# Latest

**URL:** https://discuss.elastic.co/latest.md?page=553

[Latest](https://discuss.elastic.co/latest.md) · [Categories](https://discuss.elastic.co/categories.md) · [Tags](https://discuss.elastic.co/tags.md)

**Page:** 554

---

## [BUG: panic when packetbeat parsing HTTP host header with non-standard format](https://discuss.elastic.co/t/bug-panic-when-packetbeat-parsing-http-host-header-with-non-standard-format/342258)

<div class="topic-metadata">

**Author:** [@moonD4rk](https://discuss.elastic.co/u/moonD4rk)\
**Replies:** 1\
**Last updated:** [September 4, 2023, 12:09pm UTC](https://discuss.elastic.co/t/bug-panic-when-packetbeat-parsing-http-host-header-with-non-standard-format/342258 "2023-09-04T12:09:24Z")

</div>

Summary: Packetbeat(all version) encounters a panic when parsing HTTP requests that have a non-standard Host header. The issue occurs in the function extractHostHeader and manifests as an "index out of range" panic. Ste…

---

## [General access to .kibana in Elastic 8.7.1](https://discuss.elastic.co/t/general-access-to-kibana-in-elastic-8-7-1/342128)

<div class="topic-metadata">

**Author:** [@Robert\_HARRIS](https://discuss.elastic.co/u/Robert_HARRIS)\
**Replies:** 1\
**Last updated:** [September 4, 2023, 11:59am UTC](https://discuss.elastic.co/t/general-access-to-kibana-in-elastic-8-7-1/342128 "2023-09-04T11:59:53Z")

</div>

Hello, I'm facing some issues related to the changes made regarding the access for users (and logstash) to system index .kibana, and am seeking for the best way to get around it. Basically, I have built a dashboard tha…

---

## [Lag in logs](https://discuss.elastic.co/t/lag-in-logs/342233)

<div class="topic-metadata">

**Author:** [@kriti\_dabas](https://discuss.elastic.co/u/kriti_dabas)\
**Replies:** 2\
**Last updated:** [September 4, 2023, 11:35am UTC](https://discuss.elastic.co/t/lag-in-logs/342233 "2023-09-04T11:35:01Z")

</div>

filter { json { source =\> "message" } grok { match =\> { "message" =\> \[ "%{DATA:description} default %{DATA:connection\_details} : SPCBId %{DATA:spcbId} - ClientIP %{DATA:clientIP} - Client…

---

## [Which index holds the fleet Healthy/Unhealthy status?](https://discuss.elastic.co/t/which-index-holds-the-fleet-healthy-unhealthy-status/341810)

<div class="topic-metadata">

**Author:** [@Blason](https://discuss.elastic.co/u/Blason)\
**Replies:** 3\
**Last updated:** [September 4, 2023, 11:32am UTC](https://discuss.elastic.co/t/which-index-holds-the-fleet-healthy-unhealthy-status/341810 "2023-09-04T11:32:41Z")

</div>

Hi Guys, I need to fetch the data from elasticsearch indices using \_search API and need to know which indices hold the data for fleet and agent status? And how do I run the query using curl to get the Host name and IP …

---

## [Same index pattern but different index template](https://discuss.elastic.co/t/same-index-pattern-but-different-index-template/342018)

<div class="topic-metadata">

**Author:** [@Cruz](https://discuss.elastic.co/u/Cruz)\
**Replies:** 5\
**Last updated:** [September 4, 2023, 11:24am UTC](https://discuss.elastic.co/t/same-index-pattern-but-different-index-template/342018 "2023-09-04T11:24:33Z")

</div>

Good day! I just have a question regarding on Index Template is it possible to create a different index template but same index pattern? What I am going to do is to create a index template but same name on the index p…

---

## [Error while dialing dial unix /var/run/elastic-agent.sock](https://discuss.elastic.co/t/error-while-dialing-dial-unix-var-run-elastic-agent-sock/342249)

<div class="topic-metadata">

**Author:** [@netteans](https://discuss.elastic.co/u/netteans)\
**Replies:** 0\
**Last updated:** [September 4, 2023, 10:56am UTC](https://discuss.elastic.co/t/error-while-dialing-dial-unix-var-run-elastic-agent-sock/342249 "2023-09-04T10:56:40Z")

</div>

I got same errors like https://discuss.elastic.co/t/var-run-elastic-agent-sock-connect-no-such-file-or-directory/335817/2?u=netteans mac@mybookpro Elastic % sudo /Library/Elastic/Agent/elastic-agent status Password: Err…

---

## [Logstash is not getting whole table data](https://discuss.elastic.co/t/logstash-is-not-getting-whole-table-data/341945)

<div class="topic-metadata">

**Author:** [@uma\_parvathy](https://discuss.elastic.co/u/uma_parvathy)\
**Replies:** 2\
**Last updated:** [September 4, 2023, 10:28am UTC](https://discuss.elastic.co/t/logstash-is-not-getting-whole-table-data/341945 "2023-09-04T10:28:42Z")

</div>

Hi All, i've been working on Elasticsearch recently. the logstash pipeline pulls the data only 10k records from the db table. How shall i make it to pull whole table data ? i tried both jdbc\_page\_size and jdbc\_fetch\_s…

---

## [Help, make a selection by the field of the object](https://discuss.elastic.co/t/help-make-a-selection-by-the-field-of-the-object/342245)

<div class="topic-metadata">

**Author:** [@sitnik.ilya.93](https://discuss.elastic.co/u/sitnik.ilya.93)\
**Replies:** 0\
**Last updated:** [September 4, 2023, 10:27am UTC](https://discuss.elastic.co/t/help-make-a-selection-by-the-field-of-the-object/342245 "2023-09-04T10:27:24Z")

</div>

you need to make a selection only by file type, the object was saved simply as Object.class try to choose by, searchResponse = osClient.search(new SearchRequest(eventIndex) .scroll(scroll) …

---

## [Kibana upgrade to 8.9 from 7.17.12 security\_exception reindex](https://discuss.elastic.co/t/kibana-upgrade-to-8-9-from-7-17-12-security-exception-reindex/340284)

<div class="topic-metadata">

**Author:** [@Hywelj](https://discuss.elastic.co/u/Hywelj)\
**Replies:** 3\
**Last updated:** [September 4, 2023, 10:08am UTC](https://discuss.elastic.co/t/kibana-upgrade-to-8-9-from-7-17-12-security-exception-reindex/340284 "2023-09-04T10:08:59Z")

</div>

So I have upgraded my elasticsearch cluster from 7.17.12 to 8.9 and my cluster is now up and running and in a green health state. When I start 8.9 Kibana I get the following error for multiple .kibana\* indices \[INFO \]\[s…

---

## [How it's posiible for query cache to be bigger than total heap?](https://discuss.elastic.co/t/how-its-posiible-for-query-cache-to-be-bigger-than-total-heap/342234)

<div class="topic-metadata">

**Author:** [@lifer](https://discuss.elastic.co/u/lifer)\
**Replies:** 0\
**Last updated:** [September 4, 2023, 9:57am UTC](https://discuss.elastic.co/t/how-its-posiible-for-query-cache-to-be-bigger-than-total-heap/342234 "2023-09-04T09:57:38Z")

</div>

Hello! Our setup: ES 8.8.2, 6 nodes, self-hosted on AWS. I've noticed something strange in our kibana "stack monitoring" metrics for one of data nodes: query cache goes up to 14 GB: but total heap is set to 8GB: …

---

## [Index Lifecycle Policy does not work](https://discuss.elastic.co/t/index-lifecycle-policy-does-not-work/342231)

<div class="topic-metadata">

**Author:** [@JasonREC](https://discuss.elastic.co/u/JasonREC)\
**Replies:** 2\
**Last updated:** [September 4, 2023, 9:52am UTC](https://discuss.elastic.co/t/index-lifecycle-policy-does-not-work/342231 "2023-09-04T09:52:52Z")

</div>

Hi, I am not sure if I understand the Index Lifecycle policy correctly Currently my index's size is over 20GB I have set the rollover to trigger as soon as the shard is greater than 15GB And move the index to de…

---

## [Getting error while trying to create knn index on elasticsearch version 8.7.1](https://discuss.elastic.co/t/getting-error-while-trying-to-create-knn-index-on-elasticsearch-version-8-7-1/342101)

<div class="topic-metadata">

**Author:** [@Sharad\_Nautiyal](https://discuss.elastic.co/u/Sharad_Nautiyal)\
**Replies:** 4\
**Last updated:** [September 4, 2023, 9:27am UTC](https://discuss.elastic.co/t/getting-error-while-trying-to-create-knn-index-on-elasticsearch-version-8-7-1/342101 "2023-09-04T09:27:08Z")

</div>

Below is the request I am sending while creating knn index: PUT posting { "settings": { "index": { "number\_of\_shards" :20, "number\_of\_replicas": 1, "knn":{ "algo\_param":{ "ef\_se…

---

## [Watcher email reports, getting resend while restarting elasticsearch](https://discuss.elastic.co/t/watcher-email-reports-getting-resend-while-restarting-elasticsearch/342230)

<div class="topic-metadata">

**Author:** [@forabraham1](https://discuss.elastic.co/u/forabraham1)\
**Replies:** 0\
**Last updated:** [September 4, 2023, 8:59am UTC](https://discuss.elastic.co/t/watcher-email-reports-getting-resend-while-restarting-elasticsearch/342230 "2023-09-04T08:59:20Z")

</div>

Hi, Email alerts (reports as pdf of a dashboard) setup to trigger once per day early morning which are working fine. But during the day time if the elasticsearch is getting restarted, email reports alerts being resend. …

---

## [Aggregate by concatenate in lens](https://discuss.elastic.co/t/aggregate-by-concatenate-in-lens/341820)

<div class="topic-metadata">

**Author:** [@Jonas\_S](https://discuss.elastic.co/u/Jonas_S)\
**Replies:** 12\
**Last updated:** [September 4, 2023, 8:58am UTC](https://discuss.elastic.co/t/aggregate-by-concatenate-in-lens/341820 "2023-09-04T08:58:40Z")

</div>

Hello, i have Kibana 8.7 and am looking for a way to aggregate multiple documents in a table lens by concatenating a string field. Is this possible? I can only find this functionality in TSVB.

---

## [Dynamic link creation in kibana from config file or backend data and used to display in dashboards](https://discuss.elastic.co/t/dynamic-link-creation-in-kibana-from-config-file-or-backend-data-and-used-to-display-in-dashboards/342229)

<div class="topic-metadata">

**Author:** [@PRASHANT\_MEHTA](https://discuss.elastic.co/u/PRASHANT_MEHTA)\
**Replies:** 0\
**Last updated:** [September 4, 2023, 8:51am UTC](https://discuss.elastic.co/t/dynamic-link-creation-in-kibana-from-config-file-or-backend-data-and-used-to-display-in-dashboards/342229 "2023-09-04T08:51:10Z")

</div>

Hello All, I need to know best possibilities to achive below requirement: I have a HOME dashboard displaying critical alerts per usecases and click on particular link and land to respective dashborads. Now this would…

---

## [Separating pipeline logs issues](https://discuss.elastic.co/t/separating-pipeline-logs-issues/340199)

<div class="topic-metadata">

**Author:** [@Siavash\_Fazli](https://discuss.elastic.co/u/Siavash_Fazli)\
**Replies:** 6\
**Last updated:** [September 4, 2023, 8:46am UTC](https://discuss.elastic.co/t/separating-pipeline-logs-issues/340199 "2023-09-04T08:46:00Z")

</div>

Hi guys. I am running Logstash version 8.8.2 on docker with more than 10 pipelines. I want to separate pipeline logs to separate log files, according to logstash document: document said set path.logs and pipeline.sep…

---

## [Error log curl: (52) Empty reply from server in v8.8.2](https://discuss.elastic.co/t/error-log-curl-52-empty-reply-from-server-in-v8-8-2/338981)

<div class="topic-metadata">

**Author:** [@Ridwan\_Satrio\_Hadiku](https://discuss.elastic.co/u/Ridwan_Satrio_Hadiku)\
**Replies:** 2\
**Last updated:** [September 4, 2023, 8:39am UTC](https://discuss.elastic.co/t/error-log-curl-52-empty-reply-from-server-in-v8-8-2/338981 "2023-09-04T08:39:45Z")

</div>

Hello, can anyone help me? I found error log curl: (52) Empty reply from server when entering command curl -X GET Even though when referring to the problem of: I have followed the instructions and still get the sa…

---

## [Exact KNN queries not cached](https://discuss.elastic.co/t/exact-knn-queries-not-cached/342225)

<div class="topic-metadata">

**Author:** [@Dhineshkumar\_R](https://discuss.elastic.co/u/Dhineshkumar_R)\
**Replies:** 0\
**Last updated:** [September 4, 2023, 7:28am UTC](https://discuss.elastic.co/t/exact-knn-queries-not-cached/342225 "2023-09-04T07:28:34Z")

</div>

Hi Folks, I have a cluster with vectors indexed in a knn index and I'd like to find exact K-nearest neighbors for a given vector using score\_script. There are about 500K documents in total. I'm using the following quer…

---

## [DSL : Format avg result](https://discuss.elastic.co/t/dsl-format-avg-result/341692)

<div class="topic-metadata">

**Author:** [@RickT](https://discuss.elastic.co/u/RickT)\
**Replies:** 1\
**Last updated:** [September 4, 2023, 7:53am UTC](https://discuss.elastic.co/t/dsl-format-avg-result/341692 "2023-09-04T07:53:51Z")

</div>

Hi, I'm using a DSL script to extract some datas. I use an aggregation with an average method. It's ok, but the end result does not suit me :confused: Indeed, the result format is like this 5133.076923076923 and I wou…

---

## [Elasticsearch resource calculation](https://discuss.elastic.co/t/elasticsearch-resource-calculation/341887)

<div class="topic-metadata">

**Author:** [@Ibrahim\_Can\_Duran](https://discuss.elastic.co/u/Ibrahim_Can_Duran)\
**Replies:** 5\
**Last updated:** [September 4, 2023, 7:40am UTC](https://discuss.elastic.co/t/elasticsearch-resource-calculation/341887 "2023-09-04T07:40:02Z")

</div>

I am trying to calculate the Resource requirements for an ELK system which will be deployed on k8s. The total load will be 4 TB and i will use 1 replica. Is it possible to have equations for required number of shard and…

---

## [Kibana Vega Calendar](https://discuss.elastic.co/t/kibana-vega-calendar/342223)

<div class="topic-metadata">

**Author:** [@vardhan](https://discuss.elastic.co/u/vardhan)\
**Replies:** 0\
**Last updated:** [September 4, 2023, 7:18am UTC](https://discuss.elastic.co/t/kibana-vega-calendar/342223 "2023-09-04T07:18:55Z")

</div>

hii team , we are trying to create a calendar visualization which compares the total sum value of yesterday's order value and today's order value and show case the difference in percentage. we are able to create visua…

---

## [Allocation Failed](https://discuss.elastic.co/t/allocation-failed/342167)

<div class="topic-metadata">

**Author:** [@njain213](https://discuss.elastic.co/u/njain213)\
**Replies:** 4\
**Last updated:** [September 4, 2023, 6:09am UTC](https://discuss.elastic.co/t/allocation-failed/342167 "2023-09-04T06:09:30Z")

</div>

Hello Team, One of my index is showing below error. I have created new shard where new data is going now but how to assign old index back to node. "unassigned\_info" : { "reason" : "ALLOCATION\_FAILED", "at" : "2023-09…

---

## [Filebeat setup for cakephp logs](https://discuss.elastic.co/t/filebeat-setup-for-cakephp-logs/339620)

<div class="topic-metadata">

**Author:** [@sanjeev1895](https://discuss.elastic.co/u/sanjeev1895)\
**Replies:** 35\
**Last updated:** [September 4, 2023, 6:00am UTC](https://discuss.elastic.co/t/filebeat-setup-for-cakephp-logs/339620 "2023-09-04T06:00:58Z")

</div>

Hi, Can anyone advice how to configure the filebeat and logstash for cakephp logs. I need to configure filebeat for following cakephp logs, cake.log error.log Is do I need to enable any module in filebeat? Please c…

---

## [Training Progression](https://discuss.elastic.co/t/training-progression/342217)

<div class="topic-metadata">

**Author:** [@HHaynie](https://discuss.elastic.co/u/HHaynie)\
**Replies:** 0\
**Last updated:** [September 4, 2023, 5:58am UTC](https://discuss.elastic.co/t/training-progression/342217 "2023-09-04T05:58:04Z")

</div>

Course: \<Which course are you asking about?\> Data Analysis with Kibana (On-Demand)(https://learn.elastic.co/#) Version: \<And which particular version?\> N/A Question: I have been going round and round with this training…

---

## [Grouping metrics by env](https://discuss.elastic.co/t/grouping-metrics-by-env/342211)

<div class="topic-metadata">

**Author:** [@Supun\_Madushanka](https://discuss.elastic.co/u/Supun_Madushanka)\
**Replies:** 0\
**Last updated:** [September 4, 2023, 5:09am UTC](https://discuss.elastic.co/t/grouping-metrics-by-env/342211 "2023-09-04T05:09:05Z")

</div>

metricbeat.config.modules: path: ${path.config}/modules.d/\*.yml reload.period: 10s reload.enabled: true metricbeat.max\_start\_delay: 10s setup.dashboards.enabled: true metricbeat.…

---

## [Elastic agent shows \`Input not supported error\` when configuring Fleet managed APM integration](https://discuss.elastic.co/t/elastic-agent-shows-input-not-supported-error-when-configuring-fleet-managed-apm-integration/342025)

<div class="topic-metadata">

**Author:** [@Ong\_Yi\_Chong](https://discuss.elastic.co/u/Ong_Yi_Chong)\
**Replies:** 1\
**Last updated:** [September 4, 2023, 4:39am UTC](https://discuss.elastic.co/t/elastic-agent-shows-input-not-supported-error-when-configuring-fleet-managed-apm-integration/342025 "2023-09-04T04:39:20Z")

</div>

Kibana version: 8.9.1 Elasticsearch version: 8.9.1 APM Server version: 8.9.1 I am trying to configure the apm server via \[Fleet-managed APM Server | APM User Guide \[8.9\] | Elastic\](Fleet managed APM). However, when a…

---

## [Setting up Alerting in Kibana](https://discuss.elastic.co/t/setting-up-alerting-in-kibana/342009)

<div class="topic-metadata">

**Author:** [@queencass](https://discuss.elastic.co/u/queencass)\
**Replies:** 2\
**Last updated:** [September 4, 2023, 2:00am UTC](https://discuss.elastic.co/t/setting-up-alerting-in-kibana/342009 "2023-09-04T02:00:52Z")

</div>

Hi there! I am new to Elastic and trying to figure things out, so I hope you could help me out. I have setup Elasticsearch and Kibana and wanted to setup alerting feature in Kibana as well. I have uploaded sets of data t…

---

## [Filebeat sends malformed logs](https://discuss.elastic.co/t/filebeat-sends-malformed-logs/342078)

<div class="topic-metadata">

**Author:** [@MheniMerz](https://discuss.elastic.co/u/MheniMerz)\
**Replies:** 6\
**Last updated:** [September 3, 2023, 9:59pm UTC](https://discuss.elastic.co/t/filebeat-sends-malformed-logs/342078 "2023-09-03T21:59:07Z")

</div>

Hi, i'm using filebeat to receive logs from a Juniper firewall and forward them to logstash which then sends them to elasticsearch. i configured my juniper firewall to use the required log format structured-data + brie…

---

## ["node is locked into cluster" message](https://discuss.elastic.co/t/node-is-locked-into-cluster-message/342200)

<div class="topic-metadata">

**Author:** [@lifer](https://discuss.elastic.co/u/lifer)\
**Replies:** 1\
**Last updated:** [September 3, 2023, 6:41pm UTC](https://discuss.elastic.co/t/node-is-locked-into-cluster-message/342200 "2023-09-03T18:41:38Z")

</div>

Hi! We have a 6 nodes ES cluster, self-hosted on AWS. There are three dedicated master nodes, and three data nodes. Please help me to understand this message: \[2023-09-03T08:32:18,239\]\[WARN \]\[o.e.c.c.ClusterBootstrapS…

---

## [Elasticsearch remote cluster reindexing wildcard](https://discuss.elastic.co/t/elasticsearch-remote-cluster-reindexing-wildcard/342168)

<div class="topic-metadata">

**Author:** [@ANUBHAV\_GUPTA](https://discuss.elastic.co/u/ANUBHAV_GUPTA)\
**Replies:** 2\
**Last updated:** [September 3, 2023, 4:08pm UTC](https://discuss.elastic.co/t/elasticsearch-remote-cluster-reindexing-wildcard/342168 "2023-09-03T16:08:57Z")

</div>

Hi there, I am trying to use -e reindex.remote.whitelist="\*" in my docker run command to allow all domains in whitelist. But I am getting the following error when I try to run this:- Exception in thread "main" org.el…

[Previous page](https://discuss.elastic.co/latest.md?page=552)

[Next page](https://discuss.elastic.co/latest.md?page=554)
