# Latest

**URL:** https://discuss.elastic.co/latest.md?page=463

[Latest](https://discuss.elastic.co/latest.md) · [Categories](https://discuss.elastic.co/categories.md) · [Tags](https://discuss.elastic.co/tags.md)

**Page:** 464

---

## [Grok\_timeout coming in logstash logs](https://discuss.elastic.co/t/grok-timeout-coming-in-logstash-logs/348623)

<div class="topic-metadata">

**Author:** [@Biswajit\_naik](https://discuss.elastic.co/u/Biswajit_naik)\
**Replies:** 2\
**Last updated:** [December 5, 2023, 5:25pm UTC](https://discuss.elastic.co/t/grok-timeout-coming-in-logstash-logs/348623 "2023-12-05T17:25:00Z")

</div>

when i process multiple type of logs by grok parser ,if the one of logline is not matched with the filter parser ,then i am excepting that it should be come grok parser faliure ,but it comes grok timeout warning in Logst…

---

## [Drop logstash logs not containing certain field](https://discuss.elastic.co/t/drop-logstash-logs-not-containing-certain-field/348626)

<div class="topic-metadata">

**Author:** [@e.vedelaar](https://discuss.elastic.co/u/e.vedelaar)\
**Replies:** 1\
**Last updated:** [December 5, 2023, 5:23pm UTC](https://discuss.elastic.co/t/drop-logstash-logs-not-containing-certain-field/348626 "2023-12-05T17:23:13Z")

</div>

I want to drop all logs who don't contain the dns.question.name field (or if the field is empty) how would i do this?

---

## [Critical vulns in logstash docker: CVE-2022-46337, CVE-2021-26291](https://discuss.elastic.co/t/critical-vulns-in-logstash-docker-cve-2022-46337-cve-2021-26291/348637)

<div class="topic-metadata">

**Author:** [@AdrianTT](https://discuss.elastic.co/u/AdrianTT)\
**Replies:** 1\
**Last updated:** [December 5, 2023, 5:11pm UTC](https://discuss.elastic.co/t/critical-vulns-in-logstash-docker-cve-2022-46337-cve-2021-26291/348637 "2023-12-05T17:11:36Z")

</div>

trivy reports in the logstash:8.11 docker image the following critical vulns: CVE-2022-46337 in org.apache.derby:derby (derby-10.14.1.0.jar) CVE-2021-26291 in org.apache.maven:maven-compat (maven-compat-3.3.9.jar), org…

---

## [How to connect to \`elasticsearch\` version \`8.x\` using \`API Key\` from \`logstash\`?](https://discuss.elastic.co/t/how-to-connect-to-elasticsearch-version-8-x-using-api-key-from-logstash/348612)

<div class="topic-metadata">

**Author:** [@pushanbhattacharya](https://discuss.elastic.co/u/pushanbhattacharya)\
**Replies:** 4\
**Last updated:** [December 5, 2023, 4:21pm UTC](https://discuss.elastic.co/t/how-to-connect-to-elasticsearch-version-8-x-using-api-key-from-logstash/348612 "2023-12-05T16:21:34Z")

</div>

Hi, I have been using ELK since last 5 years. My codebase is mostly for logstash where the input is a JDBC connection (DB) and after filtering output is the Elasticsearch cluster (for most of the cases). So far I was u…

---

## [Take the Elasticsearch developer survey](https://discuss.elastic.co/t/take-the-elasticsearch-developer-survey/348664)

<div class="topic-metadata">

**Author:** [@carly.richmond](https://discuss.elastic.co/u/carly.richmond)\
**Replies:** 0\
**Last updated:** [December 5, 2023, 4:28pm UTC](https://discuss.elastic.co/t/take-the-elasticsearch-developer-survey/348664 "2023-12-05T16:28:35Z")

</div>

Our developer community is a big part of why Elasticsearch is so popular. To make sure Elastic continues to be a great choice for speed, scale, and relevance, we’d like your help. This survey on your developer experienc…

---

## [Elasticsearch-hadoop 7.17.11 / 8.9.0 Security Update (ESA-2023-28)](https://discuss.elastic.co/t/elasticsearch-hadoop-7-17-11-8-9-0-security-update-esa-2023-28/348663)

<div class="topic-metadata">

**Author:** [@Bryan\_Garcia](https://discuss.elastic.co/u/Bryan_Garcia)\
**Replies:** 0\
**Last updated:** [December 5, 2023, 4:27pm UTC](https://discuss.elastic.co/t/elasticsearch-hadoop-7-17-11-8-9-0-security-update-esa-2023-28/348663 "2023-12-05T16:27:11Z")

</div>

Elasticsearch-hadoop Unsafe Deserialization (ESA-2023-28) An issue was identified that allowed the unsafe deserialization of java objects from hadoop or spark configuration properties that could have been modified by au…

---

## [ELK Stack Events Per Second and Flow Per Minute](https://discuss.elastic.co/t/elk-stack-events-per-second-and-flow-per-minute/348660)

<div class="topic-metadata">

**Author:** [@Guestaba](https://discuss.elastic.co/u/Guestaba)\
**Replies:** 1\
**Last updated:** [December 5, 2023, 3:57pm UTC](https://discuss.elastic.co/t/elk-stack-events-per-second-and-flow-per-minute/348660 "2023-12-05T15:57:39Z")

</div>

Hi everyone, I have and ELK Stack as a SIEM and I am trying to know what are the Events Per Second and the Flow Per Minute of my SIEM. Can someone help me figure this out Thanks in advance

---

## [Elastic APM index name requirement?](https://discuss.elastic.co/t/elastic-apm-index-name-requirement/348639)

<div class="topic-metadata">

**Author:** [@Jasonespo](https://discuss.elastic.co/u/Jasonespo)\
**Replies:** 2\
**Last updated:** [December 5, 2023, 3:39pm UTC](https://discuss.elastic.co/t/elastic-apm-index-name-requirement/348639 "2023-12-05T15:39:20Z")

</div>

Hi, I was wondering if there is a requirement on the index name for the logs to appear in the logs section of an Elastic APM transaction? I moved to using Elastic Serverless Forwarder to send applications logs to a cus…

---

## [On Docker containers. Kibana connect to cloud instead the Elasticsearch container](https://discuss.elastic.co/t/on-docker-containers-kibana-connect-to-cloud-instead-the-elasticsearch-container/348336)

<div class="topic-metadata">

**Author:** [@Juan\_Pablo\_Scodelari](https://discuss.elastic.co/u/Juan_Pablo_Scodelari)\
**Replies:** 7\
**Last updated:** [December 5, 2023, 3:33pm UTC](https://discuss.elastic.co/t/on-docker-containers-kibana-connect-to-cloud-instead-the-elasticsearch-container/348336 "2023-12-05T15:33:45Z")

</div>

Hi, I want to install and run locally Elasticsearch and Kibana with Docker. I've tried several methods and reinstalled everything, many times with no success. I can't get Kibana to connect to the elasticsearch in the …

---

## [Add Geojson Files to Elastic Map Service](https://discuss.elastic.co/t/add-geojson-files-to-elastic-map-service/348646)

<div class="topic-metadata">

**Author:** [@m.hanna](https://discuss.elastic.co/u/m.hanna)\
**Replies:** 1\
**Last updated:** [December 5, 2023, 3:10pm UTC](https://discuss.elastic.co/t/add-geojson-files-to-elastic-map-service/348646 "2023-12-05T15:10:31Z")

</div>

We have some geojson files that we created that we would like to add to our Elastic Map Service instance. Examples - airports.geojson that has geo points of airports worldwide us\_states\_territories.geojson that includ…

---

## [A question about Logstash S3 output plugin behaviour](https://discuss.elastic.co/t/a-question-about-logstash-s3-output-plugin-behaviour/348651)

<div class="topic-metadata">

**Author:** [@milon.james](https://discuss.elastic.co/u/milon.james)\
**Replies:** 0\
**Last updated:** [December 5, 2023, 2:33pm UTC](https://discuss.elastic.co/t/a-question-about-logstash-s3-output-plugin-behaviour/348651 "2023-12-05T14:33:35Z")

</div>

Hello, Would like to know what is the default behaviour of Logstash S3 output plugin if we stop the process. Can we configure the plugin to close all the open temporary files and push them to S3 before the process shuts…

---

## [Delete (Elastic Web crawler) crawled Web pages - maybe per Pipeline](https://discuss.elastic.co/t/delete-elastic-web-crawler-crawled-web-pages-maybe-per-pipeline/344974)

<div class="topic-metadata">

**Author:** [@sebastianboelling](https://discuss.elastic.co/u/sebastianboelling)\
**Replies:** 3\
**Last updated:** [December 5, 2023, 2:30pm UTC](https://discuss.elastic.co/t/delete-elastic-web-crawler-crawled-web-pages-maybe-per-pipeline/344974 "2023-12-05T14:30:36Z")

</div>

Hi all, we are looking a bit arround how we can delete crawled "pages" (documents) from an index when they are outdated or change their nodindex from INDEX to index or if they match any other metadata. We experimented …

---

## [Remove N leading bytes from TCP input](https://discuss.elastic.co/t/remove-n-leading-bytes-from-tcp-input/348650)

<div class="topic-metadata">

**Author:** [@rcz](https://discuss.elastic.co/u/rcz)\
**Replies:** 0\
**Last updated:** [December 5, 2023, 2:29pm UTC](https://discuss.elastic.co/t/remove-n-leading-bytes-from-tcp-input/348650 "2023-12-05T14:29:03Z")

</div>

Hi, We are receiving some dubious Protobuf-encoded messages on our TCP input. The sender is leading with a custom length-header of 4 bytes. If we manually dissect the messages, remove the first 4 bytes, and then give …

---

## [CreateIndexRequest with date math](https://discuss.elastic.co/t/createindexrequest-with-date-math/348496)

<div class="topic-metadata">

**Author:** [@avnere](https://discuss.elastic.co/u/avnere)\
**Replies:** 1\
**Last updated:** [December 5, 2023, 1:52pm UTC](https://discuss.elastic.co/t/createindexrequest-with-date-math/348496 "2023-12-05T13:52:55Z")

</div>

Hi I am using RestHighLevelClient 7.13. I am trying to create an index with date math: CreateIndexRequest cir = new CreateIndexRequest("\<books-{now/d}-0001\>"); It create an index with the name books, without the date…

---

## [One Kibana for multiple Elastic Clusters](https://discuss.elastic.co/t/one-kibana-for-multiple-elastic-clusters/348539)

<div class="topic-metadata">

**Author:** [@Jose\_E](https://discuss.elastic.co/u/Jose_E)\
**Replies:** 2\
**Last updated:** [December 5, 2023, 1:18pm UTC](https://discuss.elastic.co/t/one-kibana-for-multiple-elastic-clusters/348539 "2023-12-05T13:18:56Z")

</div>

Hi everyone, I have a technical doubt regarding the capabilities of Kibana. I currently run an Elasticsearch Cluster with some storage issues and we cannot increase the storage size due to some limitations. However, we …

---

## [Logstash config](https://discuss.elastic.co/t/logstash-config/348644)

<div class="topic-metadata">

**Author:** [@kibanauser4](https://discuss.elastic.co/u/kibanauser4)\
**Replies:** 0\
**Last updated:** [December 5, 2023, 1:16pm UTC](https://discuss.elastic.co/t/logstash-config/348644 "2023-12-05T13:16:17Z")

</div>

I have installed 7.15.0 version of Logstash. I have the following config file: input { file { path =\> "C:/Users/ELK Stack/data/sample.csv" start\_position =\> "beginning" sincedb\_path =\> "NUL" } } filter { csv {…

---

## ["has no content yet" spam](https://discuss.elastic.co/t/has-no-content-yet-spam/347003)

<div class="topic-metadata">

**Author:** [@terrainc](https://discuss.elastic.co/u/terrainc)\
**Replies:** 1\
**Last updated:** [December 5, 2023, 1:10pm UTC](https://discuss.elastic.co/t/has-no-content-yet-spam/347003 "2023-12-05T13:10:07Z")

</div>

After Fix empty file edge case by rdner · Pull Request #36076 · elastic/beats · GitHub my logs now full of spam "has no content yet, skipping" for all zero size logs. And on the "warning" level =(

---

## [The client is unable to verify that the server is Elasticsearch due to an unsuccessful product check call](https://discuss.elastic.co/t/the-client-is-unable-to-verify-that-the-server-is-elasticsearch-due-to-an-unsuccessful-product-check-call/348635)

<div class="topic-metadata">

**Author:** [@GRK](https://discuss.elastic.co/u/GRK)\
**Replies:** 7\
**Last updated:** [December 5, 2023, 12:29pm UTC](https://discuss.elastic.co/t/the-client-is-unable-to-verify-that-the-server-is-elasticsearch-due-to-an-unsuccessful-product-check-call/348635 "2023-12-05T12:29:19Z")

</div>

Invalid NEST response built from a unsuccessful () low level call on HEAD: /indexname Audit trail of this API call: \[1\] ProductCheckOnStartup: Took: \[2\] ProductCheckFailure: Node: OriginalException: Elasticsearch.Net…

---

## [Master node is not able to collect garbage memory](https://discuss.elastic.co/t/master-node-is-not-able-to-collect-garbage-memory/348625)

<div class="topic-metadata">

**Author:** [@equisde](https://discuss.elastic.co/u/equisde)\
**Replies:** 2\
**Last updated:** [December 5, 2023, 10:46am UTC](https://discuss.elastic.co/t/master-node-is-not-able-to-collect-garbage-memory/348625 "2023-12-05T10:46:06Z")

</div>

The active master node in my Elasticsearch cluster is not able to collect garbage memory. All other standby master nodes are fine. Symptoms: Heap gets increasing forever ES Version: 7.16.3 Nodes: 3 master nodes,…

---

## [Multiselect values in Kibana Visualizations](https://discuss.elastic.co/t/multiselect-values-in-kibana-visualizations/346659)

<div class="topic-metadata">

**Author:** [@fniwes](https://discuss.elastic.co/u/fniwes)\
**Replies:** 3\
**Last updated:** [December 5, 2023, 9:50am UTC](https://discuss.elastic.co/t/multiselect-values-in-kibana-visualizations/346659 "2023-12-05T09:50:40Z")

</div>

Hi! I have several visualizations, some as pie chart with multiple values. I want to select multiple values from the visualization to filter and also to explore in detail using discovery. But I am only able to select on…

---

## [Index stat analyse to increase performance](https://discuss.elastic.co/t/index-stat-analyse-to-increase-performance/348624)

<div class="topic-metadata">

**Author:** [@INS](https://discuss.elastic.co/u/INS)\
**Replies:** 0\
**Last updated:** [December 5, 2023, 9:39am UTC](https://discuss.elastic.co/t/index-stat-analyse-to-increase-performance/348624 "2023-12-05T09:39:54Z")

</div>

Hi Can You look at the statistic from one of index. From our observations, it seems that the longer this index is updated, the worse the performanc i.e. response time results come out. What to pay attention to? Is there…

---

## [ILM not working node does not match index setting \[index.routing.allocation.require\] filters \[data:\\"warm\\"\]](https://discuss.elastic.co/t/ilm-not-working-node-does-not-match-index-setting-index-routing-allocation-require-filters-data-warm/348617)

<div class="topic-metadata">

**Author:** [@esseti](https://discuss.elastic.co/u/esseti)\
**Replies:** 0\
**Last updated:** [December 5, 2023, 8:42am UTC](https://discuss.elastic.co/t/ilm-not-working-node-does-not-match-index-setting-index-routing-allocation-require-filters-data-warm/348617 "2023-12-05T08:42:41Z")

</div>

Hello i've setup an ILM but i noticed that indeces never leave the warm state, by checking \_cluster/allocation/ i get this message node does not match index setting \[index.routing.allocation.require\] filters \[data:\\"…

---

## [NEST and new elastic .net client](https://discuss.elastic.co/t/nest-and-new-elastic-net-client/348485)

<div class="topic-metadata">

**Author:** [@agonzalez](https://discuss.elastic.co/u/agonzalez)\
**Replies:** 1\
**Last updated:** [December 5, 2023, 8:04am UTC](https://discuss.elastic.co/t/nest-and-new-elastic-net-client/348485 "2023-12-05T08:04:06Z")

</div>

New elastic net client is not compatible with old NEST, we have complex application build on old NEST and is very difficult to migrate and test to new client. Is NEST going to be supported in future elastic version in c…

---

## [Dec 5th, 2023: \[FR\] Père Noël ? Il est temps de partir ! - TTL avec Elasticsearch](https://discuss.elastic.co/t/dec-5th-2023-fr-pere-noel-il-est-temps-de-partir-ttl-avec-elasticsearch/347929)

<div class="topic-metadata">

**Author:** [@dadoonet](https://discuss.elastic.co/u/dadoonet)\
**Replies:** 0\
**Last updated:** [December 5, 2023, 8:00am UTC](https://discuss.elastic.co/t/dec-5th-2023-fr-pere-noel-il-est-temps-de-partir-ttl-avec-elasticsearch/347929 "2023-12-05T08:00:33Z")

</div>

This post is also available in english. Imaginez que le père Noël doit livrer des cadeaux à tous les enfants du monde. Il a beaucoup de travail à faire et il doit être efficace. Il a une liste de tous les enfants et …

---

## [Dec 5th, 2023: \[EN\] Santa? It's Time To Leave! - Using TTL on Elasticsearch documents](https://discuss.elastic.co/t/dec-5th-2023-en-santa-its-time-to-leave-using-ttl-on-elasticsearch-documents/347847)

<div class="topic-metadata">

**Author:** [@dadoonet](https://discuss.elastic.co/u/dadoonet)\
**Replies:** 0\
**Last updated:** [December 5, 2023, 8:00am UTC](https://discuss.elastic.co/t/dec-5th-2023-en-santa-its-time-to-leave-using-ttl-on-elasticsearch-documents/347847 "2023-12-05T08:00:33Z")

</div>

Cet article est également disponible en français. Imagine that Santa has to deliver presents to all the children in the world. He has a lot of work to do and he needs to be efficient. He has a list of all the childre…

---

## [Is it possible to get an alert when an index of certain pattern is rolled over](https://discuss.elastic.co/t/is-it-possible-to-get-an-alert-when-an-index-of-certain-pattern-is-rolled-over/348611)

<div class="topic-metadata">

**Author:** [@Krishna\_Teja](https://discuss.elastic.co/u/Krishna_Teja)\
**Replies:** 0\
**Last updated:** [December 5, 2023, 5:16am UTC](https://discuss.elastic.co/t/is-it-possible-to-get-an-alert-when-an-index-of-certain-pattern-is-rolled-over/348611 "2023-12-05T05:16:21Z")

</div>

I have an ILM policy setup to roll over a datastream when it reaches certain threshold values. Once a new index is created, I want to get notified so I can run a script to update some parameters in my backend. Is there a…

---

## [How to retrieve elastic data to import it in another instance with different version?](https://discuss.elastic.co/t/how-to-retrieve-elastic-data-to-import-it-in-another-instance-with-different-version/348608)

<div class="topic-metadata">

**Author:** [@Kliwon\_Zervaloski](https://discuss.elastic.co/u/Kliwon_Zervaloski)\
**Replies:** 0\
**Last updated:** [December 5, 2023, 3:56am UTC](https://discuss.elastic.co/t/how-to-retrieve-elastic-data-to-import-it-in-another-instance-with-different-version/348608 "2023-12-05T03:56:06Z")

</div>

Hi Everyone, I want to migrate all the data from my old elastic instance which i installed on my local VM(the version is 7.16.3) and i want to send the data do my new instance on cloud vm with the latest version, is ther…

---

## [Problem on memory leak on auditbeat pod](https://discuss.elastic.co/t/problem-on-memory-leak-on-auditbeat-pod/348606)

<div class="topic-metadata">

**Author:** [@masonlu2014](https://discuss.elastic.co/u/masonlu2014)\
**Replies:** 0\
**Last updated:** [December 5, 2023, 3:06am UTC](https://discuss.elastic.co/t/problem-on-memory-leak-on-auditbeat-pod/348606 "2023-12-05T03:06:19Z")

</div>

hello guys, would you pls help me take a look memory leak problem on auditbeat , i am using v7.7.15 version of auditbeat , and i also have patched libbeat/processors/add\_process\_metadata: implement a process cache evic…

---

## [Clone api Bad Gateway error](https://discuss.elastic.co/t/clone-api-bad-gateway-error/348604)

<div class="topic-metadata">

**Author:** [@Krishna94](https://discuss.elastic.co/u/Krishna94)\
**Replies:** 0\
**Last updated:** [December 5, 2023, 2:27am UTC](https://discuss.elastic.co/t/clone-api-bad-gateway-error/348604 "2023-12-05T02:27:54Z")

</div>

Hi team, I tried to do a reindexing of my data but its taking more than 10 days so I tried to clone my index which is of 816GB and when I run clone api I am getting the following error, {"statusCode":502,"error":"Bad G…

---

## [How to use a dropdown filter in Canvas with graphics loaded from Visuallize Library](https://discuss.elastic.co/t/how-to-use-a-dropdown-filter-in-canvas-with-graphics-loaded-from-visuallize-library/348427)

<div class="topic-metadata">

**Author:** [@ajogonpez](https://discuss.elastic.co/u/ajogonpez)\
**Replies:** 1\
**Last updated:** [December 4, 2023, 10:42pm UTC](https://discuss.elastic.co/t/how-to-use-a-dropdown-filter-in-canvas-with-graphics-loaded-from-visuallize-library/348427 "2023-12-04T22:42:31Z")

</div>

Hello, I am working with the Canvas part, i have several dashboards in which I use different graphics that I have saved in the Visualize Library section to create these Dashes. Now I want to create a Canvas with these g…

[Previous page](https://discuss.elastic.co/latest.md?page=462)

[Next page](https://discuss.elastic.co/latest.md?page=464)
