# Latest

**URL:** https://discuss.elastic.co/latest.md?page=529

[Latest](https://discuss.elastic.co/latest.md) · [Categories](https://discuss.elastic.co/categories.md) · [Tags](https://discuss.elastic.co/tags.md)

**Page:** 530

---

## [Importing / Exporting dashboards and agent policy's](https://discuss.elastic.co/t/importing-exporting-dashboards-and-agent-policys/343878)

<div class="topic-metadata">

**Author:** [@Maretti](https://discuss.elastic.co/u/Maretti)\
**Replies:** 2\
**Last updated:** [September 26, 2023, 2:24pm UTC](https://discuss.elastic.co/t/importing-exporting-dashboards-and-agent-policys/343878 "2023-09-26T14:24:39Z")

</div>

Hi, I would like to export my dashboards and agent policies to use in another Elastic cluster. Is this possible to do? If so, how can I do this? Thanks!

---

## [StatusCode:401, Unauthorized - Kibana - API request](https://discuss.elastic.co/t/statuscode-401-unauthorized-kibana-api-request/343899)

<div class="topic-metadata">

**Author:** [@tfournier](https://discuss.elastic.co/u/tfournier)\
**Replies:** 0\
**Last updated:** [September 26, 2023, 2:18pm UTC](https://discuss.elastic.co/t/statuscode-401-unauthorized-kibana-api-request/343899 "2023-09-26T14:18:06Z")

</div>

Hi there, I'm not able to find Kibana cases by API request. This is the error I get : {"statusCode":401,"error":"Unauthorized","message":"Unauthorized"} I'm trying to find cases with this curl : curl --user usern…

---

## [How to parse values as key value not array](https://discuss.elastic.co/t/how-to-parse-values-as-key-value-not-array/342896)

<div class="topic-metadata">

**Author:** [@dreambeam](https://discuss.elastic.co/u/dreambeam)\
**Replies:** 2\
**Last updated:** [September 26, 2023, 2:02pm UTC](https://discuss.elastic.co/t/how-to-parse-values-as-key-value-not-array/342896 "2023-09-26T14:02:17Z")

</div>

Hi there. I am trying parse a text file containing values below. 15, 3241 16, 800 17, 1 Below if my logstash configuration. When I checked in Kibana , I have the field document displayed as a array. "hcount": \[ 800 \] …

---

## [Configuring alerts on event](https://discuss.elastic.co/t/configuring-alerts-on-event/343892)

<div class="topic-metadata">

**Author:** [@oll](https://discuss.elastic.co/u/oll)\
**Replies:** 0\
**Last updated:** [September 26, 2023, 1:45pm UTC](https://discuss.elastic.co/t/configuring-alerts-on-event/343892 "2023-09-26T13:45:20Z")

</div>

Hello! Help me to find a way to notify about winlogbeat event c for example event.code 4625 - An account failed to log on. The idea is to notify the administrator if the number of failed logins from a user exceeds for…

---

## [Unable to send metricbeat to aws MSK kafka with sasl\_ssl authentication](https://discuss.elastic.co/t/unable-to-send-metricbeat-to-aws-msk-kafka-with-sasl-ssl-authentication/343885)

<div class="topic-metadata">

**Author:** [@Kotesh\_Nataru](https://discuss.elastic.co/u/Kotesh_Nataru)\
**Replies:** 0\
**Last updated:** [September 26, 2023, 1:25pm UTC](https://discuss.elastic.co/t/unable-to-send-metricbeat-to-aws-msk-kafka-with-sasl-ssl-authentication/343885 "2023-09-26T13:25:26Z")

</div>

I have created AWS MSK service with SASL\_SSL authentication and able to send/receive data through python code to it. i am trying to send metricbeat and getting the below error. this if from windows machine Here is the m…

---

## [Search\_after still gives me duplicates](https://discuss.elastic.co/t/search-after-still-gives-me-duplicates/343861)

<div class="topic-metadata">

**Author:** [@George\_Githinji](https://discuss.elastic.co/u/George_Githinji)\
**Replies:** 1\
**Last updated:** [September 26, 2023, 1:22pm UTC](https://discuss.elastic.co/t/search-after-still-gives-me-duplicates/343861 "2023-09-26T13:22:32Z")

</div>

Hi, I have implemented a search-after pattern in my Elasticsearch implementation with a hope of solving duplicate issue we are currently facing. On the first request, I am getting a batch of 100 and then get the raw\_scor…

---

## [Why does the documentation lack so many topics?](https://discuss.elastic.co/t/why-does-the-documentation-lack-so-many-topics/343746)

<div class="topic-metadata">

**Author:** [@du-it](https://discuss.elastic.co/u/du-it)\
**Replies:** 4\
**Last updated:** [September 26, 2023, 1:16pm UTC](https://discuss.elastic.co/t/why-does-the-documentation-lack-so-many-topics/343746 "2023-09-26T13:16:49Z")

</div>

To be able to replace org.elasticsearch.\* classes with co.elastic.\* classes it would be very helpful to find a good documentation with a lot of examples. Why is it poorly possible to find any? For instance, what are the…

---

## [Installation and configuring metricbeat in docker](https://discuss.elastic.co/t/installation-and-configuring-metricbeat-in-docker/343736)

<div class="topic-metadata">

**Author:** [@swikriti.debnath](https://discuss.elastic.co/u/swikriti.debnath)\
**Replies:** 1\
**Last updated:** [September 26, 2023, 12:29pm UTC](https://discuss.elastic.co/t/installation-and-configuring-metricbeat-in-docker/343736 "2023-09-26T12:29:42Z")

</div>

Already seen metric beat installation detailed video but without docker . Please arrange one detailed series on metric beat docker installation and configuration.

---

## [Use a NEST based Client with Indices created from fscrawler](https://discuss.elastic.co/t/use-a-nest-based-client-with-indices-created-from-fscrawler/343782)

<div class="topic-metadata">

**Author:** [@Voidi](https://discuss.elastic.co/u/Voidi)\
**Replies:** 4\
**Last updated:** [September 26, 2023, 12:20pm UTC](https://discuss.elastic.co/t/use-a-nest-based-client-with-indices-created-from-fscrawler/343782 "2023-09-26T12:20:17Z")

</div>

I want create Client program based on the NEST Library which queries an Index created with GitHub - dadoonet/fscrawler: Elasticsearch File System Crawler (FS Crawler) . Most NEST tutorials show that i should create a cl…

---

## [How to ignore last element of array in elastic watcher \\ mustache template](https://discuss.elastic.co/t/how-to-ignore-last-element-of-array-in-elastic-watcher-mustache-template/342801)

<div class="topic-metadata">

**Author:** [@vladislav](https://discuss.elastic.co/u/vladislav)\
**Replies:** 1\
**Last updated:** [September 26, 2023, 12:12pm UTC](https://discuss.elastic.co/t/how-to-ignore-last-element-of-array-in-elastic-watcher-mustache-template/342801 "2023-09-26T12:12:49Z")

</div>

Hello! I have an issue when trying to set an elasticsearch watcher. Here is the part of its config: "input": { "chain": { "inputs": \[ { "\*\*first\*\*": { "search": { …

---

## [Will it be possible to change the size of query output while Scrolling](https://discuss.elastic.co/t/will-it-be-possible-to-change-the-size-of-query-output-while-scrolling/343833)

<div class="topic-metadata">

**Author:** [@2fbf693dba5c4818f8b4](https://discuss.elastic.co/u/2fbf693dba5c4818f8b4)\
**Replies:** 1\
**Last updated:** [September 26, 2023, 12:06pm UTC](https://discuss.elastic.co/t/will-it-be-possible-to-change-the-size-of-query-output-while-scrolling/343833 "2023-09-26T12:06:35Z")

</div>

public SearchResponse scroll(String scrollId) throws IOException { log.debug("ScrollId: {}", scrollId); Scroll scroll = new Scroll(TimeValue.timeValueMinutes(5L)); SearchScrollRequest scrollRequest = new SearchScrollR…

---

## [Long "Stop the world" breaks in Tomcat, monitored by apm-java-agent](https://discuss.elastic.co/t/long-stop-the-world-breaks-in-tomcat-monitored-by-apm-java-agent/343675)

<div class="topic-metadata">

**Author:** [@Bela\_Borbely](https://discuss.elastic.co/u/Bela_Borbely)\
**Replies:** 9\
**Last updated:** [September 26, 2023, 11:34am UTC](https://discuss.elastic.co/t/long-stop-the-world-breaks-in-tomcat-monitored-by-apm-java-agent/343675 "2023-09-26T11:34:22Z")

</div>

We have ELK-stack with APM server in the Cloud: cloud.elastic.co (APM Server 8.9.1) We are monitoring our production application servers (several Tomcats behind HAproxy) by apm-java-agent (v 1.42) and we (and unfortunat…

---

## [Date math Incorrect HTTP method for uri](https://discuss.elastic.co/t/date-math-incorrect-http-method-for-uri/343843)

<div class="topic-metadata">

**Author:** [@INS](https://discuss.elastic.co/u/INS)\
**Replies:** 1\
**Last updated:** [September 26, 2023, 11:30am UTC](https://discuss.elastic.co/t/date-math-incorrect-http-method-for-uri/343843 "2023-09-26T11:30:53Z")

</div>

Hi I just want to create index with date math from dev tool console for rollover but I got below error: request PUT /%3Cindex\_test-%7Bnow%2Fd%7BYYYYMMDD%7D%7D%3E { "aliases": { "logs\_write": {} } } { "error…

---

## [Elastic apm instrumentation not working for my Flask application running in python 3.x](https://discuss.elastic.co/t/elastic-apm-instrumentation-not-working-for-my-flask-application-running-in-python-3-x/343693)

<div class="topic-metadata">

**Author:** [@Ankit\_kumar\_Srivasta](https://discuss.elastic.co/u/Ankit_kumar_Srivasta)\
**Replies:** 3\
**Last updated:** [September 26, 2023, 11:22am UTC](https://discuss.elastic.co/t/elastic-apm-instrumentation-not-working-for-my-flask-application-running-in-python-3-x/343693 "2023-09-26T11:22:04Z")

</div>

I am unable to find out transaction traces on kibana server after using the apm object like this. app = Flask(\_\_name\_\_) app.secret\_key = "ahugekey@netcore#2019" app.config\['ELASTIC\_APM'\] = { 'SERVICE\_NAME': 'o…

---

## [Help with POST URL](https://discuss.elastic.co/t/help-with-post-url/343444)

<div class="topic-metadata">

**Author:** [@ElasticNovis](https://discuss.elastic.co/u/ElasticNovis)\
**Replies:** 3\
**Last updated:** [September 26, 2023, 11:14am UTC](https://discuss.elastic.co/t/help-with-post-url/343444 "2023-09-26T11:14:49Z")

</div>

Hi, I am new to POST URLs but my goal is to generate a pdf from a dashboard automatically, and save it locally to a shared area. I have got my POST URL of my dashboard and using Unix curl command I have tried to get the…

---

## [How to restore a snapshot/how to backup the indexes in my locally installed Elastic Search from Elastic Cloud?](https://discuss.elastic.co/t/how-to-restore-a-snapshot-how-to-backup-the-indexes-in-my-locally-installed-elastic-search-from-elastic-cloud/343852)

<div class="topic-metadata">

**Author:** [@Shashank02](https://discuss.elastic.co/u/Shashank02)\
**Replies:** 1\
**Last updated:** [September 26, 2023, 11:06am UTC](https://discuss.elastic.co/t/how-to-restore-a-snapshot-how-to-backup-the-indexes-in-my-locally-installed-elastic-search-from-elastic-cloud/343852 "2023-09-26T11:06:45Z")

</div>

So, I have some indices on my elastic cloud. Initially, I registered a repository on my own AWS S3 bucket and then created a snapshot that has all the indices stored within it. Now, I have installed Elastic Search and Ki…

---

## [How to update ES node transport address](https://discuss.elastic.co/t/how-to-update-es-node-transport-address/343851)

<div class="topic-metadata">

**Author:** [@HadesC](https://discuss.elastic.co/u/HadesC)\
**Replies:** 1\
**Last updated:** [September 26, 2023, 10:59am UTC](https://discuss.elastic.co/t/how-to-update-es-node-transport-address/343851 "2023-09-26T10:59:32Z")

</div>

I have two Red Hat installed ES 7.9.1 nodes (build type: tar) in my environment, joined to same cluster. Suppose one of the Red Hat nodes should only have private IP 10.121.0.2, somehow there is another private IP 10.12…

---

## [Logstash google pubsub output plugin](https://discuss.elastic.co/t/logstash-google-pubsub-output-plugin/343791)

<div class="topic-metadata">

**Author:** [@Bala\_Joshi](https://discuss.elastic.co/u/Bala_Joshi)\
**Replies:** 1\
**Last updated:** [September 26, 2023, 10:21am UTC](https://discuss.elastic.co/t/logstash-google-pubsub-output-plugin/343791 "2023-09-26T10:21:32Z")

</div>

hello All, I am trying to injest to google pubsub topic from logstash server. Below are the configuration google\_pubsub { project\_id =\> "xx" topic =\> "xx" json\_key\_file =\> "xx" #Options for configuring the upload …

---

## [SAML Configuration Questions for Elastic Cloud](https://discuss.elastic.co/t/saml-configuration-questions-for-elastic-cloud/343525)

<div class="topic-metadata">

**Author:** [@yago82](https://discuss.elastic.co/u/yago82)\
**Replies:** 1\
**Last updated:** [September 26, 2023, 10:17am UTC](https://discuss.elastic.co/t/saml-configuration-questions-for-elastic-cloud/343525 "2023-09-26T10:17:37Z")

</div>

Hello Elastic community, I'm currently working on configuring SAML authentication for Elastic Cloud (not ECE). I have the following SAML configuration that I need to implement: xpack.security.authc.realms.saml.saml1: …

---

## [Elastic Cloud on Kubernetes (ECK) 2.8 Security Update](https://discuss.elastic.co/t/elastic-cloud-on-kubernetes-eck-2-8-security-update/343854)

<div class="topic-metadata">

**Author:** [@ismisepaul](https://discuss.elastic.co/u/ismisepaul)\
**Replies:** 0\
**Last updated:** [September 26, 2023, 9:48am UTC](https://discuss.elastic.co/t/elastic-cloud-on-kubernetes-eck-2-8-security-update/343854 "2023-09-26T09:48:13Z")

</div>

Elastic Cloud on Kubernetes (ECK) secret token configuration issue (ESA-2023-11) Secret token configuration is never applied when using ECK \<2.8 with APM Server \>=8.0. This could lead to anonymous requests to an APM Se…

---

## [Kibana Lens Annotations](https://discuss.elastic.co/t/kibana-lens-annotations/343639)

<div class="topic-metadata">

**Author:** [@kbujold\_wr](https://discuss.elastic.co/u/kbujold_wr)\
**Replies:** 1\
**Last updated:** [September 26, 2023, 8:27am UTC](https://discuss.elastic.co/t/kibana-lens-annotations/343639 "2023-09-26T08:27:12Z")

</div>

Hi we are creating a Dashboard in Kibana 8.9.0. We are using Lens. Is there a way to have the annotation value be left justified with the tooltip? Or the ability to make it wider?

---

## [Error while dialing: dial tcp: lookup apm-server on 127.0.0.11:53](https://discuss.elastic.co/t/error-while-dialing-dial-tcp-lookup-apm-server-on-127-0-0-11-53/343354)

<div class="topic-metadata">

**Author:** [@Hamad](https://discuss.elastic.co/u/Hamad)\
**Replies:** 3\
**Last updated:** [September 26, 2023, 8:14am UTC](https://discuss.elastic.co/t/error-while-dialing-dial-tcp-lookup-apm-server-on-127-0-0-11-53/343354 "2023-09-26T08:14:20Z")

</div>

I have installed apm-server to show traces and metrics that are being exported from otel. I can see my service on the APM on kibana but cant see the traces that are exported by otel. while seeing logs of otel collector o…

---

## [Need to create a graph for hourly committed frequency in pie chart](https://discuss.elastic.co/t/need-to-create-a-graph-for-hourly-committed-frequency-in-pie-chart/343842)

<div class="topic-metadata">

**Author:** [@Manjari](https://discuss.elastic.co/u/Manjari)\
**Replies:** 0\
**Last updated:** [September 26, 2023, 7:54am UTC](https://discuss.elastic.co/t/need-to-create-a-graph-for-hourly-committed-frequency-in-pie-chart/343842 "2023-09-26T07:54:00Z")

</div>

No of commits per hour for example 1 commit an hour 5% of the time 2 commit an hour 23% of the time.. and so on

---

## [When using log4j AsyncLoggerContextSelector , trace.id and transaction.id is not injected into the MDC context](https://discuss.elastic.co/t/when-using-log4j-asyncloggercontextselector-trace-id-and-transaction-id-is-not-injected-into-the-mdc-context/343796)

<div class="topic-metadata">

**Author:** [@rkg1201](https://discuss.elastic.co/u/rkg1201)\
**Replies:** 1\
**Last updated:** [September 26, 2023, 7:22am UTC](https://discuss.elastic.co/t/when-using-log4j-asyncloggercontextselector-trace-id-and-transaction-id-is-not-injected-into-the-mdc-context/343796 "2023-09-26T07:22:19Z")

</div>

Hi , we are setting -DLog4jContextSelector=org.apache.logging.log4j.core.async.AsyncLoggerContextSelector in our jvm proprties and using elastic agent version 1.42.0 . When using the above mentioned log4j async context…

---

## [How to go to specific transaction details by just clicking on it on bar chart?](https://discuss.elastic.co/t/how-to-go-to-specific-transaction-details-by-just-clicking-on-it-on-bar-chart/343704)

<div class="topic-metadata">

**Author:** [@Hamad](https://discuss.elastic.co/u/Hamad)\
**Replies:** 2\
**Last updated:** [September 26, 2023, 7:07am UTC](https://discuss.elastic.co/t/how-to-go-to-specific-transaction-details-by-just-clicking-on-it-on-bar-chart/343704 "2023-09-26T07:07:47Z")

</div>

Hi everyone! How can i go into details of specific transaction from the bar chart in dashboard? If i click on any transaction in my bar chart, it adds a filter instead of going to that transaction details page. for now i…

---

## [Heartbeat Http & ICMP - Discovery from CMDB](https://discuss.elastic.co/t/heartbeat-http-icmp-discovery-from-cmdb/343835)

<div class="topic-metadata">

**Author:** [@praveen\_raju](https://discuss.elastic.co/u/praveen_raju)\
**Replies:** 0\
**Last updated:** [September 26, 2023, 6:31am UTC](https://discuss.elastic.co/t/heartbeat-http-icmp-discovery-from-cmdb/343835 "2023-09-26T06:31:28Z")

</div>

Hello, We would like to build the config file ex: heartbeat.yml from our CMDB (ServiceNow & Netbox) inventory. Is it something possible ? Thanks, Praveen

---

## [Data collection and labeling with some of the Beats](https://discuss.elastic.co/t/data-collection-and-labeling-with-some-of-the-beats/343824)

<div class="topic-metadata">

**Author:** [@Oscar\_Llerena](https://discuss.elastic.co/u/Oscar_Llerena)\
**Replies:** 1\
**Last updated:** [September 26, 2023, 5:20am UTC](https://discuss.elastic.co/t/data-collection-and-labeling-with-some-of-the-beats/343824 "2023-09-26T05:20:17Z")

</div>

Hello everyone, I am currently engaged in an exploration of Elastic Stack's Beats products, specifically Packetbeats, FileBeats, WinlogBeats, and Metricbeats, across Linux and Windows platforms. My end goal is to levera…

---

## [Dashboard is not created](https://discuss.elastic.co/t/dashboard-is-not-created/343828)

<div class="topic-metadata">

**Author:** [@Daemon1](https://discuss.elastic.co/u/Daemon1)\
**Replies:** 0\
**Last updated:** [September 26, 2023, 4:58am UTC](https://discuss.elastic.co/t/dashboard-is-not-created/343828 "2023-09-26T04:58:28Z")

</div>

Hi, I am creating dashboard by importing ndjson file. Using below API to import, POST \<kibana host\>:\<port\>/s/\<space\_id\>/api/saved\_objects/\_import Issue is dashboard is created with new dashboard id not with the one p…

---

## [ELK - Enable Kibana Login (Basic Auth) without SSL/TLS on Multi Instance Docker Swarm Cluster](https://discuss.elastic.co/t/elk-enable-kibana-login-basic-auth-without-ssl-tls-on-multi-instance-docker-swarm-cluster/343827)

<div class="topic-metadata">

**Author:** [@vdcharter](https://discuss.elastic.co/u/vdcharter)\
**Replies:** 0\
**Last updated:** [September 26, 2023, 4:24am UTC](https://discuss.elastic.co/t/elk-enable-kibana-login-basic-auth-without-ssl-tls-on-multi-instance-docker-swarm-cluster/343827 "2023-09-26T04:24:47Z")

</div>

Hi, I have a multi node - multi instance (VM and BareMetal servers) docker swarm cluster for my ELK Stack with 3 ES Masters, 3 Kibana Nodes, data nodes etc. ES and Kibana Version - 7.17.8 I want to enable basic authent…

---

## [Asking how to nested logstash](https://discuss.elastic.co/t/asking-how-to-nested-logstash/343826)

<div class="topic-metadata">

**Author:** [@Shi\_Eng\_Ng](https://discuss.elastic.co/u/Shi_Eng_Ng)\
**Replies:** 0\
**Last updated:** [September 26, 2023, 3:47am UTC](https://discuss.elastic.co/t/asking-how-to-nested-logstash/343826 "2023-09-26T03:47:33Z")

</div>

"archives\_id": null, "level\_of\_detail": null, "items": \[ { "barcode": "000892", "brn": "4188", "collection": "\["Books"\]", "updated\_time": "2023-09-13 11:36:56.000000", "suffix": "LAI", "status": "Available", "a…

[Previous page](https://discuss.elastic.co/latest.md?page=528)

[Next page](https://discuss.elastic.co/latest.md?page=530)
