# Latest

**URL:** https://discuss.elastic.co/latest.md?page=535

[Latest](https://discuss.elastic.co/latest.md) · [Categories](https://discuss.elastic.co/categories.md) · [Tags](https://discuss.elastic.co/tags.md)

**Page:** 536

---

## [Time-based rule exclusions](https://discuss.elastic.co/t/time-based-rule-exclusions/343451)

<div class="topic-metadata">

**Author:** [@austinvdm](https://discuss.elastic.co/u/austinvdm)\
**Replies:** 0\
**Last updated:** [September 20, 2023, 11:42am UTC](https://discuss.elastic.co/t/time-based-rule-exclusions/343451 "2023-09-20T11:42:44Z")

</div>

Hello, I am curious if there is a way to implement "time-based exclusions" for security rules? For example, we are trying to excluded specific endpoints from a rule on Saturday and Sundays when we run OS updates but stil…

---

## [Error while starting elasticsearch v8.9.1](https://discuss.elastic.co/t/error-while-starting-elasticsearch-v8-9-1/343335)

<div class="topic-metadata">

**Author:** [@sanyam](https://discuss.elastic.co/u/sanyam)\
**Replies:** 3\
**Last updated:** [September 20, 2023, 10:32am UTC](https://discuss.elastic.co/t/error-while-starting-elasticsearch-v8-9-1/343335 "2023-09-20T10:32:21Z")

</div>

Whenever I start up ES by running ES .bat file on Windows, I receive this error: \[ERROR\]\[o.e.b.Elasticsearch \] \[node-1\] fatal exception while booting Elasticsearchorg.elasticsearch.ElasticsearchSecurityException: i…

---

## [Some entries is not coming in the field](https://discuss.elastic.co/t/some-entries-is-not-coming-in-the-field/343442)

<div class="topic-metadata">

**Author:** [@Rutuja\_More](https://discuss.elastic.co/u/Rutuja_More)\
**Replies:** 0\
**Last updated:** [September 20, 2023, 10:26am UTC](https://discuss.elastic.co/t/some-entries-is-not-coming-in-the-field/343442 "2023-09-20T10:26:14Z")

</div>

In my kibana field im putting one by one log but some entries is coming properly and some is not? @timestamp timestamp log\_type log\_level log\_message message Sep 20, 2023 @ 13:32:44.312 - - - - 023-09-01 14:07:0…

---

## [Kiaban generated url for index pattern](https://discuss.elastic.co/t/kiaban-generated-url-for-index-pattern/343438)

<div class="topic-metadata">

**Author:** [@O\_K](https://discuss.elastic.co/u/O_K)\
**Replies:** 0\
**Last updated:** [September 20, 2023, 9:50am UTC](https://discuss.elastic.co/t/kiaban-generated-url-for-index-pattern/343438 "2023-09-20T09:50:13Z")

</div>

I'm writing some app which will be generating kibana URLs with particular logs. The problem I faced that I can discover indexes in kibana UI using data view or get data view id from kibana API /api/data\_views and then ma…

---

## [Metricbeat 7.13 not working](https://discuss.elastic.co/t/metricbeat-7-13-not-working/343439)

<div class="topic-metadata">

**Author:** [@Spottie](https://discuss.elastic.co/u/Spottie)\
**Replies:** 0\
**Last updated:** [September 20, 2023, 9:56am UTC](https://discuss.elastic.co/t/metricbeat-7-13-not-working/343439 "2023-09-20T09:56:10Z")

</div>

I have a docker setup with multiple containers running and then setup a filebeat that logs into my elasticsearch. Now I wanted to setup a metricbeat as described here: Set up and run Metricbeat | Metricbeat Reference \[7…

---

## [Daily index size with rollover](https://discuss.elastic.co/t/daily-index-size-with-rollover/343402)

<div class="topic-metadata">

**Author:** [@INS](https://discuss.elastic.co/u/INS)\
**Replies:** 4\
**Last updated:** [September 20, 2023, 9:55am UTC](https://discuss.elastic.co/t/daily-index-size-with-rollover/343402 "2023-09-20T09:55:21Z")

</div>

Hi Can You help me to find a solution how to make a chart with daily index size.Such index are rollover a few times per day. Thx for hint

---

## [Reference line with the median of max values](https://discuss.elastic.co/t/reference-line-with-the-median-of-max-values/343433)

<div class="topic-metadata">

**Author:** [@SpicyS](https://discuss.elastic.co/u/SpicyS)\
**Replies:** 2\
**Last updated:** [September 20, 2023, 9:29am UTC](https://discuss.elastic.co/t/reference-line-with-the-median-of-max-values/343433 "2023-09-20T09:29:09Z")

</div>

Hello, In kibana lens I would like to know if it is possible to create a reference line layer that show me de median of the max values over time. This way i can compare the current average with the median of max value t…

---

## ["Failed to decode response" error from Java Client 8.8.0](https://discuss.elastic.co/t/failed-to-decode-response-error-from-java-client-8-8-0/343309)

<div class="topic-metadata">

**Author:** [@Roman\_Kagan](https://discuss.elastic.co/u/Roman_Kagan)\
**Replies:** 10\
**Last updated:** [September 20, 2023, 9:12am UTC](https://discuss.elastic.co/t/failed-to-decode-response-error-from-java-client-8-8-0/343309 "2023-09-20T09:12:14Z")

</div>

Hello: I am trying to use Elastic Java Client 8.8.0 (also known low-level rest client) and getting the error: status: 200, \[es/search\] Failed to decode response I used the same library to create a new index and insert …

---

## [Document to setup on-prem single node ECK on Kubernetes with elastic agent](https://discuss.elastic.co/t/document-to-setup-on-prem-single-node-eck-on-kubernetes-with-elastic-agent/343428)

<div class="topic-metadata">

**Author:** [@sankumar](https://discuss.elastic.co/u/sankumar)\
**Replies:** 0\
**Last updated:** [September 20, 2023, 8:19am UTC](https://discuss.elastic.co/t/document-to-setup-on-prem-single-node-eck-on-kubernetes-with-elastic-agent/343428 "2023-09-20T08:19:00Z")

</div>

Want to setup single node ECK on Kubernetes with elastic agent. So looking for the document to setup.

---

## [Uptime monitor status cant use KQL to select specific synthetic monitor](https://discuss.elastic.co/t/uptime-monitor-status-cant-use-kql-to-select-specific-synthetic-monitor/343368)

<div class="topic-metadata">

**Author:** [@niecore](https://discuss.elastic.co/u/niecore)\
**Replies:** 6\
**Last updated:** [September 20, 2023, 8:06am UTC](https://discuss.elastic.co/t/uptime-monitor-status-cant-use-kql-to-select-specific-synthetic-monitor/343368 "2023-09-20T08:06:55Z")

</div>

Hello, Our elastic cloud stack (8.9.1) currently has following issue, where I can not use the KQL to create a alert for a specific synthetic monitor. The screenshot below shows the info "0 Monitors" selected. Has an…

---

## [Semantic search on more than 10k documents](https://discuss.elastic.co/t/semantic-search-on-more-than-10k-documents/343362)

<div class="topic-metadata">

**Author:** [@Denis\_Stefan](https://discuss.elastic.co/u/Denis_Stefan)\
**Replies:** 3\
**Last updated:** [September 20, 2023, 7:44am UTC](https://discuss.elastic.co/t/semantic-search-on-more-than-10k-documents/343362 "2023-09-20T07:44:47Z")

</div>

Hello. I am currently developing a semantic search solution and I have to work with more than 10k documents (more than the maximum number of candidates which is 10k for the kNN algorithm). I am trying to find a solution…

---

## [Sending output to different indices depending on conditions](https://discuss.elastic.co/t/sending-output-to-different-indices-depending-on-conditions/343423)

<div class="topic-metadata">

**Author:** [@DetlefG](https://discuss.elastic.co/u/DetlefG)\
**Replies:** 0\
**Last updated:** [September 20, 2023, 7:31am UTC](https://discuss.elastic.co/t/sending-output-to-different-indices-depending-on-conditions/343423 "2023-09-20T07:31:17Z")

</div>

Hi, I try to write logs via filebeat to different indices depending on a field in the logs. But I'm not sure, how the rule setting when is working. Is it correct, that if the first when condition is fullfilled the seco…

---

## [Hardware compability for elasticsearch](https://discuss.elastic.co/t/hardware-compability-for-elasticsearch/343405)

<div class="topic-metadata">

**Author:** [@Cino](https://discuss.elastic.co/u/Cino)\
**Replies:** 1\
**Last updated:** [September 20, 2023, 7:24am UTC](https://discuss.elastic.co/t/hardware-compability-for-elasticsearch/343405 "2023-09-20T07:24:07Z")

</div>

hello team, I have a basic question about hardware compability or dependency with search engine. My hardware consists of NVMe direct attached disks( for better performance). Could we use such alternate raid options like…

---

## [ELK Pricing help for onprem cluster](https://discuss.elastic.co/t/elk-pricing-help-for-onprem-cluster/343322)

<div class="topic-metadata">

**Author:** [@mangeshmj1992](https://discuss.elastic.co/u/mangeshmj1992)\
**Replies:** 2\
**Last updated:** [September 20, 2023, 5:14am UTC](https://discuss.elastic.co/t/elk-pricing-help-for-onprem-cluster/343322 "2023-09-20T05:14:22Z")

</div>

Hi team, Can you please help us to understand pricing for ELK onprem 4 node cluster with 128 GB of ram for each node and 12 TB harddisk or each node Please share for platinum and enterprise pricing comparision

---

## [What is the max throughput of the stdout?](https://discuss.elastic.co/t/what-is-the-max-throughput-of-the-stdout/343416)

<div class="topic-metadata">

**Author:** [@Daniel9](https://discuss.elastic.co/u/Daniel9)\
**Replies:** 0\
**Last updated:** [September 20, 2023, 5:00am UTC](https://discuss.elastic.co/t/what-is-the-max-throughput-of-the-stdout/343416 "2023-09-20T05:00:14Z")

</div>

Here is my out output configration below: output { stdout { codec =\> json\_lines } } Here is my verification result: |Logs/s(In)|Logs/s (out)|Bytes/log (out)|Queue increase size (m)| |1500|200|580|700m| |780|200|5…

---

## [ELK stack - Kibana fails time to time giving the same error ( Elasticsearch failed Search rejected due to missing shards \[)\[.kibana\_task\_manager\_7.17.7\_001\]\[0\]\])](https://discuss.elastic.co/t/elk-stack-kibana-fails-time-to-time-giving-the-same-error-elasticsearch-failed-search-rejected-due-to-missing-shards-kibana-task-manager-7-17-7-001-0/343414)

<div class="topic-metadata">

**Author:** [@Senith\_Dilitha](https://discuss.elastic.co/u/Senith_Dilitha)\
**Replies:** 0\
**Last updated:** [September 20, 2023, 3:37am UTC](https://discuss.elastic.co/t/elk-stack-kibana-fails-time-to-time-giving-the-same-error-elasticsearch-failed-search-rejected-due-to-missing-shards-kibana-task-manager-7-17-7-001-0/343414 "2023-09-20T03:37:46Z")

</div>

I am using the ELK stack deployed in a docker swarm for logging. From time to time I get the below error and Kibana service fails. \[Elasticsearch failed Search rejected due to missing shards \[\[.kibana\_task\_manager\_7.17.…

---

## [Elastic Cloud: Defining roles to user in Okta using SAML](https://discuss.elastic.co/t/elastic-cloud-defining-roles-to-user-in-okta-using-saml/343153)

<div class="topic-metadata">

**Author:** [@Buddha](https://discuss.elastic.co/u/Buddha)\
**Replies:** 1\
**Last updated:** [September 20, 2023, 1:59am UTC](https://discuss.elastic.co/t/elastic-cloud-defining-roles-to-user-in-okta-using-saml/343153 "2023-09-20T01:59:37Z")

</div>

Hello, Right now, I'm defining roles for user using the security api POST /\_security/role\_mapping/viewer\_mapping { "roles": \[ "custome\_role\_viewer"\], "enabled": true, "rules": { "field" : { "username" : \["us…

---

## [I got the exception when I added kerberos authentication to es](https://discuss.elastic.co/t/i-got-the-exception-when-i-added-kerberos-authentication-to-es/343116)

<div class="topic-metadata">

**Author:** [@zytine](https://discuss.elastic.co/u/zytine)\
**Replies:** 4\
**Last updated:** [September 20, 2023, 1:53am UTC](https://discuss.elastic.co/t/i-got-the-exception-when-i-added-kerberos-authentication-to-es/343116 "2023-09-20T01:53:49Z")

</div>

Hello, My es was running fine, but when I added kerberos authentication and restarted，I got the following error \[2023-09-15T23:09:36,876\]\[WARN \]\[o.e.x.s.a.s.m.NativeRoleMappingStore\] \[bsa264\] Failed to clear cache for…

---

## [Error: Config validation of xpack.fleet.proxy - Docker - kibana.yml - v8.10.1](https://discuss.elastic.co/t/error-config-validation-of-xpack-fleet-proxy-docker-kibana-yml-v8-10-1/343408)

<div class="topic-metadata">

**Author:** [@Peeki](https://discuss.elastic.co/u/Peeki)\
**Replies:** 0\
**Last updated:** [September 19, 2023, 11:58pm UTC](https://discuss.elastic.co/t/error-config-validation-of-xpack-fleet-proxy-docker-kibana-yml-v8-10-1/343408 "2023-09-19T23:58:19Z")

</div>

Hi, When i start my Kibana container i get the following error. Error: \[config validation of \[xpack.fleet\].proxy\] kibana.yml configs are xpack.fleet.proxy: - id: aproxy name: aproxy url: http://fleetserver…

---

## [Fleet-server and elastic-agent metricbeat x509 unknown CA on kubernetes](https://discuss.elastic.co/t/fleet-server-and-elastic-agent-metricbeat-x509-unknown-ca-on-kubernetes/343279)

<div class="topic-metadata">

**Author:** [@Eric-Domeier](https://discuss.elastic.co/u/Eric-Domeier)\
**Replies:** 1\
**Last updated:** [September 19, 2023, 9:30pm UTC](https://discuss.elastic.co/t/fleet-server-and-elastic-agent-metricbeat-x509-unknown-ca-on-kubernetes/343279 "2023-09-19T21:30:04Z")

</div>

Environment details Kubernetes cluster RKE2 v1.27.3 with DISA STIG's ECK Operator: 2.9.0 (Ironbank image) Elastic Agent Image: 8.9.0 (Ironbank image) Issue: After getting the pod(s) fleet server and agents to a runn…

---

## [Unable to authenticate user \[elastic\] for REST request \[/\]](https://discuss.elastic.co/t/unable-to-authenticate-user-elastic-for-rest-request/343393)

<div class="topic-metadata">

**Author:** [@alexus](https://discuss.elastic.co/u/alexus)\
**Replies:** 1\
**Last updated:** [September 19, 2023, 8:14pm UTC](https://discuss.elastic.co/t/unable-to-authenticate-user-elastic-for-rest-request/343393 "2023-09-19T20:14:00Z")

</div>

Hello, I'm trying to configure logs for my Elasticsearch cluster, by following this: and even though i set verification\_mode to none, i still getting 401 {"log.level":"error","@timestamp":"2023-09-19T19:13:02.623Z…

---

## [InferenceConfig doesn't support text\_expansion value when creating a pipeline from java](https://discuss.elastic.co/t/inferenceconfig-doesnt-support-text-expansion-value-when-creating-a-pipeline-from-java/342377)

<div class="topic-metadata">

**Author:** [@ajperez](https://discuss.elastic.co/u/ajperez)\
**Replies:** 6\
**Last updated:** [September 19, 2023, 9:04pm UTC](https://discuss.elastic.co/t/inferenceconfig-doesnt-support-text-expansion-value-when-creating-a-pipeline-from-java/342377 "2023-09-19T21:04:33Z")

</div>

When creating a PutPipelineRequest with the Java client version 8.9.1, InferenceConfig doesn’t support “text\_expansion” value, an error is thrown co.elastic.clients.json.JsonpMappingException: Error deserializing co.elas…

---

## [Cancel after time interval clarification](https://discuss.elastic.co/t/cancel-after-time-interval-clarification/343401)

<div class="topic-metadata">

**Author:** [@maxfriz](https://discuss.elastic.co/u/maxfriz)\
**Replies:** 0\
**Last updated:** [September 19, 2023, 8:48pm UTC](https://discuss.elastic.co/t/cancel-after-time-interval-clarification/343401 "2023-09-19T20:48:29Z")

</div>

To ensure a clear understanding of our global search configuration for a given cluster, I would like to clarify the following as written: The search.cancel\_after\_time\_interval configures (at the data node level) the t…

---

## [What's the secret to fast recovery when adding a new node?](https://discuss.elastic.co/t/whats-the-secret-to-fast-recovery-when-adding-a-new-node/343397)

<div class="topic-metadata">

**Author:** [@linkerc](https://discuss.elastic.co/u/linkerc)\
**Replies:** 0\
**Last updated:** [September 19, 2023, 8:08pm UTC](https://discuss.elastic.co/t/whats-the-secret-to-fast-recovery-when-adding-a-new-node/343397 "2023-09-19T20:08:45Z")

</div>

We are on on version 7.15. Still experiencing issues during recovery. The cluster will often (very likely) move shards from new node back to old nodes even though the new node(s) are still have way fewer shards (and lo…

---

## [Pfelk logstash data parsing](https://discuss.elastic.co/t/pfelk-logstash-data-parsing/343284)

<div class="topic-metadata">

**Author:** [@kozistan](https://discuss.elastic.co/u/kozistan)\
**Replies:** 8\
**Last updated:** [September 19, 2023, 7:54pm UTC](https://discuss.elastic.co/t/pfelk-logstash-data-parsing/343284 "2023-09-19T19:54:03Z")

</div>

Hello would appreciate help with logstash parsing data into elastisearch. Please check my log output. Using opnsense syslog to logstash's pfelk addon and can not figure out whe right mutate filter to get this done. Thank…

---

## [Failed to start the service winlogbeat](https://discuss.elastic.co/t/failed-to-start-the-service-winlogbeat/343289)

<div class="topic-metadata">

**Author:** [@Waseem.M](https://discuss.elastic.co/u/Waseem.M)\
**Replies:** 3\
**Last updated:** [September 19, 2023, 7:26pm UTC](https://discuss.elastic.co/t/failed-to-start-the-service-winlogbeat/343289 "2023-09-19T19:26:24Z")

</div>

Hi everyone, I'm facing the issue to start the winlogbeat server on my windows servers " windows couldn't start the winlogbeat on your local computer. Error 1067 Please assist if anyone faced this issues and solved. Th…

---

## [Logstash 7.x Log4j CVE remediation on Windows server](https://discuss.elastic.co/t/logstash-7-x-log4j-cve-remediation-on-windows-server/343374)

<div class="topic-metadata">

**Author:** [@newschapmj1](https://discuss.elastic.co/u/newschapmj1)\
**Replies:** 0\
**Last updated:** [September 19, 2023, 2:22pm UTC](https://discuss.elastic.co/t/logstash-7-x-log4j-cve-remediation-on-windows-server/343374 "2023-09-19T14:22:04Z")

</div>

Logstash 7.x Log4j Windows script Contains Linux and MacOs Installations and Docker. Has anyone got the same script/steps for Windows server?

---

## [Kibana 8.10.1 Security Update](https://discuss.elastic.co/t/kibana-8-10-1-security-update/343287)

<div class="topic-metadata">

**Author:** [@Levine](https://discuss.elastic.co/u/Levine)\
**Replies:** 0\
**Last updated:** [September 18, 2023, 5:53pm UTC](https://discuss.elastic.co/t/kibana-8-10-1-security-update/343287 "2023-09-18T17:53:06Z")

</div>

Kibana Insertion of Sensitive Information into Log File (ESA-2023-17) An issue was discovered by Elastic whereby sensitive information is recorded in Kibana logs in the event of an error. The issue impacts only Kibana ve…

---

## [Pipeline date\_time parser failure beats me (sorry for the pun :)](https://discuss.elastic.co/t/pipeline-date-time-parser-failure-beats-me-sorry-for-the-pun/343380)

<div class="topic-metadata">

**Author:** [@stefws](https://discuss.elastic.co/u/stefws)\
**Replies:** 4\
**Last updated:** [September 19, 2023, 5:30pm UTC](https://discuss.elastic.co/t/pipeline-date-time-parser-failure-beats-me-sorry-for-the-pun/343380 "2023-09-19T17:30:51Z")

</div>

I'm ingesting Redhat AMQ log with filebeat, only filebeat claims the ingest pipeline fails to parse date time of every event. But testing a sample event/document from fiebeat log, pipeline works fine, that beats me. Hint…

---

## [Beats, Elastic Agent, APM Server, and Fleet Server 8.10.1 Security Update - Improper Certificate Validation issue (ESA-2023-16)](https://discuss.elastic.co/t/beats-elastic-agent-apm-server-and-fleet-server-8-10-1-security-update-improper-certificate-validation-issue-esa-2023-16/343385)

<div class="topic-metadata">

**Author:** [@rodrigo\_silva](https://discuss.elastic.co/u/rodrigo_silva)\
**Replies:** 0\
**Last updated:** [September 19, 2023, 3:32pm UTC](https://discuss.elastic.co/t/beats-elastic-agent-apm-server-and-fleet-server-8-10-1-security-update-improper-certificate-validation-issue-esa-2023-16/343385 "2023-09-19T15:32:21Z")

</div>

Beats, Elastic Agent, APM Server, and Fleet Server Improper Certificate Validation issue (ESA-2023-16) It was discovered that when acting as TLS clients, Beats, Elastic Agent, APM Server, and Fleet Server did not verify …

[Previous page](https://discuss.elastic.co/latest.md?page=534)

[Next page](https://discuss.elastic.co/latest.md?page=536)
