# Latest

**URL:** https://discuss.elastic.co/latest.md?page=758

[Latest](https://discuss.elastic.co/latest.md) · [Categories](https://discuss.elastic.co/categories.md) · [Tags](https://discuss.elastic.co/tags.md)

**Page:** 759

---

## [Simple Query to search within log text (not keyword)](https://discuss.elastic.co/t/simple-query-to-search-within-log-text-not-keyword/327095)

<div class="topic-metadata">

**Author:** [@Mark\_S](https://discuss.elastic.co/u/Mark_S)\
**Replies:** 3\
**Last updated:** [March 6, 2023, 6:51pm UTC](https://discuss.elastic.co/t/simple-query-to-search-within-log-text-not-keyword/327095 "2023-03-06T18:51:30Z")

</div>

I am trying to search within text that originates from log files. Am I using the correct query? Any suggestions on how to restrict results only to the exact match? (eg show only results with higher score?) I am using e…

---

## [Will influencer change the way a model might detect and anomaly?](https://discuss.elastic.co/t/will-influencer-change-the-way-a-model-might-detect-and-anomaly/326908)

<div class="topic-metadata">

**Author:** [@Umang\_Pachaury](https://discuss.elastic.co/u/Umang_Pachaury)\
**Replies:** 3\
**Last updated:** [March 6, 2023, 5:29pm UTC](https://discuss.elastic.co/t/will-influencer-change-the-way-a-model-might-detect-and-anomaly/326908 "2023-03-06T17:29:15Z")

</div>

Hello Team, I am working with the machine learning tools provided by elastic. I am detecting certain rare events over time. But now I have certain fields that I want the model to take in consideration while detecting th…

---

## [Failed to publish events](https://discuss.elastic.co/t/failed-to-publish-events/327090)

<div class="topic-metadata">

**Author:** [@zaeemmasood](https://discuss.elastic.co/u/zaeemmasood)\
**Replies:** 1\
**Last updated:** [March 6, 2023, 5:18pm UTC](https://discuss.elastic.co/t/failed-to-publish-events/327090 "2023-03-06T17:18:56Z")

</div>

Hi All, We see the following error in filebeat log resulting in loss of data: pipeline/output.go:121 Failed to publish events: write tcp 19.14.25.26:42660-\>14.18.8.1:5044: write: connection reset by peer It seems tha…

---

## [Saving the content of a file in an elasticsearch index using springboot RESTAPI](https://discuss.elastic.co/t/saving-the-content-of-a-file-in-an-elasticsearch-index-using-springboot-restapi/327112)

<div class="topic-metadata">

**Author:** [@BEY\_MEHREZ](https://discuss.elastic.co/u/BEY_MEHREZ)\
**Replies:** 0\
**Last updated:** [March 6, 2023, 5:14pm UTC](https://discuss.elastic.co/t/saving-the-content-of-a-file-in-an-elasticsearch-index-using-springboot-restapi/327112 "2023-03-06T17:14:53Z")

</div>

So I am building a Spring Boot rest api that it takes a file ( Multipart file ) ( and it is a log file ) as an argument and saves its content in a unique elasticsearch index ! Each line of the file will be in a document.…

---

## [Alter Search UI React App's query paramter](https://discuss.elastic.co/t/alter-search-ui-react-apps-query-paramter/326469)

<div class="topic-metadata">

**Author:** [@John\_Brandenburg](https://discuss.elastic.co/u/John_Brandenburg)\
**Replies:** 7\
**Last updated:** [March 6, 2023, 5:14pm UTC](https://discuss.elastic.co/t/alter-search-ui-react-apps-query-paramter/326469 "2023-03-06T17:14:16Z")

</div>

I am trying to set up the search-ui with an app search engine, and embed the generated app into an existing website. One issue I am running into is a clash with the query parameter "?q=". The app uses this for the keywor…

---

## [Debugging lost data in logstash coming from filebeat](https://discuss.elastic.co/t/debugging-lost-data-in-logstash-coming-from-filebeat/327110)

<div class="topic-metadata">

**Author:** [@mayer](https://discuss.elastic.co/u/mayer)\
**Replies:** 0\
**Last updated:** [March 6, 2023, 5:07pm UTC](https://discuss.elastic.co/t/debugging-lost-data-in-logstash-coming-from-filebeat/327110 "2023-03-06T17:07:51Z")

</div>

Dear All, I am running a central ELK stack 8.6.2 with logstash to collect data from some server around. More than 2 years ago I compiled filebeat by myself as it was not available on ARM architecture. With a minimal con…

---

## [Bufforing logs using ingest node](https://discuss.elastic.co/t/bufforing-logs-using-ingest-node/327103)

<div class="topic-metadata">

**Author:** [@krzychohoho](https://discuss.elastic.co/u/krzychohoho)\
**Replies:** 1\
**Last updated:** [March 6, 2023, 4:50pm UTC](https://discuss.elastic.co/t/bufforing-logs-using-ingest-node/327103 "2023-03-06T16:50:27Z")

</div>

Hi, I need to create an Elastic SIEM cluster in which logs will be buffered in the event of a data node failure. When the data node is brought back to life, the logs from the period when the node was not functioning wil…

---

## [Elasticsearch Compilation issues on Linux](https://discuss.elastic.co/t/elasticsearch-compilation-issues-on-linux/327096)

<div class="topic-metadata">

**Author:** [@markchennai](https://discuss.elastic.co/u/markchennai)\
**Replies:** 2\
**Last updated:** [March 6, 2023, 3:19pm UTC](https://discuss.elastic.co/t/elasticsearch-compilation-issues-on-linux/327096 "2023-03-06T15:19:47Z")

</div>

Team, I am facing issues while compiling Elasticsearch 8.5.1, the source code is allowed to pull the files from the in-house repo, FAILURE: Build failed with an exception. What went wrong: A problem occurred configu…

---

## [Logstash still holding onto deleted logstash application logs](https://discuss.elastic.co/t/logstash-still-holding-onto-deleted-logstash-application-logs/325479)

<div class="topic-metadata">

**Author:** [@Shreesh\_Narayanan](https://discuss.elastic.co/u/Shreesh_Narayanan)\
**Replies:** 3\
**Last updated:** [March 6, 2023, 3:09pm UTC](https://discuss.elastic.co/t/logstash-still-holding-onto-deleted-logstash-application-logs/325479 "2023-03-06T15:09:12Z")

</div>

Hello, It seems logstash refuses to let go of deleted logs (logstash's own logs) and this takes up all the space on disks , until a service restart takes place . Is there a way , we could fix this ? Is something need to…

---

## [Error from NodeJS APM package: "APM Server transport error: error fetching APM Server version"](https://discuss.elastic.co/t/error-from-nodejs-apm-package-apm-server-transport-error-error-fetching-apm-server-version/326707)

<div class="topic-metadata">

**Author:** [@pocketcolin](https://discuss.elastic.co/u/pocketcolin)\
**Replies:** 2\
**Last updated:** [March 6, 2023, 3:05pm UTC](https://discuss.elastic.co/t/error-from-nodejs-apm-package-apm-server-transport-error-error-fetching-apm-server-version/326707 "2023-03-06T15:05:52Z")

</div>

This error is showing up when my server first starts up and initializes the APM service. It doesn't actually cause any issues from what I can tell and the APM starts up fine, but I'd love to understand why it's throwing …

---

## [Elastic Docker Integration - not collecting logs](https://discuss.elastic.co/t/elastic-docker-integration-not-collecting-logs/326947)

<div class="topic-metadata">

**Author:** [@sc1215](https://discuss.elastic.co/u/sc1215)\
**Replies:** 4\
**Last updated:** [March 6, 2023, 3:01pm UTC](https://discuss.elastic.co/t/elastic-docker-integration-not-collecting-logs/326947 "2023-03-06T15:01:20Z")

</div>

I had been using the 'System' integration agent to consume my docker logs which are saved in the path: /var/lib/docker/containers/\*/\*-json.log This has been working, but unfortunately, it was splitting up log lines whic…

---

## [Best way to Send data from influxdb to elastic](https://discuss.elastic.co/t/best-way-to-send-data-from-influxdb-to-elastic/327010)

<div class="topic-metadata">

**Author:** [@Indeed2000](https://discuss.elastic.co/u/Indeed2000)\
**Replies:** 6\
**Last updated:** [March 6, 2023, 2:49pm UTC](https://discuss.elastic.co/t/best-way-to-send-data-from-influxdb-to-elastic/327010 "2023-03-06T14:49:36Z")

</div>

Hi I have influxdb in production that store metric from different source now question is: 1-How can i send these metric to elastic for realtime analysis? 2-which is better? read data with elastic from influx, or confi…

---

## [Logstash Config File not running getting error: contains non-ascii characters but are not UTF-8 encoded](https://discuss.elastic.co/t/logstash-config-file-not-running-getting-error-contains-non-ascii-characters-but-are-not-utf-8-encoded/327080)

<div class="topic-metadata">

**Author:** [@PRASHANT\_MEHTA](https://discuss.elastic.co/u/PRASHANT_MEHTA)\
**Replies:** 2\
**Last updated:** [March 6, 2023, 2:24pm UTC](https://discuss.elastic.co/t/logstash-config-file-not-running-getting-error-contains-non-ascii-characters-but-are-not-utf-8-encoded/327080 "2023-03-06T14:24:27Z")

</div>

Hello All, I'm getting below error while running the logstash config,Unable to understand how it can be resolved.Eearlier it worked by now giving error. input { jdbc { jdbc\_connection\_string =\> "jdbc:oracle:thin…

---

## [Clone a space via API](https://discuss.elastic.co/t/clone-a-space-via-api/327041)

<div class="topic-metadata">

**Author:** [@oliverj](https://discuss.elastic.co/u/oliverj)\
**Replies:** 1\
**Last updated:** [March 6, 2023, 2:23pm UTC](https://discuss.elastic.co/t/clone-a-space-via-api/327041 "2023-03-06T14:23:18Z")

</div>

We are standing up our first Cluster, and one of the things we have run into is that people have no "user context" for the artifcats they create. Everything is shared by space. So, our plan is to have 2 spaces for our us…

---

## [java.lang.RuntimeException when using client in Java API in Kotlin](https://discuss.elastic.co/t/java-lang-runtimeexception-when-using-client-in-java-api-in-kotlin/327013)

<div class="topic-metadata">

**Author:** [@GAETANO\_SIMONELLI](https://discuss.elastic.co/u/GAETANO_SIMONELLI)\
**Replies:** 6\
**Last updated:** [March 6, 2023, 1:05pm UTC](https://discuss.elastic.co/t/java-lang-runtimeexception-when-using-client-in-java-api-in-kotlin/327013 "2023-03-06T13:05:38Z")

</div>

I am trying to use the Elasticsearch Java API in a Kotlin application, following the official tutorial page (Connecting | Elasticsearch Java API Client \[8.6\] | Elastic). However, I am encountering a java.lang.RuntimeExce…

---

## [Calculate MTTR for jenkins builds](https://discuss.elastic.co/t/calculate-mttr-for-jenkins-builds/327067)

<div class="topic-metadata">

**Author:** [@khuongdp](https://discuss.elastic.co/u/khuongdp)\
**Replies:** 2\
**Last updated:** [March 6, 2023, 1:44pm UTC](https://discuss.elastic.co/t/calculate-mttr-for-jenkins-builds/327067 "2023-03-06T13:44:20Z")

</div>

Hi I would like to calculate MTTR for some jenkins builds. I have these fields in multiple documents: Using Elasticsearch 8.3.0 input : name, type \[type1|type2\], status \[failure|success\], buildDateTime Output (somet…

---

## [High CPU Utilization in Elasticsearch Nodes](https://discuss.elastic.co/t/high-cpu-utilization-in-elasticsearch-nodes/327078)

<div class="topic-metadata">

**Author:** [@Souvik\_Das](https://discuss.elastic.co/u/Souvik_Das)\
**Replies:** 0\
**Last updated:** [March 6, 2023, 1:12pm UTC](https://discuss.elastic.co/t/high-cpu-utilization-in-elasticsearch-nodes/327078 "2023-03-06T13:12:26Z")

</div>

Hi, We have been experiencing HIGH CPU USAGE in elasticsearch nodes for the last couple of days causing timeout exceptions for most of the search queries. We have dedicated nodes for ES, however, there is no defined mas…

---

## [Gauge ordering by value calculated in bucket script aggregation](https://discuss.elastic.co/t/gauge-ordering-by-value-calculated-in-bucket-script-aggregation/327077)

<div class="topic-metadata">

**Author:** [@tumbl3w33d](https://discuss.elastic.co/u/tumbl3w33d)\
**Replies:** 0\
**Last updated:** [March 6, 2023, 1:07pm UTC](https://discuss.elastic.co/t/gauge-ordering-by-value-calculated-in-bucket-script-aggregation/327077 "2023-03-06T13:07:50Z")

</div>

Hello, I'm using elastic agent with its system integration to collect metrics and I want to display the disk use per host as gauges. It's achieved by calculating the percentual use in a bucket script: The ordering d…

---

## [Setup Elastic Watcher Alert to match two message strings in a log](https://discuss.elastic.co/t/setup-elastic-watcher-alert-to-match-two-message-strings-in-a-log/326804)

<div class="topic-metadata">

**Author:** [@scott.godfrey](https://discuss.elastic.co/u/scott.godfrey)\
**Replies:** 3\
**Last updated:** [March 6, 2023, 1:09pm UTC](https://discuss.elastic.co/t/setup-elastic-watcher-alert-to-match-two-message-strings-in-a-log/326804 "2023-03-06T13:09:34Z")

</div>

I'm trying to setup an Elastic Watcher Alert that will scan a logfile and match 2 different messages in the log and then send an alert. Sample Log \[2023-02-13 09:00:10.749 -05:00 INF\] This is test 1 \[2023-02-13 09:10…

---

## [Netty Reactive Monitoring](https://discuss.elastic.co/t/netty-reactive-monitoring/327060)

<div class="topic-metadata">

**Author:** [@Ivan\_Hosea](https://discuss.elastic.co/u/Ivan_Hosea)\
**Replies:** 1\
**Last updated:** [March 6, 2023, 11:45am UTC](https://discuss.elastic.co/t/netty-reactive-monitoring/327060 "2023-03-06T11:45:14Z")

</div>

Hi, I was wondering if there is any way to monitor Netty Reactor. From the documentation I see that it doesn't have anything to say about Netty Reactor, but Reactor itself seems to be supported experimentally: Supported …

---

## [All the shards are being assigned to a single node](https://discuss.elastic.co/t/all-the-shards-are-being-assigned-to-a-single-node/326857)

<div class="topic-metadata">

**Author:** [@sanju1323](https://discuss.elastic.co/u/sanju1323)\
**Replies:** 4\
**Last updated:** [March 6, 2023, 11:27am UTC](https://discuss.elastic.co/t/all-the-shards-are-being-assigned-to-a-single-node/326857 "2023-03-06T11:27:41Z")

</div>

Hi.. We have a 6 data node cluster and we have around 2000 indices with 9500 shards. We have the below cluster settings and have enabled all the shards to be re-balanced to distribute the shards across the cluster. { …

---

## [Elasticsearch deprecation issues](https://discuss.elastic.co/t/elasticsearch-deprecation-issues/325543)

<div class="topic-metadata">

**Author:** [@hermlam](https://discuss.elastic.co/u/hermlam)\
**Replies:** 5\
**Last updated:** [March 6, 2023, 11:20am UTC](https://discuss.elastic.co/t/elasticsearch-deprecation-issues/325543 "2023-03-06T11:20:40Z")

</div>

I can't upgrade to 8.6.1 due to a deprecation issue. I can't update the elasticsearch.yml, because I have a cloud solution. Problem: setting \[cluster.routing.allocation.disk.watermark.enable\_for\_single\_data\_node\] is dep…

---

## [Make a grok pattern for a field that might be missing](https://discuss.elastic.co/t/make-a-grok-pattern-for-a-field-that-might-be-missing/327014)

<div class="topic-metadata">

**Author:** [@ira-zaya](https://discuss.elastic.co/u/ira-zaya)\
**Replies:** 3\
**Last updated:** [March 6, 2023, 11:12am UTC](https://discuss.elastic.co/t/make-a-grok-pattern-for-a-field-that-might-be-missing/327014 "2023-03-06T11:12:38Z")

</div>

Hi! There are logs in the following format: 2023-03-05 17:07:01.586+0000 \[L: WARN\] \[O: A.b.c.d.e.FGScript\] \[I: \] \[U: email@example.com\] \[S: \] \[P: \] \[T: ABCProcessor-23 \] @@@ aboba=5 beboba=1 ceboba=4 So I have a correc…

---

## [To find top 5 values and All value on selection of radio button on the basis of same field in Vega-lite using Kibana](https://discuss.elastic.co/t/to-find-top-5-values-and-all-value-on-selection-of-radio-button-on-the-basis-of-same-field-in-vega-lite-using-kibana/327066)

<div class="topic-metadata">

**Author:** [@ysattvik](https://discuss.elastic.co/u/ysattvik)\
**Replies:** 0\
**Last updated:** [March 6, 2023, 10:38am UTC](https://discuss.elastic.co/t/to-find-top-5-values-and-all-value-on-selection-of-radio-button-on-the-basis-of-same-field-in-vega-lite-using-kibana/327066 "2023-03-06T10:38:54Z")

</div>

Hi Team, I am trying to implement selection options using radio button to show the top 5 values and other radio button shows the all the values available in that field using Vega-lite. It can be easily explained by this…

---

## [Problem with PowerShell security rules that use process.args](https://discuss.elastic.co/t/problem-with-powershell-security-rules-that-use-process-args/326861)

<div class="topic-metadata">

**Author:** [@Maretti](https://discuss.elastic.co/u/Maretti)\
**Replies:** 2\
**Last updated:** [March 6, 2023, 9:58am UTC](https://discuss.elastic.co/t/problem-with-powershell-security-rules-that-use-process-args/326861 "2023-03-06T09:58:32Z")

</div>

The Problem Rules that are based off powershell like Disabling Windows Defender Security Settings via PowerShell and Windows Firewall Disabled via PowerShell are not giving alerts back. Windows Firewall Disabled via Pow…

---

## [Elastic ML Alert Mustache Syntax (Break Line)](https://discuss.elastic.co/t/elastic-ml-alert-mustache-syntax-break-line/327024)

<div class="topic-metadata">

**Author:** [@aisyaharifin](https://discuss.elastic.co/u/aisyaharifin)\
**Replies:** 1\
**Last updated:** [March 6, 2023, 9:16am UTC](https://discuss.elastic.co/t/elastic-ml-alert-mustache-syntax-break-line/327024 "2023-03-06T09:16:18Z")

</div>

Hi, I would like to adjust my email alert to break to a new line. From above image, the upper context for (Environment Affected) is working as I used {{{foo}}} to break it. However, it does not work for the (Detect…

---

## [Searching non-indexed fields](https://discuss.elastic.co/t/searching-non-indexed-fields/327033)

<div class="topic-metadata">

**Author:** [@kpachar](https://discuss.elastic.co/u/kpachar)\
**Replies:** 1\
**Last updated:** [March 6, 2023, 8:40am UTC](https://discuss.elastic.co/t/searching-non-indexed-fields/327033 "2023-03-06T08:40:00Z")

</div>

Hi everyone, Contrary to popular opinion, I'm able to search non-indexed fields in Elasticsearch. I'm wondering if this is is a bug or a newly introduced feature. I'm on Elasticsearch 8.6.2. The documentation says "Fie…

---

## [File Descriptors count](https://discuss.elastic.co/t/file-descriptors-count/327043)

<div class="topic-metadata">

**Author:** [@avnere](https://discuss.elastic.co/u/avnere)\
**Replies:** 0\
**Last updated:** [March 6, 2023, 8:15am UTC](https://discuss.elastic.co/t/file-descriptors-count/327043 "2023-03-06T08:15:17Z")

</div>

Hi, According to docs it is recommended to set File Descriptors to 65535 (ulimit -n). How it effect my node? What will be the behavior if I will set higher value? for instance: 500000 Thanks

---

## [Metricbeat sends timestamp as keyword type instead of date type to Elasticsearch, old template endpoints work instead of new one](https://discuss.elastic.co/t/metricbeat-sends-timestamp-as-keyword-type-instead-of-date-type-to-elasticsearch-old-template-endpoints-work-instead-of-new-one/326703)

<div class="topic-metadata">

**Author:** [@learner75](https://discuss.elastic.co/u/learner75)\
**Replies:** 2\
**Last updated:** [March 6, 2023, 8:05am UTC](https://discuss.elastic.co/t/metricbeat-sends-timestamp-as-keyword-type-instead-of-date-type-to-elasticsearch-old-template-endpoints-work-instead-of-new-one/326703 "2023-03-06T08:05:05Z")

</div>

Current problem: Metricbeat sends timestamp as keyword type instead of date type. Have to use a separate command with the old index template api to update mapping. Background: Our ELK stack was upgraded from 6.8.23 to …

---

## [Metricbeat services restarted automatically](https://discuss.elastic.co/t/metricbeat-services-restarted-automatically/326822)

<div class="topic-metadata">

**Author:** [@ArpitChoudhary](https://discuss.elastic.co/u/ArpitChoudhary)\
**Replies:** 4\
**Last updated:** [March 6, 2023, 6:53am UTC](https://discuss.elastic.co/t/metricbeat-services-restarted-automatically/326822 "2023-03-06T06:53:36Z")

</div>

Hello Guys. Facing an issue , Metricbeat service is recursively getting restarting. Please find below status/log of service.

[Previous page](https://discuss.elastic.co/latest.md?page=757)

[Next page](https://discuss.elastic.co/latest.md?page=759)
