# Latest

**URL:** https://discuss.elastic.co/latest.md?page=680

[Latest](https://discuss.elastic.co/latest.md) · [Categories](https://discuss.elastic.co/categories.md) · [Tags](https://discuss.elastic.co/tags.md)

**Page:** 681

---

## [How do I 'Update All Fields Where'](https://discuss.elastic.co/t/how-do-i-update-all-fields-where/333293)

<div class="topic-metadata">

**Author:** [@ste1](https://discuss.elastic.co/u/ste1)\
**Replies:** 0\
**Last updated:** [May 12, 2023, 11:21am UTC](https://discuss.elastic.co/t/how-do-i-update-all-fields-where/333293 "2023-05-12T11:21:05Z")

</div>

I have a few different indicies that have logs in them that were digested using Logstash. The filter in my config looks like this: filter { csv { autodetect\_column\_names =\> false columns =\> \["uid", "ip"\] …

---

## [Why does the performance difference occur when searching in the regular or keyword field?](https://discuss.elastic.co/t/why-does-the-performance-difference-occur-when-searching-in-the-regular-or-keyword-field/333289)

<div class="topic-metadata">

**Author:** [@Ruveyda\_Aksoy](https://discuss.elastic.co/u/Ruveyda_Aksoy)\
**Replies:** 0\
**Last updated:** [May 12, 2023, 11:13am UTC](https://discuss.elastic.co/t/why-does-the-performance-difference-occur-when-searching-in-the-regular-or-keyword-field/333289 "2023-05-12T11:13:39Z")

</div>

Hi, I have a question regarding query performance. The data types of the fields I am querying are as follows. "primaryIdentificationNumber" : { "type" : "keyword", "fields" : { …

---

## [Collapse feature and total\_hist after collapse](https://discuss.elastic.co/t/collapse-feature-and-total-hist-after-collapse/333288)

<div class="topic-metadata">

**Author:** [@\_zogaj](https://discuss.elastic.co/u/_zogaj)\
**Replies:** 0\
**Last updated:** [May 12, 2023, 11:12am UTC](https://discuss.elastic.co/t/collapse-feature-and-total-hist-after-collapse/333288 "2023-05-12T11:12:41Z")

</div>

As Elastisearch documantion said: The total number of hits in the response indicates the number of matching documents without collapsing. The total number of distinct group is unknown. I am using a search with paginatio…

---

## [Reasoning behind Geonames Rally Design](https://discuss.elastic.co/t/reasoning-behind-geonames-rally-design/333271)

<div class="topic-metadata">

**Author:** [@lquenti](https://discuss.elastic.co/u/lquenti)\
**Replies:** 1\
**Last updated:** [May 12, 2023, 11:04am UTC](https://discuss.elastic.co/t/reasoning-behind-geonames-rally-design/333271 "2023-05-12T11:04:28Z")

</div>

Hi, I am currently evaluating Elasticsearch for a HPC related data lake infrastructure. For that, we are currently using rally benchmarker, especially with the geonames and nyc taxis. Since our HPC environment is batch…

---

## [Fleet & Elastic Agent not working](https://discuss.elastic.co/t/fleet-elastic-agent-not-working/333282)

<div class="topic-metadata">

**Author:** [@knit](https://discuss.elastic.co/u/knit)\
**Replies:** 0\
**Last updated:** [May 12, 2023, 10:24am UTC](https://discuss.elastic.co/t/fleet-elastic-agent-not-working/333282 "2023-05-12T10:24:29Z")

</div>

Hi Team, We recently moved log data (/var/lib/elasticsearch) from AWS EBS to S3. During this process all the services were stopped except elasticagent. After successful data transfer, integrations through filebeat is wo…

---

## [Readiness probe failed: {"timestamp": "2023-05-12T08:12:09+00:00", "message": "readiness probe failed", "curl\_rc": "7"}](https://discuss.elastic.co/t/readiness-probe-failed-timestamp-2023-05-12t0809-00-00-message-readiness-probe-failed-curl-rc-7/333280)

<div class="topic-metadata">

**Author:** [@Swathi\_Kakumanu](https://discuss.elastic.co/u/Swathi_Kakumanu)\
**Replies:** 0\
**Last updated:** [May 12, 2023, 10:19am UTC](https://discuss.elastic.co/t/readiness-probe-failed-timestamp-2023-05-12t0809-00-00-message-readiness-probe-failed-curl-rc-7/333280 "2023-05-12T10:19:35Z")

</div>

I am trying to deploy Elastic search cluster using ECK 2.7 version and it fails with below error. can someone pls help me find the issue. I am following the sample yaml provide in elastic documentation elasticsearch.…

---

## [Unable to view apm services in other spaces in kibana](https://discuss.elastic.co/t/unable-to-view-apm-services-in-other-spaces-in-kibana/333279)

<div class="topic-metadata">

**Author:** [@lalchand\_rajak](https://discuss.elastic.co/u/lalchand_rajak)\
**Replies:** 0\
**Last updated:** [May 12, 2023, 10:19am UTC](https://discuss.elastic.co/t/unable-to-view-apm-services-in-other-spaces-in-kibana/333279 "2023-05-12T10:19:13Z")

</div>

Unable to view the apm services other than default space. I have created developer space and wanted to give the access to developer of APM services and provides read and indices access to it but it not showing the apm …

---

## [Illegal\_argument\_exception: index.lifecycle.rollover\_alias \[nginx\_uat\_test-frontend\_mobile-test\] does not point to index \[nginx\_uat\_test-frontend\_mobile\_2023.05.12\]](https://discuss.elastic.co/t/illegal-argument-exception-index-lifecycle-rollover-alias-nginx-uat-test-frontend-mobile-test-does-not-point-to-index-nginx-uat-test-frontend-mobile-2023-05-12/333276)

<div class="topic-metadata">

**Author:** [@Alwyn\_Tiu](https://discuss.elastic.co/u/Alwyn_Tiu)\
**Replies:** 0\
**Last updated:** [May 12, 2023, 9:54am UTC](https://discuss.elastic.co/t/illegal-argument-exception-index-lifecycle-rollover-alias-nginx-uat-test-frontend-mobile-test-does-not-point-to-index-nginx-uat-test-frontend-mobile-2023-05-12/333276 "2023-05-12T09:54:03Z")

</div>

Rule： { "del-test" : { "version" : 1, "modified\_date" : "2023-05-11T09:30:54.350Z", "policy" : { "phases" : { "hot" : { "min\_age" : "0ms", "actions" : { "rollover" : { "max\_age" : "1d" }, "set\_priority" : { …

---

## [How works Allocation shards data tiers recommanded](https://discuss.elastic.co/t/how-works-allocation-shards-data-tiers-recommanded/333274)

<div class="topic-metadata">

**Author:** [@pepite](https://discuss.elastic.co/u/pepite)\
**Replies:** 0\
**Last updated:** [May 12, 2023, 9:17am UTC](https://discuss.elastic.co/t/how-works-allocation-shards-data-tiers-recommanded/333274 "2023-05-12T09:17:14Z")

</div>

Hi everybody, Fine ? Questions about the allocation of the shards :wink: I have a big index that has his dedicated index template with 3 primary shards and 1 replica { "order": 1, "index\_patterns": \[ "tdir\_busin…

---

## [Timeline template change timefilter to @timestamp instead of event.ingested?](https://discuss.elastic.co/t/timeline-template-change-timefilter-to-timestamp-instead-of-event-ingested/333087)

<div class="topic-metadata">

**Author:** [@elk\_jh](https://discuss.elastic.co/u/elk_jh)\
**Replies:** 2\
**Last updated:** [May 12, 2023, 8:54am UTC](https://discuss.elastic.co/t/timeline-template-change-timefilter-to-timestamp-instead-of-event-ingested/333087 "2023-05-12T08:54:44Z")

</div>

Hello~ I'm having an issue where I use a timeline template in the investigate in timeline feature of a rule in elastic security. When we create the rule, we override the timestamp to event.ingested. Our logs has a lag du…

---

## [Can't access connect to Fleet Server](https://discuss.elastic.co/t/cant-access-connect-to-fleet-server/333248)

<div class="topic-metadata">

**Author:** [@vanhaiit90](https://discuss.elastic.co/u/vanhaiit90)\
**Replies:** 1\
**Last updated:** [May 12, 2023, 8:20am UTC](https://discuss.elastic.co/t/cant-access-connect-to-fleet-server/333248 "2023-05-12T08:20:10Z")

</div>

Last day I completed configure cluster elasticsearch and I access to kibana is ok but I only cannot access Fleet. And Here is the error picture and details from the log https-in/1: SSL handshake failure message":"F…

---

## [Elastic App Search Analytics Queries Pagination](https://discuss.elastic.co/t/elastic-app-search-analytics-queries-pagination/330275)

<div class="topic-metadata">

**Author:** [@Thymen](https://discuss.elastic.co/u/Thymen)\
**Replies:** 4\
**Last updated:** [May 12, 2023, 8:16am UTC](https://discuss.elastic.co/t/elastic-app-search-analytics-queries-pagination/330275 "2023-05-12T08:16:48Z")

</div>

Hello there, Using Enterprise Search PHP I am trying to fetch the analytics queries as it is documented here. Now I know that the limit to the amount of records returned per page is 1000 records. My user case requires …

---

## [Kibana visualization](https://discuss.elastic.co/t/kibana-visualization/333217)

<div class="topic-metadata">

**Author:** [@sai\_ravi\_shankar](https://discuss.elastic.co/u/sai_ravi_shankar)\
**Replies:** 1\
**Last updated:** [May 12, 2023, 7:48am UTC](https://discuss.elastic.co/t/kibana-visualization/333217 "2023-05-12T07:48:38Z")

</div>

Hi I am trying to build a visualization. Here is the scenario. i have two coulmns, lets say company\_name and cost\_paid\_by\_company. i need to show the cost\_paid\_by\_company which is higher and lower than the threshold in…

---

## [How to add buckets in horizontal bars chart in lens?](https://discuss.elastic.co/t/how-to-add-buckets-in-horizontal-bars-chart-in-lens/330667)

<div class="topic-metadata">

**Author:** [@Yves\_Frerot](https://discuss.elastic.co/u/Yves_Frerot)\
**Replies:** 2\
**Last updated:** [May 12, 2023, 7:41am UTC](https://discuss.elastic.co/t/how-to-add-buckets-in-horizontal-bars-chart-in-lens/330667 "2023-05-12T07:41:14Z")

</div>

I have a chart with a formula as metric. I succeed in a lens horizontal bar graph. But I want to do it for all values of a field with 4 values. I understand the option that consists in repeating the same graph with 4 fil…

---

## [Parse Array of JSON object](https://discuss.elastic.co/t/parse-array-of-json-object/333034)

<div class="topic-metadata">

**Author:** [@Nurm](https://discuss.elastic.co/u/Nurm)\
**Replies:** 4\
**Last updated:** [May 12, 2023, 7:10am UTC](https://discuss.elastic.co/t/parse-array-of-json-object/333034 "2023-05-12T07:10:55Z")

</div>

input { jdbc { jdbc\_connection\_string =\> "jdbc:postgresql://localhost:5432/db" jdbc\_user =\> "user" jdbc\_password =\> "pass" jdbc\_driver\_library =\> "/usr/share/logstash/lib/postgresql-42…

---

## [Index deletion error due to change from Gold to Basic license](https://discuss.elastic.co/t/index-deletion-error-due-to-change-from-gold-to-basic-license/329974)

<div class="topic-metadata">

**Author:** [@kazuo](https://discuss.elastic.co/u/kazuo)\
**Replies:** 4\
**Last updated:** [May 12, 2023, 6:36am UTC](https://discuss.elastic.co/t/index-deletion-error-due-to-change-from-gold-to-basic-license/329974 "2023-05-12T06:36:32Z")

</div>

Hello, I was using a GOLD license, but did not renew my contract and I did not renew the contract and switched to the free version. One week after the switchover I received the following message ERROR Failed to compl…

---

## [I want to split from filed value using logstash](https://discuss.elastic.co/t/i-want-to-split-from-filed-value-using-logstash/333059)

<div class="topic-metadata">

**Author:** [@dharminfadia](https://discuss.elastic.co/u/dharminfadia)\
**Replies:** 7\
**Last updated:** [May 12, 2023, 6:12am UTC](https://discuss.elastic.co/t/i-want-to-split-from-filed-value-using-logstash/333059 "2023-05-12T06:12:50Z")

</div>

@warkolm @Badger help me.... Hello Everyone I am trying to split recipient-status feild first 3 digit and want to add in to new feild I tried mutate split and add filed but no luck can any one suggest how I can achiv…

---

## [Bug of /\_nlpcn/sql with subqueries](https://discuss.elastic.co/t/bug-of-nlpcn-sql-with-subqueries/333243)

<div class="topic-metadata">

**Author:** [@liuchsh01](https://discuss.elastic.co/u/liuchsh01)\
**Replies:** 1\
**Last updated:** [May 12, 2023, 3:51am UTC](https://discuss.elastic.co/t/bug-of-nlpcn-sql-with-subqueries/333243 "2023-05-12T03:51:44Z")

</div>

After using the /\_nlpcn/sql interface to query the sql with subqueries, some subsequent queries will time out. sql sample: SELECT count(\*) FROM a\_index where someCode in (SELECT code FROM b\_index where someType ='ttt') …

---

## [Run elastic in docker](https://discuss.elastic.co/t/run-elastic-in-docker/332720)

<div class="topic-metadata">

**Author:** [@Fatiha](https://discuss.elastic.co/u/Fatiha)\
**Replies:** 2\
**Last updated:** [May 12, 2023, 3:48am UTC](https://discuss.elastic.co/t/run-elastic-in-docker/332720 "2023-05-12T03:48:55Z")

</div>

HI i run my elastic in docker but when i tap this command curl --cacert http\_ca.crt -u elastic https://localhost:9200 Enter host password for user 'elastic': i have this problem: curl: (60) schannel: CertGetCertific…

---

## [Abbreviation CST timezone issue when use postgresql filebeat module](https://discuss.elastic.co/t/abbreviation-cst-timezone-issue-when-use-postgresql-filebeat-module/333251)

<div class="topic-metadata">

**Author:** [@yanhj93](https://discuss.elastic.co/u/yanhj93)\
**Replies:** 1\
**Last updated:** [May 12, 2023, 3:29am UTC](https://discuss.elastic.co/t/abbreviation-cst-timezone-issue-when-use-postgresql-filebeat-module/333251 "2023-05-12T03:29:09Z")

</div>

filebeat.modules: - module: postgresql log: enabled: true var.paths: \["/data/pgdata/pg\_log/\*.log"\] input: tags: "server" processors: - drop\_fields: …

---

## [Need input for ideal master and data node cluster for elastic search](https://discuss.elastic.co/t/need-input-for-ideal-master-and-data-node-cluster-for-elastic-search/333231)

<div class="topic-metadata">

**Author:** [@susmithabadam1609](https://discuss.elastic.co/u/susmithabadam1609)\
**Replies:** 2\
**Last updated:** [May 12, 2023, 3:16am UTC](https://discuss.elastic.co/t/need-input-for-ideal-master-and-data-node-cluster-for-elastic-search/333231 "2023-05-12T03:16:38Z")

</div>

Hi Team, I am trying to deploy Elasticsearch version "8.7.0" and I am currently using "2.7.0" eck operator. I need to deploy Elasticsearch in master-data architecture. Could you please share the ideal(recommended) num…

---

## [Change HTTP SSL security without private key of CA](https://discuss.elastic.co/t/change-http-ssl-security-without-private-key-of-ca/331465)

<div class="topic-metadata">

**Author:** [@Alex\_Fan](https://discuss.elastic.co/u/Alex_Fan)\
**Replies:** 4\
**Last updated:** [May 12, 2023, 2:31am UTC](https://discuss.elastic.co/t/change-http-ssl-security-without-private-key-of-ca/331465 "2023-05-12T02:31:28Z")

</div>

We just installed ELK stack v8.5.1 on RHEL linux server and the elasticsearch is using the generated certs and I can generate the enrollment token for my Kibana to connect. However, we want to use our corporate internal …

---

## [Trouble with installing ECK on my RKE2 Kubernetes cluster](https://discuss.elastic.co/t/trouble-with-installing-eck-on-my-rke2-kubernetes-cluster/330773)

<div class="topic-metadata">

**Author:** [@Michael\_Anthony](https://discuss.elastic.co/u/Michael_Anthony)\
**Replies:** 11\
**Last updated:** [May 12, 2023, 12:51am UTC](https://discuss.elastic.co/t/trouble-with-installing-eck-on-my-rke2-kubernetes-cluster/330773 "2023-05-12T00:51:33Z")

</div>

I'm just trying to follow the instructions on the elastic docs for their quick start guide to deploy ECK on my cluster and I can't get the "quickstart-es-default-0" pod to spin up. I'm following all the instructions. Do…

---

## [Logstash error connecting to ElasticSearch](https://discuss.elastic.co/t/logstash-error-connecting-to-elasticsearch/333168)

<div class="topic-metadata">

**Author:** [@audric\_w](https://discuss.elastic.co/u/audric_w)\
**Replies:** 3\
**Last updated:** [May 11, 2023, 10:29pm UTC](https://discuss.elastic.co/t/logstash-error-connecting-to-elasticsearch/333168 "2023-05-11T22:29:15Z")

</div>

I've tried to created sidecar using beats and logstash on OpenShift. However the logstash always attempted to resurrect connection to dead ES instance (to http://elastisearch:9200), despite configs that I've done. Logst…

---

## [Filter Windows Device Scanning from Direct Outbound SMB Connection rule](https://discuss.elastic.co/t/filter-windows-device-scanning-from-direct-outbound-smb-connection-rule/332248)

<div class="topic-metadata">

**Author:** [@Thyrum](https://discuss.elastic.co/u/Thyrum)\
**Replies:** 1\
**Last updated:** [May 11, 2023, 10:11pm UTC](https://discuss.elastic.co/t/filter-windows-device-scanning-from-direct-outbound-smb-connection-rule/332248 "2023-05-11T22:11:06Z")

</div>

Hi, We have been trying to filter out windows device scanning from our Direct Outbound SMB Connection rule logs. As is mentioned in the first note of Configure device discovery | Microsoft Learn, these SMB connections a…

---

## [Version conflict, document already exists (current version \[1\])](https://discuss.elastic.co/t/version-conflict-document-already-exists-current-version-1/333107)

<div class="topic-metadata">

**Author:** [@elasticforme](https://discuss.elastic.co/u/elasticforme)\
**Replies:** 11\
**Last updated:** [May 11, 2023, 8:46pm UTC](https://discuss.elastic.co/t/version-conflict-document-already-exists-current-version-1/333107 "2023-05-11T20:46:01Z")

</div>

I am running metricbeat on few system. sending that data to proxy server. proxy then sends data to two logstash servers logstash then parse this and stores records in Elasticsearch. I am creating my own \_id for each …

---

## [Index Pattern might be treated as substring of other Index Pattern](https://discuss.elastic.co/t/index-pattern-might-be-treated-as-substring-of-other-index-pattern/333220)

<div class="topic-metadata">

**Author:** [@paolovalladolid](https://discuss.elastic.co/u/paolovalladolid)\
**Replies:** 1\
**Last updated:** [May 11, 2023, 7:51pm UTC](https://discuss.elastic.co/t/index-pattern-might-be-treated-as-substring-of-other-index-pattern/333220 "2023-05-11T19:51:51Z")

</div>

We have 2 servers running Winlogbeat. Server 1 Winlogbeat has this index pattern configured: developer-portal-%{+yyyyMMdd} Server 2 Winlogbeat has this index pattern configured: developer-portal-hydrator-%{+yyyyMMdd} …

---

## [Unable to view docs in dataview (w/timestamp field) after doc update](https://discuss.elastic.co/t/unable-to-view-docs-in-dataview-w-timestamp-field-after-doc-update/333189)

<div class="topic-metadata">

**Author:** [@petersedivec](https://discuss.elastic.co/u/petersedivec)\
**Replies:** 4\
**Last updated:** [May 11, 2023, 7:42pm UTC](https://discuss.elastic.co/t/unable-to-view-docs-in-dataview-w-timestamp-field-after-doc-update/333189 "2023-05-11T19:42:06Z")

</div>

I'm inserting docs to an index. There's a created\_at field that I use in the dataview for time filtering. After initial doc inserts I can see all the docs in Kibana in my data view. I'm then needing to update docs so …

---

## [Create new fields in elasticsearch](https://discuss.elastic.co/t/create-new-fields-in-elasticsearch/332659)

<div class="topic-metadata">

**Author:** [@kibana\_dev\_iko](https://discuss.elastic.co/u/kibana_dev_iko)\
**Replies:** 1\
**Last updated:** [May 11, 2023, 7:19pm UTC](https://discuss.elastic.co/t/create-new-fields-in-elasticsearch/332659 "2023-05-11T19:19:15Z")

</div>

i want to calculate the difference in time between 2 logs different and add the value to a new field i search in google and i find that is possible with painless scripting but i dont know how to do it if there is anyon…

---

## [Change IP of single node instance](https://discuss.elastic.co/t/change-ip-of-single-node-instance/333133)

<div class="topic-metadata">

**Author:** [@Dusty\_Boley](https://discuss.elastic.co/u/Dusty_Boley)\
**Replies:** 2\
**Last updated:** [May 11, 2023, 7:12pm UTC](https://discuss.elastic.co/t/change-ip-of-single-node-instance/333133 "2023-05-11T19:12:05Z")

</div>

Hello all, if this info is somewhere and my search missed it I apologize. Also, I am an Elasticsearch noob so my apologies if I mix up terminology. I have a simple single node setup running version 8.7 to service a sma…

[Previous page](https://discuss.elastic.co/latest.md?page=679)

[Next page](https://discuss.elastic.co/latest.md?page=681)
