# Latest

**URL:** https://discuss.elastic.co/latest.md?page=541

[Latest](https://discuss.elastic.co/latest.md) · [Categories](https://discuss.elastic.co/categories.md) · [Tags](https://discuss.elastic.co/tags.md)

**Page:** 542

---

## [Filebeat: send data from a dynamic log + static file version.txt in one event](https://discuss.elastic.co/t/filebeat-send-data-from-a-dynamic-log-static-file-version-txt-in-one-event/343033)

<div class="topic-metadata">

**Author:** [@john123](https://discuss.elastic.co/u/john123)\
**Replies:** 0\
**Last updated:** [September 14, 2023, 9:27am UTC](https://discuss.elastic.co/t/filebeat-send-data-from-a-dynamic-log-static-file-version-txt-in-one-event/343033 "2023-09-14T09:27:00Z")

</div>

Hi, we have a dynamic log 'app.log' and a static file version.txt with th version of the app. We have to send both as a single event with the purpose to have a trace of the errors in function of changing version of the …

---

## [How can I prevent Cloud APM server from flattening my OpenTelemetry tag hierarchy?](https://discuss.elastic.co/t/how-can-i-prevent-cloud-apm-server-from-flattening-my-opentelemetry-tag-hierarchy/342814)

<div class="topic-metadata">

**Author:** [@Annxii](https://discuss.elastic.co/u/Annxii)\
**Replies:** 5\
**Last updated:** [September 14, 2023, 9:08am UTC](https://discuss.elastic.co/t/how-can-i-prevent-cloud-apm-server-from-flattening-my-opentelemetry-tag-hierarchy/342814 "2023-09-14T09:08:33Z")

</div>

We have recently made a deployment to Elastic Cloud with APM (currently running v8.9.1). We are sending OpenTelemetry traces directly from dotnet applications to the APM endpoint. This is working fine, but we are having …

---

## [Index size and doc\_count of a customer or field filter](https://discuss.elastic.co/t/index-size-and-doc-count-of-a-customer-or-field-filter/343025)

<div class="topic-metadata">

**Author:** [@agonzalez](https://discuss.elastic.co/u/agonzalez)\
**Replies:** 0\
**Last updated:** [September 14, 2023, 8:05am UTC](https://discuss.elastic.co/t/index-size-and-doc-count-of-a-customer-or-field-filter/343025 "2023-09-14T08:05:24Z")

</div>

Hi, i have one index where i store documents from different customerid differentiated but a customerid field. I want to know how many documents and storage size each customer is consuming in my index, I can see this for…

---

## [Elastic Logging Plugin SSL certificates issue](https://discuss.elastic.co/t/elastic-logging-plugin-ssl-certificates-issue/343021)

<div class="topic-metadata">

**Author:** [@Vladimir7172](https://discuss.elastic.co/u/Vladimir7172)\
**Replies:** 0\
**Last updated:** [September 14, 2023, 7:23am UTC](https://discuss.elastic.co/t/elastic-logging-plugin-ssl-certificates-issue/343021 "2023-09-14T07:23:48Z")

</div>

Hello! I'm trying to transfer logs from a docker container to ELK using elastic-logging-plugin:8.9.2 On the Elastic side I see this type of error: "error.message":"javax.net.ssl.SSLHandshakeException: Received fatal a…

---

## [Installing Elasticsearch Error](https://discuss.elastic.co/t/installing-elasticsearch-error/342976)

<div class="topic-metadata">

**Author:** [@heureux](https://discuss.elastic.co/u/heureux)\
**Replies:** 2\
**Last updated:** [September 14, 2023, 6:56am UTC](https://discuss.elastic.co/t/installing-elasticsearch-error/342976 "2023-09-14T06:56:38Z")

</div>

Hi, By executing the command: ./bin/elasticsearch I have this error: \< \[ERROR\]\[o.e.b.Elasticsearch \] \[wazuh-server\] fatal exception while booting Elasticsearchjava.lang.RuntimeException: can not run elasticsearc…

---

## [How to show only 2 numbers in vertical axis](https://discuss.elastic.co/t/how-to-show-only-2-numbers-in-vertical-axis/342897)

<div class="topic-metadata">

**Author:** [@rkidev](https://discuss.elastic.co/u/rkidev)\
**Replies:** 3\
**Last updated:** [September 14, 2023, 6:48am UTC](https://discuss.elastic.co/t/how-to-show-only-2-numbers-in-vertical-axis/342897 "2023-09-14T06:48:24Z")

</div>

Hi, I have only 2 servers and in the time series graph I want to show which server is online. Is there any way in Kibana to show only 2 numbers in X-axis ? I know Kibana dynamically set the ranges and display values but…

---

## [The Elasticsearch process is experiencing rapid memory growth in the older generation](https://discuss.elastic.co/t/the-elasticsearch-process-is-experiencing-rapid-memory-growth-in-the-older-generation/343013)

<div class="topic-metadata">

**Author:** [@liguifa](https://discuss.elastic.co/u/liguifa)\
**Replies:** 5\
**Last updated:** [September 14, 2023, 6:46am UTC](https://discuss.elastic.co/t/the-elasticsearch-process-is-experiencing-rapid-memory-growth-in-the-older-generation/343013 "2023-09-14T06:46:43Z")

</div>

As shown in the above figure, my Elasticsearch cluster has experienced rapid memory growth in its old age, and after a period of time, it will be reclaimed, which will also occupy a large amount of memory. How should …

---

## [Help me - The speed of filebeat collection cannot keep up with the speed of file writing](https://discuss.elastic.co/t/help-me-the-speed-of-filebeat-collection-cannot-keep-up-with-the-speed-of-file-writing/343017)

<div class="topic-metadata">

**Author:** [@evanzhang87](https://discuss.elastic.co/u/evanzhang87)\
**Replies:** 0\
**Last updated:** [September 14, 2023, 6:35am UTC](https://discuss.elastic.co/t/help-me-the-speed-of-filebeat-collection-cannot-keep-up-with-the-speed-of-file-writing/343017 "2023-09-14T06:35:50Z")

</div>

My log writing rate is about 3M/s, single log input, my output is kafka, I checked the metrics, pipeline.events.active keeps 4118, {"monitoring": {"metrics": {"beat":{"cgroup":{"cpuacct":{"total":{"ns":1024565234}},"mem…

---

## [No Logs from logstash docker](https://discuss.elastic.co/t/no-logs-from-logstash-docker/342882)

<div class="topic-metadata">

**Author:** [@ranjini](https://discuss.elastic.co/u/ranjini)\
**Replies:** 10\
**Last updated:** [September 14, 2023, 6:12am UTC](https://discuss.elastic.co/t/no-logs-from-logstash-docker/342882 "2023-09-14T06:12:18Z")

</div>

I call logstash from commandline /usr/share/logstash/bin/logstash --path.settings=/usr/share/logstash/config -f /usr/share/logstash/conf.d/ But no logs written bash-4.4$ ls -ld logs1 drwxrwxrwx 2 logstash logstash 6 S…

---

## [Filebeat unable to collect logs from 'nodeSelector' deployment](https://discuss.elastic.co/t/filebeat-unable-to-collect-logs-from-nodeselector-deployment/343011)

<div class="topic-metadata">

**Author:** [@Achu](https://discuss.elastic.co/u/Achu)\
**Replies:** 0\
**Last updated:** [September 14, 2023, 5:58am UTC](https://discuss.elastic.co/t/filebeat-unable-to-collect-logs-from-nodeselector-deployment/343011 "2023-09-14T05:58:25Z")

</div>

I’m experiencing a peculiar issue with Filebeat. I can collect logs from all deployments except a couple of deployments that have a node selection. Filebeat Daemonset is running on this node, and I don’t see any errors f…

---

## [What is the best way to detect inconsistency between elasticsearch with another authorized data store](https://discuss.elastic.co/t/what-is-the-best-way-to-detect-inconsistency-between-elasticsearch-with-another-authorized-data-store/343009)

<div class="topic-metadata">

**Author:** [@zouyang](https://discuss.elastic.co/u/zouyang)\
**Replies:** 0\
**Last updated:** [September 14, 2023, 5:11am UTC](https://discuss.elastic.co/t/what-is-the-best-way-to-detect-inconsistency-between-elasticsearch-with-another-authorized-data-store/343009 "2023-09-14T05:11:37Z")

</div>

Hi, Our system uses dynamoDB as the data store and sync the data to elasticsearch with kafka. In case there are any data loss due to the failure of any part of the system, we would have inconsistency between dynamo and…

---

## [Elasticsearch Security Statement regarding CVE-2022-1471](https://discuss.elastic.co/t/elasticsearch-security-statement-regarding-cve-2022-1471/343006)

<div class="topic-metadata">

**Author:** [@ikakavas](https://discuss.elastic.co/u/ikakavas)\
**Replies:** 0\
**Last updated:** [September 14, 2023, 4:53am UTC](https://discuss.elastic.co/t/elasticsearch-security-statement-regarding-cve-2022-1471/343006 "2023-09-14T04:53:14Z")

</div>

Elasticsearch is not affected by this issue. Elasticsearch is not affected by the issue described in CVE-2022-1471 as, in general, it does not use Snakeyaml to parse YAML. Summary Elasticsearch supports YAML as a format…

---

## [Kibana quits 1 second after launch](https://discuss.elastic.co/t/kibana-quits-1-second-after-launch/342997)

<div class="topic-metadata">

**Author:** [@ljk602308](https://discuss.elastic.co/u/ljk602308)\
**Replies:** 1\
**Last updated:** [September 14, 2023, 3:31am UTC](https://discuss.elastic.co/t/kibana-quits-1-second-after-launch/342997 "2023-09-14T03:31:29Z")

</div>

It was running a week ago, but when I ran it this time, Kibana did not run. The issue of the console window closing as soon as you run kibana.bat still occurs even if you reinstall Kibana. I'm using Windows 10, and Ela…

---

## [Discuss configuration connectors about mail exchange](https://discuss.elastic.co/t/discuss-configuration-connectors-about-mail-exchange/343000)

<div class="topic-metadata">

**Author:** [@vanhaiit90](https://discuss.elastic.co/u/vanhaiit90)\
**Replies:** 2\
**Last updated:** [September 14, 2023, 2:38am UTC](https://discuss.elastic.co/t/discuss-configuration-connectors-about-mail-exchange/343000 "2023-09-14T02:38:43Z")

</div>

Hi everyone! I getting issue when after completed configure connector mail exchange with Client ID and Tenant ID . So I have tried test send but it still shows error And this is a text configure connect mail exch…

---

## [Why is my latest rollover index collecting the data from beginning to last?](https://discuss.elastic.co/t/why-is-my-latest-rollover-index-collecting-the-data-from-beginning-to-last/342893)

<div class="topic-metadata">

**Author:** [@Geeboy](https://discuss.elastic.co/u/Geeboy)\
**Replies:** 6\
**Last updated:** [September 14, 2023, 1:12am UTC](https://discuss.elastic.co/t/why-is-my-latest-rollover-index-collecting-the-data-from-beginning-to-last/342893 "2023-09-14T01:12:22Z")

</div>

good day, I'm experiencing this scenario, the rollover index is collecting data from the beginning to the newest/last data of the logs, as I know only the newest log should be written to the latest rollover index and the…

---

## [How to resolve "Infinite extent for field" if the field is not in all ingested documents?](https://discuss.elastic.co/t/how-to-resolve-infinite-extent-for-field-if-the-field-is-not-in-all-ingested-documents/342996)

<div class="topic-metadata">

**Author:** [@carollyl](https://discuss.elastic.co/u/carollyl)\
**Replies:** 0\
**Last updated:** [September 14, 2023, 12:15am UTC](https://discuss.elastic.co/t/how-to-resolve-infinite-extent-for-field-if-the-field-is-not-in-all-ingested-documents/342996 "2023-09-14T00:15:13Z")

</div>

I have a field named runtime, however, it does not present in all ingested document within the index pattern. Is there a way to filter out the document that does not contains the runtime field for Vega to work? { $sch…

---

## [Migration of ELK users](https://discuss.elastic.co/t/migration-of-elk-users/342647)

<div class="topic-metadata">

**Author:** [@mostafaelsayed](https://discuss.elastic.co/u/mostafaelsayed)\
**Replies:** 3\
**Last updated:** [September 13, 2023, 8:59pm UTC](https://discuss.elastic.co/t/migration-of-elk-users/342647 "2023-09-13T20:59:59Z")

</div>

Hello, Is there a secure way to migrate kibana users from one instance to another along with their passwords? Thanks

---

## [Logstash file plugin on windows](https://discuss.elastic.co/t/logstash-file-plugin-on-windows/342852)

<div class="topic-metadata">

**Author:** [@mahmoud.shsuite](https://discuss.elastic.co/u/mahmoud.shsuite)\
**Replies:** 7\
**Last updated:** [September 13, 2023, 8:03pm UTC](https://discuss.elastic.co/t/logstash-file-plugin-on-windows/342852 "2023-09-13T20:03:41Z")

</div>

I've just installed logstach version 8.9.2 on windows and tried to do first file sample but I am greeting message=\>"Unable to configure plugins: (PluginLoadingError) Couldn't find any input plugin named 'file' I insured…

---

## [REST API Crowdstrike FDR Dashboard Error](https://discuss.elastic.co/t/rest-api-crowdstrike-fdr-dashboard-error/342966)

<div class="topic-metadata">

**Author:** [@sgrubb](https://discuss.elastic.co/u/sgrubb)\
**Replies:** 2\
**Last updated:** [September 13, 2023, 7:57pm UTC](https://discuss.elastic.co/t/rest-api-crowdstrike-fdr-dashboard-error/342966 "2023-09-13T19:57:43Z")

</div>

Good morning, I recently integrated the Crowdstrike FDR stream into my Elastic instance. The integration includes a premade dashboard called \[Crowdstrike\] FDR Overview. When I load the dashboard up, the data is populate…

---

## [Monitor cluster with elastic agent](https://discuss.elastic.co/t/monitor-cluster-with-elastic-agent/342413)

<div class="topic-metadata">

**Author:** [@lduvnjak](https://discuss.elastic.co/u/lduvnjak)\
**Replies:** 16\
**Last updated:** [September 13, 2023, 6:39pm UTC](https://discuss.elastic.co/t/monitor-cluster-with-elastic-agent/342413 "2023-09-13T18:39:17Z")

</div>

Hey Everyone, We're trying to move from the legacy exporters over to Elastic Agent. Our data pipeline is Elastic Agent \> Logstash \> Kafka \> Elastic. I have a couple of questions and would appreciate any and all knowledg…

---

## [Fleet Server shutdown after enroll](https://discuss.elastic.co/t/fleet-server-shutdown-after-enroll/342791)

<div class="topic-metadata">

**Author:** [@bixiyan](https://discuss.elastic.co/u/bixiyan)\
**Replies:** 0\
**Last updated:** [September 12, 2023, 8:47am UTC](https://discuss.elastic.co/t/fleet-server-shutdown-after-enroll/342791 "2023-09-12T08:47:39Z")

</div>

Hi Team: I want to set up fleet server but failed after executed enroll command. My es version is v 7.16.3 . Let me know any more infomation you needed. Here is my fleet enroll command. elastic-agent enroll --url=htt…

---

## [Logstash crashing](https://discuss.elastic.co/t/logstash-crashing/342972)

<div class="topic-metadata">

**Author:** [@sc5283](https://discuss.elastic.co/u/sc5283)\
**Replies:** 4\
**Last updated:** [September 13, 2023, 5:49pm UTC](https://discuss.elastic.co/t/logstash-crashing/342972 "2023-09-13T17:49:37Z")

</div>

Input is from S3 layout of S3 bucket is : s3 { .... bucket =\> "bucket" prefix =\> "YYYY/MM/DD/hh/" ..... } so every hour I have to create a new conf file with the corresponding prefix…

---

## [How are you supposed to use downsampled TSDS data?](https://discuss.elastic.co/t/how-are-you-supposed-to-use-downsampled-tsds-data/342643)

<div class="topic-metadata">

**Author:** [@jerrac](https://discuss.elastic.co/u/jerrac)\
**Replies:** 2\
**Last updated:** [September 13, 2023, 5:39pm UTC](https://discuss.elastic.co/t/how-are-you-supposed-to-use-downsampled-tsds-data/342643 "2023-09-13T17:39:43Z")

</div>

Hey all, yet another topic here related to my efforts at reducing ELK's footprint. This time I'm trying to figure out downsampling. I've successfully configured my dev environment to downsample data. I have downsample\* …

---

## [Error toasts rendering in canvas pdfs](https://discuss.elastic.co/t/error-toasts-rendering-in-canvas-pdfs/342742)

<div class="topic-metadata">

**Author:** [@Krikkits](https://discuss.elastic.co/u/Krikkits)\
**Replies:** 6\
**Last updated:** [September 13, 2023, 5:12pm UTC](https://discuss.elastic.co/t/error-toasts-rendering-in-canvas-pdfs/342742 "2023-09-13T17:12:25Z")

</div>

I saw that there was a github issue raised about it (Kibana should stop rendering security warning on PDFs on unsecured cluster · Issue #82891 · elastic/kibana · GitHub) but I was wondering if there has been a fix or wor…

---

## [Certificate signature failure](https://discuss.elastic.co/t/certificate-signature-failure/342981)

<div class="topic-metadata">

**Author:** [@solo1](https://discuss.elastic.co/u/solo1)\
**Replies:** 0\
**Last updated:** [September 13, 2023, 5:11pm UTC](https://discuss.elastic.co/t/certificate-signature-failure/342981 "2023-09-13T17:11:10Z")

</div>

I tried to follow this (elastic security-basic-setup-https) to configure my elasticsearch and kibana. While the elasticsearch works fine and clients is able to connect successfully with username,password and ca cert(sign…

---

## [Top n over Max() aggregation with group by and then return all fields](https://discuss.elastic.co/t/top-n-over-max-aggregation-with-group-by-and-then-return-all-fields/342954)

<div class="topic-metadata">

**Author:** [@aakashagrawal](https://discuss.elastic.co/u/aakashagrawal)\
**Replies:** 1\
**Last updated:** [September 13, 2023, 4:24pm UTC](https://discuss.elastic.co/t/top-n-over-max-aggregation-with-group-by-and-then-return-all-fields/342954 "2023-09-13T16:24:56Z")

</div>

Hi, I'm a total newbie to Elasticsearch and hence please ignore if you think my question is very basic. I've already looked at this post which solves one part of my problem: What I want is only top n (say top 2) resu…

---

## [Custom index for transaction traces & spans](https://discuss.elastic.co/t/custom-index-for-transaction-traces-spans/341580)

<div class="topic-metadata">

**Author:** [@Namita\_Jaokar](https://discuss.elastic.co/u/Namita_Jaokar)\
**Replies:** 2\
**Last updated:** [September 13, 2023, 4:10pm UTC](https://discuss.elastic.co/t/custom-index-for-transaction-traces-spans/341580 "2023-09-13T16:10:02Z")

</div>

Hi , I am trying to create custom indices for my java agent. I want my transaction traces to be saved in those indices and not the custom .ds-traces\* For the same , I came across APM\>Settings\>Indices in the kibana sec…

---

## [Elastic agent indices - ILM](https://discuss.elastic.co/t/elastic-agent-indices-ilm/342243)

<div class="topic-metadata">

**Author:** [@Tyty](https://discuss.elastic.co/u/Tyty)\
**Replies:** 5\
**Last updated:** [September 13, 2023, 3:30pm UTC](https://discuss.elastic.co/t/elastic-agent-indices-ilm/342243 "2023-09-13T15:30:02Z")

</div>

Hi All, Currently using ELK stack 8.91. Fleet enable. Elasticc-agent deployed on around 100 Servers/vm. I notice that indexes will never be cleared. Seems to be a default behavior. I need to know how to setup an Inde…

---

## [A query builder java library for parsing web query into an elastic client Query object](https://discuss.elastic.co/t/a-query-builder-java-library-for-parsing-web-query-into-an-elastic-client-query-object/342958)

<div class="topic-metadata">

**Author:** [@Jim\_Song](https://discuss.elastic.co/u/Jim_Song)\
**Replies:** 1\
**Last updated:** [September 13, 2023, 3:28pm UTC](https://discuss.elastic.co/t/a-query-builder-java-library-for-parsing-web-query-into-an-elastic-client-query-object/342958 "2023-09-13T15:28:32Z")

</div>

I am building an elastic client Java application that users will enter a search query from the browser. I am looking for an open source Java library that can take the user inputs and parse them into an elasticsearch clie…

---

## [How to delete the records older than certain time using elastic java rest client](https://discuss.elastic.co/t/how-to-delete-the-records-older-than-certain-time-using-elastic-java-rest-client/342960)

<div class="topic-metadata">

**Author:** [@Tukaram](https://discuss.elastic.co/u/Tukaram)\
**Replies:** 1\
**Last updated:** [September 13, 2023, 3:27pm UTC](https://discuss.elastic.co/t/how-to-delete-the-records-older-than-certain-time-using-elastic-java-rest-client/342960 "2023-09-13T15:27:18Z")

</div>

Hi, I am looking to delete all the records older than 1 month or so(in bulk). How to get this done using java restclient.

[Previous page](https://discuss.elastic.co/latest.md?page=540)

[Next page](https://discuss.elastic.co/latest.md?page=542)
