# Latest

**URL:** https://discuss.elastic.co/latest.md?page=531

[Latest](https://discuss.elastic.co/latest.md) · [Categories](https://discuss.elastic.co/categories.md) · [Tags](https://discuss.elastic.co/tags.md)

**Page:** 532

---

## [Default space](https://discuss.elastic.co/t/default-space/343747)

<div class="topic-metadata">

**Author:** [@ponpon](https://discuss.elastic.co/u/ponpon)\
**Replies:** 2\
**Last updated:** [September 25, 2023, 11:05am UTC](https://discuss.elastic.co/t/default-space/343747 "2023-09-25T11:05:48Z")

</div>

Hi, my default space is unaccessible. when I am presented with the " Select your space" page and I choose Default, I am redirected to one of the other spaces. I have restarted Kibana and I have checked that .kabana is w…

---

## ["logs threshold rule" missing "comparator": "MATCHES"](https://discuss.elastic.co/t/logs-threshold-rule-missing-comparator-matches/343734)

<div class="topic-metadata">

**Author:** [@BRINDAH\_B](https://discuss.elastic.co/u/BRINDAH_B)\
**Replies:** 0\
**Last updated:** [September 25, 2023, 9:46am UTC](https://discuss.elastic.co/t/logs-threshold-rule-missing-comparator-matches/343734 "2023-09-25T09:46:03Z")

</div>

I want to create a "logs threshold rule" with "comparator": "MATCHES" or "MATCHES PHRASE". I want to be able to use the "message" field in my log-threshold rule, which is of type "text". Is this possible? Right now im …

---

## [Does ece persist data outside of the container?](https://discuss.elastic.co/t/does-ece-persist-data-outside-of-the-container/343453)

<div class="topic-metadata">

**Author:** [@steman-provinzial](https://discuss.elastic.co/u/steman-provinzial)\
**Replies:** 1\
**Last updated:** [September 25, 2023, 9:56am UTC](https://discuss.elastic.co/t/does-ece-persist-data-outside-of-the-container/343453 "2023-09-25T09:56:52Z")

</div>

Hi there, does ECE persist the data / indices also locally on the respective allocator / host? All I can find is the data in the container itself. For example: sh-5.0# ls -ltr total 12 -rw-rw-r-- 1 elasticsearch e…

---

## [UNASSIGNED NODE\_LEFT](https://discuss.elastic.co/t/unassigned-node-left/343737)

<div class="topic-metadata">

**Author:** [@PugachevLB](https://discuss.elastic.co/u/PugachevLB)\
**Replies:** 0\
**Last updated:** [September 25, 2023, 9:51am UTC](https://discuss.elastic.co/t/unassigned-node-left/343737 "2023-09-25T09:51:30Z")

</div>

We have a cluster of 30 nodes (3 phys servers 64 cpu + 512 mem with 10 ES instances on each (1 master + 9 data)). Sometimes after uploading a new index (~700 Gb 24 shards \* 2 rep factor) we have some instances crushed (…

---

## [Filebeat-7.17.12-system-syslog-pi peline\] does not exist](https://discuss.elastic.co/t/filebeat-7-17-12-system-syslog-pi-peline-does-not-exist/343735)

<div class="topic-metadata">

**Author:** [@YassBout](https://discuss.elastic.co/u/YassBout)\
**Replies:** 0\
**Last updated:** [September 25, 2023, 9:46am UTC](https://discuss.elastic.co/t/filebeat-7-17-12-system-syslog-pi-peline-does-not-exist/343735 "2023-09-25T09:46:18Z")

</div>

Hello, I've installed the ELK stack on a VPS to monitor remote logs from multiple companies. However, when I install and start all the services, I encounter this error: 2023-08-27T09:17:59.426Z#011INFO#011\[publisher\]#0…

---

## [Kibana Dashboard - Display difference between two counts](https://discuss.elastic.co/t/kibana-dashboard-display-difference-between-two-counts/343687)

<div class="topic-metadata">

**Author:** [@seb.sch](https://discuss.elastic.co/u/seb.sch)\
**Replies:** 1\
**Last updated:** [September 25, 2023, 8:56am UTC](https://discuss.elastic.co/t/kibana-dashboard-display-difference-between-two-counts/343687 "2023-09-25T08:56:29Z")

</div>

Hi there, I've been searching on anything new to this issue for the whole weekend now, but I've found only posts which are 3+ years old. If I needed to do implement my requirement manually, I'd do the following: GET m…

---

## [Implement word cloud in Kibana](https://discuss.elastic.co/t/implement-word-cloud-in-kibana/307480)

<div class="topic-metadata">

**Author:** [@Abhishek\_Shinde](https://discuss.elastic.co/u/Abhishek_Shinde)\
**Replies:** 2\
**Last updated:** [September 25, 2023, 8:41am UTC](https://discuss.elastic.co/t/implement-word-cloud-in-kibana/307480 "2023-09-25T08:41:28Z")

</div>

I wanted to implement Word Cloud visualization using Kibana in my application. The example is attached. I'm looking for reference material on the Elastic site on how to get this done. It would be good if someone can shar…

---

## [Elastic Web Crawler API or configuration transport](https://discuss.elastic.co/t/elastic-web-crawler-api-or-configuration-transport/343718)

<div class="topic-metadata">

**Author:** [@sebastianboelling](https://discuss.elastic.co/u/sebastianboelling)\
**Replies:** 0\
**Last updated:** [September 25, 2023, 8:21am UTC](https://discuss.elastic.co/t/elastic-web-crawler-api-or-configuration-transport/343718 "2023-09-25T08:21:39Z")

</div>

Hi, we are using the Elastic Web Crawler. In our environment we have a lot of websites to crawl with different extraction rules, schedules etc. It is a lot of manual work to configure this with the Kibana GUI and a stag…

---

## [How to access APM server config file from ECE?](https://discuss.elastic.co/t/how-to-access-apm-server-config-file-from-ece/343716)

<div class="topic-metadata">

**Author:** [@Ong](https://discuss.elastic.co/u/Ong)\
**Replies:** 0\
**Last updated:** [September 25, 2023, 8:14am UTC](https://discuss.elastic.co/t/how-to-access-apm-server-config-file-from-ece/343716 "2023-09-25T08:14:51Z")

</div>

I am setting up RUM on a APM server on ECE. Based on the documentation , RUM needs to be enabled with this line apm-server.rum.enabled: true The problem is how do I add this line to the APM server? Unlike Elasticsearch…

---

## [Error "illegal base64 data at input byte 56" when enroll elastic-agent](https://discuss.elastic.co/t/error-illegal-base64-data-at-input-byte-56-when-enroll-elastic-agent/343553)

<div class="topic-metadata">

**Author:** [@neva-ops](https://discuss.elastic.co/u/neva-ops)\
**Replies:** 1\
**Last updated:** [September 25, 2023, 8:12am UTC](https://discuss.elastic.co/t/error-illegal-base64-data-at-input-byte-56-when-enroll-elastic-agent/343553 "2023-09-25T08:12:45Z")

</div>

Can't enroll elastic-agent in Fleet. When I run elastic-agent with docker compose then I get this errors: {"log.level":"info","@timestamp":"2023-09-21T14:02:42.544Z","message":"HTTP request error","component":{"binary…

---

## [Fleet Server Agent Not able to 'identify' kibana secret in ECK](https://discuss.elastic.co/t/fleet-server-agent-not-able-to-identify-kibana-secret-in-eck/343105)

<div class="topic-metadata">

**Author:** [@VVK](https://discuss.elastic.co/u/VVK)\
**Replies:** 2\
**Last updated:** [September 25, 2023, 8:00am UTC](https://discuss.elastic.co/t/fleet-server-agent-not-able-to-identify-kibana-secret-in-eck/343105 "2023-09-25T08:00:03Z")

</div>

Environment: We are managing our own k8s enviornment and have our kibana/Elasticsearch w/o any problems. Filebeat and Metricbeat are working fine. No issues. Observability & Elastic APM is working as per expectation. …

---

## [Sophos integration with elastic agent v 8.9.1](https://discuss.elastic.co/t/sophos-integration-with-elastic-agent-v-8-9-1/341953)

<div class="topic-metadata">

**Author:** [@Ahmad\_Shrateh](https://discuss.elastic.co/u/Ahmad_Shrateh)\
**Replies:** 1\
**Last updated:** [September 25, 2023, 7:21am UTC](https://discuss.elastic.co/t/sophos-integration-with-elastic-agent-v-8-9-1/341953 "2023-09-25T07:21:22Z")

</div>

I working on integrating Sophos firewall via UDP --\> screenshot attached I'm receiving the logs perfectly but I had an issue with no correct parsing of the data, and since all the log details are on the same field and t…

---

## [Creating Multi-Fields using Kibana UI](https://discuss.elastic.co/t/creating-multi-fields-using-kibana-ui/343707)

<div class="topic-metadata">

**Author:** [@randomnamegenerator](https://discuss.elastic.co/u/randomnamegenerator)\
**Replies:** 0\
**Last updated:** [September 25, 2023, 6:24am UTC](https://discuss.elastic.co/t/creating-multi-fields-using-kibana-ui/343707 "2023-09-25T06:24:51Z")

</div>

Hello All, Apologies in advance if this is the wrong sub-forum to ask the question. I am new to the forum and ELK in general. I am looking to create multi-field mapping for a legacy index template using the Kibana crea…

---

## [How to fetch nested json data in separate fields](https://discuss.elastic.co/t/how-to-fetch-nested-json-data-in-separate-fields/343701)

<div class="topic-metadata">

**Author:** [@bharti](https://discuss.elastic.co/u/bharti)\
**Replies:** 1\
**Last updated:** [September 25, 2023, 5:23am UTC](https://discuss.elastic.co/t/how-to-fetch-nested-json-data-in-separate-fields/343701 "2023-09-25T05:23:02Z")

</div>

Hello I need a little help. I want to fetch some nested json data into separate fields input { beats { port =\> 5044 } } filter { if "/var/log/ABC.log" in \[log\]\[file\]\[path\] { grok { match =\> …

---

## [Elasticsearch Node went down abruptly and lost data](https://discuss.elastic.co/t/elasticsearch-node-went-down-abruptly-and-lost-data/343566)

<div class="topic-metadata">

**Author:** [@nsoni](https://discuss.elastic.co/u/nsoni)\
**Replies:** 4\
**Last updated:** [September 25, 2023, 5:16am UTC](https://discuss.elastic.co/t/elasticsearch-node-went-down-abruptly-and-lost-data/343566 "2023-09-25T05:16:23Z")

</div>

I am running Elasticsearch cluster version 7.10.0 It's running for a year now, never faced any issues. Our setup comprises 1 primary and 1 replica in a different availability zone. Distribution is through the rack\_id a…

---

## [Elastic Agent, aws-s3-default-aws-s3-vpcflow keeps failing](https://discuss.elastic.co/t/elastic-agent-aws-s3-default-aws-s3-vpcflow-keeps-failing/343697)

<div class="topic-metadata">

**Author:** [@digital-thought](https://discuss.elastic.co/u/digital-thought)\
**Replies:** 5\
**Last updated:** [September 25, 2023, 4:51am UTC](https://discuss.elastic.co/t/elastic-agent-aws-s3-default-aws-s3-vpcflow-keeps-failing/343697 "2023-09-25T04:51:41Z")

</div>

I have an AWS environment which ships VPC logs to a S3 bucket. I am using the AWS VPC Log Processing integration within Elastic Agent to process these logs and to monitor for new logs. It connects to the bucket success…

---

## [Regarding the usage of nested fields](https://discuss.elastic.co/t/regarding-the-usage-of-nested-fields/343655)

<div class="topic-metadata">

**Author:** [@yeikel](https://discuss.elastic.co/u/yeikel)\
**Replies:** 1\
**Last updated:** [September 25, 2023, 4:22am UTC](https://discuss.elastic.co/t/regarding-the-usage-of-nested-fields/343655 "2023-09-25T04:22:45Z")

</div>

Hi all, I need to ingest a large volume of records from one data source to another and one topic that I am currently debating is regarding the usage of Nested Field with Arrays or using Multi match and search across mu…

---

## [Api to get saved objects info like Dashboard for kibana 8.9.0?](https://discuss.elastic.co/t/api-to-get-saved-objects-info-like-dashboard-for-kibana-8-9-0/341855)

<div class="topic-metadata">

**Author:** [@Daemon1](https://discuss.elastic.co/u/Daemon1)\
**Replies:** 7\
**Last updated:** [September 24, 2023, 11:48pm UTC](https://discuss.elastic.co/t/api-to-get-saved-objects-info-like-dashboard-for-kibana-8-9-0/341855 "2023-09-24T23:48:24Z")

</div>

GET \<kibana host\>:\<port\>/api/saved\_objects/\<type\>/\<id\> The above API is deprecated for version 8.9.0 GET \<kibana host\>:\<port\>/api/data\_views This API only returns the info about data\_views not dashboard. What is the …

---

## [Kibana Table (dashboard) - compute percentage when all row are filters](https://discuss.elastic.co/t/kibana-table-dashboard-compute-percentage-when-all-row-are-filters/343647)

<div class="topic-metadata">

**Author:** [@ctinp](https://discuss.elastic.co/u/ctinp)\
**Replies:** 2\
**Last updated:** [September 23, 2023, 10:49pm UTC](https://discuss.elastic.co/t/kibana-table-dashboard-compute-percentage-when-all-row-are-filters/343647 "2023-09-23T22:49:14Z")

</div>

One of the fields in my logs contains a list of vulnerabilities separated by comma (e.g. attacks=XSS,SQLI,LOG4J. In Kibana, I have created a table visualisation where each row is a filter for one of the signals (e.g. at…

---

## [Kibana Visualisations](https://discuss.elastic.co/t/kibana-visualisations/342622)

<div class="topic-metadata">

**Author:** [@DivyaDileep](https://discuss.elastic.co/u/DivyaDileep)\
**Replies:** 1\
**Last updated:** [September 23, 2023, 10:46pm UTC](https://discuss.elastic.co/t/kibana-visualisations/342622 "2023-09-23T22:46:13Z")

</div>

If I want to create a dashboad for "instance\_name & diskIndex in message to be matched, then the diskPath & diskPercent fields displayed so it shows what the partition is called & how full it is in a percentage." diskPer…

---

## [Pipeline creation with multiple fields](https://discuss.elastic.co/t/pipeline-creation-with-multiple-fields/343635)

<div class="topic-metadata">

**Author:** [@Manasa4](https://discuss.elastic.co/u/Manasa4)\
**Replies:** 1\
**Last updated:** [September 23, 2023, 9:56pm UTC](https://discuss.elastic.co/t/pipeline-creation-with-multiple-fields/343635 "2023-09-23T21:56:34Z")

</div>

Hi, I have created a pipeline for NER with a single "field\_map", but I want a pipeline which can process multiple fields. Is that possible in the real case scenario? PUT \_ingest/pipeline/ner { "description": "NER pip…

---

## [Do collapse keys benefit from document routing?](https://discuss.elastic.co/t/do-collapse-keys-benefit-from-document-routing/343677)

<div class="topic-metadata">

**Author:** [@davidgAID](https://discuss.elastic.co/u/davidgAID)\
**Replies:** 0\
**Last updated:** [September 23, 2023, 7:02pm UTC](https://discuss.elastic.co/t/do-collapse-keys-benefit-from-document-routing/343677 "2023-09-23T19:02:29Z")

</div>

I have an index with denormalized data that is almost exclusively used with collapse queries. If I configure index routing to use the collapse key, which would keep denormalized sibling documents on the same shard, would…

---

## [I have elk, logstash, kibana and filebeat version 7.10.1 and want upgarde to latest](https://discuss.elastic.co/t/i-have-elk-logstash-kibana-and-filebeat-version-7-10-1-and-want-upgarde-to-latest/343662)

<div class="topic-metadata">

**Author:** [@Mostafa\_Faridi](https://discuss.elastic.co/u/Mostafa_Faridi)\
**Replies:** 5\
**Last updated:** [September 23, 2023, 5:33pm UTC](https://discuss.elastic.co/t/i-have-elk-logstash-kibana-and-filebeat-version-7-10-1-and-want-upgarde-to-latest/343662 "2023-09-23T17:33:18Z")

</div>

I have install ELK stack with RPM on my Oracle Linux and its work and I have six Oracle Linux and install elasticserch and kibana and logstash on one server and install filebeat on other servers. I want right now upgrad…

---

## [Logstash cannot connect to my postgresql database, they are both running in docker containers on the same compose network](https://discuss.elastic.co/t/logstash-cannot-connect-to-my-postgresql-database-they-are-both-running-in-docker-containers-on-the-same-compose-network/343668)

<div class="topic-metadata">

**Author:** [@descholar-ceo](https://discuss.elastic.co/u/descholar-ceo)\
**Replies:** 0\
**Last updated:** [September 23, 2023, 9:33am UTC](https://discuss.elastic.co/t/logstash-cannot-connect-to-my-postgresql-database-they-are-both-running-in-docker-containers-on-the-same-compose-network/343668 "2023-09-23T09:33:39Z")

</div>

I am looking for a help, I am struggling with connecting Logstash to my postgres db, they are both running on the same docker compose network and the connection string I passed works from my application which is running …

---

## [Elasticsearch ILM Policies](https://discuss.elastic.co/t/elasticsearch-ilm-policies/343671)

<div class="topic-metadata">

**Author:** [@gsekar](https://discuss.elastic.co/u/gsekar)\
**Replies:** 0\
**Last updated:** [September 23, 2023, 10:30am UTC](https://discuss.elastic.co/t/elasticsearch-ilm-policies/343671 "2023-09-23T10:30:52Z")

</div>

Hi All Currently we are sending logs to elasticsearch and it's configured in such a way that daily datastreams are created. For Eg: logs-app1-2023-09-23, logs-app1-2023-09-24 etc. Goal is to keep logs for 3 days. We hav…

---

## [DEMORA EN CARGAR INTERFAZ GRAFICA WAZUH](https://discuss.elastic.co/t/demora-en-cargar-interfaz-grafica-wazuh/343653)

<div class="topic-metadata">

**Author:** [@stefanny\_chavez\_anto](https://discuss.elastic.co/u/stefanny_chavez_anto)\
**Replies:** 1\
**Last updated:** [September 23, 2023, 2:04am UTC](https://discuss.elastic.co/t/demora-en-cargar-interfaz-grafica-wazuh/343653 "2023-09-23T02:04:04Z")

</div>

Tengo un problema al visualizar la interfaz grafica de Wazuh, he procedido a reinicar el servidor ubuntu y al momento de encender todos los servicios (filebeat, elasticsearch, kibana y wazuh-manager) están activos, pero …

---

## [Alter Index so every user can see it](https://discuss.elastic.co/t/alter-index-so-every-user-can-see-it/343537)

<div class="topic-metadata">

**Author:** [@yogobah921](https://discuss.elastic.co/u/yogobah921)\
**Replies:** 1\
**Last updated:** [September 23, 2023, 12:11am UTC](https://discuss.elastic.co/t/alter-index-so-every-user-can-see-it/343537 "2023-09-23T00:11:33Z")

</div>

I have multiple accounts with different roles and now I created a new index. Now the roles can't access the new index because it is not listed in their indices configuration. how can I alter the index so every user can…

---

## [DEMORA EN CARGAR INTERFAZ GRAFICA WAZUH](https://discuss.elastic.co/t/demora-en-cargar-interfaz-grafica-wazuh/343654)

<div class="topic-metadata">

**Author:** [@stefanny\_chavez\_anto](https://discuss.elastic.co/u/stefanny_chavez_anto)\
**Replies:** 0\
**Last updated:** [September 22, 2023, 8:24pm UTC](https://discuss.elastic.co/t/demora-en-cargar-interfaz-grafica-wazuh/343654 "2023-09-22T20:24:41Z")

</div>

Tengo un problema al visualizar la interfaz grafica de Wazuh, he procedido a reinicar el servidor ubuntu y al momento de encender todos los servicios (filebeat, elasticsearch, kibana y wazuh-manager) están activos, pero …

---

## [ElasticsearchSecurityException when security is enabled on master node but not the data nodes](https://discuss.elastic.co/t/elasticsearchsecurityexception-when-security-is-enabled-on-master-node-but-not-the-data-nodes/342076)

<div class="topic-metadata">

**Author:** [@darshanypatel](https://discuss.elastic.co/u/darshanypatel)\
**Replies:** 6\
**Last updated:** [September 22, 2023, 7:44pm UTC](https://discuss.elastic.co/t/elasticsearchsecurityexception-when-security-is-enabled-on-master-node-but-not-the-data-nodes/342076 "2023-09-22T19:44:26Z")

</div>

I have an ES 7.16.2 cluster running with dedicated master nodes and separate data nodes. If/when - xpack.security.enabled is set to true on the master nodes some of the data nodes have xpack security disabled anonymou…

---

## [Need Help Configuring HTTPS Between Elasticsearch and Kibana](https://discuss.elastic.co/t/need-help-configuring-https-between-elasticsearch-and-kibana/343649)

<div class="topic-metadata">

**Author:** [@sami\_mezghani](https://discuss.elastic.co/u/sami_mezghani)\
**Replies:** 0\
**Last updated:** [September 22, 2023, 6:11pm UTC](https://discuss.elastic.co/t/need-help-configuring-https-between-elasticsearch-and-kibana/343649 "2023-09-22T18:11:55Z")

</div>

Hello forum members, I'm new to Elasticsearch and Kibana, and I'm currently trying to set up a secure connection (HTTPS) between Elasticsearch and Kibana. I've generated the necessary certificates using elasticsearch-ce…

[Previous page](https://discuss.elastic.co/latest.md?page=530)

[Next page](https://discuss.elastic.co/latest.md?page=532)
