# Latest

**URL:** https://discuss.elastic.co/latest.md?page=763

[Latest](https://discuss.elastic.co/latest.md) · [Categories](https://discuss.elastic.co/categories.md) · [Tags](https://discuss.elastic.co/tags.md)

**Page:** 764

---

## [Problem generating Grok from AWS Postgres logs](https://discuss.elastic.co/t/problem-generating-grok-from-aws-postgres-logs/326100)

<div class="topic-metadata">

**Author:** [@ingri.mahecha](https://discuss.elastic.co/u/ingri.mahecha)\
**Replies:** 1\
**Last updated:** [March 1, 2023, 5:13pm UTC](https://discuss.elastic.co/t/problem-generating-grok-from-aws-postgres-logs/326100 "2023-03-01T17:13:11Z")

</div>

Hi, I'm having trouble generating the GROK of AWS logs from the same elasticsearch configuration, as well as from the filebeat.yml file. # ============================== Filebeat inputs =============================== f…

---

## [New Dark theme!](https://discuss.elastic.co/t/new-dark-theme/326634)

<div class="topic-metadata">

**Author:** [@warkolm](https://discuss.elastic.co/u/warkolm)\
**Replies:** 1\
**Last updated:** [March 1, 2023, 5:00pm UTC](https://discuss.elastic.co/t/new-dark-theme/326634 "2023-03-01T17:00:54Z")

</div>

We've enabled a new dark theme here thanks to the super awesome team at Discourse! Currently it is set to automatic, meaning the theme will change with your system settings, and you can change this; Click your profile…

---

## [Ha Proxy integration issues](https://discuss.elastic.co/t/ha-proxy-integration-issues/326785)

<div class="topic-metadata">

**Author:** [@Mistral](https://discuss.elastic.co/u/Mistral)\
**Replies:** 0\
**Last updated:** [March 1, 2023, 4:37pm UTC](https://discuss.elastic.co/t/ha-proxy-integration-issues/326785 "2023-03-01T16:37:15Z")

</div>

Hey, I'm trying to make the HA Proxy integration working on my ELK stack. I'm able to gather the system metrics as expected, so I tried to add the HA Proxy integration on my hosts with HA proxy servers running. So what…

---

## [I cannot update template](https://discuss.elastic.co/t/i-cannot-update-template/326775)

<div class="topic-metadata">

**Author:** [@rachelyang](https://discuss.elastic.co/u/rachelyang)\
**Replies:** 1\
**Last updated:** [March 1, 2023, 4:33pm UTC](https://discuss.elastic.co/t/i-cannot-update-template/326775 "2023-03-01T16:33:40Z")

</div>

I updated the template of filebeat in the elasticsearch node. It returned me an error: { "error": { "root\_cause": \[ { "type": "mapper\_parsing\_exception", "reason": "Root mapping definition has unsupported …

---

## [Groke parse failure on Haproxy logs while debugger is OK](https://discuss.elastic.co/t/groke-parse-failure-on-haproxy-logs-while-debugger-is-ok/326779)

<div class="topic-metadata">

**Author:** [@Bastien\_Bsc](https://discuss.elastic.co/u/Bastien_Bsc)\
**Replies:** 1\
**Last updated:** [March 1, 2023, 4:29pm UTC](https://discuss.elastic.co/t/groke-parse-failure-on-haproxy-logs-while-debugger-is-ok/326779 "2023-03-01T16:29:42Z")

</div>

Hello, I have a weird situation where the data is correctly parsed, grok debugger doesn't return errors. But logstash still adds a grokeparse\_failure tag. Here is an exemple log (in /var/log/haproxy.log) : Mar 1 15:4…

---

## [Rollover Errors](https://discuss.elastic.co/t/rollover-errors/325272)

<div class="topic-metadata">

**Author:** [@MKirby](https://discuss.elastic.co/u/MKirby)\
**Replies:** 2\
**Last updated:** [March 1, 2023, 4:23pm UTC](https://discuss.elastic.co/t/rollover-errors/325272 "2023-03-01T16:23:34Z")

</div>

Hello I have been working on some code to be able to rollover my syslogs so that it will continue to populate the Kibana. I am getting the following error in the Dev Tools Illegal argument exception rollover target is…

---

## [Installation and download of free version of Elastic Enterprise Search on Windows](https://discuss.elastic.co/t/installation-and-download-of-free-version-of-elastic-enterprise-search-on-windows/326755)

<div class="topic-metadata">

**Author:** [@mansi\_raval](https://discuss.elastic.co/u/mansi_raval)\
**Replies:** 2\
**Last updated:** [March 1, 2023, 4:03pm UTC](https://discuss.elastic.co/t/installation-and-download-of-free-version-of-elastic-enterprise-search-on-windows/326755 "2023-03-01T16:03:42Z")

</div>

I started the free trial of 14 days of the Elastic Enterprise Search and uploaded tons of files and documents and explored its functionality. However, I need to develop a permanent system (search engine) to search throug…

---

## [Search-UI RoadMap?](https://discuss.elastic.co/t/search-ui-roadmap/326769)

<div class="topic-metadata">

**Author:** [@AndrewSharp](https://discuss.elastic.co/u/AndrewSharp)\
**Replies:** 2\
**Last updated:** [March 1, 2023, 3:35pm UTC](https://discuss.elastic.co/t/search-ui-roadmap/326769 "2023-03-01T15:35:29Z")

</div>

Hi, I'm trying to integrate the search-UI into our webpage, but there are 2 bugs holding us back and I was wondering if there was an ETA on them or a RoadMap somewhere. The two issues are: and to a lesser degree: Nes…

---

## [Jupyter spark connect to elasticsearch](https://discuss.elastic.co/t/jupyter-spark-connect-to-elasticsearch/326585)

<div class="topic-metadata">

**Author:** [@INS](https://discuss.elastic.co/u/INS)\
**Replies:** 11\
**Last updated:** [March 1, 2023, 3:14pm UTC](https://discuss.elastic.co/t/jupyter-spark-connect-to-elasticsearch/326585 "2023-03-01T15:14:21Z")

</div>

I'm trying to connect from spark to elasticsearch , so as first I've build docker images from spark3.2.1 for kubernetes then from jupyter notebook I've opened a session to spark a build the context to elasticsearch on t…

---

## [Filestream processing of CSV files](https://discuss.elastic.co/t/filestream-processing-of-csv-files/326704)

<div class="topic-metadata">

**Author:** [@rsaeks](https://discuss.elastic.co/u/rsaeks)\
**Replies:** 2\
**Last updated:** [March 1, 2023, 2:22pm UTC](https://discuss.elastic.co/t/filestream-processing-of-csv-files/326704 "2023-03-01T14:22:23Z")

</div>

Hi all, I'm slowly migrating over to filestream to process some log files and have data coming in and stored into the message field. Here is an example: ec26.515d.ebcf,someUser,GSS-A-1FL-122,SD35 What I would like to …

---

## [Elastic Crawler Debugging](https://discuss.elastic.co/t/elastic-crawler-debugging/326628)

<div class="topic-metadata">

**Author:** [@alongaks](https://discuss.elastic.co/u/alongaks)\
**Replies:** 7\
**Last updated:** [March 1, 2023, 1:01pm UTC](https://discuss.elastic.co/t/elastic-crawler-debugging/326628 "2023-03-01T13:01:58Z")

</div>

Hello, I am looking for info if it is possible for the Elastic Crawler ( cloud deployment ) to enable a debug log, just for a crawl job. I am hitting 599 timeout errors during a crawl, and once this occurs the crawl is…

---

## [Kibana generating false Recovery Monitor UP documents for offline monitors](https://discuss.elastic.co/t/kibana-generating-false-recovery-monitor-up-documents-for-offline-monitors/326566)

<div class="topic-metadata">

**Author:** [@Adriann](https://discuss.elastic.co/u/Adriann)\
**Replies:** 4\
**Last updated:** [March 1, 2023, 11:08am UTC](https://discuss.elastic.co/t/kibana-generating-false-recovery-monitor-up-documents-for-offline-monitors/326566 "2023-03-01T11:08:30Z")

</div>

Hi everyone, I'm experiencing an issue with Kibana generating false Recovery Monitor UP documents for monitors that have been offline for a long time. Specifically, when a host is monitored using heartbeat and is offlin…

---

## [Logstash how to mutate string of float array to denseVector](https://discuss.elastic.co/t/logstash-how-to-mutate-string-of-float-array-to-densevector/326750)

<div class="topic-metadata">

**Author:** [@wensi](https://discuss.elastic.co/u/wensi)\
**Replies:** 1\
**Last updated:** [March 1, 2023, 11:03am UTC](https://discuss.elastic.co/t/logstash-how-to-mutate-string-of-float-array-to-densevector/326750 "2023-03-01T11:03:50Z")

</div>

I am using Logstash to transfer data from MySQL to ES, one column in MySQL is \`vec\` text NOT NULL vec has value like \[0.1, 0.2, 0.3\] and is of string type. How to convert string of float array to ES dense\_vector? I tr…

---

## [Subtraction between current date and doc created date](https://discuss.elastic.co/t/subtraction-between-current-date-and-doc-created-date/326405)

<div class="topic-metadata">

**Author:** [@PappuSingh](https://discuss.elastic.co/u/PappuSingh)\
**Replies:** 4\
**Last updated:** [March 1, 2023, 10:54am UTC](https://discuss.elastic.co/t/subtraction-between-current-date-and-doc-created-date/326405 "2023-03-01T10:54:44Z")

</div>

Hi, Please see the below code sample. long l1=(new Date().getTime()); //emit(l1); long l= ChronoUnit.SECONDS.between(l1, doc\['timestamp'\].value); if(l\<=100000){ emit('New') } else{emit('Old')} I am getting the b…

---

## [Kibana Dashboard loading Issue](https://discuss.elastic.co/t/kibana-dashboard-loading-issue/326702)

<div class="topic-metadata">

**Author:** [@rohitguptaggg](https://discuss.elastic.co/u/rohitguptaggg)\
**Replies:** 1\
**Last updated:** [March 1, 2023, 10:41am UTC](https://discuss.elastic.co/t/kibana-dashboard-loading-issue/326702 "2023-03-01T10:41:31Z")

</div>

Hello, I have created a Kibana dashboard using a filter and query, but it is causing loading issues and the Elasticsearch CPU is going up to 99%, even though there are 3 Elasticsearch nodes. Can someone please help and …

---

## [Autodetect\_column\_names in condition](https://discuss.elastic.co/t/autodetect-column-names-in-condition/326439)

<div class="topic-metadata">

**Author:** [@INS](https://discuss.elastic.co/u/INS)\
**Replies:** 6\
**Last updated:** [March 1, 2023, 10:36am UTC](https://discuss.elastic.co/t/autodetect-column-names-in-condition/326439 "2023-03-01T10:36:45Z")

</div>

Hi Maybe You have idea why in this case autodetect\_column\_names doesn't work as independent. input: "CLLI","SWREL","RPTDATE","RPTIME","TZ","RPTTYPE","RPTPD","IVALDATE","IVALSTART","IVALEND","NUMENTIDS" "wifi06","EAGL…

---

## [Failure to parce query](https://discuss.elastic.co/t/failure-to-parce-query/326699)

<div class="topic-metadata">

**Author:** [@mikes1962](https://discuss.elastic.co/u/mikes1962)\
**Replies:** 1\
**Last updated:** [March 1, 2023, 10:27am UTC](https://discuss.elastic.co/t/failure-to-parce-query/326699 "2023-03-01T10:27:32Z")

</div>

I'm very new to elasticsearch so please forgive me if this is a stupid question. I'm writing python code to read data from the stack but from time to time I get a message like this: Exception: Invalid Query: \[erm/d-2Cll…

---

## [How to remove restriction from the value of a field in a document such that the field doesn't get marked as \_ignored due to it's long length](https://discuss.elastic.co/t/how-to-remove-restriction-from-the-value-of-a-field-in-a-document-such-that-the-field-doesnt-get-marked-as-ignored-due-to-its-long-length/326727)

<div class="topic-metadata">

**Author:** [@Deepanshu\_Yadav1](https://discuss.elastic.co/u/Deepanshu_Yadav1)\
**Replies:** 2\
**Last updated:** [March 1, 2023, 10:16am UTC](https://discuss.elastic.co/t/how-to-remove-restriction-from-the-value-of-a-field-in-a-document-such-that-the-field-doesnt-get-marked-as-ignored-due-to-its-long-length/326727 "2023-03-01T10:16:32Z")

</div>

PROLOGUE: We are using Elastic Fleet and Elastic Agents. Using filebeat and ingest pipeline we are fetching logs from a custom log file kept on an elastic agent. These logs are then indexed in Elastic Search and can b…

---

## [Output stdout does not print to shell when given info log level](https://discuss.elastic.co/t/output-stdout-does-not-print-to-shell-when-given-info-log-level/326392)

<div class="topic-metadata">

**Author:** [@wensi](https://discuss.elastic.co/u/wensi)\
**Replies:** 1\
**Last updated:** [March 1, 2023, 9:47am UTC](https://discuss.elastic.co/t/output-stdout-does-not-print-to-shell-when-given-info-log-level/326392 "2023-03-01T09:47:19Z")

</div>

The following script reads from mysql through jdbc plugin, and output every item through stdout. However, by running logstash -f mysql2es.conf， it does not print anything. Then I added --debug, I can see entities jdbc re…

---

## [Filebeat problem](https://discuss.elastic.co/t/filebeat-problem/325831)

<div class="topic-metadata">

**Author:** [@Elie\_Sbat](https://discuss.elastic.co/u/Elie_Sbat)\
**Replies:** 1\
**Last updated:** [March 1, 2023, 9:38am UTC](https://discuss.elastic.co/t/filebeat-problem/325831 "2023-03-01T09:38:36Z")

</div>

Hello, I am using filebeat v8 that sends data to kafka. On startup, filebeat sends a chunk of data and then NO data is being transferred. I checked filebeat logs no errors are present. Filebeat registry is accessible an…

---

## [How to install custom package of elastic-agent in my kibana](https://discuss.elastic.co/t/how-to-install-custom-package-of-elastic-agent-in-my-kibana/326741)

<div class="topic-metadata">

**Author:** [@aurangzeb99](https://discuss.elastic.co/u/aurangzeb99)\
**Replies:** 3\
**Last updated:** [March 1, 2023, 9:16am UTC](https://discuss.elastic.co/t/how-to-install-custom-package-of-elastic-agent-in-my-kibana/326741 "2023-03-01T09:16:21Z")

</div>

I Followed this link and created custom package for elastic-agent (integration) Build an integration after creating build .zip of the package how i can install this package (integration) into my elasticsearch-kibana ?? …

---

## [Gradual migration from container input to kubernetes autodiscover](https://discuss.elastic.co/t/gradual-migration-from-container-input-to-kubernetes-autodiscover/325979)

<div class="topic-metadata">

**Author:** [@OranShuster](https://discuss.elastic.co/u/OranShuster)\
**Replies:** 3\
**Last updated:** [March 1, 2023, 9:14am UTC](https://discuss.elastic.co/t/gradual-migration-from-container-input-to-kubernetes-autodiscover/325979 "2023-03-01T09:14:11Z")

</div>

We are currently using a filebeat daemon set with the "old" container input, both version 7.17.x we want to start migrating to the newer approach of hint based log collection for this we need the old filebeat daemon se…

---

## [Can I make scripts I run in Kibana tools into Kibana objects](https://discuss.elastic.co/t/can-i-make-scripts-i-run-in-kibana-tools-into-kibana-objects/326471)

<div class="topic-metadata">

**Author:** [@gyannea](https://discuss.elastic.co/u/gyannea)\
**Replies:** 2\
**Last updated:** [March 1, 2023, 9:04am UTC](https://discuss.elastic.co/t/can-i-make-scripts-i-run-in-kibana-tools-into-kibana-objects/326471 "2023-03-01T09:04:21Z")

</div>

I can write REST, painless, etc. scripts using the Kibana tools (dev Tools) console. At least I can write REST searches. Is it possible to take these searches and make them into a Kibana object? Right now it only seems p…

---

## [Interface name](https://discuss.elastic.co/t/interface-name/326736)

<div class="topic-metadata">

**Author:** [@teplyukdimka](https://discuss.elastic.co/u/teplyukdimka)\
**Replies:** 0\
**Last updated:** [March 1, 2023, 8:20am UTC](https://discuss.elastic.co/t/interface-name/326736 "2023-03-01T08:20:49Z")

</div>

Good day. Tell me, please, I collect netflow using filebeat. There are fields '''' "egress\_interface" : 199, "ingress\_interface" : 277, '''' Through SNMP, I found out which network interfaces correspond to these i…

---

## [Synthetics Playwright version](https://discuss.elastic.co/t/synthetics-playwright-version/324987)

<div class="topic-metadata">

**Author:** [@jasonwhetton](https://discuss.elastic.co/u/jasonwhetton)\
**Replies:** 12\
**Last updated:** [March 1, 2023, 6:54am UTC](https://discuss.elastic.co/t/synthetics-playwright-version/324987 "2023-03-01T06:54:09Z")

</div>

Hi, I'm trying to migrate some playwright tests to elastic synthetics and getting issues running the newer playwright methods e.g. getByRole. These are recognised when I run locally but not when I push to the server. Wha…

---

## [ELASTICSEARCH\_17 - Could not index '1' records: listener timeout after waiting for \[30000\] ms](https://discuss.elastic.co/t/elasticsearch-17-could-not-index-1-records-listener-timeout-after-waiting-for-30000-ms/326688)

<div class="topic-metadata">

**Author:** [@senix](https://discuss.elastic.co/u/senix)\
**Replies:** 5\
**Last updated:** [March 1, 2023, 6:32am UTC](https://discuss.elastic.co/t/elasticsearch-17-could-not-index-1-records-listener-timeout-after-waiting-for-30000-ms/326688 "2023-03-01T06:32:05Z")

</div>

We're using streamsets to send messages to Elasticsearch and are consistently getting the following error: ELASTICSEARCH\_17 - Could not index '1' records: listener timeout after waiting for \[30000\] ms We've tried vario…

---

## [Run Logstash manually without interrupting logstash service and logstash Scheduler](https://discuss.elastic.co/t/run-logstash-manually-without-interrupting-logstash-service-and-logstash-scheduler/326036)

<div class="topic-metadata">

**Author:** [@Rakhshunda\_Noorein\_J](https://discuss.elastic.co/u/Rakhshunda_Noorein_J)\
**Replies:** 8\
**Last updated:** [March 1, 2023, 6:25am UTC](https://discuss.elastic.co/t/run-logstash-manually-without-interrupting-logstash-service-and-logstash-scheduler/326036 "2023-03-01T06:25:43Z")

</div>

Hello, I have a configuration file with http\_poller plugins, where I have some scheduler which on the given schedule pull the data and enter it into my elastic db. But to manually run lagstash instantly, What I have to…

---

## [How to get Metric from Transaction Page - APM](https://discuss.elastic.co/t/how-to-get-metric-from-transaction-page-apm/326651)

<div class="topic-metadata">

**Author:** [@zerratriani](https://discuss.elastic.co/u/zerratriani)\
**Replies:** 2\
**Last updated:** [March 1, 2023, 4:02am UTC](https://discuss.elastic.co/t/how-to-get-metric-from-transaction-page-apm/326651 "2023-03-01T04:02:19Z")

</div>

I want to create a dashboard from the metrics on the transaction page. How and what metrics are used? I use elasticsearch and kibana 8.5.3 and using java appilication

---

## [Elastic agent: "output not supported" using Logstash output on 8.6](https://discuss.elastic.co/t/elastic-agent-output-not-supported-using-logstash-output-on-8-6/326010)

<div class="topic-metadata">

**Author:** [@ceekay](https://discuss.elastic.co/u/ceekay)\
**Replies:** 1\
**Last updated:** [February 28, 2023, 10:36pm UTC](https://discuss.elastic.co/t/elastic-agent-output-not-supported-using-logstash-output-on-8-6/326010 "2023-02-28T22:36:31Z")

</div>

Hi all, I have a previously working\* Fleet/Agent config with 8.5.3 and Logstash output configured. \* aside from 8.5.1 agents go unhealthy · Issue #1790 · elastic/elastic-agent · GitHub but I have a workaround for this…

---

## [Filebeat gives an error when it outputs to elasticsearch](https://discuss.elastic.co/t/filebeat-gives-an-error-when-it-outputs-to-elasticsearch/326667)

<div class="topic-metadata">

**Author:** [@limedong1](https://discuss.elastic.co/u/limedong1)\
**Replies:** 0\
**Last updated:** [February 28, 2023, 8:51am UTC](https://discuss.elastic.co/t/filebeat-gives-an-error-when-it-outputs-to-elasticsearch/326667 "2023-02-28T08:51:01Z")

</div>

My elastic cluster version is 8.6.0 and filebeat version is 8.6.0 The log has been successfully read, but there will be some errors in the log output. Failed to connect to backoff (elasticsearch (http://192.168.3.74:30…

[Previous page](https://discuss.elastic.co/latest.md?page=762)

[Next page](https://discuss.elastic.co/latest.md?page=764)
