# Latest

**URL:** https://discuss.elastic.co/latest.md?page=755

[Latest](https://discuss.elastic.co/latest.md) · [Categories](https://discuss.elastic.co/categories.md) · [Tags](https://discuss.elastic.co/tags.md)

**Page:** 756

---

## [Is it possible to sort in a custom grouping manner with unicode collation algorithm in elasticsearch?](https://discuss.elastic.co/t/is-it-possible-to-sort-in-a-custom-grouping-manner-with-unicode-collation-algorithm-in-elasticsearch/327294)

<div class="topic-metadata">

**Author:** [@Karthik\_Amar](https://discuss.elastic.co/u/Karthik_Amar)\
**Replies:** 0\
**Last updated:** [March 8, 2023, 5:11pm UTC](https://discuss.elastic.co/t/is-it-possible-to-sort-in-a-custom-grouping-manner-with-unicode-collation-algorithm-in-elasticsearch/327294 "2023-03-08T17:11:35Z")

</div>

I am working on a phonebook, where if the user does not provide Name but fills only email, I will show the email value in phonebook (as in mac contacts). And the priority is as follows Name (if not present) -\> Email (if…

---

## [How to get logs from jupyter notebook instances generated by jupyterhub](https://discuss.elastic.co/t/how-to-get-logs-from-jupyter-notebook-instances-generated-by-jupyterhub/327290)

<div class="topic-metadata">

**Author:** [@SirReno](https://discuss.elastic.co/u/SirReno)\
**Replies:** 0\
**Last updated:** [March 8, 2023, 4:45pm UTC](https://discuss.elastic.co/t/how-to-get-logs-from-jupyter-notebook-instances-generated-by-jupyterhub/327290 "2023-03-08T16:45:50Z")

</div>

Hello eveyone; We have a jupyterhub (that is being monitored by filebeat) that spawns individual jupyter-notebooks (based on docker image), since it spawns a pod, the filebeat that monitors jupyterhub, cant reach the in…

---

## [Null\_pointer\_exception: Cannot invoke "String.equals(Object)" because the return value of "org.apache.lucene.search.SortField.getField()" is null](https://discuss.elastic.co/t/null-pointer-exception-cannot-invoke-string-equals-object-because-the-return-value-of-org-apache-lucene-search-sortfield-getfield-is-null/327235)

<div class="topic-metadata">

**Author:** [@davidgAID](https://discuss.elastic.co/u/davidgAID)\
**Replies:** 1\
**Last updated:** [March 8, 2023, 4:35pm UTC](https://discuss.elastic.co/t/null-pointer-exception-cannot-invoke-string-equals-object-because-the-return-value-of-org-apache-lucene-search-sortfield-getfield-is-null/327235 "2023-03-08T16:35:29Z")

</div>

This is on Elasticsearch 8.6.2. I have a pretty mundane query that I want to paginate via search\_after. The initial query looks like this: { "\_source": true, "collapse": { "field": "collapse\_col" }, "query…

---

## [Data nodes separation (via attributes) vs. clusters separation](https://discuss.elastic.co/t/data-nodes-separation-via-attributes-vs-clusters-separation/327216)

<div class="topic-metadata">

**Author:** [@Itay\_Bittan](https://discuss.elastic.co/u/Itay_Bittan)\
**Replies:** 3\
**Last updated:** [March 8, 2023, 4:33pm UTC](https://discuss.elastic.co/t/data-nodes-separation-via-attributes-vs-clusters-separation/327216 "2023-03-08T16:33:45Z")

</div>

Hi, We are B2B that maintain one index per each one of our customers. Every index is being indexed every day from scratch and once it is ready, it replace the previous day index. Once the index is ready, it's in read-…

---

## [Kibana Dashboard is empty with a lot of errors](https://discuss.elastic.co/t/kibana-dashboard-is-empty-with-a-lot-of-errors/327204)

<div class="topic-metadata">

**Author:** [@tagba](https://discuss.elastic.co/u/tagba)\
**Replies:** 3\
**Last updated:** [March 8, 2023, 4:16pm UTC](https://discuss.elastic.co/t/kibana-dashboard-is-empty-with-a-lot-of-errors/327204 "2023-03-08T16:16:19Z")

</div>

I'm new to kibana and Elasticsearch. Could someone tell me what to do here I have everything installed properly I think but I can't see anything in the dashboard. I have siem\_events and siem\_alarm index patterns creat…

---

## [Question about must query](https://discuss.elastic.co/t/question-about-must-query/327282)

<div class="topic-metadata">

**Author:** [@tomizius](https://discuss.elastic.co/u/tomizius)\
**Replies:** 3\
**Last updated:** [March 8, 2023, 4:14pm UTC](https://discuss.elastic.co/t/question-about-must-query/327282 "2023-03-08T16:14:25Z")

</div>

Course: \< Elastic Certified Engineer Exam\> Version: \<8.1\> Question: What is the difference between following two queries? 1: { "query": { "bool": { "must": \[ { "multi\_match": { …

---

## [Unable to connect to Elasticsearch client running locally: receiving 'connection refused' on KOTLIN](https://discuss.elastic.co/t/unable-to-connect-to-elasticsearch-client-running-locally-receiving-connection-refused-on-kotlin/327215)

<div class="topic-metadata">

**Author:** [@GAETANO\_SIMONELLI](https://discuss.elastic.co/u/GAETANO_SIMONELLI)\
**Replies:** 2\
**Last updated:** [March 8, 2023, 4:05pm UTC](https://discuss.elastic.co/t/unable-to-connect-to-elasticsearch-client-running-locally-receiving-connection-refused-on-kotlin/327215 "2023-03-08T16:05:49Z")

</div>

I am experiencing connection issues with my Elasticsearch client running locally. Specifically, when I try to connect using localhost in the RestClient.builder, I receive a java.net.connectException: connection refused e…

---

## [Is there a quicker way to import data to Elastic?](https://discuss.elastic.co/t/is-there-a-quicker-way-to-import-data-to-elastic/327275)

<div class="topic-metadata">

**Author:** [@eeijlar](https://discuss.elastic.co/u/eeijlar)\
**Replies:** 5\
**Last updated:** [March 8, 2023, 3:49pm UTC](https://discuss.elastic.co/t/is-there-a-quicker-way-to-import-data-to-elastic/327275 "2023-03-08T15:49:54Z")

</div>

I have exported elastic indices using logstash with the following logstash configuration: - pipeline.id: export-process pipeline.workers: 4 config.string: | input { elasticsearch { …

---

## [User experience dashboard is empty even after enabling RUM](https://discuss.elastic.co/t/user-experience-dashboard-is-empty-even-after-enabling-rum/327251)

<div class="topic-metadata">

**Author:** [@rahul\_sirugudi](https://discuss.elastic.co/u/rahul_sirugudi)\
**Replies:** 2\
**Last updated:** [March 8, 2023, 3:49pm UTC](https://discuss.elastic.co/t/user-experience-dashboard-is-empty-even-after-enabling-rum/327251 "2023-03-08T15:49:49Z")

</div>

I have enabled APM Monitoring on Java based application. I am using javaagent on the apm agents. In order to get RUM do i need to use RUM(JS)? Along side with java agent? But user experince dashboard is showing empty.…

---

## [Time Filter Canvas](https://discuss.elastic.co/t/time-filter-canvas/327046)

<div class="topic-metadata">

**Author:** [@puched](https://discuss.elastic.co/u/puched)\
**Replies:** 1\
**Last updated:** [March 8, 2023, 2:48pm UTC](https://discuss.elastic.co/t/time-filter-canvas/327046 "2023-03-08T14:48:28Z")

</div>

Hello, im trying to do a global time filter for my canvas presentation, I dont know what im doing wrong with the filters. Im filtering with logTime variable, I apply the global timefilter but the data is being show…

---

## [Elastic Search Heap size](https://discuss.elastic.co/t/elastic-search-heap-size/327266)

<div class="topic-metadata">

**Author:** [@Jozelle\_Cinco](https://discuss.elastic.co/u/Jozelle_Cinco)\
**Replies:** 1\
**Last updated:** [March 8, 2023, 2:38pm UTC](https://discuss.elastic.co/t/elastic-search-heap-size/327266 "2023-03-08T14:38:51Z")

</div>

Hi! We have a Headless Drupal 9 site (FE: Gatsby) with Elasticsearch that's currently encountering \[circuit\_breaking\_exception\] when doing a search. As per some discussions it is suggested we adjust the Heap size on Pro…

---

## [Logstash syslog message, doesn't choose right if statement](https://discuss.elastic.co/t/logstash-syslog-message-doesnt-choose-right-if-statement/327181)

<div class="topic-metadata">

**Author:** [@splitmessage88](https://discuss.elastic.co/u/splitmessage88)\
**Replies:** 2\
**Last updated:** [March 8, 2023, 2:36pm UTC](https://discuss.elastic.co/t/logstash-syslog-message-doesnt-choose-right-if-statement/327181 "2023-03-08T14:36:26Z")

</div>

Hi, I'm trying to create a logstash pipeline for cisco FMC audit log. I have create 3 if statements and would like for logstash to parse the syslog message according to the if statement. Here is two example syslog mes…

---

## [Example of testing cumstom plugins](https://discuss.elastic.co/t/example-of-testing-cumstom-plugins/327038)

<div class="topic-metadata">

**Author:** [@iljaskajrris](https://discuss.elastic.co/u/iljaskajrris)\
**Replies:** 1\
**Last updated:** [March 8, 2023, 2:33pm UTC](https://discuss.elastic.co/t/example-of-testing-cumstom-plugins/327038 "2023-03-08T14:33:34Z")

</div>

Hi team, i develop plugin for Kibana 7.10 and wonder if there any working example of functional tests for that. Can anybody help?

---

## [I have imported the dashboard](https://discuss.elastic.co/t/i-have-imported-the-dashboard/327144)

<div class="topic-metadata">

**Author:** [@ghorpade84](https://discuss.elastic.co/u/ghorpade84)\
**Replies:** 6\
**Last updated:** [March 8, 2023, 2:20pm UTC](https://discuss.elastic.co/t/i-have-imported-the-dashboard/327144 "2023-03-08T14:20:56Z")

</div>

I have imported the dashboard from git however dashboard shows no data in it , visualization id not found

---

## [Filebeat Helm chart 8.x requires \`elasticsearch-master-certs\`](https://discuss.elastic.co/t/filebeat-helm-chart-8-x-requires-elasticsearch-master-certs/325049)

<div class="topic-metadata">

**Author:** [@Roman\_Kournjaev](https://discuss.elastic.co/u/Roman_Kournjaev)\
**Replies:** 3\
**Last updated:** [March 8, 2023, 2:15pm UTC](https://discuss.elastic.co/t/filebeat-helm-chart-8-x-requires-elasticsearch-master-certs/325049 "2023-03-08T14:15:55Z")

</div>

We are using beats to ship our logs from k8s to the elastic cloud. I would like to upgrade our beats helm chart version from 7.x to 8.x and it introduces a breaking change where i would have to create a secret with elas…

---

## [Logstash ignore\_older opposite](https://discuss.elastic.co/t/logstash-ignore-older-opposite/327279)

<div class="topic-metadata">

**Author:** [@GinkoLucas](https://discuss.elastic.co/u/GinkoLucas)\
**Replies:** 1\
**Last updated:** [March 8, 2023, 2:13pm UTC](https://discuss.elastic.co/t/logstash-ignore-older-opposite/327279 "2023-03-08T14:13:47Z")

</div>

Hello, I would like Logstash to read only files older than one day. How can I do that? It would be sort of the opposite of "ignore\_older". Thx

---

## [Filebeat shared folder](https://discuss.elastic.co/t/filebeat-shared-folder/327106)

<div class="topic-metadata">

**Author:** [@GinkoLucas](https://discuss.elastic.co/u/GinkoLucas)\
**Replies:** 3\
**Last updated:** [March 8, 2023, 2:04pm UTC](https://discuss.elastic.co/t/filebeat-shared-folder/327106 "2023-03-08T14:04:32Z")

</div>

Hello, I have to install Filebeat on a server (windows). Filebeat will have to read logs file on a shared folder. In my .yml, i got that : filebeat.inputs: - type: log paths: - \\\\dpm\\\*.log But this doesn't work…

---

## [Shard allocation - strange behaviour of index tier preference](https://discuss.elastic.co/t/shard-allocation-strange-behaviour-of-index-tier-preference/326746)

<div class="topic-metadata">

**Author:** [@Michael\_Hyatt](https://discuss.elastic.co/u/Michael_Hyatt)\
**Replies:** 11\
**Last updated:** [March 8, 2023, 1:56pm UTC](https://discuss.elastic.co/t/shard-allocation-strange-behaviour-of-index-tier-preference/326746 "2023-03-08T13:56:43Z")

</div>

Hi there, I have a hot-warm cluster with 2 hot and 2 warm nodes (Elastic cloud v8.6.1). I also have an index that I want to distribute to both, hot and warm-tier nodes. To do that, I want to set up the number of replica…

---

## [Change Wilnogbeat index name](https://discuss.elastic.co/t/change-wilnogbeat-index-name/327273)

<div class="topic-metadata">

**Author:** [@krzychohoho](https://discuss.elastic.co/u/krzychohoho)\
**Replies:** 0\
**Last updated:** [March 8, 2023, 1:08pm UTC](https://discuss.elastic.co/t/change-wilnogbeat-index-name/327273 "2023-03-08T13:08:03Z")

</div>

Hi, I want to change index name from winlogbeat and i am following your instructions. This is my yml file: But still getting this error: Exiting: error loading template: failed to put data stream: could not put data…

---

## [Query index from within an AnalysisProvider?](https://discuss.elastic.co/t/query-index-from-within-an-analysisprovider/327191)

<div class="topic-metadata">

**Author:** [@jnioche](https://discuss.elastic.co/u/jnioche)\
**Replies:** 2\
**Last updated:** [March 8, 2023, 12:38pm UTC](https://discuss.elastic.co/t/query-index-from-within-an-analysisprovider/327191 "2023-03-08T12:38:38Z")

</div>

Hi, Here is the context of my question: Synonym graph token filter backed by Elastic index I am writing a custom AnalysisPlugin to generate a list of synonyms from an Elastic index instead of using a static file. A na…

---

## [Performance implications of \`index.max\_result\_window\` vs \`track\_total\_hits\`](https://discuss.elastic.co/t/performance-implications-of-index-max-result-window-vs-track-total-hits/327270)

<div class="topic-metadata">

**Author:** [@Cristian\_Calara](https://discuss.elastic.co/u/Cristian_Calara)\
**Replies:** 1\
**Last updated:** [March 8, 2023, 12:21pm UTC](https://discuss.elastic.co/t/performance-implications-of-index-max-result-window-vs-track-total-hits/327270 "2023-03-08T12:21:15Z")

</div>

Hello, For example, if we would have 50.000 results for a search query. If we really need to return an exact total number of matches and we enabled track\_total\_hits to get it. Should we just as well increase the max\_res…

---

## [Elastic search container upgrade from 7.10.2 to 7.17.9](https://discuss.elastic.co/t/elastic-search-container-upgrade-from-7-10-2-to-7-17-9/327061)

<div class="topic-metadata">

**Author:** [@sundar.s](https://discuss.elastic.co/u/sundar.s)\
**Replies:** 2\
**Last updated:** [March 8, 2023, 12:03pm UTC](https://discuss.elastic.co/t/elastic-search-container-upgrade-from-7-10-2-to-7-17-9/327061 "2023-03-08T12:03:11Z")

</div>

Hi, We are trying to upgrade from 7.10.2 Elasticsearch containers to 7.17.9. Can I ran my Elasticsearch container directly on the data node created/used by 7.10.2 containers ? Do I need to do additional steps to make s…

---

## [What is the best method to backup Fleet policies](https://discuss.elastic.co/t/what-is-the-best-method-to-backup-fleet-policies/327265)

<div class="topic-metadata">

**Author:** [@Patryk\_Ostrowski](https://discuss.elastic.co/u/Patryk_Ostrowski)\
**Replies:** 0\
**Last updated:** [March 8, 2023, 10:55am UTC](https://discuss.elastic.co/t/what-is-the-best-method-to-backup-fleet-policies/327265 "2023-03-08T10:55:51Z")

</div>

Hello, In the event of server failures, I have snapshots to recover data. But how can I recover fleet server integration configurations, installed agents and their policies?

---

## [Elastic.Clients.Elasticsearch 8.x (custom) serialization](https://discuss.elastic.co/t/elastic-clients-elasticsearch-8-x-custom-serialization/324435)

<div class="topic-metadata">

**Author:** [@KoalaBear](https://discuss.elastic.co/u/KoalaBear)\
**Replies:** 3\
**Last updated:** [March 8, 2023, 10:11am UTC](https://discuss.elastic.co/t/elastic-clients-elasticsearch-8-x-custom-serialization/324435 "2023-03-08T10:11:32Z")

</div>

I would like to do something like we have in Netwonsoft Json: options.SerializerSettings.ReferenceLoopHandling = Newtonsoft.Json.ReferenceLoopHandling.Ignore And also have in System.Text.Json: JsonSerializerOptions op…

---

## [How to filter date with optional keyword search](https://discuss.elastic.co/t/how-to-filter-date-with-optional-keyword-search/327260)

<div class="topic-metadata">

**Author:** [@gopikrish](https://discuss.elastic.co/u/gopikrish)\
**Replies:** 0\
**Last updated:** [March 8, 2023, 10:08am UTC](https://discuss.elastic.co/t/how-to-filter-date-with-optional-keyword-search/327260 "2023-03-08T10:08:48Z")

</div>

Hi All , while retrieving data from ELK, I need to filter records between two date(mandatory) with keyword (optional) parameter. The searching keyword is only present in value format not in key value pair. For eg ; { …

---

## [Vega kibana Dashboard Lagging](https://discuss.elastic.co/t/vega-kibana-dashboard-lagging/327259)

<div class="topic-metadata">

**Author:** [@Farah\_Bhr](https://discuss.elastic.co/u/Farah_Bhr)\
**Replies:** 0\
**Last updated:** [March 8, 2023, 9:56am UTC](https://discuss.elastic.co/t/vega-kibana-dashboard-lagging/327259 "2023-03-08T09:56:46Z")

</div>

I created a vega kibana dashboard from an elasticsearch query with different mark types: 2 areas, rule, rect and symbols I created a tooltip too but when hovering with the mouse , I got the Vega Kibana dashboard lagging…

---

## [Index.mapping.depth.limit not persistent after an index rollover](https://discuss.elastic.co/t/index-mapping-depth-limit-not-persistent-after-an-index-rollover/327182)

<div class="topic-metadata">

**Author:** [@Khaled\_Saidi](https://discuss.elastic.co/u/Khaled_Saidi)\
**Replies:** 2\
**Last updated:** [March 8, 2023, 8:58am UTC](https://discuss.elastic.co/t/index-mapping-depth-limit-not-persistent-after-an-index-rollover/327182 "2023-03-08T08:58:52Z")

</div>

Hi everyone, I notice that when the current index is rollovered, the index.mapping.depth.limit is not take into account for the new created index. We are running an elasticsearch cluster and after we have created the f…

---

## [Elastic Search \> @SearchUI \> group with sort](https://discuss.elastic.co/t/elastic-search-searchui-group-with-sort/327154)

<div class="topic-metadata">

**Author:** [@parliament718](https://discuss.elastic.co/u/parliament718)\
**Replies:** 15\
**Last updated:** [March 8, 2023, 8:39am UTC](https://discuss.elastic.co/t/elastic-search-searchui-group-with-sort/327154 "2023-03-08T08:39:10Z")

</div>

I've been trying for days to get group+sort working with @search-ui, with either the app-search connector or the elasticsearch connector with limited success with both. Originally I used the app-search connector and set…

---

## [Not able to remove tag from xml](https://discuss.elastic.co/t/not-able-to-remove-tag-from-xml/326771)

<div class="topic-metadata">

**Author:** [@Navya\_04](https://discuss.elastic.co/u/Navya_04)\
**Replies:** 14\
**Last updated:** [March 8, 2023, 8:32am UTC](https://discuss.elastic.co/t/not-able-to-remove-tag-from-xml/326771 "2023-03-08T08:32:22Z")

</div>

I am trying to load xml through logstash. I have an unwnated tag which needs to be removed from xml while parsing. Used remove\_tag but not able to remove the tag while indexing to Elasticsearch xml File \<?xml version="…

---

## [Filebeat connection error with logstash](https://discuss.elastic.co/t/filebeat-connection-error-with-logstash/327208)

<div class="topic-metadata">

**Author:** [@sebglon](https://discuss.elastic.co/u/sebglon)\
**Replies:** 1\
**Last updated:** [March 8, 2023, 8:24am UTC](https://discuss.elastic.co/t/filebeat-connection-error-with-logstash/327208 "2023-03-08T08:24:03Z")

</div>

Hi, We have a K8s cluster with more than 30 nodes. on each nodes we have a filebeat agent to collect container logs and node logs. filebeat agents send data to 3 logstash on the same cluster. On some nodes and after …

[Previous page](https://discuss.elastic.co/latest.md?page=754)

[Next page](https://discuss.elastic.co/latest.md?page=756)
