# Latest

**URL:** https://discuss.elastic.co/latest.md?page=550

[Latest](https://discuss.elastic.co/latest.md) · [Categories](https://discuss.elastic.co/categories.md) · [Tags](https://discuss.elastic.co/tags.md)

**Page:** 551

---

## [Kibana won't open on web - This site can’t be reached, kibana.pci.local took too long to respond](https://discuss.elastic.co/t/kibana-wont-open-on-web-this-site-can-t-be-reached-kibana-pci-local-took-too-long-to-respond/342408)

<div class="topic-metadata">

**Author:** [@daniela09](https://discuss.elastic.co/u/daniela09)\
**Replies:** 0\
**Last updated:** [September 6, 2023, 8:51am UTC](https://discuss.elastic.co/t/kibana-wont-open-on-web-this-site-can-t-be-reached-kibana-pci-local-took-too-long-to-respond/342408 "2023-09-06T08:51:17Z")

</div>

Hi, I have EFK stack on Kubernetes in production and everything was working fine until this morning, now Kibana won't open on web and there weren't any errors in the logs. After I restarted Kibana this is in the logs: \[…

---

## [Filebeat not sending suricata logs to elasticsearch](https://discuss.elastic.co/t/filebeat-not-sending-suricata-logs-to-elasticsearch/342399)

<div class="topic-metadata">

**Author:** [@Dhruv\_Kumar](https://discuss.elastic.co/u/Dhruv_Kumar)\
**Replies:** 3\
**Last updated:** [September 6, 2023, 8:44am UTC](https://discuss.elastic.co/t/filebeat-not-sending-suricata-logs-to-elasticsearch/342399 "2023-09-06T08:44:51Z")

</div>

Hello . I have a server in which i am running suricata . In the same server I have installed filebeat which i am using to send my suricata logs to Elasticsearch .I have setup es and kibana inside a vm .After starting eve…

---

## [How to Select only Last Day Filters in LENS](https://discuss.elastic.co/t/how-to-select-only-last-day-filters-in-lens/341436)

<div class="topic-metadata">

**Author:** [@Arshukla](https://discuss.elastic.co/u/Arshukla)\
**Replies:** 2\
**Last updated:** [September 6, 2023, 8:19am UTC](https://discuss.elastic.co/t/how-to-select-only-last-day-filters-in-lens/341436 "2023-09-06T08:19:24Z")

</div>

Hello Team @Marco\_Liberati When I apply the parameter "reducedTimeRange='1d'" to select values for a variable, it's currently retrieving data from the last 24 hours instead of the specific time range I want, which is fr…

---

## [Empty row in Security Alerts table](https://discuss.elastic.co/t/empty-row-in-security-alerts-table/342407)

<div class="topic-metadata">

**Author:** [@francesco.amato](https://discuss.elastic.co/u/francesco.amato)\
**Replies:** 0\
**Last updated:** [September 6, 2023, 8:17am UTC](https://discuss.elastic.co/t/empty-row-in-security-alerts-table/342407 "2023-09-06T08:17:23Z")

</div>

Hi to all I have a strange problem with the Security Alerts page I have empty rows in the bottom table, only in one page. If I change page, I see my records. I don't know if it is a problem in my Elastic instance or …

---

## [I want to monitor .net app both with apm and grafana can i use both at same with opentelemetry and report to both?](https://discuss.elastic.co/t/i-want-to-monitor-net-app-both-with-apm-and-grafana-can-i-use-both-at-same-with-opentelemetry-and-report-to-both/342382)

<div class="topic-metadata">

**Author:** [@agonzalez](https://discuss.elastic.co/u/agonzalez)\
**Replies:** 1\
**Last updated:** [September 6, 2023, 7:56am UTC](https://discuss.elastic.co/t/i-want-to-monitor-net-app-both-with-apm-and-grafana-can-i-use-both-at-same-with-opentelemetry-and-report-to-both/342382 "2023-09-06T07:56:37Z")

</div>

or there is any incompatibility? what is preferred way for APM use apm .net agent or opentelemetry? any difference in metrics that are collected?

---

## [Filebeat how to delete indexes automaticality after a few days](https://discuss.elastic.co/t/filebeat-how-to-delete-indexes-automaticality-after-a-few-days/342308)

<div class="topic-metadata">

**Author:** [@R1d3rBG](https://discuss.elastic.co/u/R1d3rBG)\
**Replies:** 3\
**Last updated:** [September 6, 2023, 7:47am UTC](https://discuss.elastic.co/t/filebeat-how-to-delete-indexes-automaticality-after-a-few-days/342308 "2023-09-06T07:47:51Z")

</div>

Hello I have installed ELK and I would like to optimise it a little bit. CentOS Linux release 7.9.2009 (Core) bin/kibana --version 8.6.2 bin/elasticsearch --version Version: 8.6.2, Build: I'm using filebeat and aft…

---

## [ES server specs for a good search performance](https://discuss.elastic.co/t/es-server-specs-for-a-good-search-performance/342355)

<div class="topic-metadata">

**Author:** [@Don\_Boscow](https://discuss.elastic.co/u/Don_Boscow)\
**Replies:** 3\
**Last updated:** [September 6, 2023, 7:39am UTC](https://discuss.elastic.co/t/es-server-specs-for-a-good-search-performance/342355 "2023-09-06T07:39:43Z")

</div>

So we have a situation where we want to make a mini-search engine for our project - the total volume of the data being 5 PB. We want to create a backup, so the total size to be needed overall is 10 PB, approximately. The…

---

## [Elastic agent Failed Connect Failed to connect to backoff 401 Unauthorized](https://discuss.elastic.co/t/elastic-agent-failed-connect-failed-to-connect-to-backoff-401-unauthorized/342395)

<div class="topic-metadata">

**Author:** [@Khunakorn](https://discuss.elastic.co/u/Khunakorn)\
**Replies:** 0\
**Last updated:** [September 6, 2023, 6:33am UTC](https://discuss.elastic.co/t/elastic-agent-failed-connect-failed-to-connect-to-backoff-401-unauthorized/342395 "2023-09-06T06:33:06Z")

</div>

{"log.level":"error","@timestamp":"2023-09-06T04:35:47.597Z","message":"Failed to connect to backoff(elasticsearch(cloud.com:443)): 401 Unauthorized: {"error":{"root\_cause":\[{"type":"security\_exception","reason":"unable …

---

## [Not all fields are indexed](https://discuss.elastic.co/t/not-all-fields-are-indexed/342369)

<div class="topic-metadata">

**Author:** [@Jim\_Song](https://discuss.elastic.co/u/Jim_Song)\
**Replies:** 2\
**Last updated:** [September 6, 2023, 5:34am UTC](https://discuss.elastic.co/t/not-all-fields-are-indexed/342369 "2023-09-06T05:34:19Z")

</div>

I indexed several raw json documents using BulkRequest index BinaryData from json string. If I run a match all query, I am getting back all my documents. However only certain fields are searchable. Why aren't all field…

---

## [Filebeat to analyze xml logs](https://discuss.elastic.co/t/filebeat-to-analyze-xml-logs/342305)

<div class="topic-metadata">

**Author:** [@Ted0011](https://discuss.elastic.co/u/Ted0011)\
**Replies:** 8\
**Last updated:** [September 6, 2023, 3:53am UTC](https://discuss.elastic.co/t/filebeat-to-analyze-xml-logs/342305 "2023-09-06T03:53:56Z")

</div>

Hello Its Suman Ghorashine I am new to wazuh and ELK stack. And I wanted to know some certain things. I have a xml log format set to wazuh server for analysis from agent configuration file. But when filtering the logs …

---

## [Does Elastic Agent support Docker label based autodiscovery?](https://discuss.elastic.co/t/does-elastic-agent-support-docker-label-based-autodiscovery/342383)

<div class="topic-metadata">

**Author:** [@jerrac](https://discuss.elastic.co/u/jerrac)\
**Replies:** 0\
**Last updated:** [September 5, 2023, 11:13pm UTC](https://discuss.elastic.co/t/does-elastic-agent-support-docker-label-based-autodiscovery/342383 "2023-09-05T23:13:24Z")

</div>

While experimenting with using Metricbeat and Filebeat directly, I found the documentation on hint based auto-discovery that would send the docker logs and metrics through the correct pipelines for different modules. Lik…

---

## [Advanced Watch](https://discuss.elastic.co/t/advanced-watch/338906)

<div class="topic-metadata">

**Author:** [@Kumar\_Abhinav](https://discuss.elastic.co/u/Kumar_Abhinav)\
**Replies:** 7\
**Last updated:** [September 5, 2023, 9:30pm UTC](https://discuss.elastic.co/t/advanced-watch/338906 "2023-09-05T21:30:01Z")

</div>

Hi, I am using ELK in Supply Chain Traceability Company. 1 -- I wanted to create a Watcher to send "Alerts" from Kibana for the inventory items and it should be continuous alerts through email notification. Suppose a…

---

## [Block java.exe outbound in firewall](https://discuss.elastic.co/t/block-java-exe-outbound-in-firewall/342374)

<div class="topic-metadata">

**Author:** [@jonnyo](https://discuss.elastic.co/u/jonnyo)\
**Replies:** 0\
**Last updated:** [September 5, 2023, 7:55pm UTC](https://discuss.elastic.co/t/block-java-exe-outbound-in-firewall/342374 "2023-09-05T19:55:19Z")

</div>

Hi. I have an Elastic cluster with 4 nodes, all on Windows Server. We are using Windows Defender Firewall to limit access to ports 9200 and 9300 between the nodes. We have now been asked if we can limit the OpenJDK java.…

---

## [ElasticSearch TASKS API - Task is given to a different client node after 1 minute of execution](https://discuss.elastic.co/t/elasticsearch-tasks-api-task-is-given-to-a-different-client-node-after-1-minute-of-execution/340801)

<div class="topic-metadata">

**Author:** [@es2learn](https://discuss.elastic.co/u/es2learn)\
**Replies:** 2\
**Last updated:** [September 5, 2023, 7:41pm UTC](https://discuss.elastic.co/t/elasticsearch-tasks-api-task-is-given-to-a-different-client-node-after-1-minute-of-execution/340801 "2023-09-05T19:41:43Z")

</div>

Hi Team, I had a weird observation in our Elasticsearch Cluster. We have an ES Query that will be executed from a python script. When the Query is being fired from python, right away a task will get created under GET /…

---

## [Services error](https://discuss.elastic.co/t/services-error/342372)

<div class="topic-metadata">

**Author:** [@Waseem.M](https://discuss.elastic.co/u/Waseem.M)\
**Replies:** 0\
**Last updated:** [September 5, 2023, 7:41pm UTC](https://discuss.elastic.co/t/services-error/342372 "2023-09-05T19:41:08Z")

</div>

When I try to start the winlogbeat service on windows server 2012 and 2016 : throwing the error : Windows could not start the winlogbeat service on local computer. Error 1067 : The process Terminated unexpectedly. Plea…

---

## [Cisco filebeat module not listening on port as configured](https://discuss.elastic.co/t/cisco-filebeat-module-not-listening-on-port-as-configured/341988)

<div class="topic-metadata">

**Author:** [@artschooldropout](https://discuss.elastic.co/u/artschooldropout)\
**Replies:** 18\
**Last updated:** [September 5, 2023, 7:26pm UTC](https://discuss.elastic.co/t/cisco-filebeat-module-not-listening-on-port-as-configured/341988 "2023-09-05T19:26:40Z")

</div>

We have an existing functional Elastic instance running with Filebeat 8.9, running on Ubuntu 22.04. We're attempting to add Cisco logs using the Cisco filebeat module. However, we're not seeing any logs coming in. We hav…

---

## [Windows server 2012 and 2008](https://discuss.elastic.co/t/windows-server-2012-and-2008/342371)

<div class="topic-metadata">

**Author:** [@Waseem.M](https://discuss.elastic.co/u/Waseem.M)\
**Replies:** 1\
**Last updated:** [September 5, 2023, 7:11pm UTC](https://discuss.elastic.co/t/windows-server-2012-and-2008/342371 "2023-09-05T19:11:21Z")

</div>

Hi Everyone, Recently start working on Kibana. I have created the dashboard and working on windows server 2008 and 2012 looking for advice. which file do I need to install winlogbeat is there any compatible version of w…

---

## [Difficulty Making a REST API Call to ElasticSearch](https://discuss.elastic.co/t/difficulty-making-a-rest-api-call-to-elasticsearch/342296)

<div class="topic-metadata">

**Author:** [@Conrad414](https://discuss.elastic.co/u/Conrad414)\
**Replies:** 3\
**Last updated:** [September 5, 2023, 6:51pm UTC](https://discuss.elastic.co/t/difficulty-making-a-rest-api-call-to-elasticsearch/342296 "2023-09-05T18:51:14Z")

</div>

Hello, I'm currently trying to follow the steps for installing Elasticsearch with Docker Install Elasticsearch with Docker | Elasticsearch Guide \[8.11\] | Elastic and I'm struggling with making a REST API call to Elastics…

---

## [Stored fields and SearchResponse](https://discuss.elastic.co/t/stored-fields-and-searchresponse/342062)

<div class="topic-metadata">

**Author:** [@toddcarv](https://discuss.elastic.co/u/toddcarv)\
**Replies:** 7\
**Last updated:** [September 5, 2023, 7:00pm UTC](https://discuss.elastic.co/t/stored-fields-and-searchresponse/342062 "2023-09-05T19:00:34Z")

</div>

Example: SearchResponse\<ObjectNode\> searchResponse = elasticsearchClient.search(searchRequest, ObjectNode.class); Hit\<ObjectNode\> hit = searchResponse.hits().hits().get(0); Map\<String, JsonData\> fields = hit.fields(); J…

---

## [Can't set a replication factor for some hidden indices](https://discuss.elastic.co/t/cant-set-a-replication-factor-for-some-hidden-indices/341839)

<div class="topic-metadata">

**Author:** [@Vadym](https://discuss.elastic.co/u/Vadym)\
**Replies:** 4\
**Last updated:** [September 5, 2023, 6:26pm UTC](https://discuss.elastic.co/t/cant-set-a-replication-factor-for-some-hidden-indices/341839 "2023-09-05T18:26:52Z")

</div>

Hi, I can't seem to change a replication factor for some hidden indices: i.e. curl -X PUT "x.x.x.x:9200/.\*/\_settings" -H 'Content-Type: application/json' -d'{ "index" : { "number\_of\_replicas" : 2 } }' {"acknowledged":…

---

## [I don't understand why my bill is more than the cents per hour stated on the dashboard](https://discuss.elastic.co/t/i-dont-understand-why-my-bill-is-more-than-the-cents-per-hour-stated-on-the-dashboard/342079)

<div class="topic-metadata">

**Author:** [@tonyfam](https://discuss.elastic.co/u/tonyfam)\
**Replies:** 5\
**Last updated:** [September 5, 2023, 6:05pm UTC](https://discuss.elastic.co/t/i-dont-understand-why-my-bill-is-more-than-the-cents-per-hour-stated-on-the-dashboard/342079 "2023-09-05T18:05:29Z")

</div>

Hello, can someone please help me understand our bill? Budget crunch. On the dashboard, it says our one deployment is supposed to cost .0957 cents per hour. We have 2 x 45 GB. Enterprise search and Kibana is suppose…

---

## [Logstash SSL/TLS error](https://discuss.elastic.co/t/logstash-ssl-tls-error/342368)

<div class="topic-metadata">

**Author:** [@Kvoyce2023](https://discuss.elastic.co/u/Kvoyce2023)\
**Replies:** 0\
**Last updated:** [September 5, 2023, 5:56pm UTC](https://discuss.elastic.co/t/logstash-ssl-tls-error/342368 "2023-09-05T17:56:55Z")

</div>

My ELK stack got 3 ES nodes and 2 logstash nodes. Kibana is installed on one of the Logstash nodes. I was able to generate CA and all certificates. Distributed the certificates to all nodes.Confirmed Elasticsearch nodes …

---

## [Fleet not showing latest version of Elastic Agent](https://discuss.elastic.co/t/fleet-not-showing-latest-version-of-elastic-agent/342367)

<div class="topic-metadata">

**Author:** [@JP\_1987](https://discuss.elastic.co/u/JP_1987)\
**Replies:** 0\
**Last updated:** [September 5, 2023, 5:50pm UTC](https://discuss.elastic.co/t/fleet-not-showing-latest-version-of-elastic-agent/342367 "2023-09-05T17:50:50Z")

</div>

Have setup a fleet server with several agents. My fleet server is running agent 8.91, but version of Elastic agent is only allowing updates to version 8.8.2 Is this an automatic update when a new version is released th…

---

## [Doubts about any field of wildcard](https://discuss.elastic.co/t/doubts-about-any-field-of-wildcard/342365)

<div class="topic-metadata">

**Author:** [@caixukun](https://discuss.elastic.co/u/caixukun)\
**Replies:** 0\
**Last updated:** [September 5, 2023, 5:21pm UTC](https://discuss.elastic.co/t/doubts-about-any-field-of-wildcard/342365 "2023-09-05T17:21:34Z")

</div>

hello everyone I currently have a problem. I want to search exactly for field a and match the search for field b. this is my code GET /\_search { "query": { "bool": { "must": \[ { "multi\_match": { "q…

---

## [Extract specific log set from others indexed togheter](https://discuss.elastic.co/t/extract-specific-log-set-from-others-indexed-togheter/341262)

<div class="topic-metadata">

**Author:** [@necromancer](https://discuss.elastic.co/u/necromancer)\
**Replies:** 1\
**Last updated:** [September 5, 2023, 4:33pm UTC](https://discuss.elastic.co/t/extract-specific-log-set-from-others-indexed-togheter/341262 "2023-09-05T16:33:44Z")

</div>

I want to know ihow can I extract/separate my nginx logs from an index where they are saved along with systemd logs and others (cron, fail2ban, etc)? I have it indexed with the ident "nginx". My point with it is be abl…

---

## [Aggregation with max field value](https://discuss.elastic.co/t/aggregation-with-max-field-value/341723)

<div class="topic-metadata">

**Author:** [@Mauricio\_Castrillon](https://discuss.elastic.co/u/Mauricio_Castrillon)\
**Replies:** 2\
**Last updated:** [September 5, 2023, 4:24pm UTC](https://discuss.elastic.co/t/aggregation-with-max-field-value/341723 "2023-09-05T16:24:57Z")

</div>

Hello, I'm trying to create a metric in Kibana for a dashboard with some information from servers. The main idea is to have the total amount of objects by location. The challenge is, in each location, I have a certain …

---

## [Sort results by inner hits (min/max)](https://discuss.elastic.co/t/sort-results-by-inner-hits-min-max/342359)

<div class="topic-metadata">

**Author:** [@LeoAdamek](https://discuss.elastic.co/u/LeoAdamek)\
**Replies:** 0\
**Last updated:** [September 5, 2023, 4:11pm UTC](https://discuss.elastic.co/t/sort-results-by-inner-hits-min-max/342359 "2023-09-05T16:11:18Z")

</div>

I'm using a join field and an has\_child filter in my search to join products with their various configuration permutations. There's a single level join from a product to a configuration. When a user searches for somethi…

---

## [Filebeat threshold set](https://discuss.elastic.co/t/filebeat-threshold-set/342356)

<div class="topic-metadata">

**Author:** [@anupvtr](https://discuss.elastic.co/u/anupvtr)\
**Replies:** 0\
**Last updated:** [September 5, 2023, 4:02pm UTC](https://discuss.elastic.co/t/filebeat-threshold-set/342356 "2023-09-05T16:02:41Z")

</div>

Thanks in advance, Is there any possibility to implement the below requirement. We are using filebeat agent to forward data to logstash. To avoid log burst, is there a way to set a threshold limit on the amount of log…

---

## [Import trained model to ElastichSearch](https://discuss.elastic.co/t/import-trained-model-to-elastichsearch/342197)

<div class="topic-metadata">

**Author:** [@Khanh\_Dao\_Minh](https://discuss.elastic.co/u/Khanh_Dao_Minh)\
**Replies:** 2\
**Last updated:** [September 5, 2023, 3:43pm UTC](https://discuss.elastic.co/t/import-trained-model-to-elastichsearch/342197 "2023-09-05T15:43:23Z")

</div>

hello everyone. I have a question about importing my model to Elasticsearch. When i imported the model for task text embedding and started deployment mode on Kibana web, i got an error message " Couldn't start trained …

---

## [Is rrf available in the free, self-hosted version of elastic search?](https://discuss.elastic.co/t/is-rrf-available-in-the-free-self-hosted-version-of-elastic-search/342354)

<div class="topic-metadata">

**Author:** [@panivan99pl](https://discuss.elastic.co/u/panivan99pl)\
**Replies:** 1\
**Last updated:** [September 5, 2023, 3:39pm UTC](https://discuss.elastic.co/t/is-rrf-available-in-the-free-self-hosted-version-of-elastic-search/342354 "2023-09-05T15:39:40Z")

</div>

I am using Elasticsearch as self-hosted in docker container, 8.9.1. When I query with the parameter rrf Reciprocal rank fusion, I get this message elasticsearch.AuthorizationException: AuthorizationException(403, 'secur…

[Previous page](https://discuss.elastic.co/latest.md?page=549)

[Next page](https://discuss.elastic.co/latest.md?page=551)
