# Latest

**URL:** https://discuss.elastic.co/latest.md?page=740

[Latest](https://discuss.elastic.co/latest.md) · [Categories](https://discuss.elastic.co/categories.md) · [Tags](https://discuss.elastic.co/tags.md)

**Page:** 741

---

## [How to avoid host.name field in filebeat](https://discuss.elastic.co/t/how-to-avoid-host-name-field-in-filebeat/327578)

<div class="topic-metadata">

**Author:** [@r.ganeshbabu](https://discuss.elastic.co/u/r.ganeshbabu)\
**Replies:** 4\
**Last updated:** [March 21, 2023, 4:06pm UTC](https://discuss.elastic.co/t/how-to-avoid-host-name-field-in-filebeat/327578 "2023-03-21T16:06:24Z")

</div>

Hi Team, I am sending data to elasticsearch using filebeat once the file were harvested I can see field host.name where the value is hostname of the VM { "\_index": "filebeat-7.17.6-2023.03.13-000001", "\_type":…

---

## [Query Elastic APM Data for Custom Dashboard](https://discuss.elastic.co/t/query-elastic-apm-data-for-custom-dashboard/328107)

<div class="topic-metadata">

**Author:** [@DougR](https://discuss.elastic.co/u/DougR)\
**Replies:** 1\
**Last updated:** [March 21, 2023, 4:02pm UTC](https://discuss.elastic.co/t/query-elastic-apm-data-for-custom-dashboard/328107 "2023-03-21T16:02:29Z")

</div>

As our company's Elastic Cloud admin (v8.6.2), I have some users who would EITHER like to include a component from the Obervability-\>APM Overview as part of a custom dashboard OR build a similar visualization from APM da…

---

## [Strange behaviour with APM and negation filters](https://discuss.elastic.co/t/strange-behaviour-with-apm-and-negation-filters/327831)

<div class="topic-metadata">

**Author:** [@Jeremy\_Cohen\_Solal](https://discuss.elastic.co/u/Jeremy_Cohen_Solal)\
**Replies:** 3\
**Last updated:** [March 21, 2023, 3:53pm UTC](https://discuss.elastic.co/t/strange-behaviour-with-apm-and-negation-filters/327831 "2023-03-21T15:53:58Z")

</div>

Kibana version: tested on 7.17.8 and latest (8) locally Elasticsearch version: same APM Server version: same APM Agent language and version: python Browser version: chrome Original install method (e.g. download page…

---

## [To Know about Legacy Index Template](https://discuss.elastic.co/t/to-know-about-legacy-index-template/327180)

<div class="topic-metadata">

**Author:** [@anushyaadam](https://discuss.elastic.co/u/anushyaadam)\
**Replies:** 3\
**Last updated:** [March 21, 2023, 3:25pm UTC](https://discuss.elastic.co/t/to-know-about-legacy-index-template/327180 "2023-03-21T15:25:06Z")

</div>

Hi Team, We changed the ILM of one of the index from 10days to 7days, but we can see the Legacy index templates still showing ILM as 10days. If present ILM of 7days doesn't work, will it consider the older ILM of 10day…

---

## [Metricbeat setup: one-time?](https://discuss.elastic.co/t/metricbeat-setup-one-time/327959)

<div class="topic-metadata">

**Author:** [@NominaSumpta](https://discuss.elastic.co/u/NominaSumpta)\
**Replies:** 11\
**Last updated:** [March 21, 2023, 2:02pm UTC](https://discuss.elastic.co/t/metricbeat-setup-one-time/327959 "2023-03-21T14:02:55Z")

</div>

Is metricbeat setup meant to be run once per cluster? The documentation (Metricbeat quick start: installation and configuration | Metricbeat Reference \[8.6\] | Elastic) does not say. It is implied that this command is m…

---

## [Use Graph inside plugin](https://discuss.elastic.co/t/use-graph-inside-plugin/328129)

<div class="topic-metadata">

**Author:** [@Sheereen](https://discuss.elastic.co/u/Sheereen)\
**Replies:** 5\
**Last updated:** [March 21, 2023, 2:25pm UTC](https://discuss.elastic.co/t/use-graph-inside-plugin/328129 "2023-03-21T14:25:38Z")

</div>

Hi, I am developing an external plugin using React. I want to draw graphs inside the same. Is there a library or api using which I can draw custom graphs inside the plugin? Thanks

---

## [Extract from ElasticSearch, into Kafka, continuously add any new ES updates using logstash](https://discuss.elastic.co/t/extract-from-elasticsearch-into-kafka-continuously-add-any-new-es-updates-using-logstash/328172)

<div class="topic-metadata">

**Author:** [@aniketdatir](https://discuss.elastic.co/u/aniketdatir)\
**Replies:** 0\
**Last updated:** [March 21, 2023, 2:21pm UTC](https://discuss.elastic.co/t/extract-from-elasticsearch-into-kafka-continuously-add-any-new-es-updates-using-logstash/328172 "2023-03-21T14:21:20Z")

</div>

Hi Team, My objective is to add latest ES index documents to kafka Below is my logstash conf -\> ''' input { elasticsearch { hosts =\> \["IP"\] index =\> "Index\_name" query =\> '{"query":{"range":{"@timestamp":{"gte": …

---

## [Logstash Parse stingyfied json to seperate json fieldsl](https://discuss.elastic.co/t/logstash-parse-stingyfied-json-to-seperate-json-fieldsl/327097)

<div class="topic-metadata">

**Author:** [@PRASHANT\_MEHTA](https://discuss.elastic.co/u/PRASHANT_MEHTA)\
**Replies:** 0\
**Last updated:** [March 6, 2023, 3:13pm UTC](https://discuss.elastic.co/t/logstash-parse-stingyfied-json-to-seperate-json-fieldsl/327097 "2023-03-06T15:13:24Z")

</div>

Hello All, I've a column in oracle table PACKAGE\_DATA and it has json like string in it and I would like to get every fileds and its value seperate: PACKAGE\_DATA Column data {"status":"READY\_FOR\_PROCESSING","errorData…

---

## [Logstash filter to process jason array fileds as seperate fileds in elastic indexl](https://discuss.elastic.co/t/logstash-filter-to-process-jason-array-fileds-as-seperate-fileds-in-elastic-indexl/326874)

<div class="topic-metadata">

**Author:** [@PRASHANT\_MEHTA](https://discuss.elastic.co/u/PRASHANT_MEHTA)\
**Replies:** 9\
**Last updated:** [March 15, 2023, 3:56pm UTC](https://discuss.elastic.co/t/logstash-filter-to-process-jason-array-fileds-as-seperate-fileds-in-elastic-indexl/326874 "2023-03-15T15:56:53Z")

</div>

Hello All, After trying several time,I'm unable to process one column in oracle table that contains json data and I would require every field in that as seperate filed created in elastic index.Could someone guide what a…

---

## [Filtering two different nested fields in the same agg](https://discuss.elastic.co/t/filtering-two-different-nested-fields-in-the-same-agg/328169)

<div class="topic-metadata">

**Author:** [@ndtreviv](https://discuss.elastic.co/u/ndtreviv)\
**Replies:** 0\
**Last updated:** [March 21, 2023, 1:55pm UTC](https://discuss.elastic.co/t/filtering-two-different-nested-fields-in-the-same-agg/328169 "2023-03-21T13:55:39Z")

</div>

I understand how to filter on two nested fields using sub aggregations and get individual doc\_counts out of them, but I want to filter and count one nested field by the value of another nested field. eg: Imagine a docu…

---

## [Request API to obtain active alerts](https://discuss.elastic.co/t/request-api-to-obtain-active-alerts/326461)

<div class="topic-metadata">

**Author:** [@fabien9402](https://discuss.elastic.co/u/fabien9402)\
**Replies:** 4\
**Last updated:** [March 21, 2023, 1:27pm UTC](https://discuss.elastic.co/t/request-api-to-obtain-active-alerts/326461 "2023-03-21T13:27:45Z")

</div>

Hello everyone, On the Kibana interface I have a rule called "No logs from docker", this is a "Log threshold" rule which should tell me when I have not received a log containing the "event.dataset" with value "docker.co…

---

## [ELK APM Security (RUM agents)](https://discuss.elastic.co/t/elk-apm-security-rum-agents/328158)

<div class="topic-metadata">

**Author:** [@Shalinicts](https://discuss.elastic.co/u/Shalinicts)\
**Replies:** 4\
**Last updated:** [March 21, 2023, 1:27pm UTC](https://discuss.elastic.co/t/elk-apm-security-rum-agents/328158 "2023-03-21T13:27:40Z")

</div>

Hi Team, Hi Team, APM server - is implemented in a Linux server. APM agent - RUM.JS AWS Loadbalancer URL (https:x.x.x.x) is implemented between APM agents and APM server. APM agent send data to this loadbalancing…

---

## [Updating an existing field using path data](https://discuss.elastic.co/t/updating-an-existing-field-using-path-data/328110)

<div class="topic-metadata">

**Author:** [@Jeferson\_Schiavinato](https://discuss.elastic.co/u/Jeferson_Schiavinato)\
**Replies:** 5\
**Last updated:** [March 21, 2023, 1:07pm UTC](https://discuss.elastic.co/t/updating-an-existing-field-using-path-data/328110 "2023-03-21T13:07:36Z")

</div>

Hello Guys, I am using a path which is formed by /dir/subdir/filename\_log.gz. I want to extract the filename and update an existent Field called Hostname with this information. I have tried to use this code, but I had…

---

## [Offline plugin needed elf\_elk](https://discuss.elastic.co/t/offline-plugin-needed-elf-elk/328163)

<div class="topic-metadata">

**Author:** [@UsmanNiazi](https://discuss.elastic.co/u/UsmanNiazi)\
**Replies:** 4\
**Last updated:** [March 21, 2023, 12:48pm UTC](https://discuss.elastic.co/t/offline-plugin-needed-elf-elk/328163 "2023-03-21T12:48:39Z")

</div>

Hi I need to install Salesforce Event Log File on ELK Stack. But it is giving error. Can you please provide the offline plugin. I have tried to download the plugin from below but its not working. Giving errors when try …

---

## [Merge 2 Clusters with same name](https://discuss.elastic.co/t/merge-2-clusters-with-same-name/328065)

<div class="topic-metadata">

**Author:** [@devarajsit](https://discuss.elastic.co/u/devarajsit)\
**Replies:** 5\
**Last updated:** [March 21, 2023, 12:09pm UTC](https://discuss.elastic.co/t/merge-2-clusters-with-same-name/328065 "2023-03-21T12:09:20Z")

</div>

Hi Team, Is there any way where we can merge 2 clusters with same name to 1. Scenario is... will have an existing cluster with name xyz and have some data. Will create additional cluster in different nodes with same na…

---

## [Kibana Canvas drop-down filter not updating count metric correctly](https://discuss.elastic.co/t/kibana-canvas-drop-down-filter-not-updating-count-metric-correctly/328062)

<div class="topic-metadata">

**Author:** [@cristinan](https://discuss.elastic.co/u/cristinan)\
**Replies:** 2\
**Last updated:** [March 21, 2023, 11:32am UTC](https://discuss.elastic.co/t/kibana-canvas-drop-down-filter-not-updating-count-metric-correctly/328062 "2023-03-21T11:32:55Z")

</div>

My metric shows okay on dateTime filter, but not on drop down filter. The date time filter uses a column pmt-stsDtTm which is to be found in indices queried to populate drop-down filters. I have uploaded also…

---

## [Is there a way to get less used/searched logs in Elasticsearch](https://discuss.elastic.co/t/is-there-a-way-to-get-less-used-searched-logs-in-elasticsearch/328081)

<div class="topic-metadata">

**Author:** [@Amulya\_Nanda](https://discuss.elastic.co/u/Amulya_Nanda)\
**Replies:** 5\
**Last updated:** [March 21, 2023, 11:24am UTC](https://discuss.elastic.co/t/is-there-a-way-to-get-less-used-searched-logs-in-elasticsearch/328081 "2023-03-21T11:24:07Z")

</div>

Hi Team, We are looking to list out less usage logs in Elasticsearch. For example: we have logs getting ingested from many setups. We wanted to query/ or list out less used logs from setups basis. How can we get the d…

---

## [Display date range](https://discuss.elastic.co/t/display-date-range/328087)

<div class="topic-metadata">

**Author:** [@Igor\_Stankovic](https://discuss.elastic.co/u/Igor_Stankovic)\
**Replies:** 2\
**Last updated:** [March 21, 2023, 10:57am UTC](https://discuss.elastic.co/t/display-date-range/328087 "2023-03-21T10:57:42Z")

</div>

Hi there! I am wondering if there is a possibility to display the selected date range filter in a lens in Kibana. The issue for me is that when in full screen in view mode, the currently selected date range is hidden a…

---

## [Error: failed to perform any bulk index operations: 429 Too Many Requests](https://discuss.elastic.co/t/error-failed-to-perform-any-bulk-index-operations-429-too-many-requests/328074)

<div class="topic-metadata">

**Author:** [@Nicolas\_Pelletier](https://discuss.elastic.co/u/Nicolas_Pelletier)\
**Replies:** 10\
**Last updated:** [March 21, 2023, 10:07am UTC](https://discuss.elastic.co/t/error-failed-to-perform-any-bulk-index-operations-429-too-many-requests/328074 "2023-03-21T10:07:04Z")

</div>

Hello, I know that there is already a lot of post on (github | stackoverflow | here) about this error and how to fix it but despite the reading of all of these ones i was not able to get rid of this error: Here is a sn…

---

## [Ingest logs from S3 bucket](https://discuss.elastic.co/t/ingest-logs-from-s3-bucket/328155)

<div class="topic-metadata">

**Author:** [@rahul\_sirugudi](https://discuss.elastic.co/u/rahul_sirugudi)\
**Replies:** 0\
**Last updated:** [March 21, 2023, 10:25am UTC](https://discuss.elastic.co/t/ingest-logs-from-s3-bucket/328155 "2023-03-21T10:25:43Z")

</div>

Currently i am using elk stack to ingest only warning and errors logs to Elasticsearch server. Also i am using elastic beanstalk to rotate logs to S3 bucket. Now as i ingest only warning and error logs sometimes i need …

---

## [Import from Azure Log Analytics Workspace](https://discuss.elastic.co/t/import-from-azure-log-analytics-workspace/328144)

<div class="topic-metadata">

**Author:** [@tigerkungen](https://discuss.elastic.co/u/tigerkungen)\
**Replies:** 0\
**Last updated:** [March 21, 2023, 8:57am UTC](https://discuss.elastic.co/t/import-from-azure-log-analytics-workspace/328144 "2023-03-21T08:57:41Z")

</div>

What is the recommended design for importing logs from Azure Log Analytics Workspace to Elastic Cloud? Read somewhere that you could export direct to elastic via the advanced menu in Azure Log Analytics workspace. But …

---

## [Overwrite data VS data duplication](https://discuss.elastic.co/t/overwrite-data-vs-data-duplication/328143)

<div class="topic-metadata">

**Author:** [@m3bgwad](https://discuss.elastic.co/u/m3bgwad)\
**Replies:** 0\
**Last updated:** [March 21, 2023, 8:53am UTC](https://discuss.elastic.co/t/overwrite-data-vs-data-duplication/328143 "2023-03-21T08:53:18Z")

</div>

Hello, every all, What is the goal of handling the data duplication using a fingerprint filter, In my opinion, this is overwritten data, not preventing the duplication. Let's say the overwrite is removing the oldest an…

---

## [My Kibana Dashboard shows 350 percentage or more for CPU utilization for Servers.. i wanted to have the vaules under 100 percentage](https://discuss.elastic.co/t/my-kibana-dashboard-shows-350-percentage-or-more-for-cpu-utilization-for-servers-i-wanted-to-have-the-vaules-under-100-percentage/328141)

<div class="topic-metadata">

**Author:** [@AKAM14](https://discuss.elastic.co/u/AKAM14)\
**Replies:** 0\
**Last updated:** [March 21, 2023, 8:40am UTC](https://discuss.elastic.co/t/my-kibana-dashboard-shows-350-percentage-or-more-for-cpu-utilization-for-servers-i-wanted-to-have-the-vaules-under-100-percentage/328141 "2023-03-21T08:40:55Z")

</div>

ELK 7.17.3 , KIBANA : 7.17.3 I have created Kibana Dashboards - there is a Average CPU Utilization dashboard for Application servers - the graph shows 350 or 250 percentage for cpu . which is quite confusing . I would…

---

## [What are logstash-plain-YYYY-MM-DD.log.gz and logstash-deprecation-YYYY-MM-DD.log.gz?](https://discuss.elastic.co/t/what-are-logstash-plain-yyyy-mm-dd-log-gz-and-logstash-deprecation-yyyy-mm-dd-log-gz/328125)

<div class="topic-metadata">

**Author:** [@ohaya](https://discuss.elastic.co/u/ohaya)\
**Replies:** 1\
**Last updated:** [March 21, 2023, 8:21am UTC](https://discuss.elastic.co/t/what-are-logstash-plain-yyyy-mm-dd-log-gz-and-logstash-deprecation-yyyy-mm-dd-log-gz/328125 "2023-03-21T08:21:37Z")

</div>

Hi, I'm fairly new working with logstash (and actually the entire ELK components), but am trying to determine why some logs are not being ingested and indexed. While I was investigating this, I noticed that on the mach…

---

## [Sending data from 2 logstash nodes to an elasticsearch cluster](https://discuss.elastic.co/t/sending-data-from-2-logstash-nodes-to-an-elasticsearch-cluster/328128)

<div class="topic-metadata">

**Author:** [@Shreesh\_Narayanan](https://discuss.elastic.co/u/Shreesh_Narayanan)\
**Replies:** 4\
**Last updated:** [March 21, 2023, 6:29am UTC](https://discuss.elastic.co/t/sending-data-from-2-logstash-nodes-to-an-elasticsearch-cluster/328128 "2023-03-21T06:29:34Z")

</div>

Hi Folks, I have 2 logstash nodes (version -8.6.2) that i want to send data to 2 elasticsearch nodes (version -8.6.2) ( a third node will be added soon to the cluster) . Do i just mention the elasticsearch nodes' in t…

---

## [Sort on multiple fields Not working](https://discuss.elastic.co/t/sort-on-multiple-fields-not-working/328131)

<div class="topic-metadata">

**Author:** [@\_baba](https://discuss.elastic.co/u/_baba)\
**Replies:** 2\
**Last updated:** [March 21, 2023, 6:27am UTC](https://discuss.elastic.co/t/sort-on-multiple-fields-not-working/328131 "2023-03-21T06:27:58Z")

</div>

Hi, I'm trying to sort on multiple fields like - sort on field1 first if there is a tie on field1, sort based on field 2. POST sort\_logic/\_doc { "field1" : 4, "field2" : "4" } POST sort\_logic/\_doc { "field1" : …

---

## [How to specify "bulk\_path" in elasticsearch output on logstash config](https://discuss.elastic.co/t/how-to-specify-bulk-path-in-elasticsearch-output-on-logstash-config/328130)

<div class="topic-metadata">

**Author:** [@Shreesh\_Narayanan](https://discuss.elastic.co/u/Shreesh_Narayanan)\
**Replies:** 0\
**Last updated:** [March 21, 2023, 5:49am UTC](https://discuss.elastic.co/t/how-to-specify-bulk-path-in-elasticsearch-output-on-logstash-config/328130 "2023-03-21T05:49:19Z")

</div>

Hello, how do i mention "bulk\_path" in the ES output in logstash ? this is how it's currently implemented (testing) , but i wanted to confirm if i'm doing is correct I have 2 elasticsearch nodes ( a 3rd one will be pr…

---

## [Cases API not working on ELK 8.1](https://discuss.elastic.co/t/cases-api-not-working-on-elk-8-1/328066)

<div class="topic-metadata">

**Author:** [@nitisha](https://discuss.elastic.co/u/nitisha)\
**Replies:** 4\
**Last updated:** [March 21, 2023, 5:52am UTC](https://discuss.elastic.co/t/cases-api-not-working-on-elk-8-1/328066 "2023-03-21T05:52:27Z")

</div>

Hi, I am running ELK stack 8.1 in our production environment and would like to create cases based on the log alerts we're filtering using grok pattern. As I understood correctly beginning 8.2 version, we have an option…

---

## [Elasticsearch Java Client create query for field with list of values](https://discuss.elastic.co/t/elasticsearch-java-client-create-query-for-field-with-list-of-values/328040)

<div class="topic-metadata">

**Author:** [@tcpeiris](https://discuss.elastic.co/u/tcpeiris)\
**Replies:** 2\
**Last updated:** [March 20, 2023, 1:59pm UTC](https://discuss.elastic.co/t/elasticsearch-java-client-create-query-for-field-with-list-of-values/328040 "2023-03-20T13:59:32Z")

</div>

String searchText = "TEST"; .query(q -\> q.bool(b -\> b .must(c-\> c .match(t -\> t .field("FI…

---

## ["dynamic method \[java.lang.Long, toInstant/0\] not found"](https://discuss.elastic.co/t/dynamic-method-java-lang-long-toinstant-0-not-found/328127)

<div class="topic-metadata">

**Author:** [@saupuran](https://discuss.elastic.co/u/saupuran)\
**Replies:** 0\
**Last updated:** [March 21, 2023, 5:36am UTC](https://discuss.elastic.co/t/dynamic-method-java-lang-long-toinstant-0-not-found/328127 "2023-03-21T05:36:55Z")

</div>

Currently we are using 'LogDate' as scripted field with script doc\['transactiondate'\].value to convert unix time format of 'transactiondate' into human readable date format. When we apply filter with 'LogDate', condition…

[Previous page](https://discuss.elastic.co/latest.md?page=739)

[Next page](https://discuss.elastic.co/latest.md?page=741)
