# Latest

**URL:** https://discuss.elastic.co/latest.md?page=700

[Latest](https://discuss.elastic.co/latest.md) · [Categories](https://discuss.elastic.co/categories.md) · [Tags](https://discuss.elastic.co/tags.md)

**Page:** 701

---

## [Logging and metrics to on prem or outside the ECE](https://discuss.elastic.co/t/logging-and-metrics-to-on-prem-or-outside-the-ece/330680)

<div class="topic-metadata">

**Author:** [@shani\_angarkadu](https://discuss.elastic.co/u/shani_angarkadu)\
**Replies:** 1\
**Last updated:** [April 24, 2023, 6:07pm UTC](https://discuss.elastic.co/t/logging-and-metrics-to-on-prem-or-outside-the-ece/330680 "2023-04-24T18:07:11Z")

</div>

We have ECE setup and few deployments/clusters running. But we would like to send the logging and metrics data for each deployment to outside ECE on premises Elastic cluster. But we didn’t see an option to add Elastic c…

---

## [Geo\_Point field for mapping](https://discuss.elastic.co/t/geo-point-field-for-mapping/330363)

<div class="topic-metadata">

**Author:** [@Abdeljalil\_El\_Yousso](https://discuss.elastic.co/u/Abdeljalil_El_Yousso)\
**Replies:** 1\
**Last updated:** [April 24, 2023, 5:53pm UTC](https://discuss.elastic.co/t/geo-point-field-for-mapping/330363 "2023-04-24T17:53:27Z")

</div>

hey , im tryin g to create and have and geo\_point field to create a map visualisation , but im finding difficulties , my Lat and Long fields that i extracted previously from Geoip filter on My configuration file are flo…

---

## [Using legacy APM setup after upgrading Elasticsearch to 8.X](https://discuss.elastic.co/t/using-legacy-apm-setup-after-upgrading-elasticsearch-to-8-x/329351)

<div class="topic-metadata">

**Author:** [@YvorL](https://discuss.elastic.co/u/YvorL)\
**Replies:** 3\
**Last updated:** [April 24, 2023, 5:42pm UTC](https://discuss.elastic.co/t/using-legacy-apm-setup-after-upgrading-elasticsearch-to-8-x/329351 "2023-04-24T17:42:09Z")

</div>

Hi, I have a self-managed setup on v7.9.2 that ooks like this: Custom APM agents (hundreds) --\> load balancer --\> APM servers --\> Kafka for MQ --\> Logstash servers --\> Elasticsearch servers I upgraded a development sta…

---

## [100% disk, single node cluster how to fix?](https://discuss.elastic.co/t/100-disk-single-node-cluster-how-to-fix/330588)

<div class="topic-metadata">

**Author:** [@elasticforme](https://discuss.elastic.co/u/elasticforme)\
**Replies:** 8\
**Last updated:** [April 24, 2023, 5:12pm UTC](https://discuss.elastic.co/t/100-disk-single-node-cluster-how-to-fix/330588 "2023-04-24T17:12:47Z")

</div>

I have a test single node cluster. I know what the problem is but can't seems to figure out how to get out of it and fix without removing everything and star over this node has all index without replica because I exe…

---

## [Using Time Serie DataStream (TSDS) for discrete events with high cardinality](https://discuss.elastic.co/t/using-time-serie-datastream-tsds-for-discrete-events-with-high-cardinality/330679)

<div class="topic-metadata">

**Author:** [@Marchelune](https://discuss.elastic.co/u/Marchelune)\
**Replies:** 0\
**Last updated:** [April 24, 2023, 4:57pm UTC](https://discuss.elastic.co/t/using-time-serie-datastream-tsds-for-discrete-events-with-high-cardinality/330679 "2023-04-24T16:57:04Z")

</div>

Hi there! I'm new to TSDS and time series in general. Let's say I have the following index mapping: { "properties": { "@timestamp": { "type": "date" }, "game\_id": { "…

---

## [ELastic Defend agent high latency on DCs](https://discuss.elastic.co/t/elastic-defend-agent-high-latency-on-dcs/328766)

<div class="topic-metadata">

**Author:** [@Kelly\_Slavens](https://discuss.elastic.co/u/Kelly_Slavens)\
**Replies:** 2\
**Last updated:** [April 24, 2023, 4:44pm UTC](https://discuss.elastic.co/t/elastic-defend-agent-high-latency-on-dcs/328766 "2023-04-24T16:44:41Z")

</div>

We're seeing extreme latency on 2022 Domain controllers when Elastic Defend 8.6.2 Malicious Behavior rules are enabled. The server becomes very sluggish but performance metrics don't appear to show any sign of excesses l…

---

## [Update nested documents via painless](https://discuss.elastic.co/t/update-nested-documents-via-painless/330676)

<div class="topic-metadata">

**Author:** [@Tudor\_Plugaru](https://discuss.elastic.co/u/Tudor_Plugaru)\
**Replies:** 0\
**Last updated:** [April 24, 2023, 4:12pm UTC](https://discuss.elastic.co/t/update-nested-documents-via-painless/330676 "2023-04-24T16:12:47Z")

</div>

Hi, Assuming we have the following mapping "mappings": { "properties": { "id": { "type": "text", }, "messages": { "type": "nested", "dynamic": "strict", "properties": { "id…

---

## [APM error on Kubernetes minikube local cluster](https://discuss.elastic.co/t/apm-error-on-kubernetes-minikube-local-cluster/326811)

<div class="topic-metadata">

**Author:** [@thiago.silva](https://discuss.elastic.co/u/thiago.silva)\
**Replies:** 1\
**Last updated:** [April 24, 2023, 3:33pm UTC](https://discuss.elastic.co/t/apm-error-on-kubernetes-minikube-local-cluster/326811 "2023-04-24T15:33:30Z")

</div>

I encountered an issue while setting up APM server for Elasticsearch and Kibana. The error message indicates that APM server failed to import Kibana index patterns due to a 403 Forbidden error. I have tried troubleshooti…

---

## [Prometheus compatible metrics](https://discuss.elastic.co/t/prometheus-compatible-metrics/329988)

<div class="topic-metadata">

**Author:** [@Maksym\_Postument](https://discuss.elastic.co/u/Maksym_Postument)\
**Replies:** 1\
**Last updated:** [April 24, 2023, 3:17pm UTC](https://discuss.elastic.co/t/prometheus-compatible-metrics/329988 "2023-04-24T15:17:44Z")

</div>

Is there a way to expose apm metrics in prometheus compatible format? Kibana version: 8.6.0 Elasticsearch version: 8.6.0 APM Server version: 8.6.0 APM Agent language and version: otel Browser version: Original inst…

---

## [Apm-server installation without fleet server in single node](https://discuss.elastic.co/t/apm-server-installation-without-fleet-server-in-single-node/330600)

<div class="topic-metadata">

**Author:** [@lalchand\_rajak](https://discuss.elastic.co/u/lalchand_rajak)\
**Replies:** 1\
**Last updated:** [April 24, 2023, 3:11pm UTC](https://discuss.elastic.co/t/apm-server-installation-without-fleet-server-in-single-node/330600 "2023-04-24T15:11:43Z")

</div>

Can we install the APM server version 8.7 without fleet server in single node...? if yes, does it require to have internet access to install and integrate with apm-server. Because I have been trying to install the fleet …

---

## [\[NEWBIE\] Increase speed of indexation huge logs](https://discuss.elastic.co/t/newbie-increase-speed-of-indexation-huge-logs/330069)

<div class="topic-metadata">

**Author:** [@pepite](https://discuss.elastic.co/u/pepite)\
**Replies:** 25\
**Last updated:** [April 24, 2023, 9:21am UTC](https://discuss.elastic.co/t/newbie-increase-speed-of-indexation-huge-logs/330069 "2023-04-24T09:21:27Z")

</div>

Hi everybody, I'm french and i m a very newbie with elasticsearch. Elasticsearch version imposed by security team : 7.10.2 I create a cluster like this with dedicate nodes: 2 master node 1 master only eligible node 1…

---

## [SlowLogs Info Missing in 8.6 - "event.duration"](https://discuss.elastic.co/t/slowlogs-info-missing-in-8-6-event-duration/329040)

<div class="topic-metadata">

**Author:** [@moni15moni](https://discuss.elastic.co/u/moni15moni)\
**Replies:** 5\
**Last updated:** [April 24, 2023, 2:52pm UTC](https://discuss.elastic.co/t/slowlogs-info-missing-in-8-6-event-duration/329040 "2023-04-24T14:52:08Z")

</div>

Hi Team, Previously we used elasticcloud 7.17 , where we configured the observability in the different es cluster (7.17), When the slow logs are triggered the following events are captured in the slowllog. "event": { …

---

## [Filter search by ids with BM25 score in Python (Elastic 8.7)](https://discuss.elastic.co/t/filter-search-by-ids-with-bm25-score-in-python-elastic-8-7/330625)

<div class="topic-metadata">

**Author:** [@Francisco\_Rocha](https://discuss.elastic.co/u/Francisco_Rocha)\
**Replies:** 2\
**Last updated:** [April 24, 2023, 2:32pm UTC](https://discuss.elastic.co/t/filter-search-by-ids-with-bm25-score-in-python-elastic-8-7/330625 "2023-04-24T14:32:46Z")

</div>

Hi folks, I'm working with Python client and would like to know if it is possible to do a search by target ids with BM25. I have a 500k index and a list of ids that I would like to filter and at the same time obtain BM2…

---

## [Adding syslog priority fields to System integration](https://discuss.elastic.co/t/adding-syslog-priority-fields-to-system-integration/330519)

<div class="topic-metadata">

**Author:** [@sebek](https://discuss.elastic.co/u/sebek)\
**Replies:** 2\
**Last updated:** [April 24, 2023, 2:28pm UTC](https://discuss.elastic.co/t/adding-syslog-priority-fields-to-system-integration/330519 "2023-04-24T14:28:32Z")

</div>

Hi, i'm trying to work out how to add information about syslog priority to my logdata in elasticsearch. I'm testing out a self managed ELK stack, for collecting syslog data from linux(ubuntu) servers and workstations. …

---

## [Elastic Agent kubernetes container logs not shipping from nodes](https://discuss.elastic.co/t/elastic-agent-kubernetes-container-logs-not-shipping-from-nodes/330664)

<div class="topic-metadata">

**Author:** [@Rydzu](https://discuss.elastic.co/u/Rydzu)\
**Replies:** 0\
**Last updated:** [April 24, 2023, 2:21pm UTC](https://discuss.elastic.co/t/elastic-agent-kubernetes-container-logs-not-shipping-from-nodes/330664 "2023-04-24T14:21:01Z")

</div>

I'm quite fresh with elastic stack and I have a problem with elastic agents on k8. Setup: Both Elastic Stack (v8.7) and k8 (v1.25 with cri-o; 1 master, 3 nodes) are deployed on local environment. Elastic Stack deployed…

---

## ['npx @elastic/synthetic journeys' Command to run on specific \*journey.ts files](https://discuss.elastic.co/t/npx-elastic-synthetic-journeys-command-to-run-on-specific-journey-ts-files/330473)

<div class="topic-metadata">

**Author:** [@ameindel](https://discuss.elastic.co/u/ameindel)\
**Replies:** 4\
**Last updated:** [April 24, 2023, 2:02pm UTC](https://discuss.elastic.co/t/npx-elastic-synthetic-journeys-command-to-run-on-specific-journey-ts-files/330473 "2023-04-24T14:02:54Z")

</div>

Hello there, I've been playing with the --pattern, --match and --tags CLI parameters to get just a specific .journey.ts synthetic to execute locally (which will eventually be used in a push command). In my project/jour…

---

## [Is it Possible to have a Hierarchy of Rules](https://discuss.elastic.co/t/is-it-possible-to-have-a-hierarchy-of-rules/329210)

<div class="topic-metadata">

**Author:** [@juliette.littlewood](https://discuss.elastic.co/u/juliette.littlewood)\
**Replies:** 2\
**Last updated:** [April 24, 2023, 1:51pm UTC](https://discuss.elastic.co/t/is-it-possible-to-have-a-hierarchy-of-rules/329210 "2023-04-24T13:51:00Z")

</div>

Hi everyone, I'm setting up custom query rules that alert when fields in a document exceed pre-defined thresholds. In some circumstances, if the document category is a particular string value, then the thresholds shoul…

---

## [No Tests Found! when using --dry-run](https://discuss.elastic.co/t/no-tests-found-when-using-dry-run/330458)

<div class="topic-metadata">

**Author:** [@spaulovich](https://discuss.elastic.co/u/spaulovich)\
**Replies:** 4\
**Last updated:** [April 24, 2023, 1:34pm UTC](https://discuss.elastic.co/t/no-tests-found-when-using-dry-run/330458 "2023-04-24T13:34:08Z")

</div>

npx @elastic/synthetics . --dry-run results in "No tests found!" Omitting the --dry-run param, my journey ran locally without issue. CLI --help says, --dry-run don't actually execute anything, report only registered j…

---

## [Logstash show error "undefined method \`length' for nil:NilClass"](https://discuss.elastic.co/t/logstash-show-error-undefined-method-length-for-nil-nilclass/330373)

<div class="topic-metadata">

**Author:** [@C\_Wesley](https://discuss.elastic.co/u/C_Wesley)\
**Replies:** 7\
**Last updated:** [April 24, 2023, 1:20pm UTC](https://discuss.elastic.co/t/logstash-show-error-undefined-method-length-for-nil-nilclass/330373 "2023-04-24T13:20:09Z")

</div>

Hi there, I have an issue with the title. When I send the JSON log to Filebeat and send it ti my logstash, sometimes it passes the filter, but sometimes it fails. Would you please help me check my configuration to see w…

---

## [Logstash Opensearch Configuration havin codec json](https://discuss.elastic.co/t/logstash-opensearch-configuration-havin-codec-json/330607)

<div class="topic-metadata">

**Author:** [@djrshn2346](https://discuss.elastic.co/u/djrshn2346)\
**Replies:** 2\
**Last updated:** [April 24, 2023, 12:17pm UTC](https://discuss.elastic.co/t/logstash-opensearch-configuration-havin-codec-json/330607 "2023-04-24T12:17:04Z")

</div>

I am using opensearch with logstash, I wanted to use codec =\> json in output section of opensearch configuration. How can I achieve that? opensearch { hosts =\> \["${OPENSEARCH\_HOSTS}"\] index =\> "%{logplan…

---

## [How to know how much resources are being used for machine learning?](https://discuss.elastic.co/t/how-to-know-how-much-resources-are-being-used-for-machine-learning/330606)

<div class="topic-metadata">

**Author:** [@ElasticLiver](https://discuss.elastic.co/u/ElasticLiver)\
**Replies:** 1\
**Last updated:** [April 24, 2023, 11:49am UTC](https://discuss.elastic.co/t/how-to-know-how-much-resources-are-being-used-for-machine-learning/330606 "2023-04-24T11:49:28Z")

</div>

Hi, we are considering to add a new node exclusively for machine learning, how I can find out how much resources are being used for machine learning for all the jobs runing in real time? the documentation says that ther…

---

## [Different filters for different visualizations inside the same dashboard](https://discuss.elastic.co/t/different-filters-for-different-visualizations-inside-the-same-dashboard/330208)

<div class="topic-metadata">

**Author:** [@InesCM](https://discuss.elastic.co/u/InesCM)\
**Replies:** 6\
**Last updated:** [April 24, 2023, 11:21am UTC](https://discuss.elastic.co/t/different-filters-for-different-visualizations-inside-the-same-dashboard/330208 "2023-04-24T11:21:13Z")

</div>

Hi! I'm building a dashboard that has two visualizations, each of them taking data from different indexes. I want to apply a filter (that can be edited on the dashboard to show different data), but as the data comes fro…

---

## [Should I create an SQL Output for beats](https://discuss.elastic.co/t/should-i-create-an-sql-output-for-beats/330563)

<div class="topic-metadata">

**Author:** [@Toaster2-0](https://discuss.elastic.co/u/Toaster2-0)\
**Replies:** 2\
**Last updated:** [April 24, 2023, 10:50am UTC](https://discuss.elastic.co/t/should-i-create-an-sql-output-for-beats/330563 "2023-04-24T10:50:59Z")

</div>

Hello, TL;DR: I was thinking about making an output plugin for SQL. I tried the Elastic Stack for a few month with my private project, but the Stack seems too big for it and I am very comfortable in SQL. Now I was sear…

---

## [ECK Anonymous user concatenation of privileges](https://discuss.elastic.co/t/eck-anonymous-user-concatenation-of-privileges/330617)

<div class="topic-metadata">

**Author:** [@Patrick\_Bardo](https://discuss.elastic.co/u/Patrick_Bardo)\
**Replies:** 0\
**Last updated:** [April 24, 2023, 9:07am UTC](https://discuss.elastic.co/t/eck-anonymous-user-concatenation-of-privileges/330617 "2023-04-24T09:07:09Z")

</div>

We are using ECK operator v2.6.1 and Elastic and Kibana v8.6.2. We would like to enable anonymous access of kibana to our users, and have this user be authenticated with elasticsearch to have certain limited permissions.…

---

## [Unable to configure elastic search apt repository as a remote repository in Artifactory](https://discuss.elastic.co/t/unable-to-configure-elastic-search-apt-repository-as-a-remote-repository-in-artifactory/330286)

<div class="topic-metadata">

**Author:** [@joaobaptista](https://discuss.elastic.co/u/joaobaptista)\
**Replies:** 4\
**Last updated:** [April 24, 2023, 9:00am UTC](https://discuss.elastic.co/t/unable-to-configure-elastic-search-apt-repository-as-a-remote-repository-in-artifactory/330286 "2023-04-24T09:00:57Z")

</div>

Hi all, We are trying to configure Elasticsearch apt repository in Artifactory, but it always fails due to a error: "HTTP ERROR 404" We are using the following URL: https://artifacts.elastic.co/packages/8.x/apt The sa…

---

## [Filebeat unable to monitor container custom log path](https://discuss.elastic.co/t/filebeat-unable-to-monitor-container-custom-log-path/329905)

<div class="topic-metadata">

**Author:** [@pratikshatiwari](https://discuss.elastic.co/u/pratikshatiwari)\
**Replies:** 16\
**Last updated:** [April 24, 2023, 8:40am UTC](https://discuss.elastic.co/t/filebeat-unable-to-monitor-container-custom-log-path/329905 "2023-04-24T08:40:40Z")

</div>

Hello, I want to monitor the containers logs using filebeat kubernetes deplyment and the log format is in json format it is just monitoring the logs from containers but not this json file saved inside the container So …

---

## [What diffirent about nested and bool composite query](https://discuss.elastic.co/t/what-diffirent-about-nested-and-bool-composite-query/330063)

<div class="topic-metadata">

**Author:** [@sslhj](https://discuss.elastic.co/u/sslhj)\
**Replies:** 2\
**Last updated:** [April 24, 2023, 7:55am UTC](https://discuss.elastic.co/t/what-diffirent-about-nested-and-bool-composite-query/330063 "2023-04-24T07:55:36Z")

</div>

I have devloped a component that translate expression to esdel, now i have an exp like that "((extras.key== ‘k1’ and extras.value==100 ) or (extras.key== “k2” and extras.value==”v2”))", in that, ”extras“ is a nested fie…

---

## [Beats error: No paths were defined for input accessing config](https://discuss.elastic.co/t/beats-error-no-paths-were-defined-for-input-accessing-config/330285)

<div class="topic-metadata">

**Author:** [@Skairik](https://discuss.elastic.co/u/Skairik)\
**Replies:** 3\
**Last updated:** [April 24, 2023, 7:36am UTC](https://discuss.elastic.co/t/beats-error-no-paths-were-defined-for-input-accessing-config/330285 "2023-04-24T07:36:47Z")

</div>

Hi everyone , I am currently trying to configure filebeat to retrieve logs from my palo alto firewall, I have configured and enable the panw modules: - module: panw panos: enabled: true var.input: udp var…

---

## [In Elastic search, can we change the names of retrieved fields of searched response dynamically, like mongoDB projection?](https://discuss.elastic.co/t/in-elastic-search-can-we-change-the-names-of-retrieved-fields-of-searched-response-dynamically-like-mongodb-projection/330599)

<div class="topic-metadata">

**Author:** [@cvam199](https://discuss.elastic.co/u/cvam199)\
**Replies:** 3\
**Last updated:** [April 24, 2023, 6:42am UTC](https://discuss.elastic.co/t/in-elastic-search-can-we-change-the-names-of-retrieved-fields-of-searched-response-dynamically-like-mongodb-projection/330599 "2023-04-24T06:42:21Z")

</div>

When I query on Elasticsearch (ES) to get some data, I get it in following format: Response: "hits" : \[ { "\_index" : "testpoc", "\_type" : "\_doc", "\_id" : "1", "\_score" : 1.0, …

---

## [Elasticsearch template not working](https://discuss.elastic.co/t/elasticsearch-template-not-working/330574)

<div class="topic-metadata">

**Author:** [@jiankunking](https://discuss.elastic.co/u/jiankunking)\
**Replies:** 7\
**Last updated:** [April 24, 2023, 6:13am UTC](https://discuss.elastic.co/t/elasticsearch-template-not-working/330574 "2023-04-24T06:13:59Z")

</div>

I first write data directly to the specified index, and then create an index template, After the index template is created, I continue to write data into the specified index. At this time, I write the new properties of …

[Previous page](https://discuss.elastic.co/latest.md?page=699)

[Next page](https://discuss.elastic.co/latest.md?page=701)
