# Latest

**URL:** https://discuss.elastic.co/latest.md?page=684

[Latest](https://discuss.elastic.co/latest.md) · [Categories](https://discuss.elastic.co/categories.md) · [Tags](https://discuss.elastic.co/tags.md)

**Page:** 685

---

## [LEAD/LAG window function in elasticsearch](https://discuss.elastic.co/t/lead-lag-window-function-in-elasticsearch/332866)

<div class="topic-metadata">

**Author:** [@Sanjana\_Saswade](https://discuss.elastic.co/u/Sanjana_Saswade)\
**Replies:** 4\
**Last updated:** [May 9, 2023, 2:47pm UTC](https://discuss.elastic.co/t/lead-lag-window-function-in-elasticsearch/332866 "2023-05-09T14:47:33Z")

</div>

I need to use LEAD /LAG function in elasticsearch. i tried collapse in ELK but it's not working. How do I fix this? sql query for convert in Elasticsearch query: select name, LAG(salary) OVER(PARTITION BY department …

---

## [Grok debugger works, on logstash not](https://discuss.elastic.co/t/grok-debugger-works-on-logstash-not/332930)

<div class="topic-metadata">

**Author:** [@psyskeletor](https://discuss.elastic.co/u/psyskeletor)\
**Replies:** 2\
**Last updated:** [May 10, 2023, 8:23am UTC](https://discuss.elastic.co/t/grok-debugger-works-on-logstash-not/332930 "2023-05-10T08:23:54Z")

</div>

Hi there. Super new to logstash. I wanted to extract exit code from logs, so i came with this solution using grok debugger filter { grok { match =\> { "message" =\> "(?\<exit\_code\>\\b\[exit code \]\\d+ \\b)" } …

---

## [Aggregating unique (timestamp) values](https://discuss.elastic.co/t/aggregating-unique-timestamp-values/333043)

<div class="topic-metadata">

**Author:** [@idrv](https://discuss.elastic.co/u/idrv)\
**Replies:** 0\
**Last updated:** [May 10, 2023, 8:13am UTC](https://discuss.elastic.co/t/aggregating-unique-timestamp-values/333043 "2023-05-10T08:13:27Z")

</div>

Hello, community! I hope my question doesn't double something already asked and answered here. I'm searching for the best way to store aggregated data in a dedicated index. In the best-case scenario, it should include …

---

## [What are the best ways to find near phrases? How to combine them to find near to nearest near? ))](https://discuss.elastic.co/t/what-are-the-best-ways-to-find-near-phrases-how-to-combine-them-to-find-near-to-nearest-near/333042)

<div class="topic-metadata">

**Author:** [@Eduard\_mart](https://discuss.elastic.co/u/Eduard_mart)\
**Replies:** 0\
**Last updated:** [May 10, 2023, 8:11am UTC](https://discuss.elastic.co/t/what-are-the-best-ways-to-find-near-phrases-how-to-combine-them-to-find-near-to-nearest-near/333042 "2023-05-10T08:11:59Z")

</div>

How to find nearest near. Example: "query" : { "query\_string": { "query": "\\"field korean\\"~10", "fields" : \["message.stemmed"\], "default\_operator": "AND" } It finds all strings that contain …

---

## [Remove all backslash from fields in logstash](https://discuss.elastic.co/t/remove-all-backslash-from-fields-in-logstash/333041)

<div class="topic-metadata">

**Author:** [@SmoZyNS](https://discuss.elastic.co/u/SmoZyNS)\
**Replies:** 0\
**Last updated:** [May 10, 2023, 8:08am UTC](https://discuss.elastic.co/t/remove-all-backslash-from-fields-in-logstash/333041 "2023-05-10T08:08:08Z")

</div>

Hello, what I am trying to do is to remove backslash as well as double quotes from fields after parsing them with kv. Here is the original input sent to logstash: \<14\>1 2023-05-09T15:06:23+02:00 NAS WinFileService - -…

---

## [Npx @elastic/synthetic Command Line Options for Selectively Deploying 'lightweight' Synthetics](https://discuss.elastic.co/t/npx-elastic-synthetic-command-line-options-for-selectively-deploying-lightweight-synthetics/330747)

<div class="topic-metadata">

**Author:** [@ameindel](https://discuss.elastic.co/u/ameindel)\
**Replies:** 3\
**Last updated:** [May 10, 2023, 7:26am UTC](https://discuss.elastic.co/t/npx-elastic-synthetic-command-line-options-for-selectively-deploying-lightweight-synthetics/330747 "2023-05-10T07:26:21Z")

</div>

Hello there, I was wondering if there is any undocumented functionality that allows one to selectively deploy 'lightweight' synthetics, similar to how 'journeys' synthetics can be selectively run using --pattern, --matc…

---

## [Can not access json.orig\_bytes and json.resp\_bytes in filebeat zeek's module](https://discuss.elastic.co/t/can-not-access-json-orig-bytes-and-json-resp-bytes-in-filebeat-zeeks-module/333029)

<div class="topic-metadata">

**Author:** [@pakban3242](https://discuss.elastic.co/u/pakban3242)\
**Replies:** 0\
**Last updated:** [May 10, 2023, 7:05am UTC](https://discuss.elastic.co/t/can-not-access-json-orig-bytes-and-json-resp-bytes-in-filebeat-zeeks-module/333029 "2023-05-10T07:05:00Z")

</div>

Hi , i want to bring zeek logs to Elasticsearch , but this two modules are not included json.orig\_bytes","json.resp\_bytes i have changed this file /usr/share/filebeat/module/zeek/connection/config/connection.yml and …

---

## [Issue with logsatsh](https://discuss.elastic.co/t/issue-with-logsatsh/330227)

<div class="topic-metadata">

**Author:** [@Hanni](https://discuss.elastic.co/u/Hanni)\
**Replies:** 38\
**Last updated:** [May 10, 2023, 6:34am UTC](https://discuss.elastic.co/t/issue-with-logsatsh/330227 "2023-05-10T06:34:23Z")

</div>

Hello, I am currently working on a subject. I am trying to parse my data in JSON format to store it in Elasticsearch, but Logstash is unable to parse my data and is generating errors. Can you help me?

---

## [Conditionally change row colour in EuiInMemoryTable](https://discuss.elastic.co/t/conditionally-change-row-colour-in-euiinmemorytable/332515)

<div class="topic-metadata">

**Author:** [@Sheereen](https://discuss.elastic.co/u/Sheereen)\
**Replies:** 2\
**Last updated:** [May 10, 2023, 5:24am UTC](https://discuss.elastic.co/t/conditionally-change-row-colour-in-euiinmemorytable/332515 "2023-05-10T05:24:44Z")

</div>

Hi, How can I conditionally change the row colour in EuiInMemoryTable ? I have a column, say health. I want to change the entire row colour based on the value in the health column (of the corresponding row). Health -\> …

---

## [Mapping conflict between two indexes of different versions of metricbeat](https://discuss.elastic.co/t/mapping-conflict-between-two-indexes-of-different-versions-of-metricbeat/333010)

<div class="topic-metadata">

**Author:** [@ElasticLiver](https://discuss.elastic.co/u/ElasticLiver)\
**Replies:** 7\
**Last updated:** [May 10, 2023, 5:19am UTC](https://discuss.elastic.co/t/mapping-conflict-between-two-indexes-of-different-versions-of-metricbeat/333010 "2023-05-10T05:19:15Z")

</div>

Hi, I have two metricbeats with diferent versions pointing to the same elasticsearch, the difference between their mapping is causing me problems when I try to use the control visualization in kibana. if i choose to u…

---

## [How to change timezone on painless script](https://discuss.elastic.co/t/how-to-change-timezone-on-painless-script/332871)

<div class="topic-metadata">

**Author:** [@yuswanul](https://discuss.elastic.co/u/yuswanul)\
**Replies:** 2\
**Last updated:** [May 10, 2023, 3:30am UTC](https://discuss.elastic.co/t/how-to-change-timezone-on-painless-script/332871 "2023-05-10T03:30:59Z")

</div>

Hello everyone, i want to ask something about painless script. so i just made a painless script that look like this: but unfortunately the result of this script is still in utc and i want to change it to another time…

---

## [Creating APM index in Elasticsearch based on event name in APM server 8.7.1](https://discuss.elastic.co/t/creating-apm-index-in-elasticsearch-based-on-event-name-in-apm-server-8-7-1/332811)

<div class="topic-metadata">

**Author:** [@mralians](https://discuss.elastic.co/u/mralians)\
**Replies:** 3\
**Last updated:** [May 10, 2023, 1:12am UTC](https://discuss.elastic.co/t/creating-apm-index-in-elasticsearch-based-on-event-name-in-apm-server-8-7-1/332811 "2023-05-10T01:12:09Z")

</div>

I upgraded APM from version 7.17 to 8.7.1. In the previous version, the APM index in Elasticsearch was based on this APM server configuration: - index: "apm-%{\[observer.version\]}-%{\[service.name\]}-metric-%{+yyyy.MM.dd}"…

---

## [Trace source of authentication failures from logs](https://discuss.elastic.co/t/trace-source-of-authentication-failures-from-logs/333005)

<div class="topic-metadata">

**Author:** [@Russell\_Fulton](https://discuss.elastic.co/u/Russell_Fulton)\
**Replies:** 1\
**Last updated:** [May 10, 2023, 12:40am UTC](https://discuss.elastic.co/t/trace-source-of-authentication-failures-from-logs/333005 "2023-05-10T00:40:13Z")

</div>

I am seeing this log repeated twice a minute on one of my ES servers: \[2023-05-10T00:11:33,186\]\[WARN \]\[o.e.x.s.a.RealmsAuthenticator\] \[secesprd02\] Authentication to realm default\_native failed - Password authentication …

---

## [Kibana custom plugin](https://discuss.elastic.co/t/kibana-custom-plugin/332603)

<div class="topic-metadata">

**Author:** [@rodrigo\_Ceron](https://discuss.elastic.co/u/rodrigo_Ceron)\
**Replies:** 2\
**Last updated:** [May 9, 2023, 10:35pm UTC](https://discuss.elastic.co/t/kibana-custom-plugin/332603 "2023-05-09T22:35:01Z")

</div>

Hi everyone, I'm developing a customplugin however I have a question. Is it possible to give privileges to a user so they can access only this plugin?

---

## [Restoring snapshot from one cluster to brand new deployment](https://discuss.elastic.co/t/restoring-snapshot-from-one-cluster-to-brand-new-deployment/332844)

<div class="topic-metadata">

**Author:** [@Buddha](https://discuss.elastic.co/u/Buddha)\
**Replies:** 2\
**Last updated:** [May 9, 2023, 10:29pm UTC](https://discuss.elastic.co/t/restoring-snapshot-from-one-cluster-to-brand-new-deployment/332844 "2023-05-09T22:29:18Z")

</div>

Hello, I am using the Clastic cloud services and I was going through a practice exercise of restoring snapshot from one deployment to brand new deployment in case of any disaster. The GUi is straight forward, but I am …

---

## [Runtime field causes the error "A document doesn't have a field"](https://discuss.elastic.co/t/runtime-field-causes-the-error-a-document-doesnt-have-a-field/332848)

<div class="topic-metadata">

**Author:** [@learningelastic](https://discuss.elastic.co/u/learningelastic)\
**Replies:** 3\
**Last updated:** [May 9, 2023, 8:34pm UTC](https://discuss.elastic.co/t/runtime-field-causes-the-error-a-document-doesnt-have-a-field/332848 "2023-05-09T20:34:35Z")

</div>

I'm trying to use a run time field but I keep getting the error: A document doesn't have a value for a field! Use doc\[\<field\>\].size()==0 to check if a document is missing a field! You can reproduce the issue by running…

---

## [Not Able To Install Elastic Agent Onto Windows 10](https://discuss.elastic.co/t/not-able-to-install-elastic-agent-onto-windows-10/332971)

<div class="topic-metadata">

**Author:** [@mx09](https://discuss.elastic.co/u/mx09)\
**Replies:** 2\
**Last updated:** [May 9, 2023, 8:29pm UTC](https://discuss.elastic.co/t/not-able-to-install-elastic-agent-onto-windows-10/332971 "2023-05-09T20:29:52Z")

</div>

Error: unable to perform install command, not executed with Administrator permissions I've tried to add an Agent onto what will be my "Victim Machine" I'm doing this with the Kali Purple instance in a virtual environmen…

---

## [Field in MSSQL as ID and the use of versioning](https://discuss.elastic.co/t/field-in-mssql-as-id-and-the-use-of-versioning/332414)

<div class="topic-metadata">

**Author:** [@Ric1](https://discuss.elastic.co/u/Ric1)\
**Replies:** 3\
**Last updated:** [May 9, 2023, 7:34pm UTC](https://discuss.elastic.co/t/field-in-mssql-as-id-and-the-use-of-versioning/332414 "2023-05-09T19:34:01Z")

</div>

Hello, I hope I've put this in the correct place. My scenario is: I have data accessible via the JDBC input on MSSQL. The JDBC input plugin runs a command to find records that match a certain query. The output is an …

---

## [Form data in body for Logstash HTTP filter](https://discuss.elastic.co/t/form-data-in-body-for-logstash-http-filter/332574)

<div class="topic-metadata">

**Author:** [@analog\_memories](https://discuss.elastic.co/u/analog_memories)\
**Replies:** 2\
**Last updated:** [May 9, 2023, 7:18pm UTC](https://discuss.elastic.co/t/form-data-in-body-for-logstash-http-filter/332574 "2023-05-09T19:18:37Z")

</div>

Hello, I was wondering if anyone has had the syntax for using form data in the body of HTTP filter. I have tried all manor of ways to make it work, and searched the forums, but have not found anything. This post is pr…

---

## [Support for multiple named computed scores in a single search](https://discuss.elastic.co/t/support-for-multiple-named-computed-scores-in-a-single-search/332995)

<div class="topic-metadata">

**Author:** [@Krum\_Bakalsky](https://discuss.elastic.co/u/Krum_Bakalsky)\
**Replies:** 0\
**Last updated:** [May 9, 2023, 7:05pm UTC](https://discuss.elastic.co/t/support-for-multiple-named-computed-scores-in-a-single-search/332995 "2023-05-09T19:05:38Z")

</div>

Hello Elasticsearch community, When serving a given search query, our service is computing and using proximity score for each document in our index relative to the given query. This we currently implement by invoking th…

---

## [Is it preferable to use publicly signed certificates for fleet server?](https://discuss.elastic.co/t/is-it-preferable-to-use-publicly-signed-certificates-for-fleet-server/332732)

<div class="topic-metadata">

**Author:** [@learningelastic](https://discuss.elastic.co/u/learningelastic)\
**Replies:** 2\
**Last updated:** [May 9, 2023, 7:02pm UTC](https://discuss.elastic.co/t/is-it-preferable-to-use-publicly-signed-certificates-for-fleet-server/332732 "2023-05-09T19:02:27Z")

</div>

I'm reading through the documentation for fleet servers in elastic 8.7. On the subject of configuring TLS/SSL for fleet servers, I see this: Is it preferable to create certificates for fleet servers with ./bin/elasti…

---

## [Request http error on Wildfly 9 io.undertow.servlet.spec.HttpServletRequestImpl](https://discuss.elastic.co/t/request-http-error-on-wildfly-9-io-undertow-servlet-spec-httpservletrequestimpl/329547)

<div class="topic-metadata">

**Author:** [@miguel.longo](https://discuss.elastic.co/u/miguel.longo)\
**Replies:** 7\
**Last updated:** [May 9, 2023, 6:57pm UTC](https://discuss.elastic.co/t/request-http-error-on-wildfly-9-io-undertow-servlet-spec-httpservletrequestimpl/329547 "2023-05-09T18:57:00Z")

</div>

Kibana version: 8.6.2 Elasticsearch version: 8.6.2 APM Server version: 8.6.2 APM Agent language and version: Java on 1.36.0 Browser version: Original install method (e.g. download page, yum, deb, from source, etc.)…

---

## [Getting ENOSPC error when using file output plugin in Logstash](https://discuss.elastic.co/t/getting-enospc-error-when-using-file-output-plugin-in-logstash/332985)

<div class="topic-metadata">

**Author:** [@Arinjay\_Jain](https://discuss.elastic.co/u/Arinjay_Jain)\
**Replies:** 0\
**Last updated:** [May 9, 2023, 6:26pm UTC](https://discuss.elastic.co/t/getting-enospc-error-when-using-file-output-plugin-in-logstash/332985 "2023-05-09T18:26:39Z")

</div>

Hi Team, I have the following logstash pipeline config. input { tcp { port =\> "${TCP\_PORT}" codec =\> line } } filter { grok { match =\> {"message" =\> "%{SYSLOGTIMESTAMP:time} %{DATA:s…

---

## [Manage several data stream(s) in the elasitcsearch output with interpolation](https://discuss.elastic.co/t/manage-several-data-stream-s-in-the-elasitcsearch-output-with-interpolation/332981)

<div class="topic-metadata">

**Author:** [@Pascal\_Nuccio](https://discuss.elastic.co/u/Pascal_Nuccio)\
**Replies:** 1\
**Last updated:** [May 9, 2023, 6:23pm UTC](https://discuss.elastic.co/t/manage-several-data-stream-s-in-the-elasitcsearch-output-with-interpolation/332981 "2023-05-09T18:23:51Z")

</div>

If you need to manage several data streams for one LOGSTASH instance, you can configure the elasticsearch output like this in your logstash configuration: We must use a filter to configure the data\_stream parameters (ty…

---

## [Using a modal to display Elastic Search-UI results, but there is a weird lag where only part of the original search term is searched](https://discuss.elastic.co/t/using-a-modal-to-display-elastic-search-ui-results-but-there-is-a-weird-lag-where-only-part-of-the-original-search-term-is-searched/332973)

<div class="topic-metadata">

**Author:** [@Jonah\_Cornish\_Packer](https://discuss.elastic.co/u/Jonah_Cornish_Packer)\
**Replies:** 1\
**Last updated:** [May 9, 2023, 5:33pm UTC](https://discuss.elastic.co/t/using-a-modal-to-display-elastic-search-ui-results-but-there-is-a-weird-lag-where-only-part-of-the-original-search-term-is-searched/332973 "2023-05-09T17:33:12Z")

</div>

I have implemented Elastic's Search-UI on my website, where the user can enter their search term on the parent page and when they submit their search the results show up in a modal. The modal displays the search results …

---

## [Error Installing Fleet Server Agent on Centralized Host](https://discuss.elastic.co/t/error-installing-fleet-server-agent-on-centralized-host/332310)

<div class="topic-metadata">

**Author:** [@gmosornoza](https://discuss.elastic.co/u/gmosornoza)\
**Replies:** 2\
**Last updated:** [May 9, 2023, 4:55pm UTC](https://discuss.elastic.co/t/error-installing-fleet-server-agent-on-centralized-host/332310 "2023-05-09T16:55:03Z")

</div>

Hi! I'm facing an issue when installing Fleet Server as centralized host. I' running this command sudo ./elastic-agent install \\ --fleet-server-es=https://XXX.XXX.XXX.XXX:9200 \\ --fleet-server-service-token=my\_tok…

---

## [Use new metric like legacy with Last value function on keyword field](https://discuss.elastic.co/t/use-new-metric-like-legacy-with-last-value-function-on-keyword-field/332927)

<div class="topic-metadata">

**Author:** [@Jonas\_S](https://discuss.elastic.co/u/Jonas_S)\
**Replies:** 3\
**Last updated:** [May 9, 2023, 3:31pm UTC](https://discuss.elastic.co/t/use-new-metric-like-legacy-with-last-value-function-on-keyword-field/332927 "2023-05-09T15:31:48Z")

</div>

Hello, i create one index per month, which are grouped in a data view. There is a keyword field in the index which contains a string representation of the month that the index was created like 'May 2023'. Up until now …

---

## [List all runtime fields in index pattern?](https://discuss.elastic.co/t/list-all-runtime-fields-in-index-pattern/332908)

<div class="topic-metadata">

**Author:** [@nisow95612](https://discuss.elastic.co/u/nisow95612)\
**Replies:** 4\
**Last updated:** [May 9, 2023, 3:28pm UTC](https://discuss.elastic.co/t/list-all-runtime-fields-in-index-pattern/332908 "2023-05-09T15:28:57Z")

</div>

Hello, sadly it seems Are runtime multi-fields possible? is not possible, so my question for today is: Is it possible to list all runtime fields for an index pattern in Kibana? I know I can dump the mapping for each i…

---

## [Elastic APM agent VS OpenTelemetry client](https://discuss.elastic.co/t/elastic-apm-agent-vs-opentelemetry-client/332903)

<div class="topic-metadata">

**Author:** [@AThomsen](https://discuss.elastic.co/u/AThomsen)\
**Replies:** 1\
**Last updated:** [May 9, 2023, 3:16pm UTC](https://discuss.elastic.co/t/elastic-apm-agent-vs-opentelemetry-client/332903 "2023-05-09T15:16:26Z")

</div>

Now that Elastic Stack has native support for OpenTelemetry I guess there are (at least) two ways to do APM from a .Net application (the same question is probably valid for java and others as well). Using the Elastic A…

---

## [Vega: Signal resets to initial value after refreshing the dashboard (revisit)](https://discuss.elastic.co/t/vega-signal-resets-to-initial-value-after-refreshing-the-dashboard-revisit/332963)

<div class="topic-metadata">

**Author:** [@edgarmat1964](https://discuss.elastic.co/u/edgarmat1964)\
**Replies:** 0\
**Last updated:** [May 9, 2023, 3:15pm UTC](https://discuss.elastic.co/t/vega-signal-resets-to-initial-value-after-refreshing-the-dashboard-revisit/332963 "2023-05-09T15:15:36Z")

</div>

LS, when is this https://discuss.elastic.co/t/vega-signal-resets-to-initial-value-after-refreshing-the-dashboard/138263 issue going to be solved? I'm running into this issue. Elasticsearch 7.17.9 Kibana 7.17.9 Rock…

[Previous page](https://discuss.elastic.co/latest.md?page=683)

[Next page](https://discuss.elastic.co/latest.md?page=685)
