# Latest

**URL:** https://discuss.elastic.co/latest.md?page=486

[Latest](https://discuss.elastic.co/latest.md) · [Categories](https://discuss.elastic.co/categories.md) · [Tags](https://discuss.elastic.co/tags.md)

**Page:** 487

---

## [Elastic Observability Engineer(On-Demand) course Lab wont allow me to login after I tried creating a new user after the heartbeat installation indicated permission issue](https://discuss.elastic.co/t/elastic-observability-engineer-on-demand-course-lab-wont-allow-me-to-login-after-i-tried-creating-a-new-user-after-the-heartbeat-installation-indicated-permission-issue/346917)

<div class="topic-metadata">

**Author:** [@nisa](https://discuss.elastic.co/u/nisa)\
**Replies:** 1\
**Last updated:** [November 12, 2023, 12:19am UTC](https://discuss.elastic.co/t/elastic-observability-engineer-on-demand-course-lab-wont-allow-me-to-login-after-i-tried-creating-a-new-user-after-the-heartbeat-installation-indicated-permission-issue/346917 "2023-11-12T00:19:37Z")

</div>

Course: \< Elastic Observability OnDemand Course \> Version: \<8.2.0\> Question: \<When attempting labs in the observability ondemand course, After I created a new user and role under Stack Management, I tried logging with …

---

## [How to remove master nodes from the elasticsearch cluster](https://discuss.elastic.co/t/how-to-remove-master-nodes-from-the-elasticsearch-cluster/346732)

<div class="topic-metadata">

**Author:** [@efrainMZ](https://discuss.elastic.co/u/efrainMZ)\
**Replies:** 7\
**Last updated:** [November 11, 2023, 6:20pm UTC](https://discuss.elastic.co/t/how-to-remove-master-nodes-from-the-elasticsearch-cluster/346732 "2023-11-11T18:20:36Z")

</div>

How could I delete two master nodes that are in my cluster, I currently have 3 master nodes, the cluster version is 7.17. thank you

---

## [How to remove fields not required when sending logs via elastic agent](https://discuss.elastic.co/t/how-to-remove-fields-not-required-when-sending-logs-via-elastic-agent/346892)

<div class="topic-metadata">

**Author:** [@HHobeck](https://discuss.elastic.co/u/HHobeck)\
**Replies:** 2\
**Last updated:** [November 11, 2023, 12:48pm UTC](https://discuss.elastic.co/t/how-to-remove-fields-not-required-when-sending-logs-via-elastic-agent/346892 "2023-11-11T12:48:23Z")

</div>

Dear community. I have exactly the same issue like shi in Reference \[1\] but with the different that I'm using elastic agent with custom log integration. Under the surface I guess file beat will be used but I have no luc…

---

## [Kibana not responding following 8.11.0 upgrade](https://discuss.elastic.co/t/kibana-not-responding-following-8-11-0-upgrade/346889)

<div class="topic-metadata">

**Author:** [@jdswifty](https://discuss.elastic.co/u/jdswifty)\
**Replies:** 4\
**Last updated:** [November 11, 2023, 11:01am UTC](https://discuss.elastic.co/t/kibana-not-responding-following-8-11-0-upgrade/346889 "2023-11-11T11:01:08Z")

</div>

Just completed upgrading both ES & Kibana from 8.9.0 to 8.11.0 & the kibana web front end is not responding at all seeing no obvious errors in the logs \[2023-11-10T16:07:48.509+00:00\]\[INFO \]\[http.server.Preboot\] http s…

---

## [Best strategy to join two clusters](https://discuss.elastic.co/t/best-strategy-to-join-two-clusters/346883)

<div class="topic-metadata">

**Author:** [@ElasticLiver](https://discuss.elastic.co/u/ElasticLiver)\
**Replies:** 2\
**Last updated:** [November 11, 2023, 7:05am UTC](https://discuss.elastic.co/t/best-strategy-to-join-two-clusters/346883 "2023-11-11T07:05:36Z")

</div>

Hi, A customer hand me two clusters, these are in two servers, on each server there are 3 nodes on dockers, what will the best strategy to join these two clusters? Also I was thinking that would be better to get rid of …

---

## [I create a model in Elasticsearch after some time later my Elasticsearch model does not found](https://discuss.elastic.co/t/i-create-a-model-in-elasticsearch-after-some-time-later-my-elasticsearch-model-does-not-found/346903)

<div class="topic-metadata">

**Author:** [@rakibulinux](https://discuss.elastic.co/u/rakibulinux)\
**Replies:** 1\
**Last updated:** [November 11, 2023, 3:48am UTC](https://discuss.elastic.co/t/i-create-a-model-in-elasticsearch-after-some-time-later-my-elasticsearch-model-does-not-found/346903 "2023-11-11T03:48:20Z")

</div>

Hi, @stephenb, how are you today? I create a model in elasticsearch after some time later my elasticsearch model does not found. I see it's automatically get removed. And throwing me this error. {"error":{"root\_cause":\[…

---

## [Auditbeat 8.11 does not provide container id without privilege mode when cgroup v2 is enabled](https://discuss.elastic.co/t/auditbeat-8-11-does-not-provide-container-id-without-privilege-mode-when-cgroup-v2-is-enabled/346901)

<div class="topic-metadata">

**Author:** [@deva\_raj1](https://discuss.elastic.co/u/deva_raj1)\
**Replies:** 0\
**Last updated:** [November 11, 2023, 2:28am UTC](https://discuss.elastic.co/t/auditbeat-8-11-does-not-provide-container-id-without-privilege-mode-when-cgroup-v2-is-enabled/346901 "2023-11-11T02:28:04Z")

</div>

Auditbeat 8.11 throughs error when installed as k8 daemonset with cgroup v2 . DEBUG \[gosigar\_cid\_provider\] add\_process\_metadata/gosigar\_cid\_provider.go:63 failed to get cgroups for pid=1395: failed to read cgro…

---

## [Is it possible to create an alert in case an Elastic Agent goes offline?](https://discuss.elastic.co/t/is-it-possible-to-create-an-alert-in-case-an-elastic-agent-goes-offline/346878)

<div class="topic-metadata">

**Author:** [@SamuelSMendes](https://discuss.elastic.co/u/SamuelSMendes)\
**Replies:** 2\
**Last updated:** [November 11, 2023, 12:55am UTC](https://discuss.elastic.co/t/is-it-possible-to-create-an-alert-in-case-an-elastic-agent-goes-offline/346878 "2023-11-11T00:55:03Z")

</div>

I have a few Elastic-Agents working on metric collection but we got a problem for when one of them goes down. I know so far that there's an alerting option for metrics/logs threshold but I'm not sure about how to set an …

---

## [GeoIP enrich IP addresses broken if fileting with include\_fields](https://discuss.elastic.co/t/geoip-enrich-ip-addresses-broken-if-fileting-with-include-fields/346824)

<div class="topic-metadata">

**Author:** [@dmgeurts](https://discuss.elastic.co/u/dmgeurts)\
**Replies:** 1\
**Last updated:** [November 10, 2023, 10:50pm UTC](https://discuss.elastic.co/t/geoip-enrich-ip-addresses-broken-if-fileting-with-include-fields/346824 "2023-11-10T22:50:23Z")

</div>

I'm logging DNS packets without dns.response\_code: NOERROR. This part works fine. But when I try to smile down the logged data, by adding a filter to drop all but some selected fields, GeoIP breaks. GeoIP can't be used …

---

## [Best practices for maintaining custom Metricbeats](https://discuss.elastic.co/t/best-practices-for-maintaining-custom-metricbeats/346895)

<div class="topic-metadata">

**Author:** [@Keith\_Wegner](https://discuss.elastic.co/u/Keith_Wegner)\
**Replies:** 0\
**Last updated:** [November 10, 2023, 8:23pm UTC](https://discuss.elastic.co/t/best-practices-for-maintaining-custom-metricbeats/346895 "2023-11-10T20:23:05Z")

</div>

My software team has extended Metricbeat a few times, creating new modules/metricsets. We're looking for advice regarding the best way to maintain the Git repository (i.e., keeping with Elastic Beat's main branch). Curre…

---

## [Logstash and Kafka Input](https://discuss.elastic.co/t/logstash-and-kafka-input/346638)

<div class="topic-metadata">

**Author:** [@rpd](https://discuss.elastic.co/u/rpd)\
**Replies:** 7\
**Last updated:** [November 10, 2023, 7:48pm UTC](https://discuss.elastic.co/t/logstash-and-kafka-input/346638 "2023-11-10T19:48:36Z")

</div>

Hello Folks, I have a query about an observed side-effect of my Logstash kafka-input configuration. It is not directly apparent to me what the problem is and hope people with deep expertise can help me out here. We hav…

---

## [Does Elastic Web Crawler supports noindex and nofollow directive](https://discuss.elastic.co/t/does-elastic-web-crawler-supports-noindex-and-nofollow-directive/344821)

<div class="topic-metadata">

**Author:** [@sebastianboelling](https://discuss.elastic.co/u/sebastianboelling)\
**Replies:** 9\
**Last updated:** [November 10, 2023, 5:10pm UTC](https://discuss.elastic.co/t/does-elastic-web-crawler-supports-noindex-and-nofollow-directive/344821 "2023-11-10T17:10:51Z")

</div>

Hi all, does the Elastic Web Crawler supports noindex and nofollow directive? I've found this feature only on the App Search Web Crawler reference Web crawler reference | App Search documentation \[8.10\] | Elastic and no…

---

## [Host Elastic Maps Service locally](https://discuss.elastic.co/t/host-elastic-maps-service-locally/346347)

<div class="topic-metadata">

**Author:** [@Manal\_A](https://discuss.elastic.co/u/Manal_A)\
**Replies:** 12\
**Last updated:** [November 10, 2023, 4:33pm UTC](https://discuss.elastic.co/t/host-elastic-maps-service-locally/346347 "2023-11-10T16:33:50Z")

</div>

I use an offline virtual machine (Red Hat), and I want to create some maps. So, I followed the documentation of hosting Elastic maps service locally, and I'm going to use the Docker image for the map server. However, wh…

---

## [Am I right in thinking Lucene regex doesn't support lookahead?](https://discuss.elastic.co/t/am-i-right-in-thinking-lucene-regex-doesnt-support-lookahead/346882)

<div class="topic-metadata">

**Author:** [@dmgeurts](https://discuss.elastic.co/u/dmgeurts)\
**Replies:** 0\
**Last updated:** [November 10, 2023, 4:02pm UTC](https://discuss.elastic.co/t/am-i-right-in-thinking-lucene-regex-doesnt-support-lookahead/346882 "2023-11-10T16:02:41Z")

</div>

Creating a new visualisation I just came across a curious case of regex filtering. The following Regex Lucene filter is what I had to use to show only values containing both upper and lower caps: Works dns.question.na…

---

## [Elastic agent unhealthy](https://discuss.elastic.co/t/elastic-agent-unhealthy/346188)

<div class="topic-metadata">

**Author:** [@abdul90082](https://discuss.elastic.co/u/abdul90082)\
**Replies:** 1\
**Last updated:** [November 10, 2023, 3:49pm UTC](https://discuss.elastic.co/t/elastic-agent-unhealthy/346188 "2023-11-10T15:49:11Z")

</div>

We are encountering errors in our current deployment involving Fleet Server and Fleet Agent components. The specific errors we are facing are as follows: Fleet Server Error: Error Message: "Non-zero metrics in the last …

---

## [Do we have to install new agent for every new host for Fleet](https://discuss.elastic.co/t/do-we-have-to-install-new-agent-for-every-new-host-for-fleet/346846)

<div class="topic-metadata">

**Author:** [@Umang\_Pachaury](https://discuss.elastic.co/u/Umang_Pachaury)\
**Replies:** 2\
**Last updated:** [November 10, 2023, 3:34pm UTC](https://discuss.elastic.co/t/do-we-have-to-install-new-agent-for-every-new-host-for-fleet/346846 "2023-11-10T15:34:42Z")

</div>

I was currently exploring regarding elasticsearch fleet and I set up a basic fleet server and a enrolled an elastic-agent on one machine, for example, "machine-A" with a agent policy: "p1", Agent policy p1 is configured …

---

## [Ruby filter to pack string value into object](https://discuss.elastic.co/t/ruby-filter-to-pack-string-value-into-object/346854)

<div class="topic-metadata">

**Author:** [@rcz](https://discuss.elastic.co/u/rcz)\
**Replies:** 7\
**Last updated:** [November 10, 2023, 2:17pm UTC](https://discuss.elastic.co/t/ruby-filter-to-pack-string-value-into-object/346854 "2023-11-10T14:17:09Z")

</div>

I have a client that sends HTTP request events with a nested structure, like: context.response.body context.response.code context.response.headers.Content-Length context.response.headers.Content-Type etc.. But sometime…

---

## [Help to understand match fields](https://discuss.elastic.co/t/help-to-understand-match-fields/346851)

<div class="topic-metadata">

**Author:** [@libertey](https://discuss.elastic.co/u/libertey)\
**Replies:** 2\
**Last updated:** [November 10, 2023, 2:08pm UTC](https://discuss.elastic.co/t/help-to-understand-match-fields/346851 "2023-11-10T14:08:24Z")

</div>

I have a Problem i have a es database with a huge amount of text and now i try to understand why one article is not found. Here we have our ES-Indexsettings: { "stories": { "aliases": {}, "mappings": { "stories…

---

## [Nested json with multi field parsing through logstash](https://discuss.elastic.co/t/nested-json-with-multi-field-parsing-through-logstash/345549)

<div class="topic-metadata">

**Author:** [@sudhir\_singh](https://discuss.elastic.co/u/sudhir_singh)\
**Replies:** 15\
**Last updated:** [November 10, 2023, 1:31pm UTC](https://discuss.elastic.co/t/nested-json-with-multi-field-parsing-through-logstash/345549 "2023-11-10T13:31:21Z")

</div>

Please help me with below log how do I parse it ? {"@timestamp":"2023-10-11T07:38:56.607Z","log.level":"error","message":"API REQUEST TIME","ecs":{"version":"1.6.0"},"requestedAPI":\["https://cloudservices.indiatimes.com…

---

## [Where are Security Rules run?](https://discuss.elastic.co/t/where-are-security-rules-run/346753)

<div class="topic-metadata">

**Author:** [@digital-thought](https://discuss.elastic.co/u/digital-thought)\
**Replies:** 4\
**Last updated:** [November 10, 2023, 12:43pm UTC](https://discuss.elastic.co/t/where-are-security-rules-run/346753 "2023-11-10T12:43:39Z")

</div>

The security rules and alerts are fantastic in ELK. Am curious to know, where are the Rules (which dont require Machine Learning) run from? Is it the instance running Kibana or one of the Elastic instances with a speci…

---

## [Kibana 8.5.3, Aggregation Based Visualization Error](https://discuss.elastic.co/t/kibana-8-5-3-aggregation-based-visualization-error/346868)

<div class="topic-metadata">

**Author:** [@Kavikrishnan\_P](https://discuss.elastic.co/u/Kavikrishnan_P)\
**Replies:** 0\
**Last updated:** [November 10, 2023, 11:57am UTC](https://discuss.elastic.co/t/kibana-8-5-3-aggregation-based-visualization-error/346868 "2023-11-10T11:57:55Z")

</div>

In kibana 8.5.3 version, using Aggregation based Visualization, I created 3 'split slices' sub-buckets and in 1st level, one filter type sub aggregation and in 2nd level, two filter type sub aggregation and in 3rd lev…

---

## [Watcher - find difference between 2 buckets keys](https://discuss.elastic.co/t/watcher-find-difference-between-2-buckets-keys/346863)

<div class="topic-metadata">

**Author:** [@hofrichterovak](https://discuss.elastic.co/u/hofrichterovak)\
**Replies:** 0\
**Last updated:** [November 10, 2023, 11:05am UTC](https://discuss.elastic.co/t/watcher-find-difference-between-2-buckets-keys/346863 "2023-11-10T11:05:49Z")

</div>

Hello, I would like to ask for help. I would like to have a watcher that would find the difference between 2 buckets keys. The goal is to find out if there is a difference in the values of the HOST field now and some t…

---

## [I can't install plugins elasticsearch in docker](https://discuss.elastic.co/t/i-cant-install-plugins-elasticsearch-in-docker/346723)

<div class="topic-metadata">

**Author:** [@arro](https://discuss.elastic.co/u/arro)\
**Replies:** 1\
**Last updated:** [November 10, 2023, 10:43am UTC](https://discuss.elastic.co/t/i-cant-install-plugins-elasticsearch-in-docker/346723 "2023-11-10T10:43:53Z")

</div>

I'm trying to install a plugin for elasticsearch in a docker container. I run the command: docker exec a15de2d3dc21 bin/elasticsearch-plugin install analysis-phonetic and get an error: -\> Installing analysis-phonetic …

---

## [Extend the expiry of the certificates](https://discuss.elastic.co/t/extend-the-expiry-of-the-certificates/346548)

<div class="topic-metadata">

**Author:** [@smiley\_tamy](https://discuss.elastic.co/u/smiley_tamy)\
**Replies:** 5\
**Last updated:** [November 10, 2023, 10:37am UTC](https://discuss.elastic.co/t/extend-the-expiry-of-the-certificates/346548 "2023-11-10T10:37:45Z")

</div>

Hi, we have enabled security for Elasticsearch. We extended the expiry of certificates. But still instance certificate does not get changed and retains the default expiry of 3 years Is there a way to make it work

---

## [ Logstash stopped processing because of an error: (SystemExit) exit Logstash stopped processing because of an error: (SystemExit) exit](https://discuss.elastic.co/t/logstash-stopped-processing-because-of-an-error-systemexit-exit-logstash-stopped-processing-because-of-an-error-systemexit-exit/346805)

<div class="topic-metadata">

**Author:** [@17\_Chinmay\_Shelke](https://discuss.elastic.co/u/17_Chinmay_Shelke)\
**Replies:** 3\
**Last updated:** [November 10, 2023, 10:34am UTC](https://discuss.elastic.co/t/logstash-stopped-processing-because-of-an-error-systemexit-exit-logstash-stopped-processing-because-of-an-error-systemexit-exit/346805 "2023-11-10T10:34:33Z")

</div>

Successfully started Logstash API endpoint {:port=\>9600, :ssl\_enabled=\>false} \[2023-11-09T11:25:11,753\]\[INFO \]\[logstash.runner \] Logstash shut down. \[2023-11-09T11:25:11,758\]\[FATAL\]\[org.logstash.Logstash \] …

---

## [Xiting: error connecting to Kibana: fail to get the Kibana version: HTTP GET request to https://kibana.demo.net:5601/api/status fails: fail to execute the HTTP GET request: Get "https://kibana.demo.net:5601/api/status": x509: certificate signed by unkn](https://discuss.elastic.co/t/xiting-error-connecting-to-kibana-fail-to-get-the-kibana-version-http-get-request-to-https-kibana-demo-net-5601-api-status-fails-fail-to-execute-the-http-get-request-get-https-kibana-demo-net-5601-api-status-x509-certificate-signed-by-unkn/346717)

<div class="topic-metadata">

**Author:** [@whanklee](https://discuss.elastic.co/u/whanklee)\
**Replies:** 2\
**Last updated:** [November 10, 2023, 9:22am UTC](https://discuss.elastic.co/t/xiting-error-connecting-to-kibana-fail-to-get-the-kibana-version-http-get-request-to-https-kibana-demo-net-5601-api-status-fails-fail-to-execute-the-http-get-request-get-https-kibana-demo-net-5601-api-status-x509-certificate-signed-by-unkn/346717 "2023-11-10T09:22:05Z")

</div>

Hi there, I run the following command and always get error message. sudo filebeat setup -E output.logstash.enabled=false -E output.elasticsearch.hosts=\['https://elastic.demo.net:9200'\] -E setup.kibana.host=https://kiba…

---

## [Understanding why only one agent policy can be assigned to an agent](https://discuss.elastic.co/t/understanding-why-only-one-agent-policy-can-be-assigned-to-an-agent/346828)

<div class="topic-metadata">

**Author:** [@HHobeck](https://discuss.elastic.co/u/HHobeck)\
**Replies:** 2\
**Last updated:** [November 10, 2023, 8:23am UTC](https://discuss.elastic.co/t/understanding-why-only-one-agent-policy-can-be-assigned-to-an-agent/346828 "2023-11-10T08:23:59Z")

</div>

Dear community. I'm in the situation to setup an elastic agent to retrieve logs with custom integration from a directory e.g. d:\\Logs\\MyApp\_Staging\\\*.log on machine A and on machine B. So I have created an agent policy…

---

## [Winlogbeat only sends logs when I restart the service](https://discuss.elastic.co/t/winlogbeat-only-sends-logs-when-i-restart-the-service/346610)

<div class="topic-metadata">

**Author:** [@Jann](https://discuss.elastic.co/u/Jann)\
**Replies:** 2\
**Last updated:** [November 10, 2023, 7:50am UTC](https://discuss.elastic.co/t/winlogbeat-only-sends-logs-when-i-restart-the-service/346610 "2023-11-10T07:50:58Z")

</div>

Hello, At the moment I try to send only critical, warning en errors to my Kibana dashboard. It does work, but only when I restart Winlogbeat. It must sent the logs 24/7. Any help?

---

## [Can I change http client used for @elastic/elasticsearch in node js?](https://discuss.elastic.co/t/can-i-change-http-client-used-for-elastic-elasticsearch-in-node-js/346843)

<div class="topic-metadata">

**Author:** [@ghanshyam1](https://discuss.elastic.co/u/ghanshyam1)\
**Replies:** 0\
**Last updated:** [November 10, 2023, 7:39am UTC](https://discuss.elastic.co/t/can-i-change-http-client-used-for-elastic-elasticsearch-in-node-js/346843 "2023-11-10T07:39:42Z")

</div>

I want to use axios as http client underneath @elastic/elasticsearch.... I am trying using following code, const { Client } = require('@elastic/elasticsearch'); const axios = require('axios'); // Create a custom trans…

---

## [How can I fix a query dsl so that ALL documents are boosted in the function\_score?](https://discuss.elastic.co/t/how-can-i-fix-a-query-dsl-so-that-all-documents-are-boosted-in-the-function-score/346839)

<div class="topic-metadata">

**Author:** [@Kirill\_Cyber](https://discuss.elastic.co/u/Kirill_Cyber)\
**Replies:** 0\
**Last updated:** [November 10, 2023, 7:05am UTC](https://discuss.elastic.co/t/how-can-i-fix-a-query-dsl-so-that-all-documents-are-boosted-in-the-function-score/346839 "2023-11-10T07:05:45Z")

</div>

I have dsl query with structure { "query": { "function\_score": { "query": { "bool": { "must": { "multi\_match": { …

[Previous page](https://discuss.elastic.co/latest.md?page=485)

[Next page](https://discuss.elastic.co/latest.md?page=487)
