# Latest

**URL:** https://discuss.elastic.co/latest.md?page=565

[Latest](https://discuss.elastic.co/latest.md) · [Categories](https://discuss.elastic.co/categories.md) · [Tags](https://discuss.elastic.co/tags.md)

**Page:** 566

---

## [Rsyslog and syslog-ng direct logging to Elasticsearch, viable replacement for elastic-agent?](https://discuss.elastic.co/t/rsyslog-and-syslog-ng-direct-logging-to-elasticsearch-viable-replacement-for-elastic-agent/341390)

<div class="topic-metadata">

**Author:** [@Craig\_Rodrigues](https://discuss.elastic.co/u/Craig_Rodrigues)\
**Replies:** 4\
**Last updated:** [August 22, 2023, 4:43pm UTC](https://discuss.elastic.co/t/rsyslog-and-syslog-ng-direct-logging-to-elasticsearch-viable-replacement-for-elastic-agent/341390 "2023-08-22T16:43:26Z")

</div>

rsyslog has a module to send directly to Elasticsearch: syslog-ng also has a module for logging directly to Elasticsearch: https://www.syslog-ng.com/technical-documents/doc/syslog-ng-open-source-edition/3.22/adminis…

---

## [Get most frequent combinations of nested docs](https://discuss.elastic.co/t/get-most-frequent-combinations-of-nested-docs/341397)

<div class="topic-metadata">

**Author:** [@JsRg](https://discuss.elastic.co/u/JsRg)\
**Replies:** 0\
**Last updated:** [August 22, 2023, 4:41pm UTC](https://discuss.elastic.co/t/get-most-frequent-combinations-of-nested-docs/341397 "2023-08-22T16:41:46Z")

</div>

I have a elasticsearch index with nested documents (colors). I would like to have a query with an aggregation, which shows the most frequent combinations of colors. An example: I have three documents \[ { "name": "D…

---

## [Using DataDog's vector to ship logs to ElasticSearch instead of elastic-agent?](https://discuss.elastic.co/t/using-datadogs-vector-to-ship-logs-to-elasticsearch-instead-of-elastic-agent/341388)

<div class="topic-metadata">

**Author:** [@Craig\_Rodrigues](https://discuss.elastic.co/u/Craig_Rodrigues)\
**Replies:** 3\
**Last updated:** [August 22, 2023, 4:29pm UTC](https://discuss.elastic.co/t/using-datadogs-vector-to-ship-logs-to-elasticsearch-instead-of-elastic-agent/341388 "2023-08-22T16:29:19Z")

</div>

DataDog's vector program has a feature which allows you to ship logs directly to Elasticsearch: This looks like this could be used as an alternative to elastic-agent. Does anyone have any experiences to share on usi…

---

## [Modify the Font Styles for Discover tables](https://discuss.elastic.co/t/modify-the-font-styles-for-discover-tables/341127)

<div class="topic-metadata">

**Author:** [@Rajkumar\_M](https://discuss.elastic.co/u/Rajkumar_M)\
**Replies:** 1\
**Last updated:** [August 22, 2023, 4:22pm UTC](https://discuss.elastic.co/t/modify-the-font-styles-for-discover-tables/341127 "2023-08-22T16:22:36Z")

</div>

I need to update the Font styles (color, size, ..) in the Kibana Discover Table. Please let me know the options to do that in Kibana UI.

---

## [Facing issue adding fleet server](https://discuss.elastic.co/t/facing-issue-adding-fleet-server/340803)

<div class="topic-metadata">

**Author:** [@TirathS](https://discuss.elastic.co/u/TirathS)\
**Replies:** 1\
**Last updated:** [August 22, 2023, 10:59am UTC](https://discuss.elastic.co/t/facing-issue-adding-fleet-server/340803 "2023-08-22T10:59:21Z")

</div>

Hello All, I am fairly new to entire elk stack and right now trying to setup a home lab. I am facing a weird issue while adding a fleet server. I am using the official guide to install and whenever i am doing: sudo ./…

---

## [Elastic agent upgrade 8.7.1 failed](https://discuss.elastic.co/t/elastic-agent-upgrade-8-7-1-failed/341169)

<div class="topic-metadata">

**Author:** [@xqaiviwjxzw](https://discuss.elastic.co/u/xqaiviwjxzw)\
**Replies:** 2\
**Last updated:** [August 22, 2023, 3:40pm UTC](https://discuss.elastic.co/t/elastic-agent-upgrade-8-7-1-failed/341169 "2023-08-22T15:40:04Z")

</div>

Hello ,When I upgraded the elastic agent from 8.5.2 to 8.7.1, the following error occurred, and I have been unable to upgrade to 8.7.1. What is the solution? message: "component gateway-8da30c24: failed to dispatch acti…

---

## [Elasticsearch 8.9.1 - How to extract the self-signed CA and server cert](https://discuss.elastic.co/t/elasticsearch-8-9-1-how-to-extract-the-self-signed-ca-and-server-cert/341304)

<div class="topic-metadata">

**Author:** [@saltspreader](https://discuss.elastic.co/u/saltspreader)\
**Replies:** 2\
**Last updated:** [August 22, 2023, 3:06pm UTC](https://discuss.elastic.co/t/elasticsearch-8-9-1-how-to-extract-the-self-signed-ca-and-server-cert/341304 "2023-08-22T15:06:46Z")

</div>

Hi there, Elasticsearch v 8.9.1 installed via ES apt repo on ubuntu 22.04. I need to extract the self-signed CA and https cert from my elasticsearch 8.9.1 setup to copy to a gitlab instance for https connections. I've …

---

## [Tooltip position in vega is wrong](https://discuss.elastic.co/t/tooltip-position-in-vega-is-wrong/341128)

<div class="topic-metadata">

**Author:** [@karlanakamura](https://discuss.elastic.co/u/karlanakamura)\
**Replies:** 2\
**Last updated:** [August 22, 2023, 3:12pm UTC](https://discuss.elastic.co/t/tooltip-position-in-vega-is-wrong/341128 "2023-08-22T15:12:44Z")

</div>

Hello, I'm using version 8.6.0 in elastic cloud. I would like to know what I can do so that the tooltip is in the correct position. I noticed that this bug often happens when I use a mark of type group. The code below …

---

## [Upgrading elastic to 8.8 has resulted in a master node sending out 5 megabytes a second](https://discuss.elastic.co/t/upgrading-elastic-to-8-8-has-resulted-in-a-master-node-sending-out-5-megabytes-a-second/341299)

<div class="topic-metadata">

**Author:** [@data\_smith](https://discuss.elastic.co/u/data_smith)\
**Replies:** 2\
**Last updated:** [August 22, 2023, 2:19pm UTC](https://discuss.elastic.co/t/upgrading-elastic-to-8-8-has-resulted-in-a-master-node-sending-out-5-megabytes-a-second/341299 "2023-08-22T14:19:08Z")

</div>

Usually elastic master nodes send out 100 kilobytes a second of data. But after upgrading the active master is sending out 5 megabytes. There's no known issue but this doesn't seem healthy. It's role is only master.

---

## [Trial License ECK Issues](https://discuss.elastic.co/t/trial-license-eck-issues/341381)

<div class="topic-metadata">

**Author:** [@walberss](https://discuss.elastic.co/u/walberss)\
**Replies:** 0\
**Last updated:** [August 22, 2023, 2:04pm UTC](https://discuss.elastic.co/t/trial-license-eck-issues/341381 "2023-08-22T14:04:16Z")

</div>

Hi guys I'm trying make tests with ldap integration on kubernetes eck and i can change de license from basic to trial, after few seconds the license come back to basic, Has anyone already caught this behavior? {"type":…

---

## [Training lab incorrectly built](https://discuss.elastic.co/t/training-lab-incorrectly-built/341364)

<div class="topic-metadata">

**Author:** [@Craig\_Anderson](https://discuss.elastic.co/u/Craig_Anderson)\
**Replies:** 2\
**Last updated:** [August 22, 2023, 2:06pm UTC](https://discuss.elastic.co/t/training-lab-incorrectly-built/341364 "2023-08-22T14:06:44Z")

</div>

Try to reach out to the training Labs team. I am attending to compile the practice analyst practice exam and it seems that the lab is incorrectly built as I am missing index’s Can any one help

---

## [Threshold detection rule - limitation of group by fields](https://discuss.elastic.co/t/threshold-detection-rule-limitation-of-group-by-fields/338383)

<div class="topic-metadata">

**Author:** [@Poukim0m](https://discuss.elastic.co/u/Poukim0m)\
**Replies:** 3\
**Last updated:** [August 22, 2023, 1:51pm UTC](https://discuss.elastic.co/t/threshold-detection-rule-limitation-of-group-by-fields/338383 "2023-08-22T13:51:54Z")

</div>

Hello, I want to implement a threshold detection rule that aggregates more than 3 fields in the "Group by" section of rule definition. But there seems to be a limitation of 3 fields as i get an error message "Number of …

---

## [Connect Salesforce with Elastic](https://discuss.elastic.co/t/connect-salesforce-with-elastic/341255)

<div class="topic-metadata">

**Author:** [@Samuele\_Lolli](https://discuss.elastic.co/u/Samuele_Lolli)\
**Replies:** 1\
**Last updated:** [August 22, 2023, 1:51pm UTC](https://discuss.elastic.co/t/connect-salesforce-with-elastic/341255 "2023-08-22T13:51:02Z")

</div>

Hi everyone, im using elastic cloud and i need to integrate Salesforce. What i need to do is analize logs coming from salesforce like SetupAuditTrail. I have found different solution for my problem: Using the Integra…

---

## [Not able to see the traces of my applicaton(mule4)](https://discuss.elastic.co/t/not-able-to-see-the-traces-of-my-applicaton-mule4/340421)

<div class="topic-metadata">

**Author:** [@vikascateina](https://discuss.elastic.co/u/vikascateina)\
**Replies:** 20\
**Last updated:** [August 22, 2023, 1:47pm UTC](https://discuss.elastic.co/t/not-able-to-see-the-traces-of-my-applicaton-mule4/340421 "2023-08-22T13:47:14Z")

</div>

Kibana version:7.17.9 Elasticsearch version:7.17.9 APM Server version:7.17.9 APM Agent language and version:mule4 agent Browser version:Version 114.0.5735.198 (Official Build) (64-bit) I am using elasticsearch,kiban…

---

## [High latency issue with inner\_hits](https://discuss.elastic.co/t/high-latency-issue-with-inner-hits/341375)

<div class="topic-metadata">

**Author:** [@Gilat\_Naveh](https://discuss.elastic.co/u/Gilat_Naveh)\
**Replies:** 0\
**Last updated:** [August 22, 2023, 1:46pm UTC](https://discuss.elastic.co/t/high-latency-issue-with-inner-hits/341375 "2023-08-22T13:46:56Z")

</div>

I’m trying to install a new cluster on ECK (version 8.8.1) and I’m having latency issues (~300ms). We already have a similar cluster working in version 6.5.3 (EC2) and for the same query timing is good (~20ms) The quer…

---

## [Microsoft-sentinel-log-analytics-logstash-output-plugin functionality](https://discuss.elastic.co/t/microsoft-sentinel-log-analytics-logstash-output-plugin-functionality/341374)

<div class="topic-metadata">

**Author:** [@shadu88](https://discuss.elastic.co/u/shadu88)\
**Replies:** 0\
**Last updated:** [August 22, 2023, 1:40pm UTC](https://discuss.elastic.co/t/microsoft-sentinel-log-analytics-logstash-output-plugin-functionality/341374 "2023-08-22T13:40:10Z")

</div>

Hello Dear ELKs i was using "microsoft-sentinel-log-analytics-logstash-output-plugin" to forward the logs to azure sentinel but we switched to AMA( azure native) recently but post this switch the amount of logs doubled/…

---

## [Document level Privileges Not Working](https://discuss.elastic.co/t/document-level-privileges-not-working/340649)

<div class="topic-metadata">

**Author:** [@Namita\_Jaokar](https://discuss.elastic.co/u/Namita_Jaokar)\
**Replies:** 4\
**Last updated:** [August 22, 2023, 1:25pm UTC](https://discuss.elastic.co/t/document-level-privileges-not-working/340649 "2023-08-22T13:25:51Z")

</div>

Hi All, I am using ELK version 8.6.2 and need to implement user security in APM agents. I want only privileged user to view or edit data for the APM Agent. Example: if there are 2 users using 2 different APM Agents on…

---

## [Search scroll](https://discuss.elastic.co/t/search-scroll/341283)

<div class="topic-metadata">

**Author:** [@toddcarv](https://discuss.elastic.co/u/toddcarv)\
**Replies:** 4\
**Last updated:** [August 22, 2023, 1:25pm UTC](https://discuss.elastic.co/t/search-scroll/341283 "2023-08-22T13:25:36Z")

</div>

Can anyone point me to any documentation regarding search scroll for the new java api client? I'm talking about this from the HLRC - Search Scroll API | Java REST Client \[7.17\] | Elastic. Thanks.

---

## [Cant start kibana on docker any more](https://discuss.elastic.co/t/cant-start-kibana-on-docker-any-more/341108)

<div class="topic-metadata">

**Author:** [@Murilo\_Livorato](https://discuss.elastic.co/u/Murilo_Livorato)\
**Replies:** 2\
**Last updated:** [August 22, 2023, 1:20pm UTC](https://discuss.elastic.co/t/cant-start-kibana-on-docker-any-more/341108 "2023-08-22T13:20:16Z")

</div>

I am using this with docker image - and now , sundly I cant start the kibana any more . it showed this message - Kibana server is not ready yet. I runned the command - docker-compose logs , and shoed this message …

---

## [Elasticsearch docker cluster](https://discuss.elastic.co/t/elasticsearch-docker-cluster/341371)

<div class="topic-metadata">

**Author:** [@Swapnadeep\_Mondal](https://discuss.elastic.co/u/Swapnadeep_Mondal)\
**Replies:** 0\
**Last updated:** [August 22, 2023, 1:18pm UTC](https://discuss.elastic.co/t/elasticsearch-docker-cluster/341371 "2023-08-22T13:18:33Z")

</div>

Hi, I am trying to create the Elasticsearch cluster in remote servers using the docker containers, one catch is that I am not using the docker-compose file. When I start the docker containers in different remote hosts …

---

## [Iam trying to get the Duplicate Industries within the Column Industries in ABC index!](https://discuss.elastic.co/t/iam-trying-to-get-the-duplicate-industries-within-the-column-industries-in-abc-index/341367)

<div class="topic-metadata">

**Author:** [@Manasa\_BR](https://discuss.elastic.co/u/Manasa_BR)\
**Replies:** 0\
**Last updated:** [August 22, 2023, 12:32pm UTC](https://discuss.elastic.co/t/iam-trying-to-get-the-duplicate-industries-within-the-column-industries-in-abc-index/341367 "2023-08-22T12:32:15Z")

</div>

as mentioned iam trying to get the Duplicate Industries within the Column Industries in ABC index, and when i execute the below query iam getting other results GET /abc/\_search { "query": { "match": { "industries.…

---

## [Aggregations and sub-Aggregations in java API client](https://discuss.elastic.co/t/aggregations-and-sub-aggregations-in-java-api-client/341363)

<div class="topic-metadata">

**Author:** [@dt2244](https://discuss.elastic.co/u/dt2244)\
**Replies:** 0\
**Last updated:** [August 22, 2023, 12:13pm UTC](https://discuss.elastic.co/t/aggregations-and-sub-aggregations-in-java-api-client/341363 "2023-08-22T12:13:22Z")

</div>

i am trying to rewrite my code from elasticsearch version 7.10.2 to latest version es 8.9 but i am having some problems: code version 7.10.2: FilterAggregationBuilder filteredAggs = AggregationBuilders …

---

## [Elaticsearch SQL CLI is not working](https://discuss.elastic.co/t/elaticsearch-sql-cli-is-not-working/340615)

<div class="topic-metadata">

**Author:** [@ashishshukla](https://discuss.elastic.co/u/ashishshukla)\
**Replies:** 10\
**Last updated:** [August 22, 2023, 11:41am UTC](https://discuss.elastic.co/t/elaticsearch-sql-cli-is-not-working/340615 "2023-08-22T11:41:02Z")

</div>

Hi Team, I am trying to execute some sql commands from SQL CLI in elasticsearch -8.8.2 but while executing below commands to open SQL CLI ./bin/elasticsearch-sql-cli I am getting below error ERROR: Cannot communicat…

---

## [Geo-distance query to match geo\_point within a given distance of a geopoint](https://discuss.elastic.co/t/geo-distance-query-to-match-geo-point-within-a-given-distance-of-a-geopoint/341356)

<div class="topic-metadata">

**Author:** [@Allen\_Liang](https://discuss.elastic.co/u/Allen_Liang)\
**Replies:** 0\
**Last updated:** [August 22, 2023, 11:27am UTC](https://discuss.elastic.co/t/geo-distance-query-to-match-geo-point-within-a-given-distance-of-a-geopoint/341356 "2023-08-22T11:27:27Z")

</div>

Hello, I'm seeking clarification regarding the distance utilised for filtering documents using the geo-distance query (Geo-distance query | Elasticsearch Guide \[8.9\] | Elastic). In each of my documents, there exists a …

---

## [Annotations in stacked vertical bar graph](https://discuss.elastic.co/t/annotations-in-stacked-vertical-bar-graph/341327)

<div class="topic-metadata">

**Author:** [@Neelam\_Zanvar](https://discuss.elastic.co/u/Neelam_Zanvar)\
**Replies:** 3\
**Last updated:** [August 22, 2023, 10:29am UTC](https://discuss.elastic.co/t/annotations-in-stacked-vertical-bar-graph/341327 "2023-08-22T10:29:25Z")

</div>

Hi I have created the following stacked bar graph I have used annotation to display extra data at a specific time on x axis. When i hover on the number in the pink circle at the top but i am not able to take co…

---

## [Line Chart](https://discuss.elastic.co/t/line-chart/341269)

<div class="topic-metadata">

**Author:** [@Lorenz\_Bucago](https://discuss.elastic.co/u/Lorenz_Bucago)\
**Replies:** 3\
**Last updated:** [August 22, 2023, 10:20am UTC](https://discuss.elastic.co/t/line-chart/341269 "2023-08-22T10:20:42Z")

</div>

This might be a stupid question but Im just new with Kibana. Im trying to add legend on top of each data points but I tried but its still not showing. n

---

## [Fleet Server Cluster](https://discuss.elastic.co/t/fleet-server-cluster/341326)

<div class="topic-metadata">

**Author:** [@Mohsin\_Ashraf](https://discuss.elastic.co/u/Mohsin_Ashraf)\
**Replies:** 1\
**Last updated:** [August 22, 2023, 9:29am UTC](https://discuss.elastic.co/t/fleet-server-cluster/341326 "2023-08-22T09:29:54Z")

</div>

Hi, I want to set up a fleet server cluster for high availability purposes. but I got nothing related to this. please help me in this regard.

---

## [Elastic Integrations fail to install and lead to broken Dashboards when used with multiple Kibana Spaces](https://discuss.elastic.co/t/elastic-integrations-fail-to-install-and-lead-to-broken-dashboards-when-used-with-multiple-kibana-spaces/337246)

<div class="topic-metadata">

**Author:** [@matled](https://discuss.elastic.co/u/matled)\
**Replies:** 6\
**Last updated:** [August 22, 2023, 9:26am UTC](https://discuss.elastic.co/t/elastic-integrations-fail-to-install-and-lead-to-broken-dashboards-when-used-with-multiple-kibana-spaces/337246 "2023-08-22T09:26:07Z")

</div>

Production Environment: Elastic-Stack 8.8.2 Debian 12 7 Elasticsearch Nodes 3 Kibana Nodes 2 Fleet Agents 5 Kibana spaces 70 Elastic-Agents Since about Elastic-Stack 8.8.0 we have issues installing or reinstalling Ela…

---

## [How to perform with condition divide math operation in elasticsearch](https://discuss.elastic.co/t/how-to-perform-with-condition-divide-math-operation-in-elasticsearch/341329)

<div class="topic-metadata">

**Author:** [@Huy\_Vu\_Quang](https://discuss.elastic.co/u/Huy_Vu_Quang)\
**Replies:** 0\
**Last updated:** [August 22, 2023, 6:54am UTC](https://discuss.elastic.co/t/how-to-perform-with-condition-divide-math-operation-in-elasticsearch/341329 "2023-08-22T06:54:06Z")

</div>

I have a query like this how I perform a query in Elasticsearch with this condition if wager == 0 : payout/1 \>= multiplier else: payout/wager \>= multiplier filter multiplier according to this condition I wrote this …

---

## [How to Optimize time start Logstash with than 100 condition in output](https://discuss.elastic.co/t/how-to-optimize-time-start-logstash-with-than-100-condition-in-output/341335)

<div class="topic-metadata">

**Author:** [@quoctuan2311](https://discuss.elastic.co/u/quoctuan2311)\
**Replies:** 0\
**Last updated:** [August 22, 2023, 7:37am UTC](https://discuss.elastic.co/t/how-to-optimize-time-start-logstash-with-than-100-condition-in-output/341335 "2023-08-22T07:37:58Z")

</div>

Hi, I have built an ES with architect such as picture. And deploy it on AWS EKS. My expected is filebeat will collect logs all pods on EKS. And send it to Logstash. And Logstash will send this to Elasticsearch. At…

[Previous page](https://discuss.elastic.co/latest.md?page=564)

[Next page](https://discuss.elastic.co/latest.md?page=566)
