# Latest

**URL:** https://discuss.elastic.co/latest.md?page=762

[Latest](https://discuss.elastic.co/latest.md) · [Categories](https://discuss.elastic.co/categories.md) · [Tags](https://discuss.elastic.co/tags.md)

**Page:** 763

---

## [Ruby filter counting error Workers](https://discuss.elastic.co/t/ruby-filter-counting-error-workers/326330)

<div class="topic-metadata">

**Author:** [@puched](https://discuss.elastic.co/u/puched)\
**Replies:** 6\
**Last updated:** [March 2, 2023, 12:51pm UTC](https://discuss.elastic.co/t/ruby-filter-counting-error-workers/326330 "2023-03-02T12:51:42Z")

</div>

I want to store the line number as the document\_id, but i saw that sometimes its not storing in the right way the numbers in order, i guess its because of the multiple workers, the question is Is there a way to store num…

---

## [Error fetching data for metricset http.json](https://discuss.elastic.co/t/error-fetching-data-for-metricset-http-json/326848)

<div class="topic-metadata">

**Author:** [@abdul90082](https://discuss.elastic.co/u/abdul90082)\
**Replies:** 0\
**Last updated:** [March 2, 2023, 12:41pm UTC](https://discuss.elastic.co/t/error-fetching-data-for-metricset-http-json/326848 "2023-03-02T12:41:03Z")

</div>

{ "log.level": "error", "@timestamp": "2023-03-02T11:40:42.101Z", "message": "Error fetching data for metricset http.json: error making http request: Get \\"http://unix/stats\\": context deadline exceeded (Client.Timeout e…

---

## [How to check unmanaged indices in Kibana watcher](https://discuss.elastic.co/t/how-to-check-unmanaged-indices-in-kibana-watcher/326749)

<div class="topic-metadata">

**Author:** [@mr\_sharma](https://discuss.elastic.co/u/mr_sharma)\
**Replies:** 2\
**Last updated:** [March 2, 2023, 12:18pm UTC](https://discuss.elastic.co/t/how-to-check-unmanaged-indices-in-kibana-watcher/326749 "2023-03-02T12:18:17Z")

</div>

I've been trying watcher method in Kibana to get alerts if An index is unmanaged (not following any ILM policy) and it's size is more than 10GB. I'm new to Elastic and it seems so difficult develop the watcher script …

---

## [1 dashboard for multiple nodes](https://discuss.elastic.co/t/1-dashboard-for-multiple-nodes/326761)

<div class="topic-metadata">

**Author:** [@avnere](https://discuss.elastic.co/u/avnere)\
**Replies:** 3\
**Last updated:** [March 2, 2023, 12:10pm UTC](https://discuss.elastic.co/t/1-dashboard-for-multiple-nodes/326761 "2023-03-02T12:10:54Z")

</div>

Hi, How can I combine the multiple nodes graphs to 1 dashboard? Thanks

---

## [How to show percentage column in table lens](https://discuss.elastic.co/t/how-to-show-percentage-column-in-table-lens/326825)

<div class="topic-metadata">

**Author:** [@PappuSingh](https://discuss.elastic.co/u/PappuSingh)\
**Replies:** 2\
**Last updated:** [March 2, 2023, 11:20am UTC](https://discuss.elastic.co/t/how-to-show-percentage-column-in-table-lens/326825 "2023-03-02T11:20:13Z")

</div>

Hi, How we can calculate and add a percentage column in the below snap

---

## [How does Logstash convert a integer value to another integer value](https://discuss.elastic.co/t/how-does-logstash-convert-a-integer-value-to-another-integer-value/326830)

<div class="topic-metadata">

**Author:** [@wensi](https://discuss.elastic.co/u/wensi)\
**Replies:** 1\
**Last updated:** [March 2, 2023, 11:02am UTC](https://discuss.elastic.co/t/how-does-logstash-convert-a-integer-value-to-another-integer-value/326830 "2023-03-02T11:02:10Z")

</div>

In the following pipeline, I want to add a shift (1000000) to id column value, id was 1, and I want it to be 1000001. However, with mutate update generates a string "1 + 1000000" instead of making integer shifted. I al…

---

## [How to correctly determine the weight of a node](https://discuss.elastic.co/t/how-to-correctly-determine-the-weight-of-a-node/224871)

<div class="topic-metadata">

**Author:** [@ld\_pvl](https://discuss.elastic.co/u/ld_pvl)\
**Replies:** 1\
**Last updated:** [March 2, 2023, 9:59am UTC](https://discuss.elastic.co/t/how-to-correctly-determine-the-weight-of-a-node/224871 "2023-03-02T09:59:41Z")

</div>

Hey Team, I'm trying to calculate the weights of each node based on the below two settings taken from shard balancing heuristics: cluster.routing.allocation.balance.shard cluster.routing.allocation.balance.index Let's…

---

## [Difference between Hits and Hits(total)](https://discuss.elastic.co/t/difference-between-hits-and-hits-total/326798)

<div class="topic-metadata">

**Author:** [@joerg55](https://discuss.elastic.co/u/joerg55)\
**Replies:** 2\
**Last updated:** [March 2, 2023, 9:18am UTC](https://discuss.elastic.co/t/difference-between-hits-and-hits-total/326798 "2023-03-02T09:18:56Z")

</div>

Hi at all, I'm new here and am trying to create a few charts with vega-lite. With some help from here some bars are to be seen. But I have a problem with the amount of records wich are given from the request. Although m…

---

## [App Search error create engine](https://discuss.elastic.co/t/app-search-error-create-engine/326827)

<div class="topic-metadata">

**Author:** [@GHostlyFOX](https://discuss.elastic.co/u/GHostlyFOX)\
**Replies:** 3\
**Last updated:** [March 2, 2023, 9:13am UTC](https://discuss.elastic.co/t/app-search-error-create-engine/326827 "2023-03-02T09:13:24Z")

</div>

The documentation describes the process of creating a new Engine through the API but with the default type. How to create a Engine with elasticsearch type? I look at debugging requests that come from Kibana, repeat the…

---

## [What are the strengths of 'Rally' compared to 'JMeter' or 'nGrinder'?](https://discuss.elastic.co/t/what-are-the-strengths-of-rally-compared-to-jmeter-or-ngrinder/326266)

<div class="topic-metadata">

**Author:** [@dan\_kim](https://discuss.elastic.co/u/dan_kim)\
**Replies:** 2\
**Last updated:** [March 2, 2023, 9:07am UTC](https://discuss.elastic.co/t/what-are-the-strengths-of-rally-compared-to-jmeter-or-ngrinder/326266 "2023-03-02T09:07:12Z")

</div>

What are the strengths of 'Rally' compared to 'JMeter' or 'nGrinder'? I have used 'Rally' before, but have not used 'Apache JMeter' or 'nGrinder'. Are there any relative advantages and disadvantages HAVE A GOOD DAY …

---

## [Cannot collect logs from kubernetes with containerd runtimes](https://discuss.elastic.co/t/cannot-collect-logs-from-kubernetes-with-containerd-runtimes/326678)

<div class="topic-metadata">

**Author:** [@venturieffect](https://discuss.elastic.co/u/venturieffect)\
**Replies:** 2\
**Last updated:** [March 2, 2023, 8:46am UTC](https://discuss.elastic.co/t/cannot-collect-logs-from-kubernetes-with-containerd-runtimes/326678 "2023-03-02T08:46:17Z")

</div>

Hi everyone We deployed elastic agents with kubernetes integrations on newly installed kubernetes clusters 1.24. We noticed some missing logs and investigated the agents logs and status: we have this kind of error for e…

---

## [Is it Possible to call a field using uptime tls alerting?](https://discuss.elastic.co/t/is-it-possible-to-call-a-field-using-uptime-tls-alerting/326829)

<div class="topic-metadata">

**Author:** [@yuswanul](https://discuss.elastic.co/u/yuswanul)\
**Replies:** 0\
**Last updated:** [March 2, 2023, 8:30am UTC](https://discuss.elastic.co/t/is-it-possible-to-call-a-field-using-uptime-tls-alerting/326829 "2023-03-02T08:30:35Z")

</div>

Hi there, i have made an alert rule like this using elasticsearch query: i set the action to write the alert to kibana.log Here is the message and query: { "query":{ "bool": { "filter": \[ { …

---

## [Blank spaces in Elastic monitoring indicating possible problems?](https://discuss.elastic.co/t/blank-spaces-in-elastic-monitoring-indicating-possible-problems/326828)

<div class="topic-metadata">

**Author:** [@Lay0ut](https://discuss.elastic.co/u/Lay0ut)\
**Replies:** 0\
**Last updated:** [March 2, 2023, 8:13am UTC](https://discuss.elastic.co/t/blank-spaces-in-elastic-monitoring-indicating-possible-problems/326828 "2023-03-02T08:13:40Z")

</div>

Hello everyone, starting this week i noticed that there are occasional gaps in the monitoring graph of my elastic cluster. I wonder if these could indicate a possible problem with the cluster and what could cause these: …

---

## [Ranking in Lens Formula Features Visualization](https://discuss.elastic.co/t/ranking-in-lens-formula-features-visualization/326718)

<div class="topic-metadata">

**Author:** [@aisyaharifin](https://discuss.elastic.co/u/aisyaharifin)\
**Replies:** 7\
**Last updated:** [March 2, 2023, 7:58am UTC](https://discuss.elastic.co/t/ranking-in-lens-formula-features-visualization/326718 "2023-03-02T07:58:12Z")

</div>

Hi, I have problem in ranking my visualization dashboard. I would like to visualize Top 10 Uptime Monitor Availability. I already tried using the TVSB visualization type which is Top N to visualize Top 10 Uptime Monit…

---

## [Use geoip in Painless Script](https://discuss.elastic.co/t/use-geoip-in-painless-script/326550)

<div class="topic-metadata">

**Author:** [@sigizmynd](https://discuss.elastic.co/u/sigizmynd)\
**Replies:** 2\
**Last updated:** [March 2, 2023, 7:49am UTC](https://discuss.elastic.co/t/use-geoip-in-painless-script/326550 "2023-03-02T07:49:00Z")

</div>

hello I want to add geiop to Painless script For example def t4 = "IP\_ADDRESS"; def cntr = t4.geoip;

---

## [Use vector search for semantic search in Enterprise Search / App Search](https://discuss.elastic.co/t/use-vector-search-for-semantic-search-in-enterprise-search-app-search/326778)

<div class="topic-metadata">

**Author:** [@sebastianboelling](https://discuss.elastic.co/u/sebastianboelling)\
**Replies:** 2\
**Last updated:** [March 2, 2023, 7:30am UTC](https://discuss.elastic.co/t/use-vector-search-for-semantic-search-in-enterprise-search-app-search/326778 "2023-03-02T07:30:07Z")

</div>

Hi, I am trying to implement a vector search with App Search. I read this useful documentation how to ingest vectors and ML/NLP generated content with ML inference pipeline. Document enrichment with ML | Elastic Enterp…

---

## [Can't find my index](https://discuss.elastic.co/t/cant-find-my-index/324494)

<div class="topic-metadata">

**Author:** [@Martin\_Sander](https://discuss.elastic.co/u/Martin_Sander)\
**Replies:** 11\
**Last updated:** [March 2, 2023, 7:17am UTC](https://discuss.elastic.co/t/cant-find-my-index/324494 "2023-03-02T07:17:46Z")

</div>

I have a problem finding my created intex in Kibana/Search App engine. I have an API with a bunch of articles and already created an index with a python script. When I browse 127.0.0.1:9200/articles I do get a response …

---

## [Some questions on system.diskio latency metrics](https://discuss.elastic.co/t/some-questions-on-system-diskio-latency-metrics/326817)

<div class="topic-metadata">

**Author:** [@CatLoveFishma](https://discuss.elastic.co/u/CatLoveFishma)\
**Replies:** 3\
**Last updated:** [March 2, 2023, 7:00am UTC](https://discuss.elastic.co/t/some-questions-on-system-diskio-latency-metrics/326817 "2023-03-02T07:00:31Z")

</div>

Hello, I am trying to get a better understanding of the disk io metrics below. Included are the definitions for each per the Elastic documentation online. system.diskio.read.time - total number of milliseconds spent by…

---

## [APM server tuning for heavy workload](https://discuss.elastic.co/t/apm-server-tuning-for-heavy-workload/324455)

<div class="topic-metadata">

**Author:** [@senyam08](https://discuss.elastic.co/u/senyam08)\
**Replies:** 11\
**Last updated:** [March 2, 2023, 5:07am UTC](https://discuss.elastic.co/t/apm-server-tuning-for-heavy-workload/324455 "2023-03-02T05:07:14Z")

</div>

After deploying elastic cluster for tracing, we see following errors due to heavy workload in APM server/Agents co.elastic.apm.agent.report.ApmServerReporter - dropped events because of full queue: 305 \[elastic-apm-ser…

---

## [Error when searching in a specific field](https://discuss.elastic.co/t/error-when-searching-in-a-specific-field/326734)

<div class="topic-metadata">

**Author:** [@Thoriqul\_Umar](https://discuss.elastic.co/u/Thoriqul_Umar)\
**Replies:** 4\
**Last updated:** [March 2, 2023, 4:14am UTC](https://discuss.elastic.co/t/error-when-searching-in-a-specific-field/326734 "2023-03-02T04:14:51Z")

</div>

hello, I got error "failed to connect to console's backed. please check the kibana server is up and running" when tried to search on field "file\_content". here is my query { "query": { "multi\_match": { "qu…

---

## [Ccs query without log content in Table tab page](https://discuss.elastic.co/t/ccs-query-without-log-content-in-table-tab-page/326816)

<div class="topic-metadata">

**Author:** [@zhangzhuzi](https://discuss.elastic.co/u/zhangzhuzi)\
**Replies:** 0\
**Last updated:** [March 2, 2023, 2:27am UTC](https://discuss.elastic.co/t/ccs-query-without-log-content-in-table-tab-page/326816 "2023-03-02T02:27:53Z")

</div>

Kibana Discover CCS query results do not display log content on the table tab page. Switching to the JSON tab page display the log content, but I can directly query the log content through the command line. What is the r…

---

## [Elasticsearch Indexing Issues](https://discuss.elastic.co/t/elasticsearch-indexing-issues/326768)

<div class="topic-metadata">

**Author:** [@H-Soni](https://discuss.elastic.co/u/H-Soni)\
**Replies:** 1\
**Last updated:** [March 1, 2023, 11:54pm UTC](https://discuss.elastic.co/t/elasticsearch-indexing-issues/326768 "2023-03-01T23:54:56Z")

</div>

Hi, We have a 5-node cluster, currently running ES 5.6.11. When there's an increased load in indexing, heap usage reaches 90% in one of the nodes, while some have only 40-50% heap usage. Because of this, elasticsearch t…

---

## [Structured JSON logs via ElasticAgent Kubernetes Integration](https://discuss.elastic.co/t/structured-json-logs-via-elasticagent-kubernetes-integration/326809)

<div class="topic-metadata">

**Author:** [@metalp](https://discuss.elastic.co/u/metalp)\
**Replies:** 0\
**Last updated:** [March 1, 2023, 11:23pm UTC](https://discuss.elastic.co/t/structured-json-logs-via-elasticagent-kubernetes-integration/326809 "2023-03-01T23:23:59Z")

</div>

We're adopting Elastic stack to log our Kubernetes applications. We have installed ElasticAgent into our cluster via the Fleet managed manifest: https://raw.githubusercontent.com/elastic/elastic-agent/master/deploy/kub…

---

## [Need Help - with \_update\_by\_query query several indexes for two fields (one is optional)](https://discuss.elastic.co/t/need-help-with-update-by-query-query-several-indexes-for-two-fields-one-is-optional/326786)

<div class="topic-metadata">

**Author:** [@brunofl](https://discuss.elastic.co/u/brunofl)\
**Replies:** 0\
**Last updated:** [March 1, 2023, 4:37pm UTC](https://discuss.elastic.co/t/need-help-with-update-by-query-query-several-indexes-for-two-fields-one-is-optional/326786 "2023-03-01T16:37:49Z")

</div>

Need help- with \_update\_by\_query to query several indexes for two fields (one is optional, for the indexes where the field exists). I was doing two separate update by query, one when the index' document has a field com…

---

## [Get only the last record of an index in Kibana](https://discuss.elastic.co/t/get-only-the-last-record-of-an-index-in-kibana/326792)

<div class="topic-metadata">

**Author:** [@ismi2002](https://discuss.elastic.co/u/ismi2002)\
**Replies:** 2\
**Last updated:** [March 1, 2023, 10:06pm UTC](https://discuss.elastic.co/t/get-only-the-last-record-of-an-index-in-kibana/326792 "2023-03-01T22:06:28Z")

</div>

Hello everyone, I'm trying to do a visualization of "live events", therefore, I want to see only the last record inserted in an index in Kibana, can you help me with this? Thanks!

---

## [Problema al agregar certificado de empresa en kibana](https://discuss.elastic.co/t/problema-al-agregar-certificado-de-empresa-en-kibana/326807)

<div class="topic-metadata">

**Author:** [@DARWIN\_PEREZ](https://discuss.elastic.co/u/DARWIN_PEREZ)\
**Replies:** 0\
**Last updated:** [March 1, 2023, 9:46pm UTC](https://discuss.elastic.co/t/problema-al-agregar-certificado-de-empresa-en-kibana/326807 "2023-03-01T21:46:59Z")

</div>

Hola, me pueden apoyar, al momento de cambiar el certificado de confianza que entrega elastic, por una generado en una PKI , el servicio de kibana no arranca y sale el mensaje "El servidor Kibana aún no está listo."

---

## [Problema al agregar certificado de empresa en Elasticsearch Centos 7](https://discuss.elastic.co/t/problema-al-agregar-certificado-de-empresa-en-elasticsearch-centos-7/326806)

<div class="topic-metadata">

**Author:** [@DARWIN\_PEREZ](https://discuss.elastic.co/u/DARWIN_PEREZ)\
**Replies:** 1\
**Last updated:** [March 1, 2023, 9:40pm UTC](https://discuss.elastic.co/t/problema-al-agregar-certificado-de-empresa-en-elasticsearch-centos-7/326806 "2023-03-01T21:40:24Z")

</div>

kibana server is not ready yet

---

## [How to Add custom integration into elastic-agent integration package registry](https://discuss.elastic.co/t/how-to-add-custom-integration-into-elastic-agent-integration-package-registry/326740)

<div class="topic-metadata">

**Author:** [@aurangzeb99](https://discuss.elastic.co/u/aurangzeb99)\
**Replies:** 1\
**Last updated:** [March 1, 2023, 9:29pm UTC](https://discuss.elastic.co/t/how-to-add-custom-integration-into-elastic-agent-integration-package-registry/326740 "2023-03-01T21:29:05Z")

</div>

I am Following this guide Build an integration build is successfully done using the command elastic-package build getting error Custom build packages directory found: /opt/elastic-package/build/packages Packages fro…

---

## [Logstash isn't sending data to elastic](https://discuss.elastic.co/t/logstash-isnt-sending-data-to-elastic/326686)

<div class="topic-metadata">

**Author:** [@Uzzi](https://discuss.elastic.co/u/Uzzi)\
**Replies:** 8\
**Last updated:** [March 1, 2023, 6:34pm UTC](https://discuss.elastic.co/t/logstash-isnt-sending-data-to-elastic/326686 "2023-03-01T18:34:18Z")

</div>

Hi, I've 1 vmq for Kibana+elasticsearch and 1 vm for Logstash. Logstash isn't sending data to elastic, this is log: \[DEBUG\]\[logstash.instrument.periodicpoller.cgroup\] One or more required cgroup files or directories no…

---

## [How to delete documents by a certain field?](https://discuss.elastic.co/t/how-to-delete-documents-by-a-certain-field/326787)

<div class="topic-metadata">

**Author:** [@tom5](https://discuss.elastic.co/u/tom5)\
**Replies:** 2\
**Last updated:** [March 1, 2023, 5:57pm UTC](https://discuss.elastic.co/t/how-to-delete-documents-by-a-certain-field/326787 "2023-03-01T17:57:31Z")

</div>

Hello, I have an App Search engine and I need to delete documents in it by a certain field value. I receive JSON files that look something like this: { "entries": \[ { "id": "park\_rocky-mountain", "cat…

[Previous page](https://discuss.elastic.co/latest.md?page=761)

[Next page](https://discuss.elastic.co/latest.md?page=763)
