# Latest

**URL:** https://discuss.elastic.co/latest.md?page=450

[Latest](https://discuss.elastic.co/latest.md) · [Categories](https://discuss.elastic.co/categories.md) · [Tags](https://discuss.elastic.co/tags.md)

**Page:** 451

---

## [Dec 19th, 2023: \[EN\] Kibana Lens Color Mapping & Color Palettes](https://discuss.elastic.co/t/dec-19th-2023-en-kibana-lens-color-mapping-color-palettes/347298)

<div class="topic-metadata">

**Author:** [@markov00](https://discuss.elastic.co/u/markov00)\
**Replies:** 0\
**Last updated:** [December 19, 2023, 8:00am UTC](https://discuss.elastic.co/t/dec-19th-2023-en-kibana-lens-color-mapping-color-palettes/347298 "2023-12-19T08:00:07Z")

</div>

Written by @Giovanni\_Magni and @markov00 The possibility to customize colors in charts simply and intuitively has been a feature requested for a long time. Given its complexity, it required some time to fully underst…

---

## [Create an alert set at specific time of the day](https://discuss.elastic.co/t/create-an-alert-set-at-specific-time-of-the-day/337280)

<div class="topic-metadata">

**Author:** [@Gio\_27](https://discuss.elastic.co/u/Gio_27)\
**Replies:** 1\
**Last updated:** [December 19, 2023, 1:06pm UTC](https://discuss.elastic.co/t/create-an-alert-set-at-specific-time-of-the-day/337280 "2023-12-19T13:06:25Z")

</div>

Goodmorning y'all! I'm finding myself in front of a issue which regards the timestamp field. The idea is to create an alert which would trigger whenever an admin user (or a user with particular access privileges) log o…

---

## [About Logstash configuration using ssl](https://discuss.elastic.co/t/about-logstash-configuration-using-ssl/349628)

<div class="topic-metadata">

**Author:** [@Hamada](https://discuss.elastic.co/u/Hamada)\
**Replies:** 1\
**Last updated:** [December 19, 2023, 12:59pm UTC](https://discuss.elastic.co/t/about-logstash-configuration-using-ssl/349628 "2023-12-19T12:59:12Z")

</div>

I have a question regarding Logstash configuration. In order to connect to Elasticsearch from Logstash, enter the following into the Logstash configuration and execute. == output{ elasticsearch { hosts =\> \["https://…

---

## [I configure rsyslog for my linux server now I want to send logs to LOGSTASH. How could I achieve that](https://discuss.elastic.co/t/i-configure-rsyslog-for-my-linux-server-now-i-want-to-send-logs-to-logstash-how-could-i-achieve-that/349566)

<div class="topic-metadata">

**Author:** [@Subrato1](https://discuss.elastic.co/u/Subrato1)\
**Replies:** 4\
**Last updated:** [December 19, 2023, 12:52pm UTC](https://discuss.elastic.co/t/i-configure-rsyslog-for-my-linux-server-now-i-want-to-send-logs-to-logstash-how-could-i-achieve-that/349566 "2023-12-19T12:52:08Z")

</div>

Below is my rsyslog conf. My audit logs are generating in syslogs only.

---

## [Logstash split log base on space and =](https://discuss.elastic.co/t/logstash-split-log-base-on-space-and/348526)

<div class="topic-metadata">

**Author:** [@sahere37](https://discuss.elastic.co/u/sahere37)\
**Replies:** 2\
**Last updated:** [December 19, 2023, 11:51am UTC](https://discuss.elastic.co/t/logstash-split-log-base-on-space-and/348526 "2023-12-19T11:51:39Z")

</div>

I want to separate below log in Logstash, I know that we can do it by grok filter, but is there any way to do it without grok? Log: date=2023-12-04 time=11:26:01 my\_id=5646875 dir="D" type=ML severety=info mtype="my lo…

---

## [Manually capturing database statement](https://discuss.elastic.co/t/manually-capturing-database-statement/349593)

<div class="topic-metadata">

**Author:** [@georgms](https://discuss.elastic.co/u/georgms)\
**Replies:** 1\
**Last updated:** [December 19, 2023, 10:56am UTC](https://discuss.elastic.co/t/manually-capturing-database-statement/349593 "2023-12-19T10:56:29Z")

</div>

The Elastic Java agent is able to automatically capture "database" statement e.g. when firing a request to Elastic Search: This happens in the Elastic Java agent instrumentation using the span.db.statement field. The…

---

## [Discovery-EC2 - master not discovered yet, this node has not previously joined a bootstrapped cluster, and \[cluster.initial\_master\_nodes\] is empty on this node: have discovered](https://discuss.elastic.co/t/discovery-ec2-master-not-discovered-yet-this-node-has-not-previously-joined-a-bootstrapped-cluster-and-cluster-initial-master-nodes-is-empty-on-this-node-have-discovered/349493)

<div class="topic-metadata">

**Author:** [@lakshmikandan](https://discuss.elastic.co/u/lakshmikandan)\
**Replies:** 4\
**Last updated:** [December 19, 2023, 10:15am UTC](https://discuss.elastic.co/t/discovery-ec2-master-not-discovered-yet-this-node-has-not-previously-joined-a-bootstrapped-cluster-and-cluster-initial-master-nodes-is-empty-on-this-node-have-discovered/349493 "2023-12-19T10:15:30Z")

</div>

Version: 8.11.0, Build: rpm/d9ec3fa628c7b0ba3d25692e277ba26814820b20/2023-11-04T10:04:57.184859352Z, JVM: 21.0.1 \[WARN \]\[o.e.c.c.ClusterFormationFailureHelper\] \[ip-10-10-10-1.us-west-2.compute.internal\] master not disco…

---

## [Elasticsearch deployment with 5 nodes](https://discuss.elastic.co/t/elasticsearch-deployment-with-5-nodes/349639)

<div class="topic-metadata">

**Author:** [@vapetri](https://discuss.elastic.co/u/vapetri)\
**Replies:** 0\
**Last updated:** [December 19, 2023, 9:39am UTC](https://discuss.elastic.co/t/elasticsearch-deployment-with-5-nodes/349639 "2023-12-19T09:39:19Z")

</div>

Hi, i am trying to deploy a test elasticsearch cluster on a 5 worker nodes kubernetes cluster. I am using 2 storage classes, one for data and for snapshot repositories as below. --- apiVersion: elasticsearch.k8s.elasti…

---

## [Monitoring new users on Linux with Auditbeat](https://discuss.elastic.co/t/monitoring-new-users-on-linux-with-auditbeat/348647)

<div class="topic-metadata">

**Author:** [@DominikStejskal](https://discuss.elastic.co/u/DominikStejskal)\
**Replies:** 1\
**Last updated:** [December 19, 2023, 9:42am UTC](https://discuss.elastic.co/t/monitoring-new-users-on-linux-with-auditbeat/348647 "2023-12-19T09:42:45Z")

</div>

Hello, we are trying to monitor the creation of new user accounts on Linux machines with Auditbeat (7.17). We would like to know the names of the newly created users. Creating a new user shows up in Kibana as an event f…

---

## [Elasticsearch APM Missing Alerts](https://discuss.elastic.co/t/elasticsearch-apm-missing-alerts/349268)

<div class="topic-metadata">

**Author:** [@Shameek\_Agarwal](https://discuss.elastic.co/u/Shameek_Agarwal)\
**Replies:** 3\
**Last updated:** [December 19, 2023, 9:30am UTC](https://discuss.elastic.co/t/elasticsearch-apm-missing-alerts/349268 "2023-12-19T09:30:58Z")

</div>

hi all, really liking apm so far! so basically, i am doing via opentelemetry (logs + traces only for now) now, i want to alert for e.g. by email whenever any error occurs e.g. if traces / logs from opentelemetry obser…

---

## [Kibana is unable to display metrics on kibana discover tab](https://discuss.elastic.co/t/kibana-is-unable-to-display-metrics-on-kibana-discover-tab/349637)

<div class="topic-metadata">

**Author:** [@skumarya](https://discuss.elastic.co/u/skumarya)\
**Replies:** 0\
**Last updated:** [December 19, 2023, 9:04am UTC](https://discuss.elastic.co/t/kibana-is-unable-to-display-metrics-on-kibana-discover-tab/349637 "2023-12-19T09:04:46Z")

</div>

we were using 7.16 elasticsearch,kibana and filebeat verison earlier which used to scrap metrics and displayed in the kibana discover tab but when upgraded to 8.8.0 it doesn't display elastic,kibana and filebeat yaml fi…

---

## [./bin/kibana-keystore add elastic.apm.secretToken does nothing](https://discuss.elastic.co/t/bin-kibana-keystore-add-elastic-apm-secrettoken-does-nothing/349577)

<div class="topic-metadata">

**Author:** [@learningelastic](https://discuss.elastic.co/u/learningelastic)\
**Replies:** 0\
**Last updated:** [December 18, 2023, 4:06pm UTC](https://discuss.elastic.co/t/bin-kibana-keystore-add-elastic-apm-secrettoken-does-nothing/349577 "2023-12-18T16:06:47Z")

</div>

I can't seem to get the ./bin/kibana-keystore to work for the field elastic.apm.secretToken. I started by making sure Kibana can work with APM. This kibana.yml file works perfectly: elastic: apm: active: true …

---

## [Can I use PHP Elasitcsearch client version 8 for Elasticsearch cluster version 7](https://discuss.elastic.co/t/can-i-use-php-elasitcsearch-client-version-8-for-elasticsearch-cluster-version-7/349631)

<div class="topic-metadata">

**Author:** [@yoss\_fazwaz](https://discuss.elastic.co/u/yoss_fazwaz)\
**Replies:** 0\
**Last updated:** [December 19, 2023, 8:04am UTC](https://discuss.elastic.co/t/can-i-use-php-elasitcsearch-client-version-8-for-elasticsearch-cluster-version-7/349631 "2023-12-19T08:04:43Z")

</div>

I am currently using Elasticsearch cluster version 7.17.7 and Elasticsearch client version 7.17.1. However, I want to upgrade the Elasticsearch client to version 8.11. Will Elasticsearch client version 8.11 function pro…

---

## [How should I configure TLS?](https://discuss.elastic.co/t/how-should-i-configure-tls/349431)

<div class="topic-metadata">

**Author:** [@Hamada](https://discuss.elastic.co/u/Hamada)\
**Replies:** 3\
**Last updated:** [December 19, 2023, 7:14am UTC](https://discuss.elastic.co/t/how-should-i-configure-tls/349431 "2023-12-19T07:14:02Z")

</div>

I don't know how to set up a certificate to connect Winlogbeat to Elasticsearch via https. What should I do to create a PEM file from the CA (http.p12) created at initial startup? I don't understand what is required in…

---

## [Filebeat stops pusing the logs to logstash](https://discuss.elastic.co/t/filebeat-stops-pusing-the-logs-to-logstash/349627)

<div class="topic-metadata">

**Author:** [@sudhir\_singh](https://discuss.elastic.co/u/sudhir_singh)\
**Replies:** 0\
**Last updated:** [December 19, 2023, 7:03am UTC](https://discuss.elastic.co/t/filebeat-stops-pusing-the-logs-to-logstash/349627 "2023-12-19T07:03:28Z")

</div>

/// I'm pushing windows DHCP logs to linux logstash it sends the logs but after sometime it stops sending the logs again when I delete the registry file start with filebeat -e -c filebeat.yml It starts sending logs but …

---

## [\[2023-12-19T02:08:38,809\]\[ERROR\]\[i.n.u.c.D.rejectedExecution\] \[data\_node4\] Failed to submit a listener notification task. Event loop shut down? java.util.concurrent.RejectedExecutionException: event executor terminated](https://discuss.elastic.co/t/2023-12-19t0238-809-error-i-n-u-c-d-rejectedexecution-data-node4-failed-to-submit-a-listener-notification-task-event-loop-shut-down-java-util-concurrent-rejectedexecutionexception-event-executor-terminated/349620)

<div class="topic-metadata">

**Author:** [@Kelvin\_A\_Escobar\_Mor](https://discuss.elastic.co/u/Kelvin_A_Escobar_Mor)\
**Replies:** 0\
**Last updated:** [December 19, 2023, 6:15am UTC](https://discuss.elastic.co/t/2023-12-19t0238-809-error-i-n-u-c-d-rejectedexecution-data-node4-failed-to-submit-a-listener-notification-task-event-loop-shut-down-java-util-concurrent-rejectedexecutionexception-event-executor-terminated/349620 "2023-12-19T06:15:39Z")

</div>

\[2023-12-19T02:08:38,809\]\[ERROR\]\[i.n.u.c.D.rejectedExecution\] \[data\_node4\] Failed to submit a listener notification task. Event loop shut down? java.util.concurrent.RejectedExecutionException: event executor terminated …

---

## [How to mock handlers for elastic search client v8.11.0](https://discuss.elastic.co/t/how-to-mock-handlers-for-elastic-search-client-v8-11-0/349614)

<div class="topic-metadata">

**Author:** [@yoss\_fazwaz](https://discuss.elastic.co/u/yoss_fazwaz)\
**Replies:** 1\
**Last updated:** [December 19, 2023, 5:30am UTC](https://discuss.elastic.co/t/how-to-mock-handlers-for-elastic-search-client-v8-11-0/349614 "2023-12-19T05:30:56Z")

</div>

Hi, guys, I have updated my Elasticsearch client from V7 to V8, and it seems that the setHandler is removed. I have no idea how to set it in version 8.

---

## [Multiple unrelated databases using same service name resulting in inaccurate service map](https://discuss.elastic.co/t/multiple-unrelated-databases-using-same-service-name-resulting-in-inaccurate-service-map/348240)

<div class="topic-metadata">

**Author:** [@craigandrews](https://discuss.elastic.co/u/craigandrews)\
**Replies:** 0\
**Last updated:** [November 29, 2023, 2:34pm UTC](https://discuss.elastic.co/t/multiple-unrelated-databases-using-same-service-name-resulting-in-inaccurate-service-map/348240 "2023-11-29T14:34:24Z")

</div>

I have a bunch of completely different, unrelated Java/Spring applications running on a cloud provider. Each application has its own service name so I can differentiate them in Elastic. Each application uses its own data…

---

## [Dissect in logstash and tabs](https://discuss.elastic.co/t/dissect-in-logstash-and-tabs/349595)

<div class="topic-metadata">

**Author:** [@astateofmind](https://discuss.elastic.co/u/astateofmind)\
**Replies:** 3\
**Last updated:** [December 19, 2023, 2:29am UTC](https://discuss.elastic.co/t/dissect-in-logstash-and-tabs/349595 "2023-12-19T02:29:56Z")

</div>

Trying to use dissect to add log.level field to some beats. Using filebeat to send the data and some logs have their fields separated by tabs instead of spaces. The logs with space work ok with this filter: "%{} %{log…

---

## [Kibana 5601 port protocol & cipher can't detected](https://discuss.elastic.co/t/kibana-5601-port-protocol-cipher-cant-detected/349613)

<div class="topic-metadata">

**Author:** [@Septianingrum.17](https://discuss.elastic.co/u/Septianingrum.17)\
**Replies:** 1\
**Last updated:** [December 19, 2023, 3:39am UTC](https://discuss.elastic.co/t/kibana-5601-port-protocol-cipher-cant-detected/349613 "2023-12-19T03:39:00Z")

</div>

I just did a vulnerability scan and got the issue "SSH in Elastic server CBC Mode Ciphers Enabled" this vulnerability was detected on the Kibana server. I have changed the server.ssl.cipherSuites and server.ssl.supporte…

---

## [Elasticsearch Input on Logstash](https://discuss.elastic.co/t/elasticsearch-input-on-logstash/349609)

<div class="topic-metadata">

**Author:** [@Leonadius](https://discuss.elastic.co/u/Leonadius)\
**Replies:** 0\
**Last updated:** [December 19, 2023, 3:04am UTC](https://discuss.elastic.co/t/elasticsearch-input-on-logstash/349609 "2023-12-19T03:04:23Z")

</div>

Dear Elastic Team, I have a case where i need to sync all of the documents from 1 index to another elastic cluster with near real-time. I'm thinking using logstash elasticsearch input to read all of the documents conti…

---

## [Should I deploy elasticsearch in docker on one machine?](https://discuss.elastic.co/t/should-i-deploy-elasticsearch-in-docker-on-one-machine/349115)

<div class="topic-metadata">

**Author:** [@sigmastar](https://discuss.elastic.co/u/sigmastar)\
**Replies:** 13\
**Last updated:** [December 19, 2023, 2:06am UTC](https://discuss.elastic.co/t/should-i-deploy-elasticsearch-in-docker-on-one-machine/349115 "2023-12-19T02:06:57Z")

</div>

I wanna achive the best performance for Elasticsearch on a single machine. But right now, I'm running three Elasticsearch instance in docker on only one machine. Shoud I keep this for better performance or I should deplo…

---

## [Issue in Advanced Sync Rules for JOIN Query](https://discuss.elastic.co/t/issue-in-advanced-sync-rules-for-join-query/349605)

<div class="topic-metadata">

**Author:** [@aisyaharifin](https://discuss.elastic.co/u/aisyaharifin)\
**Replies:** 0\
**Last updated:** [December 19, 2023, 1:47am UTC](https://discuss.elastic.co/t/issue-in-advanced-sync-rules-for-join-query/349605 "2023-12-19T01:47:12Z")

</div>

Hi Elastic, I have a question to ask where I've encountered issue with the Advanced Sync Rules Query : So I have an application lets call it myStaff, where I've been pulling multiple tables from the db using Microso…

---

## [Search UI Integration with Workplace Search](https://discuss.elastic.co/t/search-ui-integration-with-workplace-search/349428)

<div class="topic-metadata">

**Author:** [@aisyaharifin](https://discuss.elastic.co/u/aisyaharifin)\
**Replies:** 2\
**Last updated:** [December 19, 2023, 1:28am UTC](https://discuss.elastic.co/t/search-ui-integration-with-workplace-search/349428 "2023-12-19T01:28:25Z")

</div>

Hi Elastic, I want to ask does Search UI in App Search able to connect to Workplace Search? The reason is because would like to have one platform where App Search and Workplace Search under one Search UI. Would like t…

---

## [Validation Failed: 1: this action would add \[8\] total shards, but this cluster currently has \[3997\]/\[4000\] maximum shards open](https://discuss.elastic.co/t/validation-failed-1-this-action-would-add-8-total-shards-but-this-cluster-currently-has-3997-4000-maximum-shards-open/349527)

<div class="topic-metadata">

**Author:** [@HyebinHong](https://discuss.elastic.co/u/HyebinHong)\
**Replies:** 5\
**Last updated:** [December 18, 2023, 11:12pm UTC](https://discuss.elastic.co/t/validation-failed-1-this-action-would-add-8-total-shards-but-this-cluster-currently-has-3997-4000-maximum-shards-open/349527 "2023-12-18T23:12:26Z")

</div>

Hello, Elastic! I'm facing the trouble while indexing data. I run both ES 8.11 and OpenSearch 2.11 but both have same issues. Please help me. I found out my shards had reached the maximum(1000 shards per nodes). My da…

---

## [Secure ELK Stack with cloudflare wildcard SSL Failing on an ubuntu setup](https://discuss.elastic.co/t/secure-elk-stack-with-cloudflare-wildcard-ssl-failing-on-an-ubuntu-setup/349597)

<div class="topic-metadata">

**Author:** [@gurungo\_lovemore](https://discuss.elastic.co/u/gurungo_lovemore)\
**Replies:** 0\
**Last updated:** [December 18, 2023, 8:58pm UTC](https://discuss.elastic.co/t/secure-elk-stack-with-cloudflare-wildcard-ssl-failing-on-an-ubuntu-setup/349597 "2023-12-18T20:58:57Z")

</div>

I have a cloudflare wildcard ssl for my organization that i have configured on my elasticsearch and Kibana as follows: ''''''''' Elasticsearch # Enable security features xpack.security.enabled: true xpack.security.en…

---

## [Keystore for secrets in elastic-agent.yml](https://discuss.elastic.co/t/keystore-for-secrets-in-elastic-agent-yml/349525)

<div class="topic-metadata">

**Author:** [@learningelastic](https://discuss.elastic.co/u/learningelastic)\
**Replies:** 9\
**Last updated:** [December 18, 2023, 10:59pm UTC](https://discuss.elastic.co/t/keystore-for-secrets-in-elastic-agent-yml/349525 "2023-12-18T22:59:58Z")

</div>

I have some secret values in my ./elastic-agent.yml file. I was hoping to use a keystore to help manage those secrets. I tried this command ./elastic-agent keystore add outputs.default.password, but it gave the error E…

---

## [Issue while running a pipeline](https://discuss.elastic.co/t/issue-while-running-a-pipeline/347650)

<div class="topic-metadata">

**Author:** [@Manasa4](https://discuss.elastic.co/u/Manasa4)\
**Replies:** 1\
**Last updated:** [December 18, 2023, 10:34pm UTC](https://discuss.elastic.co/t/issue-while-running-a-pipeline/347650 "2023-12-18T22:34:50Z")

</div>

Hi Team, I'm trying to run elser and ner pipelines through the reindexing and I'm having the following error : pipeline with id \[elser\_pipeline\_peopleagg\] could not be loaded, caused by \[org.elasticsearch.Elasticsearch…

---

## [Enrich table size](https://discuss.elastic.co/t/enrich-table-size/349600)

<div class="topic-metadata">

**Author:** [@lkw](https://discuss.elastic.co/u/lkw)\
**Replies:** 1\
**Last updated:** [December 18, 2023, 10:33pm UTC](https://discuss.elastic.co/t/enrich-table-size/349600 "2023-12-18T22:33:32Z")

</div>

I am ingesting time-series data and want to enrich it. But my enrich table could be quite large. Are there any rules of thumb regarding the size an index used for enrich in an ingress pipeline can be? Is 10k documents …

---

## [ES 8.8.2 high query latency](https://discuss.elastic.co/t/es-8-8-2-high-query-latency/349191)

<div class="topic-metadata">

**Author:** [@darshanypatel](https://discuss.elastic.co/u/darshanypatel)\
**Replies:** 3\
**Last updated:** [December 18, 2023, 10:19pm UTC](https://discuss.elastic.co/t/es-8-8-2-high-query-latency/349191 "2023-12-18T22:19:42Z")

</div>

I am encountering degraded query latency in v8. We are upgrading our cluster from 7.16.2 to 8.8.2 by standing up a new duplicate cluster with the new version and reindexing the data to it. The latency is 500ms to several…

[Previous page](https://discuss.elastic.co/latest.md?page=449)

[Next page](https://discuss.elastic.co/latest.md?page=451)
