# Latest

**URL:** https://discuss.elastic.co/latest.md?page=618

[Latest](https://discuss.elastic.co/latest.md) · [Categories](https://discuss.elastic.co/categories.md) · [Tags](https://discuss.elastic.co/tags.md)

**Page:** 619

---

## [PutComposableIndexTemplateRequest in Custom Plugin](https://discuss.elastic.co/t/putcomposableindextemplaterequest-in-custom-plugin/337625)

<div class="topic-metadata">

**Author:** [@\_murat](https://discuss.elastic.co/u/_murat)\
**Replies:** 0\
**Last updated:** [July 5, 2023, 7:12am UTC](https://discuss.elastic.co/t/putcomposableindextemplaterequest-in-custom-plugin/337625 "2023-07-05T07:12:14Z")

</div>

Hello! I have been working on a custom Elasticsearch plugin that should create an index template and its components when an Elasticsearch instance loads this plugin. The only client that I can access is NodeClient and t…

---

## [MongoDB to Elasticsearch?](https://discuss.elastic.co/t/mongodb-to-elasticsearch/336767)

<div class="topic-metadata">

**Author:** [@stephane\_chan](https://discuss.elastic.co/u/stephane_chan)\
**Replies:** 4\
**Last updated:** [July 5, 2023, 6:40am UTC](https://discuss.elastic.co/t/mongodb-to-elasticsearch/336767 "2023-07-05T06:40:52Z")

</div>

Is there a way to index data from mongoDB to elasticsearch? I've searched a bit but I haven't found any mongodb input on logstash i.e. part of the mongoDB collection by making an aggregation query and then storing the r…

---

## [How to use curl command to input data into logstash](https://discuss.elastic.co/t/how-to-use-curl-command-to-input-data-into-logstash/337615)

<div class="topic-metadata">

**Author:** [@vijeibarthi](https://discuss.elastic.co/u/vijeibarthi)\
**Replies:** 0\
**Last updated:** [July 5, 2023, 6:21am UTC](https://discuss.elastic.co/t/how-to-use-curl-command-to-input-data-into-logstash/337615 "2023-07-05T06:21:16Z")

</div>

Hi All, I have a curl command which works fine but I have trouble using that curl command in the json format. Please guide on how to correct this script to output the data. =============================================…

---

## [Regular expressions in kibana filters](https://discuss.elastic.co/t/regular-expressions-in-kibana-filters/337548)

<div class="topic-metadata">

**Author:** [@SajjanKumarPatea](https://discuss.elastic.co/u/SajjanKumarPatea)\
**Replies:** 1\
**Last updated:** [July 5, 2023, 6:11am UTC](https://discuss.elastic.co/t/regular-expressions-in-kibana-filters/337548 "2023-07-05T06:11:55Z")

</div>

Can you tell me how to filter messages in indexes correctly? I am filtering messages by a specific field. And I want to see messages only with this value in the field: id-nmap100-tapic-prod But I also get messages wit…

---

## [TCP input failed with Checkpoint syslog integration](https://discuss.elastic.co/t/tcp-input-failed-with-checkpoint-syslog-integration/337609)

<div class="topic-metadata">

**Author:** [@adub08](https://discuss.elastic.co/u/adub08)\
**Replies:** 0\
**Last updated:** [July 5, 2023, 6:04am UTC](https://discuss.elastic.co/t/tcp-input-failed-with-checkpoint-syslog-integration/337609 "2023-07-05T06:04:50Z")

</div>

Hi I've been unable to setup the Checkpoint Elastic integration due to this error. \[elastic\_agent.filebeat\]\[error\] Input 'tcp' failed with: context canceled Settings: Integration info: logfile: disabled UDP: disa…

---

## [Not eligible for data streams because config contains one or more settings that are not compatible with data streams](https://discuss.elastic.co/t/not-eligible-for-data-streams-because-config-contains-one-or-more-settings-that-are-not-compatible-with-data-streams/337594)

<div class="topic-metadata">

**Author:** [@Cruz](https://discuss.elastic.co/u/Cruz)\
**Replies:** 4\
**Last updated:** [July 5, 2023, 3:27am UTC](https://discuss.elastic.co/t/not-eligible-for-data-streams-because-config-contains-one-or-more-settings-that-are-not-compatible-with-data-streams/337594 "2023-07-05T03:27:44Z")

</div>

I tried to upload my template using Logstash, but it did not. It says that \[2023-07-05T00:03:53,496\]\[INFO \]\[logstash.outputs.elasticsearch\]\[main\] Not eligible for data streams because config contains one or more settin…

---

## [Can I use "from/size", "timeout", "track\_total\_hits", "format", etc. for free?](https://discuss.elastic.co/t/can-i-use-from-size-timeout-track-total-hits-format-etc-for-free/337523)

<div class="topic-metadata">

**Author:** [@kimjinyoung](https://discuss.elastic.co/u/kimjinyoung)\
**Replies:** 2\
**Last updated:** [July 4, 2023, 11:46pm UTC](https://discuss.elastic.co/t/can-i-use-from-size-timeout-track-total-hits-format-etc-for-free/337523 "2023-07-04T23:46:30Z")

</div>

hi thank for watching Can I use "from/size", "timeout", "track\_total\_hits", "format", etc. for free? "When I looked it up on the following site, I found that "from/size", "timeout"," "track\_total\_hits" and "format" be…

---

## [Strategy for matching unstructured text to phrases in index](https://discuss.elastic.co/t/strategy-for-matching-unstructured-text-to-phrases-in-index/337583)

<div class="topic-metadata">

**Author:** [@rustunooldu](https://discuss.elastic.co/u/rustunooldu)\
**Replies:** 2\
**Last updated:** [July 4, 2023, 7:39pm UTC](https://discuss.elastic.co/t/strategy-for-matching-unstructured-text-to-phrases-in-index/337583 "2023-07-04T19:39:59Z")

</div>

I'm trying to extract data from product descriptions, and I have the catalog data indexed and categorized. For example, I have a color name index (that contains all possible colors for the product), and I want to be able…

---

## [Replicas shards of Default indexers are in UNASSIGNED State](https://discuss.elastic.co/t/replicas-shards-of-default-indexers-are-in-unassigned-state/336979)

<div class="topic-metadata">

**Author:** [@Sathish22](https://discuss.elastic.co/u/Sathish22)\
**Replies:** 11\
**Last updated:** [July 4, 2023, 5:42pm UTC](https://discuss.elastic.co/t/replicas-shards-of-default-indexers-are-in-unassigned-state/336979 "2023-07-04T17:42:45Z")

</div>

Hi Team, Recently we are facing a issue with replicas shards and all default indexers replica shards are in UNASSIGNED State. due to this cluster is going to yellow and red state. index shard prirep state .ta…

---

## [Bitdefender GravityZone and Logstash Integration](https://discuss.elastic.co/t/bitdefender-gravityzone-and-logstash-integration/337582)

<div class="topic-metadata">

**Author:** [@Paulo\_Martins\_de\_Sen](https://discuss.elastic.co/u/Paulo_Martins_de_Sen)\
**Replies:** 0\
**Last updated:** [July 4, 2023, 5:24pm UTC](https://discuss.elastic.co/t/bitdefender-gravityzone-and-logstash-integration/337582 "2023-07-04T17:24:48Z")

</div>

Hey guys, has anyone done Bitdefender GravityZone and Elastic Security integration? I'm trying to do it through agent elastic, but without success so far.

---

## [How to check if a keyword exists in elastalert](https://discuss.elastic.co/t/how-to-check-if-a-keyword-exists-in-elastalert/337581)

<div class="topic-metadata">

**Author:** [@Chel\_Db](https://discuss.elastic.co/u/Chel_Db)\
**Replies:** 2\
**Last updated:** [July 4, 2023, 5:14pm UTC](https://discuss.elastic.co/t/how-to-check-if-a-keyword-exists-in-elastalert/337581 "2023-07-04T17:14:33Z")

</div>

I wanted to send out an alert to our slack channel if a there is an indexing error or the number of events \> 20 for last 10 minutes. Below is my elastalert yaml configuration. influx\_indexing\_error\_slack\_message\_rule: |…

---

## [ilm policy delete action is disable but index is still be deleted](https://discuss.elastic.co/t/ilm-policy-delete-action-is-disable-but-index-is-still-be-deleted/337515)

<div class="topic-metadata">

**Author:** [@frank\_spr](https://discuss.elastic.co/u/frank_spr)\
**Replies:** 2\
**Last updated:** [July 4, 2023, 4:37pm UTC](https://discuss.elastic.co/t/ilm-policy-delete-action-is-disable-but-index-is-still-be-deleted/337515 "2023-07-04T16:37:49Z")

</div>

My Elasticsearch index is managed by IML. Recently, I discovered that my index has been deleted for no reason, so I disabled the delete operation in the IML policy. However, I found that my index will still be deleted 1…

---

## [Log alerting for different applications](https://discuss.elastic.co/t/log-alerting-for-different-applications/337559)

<div class="topic-metadata">

**Author:** [@Jonas\_S](https://discuss.elastic.co/u/Jonas_S)\
**Replies:** 3\
**Last updated:** [July 4, 2023, 4:20pm UTC](https://discuss.elastic.co/t/log-alerting-for-different-applications/337559 "2023-07-04T16:20:31Z")

</div>

Hello, i'm a bit confused over the way the alerting works in the elastic stack. I have multiple small applications that generate logs and also have to manage multiple larger applications that generate multiple differen…

---

## [Logstash @timestamp not including milliseconds](https://discuss.elastic.co/t/logstash-timestamp-not-including-milliseconds/337579)

<div class="topic-metadata">

**Author:** [@Anthony\_Zottola](https://discuss.elastic.co/u/Anthony_Zottola)\
**Replies:** 2\
**Last updated:** [July 4, 2023, 4:17pm UTC](https://discuss.elastic.co/t/logstash-timestamp-not-including-milliseconds/337579 "2023-07-04T16:17:08Z")

</div>

All of my logs have this format "@timestamp" =\> 2023-07-04T15:40:19.000Z where the milliseconds are missing, is there any way to make it included the milliseconds. I tried manually adding it but it is read only. My con…

---

## [Heartbeat: Ping TImeout on hosts causes state.duration\_ms to stay at 0?](https://discuss.elastic.co/t/heartbeat-ping-timeout-on-hosts-causes-state-duration-ms-to-stay-at-0/334051)

<div class="topic-metadata">

**Author:** [@scantron](https://discuss.elastic.co/u/scantron)\
**Replies:** 7\
**Last updated:** [July 4, 2023, 3:46pm UTC](https://discuss.elastic.co/t/heartbeat-ping-timeout-on-hosts-causes-state-duration-ms-to-stay-at-0/334051 "2023-07-04T15:46:49Z")

</div>

We are monitoring a few hosts using ICMP on heartbeat. Heartbeat accurately depicts the uptime using the state.duration\_ms field. However, shutting down a host for testing leads to the error.message field of "ping timeou…

---

## [How to setup a cluster from scratch](https://discuss.elastic.co/t/how-to-setup-a-cluster-from-scratch/337564)

<div class="topic-metadata">

**Author:** [@Dheeraj\_Gupta](https://discuss.elastic.co/u/Dheeraj_Gupta)\
**Replies:** 4\
**Last updated:** [July 4, 2023, 2:31pm UTC](https://discuss.elastic.co/t/how-to-setup-a-cluster-from-scratch/337564 "2023-07-04T14:31:18Z")

</div>

Hi, I have been using elasticsearch for a long time. Our initial cluster was setup in 5.x days (installation procedures have been 'lost') and we have performed rolling upgrade ever since. Currently the cluster is 8.8 wi…

---

## [How to change the username by own instead of elastic?](https://discuss.elastic.co/t/how-to-change-the-username-by-own-instead-of-elastic/337552)

<div class="topic-metadata">

**Author:** [@merson](https://discuss.elastic.co/u/merson)\
**Replies:** 1\
**Last updated:** [July 4, 2023, 2:09pm UTC](https://discuss.elastic.co/t/how-to-change-the-username-by-own-instead-of-elastic/337552 "2023-07-04T14:09:37Z")

</div>

How to change the username by own instead of elastic in ELK?

---

## [Metricbeat windows module error](https://discuss.elastic.co/t/metricbeat-windows-module-error/337566)

<div class="topic-metadata">

**Author:** [@dchaarifreedomofdev](https://discuss.elastic.co/u/dchaarifreedomofdev)\
**Replies:** 0\
**Last updated:** [July 4, 2023, 1:43pm UTC](https://discuss.elastic.co/t/metricbeat-windows-module-error/337566 "2023-07-04T13:43:14Z")

</div>

I have installed metricbeat 7.17.5 on my windows machine and I enabled the windows module. And I added this configuration : module: windows metricsets: - service enabled: true period: 30s But when I r…

---

## [Comment logguer une stacktrace en un seul message au lieu de plusieurs lignes dans kibana?](https://discuss.elastic.co/t/comment-logguer-une-stacktrace-en-un-seul-message-au-lieu-de-plusieurs-lignes-dans-kibana/337561)

<div class="topic-metadata">

**Author:** [@ANARAN](https://discuss.elastic.co/u/ANARAN)\
**Replies:** 0\
**Last updated:** [July 4, 2023, 12:39pm UTC](https://discuss.elastic.co/t/comment-logguer-une-stacktrace-en-un-seul-message-au-lieu-de-plusieurs-lignes-dans-kibana/337561 "2023-07-04T12:39:56Z")

</div>

Bonjour, Je travaille sur un projet liferay qui utilise log4j 1 . Mon but est de réduire une liste de message pour une stacktrace en un seul message dépliable (ci-dessous ce que j'ai pour l'instant) : Mon projet fo…

---

## [Documents not editable of index](https://discuss.elastic.co/t/documents-not-editable-of-index/337307)

<div class="topic-metadata">

**Author:** [@Jay\_Desai](https://discuss.elastic.co/u/Jay_Desai)\
**Replies:** 13\
**Last updated:** [July 4, 2023, 12:37pm UTC](https://discuss.elastic.co/t/documents-not-editable-of-index/337307 "2023-07-04T12:37:55Z")

</div>

PUT /your-index/\_settings { "index.blocks.write": true } not working

---

## [ECK Operator 2.8+ Shutdown API/Pre-stop Hook Script Change with many node drains question](https://discuss.elastic.co/t/eck-operator-2-8-shutdown-api-pre-stop-hook-script-change-with-many-node-drains-question/337473)

<div class="topic-metadata">

**Author:** [@BenB196](https://discuss.elastic.co/u/BenB196)\
**Replies:** 2\
**Last updated:** [July 4, 2023, 11:23am UTC](https://discuss.elastic.co/t/eck-operator-2-8-shutdown-api-pre-stop-hook-script-change-with-many-node-drains-question/337473 "2023-07-04T11:23:40Z")

</div>

Hello, I had a question, that I couldn't really find an answer too. In ECK Operator 2.8.0 the Shutdown API was moved to the pre-stop hook: https://github.com/elastic/cloud-on-k8s/pull/6544. The question I have and what …

---

## [Boost score if query contains all tokens in the field](https://discuss.elastic.co/t/boost-score-if-query-contains-all-tokens-in-the-field/337551)

<div class="topic-metadata">

**Author:** [@Siah\_Wei\_Chong](https://discuss.elastic.co/u/Siah_Wei_Chong)\
**Replies:** 0\
**Last updated:** [July 4, 2023, 10:31am UTC](https://discuss.elastic.co/t/boost-score-if-query-contains-all-tokens-in-the-field/337551 "2023-07-04T10:31:17Z")

</div>

I am new to Elasticsearch. I am working off Search for an address My query looks like this GET all\_address/\_search { "explain":true, "query":{ "multi\_match": { "query": "Flat 1, Floor 1, Raymond Court"…

---

## [Elastic Security Detection Rule Management - Update of Duplicates](https://discuss.elastic.co/t/elastic-security-detection-rule-management-update-of-duplicates/337550)

<div class="topic-metadata">

**Author:** [@hanna](https://discuss.elastic.co/u/hanna)\
**Replies:** 0\
**Last updated:** [July 4, 2023, 10:28am UTC](https://discuss.elastic.co/t/elastic-security-detection-rule-management-update-of-duplicates/337550 "2023-07-04T10:28:57Z")

</div>

Hi everyone, does anyone have experience with managing prebuilt detection rules with your own index-patterns and exceptions? Right now I load the prebuilt rules into kibana and then duplicate them in order to add my ow…

---

## [Filebeat restart question](https://discuss.elastic.co/t/filebeat-restart-question/335194)

<div class="topic-metadata">

**Author:** [@nunex\_17](https://discuss.elastic.co/u/nunex_17)\
**Replies:** 4\
**Last updated:** [July 4, 2023, 10:24am UTC](https://discuss.elastic.co/t/filebeat-restart-question/335194 "2023-07-04T10:24:32Z")

</div>

Hi there, Everytime I need to restart Filebeat, my "scripted fields" and customization to some fields are broken. Also the dashboards are reset. Is this normal? Is there any way that I can fix this behaviour to prevent…

---

## [APM Transaction Query](https://discuss.elastic.co/t/apm-transaction-query/337547)

<div class="topic-metadata">

**Author:** [@User1030](https://discuss.elastic.co/u/User1030)\
**Replies:** 0\
**Last updated:** [July 4, 2023, 10:18am UTC](https://discuss.elastic.co/t/apm-transaction-query/337547 "2023-07-04T10:18:21Z")

</div>

In Elastic APM portal is there a way to query for transactions based on the duration of the gap between spans? Like the image in Improving analysis of gaps between spans

---

## [How to create request body for Rust Elasticsearch mSearch](https://discuss.elastic.co/t/how-to-create-request-body-for-rust-elasticsearch-msearch/337540)

<div class="topic-metadata">

**Author:** [@aniket\_mandhare](https://discuss.elastic.co/u/aniket_mandhare)\
**Replies:** 1\
**Last updated:** [July 4, 2023, 9:50am UTC](https://discuss.elastic.co/t/how-to-create-request-body-for-rust-elasticsearch-msearch/337540 "2023-07-04T09:50:50Z")

</div>

Please help me to implement multi search functionality or \_msearch api in in Rust programming language.

---

## [Balance Nodes by CPU Usage](https://discuss.elastic.co/t/balance-nodes-by-cpu-usage/336932)

<div class="topic-metadata">

**Author:** [@IsaacD](https://discuss.elastic.co/u/IsaacD)\
**Replies:** 10\
**Last updated:** [July 4, 2023, 8:06am UTC](https://discuss.elastic.co/t/balance-nodes-by-cpu-usage/336932 "2023-07-04T08:06:19Z")

</div>

Is there a way to balance the nodes by CPU instead of shard count? I'm constantly seeing 1-3 of our hot nodes sitting above 60% cpu usage where the other 6 hot nodes are around 10%. They all have the same amount of sha…

---

## [Java ElasticsearchClient: Conditionally mapping result hits to a certain object depending on a field or index](https://discuss.elastic.co/t/java-elasticsearchclient-conditionally-mapping-result-hits-to-a-certain-object-depending-on-a-field-or-index/337524)

<div class="topic-metadata">

**Author:** [@paulwellnerbou](https://discuss.elastic.co/u/paulwellnerbou)\
**Replies:** 0\
**Last updated:** [July 4, 2023, 7:33am UTC](https://discuss.elastic.co/t/java-elasticsearchclient-conditionally-mapping-result-hits-to-a-certain-object-depending-on-a-field-or-index/337524 "2023-07-04T07:33:09Z")

</div>

Using the Java ElasticsearchClient, is it possible to create a custom mapper, so that depending on a certain field (or index) of the result hit, a different object is mapped? I have several indices with different, but v…

---

## [Quarkus micrometer not consumed by APM server](https://discuss.elastic.co/t/quarkus-micrometer-not-consumed-by-apm-server/337521)

<div class="topic-metadata">

**Author:** [@wilfried\_vandenbergh](https://discuss.elastic.co/u/wilfried_vandenbergh)\
**Replies:** 0\
**Last updated:** [July 4, 2023, 7:24am UTC](https://discuss.elastic.co/t/quarkus-micrometer-not-consumed-by-apm-server/337521 "2023-07-04T07:24:43Z")

</div>

I'm trying to push traces and metrics from a Quarkus application to APM Server (version 8.3) by using opentelemetry. For traces, it works fine, I'm able to retrieve my data in elastic indexes, but not for metrics, it see…

---

## [External application to connect kafka in internal network](https://discuss.elastic.co/t/external-application-to-connect-kafka-in-internal-network/337481)

<div class="topic-metadata">

**Author:** [@Shalinicts](https://discuss.elastic.co/u/Shalinicts)\
**Replies:** 4\
**Last updated:** [July 4, 2023, 7:13am UTC](https://discuss.elastic.co/t/external-application-to-connect-kafka-in-internal-network/337481 "2023-07-04T07:13:05Z")

</div>

Hi Team, How can I expose Kafka to external network so that external source can connect or push data to my Kafka within internal network . Thanks

[Previous page](https://discuss.elastic.co/latest.md?page=617)

[Next page](https://discuss.elastic.co/latest.md?page=619)
