# Latest

**URL:** https://discuss.elastic.co/latest.md?page=398

[Latest](https://discuss.elastic.co/latest.md) · [Categories](https://discuss.elastic.co/categories.md) · [Tags](https://discuss.elastic.co/tags.md)

**Page:** 399

---

## [Can not create certificates for elasticsearch](https://discuss.elastic.co/t/can-not-create-certificates-for-elasticsearch/353509)

<div class="topic-metadata">

**Author:** [@Yerbolat\_Talasbekov](https://discuss.elastic.co/u/Yerbolat_Talasbekov)\
**Replies:** 7\
**Last updated:** [February 18, 2024, 2:39pm UTC](https://discuss.elastic.co/t/can-not-create-certificates-for-elasticsearch/353509 "2024-02-18T14:39:48Z")

</div>

Hello, can somebody help me with certificate creation? Here is my screens

---

## [Combine data views in Timeline Template](https://discuss.elastic.co/t/combine-data-views-in-timeline-template/353515)

<div class="topic-metadata">

**Author:** [@RoeeKent](https://discuss.elastic.co/u/RoeeKent)\
**Replies:** 1\
**Last updated:** [February 18, 2024, 1:42pm UTC](https://discuss.elastic.co/t/combine-data-views-in-timeline-template/353515 "2024-02-18T13:42:09Z")

</div>

Hi Everyone! I'm implementing the usage of timeline templates in my organization, but when I need to use different indices at the same time, I can't because it is based on data views and not on index patterns. I have so…

---

## [SQL data upload using JDBC-logstash](https://discuss.elastic.co/t/sql-data-upload-using-jdbc-logstash/353435)

<div class="topic-metadata">

**Author:** [@Ritikapawar](https://discuss.elastic.co/u/Ritikapawar)\
**Replies:** 8\
**Last updated:** [February 18, 2024, 10:04am UTC](https://discuss.elastic.co/t/sql-data-upload-using-jdbc-logstash/353435 "2024-02-18T10:04:22Z")

</div>

Hi, I'm uploading data using jdbc-logstash script but when i run ths script it adds allover data again and again so index is showing count of duplicate data too. This is the script which i am using input { jdbc { …

---

## [Kibana formula "reducedTimeRange" not working](https://discuss.elastic.co/t/kibana-formula-reducedtimerange-not-working/353243)

<div class="topic-metadata">

**Author:** [@SamehSaeed](https://discuss.elastic.co/u/SamehSaeed)\
**Replies:** 3\
**Last updated:** [February 18, 2024, 7:13am UTC](https://discuss.elastic.co/t/kibana-formula-reducedtimerange-not-working/353243 "2024-02-18T07:13:36Z")

</div>

I'm facing an issue while creating a visualization, whenever i use "reducedTimeRange" the result value becomes 0.

---

## [Elastic badrequest error: contains unrecognized parameter: \[type\]](https://discuss.elastic.co/t/elastic-badrequest-error-contains-unrecognized-parameter-type/353427)

<div class="topic-metadata">

**Author:** [@Vicapelli](https://discuss.elastic.co/u/Vicapelli)\
**Replies:** 4\
**Last updated:** [February 17, 2024, 9:45pm UTC](https://discuss.elastic.co/t/elastic-badrequest-error-contains-unrecognized-parameter-type/353427 "2024-02-17T21:45:37Z")

</div>

I am using Elasticsearch in a Rails application through the Elasticsearch-rails gem. After creating the indexes, I want to import the data into these indexes. But I am getting the following error: Elastic::Transport::T…

---

## [Logstash TCP encoder](https://discuss.elastic.co/t/logstash-tcp-encoder/353469)

<div class="topic-metadata">

**Author:** [@kypdk](https://discuss.elastic.co/u/kypdk)\
**Replies:** 3\
**Last updated:** [February 17, 2024, 3:54pm UTC](https://discuss.elastic.co/t/logstash-tcp-encoder/353469 "2024-02-17T15:54:41Z")

</div>

The logs go to the logstash server, but they are not indexed because they are not in the format I want. How should I configure it? output { elasticsearch { hosts =\> "elasticsearch:9200" …

---

## [Azure SAML configuration using free elastic/kibana version](https://discuss.elastic.co/t/azure-saml-configuration-using-free-elastic-kibana-version/353497)

<div class="topic-metadata">

**Author:** [@Pablo\_Lencinas](https://discuss.elastic.co/u/Pablo_Lencinas)\
**Replies:** 2\
**Last updated:** [February 17, 2024, 3:45pm UTC](https://discuss.elastic.co/t/azure-saml-configuration-using-free-elastic-kibana-version/353497 "2024-02-17T15:45:55Z")

</div>

Hi. I'm using elastic/kibana and elastiflow to collect netflow traffic and I would like to configure SAML authentication using Azure AD. I'm using Elastic v8.7.0 (free version). It is possible to configure this feature? …

---

## [Elasticsearch Query: search result not same when am searching for wooden door and wooden doors](https://discuss.elastic.co/t/elasticsearch-query-search-result-not-same-when-am-searching-for-wooden-door-and-wooden-doors/353504)

<div class="topic-metadata">

**Author:** [@Mohan\_T](https://discuss.elastic.co/u/Mohan_T)\
**Replies:** 1\
**Last updated:** [February 17, 2024, 12:15pm UTC](https://discuss.elastic.co/t/elasticsearch-query-search-result-not-same-when-am-searching-for-wooden-door-and-wooden-doors/353504 "2024-02-17T12:15:25Z")

</div>

when am search for wooden door and wooden doors results not show the same. Query which i have used to fetch the data { "query": { "bool": { "should": \[ { "mat…

---

## [First time user - Unable to get Filebeat \> logstash](https://discuss.elastic.co/t/first-time-user-unable-to-get-filebeat-logstash/352451)

<div class="topic-metadata">

**Author:** [@eezeetee](https://discuss.elastic.co/u/eezeetee)\
**Replies:** 18\
**Last updated:** [February 17, 2024, 5:24am UTC](https://discuss.elastic.co/t/first-time-user-unable-to-get-filebeat-logstash/352451 "2024-02-17T05:24:46Z")

</div>

I've been trying to get a home monitoring system up and running and i've fallen flat. My goal was to get MQTT and other messages into filebeat, thru logstash and into Kibana to build a dashboard. I've followed a few gu…

---

## [Lens - Pie Chart Summary](https://discuss.elastic.co/t/lens-pie-chart-summary/353493)

<div class="topic-metadata">

**Author:** [@erikg](https://discuss.elastic.co/u/erikg)\
**Replies:** 4\
**Last updated:** [February 17, 2024, 2:18am UTC](https://discuss.elastic.co/t/lens-pie-chart-summary/353493 "2024-02-17T02:18:39Z")

</div>

Hello, I was wondering if there's a way to make a summary pie chart. The problem is with pie charts, I can't seem to be able to "Last Value" of a keyword. But in a data table, I can. This is an example of the data ta…

---

## [Elastic-filebeat-nginx-kibana-docker compose](https://discuss.elastic.co/t/elastic-filebeat-nginx-kibana-docker-compose/353457)

<div class="topic-metadata">

**Author:** [@v.popov](https://discuss.elastic.co/u/v.popov)\
**Replies:** 4\
**Last updated:** [February 16, 2024, 8:14pm UTC](https://discuss.elastic.co/t/elastic-filebeat-nginx-kibana-docker-compose/353457 "2024-02-16T20:14:53Z")

</div>

Попробуем сначала на русском. Всем привет, я работаю с Elastic через docker compose. У меня сейчас 2 вопроса: 1- Почему у меня огромное количество отдаваемых логов от nginx? После создания index filebeat-\* перехожу к л…

---

## [Elasticsearch password during installation](https://discuss.elastic.co/t/elasticsearch-password-during-installation/353490)

<div class="topic-metadata">

**Author:** [@SippingOnesAndZeros](https://discuss.elastic.co/u/SippingOnesAndZeros)\
**Replies:** 0\
**Last updated:** [February 16, 2024, 8:04pm UTC](https://discuss.elastic.co/t/elasticsearch-password-during-installation/353490 "2024-02-16T20:04:41Z")

</div>

Hello, I have a question related to the password setting in .env as in the example Enterprise Search 8.x - Docker Compose example If the password is not provided, will there be any negative consequences other than manu…

---

## [Add context to suggestions field while re-indexing](https://discuss.elastic.co/t/add-context-to-suggestions-field-while-re-indexing/353407)

<div class="topic-metadata">

**Author:** [@dat\_boi](https://discuss.elastic.co/u/dat_boi)\
**Replies:** 6\
**Last updated:** [February 16, 2024, 7:18pm UTC](https://discuss.elastic.co/t/add-context-to-suggestions-field-while-re-indexing/353407 "2024-02-16T19:18:25Z")

</div>

so i'v been trying to add suggester to my old index which had docs with the fields -name --\> text -category --\> long -status --\> long i created a new index with the same mapping as the old one and i add the suggestio…

---

## [Windows install : jruby not found](https://discuss.elastic.co/t/windows-install-jruby-not-found/353487)

<div class="topic-metadata">

**Author:** [@jim.patterson](https://discuss.elastic.co/u/jim.patterson)\
**Replies:** 3\
**Last updated:** [February 16, 2024, 7:17pm UTC](https://discuss.elastic.co/t/windows-install-jruby-not-found/353487 "2024-02-16T19:17:55Z")

</div>

The error message I am getting: "could not find jruby in D:\\elastic\_stack\\logstash-8.12.0\\vendor\\jruby" I've opened and extracted the logstash-8.12.0-windows-x86\_64 file with 7zip, I didn't use windows default zip file…

---

## [Very High Cpu Usage for search](https://discuss.elastic.co/t/very-high-cpu-usage-for-search/352110)

<div class="topic-metadata">

**Author:** [@bharat\_bhushan\_ship](https://discuss.elastic.co/u/bharat_bhushan_ship)\
**Replies:** 8\
**Last updated:** [February 16, 2024, 6:14pm UTC](https://discuss.elastic.co/t/very-high-cpu-usage-for-search/352110 "2024-02-16T18:14:44Z")

</div>

I have a cluster (ES version 7.0.3) with 3 nodes with ubuntu servers and i have not declare any node as a master or data node, by default it elect one master and other data nodes itself. And i have only one index on this…

---

## [Logstash-filter-fingerprint failing intermittently](https://discuss.elastic.co/t/logstash-filter-fingerprint-failing-intermittently/353317)

<div class="topic-metadata">

**Author:** [@ellje](https://discuss.elastic.co/u/ellje)\
**Replies:** 2\
**Last updated:** [February 16, 2024, 5:51pm UTC](https://discuss.elastic.co/t/logstash-filter-fingerprint-failing-intermittently/353317 "2024-02-16T17:51:27Z")

</div>

My pipeline starts up fine and eventually fails for this error, and has only happened twice in a long period of time, but I would like to understand what is the issue. Getting the following error: Pipeline worker error…

---

## [Multipipeline Sending data to wrong index](https://discuss.elastic.co/t/multipipeline-sending-data-to-wrong-index/353428)

<div class="topic-metadata">

**Author:** [@dro](https://discuss.elastic.co/u/dro)\
**Replies:** 2\
**Last updated:** [February 16, 2024, 5:22pm UTC](https://discuss.elastic.co/t/multipipeline-sending-data-to-wrong-index/353428 "2024-02-16T17:22:29Z")

</div>

Hello all, I am trying to implement multiple pipelines, but it appears the output of one is being sent to two indices; its own and the other pipelines. $logstash --version Using bundled JDK: /usr/share/logstash/jdk logs…

---

## [Syslog output plugin message parameter ignored](https://discuss.elastic.co/t/syslog-output-plugin-message-parameter-ignored/352560)

<div class="topic-metadata">

**Author:** [@mutt13y](https://discuss.elastic.co/u/mutt13y)\
**Replies:** 3\
**Last updated:** [February 16, 2024, 5:22pm UTC](https://discuss.elastic.co/t/syslog-output-plugin-message-parameter-ignored/352560 "2024-02-16T17:22:14Z")

</div>

the message parameter for the syslog output plugin is documented as used to set the syslog message (default "%{message}") The parameter is defined here logstash-output-syslog/lib/logstash/outputs/syslog.rb at main · log…

---

## [FATAL Error: Cannot find module '../../../../packages/kbn-config-schema'](https://discuss.elastic.co/t/fatal-error-cannot-find-module-packages-kbn-config-schema/353481)

<div class="topic-metadata">

**Author:** [@trosagnant](https://discuss.elastic.co/u/trosagnant)\
**Replies:** 0\
**Last updated:** [February 16, 2024, 3:57pm UTC](https://discuss.elastic.co/t/fatal-error-cannot-find-module-packages-kbn-config-schema/353481 "2024-02-16T15:57:28Z")

</div>

ELK version: 8.5.3 yarn version: 1.22.19 So I'm developing a Kibana plugin and whenever I need to call @kbn/config-schema inside of it, I get the fatal error on Kibana startup after installation of said plugin (pasted …

---

## [Cannot expose Enterprise Search together with Kibana and Elasticsearch using Ingress controller - ESS POD crashes](https://discuss.elastic.co/t/cannot-expose-enterprise-search-together-with-kibana-and-elasticsearch-using-ingress-controller-ess-pod-crashes/353480)

<div class="topic-metadata">

**Author:** [@sebastianboelling](https://discuss.elastic.co/u/sebastianboelling)\
**Replies:** 0\
**Last updated:** [February 16, 2024, 3:50pm UTC](https://discuss.elastic.co/t/cannot-expose-enterprise-search-together-with-kibana-and-elasticsearch-using-ingress-controller-ess-pod-crashes/353480 "2024-02-16T15:50:18Z")

</div>

Hi all, I am using ECK 2.9.0. I'll try to set up a cluster containt Elasticsearch, Kibana and Enterprise Search. The cluster runs well. No I want ro expose Elasticsearch, Kibana and Enterprise Search via Ingress contro…

---

## [Elastic agent an system Integrations generate infinite void indixes with infinite rollover](https://discuss.elastic.co/t/elastic-agent-an-system-integrations-generate-infinite-void-indixes-with-infinite-rollover/353478)

<div class="topic-metadata">

**Author:** [@hectorGC](https://discuss.elastic.co/u/hectorGC)\
**Replies:** 0\
**Last updated:** [February 16, 2024, 3:36pm UTC](https://discuss.elastic.co/t/elastic-agent-an-system-integrations-generate-infinite-void-indixes-with-infinite-rollover/353478 "2024-02-16T15:36:00Z")

</div>

Suddenly after normal work of the team we suffered a big amount of metrics logs, looking at that we discovered that the integrations of elastic-agent and system indexes started to make rollover of all namespaces. Continu…

---

## [Integrating Panorama (Palo Alto tool) logs to ElasticSearch](https://discuss.elastic.co/t/integrating-panorama-palo-alto-tool-logs-to-elasticsearch/353476)

<div class="topic-metadata">

**Author:** [@anoman](https://discuss.elastic.co/u/anoman)\
**Replies:** 0\
**Last updated:** [February 16, 2024, 3:02pm UTC](https://discuss.elastic.co/t/integrating-panorama-palo-alto-tool-logs-to-elasticsearch/353476 "2024-02-16T15:02:39Z")

</div>

Hello, I have been looking for documentation or steps on how to integrate firewall log from palo alto product panorama. I have tried the steps i found for integration for palo alto next generation firewall but that didn…

---

## [Once Filebeat/Elasticsearch has ingested log files, can the logs themselves be deleted?](https://discuss.elastic.co/t/once-filebeat-elasticsearch-has-ingested-log-files-can-the-logs-themselves-be-deleted/353473)

<div class="topic-metadata">

**Author:** [@artschooldropout](https://discuss.elastic.co/u/artschooldropout)\
**Replies:** 2\
**Last updated:** [February 16, 2024, 2:49pm UTC](https://discuss.elastic.co/t/once-filebeat-elasticsearch-has-ingested-log-files-can-the-logs-themselves-be-deleted/353473 "2024-02-16T14:49:37Z")

</div>

I'm using Filebeat/Elasticsearch to index Zeek network traffic logs. I'm missing a key piece of understanding about Filebeat/Elasticsearch. Once the logs have been ingested and indexed, are the logs themselves accessed t…

---

## [Lens - No results found](https://discuss.elastic.co/t/lens-no-results-found/353306)

<div class="topic-metadata">

**Author:** [@erikg](https://discuss.elastic.co/u/erikg)\
**Replies:** 6\
**Last updated:** [February 16, 2024, 2:35pm UTC](https://discuss.elastic.co/t/lens-no-results-found/353306 "2024-02-16T14:35:42Z")

</div>

Hello, So I made a bar vertically stacked graph, when there's data it populates the graph based on the time interval. This is expected behavior. The problem is if there's no data then it shows "no results found", t…

---

## [Revent Windows Service Changes c:\\programdata\\?](https://discuss.elastic.co/t/revent-windows-service-changes-c-programdata/353423)

<div class="topic-metadata">

**Author:** [@Aaron\_C\_de\_Bruyn](https://discuss.elastic.co/u/Aaron_C_de_Bruyn)\
**Replies:** 4\
**Last updated:** [February 16, 2024, 2:33pm UTC](https://discuss.elastic.co/t/revent-windows-service-changes-c-programdata/353423 "2024-02-16T14:33:38Z")

</div>

I just updated Winlogbeat on a Windows Server from 8.9.2 to 8.12.1 and the winlogbeat service won't start. I did some quick digging, and the service runs: "C:\\Program Files\\Elastic\\Beats\\8.12.1\\winlogbeat\\winlogbeat.ex…

---

## [Issue with Filebeat Zeek module](https://discuss.elastic.co/t/issue-with-filebeat-zeek-module/353458)

<div class="topic-metadata">

**Author:** [@OwenGauci](https://discuss.elastic.co/u/OwenGauci)\
**Replies:** 17\
**Last updated:** [February 16, 2024, 2:32pm UTC](https://discuss.elastic.co/t/issue-with-filebeat-zeek-module/353458 "2024-02-16T14:32:31Z")

</div>

Hi, I Installed Zeek on an Ubuntu 22 VM and would like to send logs to Elasticsearch/Kibana using Filebeat. I followed Zeek Logs Intergation Tutorial but it's not able to send the logs. These are on separate Ubuntu 22 VM…

---

## [When filebeat logs are deleted, does this delete Elasticsearch indices?](https://discuss.elastic.co/t/when-filebeat-logs-are-deleted-does-this-delete-elasticsearch-indices/353408)

<div class="topic-metadata">

**Author:** [@artschooldropout](https://discuss.elastic.co/u/artschooldropout)\
**Replies:** 5\
**Last updated:** [February 16, 2024, 2:21pm UTC](https://discuss.elastic.co/t/when-filebeat-logs-are-deleted-does-this-delete-elasticsearch-indices/353408 "2024-02-16T14:21:52Z")

</div>

I have an elasticsearch cluster which ingests logs from Filebeat. I'm trying to limit the total size of the indices. If I delete the raw files that filebeat is ingesting, will the corresponding Elasticsearch indices be d…

---

## [Very uneven distribution of docs accross shards](https://discuss.elastic.co/t/very-uneven-distribution-of-docs-accross-shards/353463)

<div class="topic-metadata">

**Author:** [@Emil](https://discuss.elastic.co/u/Emil)\
**Replies:** 8\
**Last updated:** [February 16, 2024, 1:30pm UTC](https://discuss.elastic.co/t/very-uneven-distribution-of-docs-accross-shards/353463 "2024-02-16T13:30:44Z")

</div>

We've been indexing documents to an index with 20 primary shards, but the shards have grown to have uneven sizes (smallest is 3.2 GB, largest 31.7GB, so 10 times as large) Investigating, I found out that while the total…

---

## [Can i use NLP (Question answer) on structured data?](https://discuss.elastic.co/t/can-i-use-nlp-question-answer-on-structured-data/352596)

<div class="topic-metadata">

**Author:** [@9d224d4833094bd482cf](https://discuss.elastic.co/u/9d224d4833094bd482cf)\
**Replies:** 6\
**Last updated:** [February 16, 2024, 1:09pm UTC](https://discuss.elastic.co/t/can-i-use-nlp-question-answer-on-structured-data/352596 "2024-02-16T13:09:01Z")

</div>

We are using Elasticsearch database. We are planning to provide global search with lot of filters. Our data is mostly structured and there are built in relationships. Having many filters on global search can create usabi…

---

## [Elastic Search 2.4.1 Windows Service](https://discuss.elastic.co/t/elastic-search-2-4-1-windows-service/353453)

<div class="topic-metadata">

**Author:** [@Franco.dicarlo](https://discuss.elastic.co/u/Franco.dicarlo)\
**Replies:** 1\
**Last updated:** [February 16, 2024, 12:46pm UTC](https://discuss.elastic.co/t/elastic-search-2-4-1-windows-service/353453 "2024-02-16T12:46:23Z")

</div>

Hi to all, I have a 2.4.1 Elastic Search installed as a service on a windows server. I was working with ES in c#, I was trying to delete items in a specific index. Unfortunately I deleted more data than necessary,I im…

[Previous page](https://discuss.elastic.co/latest.md?page=397)

[Next page](https://discuss.elastic.co/latest.md?page=399)
