# Latest

**URL:** https://discuss.elastic.co/latest.md?page=716

[Latest](https://discuss.elastic.co/latest.md) · [Categories](https://discuss.elastic.co/categories.md) · [Tags](https://discuss.elastic.co/tags.md)

**Page:** 717

---

## [Parsing logfiles](https://discuss.elastic.co/t/parsing-logfiles/329505)

<div class="topic-metadata">

**Author:** [@SIRAJEDDINE-HAMZA](https://discuss.elastic.co/u/SIRAJEDDINE-HAMZA)\
**Replies:** 2\
**Last updated:** [April 11, 2023, 1:08pm UTC](https://discuss.elastic.co/t/parsing-logfiles/329505 "2023-04-11T13:08:16Z")

</div>

I'm new to using ElasticStack and I'm having trouble parsing a log file using Logstash. Specifically, I want to split the file using the timestamp as a separator and extract data from each block, but I'm not sure how to …

---

## [License in a cluster](https://discuss.elastic.co/t/license-in-a-cluster/329502)

<div class="topic-metadata">

**Author:** [@Joel\_Goncalves](https://discuss.elastic.co/u/Joel_Goncalves)\
**Replies:** 6\
**Last updated:** [April 11, 2023, 12:33pm UTC](https://discuss.elastic.co/t/license-in-a-cluster/329502 "2023-04-11T12:33:05Z")

</div>

Hello I have a cluster with 5 nodes, one of them (master) is installed on-premises and I have 4 nodes connected to it if I put a license on elasticsearch which is installed on-premises will this license be passed to the…

---

## [Active alert for terminated instance](https://discuss.elastic.co/t/active-alert-for-terminated-instance/329552)

<div class="topic-metadata">

**Author:** [@leandro.silva](https://discuss.elastic.co/u/leandro.silva)\
**Replies:** 1\
**Last updated:** [April 11, 2023, 12:27pm UTC](https://discuss.elastic.co/t/active-alert-for-terminated-instance/329552 "2023-04-11T12:27:52Z")

</div>

I've installed the elastic agent on some instances. On March 27 one instance generated an alert about hard disk available space. On March 31 the instance was terminated. The problem is that the alert is still active. Te…

---

## [Bulk ingester no close at the end](https://discuss.elastic.co/t/bulk-ingester-no-close-at-the-end/329633)

<div class="topic-metadata">

**Author:** [@ALX\_DM](https://discuss.elastic.co/u/ALX_DM)\
**Replies:** 3\
**Last updated:** [April 11, 2023, 12:11pm UTC](https://discuss.elastic.co/t/bulk-ingester-no-close-at-the-end/329633 "2023-04-11T12:11:49Z")

</div>

I read the documents but it is not clear to me. I have this code: public void indexProduct(Product product) { try (BulkIngester\<String\> bulkIngester = indexingService.createBulkIngester()) { indexingService.bulkI…

---

## [Run direct dsl query using high level client elasticsearch](https://discuss.elastic.co/t/run-direct-dsl-query-using-high-level-client-elasticsearch/329746)

<div class="topic-metadata">

**Author:** [@mangeshs](https://discuss.elastic.co/u/mangeshs)\
**Replies:** 0\
**Last updated:** [April 11, 2023, 11:56am UTC](https://discuss.elastic.co/t/run-direct-dsl-query-using-high-level-client-elasticsearch/329746 "2023-04-11T11:56:47Z")

</div>

I am trying run dsl query directly as we do from dev tools. I created java api for that but want provide formatted string. Is there any way to do this? in Elasticsearch

---

## [How to set default value for rank\_feature field type](https://discuss.elastic.co/t/how-to-set-default-value-for-rank-feature-field-type/329694)

<div class="topic-metadata">

**Author:** [@binoiii](https://discuss.elastic.co/u/binoiii)\
**Replies:** 0\
**Last updated:** [April 11, 2023, 1:09am UTC](https://discuss.elastic.co/t/how-to-set-default-value-for-rank-feature-field-type/329694 "2023-04-11T01:09:13Z")

</div>

I'm performing a rank\_feature query and there is a possibility that the fields that I will rank i.e bid field (please below) won't be available. I wonder if there is a way to set a default for bid if the field is not pr…

---

## [How to receive alerts in two elasticsearch](https://discuss.elastic.co/t/how-to-receive-alerts-in-two-elasticsearch/329743)

<div class="topic-metadata">

**Author:** [@Joel\_Goncalves](https://discuss.elastic.co/u/Joel_Goncalves)\
**Replies:** 0\
**Last updated:** [April 11, 2023, 11:40am UTC](https://discuss.elastic.co/t/how-to-receive-alerts-in-two-elasticsearch/329743 "2023-04-11T11:40:51Z")

</div>

Hello, I want to know how do I send alerts from one elasticsearch to another. Let's imagine that I have 2 elasticsearch servers in different networks and clusters and on one server I have the fleet installed and several …

---

## [Single page appliaction (SPA) using Elasticsearch REST APIs](https://discuss.elastic.co/t/single-page-appliaction-spa-using-elasticsearch-rest-apis/329735)

<div class="topic-metadata">

**Author:** [@gichhr](https://discuss.elastic.co/u/gichhr)\
**Replies:** 0\
**Last updated:** [April 11, 2023, 10:52am UTC](https://discuss.elastic.co/t/single-page-appliaction-spa-using-elasticsearch-rest-apis/329735 "2023-04-11T10:52:48Z")

</div>

Hello, I'd like to confirm that can be generated a React static Single Page Application (SPA) that use Elasticsearch REST APIs for authentication and role authorization and queering data form indexes. This static SPA ca…

---

## [Search logs for sensitive data](https://discuss.elastic.co/t/search-logs-for-sensitive-data/329734)

<div class="topic-metadata">

**Author:** [@Cejs](https://discuss.elastic.co/u/Cejs)\
**Replies:** 0\
**Last updated:** [April 11, 2023, 10:43am UTC](https://discuss.elastic.co/t/search-logs-for-sensitive-data/329734 "2023-04-11T10:43:22Z")

</div>

Hi, I am working on finding logs with potentially sensitive content like personal data and I would like to ask for your experience. Do you guys have some source I can use to define patterns for regexes? I have only som…

---

## [How to view documents by lucene segment?](https://discuss.elastic.co/t/how-to-view-documents-by-lucene-segment/329512)

<div class="topic-metadata">

**Author:** [@nisow95612](https://discuss.elastic.co/u/nisow95612)\
**Replies:** 2\
**Last updated:** [April 11, 2023, 10:16am UTC](https://discuss.elastic.co/t/how-to-view-documents-by-lucene-segment/329512 "2023-04-11T10:16:03Z")

</div>

Hello elasticsearch, I have a tricky question. I accidentally reindexed a bunch of documents into a wrong index. This original index was previously forcemerged to one big segment per shard. Indexing new documents creat…

---

## [What the different between ClusterStateTaskListener and AckedClusterStateTaskListener](https://discuss.elastic.co/t/what-the-different-between-clusterstatetasklistener-and-ackedclusterstatetasklistener/329719)

<div class="topic-metadata">

**Author:** [@cm\_z](https://discuss.elastic.co/u/cm_z)\
**Replies:** 2\
**Last updated:** [April 11, 2023, 10:05am UTC](https://discuss.elastic.co/t/what-the-different-between-clusterstatetasklistener-and-ackedclusterstatetasklistener/329719 "2023-04-11T10:05:25Z")

</div>

what the different between ClusterStateTaskListener.clusterStateProcessed and AckedClusterStateTaskListener.onAllNodesAcked , they all call after elasticsearch publish finish.

---

## [Use .cer file ( security certifciates ) with default elastic search installation](https://discuss.elastic.co/t/use-cer-file-security-certifciates-with-default-elastic-search-installation/329032)

<div class="topic-metadata">

**Author:** [@Nilesh\_Jethwani](https://discuss.elastic.co/u/Nilesh_Jethwani)\
**Replies:** 4\
**Last updated:** [April 11, 2023, 10:13am UTC](https://discuss.elastic.co/t/use-cer-file-security-certifciates-with-default-elastic-search-installation/329032 "2023-04-11T10:13:39Z")

</div>

I have been provided 3 certificate files from one of the providers intermediate.cer root.cer main.cer I want to use the above in my default elasticsearch deployment. Currently http.p12 is being used ( default)

---

## [Use NTLM authentication while crawling domains](https://discuss.elastic.co/t/use-ntlm-authentication-while-crawling-domains/327522)

<div class="topic-metadata">

**Author:** [@Disha\_Bodade](https://discuss.elastic.co/u/Disha_Bodade)\
**Replies:** 8\
**Last updated:** [April 11, 2023, 10:09am UTC](https://discuss.elastic.co/t/use-ntlm-authentication-while-crawling-domains/327522 "2023-04-11T10:09:42Z")

</div>

Hi Team, I am trying to crawl website which uses NTLM authentication. but I am not able to crawl it. I can't see any option in UI to add authentication details for website. and also in crawl api we have only basic and r…

---

## [Elastic Log Threshold rule problem](https://discuss.elastic.co/t/elastic-log-threshold-rule-problem/329213)

<div class="topic-metadata">

**Author:** [@amityahav](https://discuss.elastic.co/u/amityahav)\
**Replies:** 4\
**Last updated:** [April 11, 2023, 10:03am UTC](https://discuss.elastic.co/t/elastic-log-threshold-rule-problem/329213 "2023-04-11T10:03:40Z")

</div>

Hey there, i've been experimenting with log threshold type of rules recently and i've encountered some strange behaviors. Elastic version is 8.6.2 given a log threshold rule with action connector of some index. When …

---

## [Elasticsearch Cluster Sizing](https://discuss.elastic.co/t/elasticsearch-cluster-sizing/329703)

<div class="topic-metadata">

**Author:** [@Darshan\_J](https://discuss.elastic.co/u/Darshan_J)\
**Replies:** 4\
**Last updated:** [April 11, 2023, 9:57am UTC](https://discuss.elastic.co/t/elasticsearch-cluster-sizing/329703 "2023-04-11T09:57:00Z")

</div>

The webinar above showcases bunch of formulas for Elasticsearch cluster sizing. There are discussions where responses show unfamiliarity with the formulas or techniques given in the webinar. The discussion also follows…

---

## [Filebeat read different log paths and write to different elastic index with their own ilm policy,How?](https://discuss.elastic.co/t/filebeat-read-different-log-paths-and-write-to-different-elastic-index-with-their-own-ilm-policy-how/327638)

<div class="topic-metadata">

**Author:** [@PRASHANT\_MEHTA](https://discuss.elastic.co/u/PRASHANT_MEHTA)\
**Replies:** 25\
**Last updated:** [April 11, 2023, 9:47am UTC](https://discuss.elastic.co/t/filebeat-read-different-log-paths-and-write-to-different-elastic-index-with-their-own-ilm-policy-how/327638 "2023-04-11T09:47:23Z")

</div>

Hello All, I'm having a bit of a hard time understanding the best config for our setup. We are running filebeat to ship several logs from different file location to elastic that need their own index template and policy. …

---

## [How to exploit rules](https://discuss.elastic.co/t/how-to-exploit-rules/328174)

<div class="topic-metadata">

**Author:** [@Iroshu](https://discuss.elastic.co/u/Iroshu)\
**Replies:** 10\
**Last updated:** [April 11, 2023, 8:58am UTC](https://discuss.elastic.co/t/how-to-exploit-rules/328174 "2023-04-11T08:58:30Z")

</div>

Dear team, We are actually playing with the detection of elastic and something seems weird for us. We have created a Rule and we add an action in order to populate an index using our collector : We choose all fied…

---

## [Logstash input pipelines are slow after restart](https://discuss.elastic.co/t/logstash-input-pipelines-are-slow-after-restart/329715)

<div class="topic-metadata">

**Author:** [@Amit\_Gupta2](https://discuss.elastic.co/u/Amit_Gupta2)\
**Replies:** 1\
**Last updated:** [April 11, 2023, 8:03am UTC](https://discuss.elastic.co/t/logstash-input-pipelines-are-slow-after-restart/329715 "2023-04-11T08:03:56Z")

</div>

Hi Team, I am facing slowness issue in data sync after every restart of logstash. My observation is that input pipeline are taking time to start in parallel. I am using Logstash 6.8 which is deployed on an EC2 instance…

---

## [Logs getting Merged/clubbed with each other in some cases](https://discuss.elastic.co/t/logs-getting-merged-clubbed-with-each-other-in-some-cases/329588)

<div class="topic-metadata">

**Author:** [@shadu88](https://discuss.elastic.co/u/shadu88)\
**Replies:** 10\
**Last updated:** [April 11, 2023, 7:52am UTC](https://discuss.elastic.co/t/logs-getting-merged-clubbed-with-each-other-in-some-cases/329588 "2023-04-11T07:52:05Z")

</div>

Hello Dear ELKs, I'm using logstash7.10 for forward the logs to Qradar and Azure sentinel. Have noticed some irregularities with some log source type. Log flow : heterogenous logs -\> file --\> logstash( file input) --\> …

---

## [How a elastic machine learning(anomaly detection) job depends on historical data?](https://discuss.elastic.co/t/how-a-elastic-machine-learning-anomaly-detection-job-depends-on-historical-data/327806)

<div class="topic-metadata">

**Author:** [@Souvik\_Das](https://discuss.elastic.co/u/Souvik_Das)\
**Replies:** 5\
**Last updated:** [April 11, 2023, 6:53am UTC](https://discuss.elastic.co/t/how-a-elastic-machine-learning-anomaly-detection-job-depends-on-historical-data/327806 "2023-04-11T06:53:25Z")

</div>

Hi, Is it possible to redirect one machine learning (anomaly detection) job to a new data stream having the same sets of fields of the old historical index when it is live? Background: We have 10 ML jobs (anomaly det…

---

## [How to add deletion phase in policy (POST does not seem to work)](https://discuss.elastic.co/t/how-to-add-deletion-phase-in-policy-post-does-not-seem-to-work/329409)

<div class="topic-metadata">

**Author:** [@Mark\_S](https://discuss.elastic.co/u/Mark_S)\
**Replies:** 2\
**Last updated:** [April 11, 2023, 6:53am UTC](https://discuss.elastic.co/t/how-to-add-deletion-phase-in-policy-post-does-not-seem-to-work/329409 "2023-04-11T06:53:07Z")

</div>

I am trying to add a deletion phase in an existing policy. The policy works fine, creating new indices every day. However, I cannot add a deletion phase. Since this is not possible from the UI, I tried with a POST : Bu…

---

## [getFieldMapping request using java API for elasticsearch](https://discuss.elastic.co/t/getfieldmapping-request-using-java-api-for-elasticsearch/329705)

<div class="topic-metadata">

**Author:** [@shwetanb](https://discuss.elastic.co/u/shwetanb)\
**Replies:** 0\
**Last updated:** [April 11, 2023, 5:10am UTC](https://discuss.elastic.co/t/getfieldmapping-request-using-java-api-for-elasticsearch/329705 "2023-04-11T05:10:34Z")

</div>

I am trying to replicate below query DSL using java: GET /test/\_mapping/field/\*?include\_defaults=true I am using below code to get mappings: GetFieldMappingResponse resp = client.indices().getFieldMapping(new GetField…

---

## [Table in dashboards is not showing multiline logs](https://discuss.elastic.co/t/table-in-dashboards-is-not-showing-multiline-logs/328355)

<div class="topic-metadata">

**Author:** [@tulio.farias](https://discuss.elastic.co/u/tulio.farias)\
**Replies:** 11\
**Last updated:** [April 10, 2023, 10:06pm UTC](https://discuss.elastic.co/t/table-in-dashboards-is-not-showing-multiline-logs/328355 "2023-04-10T22:06:18Z")

</div>

In Dashboad, I have created a table to show only ERROR logs' messages, but it is not showing logs with multiple lines: If I go to Discover, I see there is a multiline log (using the same filters): Could someone h…

---

## [How to filter Filebeat output by input id?](https://discuss.elastic.co/t/how-to-filter-filebeat-output-by-input-id/329603)

<div class="topic-metadata">

**Author:** [@paolovalladolid](https://discuss.elastic.co/u/paolovalladolid)\
**Replies:** 4\
**Last updated:** [April 10, 2023, 9:44pm UTC](https://discuss.elastic.co/t/how-to-filter-filebeat-output-by-input-id/329603 "2023-04-10T21:44:02Z")

</div>

I configured filebeat.yml as follows: filebeat.inputs: - type: filestream id: my-input1 paths: - /opt/mything1/logs/\*.log - type: filestream id: my-input2 paths: - /opt/mything2/logs/\*.log - type: file…

---

## [Kibana Dashboard shows no result even if there is non-zero number of hits](https://discuss.elastic.co/t/kibana-dashboard-shows-no-result-even-if-there-is-non-zero-number-of-hits/326668)

<div class="topic-metadata">

**Author:** [@Piotrek](https://discuss.elastic.co/u/Piotrek)\
**Replies:** 1\
**Last updated:** [April 10, 2023, 9:33pm UTC](https://discuss.elastic.co/t/kibana-dashboard-shows-no-result-even-if-there-is-non-zero-number-of-hits/326668 "2023-04-10T21:33:45Z")

</div>

Dear Community, I'm designing my Dashboard with controls, where user can filter all the results on agregated data. However when using particular filters on some values I receive 'No results found' however when inspectin…

---

## [Dashboard as pdf which is scheduled in Advanced watcher alert showing incomplete visuals](https://discuss.elastic.co/t/dashboard-as-pdf-which-is-scheduled-in-advanced-watcher-alert-showing-incomplete-visuals/327083)

<div class="topic-metadata">

**Author:** [@Avinash\_J](https://discuss.elastic.co/u/Avinash_J)\
**Replies:** 1\
**Last updated:** [April 10, 2023, 9:27pm UTC](https://discuss.elastic.co/t/dashboard-as-pdf-which-is-scheduled-in-advanced-watcher-alert-showing-incomplete-visuals/327083 "2023-04-10T21:27:35Z")

</div>

Hi Team, I have created an Advanced watcher alert in which a dashboard will be shared as pdf to the mentioned email id's. As my dashboard contains too many visuals and the index pattern used for dashboard holds large v…

---

## [Control/filter how to show only possible values](https://discuss.elastic.co/t/control-filter-how-to-show-only-possible-values/328377)

<div class="topic-metadata">

**Author:** [@pratverd](https://discuss.elastic.co/u/pratverd)\
**Replies:** 1\
**Last updated:** [April 10, 2023, 9:23pm UTC](https://discuss.elastic.co/t/control-filter-how-to-show-only-possible-values/328377 "2023-04-10T21:23:50Z")

</div>

Hi everyone :slight\_smile: I'm trying to filter with controls and I would like to have only possible values when I choose a filter and I have to filter with another one. Above an example: | filter 1 | filter 2 | | ap…

---

## [FIPS 140-2 Config, On-Prem](https://discuss.elastic.co/t/fips-140-2-config-on-prem/329686)

<div class="topic-metadata">

**Author:** [@pschadha1](https://discuss.elastic.co/u/pschadha1)\
**Replies:** 1\
**Last updated:** [April 10, 2023, 9:05pm UTC](https://discuss.elastic.co/t/fips-140-2-config-on-prem/329686 "2023-04-10T21:05:04Z")

</div>

Hello, We have a requirement to run ES in FIPS mode. I understand that xpack.security.fips\_mode.enabled is what allows ES to run in a JVM that is configured for FIPS. I also understand that it requires a Platinum lice…

---

## [Missing transactions in the traceview after a call to DAPR](https://discuss.elastic.co/t/missing-transactions-in-the-traceview-after-a-call-to-dapr/329578)

<div class="topic-metadata">

**Author:** [@Daniel\_Khoroshko](https://discuss.elastic.co/u/Daniel_Khoroshko)\
**Replies:** 3\
**Last updated:** [April 10, 2023, 8:59pm UTC](https://discuss.elastic.co/t/missing-transactions-in-the-traceview-after-a-call-to-dapr/329578 "2023-04-10T20:59:12Z")

</div>

As you can see the trace consists of many transactions: However when I open the first transaction I can see the trace chart not showing all the transactions, but just one of them What could be the reason for such…

---

## [How to display a "string" metric](https://discuss.elastic.co/t/how-to-display-a-string-metric/327815)

<div class="topic-metadata">

**Author:** [@tinrik](https://discuss.elastic.co/u/tinrik)\
**Replies:** 1\
**Last updated:** [April 10, 2023, 8:34pm UTC](https://discuss.elastic.co/t/how-to-display-a-string-metric/327815 "2023-04-10T20:34:57Z")

</div>

Hi! I want to display a single string in my dashboard - a hash that represents the commit hash of the repo from which the visualized data was generated. Ideally I'd like to use the "Metric" visualization, since it's on…

[Previous page](https://discuss.elastic.co/latest.md?page=715)

[Next page](https://discuss.elastic.co/latest.md?page=717)
