# Latest

**URL:** https://discuss.elastic.co/latest.md?page=440

[Latest](https://discuss.elastic.co/latest.md) · [Categories](https://discuss.elastic.co/categories.md) · [Tags](https://discuss.elastic.co/tags.md)

**Page:** 441

---

## [Embedding kibana using iframe](https://discuss.elastic.co/t/embedding-kibana-using-iframe/350042)

<div class="topic-metadata">

**Author:** [@Atul87](https://discuss.elastic.co/u/Atul87)\
**Replies:** 3\
**Last updated:** [January 4, 2024, 8:28am UTC](https://discuss.elastic.co/t/embedding-kibana-using-iframe/350042 "2024-01-04T08:28:10Z")

</div>

Hi team, I am trying to embed kibana url using iframe, but its not working for me. I am using kibana version 7.17.13, I want to embed overall kibana, with all its functionality not just any one dashbord of it. Authenti…

---

## [APM Server transport error: intake response timeout: APM server did not respond within 10s of gzip stream finish](https://discuss.elastic.co/t/apm-server-transport-error-intake-response-timeout-apm-server-did-not-respond-within-10s-of-gzip-stream-finish/349422)

<div class="topic-metadata">

**Author:** [@khteh](https://discuss.elastic.co/u/khteh)\
**Replies:** 4\
**Last updated:** [January 4, 2024, 8:24am UTC](https://discuss.elastic.co/t/apm-server-transport-error-intake-response-timeout-apm-server-did-not-respond-within-10s-of-gzip-stream-finish/349422 "2024-01-04T08:24:10Z")

</div>

If you are asking about a problem you are experiencing, please use the following template, as it will help us help you. If you have a different problem, please delete all of this text :slight\_smile: TIP 1: select at lea…

---

## [Backup large indexes to other locations on a time-by-time basis and clean up the index](https://discuss.elastic.co/t/backup-large-indexes-to-other-locations-on-a-time-by-time-basis-and-clean-up-the-index/350191)

<div class="topic-metadata">

**Author:** [@sqq](https://discuss.elastic.co/u/sqq)\
**Replies:** 12\
**Last updated:** [January 4, 2024, 7:42am UTC](https://discuss.elastic.co/t/backup-large-indexes-to-other-locations-on-a-time-by-time-basis-and-clean-up-the-index/350191 "2024-01-04T07:42:25Z")

</div>

Backup large indexes to other locations on a time-by-time basis and clean up the index

---

## [Logstash metrics using modules in Metricbeat](https://discuss.elastic.co/t/logstash-metrics-using-modules-in-metricbeat/350279)

<div class="topic-metadata">

**Author:** [@maadhav](https://discuss.elastic.co/u/maadhav)\
**Replies:** 4\
**Last updated:** [January 4, 2024, 5:41am UTC](https://discuss.elastic.co/t/logstash-metrics-using-modules-in-metricbeat/350279 "2024-01-04T05:41:29Z")

</div>

Hi Team There are 2 modules in Metricbeat to collect Logstash metrics logstash logstash-xpack Which module should be used ? Regards

---

## [Is dfs\_query\_then\_fetch automatically disabled on single shard?](https://discuss.elastic.co/t/is-dfs-query-then-fetch-automatically-disabled-on-single-shard/350351)

<div class="topic-metadata">

**Author:** [@Yukha\_Dharmeswara](https://discuss.elastic.co/u/Yukha_Dharmeswara)\
**Replies:** 0\
**Last updated:** [January 4, 2024, 5:17am UTC](https://discuss.elastic.co/t/is-dfs-query-then-fetch-automatically-disabled-on-single-shard/350351 "2024-01-04T05:17:34Z")

</div>

When we specify search\_type=dfs\_query\_then\_fetch in querystring, does Elasticsearch automatically disable dfs\_query\_then\_fetch when there's only 1 shard in single node mode? Or do i have to use query\_then\_fetch to trigge…

---

## [Configure ingest pipeline to add both GeoLite2-City AND GeoLite2-ASN fields](https://discuss.elastic.co/t/configure-ingest-pipeline-to-add-both-geolite2-city-and-geolite2-asn-fields/350339)

<div class="topic-metadata">

**Author:** [@jbrowe](https://discuss.elastic.co/u/jbrowe)\
**Replies:** 1\
**Last updated:** [January 4, 2024, 12:00am UTC](https://discuss.elastic.co/t/configure-ingest-pipeline-to-add-both-geolite2-city-and-geolite2-asn-fields/350339 "2024-01-04T00:00:58Z")

</div>

I have and event stream that contains IP addresses. I wish to add meta-data from the GeoLite2 Max Mind databases. I can successfully add the city data. I can also successfully add the ASN data. Somehow, I cannot add both…

---

## [Rollup or downsampling](https://discuss.elastic.co/t/rollup-or-downsampling/350342)

<div class="topic-metadata">

**Author:** [@EdRayQO](https://discuss.elastic.co/u/EdRayQO)\
**Replies:** 0\
**Last updated:** [January 3, 2024, 11:17pm UTC](https://discuss.elastic.co/t/rollup-or-downsampling/350342 "2024-01-03T23:17:07Z")

</div>

I'm trying to compress log data I have in a monitoring cluster and that is configured to be erased after 7 days, and I'm not sure which path should I follow between rollup jobs and down sampling in order to compress that…

---

## [Stack Monitoring Access Denied](https://discuss.elastic.co/t/stack-monitoring-access-denied/350313)

<div class="topic-metadata">

**Author:** [@sourcreamnormanbates](https://discuss.elastic.co/u/sourcreamnormanbates)\
**Replies:** 3\
**Last updated:** [January 3, 2024, 9:32pm UTC](https://discuss.elastic.co/t/stack-monitoring-access-denied/350313 "2024-01-03T21:32:48Z")

</div>

When I try to view Stack Monitoring, I receive an error message. I get the same message with the default elastic admin user as well as my provisioned unique admin user account I use. I only have one cluster, so I'm not…

---

## [Error log curl: (52) Empty reply from server in v8.11.3](https://discuss.elastic.co/t/error-log-curl-52-empty-reply-from-server-in-v8-11-3/350338)

<div class="topic-metadata">

**Author:** [@ACodingfreak](https://discuss.elastic.co/u/ACodingfreak)\
**Replies:** 2\
**Last updated:** [January 3, 2024, 8:18pm UTC](https://discuss.elastic.co/t/error-log-curl-52-empty-reply-from-server-in-v8-11-3/350338 "2024-01-03T20:18:34Z")

</div>

Hi All, I am new to ELK and started using the same via docker compose. I have used the standard docker-compose.yaml file which is available in below link. As shown in below logs all containers are up and running $ …

---

## [Share a dashboard in read-only mode](https://discuss.elastic.co/t/share-a-dashboard-in-read-only-mode/350326)

<div class="topic-metadata">

**Author:** [@gnatola](https://discuss.elastic.co/u/gnatola)\
**Replies:** 3\
**Last updated:** [January 3, 2024, 7:58pm UTC](https://discuss.elastic.co/t/share-a-dashboard-in-read-only-mode/350326 "2024-01-03T19:58:40Z")

</div>

Hello, using Kibana 8.11. Created a dashboard that I would like to share in read-only mode. I would like to be the only person who can edit the dashboard. What is the best way to accomplish this? Thanks.

---

## [ES SQL custom mappings](https://discuss.elastic.co/t/es-sql-custom-mappings/349980)

<div class="topic-metadata">

**Author:** [@ES\_SQL\_HELP](https://discuss.elastic.co/u/ES_SQL_HELP)\
**Replies:** 6\
**Last updated:** [January 3, 2024, 5:08pm UTC](https://discuss.elastic.co/t/es-sql-custom-mappings/349980 "2024-01-03T17:08:54Z")

</div>

Hello, I'm wondering if it's possible to use ES SQL on custom field mappings for types e.g. long, integer, doubles.

---

## [Audit logging in Elastic Cloud](https://discuss.elastic.co/t/audit-logging-in-elastic-cloud/348688)

<div class="topic-metadata">

**Author:** [@lreger](https://discuss.elastic.co/u/lreger)\
**Replies:** 2\
**Last updated:** [January 3, 2024, 5:08pm UTC](https://discuss.elastic.co/t/audit-logging-in-elastic-cloud/348688 "2024-01-03T17:08:34Z")

</div>

I have two questions I was hoping someone could answer. Question 1: I am using an elastic cloud deployment running ES 7.17.5. I know how to enable audit logging and ship those logs to my monitoring deployment. I noticed…

---

## [How to read GZIP and encoding with UTF-8 logs from kafka topic through logstash pipeline](https://discuss.elastic.co/t/how-to-read-gzip-and-encoding-with-utf-8-logs-from-kafka-topic-through-logstash-pipeline/349775)

<div class="topic-metadata">

**Author:** [@upreddy](https://discuss.elastic.co/u/upreddy)\
**Replies:** 5\
**Last updated:** [January 3, 2024, 4:53pm UTC](https://discuss.elastic.co/t/how-to-read-gzip-and-encoding-with-utf-8-logs-from-kafka-topic-through-logstash-pipeline/349775 "2024-01-03T16:53:39Z")

</div>

Hi All, Application team doing "GZIP and encoding with UTF-8" and sending their logs to kafka topics. Now i want to read those logs through logstash pipeline. Could you please guide me on this? Thanks

---

## [Error running Elastic Maps behind proxy](https://discuss.elastic.co/t/error-running-elastic-maps-behind-proxy/350082)

<div class="topic-metadata">

**Author:** [@m.hanna](https://discuss.elastic.co/u/m.hanna)\
**Replies:** 7\
**Last updated:** [January 3, 2024, 4:52pm UTC](https://discuss.elastic.co/t/error-running-elastic-maps-behind-proxy/350082 "2024-01-03T16:52:38Z")

</div>

I am trying to run an EMS server on a disconnected network behind an Nginx reverse-proxy in a docker swarm. I am able to start EMS up and it looks to connect to elasticsearch without the basePath setting. As soon as I a…

---

## [Inconsistencies between platforms](https://discuss.elastic.co/t/inconsistencies-between-platforms/350261)

<div class="topic-metadata">

**Author:** [@nml1988](https://discuss.elastic.co/u/nml1988)\
**Replies:** 11\
**Last updated:** [January 3, 2024, 3:35pm UTC](https://discuss.elastic.co/t/inconsistencies-between-platforms/350261 "2024-01-03T15:35:06Z")

</div>

Hello! I need help with a problem I'm having between 2 versions of ELK. These versions correspond to two different platforms that consume data from the same source. The first image corresponds to an ELK stack 7.9, where…

---

## [How to use Filters, Facets and Group By feature in .NET client?](https://discuss.elastic.co/t/how-to-use-filters-facets-and-group-by-feature-in-net-client/350322)

<div class="topic-metadata">

**Author:** [@RamuAnnamalai](https://discuss.elastic.co/u/RamuAnnamalai)\
**Replies:** 0\
**Last updated:** [January 3, 2024, 3:21pm UTC](https://discuss.elastic.co/t/how-to-use-filters-facets-and-group-by-feature-in-net-client/350322 "2024-01-03T15:21:48Z")

</div>

I have integrated Elastic Search feature in .NET 6.0 API framework. I need to know how to use filters, facets & group by features in REST API .NET Client? Do you have any documentation for this? Thanks, Ramu

---

## [Delete by query conflict](https://discuss.elastic.co/t/delete-by-query-conflict/350320)

<div class="topic-metadata">

**Author:** [@Hariharan](https://discuss.elastic.co/u/Hariharan)\
**Replies:** 0\
**Last updated:** [January 3, 2024, 3:06pm UTC](https://discuss.elastic.co/t/delete-by-query-conflict/350320 "2024-01-03T15:06:35Z")

</div>

Hey folks, I have a quick question on how to handle a particular scenario I'm running into. So we have a sync between a person's calendar events and Elasticsearch to index the events from Calendar and build some sort of…

---

## [Connectors Relationship with Db](https://discuss.elastic.co/t/connectors-relationship-with-db/349611)

<div class="topic-metadata">

**Author:** [@aisyaharifin](https://discuss.elastic.co/u/aisyaharifin)\
**Replies:** 1\
**Last updated:** [January 3, 2024, 2:23pm UTC](https://discuss.elastic.co/t/connectors-relationship-with-db/349611 "2024-01-03T14:23:21Z")

</div>

Hello Elastic, I want to ask, I have issue where I've been configuring Connectors in Production environment which specifically Microsoft SQL connectors to pull the data into Elasticsearch Indices and it seems like it co…

---

## [Elastic Security Rule Keyword issue](https://discuss.elastic.co/t/elastic-security-rule-keyword-issue/349782)

<div class="topic-metadata">

**Author:** [@DVD\_MNC](https://discuss.elastic.co/u/DVD_MNC)\
**Replies:** 1\
**Last updated:** [January 3, 2024, 2:13pm UTC](https://discuss.elastic.co/t/elastic-security-rule-keyword-issue/349782 "2024-01-03T14:13:56Z")

</div>

Hello everyone, I have a strange problem with elastic rules. As you can see from the rule, I'm trying to trigger an alert every time a user misses a login twice (it's just a test). The preview of the rule works only i…

---

## [ELSER2 | Spell check before creating embeddings](https://discuss.elastic.co/t/elser2-spell-check-before-creating-embeddings/350303)

<div class="topic-metadata">

**Author:** [@Rakesh\_Nayak](https://discuss.elastic.co/u/Rakesh_Nayak)\
**Replies:** 1\
**Last updated:** [January 3, 2024, 2:07pm UTC](https://discuss.elastic.co/t/elser2-spell-check-before-creating-embeddings/350303 "2024-01-03T14:07:16Z")

</div>

Hello Team, Any suggestion of doing spell check before creating embeddings? e.g. if the query is misspelt "toiket rolls" instead of "toilet rolls" can we create the embeddings for "toilet rolls" using ELSER2 model POST…

---

## [Add filed to Elastic Agentedit](https://discuss.elastic.co/t/add-filed-to-elastic-agentedit/350139)

<div class="topic-metadata">

**Author:** [@Crazyworlds](https://discuss.elastic.co/u/Crazyworlds)\
**Replies:** 2\
**Last updated:** [January 3, 2024, 2:03pm UTC](https://discuss.elastic.co/t/add-filed-to-elastic-agentedit/350139 "2024-01-03T14:03:05Z")

</div>

I notice that Elastic Agent does not populate the ecs filed organization.name and for this, following the documentation I try to create a pipiline as this: POST /\_ingest/pipeline/\_simulate { "pipeline" : { "processo…

---

## [Apm server configured by elastic operator ignore ${SECRET\_TOKEN} variable](https://discuss.elastic.co/t/apm-server-configured-by-elastic-operator-ignore-secret-token-variable/350305)

<div class="topic-metadata">

**Author:** [@hetii](https://discuss.elastic.co/u/hetii)\
**Replies:** 0\
**Last updated:** [January 3, 2024, 1:27pm UTC](https://discuss.elastic.co/t/apm-server-configured-by-elastic-operator-ignore-secret-token-variable/350305 "2024-01-03T13:27:38Z")

</div>

Hi :wink: For code like below Apm server configured by elastic operator ignore ${SECRET\_TOKEN} variable. apiVersion: apm.k8s.elastic.co/v1 kind: ApmServer metadata: name: apm-server namespace: elfstack spec: vers…

---

## [Production configuration question](https://discuss.elastic.co/t/production-configuration-question/350302)

<div class="topic-metadata">

**Author:** [@Aleksandar\_Aleksand1](https://discuss.elastic.co/u/Aleksandar_Aleksand1)\
**Replies:** 3\
**Last updated:** [January 3, 2024, 1:07pm UTC](https://discuss.elastic.co/t/production-configuration-question/350302 "2024-01-03T13:07:42Z")

</div>

Hi all, I am preparing the following elasticsearch cluster architecture: Total 6 Nodes: 1 Node with roles: master and remote\_cluster\_client 3 Nodes with roles: data, data\_hot, data\_content and ingest 1 Node with role…

---

## [Metricbeat fails to fetch metrics for mongoDB 6.0.4](https://discuss.elastic.co/t/metricbeat-fails-to-fetch-metrics-for-mongodb-6-0-4/349660)

<div class="topic-metadata">

**Author:** [@Usama\_Tariq](https://discuss.elastic.co/u/Usama_Tariq)\
**Replies:** 3\
**Last updated:** [January 3, 2024, 1:03pm UTC](https://discuss.elastic.co/t/metricbeat-fails-to-fetch-metrics-for-mongodb-6-0-4/349660 "2024-01-03T13:03:42Z")

</div>

Metricbeat version: 8.3.1 MongoDB version: 6.0.4 My metricbeat config is as follows: ################### metricbeat Configuration ######################### ############################# metricbeat ###################…

---

## [Integration of elastic and logstash with other vizualization](https://discuss.elastic.co/t/integration-of-elastic-and-logstash-with-other-vizualization/350292)

<div class="topic-metadata">

**Author:** [@Karan\_Lobo](https://discuss.elastic.co/u/Karan_Lobo)\
**Replies:** 1\
**Last updated:** [January 3, 2024, 12:50pm UTC](https://discuss.elastic.co/t/integration-of-elastic-and-logstash-with-other-vizualization/350292 "2024-01-03T12:50:41Z")

</div>

Hey there i am working on a project that requires me to integrate ELK stack with other vizualiation tools fo free , however i am running into the issue of downloading the ODBC driver as it is showing that i would need a …

---

## [ES curator not deleting the indices data](https://discuss.elastic.co/t/es-curator-not-deleting-the-indices-data/350241)

<div class="topic-metadata">

**Author:** [@Ravi\_Pattar](https://discuss.elastic.co/u/Ravi_Pattar)\
**Replies:** 2\
**Last updated:** [January 3, 2024, 12:49pm UTC](https://discuss.elastic.co/t/es-curator-not-deleting-the-indices-data/350241 "2024-01-03T12:49:26Z")

</div>

Hello, I have installed the ES-curator and below are my curator.yml and action.yml. I am seeing below errors while running the dry run and also when I tried with the cronjob entries. Because I don't see the indices dat…

---

## [Plugin installation was unsuccessful due to error Plugin kibanaPrometheusExporter \[7.17.0\] is incompatible with Kibana \[7.17.15\]](https://discuss.elastic.co/t/plugin-installation-was-unsuccessful-due-to-error-plugin-kibanaprometheusexporter-7-17-0-is-incompatible-with-kibana-7-17-15/350231)

<div class="topic-metadata">

**Author:** [@Domnic\_Raj\_D](https://discuss.elastic.co/u/Domnic_Raj_D)\
**Replies:** 6\
**Last updated:** [January 3, 2024, 12:44pm UTC](https://discuss.elastic.co/t/plugin-installation-was-unsuccessful-due-to-error-plugin-kibanaprometheusexporter-7-17-0-is-incompatible-with-kibana-7-17-15/350231 "2024-01-03T12:44:55Z")

</div>

I have upgraded Kibana to version 7.17.15 in our environment, but I cannot find the Kibana Prometheus Exporter version 7.17.15 on the GitHub page. I attempted versions 7.17.0 and the latest patch version, but encountered…

---

## [Error creating web crawl index using Enterprise Search in Docker](https://discuss.elastic.co/t/error-creating-web-crawl-index-using-enterprise-search-in-docker/350267)

<div class="topic-metadata">

**Author:** [@sneh3091](https://discuss.elastic.co/u/sneh3091)\
**Replies:** 1\
**Last updated:** [January 3, 2024, 11:33am UTC](https://discuss.elastic.co/t/error-creating-web-crawl-index-using-enterprise-search-in-docker/350267 "2024-01-03T11:33:25Z")

</div>

Hi all, When trying to create a web crawl based index after spinning up Eneterprise Search and Kibana locally through Docker, I see this error. After hours of trying to figure out, I wanted to reach out here to understa…

---

## [Help for Tracking Exception Rule Hits in Elastic Security](https://discuss.elastic.co/t/help-for-tracking-exception-rule-hits-in-elastic-security/350298)

<div class="topic-metadata">

**Author:** [@anak1n](https://discuss.elastic.co/u/anak1n)\
**Replies:** 0\
**Last updated:** [January 3, 2024, 11:22am UTC](https://discuss.elastic.co/t/help-for-tracking-exception-rule-hits-in-elastic-security/350298 "2024-01-03T11:22:43Z")

</div>

Hello Elastic Security Community, I'm currently working with Elastic Security and have implemented several exception rules to fine-tune my alert system. However, I've encountered a challenge: I need to measure the effec…

---

## [Kibana server is not ready yet](https://discuss.elastic.co/t/kibana-server-is-not-ready-yet/350280)

<div class="topic-metadata">

**Author:** [@MD\_Rezaul\_Karim](https://discuss.elastic.co/u/MD_Rezaul_Karim)\
**Replies:** 10\
**Last updated:** [January 3, 2024, 11:11am UTC](https://discuss.elastic.co/t/kibana-server-is-not-ready-yet/350280 "2024-01-03T11:11:08Z")

</div>

Hi, I am getting following error. anyone pls. help me .. Jan 03 13:21:50 siem kibana\[10792\]: FATAL Error: Unable to complete saved object migrations for the \[.kibana\_task\_manager\] index. Please check the health of you…

[Previous page](https://discuss.elastic.co/latest.md?page=439)

[Next page](https://discuss.elastic.co/latest.md?page=441)
