# Latest

**URL:** https://discuss.elastic.co/latest.md?page=442

[Latest](https://discuss.elastic.co/latest.md) · [Categories](https://discuss.elastic.co/categories.md) · [Tags](https://discuss.elastic.co/tags.md)

**Page:** 443

---

## [Two Logstash nodes. Same config. Persistent queue filling only in one of them](https://discuss.elastic.co/t/two-logstash-nodes-same-config-persistent-queue-filling-only-in-one-of-them/350229)

<div class="topic-metadata">

**Author:** [@nahiko](https://discuss.elastic.co/u/nahiko)\
**Replies:** 1\
**Last updated:** [January 2, 2024, 1:34pm UTC](https://discuss.elastic.co/t/two-logstash-nodes-same-config-persistent-queue-filling-only-in-one-of-them/350229 "2024-01-02T13:34:31Z")

</div>

Hello! I have a 3 node Elasticsearch cluster, 2 Logstash nodes and about 100 filebeats sending data to Logstash. Every piece is 7.17 Both Logstash nodes have the exact same configuration. There is a 16 GB persistent q…

---

## [Logstash inconsistency while reading csv data](https://discuss.elastic.co/t/logstash-inconsistency-while-reading-csv-data/348881)

<div class="topic-metadata">

**Author:** [@iko](https://discuss.elastic.co/u/iko)\
**Replies:** 8\
**Last updated:** [January 2, 2024, 1:15pm UTC](https://discuss.elastic.co/t/logstash-inconsistency-while-reading-csv-data/348881 "2024-01-02T13:15:05Z")

</div>

Hello, We are using Logstash for parsing csv data and load them into Postgresql and then after making proper transformation we move that data to Elasticsearch by using same Logstash . We don't have any problem about tra…

---

## [How much cpu power needed for elk consider security use case?](https://discuss.elastic.co/t/how-much-cpu-power-needed-for-elk-consider-security-use-case/350179)

<div class="topic-metadata">

**Author:** [@Ammar\_Mostafa](https://discuss.elastic.co/u/Ammar_Mostafa)\
**Replies:** 4\
**Last updated:** [January 2, 2024, 12:48pm UTC](https://discuss.elastic.co/t/how-much-cpu-power-needed-for-elk-consider-security-use-case/350179 "2024-01-02T12:48:27Z")

</div>

elk documentation say that for every 20 shard we need 1 gb ram what about cpu?

---

## [Elastic Engineer On-Demand Course Lab in Strigo has ended](https://discuss.elastic.co/t/elastic-engineer-on-demand-course-lab-in-strigo-has-ended/350183)

<div class="topic-metadata">

**Author:** [@Maor\_Shmul](https://discuss.elastic.co/u/Maor_Shmul)\
**Replies:** 1\
**Last updated:** [January 2, 2024, 11:49am UTC](https://discuss.elastic.co/t/elastic-engineer-on-demand-course-lab-in-strigo-has-ended/350183 "2024-01-02T11:49:17Z")

</div>

Course: Version: Question: \<I enrolled in Elastic Engineer On-Demand 3 months ago and took a break for paternity leave. I resumed 2 weeks ago, but yesterday I got notified that Strigo lab ended. Can I get a new envir…

---

## [Playwright script is working while testing in synthetic recorder but its networking while configure it in the monitor](https://discuss.elastic.co/t/playwright-script-is-working-while-testing-in-synthetic-recorder-but-its-networking-while-configure-it-in-the-monitor/349859)

<div class="topic-metadata">

**Author:** [@surya\_dadi\_dhamarake](https://discuss.elastic.co/u/surya_dadi_dhamarake)\
**Replies:** 5\
**Last updated:** [January 2, 2024, 11:13am UTC](https://discuss.elastic.co/t/playwright-script-is-working-while-testing-in-synthetic-recorder-but-its-networking-while-configure-it-in-the-monitor/349859 "2024-01-02T11:13:00Z")

</div>

Hi Team, I have recorded an activity on a website using synthetic recorder and while I am testing the script that is formed in synthetic recorder itself is working fine but when I configure the same in synthetic multipa…

---

## [Kibana 审计功能](https://discuss.elastic.co/t/kibana/350219)

<div class="topic-metadata">

**Author:** [@wq1357226](https://discuss.elastic.co/u/wq1357226)\
**Replies:** 0\
**Last updated:** [January 2, 2024, 10:04am UTC](https://discuss.elastic.co/t/kibana/350219 "2024-01-02T10:04:37Z")

</div>

kibana7.11.2咋样开启审计日志功能，记录在目标日志中或者展示到控制台上，根据官网文档添加配置重启，无报错，也无日志输出

---

## [Filebeat not deleting disk queue segment files](https://discuss.elastic.co/t/filebeat-not-deleting-disk-queue-segment-files/349094)

<div class="topic-metadata">

**Author:** [@vis20953](https://discuss.elastic.co/u/vis20953)\
**Replies:** 1\
**Last updated:** [January 2, 2024, 10:04am UTC](https://discuss.elastic.co/t/filebeat-not-deleting-disk-queue-segment-files/349094 "2024-01-02T10:04:18Z")

</div>

Hi friends, We are experiencing an issue where the Filebeat service does not delete the segment files in the disk queue, resulting in the service not sending log entries to Logstash when the max\_size has been reached: …

---

## [Kibana v8(beat)和V7主题版本的区别](https://discuss.elastic.co/t/kibana-v8-beat-v7/350217)

<div class="topic-metadata">

**Author:** [@wq1357226](https://discuss.elastic.co/u/wq1357226)\
**Replies:** 0\
**Last updated:** [January 2, 2024, 10:01am UTC](https://discuss.elastic.co/t/kibana-v8-beat-v7/350217 "2024-01-02T10:01:19Z")

</div>

kibana7.11.2提供V8（beat）和V7两种版本选择，有什么区别呢

---

## [Certificate pinning in Elasticsearch](https://discuss.elastic.co/t/certificate-pinning-in-elasticsearch/350214)

<div class="topic-metadata">

**Author:** [@jaykb77](https://discuss.elastic.co/u/jaykb77)\
**Replies:** 1\
**Last updated:** [January 2, 2024, 9:55am UTC](https://discuss.elastic.co/t/certificate-pinning-in-elasticsearch/350214 "2024-01-02T09:55:54Z")

</div>

Hi, We are using Elasticsearch 7.17.0 and using azure storage blobs for snapshots. We recently received a general notification from azure about certificate pinning. I believe we do not have any such configuration tha…

---

## [ERROR no receiver metrics in apm-server](https://discuss.elastic.co/t/error-no-receiver-metrics-in-apm-server/349307)

<div class="topic-metadata">

**Author:** [@tungnx1](https://discuss.elastic.co/u/tungnx1)\
**Replies:** 0\
**Last updated:** [December 14, 2023, 1:31am UTC](https://discuss.elastic.co/t/error-no-receiver-metrics-in-apm-server/349307 "2023-12-14T01:31:18Z")

</div>

Hi, I am having the following problem: I used apm-server monitor service java. After but enable https://x.x.x.x:9200, https://x.x.x.x:5601. I gen cert config in elasticsearch.yml, kibana.yml, apm-server.yml status se…

---

## [Logstash upgrade issue - 8.11.3 version](https://discuss.elastic.co/t/logstash-upgrade-issue-8-11-3-version/350132)

<div class="topic-metadata">

**Author:** [@siva0030](https://discuss.elastic.co/u/siva0030)\
**Replies:** 7\
**Last updated:** [January 2, 2024, 9:23am UTC](https://discuss.elastic.co/t/logstash-upgrade-issue-8-11-3-version/350132 "2024-01-02T09:23:40Z")

</div>

Hello Team, Good evening! Today I have upgraded the Logstash from version 8.10.4 to 8.11.3 version. After the upgrade the Logstash is keep restarting and throwing below errors. This type of FATAL error is coming for a…

---

## [Esrally creat index error,class\_cast\_exception](https://discuss.elastic.co/t/esrally-creat-index-error-class-cast-exception/350215)

<div class="topic-metadata">

**Author:** [@zhouxuanxuan](https://discuss.elastic.co/u/zhouxuanxuan)\
**Replies:** 0\
**Last updated:** [January 2, 2024, 9:19am UTC](https://discuss.elastic.co/t/esrally-creat-index-error-class-cast-exception/350215 "2024-01-02T09:19:44Z")

</div>

\[ERROR\] Cannot race. Error in load generator \[0\] Cannot run task \[create-index\]: Request returned an error. Error type: transport, Description: class\_cast\_exception ({'error': {'root\_cause': \[{'type': 'class\_cast\_except…

---

## [Encountered a retryable error (will retry with exponential backoff) {:code=\>413}](https://discuss.elastic.co/t/encountered-a-retryable-error-will-retry-with-exponential-backoff-code-413/349802)

<div class="topic-metadata">

**Author:** [@sathishkumarD](https://discuss.elastic.co/u/sathishkumarD)\
**Replies:** 3\
**Last updated:** [January 2, 2024, 9:02am UTC](https://discuss.elastic.co/t/encountered-a-retryable-error-will-retry-with-exponential-backoff-code-413/349802 "2024-01-02T09:02:25Z")

</div>

Elastic search and Logstash version: 8.5.1 Getting below error from logstash when trying to transfer files to elasticsearch. Could someone help me to fix the issue. \[ERROR\]\[logstash.outputs.elasticsearch\]\[main\]\[532e27b…

---

## [Elasticsearch 7.16 shard recovery slow](https://discuss.elastic.co/t/elasticsearch-7-16-shard-recovery-slow/349952)

<div class="topic-metadata">

**Author:** [@wangxiangyu](https://discuss.elastic.co/u/wangxiangyu)\
**Replies:** 6\
**Last updated:** [January 2, 2024, 8:51am UTC](https://discuss.elastic.co/t/elasticsearch-7-16-shard-recovery-slow/349952 "2024-01-02T08:51:47Z")

</div>

hi, The elasticsearch cluster has 6 hot node and 4 cold node. One cold node is removed caused by hardware failure. So lots of missing replica shards( about 20TB) began to recover. But I found the recovery process was v…

---

## [.NET 8 - ElasticsearchClientException: The client is unable to verify that the server is Elasticsearch due to an unsuccessful product check call](https://discuss.elastic.co/t/net-8-elasticsearchclientexception-the-client-is-unable-to-verify-that-the-server-is-elasticsearch-due-to-an-unsuccessful-product-check-call/350208)

<div class="topic-metadata">

**Author:** [@Urbancsik\_Gergely](https://discuss.elastic.co/u/Urbancsik_Gergely)\
**Replies:** 0\
**Last updated:** [January 2, 2024, 8:34am UTC](https://discuss.elastic.co/t/net-8-elasticsearchclientexception-the-client-is-unable-to-verify-that-the-server-is-elasticsearch-due-to-an-unsuccessful-product-check-call/350208 "2024-01-02T08:34:37Z")

</div>

Hello. We upgrade our application to .net 8, and and we also upgrade the latest NEST library: version: \<PackageReference Include="NEST" Version="7.17.5" /\> \<PackageReference Include="NEST.JsonNetSerializer" Version="7.…

---

## [Kibana\_error](https://discuss.elastic.co/t/kibana-error/349585)

<div class="topic-metadata">

**Author:** [@sossoulokoariel](https://discuss.elastic.co/u/sossoulokoariel)\
**Replies:** 3\
**Last updated:** [January 2, 2024, 8:30am UTC](https://discuss.elastic.co/t/kibana-error/349585 "2024-01-02T08:30:48Z")

</div>

Hi community, hope you're well. I'm in the process of implementing the ELK stack as part of my dissertation project. For a few weeks I haven't logged in, but today I logged in, but the web interface puts Kibana is not re…

---

## [Fail Setup Logstash](https://discuss.elastic.co/t/fail-setup-logstash/350203)

<div class="topic-metadata">

**Author:** [@Septianingrum.17](https://discuss.elastic.co/u/Septianingrum.17)\
**Replies:** 0\
**Last updated:** [January 2, 2024, 8:23am UTC](https://discuss.elastic.co/t/fail-setup-logstash/350203 "2024-01-02T08:23:05Z")

</div>

Hi, I tried setting up logstash in my environment, previously I had 3 elasticsearch nodes and 1 kibana. I followed the steps" based on the URL: https://www.elastic.co/blog/configuring-ssl-tls-and-https-to-secure-elasti…

---

## [Ignore\_inactive does not work in filebeat with filestream config type](https://discuss.elastic.co/t/ignore-inactive-does-not-work-in-filebeat-with-filestream-config-type/349111)

<div class="topic-metadata">

**Author:** [@josepcorrea](https://discuss.elastic.co/u/josepcorrea)\
**Replies:** 7\
**Last updated:** [January 2, 2024, 8:15am UTC](https://discuss.elastic.co/t/ignore-inactive-does-not-work-in-filebeat-with-filestream-config-type/349111 "2024-01-02T08:15:05Z")

</div>

When I use the filestream type instead of the log type, filebeat always reads the entire log file from the beginning. - type: filestream id: test\_id enable: true paths: - "/usr/share/filebeat/inputs.d/\*.log" …

---

## [Failed to Fetching the Redis Info and keyspace logs to Kibana](https://discuss.elastic.co/t/failed-to-fetching-the-redis-info-and-keyspace-logs-to-kibana/350201)

<div class="topic-metadata">

**Author:** [@Pranjal\_Sett](https://discuss.elastic.co/u/Pranjal_Sett)\
**Replies:** 0\
**Last updated:** [January 2, 2024, 8:10am UTC](https://discuss.elastic.co/t/failed-to-fetching-the-redis-info-and-keyspace-logs-to-kibana/350201 "2024-01-02T08:10:10Z")

</div>

So my task was to install the metricbeat and enable the redis module to pick the INFO and Keyspace values. By providing that I was facing lot of issues mostly on TCP related. I have tried multiple ways to mitigate this b…

---

## [Kibana8.4.3 & nginx，nginx returns 502 bad gateway](https://discuss.elastic.co/t/kibana8-4-3-nginx-nginx-returns-502-bad-gateway/350197)

<div class="topic-metadata">

**Author:** [@gaygayGuys](https://discuss.elastic.co/u/gaygayGuys)\
**Replies:** 0\
**Last updated:** [January 2, 2024, 7:29am UTC](https://discuss.elastic.co/t/kibana8-4-3-nginx-nginx-returns-502-bad-gateway/350197 "2024-01-02T07:29:19Z")

</div>

hello everyone ! i need help !!!! when i use nginx to proxy kibana ,i find a tricky problem. at the beginning ,everything is ok. but several minutes later, 502 bad gateway is starting to appear! i hava no idea to solve…

---

## [Little help understanding a document query issue](https://discuss.elastic.co/t/little-help-understanding-a-document-query-issue/350198)

<div class="topic-metadata">

**Author:** [@Oscar\_Llerena](https://discuss.elastic.co/u/Oscar_Llerena)\
**Replies:** 0\
**Last updated:** [January 2, 2024, 7:29am UTC](https://discuss.elastic.co/t/little-help-understanding-a-document-query-issue/350198 "2024-01-02T07:29:47Z")

</div>

Hi everyone, happy new year! Can somebody please help me understanding the following issue? I have Elasticsearch (Elastic Defend) & Kibana in one server and Fleet in other separated. The monitoring agents are in a virt…

---

## [Elastic SIEM Fundamentals no longer available?](https://discuss.elastic.co/t/elastic-siem-fundamentals-no-longer-available/350195)

<div class="topic-metadata">

**Author:** [@coroso136](https://discuss.elastic.co/u/coroso136)\
**Replies:** 0\
**Last updated:** [January 2, 2024, 7:16am UTC](https://discuss.elastic.co/t/elastic-siem-fundamentals-no-longer-available/350195 "2024-01-02T07:16:30Z")

</div>

Course: Elastic SIEM Fundamentals Question: Hey there, is the course no longer available? I can't enroll unfortunately.

---

## [ElasticSearch affected by CVE-2023-44487](https://discuss.elastic.co/t/elasticsearch-affected-by-cve-2023-44487/350190)

<div class="topic-metadata">

**Author:** [@rairanjit](https://discuss.elastic.co/u/rairanjit)\
**Replies:** 0\
**Last updated:** [January 2, 2024, 4:16am UTC](https://discuss.elastic.co/t/elasticsearch-affected-by-cve-2023-44487/350190 "2024-01-02T04:16:42Z")

</div>

Elasticsearch 8.11.3 show that following file in respository-azure folder is affected by CVE-2023-44487. netty-codec-http2-4.1.94.Final.jar Is there a safe way I can remove this from docker images, so that modules load…

---

## [Where if anywhere does ES documentation explain about metadata, specifically index creation datetimes?](https://discuss.elastic.co/t/where-if-anywhere-does-es-documentation-explain-about-metadata-specifically-index-creation-datetimes/350185)

<div class="topic-metadata">

**Author:** [@mrodent](https://discuss.elastic.co/u/mrodent)\
**Replies:** 4\
**Last updated:** [January 1, 2024, 10:57pm UTC](https://discuss.elastic.co/t/where-if-anywhere-does-es-documentation-explain-about-metadata-specifically-index-creation-datetimes/350185 "2024-01-01T22:57:57Z")

</div>

This in an application context, not "human consumption". With a bit of searching I finally found this answer. The up-to-date (v. 8.11) documentation for this appears to be here, "cat indices API". But there it says "ca…

---

## [Invalid version of beats protocol: 69](https://discuss.elastic.co/t/invalid-version-of-beats-protocol-69/349830)

<div class="topic-metadata">

**Author:** [@e-ferrari](https://discuss.elastic.co/u/e-ferrari)\
**Replies:** 10\
**Last updated:** [January 1, 2024, 10:28pm UTC](https://discuss.elastic.co/t/invalid-version-of-beats-protocol-69/349830 "2024-01-01T22:28:56Z")

</div>

Hello, I'm completely new to ELK. I'm reading the doc and try to execute this: But i got an error from logstash: \[2023-12-21T23:21:37,978\]\[WARN \]\[io.netty.channel.DefaultChannelPipeline\]\[main\]\[c6b88577022f3da3a78380…

---

## [Date Column has some rows with NULL - strict\_date\_optional\_time causes Exception](https://discuss.elastic.co/t/date-column-has-some-rows-with-null-strict-date-optional-time-causes-exception/350164)

<div class="topic-metadata">

**Author:** [@Ethan777100](https://discuss.elastic.co/u/Ethan777100)\
**Replies:** 23\
**Last updated:** [January 1, 2024, 5:11pm UTC](https://discuss.elastic.co/t/date-column-has-some-rows-with-null-strict-date-optional-time-causes-exception/350164 "2024-01-01T17:11:46Z")

</div>

All this time, I use \[strict\_date\_optional\_time||yyyy-MM-dd HH:mm:ss.SSS||yyyy-MM-dd HH:mm:ss.SS||yyyy-MM-dd HH:mm:ss||yyyy-MM-dd HH:mm:ss.S\] To parse in columns with dates. Now, I have a csv file whose columns have ro…

---

## [Sizing elk for SIEM(security) use case](https://discuss.elastic.co/t/sizing-elk-for-siem-security-use-case/350178)

<div class="topic-metadata">

**Author:** [@Ammar\_Mostafa](https://discuss.elastic.co/u/Ammar_Mostafa)\
**Replies:** 2\
**Last updated:** [January 1, 2024, 4:42pm UTC](https://discuss.elastic.co/t/sizing-elk-for-siem-security-use-case/350178 "2024-01-01T16:42:52Z")

</div>

Hello everyone, can you help me how to size my elk as SIEM? any thoughts or resources can help please give to me. Thanks in advance.

---

## [Does Elasticsearch clients try to request to the node that has the primary shard of a specific doc?](https://discuss.elastic.co/t/does-elasticsearch-clients-try-to-request-to-the-node-that-has-the-primary-shard-of-a-specific-doc/350181)

<div class="topic-metadata">

**Author:** [@AmirrezaRiahi](https://discuss.elastic.co/u/AmirrezaRiahi)\
**Replies:** 3\
**Last updated:** [January 1, 2024, 3:49pm UTC](https://discuss.elastic.co/t/does-elasticsearch-clients-try-to-request-to-the-node-that-has-the-primary-shard-of-a-specific-doc/350181 "2024-01-01T15:49:50Z")

</div>

From my understanding, nodes only can perform write operations on documents if they own their primary shard. Therefore if we have 2 nodes A, B and A owns the primary shard of the doc D, if the client asks node B to modif…

---

## [2023: The Year in Review](https://discuss.elastic.co/t/2023-the-year-in-review/350184)

<div class="topic-metadata">

**Author:** [@system](https://discuss.elastic.co/u/system)\
**Replies:** 17\
**Last updated:** [January 1, 2024, 3:41pm UTC](https://discuss.elastic.co/t/2023-the-year-in-review/350184 "2024-01-01T15:41:16Z")

</div>

2023's Top Users Most Time Reading User Hours Read @stephenb 281 @leandrojmp 234 @Christian\_Dahlqvist 155 @Rios 120 @Badger 103 @DavidTurner 49 @carly.richmond 46 @PRASHANT\_MEHTA 40 @wa…

---

## [Attempt to create Lens visualization produces an error "Cannot read properties of undefined (reading 'localeCompare')"](https://discuss.elastic.co/t/attempt-to-create-lens-visualization-produces-an-error-cannot-read-properties-of-undefined-reading-localecompare/350010)

<div class="topic-metadata">

**Author:** [@Nicole\_Hirshler](https://discuss.elastic.co/u/Nicole_Hirshler)\
**Replies:** 4\
**Last updated:** [January 1, 2024, 12:29pm UTC](https://discuss.elastic.co/t/attempt-to-create-lens-visualization-produces-an-error-cannot-read-properties-of-undefined-reading-localecompare/350010 "2024-01-01T12:29:42Z")

</div>

Since the upgrade to 7.17.12 ELK, I cannot create Lens visualization. I searched the internet and found some post saying that it can be related to the security. ELK is configured in my setup with two users: elastic and s…

[Previous page](https://discuss.elastic.co/latest.md?page=441)

[Next page](https://discuss.elastic.co/latest.md?page=443)
