# Latest

**URL:** https://discuss.elastic.co/latest.md?page=709

[Latest](https://discuss.elastic.co/latest.md) · [Categories](https://discuss.elastic.co/categories.md) · [Tags](https://discuss.elastic.co/tags.md)

**Page:** 710

---

## [Kafka-Elasticsearch Logstash Configuration Error](https://discuss.elastic.co/t/kafka-elasticsearch-logstash-configuration-error/330130)

<div class="topic-metadata">

**Author:** [@Mustafa\_AYDOGDU](https://discuss.elastic.co/u/Mustafa_AYDOGDU)\
**Replies:** 1\
**Last updated:** [April 17, 2023, 2:52pm UTC](https://discuss.elastic.co/t/kafka-elasticsearch-logstash-configuration-error/330130 "2023-04-17T14:52:20Z")

</div>

I have a logstash pipeline which gets data from kafka and sends it to elasticsearch. However, in elasticsearch, data is not represented correctly. In this data I want it to be just field:value. But it is field:\[value,fi…

---

## [How to display the last date on a grouping set](https://discuss.elastic.co/t/how-to-display-the-last-date-on-a-grouping-set/329854)

<div class="topic-metadata">

**Author:** [@FTOR](https://discuss.elastic.co/u/FTOR)\
**Replies:** 2\
**Last updated:** [April 17, 2023, 2:45pm UTC](https://discuss.elastic.co/t/how-to-display-the-last-date-on-a-grouping-set/329854 "2023-04-17T14:45:02Z")

</div>

Hello, I am working on a dashboard, and I would like to show the last date on a grouping set. I take the kibana\_sample\_data\_ecommerce as example. Attachedn an example of row part. I would like to group by product\_id…

---

## [Help pattern for multiline logs](https://discuss.elastic.co/t/help-pattern-for-multiline-logs/330134)

<div class="topic-metadata">

**Author:** [@JackieLaFrite](https://discuss.elastic.co/u/JackieLaFrite)\
**Replies:** 4\
**Last updated:** [April 17, 2023, 2:41pm UTC](https://discuss.elastic.co/t/help-pattern-for-multiline-logs/330134 "2023-04-17T14:41:54Z")

</div>

What pattern should I use to retrieve correctly multi-lines logs ? Normally I use : file { path =\> "/var/log/appslogs/\*\*/\*.log" start\_position =\> "beginning" sincedb\_path =\> "/dev/null" codec =\> multili…

---

## [Use reciprocal ranking fusion to combine the results of two queries](https://discuss.elastic.co/t/use-reciprocal-ranking-fusion-to-combine-the-results-of-two-queries/329614)

<div class="topic-metadata">

**Author:** [@flando](https://discuss.elastic.co/u/flando)\
**Replies:** 1\
**Last updated:** [April 17, 2023, 2:32pm UTC](https://discuss.elastic.co/t/use-reciprocal-ranking-fusion-to-combine-the-results-of-two-queries/329614 "2023-04-17T14:32:21Z")

</div>

Hi everyone, I'm trying to use reciprocal ranking fusion (RRF) to combine the results of two query performed with the following code: GET /books\_index/\_search { "query": { "bool": { "should": \[ { …

---

## [Trying to update a document but keep getting validation or parse errors](https://discuss.elastic.co/t/trying-to-update-a-document-but-keep-getting-validation-or-parse-errors/330117)

<div class="topic-metadata">

**Author:** [@bizmate](https://discuss.elastic.co/u/bizmate)\
**Replies:** 9\
**Last updated:** [April 17, 2023, 2:25pm UTC](https://discuss.elastic.co/t/trying-to-update-a-document-but-keep-getting-validation-or-parse-errors/330117 "2023-04-17T14:25:57Z")

</div>

I have a set of documents created by filebeat -\> logstash pushed to Elasticsearch and they look like this... { "\_index": "sub\_myapp\_prod-filebeat-7.17.7-2023.04", "\_type": "\_doc", "\_id": "IPLahocBBfkGcvN800\_A", …

---

## [Logstash docker cannot log into elasticsearch docker](https://discuss.elastic.co/t/logstash-docker-cannot-log-into-elasticsearch-docker/328336)

<div class="topic-metadata">

**Author:** [@kpankhurst](https://discuss.elastic.co/u/kpankhurst)\
**Replies:** 10\
**Last updated:** [April 17, 2023, 2:25pm UTC](https://discuss.elastic.co/t/logstash-docker-cannot-log-into-elasticsearch-docker/328336 "2023-04-17T14:25:01Z")

</div>

I have 2 dockers set up as follows: elasticsearch: image: docker.elastic.co/elasticsearch/elasticsearch:8.6.0 volumes: - ./config/elasticsearch/esdata:/usr/share/elasticsearch/data - ./config/elast…

---

## [Perform aggregation on a modified term](https://discuss.elastic.co/t/perform-aggregation-on-a-modified-term/330141)

<div class="topic-metadata">

**Author:** [@manropinxu](https://discuss.elastic.co/u/manropinxu)\
**Replies:** 0\
**Last updated:** [April 17, 2023, 2:11pm UTC](https://discuss.elastic.co/t/perform-aggregation-on-a-modified-term/330141 "2023-04-17T14:11:29Z")

</div>

I'd like to perform an aggregation grouping by a modified version of amessage field. I have lots of messages like invalid x with uuid=1e659cfc-a375-4a8a-88f5-467419fdf87d invalid x with uuid=49c4742e-0368-49a2-aab4-7f…

---

## [Problems Accessing Kibana Lab](https://discuss.elastic.co/t/problems-accessing-kibana-lab/329545)

<div class="topic-metadata">

**Author:** [@ltan](https://discuss.elastic.co/u/ltan)\
**Replies:** 2\
**Last updated:** [April 17, 2023, 1:31pm UTC](https://discuss.elastic.co/t/problems-accessing-kibana-lab/329545 "2023-04-17T13:31:01Z")

</div>

Hi, I am currently enrolled in the Data Analysis with Kibana on-demand course. I have been trying to use the lab environment to use Kibana. But I have been getting multiple issues such as 'kibana server is not ready ye…

---

## [CVE-2022-1471 is not listed in Security Issues site](https://discuss.elastic.co/t/cve-2022-1471-is-not-listed-in-security-issues-site/330110)

<div class="topic-metadata">

**Author:** [@Mike\_Joseph](https://discuss.elastic.co/u/Mike_Joseph)\
**Replies:** 1\
**Last updated:** [April 17, 2023, 1:24pm UTC](https://discuss.elastic.co/t/cve-2022-1471-is-not-listed-in-security-issues-site/330110 "2023-04-17T13:24:13Z")

</div>

Continuing the discussion from Snakeyaml vulnerability (CVE-2022-1471) on latest ES version: @DavidTurner Forwarded the topic to Security issues but it is still not addressed in the site.

---

## [How to enable CORS for all possible connections?](https://discuss.elastic.co/t/how-to-enable-cors-for-all-possible-connections/330135)

<div class="topic-metadata">

**Author:** [@Eduard\_mart](https://discuss.elastic.co/u/Eduard_mart)\
**Replies:** 0\
**Last updated:** [April 17, 2023, 1:12pm UTC](https://discuss.elastic.co/t/how-to-enable-cors-for-all-possible-connections/330135 "2023-04-17T13:12:12Z")

</div>

How to enable CORS for all possible connections?

---

## [Failed to start Elasticsearch](https://discuss.elastic.co/t/failed-to-start-elasticsearch/330061)

<div class="topic-metadata">

**Author:** [@Hugo\_Demont](https://discuss.elastic.co/u/Hugo_Demont)\
**Replies:** 1\
**Last updated:** [April 17, 2023, 1:03pm UTC](https://discuss.elastic.co/t/failed-to-start-elasticsearch/330061 "2023-04-17T13:03:10Z")

</div>

Hello ! I'm try to run elasticsearch on my linux computer to download Magento 2 when I try sudo systemctl start elasticsearch I get an error and I dont know how to solve it :confused: Error : \`avril 15 10:34:55 demon…

---

## [Clarification on end of maintenance of elastic search 8.x](https://discuss.elastic.co/t/clarification-on-end-of-maintenance-of-elastic-search-8-x/330129)

<div class="topic-metadata">

**Author:** [@mohammed\_rizwan](https://discuss.elastic.co/u/mohammed_rizwan)\
**Replies:** 1\
**Last updated:** [April 17, 2023, 12:55pm UTC](https://discuss.elastic.co/t/clarification-on-end-of-maintenance-of-elastic-search-8-x/330129 "2023-04-17T12:55:01Z")

</div>

Hi team, From the Elasticsearch link Elastic Product End of Life Dates | Elastic, the Elasticsearch (8.x) end of maintenance is mentioned as "The later of 2024-08-10 or 6 months after the release date of 9.0 (TBD)". Is…

---

## [Can't sort by column/field in Kabana](https://discuss.elastic.co/t/cant-sort-by-column-field-in-kabana/329929)

<div class="topic-metadata">

**Author:** [@JackieLaFrite](https://discuss.elastic.co/u/JackieLaFrite)\
**Replies:** 4\
**Last updated:** [April 17, 2023, 8:31am UTC](https://discuss.elastic.co/t/cant-sort-by-column-field-in-kabana/329929 "2023-04-17T08:31:29Z")

</div>

Hello, I'm currently implementing ELK on my environment to retrieve the logs and I got a problem. In the discover tab, I can't sort a column. I can only sort by the @Timestamp. I would like to be able to sort by the…

---

## [RUM js agent - Failed transaction rate is "N/A" for different transaction types](https://discuss.elastic.co/t/rum-js-agent-failed-transaction-rate-is-n-a-for-different-transaction-types/329318)

<div class="topic-metadata">

**Author:** [@dacothe](https://discuss.elastic.co/u/dacothe)\
**Replies:** 2\
**Last updated:** [April 17, 2023, 12:09pm UTC](https://discuss.elastic.co/t/rum-js-agent-failed-transaction-rate-is-n-a-for-different-transaction-types/329318 "2023-04-17T12:09:20Z")

</div>

Kibana version: 7.16.3 Elasticsearch version: 7.16.3 APM Server version: 7.16.3 APM Agent language and version: @elastic/apm-rum:5.12 Browser version: Chrome 110.0.5481.100 Hi all, We have recently started using th…

---

## [Connect: connection refused](https://discuss.elastic.co/t/connect-connection-refused/330123)

<div class="topic-metadata">

**Author:** [@Kay\_Khan](https://discuss.elastic.co/u/Kay_Khan)\
**Replies:** 0\
**Last updated:** [April 17, 2023, 11:55am UTC](https://discuss.elastic.co/t/connect-connection-refused/330123 "2023-04-17T11:55:20Z")

</div>

I have a fresh elasticsearch cluster deployed on kubernetes. I have deployed metricbeat 8.7.0 and i get the following error in the logs of each metricbeat pod. Does anyone know how to resolve this issue? {"log.level":…

---

## [Recommended RAM/CPU size for hot data nodes in gcp](https://discuss.elastic.co/t/recommended-ram-cpu-size-for-hot-data-nodes-in-gcp/330119)

<div class="topic-metadata">

**Author:** [@alok.nashikkar](https://discuss.elastic.co/u/alok.nashikkar)\
**Replies:** 1\
**Last updated:** [April 17, 2023, 11:16am UTC](https://discuss.elastic.co/t/recommended-ram-cpu-size-for-hot-data-nodes-in-gcp/330119 "2023-04-17T11:16:30Z")

</div>

Hello, I am exploring recommendations for infra sizing for Elasticsearch hot data nodes in GCP with recommendations for CPU and RAM for probably 3 TB SSD with machine types ex n2d/e2 or some other in similar performance…

---

## [Logstash throws java.lang.OutOfMemoryError: Java heap space no matter the heap size](https://discuss.elastic.co/t/logstash-throws-java-lang-outofmemoryerror-java-heap-space-no-matter-the-heap-size/330089)

<div class="topic-metadata">

**Author:** [@ste1](https://discuss.elastic.co/u/ste1)\
**Replies:** 6\
**Last updated:** [April 17, 2023, 10:57am UTC](https://discuss.elastic.co/t/logstash-throws-java-lang-outofmemoryerror-java-heap-space-no-matter-the-heap-size/330089 "2023-04-17T10:57:36Z")

</div>

Im attempting to parse a huge (few million lines) csv file with logstash and output it to elasticsearch. \[FATAL\] 2023-04-16 19:00:19.011 \[LogStash::Runner\] Logstash - java.lang.OutOfMemoryError: Java heap space …

---

## [Elasticsearch Transform API - Trying to Script a Moving Average](https://discuss.elastic.co/t/elasticsearch-transform-api-trying-to-script-a-moving-average/330115)

<div class="topic-metadata">

**Author:** [@Silver137](https://discuss.elastic.co/u/Silver137)\
**Replies:** 0\
**Last updated:** [April 17, 2023, 10:43am UTC](https://discuss.elastic.co/t/elasticsearch-transform-api-trying-to-script-a-moving-average/330115 "2023-04-17T10:43:09Z")

</div>

My use case requieres keeping the moving average over hours withing a windows of the last 12 hours, every time the transofrm is executed. It's possible to use the "pivot" "group by" to program a transform that keeps tra…

---

## [Is it possible to have a variable scripted field which changes based on Kibana Dashboard selection?](https://discuss.elastic.co/t/is-it-possible-to-have-a-variable-scripted-field-which-changes-based-on-kibana-dashboard-selection/329908)

<div class="topic-metadata">

**Author:** [@stramzik](https://discuss.elastic.co/u/stramzik)\
**Replies:** 2\
**Last updated:** [April 17, 2023, 10:15am UTC](https://discuss.elastic.co/t/is-it-possible-to-have-a-variable-scripted-field-which-changes-based-on-kibana-dashboard-selection/329908 "2023-04-17T10:15:46Z")

</div>

Hi, Is it possible to have a variable scripted field which changes based on Kibana Dashboard selection? I want a scripted field which changes to true of false based on kibana lens selection on the dashboard.

---

## [Elastic.Apm.StackExchange.Redis for IDistributedCache?](https://discuss.elastic.co/t/elastic-apm-stackexchange-redis-for-idistributedcache/328581)

<div class="topic-metadata">

**Author:** [@ThorstenKraus](https://discuss.elastic.co/u/ThorstenKraus)\
**Replies:** 2\
**Last updated:** [April 17, 2023, 9:42am UTC](https://discuss.elastic.co/t/elastic-apm-stackexchange-redis-for-idistributedcache/328581 "2023-04-17T09:42:04Z")

</div>

Hello, in our project, we use the Microsoft.Extensions.Caching.Distributed package for configuring the Redis cache like shown in this code snippet: services.AddStackExchangeRedisCache(options =\> { options.Configurati…

---

## [Block installation of bundled Npcap via Network Packet Capture integration?](https://discuss.elastic.co/t/block-installation-of-bundled-npcap-via-network-packet-capture-integration/329748)

<div class="topic-metadata">

**Author:** [@jaegerschnitzel](https://discuss.elastic.co/u/jaegerschnitzel)\
**Replies:** 2\
**Last updated:** [April 17, 2023, 9:01am UTC](https://discuss.elastic.co/t/block-installation-of-bundled-npcap-via-network-packet-capture-integration/329748 "2023-04-17T09:01:28Z")

</div>

My old thread is closed so I'm creating a new one. We updated our Elastic Agent to v8.7.0 in order to use the new feature to block installation of the bundled Npcap library. Unfortunately this option is not available in…

---

## [Kibana helmchart throws error](https://discuss.elastic.co/t/kibana-helmchart-throws-error/330101)

<div class="topic-metadata">

**Author:** [@arun\_udaiyar](https://discuss.elastic.co/u/arun_udaiyar)\
**Replies:** 1\
**Last updated:** [April 17, 2023, 8:40am UTC](https://discuss.elastic.co/t/kibana-helmchart-throws-error/330101 "2023-04-17T08:40:19Z")

</div>

Hi Team, I have used helmchart to deploy the stack and i have created own self-signed using openssl as per the documentation. seems fine for master, data and client communication. root@N81111:/mnt/d/elasticsearch# kub…

---

## [Alerts in a Cluster](https://discuss.elastic.co/t/alerts-in-a-cluster/330003)

<div class="topic-metadata">

**Author:** [@Joel\_Goncalves1](https://discuss.elastic.co/u/Joel_Goncalves1)\
**Replies:** 2\
**Last updated:** [April 17, 2023, 8:27am UTC](https://discuss.elastic.co/t/alerts-in-a-cluster/330003 "2023-04-17T08:27:08Z")

</div>

Is it possible to create a cluster and each node configure rules and when an alert is heard in a node, this alert is replicated to a master node? But I didn't want alerts from other nodes or master's alerts to be replica…

---

## [Multiple lines Canva Kibana](https://discuss.elastic.co/t/multiple-lines-canva-kibana/329926)

<div class="topic-metadata">

**Author:** [@Julie\_Gils](https://discuss.elastic.co/u/Julie_Gils)\
**Replies:** 2\
**Last updated:** [April 17, 2023, 7:45am UTC](https://discuss.elastic.co/t/multiple-lines-canva-kibana/329926 "2023-04-17T07:45:33Z")

</div>

Hi, I have several data that are calculated like this: I just wanna have the number of process by step. Data used (with aggregation) look like : And I want the chart looks like : but with canva line chart. At …

---

## [Elastic cloud with Okta SSO](https://discuss.elastic.co/t/elastic-cloud-with-okta-sso/329561)

<div class="topic-metadata">

**Author:** [@joshuskarki](https://discuss.elastic.co/u/joshuskarki)\
**Replies:** 2\
**Last updated:** [April 17, 2023, 5:46am UTC](https://discuss.elastic.co/t/elastic-cloud-with-okta-sso/329561 "2023-04-17T05:46:12Z")

</div>

I am trying to get the Kibana with Okta SAML working, but after successfully signing in, I get {"statusCode":404,"error":"Not Found","message":"Not Found"} Has anybody come across this and know how to fix it?

---

## [Ece & openshift](https://discuss.elastic.co/t/ece-openshift/329895)

<div class="topic-metadata">

**Author:** [@steman-provinzial](https://discuss.elastic.co/u/steman-provinzial)\
**Replies:** 2\
**Last updated:** [April 17, 2023, 6:00am UTC](https://discuss.elastic.co/t/ece-openshift/329895 "2023-04-17T06:00:39Z")

</div>

Hi there, I am new to ece - just made a small test installation. I know there is a another flavour called eck. My question: Is there alreadey an ece running on / with openshift? Thank you and kind regards Stefano

---

## [Document size, weight and performance in an automatic mapping and improve it afterwards manually](https://discuss.elastic.co/t/document-size-weight-and-performance-in-an-automatic-mapping-and-improve-it-afterwards-manually/330085)

<div class="topic-metadata">

**Author:** [@martel](https://discuss.elastic.co/u/martel)\
**Replies:** 3\
**Last updated:** [April 17, 2023, 5:13am UTC](https://discuss.elastic.co/t/document-size-weight-and-performance-in-an-automatic-mapping-and-improve-it-afterwards-manually/330085 "2023-04-17T05:13:21Z")

</div>

Is it possible to know the weight of a document in terms of bytes, to know the impact index in terms of indexing? All this in order to better optimize, to know how to configure a mapping of fields in such and such a way…

---

## [Metricbeat Azure Module - unable to get metrices of MSSQL Database Account](https://discuss.elastic.co/t/metricbeat-azure-module-unable-to-get-metrices-of-mssql-database-account/330091)

<div class="topic-metadata">

**Author:** [@vin89](https://discuss.elastic.co/u/vin89)\
**Replies:** 0\
**Last updated:** [April 17, 2023, 3:09am UTC](https://discuss.elastic.co/t/metricbeat-azure-module-unable-to-get-metrices-of-mssql-database-account/330091 "2023-04-17T03:09:58Z")

</div>

Hi, We are trying to implement metricbeat for our Azure resources where we are using Azure Module provided by metricbeat itself. Here we are facing a challenge that we are not able to capture MSSQL database metrices fro…

---

## [Docker-compose issue with elasticsearch and kibana docker image](https://discuss.elastic.co/t/docker-compose-issue-with-elasticsearch-and-kibana-docker-image/330067)

<div class="topic-metadata">

**Author:** [@toki0709](https://discuss.elastic.co/u/toki0709)\
**Replies:** 3\
**Last updated:** [April 16, 2023, 3:49pm UTC](https://discuss.elastic.co/t/docker-compose-issue-with-elasticsearch-and-kibana-docker-image/330067 "2023-04-16T15:49:51Z")

</div>

I am trying to create a docker-compose file with the latest image version of Elasticsearch and Kibana. Even after mentioning the version name in docker-compose.yml, I am noticing that the image version is 7.11.1 for both…

---

## [Frequently occurring "should have been dropped, but couldn't as state is not finished"](https://discuss.elastic.co/t/frequently-occurring-should-have-been-dropped-but-couldnt-as-state-is-not-finished/330082)

<div class="topic-metadata">

**Author:** [@micmeow](https://discuss.elastic.co/u/micmeow)\
**Replies:** 1\
**Last updated:** [April 16, 2023, 8:32am UTC](https://discuss.elastic.co/t/frequently-occurring-should-have-been-dropped-but-couldnt-as-state-is-not-finished/330082 "2023-04-16T08:32:13Z")

</div>

Hello. If you know how fix that, lend me your wisdom. I use filebeat to transfer logs to Logstash to Opensearch. When I checked the filebeat log, I found that the same log file transfer errors were occurring frequently…

[Previous page](https://discuss.elastic.co/latest.md?page=708)

[Next page](https://discuss.elastic.co/latest.md?page=710)
