# Latest

**URL:** https://discuss.elastic.co/latest.md?page=712

[Latest](https://discuss.elastic.co/latest.md) · [Categories](https://discuss.elastic.co/categories.md) · [Tags](https://discuss.elastic.co/tags.md)

**Page:** 713

---

## [Filebeat Input X kafka topics](https://discuss.elastic.co/t/filebeat-input-x-kafka-topics/329950)

<div class="topic-metadata">

**Author:** [@luizsouzagarcia](https://discuss.elastic.co/u/luizsouzagarcia)\
**Replies:** 1\
**Last updated:** [April 13, 2023, 9:49pm UTC](https://discuss.elastic.co/t/filebeat-input-x-kafka-topics/329950 "2023-04-13T21:49:21Z")

</div>

Is it possible to consume all topics of a kafka cluster through filebeat input? ex: type: kafka hosts: - ${KAFKA\_BROKERCONNECT} topics: \["\*"\]. --------\> It doesn't work, I've tried several regex =/ group\_id: "kaf…

---

## [We're looking for community members to test Elastic Serverless!](https://discuss.elastic.co/t/were-looking-for-community-members-to-test-elastic-serverless/329952)

<div class="topic-metadata">

**Author:** [@Scotty\_Saunders](https://discuss.elastic.co/u/Scotty_Saunders)\
**Replies:** 0\
**Last updated:** [April 13, 2023, 9:42pm UTC](https://discuss.elastic.co/t/were-looking-for-community-members-to-test-elastic-serverless/329952 "2023-04-13T21:42:50Z")

</div>

Hey everyone :wave:, my name is Scotty Saunders - I’m a UX Researcher here at Elastic. I’m also part of a larger team helping design and build out a serverless/fully managed offering for Elastic solutions. Our UX researc…

---

## [From the time to time Elastic's docs.count value is updated by logstash. Is it normal?](https://discuss.elastic.co/t/from-the-time-to-time-elastics-docs-count-value-is-updated-by-logstash-is-it-normal/329875)

<div class="topic-metadata">

**Author:** [@german](https://discuss.elastic.co/u/german)\
**Replies:** 4\
**Last updated:** [April 13, 2023, 7:42pm UTC](https://discuss.elastic.co/t/from-the-time-to-time-elastics-docs-count-value-is-updated-by-logstash-is-it-normal/329875 "2023-04-13T19:42:41Z")

</div>

Hi everybody, I have a little question about elastic's docs.count as I have noticed that it's not updated constantly. For example: (Don't pay attention to credentials. It's only a lab test). The 3487 docs.count val…

---

## [Same synonyms in different synonym files](https://discuss.elastic.co/t/same-synonyms-in-different-synonym-files/329358)

<div class="topic-metadata">

**Author:** [@antoinelefloch](https://discuss.elastic.co/u/antoinelefloch)\
**Replies:** 4\
**Last updated:** [April 13, 2023, 6:26pm UTC](https://discuss.elastic.co/t/same-synonyms-in-different-synonym-files/329358 "2023-04-13T18:26:19Z")

</div>

Hello, it seems synonyms in 2nd file are not taken into account if already used in 1st file. In 1st file, I have: aaa,bbb In second file, I have: aaa,synaaa bbb,synbbb ccc,synccc When I do the \_analyze { "expl…

---

## [Kibana Visualization modify size](https://discuss.elastic.co/t/kibana-visualization-modify-size/327492)

<div class="topic-metadata">

**Author:** [@chandap](https://discuss.elastic.co/u/chandap)\
**Replies:** 2\
**Last updated:** [April 13, 2023, 6:11pm UTC](https://discuss.elastic.co/t/kibana-visualization-modify-size/327492 "2023-04-13T18:11:50Z")

</div>

When I create visualizations (line graph) in Kibana and try to generate a png to send in an email via a watcher, the image is way too large. Is there any way at all to resize the image or the visualization its self so t…

---

## [Logstash add subfield to elasticsearch index](https://discuss.elastic.co/t/logstash-add-subfield-to-elasticsearch-index/329870)

<div class="topic-metadata">

**Author:** [@Utibeabasi\_Umanah](https://discuss.elastic.co/u/Utibeabasi_Umanah)\
**Replies:** 3\
**Last updated:** [April 13, 2023, 5:59pm UTC](https://discuss.elastic.co/t/logstash-add-subfield-to-elasticsearch-index/329870 "2023-04-13T17:59:00Z")

</div>

Hi, i want to add a sub field called prefix to a text field called title using a logstash filter plugin. how do i go about this? i need this because the sub fields are required in app search. here is my logstash config s…

---

## [How to Reduce the Embedded Dashboard load time inside the angular iframe?](https://discuss.elastic.co/t/how-to-reduce-the-embedded-dashboard-load-time-inside-the-angular-iframe/329840)

<div class="topic-metadata">

**Author:** [@brusque.sowers](https://discuss.elastic.co/u/brusque.sowers)\
**Replies:** 2\
**Last updated:** [April 13, 2023, 5:44pm UTC](https://discuss.elastic.co/t/how-to-reduce-the-embedded-dashboard-load-time-inside-the-angular-iframe/329840 "2023-04-13T17:44:21Z")

</div>

I have embedded Kibana dashboard in a angular app , The dashboard contains around 12 vega-lite visualisations as well as 5 Kibana lens visualizations . The dashboard takes around 25-30 seconds to get completely fetched o…

---

## [How can I check the avaiability of a Heartbeat monitor in Elasticsearch?](https://discuss.elastic.co/t/how-can-i-check-the-avaiability-of-a-heartbeat-monitor-in-elasticsearch/329942)

<div class="topic-metadata">

**Author:** [@SamuelSMendes](https://discuss.elastic.co/u/SamuelSMendes)\
**Replies:** 2\
**Last updated:** [April 13, 2023, 4:59pm UTC](https://discuss.elastic.co/t/how-can-i-check-the-avaiability-of-a-heartbeat-monitor-in-elasticsearch/329942 "2023-04-13T16:59:47Z")

</div>

I have a few monitors in heartbeat which I am going to plan a few alerts. One of the alerts should be aiming for the avaiability of a monitor in the uptime in a range of a whole period of time (could be a day or a month)…

---

## [Getting started with Logstash JDBC Integration on Windows](https://discuss.elastic.co/t/getting-started-with-logstash-jdbc-integration-on-windows/329784)

<div class="topic-metadata">

**Author:** [@Dale\_ander](https://discuss.elastic.co/u/Dale_ander)\
**Replies:** 3\
**Last updated:** [April 13, 2023, 4:20pm UTC](https://discuss.elastic.co/t/getting-started-with-logstash-jdbc-integration-on-windows/329784 "2023-04-13T16:20:15Z")

</div>

I'm just beginning my learning process on ELK but from what I've seen, I'd like to learn how to index data from an RDB table, I presume using the Logstash JDBC Integration plugin, so I can start trying to create differen…

---

## [Programmatically trigger the search action (React UI)](https://discuss.elastic.co/t/programmatically-trigger-the-search-action-react-ui/329943)

<div class="topic-metadata">

**Author:** [@Olivia\_Xu](https://discuss.elastic.co/u/Olivia_Xu)\
**Replies:** 0\
**Last updated:** [April 13, 2023, 3:52pm UTC](https://discuss.elastic.co/t/programmatically-trigger-the-search-action-react-ui/329943 "2023-04-13T15:52:34Z")

</div>

We hope to programmatically trigger the search action in some cases without the user having to type and click the search button from the front end. We are using React UI components. Is this possible to achieve? We have t…

---

## [Can I make two input and output in the logstash config file?](https://discuss.elastic.co/t/can-i-make-two-input-and-output-in-the-logstash-config-file/329933)

<div class="topic-metadata">

**Author:** [@lilyyy](https://discuss.elastic.co/u/lilyyy)\
**Replies:** 3\
**Last updated:** [April 13, 2023, 3:26pm UTC](https://discuss.elastic.co/t/can-i-make-two-input-and-output-in-the-logstash-config-file/329933 "2023-04-13T15:26:19Z")

</div>

Hello all. I want to get the two indexes from two input data in the one logstash config file. (One is from tshark file and the other one is filebeat so each data are different.) tshark data is changed to json file for …

---

## [Ls there a processor in filebeat same as a prune filter in logstash?](https://discuss.elastic.co/t/ls-there-a-processor-in-filebeat-same-as-a-prune-filter-in-logstash/329940)

<div class="topic-metadata">

**Author:** [@lilyyy](https://discuss.elastic.co/u/lilyyy)\
**Replies:** 1\
**Last updated:** [April 13, 2023, 3:25pm UTC](https://discuss.elastic.co/t/ls-there-a-processor-in-filebeat-same-as-a-prune-filter-in-logstash/329940 "2023-04-13T15:25:05Z")

</div>

Hello. I want to get only specific fields in filebeat data. I know there is a prune filter in logstash config file but which one is same thing in filebeat config file processor? I used include\_fields processor, but it …

---

## [Getting updated documents](https://discuss.elastic.co/t/getting-updated-documents/329910)

<div class="topic-metadata">

**Author:** [@Ismet](https://discuss.elastic.co/u/Ismet)\
**Replies:** 5\
**Last updated:** [April 13, 2023, 3:21pm UTC](https://discuss.elastic.co/t/getting-updated-documents/329910 "2023-04-13T15:21:11Z")

</div>

How to get all documents that have been edited in the last 24 hours and return only the id and attributes that have been changed? Is it possible to do this automatically via Elasticsearch without tracking each attribute?…

---

## [Position Kibana Markdown/shapes with coordinates](https://discuss.elastic.co/t/position-kibana-markdown-shapes-with-coordinates/328821)

<div class="topic-metadata">

**Author:** [@v01d53t](https://discuss.elastic.co/u/v01d53t)\
**Replies:** 1\
**Last updated:** [April 13, 2023, 3:21pm UTC](https://discuss.elastic.co/t/position-kibana-markdown-shapes-with-coordinates/328821 "2023-04-13T15:21:10Z")

</div>

Hello everyone new user here, I am building something in Kibana that visualizes spots in certain places on an avatar image. The circle shape does just well for that. My problem is that I need some way to place the circ…

---

## [FleetServer Policy with Logstash type output failing](https://discuss.elastic.co/t/fleetserver-policy-with-logstash-type-output-failing/329839)

<div class="topic-metadata">

**Author:** [@Bradut\_B](https://discuss.elastic.co/u/Bradut_B)\
**Replies:** 6\
**Last updated:** [April 13, 2023, 3:02pm UTC](https://discuss.elastic.co/t/fleetserver-policy-with-logstash-type-output-failing/329839 "2023-04-13T15:02:08Z")

</div>

I have the following scenario that works: FleetServer policy -\> output type Elasticsearch AgentPolicy -\> output type Logstash However if I try to change the output type for the Fleet Server policy, to Logstash I get a…

---

## [Reindexing with a script including hashing](https://discuss.elastic.co/t/reindexing-with-a-script-including-hashing/329937)

<div class="topic-metadata">

**Author:** [@hannesulrich](https://discuss.elastic.co/u/hannesulrich)\
**Replies:** 0\
**Last updated:** [April 13, 2023, 2:30pm UTC](https://discuss.elastic.co/t/reindexing-with-a-script-including-hashing/329937 "2023-04-13T14:30:50Z")

</div>

Hey, we are currently looking into reindexing our indices and adding a new field which is the hash fingerprint of a larger field. Our approach is to pass the script to the reindexing api, but it won't work. Our request…

---

## [APM Server not working](https://discuss.elastic.co/t/apm-server-not-working/329855)

<div class="topic-metadata">

**Author:** [@Ruben\_Marinho](https://discuss.elastic.co/u/Ruben_Marinho)\
**Replies:** 1\
**Last updated:** [April 13, 2023, 2:17pm UTC](https://discuss.elastic.co/t/apm-server-not-working/329855 "2023-04-13T14:17:27Z")

</div>

Hi, I'm having issues with APM. I start some transactions using Agent.Tracer.StartTransaction("test", "xhr\_test"); and close it using the End method. I make over 100 calls but the transactions don't appear on APM. I…

---

## [Versioning in Update API](https://discuss.elastic.co/t/versioning-in-update-api/329934)

<div class="topic-metadata">

**Author:** [@Mykyta\_Piddubskiy](https://discuss.elastic.co/u/Mykyta_Piddubskiy)\
**Replies:** 0\
**Last updated:** [April 13, 2023, 1:53pm UTC](https://discuss.elastic.co/t/versioning-in-update-api/329934 "2023-04-13T13:53:41Z")

</div>

Hello, I need to do version checks when I do some operations in Elastic. Example: I want to use date instance in milliseconds as a version to reject any old doc updates. So I chose \_version as a suitable mechanism fo…

---

## [Find users (IP adresses) which only access one group of servers](https://discuss.elastic.co/t/find-users-ip-adresses-which-only-access-one-group-of-servers/328714)

<div class="topic-metadata">

**Author:** [@zebu14](https://discuss.elastic.co/u/zebu14)\
**Replies:** 1\
**Last updated:** [April 13, 2023, 1:53pm UTC](https://discuss.elastic.co/t/find-users-ip-adresses-which-only-access-one-group-of-servers/328714 "2023-04-13T13:53:41Z")

</div>

Hello, I have two groups of forward proxies running Squid (2x 4 servers) Many users are using these proxies. A load balancer sends each new connection on a group or another. Some users are not using the load balancer…

---

## [Restarting logstash cloudwatch plugin](https://discuss.elastic.co/t/restarting-logstash-cloudwatch-plugin/329681)

<div class="topic-metadata">

**Author:** [@mphilip9](https://discuss.elastic.co/u/mphilip9)\
**Replies:** 15\
**Last updated:** [April 13, 2023, 1:42pm UTC](https://discuss.elastic.co/t/restarting-logstash-cloudwatch-plugin/329681 "2023-04-13T13:42:41Z")

</div>

We have an ELK stack app that has been down for over a month due to a credentials issue in the logstash cloudwatch plugin. The plugin is digesting data again now, but what is strange is that it is digesting logs from the…

---

## [Can I save the fields that I only want?](https://discuss.elastic.co/t/can-i-save-the-fields-that-i-only-want/329736)

<div class="topic-metadata">

**Author:** [@lilyyy](https://discuss.elastic.co/u/lilyyy)\
**Replies:** 2\
**Last updated:** [April 13, 2023, 1:29pm UTC](https://discuss.elastic.co/t/can-i-save-the-fields-that-i-only-want/329736 "2023-04-13T13:29:34Z")

</div>

Hello all. I collect the network packet data through the 'tshark' and then the packet is filtered through logstash. But there are a lot of fields in packet data so when I see data in the elasticsearch, there are a lot …

---

## [【Please！】How to replace the host name display in kibana with my personal name](https://discuss.elastic.co/t/please-how-to-replace-the-host-name-display-in-kibana-with-my-personal-name/328634)

<div class="topic-metadata">

**Author:** [@YUUTA.INOUE-JPN](https://discuss.elastic.co/u/YUUTA.INOUE-JPN)\
**Replies:** 1\
**Last updated:** [April 13, 2023, 1:28pm UTC](https://discuss.elastic.co/t/please-how-to-replace-the-host-name-display-in-kibana-with-my-personal-name/328634 "2023-04-13T13:28:30Z")

</div>

Hello from Japan I have a question for you respected engineers. I am an inexperienced Japanese engineer with Elastic search. I have installed winlogbeat on my Windows PC and have built an environment to send Windows l…

---

## [How to join or merge two document ID data into a single document using a common field value in both Document ID](https://discuss.elastic.co/t/how-to-join-or-merge-two-document-id-data-into-a-single-document-using-a-common-field-value-in-both-document-id/328515)

<div class="topic-metadata">

**Author:** [@Gaurav\_kr](https://discuss.elastic.co/u/Gaurav_kr)\
**Replies:** 1\
**Last updated:** [April 13, 2023, 1:20pm UTC](https://discuss.elastic.co/t/how-to-join-or-merge-two-document-id-data-into-a-single-document-using-a-common-field-value-in-both-document-id/328515 "2023-04-13T13:20:21Z")

</div>

Hi All, I am using ELK 8.0.0 version and wanted to know can we merge or join the 2 different document ID into a single data with a common field value in both the documents. e.g first document ID has below data emp\_na…

---

## [Unable to start logstash on FreeBSD](https://discuss.elastic.co/t/unable-to-start-logstash-on-freebsd/329874)

<div class="topic-metadata">

**Author:** [@odhiambo](https://discuss.elastic.co/u/odhiambo)\
**Replies:** 4\
**Last updated:** [April 13, 2023, 1:05pm UTC](https://discuss.elastic.co/t/unable-to-start-logstash-on-freebsd/329874 "2023-04-13T13:05:45Z")

</div>

I have installed logstash on FreeBSD. For some reason, starting or stopping it prompts for Kerberos authentication. I am not sure where it is getting this from, although it does seem there is some kerberos config somewhe…

---

## [Search using special characters in standard analyzer](https://discuss.elastic.co/t/search-using-special-characters-in-standard-analyzer/329920)

<div class="topic-metadata">

**Author:** [@Umang\_Pachaury](https://discuss.elastic.co/u/Umang_Pachaury)\
**Replies:** 0\
**Last updated:** [April 13, 2023, 10:36am UTC](https://discuss.elastic.co/t/search-using-special-characters-in-standard-analyzer/329920 "2023-04-13T10:36:23Z")

</div>

Hi guys, I have a cluster running and I have run into a problem involving including special characters in my search query. Now I did not setup the mapping for the index the mapping is dynamic and the analyzer is also st…

---

## [KIBANA 7.1X alerts anomaly](https://discuss.elastic.co/t/kibana-7-1x-alerts-anomaly/329924)

<div class="topic-metadata">

**Author:** [@mkibani](https://discuss.elastic.co/u/mkibani)\
**Replies:** 2\
**Last updated:** [April 13, 2023, 12:35pm UTC](https://discuss.elastic.co/t/kibana-7-1x-alerts-anomaly/329924 "2023-04-13T12:35:08Z")

</div>

Hey Community, i have a recurring problem where my Kibana security alerts stop being fired. I have noticed this problem in two clusters, one running Kibana version 7.14.1 and the other running 7.17.2, the queries succe…

---

## [Error in Logstash - failed to parse date field with format strict\_date\_optional\_time||epoch\_millis date-time-parse-exception](https://discuss.elastic.co/t/error-in-logstash-failed-to-parse-date-field-with-format-strict-date-optional-time-epoch-millis-date-time-parse-exception/329797)

<div class="topic-metadata">

**Author:** [@sarath.sarepaka](https://discuss.elastic.co/u/sarath.sarepaka)\
**Replies:** 3\
**Last updated:** [April 13, 2023, 12:30pm UTC](https://discuss.elastic.co/t/error-in-logstash-failed-to-parse-date-field-with-format-strict-date-optional-time-epoch-millis-date-time-parse-exception/329797 "2023-04-13T12:30:34Z")

</div>

Hi, We are getting the below error in the logstash. We are using a field called "destination" for both time and string. We observed below issue when the destination field value is a string . ELasticsearch and Logstash …

---

## [How to use pipelines](https://discuss.elastic.co/t/how-to-use-pipelines/329919)

<div class="topic-metadata">

**Author:** [@Hajar\_Lachhab](https://discuss.elastic.co/u/Hajar_Lachhab)\
**Replies:** 1\
**Last updated:** [April 13, 2023, 11:00am UTC](https://discuss.elastic.co/t/how-to-use-pipelines/329919 "2023-04-13T11:00:29Z")

</div>

Hello evryone, I have created a pipeline that parse web logs but I don't know how to apply it on my data view. My data view is filebeat-8.6.2 and my pipeline is this:

---

## [Kibana 8.6 I dont see in fiscovery my data](https://discuss.elastic.co/t/kibana-8-6-i-dont-see-in-fiscovery-my-data/328280)

<div class="topic-metadata">

**Author:** [@Mary2022](https://discuss.elastic.co/u/Mary2022)\
**Replies:** 2\
**Last updated:** [April 13, 2023, 10:56am UTC](https://discuss.elastic.co/t/kibana-8-6-i-dont-see-in-fiscovery-my-data/328280 "2023-04-13T10:56:43Z")

</div>

I copied the pipeline from our old stack (7.17) and pasted it to our new ELK stack (8.6). I copied the mapping of one of my indices in the old stack and created a new index in my new kibana with that mapping. In my new…

---

## [Elastic search and kibana elastic didnot load properly](https://discuss.elastic.co/t/elastic-search-and-kibana-elastic-didnot-load-properly/329274)

<div class="topic-metadata">

**Author:** [@Moksha2](https://discuss.elastic.co/u/Moksha2)\
**Replies:** 3\
**Last updated:** [April 13, 2023, 10:52am UTC](https://discuss.elastic.co/t/elastic-search-and-kibana-elastic-didnot-load-properly/329274 "2023-04-13T10:52:46Z")

</div>

Hi Team, Elastic search(8.5.3) and kibana deployed through ECK , while accessing the kibana Most of the time facing issue like Elastic did not load properly check the logs . Is it cover security in the free version of …

[Previous page](https://discuss.elastic.co/latest.md?page=711)

[Next page](https://discuss.elastic.co/latest.md?page=713)
