# Latest

**URL:** https://discuss.elastic.co/latest.md?page=732

[Latest](https://discuss.elastic.co/latest.md) · [Categories](https://discuss.elastic.co/categories.md) · [Tags](https://discuss.elastic.co/tags.md)

**Page:** 733

---

## [Kibana developer guide](https://discuss.elastic.co/t/kibana-developer-guide/328421)

<div class="topic-metadata">

**Author:** [@dms6978](https://discuss.elastic.co/u/dms6978)\
**Replies:** 5\
**Last updated:** [March 28, 2023, 2:30am UTC](https://discuss.elastic.co/t/kibana-developer-guide/328421 "2023-03-28T02:30:50Z")

</div>

I ran 'yarn kbn bootstrap' while looking at the kibana developer guide, and the error follows. UNHANDLED EXCEPTION: Error: spawn git ENOENT at Process.ChildProcess.\_handle.onexit (node:internal/child\_process:285:19)…

---

## [Inconsistent scoring starting w/ 7.0.0 (worse in 7.4.0)](https://discuss.elastic.co/t/inconsistent-scoring-starting-w-7-0-0-worse-in-7-4-0/328658)

<div class="topic-metadata">

**Author:** [@workmanw](https://discuss.elastic.co/u/workmanw)\
**Replies:** 0\
**Last updated:** [March 28, 2023, 2:21am UTC](https://discuss.elastic.co/t/inconsistent-scoring-starting-w-7-0-0-worse-in-7-4-0/328658 "2023-03-28T02:21:36Z")

</div>

Hello, I'm in the process of upgrading from 6.x to 7.x. Along the way I discovered an unexpected issue with document updates and relevancy scoring. In my application's integration test suite we have a series of very bas…

---

## [How to clear filebeat so it does not into kibana?](https://discuss.elastic.co/t/how-to-clear-filebeat-so-it-does-not-into-kibana/328485)

<div class="topic-metadata">

**Author:** [@iqworks](https://discuss.elastic.co/u/iqworks)\
**Replies:** 1\
**Last updated:** [March 28, 2023, 1:28am UTC](https://discuss.elastic.co/t/how-to-clear-filebeat-so-it-does-not-into-kibana/328485 "2023-03-28T01:28:34Z")

</div>

Hi, I know I filebeat in my security onion so-status. I am using windows 10. The events get into my kibana, even when i so-elastic-clear and so-nsm-clear. How can I clear filebeat so kibana is completely empty? thanks …

---

## [Is elasticsearch documents stored on file encrypted?](https://discuss.elastic.co/t/is-elasticsearch-documents-stored-on-file-encrypted/328652)

<div class="topic-metadata">

**Author:** [@eleong](https://discuss.elastic.co/u/eleong)\
**Replies:** 2\
**Last updated:** [March 28, 2023, 12:50am UTC](https://discuss.elastic.co/t/is-elasticsearch-documents-stored-on-file-encrypted/328652 "2023-03-28T00:50:39Z")

</div>

Hi, We have a compliance audit coming up soon and one of the requirement is that the information stored in Elastic (as a SIEM) must be encrypted. Now, I understand that Elastic don't do encryption because these documen…

---

## [Error in the installation Elasticsearch process](https://discuss.elastic.co/t/error-in-the-installation-elasticsearch-process/328607)

<div class="topic-metadata">

**Author:** [@Hubert\_Homaei](https://discuss.elastic.co/u/Hubert_Homaei)\
**Replies:** 1\
**Last updated:** [March 27, 2023, 10:28pm UTC](https://discuss.elastic.co/t/error-in-the-installation-elasticsearch-process/328607 "2023-03-27T22:28:48Z")

</div>

Hi, I wanted to install Elastic search on a local system; I checked all requirements, installed JDK, and set the variable path for java.exe. But when I execute elasticsearch.bat in CMD, I got this warning: warning: igno…

---

## [Metricbeat:action \[indices:admin/auto\_create\] is unauthorized for user \[metricbeat\] with effective roles \[ES\_metricbeat\] on indices \[metricbeat-8.6.2\], this action is granted by the index privileges](https://discuss.elastic.co/t/metricbeat-action-indices-admin-auto-create-is-unauthorized-for-user-metricbeat-with-effective-roles-es-metricbeat-on-indices-metricbeat-8-6-2-this-action-is-granted-by-the-index-privileges/328648)

<div class="topic-metadata">

**Author:** [@Tussingh](https://discuss.elastic.co/u/Tussingh)\
**Replies:** 0\
**Last updated:** [March 27, 2023, 7:54pm UTC](https://discuss.elastic.co/t/metricbeat-action-indices-admin-auto-create-is-unauthorized-for-user-metricbeat-with-effective-roles-es-metricbeat-on-indices-metricbeat-8-6-2-this-action-is-granted-by-the-index-privileges/328648 "2023-03-27T19:54:33Z")

</div>

I am facing error in ingesting data from metricbeat to elastic. Please help {"log.level":"warn","@timestamp":"2023-03-28T01:22:21.499+0530","log.logger":"elasticsearch","log.origin":{"file.name":"elasticsearch/client.go…

---

## [Elastic EnterpriseSearch Indexing limits](https://discuss.elastic.co/t/elastic-enterprisesearch-indexing-limits/327313)

<div class="topic-metadata">

**Author:** [@mbrimmer83](https://discuss.elastic.co/u/mbrimmer83)\
**Replies:** 3\
**Last updated:** [March 27, 2023, 6:56pm UTC](https://discuss.elastic.co/t/elastic-enterprisesearch-indexing-limits/327313 "2023-03-27T18:56:07Z")

</div>

We are encountering issues when trying to index large numbers of documents in parallel. More than 100 indexing requests per second. Error: socket hang up. Are we running into limits with our ES instance? We have continua…

---

## [Several configuration files for one pipeline](https://discuss.elastic.co/t/several-configuration-files-for-one-pipeline/328640)

<div class="topic-metadata">

**Author:** [@Daniel\_Lopez](https://discuss.elastic.co/u/Daniel_Lopez)\
**Replies:** 0\
**Last updated:** [March 27, 2023, 6:34pm UTC](https://discuss.elastic.co/t/several-configuration-files-for-one-pipeline/328640 "2023-03-27T18:34:23Z")

</div>

I'm trying to reduce high cpu consumption in our logstash, so i decide to join several pipelines in one and run these configuration files as only one pipeline I'm testing with only two files without filter, only input a…

---

## [Elastic Search First Query is always slow and shards not getting distributed properly](https://discuss.elastic.co/t/elastic-search-first-query-is-always-slow-and-shards-not-getting-distributed-properly/328639)

<div class="topic-metadata">

**Author:** [@Gaurav\_Sachdeva](https://discuss.elastic.co/u/Gaurav_Sachdeva)\
**Replies:** 1\
**Last updated:** [March 27, 2023, 6:29pm UTC](https://discuss.elastic.co/t/elastic-search-first-query-is-always-slow-and-shards-not-getting-distributed-properly/328639 "2023-03-27T18:29:39Z")

</div>

I am creating per day index in Elastic Search ( version: 7.5.1 ). I have 3 nodes in total and 2 shards with one replica each, total disk: 5.6 TB and JVM Heap: 95.8 GB per day index size is 40 GB with 110m documents. I …

---

## [Split data in painless](https://discuss.elastic.co/t/split-data-in-painless/327576)

<div class="topic-metadata">

**Author:** [@Daniel\_Lopez](https://discuss.elastic.co/u/Daniel_Lopez)\
**Replies:** 2\
**Last updated:** [March 27, 2023, 6:28pm UTC](https://discuss.elastic.co/t/split-data-in-painless/327576 "2023-03-27T18:28:52Z")

</div>

Hi team This is part of a watcher that i'm doing, but split part is nor working, this is my example String indices = "index1\\nindex2\\n"; String\[\] arr = indices.split('\\n'); return arr; But i g…

---

## [Case\_insensitive not working on wildcard field type with cyrilic data](https://discuss.elastic.co/t/case-insensitive-not-working-on-wildcard-field-type-with-cyrilic-data/326839)

<div class="topic-metadata">

**Author:** [@irfan94](https://discuss.elastic.co/u/irfan94)\
**Replies:** 3\
**Last updated:** [March 27, 2023, 6:27pm UTC](https://discuss.elastic.co/t/case-insensitive-not-working-on-wildcard-field-type-with-cyrilic-data/326839 "2023-03-27T18:27:12Z")

</div>

Hello, When you have an index with field that its type is wildcard and its filled with Cyrillic data and then when you perform wildcard query with case\_insensitive: true, no documents are found. Note: we are currently …

---

## [Comparison between index size and doc source size](https://discuss.elastic.co/t/comparison-between-index-size-and-doc-source-size/328596)

<div class="topic-metadata">

**Author:** [@AlessandroKP](https://discuss.elastic.co/u/AlessandroKP)\
**Replies:** 4\
**Last updated:** [March 27, 2023, 6:18pm UTC](https://discuss.elastic.co/t/comparison-between-index-size-and-doc-source-size/328596 "2023-03-27T18:18:20Z")

</div>

Hello, I have some questions regarding the mapper size plugin and how the size of the source of documents relate to the size of the index. So, I installed the mapper size plugin on a single-node Elasticsearch cluster, …

---

## [JSON KIBANA mapeo de campos](https://discuss.elastic.co/t/json-kibana-mapeo-de-campos/328525)

<div class="topic-metadata">

**Author:** [@Whazaza](https://discuss.elastic.co/u/Whazaza)\
**Replies:** 10\
**Last updated:** [March 27, 2023, 5:32pm UTC](https://discuss.elastic.co/t/json-kibana-mapeo-de-campos/328525 "2023-03-27T17:32:37Z")

</div>

Hola buenas tengo un inconveniente con logstash y kibana. Estoy intentado tomar campos de un JSON que lo tomo de un input TCP y lo mando a kibana ahora mi inconveniente es a la hora de generar un filtro en “logstash.con…

---

## [Dense vector search using script\_score](https://discuss.elastic.co/t/dense-vector-search-using-script-score/328375)

<div class="topic-metadata">

**Author:** [@Marco\_Scoppetta](https://discuss.elastic.co/u/Marco_Scoppetta)\
**Replies:** 2\
**Last updated:** [March 27, 2023, 5:13pm UTC](https://discuss.elastic.co/t/dense-vector-search-using-script-score/328375 "2023-03-27T17:13:19Z")

</div>

Hi all, I'm trying to run an exact kNN search. I've created the following index with the mappings: await client.indices.create({ index: "semantic-stuff", mappings: { properties: { data: { …

---

## [Filebeat / Haproxy : Grok in pipeline need to have both request and response headers captured to parse them](https://discuss.elastic.co/t/filebeat-haproxy-grok-in-pipeline-need-to-have-both-request-and-response-headers-captured-to-parse-them/328637)

<div class="topic-metadata">

**Author:** [@lpoujol](https://discuss.elastic.co/u/lpoujol)\
**Replies:** 0\
**Last updated:** [March 27, 2023, 4:10pm UTC](https://discuss.elastic.co/t/filebeat-haproxy-grok-in-pipeline-need-to-have-both-request-and-response-headers-captured-to-parse-them/328637 "2023-03-27T16:10:35Z")

</div>

Hi I've been testing Filebeat (8.6.2) to collect logs generated by HAProxy 2.2. The logs are directly sent to Elasticsearch, and treated by the haproxy pipeline setup by Filebeat. In my Haproxy setup, I only capture re…

---

## [Discover - eager loading](https://discuss.elastic.co/t/discover-eager-loading/328458)

<div class="topic-metadata">

**Author:** [@Kamil\_Zielinski](https://discuss.elastic.co/u/Kamil_Zielinski)\
**Replies:** 3\
**Last updated:** [March 27, 2023, 3:56pm UTC](https://discuss.elastic.co/t/discover-eager-loading/328458 "2023-03-27T15:56:46Z")

</div>

Hey, Is there a way to enable the eager loading of the logs in the Kibana/Discovery tab? I'm using Kibana 8.6v. Currently, When I type some query into the Discover search box I get around 400 rows with various JSONs. …

---

## [Synthetic Logs](https://discuss.elastic.co/t/synthetic-logs/328598)

<div class="topic-metadata">

**Author:** [@aisyaharifin](https://discuss.elastic.co/u/aisyaharifin)\
**Replies:** 1\
**Last updated:** [March 27, 2023, 3:54pm UTC](https://discuss.elastic.co/t/synthetic-logs/328598 "2023-03-27T15:54:17Z")

</div>

Hello, I noticed from my synthetic logs about this 403 error. How do I authorized the API key id? {"log.level":"warn","@timestamp":"2023-03-24T09:08:57.835Z","message":"could not load last externally recorded state, w…

---

## [Teams Connector Kibana with proxy](https://discuss.elastic.co/t/teams-connector-kibana-with-proxy/328482)

<div class="topic-metadata">

**Author:** [@federica.forti](https://discuss.elastic.co/u/federica.forti)\
**Replies:** 3\
**Last updated:** [March 27, 2023, 3:31pm UTC](https://discuss.elastic.co/t/teams-connector-kibana-with-proxy/328482 "2023-03-27T15:31:49Z")

</div>

Hi, we would like to implement Teams connector in Kibana, we create the webhook url but the problem is that this url only works if we use a proxy (we tested as curl in the server). How can we add the proxy setting in t…

---

## [Managed Elasticsearch service in AZURE, GCP and AWC](https://discuss.elastic.co/t/managed-elasticsearch-service-in-azure-gcp-and-awc/328590)

<div class="topic-metadata">

**Author:** [@mruthyu](https://discuss.elastic.co/u/mruthyu)\
**Replies:** 3\
**Last updated:** [March 27, 2023, 3:24pm UTC](https://discuss.elastic.co/t/managed-elasticsearch-service-in-azure-gcp-and-awc/328590 "2023-03-27T15:24:04Z")

</div>

Would like to know which license - Platinum or Enterprise is considered for the managed elasticsearch service on Azure, AWS and GCP?

---

## [Custom Plugins in Elasticsearch](https://discuss.elastic.co/t/custom-plugins-in-elasticsearch/328432)

<div class="topic-metadata">

**Author:** [@JAYAVARDHAN\_VEJENDLA](https://discuss.elastic.co/u/JAYAVARDHAN_VEJENDLA)\
**Replies:** 7\
**Last updated:** [March 27, 2023, 3:05pm UTC](https://discuss.elastic.co/t/custom-plugins-in-elasticsearch/328432 "2023-03-27T15:05:32Z")

</div>

Hello everyone! We are using Elasticsearch in the Legal and Investigation area. We need to perform Proximity and Wildcard Search in a single query-string query, and we found out that elasticsearch is not providing that f…

---

## [ELK version 8.6.2 - custom data-stream and index name](https://discuss.elastic.co/t/elk-version-8-6-2-custom-data-stream-and-index-name/328382)

<div class="topic-metadata">

**Author:** [@nunex\_17](https://discuss.elastic.co/u/nunex_17)\
**Replies:** 2\
**Last updated:** [March 27, 2023, 2:53pm UTC](https://discuss.elastic.co/t/elk-version-8-6-2-custom-data-stream-and-index-name/328382 "2023-03-27T14:53:13Z")

</div>

Hi. Since i updated to this new version, i can´t configure a custom name to my index and data-stream. By default, filebeat creates a Data Stream named "filebeat-8.6.2" and a index ".ds-filebeat-8.6.2-2023.03.23-000001"…

---

## [Slowlog will not show specific document searches](https://discuss.elastic.co/t/slowlog-will-not-show-specific-document-searches/328628)

<div class="topic-metadata">

**Author:** [@rschirin](https://discuss.elastic.co/u/rschirin)\
**Replies:** 0\
**Last updated:** [March 27, 2023, 2:41pm UTC](https://discuss.elastic.co/t/slowlog-will-not-show-specific-document-searches/328628 "2023-03-27T14:41:45Z")

</div>

Hey there, I was trying to get the slowlog for every search operations sent to ES. I saw that I can trace only standard search query, while I cannot see any GET operation of a specific and unique document. is this correc…

---

## [Filebeat - doesn't log kafka processor activity](https://discuss.elastic.co/t/filebeat-doesnt-log-kafka-processor-activity/328623)

<div class="topic-metadata">

**Author:** [@jose\_carlos](https://discuss.elastic.co/u/jose_carlos)\
**Replies:** 0\
**Last updated:** [March 27, 2023, 2:20pm UTC](https://discuss.elastic.co/t/filebeat-doesnt-log-kafka-processor-activity/328623 "2023-03-27T14:20:41Z")

</div>

Hi, Currently monitoring a log file with Filebeat and sending content to Kafka. All is working as expected however, unless we raise the debug level do "debug" we have no idea if Filebeat worked properly. We have a diss…

---

## [Using collapse DSL queries in Kibana?](https://discuss.elastic.co/t/using-collapse-dsl-queries-in-kibana/328500)

<div class="topic-metadata">

**Author:** [@pocketcolin](https://discuss.elastic.co/u/pocketcolin)\
**Replies:** 1\
**Last updated:** [March 27, 2023, 2:20pm UTC](https://discuss.elastic.co/t/using-collapse-dsl-queries-in-kibana/328500 "2023-03-27T14:20:35Z")

</div>

I have a DSL query that I wrote in Dev Console and I'm trying to use it in Kibana to filter down results to show in a pie chart. However, when I add the following script as a filter in Kibana, it removes the collapse por…

---

## [How to add action buttons to a Kibana DashBoard table?](https://discuss.elastic.co/t/how-to-add-action-buttons-to-a-kibana-dashboard-table/328437)

<div class="topic-metadata">

**Author:** [@LucasE](https://discuss.elastic.co/u/LucasE)\
**Replies:** 4\
**Last updated:** [March 27, 2023, 2:19pm UTC](https://discuss.elastic.co/t/how-to-add-action-buttons-to-a-kibana-dashboard-table/328437 "2023-03-27T14:19:57Z")

</div>

Hello everyone, I currently have a Kibana ( 8.3.3 ) DashBoard that uses data from Elastic Search ( Data View ). In this DashBoard I have a table that shows flows, the number of messages sent through each flow etc. I w…

---

## [Assign a role to multiple users](https://discuss.elastic.co/t/assign-a-role-to-multiple-users/328462)

<div class="topic-metadata">

**Author:** [@artax\_sb](https://discuss.elastic.co/u/artax_sb)\
**Replies:** 2\
**Last updated:** [March 27, 2023, 1:59pm UTC](https://discuss.elastic.co/t/assign-a-role-to-multiple-users/328462 "2023-03-27T13:59:29Z")

</div>

I want to assign a new role to my users, but i have 150 users.... there is a way to assign the role to all users at the same time thanks in advance

---

## [Enterprise Search : Import JSON Documents Error](https://discuss.elastic.co/t/enterprise-search-import-json-documents-error/328300)

<div class="topic-metadata">

**Author:** [@aisyaharifin](https://discuss.elastic.co/u/aisyaharifin)\
**Replies:** 1\
**Last updated:** [March 27, 2023, 1:45pm UTC](https://discuss.elastic.co/t/enterprise-search-import-json-documents-error/328300 "2023-03-27T13:45:00Z")

</div>

Hello, I have a problem in importing my JSON document, it keeps showing such errors. I already removed any space, uppercase, and null value, it still has the same error, I don't understand why. Thank you.

---

## [Create fleet agent status table for a particular space](https://discuss.elastic.co/t/create-fleet-agent-status-table-for-a-particular-space/328620)

<div class="topic-metadata">

**Author:** [@niveditakathal](https://discuss.elastic.co/u/niveditakathal)\
**Replies:** 0\
**Last updated:** [March 27, 2023, 1:37pm UTC](https://discuss.elastic.co/t/create-fleet-agent-status-table-for-a-particular-space/328620 "2023-03-27T13:37:51Z")

</div>

Hi Experts, I want to create a custom dashboard for a space in my Kibana to show all agents registered to a particular fleet agent policy. In order to achieve this I used Index pattern .fleet-agents\* with appropriate…

---

## [Synthetic monitoring for url redirect](https://discuss.elastic.co/t/synthetic-monitoring-for-url-redirect/328615)

<div class="topic-metadata">

**Author:** [@rahul\_sirugudi](https://discuss.elastic.co/u/rahul_sirugudi)\
**Replies:** 1\
**Last updated:** [March 27, 2023, 1:32pm UTC](https://discuss.elastic.co/t/synthetic-monitoring-for-url-redirect/328615 "2023-03-27T13:32:53Z")

</div>

I am trying to configure synthetic monitoring for my website, but for some reason it is not working. This is my scenario. step 1: hit the url for suppose say (https://example.com) step 2: this https://example.com will…

---

## [Logstash could not index event, how to view what server send the event](https://discuss.elastic.co/t/logstash-could-not-index-event-how-to-view-what-server-send-the-event/328619)

<div class="topic-metadata">

**Author:** [@ginokok1996](https://discuss.elastic.co/u/ginokok1996)\
**Replies:** 2\
**Last updated:** [March 27, 2023, 1:28pm UTC](https://discuss.elastic.co/t/logstash-could-not-index-event-how-to-view-what-server-send-the-event/328619 "2023-03-27T13:28:27Z")

</div>

Hi, We are currently receiving quite some errors relating to the same issue: \[2023-03-27T15:13:43,994\]\[WARN \]\[logstash.outputs.elasticsearch\] Could not index event to Elasticsearch. {:status=\>400, :action=\>\["index", {:…

[Previous page](https://discuss.elastic.co/latest.md?page=731)

[Next page](https://discuss.elastic.co/latest.md?page=733)
