# Latest

**URL:** https://discuss.elastic.co/latest.md?page=563

[Latest](https://discuss.elastic.co/latest.md) · [Categories](https://discuss.elastic.co/categories.md) · [Tags](https://discuss.elastic.co/tags.md)

**Page:** 564

---

## [Missing child spans on OpenTelemetry traces](https://discuss.elastic.co/t/missing-child-spans-on-opentelemetry-traces/340390)

<div class="topic-metadata">

**Author:** [@Sebastien\_Dan](https://discuss.elastic.co/u/Sebastien_Dan)\
**Replies:** 4\
**Last updated:** [August 24, 2023, 7:17am UTC](https://discuss.elastic.co/t/missing-child-spans-on-opentelemetry-traces/340390 "2023-08-24T07:17:58Z")

</div>

Kibana version: 8.9.0 Elasticsearch version: 8.9.0 Original install method (e.g. download page, yum, deb, from source, etc.) and version: Elastic Cloud, no APM agent Description of the problem including expected versu…

---

## [Columns exported from Tabular CSV are reshuffled](https://discuss.elastic.co/t/columns-exported-from-tabular-csv-are-reshuffled/340921)

<div class="topic-metadata">

**Author:** [@Arshukla](https://discuss.elastic.co/u/Arshukla)\
**Replies:** 10\
**Last updated:** [August 24, 2023, 7:05am UTC](https://discuss.elastic.co/t/columns-exported-from-tabular-csv-are-reshuffled/340921 "2023-08-24T07:05:37Z")

</div>

Hello Team, Columns are getting reshuflled when exported to CSV format When exported in CSV, columns are getting shifted Please can you help me for how to resolve this one

---

## [Multiple fleet entries cleanup](https://discuss.elastic.co/t/multiple-fleet-entries-cleanup/341141)

<div class="topic-metadata">

**Author:** [@GKre](https://discuss.elastic.co/u/GKre)\
**Replies:** 12\
**Last updated:** [August 24, 2023, 6:28am UTC](https://discuss.elastic.co/t/multiple-fleet-entries-cleanup/341141 "2023-08-24T06:28:24Z")

</div>

Hello, in my fleet management there's 3 entries for the agent on one machine. Two of them are obsolete. I wonder what is happening if i uninstall with the one fleet server i need for management? Is it somehow possible…

---

## [Random function in Painless?](https://discuss.elastic.co/t/random-function-in-painless/70280)

<div class="topic-metadata">

**Author:** [@Dom-nik](https://discuss.elastic.co/u/Dom-nik)\
**Replies:** 3\
**Last updated:** [August 24, 2023, 6:25am UTC](https://discuss.elastic.co/t/random-function-in-painless/70280 "2023-08-24T06:25:09Z")

</div>

Hello, What is the way to genereate a random value in Painless? Being able to draw one value from a set would be particularly great - I want to use it to add a new field to my mock data and I need a possibility to add…

---

## [How can I store the average of CPU,Memory,Disk data of one day in some logs](https://discuss.elastic.co/t/how-can-i-store-the-average-of-cpu-memory-disk-data-of-one-day-in-some-logs/340112)

<div class="topic-metadata">

**Author:** [@AkshayP21296](https://discuss.elastic.co/u/AkshayP21296)\
**Replies:** 4\
**Last updated:** [August 24, 2023, 6:04am UTC](https://discuss.elastic.co/t/how-can-i-store-the-average-of-cpu-memory-disk-data-of-one-day-in-some-logs/340112 "2023-08-24T06:04:25Z")

</div>

Hello Sir, I am using metricbeat for infra monitoring but as it is consuming so much data do we have the option to store the average of a complete day in only few logs .

---

## [ElasticSearch Service Startup Issue](https://discuss.elastic.co/t/elasticsearch-service-startup-issue/341532)

<div class="topic-metadata">

**Author:** [@Jeevagan](https://discuss.elastic.co/u/Jeevagan)\
**Replies:** 0\
**Last updated:** [August 24, 2023, 4:40am UTC](https://discuss.elastic.co/t/elasticsearch-service-startup-issue/341532 "2023-08-24T04:40:06Z")

</div>

Hey everyone, I hope you're doing well. I've been working on setting up an Elasticsearch service using a systemd service file, but I'm encountering an issue when trying to start the application. I'm hoping someone here …

---

## [Logstash-7.17.12 file input not working](https://discuss.elastic.co/t/logstash-7-17-12-file-input-not-working/341527)

<div class="topic-metadata">

**Author:** [@Jongwook\_Seong](https://discuss.elastic.co/u/Jongwook_Seong)\
**Replies:** 2\
**Last updated:** [August 24, 2023, 4:44am UTC](https://discuss.elastic.co/t/logstash-7-17-12-file-input-not-working/341527 "2023-08-24T04:44:44Z")

</div>

I am using logstash-7.17.12 to input the contents of logstash-test.conf file. The contents of logstash-test.conf are as follows. input { file { path =\> "C:/Users/user/logstash-7.17.12/config/filter-example.log" …

---

## [Elastic Agent Unhealthy - 504 Gateway Timeout - net/hxxp: TLS handshake timeout](https://discuss.elastic.co/t/elastic-agent-unhealthy-504-gateway-timeout-net-hxxp-tls-handshake-timeout/341325)

<div class="topic-metadata">

**Author:** [@Shinej](https://discuss.elastic.co/u/Shinej)\
**Replies:** 2\
**Last updated:** [August 24, 2023, 4:23am UTC](https://discuss.elastic.co/t/elastic-agent-unhealthy-504-gateway-timeout-net-hxxp-tls-handshake-timeout/341325 "2023-08-24T04:23:26Z")

</div>

Hi, Elastic agent is un healthy and not send logs -- Logs below -- appreciate any help. \[elastic\_agent.filebeat\]\[warn\] WinEventLog\[winlog-winlog.winlog-c97bd33a-1398-47bc-88a7-284efdb43f68\] error salvaging message (eve…

---

## [Name or service not known in java RestHighLevelClient](https://discuss.elastic.co/t/name-or-service-not-known-in-java-resthighlevelclient/341415)

<div class="topic-metadata">

**Author:** [@ChiMu\_Yuan](https://discuss.elastic.co/u/ChiMu_Yuan)\
**Replies:** 2\
**Last updated:** [August 24, 2023, 3:52am UTC](https://discuss.elastic.co/t/name-or-service-not-known-in-java-resthighlevelclient/341415 "2023-08-24T03:52:37Z")

</div>

Hi, everyone. I am using the Elasticsearch High Level REST client to access the service, but I am getting an error Name or service not known. However, I can successfully access the service using curl. Since I upgraded f…

---

## [Elasticsearch Aggregate Search Impact on Performance](https://discuss.elastic.co/t/elasticsearch-aggregate-search-impact-on-performance/340740)

<div class="topic-metadata">

**Author:** [@fangyan](https://discuss.elastic.co/u/fangyan)\
**Replies:** 2\
**Last updated:** [August 24, 2023, 3:45am UTC](https://discuss.elastic.co/t/elasticsearch-aggregate-search-impact-on-performance/340740 "2023-08-24T03:45:04Z")

</div>

Is there a leader in ES? For general product comprehensive search and display lists, it is recommended to use direct query or AGG aggregation form, as AGG has little impact on performance

---

## [When the number of documents exceeds 2 billion, the index status becomes RED](https://discuss.elastic.co/t/when-the-number-of-documents-exceeds-2-billion-the-index-status-becomes-red/341461)

<div class="topic-metadata">

**Author:** [@im.jinxinwang](https://discuss.elastic.co/u/im.jinxinwang)\
**Replies:** 5\
**Last updated:** [August 24, 2023, 3:24am UTC](https://discuss.elastic.co/t/when-the-number-of-documents-exceeds-2-billion-the-index-status-becomes-red/341461 "2023-08-24T03:24:29Z")

</div>

Version: 7.8.1 Cause of failure: The number of important index documents in the 7.8.1 open source version of ES has reached the limit of 2147483519 in Lucene. The index status is red, and read and write operations canno…

---

## [Blocklist not working as expected](https://discuss.elastic.co/t/blocklist-not-working-as-expected/341465)

<div class="topic-metadata">

**Author:** [@Krishna\_Teja](https://discuss.elastic.co/u/Krishna_Teja)\
**Replies:** 2\
**Last updated:** [August 24, 2023, 2:10am UTC](https://discuss.elastic.co/t/blocklist-not-working-as-expected/341465 "2023-08-24T02:10:47Z")

</div>

I added an application to blocklist. Ensured malware protections and blocklist are enabled for the policy. Even after hours of adding, I'm still able to run the application.

---

## [Integrate Kibana with an external logging agent](https://discuss.elastic.co/t/integrate-kibana-with-an-external-logging-agent/341523)

<div class="topic-metadata">

**Author:** [@quarkytale](https://discuss.elastic.co/u/quarkytale)\
**Replies:** 1\
**Last updated:** [August 24, 2023, 1:32am UTC](https://discuss.elastic.co/t/integrate-kibana-with-an-external-logging-agent/341523 "2023-08-24T01:32:45Z")

</div>

Is it possible to integrate Kibana with an external logging agent instead of using Elasticsearch. Would appreciate any resources on the same, especially message formats and configuration details.

---

## [Connectors-python mysql - selfsigned SSL can not verify](https://discuss.elastic.co/t/connectors-python-mysql-selfsigned-ssl-can-not-verify/341512)

<div class="topic-metadata">

**Author:** [@lenny1](https://discuss.elastic.co/u/lenny1)\
**Replies:** 1\
**Last updated:** [August 24, 2023, 12:08am UTC](https://discuss.elastic.co/t/connectors-python-mysql-selfsigned-ssl-can-not-verify/341512 "2023-08-24T00:08:55Z")

</div>

Hello, when I try to connect to our mysql / mariadb database instance using SSL and providing the CA-cert.pem file of the selfsigned certificate, the connectors-python connector outputs an error that the selfsigned SSL …

---

## [Optimizing ElasticSearch startup time for CI](https://discuss.elastic.co/t/optimizing-elasticsearch-startup-time-for-ci/341516)

<div class="topic-metadata">

**Author:** [@blindsnowmobile](https://discuss.elastic.co/u/blindsnowmobile)\
**Replies:** 0\
**Last updated:** [August 23, 2023, 9:11pm UTC](https://discuss.elastic.co/t/optimizing-elasticsearch-startup-time-for-ci/341516 "2023-08-23T21:11:20Z")

</div>

We use Elasticsearch in our integration tests, which run many times every day. Running ES in this way has a different set of requirements than in our production environment. We need ES to start as fast as possible with…

---

## [Looking for data in Kibana](https://discuss.elastic.co/t/looking-for-data-in-kibana/341383)

<div class="topic-metadata">

**Author:** [@Naveen.Bhonagiri](https://discuss.elastic.co/u/Naveen.Bhonagiri)\
**Replies:** 5\
**Last updated:** [August 23, 2023, 8:41pm UTC](https://discuss.elastic.co/t/looking-for-data-in-kibana/341383 "2023-08-23T20:41:46Z")

</div>

HI Team, I am looking for a help, i am having some devices list (approx 900 devices) which are injecting logs to Elastic, i want help in finding the devices that never sent logs to elastic from my actual devices. If an…

---

## [Can Rollover API / ILM be used to keep only x days data in an index at any point of time](https://discuss.elastic.co/t/can-rollover-api-ilm-be-used-to-keep-only-x-days-data-in-an-index-at-any-point-of-time/341410)

<div class="topic-metadata">

**Author:** [@Aditya1996](https://discuss.elastic.co/u/Aditya1996)\
**Replies:** 14\
**Last updated:** [August 23, 2023, 6:44pm UTC](https://discuss.elastic.co/t/can-rollover-api-ilm-be-used-to-keep-only-x-days-data-in-an-index-at-any-point-of-time/341410 "2023-08-23T18:44:02Z")

</div>

I have read a few threads regarding this question , Most of them suggest using DeleteBy Query as Rollover API seems to delete/move to other phase the indices and create the new ones based on given condition. I could not…

---

## [Elastic Agent stopped sending ssh failed logs](https://discuss.elastic.co/t/elastic-agent-stopped-sending-ssh-failed-logs/341369)

<div class="topic-metadata">

**Author:** [@hoomant](https://discuss.elastic.co/u/hoomant)\
**Replies:** 1\
**Last updated:** [August 23, 2023, 6:04pm UTC](https://discuss.elastic.co/t/elastic-agent-stopped-sending-ssh-failed-logs/341369 "2023-08-23T18:04:32Z")

</div>

Hi I have setup elastic agent in an elasticsearch 8.7 environment and up to a few days ago everything was working fine but now it is not sending the ssh failed events to the elasticsearch which was a no problem in previo…

---

## [Install ECE Error Security Cluster](https://discuss.elastic.co/t/install-ece-error-security-cluster/341404)

<div class="topic-metadata">

**Author:** [@Eljafopregunta](https://discuss.elastic.co/u/Eljafopregunta)\
**Replies:** 1\
**Last updated:** [August 23, 2023, 5:52pm UTC](https://discuss.elastic.co/t/install-ece-error-security-cluster/341404 "2023-08-23T17:52:03Z")

</div>

Hello! I'm installing ECE with Podman, but it fails when creating the "Security cluster." The error I'm getting is as follows: \[2023-08-22 18:39:11,986\]\[ERROR\]\[no.found.bootstrap.clusters.SecurityClusterBootstrap$Defau…

---

## [Data parse from multiple rsyslog to logstash to elasticsearch](https://discuss.elastic.co/t/data-parse-from-multiple-rsyslog-to-logstash-to-elasticsearch/341506)

<div class="topic-metadata">

**Author:** [@ermilan2309](https://discuss.elastic.co/u/ermilan2309)\
**Replies:** 0\
**Last updated:** [August 23, 2023, 5:38pm UTC](https://discuss.elastic.co/t/data-parse-from-multiple-rsyslog-to-logstash-to-elasticsearch/341506 "2023-08-23T17:38:28Z")

</div>

Hello, I am new to ELK. I have deployed my ELK with this article. https://www.digitalocean.com/community/tutorials/how-to-install-elasticsearch-logstash-and-kibana-elastic-stack-on-ubuntu-22-04 I skipped the nginx par…

---

## [Stored fields](https://discuss.elastic.co/t/stored-fields/341503)

<div class="topic-metadata">

**Author:** [@toddcarv](https://discuss.elastic.co/u/toddcarv)\
**Replies:** 0\
**Last updated:** [August 23, 2023, 5:02pm UTC](https://discuss.elastic.co/t/stored-fields/341503 "2023-08-23T17:02:30Z")

</div>

Looking for help interacting with stored fields returned from the search. Specifically hit.fields() returns a map of string and JsonData. How do you turn that JsonData into something you can manipulate? Thanks. SearchRe…

---

## [Kibana not opening up in elastic on demand](https://discuss.elastic.co/t/kibana-not-opening-up-in-elastic-on-demand/341281)

<div class="topic-metadata">

**Author:** [@regepiyu](https://discuss.elastic.co/u/regepiyu)\
**Replies:** 3\
**Last updated:** [August 23, 2023, 4:53pm UTC](https://discuss.elastic.co/t/kibana-not-opening-up-in-elastic-on-demand/341281 "2023-08-23T16:53:37Z")

</div>

Course: Elasticsearch Engineer (On Demand) Version: \<And which particular version?\> Question: I was using Kibana 1 and Kibana2 terminals in the on demand course. Suddenly it stopped working and getting DNS error. se…

---

## [Lab material accessibility issues](https://discuss.elastic.co/t/lab-material-accessibility-issues/341484)

<div class="topic-metadata">

**Author:** [@halamrii](https://discuss.elastic.co/u/halamrii)\
**Replies:** 1\
**Last updated:** [August 23, 2023, 4:43pm UTC](https://discuss.elastic.co/t/lab-material-accessibility-issues/341484 "2023-08-23T16:43:00Z")

</div>

Course: Elasticsearch engineer Question: My strigo account has expired, and i am currently looking for the Lab material for the Elasticsearch engineer (on-demand) course. Note that i have access to the course material …

---

## [Logstash stops processing AWS WAF logs when fields exceed 1000 (or any number)](https://discuss.elastic.co/t/logstash-stops-processing-aws-waf-logs-when-fields-exceed-1000-or-any-number/341497)

<div class="topic-metadata">

**Author:** [@feo13](https://discuss.elastic.co/u/feo13)\
**Replies:** 4\
**Last updated:** [August 23, 2023, 4:41pm UTC](https://discuss.elastic.co/t/logstash-stops-processing-aws-waf-logs-when-fields-exceed-1000-or-any-number/341497 "2023-08-23T16:41:41Z")

</div>

Hi there, I'm ingesting AWS WAF logs and it works fine for a few minutes but then stops with the following error: response=\>{"index"=\>{"\_index"=\>"waf-logs-2023.08.01", "\_id"=\>"rjCKGYoBsxYs-jwL007l", "status"=\>400, "err…

---

## [How to serialize/deserialize FieldValue object?](https://discuss.elastic.co/t/how-to-serialize-deserialize-fieldvalue-object/341498)

<div class="topic-metadata">

**Author:** [@icruces](https://discuss.elastic.co/u/icruces)\
**Replies:** 0\
**Last updated:** [August 23, 2023, 3:40pm UTC](https://discuss.elastic.co/t/how-to-serialize-deserialize-fieldvalue-object/341498 "2023-08-23T15:40:24Z")

</div>

I have upgraded the Java API from 8.2 to the latest. The method Hit::sort now returns a List\<FieldValue\> instead of List\<String\>. I understand this is the correct way but it breaks my app as I was base64 encoding/decodin…

---

## [About Kibana UI](https://discuss.elastic.co/t/about-kibana-ui/340993)

<div class="topic-metadata">

**Author:** [@Vamsi\_Ramisetti](https://discuss.elastic.co/u/Vamsi_Ramisetti)\
**Replies:** 2\
**Last updated:** [August 23, 2023, 2:55pm UTC](https://discuss.elastic.co/t/about-kibana-ui/340993 "2023-08-23T14:55:58Z")

</div>

In Kibana UI in the above uploaded image the document filed is showing empty but the timestamp is displaying. The logs is coming but not displaying in the document field

---

## [Postgresql to Elastic Search](https://discuss.elastic.co/t/postgresql-to-elastic-search/341319)

<div class="topic-metadata">

**Author:** [@oreobiskuit](https://discuss.elastic.co/u/oreobiskuit)\
**Replies:** 1\
**Last updated:** [August 23, 2023, 2:51pm UTC](https://discuss.elastic.co/t/postgresql-to-elastic-search/341319 "2023-08-23T14:51:44Z")

</div>

Hi everyone, I'm new to Elasticsearch. Currently I'm trying to replicate my db from postgresql and transform it to Elasticsearch. I've tried using google datastream (since my db is deployed in cloudSql) to cloud storage…

---

## [Cross Cluster Search - 7.17 on EC2 to 8.8 on Kubernetes](https://discuss.elastic.co/t/cross-cluster-search-7-17-on-ec2-to-8-8-on-kubernetes/341391)

<div class="topic-metadata">

**Author:** [@Doc\_Kaos](https://discuss.elastic.co/u/Doc_Kaos)\
**Replies:** 2\
**Last updated:** [August 23, 2023, 1:59pm UTC](https://discuss.elastic.co/t/cross-cluster-search-7-17-on-ec2-to-8-8-on-kubernetes/341391 "2023-08-23T13:59:10Z")

</div>

I have a 7.17 cluster running on EC2 nodes in AWS. No security enabled. I'm trying to connect it to an 8.8 cluster on K8s with security enabled. Is this even possible? Having no issues connecting to other 7.17 clusters …

---

## [Fleet: Logstash Load Balancing?](https://discuss.elastic.co/t/fleet-logstash-load-balancing/341479)

<div class="topic-metadata">

**Author:** [@DefensiveDepth](https://discuss.elastic.co/u/DefensiveDepth)\
**Replies:** 4\
**Last updated:** [August 23, 2023, 1:44pm UTC](https://discuss.elastic.co/t/fleet-logstash-load-balancing/341479 "2023-08-23T13:44:03Z")

</div>

I don't see this documented anywhere. For Fleet-managed Logstash Output, is there a way to loadbalance among the Logstash endpoints specified?

---

## [Is reading elastic logs from a node directly possible?](https://discuss.elastic.co/t/is-reading-elastic-logs-from-a-node-directly-possible/341473)

<div class="topic-metadata">

**Author:** [@mscch](https://discuss.elastic.co/u/mscch)\
**Replies:** 2\
**Last updated:** [August 23, 2023, 1:41pm UTC](https://discuss.elastic.co/t/is-reading-elastic-logs-from-a-node-directly-possible/341473 "2023-08-23T13:41:19Z")

</div>

Hi all Is there a way to read logs (sent to elastic by Logstash) directly from an Elasticsearch node? Our Elasticsearch version is 8.30. Because of a Ransomware attack, we currently do not have access to the Kibana VM.…

[Previous page](https://discuss.elastic.co/latest.md?page=562)

[Next page](https://discuss.elastic.co/latest.md?page=564)
