# Latest

**URL:** https://discuss.elastic.co/latest.md?page=462

[Latest](https://discuss.elastic.co/latest.md) · [Categories](https://discuss.elastic.co/categories.md) · [Tags](https://discuss.elastic.co/tags.md)

**Page:** 463

---

## [No d for data node anymore?](https://discuss.elastic.co/t/no-d-for-data-node-anymore/348736)

<div class="topic-metadata">

**Author:** [@Doc\_Kaos](https://discuss.elastic.co/u/Doc_Kaos)\
**Replies:** 1\
**Last updated:** [December 6, 2023, 7:20pm UTC](https://discuss.elastic.co/t/no-d-for-data-node-anymore/348736 "2023-12-06T19:20:53Z")

</div>

Looking at the documentation cat nodes API | Elasticsearch Guide \[8.11\] | Elastic It appears that a "Hot" node should have roles hd ... but that's not true in real life. Is a hot node not a "data" node? Are 'data\_content…

---

## [Logstash doesn't get logs from other container in Azure container group](https://discuss.elastic.co/t/logstash-doesnt-get-logs-from-other-container-in-azure-container-group/348755)

<div class="topic-metadata">

**Author:** [@TheNewGuy123](https://discuss.elastic.co/u/TheNewGuy123)\
**Replies:** 0\
**Last updated:** [December 6, 2023, 5:50pm UTC](https://discuss.elastic.co/t/logstash-doesnt-get-logs-from-other-container-in-azure-container-group/348755 "2023-12-06T17:50:34Z")

</div>

Hey, I'm trying to debug why my Azure container based Logstash being a side car to my test application that periodically sends out logs with gelf isn't consuming those logs. So both containers (logstash and my app) are h…

---

## [Updating to version 7.17.15 caused the 'Failed to publish events' issue caused connection reset by peer](https://discuss.elastic.co/t/updating-to-version-7-17-15-caused-the-failed-to-publish-events-issue-caused-connection-reset-by-peer/348740)

<div class="topic-metadata">

**Author:** [@Saleh\_Houshangi](https://discuss.elastic.co/u/Saleh_Houshangi)\
**Replies:** 0\
**Last updated:** [December 6, 2023, 4:10pm UTC](https://discuss.elastic.co/t/updating-to-version-7-17-15-caused-the-failed-to-publish-events-issue-caused-connection-reset-by-peer/348740 "2023-12-06T16:10:49Z")

</div>

After updating Elasticsearch and Logstash from version 7.17.5 to 7.17.15, all Filebeat instances sporadically encounter the following error in the log file: caa27ea3-c641-4ad2-9f03-578f008a4013'} 2023-12-06T16:06:56.260…

---

## [Use Logstash for access REST APIs and do complex queries or better Connector Clients](https://discuss.elastic.co/t/use-logstash-for-access-rest-apis-and-do-complex-queries-or-better-connector-clients/348725)

<div class="topic-metadata">

**Author:** [@sebastianboelling](https://discuss.elastic.co/u/sebastianboelling)\
**Replies:** 1\
**Last updated:** [December 6, 2023, 3:47pm UTC](https://discuss.elastic.co/t/use-logstash-for-access-rest-apis-and-do-complex-queries-or-better-connector-clients/348725 "2023-12-06T15:47:55Z")

</div>

Hi anybody, has anybody experiences in using Logstash to gather data from a complex REST/JSON API. The API delivers user specific data similar to OneDrive or SharePoint. That means I have to access the (1) users list a…

---

## [How can set providers.docker.host when deploying elastic-agent via docker?](https://discuss.elastic.co/t/how-can-set-providers-docker-host-when-deploying-elastic-agent-via-docker/348737)

<div class="topic-metadata">

**Author:** [@JohannesKoch](https://discuss.elastic.co/u/JohannesKoch)\
**Replies:** 0\
**Last updated:** [December 6, 2023, 3:45pm UTC](https://discuss.elastic.co/t/how-can-set-providers-docker-host-when-deploying-elastic-agent-via-docker/348737 "2023-12-06T15:45:24Z")

</div>

Hello, I have already setup elasticsearch, kibana and a fleet-server. They are all reachable and do get data from an elastic-agent running inside docker on another host. I don't like the idea of mounting the docker so…

---

## [Failed Snapshot using S3 Repository](https://discuss.elastic.co/t/failed-snapshot-using-s3-repository/348682)

<div class="topic-metadata">

**Author:** [@iTiago](https://discuss.elastic.co/u/iTiago)\
**Replies:** 1\
**Last updated:** [December 6, 2023, 3:13pm UTC](https://discuss.elastic.co/t/failed-snapshot-using-s3-repository/348682 "2023-12-06T15:13:32Z")

</div>

Guys, I am trying to take a snapshot of all my indexes in an S3 repository, I already checked the credentials and so on at the time of creating it and there was no problem, the problem occurs at the time of taking the sn…

---

## [Use logstash to connect VMware vCenter API?](https://discuss.elastic.co/t/use-logstash-to-connect-vmware-vcenter-api/348517)

<div class="topic-metadata">

**Author:** [@pyk346](https://discuss.elastic.co/u/pyk346)\
**Replies:** 7\
**Last updated:** [December 6, 2023, 2:33pm UTC](https://discuss.elastic.co/t/use-logstash-to-connect-vmware-vcenter-api/348517 "2023-12-06T14:33:35Z")

</div>

I'm trying to utilize the elastic logstash to obtain VMware vcenter datacenter metrics via API but failed to connect them. The vCenter version is 8.0.1. I had successfully configured "syslog" as input and recieved logs…

---

## [How to Setup File Integrity Monitoring with winlogbeat-7.3.2](https://discuss.elastic.co/t/how-to-setup-file-integrity-monitoring-with-winlogbeat-7-3-2/348655)

<div class="topic-metadata">

**Author:** [@Disha\_Bodade](https://discuss.elastic.co/u/Disha_Bodade)\
**Replies:** 1\
**Last updated:** [December 6, 2023, 2:40pm UTC](https://discuss.elastic.co/t/how-to-setup-file-integrity-monitoring-with-winlogbeat-7-3-2/348655 "2023-12-06T14:40:39Z")

</div>

Hi Team, I am trying to setup FIM feature using winlogbeat for windows servers. I can see there are ECS fields available ECS fields | Winlogbeat Reference \[7.3\] | Elastic But I don't see any proper configuration to se…

---

## [Event.Module (Auditd) for Auditbeat](https://discuss.elastic.co/t/event-module-auditd-for-auditbeat/348716)

<div class="topic-metadata">

**Author:** [@tagba](https://discuss.elastic.co/u/tagba)\
**Replies:** 2\
**Last updated:** [December 6, 2023, 2:28pm UTC](https://discuss.elastic.co/t/event-module-auditd-for-auditbeat/348716 "2023-12-06T14:28:44Z")

</div>

Am trying to monitor logs in with Auditbeat version 7.4. specifically the auditd module.I have created a yml file to send send the logs to logstash. please how do I extract the time and date of each event in the auditd …

---

## [Missing metrics in Logstash node stats](https://discuss.elastic.co/t/missing-metrics-in-logstash-node-stats/348710)

<div class="topic-metadata">

**Author:** [@ofekinger](https://discuss.elastic.co/u/ofekinger)\
**Replies:** 3\
**Last updated:** [December 6, 2023, 2:20pm UTC](https://discuss.elastic.co/t/missing-metrics-in-logstash-node-stats/348710 "2023-12-06T14:20:08Z")

</div>

Hello everyone, I went over the code for a few Logstash plugins and noticed they had metrics that I can't see when running: curl http://localhost:9600/\_node/stats I'm talking about metrics like: And a few other plac…

---

## [Download Windows Agent from source artifacts.elastic.co](https://discuss.elastic.co/t/download-windows-agent-from-source-artifacts-elastic-co/348654)

<div class="topic-metadata">

**Author:** [@Tybe\_sacha](https://discuss.elastic.co/u/Tybe_sacha)\
**Replies:** 4\
**Last updated:** [December 6, 2023, 2:00pm UTC](https://discuss.elastic.co/t/download-windows-agent-from-source-artifacts-elastic-co/348654 "2023-12-06T14:00:04Z")

</div>

Hi, I'm trying to install the Fleet Server and Windows Agent. Here is text I paste : $ProgressPreference = 'SilentlyContinue' Invoke-WebRequest -Uri https://artifacts.elastic.co/downloads/beats/elastic-agent/elastic-ag…

---

## [JVM very greedy with memory. How do I get it to shrink when possible?](https://discuss.elastic.co/t/jvm-very-greedy-with-memory-how-do-i-get-it-to-shrink-when-possible/348657)

<div class="topic-metadata">

**Author:** [@Vulume](https://discuss.elastic.co/u/Vulume)\
**Replies:** 2\
**Last updated:** [December 6, 2023, 1:57pm UTC](https://discuss.elastic.co/t/jvm-very-greedy-with-memory-how-do-i-get-it-to-shrink-when-possible/348657 "2023-12-06T13:57:37Z")

</div>

I want my JVM to give back memory to the OS if it's not using it. I don't care about performance. When I set -Xms128m -Xmx4g, I see the JVM's memory usage grow while indexing and searching, but it never shrinks again af…

---

## [How to know if the result was due to a fuzzysearch?](https://discuss.elastic.co/t/how-to-know-if-the-result-was-due-to-a-fuzzysearch/348726)

<div class="topic-metadata">

**Author:** [@vidhaat](https://discuss.elastic.co/u/vidhaat)\
**Replies:** 0\
**Last updated:** [December 6, 2023, 1:50pm UTC](https://discuss.elastic.co/t/how-to-know-if-the-result-was-due-to-a-fuzzysearch/348726 "2023-12-06T13:50:34Z")

</div>

I have a query where I get results which may or may not have fuzzy search results. I want to get analytics on what results are the result of fuzzy search. How can this be achieved ? { "query": { "bool": { "f…

---

## [Grok-Debugger API-Endpoint](https://discuss.elastic.co/t/grok-debugger-api-endpoint/348317)

<div class="topic-metadata">

**Author:** [@justin\_sch](https://discuss.elastic.co/u/justin_sch)\
**Replies:** 5\
**Last updated:** [December 6, 2023, 1:01pm UTC](https://discuss.elastic.co/t/grok-debugger-api-endpoint/348317 "2023-12-06T13:01:52Z")

</div>

Hey, I'd like to use the grokdebuggerof the devtools via an api-endpoint. Unfortunally I can't find any documentation of this, is this tool even available via the rest-api?

---

## [Logstash stdout output text as in file](https://discuss.elastic.co/t/logstash-stdout-output-text-as-in-file/348675)

<div class="topic-metadata">

**Author:** [@carter.kovrov](https://discuss.elastic.co/u/carter.kovrov)\
**Replies:** 6\
**Last updated:** [December 6, 2023, 11:48am UTC](https://discuss.elastic.co/t/logstash-stdout-output-text-as-in-file/348675 "2023-12-06T11:48:31Z")

</div>

Hi all Tell me how to display information as in a file without additional fields? For example, there is a file app.log with the contents 12-15-2023 app running... 12-15-2023 app login user test necessary information …

---

## [JDBC Static Filter Plugin - Error handling, how to skip enrichment when Database is down](https://discuss.elastic.co/t/jdbc-static-filter-plugin-error-handling-how-to-skip-enrichment-when-database-is-down/347204)

<div class="topic-metadata">

**Author:** [@tori](https://discuss.elastic.co/u/tori)\
**Replies:** 2\
**Last updated:** [December 6, 2023, 10:40am UTC](https://discuss.elastic.co/t/jdbc-static-filter-plugin-error-handling-how-to-skip-enrichment-when-database-is-down/347204 "2023-12-06T10:40:58Z")

</div>

Hi, We've got logstash fetching some information from a MySQL database for log enrichment via JDBC Static Filter Plugin. The settings work just fine when things are working as expected: ... jdbc\_static { l…

---

## [SWEET32 Vulnerability Remediation for Elastic Fleet](https://discuss.elastic.co/t/sweet32-vulnerability-remediation-for-elastic-fleet/348598)

<div class="topic-metadata">

**Author:** [@jakechoi](https://discuss.elastic.co/u/jakechoi)\
**Replies:** 1\
**Last updated:** [December 6, 2023, 10:28am UTC](https://discuss.elastic.co/t/sweet32-vulnerability-remediation-for-elastic-fleet/348598 "2023-12-06T10:28:39Z")

</div>

Apologies if this is the wrong location to post this topic. I've been troubleshooting a vulnerability found by our Nessus scanner on our Kibana instance. Nessus shows that the port used by our fleet on our Kibana instan…

---

## [ECE frc-\* Container Descriptions](https://discuss.elastic.co/t/ece-frc-container-descriptions/306366)

<div class="topic-metadata">

**Author:** [@rahst12](https://discuss.elastic.co/u/rahst12)\
**Replies:** 1\
**Last updated:** [December 6, 2023, 8:51am UTC](https://discuss.elastic.co/t/ece-frc-container-descriptions/306366 "2023-12-06T08:51:05Z")

</div>

I'm looking for a description of what each of these ECE "default" containers are supposed to be doing on an allocator: frc-container-task-services-container-task-service frc-allocator-metricbeats-allocator-metricbeat f…

---

## [Kibana Azure AD SSO Authentication](https://discuss.elastic.co/t/kibana-azure-ad-sso-authentication/348692)

<div class="topic-metadata">

**Author:** [@Ilter\_Sag](https://discuss.elastic.co/u/Ilter_Sag)\
**Replies:** 1\
**Last updated:** [December 6, 2023, 8:37am UTC](https://discuss.elastic.co/t/kibana-azure-ad-sso-authentication/348692 "2023-12-06T08:37:34Z")

</div>

Hello, I am trying to setup Kibana Authentication with Azure AD SSO and getting this error. What will be the cause of that error? My server has connection to login.microsoftonline.com and can fetch federation xml. Ela…

---

## [Stack Monitoring with Fleet/elastic-agent](https://discuss.elastic.co/t/stack-monitoring-with-fleet-elastic-agent/347244)

<div class="topic-metadata">

**Author:** [@rastro](https://discuss.elastic.co/u/rastro)\
**Replies:** 36\
**Last updated:** [December 6, 2023, 8:25am UTC](https://discuss.elastic.co/t/stack-monitoring-with-fleet-elastic-agent/347244 "2023-12-06T08:25:21Z")

</div>

In Kibana, when you go to Stack Monitoring, it says "No monitoring data found" and suggests using Metricbeat. Except, shouldn't we be using Elastic Agent? So, how can I get the Stack Monitoring page working with Agent?…

---

## [Custom analyzer for search and indexing](https://discuss.elastic.co/t/custom-analyzer-for-search-and-indexing/348661)

<div class="topic-metadata">

**Author:** [@ssanja](https://discuss.elastic.co/u/ssanja)\
**Replies:** 1\
**Last updated:** [December 6, 2023, 6:33am UTC](https://discuss.elastic.co/t/custom-analyzer-for-search-and-indexing/348661 "2023-12-06T06:33:34Z")

</div>

Hello, when creating an index I specifically created a custom analyzer which should be used for indexing and searching (see the example code below) "settings": { "analysis": { "analyzer": { "custom\_…

---

## [Azure AD SSO setting behind a proxy not working](https://discuss.elastic.co/t/azure-ad-sso-setting-behind-a-proxy-not-working/346654)

<div class="topic-metadata">

**Author:** [@Ilter\_Sag](https://discuss.elastic.co/u/Ilter_Sag)\
**Replies:** 5\
**Last updated:** [December 6, 2023, 5:28am UTC](https://discuss.elastic.co/t/azure-ad-sso-setting-behind-a-proxy-not-working/346654 "2023-12-06T05:28:36Z")

</div>

Hello, I am trying to integrate Azure AD to Elasticsearch cluster behind a proxy. I tried the proxy parameter settings below but could not succeeded. You can find the log behind that post. It say it cannot access to mic…

---

## [Using Debug.explain kills data nodes. (8.11.1)](https://discuss.elastic.co/t/using-debug-explain-kills-data-nodes-8-11-1/348690)

<div class="topic-metadata">

**Author:** [@ong-ar](https://discuss.elastic.co/u/ong-ar)\
**Replies:** 1\
**Last updated:** [December 6, 2023, 3:35am UTC](https://discuss.elastic.co/t/using-debug-explain-kills-data-nodes-8-11-1/348690 "2023-12-06T03:35:44Z")

</div>

Elasticsearch Version Version: 8.11.1, Build: rpm/6f9ff581fbcde658e6f69d6ce03050f060d1fd0c/2023-11-11T10:05:59.421038163Z, JVM: 21.0.1 Installed Plugins Java Version openjdk version "21.0.1" OS Version 6.1.61-85.141.…

---

## [How to Implement a Flexible Search Method in Java with Low Level Client to Filter, Sort, and Limit Fields?](https://discuss.elastic.co/t/how-to-implement-a-flexible-search-method-in-java-with-low-level-client-to-filter-sort-and-limit-fields/346253)

<div class="topic-metadata">

**Author:** [@Roman\_Kagan](https://discuss.elastic.co/u/Roman_Kagan)\
**Replies:** 4\
**Last updated:** [December 6, 2023, 2:29am UTC](https://discuss.elastic.co/t/how-to-implement-a-flexible-search-method-in-java-with-low-level-client-to-filter-sort-and-limit-fields/346253 "2023-12-06T02:29:18Z")

</div>

Hello, I'm working on implementing a search method in Java that needs to support several variations of search criteria. Specifically, I need the method to be able to: Search by a term within certain fields, conditiona…

---

## [Fields are not populating from logstash to elastic](https://discuss.elastic.co/t/fields-are-not-populating-from-logstash-to-elastic/348593)

<div class="topic-metadata">

**Author:** [@mmercaldi](https://discuss.elastic.co/u/mmercaldi)\
**Replies:** 10\
**Last updated:** [December 5, 2023, 10:44pm UTC](https://discuss.elastic.co/t/fields-are-not-populating-from-logstash-to-elastic/348593 "2023-12-05T22:44:34Z")

</div>

I am using logstash to populate elastic I have it set so this filter: filter { json { source =\> "message" target =\> "jsoncontent" remove\_field =\> \["message"\] } } and jsoncontent: {"switchname": "swi…

---

## [Accuracy of date histogram sub-aggregation doc count under terms aggregation](https://discuss.elastic.co/t/accuracy-of-date-histogram-sub-aggregation-doc-count-under-terms-aggregation/348685)

<div class="topic-metadata">

**Author:** [@myronmarston](https://discuss.elastic.co/u/myronmarston)\
**Replies:** 0\
**Last updated:** [December 5, 2023, 10:26pm UTC](https://discuss.elastic.co/t/accuracy-of-date-histogram-sub-aggregation-doc-count-under-terms-aggregation/348685 "2023-12-05T22:26:57Z")

</div>

Hello, I am working on query that combines a terms aggregation with a date histogram sub-aggregation. I would like to get the doc count of each sub-aggregation bucket, determine if it is accurate, and, if it is not acc…

---

## [Kibana Password User Interface](https://discuss.elastic.co/t/kibana-password-user-interface/348669)

<div class="topic-metadata">

**Author:** [@juancamiloll](https://discuss.elastic.co/u/juancamiloll)\
**Replies:** 1\
**Last updated:** [December 5, 2023, 10:15pm UTC](https://discuss.elastic.co/t/kibana-password-user-interface/348669 "2023-12-05T22:15:49Z")

</div>

Hello, Again I ejjeje, I can't get past this point, what should I do? And if I don't want to be prompted for a password, what can I do?

---

## [Connection reset when ingesting data from Filebeat to Logstash](https://discuss.elastic.co/t/connection-reset-when-ingesting-data-from-filebeat-to-logstash/348681)

<div class="topic-metadata">

**Author:** [@epronetlc](https://discuss.elastic.co/u/epronetlc)\
**Replies:** 0\
**Last updated:** [December 5, 2023, 8:55pm UTC](https://discuss.elastic.co/t/connection-reset-when-ingesting-data-from-filebeat-to-logstash/348681 "2023-12-05T20:55:06Z")

</div>

I have Filebeat 8.11.1 configured on a server running Windows Server 2019 with an output to Logstash. I have Logstash 8.11.1 configured on a server running Windows Server 2022 with an input from beats and an output to JD…

---

## [Adding APM as integration facing Kibana security must be enabled to use Fleet](https://discuss.elastic.co/t/adding-apm-as-integration-facing-kibana-security-must-be-enabled-to-use-fleet/348292)

<div class="topic-metadata">

**Author:** [@Yasir\_Zafar](https://discuss.elastic.co/u/Yasir_Zafar)\
**Replies:** 1\
**Last updated:** [December 5, 2023, 8:10pm UTC](https://discuss.elastic.co/t/adding-apm-as-integration-facing-kibana-security-must-be-enabled-to-use-fleet/348292 "2023-12-05T20:10:07Z")

</div>

When i am trying to add APM as integration point facing. Error loading integration details Kibana security must be enabled to use Fleet.

---

## [Default ingest pipeline overwritten](https://discuss.elastic.co/t/default-ingest-pipeline-overwritten/348640)

<div class="topic-metadata">

**Author:** [@Jasonespo](https://discuss.elastic.co/u/Jasonespo)\
**Replies:** 5\
**Last updated:** [December 5, 2023, 6:05pm UTC](https://discuss.elastic.co/t/default-ingest-pipeline-overwritten/348640 "2023-12-05T18:05:17Z")

</div>

Hi, I created an index template \`logs-{dataset\_name}-default' as well as setting up a data stream. I also setup a default ingest pipeline for this index. However after a number of days (and maybe coincidentally an Elas…

[Previous page](https://discuss.elastic.co/latest.md?page=461)

[Next page](https://discuss.elastic.co/latest.md?page=463)
