# Latest

**URL:** https://discuss.elastic.co/latest.md?page=621

[Latest](https://discuss.elastic.co/latest.md) · [Categories](https://discuss.elastic.co/categories.md) · [Tags](https://discuss.elastic.co/tags.md)

**Page:** 622

---

## [Boostrap Elasticsearch Index Template](https://discuss.elastic.co/t/boostrap-elasticsearch-index-template/337377)

<div class="topic-metadata">

**Author:** [@mibeyki](https://discuss.elastic.co/u/mibeyki)\
**Replies:** 2\
**Last updated:** [July 1, 2023, 3:35pm UTC](https://discuss.elastic.co/t/boostrap-elasticsearch-index-template/337377 "2023-07-01T15:35:56Z")

</div>

Hello, I am trying to configure Filebeat to write data to a custom index like my-index-{now/d}-000001 (using filebeat-8.8.1 and Elastcicsearch 8.8.1). I have followed this guide; But when i try to bootstrap the index u…

---

## [Netflow Mikrotik no data in elasticsearch](https://discuss.elastic.co/t/netflow-mikrotik-no-data-in-elasticsearch/335692)

<div class="topic-metadata">

**Author:** [@sana1567](https://discuss.elastic.co/u/sana1567)\
**Replies:** 20\
**Last updated:** [July 1, 2023, 2:29pm UTC](https://discuss.elastic.co/t/netflow-mikrotik-no-data-in-elasticsearch/335692 "2023-07-01T14:29:16Z")

</div>

hello please help, installed elastic 8.8 + kibana filebeat + netflow I don't see data in my Elasticsearch also when checking the netflow module - check data - No data has been received from this module yet /etc/filebe…

---

## [Custom index not showing in Kibana V8.8.0](https://discuss.elastic.co/t/custom-index-not-showing-in-kibana-v8-8-0/336621)

<div class="topic-metadata">

**Author:** [@huzaifa224](https://discuss.elastic.co/u/huzaifa224)\
**Replies:** 11\
**Last updated:** [July 1, 2023, 1:16pm UTC](https://discuss.elastic.co/t/custom-index-not-showing-in-kibana-v8-8-0/336621 "2023-07-01T13:16:50Z")

</div>

I have multiple filebeats v 7.17.5 are configured on different remote servers with custom index names. I have recently updated my ELk stack to 8.8.0 and also updating the filebeat version to 8.8.0. I also try to add some…

---

## [Connection Reset to Logstash](https://discuss.elastic.co/t/connection-reset-to-logstash/337242)

<div class="topic-metadata">

**Author:** [@wwalker](https://discuss.elastic.co/u/wwalker)\
**Replies:** 2\
**Last updated:** [June 30, 2023, 7:23pm UTC](https://discuss.elastic.co/t/connection-reset-to-logstash/337242 "2023-06-30T19:23:01Z")

</div>

Trying to send Metricbeat to Logstash. Metricbeat logs don't throw any errors, but Logstash shows the following: \[2023-06-29T15:30:02,110\]\[INFO \]\[org.logstash.beats.BeatsHandler\] \[local: 192.168.1.78:5045, remote: 192.…

---

## [Create snapshot API not working](https://discuss.elastic.co/t/create-snapshot-api-not-working/337244)

<div class="topic-metadata">

**Author:** [@Mike\_Z](https://discuss.elastic.co/u/Mike_Z)\
**Replies:** 2\
**Last updated:** [June 30, 2023, 6:29pm UTC](https://discuss.elastic.co/t/create-snapshot-api-not-working/337244 "2023-06-30T18:29:42Z")

</div>

We are new to the snapshot-and-restore function of Elasticsearch. Following the example below, we are trying to create a snapshot repository with the Console of Dev Tools. The Elasticsearch server under test runs as a D…

---

## [How to refer to the whole modified event inside http output plugin](https://discuss.elastic.co/t/how-to-refer-to-the-whole-modified-event-inside-http-output-plugin/337232)

<div class="topic-metadata">

**Author:** [@ld\_pvl](https://discuss.elastic.co/u/ld_pvl)\
**Replies:** 2\
**Last updated:** [June 30, 2023, 6:23pm UTC](https://discuss.elastic.co/t/how-to-refer-to-the-whole-modified-event-inside-http-output-plugin/337232 "2023-06-30T18:23:38Z")

</div>

I am trying to map my http payload and put the whole Logstash event inside another json key/field: http { format =\> "json" http\_method =\> "post" url =\> "some url" headers =\> \["some header"\] ma…

---

## [Getting latest data per user\_id in time series data without latest transforms?](https://discuss.elastic.co/t/getting-latest-data-per-user-id-in-time-series-data-without-latest-transforms/337329)

<div class="topic-metadata">

**Author:** [@MaterializedView](https://discuss.elastic.co/u/MaterializedView)\
**Replies:** 2\
**Last updated:** [June 30, 2023, 6:21pm UTC](https://discuss.elastic.co/t/getting-latest-data-per-user-id-in-time-series-data-without-latest-transforms/337329 "2023-06-30T18:21:00Z")

</div>

I have a users index. Users have various status "New", "Waiting", "Completed". A status can go from "Completed" to "New" again. So in time series it would look something like user\_id, status, timestamp 1 NEW…

---

## [Change destination datastream with Elasticsearch ingest pipeline](https://discuss.elastic.co/t/change-destination-datastream-with-elasticsearch-ingest-pipeline/336912)

<div class="topic-metadata">

**Author:** [@i.raisr](https://discuss.elastic.co/u/i.raisr)\
**Replies:** 10\
**Last updated:** [June 30, 2023, 6:11pm UTC](https://discuss.elastic.co/t/change-destination-datastream-with-elasticsearch-ingest-pipeline/336912 "2023-06-30T18:11:51Z")

</div>

We run Elastic stack in docker containers. The container logs are collected with Elastic Agent, using docker integration and datastreams. This means that the logs of elasticsearch container itself by default end up in l…

---

## [Elasticsearch 8.8 dynamic search request query](https://discuss.elastic.co/t/elasticsearch-8-8-dynamic-search-request-query/336994)

<div class="topic-metadata">

**Author:** [@tcpeiris](https://discuss.elastic.co/u/tcpeiris)\
**Replies:** 2\
**Last updated:** [June 30, 2023, 5:42pm UTC](https://discuss.elastic.co/t/elasticsearch-8-8-dynamic-search-request-query/336994 "2023-06-30T17:42:55Z")

</div>

SearchResponse\<ObjectNode\> searchResponse = elasticsearchClient.search(req -\> req.index(index) .from((pageNumber - 1) \* pageSize) .size(pageSize) …

---

## [Force Logstash Finish on Error](https://discuss.elastic.co/t/force-logstash-finish-on-error/337331)

<div class="topic-metadata">

**Author:** [@palomasun](https://discuss.elastic.co/u/palomasun)\
**Replies:** 2\
**Last updated:** [June 30, 2023, 5:03pm UTC](https://discuss.elastic.co/t/force-logstash-finish-on-error/337331 "2023-06-30T17:03:07Z")

</div>

Hi, I use logstash 7.12.1 and I would like to avoid, in case of any error, a ethernal loop: For instance, if my configuration file doesn´t have a certification path it , loops: "unreacheble elastic... " Is there a way…

---

## [Elasticsearch-PHP \[8.8\] - Search for field in date-range, Client Helpers SearchResponseIterator & SearchHitIterator](https://discuss.elastic.co/t/elasticsearch-php-8-8-search-for-field-in-date-range-client-helpers-searchresponseiterator-searchhititerator/337237)

<div class="topic-metadata">

**Author:** [@DavidDPD](https://discuss.elastic.co/u/DavidDPD)\
**Replies:** 1\
**Last updated:** [June 30, 2023, 4:41pm UTC](https://discuss.elastic.co/t/elasticsearch-php-8-8-search-for-field-in-date-range-client-helpers-searchresponseiterator-searchhititerator/337237 "2023-06-30T16:41:08Z")

</div>

The poor documentation of Elasticsearch continues to hamper expanding my usage, and even poorer vagueness in the PHP API documentation. This seems like a simple example. Search for field (it is a tag field, it can have…

---

## [Configure elastic-apm-node](https://discuss.elastic.co/t/configure-elastic-apm-node/337272)

<div class="topic-metadata">

**Author:** [@Supun\_Madushanka](https://discuss.elastic.co/u/Supun_Madushanka)\
**Replies:** 1\
**Last updated:** [June 30, 2023, 3:25pm UTC](https://discuss.elastic.co/t/configure-elastic-apm-node/337272 "2023-06-30T15:25:31Z")

</div>

elastic cloud latest version const config = require('./config'); const apm = require('elastic-apm-node').start({ serviceName: config.ELASTIC\_APM\_SERVICE\_NAME, secretToken: config.ELASTIC\_APM\_SERVICE\_SECRET, …

---

## [Logstash duplication](https://discuss.elastic.co/t/logstash-duplication/335847)

<div class="topic-metadata">

**Author:** [@ramiwashere](https://discuss.elastic.co/u/ramiwashere)\
**Replies:** 2\
**Last updated:** [June 30, 2023, 3:06pm UTC](https://discuss.elastic.co/t/logstash-duplication/335847 "2023-06-30T15:06:12Z")

</div>

Hello I have created a logstash pipeline via the http\_poller plugin in order to collect information from an API link. In order to manage the duplication of documents, I used the 'fingerprint' plugin in the filter part …

---

## [Filebeat - elasticsearch output without pipeline management](https://discuss.elastic.co/t/filebeat-elasticsearch-output-without-pipeline-management/337322)

<div class="topic-metadata">

**Author:** [@anon68795679](https://discuss.elastic.co/u/anon68795679)\
**Replies:** 0\
**Last updated:** [June 30, 2023, 2:30pm UTC](https://discuss.elastic.co/t/filebeat-elasticsearch-output-without-pipeline-management/337322 "2023-06-30T14:30:32Z")

</div>

Hi, we want to deliver PostgresSQL logs with the filebeat postgres module to an elasticsearch output. But the filebeat shouldn't manage anything in the elasticsearch. ILM, template and ingest pipelines are managed by o…

---

## [SQS Input Plugin retries](https://discuss.elastic.co/t/sqs-input-plugin-retries/337321)

<div class="topic-metadata">

**Author:** [@fine\_porcupine](https://discuss.elastic.co/u/fine_porcupine)\
**Replies:** 0\
**Last updated:** [June 30, 2023, 2:27pm UTC](https://discuss.elastic.co/t/sqs-input-plugin-retries/337321 "2023-06-30T14:27:44Z")

</div>

I have a Logstash pipeline that receives events from an AWS SQS queue via the SQS Input Plugin. If there is a failure during data processing, will SQS retry the event, or do I need a Logstash DLQ to handle intermittent f…

---

## [Fleet Server 8.8.1 on prems boot issue](https://discuss.elastic.co/t/fleet-server-8-8-1-on-prems-boot-issue/337312)

<div class="topic-metadata">

**Author:** [@johnjohnsp1](https://discuss.elastic.co/u/johnjohnsp1)\
**Replies:** 3\
**Last updated:** [June 30, 2023, 2:08pm UTC](https://discuss.elastic.co/t/fleet-server-8-8-1-on-prems-boot-issue/337312 "2023-06-30T14:08:46Z")

</div>

Hi, i have deployed on prems elasticsearch,kibana and fleet (version 8) on a Centos 8 distro, now every time i boot up the server i see the fleet service is up and running, but, once i go to the fleet sheet i see the ag…

---

## [Strange error with empty delimiter in dissect processor in filebeat](https://discuss.elastic.co/t/strange-error-with-empty-delimiter-in-dissect-processor-in-filebeat/337304)

<div class="topic-metadata">

**Author:** [@calipee](https://discuss.elastic.co/u/calipee)\
**Replies:** 3\
**Last updated:** [June 30, 2023, 1:57pm UTC](https://discuss.elastic.co/t/strange-error-with-empty-delimiter-in-dissect-processor-in-filebeat/337304 "2023-06-30T13:57:55Z")

</div>

I'm trying to dissect the log message and pattern shown in the following error. I validated my input using an dissect-tester by jorgelbg where it works without any issues. I think its especially strange that the delimi…

---

## [Unable to run a benchmark on a 3 node Elastic-Search Cluster](https://discuss.elastic.co/t/unable-to-run-a-benchmark-on-a-3-node-elastic-search-cluster/337120)

<div class="topic-metadata">

**Author:** [@Kavya2708](https://discuss.elastic.co/u/Kavya2708)\
**Replies:** 2\
**Last updated:** [June 30, 2023, 1:39pm UTC](https://discuss.elastic.co/t/unable-to-run-a-benchmark-on-a-3-node-elastic-search-cluster/337120 "2023-06-30T13:39:59Z")

</div>

When running a race on a 3 node Elasticsearch cluster we are getting the following error. We were able to run a benchmark on a single node cluster. The single node had a document count of 3,556,667 , whereas the 3 node …

---

## [Is SIEM still free as Elastic Security? I cant seem to find the download for it. Anyone?](https://discuss.elastic.co/t/is-siem-still-free-as-elastic-security-i-cant-seem-to-find-the-download-for-it-anyone/337112)

<div class="topic-metadata">

**Author:** [@gabe-elastic](https://discuss.elastic.co/u/gabe-elastic)\
**Replies:** 6\
**Last updated:** [June 30, 2023, 1:39pm UTC](https://discuss.elastic.co/t/is-siem-still-free-as-elastic-security-i-cant-seem-to-find-the-download-for-it-anyone/337112 "2023-06-30T13:39:52Z")

</div>

Is SIEM still free as Elastic Security? I cant seem to find the download for it. Anyone?

---

## [Elasticsearch index migration](https://discuss.elastic.co/t/elasticsearch-index-migration/337314)

<div class="topic-metadata">

**Author:** [@zaeemmasood](https://discuss.elastic.co/u/zaeemmasood)\
**Replies:** 4\
**Last updated:** [June 30, 2023, 1:23pm UTC](https://discuss.elastic.co/t/elasticsearch-index-migration/337314 "2023-06-30T13:23:28Z")

</div>

Hello. We are in the process of migrating from elasticsearch 7.6.2 to version 8.7.0 In our present set up the indices are stored on local disk of all nodes in the cluster and we do not have a shared storage (NAS). Is t…

---

## [Roles N/A in stack monitoring](https://discuss.elastic.co/t/roles-n-a-in-stack-monitoring/337251)

<div class="topic-metadata">

**Author:** [@UP\_NEWS](https://discuss.elastic.co/u/UP_NEWS)\
**Replies:** 7\
**Last updated:** [June 30, 2023, 1:15pm UTC](https://discuss.elastic.co/t/roles-n-a-in-stack-monitoring/337251 "2023-06-30T13:15:38Z")

</div>

Hi team, how can i resolve this problem the roles is showing N/A in stack monitoring i'm alreay specified the node.roles in elasticsearch.yml Thanks in advance

---

## [Metricbeat installed machine is not showing in kibana monitor](https://discuss.elastic.co/t/metricbeat-installed-machine-is-not-showing-in-kibana-monitor/336661)

<div class="topic-metadata">

**Author:** [@Nitin08bisht](https://discuss.elastic.co/u/Nitin08bisht)\
**Replies:** 2\
**Last updated:** [June 30, 2023, 12:55pm UTC](https://discuss.elastic.co/t/metricbeat-installed-machine-is-not-showing-in-kibana-monitor/336661 "2023-06-30T12:55:22Z")

</div>

Hi I have configured metricbeat in AWS machine and metricbeat service showing in running state but when I have checked on kibana machine is not showing on uptime monitor. And also you can see in below screenshot metricb…

---

## [Reindex data stream](https://discuss.elastic.co/t/reindex-data-stream/337305)

<div class="topic-metadata">

**Author:** [@VirusProtect](https://discuss.elastic.co/u/VirusProtect)\
**Replies:** 1\
**Last updated:** [June 30, 2023, 12:34pm UTC](https://discuss.elastic.co/t/reindex-data-stream/337305 "2023-06-30T12:34:56Z")

</div>

Hello, There is conflicts with fields in the data stream backing indices. I would like to know the correct way to resolve this issue. While reindexing data is possible with regular indexes, I am unsure how to proceed wi…

---

## [ECK Metricbeat running as deamonset not showind data for field/value metricset.name : "process"](https://discuss.elastic.co/t/eck-metricbeat-running-as-deamonset-not-showind-data-for-field-value-metricset-name-process/336282)

<div class="topic-metadata">

**Author:** [@Carlos\_T](https://discuss.elastic.co/u/Carlos_T)\
**Replies:** 7\
**Last updated:** [June 30, 2023, 12:24pm UTC](https://discuss.elastic.co/t/eck-metricbeat-running-as-deamonset-not-showind-data-for-field-value-metricset-name-process/336282 "2023-06-30T12:24:39Z")

</div>

Hi all I've install a ECK cluster in a 5 workers nodes K8s. In the deployment I used a Metricbeat runs as DaemonSet for each worker node. The problem Im having is that I'm not getting any document with information …

---

## [Kibana Fleet high CPU Load on Elasticsearch when adding Integrations](https://discuss.elastic.co/t/kibana-fleet-high-cpu-load-on-elasticsearch-when-adding-integrations/336729)

<div class="topic-metadata">

**Author:** [@matled](https://discuss.elastic.co/u/matled)\
**Replies:** 10\
**Last updated:** [June 30, 2023, 11:29am UTC](https://discuss.elastic.co/t/kibana-fleet-high-cpu-load-on-elasticsearch-when-adding-integrations/336729 "2023-06-30T11:29:55Z")

</div>

Since Elastic-Stack 8.8.0 we observe an issue that is reproducible when navigating fleet and especially modifying integrations where the Elastic-Stack Cluster stalls out due to high CPU. In the following screenshot I've …

---

## [Cannot upgrade node because incompatible indices created with version \[6.2.3\] exist](https://discuss.elastic.co/t/cannot-upgrade-node-because-incompatible-indices-created-with-version-6-2-3-exist/337293)

<div class="topic-metadata">

**Author:** [@Achyut\_Muley](https://discuss.elastic.co/u/Achyut_Muley)\
**Replies:** 2\
**Last updated:** [June 30, 2023, 10:52am UTC](https://discuss.elastic.co/t/cannot-upgrade-node-because-incompatible-indices-created-with-version-6-2-3-exist/337293 "2023-06-30T10:52:28Z")

</div>

I recently started using 8.5.3 version of Elasticsearch.I have some indices that were created in two earlier versions i.e. 7.17.0 and 6.2.3 Now when i while starting Elasticsearch for the version 8.5.3 i am getting the …

---

## [Elasticsearch query with multiple fuzziness and weights](https://discuss.elastic.co/t/elasticsearch-query-with-multiple-fuzziness-and-weights/336948)

<div class="topic-metadata">

**Author:** [@alex.shmukler](https://discuss.elastic.co/u/alex.shmukler)\
**Replies:** 2\
**Last updated:** [June 30, 2023, 10:22am UTC](https://discuss.elastic.co/t/elasticsearch-query-with-multiple-fuzziness-and-weights/336948 "2023-06-30T10:22:18Z")

</div>

Hey Guys, I need to write query that will combine simple match and fuzziness together on different fields. At the beginning I need to normalize each field to characters and numbers only. Each field will have a differ…

---

## [Embedding Kibana dashboard in a React web app](https://discuss.elastic.co/t/embedding-kibana-dashboard-in-a-react-web-app/336672)

<div class="topic-metadata">

**Author:** [@Radhika\_Praveen](https://discuss.elastic.co/u/Radhika_Praveen)\
**Replies:** 2\
**Last updated:** [June 30, 2023, 10:16am UTC](https://discuss.elastic.co/t/embedding-kibana-dashboard-in-a-react-web-app/336672 "2023-06-30T10:16:59Z")

</div>

Hello, My team has been exploring on the options to embed Kibana dashboard into a React web app. After some exploration we have found the below options: iFrame is one way. But we dont want to use iFrame due to securit…

---

## [Replace Null to 0 if no records found in Visualisation](https://discuss.elastic.co/t/replace-null-to-0-if-no-records-found-in-visualisation/336989)

<div class="topic-metadata">

**Author:** [@bandodkarD](https://discuss.elastic.co/u/bandodkarD)\
**Replies:** 8\
**Last updated:** [June 30, 2023, 10:09am UTC](https://discuss.elastic.co/t/replace-null-to-0-if-no-records-found-in-visualisation/336989 "2023-06-30T10:09:28Z")

</div>

We have this visualisation created. We want the CSV download to show the value as 0 not "null" for filters with no records. Is this possible ?

---

## [Auditbeat process.args shortened](https://discuss.elastic.co/t/auditbeat-process-args-shortened/337298)

<div class="topic-metadata">

**Author:** [@radovan](https://discuss.elastic.co/u/radovan)\
**Replies:** 0\
**Last updated:** [June 30, 2023, 10:02am UTC](https://discuss.elastic.co/t/auditbeat-process-args-shortened/337298 "2023-06-30T10:02:49Z")

</div>

Hi, I noticed some time ago, that sometimes process.args get shortened in a way that 3 dots are put there instead of more arguments from the commandline so it looks like this: (this is from socket event.dataset, arg…

[Previous page](https://discuss.elastic.co/latest.md?page=620)

[Next page](https://discuss.elastic.co/latest.md?page=622)
