# Latest

**URL:** https://discuss.elastic.co/latest.md?page=609

[Latest](https://discuss.elastic.co/latest.md) · [Categories](https://discuss.elastic.co/categories.md) · [Tags](https://discuss.elastic.co/tags.md)

**Page:** 610

---

## [Documentation on running our own elastic package storage](https://discuss.elastic.co/t/documentation-on-running-our-own-elastic-package-storage/338274)

<div class="topic-metadata">

**Author:** [@hari\_ibm](https://discuss.elastic.co/u/hari_ibm)\
**Replies:** 0\
**Last updated:** [July 13, 2023, 4:43am UTC](https://discuss.elastic.co/t/documentation-on-running-our-own-elastic-package-storage/338274 "2023-07-13T04:43:09Z")

</div>

Documentation on running our own elastic package storage I have build custom integration and also have setup our own elastic package registry? I couldn't able to find documentation on pushing the package to my registry

---

## [Is elastic Ingest pipelines resource intensive?](https://discuss.elastic.co/t/is-elastic-ingest-pipelines-resource-intensive/338049)

<div class="topic-metadata">

**Author:** [@JasonREC](https://discuss.elastic.co/u/JasonREC)\
**Replies:** 7\
**Last updated:** [July 13, 2023, 4:30am UTC](https://discuss.elastic.co/t/is-elastic-ingest-pipelines-resource-intensive/338049 "2023-07-13T04:30:05Z")

</div>

Hi, I am currently using injest pipelines to enrich my document before it wrote into index. I am wondering if this process would have a potenial hugh resouce(heap ram or cpu) comsumed for my Elasticsearch node behind …

---

## [Hostname/IP does not match certificate's altnames](https://discuss.elastic.co/t/hostname-ip-does-not-match-certificates-altnames/338234)

<div class="topic-metadata">

**Author:** [@ANUBHAV\_GUPTA](https://discuss.elastic.co/u/ANUBHAV_GUPTA)\
**Replies:** 2\
**Last updated:** [July 13, 2023, 3:11am UTC](https://discuss.elastic.co/t/hostname-ip-does-not-match-certificates-altnames/338234 "2023-07-13T03:11:36Z")

</div>

Hi there, I am trying to enroll kibana with elasticsearch cluster. Here is my deployment detail. I have deployed an Elasticsearch cluster on an EC2 instance using docker and, I am able to access it using the publicI…

---

## [Index template failing with "reason": "unknown key \[index\_patterns\] for create index"](https://discuss.elastic.co/t/index-template-failing-with-reason-unknown-key-index-patterns-for-create-index/338270)

<div class="topic-metadata">

**Author:** [@shailendra1](https://discuss.elastic.co/u/shailendra1)\
**Replies:** 0\
**Last updated:** [July 13, 2023, 3:04am UTC](https://discuss.elastic.co/t/index-template-failing-with-reason-unknown-key-index-patterns-for-create-index/338270 "2023-07-13T03:04:51Z")

</div>

I am facing the unknown key for my index template creation time, "reason": "unknown key \[index\_patterns\] for create index" below is the top heading of my template { "index\_patterns" : \[ "data\_center-…

---

## [Enroll Kibana using the Elasticsearch "\_security/enroll/kibana" API](https://discuss.elastic.co/t/enroll-kibana-using-the-elasticsearch-security-enroll-kibana-api/338117)

<div class="topic-metadata">

**Author:** [@ANUBHAV\_GUPTA](https://discuss.elastic.co/u/ANUBHAV_GUPTA)\
**Replies:** 2\
**Last updated:** [July 13, 2023, 3:02am UTC](https://discuss.elastic.co/t/enroll-kibana-using-the-elasticsearch-security-enroll-kibana-api/338117 "2023-07-13T03:02:46Z")

</div>

Hi, I am generating an enrollment token using curl -k https://username:password@address:9200/\_security/enroll/kibana Now, If I am using the token in Kibana enrollment token pagafter starting, am getting error as:- En…

---

## [Installing elastic agent using K8S is not normal](https://discuss.elastic.co/t/installing-elastic-agent-using-k8s-is-not-normal/337064)

<div class="topic-metadata">

**Author:** [@L1NG](https://discuss.elastic.co/u/L1NG)\
**Replies:** 9\
**Last updated:** [July 13, 2023, 2:11am UTC](https://discuss.elastic.co/t/installing-elastic-agent-using-k8s-is-not-normal/337064 "2023-07-13T02:11:26Z")

</div>

1.Install the elastic agent using K8S and check if the pod is running. The result is that it is running 2.But it's not normal to see it in Kibana 3.View detailed proxy information, which shows that there is an issue wi…

---

## [When I installed the ELASTICSEARCH 8.8.1, I am not able to change the number of replicas of .security and .security-profile index](https://discuss.elastic.co/t/when-i-installed-the-elasticsearch-8-8-1-i-am-not-able-to-change-the-number-of-replicas-of-security-and-security-profile-index/337597)

<div class="topic-metadata">

**Author:** [@KunwarAkanksha](https://discuss.elastic.co/u/KunwarAkanksha)\
**Replies:** 2\
**Last updated:** [July 13, 2023, 12:10am UTC](https://discuss.elastic.co/t/when-i-installed-the-elasticsearch-8-8-1-i-am-not-able-to-change-the-number-of-replicas-of-security-and-security-profile-index/337597 "2023-07-13T00:10:49Z")

</div>

If the Node having the .security index goes down the whole cluster is not functioning. And superuser elastic is unable to edit the setting of this .security index

---

## [Action over webhook status](https://discuss.elastic.co/t/action-over-webhook-status/338055)

<div class="topic-metadata">

**Author:** [@ddoroshenko](https://discuss.elastic.co/u/ddoroshenko)\
**Replies:** 1\
**Last updated:** [July 13, 2023, 12:02am UTC](https://discuss.elastic.co/t/action-over-webhook-status/338055 "2023-07-13T00:02:56Z")

</div>

Hi, I have a watcher with webhook action in it. Is it possible to make another action based on webhook response status? Something like that actions: { webhook\_action: { webhook: { scheme: host: …

---

## [Rollover of indices doesn't work any more](https://discuss.elastic.co/t/rollover-of-indices-doesnt-work-any-more/338075)

<div class="topic-metadata">

**Author:** [@ronin667](https://discuss.elastic.co/u/ronin667)\
**Replies:** 1\
**Last updated:** [July 12, 2023, 11:54pm UTC](https://discuss.elastic.co/t/rollover-of-indices-doesnt-work-any-more/338075 "2023-07-12T23:54:46Z")

</div>

Hi community, we're running an Elastic Cloud cluster with Elasticsearch and Kibana that has been giving us some trouble in the last few weeks. After our cluster ran out of storage a few weeks ago, the cluster stopped a…

---

## [Multiple events processing and runtime fields](https://discuss.elastic.co/t/multiple-events-processing-and-runtime-fields/338115)

<div class="topic-metadata">

**Author:** [@Thibadu](https://discuss.elastic.co/u/Thibadu)\
**Replies:** 1\
**Last updated:** [July 12, 2023, 11:23pm UTC](https://discuss.elastic.co/t/multiple-events-processing-and-runtime-fields/338115 "2023-07-12T23:23:45Z")

</div>

Hello there, I am currently working on how to raise an alert in Kibana in case a field's value is identical across two different events. Here's how my setup is configured : Network traffic -\> Suricata -\> log file -\> F…

---

## [How do I get unique keys counts, not unique values per key?](https://discuss.elastic.co/t/how-do-i-get-unique-keys-counts-not-unique-values-per-key/338044)

<div class="topic-metadata">

**Author:** [@ecc256](https://discuss.elastic.co/u/ecc256)\
**Replies:** 1\
**Last updated:** [July 12, 2023, 10:48pm UTC](https://discuss.elastic.co/t/how-do-i-get-unique-keys-counts-not-unique-values-per-key/338044 "2023-07-12T22:48:00Z")

</div>

I have a collections of documents. What query can produce unique keys counts (for a time interval), not unique values per key? It might be too simple to do and not mentioned anywhere... thus I cannot find it?

---

## [Elastic Search / ILM / Snapshots S3/Minio](https://discuss.elastic.co/t/elastic-search-ilm-snapshots-s3-minio/338263)

<div class="topic-metadata">

**Author:** [@datencio](https://discuss.elastic.co/u/datencio)\
**Replies:** 1\
**Last updated:** [July 12, 2023, 10:42pm UTC](https://discuss.elastic.co/t/elastic-search-ilm-snapshots-s3-minio/338263 "2023-07-12T22:42:59Z")

</div>

I have been asked to do a POC to see how to properly configure our systems so that ILM will before it deletes an indice will take a snapshot of the indice and store it into S3/Minio. I have successfully updated the clust…

---

## [Dashboard which automatically selects today's index](https://discuss.elastic.co/t/dashboard-which-automatically-selects-todays-index/338142)

<div class="topic-metadata">

**Author:** [@Sam\_Estes](https://discuss.elastic.co/u/Sam_Estes)\
**Replies:** 2\
**Last updated:** [July 12, 2023, 10:35pm UTC](https://discuss.elastic.co/t/dashboard-which-automatically-selects-todays-index/338142 "2023-07-12T22:35:39Z")

</div>

Hello, I have a database with an index for each day. I would like to create a dashboard with visualizations using data from today's index. Each day, we create a new index so I would like the dashboard to automatically u…

---

## [Sometimes I fail to start up and the error message is as follows.](https://discuss.elastic.co/t/sometimes-i-fail-to-start-up-and-the-error-message-is-as-follows/338174)

<div class="topic-metadata">

**Author:** [@pl02206984](https://discuss.elastic.co/u/pl02206984)\
**Replies:** 2\
**Last updated:** [July 12, 2023, 9:46pm UTC](https://discuss.elastic.co/t/sometimes-i-fail-to-start-up-and-the-error-message-is-as-follows/338174 "2023-07-12T21:46:54Z")

</div>

Sometimes I fail to start up and the error message is as follows. \[2023-07-12T10:50:36,815\]\[ERROR\]\[logstash.config.sourceloader\] No configuration found in the configured sources. \[2023-07-12T10:50:36,932\]\[INFO \]\[logstas…

---

## [In ElasticSearch8.5.1, sorted by longitude and latitude](https://discuss.elastic.co/t/in-elasticsearch8-5-1-sorted-by-longitude-and-latitude/338187)

<div class="topic-metadata">

**Author:** [@maoqingjue](https://discuss.elastic.co/u/maoqingjue)\
**Replies:** 1\
**Last updated:** [July 12, 2023, 8:44pm UTC](https://discuss.elastic.co/t/in-elasticsearch8-5-1-sorted-by-longitude-and-latitude/338187 "2023-07-12T20:44:08Z")

</div>

In Elasticsearch8.5.1, sorted by longitude and latitude, my data format is: Post\_info\_address\_index:\[ { LatALng:{ Lat: 37.520804, Lon: 121.219555 } }, { LatALng:{ Lat: 37.520496, Lon: 121.220644 } } \] I us…

---

## [Node repurpose from data to master made primary shard unavailable. How to reset the cluster as API not working](https://discuss.elastic.co/t/node-repurpose-from-data-to-master-made-primary-shard-unavailable-how-to-reset-the-cluster-as-api-not-working/338258)

<div class="topic-metadata">

**Author:** [@vaibhav.ubale](https://discuss.elastic.co/u/vaibhav.ubale)\
**Replies:** 0\
**Last updated:** [July 12, 2023, 8:12pm UTC](https://discuss.elastic.co/t/node-repurpose-from-data-to-master-made-primary-shard-unavailable-how-to-reset-the-cluster-as-api-not-working/338258 "2023-07-12T20:12:31Z")

</div>

node repurpose from data to master made primary shard unavailable. How to reset the cluster as API not working. I am ok to loose the data but not able to start the cluster a fresh. Please suggest.

---

## [How to make Visualization x axis terms in certain order](https://discuss.elastic.co/t/how-to-make-visualization-x-axis-terms-in-certain-order/338038)

<div class="topic-metadata">

**Author:** [@grace\_Li](https://discuss.elastic.co/u/grace_Li)\
**Replies:** 2\
**Last updated:** [July 12, 2023, 7:49pm UTC](https://discuss.elastic.co/t/how-to-make-visualization-x-axis-terms-in-certain-order/338038 "2023-07-12T19:49:02Z")

</div>

Hi, I'm trying to build a visualization with some text type terms as x-axis. Is there a way to put these text value in a given order instead of by alphabetical? For example I'd like to have the response time as Y-axis…

---

## [Sending request to one index, writing to multiple indices](https://discuss.elastic.co/t/sending-request-to-one-index-writing-to-multiple-indices/338079)

<div class="topic-metadata">

**Author:** [@Aditya\_Teltia](https://discuss.elastic.co/u/Aditya_Teltia)\
**Replies:** 23\
**Last updated:** [July 12, 2023, 7:19pm UTC](https://discuss.elastic.co/t/sending-request-to-one-index-writing-to-multiple-indices/338079 "2023-07-12T19:19:13Z")

</div>

I have a index named index1. I want to configure it such that any write/update request that comes to index1 gets written to both index1 and index2 but any search request still uses index1. Is this possible with some exis…

---

## [Ingest error from one pipeline causing errors in other pipelines](https://discuss.elastic.co/t/ingest-error-from-one-pipeline-causing-errors-in-other-pipelines/338255)

<div class="topic-metadata">

**Author:** [@twilson](https://discuss.elastic.co/u/twilson)\
**Replies:** 0\
**Last updated:** [July 12, 2023, 6:53pm UTC](https://discuss.elastic.co/t/ingest-error-from-one-pipeline-causing-errors-in-other-pipelines/338255 "2023-07-12T18:53:42Z")

</div>

The problem we are experiencing is that an ingest error from the Apache integration (agent) is causing an enrichment processor in a separate pipeline to fail with the same error the Apache processor failed with. This is…

---

## [Elasticsearch 7.17 suddenly prevents login](https://discuss.elastic.co/t/elasticsearch-7-17-suddenly-prevents-login/338249)

<div class="topic-metadata">

**Author:** [@eastdrive](https://discuss.elastic.co/u/eastdrive)\
**Replies:** 4\
**Last updated:** [July 12, 2023, 6:35pm UTC](https://discuss.elastic.co/t/elasticsearch-7-17-suddenly-prevents-login/338249 "2023-07-12T18:35:38Z")

</div>

I installed elasticsearch 7.17.11 from the artifacts.elastic.co repo with security, on a fresh Ubuntu 20.04.6 node a couple of days ago, for a Magento 2.4.5-p3 store. It worked fine, certainly allowed me to connect remot…

---

## [Rule Actions Sometimes Don't Fire](https://discuss.elastic.co/t/rule-actions-sometimes-dont-fire/338245)

<div class="topic-metadata">

**Author:** [@SomeRobot](https://discuss.elastic.co/u/SomeRobot)\
**Replies:** 2\
**Last updated:** [July 12, 2023, 5:49pm UTC](https://discuss.elastic.co/t/rule-actions-sometimes-dont-fire/338245 "2023-07-12T17:49:06Z")

</div>

We have hundreds of rules created in Elastic Security which we are leveraging as our SIEM, many Elastic created, some are ours. These rules are all configured to perform the same action, which is to send some details to …

---

## [Filebeat service is failing again and again](https://discuss.elastic.co/t/filebeat-service-is-failing-again-and-again/337642)

<div class="topic-metadata">

**Author:** [@Kanika\_Gola](https://discuss.elastic.co/u/Kanika_Gola)\
**Replies:** 3\
**Last updated:** [July 12, 2023, 5:33pm UTC](https://discuss.elastic.co/t/filebeat-service-is-failing-again-and-again/337642 "2023-07-12T17:33:47Z")

</div>

---

## [Visualization - Threshold Value Based](https://discuss.elastic.co/t/visualization-threshold-value-based/338026)

<div class="topic-metadata">

**Author:** [@Surabhi\_Pol](https://discuss.elastic.co/u/Surabhi_Pol)\
**Replies:** 1\
**Last updated:** [July 12, 2023, 5:08pm UTC](https://discuss.elastic.co/t/visualization-threshold-value-based/338026 "2023-07-12T17:08:37Z")

</div>

Hi All, We are using Kibana (Stack Management 7.16.1) for analyzing purpose. Here some vital information's about servers/applications - success / failure rate we are visualizing through dashboards - Visualizations (char…

---

## [Cannot increase buffer: current=512000 requested=544768 max=512000](https://discuss.elastic.co/t/cannot-increase-buffer-current-512000-requested-544768-max-512000/338020)

<div class="topic-metadata">

**Author:** [@premkumarmuddeneni](https://discuss.elastic.co/u/premkumarmuddeneni)\
**Replies:** 1\
**Last updated:** [July 12, 2023, 5:06pm UTC](https://discuss.elastic.co/t/cannot-increase-buffer-current-512000-requested-544768-max-512000/338020 "2023-07-12T17:06:36Z")

</div>

We are using Elastic search of V8.7.0 and fluent bit v2.0.10 and kubernetes is v1.24. We had deployed the Fluent bit as a daemon set in kubernetes and collecting the logs from pods and pushing to Elasticsearch We are f…

---

## [Filebeat is using more than 4GB memory](https://discuss.elastic.co/t/filebeat-is-using-more-than-4gb-memory/337952)

<div class="topic-metadata">

**Author:** [@Sharad\_Dubey](https://discuss.elastic.co/u/Sharad_Dubey)\
**Replies:** 1\
**Last updated:** [July 12, 2023, 4:53pm UTC](https://discuss.elastic.co/t/filebeat-is-using-more-than-4gb-memory/337952 "2023-07-12T16:53:56Z")

</div>

Hi Champs, My filebeat consumtipn is very high and using more than 4GB of RAM, only log files which I am pushing are some app logs , /var/log/messages and /var/log/secure. Npt sure why this happening. Please help \[roo…

---

## [Kibana Dashboards for inventory tracking with deleted indexes](https://discuss.elastic.co/t/kibana-dashboards-for-inventory-tracking-with-deleted-indexes/337693)

<div class="topic-metadata">

**Author:** [@Sam\_Estes](https://discuss.elastic.co/u/Sam_Estes)\
**Replies:** 5\
**Last updated:** [July 12, 2023, 4:46pm UTC](https://discuss.elastic.co/t/kibana-dashboards-for-inventory-tracking-with-deleted-indexes/337693 "2023-07-12T16:46:43Z")

</div>

Hi, I have an ES database which is updated daily. We maintain two indexes (one for each day's worth of data). During the update, the older of the two indexes is deleted and a new one is created for the new day. We want t…

---

## [Alerts from Kibana log monitoring](https://discuss.elastic.co/t/alerts-from-kibana-log-monitoring/337769)

<div class="topic-metadata">

**Author:** [@SMaric](https://discuss.elastic.co/u/SMaric)\
**Replies:** 1\
**Last updated:** [July 12, 2023, 4:46pm UTC](https://discuss.elastic.co/t/alerts-from-kibana-log-monitoring/337769 "2023-07-12T16:46:38Z")

</div>

Hi We have configured Kibana to ingest our application log files Now we want an Alert from Kibana if it sees 2 log file signals (within a reasonable time of each other) Can someone please point me at an example of ho…

---

## [Does kibana will restart if it can't connect to elasticsearh?](https://discuss.elastic.co/t/does-kibana-will-restart-if-it-cant-connect-to-elasticsearh/337545)

<div class="topic-metadata">

**Author:** [@yuswanul](https://discuss.elastic.co/u/yuswanul)\
**Replies:** 1\
**Last updated:** [July 12, 2023, 4:36pm UTC](https://discuss.elastic.co/t/does-kibana-will-restart-if-it-cant-connect-to-elasticsearh/337545 "2023-07-12T16:36:21Z")

</div>

Hi there, i have a question about kibana. so i have a VM that installed kibana and elastic there. then at some point, my elastic is experience OOM, so it produce hprof file. but bufore i knew that my elastic was OOM, i …

---

## [Version mismatch message even though versions match](https://discuss.elastic.co/t/version-mismatch-message-even-though-versions-match/337819)

<div class="topic-metadata">

**Author:** [@McJava1967](https://discuss.elastic.co/u/McJava1967)\
**Replies:** 15\
**Last updated:** [July 12, 2023, 3:49pm UTC](https://discuss.elastic.co/t/version-mismatch-message-even-though-versions-match/337819 "2023-07-12T15:49:08Z")

</div>

Hi all. I'm trying out ELK 8.8.2, and getting this message: Job creation error The client noticed that the server is not Elasticsearch and we do not support this unknown product. All explanations in various posts s…

---

## [Periodic disconnection of same data nodes](https://discuss.elastic.co/t/periodic-disconnection-of-same-data-nodes/338197)

<div class="topic-metadata">

**Author:** [@alissan](https://discuss.elastic.co/u/alissan)\
**Replies:** 5\
**Last updated:** [July 12, 2023, 3:01pm UTC](https://discuss.elastic.co/t/periodic-disconnection-of-same-data-nodes/338197 "2023-07-12T15:01:53Z")

</div>

Hello, I have a cluster with 3 master, 40 data nodes (d1,d2,...,d40). First 5 data nodes have voting only master role. Only the following data nodes have periodic abnormal behavior: d11,d12,d13,d14,d15,d16,d17,d21,d2…

[Previous page](https://discuss.elastic.co/latest.md?page=608)

[Next page](https://discuss.elastic.co/latest.md?page=610)
