# Latest

**URL:** https://discuss.elastic.co/latest.md?page=651

[Latest](https://discuss.elastic.co/latest.md) · [Categories](https://discuss.elastic.co/categories.md) · [Tags](https://discuss.elastic.co/tags.md)

**Page:** 652

---

## [Kubernetes annotation - array value declaration](https://discuss.elastic.co/t/kubernetes-annotation-array-value-declaration/335304)

<div class="topic-metadata">

**Author:** [@Vijayakumar\_Kannan](https://discuss.elastic.co/u/Vijayakumar_Kannan)\
**Replies:** 3\
**Last updated:** [June 6, 2023, 1:39pm UTC](https://discuss.elastic.co/t/kubernetes-annotation-array-value-declaration/335304 "2023-06-06T13:39:11Z")

</div>

How do we convert the following filebeat config into kubernetes pod annotation level. processors: - decode\_json\_fields: fields: \["message","msg"\] target: "qrapp" add\_error\_key: true kuber…

---

## [Docker-compose instructions lead to "unable to authenticate user \[elastic\]"](https://discuss.elastic.co/t/docker-compose-instructions-lead-to-unable-to-authenticate-user-elastic/333060)

<div class="topic-metadata">

**Author:** [@Pinch](https://discuss.elastic.co/u/Pinch)\
**Replies:** 27\
**Last updated:** [June 6, 2023, 1:09pm UTC](https://discuss.elastic.co/t/docker-compose-instructions-lead-to-unable-to-authenticate-user-elastic/333060 "2023-06-06T13:09:10Z")

</div>

Following these official instructions: Brings me to a state of "Kibana server is not ready yet." in the browser. Inspecting the logs I can see from the Kibana container that kibana\_system is not authenticated. Then c…

---

## [Add custom field for action to teams webhook](https://discuss.elastic.co/t/add-custom-field-for-action-to-teams-webhook/334779)

<div class="topic-metadata">

**Author:** [@fontexD](https://discuss.elastic.co/u/fontexD)\
**Replies:** 3\
**Last updated:** [June 6, 2023, 12:58pm UTC](https://discuss.elastic.co/t/add-custom-field-for-action-to-teams-webhook/334779 "2023-06-06T12:58:02Z")

</div>

im trying to add a custom field from the table of the event but it dosent pass the value into the teams webhook

---

## [Rest API client](https://discuss.elastic.co/t/rest-api-client/335323)

<div class="topic-metadata">

**Author:** [@mhr](https://discuss.elastic.co/u/mhr)\
**Replies:** 1\
**Last updated:** [June 6, 2023, 12:41pm UTC](https://discuss.elastic.co/t/rest-api-client/335323 "2023-06-06T12:41:42Z")

</div>

Do i need to upgrade REST API client version 7.2.1 also after ES up-gradation from version 7.8 to 7.17.

---

## [Best Practice: Update metadata on larger documents](https://discuss.elastic.co/t/best-practice-update-metadata-on-larger-documents/335311)

<div class="topic-metadata">

**Author:** [@Hiketas](https://discuss.elastic.co/u/Hiketas)\
**Replies:** 5\
**Last updated:** [June 6, 2023, 12:21pm UTC](https://discuss.elastic.co/t/best-practice-update-metadata-on-larger-documents/335311 "2023-06-06T12:21:51Z")

</div>

I have a question about best practice in the following scenario: I have documents with some meta fields among others with a full text field which can be up to 10 MB in size. We currently do not use parent/child relation…

---

## [Displaying Latest Image with filter from Log Message](https://discuss.elastic.co/t/displaying-latest-image-with-filter-from-log-message/335160)

<div class="topic-metadata">

**Author:** [@witwit](https://discuss.elastic.co/u/witwit)\
**Replies:** 4\
**Last updated:** [June 6, 2023, 11:19am UTC](https://discuss.elastic.co/t/displaying-latest-image-with-filter-from-log-message/335160 "2023-06-06T11:19:25Z")

</div>

Hi everyone. So currently, I'm getting logs from various services. I manage to tag these services as a field when it's ingested into elasticsearch via logstash. I'm currently stump with one part where i'm trying to disp…

---

## [How to search a value by special character](https://discuss.elastic.co/t/how-to-search-a-value-by-special-character/334611)

<div class="topic-metadata">

**Author:** [@yuswanul](https://discuss.elastic.co/u/yuswanul)\
**Replies:** 17\
**Last updated:** [June 6, 2023, 11:17am UTC](https://discuss.elastic.co/t/how-to-search-a-value-by-special-character/334611 "2023-06-06T11:17:22Z")

</div>

Hi there, so i have a field named uri\_api and some of them have a value like this: /scrt/kpi/v3/code/shean%20jeremy%20patok i want to search other value like that in uri\_api field. how can i achieve it? i already try …

---

## [Hide the time filter in dashboards](https://discuss.elastic.co/t/hide-the-time-filter-in-dashboards/335321)

<div class="topic-metadata">

**Author:** [@Alice\_Ionescu](https://discuss.elastic.co/u/Alice_Ionescu)\
**Replies:** 2\
**Last updated:** [June 6, 2023, 11:08am UTC](https://discuss.elastic.co/t/hide-the-time-filter-in-dashboards/335321 "2023-06-06T11:08:51Z")

</div>

Hello, I have an index pattern for which I did not set a time field. I created a visualization based on this pattern index, and added it to a dashboard. In the dashboard I still have the time picker. How can I make it…

---

## [Kibana Version in Hindi Language](https://discuss.elastic.co/t/kibana-version-in-hindi-language/335277)

<div class="topic-metadata">

**Author:** [@Sandeep\_Raju](https://discuss.elastic.co/u/Sandeep_Raju)\
**Replies:** 1\
**Last updated:** [June 6, 2023, 10:59am UTC](https://discuss.elastic.co/t/kibana-version-in-hindi-language/335277 "2023-06-06T10:59:51Z")

</div>

Hi all, I want a Kibana version in Hindi language that can display everything in Hindi including Dashboard name, visualization Name, options etc. Any setting for language or Kibana version for Hindi language that I can…

---

## [Kibana TSVB - Percentage of Samples crossing Threshold Filter Ratio Always Returning 0 for one Index](https://discuss.elastic.co/t/kibana-tsvb-percentage-of-samples-crossing-threshold-filter-ratio-always-returning-0-for-one-index/334988)

<div class="topic-metadata">

**Author:** [@shgpde](https://discuss.elastic.co/u/shgpde)\
**Replies:** 4\
**Last updated:** [June 6, 2023, 10:55am UTC](https://discuss.elastic.co/t/kibana-tsvb-percentage-of-samples-crossing-threshold-filter-ratio-always-returning-0-for-one-index/334988 "2023-06-06T10:55:38Z")

</div>

Hi, First time poster, I'm having difficulty getting the data I want from a Kibana visualisation and I'm hoping for some insight. I'm using Kibana v7.6.1 and have been running into an issue trying to use a Filter Ratio…

---

## [Performance issue found : Upgade elasticsearch 7.8 to 7.17](https://discuss.elastic.co/t/performance-issue-found-upgade-elasticsearch-7-8-to-7-17/335324)

<div class="topic-metadata">

**Author:** [@Abhishek\_Tiwari1](https://discuss.elastic.co/u/Abhishek_Tiwari1)\
**Replies:** 0\
**Last updated:** [June 6, 2023, 10:53am UTC](https://discuss.elastic.co/t/performance-issue-found-upgade-elasticsearch-7-8-to-7-17/335324 "2023-06-06T10:53:22Z")

</div>

Hi Team, We are facing major performance issue after upgrade elasticsearch from 7.8 to 7.17 by rolling method. Our Query hits elasticsearch using java rest api(7.2.1). Perfomance degrade form 20ms to 300ms. I need to…

---

## [Show HTML Character Entities as symbols in Kibana](https://discuss.elastic.co/t/show-html-character-entities-as-symbols-in-kibana/335191)

<div class="topic-metadata">

**Author:** [@ddoroshenko](https://discuss.elastic.co/u/ddoroshenko)\
**Replies:** 4\
**Last updated:** [June 6, 2023, 10:43am UTC](https://discuss.elastic.co/t/show-html-character-entities-as-symbols-in-kibana/335191 "2023-06-06T10:43:38Z")

</div>

Hi, I have records in ES where symbols are presented as Character Entities. For example | as &#124; and a record could looks like bla&#124;bla&#124;bla. Is it posible in Kibana to show these entities as symbols, i.e. b…

---

## [Role based Access in Kibana](https://discuss.elastic.co/t/role-based-access-in-kibana/335218)

<div class="topic-metadata">

**Author:** [@nitinkapoor](https://discuss.elastic.co/u/nitinkapoor)\
**Replies:** 3\
**Last updated:** [June 6, 2023, 10:23am UTC](https://discuss.elastic.co/t/role-based-access-in-kibana/335218 "2023-06-06T10:23:31Z")

</div>

Hi I have a use case where based on Role user should be able to see only selected Indices for example compliance auditors should be able to see only compliance indices , they should not be able to see any other indices…

---

## [Shuffle sorted documents](https://discuss.elastic.co/t/shuffle-sorted-documents/335255)

<div class="topic-metadata">

**Author:** [@Novel\_one](https://discuss.elastic.co/u/Novel_one)\
**Replies:** 3\
**Last updated:** [June 6, 2023, 10:10am UTC](https://discuss.elastic.co/t/shuffle-sorted-documents/335255 "2023-06-06T10:10:22Z")

</div>

Hi, I want to create a promotional box in my marketplace, with the top rated articles. I dont want always to be the same articles, so i want them be shuffled a little by multiplying the article avg rate by a random num…

---

## [Kibana cluster acces via F5 load balancer](https://discuss.elastic.co/t/kibana-cluster-acces-via-f5-load-balancer/335285)

<div class="topic-metadata">

**Author:** [@kannan2096](https://discuss.elastic.co/u/kannan2096)\
**Replies:** 1\
**Last updated:** [June 6, 2023, 9:31am UTC](https://discuss.elastic.co/t/kibana-cluster-acces-via-f5-load-balancer/335285 "2023-06-06T09:31:18Z")

</div>

Hi I'm new to ELK and I'm doing POC to implement ELK with cluster setup. With the basic cluster configuration of Elasticsearch(2nodes), the Kibana GUI working fine. But via F5 load balance URL it is not working. The log…

---

## [Running elastic search](https://discuss.elastic.co/t/running-elastic-search/335182)

<div class="topic-metadata">

**Author:** [@waqar\_jamali](https://discuss.elastic.co/u/waqar_jamali)\
**Replies:** 1\
**Last updated:** [June 6, 2023, 9:20am UTC](https://discuss.elastic.co/t/running-elastic-search/335182 "2023-06-06T09:20:34Z")

</div>

How can I run elasticsearch using python client on google colab. I have a python code which is running on my machine. I want to run it on google colab or other notebook online platform. What setup or instruction I need f…

---

## [Kibana support for System for Cross-Domain Identity Management (SCIM)](https://discuss.elastic.co/t/kibana-support-for-system-for-cross-domain-identity-management-scim/334930)

<div class="topic-metadata">

**Author:** [@sivanov](https://discuss.elastic.co/u/sivanov)\
**Replies:** 4\
**Last updated:** [June 6, 2023, 8:44am UTC](https://discuss.elastic.co/t/kibana-support-for-system-for-cross-domain-identity-management-scim/334930 "2023-06-06T08:44:22Z")

</div>

Hi, Does Kibana / Elastic Stack support SCIM for identity providers like Microsoft (Azure/AD)? There is no documentation available on the topic. A short info on SCIM systems: SCIM synchronization with Azure Active Dir…

---

## [Single node yellow](https://discuss.elastic.co/t/single-node-yellow/335249)

<div class="topic-metadata">

**Author:** [@decibel83](https://discuss.elastic.co/u/decibel83)\
**Replies:** 2\
**Last updated:** [June 6, 2023, 8:38am UTC](https://discuss.elastic.co/t/single-node-yellow/335249 "2023-06-06T08:38:07Z")

</div>

Hi have a single node elastic cluster which is yellow: GET /\_cluster/health: { "cluster\_name": "log", "status": "yellow", "timed\_out": false, "number\_of\_nodes": 1, "number\_of\_data\_nodes": 1, "act…

---

## [Curator 7 is failing to delete indices](https://discuss.elastic.co/t/curator-7-is-failing-to-delete-indices/335287)

<div class="topic-metadata">

**Author:** [@chiranjeevirao](https://discuss.elastic.co/u/chiranjeevirao)\
**Replies:** 2\
**Last updated:** [June 6, 2023, 8:35am UTC](https://discuss.elastic.co/t/curator-7-is-failing-to-delete-indices/335287 "2023-06-06T08:35:13Z")

</div>

Hi We are using opensearch 1.2.4 (derived from Elasticsearch 7.10.2). We could see in the curator release document that curator 7 will work with Elasticsearch 7.x and is functionally identical to 5.8.4 and uplifted cur…

---

## [Migration from HighRestLevelCLient to ElasticSearchClient](https://discuss.elastic.co/t/migration-from-highrestlevelclient-to-elasticsearchclient/335023)

<div class="topic-metadata">

**Author:** [@neodeveloper](https://discuss.elastic.co/u/neodeveloper)\
**Replies:** 1\
**Last updated:** [June 6, 2023, 8:21am UTC](https://discuss.elastic.co/t/migration-from-highrestlevelclient-to-elasticsearchclient/335023 "2023-06-06T08:21:47Z")

</div>

Good morning, We are planning to upgrade to springboot3.0 and we are heavily using the deprecated client named HighRestLevelClient which is removed in springboot3 and replaced with the new java api client named ElasticS…

---

## [Log4j Vulnerability Elasticsearch 7.8.0](https://discuss.elastic.co/t/log4j-vulnerability-elasticsearch-7-8-0/333035)

<div class="topic-metadata">

**Author:** [@Faisal\_Umer](https://discuss.elastic.co/u/Faisal_Umer)\
**Replies:** 7\
**Last updated:** [June 6, 2023, 8:08am UTC](https://discuss.elastic.co/t/log4j-vulnerability-elasticsearch-7-8-0/333035 "2023-06-06T08:08:01Z")

</div>

We have Elasticsearch 7.8.0 cluster which has CVE-2021-44228. Can we somehow patch it without upgrading the Elasticsearch version? If yes, can you please share any relevant thread or documentation?

---

## [I want to use spark to read data from es, but I don't know what es.net.ssl.keystore.pass is](https://discuss.elastic.co/t/i-want-to-use-spark-to-read-data-from-es-but-i-dont-know-what-es-net-ssl-keystore-pass-is/335210)

<div class="topic-metadata">

**Author:** [@gaorui](https://discuss.elastic.co/u/gaorui)\
**Replies:** 3\
**Last updated:** [June 6, 2023, 7:58am UTC](https://discuss.elastic.co/t/i-want-to-use-spark-to-read-data-from-es-but-i-dont-know-what-es-net-ssl-keystore-pass-is/335210 "2023-06-06T07:58:51Z")

</div>

When I built the es cluster, I used bin/elasticsearch-certutil to generate the CA certificate and p12 certificate, but I did not enter the password, but chose to press Enter directly. When I want to use spark to connect…

---

## [Applying ILM on custom index](https://discuss.elastic.co/t/applying-ilm-on-custom-index/334924)

<div class="topic-metadata">

**Author:** [@hjazz6](https://discuss.elastic.co/u/hjazz6)\
**Replies:** 3\
**Last updated:** [June 6, 2023, 7:53am UTC](https://discuss.elastic.co/t/applying-ilm-on-custom-index/334924 "2023-06-06T07:53:56Z")

</div>

Hi, I am using filebeat 8.3.3 with several inputs and writing them to the same ES 8.3.3. To separate the different inputs on ES, I have the following in my filebeat.yml. output.elasticsearch: indices: - index: "f…

---

## [AppSearch: crawling takes a long time](https://discuss.elastic.co/t/appsearch-crawling-takes-a-long-time/334650)

<div class="topic-metadata">

**Author:** [@andi.avram](https://discuss.elastic.co/u/andi.avram)\
**Replies:** 4\
**Last updated:** [June 6, 2023, 7:32am UTC](https://discuss.elastic.co/t/appsearch-crawling-takes-a-long-time/334650 "2023-06-06T07:32:00Z")

</div>

Dear Elastic community, For one of our clients we are using AppSearch for our search functionality, and we are using the OOTB AppSearch crawler to crawl our websites. We observed that crawling takes quite a long time, …

---

## [How to get docs in aggregated format in ElasticSearch aggregation query?](https://discuss.elastic.co/t/how-to-get-docs-in-aggregated-format-in-elasticsearch-aggregation-query/335292)

<div class="topic-metadata">

**Author:** [@maulik\_trapasiya](https://discuss.elastic.co/u/maulik_trapasiya)\
**Replies:** 0\
**Last updated:** [June 6, 2023, 7:27am UTC](https://discuss.elastic.co/t/how-to-get-docs-in-aggregated-format-in-elasticsearch-aggregation-query/335292 "2023-06-06T07:27:25Z")

</div>

My query { "aggs": { "distinct\_colours": { "terms": { "field": "colour" } } } } Required Result: { "took" : 2037, "timed\_out" : false, "\_shards" : { "total" : 1, "successf…

---

## [TSVB - Top N - Item URL: keep time interval when link to other dashboard](https://discuss.elastic.co/t/tsvb-top-n-item-url-keep-time-interval-when-link-to-other-dashboard/335151)

<div class="topic-metadata">

**Author:** [@Ofir\_Edi](https://discuss.elastic.co/u/Ofir_Edi)\
**Replies:** 2\
**Last updated:** [June 6, 2023, 7:04am UTC](https://discuss.elastic.co/t/tsvb-top-n-item-url-keep-time-interval-when-link-to-other-dashboard/335151 "2023-06-06T07:04:29Z")

</div>

Hi, This is a duplicate of this thread which was not answered. I have TSVB top n visualization of host names and i'm using item URL feature to drilldown to more specific dashboard with the {{key}} place holder. However…

---

## [Failed to parse date field \[message.details.message.keyword\] with format \[strict\_date\_optional\_time\]](https://discuss.elastic.co/t/failed-to-parse-date-field-message-details-message-keyword-with-format-strict-date-optional-time/335099)

<div class="topic-metadata">

**Author:** [@gustavo6](https://discuss.elastic.co/u/gustavo6)\
**Replies:** 0\
**Last updated:** [June 2, 2023, 3:26pm UTC](https://discuss.elastic.co/t/failed-to-parse-date-field-message-details-message-keyword-with-format-strict-date-optional-time/335099 "2023-06-02T15:26:43Z")

</div>

Hi! I'm getting this error: \[essql\] \> Unexpected error from Elasticsearch: illegal\_argument\_exception - failed to parse date field \[message.details.message.keyword\] with format \[strict\_date\_optional\_time\] on this quer…

---

## [Indices in DR Cluster (CCR dest cluster) stuck on forcemerge causing the Space filled up](https://discuss.elastic.co/t/indices-in-dr-cluster-ccr-dest-cluster-stuck-on-forcemerge-causing-the-space-filled-up/335276)

<div class="topic-metadata">

**Author:** [@vikasp](https://discuss.elastic.co/u/vikasp)\
**Replies:** 1\
**Last updated:** [June 6, 2023, 6:01am UTC](https://discuss.elastic.co/t/indices-in-dr-cluster-ccr-dest-cluster-stuck-on-forcemerge-causing-the-space-filled-up/335276 "2023-06-06T06:01:18Z")

</div>

I have 2 elasticsearch clusters deployed in 2 different regions in Amazon EKS. replicating data from east1 to east2 using CCR. I only keep the indices in east2 (dest cluster) for 2 days. 0 day after roller to warm (also…

---

## [CVE-2022-30123	- Rack Vulnerability](https://discuss.elastic.co/t/cve-2022-30123-rack-vulnerability/335274)

<div class="topic-metadata">

**Author:** [@priya\_dhana](https://discuss.elastic.co/u/priya_dhana)\
**Replies:** 1\
**Last updated:** [June 6, 2023, 5:46am UTC](https://discuss.elastic.co/t/cve-2022-30123-rack-vulnerability/335274 "2023-06-06T05:46:47Z")

</div>

Security Scan has flagged Critical CVE-2022-30123 Rack::RELEASE in the logstash 8.7.1 tar file. How can we remove rack or upgrade to a newer version? Thanks, Priya V

---

## [How to use mapper size pluging?](https://discuss.elastic.co/t/how-to-use-mapper-size-pluging/335131)

<div class="topic-metadata">

**Author:** [@Amirhossein\_eidy](https://discuss.elastic.co/u/Amirhossein_eidy)\
**Replies:** 2\
**Last updated:** [June 6, 2023, 5:12am UTC](https://discuss.elastic.co/t/how-to-use-mapper-size-pluging/335131 "2023-06-06T05:12:24Z")

</div>

Hi folks I want to find the largest documents in my indices and I have installed the mapper size plugin and added the field to index as it explained I have two questions now how to add it to index pattern in kibana? …

[Previous page](https://discuss.elastic.co/latest.md?page=650)

[Next page](https://discuss.elastic.co/latest.md?page=652)
