# Latest

**URL:** https://discuss.elastic.co/latest.md?page=658

[Latest](https://discuss.elastic.co/latest.md) · [Categories](https://discuss.elastic.co/categories.md) · [Tags](https://discuss.elastic.co/tags.md)

**Page:** 659

---

## [Log files to Logstash](https://discuss.elastic.co/t/log-files-to-logstash/333063)

<div class="topic-metadata">

**Author:** [@hjsroldan](https://discuss.elastic.co/u/hjsroldan)\
**Replies:** 1\
**Last updated:** [May 31, 2023, 8:43pm UTC](https://discuss.elastic.co/t/log-files-to-logstash/333063 "2023-05-31T20:43:19Z")

</div>

Hi, Good day! I have this scenario where I’m trying to collect log files and ship or ingest it to Logstash. Below is my logstash.conf Below is my input file (my-topics-1.txt) which contains 1-25 as shown below. …

---

## [How to add logging integration for getting filebeat logs in kibana dashboard](https://discuss.elastic.co/t/how-to-add-logging-integration-for-getting-filebeat-logs-in-kibana-dashboard/332553)

<div class="topic-metadata">

**Author:** [@kirankumarb](https://discuss.elastic.co/u/kirankumarb)\
**Replies:** 16\
**Last updated:** [May 31, 2023, 8:26pm UTC](https://discuss.elastic.co/t/how-to-add-logging-integration-for-getting-filebeat-logs-in-kibana-dashboard/332553 "2023-05-31T20:26:46Z")

</div>

We are not getting the logs as filebeat is not configured, so please help me in logging integration for kibana dashboard

---

## [Can I still jump from 7.17 to the new 8.8?](https://discuss.elastic.co/t/can-i-still-jump-from-7-17-to-the-new-8-8/334616)

<div class="topic-metadata">

**Author:** [@GenSSC](https://discuss.elastic.co/u/GenSSC)\
**Replies:** 8\
**Last updated:** [May 31, 2023, 7:16pm UTC](https://discuss.elastic.co/t/can-i-still-jump-from-7-17-to-the-new-8-8/334616 "2023-05-31T19:16:57Z")

</div>

I'm at 7.16 right now. I know I need to update to 7.17 first, but I am wondering if right after that I can go directly to 8.8? I know I could jump to 8.7 from 7.17. Just wondering if it's still the case.

---

## [Take snapshot of a datastream](https://discuss.elastic.co/t/take-snapshot-of-a-datastream/334867)

<div class="topic-metadata">

**Author:** [@Abhilash\_B](https://discuss.elastic.co/u/Abhilash_B)\
**Replies:** 0\
**Last updated:** [May 31, 2023, 7:13pm UTC](https://discuss.elastic.co/t/take-snapshot-of-a-datastream/334867 "2023-05-31T19:13:37Z")

</div>

I have scrambled through a lot of documentation on Snapshot and Restore. I was unable to find a specific example that show how to take a snapshot of a datastream and then restore it. Any help is highly appreciated.

---

## [Elastic Synthetics Journey: Receiving \`permission denied\`](https://discuss.elastic.co/t/elastic-synthetics-journey-receiving-permission-denied/330032)

<div class="topic-metadata">

**Author:** [@DougR](https://discuss.elastic.co/u/DougR)\
**Replies:** 27\
**Last updated:** [May 31, 2023, 6:41pm UTC](https://discuss.elastic.co/t/elastic-synthetics-journey-receiving-permission-denied/330032 "2023-05-31T18:41:25Z")

</div>

I am deploying a journey to Elastic Synthetics using the following command: npm run push. I'm using Elastic Cloud 8.7.0 and my agent is an elastic-agent-complete:8.7.0 container. The test is pushing to Elastic Cloud as…

---

## [MISP + Alerts](https://discuss.elastic.co/t/misp-alerts/334280)

<div class="topic-metadata">

**Author:** [@VellayLoket](https://discuss.elastic.co/u/VellayLoket)\
**Replies:** 7\
**Last updated:** [May 31, 2023, 6:37pm UTC](https://discuss.elastic.co/t/misp-alerts/334280 "2023-05-31T18:37:03Z")

</div>

I had connect MISP to ELK with filebeat. So now i have index named filebeat, there are many IOCs. Next i have index with network activity from workstations. So i want to match IP from winlog index with IOCs from MISP …

---

## [Span\_Near and Span\_or query for two multiword match is not giving expected result](https://discuss.elastic.co/t/span-near-and-span-or-query-for-two-multiword-match-is-not-giving-expected-result/334862)

<div class="topic-metadata">

**Author:** [@chetab](https://discuss.elastic.co/u/chetab)\
**Replies:** 0\
**Last updated:** [May 31, 2023, 5:27pm UTC](https://discuss.elastic.co/t/span-near-and-span-or-query-for-two-multiword-match-is-not-giving-expected-result/334862 "2023-05-31T17:27:55Z")

</div>

I need to write the query for below scenario: Ex: The car will be getting close to me but I am unable to stop it. or The car is too close to me but I am unable to stop it. like: Span\_near(span\_or("getting close", "is t…

---

## [Split Value into different document](https://discuss.elastic.co/t/split-value-into-different-document/332799)

<div class="topic-metadata">

**Author:** [@yuswanul](https://discuss.elastic.co/u/yuswanul)\
**Replies:** 1\
**Last updated:** [May 31, 2023, 5:12pm UTC](https://discuss.elastic.co/t/split-value-into-different-document/332799 "2023-05-31T17:12:51Z")

</div>

Hi there, if i have data like this \[{...},{...},{...}\] how can i split them into different documents like document 1 =\> {...} document 2 =\> {...} document 3 =\> {...} so in that way, I can use the json filter to spre…

---

## [Upgrade Elastic Stack 7.15.1 to 7.17.10](https://discuss.elastic.co/t/upgrade-elastic-stack-7-15-1-to-7-17-10/334717)

<div class="topic-metadata">

**Author:** [@SAMY-ELK](https://discuss.elastic.co/u/SAMY-ELK)\
**Replies:** 6\
**Last updated:** [May 31, 2023, 4:36pm UTC](https://discuss.elastic.co/t/upgrade-elastic-stack-7-15-1-to-7-17-10/334717 "2023-05-31T16:36:33Z")

</div>

Hello Team, I need to perform a backup Data KIBANA : tenants-spaces-Index pattern-alias-dashboard -visualisation before upgrade to Elastic version 7.17.10. when i getting issue on upgrade i can restore DATA. how to do…

---

## [Logstash Enrich and translate plugin use](https://discuss.elastic.co/t/logstash-enrich-and-translate-plugin-use/332897)

<div class="topic-metadata">

**Author:** [@gbandasha](https://discuss.elastic.co/u/gbandasha)\
**Replies:** 6\
**Last updated:** [May 31, 2023, 4:08pm UTC](https://discuss.elastic.co/t/logstash-enrich-and-translate-plugin-use/332897 "2023-05-31T16:08:27Z")

</div>

Hello Team, I am trying to enrich the data before it makes its way too elastic, I have tried the below methods but both are currently not working Using the elasticsearch plugin in filter input { kafka { …

---

## [Is it possible to use a runtime field in document based security query](https://discuss.elastic.co/t/is-it-possible-to-use-a-runtime-field-in-document-based-security-query/334730)

<div class="topic-metadata">

**Author:** [@ksobon](https://discuss.elastic.co/u/ksobon)\
**Replies:** 2\
**Last updated:** [May 31, 2023, 4:06pm UTC](https://discuss.elastic.co/t/is-it-possible-to-use-a-runtime-field-in-document-based-security-query/334730 "2023-05-31T16:06:47Z")

</div>

If I wanted to setup a role that has document based security and uses runtime field in the query, would that be possible? I can use regular, already indexed fields to do that, but I don't know how to do that with a Runti…

---

## [Match query with operator "and", doesn't work when using synonyms analyzer](https://discuss.elastic.co/t/match-query-with-operator-and-doesnt-work-when-using-synonyms-analyzer/334821)

<div class="topic-metadata">

**Author:** [@Bage\_Atanasovska](https://discuss.elastic.co/u/Bage_Atanasovska)\
**Replies:** 0\
**Last updated:** [May 31, 2023, 3:40pm UTC](https://discuss.elastic.co/t/match-query-with-operator-and-doesnt-work-when-using-synonyms-analyzer/334821 "2023-05-31T15:40:02Z")

</div>

I am creating an index using as a search analyzer, an alayzer that has a synonym filter. The query that creates the index is the following: { "settings": { "index": { "analysis": { …

---

## [Pipeline client receives callback 'onFilteredOut'](https://discuss.elastic.co/t/pipeline-client-receives-callback-onfilteredout/334818)

<div class="topic-metadata">

**Author:** [@TheMadmax](https://discuss.elastic.co/u/TheMadmax)\
**Replies:** 0\
**Last updated:** [May 31, 2023, 2:55pm UTC](https://discuss.elastic.co/t/pipeline-client-receives-callback-onfilteredout/334818 "2023-05-31T14:55:43Z")

</div>

Hello, I'm facing an error with my f5\_bigip pipeline. I use the elastic integration module for that, but ,the agent does receive data, but they don't process it : "Pipeline client receives callback 'onFilteredOut' for…

---

## [Enterprise Search Mongo-Connector Advanced Rule to Filter by Current Date](https://discuss.elastic.co/t/enterprise-search-mongo-connector-advanced-rule-to-filter-by-current-date/332660)

<div class="topic-metadata">

**Author:** [@pocketcolin](https://discuss.elastic.co/u/pocketcolin)\
**Replies:** 2\
**Last updated:** [May 31, 2023, 2:37pm UTC](https://discuss.elastic.co/t/enterprise-search-mongo-connector-advanced-rule-to-filter-by-current-date/332660 "2023-05-31T14:37:10Z")

</div>

Hello! I am trying to ingest records from MongoDB through a Enterprise Search Mongo-Connector. I would like to use an advanced rule to only pull in those where a specific field (expiresAt) is greater than or equal to the…

---

## [Logstash SWAP OOM](https://discuss.elastic.co/t/logstash-swap-oom/334675)

<div class="topic-metadata">

**Author:** [@nilsen](https://discuss.elastic.co/u/nilsen)\
**Replies:** 2\
**Last updated:** [May 31, 2023, 2:27pm UTC](https://discuss.elastic.co/t/logstash-swap-oom/334675 "2023-05-31T14:27:39Z")

</div>

We have the past months installed the ELK stack trying to follow the elastic documentation. Currently using logstash to push approx. 15 logs into our elastic indexes. Hoping to push all of our approx. 100 logs into diffe…

---

## [ECK in azure](https://discuss.elastic.co/t/eck-in-azure/334814)

<div class="topic-metadata">

**Author:** [@macdadi112](https://discuss.elastic.co/u/macdadi112)\
**Replies:** 0\
**Last updated:** [May 31, 2023, 2:15pm UTC](https://discuss.elastic.co/t/eck-in-azure/334814 "2023-05-31T14:15:47Z")

</div>

Hi, I have managed to install the ECK as explained in the quikcstart guides (Quickstart | Elastic Cloud on Kubernetes \[2.8\] | Elastic) but now I am trying to install with integration to Azure AD. I changed my elasticse…

---

## [Issue while running FSCrawler on WSL](https://discuss.elastic.co/t/issue-while-running-fscrawler-on-wsl/334620)

<div class="topic-metadata">

**Author:** [@chloesun](https://discuss.elastic.co/u/chloesun)\
**Replies:** 6\
**Last updated:** [May 31, 2023, 2:05pm UTC](https://discuss.elastic.co/t/issue-while-running-fscrawler-on-wsl/334620 "2023-05-31T14:05:48Z")

</div>

I installed JAVA 11, Elastic Search 7, and Fscrawler2.8 on WSL on my Windows machine. Elastic search has no issue starting, and I already configured JAVA\_HOME in .bashrc export JAVA\_HOME="/usr/lib/jvm/java-11-openjdk-am…

---

## [Akamai integration version 2.7.0 sending wrong values in from and to params](https://discuss.elastic.co/t/akamai-integration-version-2-7-0-sending-wrong-values-in-from-and-to-params/334529)

<div class="topic-metadata">

**Author:** [@abhishek-devops](https://discuss.elastic.co/u/abhishek-devops)\
**Replies:** 3\
**Last updated:** [May 31, 2023, 2:03pm UTC](https://discuss.elastic.co/t/akamai-integration-version-2-7-0-sending-wrong-values-in-from-and-to-params/334529 "2023-05-31T14:03:52Z")

</div>

Hello Team, After upgrading akamai integration the from and to params are getting wrong values ... please refer below logs: "log.level":"debug","@timestamp":"2023-05-28T12:35:53.527Z","message":"HTTP request","transac…

---

## [Mapper\_parsing\_exception error](https://discuss.elastic.co/t/mapper-parsing-exception-error/334447)

<div class="topic-metadata">

**Author:** [@Ruwi](https://discuss.elastic.co/u/Ruwi)\
**Replies:** 6\
**Last updated:** [May 31, 2023, 2:01pm UTC](https://discuss.elastic.co/t/mapper-parsing-exception-error/334447 "2023-05-31T14:01:26Z")

</div>

Hi all, I create indexes on a daily basis using fluentd in Elasticsearch. I don't do any mapping on elasticsearch side. After a while, the related index could not be created in Elasticsearch and I got the following erro…

---

## [Elastic Search 8.6.2 SSL enabled with 3rd party certificate](https://discuss.elastic.co/t/elastic-search-8-6-2-ssl-enabled-with-3rd-party-certificate/334713)

<div class="topic-metadata">

**Author:** [@neil.maffitt](https://discuss.elastic.co/u/neil.maffitt)\
**Replies:** 21\
**Last updated:** [May 31, 2023, 1:50pm UTC](https://discuss.elastic.co/t/elastic-search-8-6-2-ssl-enabled-with-3rd-party-certificate/334713 "2023-05-31T13:50:36Z")

</div>

I have a single instance of Elastic Search 8.6.2 installed on a redhat server. No cloud, No docker and single node, very simple install. We need SSL enabled and configured to use a 3rd party certificate we can't use El…

---

## [Kibana rule false positivie](https://discuss.elastic.co/t/kibana-rule-false-positivie/334025)

<div class="topic-metadata">

**Author:** [@amityahav](https://discuss.elastic.co/u/amityahav)\
**Replies:** 2\
**Last updated:** [May 31, 2023, 1:25pm UTC](https://discuss.elastic.co/t/kibana-rule-false-positivie/334025 "2023-05-31T13:25:28Z")

</div>

Hey there, We have alerting rules in our company which are triggered even though it seems that they shouldnt in this example i've configured the alert to trigger when then number of docs is below 75k for the last 3…

---

## [How to change the date structure to YYYY:MM:DD](https://discuss.elastic.co/t/how-to-change-the-date-structure-to-yyyydd/334789)

<div class="topic-metadata">

**Author:** [@subash\_k](https://discuss.elastic.co/u/subash_k)\
**Replies:** 5\
**Last updated:** [May 31, 2023, 1:18pm UTC](https://discuss.elastic.co/t/how-to-change-the-date-structure-to-yyyydd/334789 "2023-05-31T13:18:44Z")

</div>

Hi, I tried multiple way to change the date event into YYYY:MMM:DD as log\_date. below format is actual date event (2023-05-31 10:30:50,244). I tried manual string concatenation even though am getting type as timestamp …

---

## [Ndjson parser doesn't expand keys if target is set](https://discuss.elastic.co/t/ndjson-parser-doesnt-expand-keys-if-target-is-set/334799)

<div class="topic-metadata">

**Author:** [@anon68795679](https://discuss.elastic.co/u/anon68795679)\
**Replies:** 2\
**Last updated:** [May 31, 2023, 1:13pm UTC](https://discuss.elastic.co/t/ndjson-parser-doesnt-expand-keys-if-target-is-set/334799 "2023-05-31T13:13:05Z")

</div>

Hi, it seems that there is the same issue with the ndjson parser like in the decode\_json\_fields processor some time ago: Expand fields in \`decode\_json\_fields\` if target is set by kvch · Pull Request #32010 · elastic/bea…

---

## [Heartbeat parsing JSON object for HTTP monitor failure](https://discuss.elastic.co/t/heartbeat-parsing-json-object-for-http-monitor-failure/334335)

<div class="topic-metadata">

**Author:** [@rschirin](https://discuss.elastic.co/u/rschirin)\
**Replies:** 2\
**Last updated:** [May 31, 2023, 1:05pm UTC](https://discuss.elastic.co/t/heartbeat-parsing-json-object-for-http-monitor-failure/334335 "2023-05-31T13:05:18Z")

</div>

hey there, I am using Heartbeat 8.x and according to I was trying to check the Sendgrid SMTP service using the public url https://status.sendgrid.com/api/v2/components.json Using this code: - type: http id: sendgr…

---

## [Range queries with should clause not working](https://discuss.elastic.co/t/range-queries-with-should-clause-not-working/334764)

<div class="topic-metadata">

**Author:** [@\_baba](https://discuss.elastic.co/u/_baba)\
**Replies:** 3\
**Last updated:** [May 31, 2023, 12:58pm UTC](https://discuss.elastic.co/t/range-queries-with-should-clause-not-working/334764 "2023-05-31T12:58:54Z")

</div>

Hi, I'm trying below range query with must and should clause: Product id can range from 1 to 1000. I'm using below query to fetch product\_id between 1 to 99 or product\_id = 100. However I can only see the must clause…

---

## ["The incoming YAML document exceeds the limit: 3145728 code points" in Logstash/ElastiFLOW](https://discuss.elastic.co/t/the-incoming-yaml-document-exceeds-the-limit-3145728-code-points-in-logstash-elastiflow/334803)

<div class="topic-metadata">

**Author:** [@numpty-boy](https://discuss.elastic.co/u/numpty-boy)\
**Replies:** 0\
**Last updated:** [May 31, 2023, 12:48pm UTC](https://discuss.elastic.co/t/the-incoming-yaml-document-exceeds-the-limit-3145728-code-points-in-logstash-elastiflow/334803 "2023-05-31T12:48:41Z")

</div>

Since upgrading to logstash 7.17.10 on Centos 7, I've been seeing the above error when starting. I see some other folks have had similar problems 8.7, and there are similar problems reported in RUBY forums. I had no su…

---

## [Faceting, sorting, paginating within buckets](https://discuss.elastic.co/t/faceting-sorting-paginating-within-buckets/334801)

<div class="topic-metadata">

**Author:** [@milindyedge](https://discuss.elastic.co/u/milindyedge)\
**Replies:** 0\
**Last updated:** [May 31, 2023, 12:30pm UTC](https://discuss.elastic.co/t/faceting-sorting-paginating-within-buckets/334801 "2023-05-31T12:30:56Z")

</div>

Hi there, I have a question around Elasticsearch's aggregation functionality. We have a use case where we need to do search with a "search term" and then group results by a field in the document and read documents within…

---

## [Dev-Tools gone](https://discuss.elastic.co/t/dev-tools-gone/334720)

<div class="topic-metadata">

**Author:** [@DavidGreensfelder](https://discuss.elastic.co/u/DavidGreensfelder)\
**Replies:** 2\
**Last updated:** [May 31, 2023, 12:14pm UTC](https://discuss.elastic.co/t/dev-tools-gone/334720 "2023-05-31T12:14:07Z")

</div>

Could someone tell me why my Dev-Tool are gone? What makes them get removed? Are they stored in the cache of my local machine?

---

## [Normalizing the score during indexing](https://discuss.elastic.co/t/normalizing-the-score-during-indexing/334708)

<div class="topic-metadata">

**Author:** [@akhil\_reddy](https://discuss.elastic.co/u/akhil_reddy)\
**Replies:** 3\
**Last updated:** [May 31, 2023, 12:08pm UTC](https://discuss.elastic.co/t/normalizing-the-score-during-indexing/334708 "2023-05-31T12:08:19Z")

</div>

Hi, Is there a way to normalize the elastic score between 0 and 1. I know it is possible to do it during query time by using script, but I am looking for ways to do it during index time. Thank you

---

## [Unable to form an ES cluster](https://discuss.elastic.co/t/unable-to-form-an-es-cluster/334795)

<div class="topic-metadata">

**Author:** [@ANUBHAV\_GUPTA](https://discuss.elastic.co/u/ANUBHAV_GUPTA)\
**Replies:** 1\
**Last updated:** [May 31, 2023, 11:31am UTC](https://discuss.elastic.co/t/unable-to-form-an-es-cluster/334795 "2023-05-31T11:31:42Z")

</div>

I am having 2 nodes having elasticsearch installed. I am running first node as :- sudo docker run -it --pull=always --net elastic -p 9200:9200 -p 9300:9300 -e discovery.type=multi-node -e cluster.name="my-elasticsearch-…

[Previous page](https://discuss.elastic.co/latest.md?page=657)

[Next page](https://discuss.elastic.co/latest.md?page=659)
