# Latest

**URL:** https://discuss.elastic.co/latest.md?page=706

[Latest](https://discuss.elastic.co/latest.md) · [Categories](https://discuss.elastic.co/categories.md) · [Tags](https://discuss.elastic.co/tags.md)

**Page:** 707

---

## [Get a substring of a string](https://discuss.elastic.co/t/get-a-substring-of-a-string/330278)

<div class="topic-metadata">

**Author:** [@obelaisk](https://discuss.elastic.co/u/obelaisk)\
**Replies:** 0\
**Last updated:** [April 19, 2023, 8:53am UTC](https://discuss.elastic.co/t/get-a-substring-of-a-string/330278 "2023-04-19T08:53:22Z")

</div>

Hi, im using canvas and i don't know if it's possible to get a substring of a given string in expression editor

---

## [Wondering about the coordinator](https://discuss.elastic.co/t/wondering-about-the-coordinator/330273)

<div class="topic-metadata">

**Author:** [@steman-provinzial](https://discuss.elastic.co/u/steman-provinzial)\
**Replies:** 0\
**Last updated:** [April 19, 2023, 8:03am UTC](https://discuss.elastic.co/t/wondering-about-the-coordinator/330273 "2023-04-19T08:03:12Z")

</div>

Hi there, I am new to ece and wondering about the roles in ece. In the documentation it is spoken about the coordinator role. But in the overview: Service-oriented architecture | Elastic Cloud Enterprise Reference \[3…

---

## [Anomaly Detection transactions financial data](https://discuss.elastic.co/t/anomaly-detection-transactions-financial-data/330207)

<div class="topic-metadata">

**Author:** [@Maretti](https://discuss.elastic.co/u/Maretti)\
**Replies:** 2\
**Last updated:** [April 19, 2023, 7:57am UTC](https://discuss.elastic.co/t/anomaly-detection-transactions-financial-data/330207 "2023-04-19T07:57:05Z")

</div>

I have a data set that holds data like this: I want to create an anomaly detection job that alerts about suspicious large transactions but when I create a anomaly detection job it always looks at for example 1 day an…

---

## [Logstash-8.7 fails to load YAML larger than 3MB](https://discuss.elastic.co/t/logstash-8-7-fails-to-load-yaml-larger-than-3mb/330269)

<div class="topic-metadata">

**Author:** [@Dheeraj\_Gupta](https://discuss.elastic.co/u/Dheeraj_Gupta)\
**Replies:** 0\
**Last updated:** [April 19, 2023, 7:55am UTC](https://discuss.elastic.co/t/logstash-8-7-fails-to-load-yaml-larger-than-3mb/330269 "2023-04-19T07:55:24Z")

</div>

We are using Logstash translate plugin to add user information to IP addresses in logs/events in our organization. The user data is loaded via YAML. The file is large (5.5MB with around 15K entries). Till Logstash-8.6, …

---

## [Remove setup directory agent old version](https://discuss.elastic.co/t/remove-setup-directory-agent-old-version/330244)

<div class="topic-metadata">

**Author:** [@GKre](https://discuss.elastic.co/u/GKre)\
**Replies:** 2\
**Last updated:** [April 19, 2023, 7:35am UTC](https://discuss.elastic.co/t/remove-setup-directory-agent-old-version/330244 "2023-04-19T07:35:05Z")

</div>

Hello, due to the wonderfull help inside this forum i come more and more into the system and i really like what i learn and see. I had the problem that upgrade of the agent to 8.7.0 did not work like expected. So i ch…

---

## [Count number of times an index was searched](https://discuss.elastic.co/t/count-number-of-times-an-index-was-searched/330260)

<div class="topic-metadata">

**Author:** [@searchwithme](https://discuss.elastic.co/u/searchwithme)\
**Replies:** 1\
**Last updated:** [April 19, 2023, 6:30am UTC](https://discuss.elastic.co/t/count-number-of-times-an-index-was-searched/330260 "2023-04-19T06:30:58Z")

</div>

Hi team! Is there a way to find out how many times a particular index was searched/queries? If not a direct API in elastic, is there a workaround to get this metric?

---

## [Kibana Dashboard in slideshow Mode](https://discuss.elastic.co/t/kibana-dashboard-in-slideshow-mode/330263)

<div class="topic-metadata">

**Author:** [@Dipesh](https://discuss.elastic.co/u/Dipesh)\
**Replies:** 0\
**Last updated:** [April 19, 2023, 6:01am UTC](https://discuss.elastic.co/t/kibana-dashboard-in-slideshow-mode/330263 "2023-04-19T06:01:16Z")

</div>

Hi, I have some dashboards with multiple visualisation attached in it, since it has 30+ Visualize charts added in the dashboard, its doesn't look good and also unable to see in a single screen, so i am searching for som…

---

## [Exiting: error initializing publisher: output type http undefined in filebeat.yml](https://discuss.elastic.co/t/exiting-error-initializing-publisher-output-type-http-undefined-in-filebeat-yml/330258)

<div class="topic-metadata">

**Author:** [@karthic](https://discuss.elastic.co/u/karthic)\
**Replies:** 1\
**Last updated:** [April 19, 2023, 5:39am UTC](https://discuss.elastic.co/t/exiting-error-initializing-publisher-output-type-http-undefined-in-filebeat-yml/330258 "2023-04-19T05:39:28Z")

</div>

Hi I need to forward the logs to my own api, In the config, i am using Http.output which says the error "Exiting: error initializing publisher: output type http undefined in filebeat" output.http: url: "https://API…

---

## [AI-powered Elastic search alternative, for small project?](https://discuss.elastic.co/t/ai-powered-elastic-search-alternative-for-small-project/330261)

<div class="topic-metadata">

**Author:** [@c\_u\_be\_binh\_an](https://discuss.elastic.co/u/c_u_be_binh_an)\
**Replies:** 0\
**Last updated:** [April 19, 2023, 4:51am UTC](https://discuss.elastic.co/t/ai-powered-elastic-search-alternative-for-small-project/330261 "2023-04-19T04:51:04Z")

</div>

I am developing a job board using NodeJs and it currently has around 1,000 items. However, I am facing an issue with deploying it on a 1GB RAM VPS as it cannot run Elastic Search on it. Therefore, I am searching for a li…

---

## [Mail enable smtp activity logs](https://discuss.elastic.co/t/mail-enable-smtp-activity-logs/329672)

<div class="topic-metadata">

**Author:** [@dharminfadia](https://discuss.elastic.co/u/dharminfadia)\
**Replies:** 2\
**Last updated:** [April 19, 2023, 4:29am UTC](https://discuss.elastic.co/t/mail-enable-smtp-activity-logs/329672 "2023-04-19T04:29:45Z")

</div>

Hello everyone I am trying to pars mail enable activity loga there are millions of logs in un even pattern I write some of the pattern and logs pars in well manner ans structured but now the issue is so many logs parsin…

---

## [How to monitor detail why elasstic data node is overloaded](https://discuss.elastic.co/t/how-to-monitor-detail-why-elasstic-data-node-is-overloaded/330105)

<div class="topic-metadata">

**Author:** [@Petr.Simik](https://discuss.elastic.co/u/Petr.Simik)\
**Replies:** 3\
**Last updated:** [April 19, 2023, 4:25am UTC](https://discuss.elastic.co/t/how-to-monitor-detail-why-elasstic-data-node-is-overloaded/330105 "2023-04-19T04:25:39Z")

</div>

our elastic is v8.6 3 master, 40x datanode (8core/32GB/2TB) , 2x loadbalancer node We ingest 100k-900K events/sec by few hundreds of different ingest pipelines, some of them creates small indices but there is about 5-…

---

## [Getting 403 denied to elastic.co (for anything: apt refresh, wget, etc)](https://discuss.elastic.co/t/getting-403-denied-to-elastic-co-for-anything-apt-refresh-wget-etc/329903)

<div class="topic-metadata">

**Author:** [@olegkrysinov](https://discuss.elastic.co/u/olegkrysinov)\
**Replies:** 1\
**Last updated:** [April 19, 2023, 2:20am UTC](https://discuss.elastic.co/t/getting-403-denied-to-elastic-co-for-anything-apt-refresh-wget-etc/329903 "2023-04-19T02:20:28Z")

</div>

Hello! I\`ve a problem (( Error:1 https://artifacts.elastic.co:443/packages/8.x/apt stable InRelease 403 Forbidden \[IP: 34.120.127.130 443\] E: Failed to fetch http://artifacts.elastic.co/packages/8.x/apt/dists/stable/I…

---

## [Move all Indexes to new host](https://discuss.elastic.co/t/move-all-indexes-to-new-host/329825)

<div class="topic-metadata">

**Author:** [@acosta353](https://discuss.elastic.co/u/acosta353)\
**Replies:** 1\
**Last updated:** [April 19, 2023, 2:14am UTC](https://discuss.elastic.co/t/move-all-indexes-to-new-host/329825 "2023-04-19T02:14:39Z")

</div>

Hello, I have a host for Warm and another to Cold Phase without replicas configured. Now, I need to proceed to a maintenance on this Warm host, so i wanted to move all those Warm Indexes temporarily to Cold host (Added …

---

## [Error generating a custom certificate and private key for Fleet Server](https://discuss.elastic.co/t/error-generating-a-custom-certificate-and-private-key-for-fleet-server/330256)

<div class="topic-metadata">

**Author:** [@Lelc79](https://discuss.elastic.co/u/Lelc79)\
**Replies:** 0\
**Last updated:** [April 19, 2023, 12:57am UTC](https://discuss.elastic.co/t/error-generating-a-custom-certificate-and-private-key-for-fleet-server/330256 "2023-04-19T00:57:13Z")

</div>

Hi Elastic community I am generating my certificates to my Fleet Server Step1 ./bin/elasticsearch-certutil ca --pem i moved my CA.cert & ca.key to /path/to/ca Step2: ./bin/elasticsearch-certutil cert --name Flee…

---

## [Cluster health wrong yellow spikes (because new index ?)](https://discuss.elastic.co/t/cluster-health-wrong-yellow-spikes-because-new-index/330124)

<div class="topic-metadata">

**Author:** [@ebuildy](https://discuss.elastic.co/u/ebuildy)\
**Replies:** 7\
**Last updated:** [April 18, 2023, 10:53pm UTC](https://discuss.elastic.co/t/cluster-health-wrong-yellow-spikes-because-new-index/330124 "2023-04-18T22:53:25Z")

</div>

We are running elasticsearch on kubernetes, via the ECK operator. Every day we receive at least 4 alerts about elasticsearch cluster health go to yellow. Also, we use argocd to deploy it, the health check script here a…

---

## [Possible Bug in Timeline: Fields containing "\\\\" string](https://discuss.elastic.co/t/possible-bug-in-timeline-fields-containing-string/330248)

<div class="topic-metadata">

**Author:** [@nemhods](https://discuss.elastic.co/u/nemhods)\
**Replies:** 0\
**Last updated:** [April 18, 2023, 8:10pm UTC](https://discuss.elastic.co/t/possible-bug-in-timeline-fields-containing-string/330248 "2023-04-18T20:10:42Z")

</div>

Hey, I just experienced a possible bug with timeline: I have found events in a timeline view. All events in my timeline have the field "winlog.event\_data.ShareName "="\\\*\\Archiv". So when I filter for this field, nothi…

---

## [Error: fleet-server failed: context canceled](https://discuss.elastic.co/t/error-fleet-server-failed-context-canceled/330050)

<div class="topic-metadata">

**Author:** [@Lelc79](https://discuss.elastic.co/u/Lelc79)\
**Replies:** 3\
**Last updated:** [April 18, 2023, 6:21pm UTC](https://discuss.elastic.co/t/error-fleet-server-failed-context-canceled/330050 "2023-04-18T18:21:28Z")

</div>

hello elastic community I have a problem trying to configure the fleet server, I have done the following: Inside Kibana - fleet/settings Fleet server hosts I have put my local server 192.0.1.20 with port 8220 Output…

---

## [Mapping Error with Run Time Field](https://discuss.elastic.co/t/mapping-error-with-run-time-field/330231)

<div class="topic-metadata">

**Author:** [@JeremyP](https://discuss.elastic.co/u/JeremyP)\
**Replies:** 4\
**Last updated:** [April 18, 2023, 5:25pm UTC](https://discuss.elastic.co/t/mapping-error-with-run-time-field/330231 "2023-04-18T17:25:18Z")

</div>

Hello, I'm having issues with runtime fields with Elastic. I have this run time field working fine in Kibana, however, I need this field to be present in the database. I simplified the script, mostly to redact it's sen…

---

## [Embedding kibana via fastly edge proxy](https://discuss.elastic.co/t/embedding-kibana-via-fastly-edge-proxy/330242)

<div class="topic-metadata">

**Author:** [@Shubham\_Pancholi](https://discuss.elastic.co/u/Shubham_Pancholi)\
**Replies:** 0\
**Last updated:** [April 18, 2023, 5:23pm UTC](https://discuss.elastic.co/t/embedding-kibana-via-fastly-edge-proxy/330242 "2023-04-18T17:23:33Z")

</div>

We are using Elasticsearch and kibana, we are using kibana to create dashboard which we will are embedding into our system. We don't want to use login in kibana from fontend so we are using our fastly compute edge to re…

---

## [Control visualisation issues](https://discuss.elastic.co/t/control-visualisation-issues/330170)

<div class="topic-metadata">

**Author:** [@elasticforme](https://discuss.elastic.co/u/elasticforme)\
**Replies:** 3\
**Last updated:** [April 18, 2023, 5:15pm UTC](https://discuss.elastic.co/t/control-visualisation-issues/330170 "2023-04-18T17:15:03Z")

</div>

I have 8.5.3 and control is messed up there as well. it has white background and light color font, hard to see anything. it is fixed in next version, but I am not ready to upgrade . It seems control viz is not good eno…

---

## [Time difference between dashboard and devTools (ElasticSearch)](https://discuss.elastic.co/t/time-difference-between-dashboard-and-devtools-elasticsearch/330236)

<div class="topic-metadata">

**Author:** [@FTOR](https://discuss.elastic.co/u/FTOR)\
**Replies:** 3\
**Last updated:** [April 18, 2023, 5:02pm UTC](https://discuss.elastic.co/t/time-difference-between-dashboard-and-devtools-elasticsearch/330236 "2023-04-18T17:02:54Z")

</div>

Hello, I have a time difference of 2 hours between Elasticsearch and kibana's dashboard. For example, the dashboard shows this date as follow, but the real value is 2023-04-18 13:53:00.890 I changed the Time Zone …

---

## [How to customize the exported fields?](https://discuss.elastic.co/t/how-to-customize-the-exported-fields/330240)

<div class="topic-metadata">

**Author:** [@matheuscirillo](https://discuss.elastic.co/u/matheuscirillo)\
**Replies:** 0\
**Last updated:** [April 18, 2023, 4:59pm UTC](https://discuss.elastic.co/t/how-to-customize-the-exported-fields/330240 "2023-04-18T16:59:01Z")

</div>

I have a very basic filebeats.yml configuration file: filebeat: inputs: - type: filestream id: my-log-stream paths: - /path/to/application/logs/\*.log json: keys\_under\_root: true add\_err…

---

## [Logstash JDBC Static Filter Can't Connect to SQLite DB](https://discuss.elastic.co/t/logstash-jdbc-static-filter-cant-connect-to-sqlite-db/330171)

<div class="topic-metadata">

**Author:** [@Dustin527](https://discuss.elastic.co/u/Dustin527)\
**Replies:** 6\
**Last updated:** [April 18, 2023, 4:52pm UTC](https://discuss.elastic.co/t/logstash-jdbc-static-filter-cant-connect-to-sqlite-db/330171 "2023-04-18T16:52:00Z")

</div>

Hi I am having trouble getting the JDBC static filter to work with an SQLite DB. I am using the xerial sqlite jdbc lib on Debian and the latest logstash package. I even have a small java program that can connect to and …

---

## [Ask For help](https://discuss.elastic.co/t/ask-for-help/330234)

<div class="topic-metadata">

**Author:** [@Farah\_Bannour](https://discuss.elastic.co/u/Farah_Bannour)\
**Replies:** 2\
**Last updated:** [April 18, 2023, 3:50pm UTC](https://discuss.elastic.co/t/ask-for-help/330234 "2023-04-18T15:50:11Z")

</div>

Good morning I'm doing an internship in Business intelligence working to collect data from odoo.sh to ELK Stack I'm working in odoo.sh. I want to ask you about the integration of the module in odoo.sh is possible or no…

---

## ["reset" ILM failed step](https://discuss.elastic.co/t/reset-ilm-failed-step/327754)

<div class="topic-metadata">

**Author:** [@pestevao](https://discuss.elastic.co/u/pestevao)\
**Replies:** 7\
**Last updated:** [April 18, 2023, 3:40pm UTC](https://discuss.elastic.co/t/reset-ilm-failed-step/327754 "2023-04-18T15:40:44Z")

</div>

Hello, I've some restricted indices stuck on ILM actions because of permissions. security\_exception: action \[indices:admin/delete\] is unauthorized for user \[xxx\] with roles \[superuser\] on restricted indices \[.ds-.fleet…

---

## [Filter result by collapsed date](https://discuss.elastic.co/t/filter-result-by-collapsed-date/330235)

<div class="topic-metadata">

**Author:** [@Mickael\_BARBIER](https://discuss.elastic.co/u/Mickael_BARBIER)\
**Replies:** 0\
**Last updated:** [April 18, 2023, 3:35pm UTC](https://discuss.elastic.co/t/filter-result-by-collapsed-date/330235 "2023-04-18T15:35:32Z")

</div>

Hello, i have a topic/news system (a topic can have many news in different language) i want to get the oldest news of each topic. And i want the result sorted by the oldest news displayedAt column. ex: topic1 -News…

---

## [Last value in painless script](https://discuss.elastic.co/t/last-value-in-painless-script/329298)

<div class="topic-metadata">

**Author:** [@martinsbleu](https://discuss.elastic.co/u/martinsbleu)\
**Replies:** 2\
**Last updated:** [April 18, 2023, 3:32pm UTC](https://discuss.elastic.co/t/last-value-in-painless-script/329298 "2023-04-18T15:32:56Z")

</div>

Hello Team, Like in the title, I am trying to get the last\_value of a field for the Return On Investment calculation. Normally, I can do this in Lens Formula (rf. below) on a monthly index. But I don't know how for a da…

---

## [Add field from filebeat eventhub input parameter](https://discuss.elastic.co/t/add-field-from-filebeat-eventhub-input-parameter/330139)

<div class="topic-metadata">

**Author:** [@Paf](https://discuss.elastic.co/u/Paf)\
**Replies:** 2\
**Last updated:** [April 18, 2023, 3:18pm UTC](https://discuss.elastic.co/t/add-field-from-filebeat-eventhub-input-parameter/330139 "2023-04-18T15:18:40Z")

</div>

Hello, I want to add field from filebeat eventhub input parameter. I use this input configuration: - type: azure-eventhub id: azure-eventhub-insights-activity-1 eventhub: "activity-logs" consumer\_group: "$Defaul…

---

## [How to build query using elastic8 java client](https://discuss.elastic.co/t/how-to-build-query-using-elastic8-java-client/330194)

<div class="topic-metadata">

**Author:** [@suresh\_chaudhari](https://discuss.elastic.co/u/suresh_chaudhari)\
**Replies:** 2\
**Last updated:** [April 18, 2023, 3:14pm UTC](https://discuss.elastic.co/t/how-to-build-query-using-elastic8-java-client/330194 "2023-04-18T15:14:25Z")

</div>

I need one example where using elastic 8 dsl creates query which includes boolquery with should shouldnot must .query(q -\> q.bool( b -\> b.must(ListObj).should(listShould).mustNot(listMustNot)…

---

## [Sort document based on a field value](https://discuss.elastic.co/t/sort-document-based-on-a-field-value/330084)

<div class="topic-metadata">

**Author:** [@mohammedsajidkhaleel](https://discuss.elastic.co/u/mohammedsajidkhaleel)\
**Replies:** 8\
**Last updated:** [April 18, 2023, 2:41pm UTC](https://discuss.elastic.co/t/sort-document-based-on-a-field-value/330084 "2023-04-18T14:41:19Z")

</div>

Hi, Am having a real estate ads and I would like sort the document based on the users current city. All ads based on the current user city should be on top and other cities ads should be after this. What is the option t…

[Previous page](https://discuss.elastic.co/latest.md?page=705)

[Next page](https://discuss.elastic.co/latest.md?page=707)
