# Latest

**URL:** https://discuss.elastic.co/latest.md?page=413

[Latest](https://discuss.elastic.co/latest.md) · [Categories](https://discuss.elastic.co/categories.md) · [Tags](https://discuss.elastic.co/tags.md)

**Page:** 414

---

## [Schedule backup using kibana](https://discuss.elastic.co/t/schedule-backup-using-kibana/352266)

<div class="topic-metadata">

**Author:** [@VijayIQA](https://discuss.elastic.co/u/VijayIQA)\
**Replies:** 6\
**Last updated:** [February 2, 2024, 4:10am UTC](https://discuss.elastic.co/t/schedule-backup-using-kibana/352266 "2024-02-02T04:10:03Z")

</div>

Hi Team, I schedule a job on Kibana to take schedule backup. the job should be fire every day 15:00pm for that my cron expression is 0 0 15 ? \* \* but on Kibana it is showing 08:30pm

---

## [A potential bug with Filebeat script processor](https://discuss.elastic.co/t/a-potential-bug-with-filebeat-script-processor/351914)

<div class="topic-metadata">

**Author:** [@Calvin\_Li](https://discuss.elastic.co/u/Calvin_Li)\
**Replies:** 6\
**Last updated:** [February 2, 2024, 4:06am UTC](https://discuss.elastic.co/t/a-potential-bug-with-filebeat-script-processor/351914 "2024-02-02T04:06:42Z")

</div>

Hi team, thanks for your great work! I'm using filebeat 8.10.3, and seeing a potential bug with it. I'm using the script processor to do some caching & filtering of log messages. To be specific, I'm using a LRU cache to…

---

## [Kibana service giving "FATAL Error: \[config validation of \[server\].host\]: value must be a valid hostname (see RFC 1123)" error](https://discuss.elastic.co/t/kibana-service-giving-fatal-error-config-validation-of-server-host-value-must-be-a-valid-hostname-see-rfc-1123-error/351913)

<div class="topic-metadata">

**Author:** [@vikas.shirke](https://discuss.elastic.co/u/vikas.shirke)\
**Replies:** 2\
**Last updated:** [February 2, 2024, 4:02am UTC](https://discuss.elastic.co/t/kibana-service-giving-fatal-error-config-validation-of-server-host-value-must-be-a-valid-hostname-see-rfc-1123-error/351913 "2024-02-02T04:02:00Z")

</div>

On the VM where we have installed Elasticsearch and Kibana service, Kibana service is giving "FATAL Error: \[config validation of \[server\].host\]: value must be a valid hostname (see RFC 1123)" error. After troubleshootin…

---

## [Webhook connector generated invalid """ json elements](https://discuss.elastic.co/t/webhook-connector-generated-invalid-json-elements/351950)

<div class="topic-metadata">

**Author:** [@garethhumphriesgkc](https://discuss.elastic.co/u/garethhumphriesgkc)\
**Replies:** 1\
**Last updated:** [February 2, 2024, 2:18am UTC](https://discuss.elastic.co/t/webhook-connector-generated-invalid-json-elements/351950 "2024-02-02T02:18:41Z")

</div>

Hi, I'm using the webhook connector to send some JSON data to a webhook destination whenever a rule triggers. One of the JSON fields I'm sending is multiline, but anytime I try to embed \\ns in the JSON, kibana converts…

---

## [Should I increase my amount of RAM?](https://discuss.elastic.co/t/should-i-increase-my-amount-of-ram/352214)

<div class="topic-metadata">

**Author:** [@louisdeveloper](https://discuss.elastic.co/u/louisdeveloper)\
**Replies:** 9\
**Last updated:** [February 2, 2024, 1:57am UTC](https://discuss.elastic.co/t/should-i-increase-my-amount-of-ram/352214 "2024-02-02T01:57:22Z")

</div>

I noticed that the RAM usage percentage of my nodes is quite high. Based on these logs, should I increase the amount of RAM on my servers? The master is usually the master-01 machine, but in the log it is as master-02,…

---

## [How to integrate ElasticSearch with AEM Dam and Pages?](https://discuss.elastic.co/t/how-to-integrate-elasticsearch-with-aem-dam-and-pages/352350)

<div class="topic-metadata">

**Author:** [@jmichael990](https://discuss.elastic.co/u/jmichael990)\
**Replies:** 0\
**Last updated:** [February 2, 2024, 1:24am UTC](https://discuss.elastic.co/t/how-to-integrate-elasticsearch-with-aem-dam-and-pages/352350 "2024-02-02T01:24:53Z")

</div>

Has anyone integrated Elasticsearch with AEM? I have a headless AEM architecture and am seeing how feasible it would be to implement a frontend solution for search that would be integrate the AEM backend to index webpage…

---

## [How to Azure Entra ID Groups for SAML SSO?](https://discuss.elastic.co/t/how-to-azure-entra-id-groups-for-saml-sso/352340)

<div class="topic-metadata">

**Author:** [@World\_Python](https://discuss.elastic.co/u/World_Python)\
**Replies:** 1\
**Last updated:** [February 1, 2024, 11:38pm UTC](https://discuss.elastic.co/t/how-to-azure-entra-id-groups-for-saml-sso/352340 "2024-02-01T23:38:50Z")

</div>

Following these docs: Config: xpack: security: authc: realms: saml: saml1: order: 3 attributes.dn: "http://schemas.xmlsoap.org/ws/2005/05/identity/claims/emailaddr…

---

## [Use Field in Alert Email Action](https://discuss.elastic.co/t/use-field-in-alert-email-action/352344)

<div class="topic-metadata">

**Author:** [@Ray3](https://discuss.elastic.co/u/Ray3)\
**Replies:** 0\
**Last updated:** [February 1, 2024, 11:31pm UTC](https://discuss.elastic.co/t/use-field-in-alert-email-action/352344 "2024-02-01T23:31:26Z")

</div>

I think I saw this somewhere but have been unable to find it again. Can I set a rule and alert to send to an email address stored in document field. Our field is alertdistlist and it has a formatted email address. I …

---

## [‏how to display the documents of an index in kibana 7.5?](https://discuss.elastic.co/t/how-to-display-the-documents-of-an-index-in-kibana-7-5/352118)

<div class="topic-metadata">

**Author:** [@mpniel](https://discuss.elastic.co/u/mpniel)\
**Replies:** 4\
**Last updated:** [February 1, 2024, 10:59pm UTC](https://discuss.elastic.co/t/how-to-display-the-documents-of-an-index-in-kibana-7-5/352118 "2024-02-01T22:59:34Z")

</div>

‏how to list the contents and view the documents of an index in kibana 7.5, using index management or api?

---

## [Logstash Fingerprint Plugin Target Unchanged](https://discuss.elastic.co/t/logstash-fingerprint-plugin-target-unchanged/352247)

<div class="topic-metadata">

**Author:** [@Cheese](https://discuss.elastic.co/u/Cheese)\
**Replies:** 3\
**Last updated:** [February 1, 2024, 9:44pm UTC](https://discuss.elastic.co/t/logstash-fingerprint-plugin-target-unchanged/352247 "2024-02-01T21:44:30Z")

</div>

HI all, Needing some help with using the Fingerprint plugin. I use the fingerprint plugin to generate a SHA-1 signature using a base string and a key. My logstash config file is like so: mutate { add\_field { "si…

---

## [Logstash creates page file size that reaches its limit causing other pages to not be created](https://discuss.elastic.co/t/logstash-creates-page-file-size-that-reaches-its-limit-causing-other-pages-to-not-be-created/352200)

<div class="topic-metadata">

**Author:** [@tcapp24](https://discuss.elastic.co/u/tcapp24)\
**Replies:** 11\
**Last updated:** [February 1, 2024, 8:46pm UTC](https://discuss.elastic.co/t/logstash-creates-page-file-size-that-reaches-its-limit-causing-other-pages-to-not-be-created/352200 "2024-02-01T20:46:29Z")

</div>

We 're currently running Logstash 7.17.8 using a docker container on a Linux VM. We have run into an issue where Logstash creates page.0 which quickly fills up and reaches its queue.page\_capacity of 256mb. Once it reach…

---

## [Api calls for Kibana](https://discuss.elastic.co/t/api-calls-for-kibana/352328)

<div class="topic-metadata">

**Author:** [@alon\_carmelly](https://discuss.elastic.co/u/alon_carmelly)\
**Replies:** 2\
**Last updated:** [February 1, 2024, 7:45pm UTC](https://discuss.elastic.co/t/api-calls-for-kibana/352328 "2024-02-01T19:45:17Z")

</div>

Hi there, I am setting up Elk stack on a eks cluster using helm charts. In regards to the helm chart and in general. What configuration elements should be enabled to allow me to set data views with a simple api call? I…

---

## [Filebeat not sending most logs across the network](https://discuss.elastic.co/t/filebeat-not-sending-most-logs-across-the-network/351472)

<div class="topic-metadata">

**Author:** [@reshippie](https://discuss.elastic.co/u/reshippie)\
**Replies:** 34\
**Last updated:** [February 1, 2024, 7:16pm UTC](https://discuss.elastic.co/t/filebeat-not-sending-most-logs-across-the-network/351472 "2024-02-01T19:16:01Z")

</div>

I changed the output to console and verified that filebeat is actually examining the logs and there are hundreds of lines that should be sent to Logstash. The only error messages that journalctl shows are about empty fi…

---

## [After Reindex, no more new records](https://discuss.elastic.co/t/after-reindex-no-more-new-records/352335)

<div class="topic-metadata">

**Author:** [@rachelyang](https://discuss.elastic.co/u/rachelyang)\
**Replies:** 0\
**Last updated:** [February 1, 2024, 6:09pm UTC](https://discuss.elastic.co/t/after-reindex-no-more-new-records/352335 "2024-02-01T18:09:12Z")

</div>

I want to change the type of the geo field, so I reindex the current index. The reindex was successful. I have recovered all the records in the past. But no more new record are coming in. The docs.count and store.size do…

---

## [How do I store the data from an Elasticsearch store](https://discuss.elastic.co/t/how-do-i-store-the-data-from-an-elasticsearch-store/351597)

<div class="topic-metadata">

**Author:** [@susnato](https://discuss.elastic.co/u/susnato)\
**Replies:** 4\
**Last updated:** [February 1, 2024, 6:07pm UTC](https://discuss.elastic.co/t/how-do-i-store-the-data-from-an-elasticsearch-store/351597 "2024-02-01T18:07:01Z")

</div>

(Hi, I am totally new to Elastic search, so sorry if this is very basic question.) I have an Elasticsearch store running in background using docker. I have added some files and corresponding embeddings to it and now…

---

## [JAVA APM Agent, System CPU reporting with java 8](https://discuss.elastic.co/t/java-apm-agent-system-cpu-reporting-with-java-8/352326)

<div class="topic-metadata">

**Author:** [@Yasim\_Zeballos](https://discuss.elastic.co/u/Yasim_Zeballos)\
**Replies:** 0\
**Last updated:** [February 1, 2024, 4:07pm UTC](https://discuss.elastic.co/t/java-apm-agent-system-cpu-reporting-with-java-8/352326 "2024-02-01T16:07:27Z")

</div>

Kibana version: 7.17.X Elasticsearch version: 7.17.X APM Server version: 7.17.X jar java agent: opentelemetry-javaagent-2.0.0.jar Java version: Java 8 As image shows, only thread count is shown. Why CPU usage is…

---

## [How to segregate from which source elastic is receiving messages?](https://discuss.elastic.co/t/how-to-segregate-from-which-source-elastic-is-receiving-messages/352323)

<div class="topic-metadata">

**Author:** [@Sanjay\_Kumar2](https://discuss.elastic.co/u/Sanjay_Kumar2)\
**Replies:** 0\
**Last updated:** [February 1, 2024, 3:53pm UTC](https://discuss.elastic.co/t/how-to-segregate-from-which-source-elastic-is-receiving-messages/352323 "2024-02-01T15:53:41Z")

</div>

As a part of ELK migration we are trying to setup our new cluster in a shared AKS cluster. Issue is, we have the flow as Filebeat -\> Ingress -\> Logstash entry -\> Logstash indexing -\> Kafka -\> Elastic. Currently as a part…

---

## [Monitoring openshift with elastic 8.12](https://discuss.elastic.co/t/monitoring-openshift-with-elastic-8-12/352321)

<div class="topic-metadata">

**Author:** [@gbeltramelli](https://discuss.elastic.co/u/gbeltramelli)\
**Replies:** 0\
**Last updated:** [February 1, 2024, 3:47pm UTC](https://discuss.elastic.co/t/monitoring-openshift-with-elastic-8-12/352321 "2024-02-01T15:47:10Z")

</div>

Hello!! i was looking for any documentation about the procedures for monitoring our openshift with elastic (metrics packets filebeat apm everything) but i was not able to find any up to date info about it, does anyone ha…

---

## [I get status: Red page when connecting to kibana](https://discuss.elastic.co/t/i-get-status-red-page-when-connecting-to-kibana/352317)

<div class="topic-metadata">

**Author:** [@mpniel](https://discuss.elastic.co/u/mpniel)\
**Replies:** 0\
**Last updated:** [February 1, 2024, 3:26pm UTC](https://discuss.elastic.co/t/i-get-status-red-page-when-connecting-to-kibana/352317 "2024-02-01T15:26:13Z")

</div>

I get status: Red page when connecting to kibana. The elasticsearch log say that not enough master nodes discovered. The cluster have 3 nodes and only one node is up. I tried to power on the other nodes but after a whi…

---

## [Logstash Tab / Space Delimiter](https://discuss.elastic.co/t/logstash-tab-space-delimiter/352231)

<div class="topic-metadata">

**Author:** [@dfir](https://discuss.elastic.co/u/dfir)\
**Replies:** 6\
**Last updated:** [February 1, 2024, 2:56pm UTC](https://discuss.elastic.co/t/logstash-tab-space-delimiter/352231 "2024-02-01T14:56:22Z")

</div>

Hi All. I am trying to ingest some IIS logs into Elastic via logtstash. They are CSVs but the separator is NOT a ,. How can I account for a space or a tab as the separator. I have multiple different kinds of files w…

---

## [Knowlegde Graphs, ELK and NEO4j](https://discuss.elastic.co/t/knowlegde-graphs-elk-and-neo4j/351686)

<div class="topic-metadata">

**Author:** [@wil93](https://discuss.elastic.co/u/wil93)\
**Replies:** 4\
**Last updated:** [February 1, 2024, 2:47pm UTC](https://discuss.elastic.co/t/knowlegde-graphs-elk-and-neo4j/351686 "2024-02-01T14:47:48Z")

</div>

Hello, I would like to use ‘knowledge graph’ capabilities to detect and identify potential relationships and patterns in data (1). That data is currently stored in Elasticsearch indices. I would like to detect relation…

---

## [Metricbeat can not connect to elasticsearch](https://discuss.elastic.co/t/metricbeat-can-not-connect-to-elasticsearch/352301)

<div class="topic-metadata">

**Author:** [@Beeblbroy](https://discuss.elastic.co/u/Beeblbroy)\
**Replies:** 0\
**Last updated:** [February 1, 2024, 2:07pm UTC](https://discuss.elastic.co/t/metricbeat-can-not-connect-to-elasticsearch/352301 "2024-02-01T14:07:34Z")

</div>

Hi! I have a VPS running ELK in docker, ports are lisening, and I cannot connect to it from another machine where i've installed metricbeat. ( tried it from two different machine, same issue) I got a following error aft…

---

## [Unable to retrieve version information from Elasticsearch nodes](https://discuss.elastic.co/t/unable-to-retrieve-version-information-from-elasticsearch-nodes/352299)

<div class="topic-metadata">

**Author:** [@Twobuy1](https://discuss.elastic.co/u/Twobuy1)\
**Replies:** 0\
**Last updated:** [February 1, 2024, 2:03pm UTC](https://discuss.elastic.co/t/unable-to-retrieve-version-information-from-elasticsearch-nodes/352299 "2024-02-01T14:03:56Z")

</div>

Elasticsearch starts up good then when i open up kibana i start gettting this issue. Please keep aware this is my first time doing this and new to any type of code. \[2024-02-01T05:55:42.170-08:00\]\[INFO \]\[plugins.alertin…

---

## [Help with my Query :)](https://discuss.elastic.co/t/help-with-my-query/351975)

<div class="topic-metadata">

**Author:** [@Kiwisaki](https://discuss.elastic.co/u/Kiwisaki)\
**Replies:** 2\
**Last updated:** [February 1, 2024, 1:46pm UTC](https://discuss.elastic.co/t/help-with-my-query/351975 "2024-02-01T13:46:28Z")

</div>

Can anyone advise where im going wrong with my query ? I am trying to achieve the following: Generate an Alert whenever event.code 4648 is seen - with the only exception being to not alert if the winlog.event\_data.Subj…

---

## [How to set precision\_threshold in Kibana 8.10 version](https://discuss.elastic.co/t/how-to-set-precision-threshold-in-kibana-8-10-version/350904)

<div class="topic-metadata">

**Author:** [@Sagesh](https://discuss.elastic.co/u/Sagesh)\
**Replies:** 1\
**Last updated:** [February 1, 2024, 1:45pm UTC](https://discuss.elastic.co/t/how-to-set-precision-threshold-in-kibana-8-10-version/350904 "2024-02-01T13:45:04Z")

</div>

Precision\_threshold is not working in Kibana 8.10.2 version. I tried providing it in Advance Json like "{ "precision\_threshold":4000} but it throws an error. Thanks, Sagesh

---

## [Meaning of packages/methods with underscore prefix in java-api library](https://discuss.elastic.co/t/meaning-of-packages-methods-with-underscore-prefix-in-java-api-library/352295)

<div class="topic-metadata">

**Author:** [@buitcj](https://discuss.elastic.co/u/buitcj)\
**Replies:** 0\
**Last updated:** [February 1, 2024, 1:44pm UTC](https://discuss.elastic.co/t/meaning-of-packages-methods-with-underscore-prefix-in-java-api-library/352295 "2024-02-01T13:44:44Z")

</div>

Just wondering why some of method calls like the following \_toQuery(), which was found in public docs, have underscore prefixes. I also saw this in some packages like \_types. Typically I see this done for internal usage,…

---

## [Create analytics based dashboard](https://discuss.elastic.co/t/create-analytics-based-dashboard/352294)

<div class="topic-metadata">

**Author:** [@Prakash\_Khadka](https://discuss.elastic.co/u/Prakash_Khadka)\
**Replies:** 0\
**Last updated:** [February 1, 2024, 1:40pm UTC](https://discuss.elastic.co/t/create-analytics-based-dashboard/352294 "2024-02-01T13:40:22Z")

</div>

Hello, Under app search --\> analytics, I can see the analytics related to queries, and clicks. However, these records can't be exported directly from the analytics. Therefore, I want to create a dashboard with top queri…

---

## [Snapshot creation failed](https://discuss.elastic.co/t/snapshot-creation-failed/352243)

<div class="topic-metadata">

**Author:** [@VijayIQA](https://discuss.elastic.co/u/VijayIQA)\
**Replies:** 0\
**Last updated:** [February 1, 2024, 4:51am UTC](https://discuss.elastic.co/t/snapshot-creation-failed/352243 "2024-02-01T04:51:12Z")

</div>

HI Team, I was taken snapshot of Elasticsearch version 8.8.1, Then restored that snapshot into Elasticsearch version of 8.12.0. Now Tried to take snapshot from Elasticsearch version of 8.12.0 Getting an error as {"@ti…

---

## [How can a Threshold line be provided on a Vertical bar graph in Kibana?](https://discuss.elastic.co/t/how-can-a-threshold-line-be-provided-on-a-vertical-bar-graph-in-kibana/352259)

<div class="topic-metadata">

**Author:** [@Pushpender\_Singh](https://discuss.elastic.co/u/Pushpender_Singh)\
**Replies:** 1\
**Last updated:** [February 1, 2024, 1:33pm UTC](https://discuss.elastic.co/t/how-can-a-threshold-line-be-provided-on-a-vertical-bar-graph-in-kibana/352259 "2024-02-01T13:33:07Z")

</div>

Hi Elastic Community, I am not able to get a threshold line on my Vertical bar graph, after selecting "Show Threshold Line" and configuring Panel Settings as shown below. Even after I update all the details as shown bel…

---

## [Elasticsearch and Kibana 8.11.3 running issue in WSL](https://discuss.elastic.co/t/elasticsearch-and-kibana-8-11-3-running-issue-in-wsl/352289)

<div class="topic-metadata">

**Author:** [@vikas.shirke](https://discuss.elastic.co/u/vikas.shirke)\
**Replies:** 2\
**Last updated:** [February 1, 2024, 1:24pm UTC](https://discuss.elastic.co/t/elasticsearch-and-kibana-8-11-3-running-issue-in-wsl/352289 "2024-02-01T13:24:51Z")

</div>

Hi I am trying to run Elasticsearch and Kibana version 8.11.3 on Windows WSL version to build custom theme. I am able to run the yarn kbn bootstrap sucessfully. I have used below commands in separate windows to start …

[Previous page](https://discuss.elastic.co/latest.md?page=412)

[Next page](https://discuss.elastic.co/latest.md?page=414)
