# Latest

**URL:** https://discuss.elastic.co/latest.md?page=485

[Latest](https://discuss.elastic.co/latest.md) · [Categories](https://discuss.elastic.co/categories.md) · [Tags](https://discuss.elastic.co/tags.md)

**Page:** 486

---

## [What is better, update or install from the beginning?](https://discuss.elastic.co/t/what-is-better-update-or-install-from-the-beginning/346820)

<div class="topic-metadata">

**Author:** [@efrainMZ](https://discuss.elastic.co/u/efrainMZ)\
**Replies:** 1\
**Last updated:** [November 13, 2023, 3:26pm UTC](https://discuss.elastic.co/t/what-is-better-update-or-install-from-the-beginning/346820 "2023-11-13T15:26:18Z")

</div>

Hello, good day, I have an elasticsearch cluster with version 7.17. I would like to know what is most convenient? upgrade the cluster to version 8.10 or perform a new installation with version 8.10 and only migrate the d…

---

## [Elastic Integration with Sentinel one deep visibility data](https://discuss.elastic.co/t/elastic-integration-with-sentinel-one-deep-visibility-data/346301)

<div class="topic-metadata">

**Author:** [@ksrawat88](https://discuss.elastic.co/u/ksrawat88)\
**Replies:** 2\
**Last updated:** [November 13, 2023, 3:05pm UTC](https://discuss.elastic.co/t/elastic-integration-with-sentinel-one-deep-visibility-data/346301 "2023-11-13T15:05:12Z")

</div>

Anyone has integrated Sentinel one deep visibility data with ELK stack.? or atlease able to search on sentinel one deep visibilty data from Kibana. ? We are looking in this option and right now we have open source ELK s…

---

## [Why is .transform-notifications in my snaphot?](https://discuss.elastic.co/t/why-is-transform-notifications-in-my-snaphot/347028)

<div class="topic-metadata">

**Author:** [@Alain\_Bod](https://discuss.elastic.co/u/Alain_Bod)\
**Replies:** 0\
**Last updated:** [November 13, 2023, 3:02pm UTC](https://discuss.elastic.co/t/why-is-transform-notifications-in-my-snaphot/347028 "2023-11-13T15:02:43Z")

</div>

Hi, I've created a snaphot policy with indices "index1, index2". But I get ".transform-notifications" as well in my snapshot. Why is that? ES version 8.11.0

---

## [Can we consolidate or correlate simliar incidents](https://discuss.elastic.co/t/can-we-consolidate-or-correlate-simliar-incidents/346304)

<div class="topic-metadata">

**Author:** [@ksrawat88](https://discuss.elastic.co/u/ksrawat88)\
**Replies:** 3\
**Last updated:** [November 13, 2023, 3:02pm UTC](https://discuss.elastic.co/t/can-we-consolidate-or-correlate-simliar-incidents/346304 "2023-11-13T15:02:33Z")

</div>

We are using open source ELK stack and we have different log sources enabled. Is there anyway we can have log correlation between different log sources. For example if we search for one IP or user we can see all logs fr…

---

## [Elastic APM agent and opentelemetry-php](https://discuss.elastic.co/t/elastic-apm-agent-and-opentelemetry-php/346775)

<div class="topic-metadata">

**Author:** [@ArtemisMucaj](https://discuss.elastic.co/u/ArtemisMucaj)\
**Replies:** 2\
**Last updated:** [November 13, 2023, 1:58pm UTC](https://discuss.elastic.co/t/elastic-apm-agent-and-opentelemetry-php/346775 "2023-11-13T13:58:34Z")

</div>

Hi, I have a question about the vision of the Elastic team about the Elastic APM PHP agent and the OpenTelemetry PHP agent (which hit a stable version not so long ago). What's the vision? Will development happen in both…

---

## [Stats aggregation: as\_string fields missing when searching in multiple indices](https://discuss.elastic.co/t/stats-aggregation-as-string-fields-missing-when-searching-in-multiple-indices/347016)

<div class="topic-metadata">

**Author:** [@msh](https://discuss.elastic.co/u/msh)\
**Replies:** 0\
**Last updated:** [November 13, 2023, 1:23pm UTC](https://discuss.elastic.co/t/stats-aggregation-as-string-fields-missing-when-searching-in-multiple-indices/347016 "2023-11-13T13:23:19Z")

</div>

Hi, here are steps to reproduce: Fresh installation of ES v 8.11 Create an index "items" with a document containing a date: curl --location --request PUT 'localhost:9200/items/\_doc/1' \\ --header 'Content-Type: applic…

---

## [Show only Data in the kibana table if any of the column's has more than one value](https://discuss.elastic.co/t/show-only-data-in-the-kibana-table-if-any-of-the-columns-has-more-than-one-value/346867)

<div class="topic-metadata">

**Author:** [@Rajesh\_Cherukuri](https://discuss.elastic.co/u/Rajesh_Cherukuri)\
**Replies:** 1\
**Last updated:** [November 13, 2023, 1:46pm UTC](https://discuss.elastic.co/t/show-only-data-in-the-kibana-table-if-any-of-the-columns-has-more-than-one-value/346867 "2023-11-13T13:46:09Z")

</div>

hi here is the kibana table visualization where multiple values are available only for few columns i want to show only columns that has multiple values but not the columns that has single value

---

## [Error on transformation software.amazon.awssdk.core.internal.handler.BaseAsyncClientHandler](https://discuss.elastic.co/t/error-on-transformation-software-amazon-awssdk-core-internal-handler-baseasyncclienthandler/345278)

<div class="topic-metadata">

**Author:** [@IngoStrauch2020](https://discuss.elastic.co/u/IngoStrauch2020)\
**Replies:** 4\
**Last updated:** [November 13, 2023, 1:37pm UTC](https://discuss.elastic.co/t/error-on-transformation-software-amazon-awssdk-core-internal-handler-baseasyncclienthandler/345278 "2023-11-13T13:37:36Z")

</div>

APM Agent language and version: Java 1.43.0 Description of the problem including expected versus actual behavior. After upgrading the AWS SDK v2 in our spring boot service from 2.20.162 to 2.21.0 we see the following …

---

## [LDAP user authentication](https://discuss.elastic.co/t/ldap-user-authentication/347000)

<div class="topic-metadata">

**Author:** [@Manal\_A](https://discuss.elastic.co/u/Manal_A)\
**Replies:** 1\
**Last updated:** [November 13, 2023, 12:58pm UTC](https://discuss.elastic.co/t/ldap-user-authentication/347000 "2023-11-13T12:58:31Z")

</div>

Hello, I want to configure LDAP. Should the configuration be done at the Kibana level or the Elasticsearch level? And for the flow openings, should I create openings between LDAP and Kibana or LDAP and Elasticsearch? T…

---

## [How should I configure memory swapping?](https://discuss.elastic.co/t/how-should-i-configure-memory-swapping/347010)

<div class="topic-metadata">

**Author:** [@elasticsearchman](https://discuss.elastic.co/u/elasticsearchman)\
**Replies:** 0\
**Last updated:** [November 13, 2023, 12:24pm UTC](https://discuss.elastic.co/t/how-should-i-configure-memory-swapping/347010 "2023-11-13T12:24:47Z")

</div>

Hello, I want to build Elasticsearch and Kibana using Podman on RHEL 8.5. It is my understanding that disabling memory swapping is a best practice in Elasticsearch. I am planning to implement the following settings bas…

---

## [Cisco Meraki webhooks integration fails when using shared secrets](https://discuss.elastic.co/t/cisco-meraki-webhooks-integration-fails-when-using-shared-secrets/347007)

<div class="topic-metadata">

**Author:** [@brynjar](https://discuss.elastic.co/u/brynjar)\
**Replies:** 0\
**Last updated:** [November 13, 2023, 11:59am UTC](https://discuss.elastic.co/t/cisco-meraki-webhooks-integration-fails-when-using-shared-secrets/347007 "2023-11-13T11:59:53Z")

</div>

Hello, I've been testing the Cisco Meraki webhooks integration lately, and while it works just fine without specifying a shared secret, it stops working immediately once any text is entered in secret\_value as described …

---

## [The state of the new Java Client (ES 8)](https://discuss.elastic.co/t/the-state-of-the-new-java-client-es-8/346689)

<div class="topic-metadata">

**Author:** [@rand0m86](https://discuss.elastic.co/u/rand0m86)\
**Replies:** 2\
**Last updated:** [November 13, 2023, 11:58am UTC](https://discuss.elastic.co/t/the-state-of-the-new-java-client-es-8/346689 "2023-11-13T11:58:41Z")

</div>

Hi there, I just want to hear back from ES maintainers on the current state of the new Elasticsearch Java Client. We did quite some effort migrating our app from ES 6.8 to 8.x in terms of switching to this new client, …

---

## [TSDS Best Compression On ILM Rollover?](https://discuss.elastic.co/t/tsds-best-compression-on-ilm-rollover/346886)

<div class="topic-metadata">

**Author:** [@BenB196](https://discuss.elastic.co/u/BenB196)\
**Replies:** 2\
**Last updated:** [November 13, 2023, 11:36am UTC](https://discuss.elastic.co/t/tsds-best-compression-on-ilm-rollover/346886 "2023-11-13T11:36:29Z")

</div>

Hi All, I recently saw this issue; Don't set index.codec: 'best\_compression' for TSDB data streams · Issue #160288 · elastic/kibana (github.com), and I was kind of curious. What is the guidance for compression as part o…

---

## [Script Processor Conditional](https://discuss.elastic.co/t/script-processor-conditional/347004)

<div class="topic-metadata">

**Author:** [@karnamonkster](https://discuss.elastic.co/u/karnamonkster)\
**Replies:** 0\
**Last updated:** [November 13, 2023, 11:19am UTC](https://discuss.elastic.co/t/script-processor-conditional/347004 "2023-11-13T11:19:41Z")

</div>

Hi, I have a field - src-station-id in the logs that brings in IP and Hostnames as string. Now in order to create a new field when src-station-id only contains IP, I am trying to get a script processor identify that as…

---

## [Logstash error: \[FATAL\]\[org.logstash.Logstash \] Logstash stopped processing because of an error: (SystemExit) exit org.jruby.exceptions.SystemExit: (SystemExit) exit](https://discuss.elastic.co/t/logstash-error-fatal-org-logstash-logstash-logstash-stopped-processing-because-of-an-error-systemexit-exit-org-jruby-exceptions-systemexit-systemexit-exit/347001)

<div class="topic-metadata">

**Author:** [@Jann](https://discuss.elastic.co/u/Jann)\
**Replies:** 0\
**Last updated:** [November 13, 2023, 11:12am UTC](https://discuss.elastic.co/t/logstash-error-fatal-org-logstash-logstash-logstash-stopped-processing-because-of-an-error-systemexit-exit-org-jruby-exceptions-systemexit-systemexit-exit/347001 "2023-11-13T11:12:28Z")

</div>

Hello, I'm trying to send txt files from my server to my other server (where ELK is running). Otherwise when I try to send files, I receive this error: \[FATAL\]\[org.logstash.Logstash \] Logstash stopped processing bec…

---

## [Elasticsearch-cli](https://discuss.elastic.co/t/elasticsearch-cli/346847)

<div class="topic-metadata">

**Author:** [@VijayIQA](https://discuss.elastic.co/u/VijayIQA)\
**Replies:** 11\
**Last updated:** [November 13, 2023, 11:06am UTC](https://discuss.elastic.co/t/elasticsearch-cli/346847 "2023-11-13T11:06:35Z")

</div>

Hi Team, while installing plugin or else using Elasticsearch-cli command getting an error. screenshot attached here.

---

## [Kibana elasticseach inaccessible](https://discuss.elastic.co/t/kibana-elasticseach-inaccessible/346450)

<div class="topic-metadata">

**Author:** [@Epangilinangt](https://discuss.elastic.co/u/Epangilinangt)\
**Replies:** 6\
**Last updated:** [November 13, 2023, 10:28am UTC](https://discuss.elastic.co/t/kibana-elasticseach-inaccessible/346450 "2023-11-13T10:28:28Z")

</div>

{ "statusCode": 503, "error": "Service Unavailable", "message": "License is not available." } does anyone help me with this kind of error, tried a lot of troubleshooting still did not work

---

## [Updating field mapping in Index Template](https://discuss.elastic.co/t/updating-field-mapping-in-index-template/345528)

<div class="topic-metadata">

**Author:** [@randomnamegenerator](https://discuss.elastic.co/u/randomnamegenerator)\
**Replies:** 3\
**Last updated:** [November 13, 2023, 10:10am UTC](https://discuss.elastic.co/t/updating-field-mapping-in-index-template/345528 "2023-11-13T10:10:30Z")

</div>

Hello all, We have an application that sends logs daily to our ELK server. We are an index template which creates an new indice for each day. We are using ELK (with filebeat) 7.10 I am looking to update the mapping to …

---

## [Does anyone use connection pooling in ElasticSearch8.5? How to use it?](https://discuss.elastic.co/t/does-anyone-use-connection-pooling-in-elasticsearch8-5-how-to-use-it/346975)

<div class="topic-metadata">

**Author:** [@maoqingjue](https://discuss.elastic.co/u/maoqingjue)\
**Replies:** 1\
**Last updated:** [November 13, 2023, 10:00am UTC](https://discuss.elastic.co/t/does-anyone-use-connection-pooling-in-elasticsearch8-5-how-to-use-it/346975 "2023-11-13T10:00:19Z")

</div>

Does anyone use connection pooling in Elasticsearch8.5? How to use it?

---

## [Use k8s provider fields in filebeat config](https://discuss.elastic.co/t/use-k8s-provider-fields-in-filebeat-config/346864)

<div class="topic-metadata">

**Author:** [@GeorgeGkinis](https://discuss.elastic.co/u/GeorgeGkinis)\
**Replies:** 1\
**Last updated:** [November 13, 2023, 9:27am UTC](https://discuss.elastic.co/t/use-k8s-provider-fields-in-filebeat-config/346864 "2023-11-13T09:27:07Z")

</div>

Hello everyone! We are deploying the Elastic Agent as a daemonset to slurp up our container logs using hints based autodiscovery. This works and we can selectively parse pods based on the following hint: podTempla…

---

## [Error: failed to publish events: write tcp XX.XX.XX.XX:50882-\>XX.XX.XX.XX:5044: write: broken pipe](https://discuss.elastic.co/t/error-failed-to-publish-events-write-tcp-xx-xx-xx-xx-50882-xx-xx-xx-xx-write-broken-pipe/346852)

<div class="topic-metadata">

**Author:** [@charown](https://discuss.elastic.co/u/charown)\
**Replies:** 12\
**Last updated:** [November 13, 2023, 9:15am UTC](https://discuss.elastic.co/t/error-failed-to-publish-events-write-tcp-xx-xx-xx-xx-50882-xx-xx-xx-xx-write-broken-pipe/346852 "2023-11-13T09:15:26Z")

</div>

I have docker-compose.yml version: "2.4" services: …

---

## [Detection alerts not visible to all users](https://discuss.elastic.co/t/detection-alerts-not-visible-to-all-users/346456)

<div class="topic-metadata">

**Author:** [@abubacker](https://discuss.elastic.co/u/abubacker)\
**Replies:** 2\
**Last updated:** [November 13, 2023, 8:57am UTC](https://discuss.elastic.co/t/detection-alerts-not-visible-to-all-users/346456 "2023-11-13T08:57:57Z")

</div>

Hi All, Elastic detection alerts are not visible to all users and are highlighted in yellow. All other alerts are visible some alerts only have this issue. If anyone knows how to solve this issue please let me know w…

---

## [How to access index of array correct in plainess?](https://discuss.elastic.co/t/how-to-access-index-of-array-correct-in-plainess/345617)

<div class="topic-metadata">

**Author:** [@duyhunter1001](https://discuss.elastic.co/u/duyhunter1001)\
**Replies:** 2\
**Last updated:** [November 13, 2023, 8:46am UTC](https://discuss.elastic.co/t/how-to-access-index-of-array-correct-in-plainess/345617 "2023-11-13T08:46:51Z")

</div>

Hi everyone, I'm facing a situation like this. I have index example: PUT my\_index { "mappings": { "properties": { "targetoperator": { type: "keyword" }, "targetvalue": { type: "keyword" } } } …

---

## [Problem with csv import into a fresh elasticsearch and kibana environment](https://discuss.elastic.co/t/problem-with-csv-import-into-a-fresh-elasticsearch-and-kibana-environment/346877)

<div class="topic-metadata">

**Author:** [@um3n](https://discuss.elastic.co/u/um3n)\
**Replies:** 4\
**Last updated:** [November 13, 2023, 8:44am UTC](https://discuss.elastic.co/t/problem-with-csv-import-into-a-fresh-elasticsearch-and-kibana-environment/346877 "2023-11-13T08:44:40Z")

</div>

Hi guys, I'm hoping to get some help with a problem I'm having. I just installed two Elasticsearch nodes in a cluster with a Kibana frontend (also freshly installed). I have configured everything according to the docum…

---

## [nextJS RUM agent](https://discuss.elastic.co/t/nextjs-rum-agent/346842)

<div class="topic-metadata">

**Author:** [@Sami\_Ullah\_Jan1](https://discuss.elastic.co/u/Sami_Ullah_Jan1)\
**Replies:** 3\
**Last updated:** [November 13, 2023, 8:05am UTC](https://discuss.elastic.co/t/nextjs-rum-agent/346842 "2023-11-13T08:05:11Z")

</div>

Kibana version: v 8.10.4 Elasticsearch version:v 8.10.4 APM Server version: using agent only APM Agent language and version: elastic-agent-8.10.4-linux-x86\_64.tar.gz (standalone agent) Browser version: Chrome Version…

---

## [Using analyze API for encryption at rest](https://discuss.elastic.co/t/using-analyze-api-for-encryption-at-rest/346960)

<div class="topic-metadata">

**Author:** [@harispy](https://discuss.elastic.co/u/harispy)\
**Replies:** 0\
**Last updated:** [November 13, 2023, 7:46am UTC](https://discuss.elastic.co/t/using-analyze-api-for-encryption-at-rest/346960 "2023-11-13T07:46:21Z")

</div>

Hi everyone. we want to encrypt one field of our documents in Elastic and I went through lots of methods for doing this and none of them was good with our situation (for example third-party proxy and plugins because the…

---

## [Having log error while trying to install pega 8.5 on kubernetes cluster](https://discuss.elastic.co/t/having-log-error-while-trying-to-install-pega-8-5-on-kubernetes-cluster/346943)

<div class="topic-metadata">

**Author:** [@musheer](https://discuss.elastic.co/u/musheer)\
**Replies:** 1\
**Last updated:** [November 13, 2023, 5:12am UTC](https://discuss.elastic.co/t/having-log-error-while-trying-to-install-pega-8-5-on-kubernetes-cluster/346943 "2023-11-13T05:12:39Z")

</div>

Hi, when i installed pega 8.5 on kubernetes cluster ,the pod of pega search was in pending state and i checked the logs and got following error .Need to solve this issue as soon as possible.Please help ERROR: kubectl …

---

## [Warm nodes respond poorly](https://discuss.elastic.co/t/warm-nodes-respond-poorly/346552)

<div class="topic-metadata">

**Author:** [@YvorL](https://discuss.elastic.co/u/YvorL)\
**Replies:** 4\
**Last updated:** [November 12, 2023, 6:12pm UTC](https://discuss.elastic.co/t/warm-nodes-respond-poorly/346552 "2023-11-12T18:12:54Z")

</div>

Hello, I have the following issue. Our largest datastream ("C") is responding poorly to the queries. The main parts of the stack: 10\*hot nodes (each: 16 cores, 60GB+ memory) 6\*warm nodes (each: 16 cores, 60GB+ memo…

---

## [Eql with time range](https://discuss.elastic.co/t/eql-with-time-range/346928)

<div class="topic-metadata">

**Author:** [@mary-20](https://discuss.elastic.co/u/mary-20)\
**Replies:** 0\
**Last updated:** [November 12, 2023, 1:30pm UTC](https://discuss.elastic.co/t/eql-with-time-range/346928 "2023-11-12T13:30:22Z")

</div>

Hi guys, I'm looking for EQL to match logs with a timestamp within the last 5 minutes. I have read a with maxspan statement, but it has some limitation: It must be used with sequence it starts at the first event’s ti…

---

## [Adding data for all documents in an index](https://discuss.elastic.co/t/adding-data-for-all-documents-in-an-index/346761)

<div class="topic-metadata">

**Author:** [@dor](https://discuss.elastic.co/u/dor)\
**Replies:** 2\
**Last updated:** [November 12, 2023, 7:10am UTC](https://discuss.elastic.co/t/adding-data-for-all-documents-in-an-index/346761 "2023-11-12T07:10:50Z")

</div>

Hi, My case is the following: I have data in elastic indexes. At some stage, I'm running some post-processing on this data using Python, and I have a new field that I want to be able to make queries on. For example, th…

[Previous page](https://discuss.elastic.co/latest.md?page=484)

[Next page](https://discuss.elastic.co/latest.md?page=486)
