# Latest

**URL:** https://discuss.elastic.co/latest.md?page=433

[Latest](https://discuss.elastic.co/latest.md) · [Categories](https://discuss.elastic.co/categories.md) · [Tags](https://discuss.elastic.co/tags.md)

**Page:** 434

---

## [Very slow queries always take 1s](https://discuss.elastic.co/t/very-slow-queries-always-take-1s/350933)

<div class="topic-metadata">

**Author:** [@matthijs1](https://discuss.elastic.co/u/matthijs1)\
**Replies:** 0\
**Last updated:** [January 12, 2024, 11:02am UTC](https://discuss.elastic.co/t/very-slow-queries-always-take-1s/350933 "2024-01-12T11:02:06Z")

</div>

Hi All, I'm not that experienced in Elastic Search, but I have a problem and I'm out of ideas to try. In a test setup, I have a 3-node cluster running ES6.8.22 on windows. Until a windows reboot (for updates) 2 days a…

---

## [\[Filebeat\] Bug with aws-cloudwatch logs using log\_group\_arn](https://discuss.elastic.co/t/filebeat-bug-with-aws-cloudwatch-logs-using-log-group-arn/350930)

<div class="topic-metadata">

**Author:** [@Blaj\_Dragos](https://discuss.elastic.co/u/Blaj_Dragos)\
**Replies:** 0\
**Last updated:** [January 12, 2024, 10:35am UTC](https://discuss.elastic.co/t/filebeat-bug-with-aws-cloudwatch-logs-using-log-group-arn/350930 "2024-01-12T10:35:48Z")

</div>

Hi! I have a filebeat system with the following configuration as an input: filebeat.inputs: - type: aws-cloudwatch log\_group\_arn: arn:aws:logs:eu-west-1:\*:log-group:/ecs/log:\* scan\_frequency: 30s s…

---

## [Configuration fortigate with filebeat](https://discuss.elastic.co/t/configuration-fortigate-with-filebeat/350421)

<div class="topic-metadata">

**Author:** [@Dy\_Vanrith](https://discuss.elastic.co/u/Dy_Vanrith)\
**Replies:** 5\
**Last updated:** [January 12, 2024, 10:11am UTC](https://discuss.elastic.co/t/configuration-fortigate-with-filebeat/350421 "2024-01-12T10:11:51Z")

</div>

Hello i have project that work with fortigate and filebeat i want to collect sys\_log from fortigate into filebeat my configuration fortigate config log syslogd setting set status enable set server filebeat\_server s…

---

## [Watcher to index all data from /cat/indices/\*,-.\* each indexname should be inserted as one doc](https://discuss.elastic.co/t/watcher-to-index-all-data-from-cat-indices-each-indexname-should-be-inserted-as-one-doc/350672)

<div class="topic-metadata">

**Author:** [@mangeshmj1992](https://discuss.elastic.co/u/mangeshmj1992)\
**Replies:** 5\
**Last updated:** [January 12, 2024, 9:38am UTC](https://discuss.elastic.co/t/watcher-to-index-all-data-from-cat-indices-each-indexname-should-be-inserted-as-one-doc/350672 "2024-01-12T09:38:38Z")

</div>

Hi team, Can you please help me on below requirement: Get index name and size (in bytes) from GET /cat/indices/,-. Insert this data into new index IDs should be elastic generated. Add timestamp field in every doc Pro…

---

## [Silent failures with delete-by-query](https://discuss.elastic.co/t/silent-failures-with-delete-by-query/350925)

<div class="topic-metadata">

**Author:** [@mrodent](https://discuss.elastic.co/u/mrodent)\
**Replies:** 0\
**Last updated:** [January 12, 2024, 9:38am UTC](https://discuss.elastic.co/t/silent-failures-with-delete-by-query/350925 "2024-01-12T09:38:27Z")

</div>

I've examined all the questions on this subject. None seems to address the problem I'm having. I need to loop through doing multiple delete\_by\_queries. As I've set things up for experimenting, just a handful. The proble…

---

## [Transform destination index rollover](https://discuss.elastic.co/t/transform-destination-index-rollover/350578)

<div class="topic-metadata">

**Author:** [@veryelastic](https://discuss.elastic.co/u/veryelastic)\
**Replies:** 2\
**Last updated:** [January 12, 2024, 9:25am UTC](https://discuss.elastic.co/t/transform-destination-index-rollover/350578 "2024-01-12T09:25:38Z")

</div>

Hello, It has been a while (I think) since this question came up on here, so I thought I'd check whether the answer had changed or not. I have a transform which produces consolidated data with a time-series element to …

---

## [Visualization (pie) of index with all fields included](https://discuss.elastic.co/t/visualization-pie-of-index-with-all-fields-included/350845)

<div class="topic-metadata">

**Author:** [@Anomalous\_User](https://discuss.elastic.co/u/Anomalous_User)\
**Replies:** 3\
**Last updated:** [January 12, 2024, 9:14am UTC](https://discuss.elastic.co/t/visualization-pie-of-index-with-all-fields-included/350845 "2024-01-12T09:14:07Z")

</div>

Hi, I'm using 7.17 (we're upgrading soon). At the moment I have lens/graph/visualize library all open searching for a way to include all fields (many) from an index and display them in a pie chart. I can see how to do th…

---

## [Curl XPOST not working after upgrading from Elastic v7 to Elastic v8](https://discuss.elastic.co/t/curl-xpost-not-working-after-upgrading-from-elastic-v7-to-elastic-v8/350706)

<div class="topic-metadata">

**Author:** [@zeninuxx](https://discuss.elastic.co/u/zeninuxx)\
**Replies:** 3\
**Last updated:** [January 12, 2024, 8:51am UTC](https://discuss.elastic.co/t/curl-xpost-not-working-after-upgrading-from-elastic-v7-to-elastic-v8/350706 "2024-01-12T08:51:00Z")

</div>

This is an example of a json file I am trying to POST into elasticsearch: {"index": {}} {"topic": "example1", "size": 2192, "timestamp": "2024-01-10"} {"index": {}} {"topic": "example2", "size": 2052, "timestamp": "2024…

---

## [BigQuery to ElasticSearch using DataFlow template, Not working](https://discuss.elastic.co/t/bigquery-to-elasticsearch-using-dataflow-template-not-working/350759)

<div class="topic-metadata">

**Author:** [@aji.shinde7](https://discuss.elastic.co/u/aji.shinde7)\
**Replies:** 1\
**Last updated:** [January 12, 2024, 8:19am UTC](https://discuss.elastic.co/t/bigquery-to-elasticsearch-using-dataflow-template-not-working/350759 "2024-01-12T08:19:26Z")

</div>

Hello Experts, Please Help, I followed this article to pull data from Google BigQuery into Elastic using Google DataFlow : Ingest data directly from Google BigQuery into Elastic using Google Dataflow | Elastic Blog I …

---

## [Logstash input with beats function is not work good by OCP platform in ingress](https://discuss.elastic.co/t/logstash-input-with-beats-function-is-not-work-good-by-ocp-platform-in-ingress/350915)

<div class="topic-metadata">

**Author:** [@bigwind123](https://discuss.elastic.co/u/bigwind123)\
**Replies:** 0\
**Last updated:** [January 12, 2024, 7:47am UTC](https://discuss.elastic.co/t/logstash-input-with-beats-function-is-not-work-good-by-ocp-platform-in-ingress/350915 "2024-01-12T07:47:36Z")

</div>

I am currently facing a problem. I'm planning to set up an ELK service on a redhat ocp platform and install metricbeat on the VM to send the data to a logstash pod in ocp, I'm currently doing the following. a pod -\> e…

---

## [Unable to connect filbeat to logstash](https://discuss.elastic.co/t/unable-to-connect-filbeat-to-logstash/350912)

<div class="topic-metadata">

**Author:** [@dark\_header](https://discuss.elastic.co/u/dark_header)\
**Replies:** 0\
**Last updated:** [January 12, 2024, 7:32am UTC](https://discuss.elastic.co/t/unable-to-connect-filbeat-to-logstash/350912 "2024-01-12T07:32:56Z")

</div>

hi team , installed in ELK ( Elasticsearch , logstash , kibana and filebeat ) in same server unable to connect from filebeat to logstash , getting error below {"log.level":"error","timestamp":"2024-01-11T17:49:55.606+0…

---

## [How to pause the logstash output temporarily](https://discuss.elastic.co/t/how-to-pause-the-logstash-output-temporarily/350841)

<div class="topic-metadata">

**Author:** [@jevonsnotes](https://discuss.elastic.co/u/jevonsnotes)\
**Replies:** 3\
**Last updated:** [January 12, 2024, 5:36am UTC](https://discuss.elastic.co/t/how-to-pause-the-logstash-output-temporarily/350841 "2024-01-12T05:36:49Z")

</div>

how to keep the logstash accept the input data but pause the output temporarily?

---

## [●\[TLS\] Question: Secure communication between Winlogbeat/ElasticSearch causes an error](https://discuss.elastic.co/t/tls-question-secure-communication-between-winlogbeat-elasticsearch-causes-an-error/350898)

<div class="topic-metadata">

**Author:** [@YUUTA.INOUE-JPN](https://discuss.elastic.co/u/YUUTA.INOUE-JPN)\
**Replies:** 2\
**Last updated:** [January 12, 2024, 3:33am UTC](https://discuss.elastic.co/t/tls-question-secure-communication-between-winlogbeat-elasticsearch-causes-an-error/350898 "2024-01-12T03:33:52Z")

</div>

I am configuring "Elastic Stack" using a self-signed certificate. Secure communication between Elasticsearch worked fine, but Secure communication between Winlogbeat/Elasticsearch will result in an error. Please teach…

---

## [Elastic Agent failing to parse valid condition functions](https://discuss.elastic.co/t/elastic-agent-failing-to-parse-valid-condition-functions/349579)

<div class="topic-metadata">

**Author:** [@BenB196](https://discuss.elastic.co/u/BenB196)\
**Replies:** 8\
**Last updated:** [January 12, 2024, 1:34am UTC](https://discuss.elastic.co/t/elastic-agent-failing-to-parse-valid-condition-functions/349579 "2024-01-12T01:34:46Z")

</div>

Hi, I'm having an issue where if I try to run elastic-agent inspect with a policy that defines a condition with a function, I get an error, even if the function is valid. Elastic Agent 8.11.3 Example: Use the Kuberne…

---

## [About the special handling of Java 17 inside the \`ModuleOpenerImpl\` class](https://discuss.elastic.co/t/about-the-special-handling-of-java-17-inside-the-moduleopenerimpl-class/350739)

<div class="topic-metadata">

**Author:** [@dogourd](https://discuss.elastic.co/u/dogourd)\
**Replies:** 4\
**Last updated:** [January 12, 2024, 1:27am UTC](https://discuss.elastic.co/t/about-the-special-handling-of-java-17-inside-the-moduleopenerimpl-class/350739 "2024-01-12T01:27:10Z")

</div>

In the Javaagent public boolean openModuleTo(Instrumentation instrumentation, Class\<?\> classFromTargetModule, ClassLoader openTo, Collection\<String\> packagesToOpen) { Module targetModule = classFromTargetModule.…

---

## [Logstash TCP Input Codecs](https://discuss.elastic.co/t/logstash-tcp-input-codecs/350517)

<div class="topic-metadata">

**Author:** [@mgotechlock](https://discuss.elastic.co/u/mgotechlock)\
**Replies:** 10\
**Last updated:** [January 11, 2024, 11:09pm UTC](https://discuss.elastic.co/t/logstash-tcp-input-codecs/350517 "2024-01-11T23:09:15Z")

</div>

Is there a place to undestand exactly what format each of the TCP input codecs are meant to cover? (line vs json vs plain vs cef). I have a situation of a new log source (Sophos firewall). Must use TLS so syslog input i…

---

## [How to parse json from message field](https://discuss.elastic.co/t/how-to-parse-json-from-message-field/350769)

<div class="topic-metadata">

**Author:** [@wrender1](https://discuss.elastic.co/u/wrender1)\
**Replies:** 3\
**Last updated:** [January 11, 2024, 9:59pm UTC](https://discuss.elastic.co/t/how-to-parse-json-from-message-field/350769 "2024-01-11T21:59:07Z")

</div>

Hello, I'm looking for help with parsing json data out of a log field. I'm using the elastic agent standalone in Kubernetes and not sure how to configure it for this. I believe the filebeat portion of the elastic agent …

---

## [Observability/apm-lambda-extension docker image causing vulnerabilities](https://discuss.elastic.co/t/observability-apm-lambda-extension-docker-image-causing-vulnerabilities/350685)

<div class="topic-metadata">

**Author:** [@SELENAAA](https://discuss.elastic.co/u/SELENAAA)\
**Replies:** 8\
**Last updated:** [January 11, 2024, 9:31pm UTC](https://discuss.elastic.co/t/observability-apm-lambda-extension-docker-image-causing-vulnerabilities/350685 "2024-01-11T21:31:34Z")

</div>

I'm following this guide to add a nodejs apm agent to my container image based function; however, the observability/apm-lambda-extension is causing some scan image vulnerabilities with the package go. I'm searching for t…

---

## [Collect values from elasticsearch/kibana](https://discuss.elastic.co/t/collect-values-from-elasticsearch-kibana/350886)

<div class="topic-metadata">

**Author:** [@cyberphantom](https://discuss.elastic.co/u/cyberphantom)\
**Replies:** 1\
**Last updated:** [January 11, 2024, 8:54pm UTC](https://discuss.elastic.co/t/collect-values-from-elasticsearch-kibana/350886 "2024-01-11T20:54:08Z")

</div>

Hello! I'm trying to retrieve specific values from my Elasticsearch/Kibana graphs to manipulate them in another environment. Initially, I thought I could achieve this using the Elasticsearch API, but being relatively ne…

---

## [How can I estimate MbB/s for an API endpoit based on APM logs?](https://discuss.elastic.co/t/how-can-i-estimate-mbb-s-for-an-api-endpoit-based-on-apm-logs/350801)

<div class="topic-metadata">

**Author:** [@rturk](https://discuss.elastic.co/u/rturk)\
**Replies:** 1\
**Last updated:** [January 11, 2024, 8:41pm UTC](https://discuss.elastic.co/t/how-can-i-estimate-mbb-s-for-an-api-endpoit-based-on-apm-logs/350801 "2024-01-11T20:41:45Z")

</div>

Hi everyone, I'm working with Elasticsearch APM monitoring performance of our services, and I'm interested in estimating the network traffic (in MB/s) generated by the requests and responses logged by APM for APIs, or P…

---

## [Elastic APM Javagent + Elastic search](https://discuss.elastic.co/t/elastic-apm-javagent-elastic-search/350805)

<div class="topic-metadata">

**Author:** [@RavaliJ](https://discuss.elastic.co/u/RavaliJ)\
**Replies:** 8\
**Last updated:** [January 11, 2024, 8:25pm UTC](https://discuss.elastic.co/t/elastic-apm-javagent-elastic-search/350805 "2024-01-11T20:25:44Z")

</div>

Hi, I am using elastic-apm-agent-1.45.0.jar to instrument a java spring boot application. I have installed Elasticsearch - 8.8.0 and apm-server-8.8.0 on my local windows machine. Made necessary basic config changes to t…

---

## [Elastic Canvas: Discrepancy on data using ES SQL](https://discuss.elastic.co/t/elastic-canvas-discrepancy-on-data-using-es-sql/350882)

<div class="topic-metadata">

**Author:** [@pikaia](https://discuss.elastic.co/u/pikaia)\
**Replies:** 0\
**Last updated:** [January 11, 2024, 6:35pm UTC](https://discuss.elastic.co/t/elastic-canvas-discrepancy-on-data-using-es-sql/350882 "2024-01-11T18:35:24Z")

</div>

Hi, I've been uploading vulnerabilities to Elastic where the fields are already mapped to ECS, and so far, everything has been working fine. Now, I have the need to generate a report at the beginning of each month to pr…

---

## [Normalization or denormalization structure(Notification to multiple recipients - business logic)](https://discuss.elastic.co/t/normalization-or-denormalization-structure-notification-to-multiple-recipients-business-logic/350877)

<div class="topic-metadata">

**Author:** [@Behemo1h](https://discuss.elastic.co/u/Behemo1h)\
**Replies:** 0\
**Last updated:** [January 11, 2024, 6:09pm UTC](https://discuss.elastic.co/t/normalization-or-denormalization-structure-notification-to-multiple-recipients-business-logic/350877 "2024-01-11T18:09:27Z")

</div>

Hello all. I can't decide whether to "normalize" the data or not. I have notification datas in my app. When notification can be triggered for whole complay, user, or user in company. My current data looks like: Its o…

---

## [Index\_not\_found\_exception](https://discuss.elastic.co/t/index-not-found-exception/350736)

<div class="topic-metadata">

**Author:** [@e-ferrari](https://discuss.elastic.co/u/e-ferrari)\
**Replies:** 2\
**Last updated:** [January 11, 2024, 4:57pm UTC](https://discuss.elastic.co/t/index-not-found-exception/350736 "2024-01-11T16:57:55Z")

</div>

Hi, i'm following Parsing Logs with Logstash | Logstash Reference \[8.11\] | Elastic. When i try, as mentioned in the text curl -k -u elastic:xxxxxxxxxxxxxxxxxxxxx -XGET 'https://localhost:9200/2024.01.10/\_search?pretty&q…

---

## [Getting crazy with nnotes.dll](https://discuss.elastic.co/t/getting-crazy-with-nnotes-dll/349544)

<div class="topic-metadata">

**Author:** [@GKre](https://discuss.elastic.co/u/GKre)\
**Replies:** 8\
**Last updated:** [January 11, 2024, 3:41pm UTC](https://discuss.elastic.co/t/getting-crazy-with-nnotes-dll/349544 "2024-01-11T15:41:53Z")

</div>

Yes - i am using HCL Notes / Domino in release 12 and 14 (the newest one). Elastic Endpoint Security is driving me crazy as it is putting the file "nnotes.dll" into quartantain. I tested rule exception and endpoint exc…

---

## [Error: can not write type \[class java.time.LocalDate\] - Elasticsearch v8.10](https://discuss.elastic.co/t/error-can-not-write-type-class-java-time-localdate-elasticsearch-v8-10/350868)

<div class="topic-metadata">

**Author:** [@Abhishek](https://discuss.elastic.co/u/Abhishek)\
**Replies:** 0\
**Last updated:** [January 11, 2024, 2:39pm UTC](https://discuss.elastic.co/t/error-can-not-write-type-class-java-time-localdate-elasticsearch-v8-10/350868 "2024-01-11T14:39:34Z")

</div>

Hi Everyone, I have recently upgraded from es 5.6 to es 8.10. Following script field is working fine in es5.6 "script\_fields": { "customDate": { "script": { "inline": "def i ; if(params.\_source.cu…

---

## [Think Like a Relevance Engineer for Elasticsearch with on-demand self-led training](https://discuss.elastic.co/t/think-like-a-relevance-engineer-for-elasticsearch-with-on-demand-self-led-training/350866)

<div class="topic-metadata">

**Author:** [@flaxsearch](https://discuss.elastic.co/u/flaxsearch)\
**Replies:** 0\
**Last updated:** [January 11, 2024, 2:09pm UTC](https://discuss.elastic.co/t/think-like-a-relevance-engineer-for-elasticsearch-with-on-demand-self-led-training/350866 "2024-01-11T14:09:54Z")

</div>

I'm very pleased to announce that OSC's flagship trainings, inspired by the book Relevant Search and which have been taken by hundreds of relevance engineers worldwide, are now available on demand as self-led courses. If…

---

## [What is the recommended memory:data ratio for a cold zone?](https://discuss.elastic.co/t/what-is-the-recommended-memory-data-ratio-for-a-cold-zone/349755)

<div class="topic-metadata">

**Author:** [@calin](https://discuss.elastic.co/u/calin)\
**Replies:** 8\
**Last updated:** [January 11, 2024, 1:31pm UTC](https://discuss.elastic.co/t/what-is-the-recommended-memory-data-ratio-for-a-cold-zone/349755 "2024-01-11T13:31:48Z")

</div>

I see for the hot zone it's 30. For a warm zone it's 160. I haven't seen a value for cold zone. And how exactly is that calculated ? Thank you.

---

## [Windows two Node Cluster stuck on tring to determine master](https://discuss.elastic.co/t/windows-two-node-cluster-stuck-on-tring-to-determine-master/350691)

<div class="topic-metadata">

**Author:** [@bytelink](https://discuss.elastic.co/u/bytelink)\
**Replies:** 11\
**Last updated:** [January 11, 2024, 1:28pm UTC](https://discuss.elastic.co/t/windows-two-node-cluster-stuck-on-tring-to-determine-master/350691 "2024-01-11T13:28:07Z")

</div>

I have been trying to install a new two node cluster on two windows servers and no matter what I have tried I get a situation where the two nodes do not seem to be able to determine which should be the master. I have tr…

---

## [TLS/SSL Certification](https://discuss.elastic.co/t/tls-ssl-certification/350859)

<div class="topic-metadata">

**Author:** [@jhanani](https://discuss.elastic.co/u/jhanani)\
**Replies:** 0\
**Last updated:** [January 11, 2024, 12:58pm UTC](https://discuss.elastic.co/t/tls-ssl-certification/350859 "2024-01-11T12:58:00Z")

</div>

I am running Elasticsearch and Kibana 8.11.3 version on ubuntu VM using docker. If I try to connect the Elasticsearch with PowerBI through API key. It is showing the below error. Error Message: -"The underlying connect…

[Previous page](https://discuss.elastic.co/latest.md?page=432)

[Next page](https://discuss.elastic.co/latest.md?page=434)
