# Latest

**URL:** https://discuss.elastic.co/latest.md?page=634

[Latest](https://discuss.elastic.co/latest.md) · [Categories](https://discuss.elastic.co/categories.md) · [Tags](https://discuss.elastic.co/tags.md)

**Page:** 635

---

## [Alert rules with document link](https://discuss.elastic.co/t/alert-rules-with-document-link/336494)

<div class="topic-metadata">

**Author:** [@pantonis](https://discuss.elastic.co/u/pantonis)\
**Replies:** 0\
**Last updated:** [June 20, 2023, 2:48pm UTC](https://discuss.elastic.co/t/alert-rules-with-document-link/336494 "2023-06-20T14:48:44Z")

</div>

I have created an alert that filters documents based on a condition and for each document that evaluate a condition I send an email based on a mustache expression. Everything works find except I'm missing one thing. Fo…

---

## [EQL - Alert when Follow up event doesn't occur](https://discuss.elastic.co/t/eql-alert-when-follow-up-event-doesnt-occur/329917)

<div class="topic-metadata">

**Author:** [@lilow](https://discuss.elastic.co/u/lilow)\
**Replies:** 2\
**Last updated:** [June 20, 2023, 2:38pm UTC](https://discuss.elastic.co/t/eql-alert-when-follow-up-event-doesnt-occur/329917 "2023-06-20T14:38:07Z")

</div>

Hey, I'm trying to implement a rule with eql where I only want to get an alert when a follow up event doesn't occur within a certain time frame. Unfortunately it's not really doing what I'm hoping. Is there any way how…

---

## [Custom JacksonJsonpMapper in RestClientTransport](https://discuss.elastic.co/t/custom-jacksonjsonpmapper-in-restclienttransport/336481)

<div class="topic-metadata">

**Author:** [@JaroslavHolan](https://discuss.elastic.co/u/JaroslavHolan)\
**Replies:** 2\
**Last updated:** [June 20, 2023, 2:24pm UTC](https://discuss.elastic.co/t/custom-jacksonjsonpmapper-in-restclienttransport/336481 "2023-06-20T14:24:42Z")

</div>

Hi, I need to help with how to pass my instance of JacksonJsonpMapper to RestClientTransport in Spring Java/Kotlin project. I have the following exception com.fasterxml.jackson.databind.exc.InvalidDefinitionException:…

---

## [Percolate Query Issues after Upgrading to Elasticsearch 8.6.2 with REST High-Level Client 7.17.9](https://discuss.elastic.co/t/percolate-query-issues-after-upgrading-to-elasticsearch-8-6-2-with-rest-high-level-client-7-17-9/336359)

<div class="topic-metadata">

**Author:** [@ulysse42](https://discuss.elastic.co/u/ulysse42)\
**Replies:** 5\
**Last updated:** [June 20, 2023, 2:16pm UTC](https://discuss.elastic.co/t/percolate-query-issues-after-upgrading-to-elasticsearch-8-6-2-with-rest-high-level-client-7-17-9/336359 "2023-06-20T14:16:35Z")

</div>

Hello Elasticsearch community, I'm currently experiencing an issue with the Percolate Query after upgrading my Elasticsearch version to 8.6.2. I'm still using the REST High-Level Client 7.17.9. Here's the exception I'm…

---

## [Unassigned shards =\> How to set default replica number to 0?](https://discuss.elastic.co/t/unassigned-shards-how-to-set-default-replica-number-to-0/336458)

<div class="topic-metadata">

**Author:** [@sbocquet](https://discuss.elastic.co/u/sbocquet)\
**Replies:** 1\
**Last updated:** [June 20, 2023, 1:36pm UTC](https://discuss.elastic.co/t/unassigned-shards-how-to-set-default-replica-number-to-0/336458 "2023-06-20T13:36:37Z")

</div>

Hi, A few days ago, I've just installed a new node to my single node cluster, in order to manage datastreams lifecycle policies between 2 nodes : elk1 is configured in elasticsearch.yml with node.roles: master, data\_…

---

## [Transforms group by on 2 different data fields having same value](https://discuss.elastic.co/t/transforms-group-by-on-2-different-data-fields-having-same-value/336478)

<div class="topic-metadata">

**Author:** [@ashwani\_perf](https://discuss.elastic.co/u/ashwani_perf)\
**Replies:** 2\
**Last updated:** [June 20, 2023, 1:34pm UTC](https://discuss.elastic.co/t/transforms-group-by-on-2-different-data-fields-having-same-value/336478 "2023-06-20T13:34:43Z")

</div>

Hi Team, I am fairly new to Kibana and have run into a problem. I am trying to write a single transform which captures ingress and egress of a single event so that i can aggregate them by timestamp max and min and then …

---

## [Unable to install s3-repository plugin](https://discuss.elastic.co/t/unable-to-install-s3-repository-plugin/336443)

<div class="topic-metadata">

**Author:** [@ANUBHAV\_GUPTA](https://discuss.elastic.co/u/ANUBHAV_GUPTA)\
**Replies:** 6\
**Last updated:** [June 20, 2023, 1:29pm UTC](https://discuss.elastic.co/t/unable-to-install-s3-repository-plugin/336443 "2023-06-20T13:29:26Z")

</div>

Hi, I am trying to install s3-repository plugin but getting the following error:- -\> Installing repository-s3 \[repository-s3\] is no longer a plugin but instead a module packaged with this distribution of Elasticsearch -\>…

---

## [Seeking a developer to help extend Elasticsearch to connect with Web3 API](https://discuss.elastic.co/t/seeking-a-developer-to-help-extend-elasticsearch-to-connect-with-web3-api/336114)

<div class="topic-metadata">

**Author:** [@Jules\_Lai](https://discuss.elastic.co/u/Jules_Lai)\
**Replies:** 6\
**Last updated:** [June 19, 2023, 4:42pm UTC](https://discuss.elastic.co/t/seeking-a-developer-to-help-extend-elasticsearch-to-connect-with-web3-api/336114 "2023-06-19T16:42:34Z")

</div>

Hi, I am looking for a developer who is able to help integrate Web3 into Elasticsearch. I am one of the developers working on the Web3 interface for SIA decentralised storage. I will be mainly using Elasticsearch with…

---

## [Dynamically set s3 bucket name in logstash output](https://discuss.elastic.co/t/dynamically-set-s3-bucket-name-in-logstash-output/336484)

<div class="topic-metadata">

**Author:** [@kunalmohan](https://discuss.elastic.co/u/kunalmohan)\
**Replies:** 1\
**Last updated:** [June 20, 2023, 1:09pm UTC](https://discuss.elastic.co/t/dynamically-set-s3-bucket-name-in-logstash-output/336484 "2023-06-20T13:09:34Z")

</div>

Is there a way I can set s3 bucket name using a @metadata field?

---

## [Most efficient way of accessing long\[\]\[\] data in Painless scripts](https://discuss.elastic.co/t/most-efficient-way-of-accessing-long-data-in-painless-scripts/336437)

<div class="topic-metadata">

**Author:** [@Pyppe](https://discuss.elastic.co/u/Pyppe)\
**Replies:** 1\
**Last updated:** [June 20, 2023, 1:06pm UTC](https://discuss.elastic.co/t/most-efficient-way-of-accessing-long-data-in-painless-scripts/336437 "2023-06-20T13:06:46Z")

</div>

Hi! We have a custom solution for calculating similarities using feature vectors. Each document in Elasticsearch index can have multiple entities. Thus, for each document we have basically long\[\]\[\] formatted data we wou…

---

## [Recursive glob pattern depth](https://discuss.elastic.co/t/recursive-glob-pattern-depth/336471)

<div class="topic-metadata">

**Author:** [@unknotted-evacuee](https://discuss.elastic.co/u/unknotted-evacuee)\
**Replies:** 3\
**Last updated:** [June 20, 2023, 1:04pm UTC](https://discuss.elastic.co/t/recursive-glob-pattern-depth/336471 "2023-06-20T13:04:27Z")

</div>

We are trying to recursively capture logs from a file tree that gets quite deep. According to the documentation here: filestream input | Filebeat Reference \[8.8\] | Elastic This states that: "If enabled it expands a sing…

---

## [Install/ create 6 node elasticsearch 8.7 cluster](https://discuss.elastic.co/t/install-create-6-node-elasticsearch-8-7-cluster/336148)

<div class="topic-metadata">

**Author:** [@zaeemmasood](https://discuss.elastic.co/u/zaeemmasood)\
**Replies:** 2\
**Last updated:** [June 20, 2023, 1:02pm UTC](https://discuss.elastic.co/t/install-create-6-node-elasticsearch-8-7-cluster/336148 "2023-06-20T13:02:24Z")

</div>

Hi All, I am looking for some info on how to install and create ES 8.7 cluster on RHEL 7 servers using tar.gz. I am not able to find the steps in the documentation. Need to know how to make nodes join a cluster. Need…

---

## [Logstash not listening for second input](https://discuss.elastic.co/t/logstash-not-listening-for-second-input/336480)

<div class="topic-metadata">

**Author:** [@Shabu](https://discuss.elastic.co/u/Shabu)\
**Replies:** 2\
**Last updated:** [June 20, 2023, 1:01pm UTC](https://discuss.elastic.co/t/logstash-not-listening-for-second-input/336480 "2023-06-20T13:01:21Z")

</div>

I have set up a working ELK stack with input from winlogbeat. Now I want to add a second input for ingesting syslog logs from a switch. I configured my logstash to do so, but it still only listens on port 5044 after rest…

---

## [Issue with mapping in elasticsearch](https://discuss.elastic.co/t/issue-with-mapping-in-elasticsearch/336461)

<div class="topic-metadata">

**Author:** [@Hanni](https://discuss.elastic.co/u/Hanni)\
**Replies:** 1\
**Last updated:** [June 20, 2023, 12:03pm UTC](https://discuss.elastic.co/t/issue-with-mapping-in-elasticsearch/336461 "2023-06-20T12:03:52Z")

</div>

Hi, I'm trying to index a field in elasticsearch with my index template. Except that my field can either be of type text (ex: No) or it can be of type float ( ex: 8.1). When I set the type to float in my mapping, I get e…

---

## [Can not have the same result](https://discuss.elastic.co/t/can-not-have-the-same-result/336460)

<div class="topic-metadata">

**Author:** [@stephane\_chan](https://discuss.elastic.co/u/stephane_chan)\
**Replies:** 3\
**Last updated:** [June 20, 2023, 11:54am UTC](https://discuss.elastic.co/t/can-not-have-the-same-result/336460 "2023-06-20T11:54:33Z")

</div>

Hi, I can't do a song search on an elasticsearch lyrics excerpt, The lyric: "... Na dia mbola zaza Na dia mbola kely ..." if I search for "mbola zaza" it gives me the result but if I type "ola zaza" it gives me no re…

---

## [Not working TCP input with TLS](https://discuss.elastic.co/t/not-working-tcp-input-with-tls/336473)

<div class="topic-metadata">

**Author:** [@wedkarz014](https://discuss.elastic.co/u/wedkarz014)\
**Replies:** 0\
**Last updated:** [June 20, 2023, 11:41am UTC](https://discuss.elastic.co/t/not-working-tcp-input-with-tls/336473 "2023-06-20T11:41:28Z")

</div>

Hi, I want to send syslog events but with tls, unfortunately i have a problem with that. Logstash receive first event and that's all, i don't have any error logs. Here is output config: output { tcp { host =\> …

---

## [TSVB Markdown visualization](https://discuss.elastic.co/t/tsvb-markdown-visualization/335319)

<div class="topic-metadata">

**Author:** [@Alice\_Ionescu](https://discuss.elastic.co/u/Alice_Ionescu)\
**Replies:** 1\
**Last updated:** [June 20, 2023, 11:11am UTC](https://discuss.elastic.co/t/tsvb-markdown-visualization/335319 "2023-06-20T11:11:26Z")

</div>

Hello, I am trying to create a table which is displayed like this: ||column\_name ||column\_value|| ||column\_name ||column\_value|| And display information only on a row from an index. in TSVB Markdown visualization. …

---

## [Using "&embed=true" or "&hide-filter-bar=true" to hide KQL doesn't work](https://discuss.elastic.co/t/using-embed-true-or-hide-filter-bar-true-to-hide-kql-doesnt-work/334660)

<div class="topic-metadata">

**Author:** [@cpu](https://discuss.elastic.co/u/cpu)\
**Replies:** 2\
**Last updated:** [June 20, 2023, 10:53am UTC](https://discuss.elastic.co/t/using-embed-true-or-hide-filter-bar-true-to-hide-kql-doesnt-work/334660 "2023-06-20T10:53:29Z")

</div>

Hello, I tried both solutions proposed in the community forum: 1- "Adding !\[kql|410x161\](upload://A1ggJ3BBz6XtO6BbN1Fpt2tVP6p.jpeg) to the URL should remove the filter options." 2- You could add &embed=true a the end…

---

## [Logs related to database (postgres) pods are not moving to elastic](https://discuss.elastic.co/t/logs-related-to-database-postgres-pods-are-not-moving-to-elastic/336459)

<div class="topic-metadata">

**Author:** [@unais](https://discuss.elastic.co/u/unais)\
**Replies:** 0\
**Last updated:** [June 20, 2023, 9:29am UTC](https://discuss.elastic.co/t/logs-related-to-database-postgres-pods-are-not-moving-to-elastic/336459 "2023-06-20T09:29:37Z")

</div>

Hi community, I'm not able to see the logs related postgres even though I have mentioned the name of the pod in filebeat. postgres logs: (on running kubectl logs command) 2023-06-19 07:37:39.591 UTC \[73\] ERROR: "xyz" …

---

## [Vega-Lite problem with the visualization](https://discuss.elastic.co/t/vega-lite-problem-with-the-visualization/334220)

<div class="topic-metadata">

**Author:** [@martinez061](https://discuss.elastic.co/u/martinez061)\
**Replies:** 1\
**Last updated:** [June 20, 2023, 9:56am UTC](https://discuss.elastic.co/t/vega-lite-problem-with-the-visualization/334220 "2023-06-20T09:56:38Z")

</div>

Hi im trying to create something similar to image below. The data, that i want to visualise is syslog\_hostname syslog\_ip\_address syslog\_url syslog\_url\_status For one destination im checking 3 website, and i want…

---

## [LogStash and parsing OPNSenser logs](https://discuss.elastic.co/t/logstash-and-parsing-opnsenser-logs/334234)

<div class="topic-metadata">

**Author:** [@LoggingJennfier](https://discuss.elastic.co/u/LoggingJennfier)\
**Replies:** 2\
**Last updated:** [June 20, 2023, 9:16am UTC](https://discuss.elastic.co/t/logstash-and-parsing-opnsenser-logs/334234 "2023-06-20T09:16:07Z")

</div>

My logs are coming in as follows: \<134\>May 24 14:39:32 edge.internal filterlog\[2535\]: 78,,,ffe6d10d1f27a42fc0edc3abb3a6d333,ovpnc1,match,pass,out,4,0x0,,63,61951,0,DF,6,tcp,60,10.8.0.2,20.44.17.5,44575,443,0,S,149708160…

---

## [Filebeat error for port ERROR: Address already in use](https://discuss.elastic.co/t/filebeat-error-for-port-error-address-already-in-use/336422)

<div class="topic-metadata">

**Author:** [@yogesh.gangwar](https://discuss.elastic.co/u/yogesh.gangwar)\
**Replies:** 1\
**Last updated:** [June 20, 2023, 8:54am UTC](https://discuss.elastic.co/t/filebeat-error-for-port-error-address-already-in-use/336422 "2023-06-20T08:54:33Z")

</div>

While running the logstash I'm getting an issue of "A plugin had an unrecoverable error. Will restart this plugin." \</ \[2023-06-20T10:37:52,046\]\[INFO \]\[org.logstash.beats.Server\]\[main\]\[f36c0056714d92177d9fb7e027196d5ceb…

---

## [No permissions for user | Security Exception](https://discuss.elastic.co/t/no-permissions-for-user-security-exception/335499)

<div class="topic-metadata">

**Author:** [@Faisal\_Umer](https://discuss.elastic.co/u/Faisal_Umer)\
**Replies:** 6\
**Last updated:** [June 20, 2023, 8:52am UTC](https://discuss.elastic.co/t/no-permissions-for-user-security-exception/335499 "2023-06-20T08:52:58Z")

</div>

I have to delay the shards assignment after a failure and running this command for that PUT \_all/\_settings { "settings": { "index.unassigned.node\_left.delayed\_timeout": "5m" } } Getting the following error whi…

---

## [Elasticerach 8.5.1 version image gives this error curl: (52) Empty reply from server](https://discuss.elastic.co/t/elasticerach-8-5-1-version-image-gives-this-error-curl-52-empty-reply-from-server/336444)

<div class="topic-metadata">

**Author:** [@Piyumitha\_Nirman](https://discuss.elastic.co/u/Piyumitha_Nirman)\
**Replies:** 2\
**Last updated:** [June 20, 2023, 8:48am UTC](https://discuss.elastic.co/t/elasticerach-8-5-1-version-image-gives-this-error-curl-52-empty-reply-from-server/336444 "2023-06-20T08:48:09Z")

</div>

I used Elasticsearch 8.5.1 image for my Kubernetes cluster. After installing using the helm chart pod is running correctly. but when I tried to check Elasticsearch cluster healthiness. it gave this error. curl 127.0.0.1:…

---

## [Undefined class constant 'MAJOR\_VERSION](https://discuss.elastic.co/t/undefined-class-constant-major-version/336429)

<div class="topic-metadata">

**Author:** [@zaheer8](https://discuss.elastic.co/u/zaheer8)\
**Replies:** 4\
**Last updated:** [June 20, 2023, 8:46am UTC](https://discuss.elastic.co/t/undefined-class-constant-major-version/336429 "2023-06-20T08:46:53Z")

</div>

Hi Geek Elasticsearch component is showing the Undefined class constant 'MAJOR\_VERSION' error in Elasticsearch version 6.x . Can you help why it is showing this error?

---

## [Which visualization should i choose for displaying Host.version](https://discuss.elastic.co/t/which-visualization-should-i-choose-for-displaying-host-version/335927)

<div class="topic-metadata">

**Author:** [@vijay\_kaali](https://discuss.elastic.co/u/vijay_kaali)\
**Replies:** 6\
**Last updated:** [June 20, 2023, 8:46am UTC](https://discuss.elastic.co/t/which-visualization-should-i-choose-for-displaying-host-version/335927 "2023-06-20T08:46:10Z")

</div>

i am want to display host confirmation i dashboard like cpu count, total memory , host.os.version . which visualisation should i choose . as all require aggregate function but . these are not . and more over for my …

---

## [Edit kibana login UI Title](https://discuss.elastic.co/t/edit-kibana-login-ui-title/335962)

<div class="topic-metadata">

**Author:** [@mr\_ph](https://discuss.elastic.co/u/mr_ph)\
**Replies:** 9\
**Last updated:** [June 20, 2023, 8:36am UTC](https://discuss.elastic.co/t/edit-kibana-login-ui-title/335962 "2023-06-20T08:36:23Z")

</div>

how can i edit the title seeing in the loging page of kibana, Where i can find the respective file. how can i add other logos and title texts in it. Change the welcome to elastic into any other title, for that wher…

---

## [Slowness after upgrading ElasticSearch 6.5 to 7.10](https://discuss.elastic.co/t/slowness-after-upgrading-elasticsearch-6-5-to-7-10/336439)

<div class="topic-metadata">

**Author:** [@Thomas\_Kang](https://discuss.elastic.co/u/Thomas_Kang)\
**Replies:** 5\
**Last updated:** [June 20, 2023, 8:26am UTC](https://discuss.elastic.co/t/slowness-after-upgrading-elasticsearch-6-5-to-7-10/336439 "2023-06-20T08:26:35Z")

</div>

Hi folks, I'm experiencing slowness after upgrading Elasticsearch from 6.5.4 to 7.10.2. I can reproduce it in my local (using the official docker images) and also in AWS' managed clusters. Here are the index mappings …

---

## [Display best permutation of different fields](https://discuss.elastic.co/t/display-best-permutation-of-different-fields/336055)

<div class="topic-metadata">

**Author:** [@Ravid\_Cohen](https://discuss.elastic.co/u/Ravid_Cohen)\
**Replies:** 1\
**Last updated:** [June 20, 2023, 8:08am UTC](https://discuss.elastic.co/t/display-best-permutation-of-different-fields/336055 "2023-06-20T08:08:51Z")

</div>

I have a metric (document) that contains three different fields: a, b, and c. The metric can be filtered by time and location. I want to filter all the data points of this metric according to time and location (using Ki…

---

## [Min and Max timestamp difference](https://discuss.elastic.co/t/min-and-max-timestamp-difference/334634)

<div class="topic-metadata">

**Author:** [@SUBIN\_B\_MATHEW](https://discuss.elastic.co/u/SUBIN_B_MATHEW)\
**Replies:** 1\
**Last updated:** [June 20, 2023, 8:04am UTC](https://discuss.elastic.co/t/min-and-max-timestamp-difference/334634 "2023-06-20T08:04:11Z")

</div>

Aggregated the Min and Max timestamp based on the message id. I wanted to calculate the time difference between min and Max time and show it in a data table on kibana dashboard , could you please help me on this?

[Previous page](https://discuss.elastic.co/latest.md?page=633)

[Next page](https://discuss.elastic.co/latest.md?page=635)
