# Latest

**URL:** https://discuss.elastic.co/latest.md?page=513

[Latest](https://discuss.elastic.co/latest.md) · [Categories](https://discuss.elastic.co/categories.md) · [Tags](https://discuss.elastic.co/tags.md)

**Page:** 514

---

## [Winlogbeats error when using xml\_query](https://discuss.elastic.co/t/winlogbeats-error-when-using-xml-query/344936)

<div class="topic-metadata">

**Author:** [@rojjin](https://discuss.elastic.co/u/rojjin)\
**Replies:** 6\
**Last updated:** [October 13, 2023, 7:46am UTC](https://discuss.elastic.co/t/winlogbeats-error-when-using-xml-query/344936 "2023-10-13T07:46:31Z")

</div>

Winlogbeats logs an error when trying to use an xml\_query to return custom events. I have read thru the documentation and believe the config is correct. Here is the config: output.logstash: hosts: \["server"\] path: d…

---

## [Facing issuse while running logstash of ELK version 8.10](https://discuss.elastic.co/t/facing-issuse-while-running-logstash-of-elk-version-8-10/344968)

<div class="topic-metadata">

**Author:** [@sandraimmaculate](https://discuss.elastic.co/u/sandraimmaculate)\
**Replies:** 0\
**Last updated:** [October 13, 2023, 6:55am UTC](https://discuss.elastic.co/t/facing-issuse-while-running-logstash-of-elk-version-8-10/344968 "2023-10-13T06:55:40Z")

</div>

Hi, i have installed elk in AWS instance with AMI Ubuntu 20.04 and hardware requirement 2vpcu, 4gb ram. i have created a Logstash configuration file like and created a log file in which contain the access logs when …

---

## [Search error and escaping characters](https://discuss.elastic.co/t/search-error-and-escaping-characters/344935)

<div class="topic-metadata">

**Author:** [@Lewis030](https://discuss.elastic.co/u/Lewis030)\
**Replies:** 1\
**Last updated:** [October 13, 2023, 5:59am UTC](https://discuss.elastic.co/t/search-error-and-escaping-characters/344935 "2023-10-13T05:59:07Z")

</div>

Hello there, i'm trying to play around with a rule to search for instances of the Sticky Key being abused in Windows. The output below has been created from converting a SIGMA rule: process where (event.category : "pro…

---

## [Change the Account which is used to run the elastic stack (Windows Server)](https://discuss.elastic.co/t/change-the-account-which-is-used-to-run-the-elastic-stack-windows-server/344741)

<div class="topic-metadata">

**Author:** [@Shaakxuur](https://discuss.elastic.co/u/Shaakxuur)\
**Replies:** 2\
**Last updated:** [October 13, 2023, 5:39am UTC](https://discuss.elastic.co/t/change-the-account-which-is-used-to-run-the-elastic-stack-windows-server/344741 "2023-10-13T05:39:17Z")

</div>

Hi! I´m running the Elastic Stack onPrem with the latest version 8.10.2 (Elasticsearch - Kibana - WinlogBeat + Metricbeat). The Elastic stack was installed with my normal Windows account on a Windows Server 2016. Now …

---

## [Path of query](https://discuss.elastic.co/t/path-of-query/344958)

<div class="topic-metadata">

**Author:** [@Alan\_Hsiao](https://discuss.elastic.co/u/Alan_Hsiao)\
**Replies:** 0\
**Last updated:** [October 13, 2023, 1:40am UTC](https://discuss.elastic.co/t/path-of-query/344958 "2023-10-13T01:40:17Z")

</div>

This is one of my filter in my watcher "filter": \[ { "range": { "@timestamp": { "gte": "now-30m" } } …

---

## [Elasticsearch data directory in S3 bucket](https://discuss.elastic.co/t/elasticsearch-data-directory-in-s3-bucket/344945)

<div class="topic-metadata">

**Author:** [@zaeemmasood](https://discuss.elastic.co/u/zaeemmasood)\
**Replies:** 5\
**Last updated:** [October 12, 2023, 8:04pm UTC](https://discuss.elastic.co/t/elasticsearch-data-directory-in-s3-bucket/344945 "2023-10-12T20:04:55Z")

</div>

Hi All, Is it possible to have the data directory of a newly built ES 8 cluster hosted on a S3 bucket. Idea is for the data nodes to use S3 instead of local disk or NAS. Thanks

---

## [Apmotel adding resource attributes as labels](https://discuss.elastic.co/t/apmotel-adding-resource-attributes-as-labels/344949)

<div class="topic-metadata">

**Author:** [@Justin\_Thomas](https://discuss.elastic.co/u/Justin_Thomas)\
**Replies:** 0\
**Last updated:** [October 12, 2023, 7:56pm UTC](https://discuss.elastic.co/t/apmotel-adding-resource-attributes-as-labels/344949 "2023-10-12T19:56:19Z")

</div>

I'm hoping someone can help me understand what is happening and how I might fix it. Setup: apm-agent-go open telemetry Go 1.19 I've been trying to use the otel package for tracing and want to expirement with collect…

---

## [Elastic Defend - Folder- Extensions and Process-exceptions](https://discuss.elastic.co/t/elastic-defend-folder-extensions-and-process-exceptions/344810)

<div class="topic-metadata">

**Author:** [@slash24](https://discuss.elastic.co/u/slash24)\
**Replies:** 1\
**Last updated:** [October 12, 2023, 7:37pm UTC](https://discuss.elastic.co/t/elastic-defend-folder-extensions-and-process-exceptions/344810 "2023-10-12T19:37:35Z")

</div>

When using elastic defend on enterprise workloads (Windows Servers), I want to adhere and follow official list of AV exclusions. These guidelines often includes Processes, folders, specific file-extensions (again, window…

---

## [Visualizing certain elements in an Array field](https://discuss.elastic.co/t/visualizing-certain-elements-in-an-array-field/344849)

<div class="topic-metadata">

**Author:** [@hs121](https://discuss.elastic.co/u/hs121)\
**Replies:** 2\
**Last updated:** [October 12, 2023, 3:21pm UTC](https://discuss.elastic.co/t/visualizing-certain-elements-in-an-array-field/344849 "2023-10-12T15:21:18Z")

</div>

Hi there, This is a naive question but I have a field called "tools\_usage" that holds some Array data: e.g tools\_record = \[ "toolname:banana", "toolcategory:fruit", "success:true", \] self.es.index(index="my\_i…

---

## [Elasticsearch api returning empty response (python)](https://discuss.elastic.co/t/elasticsearch-api-returning-empty-response-python/344238)

<div class="topic-metadata">

**Author:** [@Aidan\_Campbell](https://discuss.elastic.co/u/Aidan_Campbell)\
**Replies:** 3\
**Last updated:** [October 12, 2023, 3:10pm UTC](https://discuss.elastic.co/t/elasticsearch-api-returning-empty-response-python/344238 "2023-10-12T15:10:46Z")

</div>

I am trying to retrieve elasticsearch data in python using the elasticsearch rest api. When I attempt to call the search api using the requests python library, the elasticsearch python client, or directly from the comma…

---

## [Bar chart comparison of count for today and yesterday](https://discuss.elastic.co/t/bar-chart-comparison-of-count-for-today-and-yesterday/344687)

<div class="topic-metadata">

**Author:** [@Jason\_Paralta](https://discuss.elastic.co/u/Jason_Paralta)\
**Replies:** 6\
**Last updated:** [October 12, 2023, 2:25pm UTC](https://discuss.elastic.co/t/bar-chart-comparison-of-count-for-today-and-yesterday/344687 "2023-10-12T14:25:28Z")

</div>

Hello, I have 3 different regions namely US,APAC and EMEA based licennse. Now I have index with below field: us.region.license.inuse, apac.region.license.inuse and emea.region.license.inuse and now I want to make bar c…

---

## [Unable to connect one elasticsearch master pod to another pod to setup two node cluster](https://discuss.elastic.co/t/unable-to-connect-one-elasticsearch-master-pod-to-another-pod-to-setup-two-node-cluster/344915)

<div class="topic-metadata">

**Author:** [@Santhosh\_Sekar](https://discuss.elastic.co/u/Santhosh_Sekar)\
**Replies:** 2\
**Last updated:** [October 12, 2023, 2:23pm UTC](https://discuss.elastic.co/t/unable-to-connect-one-elasticsearch-master-pod-to-another-pod-to-setup-two-node-cluster/344915 "2023-10-12T14:23:18Z")

</div>

Hello Team, I am trying to setup two node es cluster in k8s. Issue that i am facing is that es-1 could not elect that as master and could not connect to another pod es-2.yml file cluster.name: "elastic.cluster" …

---

## [Error: Forbidden curl https://artifacts.elastic.co/GPG-KEY-elasticsearch](https://discuss.elastic.co/t/error-forbidden-curl-https-artifacts-elastic-co-gpg-key-elasticsearch/344832)

<div class="topic-metadata">

**Author:** [@qwerty1q2w](https://discuss.elastic.co/u/qwerty1q2w)\
**Replies:** 3\
**Last updated:** [October 12, 2023, 2:13pm UTC](https://discuss.elastic.co/t/error-forbidden-curl-https-artifacts-elastic-co-gpg-key-elasticsearch/344832 "2023-10-12T14:13:11Z")

</div>

Hello! I can't download GPG key from hetzner server. request - curl https://artifacts.elastic.co/GPG-KEY-elasticsearch response 403 Forbidden our client does not have permission to get URL from this server.

---

## [Is reindex from remote included in Python client](https://discuss.elastic.co/t/is-reindex-from-remote-included-in-python-client/344814)

<div class="topic-metadata">

**Author:** [@Shahab\_Malekzadeh](https://discuss.elastic.co/u/Shahab_Malekzadeh)\
**Replies:** 7\
**Last updated:** [October 12, 2023, 1:46pm UTC](https://discuss.elastic.co/t/is-reindex-from-remote-included-in-python-client/344814 "2023-10-12T13:46:04Z")

</div>

The Elasticsearch documentation specify the ability to reindex from remote. Can this be done through Python client? I can't find any example. This is what I got which returns error: host = 'https://XXXXXXXXX' indexna…

---

## [Name resolution in hierarchical facets. How to do it better?](https://discuss.elastic.co/t/name-resolution-in-hierarchical-facets-how-to-do-it-better/344719)

<div class="topic-metadata">

**Author:** [@Zer0](https://discuss.elastic.co/u/Zer0)\
**Replies:** 2\
**Last updated:** [October 12, 2023, 1:33pm UTC](https://discuss.elastic.co/t/name-resolution-in-hierarchical-facets-how-to-do-it-better/344719 "2023-10-12T13:33:52Z")

</div>

Hi, I have a question about how to model the following scenario in ES and if there is a better way for it than we already have. In our system there are documents and categories for these documents. The categories can be…

---

## [Error with Logstash on Docker](https://discuss.elastic.co/t/error-with-logstash-on-docker/344918)

<div class="topic-metadata">

**Author:** [@Samuele\_Lolli](https://discuss.elastic.co/u/Samuele_Lolli)\
**Replies:** 0\
**Last updated:** [October 12, 2023, 12:54pm UTC](https://discuss.elastic.co/t/error-with-logstash-on-docker/344918 "2023-10-12T12:54:17Z")

</div>

Hi everyone, im trying to use logstash with docker but the pipeline doesn't work. I'm using the same configuration that in logstash without docker work fine. I really need help because im stuck. I posted the log and th…

---

## [Logstash Service Restart continuously](https://discuss.elastic.co/t/logstash-service-restart-continuously/344736)

<div class="topic-metadata">

**Author:** [@Kamesh\_Pratapa](https://discuss.elastic.co/u/Kamesh_Pratapa)\
**Replies:** 9\
**Last updated:** [October 12, 2023, 12:45pm UTC](https://discuss.elastic.co/t/logstash-service-restart-continuously/344736 "2023-10-12T12:45:58Z")

</div>

Hi, All of a sudden my logstash service is restarting every 3 minutes and getting the below error \[FATAL\]\[org.logstash.Logstash \] Logstash stopped processing because of an error: (LoadError) Could not load FFI Prov…

---

## [I receive this error when trying to send index to elastic output](https://discuss.elastic.co/t/i-receive-this-error-when-trying-to-send-index-to-elastic-output/344491)

<div class="topic-metadata">

**Author:** [@alex\_base](https://discuss.elastic.co/u/alex_base)\
**Replies:** 2\
**Last updated:** [October 12, 2023, 12:43pm UTC](https://discuss.elastic.co/t/i-receive-this-error-when-trying-to-send-index-to-elastic-output/344491 "2023-10-12T12:43:20Z")

</div>

\[INFO \]\[logstash.agent \] Pipelines running {:count=\>1, :running\_pipelines=\>\[:exec\_result\], :non\_running\_pipelines=\>\[\]} \[2023-10-05T13:36:37,359\]\[ERROR\]\[logstash.javapipeline \]\[exec\_result\] Pipeline worker er…

---

## [Fleet - how does the "Oauth2 Endpoint Params" field work in integration configuration](https://discuss.elastic.co/t/fleet-how-does-the-oauth2-endpoint-params-field-work-in-integration-configuration/344833)

<div class="topic-metadata">

**Author:** [@mik0w](https://discuss.elastic.co/u/mik0w)\
**Replies:** 3\
**Last updated:** [October 12, 2023, 12:04pm UTC](https://discuss.elastic.co/t/fleet-how-does-the-oauth2-endpoint-params-field-work-in-integration-configuration/344833 "2023-10-12T12:04:00Z")

</div>

Hello, I am trying to integrate Elastic with Zoom API. Even though there's a Zoom Webhook integration plugin available in Elastic, I want to query Zoom's REST API. Zoom's API requires user to authenticate using OAuth a…

---

## [Is elasticsearch impacted by libwebp vulnerabilities](https://discuss.elastic.co/t/is-elasticsearch-impacted-by-libwebp-vulnerabilities/344910)

<div class="topic-metadata">

**Author:** [@jaykb77](https://discuss.elastic.co/u/jaykb77)\
**Replies:** 0\
**Last updated:** [October 12, 2023, 12:03pm UTC](https://discuss.elastic.co/t/is-elasticsearch-impacted-by-libwebp-vulnerabilities/344910 "2023-10-12T12:03:38Z")

</div>

We have received information on vulnerabilities(CVE-2023-4863 / CVE-2023-5129) impacting libwebp packages as can be read below. Is elasticsearch or anything from the stack somehow impacted / depending on libwebp?

---

## [Elastic Search Next js 13 integration](https://discuss.elastic.co/t/elastic-search-next-js-13-integration/344905)

<div class="topic-metadata">

**Author:** [@Alex770](https://discuss.elastic.co/u/Alex770)\
**Replies:** 0\
**Last updated:** [October 12, 2023, 11:14am UTC](https://discuss.elastic.co/t/elastic-search-next-js-13-integration/344905 "2023-10-12T11:14:19Z")

</div>

Need help to connect to my cluster using search-ui-elasticsearch-connector with my Next jx 13 app. The tls secure connection was established with elastic client. But I am unable to connect with search-ui library.

---

## [Filebeat is not writing log to Destination folder](https://discuss.elastic.co/t/filebeat-is-not-writing-log-to-destination-folder/344822)

<div class="topic-metadata">

**Author:** [@Debasis\_Mallick](https://discuss.elastic.co/u/Debasis_Mallick)\
**Replies:** 3\
**Last updated:** [October 12, 2023, 11:00am UTC](https://discuss.elastic.co/t/filebeat-is-not-writing-log-to-destination-folder/344822 "2023-10-12T11:00:49Z")

</div>

Hi Team, In my current project I am using filebeat to load csv files to Elasticsearch but filebeat is not writing the log files in to the destination folder instead it is writing /var/log/messages file. Could you please…

---

## [Ram usage problem](https://discuss.elastic.co/t/ram-usage-problem/344900)

<div class="topic-metadata">

**Author:** [@Mertozturkk](https://discuss.elastic.co/u/Mertozturkk)\
**Replies:** 0\
**Last updated:** [October 12, 2023, 10:58am UTC](https://discuss.elastic.co/t/ram-usage-problem/344900 "2023-10-12T10:58:01Z")

</div>

All nodes in the cluster appear to be using approximately 99% of their RAM. What could be the reason for this? I took this image with the elasticvue plugin. This is one of the nodes

---

## [Filebeat service failing after certain time](https://discuss.elastic.co/t/filebeat-service-failing-after-certain-time/344896)

<div class="topic-metadata">

**Author:** [@parvvam](https://discuss.elastic.co/u/parvvam)\
**Replies:** 0\
**Last updated:** [October 12, 2023, 10:45am UTC](https://discuss.elastic.co/t/filebeat-service-failing-after-certain-time/344896 "2023-10-12T10:45:39Z")

</div>

I am using filebeat 7.11.1 to push logs to logstash on a different server where logstatsh and Elasticsearch are installed. The service of filebeat fails after a certain time. It works properly for a minute or two withou…

---

## [How to disable caching in ES?](https://discuss.elastic.co/t/how-to-disable-caching-in-es/344889)

<div class="topic-metadata">

**Author:** [@leslience](https://discuss.elastic.co/u/leslience)\
**Replies:** 1\
**Last updated:** [October 12, 2023, 10:33am UTC](https://discuss.elastic.co/t/how-to-disable-caching-in-es/344889 "2023-10-12T10:33:27Z")

</div>

I am currently facing a challenge where I want to disable the query cache in ES, so that every query request reads data from disk instead of directly accessing ES's JVM memory cache. Query requests include but are not li…

---

## [How to block drilldown except for a specific field in the table in kibana?](https://discuss.elastic.co/t/how-to-block-drilldown-except-for-a-specific-field-in-the-table-in-kibana/344871)

<div class="topic-metadata">

**Author:** [@Aromal\_Thulazi](https://discuss.elastic.co/u/Aromal_Thulazi)\
**Replies:** 2\
**Last updated:** [October 12, 2023, 10:10am UTC](https://discuss.elastic.co/t/how-to-block-drilldown-except-for-a-specific-field-in-the-table-in-kibana/344871 "2023-10-12T10:10:15Z")

</div>

I have two dashboards & it is connected using drilldown .In my first dashboard I have an aggregation based table & have many columns on that table . I want to block the option to go to other dashboard from all other col…

---

## [Kibana Transform\_Vis plugin for 8.x](https://discuss.elastic.co/t/kibana-transform-vis-plugin-for-8-x/344626)

<div class="topic-metadata">

**Author:** [@pchanas](https://discuss.elastic.co/u/pchanas)\
**Replies:** 3\
**Last updated:** [October 12, 2023, 8:56am UTC](https://discuss.elastic.co/t/kibana-transform-vis-plugin-for-8-x/344626 "2023-10-12T08:56:12Z")

</div>

Hi everybody, We have an extensive usage of the transform\_viz plugin firstly released by PhaedrusTheGreek and then maintained by \[gwintzer\] (GitHub - gwintzer/transform\_vis: Transform Visualization for Kibana). Has any…

---

## [Performance tuning in elastic search in application level joins](https://discuss.elastic.co/t/performance-tuning-in-elastic-search-in-application-level-joins/344788)

<div class="topic-metadata">

**Author:** [@yash\_gehi](https://discuss.elastic.co/u/yash_gehi)\
**Replies:** 7\
**Last updated:** [October 12, 2023, 8:47am UTC](https://discuss.elastic.co/t/performance-tuning-in-elastic-search-in-application-level-joins/344788 "2023-10-12T08:47:04Z")

</div>

I have 2 tables which I have to join based on 3 common keys I'm trying for application level joins But it is getting more time in execution and dataset size is kind of large around 3-4 million Can you tell me how…

---

## [Replacing the IP address of two nodes in the elasticsearch cluster](https://discuss.elastic.co/t/replacing-the-ip-address-of-two-nodes-in-the-elasticsearch-cluster/344886)

<div class="topic-metadata">

**Author:** [@zmaxutbekov](https://discuss.elastic.co/u/zmaxutbekov)\
**Replies:** 0\
**Last updated:** [October 12, 2023, 8:44am UTC](https://discuss.elastic.co/t/replacing-the-ip-address-of-two-nodes-in-the-elasticsearch-cluster/344886 "2023-10-12T08:44:19Z")

</div>

Hi, everyone! I have a cluster of 6 nodes. And I needed to change the IP addresses of two nodes. I have taken the following steps: I connected to the node where I need to change the IP address, performed a disable shar…

---

## [How to create API key with built-in role ? Filebeat to Elastic configuration](https://discuss.elastic.co/t/how-to-create-api-key-with-built-in-role-filebeat-to-elastic-configuration/344884)

<div class="topic-metadata">

**Author:** [@Gaetan\_Verdin-Pol](https://discuss.elastic.co/u/Gaetan_Verdin-Pol)\
**Replies:** 0\
**Last updated:** [October 12, 2023, 8:29am UTC](https://discuss.elastic.co/t/how-to-create-api-key-with-built-in-role-filebeat-to-elastic-configuration/344884 "2023-10-12T08:29:29Z")

</div>

Hello all ! I am currently following the nginx filebeat integration from Filebeat to Elastic and I want to use api\_key instead of username/password to authenticate to my Elastic instance and setup the filebeat module. B…

[Previous page](https://discuss.elastic.co/latest.md?page=512)

[Next page](https://discuss.elastic.co/latest.md?page=514)
