# Latest

**URL:** https://discuss.elastic.co/latest.md?page=781

[Latest](https://discuss.elastic.co/latest.md) · [Categories](https://discuss.elastic.co/categories.md) · [Tags](https://discuss.elastic.co/tags.md)

**Page:** 782

---

## [Filebeat : field \[event\] not present as part of path \[event.start\]](https://discuss.elastic.co/t/filebeat-field-event-not-present-as-part-of-path-event-start/325634)

<div class="topic-metadata">

**Author:** [@Youssef\_Mouadden](https://discuss.elastic.co/u/Youssef_Mouadden)\
**Replies:** 1\
**Last updated:** [February 15, 2023, 6:20pm UTC](https://discuss.elastic.co/t/filebeat-field-event-not-present-as-part-of-path-event-start/325634 "2023-02-15T18:20:51Z")

</div>

hello, I'm facing a problem with filebeat pipeline. when I execute the pipeline with a console output, I have no error and I have the right execution, except that when I put an elasticsearch output I receive the followi…

---

## [ECK fails to start](https://discuss.elastic.co/t/eck-fails-to-start/325617)

<div class="topic-metadata">

**Author:** [@gjahagir](https://discuss.elastic.co/u/gjahagir)\
**Replies:** 0\
**Last updated:** [February 15, 2023, 1:14pm UTC](https://discuss.elastic.co/t/eck-fails-to-start/325617 "2023-02-15T13:14:12Z")

</div>

Hi. I'm exploring ECK to evalute how it works for our requirements. I followed the documentation here to set up the Elasticsearch operator. CRDs and Operator installed fine. Then used this YAML to create a single node…

---

## [Term contains a dot (.), nothing is returned](https://discuss.elastic.co/t/term-contains-a-dot-nothing-is-returned/325508)

<div class="topic-metadata">

**Author:** [@thales788](https://discuss.elastic.co/u/thales788)\
**Replies:** 9\
**Last updated:** [February 15, 2023, 5:28pm UTC](https://discuss.elastic.co/t/term-contains-a-dot-nothing-is-returned/325508 "2023-02-15T17:28:45Z")

</div>

Hello. I'm doing a query on the "username" field. The results are correct in most cases. When the given term contains a dot (.), nothing is returned. Ex: "firstname.lastname" = nothing is returned "firstname lastname" …

---

## [Elastic Agent conditions-based autodiscover doesn't pick up newly-scheduled pods/containers](https://discuss.elastic.co/t/elastic-agent-conditions-based-autodiscover-doesnt-pick-up-newly-scheduled-pods-containers/325271)

<div class="topic-metadata">

**Author:** [@DougR](https://discuss.elastic.co/u/DougR)\
**Replies:** 5\
**Last updated:** [February 15, 2023, 5:18pm UTC](https://discuss.elastic.co/t/elastic-agent-conditions-based-autodiscover-doesnt-pick-up-newly-scheduled-pods-containers/325271 "2023-02-15T17:18:39Z")

</div>

I am currently using Elastic Cloud, v8.6.1, with Elastic Agent Standalone v8.6.0 deployed to EKS, running Kubernetes v1.22.16 in our non-production cluster and v1.21.14 in our production cluster (to be updated this weeke…

---

## [High search\_fetch\_time for elasticsearch cluster](https://discuss.elastic.co/t/high-search-fetch-time-for-elasticsearch-cluster/325625)

<div class="topic-metadata">

**Author:** [@jaykb77](https://discuss.elastic.co/u/jaykb77)\
**Replies:** 1\
**Last updated:** [February 15, 2023, 5:13pm UTC](https://discuss.elastic.co/t/high-search-fetch-time-for-elasticsearch-cluster/325625 "2023-02-15T17:13:03Z")

</div>

We started seeing some high latency with the applications querying elasticsearch(7.17.0) and found that search\_fetch\_time is significantly increasing whenever there is some significant increase in incoming search traffic…

---

## [Send metricbeat via logstash as datastream](https://discuss.elastic.co/t/send-metricbeat-via-logstash-as-datastream/325628)

<div class="topic-metadata">

**Author:** [@A\_Mightiev](https://discuss.elastic.co/u/A_Mightiev)\
**Replies:** 4\
**Last updated:** [February 15, 2023, 4:41pm UTC](https://discuss.elastic.co/t/send-metricbeat-via-logstash-as-datastream/325628 "2023-02-15T16:41:24Z")

</div>

Hi I'm trying to send metricbeat data to logstash then store it as datastream into elasticsearch. I already have an datastream in elasticsearch "metricbeat-8.6.1", in my dashboards I'm using "metricbeat\*" index pattern …

---

## [Filebeat Helm chart run as non root](https://discuss.elastic.co/t/filebeat-helm-chart-run-as-non-root/325649)

<div class="topic-metadata">

**Author:** [@DarthVader](https://discuss.elastic.co/u/DarthVader)\
**Replies:** 0\
**Last updated:** [February 15, 2023, 4:31pm UTC](https://discuss.elastic.co/t/filebeat-helm-chart-run-as-non-root/325649 "2023-02-15T16:31:17Z")

</div>

Hello, I have been using Terraform to deploy the filebeat helm chart which currently runs successfully as root. Due to security policies I need to apply the pod security context "fsGroup" or anything similar that will e…

---

## [Master not discovered or elected yet, an election requires at least 2 nodes with ids - ELK Stack - Docker Swarm](https://discuss.elastic.co/t/master-not-discovered-or-elected-yet-an-election-requires-at-least-2-nodes-with-ids-elk-stack-docker-swarm/325548)

<div class="topic-metadata">

**Author:** [@vdcharter](https://discuss.elastic.co/u/vdcharter)\
**Replies:** 2\
**Last updated:** [February 15, 2023, 4:19pm UTC](https://discuss.elastic.co/t/master-not-discovered-or-elected-yet-an-election-requires-at-least-2-nodes-with-ids-elk-stack-docker-swarm/325548 "2023-02-15T16:19:09Z")

</div>

Hi, I am trying to setup a elastic cluster with 3 masters, 1 kibana node and 1 data node. This is a common topic but would like to understand what I am doing wrong. Below is portainer error log on master1 WARN master n…

---

## [Connect kibana to Elasticsearch after changes made](https://discuss.elastic.co/t/connect-kibana-to-elasticsearch-after-changes-made/325518)

<div class="topic-metadata">

**Author:** [@vassiliy.vins](https://discuss.elastic.co/u/vassiliy.vins)\
**Replies:** 16\
**Last updated:** [February 15, 2023, 4:00pm UTC](https://discuss.elastic.co/t/connect-kibana-to-elasticsearch-after-changes-made/325518 "2023-02-15T16:00:15Z")

</div>

Hello! My kibana doesnt talk to Elasticsearch after changes are made in elasticsearch config Some history: installed ELK on one host and filebeat on another one. Started elasticsearch, started kibana, started logsta…

---

## [Elastic SaaS Crawl Frequency Settings, also SSO](https://discuss.elastic.co/t/elastic-saas-crawl-frequency-settings-also-sso/325173)

<div class="topic-metadata">

**Author:** [@alongaks](https://discuss.elastic.co/u/alongaks)\
**Replies:** 3\
**Last updated:** [February 15, 2023, 3:50pm UTC](https://discuss.elastic.co/t/elastic-saas-crawl-frequency-settings-also-sso/325173 "2023-02-15T15:50:06Z")

</div>

Hello, I have a couple questions about the capability of SaaS Elastic crawling and also SSO. Crawl Scheduling: I am running a trial with a couple test indices. In one index there multiple domains/subdomains. One of th…

---

## [Elasticsearch sort returns incorrect results?](https://discuss.elastic.co/t/elasticsearch-sort-returns-incorrect-results/325512)

<div class="topic-metadata">

**Author:** [@Fatih\_Erol1](https://discuss.elastic.co/u/Fatih_Erol1)\
**Replies:** 1\
**Last updated:** [February 15, 2023, 3:40pm UTC](https://discuss.elastic.co/t/elasticsearch-sort-returns-incorrect-results/325512 "2023-02-15T15:40:18Z")

</div>

Why elasticsearch sort returns incorrect results? Mappings { "mappings": { "\_doc": { "properties": { "name": { "type": "keyword", "fields": { "sort": { …

---

## [Logstash - Could not connect to a compatible version of Elasticsearch](https://discuss.elastic.co/t/logstash-could-not-connect-to-a-compatible-version-of-elasticsearch/325629)

<div class="topic-metadata">

**Author:** [@hnclientes\_HN](https://discuss.elastic.co/u/hnclientes_HN)\
**Replies:** 1\
**Last updated:** [February 15, 2023, 3:20pm UTC](https://discuss.elastic.co/t/logstash-could-not-connect-to-a-compatible-version-of-elasticsearch/325629 "2023-02-15T15:20:58Z")

</div>

I'm trying to upload a .csv file via logstash to a test version on Cloud V 8.6.1 and I get an error when trying (I'm using logstash version 8.6.1 anyway) and I get the following error: ´\`\`\` \[2023-02-14T23:21:15,274\]\[ER…

---

## [Limit of total fields \[1000\] in index has been exceeded after changing case classes to maps](https://discuss.elastic.co/t/limit-of-total-fields-1000-in-index-has-been-exceeded-after-changing-case-classes-to-maps/325635)

<div class="topic-metadata">

**Author:** [@markcitizen](https://discuss.elastic.co/u/markcitizen)\
**Replies:** 0\
**Last updated:** [February 15, 2023, 3:19pm UTC](https://discuss.elastic.co/t/limit-of-total-fields-1000-in-index-has-been-exceeded-after-changing-case-classes-to-maps/325635 "2023-02-15T15:19:34Z")

</div>

Hello, I have a Scala Spark job that's writing output data to ES index. I modified my code to recursively convert Scala classes into Maps before writing those to the index. Before (when using case classes) index write w…

---

## [When to clear es cache?](https://discuss.elastic.co/t/when-to-clear-es-cache/325428)

<div class="topic-metadata">

**Author:** [@elastic-db-user](https://discuss.elastic.co/u/elastic-db-user)\
**Replies:** 8\
**Last updated:** [February 15, 2023, 2:59pm UTC](https://discuss.elastic.co/t/when-to-clear-es-cache/325428 "2023-02-15T14:59:45Z")

</div>

Is it a good idea to proactively clear all cache with a daily cron job to avoid any circuit breaker or any other memory related issues? Api calls from app to Elasticsearch are the same query e.g. count, histogram, get, …

---

## [Bar horizontal percentage chart from boolean](https://discuss.elastic.co/t/bar-horizontal-percentage-chart-from-boolean/325619)

<div class="topic-metadata">

**Author:** [@fbaer](https://discuss.elastic.co/u/fbaer)\
**Replies:** 2\
**Last updated:** [February 15, 2023, 2:52pm UTC](https://discuss.elastic.co/t/bar-horizontal-percentage-chart-from-boolean/325619 "2023-02-15T14:52:48Z")

</div>

I am retrieving a boolean field from my logs. Now i want to show this field as horizontal bar in percent with two colors green for true and red for false. It would be great if there was one bar showing the percentage of …

---

## [Elastic AppSearch operators in query string yield unexpected results](https://discuss.elastic.co/t/elastic-appsearch-operators-in-query-string-yield-unexpected-results/325572)

<div class="topic-metadata">

**Author:** [@Nguyen\_Anh\_Vu](https://discuss.elastic.co/u/Nguyen_Anh_Vu)\
**Replies:** 1\
**Last updated:** [February 15, 2023, 2:49pm UTC](https://discuss.elastic.co/t/elastic-appsearch-operators-in-query-string-yield-unexpected-results/325572 "2023-02-15T14:49:37Z")

</div>

I run these queries and here are the number of results I got // Query 1 machine AND building { "query": "machine AND building" } // Total 109 items // Query 2 machine AND car // Total 27 items // Query 3. Total 6 it…

---

## [Kibana does not log all lines as json](https://discuss.elastic.co/t/kibana-does-not-log-all-lines-as-json/325627)

<div class="topic-metadata">

**Author:** [@woodywoodsta](https://discuss.elastic.co/u/woodywoodsta)\
**Replies:** 0\
**Last updated:** [February 15, 2023, 2:36pm UTC](https://discuss.elastic.co/t/kibana-does-not-log-all-lines-as-json/325627 "2023-02-15T14:36:24Z")

</div>

I have Kibana deployed as an ECK resource. Despite the following config: config: logging: appenders: json-layout: type: console layout: type: json root: appenders: \[json-…

---

## [Config Auditbeat](https://discuss.elastic.co/t/config-auditbeat/325519)

<div class="topic-metadata">

**Author:** [@CodeRed](https://discuss.elastic.co/u/CodeRed)\
**Replies:** 0\
**Last updated:** [February 14, 2023, 10:37pm UTC](https://discuss.elastic.co/t/config-auditbeat/325519 "2023-02-14T22:37:07Z")

</div>

Currently i am experimenting with auditbeat the config process i want to collect the whole log due to the auditd rules i added but the log i get is no log auditd here is my config file auditbeat.modules: module: audi…

---

## [Some indexes stopped to rollover and are now created without alias](https://discuss.elastic.co/t/some-indexes-stopped-to-rollover-and-are-now-created-without-alias/325623)

<div class="topic-metadata">

**Author:** [@zebu14](https://discuss.elastic.co/u/zebu14)\
**Replies:** 0\
**Last updated:** [February 15, 2023, 2:08pm UTC](https://discuss.elastic.co/t/some-indexes-stopped-to-rollover-and-are-now-created-without-alias/325623 "2023-02-15T14:08:59Z")

</div>

Hello, Some weeks ago, I had a full disk problem on my dev cluster. I made some space, reactivated index writing with PUT /\_all/\_settings { "index.blocks.read\_only\_allow\_delete": null } Most of the indexes are doin…

---

## [Elastic agent on eks](https://discuss.elastic.co/t/elastic-agent-on-eks/324903)

<div class="topic-metadata">

**Author:** [@oded\_rafi](https://discuss.elastic.co/u/oded_rafi)\
**Replies:** 1\
**Last updated:** [February 15, 2023, 1:48pm UTC](https://discuss.elastic.co/t/elastic-agent-on-eks/324903 "2023-02-15T13:48:27Z")

</div>

hey all i am trying to run an agent on my eks cluster and the pods wont run i am using the code from elastic as is. could anyone help? --- # For more information refer to https://www.elastic.co/guide/en/fleet/current…

---

## [Elastic Agent not shipping all logs from Kubernetes Cluster. Errors in logs](https://discuss.elastic.co/t/elastic-agent-not-shipping-all-logs-from-kubernetes-cluster-errors-in-logs/325620)

<div class="topic-metadata">

**Author:** [@slogger](https://discuss.elastic.co/u/slogger)\
**Replies:** 0\
**Last updated:** [February 15, 2023, 1:44pm UTC](https://discuss.elastic.co/t/elastic-agent-not-shipping-all-logs-from-kubernetes-cluster-errors-in-logs/325620 "2023-02-15T13:44:55Z")

</div>

Hello I have Elastic Agent installed on 5 EKS clusters for logging and monitoring. Recently the agents have stopped shipping all logs to the cluster (Hosted with elastic.cloud). Im seeing some logs, but not all (usual…

---

## [Designing a visualisation for success/failure of processes](https://discuss.elastic.co/t/designing-a-visualisation-for-success-failure-of-processes/324634)

<div class="topic-metadata">

**Author:** [@PetervH](https://discuss.elastic.co/u/PetervH)\
**Replies:** 3\
**Last updated:** [February 15, 2023, 1:38pm UTC](https://discuss.elastic.co/t/designing-a-visualisation-for-success-failure-of-processes/324634 "2023-02-15T13:38:39Z")

</div>

Hi Can someone suggest a way to achieve the following: I'm getting a constant stream of events from a source. These events include data that specifies whether a particular process has completed successfully, as indicat…

---

## [Fleet server lose agents at restart](https://discuss.elastic.co/t/fleet-server-lose-agents-at-restart/325477)

<div class="topic-metadata">

**Author:** [@K8pl3r](https://discuss.elastic.co/u/K8pl3r)\
**Replies:** 5\
**Last updated:** [February 15, 2023, 1:13pm UTC](https://discuss.elastic.co/t/fleet-server-lose-agents-at-restart/325477 "2023-02-15T13:13:52Z")

</div>

Hello I'm a student who's getting started with Elastic, I have configured my stack with elasticsearch and Kibana. I have an issue when I reboot my fleet server, all of my elastic-agents are offline (I have enabled the …

---

## [Elasticsearch.service craches (Active: failed) every 1,2 days](https://discuss.elastic.co/t/elasticsearch-service-craches-active-failed-every-1-2-days/325373)

<div class="topic-metadata">

**Author:** [@Ziad\_Khater](https://discuss.elastic.co/u/Ziad_Khater)\
**Replies:** 12\
**Last updated:** [February 15, 2023, 12:42pm UTC](https://discuss.elastic.co/t/elasticsearch-service-craches-active-failed-every-1-2-days/325373 "2023-02-15T12:42:09Z")

</div>

Hi Team, every 1,2 days elasticsearch.service failed on my ubunto machine. It has all memory/disk resources it needs. I'll attach logs here and below is the failed status of elasticsearch. ===========================…

---

## [Multiline filter is not working even after installing the plugin](https://discuss.elastic.co/t/multiline-filter-is-not-working-even-after-installing-the-plugin/325611)

<div class="topic-metadata">

**Author:** [@Balaguru\_Maruthamuth](https://discuss.elastic.co/u/Balaguru_Maruthamuth)\
**Replies:** 2\
**Last updated:** [February 15, 2023, 12:44pm UTC](https://discuss.elastic.co/t/multiline-filter-is-not-working-even-after-installing-the-plugin/325611 "2023-02-15T12:44:36Z")

</div>

Warning: Manual override - there are filters that might not work with multiple worker threads {:pipeline\_id=\>"exterro", :worker\_threads=\>3, :filters=\>\["multiline", "multiline", "multiline", "multiline", "multiline", "mul…

---

## [Change time zone using date filter](https://discuss.elastic.co/t/change-time-zone-using-date-filter/325461)

<div class="topic-metadata">

**Author:** [@yuswanul](https://discuss.elastic.co/u/yuswanul)\
**Replies:** 5\
**Last updated:** [February 15, 2023, 12:37pm UTC](https://discuss.elastic.co/t/change-time-zone-using-date-filter/325461 "2023-02-15T12:37:36Z")

</div>

Hi there, i have a problem with timezone in date filter. so this is the situation: i have a field contain an epoch timestamp like this i try to convert it using date filter like this but it didn't work mutate{ …

---

## [Problems using search\_fields and weighting in queries](https://discuss.elastic.co/t/problems-using-search-fields-and-weighting-in-queries/325610)

<div class="topic-metadata">

**Author:** [@bar8s](https://discuss.elastic.co/u/bar8s)\
**Replies:** 0\
**Last updated:** [February 15, 2023, 12:35pm UTC](https://discuss.elastic.co/t/problems-using-search-fields-and-weighting-in-queries/325610 "2023-02-15T12:35:34Z")

</div>

I am trying to query an Elasticsearch index with some dynamic weighting on specific fields, but the query parser is rejecting the query I am basing this on the documentation at Relevance Tuning Guide, Weights and Boosts…

---

## [Synonyms Exact match Multiword Search](https://discuss.elastic.co/t/synonyms-exact-match-multiword-search/325439)

<div class="topic-metadata">

**Author:** [@Sahil5](https://discuss.elastic.co/u/Sahil5)\
**Replies:** 3\
**Last updated:** [February 15, 2023, 12:34pm UTC](https://discuss.elastic.co/t/synonyms-exact-match-multiword-search/325439 "2023-02-15T12:34:42Z")

</div>

Hi Team, We are looking for solution to search synonyms with exact match. For Example User is searching string - abc xyz abc has synonyms - abc1 abc2 xyz has synonyms - xyz1 xyz2 Data in Index Article1 - test abc1 …

---

## [Column count doesn't match after doing alias](https://discuss.elastic.co/t/column-count-doesnt-match-after-doing-alias/325454)

<div class="topic-metadata">

**Author:** [@Rushikesh\_Dikey](https://discuss.elastic.co/u/Rushikesh_Dikey)\
**Replies:** 1\
**Last updated:** [February 15, 2023, 10:37am UTC](https://discuss.elastic.co/t/column-count-doesnt-match-after-doing-alias/325454 "2023-02-15T10:37:23Z")

</div>

Hi Team, I am trying to merge two different index, so i used // POST /\_aliases { "actions": \[ { "add": { "index": "abc", "alias": "poc" } }, { "add": { "index": "xyz", …

---

## [Logs, metrics and APM on Solaris, HPUX - I know it's not supported - but related question anyway](https://discuss.elastic.co/t/logs-metrics-and-apm-on-solaris-hpux-i-know-its-not-supported-but-related-question-anyway/325598)

<div class="topic-metadata">

**Author:** [@Melee](https://discuss.elastic.co/u/Melee)\
**Replies:** 0\
**Last updated:** [February 15, 2023, 10:30am UTC](https://discuss.elastic.co/t/logs-metrics-and-apm-on-solaris-hpux-i-know-its-not-supported-but-related-question-anyway/325598 "2023-02-15T10:30:29Z")

</div>

Hello together, we are using the elastic stack (elastic agent, APM agent, heartbeat, logstash, kibana). So far so fine. Now, we have some legacy systems esp. Solaris, HPUX and also RHEL 6. There were already multiple …

[Previous page](https://discuss.elastic.co/latest.md?page=780)

[Next page](https://discuss.elastic.co/latest.md?page=782)
