# Latest

**URL:** https://discuss.elastic.co/latest.md?page=637

[Latest](https://discuss.elastic.co/latest.md) · [Categories](https://discuss.elastic.co/categories.md) · [Tags](https://discuss.elastic.co/tags.md)

**Page:** 638

---

## [Unable to find in Java Client API ES 8.7 replacement of fieldsAndWeights in QueryStringQueryBuilder of earlier version](https://discuss.elastic.co/t/unable-to-find-in-java-client-api-es-8-7-replacement-of-fieldsandweights-in-querystringquerybuilder-of-earlier-version/336285)

<div class="topic-metadata">

**Author:** [@ramyogi](https://discuss.elastic.co/u/ramyogi)\
**Replies:** 4\
**Last updated:** [June 19, 2023, 12:20am UTC](https://discuss.elastic.co/t/unable-to-find-in-java-client-api-es-8-7-replacement-of-fieldsandweights-in-querystringquerybuilder-of-earlier-version/336285 "2023-06-19T00:20:16Z")

</div>

Before ES 8 we were using below query. final BoolQueryBuilder expectedBooleanQuery = QueryBuilders.boolQuery(); expectedBooleanQuery.must( QueryBuilders.queryStringQuery("water") .defaultOperato…

---

## [Elastic Defend Integration with Airgapped Package Registry](https://discuss.elastic.co/t/elastic-defend-integration-with-airgapped-package-registry/336314)

<div class="topic-metadata">

**Author:** [@sgehman](https://discuss.elastic.co/u/sgehman)\
**Replies:** 0\
**Last updated:** [June 18, 2023, 9:17pm UTC](https://discuss.elastic.co/t/elastic-defend-integration-with-airgapped-package-registry/336314 "2023-06-18T21:17:12Z")

</div>

I am using Andrew Peases Elastic Container Project, and version 8.6.2 for Elasticsearch, Kibana, and the Elastic Agent which serves as my fleet server. This is in an Airgapped environment, and I have followed the Documen…

---

## [Problems spinning up the docker compose example](https://discuss.elastic.co/t/problems-spinning-up-the-docker-compose-example/336268)

<div class="topic-metadata">

**Author:** [@Sasho](https://discuss.elastic.co/u/Sasho)\
**Replies:** 2\
**Last updated:** [June 18, 2023, 9:17pm UTC](https://discuss.elastic.co/t/problems-spinning-up-the-docker-compose-example/336268 "2023-06-18T21:17:06Z")

</div>

Hello, I'm following the instructions on Start a multi-node cluster with Docker Compose. I believe I have set up everything correctly. My .env file looks like this: # Password for the 'elastic' user (at least 6 chara…

---

## [Recent ecommerce requirement change ballooned our hosting costs x7. Need help with data model](https://discuss.elastic.co/t/recent-ecommerce-requirement-change-ballooned-our-hosting-costs-x7-need-help-with-data-model/336308)

<div class="topic-metadata">

**Author:** [@sdata47](https://discuss.elastic.co/u/sdata47)\
**Replies:** 0\
**Last updated:** [June 18, 2023, 6:14pm UTC](https://discuss.elastic.co/t/recent-ecommerce-requirement-change-ballooned-our-hosting-costs-x7-need-help-with-data-model/336308 "2023-06-18T18:14:54Z")

</div>

We're having a serious issue using Elasticsearch at work without large hosting costs. A recent requirement change bumped us up from $120 to $700 a month. Essentially, this is the issue. We have a catalog of products, …

---

## [Transform + Enrichment Policy](https://discuss.elastic.co/t/transform-enrichment-policy/334878)

<div class="topic-metadata">

**Author:** [@emi\_rose](https://discuss.elastic.co/u/emi_rose)\
**Replies:** 12\
**Last updated:** [June 18, 2023, 5:13pm UTC](https://discuss.elastic.co/t/transform-enrichment-policy/334878 "2023-06-18T17:13:47Z")

</div>

Hello, I had the idea to use the target index of a sum aggregation transform as the same target index for an enrichment policy. Essentially, I want to perform a join on the field being grouped on in the transform and en…

---

## [Any better solution to make elastic agent DaemonSet collect log smoothly?](https://discuss.elastic.co/t/any-better-solution-to-make-elastic-agent-daemonset-collect-log-smoothly/334763)

<div class="topic-metadata">

**Author:** [@Kelvin\_Chan](https://discuss.elastic.co/u/Kelvin_Chan)\
**Replies:** 8\
**Last updated:** [June 18, 2023, 12:41pm UTC](https://discuss.elastic.co/t/any-better-solution-to-make-elastic-agent-daemonset-collect-log-smoothly/334763 "2023-06-18T12:41:42Z")

</div>

I deployed a elastic agent DaemonSet to monitor elasticsearch cluster, but elastic agent mounts /var/log/containers, /var/log/pods, /var/lib/docker/containers to read container log, but these log files are only contain c…

---

## [Little confuse about decay function source code](https://discuss.elastic.co/t/little-confuse-about-decay-function-source-code/336296)

<div class="topic-metadata">

**Author:** [@RandalTeng](https://discuss.elastic.co/u/RandalTeng)\
**Replies:** 2\
**Last updated:** [June 18, 2023, 8:36am UTC](https://discuss.elastic.co/t/little-confuse-about-decay-function-source-code/336296 "2023-06-18T08:36:15Z")

</div>

hi guys, I recently read some source code about the decay function. there is some code doc, I can't figure out why it should be. the code line is: https://github.com/elastic/elasticsearch/blob/13fb93511c23fe0d1a02de07…

---

## [Updating index is not working for existing data inside json object](https://discuss.elastic.co/t/updating-index-is-not-working-for-existing-data-inside-json-object/336291)

<div class="topic-metadata">

**Author:** [@J\_S](https://discuss.elastic.co/u/J_S)\
**Replies:** 1\
**Last updated:** [June 18, 2023, 7:15am UTC](https://discuss.elastic.co/t/updating-index-is-not-working-for-existing-data-inside-json-object/336291 "2023-06-18T07:15:53Z")

</div>

I am repeatedly fetching rows from a database. I insert them into elasticsearch using the unique key as the document\_id. For any fields not on the current document I want to add any missing columns to the exiting documen…

---

## [Event.remove method not working inside aggregate section in code block](https://discuss.elastic.co/t/event-remove-method-not-working-inside-aggregate-section-in-code-block/336201)

<div class="topic-metadata">

**Author:** [@J\_S](https://discuss.elastic.co/u/J_S)\
**Replies:** 20\
**Last updated:** [June 18, 2023, 3:37am UTC](https://discuss.elastic.co/t/event-remove-method-not-working-inside-aggregate-section-in-code-block/336201 "2023-06-18T03:37:16Z")

</div>

Hi All, I am newbie to ELK stack, I am trying to remove the field called "attributes" while aggregate the data inside code block. But it is not removing the already existing "attributes" in the corresponding "id" but on…

---

## [Unable to Use Elasticsearch Object Export API](https://discuss.elastic.co/t/unable-to-use-elasticsearch-object-export-api/336287)

<div class="topic-metadata">

**Author:** [@vdashora](https://discuss.elastic.co/u/vdashora)\
**Replies:** 1\
**Last updated:** [June 18, 2023, 1:05am UTC](https://discuss.elastic.co/t/unable-to-use-elasticsearch-object-export-api/336287 "2023-06-18T01:05:18Z")

</div>

Hi all, I'm trying to export a dashboard we have in Kibana using the API command. I've written a Python script but when I run the command it gives me this error: Export failed with status code: 404 {"statusCode":404,"e…

---

## [X-pack/metricbeat/module/statsd: Unable to parse float values (statsd module) of counter metric type](https://discuss.elastic.co/t/x-pack-metricbeat-module-statsd-unable-to-parse-float-values-statsd-module-of-counter-metric-type/330095)

<div class="topic-metadata">

**Author:** [@shmsr\_elastic](https://discuss.elastic.co/u/shmsr_elastic)\
**Replies:** 1\
**Last updated:** [June 17, 2023, 7:04pm UTC](https://discuss.elastic.co/t/x-pack-metricbeat-module-statsd-unable-to-parse-float-values-statsd-module-of-counter-metric-type/330095 "2023-06-17T19:04:59Z")

</div>

I was exploring statsd's module code in beats while making some changes to the same and I noticed that the for metrics of type counter, we just support integers (of base 10 and 64 bitsize) and in case it is not the same…

---

## [Can you forward logs going into elasticsearch to a third party?](https://discuss.elastic.co/t/can-you-forward-logs-going-into-elasticsearch-to-a-third-party/334800)

<div class="topic-metadata">

**Author:** [@willsy](https://discuss.elastic.co/u/willsy)\
**Replies:** 3\
**Last updated:** [June 17, 2023, 3:32pm UTC](https://discuss.elastic.co/t/can-you-forward-logs-going-into-elasticsearch-to-a-third-party/334800 "2023-06-17T15:32:43Z")

</div>

I have a single instance of elasticsearch, kibana and i am getting the data in this via agents and filebeats. is there a way to "forward" the data that is ingested into elasticsearch to another device or instance?

---

## [Logstash to Elasticsearch there is 10-20min for delay, also not all logs are indexed](https://discuss.elastic.co/t/logstash-to-elasticsearch-there-is-10-20min-for-delay-also-not-all-logs-are-indexed/336241)

<div class="topic-metadata">

**Author:** [@mayank\_singh](https://discuss.elastic.co/u/mayank_singh)\
**Replies:** 3\
**Last updated:** [June 17, 2023, 3:20pm UTC](https://discuss.elastic.co/t/logstash-to-elasticsearch-there-is-10-20min-for-delay-also-not-all-logs-are-indexed/336241 "2023-06-17T15:20:49Z")

</div>

Hi, I am sending logs from Logstash to Elasticsearch. The Elasticsearch seems to be working fine but there is 10-20mins of delay in logs index also getting below error on logstash, any help would be greatly appreciated. …

---

## [Update field with new values is not possible using aggregate filter](https://discuss.elastic.co/t/update-field-with-new-values-is-not-possible-using-aggregate-filter/336266)

<div class="topic-metadata">

**Author:** [@J\_S](https://discuss.elastic.co/u/J_S)\
**Replies:** 0\
**Last updated:** [June 17, 2023, 10:27am UTC](https://discuss.elastic.co/t/update-field-with-new-values-is-not-possible-using-aggregate-filter/336266 "2023-06-17T10:27:51Z")

</div>

I am trying to update a JSON object called "attributes" inside aggregate filter. In some cases, I may or may not have attributes in Index, if it is not available means I will insert "attributes" as new JSON object field…

---

## [Reindex From json File only specific log file path docs](https://discuss.elastic.co/t/reindex-from-json-file-only-specific-log-file-path-docs/336195)

<div class="topic-metadata">

**Author:** [@bill210kouk](https://discuss.elastic.co/u/bill210kouk)\
**Replies:** 2\
**Last updated:** [June 17, 2023, 9:43am UTC](https://discuss.elastic.co/t/reindex-from-json-file-only-specific-log-file-path-docs/336195 "2023-06-17T09:43:18Z")

</div>

Good Morning I hope you're Alright. I'm a newbie and i would like to ask something. I've made an export process with elasticdump and it was a success. I would like to ask . My end goal is to keep only valuable documents…

---

## [Problems while using \_bulk api via camel rest route](https://discuss.elastic.co/t/problems-while-using-bulk-api-via-camel-rest-route/336238)

<div class="topic-metadata">

**Author:** [@markchennai](https://discuss.elastic.co/u/markchennai)\
**Replies:** 1\
**Last updated:** [June 17, 2023, 7:36am UTC](https://discuss.elastic.co/t/problems-while-using-bulk-api-via-camel-rest-route/336238 "2023-06-17T07:36:03Z")

</div>

Message History (source location and message history is disabled) Source ID Processor Elapsed (ms) route1/route1 …

---

## [Elasticsearch does not start](https://discuss.elastic.co/t/elasticsearch-does-not-start/336261)

<div class="topic-metadata">

**Author:** [@pan\_sjan](https://discuss.elastic.co/u/pan_sjan)\
**Replies:** 4\
**Last updated:** [June 17, 2023, 6:09am UTC](https://discuss.elastic.co/t/elasticsearch-does-not-start/336261 "2023-06-17T06:09:55Z")

</div>

I am using the es 7.17.10 tarball from https://artifacts.elastic.co/downloads/elasticsearch/elasticsearch-7.17.10-linux-x86\_64.tar.gz The Java version I have is JDK 18 # /usr/java/latest/bin/java -version openjdk vers…

---

## [Possible issue with tracking\_column\_type =\> "timestamp" in 8.1.1](https://discuss.elastic.co/t/possible-issue-with-tracking-column-type-timestamp-in-8-1-1/336255)

<div class="topic-metadata">

**Author:** [@SrxDevOps](https://discuss.elastic.co/u/SrxDevOps)\
**Replies:** 1\
**Last updated:** [June 16, 2023, 8:18pm UTC](https://discuss.elastic.co/t/possible-issue-with-tracking-column-type-timestamp-in-8-1-1/336255 "2023-06-16T20:18:17Z")

</div>

After updating from 7x to 8.1.1 any pipeline that uses tracking\_column\_type =\> "timestamp" fails with the error \[2023-06-16T14:37:50,485\]\[ERROR\]\[logstash.javapipeline \]\[Questions\] Pipeline error {:pipeline\_id=\>"Quest…

---

## [JIRA metrics](https://discuss.elastic.co/t/jira-metrics/336076)

<div class="topic-metadata">

**Author:** [@hegdeshashi](https://discuss.elastic.co/u/hegdeshashi)\
**Replies:** 3\
**Last updated:** [June 16, 2023, 8:54pm UTC](https://discuss.elastic.co/t/jira-metrics/336076 "2023-06-16T20:54:44Z")

</div>

Hi, any idea what and all info I will get as a part of metrics for JIRA if I add JIRA connector ? like how many JIRAs, what are all the status , number of JIRAs owned by a person, project-wise JIRAs, something like that.…

---

## [Normalising scores?](https://discuss.elastic.co/t/normalising-scores/336149)

<div class="topic-metadata">

**Author:** [@catmanjan](https://discuss.elastic.co/u/catmanjan)\
**Replies:** 1\
**Last updated:** [June 16, 2023, 8:49pm UTC](https://discuss.elastic.co/t/normalising-scores/336149 "2023-06-16T20:49:31Z")

</div>

I've been searching how to normalise the scores so we can display the score as a percentage to the end user - it seems that this is/was not possible? That seems incredible to me... Is there really no way to tell elastic…

---

## [Convert datetime to another timezone in logstash](https://discuss.elastic.co/t/convert-datetime-to-another-timezone-in-logstash/336214)

<div class="topic-metadata">

**Author:** [@ashokkrishna99\_Vemur](https://discuss.elastic.co/u/ashokkrishna99_Vemur)\
**Replies:** 8\
**Last updated:** [June 16, 2023, 8:06pm UTC](https://discuss.elastic.co/t/convert-datetime-to-another-timezone-in-logstash/336214 "2023-06-16T20:06:33Z")

</div>

I am getting logs from a firewall which are in GMT timezone. For example firewall sending rt=Jun 16 2023 11:24:40 GMT I want to convert that time to MYT rt=June 16 2023 19:24:40 MYT. How can I do that. filter { grok…

---

## [How can I modify the path Elasticsearch 2.4.6 uses to run Java in Linux?](https://discuss.elastic.co/t/how-can-i-modify-the-path-elasticsearch-2-4-6-uses-to-run-java-in-linux/335893)

<div class="topic-metadata">

**Author:** [@Latitude](https://discuss.elastic.co/u/Latitude)\
**Replies:** 4\
**Last updated:** [June 16, 2023, 7:59pm UTC](https://discuss.elastic.co/t/how-can-i-modify-the-path-elasticsearch-2-4-6-uses-to-run-java-in-linux/335893 "2023-06-16T19:59:31Z")

</div>

Brand new to Elasticsearch. Can anyone explain how how to modify the path Elasticsearch v2.4.6 uses for Java on Linux? There is a discrepancy between Test and Production and I need to change Test to match Production: Pr…

---

## [Unexpected \_dateparsefailure with ISO8601 timestamp from winlogs](https://discuss.elastic.co/t/unexpected-dateparsefailure-with-iso8601-timestamp-from-winlogs/336246)

<div class="topic-metadata">

**Author:** [@waves](https://discuss.elastic.co/u/waves)\
**Replies:** 5\
**Last updated:** [June 16, 2023, 7:25pm UTC](https://discuss.elastic.co/t/unexpected-dateparsefailure-with-iso8601-timestamp-from-winlogs/336246 "2023-06-16T19:25:24Z")

</div>

Hi I'm using winlogbeat and receive nice logs with a nice ISO8601 @timestamp in the received events (I used a logstash conf stdout to check them.) "@timestamp" =\> 2023-06-15T14:44:20.273Z, which I think logstash auto…

---

## [Issue after login with new user with new customized role](https://discuss.elastic.co/t/issue-after-login-with-new-user-with-new-customized-role/336250)

<div class="topic-metadata">

**Author:** [@Ahmedeyhaab](https://discuss.elastic.co/u/Ahmedeyhaab)\
**Replies:** 0\
**Last updated:** [June 16, 2023, 5:32pm UTC](https://discuss.elastic.co/t/issue-after-login-with-new-user-with-new-customized-role/336250 "2023-06-16T17:32:18Z")

</div>

Hi, Issue Description:- I have an issue whenever I create a new user with specific customized role using kibana UI or file based configuration and command line, after login by the new user, the only available applicati…

---

## [\[ERROR\]\[plugins.fleet\] Failed to fetch latest version](https://discuss.elastic.co/t/error-plugins-fleet-failed-to-fetch-latest-version/335115)

<div class="topic-metadata">

**Author:** [@Verdugo\_Gonzalo](https://discuss.elastic.co/u/Verdugo_Gonzalo)\
**Replies:** 2\
**Last updated:** [June 16, 2023, 5:11pm UTC](https://discuss.elastic.co/t/error-plugins-fleet-failed-to-fetch-latest-version/335115 "2023-06-16T17:11:30Z")

</div>

Hello everyone I have the same error that is shown in this closed post: (Fleet server loading slowly) Internet access goes through a proxy, but throwing curl to said URL responds without problems. Also added this info …

---

## [How to shutdown ES using API call](https://discuss.elastic.co/t/how-to-shutdown-es-using-api-call/336210)

<div class="topic-metadata">

**Author:** [@ANUBHAV\_GUPTA](https://discuss.elastic.co/u/ANUBHAV_GUPTA)\
**Replies:** 5\
**Last updated:** [June 16, 2023, 4:51pm UTC](https://discuss.elastic.co/t/how-to-shutdown-es-using-api-call/336210 "2023-06-16T16:51:54Z")

</div>

Hi, I am wondering if there is a way or an API using which I can shutdown my ES server?

---

## [Logstash log clarification](https://discuss.elastic.co/t/logstash-log-clarification/336240)

<div class="topic-metadata">

**Author:** [@Karthik9099](https://discuss.elastic.co/u/Karthik9099)\
**Replies:** 1\
**Last updated:** [June 16, 2023, 3:22pm UTC](https://discuss.elastic.co/t/logstash-log-clarification/336240 "2023-06-16T15:22:54Z")

</div>

Logstash logs show - "Added to Object" - \<\> What does it mean? Is it reading the file or skipping out or accumulating data?

---

## [Manually strip parameters on SQL queries](https://discuss.elastic.co/t/manually-strip-parameters-on-sql-queries/336202)

<div class="topic-metadata">

**Author:** [@bram](https://discuss.elastic.co/u/bram)\
**Replies:** 0\
**Last updated:** [June 16, 2023, 9:38am UTC](https://discuss.elastic.co/t/manually-strip-parameters-on-sql-queries/336202 "2023-06-16T09:38:34Z")

</div>

Kibana/Elasticsearch/APM Server version: 8.8.1 APM Agent language and version: PHP 1.8.4 Browser version: 113.0.1774.35 Original install method (e.g. download page, yum, deb, from source, etc.) and version: deb F…

---

## [Python Elasticsearch API: Error 'data too large' when iterating](https://discuss.elastic.co/t/python-elasticsearch-api-error-data-too-large-when-iterating/336234)

<div class="topic-metadata">

**Author:** [@tmslara.a](https://discuss.elastic.co/u/tmslara.a)\
**Replies:** 0\
**Last updated:** [June 16, 2023, 2:15pm UTC](https://discuss.elastic.co/t/python-elasticsearch-api-error-data-too-large-when-iterating/336234 "2023-06-16T14:15:28Z")

</div>

I am using the Python Elasticsearch API to interact with my Elastic cluster. I'm getting an error when I try to perform several searches in a for loop. In synthesis, I'm doing the following: I iterate over a list of valu…

---

## [Display flattened fields on canvas](https://discuss.elastic.co/t/display-flattened-fields-on-canvas/336233)

<div class="topic-metadata">

**Author:** [@witwit](https://discuss.elastic.co/u/witwit)\
**Replies:** 1\
**Last updated:** [June 16, 2023, 2:09pm UTC](https://discuss.elastic.co/t/display-flattened-fields-on-canvas/336233 "2023-06-16T14:09:23Z")

</div>

Hi everyone, I have a set of logs that i've been processing. In processing, I managed to tag these logs types as file, download status etc. Afterwards, I used transform to group these logs based on files and aggregate d…

[Previous page](https://discuss.elastic.co/latest.md?page=636)

[Next page](https://discuss.elastic.co/latest.md?page=638)
