# Latest

**URL:** https://discuss.elastic.co/latest.md?page=782

[Latest](https://discuss.elastic.co/latest.md) · [Categories](https://discuss.elastic.co/categories.md) · [Tags](https://discuss.elastic.co/tags.md)

**Page:** 783

---

## [Security Alert ：How to suppress repeat alarms](https://discuss.elastic.co/t/security-alert-how-to-suppress-repeat-alarms/325565)

<div class="topic-metadata">

**Author:** [@xqaiviwjxzw](https://discuss.elastic.co/u/xqaiviwjxzw)\
**Replies:** 1\
**Last updated:** [February 15, 2023, 10:29am UTC](https://discuss.elastic.co/t/security-alert-how-to-suppress-repeat-alarms/325565 "2023-02-15T10:29:32Z")

</div>

More than 100 duplicate alarms are generated in 1 minute, what can be done to suppress duplicate alarms and display only one of the duplicate alarms?

---

## [Vega-lite, create a forecast similar as lens visualization](https://discuss.elastic.co/t/vega-lite-create-a-forecast-similar-as-lens-visualization/323572)

<div class="topic-metadata">

**Author:** [@plus](https://discuss.elastic.co/u/plus)\
**Replies:** 7\
**Last updated:** [February 15, 2023, 10:05am UTC](https://discuss.elastic.co/t/vega-lite-create-a-forecast-similar-as-lens-visualization/323572 "2023-02-15T10:05:12Z")

</div>

Hello everyone I have a question with vega-lite and I don't know how to follow up. I checked on lens I can see data from last 2 hours and next 4 hours on the same graphic (a forecast job has been launched previously to …

---

## [Remote Linux logs](https://discuss.elastic.co/t/remote-linux-logs/325578)

<div class="topic-metadata">

**Author:** [@Derick\_Jansen](https://discuss.elastic.co/u/Derick_Jansen)\
**Replies:** 0\
**Last updated:** [February 15, 2023, 9:48am UTC](https://discuss.elastic.co/t/remote-linux-logs/325578 "2023-02-15T09:48:42Z")

</div>

Is there no way to use Elastic Agent or Filebeat to accept TCP Syslog messages forwarded from Linux hosts? Will I need to use something like rsyslog or Logstash to write the files to disk first, then use the system inte…

---

## [Log4j add more fields](https://discuss.elastic.co/t/log4j-add-more-fields/325546)

<div class="topic-metadata">

**Author:** [@manusha\_karunathilak](https://discuss.elastic.co/u/manusha_karunathilak)\
**Replies:** 0\
**Last updated:** [February 15, 2023, 6:18am UTC](https://discuss.elastic.co/t/log4j-add-more-fields/325546 "2023-02-15T06:18:53Z")

</div>

I have setup to write log4j logs to elasticsearch. However it only maps log4j default fields such as level, message and etc. Full log message contains session id in the console log but that part is not mapped by default…

---

## [Conflicting Field Elasticsearch host.ip in metrics\*-\* Index Pattern](https://discuss.elastic.co/t/conflicting-field-elasticsearch-host-ip-in-metrics-index-pattern/325539)

<div class="topic-metadata">

**Author:** [@OmFJ](https://discuss.elastic.co/u/OmFJ)\
**Replies:** 1\
**Last updated:** [February 15, 2023, 8:27am UTC](https://discuss.elastic.co/t/conflicting-field-elasticsearch-host-ip-in-metrics-index-pattern/325539 "2023-02-15T08:27:32Z")

</div>

Hello Everyone, in this topic, i would like to ask about conflicting field. From all discussions and forum i visited most of them tell you to re-index your index. but i come across this problem where the conflicting fie…

---

## [How to develop Kibana custom plugin to add a custom agg type in Kibana Platform?](https://discuss.elastic.co/t/how-to-develop-kibana-custom-plugin-to-add-a-custom-agg-type-in-kibana-platform/325556)

<div class="topic-metadata">

**Author:** [@gnehcnij](https://discuss.elastic.co/u/gnehcnij)\
**Replies:** 0\
**Last updated:** [February 15, 2023, 8:06am UTC](https://discuss.elastic.co/t/how-to-develop-kibana-custom-plugin-to-add-a-custom-agg-type-in-kibana-platform/325556 "2023-02-15T08:06:28Z")

</div>

I want to update Kibana from v6.8.23 to v7.17.8, but the plugin kibana-datasweet-formula that I want to migrate to Kibana Platform do not work (Installation failed). I found this place to register each agg type: but…

---

## [Elastic Upgrade Issue](https://discuss.elastic.co/t/elastic-upgrade-issue/325470)

<div class="topic-metadata">

**Author:** [@cobdeng](https://discuss.elastic.co/u/cobdeng)\
**Replies:** 3\
**Last updated:** [February 15, 2023, 7:30am UTC](https://discuss.elastic.co/t/elastic-upgrade-issue/325470 "2023-02-15T07:30:44Z")

</div>

Hi We are currently using Elasticsearch 7.16.2 and are now looking at the upgrade process to 7.16.3 and upwards. When we initially installed Elasticsearch, we used the msi installers that were then available as we are …

---

## [Custom plugin and custom entries in /etc/default/logstash gets deleted after each update on ubuntu](https://discuss.elastic.co/t/custom-plugin-and-custom-entries-in-etc-default-logstash-gets-deleted-after-each-update-on-ubuntu/325549)

<div class="topic-metadata">

**Author:** [@stillfreem](https://discuss.elastic.co/u/stillfreem)\
**Replies:** 0\
**Last updated:** [February 15, 2023, 6:44am UTC](https://discuss.elastic.co/t/custom-plugin-and-custom-entries-in-etc-default-logstash-gets-deleted-after-each-update-on-ubuntu/325549 "2023-02-15T06:44:03Z")

</div>

Hello All, I wanted a to ask if anybody knows why after almost each apt-get update/upgrate on my server two output plugins always gets deleted and I need to reinstall them along with all custom Logstash entries in /etc/…

---

## [Bash: ./bin/elasticsearch: No such file or directory](https://discuss.elastic.co/t/bash-bin-elasticsearch-no-such-file-or-directory/325506)

<div class="topic-metadata">

**Author:** [@samidha\_dubey](https://discuss.elastic.co/u/samidha_dubey)\
**Replies:** 2\
**Last updated:** [February 15, 2023, 6:40am UTC](https://discuss.elastic.co/t/bash-bin-elasticsearch-no-such-file-or-directory/325506 "2023-02-15T06:40:11Z")

</div>

Hello i am facing issue while setting up users for my ELK stack, I setup ELK on docker so my ELK is running as a docker container i used sebp/elk image and my container is running fine i can access kibana dashboard, i …

---

## [Update\_by\_query - empty failures list in response when conflicts=proceed](https://discuss.elastic.co/t/update-by-query-empty-failures-list-in-response-when-conflicts-proceed/325100)

<div class="topic-metadata">

**Author:** [@Przemyslaw\_Mantaj](https://discuss.elastic.co/u/Przemyslaw_Mantaj)\
**Replies:** 1\
**Last updated:** [February 15, 2023, 5:51am UTC](https://discuss.elastic.co/t/update-by-query-empty-failures-list-in-response-when-conflicts-proceed/325100 "2023-02-15T05:51:30Z")

</div>

Continuing the discussion from Update\_by\_query with proceed does not return failure: I repeat @Paul\_Le\_Tilly question. Is it possible to return the failures list when the conflicts option has been set to proceed? Than…

---

## [Incorrect Filebeat Metrics](https://discuss.elastic.co/t/incorrect-filebeat-metrics/325540)

<div class="topic-metadata">

**Author:** [@vinit0711](https://discuss.elastic.co/u/vinit0711)\
**Replies:** 0\
**Last updated:** [February 15, 2023, 5:19am UTC](https://discuss.elastic.co/t/incorrect-filebeat-metrics/325540 "2023-02-15T05:19:34Z")

</div>

I have Netflow Input For Filebeat . Fiebeat is processing the flow and sending to Elastic. I am receiving following metric logs From filebeat which are generated after every 30s {"monitoring":{"metrics":{"beat":{"cgrou…

---

## [How to search file path field value in Kibana?](https://discuss.elastic.co/t/how-to-search-file-path-field-value-in-kibana/325538)

<div class="topic-metadata">

**Author:** [@First\_Last](https://discuss.elastic.co/u/First_Last)\
**Replies:** 0\
**Last updated:** [February 15, 2023, 4:51am UTC](https://discuss.elastic.co/t/how-to-search-file-path-field-value-in-kibana/325538 "2023-02-15T04:51:59Z")

</div>

New to Kibana and need some help understanding escaping special characters. Basically what I'm trying to do is take what I know in splunk and wildcard searching substrings of eventlog fields. Below is what I tried but re…

---

## [Error importing Kibana dashboards: fail to import the dashboards in Kibana:](https://discuss.elastic.co/t/error-importing-kibana-dashboards-fail-to-import-the-dashboards-in-kibana/316015)

<div class="topic-metadata">

**Author:** [@Joao\_Malebo](https://discuss.elastic.co/u/Joao_Malebo)\
**Replies:** 6\
**Last updated:** [February 15, 2023, 4:16am UTC](https://discuss.elastic.co/t/error-importing-kibana-dashboards-fail-to-import-the-dashboards-in-kibana/316015 "2023-02-15T04:16:07Z")

</div>

I'm having errors when running the command to check the version information. To load dashboards when Logstash is enabled, you need to disable Logstash output and enable Elasticsearch output: Follow the command and error…

---

## [Elasticsearch + Java - Inconsistent Search/Query time](https://discuss.elastic.co/t/elasticsearch-java-inconsistent-search-query-time/325527)

<div class="topic-metadata">

**Author:** [@Java2avaj](https://discuss.elastic.co/u/Java2avaj)\
**Replies:** 0\
**Last updated:** [February 15, 2023, 3:38am UTC](https://discuss.elastic.co/t/elasticsearch-java-inconsistent-search-query-time/325527 "2023-02-15T03:38:35Z")

</div>

We are searching over 10million documents with a simple query that contains bool and multiple shoulds. But query time is inconsistent- taking sometimes 100ms sometimes 4 seconds. How can we tune this so that query time …

---

## [Elastic Security Manage - EndPoint not work](https://discuss.elastic.co/t/elastic-security-manage-endpoint-not-work/325367)

<div class="topic-metadata">

**Author:** [@NathanLau](https://discuss.elastic.co/u/NathanLau)\
**Replies:** 8\
**Last updated:** [February 15, 2023, 2:51am UTC](https://discuss.elastic.co/t/elastic-security-manage-endpoint-not-work/325367 "2023-02-15T02:51:03Z")

</div>

Hi , When I deleted agents for endpoint , I want to re-add agent to endpoint but not work , even I reinstall fleet server or any hosts to security --\> manage --\> Endpoint. references: Keep showing this to inst…

---

## [How to dynamically specify a url formatter](https://discuss.elastic.co/t/how-to-dynamically-specify-a-url-formatter/325520)

<div class="topic-metadata">

**Author:** [@kohkaw](https://discuss.elastic.co/u/kohkaw)\
**Replies:** 0\
**Last updated:** [February 15, 2023, 1:58am UTC](https://discuss.elastic.co/t/how-to-dynamically-specify-a-url-formatter/325520 "2023-02-15T01:58:25Z")

</div>

I want to dynamically specify a url formatter for a document that contains an ever-increasing number of URL strings. Is there any other way than manually setting Set format=url from Index pattern?

---

## [Reindexing in Production Environment](https://discuss.elastic.co/t/reindexing-in-production-environment/323543)

<div class="topic-metadata">

**Author:** [@vishnu\_teja](https://discuss.elastic.co/u/vishnu_teja)\
**Replies:** 1\
**Last updated:** [February 15, 2023, 12:18am UTC](https://discuss.elastic.co/t/reindexing-in-production-environment/323543 "2023-02-15T00:18:19Z")

</div>

Hi Everyone, Currently in our Elasticsearch cluster we have a lot of documents which need to deleted, so we are looking to re-index the used documents to a new index and delete the old index. We will be doing this in pro…

---

## [Elastic Network Drive Connector - OCR & PDF](https://discuss.elastic.co/t/elastic-network-drive-connector-ocr-pdf/325505)

<div class="topic-metadata">

**Author:** [@mike\_dmhc](https://discuss.elastic.co/u/mike_dmhc)\
**Replies:** 0\
**Last updated:** [February 14, 2023, 6:33pm UTC](https://discuss.elastic.co/t/elastic-network-drive-connector-ocr-pdf/325505 "2023-02-14T18:33:26Z")

</div>

Wondering if anyone is using the Elastic Network Drive Connector to run OCR on PDF documents? Is there any configuration besides having Tesseract installed? The documentation is a bit sparse on OCR in the Network Drive C…

---

## [Editing a managed policy can break Kibana caution](https://discuss.elastic.co/t/editing-a-managed-policy-can-break-kibana-caution/325515)

<div class="topic-metadata">

**Author:** [@David41](https://discuss.elastic.co/u/David41)\
**Replies:** 1\
**Last updated:** [February 14, 2023, 10:54pm UTC](https://discuss.elastic.co/t/editing-a-managed-policy-can-break-kibana-caution/325515 "2023-02-14T22:54:04Z")

</div>

Hi, I am wanting to edit an existing policy and I notice that there is a caution symbol that states that "Editing a managed policy can break Kibana" I am not sure if it will break or not . However there is an option tha…

---

## [Message: app heartbeat--8.4.3-d6501b26: Missed two check-in elastic-agent standalone](https://discuss.elastic.co/t/message-app-heartbeat-8-4-3-d6501b26-missed-two-check-in-elastic-agent-standalone/325050)

<div class="topic-metadata">

**Author:** [@Bhrugu\_Sharma](https://discuss.elastic.co/u/Bhrugu_Sharma)\
**Replies:** 3\
**Last updated:** [February 14, 2023, 9:34pm UTC](https://discuss.elastic.co/t/message-app-heartbeat-8-4-3-d6501b26-missed-two-check-in-elastic-agent-standalone/325050 "2023-02-14T21:34:13Z")

</div>

I've used the code mentioned below, and when i log into one of the agents and do ./elastic-agent status i get the following error and the logs for kibana states sample code apiVersion: v1 kind: ConfigMap metadata…

---

## [How to parse csv via Elastic Agent?](https://discuss.elastic.co/t/how-to-parse-csv-via-elastic-agent/324121)

<div class="topic-metadata">

**Author:** [@test\_qweqwe](https://discuss.elastic.co/u/test_qweqwe)\
**Replies:** 16\
**Last updated:** [February 14, 2023, 9:05pm UTC](https://discuss.elastic.co/t/how-to-parse-csv-via-elastic-agent/324121 "2023-02-14T21:05:22Z")

</div>

Hi! I want to collects csv logs and if I understand correct, I need to add new integration based on "Custom Logs"? I'm not sure how to do it. I have this config for logstash under conf.d folder and everything work fin…

---

## [Elasticsearch query for \`SELECT id FROM foo WHERE id NOT IN (SELECT id FROM foo WHERE ...)](https://discuss.elastic.co/t/elasticsearch-query-for-select-id-from-foo-where-id-not-in-select-id-from-foo-where/325302)

<div class="topic-metadata">

**Author:** [@learningelastic](https://discuss.elastic.co/u/learningelastic)\
**Replies:** 4\
**Last updated:** [February 14, 2023, 7:51pm UTC](https://discuss.elastic.co/t/elasticsearch-query-for-select-id-from-foo-where-id-not-in-select-id-from-foo-where/325302 "2023-02-14T19:51:34Z")

</div>

I want to do a "not in present index" type of operation. For example, let's say I have an index called customer\_subscription with just these 4 records: | customer\_id | pay\_date | +-------------+------------+ | …

---

## [Why is multiline not working for this unstructured log?](https://discuss.elastic.co/t/why-is-multiline-not-working-for-this-unstructured-log/325510)

<div class="topic-metadata">

**Author:** [@erwin339](https://discuss.elastic.co/u/erwin339)\
**Replies:** 0\
**Last updated:** [February 14, 2023, 7:32pm UTC](https://discuss.elastic.co/t/why-is-multiline-not-working-for-this-unstructured-log/325510 "2023-02-14T19:32:18Z")

</div>

My multiline: parsers: -multiline: type: pattern pattern: '^\\{' negate: true match: after The format of my log can be like this: { C-FLOW-ID-CAB APN101MQ C-OPERATION-CAB P T-EVENTO-CAB RUNN…

---

## [Unable to edit synthetic monitors because of limited privilege](https://discuss.elastic.co/t/unable-to-edit-synthetic-monitors-because-of-limited-privilege/325384)

<div class="topic-metadata">

**Author:** [@shinki927](https://discuss.elastic.co/u/shinki927)\
**Replies:** 2\
**Last updated:** [February 14, 2023, 7:32pm UTC](https://discuss.elastic.co/t/unable-to-edit-synthetic-monitors-because-of-limited-privilege/325384 "2023-02-14T19:32:00Z")

</div>

Hello, I would like to figure out which privilege is necessary to fully access the monitor management in Uptime. We grant the following privilege according to Elastic doc: Our user is able to create and delete monit…

---

## [Detection rule execution failure: "Rule registry writing is disabled due to an error during Rule Data Client initialization."](https://discuss.elastic.co/t/detection-rule-execution-failure-rule-registry-writing-is-disabled-due-to-an-error-during-rule-data-client-initialization/325356)

<div class="topic-metadata">

**Author:** [@bil15](https://discuss.elastic.co/u/bil15)\
**Replies:** 3\
**Last updated:** [February 14, 2023, 6:46pm UTC](https://discuss.elastic.co/t/detection-rule-execution-failure-rule-registry-writing-is-disabled-due-to-an-error-during-rule-data-client-initialization/325356 "2023-02-14T18:46:17Z")

</div>

Hello! I am struggling with error that leads to detection rules execution failure. For the context: I am creating new detection rules in separate Space with limited permissions, so I am not an admin. When a detection …

---

## [Restarting logstash container sends events again to elastic, despite sincedb](https://discuss.elastic.co/t/restarting-logstash-container-sends-events-again-to-elastic-despite-sincedb/324675)

<div class="topic-metadata">

**Author:** [@paul\_chrlt](https://discuss.elastic.co/u/paul_chrlt)\
**Replies:** 7\
**Last updated:** [February 14, 2023, 6:03pm UTC](https://discuss.elastic.co/t/restarting-logstash-container-sends-events-again-to-elastic-despite-sincedb/324675 "2023-02-14T18:03:09Z")

</div>

Hi all, Can you help us ? We use elk 7.17.7 in docker containers hosted on a server with persistent shared volumes for path (read only), file\_completed\_log\_path, sincedb\_path. Each time we stop and start our logstash …

---

## [No data streams and logs under fleet server](https://discuss.elastic.co/t/no-data-streams-and-logs-under-fleet-server/325493)

<div class="topic-metadata">

**Author:** [@Leonardo\_Henrique](https://discuss.elastic.co/u/Leonardo_Henrique)\
**Replies:** 0\
**Last updated:** [February 14, 2023, 3:21pm UTC](https://discuss.elastic.co/t/no-data-streams-and-logs-under-fleet-server/325493 "2023-02-14T15:21:35Z")

</div>

Hey everyone. I have configured fleet server but I can not see any log messages or data streams in the Kibana UI. Elasticsearch nodes are configured with SSL (with elasticsearch-certutil) and fleet-server is using the …

---

## [Implement User interface buttons for Logstash](https://discuss.elastic.co/t/implement-user-interface-buttons-for-logstash/323641)

<div class="topic-metadata">

**Author:** [@Sandeep\_Raju](https://discuss.elastic.co/u/Sandeep_Raju)\
**Replies:** 1\
**Last updated:** [February 14, 2023, 3:42pm UTC](https://discuss.elastic.co/t/implement-user-interface-buttons-for-logstash/323641 "2023-02-14T15:42:39Z")

</div>

Hi all, I am currently pushing data to indices in my elasticsearch 8.4 using logstash in my terminal. However , One of my friends does not know logstash and wants to work with logstash in User interface and push data i…

---

## [Optimizer fails when running yarn start in Kibana version 8](https://discuss.elastic.co/t/optimizer-fails-when-running-yarn-start-in-kibana-version-8/324142)

<div class="topic-metadata">

**Author:** [@ssimmons](https://discuss.elastic.co/u/ssimmons)\
**Replies:** 1\
**Last updated:** [February 14, 2023, 4:49pm UTC](https://discuss.elastic.co/t/optimizer-fails-when-running-yarn-start-in-kibana-version-8/324142 "2023-02-14T16:49:19Z")

</div>

I'm in the process of upgrading our custom plugins to Kibana version 8. I'm trying to setup Kibana and Elasticsearch through docker. In the past, I built Kibana using a Dockerfile that would clone Kibana and then run yar…

---

## [Index Patterns](https://discuss.elastic.co/t/index-patterns/325496)

<div class="topic-metadata">

**Author:** [@hnclientes\_HN](https://discuss.elastic.co/u/hnclientes_HN)\
**Replies:** 2\
**Last updated:** [February 14, 2023, 4:48pm UTC](https://discuss.elastic.co/t/index-patterns/325496 "2023-02-14T16:48:48Z")

</div>

Hi, I'm testing this version (cloud), and I can't find the option to create an index pattern for an index that I create using devtools. Could you tell me how I can activate this option please? Thank you

[Previous page](https://discuss.elastic.co/latest.md?page=781)

[Next page](https://discuss.elastic.co/latest.md?page=783)
