# Latest

**URL:** https://discuss.elastic.co/latest.md?page=783

[Latest](https://discuss.elastic.co/latest.md) · [Categories](https://discuss.elastic.co/categories.md) · [Tags](https://discuss.elastic.co/tags.md)

**Page:** 784

---

## [Add a custom tooltip to charts in Kibana?](https://discuss.elastic.co/t/add-a-custom-tooltip-to-charts-in-kibana/325487)

<div class="topic-metadata">

**Author:** [@Senol\_Kurt](https://discuss.elastic.co/u/Senol_Kurt)\
**Replies:** 2\
**Last updated:** [February 14, 2023, 3:50pm UTC](https://discuss.elastic.co/t/add-a-custom-tooltip-to-charts-in-kibana/325487 "2023-02-14T15:50:03Z")

</div>

I want to add a custom tooltip that explains charts created with Lens. Is it possible with Kibana? Elasticsearch v.8.3.3

---

## [Filebeat autodiscover stopping too early when kubernetes pod terminates](https://discuss.elastic.co/t/filebeat-autodiscover-stopping-too-early-when-kubernetes-pod-terminates/325491)

<div class="topic-metadata">

**Author:** [@cpaton](https://discuss.elastic.co/u/cpaton)\
**Replies:** 0\
**Last updated:** [February 14, 2023, 2:49pm UTC](https://discuss.elastic.co/t/filebeat-autodiscover-stopping-too-early-when-kubernetes-pod-terminates/325491 "2023-02-14T14:49:14Z")

</div>

I am using filebeat with autodiscover within a Kubernetes cluster to capture logs. When a Kubernetes pod terminates filebeat immediately stops reading log entries which can result in log lines at the end of the logs not…

---

## [OpenTelemetry metrics are not properly shown on Kibana](https://discuss.elastic.co/t/opentelemetry-metrics-are-not-properly-shown-on-kibana/325478)

<div class="topic-metadata">

**Author:** [@nicolas.orbes](https://discuss.elastic.co/u/nicolas.orbes)\
**Replies:** 2\
**Last updated:** [February 14, 2023, 2:46pm UTC](https://discuss.elastic.co/t/opentelemetry-metrics-are-not-properly-shown-on-kibana/325478 "2023-02-14T14:46:43Z")

</div>

Kibana version: 8.6.1 Elasticsearch version: 8.6.1 APM Server version: 8.6.1 OpenTelementry Java Agent: 1.22.1 Original install method (e.g. download page, yum, deb, from source, etc.) and version: We used the docke…

---

## [Logstash fetched data not available in elastic search](https://discuss.elastic.co/t/logstash-fetched-data-not-available-in-elastic-search/325216)

<div class="topic-metadata">

**Author:** [@ekambaram\_varathan](https://discuss.elastic.co/u/ekambaram_varathan)\
**Replies:** 1\
**Last updated:** [February 14, 2023, 3:26am UTC](https://discuss.elastic.co/t/logstash-fetched-data-not-available-in-elastic-search/325216 "2023-02-14T03:26:58Z")

</div>

Hi Team, I am using ELK version: 6.8.23. Though Logstash uploaded csv file data are not present in elasticsearch. my logstash conf file content as follows, input { file { path =\> "/home/data/reports/\*.csv" …

---

## [Yum is unable to update/install from elastic repo](https://discuss.elastic.co/t/yum-is-unable-to-update-install-from-elastic-repo/325221)

<div class="topic-metadata">

**Author:** [@Thomas3](https://discuss.elastic.co/u/Thomas3)\
**Replies:** 3\
**Last updated:** [February 14, 2023, 2:20pm UTC](https://discuss.elastic.co/t/yum-is-unable-to-update-install-from-elastic-repo/325221 "2023-02-14T14:20:51Z")

</div>

Hello, when trying to perform updates in RHEL8, I'm getting Failed to download metadata for repo 'logstash-7.x': Cannot download repomd.xml: Cannot download repodata/repomd.xml: All mirrors were tried with the follo…

---

## [Rule type Log threshold](https://discuss.elastic.co/t/rule-type-log-threshold/325436)

<div class="topic-metadata">

**Author:** [@maxxl](https://discuss.elastic.co/u/maxxl)\
**Replies:** 1\
**Last updated:** [February 14, 2023, 12:44pm UTC](https://discuss.elastic.co/t/rule-type-log-threshold/325436 "2023-02-14T12:44:22Z")

</div>

Kibana 8.4.3 Stack Management \\ Rules and Connectors Connectors type - Server Log Rule type - Log threshold The rule works well. How do I send the hostname and the original log (error.message) to the message?

---

## [SnapShot with select indices is still using all indices](https://discuss.elastic.co/t/snapshot-with-select-indices-is-still-using-all-indices/325437)

<div class="topic-metadata">

**Author:** [@tymercer](https://discuss.elastic.co/u/tymercer)\
**Replies:** 2\
**Last updated:** [February 14, 2023, 12:26pm UTC](https://discuss.elastic.co/t/snapshot-with-select-indices-is-still-using-all-indices/325437 "2023-02-14T12:26:00Z")

</div>

Hello, pretty new to ES and everything related to it. Just trying to do a snapshot and only selecting a set of things from 2023 and everything with .xxx in the name as part of it, tons of old data we aren't capable of d…

---

## [Parse different records in 1 document](https://discuss.elastic.co/t/parse-different-records-in-1-document/325471)

<div class="topic-metadata">

**Author:** [@Bart-d-sdlr](https://discuss.elastic.co/u/Bart-d-sdlr)\
**Replies:** 0\
**Last updated:** [February 14, 2023, 12:25pm UTC](https://discuss.elastic.co/t/parse-different-records-in-1-document/325471 "2023-02-14T12:25:52Z")

</div>

Hi, I have a (maybe stupid) question concerning parsing of custom logfile where the Date is the first record followed by the detailed lines (time,....) I don't use logstash, but filebeat and pipelines Simple example: …

---

## [500Gb text data per day - how to design elk solution](https://discuss.elastic.co/t/500gb-text-data-per-day-how-to-design-elk-solution/325432)

<div class="topic-metadata">

**Author:** [@coldcoder8502](https://discuss.elastic.co/u/coldcoder8502)\
**Replies:** 1\
**Last updated:** [February 14, 2023, 12:19pm UTC](https://discuss.elastic.co/t/500gb-text-data-per-day-how-to-design-elk-solution/325432 "2023-02-14T12:19:15Z")

</div>

I have a device which is sending 500GB text data (logs) per day to my central server. I want to design a system using which user can: Apply exact-match filters and go through data using pagination Export PDF/CSV report…

---

## [How do I retrieve statistics from two CEPH clusters using metricbeat autodiscover?](https://discuss.elastic.co/t/how-do-i-retrieve-statistics-from-two-ceph-clusters-using-metricbeat-autodiscover/325386)

<div class="topic-metadata">

**Author:** [@eeijlar](https://discuss.elastic.co/u/eeijlar)\
**Replies:** 1\
**Last updated:** [February 14, 2023, 11:54am UTC](https://discuss.elastic.co/t/how-do-i-retrieve-statistics-from-two-ceph-clusters-using-metricbeat-autodiscover/325386 "2023-02-14T11:54:15Z")

</div>

I am retrieving statistics from a CEPH cluster running in a kubernetes deployment using this values file: metricbeat: extraEnvs: - name: CEPH\_API\_USERNAME value: monitoring-ceph - name: CEPH\_API\_PASSWOR…

---

## [Remove json object from nested log](https://discuss.elastic.co/t/remove-json-object-from-nested-log/325468)

<div class="topic-metadata">

**Author:** [@Sharoze\_Meraj](https://discuss.elastic.co/u/Sharoze_Meraj)\
**Replies:** 0\
**Last updated:** [February 14, 2023, 12:03pm UTC](https://discuss.elastic.co/t/remove-json-object-from-nested-log/325468 "2023-02-14T12:03:08Z")

</div>

How can I use ruby code or some other filter plugin to detect and remove json object fields from my nested json logs. This is required because the fields can either be json objects or strings. If I remove the json objec…

---

## [Elasticsearch Master Quorum is lost](https://discuss.elastic.co/t/elasticsearch-master-quorum-is-lost/325459)

<div class="topic-metadata">

**Author:** [@tusharnemade](https://discuss.elastic.co/u/tusharnemade)\
**Replies:** 3\
**Last updated:** [February 14, 2023, 11:46am UTC](https://discuss.elastic.co/t/elasticsearch-master-quorum-is-lost/325459 "2023-02-14T11:46:57Z")

</div>

Hello : We are having Elasticsearch version 7.8.0 , running with 6 node cluster. All 6 nodes were data and master nodes. We have lost 3 Nodes out of 6 , and now we have message in logfile \[2023-02-14T10:58:47,994\]\[WA…

---

## [Retrieve data having date from 1st, Jan to current date on a date field](https://discuss.elastic.co/t/retrieve-data-having-date-from-1st-jan-to-current-date-on-a-date-field/325451)

<div class="topic-metadata">

**Author:** [@kajalp](https://discuss.elastic.co/u/kajalp)\
**Replies:** 3\
**Last updated:** [February 14, 2023, 10:24am UTC](https://discuss.elastic.co/t/retrieve-data-having-date-from-1st-jan-to-current-date-on-a-date-field/325451 "2023-02-14T10:24:20Z")

</div>

Hi All, I have data with a date field having dates from last 3 years. What I want? I want to get all the records from Jan1st to current day at any given time over a year. I tried below query: GET index\_name/\_search …

---

## [Query performance measuring tool](https://discuss.elastic.co/t/query-performance-measuring-tool/325446)

<div class="topic-metadata">

**Author:** [@siddhartha\_c](https://discuss.elastic.co/u/siddhartha_c)\
**Replies:** 2\
**Last updated:** [February 14, 2023, 10:20am UTC](https://discuss.elastic.co/t/query-performance-measuring-tool/325446 "2023-02-14T10:20:06Z")

</div>

How do I monitor the search performance for an Index, wherein data is constantly getting indexed. I want to restrict the size of the Index wherein the search performance starts degrading with new incoming data. We have…

---

## [Logstash issue](https://discuss.elastic.co/t/logstash-issue/325414)

<div class="topic-metadata">

**Author:** [@namdev](https://discuss.elastic.co/u/namdev)\
**Replies:** 1\
**Last updated:** [February 14, 2023, 10:00am UTC](https://discuss.elastic.co/t/logstash-issue/325414 "2023-02-14T10:00:44Z")

</div>

Hi , I am new to elk stack,I want to create a new field which is the difference between two dates field. I want to do it in logstash. The two dates field data is given. I am using filter like this but not getting the …

---

## [Kibana Visualize - Display count even if field not exists](https://discuss.elastic.co/t/kibana-visualize-display-count-even-if-field-not-exists/325246)

<div class="topic-metadata">

**Author:** [@Pedro\_Ventura](https://discuss.elastic.co/u/Pedro_Ventura)\
**Replies:** 3\
**Last updated:** [February 14, 2023, 9:41am UTC](https://discuss.elastic.co/t/kibana-visualize-display-count-even-if-field-not-exists/325246 "2023-02-14T09:41:02Z")

</div>

Hello! First time posting here, I've been looking around but haven't found anything to point me towards the right direction to solve my issue. I'm creating a data table which contains an aggregation by Terms for a date …

---

## [Ruby exception occurred: undefined method \`\*' for nil:NilClass](https://discuss.elastic.co/t/ruby-exception-occurred-undefined-method-for-nil-nilclass/325411)

<div class="topic-metadata">

**Author:** [@mc96](https://discuss.elastic.co/u/mc96)\
**Replies:** 2\
**Last updated:** [February 14, 2023, 9:25am UTC](https://discuss.elastic.co/t/ruby-exception-occurred-undefined-method-for-nil-nilclass/325411 "2023-02-14T09:25:03Z")

</div>

I have a filter that is as follows: event.set('\[json\]\[event\]\[packetloss1\]', event.get('\[packets-received\]') / event.get('\[packets-sent\]') \* 100) event.set('\[json\]\[event\]\[packetlosspercentage\]', 100 - event.get('\[json\]…

---

## [Elastic keeps creating indices with replica:1](https://discuss.elastic.co/t/elastic-keeps-creating-indices-with-replica-1/325390)

<div class="topic-metadata">

**Author:** [@martijnomoda](https://discuss.elastic.co/u/martijnomoda)\
**Replies:** 2\
**Last updated:** [February 14, 2023, 9:26am UTC](https://discuss.elastic.co/t/elastic-keeps-creating-indices-with-replica-1/325390 "2023-02-14T09:26:01Z")

</div>

I have an cloud Elastic cluster with 1 hot node and 1 cold node. Because of this, I limited my replica to 0 when an index has been created. I have done this trough a index template with a high prioritity (99999), with th…

---

## [What is the time complexity of query a word in lucene?](https://discuss.elastic.co/t/what-is-the-time-complexity-of-query-a-word-in-lucene/325385)

<div class="topic-metadata">

**Author:** [@dan\_kim](https://discuss.elastic.co/u/dan_kim)\
**Replies:** 7\
**Last updated:** [February 14, 2023, 9:10am UTC](https://discuss.elastic.co/t/what-is-the-time-complexity-of-query-a-word-in-lucene/325385 "2023-02-14T09:10:22Z")

</div>

Hello! please let me know what is the time complexity of query in lucene index . for example, jus simple query to a index like "localhost:9200/index1/\_search?q={searchWord}" I know it is inverted index , but i think …

---

## [Elastic Java Client Async APM Transaction](https://discuss.elastic.co/t/elastic-java-client-async-apm-transaction/322986)

<div class="topic-metadata">

**Author:** [@elastic\_rookie](https://discuss.elastic.co/u/elastic_rookie)\
**Replies:** 7\
**Last updated:** [February 14, 2023, 9:01am UTC](https://discuss.elastic.co/t/elastic-java-client-async-apm-transaction/322986 "2023-02-14T09:01:45Z")

</div>

If you are asking about a problem you are experiencing, please use the following template, as it will help us help you. If you have a different problem, please delete all of this text :slight\_smile: TIP 1: select at lea…

---

## [Canvas failed to load after upgrading kibana v7.17.1 to v8.5.2](https://discuss.elastic.co/t/canvas-failed-to-load-after-upgrading-kibana-v7-17-1-to-v8-5-2/325443)

<div class="topic-metadata">

**Author:** [@Aida](https://discuss.elastic.co/u/Aida)\
**Replies:** 0\
**Last updated:** [February 14, 2023, 7:16am UTC](https://discuss.elastic.co/t/canvas-failed-to-load-after-upgrading-kibana-v7-17-1-to-v8-5-2/325443 "2023-02-14T07:16:28Z")

</div>

Hi, i have issue where canvas failed to load after upgrading from v7.17.1 to v8.5.2. It's taking really long time to load (more than 10mins). There are few times the canvas loaded after reaching timeout, & i see this err…

---

## [Getting a 403 when trying to download a GPG key / install filebeat](https://discuss.elastic.co/t/getting-a-403-when-trying-to-download-a-gpg-key-install-filebeat/325447)

<div class="topic-metadata">

**Author:** [@BlueIceAce](https://discuss.elastic.co/u/BlueIceAce)\
**Replies:** 1\
**Last updated:** [February 14, 2023, 8:56am UTC](https://discuss.elastic.co/t/getting-a-403-when-trying-to-download-a-gpg-key-install-filebeat/325447 "2023-02-14T08:56:00Z")

</div>

Hey, guys! I get a 403 error when I try to download the GPG key, as well as when installing filebeat through apt repository. Adding a GPG key via Ansible: "msg": "Failed to download key at https://artifacts.elastic.co…

---

## [How to index a book](https://discuss.elastic.co/t/how-to-index-a-book/325448)

<div class="topic-metadata">

**Author:** [@Piyush\_Purohit](https://discuss.elastic.co/u/Piyush_Purohit)\
**Replies:** 1\
**Last updated:** [February 14, 2023, 8:54am UTC](https://discuss.elastic.co/t/how-to-index-a-book/325448 "2023-02-14T08:54:56Z")

</div>

I want to index a book, in that I want to store book\_name,page\_number and page\_content following is sample - { "book\_name": "first", "pages" : \[ { "page\_number" : 1, "page\_content" : "test data for check." }, { …

---

## [Elasticsearch and Power bi connection through ODBC driver](https://discuss.elastic.co/t/elasticsearch-and-power-bi-connection-through-odbc-driver/325405)

<div class="topic-metadata">

**Author:** [@Vitaliy.N](https://discuss.elastic.co/u/Vitaliy.N)\
**Replies:** 6\
**Last updated:** [February 14, 2023, 8:31am UTC](https://discuss.elastic.co/t/elasticsearch-and-power-bi-connection-through-odbc-driver/325405 "2023-02-14T08:31:58Z")

</div>

Hello Everyone, I am trying to connect Elasticsearch (running in docker container) with desktop power bi and having some issues. When testing connection using ODBC driver I am getting this error "libcurl: failed to per…

---

## [How to start the ELK watcher (POST \_watcher/\_start) in shell script through curl command](https://discuss.elastic.co/t/how-to-start-the-elk-watcher-post-watcher-start-in-shell-script-through-curl-command/325379)

<div class="topic-metadata">

**Author:** [@basavarajvn0513](https://discuss.elastic.co/u/basavarajvn0513)\
**Replies:** 2\
**Last updated:** [February 14, 2023, 7:36am UTC](https://discuss.elastic.co/t/how-to-start-the-elk-watcher-post-watcher-start-in-shell-script-through-curl-command/325379 "2023-02-14T07:36:31Z")

</div>

I have shell script to get the status of the elk watcher curl -k -s -X GET -H "Authorization: AAAAAA https://elastic If the status is not started I am sending the alerts . Now I also I want to start the elk watcher.…

---

## [Elasticsearch instance hangs for a while](https://discuss.elastic.co/t/elasticsearch-instance-hangs-for-a-while/325442)

<div class="topic-metadata">

**Author:** [@taghizadeh](https://discuss.elastic.co/u/taghizadeh)\
**Replies:** 0\
**Last updated:** [February 14, 2023, 6:58am UTC](https://discuss.elastic.co/t/elasticsearch-instance-hangs-for-a-while/325442 "2023-02-14T06:58:13Z")

</div>

I have an instance of elasticsearch (v8.6.1) with single node configuration. The hardware spec is: RAM: 32GB Storage: 1TB NVME-M2 CPU: 20 core Currently less than 30% of storage is used and swap is off. The problem…

---

## [Improve filtering with control fields](https://discuss.elastic.co/t/improve-filtering-with-control-fields/325397)

<div class="topic-metadata">

**Author:** [@moep](https://discuss.elastic.co/u/moep)\
**Replies:** 0\
**Last updated:** [February 13, 2023, 2:40pm UTC](https://discuss.elastic.co/t/improve-filtering-with-control-fields/325397 "2023-02-13T14:40:27Z")

</div>

Hello Community, I'm working of a kind of project to visulaze the mail flow. (see also here: Issue in Controls - #19 by moep ). The main problem is, that my content is not in the same line for example a mail flow looks …

---

## [Installation Guide](https://discuss.elastic.co/t/installation-guide/325434)

<div class="topic-metadata">

**Author:** [@ELK\_USR1](https://discuss.elastic.co/u/ELK_USR1)\
**Replies:** 3\
**Last updated:** [February 14, 2023, 6:47am UTC](https://discuss.elastic.co/t/installation-guide/325434 "2023-02-14T06:47:48Z")

</div>

Hi, Can Somebody gives me the steps to install the ELK stack on Linux node through package installation.

---

## [Request contains unrecognized parameters for Search API](https://discuss.elastic.co/t/request-contains-unrecognized-parameters-for-search-api/325139)

<div class="topic-metadata">

**Author:** [@Abhilash\_Kumar](https://discuss.elastic.co/u/Abhilash_Kumar)\
**Replies:** 8\
**Last updated:** [February 14, 2023, 6:08am UTC](https://discuss.elastic.co/t/request-contains-unrecognized-parameters-for-search-api/325139 "2023-02-14T06:08:17Z")

</div>

Hi folks, In our project, when we are trying to query ES Search API we are getting the below error { "error": { "root\_cause": \[ { "type": "illegal\_argument\_exception", …

---

## [Resetting versions](https://discuss.elastic.co/t/resetting-versions/324994)

<div class="topic-metadata">

**Author:** [@Limess](https://discuss.elastic.co/u/Limess)\
**Replies:** 1\
**Last updated:** [February 14, 2023, 5:25am UTC](https://discuss.elastic.co/t/resetting-versions/324994 "2023-02-14T05:25:34Z")

</div>

Hello, I've seen a few posts on this in the past but was wondering if there's any newer solution: We have had issues in production where we indexed documents with an external, then had to restore older versions of the …

[Previous page](https://discuss.elastic.co/latest.md?page=782)

[Next page](https://discuss.elastic.co/latest.md?page=784)
