# Latest

**URL:** https://discuss.elastic.co/latest.md?page=616

[Latest](https://discuss.elastic.co/latest.md) · [Categories](https://discuss.elastic.co/categories.md) · [Tags](https://discuss.elastic.co/tags.md)

**Page:** 617

---

## [Kibana hangs during search for logs containing base64](https://discuss.elastic.co/t/kibana-hangs-during-search-for-logs-containing-base64/337565)

<div class="topic-metadata">

**Author:** [@duch](https://discuss.elastic.co/u/duch)\
**Replies:** 1\
**Last updated:** [July 6, 2023, 11:13am UTC](https://discuss.elastic.co/t/kibana-hangs-during-search-for-logs-containing-base64/337565 "2023-07-06T11:13:43Z")

</div>

Hi, we are running into a problem where kibana starts hanging when a search is performed in which logs are returned that contain base64 in a message field. The field encompases an api response with among others 10 mb of…

---

## [Looking for community members for a UX research study!](https://discuss.elastic.co/t/looking-for-community-members-for-a-ux-research-study/337786)

<div class="topic-metadata">

**Author:** [@Gabriel\_Hughes](https://discuss.elastic.co/u/Gabriel_Hughes)\
**Replies:** 0\
**Last updated:** [July 6, 2023, 10:58am UTC](https://discuss.elastic.co/t/looking-for-community-members-for-a-ux-research-study/337786 "2023-07-06T10:58:30Z")

</div>

Hey everyone, my name is Gabriel Hughes - I’m a UX Researcher here at Elastic, focusing on Search solutions. The Search product team is looking for community members to participate in discussions to learn more about how …

---

## [Kibana query problem](https://discuss.elastic.co/t/kibana-query-problem/337671)

<div class="topic-metadata">

**Author:** [@Hanni](https://discuss.elastic.co/u/Hanni)\
**Replies:** 7\
**Last updated:** [July 6, 2023, 10:55am UTC](https://discuss.elastic.co/t/kibana-query-problem/337671 "2023-07-06T10:55:52Z")

</div>

Hello, I'm currently working with kibana. Currently I have made a visualization that allows me to count the unique host. I have another plugin \_id field But the problem is that I want to be able to count the unique pl…

---

## [Logstash does not update document](https://discuss.elastic.co/t/logstash-does-not-update-document/337777)

<div class="topic-metadata">

**Author:** [@mehmetalix](https://discuss.elastic.co/u/mehmetalix)\
**Replies:** 0\
**Last updated:** [July 6, 2023, 10:24am UTC](https://discuss.elastic.co/t/logstash-does-not-update-document/337777 "2023-07-06T10:24:23Z")

</div>

Hi, I have a problem with data update in logstash. I need to update specific field in some document according to sql data. My data is looking like this: testid-field1-field2-field3-testtype-time 1-1-1-1-1-2023/05 1…

---

## [Issues with ELK](https://discuss.elastic.co/t/issues-with-elk/337326)

<div class="topic-metadata">

**Author:** [@pero](https://discuss.elastic.co/u/pero)\
**Replies:** 20\
**Last updated:** [July 6, 2023, 10:40am UTC](https://discuss.elastic.co/t/issues-with-elk/337326 "2023-07-06T10:40:38Z")

</div>

Hi All, I have the template siem\_alarm created in my kibana index pattern but i have this error "Error: No indices match pattern "siem\_alarms" at url/bundles/commons.bundle.js:3:1337196" Does anyone know what could be …

---

## [Elastic Curl search index refine](https://discuss.elastic.co/t/elastic-curl-search-index-refine/337776)

<div class="topic-metadata">

**Author:** [@kuthputheen](https://discuss.elastic.co/u/kuthputheen)\
**Replies:** 0\
**Last updated:** [July 6, 2023, 10:21am UTC](https://discuss.elastic.co/t/elastic-curl-search-index-refine/337776 "2023-07-06T10:21:43Z")

</div>

Team, I am using Elastic aggregation to fetch the certain values from the Logstash-database ( Index Name) search and the JSON results generating huge output (currently fetches 30,000 lines output) and bit time consuming…

---

## [Using own SSL certificate doesn't work on stack Elasticsearch + Kibana](https://discuss.elastic.co/t/using-own-ssl-certificate-doesnt-work-on-stack-elasticsearch-kibana/337772)

<div class="topic-metadata">

**Author:** [@vojtech-cerveny](https://discuss.elastic.co/u/vojtech-cerveny)\
**Replies:** 0\
**Last updated:** [July 6, 2023, 9:31am UTC](https://discuss.elastic.co/t/using-own-ssl-certificate-doesnt-work-on-stack-elasticsearch-kibana/337772 "2023-07-06T09:31:34Z")

</div>

Hello! I tried to create production stack kibana + elasticsearch and I am kinda stuck on certificates. Can you help me find the problem in my setting? Situation: We have SSL certificate for \*.example.com and I need …

---

## [Installing elasticsearch at Redhat openshift](https://discuss.elastic.co/t/installing-elasticsearch-at-redhat-openshift/337637)

<div class="topic-metadata">

**Author:** [@Yasser\_Alsawy](https://discuss.elastic.co/u/Yasser_Alsawy)\
**Replies:** 2\
**Last updated:** [July 6, 2023, 8:52am UTC](https://discuss.elastic.co/t/installing-elasticsearch-at-redhat-openshift/337637 "2023-07-06T08:52:31Z")

</div>

I want to install Elasticsearch at Openshif on-premise. I'm not sure if I have to follow ECE or is it limited to only installation on cloud? should I create servers with roles allocator, director, proxy and coordinator …

---

## [Can't enroll new node in current cluster](https://discuss.elastic.co/t/cant-enroll-new-node-in-current-cluster/337764)

<div class="topic-metadata">

**Author:** [@Hi\_u\_Thu\_n](https://discuss.elastic.co/u/Hi_u_Thu_n)\
**Replies:** 0\
**Last updated:** [July 6, 2023, 8:28am UTC](https://discuss.elastic.co/t/cant-enroll-new-node-in-current-cluster/337764 "2023-07-06T08:28:12Z")

</div>

When i try bin\\elasticsearch --enrollment-token MyErrollMent It show an error ERROR: Skipping security auto configuration because it appears that the node is not starting up for the first time. The node might already …

---

## [Elastic Stack Upgradation](https://discuss.elastic.co/t/elastic-stack-upgradation/337760)

<div class="topic-metadata">

**Author:** [@Akulainelastic](https://discuss.elastic.co/u/Akulainelastic)\
**Replies:** 1\
**Last updated:** [July 6, 2023, 7:57am UTC](https://discuss.elastic.co/t/elastic-stack-upgradation/337760 "2023-07-06T07:57:59Z")

</div>

Hi All, so I want to upgrade the entire elk stack version from 7.2 to 8.4 , could anyone shed some light here upon what all backup and prerequisites I need to take care of. Thanks in advance.

---

## [Issue's in configuring kafka input plugin with TLS](https://discuss.elastic.co/t/issues-in-configuring-kafka-input-plugin-with-tls/337761)

<div class="topic-metadata">

**Author:** [@girish.ms](https://discuss.elastic.co/u/girish.ms)\
**Replies:** 0\
**Last updated:** [July 6, 2023, 7:50am UTC](https://discuss.elastic.co/t/issues-in-configuring-kafka-input-plugin-with-tls/337761 "2023-07-06T07:50:34Z")

</div>

Description of the problem: I'm having trouble integrating Kafka with Logstash, and Kafka is configured with TLS. I am getting the following exceptions when trying to provide PKCS12 format TLS certificates in the Kafka…

---

## [Does App Search support federated search and xpack security](https://discuss.elastic.co/t/does-app-search-support-federated-search-and-xpack-security/337409)

<div class="topic-metadata">

**Author:** [@Ong](https://discuss.elastic.co/u/Ong)\
**Replies:** 1\
**Last updated:** [July 6, 2023, 7:50am UTC](https://discuss.elastic.co/t/does-app-search-support-federated-search-and-xpack-security/337409 "2023-07-06T07:50:26Z")

</div>

I am not able to find a category for App Search while Enterprise Search seems to be the closest fit. So apologies if this topic is better fit in another category. Does App Search support federated search across multiple…

---

## [\[App Search\] - Ingesting Wrong Documents Issue](https://discuss.elastic.co/t/app-search-ingesting-wrong-documents-issue/336951)

<div class="topic-metadata">

**Author:** [@aisyaharifin](https://discuss.elastic.co/u/aisyaharifin)\
**Replies:** 1\
**Last updated:** [July 6, 2023, 7:39am UTC](https://discuss.elastic.co/t/app-search-ingesting-wrong-documents-issue/336951 "2023-07-06T07:39:09Z")

</div>

Hello, I have a case where the data that I've been ingested got detected as wrong data. The data have been classified into MATERIAL and SERVICE type of data. The wrong data resides under SERVICE classification with a t…

---

## [Standard logs from nodejs application to kibana using winston-elasticsearch, elastic-apm-node or elastic apm logger](https://discuss.elastic.co/t/standard-logs-from-nodejs-application-to-kibana-using-winston-elasticsearch-elastic-apm-node-or-elastic-apm-logger/337748)

<div class="topic-metadata">

**Author:** [@akhil11](https://discuss.elastic.co/u/akhil11)\
**Replies:** 0\
**Last updated:** [July 6, 2023, 5:41am UTC](https://discuss.elastic.co/t/standard-logs-from-nodejs-application-to-kibana-using-winston-elasticsearch-elastic-apm-node-or-elastic-apm-logger/337748 "2023-07-06T05:41:16Z")

</div>

Hey team i am trying to get normal logs I am using NodeJs - Typescript and using an nodejs agent from elastic to connect using server name and server token. I want to capture general logs like below to be captured and…

---

## [Issue running elastics/security track in esrally offline mode](https://discuss.elastic.co/t/issue-running-elastics-security-track-in-esrally-offline-mode/336609)

<div class="topic-metadata">

**Author:** [@Swathi\_Kakumanu](https://discuss.elastic.co/u/Swathi_Kakumanu)\
**Replies:** 3\
**Last updated:** [July 6, 2023, 4:49am UTC](https://discuss.elastic.co/t/issue-running-elastics-security-track-in-esrally-offline-mode/336609 "2023-07-06T04:49:50Z")

</div>

Hi, I am trying to run esrally in offline mode. I am successful in running the http\_logs or geonames tracks in offline mode. However, I am facing issue when running the elastic/security or elastic/logs tracks in offline…

---

## [Elastic-agent not connecting to fleet server](https://discuss.elastic.co/t/elastic-agent-not-connecting-to-fleet-server/337744)

<div class="topic-metadata">

**Author:** [@pennywise01](https://discuss.elastic.co/u/pennywise01)\
**Replies:** 0\
**Last updated:** [July 6, 2023, 4:30am UTC](https://discuss.elastic.co/t/elastic-agent-not-connecting-to-fleet-server/337744 "2023-07-06T04:30:40Z")

</div>

Hi, I am still new to this elastic-agent stuff. I am trying to connect my elastic agent that i want to install on my vm on GCP to connect to my fleet server on AWS EC2. I have already configured firewall rules to allow c…

---

## [JSON parse error, original data now in message field {:message=\>"Could not set field 'original' on object '' to value '{\\"event\\": \\"\\"}'](https://discuss.elastic.co/t/json-parse-error-original-data-now-in-message-field-message-could-not-set-field-original-on-object-to-value-event/337740)

<div class="topic-metadata">

**Author:** [@cosmosir](https://discuss.elastic.co/u/cosmosir)\
**Replies:** 0\
**Last updated:** [July 6, 2023, 4:09am UTC](https://discuss.elastic.co/t/json-parse-error-original-data-now-in-message-field-message-could-not-set-field-original-on-object-to-value-event/337740 "2023-07-06T04:09:53Z")

</div>

logstash8.8.1 JSON parse error, original data now in message field {:message=\>"Could not set field 'original' on object '' to value '{"event": ""}'.This is probably due to trying to set a field like \[foo\]\[bar\] = someVal…

---

## [Elasticsearch restoring got conflicts with the internal system indices](https://discuss.elastic.co/t/elasticsearch-restoring-got-conflicts-with-the-internal-system-indices/337586)

<div class="topic-metadata">

**Author:** [@Mike\_Z](https://discuss.elastic.co/u/Mike_Z)\
**Replies:** 2\
**Last updated:** [July 5, 2023, 11:25pm UTC](https://discuss.elastic.co/t/elasticsearch-restoring-got-conflicts-with-the-internal-system-indices/337586 "2023-07-05T23:25:50Z")

</div>

We are trying to restore a snapshot made previously, using the following command: POST /\_snapshot/my\_backup/my\_snapshot\_2023.06.30/\_restore However, the command keeps getting errors saying ... index \[.xxxxxx\] because a…

---

## [Elastic Agent - Remove Unused Beats](https://discuss.elastic.co/t/elastic-agent-remove-unused-beats/337726)

<div class="topic-metadata">

**Author:** [@RichardH1](https://discuss.elastic.co/u/RichardH1)\
**Replies:** 0\
**Last updated:** [July 5, 2023, 10:36pm UTC](https://discuss.elastic.co/t/elastic-agent-remove-unused-beats/337726 "2023-07-05T22:36:44Z")

</div>

Hi, We want to use Elastic Agent for our server deployments but the package size is larger than competing technologies. 90% of our servers just need Metricbeat installed so I'm wondering if we can strip out the other be…

---

## [Search UI - custom checkbox styling issue](https://discuss.elastic.co/t/search-ui-custom-checkbox-styling-issue/337725)

<div class="topic-metadata">

**Author:** [@JeroenAdam](https://discuss.elastic.co/u/JeroenAdam)\
**Replies:** 0\
**Last updated:** [July 5, 2023, 10:28pm UTC](https://discuss.elastic.co/t/search-ui-custom-checkbox-styling-issue/337725 "2023-07-05T22:28:05Z")

</div>

Hi there, I'm developing an app using search UI and Elasticsearch, great experience so far. I 'm lacking in advanced React skills, I have no idea why my custom styled checkboxes won't reflect the correct state in the UI…

---

## [ILM not deleting index](https://discuss.elastic.co/t/ilm-not-deleting-index/337241)

<div class="topic-metadata">

**Author:** [@raymondmintz11](https://discuss.elastic.co/u/raymondmintz11)\
**Replies:** 22\
**Last updated:** [July 5, 2023, 10:12pm UTC](https://discuss.elastic.co/t/ilm-not-deleting-index/337241 "2023-07-05T22:12:11Z")

</div>

I am running a simple setup with ILM and small index. ILM should delete the index but instead its stuck at "step": "check-rollover-ready", here is my script to recreate the index #!/bin/bash echo -e "\\n update s…

---

## [Adding Uptime Monitors to a Dashboard](https://discuss.elastic.co/t/adding-uptime-monitors-to-a-dashboard/336454)

<div class="topic-metadata">

**Author:** [@mpinto](https://discuss.elastic.co/u/mpinto)\
**Replies:** 5\
**Last updated:** [July 5, 2023, 9:36pm UTC](https://discuss.elastic.co/t/adding-uptime-monitors-to-a-dashboard/336454 "2023-07-05T21:36:19Z")

</div>

Hello, I am creating a few dashboards to monitor our solutions' logs and we have a separate "dashboard" with all our Uptime Monitors. Is there a way to incorporate these uptime monitors in the dashboards we're building? …

---

## [Heartbeat auto-discover not working for AWS ELB](https://discuss.elastic.co/t/heartbeat-auto-discover-not-working-for-aws-elb/337187)

<div class="topic-metadata">

**Author:** [@michael31](https://discuss.elastic.co/u/michael31)\
**Replies:** 2\
**Last updated:** [July 5, 2023, 9:31pm UTC](https://discuss.elastic.co/t/heartbeat-auto-discover-not-working-for-aws-elb/337187 "2023-07-05T21:31:47Z")

</div>

Hello, I am trying to set up heartbeat for AWS autodiscover ELB in 2 accounts (1 I did succesffully) and on the second with the exact same configuration I am getting the following errors. I configured everything as a far…

---

## [Wildcard search for a word](https://discuss.elastic.co/t/wildcard-search-for-a-word/337718)

<div class="topic-metadata">

**Author:** [@umesh\_choudary](https://discuss.elastic.co/u/umesh_choudary)\
**Replies:** 0\
**Last updated:** [July 5, 2023, 9:03pm UTC](https://discuss.elastic.co/t/wildcard-search-for-a-word/337718 "2023-07-05T21:03:02Z")

</div>

How can i search for a word as contains while searching index. eg: if i search the index using books, i need to get the results which should contain book and books in the response..

---

## [Add a customizable ID for package policy](https://discuss.elastic.co/t/add-a-customizable-id-for-package-policy/337690)

<div class="topic-metadata">

**Author:** [@Bearloggs](https://discuss.elastic.co/u/Bearloggs)\
**Replies:** 2\
**Last updated:** [July 5, 2023, 8:58pm UTC](https://discuss.elastic.co/t/add-a-customizable-id-for-package-policy/337690 "2023-07-05T20:58:05Z")

</div>

Hello, I am trying to create a policy package using the Kibana Dev Tools and I wondered if it was possible to apply a unique customizable ID. For example, I want to create osquery manager package policy with ID "osquer…

---

## [Change Timestamp to event.ingested](https://discuss.elastic.co/t/change-timestamp-to-event-ingested/337498)

<div class="topic-metadata">

**Author:** [@Xenial](https://discuss.elastic.co/u/Xenial)\
**Replies:** 1\
**Last updated:** [July 5, 2023, 8:44pm UTC](https://discuss.elastic.co/t/change-timestamp-to-event-ingested/337498 "2023-07-05T20:44:29Z")

</div>

Hello Elastic Team, Can you help me , i want to change timestamp field to event.ingested on Kibana 8.8 and elasticsearch 8 Thankyou

---

## [Time since last response](https://discuss.elastic.co/t/time-since-last-response/337440)

<div class="topic-metadata">

**Author:** [@tomwood](https://discuss.elastic.co/u/tomwood)\
**Replies:** 4\
**Last updated:** [July 5, 2023, 8:35pm UTC](https://discuss.elastic.co/t/time-since-last-response/337440 "2023-07-05T20:35:46Z")

</div>

I'm trying to create a visualisation in Kibana dashboard that shows the UP Time of some API's and also shows when they last logged a response into Elastic. I want to colour each api's info green, amber or red, depending …

---

## [Vulnerability is not being allowed in event.category](https://discuss.elastic.co/t/vulnerability-is-not-being-allowed-in-event-category/337674)

<div class="topic-metadata">

**Author:** [@hodgepodge](https://discuss.elastic.co/u/hodgepodge)\
**Replies:** 2\
**Last updated:** [July 5, 2023, 7:59pm UTC](https://discuss.elastic.co/t/vulnerability-is-not-being-allowed-in-event-category/337674 "2023-07-05T19:59:51Z")

</div>

I am seeing this failure while testing pipeline of integration: \[0\] parsing field value failed: field "event.category"'s value "vulnerability" is not one of the allowed values (authentication, configuration, database, d…

---

## [Deserializing Avro Records with different schemas](https://discuss.elastic.co/t/deserializing-avro-records-with-different-schemas/337701)

<div class="topic-metadata">

**Author:** [@fine\_porcupine](https://discuss.elastic.co/u/fine_porcupine)\
**Replies:** 2\
**Last updated:** [July 5, 2023, 7:43pm UTC](https://discuss.elastic.co/t/deserializing-avro-records-with-different-schemas/337701 "2023-07-05T19:43:12Z")

</div>

I'm doing the due diligence on the Avro Codec Plugin and I'm wondering if it's possible to use this if there are different types of events in the same SQS queue? For example - SQS Queue contains serialized events with s…

---

## [Kibana: export option for table visualisations](https://discuss.elastic.co/t/kibana-export-option-for-table-visualisations/337592)

<div class="topic-metadata">

**Author:** [@Russell\_Fulton](https://discuss.elastic.co/u/Russell_Fulton)\
**Replies:** 2\
**Last updated:** [July 5, 2023, 7:38pm UTC](https://discuss.elastic.co/t/kibana-export-option-for-table-visualisations/337592 "2023-07-05T19:38:39Z")

</div>

ES/Kibana version 7.17.1 I want to be able to export data from aggregation table visualisations. I have some existing ones that have an export option: so far as I can tell these are not Lense but the original "Aggre…

[Previous page](https://discuss.elastic.co/latest.md?page=615)

[Next page](https://discuss.elastic.co/latest.md?page=617)
