# Latest

**URL:** https://discuss.elastic.co/latest.md?page=543

[Latest](https://discuss.elastic.co/latest.md) · [Categories](https://discuss.elastic.co/categories.md) · [Tags](https://discuss.elastic.co/tags.md)

**Page:** 544

---

## [Logstash 8.9.0 docker logs to stdout. how to provide custom path for it?](https://discuss.elastic.co/t/logstash-8-9-0-docker-logs-to-stdout-how-to-provide-custom-path-for-it/342594)

<div class="topic-metadata">

**Author:** [@ranjini](https://discuss.elastic.co/u/ranjini)\
**Replies:** 4\
**Last updated:** [September 12, 2023, 7:07pm UTC](https://discuss.elastic.co/t/logstash-8-9-0-docker-logs-to-stdout-how-to-provide-custom-path-for-it/342594 "2023-09-12T19:07:53Z")

</div>

What is the file and path that needs to changed to provide custom log path for logstash-plain.log and so on. Please advise

---

## [Getting started graph analytics 7.17](https://discuss.elastic.co/t/getting-started-graph-analytics-7-17/342881)

<div class="topic-metadata">

**Author:** [@hud](https://discuss.elastic.co/u/hud)\
**Replies:** 0\
**Last updated:** [September 12, 2023, 6:24pm UTC](https://discuss.elastic.co/t/getting-started-graph-analytics-7-17/342881 "2023-09-12T18:24:28Z")

</div>

hi all am trying to recreate graph analytics like that from siren Wondering if there was a tutorial / sample data for getting started in creating the graphs. Not sure if this is available on 7.17. Best Hud

---

## [Issue creating case from Dev Panel](https://discuss.elastic.co/t/issue-creating-case-from-dev-panel/341718)

<div class="topic-metadata">

**Author:** [@AceVla](https://discuss.elastic.co/u/AceVla)\
**Replies:** 16\
**Last updated:** [September 12, 2023, 6:19pm UTC](https://discuss.elastic.co/t/issue-creating-case-from-dev-panel/341718 "2023-09-12T18:19:08Z")

</div>

We are creating a case in the dev panel in Elastic, here is the code: POST api/cases { "description": "A case description.", "title": "Case title 1", "tags": \[ "tag 1" \], "connector": { "id": "none", "na…

---

## [Support for Osquery's Carves Table in Upcoming Roadmap?](https://discuss.elastic.co/t/support-for-osquerys-carves-table-in-upcoming-roadmap/342874)

<div class="topic-metadata">

**Author:** [@Bearloggs](https://discuss.elastic.co/u/Bearloggs)\
**Replies:** 0\
**Last updated:** [September 12, 2023, 4:59pm UTC](https://discuss.elastic.co/t/support-for-osquerys-carves-table-in-upcoming-roadmap/342874 "2023-09-12T16:59:09Z")

</div>

Hello, I've been exploring the integration of osquery with Elastic and was curious about a specific feature – the support for osquery's "carves table". The ability to use the carves table for file pulling can be incred…

---

## [How to use frozen storage the right way](https://discuss.elastic.co/t/how-to-use-frozen-storage-the-right-way/342839)

<div class="topic-metadata">

**Author:** [@axel\_r](https://discuss.elastic.co/u/axel_r)\
**Replies:** 3\
**Last updated:** [September 12, 2023, 4:08pm UTC](https://discuss.elastic.co/t/how-to-use-frozen-storage-the-right-way/342839 "2023-09-12T16:08:12Z")

</div>

Hello everyone, I'd like some clarification and information on data tiers frozen in an Elastic Cloud environment. I'm not sure if I understand how this works and I can't find any documentation that answers my questions…

---

## [Bulk import role mappings from one cluster to another via API](https://discuss.elastic.co/t/bulk-import-role-mappings-from-one-cluster-to-another-via-api/342869)

<div class="topic-metadata">

**Author:** [@AndrewDatTeranet](https://discuss.elastic.co/u/AndrewDatTeranet)\
**Replies:** 1\
**Last updated:** [September 12, 2023, 4:16pm UTC](https://discuss.elastic.co/t/bulk-import-role-mappings-from-one-cluster-to-another-via-api/342869 "2023-09-12T16:16:29Z")

</div>

I am attempting to dump all role mappings out of one cluster into another by using the Role Mapping API. I use the generic: GET /\_security/role\_mapping to dump all the mappings but cannot find a way to easily bulk imp…

---

## [Painless Elasticsearch update do not handle big numbers](https://discuss.elastic.co/t/painless-elasticsearch-update-do-not-handle-big-numbers/342633)

<div class="topic-metadata">

**Author:** [@DidierB](https://discuss.elastic.co/u/DidierB)\
**Replies:** 2\
**Last updated:** [September 12, 2023, 4:10pm UTC](https://discuss.elastic.co/t/painless-elasticsearch-update-do-not-handle-big-numbers/342633 "2023-09-12T16:10:37Z")

</div>

Hello, I'm using an index that contains big numbers (tracking data byte count per IP). Each time I see an IP in the log I extract the size of the request and add it to an index with the IP as a key. The index has a mapp…

---

## [Anyone have an easy way to make Metricbeat use Time Series Data Streams (TSDS)?](https://discuss.elastic.co/t/anyone-have-an-easy-way-to-make-metricbeat-use-time-series-data-streams-tsds/342375)

<div class="topic-metadata">

**Author:** [@jerrac](https://discuss.elastic.co/u/jerrac)\
**Replies:** 4\
**Last updated:** [September 12, 2023, 3:17pm UTC](https://discuss.elastic.co/t/anyone-have-an-easy-way-to-make-metricbeat-use-time-series-data-streams-tsds/342375 "2023-09-12T15:17:44Z")

</div>

Long story short, we need to shrink our resource usage with our Elastic Stack. Part of my attempts at that has been implementing down sampling. But, after finally reading the docs carefully enough, I found out that we ne…

---

## [Filebeat registry/log.json size keeps increasing though there are no new log entries in my application log](https://discuss.elastic.co/t/filebeat-registry-log-json-size-keeps-increasing-though-there-are-no-new-log-entries-in-my-application-log/342757)

<div class="topic-metadata">

**Author:** [@palansk](https://discuss.elastic.co/u/palansk)\
**Replies:** 1\
**Last updated:** [September 12, 2023, 3:14pm UTC](https://discuss.elastic.co/t/filebeat-registry-log-json-size-keeps-increasing-though-there-are-no-new-log-entries-in-my-application-log/342757 "2023-09-12T15:14:15Z")

</div>

Filebeat is making entry to log.json file even though are no new logs being added to my application log file. Below is the excerpt of the log.json file {"k":"filebeat::logs::native::670096-64768","v":{"ttl":-1,"FileSta…

---

## [Metricbeat unable to insert data after upgrade from 7 to 8](https://discuss.elastic.co/t/metricbeat-unable-to-insert-data-after-upgrade-from-7-to-8/342859)

<div class="topic-metadata">

**Author:** [@Claude\_Brassel](https://discuss.elastic.co/u/Claude_Brassel)\
**Replies:** 0\
**Last updated:** [September 12, 2023, 2:52pm UTC](https://discuss.elastic.co/t/metricbeat-unable-to-insert-data-after-upgrade-from-7-to-8/342859 "2023-09-12T14:52:24Z")

</div>

Hello, I have upgraded my elk cluster from 7.17 to 8.10, everything is fine but metricbeat seem's unable to insert new data : (status=403): {"type":"security\_exception","reason":"action \[indices:admin/mapping/auto\_put\]…

---

## [I am not able to save actual values in index connector created my new index, values like rule\_id, action\_id etc. How can I do this?](https://discuss.elastic.co/t/i-am-not-able-to-save-actual-values-in-index-connector-created-my-new-index-values-like-rule-id-action-id-etc-how-can-i-do-this/342857)

<div class="topic-metadata">

**Author:** [@jaimika\_kosambia](https://discuss.elastic.co/u/jaimika_kosambia)\
**Replies:** 0\
**Last updated:** [September 12, 2023, 2:50pm UTC](https://discuss.elastic.co/t/i-am-not-able-to-save-actual-values-in-index-connector-created-my-new-index-values-like-rule-id-action-id-etc-how-can-i-do-this/342857 "2023-09-12T14:50:09Z")

</div>

I am not able to save actual values in index connector created my new index, values like rule\_id, action\_id etc. How can I do this ? Please help.

---

## [Calculate the size of logs in a specific time period](https://discuss.elastic.co/t/calculate-the-size-of-logs-in-a-specific-time-period/342845)

<div class="topic-metadata">

**Author:** [@nickmannouch](https://discuss.elastic.co/u/nickmannouch)\
**Replies:** 1\
**Last updated:** [September 12, 2023, 2:47pm UTC](https://discuss.elastic.co/t/calculate-the-size-of-logs-in-a-specific-time-period/342845 "2023-09-12T14:47:05Z")

</div>

Hi, We can see that in a specific 12 hour period, we have 1.3 million log entries. We want to see how much disk space was consumed by this. We thought we could just add 'bytes' as a metric to the graph. However, bytes …

---

## [Backup policy](https://discuss.elastic.co/t/backup-policy/342853)

<div class="topic-metadata">

**Author:** [@sravanth\_cabbu](https://discuss.elastic.co/u/sravanth_cabbu)\
**Replies:** 0\
**Last updated:** [September 12, 2023, 2:39pm UTC](https://discuss.elastic.co/t/backup-policy/342853 "2023-09-12T14:39:34Z")

</div>

Hi Team, We are upgrading RHEL7 to 8 and installed ES. We have NAS mount in place and restored all indices. So in the process of cutover from rhel 7 to 8, we have to add the backup policy to rhel 8 for snapshot. we have…

---

## [Ingest Pipeline Dissect Pattern unable to match Append modifiers](https://discuss.elastic.co/t/ingest-pipeline-dissect-pattern-unable-to-match-append-modifiers/342765)

<div class="topic-metadata">

**Author:** [@paolovalladolid](https://discuss.elastic.co/u/paolovalladolid)\
**Replies:** 4\
**Last updated:** [September 12, 2023, 2:20pm UTC](https://discuss.elastic.co/t/ingest-pipeline-dissect-pattern-unable-to-match-append-modifiers/342765 "2023-09-12T14:20:31Z")

</div>

This is is the dissect pattern %{+dateStr} %(+dateStr) %{logLevel} %{className} %{httpNio} %{+messageContent} %{+messageContent} %{+messageContent} %{} This is a sample line from the document that the dissect is failin…

---

## [Java api bulk opreration](https://discuss.elastic.co/t/java-api-bulk-opreration/342659)

<div class="topic-metadata">

**Author:** [@zgy](https://discuss.elastic.co/u/zgy)\
**Replies:** 2\
**Last updated:** [September 12, 2023, 2:04pm UTC](https://discuss.elastic.co/t/java-api-bulk-opreration/342659 "2023-09-12T14:04:31Z")

</div>

hello,I'm a student , and learning elasticsearch recently. when I use the java bulk api follow the official guides as Bulk: indexing multiple documents | Elasticsearch Java API Client \[8.3\] | Elastic. but it's occured a…

---

## [Reading new data from elastic using logstash to rabbitMQ](https://discuss.elastic.co/t/reading-new-data-from-elastic-using-logstash-to-rabbitmq/342844)

<div class="topic-metadata">

**Author:** [@Shay\_Hershko](https://discuss.elastic.co/u/Shay_Hershko)\
**Replies:** 0\
**Last updated:** [September 12, 2023, 1:51pm UTC](https://discuss.elastic.co/t/reading-new-data-from-elastic-using-logstash-to-rabbitmq/342844 "2023-09-12T13:51:59Z")

</div>

Hi, I want to send every new data entered to index in elastic to a RabbitMQ queue every second. I tried using logstash for it but for some reason it send all the data and not just the new one. I saw you can use time st…

---

## [Update By Query | Alias](https://discuss.elastic.co/t/update-by-query-alias/342834)

<div class="topic-metadata">

**Author:** [@ankitpandoh](https://discuss.elastic.co/u/ankitpandoh)\
**Replies:** 5\
**Last updated:** [September 12, 2023, 1:51pm UTC](https://discuss.elastic.co/t/update-by-query-alias/342834 "2023-09-12T13:51:26Z")

</div>

I am able to add a document to an index say my-main-index having some alias my-alias-index. When I did a search like below, I was able to get the documents. GET /my-main-index/\_search { "query":{ "match\_all": {} …

---

## [Feasibility to send alerts only if consecutive errors are occurred using elastalert](https://discuss.elastic.co/t/feasibility-to-send-alerts-only-if-consecutive-errors-are-occurred-using-elastalert/341485)

<div class="topic-metadata">

**Author:** [@prathameshdvk](https://discuss.elastic.co/u/prathameshdvk)\
**Replies:** 3\
**Last updated:** [September 12, 2023, 1:34pm UTC](https://discuss.elastic.co/t/feasibility-to-send-alerts-only-if-consecutive-errors-are-occurred-using-elastalert/341485 "2023-09-12T13:34:38Z")

</div>

Hi All, I am trying to setup alerting using elastalert and I am trying to achieve below scenarios. scenario 1: Send alert if there are 3 consecutive 400 errors. (Which is working fine) scenario 2: Do not send alert if…

---

## [ElasticSearch v7 docker container not starting on RHEL 8.8](https://discuss.elastic.co/t/elasticsearch-v7-docker-container-not-starting-on-rhel-8-8/341913)

<div class="topic-metadata">

**Author:** [@hakakuma](https://discuss.elastic.co/u/hakakuma)\
**Replies:** 1\
**Last updated:** [September 12, 2023, 1:31pm UTC](https://discuss.elastic.co/t/elasticsearch-v7-docker-container-not-starting-on-rhel-8-8/341913 "2023-09-12T13:31:07Z")

</div>

When we try to run elasticsearch v7.17.0 or v7.17.12, we are facing an error to start the container. It fails with "2023-08-29T12:34:54.499254418+05:30 stderr F chroot: cannot change root directory to '/': Operation not …

---

## [Help me: Unable to parse response body for Bulk Request posted](https://discuss.elastic.co/t/help-me-unable-to-parse-response-body-for-bulk-request-posted/342793)

<div class="topic-metadata">

**Author:** [@adibas](https://discuss.elastic.co/u/adibas)\
**Replies:** 1\
**Last updated:** [September 12, 2023, 1:09pm UTC](https://discuss.elastic.co/t/help-me-unable-to-parse-response-body-for-bulk-request-posted/342793 "2023-09-12T13:09:33Z")

</div>

Error Details: java.io.IOException: Unable to parse response body for Response{requestLine=POST /\_bulk?timeout=1m HTTP/1.1, host=eu-west-1.es.amazonaws.com, response=HTTP/1.1 200 OK} Tried to investigate and I see the …

---

## [Elasticsearch using bundled JDK instead of the one at JAVA\_HOME](https://discuss.elastic.co/t/elasticsearch-using-bundled-jdk-instead-of-the-one-at-java-home/342797)

<div class="topic-metadata">

**Author:** [@martha889](https://discuss.elastic.co/u/martha889)\
**Replies:** 1\
**Last updated:** [September 12, 2023, 1:06pm UTC](https://discuss.elastic.co/t/elasticsearch-using-bundled-jdk-instead-of-the-one-at-java-home/342797 "2023-09-12T13:06:30Z")

</div>

Seeing this error while trying to run elasticsearch on redhat docker container. Any idea why elasticserach is not using the JDK present in JAVA\_HOME or how to fix this error? root@5196a84b088b:/var/lib/avi/logs# JAVA\_HO…

---

## [Input jdbc error handling](https://discuss.elastic.co/t/input-jdbc-error-handling/342836)

<div class="topic-metadata">

**Author:** [@inbeom\_cho](https://discuss.elastic.co/u/inbeom_cho)\
**Replies:** 0\
**Last updated:** [September 12, 2023, 1:03pm UTC](https://discuss.elastic.co/t/input-jdbc-error-handling/342836 "2023-09-12T13:03:16Z")

</div>

hi all this is my input jdbc input { jdbc { jdbc\_driver\_library =\> "/usr/share/java/postgresql.jar" jdbc\_driver\_class =\> "org.postgresql.Driver" jdbc\_connection\_string =\> "jdbc:postgresql://\*.\*.\*.\*/databa…

---

## [Stack monitoring not visible in Kibana UI 8.8.2 version](https://discuss.elastic.co/t/stack-monitoring-not-visible-in-kibana-ui-8-8-2-version/342831)

<div class="topic-metadata">

**Author:** [@PRASHANT\_MEHTA](https://discuss.elastic.co/u/PRASHANT_MEHTA)\
**Replies:** 1\
**Last updated:** [September 12, 2023, 12:31pm UTC](https://discuss.elastic.co/t/stack-monitoring-not-visible-in-kibana-ui-8-8-2-version/342831 "2023-09-12T12:31:55Z")

</div>

Hello All, I am using Enterprise license of kibana and migrated from 7.9.1 to 8.8.2 version. Earlier it used to show STACK MONITORING OPTION in kibana now its not showing in 8.8.2 version. How to enable? , I tried belo…

---

## [After upgrading logstash to version 8.9.1, it disconnects from the DB2 database after a few days](https://discuss.elastic.co/t/after-upgrading-logstash-to-version-8-9-1-it-disconnects-from-the-db2-database-after-a-few-days/342830)

<div class="topic-metadata">

**Author:** [@Lukas\_Hrcka](https://discuss.elastic.co/u/Lukas_Hrcka)\
**Replies:** 0\
**Last updated:** [September 12, 2023, 12:20pm UTC](https://discuss.elastic.co/t/after-upgrading-logstash-to-version-8-9-1-it-disconnects-from-the-db2-database-after-a-few-days/342830 "2023-09-12T12:20:33Z")

</div>

Hello, after upgrading logstash to version 8.9.1 from 7.17.x, I have problems with the automatic loss of connection to the DB2 database (DB2 ver. 11.5 Mod 7). The previous version of ELK 7.17.x had no problem, the conne…

---

## [The metric beat index size is incrasing rapidly.can we remove some of the fields present in the index](https://discuss.elastic.co/t/the-metric-beat-index-size-is-incrasing-rapidly-can-we-remove-some-of-the-fields-present-in-the-index/342804)

<div class="topic-metadata">

**Author:** [@Ambikaguntu](https://discuss.elastic.co/u/Ambikaguntu)\
**Replies:** 1\
**Last updated:** [September 12, 2023, 12:10pm UTC](https://discuss.elastic.co/t/the-metric-beat-index-size-is-incrasing-rapidly-can-we-remove-some-of-the-fields-present-in-the-index/342804 "2023-09-12T12:10:42Z")

</div>

My metricbeat default field brings in too much unnecessary data. Can i remove the fields in the index what I need. I have removed the Metricbeat processor to drop fields in the metricbeat configuaration .Still there are…

---

## [Comparison of data at a kibana dashboard](https://discuss.elastic.co/t/comparison-of-data-at-a-kibana-dashboard/342805)

<div class="topic-metadata">

**Author:** [@Voula\_Mikr](https://discuss.elastic.co/u/Voula_Mikr)\
**Replies:** 1\
**Last updated:** [September 12, 2023, 12:09pm UTC](https://discuss.elastic.co/t/comparison-of-data-at-a-kibana-dashboard/342805 "2023-09-12T12:09:37Z")

</div>

Hi , I have the below kind of data counter1: { "name":"name1", "vnf\_type":"ZTS", "counter":"cpu", "value":"10", "event\_time\_stamp":"2021-02-15T02:44:19Z" } I would like to compare the value "value" of t…

---

## [Kibana Stack Monitoring: Elasticsearch node status offline](https://discuss.elastic.co/t/kibana-stack-monitoring-elasticsearch-node-status-offline/342779)

<div class="topic-metadata">

**Author:** [@phu\_phat](https://discuss.elastic.co/u/phu_phat)\
**Replies:** 3\
**Last updated:** [September 12, 2023, 12:08pm UTC](https://discuss.elastic.co/t/kibana-stack-monitoring-elasticsearch-node-status-offline/342779 "2023-09-12T12:08:47Z")

</div>

After upgrade ELK Stack (ES, Kibana, Metricbeat, Logstash) from 7.17 to 8.9.2 all node in cluster status offline without elasticsearch in same kibana node In index management Before upgrade to 8.9.2 Data insert to .mo…

---

## [Instrumentation of tedious and ioredis is not working when deploying the next.js project in standalone mode](https://discuss.elastic.co/t/instrumentation-of-tedious-and-ioredis-is-not-working-when-deploying-the-next-js-project-in-standalone-mode/342826)

<div class="topic-metadata">

**Author:** [@gsmicky1994](https://discuss.elastic.co/u/gsmicky1994)\
**Replies:** 0\
**Last updated:** [September 12, 2023, 11:33am UTC](https://discuss.elastic.co/t/instrumentation-of-tedious-and-ioredis-is-not-working-when-deploying-the-next-js-project-in-standalone-mode/342826 "2023-09-12T11:33:43Z")

</div>

Kibana version: 8.9.1 Elasticsearch version: 8.9.1 APM Server version: 8.9.1 APM Agent language and version: 3.49.1 (node.js) Original install method (e.g. download page, yum, deb, from source, etc.) and version: np…

---

## [Rolling restart triggers primary-replica resync leading to write unavailability](https://discuss.elastic.co/t/rolling-restart-triggers-primary-replica-resync-leading-to-write-unavailability/339301)

<div class="topic-metadata">

**Author:** [@devoxel](https://discuss.elastic.co/u/devoxel)\
**Replies:** 10\
**Last updated:** [September 12, 2023, 10:54am UTC](https://discuss.elastic.co/t/rolling-restart-triggers-primary-replica-resync-leading-to-write-unavailability/339301 "2023-09-12T10:54:13Z")

</div>

When a node is shutdown during a normal rolling restart, we end up in a loss of write availability for a period of 10 mins. We're using ECK operator to manage the cluster. It's 7.17 and the operator is the latest versio…

---

## [Custom Machine Learning Model on Elastic Security](https://discuss.elastic.co/t/custom-machine-learning-model-on-elastic-security/341862)

<div class="topic-metadata">

**Author:** [@xynobob](https://discuss.elastic.co/u/xynobob)\
**Replies:** 3\
**Last updated:** [September 12, 2023, 10:38am UTC](https://discuss.elastic.co/t/custom-machine-learning-model-on-elastic-security/341862 "2023-09-12T10:38:52Z")

</div>

Hi, I am doing a small side project and this is my first time diving into Elastic Security. Read several documentations, however it doesn't clarify my doubt, so am asking here instead. So my question is - Is it possible…

[Previous page](https://discuss.elastic.co/latest.md?page=542)

[Next page](https://discuss.elastic.co/latest.md?page=544)
