# Latest

**URL:** https://discuss.elastic.co/latest.md?page=445

[Latest](https://discuss.elastic.co/latest.md) · [Categories](https://discuss.elastic.co/categories.md) · [Tags](https://discuss.elastic.co/tags.md)

**Page:** 446

---

## [Elasticsearch cloud does not receive logs from Serilog](https://discuss.elastic.co/t/elasticsearch-cloud-does-not-receive-logs-from-serilog/349452)

<div class="topic-metadata">

**Author:** [@Zsombor\_Veres-Lakos](https://discuss.elastic.co/u/Zsombor_Veres-Lakos)\
**Replies:** 0\
**Last updated:** [December 15, 2023, 12:47pm UTC](https://discuss.elastic.co/t/elasticsearch-cloud-does-not-receive-logs-from-serilog/349452 "2023-12-15T12:47:02Z")

</div>

Yesterday I was trying to set minimal privileges for Apikey, so I built a dummy logging application. I used that application from 10:00-19:00 and then the Elastic search stopped showing logs. Since yesterday 19:00 I am …

---

## [Percentage Metric](https://discuss.elastic.co/t/percentage-metric/349388)

<div class="topic-metadata">

**Author:** [@sbottura](https://discuss.elastic.co/u/sbottura)\
**Replies:** 1\
**Last updated:** [December 27, 2023, 10:26pm UTC](https://discuss.elastic.co/t/percentage-metric/349388 "2023-12-27T22:26:17Z")

</div>

Hello, I need to create a Metric which shows the percentage of the sum of one field to the sum of another field. Let's say "a" is the sum of all the money I cashed in so far and "b" is the sum of all the money I am set…

---

## [Kibana plugin installation: Error when installing plugin in kibana 8.8.2](https://discuss.elastic.co/t/kibana-plugin-installation-error-when-installing-plugin-in-kibana-8-8-2/348475)

<div class="topic-metadata">

**Author:** [@Bisrat\_Awoke](https://discuss.elastic.co/u/Bisrat_Awoke)\
**Replies:** 1\
**Last updated:** [December 27, 2023, 10:17pm UTC](https://discuss.elastic.co/t/kibana-plugin-installation-error-when-installing-plugin-in-kibana-8-8-2/348475 "2023-12-27T22:17:55Z")

</div>

I developed a custom plugin and when i try to install it i get the following error. The browser is making a request to fetch my plugins plugin.js file but the server is responding with 404. Whats weird is that i this…

---

## [Alert for kubernetes pods](https://discuss.elastic.co/t/alert-for-kubernetes-pods/348424)

<div class="topic-metadata">

**Author:** [@Aniket\_Pant](https://discuss.elastic.co/u/Aniket_Pant)\
**Replies:** 0\
**Last updated:** [December 1, 2023, 10:53am UTC](https://discuss.elastic.co/t/alert-for-kubernetes-pods/348424 "2023-12-01T10:53:12Z")

</div>

Hi Team, We are monitoring kubernetes pods and we need to set an alert when a pod is restart or down. How to do this using kibana alert as we are not able to find it.

---

## [Can I create Kibana Heat Map based on many different saved DSL queries?](https://discuss.elastic.co/t/can-i-create-kibana-heat-map-based-on-many-different-saved-dsl-queries/349618)

<div class="topic-metadata">

**Author:** [@allan.silverstein](https://discuss.elastic.co/u/allan.silverstein)\
**Replies:** 1\
**Last updated:** [December 27, 2023, 9:33pm UTC](https://discuss.elastic.co/t/can-i-create-kibana-heat-map-based-on-many-different-saved-dsl-queries/349618 "2023-12-27T21:33:50Z")

</div>

Here is what I'd like to do: In Kibana, I'd like to create a Heat Map where each box in the heat map represents the result of a specific saved query. Each box in the heatmap should represent the count of the result of …

---

## [3D map plugin](https://discuss.elastic.co/t/3d-map-plugin/349672)

<div class="topic-metadata">

**Author:** [@pchakour](https://discuss.elastic.co/u/pchakour)\
**Replies:** 1\
**Last updated:** [December 27, 2023, 9:23pm UTC](https://discuss.elastic.co/t/3d-map-plugin/349672 "2023-12-27T21:23:32Z")

</div>

Hello ! I'm trying to start the development of new plugin. The aim of this plugin is to render data in a 3D map. Anyone already do this kind of plugin ? I found a lib named Cesium which seems to be awesome. Unfortuna…

---

## [To create a dashboard to get the highest transactions in a week in any interval](https://discuss.elastic.co/t/to-create-a-dashboard-to-get-the-highest-transactions-in-a-week-in-any-interval/349693)

<div class="topic-metadata">

**Author:** [@0954bd6f79bcb4a34df4](https://discuss.elastic.co/u/0954bd6f79bcb4a34df4)\
**Replies:** 1\
**Last updated:** [December 27, 2023, 9:17pm UTC](https://discuss.elastic.co/t/to-create-a-dashboard-to-get-the-highest-transactions-in-a-week-in-any-interval/349693 "2023-12-27T21:17:17Z")

</div>

i need to create a dashboard where it should display highest transactions of all weeks in any interval ,say 6 months (Monday to sunday i,e; highest Monday, Tuesday,,,,Sunday transactions in all weeks of the 6 months) .…

---

## [Configure Elastic Cloud login on on-premise Kibana](https://discuss.elastic.co/t/configure-elastic-cloud-login-on-on-premise-kibana/349805)

<div class="topic-metadata">

**Author:** [@Gianfranco\_Demarco](https://discuss.elastic.co/u/Gianfranco_Demarco)\
**Replies:** 1\
**Last updated:** [December 27, 2023, 9:11pm UTC](https://discuss.elastic.co/t/configure-elastic-cloud-login-on-on-premise-kibana/349805 "2023-12-27T21:11:16Z")

</div>

Hello, on our setup we have an additional on-premise Kibana instance. When we try to log in, at the moment, only the "Log in with Elasticsearch" option is present. We would like to add the "Log in with Elastic Cloud" …

---

## [Kibana can not generate CSV file ,it show internal server error](https://discuss.elastic.co/t/kibana-can-not-generate-csv-file-it-show-internal-server-error/348629)

<div class="topic-metadata">

**Author:** [@hejunliang1234](https://discuss.elastic.co/u/hejunliang1234)\
**Replies:** 2\
**Last updated:** [December 27, 2023, 9:06pm UTC](https://discuss.elastic.co/t/kibana-can-not-generate-csv-file-it-show-internal-server-error/348629 "2023-12-27T21:06:15Z")

</div>

Dear all, When i want to generate CSV file, it show internal server error .Below is log. {"type":"response","@timestamp":"2023-12-05T18:59:23+08:00","tags":\[\],"pid":3078,"method":"post","statusCode":200,"req":{"url":"/…

---

## [What is the recommended approach to do logs in kibana plugin?](https://discuss.elastic.co/t/what-is-the-recommended-approach-to-do-logs-in-kibana-plugin/349911)

<div class="topic-metadata">

**Author:** [@cyrildaniel](https://discuss.elastic.co/u/cyrildaniel)\
**Replies:** 1\
**Last updated:** [December 27, 2023, 9:02pm UTC](https://discuss.elastic.co/t/what-is-the-recommended-approach-to-do-logs-in-kibana-plugin/349911 "2023-12-27T21:02:02Z")

</div>

Can anyone tell what is the recommended approach to do logs for actions in kibana plugin? Also using this service Logging service | Kibana Guide \[8.11\] | Elastic where can I find the kibana package as shown in the scree…

---

## [How to increase font size in Metric chart (kibana 8.9.2)?](https://discuss.elastic.co/t/how-to-increase-font-size-in-metric-chart-kibana-8-9-2/349942)

<div class="topic-metadata">

**Author:** [@Charan\_Kumar\_reddy](https://discuss.elastic.co/u/Charan_Kumar_reddy)\
**Replies:** 1\
**Last updated:** [December 27, 2023, 8:54pm UTC](https://discuss.elastic.co/t/how-to-increase-font-size-in-metric-chart-kibana-8-9-2/349942 "2023-12-27T20:54:21Z")

</div>

I am using kibana version 8.9.2. I have created a metric chart it's showing text at right bottom corner. Which is not much visible , i want to increase the size . How to do that please help me? .

---

## [Error fetching data for metricset kibana.node\_rules: error making http request](https://discuss.elastic.co/t/error-fetching-data-for-metricset-kibana-node-rules-error-making-http-request/349990)

<div class="topic-metadata">

**Author:** [@husoelasticbe](https://discuss.elastic.co/u/husoelasticbe)\
**Replies:** 10\
**Last updated:** [December 27, 2023, 8:15pm UTC](https://discuss.elastic.co/t/error-fetching-data-for-metricset-kibana-node-rules-error-making-http-request/349990 "2023-12-27T20:15:15Z")

</div>

Hi Folks, I am almost getting mad. Please help me our here. I am trying to collect kibana monitoring data with metricbeat. I get strangely the following error: {"file.name":"module/wrapper.go","file.line":256},"messa…

---

## [How can I search for the latest data entered in the indexes? ](https://discuss.elastic.co/t/how-can-i-search-for-the-latest-data-entered-in-the-indexes/349972)

<div class="topic-metadata">

**Author:** [@deep1](https://discuss.elastic.co/u/deep1)\
**Replies:** 17\
**Last updated:** [December 27, 2023, 5:32pm UTC](https://discuss.elastic.co/t/how-can-i-search-for-the-latest-data-entered-in-the-indexes/349972 "2023-12-27T17:32:15Z")

</div>

For example, I want to search in 100,000 documents from each index, and it is not possible to add to that, and they are first loaded into the cache, then only this data is searched

---

## [Gather Data from Yesterday Until Today](https://discuss.elastic.co/t/gather-data-from-yesterday-until-today/349740)

<div class="topic-metadata">

**Author:** [@hi\_xavier](https://discuss.elastic.co/u/hi_xavier)\
**Replies:** 2\
**Last updated:** [December 27, 2023, 4:19pm UTC](https://discuss.elastic.co/t/gather-data-from-yesterday-until-today/349740 "2023-12-27T16:19:48Z")

</div>

Hello, I'm currently using the elk api to gather data between yesterday and today (12/19 @ 00:00:000 -- 12/20@00:00:000) Would this be the equivalent of that using a range query? "range": { "timestamp": { …

---

## [Different results of aggregation query on same version](https://discuss.elastic.co/t/different-results-of-aggregation-query-on-same-version/349872)

<div class="topic-metadata">

**Author:** [@apari](https://discuss.elastic.co/u/apari)\
**Replies:** 1\
**Last updated:** [December 27, 2023, 3:17pm UTC](https://discuss.elastic.co/t/different-results-of-aggregation-query-on-same-version/349872 "2023-12-27T15:17:24Z")

</div>

I am running the following query on multiple servers, same build (same hash, build date, and version number) of ES. 7.16.2 { "size": 0, "query": { "terms": { "FileFeedID": \[ // Some values …

---

## [Elastic SIEM](https://discuss.elastic.co/t/elastic-siem/350026)

<div class="topic-metadata">

**Author:** [@Ammar\_Mostafa](https://discuss.elastic.co/u/Ammar_Mostafa)\
**Replies:** 0\
**Last updated:** [December 27, 2023, 2:54pm UTC](https://discuss.elastic.co/t/elastic-siem/350026 "2023-12-27T14:54:06Z")

</div>

Hello All, I hope all is well with you. I'm new to elastic and I want to inquire if we can fully depend on elastic security as siem solution? Thnk you in advance.

---

## [Removing master node permanently](https://discuss.elastic.co/t/removing-master-node-permanently/350002)

<div class="topic-metadata">

**Author:** [@artechkey](https://discuss.elastic.co/u/artechkey)\
**Replies:** 4\
**Last updated:** [December 27, 2023, 2:31pm UTC](https://discuss.elastic.co/t/removing-master-node-permanently/350002 "2023-12-27T14:31:14Z")

</div>

Hi, We currently have a 2 node + master-voting only node cluster. We are expanding the cluster by adding 3 more nodes to it. As part of the expansion, we want to designate one of the new nodes as a master and take out t…

---

## [Optimizing Elasticsearch Snapshot Recovery for Node Disk Space Utilization](https://discuss.elastic.co/t/optimizing-elasticsearch-snapshot-recovery-for-node-disk-space-utilization/350013)

<div class="topic-metadata">

**Author:** [@jakub0011](https://discuss.elastic.co/u/jakub0011)\
**Replies:** 1\
**Last updated:** [December 27, 2023, 2:15pm UTC](https://discuss.elastic.co/t/optimizing-elasticsearch-snapshot-recovery-for-node-disk-space-utilization/350013 "2023-12-27T14:15:01Z")

</div>

I'm seeking advice on optimizing the snapshot recovery process in our Elasticsearch cluster, which consists of 8 nodes. Currently, when recovering various snapshots, the indices are restored to nodes based on the percent…

---

## [How to parse date field into @timestamp](https://discuss.elastic.co/t/how-to-parse-date-field-into-timestamp/349849)

<div class="topic-metadata">

**Author:** [@emoxam](https://discuss.elastic.co/u/emoxam)\
**Replies:** 11\
**Last updated:** [December 22, 2023, 2:26pm UTC](https://discuss.elastic.co/t/how-to-parse-date-field-into-timestamp/349849 "2023-12-22T14:26:55Z")

</div>

I want to move the fulltime from message field to @timestamp. That's what i created. filter { if \[message\] =~ /actions/ { json { source =\> "message" } date { match =\> \[ "message", "yyyy-MM-dd …

---

## [Nomad filebeat autodiscover seems to ignore template's condition](https://discuss.elastic.co/t/nomad-filebeat-autodiscover-seems-to-ignore-templates-condition/349985)

<div class="topic-metadata">

**Author:** [@Yuri\_Nakshin](https://discuss.elastic.co/u/Yuri_Nakshin)\
**Replies:** 2\
**Last updated:** [December 27, 2023, 12:31pm UTC](https://discuss.elastic.co/t/nomad-filebeat-autodiscover-seems-to-ignore-templates-condition/349985 "2023-12-27T12:31:01Z")

</div>

Hi, We have this setup filebeat.autodiscover: providers: - type: nomad node: {{ env "node.unique.name" }} scope: node address: \<nomad-cluster-address\> templates: - condition: …

---

## [Elasticsearch not creating index](https://discuss.elastic.co/t/elasticsearch-not-creating-index/350016)

<div class="topic-metadata">

**Author:** [@bas\_kos](https://discuss.elastic.co/u/bas_kos)\
**Replies:** 0\
**Last updated:** [December 27, 2023, 11:06am UTC](https://discuss.elastic.co/t/elasticsearch-not-creating-index/350016 "2023-12-27T11:06:38Z")

</div>

I have elasticsearch, kibana and logstash installed on docker-compose. docker-compose.yml: version: "3.8" volumes: certs: driver: local esdata01: driver: local kibanadata: driver: local metricbeatd…

---

## [Elk audit logs](https://discuss.elastic.co/t/elk-audit-logs/349924)

<div class="topic-metadata">

**Author:** [@theacodes](https://discuss.elastic.co/u/theacodes)\
**Replies:** 2\
**Last updated:** [December 27, 2023, 5:58am UTC](https://discuss.elastic.co/t/elk-audit-logs/349924 "2023-12-27T05:58:51Z")

</div>

Hey! I'm using on-prem ELK v8.1 I want to check the audit logs of ELK. which user did what activity, what rules are disabled by users, and what modifications are done by them. Currently, I'm using the basic version wi…

---

## [Unable to Access Path.Repo Eck In K8 Cluster](https://discuss.elastic.co/t/unable-to-access-path-repo-eck-in-k8-cluster/349997)

<div class="topic-metadata">

**Author:** [@Nauman\_Kyani](https://discuss.elastic.co/u/Nauman_Kyani)\
**Replies:** 0\
**Last updated:** [December 27, 2023, 5:26am UTC](https://discuss.elastic.co/t/unable-to-access-path-repo-eck-in-k8-cluster/349997 "2023-12-27T05:26:10Z")

</div>

Am facing the below issue am want to register the snpshot repo to file share system i have nfs path and configured it right way things are working finw when i update the path then i facing this issue why? Defaulted cont…

---

## [Dropdown select element not effect to essql while select value](https://discuss.elastic.co/t/dropdown-select-element-not-effect-to-essql-while-select-value/349995)

<div class="topic-metadata">

**Author:** [@Dy\_Vanrith](https://discuss.elastic.co/u/Dy_Vanrith)\
**Replies:** 0\
**Last updated:** [December 27, 2023, 4:42am UTC](https://discuss.elastic.co/t/dropdown-select-element-not-effect-to-essql-while-select-value/349995 "2023-12-27T04:42:27Z")

</div>

My expression dropdown element esdocs index="2023.12.22" fields="startAdminDate" | dropdownControl valueColumn="startAdminDate" filterColumn="startAdminDate" filterGroup="VTM" | render table element filters group="VT…

---

## [Logstash V fileBeat](https://discuss.elastic.co/t/logstash-v-filebeat/349979)

<div class="topic-metadata">

**Author:** [@pumiki](https://discuss.elastic.co/u/pumiki)\
**Replies:** 0\
**Last updated:** [December 26, 2023, 5:09pm UTC](https://discuss.elastic.co/t/logstash-v-filebeat/349979 "2023-12-26T17:09:27Z")

</div>

Hello, We have c# applications , running without docker. we want to write them to Elasticsearch. I have managed to run logstash (right now as exe) and make it write to csv files. next, i will change it to write to e…

---

## [ELK Stack: Logstash shows that it's receiving log entries from Filebeat, but Elasticsearch is not creating my index](https://discuss.elastic.co/t/elk-stack-logstash-shows-that-its-receiving-log-entries-from-filebeat-but-elasticsearch-is-not-creating-my-index/349826)

<div class="topic-metadata">

**Author:** [@BDeveloper](https://discuss.elastic.co/u/BDeveloper)\
**Replies:** 8\
**Last updated:** [December 26, 2023, 4:40pm UTC](https://discuss.elastic.co/t/elk-stack-logstash-shows-that-its-receiving-log-entries-from-filebeat-but-elasticsearch-is-not-creating-my-index/349826 "2023-12-26T16:40:57Z")

</div>

I am new to the ELK stack and I wanted to try and test it out to see if I wanted to use it. I have elasticsearch, kibana, and logstash installed on one virtual machine and I have filebeat and nginx installed on another v…

---

## [Elastic Agent successfully connect to Fleet Server but Elasticsearch did not receive data! bug](https://discuss.elastic.co/t/elastic-agent-successfully-connect-to-fleet-server-but-elasticsearch-did-not-receive-data-bug/349887)

<div class="topic-metadata">

**Author:** [@helloworld404](https://discuss.elastic.co/u/helloworld404)\
**Replies:** 1\
**Last updated:** [December 26, 2023, 4:24pm UTC](https://discuss.elastic.co/t/elastic-agent-successfully-connect-to-fleet-server-but-elasticsearch-did-not-receive-data-bug/349887 "2023-12-26T16:24:54Z")

</div>

OS lsb\_release -a No LSB modules are available. Distributor ID: Ubuntu Description: Ubuntu 22.04 LTS Release: 22.04 Codename: jammy install Elastic wget -qO - https://artifacts.elastic.co/GPG-KEY-elastic…

---

## [Logstash not sending data to Elasticsearch](https://discuss.elastic.co/t/logstash-not-sending-data-to-elasticsearch/349736)

<div class="topic-metadata">

**Author:** [@gtartjr](https://discuss.elastic.co/u/gtartjr)\
**Replies:** 5\
**Last updated:** [December 26, 2023, 4:06pm UTC](https://discuss.elastic.co/t/logstash-not-sending-data-to-elasticsearch/349736 "2023-12-26T16:06:06Z")

</div>

I am unable to get Logstash to read data and send to Elasticsearch index. My Elastcistac is 8.11.2, under a Docker for Windows platform. I have 2 jsonl formatted files that I need to index into Elasticsearch by a unique …

---

## [Display the last 100k documents](https://discuss.elastic.co/t/display-the-last-100k-documents/349961)

<div class="topic-metadata">

**Author:** [@1337](https://discuss.elastic.co/u/1337)\
**Replies:** 3\
**Last updated:** [December 26, 2023, 3:58pm UTC](https://discuss.elastic.co/t/display-the-last-100k-documents/349961 "2023-12-26T15:58:24Z")

</div>

I want to display the last 100k documents for all indices. Each index with the last 100k

---

## [I want to search only the last data entered. That is, the search is in only 100,000 per index you have, I want to search, these data are loaded into the cache and are searched only ](https://discuss.elastic.co/t/i-want-to-search-only-the-last-data-entered-that-is-the-search-is-in-only-100-000-per-index-you-have-i-want-to-search-these-data-are-loaded-into-the-cache-and-are-searched-only/349970)

<div class="topic-metadata">

**Author:** [@deep111](https://discuss.elastic.co/u/deep111)\
**Replies:** 1\
**Last updated:** [December 26, 2023, 3:56pm UTC](https://discuss.elastic.co/t/i-want-to-search-only-the-last-data-entered-that-is-the-search-is-in-only-100-000-per-index-you-have-i-want-to-search-these-data-are-loaded-into-the-cache-and-are-searched-only/349970 "2023-12-26T15:56:26Z")

</div>

Json format

[Previous page](https://discuss.elastic.co/latest.md?page=444)

[Next page](https://discuss.elastic.co/latest.md?page=446)
