# Latest

**URL:** https://discuss.elastic.co/latest.md?page=770

[Latest](https://discuss.elastic.co/latest.md) · [Categories](https://discuss.elastic.co/categories.md) · [Tags](https://discuss.elastic.co/tags.md)

**Page:** 771

---

## [Swiftype filters does not work](https://discuss.elastic.co/t/swiftype-filters-does-not-work/325682)

<div class="topic-metadata">

**Author:** [@willchenxa](https://discuss.elastic.co/u/willchenxa)\
**Replies:** 2\
**Last updated:** [February 23, 2023, 9:45pm UTC](https://discuss.elastic.co/t/swiftype-filters-does-not-work/325682 "2023-02-23T21:45:56Z")

</div>

The "filters" in swiftype search doesn't take effect at all. I use the following two different url to run the search, nothing works. {hostaddress}/api/v1/engines/{engineName}/doecument\_types/page/search.json {hostaddre…

---

## [Feature Request: minimum\_should\_match support for Terms Set query](https://discuss.elastic.co/t/feature-request-minimum-should-match-support-for-terms-set-query/326374)

<div class="topic-metadata">

**Author:** [@kulinsj](https://discuss.elastic.co/u/kulinsj)\
**Replies:** 2\
**Last updated:** [February 23, 2023, 9:32pm UTC](https://discuss.elastic.co/t/feature-request-minimum-should-match-support-for-terms-set-query/326374 "2023-02-23T21:32:36Z")

</div>

The Terms Set Query lets you match documents that have some minimum number of matches to a given array of input search terms. The minimum number of matches however can only be specified by referencing another field on th…

---

## [DakMode in kibana spaces](https://discuss.elastic.co/t/dakmode-in-kibana-spaces/326343)

<div class="topic-metadata">

**Author:** [@thomas4](https://discuss.elastic.co/u/thomas4)\
**Replies:** 8\
**Last updated:** [February 23, 2023, 8:38pm UTC](https://discuss.elastic.co/t/dakmode-in-kibana-spaces/326343 "2023-02-23T20:38:14Z")

</div>

Hi all, new to Kibana and setting up new spaces, but i want them in darkMode but can't figure out how to do it, any help would be appreciated. I'm using Kibana 7.6.1

---

## [Elasticsearch 8.6 - enrich processor is not behaving as expected](https://discuss.elastic.co/t/elasticsearch-8-6-enrich-processor-is-not-behaving-as-expected/326371)

<div class="topic-metadata">

**Author:** [@BlueNoteBird](https://discuss.elastic.co/u/BlueNoteBird)\
**Replies:** 0\
**Last updated:** [February 23, 2023, 7:44pm UTC](https://discuss.elastic.co/t/elasticsearch-8-6-enrich-processor-is-not-behaving-as-expected/326371 "2023-02-23T19:44:23Z")

</div>

Hello, I am new to Elasticsearch and I am probably missing something. It seems that enrich processor is not using custom normalizer. // My custom Normalizer PUT /\_component\_template/comptpl\_norm\_letters { "template"…

---

## [How to Set Default Integer Value in Search Template](https://discuss.elastic.co/t/how-to-set-default-integer-value-in-search-template/325279)

<div class="topic-metadata">

**Author:** [@krmathieu](https://discuss.elastic.co/u/krmathieu)\
**Replies:** 1\
**Last updated:** [February 23, 2023, 6:58pm UTC](https://discuss.elastic.co/t/how-to-set-default-integer-value-in-search-template/325279 "2023-02-23T18:58:53Z")

</div>

I am getting a number\_format\_exception when trying to run a search against a search template containing this snippet of code. It defines a CityID variable and tries to set a wildcard default and the CityID field is defin…

---

## [Elasticsearch rolling restart without indexing down time](https://discuss.elastic.co/t/elasticsearch-rolling-restart-without-indexing-down-time/326358)

<div class="topic-metadata">

**Author:** [@ebuildy](https://discuss.elastic.co/u/ebuildy)\
**Replies:** 2\
**Last updated:** [February 23, 2023, 6:50pm UTC](https://discuss.elastic.co/t/elasticsearch-rolling-restart-without-indexing-down-time/326358 "2023-02-23T18:50:06Z")

</div>

We run an elasticsearch cluster 7.17, with 3 data nodes and 3 master nodes. The use case is for monitoring with elasticAPM. We follow official documentation at Full cluster restart upgrade | Elasticsearch Guide \[7.17\] |…

---

## [Logs reflecting late in kibana](https://discuss.elastic.co/t/logs-reflecting-late-in-kibana/326291)

<div class="topic-metadata">

**Author:** [@Haneesha](https://discuss.elastic.co/u/Haneesha)\
**Replies:** 1\
**Last updated:** [February 23, 2023, 6:39pm UTC](https://discuss.elastic.co/t/logs-reflecting-late-in-kibana/326291 "2023-02-23T18:39:42Z")

</div>

Hi Team, Logs are reflecting after 20 min after the generation for a particular service. How can I sort this out.

---

## [Kibana Search on field endTime not working](https://discuss.elastic.co/t/kibana-search-on-field-endtime-not-working/326318)

<div class="topic-metadata">

**Author:** [@garmy](https://discuss.elastic.co/u/garmy)\
**Replies:** 1\
**Last updated:** [February 23, 2023, 6:04pm UTC](https://discuss.elastic.co/t/kibana-search-on-field-endtime-not-working/326318 "2023-02-23T18:04:56Z")

</div>

Hi gang, Trying to identify documents that have a time field called "endTime" \>= future times..... since this field is a UTC Time field, some may, and do have 'Future' dates and those are what I want to see (as well as …

---

## [Reindex w/ a regex](https://discuss.elastic.co/t/reindex-w-a-regex/326348)

<div class="topic-metadata">

**Author:** [@vfeydel](https://discuss.elastic.co/u/vfeydel)\
**Replies:** 1\
**Last updated:** [February 23, 2023, 5:44pm UTC](https://discuss.elastic.co/t/reindex-w-a-regex/326348 "2023-02-23T17:44:51Z")

</div>

I have lot of indices with same prefix. In those indices, I need to keep only document that have for example the field "abc" with 7 numbers only. My indices are already index in Elastic. It is possible , with a query or…

---

## [Connecting Render web service to Elasticsearch via TLS-enabled syslog drain](https://discuss.elastic.co/t/connecting-render-web-service-to-elasticsearch-via-tls-enabled-syslog-drain/326200)

<div class="topic-metadata">

**Author:** [@pocketcolin](https://discuss.elastic.co/u/pocketcolin)\
**Replies:** 8\
**Last updated:** [February 23, 2023, 4:12pm UTC](https://discuss.elastic.co/t/connecting-render-web-service-to-elasticsearch-via-tls-enabled-syslog-drain/326200 "2023-02-23T16:12:49Z")

</div>

Hello, I'm new to configuring Elasticsearch observability but my goal right now is to get syslogs from my web service setup on Render (render.com) into my Elasticsearch instance (Render log stream docs here). Is this ev…

---

## ["APM Server transport error (ECONNREFUSED): connect ECONNREFUSED ::1:8200" when trying to configure APM agent in application code](https://discuss.elastic.co/t/apm-server-transport-error-econnrefused-connect-econnrefused-8200-when-trying-to-configure-apm-agent-in-application-code/326236)

<div class="topic-metadata">

**Author:** [@Matt\_Johnston](https://discuss.elastic.co/u/Matt_Johnston)\
**Replies:** 8\
**Last updated:** [February 23, 2023, 3:43pm UTC](https://discuss.elastic.co/t/apm-server-transport-error-econnrefused-connect-econnrefused-8200-when-trying-to-configure-apm-agent-in-application-code/326236 "2023-02-23T15:43:48Z")

</div>

I am trying to configure an APM agent in my nodejs application code. I have installed the APM agent using the following command: npm install elastic-apm-node --save I then updated my application code using the followin…

---

## [Add AWS EKS Cluster name dynamically to metrics/logs collection via fleet agent](https://discuss.elastic.co/t/add-aws-eks-cluster-name-dynamically-to-metrics-logs-collection-via-fleet-agent/326341)

<div class="topic-metadata">

**Author:** [@ekane\_bksy](https://discuss.elastic.co/u/ekane_bksy)\
**Replies:** 0\
**Last updated:** [February 23, 2023, 3:41pm UTC](https://discuss.elastic.co/t/add-aws-eks-cluster-name-dynamically-to-metrics-logs-collection-via-fleet-agent/326341 "2023-02-23T15:41:04Z")

</div>

How to configure elastic-agent dynamically with AWS EKS cluster name to metrics and logs forwarded to ElasticCloud? Documentation details configuring ElasticCloud side with processor. What method can be used on agent-si…

---

## [How to analyse nested fields?](https://discuss.elastic.co/t/how-to-analyse-nested-fields/325944)

<div class="topic-metadata">

**Author:** [@Amine16](https://discuss.elastic.co/u/Amine16)\
**Replies:** 1\
**Last updated:** [February 23, 2023, 3:28pm UTC](https://discuss.elastic.co/t/how-to-analyse-nested-fields/325944 "2023-02-23T15:28:45Z")

</div>

I am working in e-health project and we have a lot of clinical data (JSON format) stored in our data base. We want to do some research in these data, that’s why we think that Elastic Search tool can help us in this proj…

---

## [Observability Lab 2.2 - mysql incorrect creds](https://discuss.elastic.co/t/observability-lab-2-2-mysql-incorrect-creds/326111)

<div class="topic-metadata">

**Author:** [@deccman](https://discuss.elastic.co/u/deccman)\
**Replies:** 3\
**Last updated:** [February 23, 2023, 2:44pm UTC](https://discuss.elastic.co/t/observability-lab-2-2-mysql-incorrect-creds/326111 "2023-02-23T14:44:59Z")

</div>

Course: Observability Engineer Version: 7.9 Question: I am currently doing the Observability Engineer Training for version 7.9 and have hit a roadblock in the lab training. In lab 2.2 you set up Metricbeats for MySQL. …

---

## [UNABLE TO START FILEBEAT ON ELASTIC V7.9 LAB](https://discuss.elastic.co/t/unable-to-start-filebeat-on-elastic-v7-9-lab/326269)

<div class="topic-metadata">

**Author:** [@chikugerson](https://discuss.elastic.co/u/chikugerson)\
**Replies:** 3\
**Last updated:** [February 23, 2023, 2:43pm UTC](https://discuss.elastic.co/t/unable-to-start-filebeat-on-elastic-v7-9-lab/326269 "2023-02-23T14:43:14Z")

</div>

Elastic Certified Observability Engineer practice lab when i start the filebeat with the command ./filebeat i get the below logs the filebeat is not starting. \[elastic@mysql filebeat\]$ ./filebeat -e 2023-02-23T07:31:49.…

---

## [APM Logs page returns logs for the previously chosen environment](https://discuss.elastic.co/t/apm-logs-page-returns-logs-for-the-previously-chosen-environment/324830)

<div class="topic-metadata">

**Author:** [@Savva\_Morozov](https://discuss.elastic.co/u/Savva_Morozov)\
**Replies:** 1\
**Last updated:** [February 23, 2023, 2:35pm UTC](https://discuss.elastic.co/t/apm-logs-page-returns-logs-for-the-previously-chosen-environment/324830 "2023-02-23T14:35:53Z")

</div>

Hello! Last Thursday I updated Elastic Stack on Cloud up to the version 8.6.1 (from 8.4.1) and I did the same to Metricbeat and Filebeat (from 7.17.6). Everything looked fine after the update but today I discovered that …

---

## [Copy Dashboard th onther space](https://discuss.elastic.co/t/copy-dashboard-th-onther-space/326194)

<div class="topic-metadata">

**Author:** [@hiba](https://discuss.elastic.co/u/hiba)\
**Replies:** 1\
**Last updated:** [February 23, 2023, 2:26pm UTC](https://discuss.elastic.co/t/copy-dashboard-th-onther-space/326194 "2023-02-23T14:26:36Z")

</div>

Hi, I copied a dashboard to another space, but I noticed that there are visualizations whose X axis is not the same For example : i copy this dashboard (original) But i get this

---

## [How to grab the trace for bulkprocessor](https://discuss.elastic.co/t/how-to-grab-the-trace-for-bulkprocessor/326149)

<div class="topic-metadata">

**Author:** [@INS](https://discuss.elastic.co/u/INS)\
**Replies:** 1\
**Last updated:** [February 23, 2023, 2:19pm UTC](https://discuss.elastic.co/t/how-to-grab-the-trace-for-bulkprocessor/326149 "2023-02-23T14:19:41Z")

</div>

Hi I need to trace same stack for bulkprocessor for tracing the cause of the error on elastic, why does the application get a timeout ERROR e.i.u.r.i.BulkIndexingProcessorConfig - - Failed to execute bulk request. Reas…

---

## [Kibana Visualizations](https://discuss.elastic.co/t/kibana-visualizations/326251)

<div class="topic-metadata">

**Author:** [@joelle\_umutoni](https://discuss.elastic.co/u/joelle_umutoni)\
**Replies:** 6\
**Last updated:** [February 23, 2023, 2:05pm UTC](https://discuss.elastic.co/t/kibana-visualizations/326251 "2023-02-23T14:05:29Z")

</div>

What to do when you click on visualization for filtering purpose but the other visualization does not update to show the data related to the one clicked.

---

## [Want to get interface classes for the current transaction](https://discuss.elastic.co/t/want-to-get-interface-classes-for-the-current-transaction/326307)

<div class="topic-metadata">

**Author:** [@sarthik](https://discuss.elastic.co/u/sarthik)\
**Replies:** 3\
**Last updated:** [February 23, 2023, 2:01pm UTC](https://discuss.elastic.co/t/want-to-get-interface-classes-for-the-current-transaction/326307 "2023-02-23T14:01:34Z")

</div>

I need to get the name of the interface classes for every transaction in the stack trace. In the current way, I am using Thread.getAllStackTraces() , but not able to getInterfaces() as it always gives the return as jav…

---

## [Logstash is taking high cpu](https://discuss.elastic.co/t/logstash-is-taking-high-cpu/326316)

<div class="topic-metadata">

**Author:** [@divya.m](https://discuss.elastic.co/u/divya.m)\
**Replies:** 1\
**Last updated:** [February 23, 2023, 2:00pm UTC](https://discuss.elastic.co/t/logstash-is-taking-high-cpu/326316 "2023-02-23T14:00:24Z")

</div>

Without any load consistently logstash is using 46% of CPU, after performance load testing logstash cpu is high root@::~ $ docker logs XXXXX | grep -i "2023-02-23 10:57" | wc 86 1238 18546

---

## [Kibana Vega : Sum of field of latest unique values](https://discuss.elastic.co/t/kibana-vega-sum-of-field-of-latest-unique-values/326047)

<div class="topic-metadata">

**Author:** [@ankitdevnalkar](https://discuss.elastic.co/u/ankitdevnalkar)\
**Replies:** 9\
**Last updated:** [February 23, 2023, 1:57pm UTC](https://discuss.elastic.co/t/kibana-vega-sum-of-field-of-latest-unique-values/326047 "2023-02-23T13:57:07Z")

</div>

Problem statement : I have written a Kibana Vega script to show sum of latest balanceusd field having a unique orgid. I am getting balance logs frequently and every latest log has the updated balance. There can be a numb…

---

## [Vega kibana tag cloud](https://discuss.elastic.co/t/vega-kibana-tag-cloud/326265)

<div class="topic-metadata">

**Author:** [@uae\_user](https://discuss.elastic.co/u/uae_user)\
**Replies:** 1\
**Last updated:** [February 23, 2023, 1:50pm UTC](https://discuss.elastic.co/t/vega-kibana-tag-cloud/326265 "2023-02-23T13:50:24Z")

</div>

Hi, I'm trying to build a tag cloud using custom visualization, I tried to follow Vega tag cloud format and replaced the value part with url , I'm sure about the query as I tried it on the dev tool and it worked. ' I'm…

---

## [Unable to search data containing math expression](https://discuss.elastic.co/t/unable-to-search-data-containing-math-expression/326287)

<div class="topic-metadata">

**Author:** [@Hassan\_zaib\_Hayat](https://discuss.elastic.co/u/Hassan_zaib_Hayat)\
**Replies:** 1\
**Last updated:** [February 23, 2023, 1:39pm UTC](https://discuss.elastic.co/t/unable-to-search-data-containing-math-expression/326287 "2023-02-23T13:39:14Z")

</div>

Hi ES folks, Hope everyone is doing fine. I am facing a problem when querying data containing mathematical expressions. For example I have following data indexed in my ES what is 3+4 what is 3-4 what is 3\*4 what is 3/…

---

## [Elastic Cloud SAML SSO in 'trial' environment](https://discuss.elastic.co/t/elastic-cloud-saml-sso-in-trial-environment/325509)

<div class="topic-metadata">

**Author:** [@alongaks](https://discuss.elastic.co/u/alongaks)\
**Replies:** 14\
**Last updated:** [February 23, 2023, 1:07pm UTC](https://discuss.elastic.co/t/elastic-cloud-saml-sso-in-trial-environment/325509 "2023-02-23T13:07:40Z")

</div>

Hello, I'm looking for some insight with configuring SAML SSO in a trial Elastic Cloud environment. The deployment is on v8.6.1. Using Elasticsearch, Kibana, Enterprise Search. The idP provider is SAML 2.0. I have be…

---

## [Custom Logs, fleet pre processor to keep on field as json itself](https://discuss.elastic.co/t/custom-logs-fleet-pre-processor-to-keep-on-field-as-json-itself/326327)

<div class="topic-metadata">

**Author:** [@coderhs](https://discuss.elastic.co/u/coderhs)\
**Replies:** 0\
**Last updated:** [February 23, 2023, 12:59pm UTC](https://discuss.elastic.co/t/custom-logs-fleet-pre-processor-to-keep-on-field-as-json-itself/326327 "2023-02-23T12:59:47Z")

</div>

I have setup a self hosted elastic stack with kibana to track logs for a web application (ruby on rails). I am pushing the production logs to elastic using fleet. I am creating the log in JSON fromat from the application…

---

## [Trying to install integration APM gives '404 Not Found'](https://discuss.elastic.co/t/trying-to-install-integration-apm-gives-404-not-found/324748)

<div class="topic-metadata">

**Author:** [@benzok](https://discuss.elastic.co/u/benzok)\
**Replies:** 2\
**Last updated:** [February 23, 2023, 12:56pm UTC](https://discuss.elastic.co/t/trying-to-install-integration-apm-gives-404-not-found/324748 "2023-02-23T12:56:15Z")

</div>

Kibana version: 8.6.1 Elasticsearch version: 8.6.1 Original install method (e.g. download page, yum, deb, from source, etc.) and version: docker-compose Fresh install or upgraded from other version? Fresh Is there an…

---

## [Why Kibana not showing date when minimum interval is selected in minutes](https://discuss.elastic.co/t/why-kibana-not-showing-date-when-minimum-interval-is-selected-in-minutes/326319)

<div class="topic-metadata">

**Author:** [@Arshukla](https://discuss.elastic.co/u/Arshukla)\
**Replies:** 1\
**Last updated:** [February 23, 2023, 12:52pm UTC](https://discuss.elastic.co/t/why-kibana-not-showing-date-when-minimum-interval-is-selected-in-minutes/326319 "2023-02-23T12:52:45Z")

</div>

When I am selecting minimum interval as "Minutes", Kibana is not having dates in timestamp column. Whereas when i am selecting "Hour", it is working as per expectation. Screenshot -when minutes selected Screenshot -…

---

## [Database span/traces not visible on Integrated APM 7.17 ( Kibana 7.17, Elastic 7.17)](https://discuss.elastic.co/t/database-span-traces-not-visible-on-integrated-apm-7-17-kibana-7-17-elastic-7-17/326322)

<div class="topic-metadata">

**Author:** [@ASB50504](https://discuss.elastic.co/u/ASB50504)\
**Replies:** 0\
**Last updated:** [February 23, 2023, 12:22pm UTC](https://discuss.elastic.co/t/database-span-traces-not-visible-on-integrated-apm-7-17-kibana-7-17-elastic-7-17/326322 "2023-02-23T12:22:21Z")

</div>

Kibana version: 7.17 Elasticsearch version: 7.17 APM Server version: 7.17 APM Agent language and version: Not agent specific (happening for NodeJS,Python,Java) Browser version: Safari 16.2 Original install method (e…

---

## [Can we give more than 32GB Memory to dedicated Machine learning Node?](https://discuss.elastic.co/t/can-we-give-more-than-32gb-memory-to-dedicated-machine-learning-node/325159)

<div class="topic-metadata">

**Author:** [@Umang\_Pachaury](https://discuss.elastic.co/u/Umang_Pachaury)\
**Replies:** 6\
**Last updated:** [February 23, 2023, 12:05pm UTC](https://discuss.elastic.co/t/can-we-give-more-than-32gb-memory-to-dedicated-machine-learning-node/325159 "2023-02-23T12:05:39Z")

</div>

As per the documentation it is recommended by Elasticsearch Team that every Elasticsearch node should have the memory slightly less than 32GB. Now My question is that does this apply to a dedicated Machine learning Node …

[Previous page](https://discuss.elastic.co/latest.md?page=769)

[Next page](https://discuss.elastic.co/latest.md?page=771)
