# Latest

**URL:** https://discuss.elastic.co/latest.md?page=470

[Latest](https://discuss.elastic.co/latest.md) · [Categories](https://discuss.elastic.co/categories.md) · [Tags](https://discuss.elastic.co/tags.md)

**Page:** 471

---

## [Increase the lens max results](https://discuss.elastic.co/t/increase-the-lens-max-results/345601)

<div class="topic-metadata">

**Author:** [@seanziee](https://discuss.elastic.co/u/seanziee)\
**Replies:** 6\
**Last updated:** [November 28, 2023, 8:21pm UTC](https://discuss.elastic.co/t/increase-the-lens-max-results/345601 "2023-11-28T20:21:15Z")

</div>

I'd like to increase the number of results on kibana lens data table viz but can't find out how. I regularly export unique ids I have to csv using lens in order to run some custom analysis, etc. I'd like to increase thi…

---

## [Synthetics - Separate Alerts for Monitors](https://discuss.elastic.co/t/synthetics-separate-alerts-for-monitors/348096)

<div class="topic-metadata">

**Author:** [@erikg](https://discuss.elastic.co/u/erikg)\
**Replies:** 5\
**Last updated:** [November 28, 2023, 7:37pm UTC](https://discuss.elastic.co/t/synthetics-separate-alerts-for-monitors/348096 "2023-11-28T19:37:18Z")

</div>

Hello, This might be obvious, but I can't seem to find the answer. We are considering using Synthetics instead of Uptime in Observability. I have set up the Elastic Agent Integration for Synthetics, and we have it up a…

---

## [Indicator Detection](https://discuss.elastic.co/t/indicator-detection/347862)

<div class="topic-metadata">

**Author:** [@Phoenix1](https://discuss.elastic.co/u/Phoenix1)\
**Replies:** 3\
**Last updated:** [November 28, 2023, 4:49pm UTC](https://discuss.elastic.co/t/indicator-detection/347862 "2023-11-28T16:49:55Z")

</div>

I want to use a CSV(Indicator file) lookup to detect the indicators available in the file to report an alert. please suggest.

---

## [Not able to Add Node to Existing Cluster](https://discuss.elastic.co/t/not-able-to-add-node-to-existing-cluster/348068)

<div class="topic-metadata">

**Author:** [@Debasis\_Mallick](https://discuss.elastic.co/u/Debasis_Mallick)\
**Replies:** 7\
**Last updated:** [November 28, 2023, 4:35pm UTC](https://discuss.elastic.co/t/not-able-to-add-node-to-existing-cluster/348068 "2023-11-28T16:35:44Z")

</div>

Hi Team, I had requirement to create two node cluster of 8.9.2 version. we did Elasticsearch installation on both nodes through RPM based. I had generated enrollment token (elasticsearch-create-enrollment-token -s node …

---

## [Stuck at setting up ELK for monitoring](https://discuss.elastic.co/t/stuck-at-setting-up-elk-for-monitoring/347999)

<div class="topic-metadata">

**Author:** [@Aamira](https://discuss.elastic.co/u/Aamira)\
**Replies:** 5\
**Last updated:** [November 28, 2023, 4:13pm UTC](https://discuss.elastic.co/t/stuck-at-setting-up-elk-for-monitoring/347999 "2023-11-28T16:13:51Z")

</div>

I'm new to ELK stack and trying to set it up to monitor my servers and services, but when i installed everything and installed metricbeat when i go to kibana to see the data that sent by metricbeat i overwhelmed by huge …

---

## [GUI of APM not showing values in the label. version 8.9.2](https://discuss.elastic.co/t/gui-of-apm-not-showing-values-in-the-label-version-8-9-2/348163)

<div class="topic-metadata">

**Author:** [@ElasticLiver](https://discuss.elastic.co/u/ElasticLiver)\
**Replies:** 0\
**Last updated:** [November 28, 2023, 3:57pm UTC](https://discuss.elastic.co/t/gui-of-apm-not-showing-values-in-the-label-version-8-9-2/348163 "2023-11-28T15:57:17Z")

</div>

Hi, a customer is asking why the values in the labes are not showing anymore, in some visualization of the APM section in observability: where in previous version the visualization show the values: Is this a bug? …

---

## [JDBC streaming array as parameter](https://discuss.elastic.co/t/jdbc-streaming-array-as-parameter/348159)

<div class="topic-metadata">

**Author:** [@Rodrigo\_Martins](https://discuss.elastic.co/u/Rodrigo_Martins)\
**Replies:** 0\
**Last updated:** [November 28, 2023, 3:19pm UTC](https://discuss.elastic.co/t/jdbc-streaming-array-as-parameter/348159 "2023-11-28T15:19:33Z")

</div>

Hello everyone, We are trying to execute a jdbc\_streaming query that takes as parameter a array of values. Our statement looks like this: statement =\> "SELECT \`table\_name\`,\`column\_name\`,\`classification\` FROM \`tableEx\`…

---

## [\[ECK\] 404 error for elastic agent running on ec2 host](https://discuss.elastic.co/t/eck-404-error-for-elastic-agent-running-on-ec2-host/348152)

<div class="topic-metadata">

**Author:** [@nitesh.singh](https://discuss.elastic.co/u/nitesh.singh)\
**Replies:** 0\
**Last updated:** [November 28, 2023, 2:23pm UTC](https://discuss.elastic.co/t/eck-404-error-for-elastic-agent-running-on-ec2-host/348152 "2023-11-28T14:23:07Z")

</div>

We are using ECK method of installation which is hosted on EKS in AWS account, where Fleet is also installed. We want to monitor ec2 instances and collect logs using an elastic agent which is managed by Fleet, hosted in…

---

## [Enrich IPs with geoip FileBeat and Elasticsearch](https://discuss.elastic.co/t/enrich-ips-with-geoip-filebeat-and-elasticsearch/348154)

<div class="topic-metadata">

**Author:** [@Wad1636](https://discuss.elastic.co/u/Wad1636)\
**Replies:** 0\
**Last updated:** [November 28, 2023, 2:27pm UTC](https://discuss.elastic.co/t/enrich-ips-with-geoip-filebeat-and-elasticsearch/348154 "2023-11-28T14:27:27Z")

</div>

Hello, I would like to obtain the geolocation of IP addresses using Filebeat and Elasticsearch. To sort the IP addresses, I am using a "dissect" schema as follows: - dissect: tokenizer: '%{+MMM d HH:mm:ss} %{nextcl…

---

## [Kibana login tracking](https://discuss.elastic.co/t/kibana-login-tracking/346684)

<div class="topic-metadata">

**Author:** [@mostafaelsayed](https://discuss.elastic.co/u/mostafaelsayed)\
**Replies:** 3\
**Last updated:** [November 28, 2023, 2:14pm UTC](https://discuss.elastic.co/t/kibana-login-tracking/346684 "2023-11-28T14:14:15Z")

</div>

Hi team, Is there a way to know who logged in kibana using specific username? If so, is IP information included? Kibana version used is 7.9.2

---

## [CCS requires wildcard after index name to search or always returns 404](https://discuss.elastic.co/t/ccs-requires-wildcard-after-index-name-to-search-or-always-returns-404/348091)

<div class="topic-metadata">

**Author:** [@Doc\_Kaos](https://discuss.elastic.co/u/Doc_Kaos)\
**Replies:** 1\
**Last updated:** [November 28, 2023, 2:12pm UTC](https://discuss.elastic.co/t/ccs-requires-wildcard-after-index-name-to-search-or-always-returns-404/348091 "2023-11-28T14:12:31Z")

</div>

Quick bit about the setup: Dedicated CCS cluster (no local indices, except for monitoring) v7.17.10 Two clusters clusterA and clusterB are connected as remote clusters v7.4.1 All of these searches are performed on the…

---

## [Auditbeat 8.10.2 caused several physical servers to crash](https://discuss.elastic.co/t/auditbeat-8-10-2-caused-several-physical-servers-to-crash/346386)

<div class="topic-metadata">

**Author:** [@kpeterson-pmts](https://discuss.elastic.co/u/kpeterson-pmts)\
**Replies:** 1\
**Last updated:** [November 28, 2023, 2:03pm UTC](https://discuss.elastic.co/t/auditbeat-8-10-2-caused-several-physical-servers-to-crash/346386 "2023-11-28T14:03:56Z")

</div>

We upgraded auditbeats from version 8.6.2 to version 8.10.2 using automation tooling. The upgrade was first tested on some of our EC2 instances, and had no issues. When we applied the upgrade to a subset of physical host…

---

## [Create a new index with the query's result](https://discuss.elastic.co/t/create-a-new-index-with-the-querys-result/347353)

<div class="topic-metadata">

**Author:** [@Mathieu64](https://discuss.elastic.co/u/Mathieu64)\
**Replies:** 1\
**Last updated:** [November 28, 2023, 2:00pm UTC](https://discuss.elastic.co/t/create-a-new-index-with-the-querys-result/347353 "2023-11-28T14:00:26Z")

</div>

Hi, I want to send the query's result in a new index : GET myindex/\_search { "size" : 0, "\_source" : false, "aggregations" : { "groupby" : { "composite" : { "size" : 1000, "sources" : \[ …

---

## [Elasticsearch NEST client GetSnapshotRequest method is not returning index\_details](https://discuss.elastic.co/t/elasticsearch-nest-client-getsnapshotrequest-method-is-not-returning-index-details/348015)

<div class="topic-metadata">

**Author:** [@EVINDX](https://discuss.elastic.co/u/EVINDX)\
**Replies:** 1\
**Last updated:** [November 28, 2023, 1:49pm UTC](https://discuss.elastic.co/t/elasticsearch-nest-client-getsnapshotrequest-method-is-not-returning-index-details/348015 "2023-11-28T13:49:00Z")

</div>

I'm using NEST version 7.17 to communicate with Elasticsearch 7.17 I have a snapshot created without any issues. I'm able to restore the snapshot as well. I can get the Elasticsearch index details in the snapshot via t…

---

## [Logstash freezes during initialization](https://discuss.elastic.co/t/logstash-freezes-during-initialization/348145)

<div class="topic-metadata">

**Author:** [@GinkoLucas](https://discuss.elastic.co/u/GinkoLucas)\
**Replies:** 0\
**Last updated:** [November 28, 2023, 1:26pm UTC](https://discuss.elastic.co/t/logstash-freezes-during-initialization/348145 "2023-11-28T13:26:16Z")

</div>

Hi, I got a Logstash who work well on local docker. When i use docker on Azure, Logstash freezes during initialization. I just got these logs : Using bundled JDK: /usr/share/logstash/jdk OpenJDK 64-Bit Server VM war…

---

## [No alive nodes. All the 5 nodes seem to be down](https://discuss.elastic.co/t/no-alive-nodes-all-the-5-nodes-seem-to-be-down/348138)

<div class="topic-metadata">

**Author:** [@Test\_Owner](https://discuss.elastic.co/u/Test_Owner)\
**Replies:** 1\
**Last updated:** [November 28, 2023, 1:15pm UTC](https://discuss.elastic.co/t/no-alive-nodes-all-the-5-nodes-seem-to-be-down/348138 "2023-11-28T13:15:56Z")

</div>

"No alive nodes. All the 5 nodes seem to be down". I get such a problem when executing a request. Previously, the request was executed correctly, but with the increase in records, I have such a problem. What can you adv…

---

## [Drastic reduction in query performance when using replicas](https://discuss.elastic.co/t/drastic-reduction-in-query-performance-when-using-replicas/348090)

<div class="topic-metadata">

**Author:** [@diegomansua](https://discuss.elastic.co/u/diegomansua)\
**Replies:** 6\
**Last updated:** [November 28, 2023, 1:03pm UTC](https://discuss.elastic.co/t/drastic-reduction-in-query-performance-when-using-replicas/348090 "2023-11-28T13:03:15Z")

</div>

Hi everyone. We're facing an issue whereby having replicas drastically decreases query performance. Our set up consists of 3 nodes running ES 7.16 with 4GB heap each. We have around 1.6 million documents that contain a…

---

## [Anomaly Jobs - General Strategies to reduce false positives](https://discuss.elastic.co/t/anomaly-jobs-general-strategies-to-reduce-false-positives/348094)

<div class="topic-metadata">

**Author:** [@marmai16](https://discuss.elastic.co/u/marmai16)\
**Replies:** 2\
**Last updated:** [November 28, 2023, 12:58pm UTC](https://discuss.elastic.co/t/anomaly-jobs-general-strategies-to-reduce-false-positives/348094 "2023-11-28T12:58:30Z")

</div>

Hello everybody, i'am struggling to baseline an anomaly detection job (filters are not really helping so far). What are the general strategies or factors which drive the model to become, simply put, more "insensitive" …

---

## [Elastic-agent entry /proc/net/udp not found](https://discuss.elastic.co/t/elastic-agent-entry-proc-net-udp-not-found/348140)

<div class="topic-metadata">

**Author:** [@atbc](https://discuss.elastic.co/u/atbc)\
**Replies:** 0\
**Last updated:** [November 28, 2023, 12:40pm UTC](https://discuss.elastic.co/t/elastic-agent-entry-proc-net-udp-not-found/348140 "2023-11-28T12:40:33Z")

</div>

Hello, I set up a Fleet server and on this same policy I added a Juniper integration, I see that it listens on the specified ports with the command "sudo ss -tulpn" and I can see the logs arriving with a TCPDUMP. But I …

---

## [Logstash elasticsearch input plugin](https://discuss.elastic.co/t/logstash-elasticsearch-input-plugin/347207)

<div class="topic-metadata">

**Author:** [@Haytham\_Shammout](https://discuss.elastic.co/u/Haytham_Shammout)\
**Replies:** 3\
**Last updated:** [November 28, 2023, 12:39pm UTC](https://discuss.elastic.co/t/logstash-elasticsearch-input-plugin/347207 "2023-11-28T12:39:22Z")

</div>

Hello dears, i am trying to create logstash job that have input from elasticsearch index pattern and to take a specific logs then to save them in a historical index so the configuration as below, input{ elasticsearch …

---

## [Monitoring: Error getting cgroup stats - io.pressure not found](https://discuss.elastic.co/t/monitoring-error-getting-cgroup-stats-io-pressure-not-found/348137)

<div class="topic-metadata">

**Author:** [@adsr](https://discuss.elastic.co/u/adsr)\
**Replies:** 0\
**Last updated:** [November 28, 2023, 12:23pm UTC](https://discuss.elastic.co/t/monitoring-error-getting-cgroup-stats-io-pressure-not-found/348137 "2023-11-28T12:23:58Z")

</div>

After upgrading from kernel 5.14.0-284.11.1.el9\_2.x86\_64 to 5.14.0-362.8.1.el9\_3.x86\_64 I get the following error every ~1minute: error getting cgroup stats: error fetching stats for controller io: error fetching IO sta…

---

## [How do I configure multiple Kibana modules in metricbeat?](https://discuss.elastic.co/t/how-do-i-configure-multiple-kibana-modules-in-metricbeat/348108)

<div class="topic-metadata">

**Author:** [@blueren](https://discuss.elastic.co/u/blueren)\
**Replies:** 1\
**Last updated:** [November 28, 2023, 12:18pm UTC](https://discuss.elastic.co/t/how-do-i-configure-multiple-kibana-modules-in-metricbeat/348108 "2023-11-28T12:18:35Z")

</div>

I am setting up a dedicated ES cluster for monitoring a production clusted as per official ES documentation. I'm able to get the metrics of ES, and now am trying to get the metrics of the two instances of production Kiba…

---

## [Elasticsearch 8.11.1 fails when using AWS IAM roles for service accounts](https://discuss.elastic.co/t/elasticsearch-8-11-1-fails-when-using-aws-iam-roles-for-service-accounts/347766)

<div class="topic-metadata">

**Author:** [@mornie](https://discuss.elastic.co/u/mornie)\
**Replies:** 1\
**Last updated:** [November 28, 2023, 11:01am UTC](https://discuss.elastic.co/t/elasticsearch-8-11-1-fails-when-using-aws-iam-roles-for-service-accounts/347766 "2023-11-28T11:01:59Z")

</div>

Hi Team I am using eck-operator-2.10.0, and when upgrading the elastic stack from 8.11.0 to 8.11.1, the elasticsearch pods is stuck in an crashloopbackoff state. I have configured AWS IAM roles for service accounts (IR…

---

## [Problem in send log consistently with filebeat](https://discuss.elastic.co/t/problem-in-send-log-consistently-with-filebeat/348121)

<div class="topic-metadata">

**Author:** [@behzad\_alipoor](https://discuss.elastic.co/u/behzad_alipoor)\
**Replies:** 0\
**Last updated:** [November 28, 2023, 10:07am UTC](https://discuss.elastic.co/t/problem-in-send-log-consistently-with-filebeat/348121 "2023-11-28T10:07:30Z")

</div>

i have problem in sending logs with filebeat to elasticsearch . it sends data and pauses and after miliseconds it sends again data . i set this config : scan\_frequency: 10s close\_inactive: 20s ignore\_older: 30s …

---

## [OpenAI connect with elastic search datasource](https://discuss.elastic.co/t/openai-connect-with-elastic-search-datasource/347901)

<div class="topic-metadata">

**Author:** [@Saurabh\_Agrawal2](https://discuss.elastic.co/u/Saurabh_Agrawal2)\
**Replies:** 5\
**Last updated:** [November 28, 2023, 9:59am UTC](https://discuss.elastic.co/t/openai-connect-with-elastic-search-datasource/347901 "2023-11-28T09:59:18Z")

</div>

I am trying call openAI with my custom index created on Elastic search but when I try to run it I am getting following error: openai.BadRequestError: Error code: 400 - {'error': {'requestid': 'aaa-bbb-404d-8a12-3da23608…

---

## [Eck on kubeadm](https://discuss.elastic.co/t/eck-on-kubeadm/348104)

<div class="topic-metadata">

**Author:** [@Swapnil2](https://discuss.elastic.co/u/Swapnil2)\
**Replies:** 0\
**Last updated:** [November 28, 2023, 4:41am UTC](https://discuss.elastic.co/t/eck-on-kubeadm/348104 "2023-11-28T04:41:06Z")

</div>

I created 3 node kubeadm cluster. I starting setup elasticsearch using eck.when I changed count 1from 3 then other pod in pending status...plz give

---

## [How to identify the IIS logs in Microsoft Exchange server?](https://discuss.elastic.co/t/how-to-identify-the-iis-logs-in-microsoft-exchange-server/347682)

<div class="topic-metadata">

**Author:** [@DW0728](https://discuss.elastic.co/u/DW0728)\
**Replies:** 1\
**Last updated:** [November 28, 2023, 3:49am UTC](https://discuss.elastic.co/t/how-to-identify-the-iis-logs-in-microsoft-exchange-server/347682 "2023-11-28T03:49:57Z")

</div>

How to identify the client IP info in IIS logs? To have this info, we would like to create a IP Map to quickly know where the mail account is logged on. But currently seems it hard to figure out the client ip info in IIS…

---

## [Disable geoip processor via filebeat ingest pipeline](https://discuss.elastic.co/t/disable-geoip-processor-via-filebeat-ingest-pipeline/348019)

<div class="topic-metadata">

**Author:** [@hjazz6](https://discuss.elastic.co/u/hjazz6)\
**Replies:** 1\
**Last updated:** [November 28, 2023, 2:57am UTC](https://discuss.elastic.co/t/disable-geoip-processor-via-filebeat-ingest-pipeline/348019 "2023-11-28T02:57:00Z")

</div>

Hi, I'm running ES and filebeat v8.8.0. I'm trying to disable the geoip processing only for netflow data written to the index test. I have netflow data written to other indices by other filebeat instances that have geoi…

---

## [Data\_stream.namespace in subject for Jira Action](https://discuss.elastic.co/t/data-stream-namespace-in-subject-for-jira-action/347459)

<div class="topic-metadata">

**Author:** [@jguilford](https://discuss.elastic.co/u/jguilford)\
**Replies:** 1\
**Last updated:** [November 28, 2023, 1:36am UTC](https://discuss.elastic.co/t/data-stream-namespace-in-subject-for-jira-action/347459 "2023-11-28T01:36:54Z")

</div>

Trying to use the data\_stream.namespace in the subject for Jira Action, but it does not pull any data, I see the data in the json for the alert. Please help. { "\_index": ".internal.alerts-security.alerts-default-000001…

---

## [Healthy agents not appearing in endpoint security](https://discuss.elastic.co/t/healthy-agents-not-appearing-in-endpoint-security/347239)

<div class="topic-metadata">

**Author:** [@eric10](https://discuss.elastic.co/u/eric10)\
**Replies:** 3\
**Last updated:** [November 27, 2023, 10:48pm UTC](https://discuss.elastic.co/t/healthy-agents-not-appearing-in-endpoint-security/347239 "2023-11-27T22:48:53Z")

</div>

I'm having issues finding any information on this... I've seen similar posts, but i see that they've been closed out due to no response... I have a healthy agent on a windows host that is able to successfully enroll into…

[Previous page](https://discuss.elastic.co/latest.md?page=469)

[Next page](https://discuss.elastic.co/latest.md?page=471)
