# Latest

**URL:** https://discuss.elastic.co/latest.md?page=735

[Latest](https://discuss.elastic.co/latest.md) · [Categories](https://discuss.elastic.co/categories.md) · [Tags](https://discuss.elastic.co/tags.md)

**Page:** 736

---

## [Context suggester with search api](https://discuss.elastic.co/t/context-suggester-with-search-api/328245)

<div class="topic-metadata">

**Author:** [@mangeshs](https://discuss.elastic.co/u/mangeshs)\
**Replies:** 2\
**Last updated:** [March 24, 2023, 12:13pm UTC](https://discuss.elastic.co/t/context-suggester-with-search-api/328245 "2023-03-24T12:13:09Z")

</div>

I am using Elasticsearch 7.4 and java client api. I want to use context suggester with search api given in this document Suggesters | Elasticsearch Guide \[8.6\] | Elastic can any one give me any sample documents which e…

---

## [Network Policy, elastic-operator eck k8s Openshift](https://discuss.elastic.co/t/network-policy-elastic-operator-eck-k8s-openshift/328457)

<div class="topic-metadata">

**Author:** [@splitmessage88](https://discuss.elastic.co/u/splitmessage88)\
**Replies:** 0\
**Last updated:** [March 24, 2023, 12:07pm UTC](https://discuss.elastic.co/t/network-policy-elastic-operator-eck-k8s-openshift/328457 "2023-03-24T12:07:59Z")

</div>

Hi team, We are stuck with the networkPolicy between elastic-operator and to our respective namespace for elastic stack. The communication between elastic-operator and elastic-agent and kibana works fine but elasticsea…

---

## [Logstash nested json parsing,getting every nested json as seperate field](https://discuss.elastic.co/t/logstash-nested-json-parsing-getting-every-nested-json-as-seperate-field/327956)

<div class="topic-metadata">

**Author:** [@PRASHANT\_MEHTA](https://discuss.elastic.co/u/PRASHANT_MEHTA)\
**Replies:** 12\
**Last updated:** [March 24, 2023, 11:51am UTC](https://discuss.elastic.co/t/logstash-nested-json-parsing-getting-every-nested-json-as-seperate-field/327956 "2023-03-24T11:51:44Z")

</div>

Hello, After trying several times I'm unable to parse below json string data coming from oracle column called: package\_data.Kindly assist how to get data in elastic to show data like below from given data. {"status":"R…

---

## [Instantiating elasticsearch processors in custom processor](https://discuss.elastic.co/t/instantiating-elasticsearch-processors-in-custom-processor/328199)

<div class="topic-metadata">

**Author:** [@CaptainAmericaFan2](https://discuss.elastic.co/u/CaptainAmericaFan2)\
**Replies:** 2\
**Last updated:** [March 24, 2023, 11:47am UTC](https://discuss.elastic.co/t/instantiating-elasticsearch-processors-in-custom-processor/328199 "2023-03-24T11:47:50Z")

</div>

Hi! I'm hoping to run language inference over a number of fields as documented in this blog: Multilingual search using language identification in Elasticsearch | Elastic Blog Because I want to run it over a number of fi…

---

## [Tenable.io integration - missing FIXED vulnerabilities](https://discuss.elastic.co/t/tenable-io-integration-missing-fixed-vulnerabilities/328351)

<div class="topic-metadata">

**Author:** [@marrc.rousseau](https://discuss.elastic.co/u/marrc.rousseau)\
**Replies:** 2\
**Last updated:** [March 24, 2023, 11:39am UTC](https://discuss.elastic.co/t/tenable-io-integration-missing-fixed-vulnerabilities/328351 "2023-03-24T11:39:42Z")

</div>

Hello, I started to test tenable.io integration (great work BTW) and found a little issue. Vulnerabilities with state FIXED are missing in logs-tenable\_io.vulnerability indexes, I can only find OPEN and REOPENED event…

---

## [Tree Vega - Change the path color based on field condition](https://discuss.elastic.co/t/tree-vega-change-the-path-color-based-on-field-condition/328452)

<div class="topic-metadata">

**Author:** [@Dimple.P](https://discuss.elastic.co/u/Dimple.P)\
**Replies:** 0\
**Last updated:** [March 24, 2023, 11:34am UTC](https://discuss.elastic.co/t/tree-vega-change-the-path-color-based-on-field-condition/328452 "2023-03-24T11:34:08Z")

</div>

Is it possible to alter the path colour of Tree Vega chart depending on a data field where the condition is, flag == 1 imply path should be in red else black in colour, I used the following code for the node and it works…

---

## [Kibana vizualization](https://discuss.elastic.co/t/kibana-vizualization/328440)

<div class="topic-metadata">

**Author:** [@kibana\_dev\_iko](https://discuss.elastic.co/u/kibana_dev_iko)\
**Replies:** 2\
**Last updated:** [March 24, 2023, 10:38am UTC](https://discuss.elastic.co/t/kibana-vizualization/328440 "2023-03-24T10:38:57Z")

</div>

hello i have a problem in kibana vizualization i can't click on source to vizualize data any help please

---

## [Need to create a bar graph for customers who are having sales less than previous month](https://discuss.elastic.co/t/need-to-create-a-bar-graph-for-customers-who-are-having-sales-less-than-previous-month/328329)

<div class="topic-metadata">

**Author:** [@Abj\_Ins](https://discuss.elastic.co/u/Abj_Ins)\
**Replies:** 4\
**Last updated:** [March 24, 2023, 10:04am UTC](https://discuss.elastic.co/t/need-to-create-a-bar-graph-for-customers-who-are-having-sales-less-than-previous-month/328329 "2023-03-24T10:04:46Z")

</div>

Hi Team, Need to create a bar graph for customers who are having sales less than previous month. Here we need departments on X-axis. Thanks.

---

## [Elasticsearch Cluster](https://discuss.elastic.co/t/elasticsearch-cluster/328443)

<div class="topic-metadata">

**Author:** [@Marco\_Batista\_12](https://discuss.elastic.co/u/Marco_Batista_12)\
**Replies:** 2\
**Last updated:** [March 24, 2023, 10:03am UTC](https://discuss.elastic.co/t/elasticsearch-cluster/328443 "2023-03-24T10:03:07Z")

</div>

Could someone help me to have a cluster with a main machine that has elasticsearch and kibana and other 9 machines with only elasticsearch that are slaves.

---

## [Backfill of data stream](https://discuss.elastic.co/t/backfill-of-data-stream/328446)

<div class="topic-metadata">

**Author:** [@obi134](https://discuss.elastic.co/u/obi134)\
**Replies:** 0\
**Last updated:** [March 24, 2023, 9:57am UTC](https://discuss.elastic.co/t/backfill-of-data-stream/328446 "2023-03-24T09:57:34Z")

</div>

Hi there, Currently we are using "normal" indexes instead of data streams in our application. But in the last days I was faced to ILM and it could be easier to implement with data streams. So I had a look if data stream…

---

## [Rule Preview not Working](https://discuss.elastic.co/t/rule-preview-not-working/327737)

<div class="topic-metadata">

**Author:** [@j91321](https://discuss.elastic.co/u/j91321)\
**Replies:** 3\
**Last updated:** [March 24, 2023, 9:55am UTC](https://discuss.elastic.co/t/rule-preview-not-working/327737 "2023-03-24T09:55:36Z")

</div>

I have this weird problem where detection engine rules preview is not working for users. Now the users have roles that grant them read access to .preview.alerts-security.alerts-\<space-id\> and All Kibana pirvileges on Ki…

---

## [How to add input fields to Eui Data Grid](https://discuss.elastic.co/t/how-to-add-input-fields-to-eui-data-grid/326567)

<div class="topic-metadata">

**Author:** [@Sheereen](https://discuss.elastic.co/u/Sheereen)\
**Replies:** 5\
**Last updated:** [March 24, 2023, 8:39am UTC](https://discuss.elastic.co/t/how-to-add-input-fields-to-eui-data-grid/326567 "2023-03-24T08:39:39Z")

</div>

Hi, I want to add input fields to my data grid. Meaning in total I'll have 10 columns After 3 columns data, I need 2 columns as input fields, and the values in the rest of the columns will depend on the values in the …

---

## [Spring Web MVC 6.x transaction names always named as DispatcherServlet#doGet](https://discuss.elastic.co/t/spring-web-mvc-6-x-transaction-names-always-named-as-dispatcherservlet-doget/328436)

<div class="topic-metadata">

**Author:** [@NickWe](https://discuss.elastic.co/u/NickWe)\
**Replies:** 1\
**Last updated:** [March 24, 2023, 8:34am UTC](https://discuss.elastic.co/t/spring-web-mvc-6-x-transaction-names-always-named-as-dispatcherservlet-doget/328436 "2023-03-24T08:34:42Z")

</div>

Kibana version: 8.5.3 Elasticsearch version: 8.5.3 APM Server version: 8.5.3 APM Agent language and version: 1.36.0 Java I noticed that the Elastic APM Java agent is not detecting Spring RestController names in S…

---

## [Improve elasticsearch aggreation performance](https://discuss.elastic.co/t/improve-elasticsearch-aggreation-performance/328434)

<div class="topic-metadata">

**Author:** [@MonikaJ](https://discuss.elastic.co/u/MonikaJ)\
**Replies:** 0\
**Last updated:** [March 24, 2023, 8:14am UTC](https://discuss.elastic.co/t/improve-elasticsearch-aggreation-performance/328434 "2023-03-24T08:14:42Z")

</div>

I am using elasticsearch aggregations to calculate counts for a faceted search. Therefore I define my general search query (e.g. status.keyword) and exlcude this filter from the status.keyword aggregation itself (the que…

---

## [Fatal error: concurrent map iteration and map write](https://discuss.elastic.co/t/fatal-error-concurrent-map-iteration-and-map-write/328350)

<div class="topic-metadata">

**Author:** [@Z4ck404](https://discuss.elastic.co/u/Z4ck404)\
**Replies:** 5\
**Last updated:** [March 24, 2023, 8:08am UTC](https://discuss.elastic.co/t/fatal-error-concurrent-map-iteration-and-map-write/328350 "2023-03-24T08:08:24Z")

</div>

I am using filebeat with google storage input and elasticsearch as output .. the filebeat starts and throws this error after few seconds : {"log.level":"warn","@timestamp":"2023-03-23T13:46:05.824Z","log.logger":"input…

---

## [.security-6 Reindex (update assistant)](https://discuss.elastic.co/t/security-6-reindex-update-assistant/328422)

<div class="topic-metadata">

**Author:** [@Moe\_Hmaidan](https://discuss.elastic.co/u/Moe_Hmaidan)\
**Replies:** 5\
**Last updated:** [March 24, 2023, 7:33am UTC](https://discuss.elastic.co/t/security-6-reindex-update-assistant/328422 "2023-03-24T07:33:48Z")

</div>

Hello, We have a cluster running elasticsearch 7.17.7, we recently decided to work on upgrading the cluster to 8.x and everything was going well, I was working on creating a snapshot when I noticed that the system indic…

---

## [Health Status is Unkown for a particular service](https://discuss.elastic.co/t/health-status-is-unkown-for-a-particular-service/326276)

<div class="topic-metadata">

**Author:** [@Divyanshu\_Raj](https://discuss.elastic.co/u/Divyanshu_Raj)\
**Replies:** 9\
**Last updated:** [March 24, 2023, 6:49am UTC](https://discuss.elastic.co/t/health-status-is-unkown-for-a-particular-service/326276 "2023-03-24T06:49:48Z")

</div>

Kibana version: 7.17.0 Elasticsearch version: 7.17.0 APM Server version: 7.17.0 APM Agent language and version: java 1.11.0 Browser version: Chrome 89 Original install method (e.g. download page, yum, deb, from sour…

---

## [License Banned Nexus IQ Vulnerability in 7.16.2](https://discuss.elastic.co/t/license-banned-nexus-iq-vulnerability-in-7-16-2/328419)

<div class="topic-metadata">

**Author:** [@PAVK\_PRASAD](https://discuss.elastic.co/u/PAVK_PRASAD)\
**Replies:** 3\
**Last updated:** [March 24, 2023, 6:31am UTC](https://discuss.elastic.co/t/license-banned-nexus-iq-vulnerability-in-7-16-2/328419 "2023-03-24T06:31:39Z")

</div>

Hi Team, We are using 7.16.2 Version of ES and we Observed "License Banned" Nexus IQ Scan issue in 7.16.2 with Elastic Search where as ES 7.10.0 doesn't have this issue. If We want go back to 7.10.0, In that version we…

---

## [2 Mongo DB collection how to merge in Logstash](https://discuss.elastic.co/t/2-mongo-db-collection-how-to-merge-in-logstash/328423)

<div class="topic-metadata">

**Author:** [@rachit](https://discuss.elastic.co/u/rachit)\
**Replies:** 0\
**Last updated:** [March 24, 2023, 6:29am UTC](https://discuss.elastic.co/t/2-mongo-db-collection-how-to-merge-in-logstash/328423 "2023-03-24T06:29:03Z")

</div>

Hi Team, Can anyone help me to merge 2 different collection of mongodb in single index in Elasticsearch with sync enable feature. Thanks

---

## [Unable to do cross cluster replication , Please help here](https://discuss.elastic.co/t/unable-to-do-cross-cluster-replication-please-help-here/328345)

<div class="topic-metadata">

**Author:** [@JayaPavani\_Pathakota](https://discuss.elastic.co/u/JayaPavani_Pathakota)\
**Replies:** 10\
**Last updated:** [March 24, 2023, 6:28am UTC](https://discuss.elastic.co/t/unable-to-do-cross-cluster-replication-please-help-here/328345 "2023-03-24T06:28:14Z")

</div>

I created two clusters in 2 data centers and I am trying to do cross cluster replication , in one of the cluster I configured leader index and in the other I did the remote configuration pointing to the cluster of leader…

---

## [Hide size parameter from URL](https://discuss.elastic.co/t/hide-size-parameter-from-url/328397)

<div class="topic-metadata">

**Author:** [@ach](https://discuss.elastic.co/u/ach)\
**Replies:** 3\
**Last updated:** [March 24, 2023, 6:18am UTC](https://discuss.elastic.co/t/hide-size-parameter-from-url/328397 "2023-03-24T06:18:14Z")

</div>

Hi all, I want to hide the size parameter from the search query URL, e.g., site.com/?q=phone&size=n\_10\_n and I want to hide '&size=n\_10\_n.' Is configuring the routing options the way to go? I would greatly appreciate i…

---

## [Visualize not works after reindex](https://discuss.elastic.co/t/visualize-not-works-after-reindex/328315)

<div class="topic-metadata">

**Author:** [@rachit](https://discuss.elastic.co/u/rachit)\
**Replies:** 11\
**Last updated:** [March 24, 2023, 5:53am UTC](https://discuss.elastic.co/t/visualize-not-works-after-reindex/328315 "2023-03-24T05:53:37Z")

</div>

Hi Team, i have merged 2 indexes with reindex Query. Billingdemo(index) filedemo(index) POST \_reindex { "source": { "index": "\*demo" }, "dest": { "index": "ReindexDemo" } } indexes merged, but now wh…

---

## [TypeError: no implicit conversion of nil into String](https://discuss.elastic.co/t/typeerror-no-implicit-conversion-of-nil-into-string/328416)

<div class="topic-metadata">

**Author:** [@kala\_y](https://discuss.elastic.co/u/kala_y)\
**Replies:** 0\
**Last updated:** [March 24, 2023, 3:38am UTC](https://discuss.elastic.co/t/typeerror-no-implicit-conversion-of-nil-into-string/328416 "2023-03-24T03:38:12Z")

</div>

2023-03-23T22:23:02.967-05:00 Copy \[2023-03-24T03:23:02,967\]\[WARN \]\[logstash.inputs.s3snssqs \]\[main\]\[97e0bbb90d3a28c08cdd88a484e0aa3737932f33f22b59839ba78170f15c7929\] Error in poller loop {:error=\>#\<TypeError: no impli…

---

## [In Metricbeat have provided the process monitoring list in system.yml but not getting process stats in the kibana dashboard](https://discuss.elastic.co/t/in-metricbeat-have-provided-the-process-monitoring-list-in-system-yml-but-not-getting-process-stats-in-the-kibana-dashboard/327183)

<div class="topic-metadata">

**Author:** [@sourabh\_rawat](https://discuss.elastic.co/u/sourabh_rawat)\
**Replies:** 2\
**Last updated:** [March 24, 2023, 3:53am UTC](https://discuss.elastic.co/t/in-metricbeat-have-provided-the-process-monitoring-list-in-system-yml-but-not-getting-process-stats-in-the-kibana-dashboard/327183 "2023-03-24T03:53:08Z")

</div>

Hi I have provided the list of processes to get monitored on my system but I am not getting stats for one of the processes for other listed processes I am getting data but. My system.yml is below # Module: system # Docs…

---

## [Hyperthreading effects on Elasticsearch performance](https://discuss.elastic.co/t/hyperthreading-effects-on-elasticsearch-performance/328402)

<div class="topic-metadata">

**Author:** [@Vadym](https://discuss.elastic.co/u/Vadym)\
**Replies:** 3\
**Last updated:** [March 24, 2023, 3:39am UTC](https://discuss.elastic.co/t/hyperthreading-effects-on-elasticsearch-performance/328402 "2023-03-24T03:39:48Z")

</div>

Hi team, What's the current recommendations regarding Hyper Threading with Elasticsearch, do we get any benefits and are there any downsides to keep HT enabled? I've seen multiple performance tests documents which clai…

---

## [Byte size in is bigger than real traffic packages in Network Explore](https://discuss.elastic.co/t/byte-size-in-is-bigger-than-real-traffic-packages-in-network-explore/328145)

<div class="topic-metadata">

**Author:** [@wishes9](https://discuss.elastic.co/u/wishes9)\
**Replies:** 2\
**Last updated:** [March 24, 2023, 3:38am UTC](https://discuss.elastic.co/t/byte-size-in-is-bigger-than-real-traffic-packages-in-network-explore/328145 "2023-03-24T03:38:22Z")

</div>

elasticsearch-8.6.1 kibana-8.6.1 logstash-8.6.1 I install packetbeat in the VM which install elastic stack. When I try to use Security - Explore - Network in Kibana, I find that the traffice Bytes account is much more…

---

## [Filebeat AWS CloudWatch input loss data](https://discuss.elastic.co/t/filebeat-aws-cloudwatch-input-loss-data/328409)

<div class="topic-metadata">

**Author:** [@jacksparrow414](https://discuss.elastic.co/u/jacksparrow414)\
**Replies:** 0\
**Last updated:** [March 24, 2023, 2:14am UTC](https://discuss.elastic.co/t/filebeat-aws-cloudwatch-input-loss-data/328409 "2023-03-24T02:14:07Z")

</div>

filebeat configuration filebeat.inputs: - type: aws-cloudwatch enabled: true log\_group\_arn: arn log\_stream\_prefix: my-logstream-prefix scan\_frequency: 10s start\_position: end access\_key\_id: omi…

---

## [Kubernetes deployment - Elastic Search](https://discuss.elastic.co/t/kubernetes-deployment-elastic-search/328384)

<div class="topic-metadata">

**Author:** [@aharo-lumificyber](https://discuss.elastic.co/u/aharo-lumificyber)\
**Replies:** 1\
**Last updated:** [March 24, 2023, 1:21am UTC](https://discuss.elastic.co/t/kubernetes-deployment-elastic-search/328384 "2023-03-24T01:21:57Z")

</div>

We currently use Elasticsearch through the Azure implementation but is getting too expensive, and I would like to know the procedure to host my own image of Elasticsearch and kibana through kubernetes. Do I need to pay f…

---

## [JSON Logstash](https://discuss.elastic.co/t/json-logstash/328403)

<div class="topic-metadata">

**Author:** [@Whazaza](https://discuss.elastic.co/u/Whazaza)\
**Replies:** 0\
**Last updated:** [March 24, 2023, 12:55am UTC](https://discuss.elastic.co/t/json-logstash/328403 "2023-03-24T00:55:06Z")

</div>

I have a problem when taking the data from my json suppose i need to take the data from this json { "header" : { "sendingApplicationNs" : "value", "sendingApplicationId" : "value", "sendingApplicationIdTy…

---

## [Multiple search criteria](https://discuss.elastic.co/t/multiple-search-criteria/328400)

<div class="topic-metadata">

**Author:** [@Sheng111](https://discuss.elastic.co/u/Sheng111)\
**Replies:** 0\
**Last updated:** [March 23, 2023, 10:52pm UTC](https://discuss.elastic.co/t/multiple-search-criteria/328400 "2023-03-23T22:52:49Z")

</div>

Hi there, one common question, how to do multiple criteria search using elasticsearch UI? for example I search for attribute A==5 and attribute B within recent 3 months; is this possible to combine above 2 filter criter…

[Previous page](https://discuss.elastic.co/latest.md?page=734)

[Next page](https://discuss.elastic.co/latest.md?page=736)
