# Latest

**URL:** https://discuss.elastic.co/latest.md?page=573

[Latest](https://discuss.elastic.co/latest.md) · [Categories](https://discuss.elastic.co/categories.md) · [Tags](https://discuss.elastic.co/tags.md)

**Page:** 574

---

## [Unable to create Runtime field \[ conflict at fetch\]](https://discuss.elastic.co/t/unable-to-create-runtime-field-conflict-at-fetch/340686)

<div class="topic-metadata">

**Author:** [@shiktec](https://discuss.elastic.co/u/shiktec)\
**Replies:** 1\
**Last updated:** [August 14, 2023, 12:02pm UTC](https://discuss.elastic.co/t/unable-to-create-runtime-field-conflict-at-fetch/340686 "2023-08-14T12:02:10Z")

</div>

I am trying to set up Airflow observability via Statsd and Elastic. I wanted to create a runtime field. the Scripts checks out well , but when i try to save the runtime fields it shows below error the Entire conf…

---

## [Aliases are lost after Elasticsearch Docker container recreate](https://discuss.elastic.co/t/aliases-are-lost-after-elasticsearch-docker-container-recreate/340743)

<div class="topic-metadata">

**Author:** [@Maxim\_Dubrovin](https://discuss.elastic.co/u/Maxim_Dubrovin)\
**Replies:** 0\
**Last updated:** [August 14, 2023, 10:43am UTC](https://discuss.elastic.co/t/aliases-are-lost-after-elasticsearch-docker-container-recreate/340743 "2023-08-14T10:43:56Z")

</div>

Hello. Our project have Elasticsearch and Logstash running as Docker containers. Both started with one "docker-compose up" command. Containers config in "docker-compose.yaml" file. Elasticsearch successfully persists dat…

---

## [I want to Use Logstash Input Plugin for capturing the audit log of Elasticsearch. But not understood which one should be suitable for this](https://discuss.elastic.co/t/i-want-to-use-logstash-input-plugin-for-capturing-the-audit-log-of-elasticsearch-but-not-understood-which-one-should-be-suitable-for-this/340745)

<div class="topic-metadata">

**Author:** [@Subrato1](https://discuss.elastic.co/u/Subrato1)\
**Replies:** 0\
**Last updated:** [August 14, 2023, 10:49am UTC](https://discuss.elastic.co/t/i-want-to-use-logstash-input-plugin-for-capturing-the-audit-log-of-elasticsearch-but-not-understood-which-one-should-be-suitable-for-this/340745 "2023-08-14T10:49:54Z")

</div>

I am trying to capture audit logs for all the executed query in Elasticsearch. i.e. DSL, EQL, SQL.

---

## [Creating an Index with .NET client](https://discuss.elastic.co/t/creating-an-index-with-net-client/340744)

<div class="topic-metadata">

**Author:** [@NekoNova](https://discuss.elastic.co/u/NekoNova)\
**Replies:** 0\
**Last updated:** [August 14, 2023, 10:44am UTC](https://discuss.elastic.co/t/creating-an-index-with-net-client/340744 "2023-08-14T10:44:18Z")

</div>

Hello, I am currently working on a project in C#.NET and we gave created Poco objects for our documents. Can I do something same for creating the Index? We have an exported index in JSON that we want to represent in c…

---

## [Embed Kibana Dashboard With Auto Authentication](https://discuss.elastic.co/t/embed-kibana-dashboard-with-auto-authentication/339278)

<div class="topic-metadata">

**Author:** [@nilaksha](https://discuss.elastic.co/u/nilaksha)\
**Replies:** 1\
**Last updated:** [August 14, 2023, 10:39am UTC](https://discuss.elastic.co/t/embed-kibana-dashboard-with-auto-authentication/339278 "2023-08-14T10:39:24Z")

</div>

hello, I use an embed dashboard to share dashboard to our application users. so when embed screen loading there is kibana basic authentication menu prompt. but I don't need to show another screen to users to login becau…

---

## [JSON serialization differences from HLRC to new Java API Client](https://discuss.elastic.co/t/json-serialization-differences-from-hlrc-to-new-java-api-client/340651)

<div class="topic-metadata">

**Author:** [@toddcarv](https://discuss.elastic.co/u/toddcarv)\
**Replies:** 1\
**Last updated:** [August 14, 2023, 10:20am UTC](https://discuss.elastic.co/t/json-serialization-differences-from-hlrc-to-new-java-api-client/340651 "2023-08-14T10:20:40Z")

</div>

With the HLRC, the timestamp field below is serialized as "2023-08-10T18:59:59.143Z". However, with the new Java API Client it is serialized as a long time. This is with the new BulkIngester. Is there a way to customize …

---

## [Filebeat cannot connect with Elasticsearch (ELK Stack setup for Suricata)](https://discuss.elastic.co/t/filebeat-cannot-connect-with-elasticsearch-elk-stack-setup-for-suricata/340728)

<div class="topic-metadata">

**Author:** [@jstnolmeme](https://discuss.elastic.co/u/jstnolmeme)\
**Replies:** 1\
**Last updated:** [August 14, 2023, 10:15am UTC](https://discuss.elastic.co/t/filebeat-cannot-connect-with-elasticsearch-elk-stack-setup-for-suricata/340728 "2023-08-14T10:15:18Z")

</div>

I'm new to Elastic, so please go easy on me :)). I am working on a project that requires ELK stack to monitor and display dashboards, based on logs collected from the IDS, Suricata. I am running a Droplet instance on D…

---

## [Kibana authentication through script- saved object install and authenticate](https://discuss.elastic.co/t/kibana-authentication-through-script-saved-object-install-and-authenticate/340620)

<div class="topic-metadata">

**Author:** [@PRASHANT\_MEHTA](https://discuss.elastic.co/u/PRASHANT_MEHTA)\
**Replies:** 1\
**Last updated:** [August 14, 2023, 10:02am UTC](https://discuss.elastic.co/t/kibana-authentication-through-script-saved-object-install-and-authenticate/340620 "2023-08-14T10:02:40Z")

</div>

Hello All, -- Question is in context of automatic (through script) installation of kibana software. -- We have enabled basic authentication for kibana and also enabled anonymous. -- and we need to import SavedObjects …

---

## [Doc Size Limits](https://discuss.elastic.co/t/doc-size-limits/340737)

<div class="topic-metadata">

**Author:** [@dawiro](https://discuss.elastic.co/u/dawiro)\
**Replies:** 0\
**Last updated:** [August 14, 2023, 9:58am UTC](https://discuss.elastic.co/t/doc-size-limits/340737 "2023-08-14T09:58:53Z")

</div>

Hi, Can I ask, does fb impose any default doc size limits? We're getting occasional reports of the beginning of message fields being truncated even though we're using combine\_partial on the docker input. The version of …

---

## [Illegal\_argument\_exception: rollover target \[log-alias\] does not point to a write index](https://discuss.elastic.co/t/illegal-argument-exception-rollover-target-log-alias-does-not-point-to-a-write-index/340735)

<div class="topic-metadata">

**Author:** [@Srijitha](https://discuss.elastic.co/u/Srijitha)\
**Replies:** 0\
**Last updated:** [August 14, 2023, 9:47am UTC](https://discuss.elastic.co/t/illegal-argument-exception-rollover-target-log-alias-does-not-point-to-a-write-index/340735 "2023-08-14T09:47:13Z")

</div>

I have EFK stack in Kubernetes, fluentd is responsible for sending application logs to elasticsearch and the index is in this format \[ logstash-%Y-%m-%d \] so it creates a new index every day. I have created Index lifecyc…

---

## [Transaction\_ignore\_urls do not work for agent dotnet](https://discuss.elastic.co/t/transaction-ignore-urls-do-not-work-for-agent-dotnet/340724)

<div class="topic-metadata">

**Author:** [@Wojciech\_Kwiecien](https://discuss.elastic.co/u/Wojciech_Kwiecien)\
**Replies:** 1\
**Last updated:** [August 14, 2023, 9:18am UTC](https://discuss.elastic.co/t/transaction-ignore-urls-do-not-work-for-agent-dotnet/340724 "2023-08-14T09:18:04Z")

</div>

Hello, I have a problem with the correct working functionality which is to Ignore transactions based on URLs. I search for this problem on this forum but I only found problems with java agent not dotnet. Kibana version:…

---

## [Object mapping for ... tried to parse field \[content\_range\] as object, but found a concrete value](https://discuss.elastic.co/t/object-mapping-for-tried-to-parse-field-content-range-as-object-but-found-a-concrete-value/340726)

<div class="topic-metadata">

**Author:** [@bohm](https://discuss.elastic.co/u/bohm)\
**Replies:** 0\
**Last updated:** [August 14, 2023, 9:08am UTC](https://discuss.elastic.co/t/object-mapping-for-tried-to-parse-field-content-range-as-object-but-found-a-concrete-value/340726 "2023-08-14T09:08:23Z")

</div>

Hello, Found some informative posts already, but guess I misintepreted some info. This is logstash logging: :response=\>{"index"=\>{"\_index"=\>"logstash-http-2023.08.14", "\_type"=\>"\_doc", "\_id"=\>"BobW8okBwOC2FKopPOGW", "…

---

## [What is best node configuration in 5 node](https://discuss.elastic.co/t/what-is-best-node-configuration-in-5-node/340709)

<div class="topic-metadata">

**Author:** [@hyungsun\_lim](https://discuss.elastic.co/u/hyungsun_lim)\
**Replies:** 1\
**Last updated:** [August 14, 2023, 9:08am UTC](https://discuss.elastic.co/t/what-is-best-node-configuration-in-5-node/340709 "2023-08-14T09:08:06Z")

</div>

I have 5 nodes for elasticsearch. When i use 3 nodes, i just use them as default mode. Is it okay to use default mode for 5 nodes? Or is there any good options to set role for 5 nodes?

---

## [Uptime Page Error - Failed to execute 'btoa' on 'Window'](https://discuss.elastic.co/t/uptime-page-error-failed-to-execute-btoa-on-window/340630)

<div class="topic-metadata">

**Author:** [@praveen\_raju](https://discuss.elastic.co/u/praveen_raju)\
**Replies:** 1\
**Last updated:** [August 14, 2023, 9:05am UTC](https://discuss.elastic.co/t/uptime-page-error-failed-to-execute-btoa-on-window/340630 "2023-08-14T09:05:52Z")

</div>

Hello, We are monitoring around 1500 endpoints using Heartbeat. While pagination we are getting this strange error. Is it something related to character on the ID or NAME using in the heartbeat configurations ??? Pleas…

---

## [Awslog driver docker](https://discuss.elastic.co/t/awslog-driver-docker/340723)

<div class="topic-metadata">

**Author:** [@Ryan5](https://discuss.elastic.co/u/Ryan5)\
**Replies:** 0\
**Last updated:** [August 14, 2023, 8:42am UTC](https://discuss.elastic.co/t/awslog-driver-docker/340723 "2023-08-14T08:42:30Z")

</div>

We are using AWS ECS EC2 with the awslog docker driver however, the issue is that the awslog driver outputs a binary file with all the .json log lines beginning with stderr and some unicode. Beats seems to crash when the…

---

## [Grok pattern failing for apache custom logs](https://discuss.elastic.co/t/grok-pattern-failing-for-apache-custom-logs/340529)

<div class="topic-metadata">

**Author:** [@shailendra1](https://discuss.elastic.co/u/shailendra1)\
**Replies:** 7\
**Last updated:** [August 14, 2023, 6:24am UTC](https://discuss.elastic.co/t/grok-pattern-failing-for-apache-custom-logs/340529 "2023-08-14T06:24:28Z")

</div>

i am facing issue for my grok is failing for the apache custom logs as beolw 10.52.245.67 - - \[12/Jul/2023:08:08:51 +0800\] uibau1a "GET /login/runtime.6b0e772316ccb94a9291.js HTTP/1.1" 200 2289bytes "10.168.224.18, 10.5…

---

## [Encryption in Elasticsearch](https://discuss.elastic.co/t/encryption-in-elasticsearch/340711)

<div class="topic-metadata">

**Author:** [@ANUBHAV\_GUPTA](https://discuss.elastic.co/u/ANUBHAV_GUPTA)\
**Replies:** 1\
**Last updated:** [August 14, 2023, 6:17am UTC](https://discuss.elastic.co/t/encryption-in-elasticsearch/340711 "2023-08-14T06:17:05Z")

</div>

Just wanted to get some idea from the folks here regarding Elasticsearch data encryption. So, I am aware about 2 ways we can get our data encrypt in Elasticsearch:- Using some encyption/tokenization on data before ing…

---

## [Logstash parsing](https://discuss.elastic.co/t/logstash-parsing/339929)

<div class="topic-metadata">

**Author:** [@dilipchiru](https://discuss.elastic.co/u/dilipchiru)\
**Replies:** 4\
**Last updated:** [August 14, 2023, 5:44am UTC](https://discuss.elastic.co/t/logstash-parsing/339929 "2023-08-14T05:44:21Z")

</div>

Hi Team, I have 2 Fields which is From and TO which contains set of values which is comma separated. For example: "from" : "Loin, Elephant, cat, movie, John" "to" : "Loin, Elephant, cat, movie, John, USA " Now we wo…

---

## [ILM policy to rollover data from hot to frozen without replica shards](https://discuss.elastic.co/t/ilm-policy-to-rollover-data-from-hot-to-frozen-without-replica-shards/340518)

<div class="topic-metadata">

**Author:** [@sajjad\_akram](https://discuss.elastic.co/u/sajjad_akram)\
**Replies:** 2\
**Last updated:** [August 14, 2023, 5:06am UTC](https://discuss.elastic.co/t/ilm-policy-to-rollover-data-from-hot-to-frozen-without-replica-shards/340518 "2023-08-14T05:06:34Z")

</div>

Hi, My indices in hot phase is configured to have 2primary and 2replica shards. I want to have an ilm policy to rollover data from hot phase to frozen phase daily but without the replicas . i see that there is an optio…

---

## [Ingest Pipeline Stats - Processor \`if\` (conditional) measurement](https://discuss.elastic.co/t/ingest-pipeline-stats-processor-if-conditional-measurement/340707)

<div class="topic-metadata">

**Author:** [@BenB196](https://discuss.elastic.co/u/BenB196)\
**Replies:** 0\
**Last updated:** [August 13, 2023, 8:18pm UTC](https://discuss.elastic.co/t/ingest-pipeline-stats-processor-if-conditional-measurement/340707 "2023-08-13T20:18:52Z")

</div>

Hi All, I have a question related to the Ingest Pipeline stats that are part of the node stats api. The API returns the time it takes to process a doc for a given processor, but what isn't clear to me is does the time …

---

## [Error log "Couldn't index event to elastic"](https://discuss.elastic.co/t/error-log-couldnt-index-event-to-elastic/340704)

<div class="topic-metadata">

**Author:** [@yuswanul](https://discuss.elastic.co/u/yuswanul)\
**Replies:** 1\
**Last updated:** [August 13, 2023, 6:22pm UTC](https://discuss.elastic.co/t/error-log-couldnt-index-event-to-elastic/340704 "2023-08-13T18:22:07Z")

</div>

Hi there, I want to confirm, if I got "Could not index event to elasticsearch" error, will it be retried if the reason that log has been resolved? I got this error and the reason shows me it caused by "Limit total field…

---

## [Moment.js Vulnerability](https://discuss.elastic.co/t/moment-js-vulnerability/340688)

<div class="topic-metadata">

**Author:** [@Ruwi](https://discuss.elastic.co/u/Ruwi)\
**Replies:** 1\
**Last updated:** [August 13, 2023, 6:14pm UTC](https://discuss.elastic.co/t/moment-js-vulnerability/340688 "2023-08-13T18:14:54Z")

</div>

Hello, I am using Elasticsearch-Kibana version 7.10.2. In the security tests, it was observed that there was a vulnerability in moment.js software. moment.js 2.28.0 --\> CVE-2022-24785 Can I update this software, does…

---

## [Excessive 4673 events due to chromium](https://discuss.elastic.co/t/excessive-4673-events-due-to-chromium/340643)

<div class="topic-metadata">

**Author:** [@Nightingale\_John](https://discuss.elastic.co/u/Nightingale_John)\
**Replies:** 0\
**Last updated:** [August 11, 2023, 2:20pm UTC](https://discuss.elastic.co/t/excessive-4673-events-due-to-chromium/340643 "2023-08-11T14:20:45Z")

</div>

Hi All, We're seeing excessive 4673 events which appear to be linked to the chromium issue causing failures against SeProfileSingleProcessPrivilege; this appears to be well know by Microsoft. Ideally we would like to e…

---

## [Deployed elasticsearch and kibana throgh eck and helm facing elastic didn't load issue](https://discuss.elastic.co/t/deployed-elasticsearch-and-kibana-throgh-eck-and-helm-facing-elastic-didnt-load-issue/339051)

<div class="topic-metadata">

**Author:** [@MahithaSarala](https://discuss.elastic.co/u/MahithaSarala)\
**Replies:** 2\
**Last updated:** [August 13, 2023, 4:39pm UTC](https://discuss.elastic.co/t/deployed-elasticsearch-and-kibana-throgh-eck-and-helm-facing-elastic-didnt-load-issue/339051 "2023-08-13T16:39:26Z")

</div>

Hi Team, Currently deployed ELK 7.14.0 version through helm without security and authentication. We have tried to upgrade from 7.14 to 8.5.1 & 8.5.3 Procedure followed in ordered to upgraded from 7.14 to 8.5.1 We ha…

---

## [Converting relative date like "now-30d" to absolute date/time format](https://discuss.elastic.co/t/converting-relative-date-like-now-30d-to-absolute-date-time-format/340701)

<div class="topic-metadata">

**Author:** [@Mohammad\_Rezaei](https://discuss.elastic.co/u/Mohammad_Rezaei)\
**Replies:** 0\
**Last updated:** [August 13, 2023, 9:08am UTC](https://discuss.elastic.co/t/converting-relative-date-like-now-30d-to-absolute-date-time-format/340701 "2023-08-13T09:08:33Z")

</div>

I am writing a plugin for Kibana. I want to display a chart: \<Chart\> \<Axis id="bottom" title={dateFormatter(startDate)} position={Position.Bottom} tickFormat={dateFormatter} /\> \<Axis id="left" …

---

## [Visualization: Controls - Not refreshing new values in options-list](https://discuss.elastic.co/t/visualization-controls-not-refreshing-new-values-in-options-list/340697)

<div class="topic-metadata">

**Author:** [@Kumbum](https://discuss.elastic.co/u/Kumbum)\
**Replies:** 0\
**Last updated:** [August 13, 2023, 4:18am UTC](https://discuss.elastic.co/t/visualization-controls-not-refreshing-new-values-in-options-list/340697 "2023-08-13T04:18:33Z")

</div>

Hi, I have an issue with control visualization; I am unable to see new values in the drop-down field of the options list. Please let me know how to fix this.

---

## [100% sampling vs. 10% sampling](https://discuss.elastic.co/t/100-sampling-vs-10-sampling/340694)

<div class="topic-metadata">

**Author:** [@jmkdev](https://discuss.elastic.co/u/jmkdev)\
**Replies:** 0\
**Last updated:** [August 12, 2023, 11:55pm UTC](https://discuss.elastic.co/t/100-sampling-vs-10-sampling/340694 "2023-08-12T23:55:49Z")

</div>

APM Java Agent language All versions Has any else tress tested the APM Java agent at extreme loads and measured the CPU and Memory resource hit to the service? We have and 100% sampling is possible with a small footprin…

---

## [Updating enrich index for pipeline](https://discuss.elastic.co/t/updating-enrich-index-for-pipeline/339732)

<div class="topic-metadata">

**Author:** [@veryelastic](https://discuss.elastic.co/u/veryelastic)\
**Replies:** 7\
**Last updated:** [August 12, 2023, 7:50pm UTC](https://discuss.elastic.co/t/updating-enrich-index-for-pipeline/339732 "2023-08-12T19:50:27Z")

</div>

Hello, I have an 8.8.1 cluster, and am running documents through a series of ingest pipelines. One of these pipelines is an enrich stage. This data which is used to enrich the documents is sourced from an index via an…

---

## [Regarding tenants](https://discuss.elastic.co/t/regarding-tenants/340234)

<div class="topic-metadata">

**Author:** [@Ajay\_Kumar.S](https://discuss.elastic.co/u/Ajay_Kumar.S)\
**Replies:** 3\
**Last updated:** [August 12, 2023, 3:03pm UTC](https://discuss.elastic.co/t/regarding-tenants/340234 "2023-08-12T15:03:09Z")

</div>

Hello community How can I create a tenant in ELK 8.9.0 version?

---

## [How to query Elasticsearch datasource in Grafana?](https://discuss.elastic.co/t/how-to-query-elasticsearch-datasource-in-grafana/340682)

<div class="topic-metadata">

**Author:** [@ZahraZare](https://discuss.elastic.co/u/ZahraZare)\
**Replies:** 0\
**Last updated:** [August 12, 2023, 10:49am UTC](https://discuss.elastic.co/t/how-to-query-elasticsearch-datasource-in-grafana/340682 "2023-08-12T10:49:39Z")

</div>

I want to use an index in Elasticsearch as a data source in Grafana. But I can't query it and extract a specific field from it. I want to have only the data of the fields I want as output from among several fields in thi…

[Previous page](https://discuss.elastic.co/latest.md?page=572)

[Next page](https://discuss.elastic.co/latest.md?page=574)
