# Latest

**URL:** https://discuss.elastic.co/latest.md?page=477

[Latest](https://discuss.elastic.co/latest.md) · [Categories](https://discuss.elastic.co/categories.md) · [Tags](https://discuss.elastic.co/tags.md)

**Page:** 478

---

## [Advantage of logstash input/output plugin over http input/output plugin](https://discuss.elastic.co/t/advantage-of-logstash-input-output-plugin-over-http-input-output-plugin/347659)

<div class="topic-metadata">

**Author:** [@Thiruvikraman](https://discuss.elastic.co/u/Thiruvikraman)\
**Replies:** 1\
**Last updated:** [November 21, 2023, 6:09pm UTC](https://discuss.elastic.co/t/advantage-of-logstash-input-output-plugin-over-http-input-output-plugin/347659 "2023-11-21T18:09:45Z")

</div>

Logstash to Logstash considerations This is the preferred method to implement Logstash-to-Logstash. It replaces Logstash-to-Logstash: HTTP output to HTTP input and has these considerations: It relies on HTTP as the co…

---

## [Mapping issue](https://discuss.elastic.co/t/mapping-issue/347532)

<div class="topic-metadata">

**Author:** [@VirusProtect](https://discuss.elastic.co/u/VirusProtect)\
**Replies:** 1\
**Last updated:** [November 21, 2023, 5:37pm UTC](https://discuss.elastic.co/t/mapping-issue/347532 "2023-11-21T17:37:33Z")

</div>

Hi, I'm working with fields changes.to and changes.from in Elasticsearch. These fields sometimes hold simple strings, and other times, they are objects with various values like address, name, etc. I'm facing an error: "…

---

## [Elasticsearch Audit Logs decipher](https://discuss.elastic.co/t/elasticsearch-audit-logs-decipher/347652)

<div class="topic-metadata">

**Author:** [@Brian-cf1](https://discuss.elastic.co/u/Brian-cf1)\
**Replies:** 2\
**Last updated:** [November 21, 2023, 4:33pm UTC](https://discuss.elastic.co/t/elasticsearch-audit-logs-decipher/347652 "2023-11-21T16:33:52Z")

</div>

I am looking at the Elasticsearch Audit logs and i am getting an authentication denied for User Elastic, why would our servers be authenticating against our Elasticsearch nodes when we are getting logs from the beats and…

---

## [Accessing fields in last\_doc scripted metric aggregation in a transform](https://discuss.elastic.co/t/accessing-fields-in-last-doc-scripted-metric-aggregation-in-a-transform/345403)

<div class="topic-metadata">

**Author:** [@Mark\_Duncan](https://discuss.elastic.co/u/Mark_Duncan)\
**Replies:** 5\
**Last updated:** [November 21, 2023, 4:12pm UTC](https://discuss.elastic.co/t/accessing-fields-in-last-doc-scripted-metric-aggregation-in-a-transform/345403 "2023-11-21T16:12:13Z")

</div>

If I have implemented this last\_doc scripted metric aggregation in a transform example, how could I access fields within the returned doc (let's imagine there is a field "price" in the last\_doc), in bucket script metric …

---

## [Customizing Time Filter Quick Ranges in Kibana: dynamicly adapat based on a specific time](https://discuss.elastic.co/t/customizing-time-filter-quick-ranges-in-kibana-dynamicly-adapat-based-on-a-specific-time/347485)

<div class="topic-metadata">

**Author:** [@Behnam.R](https://discuss.elastic.co/u/Behnam.R)\
**Replies:** 4\
**Last updated:** [November 21, 2023, 2:50pm UTC](https://discuss.elastic.co/t/customizing-time-filter-quick-ranges-in-kibana-dynamicly-adapat-based-on-a-specific-time/347485 "2023-11-21T14:50:28Z")

</div>

I'm looking to customize Kibana's Time Filter Quick Ranges with a specific date math expression and need advice on feasibility and syntax. The expression I want to use is: { "from": "((now-6h)/d)+6h", "to": "now", …

---

## [TLS error caused by: SSLError(hostname 'my\_ip' doesn't match either of 'FE80:0:0:0:E062:44FF:FEA0:4B20', 'platform',](https://discuss.elastic.co/t/tls-error-caused-by-sslerror-hostname-my-ip-doesnt-match-either-of-fe800e062fea0-4b20-platform/347648)

<div class="topic-metadata">

**Author:** [@shuaiqi\_duan](https://discuss.elastic.co/u/shuaiqi_duan)\
**Replies:** 0\
**Last updated:** [November 21, 2023, 2:49pm UTC](https://discuss.elastic.co/t/tls-error-caused-by-sslerror-hostname-my-ip-doesnt-match-either-of-fe800e062fea0-4b20-platform/347648 "2023-11-21T14:49:08Z")

</div>

I'm new to Elasticsearch. I followed the official documentation to install and start a single-node Elasticsearch service. The service automatically enabled security features and generated a CA certificate for me, which i…

---

## [Impossible to create a second index](https://discuss.elastic.co/t/impossible-to-create-a-second-index/347627)

<div class="topic-metadata">

**Author:** [@Christian\_1974](https://discuss.elastic.co/u/Christian_1974)\
**Replies:** 6\
**Last updated:** [November 21, 2023, 2:13pm UTC](https://discuss.elastic.co/t/impossible-to-create-a-second-index/347627 "2023-11-21T14:13:32Z")

</div>

Hi, (Sorry, I am not english. I am french, so, please, be patient with me, in english :)). I created a configuration to test logstash. The configuration log my local syslog in Kibana. That, that works. But if I try to …

---

## [Kibana 8.6 how to show the data per day per hour at the same time](https://discuss.elastic.co/t/kibana-8-6-how-to-show-the-data-per-day-per-hour-at-the-same-time/346812)

<div class="topic-metadata">

**Author:** [@RobertC1](https://discuss.elastic.co/u/RobertC1)\
**Replies:** 2\
**Last updated:** [November 21, 2023, 1:40pm UTC](https://discuss.elastic.co/t/kibana-8-6-how-to-show-the-data-per-day-per-hour-at-the-same-time/346812 "2023-11-21T13:40:47Z")

</div>

Hi guys! I am creating a dashboard where it has to show the data per day & per hour. I add 1 histogram field using @timestamp with minimal interval by day. Another histogram field using @timestamp with minimal inte…

---

## [Elastic apm tenancy - How it works?](https://discuss.elastic.co/t/elastic-apm-tenancy-how-it-works/347555)

<div class="topic-metadata">

**Author:** [@miguel.longo](https://discuss.elastic.co/u/miguel.longo)\
**Replies:** 0\
**Last updated:** [November 20, 2023, 9:22pm UTC](https://discuss.elastic.co/t/elastic-apm-tenancy-how-it-works/347555 "2023-11-20T21:22:35Z")

</div>

Kibana version: 8.6.2 Elasticsearch version: 8.6.2 APM Server version: 8.6.2 APM Agent language and version: Java elastic-apm-agent.jar:1.43.0 I need help to understand how tenancy works in the elasticsearch, kibana …

---

## [Error: fail to enroll: fail to execute request to fleet-server: x509: cannot validate certificate for because it doesn't contain any IP SANs I'](https://discuss.elastic.co/t/error-fail-to-enroll-fail-to-execute-request-to-fleet-server-x509-cannot-validate-certificate-for-because-it-doesnt-contain-any-ip-sans-i/347576)

<div class="topic-metadata">

**Author:** [@Virtual\_Box](https://discuss.elastic.co/u/Virtual_Box)\
**Replies:** 3\
**Last updated:** [November 21, 2023, 1:05pm UTC](https://discuss.elastic.co/t/error-fail-to-enroll-fail-to-execute-request-to-fleet-server-x509-cannot-validate-certificate-for-because-it-doesnt-contain-any-ip-sans-i/347576 "2023-11-21T13:05:21Z")

</div>

Hello there! I have a problem with fleet server. When I'm trying to install fleet server, I had a next error: Error: fail to enroll: fail to execute request to fleet-server: x509: cannot validate certificate for becaus…

---

## [How we can use Must Clause(for searching data) in Elastic.Clients.Elasticsearch library](https://discuss.elastic.co/t/how-we-can-use-must-clause-for-searching-data-in-elastic-clients-elasticsearch-library/347636)

<div class="topic-metadata">

**Author:** [@Jahanzaib](https://discuss.elastic.co/u/Jahanzaib)\
**Replies:** 0\
**Last updated:** [November 21, 2023, 12:59pm UTC](https://discuss.elastic.co/t/how-we-can-use-must-clause-for-searching-data-in-elastic-clients-elasticsearch-library/347636 "2023-11-21T12:59:13Z")

</div>

Hi Everyone, I am new here and i do not know to ask a question. I am using Elastic.Clients.Elasticsearch library not Nest. i have issue so i want to discuss with you. In this snipped i made three queries and they are…

---

## [Why it is showing java error in elastic log](https://discuss.elastic.co/t/why-it-is-showing-java-error-in-elastic-log/347622)

<div class="topic-metadata">

**Author:** [@baber1223](https://discuss.elastic.co/u/baber1223)\
**Replies:** 0\
**Last updated:** [November 21, 2023, 10:44am UTC](https://discuss.elastic.co/t/why-it-is-showing-java-error-in-elastic-log/347622 "2023-11-21T10:44:42Z")

</div>

It is showing follow in my elasticsearch log : at org.elasticsearch.ingest.geoip.GeoIpDownloader.updateDatabases(GeoIpDownloader.java:140) ~\[?:?\] at org.elasticsearch.ingest.geoip.GeoIpDownloader.runDownloader(G…

---

## [Kubernetes Autodiscovery](https://discuss.elastic.co/t/kubernetes-autodiscovery/347610)

<div class="topic-metadata">

**Author:** [@xyz7](https://discuss.elastic.co/u/xyz7)\
**Replies:** 1\
**Last updated:** [November 21, 2023, 11:15am UTC](https://discuss.elastic.co/t/kubernetes-autodiscovery/347610 "2023-11-21T11:15:25Z")

</div>

Hi @jsoriano, Below topic suggests add\_kubernetes\_metadata is enabled by default if using hints-based autodiscover as mentioned in below reference configuration. My filebeat config autodiscover part is like this: …

---

## [Use difference between two numeric values as query criteria in kibana](https://discuss.elastic.co/t/use-difference-between-two-numeric-values-as-query-criteria-in-kibana/347400)

<div class="topic-metadata">

**Author:** [@markus](https://discuss.elastic.co/u/markus)\
**Replies:** 6\
**Last updated:** [November 21, 2023, 10:38am UTC](https://discuss.elastic.co/t/use-difference-between-two-numeric-values-as-query-criteria-in-kibana/347400 "2023-11-21T10:38:09Z")

</div>

Hi, we have a logsource that we are ingesting into kibana using logstash fileinput. The logsource contains amon other things two numerical values. The fields are indexed as numerical values. What I'd like to do is fin…

---

## [Filebeat pagination doesn't support '@' in field name - Azure GraphAPI](https://discuss.elastic.co/t/filebeat-pagination-doesnt-support-in-field-name-azure-graphapi/347621)

<div class="topic-metadata">

**Author:** [@mohammadabubakr1998](https://discuss.elastic.co/u/mohammadabubakr1998)\
**Replies:** 0\
**Last updated:** [November 21, 2023, 10:36am UTC](https://discuss.elastic.co/t/filebeat-pagination-doesnt-support-in-field-name-azure-graphapi/347621 "2023-11-21T10:36:16Z")

</div>

I'm using Filebeat HTTPJson to get logs from Azure using Graph API. I'm facing issues while implementing pagination with it as Azure GraphAPI returns the next page link in a field which contains @ in its key i.e. @odata…

---

## [How to copy the data from an index of 150 GB size to another](https://discuss.elastic.co/t/how-to-copy-the-data-from-an-index-of-150-gb-size-to-another/347574)

<div class="topic-metadata">

**Author:** [@Mohan91](https://discuss.elastic.co/u/Mohan91)\
**Replies:** 1\
**Last updated:** [November 21, 2023, 10:15am UTC](https://discuss.elastic.co/t/how-to-copy-the-data-from-an-index-of-150-gb-size-to-another/347574 "2023-11-21T10:15:15Z")

</div>

I have an index "Index A" of size 150+ GB, there are few fields which needs to be converted to NESTED and for few fields the type to be changed from "keyword" to "text" and vice versa. I have created a new index "Index …

---

## [First thoughts on ES|QL](https://discuss.elastic.co/t/first-thoughts-on-es-ql/347607)

<div class="topic-metadata">

**Author:** [@Wolfram\_Haussig](https://discuss.elastic.co/u/Wolfram_Haussig)\
**Replies:** 1\
**Last updated:** [November 21, 2023, 10:01am UTC](https://discuss.elastic.co/t/first-thoughts-on-es-ql/347607 "2023-11-21T10:01:48Z")

</div>

Dear all, We are currently trying out the new ES|QL query language and as far as I have used it it is a great improvement! The flexibility and the relatively easy grammar will surely make this my preferred language in t…

---

## [Build IndexSettings from two IndexSettings](https://discuss.elastic.co/t/build-indexsettings-from-two-indexsettings/347611)

<div class="topic-metadata">

**Author:** [@Ben5](https://discuss.elastic.co/u/Ben5)\
**Replies:** 0\
**Last updated:** [November 21, 2023, 9:45am UTC](https://discuss.elastic.co/t/build-indexsettings-from-two-indexsettings/347611 "2023-11-21T09:45:15Z")

</div>

Hi, Using Java Transport Client, I was able to build index Settings from two Settings like that: Settings.builder().put(SETTINGS\_1).put(SETTINGS\_2).build() How can I do the same with Elasticsearch Client and IndexSett…

---

## [SSL Error when running logstash avro schema registry in ubuntu](https://discuss.elastic.co/t/ssl-error-when-running-logstash-avro-schema-registry-in-ubuntu/347605)

<div class="topic-metadata">

**Author:** [@amaleswar](https://discuss.elastic.co/u/amaleswar)\
**Replies:** 0\
**Last updated:** [November 21, 2023, 9:19am UTC](https://discuss.elastic.co/t/ssl-error-when-running-logstash-avro-schema-registry-in-ubuntu/347605 "2023-11-21T09:19:59Z")

</div>

I\`m trying to migrate from CentOS to Ubuntu. Able to install the Logstash and added registry info and running the config locally to make sure, it is running as expected. But it is throwing below error. \[ERROR\] 2023-11-2…

---

## [Filebeat restarting continuously with high memory usage on version 7.9.0](https://discuss.elastic.co/t/filebeat-restarting-continuously-with-high-memory-usage-on-version-7-9-0/346132)

<div class="topic-metadata">

**Author:** [@kait](https://discuss.elastic.co/u/kait)\
**Replies:** 9\
**Last updated:** [November 21, 2023, 9:07am UTC](https://discuss.elastic.co/t/filebeat-restarting-continuously-with-high-memory-usage-on-version-7-9-0/346132 "2023-11-21T09:07:43Z")

</div>

Hi, Filebeat is deployed as daemonset in all kubernetes nodes and it's restarting continuously in specific nodes which is loaded due to high memory usage. Filebeat version : 7.9.0 In filebeat.yml , tried to disable th…

---

## [Recover file from quarantine](https://discuss.elastic.co/t/recover-file-from-quarantine/346973)

<div class="topic-metadata">

**Author:** [@GKre](https://discuss.elastic.co/u/GKre)\
**Replies:** 9\
**Last updated:** [November 21, 2023, 8:32am UTC](https://discuss.elastic.co/t/recover-file-from-quarantine/346973 "2023-11-21T08:32:22Z")

</div>

well - Security quarantined nnotes.dll that is part of "HCL Notes" Installation. Now i am trying to find out how to get back the file without the need to reinstall the application. I created a rule exception and i can …

---

## [Logstash buffer for Sentinel - Architecture questions](https://discuss.elastic.co/t/logstash-buffer-for-sentinel-architecture-questions/347596)

<div class="topic-metadata">

**Author:** [@zatury](https://discuss.elastic.co/u/zatury)\
**Replies:** 1\
**Last updated:** [November 21, 2023, 8:11am UTC](https://discuss.elastic.co/t/logstash-buffer-for-sentinel-architecture-questions/347596 "2023-11-21T08:11:23Z")

</div>

Hello, My company is currently transitioning from Splunk to Sentinel, despite my preference for Elastic. Sentinel utilizes AMA agents to gather logs from various sources, listening on port 514. However, a significant ch…

---

## [Elastic-agents goes offline and get back online status frequently](https://discuss.elastic.co/t/elastic-agents-goes-offline-and-get-back-online-status-frequently/347195)

<div class="topic-metadata">

**Author:** [@cLaYYs](https://discuss.elastic.co/u/cLaYYs)\
**Replies:** 5\
**Last updated:** [November 21, 2023, 7:46am UTC](https://discuss.elastic.co/t/elastic-agents-goes-offline-and-get-back-online-status-frequently/347195 "2023-11-21T07:46:48Z")

</div>

Hi All, Version:8.9 OS:Windows Server I have encountered with this problem so recently. And it is not occurs for all elastic-agents. it happens for 4 elastic-agents. The problem is the agent status seems offline whe…

---

## [Send logs from filebeat to logstash via NGINX reverse proxy](https://discuss.elastic.co/t/send-logs-from-filebeat-to-logstash-via-nginx-reverse-proxy/347590)

<div class="topic-metadata">

**Author:** [@R\_H\_O\_M\_B\_I\_X](https://discuss.elastic.co/u/R_H_O_M_B_I_X)\
**Replies:** 0\
**Last updated:** [November 21, 2023, 7:22am UTC](https://discuss.elastic.co/t/send-logs-from-filebeat-to-logstash-via-nginx-reverse-proxy/347590 "2023-11-21T07:22:34Z")

</div>

Hi I'm looking for a way to forward my logs from filebeat where filebeat is reading logs from my local machine file and sending it to my private server in which logstash is installed via nginx reverse proxy where nginx …

---

## [File beat Multiline issue](https://discuss.elastic.co/t/file-beat-multiline-issue/347567)

<div class="topic-metadata">

**Author:** [@apsh](https://discuss.elastic.co/u/apsh)\
**Replies:** 0\
**Last updated:** [November 21, 2023, 2:36am UTC](https://discuss.elastic.co/t/file-beat-multiline-issue/347567 "2023-11-21T02:36:51Z")

</div>

Hello! I am trying to use filebeat's multiline support to combine Node.js exceptions into a single message. However, all errors start with a date and there is no unique identifier to create a pattern for this error log. …

---

## ["Connection reset by peer" message](https://discuss.elastic.co/t/connection-reset-by-peer-message/347582)

<div class="topic-metadata">

**Author:** [@hjazz6](https://discuss.elastic.co/u/hjazz6)\
**Replies:** 0\
**Last updated:** [November 21, 2023, 6:28am UTC](https://discuss.elastic.co/t/connection-reset-by-peer-message/347582 "2023-11-21T06:28:13Z")

</div>

Hi, I'm using ES and filebeat v8.8.0. I noticed that every few minutes, I would get the "Connection reset by peer" message in my filebeat logs, and then it would reconnect itself to ES. The only thing that has changed …

---

## [Disabling GeoIP processor](https://discuss.elastic.co/t/disabling-geoip-processor/347581)

<div class="topic-metadata">

**Author:** [@hjazz6](https://discuss.elastic.co/u/hjazz6)\
**Replies:** 0\
**Last updated:** [November 21, 2023, 6:24am UTC](https://discuss.elastic.co/t/disabling-geoip-processor/347581 "2023-11-21T06:24:11Z")

</div>

Hi, I have currently set "ingest.geoip.downloader.enabled" : "false" in my elasticsearch.yml file as I am using offline databases. I'm using ES v8.8.0, and filebeat to ingest data into ES. I want to do some testing, wh…

---

## [Hashtag searches and Japanese full text search](https://discuss.elastic.co/t/hashtag-searches-and-japanese-full-text-search/347324)

<div class="topic-metadata">

**Author:** [@hari-ram-s](https://discuss.elastic.co/u/hari-ram-s)\
**Replies:** 1\
**Last updated:** [November 21, 2023, 6:11am UTC](https://discuss.elastic.co/t/hashtag-searches-and-japanese-full-text-search/347324 "2023-11-21T06:11:59Z")

</div>

We are trying to incorporate hashtag searches and Japanese full text searches in our data. We were able to achieve them separately but when we try to combine the two configs together, it doesn't work as expected. I foun…

---

## [Elastic Synthetics : Global Location on my ON-Prem Setup](https://discuss.elastic.co/t/elastic-synthetics-global-location-on-my-on-prem-setup/347341)

<div class="topic-metadata">

**Author:** [@Rudra\_Prakash\_Pal](https://discuss.elastic.co/u/Rudra_Prakash_Pal)\
**Replies:** 2\
**Last updated:** [November 21, 2023, 4:01am UTC](https://discuss.elastic.co/t/elastic-synthetics-global-location-on-my-on-prem-setup/347341 "2023-11-21T04:01:28Z")

</div>

Hi All, I have Elastic SETUP running in On-Prem \[Self-Managed\]. I am running Synthetics multi step Journeys with Private location setups, Is there a way we can connect with Elastic Global Locations and run my monitors f…

---

## [GraphQL and tracing](https://discuss.elastic.co/t/graphql-and-tracing/347132)

<div class="topic-metadata">

**Author:** [@samiujan](https://discuss.elastic.co/u/samiujan)\
**Replies:** 3\
**Last updated:** [November 21, 2023, 3:56am UTC](https://discuss.elastic.co/t/graphql-and-tracing/347132 "2023-11-21T03:56:07Z")

</div>

Hi I am curious about this article: https://github.com/elastic/apm/blob/main/specs/agents/tracing-instrumentation-graphql.md I have implemented tracing in an Apollo Server running inside NestJS but I see a big block of…

[Previous page](https://discuss.elastic.co/latest.md?page=476)

[Next page](https://discuss.elastic.co/latest.md?page=478)
