# Latest

**URL:** https://discuss.elastic.co/latest.md?page=683

[Latest](https://discuss.elastic.co/latest.md) · [Categories](https://discuss.elastic.co/categories.md) · [Tags](https://discuss.elastic.co/tags.md)

**Page:** 684

---

## [Import data csv/json](https://discuss.elastic.co/t/import-data-csv-json/333090)

<div class="topic-metadata">

**Author:** [@Haitem\_Touiss](https://discuss.elastic.co/u/Haitem_Touiss)\
**Replies:** 2\
**Last updated:** [May 11, 2023, 12:03am UTC](https://discuss.elastic.co/t/import-data-csv-json/333090 "2023-05-11T00:03:01Z")

</div>

Hello, I am having difficulty importing data into Elasticsearch version 7.17, but it is working fine in the latest version. I have tried several methods, including using Logstash and Beats, but none of them seem to be w…

---

## [Disabling the \_size mapping?](https://discuss.elastic.co/t/disabling-the-size-mapping/332831)

<div class="topic-metadata">

**Author:** [@shani\_angarkadu](https://discuss.elastic.co/u/shani_angarkadu)\
**Replies:** 1\
**Last updated:** [May 10, 2023, 11:57pm UTC](https://discuss.elastic.co/t/disabling-the-size-mapping/332831 "2023-05-10T23:57:28Z")

</div>

I want to enable and disable the size mapping. Enable worked fine after the index refreshed and I disable the \_size set to false but I still able to query the \_size. How can I disable so no one can query?

---

## [Unable to recover my cluster](https://discuss.elastic.co/t/unable-to-recover-my-cluster/333000)

<div class="topic-metadata">

**Author:** [@Ashu\_Mahajan](https://discuss.elastic.co/u/Ashu_Mahajan)\
**Replies:** 12\
**Last updated:** [May 10, 2023, 10:58pm UTC](https://discuss.elastic.co/t/unable-to-recover-my-cluster/333000 "2023-05-10T22:58:56Z")

</div>

We moved our data to new version of elasticsearch. The new cluster have 3 master, 3 hot and 3 warm nodes. Everything was working fine till this morning and all of a cluster health went red. After looking at it further, I…

---

## [Question about Elasticsearch query](https://discuss.elastic.co/t/question-about-elasticsearch-query/331074)

<div class="topic-metadata">

**Author:** [@sayerszero](https://discuss.elastic.co/u/sayerszero)\
**Replies:** 1\
**Last updated:** [May 10, 2023, 9:50pm UTC](https://discuss.elastic.co/t/question-about-elasticsearch-query/331074 "2023-05-10T21:50:02Z")

</div>

New to the community and not sure this is the best category for this question, but here goes: We're trying to monitor CPU thresholds through Rules and Connectors with beats 7.16. We originally were doing this using Metr…

---

## [Logtash with saml](https://discuss.elastic.co/t/logtash-with-saml/333131)

<div class="topic-metadata">

**Author:** [@Pablo\_Crosio](https://discuss.elastic.co/u/Pablo_Crosio)\
**Replies:** 2\
**Last updated:** [May 10, 2023, 9:22pm UTC](https://discuss.elastic.co/t/logtash-with-saml/333131 "2023-05-10T21:22:38Z")

</div>

Is it possible to connect with Logtash to OpenSearch using SAML authentication? We are able to integrate with SAML and Azure AD to log in to dashboards but we are unable to connect Logtash to OpenSearch with an Azure AD…

---

## [Issue regarding setup and local host](https://discuss.elastic.co/t/issue-regarding-setup-and-local-host/333017)

<div class="topic-metadata">

**Author:** [@Tushar25](https://discuss.elastic.co/u/Tushar25)\
**Replies:** 1\
**Last updated:** [May 10, 2023, 9:16pm UTC](https://discuss.elastic.co/t/issue-regarding-setup-and-local-host/333017 "2023-05-10T21:16:45Z")

</div>

Hello there, I'm having an issue doing the setup of the version 8.7.1, (http:// localhost:9200/) this link requires a password to which the default USERNAME('elastic') and PASSWORD('changeme') is not working or giving a…

---

## [ elastic SIEM vs elastic Security](https://discuss.elastic.co/t/elastic-siem-vs-elastic-security/332846)

<div class="topic-metadata">

**Author:** [@THOR\_EL\_PODEROSO\_TEC](https://discuss.elastic.co/u/THOR_EL_PODEROSO_TEC)\
**Replies:** 1\
**Last updated:** [May 10, 2023, 8:40pm UTC](https://discuss.elastic.co/t/elastic-siem-vs-elastic-security/332846 "2023-05-10T20:40:08Z")

</div>

What is the difference between elastic SIEM and elastic Security? Is there a manual to install it in HyperV in onpremise?

---

## [Unable to intercept/send APM transactions in NestJS using elastic-apm-node package](https://discuss.elastic.co/t/unable-to-intercept-send-apm-transactions-in-nestjs-using-elastic-apm-node-package/332992)

<div class="topic-metadata">

**Author:** [@Frank\_Corona](https://discuss.elastic.co/u/Frank_Corona)\
**Replies:** 4\
**Last updated:** [May 10, 2023, 6:21pm UTC](https://discuss.elastic.co/t/unable-to-intercept-send-apm-transactions-in-nestjs-using-elastic-apm-node-package/332992 "2023-05-10T18:21:57Z")

</div>

Kibana version: v8.6.2 ECS version: 1.6.0 APM Agent language and version: "elastic-apm-node": "3.44.1" Fresh install or upgraded from other version? Fresh Install Is there anything special in your setup? For example,…

---

## [Duplicating Event To Multiple Indices](https://discuss.elastic.co/t/duplicating-event-to-multiple-indices/332955)

<div class="topic-metadata">

**Author:** [@wwalker](https://discuss.elastic.co/u/wwalker)\
**Replies:** 3\
**Last updated:** [May 10, 2023, 4:18pm UTC](https://discuss.elastic.co/t/duplicating-event-to-multiple-indices/332955 "2023-05-10T16:18:40Z")

</div>

I have events coming in with an ID of 123. Is it possible to have this event indexed into two different indices by doing something like below? output { if \[log\] == 123 { elasticsearch { index =\> "123logs" …

---

## [Ukrainian analyzer](https://discuss.elastic.co/t/ukrainian-analyzer/333062)

<div class="topic-metadata">

**Author:** [@Vladimir\_Talabko](https://discuss.elastic.co/u/Vladimir_Talabko)\
**Replies:** 16\
**Last updated:** [May 10, 2023, 3:46pm UTC](https://discuss.elastic.co/t/ukrainian-analyzer/333062 "2023-05-10T15:46:35Z")

</div>

Hello! I have a hosting with installed the Ukrainian plugin from this page Ukrainian analysis plugin | Elasticsearch Plugins and Integrations \[8.7\] | Elastic . It's proven by this command: bin/elasticsearch-plugin list …

---

## [Vega Directed Graph Breaks w/ Input Sliders](https://discuss.elastic.co/t/vega-directed-graph-breaks-w-input-sliders/332589)

<div class="topic-metadata">

**Author:** [@ikiril01](https://discuss.elastic.co/u/ikiril01)\
**Replies:** 2\
**Last updated:** [May 10, 2023, 3:43pm UTC](https://discuss.elastic.co/t/vega-directed-graph-breaks-w-input-sliders/332589 "2023-05-10T15:43:34Z")

</div>

I'm trying to build a force-directed graph in Kibana (v8.3.3) using Vega. I've got the graph built out successfully, with the caveat that sometimes it can display quite a large amount of data, thus making it overwhelmin…

---

## [Kibana - Automatizar login acceso a kibana](https://discuss.elastic.co/t/kibana-automatizar-login-acceso-a-kibana/333032)

<div class="topic-metadata">

**Author:** [@Javier\_Garcia\_Alvare](https://discuss.elastic.co/u/Javier_Garcia_Alvare)\
**Replies:** 1\
**Last updated:** [May 10, 2023, 3:15pm UTC](https://discuss.elastic.co/t/kibana-automatizar-login-acceso-a-kibana/333032 "2023-05-10T15:15:55Z")

</div>

Buenos días, versión 6.8.3 Es posible el automatizar el login de acceso a kibana y en la url de acceso pasar las credenciales y que apunten a un dashboard. Gracias, un saludo Javier.

---

## [Elasticsearch not updating data from Logstash](https://discuss.elastic.co/t/elasticsearch-not-updating-data-from-logstash/333097)

<div class="topic-metadata">

**Author:** [@VVlad23](https://discuss.elastic.co/u/VVlad23)\
**Replies:** 0\
**Last updated:** [May 10, 2023, 2:51pm UTC](https://discuss.elastic.co/t/elasticsearch-not-updating-data-from-logstash/333097 "2023-05-10T14:51:09Z")

</div>

Hello! So it's been some time I've spent trying to figure out what exactly is happening and why there is a problem. We're sending information from a server through Filebeat to Logstash. Logstash is installed on one of …

---

## [Winlogbeat 8.7.1 service crashes immediately after starting](https://discuss.elastic.co/t/winlogbeat-8-7-1-service-crashes-immediately-after-starting/332948)

<div class="topic-metadata">

**Author:** [@Mike7](https://discuss.elastic.co/u/Mike7)\
**Replies:** 6\
**Last updated:** [May 10, 2023, 2:39pm UTC](https://discuss.elastic.co/t/winlogbeat-8-7-1-service-crashes-immediately-after-starting/332948 "2023-05-10T14:39:54Z")

</div>

Hi All, On a fresh install (Server 2022) the Winlogbeat service crashes immediately after starting (when there are events in the monitored log present) or - when the log is cleared - it crashes after the first event com…

---

## [Suggestions response doesnt contain index information or information about document where the suggestion was found](https://discuss.elastic.co/t/suggestions-response-doesnt-contain-index-information-or-information-about-document-where-the-suggestion-was-found/332543)

<div class="topic-metadata">

**Author:** [@schawla](https://discuss.elastic.co/u/schawla)\
**Replies:** 3\
**Last updated:** [May 10, 2023, 2:18pm UTC](https://discuss.elastic.co/t/suggestions-response-doesnt-contain-index-information-or-information-about-document-where-the-suggestion-was-found/332543 "2023-05-10T14:18:57Z")

</div>

Hi, I am trying to trace a suggestion to its source document returned by my search suggestion query in Elasticsearch 7.9 It seems the suggest Options only returns the suggested text , frequency and score. I see that the…

---

## [Difference between UNIX\_MS and epoch\_millis in date processor?](https://discuss.elastic.co/t/difference-between-unix-ms-and-epoch-millis-in-date-processor/333048)

<div class="topic-metadata">

**Author:** [@chengye233](https://discuss.elastic.co/u/chengye233)\
**Replies:** 1\
**Last updated:** [May 10, 2023, 1:40pm UTC](https://discuss.elastic.co/t/difference-between-unix-ms-and-epoch-millis-in-date-processor/333048 "2023-05-10T13:40:17Z")

</div>

Hi, I use ingest pipeline to add @timestamp field automatically from a exist date type field. My exist date type field is called uploadTime and it's date format is epoch\_millis. In the processor, I firstly use epoch\_mi…

---

## [Vector knn search with more than 1024 dimensions](https://discuss.elastic.co/t/vector-knn-search-with-more-than-1024-dimensions/332819)

<div class="topic-metadata">

**Author:** [@sbruinsje](https://discuss.elastic.co/u/sbruinsje)\
**Replies:** 4\
**Last updated:** [May 10, 2023, 1:35pm UTC](https://discuss.elastic.co/t/vector-knn-search-with-more-than-1024-dimensions/332819 "2023-05-10T13:35:26Z")

</div>

If I understood correctly, from version 8.8 elasticsearch will support knn search for vectors over 1024 dimensions. Is there any indication when this will be released? I'm trying to work with openai embeddings (2nd gener…

---

## [OSQuery Integration user.id is \[long\] but ECS is \[keyword\]](https://discuss.elastic.co/t/osquery-integration-user-id-is-long-but-ecs-is-keyword/332700)

<div class="topic-metadata">

**Author:** [@oloughlinp](https://discuss.elastic.co/u/oloughlinp)\
**Replies:** 2\
**Last updated:** [May 10, 2023, 1:33pm UTC](https://discuss.elastic.co/t/osquery-integration-user-id-is-long-but-ecs-is-keyword/332700 "2023-05-10T13:33:50Z")

</div>

Hi all, I am trying to use some of the Windows prebuilt rules that rely on user.id in the eql query, but they are erroring out because my OSQuery manager indexes have user.id set to long, but the ECS standard (and what …

---

## [Cannot set custom data view for a bar chart in Kibana Lens](https://discuss.elastic.co/t/cannot-set-custom-data-view-for-a-bar-chart-in-kibana-lens/333086)

<div class="topic-metadata">

**Author:** [@NotSoOld](https://discuss.elastic.co/u/NotSoOld)\
**Replies:** 2\
**Last updated:** [May 10, 2023, 1:32pm UTC](https://discuss.elastic.co/t/cannot-set-custom-data-view-for-a-bar-chart-in-kibana-lens/333086 "2023-05-10T13:32:50Z")

</div>

Hello. Seems like there is a bug in Kibana Lens when I try to set custom data view for the one of my dashboard components (a bar chart). Here are the steps to follow: Add bar chart to dashboard Bar chart will have some…

---

## [Winlogbeat doesn't drop events](https://discuss.elastic.co/t/winlogbeat-doesnt-drop-events/332557)

<div class="topic-metadata">

**Author:** [@h49nakxs](https://discuss.elastic.co/u/h49nakxs)\
**Replies:** 4\
**Last updated:** [May 10, 2023, 1:08pm UTC](https://discuss.elastic.co/t/winlogbeat-doesnt-drop-events/332557 "2023-05-10T13:08:27Z")

</div>

Hi there, How the hell are we supposed to configure winlogbeats (ecs.version : 1.6.0) to drop events ? I've tried, many, many variations, but none of them worked. - name: Security processors: - drop\_event.…

---

## [Search Query Based on Nested Fields](https://discuss.elastic.co/t/search-query-based-on-nested-fields/333084)

<div class="topic-metadata">

**Author:** [@Mustafa\_AYDOGDU](https://discuss.elastic.co/u/Mustafa_AYDOGDU)\
**Replies:** 4\
**Last updated:** [May 10, 2023, 1:04pm UTC](https://discuss.elastic.co/t/search-query-based-on-nested-fields/333084 "2023-05-10T13:04:01Z")

</div>

I have this kind of data: "1655184519597531137": { "reply\_depth": 1, "gather\_likes": false, "gather\_user\_data": "false", "keyword": "galatasaray", "gather\_retw…

---

## [How to duplicate a rule?](https://discuss.elastic.co/t/how-to-duplicate-a-rule/331042)

<div class="topic-metadata">

**Author:** [@ppic](https://discuss.elastic.co/u/ppic)\
**Replies:** 7\
**Last updated:** [May 10, 2023, 12:40pm UTC](https://discuss.elastic.co/t/how-to-duplicate-a-rule/331042 "2023-05-10T12:40:13Z")

</div>

Hello, I have to create several rules-alerts that are very similar. Is there a way to duplicate (copy/paste) a rule ? Thank you.

---

## [Elasticsearch / logstash Log time shift](https://discuss.elastic.co/t/elasticsearch-logstash-log-time-shift/332898)

<div class="topic-metadata">

**Author:** [@JackieLaFrite](https://discuss.elastic.co/u/JackieLaFrite)\
**Replies:** 6\
**Last updated:** [May 10, 2023, 12:28pm UTC](https://discuss.elastic.co/t/elasticsearch-logstash-log-time-shift/332898 "2023-05-10T12:28:54Z")

</div>

I currently have a small problem and I don't know why it happens. I have my log 2023-05-09 09:20:11 \[DEBUG\] org.apache.activemq.transport.AbstractInactivityMonitor:150 -\> WriteChecker: 10000ms elapsed since last write …

---

## [Term suggester returning correct suggestions for misspelled words outside of suggester data source](https://discuss.elastic.co/t/term-suggester-returning-correct-suggestions-for-misspelled-words-outside-of-suggester-data-source/333083)

<div class="topic-metadata">

**Author:** [@MilanGatyas](https://discuss.elastic.co/u/MilanGatyas)\
**Replies:** 0\
**Last updated:** [May 10, 2023, 12:26pm UTC](https://discuss.elastic.co/t/term-suggester-returning-correct-suggestions-for-misspelled-words-outside-of-suggester-data-source/333083 "2023-05-10T12:26:07Z")

</div>

Please help me understand why this happens. We use Elasticsearch 7.10 term suggester. The field didYouMean.trigram we use for the suggestions has the following mapping "didYouMean" : { "type" : "text", "fields" : { …

---

## [Elastic 8.7\_\_enrollement-token\_\_"failed to establish trust with server "](https://discuss.elastic.co/t/elastic-8-7-enrollement-token-failed-to-establish-trust-with-server/330856)

<div class="topic-metadata">

**Author:** [@Julien069](https://discuss.elastic.co/u/Julien069)\
**Replies:** 6\
**Last updated:** [May 10, 2023, 12:06pm UTC](https://discuss.elastic.co/t/elastic-8-7-enrollement-token-failed-to-establish-trust-with-server/330856 "2023-05-10T12:06:09Z")

</div>

Hi , I have a kibana server and an elastic server with differents IP address . When I want to create a token for kibana with command : sudo bin/elasticsearch-create-enrollement-token -s kibana OR sudo bin/elasticse…

---

## [Can I do a sum on the fields that have 'keyword' type](https://discuss.elastic.co/t/can-i-do-a-sum-on-the-fields-that-have-keyword-type/333076)

<div class="topic-metadata">

**Author:** [@searchwithme](https://discuss.elastic.co/u/searchwithme)\
**Replies:** 1\
**Last updated:** [May 10, 2023, 11:06am UTC](https://discuss.elastic.co/t/can-i-do-a-sum-on-the-fields-that-have-keyword-type/333076 "2023-05-10T11:06:31Z")

</div>

I have a field that is keyword type. The index looks like this: { "key": 1 }, { "key": 2 }, { "key": 3 }, { "key":"abc" }, { "key":"zyx" } Some values are numeric and some are strings. Is there a way to …

---

## [Gather logs from podman containers](https://discuss.elastic.co/t/gather-logs-from-podman-containers/333073)

<div class="topic-metadata">

**Author:** [@asp](https://discuss.elastic.co/u/asp)\
**Replies:** 0\
**Last updated:** [May 10, 2023, 10:44am UTC](https://discuss.elastic.co/t/gather-logs-from-podman-containers/333073 "2023-05-10T10:44:40Z")

</div>

Hi, If I understand the documentation correctly the best practice for shipping logs of docker-container is the following: using container input - type: container stream: stdout paths: - "/var/log/containers/\*.…

---

## [Check performance of cluster](https://discuss.elastic.co/t/check-performance-of-cluster/332996)

<div class="topic-metadata">

**Author:** [@NNI](https://discuss.elastic.co/u/NNI)\
**Replies:** 11\
**Last updated:** [May 10, 2023, 9:56am UTC](https://discuss.elastic.co/t/check-performance-of-cluster/332996 "2023-05-10T09:56:45Z")

</div>

Hi We're facing some performance issue cluster build on 9 nodes 3x ingest 3x master 3x data (on NVMe disks) index\_with\_data 2 r STARTED 10590253 elk\_es\_data-1 index\_with\_data 2 p …

---

## [Install and run Logstash tar file](https://discuss.elastic.co/t/install-and-run-logstash-tar-file/332899)

<div class="topic-metadata">

**Author:** [@hjsroldan](https://discuss.elastic.co/u/hjsroldan)\
**Replies:** 4\
**Last updated:** [May 10, 2023, 9:56am UTC](https://discuss.elastic.co/t/install-and-run-logstash-tar-file/332899 "2023-05-10T09:56:13Z")

</div>

Hi, Good day! Does anyone know how to install and run logstash in a tar format binary? Thank you! Best regards, Hasmine Joyce Roldan

---

## [JDBC plugin - issue getting binary data](https://discuss.elastic.co/t/jdbc-plugin-issue-getting-binary-data/332537)

<div class="topic-metadata">

**Author:** [@vymk](https://discuss.elastic.co/u/vymk)\
**Replies:** 1\
**Last updated:** [May 10, 2023, 9:25am UTC](https://discuss.elastic.co/t/jdbc-plugin-issue-getting-binary-data/332537 "2023-05-10T09:25:26Z")

</div>

I use the JDBC plugin to get data from a MSSQL database. Generally this is working but my query output includes MD5 hashes saved as binary, and then the output looks something like this in stdout (and even more gibberish…

[Previous page](https://discuss.elastic.co/latest.md?page=682)

[Next page](https://discuss.elastic.co/latest.md?page=684)
