# Latest

**URL:** https://discuss.elastic.co/latest.md?page=725

[Latest](https://discuss.elastic.co/latest.md) · [Categories](https://discuss.elastic.co/categories.md) · [Tags](https://discuss.elastic.co/tags.md)

**Page:** 726

---

## [Filebeat MSSQL Module - Log Unreadable](https://discuss.elastic.co/t/filebeat-mssql-module-log-unreadable/329066)

<div class="topic-metadata">

**Author:** [@OscarFilho](https://discuss.elastic.co/u/OscarFilho)\
**Replies:** 1\
**Last updated:** [March 31, 2023, 9:13pm UTC](https://discuss.elastic.co/t/filebeat-mssql-module-log-unreadable/329066 "2023-03-31T21:13:36Z")

</div>

I installed filebeat 8.7 on my SQL Server and enabled the MSSQL module. Filebeat is normally collecting the logs from the folders I configured, but the original log message is unreadable: 72.\\u0000\\u0000\\u0000\\u0000��…

---

## [Keytool error: java.io.IOException: Invalid keystore format](https://discuss.elastic.co/t/keytool-error-java-io-ioexception-invalid-keystore-format/328939)

<div class="topic-metadata">

**Author:** [@dr01](https://discuss.elastic.co/u/dr01)\
**Replies:** 2\
**Last updated:** [March 31, 2023, 8:40pm UTC](https://discuss.elastic.co/t/keytool-error-java-io-ioexception-invalid-keystore-format/328939 "2023-03-31T20:40:24Z")

</div>

I have Elasticsearch 7.17. Following the generation of new SSL certificates, I have created a new keystore via the command /usr/share/elasticsearch/bin/elasticsearch-keystore create and I'm trying to add the CA cert…

---

## [Update Existing document through logstash](https://discuss.elastic.co/t/update-existing-document-through-logstash/329077)

<div class="topic-metadata">

**Author:** [@rubhamra](https://discuss.elastic.co/u/rubhamra)\
**Replies:** 4\
**Last updated:** [March 31, 2023, 8:40pm UTC](https://discuss.elastic.co/t/update-existing-document-through-logstash/329077 "2023-03-31T20:40:21Z")

</div>

logstash pipeline is not updating existing document for the same id, I have couples of fields which got updated frequestly for example Last Modified Date. I have below logstash config. output { elasticsearch { …

---

## [Data stream timestamp in the name of index](https://discuss.elastic.co/t/data-stream-timestamp-in-the-name-of-index/329080)

<div class="topic-metadata">

**Author:** [@INS](https://discuss.elastic.co/u/INS)\
**Replies:** 1\
**Last updated:** [March 31, 2023, 8:25pm UTC](https://discuss.elastic.co/t/data-stream-timestamp-in-the-name-of-index/329080 "2023-03-31T20:25:48Z")

</div>

Hi Is it possible to achieve name with timestamp from ingest data to elasticsearch in the index name like .ds-\<data-stream\>-\<yyyy.MM.dd\>-\<generation\> .ds-\<data-stream\>\<mytimestamp\_from\_log\>-\<generation\> I've tried to…

---

## [Kibana not give logs](https://discuss.elastic.co/t/kibana-not-give-logs/328695)

<div class="topic-metadata">

**Author:** [@Prabhath\_samarasingh](https://discuss.elastic.co/u/Prabhath_samarasingh)\
**Replies:** 7\
**Last updated:** [March 31, 2023, 8:13pm UTC](https://discuss.elastic.co/t/kibana-not-give-logs/328695 "2023-03-31T20:13:11Z")

</div>

Configured basic ELK set up.But my kibana interface had no logs. This is the guide I followed. What is the mistake I have done. Installing and Configuring Elasticsearch curl -fsSL https://artifacts.elastic.co/GPG-KEY…

---

## [Reading date format in logstash date filter](https://discuss.elastic.co/t/reading-date-format-in-logstash-date-filter/329070)

<div class="topic-metadata">

**Author:** [@UsmanNiazi](https://discuss.elastic.co/u/UsmanNiazi)\
**Replies:** 7\
**Last updated:** [March 31, 2023, 7:45pm UTC](https://discuss.elastic.co/t/reading-date-format-in-logstash-date-filter/329070 "2023-03-31T19:45:21Z")

</div>

Hi, I am unable to convert this string "03/31/2023 03:15 AM PDT" to date when using logstash date filter. Getting error dateparse failure. I am using below script date { match =\> \[ "start\_time", "mm/dd/yyyy HH:mm Z",…

---

## [Elasticsearch Malformed Query, Expected \[END\_OBJECT\] but found \[Field\_Name\]](https://discuss.elastic.co/t/elasticsearch-malformed-query-expected-end-object-but-found-field-name/329072)

<div class="topic-metadata">

**Author:** [@elrozario](https://discuss.elastic.co/u/elrozario)\
**Replies:** 2\
**Last updated:** [March 31, 2023, 7:33pm UTC](https://discuss.elastic.co/t/elasticsearch-malformed-query-expected-end-object-but-found-field-name/329072 "2023-03-31T19:33:54Z")

</div>

Hello, I am trying to run reindex with query but getting the error Malformed Query, Expected \[END\_OBJECT\] but found \[Field\_Name\]. { "source": { "index": "index-\*", "\_source" : \[ "@timestamp", "message"\], …

---

## [S3 API Costs are extraordinary expensive for snapshots](https://discuss.elastic.co/t/s3-api-costs-are-extraordinary-expensive-for-snapshots/329071)

<div class="topic-metadata">

**Author:** [@Doc\_Kaos](https://discuss.elastic.co/u/Doc_Kaos)\
**Replies:** 3\
**Last updated:** [March 31, 2023, 7:04pm UTC](https://discuss.elastic.co/t/s3-api-costs-are-extraordinary-expensive-for-snapshots/329071 "2023-03-31T19:04:45Z")

</div>

To store 5TB of data, we are paying about $1,200 in storage fees per month and $10,000 in API calls Is there a way to fix this? During a snapshot we are seeing upwards of 120k s3 api calls/minute SLM: PUT \_slm/policy/…

---

## [Elastic Search Api with Python](https://discuss.elastic.co/t/elastic-search-api-with-python/329009)

<div class="topic-metadata">

**Author:** [@Sharath\_B.S](https://discuss.elastic.co/u/Sharath_B.S)\
**Replies:** 2\
**Last updated:** [March 31, 2023, 6:45pm UTC](https://discuss.elastic.co/t/elastic-search-api-with-python/329009 "2023-03-31T18:45:31Z")

</div>

Im trying to sort the search results according to the date in ascending order. it would be helpful if i could get to know how to sort the results according to the date.

---

## [Elasticsearch 8.4.3 - security rules dashboard cannot be accessed - Privileges required](https://discuss.elastic.co/t/elasticsearch-8-4-3-security-rules-dashboard-cannot-be-accessed-privileges-required/329074)

<div class="topic-metadata">

**Author:** [@breakandfix](https://discuss.elastic.co/u/breakandfix)\
**Replies:** 1\
**Last updated:** [March 31, 2023, 6:21pm UTC](https://discuss.elastic.co/t/elasticsearch-8-4-3-security-rules-dashboard-cannot-be-accessed-privileges-required/329074 "2023-03-31T18:21:41Z")

</div>

Hi there, I created a rule in elastic and followed this document for allowing access for a user to all security features including alerts. The role has all indices access including metioned in the above document: …

---

## [In elasticsearch finding documents which meet a specific criteria for the latest for each group](https://discuss.elastic.co/t/in-elasticsearch-finding-documents-which-meet-a-specific-criteria-for-the-latest-for-each-group/329023)

<div class="topic-metadata">

**Author:** [@m.a.tanaka](https://discuss.elastic.co/u/m.a.tanaka)\
**Replies:** 2\
**Last updated:** [March 31, 2023, 5:17pm UTC](https://discuss.elastic.co/t/in-elasticsearch-finding-documents-which-meet-a-specific-criteria-for-the-latest-for-each-group/329023 "2023-03-31T17:17:38Z")

</div>

I am trying to create a query in elasticsearch, which is able to retrieve the documents for each group, which is the latest document within each group and meet a specific criteria. But I have not been able to solve this …

---

## [Elasticsearch backup - S3 repository](https://discuss.elastic.co/t/elasticsearch-backup-s3-repository/328773)

<div class="topic-metadata">

**Author:** [@chateesh](https://discuss.elastic.co/u/chateesh)\
**Replies:** 1\
**Last updated:** [March 31, 2023, 4:09pm UTC](https://discuss.elastic.co/t/elasticsearch-backup-s3-repository/328773 "2023-03-31T16:09:14Z")

</div>

Hi All, We're backing up the Elasticsearch cluster indices to a S3 bucket (S3 repository by snapshot API), daily backup is around 1TB, and deleting the snapshots older than 30 days. Total size of S3 bucket is more than …

---

## [Java API client : How to reset index settings value](https://discuss.elastic.co/t/java-api-client-how-to-reset-index-settings-value/329059)

<div class="topic-metadata">

**Author:** [@MathieuLacour](https://discuss.elastic.co/u/MathieuLacour)\
**Replies:** 2\
**Last updated:** [March 31, 2023, 3:02pm UTC](https://discuss.elastic.co/t/java-api-client-how-to-reset-index-settings-value/329059 "2023-03-31T15:02:40Z")

</div>

For performance reasons, I need to temporarily disable refresh\_interval at index settings level while bulk loading takes place in the index, and enable it back afterwards. The refresh\_interval value is held by global cl…

---

## [How to apply a filter to a control visualization](https://discuss.elastic.co/t/how-to-apply-a-filter-to-a-control-visualization/328968)

<div class="topic-metadata">

**Author:** [@richfish](https://discuss.elastic.co/u/richfish)\
**Replies:** 3\
**Last updated:** [March 31, 2023, 2:52pm UTC](https://discuss.elastic.co/t/how-to-apply-a-filter-to-a-control-visualization/328968 "2023-03-31T14:52:45Z")

</div>

In Kibana 7.10.1, I have a dashboard with multiple visualizations, each with its own filter based on the same property on the same index. I added a dropdown control that will allow the user to filter by one of those valu…

---

## [Python code in Kibana](https://discuss.elastic.co/t/python-code-in-kibana/329044)

<div class="topic-metadata">

**Author:** [@ANUBHAV\_GUPTA](https://discuss.elastic.co/u/ANUBHAV_GUPTA)\
**Replies:** 1\
**Last updated:** [March 31, 2023, 2:01pm UTC](https://discuss.elastic.co/t/python-code-in-kibana/329044 "2023-03-31T14:01:54Z")

</div>

Can we run python functions in Kibana in order to perform some transformation on the index data?

---

## [How to do Advanced Sync Rules on Date field with Relative Date for MongoDB](https://discuss.elastic.co/t/how-to-do-advanced-sync-rules-on-date-field-with-relative-date-for-mongodb/328853)

<div class="topic-metadata">

**Author:** [@pocketcolin](https://discuss.elastic.co/u/pocketcolin)\
**Replies:** 2\
**Last updated:** [March 31, 2023, 1:52pm UTC](https://discuss.elastic.co/t/how-to-do-advanced-sync-rules-on-date-field-with-relative-date-for-mongodb/328853 "2023-03-31T13:52:52Z")

</div>

I am trying to setup a MongoDB index sync that pulls over all records where a date field is $gte the current date. I assumed something like the following would work as it worked on the Mongo command line, but alas it pul…

---

## [Python UDF in Kibana](https://discuss.elastic.co/t/python-udf-in-kibana/328933)

<div class="topic-metadata">

**Author:** [@ANUBHAV\_GUPTA](https://discuss.elastic.co/u/ANUBHAV_GUPTA)\
**Replies:** 2\
**Last updated:** [March 31, 2023, 1:27pm UTC](https://discuss.elastic.co/t/python-udf-in-kibana/328933 "2023-03-31T13:27:26Z")

</div>

Can we build python UDF or any other language's UDF to transform data queried from Kibana dev-tools console?

---

## [Es restore \[parent\] data too large](https://discuss.elastic.co/t/es-restore-parent-data-too-large/329016)

<div class="topic-metadata">

**Author:** [@huang1](https://discuss.elastic.co/u/huang1)\
**Replies:** 7\
**Last updated:** [March 31, 2023, 12:34pm UTC](https://discuss.elastic.co/t/es-restore-parent-data-too-large/329016 "2023-03-31T12:34:37Z")

</div>

The total data size of es is less than 1G. Perform a regular restore. After running for a period of time, throw the \[parent\] data too large. The node executing the restore has a high xmx and a high CPU utilization rate\_ …

---

## [Trying to export data reports using Kibana discover but could not be able to export large no. of data](https://discuss.elastic.co/t/trying-to-export-data-reports-using-kibana-discover-but-could-not-be-able-to-export-large-no-of-data/329018)

<div class="topic-metadata">

**Author:** [@Mangesh\_Mathe](https://discuss.elastic.co/u/Mangesh_Mathe)\
**Replies:** 6\
**Last updated:** [March 31, 2023, 12:28pm UTC](https://discuss.elastic.co/t/trying-to-export-data-reports-using-kibana-discover-but-could-not-be-able-to-export-large-no-of-data/329018 "2023-03-31T12:28:37Z")

</div>

Hello Team, I'm trying to download discover search data with some of my filters. However, When I download I see that document limit in CSV is at 10,000 documents. Any way or setting to increase document download limit…

---

## [ElasticApm class not found after configuration (Laravel)](https://discuss.elastic.co/t/elasticapm-class-not-found-after-configuration-laravel/328759)

<div class="topic-metadata">

**Author:** [@Thiago\_Medeiros](https://discuss.elastic.co/u/Thiago_Medeiros)\
**Replies:** 7\
**Last updated:** [March 31, 2023, 12:18pm UTC](https://discuss.elastic.co/t/elasticapm-class-not-found-after-configuration-laravel/328759 "2023-03-31T12:18:53Z")

</div>

I did what Elastic PHP agent tutorial says and have: elastic\_apm plugin shown in php info :white\_check\_mark: can use ElasticApm class :x: when I import ElasticApm class with use Elastic\\Apm\\ElasticApm I'm getting C…

---

## [Version\_conflict\_engine\_exception errors with status 409](https://discuss.elastic.co/t/version-conflict-engine-exception-errors-with-status-409/328855)

<div class="topic-metadata">

**Author:** [@Fernando\_Oliveira](https://discuss.elastic.co/u/Fernando_Oliveira)\
**Replies:** 2\
**Last updated:** [March 31, 2023, 12:13pm UTC](https://discuss.elastic.co/t/version-conflict-engine-exception-errors-with-status-409/328855 "2023-03-31T12:13:14Z")

</div>

Hello, I clean my indexes in the elastic with the script below: POST /aplicacao/\_delete\_by\_query { "query": { "range": { "timeLog": { "lte": "now-5M" } } } } "aplicacao " is the name of the index, I leave …

---

## [Can't log in Kibana when a specific elasticsearch node is not running](https://discuss.elastic.co/t/cant-log-in-kibana-when-a-specific-elasticsearch-node-is-not-running/328914)

<div class="topic-metadata">

**Author:** [@jgl75](https://discuss.elastic.co/u/jgl75)\
**Replies:** 5\
**Last updated:** [March 31, 2023, 11:52am UTC](https://discuss.elastic.co/t/cant-log-in-kibana-when-a-specific-elasticsearch-node-is-not-running/328914 "2023-03-31T11:52:03Z")

</div>

Hi everyone, First time poster here. I'm working with ELK since a few weeks, learning new things every day :slight\_smile: I've solved all my problems except one. I have a 3 nodes elasticsearch cluster and a separate …

---

## [Passing dynamic values to range query](https://discuss.elastic.co/t/passing-dynamic-values-to-range-query/329037)

<div class="topic-metadata">

**Author:** [@Farah\_Bhr](https://discuss.elastic.co/u/Farah_Bhr)\
**Replies:** 0\
**Last updated:** [March 31, 2023, 9:48am UTC](https://discuss.elastic.co/t/passing-dynamic-values-to-range-query/329037 "2023-03-31T09:48:24Z")

</div>

In kibana discover, with Elasticsearch Query DSL, I want to search for a range of timestamp dynamically here is the range I used: { "range": { "@timestamp": { "gte": "2023-03-03T15:0…

---

## [Function score weight rounding score If value is high](https://discuss.elastic.co/t/function-score-weight-rounding-score-if-value-is-high/329043)

<div class="topic-metadata">

**Author:** [@eerkisi](https://discuss.elastic.co/u/eerkisi)\
**Replies:** 0\
**Last updated:** [March 31, 2023, 11:10am UTC](https://discuss.elastic.co/t/function-score-weight-rounding-score-if-value-is-high/329043 "2023-03-31T11:10:22Z")

</div>

Hello, We have function scores and functions which manipulate scores by some filters etc. We set one of the function score weight as high numbers because of the our business. Also we need fraction of the value to be abl…

---

## [Tried to build package registry image but no content](https://discuss.elastic.co/t/tried-to-build-package-registry-image-but-no-content/329039)

<div class="topic-metadata">

**Author:** [@Mudboyzh](https://discuss.elastic.co/u/Mudboyzh)\
**Replies:** 0\
**Last updated:** [March 31, 2023, 10:24am UTC](https://discuss.elastic.co/t/tried-to-build-package-registry-image-but-no-content/329039 "2023-03-31T10:24:55Z")

</div>

Hi I have already deployed ELK / Elastic Agent / Package registry with official images. They work well. Because of our company's standard, images have to fix vulnerability before deploy on k8s(air-gapped), I have to f…

---

## [Cannot send error to Elastic APM from AWS lambda](https://discuss.elastic.co/t/cannot-send-error-to-elastic-apm-from-aws-lambda/328909)

<div class="topic-metadata">

**Author:** [@JasonREC](https://discuss.elastic.co/u/JasonREC)\
**Replies:** 2\
**Last updated:** [March 31, 2023, 3:06am UTC](https://discuss.elastic.co/t/cannot-send-error-to-elastic-apm-from-aws-lambda/328909 "2023-03-31T03:06:50Z")

</div>

Kibana version: Latest Cloud version Elasticsearch version: Latest Cloud version APM Server version: Latest Cloud version APM Agent language and version:NodeJS I followd exactly this page to do the set up (Monitoring…

---

## [Fleet giving error | unable to initialize fleet](https://discuss.elastic.co/t/fleet-giving-error-unable-to-initialize-fleet/326337)

<div class="topic-metadata">

**Author:** [@theacodes](https://discuss.elastic.co/u/theacodes)\
**Replies:** 10\
**Last updated:** [March 31, 2023, 9:48am UTC](https://discuss.elastic.co/t/fleet-giving-error-unable-to-initialize-fleet/326337 "2023-03-31T09:48:00Z")

</div>

getting this error sometimes in FLEET resource\_already\_exists\_exception: \[resource\_already\_exists\_exception\] reason: task with id {endpoint.metadata\_current-default-8.6.1} already exist

---

## [Creating customised reference values based on lagged information](https://discuss.elastic.co/t/creating-customised-reference-values-based-on-lagged-information/329036)

<div class="topic-metadata">

**Author:** [@NiklasHBB](https://discuss.elastic.co/u/NiklasHBB)\
**Replies:** 0\
**Last updated:** [March 31, 2023, 9:38am UTC](https://discuss.elastic.co/t/creating-customised-reference-values-based-on-lagged-information/329036 "2023-03-31T09:38:29Z")

</div>

What is the best way to create reference values which are based on past information in Elasticsearch? My current use case involves detailling in Kibana how the values for a day, week or month relate to past developments…

---

## [Elastic Agent中使用集成Docker中如何过滤所需的docker容器日志？](https://discuss.elastic.co/t/elastic-agent-docker-docker/329035)

<div class="topic-metadata">

**Author:** [@XYYYYY](https://discuss.elastic.co/u/XYYYYY)\
**Replies:** 1\
**Last updated:** [March 31, 2023, 9:38am UTC](https://discuss.elastic.co/t/elastic-agent-docker-docker/329035 "2023-03-31T09:38:28Z")

</div>

大家好，我是一个使用Elastic Agent的新手。我曾尝试使用Docker集成收集容器日志，但我有各种各样的容器日志。我只想得到其中的几个。我怎样才能做到这一点呢? 我目前正在尝试使用收集Docker容器日志中的条件选项来设置我想要的容器过滤器，但我不确定如何输入来过滤掉我想要的容器，或者使用额外的处理器。我希望你能回答。谢谢你！

---

## [How to hide rows in table without affecting search criteria](https://discuss.elastic.co/t/how-to-hide-rows-in-table-without-affecting-search-criteria/329033)

<div class="topic-metadata">

**Author:** [@abhardwaj](https://discuss.elastic.co/u/abhardwaj)\
**Replies:** 4\
**Last updated:** [March 31, 2023, 9:35am UTC](https://discuss.elastic.co/t/how-to-hide-rows-in-table-without-affecting-search-criteria/329033 "2023-03-31T09:35:36Z")

</div>

Hello, I am creating a kibana visualization table based on few test run results in my elasticsearch index. Following is the composition of value hits. Following is the output table having the results captured T…

[Previous page](https://discuss.elastic.co/latest.md?page=724)

[Next page](https://discuss.elastic.co/latest.md?page=726)
