# Latest

**URL:** https://discuss.elastic.co/latest.md?page=480

[Latest](https://discuss.elastic.co/latest.md) · [Categories](https://discuss.elastic.co/categories.md) · [Tags](https://discuss.elastic.co/tags.md)

**Page:** 481

---

## [403 auth error when using the filebeat input azure-blob-storage (error: Request date header too old)](https://discuss.elastic.co/t/403-auth-error-when-using-the-filebeat-input-azure-blob-storage-error-request-date-header-too-old/343089)

<div class="topic-metadata">

**Author:** [@djesus](https://discuss.elastic.co/u/djesus)\
**Replies:** 8\
**Last updated:** [November 17, 2023, 2:27pm UTC](https://discuss.elastic.co/t/403-auth-error-when-using-the-filebeat-input-azure-blob-storage-error-request-date-header-too-old/343089 "2023-11-17T14:27:12Z")

</div>

Hi , while using the azure-blob-storage input for filebeat im constantly getting this error. { "@timestamp": "2023-09-14T21:03:15.549Z", "account\_name": "xxxx", "container\_name": "xxxxx", "ecs.version": "1.6.0", "…

---

## [Partition HNSW graph per user, elastic KNN](https://discuss.elastic.co/t/partition-hnsw-graph-per-user-elastic-knn/346394)

<div class="topic-metadata">

**Author:** [@s.ankursonawane](https://discuss.elastic.co/u/s.ankursonawane)\
**Replies:** 4\
**Last updated:** [November 17, 2023, 2:21pm UTC](https://discuss.elastic.co/t/partition-hnsw-graph-per-user-elastic-knn/346394 "2023-11-17T14:21:53Z")

</div>

Hi, I was exploring the performance of Elastic KNN search scaling. I would like to section off my hnsw graph per user as my searches will always be filtered by the user. The only way I can think to do this in ES seems to…

---

## [Custom Elasticsearch queries without using script](https://discuss.elastic.co/t/custom-elasticsearch-queries-without-using-script/347404)

<div class="topic-metadata">

**Author:** [@vickram](https://discuss.elastic.co/u/vickram)\
**Replies:** 0\
**Last updated:** [November 17, 2023, 12:39pm UTC](https://discuss.elastic.co/t/custom-elasticsearch-queries-without-using-script/347404 "2023-11-17T12:39:40Z")

</div>

{"publishDate":"2023-08-06T10:34:00Z","data":{"evalFrequency":"3"}} Above is the sample data that I have in Elasticsearch, where I am struggling to find the right query to get results on the basis of the below condition…

---

## [Beat setup dashboards don't work in different spaces](https://discuss.elastic.co/t/beat-setup-dashboards-dont-work-in-different-spaces/346925)

<div class="topic-metadata">

**Author:** [@litsegaard](https://discuss.elastic.co/u/litsegaard)\
**Replies:** 19\
**Last updated:** [November 17, 2023, 12:58pm UTC](https://discuss.elastic.co/t/beat-setup-dashboards-dont-work-in-different-spaces/346925 "2023-11-17T12:58:02Z")

</div>

I'm running the 8.10.4 stack and having trouble settings up the dashboards for various beats. I run a simple setup command using Docker and all the dashboards for a given beat are imported. However, when clicking a link …

---

## [Ssl between nodes](https://discuss.elastic.co/t/ssl-between-nodes/346742)

<div class="topic-metadata">

**Author:** [@My\_Self](https://discuss.elastic.co/u/My_Self)\
**Replies:** 3\
**Last updated:** [November 17, 2023, 11:09am UTC](https://discuss.elastic.co/t/ssl-between-nodes/346742 "2023-11-17T11:09:37Z")

</div>

hi I'm upgrading to 8.5.1 in a kubernetes solution with helm installation And had an issue with ssl between nodes Found The truststore does not contain any trusted certificate entries after upgrade to 8.0 and used so…

---

## [Filebeat elastic slow logs not showing](https://discuss.elastic.co/t/filebeat-elastic-slow-logs-not-showing/347385)

<div class="topic-metadata">

**Author:** [@VijayIQA](https://discuss.elastic.co/u/VijayIQA)\
**Replies:** 1\
**Last updated:** [November 17, 2023, 10:16am UTC](https://discuss.elastic.co/t/filebeat-elastic-slow-logs-not-showing/347385 "2023-11-17T10:16:01Z")

</div>

Hi Team, I have 2 node Elasticsearch cluster on docker. I was enabled slow logs and logs file storing at /var/log/elasticsearh/\<cluster\_name\_\_index\_indexing\_slowlog.log\> so that i configured filebeat as filebeat.confi…

---

## [How to configure the anonymous login to kibana](https://discuss.elastic.co/t/how-to-configure-the-anonymous-login-to-kibana/347208)

<div class="topic-metadata">

**Author:** [@MahithaSarala](https://discuss.elastic.co/u/MahithaSarala)\
**Replies:** 6\
**Last updated:** [November 17, 2023, 10:15am UTC](https://discuss.elastic.co/t/how-to-configure-the-anonymous-login-to-kibana/347208 "2023-11-17T10:15:52Z")

</div>

Hi Team, After deploying elasticsearch and kibana throgh eck, how to configure anonymous login to kibana 8.5.3 Thanks, SM

---

## [Filebeat elasticsearh](https://discuss.elastic.co/t/filebeat-elasticsearh/347077)

<div class="topic-metadata">

**Author:** [@VijayIQA](https://discuss.elastic.co/u/VijayIQA)\
**Replies:** 13\
**Last updated:** [November 17, 2023, 10:14am UTC](https://discuss.elastic.co/t/filebeat-elasticsearh/347077 "2023-11-17T10:14:04Z")

</div>

Hi Team, I have Elasticsearch database cluster with two nodes in docker. and Kibana configured. while adding filebeat getting an error. filebeat error log pasted here. {"@timestamp":"2023-11-14T04:19:07.634Z", "log.lev…

---

## [Auto reload autodiscover](https://discuss.elastic.co/t/auto-reload-autodiscover/347395)

<div class="topic-metadata">

**Author:** [@Casper\_Thrane](https://discuss.elastic.co/u/Casper_Thrane)\
**Replies:** 0\
**Last updated:** [November 17, 2023, 10:03am UTC](https://discuss.elastic.co/t/auto-reload-autodiscover/347395 "2023-11-17T10:03:35Z")

</div>

Hi Is possible to auto reload the configuration, for autodiscover? Br Casper

---

## [Action variables for a Logs threshold rule](https://discuss.elastic.co/t/action-variables-for-a-logs-threshold-rule/347394)

<div class="topic-metadata">

**Author:** [@Arty](https://discuss.elastic.co/u/Arty)\
**Replies:** 0\
**Last updated:** [November 17, 2023, 9:53am UTC](https://discuss.elastic.co/t/action-variables-for-a-logs-threshold-rule/347394 "2023-11-17T09:53:57Z")

</div>

Hi everyone, I have set up a log threshold rule to retrieve incoming suricata alerts data and send them to another tool using a webhook action. I tried accessing available variables using mustache such as {{#context.al…

---

## [Index Management](https://discuss.elastic.co/t/index-management/347321)

<div class="topic-metadata">

**Author:** [@Ted0011](https://discuss.elastic.co/u/Ted0011)\
**Replies:** 4\
**Last updated:** [November 17, 2023, 6:25am UTC](https://discuss.elastic.co/t/index-management/347321 "2023-11-17T06:25:51Z")

</div>

Hi, I am currently running out of storage on my Wazuh Server Hosted server. And from the search I found "/var/lib/wazuh-indexes/\* " is consuming a lot of disk space. First Question, Will it be okay if I delete all the p…

---

## [Elastic SIEM enterprise SOC use cases](https://discuss.elastic.co/t/elastic-siem-enterprise-soc-use-cases/347031)

<div class="topic-metadata">

**Author:** [@ksrawat88](https://discuss.elastic.co/u/ksrawat88)\
**Replies:** 1\
**Last updated:** [November 17, 2023, 6:20am UTC](https://discuss.elastic.co/t/elastic-siem-enterprise-soc-use-cases/347031 "2023-11-17T06:20:09Z")

</div>

Is anyone using Elastic SIEM enterprise version.? how do you find it day to day SOC uses comparing with splunk and qradar .? also is there any common security use case you were not able to achieve by elastic SIEM .?

---

## [Kibana 8.11.1 Security Update (ESA-2023-25)](https://discuss.elastic.co/t/kibana-8-11-1-security-update-esa-2023-25/347149)

<div class="topic-metadata">

**Author:** [@Levine](https://discuss.elastic.co/u/Levine)\
**Replies:** 2\
**Last updated:** [November 17, 2023, 3:18am UTC](https://discuss.elastic.co/t/kibana-8-11-1-security-update-esa-2023-25/347149 "2023-11-17T03:18:11Z")

</div>

Kibana Insertion of Sensitive Information into Log File (ESA-2023-25) An issue was discovered by Elastic whereby sensitive information may be recorded in Kibana logs in the event of an error. Elastic has released Kibana …

---

## [Migrating Elastic Cluster to another cluster](https://discuss.elastic.co/t/migrating-elastic-cluster-to-another-cluster/347221)

<div class="topic-metadata">

**Author:** [@Putri\_Arsyi](https://discuss.elastic.co/u/Putri_Arsyi)\
**Replies:** 2\
**Last updated:** [November 17, 2023, 2:04am UTC](https://discuss.elastic.co/t/migrating-elastic-cluster-to-another-cluster/347221 "2023-11-17T02:04:34Z")

</div>

Hi, I would like to upgrade elastic to latest version. I'm going to create new cluster with latest version then migrate the data from existing cluster (version 8.6) to new cluster. I'm going to migrate the data also th…

---

## [Elastic APM Agent and OpenTelemetry Agent Issue](https://discuss.elastic.co/t/elastic-apm-agent-and-opentelemetry-agent-issue/347273)

<div class="topic-metadata">

**Author:** [@baoletrg](https://discuss.elastic.co/u/baoletrg)\
**Replies:** 6\
**Last updated:** [November 17, 2023, 1:49am UTC](https://discuss.elastic.co/t/elastic-apm-agent-and-opentelemetry-agent-issue/347273 "2023-11-17T01:49:42Z")

</div>

I have implemented both APM Agent and OpenTelemetry Agent forward data to APM Server, but all the metrics data have this issues: No Pod metrics, No JVM metrics This seem relate to these field metricset.name, metricset.s…

---

## [Filebeat7.12 Does it support writing to multiple kafka clusters](https://discuss.elastic.co/t/filebeat7-12-does-it-support-writing-to-multiple-kafka-clusters/347376)

<div class="topic-metadata">

**Author:** [@13068098071](https://discuss.elastic.co/u/13068098071)\
**Replies:** 0\
**Last updated:** [November 17, 2023, 1:45am UTC](https://discuss.elastic.co/t/filebeat7-12-does-it-support-writing-to-multiple-kafka-clusters/347376 "2023-11-17T01:45:48Z")

</div>

I currently have multiple collection paths and want to write them to different Kafka clusters. For example: /home/work/service1 write kafka cluster1 /home/work/service2;/home/work/service3//home/work/service4 write…

---

## [Where is the bottleneck of KNN retrieval speed? How to analyze?](https://discuss.elastic.co/t/where-is-the-bottleneck-of-knn-retrieval-speed-how-to-analyze/347269)

<div class="topic-metadata">

**Author:** [@Lack](https://discuss.elastic.co/u/Lack)\
**Replies:** 2\
**Last updated:** [November 16, 2023, 11:44pm UTC](https://discuss.elastic.co/t/where-is-the-bottleneck-of-knn-retrieval-speed-how-to-analyze/347269 "2023-11-16T23:44:41Z")

</div>

I have three data nodes, configured as 16 core 64g, with an index of about 19million documents, including 768 dimensional vector fields. The number of fragments is 24, the number of copies is 1, and the total size includ…

---

## [Why plugin needed instead of SDK](https://discuss.elastic.co/t/why-plugin-needed-instead-of-sdk/347370)

<div class="topic-metadata">

**Author:** [@Prabhu\_shanmughapriy](https://discuss.elastic.co/u/Prabhu_shanmughapriy)\
**Replies:** 0\
**Last updated:** [November 16, 2023, 9:28pm UTC](https://discuss.elastic.co/t/why-plugin-needed-instead-of-sdk/347370 "2023-11-16T21:28:15Z")

</div>

Hi, I would like to understand why should we write an Elasticsearch plugin vs Elasticsearch SDK.. This for fuzzy search for indices. Is there any performance reasons with plugins?

---

## [Verify filebeat is reading logs from a docker container](https://discuss.elastic.co/t/verify-filebeat-is-reading-logs-from-a-docker-container/347365)

<div class="topic-metadata">

**Author:** [@Jim\_Maroulis](https://discuss.elastic.co/u/Jim_Maroulis)\
**Replies:** 0\
**Last updated:** [November 16, 2023, 8:24pm UTC](https://discuss.elastic.co/t/verify-filebeat-is-reading-logs-from-a-docker-container/347365 "2023-11-16T20:24:08Z")

</div>

I am attempting to setup reading logs from a docker container running a web server to filebeat to logstash and I cannot seem to get it right. My question is how do I verify if filebeat is even getting anything from the …

---

## [Parsing multiline java execption](https://discuss.elastic.co/t/parsing-multiline-java-execption/347262)

<div class="topic-metadata">

**Author:** [@apsh](https://discuss.elastic.co/u/apsh)\
**Replies:** 3\
**Last updated:** [November 16, 2023, 7:20pm UTC](https://discuss.elastic.co/t/parsing-multiline-java-execption/347262 "2023-11-16T19:20:29Z")

</div>

Hello, I am trying to add multiline to handle javaexception in our logs but still having issue : This is my pattern : paths: - /var/log/tomcat10/\* multiline.type: pattern multiline.pattern: '^\\d{2}-\\w{3}-\\d{4…

---

## [404 When Using Copy Saved Objects to Space API](https://discuss.elastic.co/t/404-when-using-copy-saved-objects-to-space-api/344942)

<div class="topic-metadata">

**Author:** [@ameindel](https://discuss.elastic.co/u/ameindel)\
**Replies:** 2\
**Last updated:** [November 16, 2023, 7:15pm UTC](https://discuss.elastic.co/t/404-when-using-copy-saved-objects-to-space-api/344942 "2023-11-16T19:15:27Z")

</div>

Hello, Elastic! I'm currently trying to use the Copy Saved Objects api (copying an Uptime status Rule from our 'sandbox' space to our 'default' space) and am having issues with 404s. The object exists in the Sandbox sp…

---

## [How to change index pattern used by visualization/widget in kibana dashboard in kibana 7.17.9?](https://discuss.elastic.co/t/how-to-change-index-pattern-used-by-visualization-widget-in-kibana-dashboard-in-kibana-7-17-9/347080)

<div class="topic-metadata">

**Author:** [@Daemon1](https://discuss.elastic.co/u/Daemon1)\
**Replies:** 2\
**Last updated:** [November 16, 2023, 7:09pm UTC](https://discuss.elastic.co/t/how-to-change-index-pattern-used-by-visualization-widget-in-kibana-dashboard-in-kibana-7-17-9/347080 "2023-11-16T19:09:31Z")

</div>

Steps: click on All type\>\>\>Aggregation based\>\>\>data table\>\> select index pattern(index-pattern1) from the list(index-pattern1, index-pattern2, index-pattern3) save the widget. Now I want to change the index-pattern1 u…

---

## [Logstash re-ingests files](https://discuss.elastic.co/t/logstash-re-ingests-files/347358)

<div class="topic-metadata">

**Author:** [@hjsroldan](https://discuss.elastic.co/u/hjsroldan)\
**Replies:** 0\
**Last updated:** [November 16, 2023, 6:21pm UTC](https://discuss.elastic.co/t/logstash-re-ingests-files/347358 "2023-11-16T18:21:11Z")

</div>

Hi, I have a Logstash to Elasticsearch project where logstash collects all the logs from the server and pushes it to elasticsearch. However, seems like the Logstash ingests my logs multiple times. Ingested logs from yes…

---

## [Docker-compose.yml Fleet server failing to start](https://discuss.elastic.co/t/docker-compose-yml-fleet-server-failing-to-start/347356)

<div class="topic-metadata">

**Author:** [@ster1ingArch3r](https://discuss.elastic.co/u/ster1ingArch3r)\
**Replies:** 0\
**Last updated:** [November 16, 2023, 5:20pm UTC](https://discuss.elastic.co/t/docker-compose-yml-fleet-server-failing-to-start/347356 "2023-11-16T17:20:21Z")

</div>

Good Day all, I am working on setting up docker-compose for the elastic stack and I cannot seem to get the fleet-server component to work properly. The dcumentation seems a bit lack luster in this regard. Below is my d…

---

## [How Kibana's parameters env work in docker?](https://discuss.elastic.co/t/how-kibanas-parameters-env-work-in-docker/347354)

<div class="topic-metadata">

**Author:** [@a-fly-fly-bird](https://discuss.elastic.co/u/a-fly-fly-bird)\
**Replies:** 0\
**Last updated:** [November 16, 2023, 4:56pm UTC](https://discuss.elastic.co/t/how-kibanas-parameters-env-work-in-docker/347354 "2023-11-16T16:56:40Z")

</div>

I am reading the docker file of Kibana. Here is the link: Kibana official docker file. I noticed that the config can come into force by just set the environments. I've seen the annotation of its theory. But I do not kno…

---

## [London Information Retrieval Meetup (20th November 2023)](https://discuss.elastic.co/t/london-information-retrieval-meetup-20th-november-2023/347351)

<div class="topic-metadata">

**Author:** [@lizbiella](https://discuss.elastic.co/u/lizbiella)\
**Replies:** 0\
**Last updated:** [November 16, 2023, 4:45pm UTC](https://discuss.elastic.co/t/london-information-retrieval-meetup-20th-november-2023/347351 "2023-11-16T16:45:29Z")

</div>

We are delighted to announce the nineteenth London Information Retrieval Meetup, a free evening event aimed at enthusiasts and professionals curious to explore and discuss the latest trends in the field. This time the M…

---

## [How to Output Display the Document Scoring](https://discuss.elastic.co/t/how-to-output-display-the-document-scoring/347074)

<div class="topic-metadata">

**Author:** [@aisyaharifin](https://discuss.elastic.co/u/aisyaharifin)\
**Replies:** 5\
**Last updated:** [November 16, 2023, 4:30pm UTC](https://discuss.elastic.co/t/how-to-output-display-the-document-scoring/347074 "2023-11-16T16:30:23Z")

</div>

Hello Elastic, I need help on how do we display the document scoring based on the search results? For example like the Score on top of the Captain Marvel. I've tried to explore the code but couldn't find on the spe…

---

## [Problem with filebeat](https://discuss.elastic.co/t/problem-with-filebeat/346913)

<div class="topic-metadata">

**Author:** [@miladmohabati](https://discuss.elastic.co/u/miladmohabati)\
**Replies:** 20\
**Last updated:** [November 16, 2023, 2:34pm UTC](https://discuss.elastic.co/t/problem-with-filebeat/346913 "2023-11-16T14:34:38Z")

</div>

Exiting: couldn't connect to any of the configured Elasticsearch hosts. Errors: \[error connecting to Elasticsearch at http://localhost:9200: Get "http://localhost:9200": EOF\]

---

## [Changing from Elasticsearch 7.10.2 OSS to Basic version](https://discuss.elastic.co/t/changing-from-elasticsearch-7-10-2-oss-to-basic-version/347347)

<div class="topic-metadata">

**Author:** [@Talha1](https://discuss.elastic.co/u/Talha1)\
**Replies:** 0\
**Last updated:** [November 16, 2023, 3:35pm UTC](https://discuss.elastic.co/t/changing-from-elasticsearch-7-10-2-oss-to-basic-version/347347 "2023-11-16T15:35:23Z")

</div>

Hi, I'm currently using Elasticsearch version 7.10. OSS version but when trying to implement security ran into challenges which turns out is because I am not on the basic version of Elasticsearch. Is there a way I can ch…

---

## [Adding incremental column based on values of another column](https://discuss.elastic.co/t/adding-incremental-column-based-on-values-of-another-column/346443)

<div class="topic-metadata">

**Author:** [@Felicien\_Ihirwe](https://discuss.elastic.co/u/Felicien_Ihirwe)\
**Replies:** 2\
**Last updated:** [November 16, 2023, 3:13pm UTC](https://discuss.elastic.co/t/adding-incremental-column-based-on-values-of-another-column/346443 "2023-11-16T15:13:58Z")

</div>

I want to create a logstash filter to come from table 1 to table 2: col1 in in out in out .. . I want to add a new column that will contain incremental values and the data will look like col1 | col 2 in | …

[Previous page](https://discuss.elastic.co/latest.md?page=479)

[Next page](https://discuss.elastic.co/latest.md?page=481)
