# Latest

**URL:** https://discuss.elastic.co/latest.md?page=456

[Latest](https://discuss.elastic.co/latest.md) · [Categories](https://discuss.elastic.co/categories.md) · [Tags](https://discuss.elastic.co/tags.md)

**Page:** 457

---

## [Filebeat-god is stopped](https://discuss.elastic.co/t/filebeat-god-is-stopped/349153)

<div class="topic-metadata">

**Author:** [@Mursel](https://discuss.elastic.co/u/Mursel)\
**Replies:** 3\
**Last updated:** [December 13, 2023, 6:07am UTC](https://discuss.elastic.co/t/filebeat-god-is-stopped/349153 "2023-12-13T06:07:42Z")

</div>

I have installed wazuh in docker. After users count reached 100 filebeat has stopped. service filebeat start Failed to get D-Bus connection: Operation not permitted Starting filebeat: 2023-12-12T13:18:58.565Z INFO …

---

## [How to add day of month field but with certain timezone](https://discuss.elastic.co/t/how-to-add-day-of-month-field-but-with-certain-timezone/349207)

<div class="topic-metadata">

**Author:** [@yuswanul](https://discuss.elastic.co/u/yuswanul)\
**Replies:** 5\
**Last updated:** [December 13, 2023, 4:42am UTC](https://discuss.elastic.co/t/how-to-add-day-of-month-field-but-with-certain-timezone/349207 "2023-12-13T04:42:18Z")

</div>

i want to create a "day of month" field for my visualization. I already did this using a scripted field before. but since I chose Grafana to visualize my data, I can't use that scripted field there. so I want to generate…

---

## [Multiple hosts in one Java Rest Client with different API Keys](https://discuss.elastic.co/t/multiple-hosts-in-one-java-rest-client-with-different-api-keys/349069)

<div class="topic-metadata">

**Author:** [@aliaksei\_dev](https://discuss.elastic.co/u/aliaksei_dev)\
**Replies:** 1\
**Last updated:** [December 12, 2023, 1:33pm UTC](https://discuss.elastic.co/t/multiple-hosts-in-one-java-rest-client-with-different-api-keys/349069 "2023-12-12T13:33:04Z")

</div>

Hi, having trouble with implementing Java Rest Client v.7.17 - the requirement is to use multiple hosts with one client. At the same time our elastic uses Api Keys with header "Authorization" to authorize. So my question…

---

## [Elasticsearch/Kibana Fleet and APM via Docker Compose](https://discuss.elastic.co/t/elasticsearch-kibana-fleet-and-apm-via-docker-compose/349204)

<div class="topic-metadata">

**Author:** [@michael.brizic](https://discuss.elastic.co/u/michael.brizic)\
**Replies:** 0\
**Last updated:** [December 13, 2023, 1:31am UTC](https://discuss.elastic.co/t/elasticsearch-kibana-fleet-and-apm-via-docker-compose/349204 "2023-12-13T01:31:36Z")

</div>

Hi, I'm attempting to run the Elasticsearch/Kibana stack along with elastic-agent as a Fleet Server and APM Server via Docker Compose in order that I may have a complete local development setup that I can spin up and do…

---

## [Need help to create a grok patter for my syslog pattern](https://discuss.elastic.co/t/need-help-to-create-a-grok-patter-for-my-syslog-pattern/349103)

<div class="topic-metadata">

**Author:** [@ameeto17](https://discuss.elastic.co/u/ameeto17)\
**Replies:** 2\
**Last updated:** [December 12, 2023, 10:17pm UTC](https://discuss.elastic.co/t/need-help-to-create-a-grok-patter-for-my-syslog-pattern/349103 "2023-12-12T22:17:28Z")

</div>

my log message looks like this message Dec 12 12:01:27 ppdtest302 test-checker: Context SHA of TEST Software Version 3.0.1\_RC5 0b1f71223180bf0df9330b13e17f8d7c62dfdaad16b97a80b8a25c99409c1109 How do i use a grok patte…

---

## [Fielddata is disabled on \[host.name\] in \[metricbeat-8.10.3\]](https://discuss.elastic.co/t/fielddata-is-disabled-on-host-name-in-metricbeat-8-10-3/348261)

<div class="topic-metadata">

**Author:** [@efrainMZ](https://discuss.elastic.co/u/efrainMZ)\
**Replies:** 8\
**Last updated:** [December 12, 2023, 9:03pm UTC](https://discuss.elastic.co/t/fielddata-is-disabled-on-host-name-in-metricbeat-8-10-3/348261 "2023-12-12T21:03:10Z")

</div>

Hello good morning! I am ingesting data from metricbeat to elasticsearch and loading the dashboards of version metricbeat 8.10.3 with the command "./metricbeat setup --dashboard" but when viewing the dashboards it shows…

---

## [Apm .net capturing outgoing http request body](https://discuss.elastic.co/t/apm-net-capturing-outgoing-http-request-body/348921)

<div class="topic-metadata">

**Author:** [@Nicolas\_Rey](https://discuss.elastic.co/u/Nicolas_Rey)\
**Replies:** 5\
**Last updated:** [December 12, 2023, 8:55pm UTC](https://discuss.elastic.co/t/apm-net-capturing-outgoing-http-request-body/348921 "2023-12-12T20:55:00Z")

</div>

Hi, I'm using the 1.25.0 version of .net apm agent, and I wonder how I can capture the body of the outgoing requests (Post, Patch ...) that are performed within an Apm transaction? What are the guidelines to do it prop…

---

## [Date\_histogram: Unknown time-zone ID: Europe/Kyiv](https://discuss.elastic.co/t/date-histogram-unknown-time-zone-id-europe-kyiv/349188)

<div class="topic-metadata">

**Author:** [@Inbal](https://discuss.elastic.co/u/Inbal)\
**Replies:** 9\
**Last updated:** [December 12, 2023, 8:15pm UTC](https://discuss.elastic.co/t/date-histogram-unknown-time-zone-id-europe-kyiv/349188 "2023-12-12T20:15:57Z")

</div>

Hey, I have a es search with aggregations which contains date\_histogram with time\_zone parameter. When I'm choosing "Europe/Kyiv" as time\_zone I'm getting the following error reason: "Unknown time-zone ID: Europe/Kyiv"…

---

## [Need help about starting logstash-8.11.2](https://discuss.elastic.co/t/need-help-about-starting-logstash-8-11-2/349125)

<div class="topic-metadata">

**Author:** [@AlexLWei](https://discuss.elastic.co/u/AlexLWei)\
**Replies:** 13\
**Last updated:** [December 12, 2023, 8:12pm UTC](https://discuss.elastic.co/t/need-help-about-starting-logstash-8-11-2/349125 "2023-12-12T20:12:08Z")

</div>

I installed Logstash by downloading and unzipping the zip file from the official website and it occurs an error about JDK , Using bundled JDK: /opt/logstash-8.11.2/jdk Unrecognized VM option 'UseConcMarkSweepGC' Erro…

---

## [Elasticsearch first time run hangs adding index template](https://discuss.elastic.co/t/elasticsearch-first-time-run-hangs-adding-index-template/349169)

<div class="topic-metadata">

**Author:** [@MColeman](https://discuss.elastic.co/u/MColeman)\
**Replies:** 15\
**Last updated:** [December 12, 2023, 7:49pm UTC](https://discuss.elastic.co/t/elasticsearch-first-time-run-hangs-adding-index-template/349169 "2023-12-12T19:49:47Z")

</div>

Hi, Using the unzip install method. Unzip, run elasticsearch.bat and it seems to be hanging at \[o.e.c.m.MetadataIndexTemplateService\] adding index template \[logs\] for index patterns \[logs--\] for hours. I was expecting t…

---

## [Can I include Environment Variables in config.yml for Elastic Serverless Forwarder?](https://discuss.elastic.co/t/can-i-include-environment-variables-in-config-yml-for-elastic-serverless-forwarder/349187)

<div class="topic-metadata">

**Author:** [@DougR](https://discuss.elastic.co/u/DougR)\
**Replies:** 0\
**Last updated:** [December 12, 2023, 6:36pm UTC](https://discuss.elastic.co/t/can-i-include-environment-variables-in-config-yml-for-elastic-serverless-forwarder/349187 "2023-12-12T18:36:08Z")

</div>

Please forgive me if this is tagged wrong, it was the closest I could find to "Elastic Stack-\>Elastic Serverless Forwarder," which is what I want. I have what should be a fairly easy question. With both beats and Elast…

---

## [Subqueries in Kibana Discover screen](https://discuss.elastic.co/t/subqueries-in-kibana-discover-screen/348931)

<div class="topic-metadata">

**Author:** [@ton1uwu](https://discuss.elastic.co/u/ton1uwu)\
**Replies:** 1\
**Last updated:** [December 12, 2023, 6:24pm UTC](https://discuss.elastic.co/t/subqueries-in-kibana-discover-screen/348931 "2023-12-12T18:24:27Z")

</div>

I need to query data based on some other record timestamp, I have a log with requests and responses from a service, but i don't really have a way to know which response is for which request besides the endpoint and the t…

---

## [Beats and Elastic Agent 8.11.3 / 7.17.16 Security Update (ESA-2023-30)](https://discuss.elastic.co/t/beats-and-elastic-agent-8-11-3-7-17-16-security-update-esa-2023-30/349180)

<div class="topic-metadata">

**Author:** [@ismisepaul](https://discuss.elastic.co/u/ismisepaul)\
**Replies:** 0\
**Last updated:** [December 12, 2023, 5:00pm UTC](https://discuss.elastic.co/t/beats-and-elastic-agent-8-11-3-7-17-16-security-update-esa-2023-30/349180 "2023-12-12T17:00:31Z")

</div>

Beats and Elastic Agent Insertion of Sensitive Information into Log File An issue was discovered by Elastic whereby Beats and Elastic Agent would log a raw event in its own logs at the WARN or ERROR level if ingesting th…

---

## [MatchAllQuery is slow once segment size exceeds 1](https://discuss.elastic.co/t/matchallquery-is-slow-once-segment-size-exceeds-1/349095)

<div class="topic-metadata">

**Author:** [@jwSmith1](https://discuss.elastic.co/u/jwSmith1)\
**Replies:** 5\
**Last updated:** [December 12, 2023, 6:04pm UTC](https://discuss.elastic.co/t/matchallquery-is-slow-once-segment-size-exceeds-1/349095 "2023-12-12T18:04:14Z")

</div>

Hi, I'm managing an extra-small index and had some issues with the latency. The index has ~4000 documents (25mb in total) 1 shard low index and search traffic I need to periodically fetch all of the documents from th…

---

## [Cannot read properties of undefined (reading 'split')](https://discuss.elastic.co/t/cannot-read-properties-of-undefined-reading-split/349034)

<div class="topic-metadata">

**Author:** [@Huzefa](https://discuss.elastic.co/u/Huzefa)\
**Replies:** 0\
**Last updated:** [December 11, 2023, 11:16am UTC](https://discuss.elastic.co/t/cannot-read-properties-of-undefined-reading-split/349034 "2023-12-11T11:16:17Z")

</div>

I am currently encountering an issue in Kibana related to "Cannot read properties of undefined (reading 'split')" when attempting to upgrade agent policies or view agent policies. The occurrence of this error was noted a…

---

## [Create visualization for sum of system.cpu.cores per host](https://discuss.elastic.co/t/create-visualization-for-sum-of-system-cpu-cores-per-host/348595)

<div class="topic-metadata">

**Author:** [@lpowers](https://discuss.elastic.co/u/lpowers)\
**Replies:** 7\
**Last updated:** [December 12, 2023, 5:23pm UTC](https://discuss.elastic.co/t/create-visualization-for-sum-of-system-cpu-cores-per-host/348595 "2023-12-12T17:23:46Z")

</div>

I'm trying to create a visualization for the total cores for each host and then sum them all up to get a count for each of our clusters. Is it possible?

---

## [Kibana 8.11.2, 7.17.16 Security Update (ESA-2023-27)](https://discuss.elastic.co/t/kibana-8-11-2-7-17-16-security-update-esa-2023-27/349182)

<div class="topic-metadata">

**Author:** [@ikakavas](https://discuss.elastic.co/u/ikakavas)\
**Replies:** 0\
**Last updated:** [December 12, 2023, 5:23pm UTC](https://discuss.elastic.co/t/kibana-8-11-2-7-17-16-security-update-esa-2023-27/349182 "2023-12-12T17:23:12Z")

</div>

Kibana Insertion of Sensitive Information into Log File (ESA-2023-27) An issue was discovered by Elastic whereby sensitive information may be recorded in Kibana logs in the event of an error or in the event where debug l…

---

## [Enterprise Search 8.11.2 / 7.17.16 Security Update (ESA-2023-31)](https://discuss.elastic.co/t/enterprise-search-8-11-2-7-17-16-security-update-esa-2023-31/349181)

<div class="topic-metadata">

**Author:** [@rodrigo\_silva](https://discuss.elastic.co/u/rodrigo_silva)\
**Replies:** 0\
**Last updated:** [December 12, 2023, 5:06pm UTC](https://discuss.elastic.co/t/enterprise-search-8-11-2-7-17-16-security-update-esa-2023-31/349181 "2023-12-12T17:06:41Z")

</div>

Enterprise Search Insertion of Sensitive Information into Log File (ESA-2023-31) An issue was discovered by Elastic whereby the Documents API of App Search logged the raw contents of indexed documents at INFO log level. …

---

## [Winlogbeat cannot sent a spécific event windows (level information) to kibana for provider .net runtime](https://discuss.elastic.co/t/winlogbeat-cannot-sent-a-specific-event-windows-level-information-to-kibana-for-provider-net-runtime/348922)

<div class="topic-metadata">

**Author:** [@SAMY-ELK](https://discuss.elastic.co/u/SAMY-ELK)\
**Replies:** 0\
**Last updated:** [December 8, 2023, 4:11pm UTC](https://discuss.elastic.co/t/winlogbeat-cannot-sent-a-specific-event-windows-level-information-to-kibana-for-provider-net-runtime/348922 "2023-12-08T16:11:00Z")

</div>

Hello Team, I noticed that we cannot sent all windows evenement with below description about "information level" with winlogbeat to kibana : " The description of event ID 0 in the .NET Runtime source cannot be found.…

---

## [Display rules in a dashboard](https://discuss.elastic.co/t/display-rules-in-a-dashboard/348671)

<div class="topic-metadata">

**Author:** [@rlao](https://discuss.elastic.co/u/rlao)\
**Replies:** 0\
**Last updated:** [December 5, 2023, 7:21pm UTC](https://discuss.elastic.co/t/display-rules-in-a-dashboard/348671 "2023-12-05T19:21:37Z")

</div>

Trying to find a way for non admin users to be able to see all Kibana rules without being able to edit them. Since the rules are managed as part of the Admin space, and granting access to admin with carefully controlled…

---

## [Elasticsearch 8.11.2, 7.17.16 Security Update (ESA-2023-29)](https://discuss.elastic.co/t/elasticsearch-8-11-2-7-17-16-security-update-esa-2023-29/349179)

<div class="topic-metadata">

**Author:** [@Levine](https://discuss.elastic.co/u/Levine)\
**Replies:** 0\
**Last updated:** [December 12, 2023, 4:57pm UTC](https://discuss.elastic.co/t/elasticsearch-8-11-2-7-17-16-security-update-esa-2023-29/349179 "2023-12-12T16:57:56Z")

</div>

Elasticsearch Insertion of Sensitive Information into Log File (ESA-2023-29) An issue was discovered by Elastic whereby Watcher search input logged the search query results on DEBUG log level. This could lead to raw cont…

---

## [How to create a geoDistance sort search in java with elasticsearch 8.11.0](https://discuss.elastic.co/t/how-to-create-a-geodistance-sort-search-in-java-with-elasticsearch-8-11-0/348983)

<div class="topic-metadata">

**Author:** [@jasin](https://discuss.elastic.co/u/jasin)\
**Replies:** 6\
**Last updated:** [December 12, 2023, 4:40pm UTC](https://discuss.elastic.co/t/how-to-create-a-geodistance-sort-search-in-java-with-elasticsearch-8-11-0/348983 "2023-12-12T16:40:49Z")

</div>

here is my code but the sort doesn't work and throw an error SearchResponse\<HotelDoc\> response = client.search(s -\> s .index("hotel") .query(q -\> q …

---

## [Implement my own Hybrid Search](https://discuss.elastic.co/t/implement-my-own-hybrid-search/349100)

<div class="topic-metadata">

**Author:** [@r1ckC139](https://discuss.elastic.co/u/r1ckC139)\
**Replies:** 1\
**Last updated:** [December 12, 2023, 4:20pm UTC](https://discuss.elastic.co/t/implement-my-own-hybrid-search/349100 "2023-12-12T16:20:36Z")

</div>

Hi team, I've developed a hybrid search algorithm. Initially, I perform a BM25 search, obtaining the top k results (id, score). Subsequently, a k-nearest neighbors (KNN) search is executed, yielding another set of top k…

---

## [F5 load balancer SSL\_ERROR\_SYSCALL, errno 104 with Elasticsearch cluster](https://discuss.elastic.co/t/f5-load-balancer-ssl-error-syscall-errno-104-with-elasticsearch-cluster/349120)

<div class="topic-metadata">

**Author:** [@miksonx](https://discuss.elastic.co/u/miksonx)\
**Replies:** 4\
**Last updated:** [December 12, 2023, 4:14pm UTC](https://discuss.elastic.co/t/f5-load-balancer-ssl-error-syscall-errno-104-with-elasticsearch-cluster/349120 "2023-12-12T16:14:11Z")

</div>

We have configured F5 LB in front of Elasticsearch nodes cluster with re-encrypt of SSL traffic to the nodes. Nodes have SSL enabled on http. Direct communication to nodes i.e. API (curl) or sending data over https on po…

---

## [Handle transactions with large amount of spans](https://discuss.elastic.co/t/handle-transactions-with-large-amount-of-spans/349167)

<div class="topic-metadata">

**Author:** [@fabiend](https://discuss.elastic.co/u/fabiend)\
**Replies:** 0\
**Last updated:** [December 12, 2023, 3:18pm UTC](https://discuss.elastic.co/t/handle-transactions-with-large-amount-of-spans/349167 "2023-12-12T15:18:04Z")

</div>

Hello, I have long running jobs on different services. I instrumented the solution to trace these jobs. They can run for hours and perform a large number of Elasticsearch requests. I would like to know what is going on …

---

## [Palo Alto Next-Gen Firewall compatibility with Global Protect VPN Client](https://discuss.elastic.co/t/palo-alto-next-gen-firewall-compatibility-with-global-protect-vpn-client/349084)

<div class="topic-metadata">

**Author:** [@CodeMonky](https://discuss.elastic.co/u/CodeMonky)\
**Replies:** 5\
**Last updated:** [December 12, 2023, 2:52pm UTC](https://discuss.elastic.co/t/palo-alto-next-gen-firewall-compatibility-with-global-protect-vpn-client/349084 "2023-12-12T14:52:15Z")

</div>

Good day all! I'm looking for confirmation on the features of the Palo Alto Next-Gen Firewall integration with elastic. On the overview page of the integration, it details support of the Global Protect type of message. …

---

## [License Platinum Subscription 64 GB only for node?](https://discuss.elastic.co/t/license-platinum-subscription-64-gb-only-for-node/348422)

<div class="topic-metadata">

**Author:** [@Rossella\_Palmisano](https://discuss.elastic.co/u/Rossella_Palmisano)\
**Replies:** 7\
**Last updated:** [December 12, 2023, 2:28pm UTC](https://discuss.elastic.co/t/license-platinum-subscription-64-gb-only-for-node/348422 "2023-12-12T14:28:09Z")

</div>

For the calculation of elastic platinum licenses should only nodes count or should I also consider the GB RAM per node? Which nodes need to be licensed? I have both master nodes and worker nodes.

---

## [Is Vega performance good on large dataset?](https://discuss.elastic.co/t/is-vega-performance-good-on-large-dataset/348713)

<div class="topic-metadata">

**Author:** [@Fiza](https://discuss.elastic.co/u/Fiza)\
**Replies:** 6\
**Last updated:** [December 12, 2023, 2:15pm UTC](https://discuss.elastic.co/t/is-vega-performance-good-on-large-dataset/348713 "2023-12-12T14:15:37Z")

</div>

I am working on a large timeseries dataset, around 120000 document approx. I want to know how the performance is of Vega on such large database. Does it take a lot of time to load to show charts and graphs. Or it works a…

---

## [When SearchBox view is used, its blurring out when we type in search term](https://discuss.elastic.co/t/when-searchbox-view-is-used-its-blurring-out-when-we-type-in-search-term/347869)

<div class="topic-metadata">

**Author:** [@shashankhat](https://discuss.elastic.co/u/shashankhat)\
**Replies:** 1\
**Last updated:** [December 12, 2023, 2:09pm UTC](https://discuss.elastic.co/t/when-searchbox-view-is-used-its-blurring-out-when-we-type-in-search-term/347869 "2023-12-12T14:09:16Z")

</div>

When I use SearchBox view, when I type in the value inside input field, its blurring out. Each time I want to type I need to select the input box. It would be very helpful if I get help in solving this issue. Below is …

---

## [Possible bug with sorting dynamically mapped fields](https://discuss.elastic.co/t/possible-bug-with-sorting-dynamically-mapped-fields/349149)

<div class="topic-metadata">

**Author:** [@Evgeni\_Dzhelyov](https://discuss.elastic.co/u/Evgeni_Dzhelyov)\
**Replies:** 0\
**Last updated:** [December 12, 2023, 1:05pm UTC](https://discuss.elastic.co/t/possible-bug-with-sorting-dynamically-mapped-fields/349149 "2023-12-12T13:05:01Z")

</div>

We ingest a lot of custom logs in Elasticsearch. For the application logs we use a custom schema with dynamic mappings, but when sorting for some of the fields we hit a strange bug: Sort by a dext.duration#double field…

[Previous page](https://discuss.elastic.co/latest.md?page=455)

[Next page](https://discuss.elastic.co/latest.md?page=457)
