# Elastic Stack

**URL:** https://discuss.elastic.co/c/elastic-stack/81.md?page=405

[Latest](https://discuss.elastic.co/latest.md) · [Categories](https://discuss.elastic.co/categories.md) · [Tags](https://discuss.elastic.co/tags.md)

**Page:** 406

---

## [Difference between number of fortigate firewall logs on Logstash and Elastic-agent managed by fleet](https://discuss.elastic.co/t/difference-between-number-of-fortigate-firewall-logs-on-logstash-and-elastic-agent-managed-by-fleet/344502)

<div class="topic-metadata">

**Author:** [@mrz](https://discuss.elastic.co/u/mrz)\
**Replies:** 4\
**Last updated:** [October 6, 2023, 4:00pm UTC](https://discuss.elastic.co/t/difference-between-number-of-fortigate-firewall-logs-on-logstash-and-elastic-agent-managed-by-fleet/344502 "2023-10-06T16:00:46Z")

</div>

Hi there, we have a cluster of Elasticsearch and have shipped firewall (FortiGate) logs to Logstash, everything is going well and we have a huge number of logs about 3.5M logs in 15 minutes, recently we decided to upgra…

---

## [Collect all Prometheus Metrics 8.7 integration, also looking to target live\_msgs](https://discuss.elastic.co/t/collect-all-prometheus-metrics-8-7-integration-also-looking-to-target-live-msgs/344536)

<div class="topic-metadata">

**Author:** [@Ryan\_Downey](https://discuss.elastic.co/u/Ryan_Downey)\
**Replies:** 0\
**Last updated:** [October 6, 2023, 3:25pm UTC](https://discuss.elastic.co/t/collect-all-prometheus-metrics-8-7-integration-also-looking-to-target-live-msgs/344536 "2023-10-06T15:25:26Z")

</div>

Team, I'm having trouble understanding how to collect all of the Prometheus metrics available. We currently have Elastic Agent (EA) working and connected to the Prometheus server but its not pulling any data for one of…

---

## [Time\_zone in Lucence query](https://discuss.elastic.co/t/time-zone-in-lucence-query/344534)

<div class="topic-metadata">

**Author:** [@Michael7](https://discuss.elastic.co/u/Michael7)\
**Replies:** 0\
**Last updated:** [October 6, 2023, 2:17pm UTC](https://discuss.elastic.co/t/time-zone-in-lucence-query/344534 "2023-10-06T14:17:34Z")

</div>

Hi, Im trying to realize how to specify time\_zone in URI query for elastic. ...&q=Mobile AND delivered\_at:\["now-30d" TO "now"\] How I can add time\_zone +03:00 to delivered\_at field?

---

## [Does elastic cloud provide any specific IP address for the deployment?](https://discuss.elastic.co/t/does-elastic-cloud-provide-any-specific-ip-address-for-the-deployment/344447)

<div class="topic-metadata">

**Author:** [@surya\_dadi\_dhamarake](https://discuss.elastic.co/u/surya_dadi_dhamarake)\
**Replies:** 2\
**Last updated:** [October 6, 2023, 2:10pm UTC](https://discuss.elastic.co/t/does-elastic-cloud-provide-any-specific-ip-address-for-the-deployment/344447 "2023-10-06T14:10:33Z")

</div>

Hi Team, Does elastic cloud provide any specific IPs for the deployment that we create? If we have to whitelist the traffic into our office network we might need specific Ip address to configure. If elastic cloud is not…

---

## [Auth0 integration issues](https://discuss.elastic.co/t/auth0-integration-issues/344392)

<div class="topic-metadata">

**Author:** [@Srinivasan\_Rajagopal](https://discuss.elastic.co/u/Srinivasan_Rajagopal)\
**Replies:** 2\
**Last updated:** [October 6, 2023, 1:13pm UTC](https://discuss.elastic.co/t/auth0-integration-issues/344392 "2023-10-06T13:13:37Z")

</div>

Hey , I am working with a client who is interested in using ELK as log solution and asked to do POC on integration feasibility between Auth0 & Elastic. I have signed up for a elastic cloud trial tenant. I am following t…

---

## [ELS 8 Java Client performance issue](https://discuss.elastic.co/t/els-8-java-client-performance-issue/344465)

<div class="topic-metadata">

**Author:** [@paulkeogh](https://discuss.elastic.co/u/paulkeogh)\
**Replies:** 0\
**Last updated:** [October 5, 2023, 9:42am UTC](https://discuss.elastic.co/t/els-8-java-client-performance-issue/344465 "2023-10-05T09:42:50Z")

</div>

We have replaced the ELS 7 REST client with the ELS 8 Java client in our application and our soak/performance tests are showing a slight performance degradation. Is this expected ? I had thought the Java client would be…

---

## [Change Log format](https://discuss.elastic.co/t/change-log-format/344476)

<div class="topic-metadata">

**Author:** [@Suleman\_Ahmed](https://discuss.elastic.co/u/Suleman_Ahmed)\
**Replies:** 1\
**Last updated:** [October 6, 2023, 12:35pm UTC](https://discuss.elastic.co/t/change-log-format/344476 "2023-10-06T12:35:17Z")

</div>

Hello! I want to change format of below mentioned log. I am new to Elk any help will be much appreciated. Thanks \[Mon Oct 02 13:14:00.967345 2023\] \[security2:error\] \[pid 186:tid 140439170467520\] \[client 192.168.76.181:…

---

## [Upload CSV File to Kibana Dashboard](https://discuss.elastic.co/t/upload-csv-file-to-kibana-dashboard/342821)

<div class="topic-metadata">

**Author:** [@Debasis\_Mallick](https://discuss.elastic.co/u/Debasis_Mallick)\
**Replies:** 25\
**Last updated:** [October 6, 2023, 10:53am UTC](https://discuss.elastic.co/t/upload-csv-file-to-kibana-dashboard/342821 "2023-10-06T10:53:19Z")

</div>

Hi Team, I need help on below two points while uploading csv file through kibana dashboard. How to upload a csv file size of more than 100MB through the kibana dashboard. How to upload multiple csv files to same indic…

---

## [Deserialising Avro data in losgstash](https://discuss.elastic.co/t/deserialising-avro-data-in-losgstash/344531)

<div class="topic-metadata">

**Author:** [@DivyaDileep](https://discuss.elastic.co/u/DivyaDileep)\
**Replies:** 0\
**Last updated:** [October 6, 2023, 10:22am UTC](https://discuss.elastic.co/t/deserialising-avro-data-in-losgstash/344531 "2023-10-06T10:22:07Z")

</div>

Continuing the discussion from Unable to Parse AVRO using Kafka Input and Avro Codec:

---

## [Elasticsearch License](https://discuss.elastic.co/t/elasticsearch-license/344471)

<div class="topic-metadata">

**Author:** [@Debasis\_Mallick](https://discuss.elastic.co/u/Debasis_Mallick)\
**Replies:** 7\
**Last updated:** [October 6, 2023, 10:10am UTC](https://discuss.elastic.co/t/elasticsearch-license/344471 "2023-10-06T10:10:36Z")

</div>

Hi Team, Could you please help me to understand the licensing part of Elasticsearch. Because I had installed Elasticsearch from below link and now while using Kibana dashboard today it is showing License related error.…

---

## [It's possible to encrypt Snapshots or ElasticSearch Snapshot repository?](https://discuss.elastic.co/t/its-possible-to-encrypt-snapshots-or-elasticsearch-snapshot-repository/344524)

<div class="topic-metadata">

**Author:** [@Alberto\_Roca](https://discuss.elastic.co/u/Alberto_Roca)\
**Replies:** 0\
**Last updated:** [October 6, 2023, 7:37am UTC](https://discuss.elastic.co/t/its-possible-to-encrypt-snapshots-or-elasticsearch-snapshot-repository/344524 "2023-10-06T07:37:05Z")

</div>

Currently the structure I have is made up of a cluster with Elasticsearch nodes, which take snapshots and are saved in their corresponding repository. This data is later sent to an already encrypted Ceph bucket. Is there…

---

## [Filebeat 7.17.6 does not overwrite agent.type and agent.version if they are already present](https://discuss.elastic.co/t/filebeat-7-17-6-does-not-overwrite-agent-type-and-agent-version-if-they-are-already-present/344521)

<div class="topic-metadata">

**Author:** [@andreycha](https://discuss.elastic.co/u/andreycha)\
**Replies:** 0\
**Last updated:** [October 6, 2023, 7:18am UTC](https://discuss.elastic.co/t/filebeat-7-17-6-does-not-overwrite-agent-type-and-agent-version-if-they-are-already-present/344521 "2023-10-06T07:18:02Z")

</div>

Hi. We're writing application logs to the files using Elastic.CommonSchema.Serilog package and then ship them with Filebeat to Elastic. Here is how agent field looks like in log files: "agent": { "type": "Elastic.Co…

---

## [Throughput tweaks for Elastic Agent Integrations? Agent integration not able to keep up with volume of events within an Eventhub](https://discuss.elastic.co/t/throughput-tweaks-for-elastic-agent-integrations-agent-integration-not-able-to-keep-up-with-volume-of-events-within-an-eventhub/344515)

<div class="topic-metadata">

**Author:** [@elasticnub](https://discuss.elastic.co/u/elasticnub)\
**Replies:** 0\
**Last updated:** [October 6, 2023, 3:17am UTC](https://discuss.elastic.co/t/throughput-tweaks-for-elastic-agent-integrations-agent-integration-not-able-to-keep-up-with-volume-of-events-within-an-eventhub/344515 "2023-10-06T03:17:32Z")

</div>

We are having issues with the agent being able to support roughly ~80GB a day of M365 event data ingestion being pulled from an EventHub. The aggregation server is by no means pegged on any resources so I am trying to fi…

---

## [Kibana: Getting "missing authentication credentials for REST request" after creating plugin](https://discuss.elastic.co/t/kibana-getting-missing-authentication-credentials-for-rest-request-after-creating-plugin/344514)

<div class="topic-metadata">

**Author:** [@Akshay\_Kumar\_Gupta](https://discuss.elastic.co/u/Akshay_Kumar_Gupta)\
**Replies:** 0\
**Last updated:** [October 6, 2023, 2:55am UTC](https://discuss.elastic.co/t/kibana-getting-missing-authentication-credentials-for-rest-request-after-creating-plugin/344514 "2023-10-06T02:55:26Z")

</div>

Hi, I am trying to create a new kibana plugin. whenever I create a new plugin using node scripts/generate\_plugin new\_pl command and start the kibana using yarn start --oss then I get the below error on browser. { "statu…

---

## [Filebeat logging MSSQL ERROR log, but not able to search on Message field in Kibana](https://discuss.elastic.co/t/filebeat-logging-mssql-error-log-but-not-able-to-search-on-message-field-in-kibana/344428)

<div class="topic-metadata">

**Author:** [@dbaddorf](https://discuss.elastic.co/u/dbaddorf)\
**Replies:** 1\
**Last updated:** [October 5, 2023, 10:26pm UTC](https://discuss.elastic.co/t/filebeat-logging-mssql-error-log-but-not-able-to-search-on-message-field-in-kibana/344428 "2023-10-05T22:26:19Z")

</div>

I have Filebeat using the MSSQL module running on a Windows SQL Server exporting logs to an Elasticsearch server. I can view the Filebeat logs in Kibana. But I can't (seem) to search on the Message field. For example,…

---

## [Migration from OpenSearch1.1 to Elasticsearch7.18 using logstash](https://discuss.elastic.co/t/migration-from-opensearch1-1-to-elasticsearch7-18-using-logstash/343535)

<div class="topic-metadata">

**Author:** [@gaurav\_jain](https://discuss.elastic.co/u/gaurav_jain)\
**Replies:** 12\
**Last updated:** [October 5, 2023, 9:19pm UTC](https://discuss.elastic.co/t/migration-from-opensearch1-1-to-elasticsearch7-18-using-logstash/343535 "2023-10-05T21:19:25Z")

</div>

Hi Experts, I am trying to migrate my Opensearch cluster version 1.1 to elastic cloud 7.18. I have created a logstash pipeline for the same who's configuration looks like this : input { opensearch { hosts …

---

## [How to display node hostname in Kibana stack monitoring?](https://discuss.elastic.co/t/how-to-display-node-hostname-in-kibana-stack-monitoring/344504)

<div class="topic-metadata">

**Author:** [@Jignesh\_Soni](https://discuss.elastic.co/u/Jignesh_Soni)\
**Replies:** 1\
**Last updated:** [October 5, 2023, 8:10pm UTC](https://discuss.elastic.co/t/how-to-display-node-hostname-in-kibana-stack-monitoring/344504 "2023-10-05T20:10:03Z")

</div>

Hi All, Hostname is set in Elasticsearch and Kibana configurations , but still Kibana stack monitoring is showing only IP address of nodes. Is there any way to show host name also of nodes in stack monitoring in Kibana…

---

## [@Timestamp is not matching event timestamp \_dateparsefailure](https://discuss.elastic.co/t/timestamp-is-not-matching-event-timestamp-dateparsefailure/344506)

<div class="topic-metadata">

**Author:** [@Cara410](https://discuss.elastic.co/u/Cara410)\
**Replies:** 2\
**Last updated:** [October 5, 2023, 8:01pm UTC](https://discuss.elastic.co/t/timestamp-is-not-matching-event-timestamp-dateparsefailure/344506 "2023-10-05T20:01:48Z")

</div>

Hello All, I am having filebeat send data through logstash and I have been unable to get the @timestamp to match the event time. I get a \_dateparsefailure tag in Kibana. Everything else is ingesting as intended. I have …

---

## [Using Elasticsearch Completion Suggester for large text search](https://discuss.elastic.co/t/using-elasticsearch-completion-suggester-for-large-text-search/344507)

<div class="topic-metadata">

**Author:** [@TomTom](https://discuss.elastic.co/u/TomTom)\
**Replies:** 0\
**Last updated:** [October 5, 2023, 7:55pm UTC](https://discuss.elastic.co/t/using-elasticsearch-completion-suggester-for-large-text-search/344507 "2023-10-05T19:55:52Z")

</div>

Is it possible to use the Completion Suggester feature for Elasticsearch to find content as text is typed, similar to Elasticsearch's Discuss? For example, I have articles in my knowledge base that have a title and cont…

---

## [Query an Elasticsearch index for one field, all documents in last 24 hours?](https://discuss.elastic.co/t/query-an-elasticsearch-index-for-one-field-all-documents-in-last-24-hours/344493)

<div class="topic-metadata">

**Author:** [@Meme-ento](https://discuss.elastic.co/u/Meme-ento)\
**Replies:** 1\
**Last updated:** [October 5, 2023, 7:40pm UTC](https://discuss.elastic.co/t/query-an-elasticsearch-index-for-one-field-all-documents-in-last-24-hours/344493 "2023-10-05T19:40:16Z")

</div>

Hi There. I'm trying to make a simple get request to my elk index. I have the right credentials, hostname, index name, etc. my ELK version is 6.8.6 But for what I'm trying to get I cannot figure out how to construct …

---

## [Elastic Common Schema support for Opensearch](https://discuss.elastic.co/t/elastic-common-schema-support-for-opensearch/344452)

<div class="topic-metadata">

**Author:** [@q3uxlyn](https://discuss.elastic.co/u/q3uxlyn)\
**Replies:** 3\
**Last updated:** [October 5, 2023, 7:22pm UTC](https://discuss.elastic.co/t/elastic-common-schema-support-for-opensearch/344452 "2023-10-05T19:22:19Z")

</div>

Hello! Have you plans about adding OpenSearch support to Elastic Common Schema? Cause of OpenSearch has different field types than Elasticsearch we can't easily use ECS. I want to be able to keep the schemas up to date…

---

## [Run time fields in Kibana VIsualizations](https://discuss.elastic.co/t/run-time-fields-in-kibana-visualizations/343567)

<div class="topic-metadata">

**Author:** [@JeremyP](https://discuss.elastic.co/u/JeremyP)\
**Replies:** 9\
**Last updated:** [October 5, 2023, 3:43pm UTC](https://discuss.elastic.co/t/run-time-fields-in-kibana-visualizations/343567 "2023-10-05T15:43:35Z")

</div>

Hello, I have a couple of run time fields defined in the index mappings which calculates the difference between two time stamps in days. It works fine, and I can see the data in Kibana discover. However, if I attempt t…

---

## [ABAC / Custom Realm / Extend JWT authentication](https://discuss.elastic.co/t/abac-custom-realm-extend-jwt-authentication/344500)

<div class="topic-metadata">

**Author:** [@SvenHa](https://discuss.elastic.co/u/SvenHa)\
**Replies:** 0\
**Last updated:** [October 5, 2023, 3:36pm UTC](https://discuss.elastic.co/t/abac-custom-realm-extend-jwt-authentication/344500 "2023-10-05T15:36:34Z")

</div>

Hello, Currently, I'm trying to evaluate the best solution for a customer project. Some facts about the project environment: User authentication with OIDC/JWT is available. It is not possible to extend the JWT with c…

---

## [Kibana error: security\_exception: \[security\_exception\] Reason: unable to authenticate with provided credentials and anonymous access is not allowed for this request](https://discuss.elastic.co/t/kibana-error-security-exception-security-exception-reason-unable-to-authenticate-with-provided-credentials-and-anonymous-access-is-not-allowed-for-this-request/344243)

<div class="topic-metadata">

**Author:** [@PodarcisMuralis](https://discuss.elastic.co/u/PodarcisMuralis)\
**Replies:** 1\
**Last updated:** [October 5, 2023, 3:26pm UTC](https://discuss.elastic.co/t/kibana-error-security-exception-security-exception-reason-unable-to-authenticate-with-provided-credentials-and-anonymous-access-is-not-allowed-for-this-request/344243 "2023-10-05T15:26:00Z")

</div>

Hi. I upgraded the Kibana from 7.17 to 8.5.3 and got some corrupt indices. then I used these instructions and deleted .kibana and . monitoring indices. Resolve Migration Failures But I also deleted .security\_7. This …

---

## [Logstash Metrics unavailable on Kibana Stack Monitoring UI](https://discuss.elastic.co/t/logstash-metrics-unavailable-on-kibana-stack-monitoring-ui/343328)

<div class="topic-metadata">

**Author:** [@gsekar](https://discuss.elastic.co/u/gsekar)\
**Replies:** 8\
**Last updated:** [October 5, 2023, 3:01pm UTC](https://discuss.elastic.co/t/logstash-metrics-unavailable-on-kibana-stack-monitoring-ui/343328 "2023-10-05T15:01:56Z")

</div>

Hi all Have installed metricbeat to monitor Logstash Nodes. The data stream - .monitoring-logstash-8-mb does get created and am seeing the data in the discover tab. But in the Stack Monitoring page for some reason the d…

---

## [Kibana Error - Error while updating search session x: Saved object x conflict](https://discuss.elastic.co/t/kibana-error-error-while-updating-search-session-x-saved-object-x-conflict/343783)

<div class="topic-metadata">

**Author:** [@PodarcisMuralis](https://discuss.elastic.co/u/PodarcisMuralis)\
**Replies:** 1\
**Last updated:** [October 5, 2023, 2:56pm UTC](https://discuss.elastic.co/t/kibana-error-error-while-updating-search-session-x-saved-object-x-conflict/343783 "2023-10-05T14:56:31Z")

</div>

Hello. I am using Kibana 8.5.3 and getting this error continuously. Error while updating search session b4100d1f-dfea-4ba9-8873-070219cbfe5f: Saved object \[search-session/b4100d1f-dfea-4ba9-8873-070219cbfe5f\] conflict…

---

## [Kibana fleet error - Failed to fetch latest version of synthetics from registry: Error connecting to package registry: request to URL failed, reason: connect ENETUNREACH xx.xxx.xxx.xxx:xxx - Local (0.0.0.0:0)](https://discuss.elastic.co/t/kibana-fleet-error-failed-to-fetch-latest-version-of-synthetics-from-registry-error-connecting-to-package-registry-request-to-url-failed-reason-connect-enetunreach-xx-xxx-xxx-xxx-xxx-local-0-0-0-0-0/344498)

<div class="topic-metadata">

**Author:** [@PodarcisMuralis](https://discuss.elastic.co/u/PodarcisMuralis)\
**Replies:** 0\
**Last updated:** [October 5, 2023, 2:43pm UTC](https://discuss.elastic.co/t/kibana-fleet-error-failed-to-fetch-latest-version-of-synthetics-from-registry-error-connecting-to-package-registry-request-to-url-failed-reason-connect-enetunreach-xx-xxx-xxx-xxx-xxx-local-0-0-0-0-0/344498 "2023-10-05T14:43:55Z")

</div>

Hi. I am using Kibana 8.5.3 and everytime I start Kibana with "sudo systemctl start kibana" or restart, I get this error once. Failed to fetch latest version of synthetics from registry: Error connecting to package reg…

---

## [bulkIndex() or saveAll()?](https://discuss.elastic.co/t/bulkindex-or-saveall/344487)

<div class="topic-metadata">

**Author:** [@Cemre\_Senyuva](https://discuss.elastic.co/u/Cemre_Senyuva)\
**Replies:** 0\
**Last updated:** [October 5, 2023, 1:24pm UTC](https://discuss.elastic.co/t/bulkindex-or-saveall/344487 "2023-10-05T13:24:19Z")

</div>

Which one is faster method to save/index in elasticsearch bulkIndex() or saveAll()?

---

## [Elasticsearch SCCM Windows deployment](https://discuss.elastic.co/t/elasticsearch-sccm-windows-deployment/344497)

<div class="topic-metadata">

**Author:** [@Waldfried](https://discuss.elastic.co/u/Waldfried)\
**Replies:** 0\
**Last updated:** [October 5, 2023, 2:24pm UTC](https://discuss.elastic.co/t/elasticsearch-sccm-windows-deployment/344497 "2023-10-05T14:24:20Z")

</div>

Hi everyone, i'm having problems deploying Elasticsearch via SCCM. During execution the setup tries to create a symlink which is working as long as i install it with a administrative user account. As soon as the setup …

---

## [Kibana errors after changing encryptionKey - Failed to decrypt "apiKey" attribute: Unsupported state or unable to authenticate data](https://discuss.elastic.co/t/kibana-errors-after-changing-encryptionkey-failed-to-decrypt-apikey-attribute-unsupported-state-or-unable-to-authenticate-data/344492)

<div class="topic-metadata">

**Author:** [@PodarcisMuralis](https://discuss.elastic.co/u/PodarcisMuralis)\
**Replies:** 1\
**Last updated:** [October 5, 2023, 2:21pm UTC](https://discuss.elastic.co/t/kibana-errors-after-changing-encryptionkey-failed-to-decrypt-apikey-attribute-unsupported-state-or-unable-to-authenticate-data/344492 "2023-10-05T14:21:07Z")

</div>

I use elasticstack 8.5.3 and have 2 Logstash, 5 ELS and 1 Kibana nodes. I was cleaning the older kibana system indices ( upgraded from 7.17.7) and deleted .security\_7 index also and had to create all built in users agai…

[Previous page](https://discuss.elastic.co/c/elastic-stack/81.md?page=404)

[Next page](https://discuss.elastic.co/c/elastic-stack/81.md?page=406)
