# Latest

**URL:** https://discuss.elastic.co/latest.md

[Latest](https://discuss.elastic.co/latest.md) · [Categories](https://discuss.elastic.co/categories.md) · [Tags](https://discuss.elastic.co/tags.md)

---

## [Notes on Using These Forums](https://discuss.elastic.co/t/notes-on-using-these-forums/118)

<div class="topic-metadata">

**Author:** [@Leslie\_Hawthorn](https://discuss.elastic.co/u/Leslie_Hawthorn)\
**Replies:** 0\
**Last updated:** [May 4, 2015, 3:24pm UTC](https://discuss.elastic.co/t/notes-on-using-these-forums/118 "2015-05-04T15:24:11Z")

</div>

Welcome to Elastic's Discussion Forums! We're glad you're here. :smile: You can use these forums to ask questions about any of Elastic's products, share tips and tricks you've learned with your fellow users and keep up …

---

## [Time picker in ES|QL query - esql](https://discuss.elastic.co/t/time-picker-in-es-ql-query-esql/390631)

<div class="topic-metadata">

**Author:** [@dot-mike](https://discuss.elastic.co/u/dot-mike)\
**Replies:** 2\
**Last updated:** [September 25, 2026, 1:55pm UTC](https://discuss.elastic.co/t/time-picker-in-es-ql-query-esql/390631 "2026-09-25T13:55:30Z")

</div>

Hi community, I was wondering about a weird behaviour that might catch some people off-guard. How does the time picker affect ES|QL searches? For example the following query implies a 24-hour search, but yet the data d…

---

## [Sharing my rule update experience on Elastic Security Serverless](https://discuss.elastic.co/t/sharing-my-rule-update-experience-on-elastic-security-serverless/389853)

<div class="topic-metadata">

**Author:** [@willemdh](https://discuss.elastic.co/u/willemdh)\
**Replies:** 13\
**Last updated:** [September 25, 2026, 12:27pm UTC](https://discuss.elastic.co/t/sharing-my-rule-update-experience-on-elastic-security-serverless/389853 "2026-09-25T12:27:47Z")

</div>

Hello, Just sharing my experience updating Elastic prebuilt Security rules after being away for about 1.5 months. When I logged back in, I had roughly 1,200 rule updates waiting. That is fine in itself - I clicked Upda…

---

## [Elastic defend (Automatic Response Action Isnt Working )](https://discuss.elastic.co/t/elastic-defend-automatic-response-action-isnt-working/390597)

<div class="topic-metadata">

**Author:** [@jatin3101](https://discuss.elastic.co/u/jatin3101)\
**Replies:** 1\
**Last updated:** [September 25, 2026, 9:17am UTC](https://discuss.elastic.co/t/elastic-defend-automatic-response-action-isnt-working/390597 "2026-09-25T09:17:29Z")

</div>

Hi , i came across this problem that my response action arent working & somehad the same issue but their was solved and i dont undertsand how detection rule- firewall disabled issue- want to run a script for enablin…

---

## [Elasticsearch 8.19.22, 9.4.7, 9.5.3 Security Update (ESA-2026-184)](https://discuss.elastic.co/t/elasticsearch-8-19-22-9-4-7-9-5-3-security-update-esa-2026-184/390688)

<div class="topic-metadata">

**Author:** [@kruskall](https://discuss.elastic.co/u/kruskall)\
**Replies:** 0\
**Last updated:** [September 25, 2026, 8:35am UTC](https://discuss.elastic.co/t/elasticsearch-8-19-22-9-4-7-9-5-3-security-update-esa-2026-184/390688 "2026-09-25T08:35:53Z")

</div>

Uncontrolled Resource Consumption in Elasticsearch Leading to denial of service Uncontrolled Resource Consumption (CWE-400) in Elasticsearch can lead denial of service via Excessive Allocation (CAPEC-130) Affected Vers…

---

## [Elasticsearch 8.19.22, 9.4.7, 9.5.4 Security Update (ESA-2026-183)](https://discuss.elastic.co/t/elasticsearch-8-19-22-9-4-7-9-5-4-security-update-esa-2026-183/390687)

<div class="topic-metadata">

**Author:** [@kruskall](https://discuss.elastic.co/u/kruskall)\
**Replies:** 0\
**Last updated:** [September 25, 2026, 8:35am UTC](https://discuss.elastic.co/t/elasticsearch-8-19-22-9-4-7-9-5-4-security-update-esa-2026-183/390687 "2026-09-25T08:35:28Z")

</div>

Uncontrolled Resource Consumption in Elasticsearch Leading to denial of service Uncontrolled Resource Consumption (CWE-400) in Elasticsearch can lead denial of service via Excessive Allocation (CAPEC-130) Affected Vers…

---

## [Elasticsearch 9.4.7, 9.5.4 Security Update (ESA-2026-182)](https://discuss.elastic.co/t/elasticsearch-9-4-7-9-5-4-security-update-esa-2026-182/390686)

<div class="topic-metadata">

**Author:** [@kruskall](https://discuss.elastic.co/u/kruskall)\
**Replies:** 0\
**Last updated:** [September 25, 2026, 8:35am UTC](https://discuss.elastic.co/t/elasticsearch-9-4-7-9-5-4-security-update-esa-2026-182/390686 "2026-09-25T08:35:05Z")

</div>

Uncontrolled Resource Consumption in Elasticsearch Leading to denial of service Uncontrolled Resource Consumption (CWE-400) in Elasticsearch can lead denial of service via Excessive Allocation (CAPEC-130) Affected Vers…

---

## [Kibana 8.19.22, 9.4.7, 9.5.3 Security Update (ESA-2026-181)](https://discuss.elastic.co/t/kibana-8-19-22-9-4-7-9-5-3-security-update-esa-2026-181/390685)

<div class="topic-metadata">

**Author:** [@kruskall](https://discuss.elastic.co/u/kruskall)\
**Replies:** 0\
**Last updated:** [September 25, 2026, 8:34am UTC](https://discuss.elastic.co/t/kibana-8-19-22-9-4-7-9-5-3-security-update-esa-2026-181/390685 "2026-09-25T08:34:42Z")

</div>

Uncontrolled Resource Consumption in Kibana Leading to denial of service Uncontrolled Resource Consumption (CWE-400) in Kibana can lead denial of service via Excessive Allocation (CAPEC-130) Affected Versions: 8.x: A…

---

## [Elasticsearch 8.19.22, 9.4.7, 9.5.4 Security Update (ESA-2026-180)](https://discuss.elastic.co/t/elasticsearch-8-19-22-9-4-7-9-5-4-security-update-esa-2026-180/390684)

<div class="topic-metadata">

**Author:** [@kruskall](https://discuss.elastic.co/u/kruskall)\
**Replies:** 0\
**Last updated:** [September 25, 2026, 8:34am UTC](https://discuss.elastic.co/t/elasticsearch-8-19-22-9-4-7-9-5-4-security-update-esa-2026-180/390684 "2026-09-25T08:34:19Z")

</div>

Uncontrolled Resource Consumption in Elasticsearch Leading to denial of service Uncontrolled Resource Consumption (CWE-400) in Elasticsearch can lead denial of service via Excessive Allocation (CAPEC-130) Affected Vers…

---

## [Elasticsearch 8.19.22, 9.4.7, 9.5.4 Security Update (ESA-2026-179)](https://discuss.elastic.co/t/elasticsearch-8-19-22-9-4-7-9-5-4-security-update-esa-2026-179/390683)

<div class="topic-metadata">

**Author:** [@kruskall](https://discuss.elastic.co/u/kruskall)\
**Replies:** 0\
**Last updated:** [September 25, 2026, 8:33am UTC](https://discuss.elastic.co/t/elasticsearch-8-19-22-9-4-7-9-5-4-security-update-esa-2026-179/390683 "2026-09-25T08:33:56Z")

</div>

Uncontrolled Resource Consumption in Elasticsearch Leading to denial of service Uncontrolled Resource Consumption (CWE-400) in Elasticsearch can lead denial of service via Excessive Allocation (CAPEC-130) Affected Vers…

---

## [Elasticsearch 8.19.22, 9.4.7, 9.5.4 Security Update (ESA-2026-176)](https://discuss.elastic.co/t/elasticsearch-8-19-22-9-4-7-9-5-4-security-update-esa-2026-176/390682)

<div class="topic-metadata">

**Author:** [@kruskall](https://discuss.elastic.co/u/kruskall)\
**Replies:** 0\
**Last updated:** [September 25, 2026, 8:33am UTC](https://discuss.elastic.co/t/elasticsearch-8-19-22-9-4-7-9-5-4-security-update-esa-2026-176/390682 "2026-09-25T08:33:33Z")

</div>

Uncontrolled Resource Consumption in Elasticsearch Leading to Denial of Service Uncontrolled Resource Consumption (CWE-400) in Elasticsearch can lead to denial of service via Excessive Allocation (CAPEC-130). Affected …

---

## [Elasticsearch 8.19.21, 9.4.6, 9.5.3 Security Update (ESA-2026-170)](https://discuss.elastic.co/t/elasticsearch-8-19-21-9-4-6-9-5-3-security-update-esa-2026-170/390681)

<div class="topic-metadata">

**Author:** [@kruskall](https://discuss.elastic.co/u/kruskall)\
**Replies:** 0\
**Last updated:** [September 25, 2026, 8:33am UTC](https://discuss.elastic.co/t/elasticsearch-8-19-21-9-4-6-9-5-3-security-update-esa-2026-170/390681 "2026-09-25T08:33:09Z")

</div>

Uncontrolled Resource Consumption in Elasticsearch Leading to Denial of Service Uncontrolled Resource Consumption (CWE-400) in Elasticsearch can lead to denial of service via Excessive Allocation (CAPEC-130). Affected …

---

## [Kibana 8.19.22, 9.4.7, 9.5.3 Security Update (ESA-2026-139)](https://discuss.elastic.co/t/kibana-8-19-22-9-4-7-9-5-3-security-update-esa-2026-139/390680)

<div class="topic-metadata">

**Author:** [@kruskall](https://discuss.elastic.co/u/kruskall)\
**Replies:** 0\
**Last updated:** [September 25, 2026, 8:32am UTC](https://discuss.elastic.co/t/kibana-8-19-22-9-4-7-9-5-3-security-update-esa-2026-139/390680 "2026-09-25T08:32:46Z")

</div>

Missing Authorization in Kibana Leading to Unauthorized Deletion of Data Missing Authorization (CWE-862) in Kibana can lead to unauthorized deletion of data via Exploiting Incorrectly Configured Access Control Security …

---

## [Kibana 8.19.22, 9.4.6 Security Update (ESA-2026-103)](https://discuss.elastic.co/t/kibana-8-19-22-9-4-6-security-update-esa-2026-103/390679)

<div class="topic-metadata">

**Author:** [@kruskall](https://discuss.elastic.co/u/kruskall)\
**Replies:** 0\
**Last updated:** [September 25, 2026, 8:32am UTC](https://discuss.elastic.co/t/kibana-8-19-22-9-4-6-security-update-esa-2026-103/390679 "2026-09-25T08:32:22Z")

</div>

Authorization Bypass Through User-Controlled Key in Kibana Leading to Unauthorized Disclosure, Modification, and Deletion of Data Authorization Bypass Through User-Controlled Key (CWE-639) in Kibana can lead to unauthor…

---

## [Kibana 9.4.7, 9.5.0 Security Update (ESA-2026-85)](https://discuss.elastic.co/t/kibana-9-4-7-9-5-0-security-update-esa-2026-85/390678)

<div class="topic-metadata">

**Author:** [@kruskall](https://discuss.elastic.co/u/kruskall)\
**Replies:** 0\
**Last updated:** [September 25, 2026, 8:31am UTC](https://discuss.elastic.co/t/kibana-9-4-7-9-5-0-security-update-esa-2026-85/390678 "2026-09-25T08:31:59Z")

</div>

Unintended Proxy or Intermediary ('Confused Deputy') in Kibana Leading to Privilege Escalation Unintended Proxy or Intermediary ('Confused Deputy') (CWE-441) in Kibana Agent Builder can lead to privilege escalation. A n…

---

## [Integration with omega-scan](https://discuss.elastic.co/t/integration-with-omega-scan/390677)

<div class="topic-metadata">

**Author:** [@wessorh](https://discuss.elastic.co/u/wessorh)\
**Replies:** 0\
**Last updated:** [September 25, 2026, 8:07am UTC](https://discuss.elastic.co/t/integration-with-omega-scan/390677 "2026-09-25T08:07:24Z")

</div>

I'm interested in testing a opensource sample scanner called omega-scan and am looking for documentation on what capabilities there are for calling 3rd party file scanners. A pointer would be greatly appreciated.

---

## [Elastic APM Java agent on Java 25 with inferred spans](https://discuss.elastic.co/t/elastic-apm-java-agent-on-java-25-with-inferred-spans/383042)

<div class="topic-metadata">

**Author:** [@rhuitl](https://discuss.elastic.co/u/rhuitl)\
**Replies:** 3\
**Last updated:** [September 25, 2026, 12:25am UTC](https://discuss.elastic.co/t/elastic-apm-java-agent-on-java-25-with-inferred-spans/383042 "2026-09-25T00:25:42Z")

</div>

I’d like to understand how to get inferred spans working with Java 25. It’s working with Java 17. Java agent version: 1.55.0 Java 25 (Azul) Profiling configuration options | APM Java agent says: “In addition only Java…

---

## [Filebeat postgresql log module produces timestamp fields that are not indexable when using ECS](https://discuss.elastic.co/t/filebeat-postgresql-log-module-produces-timestamp-fields-that-are-not-indexable-when-using-ecs/390640)

<div class="topic-metadata">

**Author:** [@kriller](https://discuss.elastic.co/u/kriller)\
**Replies:** 1\
**Last updated:** [September 24, 2026, 3:57pm UTC](https://discuss.elastic.co/t/filebeat-postgresql-log-module-produces-timestamp-fields-that-are-not-indexable-when-using-ecs/390640 "2026-09-24T15:57:40Z")

</div>

When using the ingest-pipeline that filebeat creates for postgresql logs, the resulting event contains the field postgresql.log.timestamp which conflicts with the ecs@mappings component template. The filebeat-9.5.4-post…

---

## [Elasticsearch monitoring tool - A chrome extension](https://discuss.elastic.co/t/elasticsearch-monitoring-tool-a-chrome-extension/388969)

<div class="topic-metadata">

**Author:** [@Musab\_Dogan](https://discuss.elastic.co/u/Musab_Dogan)\
**Replies:** 16\
**Last updated:** [September 24, 2026, 10:25am UTC](https://discuss.elastic.co/t/elasticsearch-monitoring-tool-a-chrome-extension/388969 "2026-09-24T10:25:05Z")

</div>

Hey guys, I've been debugging Elasticsearch clusters for years, and I got tired of jumping between \_cat APIs, and terminal tabs just to check cluster health. So I built a lightweight Chrome extension that surfaces the m…

---

## [Capture Elasticsearch diagnostics](https://discuss.elastic.co/t/capture-elasticsearch-diagnostics/390628)

<div class="topic-metadata">

**Author:** [@smm](https://discuss.elastic.co/u/smm)\
**Replies:** 0\
**Last updated:** [September 24, 2026, 8:14am UTC](https://discuss.elastic.co/t/capture-elasticsearch-diagnostics/390628 "2026-09-24T08:14:35Z")

</div>

Hi there, very soon I am going to purchase elastic licence. In a prior company I had also elastic licences and was used to use the Elasticsearch diagnostics script by the support to collect cluster health parameters. M…

---

## [Filebeat performance, 430 containers](https://discuss.elastic.co/t/filebeat-performance-430-containers/390622)

<div class="topic-metadata">

**Author:** [@zerkms](https://discuss.elastic.co/u/zerkms)\
**Replies:** 0\
**Last updated:** [September 24, 2026, 5:18am UTC](https://discuss.elastic.co/t/filebeat-performance-430-containers/390622 "2026-09-24T05:18:13Z")

</div>

I'm migrating from quite an old ES+fluentbit configuration (logging solution for a small kubernetes cluster). And this is quite simple yet inefficient (?) config I came up with (this file is generated by ECK using the B…

---

## [Logstash at Tenant end or server end?](https://discuss.elastic.co/t/logstash-at-tenant-end-or-server-end/390608)

<div class="topic-metadata">

**Author:** [@searchwithme](https://discuss.elastic.co/u/searchwithme)\
**Replies:** 0\
**Last updated:** [September 23, 2026, 1:37pm UTC](https://discuss.elastic.co/t/logstash-at-tenant-end-or-server-end/390608 "2026-09-23T13:37:47Z")

</div>

I’m trying to design an architecture where multiple tenants ingest their logs into Elastic. My understanding is that if the requirement is primarily log collection, I can use Elastic Agent, and if additional enrichment,…

---

## [GC occurred in the Elasticsearch cluster](https://discuss.elastic.co/t/gc-occurred-in-the-elasticsearch-cluster/390606)

<div class="topic-metadata">

**Author:** [@Siva\_Karan](https://discuss.elastic.co/u/Siva_Karan)\
**Replies:** 0\
**Last updated:** [September 23, 2026, 12:30pm UTC](https://discuss.elastic.co/t/gc-occurred-in-the-elasticsearch-cluster/390606 "2026-09-23T12:30:35Z")

</div>

Hi Team, \[2026-09-22T22:20:13,448\]\[WARN \]\[o.e.m.j.JvmGcMonitorService\] \[node2\] \[gc\]\[435482\] overhead, spent \[4s\] collecting in the last \[4.6s\]. we are faced the GC issue with low heap usage and also we are unable to ac…

---

## [Why is the operator run as a statefulset?](https://discuss.elastic.co/t/why-is-the-operator-run-as-a-statefulset/390605)

<div class="topic-metadata">

**Author:** [@Frederic\_PEGE](https://discuss.elastic.co/u/Frederic_PEGE)\
**Replies:** 0\
**Last updated:** [September 23, 2026, 11:37am UTC](https://discuss.elastic.co/t/why-is-the-operator-run-as-a-statefulset/390605 "2026-09-23T11:37:14Z")

</div>

Hi, Why is the operator run as a STS ? I'm talking about the ES cluster, but the actual operator ?

---

## [ILM unable to delete old index since upgrade to 8.19.20](https://discuss.elastic.co/t/ilm-unable-to-delete-old-index-since-upgrade-to-8-19-20/390601)

<div class="topic-metadata">

**Author:** [@numpty-boy](https://discuss.elastic.co/u/numpty-boy)\
**Replies:** 0\
**Last updated:** [September 23, 2026, 8:58am UTC](https://discuss.elastic.co/t/ilm-unable-to-delete-old-index-since-upgrade-to-8-19-20/390601 "2026-09-23T08:58:47Z")

</div>

Morning Team, Since upgrading to 8.19.20, I've started getting these errors: policy \[.fleet-actions-results-ilm-policy\] for index \[.ds-.fleet-actions-results-2026.05.02-000014\] on an error step due to a transient error…

---

## [RFC: Disable automatic refresh in event analyzer](https://discuss.elastic.co/t/rfc-disable-automatic-refresh-in-event-analyzer/390600)

<div class="topic-metadata">

**Author:** [@michael-a](https://discuss.elastic.co/u/michael-a)\
**Replies:** 0\
**Last updated:** [September 23, 2026, 8:35am UTC](https://discuss.elastic.co/t/rfc-disable-automatic-refresh-in-event-analyzer/390600 "2026-09-23T08:35:03Z")

</div>

When analyzing events from detections/alerts with automatic refresh, the analyze view automatically refresh too which isn't necessarily what one wants. Therefore it would be better if the automatic refresh either would t…

---

## [Field formatters in ES|QL table panels](https://discuss.elastic.co/t/field-formatters-in-es-ql-table-panels/390418)

<div class="topic-metadata">

**Author:** [@tallakh](https://discuss.elastic.co/u/tallakh)\
**Replies:** 1\
**Last updated:** [September 23, 2026, 8:07am UTC](https://discuss.elastic.co/t/field-formatters-in-es-ql-table-panels/390418 "2026-09-23T08:07:19Z")

</div>

Hi! We have started to use ES|QL a lot in our Kibana dashboards, and I love the flexibility it brings! One of the few missing features compared to Lens table panels is to set formatting on a text/keyword field. F ex a l…

---

## [New release of elastic-apm gem](https://discuss.elastic.co/t/new-release-of-elastic-apm-gem/390553)

<div class="topic-metadata">

**Author:** [@opiotrek](https://discuss.elastic.co/u/opiotrek)\
**Replies:** 2\
**Last updated:** [September 23, 2026, 5:56am UTC](https://discuss.elastic.co/t/new-release-of-elastic-apm-gem/390553 "2026-09-23T05:56:31Z")

</div>

Hello! The master branch contains an important fix that will unblock our upgrade to Ruby 4.0+. Can you release a new gem version?

---

## [Integration-level Outputs](https://discuss.elastic.co/t/integration-level-outputs/390582)

<div class="topic-metadata">

**Author:** [@jameswiggins](https://discuss.elastic.co/u/jameswiggins)\
**Replies:** 3\
**Last updated:** [September 22, 2026, 8:17pm UTC](https://discuss.elastic.co/t/integration-level-outputs/390582 "2026-09-22T20:17:35Z")

</div>

I'm trying to determine how to configure integration-level outputs: Set integration-level outputs | Elastic Docs I followed the instructions for configuring, but do not see the option. Can someone share a screenshot of…

---

## [Kibana 9 - Detail pane is a bad replacement for Expandable row for my use cases](https://discuss.elastic.co/t/kibana-9-detail-pane-is-a-bad-replacement-for-expandable-row-for-my-use-cases/390555)

<div class="topic-metadata">

**Author:** [@poifir](https://discuss.elastic.co/u/poifir)\
**Replies:** 0\
**Last updated:** [September 21, 2026, 12:00pm UTC](https://discuss.elastic.co/t/kibana-9-detail-pane-is-a-bad-replacement-for-expandable-row-for-my-use-cases/390555 "2026-09-21T12:00:16Z")

</div>

In Kibana 8 we continued to use the "old" UI that offered to expand each row individually to show it's detail values. This works good as the full width of the windows is also available to the detailed attributes and so …

[Next page](https://discuss.elastic.co/latest.md?page=1)
