# Latest

**URL:** https://discuss.elastic.co/latest.md?page=510

[Latest](https://discuss.elastic.co/latest.md) · [Categories](https://discuss.elastic.co/categories.md) · [Tags](https://discuss.elastic.co/tags.md)

**Page:** 511

---

## [Query to check field is exist or not](https://discuss.elastic.co/t/query-to-check-field-is-exist-or-not/345206)

<div class="topic-metadata">

**Author:** [@Aniket\_Pant](https://discuss.elastic.co/u/Aniket_Pant)\
**Replies:** 1\
**Last updated:** [October 17, 2023, 1:03pm UTC](https://discuss.elastic.co/t/query-to-check-field-is-exist-or-not/345206 "2023-10-17T13:03:37Z")

</div>

Is there any query we can run to check a fieldname is exist or not

---

## [Stopping/uninstalling Winlogbeat 8.8.2 fails](https://discuss.elastic.co/t/stopping-uninstalling-winlogbeat-8-8-2-fails/345209)

<div class="topic-metadata">

**Author:** [@ben-sec](https://discuss.elastic.co/u/ben-sec)\
**Replies:** 1\
**Last updated:** [October 17, 2023, 1:00pm UTC](https://discuss.elastic.co/t/stopping-uninstalling-winlogbeat-8-8-2-fails/345209 "2023-10-17T13:00:29Z")

</div>

Hello! I have problems with Winlogbeat 8.8.2 on 5% of my clients (service is running but I don't get any logs) and want to get rid of it, but I'm unable to stop the service and to uninstall Winlogbeat. Is there any kind…

---

## [ElasticSearch User Profile/Personalization](https://discuss.elastic.co/t/elasticsearch-user-profile-personalization/345127)

<div class="topic-metadata">

**Author:** [@RodAndTom](https://discuss.elastic.co/u/RodAndTom)\
**Replies:** 1\
**Last updated:** [October 17, 2023, 12:58pm UTC](https://discuss.elastic.co/t/elasticsearch-user-profile-personalization/345127 "2023-10-17T12:58:13Z")

</div>

Hi, I work with IDOL (Intelligent Data Operating Layer) more for more than 13 years and right now, we are evaluating which IDOL functionalities Elasticsearch can perform OOTB. One of these features is the user profile /…

---

## [ILM Setup support for ELK 8.3](https://discuss.elastic.co/t/ilm-setup-support-for-elk-8-3/345061)

<div class="topic-metadata">

**Author:** [@shailendra1](https://discuss.elastic.co/u/shailendra1)\
**Replies:** 1\
**Last updated:** [October 17, 2023, 12:53pm UTC](https://discuss.elastic.co/t/ilm-setup-support-for-elk-8-3/345061 "2023-10-17T12:53:09Z")

</div>

Dear All, i am looking some suggestions for setting up the ILM for my data/streaming/beats . i have below senerios to accomplished and keep running my platforms. Everyday the indices are generating with abc.yyy.mm.dd …

---

## [Custom UDP with PANW integration](https://discuss.elastic.co/t/custom-udp-with-panw-integration/344214)

<div class="topic-metadata">

**Author:** [@Patryk\_Ostrowski](https://discuss.elastic.co/u/Patryk_Ostrowski)\
**Replies:** 4\
**Last updated:** [October 17, 2023, 12:19pm UTC](https://discuss.elastic.co/t/custom-udp-with-panw-integration/344214 "2023-10-17T12:19:41Z")

</div>

Hello, I used PANOS integration that work great for me. Now I want to change my configuration and use Custom UDP Logs integration. In advanced options I changed Ingest pipelines "logs-udp.generic@custom". I also te…

---

## [New GC metrics in Elastic 8.10](https://discuss.elastic.co/t/new-gc-metrics-in-elastic-8-10/343384)

<div class="topic-metadata">

**Author:** [@senyam08](https://discuss.elastic.co/u/senyam08)\
**Replies:** 7\
**Last updated:** [October 17, 2023, 12:14pm UTC](https://discuss.elastic.co/t/new-gc-metrics-in-elastic-8-10/343384 "2023-10-17T12:14:45Z")

</div>

We are using elastic stack 8.10.1 and elastic java agent 1.42. With new changes to GC collection and memory pools usage, would like to clarify the following GC collection count per min is too high (i see 510000 per mi…

---

## [Auto instromentation is not working](https://discuss.elastic.co/t/auto-instromentation-is-not-working/345198)

<div class="topic-metadata">

**Author:** [@Samiullah\_Shah](https://discuss.elastic.co/u/Samiullah_Shah)\
**Replies:** 0\
**Last updated:** [October 17, 2023, 11:32am UTC](https://discuss.elastic.co/t/auto-instromentation-is-not-working/345198 "2023-10-17T11:32:41Z")

</div>

I have simple dotnet application which i want auto instrument. i have followed all the mentioned steps mentioned in the documentation. Steps taken: downloaded and extracted elastic\_apm\_profiler in /home/samiullah/Down…

---

## [Logstash doesn't parse new files in directory](https://discuss.elastic.co/t/logstash-doesnt-parse-new-files-in-directory/345197)

<div class="topic-metadata">

**Author:** [@Xhar](https://discuss.elastic.co/u/Xhar)\
**Replies:** 4\
**Last updated:** [October 17, 2023, 11:13am UTC](https://discuss.elastic.co/t/logstash-doesnt-parse-new-files-in-directory/345197 "2023-10-17T11:13:16Z")

</div>

Logstash doesn't parse new logs files in directory Here's my config input { file{ path =\> "/home/user/Documents/bdu/\*.json" sincedb\_path =\> "/dev/null" type =\> "bdu" codec =\> "json" } } output { …

---

## [Sample code to find similar HTML Documents](https://discuss.elastic.co/t/sample-code-to-find-similar-html-documents/345140)

<div class="topic-metadata">

**Author:** [@Ata\_Zangene](https://discuss.elastic.co/u/Ata_Zangene)\
**Replies:** 1\
**Last updated:** [October 17, 2023, 9:55am UTC](https://discuss.elastic.co/t/sample-code-to-find-similar-html-documents/345140 "2023-10-17T09:55:12Z")

</div>

Hi, I want to index around 10 million of web pages HTML code in elasticsearch, now, I want to give the HTML content as a search query and get the most similar documents related to the search query ( which is an HTML ) s…

---

## [APM server : Log events filtered out but not spans](https://discuss.elastic.co/t/apm-server-log-events-filtered-out-but-not-spans/345121)

<div class="topic-metadata">

**Author:** [@Lazio](https://discuss.elastic.co/u/Lazio)\
**Replies:** 2\
**Last updated:** [October 17, 2023, 9:55am UTC](https://discuss.elastic.co/t/apm-server-log-events-filtered-out-but-not-spans/345121 "2023-10-17T09:55:05Z")

</div>

Kibana version: 7.17.14 Elasticsearch version: 7.17.14 APM Server version: 7.17.14 APM Agent language and version: OTLP Rust 0.13 Original install method (e.g. download page, yum, deb, from source, etc.) and version:…

---

## [Please help me with this error](https://discuss.elastic.co/t/please-help-me-with-this-error/345074)

<div class="topic-metadata">

**Author:** [@Ankit\_kumar\_Srivasta](https://discuss.elastic.co/u/Ankit_kumar_Srivasta)\
**Replies:** 1\
**Last updated:** [October 17, 2023, 9:54am UTC](https://discuss.elastic.co/t/please-help-me-with-this-error/345074 "2023-10-17T09:54:55Z")

</div>

I am getting this error log in aws lambda when i am trying to capture transaction labels. 2023-10-16 07:50:32,698 \[elastic-apm-server-reporter\] ERROR co.elastic.apm.agent.report.IntakeV2ReportingEventHandler - Failed to…

---

## [ELK STACK - LICENSE CLARIFICATION](https://discuss.elastic.co/t/elk-stack-license-clarification/345171)

<div class="topic-metadata">

**Author:** [@venkatesh\_prasanth](https://discuss.elastic.co/u/venkatesh_prasanth)\
**Replies:** 1\
**Last updated:** [October 17, 2023, 9:52am UTC](https://discuss.elastic.co/t/elk-stack-license-clarification/345171 "2023-10-17T09:52:00Z")

</div>

Hi, So Basically I would like to use ELK as monitoring stack for our own purpose, Can We get alerting like mail alert for hearbeat down or anything on this Download Elastic Products | Elastic what are the limitations?…

---

## [How to add a map using GeoServer and kibana 8.10](https://discuss.elastic.co/t/how-to-add-a-map-using-geoserver-and-kibana-8-10/345130)

<div class="topic-metadata">

**Author:** [@Erez\_Danieli](https://discuss.elastic.co/u/Erez_Danieli)\
**Replies:** 6\
**Last updated:** [October 17, 2023, 9:21am UTC](https://discuss.elastic.co/t/how-to-add-a-map-using-geoserver-and-kibana-8-10/345130 "2023-10-17T09:21:19Z")

</div>

Hi there Elastic team, I'm looking for some guidance on how to add a custom map using a geoserver. I have went over the instructions on this blog Kibana and a Custom Tile Server for NHL Data | Elastic Blog and and I ca…

---

## [How to auto delete data older than 2 month or 30 days from elastcisearch index?](https://discuss.elastic.co/t/how-to-auto-delete-data-older-than-2-month-or-30-days-from-elastcisearch-index/345161)

<div class="topic-metadata">

**Author:** [@bbkunbi](https://discuss.elastic.co/u/bbkunbi)\
**Replies:** 5\
**Last updated:** [October 17, 2023, 7:40am UTC](https://discuss.elastic.co/t/how-to-auto-delete-data-older-than-2-month-or-30-days-from-elastcisearch-index/345161 "2023-10-17T07:40:02Z")

</div>

Note: I am not using date in index name like index -yyyy-mm . any method to do this i am using python Elasticsearch client to store data in es database.

---

## [Elastic Alert Rules - History of an alert being disabled/enabled](https://discuss.elastic.co/t/elastic-alert-rules-history-of-an-alert-being-disabled-enabled/344723)

<div class="topic-metadata">

**Author:** [@ElasticNovis](https://discuss.elastic.co/u/ElasticNovis)\
**Replies:** 1\
**Last updated:** [October 17, 2023, 8:01am UTC](https://discuss.elastic.co/t/elastic-alert-rules-history-of-an-alert-being-disabled-enabled/344723 "2023-10-17T08:01:18Z")

</div>

We are using v8.9.0. Is it possible to see a history of when a rule/alert (Stack Management\>Alerts and Insights\>Rules)? I am interested to see the history of when an alert was enabled/disabled. The history of the chang…

---

## [Logstash / elastic-agent how to create rule on events emitted rate](https://discuss.elastic.co/t/logstash-elastic-agent-how-to-create-rule-on-events-emitted-rate/345173)

<div class="topic-metadata">

**Author:** [@antoine\_duriez](https://discuss.elastic.co/u/antoine_duriez)\
**Replies:** 0\
**Last updated:** [October 17, 2023, 8:01am UTC](https://discuss.elastic.co/t/logstash-elastic-agent-how-to-create-rule-on-events-emitted-rate/345173 "2023-10-17T08:01:10Z")

</div>

Hello community, All data collected by my elastic agents (\>4000) is processed by a pair of logstashes. In the Stack Monitoring dashboard I can see the pipeline and the number of events emitted. I would like to know wh…

---

## [Relp error: Relp::InappropriateCommand open expecting syslog](https://discuss.elastic.co/t/relp-error-relp-inappropriatecommand-open-expecting-syslog/345125)

<div class="topic-metadata">

**Author:** [@MarcoV](https://discuss.elastic.co/u/MarcoV)\
**Replies:** 2\
**Last updated:** [October 17, 2023, 7:52am UTC](https://discuss.elastic.co/t/relp-error-relp-inappropriatecommand-open-expecting-syslog/345125 "2023-10-17T07:52:35Z")

</div>

Hello everyone. I have this warning in my logstash log: Relp error: Relp::InappropriateCommand open expecting syslog My logstash configuration filter has input relp as input but with this error the log from syslog are…

---

## [Elastic search v 7.17.10 : x-pack-SSL authentication](https://discuss.elastic.co/t/elastic-search-v-7-17-10-x-pack-ssl-authentication/345172)

<div class="topic-metadata">

**Author:** [@Deepika\_Gupta](https://discuss.elastic.co/u/Deepika_Gupta)\
**Replies:** 0\
**Last updated:** [October 17, 2023, 7:43am UTC](https://discuss.elastic.co/t/elastic-search-v-7-17-10-x-pack-ssl-authentication/345172 "2023-10-17T07:43:17Z")

</div>

Hi Team, In Elasticsearch, we have a cluster node, enabling x-pack, On Master node: x-pack enabled successfully, certification authorities successfully On a Slave node: x-pack enabled successfully, but certification a…

---

## [Elasticsearch](https://discuss.elastic.co/t/elasticsearch/345162)

<div class="topic-metadata">

**Author:** [@merson](https://discuss.elastic.co/u/merson)\
**Replies:** 1\
**Last updated:** [October 17, 2023, 7:31am UTC](https://discuss.elastic.co/t/elasticsearch/345162 "2023-10-17T07:31:01Z")

</div>

Suddenly am getting this Error in Elasticsearch: org.elasticsearch.ElasticsearchException: Trying to create too many scroll contexts. Must be less than or equal to: \[500\]. This limit can be set by changing the \[search.m…

---

## [Ingest pipeline - extract regex from events](https://discuss.elastic.co/t/ingest-pipeline-extract-regex-from-events/345133)

<div class="topic-metadata">

**Author:** [@xyz3](https://discuss.elastic.co/u/xyz3)\
**Replies:** 1\
**Last updated:** [October 17, 2023, 6:36am UTC](https://discuss.elastic.co/t/ingest-pipeline-extract-regex-from-events/345133 "2023-10-17T06:36:18Z")

</div>

Hello I need to extract some text string from existing index field: IMSChargingIdentifier and place it into new, separate field. New, incoming events should be parsed exactly the same way. Here is sample record from t…

---

## [Snapshot restore](https://discuss.elastic.co/t/snapshot-restore/345160)

<div class="topic-metadata">

**Author:** [@Sandeepa\_Kariyawasam](https://discuss.elastic.co/u/Sandeepa_Kariyawasam)\
**Replies:** 0\
**Last updated:** [October 17, 2023, 5:36am UTC](https://discuss.elastic.co/t/snapshot-restore/345160 "2023-10-17T05:36:28Z")

</div>

I have been restoring snapshots which caused some missing errors for some time but I only could find it possible one by one. Is there any way that I can restore all missing or erroneous snapshot all at once?

---

## [After AKS Node Restart - We have lost Disk Queue](https://discuss.elastic.co/t/after-aks-node-restart-we-have-lost-disk-queue/345158)

<div class="topic-metadata">

**Author:** [@zoheb](https://discuss.elastic.co/u/zoheb)\
**Replies:** 0\
**Last updated:** [October 17, 2023, 5:22am UTC](https://discuss.elastic.co/t/after-aks-node-restart-we-have-lost-disk-queue/345158 "2023-10-17T05:22:51Z")

</div>

Hi Team, Yesterday we have restarted our AKS Nodes and we have lost the disk queue. We see a new folder being created at AKS Node. Here is the configuration file for filebeat: volumeMounts: - name: config mountPath:…

---

## [Kibana giving unauthenticated first time but allowing to login second time in same session](https://discuss.elastic.co/t/kibana-giving-unauthenticated-first-time-but-allowing-to-login-second-time-in-same-session/344984)

<div class="topic-metadata">

**Author:** [@amitkumar.gupta](https://discuss.elastic.co/u/amitkumar.gupta)\
**Replies:** 1\
**Last updated:** [October 17, 2023, 5:18am UTC](https://discuss.elastic.co/t/kibana-giving-unauthenticated-first-time-but-allowing-to-login-second-time-in-same-session/344984 "2023-10-17T05:18:04Z")

</div>

I have enabled Kibana login from wso2 API manager. below I have provided Elastic configuration file. I am following instruction to configure wso2 and kibana- https://shanchathusanda.medium.com/log-in-to-elastic-stack-w…

---

## [Elasticsearch-Kibana- Deployment issues in Anthos on-prem K8s cluster](https://discuss.elastic.co/t/elasticsearch-kibana-deployment-issues-in-anthos-on-prem-k8s-cluster/343465)

<div class="topic-metadata">

**Author:** [@Esakki](https://discuss.elastic.co/u/Esakki)\
**Replies:** 27\
**Last updated:** [October 17, 2023, 4:35am UTC](https://discuss.elastic.co/t/elasticsearch-kibana-deployment-issues-in-anthos-on-prem-k8s-cluster/343465 "2023-10-17T04:35:34Z")

</div>

Hi Team, We have Anthos on-prem K8s, where we need to deploy Elasticsearch and Kibana, I used the attached .yaml file but it's not working.. I have two DNS created for Elasticsearch and Kibana something like this elast…

---

## [How to restart an Elasticsearch cluster (2 master node, 2 data node, 1 voting-only master-eligible node) after a 1 master node and 1 data node failed due to hardware failure without losing data?](https://discuss.elastic.co/t/how-to-restart-an-elasticsearch-cluster-2-master-node-2-data-node-1-voting-only-master-eligible-node-after-a-1-master-node-and-1-data-node-failed-due-to-hardware-failure-without-losing-data/345027)

<div class="topic-metadata">

**Author:** [@ThuyNguyen](https://discuss.elastic.co/u/ThuyNguyen)\
**Replies:** 5\
**Last updated:** [October 17, 2023, 3:36am UTC](https://discuss.elastic.co/t/how-to-restart-an-elasticsearch-cluster-2-master-node-2-data-node-1-voting-only-master-eligible-node-after-a-1-master-node-and-1-data-node-failed-due-to-hardware-failure-without-losing-data/345027 "2023-10-17T03:36:05Z")

</div>

Hi team, I have an Elasticsearch cluster which is setup across 3 servers through docker. Here is the configuration that I used: server 1: 1 voting-only master server 2: 1 master node, 1 data node, and snapshot server …

---

## [Signals to consider the nature of operation](https://discuss.elastic.co/t/signals-to-consider-the-nature-of-operation/343681)

<div class="topic-metadata">

**Author:** [@Dhineshkumar\_R](https://discuss.elastic.co/u/Dhineshkumar_R)\
**Replies:** 3\
**Last updated:** [October 17, 2023, 3:11am UTC](https://discuss.elastic.co/t/signals-to-consider-the-nature-of-operation/343681 "2023-10-17T03:11:36Z")

</div>

Hello folks, I recently came across this post Elasticsearch memory-bound tasks. Basis which I am trying to understand the nature of a search request to my cluster. Following are some questions I have What are the sig…

---

## [How can i setup alerts in kibana for a dashboard?](https://discuss.elastic.co/t/how-can-i-setup-alerts-in-kibana-for-a-dashboard/344538)

<div class="topic-metadata">

**Author:** [@Abhiyash\_Agrawal](https://discuss.elastic.co/u/Abhiyash_Agrawal)\
**Replies:** 1\
**Last updated:** [October 17, 2023, 3:01am UTC](https://discuss.elastic.co/t/how-can-i-setup-alerts-in-kibana-for-a-dashboard/344538 "2023-10-17T03:01:26Z")

</div>

I hope this message finds you well. I am reaching out to inquire about the possibilities of setting up alerts in Kibana for specific dashboard charts within defined durations. Our team has been utilizing Kibana for dat…

---

## [How to rollover index that is ending with date](https://discuss.elastic.co/t/how-to-rollover-index-that-is-ending-with-date/344827)

<div class="topic-metadata">

**Author:** [@hiruni.insyncit.net](https://discuss.elastic.co/u/hiruni.insyncit.net)\
**Replies:** 6\
**Last updated:** [October 17, 2023, 2:00am UTC](https://discuss.elastic.co/t/how-to-rollover-index-that-is-ending-with-date/344827 "2023-10-17T02:00:40Z")

</div>

Hi, I have some indices in the cluster that have index names as follows: abc-asd-2023-10-09 abc-asd-2023-10-10 abc-asd-2023-10-11 There is no function running in the cluster to create daily indices. I wanted to add…

---

## [How to properly use Publicly signed Certifiate in kibana to communicate witih elastic?](https://discuss.elastic.co/t/how-to-properly-use-publicly-signed-certifiate-in-kibana-to-communicate-witih-elastic/345034)

<div class="topic-metadata">

**Author:** [@Fosiul\_Alam](https://discuss.elastic.co/u/Fosiul_Alam)\
**Replies:** 19\
**Last updated:** [October 17, 2023, 12:17am UTC](https://discuss.elastic.co/t/how-to-properly-use-publicly-signed-certifiate-in-kibana-to-communicate-witih-elastic/345034 "2023-10-17T00:17:01Z")

</div>

My elasticsearch.yml configuration xpack.security.http.ssl: enabled: true keystore.path: certs/certificates.p12 Bellow procedure has been followed to create certificate.p12 \> cat private-key.key certificate.crt \> …

---

## [Exam Put vs POST](https://discuss.elastic.co/t/exam-put-vs-post/344954)

<div class="topic-metadata">

**Author:** [@Matt\_Clairmont](https://discuss.elastic.co/u/Matt_Clairmont)\
**Replies:** 2\
**Last updated:** [October 16, 2023, 11:36pm UTC](https://discuss.elastic.co/t/exam-put-vs-post/344954 "2023-10-16T23:36:13Z")

</div>

Hi, I've found myself getting a bit confused as to when the appropriate time to use a PUT vs POST when going about the labs. I'm noticing very subtle differences, primarily around server config state, but it seems that m…

[Previous page](https://discuss.elastic.co/latest.md?page=509)

[Next page](https://discuss.elastic.co/latest.md?page=511)
