# Latest

**URL:** https://discuss.elastic.co/latest.md?page=604

[Latest](https://discuss.elastic.co/latest.md) · [Categories](https://discuss.elastic.co/categories.md) · [Tags](https://discuss.elastic.co/tags.md)

**Page:** 605

---

## [Truststore does not contain any trusted certificate entries](https://discuss.elastic.co/t/truststore-does-not-contain-any-trusted-certificate-entries/338610)

<div class="topic-metadata">

**Author:** [@sslgeorge](https://discuss.elastic.co/u/sslgeorge)\
**Replies:** 0\
**Last updated:** [July 17, 2023, 11:36pm UTC](https://discuss.elastic.co/t/truststore-does-not-contain-any-trusted-certificate-entries/338610 "2023-07-17T23:36:57Z")

</div>

I used openssl to generate self signed certs for elasticsearch, but I am unable to use this certs to start elasticsearch. I keep getting the below error \[2023-07-16T19:42:22,649\]\[ERROR\]\[o.e.b.Elasticsearch \] \[Mac…

---

## [Composite aggregation returns after\_key even when there are no more buckets](https://discuss.elastic.co/t/composite-aggregation-returns-after-key-even-when-there-are-no-more-buckets/338606)

<div class="topic-metadata">

**Author:** [@cdhowie](https://discuss.elastic.co/u/cdhowie)\
**Replies:** 0\
**Last updated:** [July 17, 2023, 10:00pm UTC](https://discuss.elastic.co/t/composite-aggregation-returns-after-key-even-when-there-are-no-more-buckets/338606 "2023-07-17T22:00:35Z")

</div>

I've been working on a query that performs a composite aggregation with a large number of buckets. When I set the aggregation size to 50,000, all buckets fit in the response. However, after\_key is still present in the re…

---

## [General Log Warning Question](https://discuss.elastic.co/t/general-log-warning-question/338443)

<div class="topic-metadata">

**Author:** [@Ray3](https://discuss.elastic.co/u/Ray3)\
**Replies:** 6\
**Last updated:** [July 17, 2023, 8:38pm UTC](https://discuss.elastic.co/t/general-log-warning-question/338443 "2023-07-17T20:38:36Z")

</div>

I deployed metricbeat to a node. Unless I use superuser role, I will get warnings in the log, that it cannot take certain actions as the api key used is unauthorized. I do see data reported in kibana, it appears metric…

---

## [Installer Claims Version is Already Installed](https://discuss.elastic.co/t/installer-claims-version-is-already-installed/338603)

<div class="topic-metadata">

**Author:** [@mreeg](https://discuss.elastic.co/u/mreeg)\
**Replies:** 0\
**Last updated:** [July 17, 2023, 7:21pm UTC](https://discuss.elastic.co/t/installer-claims-version-is-already-installed/338603 "2023-07-17T19:21:45Z")

</div>

Hello, I'm trying to Install a piece of software that utilizes Elasticsearch, and includes the Elasticsearch install as part of the installation process. Due to other errors, I had to uninstall the software (includin…

---

## [Logstash HTTP code 400 {:response\_code=\>400}](https://discuss.elastic.co/t/logstash-http-code-400-response-code-400/338501)

<div class="topic-metadata">

**Author:** [@Indeed2000](https://discuss.elastic.co/u/Indeed2000)\
**Replies:** 1\
**Last updated:** [July 17, 2023, 7:19pm UTC](https://discuss.elastic.co/t/logstash-http-code-400-response-code-400/338501 "2023-07-17T19:19:13Z")

</div>

Hi when i try to send data with logstash to influxdb return this error: \[ERROR\] 2023-07-17 09:21:36.133 \[\[main\]\>worker1\] http - Encountered non-2xx HTTP code 400 {:response\_code=\>400, :url=\>"http://192.168.1.2:8086/api…

---

## [99th Percentile of index rate](https://discuss.elastic.co/t/99th-percentile-of-index-rate/338569)

<div class="topic-metadata">

**Author:** [@veryelastic](https://discuss.elastic.co/u/veryelastic)\
**Replies:** 1\
**Last updated:** [July 17, 2023, 6:57pm UTC](https://discuss.elastic.co/t/99th-percentile-of-index-rate/338569 "2023-07-17T18:57:34Z")

</div>

Hello, I have an Elastic 8.8.1 cluster up and running, and being monitored via Metricbeat feeding into stack monitoring, and I can see a chart of index rate. I'd like to visualise the 99th percentile index rate across …

---

## [How to delete docs.deleted from ELK?](https://discuss.elastic.co/t/how-to-delete-docs-deleted-from-elk/338597)

<div class="topic-metadata">

**Author:** [@Yuri\_Pires](https://discuss.elastic.co/u/Yuri_Pires)\
**Replies:** 1\
**Last updated:** [July 17, 2023, 6:50pm UTC](https://discuss.elastic.co/t/how-to-delete-docs-deleted-from-elk/338597 "2023-07-17T18:50:01Z")

</div>

Hello, in this logstash index I used the delete\_by\_query endpoint to clean old logs from storage, I was successful in this step, but I found that the docs are still on the HD and I want to delete them to free up space. h…

---

## [Is there an API to return Anomaly Detection Job results? (Not a Rule)](https://discuss.elastic.co/t/is-there-an-api-to-return-anomaly-detection-job-results-not-a-rule/338599)

<div class="topic-metadata">

**Author:** [@McJava1967](https://discuss.elastic.co/u/McJava1967)\
**Replies:** 2\
**Last updated:** [July 17, 2023, 6:24pm UTC](https://discuss.elastic.co/t/is-there-an-api-to-return-anomaly-detection-job-results-not-a-rule/338599 "2023-07-17T18:24:29Z")

</div>

Hi all. Is there an API (or some way) to programmatically return the results displayed on this page? I can do without the chart. I just need some way to know there's some score over 90, for instance. I know about…

---

## [Elastic Defend Missing Logs](https://discuss.elastic.co/t/elastic-defend-missing-logs/337805)

<div class="topic-metadata">

**Author:** [@infernalz2](https://discuss.elastic.co/u/infernalz2)\
**Replies:** 1\
**Last updated:** [July 17, 2023, 6:20pm UTC](https://discuss.elastic.co/t/elastic-defend-missing-logs/337805 "2023-07-17T18:20:46Z")

</div>

Hi guys I am running Elastic Defend 8.7.1 on multiple Ubuntu 20.04.5 and CentOS 7 vms. In both cases network logs from outbound connections are missing (logged user or services), there are only for inbound. To my unders…

---

## [Getting this on opening the UI Cannot connect to the Elasticsearch cluster See the Kibana logs for details and try reloading the page](https://discuss.elastic.co/t/getting-this-on-opening-the-ui-cannot-connect-to-the-elasticsearch-cluster-see-the-kibana-logs-for-details-and-try-reloading-the-page/338595)

<div class="topic-metadata">

**Author:** [@Mamoon\_Qazi](https://discuss.elastic.co/u/Mamoon_Qazi)\
**Replies:** 2\
**Last updated:** [July 17, 2023, 5:46pm UTC](https://discuss.elastic.co/t/getting-this-on-opening-the-ui-cannot-connect-to-the-elasticsearch-cluster-see-the-kibana-logs-for-details-and-try-reloading-the-page/338595 "2023-07-17T17:46:28Z")

</div>

On opening the Kibana UI i get this message "Cannot connect to the Elasticsearch cluster See the Kibana logs for details and try reloading the page." on checking the kibana logs i see this {"type":"log","@timestamp":"2…

---

## [Return only last message based on a specific field](https://discuss.elastic.co/t/return-only-last-message-based-on-a-specific-field/336560)

<div class="topic-metadata">

**Author:** [@WimM](https://discuss.elastic.co/u/WimM)\
**Replies:** 4\
**Last updated:** [July 17, 2023, 5:27pm UTC](https://discuss.elastic.co/t/return-only-last-message-based-on-a-specific-field/336560 "2023-07-17T17:27:13Z")

</div>

Hi I work for a telco company and we are currently reporting on tests done by the technician at the customers location I have currently a graph showing the count on all tests in total (off course with some filters appl…

---

## [Does DBeaver client translate SQL queries to API calls?](https://discuss.elastic.co/t/does-dbeaver-client-translate-sql-queries-to-api-calls/338445)

<div class="topic-metadata">

**Author:** [@Mike\_Z](https://discuss.elastic.co/u/Mike_Z)\
**Replies:** 2\
**Last updated:** [July 17, 2023, 5:08pm UTC](https://discuss.elastic.co/t/does-dbeaver-client-translate-sql-queries-to-api-calls/338445 "2023-07-17T17:08:01Z")

</div>

Following this document we have created a DBeaver connection to a testing Elasticsearch instance running the 30-day trial license. We tried SQL queries like select \* from "my-index-000001" limit 10; and the DBeaver clie…

---

## [Stack Monitoring with Metricbeat 8 -- No Cluster Found](https://discuss.elastic.co/t/stack-monitoring-with-metricbeat-8-no-cluster-found/336104)

<div class="topic-metadata">

**Author:** [@Evesy](https://discuss.elastic.co/u/Evesy)\
**Replies:** 4\
**Last updated:** [July 17, 2023, 4:52pm UTC](https://discuss.elastic.co/t/stack-monitoring-with-metricbeat-8-no-cluster-found/336104 "2023-07-17T16:52:38Z")

</div>

Kibana cannot find stack monitoring data when using Metricbeat to collect Elasticsearch/Kibana/Logstash metrics on 8.x I have the below configurations: Kibana (8.8.0) No explicit settings in regards to monitoring etc. …

---

## [Auditing Kibana's user events](https://discuss.elastic.co/t/auditing-kibanas-user-events/338395)

<div class="topic-metadata">

**Author:** [@IsItPossible](https://discuss.elastic.co/u/IsItPossible)\
**Replies:** 1\
**Last updated:** [July 17, 2023, 4:18pm UTC](https://discuss.elastic.co/t/auditing-kibanas-user-events/338395 "2023-07-17T16:18:33Z")

</div>

Hello, I have some questions about monitoring access/events done by Kibana's users. Here are some examples of events im interested in: Create/Delete/Update/Enable/Disable rules Create/Update/Close cases Close/Delete a…

---

## [Help ingesting Data](https://discuss.elastic.co/t/help-ingesting-data/338580)

<div class="topic-metadata">

**Author:** [@Tom\_Dixon](https://discuss.elastic.co/u/Tom_Dixon)\
**Replies:** 2\
**Last updated:** [July 17, 2023, 4:14pm UTC](https://discuss.elastic.co/t/help-ingesting-data/338580 "2023-07-17T16:14:42Z")

</div>

Hi all, I'm new to Elastic and Logstash. I have a source of event data which I'm having problems ingesting. I think it is because the data itself, but being new to Logstash it could also be me, so I'm not sure where the …

---

## [Indices have lifecycle errors](https://discuss.elastic.co/t/indices-have-lifecycle-errors/338524)

<div class="topic-metadata">

**Author:** [@Nde](https://discuss.elastic.co/u/Nde)\
**Replies:** 0\
**Last updated:** [July 17, 2023, 9:41am UTC](https://discuss.elastic.co/t/indices-have-lifecycle-errors/338524 "2023-07-17T09:41:41Z")

</div>

Hello, In Index Management in Kabana I got some indices with lifecycle errors. The error of these indices is about the rollover\_alias not pointed into an index. i've tried the /\_reindex method and add the alias to t…

---

## [End to end latency with traces](https://discuss.elastic.co/t/end-to-end-latency-with-traces/338452)

<div class="topic-metadata">

**Author:** [@sangramreddy](https://discuss.elastic.co/u/sangramreddy)\
**Replies:** 14\
**Last updated:** [July 17, 2023, 3:58pm UTC](https://discuss.elastic.co/t/end-to-end-latency-with-traces/338452 "2023-07-17T15:58:57Z")

</div>

Elastic APM transactions tab shows a nice graph about the latency distribution as shown below w: However, this latency distribution is only for taht specific app. How to visualize latency distribution for traces whi…

---

## [Subtraction of Sum Aggregate Values in one Index from Sum Aggregate Values in Another Index](https://discuss.elastic.co/t/subtraction-of-sum-aggregate-values-in-one-index-from-sum-aggregate-values-in-another-index/338442)

<div class="topic-metadata">

**Author:** [@nickbarry](https://discuss.elastic.co/u/nickbarry)\
**Replies:** 2\
**Last updated:** [July 17, 2023, 3:58pm UTC](https://discuss.elastic.co/t/subtraction-of-sum-aggregate-values-in-one-index-from-sum-aggregate-values-in-another-index/338442 "2023-07-17T15:58:26Z")

</div>

I have two indices within a single data view that track 'compute cycles' in some unit like 'cycle-hours per month'. One of the indices is the total max available cycle-hours for each computer in the company's data cente…

---

## [Kafka input plugin cannot parse key or value due to message keys](https://discuss.elastic.co/t/kafka-input-plugin-cannot-parse-key-or-value-due-to-message-keys/338560)

<div class="topic-metadata">

**Author:** [@kohlbecker](https://discuss.elastic.co/u/kohlbecker)\
**Replies:** 2\
**Last updated:** [July 17, 2023, 3:38pm UTC](https://discuss.elastic.co/t/kafka-input-plugin-cannot-parse-key-or-value-due-to-message-keys/338560 "2023-07-17T15:38:03Z")

</div>

Key and value of the topic messages consumed by the Kafka input plugin are prefixed with the message ids, which causes the json parser to fail: Here an example from the logstash log with decorate\_events =\> "extended" pr…

---

## [1Password Rule Vault Accessed - Desktop app](https://discuss.elastic.co/t/1password-rule-vault-accessed-desktop-app/336774)

<div class="topic-metadata">

**Author:** [@Alex.W](https://discuss.elastic.co/u/Alex.W)\
**Replies:** 1\
**Last updated:** [July 17, 2023, 2:54pm UTC](https://discuss.elastic.co/t/1password-rule-vault-accessed-desktop-app/336774 "2023-07-17T14:54:06Z")

</div>

Hello, I have created a rule that alerts on users accessing a sensitive vault within 1Password (web) but this does not appear to fire when accessing the same vault through the desktop app. There are access logs for the…

---

## [Need help with Elastic agent installation](https://discuss.elastic.co/t/need-help-with-elastic-agent-installation/338570)

<div class="topic-metadata">

**Author:** [@Retrogamer](https://discuss.elastic.co/u/Retrogamer)\
**Replies:** 3\
**Last updated:** [July 17, 2023, 2:25pm UTC](https://discuss.elastic.co/t/need-help-with-elastic-agent-installation/338570 "2023-07-17T14:25:27Z")

</div>

It has been a few days that I am going through all documentations to install Elastic-agent either with Fleet Server or Stand-alone, but still, I have not been able to understand how each components works, what is the pre…

---

## [Unable to launch Kibana Dashboard outside the Network Host](https://discuss.elastic.co/t/unable-to-launch-kibana-dashboard-outside-the-network-host/336426)

<div class="topic-metadata">

**Author:** [@rohit.tps123](https://discuss.elastic.co/u/rohit.tps123)\
**Replies:** 1\
**Last updated:** [July 17, 2023, 2:21pm UTC](https://discuss.elastic.co/t/unable-to-launch-kibana-dashboard-outside-the-network-host/336426 "2023-07-17T14:21:13Z")

</div>

Hello, I have installed Elastic Search and Kibana on one Network Host (Docker Env) While checking via curl commands. I am getting proper respone for Elastic Search and No response for Kibana I am not able to access t…

---

## [Bytes value wraps to negative value](https://discuss.elastic.co/t/bytes-value-wraps-to-negative-value/338533)

<div class="topic-metadata">

**Author:** [@eddie4](https://discuss.elastic.co/u/eddie4)\
**Replies:** 1\
**Last updated:** [July 17, 2023, 1:48pm UTC](https://discuss.elastic.co/t/bytes-value-wraps-to-negative-value/338533 "2023-07-17T13:48:14Z")

</div>

Hello, Am attempting to multiply the number of bytes from netflow by 100. This is to offset the sampling rate. The pipeline has the following script: { "script": { "source": "ctx.network.true\_bytes2 = ctx.…

---

## [Implement proxy-protocol support for beats inputs](https://discuss.elastic.co/t/implement-proxy-protocol-support-for-beats-inputs/338561)

<div class="topic-metadata">

**Author:** [@bilel\_meddeb](https://discuss.elastic.co/u/bilel_meddeb)\
**Replies:** 0\
**Last updated:** [July 17, 2023, 1:14pm UTC](https://discuss.elastic.co/t/implement-proxy-protocol-support-for-beats-inputs/338561 "2023-07-17T13:14:41Z")

</div>

Hello :wave:t4: Would it be possible to support proxy-protocol for beats inputs ? I send logs from winlogbeat to logstash and i have Haproxy between them. without proxy and with this configuration of logstash, i got …

---

## [Using sql query with parameters in dotnet client](https://discuss.elastic.co/t/using-sql-query-with-parameters-in-dotnet-client/338553)

<div class="topic-metadata">

**Author:** [@darooman](https://discuss.elastic.co/u/darooman)\
**Replies:** 0\
**Last updated:** [July 17, 2023, 12:32pm UTC](https://discuss.elastic.co/t/using-sql-query-with-parameters-in-dotnet-client/338553 "2023-07-17T12:32:22Z")

</div>

When using the .net nuget package Elastic.Clients.Elasticsearch (version 8.1.3) to connect to an elastic cloud instance (running elastic v8.7.1), I am trying to use the sql query but I am struggling with the Params prope…

---

## [ECK: Fleet server or agent not connecting to correct Elasticsearch host: Failed to connect to backoff(elasticsearch(http://elasticsearch:9200))](https://discuss.elastic.co/t/eck-fleet-server-or-agent-not-connecting-to-correct-elasticsearch-host-failed-to-connect-to-backoff-elasticsearch-http-elasticsearch-9200/338552)

<div class="topic-metadata">

**Author:** [@Usama\_Tariq](https://discuss.elastic.co/u/Usama_Tariq)\
**Replies:** 0\
**Last updated:** [July 17, 2023, 12:29pm UTC](https://discuss.elastic.co/t/eck-fleet-server-or-agent-not-connecting-to-correct-elasticsearch-host-failed-to-connect-to-backoff-elasticsearch-http-elasticsearch-9200/338552 "2023-07-17T12:29:14Z")

</div>

I have deployed Elastic Stack using ECK operator. The issue is that fleet server or agent is not connecting to correct Elasticsearch host which seems to be strange. Following are my configs for kibana, elastic and fleet…

---

## [How to automatically delete index data after a few days or after certain size limit](https://discuss.elastic.co/t/how-to-automatically-delete-index-data-after-a-few-days-or-after-certain-size-limit/338511)

<div class="topic-metadata">

**Author:** [@akash-asthana](https://discuss.elastic.co/u/akash-asthana)\
**Replies:** 3\
**Last updated:** [July 17, 2023, 12:14pm UTC](https://discuss.elastic.co/t/how-to-automatically-delete-index-data-after-a-few-days-or-after-certain-size-limit/338511 "2023-07-17T12:14:49Z")

</div>

Hello, I have a scenario where i need to clean up the index data after a given number of days or after a certain storage size is occupied. Is there any way of achieving this without deleting the actual index? Thanks

---

## [Elasticsearch License Expired](https://discuss.elastic.co/t/elasticsearch-license-expired/338546)

<div class="topic-metadata">

**Author:** [@Kosala\_Randika\_Paran](https://discuss.elastic.co/u/Kosala_Randika_Paran)\
**Replies:** 1\
**Last updated:** [July 17, 2023, 12:11pm UTC](https://discuss.elastic.co/t/elasticsearch-license-expired/338546 "2023-07-17T12:11:17Z")

</div>

Hi What happens when the Elasticsearch license expired? Currently, the cluster has assigned a commercial license and it will expire soon, so what will happen once the assigned date expired?

---

## [After K8s cluster was turned off for night Kibna "Username or password is incorrect"](https://discuss.elastic.co/t/after-k8s-cluster-was-turned-off-for-night-kibna-username-or-password-is-incorrect/337123)

<div class="topic-metadata">

**Author:** [@Bogdan\_Boyko](https://discuss.elastic.co/u/Bogdan_Boyko)\
**Replies:** 9\
**Last updated:** [July 17, 2023, 11:30am UTC](https://discuss.elastic.co/t/after-k8s-cluster-was-turned-off-for-night-kibna-username-or-password-is-incorrect/337123 "2023-07-17T11:30:23Z")

</div>

I have a problem with Kibana, when my Kubernetes cluster shuts down in the evening and turns back on in the morning, then I can't log in with the credentials that were valid yesterday. And when I delete the pod and it is…

---

## [Why is my search returning all values from time filter](https://discuss.elastic.co/t/why-is-my-search-returning-all-values-from-time-filter/338527)

<div class="topic-metadata">

**Author:** [@dsmteam](https://discuss.elastic.co/u/dsmteam)\
**Replies:** 2\
**Last updated:** [July 17, 2023, 11:25am UTC](https://discuss.elastic.co/t/why-is-my-search-returning-all-values-from-time-filter/338527 "2023-07-17T11:25:43Z")

</div>

Hi, i'm a bit confused by this simple search curl -XGET 'localhost:9200/logstash-\*/\_count?pretty' -d' { "query": { "bool": { "should": \[ { "match\_phrase": { "Info":"OPTICAL\_FIBER\_MISCONNECT(l)" …

[Previous page](https://discuss.elastic.co/latest.md?page=603)

[Next page](https://discuss.elastic.co/latest.md?page=605)
