# Latest

**URL:** https://discuss.elastic.co/latest.md?page=750

[Latest](https://discuss.elastic.co/latest.md) · [Categories](https://discuss.elastic.co/categories.md) · [Tags](https://discuss.elastic.co/tags.md)

**Page:** 751

---

## [Upgrade 7 -\> 8. depreciation messages -- ruby api](https://discuss.elastic.co/t/upgrade-7-8-depreciation-messages-ruby-api/327590)

<div class="topic-metadata">

**Author:** [@Russell\_Fulton](https://discuss.elastic.co/u/Russell_Fulton)\
**Replies:** 1\
**Last updated:** [March 13, 2023, 9:04pm UTC](https://discuss.elastic.co/t/upgrade-7-8-depreciation-messages-ruby-api/327590 "2023-03-13T21:04:54Z")

</div>

I am about to attempt to upgrade my test system from 7.17 to the latest 8.x... I have custom written ingestion processes which uses the ruby elasticsearch gem. Migration assistant says all is good but when I look at th…

---

## [Is there a way to output logs to s3 from filebeat without using logstash?](https://discuss.elastic.co/t/is-there-a-way-to-output-logs-to-s3-from-filebeat-without-using-logstash/327581)

<div class="topic-metadata">

**Author:** [@Z4ck404](https://discuss.elastic.co/u/Z4ck404)\
**Replies:** 1\
**Last updated:** [March 13, 2023, 6:29pm UTC](https://discuss.elastic.co/t/is-there-a-way-to-output-logs-to-s3-from-filebeat-without-using-logstash/327581 "2023-03-13T18:29:34Z")

</div>

Continuing the discussion from Does Filebeat support output to S3?:

---

## [Piece\_id.keyword vs piece\_id](https://discuss.elastic.co/t/piece-id-keyword-vs-piece-id/327584)

<div class="topic-metadata">

**Author:** [@Rafa\_H](https://discuss.elastic.co/u/Rafa_H)\
**Replies:** 1\
**Last updated:** [March 13, 2023, 6:11pm UTC](https://discuss.elastic.co/t/piece-id-keyword-vs-piece-id/327584 "2023-03-13T18:11:28Z")

</div>

Hello everyone. I am new to the community. I have a question related to elasticsearch and would appreciate your support. In the platform we are developing, in the local env and staging env elasticsearch works only if k…

---

## [Logstash error failed to install template](https://discuss.elastic.co/t/logstash-error-failed-to-install-template/327521)

<div class="topic-metadata">

**Author:** [@supraja\_inamadugu](https://discuss.elastic.co/u/supraja_inamadugu)\
**Replies:** 2\
**Last updated:** [March 13, 2023, 6:06pm UTC](https://discuss.elastic.co/t/logstash-error-failed-to-install-template/327521 "2023-03-13T18:06:17Z")

</div>

\[ERROR\] 2023-03-12 22:42:30.743 \[Ruby-0-Thread-10: /opt/homebrew/Cellar/logstash/8.6.1/libexec/vendor/bundle/jruby/2.6.0/gems/logstash-output-elasticsearch-11.12.1-java/lib/logstash/plugin\_mixins/elasticsearch/common.rb:…

---

## [SLM should be happening only for Delete Phase indices](https://discuss.elastic.co/t/slm-should-be-happening-only-for-delete-phase-indices/327546)

<div class="topic-metadata">

**Author:** [@Gaurav\_kr](https://discuss.elastic.co/u/Gaurav_kr)\
**Replies:** 2\
**Last updated:** [March 13, 2023, 5:28pm UTC](https://discuss.elastic.co/t/slm-should-be-happening-only-for-delete-phase-indices/327546 "2023-03-13T17:28:59Z")

</div>

Hi All, I am using ELK version 8.0.0, where we are using SLM policy but wanted to know it there any option to make sure when the SLM happens it should be only happening for indices which are in delete phase. Currently i…

---

## [User only with access to content they have created](https://discuss.elastic.co/t/user-only-with-access-to-content-they-have-created/327574)

<div class="topic-metadata">

**Author:** [@abrooky](https://discuss.elastic.co/u/abrooky)\
**Replies:** 2\
**Last updated:** [March 13, 2023, 4:36pm UTC](https://discuss.elastic.co/t/user-only-with-access-to-content-they-have-created/327574 "2023-03-13T16:36:53Z")

</div>

Can someone point me the in the right direction. I've built a simple search as you type tool for a website catalogue which will be used by multiple websites. I need to make sure that each tenant have a unique user/pass …

---

## [Grok parser and nested brackets](https://discuss.elastic.co/t/grok-parser-and-nested-brackets/327454)

<div class="topic-metadata">

**Author:** [@ddoroshenko](https://discuss.elastic.co/u/ddoroshenko)\
**Replies:** 5\
**Last updated:** [March 13, 2023, 4:03pm UTC](https://discuss.elastic.co/t/grok-parser-and-nested-brackets/327454 "2023-03-13T16:03:57Z")

</div>

Hi, I have log event like this 2023-03-03T11:11:11.000Z INFO (foo (bar) bla bla \[bla\]) 2023-03-03T11:11:11.000Z \[foo (bar) bla bla \[bla\]\] I want to parse it with grok filter like timestamp: 2023-03-03T11:11:11.000Z l…

---

## [Prometheus remote\_write to metricbeat shows up in Kibana for one minute, then stops working](https://discuss.elastic.co/t/prometheus-remote-write-to-metricbeat-shows-up-in-kibana-for-one-minute-then-stops-working/325651)

<div class="topic-metadata">

**Author:** [@megaxm](https://discuss.elastic.co/u/megaxm)\
**Replies:** 4\
**Last updated:** [March 13, 2023, 4:00pm UTC](https://discuss.elastic.co/t/prometheus-remote-write-to-metricbeat-shows-up-in-kibana-for-one-minute-then-stops-working/325651 "2023-03-13T16:00:18Z")

</div>

Hi. I have set up the elk stack in one server. And also on the same server we have installed metricbeat. Version 8.6.1 for elk as well as metricbeat When we send the metrics to metricbeat we see that metrics are shown …

---

## [Is it possible to "conditionaly" analyze same field differently? \[synonyms\]](https://discuss.elastic.co/t/is-it-possible-to-conditionaly-analyze-same-field-differently-synonyms/326441)

<div class="topic-metadata">

**Author:** [@astrodi](https://discuss.elastic.co/u/astrodi)\
**Replies:** 3\
**Last updated:** [March 13, 2023, 3:16pm UTC](https://discuss.elastic.co/t/is-it-possible-to-conditionaly-analyze-same-field-differently-synonyms/326441 "2023-03-13T15:16:46Z")

</div>

Hi there, The index contains 3 business units, the goal is to provide different set of synonyms for each BU. The field is unstructured text (PDF rendition), occupying 95% of overall index storage, currently analyzed t…

---

## [Does every index have its own shard?](https://discuss.elastic.co/t/does-every-index-have-its-own-shard/327526)

<div class="topic-metadata">

**Author:** [@emrethedev](https://discuss.elastic.co/u/emrethedev)\
**Replies:** 10\
**Last updated:** [March 13, 2023, 3:02pm UTC](https://discuss.elastic.co/t/does-every-index-have-its-own-shard/327526 "2023-03-13T15:02:47Z")

</div>

Hi, (Sorry if this is a double post but i could not find answer.) Does every index have its own shard or may they have common shards? We know that when we create an index, it has 5 shards by default. So when we create a…

---

## [Geohash\_grid aggregation in opensearch](https://discuss.elastic.co/t/geohash-grid-aggregation-in-opensearch/327553)

<div class="topic-metadata">

**Author:** [@hmkhitaryan](https://discuss.elastic.co/u/hmkhitaryan)\
**Replies:** 2\
**Last updated:** [March 13, 2023, 2:41pm UTC](https://discuss.elastic.co/t/geohash-grid-aggregation-in-opensearch/327553 "2023-03-13T14:41:35Z")

</div>

Hi. I'm gettin this error when trying "geohash\_grid" aggregation in java opensearch api. Seems opensearch doesn't have geohash\_grid aggregation type, So what can be the analog? "aggs": { "filter\_agg": { "filt…

---

## [Issues with log rotation - Filebeat lock logs file](https://discuss.elastic.co/t/issues-with-log-rotation-filebeat-lock-logs-file/327565)

<div class="topic-metadata">

**Author:** [@akhil](https://discuss.elastic.co/u/akhil)\
**Replies:** 0\
**Last updated:** [March 13, 2023, 2:26pm UTC](https://discuss.elastic.co/t/issues-with-log-rotation-filebeat-lock-logs-file/327565 "2023-03-13T14:26:24Z")

</div>

Hi All, We are having some issues with filbeat. Actually filebeat is locking a logs file and because of this the log rotation is not working. The data is keep getting ingested in the same file. Every time we have to re…

---

## [Filebeat pods keeps increasing Memory usage](https://discuss.elastic.co/t/filebeat-pods-keeps-increasing-memory-usage/325124)

<div class="topic-metadata">

**Author:** [@oandre7](https://discuss.elastic.co/u/oandre7)\
**Replies:** 12\
**Last updated:** [March 13, 2023, 2:23pm UTC](https://discuss.elastic.co/t/filebeat-pods-keeps-increasing-memory-usage/325124 "2023-03-13T14:23:01Z")

</div>

Hi all, We are having a quite a strange issue that running filebeat in any version higher than 8.0.0 will cause filebeats agent to start increasing Memory consumption until the pod is OOM killed. As mentioned versions 8…

---

## [Aggregation on specific object in an array](https://discuss.elastic.co/t/aggregation-on-specific-object-in-an-array/327533)

<div class="topic-metadata">

**Author:** [@Vivek\_Burman](https://discuss.elastic.co/u/Vivek_Burman)\
**Replies:** 3\
**Last updated:** [March 13, 2023, 1:27pm UTC](https://discuss.elastic.co/t/aggregation-on-specific-object-in-an-array/327533 "2023-03-13T13:27:33Z")

</div>

Hi, So my document has a structure as below. I would like to aggregate based on \*\*value\*\*, but only on the object with {"label": "Business Priority"}. Can you help how I can achieve this?

---

## [Elastic Cloud showing "Unhealthy" but all zones are "Healthy"](https://discuss.elastic.co/t/elastic-cloud-showing-unhealthy-but-all-zones-are-healthy/327482)

<div class="topic-metadata">

**Author:** [@matto](https://discuss.elastic.co/u/matto)\
**Replies:** 8\
**Last updated:** [March 13, 2023, 1:26pm UTC](https://discuss.elastic.co/t/elastic-cloud-showing-unhealthy-but-all-zones-are-healthy/327482 "2023-03-13T13:26:00Z")

</div>

We are running Magneto 2.4 using Elastic hosted on Elastic.co. Elastic Cloud version 7.17 due to Magento 2.4 requirements. Recently our Elastic Cloud is showing "Unhealthy" but all zones are "Healthy" - screenshot atta…

---

## [Are there any limits to the number of snapshot repositories?](https://discuss.elastic.co/t/are-there-any-limits-to-the-number-of-snapshot-repositories/327541)

<div class="topic-metadata">

**Author:** [@John\_Newman1](https://discuss.elastic.co/u/John_Newman1)\
**Replies:** 2\
**Last updated:** [March 13, 2023, 1:23pm UTC](https://discuss.elastic.co/t/are-there-any-limits-to-the-number-of-snapshot-repositories/327541 "2023-03-13T13:23:27Z")

</div>

Hi, I'm looking to backup a lot of historical indices, for now and going into the future, we have two a day going back till 2010. For our use case we'd like to set the base\_path per index, this means that we'll need to …

---

## [Questions regarding working with pie charts](https://discuss.elastic.co/t/questions-regarding-working-with-pie-charts/327554)

<div class="topic-metadata">

**Author:** [@marcober](https://discuss.elastic.co/u/marcober)\
**Replies:** 0\
**Last updated:** [March 13, 2023, 1:20pm UTC](https://discuss.elastic.co/t/questions-regarding-working-with-pie-charts/327554 "2023-03-13T13:20:45Z")

</div>

Hi, I'm new using Kibana and I have some questions regarding working with pie charts. There are two things that I've been trying to do but I have not been able to: With a KQL query I was able to handle my data and ge…

---

## [Asa integration in elastic agent](https://discuss.elastic.co/t/asa-integration-in-elastic-agent/327163)

<div class="topic-metadata">

**Author:** [@bex](https://discuss.elastic.co/u/bex)\
**Replies:** 7\
**Last updated:** [March 13, 2023, 12:54pm UTC](https://discuss.elastic.co/t/asa-integration-in-elastic-agent/327163 "2023-03-13T12:54:33Z")

</div>

Can anyone please advise with "Asa" integration in elastic agent? As we know, there are 2 ways: I am sending logs of ASA(192.168.110.1) by syslog udp to logstash(192.168.110.243). When checking by tcpdump, I see that…

---

## [Posting logs of underlying plugin libraries to Logstash log stream](https://discuss.elastic.co/t/posting-logs-of-underlying-plugin-libraries-to-logstash-log-stream/327105)

<div class="topic-metadata">

**Author:** [@alromos](https://discuss.elastic.co/u/alromos)\
**Replies:** 1\
**Last updated:** [March 13, 2023, 11:15am UTC](https://discuss.elastic.co/t/posting-logs-of-underlying-plugin-libraries-to-logstash-log-stream/327105 "2023-03-13T11:15:16Z")

</div>

Is it possible to post logs of underlying libraries to Logstash log stream? For instance, I use input JDBC plugin with MSSQL JDBC driver and I would like to see logs of the driver library for debug purposes. Is it poss…

---

## [Transport error 429](https://discuss.elastic.co/t/transport-error-429/327528)

<div class="topic-metadata">

**Author:** [@Susendiran](https://discuss.elastic.co/u/Susendiran)\
**Replies:** 5\
**Last updated:** [March 13, 2023, 10:48am UTC](https://discuss.elastic.co/t/transport-error-429/327528 "2023-03-13T10:48:31Z")

</div>

Hi Team, We are getting elasticsearch exceptions - transport error 429 while providing es.search command using python pandas for some large set of data(upto 13-15k records). It's showing the limit is more than the thres…

---

## [Adding extra field in filebeat](https://discuss.elastic.co/t/adding-extra-field-in-filebeat/327534)

<div class="topic-metadata">

**Author:** [@gyrao\_72](https://discuss.elastic.co/u/gyrao_72)\
**Replies:** 0\
**Last updated:** [March 13, 2023, 9:08am UTC](https://discuss.elastic.co/t/adding-extra-field-in-filebeat/327534 "2023-03-13T09:08:29Z")

</div>

filebeat.inputs: # Each - is an input. Most options can be set at the input level, so # you can use different inputs for various configurations. # Below are the input specific configurations. - type: log # Change to t…

---

## [NOT STRING IN ARRAY IN WATCHER](https://discuss.elastic.co/t/not-string-in-array-in-watcher/327421)

<div class="topic-metadata">

**Author:** [@Daniel\_Lopez](https://discuss.elastic.co/u/Daniel_Lopez)\
**Replies:** 1\
**Last updated:** [March 13, 2023, 10:18am UTC](https://discuss.elastic.co/t/not-string-in-array-in-watcher/327421 "2023-03-13T10:18:19Z")

</div>

Hi team! I'm trying to setup a watcher for finding a way to check if an array has not a string value, but i getting stuck, could someone have an idea?

---

## [Enabling multiple snapshot operations in ES 6.5.4](https://discuss.elastic.co/t/enabling-multiple-snapshot-operations-in-es-6-5-4/327536)

<div class="topic-metadata">

**Author:** [@Het\_Desai](https://discuss.elastic.co/u/Het_Desai)\
**Replies:** 3\
**Last updated:** [March 13, 2023, 10:16am UTC](https://discuss.elastic.co/t/enabling-multiple-snapshot-operations-in-es-6-5-4/327536 "2023-03-13T10:16:29Z")

</div>

We have ES 6.5.4 and using S3 repository in our different machines. We move data from one machine to another using snapshot/restore process. Now only 1 concurrent snapshot operation is allowed per machine. If we do some …

---

## [\[Filebeat 8.6.1 - httpjson\] chain response.transform question](https://discuss.elastic.co/t/filebeat-8-6-1-httpjson-chain-response-transform-question/326774)

<div class="topic-metadata">

**Author:** [@marrc.rousseau](https://discuss.elastic.co/u/marrc.rousseau)\
**Replies:** 2\
**Last updated:** [March 13, 2023, 8:51am UTC](https://discuss.elastic.co/t/filebeat-8-6-1-httpjson-chain-response-transform-question/326774 "2023-03-13T08:51:59Z")

</div>

Hello, I'm facing an issue with response.transform and after searching during hours I'm still not able to find a solution. I try to chain some api calls to get a list of bugs per host : Request 1: To get list of host …

---

## [Data Grid vs Table](https://discuss.elastic.co/t/data-grid-vs-table/327527)

<div class="topic-metadata">

**Author:** [@Sheereen](https://discuss.elastic.co/u/Sheereen)\
**Replies:** 2\
**Last updated:** [March 13, 2023, 8:40am UTC](https://discuss.elastic.co/t/data-grid-vs-table/327527 "2023-03-13T08:40:50Z")

</div>

Hi, I want to display data in tabular format and also give in option to edit/input extra values giving text fields/other input controls inside cell. Is EuiDataGrid or EuiTable a better option for the same? Thanks

---

## [Error while creating Parallel coordinate in Vega - "Cannot read properties of undefined (reading 'key')"](https://discuss.elastic.co/t/error-while-creating-parallel-coordinate-in-vega-cannot-read-properties-of-undefined-reading-key/327529)

<div class="topic-metadata">

**Author:** [@Fiza](https://discuss.elastic.co/u/Fiza)\
**Replies:** 1\
**Last updated:** [March 13, 2023, 8:00am UTC](https://discuss.elastic.co/t/error-while-creating-parallel-coordinate-in-vega-cannot-read-properties-of-undefined-reading-key/327529 "2023-03-13T08:00:12Z")

</div>

Hello everyone, I am trying to create parallel coordinates for my timeseries data. I am first querying to get wanted fields and then trying to use them for scale and axis plotting. But I am receiving properties undefi…

---

## [Is it possible to recognize if dashboards changes in Kibana Spaces?](https://discuss.elastic.co/t/is-it-possible-to-recognize-if-dashboards-changes-in-kibana-spaces/327448)

<div class="topic-metadata">

**Author:** [@Flo2](https://discuss.elastic.co/u/Flo2)\
**Replies:** 2\
**Last updated:** [March 13, 2023, 7:34am UTC](https://discuss.elastic.co/t/is-it-possible-to-recognize-if-dashboards-changes-in-kibana-spaces/327448 "2023-03-13T07:34:34Z")

</div>

Hello Everyone, is it possible to automatically recognize if dashboards are added or deleted from Kibana spaces? And if so, can a notification be sent to a user based on this action?

---

## [Adding only the appended part of a file to elastic using logstash](https://discuss.elastic.co/t/adding-only-the-appended-part-of-a-file-to-elastic-using-logstash/327520)

<div class="topic-metadata">

**Author:** [@aks03](https://discuss.elastic.co/u/aks03)\
**Replies:** 1\
**Last updated:** [March 13, 2023, 4:37am UTC](https://discuss.elastic.co/t/adding-only-the-appended-part-of-a-file-to-elastic-using-logstash/327520 "2023-03-13T04:37:35Z")

</div>

Hey everyone, I am new to Elk stack but currently I want to add only the appended part of a file i.e, any extra content added to the file to elastic using logstash 6.3. The files are unstructured so even that has left …

---

## [Kibana 8.6.1 \`yarn kbn bootstrap\` Error](https://discuss.elastic.co/t/kibana-8-6-1-yarn-kbn-bootstrap-error/327519)

<div class="topic-metadata">

**Author:** [@suran\_choi](https://discuss.elastic.co/u/suran_choi)\
**Replies:** 0\
**Last updated:** [March 13, 2023, 4:35am UTC](https://discuss.elastic.co/t/kibana-8-6-1-yarn-kbn-bootstrap-error/327519 "2023-03-13T04:35:38Z")

</div>

I just wanna run Kibana 8.6.1. But I got this error. Node version : 16.18.1 yarn version : 1.22.19 ubuntu@raspberrypi:/usr/local/kibana$ bin/kibana node:internal/modules/cjs/loader:988 throw err; ^ Error: Cannot …

---

## [Convert a string field to number, but only brand new indices recognized](https://discuss.elastic.co/t/convert-a-string-field-to-number-but-only-brand-new-indices-recognized/327512)

<div class="topic-metadata">

**Author:** [@KeithTt](https://discuss.elastic.co/u/KeithTt)\
**Replies:** 0\
**Last updated:** [March 13, 2023, 3:39am UTC](https://discuss.elastic.co/t/convert-a-string-field-to-number-but-only-brand-new-indices-recognized/327512 "2023-03-13T03:39:55Z")

</div>

Logstash version: 6.3.0 Here is my config: mutate { convert =\> { "bytes\_sent" =\> "integer" } } I find that a indice which first created can recognized the config, but the others ones can not, even they created erv…

[Previous page](https://discuss.elastic.co/latest.md?page=749)

[Next page](https://discuss.elastic.co/latest.md?page=751)
