# Latest

**URL:** https://discuss.elastic.co/latest.md?page=757

[Latest](https://discuss.elastic.co/latest.md) · [Categories](https://discuss.elastic.co/categories.md) · [Tags](https://discuss.elastic.co/tags.md)

**Page:** 758

---

## [Data from Filebeat Not Showing in Elastic](https://discuss.elastic.co/t/data-from-filebeat-not-showing-in-elastic/326922)

<div class="topic-metadata">

**Author:** [@ataylor](https://discuss.elastic.co/u/ataylor)\
**Replies:** 1\
**Last updated:** [March 7, 2023, 1:41pm UTC](https://discuss.elastic.co/t/data-from-filebeat-not-showing-in-elastic/326922 "2023-03-07T13:41:09Z")

</div>

Hi, Hoping you can help. I am fairly new to Elastic Stack, but the company i work for have a running implementation monitoring Apache logs. I am attempting to add to the functionality by also monitoring the access log …

---

## [Profiling kNN search](https://discuss.elastic.co/t/profiling-knn-search/327065)

<div class="topic-metadata">

**Author:** [@ruslaniv](https://discuss.elastic.co/u/ruslaniv)\
**Replies:** 4\
**Last updated:** [March 7, 2023, 1:33pm UTC](https://discuss.elastic.co/t/profiling-knn-search/327065 "2023-03-07T13:33:27Z")

</div>

I'm trying to profile slow kNN search as discussed here . So I read the documentation here and set up this query in Postman: { "profile": true, "knn": { "field": "title\_vector", "query\_vector": {{SEARCH\_TEX…

---

## [Table of contents with parameters](https://discuss.elastic.co/t/table-of-contents-with-parameters/326936)

<div class="topic-metadata">

**Author:** [@Alice\_Ionescu](https://discuss.elastic.co/u/Alice_Ionescu)\
**Replies:** 1\
**Last updated:** [March 7, 2023, 1:33pm UTC](https://discuss.elastic.co/t/table-of-contents-with-parameters/326936 "2023-03-07T13:33:18Z")

</div>

Hello, I have a markdown visualization with links to other dashboards. (a table of content) I would like to add a parameter (css combo box, a control visualization) and to pass the value to the links in the markdown vi…

---

## [Breakdown chart is missing in the trace sample](https://discuss.elastic.co/t/breakdown-chart-is-missing-in-the-trace-sample/327030)

<div class="topic-metadata">

**Author:** [@rahul\_sirugudi](https://discuss.elastic.co/u/rahul_sirugudi)\
**Replies:** 4\
**Last updated:** [March 7, 2023, 1:02pm UTC](https://discuss.elastic.co/t/breakdown-chart-is-missing-in-the-trace-sample/327030 "2023-03-07T13:02:27Z")

</div>

Recently i have observed that in APM transactions chart it is not showing me any break down that where time has mostly spent. I was expecting the format in this way, but not sure why the break down chart is missing. …

---

## [Parsing multiple JSON entries merged inside 1 "message" of filebeat input Azure Blob Storage](https://discuss.elastic.co/t/parsing-multiple-json-entries-merged-inside-1-message-of-filebeat-input-azure-blob-storage/323153)

<div class="topic-metadata">

**Author:** [@Marquito](https://discuss.elastic.co/u/Marquito)\
**Replies:** 1\
**Last updated:** [March 7, 2023, 12:46pm UTC](https://discuss.elastic.co/t/parsing-multiple-json-entries-merged-inside-1-message-of-filebeat-input-azure-blob-storage/323153 "2023-03-07T12:46:38Z")

</div>

Hello Everyone, I am currently trying to parse a message that contains multiple JSON entries with filebeat input Azure Blob Storage. I have tried using decode\_json\_fields, multiline but it seems like "multiline" only wo…

---

## [Http transaction is success although error](https://discuss.elastic.co/t/http-transaction-is-success-although-error/327075)

<div class="topic-metadata">

**Author:** [@avlachopoulos](https://discuss.elastic.co/u/avlachopoulos)\
**Replies:** 1\
**Last updated:** [March 7, 2023, 12:28pm UTC](https://discuss.elastic.co/t/http-transaction-is-success-although-error/327075 "2023-03-07T12:28:11Z")

</div>

I have a simple web transaction using fast api to test APM. The code is the following: app.get("/critical", status\_code=500) def critcal\_failure(): try: print("Doing something critical") raise Except…

---

## [Falied to start Elasticsearch to my group volumes](https://discuss.elastic.co/t/falied-to-start-elasticsearch-to-my-group-volumes/325501)

<div class="topic-metadata">

**Author:** [@MonkeyD.J](https://discuss.elastic.co/u/MonkeyD.J)\
**Replies:** 9\
**Last updated:** [March 7, 2023, 12:17pm UTC](https://discuss.elastic.co/t/falied-to-start-elasticsearch-to-my-group-volumes/325501 "2023-03-07T12:17:15Z")

</div>

Hello, Mrs,Mr, I try to start Elasticsearch on my volum group. So I am on a debian 11.3 and I install java jre1.8.0\_121. I Install the version elastick 7.17.6 amd64.deb on my folder with this command dpkg -x /applis…

---

## [502 Bad Gateway Ingress nginx with kibana](https://discuss.elastic.co/t/502-bad-gateway-ingress-nginx-with-kibana/327175)

<div class="topic-metadata">

**Author:** [@A\_Mightiev](https://discuss.elastic.co/u/A_Mightiev)\
**Replies:** 1\
**Last updated:** [March 7, 2023, 12:13pm UTC](https://discuss.elastic.co/t/502-bad-gateway-ingress-nginx-with-kibana/327175 "2023-03-07T12:13:56Z")

</div>

I deployed kibana on a kubernetes cluster the port-forward locally works, I can surf on kibana but when set my ingress configuration, it comes back with a 502 Bad Gateway. Please help! This is my ingress configuration: …

---

## [Enterprise Search MySQL native connector](https://discuss.elastic.co/t/enterprise-search-mysql-native-connector/327082)

<div class="topic-metadata">

**Author:** [@sebastianboelling](https://discuss.elastic.co/u/sebastianboelling)\
**Replies:** 2\
**Last updated:** [March 7, 2023, 11:30am UTC](https://discuss.elastic.co/t/enterprise-search-mysql-native-connector/327082 "2023-03-07T11:30:20Z")

</div>

Hi, I have an on-premise deployment of Enterprise Search 8.6.2. based on the docker compose example Install Elasticsearch with Docker | Elasticsearch Guide \[8.6\] | Elastic I am trying out the native connector to MySQL…

---

## [Elasticsearch update by query](https://discuss.elastic.co/t/elasticsearch-update-by-query/327167)

<div class="topic-metadata">

**Author:** [@v-lixiubo](https://discuss.elastic.co/u/v-lixiubo)\
**Replies:** 1\
**Last updated:** [March 7, 2023, 11:30am UTC](https://discuss.elastic.co/t/elasticsearch-update-by-query/327167 "2023-03-07T11:30:14Z")

</div>

hi , I use the java client updateByQuery to update the data, and the returned result is successful, but the data has not actually changed

---

## [LogStash - Issue with sql\_last\_value and last\_run\_metadata\_path](https://discuss.elastic.co/t/logstash-issue-with-sql-last-value-and-last-run-metadata-path/327087)

<div class="topic-metadata">

**Author:** [@CedMathis](https://discuss.elastic.co/u/CedMathis)\
**Replies:** 1\
**Last updated:** [March 7, 2023, 11:08am UTC](https://discuss.elastic.co/t/logstash-issue-with-sql-last-value-and-last-run-metadata-path/327087 "2023-03-07T11:08:07Z")

</div>

Hello, I'm new to ELK and I'm currently struggling with some setup - maybe I missed a point. I have set up my Logstash to parse my DB (MySql), and I've got 2 cases: "Unforeseen maintenance" -\> In this case, I would…

---

## [Can we add dynamic text to our dashboard?](https://discuss.elastic.co/t/can-we-add-dynamic-text-to-our-dashboard/327064)

<div class="topic-metadata">

**Author:** [@Sugunakar](https://discuss.elastic.co/u/Sugunakar)\
**Replies:** 7\
**Last updated:** [March 7, 2023, 9:56am UTC](https://discuss.elastic.co/t/can-we-add-dynamic-text-to-our-dashboard/327064 "2023-03-07T09:56:59Z")

</div>

Hi, I am new to Kibana reporting. Is there any way to add Dynamic text to Kibana using any API or using Python script. Thanks in advance.

---

## [Unable to select a different output in my agent policy](https://discuss.elastic.co/t/unable-to-select-a-different-output-in-my-agent-policy/326955)

<div class="topic-metadata">

**Author:** [@Lamine](https://discuss.elastic.co/u/Lamine)\
**Replies:** 1\
**Last updated:** [March 7, 2023, 9:42am UTC](https://discuss.elastic.co/t/unable-to-select-a-different-output-in-my-agent-policy/326955 "2023-03-07T09:42:19Z")

</div>

Hello everyone, I am trying to configure two different outputs for my agents, but when i try to create the agent policy, I am unable to select a different output. Does anyone know the reason? Thank you

---

## [Apm-server keeps retrying to insert an incorrect data](https://discuss.elastic.co/t/apm-server-keeps-retrying-to-insert-an-incorrect-data/326417)

<div class="topic-metadata">

**Author:** [@blazek](https://discuss.elastic.co/u/blazek)\
**Replies:** 2\
**Last updated:** [March 7, 2023, 9:39am UTC](https://discuss.elastic.co/t/apm-server-keeps-retrying-to-insert-an-incorrect-data/326417 "2023-03-07T09:39:14Z")

</div>

Elasticsearch version: 7.17.5 APM Server version: 7.17.5 APM Agent language and version: open-telemetry .net, Original install method (e.g. download page, yum, deb, from source, etc.) and version: deb Fresh install o…

---

## [Uploading more than 15 engines in meta engine](https://discuss.elastic.co/t/uploading-more-than-15-engines-in-meta-engine/326737)

<div class="topic-metadata">

**Author:** [@mansi\_raval](https://discuss.elastic.co/u/mansi_raval)\
**Replies:** 8\
**Last updated:** [March 7, 2023, 9:26am UTC](https://discuss.elastic.co/t/uploading-more-than-15-engines-in-meta-engine/326737 "2023-03-07T09:26:51Z")

</div>

I have a set of more than 15 engines that I've created in elastic app search and I want to create a meta engine with them. Is there any way I can increase the capacity of the meta engine? If the capacity can't be increa…

---

## [Cannot create elastic indexes after removing two nodes from cassandra](https://discuss.elastic.co/t/cannot-create-elastic-indexes-after-removing-two-nodes-from-cassandra/327151)

<div class="topic-metadata">

**Author:** [@Ram5](https://discuss.elastic.co/u/Ram5)\
**Replies:** 4\
**Last updated:** [March 7, 2023, 9:24am UTC](https://discuss.elastic.co/t/cannot-create-elastic-indexes-after-removing-two-nodes-from-cassandra/327151 "2023-03-07T09:24:47Z")

</div>

I cannot create elastic index after removing two nodes from cassandra. We had two nodes earlier, but for some reason they were unable to communicate with each other. So we removed them and changed necessary configuration…

---

## [Change the stream names](https://discuss.elastic.co/t/change-the-stream-names/327153)

<div class="topic-metadata">

**Author:** [@bex](https://discuss.elastic.co/u/bex)\
**Replies:** 3\
**Last updated:** [March 7, 2023, 9:15am UTC](https://discuss.elastic.co/t/change-the-stream-names/327153 "2023-03-07T09:15:30Z")

</div>

Is it possible to change or indicate the stream(index) name like "index =\> "client-1-%{+dd.MM.YYYY}" when using fleet server and elastic agent in logstash output. There are streams with default name like "logs-auditd.lo…

---

## ["Cannot write to a field alias \[...\]" on reindex](https://discuss.elastic.co/t/cannot-write-to-a-field-alias-on-reindex/327162)

<div class="topic-metadata">

**Author:** [@Adrien](https://discuss.elastic.co/u/Adrien)\
**Replies:** 0\
**Last updated:** [March 7, 2023, 9:14am UTC](https://discuss.elastic.co/t/cannot-write-to-a-field-alias-on-reindex/327162 "2023-03-07T09:14:59Z")

</div>

Hi, I'm trying to migrate an Elasticsearch index from 6.8 to 7.10 using the \_reindex route API. Unfortunately during the index migration I get the error Cannot write to a field alias \[gl2\_message\_id\]. The mapping, cop…

---

## [Can't assume role in filebeat cloudwatch input when IAM policy can assume multiple roles](https://discuss.elastic.co/t/cant-assume-role-in-filebeat-cloudwatch-input-when-iam-policy-can-assume-multiple-roles/327159)

<div class="topic-metadata">

**Author:** [@stwang](https://discuss.elastic.co/u/stwang)\
**Replies:** 0\
**Last updated:** [March 7, 2023, 9:10am UTC](https://discuss.elastic.co/t/cant-assume-role-in-filebeat-cloudwatch-input-when-iam-policy-can-assume-multiple-roles/327159 "2023-03-07T09:10:55Z")

</div>

We are using filebeat 7.17.5, and we are using CloudWatch input, we want to retrieve log from another AWS account b and AWS account c. So in filebeat AWS role, we have a policy which allow to assume roles for other two …

---

## [Filebeat - Single line log without newline character](https://discuss.elastic.co/t/filebeat-single-line-log-without-newline-character/327157)

<div class="topic-metadata">

**Author:** [@True](https://discuss.elastic.co/u/True)\
**Replies:** 0\
**Last updated:** [March 7, 2023, 8:45am UTC](https://discuss.elastic.co/t/filebeat-single-line-log-without-newline-character/327157 "2023-03-07T08:45:51Z")

</div>

Hello :smiling\_face\_with\_tear: Is there any possible method for shipping single-line logs without newline characters from Filebeat to Kafka? I'm using 8.6.1 Stack, and in Filebeat, filestream (log) type. The log is cr…

---

## [Apply minimum score parameter for the child queries](https://discuss.elastic.co/t/apply-minimum-score-parameter-for-the-child-queries/327139)

<div class="topic-metadata">

**Author:** [@Rahul\_S1](https://discuss.elastic.co/u/Rahul_S1)\
**Replies:** 0\
**Last updated:** [March 7, 2023, 5:42am UTC](https://discuss.elastic.co/t/apply-minimum-score-parameter-for-the-child-queries/327139 "2023-03-07T05:42:19Z")

</div>

I'm trying to apply some minimum score criteria for my has child queries, my data looks like this: {"Product Code": "A", "properties" :\[{"PROPERTY\_NAME":"density","PROPERTY\_NAME Encoded":\[0.22,0.432,.....\],"value":"low"…

---

## [Zone within data Centre](https://discuss.elastic.co/t/zone-within-data-centre/327141)

<div class="topic-metadata">

**Author:** [@Mani2](https://discuss.elastic.co/u/Mani2)\
**Replies:** 0\
**Last updated:** [March 7, 2023, 5:54am UTC](https://discuss.elastic.co/t/zone-within-data-centre/327141 "2023-03-07T05:54:19Z")

</div>

What can be criteria of deciding the maximum number of zones within a data centre. For ex, If I have 30 Racks in a Data Centre, and if I have Primary and Secondary shards are 1,2 so minimum zones require will be 3. If ea…

---

## [Different Version Elasticsearch, Kibana, Metricbeat](https://discuss.elastic.co/t/different-version-elasticsearch-kibana-metricbeat/327136)

<div class="topic-metadata">

**Author:** [@Tw1cUser](https://discuss.elastic.co/u/Tw1cUser)\
**Replies:** 2\
**Last updated:** [March 7, 2023, 5:47am UTC](https://discuss.elastic.co/t/different-version-elasticsearch-kibana-metricbeat/327136 "2023-03-07T05:47:01Z")

</div>

is it ok if use Elasticsearch, Kibana, Metricbeat version 8.6.1 to connect to version 8.6.2?

---

## [How to write a collation rule for icu\_collation\_keyword field, with alphabets having atmost precedence?](https://discuss.elastic.co/t/how-to-write-a-collation-rule-for-icu-collation-keyword-field-with-alphabets-having-atmost-precedence/327019)

<div class="topic-metadata">

**Author:** [@Karthik\_Amar](https://discuss.elastic.co/u/Karthik_Amar)\
**Replies:** 3\
**Last updated:** [March 7, 2023, 5:27am UTC](https://discuss.elastic.co/t/how-to-write-a-collation-rule-for-icu-collation-keyword-field-with-alphabets-having-atmost-precedence/327019 "2023-03-07T05:27:10Z")

</div>

Instead of using alternative locale option, I want to write a rules parameter to customise the sort behaviour with alphabets having atmost precedence. for the text values, $1232, Abi, £7232, 87343, Karthik I want the…

---

## [Filebeat gives an error when it outputs to elasticsearch](https://discuss.elastic.co/t/filebeat-gives-an-error-when-it-outputs-to-elasticsearch/326665)

<div class="topic-metadata">

**Author:** [@limedong1](https://discuss.elastic.co/u/limedong1)\
**Replies:** 2\
**Last updated:** [March 7, 2023, 5:14am UTC](https://discuss.elastic.co/t/filebeat-gives-an-error-when-it-outputs-to-elasticsearch/326665 "2023-03-07T05:14:10Z")

</div>

我的elastic集群版本是8.6.0,filebeat 版本是8.6.0 日志已经能够成功读取到了，就是日志输出时会有一部分报错， Failed to connect to backoff(elasticsearch(http://192.168.3.74:30920)): Connection marked as failed because the onConnect callback failed: error loadin…

---

## [Auditbeat Version 8.4.1 event.category](https://discuss.elastic.co/t/auditbeat-version-8-4-1-event-category/327137)

<div class="topic-metadata">

**Author:** [@jjacksonrkk](https://discuss.elastic.co/u/jjacksonrkk)\
**Replies:** 0\
**Last updated:** [March 7, 2023, 5:08am UTC](https://discuss.elastic.co/t/auditbeat-version-8-4-1-event-category/327137 "2023-03-07T05:08:18Z")

</div>

Auditbeat version 8.4.1 is in use. When debugging, event.category occurs as \["intrusion\_detection", "process"\] When running the auditbeat daemon service, event.category appears only as process, what should I set in audi…

---

## [Is there query char length limit of a match query](https://discuss.elastic.co/t/is-there-query-char-length-limit-of-a-match-query/327020)

<div class="topic-metadata">

**Author:** [@chenchuangc](https://discuss.elastic.co/u/chenchuangc)\
**Replies:** 2\
**Last updated:** [March 7, 2023, 1:49am UTC](https://discuss.elastic.co/t/is-there-query-char-length-limit-of-a-match-query/327020 "2023-03-07T01:49:34Z")

</div>

Thank you so much for having a look of my issue. ES Version 7.5.0 Query GET search\_vietnamese/\_search { "query": { "bool": { "should": \[ { "match": { "address": { …

---

## [Parsing an html inside a Json](https://discuss.elastic.co/t/parsing-an-html-inside-a-json/327104)

<div class="topic-metadata">

**Author:** [@Mhag](https://discuss.elastic.co/u/Mhag)\
**Replies:** 2\
**Last updated:** [March 6, 2023, 11:06pm UTC](https://discuss.elastic.co/t/parsing-an-html-inside-a-json/327104 "2023-03-06T23:06:35Z")

</div>

Hi, \*\* a longer explanation of the problem is in the second response to @Badger \*\* I need to parse a log with a JSON that contain a field which contains an HTML document, ex : 2023-03-04 20:20:06,817 \[http-nio-8080-ex…

---

## [Is it possible to ignore failure while using the Reindex API?](https://discuss.elastic.co/t/is-it-possible-to-ignore-failure-while-using-the-reindex-api/327120)

<div class="topic-metadata">

**Author:** [@leandrojmp](https://discuss.elastic.co/u/leandrojmp)\
**Replies:** 5\
**Last updated:** [March 6, 2023, 10:01pm UTC](https://discuss.elastic.co/t/is-it-possible-to-ignore-failure-while-using-the-reindex-api/327120 "2023-03-06T22:01:40Z")

</div>

Hello, I'm trying to run some reindex on an index and got a failure related to a mapping parsing exception, which is kinda of expected as on this data the field can change from object to text. For this reason, the dest…

---

## [Reindex document count does not match the source](https://discuss.elastic.co/t/reindex-document-count-does-not-match-the-source/327116)

<div class="topic-metadata">

**Author:** [@Parvatayya\_Malimath](https://discuss.elastic.co/u/Parvatayya_Malimath)\
**Replies:** 1\
**Last updated:** [March 6, 2023, 8:41pm UTC](https://discuss.elastic.co/t/reindex-document-count-does-not-match-the-source/327116 "2023-03-06T20:41:46Z")

</div>

I am reindexing an index from one cluster (elastic 6.8) to another cluster (elastic 7.17) Source: GET \<index\_name\>/\_count { "count" : 827908, "\_shards" : { "total" : 5, "successful" : 5, "skipped" : 0, "failed" …

[Previous page](https://discuss.elastic.co/latest.md?page=756)

[Next page](https://discuss.elastic.co/latest.md?page=758)
