# Latest

**URL:** https://discuss.elastic.co/latest.md?page=484

[Latest](https://discuss.elastic.co/latest.md) · [Categories](https://discuss.elastic.co/categories.md) · [Tags](https://discuss.elastic.co/tags.md)

**Page:** 485

---

## [Elastic Agent - Duplicate Collection of AWS CloudWatch Metrics](https://discuss.elastic.co/t/elastic-agent-duplicate-collection-of-aws-cloudwatch-metrics/347112)

<div class="topic-metadata">

**Author:** [@shwanlee](https://discuss.elastic.co/u/shwanlee)\
**Replies:** 0\
**Last updated:** [November 14, 2023, 11:43am UTC](https://discuss.elastic.co/t/elastic-agent-duplicate-collection-of-aws-cloudwatch-metrics/347112 "2023-11-14T11:43:26Z")

</div>

Hello, I am collecting AWS CloudWatch metrics with multiple Elastic Agents with the same policy, but there is an issue with data being collected redundantly. How can I solve this? If I don't have a way to handle this as…

---

## [Does anyone use connection pooling in ElasticSearch8.5? How to use it?](https://discuss.elastic.co/t/does-anyone-use-connection-pooling-in-elasticsearch8-5-how-to-use-it/346974)

<div class="topic-metadata">

**Author:** [@maoqingjue](https://discuss.elastic.co/u/maoqingjue)\
**Replies:** 16\
**Last updated:** [November 14, 2023, 11:09am UTC](https://discuss.elastic.co/t/does-anyone-use-connection-pooling-in-elasticsearch8-5-how-to-use-it/346974 "2023-11-14T11:09:13Z")

</div>

Does anyone use connection pooling in Elasticsearch8.5? How to use it?

---

## [Sending AWS Cloud Watch Logs to Elasticsearch](https://discuss.elastic.co/t/sending-aws-cloud-watch-logs-to-elasticsearch/346459)

<div class="topic-metadata">

**Author:** [@laale1](https://discuss.elastic.co/u/laale1)\
**Replies:** 5\
**Last updated:** [November 14, 2023, 11:01am UTC](https://discuss.elastic.co/t/sending-aws-cloud-watch-logs-to-elasticsearch/346459 "2023-11-14T11:01:37Z")

</div>

Hello community. I want to send AWS Cloud Watch logs to my local Elasticsearch cluster? I have seen AWS integrations but my question is how I'm going to connect those integrations on my AWS Cloud Watch?

---

## [Server requirement for every node role](https://discuss.elastic.co/t/server-requirement-for-every-node-role/347075)

<div class="topic-metadata">

**Author:** [@psanggabuana](https://discuss.elastic.co/u/psanggabuana)\
**Replies:** 3\
**Last updated:** [November 14, 2023, 10:20am UTC](https://discuss.elastic.co/t/server-requirement-for-every-node-role/347075 "2023-11-14T10:20:29Z")

</div>

Hi all, I need information about master, data, inget, and coordination server requirements. Anyone can share with me about CPU and Memory needs of each role node? CPU RAM Master Data Coordinatin…

---

## [One day, the dashboards and graphs were using disappeared](https://discuss.elastic.co/t/one-day-the-dashboards-and-graphs-were-using-disappeared/346976)

<div class="topic-metadata">

**Author:** [@Cusis\_Eel](https://discuss.elastic.co/u/Cusis_Eel)\
**Replies:** 7\
**Last updated:** [November 14, 2023, 9:47am UTC](https://discuss.elastic.co/t/one-day-the-dashboards-and-graphs-were-using-disappeared/346976 "2023-11-14T09:47:07Z")

</div>

One day, I changed the value of 'xpack.security.enabled' from 'true' to 'false' in my Kibana+Elasticsearch environment. I had no problems using it after that, but when I logged into Kibana a few days later, all my dashbo…

---

## [Elastic Defend - Is default logging on the endpoint enough?](https://discuss.elastic.co/t/elastic-defend-is-default-logging-on-the-endpoint-enough/346296)

<div class="topic-metadata">

**Author:** [@h49nakxs](https://discuss.elastic.co/u/h49nakxs)\
**Replies:** 2\
**Last updated:** [November 14, 2023, 9:27am UTC](https://discuss.elastic.co/t/elastic-defend-is-default-logging-on-the-endpoint-enough/346296 "2023-11-14T09:27:54Z")

</div>

Hello, If I use "Elastic Defend" integration, will all the Elastic Security detection rules get enough information to be triggered or do I need to enhance the logging on the endpoints (for example with Sysmon on Windows…

---

## [No span and transaction for Dubbo example](https://discuss.elastic.co/t/no-span-and-transaction-for-dubbo-example/347094)

<div class="topic-metadata">

**Author:** [@bixiyan](https://discuss.elastic.co/u/bixiyan)\
**Replies:** 0\
**Last updated:** [November 14, 2023, 9:12am UTC](https://discuss.elastic.co/t/no-span-and-transaction-for-dubbo-example/347094 "2023-11-14T09:12:30Z")

</div>

Hi team: I am doing a poc on elastic apm using dubbo. Kibana version: 7.16.3 Elasticsearch: 7.16.3 apm-server:v7.16.3 I have create a dubbo provider and consumer. Consumer run every second to call provider. Now I c…

---

## [ES 7.8.1 crashing, insufficient memory... why?!](https://discuss.elastic.co/t/es-7-8-1-crashing-insufficient-memory-why/347050)

<div class="topic-metadata">

**Author:** [@jsamhall](https://discuss.elastic.co/u/jsamhall)\
**Replies:** 4\
**Last updated:** [November 14, 2023, 8:48am UTC](https://discuss.elastic.co/t/es-7-8-1-crashing-insufficient-memory-why/347050 "2023-11-14T08:48:12Z")

</div>

Hello, I am new to being a sysadmin for ES and in this case, it is backing a Magento2 installation running on Ubuntu 18.04 LTS Problem: Occasionally, and I'm not sure why, ES performance begins to degrade and then cra…

---

## [Field and Value missmatch Paolo Alto OS11 paring Logstash \> Elastic \> Kibana](https://discuss.elastic.co/t/field-and-value-missmatch-paolo-alto-os11-paring-logstash-elastic-kibana/346969)

<div class="topic-metadata">

**Author:** [@Trung\_Nguyen](https://discuss.elastic.co/u/Trung_Nguyen)\
**Replies:** 5\
**Last updated:** [November 14, 2023, 8:30am UTC](https://discuss.elastic.co/t/field-and-value-missmatch-paolo-alto-os11-paring-logstash-elastic-kibana/346969 "2023-11-14T08:30:59Z")

</div>

Hi, i'm a new logstash and trying to parsing log from my firewall PAN\_OS 11 but the field and value dose not match, such as field "NAT Destination IP" get value from the "Rule Name" Thanks a lot for any hlep Trung

---

## [Logstash and since db permission](https://discuss.elastic.co/t/logstash-and-since-db-permission/346934)

<div class="topic-metadata">

**Author:** [@ranjini](https://discuss.elastic.co/u/ranjini)\
**Replies:** 2\
**Last updated:** [November 14, 2023, 7:15am UTC](https://discuss.elastic.co/t/logstash-and-since-db-permission/346934 "2023-11-14T07:15:56Z")

</div>

Logstash runs as a container.logstash version 8.11.0 Logstash input looks like the below input { file { path =\> "/common/logs/parser-server-tasks-application/app.log" start\_position =\> "beginning" sincedb…

---

## [Explore data in Discover in Bar chart is disabled](https://discuss.elastic.co/t/explore-data-in-discover-in-bar-chart-is-disabled/346862)

<div class="topic-metadata">

**Author:** [@Abj\_Ins](https://discuss.elastic.co/u/Abj_Ins)\
**Replies:** 3\
**Last updated:** [November 14, 2023, 7:07am UTC](https://discuss.elastic.co/t/explore-data-in-discover-in-bar-chart-is-disabled/346862 "2023-11-14T07:07:10Z")

</div>

Hi Team, we are trying to get the Explore data in discover option in Bar charts. Scenario: Here we have three Bar vertical layers individually in lens visualization then we are not getting the option (in Settings---\>Mo…

---

## [Is Logstash Free use?](https://discuss.elastic.co/t/is-logstash-free-use/347078)

<div class="topic-metadata">

**Author:** [@inbeom\_cho](https://discuss.elastic.co/u/inbeom_cho)\
**Replies:** 1\
**Last updated:** [November 14, 2023, 6:10am UTC](https://discuss.elastic.co/t/is-logstash-free-use/347078 "2023-11-14T06:10:55Z")

</div>

Hi forum, when i use only logstash 8.8 version, that is free? Or If i want free, must use logstash oss?

---

## [Reindex Api "didn't store \_source" error](https://discuss.elastic.co/t/reindex-api-didnt-store-source-error/347043)

<div class="topic-metadata">

**Author:** [@Hakan\_Kara](https://discuss.elastic.co/u/Hakan_Kara)\
**Replies:** 4\
**Last updated:** [November 14, 2023, 5:48am UTC](https://discuss.elastic.co/t/reindex-api-didnt-store-source-error/347043 "2023-11-14T05:48:46Z")

</div>

Hello, we are getting following error while using reindex api. Could we ignore these kind of errors with reindex api ? Or could we destroy the following doc with given id ? { "type" : "illegal\_argument\_exception", …

---

## [Unable to reach APM Server: 'Connection aborted.' RemoteDisconnected('Remote end closed connection without response')) (url: http://127.0.0.1:8200/intake/v2/events). (potentially caused by apm-lambda-extension/extension.handleIntakeV2Events exception)](https://discuss.elastic.co/t/unable-to-reach-apm-server-connection-aborted-remotedisconnected-remote-end-closed-connection-without-response-url-http-127-0-0-1-8200-intake-v2-events-potentially-caused-by-apm-lambda-extension-extension-handleintakev2events-exception/347039)

<div class="topic-metadata">

**Author:** [@Anton\_Matviyenko](https://discuss.elastic.co/u/Anton_Matviyenko)\
**Replies:** 1\
**Last updated:** [November 14, 2023, 5:01am UTC](https://discuss.elastic.co/t/unable-to-reach-apm-server-connection-aborted-remotedisconnected-remote-end-closed-connection-without-response-url-http-127-0-0-1-8200-intake-v2-events-potentially-caused-by-apm-lambda-extension-extension-handleintakev2events-exception/347039 "2023-11-14T05:01:40Z")

</div>

Dear Elastic Team, It looks like this issue is similar to the following: We do use Python APM Elastic Agent along with Sentry and in Sentry we do see the following exceptions: Failed to submit message: "Unable to …

---

## [Elastic Agent RUM - Cryptography](https://discuss.elastic.co/t/elastic-agent-rum-cryptography/345568)

<div class="topic-metadata">

**Author:** [@Gelinski](https://discuss.elastic.co/u/Gelinski)\
**Replies:** 4\
**Last updated:** [November 14, 2023, 3:36am UTC](https://discuss.elastic.co/t/elastic-agent-rum-cryptography/345568 "2023-11-14T03:36:15Z")

</div>

Hello folks, What is the algorithm used to encrypt data between Elastic Agent RUM and APM server? Thanks, Matheus

---

## [Elasticsearch Kibana](https://discuss.elastic.co/t/elasticsearch-kibana/346944)

<div class="topic-metadata">

**Author:** [@VijayIQA](https://discuss.elastic.co/u/VijayIQA)\
**Replies:** 5\
**Last updated:** [November 14, 2023, 3:31am UTC](https://discuss.elastic.co/t/elasticsearch-kibana/346944 "2023-11-14T03:31:34Z")

</div>

Hi Team, I was deployed Elasticsearch cluster with one master node one data node on docker with version of 8.8.1 When i am trying to add that into Kibana I am getting an error. \[2023-11-13T04:55:05.704+00:00\]\[WARN \]\[sav…

---

## [Logstash Kafka input handling extended JSON format](https://discuss.elastic.co/t/logstash-kafka-input-handling-extended-json-format/347068)

<div class="topic-metadata">

**Author:** [@ys\_goh](https://discuss.elastic.co/u/ys_goh)\
**Replies:** 1\
**Last updated:** [November 14, 2023, 1:49am UTC](https://discuss.elastic.co/t/logstash-kafka-input-handling-extended-json-format/347068 "2023-11-14T01:49:54Z")

</div>

Hello all, I am trying to get data from MongoDB to OpenSearch, and this is our pipeline: MongoDB ==\> Kafka source connector ==\> Kafka topic ==\> Logstash ==\> OpenSearch Problem is, when MongoDB data get written into the…

---

## [Logstash: SNMP Poll Input - skipping "error: no such.."](https://discuss.elastic.co/t/logstash-snmp-poll-input-skipping-error-no-such/347051)

<div class="topic-metadata">

**Author:** [@erikg](https://discuss.elastic.co/u/erikg)\
**Replies:** 2\
**Last updated:** [November 13, 2023, 10:59pm UTC](https://discuss.elastic.co/t/logstash-snmp-poll-input-skipping-error-no-such/347051 "2023-11-13T22:59:49Z")

</div>

Hello, I am using SNMP poll input for logstash. Using SNMP V3, I have a wide range of network devices to monitor which means many oids that are specific by vendor. I want to know if there is a way to skip oids in whic…

---

## [Detection rule: Email CSV file as action](https://discuss.elastic.co/t/detection-rule-email-csv-file-as-action/347065)

<div class="topic-metadata">

**Author:** [@cdelgado](https://discuss.elastic.co/u/cdelgado)\
**Replies:** 0\
**Last updated:** [November 13, 2023, 10:12pm UTC](https://discuss.elastic.co/t/detection-rule-email-csv-file-as-action/347065 "2023-11-13T22:12:19Z")

</div>

Hello, When configuring Detection Rules, is there a way to send a CSV file as part of the Email action (when the rule triggers)? I am aware Mustache and Markdown syntax is supported for the email body, but I was wonderi…

---

## [Failure on document\_parsing\_exception - dot\_product similarity on dense\_vector index field](https://discuss.elastic.co/t/failure-on-document-parsing-exception-dot-product-similarity-on-dense-vector-index-field/346718)

<div class="topic-metadata">

**Author:** [@ORipalta](https://discuss.elastic.co/u/ORipalta)\
**Replies:** 5\
**Last updated:** [November 13, 2023, 9:58pm UTC](https://discuss.elastic.co/t/failure-on-document-parsing-exception-dot-product-similarity-on-dense-vector-index-field/346718 "2023-11-13T21:58:00Z")

</div>

I'm trying to use dot-plot similarity on Elasticsearch. But after creating the index, the data/rows fail to load due to document\_parsing\_exception. The error message that is being returned is failed to parse: The \[dot\_p…

---

## [Can't delete or recover .kibana\_security\_session\_1 index](https://discuss.elastic.co/t/cant-delete-or-recover-kibana-security-session-1-index/347035)

<div class="topic-metadata">

**Author:** [@RRGTHWAR](https://discuss.elastic.co/u/RRGTHWAR)\
**Replies:** 2\
**Last updated:** [November 13, 2023, 9:26pm UTC](https://discuss.elastic.co/t/cant-delete-or-recover-kibana-security-session-1-index/347035 "2023-11-13T21:26:44Z")

</div>

My storage team badly botched an upgrade, and as a result the .kibana\_security\_session\_1 index in my ECK cluster was corrupted. I don't have any backups of it to restore, and I can't delete it because the superuser privi…

---

## [QueryPhaseCollector invokes lucene score() twice on every doc when min\_score is used](https://discuss.elastic.co/t/queryphasecollector-invokes-lucene-score-twice-on-every-doc-when-min-score-is-used/347062)

<div class="topic-metadata">

**Author:** [@Mike\_McMahon](https://discuss.elastic.co/u/Mike_McMahon)\
**Replies:** 0\
**Last updated:** [November 13, 2023, 8:56pm UTC](https://discuss.elastic.co/t/queryphasecollector-invokes-lucene-score-twice-on-every-doc-when-min-score-is-used/347062 "2023-11-13T20:56:42Z")

</div>

Elastic 8.10 introduced a major change QueryPhaseCollector (see https://github.com/elastic/elasticsearch/pull/97410) in how lucene queries are executed. I have observed that now, when using min\_score, each document gets …

---

## [Kibana server is not ready yet](https://discuss.elastic.co/t/kibana-server-is-not-ready-yet/346809)

<div class="topic-metadata">

**Author:** [@maycoonferreira](https://discuss.elastic.co/u/maycoonferreira)\
**Replies:** 17\
**Last updated:** [November 13, 2023, 6:54pm UTC](https://discuss.elastic.co/t/kibana-server-is-not-ready-yet/346809 "2023-11-13T18:54:52Z")

</div>

Kibana server is not ready yet

---

## [Elasticsearch 8.10.2 synonyms not working when synonyms\_path is used](https://discuss.elastic.co/t/elasticsearch-8-10-2-synonyms-not-working-when-synonyms-path-is-used/346745)

<div class="topic-metadata">

**Author:** [@smritibhandari91](https://discuss.elastic.co/u/smritibhandari91)\
**Replies:** 1\
**Last updated:** [November 13, 2023, 6:35pm UTC](https://discuss.elastic.co/t/elasticsearch-8-10-2-synonyms-not-working-when-synonyms-path-is-used/346745 "2023-11-13T18:35:24Z")

</div>

We successfully deployed Elasticsearch 8.10.2 using the ECK operator. However, we encountered an issue when trying to access the synonyms\_path during the index creation process. Error: The problem is that the index crea…

---

## [No .PEM generated when using --pem mode in elasticsearch-certutil](https://discuss.elastic.co/t/no-pem-generated-when-using-pem-mode-in-elasticsearch-certutil/347046)

<div class="topic-metadata">

**Author:** [@carel0x53](https://discuss.elastic.co/u/carel0x53)\
**Replies:** 3\
**Last updated:** [November 13, 2023, 5:37pm UTC](https://discuss.elastic.co/t/no-pem-generated-when-using-pem-mode-in-elasticsearch-certutil/347046 "2023-11-13T17:37:08Z")

</div>

I'm trying to generate a PEM certificate for elasticsearch using elasticsearch-certutil by introducing the following line bin/elasticsearch-certutil ca --pem Then, the program asks me to set a name for the resulting .z…

---

## [Kibana 8.11.0 Failed To Start (Exit Code 1)](https://discuss.elastic.co/t/kibana-8-11-0-failed-to-start-exit-code-1/346893)

<div class="topic-metadata">

**Author:** [@Ethan777100](https://discuss.elastic.co/u/Ethan777100)\
**Replies:** 53\
**Last updated:** [November 13, 2023, 4:53pm UTC](https://discuss.elastic.co/t/kibana-8-11-0-failed-to-start-exit-code-1/346893 "2023-11-13T16:53:10Z")

</div>

I am running a ELK Stack in a local hosted Docker Container that comprises of sub containers of Elasticsearch, Kibana and Logstash service. Setup / config wise, I followed Ali Younges youtube video closely to setup. …

---

## [Can I make a read only dashboard for display purposes?](https://discuss.elastic.co/t/can-i-make-a-read-only-dashboard-for-display-purposes/346781)

<div class="topic-metadata">

**Author:** [@ivahbo](https://discuss.elastic.co/u/ivahbo)\
**Replies:** 1\
**Last updated:** [November 13, 2023, 4:28pm UTC](https://discuss.elastic.co/t/can-i-make-a-read-only-dashboard-for-display-purposes/346781 "2023-11-13T16:28:10Z")

</div>

I want a dashboard I can give out as a URL that only exposes the components of the dashboard (pretty charts) and no other menus.

---

## [Logstash does not execute certain queries correctly](https://discuss.elastic.co/t/logstash-does-not-execute-certain-queries-correctly/346800)

<div class="topic-metadata">

**Author:** [@Stefan\_Sabolowitsch](https://discuss.elastic.co/u/Stefan_Sabolowitsch)\
**Replies:** 1\
**Last updated:** [November 13, 2023, 4:20pm UTC](https://discuss.elastic.co/t/logstash-does-not-execute-certain-queries-correctly/346800 "2023-11-13T16:20:49Z")

</div>

Hi there i do not understand the behavior of logstash. Although the field is\_read exists, a successful query is still performed and an e-mail is sent. input { elasticsearch { hosts =\> "https://elasti…

---

## [How to migrate my information from one cluster to another?](https://discuss.elastic.co/t/how-to-migrate-my-information-from-one-cluster-to-another/347027)

<div class="topic-metadata">

**Author:** [@efrainMZ](https://discuss.elastic.co/u/efrainMZ)\
**Replies:** 1\
**Last updated:** [November 13, 2023, 3:52pm UTC](https://discuss.elastic.co/t/how-to-migrate-my-information-from-one-cluster-to-another/347027 "2023-11-13T15:52:58Z")

</div>

How to migrate information from a version 7.17 cluster to a version 8.10 cluster manually without using the cloud.

---

## [Environment filtering on the Metrics tab](https://discuss.elastic.co/t/environment-filtering-on-the-metrics-tab/345725)

<div class="topic-metadata">

**Author:** [@igorlovich](https://discuss.elastic.co/u/igorlovich)\
**Replies:** 5\
**Last updated:** [November 13, 2023, 3:44pm UTC](https://discuss.elastic.co/t/environment-filtering-on-the-metrics-tab/345725 "2023-11-13T15:44:30Z")

</div>

After upgrading the stack to 8.10 from 8.9 the filtering by environment on the Metrics tab (in APM) stopped working. Specifying an Environment (e.g. production) results in no data showing. However selecting "All" in the…

[Previous page](https://discuss.elastic.co/latest.md?page=483)

[Next page](https://discuss.elastic.co/latest.md?page=485)
