# Latest

**URL:** https://discuss.elastic.co/latest.md?page=638

[Latest](https://discuss.elastic.co/latest.md) · [Categories](https://discuss.elastic.co/categories.md) · [Tags](https://discuss.elastic.co/tags.md)

**Page:** 639

---

## [DataStream field host.id is being replaced with a guid in elastic integration. How do I prevent that?](https://discuss.elastic.co/t/datastream-field-host-id-is-being-replaced-with-a-guid-in-elastic-integration-how-do-i-prevent-that/336228)

<div class="topic-metadata">

**Author:** [@hodgepodge](https://discuss.elastic.co/u/hodgepodge)\
**Replies:** 0\
**Last updated:** [June 16, 2023, 1:12pm UTC](https://discuss.elastic.co/t/datastream-field-host-id-is-being-replaced-with-a-guid-in-elastic-integration-how-do-i-prevent-that/336228 "2023-06-16T13:12:18Z")

</div>

Data on target machine is stored in a ndjson logfile and is read by filebeat/elastic-agent then transferred to fleet server agent but the host.id in the Elasticsearch index is no longer the original value stored in the n…

---

## [Allow Kibana role to access all indices EXCEPT FOR a specific one](https://discuss.elastic.co/t/allow-kibana-role-to-access-all-indices-except-for-a-specific-one/336135)

<div class="topic-metadata">

**Author:** [@DougR](https://discuss.elastic.co/u/DougR)\
**Replies:** 2\
**Last updated:** [June 16, 2023, 1:16pm UTC](https://discuss.elastic.co/t/allow-kibana-role-to-access-all-indices-except-for-a-specific-one/336135 "2023-06-16T13:16:49Z")

</div>

TL;DR How do I grant access to all indices matching a pattern, but deny access to one specific index that also matches the pattern (e.g., how do I ALLOW access to all logs, including logs-myapp.log-\*, but specifically DE…

---

## [Creating pipelines for multiple configuration](https://discuss.elastic.co/t/creating-pipelines-for-multiple-configuration/336223)

<div class="topic-metadata">

**Author:** [@vishukadam](https://discuss.elastic.co/u/vishukadam)\
**Replies:** 1\
**Last updated:** [June 16, 2023, 1:19pm UTC](https://discuss.elastic.co/t/creating-pipelines-for-multiple-configuration/336223 "2023-06-16T13:19:50Z")

</div>

Hi , I am trying to configure Logstash to read mulitple configurations (viz. A.conf and B.conf). Each configuration create separate index viz. indexA annd indexB, which i defined in the configuration file. Running indiv…

---

## [Drop docs if source.ip is on range os IPs](https://discuss.elastic.co/t/drop-docs-if-source-ip-is-on-range-os-ips/336229)

<div class="topic-metadata">

**Author:** [@Carlos\_Samuel](https://discuss.elastic.co/u/Carlos_Samuel)\
**Replies:** 0\
**Last updated:** [June 16, 2023, 1:15pm UTC](https://discuss.elastic.co/t/drop-docs-if-source-ip-is-on-range-os-ips/336229 "2023-06-16T13:15:37Z")

</div>

Hi. I need to drop docs that is on range of IP "192.168.1.1" and "192.168.3.255". What I have tried on Ingest Pipelines: This example above is getting me "Compile Error".

---

## [I am unable to access the Kibana domain name with HTTPS using SSL certificates](https://discuss.elastic.co/t/i-am-unable-to-access-the-kibana-domain-name-with-https-using-ssl-certificates/336224)

<div class="topic-metadata">

**Author:** [@Prasanth\_K](https://discuss.elastic.co/u/Prasanth_K)\
**Replies:** 0\
**Last updated:** [June 16, 2023, 12:57pm UTC](https://discuss.elastic.co/t/i-am-unable-to-access-the-kibana-domain-name-with-https-using-ssl-certificates/336224 "2023-06-16T12:57:14Z")

</div>

Hi all, I am trying to access the Kibana URL with HTTPS using the domain name and SSL certificates associated with the domain. I have configured Nginx on CentOS OS for this purpose. However, I can successfully access th…

---

## [Elastic "premium"](https://discuss.elastic.co/t/elastic-premium/336220)

<div class="topic-metadata">

**Author:** [@Skairik](https://discuss.elastic.co/u/Skairik)\
**Replies:** 1\
**Last updated:** [June 16, 2023, 12:56pm UTC](https://discuss.elastic.co/t/elastic-premium/336220 "2023-06-16T12:56:21Z")

</div>

Hello everyone, I am potentially interested in a higher version of the Elastic suite, but I am not sure of is that the prices below are only for the cloud or not: Tarifs officiels Elasticsearch : Elastic Cloud, offre E…

---

## [Creating Headers (with key value) in kafka offset using logstash Configuration](https://discuss.elastic.co/t/creating-headers-with-key-value-in-kafka-offset-using-logstash-configuration/336089)

<div class="topic-metadata">

**Author:** [@Ayushi\_bhardwaj](https://discuss.elastic.co/u/Ayushi_bhardwaj)\
**Replies:** 4\
**Last updated:** [June 16, 2023, 12:54pm UTC](https://discuss.elastic.co/t/creating-headers-with-key-value-in-kafka-offset-using-logstash-configuration/336089 "2023-06-16T12:54:28Z")

</div>

Below is my config i had written to create headers (key & value) in my logstash config , but still it does not reflect to me in headers under offset tool. input { elasticsearch { hosts =\> \["localhost"\] index…

---

## [Using the command line to install the elastic agent, a port error occurs](https://discuss.elastic.co/t/using-the-command-line-to-install-the-elastic-agent-a-port-error-occurs/336035)

<div class="topic-metadata">

**Author:** [@xqaiviwjxzw](https://discuss.elastic.co/u/xqaiviwjxzw)\
**Replies:** 3\
**Last updated:** [June 16, 2023, 11:58am UTC](https://discuss.elastic.co/t/using-the-command-line-to-install-the-elastic-agent-a-port-error-occurs/336035 "2023-06-16T11:58:10Z")

</div>

Using the command line to install the elastic agent, a port error occurs,the access port is communicable,what is the reason? How to solve it? Hope to get a reply, thank you sudo ./elastic-agent install -f --url=https:/…

---

## [Status alerting](https://discuss.elastic.co/t/status-alerting/335403)

<div class="topic-metadata">

**Author:** [@Naina\_Sharma](https://discuss.elastic.co/u/Naina_Sharma)\
**Replies:** 1\
**Last updated:** [June 16, 2023, 11:42am UTC](https://discuss.elastic.co/t/status-alerting/335403 "2023-06-16T11:42:30Z")

</div>

I am trying to create alerts where I want to check if a value of a field stays the same for lets say a minute. Right now I am able to check the number of pods that are pending in the last minute, using document count an…

---

## [OCI( oracle ) Integration elastic-agent](https://discuss.elastic.co/t/oci-oracle-integration-elastic-agent/336207)

<div class="topic-metadata">

**Author:** [@Death](https://discuss.elastic.co/u/Death)\
**Replies:** 0\
**Last updated:** [June 16, 2023, 9:50am UTC](https://discuss.elastic.co/t/oci-oracle-integration-elastic-agent/336207 "2023-06-16T09:50:21Z")

</div>

Hello, can be to know, well be created native connector to OCI ( Oracle Cloud Inf) for get logs from Audit oracle and logs Load Balancer and WAFv2 or Edge policy? whether expansion of support of Oracle is planned except…

---

## [Docker elasticsearch container : FileSystemException : Not a directory](https://discuss.elastic.co/t/docker-elasticsearch-container-filesystemexception-not-a-directory/336196)

<div class="topic-metadata">

**Author:** [@JulianMeister](https://discuss.elastic.co/u/JulianMeister)\
**Replies:** 3\
**Last updated:** [June 16, 2023, 9:27am UTC](https://discuss.elastic.co/t/docker-elasticsearch-container-filesystemexception-not-a-directory/336196 "2023-06-16T09:27:14Z")

</div>

I have the same issue as described in: I'm getting the error "java.nio.file.FileSystemException: /usr/share/elasticsearch/data/nodes/0: Not a directory" But if I change "/usr/share/elasticsearch/data" to "/usr/share/…

---

## [Rollover Index duplication data,data coming from logstash](https://discuss.elastic.co/t/rollover-index-duplication-data-data-coming-from-logstash/332726)

<div class="topic-metadata">

**Author:** [@PRASHANT\_MEHTA](https://discuss.elastic.co/u/PRASHANT_MEHTA)\
**Replies:** 18\
**Last updated:** [June 16, 2023, 9:26am UTC](https://discuss.elastic.co/t/rollover-index-duplication-data-data-coming-from-logstash/332726 "2023-06-16T09:26:14Z")

</div>

Hello , I'm facing one issue,to elaborate I've 40 elastic index and these are handled by ILM policy with rollover defined.The ilm policy is maintained to send data to new index each day(rollover) and delete after 5 days…

---

## [Docker elasticsearch container : FileSystemException : Not a directory](https://discuss.elastic.co/t/docker-elasticsearch-container-filesystemexception-not-a-directory/330204)

<div class="topic-metadata">

**Author:** [@JackieLaFrite](https://discuss.elastic.co/u/JackieLaFrite)\
**Replies:** 4\
**Last updated:** [June 16, 2023, 8:33am UTC](https://discuss.elastic.co/t/docker-elasticsearch-container-filesystemexception-not-a-directory/330204 "2023-06-16T08:33:10Z")

</div>

I tried to modify the port the docker container of elasticsearch from 9200:9200 to 9201:9200 and since I did that I got this error in the docker container : "message": "uncaught exception in thread \[main\]", "stacktrace…

---

## [Vega chart not aligned in the center](https://discuss.elastic.co/t/vega-chart-not-aligned-in-the-center/336092)

<div class="topic-metadata">

**Author:** [@vincent2mots](https://discuss.elastic.co/u/vincent2mots)\
**Replies:** 2\
**Last updated:** [June 16, 2023, 7:12am UTC](https://discuss.elastic.co/t/vega-chart-not-aligned-in-the-center/336092 "2023-06-16T07:12:16Z")

</div>

Hi there! I'm using a 7.10 version of ES and Kibana. I try to make a chart using VEGA and text marks. Here is my code : { $schema: https://vega.github.io/schema/vega-lite/v4.json // Taille du composant : "au…

---

## [PKI Authentication query](https://discuss.elastic.co/t/pki-authentication-query/334121)

<div class="topic-metadata">

**Author:** [@PRASHANT\_MEHTA](https://discuss.elastic.co/u/PRASHANT_MEHTA)\
**Replies:** 3\
**Last updated:** [June 16, 2023, 6:43am UTC](https://discuss.elastic.co/t/pki-authentication-query/334121 "2023-06-16T06:43:19Z")

</div>

Hello All, I'm using PKI based authentication for accessing kibana,The issue I'm facing is for the very first time using my PKI , I enter my password and it authenticates correctly. But now when I'm accessing the kiba…

---

## [Can we toggle off the new "pin search bar" feature in Kibana 8.8?](https://discuss.elastic.co/t/can-we-toggle-off-the-new-pin-search-bar-feature-in-kibana-8-8/334384)

<div class="topic-metadata">

**Author:** [@Cory34](https://discuss.elastic.co/u/Cory34)\
**Replies:** 1\
**Last updated:** [June 16, 2023, 5:56am UTC](https://discuss.elastic.co/t/can-we-toggle-off-the-new-pin-search-bar-feature-in-kibana-8-8/334384 "2023-06-16T05:56:13Z")

</div>

Is there a way to toggle off this new feature: "Pins the unified search bar and dashboard toolbar to the top of the dashboard page when scrolling \[#145628\]"? It's causing issues with our iFrame-created websites. Thanks…

---

## [Exclude fields from multi\_match](https://discuss.elastic.co/t/exclude-fields-from-multi-match/336034)

<div class="topic-metadata">

**Author:** [@ctatshell](https://discuss.elastic.co/u/ctatshell)\
**Replies:** 4\
**Last updated:** [June 16, 2023, 5:43am UTC](https://discuss.elastic.co/t/exclude-fields-from-multi-match/336034 "2023-06-16T05:43:19Z")

</div>

I have an index with an dynamic object property called "sourceData" which contains various properties. I am trying execute multi\_match using phrase type and one of the analyzers we have setup and the fields we must use "…

---

## [How to use terms as filter item?](https://discuss.elastic.co/t/how-to-use-terms-as-filter-item/335417)

<div class="topic-metadata">

**Author:** [@kain\_su](https://discuss.elastic.co/u/kain_su)\
**Replies:** 4\
**Last updated:** [June 16, 2023, 5:41am UTC](https://discuss.elastic.co/t/how-to-use-terms-as-filter-item/335417 "2023-06-16T05:41:31Z")

</div>

When I just filter terms\_A : \*, lens returns this error response, but I can show count of terms\_A records, does anyone knows what happened?

---

## [API to fetch kibana dashboard visualization ID](https://discuss.elastic.co/t/api-to-fetch-kibana-dashboard-visualization-id/336049)

<div class="topic-metadata">

**Author:** [@Neelam\_Zanvar](https://discuss.elastic.co/u/Neelam_Zanvar)\
**Replies:** 3\
**Last updated:** [June 16, 2023, 4:49am UTC](https://discuss.elastic.co/t/api-to-fetch-kibana-dashboard-visualization-id/336049 "2023-06-16T04:49:14Z")

</div>

Hi i want to fetch the id of a particular visualization in a dashboard using API call. Here is the json for the dashboard. I want to fetch the id of the visualization which is a legacy metric with label Number of users …

---

## [Logstash: Input File Plugin Showing Zero Events](https://discuss.elastic.co/t/logstash-input-file-plugin-showing-zero-events/336097)

<div class="topic-metadata">

**Author:** [@ksaimohan2k](https://discuss.elastic.co/u/ksaimohan2k)\
**Replies:** 2\
**Last updated:** [June 16, 2023, 5:21am UTC](https://discuss.elastic.co/t/logstash-input-file-plugin-showing-zero-events/336097 "2023-06-16T05:21:34Z")

</div>

Hello, I am new to elastic. I am trying to parse XML logs using Logstash. As a result, I am using an input file plugin, and for the filtering process, I am using an XML plugin. Pipeline is running successfully, but show…

---

## [Cannot Run Scripted\_mertic in elastic watcher input part](https://discuss.elastic.co/t/cannot-run-scripted-mertic-in-elastic-watcher-input-part/335834)

<div class="topic-metadata">

**Author:** [@JasonREC](https://discuss.elastic.co/u/JasonREC)\
**Replies:** 4\
**Last updated:** [June 16, 2023, 2:32am UTC](https://discuss.elastic.co/t/cannot-run-scripted-mertic-in-elastic-watcher-input-part/335834 "2023-06-16T02:32:39Z")

</div>

Hi, I am trying to set up a watcher and iterate throught my index. I have a search query which return buckets(region) inside another buckets(pa\_key). The inside bucket (region) has a value called ac\_count and av\_count.…

---

## [Authentication to realm oidc1 failed - Failed to authenticate user with OpenID Connect](https://discuss.elastic.co/t/authentication-to-realm-oidc1-failed-failed-to-authenticate-user-with-openid-connect/335959)

<div class="topic-metadata">

**Author:** [@latif07](https://discuss.elastic.co/u/latif07)\
**Replies:** 1\
**Last updated:** [June 15, 2023, 11:41pm UTC](https://discuss.elastic.co/t/authentication-to-realm-oidc1-failed-failed-to-authenticate-user-with-openid-connect/335959 "2023-06-15T23:41:13Z")

</div>

Hello, I am facing an error when trying to log into Kibana using Keycloak. {"@timestamp":"2023-06-14T08:40:15.478Z", "log.level": "WARN", "message":"Authentication to realm oidc1 failed - Failed to authenticate user wi…

---

## [Can I use the TSVB gauge vizualisation to show the value of a field of the most recent document in a timeframe?](https://discuss.elastic.co/t/can-i-use-the-tsvb-gauge-vizualisation-to-show-the-value-of-a-field-of-the-most-recent-document-in-a-timeframe/336051)

<div class="topic-metadata">

**Author:** [@Harold\_Van\_der\_Veken](https://discuss.elastic.co/u/Harold_Van_der_Veken)\
**Replies:** 1\
**Last updated:** [June 15, 2023, 10:35pm UTC](https://discuss.elastic.co/t/can-i-use-the-tsvb-gauge-vizualisation-to-show-the-value-of-a-field-of-the-most-recent-document-in-a-timeframe/336051 "2023-06-15T22:35:59Z")

</div>

Suppose my timeframe is last week. The most recent document has a field 'online\_systems' with a value = 4. Can I show this value in gauge? Or are there other options to show such a value?

---

## [Automation of adding parent to child relation fields into kibana visualization](https://discuss.elastic.co/t/automation-of-adding-parent-to-child-relation-fields-into-kibana-visualization/336144)

<div class="topic-metadata">

**Author:** [@Ahmedeyhaab](https://discuss.elastic.co/u/Ahmedeyhaab)\
**Replies:** 4\
**Last updated:** [June 15, 2023, 10:32pm UTC](https://discuss.elastic.co/t/automation-of-adding-parent-to-child-relation-fields-into-kibana-visualization/336144 "2023-06-15T22:32:17Z")

</div>

Hi, I have a use case that I upload json file directly to elasticsearch with the following data structure { "field\_1": "string\_value\_1", "field\_2": "numerical\_value\_2", "${parent\_field}": { "${parent\_field}\_…

---

## [Create visualizatio with filter in field](https://discuss.elastic.co/t/create-visualizatio-with-filter-in-field/336014)

<div class="topic-metadata">

**Author:** [@Joao\_Malebo](https://discuss.elastic.co/u/Joao_Malebo)\
**Replies:** 2\
**Last updated:** [June 15, 2023, 10:29pm UTC](https://discuss.elastic.co/t/create-visualizatio-with-filter-in-field/336014 "2023-06-15T22:29:03Z")

</div>

How to create a visualization from information contained in a field or with a filter in Kibana. Ex: Group in the graph all processes with the name = joão

---

## [Looking for an index were order matters](https://discuss.elastic.co/t/looking-for-an-index-were-order-matters/334573)

<div class="topic-metadata">

**Author:** [@ron247](https://discuss.elastic.co/u/ron247)\
**Replies:** 3\
**Last updated:** [June 15, 2023, 9:37pm UTC](https://discuss.elastic.co/t/looking-for-an-index-were-order-matters/334573 "2023-06-15T21:37:21Z")

</div>

I am looking for an index that takes into account the order of the search terms. For example, I have the following documents: 1:"bla bla A B bla C bla" 2: "C A bla bla C D" The search string: "bla A" should only retur…

---

## [Nest 7.17 or Elastic.Clients.Elasticsearch 8.1.0 with Server 8.7.1returns a valid JSON but fails to set SearchResponse\<T\>.Documents](https://discuss.elastic.co/t/nest-7-17-or-elastic-clients-elasticsearch-8-1-0-with-server-8-7-1returns-a-valid-json-but-fails-to-set-searchresponse-t-documents/336141)

<div class="topic-metadata">

**Author:** [@Viktor\_Markhelyuk](https://discuss.elastic.co/u/Viktor_Markhelyuk)\
**Replies:** 0\
**Last updated:** [June 15, 2023, 9:01pm UTC](https://discuss.elastic.co/t/nest-7-17-or-elastic-clients-elasticsearch-8-1-0-with-server-8-7-1returns-a-valid-json-but-fails-to-set-searchresponse-t-documents/336141 "2023-06-15T21:01:31Z")

</div>

Nest 5.0.0 with Server 5.6.1 runs correctly: result.DebugInformation shows a valid response JSON and a C# POCO: WX\_ORDER fills in with the response hits.hits.\_source data With Nest 7.17 or Elastic.Clients.Elasticsearc…

---

## [Convert normal logstash output to json output for adx ingestion](https://discuss.elastic.co/t/convert-normal-logstash-output-to-json-output-for-adx-ingestion/336138)

<div class="topic-metadata">

**Author:** [@ashokkrishna99\_Vemur](https://discuss.elastic.co/u/ashokkrishna99_Vemur)\
**Replies:** 2\
**Last updated:** [June 15, 2023, 8:51pm UTC](https://discuss.elastic.co/t/convert-normal-logstash-output-to-json-output-for-adx-ingestion/336138 "2023-06-15T20:51:23Z")

</div>

I have been working on transferring Palo Alto firewall logs(syslog format) to ADX. To achieve this, I developed grok filters and incorporated kv and mutate filters as well. However, I encountered an issue where the outpu…

---

## [Vê logs do IPS do firewall foritgate no Kibana](https://discuss.elastic.co/t/ve-logs-do-ips-do-firewall-foritgate-no-kibana/335908)

<div class="topic-metadata">

**Author:** [@Paulo\_Martins\_de\_Sen](https://discuss.elastic.co/u/Paulo_Martins_de_Sen)\
**Replies:** 4\
**Last updated:** [June 15, 2023, 8:38pm UTC](https://discuss.elastic.co/t/ve-logs-do-ips-do-firewall-foritgate-no-kibana/335908 "2023-06-15T20:38:15Z")

</div>

Hello community, I hope everyone is doing well. I have the following scenario, A fortigate(v7) firewall sending the logs to the logstash server and sending the logs back to the elasticsearch server, even calm, I can re…

---

## [Free license limitation for MSP](https://discuss.elastic.co/t/free-license-limitation-for-msp/336129)

<div class="topic-metadata">

**Author:** [@Rsinsta](https://discuss.elastic.co/u/Rsinsta)\
**Replies:** 5\
**Last updated:** [June 15, 2023, 7:44pm UTC](https://discuss.elastic.co/t/free-license-limitation-for-msp/336129 "2023-06-15T19:44:44Z")

</div>

Hi, We are a startup/MSP and we would like to provide services with the elastic stack. Is it possible to use the free license for that or do we have to buy a commercial one? Thanks!

[Previous page](https://discuss.elastic.co/latest.md?page=637)

[Next page](https://discuss.elastic.co/latest.md?page=639)
