# Latest

**URL:** https://discuss.elastic.co/latest.md?page=396

[Latest](https://discuss.elastic.co/latest.md) · [Categories](https://discuss.elastic.co/categories.md) · [Tags](https://discuss.elastic.co/tags.md)

**Page:** 397

---

## [Experiencing an error while restoring the snapshot](https://discuss.elastic.co/t/experiencing-an-error-while-restoring-the-snapshot/352280)

<div class="topic-metadata">

**Author:** [@AnushaTalluri](https://discuss.elastic.co/u/AnushaTalluri)\
**Replies:** 6\
**Last updated:** [February 20, 2024, 8:30am UTC](https://discuss.elastic.co/t/experiencing-an-error-while-restoring-the-snapshot/352280 "2024-02-20T08:30:16Z")

</div>

I've been trying to restore the snapshot preserved in Azure storage blobs. While restoring observed the below error, {"error":{"root\_cause":\[{"type":"repository\_exception","reason":"\[elasticsearch\_snapshot\] Could not d…

---

## [Kibana Observability Infrastructure Inventory Docker Containers have error (400): Error while fetching resource](https://discuss.elastic.co/t/kibana-observability-infrastructure-inventory-docker-containers-have-error-400-error-while-fetching-resource/353652)

<div class="topic-metadata">

**Author:** [@wruiwr](https://discuss.elastic.co/u/wruiwr)\
**Replies:** 0\
**Last updated:** [February 20, 2024, 7:41am UTC](https://discuss.elastic.co/t/kibana-observability-infrastructure-inventory-docker-containers-have-error-400-error-while-fetching-resource/353652 "2024-02-20T07:41:21Z")

</div>

After upgrading Elastic Stack from 8.11.4 to 8.12.0, there is an error when seeing the Docker Containers in the Inventory of Observability Infrastructure of Kibana: See the screenshot: I'm unsure if it is a bug or s…

---

## [Agents periodically disconnecting from Fleets](https://discuss.elastic.co/t/agents-periodically-disconnecting-from-fleets/353397)

<div class="topic-metadata">

**Author:** [@squatchulator](https://discuss.elastic.co/u/squatchulator)\
**Replies:** 1\
**Last updated:** [February 20, 2024, 7:40am UTC](https://discuss.elastic.co/t/agents-periodically-disconnecting-from-fleets/353397 "2024-02-20T07:40:47Z")

</div>

Version: 8.9.0 Hi there! Working on a SOC team where we manage agents for lots of local endpoints within our network. I'm pretty new to working with the stack, so I am hoping someone with more experience with agent issu…

---

## [Issue with Character Encoding When Receiving Data from RSYSLOG in Logstash 8.4.3](https://discuss.elastic.co/t/issue-with-character-encoding-when-receiving-data-from-rsyslog-in-logstash-8-4-3/353609)

<div class="topic-metadata">

**Author:** [@nw-engineer](https://discuss.elastic.co/u/nw-engineer)\
**Replies:** 4\
**Last updated:** [February 20, 2024, 5:41am UTC](https://discuss.elastic.co/t/issue-with-character-encoding-when-receiving-data-from-rsyslog-in-logstash-8-4-3/353609 "2024-02-20T05:41:19Z")

</div>

Hello, I'm currently using Logstash version 8.4.3 and encountering an issue when processing data received from RSYSLOG. The error message I'm seeing is as follows: \[WARN \]\[logstash.codecs.plain\]\[main\]\[b162f9e29529bc018…

---

## [Send logs From Filebeat to 2 different group logstash servers simultaneously](https://discuss.elastic.co/t/send-logs-from-filebeat-to-2-different-group-logstash-servers-simultaneously/353548)

<div class="topic-metadata">

**Author:** [@Frances\_Chu](https://discuss.elastic.co/u/Frances_Chu)\
**Replies:** 4\
**Last updated:** [February 20, 2024, 3:54am UTC](https://discuss.elastic.co/t/send-logs-from-filebeat-to-2-different-group-logstash-servers-simultaneously/353548 "2024-02-20T03:54:36Z")

</div>

I need to send logs From Filebeat to 2 different group logstash servers simultaneously Group A: Single logstash server with certificate\_A and CA\_A Group B: 3 logstash servers run in loadbalance mode. with certificate\_B…

---

## [Kibana failed to fetch event log KPI](https://discuss.elastic.co/t/kibana-failed-to-fetch-event-log-kpi/353640)

<div class="topic-metadata">

**Author:** [@greenhand](https://discuss.elastic.co/u/greenhand)\
**Replies:** 0\
**Last updated:** [February 20, 2024, 2:35am UTC](https://discuss.elastic.co/t/kibana-failed-to-fetch-event-log-kpi/353640 "2024-02-20T02:35:49Z")

</div>

Hello! I am an elasticsearch user from China and I thought I might need some help, I can't find the information to solve this problem in my own country.When I tried to use the alert function, I found that the log TAB did…

---

## [Failed to load SSL configuration \[xpack.security.transport.ssl\] - cannot read configured \[PKCS12\]](https://discuss.elastic.co/t/failed-to-load-ssl-configuration-xpack-security-transport-ssl-cannot-read-configured-pkcs12/352840)

<div class="topic-metadata">

**Author:** [@Jerry-yz](https://discuss.elastic.co/u/Jerry-yz)\
**Replies:** 3\
**Last updated:** [February 20, 2024, 1:54am UTC](https://discuss.elastic.co/t/failed-to-load-ssl-configuration-xpack-security-transport-ssl-cannot-read-configured-pkcs12/352840 "2024-02-20T01:54:49Z")

</div>

wehn i run es with docker; my docker run cmd is: docker run -itd -p 9200:9200 -m 2GB --privileged=true -v $PWD/config/elasticsearch.yml:/usr/share/elasticsearch/config/elasticsearch.yml -v $PWD/data:/usr/share/elasticse…

---

## [What log Windows security rules require into a winlogbeat](https://discuss.elastic.co/t/what-log-windows-security-rules-require-into-a-winlogbeat/353632)

<div class="topic-metadata">

**Author:** [@dominic.savaria](https://discuss.elastic.co/u/dominic.savaria)\
**Replies:** 0\
**Last updated:** [February 19, 2024, 8:06pm UTC](https://discuss.elastic.co/t/what-log-windows-security-rules-require-into-a-winlogbeat/353632 "2024-02-19T20:06:36Z")

</div>

I want to enable most of the Windows security rules in Kibana, but I am missing a lot of fields from my winlogbeat. We are fowarding our logs into a windows event collector but I don't know what log are missing for the s…

---

## [Issue with setting \`\_tier\_preference\` in index template](https://discuss.elastic.co/t/issue-with-setting-tier-preference-in-index-template/353631)

<div class="topic-metadata">

**Author:** [@Sebastian\_Veliz\_MQ](https://discuss.elastic.co/u/Sebastian_Veliz_MQ)\
**Replies:** 0\
**Last updated:** [February 19, 2024, 8:02pm UTC](https://discuss.elastic.co/t/issue-with-setting-tier-preference-in-index-template/353631 "2024-02-19T20:02:10Z")

</div>

Hello We are encountering an issue while trying to set the \_tier\_preference in an index template. Despite updating the setting in the index template edit page, the preview shows that \_tier\_preference is set to null inst…

---

## [Allow requests to elastic deployment only from AWS EC2 instances in VPN](https://discuss.elastic.co/t/allow-requests-to-elastic-deployment-only-from-aws-ec2-instances-in-vpn/353618)

<div class="topic-metadata">

**Author:** [@searchwithme](https://discuss.elastic.co/u/searchwithme)\
**Replies:** 1\
**Last updated:** [February 19, 2024, 6:02pm UTC](https://discuss.elastic.co/t/allow-requests-to-elastic-deployment-only-from-aws-ec2-instances-in-vpn/353618 "2024-02-19T18:02:39Z")

</div>

Is it possible to restrict access to elastic deployment only from AWS EC2 instances that are part of a particular VPN?

---

## [Slow Navigation in Kibana](https://discuss.elastic.co/t/slow-navigation-in-kibana/349279)

<div class="topic-metadata">

**Author:** [@tepus](https://discuss.elastic.co/u/tepus)\
**Replies:** 5\
**Last updated:** [February 19, 2024, 5:13pm UTC](https://discuss.elastic.co/t/slow-navigation-in-kibana/349279 "2024-02-19T17:13:33Z")

</div>

Dear Community, we use the following configuration of ELK: Version: 8.5.3 OS: RHEL 8 Number of master nodes: 1 Number of master and warm nodes: 2 Hot nodes: 2 Kibana instances: 2 Our issue is that the navigation …

---

## [Multiline does not append the lines](https://discuss.elastic.co/t/multiline-does-not-append-the-lines/353625)

<div class="topic-metadata">

**Author:** [@Pedro\_Lopez\_Gonzalez](https://discuss.elastic.co/u/Pedro_Lopez_Gonzalez)\
**Replies:** 2\
**Last updated:** [February 19, 2024, 4:55pm UTC](https://discuss.elastic.co/t/multiline-does-not-append-the-lines/353625 "2024-02-19T16:55:33Z")

</div>

Hi all, I have configured a parser to join the lines into one but it doesn´t work. This is the configuration code: filebeat.inputs: # Each - is an input. Most options can be set at the input level, so # you can use d…

---

## [Security minimal setup 7.9.0](https://discuss.elastic.co/t/security-minimal-setup-7-9-0/353304)

<div class="topic-metadata">

**Author:** [@mwitsas](https://discuss.elastic.co/u/mwitsas)\
**Replies:** 2\
**Last updated:** [February 19, 2024, 3:32pm UTC](https://discuss.elastic.co/t/security-minimal-setup-7-9-0/353304 "2024-02-19T15:32:12Z")

</div>

Can anyone confirm this procedure is valid for 7.9.0 and should work? Or can anyone highlight any issues with trying this on 7.9.0? I see the page only exists in documentation from 7.12.0 onwards - "This page is not a…

---

## [Having trouble parsing my JSON apache log using Logstash](https://discuss.elastic.co/t/having-trouble-parsing-my-json-apache-log-using-logstash/353488)

<div class="topic-metadata">

**Author:** [@ozonshak](https://discuss.elastic.co/u/ozonshak)\
**Replies:** 4\
**Last updated:** [February 19, 2024, 3:17pm UTC](https://discuss.elastic.co/t/having-trouble-parsing-my-json-apache-log-using-logstash/353488 "2024-02-19T15:17:28Z")

</div>

Hello. I have an existing Elastic stack that is pulling in app and web server logs. For the web site, I have 2 software stacks - 1 is using an older apache format (comma separated values) and 1 is using a newer JSON fo…

---

## [fatal exception while booting Elasticsearch](https://discuss.elastic.co/t/fatal-exception-while-booting-elasticsearch/353620)

<div class="topic-metadata">

**Author:** [@carrot016](https://discuss.elastic.co/u/carrot016)\
**Replies:** 0\
**Last updated:** [February 19, 2024, 3:15pm UTC](https://discuss.elastic.co/t/fatal-exception-while-booting-elasticsearch/353620 "2024-02-19T15:15:24Z")

</div>

elasticsearch-1 | {"@timestamp":"2024-02-19T12:02:08.108Z", "log.level":"ERROR", "message":"fatal exception while booting Elasticsearch", "ecs.version": "1.2.0","service.name":"ES\_ECS","event.dataset":"elasticsearch.serv…

---

## [Data tiers vs searchable snapshot \[platinum license elastic onprem\]](https://discuss.elastic.co/t/data-tiers-vs-searchable-snapshot-platinum-license-elastic-onprem/353541)

<div class="topic-metadata">

**Author:** [@searchwithme](https://discuss.elastic.co/u/searchwithme)\
**Replies:** 14\
**Last updated:** [February 19, 2024, 3:07pm UTC](https://discuss.elastic.co/t/data-tiers-vs-searchable-snapshot-platinum-license-elastic-onprem/353541 "2024-02-19T15:07:58Z")

</div>

Hello team! I want to make use of the hot, warm, cold, frozen tiers for my onprem elastic deployment. I can see from this link that data tier is possible with platinum licensing. However I see 'searchable snapshots' ca…

---

## [Autoscaling](https://discuss.elastic.co/t/autoscaling/353616)

<div class="topic-metadata">

**Author:** [@searchwithme](https://discuss.elastic.co/u/searchwithme)\
**Replies:** 0\
**Last updated:** [February 19, 2024, 2:59pm UTC](https://discuss.elastic.co/t/autoscaling/353616 "2024-02-19T14:59:40Z")

</div>

I see from documentation that elastic autoscaling works based on storage and there is no scaling available based on cpu. has anyone done scripting to automate scaling based on cpu?

---

## [Kibana APM metrics view din't show Opentelemetry JVM metrics](https://discuss.elastic.co/t/kibana-apm-metrics-view-dint-show-opentelemetry-jvm-metrics/353524)

<div class="topic-metadata">

**Author:** [@XuQing\_Tan](https://discuss.elastic.co/u/XuQing_Tan)\
**Replies:** 10\
**Last updated:** [February 19, 2024, 2:49pm UTC](https://discuss.elastic.co/t/kibana-apm-metrics-view-dint-show-opentelemetry-jvm-metrics/353524 "2024-02-19T14:49:29Z")

</div>

Versions: ES v8.11.2 opentelemtry agent 2.1.0 jre 17.0.10 I'm setting up the APM dashboard of Keycloak which uses Quarkus, so per the thread Does Elastic APM support Quarkus? - #2 by cyrilleleclerc I used opentelemetr…

---

## [Exiting: error connecting to Kibana: fail to get the Kibana version: fail to parse kibana version (): passed version is not semver:](https://discuss.elastic.co/t/exiting-error-connecting-to-kibana-fail-to-get-the-kibana-version-fail-to-parse-kibana-version-passed-version-is-not-semver/353450)

<div class="topic-metadata">

**Author:** [@alsoGAMER](https://discuss.elastic.co/u/alsoGAMER)\
**Replies:** 20\
**Last updated:** [February 19, 2024, 2:35pm UTC](https://discuss.elastic.co/t/exiting-error-connecting-to-kibana-fail-to-get-the-kibana-version-fail-to-parse-kibana-version-passed-version-is-not-semver/353450 "2024-02-19T14:35:15Z")

</div>

I'm trying to setup an ELK instance to use as a winlogbeat output, and even though both the ELK stack and winlogbeat versions are the exact same, I'm getting this cryptic error: Exiting: error connecting to Kibana: fail…

---

## [Sort by top\_hits aggregation](https://discuss.elastic.co/t/sort-by-top-hits-aggregation/353605)

<div class="topic-metadata">

**Author:** [@martid1703](https://discuss.elastic.co/u/martid1703)\
**Replies:** 0\
**Last updated:** [February 19, 2024, 2:16pm UTC](https://discuss.elastic.co/t/sort-by-top-hits-aggregation/353605 "2024-02-19T14:16:21Z")

</div>

Hi! Is it possible to sort aggregated buckets using inner aggregation result fields? Example: we have posts aggregated by topicId using composite aggregation named "topic\_aggregation". Inside it using nested 'top\_hits…

---

## [Is there a way I can store recent data on partitions?](https://discuss.elastic.co/t/is-there-a-way-i-can-store-recent-data-on-partitions/353581)

<div class="topic-metadata">

**Author:** [@Ravi\_Pattar](https://discuss.elastic.co/u/Ravi_Pattar)\
**Replies:** 3\
**Last updated:** [February 19, 2024, 2:02pm UTC](https://discuss.elastic.co/t/is-there-a-way-i-can-store-recent-data-on-partitions/353581 "2024-02-19T14:02:12Z")

</div>

Hello, Is there a way so that I can have ELK keep say the last 50 or more GB on one partition and everything else on a different partition? In general I was thinking of putting all recent logs on SSD and after X age/tim…

---

## ['took' time fast, curl sometimes slow](https://discuss.elastic.co/t/took-time-fast-curl-sometimes-slow/353422)

<div class="topic-metadata">

**Author:** [@ryans](https://discuss.elastic.co/u/ryans)\
**Replies:** 6\
**Last updated:** [February 19, 2024, 1:59pm UTC](https://discuss.elastic.co/t/took-time-fast-curl-sometimes-slow/353422 "2024-02-19T13:59:04Z")

</div>

I am using Elastic Cloud for my Elasticsearch instance. My issue is that sometimes (rarely) I'm seeing strange behavior where the curl time (round trip from my web server to Elastic Cloud) is taking 8+ seconds but the '…

---

## [Hey, i have some problems about elasticsearch and kibana! i want to create different space for my clients and i wouldn't that client had acces at the graph others! also, i want send many traffic netflow in my filebeat, but i don't know how we make!](https://discuss.elastic.co/t/hey-i-have-some-problems-about-elasticsearch-and-kibana-i-want-to-create-different-space-for-my-clients-and-i-wouldnt-that-client-had-acces-at-the-graph-others-also-i-want-send-many-traffic-netflow-in-my-filebeat-but-i-dont-know-how-we-make/353576)

<div class="topic-metadata">

**Author:** [@Pierre\_Yoboue](https://discuss.elastic.co/u/Pierre_Yoboue)\
**Replies:** 1\
**Last updated:** [February 19, 2024, 12:38pm UTC](https://discuss.elastic.co/t/hey-i-have-some-problems-about-elasticsearch-and-kibana-i-want-to-create-different-space-for-my-clients-and-i-wouldnt-that-client-had-acces-at-the-graph-others-also-i-want-send-many-traffic-netflow-in-my-filebeat-but-i-dont-know-how-we-make/353576 "2024-02-19T12:38:07Z")

</div>

Module: netflow Docs: https://www.elastic.co/guide/en/beats/filebeat/main/filebeat-module-netflow.html module: netflow log: enabled: true var: netflow\_host: 10.74.192.64 netflow\_port: 2055 tags: \["INQ"\] # intern…

---

## [Histogram query over calculated field](https://discuss.elastic.co/t/histogram-query-over-calculated-field/353586)

<div class="topic-metadata">

**Author:** [@marinavictoria](https://discuss.elastic.co/u/marinavictoria)\
**Replies:** 0\
**Last updated:** [February 19, 2024, 12:22pm UTC](https://discuss.elastic.co/t/histogram-query-over-calculated-field/353586 "2024-02-19T12:22:42Z")

</div>

My case is the following: doc1: event.type (keyword): a doc2: event.type: aa doc3: event.type: aa doc4: event.type: aaaa I want to create a query that gives me in the Y axis the count of event.type and in the X …

---

## [Updating the documents through the Ingest Pipeline](https://discuss.elastic.co/t/updating-the-documents-through-the-ingest-pipeline/353583)

<div class="topic-metadata">

**Author:** [@ksaimohan2k](https://discuss.elastic.co/u/ksaimohan2k)\
**Replies:** 0\
**Last updated:** [February 19, 2024, 11:45am UTC](https://discuss.elastic.co/t/updating-the-documents-through-the-ingest-pipeline/353583 "2024-02-19T11:45:10Z")

</div>

Is there any way to update documents using the ingest pipeline? We are trying to ingest documents using a custom API through the Ingest pipeline. We are looking to identify the duplicate records. We used the "fingerprin…

---

## [Filebeat 7.7 not working in rocky OS 9.2, Kindly help on this](https://discuss.elastic.co/t/filebeat-7-7-not-working-in-rocky-os-9-2-kindly-help-on-this/353580)

<div class="topic-metadata">

**Author:** [@Munir\_Sayyad](https://discuss.elastic.co/u/Munir_Sayyad)\
**Replies:** 1\
**Last updated:** [February 19, 2024, 11:40am UTC](https://discuss.elastic.co/t/filebeat-7-7-not-working-in-rocky-os-9-2-kindly-help-on-this/353580 "2024-02-19T11:40:12Z")

</div>

Filebeat 7.7 not working in rocky OS 9.2

---

## [CaptureBody invalid format](https://discuss.elastic.co/t/capturebody-invalid-format/353579)

<div class="topic-metadata">

**Author:** [@Kirtash](https://discuss.elastic.co/u/Kirtash)\
**Replies:** 0\
**Last updated:** [February 19, 2024, 11:36am UTC](https://discuss.elastic.co/t/capturebody-invalid-format/353579 "2024-02-19T11:36:32Z")

</div>

Good morning, I have updated the version of elasticstack to the version 8.12.0 and I capture the body in the APM transactions. But now the field http.request.body is different and appears the body inside the field "ori…

---

## [Transfer log events as files between Logstash instances](https://discuss.elastic.co/t/transfer-log-events-as-files-between-logstash-instances/353503)

<div class="topic-metadata">

**Author:** [@olavur](https://discuss.elastic.co/u/olavur)\
**Replies:** 4\
**Last updated:** [February 19, 2024, 11:34am UTC](https://discuss.elastic.co/t/transfer-log-events-as-files-between-logstash-instances/353503 "2024-02-19T11:34:15Z")

</div>

Hi, I have two logstash instances. One instance A receives events from elastic agents. The second, instance B, inputs the events and outputs them further downstream. But my only option is to transfer files from instanc…

---

## [The otelp exception.message will be used for the ecs message instead of the body field](https://discuss.elastic.co/t/the-otelp-exception-message-will-be-used-for-the-ecs-message-instead-of-the-body-field/353555)

<div class="topic-metadata">

**Author:** [@HHobeck](https://discuss.elastic.co/u/HHobeck)\
**Replies:** 1\
**Last updated:** [February 19, 2024, 11:28am UTC](https://discuss.elastic.co/t/the-otelp-exception-message-will-be-used-for-the-ecs-message-instead-of-the-body-field/353555 "2024-02-19T11:28:09Z")

</div>

Kibana version: 8.10.2 Elasticsearch version: 8.10.2 APM Server version: 8.10.2 APM Agent language and version: No idea where I can find this. Original install method (e.g. download page, yum, deb, from source, e…

---

## [Структура индекса для поиска в интернетмагазине](https://discuss.elastic.co/t/topic/353567)

<div class="topic-metadata">

**Author:** [@denis.lapa](https://discuss.elastic.co/u/denis.lapa)\
**Replies:** 0\
**Last updated:** [February 19, 2024, 10:40am UTC](https://discuss.elastic.co/t/topic/353567 "2024-02-19T10:40:40Z")

</div>

Добрый день. У нас интернет-магазин 560 000 товаров. Контент на 6-ти языках. Сейчас контент на всех языках индексируется в один индекс: поле pname = Мобильный телефон xiaomi, Mobile phone xiaomi и тд. поле сat\_name …

[Previous page](https://discuss.elastic.co/latest.md?page=395)

[Next page](https://discuss.elastic.co/latest.md?page=397)
