# Latest

**URL:** https://discuss.elastic.co/latest.md?page=474

[Latest](https://discuss.elastic.co/latest.md) · [Categories](https://discuss.elastic.co/categories.md) · [Tags](https://discuss.elastic.co/tags.md)

**Page:** 475

---

## [Enabling fingerprint file\_identiy](https://discuss.elastic.co/t/enabling-fingerprint-file-identiy/347780)

<div class="topic-metadata">

**Author:** [@MajorNickle](https://discuss.elastic.co/u/MajorNickle)\
**Replies:** 4\
**Last updated:** [November 23, 2023, 3:55pm UTC](https://discuss.elastic.co/t/enabling-fingerprint-file-identiy/347780 "2023-11-23T15:55:09Z")

</div>

Hey all, I'm stuck with getting the fingerprint file\_identity working. I have a few nfs mounts from which I'm reading log files. I tried enabling the fingerprint option in the scanner but it seems like it's not really b…

---

## [Delay of one hour in the events to ELK](https://discuss.elastic.co/t/delay-of-one-hour-in-the-events-to-elk/347875)

<div class="topic-metadata">

**Author:** [@billy.castillo.73](https://discuss.elastic.co/u/billy.castillo.73)\
**Replies:** 0\
**Last updated:** [November 23, 2023, 3:23pm UTC](https://discuss.elastic.co/t/delay-of-one-hour-in-the-events-to-elk/347875 "2023-11-23T15:23:40Z")

</div>

The events of a system that are being parsed from filebeat to our ELK are arriving an hour late. I have already configured the netscout.yml module of filebeat with the grok processors, with var.tz\_offset and with date -…

---

## [Translate kibana bar chart to TSVB](https://discuss.elastic.co/t/translate-kibana-bar-chart-to-tsvb/347421)

<div class="topic-metadata">

**Author:** [@PRASHANT\_MEHTA](https://discuss.elastic.co/u/PRASHANT_MEHTA)\
**Replies:** 3\
**Last updated:** [November 23, 2023, 2:12pm UTC](https://discuss.elastic.co/t/translate-kibana-bar-chart-to-tsvb/347421 "2023-11-23T14:12:26Z")

</div>

Hello All, I have visual made using Vertical Bar chart and over there I can't split x axis twice .I need to show max of duration for given startTime (x-axis),but same time x-axis also show release to compare. Given rel…

---

## [Cluster currently has \[1000\]/\[1000\] maximum normal shards open](https://discuss.elastic.co/t/cluster-currently-has-1000-1000-maximum-normal-shards-open/347719)

<div class="topic-metadata">

**Author:** [@DaddyYusk](https://discuss.elastic.co/u/DaddyYusk)\
**Replies:** 4\
**Last updated:** [November 23, 2023, 1:32pm UTC](https://discuss.elastic.co/t/cluster-currently-has-1000-1000-maximum-normal-shards-open/347719 "2023-11-23T13:32:03Z")

</div>

Hi, From the title, this is an error I usually encounter with my Elastic Proof Of Concept. The workaround is easy, I simply close and delete some indices from time to time... But now I'm currently deploying Elastic in…

---

## [Backing Up ES Indices](https://discuss.elastic.co/t/backing-up-es-indices/347815)

<div class="topic-metadata">

**Author:** [@Nijal](https://discuss.elastic.co/u/Nijal)\
**Replies:** 2\
**Last updated:** [November 23, 2023, 1:30pm UTC](https://discuss.elastic.co/t/backing-up-es-indices/347815 "2023-11-23T13:30:54Z")

</div>

I have a few questions about Snapshots, What is the correct approach to save snapshots to long term data store such as tape storage What is the correct proceedure to restore the snapshots stored in the tape storage. Ho…

---

## [Syncing Huge DataSet From MySQL to Elasticsearch](https://discuss.elastic.co/t/syncing-huge-dataset-from-mysql-to-elasticsearch/347853)

<div class="topic-metadata">

**Author:** [@Aswini\_Kumar\_Rout](https://discuss.elastic.co/u/Aswini_Kumar_Rout)\
**Replies:** 0\
**Last updated:** [November 23, 2023, 1:04pm UTC](https://discuss.elastic.co/t/syncing-huge-dataset-from-mysql-to-elasticsearch/347853 "2023-11-23T13:04:53Z")

</div>

Hi Team, We have one requirement to use Elasticsearch in our legacy application which has MySQL datbase and the size of the DB is around 300 GB and with 200 or more tables. So, here I am bit confused that - which would…

---

## [Editing a managed policy can break Kibana](https://discuss.elastic.co/t/editing-a-managed-policy-can-break-kibana/347828)

<div class="topic-metadata">

**Author:** [@DaddyYusk](https://discuss.elastic.co/u/DaddyYusk)\
**Replies:** 2\
**Last updated:** [November 23, 2023, 1:19pm UTC](https://discuss.elastic.co/t/editing-a-managed-policy-can-break-kibana/347828 "2023-11-23T13:19:57Z")

</div>

Hi, After a successful Fleet Server and Elastic Agent deployment, I wanted to tweak the ILM called "logs" and "metrics" which are both "Managed". But when trying to do so, I encounter this well known warning : So af…

---

## [Search template based on list](https://discuss.elastic.co/t/search-template-based-on-list/347852)

<div class="topic-metadata">

**Author:** [@pszemesy](https://discuss.elastic.co/u/pszemesy)\
**Replies:** 0\
**Last updated:** [November 23, 2023, 12:37pm UTC](https://discuss.elastic.co/t/search-template-based-on-list/347852 "2023-11-23T12:37:30Z")

</div>

Hi All, I have an index (contains translations) with the following mappings: document\_name: keyword, ... EN: { content: text, stored\_by: keyword, stored\_at: date, ... } \<\<lang code\>\>: { content: text, store…

---

## [Destination of Audit Logs After Enabling Audit Logging on Kibana](https://discuss.elastic.co/t/destination-of-audit-logs-after-enabling-audit-logging-on-kibana/347846)

<div class="topic-metadata">

**Author:** [@yago82](https://discuss.elastic.co/u/yago82)\
**Replies:** 1\
**Last updated:** [November 23, 2023, 12:16pm UTC](https://discuss.elastic.co/t/destination-of-audit-logs-after-enabling-audit-logging-on-kibana/347846 "2023-11-23T12:16:19Z")

</div>

Hi, I am currently exploring the functionalities related to audit logging on Kibana and have a technical query regarding the destination of these logs once audit logging is enabled. Specifically, upon enabling audit lo…

---

## [Rollup then backup indices](https://discuss.elastic.co/t/rollup-then-backup-indices/346036)

<div class="topic-metadata">

**Author:** [@lstoneir](https://discuss.elastic.co/u/lstoneir)\
**Replies:** 1\
**Last updated:** [November 23, 2023, 12:09pm UTC](https://discuss.elastic.co/t/rollup-then-backup-indices/346036 "2023-11-23T12:09:57Z")

</div>

Hi there, I have a elastic cluster with 5 nodes (each node 1TB) I want to backup my indices, but I dont have enough resources to backup all indices. I want to rollup indices for example my main indices are hourly, I w…

---

## [Sync 2 indices diffrenet remote clusters](https://discuss.elastic.co/t/sync-2-indices-diffrenet-remote-clusters/347851)

<div class="topic-metadata">

**Author:** [@lstoneir](https://discuss.elastic.co/u/lstoneir)\
**Replies:** 0\
**Last updated:** [November 23, 2023, 11:58am UTC](https://discuss.elastic.co/t/sync-2-indices-diffrenet-remote-clusters/347851 "2023-11-23T11:58:50Z")

</div>

Hi I have cluser A with index e.g. User\_info I have another cluster named B I want to sync User\_info (B) with User\_info (A) all time!! Can i do this with logstash? how?

---

## [Auditbeat: system/socket dataset setup failed - guess\_inet\_sock failed: timeout while waiting](https://discuss.elastic.co/t/auditbeat-system-socket-dataset-setup-failed-guess-inet-sock-failed-timeout-while-waiting/347850)

<div class="topic-metadata">

**Author:** [@Stefan\_Bauer](https://discuss.elastic.co/u/Stefan_Bauer)\
**Replies:** 0\
**Last updated:** [November 23, 2023, 11:57am UTC](https://discuss.elastic.co/t/auditbeat-system-socket-dataset-setup-failed-guess-inet-sock-failed-timeout-while-waiting/347850 "2023-11-23T11:57:52Z")

</div>

Hi folks, auditbeat fails on 2 Ubuntu 20 systems with the following errors several times a day: auditbeat\[1929153\]: {"log.level":"error","@timestamp":"2023-11-23T08:29:49.984+0100","log.origin":{"file.name":"instance/b…

---

## [Elasticsearch.yml configuration file is missing in linux](https://discuss.elastic.co/t/elasticsearch-yml-configuration-file-is-missing-in-linux/347839)

<div class="topic-metadata">

**Author:** [@krishnapro](https://discuss.elastic.co/u/krishnapro)\
**Replies:** 1\
**Last updated:** [November 23, 2023, 11:48am UTC](https://discuss.elastic.co/t/elasticsearch-yml-configuration-file-is-missing-in-linux/347839 "2023-11-23T11:48:47Z")

</div>

I have installed elasticsearch in linux mint but elasticsearch.yml file is missing. I have uninstall and reinstall it but same problem. I don't know what do please help me to fix it.

---

## [Correct user permission / role when using kibana](https://discuss.elastic.co/t/correct-user-permission-role-when-using-kibana/347845)

<div class="topic-metadata">

**Author:** [@yabetsu93](https://discuss.elastic.co/u/yabetsu93)\
**Replies:** 0\
**Last updated:** [November 23, 2023, 11:39am UTC](https://discuss.elastic.co/t/correct-user-permission-role-when-using-kibana/347845 "2023-11-23T11:39:06Z")

</div>

Good Day, I was able to deploy kibana helm-charts but setting up kibana\_system and password generated everytime i logged in as kibana\_admin role or elastic after logged out i got 403 forbidden it is kinda annoying and w…

---

## [CSV::MalformedCSVError: Missing or stray quote in line 1](https://discuss.elastic.co/t/csv-missing-or-stray-quote-in-line-1/346726)

<div class="topic-metadata">

**Author:** [@parosio](https://discuss.elastic.co/u/parosio)\
**Replies:** 1\
**Last updated:** [November 23, 2023, 11:05am UTC](https://discuss.elastic.co/t/csv-missing-or-stray-quote-in-line-1/346726 "2023-11-23T11:05:25Z")

</div>

Hello, I've read the previuos posts on this topic (and related), but still have problems with csv files containing windows command lines... For example: 98792634295,https://falcon.eu-1.crowdstrike.com/activity/detecti…

---

## [Getting Timeout after sometime](https://discuss.elastic.co/t/getting-timeout-after-sometime/347494)

<div class="topic-metadata">

**Author:** [@deepak\_Bahuguna](https://discuss.elastic.co/u/deepak_Bahuguna)\
**Replies:** 4\
**Last updated:** [November 23, 2023, 10:55am UTC](https://discuss.elastic.co/t/getting-timeout-after-sometime/347494 "2023-11-23T10:55:53Z")

</div>

HI Guys, I am new to Elastic, Kibana. I have downloaded the Elastic and Kibana then I run both and it worked fine. What is problem is after installing I have kept it opened in evening and when I see it morning it has sh…

---

## [Crawling authenticated web sites - Cookies](https://discuss.elastic.co/t/crawling-authenticated-web-sites-cookies/347644)

<div class="topic-metadata">

**Author:** [@sebastianboelling](https://discuss.elastic.co/u/sebastianboelling)\
**Replies:** 1\
**Last updated:** [November 23, 2023, 10:31am UTC](https://discuss.elastic.co/t/crawling-authenticated-web-sites-cookies/347644 "2023-11-23T10:31:04Z")

</div>

Hi all, we are trying to crawl pages which require Basic Authentication. Once authenticated a session is established on the server and a cookie is responded. This cookie identifies the the user on the next request and n…

---

## [How to get a NodeClient inside a plugin?](https://discuss.elastic.co/t/how-to-get-a-nodeclient-inside-a-plugin/347703)

<div class="topic-metadata">

**Author:** [@Azizi\_BESSEM](https://discuss.elastic.co/u/Azizi_BESSEM)\
**Replies:** 5\
**Last updated:** [November 23, 2023, 10:13am UTC](https://discuss.elastic.co/t/how-to-get-a-nodeclient-inside-a-plugin/347703 "2023-11-23T10:13:36Z")

</div>

I am currently working on developing a schedule plugin for Elasticsearch. The objective is to display only the index number every 5 minutes. However, I am encountering an issue where the NodeClient is consistently null. …

---

## [Multy-tenany elasticsearch](https://discuss.elastic.co/t/multy-tenany-elasticsearch/347832)

<div class="topic-metadata">

**Author:** [@Azizi\_BESSEM](https://discuss.elastic.co/u/Azizi_BESSEM)\
**Replies:** 0\
**Last updated:** [November 23, 2023, 10:05am UTC](https://discuss.elastic.co/t/multy-tenany-elasticsearch/347832 "2023-11-23T10:05:24Z")

</div>

I am currently working on implementing multi-tenancy in Elasticsearch and have come across two prominent approaches: using a shared index across multiple tenants and having a dedicated index per tenant. As part of my res…

---

## [\["org.elasticsearch.bootstrap.StartupException: ElasticsearchException\[failed to bind service\]; nested: CorruptIndexException\[codec footer mismatch (file truncated?)](https://discuss.elastic.co/t/org-elasticsearch-bootstrap-startupexception-elasticsearchexception-failed-to-bind-service-nested-corruptindexexception-codec-footer-mismatch-file-truncated/347642)

<div class="topic-metadata">

**Author:** [@lins](https://discuss.elastic.co/u/lins)\
**Replies:** 11\
**Last updated:** [November 23, 2023, 8:23am UTC](https://discuss.elastic.co/t/org-elasticsearch-bootstrap-startupexception-elasticsearchexception-failed-to-bind-service-nested-corruptindexexception-codec-footer-mismatch-file-truncated/347642 "2023-11-23T08:23:18Z")

</div>

{"type": "server", "timestamp": "2023-11-21T09:52:52,412Z", "level": "ERROR", "component": "o.e.b.ElasticsearchUncaughtExceptionHandler", "cluster.name": "elasticsearch", "node.name": "elasticsearch-es-master-1", "messag…

---

## [Snowflake to Elasticsearch](https://discuss.elastic.co/t/snowflake-to-elasticsearch/347543)

<div class="topic-metadata">

**Author:** [@Shalinicts](https://discuss.elastic.co/u/Shalinicts)\
**Replies:** 8\
**Last updated:** [November 23, 2023, 8:14am UTC](https://discuss.elastic.co/t/snowflake-to-elasticsearch/347543 "2023-11-23T08:14:57Z")

</div>

Hi Team , We are trying to pull data from Snowflake database to Elasticsaerch via Logstash JDBC plugin Input Config: input { jdbc { jdbc\_driver\_library =\> "/usr/share/logstash/logstash-core/lib/jars/snowflake-jd…

---

## [SSL Certificate issues](https://discuss.elastic.co/t/ssl-certificate-issues/347390)

<div class="topic-metadata">

**Author:** [@nvanalphen](https://discuss.elastic.co/u/nvanalphen)\
**Replies:** 12\
**Last updated:** [November 23, 2023, 8:14am UTC](https://discuss.elastic.co/t/ssl-certificate-issues/347390 "2023-11-23T08:14:56Z")

</div>

I am trying to set up a server to evaluate and determine if/how we can use this solution. Unfortunately I am going mad trying to set it up. I have been trying, searching, reading and trying again for over a week now and…

---

## [How to debug http.max\_content\_length on elasticsearch](https://discuss.elastic.co/t/how-to-debug-http-max-content-length-on-elasticsearch/347754)

<div class="topic-metadata">

**Author:** [@INS](https://discuss.elastic.co/u/INS)\
**Replies:** 0\
**Last updated:** [November 22, 2023, 3:03pm UTC](https://discuss.elastic.co/t/how-to-debug-http-max-content-length-on-elasticsearch/347754 "2023-11-22T15:03:21Z")

</div>

Hi Is it possible to trace a log on elasticsearch for http.max\_content\_length ? Thx!

---

## [Elasticapm.properties didn't read in java springboot](https://discuss.elastic.co/t/elasticapm-properties-didnt-read-in-java-springboot/347824)

<div class="topic-metadata">

**Author:** [@kasunpurnima](https://discuss.elastic.co/u/kasunpurnima)\
**Replies:** 0\
**Last updated:** [November 23, 2023, 7:17am UTC](https://discuss.elastic.co/t/elasticapm-properties-didnt-read-in-java-springboot/347824 "2023-11-23T07:17:46Z")

</div>

Hi, Im using below services, java 8 elasticsearch-8.2.3 kibana-8.2.3 apm-server-8.2.3 elastic-apm-agent-1.44.jar When im using elasticapm.properties below details its not take it and not going hit APM service\_name…

---

## [Ingest Microsoft Intune Audit Logs to Elastic](https://discuss.elastic.co/t/ingest-microsoft-intune-audit-logs-to-elastic/346633)

<div class="topic-metadata">

**Author:** [@momher](https://discuss.elastic.co/u/momher)\
**Replies:** 2\
**Last updated:** [November 23, 2023, 6:14am UTC](https://discuss.elastic.co/t/ingest-microsoft-intune-audit-logs-to-elastic/346633 "2023-11-23T06:14:32Z")

</div>

Do any one have done ingesting their Microsoft Intune Audit Logs to elastic for alerting purposes? For example, if there's a specific Audit Logs on Intune it gets ingested to Elastic to create an alert ticket.

---

## [Send output socket tcp or udp in line protocol format](https://discuss.elastic.co/t/send-output-socket-tcp-or-udp-in-line-protocol-format/347810)

<div class="topic-metadata">

**Author:** [@Indeed2000](https://discuss.elastic.co/u/Indeed2000)\
**Replies:** 0\
**Last updated:** [November 23, 2023, 4:37am UTC](https://discuss.elastic.co/t/send-output-socket-tcp-or-udp-in-line-protocol-format/347810 "2023-11-23T04:37:15Z")

</div>

Hi need to send data with tcp or udp in line protocol format instead on influx or http output plugin. Is it possible to create message format like http output plugin? Any idea? Thank

---

## [Logstash to influxdb2 aggregate datapoints issue](https://discuss.elastic.co/t/logstash-to-influxdb2-aggregate-datapoints-issue/347809)

<div class="topic-metadata">

**Author:** [@Indeed2000](https://discuss.elastic.co/u/Indeed2000)\
**Replies:** 0\
**Last updated:** [November 23, 2023, 4:14am UTC](https://discuss.elastic.co/t/logstash-to-influxdb2-aggregate-datapoints-issue/347809 "2023-11-23T04:14:32Z")

</div>

Hi I have lots of log lines like this in exact same time, when i try to use logstash to pars and send to influxdb2, influx or ligstash aggregates some lines! e.g here is the sample lines that aggregate is I\[847676\] 20…

---

## [Elasticsearch Cluster Down automatically](https://discuss.elastic.co/t/elasticsearch-cluster-down-automatically/347808)

<div class="topic-metadata">

**Author:** [@VijayIQA](https://discuss.elastic.co/u/VijayIQA)\
**Replies:** 0\
**Last updated:** [November 23, 2023, 3:49am UTC](https://discuss.elastic.co/t/elasticsearch-cluster-down-automatically/347808 "2023-11-23T03:49:13Z")

</div>

Hi Team, I deployed Elasticsearch Cluster on docker with 2 nodes (two containers). everything working well. but due to some technical issues sometimes need to restart the containers at that time master node up and runnin…

---

## [Reason: Setting "monitoring.enabled" doesn't exist](https://discuss.elastic.co/t/reason-setting-monitoring-enabled-doesnt-exist/347731)

<div class="topic-metadata">

**Author:** [@Vivi\_Allen](https://discuss.elastic.co/u/Vivi_Allen)\
**Replies:** 4\
**Last updated:** [November 23, 2023, 3:48am UTC](https://discuss.elastic.co/t/reason-setting-monitoring-enabled-doesnt-exist/347731 "2023-11-23T03:48:33Z")

</div>

I want to enable monitor for logstash with metricbeat. Following this guide Collect Logstash monitoring data with Metricbeat | Logstash Reference \[8.11\] | Elastic, I add monitoring.enabled: false to the logstash.yml. T…

---

## [ElasticsearchTemplate/client 8.7.1 with springboot 3.x Aggregation](https://discuss.elastic.co/t/elasticsearchtemplate-client-8-7-1-with-springboot-3-x-aggregation/347740)

<div class="topic-metadata">

**Author:** [@Priyank07](https://discuss.elastic.co/u/Priyank07)\
**Replies:** 0\
**Last updated:** [November 22, 2023, 1:33pm UTC](https://discuss.elastic.co/t/elasticsearchtemplate-client-8-7-1-with-springboot-3-x-aggregation/347740 "2023-11-22T13:33:02Z")

</div>

Hi, I want to query elasticsearch document with aggregation. My use case : I want to sum the amount based on term aggregation on a particular field. I am able to do it with elasticsearch 7.17.3. Now I have to update i…

[Previous page](https://discuss.elastic.co/latest.md?page=473)

[Next page](https://discuss.elastic.co/latest.md?page=475)
