# Latest

**URL:** https://discuss.elastic.co/latest.md?page=414

[Latest](https://discuss.elastic.co/latest.md) · [Categories](https://discuss.elastic.co/categories.md) · [Tags](https://discuss.elastic.co/tags.md)

**Page:** 415

---

## [\[Help\] Help about Winogbeat service failure](https://discuss.elastic.co/t/help-help-about-winogbeat-service-failure/352283)

<div class="topic-metadata">

**Author:** [@YUUTA.INOUE-JPN](https://discuss.elastic.co/u/YUUTA.INOUE-JPN)\
**Replies:** 0\
**Last updated:** [February 1, 2024, 12:56pm UTC](https://discuss.elastic.co/t/help-help-about-winogbeat-service-failure/352283 "2024-02-01T12:56:57Z")

</div>

Hello From Japan Dear Elastic Engineers, I would like you to check a small problem that occurred in my environment. My environment is winlogbeat8.11 and I want to send Windows event viewer logs to Elaticsearch. The co…

---

## [Remote Cluster node 9300 port cannot connect](https://discuss.elastic.co/t/remote-cluster-node-9300-port-cannot-connect/352031)

<div class="topic-metadata">

**Author:** [@rachelyang](https://discuss.elastic.co/u/rachelyang)\
**Replies:** 1\
**Last updated:** [February 1, 2024, 12:40pm UTC](https://discuss.elastic.co/t/remote-cluster-node-9300-port-cannot-connect/352031 "2024-02-01T12:40:56Z")

</div>

I am connecting a remote cluster from the local cluster. I got a connection time out error. Then I tried to curl the 9200 and 9300 port from the local cluster note to the remote cluster node. This is the response: curl …

---

## [Horizontal scaling of Elasticsearch cluster](https://discuss.elastic.co/t/horizontal-scaling-of-elasticsearch-cluster/352147)

<div class="topic-metadata">

**Author:** [@Priyanka\_chauhan](https://discuss.elastic.co/u/Priyanka_chauhan)\
**Replies:** 5\
**Last updated:** [February 1, 2024, 12:33pm UTC](https://discuss.elastic.co/t/horizontal-scaling-of-elasticsearch-cluster/352147 "2024-02-01T12:33:19Z")

</div>

if I have index size of 2tb and node size is 1tb , In that case how index will split on another nodes and if i add new data nodes so how this data can be distribute, it will do automatically? Or I can do it manually. I w…

---

## [Snapshot policy snapshot name as uniq ID](https://discuss.elastic.co/t/snapshot-policy-snapshot-name-as-uniq-id/352279)

<div class="topic-metadata">

**Author:** [@VijayIQA](https://discuss.elastic.co/u/VijayIQA)\
**Replies:** 1\
**Last updated:** [February 1, 2024, 12:29pm UTC](https://discuss.elastic.co/t/snapshot-policy-snapshot-name-as-uniq-id/352279 "2024-02-01T12:29:50Z")

</div>

Hi Team, here is my snapshot policy snapshot name math expression \<test-snap-{now{MM-dd-yyyy\_HH-mm|Asia/Kolkata}}\> so the result should be test-snap-02-01-2024\_17-09 but in kibana UI the snapshot name showing as test-s…

---

## [Get the result of split two values into alert or another value](https://discuss.elastic.co/t/get-the-result-of-split-two-values-into-alert-or-another-value/351645)

<div class="topic-metadata">

**Author:** [@cperzrt10](https://discuss.elastic.co/u/cperzrt10)\
**Replies:** 1\
**Last updated:** [February 1, 2024, 12:01pm UTC](https://discuss.elastic.co/t/get-the-result-of-split-two-values-into-alert-or-another-value/351645 "2024-02-01T12:01:13Z")

</div>

I have data with 2 variables, one is the total number of http response code and another is only the total of http response code with the value of "200". the structure is the result of transform the result is like this …

---

## [Stylizing TSVB or Lens in Canvas](https://discuss.elastic.co/t/stylizing-tsvb-or-lens-in-canvas/351459)

<div class="topic-metadata">

**Author:** [@Tom-Gorup](https://discuss.elastic.co/u/Tom-Gorup)\
**Replies:** 1\
**Last updated:** [February 1, 2024, 11:54am UTC](https://discuss.elastic.co/t/stylizing-tsvb-or-lens-in-canvas/351459 "2024-02-01T11:54:43Z")

</div>

Running into a few challenges as I attempt to tackle this problem in myriad ways. First, my desired outcome is a (1) stylized horizontal bar chart using percentage (2) as the value for each aggregated row while includin…

---

## [I have created ubuntu server for receiving logs from fortigate30e using logstash](https://discuss.elastic.co/t/i-have-created-ubuntu-server-for-receiving-logs-from-fortigate30e-using-logstash/352278)

<div class="topic-metadata">

**Author:** [@Eepe123](https://discuss.elastic.co/u/Eepe123)\
**Replies:** 0\
**Last updated:** [February 1, 2024, 11:29am UTC](https://discuss.elastic.co/t/i-have-created-ubuntu-server-for-receiving-logs-from-fortigate30e-using-logstash/352278 "2024-02-01T11:29:43Z")

</div>

Its not working and everything points to a network error, fortigate30e cant ping our ubuntu server but ubuntu server can ping fortigate firewall. Does anyone know anything we could try to fix network issue or could this …

---

## [Metricbeat package failure (mitchellh/osext not found)](https://discuss.elastic.co/t/metricbeat-package-failure-mitchellh-osext-not-found/352275)

<div class="topic-metadata">

**Author:** [@holodomi](https://discuss.elastic.co/u/holodomi)\
**Replies:** 0\
**Last updated:** [February 1, 2024, 11:12am UTC](https://discuss.elastic.co/t/metricbeat-package-failure-mitchellh-osext-not-found/352275 "2024-02-01T11:12:35Z")

</div>

I am trying to build metricbeat from scratch but am getting hung up on 'https://github.com/mitchellh/osext/' apparently not existing anymore. I am building with: $ git clone https://github.com/elastic/beats.git $ cd be…

---

## [Secure Connection Between Filebeat & Logstash using Basic Auth](https://discuss.elastic.co/t/secure-connection-between-filebeat-logstash-using-basic-auth/352269)

<div class="topic-metadata">

**Author:** [@Dhiwakar\_Ravikumar](https://discuss.elastic.co/u/Dhiwakar_Ravikumar)\
**Replies:** 1\
**Last updated:** [February 1, 2024, 10:22am UTC](https://discuss.elastic.co/t/secure-connection-between-filebeat-logstash-using-basic-auth/352269 "2024-02-01T10:22:05Z")

</div>

I want to secure the connection between filebeat & logstash using basic authentication. For logstash, I figured out that we can enable authentication for the logstash http input plugin BUT neither is such an option avai…

---

## [Search API requests returns Error 500 Internal Server Error: An internal server error occurred](https://discuss.elastic.co/t/search-api-requests-returns-error-500-internal-server-error-an-internal-server-error-occurred/352260)

<div class="topic-metadata">

**Author:** [@PustyB](https://discuss.elastic.co/u/PustyB)\
**Replies:** 7\
**Last updated:** [February 1, 2024, 9:57am UTC](https://discuss.elastic.co/t/search-api-requests-returns-error-500-internal-server-error-an-internal-server-error-occurred/352260 "2024-02-01T09:57:36Z")

</div>

Hi I have a problem with Enterprise search. I have loaded the index and want to test the search through Search UI. And generally it works fine, but sometimes the error "Internal server error. Please check your applicatio…

---

## [log whoever connects to the kibana web interface](https://discuss.elastic.co/t/log-whoever-connects-to-the-kibana-web-interface/352222)

<div class="topic-metadata">

**Author:** [@clocker87](https://discuss.elastic.co/u/clocker87)\
**Replies:** 5\
**Last updated:** [February 1, 2024, 9:44am UTC](https://discuss.elastic.co/t/log-whoever-connects-to-the-kibana-web-interface/352222 "2024-02-01T09:44:58Z")

</div>

Hi everyone, I need to have logs of who connects to the kibana web interface, I have several accounts and I would like to be able to monitor these accesses. I have kibana version 8.3.2, what can I do? Thank you

---

## [Generates self-signed client certificates (not server certificates) for Elasticsearch clients](https://discuss.elastic.co/t/generates-self-signed-client-certificates-not-server-certificates-for-elasticsearch-clients/352182)

<div class="topic-metadata">

**Author:** [@patpanda](https://discuss.elastic.co/u/patpanda)\
**Replies:** 1\
**Last updated:** [February 1, 2024, 6:58am UTC](https://discuss.elastic.co/t/generates-self-signed-client-certificates-not-server-certificates-for-elasticsearch-clients/352182 "2024-02-01T06:58:04Z")

</div>

What I am trying to achieve Generates self-signed client certificate (not server certificates) for clients trying to connect to Elasticsearch server. What did I try: I ran this command elasticsearch/bin elasticsearc…

---

## [Filebeats doesn't send logs to Elasticsearch](https://discuss.elastic.co/t/filebeats-doesnt-send-logs-to-elasticsearch/352255)

<div class="topic-metadata">

**Author:** [@Vladimir\_Fomin1](https://discuss.elastic.co/u/Vladimir_Fomin1)\
**Replies:** 0\
**Last updated:** [February 1, 2024, 6:45am UTC](https://discuss.elastic.co/t/filebeats-doesnt-send-logs-to-elasticsearch/352255 "2024-02-01T06:45:23Z")

</div>

I have some problems with Filebeats 8.12.0. in the Kubernetes cluster. My filebeat.yml: filebeat.inputs: - type: filestream paths: - /var/log/pods/\*\*/\*.log parsers: - container: ~ prospector: scanner…

---

## [How to bulk migrate users and roles with native realms authentication](https://discuss.elastic.co/t/how-to-bulk-migrate-users-and-roles-with-native-realms-authentication/350476)

<div class="topic-metadata">

**Author:** [@fim](https://discuss.elastic.co/u/fim)\
**Replies:** 1\
**Last updated:** [February 1, 2024, 6:31am UTC](https://discuss.elastic.co/t/how-to-bulk-migrate-users-and-roles-with-native-realms-authentication/350476 "2024-02-01T06:31:08Z")

</div>

I'm looking for an advice how to migrate users (if possible including passwords) and roles from an old cluster to a new cluster. (Elasticsearch v8.x) I wanna perform this with Kibana DevTools. I populate users and role…

---

## [\[Filebeat\] How to read "special text + json string" to es?](https://discuss.elastic.co/t/filebeat-how-to-read-special-text-json-string-to-es/352251)

<div class="topic-metadata">

**Author:** [@uiosun](https://discuss.elastic.co/u/uiosun)\
**Replies:** 0\
**Last updated:** [February 1, 2024, 6:21am UTC](https://discuss.elastic.co/t/filebeat-how-to-read-special-text-json-string-to-es/352251 "2024-02-01T06:21:40Z")

</div>

I have the struct in log files, like there (JSON has near 60 column......): \[2024-01-29 11:10:35\] standard.INFO: {"start\_time": "1706497834.091", "remote\_addr": "www.demo.com", "remote\_user": "a\_user"} \[2024-01-29 11:10…

---

## [Filebeat connecting to a ES cluster that is removed from config file](https://discuss.elastic.co/t/filebeat-connecting-to-a-es-cluster-that-is-removed-from-config-file/352238)

<div class="topic-metadata">

**Author:** [@hjazz6](https://discuss.elastic.co/u/hjazz6)\
**Replies:** 0\
**Last updated:** [February 1, 2024, 1:46am UTC](https://discuss.elastic.co/t/filebeat-connecting-to-a-es-cluster-that-is-removed-from-config-file/352238 "2024-02-01T01:46:27Z")

</div>

Hi, I had previously configured filebeat to connect to 2 ES hosts in filebeat.yml. I have modified the config file to output.elasticsearch.hosts: \["es02.net:443"\] #output.elasticsearch.hosts: \["es01.net:443", "es02.net…

---

## [Daemon startup failed with exit code](https://discuss.elastic.co/t/daemon-startup-failed-with-exit-code/352221)

<div class="topic-metadata">

**Author:** [@userR](https://discuss.elastic.co/u/userR)\
**Replies:** 2\
**Last updated:** [January 31, 2024, 11:19pm UTC](https://discuss.elastic.co/t/daemon-startup-failed-with-exit-code/352221 "2024-01-31T23:19:54Z")

</div>

Hi everyone, I am testing out esrally and running into the following issues while running java17 and testing 8.7.0: \[user ~\]$ esrally race --distribution-version=8.7.0 --track=geonames \_\_\_\_ \_\_\_\_ / \_\_ \\\_\_…

---

## [Packetbeat mysql only works if metricbeat mysql enabled?](https://discuss.elastic.co/t/packetbeat-mysql-only-works-if-metricbeat-mysql-enabled/352113)

<div class="topic-metadata">

**Author:** [@learningelastic](https://discuss.elastic.co/u/learningelastic)\
**Replies:** 2\
**Last updated:** [January 31, 2024, 9:37pm UTC](https://discuss.elastic.co/t/packetbeat-mysql-only-works-if-metricbeat-mysql-enabled/352113 "2024-01-31T21:37:05Z")

</div>

My goal is to go to Kibana \> Dashboard \> \[Packetbeat\] MySQL performance ECS and see some visualizations of my mysql performance. I find that \[Packetbeat\] MySQL performance only shows a bunch of No results found widgets.…

---

## [Logstash 8.11 reports error 403](https://discuss.elastic.co/t/logstash-8-11-reports-error-403/352224)

<div class="topic-metadata">

**Author:** [@andrew3](https://discuss.elastic.co/u/andrew3)\
**Replies:** 3\
**Last updated:** [January 31, 2024, 9:08pm UTC](https://discuss.elastic.co/t/logstash-8-11-reports-error-403/352224 "2024-01-31T21:08:42Z")

</div>

I am trying to connect logstash to elasticsearch. Both are on my local machine. I am using https. Logstash reports error 403. Viz: \` {:code=\>403, :url=\>"https://localhost:9200/\_bulk?filter\_path=errors,items.\*.error,i…

---

## [Logstash installation batch files v8.11.3 do not work](https://discuss.elastic.co/t/logstash-installation-batch-files-v8-11-3-do-not-work/351306)

<div class="topic-metadata">

**Author:** [@andrew3](https://discuss.elastic.co/u/andrew3)\
**Replies:** 3\
**Last updated:** [January 31, 2024, 8:41pm UTC](https://discuss.elastic.co/t/logstash-installation-batch-files-v8-11-3-do-not-work/351306 "2024-01-31T20:41:43Z")

</div>

JRUBY\_BIN: In v8.11.3 SETUP.BAT looks for it in a directory that does not exist in the Windows distribution, causing the "first stash" in the docs. to always fail. Anyone else run across this? Details: In SETUP.BAT lin…

---

## [How to create Sub categories in Data table?](https://discuss.elastic.co/t/how-to-create-sub-categories-in-data-table/352117)

<div class="topic-metadata">

**Author:** [@Shubhankar](https://discuss.elastic.co/u/Shubhankar)\
**Replies:** 4\
**Last updated:** [January 31, 2024, 8:05pm UTC](https://discuss.elastic.co/t/how-to-create-sub-categories-in-data-table/352117 "2024-01-31T20:05:20Z")

</div>

I have generated a data table using the Kibana 8 lens visualization, but I'm uncertain about adding subcategories to it. Specifically, after including the necessary columns, I aim to further segment the data from the sec…

---

## [Filter out APM service.name from ML Job](https://discuss.elastic.co/t/filter-out-apm-service-name-from-ml-job/352215)

<div class="topic-metadata">

**Author:** [@ethranes](https://discuss.elastic.co/u/ethranes)\
**Replies:** 1\
**Last updated:** [January 31, 2024, 5:35pm UTC](https://discuss.elastic.co/t/filter-out-apm-service-name-from-ml-job/352215 "2024-01-31T17:35:27Z")

</div>

Hi. From my APM page, I have setup a high transaction duration ML job. I am only able to base it from the service.environment. The issue with this is that one service, in the environment is red a lot, and we don't really…

---

## [Unable to download Kibana Windows Winzip](https://discuss.elastic.co/t/unable-to-download-kibana-windows-winzip/351365)

<div class="topic-metadata">

**Author:** [@SPT](https://discuss.elastic.co/u/SPT)\
**Replies:** 2\
**Last updated:** [January 31, 2024, 5:29pm UTC](https://discuss.elastic.co/t/unable-to-download-kibana-windows-winzip/351365 "2024-01-31T17:29:46Z")

</div>

I tried to extract the zip file but it complains that the path is too long on some files. Any advice or an alternate option to get this? Thanks.

---

## [FSCrawler - Indexing mix of Big and small files - HTTP Entity too large error](https://discuss.elastic.co/t/fscrawler-indexing-mix-of-big-and-small-files-http-entity-too-large-error/350939)

<div class="topic-metadata">

**Author:** [@kamalsharma](https://discuss.elastic.co/u/kamalsharma)\
**Replies:** 8\
**Last updated:** [January 31, 2024, 5:12pm UTC](https://discuss.elastic.co/t/fscrawler-indexing-mix-of-big-and-small-files-http-entity-too-large-error/350939 "2024-01-31T17:12:19Z")

</div>

I have splitted a large text file into multiple files of 50 MB each. When the setting of bulk\_size is 1 in Fscrawler \_settings.json, each file is indexed into Elasticsearch without any error. If the bulk size is increase…

---

## [How To Install Bundled APM Plugin](https://discuss.elastic.co/t/how-to-install-bundled-apm-plugin/352095)

<div class="topic-metadata">

**Author:** [@Evesy](https://discuss.elastic.co/u/Evesy)\
**Replies:** 0\
**Last updated:** [January 30, 2024, 2:07pm UTC](https://discuss.elastic.co/t/how-to-install-bundled-apm-plugin/352095 "2024-01-30T14:07:03Z")

</div>

Kibana 8.12.0 introduced a new bundled X-Pack plugin (x-pack/plugin/apm: introduce x-pack-apm plugin · axw/elasticsearch@2aebfcc · GitHub) that allows installing APM related index templates etc. without the need for conf…

---

## [Overwrite @timestamp field](https://discuss.elastic.co/t/overwrite-timestamp-field/352212)

<div class="topic-metadata">

**Author:** [@rmoss25](https://discuss.elastic.co/u/rmoss25)\
**Replies:** 1\
**Last updated:** [January 31, 2024, 5:03pm UTC](https://discuss.elastic.co/t/overwrite-timestamp-field/352212 "2024-01-31T17:03:58Z")

</div>

Hi, I am trying to overwrite the @timestamp filed with the time from the log source but logstash fails to start when trying to run. I am guessing it has something to do with the "-04" in the time.....see below time fro…

---

## [Who do I contact to get a STIG checklist?](https://discuss.elastic.co/t/who-do-i-contact-to-get-a-stig-checklist/352198)

<div class="topic-metadata">

**Author:** [@chris.pyle](https://discuss.elastic.co/u/chris.pyle)\
**Replies:** 1\
**Last updated:** [January 31, 2024, 4:52pm UTC](https://discuss.elastic.co/t/who-do-i-contact-to-get-a-stig-checklist/352198 "2024-01-31T16:52:54Z")

</div>

federal@elastic.co is not a valid email address.

---

## [Prometheus integration](https://discuss.elastic.co/t/prometheus-integration/352210)

<div class="topic-metadata">

**Author:** [@Lukasz\_Skrzat](https://discuss.elastic.co/u/Lukasz_Skrzat)\
**Replies:** 0\
**Last updated:** [January 31, 2024, 4:05pm UTC](https://discuss.elastic.co/t/prometheus-integration/352210 "2024-01-31T16:05:54Z")

</div>

I have a question/problem. I have several endpoints from Java applications /actuator/prometheus with metrics. Until now, all were aggregated by Prometheus, but I want to fully transition to ECK, so I'm trying to configur…

---

## [Creating Secrets in Elastic Fleet](https://discuss.elastic.co/t/creating-secrets-in-elastic-fleet/352116)

<div class="topic-metadata">

**Author:** [@DougR](https://discuss.elastic.co/u/DougR)\
**Replies:** 4\
**Last updated:** [January 31, 2024, 4:01pm UTC](https://discuss.elastic.co/t/creating-secrets-in-elastic-fleet/352116 "2024-01-31T16:01:56Z")

</div>

I'm using Elastic Cloud v8.12.0. Documentation for Fleet gives instructions on how to use a Fleet secret in an integration policy, but how to I actually CREATE one? I can't find the information in the documentation. E…

---

## [Need to disable insecure SSL cyphers/TLS 1.1 on Elastic Agent](https://discuss.elastic.co/t/need-to-disable-insecure-ssl-cyphers-tls-1-1-on-elastic-agent/352051)

<div class="topic-metadata">

**Author:** [@salemone](https://discuss.elastic.co/u/salemone)\
**Replies:** 3\
**Last updated:** [January 31, 2024, 3:45pm UTC](https://discuss.elastic.co/t/need-to-disable-insecure-ssl-cyphers-tls-1-1-on-elastic-agent/352051 "2024-01-31T15:45:55Z")

</div>

On a recent vulnerability scan we had findings for the Elastic Agent Fleet Server for having TLS 1.1 enabled along with insecure ciphers on port 8220. I have a client asking that we fix this... I added the below to ela…

[Previous page](https://discuss.elastic.co/latest.md?page=413)

[Next page](https://discuss.elastic.co/latest.md?page=415)
