# Latest

**URL:** https://discuss.elastic.co/latest.md?page=642

[Latest](https://discuss.elastic.co/latest.md) · [Categories](https://discuss.elastic.co/categories.md) · [Tags](https://discuss.elastic.co/tags.md)

**Page:** 643

---

## [Configuration of transform data with custom pipeline](https://discuss.elastic.co/t/configuration-of-transform-data-with-custom-pipeline/335923)

<div class="topic-metadata">

**Author:** [@JasonREC](https://discuss.elastic.co/u/JasonREC)\
**Replies:** 2\
**Last updated:** [June 14, 2023, 8:14am UTC](https://discuss.elastic.co/t/configuration-of-transform-data-with-custom-pipeline/335923 "2023-06-14T08:14:49Z")

</div>

Hi all, I am currenly using Elastic APM to monitor my application. and I noticed that transaction log data that created by APM agent is automactilly store in an Elasticsearch index. I want to enrich every doucment befor…

---

## [Info about the free ELK tools](https://discuss.elastic.co/t/info-about-the-free-elk-tools/335044)

<div class="topic-metadata">

**Author:** [@sonujatav35](https://discuss.elastic.co/u/sonujatav35)\
**Replies:** 6\
**Last updated:** [June 14, 2023, 8:57am UTC](https://discuss.elastic.co/t/info-about-the-free-elk-tools/335044 "2023-06-14T08:57:36Z")

</div>

Hi Elasticsearch Community, I need some advice, I am creating a New ELK stack where i am going to store oracle log in ES and by using the logstash. I would like get the some information if i use the below the additional…

---

## [Fleet not working after update](https://discuss.elastic.co/t/fleet-not-working-after-update/335950)

<div class="topic-metadata">

**Author:** [@acosta353](https://discuss.elastic.co/u/acosta353)\
**Replies:** 0\
**Last updated:** [June 14, 2023, 8:33am UTC](https://discuss.elastic.co/t/fleet-not-working-after-update/335950 "2023-06-14T08:33:19Z")

</div>

Hello, Unfortunately, by mistake, one of my elasticsearch hosts updated from version 8.5.3 to 8.8.0, so this caused a lot of problems with my installation. I've already updated the other 2 elasticserver hosts, but now …

---

## [Overwride field "\_time" in splunk](https://discuss.elastic.co/t/overwride-field-time-in-splunk/335944)

<div class="topic-metadata">

**Author:** [@Indeed2000](https://discuss.elastic.co/u/Indeed2000)\
**Replies:** 0\
**Last updated:** [June 14, 2023, 8:12am UTC](https://discuss.elastic.co/t/overwride-field-time-in-splunk/335944 "2023-06-14T08:12:24Z")

</div>

Hi I have logstash config that send logs to Splunk HEC. these data contain field that call "time". Now question is: does it possible to consider "time" as "\_time" on logstash config? FYI: i want to consider this time…

---

## [My xpack license shows valid but monitoring tab is still showing the license got expired](https://discuss.elastic.co/t/my-xpack-license-shows-valid-but-monitoring-tab-is-still-showing-the-license-got-expired/335943)

<div class="topic-metadata">

**Author:** [@Shuvo-Hoque](https://discuss.elastic.co/u/Shuvo-Hoque)\
**Replies:** 0\
**Last updated:** [June 14, 2023, 8:01am UTC](https://discuss.elastic.co/t/my-xpack-license-shows-valid-but-monitoring-tab-is-still-showing-the-license-got-expired/335943 "2023-06-14T08:01:21Z")

</div>

Hi guys! My basic license got expired and I have re-issued and installed the license again using curl -X PUT $HOST/\_xpack/license api . So when I check the license this way : curl -X GET $HOST/\_xpack/license ; It show…

---

## [Shards are going to Intialized state againa and again, like in every 15 mins](https://discuss.elastic.co/t/shards-are-going-to-intialized-state-againa-and-again-like-in-every-15-mins/335902)

<div class="topic-metadata">

**Author:** [@priyankaMS](https://discuss.elastic.co/u/priyankaMS)\
**Replies:** 5\
**Last updated:** [June 14, 2023, 6:59am UTC](https://discuss.elastic.co/t/shards-are-going-to-intialized-state-againa-and-again-like-in-every-15-mins/335902 "2023-06-14T06:59:02Z")

</div>

My Elasticsearch cluster is going to yellow state in about every 15 min, becuase 2 replica shards are going to initialization state. After 5 mins or so, cluster is going back to green state. Error Logs: \[o.e.t.Outbou…

---

## [java.lang.OutOfMemoryError: Java heap space (logstash, http\_poller)](https://discuss.elastic.co/t/java-lang-outofmemoryerror-java-heap-space-logstash-http-poller/335935)

<div class="topic-metadata">

**Author:** [@Indeed2000](https://discuss.elastic.co/u/Indeed2000)\
**Replies:** 0\
**Last updated:** [June 14, 2023, 6:39am UTC](https://discuss.elastic.co/t/java-lang-outofmemoryerror-java-heap-space-logstash-http-poller/335935 "2023-06-14T06:39:55Z")

</div>

Hi I run logstash to fetch data from infludb via http\_poller and return below error: java.lang.OutOfMemoryError: Java heap space Here is the jvm.options: -Xms10g -Xmx10g Now question is: data locate on influxdb are …

---

## [Index to red state cluster](https://discuss.elastic.co/t/index-to-red-state-cluster/335763)

<div class="topic-metadata">

**Author:** [@DJ\_Zhu](https://discuss.elastic.co/u/DJ_Zhu)\
**Replies:** 10\
**Last updated:** [June 14, 2023, 6:59am UTC](https://discuss.elastic.co/t/index-to-red-state-cluster/335763 "2023-06-14T06:59:46Z")

</div>

I have a question regarding shard selection during index/bulk operations in Elasticsearch version 6.8.6. In my cluster, I have three data nodes: A, B, and C. The shards (with no replicas) are evenly allocated across the…

---

## [ILM, content base, re-indexing](https://discuss.elastic.co/t/ilm-content-base-re-indexing/335859)

<div class="topic-metadata">

**Author:** [@wil93](https://discuss.elastic.co/u/wil93)\
**Replies:** 4\
**Last updated:** [June 14, 2023, 6:42am UTC](https://discuss.elastic.co/t/ilm-content-base-re-indexing/335859 "2023-06-14T06:42:19Z")

</div>

Hello, I'm looking for some good advice here (and I do know that the standard answer is ' it depends ' :slight\_smile: which is a justified answer BTW, no worries ... The situation / challenge: a large index: we're ab…

---

## [How to synchronise data (PostgreSQL + MongoDB) in ES](https://discuss.elastic.co/t/how-to-synchronise-data-postgresql-mongodb-in-es/335876)

<div class="topic-metadata">

**Author:** [@stephane\_chan](https://discuss.elastic.co/u/stephane_chan)\
**Replies:** 3\
**Last updated:** [June 14, 2023, 6:32am UTC](https://discuss.elastic.co/t/how-to-synchronise-data-postgresql-mongodb-in-es/335876 "2023-06-14T06:32:37Z")

</div>

Hi, I'm new in Elasticsearch. I have Logstash configurations with postgresql and mongodb as data source (data.postgresql.conf, data.mongodb.conf), my problem is that I have to launch the logstash configuration of postg…

---

## [Multiple ES-Hadoop versions detected in the classpath](https://discuss.elastic.co/t/multiple-es-hadoop-versions-detected-in-the-classpath/335852)

<div class="topic-metadata">

**Author:** [@Suna.Y](https://discuss.elastic.co/u/Suna.Y)\
**Replies:** 3\
**Last updated:** [June 14, 2023, 3:29am UTC](https://discuss.elastic.co/t/multiple-es-hadoop-versions-detected-in-the-classpath/335852 "2023-06-14T03:29:44Z")

</div>

ERROR: Multiple ES-Hadoop versions detected - Elastic Stack / Elasticsearch - Discuss the Elastic Stack I met the same question as above. If keep those versions, it occurs Multiple ES-Hadoop versions detected as follow…

---

## [Adding added field to index](https://discuss.elastic.co/t/adding-added-field-to-index/335440)

<div class="topic-metadata">

**Author:** [@rexxdad](https://discuss.elastic.co/u/rexxdad)\
**Replies:** 12\
**Last updated:** [June 14, 2023, 2:33am UTC](https://discuss.elastic.co/t/adding-added-field-to-index/335440 "2023-06-14T02:33:17Z")

</div>

i use the docker elk stack on macos with the logstash http pipeline to accept our apps http posts as input it created an index (I didn't before) reviewing the content, there are two fields that combined could make a ge…

---

## [Backup Snapshot](https://discuss.elastic.co/t/backup-snapshot/335856)

<div class="topic-metadata">

**Author:** [@marotaal](https://discuss.elastic.co/u/marotaal)\
**Replies:** 0\
**Last updated:** [June 13, 2023, 10:10am UTC](https://discuss.elastic.co/t/backup-snapshot/335856 "2023-06-13T10:10:59Z")

</div>

Hello I want to perform the next backup system, but I don’t know how I can do it. Perform the backup of an explicit index of the current day example filebeat-%DD%MM%YYYY to the repository /backup. Export from the …

---

## [Logstash in elasticcloud without elastic agent](https://discuss.elastic.co/t/logstash-in-elasticcloud-without-elastic-agent/335840)

<div class="topic-metadata">

**Author:** [@Sivaramakrishhna\_Amb](https://discuss.elastic.co/u/Sivaramakrishhna_Amb)\
**Replies:** 1\
**Last updated:** [June 13, 2023, 11:50pm UTC](https://discuss.elastic.co/t/logstash-in-elasticcloud-without-elastic-agent/335840 "2023-06-13T23:50:18Z")

</div>

Hi, we are looking for logstash without elastic agent inetgration in elastic cloud. I'm not able to find simple logstash (without elasticagent) in elastic cloud. As our network devices will send logs to logstash th…

---

## [Fetching warnings from Elasticsearch response](https://discuss.elastic.co/t/fetching-warnings-from-elasticsearch-response/335903)

<div class="topic-metadata">

**Author:** [@Daniel\_Schneider](https://discuss.elastic.co/u/Daniel_Schneider)\
**Replies:** 0\
**Last updated:** [June 13, 2023, 6:45pm UTC](https://discuss.elastic.co/t/fetching-warnings-from-elasticsearch-response/335903 "2023-06-13T18:45:27Z")

</div>

Hi, Is it possible to fetch warnings from Elasticsearch response in JAVA? E.g., when Elasticsearch security is not enabled rest client logs appropriate warning that comes with response: \[WARN \] o.e.c.RestClient - reque…

---

## [About the \`index()\` method of \`Elasticsearch Python Client\` library, is it using PUT or POST?](https://discuss.elastic.co/t/about-the-index-method-of-elasticsearch-python-client-library-is-it-using-put-or-post/335920)

<div class="topic-metadata">

**Author:** [@Mike\_Z](https://discuss.elastic.co/u/Mike_Z)\
**Replies:** 1\
**Last updated:** [June 13, 2023, 11:35pm UTC](https://discuss.elastic.co/t/about-the-index-method-of-elasticsearch-python-client-library-is-it-using-put-or-post/335920 "2023-06-13T23:35:24Z")

</div>

We are looking into a Python library Elasticsearch Python Client, and its official online document contains the below example for ingesting data into Elastic. We hope to make the ingest action idempotent, so we wonder w…

---

## [Elasticsearch 7.17.10 stuck with "triggering scheduled \[ML\] maintenance tasks"](https://discuss.elastic.co/t/elasticsearch-7-17-10-stuck-with-triggering-scheduled-ml-maintenance-tasks/335545)

<div class="topic-metadata">

**Author:** [@ewolfman](https://discuss.elastic.co/u/ewolfman)\
**Replies:** 7\
**Last updated:** [June 13, 2023, 10:33pm UTC](https://discuss.elastic.co/t/elasticsearch-7-17-10-stuck-with-triggering-scheduled-ml-maintenance-tasks/335545 "2023-06-13T22:33:32Z")

</div>

Hi, After using Elasticsearch on my laptop for quite a while without problems, I recently upgraded from 7.17.7 to 7.17.10. Since that, I encountered twice a total freeze/stuck behavior. First time I stopped and restarte…

---

## [\[Agent-Netflow\] Anomaly Detect for spikes on coms between 2 IP](https://discuss.elastic.co/t/agent-netflow-anomaly-detect-for-spikes-on-coms-between-2-ip/335542)

<div class="topic-metadata">

**Author:** [@isaqueprofeta](https://discuss.elastic.co/u/isaqueprofeta)\
**Replies:** 5\
**Last updated:** [June 13, 2023, 9:49pm UTC](https://discuss.elastic.co/t/agent-netflow-anomaly-detect-for-spikes-on-coms-between-2-ip/335542 "2023-06-13T21:49:52Z")

</div>

Hey everyone, thanks for having me, I'm currently working with Elastic 8.3 using an Agent (Fleet managed) with Netflow Integration. My current goal is to create two ML Jobs for spikes on traffic between 2 IP's, but I …

---

## [Are mappings carried over when using daily indexes?](https://discuss.elastic.co/t/are-mappings-carried-over-when-using-daily-indexes/335807)

<div class="topic-metadata">

**Author:** [@dfinn](https://discuss.elastic.co/u/dfinn)\
**Replies:** 6\
**Last updated:** [June 13, 2023, 9:36pm UTC](https://discuss.elastic.co/t/are-mappings-carried-over-when-using-daily-indexes/335807 "2023-06-13T21:36:15Z")

</div>

We are looking into an issue where we continue to hit field limits. We have been bumping them but we know this is not a permanent solution and we need to find a long term solution. We are using daily indexes that we ar…

---

## [This output type currently does not support connectivity to a remote Elasticsearch cluster](https://discuss.elastic.co/t/this-output-type-currently-does-not-support-connectivity-to-a-remote-elasticsearch-cluster/335914)

<div class="topic-metadata">

**Author:** [@Verdugo\_Gonzalo](https://discuss.elastic.co/u/Verdugo_Gonzalo)\
**Replies:** 0\
**Last updated:** [June 13, 2023, 8:45pm UTC](https://discuss.elastic.co/t/this-output-type-currently-does-not-support-connectivity-to-a-remote-elasticsearch-cluster/335914 "2023-06-13T20:45:26Z")

</div>

Greetings, I have the following error in fleet that I can't fix. This output type currently does not support connectivity to a remote Elasticsearch cluster. I share the elasticsearch.yml, maybe some configuration is g…

---

## [Is it possible to redact parts of the captured body in NodeJS APM?](https://discuss.elastic.co/t/is-it-possible-to-redact-parts-of-the-captured-body-in-nodejs-apm/335804)

<div class="topic-metadata">

**Author:** [@pocketcolin](https://discuss.elastic.co/u/pocketcolin)\
**Replies:** 5\
**Last updated:** [June 13, 2023, 8:31pm UTC](https://discuss.elastic.co/t/is-it-possible-to-redact-parts-of-the-captured-body-in-nodejs-apm/335804 "2023-06-13T20:31:45Z")

</div>

I'm using the NodeJS APM agent for capturing activity on my server. I currently have the APM init configured with captureBody: 'errors' which is great for debugging, but it doesn't seem to redact anything which means tha…

---

## [Aggregate data per document](https://discuss.elastic.co/t/aggregate-data-per-document/334812)

<div class="topic-metadata">

**Author:** [@JohnJoe](https://discuss.elastic.co/u/JohnJoe)\
**Replies:** 2\
**Last updated:** [June 13, 2023, 7:18pm UTC](https://discuss.elastic.co/t/aggregate-data-per-document/334812 "2023-06-13T19:18:31Z")

</div>

Hi All, I am wondering if the following is possible. I want to be able aggregate nested data within a document and then filter by the aggregated data. So if we have PUT warehouse/ { "mappings": { "properties": { …

---

## [Elastic agent unable to send logs to elasticsearch](https://discuss.elastic.co/t/elastic-agent-unable-to-send-logs-to-elasticsearch/335870)

<div class="topic-metadata">

**Author:** [@kafikone](https://discuss.elastic.co/u/kafikone)\
**Replies:** 1\
**Last updated:** [June 13, 2023, 6:47pm UTC](https://discuss.elastic.co/t/elastic-agent-unable-to-send-logs-to-elasticsearch/335870 "2023-06-13T18:47:51Z")

</div>

I deployed elasticsearch, kibana and logstash on a CentOS 7 virtual machine, and everything is working correctly. Then I created a fleet server and installed an elastic agent on a Windows 11 Vm. The status of my agent is…

---

## [When create controls in kibana Visualize : message '00' index doesn't match any options!](https://discuss.elastic.co/t/when-create-controls-in-kibana-visualize-message-00-index-doesnt-match-any-options/335728)

<div class="topic-metadata">

**Author:** [@Changjae\_Lee](https://discuss.elastic.co/u/Changjae_Lee)\
**Replies:** 3\
**Last updated:** [June 13, 2023, 6:22pm UTC](https://discuss.elastic.co/t/when-create-controls-in-kibana-visualize-message-00-index-doesnt-match-any-options/335728 "2023-06-13T18:22:10Z")

</div>

i'got the message. visualize controls \> Index Pattern \> "\_\_\_\_" (index name) doesn't match any options is it a version problem? need to update?

---

## [Fleet-server is unauthorized on indice](https://discuss.elastic.co/t/fleet-server-is-unauthorized-on-indice/332566)

<div class="topic-metadata">

**Author:** [@stenbot1](https://discuss.elastic.co/u/stenbot1)\
**Replies:** 3\
**Last updated:** [June 13, 2023, 5:59pm UTC](https://discuss.elastic.co/t/fleet-server-is-unauthorized-on-indice/332566 "2023-06-13T17:59:56Z")

</div>

Hello! I am pretty green when it comes to Elastic but I recently set up a brand new stack to test ingesting a log file. I installed the Elastic Agent on a Windows machine that outputs logs to a file. I have the integrat…

---

## [How to find the number of affected results from Collapse?](https://discuss.elastic.co/t/how-to-find-the-number-of-affected-results-from-collapse/335896)

<div class="topic-metadata">

**Author:** [@\_zogaj](https://discuss.elastic.co/u/_zogaj)\
**Replies:** 0\
**Last updated:** [June 13, 2023, 4:53pm UTC](https://discuss.elastic.co/t/how-to-find-the-number-of-affected-results-from-collapse/335896 "2023-06-13T16:53:57Z")

</div>

I am using collapse to remove duplicated docs. How to find affected results from Collapse ?

---

## [Unable to show Current & Max values in Gauge or Goal](https://discuss.elastic.co/t/unable-to-show-current-max-values-in-gauge-or-goal/335864)

<div class="topic-metadata">

**Author:** [@Sandeep\_Raju](https://discuss.elastic.co/u/Sandeep_Raju)\
**Replies:** 1\
**Last updated:** [June 13, 2023, 4:11pm UTC](https://discuss.elastic.co/t/unable-to-show-current-max-values-in-gauge-or-goal/335864 "2023-06-13T16:11:31Z")

</div>

Hi all, I'm having 2 fields, currentscore and maximumscore in my indexpattern I'm trying to show How much my current score is compared to max value or goal it must achieve. Both current score and max score are in dyna…

---

## [Normalizing the Huawei firewall logs](https://discuss.elastic.co/t/normalizing-the-huawei-firewall-logs/335861)

<div class="topic-metadata">

**Author:** [@Imad\_TAMELGHAGHET](https://discuss.elastic.co/u/Imad_TAMELGHAGHET)\
**Replies:** 4\
**Last updated:** [June 13, 2023, 3:07pm UTC](https://discuss.elastic.co/t/normalizing-the-huawei-firewall-logs/335861 "2023-06-13T15:07:58Z")

</div>

Hello , I am actually working on a ELK SIEM project, and one of the logs sources i am woking with is a Huawei Firewall .Since Huawei firewall logs have differents formats, I would appreciate some suggestions and insight…

---

## [Adding a negative boost in a multi\_match query](https://discuss.elastic.co/t/adding-a-negative-boost-in-a-multi-match-query/335534)

<div class="topic-metadata">

**Author:** [@daansk44](https://discuss.elastic.co/u/daansk44)\
**Replies:** 3\
**Last updated:** [June 13, 2023, 2:52pm UTC](https://discuss.elastic.co/t/adding-a-negative-boost-in-a-multi-match-query/335534 "2023-06-13T14:52:49Z")

</div>

Hi everyone, I just started with Elastic Search I wanted to make some items in the query less relevant, so I am trying to give them a negative boost (make the two items in the must\_not sub-query less relevant). And exa…

---

## [AppSearch: Web Crawler - Indexing field with multiple values](https://discuss.elastic.co/t/appsearch-web-crawler-indexing-field-with-multiple-values/335361)

<div class="topic-metadata">

**Author:** [@StefanHeijden](https://discuss.elastic.co/u/StefanHeijden)\
**Replies:** 5\
**Last updated:** [June 13, 2023, 2:52pm UTC](https://discuss.elastic.co/t/appsearch-web-crawler-indexing-field-with-multiple-values/335361 "2023-06-13T14:52:36Z")

</div>

Hello, We are using de WebCrawler to index pages from our websites. We are using some custom metatags to add extra data to each document. We want to add a field "persons" which can contain 0 or more persons. How can we …

[Previous page](https://discuss.elastic.co/latest.md?page=641)

[Next page](https://discuss.elastic.co/latest.md?page=643)
