# Latest

**URL:** https://discuss.elastic.co/latest.md?page=530

[Latest](https://discuss.elastic.co/latest.md) · [Categories](https://discuss.elastic.co/categories.md) · [Tags](https://discuss.elastic.co/tags.md)

**Page:** 531

---

## [Deploy a multi-replica Filebeat Deployment using PersistentVolumeClaims](https://discuss.elastic.co/t/deploy-a-multi-replica-filebeat-deployment-using-persistentvolumeclaims/343610)

<div class="topic-metadata">

**Author:** [@niaomingjian](https://discuss.elastic.co/u/niaomingjian)\
**Replies:** 1\
**Last updated:** [September 26, 2023, 1:24am UTC](https://discuss.elastic.co/t/deploy-a-multi-replica-filebeat-deployment-using-persistentvolumeclaims/343610 "2023-09-26T01:24:07Z")

</div>

I want to use Filebeat to import data from a Kafka topic into Elasticsearch. For high reliability (so other pods can still work if one pod fails), I would like to deploy Filebeat as a multi-replica Deployment. Deploy a …

---

## [Winlogbeat stopping due to Exception](https://discuss.elastic.co/t/winlogbeat-stopping-due-to-exception/343819)

<div class="topic-metadata">

**Author:** [@risshukla](https://discuss.elastic.co/u/risshukla)\
**Replies:** 0\
**Last updated:** [September 26, 2023, 1:22am UTC](https://discuss.elastic.co/t/winlogbeat-stopping-due-to-exception/343819 "2023-09-26T01:22:35Z")

</div>

We've been using Winlogbeat to forward Workstation logs to Logstash. However, we've encountered an issue after installing Winlogbeat (versions 8.10.2) on our Windows Server 2022. The issue is as follows: Exception 0xc0…

---

## [Host in agent stuck in "Updating" status on Fleet-Server](https://discuss.elastic.co/t/host-in-agent-stuck-in-updating-status-on-fleet-server/343664)

<div class="topic-metadata">

**Author:** [@sheaces](https://discuss.elastic.co/u/sheaces)\
**Replies:** 3\
**Last updated:** [September 26, 2023, 1:16am UTC](https://discuss.elastic.co/t/host-in-agent-stuck-in-updating-status-on-fleet-server/343664 "2023-09-26T01:16:22Z")

</div>

Course: Elastic Observability Engineer On-Demand Version: ID: E-J0E990 Question: In lab 2.1, after installing and enrolling the elastic agent to the host, the fleet server reflects that the agent is stuck in "updating"…

---

## [Unable to Upload Winevt to Elastic Stack](https://discuss.elastic.co/t/unable-to-upload-winevt-to-elastic-stack/343809)

<div class="topic-metadata">

**Author:** [@scott\_securit360](https://discuss.elastic.co/u/scott_securit360)\
**Replies:** 0\
**Last updated:** [September 25, 2023, 9:20pm UTC](https://discuss.elastic.co/t/unable-to-upload-winevt-to-elastic-stack/343809 "2023-09-25T21:20:18Z")

</div>

Hello! I've recently enabled Security on my Elastic stack (7.17) using the documentation here. I've completed up until the "Configure Beats security" section, as that is not needed in my environment. I'm using the Bur…

---

## [Elastic Fleet - Add GeoData to winlog through Ingest Pipeline](https://discuss.elastic.co/t/elastic-fleet-add-geodata-to-winlog-through-ingest-pipeline/343805)

<div class="topic-metadata">

**Author:** [@Shane\_Martin](https://discuss.elastic.co/u/Shane_Martin)\
**Replies:** 0\
**Last updated:** [September 25, 2023, 7:56pm UTC](https://discuss.elastic.co/t/elastic-fleet-add-geodata-to-winlog-through-ingest-pipeline/343805 "2023-09-25T19:56:06Z")

</div>

Trying to add geo data based on the winlog.event\_data.destinationIp field. I'm trying to use the custom ingest pipeline in fleets / integration. Testing the pipeline with test data seems to work, but the geo fields in …

---

## [vlSelectionResolve is not being called on specific scenario](https://discuss.elastic.co/t/vlselectionresolve-is-not-being-called-on-specific-scenario/343800)

<div class="topic-metadata">

**Author:** [@EdRayQO](https://discuss.elastic.co/u/EdRayQO)\
**Replies:** 0\
**Last updated:** [September 25, 2023, 6:53pm UTC](https://discuss.elastic.co/t/vlselectionresolve-is-not-being-called-on-specific-scenario/343800 "2023-09-25T18:53:08Z")

</div>

Hello everyone, I'm struggling with a bug I found when implementing a custom visualization using Vega. I'm reposting this from Stackoverflow (Where the Vega folks suggest posting) because nobody is awnsering, so I'm tryi…

---

## [Anomaly rules, select multiple services](https://discuss.elastic.co/t/anomaly-rules-select-multiple-services/343799)

<div class="topic-metadata">

**Author:** [@sguerrero](https://discuss.elastic.co/u/sguerrero)\
**Replies:** 0\
**Last updated:** [September 25, 2023, 6:41pm UTC](https://discuss.elastic.co/t/anomaly-rules-select-multiple-services/343799 "2023-09-25T18:41:30Z")

</div>

Hello, I'm currently utilizing the Anomaly rule under "Rules and Connectors" within the "Stack Management". I've encountered a situation where I need to select specific services to send emails to distinct addresses. Ho…

---

## [Encounter error "Saved field "timeStamp" of data view "index-name" is invalid for use with the "Date Histogram" aggregation. Please select a new field](https://discuss.elastic.co/t/encounter-error-saved-field-timestamp-of-data-view-index-name-is-invalid-for-use-with-the-date-histogram-aggregation-please-select-a-new-field/343798)

<div class="topic-metadata">

**Author:** [@Long\_Nguyen](https://discuss.elastic.co/u/Long_Nguyen)\
**Replies:** 0\
**Last updated:** [September 25, 2023, 6:20pm UTC](https://discuss.elastic.co/t/encounter-error-saved-field-timestamp-of-data-view-index-name-is-invalid-for-use-with-the-date-histogram-aggregation-please-select-a-new-field/343798 "2023-09-25T18:20:16Z")

</div>

Hello everyone, I'm running Elastic Stack 8.3.0. I encounter the following error in Kibana "Discover" with an index: The index is indexed from the following csv file (some fields have been redacted): timeStamp…

---

## [Is it possible to have the cluster use a node's hardware specs for allocation decisions?](https://discuss.elastic.co/t/is-it-possible-to-have-the-cluster-use-a-nodes-hardware-specs-for-allocation-decisions/343634)

<div class="topic-metadata">

**Author:** [@Mike\_Snare](https://discuss.elastic.co/u/Mike_Snare)\
**Replies:** 5\
**Last updated:** [September 25, 2023, 5:59pm UTC](https://discuss.elastic.co/t/is-it-possible-to-have-the-cluster-use-a-nodes-hardware-specs-for-allocation-decisions/343634 "2023-09-25T17:59:44Z")

</div>

I know that it's possible to use custom attributes in allocations for things like rack-awareness, but I'm more interested in whether or not elastic is capable of taking a node's hardware specs into consideration when dec…

---

## [High resource usage of query with large term filter](https://discuss.elastic.co/t/high-resource-usage-of-query-with-large-term-filter/343585)

<div class="topic-metadata">

**Author:** [@Ray\_Zhang](https://discuss.elastic.co/u/Ray_Zhang)\
**Replies:** 4\
**Last updated:** [September 25, 2023, 5:15pm UTC](https://discuss.elastic.co/t/high-resource-usage-of-query-with-large-term-filter/343585 "2023-09-25T17:15:32Z")

</div>

We are running some rather large queries with about 6 thousand of term values in the filter sections. The queries take 20 to 40 more seconds to run and much more CPU usage were observed when running with the large term …

---

## [CSV export from kibana dashboard through external API call](https://discuss.elastic.co/t/csv-export-from-kibana-dashboard-through-external-api-call/340299)

<div class="topic-metadata">

**Author:** [@manish0803](https://discuss.elastic.co/u/manish0803)\
**Replies:** 1\
**Last updated:** [September 25, 2023, 4:43pm UTC](https://discuss.elastic.co/t/csv-export-from-kibana-dashboard-through-external-api-call/340299 "2023-09-25T16:43:22Z")

</div>

Hi, I have researched and implemented the csv export functionality by calling the export link provided by Kibana. referenced : Automatically generate reports | Kibana Guide \[8.6\] | Elastic However, when I use the link…

---

## [.JSON Conf File for Logstash](https://discuss.elastic.co/t/json-conf-file-for-logstash/343638)

<div class="topic-metadata">

**Author:** [@Google-Cloud-DFIR](https://discuss.elastic.co/u/Google-Cloud-DFIR)\
**Replies:** 19\
**Last updated:** [September 25, 2023, 4:17pm UTC](https://discuss.elastic.co/t/json-conf-file-for-logstash/343638 "2023-09-25T16:17:01Z")

</div>

Hello, I've been trying to configure this .conf file to help parse out .json files correctly. This script is able to ingest Google Cloud Audit Logs (in .json), but fails to parse it correctly: input { # stdin {} …

---

## [Aggregate Logs based on Source IP](https://discuss.elastic.co/t/aggregate-logs-based-on-source-ip/343789)

<div class="topic-metadata">

**Author:** [@maof97](https://discuss.elastic.co/u/maof97)\
**Replies:** 0\
**Last updated:** [September 25, 2023, 4:16pm UTC](https://discuss.elastic.co/t/aggregate-logs-based-on-source-ip/343789 "2023-09-25T16:16:26Z")

</div>

Hello, I'm collecting firewall logs from a firewall (PfSense). On every log record, among other details, I have destination ip addresses and destination ports. Now, I need to have an aggregated list of all destination…

---

## [How to find polygons that contain a given point in Elasticsearch](https://discuss.elastic.co/t/how-to-find-polygons-that-contain-a-given-point-in-elasticsearch/343769)

<div class="topic-metadata">

**Author:** [@Pranav\_Kapur](https://discuss.elastic.co/u/Pranav_Kapur)\
**Replies:** 5\
**Last updated:** [September 25, 2023, 4:05pm UTC](https://discuss.elastic.co/t/how-to-find-polygons-that-contain-a-given-point-in-elasticsearch/343769 "2023-09-25T16:05:57Z")

</div>

I need to build a query on a database with around 50k terrain polygons (stored as geo\_shape polygons on ES) where I give a point and it returns every polygon that contains this point. I tried to create it, but getting i…

---

## [Transform checkpoints not optimized with date histogram](https://discuss.elastic.co/t/transform-checkpoints-not-optimized-with-date-histogram/343561)

<div class="topic-metadata">

**Author:** [@Imran\_Arshad](https://discuss.elastic.co/u/Imran_Arshad)\
**Replies:** 5\
**Last updated:** [September 25, 2023, 4:01pm UTC](https://discuss.elastic.co/t/transform-checkpoints-not-optimized-with-date-histogram/343561 "2023-09-25T16:01:20Z")

</div>

I am running a transform that groups by 2 fields: 1. terms on a keyword field (client\_id), 2. date histogram on a date field (transaction\_time). For sync, I am using a separate date field (updated\_at) that is basically t…

---

## [Error when clicking View Details for alert](https://discuss.elastic.co/t/error-when-clicking-view-details-for-alert/343773)

<div class="topic-metadata">

**Author:** [@val722](https://discuss.elastic.co/u/val722)\
**Replies:** 4\
**Last updated:** [September 25, 2023, 3:41pm UTC](https://discuss.elastic.co/t/error-when-clicking-view-details-for-alert/343773 "2023-09-25T15:41:58Z")

</div>

Hello I created a custom threshold detection rule and I get this error in Kibana when I click View details for the alert generated by that rule Error Error: Object.hasOwn is not a function o/\<@http://192.168.56.130:560…

---

## [How does logstash handle multiline logs in a load balancing configuration](https://discuss.elastic.co/t/how-does-logstash-handle-multiline-logs-in-a-load-balancing-configuration/343780)

<div class="topic-metadata">

**Author:** [@Ror](https://discuss.elastic.co/u/Ror)\
**Replies:** 2\
**Last updated:** [September 25, 2023, 3:18pm UTC](https://discuss.elastic.co/t/how-does-logstash-handle-multiline-logs-in-a-load-balancing-configuration/343780 "2023-09-25T15:18:17Z")

</div>

Hi all, We collect our infrastructure logs with filebeat on elastic cloud. We'd like to add a logstash cluster (multiple logstash instances load-balanced) between our filebeat agents and our elastic cloud cluster. The …

---

## [Backend calls not being traced](https://discuss.elastic.co/t/backend-calls-not-being-traced/343657)

<div class="topic-metadata">

**Author:** [@johngregg](https://discuss.elastic.co/u/johngregg)\
**Replies:** 1\
**Last updated:** [September 25, 2023, 3:11pm UTC](https://discuss.elastic.co/t/backend-calls-not-being-traced/343657 "2023-09-25T15:11:08Z")

</div>

I am using the 1.42 java agent with java 11. Some of my backend calls are not being traced. I have multiple backends that I use Apache HttpClient 4.5 with. Some are traced and some are not. I took thread dumps and th…

---

## [No way to rollover mutable timeseries data](https://discuss.elastic.co/t/no-way-to-rollover-mutable-timeseries-data/343784)

<div class="topic-metadata">

**Author:** [@kmcclellan](https://discuss.elastic.co/u/kmcclellan)\
**Replies:** 0\
**Last updated:** [September 25, 2023, 2:57pm UTC](https://discuss.elastic.co/t/no-way-to-rollover-mutable-timeseries-data/343784 "2023-09-25T14:57:56Z")

</div>

Since datastreams are append-only, Tutorial: Automate rollover with ILM | Elasticsearch Guide \[8.10\] | Elastic suggests an alternative technique for rolling over mutable documents: In these cases, you can use an index …

---

## [How different are Elasticsearch and OpenSearch?](https://discuss.elastic.co/t/how-different-are-elasticsearch-and-opensearch/343691)

<div class="topic-metadata">

**Author:** [@heermaas3](https://discuss.elastic.co/u/heermaas3)\
**Replies:** 6\
**Last updated:** [September 25, 2023, 2:48pm UTC](https://discuss.elastic.co/t/how-different-are-elasticsearch-and-opensearch/343691 "2023-09-25T14:48:50Z")

</div>

I wanted to ask for a neutral opinion on the differences between Elasticsearch and OpenSearch. Are there differences in use/integrating them into my Software? Do I have to write different code to use both of them? Can …

---

## [GROK pattern help for Audit Log](https://discuss.elastic.co/t/grok-pattern-help-for-audit-log/343761)

<div class="topic-metadata">

**Author:** [@ataylor](https://discuss.elastic.co/u/ataylor)\
**Replies:** 2\
**Last updated:** [September 25, 2023, 2:48pm UTC](https://discuss.elastic.co/t/grok-pattern-help-for-audit-log/343761 "2023-09-25T14:48:14Z")

</div>

I am struggling to find an appropriate GROK pattern to appropriately dissect my log that is being generated by the xpack Audit. My Logs currently look like {"type":"audit", "timestamp":"2023-09-07T14:34:58,359+0100", "…

---

## [How to implement Phrase suggester using .net elastic.clients.elasticsearch?](https://discuss.elastic.co/t/how-to-implement-phrase-suggester-using-net-elastic-clients-elasticsearch/343757)

<div class="topic-metadata">

**Author:** [@Bhavyagc](https://discuss.elastic.co/u/Bhavyagc)\
**Replies:** 1\
**Last updated:** [September 25, 2023, 1:25pm UTC](https://discuss.elastic.co/t/how-to-implement-phrase-suggester-using-net-elastic-clients-elasticsearch/343757 "2023-09-25T13:25:39Z")

</div>

How to implement Phrase suggester using .net elastic.clients.elasticsearch in a best way

---

## [Mapper\_exception while using runtime dynamic mapping](https://discuss.elastic.co/t/mapper-exception-while-using-runtime-dynamic-mapping/343764)

<div class="topic-metadata">

**Author:** [@jaykb77](https://discuss.elastic.co/u/jaykb77)\
**Replies:** 0\
**Last updated:** [September 25, 2023, 1:13pm UTC](https://discuss.elastic.co/t/mapper-exception-while-using-runtime-dynamic-mapping/343764 "2023-09-25T13:13:49Z")

</div>

Hi, We are using runtime dynamic mapping for indices and receiving below error while indexing. Indexing failed for some events, type: mapper\_exception, reason: timed out while waiting for a dynamic mapping update Even…

---

## [Update ILM and link to an existing index](https://discuss.elastic.co/t/update-ilm-and-link-to-an-existing-index/343762)

<div class="topic-metadata">

**Author:** [@sam1975](https://discuss.elastic.co/u/sam1975)\
**Replies:** 0\
**Last updated:** [September 25, 2023, 1:03pm UTC](https://discuss.elastic.co/t/update-ilm-and-link-to-an-existing-index/343762 "2023-09-25T13:03:21Z")

</div>

Hello, I have to update an ILM and update link to an existing index but i have a doubt on my API call Is that good one? curl -u elastic:xxxx -k -X PUT "https://elasticsearch-1:9200/index-raw-syslog/settings?pretty" -H…

---

## [Fine grained access control to reports](https://discuss.elastic.co/t/fine-grained-access-control-to-reports/343743)

<div class="topic-metadata">

**Author:** [@mpjjonker](https://discuss.elastic.co/u/mpjjonker)\
**Replies:** 1\
**Last updated:** [September 25, 2023, 12:40pm UTC](https://discuss.elastic.co/t/fine-grained-access-control-to-reports/343743 "2023-09-25T12:40:22Z")

</div>

Hi there, In Kibana there is the page where the reports appear. I have been looking for documentation around the access control to these reports. this is the page I am referring to: app/management/insightsAndAlerting…

---

## [Calculate the number of ERUs (Elasticsearch Resource Units) with an enterprise license](https://discuss.elastic.co/t/calculate-the-number-of-erus-elasticsearch-resource-units-with-an-enterprise-license/343754)

<div class="topic-metadata">

**Author:** [@Manal\_A](https://discuss.elastic.co/u/Manal_A)\
**Replies:** 0\
**Last updated:** [September 25, 2023, 12:32pm UTC](https://discuss.elastic.co/t/calculate-the-number-of-erus-elasticsearch-resource-units-with-an-enterprise-license/343754 "2023-09-25T12:32:33Z")

</div>

How do you calculate the number of ERUs (Elasticsearch Resource Units) with an enterprise license for master and data nodes in Elasticsearch ,please ?

---

## [Fleet server cannot connect to Elasticsearch when it's behind nginx reverse proxy](https://discuss.elastic.co/t/fleet-server-cannot-connect-to-elasticsearch-when-its-behind-nginx-reverse-proxy/343751)

<div class="topic-metadata">

**Author:** [@totobarbar](https://discuss.elastic.co/u/totobarbar)\
**Replies:** 0\
**Last updated:** [September 25, 2023, 12:21pm UTC](https://discuss.elastic.co/t/fleet-server-cannot-connect-to-elasticsearch-when-its-behind-nginx-reverse-proxy/343751 "2023-09-25T12:21:55Z")

</div>

Hello everyone, I want to use Elastic Stack behind nginx reverse proxies. So Kibana and Elasticsearch have a reverse proxy and they work very well together. But Fleet Server can't connect to Elasticsearch through its …

---

## [Add link to a dashboard in the email alert of Kibana Watcher](https://discuss.elastic.co/t/add-link-to-a-dashboard-in-the-email-alert-of-kibana-watcher/343565)

<div class="topic-metadata">

**Author:** [@RJC](https://discuss.elastic.co/u/RJC)\
**Replies:** 3\
**Last updated:** [September 25, 2023, 12:12pm UTC](https://discuss.elastic.co/t/add-link-to-a-dashboard-in-the-email-alert-of-kibana-watcher/343565 "2023-09-25T12:12:45Z")

</div>

I have a watcher that send email every time a condition is met. I wonder if it is possible - and if so, then how - to add to the body text a link to a Kibana dashboard? When the recipients get that email they would the…

---

## [Configuring SSL and X-Pack Security for ElasticSearch and Kibana using Bitnami Helm Chart with Ingress](https://discuss.elastic.co/t/configuring-ssl-and-x-pack-security-for-elasticsearch-and-kibana-using-bitnami-helm-chart-with-ingress/342521)

<div class="topic-metadata">

**Author:** [@Naasir\_Mohamed](https://discuss.elastic.co/u/Naasir_Mohamed)\
**Replies:** 1\
**Last updated:** [September 25, 2023, 12:11pm UTC](https://discuss.elastic.co/t/configuring-ssl-and-x-pack-security-for-elasticsearch-and-kibana-using-bitnami-helm-chart-with-ingress/342521 "2023-09-25T12:11:40Z")

</div>

Hello Elastic community, I'm currently working on deploying Elasticsearch (ES) and Kibana using the Bitnami Helm chart, and I've successfully enabled the cluster with Ingress. Now, I'm looking to enhance the security of…

---

## [Not able to see watchers UI in kibana 8.7.1 version](https://discuss.elastic.co/t/not-able-to-see-watchers-ui-in-kibana-8-7-1-version/343593)

<div class="topic-metadata">

**Author:** [@prashant1](https://discuss.elastic.co/u/prashant1)\
**Replies:** 4\
**Last updated:** [September 25, 2023, 12:02pm UTC](https://discuss.elastic.co/t/not-able-to-see-watchers-ui-in-kibana-8-7-1-version/343593 "2023-09-25T12:02:56Z")

</div>

Hi, We have updated the kibana from version 7.10.2 to 8.7.1. We are not able to see watcher UI tab. With the dev tools command we are able to see the watchers. Is there any way to get watchers UI? Could someone please…

[Previous page](https://discuss.elastic.co/latest.md?page=529)

[Next page](https://discuss.elastic.co/latest.md?page=531)
