# Latest

**URL:** https://discuss.elastic.co/latest.md?page=659

[Latest](https://discuss.elastic.co/latest.md) · [Categories](https://discuss.elastic.co/categories.md) · [Tags](https://discuss.elastic.co/tags.md)

**Page:** 660

---

## [Issue while running FSCrawler on WSL](https://discuss.elastic.co/t/issue-while-running-fscrawler-on-wsl/334620)

<div class="topic-metadata">

**Author:** [@chloesun](https://discuss.elastic.co/u/chloesun)\
**Replies:** 6\
**Last updated:** [May 31, 2023, 2:05pm UTC](https://discuss.elastic.co/t/issue-while-running-fscrawler-on-wsl/334620 "2023-05-31T14:05:48Z")

</div>

I installed JAVA 11, Elastic Search 7, and Fscrawler2.8 on WSL on my Windows machine. Elastic search has no issue starting, and I already configured JAVA\_HOME in .bashrc export JAVA\_HOME="/usr/lib/jvm/java-11-openjdk-am…

---

## [Akamai integration version 2.7.0 sending wrong values in from and to params](https://discuss.elastic.co/t/akamai-integration-version-2-7-0-sending-wrong-values-in-from-and-to-params/334529)

<div class="topic-metadata">

**Author:** [@abhishek-devops](https://discuss.elastic.co/u/abhishek-devops)\
**Replies:** 3\
**Last updated:** [May 31, 2023, 2:03pm UTC](https://discuss.elastic.co/t/akamai-integration-version-2-7-0-sending-wrong-values-in-from-and-to-params/334529 "2023-05-31T14:03:52Z")

</div>

Hello Team, After upgrading akamai integration the from and to params are getting wrong values ... please refer below logs: "log.level":"debug","@timestamp":"2023-05-28T12:35:53.527Z","message":"HTTP request","transac…

---

## [Mapper\_parsing\_exception error](https://discuss.elastic.co/t/mapper-parsing-exception-error/334447)

<div class="topic-metadata">

**Author:** [@Ruwi](https://discuss.elastic.co/u/Ruwi)\
**Replies:** 6\
**Last updated:** [May 31, 2023, 2:01pm UTC](https://discuss.elastic.co/t/mapper-parsing-exception-error/334447 "2023-05-31T14:01:26Z")

</div>

Hi all, I create indexes on a daily basis using fluentd in Elasticsearch. I don't do any mapping on elasticsearch side. After a while, the related index could not be created in Elasticsearch and I got the following erro…

---

## [Elastic Search 8.6.2 SSL enabled with 3rd party certificate](https://discuss.elastic.co/t/elastic-search-8-6-2-ssl-enabled-with-3rd-party-certificate/334713)

<div class="topic-metadata">

**Author:** [@neil.maffitt](https://discuss.elastic.co/u/neil.maffitt)\
**Replies:** 21\
**Last updated:** [May 31, 2023, 1:50pm UTC](https://discuss.elastic.co/t/elastic-search-8-6-2-ssl-enabled-with-3rd-party-certificate/334713 "2023-05-31T13:50:36Z")

</div>

I have a single instance of Elastic Search 8.6.2 installed on a redhat server. No cloud, No docker and single node, very simple install. We need SSL enabled and configured to use a 3rd party certificate we can't use El…

---

## [Kibana rule false positivie](https://discuss.elastic.co/t/kibana-rule-false-positivie/334025)

<div class="topic-metadata">

**Author:** [@amityahav](https://discuss.elastic.co/u/amityahav)\
**Replies:** 2\
**Last updated:** [May 31, 2023, 1:25pm UTC](https://discuss.elastic.co/t/kibana-rule-false-positivie/334025 "2023-05-31T13:25:28Z")

</div>

Hey there, We have alerting rules in our company which are triggered even though it seems that they shouldnt in this example i've configured the alert to trigger when then number of docs is below 75k for the last 3…

---

## [How to change the date structure to YYYY:MM:DD](https://discuss.elastic.co/t/how-to-change-the-date-structure-to-yyyydd/334789)

<div class="topic-metadata">

**Author:** [@subash\_k](https://discuss.elastic.co/u/subash_k)\
**Replies:** 5\
**Last updated:** [May 31, 2023, 1:18pm UTC](https://discuss.elastic.co/t/how-to-change-the-date-structure-to-yyyydd/334789 "2023-05-31T13:18:44Z")

</div>

Hi, I tried multiple way to change the date event into YYYY:MMM:DD as log\_date. below format is actual date event (2023-05-31 10:30:50,244). I tried manual string concatenation even though am getting type as timestamp …

---

## [Ndjson parser doesn't expand keys if target is set](https://discuss.elastic.co/t/ndjson-parser-doesnt-expand-keys-if-target-is-set/334799)

<div class="topic-metadata">

**Author:** [@anon68795679](https://discuss.elastic.co/u/anon68795679)\
**Replies:** 2\
**Last updated:** [May 31, 2023, 1:13pm UTC](https://discuss.elastic.co/t/ndjson-parser-doesnt-expand-keys-if-target-is-set/334799 "2023-05-31T13:13:05Z")

</div>

Hi, it seems that there is the same issue with the ndjson parser like in the decode\_json\_fields processor some time ago: Expand fields in \`decode\_json\_fields\` if target is set by kvch · Pull Request #32010 · elastic/bea…

---

## [Heartbeat parsing JSON object for HTTP monitor failure](https://discuss.elastic.co/t/heartbeat-parsing-json-object-for-http-monitor-failure/334335)

<div class="topic-metadata">

**Author:** [@rschirin](https://discuss.elastic.co/u/rschirin)\
**Replies:** 2\
**Last updated:** [May 31, 2023, 1:05pm UTC](https://discuss.elastic.co/t/heartbeat-parsing-json-object-for-http-monitor-failure/334335 "2023-05-31T13:05:18Z")

</div>

hey there, I am using Heartbeat 8.x and according to I was trying to check the Sendgrid SMTP service using the public url https://status.sendgrid.com/api/v2/components.json Using this code: - type: http id: sendgr…

---

## [Range queries with should clause not working](https://discuss.elastic.co/t/range-queries-with-should-clause-not-working/334764)

<div class="topic-metadata">

**Author:** [@\_baba](https://discuss.elastic.co/u/_baba)\
**Replies:** 3\
**Last updated:** [May 31, 2023, 12:58pm UTC](https://discuss.elastic.co/t/range-queries-with-should-clause-not-working/334764 "2023-05-31T12:58:54Z")

</div>

Hi, I'm trying below range query with must and should clause: Product id can range from 1 to 1000. I'm using below query to fetch product\_id between 1 to 99 or product\_id = 100. However I can only see the must clause…

---

## ["The incoming YAML document exceeds the limit: 3145728 code points" in Logstash/ElastiFLOW](https://discuss.elastic.co/t/the-incoming-yaml-document-exceeds-the-limit-3145728-code-points-in-logstash-elastiflow/334803)

<div class="topic-metadata">

**Author:** [@numpty-boy](https://discuss.elastic.co/u/numpty-boy)\
**Replies:** 0\
**Last updated:** [May 31, 2023, 12:48pm UTC](https://discuss.elastic.co/t/the-incoming-yaml-document-exceeds-the-limit-3145728-code-points-in-logstash-elastiflow/334803 "2023-05-31T12:48:41Z")

</div>

Since upgrading to logstash 7.17.10 on Centos 7, I've been seeing the above error when starting. I see some other folks have had similar problems 8.7, and there are similar problems reported in RUBY forums. I had no su…

---

## [Faceting, sorting, paginating within buckets](https://discuss.elastic.co/t/faceting-sorting-paginating-within-buckets/334801)

<div class="topic-metadata">

**Author:** [@milindyedge](https://discuss.elastic.co/u/milindyedge)\
**Replies:** 0\
**Last updated:** [May 31, 2023, 12:30pm UTC](https://discuss.elastic.co/t/faceting-sorting-paginating-within-buckets/334801 "2023-05-31T12:30:56Z")

</div>

Hi there, I have a question around Elasticsearch's aggregation functionality. We have a use case where we need to do search with a "search term" and then group results by a field in the document and read documents within…

---

## [Dev-Tools gone](https://discuss.elastic.co/t/dev-tools-gone/334720)

<div class="topic-metadata">

**Author:** [@DavidGreensfelder](https://discuss.elastic.co/u/DavidGreensfelder)\
**Replies:** 2\
**Last updated:** [May 31, 2023, 12:14pm UTC](https://discuss.elastic.co/t/dev-tools-gone/334720 "2023-05-31T12:14:07Z")

</div>

Could someone tell me why my Dev-Tool are gone? What makes them get removed? Are they stored in the cache of my local machine?

---

## [Normalizing the score during indexing](https://discuss.elastic.co/t/normalizing-the-score-during-indexing/334708)

<div class="topic-metadata">

**Author:** [@akhil\_reddy](https://discuss.elastic.co/u/akhil_reddy)\
**Replies:** 3\
**Last updated:** [May 31, 2023, 12:08pm UTC](https://discuss.elastic.co/t/normalizing-the-score-during-indexing/334708 "2023-05-31T12:08:19Z")

</div>

Hi, Is there a way to normalize the elastic score between 0 and 1. I know it is possible to do it during query time by using script, but I am looking for ways to do it during index time. Thank you

---

## [Unable to form an ES cluster](https://discuss.elastic.co/t/unable-to-form-an-es-cluster/334795)

<div class="topic-metadata">

**Author:** [@ANUBHAV\_GUPTA](https://discuss.elastic.co/u/ANUBHAV_GUPTA)\
**Replies:** 1\
**Last updated:** [May 31, 2023, 11:31am UTC](https://discuss.elastic.co/t/unable-to-form-an-es-cluster/334795 "2023-05-31T11:31:42Z")

</div>

I am having 2 nodes having elasticsearch installed. I am running first node as :- sudo docker run -it --pull=always --net elastic -p 9200:9200 -p 9300:9300 -e discovery.type=multi-node -e cluster.name="my-elasticsearch-…

---

## [Adding Custom Fields to an Elasticsearch Index](https://discuss.elastic.co/t/adding-custom-fields-to-an-elasticsearch-index/334794)

<div class="topic-metadata">

**Author:** [@Abeer\_Islam](https://discuss.elastic.co/u/Abeer_Islam)\
**Replies:** 1\
**Last updated:** [May 31, 2023, 11:29am UTC](https://discuss.elastic.co/t/adding-custom-fields-to-an-elasticsearch-index/334794 "2023-05-31T11:29:10Z")

</div>

Hi, I want to add custom fields (Year, Yearly Week, Week, Month, Exist (a boolean value)) and their corresponding values into an ES index using API. SInce, I am running the OpenDistro for Elasticsearch version which doe…

---

## [Add query parameter "level" to the IndicesStatsRequest using the 7.17 transport client](https://discuss.elastic.co/t/add-query-parameter-level-to-the-indicesstatsrequest-using-the-7-17-transport-client/334782)

<div class="topic-metadata">

**Author:** [@kley](https://discuss.elastic.co/u/kley)\
**Replies:** 2\
**Last updated:** [May 31, 2023, 11:23am UTC](https://discuss.elastic.co/t/add-query-parameter-level-to-the-indicesstatsrequest-using-the-7-17-transport-client/334782 "2023-05-31T11:23:38Z")

</div>

Hey! We are using Elasticsearch 7.17 + the corresponding transport client. I try to calculate the consumed disk space from Elasticsearch without the cat API and came up with this solution (documentation): curl -H 'Con…

---

## [Elastic-agent failed to enroll due to TLS access denied alert](https://discuss.elastic.co/t/elastic-agent-failed-to-enroll-due-to-tls-access-denied-alert/334699)

<div class="topic-metadata">

**Author:** [@kmahyyg](https://discuss.elastic.co/u/kmahyyg)\
**Replies:** 3\
**Last updated:** [May 31, 2023, 10:18am UTC](https://discuss.elastic.co/t/elastic-agent-failed-to-enroll-due-to-tls-access-denied-alert/334699 "2023-05-31T10:18:09Z")

</div>

This is a really interesting issue. Code related: elastic-agent/client.go at cda5b7e75d080c6be9e9220dfa607c145cf598b4 · elastic/elastic-agent · GitHub I've using self-signed CA to deploy elastic-agent in internal envir…

---

## [NameError, missing class name com.ibm.mq.jms.MQQueueConnectionFactory](https://discuss.elastic.co/t/nameerror-missing-class-name-com-ibm-mq-jms-mqqueueconnectionfactory/334784)

<div class="topic-metadata">

**Author:** [@paulov](https://discuss.elastic.co/u/paulov)\
**Replies:** 0\
**Last updated:** [May 31, 2023, 10:17am UTC](https://discuss.elastic.co/t/nameerror-missing-class-name-com-ibm-mq-jms-mqqueueconnectionfactory/334784 "2023-05-31T10:17:52Z")

</div>

Hello, I have a JMS plugin configuration with purpose of connecting to IBM MQ. After starting the pipeline I get: \> \> \[WARN \] 2023-05-31 10:38:14.348 \[\[main\]\<jms\] jms - JMS Consumer Died {:exception=\>"NameError", \> :…

---

## [Endpoint Offline forced uninstall, can't uninstall completely](https://discuss.elastic.co/t/endpoint-offline-forced-uninstall-cant-uninstall-completely/334244)

<div class="topic-metadata">

**Author:** [@xqaiviwjxzw](https://discuss.elastic.co/u/xqaiviwjxzw)\
**Replies:** 9\
**Last updated:** [May 31, 2023, 9:49am UTC](https://discuss.elastic.co/t/endpoint-offline-forced-uninstall-cant-uninstall-completely/334244 "2023-05-31T09:49:32Z")

</div>

What is the solution to forcibly uninstalling the agent via fleet while offline, but the uninstallation is not clean and the logs are kept and the host cannot be contacted? Thanks

---

## [Kibana visualisation-](https://discuss.elastic.co/t/kibana-visualisation/333176)

<div class="topic-metadata">

**Author:** [@Neelam\_Zanvar](https://discuss.elastic.co/u/Neelam_Zanvar)\
**Replies:** 12\
**Last updated:** [May 31, 2023, 9:15am UTC](https://discuss.elastic.co/t/kibana-visualisation/333176 "2023-05-31T09:15:18Z")

</div>

Hi I am creating a Kibana visualization. Using table in kibana lens I want to fetch the time a token is first created in the log file. I am able to view the last value of it. but how can i see the timestamp when the tok…

---

## [ECK continuous log spamming](https://discuss.elastic.co/t/eck-continuous-log-spamming/334569)

<div class="topic-metadata">

**Author:** [@anastazya](https://discuss.elastic.co/u/anastazya)\
**Replies:** 1\
**Last updated:** [May 31, 2023, 9:08am UTC](https://discuss.elastic.co/t/eck-continuous-log-spamming/334569 "2023-05-31T09:08:21Z")

</div>

I have a K8s ECK deployed as this : apiVersion: elasticsearch.k8s.elastic.co/v1 kind: Elasticsearch metadata: name: dev namespace: monitoring spec: version: 8.8.0 nodeSets: name: dev count: 3 podTemplate: sp…

---

## [DeflateCompressor threads causing memory leak in Tomcat](https://discuss.elastic.co/t/deflatecompressor-threads-causing-memory-leak-in-tomcat/334769)

<div class="topic-metadata">

**Author:** [@KristianJ](https://discuss.elastic.co/u/KristianJ)\
**Replies:** 1\
**Last updated:** [May 31, 2023, 9:06am UTC](https://discuss.elastic.co/t/deflatecompressor-threads-causing-memory-leak-in-tomcat/334769 "2023-05-31T09:06:53Z")

</div>

Hi, using ES 7.17.10 in a Tomcat container (9.0.x). When the application is shutdown there are two threads that are not removed, causing memory leaks from the DeflateCompressor class. In particular it would seem that t…

---

## [Attempted to resurrect connection to dead ES instance, but got an error](https://discuss.elastic.co/t/attempted-to-resurrect-connection-to-dead-es-instance-but-got-an-error/333650)

<div class="topic-metadata">

**Author:** [@snalaband](https://discuss.elastic.co/u/snalaband)\
**Replies:** 4\
**Last updated:** [May 31, 2023, 9:03am UTC](https://discuss.elastic.co/t/attempted-to-resurrect-connection-to-dead-es-instance-but-got-an-error/333650 "2023-05-31T09:03:02Z")

</div>

Attempted to resurrect connection to dead ES instance, but got an error. {:error\_type=\>LogStash::Outputs::Elasticsearch::HttpClient::Pool::BadResponseCodeError, :error=\>"Got response code '401' contacting Elasticsearch a…

---

## [Dashboard with kibana](https://discuss.elastic.co/t/dashboard-with-kibana/334016)

<div class="topic-metadata">

**Author:** [@Hanni](https://discuss.elastic.co/u/Hanni)\
**Replies:** 13\
**Last updated:** [May 31, 2023, 8:52am UTC](https://discuss.elastic.co/t/dashboard-with-kibana/334016 "2023-05-31T08:52:28Z")

</div>

Hello, I have two CSV files. One file contains the names of applications, and the other file contains information about a specific application. Both files have the "Host" column in common. I have imported these two files…

---

## [Upgrading 7.17 to 8.7 query search query not working](https://discuss.elastic.co/t/upgrading-7-17-to-8-7-query-search-query-not-working/334645)

<div class="topic-metadata">

**Author:** [@ak01](https://discuss.elastic.co/u/ak01)\
**Replies:** 3\
**Last updated:** [May 31, 2023, 8:48am UTC](https://discuss.elastic.co/t/upgrading-7-17-to-8-7-query-search-query-not-working/334645 "2023-05-31T08:48:32Z")

</div>

What will be the new query this I was using in old version for search: const { body } = await Client.search({ index: this.tableName, body: { sort: sortingData, from: skip, size: l…

---

## [Access Elasticsearch with public IP](https://discuss.elastic.co/t/access-elasticsearch-with-public-ip/334743)

<div class="topic-metadata">

**Author:** [@Rakhshunda\_Noorein\_J](https://discuss.elastic.co/u/Rakhshunda_Noorein_J)\
**Replies:** 2\
**Last updated:** [May 31, 2023, 8:48am UTC](https://discuss.elastic.co/t/access-elasticsearch-with-public-ip/334743 "2023-05-31T08:48:26Z")

</div>

Hello, I have my Elasticsearch running on my windows 10 server. I want to access it with \< my static public ip address \>:9200 I can access my elasticsearch from the server with: localhost:9200 \<my ipv4 address from …

---

## [I don't see db queries in elastic apm dotnet profiler agent](https://discuss.elastic.co/t/i-dont-see-db-queries-in-elastic-apm-dotnet-profiler-agent/334746)

<div class="topic-metadata">

**Author:** [@jeong.hpe](https://discuss.elastic.co/u/jeong.hpe)\
**Replies:** 0\
**Last updated:** [May 31, 2023, 6:32am UTC](https://discuss.elastic.co/t/i-dont-see-db-queries-in-elastic-apm-dotnet-profiler-agent/334746 "2023-05-31T06:32:02Z")

</div>

my iis site web.config I am using profiler. Why do I not see the db query? http 20x, 30x, 40x, 50x codes only!

---

## [Vega :- Link on text Mark which redirects to another dashboard with filter applied as per click value](https://discuss.elastic.co/t/vega-link-on-text-mark-which-redirects-to-another-dashboard-with-filter-applied-as-per-click-value/333173)

<div class="topic-metadata">

**Author:** [@Fiza](https://discuss.elastic.co/u/Fiza)\
**Replies:** 3\
**Last updated:** [May 31, 2023, 8:38am UTC](https://discuss.elastic.co/t/vega-link-on-text-mark-which-redirects-to-another-dashboard-with-filter-applied-as-per-click-value/333173 "2023-05-31T08:38:18Z")

</div>

I have created a table view in Vega and trying to put link on one of the column. The link should redirect to the new dashboard with the clicked value as filter. I want the Kibana URL functionality to apply on Vega where…

---

## [Retrieve additional information with alerts](https://discuss.elastic.co/t/retrieve-additional-information-with-alerts/334765)

<div class="topic-metadata">

**Author:** [@Skairik](https://discuss.elastic.co/u/Skairik)\
**Replies:** 0\
**Last updated:** [May 31, 2023, 8:32am UTC](https://discuss.elastic.co/t/retrieve-additional-information-with-alerts/334765 "2023-05-31T08:32:43Z")

</div>

Hello everyone, I am currently setting up various alerts on Kibana and would need to know if what I want to set up is possible. I currently have a Threshold rule with these parameters: And the following action: …

---

## [How to get CPU, Memory and Storage from VCenter not VM's using Logstash](https://discuss.elastic.co/t/how-to-get-cpu-memory-and-storage-from-vcenter-not-vms-using-logstash/334747)

<div class="topic-metadata">

**Author:** [@gaetano](https://discuss.elastic.co/u/gaetano)\
**Replies:** 0\
**Last updated:** [May 31, 2023, 6:32am UTC](https://discuss.elastic.co/t/how-to-get-cpu-memory-and-storage-from-vcenter-not-vms-using-logstash/334747 "2023-05-31T06:32:05Z")

</div>

I'm trying to send CPU, Memory and Storage parameters of VCenter Server (VMWare) to Elasticsearch node (8.6.1 verson) passing by Logstash 8.6.1. What MIB file should I use to get those specific parameters? This is my Lo…

[Previous page](https://discuss.elastic.co/latest.md?page=658)

[Next page](https://discuss.elastic.co/latest.md?page=660)
