# Latest

**URL:** https://discuss.elastic.co/latest.md?page=428

[Latest](https://discuss.elastic.co/latest.md) · [Categories](https://discuss.elastic.co/categories.md) · [Tags](https://discuss.elastic.co/tags.md)

**Page:** 429

---

## [@timestamp is 4 hours behind when i change timezone in advance setting kibana and database date field is ok](https://discuss.elastic.co/t/timestamp-is-4-hours-behind-when-i-change-timezone-in-advance-setting-kibana-and-database-date-field-is-ok/351107)

<div class="topic-metadata">

**Author:** [@Aslam\_Ansari](https://discuss.elastic.co/u/Aslam_Ansari)\
**Replies:** 6\
**Last updated:** [January 18, 2024, 8:11am UTC](https://discuss.elastic.co/t/timestamp-is-4-hours-behind-when-i-change-timezone-in-advance-setting-kibana-and-database-date-field-is-ok/351107 "2024-01-18T08:11:55Z")

</div>

@timestamp is 4 hours behind when I change the timezone as UTC in Kibana's advance settings and the database date field is correct. However, when I set the timezone as browser advance settings in Kibana, @timestamp is co…

---

## [Changing xpack settings via API](https://discuss.elastic.co/t/changing-xpack-settings-via-api/351316)

<div class="topic-metadata">

**Author:** [@hjazz6](https://discuss.elastic.co/u/hjazz6)\
**Replies:** 1\
**Last updated:** [January 18, 2024, 5:09am UTC](https://discuss.elastic.co/t/changing-xpack-settings-via-api/351316 "2024-01-18T05:09:07Z")

</div>

Hi, I wish to increase the timeout for CSV report generation on Kibana, but I don't have access to the kibana.yml file to change the xpack.reporting.queue.timeout value. Is there a way I can change it via the API method…

---

## [Web crawler is crawling URLs that are not on the sitemap](https://discuss.elastic.co/t/web-crawler-is-crawling-urls-that-are-not-on-the-sitemap/350533)

<div class="topic-metadata">

**Author:** [@mmaccou](https://discuss.elastic.co/u/mmaccou)\
**Replies:** 1\
**Last updated:** [January 17, 2024, 9:23pm UTC](https://discuss.elastic.co/t/web-crawler-is-crawling-urls-that-are-not-on-the-sitemap/350533 "2024-01-17T21:23:59Z")

</div>

I've been struggling to setup this web crawler properly. The sitemap is an XML sitemap, but the format is a table with the link to the page, number of images, and last modified date. The desired experience is for the cra…

---

## [Read Only to Everything in Elastic/Kibana](https://discuss.elastic.co/t/read-only-to-everything-in-elastic-kibana/351089)

<div class="topic-metadata">

**Author:** [@ryans](https://discuss.elastic.co/u/ryans)\
**Replies:** 5\
**Last updated:** [January 17, 2024, 9:03pm UTC](https://discuss.elastic.co/t/read-only-to-everything-in-elastic-kibana/351089 "2024-01-17T21:03:27Z")

</div>

Is there a quick/easy setting in Kibana Roles that would give a user full read only permissions to everything within the Elastic Stack? Basically, I want to create a user with a Role where they can see everything an adm…

---

## [GET \_cat/recovery How to display just 3 columns and where files\_percent \> 90%?](https://discuss.elastic.co/t/get-cat-recovery-how-to-display-just-3-columns-and-where-files-percent-90/351307)

<div class="topic-metadata">

**Author:** [@mpniel](https://discuss.elastic.co/u/mpniel)\
**Replies:** 1\
**Last updated:** [January 17, 2024, 8:57pm UTC](https://discuss.elastic.co/t/get-cat-recovery-how-to-display-just-3-columns-and-where-files-percent-90/351307 "2024-01-17T20:57:01Z")

</div>

GET \_cat/recovery How to display just 3 columns and where files\_percent \> 90% ?

---

## [Elasticsearch Query for Retrieving Dependencies of multiple documents in one index](https://discuss.elastic.co/t/elasticsearch-query-for-retrieving-dependencies-of-multiple-documents-in-one-index/350718)

<div class="topic-metadata">

**Author:** [@Super8film87](https://discuss.elastic.co/u/Super8film87)\
**Replies:** 1\
**Last updated:** [January 17, 2024, 8:45pm UTC](https://discuss.elastic.co/t/elasticsearch-query-for-retrieving-dependencies-of-multiple-documents-in-one-index/350718 "2024-01-17T20:45:34Z")

</div>

Description: I'm facing a challenge with formulating an Elasticsearch query to retrieve dependencies related to a given parent\_id. Here's a brief description of the problem: I have a set of independent documents with f…

---

## [Logstash parsing for dynamic fieldname](https://discuss.elastic.co/t/logstash-parsing-for-dynamic-fieldname/351237)

<div class="topic-metadata">

**Author:** [@Priyanka\_chauhan](https://discuss.elastic.co/u/Priyanka_chauhan)\
**Replies:** 1\
**Last updated:** [January 17, 2024, 7:34pm UTC](https://discuss.elastic.co/t/logstash-parsing-for-dynamic-fieldname/351237 "2024-01-17T19:34:19Z")

</div>

hi, I want to parse message: My message part is looking like after applying json filter is nodes.processes.C86BB2FAC5F22D51.user.name: value1 nodes.processes.C86BB2FAC5F22D51.user.sid: value2 nodes.files.EA68B2FAC5…

---

## [Elastic search (V 7.12.0) pods fail to start after EKS upgrade from 1.24 to 1.25](https://discuss.elastic.co/t/elastic-search-v-7-12-0-pods-fail-to-start-after-eks-upgrade-from-1-24-to-1-25/350300)

<div class="topic-metadata">

**Author:** [@prabeesh.p](https://discuss.elastic.co/u/prabeesh.p)\
**Replies:** 0\
**Last updated:** [January 3, 2024, 11:36am UTC](https://discuss.elastic.co/t/elastic-search-v-7-12-0-pods-fail-to-start-after-eks-upgrade-from-1-24-to-1-25/350300 "2024-01-03T11:36:22Z")

</div>

The application search is running on Elastic search 7.12.0 in Kubernetes ( EKS) 1.24. After EKS upgrade to 1.25, elastic pods fail to start. The logs show below warning. Also, xpack- security was not enabled, but https…

---

## [Failed to parse mapping: Root mapping definition has unsupported parameters](https://discuss.elastic.co/t/failed-to-parse-mapping-root-mapping-definition-has-unsupported-parameters/350358)

<div class="topic-metadata">

**Author:** [@LuongQuocKhang](https://discuss.elastic.co/u/LuongQuocKhang)\
**Replies:** 0\
**Last updated:** [January 4, 2024, 6:50am UTC](https://discuss.elastic.co/t/failed-to-parse-mapping-root-mapping-definition-has-unsupported-parameters/350358 "2024-01-04T06:50:12Z")

</div>

0 I'm having an issue when create index with mapping. It returns "Failed to parse mapping: Root mapping definition has unsupported parameters" .NET Core version 8.0 Elasticsearch.Net version 6.8.11 NEST version 6.8.11 …

---

## [In elasticsearch.yml file node.attr.storage\_term parameter, what is the meaning of hot and warm?](https://discuss.elastic.co/t/in-elasticsearch-yml-file-node-attr-storage-term-parameter-what-is-the-meaning-of-hot-and-warm/351299)

<div class="topic-metadata">

**Author:** [@mpniel](https://discuss.elastic.co/u/mpniel)\
**Replies:** 1\
**Last updated:** [January 17, 2024, 6:16pm UTC](https://discuss.elastic.co/t/in-elasticsearch-yml-file-node-attr-storage-term-parameter-what-is-the-meaning-of-hot-and-warm/351299 "2024-01-17T18:16:16Z")

</div>

In elasticsearch.yml file node.attr.storage\_term parameter, what is the meaning of hot and warm?

---

## [Aggregate to collect data in array](https://discuss.elastic.co/t/aggregate-to-collect-data-in-array/351290)

<div class="topic-metadata">

**Author:** [@masoud\_darvishi](https://discuss.elastic.co/u/masoud_darvishi)\
**Replies:** 1\
**Last updated:** [January 17, 2024, 5:12pm UTC](https://discuss.elastic.co/t/aggregate-to-collect-data-in-array/351290 "2024-01-17T17:12:09Z")

</div>

hello this is my data: \[ { type: "a", // value is "a" or "b" number: 15 // number between 1 to 100 }, { type: "b", number: 56 }, { type: "a", number: 40 }, { …

---

## [maxBodyLength limit](https://discuss.elastic.co/t/maxbodylength-limit/351162)

<div class="topic-metadata">

**Author:** [@fdranger](https://discuss.elastic.co/u/fdranger)\
**Replies:** 2\
**Last updated:** [January 17, 2024, 5:03pm UTC](https://discuss.elastic.co/t/maxbodylength-limit/351162 "2024-01-17T17:03:11Z")

</div>

log: callAsCurrentUser:scroll|{"scrollId":"DXF1ZXJ5QW5kRmV0Y2gBAAAAAAA\_Q-QWOHdpMWswdlRUamlNX0hoVDBWUFowZw==","scroll":"1m","headers":{"x-kbn-domain":"\*\*\*\*\*\*","x-kbn-user":"\*\*\*\*\*\*"}};;undefined {"type":"log","@timestamp"…

---

## [Logstash agent.\* fields](https://discuss.elastic.co/t/logstash-agent-fields/351261)

<div class="topic-metadata">

**Author:** [@mwitsas](https://discuss.elastic.co/u/mwitsas)\
**Replies:** 6\
**Last updated:** [January 17, 2024, 4:35pm UTC](https://discuss.elastic.co/t/logstash-agent-fields/351261 "2024-01-17T16:35:08Z")

</div>

Is it possible to configure logstash to populate agent.\* fields in the same way beats agents do this e.g. agent.type agent.version ... Many thanks

---

## [Rest Java Api - remove\_binary option in Attachment processor](https://discuss.elastic.co/t/rest-java-api-remove-binary-option-in-attachment-processor/351287)

<div class="topic-metadata">

**Author:** [@cpeninou](https://discuss.elastic.co/u/cpeninou)\
**Replies:** 2\
**Last updated:** [January 17, 2024, 3:19pm UTC](https://discuss.elastic.co/t/rest-java-api-remove-binary-option-in-attachment-processor/351287 "2024-01-17T15:19:27Z")

</div>

Hello, Es version: 8.11.1 I'm trying to set the option remove\_binary for the Attachment processor to true since the default one is false by using the RestApi java, but this field is missing in the AttachmentProcessor.B…

---

## [Elasticsearch node won't start after updating index setting with index.mapper.dynamic](https://discuss.elastic.co/t/elasticsearch-node-wont-start-after-updating-index-setting-with-index-mapper-dynamic/351101)

<div class="topic-metadata">

**Author:** [@dslavescu](https://discuss.elastic.co/u/dslavescu)\
**Replies:** 3\
**Last updated:** [January 17, 2024, 2:53pm UTC](https://discuss.elastic.co/t/elasticsearch-node-wont-start-after-updating-index-setting-with-index-mapper-dynamic/351101 "2024-01-17T14:53:58Z")

</div>

Hello, I have an Elasticsearch cluster with version 7.17.2. I updated one of my indices with the following setting: PUT /testindex/\_settings { "index.mapper.dynamic": true } and everything was OK, my settings were u…

---

## [Unable to connect to the Kibana server Check your network connection and try again. Code 502](https://discuss.elastic.co/t/unable-to-connect-to-the-kibana-server-check-your-network-connection-and-try-again-code-502/351288)

<div class="topic-metadata">

**Author:** [@Leomar.V](https://discuss.elastic.co/u/Leomar.V)\
**Replies:** 0\
**Last updated:** [January 17, 2024, 2:52pm UTC](https://discuss.elastic.co/t/unable-to-connect-to-the-kibana-server-check-your-network-connection-and-try-again-code-502/351288 "2024-01-17T14:52:00Z")

</div>

Good morning community, how are you? I'm new to Kibana and I have a problem with code 502, but it only happens when I open a specific space and a specific report too.

---

## [Delete Indices/index/documents but 404 NotFound](https://discuss.elastic.co/t/delete-indices-index-documents-but-404-notfound/351250)

<div class="topic-metadata">

**Author:** [@martel](https://discuss.elastic.co/u/martel)\
**Replies:** 14\
**Last updated:** [January 17, 2024, 2:15pm UTC](https://discuss.elastic.co/t/delete-indices-index-documents-but-404-notfound/351250 "2024-01-17T14:15:27Z")

</div>

Hey, I want delete all indices, document, but want keep Template index. i have already try many operations see here in forum, but nothing clean my path data. A) \_settings with index.blocks.read\_only\_allow\_delete an…

---

## [Include a custom non-ECS field in alerts](https://discuss.elastic.co/t/include-a-custom-non-ecs-field-in-alerts/351280)

<div class="topic-metadata">

**Author:** [@jcruz](https://discuss.elastic.co/u/jcruz)\
**Replies:** 1\
**Last updated:** [January 17, 2024, 2:08pm UTC](https://discuss.elastic.co/t/include-a-custom-non-ecs-field-in-alerts/351280 "2024-01-17T14:08:15Z")

</div>

Hello guys! We have some indices with enriched custom fields that are not ECS compatible, as they are business related information. We would like to have those fields in the alerts generated from Detection-Rules, so we …

---

## [Linux change monitoring](https://discuss.elastic.co/t/linux-change-monitoring/351281)

<div class="topic-metadata">

**Author:** [@Kiwisaki](https://discuss.elastic.co/u/Kiwisaki)\
**Replies:** 1\
**Last updated:** [January 17, 2024, 2:04pm UTC](https://discuss.elastic.co/t/linux-change-monitoring/351281 "2024-01-17T14:04:20Z")

</div>

Hi there, what is the best way to monitor any changes made to an linux server ? I am trying to think of the most efficient way of capturing from a very broad perspective of linux changes.

---

## [Replacing a cluster node](https://discuss.elastic.co/t/replacing-a-cluster-node/351253)

<div class="topic-metadata">

**Author:** [@rihad](https://discuss.elastic.co/u/rihad)\
**Replies:** 9\
**Last updated:** [January 17, 2024, 1:44pm UTC](https://discuss.elastic.co/t/replacing-a-cluster-node/351253 "2024-01-17T13:44:50Z")

</div>

Hi, we have a 3 node cluster, with 3 ME nodes. Today I needed to replace one node with another on a new server. I simply shut down ES on the old server, and started ES on the new server. It did join the cluster according…

---

## [Unit testing responses with the new C# client?](https://discuss.elastic.co/t/unit-testing-responses-with-the-new-c-client/351279)

<div class="topic-metadata">

**Author:** [@landlord\_matt](https://discuss.elastic.co/u/landlord_matt)\
**Replies:** 0\
**Last updated:** [January 17, 2024, 1:29pm UTC](https://discuss.elastic.co/t/unit-testing-responses-with-the-new-c-client/351279 "2024-01-17T13:29:37Z")

</div>

Hi! I would like to unit test my function that parses the SearchResponse response into a MyResultRecord array. If you search for this on the internet, you get examples with the old Nest client. var searchResponseMock =…

---

## [Visualizations using the \_cat/indices API](https://discuss.elastic.co/t/visualizations-using-the-cat-indices-api/351276)

<div class="topic-metadata">

**Author:** [@jcruz](https://discuss.elastic.co/u/jcruz)\
**Replies:** 0\
**Last updated:** [January 17, 2024, 1:22pm UTC](https://discuss.elastic.co/t/visualizations-using-the-cat-indices-api/351276 "2024-01-17T13:22:20Z")

</div>

Hello guys, I would like to create some visualizations using the \_cat/indices API, so I can monitoring and understand the index usage during time. Is there any way to get the \_cat API output into some lens panels to cr…

---

## [Bug when using list with comma-number in elastic search template toJson](https://discuss.elastic.co/t/bug-when-using-list-with-comma-number-in-elastic-search-template-tojson/351274)

<div class="topic-metadata">

**Author:** [@bertie](https://discuss.elastic.co/u/bertie)\
**Replies:** 0\
**Last updated:** [January 17, 2024, 1:13pm UTC](https://discuss.elastic.co/t/bug-when-using-list-with-comma-number-in-elastic-search-template-tojson/351274 "2024-01-17T13:13:50Z")

</div>

Attempting the pass a list containing a comma-number (fx. 1.1) to the toJson functionality inbuilt in the search templates results in the following error: { "error": { "root\_cause": \[ { "type": "ille…

---

## [Profiler Auto instrumentation not working after update c# agent to version 1.25.3](https://discuss.elastic.co/t/profiler-auto-instrumentation-not-working-after-update-c-agent-to-version-1-25-3/351106)

<div class="topic-metadata">

**Author:** [@vahe](https://discuss.elastic.co/u/vahe)\
**Replies:** 8\
**Last updated:** [January 17, 2024, 1:04pm UTC](https://discuss.elastic.co/t/profiler-auto-instrumentation-not-working-after-update-c-agent-to-version-1-25-3/351106 "2024-01-17T13:04:21Z")

</div>

Hello. Please help me. Profiler Auto instrumentation stopped working after update agent to version 1.25.3. Agent version 1.22.0 working fine. Elastic version 8.11.4 Fleet 8.11.4 APM Server 8.11.4 Linux CentOS Linux…

---

## [How can i connect my data nodes to another cluster (need to change cluster uuid)](https://discuss.elastic.co/t/how-can-i-connect-my-data-nodes-to-another-cluster-need-to-change-cluster-uuid/351270)

<div class="topic-metadata">

**Author:** [@donggyu04](https://discuss.elastic.co/u/donggyu04)\
**Replies:** 1\
**Last updated:** [January 17, 2024, 12:49pm UTC](https://discuss.elastic.co/t/how-can-i-connect-my-data-nodes-to-another-cluster-need-to-change-cluster-uuid/351270 "2024-01-17T12:49:17Z")

</div>

same issue with Data node’s cluster uuid diffrent from master node's cluster uuid but I want to connect my data nodes to new cluster without deleting their data directory. is there any way to this? I must delete data d…

---

## [How to parse date field into @timestamp](https://discuss.elastic.co/t/how-to-parse-date-field-into-timestamp/351058)

<div class="topic-metadata">

**Author:** [@emoxam](https://discuss.elastic.co/u/emoxam)\
**Replies:** 9\
**Last updated:** [January 17, 2024, 12:10pm UTC](https://discuss.elastic.co/t/how-to-parse-date-field-into-timestamp/351058 "2024-01-17T12:10:13Z")

</div>

i receive the spring app logs and i want to parse time from logs to @timestamp that's what i got but timestamp is not the same. input { tcp { port =\> 5000 codec =\>plain } } filter { if \[message\] =~ /actions/ { …

---

## [Configure Elasticsearch with script](https://discuss.elastic.co/t/configure-elasticsearch-with-script/351264)

<div class="topic-metadata">

**Author:** [@cv123](https://discuss.elastic.co/u/cv123)\
**Replies:** 0\
**Last updated:** [January 17, 2024, 11:37am UTC](https://discuss.elastic.co/t/configure-elasticsearch-with-script/351264 "2024-01-17T11:37:23Z")

</div>

Hi everyone, i tried to deploy and configure an Elastic instance via script (first test with powershell) For that i wrote a terraform script to create 2 docker container (elasticsearch and kibana), create the enrollmen…

---

## [Filebeat Components ignores logging level](https://discuss.elastic.co/t/filebeat-components-ignores-logging-level/351260)

<div class="topic-metadata">

**Author:** [@Marc\_Wolff](https://discuss.elastic.co/u/Marc_Wolff)\
**Replies:** 0\
**Last updated:** [January 17, 2024, 11:18am UTC](https://discuss.elastic.co/t/filebeat-components-ignores-logging-level/351260 "2024-01-17T11:18:35Z")

</div>

Hi all, We have an eck environment in a onprem k8s cluster with elasticsearch, kibana, logstash (http input) and elastic-agent as a standalone for the container logs. Version for all is 8.11.4 This is fine so far. Our…

---

## [SSO error failed to establish trust with server at \[login.microsoftonline.com\]](https://discuss.elastic.co/t/sso-error-failed-to-establish-trust-with-server-at-login-microsoftonline-com/350858)

<div class="topic-metadata">

**Author:** [@krzychohoho](https://discuss.elastic.co/u/krzychohoho)\
**Replies:** 2\
**Last updated:** [January 17, 2024, 11:09am UTC](https://discuss.elastic.co/t/sso-error-failed-to-establish-trust-with-server-at-login-microsoftonline-com/350858 "2024-01-17T11:09:30Z")

</div>

Hi, I came across a problem recently and I need urgent help. The machine that was running Elasticsearch was restarted and now the service will not run. The error is: sun.security.validator.ValidatorException: PKIX path …

---

## [Shards failed The data might be incomplete or wrong](https://discuss.elastic.co/t/shards-failed-the-data-might-be-incomplete-or-wrong/351244)

<div class="topic-metadata">

**Author:** [@Bhavani90](https://discuss.elastic.co/u/Bhavani90)\
**Replies:** 1\
**Last updated:** [January 17, 2024, 11:01am UTC](https://discuss.elastic.co/t/shards-failed-the-data-might-be-incomplete-or-wrong/351244 "2024-01-17T11:01:57Z")

</div>

Hi I'm Bhavani. When I try to search for data within a message using quotation marks, I encounter an error like ( No results found 1 of 2868 shards failed The data might be incomplete or wrong.). How can I resolve …

[Previous page](https://discuss.elastic.co/latest.md?page=427)

[Next page](https://discuss.elastic.co/latest.md?page=429)
