# Latest

**URL:** https://discuss.elastic.co/latest.md?page=402

[Latest](https://discuss.elastic.co/latest.md) · [Categories](https://discuss.elastic.co/categories.md) · [Tags](https://discuss.elastic.co/tags.md)

**Page:** 403

---

## [Kibana dashboard values changing indicators](https://discuss.elastic.co/t/kibana-dashboard-values-changing-indicators/352734)

<div class="topic-metadata">

**Author:** [@SamehSaeed](https://discuss.elastic.co/u/SamehSaeed)\
**Replies:** 5\
**Last updated:** [February 14, 2024, 8:58am UTC](https://discuss.elastic.co/t/kibana-dashboard-values-changing-indicators/352734 "2024-02-14T08:58:39Z")

</div>

Hello, I have a dashboard with a "table" panel (lens) which have over 100 rows, each with count of success and failure for each row (service). How can i add an indicator in that can show whether these values have change…

---

## [Registry writes slowing down filebeat](https://discuss.elastic.co/t/registry-writes-slowing-down-filebeat/353092)

<div class="topic-metadata">

**Author:** [@pces](https://discuss.elastic.co/u/pces)\
**Replies:** 4\
**Last updated:** [February 14, 2024, 8:36am UTC](https://discuss.elastic.co/t/registry-writes-slowing-down-filebeat/353092 "2024-02-14T08:36:43Z")

</div>

Hello, During a performance test, we put ~30000 files of 2.8mb each in the folder from where filebeat reads. Over a period of time, the indexing rate slowed down. All best practices followed, like index refresh set to …

---

## [Logstash upgrade issue](https://discuss.elastic.co/t/logstash-upgrade-issue/353154)

<div class="topic-metadata">

**Author:** [@mansoorpn](https://discuss.elastic.co/u/mansoorpn)\
**Replies:** 6\
**Last updated:** [February 14, 2024, 8:33am UTC](https://discuss.elastic.co/t/logstash-upgrade-issue/353154 "2024-02-14T08:33:00Z")

</div>

Hello Team, We have an IOT device and the logs generated from this device are received by a logstash instance as input and sent the same logs to the cloudamqp queue as output. Working condition -- \> Logstash version 6.…

---

## [Elasticsearch\[7.7\] Does not update data or takes time to update the data](https://discuss.elastic.co/t/elasticsearch-7-7-does-not-update-data-or-takes-time-to-update-the-data/353085)

<div class="topic-metadata">

**Author:** [@Akki\_Kulkarni](https://discuss.elastic.co/u/Akki_Kulkarni)\
**Replies:** 7\
**Last updated:** [February 14, 2024, 8:30am UTC](https://discuss.elastic.co/t/elasticsearch-7-7-does-not-update-data-or-takes-time-to-update-the-data/353085 "2024-02-14T08:30:27Z")

</div>

In my application, we are updating more than one document at a time for a index\_x. When queried for updated documents, it does not return updated data for few document, immediately. e.g. If I am updating 10 documents, 1 …

---

## [ERROR Kibana logs](https://discuss.elastic.co/t/error-kibana-logs/353241)

<div class="topic-metadata">

**Author:** [@San9](https://discuss.elastic.co/u/San9)\
**Replies:** 0\
**Last updated:** [February 14, 2024, 8:24am UTC](https://discuss.elastic.co/t/error-kibana-logs/353241 "2024-02-14T08:24:48Z")

</div>

Hi Team! I have errors in the Kibana logs after the update (and not only): \[2024-02-14T07:46:10.616+00:00\]\[ERROR\]\[plugins.alerting.xpack.synthetics.alerts.tls\] Executing Rule default:xpack.synthetics.alerts.tls:93e8500…

---

## [How to get metrics from nodejs process](https://discuss.elastic.co/t/how-to-get-metrics-from-nodejs-process/353193)

<div class="topic-metadata">

**Author:** [@rschirin](https://discuss.elastic.co/u/rschirin)\
**Replies:** 1\
**Last updated:** [February 14, 2024, 6:59am UTC](https://discuss.elastic.co/t/how-to-get-metrics-from-nodejs-process/353193 "2024-02-14T06:59:43Z")

</div>

Hey there, is there a way using Metricbeat v8.12.x to get metrics from a specific process endpoint (i.e. /metrics)? Below a short list of them: process\_virtual\_memory\_bytes 43687911424 process\_heap\_bytes 362074112 pro…

---

## [Ingest Rate in Elasticsearch is Slow](https://discuss.elastic.co/t/ingest-rate-in-elasticsearch-is-slow/352820)

<div class="topic-metadata">

**Author:** [@Debasis\_Mallick](https://discuss.elastic.co/u/Debasis_Mallick)\
**Replies:** 9\
**Last updated:** [February 14, 2024, 6:47am UTC](https://discuss.elastic.co/t/ingest-rate-in-elasticsearch-is-slow/352820 "2024-02-14T06:47:08Z")

</div>

Hi Team, We had scenario where we want to load 1 billion data to elastic cluster (consists of two node) and this process we are doing through filebeat process. As per Kibana dashboard we are checking it is below 5k/s . …

---

## [Download from Kibana is giving irrelevant rows not downloading based on the filter applied why](https://discuss.elastic.co/t/download-from-kibana-is-giving-irrelevant-rows-not-downloading-based-on-the-filter-applied-why/353231)

<div class="topic-metadata">

**Author:** [@Shahid\_Pasha](https://discuss.elastic.co/u/Shahid_Pasha)\
**Replies:** 0\
**Last updated:** [February 14, 2024, 6:45am UTC](https://discuss.elastic.co/t/download-from-kibana-is-giving-irrelevant-rows-not-downloading-based-on-the-filter-applied-why/353231 "2024-02-14T06:45:36Z")

</div>

Download from Kibana is giving irrelevant rows not downloading based on the filter applied why

---

## [Data Ingestion in Elastic Search](https://discuss.elastic.co/t/data-ingestion-in-elastic-search/353189)

<div class="topic-metadata">

**Author:** [@fatima1](https://discuss.elastic.co/u/fatima1)\
**Replies:** 3\
**Last updated:** [February 14, 2024, 6:26am UTC](https://discuss.elastic.co/t/data-ingestion-in-elastic-search/353189 "2024-02-14T06:26:39Z")

</div>

Can someone provide guidance on the process of ingesting data into Elastic Search using Logstash from MongoDB and then visualizing it in Siren? I would appreciate any assistance or guidance on this matter. Thank you.

---

## [Multiple small Index vs Single Index](https://discuss.elastic.co/t/multiple-small-index-vs-single-index/353168)

<div class="topic-metadata">

**Author:** [@Lovin\_Saini](https://discuss.elastic.co/u/Lovin_Saini)\
**Replies:** 2\
**Last updated:** [February 14, 2024, 5:29am UTC](https://discuss.elastic.co/t/multiple-small-index-vs-single-index/353168 "2024-02-14T05:29:00Z")

</div>

We do have a use case of full text search of application data. There are many clients for which we are going to manage data. Total clients will be around 100 and client data size will be from 1 GB to 50 GB. Data will hav…

---

## [Logstash script adding duplicate data](https://discuss.elastic.co/t/logstash-script-adding-duplicate-data/353223)

<div class="topic-metadata">

**Author:** [@Ritikapawar](https://discuss.elastic.co/u/Ritikapawar)\
**Replies:** 0\
**Last updated:** [February 14, 2024, 5:05am UTC](https://discuss.elastic.co/t/logstash-script-adding-duplicate-data/353223 "2024-02-14T05:05:58Z")

</div>

Hi, I'm uploading php\_error.logs using logstash script but when i run ths script it adds allover data again and again so index is showing count of duplicate data too. how i can avoid that? This is the script which i am…

---

## [Connecting Logstash To Elasticsearch via SSL (Docker Container)](https://discuss.elastic.co/t/connecting-logstash-to-elasticsearch-via-ssl-docker-container/353221)

<div class="topic-metadata">

**Author:** [@Dhiwakar\_Ravikumar](https://discuss.elastic.co/u/Dhiwakar_Ravikumar)\
**Replies:** 0\
**Last updated:** [February 14, 2024, 4:29am UTC](https://discuss.elastic.co/t/connecting-logstash-to-elasticsearch-via-ssl-docker-container/353221 "2024-02-14T04:29:50Z")

</div>

My environment consists of 2 docker containers, one running Logstash and another running Elasticsearch on the SAME host & SAME docker network. I am trying to setup SSL between the 2 of them (this is because Elasticsearc…

---

## [Need help in Vertical bar chart issue in kibana](https://discuss.elastic.co/t/need-help-in-vertical-bar-chart-issue-in-kibana/353220)

<div class="topic-metadata">

**Author:** [@Prasath\_r](https://discuss.elastic.co/u/Prasath_r)\
**Replies:** 0\
**Last updated:** [February 14, 2024, 4:26am UTC](https://discuss.elastic.co/t/need-help-in-vertical-bar-chart-issue-in-kibana/353220 "2024-02-14T04:26:40Z")

</div>

I am also facing the issue reported way back in 2016. Vertical bar chart issue in kibana - Elastic Stack / Kibana - Discuss the Elastic Stack Is there any solution to fix this issue

---

## [Solving too\_many\_nested\_clauses with maxClauseCount set to 1024](https://discuss.elastic.co/t/solving-too-many-nested-clauses-with-maxclausecount-set-to-1024/353218)

<div class="topic-metadata">

**Author:** [@sreekanth\_makam](https://discuss.elastic.co/u/sreekanth_makam)\
**Replies:** 0\
**Last updated:** [February 14, 2024, 4:12am UTC](https://discuss.elastic.co/t/solving-too-many-nested-clauses-with-maxclausecount-set-to-1024/353218 "2024-02-14T04:12:18Z")

</div>

Hi Team, We are hitting below error and we understand that we are hitting this limit somewhere in our query. "too\_many\_nested\_clauses: Query contains too many nested clauses; maxClauseCount is set to 1024" Question: …

---

## [Aggregation based off of nested fields and filtering](https://discuss.elastic.co/t/aggregation-based-off-of-nested-fields-and-filtering/353214)

<div class="topic-metadata">

**Author:** [@jessiditocco](https://discuss.elastic.co/u/jessiditocco)\
**Replies:** 0\
**Last updated:** [February 13, 2024, 10:54pm UTC](https://discuss.elastic.co/t/aggregation-based-off-of-nested-fields-and-filtering/353214 "2024-02-13T22:54:00Z")

</div>

I have an index of Provider documents that look roughly like this: \[ { "slug": "provider1", "name": "dr. evil", "employer\_networks": \[ { "slug": "network-a", …

---

## [Min/Max aggregation in Discover](https://discuss.elastic.co/t/min-max-aggregation-in-discover/353114)

<div class="topic-metadata">

**Author:** [@elementmg](https://discuss.elastic.co/u/elementmg)\
**Replies:** 4\
**Last updated:** [February 13, 2024, 7:37pm UTC](https://discuss.elastic.co/t/min-max-aggregation-in-discover/353114 "2024-02-13T19:37:41Z")

</div>

When utilizing Elasticsearch's Discover feature, I'm aiming to construct a query that fetches the maximum and minimum logs for each user, based on three fields: username, app name, and environment. Currently, my query i…

---

## [Highlighting slows down Kibana searches considerably](https://discuss.elastic.co/t/highlighting-slows-down-kibana-searches-considerably/353089)

<div class="topic-metadata">

**Author:** [@boernd](https://discuss.elastic.co/u/boernd)\
**Replies:** 3\
**Last updated:** [February 13, 2024, 10:19pm UTC](https://discuss.elastic.co/t/highlighting-slows-down-kibana-searches-considerably/353089 "2024-02-13T22:19:29Z")

</div>

Hi, we have Kibana Discover queries in our env where the highlighting functionality seems to have a big impact on the search experience. It is not really clear to me why highlighting is a bottleneck at all for this quer…

---

## [Logstash configurations for v8.12](https://discuss.elastic.co/t/logstash-configurations-for-v8-12/353210)

<div class="topic-metadata">

**Author:** [@prajeet](https://discuss.elastic.co/u/prajeet)\
**Replies:** 1\
**Last updated:** [February 13, 2024, 9:34pm UTC](https://discuss.elastic.co/t/logstash-configurations-for-v8-12/353210 "2024-02-13T21:34:12Z")

</div>

I have installed Elastic, Kibana and Logstash of different linux servers and configured Elastic and kibana with my organization trusted ca. Now, I'm trying to configure logstash to ship from logs from filebeat installed …

---

## [Running logstash](https://discuss.elastic.co/t/running-logstash/352616)

<div class="topic-metadata">

**Author:** [@Fatiha](https://discuss.elastic.co/u/Fatiha)\
**Replies:** 3\
**Last updated:** [February 13, 2024, 9:15pm UTC](https://discuss.elastic.co/t/running-logstash/352616 "2024-02-13T21:15:51Z")

</div>

hi I want to create a project that visualize my data in mysql to kibana but when I run the logstash with this cmd : .\\bin\\logstash -f logstash.conf I find only 81 fields in kibana and some fields are empty …

---

## [Aggregation of individual array elements](https://discuss.elastic.co/t/aggregation-of-individual-array-elements/353207)

<div class="topic-metadata">

**Author:** [@JeremyP](https://discuss.elastic.co/u/JeremyP)\
**Replies:** 0\
**Last updated:** [February 13, 2024, 7:59pm UTC](https://discuss.elastic.co/t/aggregation-of-individual-array-elements/353207 "2024-02-13T19:59:00Z")

</div>

Hello, I need some advice on how to proceed. I'm trying to visualize some trending I have from an asset discovery tool. Each time the asset is discovered a new array element is added the Elasticsearch document. Here is …

---

## [Continous Monitoring of Disk Allocation in Kibana Stack Monitoring](https://discuss.elastic.co/t/continous-monitoring-of-disk-allocation-in-kibana-stack-monitoring/352195)

<div class="topic-metadata">

**Author:** [@ibollman](https://discuss.elastic.co/u/ibollman)\
**Replies:** 12\
**Last updated:** [February 13, 2024, 7:26pm UTC](https://discuss.elastic.co/t/continous-monitoring-of-disk-allocation-in-kibana-stack-monitoring/352195 "2024-02-13T19:26:08Z")

</div>

Hello, we are using Elastic Cloud Enterprise and we send all the Logs and Metrics of our Deployments to a Monitoring cluster we have created just for the cluster monitoring purposes - just as the best practices suggest. …

---

## [Logstash service outputs only a few logs from input file](https://discuss.elastic.co/t/logstash-service-outputs-only-a-few-logs-from-input-file/353183)

<div class="topic-metadata">

**Author:** [@vuvu](https://discuss.elastic.co/u/vuvu)\
**Replies:** 1\
**Last updated:** [February 13, 2024, 7:14pm UTC](https://discuss.elastic.co/t/logstash-service-outputs-only-a-few-logs-from-input-file/353183 "2024-02-13T19:14:58Z")

</div>

hi! Since now, I have started Logstash by running the command: /usr/share/logstash/bin/logstash --path.settings /etc/logstash/ --path.data sensor39 -f /etc/logstash/conf.d/logstash-config.conf and it successfully sent…

---

## [Optimizing ELK with Filebeat: Managing CPU and Memory Utilization](https://discuss.elastic.co/t/optimizing-elk-with-filebeat-managing-cpu-and-memory-utilization/352754)

<div class="topic-metadata">

**Author:** [@Rutuja\_More](https://discuss.elastic.co/u/Rutuja_More)\
**Replies:** 3\
**Last updated:** [February 13, 2024, 7:00pm UTC](https://discuss.elastic.co/t/optimizing-elk-with-filebeat-managing-cpu-and-memory-utilization/352754 "2024-02-13T19:00:07Z")

</div>

I am currently working with Elasticsearch, Logstash, and Kibana (ELK) alongside Filebeat for log ingestion. I am seeking advice on optimizing CPU and memory utilization in my setup. What are some common strategies for …

---

## [devtools.UseCommunityBeatPackaging() has gone missing](https://discuss.elastic.co/t/devtools-usecommunitybeatpackaging-has-gone-missing/353201)

<div class="topic-metadata">

**Author:** [@Lasse\_Johnsen](https://discuss.elastic.co/u/Lasse_Johnsen)\
**Replies:** 0\
**Last updated:** [February 13, 2024, 6:51pm UTC](https://discuss.elastic.co/t/devtools-usecommunitybeatpackaging-has-gone-missing/353201 "2024-02-13T18:51:46Z")

</div>

At Timebeat we build a community beat. It would be great to see more support for this reintroduced. Most if not all community beats have seen no development in 2-3 years except ours. I've noticed that in the latest vers…

---

## [Filebeat and Metricbeat index have tens of thousands of fields](https://discuss.elastic.co/t/filebeat-and-metricbeat-index-have-tens-of-thousands-of-fields/353199)

<div class="topic-metadata">

**Author:** [@rsteed](https://discuss.elastic.co/u/rsteed)\
**Replies:** 0\
**Last updated:** [February 13, 2024, 6:02pm UTC](https://discuss.elastic.co/t/filebeat-and-metricbeat-index-have-tens-of-thousands-of-fields/353199 "2024-02-13T18:02:17Z")

</div>

Currently running Elastic Cloud 8.9.1 Our Filebeat and Metricbeat versions match that for the most part. There are a few older systems that are using 7.13.x beats that feed into our index, but most use the 8.9.1 Our Fi…

---

## [How to use divide() function with field](https://discuss.elastic.co/t/how-to-use-divide-function-with-field/352534)

<div class="topic-metadata">

**Author:** [@rschirin](https://discuss.elastic.co/u/rschirin)\
**Replies:** 3\
**Last updated:** [February 13, 2024, 4:46pm UTC](https://discuss.elastic.co/t/how-to-use-divide-function-with-field/352534 "2024-02-13T16:46:25Z")

</div>

Hey there, I was trying to divide the value of a specific field but I cannot do that since I am facing the error "The operation divide does not accept any field as argument". My field contains only numbers but I cannot…

---

## [Xml parse in logstash](https://discuss.elastic.co/t/xml-parse-in-logstash/352853)

<div class="topic-metadata">

**Author:** [@Ayaan\_Shaik](https://discuss.elastic.co/u/Ayaan_Shaik)\
**Replies:** 9\
**Last updated:** [February 13, 2024, 4:12pm UTC](https://discuss.elastic.co/t/xml-parse-in-logstash/352853 "2024-02-13T16:12:16Z")

</div>

Hi @Badger I'm Trying to parse the log file with below xml \<imm:IMM-contents xmlns:imm="http://www.saforum.org/IMMSchema" xmlns:xsi="http://www.w3.org/2001/XMLSchema-instance" xsi:noNamespaceSchemaLocation="SAI-AIS-IMM-…

---

## [Sharepoint Online sync error](https://discuss.elastic.co/t/sharepoint-online-sync-error/352874)

<div class="topic-metadata">

**Author:** [@Sheida](https://discuss.elastic.co/u/Sheida)\
**Replies:** 3\
**Last updated:** [February 13, 2024, 4:00pm UTC](https://discuss.elastic.co/t/sharepoint-online-sync-error/352874 "2024-02-13T16:00:54Z")

</div>

I have elasticsearch integrated with sharepoint online via elasticserach connector. connector reads documents correctly. however, it encounters an object named "wte" and an error occurs. the description of this object …

---

## [Painless syntax doc inconsistancy](https://discuss.elastic.co/t/painless-syntax-doc-inconsistancy/353190)

<div class="topic-metadata">

**Author:** [@rugenl](https://discuss.elastic.co/u/rugenl)\
**Replies:** 0\
**Last updated:** [February 13, 2024, 4:00pm UTC](https://discuss.elastic.co/t/painless-syntax-doc-inconsistancy/353190 "2024-02-13T16:00:21Z")

</div>

It's probably my lack of understanding, but in the doc document fields are sometimes referenced (top of link, in the conditional) as: doc\[item\] and other times (bottom of the linked page) as ctx.\_source.item It s…

---

## [Can I avoid elasticsearch monitoring index from moving to my temporary nodes?](https://discuss.elastic.co/t/can-i-avoid-elasticsearch-monitoring-index-from-moving-to-my-temporary-nodes/353128)

<div class="topic-metadata">

**Author:** [@Churchill](https://discuss.elastic.co/u/Churchill)\
**Replies:** 10\
**Last updated:** [February 13, 2024, 3:47pm UTC](https://discuss.elastic.co/t/can-i-avoid-elasticsearch-monitoring-index-from-moving-to-my-temporary-nodes/353128 "2024-02-13T15:47:15Z")

</div>

Good day, I'm currently maintaining a cluster with 4 permanent nodes and 3 temporary nodes. How it works is, during work hours, our temporary nodes will be started automatically, and will be shutdown after work hours. T…

[Previous page](https://discuss.elastic.co/latest.md?page=401)

[Next page](https://discuss.elastic.co/latest.md?page=403)
