# Latest

**URL:** https://discuss.elastic.co/latest.md?page=511

[Latest](https://discuss.elastic.co/latest.md) · [Categories](https://discuss.elastic.co/categories.md) · [Tags](https://discuss.elastic.co/tags.md)

**Page:** 512

---

## [How to login to Kibana embedded in an iframe using API](https://discuss.elastic.co/t/how-to-login-to-kibana-embedded-in-an-iframe-using-api/344895)

<div class="topic-metadata">

**Author:** [@Sanchet\_Nagarnaik](https://discuss.elastic.co/u/Sanchet_Nagarnaik)\
**Replies:** 1\
**Last updated:** [October 16, 2023, 10:29pm UTC](https://discuss.elastic.co/t/how-to-login-to-kibana-embedded-in-an-iframe-using-api/344895 "2023-10-16T22:29:50Z")

</div>

I have a ReactJS and Go based web application. I have a Kibana dashboard embedded in an iframe. Now when a user logs into the application, then that user must be automatically logged into Kibana as well. And the Kibana d…

---

## [Filebeat not collecting logs from EKS](https://discuss.elastic.co/t/filebeat-not-collecting-logs-from-eks/344939)

<div class="topic-metadata">

**Author:** [@rp346](https://discuss.elastic.co/u/rp346)\
**Replies:** 1\
**Last updated:** [October 16, 2023, 6:26pm UTC](https://discuss.elastic.co/t/filebeat-not-collecting-logs-from-eks/344939 "2023-10-16T18:26:25Z")

</div>

I have deployed EBK (8.5.3) stack on AWS EKS with following manifest filebeat.yaml--- apiVersion: rbac.authorization.k8s.io/v1 kind: ClusterRoleBinding metadata: name: filebeat subjects: - kind: ServiceAccount name…

---

## [Display sum of difference of a field between two day](https://discuss.elastic.co/t/display-sum-of-difference-of-a-field-between-two-day/345129)

<div class="topic-metadata">

**Author:** [@elasticforme](https://discuss.elastic.co/u/elasticforme)\
**Replies:** 1\
**Last updated:** [October 16, 2023, 5:54pm UTC](https://discuss.elastic.co/t/display-sum-of-difference-of-a-field-between-two-day/345129 "2023-10-16T17:54:55Z")

</div>

I have daily data I would like to display difference of sum(total\_size) - sum(total\_size) basically difference of today - yesterday.

---

## [Filebeat/Logstash poor disk.queue read performance: is that the maximum i can get?](https://discuss.elastic.co/t/filebeat-logstash-poor-disk-queue-read-performance-is-that-the-maximum-i-can-get/345056)

<div class="topic-metadata">

**Author:** [@sergeyarl](https://discuss.elastic.co/u/sergeyarl)\
**Replies:** 2\
**Last updated:** [October 16, 2023, 5:53pm UTC](https://discuss.elastic.co/t/filebeat-logstash-poor-disk-queue-read-performance-is-that-the-maximum-i-can-get/345056 "2023-10-16T17:53:28Z")

</div>

Testing performance of Filebeat disk.queue. Environment: AWS EC2 OS: Centos 7.x Machine parameters (FB, LS): CPU 8 vcores, RAM 16GB Filebeat version: filebeat-8.10.3-1.x86\_64 Logstash version: logstash-8.10.3-1.x86\_…

---

## [Kibana rule - raise alert when CPU is over 90% for the last 5 min](https://discuss.elastic.co/t/kibana-rule-raise-alert-when-cpu-is-over-90-for-the-last-5-min/344404)

<div class="topic-metadata">

**Author:** [@catalin.bulancea](https://discuss.elastic.co/u/catalin.bulancea)\
**Replies:** 6\
**Last updated:** [October 16, 2023, 5:02pm UTC](https://discuss.elastic.co/t/kibana-rule-raise-alert-when-cpu-is-over-90-for-the-last-5-min/344404 "2023-10-16T17:02:22Z")

</div>

Hi gurus, I'm new to Rules in Kibana so I need your help. I need to raise an email alert when the CPU is constantly exceeding 90% for the past 5 minutes. The way I configured the rule is the following: The alert i…

---

## [Log ELSER inference time](https://discuss.elastic.co/t/log-elser-inference-time/345057)

<div class="topic-metadata">

**Author:** [@cvarano](https://discuss.elastic.co/u/cvarano)\
**Replies:** 2\
**Last updated:** [October 16, 2023, 4:47pm UTC](https://discuss.elastic.co/t/log-elser-inference-time/345057 "2023-10-16T16:47:16Z")

</div>

When using ELSER, you can find the "Avg. inference time" under Kibana \> Analytics \> Machine Learning \> Model Management \> Trained Models. I cannot find any logs related to inference time when searching in Analytics \> Di…

---

## [Use winlogbeat to convert windows event logs to json?](https://discuss.elastic.co/t/use-winlogbeat-to-convert-windows-event-logs-to-json/345126)

<div class="topic-metadata">

**Author:** [@mathurin68](https://discuss.elastic.co/u/mathurin68)\
**Replies:** 0\
**Last updated:** [October 16, 2023, 4:00pm UTC](https://discuss.elastic.co/t/use-winlogbeat-to-convert-windows-event-logs-to-json/345126 "2023-10-16T16:00:30Z")

</div>

Is it still possible to use winlogbeat to convert evtx files to json? I was trying to use the powershell script from here - If(Test-Path -path $pwd\\winlogbeat.exe) { echo "Starting conversion from EVTX to JSON ..."…

---

## [No Data streams](https://discuss.elastic.co/t/no-data-streams/344985)

<div class="topic-metadata">

**Author:** [@Jean-Claude](https://discuss.elastic.co/u/Jean-Claude)\
**Replies:** 4\
**Last updated:** [October 16, 2023, 2:10pm UTC](https://discuss.elastic.co/t/no-data-streams/344985 "2023-10-16T14:10:30Z")

</div>

Hello, i hope you are doing well This my infra ELASTIC v-elkmaster01.sys.u-bordeaux.fr v-elkmaster02.sys.u-bordeaux.fr v-elkmaster03.sys.u-bordeaux.fr p-elkhot01.sys.u-bordeaux.fr p-elkhot02.sys.u-bordeaux.fr p-elkwar…

---

## [Enabling Native Multi-Factor Authentication in On-Premises versions](https://discuss.elastic.co/t/enabling-native-multi-factor-authentication-in-on-premises-versions/345108)

<div class="topic-metadata">

**Author:** [@yago82](https://discuss.elastic.co/u/yago82)\
**Replies:** 1\
**Last updated:** [October 16, 2023, 1:18pm UTC](https://discuss.elastic.co/t/enabling-native-multi-factor-authentication-in-on-premises-versions/345108 "2023-10-16T13:18:32Z")

</div>

Hello everyone, I'm currently using Elasticsearch in an on-premises environment and I'm exploring options to enhance the security of my cluster. I was wondering if enabling a native multi-factor authentication is possib…

---

## [Timestamp format](https://discuss.elastic.co/t/timestamp-format/344951)

<div class="topic-metadata">

**Author:** [@hta](https://discuss.elastic.co/u/hta)\
**Replies:** 9\
**Last updated:** [October 16, 2023, 1:02pm UTC](https://discuss.elastic.co/t/timestamp-format/344951 "2023-10-16T13:02:47Z")

</div>

We get the timestamps in this format: '2023-10-01T01:22:33.123Z'. Where can I set the format? And which time zone is preset? How can I find out the timezone from the timestamp? Is that UTC? We use filebeat agents to co…

---

## [Entreprise Resource Unit](https://discuss.elastic.co/t/entreprise-resource-unit/345104)

<div class="topic-metadata">

**Author:** [@Manal\_A](https://discuss.elastic.co/u/Manal_A)\
**Replies:** 1\
**Last updated:** [October 16, 2023, 12:58pm UTC](https://discuss.elastic.co/t/entreprise-resource-unit/345104 "2023-10-16T12:58:25Z")

</div>

I have a qst about how to calculate Elastic's Enterprise Resource Unit (ERU) licenses. Is it based on system resources or JVM resources? Thank you

---

## [Unable to Display Visualization in custom plugin](https://discuss.elastic.co/t/unable-to-display-visualization-in-custom-plugin/345106)

<div class="topic-metadata">

**Author:** [@Amit\_Dhiman](https://discuss.elastic.co/u/Amit_Dhiman)\
**Replies:** 0\
**Last updated:** [October 16, 2023, 12:52pm UTC](https://discuss.elastic.co/t/unable-to-display-visualization-in-custom-plugin/345106 "2023-10-16T12:52:41Z")

</div>

I am successful to create and display Dashbaords and Lens in my custom plugin. I have some visualizations created in Kibana Admin. I want these visualizations to be rendered into my custom plugin screen. I tried many s…

---

## [Attempted to send a bulk request to elasticsearch, but no there are no living connections in the connection pool. Perhaps Elasticsearch is unreachable or down?](https://discuss.elastic.co/t/attempted-to-send-a-bulk-request-to-elasticsearch-but-no-there-are-no-living-connections-in-the-connection-pool-perhaps-elasticsearch-is-unreachable-or-down/345042)

<div class="topic-metadata">

**Author:** [@Yazid\_Abed\_Alqader](https://discuss.elastic.co/u/Yazid_Abed_Alqader)\
**Replies:** 3\
**Last updated:** [October 16, 2023, 12:25pm UTC](https://discuss.elastic.co/t/attempted-to-send-a-bulk-request-to-elasticsearch-but-no-there-are-no-living-connections-in-the-connection-pool-perhaps-elasticsearch-is-unreachable-or-down/345042 "2023-10-16T12:25:35Z")

</div>

Hi I have these error messages in logstash logs: \[2023-10-15T08:01:31,446\]\[WARN \]\[logstash.outputs.elasticsearch\] Marking url as dead. Last error: \[LogStash::Outputs::ElasticSearch::HttpClient::Pool::HostUnreachableErr…

---

## [Not able to search with date range filter](https://discuss.elastic.co/t/not-able-to-search-with-date-range-filter/345088)

<div class="topic-metadata">

**Author:** [@bhumika](https://discuss.elastic.co/u/bhumika)\
**Replies:** 22\
**Last updated:** [October 16, 2023, 11:35am UTC](https://discuss.elastic.co/t/not-able-to-search-with-date-range-filter/345088 "2023-10-16T11:35:07Z")

</div>

I had integrated Elasticsearch in my ruby on rails project with chewy gem. All the searches are working fine except date range filter I tried every approach but not getting any error or response is always blank array th…

---

## [Observed kernel bug for Elasticsearch 7.17.5 on Debian 12](https://discuss.elastic.co/t/observed-kernel-bug-for-elasticsearch-7-17-5-on-debian-12/345083)

<div class="topic-metadata">

**Author:** [@bunste](https://discuss.elastic.co/u/bunste)\
**Replies:** 2\
**Last updated:** [October 16, 2023, 10:35am UTC](https://discuss.elastic.co/t/observed-kernel-bug-for-elasticsearch-7-17-5-on-debian-12/345083 "2023-10-16T10:35:34Z")

</div>

Hi all, we are running an ES cluster in version 7.17.5 and some of our data nodes are already running on Debian 12. Now recently one data node failed. Elasticsearch itself did not log anything about the incident. Also s…

---

## [Failed to start crawler: starting input failed: error while initializing input: No paths were defined for input accessing](https://discuss.elastic.co/t/failed-to-start-crawler-starting-input-failed-error-while-initializing-input-no-paths-were-defined-for-input-accessing/345085)

<div class="topic-metadata">

**Author:** [@Manula\_Manjitha](https://discuss.elastic.co/u/Manula_Manjitha)\
**Replies:** 0\
**Last updated:** [October 16, 2023, 9:29am UTC](https://discuss.elastic.co/t/failed-to-start-crawler-starting-input-failed-error-while-initializing-input-no-paths-were-defined-for-input-accessing/345085 "2023-10-16T09:29:27Z")

</div>

I have configured two filebeat inputs which the type of them is log. filebeat.inputs: - type: log id: gateway-elk enabled: true paths: - /home/ggg/app/ntp\_gateway/gateway-elk.log fields: {log\_type: gatewayl…

---

## [Grok issues / Fingerprint issues: Value not imported into ES after 6.x - 7-x update](https://discuss.elastic.co/t/grok-issues-fingerprint-issues-value-not-imported-into-es-after-6-x-7-x-update/344357)

<div class="topic-metadata">

**Author:** [@randomnamegenerator](https://discuss.elastic.co/u/randomnamegenerator)\
**Replies:** 9\
**Last updated:** [October 16, 2023, 8:48am UTC](https://discuss.elastic.co/t/grok-issues-fingerprint-issues-value-not-imported-into-es-after-6-x-7-x-update/344357 "2023-10-16T08:48:05Z")

</div>

Hello, I am new to ELK stack especially the filtering / Grok in Logstash, We are having issues importing DATA:servicename value into ES after moving from 6.3.X to a 7.14 version. The grok below is part of our applica…

---

## [Best approach to update huge # of documents (millions) single query](https://discuss.elastic.co/t/best-approach-to-update-huge-of-documents-millions-single-query/345080)

<div class="topic-metadata">

**Author:** [@vtadmin](https://discuss.elastic.co/u/vtadmin)\
**Replies:** 0\
**Last updated:** [October 16, 2023, 8:59am UTC](https://discuss.elastic.co/t/best-approach-to-update-huge-of-documents-millions-single-query/345080 "2023-10-16T08:59:47Z")

</div>

I'm using elastic for storing documents with multiple attributes that can go on and off (like active or inactive). They can go up to 1-2 million per index. On a daily basis I need to synchronize those documents who can…

---

## [Clean filter when going back from a drilldown](https://discuss.elastic.co/t/clean-filter-when-going-back-from-a-drilldown/345068)

<div class="topic-metadata">

**Author:** [@jaimika\_kosambia](https://discuss.elastic.co/u/jaimika_kosambia)\
**Replies:** 0\
**Last updated:** [October 16, 2023, 7:02am UTC](https://discuss.elastic.co/t/clean-filter-when-going-back-from-a-drilldown/345068 "2023-10-16T07:02:28Z")

</div>

How can we clean filter when going back from a drilldown?

---

## [Can't connect OpenTelemetry collector with APM Server](https://discuss.elastic.co/t/cant-connect-opentelemetry-collector-with-apm-server/345064)

<div class="topic-metadata">

**Author:** [@sakibul.munna](https://discuss.elastic.co/u/sakibul.munna)\
**Replies:** 0\
**Last updated:** [October 16, 2023, 5:04am UTC](https://discuss.elastic.co/t/cant-connect-opentelemetry-collector-with-apm-server/345064 "2023-10-16T05:04:18Z")

</div>

Kibana version: 8.10.2 Elasticsearch version: 8.10.2 APM Server version: 8.10.2 APM Agent language and version: Browser version: Chrome Version 118.0.5993.70 (Official Build) (64-bit) Original install method (e.g. d…

---

## [Question About Snapshot and Restore](https://discuss.elastic.co/t/question-about-snapshot-and-restore/345058)

<div class="topic-metadata">

**Author:** [@Faker](https://discuss.elastic.co/u/Faker)\
**Replies:** 0\
**Last updated:** [October 16, 2023, 2:23am UTC](https://discuss.elastic.co/t/question-about-snapshot-and-restore/345058 "2023-10-16T02:23:16Z")

</div>

Hello, I am struggling with Elasticsearch on Docker and have few questions. Even if you don't know the answers to all the questions, I'd appreciate it if you could answer them. Snapshot and Restore : Does Restoring P…

---

## [Fingerprinting source with Elastic Agent](https://discuss.elastic.co/t/fingerprinting-source-with-elastic-agent/345054)

<div class="topic-metadata">

**Author:** [@wwalker](https://discuss.elastic.co/u/wwalker)\
**Replies:** 2\
**Last updated:** [October 16, 2023, 12:05am UTC](https://discuss.elastic.co/t/fingerprinting-source-with-elastic-agent/345054 "2023-10-16T00:05:27Z")

</div>

I am ingesting logs into Elastic Cloud using an Elastic Agent. The agent sends logs to a logstash instance where I do some custom enrichment and then it goes to the cloud to be processed by an Elastic ingest pipeline. I…

---

## [Logstash JDBC unable to run multiple statements and ingest data from different tables](https://discuss.elastic.co/t/logstash-jdbc-unable-to-run-multiple-statements-and-ingest-data-from-different-tables/345015)

<div class="topic-metadata">

**Author:** [@mohsin106](https://discuss.elastic.co/u/mohsin106)\
**Replies:** 7\
**Last updated:** [October 15, 2023, 5:19pm UTC](https://discuss.elastic.co/t/logstash-jdbc-unable-to-run-multiple-statements-and-ingest-data-from-different-tables/345015 "2023-10-15T17:19:10Z")

</div>

Hi, I'm running Logstash version 8.10.2 in a Docker container to ingest data from a MySQL DB into Elastic. I don't know why the first statement is executed but the second one does not execute. Below is my logstash con…

---

## [Duplicate Data](https://discuss.elastic.co/t/duplicate-data/345053)

<div class="topic-metadata">

**Author:** [@Ruwi](https://discuss.elastic.co/u/Ruwi)\
**Replies:** 0\
**Last updated:** [October 15, 2023, 3:05pm UTC](https://discuss.elastic.co/t/duplicate-data/345053 "2023-10-15T15:05:10Z")

</div>

Hello, We have time series indexes created daily in Elasticsearch. We upgraded from version 7.10.2 to 8.10.2. While running our tests, we observed that the data coming with the creation of the first index is duplicate. …

---

## [Getting many more results than expected](https://discuss.elastic.co/t/getting-many-more-results-than-expected/345045)

<div class="topic-metadata">

**Author:** [@Shlomo\_Koppel](https://discuss.elastic.co/u/Shlomo_Koppel)\
**Replies:** 3\
**Last updated:** [October 15, 2023, 2:04pm UTC](https://discuss.elastic.co/t/getting-many-more-results-than-expected/345045 "2023-10-15T14:04:12Z")

</div>

Hi, I am making the following query: {'bool': {'must': \[{'terms': {'doc.attributes.type.keyword': \['Attachment', 'Document'\]}}, {'terms': {'doc.internal\_id': \['xxxx83a1c00f7004b52dxxxx'\]}}\], 'filter': \[{'range': {'doc.…

---

## [Reindexing a big index without down time](https://discuss.elastic.co/t/reindexing-a-big-index-without-down-time/345050)

<div class="topic-metadata">

**Author:** [@PodarcisMuralis](https://discuss.elastic.co/u/PodarcisMuralis)\
**Replies:** 0\
**Last updated:** [October 15, 2023, 12:59pm UTC](https://discuss.elastic.co/t/reindexing-a-big-index-without-down-time/345050 "2023-10-15T12:59:19Z")

</div>

Hi. I have a really big index with 100 millions of documents. I want to add some new fields, change existing ones and delete the redundant ones by applying explicit index. I will also use alias to switch the indiced. …

---

## [Filebeat stops sending logs to logstash, "message":"Harvester could not be started on existing file](https://discuss.elastic.co/t/filebeat-stops-sending-logs-to-logstash-message-harvester-could-not-be-started-on-existing-file/345048)

<div class="topic-metadata">

**Author:** [@aleem](https://discuss.elastic.co/u/aleem)\
**Replies:** 0\
**Last updated:** [October 15, 2023, 12:46pm UTC](https://discuss.elastic.co/t/filebeat-stops-sending-logs-to-logstash-message-harvester-could-not-be-started-on-existing-file/345048 "2023-10-15T12:46:22Z")

</div>

Filebeat stops sending logs to logstash and needs a manual restart to resume. Logs for specific containers are stopped, while other container's logs are still going to logstash. {"log.level":"error","@timestamp":"2023-1…

---

## [Dashboards are not picking right fields](https://discuss.elastic.co/t/dashboards-are-not-picking-right-fields/345032)

<div class="topic-metadata">

**Author:** [@huzaifa224](https://discuss.elastic.co/u/huzaifa224)\
**Replies:** 1\
**Last updated:** [October 15, 2023, 2:07am UTC](https://discuss.elastic.co/t/dashboards-are-not-picking-right-fields/345032 "2023-10-15T02:07:45Z")

</div>

I am sending data from multiple Linux servers to Logstash using Filebeat, which then forwards the data to Elasticsearch after applying parsing rules for SSH logs. The problem is that when I open the default SSH dashboard…

---

## [Logstash Cloudwatch plugin error for bringing logs into Elastic](https://discuss.elastic.co/t/logstash-cloudwatch-plugin-error-for-bringing-logs-into-elastic/345037)

<div class="topic-metadata">

**Author:** [@uprashan](https://discuss.elastic.co/u/uprashan)\
**Replies:** 0\
**Last updated:** [October 15, 2023, 2:10am UTC](https://discuss.elastic.co/t/logstash-cloudwatch-plugin-error-for-bringing-logs-into-elastic/345037 "2023-10-15T02:10:51Z")

</div>

Hi all. I'm running into the Cloudwatch plugin error for Logstash when trying to bring logs (non metrics) as a stream into Logstash.. I'm running the 8.5.3 version of Logstash... Earlier cloudwatch\_logs plugin doesn't se…

---

## [Using Fields in NEST client library](https://discuss.elastic.co/t/using-fields-in-nest-client-library/345033)

<div class="topic-metadata">

**Author:** [@xef](https://discuss.elastic.co/u/xef)\
**Replies:** 0\
**Last updated:** [October 14, 2023, 6:15pm UTC](https://discuss.elastic.co/t/using-fields-in-nest-client-library/345033 "2023-10-14T18:15:05Z")

</div>

When using the Fieds options just to get a selection of fileds using the NEST client library and setting the Source(false), the Hits object's fields property is null. How are we supposed to get access to the values retu…

[Previous page](https://discuss.elastic.co/latest.md?page=510)

[Next page](https://discuss.elastic.co/latest.md?page=512)
