# \#none

**URL:** https://discuss.elastic.co/tag/none.md?no_tags=true&page=509

[Latest](https://discuss.elastic.co/latest.md) · [Categories](https://discuss.elastic.co/categories.md) · [Tags](https://discuss.elastic.co/tags.md)

**Page:** 510

---

## [Elastic Observability On-Demand: APM RUM agent seems to have wrong version](https://discuss.elastic.co/t/elastic-observability-on-demand-apm-rum-agent-seems-to-have-wrong-version/317419)

<div class="topic-metadata">

**Author:** [@jan.stap](https://discuss.elastic.co/u/jan.stap)\
**Replies:** 15\
**Last updated:** [October 28, 2022, 12:39pm UTC](https://discuss.elastic.co/t/elastic-observability-on-demand-apm-rum-agent-seems-to-have-wrong-version/317419 "2022-10-28T12:39:06Z")

</div>

Hi, Lab 3.4 instructs to install version 4.9.0 of the APM RUM agent by running: npm install @elastic/apm-rum@4.9.0 --save After doing this and then applying the agent configuration as instructed in the lab I do receiv…

---

## [Elastic Agent Fleet Setup unauthorized](https://discuss.elastic.co/t/elastic-agent-fleet-setup-unauthorized/317406)

<div class="topic-metadata">

**Author:** [@legoguy1000](https://discuss.elastic.co/u/legoguy1000)\
**Replies:** 1\
**Last updated:** [October 26, 2022, 7:21pm UTC](https://discuss.elastic.co/t/elastic-agent-fleet-setup-unauthorized/317406 "2022-10-26T19:21:33Z")

</div>

When trying to deploy a fleet server via ECK, sometimes the pod is never created. The logs from the operator shows {"log.level":"error","@timestamp":"2022-10-25T11:42:57.936Z","log.logger":"manager.eck-operator","messa…

---

## [Have Months displayed in chronological order](https://discuss.elastic.co/t/have-months-displayed-in-chronological-order/317346)

<div class="topic-metadata">

**Author:** [@wido](https://discuss.elastic.co/u/wido)\
**Replies:** 7\
**Last updated:** [October 28, 2022, 11:59am UTC](https://discuss.elastic.co/t/have-months-displayed-in-chronological-order/317346 "2022-10-28T11:59:02Z")

</div>

Hi there! We are indexing data in ES to create dashboards using Kibana. There is a field named Month that contains the names of the months indexed as strings to both text and keyword data types. Each month is represent…

---

## [Create a pattern\_index kibana 7.6.2 api](https://discuss.elastic.co/t/create-a-pattern-index-kibana-7-6-2-api/317619)

<div class="topic-metadata">

**Author:** [@kimo1](https://discuss.elastic.co/u/kimo1)\
**Replies:** 2\
**Last updated:** [October 28, 2022, 7:43am UTC](https://discuss.elastic.co/t/create-a-pattern-index-kibana-7-6-2-api/317619 "2022-10-28T07:43:53Z")

</div>

I have created a dashboard in kibana for monitoring, and I want to create an index\_pattern already exist in elasticsearch with name (idx-traces). I did the following request curl: curl -X POST host:port/api/index\_patte…

---

## [Prepended Term Search is Faster than Term Search for Nested Field](https://discuss.elastic.co/t/prepended-term-search-is-faster-than-term-search-for-nested-field/317567)

<div class="topic-metadata">

**Author:** [@aschattopadhyay](https://discuss.elastic.co/u/aschattopadhyay)\
**Replies:** 2\
**Last updated:** [October 28, 2022, 6:11am UTC](https://discuss.elastic.co/t/prepended-term-search-is-faster-than-term-search-for-nested-field/317567 "2022-10-28T06:11:23Z")

</div>

Hi there: I am very new to Elasticsearch implementation and luckily I got this forum. Just wondering if I can get some help please regarding a scenario that we are facing for our Elasticsearch instance. We have got lik…

---

## [Customized sort in ElasticSearch](https://discuss.elastic.co/t/customized-sort-in-elasticsearch/317198)

<div class="topic-metadata">

**Author:** [@Apurba](https://discuss.elastic.co/u/Apurba)\
**Replies:** 5\
**Last updated:** [October 28, 2022, 5:02am UTC](https://discuss.elastic.co/t/customized-sort-in-elasticsearch/317198 "2022-10-28T05:02:57Z")

</div>

Can I use custom sort in ES? Like, in my ES data, one field values are -\> "A", "A", "B", "B", "C", "C", "C", "D" Can I sort this like -\> "D", "B", "B", "C", "C", "C", "A", "A" If we can sort like this, how the query s…

---

## [Why is .doc() missing in UpdateOperation?](https://discuss.elastic.co/t/why-is-doc-missing-in-updateoperation/317587)

<div class="topic-metadata">

**Author:** [@Michael\_Gattinger](https://discuss.elastic.co/u/Michael_Gattinger)\
**Replies:** 1\
**Last updated:** [October 28, 2022, 4:15am UTC](https://discuss.elastic.co/t/why-is-doc-missing-in-updateoperation/317587 "2022-10-28T04:15:25Z")

</div>

Hi, as an junior Java developer try to understand the things by using the "easy way". I actually don't understand what requirements like this mean and can't write code from the scratch with that information: update(Fun…

---

## [java.lang.IllegalArgumentException: Class class co.elastic.clients.elasticsearch.core.bulk.UpdateOperation cannot be read from JSON](https://discuss.elastic.co/t/java-lang-illegalargumentexception-class-class-co-elastic-clients-elasticsearch-core-bulk-updateoperation-cannot-be-read-from-json/317609)

<div class="topic-metadata">

**Author:** [@Michael\_Gattinger](https://discuss.elastic.co/u/Michael_Gattinger)\
**Replies:** 1\
**Last updated:** [October 28, 2022, 4:14am UTC](https://discuss.elastic.co/t/java-lang-illegalargumentexception-class-class-co-elastic-clients-elasticsearch-core-bulk-updateoperation-cannot-be-read-from-json/317609 "2022-10-28T04:14:44Z")

</div>

BulkRequest.Builder brb = new BulkRequest.Builder().index("foo"); //first try Rechnung r6 = new Rechnung(); r6.Rechnungsbetrag = 49.99f; ObjectMapper mapper = new ObjectMapper(); String myjson = mapper.writeValueAsString…

---

## ["Race condition" in Java](https://discuss.elastic.co/t/race-condition-in-java/317615)

<div class="topic-metadata">

**Author:** [@Michael\_Gattinger](https://discuss.elastic.co/u/Michael_Gattinger)\
**Replies:** 3\
**Last updated:** [October 28, 2022, 4:09am UTC](https://discuss.elastic.co/t/race-condition-in-java/317615 "2022-10-28T04:09:15Z")

</div>

Hi, what i am experiencing right now is that a document that should be already deleted will be still listet if a search is done directly after the deletion. a) indexing the document xyz b) doing other Elastic-related …

---

## [State changed to FAILED: Missed two check-ins - type: 'ERROR' - sub\_type: 'FAILED'](https://discuss.elastic.co/t/state-changed-to-failed-missed-two-check-ins-type-error-sub-type-failed/317158)

<div class="topic-metadata">

**Author:** [@safuanmansor](https://discuss.elastic.co/u/safuanmansor)\
**Replies:** 1\
**Last updated:** [October 28, 2022, 2:43am UTC](https://discuss.elastic.co/t/state-changed-to-failed-missed-two-check-ins-type-error-sub-type-failed/317158 "2022-10-28T02:43:02Z")

</div>

Hi Elastic Team, Appreciate if you can point me the issue as my elastic-agent installed status change to unhealthy after couple of hours without any configuration change. The logs file are as per the link.

---

## [How can I convert @timestamp from logstash to encoded format as YYYY-MM-DDThh:mm:ss.sss+/-hh:mm](https://discuss.elastic.co/t/how-can-i-convert-timestamp-from-logstash-to-encoded-format-as-yyyy-mm-ddthhss-sss-hh-mm/317608)

<div class="topic-metadata">

**Author:** [@teja\_tata](https://discuss.elastic.co/u/teja_tata)\
**Replies:** 11\
**Last updated:** [October 28, 2022, 1:50am UTC](https://discuss.elastic.co/t/how-can-i-convert-timestamp-from-logstash-to-encoded-format-as-yyyy-mm-ddthhss-sss-hh-mm/317608 "2022-10-28T01:50:18Z")

</div>

I have tried using date filter match option but didn't work. It would be great if someone can help me here.

---

## [Elasticsearch: how the exact matches can rank higher than fuzzy match and phrase match in the elastic search?](https://discuss.elastic.co/t/elasticsearch-how-the-exact-matches-can-rank-higher-than-fuzzy-match-and-phrase-match-in-the-elastic-search/317653)

<div class="topic-metadata">

**Author:** [@paris1](https://discuss.elastic.co/u/paris1)\
**Replies:** 0\
**Last updated:** [October 28, 2022, 12:46am UTC](https://discuss.elastic.co/t/elasticsearch-how-the-exact-matches-can-rank-higher-than-fuzzy-match-and-phrase-match-in-the-elastic-search/317653 "2022-10-28T00:46:44Z")

</div>

0 I'm trying to configure Elasticsearch to give me both exact matches and fuzzy matches and also phrase matches.I'm using Elasticsearch to search namesof foods in a database, and I want it to be fuzzy to allow for minor…

---

## [Hanging shutdown with multiple pipelines. Shutdown of pipelines in wrong order](https://discuss.elastic.co/t/hanging-shutdown-with-multiple-pipelines-shutdown-of-pipelines-in-wrong-order/316354)

<div class="topic-metadata">

**Author:** [@asp](https://discuss.elastic.co/u/asp)\
**Replies:** 2\
**Last updated:** [October 12, 2022, 7:17am UTC](https://discuss.elastic.co/t/hanging-shutdown-with-multiple-pipelines-shutdown-of-pipelines-in-wrong-order/316354 "2022-10-12T07:17:29Z")

</div>

Hi, I have a logstash config with multiple pipelines. One of the pipeline is a central output which ships to elasticsearch. The other pipelines have their own inputs and filters and having that central output pipeline a…

---

## [Logstash : How to extract a nested field from Json log and only index the content of the nested field](https://discuss.elastic.co/t/logstash-how-to-extract-a-nested-field-from-json-log-and-only-index-the-content-of-the-nested-field/317617)

<div class="topic-metadata">

**Author:** [@Ranjith\_kk](https://discuss.elastic.co/u/Ranjith_kk)\
**Replies:** 5\
**Last updated:** [October 27, 2022, 6:38pm UTC](https://discuss.elastic.co/t/logstash-how-to-extract-a-nested-field-from-json-log-and-only-index-the-content-of-the-nested-field/317617 "2022-10-27T18:38:57Z")

</div>

We have some logs in JSON format with a nested field called "data". We are looking for an option to extract only the content of this nested field and send it for indexing with ES. Actual log format: {"field1":"value1",…

---

## [What is APM Latency Threshold Alert?](https://discuss.elastic.co/t/what-is-apm-latency-threshold-alert/317627)

<div class="topic-metadata">

**Author:** [@learningelastic](https://discuss.elastic.co/u/learningelastic)\
**Replies:** 5\
**Last updated:** [October 27, 2022, 4:38pm UTC](https://discuss.elastic.co/t/what-is-apm-latency-threshold-alert/317627 "2022-10-27T16:38:20Z")

</div>

I'm trying to learn what the Latency Threshold Alert is as shown in this picture for Kibana 8.4 But the rule above never seems to fire at all, even though my node-app-1 service averages latency of 10 seconds, which i…

---

## [Issue creating index with alert](https://discuss.elastic.co/t/issue-creating-index-with-alert/317604)

<div class="topic-metadata">

**Author:** [@Florian-LB](https://discuss.elastic.co/u/Florian-LB)\
**Replies:** 2\
**Last updated:** [October 27, 2022, 3:14pm UTC](https://discuss.elastic.co/t/issue-creating-index-with-alert/317604 "2022-10-27T15:14:30Z")

</div>

Hi, I want to setup an alert when 3 login rejections occur on the same switch in order to get this info on my dashboard. I created a threshold rule “Alerte Brute Force Cisco” that raise an alert when 3 authentications …

---

## [Rollback/Downgrade of integration possible?](https://discuss.elastic.co/t/rollback-downgrade-of-integration-possible/317624)

<div class="topic-metadata">

**Author:** [@matled](https://discuss.elastic.co/u/matled)\
**Replies:** 0\
**Last updated:** [October 27, 2022, 2:40pm UTC](https://discuss.elastic.co/t/rollback-downgrade-of-integration-possible/317624 "2022-10-27T14:40:58Z")

</div>

Hi there Is it possible to rollback/downgrade to an earlier version of an integration? We currently observed an issue with the newest System Integration that doesn't populate ECS Fields like user.name or domain.name any…

---

## [Problem with Endpoint Security Initiation](https://discuss.elastic.co/t/problem-with-endpoint-security-initiation/316419)

<div class="topic-metadata">

**Author:** [@Patryk\_Ostrowski](https://discuss.elastic.co/u/Patryk_Ostrowski)\
**Replies:** 7\
**Last updated:** [October 27, 2022, 12:50pm UTC](https://discuss.elastic.co/t/problem-with-endpoint-security-initiation/316419 "2022-10-27T12:50:35Z")

</div>

Hello, I'm trying to initialize Security Endpoint on a Linux Ubuntu 20.04.4 LTS. After that I had a 13 problems for example: "Configure File Events Failure enabling file events; current state is disabled". I tried to di…

---

## [Elasticsearch integration with Zabbix](https://discuss.elastic.co/t/elasticsearch-integration-with-zabbix/316489)

<div class="topic-metadata">

**Author:** [@Muhammad\_Umar](https://discuss.elastic.co/u/Muhammad_Umar)\
**Replies:** 0\
**Last updated:** [October 13, 2022, 6:02am UTC](https://discuss.elastic.co/t/elasticsearch-integration-with-zabbix/316489 "2022-10-13T06:02:20Z")

</div>

I tried to extract log files from Zabbix to Grafana, which came out successful. Now I want to extract the same from Grafana to Elasticsearch and view the same in Kibana. Is this possible?? If “yes” explain it briefly (o…

---

## [Dynamic Elasticsearch query execution from Node JS](https://discuss.elastic.co/t/dynamic-elasticsearch-query-execution-from-node-js/317602)

<div class="topic-metadata">

**Author:** [@pravu](https://discuss.elastic.co/u/pravu)\
**Replies:** 0\
**Last updated:** [October 27, 2022, 10:55am UTC](https://discuss.elastic.co/t/dynamic-elasticsearch-query-execution-from-node-js/317602 "2022-10-27T10:55:43Z")

</div>

I need to execute dynamic queries from Node JS . I tried the following script and getting error. async function executeDynamicTest (){ const querySrting= "{index: 'entity\_index', query: { match: { amount: '1819' }}}"; …

---

## [Remove field suggestions from Query bar](https://discuss.elastic.co/t/remove-field-suggestions-from-query-bar/317471)

<div class="topic-metadata">

**Author:** [@bandodkarD](https://discuss.elastic.co/u/bandodkarD)\
**Replies:** 5\
**Last updated:** [October 27, 2022, 8:26am UTC](https://discuss.elastic.co/t/remove-field-suggestions-from-query-bar/317471 "2022-10-27T08:26:56Z")

</div>

These field name appear by default in the Query Bar. Please advise if we can remove these fields and have a simple text search.

---

## [Grok parse failure](https://discuss.elastic.co/t/grok-parse-failure/317379)

<div class="topic-metadata">

**Author:** [@Paf](https://discuss.elastic.co/u/Paf)\
**Replies:** 2\
**Last updated:** [October 27, 2022, 7:23am UTC](https://discuss.elastic.co/t/grok-parse-failure/317379 "2022-10-27T07:23:40Z")

</div>

Hello, I want to parse the field "ModifiedProperties" with this value : {"Name":"StrongAuthenticationMethod","NewValue":"\[\\r\\n {\\r\\n \\"MethodType\\": 5,\\r\\n \\"Default\\": true\\r\\n },\\r\\n {\\r\\n \\"MethodType\\":…

---

## [Oracle cloud instances logs in elk siem](https://discuss.elastic.co/t/oracle-cloud-instances-logs-in-elk-siem/317207)

<div class="topic-metadata">

**Author:** [@Sarala\_C](https://discuss.elastic.co/u/Sarala_C)\
**Replies:** 1\
**Last updated:** [October 27, 2022, 6:50am UTC](https://discuss.elastic.co/t/oracle-cloud-instances-logs-in-elk-siem/317207 "2022-10-27T06:50:53Z")

</div>

Hello, Our requirement is to ingest oracle cloud instances logs into ELK SIEM that is hosted on azure cloud. Is this possible? if yes then please can you guide. Waiting for any solution. Thanks Sarala

---

## [ELK & APIs calls](https://discuss.elastic.co/t/elk-apis-calls/317116)

<div class="topic-metadata">

**Author:** [@noshell](https://discuss.elastic.co/u/noshell)\
**Replies:** 3\
**Last updated:** [October 27, 2022, 6:28am UTC](https://discuss.elastic.co/t/elk-apis-calls/317116 "2022-10-27T06:28:46Z")

</div>

Hello, I have a design / architecture question. In a project i wish you to implement REST APIs with custom dashboards but i want to segreagte network flows. I would like to know if i used a distributed archietcture wh…

---

## [Create a conditional mapping (enabled = false) on a single field based on field value](https://discuss.elastic.co/t/create-a-conditional-mapping-enabled-false-on-a-single-field-based-on-field-value/317572)

<div class="topic-metadata">

**Author:** [@JerryKumar](https://discuss.elastic.co/u/JerryKumar)\
**Replies:** 1\
**Last updated:** [October 27, 2022, 5:57am UTC](https://discuss.elastic.co/t/create-a-conditional-mapping-enabled-false-on-a-single-field-based-on-field-value/317572 "2022-10-27T05:57:24Z")

</div>

Hey team, I have a use case in my application where a list of items called Descriptors are generated. These are filtered for a specific prefix "descsearch" and only these are being sent to the index and everything work…

---

## [How to use XContentBuilder in Elasticsearch 8.0](https://discuss.elastic.co/t/how-to-use-xcontentbuilder-in-elasticsearch-8-0/317256)

<div class="topic-metadata">

**Author:** [@Michael\_Gattinger](https://discuss.elastic.co/u/Michael_Gattinger)\
**Replies:** 8\
**Last updated:** [October 27, 2022, 5:56am UTC](https://discuss.elastic.co/t/how-to-use-xcontentbuilder-in-elasticsearch-8-0/317256 "2022-10-27T05:56:59Z")

</div>

Hi, i found some examples how to use XContentBuilder in Elasticsearch 7.x but these examples do not work any more since ESJAC is completely new programmed. But as XContentBuilder still exists: XContentBuilder (elasticse…

---

## [Elasticsearch Multi-word synonyms and stopword issue](https://discuss.elastic.co/t/elasticsearch-multi-word-synonyms-and-stopword-issue/317585)

<div class="topic-metadata">

**Author:** [@sudheesh](https://discuss.elastic.co/u/sudheesh)\
**Replies:** 0\
**Last updated:** [October 27, 2022, 5:54am UTC](https://discuss.elastic.co/t/elasticsearch-multi-word-synonyms-and-stopword-issue/317585 "2022-10-27T05:54:33Z")

</div>

I have created an index as follows PUT /wordforms\_example { "mappings": { "dynamic": "strict", "properties": { "test\_field": { "type": "text", "analyzer": "synonym\_words\_analyzer\_…

---

## [Question about statistics delayed too long](https://discuss.elastic.co/t/question-about-statistics-delayed-too-long/317577)

<div class="topic-metadata">

**Author:** [@315386775](https://discuss.elastic.co/u/315386775)\
**Replies:** 2\
**Last updated:** [October 27, 2022, 5:54am UTC](https://discuss.elastic.co/t/question-about-statistics-delayed-too-long/317577 "2022-10-27T05:54:11Z")

</div>

i use the kibana with CVAT GitHub - opencv/cvat: Annotate better with CVAT, the industry-leading data engine for machine learning. Used and trusted by teams at any scale, for data of any scale. Question in Kibana. I ca…

---

## [What is Elastic agent?](https://discuss.elastic.co/t/what-is-elastic-agent/317087)

<div class="topic-metadata">

**Author:** [@Kosala\_Randika\_Paran](https://discuss.elastic.co/u/Kosala_Randika_Paran)\
**Replies:** 6\
**Last updated:** [October 27, 2022, 4:31am UTC](https://discuss.elastic.co/t/what-is-elastic-agent/317087 "2022-10-27T04:31:05Z")

</div>

Hi everyone, I know this is going to very basic question but I am new to ELK stack, and I have so many things to learn. I have installed ELK stack (Logstash, Elasticsearch, and Kibana), and also I have configured the f…

---

## [String inteprolation in logstash data\_stream fields](https://discuss.elastic.co/t/string-inteprolation-in-logstash-data-stream-fields/317556)

<div class="topic-metadata">

**Author:** [@Austin\_ES\_Questions](https://discuss.elastic.co/u/Austin_ES_Questions)\
**Replies:** 6\
**Last updated:** [October 26, 2022, 9:42pm UTC](https://discuss.elastic.co/t/string-inteprolation-in-logstash-data-stream-fields/317556 "2022-10-26T21:42:05Z")

</div>

How can I write to different data streams for different kinesis input? We are trying to add fields in the inputs and use string interpolation in the outputs to no avail. We had been using index+ilm\_enabled in logstash, …

[Previous page](https://discuss.elastic.co/tag/none.md?no_tags=true&page=508)

[Next page](https://discuss.elastic.co/tag/none.md?no_tags=true&page=510)
