# Latest

**URL:** https://discuss.elastic.co/latest.md?page=742

[Latest](https://discuss.elastic.co/latest.md) · [Categories](https://discuss.elastic.co/categories.md) · [Tags](https://discuss.elastic.co/tags.md)

**Page:** 743

---

## [\[half\_float\] parsing error](https://discuss.elastic.co/t/half-float-parsing-error/328057)

<div class="topic-metadata">

**Author:** [@Raul\_Uria](https://discuss.elastic.co/u/Raul_Uria)\
**Replies:** 1\
**Last updated:** [March 20, 2023, 1:51pm UTC](https://discuss.elastic.co/t/half-float-parsing-error/328057 "2023-03-20T13:51:00Z")

</div>

Hi, I can´t understand why my data is not parsed. I got this on my logs: status"=\>400, "error"=\>{"type"=\>"mapper\_parsing\_exception", "reason"=\>"failed to parse field \[MyFIELD-NAME\] of type \[half\_float\] in document with …

---

## [Percent change from variable selections](https://discuss.elastic.co/t/percent-change-from-variable-selections/327864)

<div class="topic-metadata">

**Author:** [@jack-morrison](https://discuss.elastic.co/u/jack-morrison)\
**Replies:** 4\
**Last updated:** [March 20, 2023, 1:39pm UTC](https://discuss.elastic.co/t/percent-change-from-variable-selections/327864 "2023-03-20T13:39:11Z")

</div>

Hi Elastic Community! I've introduced the ELK stack to my organization, and it has been well received with the exception of one requirement I've been so far unable to meet after months of trying - deriving metrics from …

---

## [Not able to sort on Long field and Function score also not working](https://discuss.elastic.co/t/not-able-to-sort-on-long-field-and-function-score-also-not-working/328077)

<div class="topic-metadata">

**Author:** [@Rakhshunda\_Noorein\_J](https://discuss.elastic.co/u/Rakhshunda_Noorein_J)\
**Replies:** 1\
**Last updated:** [March 20, 2023, 1:27pm UTC](https://discuss.elastic.co/t/not-able-to-sort-on-long-field-and-function-score-also-not-working/328077 "2023-03-20T13:27:15Z")

</div>

Hello, I am performing a simple query and sorting on a field (Long Type). It is not sorting. { "from":0, "size": 5000, "query" : { "match\_all" : {} }, "sort":\[ { "sort\_field"…

---

## [APM Java agent not creating transactions with Vert.x even with experimental features enabled](https://discuss.elastic.co/t/apm-java-agent-not-creating-transactions-with-vert-x-even-with-experimental-features-enabled/327873)

<div class="topic-metadata">

**Author:** [@missael.denadai](https://discuss.elastic.co/u/missael.denadai)\
**Replies:** 9\
**Last updated:** [March 20, 2023, 1:16pm UTC](https://discuss.elastic.co/t/apm-java-agent-not-creating-transactions-with-vert-x-even-with-experimental-features-enabled/327873 "2023-03-20T13:16:42Z")

</div>

Hi! I am not being able to audit the transactions against my Vert.x application using the Java agent for this purpose, even though I have enabled the experimental instrumentations. -Dquarkus.profile=local -javaagent:sr…

---

## [Anyone know the elastic\_apm\_application\_packages value for Jenkins?](https://discuss.elastic.co/t/anyone-know-the-elastic-apm-application-packages-value-for-jenkins/327786)

<div class="topic-metadata">

**Author:** [@trudesea](https://discuss.elastic.co/u/trudesea)\
**Replies:** 11\
**Last updated:** [March 17, 2023, 6:52pm UTC](https://discuss.elastic.co/t/anyone-know-the-elastic-apm-application-packages-value-for-jenkins/327786 "2023-03-17T18:52:50Z")

</div>

I have no idea where/how to find this value, I've exhausted my Google Fu capabilities. Thanks

---

## [Kibana logs for tcp level blocked traffic](https://discuss.elastic.co/t/kibana-logs-for-tcp-level-blocked-traffic/328055)

<div class="topic-metadata">

**Author:** [@Vlada\_Homyakova](https://discuss.elastic.co/u/Vlada_Homyakova)\
**Replies:** 1\
**Last updated:** [March 20, 2023, 1:06pm UTC](https://discuss.elastic.co/t/kibana-logs-for-tcp-level-blocked-traffic/328055 "2023-03-20T13:06:42Z")

</div>

Hi guys! Is it possible to see blocked traffic in tcp level in Kibana logs ? For example load balancer blocked traffic , can I see it somehow in kibana dashboards the blocked requests ?

---

## [How to convert one filed date to string in Logstash](https://discuss.elastic.co/t/how-to-convert-one-filed-date-to-string-in-logstash/328075)

<div class="topic-metadata">

**Author:** [@upreddy](https://discuss.elastic.co/u/upreddy)\
**Replies:** 0\
**Last updated:** [March 20, 2023, 12:47pm UTC](https://discuss.elastic.co/t/how-to-convert-one-filed-date-to-string-in-logstash/328075 "2023-03-20T12:47:06Z")

</div>

Hi, I have below log pattern, 2023-03-15T11:11:59.341602012Z stdout F \[INFO \] {"logtype":"msg","trackingid":"XXXXXXX","abcid":"XXXXXXX","operation":{"name":"XXXXX","version":"105"} ,"usecase":"ABC","runtimes":{"output…

---

## [Chart-Title from data values](https://discuss.elastic.co/t/chart-title-from-data-values/327998)

<div class="topic-metadata">

**Author:** [@joerg55](https://discuss.elastic.co/u/joerg55)\
**Replies:** 4\
**Last updated:** [March 20, 2023, 12:32pm UTC](https://discuss.elastic.co/t/chart-title-from-data-values/327998 "2023-03-20T12:32:37Z")

</div>

Hi community, I know this is not necessarily a question for this forum, but I hope someone might be able to help. I want to take the title of my chart directly from the data which are base of the chart. For example the …

---

## [How to pass result of one chained input, into next chained input](https://discuss.elastic.co/t/how-to-pass-result-of-one-chained-input-into-next-chained-input/328069)

<div class="topic-metadata">

**Author:** [@bhavya](https://discuss.elastic.co/u/bhavya)\
**Replies:** 0\
**Last updated:** [March 20, 2023, 12:07pm UTC](https://discuss.elastic.co/t/how-to-pass-result-of-one-chained-input-into-next-chained-input/328069 "2023-03-20T12:07:03Z")

</div>

I am writing a watcher, to first fetch destination.ip field (using aggregation), and then I have to use 1st input result for terms query value (in 3rd input) POST \_watcher/watch/\_execute { "watch": { "trigger": { …

---

## [Lens formulas count problem](https://discuss.elastic.co/t/lens-formulas-count-problem/328050)

<div class="topic-metadata">

**Author:** [@lize\_su](https://discuss.elastic.co/u/lize_su)\
**Replies:** 3\
**Last updated:** [March 20, 2023, 12:06pm UTC](https://discuss.elastic.co/t/lens-formulas-count-problem/328050 "2023-03-20T12:06:48Z")

</div>

Hi all, I'm pretty new to kibana and trying to use below code to generate dashboard warning count in the last 1 hour: //count(kql='isAlarmTriggered : true')-count(kql='isAlarmTriggered : true',shift='1h') But sometime…

---

## [IBM Cloud Metric Beat Module Contribution to the Beats Community](https://discuss.elastic.co/t/ibm-cloud-metric-beat-module-contribution-to-the-beats-community/327569)

<div class="topic-metadata">

**Author:** [@prashantaruadvi](https://discuss.elastic.co/u/prashantaruadvi)\
**Replies:** 2\
**Last updated:** [March 20, 2023, 12:02pm UTC](https://discuss.elastic.co/t/ibm-cloud-metric-beat-module-contribution-to-the-beats-community/327569 "2023-03-20T12:02:55Z")

</div>

Hi Team, We have built the IBM cloud metric beat module, we would like to contribute back to the community, can you please help us what is right way to contribute, thanks in advance.

---

## [Nested fields are being indexed but are no longer searchable in Discover](https://discuss.elastic.co/t/nested-fields-are-being-indexed-but-are-no-longer-searchable-in-discover/327913)

<div class="topic-metadata">

**Author:** [@Raspberry](https://discuss.elastic.co/u/Raspberry)\
**Replies:** 2\
**Last updated:** [March 20, 2023, 11:51am UTC](https://discuss.elastic.co/t/nested-fields-are-being-indexed-but-are-no-longer-searchable-in-discover/327913 "2023-03-20T11:51:52Z")

</div>

I have the following index mappings that I set up from PHP. "index" =\> "my-index-name", "body" =\> \[ "settings" =\> \[ "number\_of\_replicas" =\> 0, "number\_of\_shards" =\> 1, \], "mappings" =\> \[ …

---

## [Solr to Elasticsearh Migration Size Differance](https://discuss.elastic.co/t/solr-to-elasticsearh-migration-size-differance/327915)

<div class="topic-metadata">

**Author:** [@bilgicsin](https://discuss.elastic.co/u/bilgicsin)\
**Replies:** 2\
**Last updated:** [March 20, 2023, 11:24am UTC](https://discuss.elastic.co/t/solr-to-elasticsearh-migration-size-differance/327915 "2023-03-20T11:24:21Z")

</div>

Hi Everyone, We have Solr and Elasticsearch in our company and we want to do a benchmark test to decide for buying extra license. We tried to transfer 4 gb Solr collection to an elasticsearch indice. We query the whole …

---

## [Unable to Tessellate shape (Polygon)](https://discuss.elastic.co/t/unable-to-tessellate-shape-polygon/327850)

<div class="topic-metadata">

**Author:** [@Shaheryar\_Mahmood](https://discuss.elastic.co/u/Shaheryar_Mahmood)\
**Replies:** 1\
**Last updated:** [March 20, 2023, 11:00am UTC](https://discuss.elastic.co/t/unable-to-tessellate-shape-polygon/327850 "2023-03-20T11:00:06Z")

</div>

I'm having an issue while indexing the polygon below. What's wrong in the shape Elasticsearch version 7.7. {"error":{"root\_cause":\[{"type":"mapper\_parsing\_exception","reason":"failed to parse field \[location\] of type \[g…

---

## [Use ap-loader to include async-profiler](https://discuss.elastic.co/t/use-ap-loader-to-include-async-profiler/327828)

<div class="topic-metadata">

**Author:** [@parttimenerd](https://discuss.elastic.co/u/parttimenerd)\
**Replies:** 7\
**Last updated:** [March 20, 2023, 10:56am UTC](https://discuss.elastic.co/t/use-ap-loader-to-include-async-profiler/327828 "2023-03-20T10:56:06Z")

</div>

I saw that you embed async-profiler binaries yourself. May I propose that you use ap-loader instead? This is a well tested (and async-profiler creator blessed) packaging of async-profiler into a platform independent JAR.…

---

## [Logstash multiple pipeline Openshift/kubernetes no traffic](https://discuss.elastic.co/t/logstash-multiple-pipeline-openshift-kubernetes-no-traffic/327776)

<div class="topic-metadata">

**Author:** [@splitmessage88](https://discuss.elastic.co/u/splitmessage88)\
**Replies:** 3\
**Last updated:** [March 20, 2023, 10:52am UTC](https://discuss.elastic.co/t/logstash-multiple-pipeline-openshift-kubernetes-no-traffic/327776 "2023-03-20T10:52:59Z")

</div>

EDIT I finally get traffic into the cluster, but I only receive logs that have the string "FMC\_AUDIT\_LOG", nothing else get past. If I receive a syslog message with the string "test", it gets dropped. I want the message…

---

## [Does Elastic Package Registry need to run for APM to work?](https://discuss.elastic.co/t/does-elastic-package-registry-need-to-run-for-apm-to-work/327245)

<div class="topic-metadata">

**Author:** [@Ong](https://discuss.elastic.co/u/Ong)\
**Replies:** 2\
**Last updated:** [March 20, 2023, 10:50am UTC](https://discuss.elastic.co/t/does-elastic-package-registry-need-to-run-for-apm-to-work/327245 "2023-03-20T10:50:47Z")

</div>

I am setting up APM and understand that the Elastic Package Registry container needs to be running in order to generate the APM server token. Elastic Registry Package After the initial setup is done, does the Package R…

---

## [APM Server installation on insecure ElasticSearch](https://discuss.elastic.co/t/apm-server-installation-on-insecure-elasticsearch/327664)

<div class="topic-metadata">

**Author:** [@patpanda](https://discuss.elastic.co/u/patpanda)\
**Replies:** 1\
**Last updated:** [March 20, 2023, 10:43am UTC](https://discuss.elastic.co/t/apm-server-installation-on-insecure-elasticsearch/327664 "2023-03-20T10:43:57Z")

</div>

Kibana version: 8.6.2 Elasticsearch version: 8.6.2 APM Server version: 8.6.2 Original install method (e.g. download page, yum, deb, from source, etc.) and version: All Elastic + Kibana + APM downloaded as tar.gz F…

---

## [How to index the PDF documents](https://discuss.elastic.co/t/how-to-index-the-pdf-documents/327987)

<div class="topic-metadata">

**Author:** [@mruthyu](https://discuss.elastic.co/u/mruthyu)\
**Replies:** 8\
**Last updated:** [March 20, 2023, 10:36am UTC](https://discuss.elastic.co/t/how-to-index-the-pdf-documents/327987 "2023-03-20T10:36:03Z")

</div>

How to index the PDF and image documents into elasticsearch. Would like to extract the entities to enable the search on keywords. Whether the workplace search provide this functionality? Whether Apache Tika has been used…

---

## [How can I restore logs from /usr/share/elasticsearch/data/nodes/0?](https://discuss.elastic.co/t/how-can-i-restore-logs-from-usr-share-elasticsearch-data-nodes-0/327822)

<div class="topic-metadata">

**Author:** [@shawnmin](https://discuss.elastic.co/u/shawnmin)\
**Replies:** 6\
**Last updated:** [March 20, 2023, 10:09am UTC](https://discuss.elastic.co/t/how-can-i-restore-logs-from-usr-share-elasticsearch-data-nodes-0/327822 "2023-03-20T10:09:19Z")

</div>

I am using Elasticsearch as a backend to save logs collected from Fluentd logging agent. Specifically, I've set up an EFK logging architecture in my Kubernetes cluster. (AWS EKS cluster to be specific) I've mounted the …

---

## [Error during startup](https://discuss.elastic.co/t/error-during-startup/327941)

<div class="topic-metadata">

**Author:** [@Soren\_vdc](https://discuss.elastic.co/u/Soren_vdc)\
**Replies:** 7\
**Last updated:** [March 20, 2023, 9:51am UTC](https://discuss.elastic.co/t/error-during-startup/327941 "2023-03-20T09:51:07Z")

</div>

Hi, I receive this error during startup: \[ERROR\]\[o.e.b.Elasticsearch \] \[s2ab00jb.be.srv.dev.sys\] fatal exception while booting Elasticsearch java.lang.IllegalArgumentException: Could not load codec 'Lucene94'. Di…

---

## [Order BY Date field KIBANA Lens visualization ordered by alphabetically](https://discuss.elastic.co/t/order-by-date-field-kibana-lens-visualization-ordered-by-alphabetically/327523)

<div class="topic-metadata">

**Author:** [@vikram\_singh](https://discuss.elastic.co/u/vikram_singh)\
**Replies:** 1\
**Last updated:** [March 20, 2023, 9:18am UTC](https://discuss.elastic.co/t/order-by-date-field-kibana-lens-visualization-ordered-by-alphabetically/327523 "2023-03-20T09:18:02Z")

</div>

Hi, I created a lens visualization in Kibana. I visualize data in tabular form like excel. When I set order on a date type field (date format like March-2023) it is not showed in correct order. Like Jan-2023, Feb-2023,…

---

## [How to use Escape key value in query\_string](https://discuss.elastic.co/t/how-to-use-escape-key-value-in-query-string/327972)

<div class="topic-metadata">

**Author:** [@anon55421226](https://discuss.elastic.co/u/anon55421226)\
**Replies:** 6\
**Last updated:** [March 20, 2023, 9:14am UTC](https://discuss.elastic.co/t/how-to-use-escape-key-value-in-query-string/327972 "2023-03-20T09:14:24Z")

</div>

So... according to the elasticsearch/QueryStringQueryBuilder.java at v7.16.3 · elastic/elasticsearch · GitHub code there should exists an escape parameter in the query\_string object, but how do i trigger it to escape my …

---

## [Is the basic free elasticsearch allows to send invitations and password reset mails?](https://discuss.elastic.co/t/is-the-basic-free-elasticsearch-allows-to-send-invitations-and-password-reset-mails/327938)

<div class="topic-metadata">

**Author:** [@coy\_aprieto](https://discuss.elastic.co/u/coy_aprieto)\
**Replies:** 4\
**Last updated:** [March 20, 2023, 8:52am UTC](https://discuss.elastic.co/t/is-the-basic-free-elasticsearch-allows-to-send-invitations-and-password-reset-mails/327938 "2023-03-20T08:52:51Z")

</div>

Hi, I'm working on an elasticsearch platform for my company, and we are still using the free version for now. Is it possible to send invitations and password resets (i know alerts and generally mail stuff for kibana is…

---

## [How to get space\_id on server side](https://discuss.elastic.co/t/how-to-get-space-id-on-server-side/328054)

<div class="topic-metadata">

**Author:** [@iljaskajrris](https://discuss.elastic.co/u/iljaskajrris)\
**Replies:** 0\
**Last updated:** [March 20, 2023, 8:50am UTC](https://discuss.elastic.co/t/how-to-get-space-id-on-server-side/328054 "2023-03-20T08:50:02Z")

</div>

Hi team, can you help me please to get space on the server side? I need to do smth like to get data based on space. router.get( { path: '/api/get\_data', validate: false, }, async (context, req, response) =\> { …

---

## [Unable to create an enrollment token](https://discuss.elastic.co/t/unable-to-create-an-enrollment-token/327917)

<div class="topic-metadata">

**Author:** [@geb](https://discuss.elastic.co/u/geb)\
**Replies:** 2\
**Last updated:** [March 20, 2023, 8:47am UTC](https://discuss.elastic.co/t/unable-to-create-an-enrollment-token/327917 "2023-03-20T08:47:36Z")

</div>

Hi, i try to add a node at at new formed 8.6 cluster. As the first step i configured the ca, certificates and modified the elasticsearch.yml Cluster started -\> fine The error is also described in: This statement does…

---

## [How to add deletion policy in existing policy?](https://discuss.elastic.co/t/how-to-add-deletion-policy-in-existing-policy/328052)

<div class="topic-metadata">

**Author:** [@Mark\_S](https://discuss.elastic.co/u/Mark_S)\
**Replies:** 0\
**Last updated:** [March 20, 2023, 8:42am UTC](https://discuss.elastic.co/t/how-to-add-deletion-policy-in-existing-policy/328052 "2023-03-20T08:42:07Z")

</div>

I have a simple rotating policy and I want to add a deletion phase. This is not available in the UI, however I have done by creating a policy directly with PUT, including the delete section. My question is if it is poss…

---

## [Simple question about Index Rollover](https://discuss.elastic.co/t/simple-question-about-index-rollover/327999)

<div class="topic-metadata">

**Author:** [@Mark\_S](https://discuss.elastic.co/u/Mark_S)\
**Replies:** 5\
**Last updated:** [March 20, 2023, 8:07am UTC](https://discuss.elastic.co/t/simple-question-about-index-rollover/327999 "2023-03-20T08:07:19Z")

</div>

I have a simple policy for index rollover every day (or every 1gb). I use an index template -\> index pattern-\>index alias (see bellow). However it does not seem to rotate. Any ideas why (or how to test it? E.g if I send…

---

## [Fleet server limits](https://discuss.elastic.co/t/fleet-server-limits/328005)

<div class="topic-metadata">

**Author:** [@bex](https://discuss.elastic.co/u/bex)\
**Replies:** 2\
**Last updated:** [March 20, 2023, 8:01am UTC](https://discuss.elastic.co/t/fleet-server-limits/328005 "2023-03-20T08:01:28Z")

</div>

Hello, I would like to clarify how many sources(elastic agents) can be managed by one fleet server? Is there any limits for fleet server? Best regards, Bex

---

## [Disable reads from few indices of an index pattern](https://discuss.elastic.co/t/disable-reads-from-few-indices-of-an-index-pattern/328026)

<div class="topic-metadata">

**Author:** [@tarunpvss](https://discuss.elastic.co/u/tarunpvss)\
**Replies:** 7\
**Last updated:** [March 20, 2023, 7:06am UTC](https://discuss.elastic.co/t/disable-reads-from-few-indices-of-an-index-pattern/328026 "2023-03-20T07:06:32Z")

</div>

Hi Team, I want to disable reads for few indices in an index pattern. I tried using index.blocks.read : true But due to this, when I am trying to query using index pattern, getting the below error { "error" : { …

[Previous page](https://discuss.elastic.co/latest.md?page=741)

[Next page](https://discuss.elastic.co/latest.md?page=743)
