# Latest

**URL:** https://discuss.elastic.co/latest.md?page=628

[Latest](https://discuss.elastic.co/latest.md) · [Categories](https://discuss.elastic.co/categories.md) · [Tags](https://discuss.elastic.co/tags.md)

**Page:** 629

---

## [Format field as Time in Color scripted field](https://discuss.elastic.co/t/format-field-as-time-in-color-scripted-field/336799)

<div class="topic-metadata">

**Author:** [@kimari](https://discuss.elastic.co/u/kimari)\
**Replies:** 1\
**Last updated:** [June 26, 2023, 6:15am UTC](https://discuss.elastic.co/t/format-field-as-time-in-color-scripted-field/336799 "2023-06-26T06:15:04Z")

</div>

I have a scripted field that I need to use the color scripted for more than 13 minutes, but this field comes in seconds I want to use the format in 00:00:00 as well, since if i use the color format, I cannot use the numb…

---

## [Where do integer document IDs in highlighting error messages come from?](https://discuss.elastic.co/t/where-do-integer-document-ids-in-highlighting-error-messages-come-from/336602)

<div class="topic-metadata">

**Author:** [@nkleinbaer](https://discuss.elastic.co/u/nkleinbaer)\
**Replies:** 1\
**Last updated:** [June 26, 2023, 5:58am UTC](https://discuss.elastic.co/t/where-do-integer-document-ids-in-highlighting-error-messages-come-from/336602 "2023-06-26T05:58:14Z")

</div>

Sometimes when searching in Kibana I will get a pop up about failed shards. Inspecting the response shows errors like this one: The length of \[message\] field of \[32\] doc of \[my-index\] index has exceeded \[1000000\] - maxi…

---

## [How to show and Export data along with simple date formate (MM-dd-YYYY HH:mm)](https://discuss.elastic.co/t/how-to-show-and-export-data-along-with-simple-date-formate-mm-dd-yyyy-hh-mm/336537)

<div class="topic-metadata">

**Author:** [@PappuSingh](https://discuss.elastic.co/u/PappuSingh)\
**Replies:** 2\
**Last updated:** [June 26, 2023, 5:46am UTC](https://discuss.elastic.co/t/how-to-show-and-export-data-along-with-simple-date-formate-mm-dd-yyyy-hh-mm/336537 "2023-06-26T05:46:41Z")

</div>

Hi , How we can export the data with a simple date format currently it exporting with this format (Jun 19, 2023 @ 14:32:50.894) but we need this format (06-19-2023 14:32) please see the below snap for your reference. …

---

## [New Document Indexing Performance Troubleshooting](https://discuss.elastic.co/t/new-document-indexing-performance-troubleshooting/336854)

<div class="topic-metadata">

**Author:** [@mfalkenstein](https://discuss.elastic.co/u/mfalkenstein)\
**Replies:** 1\
**Last updated:** [June 26, 2023, 4:43am UTC](https://discuss.elastic.co/t/new-document-indexing-performance-troubleshooting/336854 "2023-06-26T04:43:11Z")

</div>

So I've been trying to troubleshoot an issue with my Elasticsearch currently being used a production system. Our servers are hosted in AWS and the specs of each node are Standard D16s v3 (16 vcpus, 64 GiB memory, 1.5TB o…

---

## [Upgrade failed to 8.x](https://discuss.elastic.co/t/upgrade-failed-to-8-x/336665)

<div class="topic-metadata">

**Author:** [@Chel](https://discuss.elastic.co/u/Chel)\
**Replies:** 6\
**Last updated:** [June 26, 2023, 4:35am UTC](https://discuss.elastic.co/t/upgrade-failed-to-8-x/336665 "2023-06-26T04:35:16Z")

</div>

Error message: Upgrading the 7.17.4 ES version to 8.5.2 ES cluster getting the below message. We have checked the deprecation messages and upgrade assistant and nothing was reported. java.lang.IllegalStateException: ca…

---

## [Can I specify the index in a query search?](https://discuss.elastic.co/t/can-i-specify-the-index-in-a-query-search/336218)

<div class="topic-metadata">

**Author:** [@stephane\_chan](https://discuss.elastic.co/u/stephane_chan)\
**Replies:** 1\
**Last updated:** [June 26, 2023, 3:46am UTC](https://discuss.elastic.co/t/can-i-specify-the-index-in-a-query-search/336218 "2023-06-26T03:46:51Z")

</div>

I need to search multiple indexes on Elasticsearch, My problem is that on each index I have the same field name (is\_active), how do I specify that it's the field of the other index ? GET index-1,index-2/\_search { "que…

---

## [How to set up a cluster?](https://discuss.elastic.co/t/how-to-set-up-a-cluster/336790)

<div class="topic-metadata">

**Author:** [@TomTom](https://discuss.elastic.co/u/TomTom)\
**Replies:** 1\
**Last updated:** [June 26, 2023, 2:00am UTC](https://discuss.elastic.co/t/how-to-set-up-a-cluster/336790 "2023-06-26T02:00:18Z")

</div>

Does Elasticsearch have any step-by-step tutorials on how to set up a 3-node cluster? I've seen the following docs \[1, 2\], but they are just concepts, they don't show which files to edit and which commands to run.

---

## [Encountered logstash error "Expected one of \[ \\\\t\\\\r\\\\n\], \\"#\\", \\"input\\", \\"filter\\", \\"output\\" at line 1, column 1 (byte 1)""](https://discuss.elastic.co/t/encountered-logstash-error-expected-one-of-t-r-n-input-filter-output-at-line-1-column-1-byte-1/336796)

<div class="topic-metadata">

**Author:** [@pdowma](https://discuss.elastic.co/u/pdowma)\
**Replies:** 1\
**Last updated:** [June 26, 2023, 1:40am UTC](https://discuss.elastic.co/t/encountered-logstash-error-expected-one-of-t-r-n-input-filter-output-at-line-1-column-1-byte-1/336796 "2023-06-26T01:40:23Z")

</div>

Problem: When setting up a Docker-based Elastic Stack (Elasticsearch, Logstash, and Kibana) environment. The Logstash service was not able to start correctly and reported the following error message: \[2023-06-23T16:41:…

---

## [Trouble adding a new Kibana instance to an existing Elasticsearch Cluster](https://discuss.elastic.co/t/trouble-adding-a-new-kibana-instance-to-an-existing-elasticsearch-cluster/336695)

<div class="topic-metadata">

**Author:** [@viera120](https://discuss.elastic.co/u/viera120)\
**Replies:** 2\
**Last updated:** [June 26, 2023, 1:36am UTC](https://discuss.elastic.co/t/trouble-adding-a-new-kibana-instance-to-an-existing-elasticsearch-cluster/336695 "2023-06-26T01:36:56Z")

</div>

We are running a 3 Node ES Cluster with basic security (inter-node TLS) enabled. We installed Kibana on one of the Nodes initially and are now trying to install it on a second node in the cluster. The /etc/kibana/kibana…

---

## [Is it possible to keep max 5GB for logs but to delete old continously?](https://discuss.elastic.co/t/is-it-possible-to-keep-max-5gb-for-logs-but-to-delete-old-continously/336832)

<div class="topic-metadata">

**Author:** [@HannesWaser](https://discuss.elastic.co/u/HannesWaser)\
**Replies:** 1\
**Last updated:** [June 26, 2023, 12:22am UTC](https://discuss.elastic.co/t/is-it-possible-to-keep-max-5gb-for-logs-but-to-delete-old-continously/336832 "2023-06-26T00:22:14Z")

</div>

Dear all, I am a novice to Kibana. I made it run bit now I wonder how I can limit the storage kibana and elasticseach use for log data AND how I can delete old logs automatically so new ones can be added. The goal is to …

---

## [Precision tuning uses low-level and disables fuzzy queries](https://discuss.elastic.co/t/precision-tuning-uses-low-level-and-disables-fuzzy-queries/336416)

<div class="topic-metadata">

**Author:** [@ZE\_Share](https://discuss.elastic.co/u/ZE_Share)\
**Replies:** 2\
**Last updated:** [June 26, 2023, 12:09am UTC](https://discuss.elastic.co/t/precision-tuning-uses-low-level-and-disables-fuzzy-queries/336416 "2023-06-26T00:09:24Z")

</div>

Now we have difficulty querying here. I want to adjust precision-tuning to a low level (less than 8), and I don't want it to use Fuzzy queries. I also don't find a parameter like fuzziness to control it. Is there any …

---

## [Manual refresh does not seem to take effect instantly](https://discuss.elastic.co/t/manual-refresh-does-not-seem-to-take-effect-instantly/336850)

<div class="topic-metadata">

**Author:** [@sbruinsje](https://discuss.elastic.co/u/sbruinsje)\
**Replies:** 0\
**Last updated:** [June 25, 2023, 10:07pm UTC](https://discuss.elastic.co/t/manual-refresh-does-not-seem-to-take-effect-instantly/336850 "2023-06-25T22:07:38Z")

</div>

I have alot of unit tests that use an actual instance of elasticsearch. Currently between every test the index is deleted and recreated like this: await client.indices.delete({ index }); await client.indices.create({ in…

---

## [Changing ES Scheme to http](https://discuss.elastic.co/t/changing-es-scheme-to-http/336839)

<div class="topic-metadata">

**Author:** [@Geek2.0](https://discuss.elastic.co/u/Geek2.0)\
**Replies:** 1\
**Last updated:** [June 25, 2023, 8:24pm UTC](https://discuss.elastic.co/t/changing-es-scheme-to-http/336839 "2023-06-25T20:24:20Z")

</div>

Hi Community, I am working on Arches project which uses Elasticsearch as its search engine. In Arches Documentation, it is mentioned to add the following line to the settings.py in my project's directory: ELASTICSEARC…

---

## [Is it possible to create a dynamic table name in statement of jdbc input plugin in Logstash?](https://discuss.elastic.co/t/is-it-possible-to-create-a-dynamic-table-name-in-statement-of-jdbc-input-plugin-in-logstash/336846)

<div class="topic-metadata">

**Author:** [@rabih](https://discuss.elastic.co/u/rabih)\
**Replies:** 1\
**Last updated:** [June 25, 2023, 7:51pm UTC](https://discuss.elastic.co/t/is-it-possible-to-create-a-dynamic-table-name-in-statement-of-jdbc-input-plugin-in-logstash/336846 "2023-06-25T19:51:18Z")

</div>

input { jdbc { jdbc\_connection\_string =\> "jdbc:sqlserver://ip\_address:1433;databaseName=database\_name;encrypt=true;trustServerCertificate=true;" jdbc\_user =\> "userxxxx" jdbc\_password =\> "passxxxx" jdbc\_…

---

## [Filebeat exclude\_files is not working as expected for windows](https://discuss.elastic.co/t/filebeat-exclude-files-is-not-working-as-expected-for-windows/336829)

<div class="topic-metadata">

**Author:** [@junly](https://discuss.elastic.co/u/junly)\
**Replies:** 1\
**Last updated:** [June 25, 2023, 5:19pm UTC](https://discuss.elastic.co/t/filebeat-exclude-files-is-not-working-as-expected-for-windows/336829 "2023-06-25T17:19:28Z")

</div>

Elastic Filebeat 8.7.0 file path "d:\\log\\LuceneSOA\\排序搜索结果\\2023-06-21.txt", Exclude txt files dated under the file but not working the regexp was verified with regex101.com filebeat.yml input filebeat.inputs: -…

---

## [Filestream input sends duplicates events on restart and during operation](https://discuss.elastic.co/t/filestream-input-sends-duplicates-events-on-restart-and-during-operation/334951)

<div class="topic-metadata">

**Author:** [@michaelbu](https://discuss.elastic.co/u/michaelbu)\
**Replies:** 33\
**Last updated:** [June 25, 2023, 4:22pm UTC](https://discuss.elastic.co/t/filestream-input-sends-duplicates-events-on-restart-and-during-operation/334951 "2023-06-25T16:22:10Z")

</div>

We use more than 1.800 filebeats with the filestream-input in version: $ filebeat version filebeat version 8.7.0 (amd64), libbeat 8.7.0 \[a8dbc6c06381f4fe33a5dc23906d63c04c9e2444 built 2023-03-23 00:37:07 +0000 UTC\] Ro…

---

## [Auditbeat. failed to set audit PID - audiebeat complaining about itself](https://discuss.elastic.co/t/auditbeat-failed-to-set-audit-pid-audiebeat-complaining-about-itself/336841)

<div class="topic-metadata">

**Author:** [@JohnAnderson](https://discuss.elastic.co/u/JohnAnderson)\
**Replies:** 0\
**Last updated:** [June 25, 2023, 4:19pm UTC](https://discuss.elastic.co/t/auditbeat-failed-to-set-audit-pid-audiebeat-complaining-about-itself/336841 "2023-06-25T16:19:43Z")

</div>

Hi everyone! I have got no ideas where to find problem in next situation. When I start/restart container with auditd option socket\_type: unicast, I can see in logs "message":"Failure receiving audit events","service.nam…

---

## [Aproximate Nearest Neighbours python with leastic 8.8](https://discuss.elastic.co/t/aproximate-nearest-neighbours-python-with-leastic-8-8/336692)

<div class="topic-metadata">

**Author:** [@Ran\_Dubin](https://discuss.elastic.co/u/Ran_Dubin)\
**Replies:** 2\
**Last updated:** [June 25, 2023, 1:58pm UTC](https://discuss.elastic.co/t/aproximate-nearest-neighbours-python-with-leastic-8-8/336692 "2023-06-25T13:58:29Z")

</div>

Hello All I am using elastic version 8.8.1. The API for ANN has changed and I managed to index but not to query content. Index: from datetime import datetime b\_index = 'shot\_index' dim = 1280 response = es.indice…

---

## [Can we use sub aggregation after top metric aggregation](https://discuss.elastic.co/t/can-we-use-sub-aggregation-after-top-metric-aggregation/330957)

<div class="topic-metadata">

**Author:** [@Fiza](https://discuss.elastic.co/u/Fiza)\
**Replies:** 7\
**Last updated:** [May 3, 2023, 8:53am UTC](https://discuss.elastic.co/t/can-we-use-sub-aggregation-after-top-metric-aggregation/330957 "2023-05-03T08:53:41Z")

</div>

I want to get sum of latest value of a field . With several conditions which is applied over other fields. I am working on time series data and want to get information from last poled value. Example Data:- A B C …

---

## [Show discover result in dashboard](https://discuss.elastic.co/t/show-discover-result-in-dashboard/336826)

<div class="topic-metadata">

**Author:** [@Indeed2000](https://discuss.elastic.co/u/Indeed2000)\
**Replies:** 1\
**Last updated:** [June 25, 2023, 7:05am UTC](https://discuss.elastic.co/t/show-discover-result-in-dashboard/336826 "2023-06-25T07:05:23Z")

</div>

Hi Need to put discovery search on dashboard. how can i do this? the main issue is I've create table on dashboard that show top apm span by duration. as far as i know i can't add column that show this field "span.db.st…

---

## [How to connect eck elasticsearch with eck logstash](https://discuss.elastic.co/t/how-to-connect-eck-elasticsearch-with-eck-logstash/336804)

<div class="topic-metadata">

**Author:** [@Piyumitha\_Nirman](https://discuss.elastic.co/u/Piyumitha_Nirman)\
**Replies:** 3\
**Last updated:** [June 25, 2023, 6:40am UTC](https://discuss.elastic.co/t/how-to-connect-eck-elasticsearch-with-eck-logstash/336804 "2023-06-25T06:40:33Z")

</div>

eck logtash 8 version needs ca.crt of eck Elasticsearch. But i dont know how to access this ca.crt file using logstash. my log stash file has cacert location. but I don't know how to access ca.crt file. hosts =\> …

---

## [How to extract string from the log and create a new field and send to elastic search index](https://discuss.elastic.co/t/how-to-extract-string-from-the-log-and-create-a-new-field-and-send-to-elastic-search-index/336797)

<div class="topic-metadata">

**Author:** [@mbsarathchandra](https://discuss.elastic.co/u/mbsarathchandra)\
**Replies:** 2\
**Last updated:** [June 25, 2023, 1:02am UTC](https://discuss.elastic.co/t/how-to-extract-string-from-the-log-and-create-a-new-field-and-send-to-elastic-search-index/336797 "2023-06-25T01:02:46Z")

</div>

Hello Everyone, I am currently using Elastic Search Version 8.8.1 installed on RHEL os. Filebeat Version: 8.6.1 The logs are read from the Application server and pushed to Elasticsearch index using filebeat. Data str…

---

## [The es java client version has been upgraded from 7 to 8, and the syntax has changed significantly](https://discuss.elastic.co/t/the-es-java-client-version-has-been-upgraded-from-7-to-8-and-the-syntax-has-changed-significantly/336809)

<div class="topic-metadata">

**Author:** [@nzb](https://discuss.elastic.co/u/nzb)\
**Replies:** 2\
**Last updated:** [June 25, 2023, 12:57am UTC](https://discuss.elastic.co/t/the-es-java-client-version-has-been-upgraded-from-7-to-8-and-the-syntax-has-changed-significantly/336809 "2023-06-25T00:57:51Z")

</div>

I recently upgraded the es java client version from 7.9.3 to 8.5.3. The syntax has changed significantly. We spent several days modifying the syntax to be compatible, and the regression test took several days. After two …

---

## [Mutate - add\_field - only shows string not the value](https://discuss.elastic.co/t/mutate-add-field-only-shows-string-not-the-value/336816)

<div class="topic-metadata">

**Author:** [@humblemags](https://discuss.elastic.co/u/humblemags)\
**Replies:** 2\
**Last updated:** [June 24, 2023, 8:37pm UTC](https://discuss.elastic.co/t/mutate-add-field-only-shows-string-not-the-value/336816 "2023-06-24T20:37:34Z")

</div>

Hi, I am using Windows 10 with 7.17.6 on localhost install. Filebeat is input being sent to Logstash. Yes, I know the json parser will handle this for me. But I do not understand why "someNewField" does not have the v…

---

## [Include/exclude specific fields](https://discuss.elastic.co/t/include-exclude-specific-fields/336817)

<div class="topic-metadata">

**Author:** [@Itay\_Bittan](https://discuss.elastic.co/u/Itay_Bittan)\
**Replies:** 0\
**Last updated:** [June 24, 2023, 4:28pm UTC](https://discuss.elastic.co/t/include-exclude-specific-fields/336817 "2023-06-24T16:28:39Z")

</div>

My index's documents looks like that: { "sku": "1234567890", "name": "my\_name", "lng:en\_AE:name": "my\_name\_in\_AE", "lng:en\_AE:price": 10.99, "lng:en\_BH:name": "my\_name\_in\_BH", …

---

## [Logstash date timezone](https://discuss.elastic.co/t/logstash-date-timezone/336803)

<div class="topic-metadata">

**Author:** [@Mahdi\_Davoodi](https://discuss.elastic.co/u/Mahdi_Davoodi)\
**Replies:** 6\
**Last updated:** [June 24, 2023, 3:00pm UTC](https://discuss.elastic.co/t/logstash-date-timezone/336803 "2023-06-24T15:00:14Z")

</div>

I want to parse date-time records with logstash date filter. My records have Asia/Tehran time zone. After the recent changes in the time zone in Iran and the removal of DST from it, apparently my date of records does no…

---

## [Multi field match with boosting and fuzziness](https://discuss.elastic.co/t/multi-field-match-with-boosting-and-fuzziness/336806)

<div class="topic-metadata">

**Author:** [@Tim6](https://discuss.elastic.co/u/Tim6)\
**Replies:** 2\
**Last updated:** [June 24, 2023, 2:56pm UTC](https://discuss.elastic.co/t/multi-field-match-with-boosting-and-fuzziness/336806 "2023-06-24T14:56:13Z")

</div>

Hi, Say I have a database of car models containing brand and model Brand Model Foo Bar Foo Baz So if I search for a Foo Bar I want only the first document to match. If I search for just Foo both documents …

---

## [Can we use ElasticSearch of 2.3 version?](https://discuss.elastic.co/t/can-we-use-elasticsearch-of-2-3-version/336556)

<div class="topic-metadata">

**Author:** [@sanjay\_bhati](https://discuss.elastic.co/u/sanjay_bhati)\
**Replies:** 3\
**Last updated:** [June 24, 2023, 1:56pm UTC](https://discuss.elastic.co/t/can-we-use-elasticsearch-of-2-3-version/336556 "2023-06-24T13:56:21Z")

</div>

Hi Team, I need help to understand, In ES plugin we need username and password but my Elasticsearch is old version so not able to get username and passsword so in this case how I can use ES as input plugin ?

---

## [ES sending multiple API query calls for a single query request for Dashboard](https://discuss.elastic.co/t/es-sending-multiple-api-query-calls-for-a-single-query-request-for-dashboard/336805)

<div class="topic-metadata">

**Author:** [@Sandeep\_Raju](https://discuss.elastic.co/u/Sandeep_Raju)\
**Replies:** 1\
**Last updated:** [June 24, 2023, 1:35pm UTC](https://discuss.elastic.co/t/es-sending-multiple-api-query-calls-for-a-single-query-request-for-dashboard/336805 "2023-06-24T13:35:19Z")

</div>

Hi all, I'm using Kibana & ES for building a dashboard. I have allotted 8GB of memory heap space for my ES which I feel is quite enough. One of my data tables has slightly high number of documents i.e 14,000 documents…

---

## [Named query in hybrid queries](https://discuss.elastic.co/t/named-query-in-hybrid-queries/336608)

<div class="topic-metadata">

**Author:** [@Ali\_Nazari](https://discuss.elastic.co/u/Ali_Nazari)\
**Replies:** 4\
**Last updated:** [June 24, 2023, 10:54am UTC](https://discuss.elastic.co/t/named-query-in-hybrid-queries/336608 "2023-06-24T10:54:06Z")

</div>

How can I recognize which of my elasticsearch hits are because of my KNN and which are related to the query part? I don't know where to use a named query in KNN part. GET post-vector/\_search { "query": { "bool": {…

[Previous page](https://discuss.elastic.co/latest.md?page=627)

[Next page](https://discuss.elastic.co/latest.md?page=629)
