# Latest

**URL:** https://discuss.elastic.co/latest.md?page=654

[Latest](https://discuss.elastic.co/latest.md) · [Categories](https://discuss.elastic.co/categories.md) · [Tags](https://discuss.elastic.co/tags.md)

**Page:** 655

---

## [Synonyms and semantic search](https://discuss.elastic.co/t/synonyms-and-semantic-search/334880)

<div class="topic-metadata">

**Author:** [@Rahul\_Agarwal1](https://discuss.elastic.co/u/Rahul_Agarwal1)\
**Replies:** 2\
**Last updated:** [June 3, 2023, 5:37pm UTC](https://discuss.elastic.co/t/synonyms-and-semantic-search/334880 "2023-06-03T17:37:02Z")

</div>

Need your help with one more thing. What is the best way to support synonyms (we have our own custom list) with semantic search?? Couldn't find anything related to this in the documentation.

---

## [Alerts not appearing after 8.5.2 \> 8.8.0 upgrade](https://discuss.elastic.co/t/alerts-not-appearing-after-8-5-2-8-8-0-upgrade/335136)

<div class="topic-metadata">

**Author:** [@bfarren240](https://discuss.elastic.co/u/bfarren240)\
**Replies:** 0\
**Last updated:** [June 3, 2023, 3:23pm UTC](https://discuss.elastic.co/t/alerts-not-appearing-after-8-5-2-8-8-0-upgrade/335136 "2023-06-03T15:23:42Z")

</div>

I noticed that alerts are no longer appearing in the Security \> Alerts view after a 8.5.2 \> 8.8.0 upgrade. The noisy 'Component Object Model Hijacking' rule is no longer appearing during the usual browser upgrades, and …

---

## [Highlighting and text\_expansion query](https://discuss.elastic.co/t/highlighting-and-text-expansion-query/334679)

<div class="topic-metadata">

**Author:** [@Mark\_Harwood1](https://discuss.elastic.co/u/Mark_Harwood1)\
**Replies:** 2\
**Last updated:** [June 3, 2023, 2:04pm UTC](https://discuss.elastic.co/t/highlighting-and-text-expansion-query/334679 "2023-06-03T14:04:54Z")

</div>

Playing with the new ELSER model and the text\_expansion query in 8.8 which looks to be matching OK. Now I want end users to understand why documents matched but can't get highlighting to work. Does it? I've tried settin…

---

## [Grouping And Ordering Log is Posible?](https://discuss.elastic.co/t/grouping-and-ordering-log-is-posible/335017)

<div class="topic-metadata">

**Author:** [@aidensV](https://discuss.elastic.co/u/aidensV)\
**Replies:** 2\
**Last updated:** [June 3, 2023, 1:11pm UTC](https://discuss.elastic.co/t/grouping-and-ordering-log-is-posible/335017 "2023-06-03T13:11:30Z")

</div>

I have Log with example : (Case 1) CHAN1 : 23:57:05:89 |Message Start CHAN1 : 23:57:05:89 |Lorem CHAN1 : 23:57:05:89 |Ipsum CHAN1 : 23:57:05:89 |Dolor CHAN99i : 23:57:05:89 |Message Start CHAN99i : 23:57:05:89 |Lo…

---

## [ No config files found in path {:path=\>"/etc/logstash/conf.d/\*.conf"}](https://discuss.elastic.co/t/no-config-files-found-in-path-path-etc-logstash-conf-d-conf/335106)

<div class="topic-metadata">

**Author:** [@karma\_services](https://discuss.elastic.co/u/karma_services)\
**Replies:** 1\
**Last updated:** [June 3, 2023, 5:28am UTC](https://discuss.elastic.co/t/no-config-files-found-in-path-path-etc-logstash-conf-d-conf/335106 "2023-06-03T05:28:55Z")

</div>

I have installed ELK stack via debian package on Ubuntu Server. I want to send pfsense logs to logstash. File Settings: 1- /etc/logstash/conf.d/syslog.conf input { tcp { port =\> 514 type =\> "pfsense" } udp { …

---

## [I have two Elastic cloud indices on the same cluster both have one common field Transactionid , Can I join both indices to get combined results](https://discuss.elastic.co/t/i-have-two-elastic-cloud-indices-on-the-same-cluster-both-have-one-common-field-transactionid-can-i-join-both-indices-to-get-combined-results/334915)

<div class="topic-metadata">

**Author:** [@nitinkapoor](https://discuss.elastic.co/u/nitinkapoor)\
**Replies:** 3\
**Last updated:** [June 3, 2023, 2:50am UTC](https://discuss.elastic.co/t/i-have-two-elastic-cloud-indices-on-the-same-cluster-both-have-one-common-field-transactionid-can-i-join-both-indices-to-get-combined-results/334915 "2023-06-03T02:50:38Z")

</div>

I have two Elastic cloud indices on the same cluster both have one common field Transactionid , Can I join both indices to get combined results

---

## [ILM frozen data on amazon Glacier?](https://discuss.elastic.co/t/ilm-frozen-data-on-amazon-glacier/335125)

<div class="topic-metadata">

**Author:** [@shani\_angarkadu](https://discuss.elastic.co/u/shani_angarkadu)\
**Replies:** 1\
**Last updated:** [June 3, 2023, 2:48am UTC](https://discuss.elastic.co/t/ilm-frozen-data-on-amazon-glacier/335125 "2023-06-03T02:48:20Z")

</div>

We have frozen data in S3 bucket. We would like to use glacier instead of s3. Is it possible?

---

## [Visualization in timeline format](https://discuss.elastic.co/t/visualization-in-timeline-format/334448)

<div class="topic-metadata">

**Author:** [@Leandro\_Salamaia](https://discuss.elastic.co/u/Leandro_Salamaia)\
**Replies:** 2\
**Last updated:** [June 3, 2023, 1:35am UTC](https://discuss.elastic.co/t/visualization-in-timeline-format/334448 "2023-06-03T01:35:26Z")

</div>

I need to create a view in kibana that shows the time difference between a Status true message and a Status false message but I haven't found a way yet if anyone can give me some tips log example Device:S0101 Status:1…

---

## [Canva IMAGE moving](https://discuss.elastic.co/t/canva-image-moving/332339)

<div class="topic-metadata">

**Author:** [@ifalanrocha](https://discuss.elastic.co/u/ifalanrocha)\
**Replies:** 4\
**Last updated:** [June 2, 2023, 8:45pm UTC](https://discuss.elastic.co/t/canva-image-moving/332339 "2023-06-02T20:45:35Z")

</div>

Hello everyone, I hope you are well. I need to define margins on my elements inside the canvas, but when I use padding, only the canvasRenderE1 modifies, I would like to move the image. image dataurl={asset "asset-98f5…

---

## [LDAP/AD Configuration - w/o GOLD License](https://discuss.elastic.co/t/ldap-ad-configuration-w-o-gold-license/335116)

<div class="topic-metadata">

**Author:** [@mreed](https://discuss.elastic.co/u/mreed)\
**Replies:** 0\
**Last updated:** [June 2, 2023, 6:40pm UTC](https://discuss.elastic.co/t/ldap-ad-configuration-w-o-gold-license/335116 "2023-06-02T18:40:15Z")

</div>

Hello all, My apologies if this is a long post. I'm looking for some advice around integrating LDAP (Active Directory) logins via Kibana using a basic license (unfortunately we can't afford to pay for the Gold license …

---

## [Unable to initialize Fleet on Kibana in Ubuntu 22.04](https://discuss.elastic.co/t/unable-to-initialize-fleet-on-kibana-in-ubuntu-22-04/334618)

<div class="topic-metadata">

**Author:** [@Calvy93](https://discuss.elastic.co/u/Calvy93)\
**Replies:** 5\
**Last updated:** [June 2, 2023, 4:36pm UTC](https://discuss.elastic.co/t/unable-to-initialize-fleet-on-kibana-in-ubuntu-22-04/334618 "2023-06-02T16:36:40Z")

</div>

I'm currently trying to set up a fleet in Kibana as this seems to be a prerequisite for using a suricata module, but I can't get past the error message "Unable to initialize Fleet - An internal server error occured. Chec…

---

## [Is one of Exceptions](https://discuss.elastic.co/t/is-one-of-exceptions/334992)

<div class="topic-metadata">

**Author:** [@emmanuel\_lankford](https://discuss.elastic.co/u/emmanuel_lankford)\
**Replies:** 1\
**Last updated:** [June 2, 2023, 4:18pm UTC](https://discuss.elastic.co/t/is-one-of-exceptions/334992 "2023-06-02T16:18:10Z")

</div>

Just a quick question, for 8.7 it is a little unclear in the documentation if "is one of" allows for wildcarding values or if matches is the only way. If matches is the only way, will there be a more efficient way to add…

---

## [Bulk Indexing of signals failed: object mapping for \[host\] tried to parse field \[host\] as object, but found a concrete value name](https://discuss.elastic.co/t/bulk-indexing-of-signals-failed-object-mapping-for-host-tried-to-parse-field-host-as-object-but-found-a-concrete-value-name/334705)

<div class="topic-metadata">

**Author:** [@UP\_NEWS](https://discuss.elastic.co/u/UP_NEWS)\
**Replies:** 1\
**Last updated:** [June 2, 2023, 3:53pm UTC](https://discuss.elastic.co/t/bulk-indexing-of-signals-failed-object-mapping-for-host-tried-to-parse-field-host-as-object-but-found-a-concrete-value-name/334705 "2023-06-02T15:53:18Z")

</div>

Hi team, the parser used for Kaspersky, more precisely in the host field, does not allow the triggering of the rule relating to the detection of malicious files once the conditions are met.

---

## [Java apm agent not collecting all the transactions](https://discuss.elastic.co/t/java-apm-agent-not-collecting-all-the-transactions/335102)

<div class="topic-metadata">

**Author:** [@mancharagopan](https://discuss.elastic.co/u/mancharagopan)\
**Replies:** 0\
**Last updated:** [June 2, 2023, 3:49pm UTC](https://discuss.elastic.co/t/java-apm-agent-not-collecting-all-the-transactions/335102 "2023-06-02T15:49:53Z")

</div>

If you are asking about a problem you are experiencing, please use the following template, as it will help us help you. If you have a different problem, please delete all of this text :slight\_smile: TIP 1: select at lea…

---

## [Elastic detection rules fail](https://discuss.elastic.co/t/elastic-detection-rules-fail/334547)

<div class="topic-metadata">

**Author:** [@xqaiviwjxzw](https://discuss.elastic.co/u/xqaiviwjxzw)\
**Replies:** 1\
**Last updated:** [June 2, 2023, 3:46pm UTC](https://discuss.elastic.co/t/elastic-detection-rules-fail/334547 "2023-06-02T15:46:43Z")

</div>

Rule failure at May 29, 2023 @ 12:09:44.438 Bulk Indexing of signals failed: ResponseError: search\_phase\_execution\_exception Caused by: illegal\_argument\_exception: Can't sort on field \[event.ingested\]; the field has…

---

## [Existing index and lifecycle policy](https://discuss.elastic.co/t/existing-index-and-lifecycle-policy/334666)

<div class="topic-metadata">

**Author:** [@zen.xen](https://discuss.elastic.co/u/zen.xen)\
**Replies:** 2\
**Last updated:** [June 2, 2023, 3:23pm UTC](https://discuss.elastic.co/t/existing-index-and-lifecycle-policy/334666 "2023-06-02T15:23:49Z")

</div>

Hello, I need some help, I've seen many web pages how to configure it but none of them were helpfull. My existing index (daily index) is filebeat-exch-8.7.1-2023.05.30 I have created lifecycle policy 2-days whe…

---

## [Stack Monitoring Alerts Disk Usage, how to get the node name only?](https://discuss.elastic.co/t/stack-monitoring-alerts-disk-usage-how-to-get-the-node-name-only/335012)

<div class="topic-metadata">

**Author:** [@leandrojmp](https://discuss.elastic.co/u/leandrojmp)\
**Replies:** 2\
**Last updated:** [June 2, 2023, 3:19pm UTC](https://discuss.elastic.co/t/stack-monitoring-alerts-disk-usage-how-to-get-the-node-name-only/335012 "2023-06-02T15:19:03Z")

</div>

Hello, I'm using the built-in Disk Usage rule in Kibana Alert on my monitoring cluster to alert me when a node reaches more than 94% of disk usage (I've changed my watermarks), this works fine, but now I need to send th…

---

## [Kibana8.8.0 error with 'guidedOnboarding'](https://discuss.elastic.co/t/kibana8-8-0-error-with-guidedonboarding/334700)

<div class="topic-metadata">

**Author:** [@jiwon](https://discuss.elastic.co/u/jiwon)\
**Replies:** 3\
**Last updated:** [June 2, 2023, 2:59pm UTC](https://discuss.elastic.co/t/kibana8-8-0-error-with-guidedonboarding/334700 "2023-06-02T14:59:46Z")

</div>

hello :slight\_smile: I just installed Elasticsearch and Kibana. but I have some problem. I opened Kibana web browser to get started. And I input my enrollment token, username and password. enrollment token, username …

---

## [Finding user\_message index pattern for Elastic Certified Analyst Exam](https://discuss.elastic.co/t/finding-user-message-index-pattern-for-elastic-certified-analyst-exam/333380)

<div class="topic-metadata">

**Author:** [@StratCharl](https://discuss.elastic.co/u/StratCharl)\
**Replies:** 0\
**Last updated:** [May 14, 2023, 12:50pm UTC](https://discuss.elastic.co/t/finding-user-message-index-pattern-for-elastic-certified-analyst-exam/333380 "2023-05-14T12:50:36Z")

</div>

Hello, I have started the Elastic Certified Analyst Exam and am required to use the user\_message index pattern. However I cannot find it / how to add it. Any help would be appreciated on how to continue.

---

## [Problem with login after upgrading to 8.8.0](https://discuss.elastic.co/t/problem-with-login-after-upgrading-to-8-8-0/335083)

<div class="topic-metadata">

**Author:** [@ccaillet](https://discuss.elastic.co/u/ccaillet)\
**Replies:** 1\
**Last updated:** [June 2, 2023, 2:40pm UTC](https://discuss.elastic.co/t/problem-with-login-after-upgrading-to-8-8-0/335083 "2023-06-02T14:40:30Z")

</div>

Hi all, I've upgrade a cluster from 8.7.1 to 8.8.0 it's a small cluster with 3 nodes and two kibana instances. All is working well until the upgrade to 8.8.0. Globally no error during upgrade BUT unable to log in throug…

---

## [RegexpError: undefined](https://discuss.elastic.co/t/regexperror-undefined/334714)

<div class="topic-metadata">

**Author:** [@M\_D](https://discuss.elastic.co/u/M_D)\
**Replies:** 4\
**Last updated:** [June 2, 2023, 2:37pm UTC](https://discuss.elastic.co/t/regexperror-undefined/334714 "2023-06-02T14:37:30Z")

</div>

I am getting the following error using logstash:8.6.2 docker image: \[2023-05-30T18:42:18,144\]\[ERROR\]\[logstash.javapipeline \]\[main\] Pipeline error {:pipeline\_id=\>"main", :exception=\>#\<RegexpError: undefined group op…

---

## [How to size the ELK platform for on-premise setup / on-cloud setup](https://discuss.elastic.co/t/how-to-size-the-elk-platform-for-on-premise-setup-on-cloud-setup/335048)

<div class="topic-metadata">

**Author:** [@shpankaj](https://discuss.elastic.co/u/shpankaj)\
**Replies:** 1\
**Last updated:** [June 2, 2023, 1:45pm UTC](https://discuss.elastic.co/t/how-to-size-the-elk-platform-for-on-premise-setup-on-cloud-setup/335048 "2023-06-02T13:45:12Z")

</div>

We have to ingest logs and analyze as part of SOC services covering 100 windows 10 / 11 endpoints, 2 FortiGate F100 firewall, 20 Windows servers, 20 managed network switches of 24 ports, 120 EDR - sentinelOne. What shou…

---

## [Logstash unable to parse specific format of log](https://discuss.elastic.co/t/logstash-unable-to-parse-specific-format-of-log/334815)

<div class="topic-metadata">

**Author:** [@SmoZyNS](https://discuss.elastic.co/u/SmoZyNS)\
**Replies:** 11\
**Last updated:** [June 2, 2023, 1:35pm UTC](https://discuss.elastic.co/t/logstash-unable-to-parse-specific-format-of-log/334815 "2023-06-02T13:35:33Z")

</div>

Hello I am looking for some help since getting some headaches when trying to parse some logs Raw logs cs1Label=username cs1=/test@test.com cn1Label=actionSuccess cn1=1 deviceCustomDate1Label=userActionTime deviceCusto…

---

## [Filebeat filestream with pipeline and multiline](https://discuss.elastic.co/t/filebeat-filestream-with-pipeline-and-multiline/335015)

<div class="topic-metadata">

**Author:** [@das](https://discuss.elastic.co/u/das)\
**Replies:** 3\
**Last updated:** [June 2, 2023, 1:12pm UTC](https://discuss.elastic.co/t/filebeat-filestream-with-pipeline-and-multiline/335015 "2023-06-02T13:12:44Z")

</div>

I have a log format I cannot change that leads into multiline messages. I have a Ingest Pipeline set up in Kibana that works just fine on sample records. My problem is that My multiline parser seems to be ignored (at lea…

---

## [Help with creating a Logstash configuration file for Postfix log analysis](https://discuss.elastic.co/t/help-with-creating-a-logstash-configuration-file-for-postfix-log-analysis/335078)

<div class="topic-metadata">

**Author:** [@Aleksandr\_Terekhov](https://discuss.elastic.co/u/Aleksandr_Terekhov)\
**Replies:** 0\
**Last updated:** [June 2, 2023, 12:38pm UTC](https://discuss.elastic.co/t/help-with-creating-a-logstash-configuration-file-for-postfix-log-analysis/335078 "2023-06-02T12:38:59Z")

</div>

Hello everybody Can someone help to correctly create a configuration file that will display the fields from the postfix log that from status Message-id in Kiban in one line and not as in the screenshot I will be g…

---

## [Migrating Fluent Mappings from NEST to Elastic.Clients.Elasticsearch 8.1.1 Client](https://discuss.elastic.co/t/migrating-fluent-mappings-from-nest-to-elastic-clients-elasticsearch-8-1-1-client/335077)

<div class="topic-metadata">

**Author:** [@jrogalan](https://discuss.elastic.co/u/jrogalan)\
**Replies:** 0\
**Last updated:** [June 2, 2023, 12:33pm UTC](https://discuss.elastic.co/t/migrating-fluent-mappings-from-nest-to-elastic-clients-elasticsearch-8-1-1-client/335077 "2023-06-02T12:33:02Z")

</div>

How are we supposed to migrate a code like the following using NEST 7.17.5 to the new Elastic.Clients.Elasticsearch 8.1.1 client where the method .Object does not accept any longer the generic type of the child object. …

---

## [Cannot find write index](https://discuss.elastic.co/t/cannot-find-write-index/334683)

<div class="topic-metadata">

**Author:** [@Shreyansh\_Narang](https://discuss.elastic.co/u/Shreyansh_Narang)\
**Replies:** 13\
**Last updated:** [June 2, 2023, 11:46am UTC](https://discuss.elastic.co/t/cannot-find-write-index/334683 "2023-06-02T11:46:41Z")

</div>

Getting below error policy \[ilm\_cedar\] for index \[cedar-00001\] failed on step \[{"phase":"hot","action":"rollover","name":"check-rollover-ready"}\]. Moving to ERROR step java.lang.IllegalArgumentException: rollover targe…

---

## [Invalid version of beats protocol: 69 and 70](https://discuss.elastic.co/t/invalid-version-of-beats-protocol-69-and-70/334823)

<div class="topic-metadata">

**Author:** [@Aleksandr\_Terekhov](https://discuss.elastic.co/u/Aleksandr_Terekhov)\
**Replies:** 4\
**Last updated:** [June 2, 2023, 11:04am UTC](https://discuss.elastic.co/t/invalid-version-of-beats-protocol-69-and-70/334823 "2023-06-02T11:04:38Z")

</div>

Hello everybody Help to understand the problem There is an Oracle Linux 8 server on which Postfix and Filebeat 8.7.1 are installed Filebeat configuration # ============================== Filebeat inputs =============…

---

## [LogStash::Json::ParserError: Unexpected end-of-input: expected close marker for Array](https://discuss.elastic.co/t/logstash-unexpected-end-of-input-expected-close-marker-for-array/335071)

<div class="topic-metadata">

**Author:** [@niveditakathal](https://discuss.elastic.co/u/niveditakathal)\
**Replies:** 0\
**Last updated:** [June 2, 2023, 10:54am UTC](https://discuss.elastic.co/t/logstash-unexpected-end-of-input-expected-close-marker-for-array/335071 "2023-06-02T10:54:46Z")

</div>

Hi Experts, I want to ingest data from a text file (refer data.txt) to elastic using logstash and in order to achieve it, I have created the logstash.conf file as mentioned below - logstash.conf - input { file { …

---

## [Query\_string search exact phrase causes performance issues](https://discuss.elastic.co/t/query-string-search-exact-phrase-causes-performance-issues/335055)

<div class="topic-metadata">

**Author:** [@Sandeep\_Raju](https://discuss.elastic.co/u/Sandeep_Raju)\
**Replies:** 3\
**Last updated:** [June 2, 2023, 10:44am UTC](https://discuss.elastic.co/t/query-string-search-exact-phrase-causes-performance-issues/335055 "2023-06-02T10:44:22Z")

</div>

Hi all, When I make query\_string search exact phrase in Elasticsearch, POST /myindex\_\*/\_search { "query": { "query\_string": { "query": "\\"Classe A\\"" } } The query is run and shows hits, but sho…

[Previous page](https://discuss.elastic.co/latest.md?page=653)

[Next page](https://discuss.elastic.co/latest.md?page=655)
