# Latest

**URL:** https://discuss.elastic.co/latest.md?page=580

[Latest](https://discuss.elastic.co/latest.md) · [Categories](https://discuss.elastic.co/categories.md) · [Tags](https://discuss.elastic.co/tags.md)

**Page:** 581

---

## [Unable to create Synthetics projects using the API key](https://discuss.elastic.co/t/unable-to-create-synthetics-projects-using-the-api-key/340335)

<div class="topic-metadata">

**Author:** [@opensourcengineer](https://discuss.elastic.co/u/opensourcengineer)\
**Replies:** 0\
**Last updated:** [August 8, 2023, 7:37am UTC](https://discuss.elastic.co/t/unable-to-create-synthetics-projects-using-the-api-key/340335 "2023-08-08T07:37:00Z")

</div>

I am trying to create project in the monitors using the API key and getting the below error: TypeError: unusable command i used is: npx @elastic/synthetics init projects-itops version 8.4 containerisation deployment

---

## [\[.kibana\_task\_manager\] Action failed with 'Request timed out'](https://discuss.elastic.co/t/kibana-task-manager-action-failed-with-request-timed-out/340325)

<div class="topic-metadata">

**Author:** [@tegerei](https://discuss.elastic.co/u/tegerei)\
**Replies:** 2\
**Last updated:** [August 8, 2023, 7:26am UTC](https://discuss.elastic.co/t/kibana-task-manager-action-failed-with-request-timed-out/340325 "2023-08-08T07:26:44Z")

</div>

Hello, I upgraded an Elasticsearch cluster from 7.10 to 7.17.9. ES upgrade is fine, with all the nodes up. However, when upgrading Kibana, I got the error when it attempts to re-index. {"type":"log","@timestamp":"2023-…

---

## [\[version 8.9\] Kibana server is not ready yet](https://discuss.elastic.co/t/version-8-9-kibana-server-is-not-ready-yet/340316)

<div class="topic-metadata">

**Author:** [@SageJustus](https://discuss.elastic.co/u/SageJustus)\
**Replies:** 1\
**Last updated:** [August 8, 2023, 7:21am UTC](https://discuss.elastic.co/t/version-8-9-kibana-server-is-not-ready-yet/340316 "2023-08-08T07:21:31Z")

</div>

Kibana version: 8.9 Elasticsearch version: 8.9 Server OS version: Windows10 Describe the bug: Unable to start kibana. Steps to reproduce: start Elasticsearch, browser access http://localhost:9200/, get the followi…

---

## [Vega lite interactive visual](https://discuss.elastic.co/t/vega-lite-interactive-visual/339669)

<div class="topic-metadata">

**Author:** [@Akarsh\_Shaw](https://discuss.elastic.co/u/Akarsh_Shaw)\
**Replies:** 2\
**Last updated:** [August 8, 2023, 7:18am UTC](https://discuss.elastic.co/t/vega-lite-interactive-visual/339669 "2023-08-08T07:18:37Z")

</div>

I created a heatmap which is showing the failed transaction in hour bucket, and pie chart showing the error-code contributions. When I select any hour bucket in heatmap then it showing the correct error contribution in p…

---

## [Semantic search and text expansion query with self-deployed model](https://discuss.elastic.co/t/semantic-search-and-text-expansion-query-with-self-deployed-model/339708)

<div class="topic-metadata">

**Author:** [@camoneme](https://discuss.elastic.co/u/camoneme)\
**Replies:** 2\
**Last updated:** [August 8, 2023, 7:17am UTC](https://discuss.elastic.co/t/semantic-search-and-text-expansion-query-with-self-deployed-model/339708 "2023-08-08T07:17:42Z")

</div>

I'm trying to use the text expansion query to implement semantic search on a rank features field. I've read the ELSER documentation and understand the process. I'm using a local/downloaded elasticsearch on docker (not co…

---

## [Regarding traffic volume in fortinat firewall logs](https://discuss.elastic.co/t/regarding-traffic-volume-in-fortinat-firewall-logs/340327)

<div class="topic-metadata">

**Author:** [@TECHY\_GEEK](https://discuss.elastic.co/u/TECHY_GEEK)\
**Replies:** 0\
**Last updated:** [August 8, 2023, 6:48am UTC](https://discuss.elastic.co/t/regarding-traffic-volume-in-fortinat-firewall-logs/340327 "2023-08-08T06:48:28Z")

</div>

Hi! there, We are monitoring our Fortinet firewalls using Elasticsearch, Filebeat, and Kibana. But the traffic volume shown by the firewall's in-built dashboard is different from the traffic volume aggregated by Elastic…

---

## [Migration from ES V6.8 to V7.17 with an additional node](https://discuss.elastic.co/t/migration-from-es-v6-8-to-v7-17-with-an-additional-node/340252)

<div class="topic-metadata">

**Author:** [@Franco901](https://discuss.elastic.co/u/Franco901)\
**Replies:** 2\
**Last updated:** [August 8, 2023, 6:47am UTC](https://discuss.elastic.co/t/migration-from-es-v6-8-to-v7-17-with-an-additional-node/340252 "2023-08-08T06:47:43Z")

</div>

Hi there, I have a V6.8 instance with a ~350 GB index and plan to migrate to ES V7.17. I read that ES can migrate between major versions, so my idea was to setup a new V7.17 node and let him join to the existing V6.8 n…

---

## [Node Up and Down Alert](https://discuss.elastic.co/t/node-up-and-down-alert/340176)

<div class="topic-metadata">

**Author:** [@Aniket\_Pant](https://discuss.elastic.co/u/Aniket_Pant)\
**Replies:** 1\
**Last updated:** [August 8, 2023, 4:41am UTC](https://discuss.elastic.co/t/node-up-and-down-alert/340176 "2023-08-08T04:41:35Z")

</div>

I am using Elastic Cloud v8.8 and i want to create an alert for node up and down status using kibana alert. Please see the below screenshots. Screenshot-1 Screenshot-2 Screenshot-3 Screenshot-4 I am get…

---

## [Unique count function](https://discuss.elastic.co/t/unique-count-function/340320)

<div class="topic-metadata">

**Author:** [@MeghanaReddy](https://discuss.elastic.co/u/MeghanaReddy)\
**Replies:** 0\
**Last updated:** [August 8, 2023, 4:26am UTC](https://discuss.elastic.co/t/unique-count-function/340320 "2023-08-08T04:26:02Z")

</div>

I have created a table visualisation so on x-axis I have entity data and on y-axis I am having unique count of traceids function but I am getting unique count of traceids for each entity value is more than the count of …

---

## [How to do to show field values in Kibana alert?](https://discuss.elastic.co/t/how-to-do-to-show-field-values-in-kibana-alert/340319)

<div class="topic-metadata">

**Author:** [@aungsoemin](https://discuss.elastic.co/u/aungsoemin)\
**Replies:** 0\
**Last updated:** [August 8, 2023, 4:12am UTC](https://discuss.elastic.co/t/how-to-do-to-show-field-values-in-kibana-alert/340319 "2023-08-08T04:12:38Z")

</div>

Hi Everyone, I created the custom rule to get the alert when there is successful login from public IP for Windows host. The lucene query is as per below. (winlog.channel:Security AND winlog.event\_id:4624 AND (NOT ((win…

---

## [Is there any performance comparison between the default index codec and best\_compression?](https://discuss.elastic.co/t/is-there-any-performance-comparison-between-the-default-index-codec-and-best-compression/340312)

<div class="topic-metadata">

**Author:** [@leandrojmp](https://discuss.elastic.co/u/leandrojmp)\
**Replies:** 0\
**Last updated:** [August 8, 2023, 3:17am UTC](https://discuss.elastic.co/t/is-there-any-performance-comparison-between-the-default-index-codec-and-best-compression/340312 "2023-08-08T03:17:18Z")

</div>

Hello, I'm looking into ways to optimize the disk usage of my indices on my cluster and before go on the route to remove the \_source field I've decided to try and change the index codec to best\_compression. The documen…

---

## [Combined grok pattern for customized logs](https://discuss.elastic.co/t/combined-grok-pattern-for-customized-logs/338535)

<div class="topic-metadata">

**Author:** [@shailendra1](https://discuss.elastic.co/u/shailendra1)\
**Replies:** 20\
**Last updated:** [August 8, 2023, 3:09am UTC](https://discuss.elastic.co/t/combined-grok-pattern-for-customized-logs/338535 "2023-08-08T03:09:23Z")

</div>

i am looking some help and guidenace for parsing the customized logs in one file. i have httpd access logs which have two format and i need to prepare the logstash config/filtering the data. so i tried two different pat…

---

## [What's the difference between consumption-based and resource-based pricing?](https://discuss.elastic.co/t/whats-the-difference-between-consumption-based-and-resource-based-pricing/340308)

<div class="topic-metadata">

**Author:** [@Ernest\_Dong](https://discuss.elastic.co/u/Ernest_Dong)\
**Replies:** 1\
**Last updated:** [August 8, 2023, 2:44am UTC](https://discuss.elastic.co/t/whats-the-difference-between-consumption-based-and-resource-based-pricing/340308 "2023-08-08T02:44:12Z")

</div>

I see two billing models on this page and wondering: does the resource-based model mean I have to pay for ECU of kibana node even if I'm not doing analytics? does the consumption-based model mean I wouldn't need to pay…

---

## [Painless, watcher, alerts](https://discuss.elastic.co/t/painless-watcher-alerts/340305)

<div class="topic-metadata">

**Author:** [@sunny2502](https://discuss.elastic.co/u/sunny2502)\
**Replies:** 0\
**Last updated:** [August 8, 2023, 12:00am UTC](https://discuss.elastic.co/t/painless-watcher-alerts/340305 "2023-08-08T00:00:46Z")

</div>

Hi I need to maintain key value pair for my output of transform block and send that to action block to send email to particular value its key. my sample code is below, my issue is in action block my payload is not getti…

---

## [Lucene Regex issues](https://discuss.elastic.co/t/lucene-regex-issues/339869)

<div class="topic-metadata">

**Author:** [@turboz](https://discuss.elastic.co/u/turboz)\
**Replies:** 2\
**Last updated:** [August 7, 2023, 10:21pm UTC](https://discuss.elastic.co/t/lucene-regex-issues/339869 "2023-08-07T22:21:06Z")

</div>

I'm trying to use some regex and its becoming frustrating. It appears the syntax is not respected around the Kibana interface. For example, I can exclude via regex with visualizations. However I noticed if you choose to…

---

## [Issues Moving Elasticsearch and Kibana to new server (with all existing custom indexes and dashboards)](https://discuss.elastic.co/t/issues-moving-elasticsearch-and-kibana-to-new-server-with-all-existing-custom-indexes-and-dashboards/340189)

<div class="topic-metadata">

**Author:** [@Akjal](https://discuss.elastic.co/u/Akjal)\
**Replies:** 10\
**Last updated:** [August 7, 2023, 8:44pm UTC](https://discuss.elastic.co/t/issues-moving-elasticsearch-and-kibana-to-new-server-with-all-existing-custom-indexes-and-dashboards/340189 "2023-08-07T20:44:45Z")

</div>

Hello there, I am working on a large ec2 ubuntu instance where I manually downloaded and installed elasticsearch and kibana (I didn't use docker) . I connected my stack with external data sources and made a lot of custo…

---

## [Export connector using saved objects api](https://discuss.elastic.co/t/export-connector-using-saved-objects-api/338011)

<div class="topic-metadata">

**Author:** [@Bhrugu\_Sharma](https://discuss.elastic.co/u/Bhrugu_Sharma)\
**Replies:** 4\
**Last updated:** [August 7, 2023, 7:42pm UTC](https://discuss.elastic.co/t/export-connector-using-saved-objects-api/338011 "2023-08-07T19:42:20Z")

</div>

I am trying to export connectors from few of my spaces using saved objects api the request body looks like body ={ "type": "connector", "includeReferencesDeep": True } but when i do the request it says "statu…

---

## [APM Java Agent 1.40 leads to NoClassDefFoundError (ReceiveMessageRequest) in S3 communication with AWS Java SDK v2](https://discuss.elastic.co/t/apm-java-agent-1-40-leads-to-noclassdeffounderror-receivemessagerequest-in-s3-communication-with-aws-java-sdk-v2/339188)

<div class="topic-metadata">

**Author:** [@IngoStrauch2020](https://discuss.elastic.co/u/IngoStrauch2020)\
**Replies:** 13\
**Last updated:** [August 7, 2023, 6:33pm UTC](https://discuss.elastic.co/t/apm-java-agent-1-40-leads-to-noclassdeffounderror-receivemessagerequest-in-s3-communication-with-aws-java-sdk-v2/339188 "2023-08-07T18:33:40Z")

</div>

APM Agent language and version: Java 1.40.0 Description of the problem including expected versus actual behavior. Please include screenshots (if relevant): We recently updated the APM Java Agent in our Spring Boot serv…

---

## [Fetch substring from a string in logstash filter](https://discuss.elastic.co/t/fetch-substring-from-a-string-in-logstash-filter/340223)

<div class="topic-metadata">

**Author:** [@Neelam\_Zanvar](https://discuss.elastic.co/u/Neelam_Zanvar)\
**Replies:** 1\
**Last updated:** [August 7, 2023, 5:36pm UTC](https://discuss.elastic.co/t/fetch-substring-from-a-string-in-logstash-filter/340223 "2023-08-07T17:36:04Z")

</div>

Hi, I have a field called url in elasticsearch document. The sample value for the field is /3dpassport/login I want to extract only the first string before / that is 3dpassport and store it in a field. Tried this copy…

---

## [Logstash Twitter error - no address for stream.twitter.com](https://discuss.elastic.co/t/logstash-twitter-error-no-address-for-stream-twitter-com/340238)

<div class="topic-metadata">

**Author:** [@Yochai\_Ben-Chaim](https://discuss.elastic.co/u/Yochai_Ben-Chaim)\
**Replies:** 1\
**Last updated:** [August 7, 2023, 5:27pm UTC](https://discuss.elastic.co/t/logstash-twitter-error-no-address-for-stream-twitter-com/340238 "2023-08-07T17:27:56Z")

</div>

I am trying to use the twitter plugin with the latest ELK stack (8.9.0). When I activate logstash -f myconf\_file.conf I am getting error messages messages : "no address for stream.twitter.com" My conf file is very bas…

---

## [Logstash unable to send network log to elastic search database but raw data successfully store in system](https://discuss.elastic.co/t/logstash-unable-to-send-network-log-to-elastic-search-database-but-raw-data-successfully-store-in-system/340243)

<div class="topic-metadata">

**Author:** [@Kiran\_K](https://discuss.elastic.co/u/Kiran_K)\
**Replies:** 1\
**Last updated:** [August 7, 2023, 5:22pm UTC](https://discuss.elastic.co/t/logstash-unable-to-send-network-log-to-elastic-search-database-but-raw-data-successfully-store-in-system/340243 "2023-08-07T17:22:10Z")

</div>

\[WARN \] 2023-08-07 08:45:44.506 \[\[main\]-pipeline-manager\] elasticsearch - Detected a 6.x and above cluster: the type event field won't be used to determine the document \_type {:es\_version=\>8} \[INFO \] 2023-08-07 08:45:44…

---

## [Search for docs from last 24h on data field not timestamp](https://discuss.elastic.co/t/search-for-docs-from-last-24h-on-data-field-not-timestamp/338199)

<div class="topic-metadata">

**Author:** [@lemospt](https://discuss.elastic.co/u/lemospt)\
**Replies:** 1\
**Last updated:** [August 7, 2023, 4:47pm UTC](https://discuss.elastic.co/t/search-for-docs-from-last-24h-on-data-field-not-timestamp/338199 "2023-08-07T16:47:39Z")

</div>

Hi, in my documents i have the field report\_last\_request, in kibana i need a query that get all documents that has the report\_last\_request date from last 24h. Hope is clear. Thanks in advance.

---

## [Slow query concerns, how to optimize?](https://discuss.elastic.co/t/slow-query-concerns-how-to-optimize/339902)

<div class="topic-metadata">

**Author:** [@chenlx594](https://discuss.elastic.co/u/chenlx594)\
**Replies:** 6\
**Last updated:** [August 7, 2023, 4:34pm UTC](https://discuss.elastic.co/t/slow-query-concerns-how-to-optimize/339902 "2023-08-07T16:34:44Z")

</div>

Originally, there was an index a1. Now, it's modified to have index a1 with alias A, and index a2 with alias A. When querying using alias A, the query speed increases from 7ms to 60ms compared to directly querying using …

---

## [Making complete row of data table clickable (Drilldown)](https://discuss.elastic.co/t/making-complete-row-of-data-table-clickable-drilldown/340288)

<div class="topic-metadata">

**Author:** [@hughes](https://discuss.elastic.co/u/hughes)\
**Replies:** 0\
**Last updated:** [August 7, 2023, 4:22pm UTC](https://discuss.elastic.co/t/making-complete-row-of-data-table-clickable-drilldown/340288 "2023-08-07T16:22:52Z")

</div>

This is to further expand off of this post. I have the paid version of elastic, but still am unable to execute the drilldown from clicking the table row. There are three dots on the far right side of the row that I inst…

---

## [Metricbeat docker.network\_summary does not work from within a container?](https://discuss.elastic.co/t/metricbeat-docker-network-summary-does-not-work-from-within-a-container/339226)

<div class="topic-metadata">

**Author:** [@jerrac](https://discuss.elastic.co/u/jerrac)\
**Replies:** 2\
**Last updated:** [August 7, 2023, 3:33pm UTC](https://discuss.elastic.co/t/metricbeat-docker-network-summary-does-not-work-from-within-a-container/339226 "2023-08-07T15:33:49Z")

</div>

So, judging from this error I've been getting today: lanewell-metricbeat-app | {"log.level":"error","@timestamp":"2023-07-25T20:06:51.398Z","log.origin":{"file.name":"module/wrapper.go","file.line":263},"message":"Erro…

---

## [Kibana canvas auto refresh dont' work and sets automaticcaly to manual](https://discuss.elastic.co/t/kibana-canvas-auto-refresh-dont-work-and-sets-automaticcaly-to-manual/339932)

<div class="topic-metadata">

**Author:** [@PRASHANT\_MEHTA](https://discuss.elastic.co/u/PRASHANT_MEHTA)\
**Replies:** 4\
**Last updated:** [August 7, 2023, 3:17pm UTC](https://discuss.elastic.co/t/kibana-canvas-auto-refresh-dont-work-and-sets-automaticcaly-to-manual/339932 "2023-08-07T15:17:16Z")

</div>

Hello All, I'm trying to embedd the kibana canvas in my custom webui as LIVE ALERTS for admins. The auto refresh interval dosen't seems to work correctly or has some bugs, not sure. Everytime I'm setting auto refresh …

---

## [Get \`Error: s is undefined\` when browsing to "Management-\>Data-\>Transforms"](https://discuss.elastic.co/t/get-error-s-is-undefined-when-browsing-to-management-data-transforms/340276)

<div class="topic-metadata">

**Author:** [@tolland](https://discuss.elastic.co/u/tolland)\
**Replies:** 1\
**Last updated:** [August 7, 2023, 3:13pm UTC](https://discuss.elastic.co/t/get-error-s-is-undefined-when-browsing-to-management-data-transforms/340276 "2023-08-07T15:13:47Z")

</div>

I have a kibana / elasticsearch installed from rpms version 8.9.0 on rocky-8 linux. Security is disabled. When I browse to the Transforms menu: http://elasticsearch.lan:5601/app/management/data/transform I get the foll…

---

## [Kibana Message Parse](https://discuss.elastic.co/t/kibana-message-parse/339976)

<div class="topic-metadata">

**Author:** [@Kumbum](https://discuss.elastic.co/u/Kumbum)\
**Replies:** 10\
**Last updated:** [August 7, 2023, 3:09pm UTC](https://discuss.elastic.co/t/kibana-message-parse/339976 "2023-08-07T15:09:21Z")

</div>

I have a custom log file in a source machine and it comes as a single-line log through "message" attribute to the Dashboard message = \<INFO/ERROR/FATAL, etc\>, , , , , , I want this message gets split as below. messag…

---

## [Delete data stream and all it's index](https://discuss.elastic.co/t/delete-data-stream-and-all-its-index/340085)

<div class="topic-metadata">

**Author:** [@elasticforme](https://discuss.elastic.co/u/elasticforme)\
**Replies:** 3\
**Last updated:** [August 7, 2023, 3:03pm UTC](https://discuss.elastic.co/t/delete-data-stream-and-all-its-index/340085 "2023-08-07T15:03:12Z")

</div>

I have a test data stream. it works fine. But now I am trying to delete it and I can't When I do delete via command or via GUI it recreates it self DELETE /\_data\_stream/msyos1-log I can't delete index template as wel…

---

## [Wazuh template ILM policy resets to blank post-upgrade to 4.4.4](https://discuss.elastic.co/t/wazuh-template-ilm-policy-resets-to-blank-post-upgrade-to-4-4-4/340260)

<div class="topic-metadata">

**Author:** [@Nightingale\_John](https://discuss.elastic.co/u/Nightingale_John)\
**Replies:** 2\
**Last updated:** [August 7, 2023, 2:39pm UTC](https://discuss.elastic.co/t/wazuh-template-ilm-policy-resets-to-blank-post-upgrade-to-4-4-4/340260 "2023-08-07T14:39:58Z")

</div>

Hi, I use Wazuh with Elastic, and recently I performed an update of wazuh to 4.4.4. Since the upgrade the ILM policy on the Wazuh template reset to null and therefore indexes didn't roll over. I thought i fixed the ind…

[Previous page](https://discuss.elastic.co/latest.md?page=579)

[Next page](https://discuss.elastic.co/latest.md?page=581)
