# Latest

**URL:** https://discuss.elastic.co/latest.md?page=567

[Latest](https://discuss.elastic.co/latest.md) · [Categories](https://discuss.elastic.co/categories.md) · [Tags](https://discuss.elastic.co/tags.md)

**Page:** 568

---

## [High Index Count impacting Elasticsearch Performance](https://discuss.elastic.co/t/high-index-count-impacting-elasticsearch-performance/341259)

<div class="topic-metadata">

**Author:** [@Nitish\_Goyal](https://discuss.elastic.co/u/Nitish_Goyal)\
**Replies:** 0\
**Last updated:** [August 21, 2023, 2:07pm UTC](https://discuss.elastic.co/t/high-index-count-impacting-elasticsearch-performance/341259 "2023-08-21T14:07:43Z")

</div>

Problem Statement : Decrease in cluster throughput as we increase the number of indices in the cluster Cluster Set up Nodes = 8 Cores per node = 18 Memory = 90 GB Heap = 28 GB Version = 8.9.0 We are seeing decrease…

---

## [Elaticsearch SQL CLI is not working](https://discuss.elastic.co/t/elaticsearch-sql-cli-is-not-working/341258)

<div class="topic-metadata">

**Author:** [@SivaPrasadELK](https://discuss.elastic.co/u/SivaPrasadELK)\
**Replies:** 0\
**Last updated:** [August 21, 2023, 2:02pm UTC](https://discuss.elastic.co/t/elaticsearch-sql-cli-is-not-working/341258 "2023-08-21T14:02:32Z")

</div>

Hi team, I am not able to run the SQL commands in SQL CLI tool. Any pointers how to use it or any supporting docs to refer. i am getting different kind of error messages when trying to run the queries in SQL CLI . "er…

---

## [Render Json strings from Elastic API client objects](https://discuss.elastic.co/t/render-json-strings-from-elastic-api-client-objects/341238)

<div class="topic-metadata">

**Author:** [@Zer0](https://discuss.elastic.co/u/Zer0)\
**Replies:** 2\
**Last updated:** [August 21, 2023, 1:59pm UTC](https://discuss.elastic.co/t/render-json-strings-from-elastic-api-client-objects/341238 "2023-08-21T13:59:53Z")

</div>

Hi, I am using the Elasticsearch API client (8.9) for java and wondering how to render those Queries and Responses as json strings. For example I can do a simple query like so: val query = Query.of { q -\> q.matchAll {…

---

## [Update-by-query: No mapping found for \[id\] in order to sort on](https://discuss.elastic.co/t/update-by-query-no-mapping-found-for-id-in-order-to-sort-on/339671)

<div class="topic-metadata">

**Author:** [@davysteegen](https://discuss.elastic.co/u/davysteegen)\
**Replies:** 6\
**Last updated:** [August 21, 2023, 1:34pm UTC](https://discuss.elastic.co/t/update-by-query-no-mapping-found-for-id-in-order-to-sort-on/339671 "2023-08-21T13:34:27Z")

</div>

Hi, We are in the process of migrating from Elasticsearch 2.3 to 8.6. One thing I noticed is that the sorting in the update-by-query API now only allows to provide a comma separated list of field/sort direction combos. …

---

## [Using kube-state-metrics (custom resource state metrics) breaks metricbeat](https://discuss.elastic.co/t/using-kube-state-metrics-custom-resource-state-metrics-breaks-metricbeat/341249)

<div class="topic-metadata">

**Author:** [@MKruger777](https://discuss.elastic.co/u/MKruger777)\
**Replies:** 0\
**Last updated:** [August 21, 2023, 1:32pm UTC](https://discuss.elastic.co/t/using-kube-state-metrics-custom-resource-state-metrics-breaks-metricbeat/341249 "2023-08-21T13:32:04Z")

</div>

Hi there, I am running metricbeat:8.6.1 and prometheus:2.43.1 on AKS 1.25.6 Both of these are scraping metrics from kube-state-metrics:2.8.2 Because of an edge case we were forced to make use of the Custom Resource St…

---

## [Is it possible to disable or remove log4j-core-2.17.1.jar from Logstash?](https://discuss.elastic.co/t/is-it-possible-to-disable-or-remove-log4j-core-2-17-1-jar-from-logstash/341221)

<div class="topic-metadata">

**Author:** [@kam89](https://discuss.elastic.co/u/kam89)\
**Replies:** 1\
**Last updated:** [August 21, 2023, 1:20pm UTC](https://discuss.elastic.co/t/is-it-possible-to-disable-or-remove-log4j-core-2-17-1-jar-from-logstash/341221 "2023-08-21T13:20:59Z")

</div>

Hi, We are running on Logstash 8.8.0 and our IT security team has concern about the log4j-core-2.17.1.jar in the logstash-core\\lib\\jars. Can we disable log4j totally in Logstash and remove the log4j-core-2.17.1.jar fro…

---

## [Decode\_base64\_field giving weird results](https://discuss.elastic.co/t/decode-base64-field-giving-weird-results/340962)

<div class="topic-metadata">

**Author:** [@praveen\_raju](https://discuss.elastic.co/u/praveen_raju)\
**Replies:** 3\
**Last updated:** [August 21, 2023, 1:09pm UTC](https://discuss.elastic.co/t/decode-base64-field-giving-weird-results/340962 "2023-08-21T13:09:29Z")

</div>

Hello, Requirement: We are sending emails (using custom cron jobs) whenever host is down in Elasticsearch Uptime (Heartbeat). We have a need to send link to single monitor, whenever it is down. Not sure how to achieve …

---

## [Spring + elastic 8.9.0 How to create index template](https://discuss.elastic.co/t/spring-elastic-8-9-0-how-to-create-index-template/340033)

<div class="topic-metadata">

**Author:** [@Prasanth\_Gutlapalli](https://discuss.elastic.co/u/Prasanth_Gutlapalli)\
**Replies:** 3\
**Last updated:** [August 21, 2023, 1:09pm UTC](https://discuss.elastic.co/t/spring-elastic-8-9-0-how-to-create-index-template/340033 "2023-08-21T13:09:26Z")

</div>

How to create index template give java example

---

## [Using envoy proxy to create S3 endpoint](https://discuss.elastic.co/t/using-envoy-proxy-to-create-s3-endpoint/341239)

<div class="topic-metadata">

**Author:** [@subhashmk](https://discuss.elastic.co/u/subhashmk)\
**Replies:** 0\
**Last updated:** [August 21, 2023, 12:46pm UTC](https://discuss.elastic.co/t/using-envoy-proxy-to-create-s3-endpoint/341239 "2023-08-21T12:46:58Z")

</div>

In elasticsearch snapshot repo, instead of specifying main S3 endpoint, we have added new envoy proxy sidecar to take care of authentication. Envoy proxy container will add authentication to incoming request and forward …

---

## [Change index name and template - Jira using enterprise](https://discuss.elastic.co/t/change-index-name-and-template-jira-using-enterprise/341069)

<div class="topic-metadata">

**Author:** [@Sheereen](https://discuss.elastic.co/u/Sheereen)\
**Replies:** 3\
**Last updated:** [August 21, 2023, 12:18pm UTC](https://discuss.elastic.co/t/change-index-name-and-template-jira-using-enterprise/341069 "2023-08-21T12:18:36Z")

</div>

Hi, I am using ES 8.8.1. I have connected to Jira cloud using Jira connector and I am receiving the data as well. Is it possible to update/change the index name for the data received? I would also like to change/updat…

---

## [Best way to load an elastic query and manipulate it](https://discuss.elastic.co/t/best-way-to-load-an-elastic-query-and-manipulate-it/341099)

<div class="topic-metadata">

**Author:** [@Zer0](https://discuss.elastic.co/u/Zer0)\
**Replies:** 1\
**Last updated:** [August 21, 2023, 12:10pm UTC](https://discuss.elastic.co/t/best-way-to-load-an-elastic-query-and-manipulate-it/341099 "2023-08-21T12:10:06Z")

</div>

Hi, I am using the Elasticsearch Java client and what I basically want to achieve is the following: Our backend is basically a ES Proxy, so there is an endpoint that takes an ES query as input, adds a clause (to scope t…

---

## [Configure Elasticsearch monitoring integration 8.9.0](https://discuss.elastic.co/t/configure-elasticsearch-monitoring-integration-8-9-0/341231)

<div class="topic-metadata">

**Author:** [@aaszxc](https://discuss.elastic.co/u/aaszxc)\
**Replies:** 0\
**Last updated:** [August 21, 2023, 11:56am UTC](https://discuss.elastic.co/t/configure-elasticsearch-monitoring-integration-8-9-0/341231 "2023-08-21T11:56:27Z")

</div>

I am trying to configure Elasticsearch Elastic Agent integration to monitor the elasticsearch cluster as specified here: Collecting Elasticsearch monitoring data with Elastic Agent | Elasticsearch Guide \[8.11\] | Elastic …

---

## [Troubleshooting Netflow Logs Display Issue in Kibana with Elasticsearch](https://discuss.elastic.co/t/troubleshooting-netflow-logs-display-issue-in-kibana-with-elasticsearch/341146)

<div class="topic-metadata">

**Author:** [@abntkpi](https://discuss.elastic.co/u/abntkpi)\
**Replies:** 8\
**Last updated:** [August 21, 2023, 11:21am UTC](https://discuss.elastic.co/t/troubleshooting-netflow-logs-display-issue-in-kibana-with-elasticsearch/341146 "2023-08-21T11:21:42Z")

</div>

Hello and good time to you, I have installed Elasticsearch along with Kibana, and I installed the Netflow record on Kibana to receive Netflow from Cisco Switch 2960. However, the Cisco Netflow logs are not being display…

---

## [Filestream data duplication in filebeat 8.9.1](https://discuss.elastic.co/t/filestream-data-duplication-in-filebeat-8-9-1/341222)

<div class="topic-metadata">

**Author:** [@germain\_nganko](https://discuss.elastic.co/u/germain_nganko)\
**Replies:** 0\
**Last updated:** [August 21, 2023, 10:28am UTC](https://discuss.elastic.co/t/filestream-data-duplication-in-filebeat-8-9-1/341222 "2023-08-21T10:28:48Z")

</div>

Hello, I read various issues regarding the data duplication error messages in filebeat logs, However I haven't really understood what the root cause is. Please can some one explain me really what the root cause is? below…

---

## [After Update from Kibana 7.x to Kibana 8.9 =\>security\_exception: unable to authenticate user \[kibana\_system\] for REST request \[/\_cluster/settings?include\_defaults=true&f](https://discuss.elastic.co/t/after-update-from-kibana-7-x-to-kibana-8-9-security-exception-unable-to-authenticate-user-kibana-system-for-rest-request-cluster-settings-include-defaults-true-f/340984)

<div class="topic-metadata">

**Author:** [@Wolfgang\_Winter](https://discuss.elastic.co/u/Wolfgang_Winter)\
**Replies:** 6\
**Last updated:** [August 21, 2023, 10:24am UTC](https://discuss.elastic.co/t/after-update-from-kibana-7-x-to-kibana-8-9-security-exception-unable-to-authenticate-user-kibana-system-for-rest-request-cluster-settings-include-defaults-true-f/340984 "2023-08-21T10:24:36Z")

</div>

Hello, we updated yesterday our elasticsearch-stack to 8.9.0. Now, kibana don't start and i found this error in /var/log/messages FATAL ResponseError: security\_exception Aug 17 10:42:58 elasticserver kibana\[342912\]: …

---

## [Securing Elasticsearch/Kibana / "Bad Decrypt" Error](https://discuss.elastic.co/t/securing-elasticsearch-kibana-bad-decrypt-error/340944)

<div class="topic-metadata">

**Author:** [@Shaakxuur](https://discuss.elastic.co/u/Shaakxuur)\
**Replies:** 15\
**Last updated:** [August 21, 2023, 10:08am UTC](https://discuss.elastic.co/t/securing-elasticsearch-kibana-bad-decrypt-error/340944 "2023-08-21T10:08:59Z")

</div>

Hi! I think I totally lost the thread, I don't know where my error is right now. I wanted to change my Elasticsearch-Kibana-WinlogBeat installation, which was working flawlessly so far, to an encrypted connection. The …

---

## [SESSION\_EXPIRED after logging in another Kibana](https://discuss.elastic.co/t/session-expired-after-logging-in-another-kibana/341003)

<div class="topic-metadata">

**Author:** [@theo2](https://discuss.elastic.co/u/theo2)\
**Replies:** 8\
**Last updated:** [August 21, 2023, 9:59am UTC](https://discuss.elastic.co/t/session-expired-after-logging-in-another-kibana/341003 "2023-08-21T09:59:25Z")

</div>

Hello, I have a cluster with 3 Elasticsearch on it, individually it works fine. But if I have an instance A connected, and I connect to instance B or C, I receive a SESSION\_EXPIRED timeout. I run kibana locally with d…

---

## [How to get values of filters to a variable in Canvas](https://discuss.elastic.co/t/how-to-get-values-of-filters-to-a-variable-in-canvas/341216)

<div class="topic-metadata">

**Author:** [@KLM](https://discuss.elastic.co/u/KLM)\
**Replies:** 0\
**Last updated:** [August 21, 2023, 9:24am UTC](https://discuss.elastic.co/t/how-to-get-values-of-filters-to-a-variable-in-canvas/341216 "2023-08-21T09:24:41Z")

</div>

I have set of filters on the canvas and values of these will be used in an essql query to pick data to a line chart. filters | essql query="SELECT .." .. .. | render But based on some of the selected values in filter…

---

## [Kibana does not restart without information about the error](https://discuss.elastic.co/t/kibana-does-not-restart-without-information-about-the-error/341095)

<div class="topic-metadata">

**Author:** [@ismaelalt](https://discuss.elastic.co/u/ismaelalt)\
**Replies:** 1\
**Last updated:** [August 21, 2023, 9:12am UTC](https://discuss.elastic.co/t/kibana-does-not-restart-without-information-about-the-error/341095 "2023-08-21T09:12:34Z")

</div>

My team has a deployment on Elastic Cloud involving several instances of the stack (Elasticsearch, Integrations server, Kibana...). For a few weeks now our Kibana instance has been down. Using "Force restart" fails and …

---

## [How to query list of offline agents using the Fleet API?](https://discuss.elastic.co/t/how-to-query-list-of-offline-agents-using-the-fleet-api/340783)

<div class="topic-metadata">

**Author:** [@Craig\_Rodrigues](https://discuss.elastic.co/u/Craig_Rodrigues)\
**Replies:** 11\
**Last updated:** [August 21, 2023, 8:36am UTC](https://discuss.elastic.co/t/how-to-query-list-of-offline-agents-using-the-fleet-api/340783 "2023-08-21T08:36:03Z")

</div>

I looked at these two docs: and came up with this query: curl --request GET --url 'https://mykibana/api/fleet/agents?kuery=status:offline' \\ --header 'Accept: \*/\*' \\ --header 'Authorization: ApiKey myk…

---

## [How many Meticbeat modules can be processed at the same time?](https://discuss.elastic.co/t/how-many-meticbeat-modules-can-be-processed-at-the-same-time/341210)

<div class="topic-metadata">

**Author:** [@rhakdnj](https://discuss.elastic.co/u/rhakdnj)\
**Replies:** 0\
**Last updated:** [August 21, 2023, 8:17am UTC](https://discuss.elastic.co/t/how-many-meticbeat-modules-can-be-processed-at-the-same-time/341210 "2023-08-21T08:17:25Z")

</div>

Hello. First of all, thank you for providing such a simple beat. Now I'm running haproxy as a process unit. As a result, we provide a specific haproxy\_id for each process. Accordingly, we make a haproxy module for eac…

---

## [Continuously get data from Elasticsearch, when new poll data comes in](https://discuss.elastic.co/t/continuously-get-data-from-elasticsearch-when-new-poll-data-comes-in/339254)

<div class="topic-metadata">

**Author:** [@Sheereen](https://discuss.elastic.co/u/Sheereen)\
**Replies:** 3\
**Last updated:** [August 21, 2023, 8:22am UTC](https://discuss.elastic.co/t/continuously-get-data-from-elasticsearch-when-new-poll-data-comes-in/339254 "2023-08-21T08:22:56Z")

</div>

Hi, I am creating an external plugin in Kibana 8.1.1 using React. I am retrieving the data I have in ES using the data plugin. Is it possible to fetch and update the plugin state as and when data is inserted into the i…

---

## [Large indice, a lot of IO read](https://discuss.elastic.co/t/large-indice-a-lot-of-io-read/341211)

<div class="topic-metadata">

**Author:** [@pdgaaa](https://discuss.elastic.co/u/pdgaaa)\
**Replies:** 0\
**Last updated:** [August 21, 2023, 8:17am UTC](https://discuss.elastic.co/t/large-indice-a-lot-of-io-read/341211 "2023-08-21T08:17:35Z")

</div>

Hi ! Having an elastic cluster with 3 nodes under docker. 2 data nodes (indices with replica 1 and only 1 shard) and one node for the master eligibilty. ES 7.17.x 8 GB RAM / data node, 6 GB for docker, 3 GB XMX for ES.…

---

## [Problem between elasticsearch and logstash](https://discuss.elastic.co/t/problem-between-elasticsearch-and-logstash/341206)

<div class="topic-metadata">

**Author:** [@adimi\_worou](https://discuss.elastic.co/u/adimi_worou)\
**Replies:** 0\
**Last updated:** [August 21, 2023, 7:59am UTC](https://discuss.elastic.co/t/problem-between-elasticsearch-and-logstash/341206 "2023-08-21T07:59:49Z")

</div>

Good evening, Elasticsearch via logstash loads data from mysql. The problem is that logstash only retrieves a small part of the documents. Example: logstash retrieves 8 out of 510. What do you think could be the cause …

---

## [Single click option in drilldown](https://discuss.elastic.co/t/single-click-option-in-drilldown/341200)

<div class="topic-metadata">

**Author:** [@Rushi\_Bagul](https://discuss.elastic.co/u/Rushi_Bagul)\
**Replies:** 1\
**Last updated:** [August 21, 2023, 7:36am UTC](https://discuss.elastic.co/t/single-click-option-in-drilldown/341200 "2023-08-21T07:36:08Z")

</div>

I am used self deploy kibana application with basic licence and I want Single click option in drilldown for dashboard visualizations . Can anyone suggest me to approach for this?

---

## [What is Query delay and bucket span](https://discuss.elastic.co/t/what-is-query-delay-and-bucket-span/340886)

<div class="topic-metadata">

**Author:** [@Aniket\_Pant](https://discuss.elastic.co/u/Aniket_Pant)\
**Replies:** 1\
**Last updated:** [August 21, 2023, 7:26am UTC](https://discuss.elastic.co/t/what-is-query-delay-and-bucket-span/340886 "2023-08-21T07:26:21Z")

</div>

Hi Team We are running two jobs of anomaly detection where for one job we are using 10 min of bucket span and for second one we are using 1 hour bucket span. Query delay is same for both jobs i.e. default value. For bo…

---

## [Logtash url is not working](https://discuss.elastic.co/t/logtash-url-is-not-working/341176)

<div class="topic-metadata">

**Author:** [@younus](https://discuss.elastic.co/u/younus)\
**Replies:** 2\
**Last updated:** [August 21, 2023, 7:20am UTC](https://discuss.elastic.co/t/logtash-url-is-not-working/341176 "2023-08-21T07:20:59Z")

</div>

Error: Address already in use: bind Exception: Java::JavaNet::BindException Stack: sun.nio.ch.Net.bind0(Native Method) sun.nio.ch.Net.bind(sun/nio/ch/Net.java:555) sun.nio.ch.ServerSocketChannelImpl.netBind(sun/nio/c…

---

## [Error activating rule](https://discuss.elastic.co/t/error-activating-rule/340742)

<div class="topic-metadata">

**Author:** [@saudmajed99](https://discuss.elastic.co/u/saudmajed99)\
**Replies:** 5\
**Last updated:** [August 21, 2023, 6:42am UTC](https://discuss.elastic.co/t/error-activating-rule/340742 "2023-08-21T06:42:13Z")

</div>

Hi there, We have faced the issue when activated the rule and the appear this Error Alert type siem.signals is disabled because your basic license has expired My version ELK: 7.17.8 Basic license can you hlep me ?

---

## [Not able to completely delete a deployment](https://discuss.elastic.co/t/not-able-to-completely-delete-a-deployment/341201)

<div class="topic-metadata">

**Author:** [@steman-provinzial](https://discuss.elastic.co/u/steman-provinzial)\
**Replies:** 0\
**Last updated:** [August 21, 2023, 6:30am UTC](https://discuss.elastic.co/t/not-able-to-completely-delete-a-deployment/341201 "2023-08-21T06:30:43Z")

</div>

Hi there, I am trying to delete a deployment, but there is always a piece that does not get deleted. In logging and metrics I find this error message that could be related: "Elasticsearch version is not determined for…

---

## [Need critical user journey logs on Kibana to find out the errors what users get](https://discuss.elastic.co/t/need-critical-user-journey-logs-on-kibana-to-find-out-the-errors-what-users-get/341072)

<div class="topic-metadata">

**Author:** [@Rajeev3](https://discuss.elastic.co/u/Rajeev3)\
**Replies:** 1\
**Last updated:** [August 21, 2023, 5:56am UTC](https://discuss.elastic.co/t/need-critical-user-journey-logs-on-kibana-to-find-out-the-errors-what-users-get/341072 "2023-08-21T05:56:26Z")

</div>

Hi There, I just wanted to tell you that i have deployed ELK stack on an EC2 instance and have routed the logs with the help of side car container deployment with application container. And it really worked and i can ab…

[Previous page](https://discuss.elastic.co/latest.md?page=566)

[Next page](https://discuss.elastic.co/latest.md?page=568)
