# Latest

**URL:** https://discuss.elastic.co/latest.md?page=504

[Latest](https://discuss.elastic.co/latest.md) · [Categories](https://discuss.elastic.co/categories.md) · [Tags](https://discuss.elastic.co/tags.md)

**Page:** 505

---

## [Auth kibana through jwt](https://discuss.elastic.co/t/auth-kibana-through-jwt/345384)

<div class="topic-metadata">

**Author:** [@kmz161](https://discuss.elastic.co/u/kmz161)\
**Replies:** 1\
**Last updated:** [October 24, 2023, 2:14pm UTC](https://discuss.elastic.co/t/auth-kibana-through-jwt/345384 "2023-10-24T14:14:07Z")

</div>

Hello! I need auth in kibana through jwt. I find documenation for elastic settings. I use id\_token, current config xpack.security.authc.realms.jwt.jwt1: order: 3 token\_type: id\_token client\_authentication.type: s…

---

## [Pass filters dynamic](https://discuss.elastic.co/t/pass-filters-dynamic/344651)

<div class="topic-metadata">

**Author:** [@fenixon](https://discuss.elastic.co/u/fenixon)\
**Replies:** 1\
**Last updated:** [October 24, 2023, 2:01pm UTC](https://discuss.elastic.co/t/pass-filters-dynamic/344651 "2023-10-24T14:01:08Z")

</div>

I have marked Hostip in the above screenshot. Here I have hardcoded the hostip and I want to change this hostip from filter to dynamic. I have attached the filter screenshot below

---

## [Searching for APM services](https://discuss.elastic.co/t/searching-for-apm-services/345599)

<div class="topic-metadata">

**Author:** [@willemdh](https://discuss.elastic.co/u/willemdh)\
**Replies:** 2\
**Last updated:** [October 24, 2023, 1:52pm UTC](https://discuss.elastic.co/t/searching-for-apm-services/345599 "2023-10-24T13:52:27Z")

</div>

Hello, I was wondering why it seems so hard to search for specific services: We have quite a bit of APM services. Full Text Search on the service name does not give any results in the above searchbar.. Or am I miss…

---

## [Doubt about Coordinating Node Resources](https://discuss.elastic.co/t/doubt-about-coordinating-node-resources/345394)

<div class="topic-metadata">

**Author:** [@RdrgPorto](https://discuss.elastic.co/u/RdrgPorto)\
**Replies:** 8\
**Last updated:** [October 24, 2023, 1:22pm UTC](https://discuss.elastic.co/t/doubt-about-coordinating-node-resources/345394 "2023-10-24T13:22:03Z")

</div>

Hi, everyone I have a couple of questions about coordinating nodes: What are the minimum resources (RAM, CPU, disk) for a coordinating node? What do I need to do in order to estimate the resources for this kind of nod…

---

## [Difference regarding custom Namespace Setting via Fleet Policy Setting or Integrations itself?](https://discuss.elastic.co/t/difference-regarding-custom-namespace-setting-via-fleet-policy-setting-or-integrations-itself/345290)

<div class="topic-metadata">

**Author:** [@daniel-san](https://discuss.elastic.co/u/daniel-san)\
**Replies:** 4\
**Last updated:** [October 24, 2023, 1:35pm UTC](https://discuss.elastic.co/t/difference-regarding-custom-namespace-setting-via-fleet-policy-setting-or-integrations-itself/345290 "2023-10-24T13:35:40Z")

</div>

Hello there, hope you're doing fine! My question: For configure any custom Namespace to separate ingested Data in its own/specific Data Streams i've seen two different places to do this. One is via the Fleet Policy it…

---

## [Parse json in pipeline](https://discuss.elastic.co/t/parse-json-in-pipeline/345612)

<div class="topic-metadata">

**Author:** [@volkerfrank](https://discuss.elastic.co/u/volkerfrank)\
**Replies:** 2\
**Last updated:** [October 24, 2023, 1:28pm UTC](https://discuss.elastic.co/t/parse-json-in-pipeline/345612 "2023-10-24T13:28:36Z")

</div>

When I ingest json logs over a pipeline with a json parser, I get a document\_parsing\_exception error: (status = 400): { "type": "document\_parsing\_exception", "reason": "\[1:15872\] failed to parse field \[gitlab.pa…

---

## [Multiple SQL Database Monitoring](https://discuss.elastic.co/t/multiple-sql-database-monitoring/345593)

<div class="topic-metadata">

**Author:** [@brett877](https://discuss.elastic.co/u/brett877)\
**Replies:** 1\
**Last updated:** [October 24, 2023, 1:18pm UTC](https://discuss.elastic.co/t/multiple-sql-database-monitoring/345593 "2023-10-24T13:18:47Z")

</div>

Hello! I am trying to figure out how to enable "Fetch from all databases" via Fleet Manager and Microsoft SQL Server integration. I have about 150 Databases I need to monitor and I do not want to add them manually here: …

---

## [Error fetching data for metricset postgresql.activity: error in QueryStats: failed to obtain a connection with the database: pq: SSL is not enabled on the server","service.name":"metricbeat","ecs.version":"1.6.0"}](https://discuss.elastic.co/t/error-fetching-data-for-metricset-postgresql-activity-error-in-querystats-failed-to-obtain-a-connection-with-the-database-pq-ssl-is-not-enabled-on-the-server-service-name-metricbeat-ecs-version-1-6-0/344996)

<div class="topic-metadata">

**Author:** [@veerendra\_pulapa](https://discuss.elastic.co/u/veerendra_pulapa)\
**Replies:** 1\
**Last updated:** [October 24, 2023, 12:59pm UTC](https://discuss.elastic.co/t/error-fetching-data-for-metricset-postgresql-activity-error-in-querystats-failed-to-obtain-a-connection-with-the-database-pq-ssl-is-not-enabled-on-the-server-service-name-metricbeat-ecs-version-1-6-0/344996 "2023-10-24T12:59:45Z")

</div>

Dear Team, I'm encountering SSL errors when trying to connect Metricbeat to my PostgreSQL database. Here are the details: Error Message: {"log.level":"error","@timestamp":"2023-10-13T11:45:38.996Z","log.origin":{"fi…

---

## [XMS-XMX settings set in the "options" files are ignored (elasticsearch-8.1, Windows)](https://discuss.elastic.co/t/xms-xmx-settings-set-in-the-options-files-are-ignored-elasticsearch-8-1-windows/345624)

<div class="topic-metadata">

**Author:** [@CrazyDiamond](https://discuss.elastic.co/u/CrazyDiamond)\
**Replies:** 1\
**Last updated:** [October 24, 2023, 11:53am UTC](https://discuss.elastic.co/t/xms-xmx-settings-set-in-the-options-files-are-ignored-elasticsearch-8-1-windows/345624 "2023-10-24T11:53:35Z")

</div>

Hello all. I use a certain product with a built-in Elastic installation (it is installed along with the product, I did not deploy it myself). The server (Windows) has 16GB RAM, and Elastic uses 8 (I see this in the pro…

---

## [Logstash and Beats -Metricbeat,Filebeat stats monitoring using metricbeat](https://discuss.elastic.co/t/logstash-and-beats-metricbeat-filebeat-stats-monitoring-using-metricbeat/344385)

<div class="topic-metadata">

**Author:** [@Jason\_Paralta](https://discuss.elastic.co/u/Jason_Paralta)\
**Replies:** 5\
**Last updated:** [October 24, 2023, 11:50am UTC](https://discuss.elastic.co/t/logstash-and-beats-metricbeat-filebeat-stats-monitoring-using-metricbeat/344385 "2023-10-24T11:50:24Z")

</div>

Hello All, I've a simple requirement as stated below and unable to achieve after attempts: Multiple servers run metricbeat,filebeat and heartbeat in respective servers and in kibana dashboards I'd like to monitor in ta…

---

## [Opensearch adding new value to the old one](https://discuss.elastic.co/t/opensearch-adding-new-value-to-the-old-one/345626)

<div class="topic-metadata">

**Author:** [@Xhar](https://discuss.elastic.co/u/Xhar)\
**Replies:** 1\
**Last updated:** [October 24, 2023, 9:59am UTC](https://discuss.elastic.co/t/opensearch-adding-new-value-to-the-old-one/345626 "2023-10-24T09:59:38Z")

</div>

I have an opensearch and logstash stack; logstash sending logs from the base and i need to not just replace old values(that’s already works with method update in logstash and templates in opensearch), but adding new to t…

---

## [Rollup job and summarize with distinct values](https://discuss.elastic.co/t/rollup-job-and-summarize-with-distinct-values/345625)

<div class="topic-metadata">

**Author:** [@hjazz6](https://discuss.elastic.co/u/hjazz6)\
**Replies:** 0\
**Last updated:** [October 24, 2023, 9:54am UTC](https://discuss.elastic.co/t/rollup-job-and-summarize-with-distinct-values/345625 "2023-10-24T09:54:38Z")

</div>

Hi, Is there a way to have a daily rollup job and instead of aggregations like min, max, etc, we store the distinct values of specific fields instead? Not the distinct count, but the actual values. Thank you.

---

## [Exception when executing JDBC query exception=\>Sequel::DatabaseError, :message=\>"Java::ComMicrosoftSqlserverJdbc::SQLServerException: Connection reset", :cause=\>"# \<Java::ComMicrosoftSqlserverJdbc::SQLServerException: Connection reset](https://discuss.elastic.co/t/exception-when-executing-jdbc-query-exception-sequel-databaseerror-message-java-connection-reset-cause-java-connection-reset/345562)

<div class="topic-metadata">

**Author:** [@Vishweshwar](https://discuss.elastic.co/u/Vishweshwar)\
**Replies:** 1\
**Last updated:** [October 24, 2023, 7:57am UTC](https://discuss.elastic.co/t/exception-when-executing-jdbc-query-exception-sequel-databaseerror-message-java-connection-reset-cause-java-connection-reset/345562 "2023-10-24T07:57:36Z")

</div>

For some time i am able to connect DB but after few seconds i get the error "Exception when executing JDBC query " My logstash config format: input { jdbc { tags =\> "index.conf" jdbc\_connection\_string =\> "jdbc:sqlse…

---

## [Detect the deactivation of log events with Elastic ML](https://discuss.elastic.co/t/detect-the-deactivation-of-log-events-with-elastic-ml/345615)

<div class="topic-metadata">

**Author:** [@phillo197](https://discuss.elastic.co/u/phillo197)\
**Replies:** 0\
**Last updated:** [October 24, 2023, 7:40am UTC](https://discuss.elastic.co/t/detect-the-deactivation-of-log-events-with-elastic-ml/345615 "2023-10-24T07:40:23Z")

</div>

Can someone please help me. I am new to Elastic ML and I need help to configure a Elastic ML-Job, which detects the deactivation of the transmission of log events.

---

## [Network Packet Capture over Logstash](https://discuss.elastic.co/t/network-packet-capture-over-logstash/344976)

<div class="topic-metadata">

**Author:** [@lduvnjak](https://discuss.elastic.co/u/lduvnjak)\
**Replies:** 3\
**Last updated:** [October 24, 2023, 7:15am UTC](https://discuss.elastic.co/t/network-packet-capture-over-logstash/344976 "2023-10-24T07:15:14Z")

</div>

Hi Everyone, I've been having issues trying to use the Network Packet Capture (packetbeat) integration over Logstash. Whenever the Logstash output is configured for fleet, it seems like the integration stops sending da…

---

## [Help with Logstash file input](https://discuss.elastic.co/t/help-with-logstash-file-input/345475)

<div class="topic-metadata">

**Author:** [@roman-tasi](https://discuss.elastic.co/u/roman-tasi)\
**Replies:** 11\
**Last updated:** [October 24, 2023, 5:01am UTC](https://discuss.elastic.co/t/help-with-logstash-file-input/345475 "2023-10-24T05:01:02Z")

</div>

I am not receiving the contents of fortune.txt for my ELK implementation. This is the input section: file { path =\> "/etc/elasticsearch/scripts/otherScripts/fortune.txt" sincedb\_path =\> "/dev/null" sta…

---

## [Updating only a few fields out of many](https://discuss.elastic.co/t/updating-only-a-few-fields-out-of-many/345508)

<div class="topic-metadata">

**Author:** [@ktech007](https://discuss.elastic.co/u/ktech007)\
**Replies:** 3\
**Last updated:** [October 24, 2023, 1:57am UTC](https://discuss.elastic.co/t/updating-only-a-few-fields-out-of-many/345508 "2023-10-24T01:57:32Z")

</div>

ES version: 7.10 100 data nodes 1000 primary shards 5 B documents, 12 TB External versioning We are upserting almost 500 M documents a day and it is done via Index API. Each document could have 50 - 300 fields and in t…

---

## [Docker Elasticsearch 8.10.3 Java Crash](https://discuss.elastic.co/t/docker-elasticsearch-8-10-3-java-crash/345137)

<div class="topic-metadata">

**Author:** [@Matt\_Clairmont](https://discuss.elastic.co/u/Matt_Clairmont)\
**Replies:** 1\
**Last updated:** [October 24, 2023, 1:36am UTC](https://discuss.elastic.co/t/docker-elasticsearch-8-10-3-java-crash/345137 "2023-10-24T01:36:00Z")

</div>

Hey all, I tried upgrading my docker image from 8.8.0 which has been working fine, to 8.10.3 since thats the latest and encountered a Java crash when doing so. I havent been able to get a container running the 8.10.3 im…

---

## [Kibanas is stuck after elasticsearch cluster is ready](https://discuss.elastic.co/t/kibanas-is-stuck-after-elasticsearch-cluster-is-ready/345546)

<div class="topic-metadata">

**Author:** [@expert1](https://discuss.elastic.co/u/expert1)\
**Replies:** 2\
**Last updated:** [October 24, 2023, 1:04am UTC](https://discuss.elastic.co/t/kibanas-is-stuck-after-elasticsearch-cluster-is-ready/345546 "2023-10-24T01:04:15Z")

</div>

Hi, I'm using ECK 2.9. Here are my es and kibana YAML respectively. --- apiVersion: elasticsearch.k8s.elastic.co/v1 kind: Elasticsearch metadata: name: ealsticsearch spec: version: 7.17.14 volumeClaimDeletePolicy…

---

## [APM integration with ElysiaJS and Bun](https://discuss.elastic.co/t/apm-integration-with-elysiajs-and-bun/345530)

<div class="topic-metadata">

**Author:** [@Thai\_Huynh](https://discuss.elastic.co/u/Thai_Huynh)\
**Replies:** 6\
**Last updated:** [October 24, 2023, 12:44am UTC](https://discuss.elastic.co/t/apm-integration-with-elysiajs-and-bun/345530 "2023-10-24T00:44:34Z")

</div>

Hi, Has anyone successfully integrated the APM with ElysiaJS and Bun runtime? We kept getting the following message in the console: APM Server transport error: premature apm-server response with statusCode=202 We trie…

---

## [Index Pattern Refresh](https://discuss.elastic.co/t/index-pattern-refresh/345603)

<div class="topic-metadata">

**Author:** [@Manuel\_Javier\_Martin](https://discuss.elastic.co/u/Manuel_Javier_Martin)\
**Replies:** 1\
**Last updated:** [October 24, 2023, 12:23am UTC](https://discuss.elastic.co/t/index-pattern-refresh/345603 "2023-10-24T00:23:26Z")

</div>

Hi, Im using ES 7.10.2, and Im trying to refresh index patterns within python code, I already hit some endpoints GET api/index\_patterns/\_fields\_for\_wildcard?pattern=statsboard\_logs-\*&stored\_fields=\_source&stored\_fields=…

---

## [Logstash / Docker / Root (RW) access](https://discuss.elastic.co/t/logstash-docker-root-rw-access/345600)

<div class="topic-metadata">

**Author:** [@Phildefer](https://discuss.elastic.co/u/Phildefer)\
**Replies:** 0\
**Last updated:** [October 23, 2023, 10:12pm UTC](https://discuss.elastic.co/t/logstash-docker-root-rw-access/345600 "2023-10-23T22:12:59Z")

</div>

Hi, I'd like to have a root access to my container logstash. I would like to do things that the logstash user doesn't allow (updating packages with apt update, adding packages like nano with apt install nano, etc). Ho…

---

## [Failing TLS handshake between OpenTelemetry and ElasticSearch using ES CA Cert](https://discuss.elastic.co/t/failing-tls-handshake-between-opentelemetry-and-elasticsearch-using-es-ca-cert/345596)

<div class="topic-metadata">

**Author:** [@vsabado](https://discuss.elastic.co/u/vsabado)\
**Replies:** 0\
**Last updated:** [October 23, 2023, 8:26pm UTC](https://discuss.elastic.co/t/failing-tls-handshake-between-opentelemetry-and-elasticsearch-using-es-ca-cert/345596 "2023-10-23T20:26:28Z")

</div>

I downloaded the CA cert for Elastic Search from the security page. I ran the command curl -v --cacert "ESCert.crt" "myESEndpoint" and verified connection just fine. When I configure my OpenTelemetry collector config: e…

---

## [I'm working on new community beat](https://discuss.elastic.co/t/im-working-on-new-community-beat/345594)

<div class="topic-metadata">

**Author:** [@zeynepyz](https://discuss.elastic.co/u/zeynepyz)\
**Replies:** 0\
**Last updated:** [October 23, 2023, 7:33pm UTC](https://discuss.elastic.co/t/im-working-on-new-community-beat/345594 "2023-10-23T19:33:14Z")

</div>

Hello, i'm working on new project that collecting metrics from k6 via restAPI and indexes them then sending them to elasticsearch by beats. I just wonder if anyone working on this?

---

## [What's up with all the 'This topic was automatically closed 28 days after the last reply. New replies are no longer allowed.'?](https://discuss.elastic.co/t/whats-up-with-all-the-this-topic-was-automatically-closed-28-days-after-the-last-reply-new-replies-are-no-longer-allowed/345454)

<div class="topic-metadata">

**Author:** [@Boris\_Juraga](https://discuss.elastic.co/u/Boris_Juraga)\
**Replies:** 3\
**Last updated:** [October 23, 2023, 6:23pm UTC](https://discuss.elastic.co/t/whats-up-with-all-the-this-topic-was-automatically-closed-28-days-after-the-last-reply-new-replies-are-no-longer-allowed/345454 "2023-10-23T18:23:24Z")

</div>

I have been considering on writing this feedback for a while, and i am sure you got it million times, but what is the point of having this 'forum' if no one moderates it? I have a lot of issues with beats and ELK altoge…

---

## [Elasticsearch automatic rebalancing process](https://discuss.elastic.co/t/elasticsearch-automatic-rebalancing-process/345582)

<div class="topic-metadata">

**Author:** [@Itay\_Bittan](https://discuss.elastic.co/u/Itay_Bittan)\
**Replies:** 1\
**Last updated:** [October 23, 2023, 5:39pm UTC](https://discuss.elastic.co/t/elasticsearch-automatic-rebalancing-process/345582 "2023-10-23T17:39:40Z")

</div>

Hi, We are running two (almost) identical Elasticsearch clusters v8.7.0, one of them works perfectly fine and in the second one we have shard balancing issues: is there a way to see why the automatic rebalancing pro…

---

## [ScanError while scrolling more than 10k docs](https://discuss.elastic.co/t/scanerror-while-scrolling-more-than-10k-docs/345517)

<div class="topic-metadata">

**Author:** [@mans4singh](https://discuss.elastic.co/u/mans4singh)\
**Replies:** 5\
**Last updated:** [October 23, 2023, 4:08pm UTC](https://discuss.elastic.co/t/scanerror-while-scrolling-more-than-10k-docs/345517 "2023-10-23T16:08:08Z")

</div>

Hi: I am getting ScanError (ScanError('Scroll request has only succeeded on 7 (+5 skipped) shards out of 15.')) when the search results is large (mostly when it is more than 10k). I have a few questions about it: Wha…

---

## [Elastic Cloud Persistent Queue?](https://discuss.elastic.co/t/elastic-cloud-persistent-queue/345066)

<div class="topic-metadata">

**Author:** [@wwalker](https://discuss.elastic.co/u/wwalker)\
**Replies:** 5\
**Last updated:** [October 23, 2023, 4:00pm UTC](https://discuss.elastic.co/t/elastic-cloud-persistent-queue/345066 "2023-10-23T16:00:53Z")

</div>

I am ingesting logs from an on-prem logstash to Elastic Cloud. My Logstash instance has persistent queue enabled. I ingested a large set of data, about 50 million events from my on-prem Elasticsearch instance using the…

---

## [URL redirect for specific queries instead of search results](https://discuss.elastic.co/t/url-redirect-for-specific-queries-instead-of-search-results/345579)

<div class="topic-metadata">

**Author:** [@Max\_Townsend](https://discuss.elastic.co/u/Max_Townsend)\
**Replies:** 0\
**Last updated:** [October 23, 2023, 3:06pm UTC](https://discuss.elastic.co/t/url-redirect-for-specific-queries-instead-of-search-results/345579 "2023-10-23T15:06:00Z")

</div>

Is it possible to redirect to another page when certain keywords are searched? We are a marketplace and would like to redirect users to specific brand pages instead of a results page. Ability to configure certain queri…

---

## [Fails to receive any log events，when two piplines using the same input port 5044](https://discuss.elastic.co/t/fails-to-receive-any-log-events-when-two-piplines-using-the-same-input-port-5044/345564)

<div class="topic-metadata">

**Author:** [@zhsongbj](https://discuss.elastic.co/u/zhsongbj)\
**Replies:** 2\
**Last updated:** [October 23, 2023, 2:50pm UTC](https://discuss.elastic.co/t/fails-to-receive-any-log-events-when-two-piplines-using-the-same-input-port-5044/345564 "2023-10-23T14:50:04Z")

</div>

I encountered a troubling issue for which I'd like to express my gratitude to anyone who can help. One pipeline consistently failed to receive log events. The problem occurred when two pipelines used the same input port,…

[Previous page](https://discuss.elastic.co/latest.md?page=503)

[Next page](https://discuss.elastic.co/latest.md?page=505)
