# Latest

**URL:** https://discuss.elastic.co/latest.md?page=666

[Latest](https://discuss.elastic.co/latest.md) · [Categories](https://discuss.elastic.co/categories.md) · [Tags](https://discuss.elastic.co/tags.md)

**Page:** 667

---

## [Filebeat Error and Configuration Issues](https://discuss.elastic.co/t/filebeat-error-and-configuration-issues/334094)

<div class="topic-metadata">

**Author:** [@Priyaansh\_Dwivedi](https://discuss.elastic.co/u/Priyaansh_Dwivedi)\
**Replies:** 3\
**Last updated:** [May 25, 2023, 11:56am UTC](https://discuss.elastic.co/t/filebeat-error-and-configuration-issues/334094 "2023-05-25T11:56:20Z")

</div>

Despite my efforts, I have been unable to resolve the following error messages and configuration challenges. Your expertise and guidance would be greatly appreciated! When checking the status of Filebeat, I encountered …

---

## [System.filesystem.used.pct showing 0.55 want to change it in 55% on Visualization](https://discuss.elastic.co/t/system-filesystem-used-pct-showing-0-55-want-to-change-it-in-55-on-visualization/334020)

<div class="topic-metadata">

**Author:** [@vaibhav.ubale](https://discuss.elastic.co/u/vaibhav.ubale)\
**Replies:** 3\
**Last updated:** [May 25, 2023, 11:54am UTC](https://discuss.elastic.co/t/system-filesystem-used-pct-showing-0-55-want-to-change-it-in-55-on-visualization/334020 "2023-05-25T11:54:39Z")

</div>

Hi All, system.filesystem.used.pct showing 0.55 want to change it in 55% on Visualization/Dashboard. How can I change this. Thanks in advance Vaibhav Ubale

---

## [Assign current user to acknowledged alert / Elastic Security](https://discuss.elastic.co/t/assign-current-user-to-acknowledged-alert-elastic-security/334314)

<div class="topic-metadata">

**Author:** [@Mike\_S](https://discuss.elastic.co/u/Mike_S)\
**Replies:** 0\
**Last updated:** [May 25, 2023, 11:46am UTC](https://discuss.elastic.co/t/assign-current-user-to-acknowledged-alert-elastic-security/334314 "2023-05-25T11:46:16Z")

</div>

Hi, Is it possible to set the current user that has acknowledged an alert to a new field using the painless / runtime scripts to set a value? I've read over some documentation for it but can't figure out how to pull the…

---

## [Pass raw search object to \`SearchAsync\` Elastic.Clients.Elasticsearch 8.1.1 .NET](https://discuss.elastic.co/t/pass-raw-search-object-to-searchasync-elastic-clients-elasticsearch-8-1-1-net/334311)

<div class="topic-metadata">

**Author:** [@felix-stnr](https://discuss.elastic.co/u/felix-stnr)\
**Replies:** 0\
**Last updated:** [May 25, 2023, 11:10am UTC](https://discuss.elastic.co/t/pass-raw-search-object-to-searchasync-elastic-clients-elasticsearch-8-1-1-net/334311 "2023-05-25T11:10:55Z")

</div>

I am trying to implement an API, which allows users to dynamically query an Elasticsearch index. The API should therefore act like a "proxy" between the user and Elasticsearch (the API performs additional operations alon…

---

## [Can U help with optimal search method?](https://discuss.elastic.co/t/can-u-help-with-optimal-search-method/334310)

<div class="topic-metadata">

**Author:** [@Nurm](https://discuss.elastic.co/u/Nurm)\
**Replies:** 0\
**Last updated:** [May 25, 2023, 11:03am UTC](https://discuss.elastic.co/t/can-u-help-with-optimal-search-method/334310 "2023-05-25T11:03:43Z")

</div>

Can you guys show the best way to find users by first and last name or by full name. Also, when the user enters a name, I want to search for that name in both Cyrillic and Latin. Any links, ideas? Client could enter N…

---

## [Kibana drill down on bar charts](https://discuss.elastic.co/t/kibana-drill-down-on-bar-charts/334208)

<div class="topic-metadata">

**Author:** [@subash](https://discuss.elastic.co/u/subash)\
**Replies:** 1\
**Last updated:** [May 25, 2023, 10:35am UTC](https://discuss.elastic.co/t/kibana-drill-down-on-bar-charts/334208 "2023-05-25T10:35:36Z")

</div>

Hi, We are using kibana 7.17. In one of the use cases, it is required to drill down to a dashboard based on the clicked value in a bar chart. Attached the screenshot below. In this case, when the user clicks on a bar …

---

## [Polygon Self-Intersecting when there is minimal wrapping at -180/180 failing](https://discuss.elastic.co/t/polygon-self-intersecting-when-there-is-minimal-wrapping-at-180-180-failing/334065)

<div class="topic-metadata">

**Author:** [@Craig\_Roush](https://discuss.elastic.co/u/Craig_Roush)\
**Replies:** 13\
**Last updated:** [May 25, 2023, 10:05am UTC](https://discuss.elastic.co/t/polygon-self-intersecting-when-there-is-minimal-wrapping-at-180-180-failing/334065 "2023-05-25T10:05:31Z")

</div>

I am receiving a polygon-self intersecting error when I have a polygon that barely wraps across 180 to -180: I have a simple mapping for a index setup as: index\_mapping = { "time": { "type": "da…

---

## [Kibana conflicting field](https://discuss.elastic.co/t/kibana-conflicting-field/334301)

<div class="topic-metadata">

**Author:** [@jfrank](https://discuss.elastic.co/u/jfrank)\
**Replies:** 1\
**Last updated:** [May 25, 2023, 9:57am UTC](https://discuss.elastic.co/t/kibana-conflicting-field/334301 "2023-05-25T09:57:10Z")

</div>

Recently I've changed type of the field from text to long and now I see in documents in Kibana that this field is "conflicting". How Can I solve this? Kibana v 8.1.0

---

## [How to extract all log sources in ELK?](https://discuss.elastic.co/t/how-to-extract-all-log-sources-in-elk/334188)

<div class="topic-metadata">

**Author:** [@UP\_NEWS](https://discuss.elastic.co/u/UP_NEWS)\
**Replies:** 6\
**Last updated:** [May 25, 2023, 9:45am UTC](https://discuss.elastic.co/t/how-to-extract-all-log-sources-in-elk/334188 "2023-05-25T09:45:41Z")

</div>

Hi team, I'm new in elastic stack , please i need a procedure how to extract all the source logs IP and status if possible, for example i have 10 servers linux redhat integrated in elastic with auditbeat and i have 10 w…

---

## [The analyser in mapping is not getting applied to field](https://discuss.elastic.co/t/the-analyser-in-mapping-is-not-getting-applied-to-field/334286)

<div class="topic-metadata">

**Author:** [@Sheereen](https://discuss.elastic.co/u/Sheereen)\
**Replies:** 2\
**Last updated:** [May 25, 2023, 9:38am UTC](https://discuss.elastic.co/t/the-analyser-in-mapping-is-not-getting-applied-to-field/334286 "2023-05-25T09:38:44Z")

</div>

This is the mapping and settings { "blogs\_fixed2": { "aliases": {}, "mappings": { "\_meta": { "created\_by": "Sheereen Hamza KV" }, "properties": { "@timestamp": { "t…

---

## [All Host details are not visible in kibana APM UI](https://discuss.elastic.co/t/all-host-details-are-not-visible-in-kibana-apm-ui/334265)

<div class="topic-metadata">

**Author:** [@Anand\_Hitachi](https://discuss.elastic.co/u/Anand_Hitachi)\
**Replies:** 1\
**Last updated:** [May 25, 2023, 9:20am UTC](https://discuss.elastic.co/t/all-host-details-are-not-visible-in-kibana-apm-ui/334265 "2023-05-25T09:20:31Z")

</div>

All Host details are not visible in kibana APM UI even though CPU usage was detected for a certain time period . i had installed java APM agent into my host for easytravel application as demo run. Please find SS attache…

---

## [Elastic search Client API](https://discuss.elastic.co/t/elastic-search-client-api/334288)

<div class="topic-metadata">

**Author:** [@Gururaj\_Shivananda](https://discuss.elastic.co/u/Gururaj_Shivananda)\
**Replies:** 7\
**Last updated:** [May 25, 2023, 9:16am UTC](https://discuss.elastic.co/t/elastic-search-client-api/334288 "2023-05-25T09:16:26Z")

</div>

Hi we are using Elastic Search client API to read/write from OpenSearch. This is part of commercial service provided to customer. How would SSPL license Apply here.

---

## [Failing to setup Elasticsearch dual node cluster](https://discuss.elastic.co/t/failing-to-setup-elasticsearch-dual-node-cluster/334298)

<div class="topic-metadata">

**Author:** [@ANUBHAV\_GUPTA](https://discuss.elastic.co/u/ANUBHAV_GUPTA)\
**Replies:** 0\
**Last updated:** [May 25, 2023, 9:15am UTC](https://discuss.elastic.co/t/failing-to-setup-elasticsearch-dual-node-cluster/334298 "2023-05-25T09:15:43Z")

</div>

I am trying to run a 2 node Elasticsearch cluster on different ec2 instances present in different regions. I using the following commands:- Command to run data node:- sudo docker run -it --pull=always --privileged --…

---

## [Manage Multiple instances of Elasticsearch cluster with different version by ECK](https://discuss.elastic.co/t/manage-multiple-instances-of-elasticsearch-cluster-with-different-version-by-eck/332894)

<div class="topic-metadata">

**Author:** [@HadarPeeran](https://discuss.elastic.co/u/HadarPeeran)\
**Replies:** 3\
**Last updated:** [May 25, 2023, 9:02am UTC](https://discuss.elastic.co/t/manage-multiple-instances-of-elasticsearch-cluster-with-different-version-by-eck/332894 "2023-05-25T09:02:00Z")

</div>

I should deploy Elasticsearch 8 and Elasticsearch 7 on the same AKS cluster. Is it possible to upgrade the ECK operator to the latest 2.7.0 and deploy Elasticsearch 7 and 8 by this one operator? thanks

---

## [Taking snapshot of existing data and restore it after some disaster](https://discuss.elastic.co/t/taking-snapshot-of-existing-data-and-restore-it-after-some-disaster/334174)

<div class="topic-metadata">

**Author:** [@kunalhiremath](https://discuss.elastic.co/u/kunalhiremath)\
**Replies:** 2\
**Last updated:** [May 25, 2023, 8:09am UTC](https://discuss.elastic.co/t/taking-snapshot-of-existing-data-and-restore-it-after-some-disaster/334174 "2023-05-25T08:09:26Z")

</div>

I am running one node which is a master node it receives data/logs from data nodes. This node has some indices that are created when I install this master node on a server. So the logs generated by master node and data …

---

## [Customizing facet labels in Search UI](https://discuss.elastic.co/t/customizing-facet-labels-in-search-ui/334255)

<div class="topic-metadata">

**Author:** [@John\_Brandenburg](https://discuss.elastic.co/u/John_Brandenburg)\
**Replies:** 1\
**Last updated:** [May 25, 2023, 7:34am UTC](https://discuss.elastic.co/t/customizing-facet-labels-in-search-ui/334255 "2023-05-25T07:34:30Z")

</div>

I saw this topic asking how to custom facet labels in Search UI, and I figured out a way to do that, and thought I would share. p.s. you should consider not closing topics in only 28 days. In tech forums, people may come…

---

## [Rolover policy for custom Index](https://discuss.elastic.co/t/rolover-policy-for-custom-index/333399)

<div class="topic-metadata">

**Author:** [@VellayLoket](https://discuss.elastic.co/u/VellayLoket)\
**Replies:** 2\
**Last updated:** [May 25, 2023, 6:47am UTC](https://discuss.elastic.co/t/rolover-policy-for-custom-index/333399 "2023-05-25T06:47:08Z")

</div>

I got logs from winlogbeats, and i want to store them in custom indexes. So i need rollover policy for this indexes. here is part of logstash config file (output): output { if \[type\] == "winlogbeat" { elasticsearc…

---

## [Search\_phase\_execution\_exception error with all\_shared failes](https://discuss.elastic.co/t/search-phase-execution-exception-error-with-all-shared-failes/334169)

<div class="topic-metadata">

**Author:** [@Kapildev](https://discuss.elastic.co/u/Kapildev)\
**Replies:** 15\
**Last updated:** [May 25, 2023, 6:18am UTC](https://discuss.elastic.co/t/search-phase-execution-exception-error-with-all-shared-failes/334169 "2023-05-25T06:18:32Z")

</div>

hi team i am facing this search\_phase\_execution\_exception Please find the details. curl -X GET "localhost:9200/\_cluster/health?filter\_path=status,\*\_shards&pretty" { "status" : "red", "active\_primary\_shards" : 0, "…

---

## [elasticsearch build error](https://discuss.elastic.co/t/elasticsearch-build-error/334269)

<div class="topic-metadata">

**Author:** [@sand-hya](https://discuss.elastic.co/u/sand-hya)\
**Replies:** 0\
**Last updated:** [May 25, 2023, 4:56am UTC](https://discuss.elastic.co/t/elasticsearch-build-error/334269 "2023-05-25T04:56:48Z")

</div>

Hello, I was running elasticsearch 7.6.0 version from source, and when I run ./gradlew assemble I am getting this error. Configure project :x-pack:qa:third-party:active-directory Tests for :x-pack:qa:third-party:acti…

---

## [How to view inner IP packet detail](https://discuss.elastic.co/t/how-to-view-inner-ip-packet-detail/334267)

<div class="topic-metadata">

**Author:** [@a\_techie](https://discuss.elastic.co/u/a_techie)\
**Replies:** 0\
**Last updated:** [May 25, 2023, 4:50am UTC](https://discuss.elastic.co/t/how-to-view-inner-ip-packet-detail/334267 "2023-05-25T04:50:21Z")

</div>

Hello, We send flow data from network gears to Elasticsearch. There are packets that are encapsulated in another IP header. For example, please refer: CS Enterprise on cloudshark.org In the flow data search using Kiban…

---

## [Calculate percentage based on other aggregation](https://discuss.elastic.co/t/calculate-percentage-based-on-other-aggregation/334264)

<div class="topic-metadata">

**Author:** [@Wanching\_Teoh](https://discuss.elastic.co/u/Wanching_Teoh)\
**Replies:** 1\
**Last updated:** [May 25, 2023, 4:21am UTC](https://discuss.elastic.co/t/calculate-percentage-based-on-other-aggregation/334264 "2023-05-25T04:21:53Z")

</div>

Hi, I am using data table to display the API response for 200, 4xx and 5xx errors. I need to calculate percentage of 4xx and 5xx errors based on the grand total count of all response types. Any idea on how to do this o…

---

## [I am getting the error in elasticsearch Rollup jobs](https://discuss.elastic.co/t/i-am-getting-the-error-in-elasticsearch-rollup-jobs/334262)

<div class="topic-metadata">

**Author:** [@daemon](https://discuss.elastic.co/u/daemon)\
**Replies:** 0\
**Last updated:** [May 25, 2023, 12:32am UTC](https://discuss.elastic.co/t/i-am-getting-the-error-in-elasticsearch-rollup-jobs/334262 "2023-05-25T00:32:24Z")

</div>

I am getting the error in Kibana Rollup Jobs screen as shown in the image. Is there any solution?

---

## [Logstash plugin is installed and not listed and found by logstash](https://discuss.elastic.co/t/logstash-plugin-is-installed-and-not-listed-and-found-by-logstash/333595)

<div class="topic-metadata">

**Author:** [@SAMY-ELK](https://discuss.elastic.co/u/SAMY-ELK)\
**Replies:** 5\
**Last updated:** [May 23, 2023, 9:24pm UTC](https://discuss.elastic.co/t/logstash-plugin-is-installed-and-not-listed-and-found-by-logstash/333595 "2023-05-23T21:24:34Z")

</div>

Hi Team, Microsoft-sentinel-logstash-output-plugin is installed on logstash (7.15.1) server Linux but is not listed and found by logstash : /usr/share/logstash/bin #./logstash-plugin list Plugin successfully install…

---

## [Installing Elastic Cloud Enterprise Offline](https://discuss.elastic.co/t/installing-elastic-cloud-enterprise-offline/334240)

<div class="topic-metadata">

**Author:** [@geomandry](https://discuss.elastic.co/u/geomandry)\
**Replies:** 3\
**Last updated:** [May 24, 2023, 4:25pm UTC](https://discuss.elastic.co/t/installing-elastic-cloud-enterprise-offline/334240 "2023-05-24T16:25:30Z")

</div>

There are too many documents! Can someone reply with the correct guides for installing Elastic Cloud Enterprise offline on a Linux box?

---

## [COPY - PASTE from KIBANA without “ROW” and “COLUMN” information - 2](https://discuss.elastic.co/t/copy-paste-from-kibana-without-row-and-column-information-2/334026)

<div class="topic-metadata">

**Author:** [@mch](https://discuss.elastic.co/u/mch)\
**Replies:** 3\
**Last updated:** [May 24, 2023, 2:57pm UTC](https://discuss.elastic.co/t/copy-paste-from-kibana-without-row-and-column-information-2/334026 "2023-05-24T14:57:41Z")

</div>

Hello everyone, I have the same problem as described in the following ticket: COPY - PASTE from KIBANA without "ROW" and "COLUMN" information It's a real pain to export the selection we're interested in every time, whe…

---

## [How can I handle typos in synonyms?](https://discuss.elastic.co/t/how-can-i-handle-typos-in-synonyms/334141)

<div class="topic-metadata">

**Author:** [@gennadii](https://discuss.elastic.co/u/gennadii)\
**Replies:** 12\
**Last updated:** [May 24, 2023, 2:54pm UTC](https://discuss.elastic.co/t/how-can-i-handle-typos-in-synonyms/334141 "2023-05-24T14:54:38Z")

</div>

I have synonyms in synonyms.txt - "auto, vehicle =\> car". In index I have a document with string "car" and an analyzer to handle synonyms. When you use "auto", for example, it will also return you results for "car". B…

---

## [Date Range filter is not working ? NEST C# MVC.NET](https://discuss.elastic.co/t/date-range-filter-is-not-working-nest-c-mvc-net/334129)

<div class="topic-metadata">

**Author:** [@Samer\_Abdelwahed](https://discuss.elastic.co/u/Samer_Abdelwahed)\
**Replies:** 5\
**Last updated:** [May 24, 2023, 2:48pm UTC](https://discuss.elastic.co/t/date-range-filter-is-not-working-nest-c-mvc-net/334129 "2023-05-24T14:48:28Z")

</div>

hi every one Why date Range filter is not working in my code: public static DateRangeQuery GetSearchFromDate(int DayFrom, int DayTo, int MonthFrom, int MonthTo, int YearFrom, int YearTo, string fieldName) …

---

## [Not able to stop the tasks in devtool (Kibana)](https://discuss.elastic.co/t/not-able-to-stop-the-tasks-in-devtool-kibana/333857)

<div class="topic-metadata">

**Author:** [@sanjeevtomar](https://discuss.elastic.co/u/sanjeevtomar)\
**Replies:** 1\
**Last updated:** [May 24, 2023, 2:36pm UTC](https://discuss.elastic.co/t/not-able-to-stop-the-tasks-in-devtool-kibana/333857 "2023-05-24T14:36:43Z")

</div>

1.Firstly, "delete by query" was run. it exhausted 100 % of disk space, then I tried POST /\_forcemerge after adding more disk space but this space is also getting consumed rapidly can I cancel the tasks which are …

---

## [Corrupt index in Logstash causing primary shard is not active](https://discuss.elastic.co/t/corrupt-index-in-logstash-causing-primary-shard-is-not-active/334229)

<div class="topic-metadata">

**Author:** [@Vaibhav\_Aher](https://discuss.elastic.co/u/Vaibhav_Aher)\
**Replies:** 2\
**Last updated:** [May 24, 2023, 2:34pm UTC](https://discuss.elastic.co/t/corrupt-index-in-logstash-causing-primary-shard-is-not-active/334229 "2023-05-24T14:34:19Z")

</div>

Elasticsearch Version- opendistroforelasticsearch-1.4.0 Logstash Version - logstash-7.4.2 Error on Logstash: retrying failed action with response code: 503 ({"type"=\>"unavailable\_shards\_exception", "reason"=\>"\[ABC-20…

---

## [Time zone abbr is ambigous which cause @timestamp parsed wrong \[for Postgresql module\]](https://discuss.elastic.co/t/time-zone-abbr-is-ambigous-which-cause-timestamp-parsed-wrong-for-postgresql-module/333863)

<div class="topic-metadata">

**Author:** [@yanhj93](https://discuss.elastic.co/u/yanhj93)\
**Replies:** 1\
**Last updated:** [May 24, 2023, 2:33pm UTC](https://discuss.elastic.co/t/time-zone-abbr-is-ambigous-which-cause-timestamp-parsed-wrong-for-postgresql-module/333863 "2023-05-24T14:33:13Z")

</div>

Our postgre server log with timezone CST, in this case it represents China standard time. pipeline(module provid) will parse the log message and read timezone value use WORD pattern, finally date processor parse the tim…

[Previous page](https://discuss.elastic.co/latest.md?page=665)

[Next page](https://discuss.elastic.co/latest.md?page=667)
