# Latest

**URL:** https://discuss.elastic.co/latest.md?page=655

[Latest](https://discuss.elastic.co/latest.md) · [Categories](https://discuss.elastic.co/categories.md) · [Tags](https://discuss.elastic.co/tags.md)

**Page:** 656

---

## [Filebeat with multiple kibana instances](https://discuss.elastic.co/t/filebeat-with-multiple-kibana-instances/335070)

<div class="topic-metadata">

**Author:** [@Farah\_Bhr](https://discuss.elastic.co/u/Farah_Bhr)\
**Replies:** 0\
**Last updated:** [June 2, 2023, 10:41am UTC](https://discuss.elastic.co/t/filebeat-with-multiple-kibana-instances/335070 "2023-06-02T10:41:20Z")

</div>

Hello , Here I take logs use case as an example, Basically, we'll collect these system logs, application logs for each application on our production, and ship them to different logstash servers and different kibana inst…

---

## [Elastic Stack 8.3.3 - config changes fails](https://discuss.elastic.co/t/elastic-stack-8-3-3-config-changes-fails/334969)

<div class="topic-metadata">

**Author:** [@afmin](https://discuss.elastic.co/u/afmin)\
**Replies:** 1\
**Last updated:** [June 2, 2023, 10:10am UTC](https://discuss.elastic.co/t/elastic-stack-8-3-3-config-changes-fails/334969 "2023-06-02T10:10:19Z")

</div>

Hi I am trying to increase my Master Nodes with more diskspace. The two nodes are used with 82 and 83% diskspace. When I try an config change from 1 to 2 availability zones it fails by the step "Calling Elasticsearch no…

---

## [Elasticsearch performance in HDD vs SSD and 32 GB vs 64 GB of RAM](https://discuss.elastic.co/t/elasticsearch-performance-in-hdd-vs-ssd-and-32-gb-vs-64-gb-of-ram/334622)

<div class="topic-metadata">

**Author:** [@Don\_Boscow](https://discuss.elastic.co/u/Don_Boscow)\
**Replies:** 24\
**Last updated:** [June 2, 2023, 9:47am UTC](https://discuss.elastic.co/t/elasticsearch-performance-in-hdd-vs-ssd-and-32-gb-vs-64-gb-of-ram/334622 "2023-06-02T09:47:22Z")

</div>

I understand from what I have read that ES works best in conjunction with a sweet spot of 64 GB RAM per node and a fair bit of SSD (3-4 TB per node, with multiple shards in each node to handle primary copies and replicas…

---

## [Unable to see the spring boot application logs in ElasticCloud APM ](https://discuss.elastic.co/t/unable-to-see-the-spring-boot-application-logs-in-elasticcloud-apm/334473)

<div class="topic-metadata">

**Author:** [@ramakrr77](https://discuss.elastic.co/u/ramakrr77)\
**Replies:** 1\
**Last updated:** [June 2, 2023, 9:26am UTC](https://discuss.elastic.co/t/unable-to-see-the-spring-boot-application-logs-in-elasticcloud-apm/334473 "2023-06-02T09:26:56Z")

</div>

If you are asking about a problem you are experiencing, please use the following template, as it will help us help you. If you have a different problem, please delete all of this text :slight\_smile: TIP 1: select at lea…

---

## [There is a problem with elastic agent pushing logstash](https://discuss.elastic.co/t/there-is-a-problem-with-elastic-agent-pushing-logstash/335063)

<div class="topic-metadata">

**Author:** [@xqaiviwjxzw](https://discuss.elastic.co/u/xqaiviwjxzw)\
**Replies:** 0\
**Last updated:** [June 2, 2023, 9:13am UTC](https://discuss.elastic.co/t/there-is-a-problem-with-elastic-agent-pushing-logstash/335063 "2023-06-02T09:13:29Z")

</div>

By changing the original strategy of the elastic agent to push the log to Elasticsearch to push to the new strategy to push to logstash, why the log is still in the original Elasticsearch, but not pushed to the new lo…

---

## [Elasticsearch 7.10.2 error](https://discuss.elastic.co/t/elasticsearch-7-10-2-error/334975)

<div class="topic-metadata">

**Author:** [@anderstr1](https://discuss.elastic.co/u/anderstr1)\
**Replies:** 3\
**Last updated:** [June 2, 2023, 9:08am UTC](https://discuss.elastic.co/t/elasticsearch-7-10-2-error/334975 "2023-06-02T09:08:53Z")

</div>

I am trying to setup Elasticsearch version 7.10.2 using the official docker image. I only need a single-node cluster and I have successfully managed to set it up locally in the container. This is the output from health …

---

## [How to remove low correlation results?](https://discuss.elastic.co/t/how-to-remove-low-correlation-results/335056)

<div class="topic-metadata">

**Author:** [@Jinnrry](https://discuss.elastic.co/u/Jinnrry)\
**Replies:** 0\
**Last updated:** [June 2, 2023, 8:31am UTC](https://discuss.elastic.co/t/how-to-remove-low-correlation-results/335056 "2023-06-02T08:31:03Z")

</div>

I want to be able to filter my search results for less relevant results. So I use the min\_score for filtering. like this: GET xxx/\_search { "min\_score": 2.8, "query": { "match": { "xxx": "xxxx" } }…

---

## [Open source community](https://discuss.elastic.co/t/open-source-community/335051)

<div class="topic-metadata">

**Author:** [@Open\_source\_Advocate](https://discuss.elastic.co/u/Open_source_Advocate)\
**Replies:** 4\
**Last updated:** [June 2, 2023, 7:44am UTC](https://discuss.elastic.co/t/open-source-community/335051 "2023-06-02T07:44:07Z")

</div>

Where can I host a community survey to get input from community members?

---

## [Help with Grok (syntax issue as well as question regarding double quotes)](https://discuss.elastic.co/t/help-with-grok-syntax-issue-as-well-as-question-regarding-double-quotes/333891)

<div class="topic-metadata">

**Author:** [@roman-tasi](https://discuss.elastic.co/u/roman-tasi)\
**Replies:** 7\
**Last updated:** [June 2, 2023, 7:19am UTC](https://discuss.elastic.co/t/help-with-grok-syntax-issue-as-well-as-question-regarding-double-quotes/333891 "2023-06-02T07:19:40Z")

</div>

This is a sample log that I want to parse: type=EXECVE msg=audit(1684525987.999:148345): argc=2 a0="vim" a1="logstash-syslog.conf" This is the grok filter I am trying: type=%{WORD:type} msg=audit\\(%{NUMBER:audit}\\): a…

---

## [Exporting message fields from Elasticsearch for one years](https://discuss.elastic.co/t/exporting-message-fields-from-elasticsearch-for-one-years/335029)

<div class="topic-metadata">

**Author:** [@Brat\_Qaqa](https://discuss.elastic.co/u/Brat_Qaqa)\
**Replies:** 1\
**Last updated:** [June 2, 2023, 6:44am UTC](https://discuss.elastic.co/t/exporting-message-fields-from-elasticsearch-for-one-years/335029 "2023-06-02T06:44:35Z")

</div>

Hi, what is the best/easiest way of exporting message field from Elasticsearch to some text/json file?

---

## [Suggestion needed in painless script](https://discuss.elastic.co/t/suggestion-needed-in-painless-script/335052)

<div class="topic-metadata">

**Author:** [@rvadiga](https://discuss.elastic.co/u/rvadiga)\
**Replies:** 0\
**Last updated:** [June 2, 2023, 6:20am UTC](https://discuss.elastic.co/t/suggestion-needed-in-painless-script/335052 "2023-06-02T06:20:51Z")

</div>

Hi Team, Sorry, I am new to painless script and ES transform. Please bear with me on the query below. I have scenario to define a painless script in ES transform where the script needs to increase the timestamp by 1sec…

---

## [Need help in setting up Elasticsearch cluster](https://discuss.elastic.co/t/need-help-in-setting-up-elasticsearch-cluster/334642)

<div class="topic-metadata">

**Author:** [@ANUBHAV\_GUPTA](https://discuss.elastic.co/u/ANUBHAV_GUPTA)\
**Replies:** 8\
**Last updated:** [June 2, 2023, 5:57am UTC](https://discuss.elastic.co/t/need-help-in-setting-up-elasticsearch-cluster/334642 "2023-06-02T05:57:18Z")

</div>

Hi there, I am trying to run 2 nodes of elasticsearch and want them to form a cluster. But while running i am getting:- {"@timestamp":"2023-05-30T07:06:22.601Z", "log.level": "WARN", "message":"This node is a fully-fo…

---

## [How can I unwind array in elasticsearch](https://discuss.elastic.co/t/how-can-i-unwind-array-in-elasticsearch/335046)

<div class="topic-metadata">

**Author:** [@Anand\_Konagala](https://discuss.elastic.co/u/Anand_Konagala)\
**Replies:** 0\
**Last updated:** [June 2, 2023, 5:14am UTC](https://discuss.elastic.co/t/how-can-i-unwind-array-in-elasticsearch/335046 "2023-06-02T05:14:35Z")

</div>

Hii { "size": 0, "aggs": { "location\_buckets": { "composite": { "size": 1000, "sources": \[ { "city": { "terms": { "field": "location.city…

---

## [Multiple Out Of Memory Errors occurring, sometimes causing Cluster State Red Alerts](https://discuss.elastic.co/t/multiple-out-of-memory-errors-occurring-sometimes-causing-cluster-state-red-alerts/334985)

<div class="topic-metadata">

**Author:** [@Sarit\_Ghosh](https://discuss.elastic.co/u/Sarit_Ghosh)\
**Replies:** 2\
**Last updated:** [June 2, 2023, 4:03am UTC](https://discuss.elastic.co/t/multiple-out-of-memory-errors-occurring-sometimes-causing-cluster-state-red-alerts/334985 "2023-06-02T04:03:34Z")

</div>

We are getting many Out Of Memory errors on one cluster, but other clusters with similar size are not facing the issue. All the errors are of same type. \[2023-06-01T11:30:41,368\]\[ERROR\]\[o.e.b.ElasticsearchUncaughtExcept…

---

## [Output HTTP: Problem to send @metadata from one pipeline into another](https://discuss.elastic.co/t/output-http-problem-to-send-metadata-from-one-pipeline-into-another/335043)

<div class="topic-metadata">

**Author:** [@junchao](https://discuss.elastic.co/u/junchao)\
**Replies:** 0\
**Last updated:** [June 2, 2023, 3:38am UTC](https://discuss.elastic.co/t/output-http-problem-to-send-metadata-from-one-pipeline-into-another/335043 "2023-06-02T03:38:38Z")

</div>

I am trying to send the value of \[@metadata\]\[usertag\] from one pipeline 1 to pipeline 2. I tried to parse the value using "headers" setting but the value parsed is the string: "%{\[@metadata\]\[usertag\]}" and not the vari…

---

## [Predictive-analytics](https://discuss.elastic.co/t/predictive-analytics/335041)

<div class="topic-metadata">

**Author:** [@Bernhard\_Suhm](https://discuss.elastic.co/u/Bernhard_Suhm)\
**Replies:** 0\
**Last updated:** [June 2, 2023, 1:59am UTC](https://discuss.elastic.co/t/predictive-analytics/335041 "2023-06-02T01:59:55Z")

</div>

Ask questions about applying "predictive analytics" in manufacturing and industrial OT. You apply unsupervised and supervised models to automatically detect issues in manufacturing equipment or connected devices, and als…

---

## [Embedding query to baseurl](https://discuss.elastic.co/t/embedding-query-to-baseurl/334984)

<div class="topic-metadata">

**Author:** [@waqar\_jamali](https://discuss.elastic.co/u/waqar_jamali)\
**Replies:** 1\
**Last updated:** [June 2, 2023, 1:03am UTC](https://discuss.elastic.co/t/embedding-query-to-baseurl/334984 "2023-06-02T01:03:44Z")

</div>

I have url to connect to elasticsearch forexample ip:9200 I have query suppose { "query": { "range": { "@timestamp": { "gte": "now-1d/d", "lt": "now/d" } } }, "aggs": { …

---

## [Can we use dense vector field in ES v7.10 for free?](https://discuss.elastic.co/t/can-we-use-dense-vector-field-in-es-v7-10-for-free/334994)

<div class="topic-metadata">

**Author:** [@Vivek\_Sagar](https://discuss.elastic.co/u/Vivek_Sagar)\
**Replies:** 2\
**Last updated:** [June 2, 2023, 1:02am UTC](https://discuss.elastic.co/t/can-we-use-dense-vector-field-in-es-v7-10-for-free/334994 "2023-06-02T01:02:56Z")

</div>

With my installation of elasticsearch v7.10. I see x-pack enabled is true. So I am assuming the free features in x-pack is available to use. When i create a mapping with data type dense vector, I am able to do so and al…

---

## [Understanding subscriptions](https://discuss.elastic.co/t/understanding-subscriptions/335026)

<div class="topic-metadata">

**Author:** [@kevingscott](https://discuss.elastic.co/u/kevingscott)\
**Replies:** 1\
**Last updated:** [June 2, 2023, 12:37am UTC](https://discuss.elastic.co/t/understanding-subscriptions/335026 "2023-06-02T00:37:27Z")

</div>

Hello, We are trying to estimate the cost of implementing Elastic and I am confused about how the subscriptions work. Let's say that we purchased the Premium subscription and then deployed a Dev, QA and Production envi…

---

## [Uninstall plugin from the eck operator eck cluster](https://discuss.elastic.co/t/uninstall-plugin-from-the-eck-operator-eck-cluster/335033)

<div class="topic-metadata">

**Author:** [@elastic-db-user](https://discuss.elastic.co/u/elastic-db-user)\
**Replies:** 0\
**Last updated:** [June 1, 2023, 8:04pm UTC](https://discuss.elastic.co/t/uninstall-plugin-from-the-eck-operator-eck-cluster/335033 "2023-06-01T20:04:29Z")

</div>

Please share any insights on how to uninstall plugin from the eck operator managed es cluster. ex: in yaml - name: install-plugins command: - sh - -c - | bin/elasticsearch-plugin install --batch mapper-size

---

## [Fleet server managed elastic agent deployment in a azure managed kubernetes cluster running windows](https://discuss.elastic.co/t/fleet-server-managed-elastic-agent-deployment-in-a-azure-managed-kubernetes-cluster-running-windows/335038)

<div class="topic-metadata">

**Author:** [@rtalreja](https://discuss.elastic.co/u/rtalreja)\
**Replies:** 0\
**Last updated:** [June 1, 2023, 11:14pm UTC](https://discuss.elastic.co/t/fleet-server-managed-elastic-agent-deployment-in-a-azure-managed-kubernetes-cluster-running-windows/335038 "2023-06-01T23:14:47Z")

</div>

I want help with elastic-agent daemonset deployment on an Azure managed Kubernetes cluster. This agent is configured on fleet server via a policy. Searching online I found elastic-agent-managed-kubernetes.yaml file for …

---

## [Ingest EVTX file with Elastic Agent](https://discuss.elastic.co/t/ingest-evtx-file-with-elastic-agent/335031)

<div class="topic-metadata">

**Author:** [@DefensiveDepth](https://discuss.elastic.co/u/DefensiveDepth)\
**Replies:** 0\
**Last updated:** [June 1, 2023, 7:41pm UTC](https://discuss.elastic.co/t/ingest-evtx-file-with-elastic-agent/335031 "2023-06-01T19:41:59Z")

</div>

I know that it is possible to ingest evtx files with Winlogbeat (Not sure how to read from .evtx files | Winlogbeat Reference \[8.8\] | Elastic) Is there a way to do this with Elastic Agent?

---

## [Create Apache Response Code Field](https://discuss.elastic.co/t/create-apache-response-code-field/334913)

<div class="topic-metadata">

**Author:** [@sanjeev1895](https://discuss.elastic.co/u/sanjeev1895)\
**Replies:** 1\
**Last updated:** [June 1, 2023, 6:08pm UTC](https://discuss.elastic.co/t/create-apache-response-code-field/334913 "2023-06-01T18:08:14Z")

</div>

Hi Guys, Can anyone help me to do the following configuration to work as expected. I'm trying to create the separate field for apache response code status using grok filter but it print IP address first two octect. Gr…

---

## [Can we have multiple destinations in one jms plugin in logstash cofiguration?](https://discuss.elastic.co/t/can-we-have-multiple-destinations-in-one-jms-plugin-in-logstash-cofiguration/334910)

<div class="topic-metadata">

**Author:** [@Pranjal\_Sett](https://discuss.elastic.co/u/Pranjal_Sett)\
**Replies:** 1\
**Last updated:** [June 1, 2023, 6:02pm UTC](https://discuss.elastic.co/t/can-we-have-multiple-destinations-in-one-jms-plugin-in-logstash-cofiguration/334910 "2023-06-01T18:02:47Z")

</div>

So my requirement is want to insert multiple destination name in one JMS plugin. Writing multiple JMS input plugin for more than 1 destination is bit hectic. So, how can we achieve this with one single jms input plugin. …

---

## [How to Setting single table or specific table output to BigQuery?](https://discuss.elastic.co/t/how-to-setting-single-table-or-specific-table-output-to-bigquery/335022)

<div class="topic-metadata">

**Author:** [@aidensV](https://discuss.elastic.co/u/aidensV)\
**Replies:** 0\
**Last updated:** [June 1, 2023, 5:08pm UTC](https://discuss.elastic.co/t/how-to-setting-single-table-or-specific-table-output-to-bigquery/335022 "2023-06-01T17:08:40Z")

</div>

BigQuery table ID prefix to be used when creating new tables for log data. Table name will be \<table\_prefix\>\<table\_separator\>\<date\>

---

## [Kibana plugin 'yarn dev --watch' fails in Kibana 8.8.0](https://discuss.elastic.co/t/kibana-plugin-yarn-dev-watch-fails-in-kibana-8-8-0/334706)

<div class="topic-metadata">

**Author:** [@kbujold\_wr](https://discuss.elastic.co/u/kbujold_wr)\
**Replies:** 2\
**Last updated:** [June 1, 2023, 4:01pm UTC](https://discuss.elastic.co/t/kibana-plugin-yarn-dev-watch-fails-in-kibana-8-8-0/334706 "2023-06-01T16:01:56Z")

</div>

We have recently upgraded from Kibana 8.6.2 to 8.8.0. We are having issues launching the dev environment which now requires the use of yarn dev --watch as per doc kbujold@yow-kbujold-lx-vm2:wind$ yarn dev --watch yarn r…

---

## [Cross Cluster Replication for existing indexes](https://discuss.elastic.co/t/cross-cluster-replication-for-existing-indexes/334515)

<div class="topic-metadata">

**Author:** [@vvsh](https://discuss.elastic.co/u/vvsh)\
**Replies:** 8\
**Last updated:** [June 1, 2023, 3:58pm UTC](https://discuss.elastic.co/t/cross-cluster-replication-for-existing-indexes/334515 "2023-06-01T15:58:53Z")

</div>

Hello! I am considering CCR as a tool to migrate all the data (including historical data) from a source Elasticsearch single-node cluster to a target Elasticsearch multi-node cluster (both clusters have 7.17.7 version). …

---

## [Mutual tls between fluentd(act as client) and elasticsearch(act as server)](https://discuss.elastic.co/t/mutual-tls-between-fluentd-act-as-client-and-elasticsearch-act-as-server/334816)

<div class="topic-metadata">

**Author:** [@Voula\_Mikr](https://discuss.elastic.co/u/Voula_Mikr)\
**Replies:** 2\
**Last updated:** [June 1, 2023, 3:05pm UTC](https://discuss.elastic.co/t/mutual-tls-between-fluentd-act-as-client-and-elasticsearch-act-as-server/334816 "2023-06-01T15:05:33Z")

</div>

Hi I am trying to establish mutual tls between fluentd and elasticsearch. I have followed steps described in https://www.elastic.co/guide/en/elasticsearch/reference/8.7/security-basic-setup.html#generate-certificates …

---

## [My logstash conf file doesn't show me the output I don't what's the problem with that](https://discuss.elastic.co/t/my-logstash-conf-file-doesnt-show-me-the-output-i-dont-whats-the-problem-with-that/334999)

<div class="topic-metadata">

**Author:** [@Viknesh.S](https://discuss.elastic.co/u/Viknesh.S)\
**Replies:** 2\
**Last updated:** [June 1, 2023, 3:19pm UTC](https://discuss.elastic.co/t/my-logstash-conf-file-doesnt-show-me-the-output-i-dont-whats-the-problem-with-that/334999 "2023-06-01T15:19:26Z")

</div>

---

## [Connecting elastic search with microsoft fabric](https://discuss.elastic.co/t/connecting-elastic-search-with-microsoft-fabric/335000)

<div class="topic-metadata">

**Author:** [@waqar\_jamali](https://discuss.elastic.co/u/waqar_jamali)\
**Replies:** 3\
**Last updated:** [June 1, 2023, 3:04pm UTC](https://discuss.elastic.co/t/connecting-elastic-search-with-microsoft-fabric/335000 "2023-06-01T15:04:19Z")

</div>

Microsoft has released fabric for data analysis. It can connect to many types and sources of data How to connect elasticsearch data to microsoft fabric?

[Previous page](https://discuss.elastic.co/latest.md?page=654)

[Next page](https://discuss.elastic.co/latest.md?page=656)
