# Latest

**URL:** https://discuss.elastic.co/latest.md?page=694

[Latest](https://discuss.elastic.co/latest.md) · [Categories](https://discuss.elastic.co/categories.md) · [Tags](https://discuss.elastic.co/tags.md)

**Page:** 695

---

## [Aggregate field with text type](https://discuss.elastic.co/t/aggregate-field-with-text-type/331119)

<div class="topic-metadata">

**Author:** [@Indeed2000](https://discuss.elastic.co/u/Indeed2000)\
**Replies:** 1\
**Last updated:** [April 30, 2023, 5:37pm UTC](https://discuss.elastic.co/t/aggregate-field-with-text-type/331119 "2023-04-30T17:37:31Z")

</div>

Hi i have two field in kibana "hostname" and "usage", when i add "usage" it will show area chart but when i add "hostname" as breakdown not show. FYI1: hostname type are text and not aggregatable! FYI2: these field cr…

---

## [Which index do elastic agents output too?](https://discuss.elastic.co/t/which-index-do-elastic-agents-output-too/331168)

<div class="topic-metadata">

**Author:** [@learningelastic](https://discuss.elastic.co/u/learningelastic)\
**Replies:** 1\
**Last updated:** [April 30, 2023, 5:11pm UTC](https://discuss.elastic.co/t/which-index-do-elastic-agents-output-too/331168 "2023-04-30T17:11:19Z")

</div>

I'm trying to configure a stand alone elastic agent. I get a success response during installation but i'm not sure which index in elasticsearch the data get sent to? This is my elastic-agent.yml file: outputs: defau…

---

## [View In context option is not available(EFK- Elasticsearch Fluentd kibana Stack)](https://discuss.elastic.co/t/view-in-context-option-is-not-available-efk-elasticsearch-fluentd-kibana-stack/331367)

<div class="topic-metadata">

**Author:** [@Srijitha](https://discuss.elastic.co/u/Srijitha)\
**Replies:** 0\
**Last updated:** [April 30, 2023, 4:03pm UTC](https://discuss.elastic.co/t/view-in-context-option-is-not-available-efk-elasticsearch-fluentd-kibana-stack/331367 "2023-04-30T16:03:45Z")

</div>

Hi Team, I am sending log from fluentd to elasticsearch, everything works fine. But I am not able to see "VIEW IN CONTEXT" option in log section of observability, Elasticsearch version: 8.7 and Kibana Version: 8.7. Below…

---

## [How to avoid duplicate values being copied while using copy\_to?](https://discuss.elastic.co/t/how-to-avoid-duplicate-values-being-copied-while-using-copy-to/330905)

<div class="topic-metadata">

**Author:** [@Srikrishna\_Raghupath](https://discuss.elastic.co/u/Srikrishna_Raghupath)\
**Replies:** 1\
**Last updated:** [April 30, 2023, 11:22am UTC](https://discuss.elastic.co/t/how-to-avoid-duplicate-values-being-copied-while-using-copy-to/330905 "2023-04-30T11:22:10Z")

</div>

My Index definition: PUT /test-index { "mappings": { "properties": { "category":{ "type": "text", "similarity": "boolean", "term\_vector": "with\_positions\_offsets", "fields":{…

---

## [Draw circle or polygons in Kibana Maps](https://discuss.elastic.co/t/draw-circle-or-polygons-in-kibana-maps/331161)

<div class="topic-metadata">

**Author:** [@Ulpcan](https://discuss.elastic.co/u/Ulpcan)\
**Replies:** 2\
**Last updated:** [April 30, 2023, 11:11am UTC](https://discuss.elastic.co/t/draw-circle-or-polygons-in-kibana-maps/331161 "2023-04-30T11:11:19Z")

</div>

Hello, There are 2 different fields in my index: location - geo\_point distance - long (we use as km) In kibana maps I would like to visualize: location field as a center of the circle or polygon distance field is t…

---

## [Why is --fleet-server-es required if I already specified --url when installing elastic agent?](https://discuss.elastic.co/t/why-is-fleet-server-es-required-if-i-already-specified-url-when-installing-elastic-agent/331169)

<div class="topic-metadata">

**Author:** [@learningelastic](https://discuss.elastic.co/u/learningelastic)\
**Replies:** 1\
**Last updated:** [April 30, 2023, 12:56am UTC](https://discuss.elastic.co/t/why-is-fleet-server-es-required-if-i-already-specified-url-when-installing-elastic-agent/331169 "2023-04-30T00:56:30Z")

</div>

I already have a fleet server and elastic instance set up in the cloud somewhere at https://fleet.example.net:8220 and https://elastic.example.net:9200. Next, I want to install an elastic agent on my laptop. I download…

---

## [Run time field generates error when trying tutorial](https://discuss.elastic.co/t/run-time-field-generates-error-when-trying-tutorial/330158)

<div class="topic-metadata">

**Author:** [@learningelastic](https://discuss.elastic.co/u/learningelastic)\
**Replies:** 2\
**Last updated:** [April 29, 2023, 9:38pm UTC](https://discuss.elastic.co/t/run-time-field-generates-error-when-trying-tutorial/330158 "2023-04-29T21:38:03Z")

</div>

I'm trying to learn how to create run time fields by following the instructions on this page: I tried my own variation with these queries: PUT rfield POST rfield/\_doc { "Favourite Food": "My fave food is" } GET r…

---

## [Logstash gives OOM & CPU Usage too high when used with S3 Input plugin](https://discuss.elastic.co/t/logstash-gives-oom-cpu-usage-too-high-when-used-with-s3-input-plugin/331121)

<div class="topic-metadata">

**Author:** [@Utpal\_Brahma](https://discuss.elastic.co/u/Utpal_Brahma)\
**Replies:** 3\
**Last updated:** [April 29, 2023, 5:25pm UTC](https://discuss.elastic.co/t/logstash-gives-oom-cpu-usage-too-high-when-used-with-s3-input-plugin/331121 "2023-04-29T17:25:38Z")

</div>

Logstash gives out of Memory when S3 plugin is used for a bucket which has already existing tones of files.

---

## [Can't write data to elasticsearch (cannot be changed from type \[date\] to \[text)](https://discuss.elastic.co/t/cant-write-data-to-elasticsearch-cannot-be-changed-from-type-date-to-text/330062)

<div class="topic-metadata">

**Author:** [@Indeed2000](https://discuss.elastic.co/u/Indeed2000)\
**Replies:** 21\
**Last updated:** [April 29, 2023, 2:59pm UTC](https://discuss.elastic.co/t/cant-write-data-to-elasticsearch-cannot-be-changed-from-type-date-to-text/330062 "2023-04-29T14:59:19Z")

</div>

Hi can't write data to elasticsearch vi logstash(http\_poller) here is the scenario: influxdb \> logstash(http\_poller) \> elasticsearch error that I get: "status"=\>400, "error"=\>{"type"=\>"illegal\_argument\_exception", "…

---

## [7.1から8.7にアップグレードで失敗(ToT)/~~~](https://discuss.elastic.co/t/7-1-8-7-tot/331125)

<div class="topic-metadata">

**Author:** [@toshihisa-nakamura](https://discuss.elastic.co/u/toshihisa-nakamura)\
**Replies:** 0\
**Last updated:** [April 29, 2023, 11:40am UTC](https://discuss.elastic.co/t/7-1-8-7-tot/331125 "2023-04-29T11:40:33Z")

</div>

7.1から8.7にアップグレードしたことで、データが入らなくなってしまいました。 Version8.7のままで、これまで通り、データがElasticserchに入り、Kibanaでグラフ表示が出来るようにしたいです。 Elastic Cloud に 気象データを送り、Kibanaでグラフ表示するだけの用途で数年利用しておりましたが、（要件を読まずにうっかり）8.7にアップグレードしてしまいました。 そのため、データがElastic…

---

## [Elastic defendで取得するログについて](https://discuss.elastic.co/t/elastic-defend/331118)

<div class="topic-metadata">

**Author:** [@e-se](https://discuss.elastic.co/u/e-se)\
**Replies:** 0\
**Last updated:** [April 29, 2023, 8:20am UTC](https://discuss.elastic.co/t/elastic-defend/331118 "2023-04-29T08:20:28Z")

</div>

linuxのサーバにelastic agentを導入し、にelastic defend integrationをあてて、logを収集することを検討しています。 そこで疑問です。 Linuxの場合、File、Network、Processのイベントを取得できるようですが、これらは何処で作成されたログになるのでしょうか。 System integrationや、Auditd log integrationなら、設定にファイルを指定する…

---

## [Limiting data integrity risks from compromised client](https://discuss.elastic.co/t/limiting-data-integrity-risks-from-compromised-client/331086)

<div class="topic-metadata">

**Author:** [@nf4ray](https://discuss.elastic.co/u/nf4ray)\
**Replies:** 3\
**Last updated:** [April 29, 2023, 7:49am UTC](https://discuss.elastic.co/t/limiting-data-integrity-risks-from-compromised-client/331086 "2023-04-29T07:49:16Z")

</div>

Let's say I want to monitor the system logs of a cluster of servers with filebeat. Because using one data stream per host doesn't scale well and the cluster is logically part of the same application, they all write to th…

---

## [When is filebeat 8.7.1 available for download](https://discuss.elastic.co/t/when-is-filebeat-8-7-1-available-for-download/331091)

<div class="topic-metadata">

**Author:** [@pavanrangain](https://discuss.elastic.co/u/pavanrangain)\
**Replies:** 2\
**Last updated:** [April 29, 2023, 7:23am UTC](https://discuss.elastic.co/t/when-is-filebeat-8-7-1-available-for-download/331091 "2023-04-29T07:23:59Z")

</div>

Saw this a few days back - Beats version 8.7.1 | Beats Platform Reference \[8.7\] | Elastic But there is no release artifacts present for downloading. When can we expect them to be available ?

---

## [Accessing Bucket aggregation in watcher condition. unexpected token was expecting one of \[{\<EOF\>, ';'}\]](https://discuss.elastic.co/t/accessing-bucket-aggregation-in-watcher-condition-unexpected-token-was-expecting-one-of-eof/331077)

<div class="topic-metadata">

**Author:** [@rahulkothanath](https://discuss.elastic.co/u/rahulkothanath)\
**Replies:** 0\
**Last updated:** [April 28, 2023, 5:02pm UTC](https://discuss.elastic.co/t/accessing-bucket-aggregation-in-watcher-condition-unexpected-token-was-expecting-one-of-eof/331077 "2023-04-28T17:02:29Z")

</div>

I am executing the below watch and want to compare the values of bucket 1D from the aggregation in the watcher condition. However, I am getting errors while accessing the value. POST \_watcher/watch/\_execute { "watch"…

---

## [Logstash filters for log file which is included some raw data and json data](https://discuss.elastic.co/t/logstash-filters-for-log-file-which-is-included-some-raw-data-and-json-data/330950)

<div class="topic-metadata">

**Author:** [@Harish1](https://discuss.elastic.co/u/Harish1)\
**Replies:** 3\
**Last updated:** [April 28, 2023, 5:24pm UTC](https://discuss.elastic.co/t/logstash-filters-for-log-file-which-is-included-some-raw-data-and-json-data/330950 "2023-04-28T17:24:50Z")

</div>

Hi Elastic team, I'm new to ELK, I'm trying to find out the filters for below log file but I'm not able to find the proper Logstash filter for below data 2023-01-19 15:38:31 INFO VCIPDownstreamController:138 - {"timest…

---

## [Disabled xpack security plugin in Kibana 8](https://discuss.elastic.co/t/disabled-xpack-security-plugin-in-kibana-8/331065)

<div class="topic-metadata">

**Author:** [@pchakour](https://discuss.elastic.co/u/pchakour)\
**Replies:** 5\
**Last updated:** [April 28, 2023, 4:55pm UTC](https://discuss.elastic.co/t/disabled-xpack-security-plugin-in-kibana-8/331065 "2023-04-28T16:55:00Z")

</div>

Hello ! I want to migrate (from 7.16 to 8.6) my own plugin that manage Kibana security with a custom login page and a custom security strategy. Unfortunately, I notice that the xpack.security.enabled configuration disa…

---

## [Filebeat not harvesting newly added records](https://discuss.elastic.co/t/filebeat-not-harvesting-newly-added-records/330603)

<div class="topic-metadata">

**Author:** [@Dasher](https://discuss.elastic.co/u/Dasher)\
**Replies:** 1\
**Last updated:** [April 28, 2023, 4:52pm UTC](https://discuss.elastic.co/t/filebeat-not-harvesting-newly-added-records/330603 "2023-04-28T16:52:29Z")

</div>

Hi,I have a filebeat which is running on windows server 2019.The data is actively getting written to that log file but it's timestamp changes every 30 mins.I trying to reading log file,but for some reason the newly added…

---

## [How to improve Kibana initial loading time](https://discuss.elastic.co/t/how-to-improve-kibana-initial-loading-time/330619)

<div class="topic-metadata">

**Author:** [@ysattvik](https://discuss.elastic.co/u/ysattvik)\
**Replies:** 1\
**Last updated:** [April 28, 2023, 4:47pm UTC](https://discuss.elastic.co/t/how-to-improve-kibana-initial-loading-time/330619 "2023-04-28T16:47:26Z")

</div>

I have a Kibana dashboard which contains 7 Vega-lite visualizations & 2 Kibana lens visualizations. Version used: 8.6.1 The dashboard takes around 13-14 sec to load. Most of the time is spent in initial loading of Kiban…

---

## [Not able to connect my apm-agent to my apm-server and data transfer from hosted on same server](https://discuss.elastic.co/t/not-able-to-connect-my-apm-agent-to-my-apm-server-and-data-transfer-from-hosted-on-same-server/330627)

<div class="topic-metadata">

**Author:** [@Tataelastic](https://discuss.elastic.co/u/Tataelastic)\
**Replies:** 1\
**Last updated:** [April 28, 2023, 4:39pm UTC](https://discuss.elastic.co/t/not-able-to-connect-my-apm-agent-to-my-apm-server-and-data-transfer-from-hosted-on-same-server/330627 "2023-04-28T16:39:35Z")

</div>

I have deployed elasticsearch, kibana, apm-server on same server ip: 10.8.30.220 output for http://10.8.30.220:8200 { "build\_date": "2023-01-31T04:33:06Z", "build\_sha": "71a8b4c241eb5b4609862c8354d2aa2270f6c568", "…

---

## [Importing third party filebeat dashboard into Kibana (SecurityOnion)](https://discuss.elastic.co/t/importing-third-party-filebeat-dashboard-into-kibana-securityonion/331076)

<div class="topic-metadata">

**Author:** [@KhemaisKebaili](https://discuss.elastic.co/u/KhemaisKebaili)\
**Replies:** 0\
**Last updated:** [April 28, 2023, 4:31pm UTC](https://discuss.elastic.co/t/importing-third-party-filebeat-dashboard-into-kibana-securityonion/331076 "2023-04-28T16:31:26Z")

</div>

I have a SecurityOnion instance that's hosting an ELK 8.6.1 stack. I enabled the threat intelligence module and I have data coming in and could be visualized using the discovery tool. However , and from my research, when…

---

## [Migrate from ELK to ECK - roles, role\_mappings](https://discuss.elastic.co/t/migrate-from-elk-to-eck-roles-role-mappings/330505)

<div class="topic-metadata">

**Author:** [@charlot\_Attard](https://discuss.elastic.co/u/charlot_Attard)\
**Replies:** 4\
**Last updated:** [April 28, 2023, 4:14pm UTC](https://discuss.elastic.co/t/migrate-from-elk-to-eck-roles-role-mappings/330505 "2023-04-28T16:14:03Z")

</div>

Hello, We are migrating ELK Version 7.17.0 to ECK Version 7.17.0 and we want to automate as much as we can the setup of the cluster. Is there a way whilst provisioning the ECK in the yaml manifets or init scripts we cre…

---

## [Multisource index on elasticsearch passing by logstash](https://discuss.elastic.co/t/multisource-index-on-elasticsearch-passing-by-logstash/330844)

<div class="topic-metadata">

**Author:** [@Abdeljalil\_El\_Yousso](https://discuss.elastic.co/u/Abdeljalil_El_Yousso)\
**Replies:** 10\
**Last updated:** [April 28, 2023, 3:57pm UTC](https://discuss.elastic.co/t/multisource-index-on-elasticsearch-passing-by-logstash/330844 "2023-04-28T15:57:42Z")

</div>

hey , im trying to create multiple source input from Filebeat , than injecting them into logstash to apply filters , and finally transfer the sources to elasticsearch as indexes The problem i have , only one index is cr…

---

## [How to use SearchLookup getSource(LeafReaderContext ctx, int doc)](https://discuss.elastic.co/t/how-to-use-searchlookup-getsource-leafreadercontext-ctx-int-doc/331072)

<div class="topic-metadata">

**Author:** [@p4paul](https://discuss.elastic.co/u/p4paul)\
**Replies:** 0\
**Last updated:** [April 28, 2023, 3:57pm UTC](https://discuss.elastic.co/t/how-to-use-searchlookup-getsource-leafreadercontext-ctx-int-doc/331072 "2023-04-28T15:57:41Z")

</div>

In 8.7.0 the source() method was removed from SearchLookup: How do I use the new getSource method in SearchLookup for a FilterScript given the following use case... public class MyLeafFactory implements FilterScript.…

---

## [Remove random indexes](https://discuss.elastic.co/t/remove-random-indexes/331066)

<div class="topic-metadata">

**Author:** [@Marcelo\_Moro\_Brondan](https://discuss.elastic.co/u/Marcelo_Moro_Brondan)\
**Replies:** 2\
**Last updated:** [April 28, 2023, 2:59pm UTC](https://discuss.elastic.co/t/remove-random-indexes/331066 "2023-04-28T14:59:17Z")

</div>

remove random indexesremove random indexesHello! I have an elasticsearch 5.6 in centOS 7 and it is behaving unexpectedly. Random indexes are being created. I am not able to identify the origin and apply a configuration …

---

## [Filtering on pdf reports](https://discuss.elastic.co/t/filtering-on-pdf-reports/329955)

<div class="topic-metadata">

**Author:** [@ElasticLiver](https://discuss.elastic.co/u/ElasticLiver)\
**Replies:** 2\
**Last updated:** [April 28, 2023, 2:19pm UTC](https://discuss.elastic.co/t/filtering-on-pdf-reports/329955 "2023-04-28T14:19:02Z")

</div>

Hi, when in a dashboard I select share -\> pdf reports - post url to create a report, i get this url: /api/reporting/generate/printablePdfV2?jobParams=(browserTimezone:America/Santiago,layout:(dimensions:(height:1463.984…

---

## [Huge logs - how Tuning filebeat](https://discuss.elastic.co/t/huge-logs-how-tuning-filebeat/330333)

<div class="topic-metadata">

**Author:** [@pepite](https://discuss.elastic.co/u/pepite)\
**Replies:** 5\
**Last updated:** [April 28, 2023, 12:58pm UTC](https://discuss.elastic.co/t/huge-logs-how-tuning-filebeat/330333 "2023-04-28T12:58:35Z")

</div>

Hi everybody, I'm french and i m a very newbie with elasticsearch. Elasticsearch version imposed by security team : 7.10.2 I create a cluster like this with dedicate nodes: 2 master node 1 master only eligible node 1…

---

## [Index template - exclude index seems not working](https://discuss.elastic.co/t/index-template-exclude-index-seems-not-working/331060)

<div class="topic-metadata">

**Author:** [@pepite](https://discuss.elastic.co/u/pepite)\
**Replies:** 0\
**Last updated:** [April 28, 2023, 12:54pm UTC](https://discuss.elastic.co/t/index-template-exclude-index-seems-not-working/331060 "2023-04-28T12:54:14Z")

</div>

Hi everybody. I dont find the correct syntax to exclude one index of an index pattern in index template 2 index template :slight\_smile: 1st { "order": 0, "index\_patterns": \[ "\*\_\*","-tdir\_business\_prod-\*" \], …

---

## [Rename nested field based on its data type](https://discuss.elastic.co/t/rename-nested-field-based-on-its-data-type/331044)

<div class="topic-metadata">

**Author:** [@aversecguy](https://discuss.elastic.co/u/aversecguy)\
**Replies:** 0\
**Last updated:** [April 28, 2023, 10:18am UTC](https://discuss.elastic.co/t/rename-nested-field-based-on-its-data-type/331044 "2023-04-28T10:18:21Z")

</div>

Hello, dear community, I am brand new to logstash, but have to fix a problem: We are gathering eks audit logs and have errors like illegal\_state\_exception error because of the field responseObject.status could be the t…

---

## [Azure Logs Integration with ECS logs](https://discuss.elastic.co/t/azure-logs-integration-with-ecs-logs/331041)

<div class="topic-metadata">

**Author:** [@CrystalDesignDR](https://discuss.elastic.co/u/CrystalDesignDR)\
**Replies:** 0\
**Last updated:** [April 28, 2023, 10:03am UTC](https://discuss.elastic.co/t/azure-logs-integration-with-ecs-logs/331041 "2023-04-28T10:03:24Z")

</div>

Hi, we are running Elastic Cloud and want to add Application Logs to it with Elastic Agent, these logs need to be correlated with out APM traces. We are running the Elastic Azure Logs Integration with the Elastic Agent…

---

## [Failed to assign role via role mapping API ldap realm](https://discuss.elastic.co/t/failed-to-assign-role-via-role-mapping-api-ldap-realm/331039)

<div class="topic-metadata">

**Author:** [@GaetanCia](https://discuss.elastic.co/u/GaetanCia)\
**Replies:** 0\
**Last updated:** [April 28, 2023, 9:59am UTC](https://discuss.elastic.co/t/failed-to-assign-role-via-role-mapping-api-ldap-realm/331039 "2023-04-28T09:59:04Z")

</div>

Hi, I have issue to assign a role via the role-mapping setting. I tried to assign a role to a certain group of people who connect from the ldap realm. If i use the native role mapping file, it work fine My role\_mappi…

[Previous page](https://discuss.elastic.co/latest.md?page=693)

[Next page](https://discuss.elastic.co/latest.md?page=695)
