# Latest

**URL:** https://discuss.elastic.co/latest.md?page=542

[Latest](https://discuss.elastic.co/latest.md) · [Categories](https://discuss.elastic.co/categories.md) · [Tags](https://discuss.elastic.co/tags.md)

**Page:** 543

---

## [🎉 Elastic Stack 8.10 released](https://discuss.elastic.co/t/elastic-stack-8-10-released/342971)

<div class="topic-metadata">

**Author:** [@dadoonet](https://discuss.elastic.co/u/dadoonet)\
**Replies:** 0\
**Last updated:** [September 13, 2023, 3:06pm UTC](https://discuss.elastic.co/t/elastic-stack-8-10-released/342971 "2023-09-13T15:06:45Z")

</div>

:tada: What’s new in Elastic 8.10 Building modern search experiences, observing distributed systems, and protecting against complex threats has never been easier with Elastic. Discover the broad set of new capabilities i…

---

## [Global Filter Overrides the Hard coded Date Range](https://discuss.elastic.co/t/global-filter-overrides-the-hard-coded-date-range/342090)

<div class="topic-metadata">

**Author:** [@Kumar\_Abhinav](https://discuss.elastic.co/u/Kumar_Abhinav)\
**Replies:** 10\
**Last updated:** [September 13, 2023, 2:38pm UTC](https://discuss.elastic.co/t/global-filter-overrides-the-hard-coded-date-range/342090 "2023-09-13T14:38:08Z")

</div>

Hello everyone, I've been working on a Kibana dashboard to track item expirations over time. I created a Visualization table that displays the Date Range, Item Name, Item Location, Item Expiry Date, and Quantity. Specif…

---

## [How to aggregate conditionally logs](https://discuss.elastic.co/t/how-to-aggregate-conditionally-logs/342945)

<div class="topic-metadata">

**Author:** [@Marieta](https://discuss.elastic.co/u/Marieta)\
**Replies:** 1\
**Last updated:** [September 13, 2023, 2:30pm UTC](https://discuss.elastic.co/t/how-to-aggregate-conditionally-logs/342945 "2023-09-13T14:30:07Z")

</div>

Hi I am trying to aggregate the following logs: 2023-09-06 07:36:22,573 | INFO | Thread-934 | Config | ENTERORDER: identifier = 'Barbie', buy = false, quantity = 290000.0, price = 96.1, account = '123', reference = '',…

---

## [Throttling of Elastic Web Crawler](https://discuss.elastic.co/t/throttling-of-elastic-web-crawler/342955)

<div class="topic-metadata">

**Author:** [@sebastianboelling](https://discuss.elastic.co/u/sebastianboelling)\
**Replies:** 1\
**Last updated:** [September 13, 2023, 1:31pm UTC](https://discuss.elastic.co/t/throttling-of-elastic-web-crawler/342955 "2023-09-13T13:31:08Z")

</div>

Hi, we are using the Elastic Web Crawler. Is there a way or an idea to limit or throttle the requests the Crawler makes againts a Web datasource (a domain)? For example max 1 request per second ro wait x miliseconds bet…

---

## [Please help kibana show server not ready yet](https://discuss.elastic.co/t/please-help-kibana-show-server-not-ready-yet/342943)

<div class="topic-metadata">

**Author:** [@Mbrezzy](https://discuss.elastic.co/u/Mbrezzy)\
**Replies:** 1\
**Last updated:** [September 13, 2023, 1:07pm UTC](https://discuss.elastic.co/t/please-help-kibana-show-server-not-ready-yet/342943 "2023-09-13T13:07:48Z")

</div>

I have active the trial version of security but when its ended i face this problem and kibana show me server is not ready yet

---

## [Want to figure that how the mapping of an index gets changed on one env](https://discuss.elastic.co/t/want-to-figure-that-how-the-mapping-of-an-index-gets-changed-on-one-env/342934)

<div class="topic-metadata">

**Author:** [@Mansi\_Ghule](https://discuss.elastic.co/u/Mansi_Ghule)\
**Replies:** 7\
**Last updated:** [September 13, 2023, 12:53pm UTC](https://discuss.elastic.co/t/want-to-figure-that-how-the-mapping-of-an-index-gets-changed-on-one-env/342934 "2023-09-13T12:53:29Z")

</div>

Hello, I want to figure out that is there any chances that the mapping of the index may change. As the ES queries n all was running fine on one env but sudden I'm getting error while searching. And I checked that and …

---

## [Data not coming through for my ELASTIC APM for .net framework 4.6.1](https://discuss.elastic.co/t/data-not-coming-through-for-my-elastic-apm-for-net-framework-4-6-1/342949)

<div class="topic-metadata">

**Author:** [@Timmy101](https://discuss.elastic.co/u/Timmy101)\
**Replies:** 0\
**Last updated:** [September 13, 2023, 12:22pm UTC](https://discuss.elastic.co/t/data-not-coming-through-for-my-elastic-apm-for-net-framework-4-6-1/342949 "2023-09-13T12:22:03Z")

</div>

Hi All, please I have installed Elastic APM in 3 of my API -projects and they all work fine but am having issues in one. Did everything a per documentation but no data coming through. and am getting this error , don…

---

## [Substitute GROK by dissect: test of writing](https://discuss.elastic.co/t/substitute-grok-by-dissect-test-of-writing/342930)

<div class="topic-metadata">

**Author:** [@sam1975](https://discuss.elastic.co/u/sam1975)\
**Replies:** 2\
**Last updated:** [September 13, 2023, 12:07pm UTC](https://discuss.elastic.co/t/substitute-grok-by-dissect-test-of-writing/342930 "2023-09-13T12:07:54Z")

</div>

hello, I want to substitute a grok filter by a dissect In a few words, i want replace this grok filter grok { match =\> { "\[raw\_syslog\_result\]\[syslog\_message\]" =\> \[ "THREAT,%{WORD:threat\_type},%{DATA:generate\_time},%…

---

## [How to ingest Squid proxy logs into elasticsearch and visualize on kibana?](https://discuss.elastic.co/t/how-to-ingest-squid-proxy-logs-into-elasticsearch-and-visualize-on-kibana/342906)

<div class="topic-metadata">

**Author:** [@irshadalam](https://discuss.elastic.co/u/irshadalam)\
**Replies:** 2\
**Last updated:** [September 13, 2023, 11:49am UTC](https://discuss.elastic.co/t/how-to-ingest-squid-proxy-logs-into-elasticsearch-and-visualize-on-kibana/342906 "2023-09-13T11:49:07Z")

</div>

How to craete ingest-pipeline Squid proxy logs into elasticsearch and visualize on kibana ?

---

## [Elastic Security Issues](https://discuss.elastic.co/t/elastic-security-issues/342900)

<div class="topic-metadata">

**Author:** [@Phyo\_WaThone\_Win](https://discuss.elastic.co/u/Phyo_WaThone_Win)\
**Replies:** 1\
**Last updated:** [September 13, 2023, 11:18am UTC](https://discuss.elastic.co/t/elastic-security-issues/342900 "2023-09-13T11:18:03Z")

</div>

Hello, Firslty, sorry for my english. In my elastic panel, I see this error In your Elasticsearch configuration (elasticsearch.yml), enable: Elasticsearch security(opens in a new tab or window). Set xpack.security.ena…

---

## [Elasticsearch cluster status is yellow](https://discuss.elastic.co/t/elasticsearch-cluster-status-is-yellow/342911)

<div class="topic-metadata">

**Author:** [@vikascateina](https://discuss.elastic.co/u/vikascateina)\
**Replies:** 4\
**Last updated:** [September 13, 2023, 10:44am UTC](https://discuss.elastic.co/t/elasticsearch-cluster-status-is-yellow/342911 "2023-09-13T10:44:20Z")

</div>

Hi, I have created elasticsearch,kibana and apm in a single node and all is working properly ,kibana and apm is healthy but elasticsearch status is yellow.I also want to say elasticsearch status was green before,but afte…

---

## [Use fleet-server integration without authority certificates](https://discuss.elastic.co/t/use-fleet-server-integration-without-authority-certificates/342933)

<div class="topic-metadata">

**Author:** [@Guillaume\_Cotral](https://discuss.elastic.co/u/Guillaume_Cotral)\
**Replies:** 0\
**Last updated:** [September 13, 2023, 10:10am UTC](https://discuss.elastic.co/t/use-fleet-server-integration-without-authority-certificates/342933 "2023-09-13T10:10:24Z")

</div>

Hello everybody, I set up an ELK server running Docker with Elasticsearch and Kibana within my company as a test. I would like to know if it is possible to delete the authentication certificates so that the integrations…

---

## [Elastic search queue choking](https://discuss.elastic.co/t/elastic-search-queue-choking/342904)

<div class="topic-metadata">

**Author:** [@cosmos\_roeba](https://discuss.elastic.co/u/cosmos_roeba)\
**Replies:** 5\
**Last updated:** [September 13, 2023, 9:52am UTC](https://discuss.elastic.co/t/elastic-search-queue-choking/342904 "2023-09-13T09:52:59Z")

</div>

I am running a 2 node cluster with 2 core cpus. I have 2 indices with about 1 million docs each. They are flat documents and I need to enable search on title key stored both as text and keyword. Search text is minimum 3…

---

## [I cannot search the file name from path in Elasticsearch](https://discuss.elastic.co/t/i-cannot-search-the-file-name-from-path-in-elasticsearch/342812)

<div class="topic-metadata">

**Author:** [@Enes\_Can\_ISIK](https://discuss.elastic.co/u/Enes_Can_ISIK)\
**Replies:** 3\
**Last updated:** [September 13, 2023, 9:48am UTC](https://discuss.elastic.co/t/i-cannot-search-the-file-name-from-path-in-elasticsearch/342812 "2023-09-13T09:48:05Z")

</div>

I want to search filename from a path in Elasticsearch, but I cannot do it. I have documents consisting of "name" fields with paths. Example: Name "folder/folder1/test/folder2/folder/" "folder/folder1/test/folder2/f…

---

## [Doubt about cacerts file of Elasticsearch](https://discuss.elastic.co/t/doubt-about-cacerts-file-of-elasticsearch/342925)

<div class="topic-metadata">

**Author:** [@RdrgPorto](https://discuss.elastic.co/u/RdrgPorto)\
**Replies:** 0\
**Last updated:** [September 13, 2023, 9:18am UTC](https://discuss.elastic.co/t/doubt-about-cacerts-file-of-elasticsearch/342925 "2023-09-13T09:18:34Z")

</div>

Hi, everyone I would like to know the purpose of cacerts file of Elasticsearch (/usr/share/elasticsearch/jdk/lib/security/cacerts). It has some certificates into, are they important? they could be removed? Thanks in a…

---

## [Elastic CEF integration.. no messages to elasticsearch](https://discuss.elastic.co/t/elastic-cef-integration-no-messages-to-elasticsearch/340132)

<div class="topic-metadata">

**Author:** [@mr\_ph](https://discuss.elastic.co/u/mr_ph)\
**Replies:** 2\
**Last updated:** [September 13, 2023, 8:30am UTC](https://discuss.elastic.co/t/elastic-cef-integration-no-messages-to-elasticsearch/340132 "2023-09-13T08:30:52Z")

</div>

Hi, team I am using ELK 8.9. Also while i am looking into the integration, at the cef integration part after the configuration i am only getting these errors failed to get tcp6 stats from /proc: /proc/net/tcp6 entry …

---

## [Error: could not parse \[webhook\] action failed parsing http request template](https://discuss.elastic.co/t/error-could-not-parse-webhook-action-failed-parsing-http-request-template/342917)

<div class="topic-metadata">

**Author:** [@rathasatekun](https://discuss.elastic.co/u/rathasatekun)\
**Replies:** 0\
**Last updated:** [September 13, 2023, 7:38am UTC](https://discuss.elastic.co/t/error-could-not-parse-webhook-action-failed-parsing-http-request-template/342917 "2023-09-13T07:38:59Z")

</div>

I try to create Watcher , when i save it error could not parse \[webhook\] action \[42407423-32c4-4a72-aedf-03e31c4d6856/xxxx\_webhook\]. failed parsing http request template "actions": { "gosd\_webhook": { "transform": { …

---

## [Logstash output to loki](https://discuss.elastic.co/t/logstash-output-to-loki/342910)

<div class="topic-metadata">

**Author:** [@Neelam\_Zanvar](https://discuss.elastic.co/u/Neelam_Zanvar)\
**Replies:** 0\
**Last updated:** [September 13, 2023, 7:04am UTC](https://discuss.elastic.co/t/logstash-output-to-loki/342910 "2023-09-13T07:04:39Z")

</div>

Hi is there any way to send data from logstash to loki or promtial or grafana?

---

## [Elastic search response parsing error](https://discuss.elastic.co/t/elastic-search-response-parsing-error/342909)

<div class="topic-metadata">

**Author:** [@mangeshs](https://discuss.elastic.co/u/mangeshs)\
**Replies:** 0\
**Last updated:** [September 13, 2023, 6:59am UTC](https://discuss.elastic.co/t/elastic-search-response-parsing-error/342909 "2023-09-13T06:59:17Z")

</div>

I am using 7.4 El;asticSearchClient and querying to Elasticsearch. I am getting response in profile object like below "profile": { "shards": \[ { "id": "\[GArOi1iwQHGY2qpSalRgHw\]\[hbs-search-3\]\[0\]", "searches": \[ { …

---

## [How to get iml policy's use by in ES 7.10?](https://discuss.elastic.co/t/how-to-get-iml-policys-use-by-in-es-7-10/342776)

<div class="topic-metadata">

**Author:** [@vsop\_479](https://discuss.elastic.co/u/vsop_479)\
**Replies:** 3\
**Last updated:** [September 13, 2023, 6:20am UTC](https://discuss.elastic.co/t/how-to-get-iml-policys-use-by-in-es-7-10/342776 "2023-09-13T06:20:20Z")

</div>

The \_ilm/policy/my\_policy api can get which indices use this policy in current version, but in 7.10, the response does not contains in\_use\_by info. How to get the similar info(in\_use\_by) in ES 7.10? I noticed Kibana c…

---

## [Kibana status is Yellow due to plugins degraded (after upgrade to version 8.8.2)](https://discuss.elastic.co/t/kibana-status-is-yellow-due-to-plugins-degraded-after-upgrade-to-version-8-8-2/342901)

<div class="topic-metadata">

**Author:** [@chethan\_m](https://discuss.elastic.co/u/chethan_m)\
**Replies:** 1\
**Last updated:** [September 13, 2023, 5:33am UTC](https://discuss.elastic.co/t/kibana-status-is-yellow-due-to-plugins-degraded-after-upgrade-to-version-8-8-2/342901 "2023-09-13T05:33:18Z")

</div>

Hi, I just upgraded elasticseach/ kibana to 8.8.2. Cluster health is Green. But Kibana status is Yellow (when I navigate to http:///status ) What is see is there are lot of plugins in yellow status with the message de…

---

## [What happens if my Elasticsearch cluster has only two nodes with a significant difference in disk storage space?](https://discuss.elastic.co/t/what-happens-if-my-elasticsearch-cluster-has-only-two-nodes-with-a-significant-difference-in-disk-storage-space/342895)

<div class="topic-metadata">

**Author:** [@gaorui](https://discuss.elastic.co/u/gaorui)\
**Replies:** 1\
**Last updated:** [September 13, 2023, 4:06am UTC](https://discuss.elastic.co/t/what-happens-if-my-elasticsearch-cluster-has-only-two-nodes-with-a-significant-difference-in-disk-storage-space/342895 "2023-09-13T04:06:24Z")

</div>

According to the official documentation, when the disk space reaches 85%, replica allocation becomes challenging, at 90% replicas start getting relocated to other nodes (but since I have only two nodes and the principle …

---

## [Identify what a ".save" file is and its purpose](https://discuss.elastic.co/t/identify-what-a-save-file-is-and-its-purpose/342750)

<div class="topic-metadata">

**Author:** [@sampad1](https://discuss.elastic.co/u/sampad1)\
**Replies:** 2\
**Last updated:** [September 13, 2023, 1:22am UTC](https://discuss.elastic.co/t/identify-what-a-save-file-is-and-its-purpose/342750 "2023-09-13T01:22:38Z")

</div>

After deleting some documents from an index, I noticed a compound-file (.cfs) .save file extension as in \_01.cfs.save . I have looked for this file in open source docs/searches and within the community, but I have been u…

---

## [File input not sending to Elasticsearch](https://discuss.elastic.co/t/file-input-not-sending-to-elasticsearch/342891)

<div class="topic-metadata">

**Author:** [@roman-tasi](https://discuss.elastic.co/u/roman-tasi)\
**Replies:** 0\
**Last updated:** [September 13, 2023, 12:55am UTC](https://discuss.elastic.co/t/file-input-not-sending-to-elasticsearch/342891 "2023-09-13T00:55:05Z")

</div>

Hi I am just wondering if someone could look over these relevant portions of my Logstash config to see if there is an issue: input { file { path =\> "/etc/elasticsearch/scripts/otherScripts/fortune.txt" codec =\>…

---

## [Filebeat processor not doing anything](https://discuss.elastic.co/t/filebeat-processor-not-doing-anything/342890)

<div class="topic-metadata">

**Author:** [@artschooldropout](https://discuss.elastic.co/u/artschooldropout)\
**Replies:** 4\
**Last updated:** [September 12, 2023, 11:11pm UTC](https://discuss.elastic.co/t/filebeat-processor-not-doing-anything/342890 "2023-09-12T23:11:49Z")

</div>

I'm trying to use a processor to split up syslog messages into separate fields (using the '=' character as a delimiter). Here's my processor: - type: syslog format: auto protocol.udp: host: "0.0.0.0:9002" tags…

---

## [Syslog to BigQuery help](https://discuss.elastic.co/t/syslog-to-bigquery-help/342816)

<div class="topic-metadata">

**Author:** [@Russ\_Starr](https://discuss.elastic.co/u/Russ_Starr)\
**Replies:** 1\
**Last updated:** [September 12, 2023, 8:53pm UTC](https://discuss.elastic.co/t/syslog-to-bigquery-help/342816 "2023-09-12T20:53:04Z")

</div>

Hi, I am new to logstash and I've been doing some reading and grok debugging. My goal is really simple. I have a Linux box with logstash and I want to receive syslog messages from all my systems and forward them to Googl…

---

## [Error: ElasticSearch won't start when downgraded from 8.9.2 to 8.4.1](https://discuss.elastic.co/t/error-elasticsearch-wont-start-when-downgraded-from-8-9-2-to-8-4-1/342879)

<div class="topic-metadata">

**Author:** [@ujosyula](https://discuss.elastic.co/u/ujosyula)\
**Replies:** 8\
**Last updated:** [September 12, 2023, 8:52pm UTC](https://discuss.elastic.co/t/error-elasticsearch-wont-start-when-downgraded-from-8-9-2-to-8-4-1/342879 "2023-09-12T20:52:35Z")

</div>

I see this error when I try to downgrade. The version of elasticsearch is 8.4.1, but the service won't start. \[2023-09-12T09:52:39,253\]\[ERROR\]\[o.e.b.Elasticsearch \] fatal exception while booting Elasticsearch j…

---

## [How extract a value from grock pattern in a new field](https://discuss.elastic.co/t/how-extract-a-value-from-grock-pattern-in-a-new-field/342855)

<div class="topic-metadata">

**Author:** [@Amani188](https://discuss.elastic.co/u/Amani188)\
**Replies:** 1\
**Last updated:** [September 12, 2023, 7:38pm UTC](https://discuss.elastic.co/t/how-extract-a-value-from-grock-pattern-in-a-new-field/342855 "2023-09-12T19:38:10Z")

</div>

Hi, I'm trying to create new field called Systeme from a grock pattern whitch match the value of Systeme but it's always empty does anyone have an idea about how to do that. I'm using ingest pipeline like this: "gro…

---

## [Elastic Defend - Credential Harderning](https://discuss.elastic.co/t/elastic-defend-credential-harderning/342858)

<div class="topic-metadata">

**Author:** [@slash24](https://discuss.elastic.co/u/slash24)\
**Replies:** 1\
**Last updated:** [September 12, 2023, 6:29pm UTC](https://discuss.elastic.co/t/elastic-defend-credential-harderning/342858 "2023-09-12T18:29:07Z")

</div>

What does the "Credential hardening"-setting in Elastic Defend-integration do for Windows-endpoints when active? Does it simply set the RunasPPL registry key? We have thirdparty components involved in authentication an…

---

## [Read the current date file in filebeat](https://discuss.elastic.co/t/read-the-current-date-file-in-filebeat/342726)

<div class="topic-metadata">

**Author:** [@Golam\_Rabbi](https://discuss.elastic.co/u/Golam_Rabbi)\
**Replies:** 4\
**Last updated:** [September 12, 2023, 7:08pm UTC](https://discuss.elastic.co/t/read-the-current-date-file-in-filebeat/342726 "2023-09-12T19:08:19Z")

</div>

I have some custom log files for my company. The log file naming pattern is like this "api\_datalogger\_11-09-23". Here 11-09-23 means that the log file of September 11, 2023. Now I want to set my filebeat inputs to read t…

[Previous page](https://discuss.elastic.co/latest.md?page=541)

[Next page](https://discuss.elastic.co/latest.md?page=543)
