# Latest

**URL:** https://discuss.elastic.co/latest.md?page=711

[Latest](https://discuss.elastic.co/latest.md) · [Categories](https://discuss.elastic.co/categories.md) · [Tags](https://discuss.elastic.co/tags.md)

**Page:** 712

---

## [Packetbeat Alerts](https://discuss.elastic.co/t/packetbeat-alerts/329841)

<div class="topic-metadata">

**Author:** [@Joel\_Goncalves](https://discuss.elastic.co/u/Joel_Goncalves)\
**Replies:** 1\
**Last updated:** [April 14, 2023, 4:27pm UTC](https://discuss.elastic.co/t/packetbeat-alerts/329841 "2023-04-14T16:27:46Z")

</div>

I have elasticsearch, kibana and packetbeat running and I want to get alerts whenever there is abnormal activity with packetbeat information. How do I do it? My elasticsearch, kibana and packetbeat are running on-premesi…

---

## [Edge n-gram search for terms with optional spaces](https://discuss.elastic.co/t/edge-n-gram-search-for-terms-with-optional-spaces/330018)

<div class="topic-metadata">

**Author:** [@kedomingo](https://discuss.elastic.co/u/kedomingo)\
**Replies:** 3\
**Last updated:** [April 14, 2023, 4:08pm UTC](https://discuss.elastic.co/t/edge-n-gram-search-for-terms-with-optional-spaces/330018 "2023-04-14T16:08:31Z")

</div>

Short version: I have "Pentium 3" and "Pentium4", in the index. I want to be able to search "Pentium 4" and get the record for "Pentium4". I want to be able to search "Pentium3" and get the record for "Pentium 3" I want…

---

## [Alternative to lookup datatype?](https://discuss.elastic.co/t/alternative-to-lookup-datatype/329836)

<div class="topic-metadata">

**Author:** [@captainzura195](https://discuss.elastic.co/u/captainzura195)\
**Replies:** 3\
**Last updated:** [April 14, 2023, 3:53pm UTC](https://discuss.elastic.co/t/alternative-to-lookup-datatype/329836 "2023-04-14T15:53:51Z")

</div>

I wanted to populate a description field using its corresponding key, code, and another index having a key, lookup\_code, column, and a corresponding description column but without the lookup datatype I am finding it hard…

---

## [Rollup - date histogram issues](https://discuss.elastic.co/t/rollup-date-histogram-issues/328509)

<div class="topic-metadata">

**Author:** [@JeroenK](https://discuss.elastic.co/u/JeroenK)\
**Replies:** 5\
**Last updated:** [April 14, 2023, 3:47pm UTC](https://discuss.elastic.co/t/rollup-date-histogram-issues/328509 "2023-04-14T15:47:42Z")

</div>

I have a rollup job with the following settings: "groups": { "date\_histogram": { "field": "timestamp", "time\_zone": "Europe/Stockholm", "calendar\_interval"…

---

## [Configure Plugin through Cluster Settings API - Listen for updates](https://discuss.elastic.co/t/configure-plugin-through-cluster-settings-api-listen-for-updates/329946)

<div class="topic-metadata">

**Author:** [@smillies](https://discuss.elastic.co/u/smillies)\
**Replies:** 5\
**Last updated:** [April 14, 2023, 3:32pm UTC](https://discuss.elastic.co/t/configure-plugin-through-cluster-settings-api-listen-for-updates/329946 "2023-04-14T15:32:05Z")

</div>

Hello there, I am writing a plugin and would like to configure it through the cluster settings API. I have overwritten getSettings, and so far so good. I can also update my dynamic settings through the cluster settings…

---

## [Restrict the Number of Unique term to be indexed for a Document](https://discuss.elastic.co/t/restrict-the-number-of-unique-term-to-be-indexed-for-a-document/329060)

<div class="topic-metadata">

**Author:** [@siddhartha\_c](https://discuss.elastic.co/u/siddhartha_c)\
**Replies:** 6\
**Last updated:** [April 14, 2023, 3:15pm UTC](https://discuss.elastic.co/t/restrict-the-number-of-unique-term-to-be-indexed-for-a-document/329060 "2023-04-14T15:15:10Z")

</div>

Hi , I have a requirement wherein I need to restrict the number of unique terms to Index for any Document to 1000. Any unique terms beyond 1000 for a particular document should be ignored and not Index during Indexing. I…

---

## [External URLs not enabled for Vega on Elastic Cloud - Review](https://discuss.elastic.co/t/external-urls-not-enabled-for-vega-on-elastic-cloud-review/329435)

<div class="topic-metadata">

**Author:** [@victorhmorales](https://discuss.elastic.co/u/victorhmorales)\
**Replies:** 4\
**Last updated:** [April 14, 2023, 3:07pm UTC](https://discuss.elastic.co/t/external-urls-not-enabled-for-vega-on-elastic-cloud-review/329435 "2023-04-14T15:07:20Z")

</div>

Hello there, As clarified in previous posts (2018-2020), redirection to external URLs is not enabled for Vega charts on Elastic Cloud for security reasons (vega.enableExternalUrls). I would like to check if there is an…

---

## [How do you add different services to APM Service Groups?](https://discuss.elastic.co/t/how-do-you-add-different-services-to-apm-service-groups/330005)

<div class="topic-metadata">

**Author:** [@zx8086](https://discuss.elastic.co/u/zx8086)\
**Replies:** 3\
**Last updated:** [April 14, 2023, 2:56pm UTC](https://discuss.elastic.co/t/how-do-you-add-different-services-to-apm-service-groups/330005 "2023-04-14T14:56:35Z")

</div>

How do you add different services to APM Service Groups when they dont have matching terms in the naming convention for the query ? Bit pointless when you cant select the services and that they all need to be the result…

---

## [Generate node certificate](https://discuss.elastic.co/t/generate-node-certificate/329951)

<div class="topic-metadata">

**Author:** [@elasticforme](https://discuss.elastic.co/u/elasticforme)\
**Replies:** 4\
**Last updated:** [April 14, 2023, 2:51pm UTC](https://discuss.elastic.co/t/generate-node-certificate/329951 "2023-04-14T14:51:02Z")

</div>

What am I doing wrong? missing some option, parameter? I have my cluster setup with certificate and working fine with following config on all nodes. it was created using /usr/share/elasticsearch/bin/elasticsearch-cert…

---

## [Filebeat Suricata Module "module suricata is configured but has no enabled filesets"](https://discuss.elastic.co/t/filebeat-suricata-module-module-suricata-is-configured-but-has-no-enabled-filesets/329954)

<div class="topic-metadata">

**Author:** [@Aaron\_C\_de\_Bruyn](https://discuss.elastic.co/u/Aaron_C_de_Bruyn)\
**Replies:** 4\
**Last updated:** [April 14, 2023, 2:44pm UTC](https://discuss.elastic.co/t/filebeat-suricata-module-module-suricata-is-configured-but-has-no-enabled-filesets/329954 "2023-04-14T14:44:50Z")

</div>

I'm running filebeat 8.6.2. I initially had it grabbing /var/log/remote.log and it worked fine. Then I enabled the suricata module and set the configuration to this (excluding the output.elasticsearch section): filebe…

---

## [Error when importing Postgres 12 and 15 queries](https://discuss.elastic.co/t/error-when-importing-postgres-12-and-15-queries/330021)

<div class="topic-metadata">

**Author:** [@\_Leonardo\_Moerschber](https://discuss.elastic.co/u/_Leonardo_Moerschber)\
**Replies:** 0\
**Last updated:** [April 14, 2023, 2:04pm UTC](https://discuss.elastic.co/t/error-when-importing-postgres-12-and-15-queries/330021 "2023-04-14T14:04:24Z")

</div>

My environment is for testing: Elasticsearch 8.7 + fleetserver I'm trying to collect queries from Postgres version 12 and version 15 through elastic-agent. I'm not able to collect them through the csv log. Here are th…

---

## [Cannot Retrieve Search Results](https://discuss.elastic.co/t/cannot-retrieve-search-results/328711)

<div class="topic-metadata">

**Author:** [@alaine](https://discuss.elastic.co/u/alaine)\
**Replies:** 3\
**Last updated:** [April 14, 2023, 1:56pm UTC](https://discuss.elastic.co/t/cannot-retrieve-search-results/328711 "2023-04-14T13:56:52Z")

</div>

Hello, I have been getting an error message in discover on and off when I run a number of different queries: Cannot Retrieve Search Results Then w/in the text box there is a base64 encoded string. When I decode the …

---

## [Filebeat (Zeek and Suricata) output to Logstash suddenly broke](https://discuss.elastic.co/t/filebeat-zeek-and-suricata-output-to-logstash-suddenly-broke/329909)

<div class="topic-metadata">

**Author:** [@alaine](https://discuss.elastic.co/u/alaine)\
**Replies:** 1\
**Last updated:** [April 14, 2023, 1:40pm UTC](https://discuss.elastic.co/t/filebeat-zeek-and-suricata-output-to-logstash-suddenly-broke/329909 "2023-04-14T13:40:17Z")

</div>

Hello, I am sending filebeat data from a network sensor that is running Zeek and Suricata to a logstash server. This server has been sending logs successfully w/o issue for over 6 months. This morning something happened…

---

## [How do you pass custom environment variable on Amazon Elastic Beanstalk (AWS EBS)?](https://discuss.elastic.co/t/how-do-you-pass-custom-environment-variable-on-amazon-elastic-beanstalk-aws-ebs/329972)

<div class="topic-metadata">

**Author:** [@karthik\_kumar](https://discuss.elastic.co/u/karthik_kumar)\
**Replies:** 1\
**Last updated:** [April 14, 2023, 1:38pm UTC](https://discuss.elastic.co/t/how-do-you-pass-custom-environment-variable-on-amazon-elastic-beanstalk-aws-ebs/329972 "2023-04-14T13:38:40Z")

</div>

The Amazon Elastic Beanstalk blurb says: Elastic Beanstalk lets you "open the hood" and retain full control ... even pass environment variables through the Elastic Beanstalk console. How to pass other environment var…

---

## [Is possible to use Filebeat o365 plugin on "offline" data](https://discuss.elastic.co/t/is-possible-to-use-filebeat-o365-plugin-on-offline-data/329998)

<div class="topic-metadata">

**Author:** [@Jirka\_Liska](https://discuss.elastic.co/u/Jirka_Liska)\
**Replies:** 1\
**Last updated:** [April 14, 2023, 1:25pm UTC](https://discuss.elastic.co/t/is-possible-to-use-filebeat-o365-plugin-on-offline-data/329998 "2023-04-14T13:25:14Z")

</div>

Hello community! I have recently discovered o365 module for Filebeat (Office 365 module | Filebeat Reference \[8.7\] | Elastic). My question is: is it possible to use it for offline data? I'm interested to have it since…

---

## [Winlogbeat not pushing logs to elastic](https://discuss.elastic.co/t/winlogbeat-not-pushing-logs-to-elastic/330014)

<div class="topic-metadata">

**Author:** [@Ben\_C8400](https://discuss.elastic.co/u/Ben_C8400)\
**Replies:** 0\
**Last updated:** [April 14, 2023, 1:20pm UTC](https://discuss.elastic.co/t/winlogbeat-not-pushing-logs-to-elastic/330014 "2023-04-14T13:20:16Z")

</div>

Hi all, I've been trying to setup winlogbeat, but have had no success so far. After running the script i get following result, not giving any errors. On Kibana it actually shows the index template, and the dashboards …

---

## [Azure snapshot issue - getting: blob\_storage\_exception","reason":"Status code 400, "﻿\\nBlobTypeNotSupportedBlock blobs are not supported](https://discuss.elastic.co/t/azure-snapshot-issue-getting-blob-storage-exception-reason-status-code-400-nblobtypenotsupportedblock-blobs-are-not-supported/328690)

<div class="topic-metadata">

**Author:** [@Mariusko82](https://discuss.elastic.co/u/Mariusko82)\
**Replies:** 1\
**Last updated:** [April 14, 2023, 12:43pm UTC](https://discuss.elastic.co/t/azure-snapshot-issue-getting-blob-storage-exception-reason-status-code-400-nblobtypenotsupportedblock-blobs-are-not-supported/328690 "2023-04-14T12:43:01Z")

</div>

Elasticsearch Version Version: 8.2.3, Build: default/docker/9905bfb62a3f0b044948376b4f607f70a8a151b4/2022-06-08T22:21:36.455508792Z, JVM: 18.0.1.1 Installed Plugins No response Java Version bundled OS Version Linux el…

---

## [Elasticsearch is not allowing me to upload news category dataset](https://discuss.elastic.co/t/elasticsearch-is-not-allowing-me-to-upload-news-category-dataset/330001)

<div class="topic-metadata">

**Author:** [@Arvind\_Singharpuria](https://discuss.elastic.co/u/Arvind_Singharpuria)\
**Replies:** 2\
**Last updated:** [April 14, 2023, 12:18pm UTC](https://discuss.elastic.co/t/elasticsearch-is-not-allowing-me-to-upload-news-category-dataset/330001 "2023-04-14T12:18:45Z")

</div>

While uploading the dataset, it is showing me this error

---

## [Negative boosting via elastic cloud admin panel](https://discuss.elastic.co/t/negative-boosting-via-elastic-cloud-admin-panel/329999)

<div class="topic-metadata">

**Author:** [@oleksiiorel](https://discuss.elastic.co/u/oleksiiorel)\
**Replies:** 0\
**Last updated:** [April 14, 2023, 10:39am UTC](https://discuss.elastic.co/t/negative-boosting-via-elastic-cloud-admin-panel/329999 "2023-04-14T10:39:21Z")

</div>

Hi guys! Is it possible to set negative boosting for a specific field via elastic cloud admin panel ( App search). I found an option to set only positive boosting. I know how to do it with API, but is there any way to do…

---

## [Search with cluster wildcard returns data from non-matching indices](https://discuss.elastic.co/t/search-with-cluster-wildcard-returns-data-from-non-matching-indices/329990)

<div class="topic-metadata">

**Author:** [@VincentR](https://discuss.elastic.co/u/VincentR)\
**Replies:** 0\
**Last updated:** [April 14, 2023, 9:41am UTC](https://discuss.elastic.co/t/search-with-cluster-wildcard-returns-data-from-non-matching-indices/329990 "2023-04-14T09:41:24Z")

</div>

Hello, I am currently migrating from Elastic Search 7.17.8 to 8.6.2 and I am observing a very strange change of behaviour in the search API. Using the search REST api, when the index pattern (target) contains both a …

---

## [Pipelined bucket aggregation](https://discuss.elastic.co/t/pipelined-bucket-aggregation/329989)

<div class="topic-metadata">

**Author:** [@HansPeterSloot](https://discuss.elastic.co/u/HansPeterSloot)\
**Replies:** 0\
**Last updated:** [April 14, 2023, 9:38am UTC](https://discuss.elastic.co/t/pipelined-bucket-aggregation/329989 "2023-04-14T09:38:56Z")

</div>

Hello I am ingesting logs from different servers into elastic and want to be alerted when a server suddenly stops sending data. For this I have come up with this aggregation: GET .xxxt\*/\_search?size=0 { "query": { …

---

## [Elastic forwarder cloudwatch log group wildcard id not working](https://discuss.elastic.co/t/elastic-forwarder-cloudwatch-log-group-wildcard-id-not-working/329987)

<div class="topic-metadata">

**Author:** [@dchocoboo](https://discuss.elastic.co/u/dchocoboo)\
**Replies:** 0\
**Last updated:** [April 14, 2023, 9:35am UTC](https://discuss.elastic.co/t/elastic-forwarder-cloudwatch-log-group-wildcard-id-not-working/329987 "2023-04-14T09:35:01Z")

</div>

i'm trying to simplify my config.yaml based on this tutorial currently if i put this in my config - type: "cloudwatch-logs" id: "arn:aws:logs:ap-southeast-1:xxxxxxxxxx:log-group:\*:\*" outputs: - type: "el…

---

## [Is it possible to change the logging path for Elastic Agent?](https://discuss.elastic.co/t/is-it-possible-to-change-the-logging-path-for-elastic-agent/329983)

<div class="topic-metadata">

**Author:** [@lengoyvaerts](https://discuss.elastic.co/u/lengoyvaerts)\
**Replies:** 0\
**Last updated:** [April 14, 2023, 8:59am UTC](https://discuss.elastic.co/t/is-it-possible-to-change-the-logging-path-for-elastic-agent/329983 "2023-04-14T08:59:43Z")

</div>

Hi community As per the topic's title, I'm trying to configure the logging path when installing the Elastic Agent. I'm using central fleet management and following the installation guidelines from the Kibana UI as descr…

---

## [Help with Nest Fluent DSL query](https://discuss.elastic.co/t/help-with-nest-fluent-dsl-query/329982)

<div class="topic-metadata">

**Author:** [@vdelcampo](https://discuss.elastic.co/u/vdelcampo)\
**Replies:** 0\
**Last updated:** [April 14, 2023, 8:08am UTC](https://discuss.elastic.co/t/help-with-nest-fluent-dsl-query/329982 "2023-04-14T08:08:07Z")

</div>

Hi! I need help with below query. I´m using .NET Nest library, and I need to convert it to Fluent DSL: GET md-tpmiddle-f5-\*/\_count { "query": { "bool": { "filter": \[ { "bool": { …

---

## [How long does it take to clone an index with 2TB of data?](https://discuss.elastic.co/t/how-long-does-it-take-to-clone-an-index-with-2tb-of-data/329969)

<div class="topic-metadata">

**Author:** [@dilshadpaleri](https://discuss.elastic.co/u/dilshadpaleri)\
**Replies:** 2\
**Last updated:** [April 14, 2023, 7:45am UTC](https://discuss.elastic.co/t/how-long-does-it-take-to-clone-an-index-with-2tb-of-data/329969 "2023-04-14T07:45:41Z")

</div>

Hi, I want to create an identical copy of an existing index with about 2 TB of data, Clone API seems to be the best option here. To clone an index, the index must be marked as read-only, so it will block my application …

---

## [How to use elastic in wiki js](https://discuss.elastic.co/t/how-to-use-elastic-in-wiki-js/329978)

<div class="topic-metadata">

**Author:** [@Kwa](https://discuss.elastic.co/u/Kwa)\
**Replies:** 0\
**Last updated:** [April 14, 2023, 7:13am UTC](https://discuss.elastic.co/t/how-to-use-elastic-in-wiki-js/329978 "2023-04-14T07:13:00Z")

</div>

Hi everyone, i have elasticsearch installed locally in a VM with version 7.17.8. By calling http://localhost:9200 in the browser i get the information like cluster\_name, cluster\_uuid etc. In elasticsearch.yml i have en…

---

## [Elastic 8 not search with hyphen](https://discuss.elastic.co/t/elastic-8-not-search-with-hyphen/327824)

<div class="topic-metadata">

**Author:** [@suresh\_chaudhari](https://discuss.elastic.co/u/suresh_chaudhari)\
**Replies:** 6\
**Last updated:** [April 14, 2023, 6:50am UTC](https://discuss.elastic.co/t/elastic-8-not-search-with-hyphen/327824 "2023-04-14T06:50:40Z")

</div>

I have documents with id fields {id:domain-837}{id:domain-838} these are automatically stored using mapping with data type keyword. "id": { "type": "text", "fields": { "keyword": { "ignore\_above": 256, "type": "keywor…

---

## [APM agent setup issue](https://discuss.elastic.co/t/apm-agent-setup-issue/329975)

<div class="topic-metadata">

**Author:** [@hairmemez](https://discuss.elastic.co/u/hairmemez)\
**Replies:** 0\
**Last updated:** [April 14, 2023, 6:41am UTC](https://discuss.elastic.co/t/apm-agent-setup-issue/329975 "2023-04-14T06:41:05Z")

</div>

Hi Team, I have successfully configured APM-server and Agent status says "Data successfully received from 1 or more agents" but when I launch APM there are no records. I have tried running query in dev tools {scre…

---

## [After creating the snapshot, getting snapshot\_missing\_exception and no\_such\_file\_exception](https://discuss.elastic.co/t/after-creating-the-snapshot-getting-snapshot-missing-exception-and-no-such-file-exception/329970)

<div class="topic-metadata">

**Author:** [@Ramesh\_Perumal](https://discuss.elastic.co/u/Ramesh_Perumal)\
**Replies:** 1\
**Last updated:** [April 14, 2023, 6:27am UTC](https://discuss.elastic.co/t/after-creating-the-snapshot-getting-snapshot-missing-exception-and-no-such-file-exception/329970 "2023-04-14T06:27:48Z")

</div>

Hi All, I have created the repository to create snapshot with the following steps in two node (machine) cluster: curl -XPUT "https://:9200$HOSTNAME/\_snapshot/test13?verify=false" -H 'Content-Type: application/json' -…

---

## [Logstash ssl configuration for workspace search](https://discuss.elastic.co/t/logstash-ssl-configuration-for-workspace-search/329739)

<div class="topic-metadata">

**Author:** [@Gunbay\_Park](https://discuss.elastic.co/u/Gunbay_Park)\
**Replies:** 6\
**Last updated:** [April 14, 2023, 1:38am UTC](https://discuss.elastic.co/t/logstash-ssl-configuration-for-workspace-search/329739 "2023-04-14T01:38:53Z")

</div>

hi, I set kibana and workplace search ssl and loaded index to workplace search by logstash. Then error message occurred about ssl certification. elasticsearch has phrase like below, but could't find about workplace s…

[Previous page](https://discuss.elastic.co/latest.md?page=710)

[Next page](https://discuss.elastic.co/latest.md?page=712)
