# Latest

**URL:** https://discuss.elastic.co/latest.md?page=503

[Latest](https://discuss.elastic.co/latest.md) · [Categories](https://discuss.elastic.co/categories.md) · [Tags](https://discuss.elastic.co/tags.md)

**Page:** 504

---

## [Overview page for service groups](https://discuss.elastic.co/t/overview-page-for-service-groups/345646)

<div class="topic-metadata">

**Author:** [@johngregg](https://discuss.elastic.co/u/johngregg)\
**Replies:** 2\
**Last updated:** [October 25, 2023, 9:29am UTC](https://discuss.elastic.co/t/overview-page-for-service-groups/345646 "2023-10-25T09:29:47Z")

</div>

I'm using 8.8.1 Is there a way to show an Overview page for service groups like there is for an individual service? Some of my apps are composed of multiple services and people are asking for a view that aggregates all…

---

## [Is there any api or plugin for alarming/popup when an attack is detected?](https://discuss.elastic.co/t/is-there-any-api-or-plugin-for-alarming-popup-when-an-attack-is-detected/344517)

<div class="topic-metadata">

**Author:** [@lilyyy](https://discuss.elastic.co/u/lilyyy)\
**Replies:** 1\
**Last updated:** [October 25, 2023, 9:17am UTC](https://discuss.elastic.co/t/is-there-any-api-or-plugin-for-alarming-popup-when-an-attack-is-detected/344517 "2023-10-25T09:17:42Z")

</div>

Hello all, When an attack is detected, I want to show someone in a glance we detect the attack likes popup or sounds on kibana. Is there any api or plugin related with it? Thanks

---

## [IIS Integration Log Missing Fields](https://discuss.elastic.co/t/iis-integration-log-missing-fields/345704)

<div class="topic-metadata">

**Author:** [@ivanchak](https://discuss.elastic.co/u/ivanchak)\
**Replies:** 0\
**Last updated:** [October 25, 2023, 8:31am UTC](https://discuss.elastic.co/t/iis-integration-log-missing-fields/345704 "2023-10-25T08:31:22Z")

</div>

Having IIS integration v1.12.2 with default settings setup. All metric dashboard work just fine. Checked receiving both access and error logs from IIS server as well. However, fields like http.response.status\_code and et…

---

## [Fleet server status offline](https://discuss.elastic.co/t/fleet-server-status-offline/345444)

<div class="topic-metadata">

**Author:** [@candyli](https://discuss.elastic.co/u/candyli)\
**Replies:** 5\
**Last updated:** [October 25, 2023, 7:58am UTC](https://discuss.elastic.co/t/fleet-server-status-offline/345444 "2023-10-25T07:58:29Z")

</div>

I install fleet server on my centos7 Successfully. But status always display offline. I also check integration status: commandline status shows as follow: ''' \[root@fleet02 elastic-agent-8.10.4-linux-x86\_64\]# cd …

---

## [Canvas average values getting error](https://discuss.elastic.co/t/canvas-average-values-getting-error/344660)

<div class="topic-metadata">

**Author:** [@fay](https://discuss.elastic.co/u/fay)\
**Replies:** 2\
**Last updated:** [October 25, 2023, 7:20am UTC](https://discuss.elastic.co/t/canvas-average-values-getting-error/344660 "2023-10-25T07:20:59Z")

</div>

Hi , I'm using canvas and I have a field sensordata.value.numeric which is a field with many numbers I want to take the average in this field and show it as a % in Gauge visualization but I got an error while doing that …

---

## [Add a new Elasticsearch to TLS/SSL cluster](https://discuss.elastic.co/t/add-a-new-elasticsearch-to-tls-ssl-cluster/345500)

<div class="topic-metadata">

**Author:** [@Farid\_Niasti](https://discuss.elastic.co/u/Farid_Niasti)\
**Replies:** 3\
**Last updated:** [October 25, 2023, 5:56am UTC](https://discuss.elastic.co/t/add-a-new-elasticsearch-to-tls-ssl-cluster/345500 "2023-10-25T05:56:41Z")

</div>

Hi I have a cluster with 2 nodes of Elasticsearch. TLS/SSL is enables according to the bellow blog: Everything is OK and monitor-node-01 with IP 192.168.11.142 and monitor-node-02 with IP 192.168.11.143 works correct…

---

## [Is possible to create multiple Stored Scripts in 1 single operation using the API?](https://discuss.elastic.co/t/is-possible-to-create-multiple-stored-scripts-in-1-single-operation-using-the-api/345680)

<div class="topic-metadata">

**Author:** [@iTiago](https://discuss.elastic.co/u/iTiago)\
**Replies:** 1\
**Last updated:** [October 25, 2023, 5:31am UTC](https://discuss.elastic.co/t/is-possible-to-create-multiple-stored-scripts-in-1-single-operation-using-the-api/345680 "2023-10-25T05:31:16Z")

</div>

I have more than 2.5K lines in StoredScripts in my old Cloud 5.6 cluster. I want to transfer them to my new Cloud 8.10.4 Cluster. For this, is there a way to automate the creation of these a little using the API? I crea…

---

## [Deleting data while indexing](https://discuss.elastic.co/t/deleting-data-while-indexing/345565)

<div class="topic-metadata">

**Author:** [@Lilia](https://discuss.elastic.co/u/Lilia)\
**Replies:** 4\
**Last updated:** [October 25, 2023, 4:21am UTC](https://discuss.elastic.co/t/deleting-data-while-indexing/345565 "2023-10-25T04:21:16Z")

</div>

Hi all, I have a case where i need to delete data while it is indexing, to stop the process. Is this possible and if yes, can you explain me how to do it? The case is as follow i want to delete a report while it is uplo…

---

## [Fleet can not show CPU/Memory Value, No relate metric logs as well](https://discuss.elastic.co/t/fleet-can-not-show-cpu-memory-value-no-relate-metric-logs-as-well/345688)

<div class="topic-metadata">

**Author:** [@DEXUAN\_ZHU](https://discuss.elastic.co/u/DEXUAN_ZHU)\
**Replies:** 0\
**Last updated:** [October 25, 2023, 3:29am UTC](https://discuss.elastic.co/t/fleet-can-not-show-cpu-memory-value-no-relate-metric-logs-as-well/345688 "2023-10-25T03:29:47Z")

</div>

Hi Guys, I need some help. I installed some elastic agents without any error. Some of them can get CPU/Memory, some are not. Installation steps no difference, and all of them are installed by admin/root permission. For t…

---

## [Duplicate logs issue with elastic integration with Atlassian Jira](https://discuss.elastic.co/t/duplicate-logs-issue-with-elastic-integration-with-atlassian-jira/345676)

<div class="topic-metadata">

**Author:** [@TirathS](https://discuss.elastic.co/u/TirathS)\
**Replies:** 0\
**Last updated:** [October 24, 2023, 10:58pm UTC](https://discuss.elastic.co/t/duplicate-logs-issue-with-elastic-integration-with-atlassian-jira/345676 "2023-10-24T22:58:06Z")

</div>

Hello Everyone, Hope everyone is good. I am facing an issue, i am doing Elastic OOTB integration with Atlassian Jira using API. the integration is working fine, but i am seeing duplicate logs. Is there a way to get r…

---

## [@timestamp long vs. string format](https://discuss.elastic.co/t/timestamp-long-vs-string-format/345663)

<div class="topic-metadata">

**Author:** [@tlacuache](https://discuss.elastic.co/u/tlacuache)\
**Replies:** 7\
**Last updated:** [October 24, 2023, 9:37pm UTC](https://discuss.elastic.co/t/timestamp-long-vs-string-format/345663 "2023-10-24T21:37:43Z")

</div>

I'm working on a project that has a few different components that both write documents to the same indices. One of these components is Arkime, which writes its documents' @timestamp date as UNIX milliseconds value. This …

---

## [Having issues parsing time in CEF](https://discuss.elastic.co/t/having-issues-parsing-time-in-cef/291072)

<div class="topic-metadata">

**Author:** [@harwinds](https://discuss.elastic.co/u/harwinds)\
**Replies:** 15\
**Last updated:** [October 24, 2023, 8:54pm UTC](https://discuss.elastic.co/t/having-issues-parsing-time-in-cef/291072 "2023-10-24T20:54:58Z")

</div>

Hi all, I'm ingesting ExtraHop Reveal X https://www.extrahop.com/products/security/ logs using Fleet Managed Elastic Agent Integration "CEF" using the SYSLOG input over UDP. Most of the fields are being extracted corre…

---

## [ES superuser cannot Create & Delete Kibana index patterns](https://discuss.elastic.co/t/es-superuser-cannot-create-delete-kibana-index-patterns/345665)

<div class="topic-metadata">

**Author:** [@fuwei1234](https://discuss.elastic.co/u/fuwei1234)\
**Replies:** 2\
**Last updated:** [October 24, 2023, 8:37pm UTC](https://discuss.elastic.co/t/es-superuser-cannot-create-delete-kibana-index-patterns/345665 "2023-10-24T20:37:34Z")

</div>

I have an ES770, I am superuser and just found that I cannot create Kibana index pattern. When I create an index pattern, the page shows that successfully find ES index, but Next button does not go to the next page, no r…

---

## [Elasticsearch using lots of CPU and disk, flipping to read-only during heavy use](https://discuss.elastic.co/t/elasticsearch-using-lots-of-cpu-and-disk-flipping-to-read-only-during-heavy-use/345660)

<div class="topic-metadata">

**Author:** [@dpitchford](https://discuss.elastic.co/u/dpitchford)\
**Replies:** 1\
**Last updated:** [October 24, 2023, 8:37pm UTC](https://discuss.elastic.co/t/elasticsearch-using-lots-of-cpu-and-disk-flipping-to-read-only-during-heavy-use/345660 "2023-10-24T20:37:28Z")

</div>

I am trying to understand behavior I am seeing from Elasticsearch 6.8 on a production site. During a period of heavy use (indexing large numbers of documents), Prometheus metrics are showing me that ES is using large amo…

---

## [\[WATCHER\] Failed to Transform payload - Keyword field](https://discuss.elastic.co/t/watcher-failed-to-transform-payload-keyword-field/345666)

<div class="topic-metadata">

**Author:** [@Rossana](https://discuss.elastic.co/u/Rossana)\
**Replies:** 0\
**Last updated:** [October 24, 2023, 8:30pm UTC](https://discuss.elastic.co/t/watcher-failed-to-transform-payload-keyword-field/345666 "2023-10-24T20:30:53Z")

</div>

Hi, I am trying to configure a Watcher of a machine learning job. The ML job is a population job that works with keyword fields. A cause of using the keyword field, watcher gives me this error: This is the search o…

---

## [Clean Install 8.10 Security Configuration](https://discuss.elastic.co/t/clean-install-8-10-security-configuration/345510)

<div class="topic-metadata">

**Author:** [@mgriffith](https://discuss.elastic.co/u/mgriffith)\
**Replies:** 16\
**Last updated:** [October 24, 2023, 6:29pm UTC](https://discuss.elastic.co/t/clean-install-8-10-security-configuration/345510 "2023-10-24T18:29:16Z")

</div>

I've been testing Elastic 7.17 in single-node configuration and have successfully configured minimal and basic security. Now I'd like to setup a new 3-node cluster on the latest version (8.10), but can't for the life of…

---

## [Inline script not firing due to content security policy - dashboard URL link no longer loading](https://discuss.elastic.co/t/inline-script-not-firing-due-to-content-security-policy-dashboard-url-link-no-longer-loading/344092)

<div class="topic-metadata">

**Author:** [@smchamberlin](https://discuss.elastic.co/u/smchamberlin)\
**Replies:** 2\
**Last updated:** [October 24, 2023, 5:31pm UTC](https://discuss.elastic.co/t/inline-script-not-firing-due-to-content-security-policy-dashboard-url-link-no-longer-loading/344092 "2023-10-24T17:31:14Z")

</div>

After upgrading my version of kibana, I can no longer load a clickable hyperlink URL with parameters from my dashboard - it just loads indefinitely and throws exceptions. This is the URL I want to load: http://testserv…

---

## [Reporting on Saved Objects](https://discuss.elastic.co/t/reporting-on-saved-objects/344318)

<div class="topic-metadata">

**Author:** [@Nama\_Chintamani\_Illo](https://discuss.elastic.co/u/Nama_Chintamani_Illo)\
**Replies:** 2\
**Last updated:** [October 24, 2023, 5:03pm UTC](https://discuss.elastic.co/t/reporting-on-saved-objects/344318 "2023-10-24T17:03:48Z")

</div>

Is there a system index anyone would recommend to use for reporting on Kibana Saved Objects?

---

## [Big issue on Request on Canva and kibana](https://discuss.elastic.co/t/big-issue-on-request-on-canva-and-kibana/344365)

<div class="topic-metadata">

**Author:** [@elteraxya](https://discuss.elastic.co/u/elteraxya)\
**Replies:** 1\
**Last updated:** [October 24, 2023, 5:02pm UTC](https://discuss.elastic.co/t/big-issue-on-request-on-canva-and-kibana/344365 "2023-10-24T17:02:56Z")

</div>

Hello everyone, Recently I used canva to make automated reports however I noticed that esql queries on canva allow more things than kql queries on kibana. So I wanted to know if it's possible to make esql queries on ki…

---

## [Confusing about dashboard showing of AKS node memory](https://discuss.elastic.co/t/confusing-about-dashboard-showing-of-aks-node-memory/345150)

<div class="topic-metadata">

**Author:** [@John\_Vo](https://discuss.elastic.co/u/John_Vo)\
**Replies:** 0\
**Last updated:** [October 17, 2023, 3:23am UTC](https://discuss.elastic.co/t/confusing-about-dashboard-showing-of-aks-node-memory/345150 "2023-10-17T03:23:36Z")

</div>

Hi everyone, Currently, I have a bit confuse about dashboard of Memory of AKS node. The Memory usage by Node \[Metrics Kubernetes\] is about 80% The Memory Usage in Infrastructure/Inventory is about 25% Host Ove…

---

## [Kibana logstash pipelines editing multi line](https://discuss.elastic.co/t/kibana-logstash-pipelines-editing-multi-line/345103)

<div class="topic-metadata">

**Author:** [@PeterDK](https://discuss.elastic.co/u/PeterDK)\
**Replies:** 1\
**Last updated:** [October 24, 2023, 4:42pm UTC](https://discuss.elastic.co/t/kibana-logstash-pipelines-editing-multi-line/345103 "2023-10-24T16:42:53Z")

</div>

Hi, anyone noticed the UI change when editing logstash pipelines? Not only the font (size) has changed (way too large in my opinion), but also the behavior. You can duplicate lines with shift+alt+arrow key, moving lin…

---

## [Filebeat journald not collecting logs](https://discuss.elastic.co/t/filebeat-journald-not-collecting-logs/345571)

<div class="topic-metadata">

**Author:** [@Alain\_Bod](https://discuss.elastic.co/u/Alain_Bod)\
**Replies:** 1\
**Last updated:** [October 24, 2023, 4:33pm UTC](https://discuss.elastic.co/t/filebeat-journald-not-collecting-logs/345571 "2023-10-24T16:33:37Z")

</div>

Hi, I've configured a 8.10.2 stack running in docker containers on an Ubuntu 22.04. Collecting logs from docker logs works fine. I now want to collect logs from journald instead, but I don't get anything collected. Is t…

---

## [Problem with security timelines for alias](https://discuss.elastic.co/t/problem-with-security-timelines-for-alias/343966)

<div class="topic-metadata">

**Author:** [@kmz161](https://discuss.elastic.co/u/kmz161)\
**Replies:** 0\
**Last updated:** [September 27, 2023, 9:34am UTC](https://discuss.elastic.co/t/problem-with-security-timelines-for-alias/343966 "2023-09-27T09:34:04Z")

</div>

Hello! I use alias for aggregate and display log log from different sources and I often use alias for SIEM rules and it is work great. But I can't use alias for timeline. When I choose alias in timeline I can't choos…

---

## [Kibana's "average" aggregation display time is showing the time wrong](https://discuss.elastic.co/t/kibanas-average-aggregation-display-time-is-showing-the-time-wrong/344333)

<div class="topic-metadata">

**Author:** [@Skimifil](https://discuss.elastic.co/u/Skimifil)\
**Replies:** 1\
**Last updated:** [October 24, 2023, 4:19pm UTC](https://discuss.elastic.co/t/kibanas-average-aggregation-display-time-is-showing-the-time-wrong/344333 "2023-10-24T16:19:46Z")

</div>

I have a pipeline that processes a field, whose value comes in the format "HH:MM:SS", and transforms it into seconds: ruby { code =\> " duration\_parts = event.get('format\_hh\_mm\_ss').split(':').map{|str| str…

---

## [Splitting Logstash message](https://discuss.elastic.co/t/splitting-logstash-message/345597)

<div class="topic-metadata">

**Author:** [@joecarter](https://discuss.elastic.co/u/joecarter)\
**Replies:** 5\
**Last updated:** [October 24, 2023, 3:37pm UTC](https://discuss.elastic.co/t/splitting-logstash-message/345597 "2023-10-24T15:37:38Z")

</div>

I am pulling events from an Azure Event Hub, but some of the events are being grouped into a single message containing an array of "records", which I want to be processed as individual messages. The format is: { timest…

---

## [Dashboard-to-dashboard drilldown in Markdowns](https://discuss.elastic.co/t/dashboard-to-dashboard-drilldown-in-markdowns/344167)

<div class="topic-metadata">

**Author:** [@sacalata](https://discuss.elastic.co/u/sacalata)\
**Replies:** 1\
**Last updated:** [October 24, 2023, 3:24pm UTC](https://discuss.elastic.co/t/dashboard-to-dashboard-drilldown-in-markdowns/344167 "2023-10-24T15:24:25Z")

</div>

Is it possible to have "Go to Dashboard" drilldowns in Markdown?, sure we can manually place the link of the dashboard, but that won't keep the current applied filters the same way the drilldown in Lens does.

---

## [Alerting for specific user or conditions](https://discuss.elastic.co/t/alerting-for-specific-user-or-conditions/345647)

<div class="topic-metadata">

**Author:** [@daniel-san](https://discuss.elastic.co/u/daniel-san)\
**Replies:** 0\
**Last updated:** [October 24, 2023, 3:12pm UTC](https://discuss.elastic.co/t/alerting-for-specific-user-or-conditions/345647 "2023-10-24T15:12:51Z")

</div>

Hello there! Our question or what we try to achieve: Is there a possibility or best practice of how we can alert/notify specific users in case of alerts for specific hosts? Lets say we monitor (Fleet managed, Agent) a …

---

## [Transforms: How to aggregate multiple events into one event based on shared field?](https://discuss.elastic.co/t/transforms-how-to-aggregate-multiple-events-into-one-event-based-on-shared-field/345055)

<div class="topic-metadata">

**Author:** [@mohsin106](https://discuss.elastic.co/u/mohsin106)\
**Replies:** 0\
**Last updated:** [October 15, 2023, 6:28pm UTC](https://discuss.elastic.co/t/transforms-how-to-aggregate-multiple-events-into-one-event-based-on-shared-field/345055 "2023-10-15T18:28:57Z")

</div>

Hi, I have the following events writing to the same index in ES: { "@timestamp": "2023-10-15T17:06:05.137039490Z", "ssn": null, "z4date": "1697207822", "criminalnotes": null, "reason": null, "notes": null, …

---

## [How to collect the Infra logs using ELK bitnami Image](https://discuss.elastic.co/t/how-to-collect-the-infra-logs-using-elk-bitnami-image/345096)

<div class="topic-metadata">

**Author:** [@Saidi\_Reddy\_Morthala](https://discuss.elastic.co/u/Saidi_Reddy_Morthala)\
**Replies:** 1\
**Last updated:** [October 24, 2023, 2:53pm UTC](https://discuss.elastic.co/t/how-to-collect-the-infra-logs-using-elk-bitnami-image/345096 "2023-10-24T14:53:23Z")

</div>

Hi. I have installed the ELK VM using bitnami image from Azure Market place and I can able to connect to the ELK home page but unable to find the right article to integrate the Azure VM for logging purpose. Kindly help m…

---

## [My search term has reserved characters, and I need to perform a wildcard search](https://discuss.elastic.co/t/my-search-term-has-reserved-characters-and-i-need-to-perform-a-wildcard-search/344943)

<div class="topic-metadata">

**Author:** [@NandhiniD](https://discuss.elastic.co/u/NandhiniD)\
**Replies:** 1\
**Last updated:** [October 24, 2023, 2:51pm UTC](https://discuss.elastic.co/t/my-search-term-has-reserved-characters-and-i-need-to-perform-a-wildcard-search/344943 "2023-10-24T14:51:20Z")

</div>

Hi, I'm trying to search for multiple terms containing special characters using wildcards. To do this, I've employed the query string with the AND operator and multiple terms. When I exclusively use the code below, wil…

[Previous page](https://discuss.elastic.co/latest.md?page=502)

[Next page](https://discuss.elastic.co/latest.md?page=504)
