results in new Java API](https://discuss.elastic.co/t/mocking-search-results-in-new-java-api/337012)

<div class="topic-metadata">

**Author:** [@silentfilm](https://discuss.elastic.co/u/silentfilm)\
**Replies:** 3\
**Last updated:** [July 7, 2023, 9:30pm UTC](https://discuss.elastic.co/t/mocking-search-results-in-new-java-api/337012 "2023-07-07T21:30:45Z")

</div>

Are there any examples of how to mock an Elasticsearch search result for the Java API for unit tests with Mockito? Do you mock the entire search result or individual hits? If I search the Internet for examples I only see…

---

## [Logstash using codec line is not working](https://discuss.elastic.co/t/logstash-using-codec-line-is-not-working/337816)

<div class="topic-metadata">

**Author:** [@cressprm](https://discuss.elastic.co/u/cressprm)\
**Replies:** 1\
**Last updated:** [July 7, 2023, 9:29pm UTC](https://discuss.elastic.co/t/logstash-using-codec-line-is-not-working/337816 "2023-07-07T21:29:17Z")

</div>

I am new to ELK and having trouble configuring a simple Logstash pipeline. Despite enabling debug logging(--log.level=debug), I can only find a message that says 'Received line' in the logs, and nothing else. Not sure wh…

---

## [Elasticsearch.service: Main process exited, code=killed, status=9/KILL](https://discuss.elastic.co/t/elasticsearch-service-main-process-exited-code-killed-status-9-kill/337796)

<div class="topic-metadata">

**Author:** [@bbkunbi](https://discuss.elastic.co/u/bbkunbi)\
**Replies:** 3\
**Last updated:** [July 7, 2023, 9:23pm UTC](https://discuss.elastic.co/t/elasticsearch-service-main-process-exited-code-killed-status-9-kill/337796 "2023-07-07T21:23:04Z")

</div>

Errror: elasticsearch.service: Main process exited, code=killed, status=9/KILL ul 06 17:32:05 linux systemd\[1\]: elasticsearch.service: Main process exited, code=killed, status=9/KILL Jul 06 17:32:05 linux systemd\[1\]: e…

---

## [Add new field to index based on maths calculation from other fields in the same index](https://discuss.elastic.co/t/add-new-field-to-index-based-on-maths-calculation-from-other-fields-in-the-same-index/337571)

<div class="topic-metadata">

**Author:** [@patcan](https://discuss.elastic.co/u/patcan)\
**Replies:** 12\
**Last updated:** [July 7, 2023, 9:15pm UTC](https://discuss.elastic.co/t/add-new-field-to-index-based-on-maths-calculation-from-other-fields-in-the-same-index/337571 "2023-07-07T21:15:07Z")

</div>

Hi, I use elastic-agent on EKS with kubernetes integration. One of the field such as kubernetes.volume.fs.used.pct in the index provides incorrect values I was able to get the correct value using the following formula…

---

## [Cannot get network drive connector to work](https://discuss.elastic.co/t/cannot-get-network-drive-connector-to-work/337445)

<div class="topic-metadata">

**Author:** [@Bairdy](https://discuss.elastic.co/u/Bairdy)\
**Replies:** 2\
**Last updated:** [July 7, 2023, 7:43pm UTC](https://discuss.elastic.co/t/cannot-get-network-drive-connector-to-work/337445 "2023-07-07T19:43:11Z")

</div>

Hi. I'm trying to get the network drive connector working in an offline environment (the first challenge was getting the thing made and portable but that's another issue). We do have an Enterprise licence but I don't bel…

---

## [Filter by Date in URL](https://discuss.elastic.co/t/filter-by-date-in-url/337083)

<div class="topic-metadata">

**Author:** [@Lehmer](https://discuss.elastic.co/u/Lehmer)\
**Replies:** 1\
**Last updated:** [July 7, 2023, 7:40pm UTC](https://discuss.elastic.co/t/filter-by-date-in-url/337083 "2023-07-07T19:40:13Z")

</div>

Hi, I need to access a kibana web filtering by date, but I need to put the filter in the URL. I know how to filter Namespaces and Jobs with the URL using queries: https:// kibana-host/s/desa/app/dashboards#/view/9908…

---

## [Canvas : Grouping of Elements](https://discuss.elastic.co/t/canvas-grouping-of-elements/337881)

<div class="topic-metadata">

**Author:** [@ksaimohan2k](https://discuss.elastic.co/u/ksaimohan2k)\
**Replies:** 2\
**Last updated:** [July 7, 2023, 6:26pm UTC](https://discuss.elastic.co/t/canvas-grouping-of-elements/337881 "2023-07-07T18:26:36Z")

</div>

Is it possible to group different elements in Canvas? Just attach them.

---

## [Building Custom Elastic Synthetics Dashboards](https://discuss.elastic.co/t/building-custom-elastic-synthetics-dashboards/337892)

<div class="topic-metadata">

**Author:** [@DougR](https://discuss.elastic.co/u/DougR)\
**Replies:** 2\
**Last updated:** [July 7, 2023, 6:00pm UTC](https://discuss.elastic.co/t/building-custom-elastic-synthetics-dashboards/337892 "2023-07-07T18:00:04Z")

</div>

I'm using Elastic Cloud, v8.8.2. I'm receiving a request to create an executive dashboard based on Elastic Uptime and Elastic Synthetics data. This dashboard would group related applications into an easy-to view format,…

[Previous page](https://discuss.elastic.co/latest.md?page=612)

[Next page](https://discuss.elastic.co/latest.md?page=614)
