# Latest

**URL:** https://discuss.elastic.co/latest.md?page=633

[Latest](https://discuss.elastic.co/latest.md) · [Categories](https://discuss.elastic.co/categories.md) · [Tags](https://discuss.elastic.co/tags.md)

**Page:** 634

---

## [How to clean all the identites from Sailpoint?](https://discuss.elastic.co/t/how-to-clean-all-the-identites-from-sailpoint/336146)

<div class="topic-metadata">

**Author:** [@srikanth\_bollu](https://discuss.elastic.co/u/srikanth_bollu)\
**Replies:** 1\
**Last updated:** [June 21, 2023, 7:41am UTC](https://discuss.elastic.co/t/how-to-clean-all-the-identites-from-sailpoint/336146 "2023-06-21T07:41:41Z")

</div>

I want to clean all the identities and their accounts roles etc associated with identities. Is there any way to bulk delete sailpoint?

---

## [Workflow - ServiceNow](https://discuss.elastic.co/t/workflow-servicenow/336535)

<div class="topic-metadata">

**Author:** [@srikanth\_bollu](https://discuss.elastic.co/u/srikanth_bollu)\
**Replies:** 1\
**Last updated:** [June 21, 2023, 7:40am UTC](https://discuss.elastic.co/t/workflow-servicenow/336535 "2023-06-21T07:40:44Z")

</div>

I'm new to ServiceNow and followed this tutorial Workflow for ServiceNow Incidents to create a simple workflow for an approval request. The steps that I took on studio of my developer instance: Created an application …

---

## [Rules and connectors](https://discuss.elastic.co/t/rules-and-connectors/336531)

<div class="topic-metadata">

**Author:** [@imaad](https://discuss.elastic.co/u/imaad)\
**Replies:** 0\
**Last updated:** [June 21, 2023, 6:01am UTC](https://discuss.elastic.co/t/rules-and-connectors/336531 "2023-06-21T06:01:56Z")

</div>

Hello, I want to create an Alert to monitor a specific pattern error every 4 hours which occurs in the message field. Could not connect to net.tcp: The connection attempt lasted for a time span of TCP error code 10061…

---

## [How to get Distinct results using Search API](https://discuss.elastic.co/t/how-to-get-distinct-results-using-search-api/336215)

<div class="topic-metadata">

**Author:** [@asimelastic](https://discuss.elastic.co/u/asimelastic)\
**Replies:** 4\
**Last updated:** [June 21, 2023, 7:38am UTC](https://discuss.elastic.co/t/how-to-get-distinct-results-using-search-api/336215 "2023-06-21T07:38:07Z")

</div>

I have a "customer" index with fields "FirstName" and "LastName". My index contains data as follows: First Name | LastName Richard | Lockwood Richard | Lockwood 2 Richard | Lockwood 3 Richard | Lockwood 4 Richard …

---

## [Issue with Custom Nginx Ingest Pipeline in Elasticsearch 8.7](https://discuss.elastic.co/t/issue-with-custom-nginx-ingest-pipeline-in-elasticsearch-8-7/336543)

<div class="topic-metadata">

**Author:** [@MIDHUN\_KRISHNA](https://discuss.elastic.co/u/MIDHUN_KRISHNA)\
**Replies:** 0\
**Last updated:** [June 21, 2023, 7:32am UTC](https://discuss.elastic.co/t/issue-with-custom-nginx-ingest-pipeline-in-elasticsearch-8-7/336543 "2023-06-21T07:32:57Z")

</div>

I'm currently facing an issue with Elasticsearch 8.7, specifically with the integration of Nginx logs and custom ingest pipelines. I have successfully installed Fleet Server with Elastic Agent, along with the Nginx integ…

---

## [API call to fetch kibana dashboard along with data in json format](https://discuss.elastic.co/t/api-call-to-fetch-kibana-dashboard-along-with-data-in-json-format/335940)

<div class="topic-metadata">

**Author:** [@Neelam\_Zanvar](https://discuss.elastic.co/u/Neelam_Zanvar)\
**Replies:** 2\
**Last updated:** [June 21, 2023, 7:15am UTC](https://discuss.elastic.co/t/api-call-to-fetch-kibana-dashboard-along-with-data-in-json-format/335940 "2023-06-21T07:15:17Z")

</div>

Hi, I am trying to generate the json file for kibana dashboard. I am trying this command but this gives me only the dashboard of the design. How can i get the data? curl -X GET 'http://demo.icebreaker.minutuscloud.com/…

---

## [Append a string to a field after mutate convert filter](https://discuss.elastic.co/t/append-a-string-to-a-field-after-mutate-convert-filter/336327)

<div class="topic-metadata">

**Author:** [@Neelam\_Zanvar](https://discuss.elastic.co/u/Neelam_Zanvar)\
**Replies:** 3\
**Last updated:** [June 21, 2023, 7:14am UTC](https://discuss.elastic.co/t/append-a-string-to-a-field-after-mutate-convert-filter/336327 "2023-06-21T07:14:11Z")

</div>

Hi I have the following log pattern \[19/Jun/2023:11:27:35 +0530\] | 503 | 1188 ms | 299 B | 172.31.40.179 | - | - | - | "GET /3dcomment/monitoring/healthcheck HTTP/1.1" I have applied grok to fetch the bytes field i.e 2…

---

## [Error in indexing polygon data in Elasticsearch 8.8](https://discuss.elastic.co/t/error-in-indexing-polygon-data-in-elasticsearch-8-8/335335)

<div class="topic-metadata">

**Author:** [@amal\_antony](https://discuss.elastic.co/u/amal_antony)\
**Replies:** 6\
**Last updated:** [June 21, 2023, 6:00am UTC](https://discuss.elastic.co/t/error-in-indexing-polygon-data-in-elasticsearch-8-8/335335 "2023-06-21T06:00:53Z")

</div>

Greetings to the community! I am experiencing issues while ingesting polygon data into Elasticsearch 8.8. An issue had been raised before in the same context, link. This was identified as a bug in Lucene, the fix for wh…

---

## [How we can calculate only Working days only Monday to Friday and skip Saturday and Sunday](https://discuss.elastic.co/t/how-we-can-calculate-only-working-days-only-monday-to-friday-and-skip-saturday-and-sunday/335731)

<div class="topic-metadata">

**Author:** [@PappuSingh](https://discuss.elastic.co/u/PappuSingh)\
**Replies:** 4\
**Last updated:** [June 21, 2023, 5:21am UTC](https://discuss.elastic.co/t/how-we-can-calculate-only-working-days-only-monday-to-friday-and-skip-saturday-and-sunday/335731 "2023-06-21T05:21:21Z")

</div>

How we can calculate only Working days only Monday to Friday and skip Saturday and Sunday

---

## [ELK upgrade to 7.17.10](https://discuss.elastic.co/t/elk-upgrade-to-7-17-10/336513)

<div class="topic-metadata">

**Author:** [@khadija70](https://discuss.elastic.co/u/khadija70)\
**Replies:** 2\
**Last updated:** [June 21, 2023, 5:11am UTC](https://discuss.elastic.co/t/elk-upgrade-to-7-17-10/336513 "2023-06-21T05:11:10Z")

</div>

Hi , We recentely upgraded the ELK cluster from the 7.15.1 to 7.17.10 in order to fix security vulnerabilities , however after upgrading we are still have the open JDK vulnerability on Elasticsearch servers : OpenJDK…

---

## [What is the FileBeats version that is compatible in Oracle Solaris 11.3?](https://discuss.elastic.co/t/what-is-the-filebeats-version-that-is-compatible-in-oracle-solaris-11-3/336466)

<div class="topic-metadata">

**Author:** [@kam89](https://discuss.elastic.co/u/kam89)\
**Replies:** 3\
**Last updated:** [June 21, 2023, 4:02am UTC](https://discuss.elastic.co/t/what-is-the-filebeats-version-that-is-compatible-in-oracle-solaris-11-3/336466 "2023-06-21T04:02:49Z")

</div>

Hi, Is there any FileBeats version that is compatible in Oracle Solaris 11.3? Thank you and Regards

---

## [Store Old Indices in S3 and load when needed in future?](https://discuss.elastic.co/t/store-old-indices-in-s3-and-load-when-needed-in-future/336503)

<div class="topic-metadata">

**Author:** [@datencio](https://discuss.elastic.co/u/datencio)\
**Replies:** 2\
**Last updated:** [June 21, 2023, 3:59am UTC](https://discuss.elastic.co/t/store-old-indices-in-s3-and-load-when-needed-in-future/336503 "2023-06-21T03:59:01Z")

</div>

We would like to store lots of old indices in S3 for easy storage and the ability to import the indice from S3 back into Elasticsearch when needed. I have installed the repository-s3 plugin, and I have seen how i can do …

---

## [Beats Native Grok Processor](https://discuss.elastic.co/t/beats-native-grok-processor/336521)

<div class="topic-metadata">

**Author:** [@james-mchugh](https://discuss.elastic.co/u/james-mchugh)\
**Replies:** 0\
**Last updated:** [June 21, 2023, 2:32am UTC](https://discuss.elastic.co/t/beats-native-grok-processor/336521 "2023-06-21T02:32:22Z")

</div>

Hello everyone. I am looking into adding a Grok processor to Beats/Filebeat as requested in \[Filebeat\] Add grok Processor as native beat/filebeat processor · Issue #30073 · elastic/beats · GitHub. Our team has already c…

---

## [Aggregate filter の timeout\_timestamp\_field設定時の動作について](https://discuss.elastic.co/t/aggregate-filter-timeout-timestamp-field/336283)

<div class="topic-metadata">

**Author:** [@e-se](https://discuss.elastic.co/u/e-se)\
**Replies:** 3\
**Last updated:** [June 20, 2023, 9:48pm UTC](https://discuss.elastic.co/t/aggregate-filter-timeout-timestamp-field/336283 "2023-06-20T21:48:19Z")

</div>

Aggregate filter pluginのオプションtimeout\_timestamp\_fieldについて、 機能追加の経緯やドキュメントの記載から設定すると、タイムアウトの判定がシステム時間からログのタイムスタンプに変わると思っていたが、実際に動かしてみると、システム時間で判定されたような挙動をした。 （私と同じ疑問を持った方が過去にいたよう。https://discuss.elastic.co/t/aggregate-fi…

---

## [Metricbeat GCP Billing metricset fails with timeout error](https://discuss.elastic.co/t/metricbeat-gcp-billing-metricset-fails-with-timeout-error/336516)

<div class="topic-metadata">

**Author:** [@Patr123](https://discuss.elastic.co/u/Patr123)\
**Replies:** 0\
**Last updated:** [June 20, 2023, 11:05pm UTC](https://discuss.elastic.co/t/metricbeat-gcp-billing-metricset-fails-with-timeout-error/336516 "2023-06-20T23:05:32Z")

</div>

I enabled the gcp module for metricbeat and used the billing metricset as: - module: gcp metricsets: - billing period: 24h project\_id: "project" credentials\_file\_path: "/etc/metricbeat/service-account.json" …

---

## [Monthly Index Usage](https://discuss.elastic.co/t/monthly-index-usage/336407)

<div class="topic-metadata">

**Author:** [@IsaacD](https://discuss.elastic.co/u/IsaacD)\
**Replies:** 2\
**Last updated:** [June 20, 2023, 10:40pm UTC](https://discuss.elastic.co/t/monthly-index-usage/336407 "2023-06-20T22:40:14Z")

</div>

We have multiple teams using our elasticsearch stack and need to find out how much usage each team uses. Is there a way to collect the monthly resource usage (CPU, Memory, storage) for a group of indexes without digging…

---

## [Limiting Response Data Using URI Based on Value of Search Term](https://discuss.elastic.co/t/limiting-response-data-using-uri-based-on-value-of-search-term/336507)

<div class="topic-metadata">

**Author:** [@Akaash\_Mukherjee](https://discuss.elastic.co/u/Akaash_Mukherjee)\
**Replies:** 0\
**Last updated:** [June 20, 2023, 7:51pm UTC](https://discuss.elastic.co/t/limiting-response-data-using-uri-based-on-value-of-search-term/336507 "2023-06-20T19:51:14Z")

</div>

I'm looking to filter out data in response objects based on the value of a search term. The request below for instance, filters the data within the objects themselves, excluding a particular field (attribute.betaalmethod…

---

## [Elasticsearch/Kibana - Discover not showing traffic - but logs show no errors Elasticsearch 7.17.10](https://discuss.elastic.co/t/elasticsearch-kibana-discover-not-showing-traffic-but-logs-show-no-errors-elasticsearch-7-17-10/336508)

<div class="topic-metadata">

**Author:** [@Bruceclegg](https://discuss.elastic.co/u/Bruceclegg)\
**Replies:** 0\
**Last updated:** [June 20, 2023, 7:56pm UTC](https://discuss.elastic.co/t/elasticsearch-kibana-discover-not-showing-traffic-but-logs-show-no-errors-elasticsearch-7-17-10/336508 "2023-06-20T19:56:13Z")

</div>

We use nginx as the front end to move traffic from incoming port 9200 to 9400. This has been working more or less fine. We needed to make a change so port 9200 could accept both http and https traffic. So I made the ch…

---

## [User can't view APM services in Kibana](https://discuss.elastic.co/t/user-cant-view-apm-services-in-kibana/336140)

<div class="topic-metadata">

**Author:** [@qd-danh](https://discuss.elastic.co/u/qd-danh)\
**Replies:** 3\
**Last updated:** [June 20, 2023, 5:57pm UTC](https://discuss.elastic.co/t/user-cant-view-apm-services-in-kibana/336140 "2023-06-20T17:57:34Z")

</div>

We are new to sending APM data from our services to elastic (using Serilog and .NET libraries). It seems to be working fine. I am admin and can see our sample service listed in APM, Services and then can drill down into …

---

## [Getting Nginx Logs From docker Container](https://discuss.elastic.co/t/getting-nginx-logs-from-docker-container/336457)

<div class="topic-metadata">

**Author:** [@ethical20](https://discuss.elastic.co/u/ethical20)\
**Replies:** 1\
**Last updated:** [June 20, 2023, 5:36pm UTC](https://discuss.elastic.co/t/getting-nginx-logs-from-docker-container/336457 "2023-06-20T17:36:40Z")

</div>

Hi All, Usually I used to to read Nginx Logs via the Nginx integration available, but now the nginx app is dockerised within a container. The docker integration available in integrations as i can see will not read the…

---

## [Data View, Canvas, and ESQL](https://discuss.elastic.co/t/data-view-canvas-and-esql/336474)

<div class="topic-metadata">

**Author:** [@witwit](https://discuss.elastic.co/u/witwit)\
**Replies:** 1\
**Last updated:** [June 20, 2023, 5:35pm UTC](https://discuss.elastic.co/t/data-view-canvas-and-esql/336474 "2023-06-20T17:35:48Z")

</div>

Hi, So i have an index which is created from a transform with group by on a field and aggregation using terms. This means that my resulting field is a flattened field of terms. Through this I can create Data View term…

---

## [Force brute vector query](https://discuss.elastic.co/t/force-brute-vector-query/336497)

<div class="topic-metadata">

**Author:** [@Lone\_Eagle](https://discuss.elastic.co/u/Lone_Eagle)\
**Replies:** 3\
**Last updated:** [June 20, 2023, 5:17pm UTC](https://discuss.elastic.co/t/force-brute-vector-query/336497 "2023-06-20T17:17:42Z")

</div>

We are currently having a normal search and want to experiment on vectors. We managed to have a normal knn search but want to create a search query using the brute force of a vector. The query receive a text to search on…

---

## [Publication of cluster state fails - followers check retry count exceeded](https://discuss.elastic.co/t/publication-of-cluster-state-fails-followers-check-retry-count-exceeded/330097)

<div class="topic-metadata">

**Author:** [@Itay\_Bittan](https://discuss.elastic.co/u/Itay_Bittan)\
**Replies:** 49\
**Last updated:** [June 20, 2023, 4:31pm UTC](https://discuss.elastic.co/t/publication-of-cluster-state-fails-followers-check-retry-count-exceeded/330097 "2023-06-20T16:31:34Z")

</div>

Hi everyone, We are running Elasticsearch 8.6.1 (on Kubernetes) with 12 data nodes (pods) and 3 dedicated master pods. We are heavily indexing data (bulks) and we did some configuration tunes to improve indexing: indi…

---

## [How can I index only new documents without updating the older ones?](https://discuss.elastic.co/t/how-can-i-index-only-new-documents-without-updating-the-older-ones/336501)

<div class="topic-metadata">

**Author:** [@SamuelSMendes](https://discuss.elastic.co/u/SamuelSMendes)\
**Replies:** 1\
**Last updated:** [June 20, 2023, 4:23pm UTC](https://discuss.elastic.co/t/how-can-i-index-only-new-documents-without-updating-the-older-ones/336501 "2023-06-20T16:23:15Z")

</div>

I am aware of the create action but when I use it a horrendous WARN log is printed in the logstash screen. The solution of create would fit perfect if it wasn't for it. So I've been wondering if there is another way to a…

---

## [Synthetics alert for redirects from https to http](https://discuss.elastic.co/t/synthetics-alert-for-redirects-from-https-to-http/336216)

<div class="topic-metadata">

**Author:** [@Alexander\_A](https://discuss.elastic.co/u/Alexander_A)\
**Replies:** 1\
**Last updated:** [June 20, 2023, 3:20pm UTC](https://discuss.elastic.co/t/synthetics-alert-for-redirects-from-https-to-http/336216 "2023-06-20T15:20:02Z")

</div>

Is it possible to configure alarm when site uses http instead of https or when we go to https and then redirected to http? This seems like a not good thing that can be detected by synthetics and created alert/inform mes…

---

## [Logstash output s3 prefix with date](https://discuss.elastic.co/t/logstash-output-s3-prefix-with-date/336498)

<div class="topic-metadata">

**Author:** [@kunalmohan](https://discuss.elastic.co/u/kunalmohan)\
**Replies:** 1\
**Last updated:** [June 20, 2023, 3:10pm UTC](https://discuss.elastic.co/t/logstash-output-s3-prefix-with-date/336498 "2023-06-20T15:10:27Z")

</div>

S3 output plugin | Logstash Reference \[8.8\] | Elastic mentions to use prefix = "%{+YYYY}/%{+MM}/%{+dd}" for creating folders based on event date. This doesn't work for my. It simply creates two nested folders with name /.…

---

## [Creating visualization with timestamp un y axis and not count](https://discuss.elastic.co/t/creating-visualization-with-timestamp-un-y-axis-and-not-count/336430)

<div class="topic-metadata">

**Author:** [@Anusha\_Kusanghi](https://discuss.elastic.co/u/Anusha_Kusanghi)\
**Replies:** 4\
**Last updated:** [June 20, 2023, 2:54pm UTC](https://discuss.elastic.co/t/creating-visualization-with-timestamp-un-y-axis-and-not-count/336430 "2023-06-20T14:54:27Z")

</div>

Hi All, We have a index which stores the status of job running in controlm platform , like job name ,id ,job start time end time and so on... We want to create a visualization: putting date in y axis (date on which da…

---

## [Alert rules with document link](https://discuss.elastic.co/t/alert-rules-with-document-link/336494)

<div class="topic-metadata">

**Author:** [@pantonis](https://discuss.elastic.co/u/pantonis)\
**Replies:** 0\
**Last updated:** [June 20, 2023, 2:48pm UTC](https://discuss.elastic.co/t/alert-rules-with-document-link/336494 "2023-06-20T14:48:44Z")

</div>

I have created an alert that filters documents based on a condition and for each document that evaluate a condition I send an email based on a mustache expression. Everything works find except I'm missing one thing. Fo…

---

## [EQL - Alert when Follow up event doesn't occur](https://discuss.elastic.co/t/eql-alert-when-follow-up-event-doesnt-occur/329917)

<div class="topic-metadata">

**Author:** [@lilow](https://discuss.elastic.co/u/lilow)\
**Replies:** 2\
**Last updated:** [June 20, 2023, 2:38pm UTC](https://discuss.elastic.co/t/eql-alert-when-follow-up-event-doesnt-occur/329917 "2023-06-20T14:38:07Z")

</div>

Hey, I'm trying to implement a rule with eql where I only want to get an alert when a follow up event doesn't occur within a certain time frame. Unfortunately it's not really doing what I'm hoping. Is there any way how…

---

## [Custom JacksonJsonpMapper in RestClientTransport](https://discuss.elastic.co/t/custom-jacksonjsonpmapper-in-restclienttransport/336481)

<div class="topic-metadata">

**Author:** [@JaroslavHolan](https://discuss.elastic.co/u/JaroslavHolan)\
**Replies:** 2\
**Last updated:** [June 20, 2023, 2:24pm UTC](https://discuss.elastic.co/t/custom-jacksonjsonpmapper-in-restclienttransport/336481 "2023-06-20T14:24:42Z")

</div>

Hi, I need to help with how to pass my instance of JacksonJsonpMapper to RestClientTransport in Spring Java/Kotlin project. I have the following exception com.fasterxml.jackson.databind.exc.InvalidDefinitionException:…

[Previous page](https://discuss.elastic.co/latest.md?page=632)

[Next page](https://discuss.elastic.co/latest.md?page=634)
