# Latest

**URL:** https://discuss.elastic.co/latest.md?page=407

[Latest](https://discuss.elastic.co/latest.md) · [Categories](https://discuss.elastic.co/categories.md) · [Tags](https://discuss.elastic.co/tags.md)

**Page:** 408

---

## [Timeline Template see fields other then the fields in the alert](https://discuss.elastic.co/t/timeline-template-see-fields-other-then-the-fields-in-the-alert/352756)

<div class="topic-metadata">

**Author:** [@RoeeKent](https://discuss.elastic.co/u/RoeeKent)\
**Replies:** 4\
**Last updated:** [February 8, 2024, 12:23pm UTC](https://discuss.elastic.co/t/timeline-template-see-fields-other-then-the-fields-in-the-alert/352756 "2024-02-08T12:23:34Z")

</div>

Hi everyone! I would love to know if it is possible to add a timeline template to a detection rule, and use the fields in the template to see logs that are not part of the alert. For example, I have a rule that alerts …

---

## [How to setup a multi-node elasticsearch cluster in separate machines with ip specified in docker-compose.yml](https://discuss.elastic.co/t/how-to-setup-a-multi-node-elasticsearch-cluster-in-separate-machines-with-ip-specified-in-docker-compose-yml/352854)

<div class="topic-metadata">

**Author:** [@elasticheart](https://discuss.elastic.co/u/elasticheart)\
**Replies:** 1\
**Last updated:** [February 8, 2024, 12:12pm UTC](https://discuss.elastic.co/t/how-to-setup-a-multi-node-elasticsearch-cluster-in-separate-machines-with-ip-specified-in-docker-compose-yml/352854 "2024-02-08T12:12:15Z")

</div>

Hi guys, I would like to setup a multi-node elasticsearch v8.11.4 cluster using docker compose, "not in a single machine / host". I have 3 machines with IP 192.168.0.101, 192.168.0.102 and 192.168.0.103, and I want my …

---

## [Kibana alerts under stack management](https://discuss.elastic.co/t/kibana-alerts-under-stack-management/352597)

<div class="topic-metadata">

**Author:** [@anushasweety](https://discuss.elastic.co/u/anushasweety)\
**Replies:** 1\
**Last updated:** [February 8, 2024, 11:57am UTC](https://discuss.elastic.co/t/kibana-alerts-under-stack-management/352597 "2024-02-08T11:57:38Z")

</div>

Hi, I'm trying to create alert in kibana for the device\_id creating highest number of logs and trigger a mail( we have number of edge device connected and file beat is installed to collect the logs and it will send it t…

---

## [Cannot Edit the configuration of Logs Stream on Kibana UI](https://discuss.elastic.co/t/cannot-edit-the-configuration-of-logs-stream-on-kibana-ui/339981)

<div class="topic-metadata">

**Author:** [@Cruz](https://discuss.elastic.co/u/Cruz)\
**Replies:** 7\
**Last updated:** [February 8, 2024, 11:45am UTC](https://discuss.elastic.co/t/cannot-edit-the-configuration-of-logs-stream-on-kibana-ui/339981 "2024-02-08T11:45:02Z")

</div>

Does anyone know how to solve this? It seems I can't change the settings of Logs Stream. The input field not clickable. I just want to change the Log indices. I tried to restart my elastic and kibana but it's still…

---

## [Index not showing current metric data](https://discuss.elastic.co/t/index-not-showing-current-metric-data/352643)

<div class="topic-metadata">

**Author:** [@sajmeister](https://discuss.elastic.co/u/sajmeister)\
**Replies:** 1\
**Last updated:** [February 8, 2024, 11:24am UTC](https://discuss.elastic.co/t/index-not-showing-current-metric-data/352643 "2024-02-08T11:24:02Z")

</div>

Hi, Our newly created Index named 'alerts\_to\_snow' used to show us the latest metric data when in Kibana \> Discover and then select data view named 'alerts\_to\_snow'. The data we get presented is up to Jan 29th 2024 on…

---

## [Cannot build logstash-output-elasticsearch plugin locally](https://discuss.elastic.co/t/cannot-build-logstash-output-elasticsearch-plugin-locally/352845)

<div class="topic-metadata">

**Author:** [@amaciejk](https://discuss.elastic.co/u/amaciejk)\
**Replies:** 0\
**Last updated:** [February 8, 2024, 9:57am UTC](https://discuss.elastic.co/t/cannot-build-logstash-output-elasticsearch-plugin-locally/352845 "2024-02-08T09:57:03Z")

</div>

I'm attempting to build this plugin locally: However it fails seemingly due to a gemspec dependency issue: logstash-output-elasticsearch % jruby -S bundle install Fetching gem metadata from https://rubygems.org/.....…

---

## [Reindex vs Split Speed and Storage Requirements](https://discuss.elastic.co/t/reindex-vs-split-speed-and-storage-requirements/352719)

<div class="topic-metadata">

**Author:** [@zalseryani](https://discuss.elastic.co/u/zalseryani)\
**Replies:** 1\
**Last updated:** [February 8, 2024, 9:43am UTC](https://discuss.elastic.co/t/reindex-vs-split-speed-and-storage-requirements/352719 "2024-02-08T09:43:06Z")

</div>

I have seen a previous topic discussing the difference in speed between reindexing and splitting for an index Reindex vs Split index speeds if splitting is much faster than reindexing since it is hard-linking the under…

---

## [Apparent bug in logstash-output-mongodb plugin v 3.1.7 for logstash logstash-7.17.17](https://discuss.elastic.co/t/apparent-bug-in-logstash-output-mongodb-plugin-v-3-1-7-for-logstash-logstash-7-17-17/352819)

<div class="topic-metadata">

**Author:** [@shaigaut](https://discuss.elastic.co/u/shaigaut)\
**Replies:** 2\
**Last updated:** [February 8, 2024, 9:38am UTC](https://discuss.elastic.co/t/apparent-bug-in-logstash-output-mongodb-plugin-v-3-1-7-for-logstash-logstash-7-17-17/352819 "2024-02-08T09:38:17Z")

</div>

I recently migrated from mongodb 3.0 to mongodb 6.0 and logstash plugin 3.1.5 was no longer working, I upgraded the plugin to 3.1.7 and I keep getting this error in logstash logs: n\] MONGODB | Error checking 127.0.0.1:2…

---

## [I am getting the error while setting on Runcloud Based Setup on Normal setup its working like a charm but on Runcloud I am have this issue](https://discuss.elastic.co/t/i-am-getting-the-error-while-setting-on-runcloud-based-setup-on-normal-setup-its-working-like-a-charm-but-on-runcloud-i-am-have-this-issue/352834)

<div class="topic-metadata">

**Author:** [@Arya\_Aniket](https://discuss.elastic.co/u/Arya_Aniket)\
**Replies:** 0\
**Last updated:** [February 8, 2024, 8:59am UTC](https://discuss.elastic.co/t/i-am-getting-the-error-while-setting-on-runcloud-based-setup-on-normal-setup-its-working-like-a-charm-but-on-runcloud-i-am-have-this-issue/352834 "2024-02-08T08:59:20Z")

</div>

I am using LEMP setup and we are using Runcloud service for deploying the wordpress apps and Laravel apps. On raw LEMP setup its working fine but on runcloud I am getting this issue. This issue is regarding open\_basedir. …

---

## [Date attribute on POCO for new .NET client not available](https://discuss.elastic.co/t/date-attribute-on-poco-for-new-net-client-not-available/352653)

<div class="topic-metadata">

**Author:** [@kk123](https://discuss.elastic.co/u/kk123)\
**Replies:** 1\
**Last updated:** [February 8, 2024, 9:21am UTC](https://discuss.elastic.co/t/date-attribute-on-poco-for-new-net-client-not-available/352653 "2024-02-08T09:21:29Z")

</div>

Hi, I hope this is the correct category. I am updating my client from NEST to the latest Elastic.Elasticsearch.Client. With nest I was able to add an attribute to my POCO class as below... \[Date(Format = "date\_time\_no\_…

---

## [Aggregation with script code with previous result](https://discuss.elastic.co/t/aggregation-with-script-code-with-previous-result/352836)

<div class="topic-metadata">

**Author:** [@Fnizou](https://discuss.elastic.co/u/Fnizou)\
**Replies:** 0\
**Last updated:** [February 8, 2024, 9:11am UTC](https://discuss.elastic.co/t/aggregation-with-script-code-with-previous-result/352836 "2024-02-08T09:11:51Z")

</div>

Hello everyone I would like to know if it is possible in 1 single request, in the aggregations, to make a script which calculates an aggs based on the previous results: I need to dynamically calculate the interval th…

---

## [Metricbeat error](https://discuss.elastic.co/t/metricbeat-error/352828)

<div class="topic-metadata">

**Author:** [@miiroslavkardos](https://discuss.elastic.co/u/miiroslavkardos)\
**Replies:** 1\
**Last updated:** [February 8, 2024, 8:58am UTC](https://discuss.elastic.co/t/metricbeat-error/352828 "2024-02-08T08:58:11Z")

</div>

Hello, Could anyone please tell me what kind of error is this : It is in my elasticsearch log /var/log/elasticsearch/elktest01.log. \[2024-02-08T09:03:07,475\]\[WARN \]\[o.e.x.m.MonitoringService\] \[testdata01\] monitoring …

---

## [Can minimum\_should\_match be 'boxed'](https://discuss.elastic.co/t/can-minimum-should-match-be-boxed/352417)

<div class="topic-metadata">

**Author:** [@bbaronas](https://discuss.elastic.co/u/bbaronas)\
**Replies:** 3\
**Last updated:** [February 7, 2024, 4:53pm UTC](https://discuss.elastic.co/t/can-minimum-should-match-be-boxed/352417 "2024-02-07T16:53:00Z")

</div>

Is it possible to use minimum\_should\_match to control an overabundance of should clauses in a boolean query? For context: I made a query builder that allows a user to add multiple texts that get translated into individ…

---

## [What is the meaning of \[YES... and \[NO... in kibana displayed error messages?](https://discuss.elastic.co/t/what-is-the-meaning-of-yes-and-no-in-kibana-displayed-error-messages/352555)

<div class="topic-metadata">

**Author:** [@mpniel](https://discuss.elastic.co/u/mpniel)\
**Replies:** 2\
**Last updated:** [February 8, 2024, 6:51am UTC](https://discuss.elastic.co/t/what-is-the-meaning-of-yes-and-no-in-kibana-displayed-error-messages/352555 "2024-02-08T06:51:19Z")

</div>

What is the meaning of \[YES... and \[NO... in kibana displayed error messages?

---

## [Real time alert in Elasticsearch](https://discuss.elastic.co/t/real-time-alert-in-elasticsearch/352816)

<div class="topic-metadata">

**Author:** [@akashmaharana93](https://discuss.elastic.co/u/akashmaharana93)\
**Replies:** 1\
**Last updated:** [February 8, 2024, 6:49am UTC](https://discuss.elastic.co/t/real-time-alert-in-elasticsearch/352816 "2024-02-08T06:49:17Z")

</div>

Hi Team I want to configure an alert in KIbana in such a way that it will be triggered for every specific error message comes to Elasticsearch. Ex : Suppose for a JWT validation failure my error code is ERROR1. So i wa…

---

## [Logstash : parse json input from http poller failing](https://discuss.elastic.co/t/logstash-parse-json-input-from-http-poller-failing/352787)

<div class="topic-metadata">

**Author:** [@Rasheed](https://discuss.elastic.co/u/Rasheed)\
**Replies:** 8\
**Last updated:** [February 8, 2024, 5:46am UTC](https://discuss.elastic.co/t/logstash-parse-json-input-from-http-poller-failing/352787 "2024-02-08T05:46:53Z")

</div>

I have a logstash configuration of http poller input, and elastic output, but i am struggling to store the json input from poller to index as documents. it stores the entire json as a single field but i need to store eac…

---

## [Kibana 8.12.1, 7.17.18 Security Update (ESA-2024-04)](https://discuss.elastic.co/t/kibana-8-12-1-7-17-18-security-update-esa-2024-04/352805)

<div class="topic-metadata">

**Author:** [@rodrigo\_silva](https://discuss.elastic.co/u/rodrigo_silva)\
**Replies:** 0\
**Last updated:** [February 7, 2024, 10:07pm UTC](https://discuss.elastic.co/t/kibana-8-12-1-7-17-18-security-update-esa-2024-04/352805 "2024-02-07T22:07:29Z")

</div>

Kibana heap buffer overflow vulnerability (ESA-2024-04) This issue requires authenticated access to Kibana. On Dec 21, 2023, Google Chrome announced CVE-2023-7024, described as “Heap buffer overflow in WebRTC in Google…

---

## [Realtime aggregations per application transaction](https://discuss.elastic.co/t/realtime-aggregations-per-application-transaction/352708)

<div class="topic-metadata">

**Author:** [@abduimrn](https://discuss.elastic.co/u/abduimrn)\
**Replies:** 6\
**Last updated:** [February 8, 2024, 5:01am UTC](https://discuss.elastic.co/t/realtime-aggregations-per-application-transaction/352708 "2024-02-08T05:01:40Z")

</div>

Hello all, I was wondering about whether Elasticsearch is the meant to be used for real time aggregations PER application transaction request? Is this one of use cases? application transaction request = incoming reques…

---

## [Filebeat on Mac - How to get unlocked workstation log?](https://discuss.elastic.co/t/filebeat-on-mac-how-to-get-unlocked-workstation-log/352814)

<div class="topic-metadata">

**Author:** [@roman-tasi](https://discuss.elastic.co/u/roman-tasi)\
**Replies:** 0\
**Last updated:** [February 8, 2024, 1:55am UTC](https://discuss.elastic.co/t/filebeat-on-mac-how-to-get-unlocked-workstation-log/352814 "2024-02-08T01:55:59Z")

</div>

I recently installed filebeat on a Mac and have enabled the auditd and system modules. I am wondering what log represents an unlocked screen or login success. Thanks.

---

## [Allocate all unassigned shards at once!](https://discuss.elastic.co/t/allocate-all-unassigned-shards-at-once/352614)

<div class="topic-metadata">

**Author:** [@Johannes\_Haufila](https://discuss.elastic.co/u/Johannes_Haufila)\
**Replies:** 1\
**Last updated:** [February 7, 2024, 10:32pm UTC](https://discuss.elastic.co/t/allocate-all-unassigned-shards-at-once/352614 "2024-02-07T22:32:16Z")

</div>

how to allocate all unassigned shards at once. In my case I have 2897 missing replicas on my cluster

---

## [Running Pipeline Manually](https://discuss.elastic.co/t/running-pipeline-manually/352777)

<div class="topic-metadata">

**Author:** [@dfir](https://discuss.elastic.co/u/dfir)\
**Replies:** 10\
**Last updated:** [February 7, 2024, 10:14pm UTC](https://discuss.elastic.co/t/running-pipeline-manually/352777 "2024-02-07T22:14:34Z")

</div>

Quick Question for all: When I am trying to run my pipeline for logstash do I execute pipelines.yml, or just start up logstash? Based on this Documentation I believe I should be starting up logstash " This file is for…

---

## [\[GitHub Connector\] Handling GitHub API rate limits](https://discuss.elastic.co/t/github-connector-handling-github-api-rate-limits/352132)

<div class="topic-metadata">

**Author:** [@anna-safonov](https://discuss.elastic.co/u/anna-safonov)\
**Replies:** 4\
**Last updated:** [February 7, 2024, 8:52pm UTC](https://discuss.elastic.co/t/github-connector-handling-github-api-rate-limits/352132 "2024-02-07T20:52:14Z")

</div>

Hi there (again), I'm running the GitHub connector on our enterprise instance, and while I am able to do a full sync on smaller repos, we have a large repo that has over 78k+ pull requests, and we hit the rate limit dur…

---

## [Patterns defined under patterns\_dir are not valid](https://discuss.elastic.co/t/patterns-defined-under-patterns-dir-are-not-valid/352498)

<div class="topic-metadata">

**Author:** [@its-ogawa](https://discuss.elastic.co/u/its-ogawa)\
**Replies:** 23\
**Last updated:** [February 7, 2024, 8:29pm UTC](https://discuss.elastic.co/t/patterns-defined-under-patterns-dir-are-not-valid/352498 "2024-02-07T20:29:39Z")

</div>

I would like to write a grok pattern for logstash using patterns\_dir for maillog based on the following document. There is a postfix-grok-patterns file in patterns\_dir with all the following patterns. I have added th…

---

## [Migrating Kibana Plugins from Angular.js](https://discuss.elastic.co/t/migrating-kibana-plugins-from-angular-js/352546)

<div class="topic-metadata">

**Author:** [@Neeecu](https://discuss.elastic.co/u/Neeecu)\
**Replies:** 6\
**Last updated:** [February 7, 2024, 8:15pm UTC](https://discuss.elastic.co/t/migrating-kibana-plugins-from-angular-js/352546 "2024-02-07T20:15:49Z")

</div>

Hello! I have an application with Elasticsearch 7.9.3 and Kibana 7.9.3 with some plugins which are written in plain Angular.js (directives, controllers, templates etc.) and no React code. I plan on migrating and upgrad…

---

## [Multiple aggregation in single query or single single aggregation in multiple query which will perform better](https://discuss.elastic.co/t/multiple-aggregation-in-single-query-or-single-single-aggregation-in-multiple-query-which-will-perform-better/352799)

<div class="topic-metadata">

**Author:** [@kuldeep\_gupta](https://discuss.elastic.co/u/kuldeep_gupta)\
**Replies:** 0\
**Last updated:** [February 7, 2024, 8:05pm UTC](https://discuss.elastic.co/t/multiple-aggregation-in-single-query-or-single-single-aggregation-in-multiple-query-which-will-perform-better/352799 "2024-02-07T20:05:09Z")

</div>

I Have to perform two aggregation let's say query1 = { "aggs": { "traffic": { "date\_histogram": { "field": "@timestamp", "fixed\_interval": "30s", …

---

## [Fortigate 30E not sending any logs to ubuntu/logstash](https://discuss.elastic.co/t/fortigate-30e-not-sending-any-logs-to-ubuntu-logstash/352270)

<div class="topic-metadata">

**Author:** [@dadafaf](https://discuss.elastic.co/u/dadafaf)\
**Replies:** 14\
**Last updated:** [February 7, 2024, 7:49pm UTC](https://discuss.elastic.co/t/fortigate-30e-not-sending-any-logs-to-ubuntu-logstash/352270 "2024-02-07T19:49:14Z")

</div>

Hi! I have a problem that I need help with. I am using a Fortigate 30e firewall and a log server on a virtual machine with ELK stack and Logstash installed. The goal is to send logs from the Fortigate 30e to the log ser…

---

## [‏is there a shortcut instead of click to send request in kibana dev tools?](https://discuss.elastic.co/t/is-there-a-shortcut-instead-of-click-to-send-request-in-kibana-dev-tools/352740)

<div class="topic-metadata">

**Author:** [@mpniel](https://discuss.elastic.co/u/mpniel)\
**Replies:** 5\
**Last updated:** [February 7, 2024, 7:40pm UTC](https://discuss.elastic.co/t/is-there-a-shortcut-instead-of-click-to-send-request-in-kibana-dev-tools/352740 "2024-02-07T19:40:24Z")

</div>

Is there a shortcut instead of click to send request in kibana dev tools?

---

## [AWS CloudFront Ingest Pipeline Failing](https://discuss.elastic.co/t/aws-cloudfront-ingest-pipeline-failing/352678)

<div class="topic-metadata">

**Author:** [@DougR](https://discuss.elastic.co/u/DougR)\
**Replies:** 3\
**Last updated:** [February 7, 2024, 6:50pm UTC](https://discuss.elastic.co/t/aws-cloudfront-ingest-pipeline-failing/352678 "2024-02-07T18:50:13Z")

</div>

I am having an issue with logs ingesting into logs-aws.cloudfront\_logs-\* from a specific account, using Elastic Serverless Forwarder. In one specific account and this account only, I am receiving the following error in …

---

## [Error writing to Elastic search from Databricks](https://discuss.elastic.co/t/error-writing-to-elastic-search-from-databricks/352696)

<div class="topic-metadata">

**Author:** [@kichcha](https://discuss.elastic.co/u/kichcha)\
**Replies:** 5\
**Last updated:** [February 7, 2024, 6:34pm UTC](https://discuss.elastic.co/t/error-writing-to-elastic-search-from-databricks/352696 "2024-02-07T18:34:06Z")

</div>

Hello, I am an Elasticsearch newbie trying to connect to Elasticsearch on GCP from databricks on AWS. I tried following instructions provided by databricks (unable to post link here). However, I am now running into th…

---

## [Help requested to iterate and join sub-arrays](https://discuss.elastic.co/t/help-requested-to-iterate-and-join-sub-arrays/352408)

<div class="topic-metadata">

**Author:** [@lmw](https://discuss.elastic.co/u/lmw)\
**Replies:** 4\
**Last updated:** [February 7, 2024, 6:25pm UTC](https://discuss.elastic.co/t/help-requested-to-iterate-and-join-sub-arrays/352408 "2024-02-07T18:25:09Z")

</div>

Hi everyone, Please forgive me for my noob question, of it it has already been answered, but I have not been able to find it by myself. Let's consider that I have this datasource, with an arrays of vars, which may cont…

[Previous page](https://discuss.elastic.co/latest.md?page=406)

[Next page](https://discuss.elastic.co/latest.md?page=408)
