# Latest

**URL:** https://discuss.elastic.co/latest.md?page=608

[Latest](https://discuss.elastic.co/latest.md) · [Categories](https://discuss.elastic.co/categories.md) · [Tags](https://discuss.elastic.co/tags.md)

**Page:** 609

---

## [Elastic APM PHP - tracking multiple domains on same server](https://discuss.elastic.co/t/elastic-apm-php-tracking-multiple-domains-on-same-server/338348)

<div class="topic-metadata">

**Author:** [@bram](https://discuss.elastic.co/u/bram)\
**Replies:** 0\
**Last updated:** [July 13, 2023, 3:49pm UTC](https://discuss.elastic.co/t/elastic-apm-php-tracking-multiple-domains-on-same-server/338348 "2023-07-13T15:49:53Z")

</div>

Kibana version: 8.8 Elasticsearch version: 8.8 APM Server version: 8.8 APM Agent language and version: PHP Agent v1.9 Original install method: deb Fresh install or upgraded from other version?: fresh Description of…

---

## [Scripted field was used to show traffic light image up or down in index pattern 7.9.1 kibana,8.8.2 dont support,wht is alternative to implement?](https://discuss.elastic.co/t/scripted-field-was-used-to-show-traffic-light-image-up-or-down-in-index-pattern-7-9-1-kibana-8-8-2-dont-support-wht-is-alternative-to-implement/338345)

<div class="topic-metadata">

**Author:** [@PRASHANT\_MEHTA](https://discuss.elastic.co/u/PRASHANT_MEHTA)\
**Replies:** 1\
**Last updated:** [July 13, 2023, 3:35pm UTC](https://discuss.elastic.co/t/scripted-field-was-used-to-show-traffic-light-image-up-or-down-in-index-pattern-7-9-1-kibana-8-8-2-dont-support-wht-is-alternative-to-implement/338345 "2023-07-13T15:35:08Z")

</div>

In kinbana 7.9.1 I used to use scripted fields in index pattern option ,now going forward its not supported in future version.We want this feature of tarffic light image show green or red. Its recommended to use run tim…

---

## [Filebeat Syslog no listening port](https://discuss.elastic.co/t/filebeat-syslog-no-listening-port/336969)

<div class="topic-metadata">

**Author:** [@mc.gyver.reboot](https://discuss.elastic.co/u/mc.gyver.reboot)\
**Replies:** 15\
**Last updated:** [July 13, 2023, 2:35pm UTC](https://discuss.elastic.co/t/filebeat-syslog-no-listening-port/336969 "2023-07-13T14:35:45Z")

</div>

Good morning, Configuration: Ubuntu version 22 Filebeat version 8.8.1 Aucun message d'erreur au lancement de Filebeat After hours of searching and testing, I can't find why Filebeat isn't listening on the ports I te…

---

## [Anomaly Detection Rule Won't Send Email](https://discuss.elastic.co/t/anomaly-detection-rule-wont-send-email/338244)

<div class="topic-metadata">

**Author:** [@McJava1967](https://discuss.elastic.co/u/McJava1967)\
**Replies:** 6\
**Last updated:** [July 13, 2023, 2:02pm UTC](https://discuss.elastic.co/t/anomaly-detection-rule-wont-send-email/338244 "2023-07-13T14:02:45Z")

</div>

Hi all. I'm evaluating Anomaly alerting using a locally hosted Platinum trial. In short, the anomaly detection Job itself is working. I can see anomalies in the results. And I have set up a Rule with a Connector. I…

---

## [No logs in elasticsearch while using log\_sending and stdout log level = OFF](https://discuss.elastic.co/t/no-logs-in-elasticsearch-while-using-log-sending-and-stdout-log-level-off/336588)

<div class="topic-metadata">

**Author:** [@GeorgeGkinis](https://discuss.elastic.co/u/GeorgeGkinis)\
**Replies:** 4\
**Last updated:** [July 13, 2023, 2:02pm UTC](https://discuss.elastic.co/t/no-logs-in-elasticsearch-while-using-log-sending-and-stdout-log-level-off/336588 "2023-07-13T14:02:14Z")

</div>

Kibana version: 8.8.1 Elasticsearch version: 8.8.1 APM Server version: 8.8.1 APM Agent language and version: java 1.39.0 Browser version: chrome 114.0.5735.134 Original install method (e.g. download page, yum, deb, …

---

## [Catched library exception still marked as Exception in APM UI](https://discuss.elastic.co/t/catched-library-exception-still-marked-as-exception-in-apm-ui/337201)

<div class="topic-metadata">

**Author:** [@NickWe](https://discuss.elastic.co/u/NickWe)\
**Replies:** 1\
**Last updated:** [July 13, 2023, 1:58pm UTC](https://discuss.elastic.co/t/catched-library-exception-still-marked-as-exception-in-apm-ui/337201 "2023-07-13T13:58:40Z")

</div>

Hi, Is it normal that catched Exceptions in a Library are still shown as Errors in the APM UI. I could not find any relevant documentation about when/how Exceptions are sent by the APM Java agent. In this case it's t…

---

## [Elasticsearch Cluster Health watch Watcher](https://discuss.elastic.co/t/elasticsearch-cluster-health-watch-watcher/338321)

<div class="topic-metadata">

**Author:** [@Shalinicts](https://discuss.elastic.co/u/Shalinicts)\
**Replies:** 8\
**Last updated:** [July 13, 2023, 1:36pm UTC](https://discuss.elastic.co/t/elasticsearch-cluster-health-watch-watcher/338321 "2023-07-13T13:36:55Z")

</div>

Hi Team, I am trying to create a watcher for cluster health check (Clluster is 3 master and 5 data node ) as per Elastic documentation In the input section it is referred to provide host as host:localhost "input" :…

---

## [ECE & Watcher: Trouble sending API key to ECE](https://discuss.elastic.co/t/ece-watcher-trouble-sending-api-key-to-ece/300980)

<div class="topic-metadata">

**Author:** [@Apprentice](https://discuss.elastic.co/u/Apprentice)\
**Replies:** 1\
**Last updated:** [July 13, 2023, 1:05pm UTC](https://discuss.elastic.co/t/ece-watcher-trouble-sending-api-key-to-ece/300980 "2023-07-13T13:05:45Z")

</div>

I am trying to create a Watcher using information from the ECE API as input. However I am having trouble getting authenticated. This is the Input for the watcher: "input": { "http" : { "request" : { "s…

---

## [Problem to add new date field in filter logstash](https://discuss.elastic.co/t/problem-to-add-new-date-field-in-filter-logstash/338107)

<div class="topic-metadata">

**Author:** [@shayn](https://discuss.elastic.co/u/shayn)\
**Replies:** 3\
**Last updated:** [July 13, 2023, 12:27pm UTC](https://discuss.elastic.co/t/problem-to-add-new-date-field-in-filter-logstash/338107 "2023-07-13T12:27:22Z")

</div>

i have date field called case\_start\_time in format of date and time . i am trying to add new field called case\_day which will cut the date without the time from case\_start\_time . case\_start\_time: 09/07/23 23:54:26 ca…

---

## [Logstash forwarding connection refused](https://discuss.elastic.co/t/logstash-forwarding-connection-refused/338293)

<div class="topic-metadata">

**Author:** [@willsy](https://discuss.elastic.co/u/willsy)\
**Replies:** 2\
**Last updated:** [July 13, 2023, 11:29am UTC](https://discuss.elastic.co/t/logstash-forwarding-connection-refused/338293 "2023-07-13T11:29:53Z")

</div>

Hello, I am trying to forward logs to any other location for the moment however i have the following error when trying to forward any data what so ever. I have a netcat listener on the opposite end and can see the incom…

---

## [Controlled rotation of elasticsearch data nodes while enabling the shard allocation awareness](https://discuss.elastic.co/t/controlled-rotation-of-elasticsearch-data-nodes-while-enabling-the-shard-allocation-awareness/338269)

<div class="topic-metadata">

**Author:** [@veerachenna](https://discuss.elastic.co/u/veerachenna)\
**Replies:** 7\
**Last updated:** [July 13, 2023, 10:44am UTC](https://discuss.elastic.co/t/controlled-rotation-of-elasticsearch-data-nodes-while-enabling-the-shard-allocation-awareness/338269 "2023-07-13T10:44:16Z")

</div>

Hi All, We are trying to enable the shard allocation awareness on the elasticsearch cluster on "zone" attribute while rotating the data nodes one after the other. We wanted to achieve this in more controlled manner. Ini…

---

## [Logstash pipeline Http output plugin error "\[HTTP Output Failure\] Encountered non-2xx HTTP code 400"](https://discuss.elastic.co/t/logstash-pipeline-http-output-plugin-error-http-output-failure-encountered-non-2xx-http-code-400/338116)

<div class="topic-metadata">

**Author:** [@PodarcisMuralis](https://discuss.elastic.co/u/PodarcisMuralis)\
**Replies:** 1\
**Last updated:** [July 13, 2023, 9:55am UTC](https://discuss.elastic.co/t/logstash-pipeline-http-output-plugin-error-http-output-failure-encountered-non-2xx-http-code-400/338116 "2023-07-13T09:55:29Z")

</div>

Hi all, I have a logstash output http plugin: output { if \[@metadata\]\[index\_to\_delete\] == "first\_index" or \[@metadata\]\[index\_to\_delete\] == "second\_index" { http { id =\> "http\_index\_delete" …

---

## [Reduce storage taken by specific index ? Freeze index ? Frozen tier ? Cold tier?](https://discuss.elastic.co/t/reduce-storage-taken-by-specific-index-freeze-index-frozen-tier-cold-tier/338311)

<div class="topic-metadata">

**Author:** [@mlng54](https://discuss.elastic.co/u/mlng54)\
**Replies:** 0\
**Last updated:** [July 13, 2023, 9:53am UTC](https://discuss.elastic.co/t/reduce-storage-taken-by-specific-index-freeze-index-frozen-tier-cold-tier/338311 "2023-07-13T09:53:13Z")

</div>

Hi everyone, I recently experienced a DDoS attack on my Apache server. The logs are sent to Elasticsearch, so my last indices are around 70Gb/day. I have not configured ILM on my ELK stack yet but I would like to reduce…

---

## [APM for external plugin](https://discuss.elastic.co/t/apm-for-external-plugin/338217)

<div class="topic-metadata">

**Author:** [@Sheereen](https://discuss.elastic.co/u/Sheereen)\
**Replies:** 8\
**Last updated:** [July 13, 2023, 9:43am UTC](https://discuss.elastic.co/t/apm-for-external-plugin/338217 "2023-07-13T09:43:27Z")

</div>

Hi, I am creating a custom plugin in Kibana 8.8.1 using React. I want to implement APM for the same. I have successfully set up fleet server and deployed agent. My ES instance is and kibana is set up in dev mode in …

---

## [Metricbeat - how to create two different index templates from me metricbeat.yml](https://discuss.elastic.co/t/metricbeat-how-to-create-two-different-index-templates-from-me-metricbeat-yml/338298)

<div class="topic-metadata">

**Author:** [@Terkea](https://discuss.elastic.co/u/Terkea)\
**Replies:** 0\
**Last updated:** [July 13, 2023, 9:01am UTC](https://discuss.elastic.co/t/metricbeat-how-to-create-two-different-index-templates-from-me-metricbeat-yml/338298 "2023-07-13T09:01:53Z")

</div>

Hello guys, I want to create two different index templates with different ILM policies for each module that I use in metricbeat. My metricbeat.yml metricbeat: modules: - hosts: - http://localhost:5067 metr…

---

## [Elasticsearch Stack monitoring feature does not work when using metricbeat to monitor elasticsearch cluster](https://discuss.elastic.co/t/elasticsearch-stack-monitoring-feature-does-not-work-when-using-metricbeat-to-monitor-elasticsearch-cluster/333451)

<div class="topic-metadata">

**Author:** [@ramdas](https://discuss.elastic.co/u/ramdas)\
**Replies:** 13\
**Last updated:** [July 13, 2023, 8:51am UTC](https://discuss.elastic.co/t/elasticsearch-stack-monitoring-feature-does-not-work-when-using-metricbeat-to-monitor-elasticsearch-cluster/333451 "2023-07-13T08:51:07Z")

</div>

Hi, I am using elasticsearch/kibana 8.7 and also using metricbeat 8.7 to monitor elasticsearch cluster in kubernetes environment. following is the elasticsearch module config in metricbeat: - module: elasticsearch x…

---

## [How to support complex filters in nested aggregation?](https://discuss.elastic.co/t/how-to-support-complex-filters-in-nested-aggregation/337444)

<div class="topic-metadata">

**Author:** [@crowod](https://discuss.elastic.co/u/crowod)\
**Replies:** 1\
**Last updated:** [July 13, 2023, 8:51am UTC](https://discuss.elastic.co/t/how-to-support-complex-filters-in-nested-aggregation/337444 "2023-07-13T08:51:56Z")

</div>

Here is my index mapping: { "mappings": { "properties": { "non\_nested\_field": { "type": "keyword" }, "nested\_field": { "type": "nested", "properties": { "subfiel…

---

## [My ELK CLuster health is showing yellow](https://discuss.elastic.co/t/my-elk-cluster-health-is-showing-yellow/338292)

<div class="topic-metadata">

**Author:** [@bbkunbi](https://discuss.elastic.co/u/bbkunbi)\
**Replies:** 0\
**Last updated:** [July 13, 2023, 8:39am UTC](https://discuss.elastic.co/t/my-elk-cluster-health-is-showing-yellow/338292 "2023-07-13T08:39:55Z")

</div>

My ELK Cluster health is showing yellow. Missing replica shards. i am creating index using python code es.index , in that where i have to define replica shard. image is attached.

---

## [Do we need to install nginx to bypass authentication of kibana dashboards when embeded in an external application?](https://discuss.elastic.co/t/do-we-need-to-install-nginx-to-bypass-authentication-of-kibana-dashboards-when-embeded-in-an-external-application/338168)

<div class="topic-metadata">

**Author:** [@Jvv\_Satya](https://discuss.elastic.co/u/Jvv_Satya)\
**Replies:** 4\
**Last updated:** [July 13, 2023, 8:39am UTC](https://discuss.elastic.co/t/do-we-need-to-install-nginx-to-bypass-authentication-of-kibana-dashboards-when-embeded-in-an-external-application/338168 "2023-07-13T08:39:19Z")

</div>

I have created Kibana Dashboards and embedded the iFrame URL in an application. It is asking to enter the username/password inside iFrame. So, how can we bypass and get rid of the login. The kibana version i am uisng is …

---

## [Fleet Server](https://discuss.elastic.co/t/fleet-server/337475)

<div class="topic-metadata">

**Author:** [@willsy](https://discuss.elastic.co/u/willsy)\
**Replies:** 2\
**Last updated:** [July 13, 2023, 8:38am UTC](https://discuss.elastic.co/t/fleet-server/337475 "2023-07-13T08:38:25Z")

</div>

Hello everyone, when trying to enroll my fleet server (which is on the same time and IP as the elasticsearch and kibana) i encounter the following errors. know that this sits behind a proxy so could potentially be that …

---

## [Issue with logstash](https://discuss.elastic.co/t/issue-with-logstash/338290)

<div class="topic-metadata">

**Author:** [@Hanni](https://discuss.elastic.co/u/Hanni)\
**Replies:** 0\
**Last updated:** [July 13, 2023, 8:15am UTC](https://discuss.elastic.co/t/issue-with-logstash/338290 "2023-07-13T08:15:05Z")

</div>

Hello, I have a question: when you have two different configuration files in the logstash conf.d directory, does this cause a problem when importing them into elasticsearch?

---

## [GeoIp based on custom field source.ip](https://discuss.elastic.co/t/geoip-based-on-custom-field-source-ip/338088)

<div class="topic-metadata">

**Author:** [@vasile](https://discuss.elastic.co/u/vasile)\
**Replies:** 4\
**Last updated:** [July 13, 2023, 7:27am UTC](https://discuss.elastic.co/t/geoip-based-on-custom-field-source-ip/338088 "2023-07-13T07:27:41Z")

</div>

Hi all, I am trying to parse a log message. The original log looks like this: Jul 10 08:51:10 prometheus sshd\[19074\]: Accepted password for my\_user from 1.1.1.1 port 1111 ssh2 My filebeat conf is bellow: --- filebeat…

---

## [Want to create technical support case in Elastic Search](https://discuss.elastic.co/t/want-to-create-technical-support-case-in-elastic-search/338277)

<div class="topic-metadata">

**Author:** [@swapnalimag](https://discuss.elastic.co/u/swapnalimag)\
**Replies:** 1\
**Last updated:** [July 13, 2023, 7:02am UTC](https://discuss.elastic.co/t/want-to-create-technical-support-case-in-elastic-search/338277 "2023-07-13T07:02:44Z")

</div>

I want access to the technical support in Elastic Search. I am Organisational owner but not able to access to the technical support. I have only access to account or billing.

---

## [Need assistance for Uninstalling fleet agent on multiple workstation remotely](https://discuss.elastic.co/t/need-assistance-for-uninstalling-fleet-agent-on-multiple-workstation-remotely/338282)

<div class="topic-metadata">

**Author:** [@swapnalimag](https://discuss.elastic.co/u/swapnalimag)\
**Replies:** 0\
**Last updated:** [July 13, 2023, 6:06am UTC](https://discuss.elastic.co/t/need-assistance-for-uninstalling-fleet-agent-on-multiple-workstation-remotely/338282 "2023-07-13T06:06:24Z")

</div>

Hello, Recently we have deployed fleet agent on windows workstations remotely through GPO. Some of the workstations are facing high CPU usage issue. For That we need assistance for uninstalling the agents remotely. I ca…

---

## [Is leader sync cluster state to node when new node join cluster?](https://discuss.elastic.co/t/is-leader-sync-cluster-state-to-node-when-new-node-join-cluster/338185)

<div class="topic-metadata">

**Author:** [@cm\_z](https://discuss.elastic.co/u/cm_z)\
**Replies:** 4\
**Last updated:** [July 13, 2023, 5:54am UTC](https://discuss.elastic.co/t/is-leader-sync-cluster-state-to-node-when-new-node-join-cluster/338185 "2023-07-13T05:54:58Z")

</div>

When a new node or a previously joined node that was later expelled joins a stable cluster, will the leader synchronize the latest cluster status with them? If so, who can tell me where to find this functionality? I have…

---

## [Action over webhook status](https://discuss.elastic.co/t/action-over-webhook-status/338278)

<div class="topic-metadata">

**Author:** [@ddoroshenko](https://discuss.elastic.co/u/ddoroshenko)\
**Replies:** 0\
**Last updated:** [July 13, 2023, 5:45am UTC](https://discuss.elastic.co/t/action-over-webhook-status/338278 "2023-07-13T05:45:20Z")

</div>

Hi, I have a watcher with webhook action in it. Is it possible to make another action based on webhook response status? Something like that actions: { webhook\_action: { webhook: { scheme: host: …

---

## [LogStash::Json::ParserError: Unexpected character (':' (code 58))](https://discuss.elastic.co/t/logstash-unexpected-character-code-58/337864)

<div class="topic-metadata">

**Author:** [@shailendra1](https://discuss.elastic.co/u/shailendra1)\
**Replies:** 1\
**Last updated:** [July 13, 2023, 5:17am UTC](https://discuss.elastic.co/t/logstash-unexpected-character-code-58/337864 "2023-07-13T05:17:49Z")

</div>

i am facing the unexpected character error code 58 in my json data. even after validation of the data the logstash is reporting the errors . below is the sample data , can anyone help why logstash reporting an error here…

---

## [Elasticsearch 8.8: Master not discovered or elected yet, an election requires at least 2 nodes with ids from \[..\]](https://discuss.elastic.co/t/elasticsearch-8-8-master-not-discovered-or-elected-yet-an-election-requires-at-least-2-nodes-with-ids-from/338034)

<div class="topic-metadata">

**Author:** [@bhavya](https://discuss.elastic.co/u/bhavya)\
**Replies:** 2\
**Last updated:** [July 13, 2023, 5:17am UTC](https://discuss.elastic.co/t/elasticsearch-8-8-master-not-discovered-or-elected-yet-an-election-requires-at-least-2-nodes-with-ids-from/338034 "2023-07-13T05:17:48Z")

</div>

I am creating a multinode cluster (3 Master Nodes), having the configuration like xpack.ml.enabled: false xpack.security.enabled: false network.host: \[\_local\_, \_site\_\] path.data: /data/esdata path.logs: /data/logs xpack…

---

## [Calculate Unix timestamp difference in kibana](https://discuss.elastic.co/t/calculate-unix-timestamp-difference-in-kibana/338241)

<div class="topic-metadata">

**Author:** [@Babu72](https://discuss.elastic.co/u/Babu72)\
**Replies:** 4\
**Last updated:** [July 13, 2023, 5:13am UTC](https://discuss.elastic.co/t/calculate-unix-timestamp-difference-in-kibana/338241 "2023-07-13T05:13:49Z")

</div>

Hi All, I need help for new scripted field to calculate Unix timestamp difference in kibana as a Metric stop\_timestamp : start\_timestamp : output: hh:mm:ss:SS:SS 1 = 1 Nanosecond 1000 = 1 Microsecond 1000000 = 1 Milli…

---

## [Uploading ML Models into Elasticsearch](https://discuss.elastic.co/t/uploading-ml-models-into-elasticsearch/338195)

<div class="topic-metadata">

**Author:** [@ksaimohan2k](https://discuss.elastic.co/u/ksaimohan2k)\
**Replies:** 15\
**Last updated:** [July 13, 2023, 5:04am UTC](https://discuss.elastic.co/t/uploading-ml-models-into-elasticsearch/338195 "2023-07-13T05:04:09Z")

</div>

I am trying to upload ML Model into elasticsearch using the eland script provided in the documentation. Installed Python, eland & Pytorch but still unable to upload. python version : Python 3.7.9 Eland version : 8.3…

[Previous page](https://discuss.elastic.co/latest.md?page=607)

[Next page](https://discuss.elastic.co/latest.md?page=609)
