# Latest

**URL:** https://discuss.elastic.co/latest.md?page=410

[Latest](https://discuss.elastic.co/latest.md) · [Categories](https://discuss.elastic.co/categories.md) · [Tags](https://discuss.elastic.co/tags.md)

**Page:** 411

---

## [Export and import dashboard](https://discuss.elastic.co/t/export-and-import-dashboard/352445)

<div class="topic-metadata">

**Author:** [@mcosta](https://discuss.elastic.co/u/mcosta)\
**Replies:** 2\
**Last updated:** [February 5, 2024, 10:58pm UTC](https://discuss.elastic.co/t/export-and-import-dashboard/352445 "2024-02-05T22:58:35Z")

</div>

Hi, I need to export three dashboards from cluster-A (on-prem v8.10.4) and import into cluster-B (cloud v8.11.1). What is the best way to do this? Although they're listed on "Saved Objects", I can't find a way to do th…

---

## [Kibana Security Analyst course materials don't match Strigo environment instance](https://discuss.elastic.co/t/kibana-security-analyst-course-materials-dont-match-strigo-environment-instance/352232)

<div class="topic-metadata">

**Author:** [@EMParks](https://discuss.elastic.co/u/EMParks)\
**Replies:** 1\
**Last updated:** [February 2, 2024, 8:26pm UTC](https://discuss.elastic.co/t/kibana-security-analyst-course-materials-dont-match-strigo-environment-instance/352232 "2024-02-02T20:26:29Z")

</div>

Course: Kibana Security Analyst (On-demand) Version: Current Version? Question: I'm in the process of setting up my lab environment and I've noticed right off the bat that when I copy the CTFd address as shown in the …

---

## [Removing empty fields from an event (2024 edition!)](https://discuss.elastic.co/t/removing-empty-fields-from-an-event-2024-edition/352571)

<div class="topic-metadata">

**Author:** [@Supermathie](https://discuss.elastic.co/u/Supermathie)\
**Replies:** 1\
**Last updated:** [February 5, 2024, 9:55pm UTC](https://discuss.elastic.co/t/removing-empty-fields-from-an-event-2024-edition/352571 "2024-02-05T21:55:15Z")

</div>

Continuing the discussion from Never ending story: how to check and remove empty fields, arrays etc: There's no simple way to (recursively) get all field names in an event, but one can do this: filter { ruby { …

---

## [How to get count of specific value in elasticsearch java clinet](https://discuss.elastic.co/t/how-to-get-count-of-specific-value-in-elasticsearch-java-clinet/352465)

<div class="topic-metadata">

**Author:** [@Abdalrazag\_Al-Shrufa](https://discuss.elastic.co/u/Abdalrazag_Al-Shrufa)\
**Replies:** 1\
**Last updated:** [February 5, 2024, 9:43pm UTC](https://discuss.elastic.co/t/how-to-get-count-of-specific-value-in-elasticsearch-java-clinet/352465 "2024-02-05T21:43:49Z")

</div>

I am using elasticsearch-java 8.12, and I want to get the count of specific value, in my example I have log index, and there is a field called result, I want to get the number of documents that the result field is "corr…

---

## [Integration of FortiGate Firewall with Elasticsearch](https://discuss.elastic.co/t/integration-of-fortigate-firewall-with-elasticsearch/352287)

<div class="topic-metadata">

**Author:** [@Eepe123](https://discuss.elastic.co/u/Eepe123)\
**Replies:** 3\
**Last updated:** [February 5, 2024, 9:06pm UTC](https://discuss.elastic.co/t/integration-of-fortigate-firewall-with-elasticsearch/352287 "2024-02-05T21:06:35Z")

</div>

So im trying to configure fortigate30e sending logs straight to kibana by using this blog post from infrasecuritycode: integration of fortigate firewall with elasticsearch i have a screenshot of a error im getting its s…

---

## [Hide Show Timeline at bottom](https://discuss.elastic.co/t/hide-show-timeline-at-bottom/352565)

<div class="topic-metadata">

**Author:** [@sourcreamnormanbates](https://discuss.elastic.co/u/sourcreamnormanbates)\
**Replies:** 3\
**Last updated:** [February 5, 2024, 8:32pm UTC](https://discuss.elastic.co/t/hide-show-timeline-at-bottom/352565 "2024-02-05T20:32:53Z")

</div>

Is there a way to hide/show the timeline at the bottom of the page? It often makes navigation cumbersome when it is not being used such as reviewing long lists of alerts. You have to scroll all the way the bottom of th…

---

## [Is Elastic Endpoint Security Defender endgame?](https://discuss.elastic.co/t/is-elastic-endpoint-security-defender-endgame/352563)

<div class="topic-metadata">

**Author:** [@BigM1](https://discuss.elastic.co/u/BigM1)\
**Replies:** 1\
**Last updated:** [February 5, 2024, 8:16pm UTC](https://discuss.elastic.co/t/is-elastic-endpoint-security-defender-endgame/352563 "2024-02-05T20:16:20Z")

</div>

Quick questions Elasticians. With the acquisition of endgame, is Elastic Endpoint Security Defender == endgame ? Has the endgame capabilities been embedded into Elastic Endoint Defender ?

---

## [Canvas: Extending Element to continue on Next Page](https://discuss.elastic.co/t/canvas-extending-element-to-continue-on-next-page/351584)

<div class="topic-metadata">

**Author:** [@erikg](https://discuss.elastic.co/u/erikg)\
**Replies:** 4\
**Last updated:** [February 5, 2024, 7:37pm UTC](https://discuss.elastic.co/t/canvas-extending-element-to-continue-on-next-page/351584 "2024-02-05T19:37:58Z")

</div>

Hello, I am pretty new to Canvas, I am able to create a markdown table using Elastic SQL. The query retrieves a limit of 50 results. The report looks great as expected but It can only fit 17 on one page. I was wonderi…

---

## [Formal grammar for DSL?](https://discuss.elastic.co/t/formal-grammar-for-dsl/352564)

<div class="topic-metadata">

**Author:** [@Steph\_van\_Schalkwyk](https://discuss.elastic.co/u/Steph_van_Schalkwyk)\
**Replies:** 0\
**Last updated:** [February 5, 2024, 7:02pm UTC](https://discuss.elastic.co/t/formal-grammar-for-dsl/352564 "2024-02-05T19:02:21Z")

</div>

Continuing the discussion from Formal Grammar of Query DSL?: Still looking. I can find SQL and Painless grammars, but not DSL.

---

## [Corrupt primary shard, how to recover from replica shard?](https://discuss.elastic.co/t/corrupt-primary-shard-how-to-recover-from-replica-shard/352561)

<div class="topic-metadata">

**Author:** [@ncluff](https://discuss.elastic.co/u/ncluff)\
**Replies:** 2\
**Last updated:** [February 5, 2024, 6:34pm UTC](https://discuss.elastic.co/t/corrupt-primary-shard-how-to-recover-from-replica-shard/352561 "2024-02-05T18:34:49Z")

</div>

I have an index with 3 primary shards and 1 replica. Primary shard 1 for some reason goes corrupt. The error mentions merge failed, org.apache.lucene.index.CorruptIndexException which I'm looking into. Am I right thinkin…

---

## [Was CRC32 in version 7.x of Elasticsearch?](https://discuss.elastic.co/t/was-crc32-in-version-7-x-of-elasticsearch/352558)

<div class="topic-metadata">

**Author:** [@ncluff](https://discuss.elastic.co/u/ncluff)\
**Replies:** 1\
**Last updated:** [February 5, 2024, 5:58pm UTC](https://discuss.elastic.co/t/was-crc32-in-version-7-x-of-elasticsearch/352558 "2024-02-05T17:58:33Z")

</div>

I noticed this post where David Turner mentions the troubleshooting guide for corruption. The documentation started in 8.3, but I'm curious if this is the same for version 7.17.4? Backstory, I have a deployment on VMWar…

---

## [Configuring Logstash to Accept Both SSL and Non-SSL Connections](https://discuss.elastic.co/t/configuring-logstash-to-accept-both-ssl-and-non-ssl-connections/352528)

<div class="topic-metadata">

**Author:** [@yago82](https://discuss.elastic.co/u/yago82)\
**Replies:** 1\
**Last updated:** [February 5, 2024, 4:28pm UTC](https://discuss.elastic.co/t/configuring-logstash-to-accept-both-ssl-and-non-ssl-connections/352528 "2024-02-05T16:28:57Z")

</div>

Hi, I'm currently working on setting up Logstash to accept both SSL and non-SSL connections from Beats. From my understanding, I would need to configure two separate Beats inputs on different ports. For example: input …

---

## [Elasticsearch cluster goes down with 1 node capacity reached, resolutions](https://discuss.elastic.co/t/elasticsearch-cluster-goes-down-with-1-node-capacity-reached-resolutions/352550)

<div class="topic-metadata">

**Author:** [@charvi23](https://discuss.elastic.co/u/charvi23)\
**Replies:** 4\
**Last updated:** [February 5, 2024, 4:27pm UTC](https://discuss.elastic.co/t/elasticsearch-cluster-goes-down-with-1-node-capacity-reached-resolutions/352550 "2024-02-05T16:27:12Z")

</div>

I have a 2 node cluster, out of which 1 node has reached max capacity (96%). Both nodes have different capacity. It gives the following error: TOO\_MANY\_REQUESTS/12/disk usage exceeded flood-stage watermark, index has re…

---

## [Error while trying to new node to existing cluster. Bootstrap settings failed](https://discuss.elastic.co/t/error-while-trying-to-new-node-to-existing-cluster-bootstrap-settings-failed/352404)

<div class="topic-metadata">

**Author:** [@charvi23](https://discuss.elastic.co/u/charvi23)\
**Replies:** 2\
**Last updated:** [February 5, 2024, 3:43pm UTC](https://discuss.elastic.co/t/error-while-trying-to-new-node-to-existing-cluster-bootstrap-settings-failed/352404 "2024-02-05T15:43:28Z")

</div>

Getting error while adding new node to cluster. \[1\] bootstrap checks failed. You must address the points described in the following \[1\] lines before starting Elasticsearch. For more information see \[ https://www.elastic…

---

## [Can't parse event as syslog rfc3164](https://discuss.elastic.co/t/cant-parse-event-as-syslog-rfc3164/352307)

<div class="topic-metadata">

**Author:** [@Amol\_Sahare](https://discuss.elastic.co/u/Amol_Sahare)\
**Replies:** 4\
**Last updated:** [February 5, 2024, 2:50pm UTC](https://discuss.elastic.co/t/cant-parse-event-as-syslog-rfc3164/352307 "2024-02-05T14:50:35Z")

</div>

Hello, We are having problems with the'syslog' input of filebeat. I'm using the script for sending a single log to the filebeat syslog input. I've noticed that the same message is being parsed because I can see the eve…

---

## [How to parse Mime x-wine-extension-ini files](https://discuss.elastic.co/t/how-to-parse-mime-x-wine-extension-ini-files/352541)

<div class="topic-metadata">

**Author:** [@Admin\_Zee9](https://discuss.elastic.co/u/Admin_Zee9)\
**Replies:** 0\
**Last updated:** [February 5, 2024, 2:06pm UTC](https://discuss.elastic.co/t/how-to-parse-mime-x-wine-extension-ini-files/352541 "2024-02-05T14:06:14Z")

</div>

Hello, Has anyone had to deal with parsing a MIME type x-wine-extension-ini file? I need to convert many of them to CSV or XML using AWS Athena. I found that a Grok pattern could be helpful, but this is the first time…

---

## [Watcher ssl fail](https://discuss.elastic.co/t/watcher-ssl-fail/351444)

<div class="topic-metadata">

**Author:** [@hofrichterovak](https://discuss.elastic.co/u/hofrichterovak)\
**Replies:** 1\
**Last updated:** [February 5, 2024, 1:57pm UTC](https://discuss.elastic.co/t/watcher-ssl-fail/351444 "2024-02-05T13:57:40Z")

</div>

Hello, I read the documentation about sending email with PDF dashboard in the attachment \>\>\> Automatically generate reports | Kibana Guide \[8.9\] | Elastic I wanted to create my own watcher. My Kibana version is 7.17.8 …

---

## [About the ILM policy implented and on the post observations](https://discuss.elastic.co/t/about-the-ilm-policy-implented-and-on-the-post-observations/351851)

<div class="topic-metadata">

**Author:** [@Ravi\_Pattar](https://discuss.elastic.co/u/Ravi_Pattar)\
**Replies:** 6\
**Last updated:** [February 5, 2024, 1:16pm UTC](https://discuss.elastic.co/t/about-the-ilm-policy-implented-and-on-the-post-observations/351851 "2024-02-05T13:16:52Z")

</div>

Hello, Recently I have implemented ILM policy on of the production setup. However, the rollover for the existing ILM policy seems to be working fine. But I am seeing indices for other version e.g. 8.x are utilizing the…

---

## [Unable to access 'path.data' (/data/db/elasticsearch)](https://discuss.elastic.co/t/unable-to-access-path-data-data-db-elasticsearch/352302)

<div class="topic-metadata">

**Author:** [@daniela09](https://discuss.elastic.co/u/daniela09)\
**Replies:** 4\
**Last updated:** [February 5, 2024, 1:36pm UTC](https://discuss.elastic.co/t/unable-to-access-path-data-data-db-elasticsearch/352302 "2024-02-05T13:36:32Z")

</div>

This is my Statefulset for Elasticsearch spec: podManagementPolicy: OrderedReady replicas: 3 revisionHistoryLimit: 10 selector: matchLabels: app: elasticsearch serviceName: elasticsearch-data templ…

---

## [Monitor database metrics using elastic](https://discuss.elastic.co/t/monitor-database-metrics-using-elastic/352530)

<div class="topic-metadata">

**Author:** [@searchwithme](https://discuss.elastic.co/u/searchwithme)\
**Replies:** 1\
**Last updated:** [February 5, 2024, 1:19pm UTC](https://discuss.elastic.co/t/monitor-database-metrics-using-elastic/352530 "2024-02-05T13:19:06Z")

</div>

Is it possible to monitor database metrics like connection time, page reads, open connections, uptime, long running queries, etc using elastic?

---

## [Registering S3 repository from private subnet fails with "Unauthorized"](https://discuss.elastic.co/t/registering-s3-repository-from-private-subnet-fails-with-unauthorized/352527)

<div class="topic-metadata">

**Author:** [@strophy](https://discuss.elastic.co/u/strophy)\
**Replies:** 4\
**Last updated:** [February 5, 2024, 12:56pm UTC](https://discuss.elastic.co/t/registering-s3-repository-from-private-subnet-fails-with-unauthorized/352527 "2024-02-05T12:56:05Z")

</div>

I'm trying to register an S3 repository for a test cluster of two instances running Elasticsearch 8.12.0 in a private AWS subnet using IAM instance profiles instead of access keys. The subnet security group has outgoing …

---

## [What is the risk of running Rally on production?](https://discuss.elastic.co/t/what-is-the-risk-of-running-rally-on-production/352433)

<div class="topic-metadata">

**Author:** [@userR](https://discuss.elastic.co/u/userR)\
**Replies:** 1\
**Last updated:** [February 5, 2024, 11:48am UTC](https://discuss.elastic.co/t/what-is-the-risk-of-running-rally-on-production/352433 "2024-02-05T11:48:20Z")

</div>

I have ran Rally on a staging instance and wanted to compare the performance to our existing production cluster. From the documentation: First of all: Please (please, please) do NOT run Rally against your production clu…

---

## [Java api client 7.x with Elasticsearch server 8.x](https://discuss.elastic.co/t/java-api-client-7-x-with-elasticsearch-server-8-x/352369)

<div class="topic-metadata">

**Author:** [@SElasticsearch](https://discuss.elastic.co/u/SElasticsearch)\
**Replies:** 3\
**Last updated:** [February 5, 2024, 11:35am UTC](https://discuss.elastic.co/t/java-api-client-7-x-with-elasticsearch-server-8-x/352369 "2024-02-05T11:35:37Z")

</div>

We have a scenario where our application needs to connect with both 7.x and 8.x Elasticsearch server. Using Java API client 7.17.16 and it works with Elasticsearch server 7.x. Used (HttpHeaders.CONTENT\_TYPE, "applicatio…

---

## [Getting curl logs while having solr and elasticSearch both implemented in the same service](https://discuss.elastic.co/t/getting-curl-logs-while-having-solr-and-elasticsearch-both-implemented-in-the-same-service/352523)

<div class="topic-metadata">

**Author:** [@Anushka\_Srivastava](https://discuss.elastic.co/u/Anushka_Srivastava)\
**Replies:** 0\
**Last updated:** [February 5, 2024, 11:03am UTC](https://discuss.elastic.co/t/getting-curl-logs-while-having-solr-and-elasticsearch-both-implemented-in-the-same-service/352523 "2024-02-05T11:03:32Z")

</div>

The below screenshot represents how the curl logs are coming. I'm using the below dependency for Elasticsearch - api group: 'co.elastic.clients', name: 'elasticsearch-java', version: '8.12.0' And for Solr, I'm…

---

## [Are Conditional Aggregations Possible?](https://discuss.elastic.co/t/are-conditional-aggregations-possible/352518)

<div class="topic-metadata">

**Author:** [@ndtreviv](https://discuss.elastic.co/u/ndtreviv)\
**Replies:** 0\
**Last updated:** [February 5, 2024, 10:21am UTC](https://discuss.elastic.co/t/are-conditional-aggregations-possible/352518 "2024-02-05T10:21:06Z")

</div>

I want to run a count query with an associated aggregation, but only run the aggregation if the count for the query is below a certain number. Is this possible?

---

## [Logstash Proxy Credentials](https://discuss.elastic.co/t/logstash-proxy-credentials/352414)

<div class="topic-metadata">

**Author:** [@elk-user-0001](https://discuss.elastic.co/u/elk-user-0001)\
**Replies:** 2\
**Last updated:** [February 5, 2024, 9:22am UTC](https://discuss.elastic.co/t/logstash-proxy-credentials/352414 "2024-02-05T09:22:33Z")

</div>

Good afternoon colleagues! I have a logstash service in local and an elastic server in cloud. To reach it via curl I need to set --proxy https://proxy:8080 and --proxy-user 'user\\moreusername:password' . How can I do …

---

## [How can I generate root-ca.pem file for Elasticsearch](https://discuss.elastic.co/t/how-can-i-generate-root-ca-pem-file-for-elasticsearch/352511)

<div class="topic-metadata">

**Author:** [@fahim2024](https://discuss.elastic.co/u/fahim2024)\
**Replies:** 2\
**Last updated:** [February 5, 2024, 9:16am UTC](https://discuss.elastic.co/t/how-can-i-generate-root-ca-pem-file-for-elasticsearch/352511 "2024-02-05T09:16:19Z")

</div>

How can I generate root-ca.pem file for Elasticsearch ,Would be great if some help me

---

## [Enterprise search Custom Connectors - Systemd Service Fails](https://discuss.elastic.co/t/enterprise-search-custom-connectors-systemd-service-fails/352399)

<div class="topic-metadata">

**Author:** [@VIGNESHkumar](https://discuss.elastic.co/u/VIGNESHkumar)\
**Replies:** 1\
**Last updated:** [February 5, 2024, 9:07am UTC](https://discuss.elastic.co/t/enterprise-search-custom-connectors-systemd-service-fails/352399 "2024-02-05T09:07:55Z")

</div>

Hi, I have build a custom connector to crawl the data from Wordpress Application to the elasticsearch. The connectors works fine and I can able to see the data into the Elasticsearch Indices using Connector as ingestio…

---

## [Pass Kibana log in credentials to external backend server](https://discuss.elastic.co/t/pass-kibana-log-in-credentials-to-external-backend-server/351965)

<div class="topic-metadata">

**Author:** [@Sheereen](https://discuss.elastic.co/u/Sheereen)\
**Replies:** 2\
**Last updated:** [February 5, 2024, 8:34am UTC](https://discuss.elastic.co/t/pass-kibana-log-in-credentials-to-external-backend-server/351965 "2024-02-05T08:34:48Z")

</div>

Hi, I am creating a custom plugin in React JS. The plugin has UI, which communicates with an external backend/server managed by me. When user logs into Kibana, I want to pass those credentials (which was used to log i…

---

## [Kibana Home Dashboard showing critical In Red and Non critical Green](https://discuss.elastic.co/t/kibana-home-dashboard-showing-critical-in-red-and-non-critical-green/352190)

<div class="topic-metadata">

**Author:** [@PRASHANT\_MEHTA](https://discuss.elastic.co/u/PRASHANT_MEHTA)\
**Replies:** 6\
**Last updated:** [February 5, 2024, 7:58am UTC](https://discuss.elastic.co/t/kibana-home-dashboard-showing-critical-in-red-and-non-critical-green/352190 "2024-02-05T07:58:40Z")

</div>

Hello All, Is there anyway I can transfer my Old implementaion to show HOME monitoring page to admins in this new way. This first approach is not required as per customer and asked instead for second approach that I do…

[Previous page](https://discuss.elastic.co/latest.md?page=409)

[Next page](https://discuss.elastic.co/latest.md?page=411)
