# Latest

**URL:** https://discuss.elastic.co/latest.md?page=736

[Latest](https://discuss.elastic.co/latest.md) · [Categories](https://discuss.elastic.co/categories.md) · [Tags](https://discuss.elastic.co/tags.md)

**Page:** 737

---

## [How does document update work under the hood?](https://discuss.elastic.co/t/how-does-document-update-work-under-the-hood/328392)

<div class="topic-metadata">

**Author:** [@egalpin](https://discuss.elastic.co/u/egalpin)\
**Replies:** 2\
**Last updated:** [March 23, 2023, 9:10pm UTC](https://discuss.elastic.co/t/how-does-document-update-work-under-the-hood/328392 "2023-03-23T21:10:32Z")

</div>

Hi all! I’m curious to learn about how the process of document update (and upsert/partial upsert) works under the hood. I know that Lucene segments are immutable and that “deleting” a doc is a soft delete by way of tomb…

---

## [Vega tree graph in Kibana: How to filter the second level data node using Kibana filter control](https://discuss.elastic.co/t/vega-tree-graph-in-kibana-how-to-filter-the-second-level-data-node-using-kibana-filter-control/328362)

<div class="topic-metadata">

**Author:** [@Dimple.P](https://discuss.elastic.co/u/Dimple.P)\
**Replies:** 0\
**Last updated:** [March 23, 2023, 3:26pm UTC](https://discuss.elastic.co/t/vega-tree-graph-in-kibana-how-to-filter-the-second-level-data-node-using-kibana-filter-control/328362 "2023-03-23T15:26:21Z")

</div>

Hi Team, I wrote the following code to the Kibana custom visualizations widget; I want to filter only Student1 node and it's child nodes, but when I try, it expects its parent node to be filtered. This filtering can be …

---

## [Kibana custom visualizations widget (Vega) - to bind data using API](https://discuss.elastic.co/t/kibana-custom-visualizations-widget-vega-to-bind-data-using-api/328365)

<div class="topic-metadata">

**Author:** [@Dimple.P](https://discuss.elastic.co/u/Dimple.P)\
**Replies:** 0\
**Last updated:** [March 23, 2023, 3:41pm UTC](https://discuss.elastic.co/t/kibana-custom-visualizations-widget-vega-to-bind-data-using-api/328365 "2023-03-23T15:41:59Z")

</div>

Hi Team, Binding API response in Kibana Vega. Is it possible to bind API response in Kibana Vega to dynamically bind the data?

---

## [How to add yml files to a forum post reply](https://discuss.elastic.co/t/how-to-add-yml-files-to-a-forum-post-reply/328396)

<div class="topic-metadata">

**Author:** [@iqworks](https://discuss.elastic.co/u/iqworks)\
**Replies:** 1\
**Last updated:** [March 23, 2023, 8:55pm UTC](https://discuss.elastic.co/t/how-to-add-yml-files-to-a-forum-post-reply/328396 "2023-03-23T20:55:35Z")

</div>

In a forum post i created, i got a reply that requested my ymls for them to see how they were configured. But I dont see how to add ymls, only cut and paste, and some of these ymls are big. thanks for any suggestions or…

---

## [Search in Kibana with big amount of data](https://discuss.elastic.co/t/search-in-kibana-with-big-amount-of-data/328324)

<div class="topic-metadata">

**Author:** [@vladislav](https://discuss.elastic.co/u/vladislav)\
**Replies:** 3\
**Last updated:** [March 23, 2023, 8:55pm UTC](https://discuss.elastic.co/t/search-in-kibana-with-big-amount-of-data/328324 "2023-03-23T20:55:05Z")

</div>

Hello! Thanks for help in advance. I have a pretty big index about 80+ Gib of data containing multiple fields, such as ip addresses, time, requests, etc. And I need to make a search of around 1000 unique addresses in t…

---

## [Options for log collection from client applications](https://discuss.elastic.co/t/options-for-log-collection-from-client-applications/328288)

<div class="topic-metadata">

**Author:** [@malliaridis](https://discuss.elastic.co/u/malliaridis)\
**Replies:** 2\
**Last updated:** [March 23, 2023, 8:10pm UTC](https://discuss.elastic.co/t/options-for-log-collection-from-client-applications/328288 "2023-03-23T20:10:14Z")

</div>

tl;dr If I have generated logs on mobile applications / mobile devices and desktop PCs (owned by users) and stored them in files or embedded databases, what options are available and recommended to collect these logs in…

---

## [Fscrawler - change the index mapping，reduce redundant field or object](https://discuss.elastic.co/t/fscrawler-change-the-index-mapping-reduce-redundant-field-or-object/328296)

<div class="topic-metadata">

**Author:** [@bolo](https://discuss.elastic.co/u/bolo)\
**Replies:** 4\
**Last updated:** [March 23, 2023, 8:04pm UTC](https://discuss.elastic.co/t/fscrawler-change-the-index-mapping-reduce-redundant-field-or-object/328296 "2023-03-23T20:04:04Z")

</div>

i am new to fscrawler and really appreciate it. i know, the mapping can be changed. But to which content？just the analyzer? or the field type ? or the whole structure(because i dont want too much inner object). thank you …

---

## [Strange authentication error](https://discuss.elastic.co/t/strange-authentication-error/328385)

<div class="topic-metadata">

**Author:** [@PTLyon](https://discuss.elastic.co/u/PTLyon)\
**Replies:** 2\
**Last updated:** [March 23, 2023, 7:59pm UTC](https://discuss.elastic.co/t/strange-authentication-error/328385 "2023-03-23T19:59:12Z")

</div>

Hello, I have been running the ELK stack 8.6.2 for a month now with no problems, but I had security disabled. Today I attempted to enable security following this documentation: https://www.elastic.co/guide/en/elasticse…

---

## [Error connecting to node kafka-broker:9092 (id: 1 rack: null) java.net.UnknownHostException: kafka-broker](https://discuss.elastic.co/t/error-connecting-to-node-kafka-broker-9092-id-1-rack-null-java-net-unknownhostexception-kafka-broker/327434)

<div class="topic-metadata">

**Author:** [@Rajesh\_R](https://discuss.elastic.co/u/Rajesh_R)\
**Replies:** 3\
**Last updated:** [March 23, 2023, 7:31pm UTC](https://discuss.elastic.co/t/error-connecting-to-node-kafka-broker-9092-id-1-rack-null-java-net-unknownhostexception-kafka-broker/327434 "2023-03-23T19:31:43Z")

</div>

When I use kafka plugin in logstash, I am getting the below error. \[2023-03-10T15:11:46,310\]\[WARN \]\[org.apache.kafka.clients.NetworkClient\]\[main\]\[289f84d5c44d64af9505535a5352178af25a608c83252a1c520ab39a4faa4855\] \[Consum…

---

## [Permission denied /usr/share/logstash/run](https://discuss.elastic.co/t/permission-denied-usr-share-logstash-run/327769)

<div class="topic-metadata">

**Author:** [@RJC](https://discuss.elastic.co/u/RJC)\
**Replies:** 3\
**Last updated:** [March 23, 2023, 7:29pm UTC](https://discuss.elastic.co/t/permission-denied-usr-share-logstash-run/327769 "2023-03-23T19:29:51Z")

</div>

I am getting the following error message when starting Logstash on a Linux server: \[ERROR\]\[logstash.java.pipeline \]\[main\] Pipeline worker error, the pipeline will be stopped (:pipeline\_id=\>"main", :error=\>" (EACCESS) Pe…

---

## [Strip array off of ndjson data set using elasticsearch pipeline](https://discuss.elastic.co/t/strip-array-off-of-ndjson-data-set-using-elasticsearch-pipeline/328118)

<div class="topic-metadata">

**Author:** [@nika](https://discuss.elastic.co/u/nika)\
**Replies:** 4\
**Last updated:** [March 23, 2023, 6:44pm UTC](https://discuss.elastic.co/t/strip-array-off-of-ndjson-data-set-using-elasticsearch-pipeline/328118 "2023-03-23T18:44:08Z")

</div>

Hello, I have data being ingested into elasticsearch (currently using version 7.3) sent to it from filebeat (7.3). The logs are in ndjson format. A section of the data is in the format {"tagset": {"username": { "domain…

---

## [Logstash S3 input not deleting files](https://discuss.elastic.co/t/logstash-s3-input-not-deleting-files/328386)

<div class="topic-metadata">

**Author:** [@true64gurus](https://discuss.elastic.co/u/true64gurus)\
**Replies:** 0\
**Last updated:** [March 23, 2023, 6:17pm UTC](https://discuss.elastic.co/t/logstash-s3-input-not-deleting-files/328386 "2023-03-23T18:17:41Z")

</div>

I am using logstash S3 input plugin. The plugin is not deleting logs post ingestion. I am running logstsash docker on VM and have "delete =\> true". I have job running to delete logs older than 7 days and this is how I …

---

## [Version\_conflict\_engine\_exception](https://discuss.elastic.co/t/version-conflict-engine-exception/326418)

<div class="topic-metadata">

**Author:** [@INS](https://discuss.elastic.co/u/INS)\
**Replies:** 1\
**Last updated:** [March 23, 2023, 5:38pm UTC](https://discuss.elastic.co/t/version-conflict-engine-exception/326418 "2023-03-23T17:38:35Z")

</div>

Hi Can You explain me what was happened on the kibana, it was crashed and this is the tail logs from the docker container. I'm using kibana 8.1.1 \[2023-02-23T19:59:28.069+00:00\]\[ERROR\]\[plugins.dataEnhanced.data\_enhanced…

---

## [Elastic-agent "Process another repeated request" in loop indefinitely](https://discuss.elastic.co/t/elastic-agent-process-another-repeated-request-in-loop-indefinitely/328251)

<div class="topic-metadata">

**Author:** [@Nicolas\_Pellletier](https://discuss.elastic.co/u/Nicolas_Pellletier)\
**Replies:** 5\
**Last updated:** [March 23, 2023, 4:45pm UTC](https://discuss.elastic.co/t/elastic-agent-process-another-repeated-request-in-loop-indefinitely/328251 "2023-03-23T16:45:41Z")

</div>

Hello, I've got an elastic-agent with no agent monitoring settings (meaning no Agent Logs/Mertrics collection) and only one integration policy. So my elastic-agent.yml is pretty small: id: 949c1a80-c8a9-11ed-8539-532f…

---

## [Kibana from charts to excel](https://discuss.elastic.co/t/kibana-from-charts-to-excel/328368)

<div class="topic-metadata">

**Author:** [@Fatiha](https://discuss.elastic.co/u/Fatiha)\
**Replies:** 1\
**Last updated:** [March 23, 2023, 4:41pm UTC](https://discuss.elastic.co/t/kibana-from-charts-to-excel/328368 "2023-03-23T16:41:41Z")

</div>

hi I want to developp a plugin that export from the chart in kibana to excel

---

## [Heartbeat in eks](https://discuss.elastic.co/t/heartbeat-in-eks/328360)

<div class="topic-metadata">

**Author:** [@amar12](https://discuss.elastic.co/u/amar12)\
**Replies:** 1\
**Last updated:** [March 23, 2023, 4:31pm UTC](https://discuss.elastic.co/t/heartbeat-in-eks/328360 "2023-03-23T16:31:18Z")

</div>

Hi , I want to provision the heart beat in eks , I have purchased the elastic apm account . i want to do the service uptime monitoring.

---

## [Uptime monitor status rule when all monitors down](https://discuss.elastic.co/t/uptime-monitor-status-rule-when-all-monitors-down/328094)

<div class="topic-metadata">

**Author:** [@Alexander\_A](https://discuss.elastic.co/u/Alexander_A)\
**Replies:** 3\
**Last updated:** [March 23, 2023, 4:11pm UTC](https://discuss.elastic.co/t/uptime-monitor-status-rule-when-all-monitors-down/328094 "2023-03-23T16:11:07Z")

</div>

Creating "Uptime monitor status" rule there is an option to create "Status check" when "ANY MONITOR IS DOWN" but how I can create a rule when ALL MONITORS ARE DOWN (from all locations) ANY X MONITORS ARE DOWN (from X l…

---

## [WARN message when trying to install on windows 10](https://discuss.elastic.co/t/warn-message-when-trying-to-install-on-windows-10/328348)

<div class="topic-metadata">

**Author:** [@Ene\_Dragos](https://discuss.elastic.co/u/Ene_Dragos)\
**Replies:** 10\
**Last updated:** [March 23, 2023, 4:08pm UTC](https://discuss.elastic.co/t/warn-message-when-trying-to-install-on-windows-10/328348 "2023-03-23T16:08:19Z")

</div>

Hi! I'm trying to install elasticsearch on windows and i've followed the guid on here: Install Elasticsearch with .zip on Windows | Elasticsearch Guide \[8.6\] | Elastic. The issue is, when I try to configure Elasticsearc…

---

## [Error in parsing some logs from firewall due to object being returned](https://discuss.elastic.co/t/error-in-parsing-some-logs-from-firewall-due-to-object-being-returned/328349)

<div class="topic-metadata">

**Author:** [@viera120](https://discuss.elastic.co/u/viera120)\
**Replies:** 1\
**Last updated:** [March 23, 2023, 3:57pm UTC](https://discuss.elastic.co/t/error-in-parsing-some-logs-from-firewall-due-to-object-being-returned/328349 "2023-03-23T15:57:57Z")

</div>

Hi all, The setup is: Firewall --\> Filebeat --\> Logstash --\> Elasticsearch The following error keeps appearing in /var/log/logstash/logstash-plain.log \[2023-03-23T18:03:53,651\]\[WARN \]\[logstash.outputs.elasticsearch\]\[…

---

## [Kafka sink Connector to Elasticsearch](https://discuss.elastic.co/t/kafka-sink-connector-to-elasticsearch/328361)

<div class="topic-metadata">

**Author:** [@searchwithme](https://discuss.elastic.co/u/searchwithme)\
**Replies:** 1\
**Last updated:** [March 23, 2023, 3:20pm UTC](https://discuss.elastic.co/t/kafka-sink-connector-to-elasticsearch/328361 "2023-03-23T15:20:15Z")

</div>

I am trying to set up ingestion pipeline to elasticsearch cluster via kafka sink connector. A question I have is if I have a doc that haas multiple json objects like this: \[ {"name":"abc", "company":"123","dept":"test"…

---

## [RAR file download from the internet](https://discuss.elastic.co/t/rar-file-download-from-the-internet/327072)

<div class="topic-metadata">

**Author:** [@Maretti](https://discuss.elastic.co/u/Maretti)\
**Replies:** 3\
**Last updated:** [March 23, 2023, 3:17pm UTC](https://discuss.elastic.co/t/rar-file-download-from-the-internet/327072 "2023-03-23T15:17:31Z")

</div>

I tried this rule since a lot of malware is spread using password protected RAR files Roshal Archive (RAR) or PowerShell File Downloaded from the Internet | Elastic Security Solution \[7.17\] | Elastic The Query the rule…

---

## [Wrong calculations - ruby code](https://discuss.elastic.co/t/wrong-calculations-ruby-code/328093)

<div class="topic-metadata">

**Author:** [@wedkarz014](https://discuss.elastic.co/u/wedkarz014)\
**Replies:** 1\
**Last updated:** [March 23, 2023, 3:13pm UTC](https://discuss.elastic.co/t/wrong-calculations-ruby-code/328093 "2023-03-23T15:13:40Z")

</div>

Hi all, logstash v.7.17.8 I have ~45 metrics to calculate, here is the example, code and results: ruby { code =\> " if !event.get('\[Package2VersionCreatesWithoutValidation\]\[Max\]').nil? and !e…

---

## [Sourcemaps not getting applied](https://discuss.elastic.co/t/sourcemaps-not-getting-applied/326923)

<div class="topic-metadata">

**Author:** [@skumar7](https://discuss.elastic.co/u/skumar7)\
**Replies:** 4\
**Last updated:** [March 23, 2023, 3:11pm UTC](https://discuss.elastic.co/t/sourcemaps-not-getting-applied/326923 "2023-03-23T15:11:30Z")

</div>

We have a custom node app for uploading source maps and have provided all the required details like serviceName, serviceVersion, bundlePath to upload. We are getting success message for all the source maps but when we tr…

---

## [How to Install heartbeat in Openshift](https://discuss.elastic.co/t/how-to-install-heartbeat-in-openshift/328048)

<div class="topic-metadata">

**Author:** [@kiran7373](https://discuss.elastic.co/u/kiran7373)\
**Replies:** 1\
**Last updated:** [March 23, 2023, 3:06pm UTC](https://discuss.elastic.co/t/how-to-install-heartbeat-in-openshift/328048 "2023-03-23T15:06:57Z")

</div>

Our need is to install heartbeat service in Openshift . Unable to find good documentation . Can anyone please suggest.

---

## [\[Logstash\] SSL TCP input certificate issue](https://discuss.elastic.co/t/logstash-ssl-tcp-input-certificate-issue/328220)

<div class="topic-metadata">

**Author:** [@perezdev](https://discuss.elastic.co/u/perezdev)\
**Replies:** 1\
**Last updated:** [March 23, 2023, 3:00pm UTC](https://discuss.elastic.co/t/logstash-ssl-tcp-input-certificate-issue/328220 "2023-03-23T15:00:44Z")

</div>

Hello, I'm trying to setup an SSL TCP input config file in Logstash to receive logs from other syslog server over TLS 1.2. For the certificates I have created the following files using openssl: openssl req -x509 -nodes…

---

## [Filebeat is not pushing the documents to kibana (through elasticsearch)](https://discuss.elastic.co/t/filebeat-is-not-pushing-the-documents-to-kibana-through-elasticsearch/328358)

<div class="topic-metadata">

**Author:** [@Maneesh545](https://discuss.elastic.co/u/Maneesh545)\
**Replies:** 0\
**Last updated:** [March 23, 2023, 2:56pm UTC](https://discuss.elastic.co/t/filebeat-is-not-pushing-the-documents-to-kibana-through-elasticsearch/328358 "2023-03-23T14:56:04Z")

</div>

I am using the below configuration in filebeat.yml to push the logs into kibana to visualize. Initially documents used to flow into kibana but since last couple of days the documents are not flowing through elasticsear…

---

## [KNN search speed](https://discuss.elastic.co/t/knn-search-speed/326961)

<div class="topic-metadata">

**Author:** [@dendog1](https://discuss.elastic.co/u/dendog1)\
**Replies:** 11\
**Last updated:** [March 23, 2023, 2:38pm UTC](https://discuss.elastic.co/t/knn-search-speed/326961 "2023-03-23T14:38:07Z")

</div>

Hi! Today we are using ES mainly as a key / value store where most of our reads are just get by key. We have recently started to use KNN, where we have: Around 10MM docs. 384 dim vectors. Using cosine sim as the metr…

---

## [Slow aKNN search](https://discuss.elastic.co/t/slow-aknn-search/326915)

<div class="topic-metadata">

**Author:** [@ruslaniv](https://discuss.elastic.co/u/ruslaniv)\
**Replies:** 6\
**Last updated:** [March 23, 2023, 2:30pm UTC](https://discuss.elastic.co/t/slow-aknn-search/326915 "2023-03-23T14:30:50Z")

</div>

We have implemented vector similarity search using ES dense\_vector field and KNN option in the search API. We are using 1024 dimension embeddings and our index size is about 60 Gb for approx 11\_000\_000 documents. So our…

---

## [Feature Request for more robust vector graphics (Vega not enough) so I can generate good looking network maps (non-geographic)](https://discuss.elastic.co/t/feature-request-for-more-robust-vector-graphics-vega-not-enough-so-i-can-generate-good-looking-network-maps-non-geographic/328286)

<div class="topic-metadata">

**Author:** [@J\_Todd](https://discuss.elastic.co/u/J_Todd)\
**Replies:** 2\
**Last updated:** [March 23, 2023, 2:15pm UTC](https://discuss.elastic.co/t/feature-request-for-more-robust-vector-graphics-vega-not-enough-so-i-can-generate-good-looking-network-maps-non-geographic/328286 "2023-03-23T14:15:15Z")

</div>

I want to be able to generate, within Kibana and / or Elastic Security, non-geographic, good looking network maps like these: Currently there doesn't seem to be any way to do this in any Elastic product no matter…

---

## [Can't join elastic to microsoft active directory ldap](https://discuss.elastic.co/t/cant-join-elastic-to-microsoft-active-directory-ldap/326514)

<div class="topic-metadata">

**Author:** [@Indeed2000](https://discuss.elastic.co/u/Indeed2000)\
**Replies:** 16\
**Last updated:** [March 23, 2023, 2:05pm UTC](https://discuss.elastic.co/t/cant-join-elastic-to-microsoft-active-directory-ldap/326514 "2023-03-23T14:05:36Z")

</div>

Hi ldap users can't login on kibana: here is the log when user attempt to login: Feb 26 11:55:21 logdev kibana\[1784685\]: \[2023-02-26T11:55:21.243+03:30\]\[INFO \]\[plugins.security.routes\] Logging in with provider "bas…

[Previous page](https://discuss.elastic.co/latest.md?page=735)

[Next page](https://discuss.elastic.co/latest.md?page=737)
