# Latest

**URL:** https://discuss.elastic.co/latest.md?page=400

[Latest](https://discuss.elastic.co/latest.md) · [Categories](https://discuss.elastic.co/categories.md) · [Tags](https://discuss.elastic.co/tags.md)

**Page:** 401

---

## [Kibana and React](https://discuss.elastic.co/t/kibana-and-react/353342)

<div class="topic-metadata">

**Author:** [@Anteneh\_Mulu](https://discuss.elastic.co/u/Anteneh_Mulu)\
**Replies:** 1\
**Last updated:** [February 15, 2024, 12:38pm UTC](https://discuss.elastic.co/t/kibana-and-react/353342 "2024-02-15T12:38:30Z")

</div>

Hey,is it possible to add react UI(eg.Registration form or button) to kibana visualization?

---

## [Kibana won't up](https://discuss.elastic.co/t/kibana-wont-up/352648)

<div class="topic-metadata">

**Author:** [@sanjeev1895](https://discuss.elastic.co/u/sanjeev1895)\
**Replies:** 4\
**Last updated:** [February 15, 2024, 12:19pm UTC](https://discuss.elastic.co/t/kibana-wont-up/352648 "2024-02-15T12:19:49Z")

</div>

Hi, few month back I was configured the elk stack on aws ubuntu instance and it's works fine without any issue. But due to some VPC related reason, I was taken the AMI from that elk stack instance and launched the new i…

---

## [Elastic Agent installation on the window server 2012 r2](https://discuss.elastic.co/t/elastic-agent-installation-on-the-window-server-2012-r2/353364)

<div class="topic-metadata">

**Author:** [@Yogesh\_AS](https://discuss.elastic.co/u/Yogesh_AS)\
**Replies:** 1\
**Last updated:** [February 15, 2024, 12:15pm UTC](https://discuss.elastic.co/t/elastic-agent-installation-on-the-window-server-2012-r2/353364 "2024-02-15T12:15:12Z")

</div>

Hi All, I am installing the elastic agent in windows server r2 2012 edition where I am facing issue is I am unable to see the CPU and memory metrices in fleet management. please help me out to resolve issues but when I…

---

## [Moving avg counts](https://discuss.elastic.co/t/moving-avg-counts/353367)

<div class="topic-metadata">

**Author:** [@2328943\_dc](https://discuss.elastic.co/u/2328943_dc)\
**Replies:** 1\
**Last updated:** [February 15, 2024, 12:13pm UTC](https://discuss.elastic.co/t/moving-avg-counts/353367 "2024-02-15T12:13:39Z")

</div>

we have created visualization to fetch counts average count but as attached in screenshot for in place of highlighted field we want previous timeframes average count so,...is it possible to find count lik this?

---

## [Array in Response](https://discuss.elastic.co/t/array-in-response/353334)

<div class="topic-metadata">

**Author:** [@Shreya\_Chandak](https://discuss.elastic.co/u/Shreya_Chandak)\
**Replies:** 1\
**Last updated:** [February 15, 2024, 11:04am UTC](https://discuss.elastic.co/t/array-in-response/353334 "2024-02-15T11:04:06Z")

</div>

Hello Community , I am new to querying elastic , there is a requirement -\> I have logs on elk with field names request(string) and average response time (Number) , I want to first specify a date\_range in query and find …

---

## [To solve an error](https://discuss.elastic.co/t/to-solve-an-error/353339)

<div class="topic-metadata">

**Author:** [@With\_Ayush](https://discuss.elastic.co/u/With_Ayush)\
**Replies:** 1\
**Last updated:** [February 15, 2024, 10:58am UTC](https://discuss.elastic.co/t/to-solve-an-error/353339 "2024-02-15T10:58:58Z")

</div>

Facing this error. Please help me resolve, Error updating document with EventID ': AuthorizationException(403, security exception", "action \[Indices:data/read/get\] is unauthorized for user \[user\] with roles \[viewer, su…

---

## [Heartbeat on Docker not receiving logs in Kibana](https://discuss.elastic.co/t/heartbeat-on-docker-not-receiving-logs-in-kibana/353130)

<div class="topic-metadata">

**Author:** [@roman-tasi](https://discuss.elastic.co/u/roman-tasi)\
**Replies:** 5\
**Last updated:** [February 15, 2024, 10:57am UTC](https://discuss.elastic.co/t/heartbeat-on-docker-not-receiving-logs-in-kibana/353130 "2024-02-15T10:57:43Z")

</div>

This is my config: heartbeat.monitors: - type: http enabled: true schedule: '@every 10s' urls: \["http://localhost:9200"\] # Elasticsearch - type: tcp enabled: true schedule: '@every 10s' hosts: \["localhost:5…

---

## [Upgrade version from 2 to 7](https://discuss.elastic.co/t/upgrade-version-from-2-to-7/353346)

<div class="topic-metadata">

**Author:** [@nicdnepr](https://discuss.elastic.co/u/nicdnepr)\
**Replies:** 1\
**Last updated:** [February 15, 2024, 10:56am UTC](https://discuss.elastic.co/t/upgrade-version-from-2-to-7/353346 "2024-02-15T10:56:57Z")

</div>

I moved site to new server, and my new elastic version is 7.9.2 and old version is 2.3.5 I use this command to move indexes elasticdump --input=http://localhost:9200/nut\_uk --output=nut\_uk\_mapping.json --type=mappin…

---

## [NOT ABLE TO INDEX DATA USING HTTP POLLER](https://discuss.elastic.co/t/not-able-to-index-data-using-http-poller/353251)

<div class="topic-metadata">

**Author:** [@rajatbhardwaj1393](https://discuss.elastic.co/u/rajatbhardwaj1393)\
**Replies:** 12\
**Last updated:** [February 15, 2024, 10:37am UTC](https://discuss.elastic.co/t/not-able-to-index-data-using-http-poller/353251 "2024-02-15T10:37:10Z")

</div>

want to index data from the third party api. trying to index data from response but the data is coming as array of results and ruby code below is not storing it as individual event. Can someone suggest what i am doing w…

---

## [S3 compatible with repository\_verification\_exception](https://discuss.elastic.co/t/s3-compatible-with-repository-verification-exception/353360)

<div class="topic-metadata">

**Author:** [@Omizollo](https://discuss.elastic.co/u/Omizollo)\
**Replies:** 0\
**Last updated:** [February 15, 2024, 10:31am UTC](https://discuss.elastic.co/t/s3-compatible-with-repository-verification-exception/353360 "2024-02-15T10:31:32Z")

</div>

I have a custom s3 storage which I can communicate with using AWS sdk. I have configured the repository with Elasticsearch v7.17 and it is working fine, but after upgrade to the version v8.11 the verification to the repo…

---

## [Shard routing while active indexing](https://discuss.elastic.co/t/shard-routing-while-active-indexing/353326)

<div class="topic-metadata">

**Author:** [@Prashant\_Rana](https://discuss.elastic.co/u/Prashant_Rana)\
**Replies:** 3\
**Last updated:** [February 15, 2024, 10:27am UTC](https://discuss.elastic.co/t/shard-routing-while-active-indexing/353326 "2024-02-15T10:27:06Z")

</div>

What happens if I explicitly route a shard to a different node while the indexing happens to that shard in the original shard? Should I stop indexing in that shard?

---

## [ResposeError: illegal\_argument\_exception when create SLO](https://discuss.elastic.co/t/resposeerror-illegal-argument-exception-when-create-slo/353135)

<div class="topic-metadata">

**Author:** [@01052346103a](https://discuss.elastic.co/u/01052346103a)\
**Replies:** 2\
**Last updated:** [February 15, 2024, 10:16am UTC](https://discuss.elastic.co/t/resposeerror-illegal-argument-exception-when-create-slo/353135 "2024-02-15T10:16:01Z")

</div>

Hi i got error when i create SLO with Kibana UI I have no idea what to do solve this problem ES v8.11.4 Kibana v8.11.4 \[2024-02-13T16:08:55.366+09:00\]\[ERROR\]\[plugins.observability\] Cannot preview SLO transform \[slo-b…

---

## [EUI ":first-child" warning help](https://discuss.elastic.co/t/eui-first-child-warning-help/353083)

<div class="topic-metadata">

**Author:** [@David10](https://discuss.elastic.co/u/David10)\
**Replies:** 3\
**Last updated:** [February 15, 2024, 10:02am UTC](https://discuss.elastic.co/t/eui-first-child-warning-help/353083 "2024-02-15T10:02:28Z")

</div>

Hello, I've been receiving the following warning everytime I insert an tag within my plugin: "The pseudo class ":first-child" is potentially unsafe when doing server-side rendering. Try changing it to ":first-of-type".…

---

## [Elastic dashboard in Kiosk mode](https://discuss.elastic.co/t/elastic-dashboard-in-kiosk-mode/353093)

<div class="topic-metadata">

**Author:** [@gnatola](https://discuss.elastic.co/u/gnatola)\
**Replies:** 3\
**Last updated:** [February 15, 2024, 9:53am UTC](https://discuss.elastic.co/t/elastic-dashboard-in-kiosk-mode/353093 "2024-02-15T09:53:55Z")

</div>

I have a dashboard read-only user. Is there a way to configure this dashboard in kiosk mode so the user gets automatically logged in? Thanks.

---

## [How to get list of installed software/products from windows Server?](https://discuss.elastic.co/t/how-to-get-list-of-installed-software-products-from-windows-server/353088)

<div class="topic-metadata">

**Author:** [@Padam](https://discuss.elastic.co/u/Padam)\
**Replies:** 2\
**Last updated:** [February 15, 2024, 9:38am UTC](https://discuss.elastic.co/t/how-to-get-list-of-installed-software-products-from-windows-server/353088 "2024-02-15T09:38:51Z")

</div>

Hi All, Greetings!!! Could you please help me to get all list products/ software, version and their EOL details?

---

## [Is LSCL documented?](https://discuss.elastic.co/t/is-lscl-documented/353178)

<div class="topic-metadata">

**Author:** [@joostdecock](https://discuss.elastic.co/u/joostdecock)\
**Replies:** 2\
**Last updated:** [February 15, 2024, 8:36am UTC](https://discuss.elastic.co/t/is-lscl-documented/353178 "2024-02-15T08:36:53Z")

</div>

Hi all, I am looking for documentation on LSCL, the logstash configuration language. The one that inputs and pipelines are written in and looks like this: input { kafka { id =\> "whatever" } } I'm in a situatio…

---

## [Cluster.initial\_master\_nodes Settings](https://discuss.elastic.co/t/cluster-initial-master-nodes-settings/353303)

<div class="topic-metadata">

**Author:** [@pras](https://discuss.elastic.co/u/pras)\
**Replies:** 2\
**Last updated:** [February 15, 2024, 8:25am UTC](https://discuss.elastic.co/t/cluster-initial-master-nodes-settings/353303 "2024-02-15T08:25:46Z")

</div>

Hi guys I have three node cluster using Elastic 8.6. It is in operation for more than a year. We are going to upgrade to 8.8 soon. I this regard I have a question on cluster.initial\_master\_nodes setting. This setting is…

---

## [Elasticsearch and Kibana upgrade to v8.12.0 from v8.0.0](https://discuss.elastic.co/t/elasticsearch-and-kibana-upgrade-to-v8-12-0-from-v8-0-0/353170)

<div class="topic-metadata">

**Author:** [@Gaurav\_kr](https://discuss.elastic.co/u/Gaurav_kr)\
**Replies:** 3\
**Last updated:** [February 15, 2024, 8:18am UTC](https://discuss.elastic.co/t/elasticsearch-and-kibana-upgrade-to-v8-12-0-from-v8-0-0/353170 "2024-02-15T08:18:45Z")

</div>

Hi Team, We are planning to upgrade elasticsearch and Kibana to v8.12.0 from v8.0.0 For beats and ELK communication wea re using ssl true and we are using API key in yaml file of beats like metricbeat. Wanted to know …

---

## [Beats v8.12.0 use with ELK v8.0.0](https://discuss.elastic.co/t/beats-v8-12-0-use-with-elk-v8-0-0/353063)

<div class="topic-metadata">

**Author:** [@Gaurav\_kr](https://discuss.elastic.co/u/Gaurav_kr)\
**Replies:** 2\
**Last updated:** [February 15, 2024, 8:14am UTC](https://discuss.elastic.co/t/beats-v8-12-0-use-with-elk-v8-0-0/353063 "2024-02-15T08:14:01Z")

</div>

Hi Team, Could anyone help on below scenario. I am using elasticsearch and Kibana of v8.0.0 docker image and wanted to use beats of v8.12.0 of windows (not docker) I do have docker images for beats on few linux machin…

---

## [Sending logs in a my pattern to Logstash via TCP](https://discuss.elastic.co/t/sending-logs-in-a-my-pattern-to-logstash-via-tcp/353336)

<div class="topic-metadata">

**Author:** [@kypdk](https://discuss.elastic.co/u/kypdk)\
**Replies:** 0\
**Last updated:** [February 15, 2024, 7:43am UTC](https://discuss.elastic.co/t/sending-logs-in-a-my-pattern-to-logstash-via-tcp/353336 "2024-02-15T07:43:15Z")

</div>

%d{yyyy-MM-dd HH:mm:ss.SSS} \[%t\] %-5level %logger{36} - %X{requestId} %msg%n%exception{full} in this pattern Can I send to logstash over TCP in json format? I don't want to do xml configuration. I will make all the ad…

---

## [Macro in Elastic](https://discuss.elastic.co/t/macro-in-elastic/353276)

<div class="topic-metadata">

**Author:** [@rachelei](https://discuss.elastic.co/u/rachelei)\
**Replies:** 2\
**Last updated:** [February 15, 2024, 7:57am UTC](https://discuss.elastic.co/t/macro-in-elastic/353276 "2024-02-15T07:57:28Z")

</div>

We use macros stored in many queries to easily read the data and any change we need to make in the logic, we make the change in only one place and there is no need to access all the places that use the same logic to chan…

---

## [Create ILM on the timestamp field](https://discuss.elastic.co/t/create-ilm-on-the-timestamp-field/353172)

<div class="topic-metadata">

**Author:** [@Debasis\_Mallick](https://discuss.elastic.co/u/Debasis_Mallick)\
**Replies:** 4\
**Last updated:** [February 15, 2024, 7:12am UTC](https://discuss.elastic.co/t/create-ilm-on-the-timestamp-field/353172 "2024-02-15T07:12:52Z")

</div>

Hi Team, I want to create a ILM on the timestamp field (which received as field in the log file itself as epoch time). So I want create the ILM on basis of that field. Could you please let me know how we can achieve the…

---

## [Why my query cannot return any result althought the key exist in the message](https://discuss.elastic.co/t/why-my-query-cannot-return-any-result-althought-the-key-exist-in-the-message/353330)

<div class="topic-metadata">

**Author:** [@baber1223](https://discuss.elastic.co/u/baber1223)\
**Replies:** 1\
**Last updated:** [February 15, 2024, 6:44am UTC](https://discuss.elastic.co/t/why-my-query-cannot-return-any-result-althought-the-key-exist-in-the-message/353330 "2024-02-15T06:44:21Z")

</div>

Dear Hi This is my log sample \<log realm="channel/192.168.20.10:61615" at="2024-02-14T15:25:04.930" lifespan="383ms"\> \<receive\> \<isomsg direction="incoming"\> \<!-- com.middle.gateway.packager.ShetabISO87APa…

---

## [Increase in container memory with logstash 8.11.3 version](https://discuss.elastic.co/t/increase-in-container-memory-with-logstash-8-11-3-version/353225)

<div class="topic-metadata">

**Author:** [@Nikhitha\_Karennagari](https://discuss.elastic.co/u/Nikhitha_Karennagari)\
**Replies:** 1\
**Last updated:** [February 15, 2024, 4:48am UTC](https://discuss.elastic.co/t/increase-in-container-memory-with-logstash-8-11-3-version/353225 "2024-02-15T04:48:39Z")

</div>

Hi, There is gradual increase in container memory in our service which uses logstash 8.11.3. Due to this the container may go to OOM kill within a few days and our service may crash.Can anyone suggest if there is any b…

---

## [Date Variable on index name](https://discuss.elastic.co/t/date-variable-on-index-name/353321)

<div class="topic-metadata">

**Author:** [@yuswanul](https://discuss.elastic.co/u/yuswanul)\
**Replies:** 3\
**Last updated:** [February 15, 2024, 4:35am UTC](https://discuss.elastic.co/t/date-variable-on-index-name/353321 "2024-02-15T04:35:23Z")

</div>

Hello there, I'm curious when there's a pipeline with configured output like this: index =\> "log-%{+YYYY.MM.dd}" where is the date variable referring to? the timestamp on the log, or the timestamp of the logstash se…

---

## [Question about ILM Delete phrase](https://discuss.elastic.co/t/question-about-ilm-delete-phrase/353319)

<div class="topic-metadata">

**Author:** [@JasonREC](https://discuss.elastic.co/u/JasonREC)\
**Replies:** 0\
**Last updated:** [February 15, 2024, 3:14am UTC](https://discuss.elastic.co/t/question-about-ilm-delete-phrase/353319 "2024-02-15T03:14:50Z")

</div>

Hi, I have a question about the delete phrase in ILM. I have the ILM policy set when the max 15gb limit is reached in the primary shard then do the roll over and then I want that index to be completely deleted after 3 m…

---

## [Can I use these step to generate elastic search root-ca.pem](https://discuss.elastic.co/t/can-i-use-these-step-to-generate-elastic-search-root-ca-pem/353238)

<div class="topic-metadata">

**Author:** [@fahim2024](https://discuss.elastic.co/u/fahim2024)\
**Replies:** 1\
**Last updated:** [February 15, 2024, 1:20am UTC](https://discuss.elastic.co/t/can-i-use-these-step-to-generate-elastic-search-root-ca-pem/353238 "2024-02-15T01:20:02Z")

</div>

./elasticsearch-certutil ca ./elasticsearch-certutil cert --ca elastic-stack-ca.p12 openssl pkcs12 -in elastic-certificates.p12 -clcerts -nokeys -out certificate.pem openssl pkcs12 -in elastic-certificates.p12 -nocert…

---

## [Unresolved or ambiguous specs during Gem::Specification.reset: date (\>= 0), but cannot run gem command to resolve](https://discuss.elastic.co/t/unresolved-or-ambiguous-specs-during-gem-specification-reset-date-0-but-cannot-run-gem-command-to-resolve/351931)

<div class="topic-metadata">

**Author:** [@hughjarse](https://discuss.elastic.co/u/hughjarse)\
**Replies:** 2\
**Last updated:** [February 15, 2024, 1:17am UTC](https://discuss.elastic.co/t/unresolved-or-ambiguous-specs-during-gem-specification-reset-date-0-but-cannot-run-gem-command-to-resolve/351931 "2024-02-15T01:17:52Z")

</div>

Running the logstash-plugin list or logstash-plugin install commands cause the following error. How can I troubleshoot and resolve this problem with the gem command that is built into Logstash? WARN: Unresolved or ambig…

---

## [Kibana: Commonly use - Yesterday is missing](https://discuss.elastic.co/t/kibana-commonly-use-yesterday-is-missing/353055)

<div class="topic-metadata">

**Author:** [@CargoBikoMeter](https://discuss.elastic.co/u/CargoBikoMeter)\
**Replies:** 3\
**Last updated:** [February 14, 2024, 9:03pm UTC](https://discuss.elastic.co/t/kibana-commonly-use-yesterday-is-missing/353055 "2024-02-14T21:03:47Z")

</div>

It would be nice to have an entry "Yesterday" in the field "Commonly used" in the Kibana time window. Why does such entry not already exists? I use Kibana 7.17.16.

---

## [Fleet on GKE (ECK) behind a Google LB 502 errors](https://discuss.elastic.co/t/fleet-on-gke-eck-behind-a-google-lb-502-errors/353309)

<div class="topic-metadata">

**Author:** [@trudesea](https://discuss.elastic.co/u/trudesea)\
**Replies:** 0\
**Last updated:** [February 14, 2024, 8:36pm UTC](https://discuss.elastic.co/t/fleet-on-gke-eck-behind-a-google-lb-502-errors/353309 "2024-02-14T20:36:40Z")

</div>

Preformatted texto we run Elastic on GKE using ECK. We are on version 8.12. I just installed the Fleet server yesterday with 4 replicas and they are sitting behind a GCP classic http LB. The servers can be seen on the f…

[Previous page](https://discuss.elastic.co/latest.md?page=399)

[Next page](https://discuss.elastic.co/latest.md?page=401)
