# Latest

**URL:** https://discuss.elastic.co/latest.md?page=534

[Latest](https://discuss.elastic.co/latest.md) · [Categories](https://discuss.elastic.co/categories.md) · [Tags](https://discuss.elastic.co/tags.md)

**Page:** 535

---

## [Winlog beat connection issues](https://discuss.elastic.co/t/winlog-beat-connection-issues/343286)

<div class="topic-metadata">

**Author:** [@JJ007](https://discuss.elastic.co/u/JJ007)\
**Replies:** 4\
**Last updated:** [September 21, 2023, 3:44am UTC](https://discuss.elastic.co/t/winlog-beat-connection-issues/343286 "2023-09-21T03:44:39Z")

</div>

Hi, We are seeing a large number of connections from winlogbeat to EH Kafka. We have increased the keep alive setting as per the kafka recommendation by MS to 180,000 and also changing the partition setting to random. I…

---

## [Filebeat Kafka input compatibility](https://discuss.elastic.co/t/filebeat-kafka-input-compatibility/343500)

<div class="topic-metadata">

**Author:** [@niaomingjian](https://discuss.elastic.co/u/niaomingjian)\
**Replies:** 0\
**Last updated:** [September 21, 2023, 3:36am UTC](https://discuss.elastic.co/t/filebeat-kafka-input-compatibility/343500 "2023-09-21T03:36:29Z")

</div>

The doc says: This input works with all Kafka versions in between 0.11 and 2.8.0. Older versions might work as well, but are not supported. My kafka Cluster version is 3.3. Does kafka input of filebeat support kafk…

---

## [Aggregate function help](https://discuss.elastic.co/t/aggregate-function-help/343432)

<div class="topic-metadata">

**Author:** [@Ameeruddin\_Mohammed](https://discuss.elastic.co/u/Ameeruddin_Mohammed)\
**Replies:** 3\
**Last updated:** [September 20, 2023, 11:55pm UTC](https://discuss.elastic.co/t/aggregate-function-help/343432 "2023-09-20T23:55:05Z")

</div>

hi, i have logs in this format and i want to start the aggregation when start comes in the line and end the aggregation when end occurs. the aggregation is based on "username". i was able to use aggregate function but…

---

## [FileBeat on OpenShift Cluster (RHOCS ) - Operation not permitted error](https://discuss.elastic.co/t/filebeat-on-openshift-cluster-rhocs-operation-not-permitted-error/343421)

<div class="topic-metadata">

**Author:** [@vinay.bommarati](https://discuss.elastic.co/u/vinay.bommarati)\
**Replies:** 1\
**Last updated:** [September 21, 2023, 2:16am UTC](https://discuss.elastic.co/t/filebeat-on-openshift-cluster-rhocs-operation-not-permitted-error/343421 "2023-09-21T02:16:09Z")

</div>

Hi All , I have used FIleBeat docker image and created a daemon set on our Openshift cluster and gave necessary permissions to run as a privileged container as per documentation. Here is my volume and volume mount sect…

---

## [class RestHighLevelClient in package client is deprecated](https://discuss.elastic.co/t/class-resthighlevelclient-in-package-client-is-deprecated/343399)

<div class="topic-metadata">

**Author:** [@Nassereddine](https://discuss.elastic.co/u/Nassereddine)\
**Replies:** 3\
**Last updated:** [September 20, 2023, 9:23pm UTC](https://discuss.elastic.co/t/class-resthighlevelclient-in-package-client-is-deprecated/343399 "2023-09-20T21:23:14Z")

</div>

I am upgrading Elasticsearch from 7.9.2 to 7.17.6 and then to 8.4.2, in the first step i am upgrading the es cluster to the 7.17.6 version , and compiling all other ES clients, the compilation is good for all the other …

---

## [Logstash with email output plugin "no such file to load -- net/smtp"](https://discuss.elastic.co/t/logstash-with-email-output-plugin-no-such-file-to-load-net-smtp/343490)

<div class="topic-metadata">

**Author:** [@lee.clemens](https://discuss.elastic.co/u/lee.clemens)\
**Replies:** 2\
**Last updated:** [September 20, 2023, 9:21pm UTC](https://discuss.elastic.co/t/logstash-with-email-output-plugin-no-such-file-to-load-net-smtp/343490 "2023-09-20T21:21:47Z")

</div>

Hello, I recently upgraded RHEL 9 from logstash-8.8.2-1.x86\_64 to logstash-8.10.1-1.x86\_64 and now logstash fails to start. We are using the email output plugin and see this error in the logs: \[2023-09-20T13:48:49,401…

---

## [Top N User Control - In the Kibana Dashboard](https://discuss.elastic.co/t/top-n-user-control-in-the-kibana-dashboard/343488)

<div class="topic-metadata">

**Author:** [@Kumar\_Abhinav](https://discuss.elastic.co/u/Kumar_Abhinav)\
**Replies:** 1\
**Last updated:** [September 20, 2023, 9:21pm UTC](https://discuss.elastic.co/t/top-n-user-control-in-the-kibana-dashboard/343488 "2023-09-20T21:21:23Z")

</div>

I am grouping the visuals in my dashboard with Top 10 or 20 + others + missing. I want to give this control to users to filter the data to see themselves in how many counts they want to see that data. How should I do i…

---

## [Can't get Filebeat to ship Nginx Ingress Controller logs using ECK](https://discuss.elastic.co/t/cant-get-filebeat-to-ship-nginx-ingress-controller-logs-using-eck/343472)

<div class="topic-metadata">

**Author:** [@krische](https://discuss.elastic.co/u/krische)\
**Replies:** 2\
**Last updated:** [September 20, 2023, 7:54pm UTC](https://discuss.elastic.co/t/cant-get-filebeat-to-ship-nginx-ingress-controller-logs-using-eck/343472 "2023-09-20T19:54:06Z")

</div>

I have ECK setup and running on my kubernetes cluster. I followed the Configuration Examples to setup filebeat ship all container logs to Elasticsearch. That is working fine. However, now I am trying to parse the logs o…

---

## [Any Updates on Controlling Access to Jobs In Kibana ML?](https://discuss.elastic.co/t/any-updates-on-controlling-access-to-jobs-in-kibana-ml/343299)

<div class="topic-metadata">

**Author:** [@johnlbellamy](https://discuss.elastic.co/u/johnlbellamy)\
**Replies:** 4\
**Last updated:** [September 20, 2023, 7:40pm UTC](https://discuss.elastic.co/t/any-updates-on-controlling-access-to-jobs-in-kibana-ml/343299 "2023-09-20T19:40:05Z")

</div>

Hello, I have seen posts about controlling access to ML jobs. How can we stop all users from seeing other user's jobs? Any movement on this in 8.9? Have tried using the custom index name and etc. to no avail. Thank Yo…

---

## [Please delete account](https://discuss.elastic.co/t/please-delete-account/343485)

<div class="topic-metadata">

**Author:** [@AndyB](https://discuss.elastic.co/u/AndyB)\
**Replies:** 1\
**Last updated:** [September 20, 2023, 7:32pm UTC](https://discuss.elastic.co/t/please-delete-account/343485 "2023-09-20T19:32:31Z")

</div>

Please delete my account.

---

## [REST api: delete dashboard](https://discuss.elastic.co/t/rest-api-delete-dashboard/343471)

<div class="topic-metadata">

**Author:** [@emmanuel\_t](https://discuss.elastic.co/u/emmanuel_t)\
**Replies:** 1\
**Last updated:** [September 20, 2023, 7:24pm UTC](https://discuss.elastic.co/t/rest-api-delete-dashboard/343471 "2023-09-20T19:24:16Z")

</div>

I see that the saved objects API is deprecated, and that's a real bummer, the API was extremely useful for us. For most of our use cases we can probably get by using the import/export API as a worse (from our point of vi…

---

## [Integration Dashboard Links](https://discuss.elastic.co/t/integration-dashboard-links/342842)

<div class="topic-metadata">

**Author:** [@cappy](https://discuss.elastic.co/u/cappy)\
**Replies:** 3\
**Last updated:** [September 20, 2023, 6:08pm UTC](https://discuss.elastic.co/t/integration-dashboard-links/342842 "2023-09-20T18:08:08Z")

</div>

I am using version 8.8.2. No matter if I set server.basePath or server.publicBaseUrl, the links inside of the dashboards for the integrations still reference a static path like $host/app/dashboards/blah, even if I remov…

---

## [How can I remove the duplicate in the logs and prevent to create new docs](https://discuss.elastic.co/t/how-can-i-remove-the-duplicate-in-the-logs-and-prevent-to-create-new-docs/343417)

<div class="topic-metadata">

**Author:** [@Cruz](https://discuss.elastic.co/u/Cruz)\
**Replies:** 7\
**Last updated:** [September 20, 2023, 5:34pm UTC](https://discuss.elastic.co/t/how-can-i-remove-the-duplicate-in-the-logs-and-prevent-to-create-new-docs/343417 "2023-09-20T17:34:44Z")

</div>

Hello everyone! I have this logs { "\_index": ".ds-my-neoada-stream-2023.09.14-000005", "\_id": "T8v5sIoB0eBbzdbCLRnW", "\_version": 1, "\_score": 0, "\_source": { "from\_plant": "N/A", "tick\_current": "IT-…

---

## [Invalid cron expression for schedule field of elasticsearch input plugin](https://discuss.elastic.co/t/invalid-cron-expression-for-schedule-field-of-elasticsearch-input-plugin/343478)

<div class="topic-metadata">

**Author:** [@mikec1](https://discuss.elastic.co/u/mikec1)\
**Replies:** 5\
**Last updated:** [September 20, 2023, 5:08pm UTC](https://discuss.elastic.co/t/invalid-cron-expression-for-schedule-field-of-elasticsearch-input-plugin/343478 "2023-09-20T17:08:07Z")

</div>

I have a pipeline whereby the input section looks like this: input { elasticsearch { hosts =\> \["elasticsearch.my.host.here:port"\] index =\> 'my\_index\_name\_pattern' query =\> '{ "query": { "mat…

---

## [AWS logging integration error](https://discuss.elastic.co/t/aws-logging-integration-error/343469)

<div class="topic-metadata">

**Author:** [@rachelyang](https://discuss.elastic.co/u/rachelyang)\
**Replies:** 4\
**Last updated:** [September 20, 2023, 4:27pm UTC](https://discuss.elastic.co/t/aws-logging-integration-error/343469 "2023-09-20T16:27:30Z")

</div>

Hi, I want to integrate the AWS logs into my Kibana Observability log stream. Here is the access policy of SQS queue: { "Version": "2012-10-17", "Id": "arn:aws:sqs:us-east-1:334811116626:ingest-ec2-logs-sqs/SQSDef…

---

## [Restore request has no response and doesnt execute](https://discuss.elastic.co/t/restore-request-has-no-response-and-doesnt-execute/343476)

<div class="topic-metadata">

**Author:** [@Chris\_Brown](https://discuss.elastic.co/u/Chris_Brown)\
**Replies:** 2\
**Last updated:** [September 20, 2023, 4:09pm UTC](https://discuss.elastic.co/t/restore-request-has-no-response-and-doesnt-execute/343476 "2023-09-20T16:09:44Z")

</div>

Hello. I've successfully created a snapshot in s3 and it appears to be fine when calling \_snapshot/name/\_all. When trying to restore it with a POST to \_snapshot/name/snapshot/\_restore the request hangs indefinitely, nev…

---

## [Multi-level nested query structure — bug or feature](https://discuss.elastic.co/t/multi-level-nested-query-structure-bug-or-feature/343475)

<div class="topic-metadata">

**Author:** [@jonnyeom](https://discuss.elastic.co/u/jonnyeom)\
**Replies:** 0\
**Last updated:** [September 20, 2023, 3:42pm UTC](https://discuss.elastic.co/t/multi-level-nested-query-structure-bug-or-feature/343475 "2023-09-20T15:42:00Z")

</div>

Hello, Im working with multi-level nested query filters. Documentation in Nested query | Elasticsearch Guide \[8.10\] | Elastic shows an example where each level is nested as part of the search query. i.e. Query Example…

---

## [CA Certificate for Elasticsearch and Kibana in K8s](https://discuss.elastic.co/t/ca-certificate-for-elasticsearch-and-kibana-in-k8s/342733)

<div class="topic-metadata">

**Author:** [@Esakki](https://discuss.elastic.co/u/Esakki)\
**Replies:** 4\
**Last updated:** [September 20, 2023, 2:21pm UTC](https://discuss.elastic.co/t/ca-certificate-for-elasticsearch-and-kibana-in-k8s/342733 "2023-09-20T14:21:26Z")

</div>

Hi All, Can someone share the steps how to configure certificate for Elasticsearch and Kiabana which is deployed on-prem K8s cluster. Thanks in advance. Kind Regards, Esakki

---

## [The issue in a detection rule](https://discuss.elastic.co/t/the-issue-in-a-detection-rule/343448)

<div class="topic-metadata">

**Author:** [@saudmajed99](https://discuss.elastic.co/u/saudmajed99)\
**Replies:** 2\
**Last updated:** [September 20, 2023, 2:14pm UTC](https://discuss.elastic.co/t/the-issue-in-a-detection-rule/343448 "2023-09-20T14:14:08Z")

</div>

Hi there, We would like your support, we face an issue if we create a detection rule where no result appears but results appears when we do the same search in the discover side , please assist me the solving an issue wi…

---

## [Documentation on the relationship between output fields and input plugins/processors](https://discuss.elastic.co/t/documentation-on-the-relationship-between-output-fields-and-input-plugins-processors/343467)

<div class="topic-metadata">

**Author:** [@frans-wtax](https://discuss.elastic.co/u/frans-wtax)\
**Replies:** 0\
**Last updated:** [September 20, 2023, 1:53pm UTC](https://discuss.elastic.co/t/documentation-on-the-relationship-between-output-fields-and-input-plugins-processors/343467 "2023-09-20T13:53:16Z")

</div>

Various pages on the Filebeat documentation describe inputs: Configure inputs | Filebeat Reference \[8.10\] | Elastic . Similarly, processors are documented: Filter and enhance data with processors | Filebeat Reference \[8.…

---

## [Issue on db query](https://discuss.elastic.co/t/issue-on-db-query/343369)

<div class="topic-metadata">

**Author:** [@girolamo](https://discuss.elastic.co/u/girolamo)\
**Replies:** 5\
**Last updated:** [September 20, 2023, 1:49pm UTC](https://discuss.elastic.co/t/issue-on-db-query/343369 "2023-09-20T13:49:57Z")

</div>

Hello there, I'm having issues making a query on a Elasticsearch db. Indeed, if I make this request: POST my-index/\_search I get almost all documents in the index. In this way: { "took" : 15, "timed\_out" : fals…

---

## [Use variable with logstash](https://discuss.elastic.co/t/use-variable-with-logstash/343462)

<div class="topic-metadata">

**Author:** [@sam1975](https://discuss.elastic.co/u/sam1975)\
**Replies:** 1\
**Last updated:** [September 20, 2023, 1:48pm UTC](https://discuss.elastic.co/t/use-variable-with-logstash/343462 "2023-09-20T13:48:41Z")

</div>

Hello I have a long list like this if \[monitoring\_data\_name\] == "componentFault" { pipeline { send\_to =\> "componentFault" } } else if \[monitoring\_data\_name\] == "localAccountPasswordModification" { pipeline { send\_t…

---

## [What's the equivalent of NEST's QueryBase.IsVerbatim property in Elastic.Clients.Elasticsearch (8.x)](https://discuss.elastic.co/t/whats-the-equivalent-of-nests-querybase-isverbatim-property-in-elastic-clients-elasticsearch-8-x/343455)

<div class="topic-metadata">

**Author:** [@yansklyarenko](https://discuss.elastic.co/u/yansklyarenko)\
**Replies:** 2\
**Last updated:** [September 20, 2023, 1:26pm UTC](https://discuss.elastic.co/t/whats-the-equivalent-of-nests-querybase-isverbatim-property-in-elastic-clients-elasticsearch-8-x/343455 "2023-09-20T13:26:08Z")

</div>

NEST (7.x) client has QueryBase class, which in its turn has IsVerbatim boolean property. Hence, all derived query classes inherit it. However, query classes in Elastic.Clients.Elasticsearch (8.x) client don't inherit/de…

---

## [How do I count and visualize only latest doc based on certain field?](https://discuss.elastic.co/t/how-do-i-count-and-visualize-only-latest-doc-based-on-certain-field/343457)

<div class="topic-metadata">

**Author:** [@Doron\_Abramovich](https://discuss.elastic.co/u/Doron_Abramovich)\
**Replies:** 2\
**Last updated:** [September 20, 2023, 12:54pm UTC](https://discuss.elastic.co/t/how-do-i-count-and-visualize-only-latest-doc-based-on-certain-field/343457 "2023-09-20T12:54:47Z")

</div>

Hi everyone :slight\_smile: First post here after working for over year with elastic. I have an index with docs representing items moving from station to station, each doc represents a station. For example - an item mo…

---

## [Logstash json input file only required fields to output](https://discuss.elastic.co/t/logstash-json-input-file-only-required-fields-to-output/342400)

<div class="topic-metadata">

**Author:** [@Narayan\_Rao](https://discuss.elastic.co/u/Narayan_Rao)\
**Replies:** 11\
**Last updated:** [September 20, 2023, 12:53pm UTC](https://discuss.elastic.co/t/logstash-json-input-file-only-required-fields-to-output/342400 "2023-09-20T12:53:37Z")

</div>

I'm new in ELK & I have logs in JSON format. Below is the json sample log file. I want only item level array, others fields not required. Sample logs { "source": "mdm/pim", "topic": "pim-record-globalfields", "subj…

---

## [Custom CSS conditional formatting TSVB](https://discuss.elastic.co/t/custom-css-conditional-formatting-tsvb/343460)

<div class="topic-metadata">

**Author:** [@mathur7vidit](https://discuss.elastic.co/u/mathur7vidit)\
**Replies:** 0\
**Last updated:** [September 20, 2023, 12:53pm UTC](https://discuss.elastic.co/t/custom-css-conditional-formatting-tsvb/343460 "2023-09-20T12:53:27Z")

</div>

Hi Team, i am working on TSVB visualization and using filter ratio. it gives me metric as below now here i have a markdown as APP1 and i have value coming as {{ a.a.last.formatted }}. Based upon this value of {{ a.a.…

---

## [Failed to load SSL configuration \[xpack.security.transport.ssl\] - the truststore \[/usr/share/elasticsearch/ssl/qa.pfx\] does not contain any trusted certificate entries](https://discuss.elastic.co/t/failed-to-load-ssl-configuration-xpack-security-transport-ssl-the-truststore-usr-share-elasticsearch-ssl-qa-pfx-does-not-contain-any-trusted-certificate-entries/343138)

<div class="topic-metadata">

**Author:** [@Anushree](https://discuss.elastic.co/u/Anushree)\
**Replies:** 2\
**Last updated:** [September 20, 2023, 12:10pm UTC](https://discuss.elastic.co/t/failed-to-load-ssl-configuration-xpack-security-transport-ssl-the-truststore-usr-share-elasticsearch-ssl-qa-pfx-does-not-contain-any-trusted-certificate-entries/343138 "2023-09-20T12:10:08Z")

</div>

Hello, I encountered an SSL certificate trust issue when attempting to upgrade a single-node Elasticsearch instance from version 7.17 to 8.0, same certificate was working on 7.17. I am using a valid certificate chain pr…

---

## [Validation error on Kibana8 upgrade from Kibana7.17](https://discuss.elastic.co/t/validation-error-on-kibana8-upgrade-from-kibana7-17/343449)

<div class="topic-metadata">

**Author:** [@Vikrant\_Dewangan](https://discuss.elastic.co/u/Vikrant_Dewangan)\
**Replies:** 0\
**Last updated:** [September 20, 2023, 11:15am UTC](https://discuss.elastic.co/t/validation-error-on-kibana8-upgrade-from-kibana7-17/343449 "2023-09-20T11:15:07Z")

</div>

Hi, I am upgrading installing kibana8 from kibana7.17, and receiving the following error. Are there any leads for the validation type error? Configuring logger failed: ValidationError: \[config validation of \[logging\].a…

---

## [Logstash JDBC plugin](https://discuss.elastic.co/t/logstash-jdbc-plugin/343456)

<div class="topic-metadata">

**Author:** [@Akulainelastic](https://discuss.elastic.co/u/Akulainelastic)\
**Replies:** 0\
**Last updated:** [September 20, 2023, 12:04pm UTC](https://discuss.elastic.co/t/logstash-jdbc-plugin/343456 "2023-09-20T12:04:15Z")

</div>

Hello All , so I have a requirement where I need to use JDBC plugin to fetch the database data and reflect it in kibana , although I have successfully ingested data and pipelined it in logstash , the pipelines are runnin…

---

## [jakarta.json.stream.JsonParsingException when deserializing data retrieved from Elasticsearch](https://discuss.elastic.co/t/jakarta-json-stream-jsonparsingexception-when-deserializing-data-retrieved-from-elasticsearch/343367)

<div class="topic-metadata">

**Author:** [@Georgi\_Nikolov](https://discuss.elastic.co/u/Georgi_Nikolov)\
**Replies:** 4\
**Last updated:** [September 20, 2023, 11:44am UTC](https://discuss.elastic.co/t/jakarta-json-stream-jsonparsingexception-when-deserializing-data-retrieved-from-elasticsearch/343367 "2023-09-20T11:44:41Z")

</div>

for some time now I have been trying to incorporate the Elastic Java 8.10 client into my code, I have a big ELK stack with a lot of data. I am trying to fetch continuously data from it, but I am encountering some inconsi…

[Previous page](https://discuss.elastic.co/latest.md?page=533)

[Next page](https://discuss.elastic.co/latest.md?page=535)
