# Latest

**URL:** https://discuss.elastic.co/latest.md?page=699

[Latest](https://discuss.elastic.co/latest.md) · [Categories](https://discuss.elastic.co/categories.md) · [Tags](https://discuss.elastic.co/tags.md)

**Page:** 700

---

## [Connecting logstash to remote elasticsearch running on https with no port specified](https://discuss.elastic.co/t/connecting-logstash-to-remote-elasticsearch-running-on-https-with-no-port-specified/330587)

<div class="topic-metadata">

**Author:** [@Yahia-M](https://discuss.elastic.co/u/Yahia-M)\
**Replies:** 4\
**Last updated:** [April 25, 2023, 3:31pm UTC](https://discuss.elastic.co/t/connecting-logstash-to-remote-elasticsearch-running-on-https-with-no-port-specified/330587 "2023-04-25T15:31:29Z")

</div>

Hello , i am running Elasticsearch on a website called Cloud IDE gitpod. Once i start the docker image on the gitpod, docker-compose up --build Elasticsearch will start successfully i get a full https public url to ac…

---

## [Bulk upload in Elasticsearch 6.8.19 using python](https://discuss.elastic.co/t/bulk-upload-in-elasticsearch-6-8-19-using-python/330752)

<div class="topic-metadata">

**Author:** [@ANUBHAV\_GUPTA](https://discuss.elastic.co/u/ANUBHAV_GUPTA)\
**Replies:** 2\
**Last updated:** [April 25, 2023, 3:25pm UTC](https://discuss.elastic.co/t/bulk-upload-in-elasticsearch-6-8-19-using-python/330752 "2023-04-25T15:25:47Z")

</div>

Due to some reasons, I need to upload bulk csv data in Elasticsearch 6.8.19. Can someone provide me a piece of code for that. The latest version python code is not working for obvious reasons.

---

## [Kibana connection without enrollment token](https://discuss.elastic.co/t/kibana-connection-without-enrollment-token/330728)

<div class="topic-metadata">

**Author:** [@ANUBHAV\_GUPTA](https://discuss.elastic.co/u/ANUBHAV_GUPTA)\
**Replies:** 3\
**Last updated:** [April 25, 2023, 2:58pm UTC](https://discuss.elastic.co/t/kibana-connection-without-enrollment-token/330728 "2023-04-25T14:58:07Z")

</div>

Can we connect to elasticsearch using Kibana without the enrollment token and username-password? I tried sometime back, then it was not mandatory to provide enrollment token. Even tried setting xpack.security.enrollmen…

---

## [How to provide access to many Windows users and AD groups in Workplace Search using Network data connector as data source](https://discuss.elastic.co/t/how-to-provide-access-to-many-windows-users-and-ad-groups-in-workplace-search-using-network-data-connector-as-data-source/330525)

<div class="topic-metadata">

**Author:** [@aldol](https://discuss.elastic.co/u/aldol)\
**Replies:** 1\
**Last updated:** [April 25, 2023, 2:45pm UTC](https://discuss.elastic.co/t/how-to-provide-access-to-many-windows-users-and-ad-groups-in-workplace-search-using-network-data-connector-as-data-source/330525 "2023-04-25T14:45:11Z")

</div>

I have to give access to more than 500 users and 50 Active directory groups in Workplace search to be able to search data indexes from Network drive. I am able to do this using identitiy\_mappings.csv file. Detail of wha…

---

## [SharePoint online connector fails with Microsoft Graph 404 error](https://discuss.elastic.co/t/sharepoint-online-connector-fails-with-microsoft-graph-404-error/330739)

<div class="topic-metadata">

**Author:** [@ClemensW](https://discuss.elastic.co/u/ClemensW)\
**Replies:** 1\
**Last updated:** [April 25, 2023, 2:37pm UTC](https://discuss.elastic.co/t/sharepoint-online-connector-fails-with-microsoft-graph-404-error/330739 "2023-04-25T14:37:34Z")

</div>

I have been trying to set up Elasticsearch with a SharePoint integration. I am hosting elasticsearch, kibana and enterprise-search all version 8.7 in docker container. I added Sharepoint Online as a Source for the enter…

---

## [Kibana Table - Cell Text gets truncated](https://discuss.elastic.co/t/kibana-table-cell-text-gets-truncated/330407)

<div class="topic-metadata">

**Author:** [@mukesh\_pallapothu](https://discuss.elastic.co/u/mukesh_pallapothu)\
**Replies:** 8\
**Last updated:** [April 25, 2023, 2:12pm UTC](https://discuss.elastic.co/t/kibana-table-cell-text-gets-truncated/330407 "2023-04-25T14:12:09Z")

</div>

Hi Elastic Gurus, I have created a table in Kibana Dashboard and some cells have large amount of text. Is there a text wrap functionality or ability to resize the cell so that we can view the full data without get trim…

---

## [ELK stack lifecycle management](https://discuss.elastic.co/t/elk-stack-lifecycle-management/330663)

<div class="topic-metadata">

**Author:** [@mphilip9](https://discuss.elastic.co/u/mphilip9)\
**Replies:** 5\
**Last updated:** [April 25, 2023, 1:28pm UTC](https://discuss.elastic.co/t/elk-stack-lifecycle-management/330663 "2023-04-25T13:28:27Z")

</div>

I just took over an ELK stack app and I want to set up some proper index lifecycle management policies. From my understanding, I create an index lifecycle policy, and then I add/associate that policy with an index templa…

---

## [Upgrading ECK Operator on Openshift](https://discuss.elastic.co/t/upgrading-eck-operator-on-openshift/330742)

<div class="topic-metadata">

**Author:** [@gbschenkel](https://discuss.elastic.co/u/gbschenkel)\
**Replies:** 0\
**Last updated:** [April 25, 2023, 1:03pm UTC](https://discuss.elastic.co/t/upgrading-eck-operator-on-openshift/330742 "2023-04-25T13:03:26Z")

</div>

Hi, we have an instance of ELK on version 7.17.9, orchestrated on Openshift 4.11 using ECK Operator 1.9.0. For some reason the Certified ECK Operator for Openshift stopped upgrading itself. When Operator 2.0.0 came out …

---

## [Elasticsearch.Net.ElasticsearchClientException](https://discuss.elastic.co/t/elasticsearch-net-elasticsearchclientexception/330735)

<div class="topic-metadata">

**Author:** [@Atilla\_Cokmez](https://discuss.elastic.co/u/Atilla_Cokmez)\
**Replies:** 1\
**Last updated:** [April 25, 2023, 1:00pm UTC](https://discuss.elastic.co/t/elasticsearch-net-elasticsearchclientexception/330735 "2023-04-25T13:00:47Z")

</div>

I Use Elasticsearch 7.16.2 on docker and Nest 7.16.0 I added these codes by collecting them from two different classes. It may look complicated ConnectionSettings conStr = new ConnectionSettings(new Uri("http://localho…

---

## [Issue with logstash](https://discuss.elastic.co/t/issue-with-logstash/330741)

<div class="topic-metadata">

**Author:** [@Hanni](https://discuss.elastic.co/u/Hanni)\
**Replies:** 0\
**Last updated:** [April 25, 2023, 12:57pm UTC](https://discuss.elastic.co/t/issue-with-logstash/330741 "2023-04-25T12:57:52Z")

</div>

Hello, I am trying to parse this JSON with Logstash. {"creation\_date": "2023/01/04", "vulnerabilities": \[{"count": 1, "score": null, "vuln\_index": 414, "plugin\_name": "WordPad History", "severity": 0, "vpr\_score": null,…

---

## [Filebeat Config file](https://discuss.elastic.co/t/filebeat-config-file/330724)

<div class="topic-metadata">

**Author:** [@Dasher](https://discuss.elastic.co/u/Dasher)\
**Replies:** 1\
**Last updated:** [April 25, 2023, 12:56pm UTC](https://discuss.elastic.co/t/filebeat-config-file/330724 "2023-04-25T12:56:57Z")

</div>

I Need a help with the file beat config: I'm trying to read the data from a log file whose size remains the same and its modification time is changed every 30 mins.During these 30 mins interval new logs are added in pla…

---

## [What will happen to my upcoming logs in filebeat IF elasticsearch is Down](https://discuss.elastic.co/t/what-will-happen-to-my-upcoming-logs-in-filebeat-if-elasticsearch-is-down/330734)

<div class="topic-metadata">

**Author:** [@aurangzeb99](https://discuss.elastic.co/u/aurangzeb99)\
**Replies:** 0\
**Last updated:** [April 25, 2023, 11:54am UTC](https://discuss.elastic.co/t/what-will-happen-to-my-upcoming-logs-in-filebeat-if-elasticsearch-is-down/330734 "2023-04-25T11:54:29Z")

</div>

Hi I am forwarding Syslogs from Filebeat to Elasticsearch.If for some reasons my elasticsearch is down for hours or days . What will happen to my upcoming logs will filebeat hold or store locally if yes then how long …

---

## [App Search API Keys Basic Analytics Info](https://discuss.elastic.co/t/app-search-api-keys-basic-analytics-info/330307)

<div class="topic-metadata">

**Author:** [@alongaks](https://discuss.elastic.co/u/alongaks)\
**Replies:** 8\
**Last updated:** [April 25, 2023, 12:03pm UTC](https://discuss.elastic.co/t/app-search-api-keys-basic-analytics-info/330307 "2023-04-25T12:03:46Z")

</div>

Hello, I have a v8.7 deployment using App Search to crawl websites, indexing content. The site search experience is working nicely. However, I am wondering about the 'Recent queries' stats at the bottom of the page from…

---

## [How to apply ilm policy to index patter tenat-\*](https://discuss.elastic.co/t/how-to-apply-ilm-policy-to-index-patter-tenat/328428)

<div class="topic-metadata">

**Author:** [@elasticlog](https://discuss.elastic.co/u/elasticlog)\
**Replies:** 2\
**Last updated:** [April 25, 2023, 10:42am UTC](https://discuss.elastic.co/t/how-to-apply-ilm-policy-to-index-patter-tenat/328428 "2023-04-25T10:42:28Z")

</div>

Hello Expert, I have to apply an ilm policy to my index patter so that the space full issue should not occur. Im able to create the policy but not able to apply to index patter as i need to add manually for index patte…

---

## [Sampling aggregation with a fixed seed producing unstable results](https://discuss.elastic.co/t/sampling-aggregation-with-a-fixed-seed-producing-unstable-results/329849)

<div class="topic-metadata">

**Author:** [@geoffballinger](https://discuss.elastic.co/u/geoffballinger)\
**Replies:** 1\
**Last updated:** [April 25, 2023, 10:10am UTC](https://discuss.elastic.co/t/sampling-aggregation-with-a-fixed-seed-producing-unstable-results/329849 "2023-04-25T10:10:31Z")

</div>

We would like to use sampling aggregations to improve aggregation performance in some dashboards, but the results must be the same each time to avoid confusing customers. We are thus setting the seed since if we do that …

---

## [Handling of null and \[\] (empty list)](https://discuss.elastic.co/t/handling-of-null-and-empty-list/330720)

<div class="topic-metadata">

**Author:** [@nguyen\_huy](https://discuss.elastic.co/u/nguyen_huy)\
**Replies:** 0\
**Last updated:** [April 25, 2023, 9:24am UTC](https://discuss.elastic.co/t/handling-of-null-and-empty-list/330720 "2023-04-25T09:24:01Z")

</div>

Hi everybody, I am very new to Elasticsearch and I have a question regarding the handling of null and \[\] (empty list) values. Specifically, in my dummy index example, I have a document as follows { "hits": \[ …

---

## [Kibana failed to log in to the es cluster deployed by ECK, and the login timed out](https://discuss.elastic.co/t/kibana-failed-to-log-in-to-the-es-cluster-deployed-by-eck-and-the-login-timed-out/330597)

<div class="topic-metadata">

**Author:** [@Teresajw](https://discuss.elastic.co/u/Teresajw)\
**Replies:** 4\
**Last updated:** [April 25, 2023, 9:06am UTC](https://discuss.elastic.co/t/kibana-failed-to-log-in-to-the-es-cluster-deployed-by-eck-and-the-login-timed-out/330597 "2023-04-25T09:06:27Z")

</div>

Bug Report What did you do? I have installed ECK via CRD 2.7 in my Kubernetes cluster (v1.24.9) . After I have deployed Elasticsearch and Kibana via the manifests shown below. After a few minutes I can access to Kibana…

---

## [Elasticsearchversion 7.17.9 is not starting - Exception in thread "main" java.lang.RuntimeException: starting java](https://discuss.elastic.co/t/elasticsearchversion-7-17-9-is-not-starting-exception-in-thread-main-java-lang-runtimeexception-starting-java/330658)

<div class="topic-metadata">

**Author:** [@kirankumarb](https://discuss.elastic.co/u/kirankumarb)\
**Replies:** 5\
**Last updated:** [April 25, 2023, 5:48am UTC](https://discuss.elastic.co/t/elasticsearchversion-7-17-9-is-not-starting-exception-in-thread-main-java-lang-runtimeexception-starting-java/330658 "2023-04-25T05:48:42Z")

</div>

Elasticsearch 7.8 is upgraded to version 7.17.9, then unable to start the service. And in logs getting following Error: Exception in thread "main" java.lang.RuntimeException: starting java.

---

## [None of the configured nodes are available](https://discuss.elastic.co/t/none-of-the-configured-nodes-are-available/330340)

<div class="topic-metadata">

**Author:** [@zz-GuoYF](https://discuss.elastic.co/u/zz-GuoYF)\
**Replies:** 3\
**Last updated:** [April 25, 2023, 8:35am UTC](https://discuss.elastic.co/t/none-of-the-configured-nodes-are-available/330340 "2023-04-25T08:35:58Z")

</div>

The version of Elasticsearch I used is 2.4.6 and the deployment mode is single-node es. When I was running a query with a data volume of 7 million, the following error occurred in es： In addition, by adding GC log p…

---

## [Inspect raw JSON source data from Vega/Elasticsearch](https://discuss.elastic.co/t/inspect-raw-json-source-data-from-vega-elasticsearch/330629)

<div class="topic-metadata">

**Author:** [@peppar](https://discuss.elastic.co/u/peppar)\
**Replies:** 1\
**Last updated:** [April 25, 2023, 7:58am UTC](https://discuss.elastic.co/t/inspect-raw-json-source-data-from-vega-elasticsearch/330629 "2023-04-25T07:58:59Z")

</div>

I'm trying to create advanced visualizations with Vega, but I'm having the hardest time guessing the dataset names. I'm fetching my data as such: { "$schema": "https://vega.github.io/schema/vega/v4.json", "descripti…

---

## [How to send subject field data from logstash to syslog server](https://discuss.elastic.co/t/how-to-send-subject-field-data-from-logstash-to-syslog-server/330642)

<div class="topic-metadata">

**Author:** [@Thumati](https://discuss.elastic.co/u/Thumati)\
**Replies:** 2\
**Last updated:** [April 25, 2023, 6:25am UTC](https://discuss.elastic.co/t/how-to-send-subject-field-data-from-logstash-to-syslog-server/330642 "2023-04-25T06:25:52Z")

</div>

I would like to know if is it possible to send subject field to rsyslog server. Eg: subject : " username " should be sent.

---

## [Is Elasticsearch 7.17.9 is compatible withOpenJDK 1.8?](https://discuss.elastic.co/t/is-elasticsearch-7-17-9-is-compatible-withopenjdk-1-8/330654)

<div class="topic-metadata">

**Author:** [@kirankumarb](https://discuss.elastic.co/u/kirankumarb)\
**Replies:** 7\
**Last updated:** [April 25, 2023, 5:59am UTC](https://discuss.elastic.co/t/is-elasticsearch-7-17-9-is-compatible-withopenjdk-1-8/330654 "2023-04-25T05:59:59Z")

</div>

Is OpenJDK 1.8 version is compatible with elasticsearch 7.17.9 version? If not Which version of OpenJDK is compatible with elasticsearch 7.17.9?

---

## [Send logs from filebeat to elasticsearch](https://discuss.elastic.co/t/send-logs-from-filebeat-to-elasticsearch/330628)

<div class="topic-metadata">

**Author:** [@Neelam\_Zanvar](https://discuss.elastic.co/u/Neelam_Zanvar)\
**Replies:** 7\
**Last updated:** [April 25, 2023, 5:39am UTC](https://discuss.elastic.co/t/send-logs-from-filebeat-to-elasticsearch/330628 "2023-04-25T05:39:27Z")

</div>

I am trying to send logs from filebeat to elasticsearch. Here is the filbeat.yml filebeat.inputs: - type: filestream id: my-filestream-id enabled: true paths: - C:\\ProgramData\\sample\_logs\\sample.log - type: lo…

---

## [Analyzer \[full\_chinese\] contains filters \[my\_synonym\] that are not allowed to run in index time mode](https://discuss.elastic.co/t/analyzer-full-chinese-contains-filters-my-synonym-that-are-not-allowed-to-run-in-index-time-mode/330626)

<div class="topic-metadata">

**Author:** [@YKX-Can](https://discuss.elastic.co/u/YKX-Can)\
**Replies:** 1\
**Last updated:** [April 25, 2023, 2:59am UTC](https://discuss.elastic.co/t/analyzer-full-chinese-contains-filters-my-synonym-that-are-not-allowed-to-run-in-index-time-mode/330626 "2023-04-25T02:59:38Z")

</div>

this my setting PUT test { "settings": { "analysis": { "char\_filter": { "my\_tsconvert": { "convert\_type": "t2s", "type": "stconvert" } }, "filter": { "my\_synonym": { "type": "synon…

---

## [Average of sum(value)](https://discuss.elastic.co/t/average-of-sum-value/330685)

<div class="topic-metadata">

**Author:** [@elasticforme](https://discuss.elastic.co/u/elasticforme)\
**Replies:** 2\
**Last updated:** [April 24, 2023, 9:09pm UTC](https://discuss.elastic.co/t/average-of-sum-value/330685 "2023-04-24T21:09:50Z")

</div>

I am running a ingestion and records comes every 15 min one of the field is integer #user value might be 1, 2,3 or what ever. what I am trying to do is average of sum ( users) per hour for example rec1 - 10:00am { …

---

## [Runtime Field Convert the Timestamp to Display Month and Year](https://discuss.elastic.co/t/runtime-field-convert-the-timestamp-to-display-month-and-year/330164)

<div class="topic-metadata">

**Author:** [@mukesh\_pallapothu](https://discuss.elastic.co/u/mukesh_pallapothu)\
**Replies:** 2\
**Last updated:** [April 24, 2023, 7:53pm UTC](https://discuss.elastic.co/t/runtime-field-convert-the-timestamp-to-display-month-and-year/330164 "2023-04-24T19:53:47Z")

</div>

I have a requirement to show only the month and Year from the date on a Dashboard For instance I want to show how number of tickets by month and year - Apr 2023 currently the visualization shows this as below, I want t…

---

## [Send Logs from Filebeat on my local machine to Logstash having a private ip](https://discuss.elastic.co/t/send-logs-from-filebeat-on-my-local-machine-to-logstash-having-a-private-ip/330352)

<div class="topic-metadata">

**Author:** [@Neelam\_Zanvar](https://discuss.elastic.co/u/Neelam_Zanvar)\
**Replies:** 2\
**Last updated:** [April 24, 2023, 7:13pm UTC](https://discuss.elastic.co/t/send-logs-from-filebeat-on-my-local-machine-to-logstash-having-a-private-ip/330352 "2023-04-24T19:13:10Z")

</div>

Hi i have installed filebeat on my local windows machine. I want to send logs to Logstash which has a private IP only and is in a different VPC. How can i set a connection between these two machines? Is it possible?

---

## [Creation of multiple logstash pipelines using API](https://discuss.elastic.co/t/creation-of-multiple-logstash-pipelines-using-api/330612)

<div class="topic-metadata">

**Author:** [@anjali\_roy](https://discuss.elastic.co/u/anjali_roy)\
**Replies:** 9\
**Last updated:** [April 24, 2023, 7:08pm UTC](https://discuss.elastic.co/t/creation-of-multiple-logstash-pipelines-using-api/330612 "2023-04-24T19:08:11Z")

</div>

I have a use case to create multiple Logstash pipelines inside a running Logstash container, Is it possible to use Logstash APIs as I do not have Elasticsearch and Kibana host. Just a Logstash running inside a cluster. I…

---

## [Elastic search on windows](https://discuss.elastic.co/t/elastic-search-on-windows/330409)

<div class="topic-metadata">

**Author:** [@Preethi\_Manu](https://discuss.elastic.co/u/Preethi_Manu)\
**Replies:** 8\
**Last updated:** [April 24, 2023, 6:34pm UTC](https://discuss.elastic.co/t/elastic-search-on-windows/330409 "2023-04-24T18:34:34Z")

</div>

While installing Elastic search on windows , getting below error like plugin db2jcc4.jar is missing a descriptor properties file. Please help to resolve this

---

## [Kibana Authentification](https://discuss.elastic.co/t/kibana-authentification/330243)

<div class="topic-metadata">

**Author:** [@Julien069](https://discuss.elastic.co/u/Julien069)\
**Replies:** 7\
**Last updated:** [April 24, 2023, 6:27pm UTC](https://discuss.elastic.co/t/kibana-authentification/330243 "2023-04-24T18:27:00Z")

</div>

Hi, I'have a problem to authentificating Kibana on Elastic . After generating a token on Elastic, Kibana is block on "Server is not ready yet" I have two different IP on each server and they ping each other Changes i…

[Previous page](https://discuss.elastic.co/latest.md?page=698)

[Next page](https://discuss.elastic.co/latest.md?page=700)
