# Latest

**URL:** https://discuss.elastic.co/latest.md?page=723

[Latest](https://discuss.elastic.co/latest.md) · [Categories](https://discuss.elastic.co/categories.md) · [Tags](https://discuss.elastic.co/tags.md)

**Page:** 724

---

## [Streaming API to local folder using logstash](https://discuss.elastic.co/t/streaming-api-to-local-folder-using-logstash/329248)

<div class="topic-metadata">

**Author:** [@Reloef\_Khoza](https://discuss.elastic.co/u/Reloef_Khoza)\
**Replies:** 0\
**Last updated:** [April 3, 2023, 7:26pm UTC](https://discuss.elastic.co/t/streaming-api-to-local-folder-using-logstash/329248 "2023-04-03T19:26:54Z")

</div>

Any example of how to stream multiple API from a website into a local folder

---

## [How to exclude attachment content and still searching inside it?](https://discuss.elastic.co/t/how-to-exclude-attachment-content-and-still-searching-inside-it/329191)

<div class="topic-metadata">

**Author:** [@aabdo](https://discuss.elastic.co/u/aabdo)\
**Replies:** 7\
**Last updated:** [April 3, 2023, 5:35pm UTC](https://discuss.elastic.co/t/how-to-exclude-attachment-content-and-still-searching-inside-it/329191 "2023-04-03T17:35:58Z")

</div>

hello, to optimize my disk space, i'm excluding my attachment content in the mapping of my index. but i can't no longer search inside it . i don't know what am i messing !! . is there any solution for this issue ??

---

## [Elasticsearch 7.17 with G1GC and Java 17](https://discuss.elastic.co/t/elasticsearch-7-17-with-g1gc-and-java-17/329230)

<div class="topic-metadata">

**Author:** [@navaneethan](https://discuss.elastic.co/u/navaneethan)\
**Replies:** 1\
**Last updated:** [April 3, 2023, 5:14pm UTC](https://discuss.elastic.co/t/elasticsearch-7-17-with-g1gc-and-java-17/329230 "2023-04-03T17:14:39Z")

</div>

Is it good to go with G1GC in Elasticsearch 7.17 With Java 17 and is there any drawback of having this config in production

---

## [If IP results in \_geoip\_lookup\_failure is it possible to fill geoip-related vields with a custom value?](https://discuss.elastic.co/t/if-ip-results-in-geoip-lookup-failure-is-it-possible-to-fill-geoip-related-vields-with-a-custom-value/329144)

<div class="topic-metadata">

**Author:** [@roman-tasi](https://discuss.elastic.co/u/roman-tasi)\
**Replies:** 3\
**Last updated:** [April 3, 2023, 4:57pm UTC](https://discuss.elastic.co/t/if-ip-results-in-geoip-lookup-failure-is-it-possible-to-fill-geoip-related-vields-with-a-custom-value/329144 "2023-04-03T16:57:54Z")

</div>

Basically if the IP cannot be found in the database, I want to fill the geoip.city\_name, geoip.region\_name, and geoip.country\_name with a custom value like "PRIVATE ADDRESS" or "IP NOT IN DATABASE" or something similar..…

---

## [Elasticsearch Engineer (On-Demand) 8.1](https://discuss.elastic.co/t/elasticsearch-engineer-on-demand-8-1/329235)

<div class="topic-metadata">

**Author:** [@Jordan\_Rylander](https://discuss.elastic.co/u/Jordan_Rylander)\
**Replies:** 2\
**Last updated:** [April 3, 2023, 4:56pm UTC](https://discuss.elastic.co/t/elasticsearch-engineer-on-demand-8-1/329235 "2023-04-03T16:56:37Z")

</div>

Course: Elasticsearch Engineer (On-Demand) 8.1 Version: 8.1 Question: I can't seem to find any password for the Kibana instance in the training materials. Creds don't seem to be available in the Strigo console like oth…

---

## [Median Forumla Question](https://discuss.elastic.co/t/median-forumla-question/329238)

<div class="topic-metadata">

**Author:** [@Joshua\_Boyd](https://discuss.elastic.co/u/Joshua_Boyd)\
**Replies:** 0\
**Last updated:** [April 3, 2023, 4:51pm UTC](https://discuss.elastic.co/t/median-forumla-question/329238 "2023-04-03T16:51:40Z")

</div>

Hello, wondering if anyone could give advice on the following: i have a table of incidents, with column of account name and the incident id incident1, account1 incident2, account1 incident3, account2 .... I want to…

---

## [Operations over indexed documents](https://discuss.elastic.co/t/operations-over-indexed-documents/329068)

<div class="topic-metadata">

**Author:** [@tmslara.a](https://discuss.elastic.co/u/tmslara.a)\
**Replies:** 4\
**Last updated:** [April 3, 2023, 4:27pm UTC](https://discuss.elastic.co/t/operations-over-indexed-documents/329068 "2023-04-03T16:27:41Z")

</div>

Hi, Is it possible to compute variables taking the documents from an index as input? I will describe my current situation and my objective. I have data indexed on an Elasticsearch cluster. My data contains a timestamp …

---

## [Using Lens Table to Keep Track of Days of the Month](https://discuss.elastic.co/t/using-lens-table-to-keep-track-of-days-of-the-month/327597)

<div class="topic-metadata">

**Author:** [@Goishin](https://discuss.elastic.co/u/Goishin)\
**Replies:** 0\
**Last updated:** [March 13, 2023, 9:11pm UTC](https://discuss.elastic.co/t/using-lens-table-to-keep-track-of-days-of-the-month/327597 "2023-03-13T21:11:08Z")

</div>

I use a Kibana dashboard to keep track of a number of things on my team. We all look at this dashboard to see the team's current status of stuff. But our team also has regular things that happen on specific days of the m…

---

## [Grant read privileges to specific documentss](https://discuss.elastic.co/t/grant-read-privileges-to-specific-documentss/329098)

<div class="topic-metadata">

**Author:** [@hiba](https://discuss.elastic.co/u/hiba)\
**Replies:** 4\
**Last updated:** [April 3, 2023, 4:12pm UTC](https://discuss.elastic.co/t/grant-read-privileges-to-specific-documentss/329098 "2023-04-03T16:12:07Z")

</div>

Hi, I want to create a role that can read only specific documents. For example: User A can only read documents where professional\_id = 49 Now I want to display a default currency for each user For example, user A …

---

## [How to changes advance setting on my build for ELK setup](https://discuss.elastic.co/t/how-to-changes-advance-setting-on-my-build-for-elk-setup/327716)

<div class="topic-metadata">

**Author:** [@Arshukla](https://discuss.elastic.co/u/Arshukla)\
**Replies:** 1\
**Last updated:** [April 3, 2023, 3:52pm UTC](https://discuss.elastic.co/t/how-to-changes-advance-setting-on-my-build-for-elk-setup/327716 "2023-04-03T15:52:41Z")

</div>

Hello Team, Please help to change advance settings on my ELK setup for by build. I have tried with Kibana.yaml, but couldn't succeed. Below are parameters which require changes - Scaled Date Format storeinSessionStor…

---

## [Multiple index search](https://discuss.elastic.co/t/multiple-index-search/329180)

<div class="topic-metadata">

**Author:** [@Phoenix1](https://discuss.elastic.co/u/Phoenix1)\
**Replies:** 5\
**Last updated:** [April 3, 2023, 3:43pm UTC](https://discuss.elastic.co/t/multiple-index-search/329180 "2023-04-03T15:43:28Z")

</div>

How to search logs in multiple index, within discover it does not gives option to select multiple indexes in drop down option.

---

## [Logstash does not creates nor updates index on elasticsearch](https://discuss.elastic.co/t/logstash-does-not-creates-nor-updates-index-on-elasticsearch/329069)

<div class="topic-metadata">

**Author:** [@Quentin\_Moisy](https://discuss.elastic.co/u/Quentin_Moisy)\
**Replies:** 5\
**Last updated:** [April 3, 2023, 3:41pm UTC](https://discuss.elastic.co/t/logstash-does-not-creates-nor-updates-index-on-elasticsearch/329069 "2023-04-03T15:41:40Z")

</div>

Hello, I new to the ELK flow and I have some issues with Logstash. Sometime my index will be populated sometime not. Furthermore it seems that logstash does not create index on elasticsearch. Can you help on that My .c…

---

## [Read from ES index fails without write permission with HEAD \[405|Method Not Allowed:\]](https://discuss.elastic.co/t/read-from-es-index-fails-without-write-permission-with-head-405-method-not-allowed/328176)

<div class="topic-metadata">

**Author:** [@petersedivec](https://discuss.elastic.co/u/petersedivec)\
**Replies:** 10\
**Last updated:** [April 3, 2023, 3:03pm UTC](https://discuss.elastic.co/t/read-from-es-index-fails-without-write-permission-with-head-405-method-not-allowed/328176 "2023-04-03T15:03:29Z")

</div>

We're trying to connect to 2 different elastic instances and read data from databricks on indicies where a user has read permissions. For both instances we're seeing the following error EsHadoopInvalidRequest: \[HEAD\] o…

---

## [All AWS WAF event goes to message field even after using correct mapping](https://discuss.elastic.co/t/all-aws-waf-event-goes-to-message-field-even-after-using-correct-mapping/329227)

<div class="topic-metadata">

**Author:** [@SSP1](https://discuss.elastic.co/u/SSP1)\
**Replies:** 0\
**Last updated:** [April 3, 2023, 2:55pm UTC](https://discuss.elastic.co/t/all-aws-waf-event-goes-to-message-field-even-after-using-correct-mapping/329227 "2023-04-03T14:55:22Z")

</div>

HI, I'm using Logstash to ingest AWS WAF Logs from S3 using S3 Input login with SQS and logs are going through to elasticsearch. I can see those in Kibana but all the waf event goes to message filed. I have tried to use …

---

## [Databricks lakehouse delta tables as data source](https://discuss.elastic.co/t/databricks-lakehouse-delta-tables-as-data-source/328591)

<div class="topic-metadata">

**Author:** [@mruthyu](https://discuss.elastic.co/u/mruthyu)\
**Replies:** 2\
**Last updated:** [April 3, 2023, 2:44pm UTC](https://discuss.elastic.co/t/databricks-lakehouse-delta-tables-as-data-source/328591 "2023-04-03T14:44:47Z")

</div>

Is it possible to connect to the databricks lakehouse Delta tables to get the data to be indexed into elasticsearch?

---

## [Timeline displaying no data views](https://discuss.elastic.co/t/timeline-displaying-no-data-views/328841)

<div class="topic-metadata">

**Author:** [@AndyBox2](https://discuss.elastic.co/u/AndyBox2)\
**Replies:** 1\
**Last updated:** [April 3, 2023, 2:31pm UTC](https://discuss.elastic.co/t/timeline-displaying-no-data-views/328841 "2023-04-03T14:31:48Z")

</div>

I am all very new to the ELK stack. I am attempting to implement a risk based score into my test environment. I have successfully set up alerts into the SIEM. However, when I go into the timeline, the displayed data vie…

---

## [Kibana discover url link click naviagte to custom url](https://discuss.elastic.co/t/kibana-discover-url-link-click-naviagte-to-custom-url/329171)

<div class="topic-metadata">

**Author:** [@PRASHANT\_MEHTA](https://discuss.elastic.co/u/PRASHANT_MEHTA)\
**Replies:** 4\
**Last updated:** [April 3, 2023, 2:21pm UTC](https://discuss.elastic.co/t/kibana-discover-url-link-click-naviagte-to-custom-url/329171 "2023-04-03T14:21:46Z")

</div>

Hello All, Above is how my data looks like in old implementation.Now I'm using jdbc plugin in logstash to parse this data and send to elastic index.Now the data in table is simple value. Now I would like to click on …

---

## [Enterprise-search not starting new install of 8.6.2](https://discuss.elastic.co/t/enterprise-search-not-starting-new-install-of-8-6-2/328394)

<div class="topic-metadata">

**Author:** [@Neil\_Maffitt](https://discuss.elastic.co/u/Neil_Maffitt)\
**Replies:** 13\
**Last updated:** [April 3, 2023, 2:11pm UTC](https://discuss.elastic.co/t/enterprise-search-not-starting-new-install-of-8-6-2/328394 "2023-04-03T14:11:00Z")

</div>

Elastic search is running no problem curl --cacert /etc/elasticsearch/certs/http\_ca.crt -u elastic:password https://127.0.0.1:9200 Response looks good. But when starting Enterprise Search get error see below. Elastic…

---

## [Failed to obtain node locks on data dir mounted as volume in Kubernetes](https://discuss.elastic.co/t/failed-to-obtain-node-locks-on-data-dir-mounted-as-volume-in-kubernetes/329207)

<div class="topic-metadata">

**Author:** [@bade27](https://discuss.elastic.co/u/bade27)\
**Replies:** 0\
**Last updated:** [April 3, 2023, 12:44pm UTC](https://discuss.elastic.co/t/failed-to-obtain-node-locks-on-data-dir-mounted-as-volume-in-kubernetes/329207 "2023-04-03T12:44:44Z")

</div>

Hello everyone! I'm trying to deploy ES v 8.6.2 on a Kubernetes cluster in a single-node configuration, and having troubles with the data storage on bootstrap. I'm deploying ES as a StatefulSet (replicas: 1) with indexi…

---

## [Problem with mapping](https://discuss.elastic.co/t/problem-with-mapping/329221)

<div class="topic-metadata">

**Author:** [@matheusgermano](https://discuss.elastic.co/u/matheusgermano)\
**Replies:** 0\
**Last updated:** [April 3, 2023, 1:33pm UTC](https://discuss.elastic.co/t/problem-with-mapping/329221 "2023-04-03T13:33:57Z")

</div>

Hey, folks! How are you? I'm having some troubles with, I believe, mapping. I have a JsonElement field type that is not being saved in my elastic. I'm using C#, working with NEST client. Invalid NEST response built fro…

---

## [Loading BERT Model](https://discuss.elastic.co/t/loading-bert-model/327709)

<div class="topic-metadata">

**Author:** [@Cole\_Crawford](https://discuss.elastic.co/u/Cole_Crawford)\
**Replies:** 1\
**Last updated:** [April 3, 2023, 1:11pm UTC](https://discuss.elastic.co/t/loading-bert-model/327709 "2023-04-03T13:11:18Z")

</div>

I am trying to add ANN semantic search to an Elasticsearch index of scientific documents. To that end, I am trying to set up an NLP pipeline on Elasticsearch to vectorize documents on ingest. I would like to test allenai…

---

## [Find a search Object with part of the name](https://discuss.elastic.co/t/find-a-search-object-with-part-of-the-name/327843)

<div class="topic-metadata">

**Author:** [@KolodzRelyens](https://discuss.elastic.co/u/KolodzRelyens)\
**Replies:** 2\
**Last updated:** [April 3, 2023, 1:07pm UTC](https://discuss.elastic.co/t/find-a-search-object-with-part-of-the-name/327843 "2023-04-03T13:07:05Z")

</div>

Hi, My instance of Elasticsearch start to have a lot of recorded search object, like Batchs\_MyAppA\_MySpecificProcessA Batchs\_MyAppA\_MySpecificProcessB Batchs\_MyAppA\_MySpecificProcessC Batchs\_MyAppB\_MySpecificProcessD B…

---

## [Hybrid Retrieval with approximate KNN](https://discuss.elastic.co/t/hybrid-retrieval-with-approximate-knn/329196)

<div class="topic-metadata">

**Author:** [@jinmingteo](https://discuss.elastic.co/u/jinmingteo)\
**Replies:** 1\
**Last updated:** [April 3, 2023, 12:50pm UTC](https://discuss.elastic.co/t/hybrid-retrieval-with-approximate-knn/329196 "2023-04-03T12:50:49Z")

</div>

Hi, I have read through the following documentation: k-nearest neighbor (kNN) search | Elasticsearch Guide \[master\] | Elastic I have also experimented with a small database and it seems that the results are skewed towa…

---

## [Enrich Processor missing documents](https://discuss.elastic.co/t/enrich-processor-missing-documents/328843)

<div class="topic-metadata">

**Author:** [@FKarraz](https://discuss.elastic.co/u/FKarraz)\
**Replies:** 3\
**Last updated:** [April 3, 2023, 12:24pm UTC](https://discuss.elastic.co/t/enrich-processor-missing-documents/328843 "2023-04-03T12:24:30Z")

</div>

Hi, i have several ingest pipelines that has quite large processor configured in it. Each pipeline for each Data Stream. For example, pipeline "2g\_names" works with "raw\_kpi\_2g\_" (raw\_kpi\_2g\_1) Data Stream, "3g\_names" fo…

---

## [QueryBuilders.nested() in new Java REST Client works not as expected (no "nested" attribute generated), comparing to older (deprecated) HRC](https://discuss.elastic.co/t/querybuilders-nested-in-new-java-rest-client-works-not-as-expected-no-nested-attribute-generated-comparing-to-older-deprecated-hrc/329099)

<div class="topic-metadata">

**Author:** [@Mattteo](https://discuss.elastic.co/u/Mattteo)\
**Replies:** 3\
**Last updated:** [April 3, 2023, 11:31am UTC](https://discuss.elastic.co/t/querybuilders-nested-in-new-java-rest-client-works-not-as-expected-no-nested-attribute-generated-comparing-to-older-deprecated-hrc/329099 "2023-04-03T11:31:51Z")

</div>

The problem: I am trying to upgrade from deprecated HRC (7.13) to new REST Client 8.6 in Java. We use nested queries, but although there is a special NestedQuery.Builder object in the new java client, its not possible t…

---

## [Experience with Large Memory Nodes (1TB, 2TB, and more)](https://discuss.elastic.co/t/experience-with-large-memory-nodes-1tb-2tb-and-more/329124)

<div class="topic-metadata">

**Author:** [@Michael\_Sander](https://discuss.elastic.co/u/Michael_Sander)\
**Replies:** 1\
**Last updated:** [April 3, 2023, 10:53am UTC](https://discuss.elastic.co/t/experience-with-large-memory-nodes-1tb-2tb-and-more/329124 "2023-04-03T10:53:07Z")

</div>

Google Cloud, AWS, and others are now offering nodes with 2TB or more of memory. In the past, the conventional wisdom has been to not provide Elasticsearch with more than 32GB so it uses 32 bit pointers, but I wonder if …

---

## [Creación de usuarios](https://discuss.elastic.co/t/creacion-de-usuarios/328845)

<div class="topic-metadata">

**Author:** [@JorgeGV](https://discuss.elastic.co/u/JorgeGV)\
**Replies:** 3\
**Last updated:** [April 3, 2023, 10:26am UTC](https://discuss.elastic.co/t/creacion-de-usuarios/328845 "2023-04-03T10:26:35Z")

</div>

Tengo un dashboard con información global de un país y sus respectivas regiones. Ahora quiero crear usuarios para este dashboard, pero que sólo puedan acceder a la información de su región. ¿Cómo puedo hacerlo?. Gracias …

---

## [No Alerts in Winlogbeat](https://discuss.elastic.co/t/no-alerts-in-winlogbeat/328698)

<div class="topic-metadata">

**Author:** [@Shaakxuur](https://discuss.elastic.co/u/Shaakxuur)\
**Replies:** 3\
**Last updated:** [April 3, 2023, 10:15am UTC](https://discuss.elastic.co/t/no-alerts-in-winlogbeat/328698 "2023-04-03T10:15:06Z")

</div>

Hi there I´m trying to run Winlogbeat. I installed everything but I can´t see any alerts. It seem that it isn´t possible for me to find the problem :frowning: Elasticsearch, Kibana and Winlogbeat are running without …

---

## [Recommended configuration](https://discuss.elastic.co/t/recommended-configuration/329120)

<div class="topic-metadata">

**Author:** [@Noam\_Huri](https://discuss.elastic.co/u/Noam_Huri)\
**Replies:** 3\
**Last updated:** [April 3, 2023, 9:48am UTC](https://discuss.elastic.co/t/recommended-configuration/329120 "2023-04-03T09:48:59Z")

</div>

Hi, could someone please help me and guide me on how to calculate the cost or the recommended configuration that would best suit my needs? unfortunately, I'm not an IT guy :slight\_smile: Our data set consists of approx…

---

## [How to Filter Desired Container Logs in Docker Integration in Fleet？](https://discuss.elastic.co/t/how-to-filter-desired-container-logs-in-docker-integration-in-fleet/329030)

<div class="topic-metadata">

**Author:** [@XYYYYY](https://discuss.elastic.co/u/XYYYYY)\
**Replies:** 5\
**Last updated:** [April 3, 2023, 9:20am UTC](https://discuss.elastic.co/t/how-to-filter-desired-container-logs-in-docker-integration-in-fleet/329030 "2023-04-03T09:20:10Z")

</div>

Hello everyone, I am a newcomer using elastic agent. I have tried to collect container logs using Docker integration, but I have a wide variety of container logs. I only want to obtain a few of them. How can I achieve th…

[Previous page](https://discuss.elastic.co/latest.md?page=722)

[Next page](https://discuss.elastic.co/latest.md?page=724)
