# Latest

**URL:** https://discuss.elastic.co/latest.md?page=495

[Latest](https://discuss.elastic.co/latest.md) · [Categories](https://discuss.elastic.co/categories.md) · [Tags](https://discuss.elastic.co/tags.md)

**Page:** 496

---

## [Does elastic-apm collects current cpu usage or average value for the period?](https://discuss.elastic.co/t/does-elastic-apm-collects-current-cpu-usage-or-average-value-for-the-period/346228)

<div class="topic-metadata">

**Author:** [@Alex\_Zay](https://discuss.elastic.co/u/Alex_Zay)\
**Replies:** 0\
**Last updated:** [November 1, 2023, 5:49pm UTC](https://discuss.elastic.co/t/does-elastic-apm-collects-current-cpu-usage-or-average-value-for-the-period/346228 "2023-11-01T17:49:31Z")

</div>

I've set up a policy in elastic apm that sends cpu usage data every 10 seconds. Does it send current cpu usage value or calculates average cpu usage for the last 10 seconds and returns it?

---

## [Logstash Sincedb duplicate entries](https://discuss.elastic.co/t/logstash-sincedb-duplicate-entries/346187)

<div class="topic-metadata">

**Author:** [@justin\_sch](https://discuss.elastic.co/u/justin_sch)\
**Replies:** 1\
**Last updated:** [November 1, 2023, 5:46pm UTC](https://discuss.elastic.co/t/logstash-sincedb-duplicate-entries/346187 "2023-11-01T17:46:45Z")

</div>

Hey, I'm using the ELK-Stack to analyze a Log-File. Right now I clone the Log-File via SSH onto my local machine via a bash script every hour. The Logfile gets data appended every minute. This is my conf: input { …

---

## [Tracer in .NET 6 works on multi-threading](https://discuss.elastic.co/t/tracer-in-net-6-works-on-multi-threading/346224)

<div class="topic-metadata">

**Author:** [@Marcos\_Ivan\_Robles\_H](https://discuss.elastic.co/u/Marcos_Ivan_Robles_H)\
**Replies:** 0\
**Last updated:** [November 1, 2023, 5:20pm UTC](https://discuss.elastic.co/t/tracer-in-net-6-works-on-multi-threading/346224 "2023-11-01T17:20:25Z")

</div>

Does Elastic.Apm.Agent.Tracer in .NET 6 works on multi-threading scenarios? I am using StartTransaction, CaptureTransaction and SetLabel methods.

---

## [Splitting different usages in clusters?](https://discuss.elastic.co/t/splitting-different-usages-in-clusters/346215)

<div class="topic-metadata">

**Author:** [@grumpy](https://discuss.elastic.co/u/grumpy)\
**Replies:** 0\
**Last updated:** [November 1, 2023, 4:41pm UTC](https://discuss.elastic.co/t/splitting-different-usages-in-clusters/346215 "2023-11-01T16:41:28Z")

</div>

We have multiple apps indexing their own data. We're setting up our new server and are thinking of optimizing our configurations. When does it make sense to have different clusters for the different apps? What are the …

---

## [Kibana - Visualization aggregation not working on large values of a field](https://discuss.elastic.co/t/kibana-visualization-aggregation-not-working-on-large-values-of-a-field/346213)

<div class="topic-metadata">

**Author:** [@sunildate](https://discuss.elastic.co/u/sunildate)\
**Replies:** 0\
**Last updated:** [November 1, 2023, 3:47pm UTC](https://discuss.elastic.co/t/kibana-visualization-aggregation-not-working-on-large-values-of-a-field/346213 "2023-11-01T15:47:42Z")

</div>

I have aggregated field values with characters length 850. In Visualization after applying aggregation on term not returning field value. I have also updated ignore\_above to 1024. Can you please help me.

---

## [Elastic Cross Cluster Replication of Data Stream](https://discuss.elastic.co/t/elastic-cross-cluster-replication-of-data-stream/346178)

<div class="topic-metadata">

**Author:** [@adsandie](https://discuss.elastic.co/u/adsandie)\
**Replies:** 2\
**Last updated:** [November 1, 2023, 3:05pm UTC](https://discuss.elastic.co/t/elastic-cross-cluster-replication-of-data-stream/346178 "2023-11-01T15:05:00Z")

</div>

Both Cluster are using v8.9.1 Hi, this is a new upgrade from 7.16.3 to 8.9.1 and we just reconfigured CCR. This is our first time using CCR on a data stream. We have been using CCR before on Index (metricbeat-, filebeat…

---

## [Timestamp from log files to @timestamp](https://discuss.elastic.co/t/timestamp-from-log-files-to-timestamp/346199)

<div class="topic-metadata">

**Author:** [@libertey](https://discuss.elastic.co/u/libertey)\
**Replies:** 4\
**Last updated:** [November 1, 2023, 2:39pm UTC](https://discuss.elastic.co/t/timestamp-from-log-files-to-timestamp/346199 "2023-11-01T14:39:12Z")

</div>

Hey, !NOTE! i'm new to the elk stack in all its facettes. I have some Problems with displaying my logfiles from an laravel application. I'm running laravel on one server and my elk stack on another i installed logstas…

---

## [Metricbeat on Windows only returns volumes with drive letter](https://discuss.elastic.co/t/metricbeat-on-windows-only-returns-volumes-with-drive-letter/345807)

<div class="topic-metadata">

**Author:** [@kenmich](https://discuss.elastic.co/u/kenmich)\
**Replies:** 1\
**Last updated:** [November 1, 2023, 2:33pm UTC](https://discuss.elastic.co/t/metricbeat-on-windows-only-returns-volumes-with-drive-letter/345807 "2023-11-01T14:33:05Z")

</div>

I'm running metricbeat 8.10.2 on Windows Server Core 2022. It's a physical server with multiple physical disks, where only one of these is mounted with a drive letter (C:). All other disk, both SATA and NVMe are mounted…

---

## [Is it possible to create a aggregated runtime field and compare them?](https://discuss.elastic.co/t/is-it-possible-to-create-a-aggregated-runtime-field-and-compare-them/346205)

<div class="topic-metadata">

**Author:** [@turbo23](https://discuss.elastic.co/u/turbo23)\
**Replies:** 1\
**Last updated:** [November 1, 2023, 2:24pm UTC](https://discuss.elastic.co/t/is-it-possible-to-create-a-aggregated-runtime-field-and-compare-them/346205 "2023-11-01T14:24:21Z")

</div>

Hello, I want to create a dashboard that shows OK if my data\_stream distinct counted hostnames equals to my distinct counted hostnames in the cmdb index or shows NOK if it no longer equals both values. My idea: Compare…

---

## [Elastic Agent upgrade through Fleet and using Custom Agent Binary Source](https://discuss.elastic.co/t/elastic-agent-upgrade-through-fleet-and-using-custom-agent-binary-source/346206)

<div class="topic-metadata">

**Author:** [@hamidallaoui](https://discuss.elastic.co/u/hamidallaoui)\
**Replies:** 0\
**Last updated:** [November 1, 2023, 2:16pm UTC](https://discuss.elastic.co/t/elastic-agent-upgrade-through-fleet-and-using-custom-agent-binary-source/346206 "2023-11-01T14:16:32Z")

</div>

Hi All, Did someone already test to upgrade Elastic Agent through Fleet and using Custom Agent Binary Source ? We tried from our side by giving url of reverse proxy (Nginx) but it did not work. Thank you for your feed…

---

## [Kibana search fails to find string](https://discuss.elastic.co/t/kibana-search-fails-to-find-string/346163)

<div class="topic-metadata">

**Author:** [@ChazJaz](https://discuss.elastic.co/u/ChazJaz)\
**Replies:** 2\
**Last updated:** [November 1, 2023, 2:02pm UTC](https://discuss.elastic.co/t/kibana-search-fails-to-find-string/346163 "2023-11-01T14:02:51Z")

</div>

When I try a simple KQL search for the character pattern: message: "}\]}}}" it finds no results even though I can see that string pattern in some entries of an unfiltered query of my data stream. According to the KQL do…

---

## [EFK | Filebeat](https://discuss.elastic.co/t/efk-filebeat/345211)

<div class="topic-metadata">

**Author:** [@Hassan\_Ahmed](https://discuss.elastic.co/u/Hassan_Ahmed)\
**Replies:** 1\
**Last updated:** [November 1, 2023, 2:02pm UTC](https://discuss.elastic.co/t/efk-filebeat/345211 "2023-11-01T14:02:05Z")

</div>

\[2023-10-16 12:43:41\] | DEBUG | watch\_dir | django.utils.autoreload | Watching dir /home/hassan/Documents/PROJECTS/vault-api/venv/lib/python3.10/site-packages/oauth2\_provider/locale with glob. I have a log file above wi…

---

## [Log4j2 Rolling File Strategy Only Rolls Once](https://discuss.elastic.co/t/log4j2-rolling-file-strategy-only-rolls-once/345320)

<div class="topic-metadata">

**Author:** [@Kris\_Felscher](https://discuss.elastic.co/u/Kris_Felscher)\
**Replies:** 4\
**Last updated:** [November 1, 2023, 1:48pm UTC](https://discuss.elastic.co/t/log4j2-rolling-file-strategy-only-rolls-once/345320 "2023-11-01T13:48:40Z")

</div>

I'm having issues with the log4j2 rolling file appender. It only writes the first rollover file. Here's my config: status = error name = LogstashPropertiesConfig appender.console.type = Console appender.console.name =…

---

## [Configure Fleet SSL Cert Port 8220](https://discuss.elastic.co/t/configure-fleet-ssl-cert-port-8220/346157)

<div class="topic-metadata">

**Author:** [@sourcreamnormanbates](https://discuss.elastic.co/u/sourcreamnormanbates)\
**Replies:** 2\
**Last updated:** [November 1, 2023, 12:49pm UTC](https://discuss.elastic.co/t/configure-fleet-ssl-cert-port-8220/346157 "2023-11-01T12:49:36Z")

</div>

I have deployed a Fleet server and I want to change the SSL cert that is being used. Is there a config file somewhere that I can modify to use the certificates that I generated? I want to avoid having to use the --inse…

---

## [Create an Observability alert with a watch](https://discuss.elastic.co/t/create-an-observability-alert-with-a-watch/346195)

<div class="topic-metadata">

**Author:** [@willemdh](https://discuss.elastic.co/u/willemdh)\
**Replies:** 0\
**Last updated:** [November 1, 2023, 11:47am UTC](https://discuss.elastic.co/t/create-an-observability-alert-with-a-watch/346195 "2023-11-01T11:47:43Z")

</div>

Hello, What would be the best way to create Observability alerts with a watch? Is it possible to create a watch action which creates the alert? Willem

---

## [Azure Blob Storage to Elasticsearch - SaaS Elastic Cloud in Azure](https://discuss.elastic.co/t/azure-blob-storage-to-elasticsearch-saas-elastic-cloud-in-azure/346194)

<div class="topic-metadata">

**Author:** [@mruthyu](https://discuss.elastic.co/u/mruthyu)\
**Replies:** 0\
**Last updated:** [November 1, 2023, 11:44am UTC](https://discuss.elastic.co/t/azure-blob-storage-to-elasticsearch-saas-elastic-cloud-in-azure/346194 "2023-11-01T11:44:52Z")

</div>

What are the options to load the JSON/CSV files from Azure Blob Storage to Elasticsearch (Elastic Cloud in Azure) I see the following filebeat module is in Beta.

---

## [Metricbeat does not see all processes](https://discuss.elastic.co/t/metricbeat-does-not-see-all-processes/346193)

<div class="topic-metadata">

**Author:** [@vlados31999](https://discuss.elastic.co/u/vlados31999)\
**Replies:** 0\
**Last updated:** [November 1, 2023, 11:10am UTC](https://discuss.elastic.co/t/metricbeat-does-not-see-all-processes/346193 "2023-11-01T11:10:48Z")

</div>

Hi, everybody metricbeat does not see processes whose parent services.exe Help please

---

## [Get records from index based on result from another search](https://discuss.elastic.co/t/get-records-from-index-based-on-result-from-another-search/346074)

<div class="topic-metadata">

**Author:** [@Mhag](https://discuss.elastic.co/u/Mhag)\
**Replies:** 5\
**Last updated:** [November 1, 2023, 10:41am UTC](https://discuss.elastic.co/t/get-records-from-index-based-on-result-from-another-search/346074 "2023-11-01T10:41:01Z")

</div>

Hi, I have an index where we collect the requests to our api somthing like this : myindex: url: /some/path service: someservice uuid: xxx-yyy-zzz-uuu And I have a requirement to get or correlate all urls that…

---

## [Use time filter on auto-interval date histogram](https://discuss.elastic.co/t/use-time-filter-on-auto-interval-date-histogram/345964)

<div class="topic-metadata">

**Author:** [@karlanakamura](https://discuss.elastic.co/u/karlanakamura)\
**Replies:** 1\
**Last updated:** [November 1, 2023, 8:49am UTC](https://discuss.elastic.co/t/use-time-filter-on-auto-interval-date-histogram/345964 "2023-11-01T08:49:14Z")

</div>

Hello, I'm using version 8.6.0 of elastic cloud. I'm trying to develop a chart similar to the TSVB time series, but the way my data is loaded I need to do it in Vega. I'm using auto-interval date histogram to separate …

---

## [How can I format a column in Lens so it can operate as a sum of time?](https://discuss.elastic.co/t/how-can-i-format-a-column-in-lens-so-it-can-operate-as-a-sum-of-time/346151)

<div class="topic-metadata">

**Author:** [@SamuelSMendes](https://discuss.elastic.co/u/SamuelSMendes)\
**Replies:** 1\
**Last updated:** [November 1, 2023, 8:41am UTC](https://discuss.elastic.co/t/how-can-i-format-a-column-in-lens-so-it-can-operate-as-a-sum-of-time/346151 "2023-11-01T08:41:58Z")

</div>

Basically, I have a column in my index that returns the total of time a device is down like this: But as I go further in time range it turns into something like this: I need to format this into the right amount of …

---

## [Fleet-server installation error](https://discuss.elastic.co/t/fleet-server-installation-error/346179)

<div class="topic-metadata">

**Author:** [@sudhir\_singh](https://discuss.elastic.co/u/sudhir_singh)\
**Replies:** 0\
**Last updated:** [November 1, 2023, 8:06am UTC](https://discuss.elastic.co/t/fleet-server-installation-error/346179 "2023-11-01T08:06:19Z")

</div>

Hi I'm trying to run fleet I tried with self generated fleet-server certificate and with basic one without generating certificate but ended up having an error.

---

## [Performance degrade after using Elastic 8](https://discuss.elastic.co/t/performance-degrade-after-using-elastic-8/345703)

<div class="topic-metadata">

**Author:** [@smiley\_tamy](https://discuss.elastic.co/u/smiley_tamy)\
**Replies:** 3\
**Last updated:** [November 1, 2023, 8:00am UTC](https://discuss.elastic.co/t/performance-degrade-after-using-elastic-8/345703 "2023-11-01T08:00:08Z")

</div>

We have been using elastic 7.17 Our application has load tests and we generally measure the performance After upgrading to elastic 8, we see lot of difference in the results we had when compared to elastic 7 We also n…

---

## [Best approach to combine two different ES instances in one instance](https://discuss.elastic.co/t/best-approach-to-combine-two-different-es-instances-in-one-instance/346177)

<div class="topic-metadata">

**Author:** [@Prashant\_Rana](https://discuss.elastic.co/u/Prashant_Rana)\
**Replies:** 1\
**Last updated:** [November 1, 2023, 7:34am UTC](https://discuss.elastic.co/t/best-approach-to-combine-two-different-es-instances-in-one-instance/346177 "2023-11-01T07:34:05Z")

</div>

I have two instances running from two different drives. I would like to combine both. I have two approaches. Shutdown second node and use the data path of the second node in the first node as a multi-data path option c…

---

## [High cardinality on APM spans](https://discuss.elastic.co/t/high-cardinality-on-apm-spans/345460)

<div class="topic-metadata">

**Author:** [@Rajat\_Gupta1](https://discuss.elastic.co/u/Rajat_Gupta1)\
**Replies:** 6\
**Last updated:** [November 1, 2023, 7:19am UTC](https://discuss.elastic.co/t/high-cardinality-on-apm-spans/345460 "2023-11-01T07:19:26Z")

</div>

Kibana version: 8.5.1 Elasticsearch version: 8.5.1 APM Server version: 7.\* APM Agent language and version: Node js 20 Browser version: Chrome Original install method (e.g. download page, yum, deb, from source, etc.)…

---

## [Filebeat setup command showing missing references under dasboard directory](https://discuss.elastic.co/t/filebeat-setup-command-showing-missing-references-under-dasboard-directory/346172)

<div class="topic-metadata">

**Author:** [@Akshay\_Ranka](https://discuss.elastic.co/u/Akshay_Ranka)\
**Replies:** 0\
**Last updated:** [November 1, 2023, 5:38am UTC](https://discuss.elastic.co/t/filebeat-setup-command-showing-missing-references-under-dasboard-directory/346172 "2023-11-01T05:38:16Z")

</div>

I installed filebeat and it is up and running as a service. BUT i am not able to run the setup command for filebeat it is showing errors as missing references. It shows error with the json files in the dashboard folder

---

## [Consider comma separated values in a field as separate values while aggregating](https://discuss.elastic.co/t/consider-comma-separated-values-in-a-field-as-separate-values-while-aggregating/345804)

<div class="topic-metadata">

**Author:** [@Gagan\_Saluja](https://discuss.elastic.co/u/Gagan_Saluja)\
**Replies:** 2\
**Last updated:** [November 1, 2023, 4:26am UTC](https://discuss.elastic.co/t/consider-comma-separated-values-in-a-field-as-separate-values-while-aggregating/345804 "2023-11-01T04:26:34Z")

</div>

Hi, i want to do aggregation on a field which has values like doc1\_field: "A" doc2\_field: "A, B" doc3\_field: "A, B, C" What mappings / settings I can use so that when I aggregate on this field I should get results l…

---

## [Maximum document for rollup job](https://discuss.elastic.co/t/maximum-document-for-rollup-job/346169)

<div class="topic-metadata">

**Author:** [@yuswanul](https://discuss.elastic.co/u/yuswanul)\
**Replies:** 0\
**Last updated:** [November 1, 2023, 4:05am UTC](https://discuss.elastic.co/t/maximum-document-for-rollup-job/346169 "2023-11-01T04:05:45Z")

</div>

Hello there, I want to ask about rollup job. Currently, i've been created a rollup job with 1s interval and 5 fields on terms and 2 fields for metrics and 60.000 page size. And the total document for the production inde…

---

## [Ilm rollover error on datastream index](https://discuss.elastic.co/t/ilm-rollover-error-on-datastream-index/346164)

<div class="topic-metadata">

**Author:** [@Russell\_Fulton](https://discuss.elastic.co/u/Russell_Fulton)\
**Replies:** 2\
**Last updated:** [November 1, 2023, 2:30am UTC](https://discuss.elastic.co/t/ilm-rollover-error-on-datastream-index/346164 "2023-11-01T02:30:10Z")

</div>

I one index of a datastream showing an ILM error: java.lang.IllegalStateException: no rollover info found for \[.ds-sec-events-2023.08.12-000015\] with rollover target \[sec-events\], the index has not yet rolled over with …

---

## [Elastic Defend: Unexpected error occurred during diagnostic memory scan: Success](https://discuss.elastic.co/t/elastic-defend-unexpected-error-occurred-during-diagnostic-memory-scan-success/346100)

<div class="topic-metadata">

**Author:** [@aqiank](https://discuss.elastic.co/u/aqiank)\
**Replies:** 2\
**Last updated:** [November 1, 2023, 1:50am UTC](https://discuss.elastic.co/t/elastic-defend-unexpected-error-occurred-during-diagnostic-memory-scan-success/346100 "2023-11-01T01:50:37Z")

</div>

Hi, I added Elastic Defend integration to an active policy and I noticed messages like the one below on the host's logs. \[elastic\_agent.endpoint\_security\]\[warning\] MemoryScan.cpp:677 Unexpected error occurred during dia…

---

## [Elastic Sharepoint Online Python Connector v8.10.3.0 Security Update](https://discuss.elastic.co/t/elastic-sharepoint-online-python-connector-v8-10-3-0-security-update/344732)

<div class="topic-metadata">

**Author:** [@ismisepaul](https://discuss.elastic.co/u/ismisepaul)\
**Replies:** 0\
**Last updated:** [October 10, 2023, 12:18pm UTC](https://discuss.elastic.co/t/elastic-sharepoint-online-python-connector-v8-10-3-0-security-update/344732 "2023-10-10T12:18:57Z")

</div>

Elastic Sharepoint Online Python Connector Improper Access Control (ESA-2023-18) An issue was discovered when using Document Level Security and the SPO "Limited Access" functionality in Elastic Sharepoint Online Python …

[Previous page](https://discuss.elastic.co/latest.md?page=494)

[Next page](https://discuss.elastic.co/latest.md?page=496)
