# Latest

**URL:** https://discuss.elastic.co/latest.md?page=663

[Latest](https://discuss.elastic.co/latest.md) · [Categories](https://discuss.elastic.co/categories.md) · [Tags](https://discuss.elastic.co/tags.md)

**Page:** 664

---

## [Using Metricbeat to send Filebeat logs to ES](https://discuss.elastic.co/t/using-metricbeat-to-send-filebeat-logs-to-es/333850)

<div class="topic-metadata">

**Author:** [@hjazz6](https://discuss.elastic.co/u/hjazz6)\
**Replies:** 6\
**Last updated:** [May 29, 2023, 5:43am UTC](https://discuss.elastic.co/t/using-metricbeat-to-send-filebeat-logs-to-es/333850 "2023-05-29T05:43:19Z")

</div>

Hi, I'm running both Filebeat 8.3.3 and Metricbeat 8.3.3 on my RHEL 7.9 server, and sending the logs to another server which is hosting Elasticsearch and Kibana. My filebeat is sending syslog to the ES (I'm simply usin…

---

## [Insecure param does not complete disable verification](https://discuss.elastic.co/t/insecure-param-does-not-complete-disable-verification/334549)

<div class="topic-metadata">

**Author:** [@kmahyyg](https://discuss.elastic.co/u/kmahyyg)\
**Replies:** 0\
**Last updated:** [May 29, 2023, 5:01am UTC](https://discuss.elastic.co/t/insecure-param-does-not-complete-disable-verification/334549 "2023-05-29T05:01:08Z")

</div>

I use --insecure when enrolling agent into fleet server in development environment. With some unable-to-say restrictions, this development environment cannot connect to CRL server. However, in current environment, the c…

---

## [ElasticSearch - search\_after pagination sort](https://discuss.elastic.co/t/elasticsearch-search-after-pagination-sort/334502)

<div class="topic-metadata">

**Author:** [@VJ052023](https://discuss.elastic.co/u/VJ052023)\
**Replies:** 4\
**Last updated:** [May 29, 2023, 4:52am UTC](https://discuss.elastic.co/t/elasticsearch-search-after-pagination-sort/334502 "2023-05-29T04:52:32Z")

</div>

I am trying to fetch results from Elasticsearch API using search\_after for pagination. However, in order to iterate to the subsequent data I am using a sort in the request Body of the API call as shown below "sort": \[ …

---

## [Disable \_source field from indexing](https://discuss.elastic.co/t/disable-source-field-from-indexing/334486)

<div class="topic-metadata">

**Author:** [@Mhag](https://discuss.elastic.co/u/Mhag)\
**Replies:** 6\
**Last updated:** [May 29, 2023, 2:47am UTC](https://discuss.elastic.co/t/disable-source-field-from-indexing/334486 "2023-05-29T02:47:27Z")

</div>

Hi, To reduce the size of an indice I decide not to store \_source field in elasticsearch, but I got this error when I try to diable it. PUT /myindice/\_mapping { "properties": { "\_source": { "enabled": fals…

---

## [How do i create a dashboard and get a url to the dashboard using REST API](https://discuss.elastic.co/t/how-do-i-create-a-dashboard-and-get-a-url-to-the-dashboard-using-rest-api/334056)

<div class="topic-metadata">

**Author:** [@Rishi\_Shukla](https://discuss.elastic.co/u/Rishi_Shukla)\
**Replies:** 1\
**Last updated:** [May 29, 2023, 1:42am UTC](https://discuss.elastic.co/t/how-do-i-create-a-dashboard-and-get-a-url-to-the-dashboard-using-rest-api/334056 "2023-05-29T01:42:32Z")

</div>

How do i create a dashboard and get a url to the dashboard using REST API. I am running v7.13.0 which i cannot upgrade in the near term.

---

## [Part of the file bit 'daemonset pod' is CrashLoopBackOff](https://discuss.elastic.co/t/part-of-the-file-bit-daemonset-pod-is-crashloopbackoff/334261)

<div class="topic-metadata">

**Author:** [@oliverpark999](https://discuss.elastic.co/u/oliverpark999)\
**Replies:** 1\
**Last updated:** [May 29, 2023, 12:52am UTC](https://discuss.elastic.co/t/part-of-the-file-bit-daemonset-pod-is-crashloopbackoff/334261 "2023-05-29T00:52:13Z")

</div>

I configured Filebeat + Logstash in Kubernetes environment. It is working normally, but some of the Filebeat 'demonsets' do not appear to be working normally. What kind of problem? filebeat-1 1/1 Runn…

---

## [Alert index is not getting generated](https://discuss.elastic.co/t/alert-index-is-not-getting-generated/333924)

<div class="topic-metadata">

**Author:** [@Ibraheem\_Alharbi](https://discuss.elastic.co/u/Ibraheem_Alharbi)\
**Replies:** 1\
**Last updated:** [May 29, 2023, 1:11am UTC](https://discuss.elastic.co/t/alert-index-is-not-getting-generated/333924 "2023-05-29T01:11:25Z")

</div>

I didn't receive alert in elastic even agent is installed Please I need help just view little hours before delivering my project

---

## [java.lang.IllegalArgumentException: Setting \[xpack.security.transport.ssl.keystore.path\] is a non-secure setting and must be stored inside elasticsearch.yml, but was found inside the Elasticsearch keystore](https://discuss.elastic.co/t/java-lang-illegalargumentexception-setting-xpack-security-transport-ssl-keystore-path-is-a-non-secure-setting-and-must-be-stored-inside-elasticsearch-yml-but-was-found-inside-the-elasticsearch-keystore/333700)

<div class="topic-metadata">

**Author:** [@tungnx1](https://discuss.elastic.co/u/tungnx1)\
**Replies:** 1\
**Last updated:** [May 29, 2023, 12:38am UTC](https://discuss.elastic.co/t/java-lang-illegalargumentexception-setting-xpack-security-transport-ssl-keystore-path-is-a-non-secure-setting-and-must-be-stored-inside-elasticsearch-yml-but-was-found-inside-the-elasticsearch-keystore/333700 "2023-05-29T00:38:18Z")

</div>

Why after run: ./bin/elasticsearch-certutil http folder master: total 12 -rwxr-xr-x 1 root elasticsearch 3620 May 17 17:24 http.p12 -rwxr-xr-x 1 root elasticsearch 1365 May 17 17:24 README.txt -rwxr-xr-x 1 root elast…

---

## [How to print out the data in Kibana from AWS WAF?](https://discuss.elastic.co/t/how-to-print-out-the-data-in-kibana-from-aws-waf/334374)

<div class="topic-metadata">

**Author:** [@ecommd4wg](https://discuss.elastic.co/u/ecommd4wg)\
**Replies:** 3\
**Last updated:** [May 29, 2023, 12:05am UTC](https://discuss.elastic.co/t/how-to-print-out-the-data-in-kibana-from-aws-waf/334374 "2023-05-29T00:05:55Z")

</div>

n00b here. I have kibana in AWS with AWF data. I need to print out the fields and the data to see what is in them. Is there a default query to do this, that I can plug into the dev tools window? Thank you

---

## [Using Terms filter query API via elastic .net client](https://discuss.elastic.co/t/using-terms-filter-query-api-via-elastic-net-client/334439)

<div class="topic-metadata">

**Author:** [@Sagar\_Kayasth2](https://discuss.elastic.co/u/Sagar_Kayasth2)\
**Replies:** 0\
**Last updated:** [May 26, 2023, 1:50pm UTC](https://discuss.elastic.co/t/using-terms-filter-query-api-via-elastic-net-client/334439 "2023-05-26T13:50:38Z")

</div>

Hi I am currently trying to write a Terms Query via the Elastic.Clients.Elasticsearch 8.1.1 .NET client. I have to apply dynamic terms query filter for filtered categories Ids. If any category id not selected then not …

---

## [Cannot run service elastic](https://discuss.elastic.co/t/cannot-run-service-elastic/334478)

<div class="topic-metadata">

**Author:** [@Wiwatsapon\_Lertworas](https://discuss.elastic.co/u/Wiwatsapon_Lertworas)\
**Replies:** 3\
**Last updated:** [May 28, 2023, 11:20pm UTC](https://discuss.elastic.co/t/cannot-run-service-elastic/334478 "2023-05-28T23:20:31Z")

</div>

This is my error on run sudo service elasticsearch start May 27 03:07:57 elk-stack systemd-entrypoint\[354840\]: Exception in thread "main" java.lang.NullPointerException: Cannot invoke "org.apache.logging.log4j.core.con…

---

## [Jaro Winkler algorithm in elasticsearch](https://discuss.elastic.co/t/jaro-winkler-algorithm-in-elasticsearch/334505)

<div class="topic-metadata">

**Author:** [@Bakhodur\_Karomatov](https://discuss.elastic.co/u/Bakhodur_Karomatov)\
**Replies:** 4\
**Last updated:** [May 28, 2023, 11:18pm UTC](https://discuss.elastic.co/t/jaro-winkler-algorithm-in-elasticsearch/334505 "2023-05-28T23:18:32Z")

</div>

can i use jaro winkler algorithm in elasticsearch?

---

## [Elasticsearch Kuromoji plugin](https://discuss.elastic.co/t/elasticsearch-kuromoji-plugin/334361)

<div class="topic-metadata">

**Author:** [@a4amann](https://discuss.elastic.co/u/a4amann)\
**Replies:** 0\
**Last updated:** [May 25, 2023, 6:25pm UTC](https://discuss.elastic.co/t/elasticsearch-kuromoji-plugin/334361 "2023-05-25T18:25:40Z")

</div>

What is the expected output when we run : PUT test { "settings": { "index": { "analysis": { "filter": { "kuromoji\_number": { "type": "kuromoji\_number" }, "ku…

---

## [Kibana issue with timeouts on reports](https://discuss.elastic.co/t/kibana-issue-with-timeouts-on-reports/334152)

<div class="topic-metadata">

**Author:** [@dominbdg](https://discuss.elastic.co/u/dominbdg)\
**Replies:** 2\
**Last updated:** [May 28, 2023, 10:19pm UTC](https://discuss.elastic.co/t/kibana-issue-with-timeouts-on-reports/334152 "2023-05-28T22:19:18Z")

</div>

Hello I have following issue, Users are trying to perform reportts on Kibana, Reports are performing reports, but reports are incomplete. I tried to increase timeout and maxfilesize for reporting but this didn't s…

---

## [What is timezone that schedule (configuration option in elasticsearch input logstash) is based on?](https://discuss.elastic.co/t/what-is-timezone-that-schedule-configuration-option-in-elasticsearch-input-logstash-is-based-on/334223)

<div class="topic-metadata">

**Author:** [@alex\_petrov](https://discuss.elastic.co/u/alex_petrov)\
**Replies:** 2\
**Last updated:** [May 28, 2023, 4:15pm UTC](https://discuss.elastic.co/t/what-is-timezone-that-schedule-configuration-option-in-elasticsearch-input-logstash-is-based-on/334223 "2023-05-28T16:15:04Z")

</div>

I have following configuration in my logstash pipeline, I want to schedule to run the query for specific hour every day (schedule =\> "\*/5 \* \* \* \*" already working) , but it doesn't work. I have a distributed environment …

---

## [We are facing issue while installation elastic open source APM](https://discuss.elastic.co/t/we-are-facing-issue-while-installation-elastic-open-source-apm/334420)

<div class="topic-metadata">

**Author:** [@sandeep\_raj](https://discuss.elastic.co/u/sandeep_raj)\
**Replies:** 1\
**Last updated:** [May 28, 2023, 4:02pm UTC](https://discuss.elastic.co/t/we-are-facing-issue-while-installation-elastic-open-source-apm/334420 "2023-05-28T16:02:18Z")

</div>

HI Team we have installed newer version of Elasticsearch using login functionalities , elastic and kibana is working but while using APM, faced lot of challenge. can anyone help for this. Thanks Sandeep

---

## [How to pass variable from Logstash filter into ruby parameter](https://discuss.elastic.co/t/how-to-pass-variable-from-logstash-filter-into-ruby-parameter/334438)

<div class="topic-metadata">

**Author:** [@Jirka\_Liska](https://discuss.elastic.co/u/Jirka_Liska)\
**Replies:** 4\
**Last updated:** [May 28, 2023, 3:59pm UTC](https://discuss.elastic.co/t/how-to-pass-variable-from-logstash-filter-into-ruby-parameter/334438 "2023-05-28T15:59:27Z")

</div>

Hi I'm trying to create a variable which holds information from input file path. I'm able to do so for example for creating index in Kibana but I'm unable to pass this variable into ruby /plugin/ code. Anyone knows what…

---

## [Help restoring / recreating .security-7](https://discuss.elastic.co/t/help-restoring-recreating-security-7/334499)

<div class="topic-metadata">

**Author:** [@A.Hani](https://discuss.elastic.co/u/A.Hani)\
**Replies:** 12\
**Last updated:** [May 28, 2023, 2:31pm UTC](https://discuss.elastic.co/t/help-restoring-recreating-security-7/334499 "2023-05-28T14:31:39Z")

</div>

Hello, Faced an error where kibana failed to retrieve password hash for reserved user \[kibana\] at least one primary shard for the index .security-7 was missing. Followed the instructions provided here at https://discus…

---

## [Use text field as label in data visualization](https://discuss.elastic.co/t/use-text-field-as-label-in-data-visualization/334483)

<div class="topic-metadata">

**Author:** [@marine.authorities](https://discuss.elastic.co/u/marine.authorities)\
**Replies:** 1\
**Last updated:** [May 28, 2023, 12:49pm UTC](https://discuss.elastic.co/t/use-text-field-as-label-in-data-visualization/334483 "2023-05-28T12:49:12Z")

</div>

Hi! This is my first time using kibana, so sorry if this was asked before, but the threads I could find by searching were not helpful. My use case is simple: I have an index that contains the fields movieId (integer), t…

---

## [How to display images stored per record in Kibana](https://discuss.elastic.co/t/how-to-display-images-stored-per-record-in-kibana/334487)

<div class="topic-metadata">

**Author:** [@damonmaria](https://discuss.elastic.co/u/damonmaria)\
**Replies:** 3\
**Last updated:** [May 28, 2023, 8:03am UTC](https://discuss.elastic.co/t/how-to-display-images-stored-per-record-in-kibana/334487 "2023-05-28T08:03:49Z")

</div>

Our records contain URLs to images (stored outside of ES). My goal is to be able to ad-hoc filter for records and then see all these images from the records. The best I've been able to achieve is switching from the Docu…

---

## [Multiword exact search](https://discuss.elastic.co/t/multiword-exact-search/334490)

<div class="topic-metadata">

**Author:** [@Matej\_Senozetnik](https://discuss.elastic.co/u/Matej_Senozetnik)\
**Replies:** 1\
**Last updated:** [May 28, 2023, 12:27am UTC](https://discuss.elastic.co/t/multiword-exact-search/334490 "2023-05-28T00:27:07Z")

</div>

Hello, I would kindly ask how to make multi words search with multi keywords. I would like to achive following for SATB2 syndrome would like that I found exact following words: Prader-Willi syndrome (all varation of lo…

---

## [Questions about Visualize Library reports](https://discuss.elastic.co/t/questions-about-visualize-library-reports/334509)

<div class="topic-metadata">

**Author:** [@ezaidepc](https://discuss.elastic.co/u/ezaidepc)\
**Replies:** 4\
**Last updated:** [May 27, 2023, 10:57pm UTC](https://discuss.elastic.co/t/questions-about-visualize-library-reports/334509 "2023-05-27T22:57:27Z")

</div>

I am trying to use Visualize Library reports in Elastic Cloud to create reports/dashboards. However, there are two things I need to do that I cannot figure out how to do: 1 - is remove duplicate entries from my data (be…

---

## [Can not find mongodb log in Discover](https://discuss.elastic.co/t/can-not-find-mongodb-log-in-discover/334202)

<div class="topic-metadata">

**Author:** [@miladghasemi](https://discuss.elastic.co/u/miladghasemi)\
**Replies:** 2\
**Last updated:** [May 27, 2023, 10:05pm UTC](https://discuss.elastic.co/t/can-not-find-mongodb-log-in-discover/334202 "2023-05-27T22:05:43Z")

</div>

Hi (sorry for my bad english) I'm enabled mongodb module in filebeat to send mongodb log into elasticsearch. Filebeat created dashboard, my log show in discover but when i want to search in Dicover,it not show \[event.o…

---

## [Most minimal logstash.yml possible?](https://discuss.elastic.co/t/most-minimal-logstash-yml-possible/334512)

<div class="topic-metadata">

**Author:** [@newmember](https://discuss.elastic.co/u/newmember)\
**Replies:** 1\
**Last updated:** [May 27, 2023, 9:37pm UTC](https://discuss.elastic.co/t/most-minimal-logstash-yml-possible/334512 "2023-05-27T21:37:20Z")

</div>

I would like to load all my inputs via the conf.d folder. What is most minimal logstash.yml fle I can have that will allow logstash to start and then load all the yml files in the conf.d folder? Current logstash.yml fi…

---

## [Understanding filters cache for filters nested inside should clause of parent boolean query](https://discuss.elastic.co/t/understanding-filters-cache-for-filters-nested-inside-should-clause-of-parent-boolean-query/334511)

<div class="topic-metadata">

**Author:** [@Sarthak\_Madaan](https://discuss.elastic.co/u/Sarthak_Madaan)\
**Replies:** 0\
**Last updated:** [May 27, 2023, 8:52pm UTC](https://discuss.elastic.co/t/understanding-filters-cache-for-filters-nested-inside-should-clause-of-parent-boolean-query/334511 "2023-05-27T20:52:39Z")

</div>

{ "from": 0, "size": 2, "timeout": "10ms", "query": { "bool": { "should": \[ { "bool": { "filter": \[ …

---

## [Observability machine learning use cases](https://discuss.elastic.co/t/observability-machine-learning-use-cases/334417)

<div class="topic-metadata">

**Author:** [@abu7midandev](https://discuss.elastic.co/u/abu7midandev)\
**Replies:** 1\
**Last updated:** [May 27, 2023, 7:16pm UTC](https://discuss.elastic.co/t/observability-machine-learning-use-cases/334417 "2023-05-27T19:16:10Z")

</div>

dears i hope all of you doing well i am new with elastic and i need support in some points i have built APM dashboard with elastic agent and monitor our services i didn't find any topics about how to use elastic ml i…

---

## [Logstash Split Message with Multiple Messages](https://discuss.elastic.co/t/logstash-split-message-with-multiple-messages/334466)

<div class="topic-metadata">

**Author:** [@balogan](https://discuss.elastic.co/u/balogan)\
**Replies:** 3\
**Last updated:** [May 27, 2023, 2:36pm UTC](https://discuss.elastic.co/t/logstash-split-message-with-multiple-messages/334466 "2023-05-27T14:36:39Z")

</div>

Logfile I need to ingest. You can see there are 3 separate messages under alerts. We need to split that up into 3 separate messages. { "@timestamp": "2023-05-23T18:15:30.537972Z", "alerts": \[ { "s…

---

## [filebeat:Frequently occurring "should have been dropped, but couldn't as state is not finished"](https://discuss.elastic.co/t/filebeat-frequently-occurring-should-have-been-dropped-but-couldnt-as-state-is-not-finished/334497)

<div class="topic-metadata">

**Author:** [@micmeow](https://discuss.elastic.co/u/micmeow)\
**Replies:** 1\
**Last updated:** [May 27, 2023, 10:25am UTC](https://discuss.elastic.co/t/filebeat-frequently-occurring-should-have-been-dropped-but-couldnt-as-state-is-not-finished/334497 "2023-05-27T10:25:21Z")

</div>

Hello. If you know how fix that, lend me your wisdom. I use filebeat to transfer logs to Logstash to Opensearch. When I checked the filebeat log, I found that the same log file transfer errors were occurring frequently…

---

## [Logstash aggregate and calculate the sum of counts](https://discuss.elastic.co/t/logstash-aggregate-and-calculate-the-sum-of-counts/334495)

<div class="topic-metadata">

**Author:** [@m3bgwad](https://discuss.elastic.co/u/m3bgwad)\
**Replies:** 0\
**Last updated:** [May 27, 2023, 10:20am UTC](https://discuss.elastic.co/t/logstash-aggregate-and-calculate-the-sum-of-counts/334495 "2023-05-27T10:20:07Z")

</div>

Hello All, I have a scenario, I need the expertise to support this, and thanks in advanced I have a statement running by the JDBC input plugin every 1 minute, so the results returned every 1 minute until if the result…

---

## [Doubts about Kibana Rules and conections alerts](https://discuss.elastic.co/t/doubts-about-kibana-rules-and-conections-alerts/334450)

<div class="topic-metadata">

**Author:** [@ElasticLiver](https://discuss.elastic.co/u/ElasticLiver)\
**Replies:** 1\
**Last updated:** [May 26, 2023, 7:54pm UTC](https://discuss.elastic.co/t/doubts-about-kibana-rules-and-conections-alerts/334450 "2023-05-26T19:54:14Z")

</div>

Hi, I got a couple of doubts: In a Metric threshold rule, the condition "For the last 5 minutes" will trigger an alert if any document in that time range surpass the threshold specified? or is it like a bucket? if the…

[Previous page](https://discuss.elastic.co/latest.md?page=662)

[Next page](https://discuss.elastic.co/latest.md?page=664)
