# Latest

**URL:** https://discuss.elastic.co/latest.md?page=426

[Latest](https://discuss.elastic.co/latest.md) · [Categories](https://discuss.elastic.co/categories.md) · [Tags](https://discuss.elastic.co/tags.md)

**Page:** 427

---

## [Need help building dashboard](https://discuss.elastic.co/t/need-help-building-dashboard/351467)

<div class="topic-metadata">

**Author:** [@gnatola](https://discuss.elastic.co/u/gnatola)\
**Replies:** 1\
**Last updated:** [January 19, 2024, 9:45pm UTC](https://discuss.elastic.co/t/need-help-building-dashboard/351467 "2024-01-19T21:45:18Z")

</div>

Hello, I want to build a dashboard that shows users with failed logins and the number of failed logins for the last 24 hours. I built a dashboard, but it shows all users, even those whose login did not fail. How do I lim…

---

## [Software Inventory Management](https://discuss.elastic.co/t/software-inventory-management/350585)

<div class="topic-metadata">

**Author:** [@praveen\_raju](https://discuss.elastic.co/u/praveen_raju)\
**Replies:** 1\
**Last updated:** [January 19, 2024, 9:15pm UTC](https://discuss.elastic.co/t/software-inventory-management/350585 "2024-01-19T21:15:20Z")

</div>

Hi, We currently have 5000 virtual machines under monitoring using the Elastic Stack (using elastic agent). In light of recent changes, specifically the removal of the SAM module from ServiceNow, we are interested in cr…

---

## [How to delete kibana dashboard via API in ELK 8.11.3?](https://discuss.elastic.co/t/how-to-delete-kibana-dashboard-via-api-in-elk-8-11-3/350520)

<div class="topic-metadata">

**Author:** [@learningelastic](https://discuss.elastic.co/u/learningelastic)\
**Replies:** 1\
**Last updated:** [January 19, 2024, 8:29pm UTC](https://discuss.elastic.co/t/how-to-delete-kibana-dashboard-via-api-in-elk-8-11-3/350520 "2024-01-19T20:29:55Z")

</div>

Right now I'm using ELK 8.11.3 I made a Kibana Dashboard with the id 7eb136ba-4ef4-4f99-8ec3-b58673a748ec. Then I ran this curl statement to delete the dashboard: curl -k -X DELETE -u elastic:changeme "https://kibana:…

---

## [Logstash filter if statement when detecting multiple whitespace in middle of string](https://discuss.elastic.co/t/logstash-filter-if-statement-when-detecting-multiple-whitespace-in-middle-of-string/351457)

<div class="topic-metadata">

**Author:** [@mhoward](https://discuss.elastic.co/u/mhoward)\
**Replies:** 2\
**Last updated:** [January 19, 2024, 7:45pm UTC](https://discuss.elastic.co/t/logstash-filter-if-statement-when-detecting-multiple-whitespace-in-middle-of-string/351457 "2024-01-19T19:45:10Z")

</div>

Hey all. I'm working on a Logstash pipeline that includes processing addresses. Here's what my sample data might look like: " 123 ABC Street" "456 XYZ Street (a bunch of whitespaces here) PO Box 78…

---

## [Mismatch Between Query Result and Index Immediately After Re-Indexing](https://discuss.elastic.co/t/mismatch-between-query-result-and-index-immediately-after-re-indexing/351419)

<div class="topic-metadata">

**Author:** [@safakkbilici](https://discuss.elastic.co/u/safakkbilici)\
**Replies:** 6\
**Last updated:** [January 19, 2024, 7:49pm UTC](https://discuss.elastic.co/t/mismatch-between-query-result-and-index-immediately-after-re-indexing/351419 "2024-01-19T19:49:10Z")

</div>

Hello community, I have an index and our post-indexing step, we re-index the index and after, the pipeline (written in Java) uses an aggregation query to fetch product attributes (for example categories and their counts…

---

## [My Timestamp in audit log using SYSLOG input plugin not in correct format](https://discuss.elastic.co/t/my-timestamp-in-audit-log-using-syslog-input-plugin-not-in-correct-format/351127)

<div class="topic-metadata">

**Author:** [@Subrato1](https://discuss.elastic.co/u/Subrato1)\
**Replies:** 9\
**Last updated:** [January 19, 2024, 7:07pm UTC](https://discuss.elastic.co/t/my-timestamp-in-audit-log-using-syslog-input-plugin-not-in-correct-format/351127 "2024-01-19T19:07:22Z")

</div>

Configuration is below : input { syslog { port =\> 5514 type =\> "scylladb" } } filter { if \[type\] == "scylladb" { grok{ match =\> {"message" =\> "%{IP:server\_ip}:%{DATA:server\_port},\\s%{DATA:categ…

---

## [Logstash Integration Plugin configuration option field issue (Logstash Input Plugin add\_filed issue)](https://discuss.elastic.co/t/logstash-integration-plugin-configuration-option-field-issue-logstash-input-plugin-add-filed-issue/351439)

<div class="topic-metadata">

**Author:** [@siva0030](https://discuss.elastic.co/u/siva0030)\
**Replies:** 3\
**Last updated:** [January 19, 2024, 6:58pm UTC](https://discuss.elastic.co/t/logstash-integration-plugin-configuration-option-field-issue-logstash-input-plugin-add-filed-issue/351439 "2024-01-19T18:58:13Z")

</div>

Hello Team, Good noon! Recently, I've upgraded my Logstash to 8.11.3 version. Starting from Logstash 8.11 version, Logstash Integration Plugin is available. I was trying to use the Logstash input plugin to receive the …

---

## [How to write the following Elastic Search into advanced script query?](https://discuss.elastic.co/t/how-to-write-the-following-elastic-search-into-advanced-script-query/351111)

<div class="topic-metadata">

**Author:** [@ElasticDev1](https://discuss.elastic.co/u/ElasticDev1)\
**Replies:** 8\
**Last updated:** [January 19, 2024, 4:22pm UTC](https://discuss.elastic.co/t/how-to-write-the-following-elastic-search-into-advanced-script-query/351111 "2024-01-19T16:22:18Z")

</div>

{ "took": 13, "timed\_out": false, "\_shards": { "total": 5, "successful": 5, "skipped": 0, "failed": 0 }, "hits": { "total": { "value": 2, "relation": "eq" }, "max\_score":…

---

## [Learning how to use the Strigo lab](https://discuss.elastic.co/t/learning-how-to-use-the-strigo-lab/351080)

<div class="topic-metadata">

**Author:** [@aneled](https://discuss.elastic.co/u/aneled)\
**Replies:** 10\
**Last updated:** [January 19, 2024, 4:06pm UTC](https://discuss.elastic.co/t/learning-how-to-use-the-strigo-lab/351080 "2024-01-19T16:06:04Z")

</div>

Good day, I would like to get help on how to use the strigo lab for Elastic Security Fundamentals: SIEM I am new to this environment , I have already completed the 3 topics now I'm stuck at the lab after finishing Anom…

---

## [Sort Results by Matching Pair of GeoPoints within a single document](https://discuss.elastic.co/t/sort-results-by-matching-pair-of-geopoints-within-a-single-document/351199)

<div class="topic-metadata">

**Author:** [@ty.mivance](https://discuss.elastic.co/u/ty.mivance)\
**Replies:** 3\
**Last updated:** [January 19, 2024, 3:16pm UTC](https://discuss.elastic.co/t/sort-results-by-matching-pair-of-geopoints-within-a-single-document/351199 "2024-01-19T15:16:43Z")

</div>

Hi Everyone, We have an elastic index that contains the following field mapping: "mappings": { "properties": { "destination": { "type": "geo\_point" }, …

---

## [One node with high specs vs two nodes with medium specs. Performance expectation](https://discuss.elastic.co/t/one-node-with-high-specs-vs-two-nodes-with-medium-specs-performance-expectation/351133)

<div class="topic-metadata">

**Author:** [@Prashant\_Rana](https://discuss.elastic.co/u/Prashant_Rana)\
**Replies:** 2\
**Last updated:** [January 19, 2024, 2:22pm UTC](https://discuss.elastic.co/t/one-node-with-high-specs-vs-two-nodes-with-medium-specs-performance-expectation/351133 "2024-01-19T14:22:49Z")

</div>

I want to know, what indexing performance (logs indexed per second) I can expect with the single machine of 16 cores,16GB vs two-node setup of 8 cores and 16 GB RAM. (Two shards per index. Both nodes contain one shar…

---

## [Metrics system overview dashboard redirects to a 404 Dashboard not found page in Kibana](https://discuss.elastic.co/t/metrics-system-overview-dashboard-redirects-to-a-404-dashboard-not-found-page-in-kibana/351033)

<div class="topic-metadata">

**Author:** [@Patr123](https://discuss.elastic.co/u/Patr123)\
**Replies:** 10\
**Last updated:** [January 19, 2024, 2:22pm UTC](https://discuss.elastic.co/t/metrics-system-overview-dashboard-redirects-to-a-404-dashboard-not-found-page-in-kibana/351033 "2024-01-19T14:22:04Z")

</div>

Hello, We are using Kibana v8.10.4 and have installed elastic agent on one linux and a windows system. I do see logs/metrics coming in and see the dashboard visualizations getting populated for the Metrics system overv…

---

## [Using Filebeat Modules with Logstash and Differentiating Indices in Elasticsearch](https://discuss.elastic.co/t/using-filebeat-modules-with-logstash-and-differentiating-indices-in-elasticsearch/351438)

<div class="topic-metadata">

**Author:** [@yago82](https://discuss.elastic.co/u/yago82)\
**Replies:** 4\
**Last updated:** [January 19, 2024, 2:21pm UTC](https://discuss.elastic.co/t/using-filebeat-modules-with-logstash-and-differentiating-indices-in-elasticsearch/351438 "2024-01-19T14:21:26Z")

</div>

Hi, I am currently using the Apache module in Filebeat to process my Apache logs. My setup involves sending these logs to Logstash and then to Elasticsearch. I understand from the documentation (Working with Filebeat M…

---

## [Script agent removal](https://discuss.elastic.co/t/script-agent-removal/351443)

<div class="topic-metadata">

**Author:** [@Nightingale\_John](https://discuss.elastic.co/u/Nightingale_John)\
**Replies:** 2\
**Last updated:** [January 19, 2024, 2:05pm UTC](https://discuss.elastic.co/t/script-agent-removal/351443 "2024-01-19T14:05:45Z")

</div>

Hi All, Hopefully this is a quick question for someone.. but I can't find any API to unenroll an agent from Elastic? I've tried a few methods but can't seem to make progress. Is anyone aware of anyway to script an agen…

---

## [Healt indicator not showing on all services](https://discuss.elastic.co/t/healt-indicator-not-showing-on-all-services/351265)

<div class="topic-metadata">

**Author:** [@flalar](https://discuss.elastic.co/u/flalar)\
**Replies:** 2\
**Last updated:** [January 19, 2024, 1:55pm UTC](https://discuss.elastic.co/t/healt-indicator-not-showing-on-all-services/351265 "2024-01-19T13:55:37Z")

</div>

Hi, We have a few .net services instrumented with elastic apm. However, it seems the APM server is not able to detect if a service is healty or not for anything other than web requests. See screenshot below. Is ther…

---

## [Logstash input/output plugin SSL configuration error](https://discuss.elastic.co/t/logstash-input-output-plugin-ssl-configuration-error/351447)

<div class="topic-metadata">

**Author:** [@matus.vlcek](https://discuss.elastic.co/u/matus.vlcek)\
**Replies:** 0\
**Last updated:** [January 19, 2024, 1:35pm UTC](https://discuss.elastic.co/t/logstash-input-output-plugin-ssl-configuration-error/351447 "2024-01-19T13:35:25Z")

</div>

Hi guys, I've tried to configure new default approach for logstash to logstash communication using logstash input, output plugins. It works fine without SSL, but I wasn't able to get SSL to work. It outputs this error o…

---

## [Elastic Agent support RHEL 6](https://discuss.elastic.co/t/elastic-agent-support-rhel-6/351372)

<div class="topic-metadata">

**Author:** [@sajmeister](https://discuss.elastic.co/u/sajmeister)\
**Replies:** 2\
**Last updated:** [January 19, 2024, 12:33pm UTC](https://discuss.elastic.co/t/elastic-agent-support-rhel-6/351372 "2024-01-19T12:33:55Z")

</div>

Hiya, We are using Elastic Agent version 8.10.2 and can see it works on RHEL 7 but not on RHEL 6. The Support Matrix also confirms that. We then tried an older version of the Elastic Agent v7.17 on RHEL 6 and that als…

---

## [Timeout Bulk indexing with python client for even low number of documents](https://discuss.elastic.co/t/timeout-bulk-indexing-with-python-client-for-even-low-number-of-documents/351411)

<div class="topic-metadata">

**Author:** [@Rushi\_Goswami](https://discuss.elastic.co/u/Rushi_Goswami)\
**Replies:** 2\
**Last updated:** [January 19, 2024, 11:35am UTC](https://discuss.elastic.co/t/timeout-bulk-indexing-with-python-client-for-even-low-number-of-documents/351411 "2024-01-19T11:35:51Z")

</div>

I have platinum ELK on Azure with Kibana, I have setup 2 ML inference pipelines with ELSER for 2 different indices. Then I have started indexing for both of the indices with ml inference pipeline. But indexing is slowe…

---

## [Strigo Lab : Browser redirections to Kibana Start Page](https://discuss.elastic.co/t/strigo-lab-browser-redirections-to-kibana-start-page/351371)

<div class="topic-metadata">

**Author:** [@marmai16](https://discuss.elastic.co/u/marmai16)\
**Replies:** 2\
**Last updated:** [January 19, 2024, 9:20am UTC](https://discuss.elastic.co/t/strigo-lab-browser-redirections-to-kibana-start-page/351371 "2024-01-19T09:20:39Z")

</div>

Course: Analyst Practice Exam Version: 8.8.1 Question: Hello everyone, i’ve encountered an issue with my practice exam Strigo lab. Upon saving changes to a map visualization, the browser within Strigo (not Kibana it…

---

## [Querying an alias throws off scoring completely?](https://discuss.elastic.co/t/querying-an-alias-throws-off-scoring-completely/351423)

<div class="topic-metadata">

**Author:** [@pudo](https://discuss.elastic.co/u/pudo)\
**Replies:** 6\
**Last updated:** [January 19, 2024, 9:20am UTC](https://discuss.elastic.co/t/querying-an-alias-throws-off-scoring-completely/351423 "2024-01-19T09:20:10Z")

</div>

Hey all! I’m seeing some really weird behaviour around index aliases, maybe I’m doing something conceptually dumb. We have two indexes of very different size (example: 4mn docs in entities-a and 2(!) docs in entities-b …

---

## [SQL Bulk copy operation not captured by Apm Agent](https://discuss.elastic.co/t/sql-bulk-copy-operation-not-captured-by-apm-agent/350908)

<div class="topic-metadata">

**Author:** [@vinaykoul4](https://discuss.elastic.co/u/vinaykoul4)\
**Replies:** 5\
**Last updated:** [January 19, 2024, 9:17am UTC](https://discuss.elastic.co/t/sql-bulk-copy-operation-not-captured-by-apm-agent/350908 "2024-01-19T09:17:33Z")

</div>

We are using SQLBulkCopy.Write ToServerAsync method to write data to tables but these operations are not captured by APM agent. Agent is subscribed to SqlClientDiagnosticSubscriber Tried with adding package Elastic.Apm…

---

## [Painless sort not working in call cases on 8.12.0?](https://discuss.elastic.co/t/painless-sort-not-working-in-call-cases-on-8-12-0/351414)

<div class="topic-metadata">

**Author:** [@ilgrosso](https://discuss.elastic.co/u/ilgrosso)\
**Replies:** 0\
**Last updated:** [January 19, 2024, 7:51am UTC](https://discuss.elastic.co/t/painless-sort-not-working-in-call-cases-on-8-12-0/351414 "2024-01-19T07:51:14Z")

</div>

The following is working as expected up to 8.11.4: "sort": \[ { "\_script": { "order": "asc", "script": { "lang": "painless", …

---

## [Logstash cannot read new lines that are coming from .NET error exception msg](https://discuss.elastic.co/t/logstash-cannot-read-new-lines-that-are-coming-from-net-error-exception-msg/351340)

<div class="topic-metadata">

**Author:** [@theo003](https://discuss.elastic.co/u/theo003)\
**Replies:** 3\
**Last updated:** [January 19, 2024, 8:33am UTC](https://discuss.elastic.co/t/logstash-cannot-read-new-lines-that-are-coming-from-net-error-exception-msg/351340 "2024-01-19T08:33:55Z")

</div>

Hello, Our system is throwing some error exceptions in the logs with the following format: |17 01 2024 08:22:10,614| |ERROR| CreateSession API... File: "File\_name" Line: 290System.InvalidOperationException: "Error\_msg"…

---

## [Buffer overflow issue Flunetd not able to push logs to elasticsearch cluster](https://discuss.elastic.co/t/buffer-overflow-issue-flunetd-not-able-to-push-logs-to-elasticsearch-cluster/351418)

<div class="topic-metadata">

**Author:** [@Music\_World](https://discuss.elastic.co/u/Music_World)\
**Replies:** 0\
**Last updated:** [January 19, 2024, 8:04am UTC](https://discuss.elastic.co/t/buffer-overflow-issue-flunetd-not-able-to-push-logs-to-elasticsearch-cluster/351418 "2024-01-19T08:04:30Z")

</div>

Hi @all I am using elasticsearch version: 7.16.2 and fluentd version: 1.14.4 on aws eks cluster and it's throwing bufferoverflow error like failed to flush the buffer. retry\_times=0 next\_retry\_time=2024-01-19 07:43:43…

---

## [Cannot get 'Index' variant: current variant is 'Update'](https://discuss.elastic.co/t/cannot-get-index-variant-current-variant-is-update/351417)

<div class="topic-metadata">

**Author:** [@jiyong\_qin](https://discuss.elastic.co/u/jiyong_qin)\
**Replies:** 0\
**Last updated:** [January 19, 2024, 8:03am UTC](https://discuss.elastic.co/t/cannot-get-index-variant-current-variant-is-update/351417 "2024-01-19T08:03:16Z")

</div>

hi @all when i use flink(1.14.4) write data to es 8.6.2 use BulkOperation ,then something is wrong. Cannot get 'Index' variant: current variant is 'Update' and Missing required property 'BulkRequest.operations'. I don'…

---

## [How to display the maximum number of shards allowed per node?](https://discuss.elastic.co/t/how-to-display-the-maximum-number-of-shards-allowed-per-node/351308)

<div class="topic-metadata">

**Author:** [@mpniel](https://discuss.elastic.co/u/mpniel)\
**Replies:** 4\
**Last updated:** [January 19, 2024, 7:54am UTC](https://discuss.elastic.co/t/how-to-display-the-maximum-number-of-shards-allowed-per-node/351308 "2024-01-19T07:54:34Z")

</div>

how to display the maximum number of shards allowed per node?

---

## [How does elastic agent configure filebeat](https://discuss.elastic.co/t/how-does-elastic-agent-configure-filebeat/351187)

<div class="topic-metadata">

**Author:** [@mbby](https://discuss.elastic.co/u/mbby)\
**Replies:** 9\
**Last updated:** [January 19, 2024, 7:17am UTC](https://discuss.elastic.co/t/how-does-elastic-agent-configure-filebeat/351187 "2024-01-19T07:17:22Z")

</div>

Hi, I've installed an agent and added a custom log integration to the policy. It's working but I'm wondering if there's some documentation which tells me: How does the agent configure filebeat? I searched in the filesy…

---

## [Help on Elastic Search query](https://discuss.elastic.co/t/help-on-elastic-search-query/351409)

<div class="topic-metadata">

**Author:** [@hmulky](https://discuss.elastic.co/u/hmulky)\
**Replies:** 0\
**Last updated:** [January 19, 2024, 6:56am UTC](https://discuss.elastic.co/t/help-on-elastic-search-query/351409 "2024-01-19T06:56:23Z")

</div>

Hello, I think i may need some help here. I have a record in EFK as below orchestrator.resource.name : "akr1r3\*" and (log.file.path : /var/log/abc.log) and (message : "Signing with P-Origination Id \\\\\[F92DAEC5-F1C9-4F8…

---

## [Kibana Area Chart -Split chart twice i.e per release, per brand on X axis](https://discuss.elastic.co/t/kibana-area-chart-split-chart-twice-i-e-per-release-per-brand-on-x-axis/351347)

<div class="topic-metadata">

**Author:** [@PRASHANT\_MEHTA](https://discuss.elastic.co/u/PRASHANT_MEHTA)\
**Replies:** 0\
**Last updated:** [January 18, 2024, 10:04am UTC](https://discuss.elastic.co/t/kibana-area-chart-split-chart-twice-i-e-per-release-per-brand-on-x-axis/351347 "2024-01-18T10:04:30Z")

</div>

Hello All, I've a requirement and mostly I'm aware this won't be possible , but for second opinion need feedback if this can be done in some way. I am using normal area chart and problem is can SPLIT THE CHART TWICE , …

---

## [Unable to enroll Elastic Agent to fleet running in the cloud](https://discuss.elastic.co/t/unable-to-enroll-elastic-agent-to-fleet-running-in-the-cloud/351394)

<div class="topic-metadata">

**Author:** [@vngcyber](https://discuss.elastic.co/u/vngcyber)\
**Replies:** 0\
**Last updated:** [January 19, 2024, 4:00am UTC](https://discuss.elastic.co/t/unable-to-enroll-elastic-agent-to-fleet-running-in-the-cloud/351394 "2024-01-19T04:00:53Z")

</div>

Getting the below error message when attempting to enroll an Elastic Agent to a Fleet running in Elastic Cloud. Please help! {"log.level":"info","@timestamp":"2024-01-18T22:51:26.027-0500","log.origin":{"file.name":"cmd…

[Previous page](https://discuss.elastic.co/latest.md?page=425)

[Next page](https://discuss.elastic.co/latest.md?page=427)
