# Latest

**URL:** https://discuss.elastic.co/latest.md?page=610

[Latest](https://discuss.elastic.co/latest.md) · [Categories](https://discuss.elastic.co/categories.md) · [Tags](https://discuss.elastic.co/tags.md)

**Page:** 611

---

## [Select Timeout parameter for python helper async\_bulk](https://discuss.elastic.co/t/select-timeout-parameter-for-python-helper-async-bulk/338037)

<div class="topic-metadata">

**Author:** [@ionFreeman](https://discuss.elastic.co/u/ionFreeman)\
**Replies:** 1\
**Last updated:** [July 12, 2023, 2:53pm UTC](https://discuss.elastic.co/t/select-timeout-parameter-for-python-helper-async-bulk/338037 "2023-07-12T14:53:22Z")

</div>

Hello! Every so often, my async\_bulk load fails with a Connection Timeout. I have my timeout parameter set to 60; I had set it arbitrarily high, but it didn't pass code review. I can't just wrap the call in tenacity as I…

---

## [Another mysterious work logstash with errors \_grokparsefailure](https://discuss.elastic.co/t/another-mysterious-work-logstash-with-errors-grokparsefailure/337327)

<div class="topic-metadata">

**Author:** [@San9](https://discuss.elastic.co/u/San9)\
**Replies:** 18\
**Last updated:** [July 12, 2023, 2:51pm UTC](https://discuss.elastic.co/t/another-mysterious-work-logstash-with-errors-grokparsefailure/337327 "2023-07-12T14:51:43Z")

</div>

again I encounter a problem in the work of logstash, and specifically with grock. Everything is fine in the debugger, the messages are parsed, but as soon as I apply this configuration to the production, then these messa…

---

## [Log Stash Sql Server](https://discuss.elastic.co/t/log-stash-sql-server/338233)

<div class="topic-metadata">

**Author:** [@balupad14](https://discuss.elastic.co/u/balupad14)\
**Replies:** 1\
**Last updated:** [July 12, 2023, 2:49pm UTC](https://discuss.elastic.co/t/log-stash-sql-server/338233 "2023-07-12T14:49:07Z")

</div>

Hi all, I am trying to insert the data into the Elasticsearch from SQL Server. When I run the logstash, I am getting this error. Not eligible for data streams because config contains one or more settings that are not c…

---

## [Multiple instance of kibana sometime error status 404](https://discuss.elastic.co/t/multiple-instance-of-kibana-sometime-error-status-404/337980)

<div class="topic-metadata">

**Author:** [@lusynda](https://discuss.elastic.co/u/lusynda)\
**Replies:** 1\
**Last updated:** [July 12, 2023, 2:33pm UTC](https://discuss.elastic.co/t/multiple-instance-of-kibana-sometime-error-status-404/337980 "2023-07-12T14:33:10Z")

</div>

Hi all, I've tried to use multiple instance of kibana to HA. but then sometime i encounter error like this after refresh the page for a few times i was able to load the page but the problems persists very often for …

---

## [I want to get last record saved to Elasticsearch](https://discuss.elastic.co/t/i-want-to-get-last-record-saved-to-elasticsearch/338235)

<div class="topic-metadata">

**Author:** [@Valerie\_Barbacion](https://discuss.elastic.co/u/Valerie_Barbacion)\
**Replies:** 0\
**Last updated:** [July 12, 2023, 2:32pm UTC](https://discuss.elastic.co/t/i-want-to-get-last-record-saved-to-elasticsearch/338235 "2023-07-12T14:32:51Z")

</div>

Hi Pals, I have a question about throwing request to Elasticsearch. For example given I will going to send a first message to Elasticsearch with has a field value "Sample" and then I send again another message with diffe…

---

## [Not able to fetch data from openshift cluster, when using different namespace](https://discuss.elastic.co/t/not-able-to-fetch-data-from-openshift-cluster-when-using-different-namespace/338232)

<div class="topic-metadata">

**Author:** [@suryakant.k](https://discuss.elastic.co/u/suryakant.k)\
**Replies:** 0\
**Last updated:** [July 12, 2023, 2:12pm UTC](https://discuss.elastic.co/t/not-able-to-fetch-data-from-openshift-cluster-when-using-different-namespace/338232 "2023-07-12T14:12:16Z")

</div>

I need to add elastic agent host in openshift kubernetes cluster, When I am changing namespace in yaml file to elk from kube-system, Pods are not getting ready, daemonset is not ready. But when I am using kube-system a…

---

## [Exiting: Error reading config file: required 'object', but found 'string' in field 'filebeat.inputs.0' (source:'filebeat.yml')](https://discuss.elastic.co/t/exiting-error-reading-config-file-required-object-but-found-string-in-field-filebeat-inputs-0-source-filebeat-yml/337940)

<div class="topic-metadata">

**Author:** [@Bhakti\_Bhabal](https://discuss.elastic.co/u/Bhakti_Bhabal)\
**Replies:** 5\
**Last updated:** [July 12, 2023, 2:07pm UTC](https://discuss.elastic.co/t/exiting-error-reading-config-file-required-object-but-found-string-in-field-filebeat-inputs-0-source-filebeat-yml/337940 "2023-07-12T14:07:37Z")

</div>

HI Guys i have created the below sample filebeat.yml and verified through yamalint still i am getting the same error . I am trying to setup filebeat to work with elastic and the filebeat itself wont start up giving the e…

---

## [When namespace in kube-state-metrics are changed from kube-system to other, Daemonset is not ready](https://discuss.elastic.co/t/when-namespace-in-kube-state-metrics-are-changed-from-kube-system-to-other-daemonset-is-not-ready/338231)

<div class="topic-metadata">

**Author:** [@suryakant.k](https://discuss.elastic.co/u/suryakant.k)\
**Replies:** 0\
**Last updated:** [July 12, 2023, 1:55pm UTC](https://discuss.elastic.co/t/when-namespace-in-kube-state-metrics-are-changed-from-kube-system-to-other-daemonset-is-not-ready/338231 "2023-07-12T13:55:54Z")

</div>

I want to install a elastic-agent in openshift kubernetes cluster, for that I was installing a kube-state-metrics with elk namespace as I dont want to install it in kube-system namespace. After running command, I get th…

---

## [Values field event.action for Cisco ASA integration](https://discuss.elastic.co/t/values-field-event-action-for-cisco-asa-integration/337794)

<div class="topic-metadata">

**Author:** [@frederikvandeputte](https://discuss.elastic.co/u/frederikvandeputte)\
**Replies:** 6\
**Last updated:** [July 12, 2023, 2:04pm UTC](https://discuss.elastic.co/t/values-field-event-action-for-cisco-asa-integration/337794 "2023-07-12T14:04:30Z")

</div>

Hi Currently parsed events coming from Cisco ASA firewall ingest pipeline show 4 types of values in field event.action: firewall-rule; flow-expiration; flow-creation and error. Value "firewall-rule" is very much a us…

---

## [Creating an Elasticsearch Alert Email Connector containing "winlog.event\_data.TargetUserName"?](https://discuss.elastic.co/t/creating-an-elasticsearch-alert-email-connector-containing-winlog-event-data-targetusername/338222)

<div class="topic-metadata">

**Author:** [@Emorta](https://discuss.elastic.co/u/Emorta)\
**Replies:** 0\
**Last updated:** [July 12, 2023, 1:03pm UTC](https://discuss.elastic.co/t/creating-an-elasticsearch-alert-email-connector-containing-winlog-event-data-targetusername/338222 "2023-07-12T13:03:09Z")

</div>

Hello Elastic Community, I Created a Alert type "Elasticsearch query" that looks for a specifc winlog.event\_id:"XXXX" and triggers when threshold it is above "x" value. There is a Email connector all this works perfec…

---

## [Creating graph in kibana](https://discuss.elastic.co/t/creating-graph-in-kibana/338208)

<div class="topic-metadata">

**Author:** [@Neelam\_Zanvar](https://discuss.elastic.co/u/Neelam_Zanvar)\
**Replies:** 1\
**Last updated:** [July 12, 2023, 12:58pm UTC](https://discuss.elastic.co/t/creating-graph-in-kibana/338208 "2023-07-12T12:58:19Z")

</div>

Hi i want to try out kibana graphs. How can i get started? i am referring this document But i don't find the graphs option in the menu in kibana. I am using kibana 8.7

---

## [To get message field for json filter](https://discuss.elastic.co/t/to-get-message-field-for-json-filter/337968)

<div class="topic-metadata">

**Author:** [@a.emrekaraman](https://discuss.elastic.co/u/a.emrekaraman)\
**Replies:** 5\
**Last updated:** [July 12, 2023, 12:44pm UTC](https://discuss.elastic.co/t/to-get-message-field-for-json-filter/337968 "2023-07-12T12:44:48Z")

</div>

Hi Team, I use json filter to parse my json data but my json data has "message" value. that's why ı'm not able to get standard message field which have all parsed log. I just have "message" field which come from json l…

---

## [Data storage stragety](https://discuss.elastic.co/t/data-storage-stragety/338159)

<div class="topic-metadata">

**Author:** [@JasonREC](https://discuss.elastic.co/u/JasonREC)\
**Replies:** 3\
**Last updated:** [July 12, 2023, 12:04pm UTC](https://discuss.elastic.co/t/data-storage-stragety/338159 "2023-07-12T12:04:50Z")

</div>

Hi, I wonder if I already have couple indices that contains a big size of data. I wonder if using snapshot or best compression are good ways to help reduding the size of the existing indices. I have looked at the docu…

---

## [Problem with new script](https://discuss.elastic.co/t/problem-with-new-script/337800)

<div class="topic-metadata">

**Author:** [@Valerija](https://discuss.elastic.co/u/Valerija)\
**Replies:** 33\
**Last updated:** [July 12, 2023, 11:49am UTC](https://discuss.elastic.co/t/problem-with-new-script/337800 "2023-07-12T11:49:08Z")

</div>

Hi there, I created a simple new script and it works w/o problems: def totalGood = doc\['actualQuantity'\].value - doc\['failureQuantity'\].value; return totalGood; Then I tried to create another one and this one does not…

---

## [Issues with pushing packages to my own package registry](https://discuss.elastic.co/t/issues-with-pushing-packages-to-my-own-package-registry/338209)

<div class="topic-metadata">

**Author:** [@hari\_ibm](https://discuss.elastic.co/u/hari_ibm)\
**Replies:** 0\
**Last updated:** [July 12, 2023, 11:40am UTC](https://discuss.elastic.co/t/issues-with-pushing-packages-to-my-own-package-registry/338209 "2023-07-12T11:40:24Z")

</div>

I have created new package and i want to push it to my custom hosted package registry? How to update the packages list in my custom hosted package registry?

---

## [How to upgrade metricbeat from 7.17.11 to 7.17.xx or 8.1.xx?](https://discuss.elastic.co/t/how-to-upgrade-metricbeat-from-7-17-11-to-7-17-xx-or-8-1-xx/338183)

<div class="topic-metadata">

**Author:** [@Swathi12](https://discuss.elastic.co/u/Swathi12)\
**Replies:** 2\
**Last updated:** [July 12, 2023, 11:13am UTC](https://discuss.elastic.co/t/how-to-upgrade-metricbeat-from-7-17-11-to-7-17-xx-or-8-1-xx/338183 "2023-07-12T11:13:59Z")

</div>

How do i upgrade next time from 7.17.11 to 7.17.xx ? or 8.x.x Is there any command which i can use in the Kibana DEV Tool ? Or how is the possible and easy way to do it ?

---

## [How is the transaction.\_start set? (elastic RUM)](https://discuss.elastic.co/t/how-is-the-transaction-start-set-elastic-rum/338077)

<div class="topic-metadata">

**Author:** [@Rbb](https://discuss.elastic.co/u/Rbb)\
**Replies:** 1\
**Last updated:** [July 12, 2023, 10:38am UTC](https://discuss.elastic.co/t/how-is-the-transaction-start-set-elastic-rum/338077 "2023-07-12T10:38:10Z")

</div>

Hi! We want to create an offset to group transactions across iframes with elastic RUM. We are wondering how transaction.\_start is set and what is it relative to? We have used the performance.timeOrigin in each initiali…

---

## [Start logstash error](https://discuss.elastic.co/t/start-logstash-error/338146)

<div class="topic-metadata">

**Author:** [@liqiu](https://discuss.elastic.co/u/liqiu)\
**Replies:** 2\
**Last updated:** [July 11, 2023, 8:05pm UTC](https://discuss.elastic.co/t/start-logstash-error/338146 "2023-07-11T20:05:01Z")

</div>

I have configured the logstash.yml configuration file logstash.yml： input {stdin{}} output {stdout{}} But when I enter ./logstash to start, the following error occurs \[2023-07-12T01:16:59,926\]\[INFO \]\[logstash.runner …

---

## [Error creating input: each processor must have exactly one action,but found 2 actions (add\_locale,decode\_json\_fields)](https://discuss.elastic.co/t/error-creating-input-each-processor-must-have-exactly-one-action-but-found-2-actions-add-locale-decode-json-fields/338201)

<div class="topic-metadata">

**Author:** [@farhad\_kh](https://discuss.elastic.co/u/farhad_kh)\
**Replies:** 1\
**Last updated:** [July 12, 2023, 10:07am UTC](https://discuss.elastic.co/t/error-creating-input-each-processor-must-have-exactly-one-action-but-found-2-actions-add-locale-decode-json-fields/338201 "2023-07-12T10:07:59Z")

</div>

hello i have a cluster kubeadm and collecting logs with filebeat autodiscover and i get this error after depoly 2023-07-12T09:34:19.588Z INFO log/input.go:152 Configured paths: \[/var/log/pods/\*\_554a0c…

---

## [How Elastic APM estimate SQL duraion](https://discuss.elastic.co/t/how-elastic-apm-estimate-sql-duraion/338198)

<div class="topic-metadata">

**Author:** [@Indeed2000](https://discuss.elastic.co/u/Indeed2000)\
**Replies:** 1\
**Last updated:** [July 12, 2023, 10:04am UTC](https://discuss.elastic.co/t/how-elastic-apm-estimate-sql-duraion/338198 "2023-07-12T10:04:32Z")

</div>

Hi I ran Elastic APM agent with my Application that use jdbc to connect to database. Now I compare top sql duration of Elastic APM agent and database log with below query on kibana: service.target.type : "sqli" and s…

---

## [Getting error even elastic container is running well but not getting respond on localhost](https://discuss.elastic.co/t/getting-error-even-elastic-container-is-running-well-but-not-getting-respond-on-localhost/337970)

<div class="topic-metadata">

**Author:** [@Rafia098](https://discuss.elastic.co/u/Rafia098)\
**Replies:** 1\
**Last updated:** [July 9, 2023, 10:54pm UTC](https://discuss.elastic.co/t/getting-error-even-elastic-container-is-running-well-but-not-getting-respond-on-localhost/337970 "2023-07-09T22:54:11Z")

</div>

event.dataset":"elasticsearch.server","process.thread.name":"elasticsearch\[76056f9efe4d\]\[transport\_worker\]\[T#1\]","log.logger":"org.elasticsearch.http.netty4.Netty4HttpServerTransport","elasticsearch.cluster.uuid":"FS0\_…

---

## [Help with query please](https://discuss.elastic.co/t/help-with-query-please/338191)

<div class="topic-metadata">

**Author:** [@lakhr034](https://discuss.elastic.co/u/lakhr034)\
**Replies:** 0\
**Last updated:** [July 12, 2023, 8:59am UTC](https://discuss.elastic.co/t/help-with-query-please/338191 "2023-07-12T08:59:04Z")

</div>

POST user\_info,user\_auth\_cards\_info/\_search { "size": 0, "query": { "bool": { "filter": \[ { "multi\_match": { "query": "test", "fields": \[ "e\_name.auto…

---

## [Each log line is split into a different document in Elastic](https://discuss.elastic.co/t/each-log-line-is-split-into-a-different-document-in-elastic/338144)

<div class="topic-metadata">

**Author:** [@Merav\_Yaacov](https://discuss.elastic.co/u/Merav_Yaacov)\
**Replies:** 3\
**Last updated:** [July 12, 2023, 5:37am UTC](https://discuss.elastic.co/t/each-log-line-is-split-into-a-different-document-in-elastic/338144 "2023-07-12T05:37:53Z")

</div>

Hi, What can be the reason that each line of log file is split into single document in Elastic? That's how Logstash is configured: input { file { type =\> "log" path =\> \["/etc/logstash/conf.d/files/\*.…

---

## [Provide values to the ctx.vars variables in the Painless file by extracting them from the YAML file](https://discuss.elastic.co/t/provide-values-to-the-ctx-vars-variables-in-the-painless-file-by-extracting-them-from-the-yaml-file/338172)

<div class="topic-metadata">

**Author:** [@Hardik\_Dave](https://discuss.elastic.co/u/Hardik_Dave)\
**Replies:** 0\
**Last updated:** [July 12, 2023, 5:37am UTC](https://discuss.elastic.co/t/provide-values-to-the-ctx-vars-variables-in-the-painless-file-by-extracting-them-from-the-yaml-file/338172 "2023-07-12T05:37:24Z")

</div>

I have a .painless file as mentioned below. As of now, the ctx.vars.var1 have hardcoded values in my original file, which now need to be retrieved from a YAML file. All these files are in same project, so relative path w…

---

## [Filebeat integration with DataDog](https://discuss.elastic.co/t/filebeat-integration-with-datadog/338163)

<div class="topic-metadata">

**Author:** [@KSimon](https://discuss.elastic.co/u/KSimon)\
**Replies:** 0\
**Last updated:** [July 12, 2023, 4:09am UTC](https://discuss.elastic.co/t/filebeat-integration-with-datadog/338163 "2023-07-12T04:09:39Z")

</div>

Hello, we have a use case to use Filebeat as a transporter of logs from one Cloud Source and feed the logs to DataDog and Kafka. There is a documentation for Kafka Output, however, there are no documentations to support…

---

## [Parsing the message field in security event.code 4624](https://discuss.elastic.co/t/parsing-the-message-field-in-security-event-code-4624/338046)

<div class="topic-metadata">

**Author:** [@Cruz](https://discuss.elastic.co/u/Cruz)\
**Replies:** 2\
**Last updated:** [July 11, 2023, 11:19pm UTC](https://discuss.elastic.co/t/parsing-the-message-field-in-security-event-code-4624/338046 "2023-07-11T23:19:14Z")

</div>

The information that I want is located under the first sub-header "Subject" and "Network Information". My basic question is this, how do I pull this information out of the Message field and display it along with the Time…

---

## [Filebeat not sending data to elasticsearch](https://discuss.elastic.co/t/filebeat-not-sending-data-to-elasticsearch/338154)

<div class="topic-metadata">

**Author:** [@gigallo](https://discuss.elastic.co/u/gigallo)\
**Replies:** 2\
**Last updated:** [July 11, 2023, 9:46pm UTC](https://discuss.elastic.co/t/filebeat-not-sending-data-to-elasticsearch/338154 "2023-07-11T21:46:02Z")

</div>

Hi 've installed elasticsearch 8.5 and Kibana 8.5 in my kubernetes cluster simply applying the official helm file in the elastic repo. Now I'm trying to install filebeat with the following conf: filebeat.inputs: - …

---

## [How to convert the Logstash message to fileds](https://discuss.elastic.co/t/how-to-convert-the-logstash-message-to-fileds/337910)

<div class="topic-metadata">

**Author:** [@Harper\_S1](https://discuss.elastic.co/u/Harper_S1)\
**Replies:** 15\
**Last updated:** [July 11, 2023, 9:17pm UTC](https://discuss.elastic.co/t/how-to-convert-the-logstash-message-to-fileds/337910 "2023-07-11T21:17:00Z")

</div>

Hi, I am using Logstash as a syslog server which sends data to elastic. here is the output. @timestampJul 7, 2023 @ 11:30:12.520@version1 hostname10.11.12.13 message {"proxyname":"test-123-abc","revision":"8","latency…

---

## [Forwarding logs from Sun Solaris to ELK](https://discuss.elastic.co/t/forwarding-logs-from-sun-solaris-to-elk/338147)

<div class="topic-metadata">

**Author:** [@DKalin0789e](https://discuss.elastic.co/u/DKalin0789e)\
**Replies:** 6\
**Last updated:** [July 11, 2023, 9:04pm UTC](https://discuss.elastic.co/t/forwarding-logs-from-sun-solaris-to-elk/338147 "2023-07-11T21:04:29Z")

</div>

We need to find a workaround for forwarding logs from Sun Solaris to ELK. Any ideas - very welcome! No any vendors like Logstash, Filebeat, Vector officially support Log Forwarders on Sun Solaris. Any help? Thank you.

---

## [Cannot use terms aggregation to get the field which is injest by enrich processor](https://discuss.elastic.co/t/cannot-use-terms-aggregation-to-get-the-field-which-is-injest-by-enrich-processor/336554)

<div class="topic-metadata">

**Author:** [@JasonREC](https://discuss.elastic.co/u/JasonREC)\
**Replies:** 1\
**Last updated:** [July 11, 2023, 8:23pm UTC](https://discuss.elastic.co/t/cannot-use-terms-aggregation-to-get-the-field-which-is-injest-by-enrich-processor/336554 "2023-07-11T20:23:04Z")

</div>

I am trying to get the db\_tag field which is injested using injestpipeline with enrich processor, but it does not return anything even the field is existed in the doucment.

[Previous page](https://discuss.elastic.co/latest.md?page=609)

[Next page](https://discuss.elastic.co/latest.md?page=611)
