# Latest

**URL:** https://discuss.elastic.co/latest.md?page=741

[Latest](https://discuss.elastic.co/latest.md) · [Categories](https://discuss.elastic.co/categories.md) · [Tags](https://discuss.elastic.co/tags.md)

**Page:** 742

---

## [Sort based on absolute value](https://discuss.elastic.co/t/sort-based-on-absolute-value/328078)

<div class="topic-metadata">

**Author:** [@\_baba](https://discuss.elastic.co/u/_baba)\
**Replies:** 5\
**Last updated:** [March 21, 2023, 5:36am UTC](https://discuss.elastic.co/t/sort-based-on-absolute-value/328078 "2023-03-21T05:36:07Z")

</div>

Hi, I'm looking to sort documents based on a field of long type by their absolute value. So, the change field has both positive and negative numbers. "change" : { "type" : "long" } I want to sort it in such a way th…

---

## [Index\_failed number is increasing after adding a new node to elasticsearch cluster(previously single node)](https://discuss.elastic.co/t/index-failed-number-is-increasing-after-adding-a-new-node-to-elasticsearch-cluster-previously-single-node/328098)

<div class="topic-metadata">

**Author:** [@Shreesh\_Narayanan](https://discuss.elastic.co/u/Shreesh_Narayanan)\
**Replies:** 2\
**Last updated:** [March 21, 2023, 5:32am UTC](https://discuss.elastic.co/t/index-failed-number-is-increasing-after-adding-a-new-node-to-elasticsearch-cluster-previously-single-node/328098 "2023-03-21T05:32:45Z")

</div>

Hi Folks, Today i added a new node to a previously single -node elasticsearch cluster and the process was successful . however when i look at the node stats (via the node stats API) it shows the index\_failed numbers to …

---

## [What the better way, create 400 columns with types keyword, text, float, date and boolean in index or 5 nested fields?](https://discuss.elastic.co/t/what-the-better-way-create-400-columns-with-types-keyword-text-float-date-and-boolean-in-index-or-5-nested-fields/328123)

<div class="topic-metadata">

**Author:** [@Yuri\_Khmelevsky](https://discuss.elastic.co/u/Yuri_Khmelevsky)\
**Replies:** 0\
**Last updated:** [March 21, 2023, 4:02am UTC](https://discuss.elastic.co/t/what-the-better-way-create-400-columns-with-types-keyword-text-float-date-and-boolean-in-index-or-5-nested-fields/328123 "2023-03-21T04:02:18Z")

</div>

What is the better for read and write performance? And in general is this good idea to store 400 columns in index (I know that I can store 1000 columns per index by default). I expect that one documents will have 5-15 t…

---

## [How to enriching events with "dynamic" data from a file](https://discuss.elastic.co/t/how-to-enriching-events-with-dynamic-data-from-a-file/328019)

<div class="topic-metadata">

**Author:** [@stefws](https://discuss.elastic.co/u/stefws)\
**Replies:** 9\
**Last updated:** [March 21, 2023, 3:10am UTC](https://discuss.elastic.co/t/how-to-enriching-events-with-dynamic-data-from-a-file/328019 "2023-03-21T03:10:25Z")

</div>

Tinkering with how to enrich filebeat events by tagging/labelling with data picked from a text that might change infrequently but still change (days, weeks, months). We're talking off application version data, so wheneve…

---

## [Setup global\_labels in remote apm agent configuration](https://discuss.elastic.co/t/setup-global-labels-in-remote-apm-agent-configuration/328112)

<div class="topic-metadata">

**Author:** [@barcus](https://discuss.elastic.co/u/barcus)\
**Replies:** 1\
**Last updated:** [March 21, 2023, 1:41am UTC](https://discuss.elastic.co/t/setup-global-labels-in-remote-apm-agent-configuration/328112 "2023-03-21T01:41:53Z")

</div>

Is there any way to configure global\_labels using Kibana or APM-server API for remote agent configuration, based on service name ? I can do it in agent configuration, but I would like to manage static labels remotely, t…

---

## [How to join two indexes or use an index as a lookup](https://discuss.elastic.co/t/how-to-join-two-indexes-or-use-an-index-as-a-lookup/328073)

<div class="topic-metadata">

**Author:** [@alissan](https://discuss.elastic.co/u/alissan)\
**Replies:** 5\
**Last updated:** [March 21, 2023, 1:19am UTC](https://discuss.elastic.co/t/how-to-join-two-indexes-or-use-an-index-as-a-lookup/328073 "2023-03-21T01:19:15Z")

</div>

I have log indexes with 500 million records daily in one index (logs-20230320,logs-20230321,...) And i have malicious IP addresses list ( ~150.000 records) in another index (blacklist-202303) (rebuilt every day) I need…

---

## [Strigo says "course has ended" after restarting subscription](https://discuss.elastic.co/t/strigo-says-course-has-ended-after-restarting-subscription/328116)

<div class="topic-metadata">

**Author:** [@lkey4126](https://discuss.elastic.co/u/lkey4126)\
**Replies:** 1\
**Last updated:** [March 20, 2023, 11:41pm UTC](https://discuss.elastic.co/t/strigo-says-course-has-ended-after-restarting-subscription/328116 "2023-03-20T23:41:21Z")

</div>

Course:Elasticsearch Engineer Version: \<And which particular version?\> Question: I was working through the Elasticsearch Engineer course when my subscription expired. After procuring another subscription 4 months lat…

---

## [Scripted fields in pyspark](https://discuss.elastic.co/t/scripted-fields-in-pyspark/328092)

<div class="topic-metadata">

**Author:** [@nissan15](https://discuss.elastic.co/u/nissan15)\
**Replies:** 1\
**Last updated:** [March 20, 2023, 10:41pm UTC](https://discuss.elastic.co/t/scripted-fields-in-pyspark/328092 "2023-03-20T22:41:12Z")

</div>

Hey, Is it possible to use scripted fields using pyspark? if so how can I use it? and if not - how can I query field and convert the field from float to integer in the query itself? thanks

---

## [Issue with apache Tika Extraction for Tabular Column Data in PDF](https://discuss.elastic.co/t/issue-with-apache-tika-extraction-for-tabular-column-data-in-pdf/328080)

<div class="topic-metadata">

**Author:** [@Sai\_Kiran\_solix](https://discuss.elastic.co/u/Sai_Kiran_solix)\
**Replies:** 1\
**Last updated:** [March 20, 2023, 9:05pm UTC](https://discuss.elastic.co/t/issue-with-apache-tika-extraction-for-tabular-column-data-in-pdf/328080 "2023-03-20T21:05:04Z")

</div>

I extracted a PDF that has tabular column data using apache Tika, in the result the row data from different columns are getting merged Before Extracting | Column A | Column B | | -------- | -------- | | 1 | saikiran | |…

---

## [My Runtime Script is not returning a value](https://discuss.elastic.co/t/my-runtime-script-is-not-returning-a-value/327217)

<div class="topic-metadata">

**Author:** [@jreyes25](https://discuss.elastic.co/u/jreyes25)\
**Replies:** 1\
**Last updated:** [March 20, 2023, 8:33pm UTC](https://discuss.elastic.co/t/my-runtime-script-is-not-returning-a-value/327217 "2023-03-20T20:33:10Z")

</div>

Hello, I have created a runtime field named "user". My goal is to extract the username (user=Bob) from a 'event.original' mapping which looks like this: "event.original": \[ "Mar 7 10:17:44 Bob gdm-password\]\[15454…

---

## [Changed password for metricbeat user, now I can't connect to Kibana](https://discuss.elastic.co/t/changed-password-for-metricbeat-user-now-i-cant-connect-to-kibana/327970)

<div class="topic-metadata">

**Author:** [@JacobBaynes](https://discuss.elastic.co/u/JacobBaynes)\
**Replies:** 4\
**Last updated:** [March 20, 2023, 7:41pm UTC](https://discuss.elastic.co/t/changed-password-for-metricbeat-user-now-i-cant-connect-to-kibana/327970 "2023-03-20T19:41:15Z")

</div>

Hello! The employee who set up our instance of elastic is no longer working here and he did not document how he set things up or the passwords that he created for the user that metricbeat uses to connect to the kibana/el…

---

## [Filebeat error no data coming to kibana](https://discuss.elastic.co/t/filebeat-error-no-data-coming-to-kibana/328034)

<div class="topic-metadata">

**Author:** [@Whazaza](https://discuss.elastic.co/u/Whazaza)\
**Replies:** 13\
**Last updated:** [March 20, 2023, 7:01pm UTC](https://discuss.elastic.co/t/filebeat-error-no-data-coming-to-kibana/328034 "2023-03-20T19:01:04Z")

</div>

Configure filebeat as indicated in the kibana integrations with the following steps: curl -L -O https://artifacts.elastic.co/downloads/beats/filebeat/filebeat-8.6.2-amd64.deb sudo dpkg -i filebeat-8.6.2-amd64.deb (modi…

---

## [RPM signing key is invalid on newer operating systems](https://discuss.elastic.co/t/rpm-signing-key-is-invalid-on-newer-operating-systems/327476)

<div class="topic-metadata">

**Author:** [@twilson](https://discuss.elastic.co/u/twilson)\
**Replies:** 1\
**Last updated:** [March 20, 2023, 7:04pm UTC](https://discuss.elastic.co/t/rpm-signing-key-is-invalid-on-newer-operating-systems/327476 "2023-03-20T19:04:59Z")

</div>

The signing key used for RPM packages (and I assume other package types) is no longer valid on newer operating systems since the key is SHA1 and these newer operating systems have deprecated SHA1. Specifically, I'm tryi…

---

## [My elasticsearch is not running with error code 128](https://discuss.elastic.co/t/my-elasticsearch-is-not-running-with-error-code-128/327892)

<div class="topic-metadata">

**Author:** [@Terry\_2018](https://discuss.elastic.co/u/Terry_2018)\
**Replies:** 9\
**Last updated:** [March 20, 2023, 6:54pm UTC](https://discuss.elastic.co/t/my-elasticsearch-is-not-running-with-error-code-128/327892 "2023-03-20T18:54:02Z")

</div>

Hi. I'm using Elasticsearch 8.6.2 on Ubuntu 22.04. Since a few days ago, my elastic is not running. Please help me. The system output is below. dev@logserver:~$ sudo systemctl status elasticsearch × elasticsearch.se…

---

## [Allocation Failed](https://discuss.elastic.co/t/allocation-failed/328097)

<div class="topic-metadata">

**Author:** [@fnitz](https://discuss.elastic.co/u/fnitz)\
**Replies:** 6\
**Last updated:** [March 20, 2023, 5:58pm UTC](https://discuss.elastic.co/t/allocation-failed/328097 "2023-03-20T17:58:03Z")

</div>

Hi, I've got many error messages like that: { "index" : "logstash-prod\_operations\_clear-001098", "shard" : 0, "primary" : false, "current\_state" : "unassigned", "unassigned\_info" : { "reason" : "ALLOCATIO…

---

## [How to send aggregation key one by one to webhook action](https://discuss.elastic.co/t/how-to-send-aggregation-key-one-by-one-to-webhook-action/328102)

<div class="topic-metadata">

**Author:** [@sai7276p](https://discuss.elastic.co/u/sai7276p)\
**Replies:** 0\
**Last updated:** [March 20, 2023, 5:20pm UTC](https://discuss.elastic.co/t/how-to-send-aggregation-key-one-by-one-to-webhook-action/328102 "2023-03-20T17:20:20Z")

</div>

Hi I am trying to send an aggregated hosts keys to webhook actions in parameters fields.. When I use single action and this template //{{#ctx.payload.hosts}}{{key}} {{/ctx.payload.hosts}} It perfectly sends an array …

---

## [Does Rally support benchmark the performance about deleting a type of documents?](https://discuss.elastic.co/t/does-rally-support-benchmark-the-performance-about-deleting-a-type-of-documents/328033)

<div class="topic-metadata">

**Author:** [@gloriacs](https://discuss.elastic.co/u/gloriacs)\
**Replies:** 3\
**Last updated:** [March 20, 2023, 4:53pm UTC](https://discuss.elastic.co/t/does-rally-support-benchmark-the-performance-about-deleting-a-type-of-documents/328033 "2023-03-20T16:53:08Z")

</div>

Hi all, I want to use Rally to benchmark the performance of deleting documents instead of deleting an index. Like, delete all documents from that specific day. I know elasticsearch support that by using delete\_by\_query …

---

## [Elastic Agent falling after first enrollment on fleet server](https://discuss.elastic.co/t/elastic-agent-falling-after-first-enrollment-on-fleet-server/327385)

<div class="topic-metadata">

**Author:** [@thiago8martins](https://discuss.elastic.co/u/thiago8martins)\
**Replies:** 2\
**Last updated:** [March 20, 2023, 4:45pm UTC](https://discuss.elastic.co/t/elastic-agent-falling-after-first-enrollment-on-fleet-server/327385 "2023-03-20T16:45:16Z")

</div>

Hello Folks, I'm deploying Elastic Agent and Fleet Server on K8s environment: The Fleet Server I have deployed at the same cluster as the Kibana and ES using ECK. The Elastic Agent i need to deploy in other K8s clust…

---

## [Json parsin](https://discuss.elastic.co/t/json-parsin/326849)

<div class="topic-metadata">

**Author:** [@chrispos](https://discuss.elastic.co/u/chrispos)\
**Replies:** 10\
**Last updated:** [March 20, 2023, 4:34pm UTC](https://discuss.elastic.co/t/json-parsin/326849 "2023-03-20T16:34:54Z")

</div>

Hello, I have a question. We are trying to set up a logging system for a java application running on Jboss. The goal is to be able to filter for certain errors. We've done the following Server.log converted to server.…

---

## [Convert Minutes in to hour in Kibana field "TotalDuration"](https://discuss.elastic.co/t/convert-minutes-in-to-hour-in-kibana-field-totalduration/327413)

<div class="topic-metadata">

**Author:** [@Vivek\_Nigam](https://discuss.elastic.co/u/Vivek_Nigam)\
**Replies:** 5\
**Last updated:** [March 20, 2023, 3:44pm UTC](https://discuss.elastic.co/t/convert-minutes-in-to-hour-in-kibana-field-totalduration/327413 "2023-03-20T15:44:43Z")

</div>

Hi, I calulating sum of TotalDuration field in kibana , TotalDuration field is in Minutes. i want to convert minutes in to Hours while dispalying in kibana visulization . I tried json input : { "script": { "inline…

---

## [Please reset elastic engineer training and practice exam lab enviroments](https://discuss.elastic.co/t/please-reset-elastic-engineer-training-and-practice-exam-lab-enviroments/328031)

<div class="topic-metadata">

**Author:** [@cwilkey](https://discuss.elastic.co/u/cwilkey)\
**Replies:** 1\
**Last updated:** [March 20, 2023, 3:42pm UTC](https://discuss.elastic.co/t/please-reset-elastic-engineer-training-and-practice-exam-lab-enviroments/328031 "2023-03-20T15:42:13Z")

</div>

Hi, Please could someone reset my Strigo lab environment and training progress for the Elastic Engineer course and the Strigo Elastic Engineer practice exam environment , as I would like to a re-run of the course before…

---

## [Strigo lab expired even before I could use it](https://discuss.elastic.co/t/strigo-lab-expired-even-before-i-could-use-it/328016)

<div class="topic-metadata">

**Author:** [@AmolV](https://discuss.elastic.co/u/AmolV)\
**Replies:** 1\
**Last updated:** [March 20, 2023, 3:40pm UTC](https://discuss.elastic.co/t/strigo-lab-expired-even-before-i-could-use-it/328016 "2023-03-20T15:40:36Z")

</div>

Course: Elasticsearch Engineer (On-Demand) Version: \<And which particular version?\> Question: The very first step in this course is about setting up the lab and strigo account. The course is valid for 1 year. So when I…

---

## [Unable to configure curator to archive data from Elasticsearch](https://discuss.elastic.co/t/unable-to-configure-curator-to-archive-data-from-elasticsearch/323354)

<div class="topic-metadata">

**Author:** [@Pendela-BhargavaSai](https://discuss.elastic.co/u/Pendela-BhargavaSai)\
**Replies:** 5\
**Last updated:** [March 20, 2023, 3:37pm UTC](https://discuss.elastic.co/t/unable-to-configure-curator-to-archive-data-from-elasticsearch/323354 "2023-03-20T15:37:39Z")

</div>

Hi I am a newbie to Elastic search. In my project we are working on archiving data using Curator. I am trying to configure the curator with Elasticsearch but unable to do that. I am facing some connectivity issues for c…

---

## [Kibana Graph - Tree, Tidy of D3.js for create a line trail on my infrastructure with a correlationID](https://discuss.elastic.co/t/kibana-graph-tree-tidy-of-d3-js-for-create-a-line-trail-on-my-infrastructure-with-a-correlationid/328061)

<div class="topic-metadata">

**Author:** [@martel](https://discuss.elastic.co/u/martel)\
**Replies:** 6\
**Last updated:** [March 20, 2023, 3:35pm UTC](https://discuss.elastic.co/t/kibana-graph-tree-tidy-of-d3-js-for-create-a-line-trail-on-my-infrastructure-with-a-correlationid/328061 "2023-03-20T15:35:15Z")

</div>

Hey, i want know if the Graph module on Kibana use D3.js ? and if is possible to create a tree graph with only path on dateTime log . I should see a from left to right (oldest to newest) a path on each place where a p…

---

## [Kibana api data view NOT working as expected with namespaces parameter](https://discuss.elastic.co/t/kibana-api-data-view-not-working-as-expected-with-namespaces-parameter/327168)

<div class="topic-metadata">

**Author:** [@Gautier\_Franchini](https://discuss.elastic.co/u/Gautier_Franchini)\
**Replies:** 4\
**Last updated:** [March 20, 2023, 3:29pm UTC](https://discuss.elastic.co/t/kibana-api-data-view-not-working-as-expected-with-namespaces-parameter/327168 "2023-03-20T15:29:11Z")

</div>

Dear All, my goal is to create kibana data\_views using the API; It works fine if I create simple data\_view in the default space. But it's not working if I want to precise the namespace I want to target. Looking in the…

---

## [Kibana Data View update API request doesn't work](https://discuss.elastic.co/t/kibana-data-view-update-api-request-doesnt-work/327435)

<div class="topic-metadata">

**Author:** [@nilaksha](https://discuss.elastic.co/u/nilaksha)\
**Replies:** 5\
**Last updated:** [March 20, 2023, 3:19pm UTC](https://discuss.elastic.co/t/kibana-data-view-update-api-request-doesnt-work/327435 "2023-03-20T15:19:43Z")

</div>

I'm using latest version of 8.6.2 kibana and i need to change the index pattern in kibana Data View to visualize data dynamically. so i have to do it using kibana rest API and found Data View Update API Documentation. bu…

---

## [Prefix and port appear flipped in es-hadoop implementation](https://discuss.elastic.co/t/prefix-and-port-appear-flipped-in-es-hadoop-implementation/328072)

<div class="topic-metadata">

**Author:** [@petersedivec](https://discuss.elastic.co/u/petersedivec)\
**Replies:** 3\
**Last updated:** [March 20, 2023, 3:01pm UTC](https://discuss.elastic.co/t/prefix-and-port-appear-flipped-in-es-hadoop-implementation/328072 "2023-03-20T15:01:51Z")

</div>

Attempting to read/write with es-hadoop however I am getting the following error in Databricks EsHadoopInvalidRequest: \[HEAD\] on \[index\_name\] failed; server \[https://serveraddress.com/es:443\] returned \[405|Method Not Al…

---

## [How to write elastic search query for one required parameter and another optional paramater](https://discuss.elastic.co/t/how-to-write-elastic-search-query-for-one-required-parameter-and-another-optional-paramater/328089)

<div class="topic-metadata">

**Author:** [@Phoenix1990](https://discuss.elastic.co/u/Phoenix1990)\
**Replies:** 0\
**Last updated:** [March 20, 2023, 2:39pm UTC](https://discuss.elastic.co/t/how-to-write-elastic-search-query-for-one-required-parameter-and-another-optional-paramater/328089 "2023-03-20T14:39:33Z")

</div>

I need to create an Elasticsearch endpoint with two paramater : Session(required field),CallType(Optional) which returns call details bewteen Teacher and student. I can search for specific session with below details. My …

---

## [Transform for change between states](https://discuss.elastic.co/t/transform-for-change-between-states/328082)

<div class="topic-metadata">

**Author:** [@tommycahir](https://discuss.elastic.co/u/tommycahir)\
**Replies:** 0\
**Last updated:** [March 20, 2023, 2:06pm UTC](https://discuss.elastic.co/t/transform-for-change-between-states/328082 "2023-03-20T14:06:27Z")

</div>

Hi All I have a large index that is populated using logstash with a Kafka input ~200m documents in it. We are building a pretty conmplex dashboard based on the data from that index I need some guidance on how I can bui…

---

## [We couldn't log you in. Please try again](https://discuss.elastic.co/t/we-couldnt-log-you-in-please-try-again/327950)

<div class="topic-metadata">

**Author:** [@prabakaran23](https://discuss.elastic.co/u/prabakaran23)\
**Replies:** 3\
**Last updated:** [March 20, 2023, 1:55pm UTC](https://discuss.elastic.co/t/we-couldnt-log-you-in-please-try-again/327950 "2023-03-20T13:55:25Z")

</div>

Hi, Unable to login the kibana console today. We are facing following error "We couldn't log you in. Please try again." Kindly help on this..

[Previous page](https://discuss.elastic.co/latest.md?page=740)

[Next page](https://discuss.elastic.co/latest.md?page=742)
