# Latest

**URL:** https://discuss.elastic.co/latest.md?page=607

[Latest](https://discuss.elastic.co/latest.md) · [Categories](https://discuss.elastic.co/categories.md) · [Tags](https://discuss.elastic.co/tags.md)

**Page:** 608

---

## [Kafka logstash logs are showing into filebeat logstash index](https://discuss.elastic.co/t/kafka-logstash-logs-are-showing-into-filebeat-logstash-index/337419)

<div class="topic-metadata">

**Author:** [@lalchand\_rajak](https://discuss.elastic.co/u/lalchand_rajak)\
**Replies:** 10\
**Last updated:** [July 14, 2023, 2:27pm UTC](https://discuss.elastic.co/t/kafka-logstash-logs-are-showing-into-filebeat-logstash-index/337419 "2023-07-14T14:27:36Z")

</div>

Hello, I have kafka-logstash conf and logstash reciveing the logs from kafka. here is the config. input { kafka { topics =\> \["sitlogtopic","locallogtopic"\] bootstrap\_servers =\> "ddr-kafkadev.pvt.cci…

---

## [Elastic.Apm.NetCoreAll how to ignore transaction of OPTIONS http method?](https://discuss.elastic.co/t/elastic-apm-netcoreall-how-to-ignore-transaction-of-options-http-method/337513)

<div class="topic-metadata">

**Author:** [@khteh](https://discuss.elastic.co/u/khteh)\
**Replies:** 1\
**Last updated:** [July 14, 2023, 2:24pm UTC](https://discuss.elastic.co/t/elastic-apm-netcoreall-how-to-ignore-transaction-of-options-http-method/337513 "2023-07-14T14:24:40Z")

</div>

If you are asking about a problem you are experiencing, please use the following template, as it will help us help you. If you have a different problem, please delete all of this text :slight\_smile: TIP 1: select at lea…

---

## [APM NET agent errors: An unhandled exception was thrown by the application](https://discuss.elastic.co/t/apm-net-agent-errors-an-unhandled-exception-was-thrown-by-the-application/337416)

<div class="topic-metadata">

**Author:** [@agonzalez](https://discuss.elastic.co/u/agonzalez)\
**Replies:** 2\
**Last updated:** [July 14, 2023, 2:19pm UTC](https://discuss.elastic.co/t/apm-net-agent-errors-an-unhandled-exception-was-thrown-by-the-application/337416 "2023-07-14T14:19:49Z")

</div>

I am testing APM and since i have included NET APM agent on my .NET 7 service in linux I am seeing this error repeated so many times. Can anyone tell me how to fix this? or what is the problem? fail: Microsoft.AspNetCor…

---

## [.NET framwork APM on windows server 2012 (IIS 8.5) not capturing data](https://discuss.elastic.co/t/net-framwork-apm-on-windows-server-2012-iis-8-5-not-capturing-data/337828)

<div class="topic-metadata">

**Author:** [@Dov](https://discuss.elastic.co/u/Dov)\
**Replies:** 1\
**Last updated:** [July 14, 2023, 2:10pm UTC](https://discuss.elastic.co/t/net-framwork-apm-on-windows-server-2012-iis-8-5-not-capturing-data/337828 "2023-07-14T14:10:40Z")

</div>

Elasticsearch version: 8.5.3 I tried to install APM profiler on windows server 2012 R2 with IIS 8.5 with 80-90 application pools base .net framework. The APM Profiler is working well on IIS 10, and I don't have any pro…

---

## [Parsing firewall logs in logstash](https://discuss.elastic.co/t/parsing-firewall-logs-in-logstash/338405)

<div class="topic-metadata">

**Author:** [@secsec](https://discuss.elastic.co/u/secsec)\
**Replies:** 1\
**Last updated:** [July 14, 2023, 1:31pm UTC](https://discuss.elastic.co/t/parsing-firewall-logs-in-logstash/338405 "2023-07-14T13:31:25Z")

</div>

Hello, our sophos firewall are sending logs to filebeat, then filebeat send to logstash. In logstash im trying to separate field called "action" to be able to filter it under elasticsearch. So far no luck. I managed to …

---

## [ECE install on podman (no docker group)](https://discuss.elastic.co/t/ece-install-on-podman-no-docker-group/338419)

<div class="topic-metadata">

**Author:** [@andrew.luke](https://discuss.elastic.co/u/andrew.luke)\
**Replies:** 0\
**Last updated:** [July 14, 2023, 1:30pm UTC](https://discuss.elastic.co/t/ece-install-on-podman-no-docker-group/338419 "2023-07-14T13:30:10Z")

</div>

TLDR: When I try to install ECE with the --podman flag it throws an error about the user not being in the docker group, which doesn't exist in a podman install. We are currently using ECE on RHEL with docker. I was jus…

---

## [Elastich search:unassigned shards: status yellow](https://discuss.elastic.co/t/elastich-search-unassigned-shards-status-yellow/338120)

<div class="topic-metadata">

**Author:** [@Deepika\_Gupta](https://discuss.elastic.co/u/Deepika_Gupta)\
**Replies:** 5\
**Last updated:** [July 14, 2023, 12:58pm UTC](https://discuss.elastic.co/t/elastich-search-unassigned-shards-status-yellow/338120 "2023-07-14T12:58:38Z")

</div>

Hello Team, My team is trying to create an Elasticsearch -cluster with Kibana. on one server Elasticsearch node works fine with zero shards. But another server is complaining about the status "yellow". Below is the u…

---

## [Facing java.io.EOFException: read past EOF exception and org.apache.lucene.index.CorruptIndexException: compound sub-files must have a valid codec header and footer: file is too small (0 bytes) in elastic 7.17.5](https://discuss.elastic.co/t/facing-java-io-eofexception-read-past-eof-exception-and-org-apache-lucene-index-corruptindexexception-compound-sub-files-must-have-a-valid-codec-header-and-footer-file-is-too-small-0-bytes-in-elastic-7-17-5/338370)

<div class="topic-metadata">

**Author:** [@Kesavan](https://discuss.elastic.co/u/Kesavan)\
**Replies:** 4\
**Last updated:** [July 14, 2023, 10:34am UTC](https://discuss.elastic.co/t/facing-java-io-eofexception-read-past-eof-exception-and-org-apache-lucene-index-corruptindexexception-compound-sub-files-must-have-a-valid-codec-header-and-footer-file-is-too-small-0-bytes-in-elastic-7-17-5/338370 "2023-07-14T10:34:03Z")

</div>

In one our environment we are facing the "CorruptIndexException". While analyzing the elastic log we found the below are the list of exception details: infinity\_infinity-elasticsearch.1.862455ajz1ca@WorkerNode03Prod …

---

## [Eck stack helm install, expose ingress](https://discuss.elastic.co/t/eck-stack-helm-install-expose-ingress/338399)

<div class="topic-metadata">

**Author:** [@simonebenati](https://discuss.elastic.co/u/simonebenati)\
**Replies:** 0\
**Last updated:** [July 14, 2023, 10:31am UTC](https://discuss.elastic.co/t/eck-stack-helm-install-expose-ingress/338399 "2023-07-14T10:31:30Z")

</div>

Hello, I installed eck operator via helm and then the eck stack via helm. Now I want to expose via ingress Elasticsearch but I am not able to find anywhere in the helm values or docs the value in order to expose an ingr…

---

## [Metrics alert based on ratio](https://discuss.elastic.co/t/metrics-alert-based-on-ratio/338397)

<div class="topic-metadata">

**Author:** [@dspeschabls](https://discuss.elastic.co/u/dspeschabls)\
**Replies:** 0\
**Last updated:** [July 14, 2023, 10:10am UTC](https://discuss.elastic.co/t/metrics-alert-based-on-ratio/338397 "2023-07-14T10:10:40Z")

</div>

We have a Spring Boot application and push its metrics to elastic, among others also usage of API paths. This generates one document per uri (path) and outcome with count per time unit. Example: {uri="api/v2/dosomethin…

---

## [Angular integration with Elastic APM](https://discuss.elastic.co/t/angular-integration-with-elastic-apm/338285)

<div class="topic-metadata">

**Author:** [@Mangesh\_Mathe](https://discuss.elastic.co/u/Mangesh_Mathe)\
**Replies:** 3\
**Last updated:** [July 14, 2023, 9:07am UTC](https://discuss.elastic.co/t/angular-integration-with-elastic-apm/338285 "2023-07-14T09:07:52Z")

</div>

Hello Team, My elastic setup is on cloud. elastic version : 8.4.2 Angular version: 13.0 Where we have integrated Angular APM client with elastic APM server. We referred the link from documentation, and installed/con…

---

## [Elastic SIEM Detection Rules / Exception Containers / Exception Lists](https://discuss.elastic.co/t/elastic-siem-detection-rules-exception-containers-exception-lists/338390)

<div class="topic-metadata">

**Author:** [@tsigouris007](https://discuss.elastic.co/u/tsigouris007)\
**Replies:** 0\
**Last updated:** [July 14, 2023, 8:45am UTC](https://discuss.elastic.co/t/elastic-siem-detection-rules-exception-containers-exception-lists/338390 "2023-07-14T08:45:53Z")

</div>

Hello, I have created a Terraform Provider for the Elastic SIEM components. You can find the Git repo here: https://github.com/tsigouris007/terraform-provider-elastic-siem-detection The provider is also published to t…

---

## [Xpack disable](https://discuss.elastic.co/t/xpack-disable/338350)

<div class="topic-metadata">

**Author:** [@mannoj87](https://discuss.elastic.co/u/mannoj87)\
**Replies:** 4\
**Last updated:** [July 14, 2023, 7:10am UTC](https://discuss.elastic.co/t/xpack-disable/338350 "2023-07-14T07:10:16Z")

</div>

ES Version: 7.10.2 Query 1 : If I need to disable xpack I need to make yml changes to make xpack settings to false and restart each nodes ? Query1 My Understanding is : Yes, there is no API call to disable or enable dy…

---

## [Kibana data-table visualization not displaying all data rows](https://discuss.elastic.co/t/kibana-data-table-visualization-not-displaying-all-data-rows/337861)

<div class="topic-metadata">

**Author:** [@mohanss08](https://discuss.elastic.co/u/mohanss08)\
**Replies:** 6\
**Last updated:** [July 14, 2023, 5:25am UTC](https://discuss.elastic.co/t/kibana-data-table-visualization-not-displaying-all-data-rows/337861 "2023-07-14T05:25:18Z")

</div>

I’m trying to create a Data Table visualization and I have below issue. My buckets selections as follows. In discover page, i can able to view the data , each fields value and its rows without any problem. But in v…

---

## [Feedback regarding Synthetics Tests](https://discuss.elastic.co/t/feedback-regarding-synthetics-tests/335587)

<div class="topic-metadata">

**Author:** [@Wolfram\_Haussig](https://discuss.elastic.co/u/Wolfram_Haussig)\
**Replies:** 11\
**Last updated:** [July 14, 2023, 5:12am UTC](https://discuss.elastic.co/t/feedback-regarding-synthetics-tests/335587 "2023-07-14T05:12:03Z")

</div>

Dear all, We are currently evaluating the Synthetic Monitoring of Elastic with 2 applications (1 Java with JSP, 1 Angular) and although we did not create huge tests yet, I would like to give our opinion about the curren…

---

## [Logstash grok pattern for apache error log](https://discuss.elastic.co/t/logstash-grok-pattern-for-apache-error-log/337676)

<div class="topic-metadata">

**Author:** [@sanjeev1895](https://discuss.elastic.co/u/sanjeev1895)\
**Replies:** 4\
**Last updated:** [July 14, 2023, 4:59am UTC](https://discuss.elastic.co/t/logstash-grok-pattern-for-apache-error-log/337676 "2023-07-14T04:59:24Z")

</div>

Hi experts, Can any one tell me that how to configure the logstash grok custom pattern for apache web server error log. below is my apache web server sample error log, \[Fri Jun 09 08:26:38.311375 2023\] \[proxy\_fcgi:err…

---

## [In Elastic Cloud field type is correct i.e. keyword](https://discuss.elastic.co/t/in-elastic-cloud-field-type-is-correct-i-e-keyword/338368)

<div class="topic-metadata">

**Author:** [@Nishant\_Chauhan](https://discuss.elastic.co/u/Nishant_Chauhan)\
**Replies:** 0\
**Last updated:** [July 14, 2023, 4:35am UTC](https://discuss.elastic.co/t/in-elastic-cloud-field-type-is-correct-i-e-keyword/338368 "2023-07-14T04:35:13Z")

</div>

In Elastic Cloud, when I install any integration data ingest in proper field type i.e. keyword. However, in local deployment, when i install any integration data always comes in text field type.

---

## [How to update service account which is used to create snapshot](https://discuss.elastic.co/t/how-to-update-service-account-which-is-used-to-create-snapshot/337128)

<div class="topic-metadata">

**Author:** [@Aysh14](https://discuss.elastic.co/u/Aysh14)\
**Replies:** 5\
**Last updated:** [July 14, 2023, 3:38am UTC](https://discuss.elastic.co/t/how-to-update-service-account-which-is-used-to-create-snapshot/337128 "2023-07-14T03:38:16Z")

</div>

How to update service account which is used to create snapshot. I created repository from Kibana to snapshot the Elastic search indices. The snapshot location is GCS bucket. However, the repository is not getting verifie…

---

## [Snapshotter setup](https://discuss.elastic.co/t/snapshotter-setup/338365)

<div class="topic-metadata">

**Author:** [@Aysh14](https://discuss.elastic.co/u/Aysh14)\
**Replies:** 0\
**Last updated:** [July 14, 2023, 3:33am UTC](https://discuss.elastic.co/t/snapshotter-setup/338365 "2023-07-14T03:33:39Z")

</div>

Can I setup a new repository to take snapshots today onwards without having to restart the data and master nodes on the Elastic Search cluster ? I am currently using ES 7.16 . The old snapshots are not available and ther…

---

## [Kibana Watcher to trigger email by checking aggregation results with dynamic threshold value](https://discuss.elastic.co/t/kibana-watcher-to-trigger-email-by-checking-aggregation-results-with-dynamic-threshold-value/338357)

<div class="topic-metadata">

**Author:** [@Santosh1667](https://discuss.elastic.co/u/Santosh1667)\
**Replies:** 0\
**Last updated:** [July 13, 2023, 8:30pm UTC](https://discuss.elastic.co/t/kibana-watcher-to-trigger-email-by-checking-aggregation-results-with-dynamic-threshold-value/338357 "2023-07-13T20:30:17Z")

</div>

Hi , I had a Kibana watcher which will give aggregation buckets in below format distinct\_error\_count:\[ { key:"Error 1 Occured", distinct\_count:6 }, { key:"Error 2 Occured", distinct\_count:4 }, { key:"Error 3 Occured", d…

---

## [Error loading execution history for alert rules](https://discuss.elastic.co/t/error-loading-execution-history-for-alert-rules/329774)

<div class="topic-metadata">

**Author:** [@Landorks](https://discuss.elastic.co/u/Landorks)\
**Replies:** 2\
**Last updated:** [July 13, 2023, 7:47pm UTC](https://discuss.elastic.co/t/error-loading-execution-history-for-alert-rules/329774 "2023-07-13T19:47:34Z")

</div>

Hi, I get the following error in Kibana (8.4.3) when trying to view an alert. It appears that this is causing alerts not to fire at all. Everything was working fine about a week ago. I've already tried creating a new al…

---

## [Charts are not properly embeding in the dash board](https://discuss.elastic.co/t/charts-are-not-properly-embeding-in-the-dash-board/338261)

<div class="topic-metadata">

**Author:** [@Kumar\_Abhinav](https://discuss.elastic.co/u/Kumar_Abhinav)\
**Replies:** 2\
**Last updated:** [July 13, 2023, 7:39pm UTC](https://discuss.elastic.co/t/charts-are-not-properly-embeding-in-the-dash-board/338261 "2023-07-13T19:39:14Z")

</div>

Hi, I have edited a field name with a Custom Label and edited the Format to Title Case. While it is showing well in the visualization i.e. (With Changes) when I import the visual into the dashboard it goes back to its d…

---

## [Is there a way to identify which visualization type was used to in a dashboard besides deducing and testing?](https://discuss.elastic.co/t/is-there-a-way-to-identify-which-visualization-type-was-used-to-in-a-dashboard-besides-deducing-and-testing/338043)

<div class="topic-metadata">

**Author:** [@brunofl](https://discuss.elastic.co/u/brunofl)\
**Replies:** 3\
**Last updated:** [July 13, 2023, 7:26pm UTC](https://discuss.elastic.co/t/is-there-a-way-to-identify-which-visualization-type-was-used-to-in-a-dashboard-besides-deducing-and-testing/338043 "2023-07-13T19:26:31Z")

</div>

Hi, I am working on migration of kibana dashboards to a new instance and having trouble to find what type of table was used in certain visualizations. Is there a way to check this in the existing dashboard what was the e…

---

## [Terms aggregation over section of a keyword](https://discuss.elastic.co/t/terms-aggregation-over-section-of-a-keyword/338351)

<div class="topic-metadata">

**Author:** [@tmslara.a](https://discuss.elastic.co/u/tmslara.a)\
**Replies:** 1\
**Last updated:** [July 13, 2023, 5:55pm UTC](https://discuss.elastic.co/t/terms-aggregation-over-section-of-a-keyword/338351 "2023-07-13T17:55:59Z")

</div>

Hi, I have an index with a keyword field. The values are in the form '\<code\>\<numbers\>' where I know the code is a three figures number (e.g., in '123456789' the code is 123). I want to perform an aggregation like a term…

---

## [Peridiocally Java APM Agent experiences errors with connection to APM server](https://discuss.elastic.co/t/peridiocally-java-apm-agent-experiences-errors-with-connection-to-apm-server/335888)

<div class="topic-metadata">

**Author:** [@Savva\_Morozov](https://discuss.elastic.co/u/Savva_Morozov)\
**Replies:** 6\
**Last updated:** [July 13, 2023, 6:55pm UTC](https://discuss.elastic.co/t/peridiocally-java-apm-agent-experiences-errors-with-connection-to-apm-server/335888 "2023-07-13T18:55:49Z")

</div>

Kibana version: v8.6.2 Elasticsearch version: v8.6.2 APM Server version: v8.6.2 APM Agent language and version: Java APM Agent 1.34.1 Description of the problem including expected versus actual behavior. Please inc…

---

## [Kibana savej object giving error on import: migrating from 7.9.1 to 8.7.1 version full elk stack](https://discuss.elastic.co/t/kibana-savej-object-giving-error-on-import-migrating-from-7-9-1-to-8-7-1-version-full-elk-stack/338220)

<div class="topic-metadata">

**Author:** [@PRASHANT\_MEHTA](https://discuss.elastic.co/u/PRASHANT_MEHTA)\
**Replies:** 8\
**Last updated:** [July 13, 2023, 6:35pm UTC](https://discuss.elastic.co/t/kibana-savej-object-giving-error-on-import-migrating-from-7-9-1-to-8-7-1-version-full-elk-stack/338220 "2023-07-13T18:35:47Z")

</div>

Hello All, I'm migrating my full elk stack stack from 7.9.1 to 8.7.1 and facing issues while importing saved object in 8.7.1,below is the error in second image: How do I save saved object and download -shown below 1st …

---

## [Elasticsearch creating different indices with identical data](https://discuss.elastic.co/t/elasticsearch-creating-different-indices-with-identical-data/338352)

<div class="topic-metadata">

**Author:** [@mfisher](https://discuss.elastic.co/u/mfisher)\
**Replies:** 5\
**Last updated:** [July 13, 2023, 6:30pm UTC](https://discuss.elastic.co/t/elasticsearch-creating-different-indices-with-identical-data/338352 "2023-07-13T18:30:00Z")

</div>

I recently moved from ELK stack 7.X to 8.8.2. I'm using my old Logstash pipline confs. For some reason Elasticsearch/Kibana is showing each individual index but each index as the same data. I don't think its a datavie…

---

## [Methods to Enroll Kibana](https://discuss.elastic.co/t/methods-to-enroll-kibana/338164)

<div class="topic-metadata">

**Author:** [@ANUBHAV\_GUPTA](https://discuss.elastic.co/u/ANUBHAV_GUPTA)\
**Replies:** 5\
**Last updated:** [July 13, 2023, 6:12pm UTC](https://discuss.elastic.co/t/methods-to-enroll-kibana/338164 "2023-07-13T18:12:03Z")

</div>

Hi there, Is there a way to enroll kibana other than the mentioned 2 below:- bin/elasticsearch-create-enrollment-token copy the enrollment token from the elasticsearch stdout Note: I am using docker to deploy these t…

---

## [Best Practice For Private Locations (Synthetics)](https://discuss.elastic.co/t/best-practice-for-private-locations-synthetics/337318)

<div class="topic-metadata">

**Author:** [@ameindel](https://discuss.elastic.co/u/ameindel)\
**Replies:** 2\
**Last updated:** [July 13, 2023, 6:01pm UTC](https://discuss.elastic.co/t/best-practice-for-private-locations-synthetics/337318 "2023-07-13T18:01:00Z")

</div>

Hello, Elastic! I had a couple questions for you regarding best practices for utilizing Private Locations with Synthetics. I'll explain the two scenarios: 1 - We currently have two Elastic Stacks (dev and prod). The '…

---

## [Record Who Closes Alert](https://discuss.elastic.co/t/record-who-closes-alert/338254)

<div class="topic-metadata">

**Author:** [@SomeRobot](https://discuss.elastic.co/u/SomeRobot)\
**Replies:** 1\
**Last updated:** [July 13, 2023, 4:29pm UTC](https://discuss.elastic.co/t/record-who-closes-alert/338254 "2023-07-13T16:29:24Z")

</div>

Is there a way to record which user has 'closed' an alert in Elastic Security? I read through the audit log documentation, and it doesn't reference this specific topic. Is there any way to log this?

[Previous page](https://discuss.elastic.co/latest.md?page=606)

[Next page](https://discuss.elastic.co/latest.md?page=608)
